Revolut Traced Breach to Italian Prefecture as Hacker Demands €670M Ransom Following Botched Data Retraction
Italian authorities have traced the fraudulent data demands that duped Revolut to a compromised certified mailbox within the Prefecture of Reggio Calabria. Following leaked emails showing Revolut unsuccessfully asking the impostor to destroy the records, the attacker demanded a €670 million Bitcoin ransom and began publishing customer dossiers on Telegram.
Owen Li
Editor-in-Chief
- Published
- Reading time
- 4 min read
The operational failure that led British neobank Revolut to surrender customer passports and Bitcoin ledgers to an impostor has escalated into an active extortion campaign, with the breach traced to a compromised account inside the Prefecture of Reggio Calabria and the hacker demanding a 10,000 Bitcoin ransom.
Newly leaked correspondence reveals that Revolut compliance personnel belatedly realized they had disclosed records outside Italian jurisdiction and sent a message politely asking the fraudulent "authority" to destroy the files, unaware they were corresponding with an extortionist.
While registrars swiftly took down the attacker’s primary extortion website, the perpetrator has shifted to Telegram, publishing customer dossiers belonging to prominent athletes, executives, and cryptocurrency founders.
The Leaked Retraction: Asking the Hacker to 'Destroy' the Files
Screenshots leaked by the threat actor—operating under the moniker IAmNotAVillain—and verified by Italian investigative outlets document the breakdown in Revolut’s legal verification.

In an email dispatched from Revolut’s official Italian certified address (revolut.italy.pec@legalmail.it) to the compromised government account, Revolut acknowledged it had mistakenly transferred dossiers protected by foreign banking secrecy laws:
"We follow up on the request in question and the documentation we sent on [...] 2026. We hereby kindly request that we proceed with the destruction of all documentation sent in reference to the accounts... It specifies that the aforementioned accounts are subject to a different jurisdiction and, since the information is bound by the requirements of banking secrecy, we should not have provided any information.
If deemed necessary, we invite you to consider the issuance of a formal request by a Lithuanian or Swiss authority... In apologizing for the incident and thanking you for your cooperation, we extend our warmest regards."
Alongside the email, the attacker leaked copies of Revolut Account Confirmation records displaying customers' full names, dates of birth, residential addresses, phone numbers, email addresses, and internal wallet reference numbers.
Infiltration Traced to Reggio Calabria
Italian news agency ANSA and cybersecurity investigators confirmed that the fake inquiries were transmitted from an authentic Posta Elettronica Certificata (PEC) mailbox belonging to the Prefecture of Reggio Calabria (entilocali.prefrc@pec.interno.it), an administrative branch of Italy's Ministry of the Interior. The prefecture confirmed to authorities that it never issued the demands.
Technical investigations indicate the compromise did not require cracking PEC’s underlying encryption. Instead, credentials were harvested by an infostealer malware on a municipal employee’s workstation. The attacker used the authenticated session to serve forged European Investigation Orders on Revolut Bank UAB in Lithuania, maintaining an active, trusted correspondence with compliance staff across several months.
Domain Seizure and the Pivot to Telegram Extortion
On September 13, the attacker launched a dedicated clearinghouse website, iamnotavillain.xyz, registered through GoDaddy, to publicize the stolen data. Within 48 hours, GoDaddy and the .xyz registry operator executed an emergency abuse intervention, placing the domain under serverHold and clientHold to remove it from the global DNS zone.
Following the domain takedown, the attacker migrated the extortion operation to Telegram. As reported by The Register and The Financial Times, the threat actor is demanding 10,000 Bitcoin (roughly €670 million) to delete the material, threatening to publish additional customer records daily until Revolut pays.
The dossiers published on Telegram contain complete KYC onboarding packets—scanned passports, verification selfies, and Bitcoin transaction logs. Among the verified victims are:
- Felix Römer, German cryptocurrency entrepreneur and founder of Gamdom
- Alexander Shevchenko, professional tennis player
- Georges Mikautadze, professional footballer for Villarreal
The hacker separately claims to possess 147 GB of data harvested from Italian government systems, though officials have not confirmed that wider breach.
Criminal and Regulatory Scrutiny
The case has triggered dual proceedings across Europe:
- Criminal Probe in Italy: The Polizia Postale, Italy's specialized cybercrime police, has opened an investigation into unauthorized computer access and fraud. Italian lawmaker Giulia Pastorella has formally questioned the Ministry of the Interior over the compromise of its certified communication systems.
- GDPR Inquiry in the UK: The UK Information Commissioner’s Office (ICO) has opened a formal data-protection investigation into Revolut. The probe is reviewing whether Revolut’s reliance on inbound email headers breached statutory obligations to implement appropriate organizational safeguards before transferring sensitive personal dossiers.
Revolut maintains that its backend infrastructure, servers, and customer funds were not compromised, stating it alerted Italian authorities and blocked the rogue account immediately upon discovering the fraud.
Systemic Risks in Government Data Requests
The incident highlights a critical vulnerability in the handling of Emergency Data Requests (EDRs). Under Italian law, PEC guarantees message transmission and integrity, but it does not authenticate the physical user of an account.
Italy’s cybersecurity agency, CERT-AGID, had already flagged the danger earlier this year, reporting it had handled over 650 compromised PEC accounts in the first half of 2026.
Because financial institutions face statutory deadlines and legal liabilities for resisting official investigations, attackers who breach government inboxes can exploit the legal mandate itself. Tying public blockchain records directly to verified identities and physical home addresses leaves affected crypto holders facing acute risks of targeted extortion and physical violence, demonstrating the broader hazards of processing legal data disclosures over conventional email infrastructure.