In September, it emerged that Revolut was facing a reported $3 million ransom demand after hackers posing as government officials accessed the data of hundreds of the bank’s cryptocurrency customers, including one victim who said they feared for their safety.
At a time when financial organisations face multi-faceted attacks, what lessons can CISOs learn to prevent facing a similar breach?
Valuable Information
Financial firms such as Revolut are at risk of attacks partly due to the vast amounts of personal data they hold.
This can include identity documents, addresses, account information and transaction histories. At the same time, the sector has obligations to respond to regulators, law enforcement and other public authorities.
Financial services have always been a prime target for adversaries, but the risk has significantly shifted over the past few years as the combination of personally identifiable information, financial credentials, and now cryptocurrency holdings make fintech platforms an “extraordinarily rich target,” says Tracey Hannan-Jones, consulting director in information security, UBDS Digital.
She describes how rapid growth in the sector has created its own vulnerabilities. “Firms that scale from startup to multi-million-user platform in a few years often find their security architecture struggling to keep pace with their commercial ambition.”
At the same time, the financial sector uses processes where “both trust and speed matter," says Tobias Ander founder of Securebyme AB and author of ‘Information Security Culture: The Missing Layer of Cyber Defence.
Therefore, he says an attacker who can convincingly impersonate an authority as they did in the Revolut incident “may not need to break through the technical perimeter at all.”
Targeted Attack
The details released so far about the Revolut incident paint “a clear picture of a targeted, socially engineered attack,” according to Hannan-Jones.
The method of entry, where attackers were impersonating a legitimate authority, is “notable,” she says: “It suggests either that the attackers possessed convincing materials to support impersonation, or that internal verification processes were insufficient to challenge a credible-sounding request,” says Hannan-Jones. “Either way, the result was unauthorised access to a dataset that has now become a weapon against the very customers the organisation was trusted to protect.”
The most important lesson from the Revolut incident is that organisations can no longer think about cyber security purely in terms of protecting systems from external attacks, says Tom Lovell, head of security services Infinity. He describes how attackers are increasingly targeting people, processes and trust relationships instead.
The Revolut breach also demonstrates how the damage from cyber-attacks can outlast the initial incident. In Revolut’s case, affected customers have received targeted phishing texts using the leaked data to make scams more credible. “Once personal data like this is out there, criminals can use it to make subsequent approaches look far more convincing,” says Daryl Flack, partner at Avella Security
This is where a data breach can become a fraud problem, says Flack. “A phishing message containing information only your bank should know is much harder for a customer to spot as a scam.”
Flack says Revolut should have had stronger out-of-band verification for official requests, rather than relying on trust in email domain authenticity. “An email coming from the right domain should not automatically mean the person behind it is who they say they are.”
There should also have been tighter controls and dual authorisation before releasing information collected through Know Your Customer checks, particularly identity documents and detailed transaction histories, Flack says. “The more sensitive the information being requested, the harder it should be for one request – or one person – to release it.”
Customer guidance could also have been more clear and specific about the exact risks customers faced, and the protective steps they should take, says Flack. “’Be alert for phishing’ only goes so far. Customers need to know what attackers now know about them, how that information might be used and what a suspicious approach could look like.”
Yet experts say Revolut should also be praised for its communications around the incident. Revolut disclosed the incident, engaged with the relevant authorities, and moved to notify affected customers swiftly, says Hannan-Jones. “In an environment where organisations still agonise over disclosure timelines – sometimes to the detriment of the people whose data has been compromised – transparency and speed of communication matter.”
Lessons For CISOs
Even so, there are lessons to be learned for all CISOs. Firstly, verification processes need the same level of scrutiny as technical controls, according to Lovell.
Organisations should be asking themselves whether requests for sensitive data can be independently verified, whether high-risk disclosures require secondary approval, and whether staff feel empowered to challenge requests that appear unusual – even when they come from seemingly trusted sources, he advises. “Security awareness training remains important, but organisations also need security processes that assume people can be deceived.”
Ander thinks financial firms should look closely at where the organisation relies on trust. ”Most businesses have processes where a regulator, law enforcement agency, supplier, auditor or another trusted external party can trigger a sensitive action. CISOs spend a great deal of time thinking about who can access systems. They should also ask who can persuade their organisation to take a sensitive action, and what happens before somebody says yes.”
CISOs also need to think beyond preventing the initial breach, says Flack. “Assume that if valuable personal data gets out, somebody will try to weaponise it. Once personal data is out there, phishing follows.”
Customer communications and fraud monitoring need to be “ready to go,” so organisations can respond to the secondary attacks that follow the initial incident, Flack advises. “The breach is only the first part of the incident. What criminals do with the data afterwards can be just as damaging.”
,
Written by
Kate O'Flaherty
Cybersecurity and privacy journalist