Hackers breached Revolut through a compromised Italian government email account and are demanding $3 million in Monero for the return of identity documents belonging to roughly 680 European customers, a case that has drawn Italy’s anti-mafia directorate and two national data regulators into a cross-border investigation.
The breach vector
Prosecutors in Reggio Calabria say the attackers used a certified institutional email account belonging to the local prefecture to request sensitive data from the London-founded digital bank. The operation lasted months, according to the cybercrime division, though it remains unclear whether the prefecture’s own systems or those of the Interior Ministry were infiltrated, or whether the account was cloned rather than hacked. Revolut confirmed the data loss but said customer funds were not affected.
The ransom demand
The group calling itself “iamnotavillain” posted a public demand on its dark-web site Wednesday for 6,000 XMR, the ticker for Monero, valued at $3 million or €2.61 million, with a 24-hour deadline. The Financial Times, which communicated with the hackers via Telegram, received a 60-second screen recording showing an unidentified user scrolling through what appear to be Revolut documents, passports, driving licences, other identity papers and photographs, totalling a claimed 147 gigabytes. Public ransom demands are unusual; extortion typically begins privately and goes public only after a refusal to pay.
The regulatory response
Italy’s National Anti-Mafia and Counter-Terrorism Directorate has joined the inquiry, which is being framed as intrusion into an IT system of public interest. The Italian data protection authority has ordered immediate security reviews at Italian banks and opened an information exchange with its Lithuanian counterpart, where Revolut holds its registered office, to coordinate containment efforts.
What to watch next
The investigation will determine whether other public bodies were compromised through the same channel and whether the email account was infiltrated or merely spoofed. Revolut has not stated whether it intends to negotiate; the hackers told the Financial Times they had not yet contacted the bank directly. With a 24-hour clock that began Wednesday, the next moves will test whether the public demand was bluster or a genuine escalation.
