Revolut Denies Direct Contact with Hackers Demanding $3 Million Ransom
Revolut has denied receiving direct contact from hackers demanding a $3 million ransom in Monero (XMR) following a customer data breach. A group calling itself 'IAmNotAVillain' made the demand, but Revolut says it has not received any direct messages or communication from the individuals behind those claims.
A rival claimant, 'Revolut Smilik', previously circulated a far larger Bitcoin (BTC) demand of 10,000 units, worth around $780 million at the time, widening uncertainty over who controls the stolen data. The competing ransom claims muddy attribution and make it difficult for outside observers to confidently map which group is operating the extortion pipeline.
Revolut's statement that it has not received any direct contact suggests the company cannot yet validate that the public demand corresponds to a party willing or able to engage with the organization privately, affecting customer-impact assessments and remediation efforts. Italian investigators are broadening their probe because the suspected intrusion involves an alleged compromise or cloning of a government email account.
The regulator is separately examining whether other banks or financial institutions may have been affected, implying that the breach method may not have been isolated to Revolut's environment. The official inquiry remains a key reference point for what investigators can substantiate about the intrusion path and how it affects customers and markets.