Phone us
A recent Revolut data breach has highlighted the risks of relying on apparently legitimate email requests for sensitive information. This article looks at what happened and the controls organisations can use to reduce the risk of inappropriate disclosure.

Revolut confirmed on 12 September 2026 that sensitive customer information had been disclosed following fraudulent requests that appeared to come from a legitimate government agency email domain. The company said its core systems and customer funds were unaffected and that only a limited number of customers were involved.

Subsequent reporting indicated that approximately 680 customers may have been affected, with compromised information reportedly including dates of birth, postal and email addresses, telephone numbers and copies of identity documents.

The incident is still being investigated, so it would be premature to draw firm conclusions about exactly how the requests were generated or which controls failed. However, it raises a much broader issue for organisations that routinely receive requests for sensitive information: a trusted communication channel is not necessarily proof that the person using it is trustworthy.

Legitimate Requests Create a Difficult Security Problem

Financial institutions, telecommunications companies, technology providers and many other organisations routinely receive requests for personal information from law enforcement agencies, courts, regulators and other public bodies.

UK data protection law allows information to be shared with law enforcement where the appropriate legal conditions are met. Simply refusing external requests is therefore not realistic. The challenge is establishing whether a request is genuine and whether the disclosure is lawful, necessary and proportionate.

A Familiar Email Domain Is Only One Signal

A recognised police, government or regulator email domain naturally gives a message credibility. But where sensitive information is involved, it should not be the only form of verification.

If a legitimate account or infrastructure has been compromised, the email address may be genuine, the terminology correct and the request convincing. None of those factors necessarily proves that the requester is authorised to receive the information.

Authentication of the communication channel should therefore not automatically be treated as authentication of the person making the request.

Verification Should Take Place Outside the Original Request

Sensitive or unusual requests should be independently verified using information that does not rely entirely on the original communication.

For example, staff should avoid verifying a questionable request using a telephone number provided within the same email. Contact details should instead come from an independently verified source, such as an existing authority directory, official website, established contact or internal liaison process.

It is the same principle businesses apply when verifying a request to change supplier bank details: use contact information already known to be genuine.

Data Can Be as Valuable as Money

Organisations often apply strong controls to financial transfers, including dual approval, beneficiary checks and transaction limits.

Sensitive information deserves similar consideration. Identity documents, addresses, contact details and financial information can all be valuable to criminals carrying out identity fraud, social engineering or account takeover attempts.

Organisations should therefore consider whether highly sensitive disclosures warrant controls comparable with those applied to significant financial transactions.

Law-Enforcement Requests Still Require Data Protection Judgement

A request from a law-enforcement authority does not remove an organisation’s responsibilities under data protection law.

ICO guidance states that organisations should establish an appropriate lawful basis, consider whether disclosure is necessary and proportionate and provide only the information required.

A request should therefore be assessed rather than simply processed. Organisations need to understand who is requesting the information, why it is required, the legal basis for disclosure and whether everything requested is genuinely necessary.

Data Minimisation Can Limit the Consequences of Fraudulent Requests

No verification process will be perfect, making data minimisation another important safeguard.

If an authority requests considerably more information than appears necessary, organisations should question whether the full disclosure is justified. Providing only information that is adequate, relevant and necessary limits the potential consequences if a request later proves to have been fraudulent.

Data minimisation is therefore both a privacy principle and a security control.

High-Risk Requests May Need Dual Approval

Particularly sensitive disclosures may warrant review by more than one person.

Rather than applying this to every request, organisations can take a risk-based approach, with additional scrutiny for requests involving identity documents, financial histories, large volumes of records, special-category information or other particularly sensitive data.

A second reviewer can question the scope, legitimacy and legal basis of the request and determine whether legal, compliance or data protection specialists should be involved.

Urgency Should Increase Scrutiny, Not Reduce It

Social engineering often creates a sense of urgency. A requester may claim that immediate disclosure is required because an investigation is active or evidence is at risk.

Genuine law-enforcement requests can, of course, be urgent. Organisations therefore need a defined emergency process setting out who can authorise disclosure, how requests can be verified outside normal working hours and how decisions should be documented.

Urgency should trigger an established process, not the removal of controls.

Organisations Need an Information-Disclosure Process, Not Just a Mailbox

Sensitive information requests should ideally pass through a controlled process rather than being handled informally across an organisation.

That process might include centralised intake, requester verification, legal authority checks, data minimisation, defined approval levels, secure transmission, logging and escalation criteria.

Centralisation can also make suspicious patterns easier to identify, particularly where several similar requests are received from the same source or jurisdiction.

Staff Need Permission to Challenge Authority

Employees may feel uncomfortable questioning someone claiming to represent the police, a regulator or a government department.

Good governance should make clear that verifying unusual requests is part of the employee’s role, not an obstruction to legitimate enquiries.

Training also needs to extend beyond recognising obviously suspicious emails. Modern social engineering may involve legitimate infrastructure, convincing documentation and detailed knowledge of organisational processes. The question should increasingly be: what evidence do I have that this request is genuine?

