Who Verifies the Government?
# Who Verifies the Government?
Revolut's latest breach isn't about clever malware or some brilliant exploit. It's an email story. Or maybe a stack of emails and documents that looked official enough to convince a fintech giant to hand over passport copies and full transaction histories. The company confirmed the leak happened because they fell for fake government requests, and that is possibly the most embarrassing way to lose data I have ever heard of. There was no intrusion in the sense of someone picking a lock. Revolut just opened the door, walked the attackers into the vault, and handed them the folders.
For those of us running ten-person shops without dedicated security heads, this is oddly comforting. Most people assume that if a multi-billion dollar company gets hit, it must have been some sophisticated "superhuman" AI attack or a nation-state zero-day. It usually isn't. Often it's just someone in the middle office who didn't want to annoy a perceived regulator and clicked 'Send' on a CSV file containing sensitive PII. The attackers likely spent more time researching which government agency would be most intimidating to Revolut's compliance team than they did writing code. They probably used forged letterheads, spoofed email addresses, and the right jargon to create a sense of urgency. Once the request looked legitimate, the internal process for approving that data transfer apparently had a hole large enough to drive a truck through.
Revolut's public statements are carefully curated, and they admit the "how" (fraudulent government requests) but avoid the "why. Why was there no secondary verification? Why didn't someone pick up a phone and call a known, official number at the agency in question? Most importantly, why did the system allow for the bulk export of passport copies without a high-level sign-off that required more than just an email trail?
Handling the intrusion is common. Handling the response this poorly is a choice. By admitting they were fooled by fake requests, Revolut has admitted their internal governance is performative. They have the tools to stop a hacker from brute-forcing a password, but they don't have a process to stop an employee from being too helpful to a liar.
This costs differently depending on who you are, and for an enterprise like Revolut, the cost is measured in regulatory fines that could hit north of 4% of global turnover under GDPR and a massive hit to customer trust. They will spend millions on "remediation" and PR firms to tell everyone their data is now "more secure than ever."
For a small business, this kind of failure costs everything. If you've got ten employees and you accidentally send your client list or payroll to a "tax auditor" who turns out to be a criminal in a different time zone, you don't have a PR firm to soften the blow. You just have a very awkward phone call with your clients and a potential bankruptcy filing.
The gap here is wild. The enterprise spends millions on AI-driven threat detection and still fails at basic human verification. A small shop can implement the same defense for exactly zero dollars: a written policy that says no sensitive data leaves the building without a voice-verified confirmation from a known contact.
It's a boring control, but it works.
Revolut is ignoring a second order effect. Losing transaction histories hurts more than losing passwords. You can change a password. Transaction history is a permanent map of a life. Attackers now know where these customers shop, what they spend, and who gets paid.
This allows for hyper targeted phishing. If a criminal knows you spend 12 dollars at the same deli every morning at 8:05 AM, they can send a fake billing error email from that exact deli. The success rate is higher than some generic account locked warning because the bait is real. Customers aren't just exposed. They are precisely targetable.
It sounds like old school bank fraud from twenty years ago. Back then, criminals called branch managers and pretended to be from the head office to force a wire transfer. Now we use PDFs and encrypted emails instead of phone calls; it gives attackers a veneer of legitimacy. The scale is where it differs. You couldn't fool ten thousand bank managers in one afternoon in 2006, and today, you can send ten thousand government requests with a single script.
Financial services are the fourth most targeted of twelve sectors we tracked this week. There were 80 stories mentioning them, including 19 new ones today. The trend is simple. Attackers aren't trying to get around security software, and they just ask the people running the software for the data.
People usually argue that the attackers were too sophisticated or used deepfakes. Maybe they did. But sophistication doesn't bypass a callback policy. When you get a request for sensitive data, you don't reply to the email. You don't click the PDF link. Why not just go to the official government website, find the public phone number, and ask if they actually sent the request?
If Revolut had done that, this breach wouldn't have happened. Instead, they relied on the "look" of the request rather than the "source" of it.
A ten person shop doesn't need a SOC. Forget the expensive dashboards too. You just have to be a bit more cynical than whoever signed off on Revolut's data export. Decide now that every email is a lie, regardless of the logo or the high ranking title in the signature, and it isn't true until you hear a human voice on a trusted line.
It’s unglamorous, it takes five minutes of extra work, and it costs nothing. It's also the only thing that actually stops this specific type of disaster.
Take a look at your authorized list of people allowed to export customer data this week, and if that list just says anyone with admin rights, you're one fake email away from a ruined Sunday.
◼
Sources
The reporting this analysis was built from. Follow the originals before acting on anything here.
- CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV The Hacker News
- Revolut Data Breach Exposes Customers' Passport Copies and Full Transaction Histories to Hackers - cybersecuritynews.com Google News Security
- AdaptHealth Data Breach Exposes 4.1 Million Patients' Information - Readers.id Google News Security
- Data Breach at AdaptHealth Exposes Personal Information of Over 4.1 Million Individuals - SSBCrack Google News Security
- Revolut confirms customer data breach through fake government requests - TechCrunch Google News Security
- Just before Israel launch • Fintech giant Revolut confirms customer data breach by fake government requests - Haaretz Google News Security
- Revolut confirms sensitive customer data breach, falling for fake government requests - CNA Google News Security
- EasyEquities puts its 3 m clients on alert after ‘cybersecurity incident’ - news24.com Google News Security