Hackers changed the ransom amount for Revolut customer data.

The hacker group IAmNotAVillain, which claimed responsibility for the data breach at the British fintech service Revolut, has issued a new ransom demand: 6,000 XMR tokens (Monero) worth approximately $3 million, the Financial Times reports. The attackers are demanding the cryptocurrency transfer within 24 hours, threatening to sell confidential records of hundreds of customers to other criminal groups if the deadline is missed. This marks the hackers' second ultimatum; they initially demanded 10,000 bitcoins. The hack against Revolut was orchestrated from Italy, with the attackers using a compromised government email account to target "whale accounts"—Revolut customers holding large cryptocurrency balances. According to the hackers, the majority of the 680 affected individuals reside in Switzerland and France, with the remainder spread across 31 other countries, primarily in Europe. Italian media report that IAmNotAVillain also obtained approximately 147 GB of files belonging to Italian law enforcement agencies. The stolen data includes copies of passports and driver's licenses, identity verification selfies, account statements, withdrawal records, and full transaction histories, including Bitcoin transactions. According to the FT and Italian media, the compromised account belongs to the Italian PEC (Posta Elettronica Certificata) system—a certified email service used for corporate and government correspondence. Journalists linked the specific compromised account to the Italian Ministry of the Interior; some Italian publications identified it as the email address of the Reggio Calabria Prefecture. This implies that Revolut should not have disclosed customer information to the requesting party, as the request did not originate from a regulatory authority. Italy’s National Cybersecurity Agency (CERT-AGID) had warned as early as June that the PEC system does not guarantee the security of message content; since the beginning of the year, the agency has recorded over 650 instances of unauthorized use of PEC accounts. The attack on Revolut took place on September 12. The company confirmed the breach, stating that attackers used the email account of an unnamed government agency to send a request for confidential information. The messages passed the company's internal compliance checks; employees treated them as a standard, legitimate request and voluntarily handed over the information to the attackers.
