Urgent.News

What's breaking now, across thousands of outlets.

Finance & Markets

Revolut and Fed Incidents Expose New Risks Inside Banking’s Trust System

Revolut and the Federal Reserve are in the news this week after suffering two banking infrastructure compromises. However, the most interesting thing about the separate incidents isn’t what happened; it’s what did not. Hackers did not have to break into Revolut to obtain sensitive customer information. And banks did not have to suffer their own […] The post Revolut and Fed Incidents Expose New…

Revolut and Fed Incidents Expose New Risks Inside Banking’s Trust System

Revolut and the Federal Reserve experienced separate security breaches in recent weeks, but the most alarming aspect isn't the breach itself—it's the underlying vulnerability. Hackers didn't need to infiltrate Revolut to obtain personal data, and banks didn't require technology failures to disrupt infrastructure monitoring the financial system. The weak points arose within the trusted systems that surround financial institutions.

On September 11, Revolut revealed it had fallen victim to a fake emergency data request originating from a compromised Italian email system. Attackers had been impersonating law enforcement over several months, leading the FinTech to share sensitive client information, potentially including identification documents, selfies, addresses, account statements, transaction histories, and even cryptocurrency activity. Revolut now faces extortion from the hackers behind the breach.

In August, the Federal Reserve's National Information Center (NIC) suffered an outage that disrupted internal systems and data pipelines across multiple Fed business areas. Although unrelated, these incidents highlight a growing operational challenge for financial institutions. Banks have been investing in their defenses and scrutinizing vendors, but the next risk perimeter may involve the institutions they trust, a control harder to manage.

The PYMNTS report, "Payment Protection: Why Firms Still Aren't Real-Time Ready," noted that 65% of firms plan to adopt or expand identity verification and KYC automation within the next year. However, government requests complicate matters. A bank can verify a message's legitimacy through legitimate government infrastructure, but establishing the individual's authority to request specific customer data becomes challenging.

For banks, holding passports, driver's licenses, addresses, and detailed financial histories creates valuable targets for fake government requests, turning them into operational risks.

In the case of the Fed's NIC outage, the government infrastructure itself became unavailable, contrasting with the hacker-driven breach at Revolut. Banks possess sophisticated measures to deal with commercial dependencies, but government infrastructure presents a different challenge. Switching regulators isn't an option, and dictating technical architectures of law enforcement platforms isn't feasible.

Therefore, financial institutions must adapt their risk management strategies to address these emerging threats within trusted institutional machinery.

Written by urgent.news from PYMNTS's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at pymnts.com →

More in Finance & Markets

More from Wednesday 16 September →