CTIPilot

Imnotavillain

actor · actor:imnotavillain single-source-victim

Extortion actor claiming sole responsibility for the 2026-09 Revolut KYC-data breach via its own darknet leak site (Heise Online spelling: 'Imnotavillain'), disputing a rival claimant it calls a fraud, and pivoting to individually extorting roughly 680 named customers directly (Heise Online, 2026-09-25). A separately-spelled actor, 'iamnotavillain' (The Irish Times, 2026-09-17), issued a $3 million ransom ultimatum over the same breach; no cited source states the two spellings name the same actor, and neither claimant's identity is independently established.

Coverage timeline
1
first 2026-09-13 → last 2026-09-13
Peak priority
notable
1 notable
Sources cited
7
7 hosts
Sections touched
1
active-threats
Co-occurring entities
1
see Co-occurring entities below
ATT&CK techniques
5
pinned v19.2 · see below

ATT&CK techniques

5 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Reconnaissance TA0043

T1598Phishing for Information×1

Adversaries may send phishing messages to elicit sensitive information that can be used during targeting. Phishing for information is an attempt to trick targets into divulging information, frequently credentials or other actionable information. Phishing for information is different from Phishing in that the objective is gathering data from the victim rather than executing malicious code.

Evidence: 2026-09-13/revolut-fake-government-request-kyc-breach · ATT&CK page ↗

Resource Development TA0042

T1586.002Compromise Accounts: Email Accounts×1

Adversaries may compromise email accounts that can be used during targeting. Adversaries can use compromised email accounts to further their operations, such as leveraging them to conduct Phishing for Information, Phishing, or large-scale spam email campaigns. Utilizing an existing persona with a compromised email account may engender a level of trust in a potential victim if they have a relationship with, or knowledge of, the compromised persona. Compromised email accounts can also be used in the acquisition of infrastructure (ex: Domains).

Evidence: 2026-09-13/revolut-fake-government-request-kyc-breach · ATT&CK page ↗

Stealth TA0005

T1070.008Indicator Removal: Clear Mailbox Data×1

Adversaries may modify mail and mail application data to remove evidence of their activity. Email applications allow users and other programs to export and delete mailbox data via command line tools or use of APIs. Mail application data can be emails, email metadata, or logs generated by the application or operating system, such as export requests.

Evidence: 2026-09-13/revolut-fake-government-request-kyc-breach · ATT&CK page ↗

T1684.001Social Engineering: Impersonation×1

Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For example, adversaries may communicate with victims (via Phishing for Information, Phishing, or Internal Spearphishing) while impersonating a known sender such as an executive, colleague, or third-party vendor. Established trust can then be leveraged to accomplish an adversary’s ultimate goals, possibly against multiple victims.

Evidence: 2026-09-13/revolut-fake-government-request-kyc-breach · ATT&CK page ↗

Impact TA0040

T1657Financial Theft×1

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

Evidence: 2026-09-13/revolut-fake-government-request-kyc-breach · ATT&CK page ↗

Story timeline

  1. 2026-09-13Revolut discloses a customer KYC data breach after fulfilling a fraudulent request sent from inside a genuine government agency's own email domain
    active-threatsRevolut handed over customer identity documents and crypto histories because the request came from an authentic-looking government email address

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

related to

Where this entity is cited

  • active-threats1

Source distribution

  • cyberinsider.com1 (14%)
  • databreaches.net1 (14%)
  • heise.de1 (14%)
  • hudsonrock.com1 (14%)
  • irishtimes.com1 (14%)
  • securityaffairs.com1 (14%)
  • techcrunch.com1 (14%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Imnotavillain (1)

2026-09-13 · view entry permalink →

NOTABLEupdatedNATOB2

Revolut discloses a customer KYC data breach after fulfilling a fraudulent request sent from inside a genuine government agency's own email domain

