Don't Fall Asleep At The Email "Wheel": Even Authenticated Emails Cannot Be Trusted

A fintech company, Revolut, recently confirmed that sensitive customer information was leaked to an unauthorized third party via a fraudulent email request.

Revolut stated it disclosed this information after inspecting the email and determining the email domain was legitimate and from a government agency.

Upon discovery of the fraud, the company said it immediately blocked the email address and alerted the government agency, law enforcement, data protection agencies, and financial regulators.

Revolut claims the scope of the breach only reached a "very limited" number of customers who have already been notified. Data revealed included date of birth, address, email address, phone numbers, and copies of identity documents, including driver's licenses and passports.

The company's internal systems and customer funds were allegedly not affected by this data leak.

Source: https://www.reuters.com/legal/litigation/revolut-confirms-sensitive-customer-data-breach-falling-fake-government-requests-2026-09-12/

Commentary

Email authentication protocols, SPF, DKIM, and DMARC, tell recipients whether an email was sent via an authorized path for the sending domain.

What they fail to do is verify - without a doubt - that the person who actually wrote that email is who they claim to be. This complicates cybersecurity measures because, in these cases, the email will appear legitimate and even its authentication will be correct.

That appears to be what happened in the above matter. Cybercriminals utilized a technically-valid email domain to carry out their scheme and fool the recipient.

To help reduce the risks, organizations should not only rely on email authentication, but they must also rely on proper procedural controls.

Any emailed requests for money or information should be verified with the sender via a separate communication method, for example phone call or through an online portal's messaging feature.

The final takeaway is that even email authentication cannot assure that every email is safe. Organizations should never fall asleep at the wheel when it comes to verifying emails.

Finally, your opinion is important to us. Please complete the opinion survey:

Product

Articles

Don't Fall Asleep At The Email "Wheel": Even Authenticated Emails Cannot Be Trusted

A fintech company experienced a data breach after a fraudulent email request. We discuss why even the best technical authentication cannot catch every email fraud scheme.

The Potentially Costly Disadvantages Of Failing To Document Patient Safety Issues

A nursing home faces a lawsuit involving lack of documentation after a nurse reported patient wellbeing concerns. We discuss why failing to document creates more risks than some may realize.

Attack Times Are Shortening, Requiring Response Times To Match

Cybercriminals are using online meeting software to deploy malware within 17 hours. We discuss what these fast attacks mean for organizations.

Ignoring Pay Disparity Claims: A Risky Strategy For Healthcare Employers

The EEOC sued a healthcare employer and alleged a female employee was paid far less than her male coworker. We discuss.

Why Relying On Restitution Is Not A Good Bet

A tribal organization suffered a loss of nearly $5M after an employee's embezzlement scheme. We discuss why restitution does not always equal full recovery.