Get our latest research in your inbox

New threat intelligence, detection engineering, and red team write-ups, delivered when we publish.

The Revolut Breach: Infrastructure, Actors, and the Compliance Gap

September 16, 2026Crimson7 Threat Intelligence
threat intelligenceOSINTextortionfraudulent EDRsocial engineeringfintechRevolutthreat huntingdark webIAmNotAVillain
  • Classification: TLP:CLEAR
  • Threat type: Fraudulent Emergency Data Request / Data Extortion
  • Severity: High

Threat Hunt Report: IAmNotAVillain / Revolut Breach On September 12, 2026, Revolut confirmed it disclosed sensitive customer data (passport scans, transaction histories, crypto wallet identifiers, KYC selfies) to an unauthorized party impersonating a government agency. The request came from a real, compromised government email account and passed SPF, DKIM and DMARC. Two competing threat actors claim credit. The primary leak domain was seized within 26 hours. The jurisdictionally diversified backup lasted about five hours longer before the .xyz registry placed it on hold over the head of its Hong Kong registrar. Both actors demand 10,000 BTC. Neither is getting it. If your organization answers emergency data requests, verify them out of band, through a callback to a known number at the requesting agency, before any data leaves.


DISCLAIMER: All intelligence in this report was gathered through passive data collection only: WHOIS and RDAP queries, passive DNS, certificate transparency logs, public urlscan results, VirusTotal community intelligence, public GitHub repository metadata and commit history, public news sources, and open APIs. The darknet marketplace listing referenced in Section 5 was observed through keyword monitoring only. No attacker-controlled systems were accessed, modified, or disrupted at any point during this investigation. Victim identity data visible in leak site screenshots has been redacted by Crimson7 beyond what the actor applied.


Table of Contents

  1. Executive Summary
  2. Initial Incident: A Domain That Died Young
  3. Initial Reconnaissance: What the Dead Domain Left Behind
  4. External Intelligence: Pulling the Thread
  5. Darknet Signal: A Revolut Account Shop Restocks
  6. Attack Description: The Compliance Pipeline as an Exfiltration Channel
  7. Attribution: Two Actors, One Breach, Zero Trust
  8. Timeline
  9. Ecosystem Context
  10. MITRE ATT&CK Mapping
  11. Indicators of Compromise
  12. Key Takeaways

1. Executive Summary

On September 12, 2026, Revolut confirmed that it disclosed sensitive customer data, including passport scans, transaction histories, crypto wallet identifiers and KYC selfies, to an unauthorized party impersonating a government agency. The fraudulent request came from a real, compromised government email account. Two competing threat actors now claim credit for the breach. One built a leak site, got it seized, and had a backup ready on a different continent. The other, described by the first as a "scammer and former associate," is running the same extortion play with a subset of the data. Both demand 10,000 BTC. Neither is getting it.

Since the initial investigation on September 15, two things changed. The backup domain, registered through a Hong Kong registrar with Chinese nameservers specifically to outlast a takedown, was placed on registry hold the same afternoon. And a long-running darknet shop selling Revolut accounts refreshed its inventory on September 16, four days after the disclosure. Whether that stock comes from this breach is unproven, and we treat it as such.

This report traces the infrastructure, the actors, and the technique.


2. Initial Incident: A Domain That Died Young

The investigation began with a dead domain: iamnotavillain.xyz. It wasn't resolving. No A records, no web server, nothing. Just the kind of silence that usually means a registrar pulled the plug. Given the name alone, you could guess why.

A WHOIS query confirmed the suspicion immediately. The domain had been registered on September 13, 2026 at 23:29 UTC via GoDaddy, and by 01:44 UTC on September 15, roughly 26 hours later, it was wearing every status flag a registrar can throw at a domain:

  • serverHold and clientHold: domain removed from DNS at both registry and registrar level
  • clientRenewProhibited, clientTransferProhibited, clientUpdateProhibited: locked against any modification
  • clientDeleteProhibited: preserved as evidence

That last flag is the interesting one. You don't prevent deletion of a domain unless someone with legal authority wants to keep the records intact. This wasn't a routine abuse takedown. It was a seizure with evidence preservation.

Figure 1: Primary domain post-seizure. DNS resolution removed, serverHold and clientHold active.


3. Initial Reconnaissance: What the Dead Domain Left Behind

Modern internet infrastructure is noisy. Even a short-lived extortion site leaves residue across a dozen telemetry sources before anyone thinks to look.

urlscan: Screenshots from the Grave

Three urlscan captures survived from September 14, taken while the site was still live. The screenshots reveal a surprisingly polished page: monospace typography (IBM Plex Mono and Instrument Sans via Google Fonts), dark theme, sectioned layout with navigation anchors (Notice, Warning, Why it matters, What is stored, Jurisdiction, Press, Contact). No tracking cookies. No analytics. Zero JavaScript beyond a single copyId function, likely for copying a cryptocurrency wallet address or a contact identifier.

