Website Fundamentals

What Local Businesses Should Learn From Revolut’s Fake Government Data Requests

Learn how to spot and handle suspicious requests for customer, contact-form, or account information.

The StoopCraft Team
a fake news megaphone with the word fake news coming out of it

A reported breach is a reminder to verify before sharing

Reuters reported that Revolut confirmed a sensitive customer data breach involving fake government requests. The Financial Times reported that data from nearly 700 customers was handed to scammers. Reuters | Financial Times

The reporting does not establish that local businesses, website contact forms, or StoopCraft customers were involved in the same kind of attack. But it is a useful reminder of a practical risk: a request can look official, urgent, and credible while still being fraudulent.

For a local business, customer information may include contact-form submissions, quote requests, booking details, invoices, customer email addresses, phone numbers, or account-access information. A small team does not need to assume every unusual request is malicious. It does need a clear process for slowing down, verifying the requester, and limiting who can disclose information.

This is general operational guidance, not legal, cybersecurity, or compliance advice. Businesses that handle regulated, highly sensitive, or payment-related information should seek advice from qualified security and legal professionals.

Table of contents

Why fake government requests can be convincing

Fraudulent requests often rely on social pressure rather than a complicated technical attack. The sender may use an official-looking title, a logo, formal language, or a deadline designed to make the recipient act before checking.

For a local business, warning signs may include:

  • An unexpected request for customer, lead, or account information
  • Pressure to respond immediately or keep the request confidential
  • A request sent from an unfamiliar email address or phone number
  • A demand to send files through ordinary email
  • A link, attachment, or portal that was not expected
  • A request that bypasses the person who normally handles records, vendors, or account access
  • A message that says verification is unnecessary because of urgency

None of these signs proves a request is fraudulent. But they are good reasons to pause. A legitimate request can withstand a reasonable verification step.

What information on a local-business website may need protection

A business does not need to collect highly sensitive information through its website to have data worth protecting. Even a basic contact form can contain information a customer reasonably expects the business to handle carefully.

Review where your team receives or stores:

  • Name, email address, and phone number from contact forms
  • Requested service details, addresses, or appointment preferences
  • Quote requests and project notes
  • Booking inquiries
  • Customer messages sent through website chat
  • Email notifications generated when a form is submitted
  • Website-hosting, domain, analytics, or email-platform account access
  • Shared documents that contain customer or lead records

Start with your local business website lead form privacy checklist. The goal is not to eliminate every data field. It is to collect only what is useful for the next step and to know who can access it.

A practical verification checklist

When someone requests customer, lead, or account information, use a written process instead of relying on instinct.

1. Do not reply using the contact details in the request

If a message claims to be from a government agency, a payment provider, a website vendor, or another authority, do not use the phone number, email link, or portal provided in that message as your only verification method.

Instead, find contact information independently through:

  • The organization’s official website
  • A known account representative
  • An existing vendor agreement or verified support channel
  • A phone number your business has used successfully before

Then ask whether the request is legitimate.

2. Confirm who is authorized to disclose information

Decide in advance who can respond to unusual data requests. For a small business, this might be the owner, an operations manager, or a designated person responsible for customer records.

Front-desk employees, sales staff, contractors, and web administrators should know that they are not expected to make that decision alone.

A simple internal rule can help:

Do not send customer, lead, account, or login information to an unexpected requester without independent verification and approval from the designated person.

3. Clarify exactly what is being requested

Do not send an entire spreadsheet, inbox export, or folder when a request is vague. Document:

  • Who made the request
  • What they asked for
  • Why they say they need it
  • The date and time of the request
  • How the requester was independently verified
  • Who approved any response
  • What information, if any, was shared

Keeping a record can help your business avoid confusion when several employees receive related messages.

4. Avoid sending sensitive information through ordinary email

Email can be convenient, but it is not always the right channel for customer or account information. If a request appears legitimate and information must be shared, ask the appropriate professional or provider what secure, approved method should be used.

Do not assume that password-protected attachments or a familiar-looking email address alone make a transfer appropriate.

5. Escalate regulated or especially sensitive requests

A medical practice, financial business, legal office, school, or other business handling regulated information may have specific obligations. Do not improvise a response to a request for records, identity information, health information, payment data, or other sensitive material.

