cyberx_█
← back to indexCompliance & Regulation9 min read

The email was the government's. The request wasn't.

Revolut handed over documents, verification selfies and customer statements to someone writing from a legitimate government domain. The request was fake. In Brazil, the law lets an administrative authority demand subscriber data without a judge, and the urgency exception widens that door further. What the Brazilian rule limits — and what it doesn't prevent.

Robert F.
The email was the government's. The request wasn't.
▸In this article

On Saturday, 12 September 2026, Revolut confirmed that it had handed customer data to someone with no right to it. There was no system intrusion, according to the company. There was a request.

In the notice sent to affected customers, the British fintech explains what happened in two sentences. The request for information "appeared to come from a legitimate government agency" and originated from "an unauthorised email account", sent "directly using the official email domain" of the body in question. "As the communication carried valid domain authentication credentials, it was actioned under the reasonable belief that it was an authentic request."

The whole story is in that sentence. The email was the government's. The request wasn't.

What was handed over

The notice lists four categories of data:

  • identification: full name, date of birth and occupation;
  • contact details: postal address, email and phone number;
  • document and verification: a copy of the passport or driving licence and the selfie submitted during identity verification;
  • financial data: statements, including IBAN, account status and opening date, withdrawal records and the full transaction history, "including Bitcoin".

The company notes that no facial biometric telemetry data was involved.

Revolut does not say how many customers were affected; it refers to "a limited number". According to the Financial Times, the figure was 680, which City AM confirmed with a source close to the bank. The company says that once it detected the fraud it blocked the address and notified the agency, the police and both the data protection and financial regulators. The ICO, the UK data protection authority, told City AM it had received the report and was "assessing the information provided"; the Financial Conduct Authority, which supervises the company in the UK, said it was "in contact with the firm to understand the impact".

What Revolut did not say is also information: which agency, in which country, and whether the incident is confined to any single market. According to City AM, a group claiming responsibility has begun demanding payment and threatening to publish more data each day. Revolut has confirmed neither the attribution nor the content, and none of the group's claims has been verified.

The scam has a name, and the FBI warned about it in 2024

In November 2024, the FBI issued a private industry notification about exactly this pattern: compromised government email accounts, in the United States and elsewhere, used to send fake emergency data requests to companies. The document defines an emergency request as one used to obtain information "immediately" from a company, "bypassing further review of the request's legitimacy".

The alert describes a market. In August 2024, a criminal advertised on a forum the sale of "high-quality .gov emails" for "data requests", offering buyer guidance and real stolen subpoena documents. In March, another claimed to hold government emails "from over 25 countries". In December 2023, fake requests were arriving with assertions that someone "will suffer greatly or die" unless the information was handed over.

And the FBI's recommendation to companies is the sentence that sums up the problem: criminals "understand the need for urgency and use it to shorten the required analysis".

Revolut is not the first case. It is the case in which the recipient of the request was a bank, and what went out was the entire identity verification dossier.

The Brazilian door: the official request with no judge

Revolut also operates in Brazil, authorised by the Banco Central as a direct credit company since 2023. But the Brazilian question does not depend on whether any Brazilian customer was caught up in the incident. It is a different one: through which door would a request like this arrive here, and what could it carry out?

The door exists and it is in the statute book. The Marco Civil da Internet allows an administrative authority with legal competence to requisition subscriber data without a court order (art. 10, § 3), and the Money Laundering Act gives the police and the Public Prosecutor's Office the same access, "regardless of judicial authorisation", at banks, telecom operators, providers and card administrators (art. 17-B). This is what the digital evidence glossary called data that leaves by official request.

The decree implementing the Marco Civil sets out what the request must contain. The authority must state "the legal basis of express competence for the access and the grounds for the request", specify "the individuals whose data is being requisitioned and the information sought", and "collective requests that are generic or unspecific are prohibited" (Decree 8,771/2016, art. 11).

