FAKE GOV. REQUEST.
REAL DATA OUT.
Revolut confirmed that sensitive customer information was disclosed to an unauthorised third party after fraudulent requests arrived from a legitimate government-agency email domain. Reported exposed data covers identity and contact details and copies of identity documents; TechCrunch reports the affected data may also have included verification selfies, account statements and transaction histories. Revolut says its systems and customer funds were unaffected. No intrusion is described — the disclosure workflow was the attack surface.
One bank. A known attack class.
timelineApple · Meta · Discord
Recursion Team / Lapsus$ actors pull user data with forged emergency data requests sent from compromised police mailboxes.
Verizon
Fake EDR from a Proton Mail address yields a woman’s address and call logs; the requester appears at her home armed.
Productized
FBI IC3 PIN documents gov email credentials from 25+ countries sold for EDR fraud. Kits ~$100; verified police mailboxes ~$1,000; per-request service $1,000–3,000. PayPal MLAT forgery attempted.
Revolut
Legitimate agency domain + passing credentials → full customer files released. The disclosure desk had no bounded, revocable, auditable state between “request received” and “file sent”.
The structural diagnosis
evidenceof 1,597 processed EDRs failed second-level verification. Nearly 4,000 law-enforcement user accounts suspended. Single-check full disclosure is empirically indefensible.
The emergency channel is optimized for speed; the clock is the weapon; each firm verifies alone and never sees the pattern. Every speed optimization is a verification gap.
Digital Authenticity for Court Orders Act (Wyden / Tillis / Whitehouse) — cryptographic signing of legal process — not passed. No external basis to trust a bare email exists.
No model was wrong. No malware ran. An e-mail channel was treated as proof of authority. The institution's authority plumbing failed: "request received" and "full customer file released" had no bounded, revocable, auditable state machine between them. > This is a layer-02/03 failure (policy + evidence) — exactly the layer the Sovereign Decision Plane attacks.
Revolut failure catalogue
empirical · each mapped to its counter-planeRecord supervisory AML fine: monitoring heuristics missed high-velocity structuring, pass-throughs and cross-border flows without economic rationale.
Declined POS purchases misread by the US adapter as valid refund grounds; gross $23M drained via ATM, ~2/3 of FY2021 net profit.
Async dispatch pipeline paid out from NCA-frozen accounts before stop-notices propagated.
IT architecture prevented auditors verifying transaction completeness — 75% of reported revenue unverified; multi-year PRA licensing delay.
Exposure magnitude (log scale)
canvasEvery entry: a check that returned the wrong answer (fake-pass), a state that could not be revoked (frozen funds), or a trace that could not be audited (revenue). > Not perception failures. Authority plumbing failures.
Sovereign Decision Plane
the old approach, upgradedLive Case 02 state machine — run it
simulator// select a trajectory
Hard invariants — not prose, tests
CI asserts| # | Invariant | Kills which failure |
|---|---|---|
| 01 | Hard red ⇒ no ALLOW — full or provisional. A fake-pass can never become authority. | Revolut 2026 fake gov request |
| 02 | AI override = false — always, both paths. | Automation complacency |
| 05 | PROVISIONAL ⇒ cap + TTL — temporary authority bounded in exposure and time. | NCA £1.7M unbounded payout |
| 06 | TTL expiry ⇒ state change — silence never extends provisional status. | Deferred-control rot |
| 09 | Late FAIL ⇒ no unrestricted ALLOW — new evidence reduces authority, monotonically. | BDO unauditable trail |
| 12 | Aggregate exposure bounded — concurrent provisional cases per counterparty cannot sum past ceiling. | 500-file week-one requester |
| 14 | Rule changes are events, not edits — revision packet supersedes assumption set, with cause, author, hash. | “Why did you allow that?” has a checkable answer |
∀a∈Accounts ∀t∈Tx :
type(t,refund) ∧ target(t,a)
⇒ ∃t'∈Tx : type(t',debit) ∧ source(t',a)
∧ state(t',settled) ∧ amount(t) ≤ amount(t')
> Revolut US exploit → SMT verdict: UNSAT → dispatch terminated < 5 ms.
New build: Sovereign Disclosure Plane
live case 03 · proposalThe earlier version of this page proposed provisional disclosure before the principal was verified. That is withdrawn. Once an address, phone number or ID fragment leaves the bank, nothing about it is provisional. Replacement rule: HOLD — preserve, prepare, escalate internally; packet_out = null until principal + capacity + mandate + scope pass. A case may be provisional. An outbound packet may not.
No statute obliges trusting an unverified channel. Full immediate disclosure is therefore not compliance — it is unexamined risk appetite. Tag it internal discretion and make it defensible, or replace it.
Identity must pass an independent second channel (registry lookup / known-requester network / callback via independently sourced number) — the MRZ-check analog. Channel match: necessary, never sufficient.
Global models + the proposed one
benchmark| Model | Extraction | Granularity | PII / GDPR | Regulator uptake |
|---|---|---|---|---|
| Arival “regulator-as-client” (2019–23) | Read-only UI/API into bank DB | Absolute (raw logs) | Low — fishing risk | Low — liability fear; later OCIF pressure |
| AuRep Data Cube (Austria) | Replication into inter-agency hub | High (Smart Cube) | High — pseudonymized | Reference — statutory |
| MAS COSMIC (Singapore) | Threat-triggered exchange, 6 banks | Targeted (suspects) | High — legal immunity | High — partnership |
| LEAO portals (Revolut/Monzo/N26) | Encrypted archive per court order | Point (named subjects) | High — minimization | High — standard |
| Sovereign Disclosure Plane (proposed) | HOLD until authority complete; scope-bound release only | Minimised at dispatch | Minimized by construction | To earn — executable proof, CI-tested |
Assumption set — disclosure controls
excerptgov_request_authenticity: channel_match: necessary_not_sufficient second_channel: mandatory_for_full_content may_be_deferred: false # R002 — was true, withdrawn 14 Sep provenance: { basis: internal } # no instrument compels trusting a bare email hold_state: # replaces provisional_disclosure (R002) permits: [preserve, prepare_internal, restrict_deletion, escalate] forbids: [release_pii, export_kyc, disclose_tx_history] packet_out: null aggregate_exposure: bounded # invariant 12 counterparty_notice: mandatory # PACKET 003 — outward-facing revision_path: # incident revises the rule trigger: deferred_control_resolved_FAIL effect: assumption_set superseded by revision packet (cause, author, hash)
Horizon: prove, don't hand over
next sprintzk-SNARK proofs of solvency / screening completeness — zero bytes of customer data cross the perimeter.
Banks jointly compute on encrypted payment graphs — smurfing rings visible at sector level, keys never shared.
Regulator agents execute in hardware enclaves on bank silicon; norms published as executable code (ISDA CDM / FIRE).