Revolut says no direct contact from hackers after $3M public ransom demand
Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
Revolut announced it has not received any direct communication from the group "IAmNotAVillain," which publicly demanded 6,000 Monero (about $3 million) in ransom following a customer data breach. Multiple groups, including "Revolut Smilik" and an actor linked to the revoloot.lol website, have also claimed responsibility, creating uncertainty over who controls the stolen data. Italian authorities are expanding their investigation into the incident, particularly regarding the misuse of a government email account.
Why it matters
The source highlights that the breach involves a government entity and has prompted investigations by Italy’s National Anti-Mafia and Anti-Terrorism Directorate, indicating potential wider implications for public sector cybersecurity. The involvement of multiple claimed ransom calls and the targeting of government data may increase scrutiny on financial institutions’ data security practices. The source does not elaborate further on market or user impacts.
Key context
Revolut first disclosed the data breach last week, and the ransom demand from "IAmNotAVillain" followed, threatening to sell customer records. A previous claim by "Revolut Smilik" demanded 10,000 Bitcoin, much higher than the current ransom demand. Italy’s privacy regulator is reviewing banking access system security in response to this incident, reflecting broader concern over institutional vulnerabilities.
Key numbers and entities
Revolut; hacking groups "IAmNotAVillain," "Revolut Smilik," and an unknown actor linked to revoloot.lol; 6,000 Monero (approx. $3 million); 10,000 Bitcoin (approx. $780 million); Italy’s National Anti-Mafia and Anti-Terrorism Directorate; prosecutors in Reggio Calabria; Italy’s privacy regulator ANSA.
What remains unclear
The actual identity and control over the stolen customer data remain uncertain due to conflicting ransom claims and inaccessible associated websites. Details about the extent of the data breach and whether other institutions are affected are not established. The source does not clarify if Revolut has paid any ransom or how it is addressing the breach internally.