Two things stood out in the page content. The first was the "Notice" section:

"Revolut got a report about a user database. They ignored it, so we are exposing them for failing to keep user information secure, and for sending data from a different jurisdiction. We have everything, including KYC documents, address, phone number, email, bank accounts, and fiat and crypto transactions."

The second was buried in the "Warning" section, a message not directed at Revolut or its customers, but at another threat actor:

"An impersonator and scammer who used to work with us took a small sample we handed him and is now claiming the breach as his. That cut is not the full set. Revolut and the other companies sent the data to us. He did not do this. We can prove it: the originals, the volume, the conversations, and the companies that sent it. Do not deal with him. You WILL get scammed."

Two competing actors claiming the same breach, airing their dispute on the leak site itself. And that throwaway line, "Revolut and the other companies," suggesting this wasn't a one-target operation.

Figure 2: Backup domain imnotavillain.xyz serving the same content. Notice and Warning sections visible.

Telegram Discovery

Buried in the urlscan DOM capture was a Telegram link that didn't appear in any news reporting: t.me/IAmNotAVillain2. By September 15, the channel had already rotated to IAmNotAVillain3, meaning at least two prior channels banned, a clear ban-evasion cycle. The channel was active and being used for data sample publication and communication with journalists, including @IntCyberDigest on X, who appears to have been the primary OSINT contact for both competing actors.

Session Messenger

The contact section also referenced Session, a lesser-known encrypted messenger that routes through the Oxen blockchain's onion-routing network. Unlike Signal or Telegram, Session requires no phone number or email to create an account. The Session ID was not in the urlscan data, but was recovered from the gracemattsson repo's commit history, where it has been constant since the first commit: 0548b3c2be496218baa2314386787badfd458a868240a19ede82eabb6a13dd2c26.

Certificate Transparency

Certificate transparency logs revealed a subdomain that news reporting missed: pay.iamnotavillain.xyz, with a dedicated GoDaddy DV certificate (serial 00fdfeee3a4ff302f2) issued on September 13, the same day as domain registration. A payment subdomain with its own cert, separate from the GitHub Pages Let's Encrypt cert covering the main site. This actor was setting up infrastructure to receive money, not just to make threats.


4. External Intelligence: Pulling the Thread

Infrastructure Mapping: The Primary Domain

The primary domain's infrastructure was commodity-grade and disposable by design:

  • Registrar: GoDaddy (fast, cheap, $2 .xyz domains)
  • Hosting: GitHub Pages via Fastly CDN (free, no billing identity required)
  • IPs: 185.199.108-111.153 (standard GitHub Pages range, shared by millions of sites, worthless for attribution)
  • TLS: Let's Encrypt via GitHub Pages automatic provisioning (issuer: YR2)
  • DNS: GoDaddy default nameservers (ns03/ns04.domaincontrol.com)

The entire stack is free-tier, anonymous, and can be stood up in under ten minutes by anyone with a GitHub account.

The GitHub Accounts: The OPSEC Failure

The primary GitHub account iamnotavillain (ID: 248150151) was created on December 6, 2025, nine months before the breach went public. Zero public repos, zero followers, every profile field blank. Operationally clean.

The backup domain told a different story. Its www CNAME record points not to iamnotavillain.github.io but to gracemattsson.github.io, a second GitHub account (ID: 299922428), created July 4, 2026, with one public repo: 9hpj8ue5r6s12oim.9hpj8ue5r6s12oim123. The randomized repo name suggests an attempt at obscurity, but the repo is public, and every one of its commits (45 on our first pass, 59 by the evening of September 15) is attributed to gracemattsson with the email izaelwongfjgd@outlook.com. That email appears nowhere else on the internet. A burner, but now a burned one.

The commit history is the strongest evidence tying both domains to the same operator: the repo's CNAME file was initially set to iamnotavillain.xyz, then switched to imnotavillain.xyz on September 14. Deleted files are recoverable from git history: logo.jpg, Screenshot_35.jpg, and earlier index.html revisions. The first leaks.html commit (Sep 14, 20:28 UTC) was a template: "Posts go ... Duplicate this card when there is a new post", a serialized release structure. The victim images on the leaks page are served unblurred; the "blur" visible on the site is client-side CSS only.

The Commit Log, Read as a Diary

Because the repo is public, the full log is the closest thing we have to a diary of the operation. Fifty-nine commits over 27 hours, all under the same burner identity.

