Revolut falls for fake government requests, hands over customer data
- ID
- 24154
- Status
- summarized
- Published
- 14 Sep 2026, 7:26 PM
- Fetched
- 14 Sep 2026, 8:07 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/cyber-crime/2026/09/14/revolut-falls-for-fake-government-requests-hands-over-customer-data/5296118
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 6.5
- Created
- 14 Sep 2026, 8:11 PM
- Tags
- Audience
- developerssaas_founders
What happened
Revolut exposed sensitive customer KYC data—including passports, driver's licenses, verification selfies, IBANs, and full transaction histories—after falling for fraudulent information requests sent from a legitimate government agency's email domain. Self-proclaimed culprits are demanding 10,000 Bitcoin, and Revolut has not disclosed how many customers were affected.
Why it matters
If you build or operate a fintech, SaaS, or any platform that responds to government or law enforcement data requests, this is a concrete reminder that a request coming from a genuine government email domain is not sufficient verification. Builders should implement out-of-band verification workflows—callback to a known agency number, secondary channel confirmation—before releasing customer PII, rather than trusting sender domain alone.
Discussion angle
What verification steps should a Malaysian fintech or SaaS startup have in place before responding to a data request that appears to come from a government domain like gov.my—especially given that email spoofing or compromised government accounts are realistic attack vectors?