The Fin Desk Brief
▸Hackers Demand $3M in Monero After Fraudulent Requests Hit Revolut via Italian Gov Email System▸Fed Seeks Comment on Regulatory Framework for Board-Supervised Payment Stablecoin Issuers▸FCA Opens Authorisation Gateway for UK Cryptoasset Firms▸Mastercard Builds Agentic Commerce Infrastructure Across Two-Phase Programme▸SoFi Bank Goes Live With Stablecoin Settlement on Mastercard Network▸Mastercard and Google Pay target biometric card authentication in India via CDCVM▸Thredd Partners Velocity to Layer Stablecoin Settlement onto Card Infrastructure▸Visa Data: Nearly 17% of Stablecoin-Linked Card Volume Flows Through Commercial Programmes▸Coinbase Launches Retail IPO Access, Debuts Feature With Oura Smart-Ring Offering▸Global Payments posts 12% adj. EPS growth in Q4 2024, launches $250m buyback amid Worldpay deal▸Hackers Demand $3M in Monero After Fraudulent Requests Hit Revolut via Italian Gov Email System▸Fed Seeks Comment on Regulatory Framework for Board-Supervised Payment Stablecoin Issuers▸FCA Opens Authorisation Gateway for UK Cryptoasset Firms▸Mastercard Builds Agentic Commerce Infrastructure Across Two-Phase Programme▸SoFi Bank Goes Live With Stablecoin Settlement on Mastercard Network▸Mastercard and Google Pay target biometric card authentication in India via CDCVM▸Thredd Partners Velocity to Layer Stablecoin Settlement onto Card Infrastructure▸Visa Data: Nearly 17% of Stablecoin-Linked Card Volume Flows Through Commercial Programmes▸Coinbase Launches Retail IPO Access, Debuts Feature With Oura Smart-Ring Offering▸Global Payments posts 12% adj. EPS growth in Q4 2024, launches $250m buyback amid Worldpay deal

Hackers Demand $3M in Monero After Fraudulent Requests Hit Revolut via Italian Gov Email System

A hacking group calling itself 'iamnotavillain' has publicly demanded 6,000 Monero — worth approximately $3 million — from Revolut after claiming to hold data on around 680 customers across 31 countries. Revolut says its own systems and customer funds were not compromised but confirmed it blocked a fraudulent channel using a legitimate government agency email domain.

The Fin Desk Newsroom2 October 2026Updated 1h ago3 min read
Hackers Demand $3M in Monero After Fraudulent Requests Hit Revolut via Italian Gov Email System
A dark-toned editorial illustration of a padlock overlaid on Revolut's signature gradient branding, with Monero coin iconography and a countdown timer, evoking digital extortion and data vulnerability.Rafael Minguet Delgado / Pexels
Why this matters

The exploitation of Italy's PEC certified government email infrastructure to submit fraudulent data requests to a regulated financial firm exposes a systemic verification risk for institutions that rely on trusted institutional communications channels.

Hackers Demand $3 Million in Monero After Revolut Customer Data Obtained Via Italian Government Email System

A hacking group calling itself "iamnotavillain" has publicly demanded 6,000 Monero — equivalent to approximately $3 million — from Revolut, threatening to sell customer data to other criminal organisations if the ransom is not paid within 24 hours. Revolut confirmed on 12 September 2026 that fraudulent requests for customer information had been submitted using a legitimate government agency email domain, but stated its own systems and customer funds were not compromised.

What Happened

According to reporting corroborated across multiple primary sources — including OCCRP, HTX/Cointelegraph, and ETCISO/Reuters — the group "iamnotavillain" posted its demand publicly rather than contacting Revolut directly. Revolut confirmed it received no direct contact or ransom demand from the individuals or group making the claims.

The neobank said it discovered fraudulent requests for customer data had been submitted via what appeared to be a legitimate government agency email domain. Upon identifying the fraudulent channel, Revolut said it blocked it. The company maintains that its own infrastructure and customer funds were not compromised as a result.

The group claims to hold files on approximately 680 Revolut customers across 31 countries. Compromised data could include names, dates of birth, home addresses and email addresses, according to OCCRP.

The Italian Government Email Connection

Italian authorities have widened their investigation into the breach, with suspicion focused on unauthorised access to Italy's PEC certified email system — a government-backed secure email infrastructure. This connection is corroborated across multiple primary sources, including HTX/Cointelegraph, HackMag and Blockonomi. The exploitation of a trusted institutional email channel to submit fraudulent data requests to a financial firm represents a significant operational security concern for regulated entities that rely on government communications as a verification mechanism.

Italy's privacy regulator has instructed banks to review their security systems following the incident. No confirmed public statement from other national regulators has been identified in the verified research package.

Why Monero

The group specified Monero (XMR) as its demanded cryptocurrency. Monero is a privacy-focused digital asset designed to obscure transaction details, including sender, recipient and amounts, making blockchain tracing substantially more difficult than with transparent-ledger cryptocurrencies. The choice is consistent with ransom demands where actors seek to reduce the risk of fund recovery or attribution, analysts note.

Revolut acknowledged that fraudulent requests for customer information were submitted via what appeared to be a legitimate government agency email domain, and said it had blocked that channel after discovering the fraud.

Regulatory Exposure

In regulatory terms, a breach affecting customer personal data across multiple jurisdictions carries notification obligations under applicable data protection frameworks. Italy's privacy regulator has already acted, directing banks to assess their own systems. Whether Revolut faces formal regulatory investigation from other national authorities has not been confirmed in the verified research package.

What Revolut Says

Revolut's position, as reported by OCCRP, HTX/Cointelegraph and ETCISO/Reuters, rests on three points: first, that the breach originated via a fraudulent external request rather than a compromise of its own systems; second, that customer funds were not affected; and third, that the company had no direct contact with the group that subsequently made the public ransom demand. The blocking of the fraudulent email channel is presented by the company as a remediation step already taken.

Significance

The incident is notable for the attack vector used. Rather than breaching Revolut's technical infrastructure, the group — or actors working with it — appears to have exploited the trusted status of a government-certified email system to obtain customer records. Italian authorities' widened investigation into the PEC system suggests the Revolut case may be part of a broader pattern of abuse of institutional email infrastructure, with implications for how financial firms authenticate and act upon government data requests across the European Union.

data breachcybersecurityRevolutransomwareGDPRneobank
Companies in this story
About the Author
The Fin Desk Newsroom
Newsroom

The Fin Desk Newsroom publishes verified reporting on the developments shaping fintech, payments and modern financial infrastructure.

Related Stories

The Fin Desk Daily

The essential developments in modern finance

The essential developments across fintech, payments and modern finance — delivered to your inbox.

Free. No spam. Unsubscribe anytime.