Revolut confirmed on September 12 that it had disclosed sensitive customer information to an unauthorized party after receiving fraudulent requests sent from the legitimate email domain of a government agency. The company said its own systems had not been compromised, customer funds had not been affected, and the incident concerned a “very limited” number of people. It has not disclosed the exact number of affected customers or identified the public institution involved. After discovering the fraud, Revolut blocked the address and informed the agency, law-enforcement authorities and regulators, according to Reuters.
The nature of the information disclosed makes the incident difficult to dismiss as minor. According to notifications sent to affected customers and reviewed by TechCrunch, the data could include dates of birth, postal and email addresses, phone numbers, copies of passports or driving licences and, in some cases, selfies used for identity verification, bank statements and transaction histories.
The value of such information lies not only in each individual data point but in the ability to combine them. A phone number, address or date of birth can support a conventional phishing attempt. A verified identity document, knowledge of the bank used by the target and a detailed transaction history can support something considerably more sophisticated: a convincing and internally consistent story about the victim.
The case becomes more interesting, however, when we consider what apparently did not happen. There is currently no indication that an attacker penetrated Revolut’s databases and extracted customer information directly. According to the company’s account, the information was disclosed because the requests appeared to originate from a legitimate authority. The security perimeter was therefore not necessarily overcome by breaking through Revolut’s technical defences, but by exploiting an institutional relationship built on trust.
That distinction takes the incident far beyond a single financial company.
When one institution’s vulnerability becomes another’s
A modern bank can protect its infrastructure through multifactor authentication, network segmentation, access controls, encryption, anti-fraud systems and increasingly sophisticated monitoring of suspicious activity. But banks do not operate in isolation. They are legally required to cooperate with courts, prosecutors, police forces, tax authorities, regulators and other public bodies that may, under specific conditions, request customer information.
This system depends on institutional trust. A request arriving through the infrastructure of a government authority naturally carries far greater credibility than a message sent from an unknown address. It is precisely this credibility that becomes valuable to an attacker.
If an account, domain or other element of a public institution’s digital infrastructure is compromised or abused, the consequences may extend well beyond that institution. For a limited period, the attacker may effectively inherit part of the trust that other organizations place in it.
From this perspective, the Revolut incident illustrates a potentially systemic problem: an organization’s security increasingly depends on the security of the organizations it is required to trust.
For the financial sector, the implication is significant. Banks can spend billions protecting their own infrastructure, but they cannot eliminate every risk created by public authorities, suppliers or other participants in the ecosystem. If a government body is legally empowered to request information from hundreds or thousands of organizations, its digital identity effectively becomes a key capable of opening many doors.
Insufficient cybersecurity in the public sector can therefore no longer be treated merely as an administrative weakness of government. In a digital economy, it can become a source of risk for banking, telecommunications, healthcare, insurance, technology platforms and any other sector in which private organizations are required to disclose information to public authorities.
Authenticating the message is no longer enough
The case also highlights a distinction that security systems are likely to have to treat far more rigorously in the years ahead: the difference between establishing the authenticity of the channel through which a request arrives and establishing the authority of the person making it.
In security terminology, these are two different problems. Authentication seeks to establish identity: who is the person or system we are communicating with? Authorization concerns the rights attached to that identity: what is that person or system permitted to do?
A message may genuinely travel through the infrastructure of a public institution without the person controlling the relevant account at that moment having the right to request the information in question. Even confirmation that an email originated from a legitimate domain does not establish that the request was made by the competent official, that a genuine case exists or that the person concerned has the legal authority to obtain that particular category of information.
For organizations holding highly sensitive data, verification may therefore need to evolve from a simple check of origin into a chain of controls. The channel must be verified, followed by the identity of the person, the authority attached to that identity, the legal basis for the request and the relationship between what is being requested and what the official is entitled to receive.
For high-risk disclosures, independent confirmation through a second channel — known in security as out-of-band verification — may become essential. More advanced systems could involve cryptographically verifiable institutional identities, registries of authorized officials, unique identifiers for official requests, mechanisms allowing the recipient to verify the existence of a case directly within the issuing authority’s infrastructure, or additional approvals before particularly sensitive information can leave an organization.
The Revolut case does not tell us what checks the company performed or exactly where the process failed. It would therefore be wrong to conclude from the available information that verification consisted only of checking the sender’s domain. What the outcome does show is that the controls in place were insufficient to distinguish the fraudulent request from a legitimate one.
What does “very limited” actually mean?
Revolut has described the number of affected customers as “very limited”, but has not disclosed the exact figure or said whether the victims were concentrated in a particular market. Relative to a company serving tens of millions of customers worldwide, the number may indeed be extremely small. Without further information, however, the limited scale tells us very little about the nature of the operation.
There is a substantial difference between an attack intended to obtain as much information as possible but detected after only a handful of successful requests, and an operation designed from the outset to obtain the files of a small number of carefully selected individuals.
