The financial technology company Revolut inadvertently shared sensitive customer information with an illegitimate recipient following receipt of what appeared to be an authentic government data request. The fraudulent communication originated from a genuine government agency email domain and successfully cleared standard domain verification protocols.