Revolut Discloses Unauthorized Release of Customer IDs and Financial Data to Impostor
What Happened — Revolut confirmed that a fraudster posing as a government official obtained customer identification numbers, account balances, and transaction histories. The impostor leveraged social‑engineering tactics to convince support staff to share the data, affecting thousands of users.
Why It Matters for Trust & Control Assurance
- Highlights the need for rigorous identity‑verification controls around data‑request workflows – a core control‑area that continuous‑monitoring programs must evidence.
- Demonstrates how a lapse in access‑control policies can create audit‑ready gaps across multiple frameworks (e.g., NIST CSF, ISO 27001).
- Directly ties to Verisq’s Access Controls capability, which helps organizations capture, monitor, and prove that request‑validation procedures are consistently applied.
Who Is Affected – Financial services, digital‑banking platforms, and any organization handling sensitive customer financial data.
Recommended Actions
- Review and tighten verification procedures for any external data‑request, especially those claiming governmental authority.
- Implement continuous logging of data‑disclosure events and integrate them into your audit‑evidence repository.
- Conduct targeted security‑awareness training for support and compliance staff on social‑engineering detection.
Source: Malwarebytes Labs – Weekly Security Roundup
Technical Notes
- Attack vector: Social engineering (impersonation of a government official).
- Data types exposed: Customer IDs, account balances, transaction history.
- No public vulnerability (CVE) associated; the breach stems from process failure.
Source: same as above