decrypted · 15 september 2026 · ransomware and cybercrime · uk policy and law · ai and llm security

Revolut handed over customer data because an email looked official

Revolut, the London-based fintech with more than 80 million customers, has confirmed that it handed over customer passports, driving licences, verification selfies and transaction histories to a criminal who simply asked for them the right way. No malware, no exploit, no breached database. An attacker used a legitimate government agency's email domain to submit a data request that carried valid technical authentication, and Revolut staff processed it as routine compliance. The company says systems and funds are unaffected and only a small proportion of customers were hit, though it will not say how many, in which country, or which agency was spoofed. A ransom demand for 10,000 Bitcoin, reportedly posted by the attacker in Telegram channels, is an unverified claim rather than a confirmed fact, and Revolut has declined to comment on it.

Authenticated does not mean authorised

The detail worth sitting with is that the email "carried valid domain authentication credentials", in Revolut's own words. That means the standard checks a mail server runs, the ones confirming a message really did originate from the sender's claimed domain, all passed. What those checks cannot do is confirm that the human sending the message is entitled to ask for a named customer's passport scan. It is the digital equivalent of a courier accepting a parcel redirect because the letter arrived on the right headed paper, without ever telephoning the depot to check who actually wrote it.

This is why the failure matters more than a technical breach would: it happened inside a process built specifically to be trusted with sensitive data on request, at a company whose entire business is handling exactly this kind of information carefully.

The Secure by Design lesson

Any UK organisation that fields data requests from regulators, law enforcement or government bodies should treat domain authentication as necessary and nowhere near sufficient. The fix is boring and well understood: call back on a published, independently sourced number before releasing anything sensitive, route requests through an accreditation portal rather than open email, and require a second person to authorise disclosure of identity documents or financial history regardless of how official the request looks. None of that needs new technology. It needs a design decision that a plausible email is never, on its own, a valid instruction to move personal data, and that decision has to be made before the request arrives, not while someone is under pressure to respond quickly to what looks like a government deadline.

Also this week

The UK government began rolling out passkeys across GOV.UK One Login on 14 September, giving more than 23 million users a passwordless way into services from driving licence renewals to State Pension checks, following a trial with over 300,000 people. Passkeys use a device's fingerprint, face scan or PIN rather than a shared secret, and the NCSC's case for them is straightforward: a credential that cannot be phished, reused or typed into a fake login page removes an entire category of the social engineering that just cost Revolut its customers' documents. It is a genuine Secure by Design move rather than a compliance exercise, since it changes what is possible to steal instead of adding another layer to defend. Passwords remain available as a fallback, which is the right call for a public service used by people without modern devices.

Separately, the NCSC used a blog post earlier this month to warn that shadow AI, meaning staff using AI tools their employer has not approved, is now a routine feature of UK workplaces rather than an edge case. It cited Microsoft research putting the figure at 71% of UK employees having used an unapproved AI tool at work. The agency's advice is refreshingly realistic: blocking every consumer AI service is not achievable, so the better design is a sanctioned, monitored route for staff to use AI on company data, built before people go looking for their own. Between a government login system and a workplace AI habit, the thread running through this week's stories is the same: control comes from designing what a system will accept, not from trusting that a request looks right.

Sources

Worried a plausible-looking request could walk sensitive data out of your organisation? Get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.