This week’s Orpheus Weekly Intelligence Summary examines the Revolut data exposure, which affected 680 customers after fraudulent requests were submitted from a legitimate government email domain. Personal and financial information was disclosed, while customer funds and credentials remained unaffected.
The requests passed domain-authentication checks without attackers directly compromising Revolut’s systems. Our assessment examines the weaknesses in the verification process and what the incident means for organisations handling sensitive data requests.