Don't Fall Asleep At The Email "Wheel": Even Authenticated Emails Cannot Be Trusted

A fintech company, Revolut, recently confirmed that sensitive customer information was leaked to an unauthorized third party via a fraudulent email request.

Revolut stated it disclosed this information after inspecting the email and determining the email domain was legitimate and from a government agency.

Upon discovery of the fraud, the company said it immediately blocked the email address and alerted the government agency, law enforcement, data protection agencies, and financial regulators.

Revolut claims the scope of the breach only reached a "very limited" number of customers who have already been notified. Data revealed included date of birth, address, email address, phone numbers, and copies of identity documents, including driver's licenses and passports.

The company's internal systems and customer funds were allegedly not affected by this data leak.

Source: https://www.reuters.com/legal/litigation/revolut-confirms-sensitive-customer-data-breach-falling-fake-government-requests-2026-09-12/

Commentary

Email authentication protocols, SPF, DKIM, and DMARC, tell recipients whether an email was sent via an authorized path for the sending domain.

What they fail to do is verify - without a doubt - that the person who actually wrote that email is who they claim to be. This complicates cybersecurity measures because, in these cases, the email will appear legitimate and even its authentication will be correct.

That appears to be what happened in the above matter. Cybercriminals utilized a technically-valid email domain to carry out their scheme and fool the recipient.

To help reduce the risks, organizations should not only rely on email authentication, but they must also rely on proper procedural controls.

Any emailed requests for money or information should be verified with the sender via a separate communication method, for example phone call or through an online portal's messaging feature.

The final takeaway is that even email authentication cannot assure that every email is safe. Organizations should never fall asleep at the wheel when it comes to verifying emails.

Finally, your opinion is important to us. Please complete the opinion survey: