Revolut’s Breach Shows the Cybersecurity Risk African Fintechs Cannot Ignore

Share

For fintech companies, cybersecurity has traditionally centred on protecting the systems that hold customers’ money. A recent incident at Revolut proves companies may also be vulnerable through the processes used to handle sensitive customer information.

The UK fintech has disclosed that sensitive customer information was handed to an unauthorised third party after the company received what appeared to be a legitimate request from a government agency.

The request came from an email account using the agency’s genuine domain and passed technical authentication checks. Revolut subsequently treated the request as a legitimate legal-compliance request.

The incident reportedly affected around 680 customers, with exposed data including names, dates of birth, addresses, phone numbers, identity documents, and facial verification images. Some customer statements and transaction histories were also reportedly involved. Revolut has said its core banking infrastructure was not compromised and customer funds were unaffected.

For African fintechs, this highlights a risk that deserves greater attention as the sector expands and companies begin operating across more markets.

The threat is moving beyond the system

African fintechs have invested heavily in securing their platforms, particularly as they increasingly handle payments, savings, lending, remittances and other financial services at scale. The Revolut incident demonstrates how those investments can be undermined.

The attacker did not need to gain access to Revolut’s banking infrastructure. Instead, the attack exploited an existing business process, responding to what appeared to be an official request for customer information. “The challenge is that the attacker does not necessarily need to compromise the technology. They need to convince a person that a request is legitimate,”  Kemisola Adelumo, Cybersecurity, GRC & AI Governance and Security Specialist, told Tech Disrupt. 

“A convincing email should never, on its own, be enough to authorise the release of sensitive customer information. The stronger approach is to build controls around the employee so that even if a convincing request gets through, one mistake does not automatically become a serious data breach,” she stated.

That creates difficult questions for fintech operators.

Who is authorised to request customer data? How should that request be verified? Can an employee rely on an authenticated email address? What additional checks should apply when a request appears to come from a regulator, law enforcement agency or another trusted institution?

These questions become more important as fintechs become larger and operate across multiple markets.

African fintechs are building increasingly valuable data assets

The growth of African fintech has also changed the nature of the information these companies hold.

A successful fintech may have access to identity documents, transaction histories, account information, phone numbers, addresses and other highly sensitive customer data. For companies operating across borders, the volume and complexity of that information can increase further as they deal with different regulatory regimes, banking partners, payment providers and government agencies.

This creates more opportunities for mistakes, manipulation and unauthorised access. The risk can sit across the organisation, from technology and compliance teams to customer support, finance and operations.

That matters particularly for fintechs expanding into markets such as the UK, where regulatory obligations can generate regular requests for customer and transaction information. As companies build these international operations, the processes surrounding data sharing need to receive the same level of attention as the technology itself.

The human layer needs the same investment

The Revolut incident also raises questions about how fintechs approach internal security.

Much of the focus tends to sit with encryption, authentication, fraud detection, penetration testing and monitoring. Those measures remain essential, but employees and business processes form another critical part of the security architecture. A convincing request can bypass sophisticated technical controls if the person receiving it has the authority to release sensitive information.

Kemisola also noted that “Employees should only have access to the customer information they genuinely need to perform their role. That limits the potential impact if an employee is targeted successfully. Where appropriate, the request should be independently verified through a trusted channel.”

Recommending regular security awareness training for employees, the cybersecurity expert added that organisations should build guardrails around processes for identifying and escalating suspicious and unusual requests. “The objective should not be to expect employees to identify every sophisticated phishing attempt perfectly, but to build controls around them so that one mistake does not automatically become a data breach.”

For African fintech founders, security policies should therefore establish clear procedures for handling sensitive information requests, particularly those involving identity documents, financial records or large volumes of customer data.

A request appearing to come from a legitimate institution should still be independently verified where the sensitivity of the information warrants it. That becomes increasingly important as artificial intelligence makes impersonation and social engineering more convincing and easier to scale.

The cost extends beyond the breach

For a growing fintech, a data incident can create consequences across several parts of the business. There can be regulatory scrutiny, customer concerns, remediation costs and reputational damage. The impact can also extend to relationships with banking partners, investors and potential international partners.

For African fintechs seeking to expand internationally, these risks become part of the wider challenge of building an organisation that can operate reliably across jurisdictions. Consequently, cybersecurity needs to feature in decisions around market expansion, compliance and operational design.

The question for founders is how effectively their organisation can verify the people and institutions asking for access to sensitive information, particularly when the request appears legitimate. Revolut’s experience offers a useful case study. A sophisticated financial technology company can have strong technical defences and still face serious exposure when trust is exploited through an ordinary business process.

Read more

Local News