A request came from a legitimate government email domain.
It looked authentic.
Sensitive customer information was released.
Revolut has now confirmed a data breach caused by what it describes as a sophisticated external impersonation scam.
Around 680 customers are understood to have been affected, including 12 in Ireland.
The interesting lesson for businesses is not simply cybersecurity.
It is trust.
And as organisations increasingly introduce AI into workflows involving customer information, legal requests and decision-making, that lesson becomes particularly important.
What happened?
Revolut confirmed on 12 September that an unauthorised third party submitted fraudulent requests for customer information using a legitimate government-agency email domain.
The company responded to those requests.
Information potentially disclosed included:
- names and dates of birth
- postal and email addresses
- phone numbers
- passports and driving licences
- identity-verification selfies
- account information
- transaction histories
Revolut says its underlying systems and customer funds were not compromised.
Affected customers have been contacted.
The important distinction is that this was not a traditional attack where someone broke directly into Revolut's banking systems.
The organisation was persuaded to release legitimate information to someone who appeared authorised to receive it.
This is not a confirmed AI breach
There is currently no public evidence that AI caused the Revolut incident.
That distinction matters.
Not every technology, security or data-protection incident should be rebranded as an AI problem.
But the case demonstrates a governance problem that becomes increasingly relevant when AI is introduced into operational workflows:
A credible-looking input is not the same as a verified input.
Imagine an AI agent that helps process government information requests.
It receives a request from a genuine government domain.
It recognises the format.
It retrieves the requested records.
It prepares or even triggers a response.
Automation can make a good process faster.
It can also make a weak verification process faster.
Why verification matters more as AI becomes autonomous
Businesses are beginning to move beyond AI that simply writes text.
AI systems and agents can increasingly:
- retrieve company information
- access internal systems
- process customer records
- classify requests
- recommend actions
- trigger workflows
That makes permission and escalation design increasingly important.
The question should not simply be:
“Can the AI do this?”
It should also be:
“Under what circumstances is the AI allowed to do this?”
Four lessons for AI-enabled businesses
1. Never use appearance as the only proof of authority
A recognised email domain, familiar formatting or convincing language should not automatically authorise disclosure of sensitive information.
High-impact requests need independent verification.
2. Define what AI can access
An AI assistant does not necessarily need access to every dataset simply because that information exists.
Permissions should reflect the task.
Sensitive identity, financial, employee and customer information deserves particularly careful access controls.
3. Keep meaningful human escalation
Some actions should require a second person, independent verification or another approval step before data is released.
Human oversight should be capable of stopping the process, not merely observing it.
4. Plan for incidents before they happen
Organisations should know:
Who reports a suspicious AI action?
Who can stop a workflow?
Who investigates?
What information is logged?
Who handles data-protection notification?
Incident response belongs inside AI governance, not beside it.
The GDPR lesson is already clear
The GDPR requires organisations to implement technical and organisational security measures appropriate to the risk.
Ireland's Data Protection Commission also specifically warns organisations about phishing and social-engineering attacks.
Its guidance encourages verification where unusual requests appear to come from trusted sources.
For qualifying personal-data breaches, GDPR also contains notification requirements to supervisory authorities and, where the risk is sufficiently high, affected individuals.
These obligations exist independently of the EU AI Act.
Blanche perspective
The Revolut incident is not an AI compliance case.
But it is a useful warning for the next generation of AI-enabled business processes.
AI can analyse faster.
AI can retrieve faster.
AI can respond faster.
None of those capabilities prove that the original instruction was legitimate.
Good AI governance therefore needs more than rules about which chatbot employees can use.
It needs clear answers to:
What can AI access?
What can AI act on?
What needs independent verification?
When must a human step in?
The more capable AI becomes, the more important those boundaries become.
Sources
Primary and authoritative sources used for this Insight.
- News reporting: Reuters, Revolut statement confirming disclosure after fraudulent government requests (12 September 2026)
- News reporting: RTÉ, 12 Irish Revolut customers impacted by data breach (15 September 2026)
- News reporting: TheJournal.ie, Data of a dozen Irish customers understood to be impacted
- News reporting: Financial Times, Revolut handed nearly 700 customers’ data to scammers
- Official regulator guidance: DPC, Phishing and Social Engineering Attacks
- Official regulator guidance: DPC, When your personal data has been affected by a breach
- Binding EU law: GDPR, Articles 32, 33 and 34, security and breach notifications