Skip to content

Coins

Revolut Hackers Demand 6,000 XMR as Italy Opens Data Probe

Key Highlights Italian prosecutors and anti-mafia authorities have launched an investigation after hackers allegedly compromised an Italian government email account to steal sensitive data from at least 680 Revolut customers....

Key Highlights

  • Italian prosecutors and anti-mafia authorities have launched an investigation after hackers allegedly compromised an Italian government email account to steal sensitive data from at least 680 Revolut customers.
  • The group “iamnotavillain” demanded 6,000 Monero (XMR), valued at approximately $3 million, threatening to sell passports, driving licenses, identity photos, and transaction histories if the ransom was not paid by a September 16 deadline.
  • Revolut confirmed no internal systems or client funds were breached, stated it had not formally received a ransom demand, and is cooperating with regulators and law enforcement while offering support to affected customers.

Italian Authorities Investigate Government Email Compromise Linked to Revolut Data Theft

Italian prosecutors have opened a formal investigation following allegations that cybercriminals infiltrated a government email system to obtain confidential information on hundreds of Revolut customers. According to reports from the Financial Times and Euronews, the breach enabled attackers to pose as law enforcement officials and extract sensitive personal data, including passports, driving licenses, identity photographs, and detailed transaction histories. At least 680 customer accounts are confirmed to have been compromised in the operation.

Ransom Demand and the Role of Monero

The threat actor, identifying as “iamnotavillain,” published a ransom demand on September 16 accompanied by a 24-hour countdown timer. The group demanded payment of 6,000 Monero (XMR), worth roughly $3 million at the time, and threatened to auction the stolen records to other criminals if the deadline passed without payment. “They said that they identified customers with a lot of crypto holdings by doing blockchain analysis.” The attackers further claimed “They said they got the records after they compromised an Italian government email system and acted as if they were law enforcement officials.” As of the latest updates, it remains unclear whether Revolut paid the ransom or if the data has been sold on underground markets.

Revolut Denies System Breach, Confirms Customer Support Measures

Revolut has maintained that its own infrastructure and client funds remain secure. “Revolut responded by stating they had not formally heard back from the group nor received any ransom demands.” The company added, “They confirmed that none of its internal nor client funds had been affected nor breached.” In a further statement, Revolut emphasized its cooperation with authorities: “Revolut has said that they have been working closely with other regulators and law enforcement bodies, and have also offered to help and support any of its affected customers.” The neobank has not disclosed the specific number of impacted users beyond the 680 figure cited in media reports.

Anti-Mafia and Counterterrorism Units Join the Probe

The investigation has escalated beyond standard cybercrime channels. Italian prosecutors are now working alongside the country’s anti-mafia and counterterrorism authorities, signaling the potential involvement of organized crime networks or the severity of the government email compromise. The participation of these specialized units underscores the gravity with which Rome is treating the infiltration of state communications infrastructure for financial fraud.

Why This Matters

This incident highlights a growing threat vector in which criminals target trusted government communication channels to legitimize social engineering attacks against financial institutions and their customers. By compromising an official email account, the attackers bypassed traditional verification protocols, exploiting the inherent trust placed in law enforcement correspondence. The use of Monero as the ransom currency reflects a broader trend in ransomware operations: threat actors increasingly favor privacy-preserving cryptocurrencies to obscure transaction trails. While Monero’s protocol was not breached—its privacy features functioned as designed—the case illustrates how legitimate privacy tools can be co-opted for illicit finance. For Revolut and the broader fintech sector, the episode underscores the need for robust verification mechanisms that do not rely solely on email domain authenticity, as well as proactive customer notification frameworks when third-party data exposures occur.

Frequently Asked Questions

How did the attackers access Revolut customer data?

The group allegedly compromised an Italian government email account and impersonated law enforcement officials to obtain sensitive customer records, including identity documents and transaction histories, from Revolut.

Was Revolut’s own platform hacked?

No. Revolut confirmed that its internal systems and client funds were not breached. The data was obtained through a compromised government email account, not through a direct intrusion into Revolut’s infrastructure.

Why did the hackers demand payment in Monero (XMR)?

Monero’s protocol obscures transaction amounts, sender addresses, and recipient addresses by default, making it significantly harder for law enforcement to trace ransom payments compared to transparent blockchains like Bitcoin.

Evan Mercer

Penulis

Evan Mercer covers coins, digital assets and the market stories shaping everyday conversations about money. His work focuses on accessible explanations, useful context and the signals behind sudden moves.