

The social engineering fraud that came through the compliance desk
Revolut said an unauthorised third party used a legitimate government email domain to ask for customer data, and that its systems and customer funds are unaffected. Customers are asking the older question: who was guarding the door?
By Katie Delaney / 2026-09-19 / 16 min read

The social engineering fraud at Revolut: what was said, and by whom#

The fox does not chase a headline, it reads the tracks. So start with the tracks. On 12 September 2026, TechCrunch reported that Revolut had confirmed a sophisticated external impersonation scam, in which an unauthorised third party used a legitimate government agency email domain to submit fraudulent requests for information. Revolut said: "Revolut systems and customer funds are unaffected." Revolut calls it an impersonation scam; in folkfox's terms it is social engineering fraud aimed at a process rather than a server, and the process in question is the compliance desk.
According to a notification Revolut emailed to affected customers, which TechCrunch reviewed, the data included identity documents such as passports and driving licences, and may have included verification selfies, account statements and transaction histories. Infosecurity Magazine reported that notifications shown by the researcher ZachXBT also listed IBANs. Revolut said it blocked the sender's address on detection, and alerted the relevant government agency, law enforcement and regulators, as TechCrunch reported.
Revolut has not published a headcount; it told TechCrunch that a limited number of customers were affected. MLex reported on 15 September that the UK Information Commissioner's Office is looking at a report from Revolut concerning about 680 customers, with an ICO spokesperson confirming the watchdog's involvement. The number, then, is MLex's account of a report to a regulator, which is worth remembering whenever a revolut data breach headline quotes it as settled.
The origin of the sender is where reports diverge from Revolut's silence. S-RM, in its 18 September briefing, said attackers used a compromised Italian government email account, and pointed to newspaper reporting for it. Revolut has not named the agency or the country, per TechCrunch, so the Italian detail is a report, not a confirmation from the company.
| Claim | Reported by | Revolut's position or status |
|---|---|---|
| Passports and licences were disclosed; selfies, statements and transaction histories may have been | TechCrunch, 12 Sep | Confirmed an impersonation scam; said systems and customer funds are unaffected |
| About 680 customers involved | MLex, 15 Sep; S-RM, 18 Sep | No figure published; said a limited number of customers were affected |
| A compromised Italian government account was used | S-RM, 18 Sep | Agency and country not named |
| The ICO is assessing a report | MLex, 15 Sep | Said it alerted data protection and financial regulators |
| A ransom was demanded | Several outlets, with differing figures | Declined to comment, per The Record |
- Passports and licences were disclosed; selfies, statements and transaction histories may have beenTechCrunch, 12 SepConfirmed an impersonation scam; said systems and customer funds are unaffected
- About 680 customers involvedMLex, 15 Sep; S-RM, 18 SepNo figure published; said a limited number of customers were affected
- A compromised Italian government account was usedS-RM, 18 SepAgency and country not named
- The ICO is assessing a reportMLex, 15 SepSaid it alerted data protection and financial regulators
- A ransom was demandedSeveral outlets, with differing figuresDeclined to comment, per The Record
Ransom demands have also been reported, and the sums differ from outlet to outlet, so this piece states none; The Record reported that Revolut declined to comment on the extortion claim. A group calling itself IAmNotAVillain has claimed months of access to Italian law enforcement systems, and Security Affairs noted that this claim has not been independently verified. Nothing here is a finding of fault; it is a map of who said what about a case of social engineering fraud.
Why a lawful-looking request outfoxes a firewall#
Social engineering fraud needs no thicket of exploits to get past a firewall when a polite letter will do. The pattern is documented. In a November 2024 Private Industry Notification, the FBI described compromised US and foreign government email addresses being used to send fraudulent emergency data requests to companies, exposing customers' personal information. Its advice to reviewers was blunt: cyber-criminals, it said, understand the need for exigency and use it to shortcut the analysis of the request.
That notice concerned US-based companies, and the Revolut reports involve a European bank, so read the link as a pattern, not a precedent. Security Affairs, citing the Duel researcher Korra, reported that fraudulent European Investigation Orders were used to ask for customer information. Under the EU directive, a European Investigation Order is a judicial decision issued or validated by a judicial authority. A real order arrives with judicial validation behind it; an email domain, however genuine, carries none.
The ICO's guidance on sharing personal data with law enforcement authorities says a controller needs a lawful basis under Article 6, should document that basis, and should provide only data that is adequate, relevant and limited. In folkfox's reading, the page tells a desk what to weigh but leaves the authentication of the sender to the organisation's own process. That undergrowth is where social engineering fraud thrives.
| Item | Value |
|---|---|
| 65% of financial and insurance breaches | 65% of financial and insurance breaches |
| involved the human element, per Verizon's 2026 DBIR | involved the human element, per Verizon's 2026 DBIR |
Verizon's 2026 Data Breach Investigations Report analysed more than 31,000 incidents, including more than 22,000 confirmed breaches in 145 countries, occurring between November 2024 and October 2025. It found the human element present in 62% of breaches, social engineering the third most common pattern at 16%, and pretexting, the invented scenario, at 6%. Its authors add that pretexting has a live, conversational side, so training desk staff "to not be helpful and supportive" toward a manipulator is harder than spotting a strange header.
For a neobank, social engineering fraud finds its quarry exactly here. A compliance officer is paid to be helpful to lawful authority, and a fake authority that looks lawful is the one visitor the desk is built to welcome. The DBIR chapter on financial firms also notes that compromises in the sector were started by social engineering of third parties, a reminder that the sender's own mailbox can be the weak link.

