Live data from Hacker News

Revolut confirms customer data breach through fake government requests

techcrunch.com

81–90 of 139 posts

Re: Revolut confirms customer data breach through fake government requests

#81
post #35

Ran an LE request desk for a while and the whole thing was PDFs from .gov-ish email addresses. Only real control we had was calling the agency back on a number we looked up ourselves, not the one on the letterhead.

You say .gov-ish, does this mean compromised gov email accounts, spoofed email addresses or domains that look like government domains?

You do not need to compromise anything, you can put any address in the "from" field. Email has no universal verification for sender address.

Re: Revolut confirms customer data breach through fake government requests

#82

Ran an LE request desk for a while and the whole thing was PDFs from .gov-ish email addresses. Only real control we had was calling the agency back on a number we looked up ourselves, not the one on the letterhead.

Is it uncommon/impossible to ask for the federally-brokered in-person procedure in the US? (The way I know it: Local court or police officer shows up at our office later that day and hands over a printout matching the request that we had been unable to confirm, on request of federal authority, in turn on request of the authority demanding we hand over some customers data. Those two requests utilizing government agenc…

> Those two requests utilizing government agency-internal auth mechanisms we do not need to know or care about.

Most likely:

> and the whole thing was PDFs from .gov-ish email addresses

But I guess this moves the liability for answering fake requests to the local branch.

Re: Revolut confirms customer data breach through fake government requests

#83

Ran an LE request desk for a while and the whole thing was PDFs from .gov-ish email addresses. Only real control we had was calling the agency back on a number we looked up ourselves, not the one on the letterhead.

> Only real control we had was calling the agency back on a number we looked up ourselves

Way to difficult for Revolut, evidently.

Re: Revolut confirms customer data breach through fake government requests

#84
post #12

How can this happen to a modern fintech... Esp. handling identity verification so poorly? > A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to…

It's fintech, it's all about growth, not customer care.

That's "legacy old bank stuff they will disrupt along all the regulations".

Re: Revolut confirms customer data breach through fake government requests

#85
post #12

How can this happen to a modern fintech... Esp. handling identity verification so poorly? > A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to…

Revolut has a history of being both halfarsed and shady in 2018 they turned off basic money laundering detection in 2019 they used job applicants as free labour to get people to sign up. in 2023 they didn't freeze accounts they were supposed to when asked by the NCA (the uk's equivalent of the FBI, kinda) again in 2024 they came bottom in the league table for reported fraud(action fraud). They had 10k reports, ahead…

Only one of them is directly harmful to users (the job applicant scheme). Everything else is enabling their own users to break the law only if they want to, and I think that is a good public service.

Of course it might hurt legit users by making other banks treat Revolut as suspicious but im not sure if thats enough to outweigh the positive. Data breaches and cancelation fees, on the other hand...

Re: Revolut confirms customer data breach through fake government requests

#87
post #30

Earlier quoted context omitted.

My understanding of the situation is that no government agency actually requested data at all, just that someone impersonated a government email address and this was enough for Revolut to reply with the requested data.

The government did request the data. And since the announcement, it has requested highly sensitive data again, and to keep such data, backed by threats of violent repercussions, that businesses cease to operate or to even exist. That's a dangerous kind of threat to be making, and to act upon. for information that should remain private let alone owned by the bank itself.

> The government did request the data.

What's your source?

That is not what the news says.

Also, you know you can easily impersonate any email? That's a flaw of the email protocol.

Re: Revolut confirms customer data breach through fake government requests

#88

Storing identification data (like a scanned passport) is not necessary. The question is “did you check the customer identity?” And if the answer is Yes, then you can mark it as such. You don’t need to store these scans at all.

in which country?

Re: Revolut confirms customer data breach through fake government requests

#89
post #40
post #11

I asked if my data was compromised, they said no, but how can I trust/verify this?

You can't, really. Banking legislation does not require them to tell you.

Data laws in EU mandate that a company has to tell you every single entity it has shared your data with, regardless of the sector they operate in.

What you're referring to is that a bank does not require to tell you whether your account is going through specific checks (anti laundering and such).

Re: Revolut confirms customer data breach through fake government requests

#90
I had an interesting experience with my Revolut card. I only top it up when traveling, and the rest of the time it sits nearly empty, with like $3-4. At some point I started getting occasional notifications about transactions declining. Stuff like video game points and random little online shops. Clearly my card's been skimmed or otherwise leaked somehow. Bummer.

Since Im months away from my next trip I didnt immediately cancel the card and just left it on out of curiosity. I started blocking every attempted merchant. At some point, I started getting Netflix subscription attempts, and when I tried to block it, it said "We can't block payments to Netflix. If you have a subscription with them, you can cancel it directly." Makes me wonder what kind of rube goldberg machine their backend runs on.

Post reply on HN