Live data from Hacker News

Evolve Bank and Trust confirms LockBit stole 7.6M people's data

theregister.com

71–80 of 83 posts

Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data

#71
post #45

Not saying that this breach is somehow connected, but all of my Wise cards(both physical and virtual) got charged($10, $100, $500) at random locations of the globe in May & June and method was manual entry. While some charges were declined initially because the expiry date was entered wrong on first try(all of my cards coincidentally have expiry date like 04/24 or similar) but cvv was always correct. To make matters…

Same, just last week on my Wise account. "Manual entry". First a 0USD "card check" was triggered, couple hours later transactions started going through. I noticed a couple days later by accident, randomly checking my balance in the app. I got no notifications from Wise app at any time. Thing is, although I have a physical Wise card, it was never used anywhere since the account was opened, so I suspected something was…

I suspect that some more data has been breached than Wise wants to disclose, but the bad practices in industry does not surprise me. It could be that the card provider for wise is at fault here and not wise directly but the fact that charges still happen and get declined due to inadequate funds without notifications for approval(which always happens for me on manual entry unless I used a vendor several times for same amount) for very random never before used vendors around the globe in short time should definitely trigger some fraud alerts.

Edit: typo

Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data

#72
post #69
post #58

Earlier quoted context omitted.

> cvv was always correct How do you know this, does Wise provide auth response data? (Merchants are not required to respect the CVV check, so it's possible for txns to go through with a non-matching CVV response code.) I'm also curious about the lack of notifications. That would seem to indicate a level of account control beyond the cardholder data. Unless they were failed due to NSF before the notification step.

> How do you know this, does Wise provide auth response data? Usually, for each transaction, wise gives a small type details, such as * manual entry: when I manually type in all details on a form * saved-detail: when I preauthorized some vendor or processor to perform txn without further interactions(think quick checkout using paypal) * apple/google pay: when card is preauthorized in such * chip and pin: means I ente…

Yep that's a classic fraud pattern. The issuing bank (Evolve?) should have flagged the card after the second or third txn attempt.

It sounds like multiple layers of risk controls failed here. I'm glad you didn't lose any funds, I'm sure others were not as fortunate/careful as you!

Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data

#75
post #45

Not saying that this breach is somehow connected, but all of my Wise cards(both physical and virtual) got charged($10, $100, $500) at random locations of the globe in May & June and method was manual entry. While some charges were declined initially because the expiry date was entered wrong on first try(all of my cards coincidentally have expiry date like 04/24 or similar) but cvv was always correct. To make matters…

Had same issue with Wise followed by same email about Evolve. I don't think Wise have discovered (or want to admit) the real scope of the issue.

Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data

#76

Earlier quoted context omitted.

Mercury itself is not FDIC insured. If Mercury collapses, your money is not insured. If Evolve collapses, your money is insured. That's the official stance. The majority of the banking industry is built on Cobol. Open Banking is the only real path forward. The issue of the US vs EU open-banking is the number of community banks. The, unfortunate, most reliable banks from a technology/data perspective are ones that are…

> Mercury itself is not FDIC insured. If Mercury collapses, your money is not insured. How is it not false advertising on the part of Mercury to describe their accounts as FDIC-insured if this is the case?

The real question for these third party services is whether each customer has a separate bank account. If there's one bank account per customer, and the third party service goes down, accessing the money probably isn't too bad. You can deal with the bank. They have regulators and obligations. If it's one consolidated account, then it probably takes a bankruptcy court to untangle the mess.

Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data

#77

Earlier quoted context omitted.

> but I'm really confused as to why they always choose the most random obscure bank. Why not partner with a major bank. Because major banks won't support startups looking to compete with them. Why would JPM, BoA, etc. service Mercury who is going after their SMB business banking vertical? Banking is a cartel in the US. The bank lobby makes it as hard as possible to compete with them.

> Banking is a cartel in the US US has more banks than any other country by a factor of 10. https://www.helgilibrary.com/charts/what-country-has-the-mos... And #4 for branches per capita: https://www.theglobaleconomy.com/rankings/bank_branches/ 7x as many branches per person as Canada Sure, those data sources are a bit sus, but I'm sure they're relatively correct. And dunno how credit unions play into it.

You're right. For the argument for the other side, the top four largest banks—JPMorgan Chase, Bank of America, Citigroup, and Wells Fargo—collectively hold approximately 43% of all deposits in the United States, and in some ways they are self regulating or have a revolving door with their regulators. But we certainly have a lot of banks and anyone can buy a small one and give the banking business a shot.

Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data

#79

Earlier quoted context omitted.

Mercury itself is not FDIC insured. If Mercury collapses, your money is not insured. If Evolve collapses, your money is insured. That's the official stance. The majority of the banking industry is built on Cobol. Open Banking is the only real path forward. The issue of the US vs EU open-banking is the number of community banks. The, unfortunate, most reliable banks from a technology/data perspective are ones that are…

> Mercury itself is not FDIC insured. If Mercury collapses, your money is not insured. How is it not false advertising on the part of Mercury to describe their accounts as FDIC-insured if this is the case?

This gets into the nuances of fintech, BaaS and neo-banking. A consumer cannot reasonably be expected to understand these. The industry and regulators have effectively stated as such. Your money is, indeed, technically FDIC insured to 250k. It is not insured against the collapse of an intermediary party such as Mercury. FDIC insurance ONLY covers the collapse of a chartered US bank.

Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data

#80
post #76

Earlier quoted context omitted.

> Mercury itself is not FDIC insured. If Mercury collapses, your money is not insured. How is it not false advertising on the part of Mercury to describe their accounts as FDIC-insured if this is the case?

The real question for these third party services is whether each customer has a separate bank account. If there's one bank account per customer, and the third party service goes down, accessing the money probably isn't too bad. You can deal with the bank. They have regulators and obligations. If it's one consolidated account, then it probably takes a bankruptcy court to untangle the mess.

Regarding FBOs, that is exactly what is happening with Synapse/Evolve. Customer funds and corporate funds were all comingled and reconciled across an inaccurate ledger held within an FBO. Whether the inaccuracies belong to the bank, or to Synapse is where the debate lies. What is also incredibly suspect in this case is that Mercury was able to transfer (IIRC) 49 million USD of money from Synapse's established FBO with Evolve to Evolve directly (under the ownership of Mercury). The ability for Mercury to have moved these funds is a massive red flag.

Regarding regulators and obligation -- in any of these relationships the bank is ultimately responsible/liable for any AML/TFL, money, etc... irregularities. A BaaS provider can effectively do everything wrong to the point its underlying bank is shut down, and switch to a different partner bank.

Post reply on HN