A group calling itself iamnotavillain has demanded 6,000 XMR, valued at approximately $3 million, from Revolut within a 24-hour window. The extortionists threaten to sell hundreds of customers' identity documents and transaction records if the payment is not made. This demand follows a breach where Revolut handed over data in response to fraudulent requests that appeared to come from a compromised Italian government email system.
The attackers used blockchain analysis to identify accounts with substantial crypto holdings before targeting specific users. The stolen information includes names, dates of birth, home addresses, passport copies, verification selfies, account statements with IBANs, and full transaction histories. At least 680 accounts were affected by this sophisticated impersonation scam. Revolut stated it received no direct contact or demand and described the number of affected customers as limited, confirming that funds and systems remained untouched.
This incident highlights a dangerous convergence of traditional social engineering and advanced on-chain surveillance. By leveraging blockchain analysis to pinpoint high-value targets before executing a phishing campaign via compromised government channels, attackers have moved beyond indiscriminate data theft to precision targeting. The extensive nature of the leaked data, including physical addresses and verified identities alongside financial holdings, significantly elevates the risk of real-world violence, such as wrench attacks, against cryptocurrency holders.
From an institutional perspective, the breach exposes critical vulnerabilities in how major fintech platforms verify external data requests. The fact that Revolut complied with fraudulent inquiries due to valid authentication from a compromised domain suggests gaps in multi-factor verification protocols for sensitive customer disclosures. While the company denies receiving the ransom demand, the public posting of the threat underscores the need for stricter operational security measures and transparent communication regarding data integrity when facing sophisticated, cross-border cybercriminal networks.


