Hackers, operating under the pseudonym "iamnotavillain," are demanding a $3 million ransom from Revolut following a data breach that exposed confidential information for approximately 680 customers. The perpetrators claim they gained access to this data by compromising an Italian government email system (La Posta Elettronica Certificata or PEC) and then posing as law enforcement to request customer details from Revolut over several months. The hackers targeted individuals identified as "crypto whales" through on-chain analysis, with most affected customers residing in Switzerland and France, alongside others in 31 European countries including the UK, Germany, and Spain.

Revolut has stated that its own systems and databases were not breached and that the incident involved the fraudulent misuse of an official, state-regulated legal communication channel. The digital bank, which boasts over 80 million customers globally, has confirmed it received fraudulent requests from a legitimate government agency email domain. The compromised data includes sensitive information such as customers' addresses, phone numbers, transaction histories, identity documents, and facial verification images.

While Revolut has not publicly commented on the ransom demand, a source familiar with the situation indicated the company had not yet been contacted by the perpetrators regarding a ransom. This incident has raised concerns, with Italian lawmaker Giulia Pastorella calling for immediate clarification from the interior ministry regarding the compromised PEC email account, emphasizing the "alarming" nature of the security breach and questioning its potential broader implications. Revolut had previously valued itself at $115 billion in a secondary share sale earlier this year.