Hackers Demand $3M in Monero After Fraudulent Requests Hit Revolut via Italian Gov Email System
A hacking group calling itself 'iamnotavillain' has publicly demanded 6,000 Monero — worth approximately $3 million — from Revolut after claiming to hold data on around 680 customers across 31 countries. Revolut says its own systems and customer funds were not compromised but confirmed it blocked a fraudulent channel using a legitimate government agency email domain.

The exploitation of Italy's PEC certified government email infrastructure to submit fraudulent data requests to a regulated financial firm exposes a systemic verification risk for institutions that rely on trusted institutional communications channels.
Hackers Demand $3 Million in Monero After Revolut Customer Data Obtained Via Italian Government Email System
A hacking group calling itself "iamnotavillain" has publicly demanded 6,000 Monero — equivalent to approximately $3 million — from Revolut, threatening to sell customer data to other criminal organisations if the ransom is not paid within 24 hours. Revolut confirmed on 12 September 2026 that fraudulent requests for customer information had been submitted using a legitimate government agency email domain, but stated its own systems and customer funds were not compromised.
What Happened
According to reporting corroborated across multiple primary sources — including OCCRP, HTX/Cointelegraph, and ETCISO/Reuters — the group "iamnotavillain" posted its demand publicly rather than contacting Revolut directly. Revolut confirmed it received no direct contact or ransom demand from the individuals or group making the claims.
The neobank said it discovered fraudulent requests for customer data had been submitted via what appeared to be a legitimate government agency email domain. Upon identifying the fraudulent channel, Revolut said it blocked it. The company maintains that its own infrastructure and customer funds were not compromised as a result.
The group claims to hold files on approximately 680 Revolut customers across 31 countries. Compromised data could include names, dates of birth, home addresses and email addresses, according to OCCRP.
The Italian Government Email Connection
Italian authorities have widened their investigation into the breach, with suspicion focused on unauthorised access to Italy's PEC certified email system — a government-backed secure email infrastructure. This connection is corroborated across multiple primary sources, including HTX/Cointelegraph, HackMag and Blockonomi. The exploitation of a trusted institutional email channel to submit fraudulent data requests to a financial firm represents a significant operational security concern for regulated entities that rely on government communications as a verification mechanism.
Italy's privacy regulator has instructed banks to review their security systems following the incident. No confirmed public statement from other national regulators has been identified in the verified research package.
Why Monero
The group specified Monero (XMR) as its demanded cryptocurrency. Monero is a privacy-focused digital asset designed to obscure transaction details, including sender, recipient and amounts, making blockchain tracing substantially more difficult than with transparent-ledger cryptocurrencies. The choice is consistent with ransom demands where actors seek to reduce the risk of fund recovery or attribution, analysts note.
Revolut acknowledged that fraudulent requests for customer information were submitted via what appeared to be a legitimate government agency email domain, and said it had blocked that channel after discovering the fraud.
Regulatory Exposure
In regulatory terms, a breach affecting customer personal data across multiple jurisdictions carries notification obligations under applicable data protection frameworks. Italy's privacy regulator has already acted, directing banks to assess their own systems. Whether Revolut faces formal regulatory investigation from other national authorities has not been confirmed in the verified research package.
What Revolut Says
Revolut's position, as reported by OCCRP, HTX/Cointelegraph and ETCISO/Reuters, rests on three points: first, that the breach originated via a fraudulent external request rather than a compromise of its own systems; second, that customer funds were not affected; and third, that the company had no direct contact with the group that subsequently made the public ransom demand. The blocking of the fraudulent email channel is presented by the company as a remediation step already taken.
Significance
The incident is notable for the attack vector used. Rather than breaching Revolut's technical infrastructure, the group — or actors working with it — appears to have exploited the trusted status of a government-certified email system to obtain customer records. Italian authorities' widened investigation into the PEC system suggests the Revolut case may be part of a broader pattern of abuse of institutional email infrastructure, with implications for how financial firms authenticate and act upon government data requests across the European Union.
The Fin Desk Newsroom publishes verified reporting on the developments shaping fintech, payments and modern financial infrastructure.
Related Stories

Coinbase Launches Retail IPO Access, Debuts Feature With Oura Smart-Ring Offering
Coinbase opened IPO-access to eligible U.S. retail customers on 21 September 2026, allowing them to request shares at the final offer price. The first listing available through the feature is Oura, a smart-ring maker that has filed an S-1/A with the SEC.

Adyen Nominates Ex-Klarna CFO Niclas Neglen as Finance Chief from February 2027
Adyen has nominated Niclas Neglen, formerly CFO of Klarna for six years, to lead its finance function and join its statutory Management Board from 1 February 2027, subject to regulatory and shareholder approval.

Revolut Cyberattack Exposed Data of 50,000-Plus Customers; Lithuanian Regulator Opens Inquiry
A targeted cyberattack on Revolut on 11 September 2022 exposed personal data including names and email addresses of more than 50,000 customers before the company contained the intrusion. Lithuania's State Data Protection Inspectorate has formally opened an investigation into the breach.

Checkout.com posts $750M annualised revenue run-rate and returns to profitability
Checkout.com has announced an annualised net revenue run-rate of $750 million for 2026, representing 28% year-on-year growth, alongside a return to full-year profitability. The UK-registered payments processor also disclosed it processed over $300 billion in total payment volume in 2025, a 64% annual increase.
The essential developments in modern finance
The essential developments across fintech, payments and modern finance — delivered to your inbox.
Free. No spam. Unsubscribe anytime.