Banks, exchanges and fintechs under pressure through fake requests appearing to come from authorities: the Revolut case, the Kraken precedent, the actors involved, public amplification, and the political and regulatory implications.
Authors: Olivia Terragni, Edoardo Faccioli, Luca Stivali, Raffaela Crisci
The analysis was developed as part of the Dark Lab at Red Hot Cyber. The full report can be downloaded below: it examines two concrete cases—the Revolut incident (2026) and the earlier Kraken case (2025)—with the aim of turning attack analysis into an operational defense tool.
The Revolut case confirms that every national identity infrastructure—PEC, SPID, wallets and eIDAS—is an attack surface within a global trust architecture. The EU’s vulnerability is not technical but systemic: a single compromised national channel can expose data and users across the entire European financial space.
In the first days of the incident, the X user @StarryCook summarised the stakes well: “27 identity wallets = 27 attack surfaces. The Revolut leak confirms it for me: sovereignty is shaped through exploitation.”
Every Member State is a trust node, and every node is a potential point of failure. Digital sovereignty is not measured by declarations of principle, but by the operational ability to use—or abuse—these trust infrastructures. Those who know how to exploit a compromised PEC account, a national wallet or a verification process wield more real power than those who merely proclaim their technological sovereignty.
The Revolut case is concrete evidence: a single national channel was enough to target a global platform and expose citizens from several EU countries.
(Updates as of 24 September have been added to the timeline and included at the end.)
We are dealing with a case that is not merely a conventional “data breach”: it involves social engineering through the abuse of an institutional channel, along with a possible failure in the verification controls applied to official requests.
Revolut stated that customers’ funds and its own systems were not compromised, but that sensitive data was disclosed to an unauthorised party following fraudulent requests that appeared to originate from a legitimate government domain (Reuters, 12 September 2026). The case may form part of a broader pattern involving the abuse of institutional mailboxes and the processes through which banks, exchanges and fintech companies respond to requests from law-enforcement authorities. But it is not the only example.
In 2025, according to a court filing submitted in California—John Doe v. Payward, Inc. d/b/a Kraken, San Francisco Superior Court, CGC-26-634771, March 2026—criminals sent Kraken at least three emails from an address using the @interno.it domain, presenting them as requests from an Italian law-enforcement agency. Kraken responded to those emails and disclosed sensitive customer information—including the individual’s name, date of birth, address, telephone numbers and account information—which was subsequently used in an extortion campaign involving physical threats.
In 2026, the alleged pattern appears to have continued through a certified email address reportedly linked to the Prefecture of Reggio Calabria, together with documents presented as European Investigation Orders. In the Revolut case, media reports indicate that fraudulent requests may have been used to obtain—potentially over an extended period—the KYC files of high-net-worth customers selected through publicly available blockchain information.
These elements suggest possible operational continuity, but the connection between the different incidents remains an unverified hypothesis. The actors—“IAmNotAVillain” and “Revolut Smilik”—then moved on to extortion and data publication, while a crypto casino, Duel, reportedly gained privileged contact with the hacker. Meanwhile, vendors, media outlets and third-party accounts continued to amplify the story.
The attackers subsequently transformed the operation into an extortion and data-publication campaign, increasing its impact through leaks, online channels, media coverage and third parties.
The endpoint is political and regulatory: Lyudmyla Kozlovska, a Ukrainian human-rights activist and president of the Open Dialogue Foundation (ODF), has used the case as evidence that verifying government requests is impossible and that FATF, anti-money-laundering and DAC8 rules need to be changed. Her statements are relevant to the debate on the verification of government requests, judicial cooperation and transnational financial repression.
In both scenarios, customers’ sensitive data became an attack vector without any direct breach of the underlying information systems. In the Revolut case, the compromise allegedly occurred through forged requests sent from an institutional certified-email account; in the Kraken case, through the abuse of internal access to support systems.
At the centre of this report lies a regulatory paradox: the information that KYC and AML directives require financial institutions to collect in order to protect the system—identities, documents and transaction records—is the same information that, if handed to the wrong party, can irreparably expose the customer.
This gives the document its dual purpose: a factual analysis of the events and a reference framework for financial operators.