Figure 3: Full commit log of the gracemattsson repo as of September 15, 17 UTC. 59 commits, one author, one burner email. Note the mix of +0000 and -0700 offsets.

Four things in that log matter.

Two workflows, one timezone slip. Fifty-two commits carry GitHub's default web-editor messages ("Add files via upload," "Update index.html," "Delete Screenshot_35.jpg") and a +0000 offset, because GitHub's web UI stamps commits in UTC. Seven commits are different: they have hand-written messages ("Update CNAME," "Update Telegram link in contact section," "Add leaks.html for displaying leak incidents") and a -0700 offset. Those came from a local git client, which stamps commits with the machine's own clock. In mid-September, UTC-7 is Pacific Daylight Time, or Mountain Standard Time in Arizona. That is not attribution on its own (a VPS, a VM with a default timezone, or a deliberate setting would all produce it), but it is the only timezone artifact the actor has left, and it was left by the more careful of the two workflows.

The CNAME switch was pre-emptive, not reactive. The commit "Update CNAME from 'iamnotavillain.xyz' to 'imnotavillain.xyz'" is stamped September 14, 21:53:57 UTC, with two follow-up CNAME edits at 22:21 and 22:47 UTC. The primary domain was not seized until 01:44 UTC the next morning. The actor pointed the GitHub Pages fallback at the backup domain nearly four hours before the seizure, while the backup was still being served from Netlify. That settles the question raised in the next subsection: the GitHub Pages A records the backup domain fell back to on September 15 were pre-configured, not scrambled together after Netlify dropped the deployment.

The Telegram rotation is timestamped. "Update Telegram link in contact section" at 09:24 UTC on September 15 is the channel switch from IAmNotAVillain2 to IAmNotAVillain3. Ten minutes later, index.html and leaks.html were deleted and re-added as fresh files. That burst, roughly eight hours after the primary seizure and two hours before the hosting shift, is the actor rebuilding the site on the backup.

The actor kept working after the hold. The .xyz registry placed the backup domain on serverHold at 15:53 UTC on September 15. Twenty-one minutes later, between 16:14 and 16:15 UTC, five image files were deleted in quick succession (Untitled.jpg, Screenshot_38.png, image (24).jpg, photo123.jpg, screenshit35.jpg). Then new files were uploaded, index.html and leaks.html were updated, and at 17:14 UTC a commit titled "Fix typos in metadata and update links" landed, followed by more edits until 17:27 UTC. Whether the actor knew about the hold at that point is unclear; the site would have been unreachable through the domain but still live at gracemattsson.github.io. Two things are clear. The deleted images remain recoverable from history, so the cleanup achieved nothing. And "update links" on a site whose domain has just been pulled is worth watching: it is where a third domain would first appear.

The Backup Domain: Jurisdictional Arbitrage

This is where the investigation got interesting. Web searches for variant domain names turned up imnotavillain.xyz (note the missing "a"), registered approximately 10 hours after the primary, at 09:06 UTC on September 14. Same content, same actor, completely different infrastructure stack:

AttributePrimary (iamnotavillain.xyz)Backup (imnotavillain.xyz)
RegistrarGoDaddy (US)NICENIC International Group (Hong Kong)
HostingGitHub Pages (US)Netlify via AWS Global Accelerator, later GitHub Pages
NameserversGoDaddy default (US)ns3/ns4.my-ndns.com (Baidu HK + Tencent)
JurisdictionUS registrar, US hostingHK registrar, Chinese NS, US CDN
Status on Sep 15, morningSEIZED (registry + registrar hold)LIVE
Status on Sep 16SEIZED (registry + registrar hold)SEIZED (registry hold only, see below)

The jurisdictional split is deliberate. GoDaddy responds to abuse reports in hours. Getting a Hong Kong registrar using Chinese nameserver infrastructure to act on a UK-originated complaint is a different timeline entirely.

The backup domain also had revisions over the original: "Home" and "Leaks" navigation buttons, a dedicated data leak page, and deployment via Netlify Drop (UUID: 7e4d29ab-6f70-46a2-bb4d-b2fe5de57882). Not just a mirror, a second revision.

Figure 4: Leaks page (imnotavillain.xyz/leaks). Victim UK driving licence, watermarked "IAmNotAVillain." Entry labeled "REVOLUT 001," suggesting sequential releases planned. Identity fields redacted by Crimson7.

Threat Intelligence Feeds

VirusTotal returned 3 malicious and 3 suspicious engine detections for the domain, with categories including "elevated exposure" and "hacking." AbuseIPDB showed the Netlify IP at 16/100 with 26 reports, mostly related to crypto drainers, which is expected for shared infrastructure. GreyNoise showed no scanning activity from any of the IPs. Mnemonic passive DNS confirmed the A records and timing. OTX had no specific pulse. The domain was too short-lived for most threat intel platforms to index it meaningfully.

