REVOLUT disclosed customer data after receiving a request from what appeared to be a genuine government email address, according to Matthew Sellers’ report. The incident did not involve a conventional server intrusion or malware: the fintech was persuaded to provide information in response to a fraudulent but convincing request. The supplied extract does not specify how many customers were affected, what data was disclosed, or whether the email address was technically compromised.
The case highlights a potential gap in cyber-insurance cover. Social-engineering endorsements commonly focus on unauthorised transfers of money, while crime policies are generally designed around financial loss and data-breach policies may assume unauthorised access to systems. A scenario in which an organisation is tricked into releasing a large volume of identity and biometric data, without money being transferred, may therefore fall between existing definitions.
The report says brokers reviewing policies for fintech and financial-services clients may need to establish whether “fraudulent instruction” clauses cover requests for information as well as payment instructions.