Do You Actually Trust That Email?
The SEC and EU regulators are currently highlighting the same fundamental failure: people trust their inbox more than they trust their controls.
Take Revolut. They gave away IDs and IBANs for 680 customers to scammers just because an email looked like it came from the government. Don't call that a sophisticated social engineering attack. It's just bad design. If your whole process for third party data requests is checking an email domain, you don't actually have a control. You have a suggestion.
I've seen this before. Early on with SOX, we wasted months arguing if a manager signing a PDF counted as a review. It didn't. The signature is theatre, while the evidence of the actual challenge is what counts as the control, and GDPR and data requests work the same way.
Regulators are moving on. They're done asking if you have a policy and now want to see the verification. Having a written policy that says you only give data to authorized government bodies means nothing if the person doing the work wasn't trained on out of band verification.
Most firms treat their Data Subject Access Request (DSAR) or government request logs as a filing exercise. They check the box, archive the email, and move on.
That costs you everything at year-end.
A breach like this doesn't just add a number to the ledger. In fact, depending on where you're based, fines for mid-sized lapses often top £4 million. But let's be clear: that isn't the heavy hit. The real expense is the fix work.
Once a regulator labels your design flawed, scope explodes. You aren't patching one process anymore, and suddenly, every single data egress point in the company needs an audit. It is tedious. It is necessary.
The C-suite usually pushes back with a familiar refrain: "We follow industry standards. They'll say their authentication is standard fare. And they're right. But then they argue no one expects them to call every government clerk across Europe just to verify an email; that's the gap, isn't it? The expectation versus the reality.
They are wrong.
You're moving high-value sensitive data? A callback or secure portal upload isn't overkill. It's the baseline. If your control plan assumes that nobody can spoof an email address, you aren't managing risk; you are gambling with customer data.
The insurers will feel it first, and d&O and cyber providers have stopped caring about "human error. They know when the mistake comes from a systemic lack of verification. Expect a questionnaire at renewal. It will ask how you verify government requests, and if your answer is "via email," brace yourself. Your premiums will jump or your coverage will shrink.
The auditors are happy, which is odd. More billable hours for them to spend on "validating" your new processes. But the person actually running these controls gets a simpler take: the old way was broken. Admitting that.
You can keep updating policy documents, and add fancy language about "security-first cultures. It doesn't matter if some guy with a Gmail account and a little creativity walks away with 680 customer records. None of those words stop him.
Before your next audit, answer one question, and what is the specific, non-digital step your team takes to verify a request before data leaves the building?
If that answer involves the word "email," start updating your resume.
Sources
The reporting this piece was written from. Check the originals before relying on anything here.
- Revolut handed customer data to fraudsters using government email account - therecord.media Data Privacy (Google News)
- SEC spots shortcomings in RIAs' annual compliance reviews - Citywire Compliance Week (Google News)
- Coupang creates outside security panel after record privacy fine - Aju Press Data Privacy (Google News)
- Revolut confirms sensitive customer data breach, falling for fake government requests - KWSN Data Privacy (Google News)
- Profusa cleared Nasdaq bid-price and equity rules, placed on one-year mandatory monitor - TradingView Compliance Week (Google News)
- Industrial Asphalts buyout falls through as Sri Lanka regulator blocks share transfer - EconomyNext Compliance Week (Google News)
- InnSuites Hospitality Received Notice of Noncompliance - TradingView Compliance Week (Google News)
- Winnipeg-Built AI Platform Answers the Question Regulators Now Ask: Why Did the AI Say That? - USA Today InfoSec Compliance (Google News)