Revolut’s user data was stolen by a “forged government email.” Many people’s first reaction is to laugh at a fintech company being so easy to fool—but what really needs to be understood is why these attacks specifically target financial institutions and often succeed.

This scam has a formal name: forged legal process. The attackers impersonate courts or law-enforcement agencies and send what appear to be legitimate subpoenas or “urgent disclosure requests” to the company’s legal and compliance teams. Its impact is in the design: legal teams receiving a “court order” must respond within a limited time window. Refusing may be construed as obstructing justice, but complying may not leave enough time to verify every detail of the document. The attack surface isn’t a system vulnerability—it’s the process and people constrained by institutional deadlines. For fintech firms with tens of millions of users, one mistaken judgment can lead to large-scale data leakage.

Revolut is a prime example of this kind of target: it has expanded extremely quickly, has a massive user base, and its compliance program has consistently lagged behind the pace of the business. Moreover, its licensed entities span multiple jurisdictions—so any “government” can be fabricated. It’s also not the first time data was leaked: in 2022, it previously exposed information of around 50,000 users due to issues with a third-party interface. The problem has never been a single point; it’s whether risk controls can keep up with the scale in a fast-growing company.

Next, there are three things to watch: how regulators classify this “forced handover”—whether it counts as force majeure or corporate negligence—which will determine fines and liability for compensation; whether the entire industry will build a unified channel to verify legal documents; and a question every user should ask customer support: is your financial app able to hand over your information based solely on a single email? #Revolut被骗交出用户数据被假政府邮件骗取