Don't Fall Asleep At The Email "Wheel": Even Authenticated Emails Cannot Be Trusted

A fintech company, Revolut, recently confirmed that sensitive customer information was leaked to an unauthorized third party via a fraudulent email request.

Revolut stated it disclosed this information after inspecting the email and determining the email domain was legitimate and from a government agency.

Upon discovery of the fraud, the company said it immediately blocked the email address and alerted the government agency, law enforcement, data protection agencies, and financial regulators.

Revolut claims the scope of the breach only reached a "very limited" number of customers who have already been notified. Data revealed included date of birth, address, email address, phone numbers, and copies of identity documents, including driver's licenses and passports.

The company's internal systems and customer funds were allegedly not affected by this data leak.

Source: https://www.reuters.com/legal/litigation/revolut-confirms-sensitive-customer-data-breach-falling-fake-government-requests-2026-09-12/

Commentary

Email authentication protocols, SPF, DKIM, and DMARC, tell recipients whether an email was sent via an authorized path for the sending domain.

What they fail to do is verify - without a doubt - that the person who actually wrote that email is who they claim to be. This complicates cybersecurity measures because, in these cases, the email will appear legitimate and even its authentication will be correct.

That appears to be what happened in the above matter. Cybercriminals utilized a technically-valid email domain to carry out their scheme and fool the recipient.

To help reduce the risks, organizations should not only rely on email authentication, but they must also rely on proper procedural controls.

Any emailed requests for money or information should be verified with the sender via a separate communication method, for example phone call or through an online portal's messaging feature.

The final takeaway is that even email authentication cannot assure that every email is safe. Organizations should never fall asleep at the wheel when it comes to verifying emails.

Finally, your opinion is important to us. Please complete the opinion survey:

What's New

Don't Fall Asleep At The Email "Wheel": Even Authenticated Emails Cannot Be Trusted

A fintech company experienced a data breach after a fraudulent email request. We discuss why even the best technical authentication cannot catch every email fraud scheme.

New Malware Threat Targeting Apple Devices Exploits Apple Notarization

A new malware threat uses a developer ID and poses as a legitimate Apple crash reporter to trick users. We examine how the malware works and what organizations that use macOS should do.

Using AI To Code Generates Higher Malware Risk: How Should Organizations Respond?

A recent study reveals significant malware risk exists associated with AI in coding. We examine the statistics and discuss the loss prevention options.

Latest Numbers

  • Unemployment Rate
    4.3% in Jan 2026
  • Payroll Employment
    +130,000(p) in Jan 2026
  • Average Hourly Earnings
    +$0.15(p) in Jan 2026
  • Employment Cost Index (ECI)
    +0.7% in 4th Qtr of 2025
  • Productivity
    +4.9% in 3rd Qtr of 2025

Source: Department of Labor