Live data from Hacker News

Revolut confirms customer data breach through fake government requests

techcrunch.com

21–30 of 139 posts

Re: Revolut confirms customer data breach through fake government requests

#21
post #10

Earlier quoted context omitted.

Other banks do not require selfies, so there are other options

But they are verifying customers in person with account creation, this is an online bank

Seems like a thing you should be able to do at the post office.

Re: Revolut confirms customer data breach through fake government requests

#22
post #12

How can this happen to a modern fintech... Esp. handling identity verification so poorly? > A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to…

This can happen with modern fintech because of greed. There's a reason they can offer such cheap services. The customer takes a risk in return. Now that risk has materialized.

Re: Revolut confirms customer data breach through fake government requests

#23
post #14
post #10

Earlier quoted context omitted.

Other banks do not require selfies, so there are other options

This is a 100% online bank account you typically open from an app. The typical clientele will just use the "selfie" auth.

The issue is that there is no alternative to the "selfie" auth in case of Revolut.

Re: Revolut confirms customer data breach through fake government requests

#24
post #12

How can this happen to a modern fintech... Esp. handling identity verification so poorly? > A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to…

You could argue that the government agency is at fault. 1 for their breach, 2 more importantly: for mandating that personal information get handed over without an official court order which would have involved a far more stringent process with multiple parties involved.

Re: Revolut confirms customer data breach through fake government requests

#25

> The data may have also included verification selfies Why do they even keep those?

I am almost sure they don't and instead they query selfies and documents on-demand from their KYC provider.

[flagged]

Re: Revolut confirms customer data breach through fake government requests

#26

Earlier quoted context omitted.

But they are verifying customers in person with account creation, this is an online bank

Seems like a thing you should be able to do at the post office.

What does post office have to do with identity verification?

Re: Revolut confirms customer data breach through fake government requests

#27
post #6

The interesting failure here is not phishing, it is that "the email came from the real government domain" was accepted as authorization. A domain proves who sent the message, not that the sender was entitled to ask. Every compliance team I have worked with in payments had the same gap: the legal-request inbox verifies DKIM and the letterhead, then a human decides under time pressure with "law enforcement" in the subj…

I was thinking about exactly that and then I found this comment.

One spoofs an email domain and then is able to get trust from a "modern global fintech"? Absolutely ridiculous. Having worked for several global scale tech companies, I've seen first hand how security is at the absolutely bottom of the list. It does not translate to $$$ so it is uncared for.

Revolut keeps pestering me with requests for interviews and I keep running away from it. One more con (pun intended) to the list.

Re: Revolut confirms customer data breach through fake government requests

#28

Earlier quoted context omitted.

Seems like a thing you should be able to do at the post office.

What does post office have to do with identity verification?

In the USA they already take passport photos. Being able to receive mail addressed to a name is the closest thing to a national ID the USA has. They're already depended on for identity verification quite a lot.

Re: Revolut confirms customer data breach through fake government requests

#29
post #6

The interesting failure here is not phishing, it is that "the email came from the real government domain" was accepted as authorization. A domain proves who sent the message, not that the sender was entitled to ask. Every compliance team I have worked with in payments had the same gap: the legal-request inbox verifies DKIM and the letterhead, then a human decides under time pressure with "law enforcement" in the subj…

I was thinking about exactly that and then I found this comment. One spoofs an email domain and then is able to get trust from a "modern global fintech"? Absolutely ridiculous. Having worked for several global scale tech companies, I've seen first hand how security is at the absolutely bottom of the list. It does not translate to $$$ so it is uncared for. Revolut keeps pestering me with requests for interviews and I…

They also pay peanuts, and the culture is toxic.

Re: Revolut confirms customer data breach through fake government requests

#30
post #12

How can this happen to a modern fintech... Esp. handling identity verification so poorly? > A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to…

You could argue that the government agency is at fault. 1 for their breach, 2 more importantly: for mandating that personal information get handed over without an official court order which would have involved a far more stringent process with multiple parties involved.

My understanding of the situation is that no government agency actually requested data at all, just that someone impersonated a government email address and this was enough for Revolut to reply with the requested data.
Post reply on HN