Revolut data incident: authentication is not authorization.
The publicly reported incident is not described by Revolut as a compromise of its internal systems. The more useful lesson is about trust: a request can arrive through a technically legitimate channel and still be fraudulent.
A trusted channel was not enough.
On 12 September 2026, Revolut confirmed that it had disclosed sensitive customer information to an unauthorised third party after receiving fraudulent information requests sent from an email address on a legitimate government agency domain.
Revolut said that a limited group of customers was affected and that its internal systems and customer funds were not compromised. Reporting based on customer notifications said the exposed information could include identity and contact data, identity documents, verification selfies, account statements and transaction histories.
This distinction matters: describing the event simply as a technical compromise of Revolut would be misleading. The reported failure occurred in a process that handled apparently authoritative requests.
Authenticate the sender. Authorise the request.
Strong email authentication, a recognised domain or a known organisation can be useful trust signals. None of them should replace a decision process for releasing sensitive data.
Verify independently
For high-risk requests, confirm identity and mandate using a second, independent channel rather than replying only inside the original conversation.
Use dual control
Require a second approval when a request exposes identity documents, financial information or unusually large volumes of customer data.
Detect anomalies
Monitor frequency, scope, requester patterns and unusual data combinations. A valid-looking channel can still carry abnormal behaviour.
Minimise disclosure
Release only the fields that are required and document why each category of information is necessary for the request.
External posture is only one layer.
An external website audit cannot test an internal legal-request workflow like the one reported here. It can, however, reveal visible weaknesses in web configuration, exposed technologies and public attack surface that deserve attention.
That is why Interface Trust separates the free external signal from deeper expert analysis. A good score is not a guarantee of security, and a poor signal should be investigated in context before remediation is commissioned.
