social-engineering A field note by Vikrant Sharma
Revolut handed over customer data to scammers pretending to be cops
A fintech with 50 million users fell for spoofed government data requests. The weak link was not the encryption.
Revolut confirmed last week that attackers impersonated law enforcement agencies and requested customer data through official channels. The company handed over sensitive information for an unknown number of users before catching the scam. The attack did not exploit a zero-day or crack encryption. It exploited the process every company builds to comply with lawful data requests. Someone forged government emails or legal documents convincingly enough that Revolut’s compliance team approved the handover. This is scarier than a database leak. A database leak is a technical failure you can patch. This is a social engineering attack that sits inside the same workflow banks use to respond to subpoenas and emergency disclosure requests. The Reuters piece does not say how many requests were fake or which jurisdictions the attackers impersonated, but the fact that it happened at all means the verification step failed. Most companies verify government requests by checking sender email domains and matching case numbers against public records. If the attackers compromised a real government email account or forged headers well enough to pass SPF and DKIM checks, that verification collapses. Add urgency (“this is an emergency request, lives at risk”) and the compliance officer approves it. Revolut has 50 million customers. The company did not disclose how many were affected, which suggests the number is not zero and not trivial. The fix is not better encryption. The fix is out-of-band verification for every single request, probably a phone call to a known number at the requesting agency. That adds friction, but the alternative is handing PII to whoever writes a convincing letter.
Source: Revolut confirms customer data breach, falling for fake government requests