Jessica Entwistle
September 14 2026
TechCrunch reports that Revolut has confirmed a customer data breach caused by fraudulent government data requests. Attackers impersonated law enforcement or regulatory authorities to submit fake legal requests for customer information, successfully obtaining personal data before the fraud was detected. Revolut has notified affected customers and alerted the relevant government agencies, law enforcement and financial regulators. The incident highlights a growing supply chain risk: attackers are increasingly targeting the processes organisations use to comply with legitimate legal obligations, exploiting trust in official channels to gain access to sensitive information. This type of attack is sometimes referred to as "legal process abuse" or "fraudulent legal requests," and it represents a sophisticated form of social engineering that targets operational processes rather than technical systems.
For UK organisations, this incident is a reminder that supply chain risk extends beyond technology vendors and software dependencies. It also includes the administrative and legal processes that organisations rely on to operate compliantly. Revolut is a financial services provider with mature compliance and legal teams, yet attackers were still able to exploit the process used to respond to government requests. This suggests that even well-resourced organisations can be vulnerable to social engineering that targets operational processes rather than technical systems. The broader lesson is that organisations should consider how they verify the legitimacy of legal requests, regulatory inquiries or official communications, particularly when those requests involve disclosing customer or employee data. For organisations in regulated sectors such as financial services, healthcare, legal or telecommunications, this risk is particularly acute because they are required by law to respond to legitimate requests from law enforcement, regulators or other government agencies. The challenge is distinguishing legitimate requests from fraudulent ones, especially when attackers are capable of forging official documents, using plausible email addresses or exploiting procedural gaps in how requests are validated.
Organisations should review how legal and regulatory requests are handled, who is authorised to respond to them and what verification steps are in place to confirm their legitimacy. Consider whether your procedures include contacting the requesting agency directly using independently verified contact details, rather than relying solely on contact information provided in the request itself. Review whether your legal, compliance and customer service teams are trained to recognise red flags in fraudulent requests, such as unusual formatting, grammatical errors, requests for data outside normal scope or pressure to respond urgently. Ensure that there is a clear escalation path for requests that appear suspicious or unusual, and that staff feel empowered to question requests that do not follow expected procedures. Finally, consider whether your organisation has a process for validating the identity of requesters, such as requiring official identification, verifying badge numbers or confirming requests through secure government portals where available. This is not about obstructing legitimate law enforcement or regulatory activity; it is about ensuring that your organisation has proportionate safeguards in place to prevent fraudulent requests from succeeding.
Source: TechCrunch