On 12 September 2026, Revolut confirmed that sensitive information relating to some customers had been disclosed to an unauthorised third party. What makes the case unusual is that the fraudsters did not need to penetrate the core banking platform. They submitted requests that appeared official because they came from a legitimate government email domain.

According to Reuters, Revolut says its systems and customer funds were unaffected. The Financial Times reported that roughly 680 people were notified. The information potentially disclosed included personal contact details and copies of identity documents. The UK data protection authority has been notified, and the investigation remains open.

The significance of the incident goes well beyond the number of affected customers. It exposes a category of risk that often receives less attention than payment authentication: the security of the process through which a financial institution lawfully shares information with a public authority.

Reconstructing the compromise chain

The public record supports a probable attack chain, although only the investigation can establish the definitive sequence.

First, the attackers obtained the use of an address within a legitimate government domain. That address was then used to frame an information request as an official inquiry. Second, the sender’s domain appears to have operated as a trust signal. Third, data was disclosed before the fraudulent nature of the request was detected.

The failure therefore occurred between receipt and disclosure. This distinction matters. An email may be technically authentic because it genuinely originated from the displayed domain, while the request itself is fraudulent because the person using the account lacks authority.

The control problem can be stated plainly:

Channel authenticity ≠ requester authority ≠ request legitimacy.

All three dimensions require separate verification.

A government domain is not sufficient evidence

Requests from police, courts or regulators are commonly processed by legal, compliance or operations teams. Controls may include checking the sender’s domain, reviewing a signature, confirming the reference to an investigation and validating the legal basis.

The Revolut case illustrates the limit of placing excessive weight on the first control. If the authority’s mailbox is compromised or a legitimate account is abused, the trusted domain becomes the means of bypass.

A stronger procedure would combine at least five independent controls:

  1. verify the requester’s identity and role through an official directory;
  2. confirm the request using contact details obtained independently of the incoming email;
  3. validate the case reference, legal basis, scope and relevant period;
  4. require dual approval before releasing sensitive information;
  5. disclose only the minimum data necessary.

Dual approval should not become a mechanical repetition. The second reviewer must be able to challenge the requester’s identity, the proportionality of the response and the quality of the authorisation evidence.

Scoring the risk before disclosure

An official request can be assessed against four groups of variables:

  • requester: relationship history, role, contact details and previous requests;
  • request: number of customers, data sensitivity, urgency and period covered;
  • behaviour: unusual language, frequency, timing or change of pattern;
  • legal evidence: warrant, order, verifiable reference and competent jurisdiction.

A request about one customer that matches an existing case does not carry the same profile as an urgent request from a new contact seeking multiple data categories. The latter should trigger enhanced confirmation and, where necessary, a temporary hold.

The score does not replace legal judgement. Its purpose is to expose anomalies and prevent a single trust signal from authorising disclosure.

Why identity documents increase the impact

A compromised password can be changed. A passport copy, date of birth or historic address remains exploitable for much longer. Combined, these records can support identity theft, account opening, service takeover or highly targeted attacks.

Impact should therefore not be measured only by the number of affected people. It must also reflect the sensitivity, permanence and combinability of the information. A small population exposed through complete identity files can face a more persistent risk than a much larger database containing email addresses alone.

The relevance for African financial institutions

African banks, fintechs, mobile money operators and payment providers also receive requests from police forces, courts, financial intelligence units and regulators. Some exchanges remain partly manual, often under time pressure and across public institutions with different levels of digital maturity.

The first lesson is to include legal and compliance teams within the operational cybersecurity perimeter. The second is to establish verifiable mechanisms with public authorities: secure portals, certificates, official contact directories, case identifiers and callback procedures. The third is to record every step so an audit can establish who requested the information, who verified the authority and which data was ultimately disclosed.

Payment security also begins outside the payment flow

Revolut says it blocked the relevant address and alerted the government agency and competent authorities. The investigation will need to establish how the requests were validated, which data was disclosed and whether internal controls operated as designed.

It is too early to assign definitive legal liability. The operational diagnosis is already clearer: protecting customer accounts and payment engines is insufficient. Any peripheral process capable of releasing sensitive data forms part of the security system.

The question after this incident is straightforward: when the next official request arrives, will the institution verify only the address that sent it, or the actual authority of the person behind it?

Sources