Live data from Hacker News

Revolut confirms customer data breach through fake government requests

techcrunch.com

111–120 of 139 posts

Re: Revolut confirms customer data breach through fake government requests

#111
post #2

Even if the trigger was spoofed, how come there is no secure channel that the govt provides to receive the data? Was this one also compromised?

If people actually knew how much of a wild west this stuff is, a lot more would be cautious with their personal info.

If you are forced to ID check with the bank via a 3rd party, the only way is to ask for removal of data after the ID check. Do you see other ways?

Re: Revolut confirms customer data breach through fake government requests

#112
post #32
post #30

Earlier quoted context omitted.

My understanding of the situation is that no government agency actually requested data at all, just that someone impersonated a government email address and this was enough for Revolut to reply with the requested data.

From the PR statement, it's unclear if a gov. agency was hacked or it was a phishing attempt, from my point of view. Both cases are still not enough, even for a greasy spoon.

If the Revolut know the agency was hacked it surely would be in their interest to say so (unless the agency hold them at "gunpoint")

Re: Revolut confirms customer data breach through fake government requests

#113
post #19

Earlier quoted context omitted.

Most banks now require selfies, try shopping around. KYC requirements get tightened all the time.

I have accounts with 2 other banks. They never asked for a selfie.

Likewise, opened a couple in the past few years and never saw this. That said, bank lobbies have tons of ambient cameras anyway, so they don't really need a selfie.

Re: Revolut confirms customer data breach through fake government requests

#114
post #85

Earlier quoted context omitted.

Revolut has a history of being both halfarsed and shady in 2018 they turned off basic money laundering detection in 2019 they used job applicants as free labour to get people to sign up. in 2023 they didn't freeze accounts they were supposed to when asked by the NCA (the uk's equivalent of the FBI, kinda) again in 2024 they came bottom in the league table for reported fraud(action fraud). They had 10k reports, ahead…

Only one of them is directly harmful to users (the job applicant scheme). Everything else is enabling their own users to break the law only if they want to , and I think that is a good public service. Of course it might hurt legit users by making other banks treat Revolut as suspicious but im not sure if thats enough to outweigh the positive. Data breaches and cancelation fees, on the other hand...

> Only one of them is directly harmful to users

You do understand what push fraud is right? One person lost ~£160k, a large chunk of it waiting for a human to answer.

also, its not like there aren't alternatives.

Re: Revolut confirms customer data breach through fake government requests

#115
post #61
post #60

Earlier quoted context omitted.

Not a bank until 2018 And they clearly figured that was easier than going through the UK where they had previously been licensed

No, they had a standard bank license, no different than any other bank operating in the country. Of course it was only valid in the EU not Britain. https://www.lb.lt/en/news/banking-licence-granted-to-revolut... edit: Comment no longer makes much sense after the one above was edited

They had an emi license before .

Re: Revolut confirms customer data breach through fake government requests

#116
post #42

Earlier quoted context omitted.

I was thinking about exactly that and then I found this comment. One spoofs an email domain and then is able to get trust from a "modern global fintech"? Absolutely ridiculous. Having worked for several global scale tech companies, I've seen first hand how security is at the absolutely bottom of the list. It does not translate to $$$ so it is uncared for. Revolut keeps pestering me with requests for interviews and I…

In the countries you are licensed in you are legally required to reply to law enforcement requests. In most places there is no official channel for this. It is literally stuff like LE@Fintech.com. Emails come from all over and random domains that appear official-ish. Most official domains do not have DKIM or SPIF setup, very easy to spoof. LE by and large do not take security seriously, they do not take data transfer…

But that's the thing, they have the money to have people chasing down the official channels of whatever email that comes from to confirm their authenticity.

Cybersecurity 101: Call back the bank at the official number and all that yada yada.

Re: Revolut confirms customer data breach through fake government requests

#117
post #61
post #60

Earlier quoted context omitted.

Not a bank until 2018 And they clearly figured that was easier than going through the UK where they had previously been licensed

No, they had a standard bank license, no different than any other bank operating in the country. Of course it was only valid in the EU not Britain. https://www.lb.lt/en/news/banking-licence-granted-to-revolut... edit: Comment no longer makes much sense after the one above was edited

my understanding is the full licences was only granted in 2021 in the eea and 2026 in the UK

Re: Revolut confirms customer data breach through fake government requests

#118

This is a reminder about what happens to people happily uploading their passport and selfies into the app. Do not do it if you do not want to end up in a Russian underground forums.

What else are you supposed to do? All bank require BYC and will ask you to control your identity. We shouldn’t blame customers for the fintech company mistakes

Some banks, I assume, allow showing the documents in person and without a selfie.

Re: Revolut confirms customer data breach through fake government requests

#120

Earlier quoted context omitted.

What else are you supposed to do? All bank require BYC and will ask you to control your identity. We shouldn’t blame customers for the fintech company mistakes

Some banks, I assume, allow showing the documents in person and without a selfie.

You assume wrong if you’re taking about old-school banks. They’ll still scan your id and it ends up in the same system
Post reply on HN