Post-Seizure: Backup Domain Shifts Hosting

A pivot pass run hours after the primary domain seizure revealed an infrastructure change on the backup domain. Between September 14 (when urlscan captured it on Netlify at 75.2.60.5) and September 15 at roughly 11:39 UTC, the A records for imnotavillain.xyz shifted from Netlify to GitHub Pages (185.199.108-111.153). DNSDumpster and FOFA both confirmed the new resolution.

TimeframeIPHostingSource
Sep 14, 20:00 to 23:04 UTC75.2.60.5Netlify / AWS GAurlscan, Robtex
Sep 15, ~11:39 UTC185.199.108-111.153GitHub Pages / FastlyDNSDumpster, FOFA
Sep 16none (NXDOMAIN)Registry holddig, RDAP

Two possible explanations: Netlify took down the deployment (via abuse report or automated detection) and DNS fell back to pre-configured GitHub Pages A records, or the actor deliberately migrated after Netlify was flagged. Either way, at that point the domain itself was still not seized. RDAP showed no serverHold or clientHold from NICENIC. The actor, or their fallback configuration, was still in control.

FOFA content searches for title="IAmNotAVillain" and body="IAmNotAVillain" returned only imnotavillain.xyz. No mirrors, clones, or additional sites carrying the same content were detected. OTX, ThreatFox, URLHaus, and Hybrid Analysis have no records for either domain. No threat intel community has published IOC feeds for this actor yet.

Update, September 16: The Registry Reaches Over the Registrar

The backup domain did not survive the day. RDAP data from the .xyz registry shows imnotavillain.xyz was last modified at 15:53:21 UTC on September 15, about four hours after the hosting shift, and now carries serverHold and serverTransferProhibited. As of September 16 the domain returns NXDOMAIN. The nameservers are unchanged, but nothing sits behind them.

The status flags tell the more interesting story. The primary domain received both serverHold (registry level) and clientHold (registrar level): the registry and GoDaddy acted together. The backup received only serverHold. NICENIC never applied a clientHold; the clientTransferProhibited and clientDeleteProhibited flags on the domain date from registration and are registrar defaults. The Hong Kong registrar did not act. The .xyz registry, which sits above every registrar in the TLD, acted for it.

This is the limit of registrar arbitrage. Picking a registrar in a slow jurisdiction buys time against that registrar's abuse desk, but every .xyz domain is ultimately controlled by the TLD registry (XYZ.COM LLC, operating on the CentralNic backend), and a registry-level serverHold removes the domain from the zone regardless of who registered it or where. The primary lasted about 26 hours. The backup lasted about 31. Chinese nameservers and a Hong Kong registrar bought the actor roughly five hours.

Infrastructure Summary Two parallel stacks: one disposable (US-based, free-tier, seized within 26 hours) and one meant to be resilient (HK registrar, Chinese nameservers) that survived a hosting migration from Netlify to GitHub Pages and then fell to a registry-level hold within 31 hours. Both stacks used commodity services requiring minimal identity verification. Standard infrastructure pivoting yielded no additional actor-controlled assets.

Entity Relationship Map

The relationships uncovered during the investigation, condensed from the interactive map used internally. Relationships that are claimed, historical, or based on shared infrastructure are marked as such.

FromRelationshipToNote
IAmNotAVillainoperatesiamnotavillain.xyz
IAmNotAVillainbackupimnotavillain.xyz
iamnotavillain.xyzsubdomainpay.iamnotavillain.xyzDedicated DV cert
IAmNotAVillainposts leaksTelegramChannel rotation 2 to 3
IAmNotAVillainhosting accountGitHub (iamnotavillain)Created 2025-12-06
IAmNotAVillainbackup accountGitHub (gracemattsson)Created 2026-07-04, 59 commits, 7 stamped UTC-7
imnotavillain.xyzCNAMEgracemattsson.github.ioTies both domains to one operator
IAmNotAVillaincontactSessionID constant across all commits
Revolut Smilikformer associateIAmNotAVillainClaimed by IAmNotAVillain
Revolut Smilikclaims breachRevolutUnverified
iamnotavillain.xyzA record185.199.108-111.153GitHub Pages, shared
imnotavillain.xyzformer A record75.2.60.5Netlify / AWS GA, shared
imnotavillain.xyzA record (Sep 15)185.199.108-111.153GitHub Pages, shared
imnotavillain.xyzNS154.85.54.43, 43.162.114.218NICENIC, Baidu HK + Tencent
iamnotavillain.xyzregistered atGoDaddy
imnotavillain.xyzregistered atNICENIC (HK)
imnotavillain.xyzformerly hostedNetlifyDrop UUID captured
IAmNotAVillaincompromised (claimed)Italian law enforcementUnverified
Italian law enforcement mailboxfraudulent EDRRevolutConfirmed by Revolut

5. Darknet Signal: A Revolut Account Shop Restocks

Threat hunting doesn't stop at the actor's own infrastructure. A keyword sweep for "revolut" across darknet marketplaces during the investigation surfaced a vendor storefront that has nothing to do with extortion and everything to do with cashing out.

