AI Weekly Malaysia

Back to items Summaries

Revolut falls for fake government requests, hands over customer data

ID
24154
Status
summarized
Published
14 Sep 2026, 7:26 PM
Fetched
14 Sep 2026, 8:07 PM
Provider
The Register
Category
technology
Original URL
https://www.theregister.com/cyber-crime/2026/09/14/revolut-falls-for-fake-government-requests-hands-over-customer-data/5296118
Source URL
https://www.theregister.com/headlines.atom

Summary

Score
6.5
Created
14 Sep 2026, 8:11 PM
Tags
Audience
developerssaas_founders

What happened

Revolut exposed sensitive customer KYC data—including passports, driver's licenses, verification selfies, IBANs, and full transaction histories—after falling for fraudulent information requests sent from a legitimate government agency's email domain. Self-proclaimed culprits are demanding 10,000 Bitcoin, and Revolut has not disclosed how many customers were affected.

Why it matters

If you build or operate a fintech, SaaS, or any platform that responds to government or law enforcement data requests, this is a concrete reminder that a request coming from a genuine government email domain is not sufficient verification. Builders should implement out-of-band verification workflows—callback to a known agency number, secondary channel confirmation—before releasing customer PII, rather than trusting sender domain alone.

Discussion angle

What verification steps should a Malaysian fintech or SaaS startup have in place before responding to a data request that appears to come from a government domain like gov.my—especially given that email spoofing or compromised government accounts are realistic attack vectors?

Top