REVOLUT.HOT INCIDENT NOTE · 11-12 SEP 2026
PUBLIC DESIGN RESPONSE · 14 SEPTEMBER 2026

A REAL GOVERNMENT DOMAIN.
A FAKE REQUEST.
REAL DATA OUT.

Revolut says fraudulent information requests came through a legitimate government-agency email domain and led to sensitive customer data being disclosed to an unauthorised third party. TechCrunch reports that affected data included identity/contact details and copies of passports or driving licences, and may also have included verification selfies, account statements and transaction histories. Revolut said its systems and customer funds were unaffected.

What passed
CHANNEL
The inbound path looked legitimate.
What did not
AUTHORITY
The requester was not entitled to the data.
What left
PII
Identity documents + account data.
What cannot happen
UN-SEND
Disclosure is not meaningfully revocable.
The domain was authentic. The authority wasn't.
00

What actually happened

public facts → design question
01 · REQUEST

Fraudulent information requests arrived through a legitimate government-agency email domain.

02 · CHECKS

The request looked sufficiently legitimate to pass Revolut's internal process and reach a disclosure decision.

03 · DATA OUT

Sensitive customer information was disclosed to an unauthorised third party.

04 · DISCOVERY

Revolut says it blocked the address and notified the relevant agency, law enforcement and regulators after identifying the scam.

01

What I would change Monday morning

no FOL required
01

Callback

Verify the requester out-of-band using a number sourced independently of the inbound request.

02

Named principal

Trust people with current capacity, not domains. Email is evidence of a channel, never sufficient authority.

03

HOLD

Until principal + mandate resolve: preserve, prepare, escalate internally. Release zero PII.

04

Two desks

Passports, selfies and broad transaction histories require a second human release approval.

05

Evidence packet

Canonicalise, hash, sign and timestamp every outbound packet together with the rule version that authorised it.

02

The 90-second self-test

would your desk have leaked?
1. Can an inbound government email alone move customer data?
Safe answer: NO.
2. Is the named requester verified outside the inbound request?
Safe answer: YES.
3. Do you verify that their agency role/capacity is current?
Safe answer: YES.
4. Is the mandate represented as an explicit case object, not just prose?
Safe answer: YES.
5. Is the default disclosure scope empty until fields are explicitly authorised?
Safe answer: YES.
0/5 answered
Answer all five. The test scores the control design, not your people.
03

Run the incident

reference state machine
trace
// choose a path
04

Why this isn't a novel attack

known class
2024

FBI warning

The FBI warned that compromised government email accounts were being used to send fraudulent emergency data requests to technology companies.

SECOND LEVEL

Verification catches a lot

Kodex told Krebs that 485 of 1,597 emergency data requests processed over a 12‑month period failed second-level verification. That number is market evidence, not a universal base rate.

DESIGN

Make urgency boring

Emergency should change SLA, not skip identity. A panic path that weakens authority checks is exactly the path an attacker will sell.

05

Open the technical manual

the rigorous layer
Five gates before DATA OUT
GateQuestionFailure state
ChannelDid the request travel through the claimed technical path?Evidence only; never authorises content.
PrincipalWho is the named human/system?Unknown principal → HOLD.
CapacityDo they currently represent the agency in the relevant role?Stale/revoked capacity → HOLD/REJECT.
MandateWhat lawful power applies to this case?Gap/ambiguity → HOLD.
ScopeWhich subjects, fields and time range are permitted?Default scope = empty.
Ten invariants
01 Channel match never authorises content. · 02 Named principal blocks before DATA OUT. · 03 Capacity + mandate + scope block DATA OUT. · 04 HOLD releases zero PII. · 05 AI override = false. · 06 Default scope = empty. · 07 High-sensitivity fields require a second human. · 08 Outbound packets are canonicalised, hashed, signed, timestamped and bound to rule version. · 09 TTL expiry changes state; silence is not consent. · 10 Rule changes are revision events, not invisible edits.
One sentence
A case may remain provisional. An outbound packet may not. Irreversible actions require complete authority at dispatch.

Try to break it.

Design the nastiest synthetic government request you can: urgency theatre, a real-looking domain, a plausible officer, a scope-expansion trick. If it crosses DATA OUT without principal + capacity + mandate + scope, the invariant should change publicly — with a revision event and a regression test.

Open research version