An outside timeline of the Revolut data-extortion claim / iamnotavillain.info
Editor's note
This page is an independent, journalistic reconstruction of an extortion campaign that surfaced in mid-September 2026 and claims to hold a database of Revolut customers. It is written from the outside, as an observer. It is not operated by the group behind the claim and takes no side in it.
Two rules govern everything below. First: every assertion made by the group is treated as a claim until independently confirmed — and, as of the last update, none of it has been. Second: the group's cryptocurrency payment address and its messaging contacts are deliberately withheld. Reproducing them would do nothing but help an extortion attempt and pressure victims. Reporting that they exist is enough.
The demand — as reported
The leak site displays a running clock and a ransom figure of 6,000 XMR (~$3,000,000), warning that the data “will be sold” if it is not paid before the deadline (on or around 21 Sep 2026). The threatening language is the group's own; we quote it only to document the campaign, not to amplify it.
Withheld by this outlet
▮ Monero (XMR) payment address — withheld
▮ Telegram handle — withheld
▮ Session ID — withheld
These details are published on the group's own site. We do not relay them.
Timeline of the claim
Timestamps are given as precisely as the record allows. Where the group did not disclose a date, that is stated plainly rather than guessed. Times are UTC.
Date undisclosedClaimed
The group says it first reported the existence of a user database to Revolut privately, and that the report was ignored. No copy of this report has been made public, and Revolut has not commented. Foundational to the group's narrative, but unverified.
Date undisclosedClaimed
Screenshots are posted that the group presents as proof that Revolut moved customer records across jurisdictions — framed as a compliance failure separate from the breach itself. The images' authenticity and context cannot be confirmed from the outside.
2026-09-16Observed
A public page appears demanding 6,000 XMR (~$3,000,000) and threatening to sell a claimed Revolut dataset — said to include KYC documents, identity data, bank and account identifiers, and fiat and crypto transaction records. A countdown of roughly 102 hours is displayed.
2026-09-16Observed
The countdown points to a payment deadline on or around 21 Sep 2026. Deadlines of this kind are a pressure tactic; a passing deadline is not, by itself, evidence that any data is real.
2026-09-16Claimed
The group publishes a warning that a former associate took a small sample it had handed him and is now claiming the whole breach as his own. The group calls him an impersonator and says the sample is not the full set. This is an internal dispute between parties to an alleged crime — see below.
OngoingEditor
As of the last update to this page, Revolut has not publicly confirmed a breach, and the scope, authenticity and even the existence of the dataset remain unverified. Everything above is either directly observed on the group's own channels or asserted by it.
Ask an AI · Share this timeline
Open a summary of this page in your tool of choice, or share it. Each opens in a new tab.
Context
Extortion crews routinely overstate what they hold. The existence of a slick site, a countdown and a large round number proves intent, not possession. The useful questions are narrow: is there a verifiable sample? does the named company confirm anything? do independent researchers corroborate the volume? Until those are answered, the honest label is “alleged.”
What is claimed to be stored
The group lists the following as part of the dataset. This is its inventory, reproduced for the record — not a confirmed manifest:
If any of this is genuine, the risk is not a one-time password reset — KYC records are durable. The same identity file can be used to impersonate support, attempt account recovery, or be re-tried against other services. That is the reason a claim like this warrants scrutiny rather than a shrug.
The impersonator dispute
Part of this episode is a quarrel between the group and a former associate, each claiming to be the “real” holder of the data. For an outside reader this is a caution, not a headline: when parties to an alleged crime accuse each other of fraud, none of them is a reliable narrator. It tells us the campaign is contested; it does not tell us the data is authentic.
Why it matters
Whether or not the dataset is real, a public extortion page naming a bank does damage: it seeds fear, invites copycats and impersonators, and gives fraudsters a pretext to phone “customers” and harvest more data under cover of the news. The responsible reader response is neither panic nor dismissal — it is to demand confirmation from Revolut before treating any of the specifics as fact.
Verification status
Confirmed: an extortion site exists, makes a monetary demand, and publishes a threat and a deadline. That much is directly observable.
Unconfirmed: that a Revolut database was actually obtained; its size; the authenticity of the sample and screenshots; the claim of an ignored report; the cross-jurisdiction allegation; and which party, if any, holds the originals.
This page will be updated if the picture changes. Corrections are welcome.