Security / Privacy
A Real Government Email Domain Can Still Carry a Fake Request
Revolut said it disclosed customer information after fraudulent requests arrived through a legitimate government-agency email domain.
#Security #Data Breach #Social Engineering #Identity #Privacy
Security training often says to check the sender.
That is useful, but it is not enough.
Revolut confirmed in September 2026 that it disclosed information about a limited number of customers after fraudulent information requests were sent from a legitimate government-agency email domain, according to TechCrunch.
The exposed information could include identity and contact details and, for some customers, copies of identity documents, verification selfies, account statements, and transaction histories.
The lesson is bigger than one company: a trusted-looking channel does not prove that the request itself is legitimate.
The defensive habit
Organizations need a second verification path for sensitive requests. A request for passports, financial records, recovery changes, or other high-value data should not be approved merely because the email address looks authoritative.
For individuals, the same principle applies.
If a bank, employer, platform, carrier, or government office contacts you asking for sensitive information or an account change, independently contact the organization through a known official channel instead of relying on the message that reached you.