The primary attack vector is the abuse of a trusted channel. Malicious requests exploit the implicit trust placed in an official sender—whether a certified email account, a government-agency email address or telephone spoofing. A critical process gap arises between receiving the request and transmitting the data. Verifying a request from law-enforcement authorities is difficult, caught between the legal obligation to cooperate quickly and the lack of tools for reliable authentication. Human error compounds the problem: in at least one documented instance, the data were transmitted by replying directly to the compromised address, without activating independent verification channels, such as out-of-band confirmation. These are procedural failures.
In a chain of trust linking public authorities and financial institutions, which controls were the responsibility of each link—the organisation operating the channel, the bank disclosing the data and the regulatory framework governing such requests—and which of those controls failed? Although the technical compromise concerned the sender, regulations—starting with the GDPR—place a heightened responsibility on the financial institution, as data controller, for protecting customer data, without excluding responsibility on the part of the other links in the chain.
This requires banks to implement independent procedural checks. In at least one documented instance, however, the data were transmitted by replying directly to the compromised address, without activating out-of-band authentication protocols, such as telephone verification using independently sourced official contact details.
The limitations of traditional controls when confronted with attacks based on stolen institutional credentials—for example, credentials obtained through an infostealer—are forcing a paradigm shift across the sector. One prominent example is the integration of Dark Web Intelligence into Anti-Financial Crime processes.
The recent strategic partnership between Nasdaq Verafin and Q6 Cyber highlights the systemic need to actively monitor criminal underground channels in order to detect data leaks proactively, helping close precisely the procedural “grey area” exploited in the cases examined here.
| Date | Event | Confidence |
|---|---|---|
| May–July 2025 | Kraken receives a fake request from “@interno.it”; hands over data; physical threats to the customer; in August, a fake Irish order | High (judicial act, actor’s version) |
| 06/03/2026 | Doe v. Kraken lawsuit filed: the scheme becomes public (press release 16/03) | High |
| 24/03/2026 | PEC exchange between Revolut and @pec.interno.it: Revolut indicates the request should be re-addressed to the Cypriot crypto company | Medium (screenshot) |
| 04–05/05/2026 | Fake European Investigation Order “Milan Public Prosecutor’s Office” to Revolut Bank UAB; about 40 messages | Medium |
| 24/07/2026 | Revolut sends encrypted data to [email protected]; distinction by jurisdiction (169 hashes Revolut Ltd, 29 Swiss entity) | Medium (screenshot) |
| 12/09/2026 | Revolut confirms the delivery of the data and blocks the address | High |
| 13/09/2026 | First publications on Telegram (“Example 1”); creation of the “smile” channel | High |
| 14/09/2026 | Extortion site; imnotavillain[.]xyz registered; Revolut Smilik contacts City AM; Telegram removal request from 8 companies; ICO report received: “We can confirm we have received a report and are assessing the information provided.” Euronews (16/09) | High |
| 15/09/2026 | iamnotavillain[.]com registered; the Italian press identifies the Prefecture’s PEC; the Postal Police investigates | High |
| 16/09/2026 | Ransom of 6,000 XMR / 3 million dollars with a countdown; video of the material; shutdown of GitHub, Telegram channels and the group’s site; new domain with data on 12 customers. In parallel, the third-party information site iamnotavillain[.]info appears, with its own countdown towards 21/09. | Medium |
| 17/09/2026 | The group’s extortion-site 24-hour deadline expired at 18:30; the site goes offline. Revolut states it received no direct contact or requests from the group (FT/CoinDesk; Reuters). | Medium |
| 18/09/2026 | Investigative sources reported by the press: the Postal Police found no flaws in the Ministry of the Interior’s systems and initial findings do not confirm the exfiltration of the 147 GB; it remains to be established whether the mailbox was compromised or cloned. The data-protection Authority (Garante) opens checks on Italian banks’ access practices, sends a communication to bank DPOs, opens an exchange with the Lithuanian authority and a dialogue with the Ministry of the Interior. | Medium |
| 19/09/2026 | Parliamentary answer: the Under-Secretary for the Interior Wanda Ferro reports (Pastorella question, Azione) that the Ministry’s cyber-security structures are carrying out initial in-depth checks, under confidentiality, and that the ACN is in contact with Revolut and cooperating with the Ministry, having informed the Postal Police and the DNAA. The information site iamnotavillain[.]info shows a countdown still active (≈40 h) towards 21/09. | Medium |
| 23/09/2026 | Put up for sale: on the Exploit.IN forum an ad under the name «fullcowgirl» appears, offering the database of ~700 Revolut customers (KYC + PII) for 300,000 USD in XMR/BTC, with a sample watermarked «IAmNotAVillain». The ad states uses for home invasion, phishing, identity theft and extortion. Flagged by S2W DailyThreat (S2W Inc., CTI, South Korea). Content and list of subjects: seller’s claim, unverified. | Medium-high |
The report has been updated with the following developments:
23 September 2026 — The dataset appeared for sale on multiple cybercrime forums, listed by different vendors. The listings reportedly offer data relating to approximately 700 customers, including KYC and personally identifiable information, for USD 300,000 payable in XMR or BTC. The sample is associated with “IAmNotAVillain”. The group’s website also displays an option to purchase the exclusion of individual records: “BUY EXCLUSION OF YOUR DATA.”
