The Revolut incident is seen as a serious warning for global businesses, as hackers are increasingly exploiting trusted identities and legitimate communication channels. This reality was clearly demonstrated following a data breach in a digital banking platform called Revolut.
Incident Details
The incident occurred when Revolut provided sensitive customer information to an unauthorized third party that had submitted fraudulent requests using the legitimate email domain of a government entity. Reports indicate that the company's systems were not hacked; rather, the requests originated from an unauthorized email account operating within the official domain of this government entity. These requests contained valid domain verification credentials, and Revolut initially assumed they were legitimate.
The leaked information included customers' full names, dates of birth, occupations, addresses, email addresses, phone numbers, copies of passports or driver's licenses, and identity verification images collected during the identity verification process.
New Security Challenges
Cybersecurity experts believe that this incident reflects broader changes in the threat landscape, where criminals are increasingly manipulating trust relationships rather than attempting to infiltrate organizational systems. Murray Haber, Chief Security Consultant at BeyondTrust, states: "This incident serves as an important reminder that cybersecurity failures do not always begin with malware, missing security patches, or stolen credentials."
Haber also pointed out critical vulnerabilities in the security processes of many organizations, saying: "Assuming that communications from a legitimate domain are automatically legitimate poses a serious risk. This incident reveals a larger challenge in the realm of identity security." He emphasized that "identity verification does not equate to authorization," and proving the source of a message does not mean that the sender is authorized to request sensitive information.
Recommended Actions for Organizations
In the wake of this incident, cybersecurity experts recommend that organizations handling personal, financial, and identity data implement stronger verification mechanisms before sharing sensitive information. Haber stresses that "requesting and verifying identity through informal channels, segregation of duties, least privilege, and human verification should be mandatory before any sensitive information is sent from the organization."
The growing complexity of these types of attacks has also impacted how security teams assess risk. Santiago Pontiroli, Senior Researcher at TRU in Acronis, states: "Criminals are increasingly exploiting legitimate accounts and business processes to achieve their goals." He emphasizes that even if a government account is compromised, fraudulent messages can bypass valid verification controls.
Ultimately, this incident reveals a broader reality for businesses globally: cyber threats have shifted from attacks on technical systems to trust-based attacks targeting individuals and processes. With the increasing importance of digital identities in customer verification and regulatory compliance, experts believe that organizations must move beyond reliance on email identity verification and continuously validate the legitimacy of any high-risk requests.