The shop sells access to Revolut accounts. It is not new, and it was reachable throughout our monitoring window. What changed is the stock. On Wednesday, September 16, 2026 the listing was updated: the inventory counter showed 52 available accounts, and the page carried a "BACK TO SCHOOL, SALE All prices -55%" promotion under the banner "Your Revolut Account vendor is back online!" The "back online" wording is the vendor's own marketing, not a return from downtime. Each row lists an internal ID, the account balance (mostly in USD, some in EUR), the card status (confirmed VISA or Mastercard credit or debit, or "two or more confirmed cards"), the account holder's country (predominantly US states, with Austria and Germany for the EU entries), and a price. Prices ranged from 68 to 225 USD, which works out to roughly 5 to 7 percent of the listed balance. Several of the higher-balance entries were already marked "SOLD" at the time of capture.

Figure 5: Darknet Revolut account storefront, inventory refreshed September 16, 2026. 52 accounts listed, priced at roughly 5 to 7 percent of balance. Captured through keyword monitoring; the marketplace was not interacted with.

What This Is, and What It Isn't

Timing is the only thing linking this storefront to the breach: the inventory refresh landed four days after Revolut's disclosure and one day after the leak domains started falling. That is suggestive, not evidence. Three things argue for caution:

  • Different product. IAmNotAVillain claims to hold KYC documents, addresses and transaction histories, the raw material for identity fraud and targeted extortion. The shop sells working account access with confirmed cards and balances. Turning KYC data into a logged-in Revolut account with a confirmed card requires an account takeover step (SIM swap, phishing, credential stuffing, or malware on the victim's device) that neither actor has claimed.
  • Different victim profile. Revolut's notifications concentrated on France and Switzerland, with high-net-worth crypto users as the targeting priority according to ZachXBT. The shop's inventory is dominated by US accounts with balances between roughly 1,100 and 4,700 dollars.
  • Pre-existing operation. The shop predates the breach and stayed reachable throughout; the "back online" banner is marketing copy, not a return from downtime. Revolut account vendors are a long-running fixture of carding markets, and a seasonal sale is not unusual for them.

Our assessment: low confidence that this inventory is sourced from the fraudulent EDR data set. The more likely reading is an opportunistic operator riding the news cycle, restocking while "Revolut" is a hot keyword and buyers are paying attention. That is still worth tracking. After a breach that exposes KYC material, downstream account shops are where the data eventually surfaces, and a shift in this vendor's inventory toward French, Swiss or crypto-heavy accounts would be the signal that changes the assessment. The storefront address is not published in this report; it remains under monitoring.


6. Attack Description: The Compliance Pipeline as an Exfiltration Channel

Revolut sent the data voluntarily, through its own compliance pipeline, in response to what it believed was a legitimate law enforcement request.

The technique is a Fraudulent Emergency Data Request (EDR): compromise a real law enforcement email account, then submit data requests that bypass normal legal process (subpoenas, court orders, MLAT treaties) by invoking imminent threat to life. It works because it is legitimate infrastructure. The compromised Italian LE mailbox passes SPF, DKIM, and DMARC. Every automated check says "this is real." The only thing wrong is the person at the keyboard.

The Fundamental Gap Email authentication systems (SPF, DKIM, DMARC) verify that a message came from an authorized server for a domain. They do not verify that the specific mailbox was not compromised or that the human sending the message is who they claim to be. A fraudulent EDR from a compromised government email account passes every automated check that exists.

According to the actor's claims on iamnotavillain.xyz, the operation ran for six months, they compromised multiple Italian law enforcement departments, and they hold 147 GB of Italian government data including internal documents, calendars, personal files, and the chat logs of a federal officer arguing with their spouse. The Italian data claims remain unverified. Italian law enforcement has not issued a public statement.

What Revolut has confirmed: they disclosed customer data including full names, dates of birth, postal and email addresses, phone numbers, passport and driver's license copies, KYC verification selfies, IBANs, account statements, full transaction histories (including cryptocurrency), and wallet reference numbers. The Financial Times reported approximately 680 customers were contacted, spread across roughly 30 countries, with France and Switzerland particularly affected. Blockchain investigator ZachXBT identified high-net-worth crypto users as a targeting priority.


