Incident pathway

How a trusted request can become a data disclosure

Each step can look routine. The control point is independent verification before sensitive records are released.

1
REQUESTOfficial-looking request

The request appears to come through a legitimate government channel.

2
VERIFYVerify the requester

Confirm identity, legal authority and scope through an independent route.

3
DISCLOSEDisclosure risk

Sensitive customer records can leave through a normal compliance process.

Documented public incident. No live system or private customer record is embedded here.
What the example presents
Official information request
What to examine
Requester authority must be independently verified

Audience / at-risk group

Banks, fintechs, legal and compliance teams; affected customers as data subjects

What you can notice

  • The reported attack targeted a compliance workflow rather than a public scam landing page.
  • Revolut told TechCrunch the requests came from a legitimate government-agency email domain and were fraudulent.
  • Reportedly exposed data included identity and contact details, identity-document copies, and possibly selfies, statements and transaction histories.
  • Revolut said its systems and customer funds were unaffected, while affected customers were contacted directly.

The takeaway

For regulated firms, a trusted domain is not enough. Sensitive data requests need independent requester verification, authority checks and escalation paths before records leave the institution.

What the source reports

TechCrunch reported on 12 September 2026 that Revolut confirmed a limited number of customers were impacted after fraudulent information requests were sent from a legitimate government-agency email domain. The Block separately reported that the incident involved KYC and account data, with possible Bitcoin transaction history exposure. The Financial Times later reported that nearly 700 customers were affected and that the UK Information Commissioner's Office had opened an investigation.

What this evidence cannot tell us

This case is based on public reporting and Revolut statements quoted by those outlets. The government agency, exact request documents, affected markets and final regulator findings were not publicly established in these sources. The incident should not be described as customer funds being stolen or Revolut's core systems being compromised unless later evidence supports that.

Suggest a correction