Industry News

Revolut Breach Shows How Fake Law Enforcement Requests Can Bypass Security Entirely

The Currency Analytics · 16 Sept 2026
Key Takeaway Australian SMBs handling customer identity documents should have strict, verified procedures for confirming the authenticity of any law enforcement or regulatory data request before releasing sensitive information.

A hacker posing as an Italian law enforcement official convinced Revolut to hand over passport copies and sensitive personal data for 680 customers, then demanded a ransom of 10,000 Bitcoin. There was no hacking in the technical sense; the attacker simply exploited EU rules requiring companies to respond to official data requests, and Revolut appears to have believed the request was genuine.

The incident highlights a wider weakness in Know Your Customer (KYC) processes, which require businesses to collect and store large volumes of identity documents such as passports, selfies, and proof of address. This creates a valuable target for criminals, since a successful social engineering attempt can unlock a large trove of verified personal data at once. Analysts note this is part of a much bigger pattern: 343 million people in the United States alone were affected by data breaches in 2026.

The case also shows how regulatory compliance pressure can be turned against a company. Because businesses often fear penalties for refusing a law enforcement request, attackers can exploit that urgency to bypass normal verification checks entirely, using impersonation rather than technical exploits.

Summarised by CISO AI from The Currency Analytics. We link back to every original so you can read it yourself.