Revolut says an impersonation scam led it to disclose sensitive customer data to an unauthorized party; it says its core infrastructure, databases, customer accounts, and funds were not hacked. A group calling itself “iamnotavillain” publicly threatened to sell records unless it received $3 million, reportedly 6,000...
Published byEdited with GPT-5.6 TerraImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: What is currently known about the alleged Revolut data breach—including the company’s statement that it has received no direct contact or ra. Article summary: Revolut has confirmed a limited customer-data disclosure caused by an impersonation/social-engineering incident, but it disputes that its core systems were breached. The ransom claim is public and attributed to a group c. Topic tags: general, news, general web. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers
Revolut has confirmed that sensitive customer information was disclosed to an unauthorized third party after the company received fraudulent requests sent from a legitimate government-agency email domain. The company characterizes the event as an external impersonation or social-engineering scam—not a confirmed compromise of its core systems. 1
2
The incident has also prompted a public ransom claim by a group using the name “iamnotavillain.” But a central caveat matters: Revolut told Reuters that it had received no direct contact or ransom demand from the people claiming responsibility. 2
According to Revolut’s statement reported by Reuters, fraudsters used a legitimate government-agency email domain to submit deceptive requests for customer information. Revolut then disclosed sensitive information to an unauthorized third party before detecting the fraud. 1
Revolut said affected customers had been notified and initially described the number as “very limited.” Reuters later reported that the incident was understood to involve about 680 customers, though that figure was not disclosed by Revolut in its initial public statement. 1
2
Reporting based on notifications to affected customers indicates that exposed information could include identity and contact data, such as dates of birth, addresses, phone numbers, and copies of identity documents. TechCrunch reported that the information may also have included verification selfies, account statements, and other account-related material. 5
Based on Revolut’s account and reporting from a source familiar with the matter, Revolut’s core infrastructure, databases, and customer accounts were not hacked. Revolut also said its systems and customer funds were unaffected. 1
2
That distinction is important. The confirmed event was a data disclosure induced by fraudulent requests, rather than a confirmed technical intrusion into Revolut’s account systems or databases. Public reporting does not independently establish every technical detail of the incident, so the full scope should not be overstated. 1
2
The Financial Times reported that the actors claiming responsibility threatened to sell confidential records of hundreds of Revolut customers to criminal groups unless the company paid $3 million within 24 hours, according to Reuters. 2
Other reports identify the requested payment as 6,000 Monero (XMR), valued at roughly $3 million at the time, and name the purported actor as “iamnotavillain.” The group reportedly posted its ultimatum online alongside a countdown clock and said negotiations had not occurred. 4
6
These details are claims made by, or attributed to, the alleged attackers. They do not establish that the group’s identity is genuine, that it possesses all the records it claims to have, or that it could carry out the threatened sale. Revolut’s statement that it received no direct demand adds further uncertainty about the status of the public ultimatum. 2
6
The available evidence supports a narrower but serious conclusion: Revolut disclosed sensitive customer data after being deceived by fraudulent requests that appeared to originate from a legitimate government email domain. Revolut disputes that its core infrastructure or customer accounts were breached. 1
2
The $3 million Monero demand, 24-hour deadline, countdown clock, and “iamnotavillain” attribution are publicly reported but remain allegations tied to the purported attackers. Until those claims are independently corroborated, they should be treated separately from the disclosure Revolut has confirmed. 2
6
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Revolut says an impersonation scam led it to disclose sensitive customer data to an unauthorized party; it says its core infrastructure, databases, customer accounts, and funds were not hacked.
Revolut says an impersonation scam led it to disclose sensitive customer data to an unauthorized party; it says its core infrastructure, databases, customer accounts, and funds were not hacked. A group calling itself “iamnotavillain” publicly threatened to sell records unless it received $3 million, reportedly 6,000 Monero, within 24 hours.
The confirmed incident is an unauthorized disclosure following fraudulent information requests.