Hackers operating under the handle IAmNotAVillain compromised an official Italian Ministry of Interior email account to send fraudulent emergency data requests to Revolut. The compliance team at Revolut complied, exposing sensitive identity documents, selfies, and Bitcoin transaction histories of roughly 680 high-net-worth crypto users. The attackers are demanding a $3 million ransom in Monero within a 24-hour window, prompting investigations by the UK Information Commissioner's Office and Italian cybercrime units.
Italian government email compromise
- ▪Italian opposition lawmaker Giulia Pastorella requested an explanation from the Ministry of Interior regarding the email compromise.
- ▪The compromised Italian government email address was used to bypass SPF, DKIM, and DMARC authentication checks on Revolut's compliance workflow.
- ▪An unauthorized third party compromised an email account on the @interno.it domain belonging to Italy's Ministry of Interior.
Revolut customer data breach
- ▪The compromised Revolut customer data included passport copies, driving licenses, verification selfies, IBANs, bank statements, and full Bitcoin transaction histories.
- ▪Revolut stated that its core internal systems and client funds were not compromised during the incident.
- ▪A data breach at Revolut exposed the personal information of approximately 680 to 700 customers, specifically targeting high-net-worth cryptocurrency holders.
- ▪Former Mt. Gox executive Mark Karpelès confirmed he was affected by the Revolut breach and received a notification that his Bitcoin transaction details were exposed.
Monero ransom demand
- ▪The threat actor IAmNotAVillain set a 24-hour deadline for the $3 million Monero ransom payment, threatening to sell the records to other criminal groups.
- ▪The threat actor IAmNotAVillain demanded a ransom of approximately $3 million, denominated as 6,000 Monero (XMR), to keep the stolen Revolut customer data confidential.
- ▪Revolut had not received a direct ransom demand or been contacted by the perpetrators through negotiated channels as of September 16, 2026.
Emergency data request exploitation
- ▪The attackers used the compromised Italian government email to submit fraudulent emergency data requests, which tech companies often process quickly without a court order.
- ▪Revolut compliance staff processed the fraudulent emergency data requests as routine legal demands before realizing the sender was an impersonator.
UK ICO investigation
- ▪The United Kingdom's Information Commissioner's Office opened an assessment into Revolut's data handling practices and verification procedures following the breach.
- ▪The United Kingdom's Financial Conduct Authority engaged with Revolut regarding the security incident.
Debatable claims
- ▪Centralized financial platforms pose an unacceptable physical security risk to high-net-worth cryptocurrency holders
- ▪Revolut should pay the $3 million ransom to protect its customers' data
- ▪Fintech platforms should require judicial approval before fulfilling emergency law enforcement data requests
Story comments
Loading comments…