GetSOC2

Revolut handed over customer data to someone pretending to be a government

September 22, 2026. From issue 7 of The Compliance Brief, one story for companies buying a SOC 2 audit.

Last reviewed 2026-09-22Written by Jacob Masse, TrazTech Inc.

Issue 7 of The Compliance Brief went to subscribers on September 22, 2026. One of its 5 stories bears on SOC 2 audits, auditors and vendor reviews, and they are below in short form. The full issue, with every take in full, is on traztech.ca.

Source: Infosecurity

Revolut confirmed that an unauthorized party obtained customer information by submitting a fraudulent data request from a legitimate government email domain. Personal and financial details were disclosed to the requester.

Our take, in short

Almost every fintech I work with has a path for law enforcement and regulator requests, and almost none of them can show me the verification steps or the log of what was released. A compromised or spoofed government domain beats a process that relies on the email looking official, so the control has to be out-of-band confirmation with the agency...

Read the full take on traztech.ca

Also in issue 7

Outside SOC 2 audits, auditors and vendor reviews, but in the same email:

Older: issue 6 All issues on GetSOC2 Newer: issue 8