Neobank Revolut has found itself at the heart of a sophisticated cyberattack that led to the exfiltration of personal data belonging to 680 customers across Europe. Departing from typical intrusive methods, the assailants exploited the Emergency Data Request (EDR) protocol, a legal mechanism designed to allow law enforcement rapid access to information in critical situations. By spoofing the digital identity of an Italian prefecture via a verified secure email account, the attackers bypassed the financial institution’s verification processes, successfully obtaining identity documents, KYC photos, and detailed transaction histories.

The group behind the operation, calling itself "iamnotavillain," issued a ransom demand of 3 million dollars, payable exclusively in Monero (XMR). The choice of this cryptocurrency, known for its anonymity, highlights a strategy aimed at evading blockchain tracing. Despite a twenty-four-hour ultimatum that has since expired, Revolut maintains that it has suffered no direct breach of its IT infrastructure and claims to have received no payment demand from the collective.

Beyond the data compromise, the incident underscores the inherent fragility of public sector emergency procedures. By specifically targeting profiles identified as having substantial crypto holdings, the hackers turned administrative data into tools for financial targeting. This segmentation, made possible by cross-referencing real-world identities with public social media addresses, exposes victims to heightened risks far exceeding simple digital identity theft.

The situation poses a strategic dilemma for regulated platforms: should they succumb to blackmail to protect their users, or refuse all transactions at the risk of seeing the data monetized on the darknet? The recent example of Coinbase, which refused a similar demand and opted to invest in legal remediation rather than paying a ransom, appears to be becoming the industry standard. For the 680 affected clients, the consequences are long-lasting, significantly increasing the risk of physical threats and targeted attacks—a stark reminder of the need for absolute discretion regarding one's digital asset holdings.