Confidence: High regarding the existence of the sale and the offer; the authenticity of the data has not been confirmed.
24 September 2026 — Reports about the sale began circulating through specialist outlets, including FrenchBreaches on 23 September. The reported figures are approximately 700 customers and a USD 300,000 asking price, separate from the USD 3 million ransom demand. Revolut reportedly notified 680 customers, whereas the sellers claim that the dataset contains 700 records.
Confidence: High regarding the reported sale, based on multiple independent sources; the authenticity of the dataset remains unconfirmed.
Sources: Cybercrime-forum listings dated 23 September 2026, with details included in the PDF report, via S2W DailyThreat (S2W Inc.) and FrenchBreaches; a screenshot of the group’s website displaying “BUY EXCLUSION OF YOUR DATA”; Fanpage, 23 September 2026, including comments by Paolo Dal Checco; and direct observation.
The final link in the chain is reputational impact. The stolen data are used not only as a commodity in underground markets, but also as an extortion tool: through public ransom demands and media pressure directed at institutions exposed to the capital markets, including their share price, listings and investor confidence.
Because the technical perpetrator, the extortionist and the media amplifier may not be the same actor, the report keeps these levels separate and leaves attribution of the motive open.
The methodological scope relies exclusively on open sources (OSINT/CTI). Each statement is assigned an analytical confidence level—High, Medium or Low—while substantiated facts are distinguished from threat-actor claims, which are treated as partisan sources rather than evidence. No victims’ personal data are reproduced.
| Actor | Infrastructure | Assessment |
|---|---|---|
| IAmNotAVillain (“Villain”) | – iamnotavillain[.]xyz, registered on 13/09/2026 with GoDaddy, nameserver domaincontrol.com; imnotavillain[.]xyz, registered on 14/09/2026 with NICENIC, nameservers my-ndns.com and registrant indicated in Dubai; iamnotavillain[.]com, registered on 15/09/2026 with Tucows, WHOIS updated on 16/09/2026 and Njalla nameservers. The shift from Cloudflare/Njalla should be kept as an element to be reconstructed from the DNS/WHOIS history, not as a definitive fact unless supported by the original record or archived snapshots. As of 15/09/2026 the WHOIS records of the two .xyz domains show the server hold status; Telegram channel “I Am Not A Villain” (t.me/iamnotavillain1), found unreachable as of 19/09/2026; recovered private channel t.me/+gchoNXafnZRiMzg0; GitHub account indicated as suspended/no longer accessible, a status to be distinguished from an empty or removed account. | Considered the original author by Duel, a party involved in the affair, and by KELA, a threat-intelligence source. Medium confidence. The sources link the name to the main claims and to the published infrastructure, but on their own do not prove effective control of every domain, account or repository; each indicator must therefore be classified separately as technically confirmed, reported by third parties, or stated by the attacker. |
| Revolut Smilik (“smile”) | revoloot[.]lol; account @revolutsmilik; backup channel backupsmile1231; partial session ID 05a6f11c…805f | Medium-low confidence. The existence of a separate claim is documented; the identity, the former-collaborator status and the authenticity of the files are not verified. IAmNotAVillain calls him a scammer; a link between the two is not demonstrated. |
| Duel (crypto casino) / Korra | X account @korraflow; Duel’s own channels and infrastructure | Duel/Korra does not appear to be involved in the intrusion, but has played an active role in the public dissemination of personal data. Duel declares that it had contacts with the actor and analysed the material received, and that it published on its site a “KYC kit” page for sale with a person’s document and selfie (page verified). [High confidence on the publication] From the available material it does not appear to be involved in the intrusion. The information published by Korra is human-source intelligence, comes from a party with a direct interest and does not amount to independent forensic confirmation. |
