Live data from Hacker News

Revolut confirms customer data breach through fake government requests

techcrunch.com

31–40 of 139 posts

Re: Revolut confirms customer data breach through fake government requests

#31
post #22
post #12

How can this happen to a modern fintech... Esp. handling identity verification so poorly? > A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to…

This can happen with modern fintech because of greed. There's a reason they can offer such cheap services. The customer takes a risk in return. Now that risk has materialized.

I see your point about greed. Thanks. Let me still contrast that: GPT6 has 99.9 in ARC-AGI 3 and multiple bug-bounty programs closed due to the sheer amount of automated attacks and reports.

And they are "FinTech". "Oh, that email looks legit, let's just hand out the data.", like they have never witnessed phishing from the old days... am curious about the story here. That PR-spokesperson is more than damaging...

Re: Revolut confirms customer data breach through fake government requests

#32
post #30

Earlier quoted context omitted.

You could argue that the government agency is at fault. 1 for their breach, 2 more importantly: for mandating that personal information get handed over without an official court order which would have involved a far more stringent process with multiple parties involved.

My understanding of the situation is that no government agency actually requested data at all, just that someone impersonated a government email address and this was enough for Revolut to reply with the requested data.

From the PR statement, it's unclear if a gov. agency was hacked or it was a phishing attempt, from my point of view. Both cases are still not enough, even for a greasy spoon.

Re: Revolut confirms customer data breach through fake government requests

#33
post #30

Earlier quoted context omitted.

You could argue that the government agency is at fault. 1 for their breach, 2 more importantly: for mandating that personal information get handed over without an official court order which would have involved a far more stringent process with multiple parties involved.

My understanding of the situation is that no government agency actually requested data at all, just that someone impersonated a government email address and this was enough for Revolut to reply with the requested data.

[flagged]

Re: Revolut confirms customer data breach through fake government requests

#34
post #22
post #12

How can this happen to a modern fintech... Esp. handling identity verification so poorly? > A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to…

This can happen with modern fintech because of greed. There's a reason they can offer such cheap services. The customer takes a risk in return. Now that risk has materialized.

Yes, because it's _only_ "modern fintech" that are susceptible to social engineering, right?

Oh.. https://edition.cnn.com/2024/02/04/asia/deepfake-cfo-scam-ho...

Re: Revolut confirms customer data breach through fake government requests

#35

Ran an LE request desk for a while and the whole thing was PDFs from .gov-ish email addresses. Only real control we had was calling the agency back on a number we looked up ourselves, not the one on the letterhead.

You say .gov-ish, does this mean compromised gov email accounts, spoofed email addresses or domains that look like government domains?

Re: Revolut confirms customer data breach through fake government requests

#36
post #12

How can this happen to a modern fintech... Esp. handling identity verification so poorly? > A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to…

I've processed government requests at a FinTech before. Some are pretty good and there are bespoke channels for them so that you can be sure their genuine. Other are literally random emails you get that you are required to reply to, many of them demanding information to be sent in the clear. We always declined to reply to those even though we legally had to, we offered them to set up PGP if they wanted the data via email, or we offered other secure mechanisms for them. Most of these (who I know were from real agencies) stopped asking for the data once we stood firm that we could only deliver it over an encrypted channel.

Note: This is now 5+ years ago so things have probably changed since then.

I am not surprised at all that fake requests receive real responses, happens probably way more than anyone thinks.

Re: Revolut confirms customer data breach through fake government requests

#37
post #35

Ran an LE request desk for a while and the whole thing was PDFs from .gov-ish email addresses. Only real control we had was calling the agency back on a number we looked up ourselves, not the one on the letterhead.

You say .gov-ish, does this mean compromised gov email accounts, spoofed email addresses or domains that look like government domains?

.gov is a US thing, and not even all US agencies use .gov ending emails.

Re: Revolut confirms customer data breach through fake government requests

#38

Ran an LE request desk for a while and the whole thing was PDFs from .gov-ish email addresses. Only real control we had was calling the agency back on a number we looked up ourselves, not the one on the letterhead.

I've done that as well and this is what most of those do look like.

Re: Revolut confirms customer data breach through fake government requests

#39

> The data may have also included verification selfies Why do they even keep those?

I am almost sure they don't and instead they query selfies and documents on-demand from their KYC provider.

Yep, the KYC provider keeps them.
Post reply on HN