
Reggio Calabria prosecutors investigate cyber extortion involving stolen data of European customers.
Prosecutors in Reggio Calabria are investigating an extortion attempt against Revolut after hackers used a compromised Italian prefecture email to demand a $3 million Monero ransom for stolen customer data affecting 680 Europeans.
AI-generated summary
Hackers compromised an institutional email account to extract data from digital banking platform Revolut and demanded a public ransom.
The public prosecutor's office in Reggio Calabria has opened an investigation into a case involving the banking services company Revolut, founded in London, which is now reportedly being blackmailed.
A group of hackers requested sensitive data from the bank using a compromised institutional email account belonging to the Reggio Calabria prefecture.
The digital bank has confirmed that data belonging to around 680 European customers has been affected, but that their funds have not been touched.
According to the Financial Times, which contacted the cybercriminals via Telegram, the group calls itself "iamnotavillain" and posted on its website on Wednesday afternoon a ransom demand for 3 million dollars, equivalent to 2.61 million euros.
If they do not receive the money within 24 hours, the hackers are threatening to sell the sensitive data to other criminal organisations.
The National Anti-Mafia and Counter-Terrorism Directorate is also working on the case, as it concerns a government body. The cybercrime division of the police says it was a highly sophisticated operation, but several points still need to be clarified.
An unusual ransom demand
The group posted the ransom demand on its site on the dark web. The Financial Times (source in Italian) notes that making such a demand public is unusual; typically, ransom and extortion attempts are made privately at first and only made public if the targets refuse to pay.
In this case, however, the British newspaper received a message demanding that Revolut transfer "6,000 XMR / 3,000,000 $… otherwise all the data will be sold and you will have blood on your hands".
XMR is the ticker symbol for the cryptocurrency Monero, often used in illegal contexts because it is difficult to trace.
The criminal group also told the newspaper that this was the first time it had used its site for a ransom demand and that it had not yet contacted the bank to open negotiations.
After making the ransom demand public, the hackers sent the Financial Times a 60-second screen recording showing an unidentified user scrolling through a collection of documents, possibly belonging to Revolut.
The information contained in the documents taken from Revolut is said to include passport details, driving licence data, other identity documents and photographs. The hackers claim to hold a total of 147 gigabytes of data.
How far the investigation has progressed
Prosecutors are considering the offence of intrusion into an IT system of public interest. An initial report from the cybercrime police indicates that the operation, which lasted for months, was highly sophisticated, and it is still not certain whether a computer at the Reggio Calabria prefecture or at Italy's Interior Ministry was compromised.
Experts are also trying to establish whether the institutional email account from which the requests originated was infiltrated or cloned.
Alongside the national Anti-Mafia and Counter-Terrorism Prosecutor's Office, the Italian data protection authority has also stepped in, immediately launching checks for possible security breaches at Italian banks and urging data-protection officers to carry out a "prompt review" and, if any vulnerabilities are found, to notify the authority immediately.
The Italian privacy watchdog has also contacted its counterpart in Lithuania, where Revolut's registered office is located, starting an exchange of information to strengthen efforts to counter the threat.
The investigation will determine how the offence was carried out and whether other public bodies were also affected.

U.S. prosecutors charged five individuals linked to Russian intelligence with conspiracy to finance terrorism and murder for hire, targeting dissidents and European infrastructure.

Alex Saab, a close ally of Venezuela's Nicolás Maduro, is set to plead guilty on Tuesday in Miami to money laundering tied to a scheme bribing officials for food import contracts during Venezuela's economic crisis. Deported by Venezuela in May under US pressure, Saab faces charges related to fake companies and falsified records to skim government funds. His prosecution follows a controversial 2023 pardon by President Biden and comes as the Trump administration seeks new oil deals with Venezuela.

Cologne police released bodycam footage of the arrest of Daniel V., a suspect in power infrastructure sabotage. Authorities found over 40 devices and a notebook detailing 160 potential targets, prompting investigations into possible foreign state involvement.

TV presenter Sarah Khalifa and 11 others are set to appeal their death sentences for synthetic drug trafficking. The case involves the classification of MDMB-4en-PINACA and follows recent changes to Egypt's criminal procedure allowing for a full appeal stage.

Egyptian TV host Sarah Khalifa and 11 others were sentenced to death for operating a synthetic drug network. Prosecutors alleged Khalifa financed the operation and acted as a coordinator. Her legal team plans to appeal the verdict through Egypt's higher courts.

TV presenter Sarah Khalifa and 11 others received death sentences in Cairo for drug manufacturing, trafficking, and illegal arms possession. The court also sentenced the group to five years for a separate abduction and assault case. The ruling remains subject to appeal.