Revolut has not had direct contact with the group claiming responsibility for a data breach and has not received a ransom demand, according to a company spokesperson cited by Reuters.

Revolut customers have reportedly been notified that their personal and financial records, including Bitcoin transaction histories, were shared following a potentially fraudulent government request.

The disclosed data reportedly includes identity documents, contact details, IBANs and account records. Onchain investigator ZachXBT said the incident appeared to target high-net-worth users but was likely limited in size.

The Financial Times reported earlier this week that attackers had demanded $3 million within 24 hours, threatening to sell confidential information belonging to hundreds of customers to other criminal groups.

A source familiar with the matter said Revolut’s core infrastructure, databases and customer accounts were not compromised. About 680 customers are understood to have been affected by the breach, according to the source. The group, identifying itself as “iamnotavillain,” published an online ultimatum on Wednesday afternoon accompanied by a countdown clock, the FT reported.

The group told the FT that the website was being used to issue its demands for the first time and said there had been no negotiations with Revolut.