The Risks Continue After the Initial Breach

The consequences of an inappropriate disclosure can extend well beyond the initial incident.

Attackers claiming responsibility for the Revolut breach reportedly threatened to sell confidential customer information unless the company paid a $3 million ransom, although Revolut said it had received no direct demand.

Stolen identity and financial information may also be used in subsequent fraud and highly targeted social-engineering attacks, meaning the risks to affected individuals can continue long after the original breach has been contained.

Breach Response Should Focus on Harm to Individuals

When an inappropriate disclosure occurs, organisations need to consider the potential harm to the people affected.

ICO guidance requires qualifying personal data breaches to be reported without undue delay and, where feasible, within 72 hours. Where a breach is likely to result in a high risk to people’s rights and freedoms, affected individuals must also be informed without undue delay.

The number of people affected is only part of that assessment. A relatively small breach involving highly sensitive information can still create significant risk.

Leadership Needs Visibility of Information Disclosure

Information requests may appear operational, but senior leadership should have assurance that appropriate controls govern the disclosure of sensitive data.

That means understanding who owns the process, how requests are verified, which cases require escalation, how decisions are recorded and whether controls are tested.

Leadership should also have visibility of trends, such as the number of requests received, challenged or rejected and whether unusual patterns are emerging.

What Should Organisations Review?

The Revolut incident provides an opportunity for organisations to review their own processes. Leadership should be able to establish:

  • who is authorised to respond to external requests for personal information;
  • how the identity and authority of requesters are independently verified;
  • whether staff rely too heavily on email domains, branding or documentation as proof of legitimacy;
  • when secondary approval or specialist review is required;
  • how lawful basis, necessity, proportionality and data minimisation are assessed;
  • how urgent and out-of-hours requests are handled;
  • whether disclosures are centrally logged and reviewed for suspicious patterns;
  • how sensitive information is transferred securely; and
  • whether employees are trained and empowered to challenge unusual requests.

These questions apply far beyond banking. Any organisation that can legitimately disclose sensitive information to an authority could potentially be targeted by someone impersonating that authority.

Social Engineering Is Becoming a Process Problem

Traditional cyber security awareness has often focused on spotting suspicious emails: checking addresses, avoiding unexpected links and looking for obvious signs of phishing.

Those controls still matter, but sophisticated attacks increasingly exploit weaknesses in business processes.

If one apparently trusted signal is enough to authorise a sensitive disclosure, compromising that signal may allow an attacker to bypass much of an organisation’s security awareness training. Processes therefore need to be designed so that a single indicator of trust is not sufficient to authorise a high-risk action.

Trust Should Be Verified in Proportion to the Risk

The aim is not to make legitimate information requests unnecessarily difficult. Verification should be proportionate to the potential consequences of an incorrect disclosure.

A routine, low-risk request may need relatively simple checks. A request involving passport copies, financial histories or large volumes of customer data should demand stronger evidence of authenticity.

The greater the potential harm, the stronger the verification should be.

The Most Convincing Request May Be the Most Dangerous

The Revolut incident is a reminder that organisations cannot rely solely on identifying communications that look suspicious. Some attacks succeed precisely because the request appears completely legitimate.

Controls therefore need to withstand the failure of individual signals of trust. Organisations should independently verify sensitive requests, establish whether disclosure is lawful and necessary, limit what is provided and introduce additional scrutiny where the consequences of an incorrect decision are significant.

AJC can help organisations review and strengthen the governance, verification and control processes surrounding sensitive information requests, helping to reduce the risk of inappropriate disclosure and strengthen wider cyber resilience. Contact us on 020 7101 4861 or email us at info@ajollyconsulting.co.uk if you think we can help.

Sources:

https://www.reuters.com/legal/litigation/revolut-confirms-sensitive-customer-data-breach-falling-fake-government-requests-2026-09-12/

https://www.reuters.com/legal/government/revolut-hackers-demand-3-million-ransom-ft-reports-2026-09-16/

https://cybersecuritynews.com/fintech-revolut-data-breach/

https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-sharing/sharing-personal-data-with-law-enforcement-authorities/

https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-sharing/can-i-share-personal-data-with-a-law-enforcement-authority/

https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/personal-data-breaches-a-guide/

Image accreditation: Head office building of Revolut at Canary Wharf, London (June 2025) from WikiMedia Commons. Last accessed on 23 September  2026. Available at: https://commons.wikimedia.org/wiki/File:London_Revolut.jpg

In case you missed it...

prepare cyber resilience act
Why Businesses Need to Prepare for...

The main requirements of the EU Cyber Resilience Act come into effect in December 2027. While that may still sound...

Read More
cookie compliance gambling websites
Cookie Compliance Lessons from UK Gambling...

Cookie compliance is about more than having a banner in place. This article looks at new research into UK gambling...

Read More
UK Air Traffic Control Disruption
UK Air Traffic Control Disruption: Why...

Recent disruption across UK airports has shown how quickly the failure of a critical system can have far-reaching consequences. While...

Read More

Get in touch

    By submitting this form you are consenting that your data be handled in accordance with our Privacy Notice and we will be in touch regarding your enquiry.