Security researcher ZachXBT has suggested that the incident may have targeted high-net-worth users, although Revolut has not confirmed that claim. It should therefore be treated as a hypothesis rather than an established fact.
The question raised by it is nevertheless important. Were only a few customers affected because the attack was stopped quickly, or because only a few customers were ever intended to be targeted?
A third possibility also exists. The attackers may have been interested not in specific names identified from the beginning but in people matching a particular profile — perhaps by wealth, type of assets, transaction activity or some other characteristic — with the information subsequently obtained being used to select the most valuable targets.
There is currently not enough evidence to determine which scenario is correct. The answer, however, would materially change the assessment of the incident. A small number of victims can indicate a failed mass operation; it can just as easily indicate a highly selective one.
A form of “reverse institutional spear-phishing”
The mechanism also suggests an interesting reversal of the conventional phishing model. In a typical phishing attack, the criminal tries to persuade the target to disclose a password, banking credentials or other information. In spear-phishing, the victim is selected and researched in advance, and the message is customized to make the approach considerably more convincing.
In an incident such as the one described by Revolut, the attacker can attempt something different. Instead of persuading the target to surrender information, the attacker persuades the organization that already possesses the best information about that person to disclose it.
A useful way of describing the mechanism — without suggesting that this is an established category in cybersecurity taxonomies — is reverse institutional spear-phishing.
The distinction matters because a bank can hold an identity file far more valuable than most of the information an attacker could obtain directly from the victim. KYC documents have been verified, transaction histories are genuine, contact information is usually current, and the combination of these elements can provide an unusually precise picture of the individual.
At its most sophisticated, such an attack is no longer primarily about breaking into the vault. It is about impersonating or compromising the authority that has the legitimate right to ask for the vault to be opened.
AI did not cause this incident. But it can make attacks like it more dangerous
There is currently no public evidence that artificial intelligence was used in the Revolut incident, and it would be misleading to describe it as an “AI attack”. Social engineering, identity theft and the compromise of institutional accounts existed long before generative AI.
The change introduced by AI is subtler and potentially more consequential. Modern models can reduce the cost of preparing a sophisticated attack. The structure of an institution, its terminology, public documents, procedures and relevant personnel can be analysed much more rapidly. A request can be drafted in the legal or administrative language appropriate to a particular jurisdiction without requiring the attacker to possess the same level of expertise. Subsequent correspondence can be adapted quickly if the recipient asks for clarification, while similar operations can be replicated across larger numbers of organizations or jurisdictions.
There is already documented evidence that AI systems are being used by malicious actors for elements of cyber operations, vulnerability research, surveillance, fraud and other hostile activities. The fundamental change is therefore not necessarily the invention of an entirely new form of attack, but a change in its economics: activities that previously required substantial time and experienced operators can increasingly be assisted, multiplied and partially automated.
Historically, one of the informal defences against fraud was the fraudster’s own imperfection. Poorly written messages, awkward translations or requests that failed to reproduce the language of the institution could raise suspicion. As those clues become less reliable, organizations will have to rely less on whether a communication looks authentic and more on systems capable of proving the identity and authority behind it.
The problem cannot be left to banks alone
Revolut clearly has responsibilities of its own. A financial institution holding passport copies, transaction histories and other highly sensitive information must have procedures capable of identifying fraudulent requests even when those requests arrive through apparently legitimate channels. The compromise or abuse of a government authority’s infrastructure does not automatically transfer responsibility away from the financial institution.
It would be equally mistaken, however, to reduce the problem to whether Revolut should simply have checked the email more carefully. In a system in which companies are legally required to respond to public authorities, security cannot work indefinitely if one side of the relationship constantly increases the sophistication of its verification mechanisms while the other remains a potential source of compromised identities.
As governments become increasingly digital, their electronic identities become part of the economic infrastructure. A compromised government account can be disproportionately valuable precisely because it carries the accumulated credibility of the institution behind it. For that reason, the security standards applied to authorities empowered to request information from banks, telecom companies, technology platforms or healthcare providers should increasingly be considered in the same context as other forms of critical infrastructure.
This may be the most important lesson from the Revolut case. In an interconnected economy, public institutions do not merely protect their own databases and employees. They also protect the trust that the rest of the economy is required to place in them. If an attacker can appropriate that trust, the vulnerability travels far beyond the institution in which the original compromise occurred.
As AI makes it easier to reproduce the outward signs of legitimacy — the right language, the right document, the right response and, increasingly, the right voice or image — economic systems will have to demand stronger evidence than appearance alone.
The Revolut incident may ultimately prove limited in numerical terms. We do not yet know. The problem it exposes is considerably larger: weak digital security in a public institution can become a vulnerability for every organization required to trust it. In that sense, improving the cybersecurity of public institutions is no longer merely a question of protecting government administration. It is becoming a condition for the security of the economy built around it.
Comments
Comments are moderated before publication.
No approved comments yet.