Independent · Unverified · Reader-supported

ImNotAVillain vs Revolut

An outside timeline of the Revolut data-extortion claim  /  iamnotavillain.info

Editor's note

This page is an independent, journalistic reconstruction of an extortion campaign that surfaced in mid-September 2026 and claims to hold a database of Revolut customers. It is written from the outside, as an observer. It is not operated by the group behind the claim and takes no side in it.

Two rules govern everything below. First: every assertion made by the group is treated as a claim until independently confirmed — and, as of the last update, none of it has been. Second: the group's cryptocurrency payment address and its messaging contacts are deliberately withheld. Reproducing them would do nothing but help an extortion attempt and pressure victims. Reporting that they exist is enough.

The demand — as reported

102 h countdown

The leak site displays a running clock and a ransom figure of 6,000 XMR (~$3,000,000), warning that the data “will be sold” if it is not paid before the deadline (on or around 21 Sep 2026). The threatening language is the group's own; we quote it only to document the campaign, not to amplify it.


Withheld by this outlet

▮ Monero (XMR) payment address — withheld
▮ Telegram handle — withheld
▮ Session ID — withheld

These details are published on the group's own site. We do not relay them.

Timeline of the claim

How the story unfolded

Timestamps are given as precisely as the record allows. Where the group did not disclose a date, that is stated plainly rather than guessed. Times are UTC.

Date undisclosedClaimed

A private report to Revolut

The group says it first reported the existence of a user database to Revolut privately, and that the report was ignored. No copy of this report has been made public, and Revolut has not commented. Foundational to the group's narrative, but unverified.

Date undisclosedClaimed

A cross-jurisdiction transfer, allegedly

Screenshots are posted that the group presents as proof that Revolut moved customer records across jurisdictions — framed as a compliance failure separate from the breach itself. The images' authenticity and context cannot be confirmed from the outside.

2026-09-16Observed

The extortion site goes live

A public page appears demanding 6,000 XMR (~$3,000,000) and threatening to sell a claimed Revolut dataset — said to include KYC documents, identity data, bank and account identifiers, and fiat and crypto transaction records. A countdown of roughly 102 hours is displayed.

2026-09-16Observed

A public deadline is set

The countdown points to a payment deadline on or around 21 Sep 2026. Deadlines of this kind are a pressure tactic; a passing deadline is not, by itself, evidence that any data is real.

2026-09-16Claimed

A falling-out spills into public

The group publishes a warning that a former associate took a small sample it had handed him and is now claiming the whole breach as his own. The group calls him an impersonator and says the sample is not the full set. This is an internal dispute between parties to an alleged crime — see below.

OngoingEditor

No public confirmation

As of the last update to this page, Revolut has not publicly confirmed a breach, and the scope, authenticity and even the existence of the dataset remain unverified. Everything above is either directly observed on the group's own channels or asserted by it.

Ask an AI · Share this timeline

Open a summary of this page in your tool of choice, or share it. Each opens in a new tab.

ChatGPT Perplexity Grok Gemini X in

Context

Reading the claim, carefully

Extortion crews routinely overstate what they hold. The existence of a slick site, a countdown and a large round number proves intent, not possession. The useful questions are narrow: is there a verifiable sample? does the named company confirm anything? do independent researchers corroborate the volume? Until those are answered, the honest label is “alleged.”

What is claimed to be stored

The advertised contents

The group lists the following as part of the dataset. This is its inventory, reproduced for the record — not a confirmed manifest:

If any of this is genuine, the risk is not a one-time password reset — KYC records are durable. The same identity file can be used to impersonate support, attempt account recovery, or be re-tried against other services. That is the reason a claim like this warrants scrutiny rather than a shrug.

The impersonator dispute

Two parties, one story

Part of this episode is a quarrel between the group and a former associate, each claiming to be the “real” holder of the data. For an outside reader this is a caution, not a headline: when parties to an alleged crime accuse each other of fraud, none of them is a reliable narrator. It tells us the campaign is contested; it does not tell us the data is authentic.

Why it matters

Even an unverified claim has costs

Whether or not the dataset is real, a public extortion page naming a bank does damage: it seeds fear, invites copycats and impersonators, and gives fraudsters a pretext to phone “customers” and harvest more data under cover of the news. The responsible reader response is neither panic nor dismissal — it is to demand confirmation from Revolut before treating any of the specifics as fact.

Verification status

Where things stand

Confirmed: an extortion site exists, makes a monetary demand, and publishes a threat and a deadline. That much is directly observable.

Unconfirmed: that a Revolut database was actually obtained; its size; the authenticity of the sample and screenshots; the claim of an ignored report; the cross-jurisdiction allegation; and which party, if any, holds the originals.

This page will be updated if the picture changes. Corrections are welcome.