What the Brazilian rule limits

This is the part that coverage abroad does not have. The same decree defines what subscriber data is: parentage, address and personal particulars, "understood as surname, given name, marital status and profession". In 2024, the Supremo Tribunal Federal (STF) fixed that limit as binding precedent for art. 17-B: access without a judge is constitutional, "excluding" any subscriber data "beyond that relating to personal particulars, parentage and address".

Set beside Revolut's notice, the arithmetic is exact. Of everything handed over, only the name, the occupation (profession, in the decree's vocabulary) and the postal address fall within that definition. Date of birth, email, phone number, passport, selfie, statements and transaction history all fall outside the official-request door.

Statements and account activity are another house entirely. Financial institutions "shall maintain secrecy in their active and passive operations and services rendered" (Complementary Law 105/2001, art. 1), and what leaves that house is information "ordered by the Judiciary" (art. 3). In Brazil, such an order is entered by the judge in Sisbajud, the National Council of Justice system that communicates with financial institutions, specifying the person under investigation and the period covered by the lifting of secrecy.

This does not mean no bank here would fall for a fake request. It means that if one did, it would have handed over what the law does not permit to be handed over through that channel.

What widens the door: urgency

The point where the FBI alert and Brazilian law meet is haste. Here, direct requisition expands in three places.

The Code of Criminal Procedure allows police chiefs and the Public Prosecutor's Office, in the crimes against personal liberty it lists, to requisition "subscriber data and information on the victim or on suspects" from "any public bodies or private-sector companies", to be complied with within 24 hours (art. 13-A). The request must state the name of the authority, the investigation file number and the responsible police unit.

At the STF, in Declaratory Action of Constitutionality (ADC) 91, the precedent proposed by the rapporteur, Justice Cristiano Zanin, accepts that, "in exceptional situations, characterised by imminent danger to legal interests of high value", the police authority or the Public Prosecutor's Office may requisition "directly" subscriber data associated with traffic data, with the act "submitted to subsequent judicial review". This series' analysis of the subject traces the chronology of the judgment.

And in ADIs 5,059 and 5,073, on the police chief's power of requisition, the rapporteur's vote by Justice Dias Toffoli, delivered on 27 August 2026, accepts, for the crimes under arts. 13-A and 13-B of the Code, direct provision of location data and of call and message records "without prior judicial control, but always subject to subsequent judicial control".

In both STF cases what exists are votes and a proposed precedent, not a fixed one: the judgments were suspended as of 15 September 2026, and the text of the Code is the only one of the three in force. But the design is the same in all three: where there is urgency, the judge comes afterwards. Subsequent review serves to annul the evidence, if appropriate. It does not return the data to whoever it was handed to.

Authenticating the channel is not authenticating the order

An email from the right domain proves that the mailbox belongs to the agency. It does not prove that whoever wrote it has the competence to make the request, nor that the request exists within a real proceeding.

Brazilian law already requires the second thing, and that is why it matters more than the first: "legal basis of express competence". Checking competence is the verification. The FBI's recommendation says the same in another language: check whether the law cited in the request is the one that applies to the requesting authority, and, when in doubt, confirm with the originating authority through a separate channel.

A bank that trusts the domain is checking the envelope.

In one line

An email from the right domain proves who owns the mailbox, not who holds the power to ask. Brazilian law knows the difference; urgency is where it risks forgetting.

Sources

About the author

Robert F.

Robert F. is the founder of CyberX, a digital intelligence operation applied to investigation, based in Brazil with cross-border reach.

He works in OSINT, on-chain tracing and antifraud for legal teams, corporate compliance, banking antifraud and public authorities.

In CyberX publications we write about what can be said in public — fraud and scam typologies, digital threats, on-chain tracing, regulation, and what separates an investigation from a database lookup. Never about a case we work on, clients, matters under judicial secrecy, or operational detail that would compromise an investigation in progress — ours or anyone else's. A third party's case enters through the public official act, and through what it teaches, not through what it exposed.

Related reading

CyberX works in digital intelligence applied to investigation — OSINT, on-chain tracing, and fraud prevention. This content is informational and does not constitute legal advice.

how we write →