Revolut Confirms Data Breach: Fake Government Requests Emerge as a New Attack Vector

Revolut data breach caused by fake government requests exposes compliance processes as an attack target.
Revolut has confirmed a customer data breach triggered by attackers impersonating government agencies through fraudulent official data requests — a tactic known as Emergency Data Request fraud. By exploiting financial institutions' legal obligation to cooperate with law enforcement, attackers bypassed technical defenses and targeted internal review processes directly. The article analyzes the attack mechanism, explains why financial institutions are especially vulnerable, and offers practical defenses including independent callback verification, multi-level approval workflows, and audit logging. Affected users are also warned to watch for follow-on attacks such as voice phishing and SIM hijacking.
Incident Overview
Digital banking giant Revolut has confirmed a customer data breach. Unlike typical system intrusions or phishing attacks, this incident was triggered by attackers impersonating government agencies and submitting fraudulent official data requests to obtain customer information.
According to Revolut's statement, the company promptly notified affected customers and reported the incident to relevant government agencies, law enforcement, and financial regulators. This multi-agency coordinated response reflects that the incident has been assessed as carrying a degree of seriousness and legal sensitivity.

Fake Government Requests: An Underestimated Attack Surface
So-called "fake government requests" refer to a technique where attackers impersonate law enforcement agencies or regulatory bodies and use seemingly legitimate legal procedures to demand user data from companies. For financial institutions, complying with government and law enforcement data requests is a legal obligation — which means such requests are typically prioritized and processed quickly.
It is precisely this "compliance reflex" that attackers exploit. Compared to brute-force attacks or vulnerability exploitation, forging official requests is far cheaper and easier to slip past technical defenses — because it doesn't target systems, but rather a company's internal review processes and trust mechanisms. In recent years, multiple tech and financial companies have fallen victim to similar "Emergency Data Request" fraud, with attackers even spoofing compromised law enforcement email accounts to boost credibility.
Why Financial Institutions Are Prime Targets
Financial institutions hold vast amounts of high-value personally identifiable information (PII) and transaction data, making them natural targets. At the same time, banks must routinely interact with regulatory bodies, anti-money laundering units, and law enforcement, handling a large volume of legitimate data requests on a daily basis — providing cover for fraudulent ones to blend in.
For rapidly expanding digital banks like Revolut, operating across multiple countries and jurisdictions means fielding requests from various government agencies in different formats and languages. The complexity of verification standards and the difficulty of cross-border validation further amplify the risk of impersonation.
How Organizations Can Defend Against This Type of Fraud
Combating fake government requests requires more than technical controls — it demands strict verification mechanisms at the process level:
Establish Independent Callback Verification
Upon receiving a data request, organizations should not rely on the contact information provided in the request itself. Instead, they should independently verify the legitimacy of the requesting agency through official public channels, avoiding the "closed loop" that attackers are counting on.
Implement Multi-Level Approval and Dedicated Teams
Requests involving sensitive customer data should go through multi-stage approval and be handled by a dedicated team familiar with legal procedures — not left to frontline customer service or operations staff to assess on their own.
Logging and Auditing
All data request handling should be fully documented to enable post-incident traceability. The fact that Revolut was able to quickly identify affected customers and notify regulators suggests the company has meaningful audit capabilities in place.
Impact on Users and Recommendations
Affected Revolut users should be alert to potential follow-on targeted phishing attacks. Once attackers obtain even partial verified information, they often use it as a foothold to launch far more convincing social engineering scams. Users are advised to enable multi-factor authentication, monitor their accounts for unusual activity, and remain skeptical of any "urgent verification" requests that claim to come from their bank.
Conclusion
The Revolut incident serves as yet another reminder to the industry: the frontline of data security isn't only in servers and code — it's also in people and processes. When attackers begin impersonating "the government" itself, organizations need to reexamine the trust chains they've long taken for granted. As this class of social engineering attacks matures, striking the right balance between compliance responsiveness and security scrutiny will be an unavoidable challenge for every data-intensive enterprise.
Related articles

Anthropic CEO Calls for Hitting the Brakes on AI Development: A Three-Step 'Pace the Frontier' Plan
Anthropic CEO Dario Amodei calls for slowing AI development with a three-step 'pace the frontier' plan, including opening model access to third-party evaluators like METR.

Insufficient Source Material: Unable to Generate Article on Sylvan Esso
The source material provided covers music duo Sylvan Esso — unrelated to AI/tech and incomplete. No viable article could be produced; publication not recommended.

"LLMs Are Real, AI Is Fake": A Debate Worth Having
Hacker News post 'LLMs are real, AI is fake' sparks debate: why LLMs are concrete and verifiable while 'AI' is often marketing hype. What this means for practitioners.