If an email was authenticated with DKIM, you cannot really blame Revolut. The attacker would have had to compromise the government email server, making it the government's fault. However, if the email relied solely on SPF, the situation is less clear. An attacker could potentially spoof SPF by compromising any service on a server sharing the same public IP address via NAT.
Revolut confirms customer data breach through fake government requests
71–80 of 139 posts
Re: Revolut confirms customer data breach through fake government requests
#72I asked if my data was compromised, they said no, but how can I trust/verify this?
Re: Revolut confirms customer data breach through fake government requests
#73Earlier quoted context omitted.
Trying to find a way to tip toe around KYC, whilst keeping their customers safe, has also turned out to only use insanely stupid methods, though. So why did they already do that?
FYI it turns out that humans are pretty bad at comparing faces to ID documents. Like, really quite bad. Automated methods, like the ones Revolut use, are significantly more effective at KYC than a Jane Doe working a 9-5 at a bank. In no way is it “tip-toeing around KYC”, and while really unfortunate leaking a selfie is pretty low down on the list of “bad stuff a bank could leak”. The implication that the solution to…
People work with their competitors all the time (see Netfix vs Amazon). Whats ridiculuous is the claim that a scammer would prefer to show up physically at a bank and risk being exposed instead of operating remotely.
>leaking a selfie is pretty low down on the list of “bad stuff a bank could leak”.
don't some of them require a selfie while holding legible official documentation?
Re: Revolut confirms customer data breach through fake government requests
#74Earlier quoted context omitted.
You could argue that the government agency is at fault. 1 for their breach, 2 more importantly: for mandating that personal information get handed over without an official court order which would have involved a far more stringent process with multiple parties involved.
My understanding of the situation is that no government agency actually requested data at all, just that someone impersonated a government email address and this was enough for Revolut to reply with the requested data.
That's a dangerous kind of threat to be making, and to act upon. for information that should remain private let alone owned by the bank itself.
Re: Revolut confirms customer data breach through fake government requests
#75How can this happen to a modern fintech... Esp. handling identity verification so poorly? > A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to…
I've processed government requests at a FinTech before. Some are pretty good and there are bespoke channels for them so that you can be sure their genuine. Other are literally random emails you get that you are required to reply to, many of them demanding information to be sent in the clear. We always declined to reply to those even though we legally had to, we offered them to set up PGP if they wanted the data via e…
Re: Revolut confirms customer data breach through fake government requests
#76Earlier quoted context omitted.
Most banks now require selfies, try shopping around. KYC requirements get tightened all the time.
I have accounts with 2 other banks. They never asked for a selfie.
Try opening one now. Today it's hard to get a hire purchase contract as an existing custoner (already known and verified) without photos of the ID and selfie.
Re: Revolut confirms customer data breach through fake government requests
#77Re: Revolut confirms customer data breach through fake government requests
#78Earlier quoted context omitted.
Sure, but that would be like insanely stupid on pretty much every level though, so why would they do that?
For security reasons, obviously! That way they wouldn't leak selfies because they wouldn't have any.
Re: Revolut confirms customer data breach through fake government requests
#79Earlier quoted context omitted.
That's some background. Thanks. My speculative mental model so far was: They fired the dept which was handling those "emails" and did let some agents handle it. Which backfired and seems to fit that history you presented.
Revolut is also run by a Russian with deep connections to wartime Russian elites, starting with his dad, who heads the biggest Gazprom R&D center.