The Desk · The Wire · Hacked Today? · Data Center RSS
The Perimeter Site

The cost of calling a fake email sophisticated

The Perimeter Desk
2026-09-14
# The cost of calling a fake email sophisticated You get paged at 3am because your customer's passport is sitting in a public Telegram channel. It's right there next to their selfie and their whole transaction history; that's the reality of the Revolut mess. It isn't some complex puzzle. It's just bad hygiene. Revolut calls this a "sophisticated impersonation scam. In SOC speak (the language of security operations centers), that usually means they're embarrassed and want to move the goalposts; strip away the corporate talk and the story is simple. Someone sent an email pretending to be a government entity. A Revolut employee saw it, believed it, and handed over the KYC data. Was there anything sophisticated about a fake email passing security checks? I don't think so. It's a failure of process; if internal controls let someone export sensitive customer dossiers just because of an inbound request that wasn't verified through a secondary out-of-band channel, the problem isn't "sophistication. It's training and policy. The attackers didn't need a CVSS 10.0 exploit like the one hitting GitLab this week; they didn't have to deploy a backdoor via JFrog Artifactory flaws or write complex VBScript payloads for a worm-like spread. All they needed was one person to click "send" on a CSV file. Getting hit is common. Handling it this poorly is a choice. Revolut keeps dodging the only question that matters: how many people actually got hit, and they use phrases like "client dossiers" and "massive breaches," but they won't give us a headcount. Irish users are just left hanging, and leaving customers to wonder if their identity is currently for sale on some Russian bot forum isn't a strategy. It's a liability. Then you have the cost, and sure, there's the immediate hit from the extortion attempt happening on Telegram right now. That's the small bill. The real invoice arrives later through regulatory fines and a slow rot of trust; when you handle KYC data, you're holding the keys to someone's financial life. Once that leaks, it's out there forever, and you can change a password, but you can't change your passport number or your face. Why isn't Revolut pricing in the second-order effects? These leaked dossiers are a goldmine for criminals. This is bigger than one fintech company losing files. The whole financial sector is now staring down a wave of high-fidelity identity theft. Attackers can take these leaked selfies and passports to open fake accounts at other banks, sliding right past the KYC checks that Revolut failed to protect. The blast radius goes way beyond their own balance sheet. Some will argue that state-level impersonation is getting harder to detect. They'll say that the social engineering was too perfect for a standard filter to catch. The argument doesn't hold water because security isn't about the filter. It's about the handover. No email (no matter how "official" it looks) should be enough authorization to export bulk sensitive data. That's a basic breach of the principle of least privilege, and if you have a single point of failure where one gullible employee can bring down the house, the process is broken. We've seen this before. It rhymes with those fintech leaks from the last few years where "compliance" was just a checkbox instead of a real security boundary, and the difference here is what was stolen. Past breaches gave up email addresses and hashed passwords. Here we have passports and KYC selfies. The current threat environment doesn't make this kind of negligence okay. Criminals are getting efficient. Take the JeetBot extension that ripped OAuth tokens from nearly 31,000 Twitch users (fast and lean). Or the GenSan hospital attack where the hackers demanded exactly 8 bitcoins, and these aren't always complex plays. Often they're just opportunistic strikes on the weakest link. One Conti operator got four years in jail for his part in a $150M extortion campaign; it shows that while the scale is massive, the methods are repetitive. Attackers know which buttons to push because companies keep leaving them exposed. Revolut didn't just let an attacker in, and their mistake was thinking they could manage the fallout with vague language and "sophisticated" labels. You don't get points in a postmortem for using fancy words to describe a basic error. You get points for finding the gap and closing it before the next email hits the inbox. Who else is trusting their KYC process to one employee judging an email header? If that's how you're set up, you aren't waiting for an attack; you're just waiting for the Telegram link to arrive.
◼

Sources

The reporting this analysis was built from. Follow the originals before acting on anything here.

  1. Three JFrog Artifactory Flaws Exploited for Backdoor Deployment SecurityWeek
  2. CISA: Hackers now exploit max severity GitLab flaw in attacks BleepingComputer
  3. ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks SecurityWeek
  4. Revolut Data Breach Exposes Passport Copies, KYC Selfies and Full Transaction Histories - cyberpress.org Google News Security
  5. Weekly Cybersecurity Newsletter Bulletin – Microsoft 0-day, FortiOS, PAN-OS Flaw, Revolut Data Breach, and... - CyberSecurityNews Google News Security
  6. Revolut hit by extortion as hackers leak client dossiers on Telegram - Pasquale Pillitteri Google News Security
  7. Revolut Exposed KYC Data After Fraudulent Government Email Passed Security Checks - securityaffairs.com Google News Security
  8. Revolut Data Breach: Hackers Leak Customer Documents, Demand Ransom Payment - Blockonomi Google News Security

How stories are selected and rated

← More from the Desk Live Wire →

About · Methodology · Contact · Privacy

Tracking a CVE from this story? Hazard shows which vulnerabilities are confirmed exploited in the wild — and what the resulting breaches have cost UK organisations.

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.