Revolut's paperwork breach shows why insurers are rethinking what counts as a 'cyber attack'

Fintech bank handed over customer data after fraudster asked for it

Revolut's paperwork breach shows why insurers are rethinking what counts as a 'cyber attack'

Cyber

By Matthew Sellers

Revolut wasn't hacked in the usual sense. No one broke into its servers or slipped malware past its defences. Someone asked for customer data, from what looked like a genuine government email address, and Revolut handed it over.

That email is now behind one of the stranger data incidents to hit a major UK fintech this year, and it doesn't sit neatly inside the categories most cyber policies are written around.

What happened

Revolut has confirmed it disclosed sensitive information belonging to around 680 customers after a fraudster sent data requests from an email account on a genuine government agency's domain. The messages passed the bank's technical authentication checks and were processed as standard legal-compliance requests, because as far as Revolut's systems could tell, they came from a verified source.

The data handed over reportedly included customers' dates of birth, home and email addresses, phone numbers, copies of passports and driving licences, verification selfies, and in some cases account statements and transaction histories. Revolut says its core banking infrastructure was not breached and customer funds and internal systems were unaffected. The problem wasn't a broken lock, it was someone at the door holding what looked like a legitimate key.

This failure isn’t unusual - "Most of the successful attacks impacting our insureds come from human error,” Simon Hughes, Chief Commercial Officer at Cowbell Cyber told Insurance Business.  “Accidentally clicking on a link, accidentally responding to someone you shouldn't."

Someone has since claimed responsibility on Telegram and is threatening to publish more of the stolen data in stages unless Revolut pays. It's a familiar extortion tactic, but attached to a breach that involved no intrusion at all. Revolut says it blocked the sender's address once the scam was identified and alerted the government agency concerned, along with law enforcement, data protection authorities and financial regulators.

Both UK watchdogs have confirmed they're looking into it. The Information Commissioner's Office said it had received a report from Revolut and was assessing it. The Financial Conduct Authority said it was engaging with the firm to understand the impact and the steps being taken. Neither has said whether formal action will follow.

Why this one is different to JLR and M&S

Most of the big UK breaches this year, Jaguar Land Rover, M&S, the Co-op, involved someone forcing their way into a system that wasn't meant to let them in. This one didn't. It relied on the fact that a request from an authenticated government domain is treated as trustworthy, which is how compliance processes at any regulated financial firm are meant to work. Verified official channels exist so staff don't have to interrogate every request from a regulator or law enforcement as if it might be fraudulent.

Social engineering and business email compromise cover has largely been built around finance-team scams: a fake invoice, a spoofed transfer request from someone posing as the boss. A spoofed government domain used to pull personal data, rather than move money, doesn't fit those definitions as cleanly.

Insurers have spent several years tightening social engineering wording and requiring independent verification of payment instructions. This incident suggests that same scrutiny may need to extend to how firms verify requests for data, not just requests for money.

Most social engineering endorsements are triggered by a transfer of funds, not a transfer of data. A scam where nothing is paid out but a large volume of identity and biometric data leaves the building can fall between a crime policy, built for financial loss, and a data breach policy, often built around unauthorised access rather than a fraudulent-but-convincing request. Brokers reviewing fintech and financial services clients' wording may want to check whether "fraudulent instruction" definitions extend to information requests, not just payment instructions.

There's also the extortion demand itself. Threatening to leak data in stages unless a ransom is paid is standard ransomware playbook, even without any ransomware, encryption or system compromise involved. Cyber extortion cover, and whether insurers should be funding these payouts at all, has been debated in the London market for a while.

The Association of British Insurers, BIBA and the International Underwriting Association have worked with the National Cyber Security Centre on guidance aimed at cutting the number of ransoms UK victims pay, and the government has separately proposed restricting ransom payments by public bodies and critical infrastructure operators. That guidance was written with system lockouts in mind, not a pure data-disclosure scam like this one, so it may not map cleanly onto what Revolut is facing.

The bigger picture for fintech risk

Revolut isn't a small operator. Founded in 2015, it now serves more than 80 million customers across more than 30 countries, and completed a secondary share sale earlier this year that valued the business at $115 billion. It picked up new licences and regulatory approvals in the UK, France, the US and the UAE over the past 12 months, and has built fraud-detection and anti-impersonation tools for its own customers, including in-app call verification designed to stop scammers posing as Revolut staff.

A firm that has invested in helping customers spot impersonation scams was, in this case, caught out by one aimed the other way.

For insurers and brokers, the risks are rising. “There's the nefarious use of AI by third parties against our insureds — definitely happening, definitely happening more and more, “ said Hughes. The takeaway is that a growing share of cyber risk sits in process failures, not technical ones. A firm can harden its network and patch every system and still be exposed if one verified-looking email is enough to unlock a data request. Fintechs hold identity documents, biometric verification data and financial history together in one place, which makes them a heavy target for this kind of scam and a hard risk to price accurately.

None of that helps the roughly 680 people whose passports and selfies are reportedly sitting somewhere they never agreed to. Revolut has declined to confirm the exact number of customers affected and hasn't said publicly whether it plans to engage with the extortion demand. But for the market covering firms like Revolut, the lesson is straightforward: "was the network breached?" is no longer the only question that matters when pricing cyber exposure.

Keep up with the latest news and events

Join our mailing list, it’s free!