Revolut confirmed to TechCrunch on 2026-09-12 that it disclosed sensitive customer data after receiving a fraudulent information request sent from "an unauthorised email account sent directly using the official government agency's email domain" (Revolut, via Security Affairs, 2026-09-12); Security Affairs assesses the attacker either registered a rogue mailbox within that domain or compromised an existing one. Because the message carried valid domain-authentication credentials, Revolut's compliance and KYC-response process treated it as authentic and fulfilled it: exposed data included full name, date of birth, occupation, postal and email address, phone number, passport or driver's-licence copies, verification selfies, IBAN and account statements, withdrawal records and full transaction history including Bitcoin (Security Affairs, 2026-09-12). "No systems were compromised, no malware was used"; the entire incident was a social-engineering compromise of the legal and regulatory data-request channel rather than a technical intrusion (Security Affairs, 2026-09-12). Revolut confirmed to TechCrunch that a "limited" number of customers were affected, declining to disclose the exact count, the government agency involved, or whether the incident was confined to one market (TechCrunch, 2026-09-12). Revolut discovered the fraud only after independently contacting the government agency to verify the request, at which point the agency confirmed it had not made it (Security Affairs, 2026-09-12); it has since blocked the sending mailbox and notified the agency, law enforcement and financial regulators (TechCrunch, 2026-09-12).

The same weakness applies to any organization whose legal or regulatory data-request process trusts that a request's sending domain is proof of the sender's authority: an attacker who obtains or spoofs access to a single mailbox on that domain can submit an urgent, seemingly authentic request that bypasses the normal verification a company would otherwise apply. Here that pattern reached a major fintech's KYC/AML compliance channel, and the entire compromise happened at the request-verification step: no phishing link was clicked and no credential was stolen, only an email that domain-authenticated correctly and asked for the right kind of data in a plausible way.

For any organization that operates a legal or regulatory data-request intake process, the transferable lesson is that domain-level email authentication (the same trust SPF, DKIM and DMARC exist to establish) is not proof of institutional authority: an adversary who controls, or convincingly spoofs, a single mailbox on a trusted government or law-enforcement domain can defraud any recipient who verifies a request only by checking that it came from the right domain. This cuts both ways for a public-sector authority: any authority that itself issues legal data requests to third parties (banks, telcos, cloud providers, ISPs) as part of investigations should assume that a compromise of its own mail infrastructure could be used to defraud those third parties in its name, and should expect the recipients of its own legitimate requests to apply out-of-band verification rather than treat that as an insult to its authority.

Revolut received a request for customer information that appeared to come from a legitimate government agency. The request came from an unauthorised email account sent directly using the official government agency's email domain.

As the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request.

Revolut (customer notification, via Security Affairs)

Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information.

Revolut spokesperson, via TechCrunch

People claiming responsibility for the incident have posted samples of the allegedly stolen information across several Telegram groups and the material appears to include details belonging to prominent individuals, including business leaders, sports professionals and performing artists.

The attackers have threatened to publish additional information “every day” unless Revolut pays a ransom of 10,000 Bitcoin – currently worth more than $782m.

Dev Kundaliya, via DataBreaches.net (relaying Computing.co.uk)

The hacker gained access to government employee accounts using an infostealer. After gaining entry to an employee's email, they would log in, add a recovery email under their control, begin logging activities, and silently monitor communications.

The Duel Investigations Team, via Hudson Rock

By checking Hudson Rock's extensive cybercrime database, we identified approximately 300 compromised pec.interno.it webmail logins stemming from already infected machines. Based on this intelligence, we assess that it is highly unlikely the hacker actively infected these specific employees themselves.

Hudson Rock 2026-09-15

Upon receiving a reply to their fraudulent emails, they would immediately download it as a .eml file and delete it before the actual account owner noticed.

The Duel Investigations Team, via Hudson Rock

The data breach is understood to have affected at least 680 customer accounts.

The Irish Times 2026-09-17

"one of their former accomplices took only part of the obtained data. He is posing as the actual perpetrator. He is, however, a fraud." # (translated from German)

"'Imnotavillain' is now offering the data sets of 680 high-ranking individuals for sale. As a special twist, the perpetrators are also luring the individual data subjects; they could buy the removal of their own record before the data is sold as a whole to interested parties in the future." # (translated from German)

Heise Online 2026-09-25
Correctionrun 2026-09-13T1307Z-auditbody

The quotation from Revolut's customer notification in the opening paragraph was rendered with an inserted ellipsis. Revolut's sentence reads in full: "The request came from an unauthorised email account sent directly using the official government agency's email domain" (Revolut, via Security Affairs, 2026-09-12). The two elided words are the operative ones for a defender reading this as a control failure: the request was sent directly from the agency's own domain rather than from a lookalike, which is why domain authentication passed and why the sending domain told Revolut's reviewer nothing about the sender's authority.

