Revolut Incident Command Active Data Breach Sim

Vector: Fake Government Request
Affected Records: 18,500
GDPR 72h Clock: 08h 14m Elapsed

Regulatory Compliance Action Required

Compliance & Risk Resolution
0%
Statutory Notification Window: 72 Hours Max
Simulation Time: T + 08h 14m
Mandatory Notifications: 0 of 4 Completed

Incident Triage Overview

Ingress Analysis #FR-8891 FRAUD DETECTED
Forged Law Enforcement Subpoena
Attacker spoofed legitimate police communications channel to request account export records.
Scope Verification CONTAINED
Core banking funds safe; access limited to customer name, email, address, and masked transaction metadata.

Incident Activity Stream

[00:00:00] Breach identified: unauthorized data disclosure via fraudulent government portal request.
[00:15:20] Scope isolated to 18,500 customer records across UK and EEA jurisdictions.
[01:00:00] GDPR Article 33 and FCA Principle 11 notification obligations triggered.

Incident Response Matrix Execute mandatory alerts below

Records Impacted: 18,500
Jurisdictions:
1. Law Enforcement & Cybercrime Unit Pending
Alert National Cybercrime Agency (NCA / Europol)
Transmit evidentiary logs on forged police email domains and spoofed digital signatures.
2. Financial Conduct Regulators (FCA / Bank of Lithuania) Pending
Submit Regulatory Operational Risk Report
Provide assessment verifying no account funds or credentials were compromised.
3. Data Protection Authority (ICO / DPA 72-Hour Rule) Pending
Lodge Article 33 Breach Notification
Disclose nature of breach, contact details of DPO, likely consequences, and mitigations.
4. Affected Customer Communication Pending
Broadcast In-App Alerts & Phishing Warnings
Warn 18,500 users of potential targeted spear-phishing or follow-on impersonation attempts.
Enjoy this tool? Build your own with Super