
Why a polite email beat the compliance process of a bank with 80 million customers.
On 12 September, Revolut told the world it had handed customers' passport details, verification selfies and bank statements to a stranger. No zero-day attack, no leaked password. An email arrived from a real government address, asked politely, and got what it asked for.
Most of the reporting I have read on this treats it as a technology story. But I think it is a people story, and the sooner we recognise that, the sooner we can do something useful about it.
What happened
On 12 September, Revolut confirmed it had released customer data to someone posing as a government agency. The requests came from a real agency email address, so the compliance team handled them like any genuine legal request. Revolut called it "a sophisticated external impersonation scam" (statement to TechCrunch).
What went out: dates of birth, home addresses, email addresses and phone numbers, passport and driving licence details and, for some customers, verification selfies, bank statements and transaction histories. The Financial Times put the number affected at 680 (Revolut will only say it was "limited"). The attackers are reportedly demanding 10,000 Bitcoin (The Register). The ICO is assessing a report, and the FCA says it is engaging with the firm.
Note that Revolut's systems were untouched and customer money was never at risk. Nobody actually hacked Revolut. Someone asked from the right email address, and a process built to say yes said yes. And it gave away a lot of sensitive personal information.
The check that passed was answering the wrong question
Revolut's own notice to affected customers, quoted by SOFX, said the request carried "valid domain authentication credentials".
Domain authentication proves that an email came from a particular mail system. If the sender's address ends in a real agency's domain (like gov.uk, for example) and the authentication checks pass, the email did leave that agency's servers. What the check cannot tell you is whether the human who pressed send was entitled to. A compromised mailbox passes every technical test, because technically nothing is wrong with it.
We know this can happen. In November 2024 the FBI warned that criminals were buying or phishing their way into police and government email accounts, then using them to send fake emergency data requests to companies. Krebs on Security reported one seller charging between $1,000 and $3,000 per successful request. They also noted that Verizon alone received more than 36,000 emergency data requests in six months in 2023 and complied with around 90 percent of all the requests it received.
So the attack that hit Revolut this month was very likely for sale, at a known price, nearly two years ago. So whilst the technology worked as designed, it did not ask the relevant questions.
Two forces and one conscientious human
When I look at this as a behavioural scientist rather than a security person, I see a textbook piece of influence, and none of it is exotic. There are two well-documented forces of how people work in play.
The first is authority. Cialdini's authority principle (see his book Influence, 1984) runs on credible signals, and the most credible signal of all is a real one. Stanley Milgram's subjects (in his 'obedience to authority' studies) did not obey an actor in a lab coat because they were stupid. They obeyed because the lab coat was a credible signal, and credible signals are what our brains are built to trust. A government domain is the digital lab coat, and this one was real. The person wearing it had 'borrowed' it.
The second is mindlessness, in Ellen Langer's sense. We respond to the form of a request more than its content, especially when it looks routine and low-stakes. In her 1978 photocopier study (Langer, Blank and Chanowitz), a bare request to jump the queue got 60 percent compliance. A real reason ("because I'm in a rush") got a yes 94 percent of the time. And an empty request that only had the shape of a reason ("because I have to make copies", asked in a queue for the copy machine!) got a yes 93 percent of the time. The form did the work, and the brain filed the request under "normal". Daniel Kahneman later popularised the label System 1 for this fast, automatic mode of thinking (Thinking, Fast and Slow, 2011). Interestingly, when the favour got bigger, 20 pages to copy instead of five, the empty reason stopped working and people started to think. A fraudulent legal request is engineered to keep feeling small, so the scrutiny never switches on. And the odds sit with the attacker: the fraudulent request only has to work once, while the person on the other end has to catch it every time, on a Friday afternoon at 4pm with a full inbox.
The uncomfortable truth is that the employee who released the data was not careless. They were responsive, they knew how a government request is supposed to be handled, and they handled it. The colleague who let the same email sit unread for a week would have saved the company by accident. I have sat in enough boardrooms to know the reassuring line that comes next: "we've got compliance for that." Revolut did. And compliance is what the attacker used.
I wrote a while ago that hackers don't break in, they log in. This time they did not even need to log in. They just asked the front desk.
The same door opens everywhere
Revolut has been here before. In September 2022 an attacker socially engineered an employee and got at the records of 50,150 customers; the Lithuanian data protection regulator investigated (SecurityWeek). Same door, four years apart. I don't say that to kick Revolut. I say it because if a bank with more than 80 million customers, a full-time compliance function and the budget to match can be talked into handing over passport details by a well-formed email, twice, then the only useful question for the rest of us is which of our inboxes it lands in.
For most of the SMEs I work with, that inbox is finance ("the supplier has changed their bank details"), HR ("can you send over the P60s for the audit"), or whoever handles data subject requests and legal notices. The requests arrive from plausible addresses. They ask for things the recipient is allowed to give. And the person receiving them is, like Revolut's compliance officer, good at their job.
Notice what the attackers took, with customer money left untouched: the documents that let someone open accounts, pass identity checks elsewhere and target rich individuals one at a time. Personal data is the payload now, and most small firms hold more of it than they realise, like staff details, client ID copies or right-to-work scans.
What behavioural science says to do instead
The industry's reflex after a breach like this is to buy something. Better email filtering, another dashboard. I have said it in enough keynotes to be boring about it: the bulk of the money goes to technology, yet the majority of the problems come from human behaviour. Revolut's filters worked, which is exactly why they are no help here.
COM-B, the behaviour model we use for our Psybersafe episodes (Michie et al, University College London, 2011), says a behaviour happens when three things line up: the Capability to do it, the Opportunity to do it, and the Motivation to do it. Run the Revolut incident through those three and the fix writes itself.
Capability. The person who receives an official-looking request needs a script, an actual sentence rather than a policy document, for pausing an authority figure. Something like: "Thanks, I'll call you back on the number we hold for your office." If they have never said those words out loud, they will not say them under pressure.
Opportunity. Out-of-band verification has to be built into the routine, not bolted on as a reminder. The step that would have stopped this is dull: before releasing identity documents, call the agency back on a number you already hold, never one from the email. Revolut has not said whether it had such a step, and I am not claiming it did not. But any check that loops back through the same mailbox the request came from can be answered by whoever controls that mailbox, which here was the attacker. Verification only counts when it leaves the channel the request arrived on.
Motivation. Refusing has to feel safe, and this is the one organisations skip. Amy Edmondson's work on psychological safety shows that people only speak up, question or delay when they believe it will not cost them. If the culture punishes the officer who delays a real police request more than the one who releases data to a fake one, people will release the data every time, and they will be right to. Give them explicit permission, from the top, to make an authority figure wait. Then thank the first person who does it, publicly, because the thanks is the training.
None of that costs what a new security product costs. It costs a habit, practised until it is the default, which is what training is supposed to be for.
The attacker never went near Revolut's technology. The whole thing turned on one person, on a working day, doing their job well. That person is in your company too, and they deserve better than a policy PDF.
