Skip to content
RJSA ReviewCyber Resilience

Why Hack When You Can Ask?

Rodney Jack BLFounder, RJ Strategic Advisory · 6 min read

A brass padlock fastened to an iron gate
In this article
  1. The Revolut disclosure
  2. A breach without a hack
  3. How data becomes credibility
  4. The same behavioural principle
  5. Why this matters for SMEs
  6. Verify the identity, the authority and the destination
  7. Proportionate governance
  8. For affected Revolut customers
  9. Older than cybersecurity

In nineteenth century New York, William Thompson became associated with a remarkably simple confidence trick. Rather than snatch a man’s watch, he would approach respectably dressed strangers, establish sufficient familiarity and ask whether they had enough confidence in him to lend him their watch until the following day. Some did. Thompson disappeared with the watch, and the method helped popularise the expression confidence man!

What made the scheme effective was not force, technical sophistication or concealment. Thompson succeeded because the person controlling the asset accepted the legitimacy of the request and voluntarily released it. Once confidence had been established, force became unnecessary.

Nearly two centuries later, the technology is different, the asset is different and the consequences are potentially far greater. The underlying vulnerability, however, remains strikingly familiar.

The Revolut disclosure

Revolut has confirmed that sensitive customer information was disclosed following fraudulent requests submitted through what appeared to be a legitimate government agency email domain. Its systems were not compromised and customer funds were unaffected. Notwithstanding that reassurance, the incident raises a more important question.

Why defeat the security protecting an asset if the person authorised to release it can instead be persuaded to do so?

The parallel with Thompson is therefore not merely rhetorical. In both cases, the decisive event was not the forcible taking of the asset, but its voluntary release following a request accepted as legitimate. Thompson manufactured familiarity. The modern attacker manufactured apparent authority. It follows that the vulnerability lies not merely in access to the asset itself, but in the judgment exercised by the person controlling its release.

A breach without a hack

That distinction is particularly important in data protection. A personal data breach does not require somebody to conventionally hack into a system. Article 4(12) GDPR (opens in a new tab) expressly encompasses the unauthorised disclosure of, or access to, personal data. Accordingly, information may be compromised notwithstanding that the technical perimeter itself remains intact.

More fundamentally, the incident exposes a different category of security failure. Security does not fail only when an unauthorised person gains access. It may also fail where an authorised person is induced to make the wrong decision.

How data becomes credibility

Reports concerning affected Revolut customers indicate that the information potentially disclosed included names, dates of birth, contact details, identity documents, verification selfies, account statements and transaction histories. Considered individually, some of those details may appear relatively ordinary. Considered together, however, they may provide something considerably more valuable, credibility.

That credibility is cumulative. A name may establish familiarity, a date of birth may reinforce identity, banking information may confirm the relationship, and knowledge of a genuine transaction may provide the context necessary to make a subsequent approach appear authentic. Each accurate fact may thereby strengthen the credibility of the next representation.

There is, accordingly, a material difference between an unsolicited caller who merely claims to represent your bank and one who already knows your name, address, banking information and details of a genuine transaction. The latter may commence the conversation already armed with sufficient information to appear legitimate.

A customer could be told that a genuine transaction has triggered a fraud investigation and thereafter be asked to provide a verification code, approve an action or transfer funds to a purportedly secure account. Much of what that person says may be true. The identity of the person saying it may be the only thing that is false.

The real concern is therefore not necessarily that the disclosed information provides direct access to a customer’s funds. Rather, it may be used in furtherance of a subsequent fraud by supplying the credibility necessary to persuade the customer to provide whatever is still missing.

The causal chain is relatively straightforward.

  1. Data
  2. Knowledge
  3. Credibility
  4. Trust
  5. Behaviour
Data creates knowledge, knowledge creates credibility, credibility creates trust, and trust may thereafter influence behaviour.

The same behavioural principle

That is precisely where the resemblance to Thompson becomes most instructive. He did not need to overpower the owner of the watch. He needed to alter the owner’s perception of the person making the request. Once the request appeared legitimate, the decision changed and possession was voluntarily surrendered.

The modern social engineer operates on the same behavioural principle. The attacker may not need to defeat the security surrounding an asset if they can instead influence the judgment of the person authorised to release it.