7. Attribution: Two Actors, One Breach, Zero Trust

IAmNotAVillain (Primary Actor)

The primary actor presents as the breach originator and operator. Evidence supporting this claim:

  1. The GitHub account predates the public operation by months (see Section 4), consistent with long-term planning rather than opportunistic data resale.
  2. The website text references "the originals, the volume, the conversations, and the companies that sent it," implying access to the original EDR correspondence, not just the resulting data.
  3. The jurisdictionally diversified backup infrastructure suggests operational sophistication beyond that of a data reseller.
  4. The actor has demonstrably more data than what's been published. The "other companies" reference implies multiple targets.

Confidence level: moderate that this actor was involved in the original operation. The pre-positioned GitHub account is the strongest indicator. However, "involved in" and "orchestrated" are different claims, and nothing publicly verifiable confirms the six-month operational timeline or the Italian law enforcement compromise.

Revolut Smilik (Secondary Actor)

The name "Revolut Smilik" surfaced independently in four sources: @IntCyberDigest on X (who was in direct contact with both actors), CityAm, CryptoPotato, and CityAm again in a separate article. IntCyberDigest described Smilik as having "launched a website" and claiming credit for the breach, with the same 10,000 BTC demand.

IAmNotAVillain's website describes Smilik as "an impersonator and scammer who used to work with us" who "took a small sample we handed him." If true, this is a classic falling-out between collaborators: one partner decides to go solo and the other goes public to discredit them.

We could not identify any infrastructure belonging to Revolut Smilik. No domains, no Telegram channels, no dark web presence. An actor who allegedly launched a website and posted across "several Telegram channels" left zero discoverable footprint. Confidence level: low-to-moderate that Smilik is a distinct individual rather than a sock puppet. The strongest evidence for a real second actor is IntCyberDigest's independent communication with both.

LAPSUS$ Comparison

The technique maps closely to LAPSUS$ (tracked by Microsoft as Strawberry Tempest, DEV-0537; MITRE G1004). LAPSUS$ pioneered the fraudulent EDR technique against Apple, Meta, and Discord in 2021 and 2022 using the Recursion Team's forged requests. Same social engineering approach, same target class (tech and fintech), same operational model (extortion without ransomware deployment). However, no technical overlap with known LAPSUS$ infrastructure was identified, and LAPSUS$ historically operated through compromised credentials purchased from initial access brokers, not through direct law enforcement system compromise. No formal attribution link is established.


8. Timeline

DateEvent
2025-12-06 11:20 UTCGitHub account iamnotavillain created (ID: 248150151). All fields left blank. No activity recorded.
February 2026Milan prosecution of 6 individuals using authentic Italian Interior Ministry and Carabinieri email accounts for data theft. Establishes precedent for Italian LE email compromise.
~March 2026 (claimed, unverified)Actor claims the operation against Italian law enforcement systems began. Six-month operational window alleged.
June 2026BrinzTech (initial access broker) begins selling verified government and LE email access at $20 to $585 per account, explicitly marketed for EDR fraud.
2026-09-11 21:59 UTCFraudulent emergency data requests sent to Revolut from a compromised Italian law enforcement email account. Requests pass SPF, DKIM, and DMARC validation.
2026-09-12Revolut confirms the breach. Blocks the requesting email address, notifies the impersonated agency and UK regulators (FCA, ICO).
2026-09-13 23:29 UTCiamnotavillain.xyz registered via GoDaddy. GitHub Pages repo deployed. GoDaddy DV certificate issued for pay.iamnotavillain.xyz.
2026-09-13 (evening)Actor begins publishing data samples on X and Telegram (t.me/IAmNotAVillain2). @zachxbt first to disclose the breach publicly.
2026-09-14 09:06 UTCBackup domain imnotavillain.xyz registered via NICENIC (Hong Kong) with Chinese nameserver infrastructure and Netlify hosting. Jurisdictional diversification.
2026-09-14 14:11 UTCFirst commit to the gracemattsson repo. CNAME created one minute later. Backup site build begins.
2026-09-14 ~20:00 UTCurlscan captures both sites live (HTTP 200). Screenshots preserved. Telegram link discovered in DOM data.
2026-09-14 21:53 UTCRepo CNAME switched from iamnotavillain.xyz to imnotavillain.xyz, with follow-up edits at 22:21 and 22:47 UTC (the latter two stamped UTC-7). GitHub Pages fallback pre-positioned nearly four hours before the primary seizure.
2026-09-14 23:04 UTCurlscan confirms imnotavillain.xyz serving from Netlify (75.2.60.5). Netlify Drop UUID captured as forensic artifact.
2026-09-15 01:44 UTCPrimary domain seized. Registry serverHold plus GoDaddy clientHold and clientDeleteProhibited applied. Domain removed from DNS with evidence preserved.
2026-09-15 09:24 UTC"Update Telegram link in contact section" committed (channel rotation to IAmNotAVillain3). index.html and leaks.html deleted and re-added by 09:34 UTC. All five commits stamped UTC-7.
2026-09-15 ~11:39 UTCBackup domain A records shift from Netlify (75.2.60.5) to GitHub Pages (185.199.108-111.153). Netlify deployment removed or migrated. Domain not yet held by registry or registrar.
2026-09-15 15:53 UTCBackup domain placed on serverHold by the .xyz registry. NICENIC applies no clientHold. Roughly 31 hours after registration.
2026-09-15 16:14 to 17:27 UTCActor keeps committing after the hold. Five image files deleted within one minute, new files uploaded, index.html and leaks.html updated, "Fix typos in metadata and update links" at 17:14 UTC. Repo at 59 commits and still public.
2026-09-15Crimson7 investigation conducted. Primary domain unreachable, backup domain observed live on new hosting earlier in the day.
2026-09-16Both domains return NXDOMAIN. Darknet Revolut account storefront refreshes inventory (52 accounts, 55 percent sale banner). Link to the breach unconfirmed. Report published.

