Revolut says no direct contact after $3 million ransom demand
IN SHORTRevolut stated on Thursday it had not received direct contact from any party claiming responsibility for a recent customer data breach, despite multiple public ransom demands. One group, "IAmNotAVillain," publicly demanded 6,000 Monero, valued at approximately $3 million, threatening to sell customer records.
Key Numbers
6,000Monero demanded by "IAmNotAVillain"
$3 millionvalue of Monero ransom demand
10,000Bitcoin demanded by a rival claimant
$780 millionvalue of Bitcoin ransom demand at the time
Who's Involved
Revolut
stated it has received no direct contact regarding ransom demands
IAmNotAVillain
publicly demanded 6,000 Monero from Revolut
Italian authorities
widened their investigation into the data breach
↳ Why This Matters
The conflicting claims and lack of direct contact from breach perpetrators create uncertainty for Revolut and its customers, potentially impacting the company's reputation and operational security as authorities investigate the incident.
Key facts
- Revolut has not received direct contact from individuals claiming responsibility for a customer data breach.
- A group calling itself "IAmNotAVillain" publicly demanded 6,000 Monero (XMR), worth about $3 million, from Revolut.
- The group "IAmNotAVillain" threatened to sell customer records to other criminal groups.
Revolut confirmed on Thursday that it has not been contacted directly by any party claiming responsibility for a recent customer data breach, despite multiple public ransom demands. A group identifying as "IAmNotAVillain" publicly demanded 6,000 Monero (XMR), valued at approximately $3 million, within 24 hours, threatening to sell the stolen customer records to other criminal entities, according to the Financial Times.
A Revolut spokesperson stated, "Revolut has not received any direct contact or demand from the individuals or group making these claims." This statement adds to the confusion surrounding the breach, as "IAmNotAVillain" is not the only entity claiming responsibility. An earlier group had reportedly demanded 10,000 Bitcoin, worth about $780 million at the time of their demand, significantly more than the current Monero request. "IAmNotAVillain" disputed this competing claim, suggesting a former associate had only a small data sample and was falsely taking credit.
Further complicating the situation, cybersecurity accounts have flagged other websites associated with different actors claiming responsibility for the incident. Meanwhile, Italian authorities, including the National Anti-Mafia and Anti-Terrorism Directorate, have expanded their investigation into the breach, which allegedly involved the misuse of a government email account. Prosecutors are examining whether the institutional email account was compromised or cloned, and Italy's privacy regulator has urged banks to review their access system security.