Key takeaways
- Revolut said on September 12 that an outside party obtained sensitive customer data after using a spoofed email address on a legitimate government agency domain; exposed data included names, birth dates, passport scans, verification selfies, and transaction histories, while Revolut said customer funds were not touched.
- Revolut responded within days by blocking the address and notifying regulators and law enforcement, but did not disclose which agency domain was spoofed or how many customers were affected.
- The article ties the breach to abuse of emergency data request workflows, which allow police to seek user data without a subpoena in claimed life-safety situations, and cites a similar Verizon case where a stalker posing as a police officer used a fake warrant to get a victim’s address and phone records.
- Named experts frame the attack as a trust problem: Alex Stamos said adversaries use the simplest method that works, John Villasenor of Brookings argued AI is eroding traditional signals of authenticity, and Dr. Lorrie Cranor said people are being forced to make trust decisions they should not have to make unsupported.
- Bruce Schneier’s long-standing view that social engineering attacks the user rather than the computer is used to argue that legal, compliance, finance, and front-desk staff all need the same pause-and-verify habit when facing manufactured urgency.
- The concrete fix recommended is a formal verification process for any government or legal request: use a callback to a publicly listed agency number rather than contact details in the message, assign a single owner for such decisions, treat urgency as a cue to slow down, and rehearse the scenario in advance.
Inside the Breach
On September 12, Revolut confirmed that an outside party had obtained sensitive customer information by using a spoofed email address built on a legitimate government agency domain. The message looked official enough to answer. Names, birth dates, passport scans, verification selfies, and transaction histories left the building before anyone caught the deception. Revolut has not disclosed which agency’s domain was spoofed or exactly how many customers were affected, and this piece doesn’t speculate on either.
Revolut moved fast once it noticed. The company blocked the address, alerted regulators and law enforcement, and confirmed that customer funds stayed untouched. That response deserves credit. Plenty of companies take weeks to even confirm what happened to them. Revolut confirmed it in days.
The story here goes beyond one bank. Attackers have found a shortcut into corporate data: convince one employee that the request in front of them already belongs on the trusted side of the door.
“Adversaries will do the simplest thing they need to get the results they want,” Alex Stamos, director of the Stanford Internet Observatory and former chief security officer at Facebook and Yahoo, said in his Black Hat USA keynote. A request dressed up as an authority everyone is trained to trust immediately is often the simplest tool available.
Government agencies sit near the top of that list. Companies build entire compliance functions around responding to law enforcement and regulators quickly, often through a process known as an emergency data request, which lets police obtain user data without a subpoena when they claim someone’s safety is at risk. That process protects people every day. It also gives attackers a shortcut, because a request wearing the right letterhead can skip past controls a normal phishing email would trip. Verizon disclosed a similar case years ago, when a stalker posing as a police officer used a fake warrant to obtain a victim’s address and phone records. Revolut’s incident shows the same tactic still works against a well-run company in 2026.
Why It Worked
John Villasenor, a nonresident senior fellow in Governance Studies at the Brookings Institution, has written about how AI is eroding the signals people once relied on to separate fact from fiction. “By exploiting our inclination to trust the reliability of evidence that we see with our own eyes, they can turn fiction into apparent fact,” Villasenor wrote in a Brookings analysis on AI and truth. He was describing deepfake video and audio, but the same principle covers a forged institutional document. Both work by presenting a fake as a credential nobody thinks to question. A spoofed government domain trades on that exact habit. The address checks out. The tone matches official correspondence. The urgency feels justified.
Blame rarely helps after an incident like this one, and this piece isn't assigning any to Revolut or its staff. Whoever handled that request was doing what almost every company trains its people to do: cooperate with law enforcement and cooperate quickly. Dr. Lorrie Cranor, director of Carnegie Mellon’s CyLab Security and Privacy Institute, has spent years studying why capable, well-trained people still get caught by traps like this. “Humans make errors, but they make errors doing things they shouldn’t have to be doing in the first place,” Cranor has said of security processes that hand people split-second trust decisions with no support to back them up.
That idea points straight at the fix. A verification process built for this moment removes the guesswork before an employee ever has to trust their gut against a convincing forgery.
Requests like the one Revolut received usually land with legal, compliance, or trust and safety teams, not the general employee population a typical security awareness program targets. The underlying vulnerability stays the same across departments. Bruce Schneier, a security technologist and fellow at Harvard Kennedy School’s Belfer Center, described this category of attack two decades ago and it still holds today: “They are much more serious and harder to defend against because they attack the user and not the computers.” A verification policy for law enforcement or legal requests belongs with legal and compliance. The instinct that policy depends on, pausing under manufactured urgency before acting on it, has to work the same way whether the person facing it sits in legal, finance, or the front desk. Adaptive builds AI-powered simulations that mirror the pressure tactics behind these requests, from a spoofed executive on a video call to a forged vendor invoice to a fraudulent letter wearing government letterhead, so whichever team owns the decision has practiced it before the day it counts.
What To Do About It
A few practices travel well across any team that handles legal, regulatory, or law enforcement requests as part of its job.
- Build one verified channel for anything claiming government or legal authority: a callback to a publicly listed number for that agency, confirmed independently every time, since a number supplied inside the request itself belongs to the attacker.
- Name one person or team who owns the decision on any message invoking legal or regulatory authority. A request landing on the desk of whoever happens to open the inbox that day puts the decision on the least prepared person available.
- Treat urgency as the signal to slow down. A legitimate agency can wait for a callback. A fraudulent one is counting on the fact that most people won’t ask it to.
- Rehearse the scenario before it shows up live. Teams that have talked through “what would we do if this landed in our inbox tomorrow” respond with calm and speed. Teams encountering the pattern for the first time in production respond with neither.
- Extend the same healthy skepticism companies already apply to a suspicious invoice or a strange executive request to anyone claiming outside authority, government agencies included. The verification muscle is the same one either way.
Schneier has made a related point about security design more broadly: “The problem isn't the users: it’s that we’ve designed our computer systems' security so badly that we demand the user do all of these counterintuitive things.” Practice is what closes that gap in the moment it matters. A team that has rehearsed this exact scenario recognizes it in seconds. A team encountering it live for the first time spends those same seconds deciding whether to believe it.The Pattern, and the Fix
The Pattern, and the Fix
Revolut’s incident will fade from headlines within a news cycle or two, the way most of these stories do. The pattern behind it will not fade nearly as fast. Any company that fields legal requests, regulatory inquiries, or law enforcement outreach, which includes most banks, telecoms, healthcare providers, and platforms handling personal data, holds the same exposure Revolut just encountered.
The good news sits in how solvable this is. A verification habit, once built, works against a forged government letter exactly as well as it works against an impersonated CEO or a fabricated invoice. Companies that use this incident to pressure-test one process today put themselves in a strong position for the next convincing forgery that lands in an inbox.
