Can Better Verification Prevent Breaches Like Revolut?

Dominic Jainy stands at the forefront of modern cybersecurity, bridging the gap between cutting-edge technological defenses and the often-overlooked human element of organizational governance. As an expert in artificial intelligence, machine learning, and blockchain, Jainy has spent years observing how threat actors adapt to technical hurdles by targeting the psychological vulnerabilities of trust and authority. His perspective is particularly vital in 2026, as deepfakes and compromised administrative channels have become the primary entry points for sophisticated breaches. Today, he joins us to analyze why even the most robust technical controls fail when employees are conditioned to trust a legitimate email domain over a rigorous verification process.

Our conversation centers on the structural weaknesses inherent in data release protocols, particularly the dangerous conflation of authentication and authorization. We explore the “loading dock” phenomenon, where sensitive customer information exits organizations through unmonitored compliance channels, and why these flows require the same risk-scoring discipline as multimillion-dollar financial transactions. Jainy also breaks down the shift toward “multifactor authenticity,” a strategy designed to counter the rise of AI-driven impersonation by moving beyond simple domain-based trust. He provides actionable insights for security leaders to empower their teams to slow down, verify out-of-band, and implement strict governance to protect the most sensitive customer assets.

When a request for sensitive customer data arrives from a legitimate, verified government email domain, why is it that traditional technical controls often fail to prevent a catastrophic breach?

The failure happens because most organizations have perfected the “front door” security—the firewalls and the logins—but they have completely neglected the “loading dock.” In the Revolut incident, the technical controls worked exactly as intended; the email passed every authentication check because it truly did come from a compromised Italian government domain. The problem is that the staff conflated technical authentication with actual administrative authorization, leading them to hand over the private details of nearly 700 individuals, including crypto transaction records and home addresses. This is a visceral challenge for any team because a request from law enforcement arrives with a psychological expectation of speed and total compliance. When an employee sees a @gov.it address, they often feel that questioning the request might put their own job at risk or lead to legal repercussions for the company. We need to shift the culture so that “deny by default” is the standard response, even for authoritative domains, until a second, independent channel confirms the request is genuine.

In the context of recent attacks, how does the impact of losing identity documents and banking information compare to more traditional financial crimes like wire fraud?

We have to understand that the stakes of a data leak are fundamentally different and, in many ways, much more permanent than a simple theft of funds. As some of the sharpest minds in the field have pointed out, you can reverse a wire transfer or recover from a fraudulent $25 million loss over time, but you simply cannot “unleak” a passport or a customer’s ID document. Once a threat actor like the one using the pseudonym IAmNotAVillain gets their hands on names, banking info, and cryptocurrency transaction records, that data becomes a permanent weapon for future crimes. The attacker in this case even threatened to sell the data to other criminals if a $3 million ransom wasn’t paid, which creates a compounding cycle of risk for the victims. For the affected customers, this is an invasive, sensory violation of their privacy that persists long after the initial breach is closed. This is why our internal governance must treat a request for 700 records with more scrutiny than a six-figure wire transfer; the latter is a financial hit, but the former is a total loss of institutional trust.

With AI-driven deepfakes now capable of impersonating high-level executives in real-time video calls, how should organizations adapt their verification processes to ensure “multifactor authenticity”?

The era of trusting your eyes and ears is effectively over, as we saw with the finance professional who was tricked into wiring $25 million after a Zoom call with what appeared to be his CFO and colleagues. To counter this, we need to move toward multifactor authenticity checks that are baked into the very fabric of how sensitive data is handled. This means that an email or even a video call is never enough on its own; we must demand out-of-band proof through a separate, trusted channel. For example, if a request comes through a government portal or email, the protocol must require a return call to a publicly listed agency number found in an independent directory, not a number provided in the email signature. By requiring this extra layer of verification, we create a buffer that neutralizes the “urgency” tactic used by attackers. It forces a moment of friction where the employee must step outside the attacker’s controlled environment to find independent confirmation of the request’s legitimacy.

What specific steps can a Chief Information Security Officer take this week to identify and close the “loading dock” security gaps within their own compliance and legal teams?

