Customer records exposed through a fake government request
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Monday, September 14th, 2026.
Revolut released sensitive identity and financial records after accepting a fraudulent request that appeared to come from a legitimate government agency. The material reportedly included copies of identity documents, verification selfies, contact details, account statements, and complete transaction histories for a limited number of users. Revolut said its systems and customer accounts weren’t compromised, customer funds remained safe, and it notified affected customers and authorities.
That distinction matters, but it doesn’t remove the risk. The exposed records could support convincing impersonation, phishing, extortion, or targeted cryptocurrency theft. Leaders shouldn’t treat authenticated email as sufficient proof for a high-risk government request. Defenders should verify sensitive disclosures through a separate trusted channel and monitor affected users for tailored fraud. Those customers may face lasting identity and financial profiling risk. The larger lesson is that a trusted business workflow can become the breach path even when core systems remain intact. Require out-of-band approval before releasing sensitive customer data to any external authority.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.