Hackers Impersonate Italian Law Enforcement to Extort Revolut Over 680 Customers

A hacking group says it tricked fintech company Revolut into handing over customer data by pretending to be Italian law enforcement, and is now demanding 6,000 monero โ worth roughly 3 million dollars โ to keep the files private.
The group, calling itself iamnotavillain, says it first reached out to Revolut a couple of months ago claiming to represent an Italian law enforcement agency. The messages reportedly went through Italy's La Posta Elettronica Certificata system, known as PEC, a certified email network used by Italian government offices, companies and citizens for official communication.
Because the emails came through a real government channel, they carried valid domain authentication โ giving Revolut no easy way to confirm the sender was not an authorised official.
## How the Scheme Worked
Over several weeks, the hackers say they repeatedly asked Revolut for account details tied to specific customers, and that the company complied, sharing names, addresses, phone numbers and transaction histories.
The targets were not chosen randomly. The group says it used onchain analysis to find Revolut users with large crypto holdings, describing them as "whales."
According to reporting from the Financial Times, 680 customer accounts were affected. Most of those customers are based in Switzerland and France, though people in 31 other countries were also impacted, including the UK, Germany and Spain.
The data allegedly obtained includes passports, selfies used for identity checks, account IDs and records of crypto deposits and withdrawals. Fiat transfers were reportedly included too.
## The Ransom Countdown
The extortion demand escalated through an unusual sequence. The hackers first floated a demand for 10,000 bitcoin on Telegram, then said that figure came from an impersonator rather than the group itself.
On September 16, iamnotavillain posted a new demand on a website using the group's name: 6,000 monero within 24 hours, or the files would be sold to other criminal groups. Monero is a cryptocurrency built to hide transaction details, unlike bitcoin, which is traceable on a public ledger โ making it a common choice for extortion demands.
Revolut has said it had not received a direct ransom demand from the group as of when the countdown appeared, and says its core systems, databases and customer funds were never breached.
In a statement, the company said the incident involved "the fraudulent misuse of an official, state-regulated legal communication channel to impersonate legitimate authority requests." Revolut says it identified the scam, blocked the address involved and notified law enforcement and regulators.
## A Government Channel Under Investigation
Italian officials, including the postal police and the interior ministry, have confirmed an investigation is underway but declined further comment. Opposition lawmaker Giulia Pastorella called the breach of a government email account "alarming" and said she plans to raise the issue in parliament.
The case exposes a vulnerability that no amount of endpoint security at the victim company could have patched: when attackers operate through a genuine, state-regulated communication channel, the authentication signals companies rely on to verify lawful requests point the wrong way. Revolut first disclosed the incident on September 12, and the investigation into how the government email system was compromised remains ongoing.
The PEC system occupies a privileged position in Italian digital life: messages sent through it carry legal validity comparable to registered mail, which is precisely why its domain authentication made the fraudulent requests so difficult to challenge. Law-enforcement data requests are among the few categories of disclosure that companies process under strict confidentiality obligations, meaning affected customers had no way to learn their data had been handed over until the extortion posts surfaced. Regulators in the UK and Lithuania, where Revolut holds banking licences, are understood to have been notified alongside Italian authorities, though none has announced formal enforcement action while the facts are still being established.
For the crypto industry, the targeting method is as significant as the breach itself. By selecting victims through onchain analysis rather than indiscriminate harvesting, the group demonstrated that public blockchain records can convert a compliance process into a target list โ turning legitimate data-request procedures into the attack surface, and leaving firms to balance legal compliance against a fraud vector that arrives wearing the credentials of the state itself.
The 24-hour deadline attached to the monero demand added a second pressure mechanism: by threatening to sell the files to other criminal groups rather than simply leak them, the group priced continued silence in a way that could outlast the news cycle. Whether the deadline produced any payment is unknown, and Revolut's public position โ no direct demand received โ leaves the confrontation at a standoff. What is documented is the method: a certified government email channel, weeks of patience, a curated victim list built from blockchain records, and a data set intimate enough that 3 million dollars was the group's opening arithmetic for keeping it quiet.
Discussion
Recommended for you
More technology
Cybersecurity
CenterPoint Energy Confirms Customer Data Stolen as Hacker Claims 7.49 Million Records in Utility Breach
9/17/2026
Cybersecurity
Hackers Exploit VPN Flaw to Breach Japan's Digital Agency and Access 240,000 People's Data
9/16/2026
Cybersecurity
Global Ransomware Attacks Hit Record 997 in August as Utilities Surge
9/16/2026
Cybersecurity