A REAL GOVERNMENT DOMAIN.
A FAKE REQUEST.
REAL DATA OUT.
Revolut says fraudulent information requests came through a legitimate government-agency email domain and led to sensitive customer data being disclosed to an unauthorised third party. TechCrunch reports that affected data included identity/contact details and copies of passports or driving licences, and may also have included verification selfies, account statements and transaction histories. Revolut said its systems and customer funds were unaffected.
What actually happened
public facts → design questionFraudulent information requests arrived through a legitimate government-agency email domain.
The request looked sufficiently legitimate to pass Revolut's internal process and reach a disclosure decision.
Sensitive customer information was disclosed to an unauthorised third party.
Revolut says it blocked the address and notified the relevant agency, law enforcement and regulators after identifying the scam.
What I would change Monday morning
no FOL requiredCallback
Verify the requester out-of-band using a number sourced independently of the inbound request.
Named principal
Trust people with current capacity, not domains. Email is evidence of a channel, never sufficient authority.
HOLD
Until principal + mandate resolve: preserve, prepare, escalate internally. Release zero PII.
Two desks
Passports, selfies and broad transaction histories require a second human release approval.
Evidence packet
Canonicalise, hash, sign and timestamp every outbound packet together with the rule version that authorised it.
The 90-second self-test
would your desk have leaked?Run the incident
reference state machine// choose a path
Why this isn't a novel attack
known classFBI warning
The FBI warned that compromised government email accounts were being used to send fraudulent emergency data requests to technology companies.
Verification catches a lot
Kodex told Krebs that 485 of 1,597 emergency data requests processed over a 12‑month period failed second-level verification. That number is market evidence, not a universal base rate.
Make urgency boring
Emergency should change SLA, not skip identity. A panic path that weakens authority checks is exactly the path an attacker will sell.
Open the technical manual
the rigorous layerFive gates before DATA OUT
| Gate | Question | Failure state |
|---|---|---|
| Channel | Did the request travel through the claimed technical path? | Evidence only; never authorises content. |
| Principal | Who is the named human/system? | Unknown principal → HOLD. |
| Capacity | Do they currently represent the agency in the relevant role? | Stale/revoked capacity → HOLD/REJECT. |
| Mandate | What lawful power applies to this case? | Gap/ambiguity → HOLD. |
| Scope | Which subjects, fields and time range are permitted? | Default scope = empty. |
Ten invariants
One sentence
Try to break it.
Design the nastiest synthetic government request you can: urgency theatre, a real-looking domain, a plausible officer, a scope-expansion trick. If it crosses DATA OUT without principal + capacity + mandate + scope, the invariant should change publicly — with a revision event and a regression test.
Open research version