Live data from Hacker News

Revolut confirms customer data breach through fake government requests

techcrunch.com

51–60 of 139 posts

Re: Revolut confirms customer data breach through fake government requests

#51
post #12

How can this happen to a modern fintech... Esp. handling identity verification so poorly? > A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to…

Revolut has a history of being both halfarsed and shady in 2018 they turned off basic money laundering detection in 2019 they used job applicants as free labour to get people to sign up. in 2023 they didn't freeze accounts they were supposed to when asked by the NCA (the uk's equivalent of the FBI, kinda) again in 2024 they came bottom in the league table for reported fraud(action fraud). They had 10k reports, ahead…

> been a fully licensed bank for ~6 months

They had an EU license in Lithuania for years.

Re: Revolut confirms customer data breach through fake government requests

#52
post #20

Earlier quoted context omitted.

But they are verifying customers in person with account creation, this is an online bank

> But they are verifying customers in person with account creation, this is an online bank Revolut could do the same as they do with ATMs: make a partnership with local banks for the verification step.

Sure, but that would be like insanely stupid on pretty much every level though, so why would they do that?

Re: Revolut confirms customer data breach through fake government requests

#53
post #48

Earlier quoted context omitted.

Revolut has a history of being both halfarsed and shady in 2018 they turned off basic money laundering detection in 2019 they used job applicants as free labour to get people to sign up. in 2023 they didn't freeze accounts they were supposed to when asked by the NCA (the uk's equivalent of the FBI, kinda) again in 2024 they came bottom in the league table for reported fraud(action fraud). They had 10k reports, ahead…

That's some background. Thanks. My speculative mental model so far was: They fired the dept which was handling those "emails" and did let some agents handle it. Which backfired and seems to fit that history you presented.

Revolut is also run by a Russian with deep connections to wartime Russian elites, starting with his dad, who heads the biggest Gazprom R&D center.

Re: Revolut confirms customer data breach through fake government requests

#54
post #40
post #11

I asked if my data was compromised, they said no, but how can I trust/verify this?

You can't, really. Banking legislation does not require them to tell you.

Banking legislation in the UK does require them to tell you for this kind of breach.

Re: Revolut confirms customer data breach through fake government requests

#55
post #39

Earlier quoted context omitted.

I am almost sure they don't and instead they query selfies and documents on-demand from their KYC provider.

Yep, the KYC provider keeps them.

Could they be put in what bitcoin people call "cold storage"? I can't imagine they're used every day.

Re: Revolut confirms customer data breach through fake government requests

#56
post #52
post #20

Earlier quoted context omitted.

> But they are verifying customers in person with account creation, this is an online bank Revolut could do the same as they do with ATMs: make a partnership with local banks for the verification step.

Sure, but that would be like insanely stupid on pretty much every level though, so why would they do that?

For security reasons, obviously! That way they wouldn't leak selfies because they wouldn't have any.

Re: Revolut confirms customer data breach through fake government requests

#57
post #7

Ran an LE request desk for a while and the whole thing was PDFs from .gov-ish email addresses. Only real control we had was calling the agency back on a number we looked up ourselves, not the one on the letterhead.

What is LE? Let’s Encrypt?

Swing and a miss.

Re: Revolut confirms customer data breach through fake government requests

#58

Ran an LE request desk for a while and the whole thing was PDFs from .gov-ish email addresses. Only real control we had was calling the agency back on a number we looked up ourselves, not the one on the letterhead.

Is it uncommon/impossible to ask for the federally-brokered in-person procedure in the US?

(The way I know it: Local court or police officer shows up at our office later that day and hands over a printout matching the request that we had been unable to confirm, on request of federal authority, in turn on request of the authority demanding we hand over some customers data. Those two requests utilizing government agency-internal auth mechanisms we do not need to know or care about.)

Re: Revolut confirms customer data breach through fake government requests

#59
post #7

Ran an LE request desk for a while and the whole thing was PDFs from .gov-ish email addresses. Only real control we had was calling the agency back on a number we looked up ourselves, not the one on the letterhead.

What is LE? Let’s Encrypt?

how would you come to that conclusion based on the context here?

Re: Revolut confirms customer data breach through fake government requests

#60
post #51

Earlier quoted context omitted.

Revolut has a history of being both halfarsed and shady in 2018 they turned off basic money laundering detection in 2019 they used job applicants as free labour to get people to sign up. in 2023 they didn't freeze accounts they were supposed to when asked by the NCA (the uk's equivalent of the FBI, kinda) again in 2024 they came bottom in the league table for reported fraud(action fraud). They had 10k reports, ahead…

> been a fully licensed bank for ~6 months They had an EU license in Lithuania for years.

Not a bank until 2018

And they clearly figured that was easier than going through the UK where they had previously been licensed

Post reply on HN