<p>In the attack on Revolut, a London-based financial technology company, threat actors used a stolen government email address to impersonate authorities and request customer information. Revolut told TechTarget that its employees complied with the attackers, believing they were corresponding with government officials. That cooperation led them to hand over the private data of nearly 700 individuals.</p>
<p>A threat actor claiming responsibility for the attack under the pseudonym <i>IAmNotAVillain</i> said in a public post that Revolut shared customers' names, home addresses, email addresses, ID documents, banking information and cryptocurrency transaction records. In messages exchanged with the <a target="_blank" href="https://x.com/FT/status/2100391190839337348" rel="noopener"><i>Financial Times</i></a>, the alleged attackers said they compromised an Italian government email system and communicated with Revolut for months. They also threatened to sell the data to other criminals if the company fails to pay a $3 million ransom.</p>
<p>"This one is hard because it passes every technical control you have, which leaves only governance. And because it comes from law enforcement, it arrives with an expectation of speed," said Ken Yao, head of partnerships at cybersecurity training platform vendor TryHackMe. "Anyone could get caught by this one."</p>
<p>The lesson for CISOs is that highly sensitive data flows should receive no less scrutiny than multimillion-dollar wire transfers, experts agreed. That means denying record requests by default — even those subject to regulatory law — unless and until they are verified through out-of-band channels and separately authorized by at least two qualified employees. Organizations must explicitly empower teams to slow their responses to legally authoritative requests, Yao added, without feeling they are putting their jobs at risk.</p>
<p>"Nobody releases six figures based solely on the fact that the email came from a real domain," said Denis Calderone, CTO at AI cybersecurity firm Suzu Labs. "But that appears to be essentially what happened here with data that, for affected customers, is more damaging than a wire fraud loss. You can reverse a wire transfer. You can't unleak a passport."</p>
<blockquote class="main-article-pullquote">
<div class="main-article-pullquote-inner">
<figure>
You can reverse a wire transfer. You can't unleak a passport.
</figure>
<figcaption>
<strong>Denis Calderone</strong>CTO, Suzu Labs
</figcaption>
<i class="icon" data-icon="z"></i>
</div>
</blockquote>
<p>As security controls go, out-of-band verification — the process of authenticating a data request through a separate, trusted channel, such as a publicly listed agency phone number or authenticated portal — is relatively simple, but not necessarily common in practice. <a href="https://www.techtarget.com/searchsecurity/feature/Deepfake-era-demands-proof-based-security-not-just-awareness">Proof-based verification processes</a> can also protect organizations against AI-based deepfake attacks, like the one that <a href="https://www.cfodive.com/news/scammers-siphon-25m-engineering-firm-arup-deepfake-cfo-ai/716501/">duped a senior finance professional into wiring $25 million</a> to threat actors who impersonated his CFO and other colleagues during a Zoom call.</p>
<p>"Multifactor authentication is not just for logging into accounts anymore," said Bryson Byrd, cybersecurity advisor at Huntress. "Between deepfakes and compromised email accounts like the one used against Revolut, what we really need are multifactor authenticity checks built into the processes of organizations that handle sensitive data."</p>
<p>Arpit Mittal, a software engineer and technical lead who specializes in financial fraud prevention at PayPal, said handing over sensitive data based solely on an email thread is a "critical process failure."</p>
<p>"Treat incoming administrative or emergency data requests with the same risk-scoring discipline applied to financial transactions," Mittal advised. "Flag anomalies such as unusual urgency, sudden deviations from standard legal formatting or targeting of high-net-worth or crypto-associated profiles."</p>
<section class="section main-article-chapter" data-menu-title="How CISOs can secure the 'loading dock'">
<h2 class="section-title"><i class="icon" data-icon="1"></i>How CISOs can secure the 'loading dock'</h2>
<p>Revolut said the threat actors did not compromise any of the company's internal systems. Rather, all the stolen data was leaked because employees voluntarily shared it.</p>
<p>That underscores another common security weakness, according to Eric Capuano, director of SOC operations at Black
[…]
Content was trimmed to protect the source. Please visit the original article for the full text.
Read the original article:
