Revolut confirms customer data breach through fake government requests
41–50 of 139 posts
Re: Revolut confirms customer data breach through fake government requests
#42The interesting failure here is not phishing, it is that "the email came from the real government domain" was accepted as authorization. A domain proves who sent the message, not that the sender was entitled to ask. Every compliance team I have worked with in payments had the same gap: the legal-request inbox verifies DKIM and the letterhead, then a human decides under time pressure with "law enforcement" in the subj…
I was thinking about exactly that and then I found this comment. One spoofs an email domain and then is able to get trust from a "modern global fintech"? Absolutely ridiculous. Having worked for several global scale tech companies, I've seen first hand how security is at the absolutely bottom of the list. It does not translate to $$$ so it is uncared for. Revolut keeps pestering me with requests for interviews and I…
Most requests are digitally signed PDFs that come via email, require a response sent to another email.
Re: Revolut confirms customer data breach through fake government requests
#43Here is one of the replies I got during my conversation with their agent (unsure if human or automated): "Your personal data must be held until it is permissible to erase it in accordance with the law. Rest assured, it is totally secure and only held for this purpose." This was in the same conversation where I sent them the article.
Re: Revolut confirms customer data breach through fake government requests
#44How can this happen to a modern fintech... Esp. handling identity verification so poorly? > A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to…
in 2018 they turned off basic money laundering detection
in 2019 they used job applicants as free labour to get people to sign up.
in 2023 they didn't freeze accounts they were supposed to when asked by the NCA (the uk's equivalent of the FBI, kinda)
again in 2024 they came bottom in the league table for reported fraud(action fraud). They had 10k reports, ahead of barclays, which at the time had a much large amount of active users.
Again in 2024, they also had the highest push payment fraud reports. now, this _could_ be bad controls, user incompetence, or data leak. it could be argued that they were part of the reason for the rule changes, meaning that banks are now 50/50 liable for this kind of fraud.
Either way, they have a history of being shady/incompetent/bastards. They've also only been a fully licensed bank for ~6 months.
Re: Revolut confirms customer data breach through fake government requests
#45Re: Revolut confirms customer data breach through fake government requests
#46Even if the trigger was spoofed, how come there is no secure channel that the govt provides to receive the data? Was this one also compromised?
Re: Revolut confirms customer data breach through fake government requests
#47Re: Revolut confirms customer data breach through fake government requests
#48How can this happen to a modern fintech... Esp. handling identity verification so poorly? > A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to…
Revolut has a history of being both halfarsed and shady in 2018 they turned off basic money laundering detection in 2019 they used job applicants as free labour to get people to sign up. in 2023 they didn't freeze accounts they were supposed to when asked by the NCA (the uk's equivalent of the FBI, kinda) again in 2024 they came bottom in the league table for reported fraud(action fraud). They had 10k reports, ahead…
My speculative mental model so far was: They fired the dept which was handling those "emails" and did let some agents handle it. Which backfired and seems to fit that history you presented.
Re: Revolut confirms customer data breach through fake government requests
#49Earlier quoted context omitted.
Seems like a thing you should be able to do at the post office.
What does post office have to do with identity verification?
This is used quite often for important things that don't have offices themselves.