Auditen
sector watch

Fake Government Requests Trigger Revolut Customer Data Breach

Revolut got played. They weren't hit by some high tech state actor or a rare zero day exploit. No, they just gave away customer passports and Bitcoin records to scammers who pretended to be government officials.

This isn't a technical failure. It is a design failure.

I've watched this happen since the early SOX days, and back then we spent half our time fighting over if a signature on a page actually proved a person looked at a report. They called it "evidence of review, and now, firms just swapped the pen for a digital workflow. The logic is still lazy, and if your control for government data requests is to get an email, check the sender's address and send the data, you don't have a control. You've got a suggestion.

Control theatre tells you that having a written policy on how to handle law enforcement requests is enough. The auditor checks the box: *Policy exists? Yes. Process followed? Yes.*

I only care about one thing when I see these findings: what's the bill at year-end? With Revolut, it isn't just the fine or the PR mess they'll face before launching in Israel. The real cost is that the whole "trust" story they've been selling has collapsed.

Look at Trezor. A breach at Brevo, a third-party provider, left just under 350,000 users open to phishing attacks, and this is what happens with second-order failures. You can drop millions on your own perimeter; it doesn't matter if you outsource your emails to a vendor with porous controls. Your security is only as good as the weakest link in the chain.

The fintech sector is currently pretending that encryption and MFA are the finish line. They aren't.

The strongest objection here is usually the "industry standard" argument. I can hear it now: "We follow every framework, we have our certifications, and we use a vetted vendor."

Certifications are trophies. They aren't controls. An ISO certificate won't stop some junior employee from emailing sensitive data to a scammer because they were too scared to call the regulator and verify the request. A vetted vendor is usually just someone who lied convincingly on a questionnaire three years ago.

The real pressure this week isn't coming from regulators, even if the SEC is always lurking, and it's shifting toward the people who signed off on these processes.

Then there's the second order effect: professional indemnity insurance for audit firms. When a breach of this size happens, especially one caused by something as basic as a fake request, the regulator asks why internal and external auditors didn't flag the lack of out of band verification. If the auditor checked that a process existed but didn't test it against a real attack vector, they're suddenly on the hook.

We are seeing a concentration of failure in identity and third-party trust. It is a systemic gap where firms assume that if a request looks official, it is official.

Stop staring at your dashboards if you're running a controls environment. Go find the person in charge of government data requests instead, and ask them exactly how they verify that the person emailing them actually works for the state. Do they have a real process? If they just show you a PDF of a policy, you've got a problem.

I'll believe fintech has matured when I see firms implementing mandatory call-back procedures for all high-sensitivity data transfers regardless of who is asking. Until then, it's just more theatre.

The fraudsters aren't getting smarter; the controls are just staying static.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. SEC Proposes to Rescind the Political Contribution Rule for Investment Advisers - Latham & Watkins LLP Compliance Week (Google News)
  2. Insider Access to Patient Records Rose 17% in 2025, Even as Breaches Grew Smaller - Pharmacy Practice News Data Privacy (Google News)
  3. Trezor phishing attack tied to Brevo breach hits 347,000 users - BetaNews Data Privacy (Google News)
  4. SEC proposal would let blockchain serve as official securities ledger - Cryptonews.net Compliance Week (Google News)
  5. Just before Israel launch • Fintech giant Revolut confirms customer data breach by fake government requests - Haaretz Data Privacy (Google News)
  6. Thailand SEC Proposes 5 Million Baht Daily Cap on Stablecoin Transfers Under Same-Owner Rule - The Crypto Times Compliance Week (Google News)
  7. Bitcoin activity, passports exposed after Revolut falls for fake government request - CoinDesk Data Privacy (Google News)
  8. Assam: Residents raise drone surveillance concerns in Tinsukia's Barekuri, threaten protest against Oil India over privacy breach - India Today NE Data Privacy (Google News)

How stories are selected and assessed