9. Ecosystem Context

The Emergency Request Problem Isn't New, It's Accelerating

The supply chain enabling this attack is maturing fast. The FBI flagged a spike in government email access sales on criminal forums in November 2024. By 2025, Google confirmed a "Scattered Lapsus$ Hunters" member had created a fraudulent LERS portal account via compromised police email. By June 2026, IAB BrinzTech was selling government credentials for $20 to $585, explicitly marketed for EDR abuse. Kodex Global, which runs LE verification platforms for tech companies, reports that roughly 30 percent of emergency data requests fail secondary verification when manual callbacks are applied, and nearly 4,000 LE accounts are suspended annually across their platforms. Actors "Pwnstar" and "Pwnipotent" sell turnkey fake EDR services at $1,000 to $3,000 per request. Kodex coined the term Law Enforcement Email Compromise (LEEC), a deliberate parallel to BEC.

In February 2026, Milan prosecutors charged six individuals for using authentic Italian Interior Ministry and Carabinieri email accounts for data theft. The Italian LE email ecosystem was demonstrably compromised before this actor claims to have entered it.

The Monetization Side

Stolen fintech data rarely stays with the actor who obtained it. It moves down a chain of resellers, fraud crews and account shops, and each hop strips context: a KYC bundle becomes a synthetic identity, a synthetic identity becomes a verified account, a verified account becomes a line item with a price. That is why the storefront in Section 5 matters even without a confirmed link. It is the kind of place this data ends up, and a change in its inventory profile is a cheaper early warning than waiting for the next leak post.


10. MITRE ATT&CK Mapping

Mapped only to observed or confirmed behaviors. Speculative additions omitted.

TechniqueIDObserved Behavior
Social Engineering: ImpersonationT1684.001Actor impersonated a government agency to submit data requests. Revolut confirmed they responded to a request from "a party who impersonated a government agency."
Compromise Accounts: Email AccountsT1586.002The fraudulent request originated from a legitimate government domain email, passing SPF, DKIM and DMARC, confirming mailbox compromise rather than domain spoofing.
Gather Victim Identity InformationT1589Inferred. ZachXBT identified targeting of high-net-worth crypto users. Victim selection is consistent with prior intelligence gathering, but no direct reconnaissance activity was observed.
Gather Victim Org Information: Business RelationshipsT1591.002Actor understood the EDR workflow: which agencies Revolut would trust, what format requests should take, and when to send them (21:59 UTC, outside Italian business hours).
Valid AccountsT1078Operated from compromised government credentials. The email account used was a real, authorized account for the requesting domain.

Worth noting what's absent: no Initial Access to Revolut's network, no Execution, no Persistence, no Lateral Movement, no C2. The company's own compliance process is the exfiltration channel. We considered mapping T1199 (Trusted Relationship), T1213 (Data from Information Repositories), and T1567 (Exfiltration Over Web Service), but each is a stretch. T1199 describes privileged third-party network access, not business-process trust. T1213 and T1567 describe attacker-initiated data collection, not a victim voluntarily sending data through their own compliance pipeline. The ATT&CK framework maps awkwardly onto social engineering attacks that never touch the target's infrastructure.


11. Indicators of Compromise

Copy-paste ready. Context included for each indicator. Status as of September 16, 2026.

