· SECURITY PROCESS
Revolut data incident: authentication is not authorization
The incident is a useful reminder that a trusted sender, valid domain or authenticated channel does not by itself prove that a sensitive request is legitimate.

Short, sourced analysis of current incidents and the security controls businesses can review before the same pattern reaches them.
Revolut confirmed that sensitive customer information was disclosed after fraudulent information requests appeared to come from a legitimate government agency email domain. The company says its internal systems and customer funds were not compromised.
The incident is a useful reminder that a trusted sender, valid domain or authenticated channel does not by itself prove that a sensitive request is legitimate.
Independent verification, dual approval for high-risk disclosures, anomaly detection, data-minimisation and incident-ready customer communication.