You're reading The SME Security Brief, practical IT, cyber security and technology advice for Irish and UK businesses. No jargon. No scare tactics. Just what you need to know, every week.

If someone forwarded this to you, you can subscribe at thesmesecuritybrief.com.

THIS WEEK'S THREAT 🔴

Revolut just handed customer data to fraudsters. Their systems were never touched.

On the 12th of September 2026, Revolut confirmed a data breach affecting approximately 680 customers. Passports. Driver's licences. KYC identity selfies. IBANs and account statements. Bitcoin transaction histories. Full names, dates of birth, home addresses, phone numbers, and email addresses. Twelve of those customers are in Ireland.

Here is the part that matters, nobody hacked Revolut's systems. There was no exploit, no malware, no sophisticated cyberattack. What happened was far simpler. Fraudsters impersonated a government agency, sent a request using what appeared to be a legitimate government email domain, and Revolut staff handed the data over. They believed the request was real.

This is called an Emergency Data Request, or EDR fraud. Legitimate law enforcement agencies can request data from companies in urgent situations, and companies are expected to comply quickly. Criminals have worked out that if you can convincingly impersonate that request, you can get data that would otherwise be locked behind legal processes and court orders. The technique was used against major tech companies in the US as far back as 2022. Now it is being used against European fintechs.

Revolut's funds were not touched. Their internal systems were not compromised. The breach happened entirely through a convincing lie.

Why this matters for your business,

Revolut is a billion euro fintech company with a full security team. They still got fooled by someone pretending to have authority they did not have. Now think about what happens when someone calls your office pretending to be Revenue, your bank, your IT provider, or a supplier. No sophisticated tools required. Just a confident voice, an urgent sounding reason, and a request you feel pressure to act on quickly.

This kind of attack is called social engineering, and it works on small businesses far more often than it works on large ones. Large organisations have verification processes, legal teams, and multiple layers of approval before data goes anywhere. In a small business, the person who answers the phone is often the same person who has access to the accounts.

What you should do this week,

  1. Talk to anyone in your business who answers the phone or responds to email requests. Make sure they know that legitimate organisations, whether Revenue, a bank, or your IT provider, will never pressure you to share sensitive data immediately or be upset if you say you need to call back to verify.

  2. Establish a simple rule, no sensitive data leaves your business in response to an inbound request until you have verified who is asking by calling them back on a number you find yourself, not one they provide.

  3. The tip section below gives you a practical verification process to put in place today.

THIS WEEK'S TIP 💡

How to verify before you hand anything over.

The reason social engineering works is not because people are careless. It is because the requests are designed to feel legitimate and urgent, and saying no feels riskier than saying yes. A caller who sounds confident, uses the right terminology, and applies a bit of time pressure is surprisingly effective, even on people who know these attacks exist.

The fix is a process, not a personality trait. If verifying everything is the rule, nobody has to make a judgement call in the moment.

The callback rule
If someone contacts you requesting sensitive information, payment changes, login credentials, or access to your systems, your default response is to take their name and tell them you will call back. Then find the genuine contact number for the organisation they claim to represent, whether that is your bank's business line, Revenue's verified contact page, or your IT provider's direct number, and call it. Not the number they gave you. The one you find yourself.

This single step defeats the vast majority of social engineering attempts, because the fraudster cannot answer the phone at Revolut's customer service number or Revenue's switchboard.

What legitimate requests look like
Real government agencies and financial institutions do not demand immediate action. Revenue will not call you and tell you that you need to transfer funds or share employee data within the hour or face consequences. Your bank will not ask you to read out passwords or authentication codes over the phone. Your IT provider does not need your Microsoft 365 admin password to fix a problem remotely. If any of these things are happening, it is not a legitimate request.

Train the person who answers the phone
In a small business, the most targeted person is often a receptionist, an office manager, or whoever picks up an unfamiliar call. They may not have had any security training, and they are under social pressure to be helpful. One conversation about what social engineering looks like, and the fact that it is always okay to say "I'll need to call you back to verify," can make a real difference.

Invoice and payment change requests deserve special attention
One of the most common social engineering attacks targeting SMEs is a fraudulent email that appears to come from a supplier, advising that their bank details have changed and asking you to update your records. These emails are often convincing, sometimes sent from a compromised supplier account. The rule here is simple, always verify bank detail changes by calling the supplier on a number you already have before processing any payment.

THIS WEEK'S TOOL 🛠️

A simple data request policy you can implement this week.

You do not need a 40 page information security policy to protect against this kind of attack. You need one clear rule that everyone in your business understands. Here is a template you can adapt and share with your team.

The rule,
Any request received by phone or email for sensitive information, such as financial data, employee records, login credentials, payment details, or personal data belonging to customers, must be verified before anything is shared. Verification means calling back on a number we have independently confirmed, not one provided in the request itself.

What counts as sensitive information,
Bank account details, either ours or a supplier's. Employee personal data, including payroll information. Customer records. Login credentials or access codes of any kind. Copies of identity documents. Payment authorisation or change requests.

How to verify,
For banks, call the number on your card or on the official website. For Revenue, use the contact information at revenue.ie. For your IT provider, call the main number you already have on file. For suppliers, use contact details from a previous invoice or email chain, not the current request.

What to do if pressured,
If a caller tells you there is no time to verify, or that calling back will cause a problem, treat this as a strong indicator that something is wrong. Legitimate organisations understand verification processes. Anyone who objects to being verified should not receive your data.

Write this down. Put it somewhere visible. Tell your team it exists and why. That is genuinely all it takes to close the door on the attack that caught Revolut.

QUICK COMPLIANCE CHECKLIST

Five questions to answer about your business this week,

  1. Does anyone in your business have a clear process for verifying inbound requests before sharing data or making payment changes?

  2. Do you have a written list of genuine contact numbers for your bank, Revenue, and your IT provider, so you can call back independently?

  3. Has anyone spoken to your front of house staff about social engineering and what to do when a call feels pressured or urgent?

  4. Do you verify supplier bank detail changes by phone before updating your records?

  5. Do you have a rule that no one should ever read out login credentials, authentication codes, or passwords over the phone to an inbound caller?

BEFORE YOU GO

The Revolut breach is a useful reminder because it shows that this is not a small business problem or a careless employee problem. It is a human problem. Revolut's staff followed what looked like a legitimate process. They did not make an obvious mistake. They were deceived by people who had studied how the process worked and designed a convincing imitation.

Your business faces the same risk. Not because your team is naive, but because these attacks are built to be convincing, and the pressure to be helpful in the moment is real.

The answer is not to make people feel bad for being trusting. It is to give them a clear rule that removes the need to make a judgement call under pressure. Call back to verify. Always. No exceptions.

That rule, properly understood and followed, is more valuable than almost any piece of security software you could buy.

See you next week.

  • The SME Security Brief

Found this useful? Forward it to a business owner who would benefit. It takes two seconds and could save them a serious headache.

You're receiving this because you subscribed at thesmesecuritybrief.com. To unsubscribe, click here.

If you find this newsletter useful and want to show your support, you can buy me a coffee. It genuinely means a lot and keeps this going. No pressure at all.