Updaterun 2026-09-16T0409Z-inteltechniquessourcesevidencesourcing_noteconfidencebody

Parties claiming responsibility for the breach have posted samples of the allegedly stolen data across several Telegram groups, reported to include details belonging to "prominent individuals, including business leaders, sports professionals and performing artists," and are demanding Revolut pay a ransom of 10,000 Bitcoin, worth more than 782 million US dollars at the time of reporting, threatening to publish further data "every day" if unpaid (DataBreaches.net, relaying Computing.co.uk, 2026-09-15). This is the first extortion dimension reported on an incident this entry previously described only as a disclosed process-abuse breach with no stated attacker demand. Computing.co.uk, the outlet that originated this reporting, remains unreachable on every transport tried as of 2026-09-16; neither Revolut nor a second independent outlet has confirmed the ransom figure, the Telegram posting, or the claimed victim identities, so these remain attacker-stated claims rather than established fact.

Updaterun 2026-09-18T0410Z-inteltechniquessourcesevidencesummarysourcing_notebody

Hudson Rock, relaying the attacker's own account to the Duel Investigations Team, reports the access vector claimed behind the fraudulent request: infostealer-compromised webmail accounts on pec.interno.it, the certified-email domain of Italy's Ministry of the Interior. Per that account, the hacker gained access to government employee accounts using an infostealer, and after gaining entry to an employee's email, would log in, add a recovery email under their control, begin logging activities, and silently monitor communications (The Duel Investigations Team, via Hudson Rock, 2026-09-15). Upon receiving a reply to their fraudulent emails, the operator would immediately download it as a .eml file and delete it before the actual account owner noticed, an anti-forensic technique the account says let the campaign run for roughly five months, beginning with forged court orders before pivoting to Revolut Bank UAB, Revolut's Lithuania-licensed EU subsidiary obligated to respond to European Investigation Orders (The Duel Investigations Team, via Hudson Rock, 2026-09-15). Hudson Rock's own cybercrime database independently identified approximately 300 compromised pec.interno.it webmail logins from already-infected machines, and on that basis assesses it is highly unlikely the hacker actively infected these specific employees themselves (Hudson Rock, 2026-09-15); the attacker's own account of the initial-access method was itself inconsistent, first describing a remote-access trojan and later an infostealer. This resolves the access-vector question the original disclosure left open; CyberInsider reports Revolut told it only that the fraudulent request "appeared authentic based on the technical indicators available to its staff" (CyberInsider, 2026-09-16), and Revolut itself has not confirmed the five-month timeline, the pec.interno.it detail, or the anti-forensic technique. CyberInsider separately references unnamed "separate reporting" giving a customer count of around 680, a figure this entry cannot independently verify.

Updaterun 2026-09-26T0404Z-intelentitiessourcesevidencesummarysourcing_notebody

The Irish Times independently confirms the customer count this entry previously could not verify: "The data breach is understood to have affected at least 680 customer accounts" (The Irish Times, 2026-09-17), reporting on a group spelling its name "iamnotavillain." A group whose name Heise Online spells "Imnotavillain" now claims sole responsibility for the breach on its own darknet site, disputing a rival claimant it says "took only part of the obtained data" and "is posing as the actual perpetrator" while calling that rival "a fraud" (Heise Online, 2026-09-25, translated from German); no cited source explicitly states the two spellings name the same actor, and neither claimant's identity is independently established. Having already issued a 6,000 XMR ($3 million) ransom ultimatum to Revolut itself with a 24-hour deadline, published on its own website with a countdown clock (The Irish Times, 2026-09-17); no cited source states what happened when that deadline passed, a separate, larger 10,000 Bitcoin demand this entry's 2026-09-16 update recorded came from a single, since-unreachable relay and is not corroborated by this Irish Times reporting or any other cited source, and the two figures are not reconciled here; a group under this name has now pivoted to individually extorting the roughly 680 named customers directly: it is "offering the data sets of 680 high-ranking individuals for sale" and letting each "buy the removal of their own record before the data is sold as a whole to interested parties in the future," publishing sample records including full name, email, phone number, address, account IDs, crypto withdrawal and balance data, bank transactions, and KYC documents and selfies as proof (Heise Online, 2026-09-25, translated from German). Revolut itself told the Irish Times at the time of the original ultimatum that it "has not received any direct contact or demand from the individuals or group making these claims" (The Irish Times, 2026-09-17); neither Revolut nor an independent researcher has confirmed either claimant's identity or the completeness of the data set.

incident13 Sep 04:37Zsingle-source · victim disclosureOpen finding ↗