ZeroHour
DataBreaches.netpublished ()ingested Dissent

Revolut’s paperwork breach shows why insurers are rethinking what counts as a ‘cyber attack’

mediumData breachimportance 45
AI summary · glm-5.3

Revolut handed customer data to an attacker using a spoofed government email, prompting insurers to rethink cyber attack coverage definitions.

Revolut disclosed customer data after receiving a request from what appeared to be a genuine government email address; no servers were breached and no malware was involved. The social engineering incident has become a test case for how cyber insurers define a 'cyber attack'. The report is by Matthew Sellers. It highlights a growing gap between technical intrusions and data-loss incidents caused by impersonation.

  • Attacker impersonated a government email address to obtain customer data from Revolut.
  • No server compromise or malware; data was handed over in response to the request.
  • Insurers are reconsidering whether such incidents count as a 'cyber attack' for coverage.
  • Incident illustrates social engineering risks outside traditional hacking definitions.
Full article

Matthew Sellers reports: Revolut wasn’t hacked in the usual sense. No one broke into its servers or slipped malware past its defences. Someone asked for customer data, from what looked like a genuine government email address, and Revolut handed it over. That email is now behind one of the stranger data incidents to hit a... Source

The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at databreaches.net.