Revolut confirms customer data breach through fake government requests
1–10 of 139 posts
Re: Revolut confirms customer data breach through fake government requests
#2Even if the trigger was spoofed, how come there is no secure channel that the govt provides to receive the data? Was this one also compromised?
Re: Revolut confirms customer data breach through fake government requests
#3> The data may have also included verification selfies
Why do they even keep those?
Re: Revolut confirms customer data breach through fake government requests
#4> The data may have also included verification selfies Why do they even keep those?
CYA in case of litigation.
Re: Revolut confirms customer data breach through fake government requests
#5Ran an LE request desk for a while and the whole thing was PDFs from .gov-ish email addresses. Only real control we had was calling the agency back on a number we looked up ourselves, not the one on the letterhead.
Re: Revolut confirms customer data breach through fake government requests
#6The interesting failure here is not phishing, it is that "the email came from the real government domain" was accepted as authorization. A domain proves who sent the message, not that the sender was entitled to ask. Every compliance team I have worked with in payments had the same gap: the legal-request inbox verifies DKIM and the letterhead, then a human decides under time pressure with "law enforcement" in the subject line. What actually works is boring: a published list of the exact channels each authority uses, a callback to a number you looked up yourself rather than one in the email, a required case reference you can verify with the agency, and a hard rule that emergency requests get a minimal data set, never full KYC packages plus transaction history. The part that should worry Revolut customers more than the passport scans is the Bitcoin history: on-chain that data is permanent, so a leaked address-to-identity mapping does not expire.
Re: Revolut confirms customer data breach through fake government requests
#7Ran an LE request desk for a while and the whole thing was PDFs from .gov-ish email addresses. Only real control we had was calling the agency back on a number we looked up ourselves, not the one on the letterhead.
What is LE? Let’s Encrypt?
Re: Revolut confirms customer data breach through fake government requests
#8Re: Revolut confirms customer data breach through fake government requests
#9> The data may have also included verification selfies Why do they even keep those?
Around banking it's usually because they have to