Revolut data breach exposes weakness in security

By Gemma Rolfe Fraud & Security
views

Revolut has disclosed sensitive information belonging to a small number of customers after fraudsters used a legitimate government agency email domain to submit apparently authentic requests for customer data.

Envato - Licenced

Revolut data breach exposes weakness in security

The fintech said an unauthorised third party carried out a sophisticated impersonation attack that resulted in information being released through its normal compliance procedures. Revolut’s systems were not compromised and customer funds were unaffected.

According to reports, exposed information included dates of birth, postal and email addresses, telephone numbers and identity documents including passports, driving licences and facial verification images. Crypto investigator ZachXBT has claimed bank statements, IBANs and transaction histories were also disclosed and that wealthy customers may have been specifically targeted.

Revolut has not disclosed how many customers were affected, describing the number as “very limited”.

Attackers exploit institutional trust

The unusual feature of the incident is how the attackers circumvented security controls.

Rather than attempting to penetrate Revolut’s technology directly, fraudulent information requests arrived from a legitimate government domain and passed technical email authentication. They therefore appeared to be genuine agency enquiries requiring disclosure under established legal and compliance processes.

Once the fraud was identified, Revolut said it blocked the address and notified the government agency, law enforcement authorities, data protection bodies and financial regulators.

The episode illustrates a growing challenge for financial institutions: securing their own infrastructure is insufficient when attackers can compromise or impersonate organisations that banks are required to trust.

Awkward timing for Revolut

The breach comes at a sensitive moment for Revolut as it expands its position within mainstream banking.

Having secured banking licences in the UK and elsewhere in Europe following years of regulatory scrutiny, the fintech is also preparing for a potential public listing that could reportedly value the business at as much as $200bn.

The incident therefore raises a wider question for banks and fintechs. As cyber defences become harder to penetrate, authentication of trusted third parties may need to become every bit as rigorous as authentication of customers.

The weakest identity in financial services may increasingly be the institution asking for the data.

Comments

Post comment

No comments found for this post