Even if the trigger was spoofed, how come there is no secure channel that the govt provides to receive the data? Was this one also compromised?
If people actually knew how much of a wild west this stuff is, a lot more would be cautious with their personal info.
That may not matter that much, as even if you run a relatively strict policy about where you send the reply, you can still easily get bitten by external mistakes there: Because of the huge number of individually administered departments that might each become authorized recipient of such data, a malicious party only needs to find one suitably dangling DNS delegation to score a "…@attacker-controlled-subdomain.legitimate.example" mailbox. The sender would not be able to prevent this.. unless its regulatory oversight body is very patient about repeatedly delaying legitimate requests for seemingly-minuscule formal defects. (Mentioning just for context. Probably not the mechanism at play here, Revolut would have tried to shift blame in the press release if it was.)