Your cookie preferences

EDPB guidance · Art. 7 GDPR

We use technical cookies essential for the platform to work (login, security, sessions). We would also like to use analytics cookies to understand how to improve it.

You can accept all, reject all, or choose which categories to switch on.Your consent is valid for 6 months and you can withdraw it at any time from the footer.

You will find everything in our privacy notice.

All news
Tech & AI September 23, 2026 6 min

The request came from a real government domain

Revolut handed over identity documents and account histories to someone posing as an authority, using an email on a legitimate government domain. Nobody broke into the systems: the verification procedure gave way

What happened

On 12 September 2026 Revolut confirmed that an unauthorised third party used an email on a legitimate government domain to send fraudulent requests for information. The company describes it as an external impersonation scam rather than an intrusion into its systems; it says it blocked the address, alerted the authorities and contacted the customers concerned. Funds are reported unaffected.

The part that matters to a DPO is neither the customer count nor the company's name. It is that the data left through a legitimate channel, authorised by a person doing what they had been taught to do: answer a request from an authority. No firewall could have stopped it. The control that gave way is a procedure, and in most organisations that procedure is written down nowhere.

  • Dates of birth, postal and email addresses, phone numbers.
  • Copies of identity documents: passports and driving licences.
  • Identity verification selfies.
  • Account statements and transaction histories.

On the characterisation there is no doubt: this is a personal data breach. The definition in Art. 4(12) GDPR covers unauthorised disclosure, and disclosure there was, to a recipient with no entitlement to it. That the deception was well made does not change the characterisation: it bears on the assessment of diligence, which is a different matter and comes later.

The question to put to the client

When a request arrives from an authority — police, prosecutor, tax agency, supervisory authority — who decides whether to answer, and on what basis do they verify that the request is genuine? If the answer is «whoever receives it decides», the procedure does not exist. A correct email domain is not verification: it is precisely the element that, in this case, was genuine.

The countermeasures are mundane, which is why they get skipped. An independent call-back channel: you ring the body on the number published on its own site, not the one given in the request. One named person who authorises disclosures to authorities, not whoever opens the post. A log of requests received and requests answered, with date, basis and recipient — which is also what you need to show you did things properly when something goes wrong. And the rule that no urgency claimed by the requester shortens the verification: urgency is the lever this scam runs on.

Official source:TechCrunch — Revolut confirms customer data breach through fake government requests (12/09/2026)Official source:Finextra — Revolut hit by data breach after fake government email scam

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free