Hackers stole personal data from roughly 680 European Revolut customers and posted a $3 million ransom demand on the dark web Wednesday, marking an unusual public escalation before any private negotiation with the London-based fintech. The group, calling itself "iamnotavillain," claims to hold 147 gigabytes of passport details, driving licences, identity documents and photographs, and gave the company 24 hours to pay in Monero, a cryptocurrency favoured for its opacity, before selling the trove to other criminal outfits.

The entry point was a government inbox

Prosecutors in Reggio Calabria opened an investigation after the attackers used a compromised institutional email account belonging to the local prefecture to request sensitive data from the bank. Italy's National Anti-Mafia and Counter-Terrorism Directorate joined the case because a public body was breached, and the cybercrime unit described a months-long operation of high sophistication. Investigators have not yet determined whether the intrusion originated at the prefecture or at the Interior Ministry, nor whether the email account was infiltrated or merely cloned.

An atypical playbook

The Financial Times, which communicated with the gang via Telegram, noted that publishing a ransom demand before contacting the victim departs from standard extortion practice, where threats typically stay private until talks collapse. The hackers told the newspaper this was their first time using their site for such a demand and that they had not yet approached Revolut. They also supplied a 60-second screen recording showing an unidentified user scrolling through what appeared to be internal documents.

Regulators move on two fronts

Italy's data protection authority immediately ordered checks across Italian banks and told data-protection officers to conduct a prompt review, notifying the watchdog of any vulnerabilities. The authority also opened a channel with its Lithuanian counterpart, Revolut's registered office sits in Vilnius, to coordinate containment. Revolut confirmed the breach affected European customers but said no funds were touched. The investigation will now establish how the offence was executed and whether other public bodies were compromised.