Revolut reports data exposure affecting 680 customers amid competing ransom demands.

On-chain investigator ZachXBT said the incident appeared to target high-net-worth customers and was likely limited in size.
The IAmNotAVillain group said it had not previously used its website to make ransom demands and told the Financial Times that no negotiations with Revolut had taken place.
IAmNotAVillain disputed the rival “Revolut Smilik” claim, alleging that a former associate had obtained only a small sample of the data before claiming responsibility and warning others not to engage with that claimant.
The website associated with IAmNotAVillain was unavailable when Cointelegraph checked it, while cybersecurity account Dark Web Informer linked a separate claim to revoloot.lol; that site was also unavailable when checked.
Digital bank Revolut confirmed that about 680 customers had their sensitive data exposed after attackers exploited a fraudulent request sent from a legitimate government email domain Crowdfund Insider. The exposed records include identity documents, contact details, IBANs, account information and Bitcoin transaction histories. However, Revolut said it has received no direct ransom demand despite a group called IAmNotAVillain publicly claiming responsibility and demanding $3 million in Monero within 24 hours CryptoBriefing.
Multiple groups are making competing claims about the breach, creating uncertainty over who actually accessed the customer data. IAmNotAVillain demanded $3 million in cryptocurrency, while another actor using the name "Revolut Smilik" made far larger claims Startup Fortune. IAmNotAVillain told the Financial Times that no negotiations with Revolut had taken place and disputed the rival claim, alleging that a former associate obtained only a small sample of data.
Revolut emphasized that its core infrastructure, customer accounts and funds were not compromised Insurance Journal. The company said it blocked the fraudulent email address, notified authorities and regulators, and contacted all affected customers directly. Italian authorities are now investigating how the government email account was exploited to send the fraudulent requests that led to the data exposure.
On-chain investigator ZachXBT said the incident appeared to target high-net-worth customers and was likely limited in scope Bitcoin News. Cybersecurity researchers identified multiple websites linked to competing breach claims. The website associated with IAmNotAVillain was unavailable when checked, while a separate site called revoloot.lol was also inaccessible. This suggests some claimants may already be abandoning their public presence.
Publishers
19
Articles
7
Reach
26