One of the tell-tale signs of fraudulent communications has traditionally been the domain from which a message originates, as cybercriminals often use lookalike websites and email addresses to impersonate trusted brands.
As these messages have become more convincing, many organizations have responded by installing email filters and conducting company-wide cybersecurity training to help employees identify and avoid them.
But as these defenses have improved, criminals have adapted their tactics. A recent attack on UK fintech Revolut illustrates the challenge. In that incident, an unauthorized third party used a legitimate government agency domain to submit fraudulent requests for customer information.
The requests bypassed Revolut’s cybersecurity defenses. According to TechCrunch, the company disclosed sensitive customer data, including birth dates, postal and email addresses, phone numbers, and copies of identification documents like passports and driver’s licenses.
“Impersonation scams, like this one, are increasingly common but not new,” said Tracy Goldberg, Director of Cybersecurity at Javelin Strategy & Research. “This is basic spear phishing–a tailored malicious email that is sent to a specific person or organization appearing to be from a trusted source. Business email compromise, also known as CEO or executive compromise, falls into this category, where employees are duped by convincing emails that appear to be coming from a high-level executive within the organization.”
“In the Revolut incident, the domain of a legitimate government agency was used to email compliance staff at Revolut, fake emergency data requests, prompting Revolut internal teams to manually compile and disclose sensitive customer data,” she said.
Fueling Scams and Schemes
Once the incident was discovered, Revolut blocked the email address and alerted the appropriate government and law enforcement organizations. While the firm said none of its systems or customer funds were affected, the exposure of personal data can have consequences of its own.
Information obtained through a breach can be can be used to target affected consumers directly, but it can also be repurposed for scams and impersonation schemes involving other individuals or organizations.
Stolen or leaked information can also contribute to the creation of synthetic identities. By combining legitimate information from multiple sources, criminals can construct identities that may be difficult to detect and that can potentially bypass static fraud checks.
Amplifying the Ramifications
These factors can cause the effects of a data breach to extend well beyond the initial incident. The challenge is compounded by a fragmented digital identity landscape, where differing state laws and inconsistent standards have muddied the waters around how identity should be established and verified online.
For financial institutions, that uncertainty can make it more difficult to distinguish legitimate activity from suspicious behavior—and to respond effectively when something appears to be wrong.
Unfortunately, these vulnerabilities will only widen as criminals gain access to more legitimate customer data. In the case of the Revolut incident, TechCrunch reported that the exposed data may have extended beyond basic contact and identification details to include verification selfies, account statements, and transaction histories. If confirmed, the breadth of that information would underscore the broader challenge, which is protecting against fraud requires more than determining whether a message or domain appears to be legitimate.
“Email security is becoming an increasingly critical piece of modern cybersecurity, and financial firms are no exception,” Goldberg said. “As spear phishing techniques continue to evolve, organizations of all types must be vigilant by shoring up their secure email gateways. Email security has evolved from being a standard IT checkbox item to a primary cyber-defense priority.”







