Like many companies before them, Revolut’s data breach, confirmed on Saturday, wasn’t down to vulnerable computer systems. Instead, it came down to social engineering and human error.
The fintech said sensitive customer information was accidentally disclosed to an unauthorised third party following fraudulent requests that came from a genuine government agency email domain.
Among the compromised data were customers’ birth dates, postal and email addresses, phone numbers, and copies of identity documents such as passports and driving licences.
Only a small number of customers are thought to be affected by the data breach, although Revolut has not confirmed exactly how many.
All those affected have been contacted, Revolut said, with its systems and customers unaffected by the breach.
But for those who are caught up in such an incident, it can be worrying. Revolut customers are not the only ones that found their data in the wrong hands.
If you have been notified that you have been caught up in a data breach, there are some steps that you can take to protect yourself.
Change passwords
Some data breaches involve the leaking of confidential login details such as email addresses and passwords. If your information has been compromised, you should immediately change the passwords of any affected accounts to keep unauthorised users out.
Think about where else you may have used those same login details. Although reusing passwords is a security no-no, plenty of people still do it. You will need to change the authentication details for those accounts too to make sure malicious users aren’t trying their luck with your other services.
For accounts that offer two-factor authentication, enable it. It will give you another layer of protection and also provide a timely warning if someone is trying to break into your accounts.
Watch out for identity theft
If, as in the case of Revolut, personal documents have been leaked, users should keep an eye out for any indication that someone is trying to use their identity. For example, if you get a notification of a new account that has been opened in your name, don’t dismiss it as a simple error.
Keep watch on your accounts
If your financial information was disclosed as part of the breach, you should monitor your bank accounts for any suspicious activity – transactions you don’t recognise, particularly smaller value ones that might fly under the radar.
Alert your bank that your information was compromised so they can keep an eye on your account, or cancel any affected cards and reissue them.
Be aware of phishing
Once a data breach happens, the bad actors will swarm. Phishing attempts will inevitably follow as others try their luck to see if they can catch you out.
Don’t click unsolicited links sent in emails or text messages. They could be fake web addresses and it is getting increasingly tough to spot the fraudulent ones. Type in the web address yourself to make sure you are visiting the genuine website.
How can you protect yourself in the future?
The less there is out there about you, the less there is for malicious users to find. Give as little information away as possible. Use email aliases to sign up for accounts rather than your regular email address – Apple users can use iCloud+ to hide their email – and you can deactivate the email address once it is no longer needed.
Don’t blindly hand over data such as your date of birth if it is not crucial to the service you are signing up for. If the data requested is optional, don’t provide it.
Forewarned is forearmed. Check websites such as HaveIbeenpwned.com to see if your email addresses have surfaced in any other data breaches online. The site also offers a notification service so should your details show up in a new breach, you will be alerted.
