Why the Revolut impersonation hack should be a wake-up call for the city
The fact that a company as established as Revolut fell victim to such an attack underlines the threats facing financial services firms, says Graeme Stewart
Who am I really talking too? That’s the uncomfortable question that is on everyone’s lips following reports that Revolut has been hit with a $3m ransom demand after a sophisticated impersonation scam.
Indeed, the rise of a new wave of highly realistic deepfakes, fraudulent emails, voice clones and tailored impersonations mean that a healthy sense of paranoia is now mandatory for City workers.
The fact that a company as established as Revolut fell victim to such an attack underlines the threats facing financial services firms, rather than being a reflection on the company’s defence systems.
A little look at the public details released so far indicate that a lot of time and effort was put into to convincing the gatekeepers at Revolut that every request for access was above board. We are told that the anonymous hackers managed to compromise an Italian government email system, allowing them to make large requests for the details of hundreds of customers, cloaked in government respectability. Whilst this is a very notable breach secured via impersonation; it most certainly won’t be the last.
Can you spot a deepfake?
Before anyone rushes to judgement, a few questions must be asked. Think you can spot a deepfake? They’re now so good, you probably can’t. Ever sent an email to a fraudulent address? You probably have, even if you didn’t hand over any compromising information. Ever heard a voice clone? They’re all-over social media, used for fake advertisements and get rich quick scams and you also probably have a few in your missed calls log.
It’s not just the City boys who should be worried. Even Andy Burnham found himself exchanging Whatsapp messages with a person purporting to be Trump aide Susie Wiles. Thank goodness the PM smelt a rat, or national security details could have found their way into the wrong hands.
One wonders, if Britain’s Prime Minister can fall victim to such attacks, are any of us safe? Fortunately, there are a series of steps that can be taken to ensure these things attacks are spotted before confidential data is handed over.
Firstly, it’s all about awareness. The reality is that the public and private sector has been unsuccessful in training staff around how these attacks take place and how to spot them. Most these scams rely on human error, for example a member of your team handing account details or authorising a payment due to pressure from someone impersonating their line manager. That’s why robust training programmes around identify verification are so important, with members of staff having a system in place to confirm requests through secure systems and with multiple sign-off points to ensure accuracy.
Secondly, the race to adopt shiny new AI tools and tech has meant that security strategy has only been an afterthought for far too many companies. Many banks and financial services firms have rigorous systems in place for background checks around KYC and money laundering but are weak when it comes to spotting deepfakes and voice clones. This mismatch cannot be allowed to continue, and verification that people are who they say they are cannot be a secondary issue when it comes to confirming a customer.
Finally, it’s about securing the supply chain. We know from major incidents such as Revolut, JLR and M&S that all too often these criminals gain access through third party systems. It’s a lot easier to break into a company if you can enter using email addresses and credentials that appear legitimate.
The truth is that the wolves are circling and these incidents are likely to get worse before they get any better. It’s time to wake up to the new wave of impersonation scams and that means a healthy dose of paranoia is no longer such a bad thing.
Graeme Stewart is head of public sector at Check Point