The first 72 hours: a data breach response plan for the compliance desk#
A data breach response plan usually starts in the security operations centre. This one starts at the desk that answers the police. The regulators' clock does not care which desk was fooled. The ICO's guide to personal data breaches says a notifiable breach must be reported "without undue delay, but not later than 72 hours" after the organisation becomes aware of it, and that people must be told directly if the risk to them is high. The General Data Protection Regulation sets the same 72 hours in Article 33 and requires, in Article 34, that the message to individuals use clear and plain language.
Revolut has said what it did on detection: blocked the address, alerted the agency, law enforcement, data protection and financial regulators, and notified affected customers, as reported by TechCrunch and Infosecurity Magazine. What it has also said, in the sentence most quoted, is that its systems and customer funds are unaffected. Both statements sit together in Revolut's account, and both matter to different readers.
Why "our systems were unaffected" can land badly#
The sentence is a system statement, and a customer does not live in the system. To someone whose passport copy reached an unauthorised third party, "unaffected" describes everyone but them. Nothing suggests Revolut's line is inaccurate, and it is not a "no evidence" claim; the risk is a mismatch of register, where the company answers the question its engineers asked and skips the one its customers did.
There is research on how that lands. A CHI 2019 study by Zou, Danino, Sun and Schaub analysed 161 real data breach notifications sent to consumers. Only 22 (14%) stated plainly that the incident happened and which data was involved, while 64 (40%) leaned on a "no evidence" argument, and the authors warn that a lack of evidence is not evidence of absence of harm. The paper is about notification letters in the United States, so treat it as a caution about wording, not a verdict on any firm.
The folkfox interactive story on brand trust under uncertainty holds the same rule: put the denial on the same panel as the claim, then say what the reader should do next. For a fintech CMO that means the first statement names what left the building, in nouns, before it names what did not.
European fintech firm Revolut gave hundreds of its customers’ data to someone masquerading as a government agency
That is the Wall Street Journal's framing on X, and it is the one customers will meet in their feeds; Revolut's position, as it has stated it, is that systems and customer funds are unaffected and that affected customers have been told directly. A brand cannot edit the headline, but it can decide whether its own first hour supplies a better sentence.
That schedule is folkfox's suggested order, not a regulatory template. The ICO's 72 hours governs the regulator notice; the customer message should not wait on the press release, and neither should wait for a final headcount. Say what is known, what is not, and when the next update lands. A data breach response plan that scripts only the security team's first hour has lit only half of the trail.
What a fintech data breach costs, and where trust sits in the bill#
Every fintech data breach has a bill, and the bill has a reputation line. The IBM and Ponemon Institute 2026 study covers breaches experienced by 602 organisations between March 2025 and February 2026, and puts the global average at USD 4.99 million, with financial services averaging USD 6.3 million. IBM's 2025 Cost of a Data Breach report, based on Ponemon research, put the same two averages at USD 4.44 million and USD 5.56 million.
| Item | Value |
|---|---|
| Global average | 4.4 to 5 |
| Financial services | 5.6 to 6.3 |
Money is only the visible half. Customers weigh trust differently, and the two surveys below are vendor-run, so their method matters. Integris, a managed IT services firm, surveyed 1,000 US banking customers and 673 banking executives for its 2026 Banking Trust and Technology Report, and reported that two-thirds of Americans say they would consider switching institutions after a major breach. That is stated intent from one country, not measured churn.
The Thales 2026 Digital Trust Index, fielded by Vanson Bourne among more than 15,500 users in 13 countries, offers the more useful clue for marketers: 45% of consumers prefer stronger security checks even if sign-ups are slower, against 22% who value speed over security. Customers, in other words, will tolerate friction that they can see doing a job.
Put those together and a quiet opportunity appears in the hedgerow. Visible defences against social engineering fraud are a product feature. Invisible ones are only a cost, and a brand cannot point to them in the first 72 hours, because customers never knew they were there.

