Imnotavillain is a small but active data leak site (DLS) on the Tor network. They have two published breaches on their .onion site, and both have downloadable biteblob samples. That’s more working evidence than most ransomware groups put out.
Site: o6rtgcjdjqyimjxexpejddhdfbehsjn4fcsazfkgwydeb27gqhtdntyd.onion
Telegram: @tempuser9063
Session: 0548b3c2be496218baa2314386787badfd458a868240a19ede82eabb6a13dd2c26
Revolut — 680 High-Net-Worth Users
The biteblob samples for this breach are already live:
- Irfan Kokli —
Irfan Kokli-account_data.zip(30.61 KB) +Irfan Kokli-transactions-history_en-mt_844b2a.zip(2.37 MB) - Jonas Kraft —
Jonas Kraft-transactions-history_de-de_bdf280.zip(282.2 KB) - 9+ other named victims, all with biteblob account data + transaction links, password:
IAmNotAVillain
The group’s claim: Revolut received a report about a user database, ignored it, and the DLS is exposing the data because Revolut sent customer records from a different jurisdiction than where they’re based.
Data types confirmed: Full name, email, phone, address, account identifiers, bank account details, crypto withdrawals, crypto deposits, fiat transactions, KYC documents, KYC verification selfie.
All biteblob links are marked “Reported as abuse material / Link Unauthorized” — the samples exist, they’re just behind some access control now.
Italy — 130,000+ Federal Officers
The bigger breach. The DLS pages describe personal information on 130K+ federal officers across top departments, including:
- Unsecured copies of identity documents in official mailboxes (passports, health cards, immigration papers, all PII)
- An arms license for an Israeli-flagged vessel left in an official email alongside hundreds of similar documents
- Diplomatic passports sitting unprotected in official systems
This one hasn’t been named after any specific government yet — the DLS just says “Italy” and shows sample biteblob links for named individuals like Jonas and Kaiming.
The Impostor Story
The DLS mentions something interesting: a former employee who used to work with them took a small sample the group handed over and is now claiming the breach as his own. Their warning:
“That cut is not the full set. Revolut and the other companies sent the data to us. He did not do this. We can prove it: the originals, the volume, the conversations, and the companies that sent it. Do not deal with him. You WILL get scammed.”
Whether the impostor is legit or not, it’s a common DLS trope — but the biteblob samples with matching password IAmNotAVillain across multiple victims suggest this group actually has data.
Exclusion Window
Users can pay to have their data removed before the sale is finalized. Once the sale goes final, no more removals are possible. This applies to both the 680 high-net-worth Revolut users and the 130K+ Italian officers.
Why This DLS Matters
Imnotavillain is small — two breaches total. But they’re doing the darknet intel thing right: publish claims, provide biteblob samples, list the data types, and maintain a clear .onion presence. Most DLS groups just put up a homepage with a Telegram handle and a list of company names. This one has downloadable evidence.
For threat intelligence, the key signals are:
- Revolut KYC data + transactions from a cross-jurisdictional export
- Italy federal officer records with physical document scans
- Active exclusion window (means data hasn’t been sold yet)
- Former employee impostor (adds a layer of operational complexity)
If the biteblob samples contain real KYC documents, this could be a high-signal source for identity verification testing and account takeover campaigns. Worth monitoring.