No Direct Contact Despite Public Ransom Ultimatums

Fintech platform Revolut announced on Thursday that it has not received any direct communication or ransom demand from the individuals or groups publicly claiming responsibility for a customer data breach, despite several high-profile ultimatums circulating online.

According to a report from the Financial Times on Wednesday, a collective operating under the handle "IAmNotAVillain" issued a 24-hour deadline to Revolut, demanding 6,000 Monero (XMR) — valued at approximately $3 million at the time — in exchange for not releasing or selling the stolen customer records to other criminal organizations.

"Revolut has not received any direct contact or demand from the individuals or group making these claims," a company spokesperson confirmed to Cointelegraph. The statement underscores a significant gap between the public posturing of the alleged actors and any actual engagement with the firm.

Multiple Competing Claims Cloud the Picture

The situation is further complicated by the fact that IAmNotAVillain is not the sole entity asserting ownership of the compromised data. An earlier group identifying as "Revolut Smilik" reportedly demanded 10,000 Bitcoin, a sum worth roughly $780 million when the claim surfaced — a figure dramatically higher than the $3 million Monero ultimatum now on the table.

In a notice posted on its own website, IAmNotAVillain pushed back against the rival group's assertion, alleging that a former associate had obtained only a small sample of the data before publicly claiming full credit for the breach. The site also issued a warning to others, advising them not to engage with the competing claimant.

Cybersecurity-focused outlet Dark Web Informer additionally flagged a third domain, revoloot.lol, linked to yet another actor asserting responsibility for the incident. Both the IAmNotAVillain site (iamnotavillain.xyz) and the revoloot.lol domain were inaccessible when checked by Cointelegraph at the time of publication.

The proliferation of competing claims raises serious questions about who, if anyone, actually holds the full dataset and whether the various actors are operating independently or as part of a coordinated scheme.

Italian Authorities Widen Scope of Investigation

The breach, first disclosed by Revolut last week, has now drawn the attention of Italy's National Anti-Mafia and Anti-Terrorism Directorate, as the alleged intrusion involves a government entity, Italian news agency ANSA reported on Wednesday.

Prosecutors in Reggio Calabria have launched an inquiry into unauthorized access to a computer system of public interest. Investigators are working to determine whether a government email account was directly breached or merely cloned to gain access to customer records.

Separately, Italy's data-protection regulator has urged banks to conduct an urgent review of their access-control systems and is assessing whether additional banks or financial institutions may have been affected by the same intrusion.

Scam-Alert Implications for Traders and Customers

From a risk-management perspective, the current scenario presents several red flags that traders and Revolut customers should note. First, the existence of multiple competing ransom claims increases the likelihood of follow-on phishing and social-engineering campaigns, as bad actors may attempt to exploit the confusion to impersonate legitimate parties or lure victims into fraudulent transactions.

Second, the threat to sell the stolen records to other criminal groups means that the data could fragment across the underground ecosystem, broadening the pool of actors capable of deploying it for targeted fraud, identity theft, or account-takeover attacks.

Third, the fact that a government-linked email account is at the center of the alleged intrusion suggests that the initial compromise may have been more sophisticated than a simple credential-stuffing attack, warranting heightened vigilance around any unsolicited communication referencing Revolut, data privacy, or account verification.

Customers and traders are advised to enable multi-factor authentication, monitor account activity closely, and treat any email or message demanding action related to the breach with extreme skepticism until verified through official Revolut channels.