The first step is to physically walk through the process with the people who actually fulfill these government and law enforcement data requests. You will likely find that these teams are operating out of a shared inbox with almost no oversight from the Security Operations Center (SOC). You must implement a mandatory second approver for any request that involves full account histories or identity documents, ensuring that no single person can make that call in a vacuum. It is also critical to set up a process to log every single official data request so the SOC can review them for anomalies, such as an unusual targeting of high-net-worth profiles or sudden deviations from standard legal formatting. Furthermore, I recommend pulling mail logs to review the context of past interactions; if a request comes from a domain that has never contacted you before, it should be treated with extreme caution. Finally, you must write down exactly who owns the decision-making process at 2:00 a.m. on a Friday, so that a junior employee isn’t left alone to handle a high-pressure, fraudulent demand.

How can the risk-scoring discipline used in financial transactions be applied to administrative and emergency data requests to prevent human error?

We need to start treating an incoming data request as a high-risk transaction that requires a score based on several variables. Arpit Mittal from PayPal has advocated for this “risk-scoring discipline,” where we flag anomalies like sudden urgency or atypical requests for crypto-associated profiles. If a request for information doesn’t follow the standard, expected legal formatting that the team is used to seeing, the risk score should skyrocket, triggering an automatic hold. This approach moves the responsibility away from the employee’s “gut feeling” and places it into a structured framework where data is only released once certain criteria are met. We should also run tabletop exercises that simulate these authoritative-looking requests, allowing the team to practice the “deny by default” response in a safe environment. By treating data as our most valuable currency, we can ensure that we aren’t just locking the front door while the loading dock remains wide open for anyone with a compromised government email address.

What is your forecast for the evolution of data release security as we move into 2027?

As we move through 2026 and into 2027, the reliance on email for sensitive data exchanges will likely become a relic of the past because it is simply too easy to spoof or compromise. I expect to see the widespread adoption of hardened, authenticated portals where every interaction is cryptographically signed and verified, removing the ambiguity of a “legitimate-looking” email domain. Organizations will shift their focus from simple awareness training to rigid, proof-based workflows that require zero-trust verification for every single outbound data flow. We will see a rise in regulatory requirements that mandate two-person integrity for PII transfers, similar to how the military handles nuclear launch codes. Ultimately, the companies that survive this era will be those that prioritize the “authenticity” of the request over the “authority” of the sender, ensuring that no amount of AI-driven deception can bypass their human and technical safeguards.

Explore more

How Can Content Repurposing Maximize Lead Generation?

Successful marketing campaigns today rely less on the volume of original concepts and more on the surgical precision of how a single idea is fractured and distributed across the digital ecosystem. When businesses move beyond the limitation of single-channel thinking, they unlock the ability to engage audiences across varying psychological touchpoints without the need for constant invention. This transition is

How to Boost Revenue and Loyalty With Gift Card Emails

A customer opens their inbox to find a digital envelope waiting with a balance specifically designated for their next purchase, instantly transforming a mundane morning into a moment of unexpected retail potential. This interaction represents a departure from the traditional promotional noise that defines modern commerce. While standard marketing often demands a sacrifice of time or attention in exchange for

How to Add Critical Context to Your Marketing Automation

The mechanical precision of a perfectly timed email often masks a fundamental lack of awareness that makes even the most advanced brand seem startlingly forgetful to the modern consumer. In the current landscape of 2026, the technical success of a marketing trigger no longer guarantees a positive customer experience; in fact, it can often achieve the opposite. When a system

How Will Maersk and Shipstore Reshape E-Commerce Logistics?

High-volume shippers are often buried under a mountain of disparate software platforms that make simple tasks feel like a marathon of manual data entry while trying to maintain operational efficiency. In the high-stakes world of e-commerce, the distance between a “buy” click and a front porch is often cluttered by a dozen different software platforms and disconnected carrier networks. For

China Expands Industrial Cross-Border E-Commerce Sector

The high-pitched whine of a tunnel drilling machine operating in the rugged terrain of Kazakhstan now traces its origin to a single digital transaction initiated thousands of miles away in Chongqing. This moment signifies a monumental pivot in the global trade architecture, where massive industrial equipment is no longer confined to the dusty catalogs of middleman distributors or the biennial