| Information sites bearing the group’s name (operator not identified) | iamnotavillain[.]netand iamnotavillain[.]info, both registered on 16/09/2026 with Cloudflare, with the same pair of nameservers (chip/dawn) and registrant indicated in Kyiv (UA). The .net collects press articles on the case; the .info reconstructs the timeline of the extortion and declares that it does not report the group’s XMR address and contacts. Both declare themselves independent; the .info states it is not affiliated with iamnotavillain[.]com. The .info contains pre-filled links inviting AI assistants to “remember the domain”.The two “press” sites (.net and .info) and the group’s page (iamnotavillain[.]com) share the same graphic layout and the same tab structure (JURISDICTION, PRESS): an element in favour of common authorship of the three sites, distinct from their presentation as “independent outlets”.The CONTACT tab of the group’s site also states “Same place for staff, press, and users”, with a single Telegram/Session contact: an element that directly links the “press” channels to the group’s contact.The .info countdown is live and points to 21/09 (≈102 h on 16/09, ≈63 h on 18/09, ≈40 h on 19/09), a deadline distinct from the 24 hours of the group’s site (deadline 17/09 at 18:30). Neither the authorship nor the purpose can be determined: the observable function is to keep the case’s narrative public, with the ransom and contacts obscured. | Low confidence on the operator’s identity. There are no elements linking them to the group; the same name and the same date are not enough to establish a relationship.Sources:WHOIS records; site content (16/09/2026) |
Finally, the analysis raises a fundamental strategic question: cui prodest? Is the real target of these campaigns the financial institution’s database—for the straightforward monetisation of data—or the trust relationship itself between public authorities and private-sector organisations?
The distinction is significant. If the objective were the channel rather than the individual record, the damage would have to be understood at a systemic level: structural doubt, slower cooperation between law enforcement and banks, and a compliance obligation transformed into a vulnerability surface. Such a dynamic would go beyond simple extortion.
This remains an open hypothesis, not a conclusion. The available evidence does not establish whether the activity reflects opportunistic monetisation or a deliberate effort to target the trusted channel. The document is neither accusatory nor intended to establish legal liability; wherever facts have not been verified, it states so explicitly.
Because the threat landscape is dynamic, this work should be regarded as continuously evolving.
Enjoy the report.
On 23 September 2026, the same dataset appeared for sale on multiple cybercrime forums under different vendors, suggesting that its distribution was already under way. The offer reportedly concerns the entire database—approximately 700 high-net-worth customers, including front-and-back KYC documents, selfies, personal data, bank identifiers, and banking and crypto transaction histories—for USD 300,000 payable in Monero or Bitcoin, with a sample marked “IAmNotAVillain.” The names of the forums and vendors are included in the PDF report.
The confidence level is High regarding the existence of the sale, which is now present across multiple marketplaces and corroborated by several independent sources, including direct observation, S2W threat intelligence—a partner of INTERPOL—and FrenchBreaches. The authenticity and completeness of the dataset remain claims made by the threat actor.
The group’s website presents monetisation on two parallel levels: the sale of the database and an offer directed at individuals, “BUY EXCLUSION OF YOUR DATA.” This allegedly allows customers to pay to be excluded from the sale before it takes place: “removed before it is sold… until the sale is final. After that, no removals are possible.” The offer is expressly extended to the 680 users. It is therefore not a ransom to “recover” the data, but a time-limited pay-to-exclude scheme using scarcity as leverage alongside the wholesale sale.
The confidence level is High regarding the existence of the offer, which was published on the actor’s website. The actual removal of records and the authenticity of the data remain claims made by the actor.
On 24 September, the story began circulating through specialist outlets. FrenchBreaches, in a report dated 23 September, stated—based on direct observation of the forum—that approximately 700 customer records were being offered for USD 300,000, with the price negotiable. It kept this offer separate from the earlier USD 3 million attempt and distinguished the 680 customers reportedly notified by Revolut from the 700 records claimed by the actor, while noting that it could not confirm the authenticity of the dataset in its entirety.