ResearchIdentity Fraud

Revolut Data Breach: Identity Risk and Digital Banking Fraud Prevention

The Revolut incident shows how sensitive identity data collected to prevent fraud can become a source of exposure itself.

Editorial artwork: Revolut Data Breach: Identity Risk and Digital Banking Fraud Prevention

Download the full research

Use your work email.

Executive summary

Heka’s incident analysis examines how identity-rich data exposure can create downstream fraud risk and what fraud teams should review in their step-up, identity and monitoring controls.

  1. Incident reconstruction

    Confirmed facts, public reporting and unverified claims separated clearly.

  2. Control-gap analysis

    How apparent authority became a decision to disclose customer data.

  3. Response checklist

    Controls to review now, over 30 days and over 90 days.

  4. Lower-data step-up

    Where identity intelligence can reduce unnecessary document collection.

Incident reconstruction

The process was the entry point. The data was the payload.

Revolut said its systems and customer funds were unaffected. Sensitive customer information was reportedly disclosed after fraudulent requests arrived through a legitimate government-agency email domain.

  1. Request receivedGovernment channel
  2. Authority assumedDomain appears legitimate
  3. Request approvedInternal process proceeds
  4. Data disclosedCustomer records leave
  5. Exposure createdSensitive data is outside the institution
The more sensitive identity data an institution retains, the greater the potential impact when a disclosure process is abused.

Important distinction: Heka would not have prevented the fraudulent government request. It helps address a related exposure: unnecessary collection and retention of sensitive identity documents.