AI Weekly Malaysia

Back to items Summaries

Revolut confirms customer data breach through fake government requests

ID
23800
Status
summarized
Published
12 Sep 2026, 10:40 PM
Fetched
12 Sep 2026, 10:47 PM
Provider
TechCrunch
Category
technology
Original URL
https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/
Source URL
https://techcrunch.com/feed/

Summary

Score
5.5
Created
12 Sep 2026, 10:47 PM
Tags
Audience
developerssaas_foundersstartup_founders

What happened

Revolut disclosed sensitive customer data—including passport copies, driver's licenses, verification selfies, and transaction histories—to an unauthorized third party who submitted fraudulent information requests from a legitimate government agency email domain. Revolut did not disclose the number of affected customers, the specific market, or which government agency's domain was compromised, but stated its systems and customer funds were unaffected.

Why it matters

If you operate a SaaS or fintech handling KYC data, this is a concrete reminder that 'the request came from a .gov email' is not sufficient verification. Builders handling identity documents should implement a secondary verification channel (e.g., callback to a known agency number, case ID validation) before releasing customer PII, especially in markets like Malaysia where digital government services are expanding and spoofing legitimate agency domains is plausible.

Discussion angle

What verification workflow should your team use before responding to any government or law enforcement data request—do you have a documented second-channel check, or would your support team hand over customer passports if the email looked official?

Top