Close Menu
UAE NEWS TODAY
    What's New

    Indian Business & Professional Council, Standard Chartered explore opportunities amid shifting global markets

    September 14, 2026

    Revolut incident highlights rising cyber risks from trusted identities

    September 14, 2026

    Mahira Khan announces second pregnancy at 41: ‘Life can surprise you’

    September 14, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    UAE NEWS TODAYUAE NEWS TODAY
    • Home
    • UAE
    • Business
    • Technology
    • Lifestyle
    • Sports
    UAE NEWS TODAY
    Home»Business»Revolut incident highlights rising cyber risks from trusted identities
    Business

    Revolut incident highlights rising cyber risks from trusted identities

    Editorial teamBy Editorial teamSeptember 14, 2026
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Global businesses are facing a growing cybersecurity challenge as attackers increasingly exploit trusted identities and legitimate communication channels rather than relying on traditional hacking techniques, security experts say, following a recent data disclosure involving digital banking platform Revolut.

    The incident came to light after Revolut provided sensitive customer information to an unauthorized third party that had sent fraudulent requests using the legitimate email domain of a government agency. According to the company, its systems were not breached. Instead, the requests originated from an unauthorized email account operating within the agency’s official domain and carried valid domain authentication credentials. Revolut fulfilled the requests believing they were genuine before later verifying them with the government agency and discovering the account was unauthorized.

    The information disclosed reportedly included customers’ full names, dates of birth, occupations, addresses, email addresses, telephone numbers, copies of passports or driving licences, and facial verification images collected during identity checks.

    Cybersecurity specialists say the case reflects a broader shift in the threat landscape, where criminals increasingly manipulate trust relationships rather than attempting to penetrate corporate systems directly.

    “The Revolut incident is an important reminder that cybersecurity failures do not always begin with malware, a missing security patch, or stolen credentials,” said Morey Haber, Chief Security Advisor at BeyondTrust. “Sometimes, via clever social engineering, a threat actor can simply ask for information and the victim provides the details freely based on poor identity confidence verification.”

    Haber said the case demonstrates a critical weakness in many organisations’ security processes, namely the assumption that communications originating from a trusted domain are automatically legitimate. According to him, the incident exposed a larger identity-security challenge because “authentication is not authorization,” meaning that proving where a message originated does not prove that the sender is entitled to request sensitive information.

    He described the event as a classic “confused deputy problem”, where a trusted organisation performs a legitimate action based on instructions that ultimately prove illegitimate.

    As a result, cybersecurity professionals are urging organisations that handle personal, financial and identity data to adopt stronger verification mechanisms before sharing sensitive information. Haber said “out of band request and identity verification, separation of duties, least privilege, and human approval should be mandatory before sensitive information leaves the organisation,” adding that “a simple email request alone should never be sufficient.”

    The growing sophistication of such attacks is also changing how security teams assess risk. Santiago Pontiroli, Lead TRU Researcher at Acronis, said threat actors are increasingly abusing legitimate accounts and business processes rather than attempting to impersonate them.

    “The key lesson is that attackers are increasingly abusing trusted identities and legitimate processes rather than trying to impersonate them,” he said. If a government account is compromised, fraudulent messages can still successfully pass widely used authentication controls including SPF, DKIM and DMARC.

    However, Pontiroli stressed that passing those checks does not guarantee a request is genuine. “SPF, DKIM and DMARC can help establish that an email is authentic. They cannot establish that the request itself is legitimate.”

    Instead, organisations should verify sensitive requests using information attackers cannot easily access, including independently sourced contact details, case validation procedures, historical request patterns and scrutiny of unusual urgency or scope.

    The incident underscores a wider reality confronting businesses worldwide: cyber threats are evolving from technical system attacks into trust-based attacks targeting people and processes. As digital identities become central to customer verification and regulatory compliance, experts say organisations must move beyond relying solely on email authentication and continuously validate the legitimacy of every high-risk request.


    Source: Khaleej Times

    Previous ArticleMahira Khan announces second pregnancy at 41: ‘Life can surprise you’
    Next Article Indian Business & Professional Council, Standard Chartered explore opportunities amid shifting global markets

    Related Posts

    Preparedness, collaboration bolster GCC tourism resilience, policymakers say at 33rd ATM

    September 14, 2026

    Goldman Sachs, JP Morgan expect September Fed hike as inflation lingers

    September 14, 2026

    Seven new tourism board tie-ups headline a busy ATM opening for Emirates

    September 14, 2026
    Top Posts

    UAE strengthens lead on day two of UAE National Jiu-Jitsu Championship

    June 13, 2026

    UAE Team Emirates-XRG targets victory at Copenhagen Sprint with Sprinter Leading Squad

    June 12, 2026

    Saeed Al Hajeri reaffirms UAE’s commitment to strengthening partnership with New Zealand

    June 12, 2026

    ECSSR Director-General meets Vice Minister of International Department of CPC Central Committee

    June 13, 2026
    Don't Miss

    Indian Business & Professional Council, Standard Chartered explore opportunities amid shifting global markets

    UAE September 14, 2026

    DUBAI, 14th September, 2026 (WAM) — The Indian Business & Professional Council Dubai (IBPC Dubai)…

    Revolut incident highlights rising cyber risks from trusted identities

    September 14, 2026

    Mahira Khan announces second pregnancy at 41: ‘Life can surprise you’

    September 14, 2026

    US Open: Zverev salutes mother who refused to let diabetes define his future

    September 14, 2026
    2026. All rights reserved.
    • UAE
    • Business
    • Technology
    • Lifestyle
    • Sports
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.