Revolut confirms customer data breach through fake government requests
91–100 of 139 posts
Re: Revolut confirms customer data breach through fake government requests
#92Earlier quoted context omitted.
FYI it turns out that humans are pretty bad at comparing faces to ID documents. Like, really quite bad. Automated methods, like the ones Revolut use, are significantly more effective at KYC than a Jane Doe working a 9-5 at a bank. In no way is it “tip-toeing around KYC”, and while really unfortunate leaking a selfie is pretty low down on the list of “bad stuff a bank could leak”. The implication that the solution to…
>The implication that the solution to this is to somehow convince your direct competitors to do inferior in-person KYC for you is the most ridiculous thing. People work with their competitors all the time (see Netfix vs Amazon). Whats ridiculuous is the claim that a scammer would prefer to show up physically at a bank and risk being exposed instead of operating remotely. >leaking a selfie is pretty low down on the li…
> Whats ridiculuous is the claim that a scammer would prefer to show up physically at a bank and risk being exposed instead of operating remotely.
Of course they wouldn’t prefer to show physically. What does that mean though? Are you saying no scammers showed up physically to banks, therefore banking fraud rates are less? Do you have a source for that?
> don't some of them require a selfie while holding legible official documentation?
You can of course do KYC as stupidly as you like (zoom calls anyone?) - Revolut (and their providers) obviously separate document presentation from the liveness check (and fyi this is a short video, not a selfie. The selfie they are talking about is just a capture from the video)
Re: Revolut confirms customer data breach through fake government requests
#93I had an interesting experience with my Revolut card. I only top it up when traveling, and the rest of the time it sits nearly empty, with like $3-4. At some point I started getting occasional notifications about transactions declining. Stuff like video game points and random little online shops. Clearly my card's been skimmed or otherwise leaked somehow. Bummer. Since Im months away from my next trip I didnt immedia…
Re: Revolut confirms customer data breach through fake government requests
#94Re: Revolut confirms customer data breach through fake government requests
#95How can this happen to a modern fintech... Esp. handling identity verification so poorly? > A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to…
It’s a modern fintech that’s most likely to be vulnerable. Banks tend to have a long history (either themselves or with the infrastructure they buy) of security, from physical to electronic. It’s what makes them often so clunky…there’s little incentive to streamline too much, and their insurance providers are reluctant to insure anything excitingly new.
Hell, banking is so conservative that their language is frozen in 14th century Italian from when banks were personally owned by rich families: the words “debit” (“give”) and “credit” (“take”) are from the bank owner’s perspective, not the customers’. But you tend not to see the kinds of breaches you see in modern fintech.
But, you know, move fast and break things, right?
Re: Revolut confirms customer data breach through fake government requests
#96Earlier quoted context omitted.
What does post office have to do with identity verification?
In the USA they already take passport photos. Being able to receive mail addressed to a name is the closest thing to a national ID the USA has. They're already depended on for identity verification quite a lot.
Re: Revolut confirms customer data breach through fake government requests
#97Here is one of the replies I got during my conversation with their agent (unsure if human or automated): "Your personal data must be held until it is permissible to erase it in accordance with the law. Rest assured, it is totally secure and only held for this purpose." This was in the same conversation where I sent them the article.
My dialogue: > Hi, me affected by your breach? Them: > "I have checked our records and can confirm that you have not received any notifications or communications regarding any security incidents or data breaches in the past 30 days. > We take your privacy extremely seriously. All data transmissions between our mobile apps, servers, and third parties are fully encrypted, and your personal information is stored in secu…
Re: Revolut confirms customer data breach through fake government requests
#98Earlier quoted context omitted.
I was thinking about exactly that and then I found this comment. One spoofs an email domain and then is able to get trust from a "modern global fintech"? Absolutely ridiculous. Having worked for several global scale tech companies, I've seen first hand how security is at the absolutely bottom of the list. It does not translate to $$$ so it is uncared for. Revolut keeps pestering me with requests for interviews and I…
In the countries you are licensed in you are legally required to reply to law enforcement requests. In most places there is no official channel for this. It is literally stuff like LE@Fintech.com. Emails come from all over and random domains that appear official-ish. Most official domains do not have DKIM or SPIF setup, very easy to spoof. LE by and large do not take security seriously, they do not take data transfer…
Revolut are known to be a bit shady but in this case they're damned if they do and damned if they don't
Re: Revolut confirms customer data breach through fake government requests
#99Earlier quoted context omitted.
You say .gov-ish, does this mean compromised gov email accounts, spoofed email addresses or domains that look like government domains?
You do not need to compromise anything, you can put any address in the "from" field. Email has no universal verification for sender address.
Re: Revolut confirms customer data breach through fake government requests
#100Ran an LE request desk for a while and the whole thing was PDFs from .gov-ish email addresses. Only real control we had was calling the agency back on a number we looked up ourselves, not the one on the letterhead.
Is it uncommon/impossible to ask for the federally-brokered in-person procedure in the US? (The way I know it: Local court or police officer shows up at our office later that day and hands over a printout matching the request that we had been unable to confirm, on request of federal authority, in turn on request of the authority demanding we hand over some customers data. Those two requests utilizing government agenc…