Anti-Financial Crime & Financial Crime Compliance
Regulatory Intelligence Leadership | Insight | Network

Cyber, Financial Crime, Fraud, Tech

ANALYSIS: Revolut breach puts renewed scrutiny on fake law enforcement data requests

Woman holds smartphone with Revolut app in front of displayed Revolut logo in this illustration taken February 4, 2020. REUTERS/Dado Ruvic/Illustration/File Photo

By CARLO BOFFA, EU Correspondent

The Revolut data breach disclosed on Saturday has highlighted one of the least-reported, yet potentially most effective, forms of fraud: fake law enforcement data requests.

Law enforcement and government agencies send hundreds of thousands of requests each year to social media platforms, telecoms companies and financial institutions, asking them to hand over customer data to assist investigations.

Such requests are normally accompanied by a court order or other legal documentation. In emergencies, however — particularly when there is an imminent threat to life — officers can send urgent requests without the usual supporting paperwork.

That creates a dilemma for companies. Because the requests are meant to deal with matters of life and death, there is often little time to verify the sender’s identity before complying.

“Companies have a duty to answer valid legal requests, often on a deadline, and the people who handle them want to help an investigation,” said Matt Donahue, co-founder and chief executive of Kodex, a company that builds software to manage such requests.

“Criminals build the request to press on both,” he added.

By compromising law enforcement networks, attackers can obtain legitimate credentials and use them to contact companies while posing as genuine government officials. Because the requests can come from official email addresses or otherwise appear authenticated, compliance teams can struggle to distinguish them from the real thing.

The consequences can be severe. Data obtained through fraudulent subpoenas can include social media posts, browsing information and, in Revolut’s case, bank statements and postal addresses. In the wrong hands, such information can expose victims not only to financial crime but to physical danger.

A terrifying threat

Revolut’s case is far from an isolated incident. The phenomenon received widespread attention in 2022, when security researcher Brian Krebs published an investigation into the growing use of fake emergency data requests.

By then, companies including Binance, Coinbase, Meta and Microsoft had already fallen victim to fraudulent emergency requests.

Krebs described the practice as “terrifying and highly effective,” highlighting a fundamental problem facing companies:

“The receiving company finds itself caught between two unsavory outcomes: failing to immediately comply with an EDR — and potentially having someone’s blood on their hands — or possibly leaking a customer record to the wrong person,” he wrote.

For criminals, the mechanics can be relatively simple. Law enforcement agencies make easy targets, as thousands run their own mail servers, many without single sign-on or two-factor authentication, according to Donahue.

Credentials belonging to police and government officers are then sold on criminal forums on the dark web for as little as $100, he said.

Once obtained, the credentials can be used to authenticate accounts on third-party platforms designed to verify law enforcement agencies before the attackers approach their targets.

The stolen information can then be sold or used directly against victims. In some cases, criminals have used personal data for wrench attacks, threatening or physically targeting cryptocurrency holders to force them to surrender access to their assets.

The blindspot

The Revolut breach shows that fake law enforcement subpoenas remain a problem for global companies despite the safeguards introduced in recent years.

Large technology and financial companies can receive thousands of requests each week from domestic agencies as well as authorities in countries where they have little or no existing relationship. Verifying every request is therefore difficult, particularly when it is framed as an emergency.

Donahue, who spent years at the US Federal Bureau of Investigation filing data requests to companies before moving to the private sector, said the volume of requests is growing by 40 per cent annually.

“A company that answers a fraudulent request has no reliable way to learn that afterward unless someone asks the agency. How many have been answered and never discovered is not knowable,” he said.

The FBI recommended in 2024 that companies strengthen passwords, use multi-factor authentication, and apply critical thinking to spot doctored logos and fake legal codes referenced in requests.

Yet Donahue pointed out that the most fundamental flaw is that companies’ defence systems are often built to confirm a server, not a sender.

“The question a legal team needs answered is whether the requester is a real, currently authorized investigator entitled to this data. No email header carries that,” he said.

Failing to prevent these scams is not only a problem for companies and their customers — it is a problem for the system itself. By demonstrating that apparently legitimate law enforcement requests can be forged, attackers undermine trust in the very mechanism designed to protect lives.

If companies become more reluctant to respond quickly to emergency requests, legitimate investigations could be slowed, putting at risk people whose lives may genuinely be in danger.

AML Intelligence
We hope you enjoyed reading this article

If you would like unlimited access to AML Intelligence premium articles, newsletter delivered twice a week, access to our Global Bank Fines and Penalties database, free access to Boardroom Series events and much more, select one of our subscription options and become a subscriber!