TypeValueContextStatus
Domainiamnotavillain[.]xyzPrimary leak site (GoDaddy / GitHub Pages)SEIZED (registry + registrar hold, Sep 15 01:44 UTC)
Domainimnotavillain[.]xyzBackup leak site (NICENIC HK / Netlify, later GitHub Pages)SEIZED (registry hold, Sep 15 15:53 UTC)
Domainpay.iamnotavillain[.]xyzPayment subdomain, dedicated DV certSEIZED
Telegramt.me/IAmNotAVillain2, t.me/IAmNotAVillain3Leak channel, ban-evasion rotation. On channel 3 as of Sep 15.ACTIVE
GitHubgithub.com/iamnotavillainPrimary hosting account (ID: 248150151)EXISTS
GitHubgithub.com/gracemattssonBackup hosting account (ID: 299922428). CNAME history ties both domains to the same operator.ACTIVE
Repogracemattsson/9hpj8ue5r6s12oim.9hpj8ue5r6s12oim123Backup site source. 59 commits as of Sep 15 17:27 UTC, deleted files recoverable, last activity after the registry hold.PUBLIC
Emailizaelwongfjgd@outlook[.]comGit commit email on gracemattsson repo. Burner, no other internet presence.ATTRIBUTION LEAD
Session0548b3c2be496218baa2314386787badfd458a868240a19ede82eabb6a13dd2c26Session messenger ID, constant across all commitsACTIVE
IP75.2.60[.]5Backup domain, Netlify via AWS Global AcceleratorSHARED INFRA
IP185.199.108[.]153GitHub Pages CDN (both domains)SHARED INFRA
IP185.199.109[.]153GitHub Pages CDN (both domains)SHARED INFRA
IP185.199.110[.]153GitHub Pages CDN (both domains)SHARED INFRA
IP185.199.111[.]153GitHub Pages CDN (both domains)SHARED INFRA
IP43.162.114[.]218ns4.my-ndns.com, NICENIC registrar NS (Tencent). Do not block, shared registrar infra.REGISTRAR
IP154.85.54[.]43ns3.my-ndns.com, NICENIC registrar NS (Baidu HK). Do not block, shared registrar infra.REGISTRAR
TLS Serial00fdfeee3a4ff302f2GoDaddy DV cert for pay.iamnotavillain.xyzSEIZED
Netlify UUID7e4d29ab-6f70-46a2-bb4d-b2fe5de57882Netlify Drop deployment for backup domainFORENSIC ARTIFACT
JARM40d40d40d00000000043d43d00043d6aff5ab0f4fc31897186312c9e639319Netlify TLS fingerprint (shared, not unique to actor)SHARED
NSns3.my-ndns[.]comNICENIC nameserver (backup domain)ACTIVE
NSns4.my-ndns[.]comNICENIC nameserver (backup domain)ACTIVE
ActorIAmNotAVillainPrimary threat actor handleACTIVE
ActorRevolut SmilikSecondary actor / former associateINFRA UNKNOWN

The darknet Revolut account storefront described in Section 5 is deliberately excluded from this table. It is not attributed to either actor, and publishing its address would serve buyers more than defenders.


12. Key Takeaways

  • Verify emergency data requests out of band. SPF, DKIM and DMARC prove the server, not the sender. A callback to a published number at the requesting agency, or verification through a platform such as Kodex, is the only control that would have stopped this. Kodex's own figure, roughly 30 percent of EDRs failing secondary verification, says how often that callback matters.
  • The compliance pipeline is an attack surface. No malware, no lateral movement, no exfiltration tooling. The victim's own legal process moved the data. Threat models that start at the network perimeter will not see this.
  • Registrar arbitrage does not beat the registry. A Hong Kong registrar and Chinese nameservers bought the actor about five hours. The .xyz registry applied serverHold without the registrar ever acting. Takedown requests that go to the registry, not just the registrar, close the jurisdictional gap.
  • OPSEC fails in the metadata. The actor's front account was clean. The backup was tied to it by a CNAME record, a public repo, a git commit email, and seven commits stamped with a UTC-7 clock from a local git client. Pivot on the infrastructure that was set up in a hurry, and read the commit log as a timeline: it dated the CNAME switch, the Telegram rotation, and the post-hold cleanup to the second.
  • Watch the account shops. A KYC breach becomes account fraud downstream. Monitoring vendor inventory for the affected brand, and for shifts in country and balance profile, is a cheap early warning that does not depend on the extortion actor posting anything.

This investigation was conducted using passive intelligence collection only. All sources are open-source or community-contributed. No attacker infrastructure was accessed, modified, or disrupted.

Case: IAmNotAVillain / Revolut Breach. Investigation conducted September 15, 2026, updated September 16, 2026. TLP:CLEAR.