decrypted · 15 september 2026 · ransomware and cybercrime · uk policy and law · ai and llm security
Revolut handed over customer data because an email looked official
Revolut, the London-based fintech with more than 80 million customers, has confirmed that it handed over customer passports, driving licences, verification selfies and transaction histories to a criminal who simply asked for them the right way. No malware, no exploit, no breached database. An attacker used a legitimate government agency's email domain to submit a data request that carried valid technical authentication, and Revolut staff processed it as routine compliance. The company says systems and funds are unaffected and only a small proportion of customers were hit, though it will not say how many, in which country, or which agency was spoofed. A ransom demand for 10,000 Bitcoin, reportedly posted by the attacker in Telegram channels, is an unverified claim rather than a confirmed fact, and Revolut has declined to comment on it.
Authenticated does not mean authorised
The detail worth sitting with is that the email "carried valid domain authentication credentials", in Revolut's own words. That means the standard checks a mail server runs, the ones confirming a message really did originate from the sender's claimed domain, all passed. What those checks cannot do is confirm that the human sending the message is entitled to ask for a named customer's passport scan. It is the digital equivalent of a courier accepting a parcel redirect because the letter arrived on the right headed paper, without ever telephoning the depot to check who actually wrote it.
This is why the failure matters more than a technical breach would: it happened inside a process built specifically to be trusted with sensitive data on request, at a company whose entire business is handling exactly this kind of information carefully.
The Secure by Design lesson
Any UK organisation that fields data requests from regulators, law enforcement or government bodies should treat domain authentication as necessary and nowhere near sufficient. The fix is boring and well understood: call back on a published, independently sourced number before releasing anything sensitive, route requests through an accreditation portal rather than open email, and require a second person to authorise disclosure of identity documents or financial history regardless of how official the request looks. None of that needs new technology. It needs a design decision that a plausible email is never, on its own, a valid instruction to move personal data, and that decision has to be made before the request arrives, not while someone is under pressure to respond quickly to what looks like a government deadline.
Also this week
The UK government began rolling out passkeys across GOV.UK One Login on 14 September, giving more than 23 million users a passwordless way into services from driving licence renewals to State Pension checks, following a trial with over 300,000 people. Passkeys use a device's fingerprint, face scan or PIN rather than a shared secret, and the NCSC's case for them is straightforward: a credential that cannot be phished, reused or typed into a fake login page removes an entire category of the social engineering that just cost Revolut its customers' documents. It is a genuine Secure by Design move rather than a compliance exercise, since it changes what is possible to steal instead of adding another layer to defend. Passwords remain available as a fallback, which is the right call for a public service used by people without modern devices.
Separately, the NCSC used a blog post earlier this month to warn that shadow AI, meaning staff using AI tools their employer has not approved, is now a routine feature of UK workplaces rather than an edge case. It cited Microsoft research putting the figure at 71% of UK employees having used an unapproved AI tool at work. The agency's advice is refreshingly realistic: blocking every consumer AI service is not achievable, so the better design is a sanctioned, monitored route for staff to use AI on company data, built before people go looking for their own. Between a government login system and a workplace AI habit, the thread running through this week's stories is the same: control comes from designing what a system will accept, not from trusting that a request looks right.
Sources
- Revolut discloses data breach exposing financial info, passports
- Revolut falls for fake government requests, hands over customer data
- Revolut confirms customer data breach through fake government requests
- Millions of people to benefit from simpler, more secure way to sign in to government services
- NCSC Warns Shadow AI Creates New Security Risks
Worried a plausible-looking request could walk sensitive data out of your organisation? Get in touch.
More like this
- The charity CRM breach that ran on one AWS key, and the 1,000 organisations behind it 10 august 2026
- The Windchill flaw PTC patched in June, and the extortion campaign that followed 25 july 2026
- The fake Claude app that lived on claude.ai, and the 29 firms it caught out 24 july 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.