
AI-generated summary
Emergency Data Requests (EDRs) allow law enforcement to obtain data quickly in a vital emergency, without a court order.This mechanism is based on verification of the sender, which was circumvented by hackers using a usurped PEC domain from Reggio de Calabria prefecture.
An authentic government email address, an emergency request, and 680 customer files changing hands. Indeed, Revolut admitted to having transmitted personal data to individuals posing as public officials. A group calling itself “iamnotavillain” is now demanding 6,000 XMR, or around $3 million. Revolut, however, denies having received any direct request from him.
The group set a twenty-four hour ultimatum for the British neobank on Wednesday September 16. It has now expired, and there is no indication that a payment has taken place. He claims to have selected his victims using blockchain analysis tools. Objective: target accounts with the largest crypto portfolios.
Key Points
The “iamnotavillain” group demands 6,000 XMR, approximately $3 million; the 24-hour ultimatum, set for September 16, has already been exceeded
Revolut delivered the data of 680 customers via a certified email account (PEC) spoofed from an Italian prefecture
Passports, driving licenses, KYC photos and transaction histories are among the exfiltrated documents
Coinbase had refused a comparable ransom of $20 million in 2025, for an estimated remediation of up to $400 million
Revolut denies any intrusion into its systems and claims not to have received any direct ransom demands
Revolut trapped by false emergency requisition
The attack claimed no software breaches or employee turnover. The hackers exploited the Emergency Data Requests (EDR) mechanism. These requests allow law enforcement to contact the platforms when a life is deemed to be in danger. The system bypasses the judicial mandate by construction: the emergency does not leave time to appear before a judge. So, companies respond within a few hours.
Everything therefore relies on a single safeguard, verification of the sender. This is where Revolut gave in. The messages came from an official domain name belonging to a real government agency. Therefore, the usual check validated the request without batting an eyelid. The documents retrieved form a complete identity file, including passports, driving licenses, KYC photos and transaction histories. KYC refers to the identification imposed on regulated players (Know Your Customer).
The account used belongs to the prefecture of Reggio Calabria, which denies having sent the slightest request. The Italian cybersecurity agency CERT-AGID had already sounded the alarm. It identifies more than 650 incidents linked to misused or fraudulently created PEC accounts since the start of the year. The majority of the 680 affected customers are in Switzerland and France. The rest is spread across 31 other European countries, including the United Kingdom, Germany and Spain.
The process has dragged on for years. Bloomberg had documented in 2022 a series of false EDRs having fooled Apple, Meta, Discord and Snap. The messages came from compromised police mailboxes, then resold on underground forums. Of the more than 80 million customers claimed by Revolut, the hackers affected 680 accounts. This sorting adds value to the operation for the attackers. They claim to have isolated the highest balances by cross-referencing public addresses and known identities. The transparency of registers, valuable for auditing a protocol, also becomes a handicap as soon as an identity is leaked elsewhere.
Ransom in Monero: why the Revolut hackers chose XMR
The ransom initially seemed much steeper. An actor called “Revolut Smilik” had claimed 10,000 BTC, or more than $780 million, according to the Financial Times. iamnotavillain describes this claim as an imposture, based, according to him, on a simple sample of data. He maintains his request at 6,000 XMR.
There is nothing arbitrary about the choice of Monero. Circle signatures, stealth addresses and RingCT hide the sender, recipient and amount of each transfer. In fact, the tracking tools that are used daily by investigators on Bitcoin or Ethereum find no use there. This same property comes at a price. Binance removed XMR from its catalog in 2024, then Kraken did the same for European users. Demand has never weakened.
Paying would only buy a promise of deletion, in a market where exfiltrated bases are recycled indefinitely. Moreover, Coinbase had resolved the question in May 2025. Customer support subcontractors, bribed from abroad, had delivered the information of nearly 70,000 users. The blackmailers demanded $20 million in bitcoins. Brian Armstrong refused and converted the sum into a reward for information leading to the arrest of those responsible. The platform has since estimated its remediation bill between $180 and $400 million.
Wrench attacks: the real risk for exposed customers
The danger goes far beyond phishing. The nominative lists of holders have for years fueled a market for physical aggression, the famous wrench attacks. For example, the leak of Ledger's customer base in 2020 fueled waves of threats for months. France has also experienced a series of kidnappings targeting figures in the industry. David Balland, co-founder of Ledger, paid the price: sequestered then released by the GIGN in January 2025.
Revolut has not reported any theft of funds at this stage and the neobank has not announced any payments. For the 680 customers concerned, the damage lies elsewhere: identity document, address and estimate of assets are already in circulation. However, no amount of password changes make up for this. What remains are the reflexes hammered in for ten years. Keep your keys on a dedicated device, keep your positions quiet, be wary of anyone claiming to be from support. The routine has not changed, but it is worth a reminder for anyone who holds cryptocurrencies.
AI outlook — possibilities, not facts
Revolut will strengthen its emergency request verification (EDR) procedures to prevent further usurpations.
Very likely · Within weeks
The Italian and European authorities will investigate the compromise of the PEC domain in Reggio de Calabria and the group <unk> iamnotavillain <unk>.
Likely · Within months

OpenAI released six reports on September 16 documenting various instances of misalignment in its AI models, ranging from hidden instructions to override rules to hiding errors and stealing API keys.

Circle, the issuer of the stablecoin USDC, has launched Arc, its EVM-enabled layer 1 blockchain dedicated to institutional payments, tokenized assets and finance. Arc uses USDC as fuel for transaction fees, offers sub-second finality via Malachite consensus, and integrates a foreign exchange engine and optional privacy. The move comes as Circle seeks to reduce its reliance on reserve revenue in the face of falling U.S. rates and competition from Tether, Stripe, Google and JPMorgan, which are also rolling out their own payment infrastructures.

The Avalanche blockchain integrates the UAE PASS digital vault in the United Arab Emirates to authenticate documents. At the same time, the network claims a role in the financial market tokenization roadmap in South Korea.

Representatives of the twenty-seven EU member states are meeting on Thursday in Brussels at the AI Council to discuss recent incidents linked to artificial intelligence and international cooperation, in a context of disagreement with Washington on the supervision of advanced models, according to Politico.

More than a hundred participants in the ECDSA.Fail competition reduced the theoretical resources required for one step of Shor's algorithm by 86.1%. Although no real attack is possible today, this work highlights the acceleration of the quantum threat.

Donald Trump accuses Dario Amodei, CEO of Anthropic, of “pretending to be a perfect little angel” by calling for a slowdown in AI, evokes an “unhealthy conspiracy” against artificial intelligence and data centers, and highlights the competition between Bitcoin miners and cloud giants for electricity in the United States.