Revolut breach: nobody hacked in, and that is the point
Revolut handed sensitive customer data to an unauthorised third party after fraudulent requests arrived from a legitimate government domain. Mark Fermor argues the real question is not how it happened, but why the process allowed it.

Why it matters
What this means for organisations holding critical data
Revolut handed sensitive customer data to an unauthorised third party after fraudulent requests arrived from a legitimate government domain. Mark Fermor argues the real question is not how it happened, but why the process allowed it.
What happened
Revolut has confirmed that sensitive customer data was disclosed to an unauthorised third party after fraudulent requests for information were submitted from an email account created within a legitimate government agency domain. The request looked genuine, because part of it was.
According to the customer notification reviewed by TechCrunch, the compromised information included dates of birth, postal and email addresses and phone numbers, as well as copies of identity documents such as passports and driving licences. Verification selfies, account statements and transaction histories may also have been exposed.
Revolut says a very limited number of customers were affected and have been contacted directly. It has not disclosed how many people are involved or named the government agency. The company blocked the email address used in the fraud after detecting the incident, alerted the agency, law enforcement, data protection authorities and financial regulators, and says its systems and customer funds were unaffected.
The incident was highlighted publicly by crypto security researcher ZachXBT, who suggested the breach appeared to have targeted high-net-worth users. Revolut has not confirmed that assessment.
We are asking the wrong question
Everyone wants to know how it happened. I am far more interested in why the process allowed it to happen.
Nobody hacked their way in. Nobody bypassed some cutting-edge security control. A request arrived, it looked legitimate enough, and sensitive customer information was handed over. According to reports, the request came from an unauthorised account created within a legitimate government domain, which made it appear genuine enough to be trusted.
That should make every organisation stop and think.
We spend huge amounts of time and money testing technology. We run penetration tests. We monitor alerts. We patch vulnerabilities. We invest in new tools. But how many organisations test the decisions their people make when a request appears to come from an authority they trust?
This is where many businesses get caught out.
Compliant and vulnerable at the same time
Two things can be true at once. You can be compliant, and you can still be vulnerable.
The problem is that many organisations behave as though those two things cannot possibly coexist. I have seen businesses with immaculate policies, successful audits and folders full of evidence. Yet when you start looking at their processes through an attacker's eyes, cracks begin to appear.
Not because they are careless. Not because they are incompetent. Because nobody has ever challenged the process in the real world.
That is the difference between documenting a process and proving it works. The organisations that worry me are not the ones that know they have gaps. It is the ones that are convinced they do not.
The question worth asking
If someone targeted your organisation tomorrow with a legitimate-looking request for customer, employee or financial data, are you confident your process would stop them? Or are you confident your process is documented?
They are not the same thing.
This is also where the data itself matters. Revolut disclosed copies of passports, driving licences and possibly statements and transaction histories because that material was retained and reachable through a routine request process. Where identity records and historical documents must be kept, Offline Secure Storage® keeps them physically disconnected from the systems and inboxes that field incoming requests, so disclosure becomes a deliberate, verified act rather than a response to a convincing email.
Test the process, not just the perimeter. And do not leave your most sensitive records permanently reachable by whoever asks nicely enough.
Mark Fermor is the founder of Firevault.
Sources
How Firevault would handle this
Controls an auditor can physically verify
Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.






