Over the last week, I've seen roughly 500,000 articles and X posts about how AI is going to compromise every system, take over the world, etc.
Then on Friday, with far less attention, we learned that a flesh-and-blood human got Revolut to hand over passports, selfies, bank statements, and full transaction histories belonging to some of its wealthiest customers.
No AI required.
How did he do it?
He sent an email asking for it.
Then Revolut gave it to him.
I've said it for years, and I'll say it again: this shouldn't still be possible.
What actually happened
It's still under investigation, and Revolut hasn't said much. Here's how it looks so far, from what Revolut has said and what's been reported:
- A criminal got hold of an email account at a real government agency. Revolut's word for it is "unauthorised." We don't know who, which agency, or how. Malware that steals saved passwords. Someone talked into handing it over. A login bought on a forum. Or an account somebody created from the inside. Take your pick.
- Using that account, they sent fraudulent requests to Revolut for specific customer records.
- Revolut checked the email. It came from the agency's real domain, with what Revolut calls "valid domain authentication credentials." That part checked out. Which tells you which server sent the message. It tells you nothing about who was at the keyboard.
- The request passed review, and Revolut produced the data: identity documents, verification selfies, personal contact details, account information, and transaction histories.
- Later, Revolut figured out the requests were fake. Reports say it went back to the agency, which said it never sent them. 😬
- Revolut blocked the address, notified regulators and police, and began emailing affected customers on September 11.
The email was real. The person behind it wasn't who they claimed to be.
That's the gap.
This is not an isolated incident
If you're new to this world, this might sound like a weird, isolated story. It isn't. We named it years ago: law enforcement email compromise, or LEEC.
Whatever happened here, this part is routine. Right now, you could go on the dark web and buy a real police email login. Prices vary by country. A fake emergency request sent from one starts at about $100.
Once you have one, you can send emails as a police officer. Claim you're working a critical case. Ask for someone's personal information. Say you need it immediately.
My company, Kodex, has flagged more than 5,000 criminals impersonating law enforcement to get customer data.
And this has been happening in public for years. In 2022, reports revealed that Apple and Meta had handed over user data to hackers using forged emergency requests sent from compromised police accounts. In 2023, Verizon gave a stalker a woman's home address and phone records after he emailed from a ProtonMail account claiming to be a cop and attached a fake warrant.
And it isn't only email. In 2025, a group created a fraudulent account inside Google's Law Enforcement Request System, the portal police use to ask Google for data. Google caught it and said no requests were submitted and no data was accessed. The attempt is the part worth noticing. The law enforcement request channel is now a target in its own right.
Revolut deserves credit for catching it, alerting the agency and regulators, and telling affected customers.
Most companies would never know. The request looked right, the domain checked out, the file went out. Why would anyone look again?
How many companies have answered one of these and never found out? Nobody knows. That's the part that should bother you.
Meanwhile, request volume is growing roughly 40% a year. More requests. Less time to verify each one. And at too many companies, verification still means a person squinting at a domain name.
Why this is so hard to defend against
Criminals love this scam. Why spend all that energy breaking into a company's systems when you can get the company to send you the data?
Two things make it especially difficult to stop.
First, companies have real obligations to respond to valid legal requests, often under tight deadlines.
Second, police agencies around the world have wildly uneven security. Many lack the basic protections a company would expect: single sign-on, strong access controls, even two-factor authentication.
One email account. Enormous power. Sometimes very little security.
And the people handling these requests don't just want to comply. They want to help.
Having worked counterterrorism for the FBI, I know what legitimate access to this information makes possible: finding people in danger, recovering stolen funds, and making our communities safer.
That urgency is real. So is the willingness to help.
Criminals exploit both.
A team shouldn't have to choose between moving quickly on a legitimate investigation and protecting its customers. It needs a reliable way to tell who's asking, and whether they're entitled to the information.
The answer
I've been saying this for seven years. One more time:
We need real KYC. Know Your Cop.
Globally. We need to verify the person behind the request, the authority to make it, and whether their account is still under their control.
And we need these exchanges to happen in a grown-up, 2026 kind of way. Too many companies and agencies are still relying on email, PDFs, and, literally, faxes.
This is a hard problem. But the infrastructure to address it already exists.
The Kodex Global Network connects 15,000 agencies and more than 160,000 verified investigators. Requests go through a secure channel, with requesters checked every time. Verification doesn't stop because someone passed a check six months ago.
Companies like Stripe, AT&T, Coinbase, and Amazon use Kodex to verify, process, and respond to these requests.
It's fast: about 15 hours instead of about six weeks. Roughly 60 times faster.
It's built for exactly this: a stolen mailbox doesn't come with a verified identity attached.
And it helps legitimate investigators do their jobs while protecting people from those impersonating them. That's what I care about most.
Revolut, credit where it's due: you caught it, and you told your customers.
For everyone else, take a look at how your company handles these requests. What actually stands between an impostor with a government email address and your customers' most sensitive information?
We need to stop pretending an inbox is a security control.
I'll spare you the full product pitch. But if you're wondering whether your company or agency is exposed to this, that's a conversation worth having. Find us at Kodex Global.
OK, rant over. Until the next one.
Matt Donahue is the co-founder and CEO of Kodex, the verification network for law enforcement data requests, and a former FBI counterterrorism agent.
Get Your Free Drone Autonomy Guide Today!

Featured Blogs
Everybody's Arguing About the Wrong Part of the CLARITY Act





