Jessica Entwistle
September 15 2026
Revolut has confirmed a customer data breach that occurred through fake government data requests. Attackers submitted fraudulent legal requests impersonating law enforcement or government agencies, successfully convincing Revolut to disclose customer information. The company has notified affected customers and alerted the relevant government agency, law enforcement and financial regulators. The incident highlights a growing trend of attackers abusing legitimate legal and regulatory processes to obtain sensitive data without needing to exploit technical vulnerabilities. This type of attack relies on social engineering and process manipulation rather than traditional hacking techniques, and demonstrates how compliance and operational procedures can themselves become attack vectors if verification steps are not robust.
This incident is significant for UK organisations because it demonstrates how attackers are targeting the processes and procedures that organisations use to comply with legal and regulatory obligations. Many UK businesses receive data requests from law enforcement, regulators or other government bodies, and have established processes for responding to them. If those processes do not include robust verification steps, they can be exploited by attackers who understand how to craft convincing fake requests. The Revolut breach shows that even large, security-conscious financial services organisations can be vulnerable to this type of attack. For organisations that handle customer data, payment information or other sensitive records, this is a reminder that compliance processes themselves need to be treated as potential attack vectors. The incident also highlights the importance of training staff who handle data requests to recognise red flags and verify the legitimacy of requests before disclosing information.
For UK businesses that handle data subject access requests, law enforcement requests or regulatory enquiries, this is a prompt to review verification procedures and ensure that staff understand how to authenticate the legitimacy of requests before disclosing sensitive information. Consider whether your current process includes steps to verify the identity of the requester, confirm the legitimacy of the request through independent channels, and escalate unusual or suspicious requests to senior staff or legal advisers. Review whether staff who handle these requests have received training on how to spot fake requests, and whether they understand the potential consequences of disclosing information to unauthorised parties. Consider whether your organisation maintains records of all data disclosure requests and responses, and whether those records are reviewed regularly to identify patterns or anomalies. Ensure that responsibility for handling legal and regulatory data requests is clearly assigned, and that processes are documented, tested and updated regularly to reflect emerging threats.
Source: TechCrunch