Building verification into the trust story#
Now the part folkfox cares about most. Trust is the product a neobank sells, and this episode of social engineering fraud came through a human compliance process, not through a server. Crisis communication has to reach the compliance desk, and trust marketing has to say something true about it.
| Item | Value |
|---|---|
| Detection | +1.5 (running total 1.5) |
| Notification | +0.4 (running total 1.9) |
| Post-breach | +1.2 (running total 3.1) |
| Lost business | +1.4 (running total 4.4) |
| Average total | 4.4 |
Read the bar the way a fox reads a hedgerow: the two lines closest to the customer are notification and lost business, and they are also the two a communications team touches. IBM defines lost business to include the cost of losing customers, acquiring new ones and reputational damage, and it counts communications with data subjects and regulators under notification. A better first statement will not shrink the detection bill, but it is one lever on the other side of the ledger.
The earlier folkfox piece Shell Was Not Breached. Its Supplier Was. reached the same fork: technically true sentences that leave the customer's real question standing. The way through is to publish the verification promise before an incident, not the denial after one.
Accurate, and not the question asked
Our systems and customer funds were not affected by this incident.
Names the data, then the next step
A stranger posing as a government agency obtained ID documents, and possibly selfies, for a small group of customers. We have contacted each one. Our systems and customer funds were not affected. Here is what we are changing.
The rewrite is illustrative wording, not Revolut's, and it is longer and less comfortable. That is the point of it. The system statement survives inside it, but as the third sentence and not the first.
Trust is what a neobank sells, and it leaves by the door nobody thought to lock.
So how does a brand make verification part of its story, without handing attackers a manual? Keep the promise about social engineering fraud general and the mechanism private. Say that every government request is verified through a channel the company already holds, that identity documents are released only on a second approval, and that customers are told when their data leaves. The FBI's notice recommends contacting the sender and the originating authority when a request needs validation, which is the callback discipline that a promise like that would rest on.
Five Monday moves for the fintech head of brand#
For a fintech head of brand, Monday needs five moves and no drama. The fintech marketing brief has always been to make the safe thing legible, and social engineering fraud widens where safety gets shown.
First, put the compliance lead in the comms rehearsal. A tabletop exercise for social engineering fraud that only includes security and press will miss the desk where the request arrives. Second, write the customer-first statement now, in two versions, one for a disclosed-to-a-stranger event and one for a systems event, and keep them apart. Third, agree the words for what left the building: nouns such as passport, selfie, IBAN and statement, not "certain information".
Fourth, decide what you will promise about government requests, and check with legal and compliance that every word is true on the day it is published. Fifth, plan the follow-up: the second message, a week later, tells customers what changed. Work on folkfox brand strategy treats that second message as the one that rebuilds trust, since the first only stops the bleeding.
If you want the trust story written and the crisis lines rehearsed together, that is what folkfox content marketing is for, and the conversation starts at the contact page.
Frequently asked questions#
Is my data safe with Revolut after this?
Revolut said its systems and customer funds are unaffected, and that it contacted the limited number of customers whose data was disclosed. It has not published who or how many. If you were not contacted, that is Revolut's account, not a guarantee. Treat unexpected calls or messages about your account as suspicious and use the in-app chat.
What is social engineering fraud in banking?
It is fraud that manipulates a person or a process into releasing data or money, rather than breaking technology. Verizon's 2026 report describes pretexting as inventing a scenario to trick someone into acting, and found the human element in 62% of breaches. A fake government request to a compliance desk is a textbook case of social engineering fraud.
Do fintechs have to report a personal data breach within 72 hours?
Under UK and EU data protection law, a notifiable breach must be reported to the regulator without undue delay and not later than 72 hours after the organisation becomes aware of it. Where the risk to people is high, they must also be told directly, in clear and plain language.
How can a bank verify a government data request?
The FBI recommends contacting the sender and the originating authority when a request needs validation, and checking legal references and documents for signs of tampering. Practical controls against social engineering fraud include a callback to a number already on file, a register of known agencies and second approval before identity documents leave.
Should a brand say its systems were not breached?
Only if it is true, and never on its own. A CHI 2019 study of 161 breach notices found many leaned on reassurance such as no evidence of misuse. Lead with what was disclosed and what customers should do, and put the systems statement after it.
What should a data breach response plan cover for fake requests?
It should treat social engineering fraud as a live scenario, name the compliance and legal desks as first responders, set a callback rule for government requests, script the customer message in plain nouns, and start the 72-hour regulator clock at awareness. Rehearse it with marketing in the room, not only security.
Read more on this topic#
Shell Was Not Breached. Its Supplier Was.
Another case where a technically true systems statement left the customer's real question standing.
Read the pieceFintechDigital banking marketing just became regulatory evidence
Why every promise on a bank's website is now something a regulator can read.
Read the pieceCybersecurityMarketing Built the Breach Surface at Three Airports
How a marketing capture point, not a core system, became the place customer data leaked from.
Read the pieceIs your trust story ready for the compliance desk?
folkfox helps fintech founders and heads of brand write the first 72 hours, the verification promise and the follow-up message, so trust is tested before the request arrives.
Want folkfox in your Google results and AI answers? Set folkfox as a preferred source.