Analysis
Revolut disclosed that it handed customer data to a threat actor impersonating a UK government agency, after fraudulent information requests arrived through what the company described as a spoofed but authenticated government-agency email domain, Infosecurity Magazine reported. Revolut called it a "sophisticated external impersonation scam" and said it has contacted roughly 680 affected customers.
The exposed data was extensive: full names, dates of birth, occupations, postal and email addresses, phone numbers, copies of passports or driver's licenses, facial verification images, account statements including IBAN numbers, withdrawal records and full transaction history including Bitcoin transactions, per The Register's account of the incident. Revolut said it blocked the email address once it discovered the scam, and has notified the impersonated government agency, law enforcement and the UK's Information Commissioner's Office, which is now investigating.
“That is a process failure at the verification layer, not a technical breach of Revolut's systems, which is a meaningfully different security story than a hacked database.”
The mechanism is the notable part. Domain-based email authentication -- the technical standard meant to prevent exactly this kind of spoofing -- apparently carried valid credentials, meaning the request passed Revolut's automated checks and reached a human reviewer who had reasonable grounds to believe it was genuine. That is a process failure at the verification layer, not a technical breach of Revolut's systems, which is a meaningfully different security story than a hacked database.
Revolut has been racing toward a public listing on the back of a valuation that has climbed past $75 billion and reportedly toward $110 billion in secondary markets this year, positioning itself as one of the most valuable fintechs in the world ahead of an eventual IPO. A data-handling failure -- however narrow in scope, at 680 of Revolut's tens of millions of customers -- lands at the exact moment regulators and prospective public-market investors are scrutinizing the company's operational controls most closely.
For any fintech nearing a public listing, the lesson generalizes past Revolut specifically: attackers have shifted from attacking systems to attacking the humans and processes that verify legitimate government requests, and a company's incident response -- self-reporting to the ICO, notifying affected customers directly -- is now as much a part of the story as the failure itself.