Skip to main content

Revolut Denies Direct Contact After $3M Public Ransom Demand



Revolut says it has received no direct messages from the hackers publicly demanding a ransom over a customer data breach, even as multiple groups compete for credit and threaten further disclosures.


A faction using the name “IAmNotAVillain” demanded 6,000 Monero (XMR)—worth about $3 million—within 24 hours, according to a report by the Financial Times. On Thursday, a Revolut spokesperson told Cointelegraph that the company has not received any direct contact or demand from the individuals behind those claims.



Key takeaways



  • Revolut confirms it has not received direct communication from “IAmNotAVillain” despite public ransom threats.

  • A rival claimant (“Revolut Smilik”) previously circulated a far larger Bitcoin demand, widening uncertainty over who controls the stolen data.

  • Investigators in Italy are broadening the probe because the suspected intrusion involves an alleged compromise or cloning of a government email account.

  • Regulators are pressing banks to review access security, suggesting the issue may extend beyond a single breach channel.



Competing ransom claims muddy attribution


Revolut’s lack of direct contact matters because public ultimatums do not automatically indicate which party actually holds the data, how much has been extracted, or whether the threat is actionable. In this case, “IAmNotAVillain” is only one name attached to online claims related to the breach.


Cointelegraph previously reported that Revolut disclosed the incident last week and tied its exposure to alleged access obtained using a fake government email account. When Cointelegraph attempted to check the “IAmNotAVillain” website, iamnotavillain.xyz, it was unavailable at the time of publication.


Adding further ambiguity, an earlier group calling itself “Revolut Smilik” reportedly made a demand of 10,000 Bitcoin (about $780 million at the time), a figure dramatically larger than the later XMR demand reported by the Financial Times.


In a notice on its site, “IAmNotAVillain” disputed the competing claim, alleging that a former associate had received only a small sample of the data before taking credit for the breach. The site also warned other parties not to “deal” with the rival claimant—an escalation that typically reflects internal disputes among actors rather than proof of control over the full dataset.


Meanwhile, a cybersecurity-focused account, Dark Web Informer, also flagged another website—revoloot.lol—as associated with a separate actor claiming responsibility. That site was also unavailable when checked by Cointelegraph. Together, these competing claims make it difficult for outside observers to confidently map which group is operating the extortion pipeline.



Why Revolut’s response is significant for customers and markets


Extortion incidents increasingly unfold as a chain of claims, samples, and retractions across multiple domains—often making it hard to determine whether a victim’s infrastructure can be directly negotiated with. Revolut’s statement that it has not received any direct contact suggests the company cannot yet validate that the public demand corresponds to a party willing or able to engage with the organization privately.


For affected customers, this distinction matters because it affects expectations around mitigation. Direct communications can sometimes include specifics about the data or the steps required to verify deletion. Without that channel, customer-impact assessments and remediation efforts rely more heavily on forensic findings than on attacker instructions.


For the broader crypto audience, the ransom component underscores how extortion ecosystems increasingly mix anonymity-preserving assets such as Monero with shifting claimant identities. In practice, the exact asset and headline valuation can change faster than the underlying breach details—particularly when multiple groups are signaling from the sidelines.



Italy expands the investigation beyond a single victim


While the extortion messaging continues online, the law-enforcement angle is also deepening. According to Italian news agency ANSA reported on Wednesday, Italy’s National Anti-Mafia and Anti-Terrorism Directorate has become involved because the suspected intrusion appears to concern a government entity.


Prosecutors in Reggio Calabria have opened an investigation into unauthorized access to a computer system of public interest. Investigators are working to determine whether the institutional email account was breached outright or cloned—an important technical distinction that can affect both accountability and how the wider ecosystem was targeted.


Italy’s privacy regulator has also asked banks to urgently review the security of their access systems. The regulator is separately examining whether other banks or financial institutions may have been affected, implying that the breach method may not have been isolated to Revolut’s environment.


Earlier coverage from Cointelegraph noted that the investigation centers on a government email account allegedly used to obtain customer data. With multiple claimant narratives still unfolding online, the official inquiry remains a key reference point for what investigators can substantiate about the intrusion path.



What to watch next


Investors, security teams, and customers should watch for two developments: whether Italian investigators can confirm the mechanism behind the government email compromise or cloning, and whether any attacker claim evolves into verifiable direct contact with Revolut or corroborating evidence about the amount and scope of the exposed data.



https://www.cryptobreaking.com/revolut-denies-direct-contact-after/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=Revolut%20Denies%20Direct%20Contact%20After%20$3M%20Public%20Ransom%20Demand%20

Comments

Popular posts from this blog

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Top Cryptocurrencies to Watch: BTC, ETH, BNB, XRP, Solana, Dogecoin & More

Market Analysis and Price Predictions for Key Cryptocurrencies Recent market dynamics reveal a cautious sentiment across the cryptocurrency landscape, with Bitcoin struggling to maintain levels above $90,000 and many major altcoins facing downward pressure. Indicators point toward reduced participation from both institutional and retail investors, raising concerns about a potential consolidation phase after notable gains earlier in the year. Bitcoin has fallen below $87,000, reflecting waning demand at higher price points. Institutional fund flows into BTC and ETH ETFs have turned negative, indicating a period of subdued market activity. Active addresses and Binance deposit/withdrawal activities are at annual lows, suggesting market indecision. Most leading altcoins are approaching support levels, with some poised for potential breakdowns. Tickers mentioned: Bitcoin, Ethereum, Binance Coin, XRP, Solana, Dogecoin, Cardano, Bitcoin Cash, Chainlink, Hyperliquid Sentiment: Neutral to Sli...

Coinbase's x402 launches AI agents app store for payments

Coinbase-backed x402 has unveiled Agentic.market, a dedicated marketplace aimed at increasing the usefulness of AI agents by aggregating thousands of apps and services that agents can access without any API keys. The rollout positions the platform as a central hub for agents to discover, evaluate, and deploy capabilities across a standardized payments layer. Coinbase product lead Nick Prince described Agentic.market in a video posted on X as a storefront for discovering, comparing, and using x402 services. The marketplace is designed to give both humans and their AI agents access to a wide range of tools—from data feeds to consumer apps—without the friction of managing API credentials. A storefront for discovering, comparing, and using x402 services. Thousands of services. Zero API keys. Powered by x402. Prince added that the market offers a web interface for humans to browse and assess services, alongside a programming layer that lets AI agents autonomously search, filter, and integra...