13 September 2026
Executive Summary
Revolut has confirmed that sensitive customer information was disclosed after the company received fraudulent requests that appeared to originate from a legitimate government email domain.
The British financial-technology company said it had been deceived by requests impersonating a government authority.
The exact categories and volume of information exposed have not yet been publicly detailed.
The incident is particularly significant because it did not require attackers to break directly into a customer database.
Instead, the attackers exploited a trusted information-disclosure process.
Financial institutions, technology companies and other businesses routinely receive legitimate requests for information from:
- Police.
- Courts.
- Regulators.
- Tax authorities.
- Government agencies.
Those processes can therefore become an attractive route for social engineering.
A request arriving from what appears to be an official government domain should not automatically be treated as proof that the request itself is genuine.
UK Impact
The incident has direct relevance for UK organisations holding sensitive information.
Particularly exposed sectors include:
- Banking.
- Insurance.
- Legal services.
- Healthcare.
- Telecommunications.
- Technology.
- Professional services.
- Online platforms.
Businesses may have well-developed controls against conventional phishing while allowing information requests from authorities to bypass some normal verification processes.
That creates a potential weakness.
Employees may be reluctant to challenge a request that appears to originate from:
- Police.
- HMRC.
- A court.
- A regulator.
- A government department.
Attackers can exploit precisely that instinct.
Global Impact
The incident demonstrates that cybersecurity does not end at the login screen.
Sensitive data can leave an organisation through an apparently authorised business process.
That creates risk involving:
- Privacy regulation.
- Litigation.
- Identity theft.
- Fraud.
- Reputational damage.
- Regulatory investigation.
- Cyber insurance.
- Professional liability.
It also illustrates the growing sophistication of social engineering.
An attacker does not necessarily need to compromise the target company itself.
Compromising, spoofing or convincingly impersonating a trusted third party may be enough.
Our View
Businesses should review how official information requests are authenticated.
Companies should ask:
- Who is authorised to release customer information?
- How is the identity of the requesting authority verified?
- Is email-domain verification considered sufficient?
- Is an independent callback required?
- Are known authority contact details maintained separately?
- Are urgent requests subject to the same verification?
- Can one employee authorise disclosure alone?
- Is dual approval required for sensitive data?
- Are request logs retained?
- Can unusual request patterns be detected?
- Are employees trained to challenge apparently official requests?
- Are legal and data-protection teams involved?
- Is the minimum necessary information disclosed?
- Does cyber insurance cover wrongful data disclosure?
- Is there a rapid notification process if information is released incorrectly?
The critical lesson is simple:
authority should be independently verified rather than inferred from the appearance of the communication.
The more trusted the apparent sender, the more damaging successful impersonation can become.
Risk Indicator: HIGH – CYBER, SOCIAL ENGINEERING & DATA PROTECTION
Does This Risk Affect Your Business?
Invictus Risk Solutions helps businesses find practical solutions to insurance, risk and commercial challenges.
From individual businesses to major international organisations, risk is our business.
TALK TO INVICTUS →Disclaimer
The information contained within these Market Alerts is provided for general market awareness and informational purposes only. It does not constitute financial, legal, investment, regulatory or insurance advice. Whilst every effort has been made to ensure accuracy at the time of publication using multiple reputable and independently verified sources, geopolitical events, legislation, regulation and market conditions may change rapidly. Readers should obtain appropriate professional advice before acting upon any information contained herein.
Invictus Risk Solutions LLP – Helping organisations stay ahead of emerging risks through informed insight and independent analysis.
