Revolut Data Leak: How Fake Italian Police Emails Exposed Crypto Holders
The Revolut data leak wasn't a hack. How fake law enforcement requests exposed crypto holders' KYC data, and why iamnotavillain's ransom fell 99.6%. (148 characters)

The page below was up on a clearnet domain for roughly a day before it went dark. It had a countdown, a Monero address, a price, and a line saying blood would be on somebody's hands.

iamnotavillain leak site, captured 16 September 2026 before takedown
The demand on that page is 6,000 XMR, around $3 million. Two days earlier the same group wanted 10,000 Bitcoin.
Chain of events
Before 12 September: For months, Revolut received requests for customer records from a mailbox on PEC, Italy's certified email system, which carries legal weight in Italian administrative practice. The mailbox was tied to the Ministry of the Interior. The requests weren't bulk. Each one named specific individuals, and all of them held cryptocurrency.
12 September: Revolut notified affected customers. It said an unauthorised third party had used a legitimate government agency domain to submit fraudulent information requests, that its systems weren't breached, and that customer funds weren't affected. As far as we can tell, all three claims hold up.
14 September: A group calling itself iamnotavillain started posting identity documents and verification selfies to public Telegram groups. It demanded 10,000 BTC (about $780 million) and promised to release more data every day until Revolut paid.
15–16 September: iamnotavillain[.]xyz appeared on the clearnet and was taken down shortly after. The group moved to a replacement domain (the one pictured), with a countdown and pages titled Notice, Warning, Jurisdiction, Press and Contact. The demand fell to 6,000 XMR, the deadline shrank to 24 hours, and the threat shifted from publishing the data to selling it.
What failed
No systems were compromised. The emails passed SPF, DKIM and DMARC because they really were sent from the domain they claimed to come from. Revolut's disclosure team got what looked like lawful requests from an Italian government mailbox and processed them, which is what that team is there to do.
The PEC detail is important. Because it's a certified channel with legal standing, a request sent through it gets treated with more authority than ordinary email would. The attacker didn't have to get around that trust; they used it.
The length of time is also significant. This wasn't one bad request slipping through. The attacker kept a disclosure process going for months, asking for people they'd already chosen, which suggests the target list existed before they had access to the mailbox.
The drop in the demand
Going from $780 million to $3 million in under 48 hours is a 99.6% cut. Groups with real leverage don't usually back down that fast.
Our read is that the 10,000 BTC figure was mainly there to generate headlines, and it did. The 6,000 XMR figure looks closer to what the group actually expects to get. The switch to Monero supports that: it's far harder to trace than Bitcoin, and that only matters if you think someone might pay.
The move from publishing to selling may say more than the number does. Leaking data to pressure a company and selling it on to other criminals are different operations with different goals.
What we've seen in our collection
On 13 September, the day after Revolut's notification, an account on one of the forums we monitor posted a thread titled "GOV emails leak | FREE | mail:pass," sharing government mailbox credentials in bulk at no cost. The post body just said "Yo. Don't cry, gov."
Earlier, on 5 May, we recorded a listing for 32,000 Italian public administration email contacts. We have no evidence linking it to the mailbox used against Revolut. It does show that Italian government email addresses were being collected and traded months before the requests started.
This kind of supply is routine. The same two vendors posted new SMTP credential dumps on 9, 11 and 14 September, in line with their usual weekly schedule.


Threat actor publishing 32k Italian public administration contacts
Assessment
We think the sale threat is weak, and the group probably knows it. Standard KYC bundles (passport, licence photo, verification selfie) go for a few dollars each on the forums we track. At that rate, 680 sets would bring in a few thousand dollars at most.
What makes this data valuable isn't the documents. Each record ties a verified identity and home address to someone known to hold cryptocurrency. There's no going rate for that, because the people who'd want it aren't buying in bulk. For affected customers, the bigger concern is physical: targeted theft, coercion or home invasion, more than fraud.
For anyone running a law enforcement disclosure desk, domain authentication confirms who sent a message and nothing else. Before releasing records, call the requesting agency on a number you've looked up yourself. It's a cheap check, and it would likely have stopped a scheme that ran for months.