Revolut breach turns trusted emails into an underwriting risk

The news: Earlier this month, Revolut disclosed that sensitive information belonging to roughly 680 customers had been compromised after a fraudster submitted legal-compliance requests through an email account on a genuine Italian government agency’s domain. 

  • The messages passed the fintech’s authentication checks and were processed as legitimate requests. 
  • No one breached Revolut’s systems, and no customer funds were taken.

Zooming out: Unlike most cyber incidents, Revolut’s breach wasn’t the result of fraudsters gaining unauthorized access; the fintech released the information voluntarily.

That distinction exposes a weakness in the trust model behind sensitive data exchanges. Email authentication can establish that a message came through an authorized domain or account, but it cannot establish that the person controlling that account is authorized to make the request.

The Information Commissioner’s Office and the Financial Conduct Authority are reviewing the incident, though neither has said whether formal action will follow.

Why it matters: For insurers, strong network defenses and email authentication don’t provide a complete picture of an insured’s cyber exposure. 

If a compromised third-party account can bypass controls without malware, a spoofed domain, or a system intrusion, the more important underwriting question becomes what happens after a request reaches an employee.

The UK’s National Cyber Security Centre provides a separate service for verifying whether someone claiming to represent the agency is genuine. That approach illustrates the control insurers may increasingly look for.

Implications for insurers: At least some cyber policies define a data breach to include the unauthorized disclosure of personal information, but voluntarily disclosing customer information to a hacked government agency can fall between the cracks of crime and cybersecurity policies.  

The immediate underwriting issue is whether insured parties treat authentication of the channel as sufficient authorization to release data. During 2027 renewals, insurers may place greater weight on controls such as independent confirmation of sensitive requests, dual approval before disclosure, established directories of authorized officials, and escalation procedures for unusual or high-volume requests.

In addition, multiple clients of the same insurer could be hit by the same attack, which could create compounding financial risks. To prevent such losses, insurers could require additional controls for higher-risk business processes that can release sensitive data without anyone “hacking” the insured. For example:

  • Mandating that customers confirm government agency requests through independently sourced contact information.
  • Requiring that more than one employee sign off on high-risk government requests
  • Moving sensitive disclosures away from email altogether and into allowlisted portals or established law-enforcement request systems.

This content is part of EMARKETER’s subscription Briefings, where we pair daily updates with data and analysis from forecasts and research reports. Our Briefings prepare you to start your day informed, to provide critical insights in an important meeting, and to understand the context of what’s happening in your industry. Non-clients can click here to get a demo of our full platform and coverage.

You've read 0 of 2 free articles this month.

Get more articles - create your free account today!