Why this matters for SMEs

For SMEs, that distinction is critical. Smaller organisations often operate effectively because communication is direct, decisions are made quickly and staff rely heavily upon established relationships. Those characteristics are commercially valuable, however, they may also become vulnerabilities where somebody successfully assumes the appearance of a trusted party.

Traditional cyber awareness training properly teaches staff to identify suspicious links, misspelled domains and unusual email addresses. The more difficult problem arises where those warning signs are absent. What happens where the domain appears legitimate, the request is plausible and the person requesting the information appears to possess the necessary authority?

In such circumstances, procedural familiarity is not enough. The apparent authenticity of a communication does not, without more, establish the identity of the person making the request, their authority to make it or their entitlement to receive the information sought.

Verify the identity, the authority and the destination

This gives rise to a simple governance principle. Verify the identity, verify the authority and verify the destination.

Verify the identity

The identity of the person making the request.

Verify the authority

Their authority to make it.

Verify the destination

Their entitlement to receive the information sought.

Where sensitive personal information is requested by somebody purporting to represent a bank, solicitor, accountant, insurer, regulator or public authority, the request should, where appropriate and proportionate to the risk, be independently verified through a separate trusted channel. That may involve locating the organisation’s contact details independently, telephoning the relevant office and confirming both that the request was made and that the person identified has authority to make it.

The same principle applies where significant funds are being transferred. Particularly where payment instructions have changed, the transaction should not ordinarily depend upon one employee relying upon one communication. A second person should independently verify the intended recipient and, where appropriate, confirm the relevant details using contact information already known to be genuine.

The reasoning is straightforward. Where the original communication may itself be compromised, verification through that same communication may merely perpetuate the original vulnerability.

Proportionate governance

For SMEs, this need not require expensive technology. It requires proportionate governance:

  • Identifying which categories of data require enhanced verification.
  • Determining who may authorise disclosure.
  • Requiring second person checks in higher risk circumstances.
  • Establishing when reverse verification must take place before information or funds are released.

Technical security protects access to the asset. Good governance must also protect the decision to release it.

For affected Revolut customers

Affected Revolut customers may also wish to establish precisely what information concerning them was disclosed. Under Article 15 GDPR (opens in a new tab), a data subject may seek access to personal data concerning them together with specified information regarding its processing, including information relating to recipients. Accordingly, an affected customer may consider making a targeted access request seeking confirmation of what personal data were disclosed, when disclosure occurred and, where the recipient can be identified, to whom those data were disclosed. Such a request should not, however, be confused with a general entitlement to Revolut’s complete internal investigation.

Older than cybersecurity

The broader lesson is therefore older than cybersecurity itself. Fraud has always depended upon the relationship between information, credibility and human judgment. Technology changes the means by which legitimacy is manufactured, it does not remove the human decision which ultimately determines whether an asset is released.

William Thompson persuaded the owner of a watch that his request was legitimate. The modern attacker may seek to do the same with personal data and thereafter use that information to make the next request considerably more convincing.

Why hack when you can ask?

Key points

  • A personal data breach does not require somebody to conventionally hack into a system.
  • Security does not fail only when an unauthorised person gains access. It may also fail where an authorised person is induced to make the wrong decision.
  • Verify the identity, verify the authority and verify the destination.
Portrait of Rodney Jack BL

Rodney Jack BL

Founder, RJ Strategic Advisory

Rodney's background in law, business, cyber-risk and compliance informs RJSA's approach to governance, data risk, communications and crisis response. About the founder

RJ Strategic Advisory, Cyber Security Risk, Governance and Compliance

Content published on RJSA Review is for general information and commentary only. It does not constitute legal, regulatory, financial, HR, cyber-security or other professional advice.

RJSA Review

More from Rodney Jack BL

View all insights
Strategic Positioning

Agility Is an SME’s Leverage

SMEs frequently compete in circumstances of structural disadvantage. It is tempting to assume that scale determines outcome. History suggests otherwise.

Read article
Reputation and Crisis

The Economics of Perception

A solution may be entirely effective in resolving the immediate difficulty and, nevertheless, create consequences elsewhere in the business.

Read article
Contact

High-stakes decisions require clear advice.

Speak with RJ Strategic Advisory about the situation you are managing or the risks you need to prepare for.