Bring in qualified legal and security guidance before sharing anything when the request has meaningful privacy, regulatory, or contractual implications.

How to respond when a request seems urgent

Urgency is a reason to verify faster, not a reason to skip verification.

A request may say that a customer is at risk, an account will be suspended, a deadline is imminent, or a legal consequence will follow if you do not act immediately. Treat those statements seriously enough to investigate, but do not let them force an unapproved disclosure.

A reasonable response sequence is:

  1. Preserve the original message, including attachments and sender details.
  2. Do not click unfamiliar links or open unexpected files.
  3. Notify the person responsible for customer records or account security.
  4. Verify the request through an independent official channel.
  5. Record what you learned and the action taken.
  6. If the request is suspicious, tell affected internal team members so they do not respond separately.

This process also helps with vendor impersonation. A message claiming to come from your website host, domain registrar, email provider, or payment service should be checked through a known account portal or verified support channel before anyone changes credentials or shares account details.

Website and access reviews that can reduce exposure

A website alone cannot prevent a data breach. Still, a few practical website and workflow reviews can reduce how widely lead information is available and help your team respond more consistently.

Review who receives form notifications

Many businesses send every website inquiry to multiple inboxes by default. Consider whether each recipient truly needs access to every submission.

For example, a business may route general service inquiries to a shared sales inbox while keeping sensitive customer-service issues with a smaller, designated team.

Also review old forwarding rules when an employee, agency, or contractor no longer works with the business.

Keep website and customer accounts separate where possible

Do not share one login broadly just because it is convenient. Separate access can make it easier to remove a former contractor’s permissions and identify which person should handle a request.

Your website provider, email provider, domain registrar, and analytics accounts may all contain useful information about customers or leads. Treat access to those systems as part of your customer-data workflow.

For a related access-control concern, read Local Business Website Security: How to Avoid Exposing Passwords in Shared Google Docs.

Review what your contact form asks for

Every field creates another piece of information to handle. Keep forms focused on what your business needs to begin a conversation.

A home-service business may need a name, phone number, service address, and a short description of the problem. It probably does not need a customer to submit unnecessary identity documents, account credentials, or payment information through a general inquiry form.

A clear contact page can also guide customers toward the right channel for booking, service questions, or urgent issues.

Establish a monthly access review

Use your local business website maintenance checklist to review:

  • Who has access to the website and form submissions
  • Which email inboxes receive lead notifications
  • Whether former employees or vendors still have access
  • Whether contact forms ask only for needed information
  • Whether staff know who handles unusual data requests
  • Whether account recovery contacts are current

The aim is not to turn a local business into a security operations center. It is to avoid avoidable confusion when an unexpected request arrives.

A simple staff response script

A staff member does not need to accuse the requester or decide whether a message is fraudulent. They only need permission to pause.

Use a response such as:

Thank you for your request. I’m not authorized to release customer or account information directly. Our designated contact will review the request through the appropriate channel.

For phone calls:

I can take down your name and organization, but I cannot provide customer or account information on this call. We will verify the request and follow up through the appropriate process.

Do not use this script to confirm that a particular person is a customer, that records exist, or that the business holds specific information. Keep the initial response limited until the request has been verified.

Key takeaways

  • Reuters reported that Revolut confirmed a sensitive customer data breach involving fake government requests; the Financial Times reported that nearly 700 customers’ data was handed to scammers.
  • The reports do not show that local-business websites or contact forms caused the incident.
  • Local businesses can still use the case as a reminder to verify unexpected requests for customer, lead, or account information independently.
  • Do not let urgency, official-sounding language, or a recognizable logo replace verification.
  • Limit access to website lead data, review form-notification recipients, and assign a clear internal owner for unusual requests.
  • For regulated or highly sensitive information, seek qualified legal and security guidance before responding.

A short website-process check can make a difference

Your website should help your team receive legitimate inquiries without making customer information harder to manage. StoopCraft builds done-for-you websites for local businesses and includes on-page SEO as part of its $69/month website service. If you need a clearer contact flow or help reviewing what your website collects, explore StoopCraft.

Keep reading