Revolut Listed by ImNotAVillain Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Revolut was listed by the ImNotAVillain ransomware group on 24 September 2026; the group claims an undisclosed number of people are affected, but the organisation has not disclosed any breach and the date of any intrusion has not been established. Individuals should check any Revolut-related notifications or account activity and consider changing credentials or contacting support if they suspect exposure.
A ransomware group calling itself ImNotAVillain has listed Revolut on a leak site, claiming that company data is available for sale and referring readers to contact details on the same page. The listing, reported on September 24, 2026, also asserts that the material includes 680 high-value, high-net-worth users. How many people may be involved overall is unknown, and the types of records supposedly on offer are not disclosed in the public summary.
Revolut has not publicly confirmed the claim as of writing. Listings of this kind are accusations and marketing by extortion crews; they can be exaggerated, recycled, incomplete, or false. For customers and anyone who has shared identity or financial details with a digital bank, the practical question is still worth treating seriously: if personal or account-related information were ever exposed, what would that mean, and what can you do while the claim remains unverified?
Inside the listing
According to the reported leak-site entry, ImNotAVillain has named Revolut and stated that “Revolut data” is on sale, with contact information placed at the bottom of the page. The same listing claims the package includes 680 high-value net-worth users. Public detail stops there. The number of people affected is unknown. Named data categories—such as full customer files, documents, credentials, or transaction histories—are not disclosed in the material provided. Timing of any alleged intrusion, technical method, duration of access, and whether any files were actually removed are likewise undisclosed.
What a leak-site post establishes is narrow: a group has chosen to associate a company name with an extortion narrative and a sales pitch. It does not, by itself, prove that a breach occurred, that the advertised set exists as described, or that the “680 high-value” figure is accurate. Until a company, regulator, or independent investigation confirms otherwise, the responsible reading is that this remains an unverified claim dated September 24, 2026.
Inside ImNotAVillain
ImNotAVillain appears in public reporting as a ransomware and extortion-style actor that uses leak sites to pressure organisations. Groups in this category commonly claim to have stolen data, threaten publication or sale, and invite buyers or the victim to make contact. Tactics associated with such crews often include double extortion narratives—encryption paired with data-theft claims—or data-theft-only pressure without a clear encryption event. Listings frequently mix screenshots, sample files, headcount claims, and vague inventories meant to increase urgency.
None of that general pattern proves what happened in any single case. For this Revolut listing specifically, the group claims data is for sale and highlights a subset of high-net-worth users; beyond those statements in the reported summary, no further victim-specific assertions from the group are included in the facts at hand. Readers should treat every detail on the page as the claimant’s version of events, not as a verified inventory.
About Revolut
Revolut is a well-known financial technology company offering digital banking-style services: accounts, cards, payments, currency exchange, and related products to consumers and businesses across multiple markets. Firms in this sector routinely collect and process information required for account opening, identity verification (KYC), anti-money-laundering checks, payments, customer support, and regulatory compliance. That can include names, contact details, dates of birth, government ID imagery or numbers, addresses, device and login metadata, card and account identifiers, and transaction records—though what any one incident might involve is a separate question and is not established here.
A credible compromise at a large consumer fintech would matter because the same records that make remote banking convenient are also useful for fraud, account takeover attempts, and targeted social engineering. The consequential nature of the sector does not convert an unconfirmed leak-site post into proof. It only explains why customers pay attention when a group publicly names such a firm.
What was likely exposed
The facts do not name exposed data types; they are not disclosed beyond the group’s broad claim of “Revolut data” on sale and a stated inclusion of 680 high-value net-worth users. It is therefore not possible to state which fields, documents, or systems—if any—were involved.
If files from a digital bank or fintech were taken, organisations of this kind typically hold identity and contact data, account and payment-related information, and supporting KYC material. High-net-worth or “high-value” customer segments, where they exist, may be associated with larger balances, wealth products, or more detailed onboarding files—but that is sector context, not a confirmed contents list for this listing. Exact contents remain unconfirmed. Any discussion of risk should stay conditional on whether the claim is later substantiated.
What's at stake
For individuals, the stakes if personal banking-related data were ever exposed are concrete: phishing and vishing that reference real account activity, attempts to reset passwords or passcodes, unauthorised payment or card misuse, identity fraud using KYC-style details, and secondary scams that cite a “Revolut breach” to harvest more information. People flagged—accurately or not—as high-net-worth can face more tailored social engineering. None of this means your data is known to be out; it describes what becomes possible if sensitive records circulate.
For the organisation, an extortion listing creates reputational pressure, customer concern, and potential regulatory attention even before facts are settled. Leak-site claims can also attract opportunistic fraudsters who have no access to any stolen set but impersonate the company or the attackers. Separating verified notice from rumour is part of the harm landscape itself.
What the listing does not establish is negligence, the quality of Revolut’s defences, or any timeline of detection and response. Those conclusions would require a claimed incident and evidence that is not present in an unverified actor post.
Steps worth taking either way
Treat the situation as a prompt for ordinary hygiene, not as proof that your file is public. If you use Revolut, enable the strongest available authentication, review recent logins and transactions, and treat unexpected calls, texts, or emails about a breach or refund as suspect until you verify them inside the official app or website. Prefer in-app notifications and known support channels over links or numbers supplied by strangers. If you reuse passwords elsewhere, change them on important accounts and watch for identity- or credit-related alerts in your country.
If you later receive a confirmed notice from Revolut or a regulator describing affected data, follow that guidance closely—freezes, replacement cards, or document re-issue differ by what was involved. In the meantime, you can run a free exposure scan of your email to check whether your address has already appeared in other known breach datasets, which is a separate and useful check regardless of whether this particular claim is ever validated.
Public detail on this listing remains limited: an ImNotAVillain claim dated September 24, 2026, unknown affected population, undisclosed data types, and an assertion about 680 high-net-worth users. Stay alert, verify sources, and wait for confirmation before assuming the worst—or the best—about what, if anything, left any system.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Italy Listed by ImNotAVillain Ransomware GroupBloom Financials Listed by Qilin Ransomware GroupPremier Fiduciary Listed by The Gentlemen Ransomware GroupPortman Finance Group Listed by Global Secret Group Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Revolut Listed by ImNotAVillain Ransomware Group →
Publicly posted by imnotavillain — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.