The threat actor known as IAmNotAVillain has issued a fresh demand and a countdown clock, a sharp climbdown from the 10,000 Bitcoin figure that circulated on Telegram over the weekend, with researchers tracking the leak site pointing to Monero as the requested payment.
Hackers behind the September customer-data disclosure at British fintech Revolut have issued a new ransom demand of about $3 million (reported as 6,000 XMR), payable within 24 hours, or the confidential records of hundreds of customers will be sold to other criminal groups.
The fresh figure marks a steep reduction from the 10,000 Bitcoin (BTC) headline that circulated on Telegram over the weekend, and researchers tracking the leak site say the payment is being sought in Monero (XMR), a privacy-focused cryptocurrency built to obscure sender, receiver and transaction amount.
The Financial Times (FT) reported on Wednesday that the operators behind the breach threatened to sell the records of hundreds of customers to other criminal groups unless the London-based fintech pays the ransom inside the 24-hour window. A person familiar with the matter told the FT, in reporting republished by the Irish Times, that Revolut had not been contacted by the perpetrators and was yet to receive a ransom demand through a negotiated channel, a distinction that can sit alongside a public countdown on the actor’s own leak site.
What Changed on Wednesday
The Crypto Times previously reported that Revolut’s compliance team accepted a fraudulent information request sent from an authenticated government mailbox. Revolut first notified affected customers on 12 September 2026; the company and later reporting say the impersonation emails ran for months before that date, exposing identity documents, passport and driving licence copies, verification selfies, contact details, International Bank Account Numbers (IBANs), account statements, withdrawal records and full transaction histories including Bitcoin activity.
What is new on 16 September 2026 is the size, speed and payment vehicle of the demand: smaller in dollar terms, faster in deadline and denominated in a privacy coin rather than Bitcoin.
The change of payment rail is not incidental. Bitcoin is transparent on-chain, and every investigator watching this file, from Britain’s data-protection regulator to European law-enforcement units, would follow a 10,000 BTC payment across exchanges within hours. Monero is designed to defeat that tracking, which is why the request now sits there.
Who The Actor Is And What It Has Said
The demand is attributed to a threat actor operating under the handle IAmNotAVillain, whose clearnet site iamnotavillain.xyz appeared earlier this week before being taken down, according to researchers monitoring the case. Infrastructure was quickly restored on a replacement domain carrying a countdown timer.
In messages sent, the group claimed the operation ran for months from Italy and used a compromised government mailbox to target “crypto whales,” selected through on-chain analysis of Revolut accounts with significant crypto holdings. Most of the 680 sit in Switzerland and France, with the rest spread across 31 other mainly European countries including the United Kingdom, Germany and Spain, according to the actor’s messages to the FT. Those country shares have not been independently confirmed by Revolut.
Italian outlets reporting the same Wednesday demand also say the actor claims to hold about 147 GB of Italian law-enforcement files. That claim is unverified; Italian authorities have not confirmed a breach of police systems.
Readers who saw the story over the weekend may recall a demand of 10,000 BTC, roughly $780 million at mid-September prices. That figure was tied to a competing brand calling itself Revolut Smilik. IAmNotAVillain has since said an impersonator who was given a data sample is falsely taking credit for the wider breach. Until Revolut or a regulator confirms otherwise, both the 10,000 BTC and $3 million figures remain threat-actor speech; only the underlying disclosure is a company fact.
The Regulatory Track
The United Kingdom’s Information Commissioner’s Office (ICO) said it had received a report and was assessing it, and the Financial Conduct Authority (FCA) said it was engaging with the firm. As The Crypto Times reported on 15 September 2026, the 680 total includes 12 customers in Ireland, 25 in Spain and 27 in Romania on the national slices then on the record, drawn from reporting by RTÉ, El Español and Profit.ro.
Revolut Bank UAB in Lithuania remains the European banking entity supervised by the European Central Bank (ECB) and the Bank of Lithuania, and is the legal-request desk that matters in this case rather than the consumer app.
The Italian Angle
Revolut has not named the identity of the impersonated agency. Italian coverage and the FT’s own reporting point to Italy’s La Posta Elettronica Certificata (PEC) system, the government-overseen certified-email network used for official correspondence, with the specific mailbox tied to Italy’s Ministry of Interior. Some Italian reporting has named a Reggio Calabria prefecture PEC address; Revolut has not confirmed the mailbox.
Italian postal police, state police, the interior ministry and the national cybersecurity agency all declined to comment on the record, although officials confirmed to the FT that investigations were under way. Italian opposition lawmaker Giulia Pastorella has asked the interior ministry for an explanation.
What Is At Stake For The 680
The bundle in circulation pairs passport and driving-licence copies with verification selfies, IBANs, statements and full Bitcoin transaction histories. That combination gives an attacker a legal name, a face, a recovery path and a chain-analysis starting point, a materially different object from a standard email-and-password dump.
No private keys, card personal identification numbers (PINs) or account balances were listed in Revolut’s notice, and no customer-fund theft has been reported. The residual risk lies in targeted extortion of the 680 and account-recovery social engineering, not a run on the app.
What Revolut Has Said
Revolut said that it had identified a “sophisticated external impersonation scam” in which an unauthorised third party used a mailbox on a legitimate government agency domain to submit fraudulent requests for information.
The messages passed Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM) and Domain-based Message Authentication, Reporting and Conformance (DMARC) checks, so compliance staff processed them as they would a routine legal demand. The company then blocked the address, alerted the impersonated agency, and notified law enforcement, data-protection authorities and financial regulators. Revolut has said its systems and customer funds were unaffected.
This is a developing story. The next facts that would move it are a public Revolut response to the $3 million demand, a named agency from London or Rome, or a regulator filing that treats the legal-request desk as the control failure rather than the mailbox as an isolated curiosity.
Also Read: Blockaid Flags FlamingoFinance Contract Exploit, $345.9K Stolen
