British fintech Revolut confirmed that it handed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain, Reuters and TechCrunch reported on September 12, 2026. The exposed data included customers' identity and contact details.
No vulnerability was exploited in the usual sense. The request looked official because it came from an address the receiving team had every reason to trust, and the company's legal-response process did what it was designed to do: comply.
Why it matters
Every large consumer platform runs a channel for law enforcement and regulatory data requests, and that channel is deliberately built to move quickly. It is also, at most companies, staffed by a small team judging authenticity from the face of a document and the domain of an email — controls that a compromised or spoofed government mailbox defeats entirely.
For customers, the loss here is identity and contact data, the raw material for account takeover and targeted fraud. For the industry, the lesson is that the emergency-disclosure path is now a named target, not a theoretical one.
How it works
Fraudulent legal requests work by borrowing institutional trust. An attacker who controls or convincingly imitates an official email domain sends a request for subscriber information, often marked urgent, and the recipient's verification amounts to checking that the sender's domain is real. Where the domain genuinely belongs to an agency — because a mailbox there has been compromised — domain checks provide no signal at all.
The counter-control is out-of-band verification: confirming the request through a separately obtained contact for the agency, and through a known case or reference number, before any data leaves.
Evidence
Reuters reported on September 12, 2026 that Revolut confirmed sensitive customer information was disclosed to an unauthorized third party after the company fell for fake government requests. TechCrunch's report the same day specifies that the fraudulent requests were sent from a legitimate government agency email domain and that exposed data included customers' identity and contact details.
What defenders should do
Any company that responds to government or law-enforcement data requests should treat sender domain as insufficient proof of authenticity. Require a verification callback to a number obtained independently of the request, log every disclosure with the identity of the requesting officer and the legal basis cited, and set a hard rule that urgency never removes the verification step.
Two further measures cost little: cap what the emergency path can return without escalation, and periodically audit past disclosures against agency records. Companies that have done the latter have generally found at least one request they should not have honoured.
What happens next
Revolut operates under UK and EU data-protection law, so regulatory review of the disclosure and the controls around it is likely. More broadly, expect renewed pressure for a verified, cryptographically authenticated channel for government data requests, an idea that has circulated for years and repeatedly stalled on the fact that thousands of agencies would have to adopt it.
