Infrastructure September 13, 2026 bearish ⇧ 59 pts across 1 thread

Revolut Breach Shows Law Enforcement Request Risk

Revolut confirmed a data breach triggered by spoofed government data requests, and the HN thread surfaced a structural problem that most companies have not solved. Someone who had run a law enforcement request desk described the actual process: PDFs from .gov-ish email addresses, with the only real control being calling the agency back on a number you looked up yourself. The question of why there is no secure government-to-company channel for receiving sensitive data went unanswered, because there largely is not one.

The breach also exposed verification selfies, and several commenters asked why those were retained at all. The data minimization question is real: companies collect sensitive identity documents for onboarding and then hold them indefinitely with no clear policy.

This is a supply chain problem for trust. The attacker did not break Revolut's technical security. They exploited the weakest link in the chain, which is the human process for responding to official requests.


So what?

Any fintech or identity-adjacent startup that responds to law enforcement requests needs a documented, verifiable process for authenticating those requests, not just email from a .gov domain. Beyond that, the Revolut case is a reminder to delete sensitive data you no longer need. Retaining verification selfies creates liability with no corresponding benefit once onboarding is complete.

Read these