Revolut said Thursday it had not received any direct contact from the individuals or group claiming responsibility for a customer data breach, despite multiple public ransom demands. According to Cointelegraph, a group calling itself “IAmNotAVillain” publicly demanded 6,000 Monero (XMR) from Revolut within 24 hours and threatened to sell the customer records to other criminal groups. The Financial Times reported Wednesday that the demand was made in connection with the breach Revolut first disclosed last week, while Italian authorities have widened their investigation into how a government email account was allegedly used to obtain customer data. A Revolut spokesperson said the company had not received any direct contact or demand from the parties making the claims. The public ultimatum has added uncertainty over who is behind the alleged breach, especially as “IAmNotAVillain” is not the only name linked to responsibility claims. Its website, iamnotavillain.xyz, was unavailable when checked by Cointelegraph at the time of publication. An earlier group calling itself “Revolut Smilik” reportedly demanded 10,000 Bitcoin, far more than the current Monero demand. IAmNotAVillain disputed that claim on its website, saying a former associate had received only a small sample of the data before taking credit for the breach and warning others not to deal with the rival claimant. Cybersecurity-focused account Dark Web Informer also identified another website, revoloot.lol, linked to a separate actor claiming responsibility, further complicating efforts to determine who controls the stolen customer records. The revoloot.lol website was also unavailable when checked by Cointelegraph.