An email arrives from a public authority asking for customer records. The domain is genuine, the language sounds official and the request appears urgent. Would your team send the files?
That question is at the centre of the data breach confirmed by Revolut in September 2026. The lesson applies far beyond banks. Accountants, clinics, hotels, retailers and professional firms all receive requests for personal information, often without a dedicated security team available to review them.
What happened at Revolut?
Revolut said an unauthorised third party submitted fraudulent information requests using a legitimate government agency email domain. The company fulfilled some of those requests and disclosed customer data before identifying the scam. It then blocked the address and notified the agency, law enforcement and relevant regulators. Revolut also said its systems and customer funds were unaffected, according to Reuters.
TechCrunch reviewed a notice sent to affected customers. It reported that exposed information included contact details and copies of identity documents. Some notices also referred to verification selfies, account statements and transaction histories.
Revolut described the affected group as limited, but it did not disclose the number of people, the country involved, the agency, or how the third party gained control of the email address. Those details remain unknown as of 15 September 2026.
This distinction matters: the public reporting does not describe a direct break-in to Revolut's systems. The breach occurred because information was released to someone who was not authorised to receive it.
Why a genuine domain can still be dangerous
Email security checks can show that a message came through systems authorised for a domain. They cannot prove that the person using a particular mailbox is authorised to make the request, or that the attached document is legally valid.
This is the practical inference from the Revolut incident: technical authenticity is only one part of identity and authority.
A mailbox may be compromised. A real employee may have been deceived. A request may use a valid address but ask for information outside that person's powers. The recipient still needs to confirm the requester, the legal basis and the exact data required.
Five checks before releasing sensitive data
Small businesses can use a simple process. It does not require specialist software, but it must be written down and followed consistently.
- Pause and classify the data. Treat identity documents, health information, payroll records, bank details and customer histories as high-risk. Urgency should increase scrutiny, not remove it.
- Verify through an independent channel. Contact the organisation using a phone number or portal obtained from its official website or an existing trusted record. Do not use the contact details contained in the request. This is also the approach recommended by the UK National Cyber Security Centre.
- Confirm authority and scope. Check the case reference, legal basis, named official, deadline and specific records requested. Ask for clarification when the request is broader than necessary.
- Require a second approver. A manager, privacy lead or external adviser should review any high-risk disclosure. One person should not be able to receive, approve and send the request alone.
- Send the minimum securely and record it. Release only the information that has been verified as necessary. Use an approved secure transfer method and record who approved it, what was sent, to whom and when.
For occasional requests, a one-page checklist and an approval log may be enough. Businesses handling them frequently should add a dedicated mailbox, access controls, staff training and an incident-response procedure.
What if information has already been sent?
Act quickly, but keep the response orderly:
- stop further disclosure and disable any shared links;
- preserve the email, attachments, approval history and access logs;
- contact the real organisation through an independent channel;
- identify exactly which people and data are involved;
- involve the person responsible for privacy, your legal adviser and your IT provider;
- assess the risk of identity fraud, financial harm and further phishing.
Under the GDPR, handing personal data to an unauthorised recipient is a personal-data breach even when no database was hacked. The European Data Protection Board's small-business guide says organisations must document breaches. A supervisory authority must generally be notified within 72 hours when the breach is likely to create a risk for individuals, and affected people must be informed without undue delay when the risk is high.
The assessment depends on the data and circumstances, so it should begin immediately rather than after the investigation is complete.
A short checklist for your business
Ask these questions now:
- Who is allowed to approve a release of customer or employee data?
- How will staff find a trusted number to verify an official request?
- Which categories always require a second reviewer?
- What secure method will be used to transfer files?
- Where will requests, approvals and disclosures be recorded?
- Who starts the breach-response process if a mistake is discovered?
If the answers depend on one employee's memory, the process is fragile. A short written procedure is easier to follow during a stressful request and easier to improve after an incident.
Frequently asked questions
Was Revolut hacked?
Revolut said its systems were unaffected. Based on the information disclosed so far, customer data was released after fraudulent requests arrived from a legitimate government email domain. The method used to control or misuse that address has not been made public.
Is checking the sender's email domain still useful?
Yes. Domain checks can detect many basic scams. For sensitive disclosures, they should be followed by independent confirmation of the person, authority, legal basis and scope.
Does every request from a public authority need a lawyer?
Routine, low-risk requests can follow an approved internal procedure. Unusual, broad or high-risk requests should be escalated to the appropriate privacy or legal adviser before information is released.
What should affected Revolut customers do?
Use Revolut's official app or website to confirm whether you were contacted. Be especially cautious about later messages or calls that use leaked personal details to appear convincing. Do not use links or contact information from an unexpected breach message.
Make verification part of the process
The Revolut case shows that security is not limited to passwords, firewalls and software updates. A convincing request can pass technical checks and still be fraudulent.
Computer On Site can review how your business receives, approves and transfers sensitive information, then turn the findings into a practical security plan. Start with our IT check-up, read our ransomware prevention guide, or contact us.

Gonzalo Marsilli