Profile · Reported & unverified

Who is the ImNotAVillain hacker?

A profile of what is known  /  iamnotavillain.net

Everything below is drawn from public reporting and from the actor's own messages. Where the actor makes a claim, it is labelled as a claim. The real identity behind the alias is not publicly known, and this page does not name, guess at, or publish personal identifiers for any individual.

In short

An alias, not a name

“ImNotAVillain” (also written iamnotavillain / IAmNotAVillain) is the online alias of the person or group that publicly claimed the theft of Revolut customer records in September 2026. As BankInfoSecurity and others have noted, the identity and the true motivation of the actor remain unclear. What exists is a body of claims, a Telegram presence, an extortion site, and a paper trail of reporting — not a confirmed person.

We deliberately do not reproduce the actor's cryptocurrency address or messaging handles. Those are operational details of an extortion attempt, not information a reader needs.

The self-image

Why “not a villain”?

The alias is a thesis. The actor frames the leak as exposure rather than crime — the argument being that Revolut failed to protect customer data and moved records across jurisdictions, and that the actor is merely holding the company to account. The extortion notice pairs that moral framing with a threat and a deadline (“the blood will be on your hands”), which is the tell: a genuine whistle-blower does not attach a price tag. The name is best read as branding, not a defence.

The claimed operation

What the actor says they did

In Telegram messages and on the leak site, the actor describes a campaign that ran for roughly six months. According to the Irish Times and Cybernews, the actor claims to have:

These are the actor's assertions. Italian authorities have not confirmed a broad compromise of ministry systems, and the volume and authenticity of the data are not independently verified.

The money

A moving ransom

The demand has not held still. Figures as high as 10,000 BTC circulated on Telegram before the actor settled on a public demand of 6,000 XMR (about $3 million) in Monero, with a countdown clock and a 24-hour ultimatum threatening to sell the data to other criminals if unpaid, as reported by the Financial Times via CryptoTimes. The choice of Monero — a privacy coin — and the shifting numbers are themselves signals: pressure tactics, not proof of what is held.

The feud

An impersonator, and a second channel

Part of this story is a falling-out. A second Telegram channel — reported under the name “Revolut Smilik” — also claimed the breach. ImNotAVillain responded that a former associate, whom it calls an impersonator and scammer, was handed a small sample and is now passing off the whole breach as his own, and it has warned victims not to negotiate with anyone else. For an outside reader this is a caution rather than a revelation: when parties to an alleged crime accuse one another of fraud, none of them is a reliable narrator. It tells us the campaign is contested; it does not tell us whose data is real.

The other side

What Revolut and regulators say

Revolut's position is that its systems were not hacked; it was deceived by a fraudulent government request and a limited number of customers were affected. The company has also said it received no direct ransom demand or contact from the group, which keeps the dollar figures firmly in the category of threat-actor speech. In the UK, the Information Commissioner's Office is assessing a report and the Financial Conduct Authority says it is engaging with the firm. Threat-intelligence teams such as KELA have examined the extortion site rather than the person behind it.

What we don't know

The honest gaps

This profile will be updated as verified reporting lands. It is a portrait of a claim and its author, not a verdict.