Cybersecurity News, Threat Intelligence & CISO Best Practices

Cybersecurity illustration of a fraudulent government data request exploiting trust to access sensitive customer information from a financial platform.

Cybersecurity incidents do not always start with malware, ransomware or a sophisticated zero-day exploit. Sometimes they begin with something far more ordinary: a request that looks completely legitimate.

Revolut recently confirmed that sensitive customer information was disclosed to an unauthorized third party after the company received fraudulent requests that appeared to originate from a legitimate government agency email domain. Revolut stated that only a very limited number of customers were affected and that its systems and customer funds remained secure.
What makes this incident particularly interesting from a cybersecurity perspective is not simply that data was disclosed, but how the disclosure occurred. The attacker did not necessarily need to penetrate Revolut’s infrastructure or defeat sophisticated technical security controls. Instead, the attack appears to have exploited something that every organization depends on every day: trust.

Companies regularly receive requests from regulators, authorities, lawyers, banks, suppliers and business partners. Many of these requests arrive by email and are processed through established internal procedures. When the sender appears legitimate, the domain is familiar and the request itself seems plausible, employees naturally tend to assume that the communication is genuine.

This is increasingly becoming a security problem.

Over the past decade, organizations have invested heavily in protecting networks, endpoints, cloud environments and identities. Firewalls, EDR, MFA, SIEM platforms, privileged access management and increasingly sophisticated AI-based detection systems have significantly improved technical security. At the same time, many important business processes still rely on a more traditional assumption: if the sender can be trusted, the request can probably be trusted as well.

The Revolut incident demonstrates why this assumption is no longer sufficient.

Reuters reported that Revolut’s systems and customer funds were unaffected, yet customer information was nevertheless disclosed. According to a TechCrunch report cited by Reuters, the compromised information included birth dates, postal and email addresses, telephone numbers and copies of identity documents such as passports and driving licences.

This distinction is important because an organization can have technically secure infrastructure and still experience a significant data breach when a legitimate operational process is manipulated. Cybersecurity therefore needs to consider not only whether a user or sender has been authenticated, but also whether the request itself is legitimate, proportionate and expected.

This becomes particularly relevant when requests originate from government agencies, regulators or law-enforcement authorities. Such communications naturally carry a degree of authority and urgency, and employees may feel that a rapid response is required. For exactly this reason, organizations should establish verification procedures that are independent of the original communication channel.

For example, sensitive information requests can be confirmed through a second channel, validated against an official case or reference number, reviewed by legal or compliance teams and subject to a four-eyes approval process before data is released. Data minimization is equally important: even where a request is legitimate, only the information strictly necessary for the stated purpose should be disclosed.

The underlying principle is closely related to Zero Trust. Just as modern security architecture no longer assumes that a user or device should be trusted merely because it is located inside the corporate network, organizations should not assume that a business transaction is legitimate solely because the communication appears to originate from a trusted organization. The context, purpose and legitimacy of the transaction itself also need to be verified.

Revolut stated that after detecting the incident it blocked the relevant address and informed the government agency concerned, law enforcement, data-protection authorities and financial regulators. This response highlights another important aspect of modern cybersecurity: resilience.

Complete prevention of every possible attack is unrealistic, which is why organizations must also be able to identify abnormal activity quickly, contain the consequences and recover effectively. Nevertheless, mature cybersecurity should increasingly aim to intervene before sensitive information has actually left the organization.

This is where the discussion becomes particularly relevant to the Automated Resilience Index (ARI). An organization capable of automatically identifying suspicious behavior and reacting within seconds is clearly more resilient than one that depends entirely on manual intervention. An even more advanced capability, however, would be to recognize an anomalous transaction before the damaging action takes place and automatically trigger additional verification or approval.

In this context, automated resilience is not simply about detecting attacks faster. It is about reducing the time between identifying abnormal behavior and taking an effective defensive action, ideally before material damage occurs.

The Revolut case also illustrates a broader evolution in identity security. Traditional security controls have concentrated on determining whether the person or system performing an action is genuinely who it claims to be. In today’s threat environment, this is no longer enough. A user may be properly authenticated, an email may originate from legitimate infrastructure and an API may operate with valid credentials, while the resulting transaction can still be malicious or unauthorized.

Security systems therefore need greater contextual awareness. They need to understand whether a particular request is normal for the organization involved, whether the requested information is appropriate, whether the volume of information is unusual, whether similar requests have occurred previously and whether an independent verification step has taken place.

These questions extend beyond traditional cybersecurity and increasingly involve risk management, legal, compliance and business operations. This is precisely why incidents of this type deserve executive attention: they expose vulnerabilities not necessarily in the technical infrastructure, but in the processes that connect technology, people and external organizations.

As technical infrastructure becomes more difficult to compromise, attackers have strong incentives to move toward the surrounding processes and trusted relationships. Instead of attempting to defeat several layers of security technology, it may be easier to manipulate an existing workflow and convince the organization itself to perform the requested action.

For CISOs, the consequence is that the security perimeter must be understood more broadly. Networks, identities, endpoints and cloud services remain essential, but they form only part of the overall risk landscape. The relationships and business processes through which information is requested, approved and transferred must increasingly become part of the security architecture as well.

The Revolut incident is therefore more than another data breach. It is a useful reminder that trust itself can become an attack surface, and that protecting sensitive information increasingly requires organizations to verify not only who is asking for the data, but also why they are asking for it and whether the request makes sense in its broader context.

Leave a Reply