Live data from Hacker News

Revolut confirms customer data breach through fake government requests

techcrunch.com

41–50 of 139 posts

Re: Revolut confirms customer data breach through fake government requests

#42
post #6

The interesting failure here is not phishing, it is that "the email came from the real government domain" was accepted as authorization. A domain proves who sent the message, not that the sender was entitled to ask. Every compliance team I have worked with in payments had the same gap: the legal-request inbox verifies DKIM and the letterhead, then a human decides under time pressure with "law enforcement" in the subj…

I was thinking about exactly that and then I found this comment. One spoofs an email domain and then is able to get trust from a "modern global fintech"? Absolutely ridiculous. Having worked for several global scale tech companies, I've seen first hand how security is at the absolutely bottom of the list. It does not translate to $$$ so it is uncared for. Revolut keeps pestering me with requests for interviews and I…

In the countries you are licensed in you are legally required to reply to law enforcement requests. In most places there is no official channel for this. It is literally stuff like LE@Fintech.com. Emails come from all over and random domains that appear official-ish. Most official domains do not have DKIM or SPIF setup, very easy to spoof. LE by and large do not take security seriously, they do not take data transfer seriously.

Most requests are digitally signed PDFs that come via email, require a response sent to another email.

Re: Revolut confirms customer data breach through fake government requests

#43
post #13

Here is one of the replies I got during my conversation with their agent (unsure if human or automated): "Your personal data must be held until it is permissible to erase it in accordance with the law. Rest assured, it is totally secure and only held for this purpose." This was in the same conversation where I sent them the article.

Was it the same agent that released the data?

Re: Revolut confirms customer data breach through fake government requests

#44
post #12

How can this happen to a modern fintech... Esp. handling identity verification so poorly? > A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to…

Revolut has a history of being both halfarsed and shady

in 2018 they turned off basic money laundering detection

in 2019 they used job applicants as free labour to get people to sign up.

in 2023 they didn't freeze accounts they were supposed to when asked by the NCA (the uk's equivalent of the FBI, kinda)

again in 2024 they came bottom in the league table for reported fraud(action fraud). They had 10k reports, ahead of barclays, which at the time had a much large amount of active users.

Again in 2024, they also had the highest push payment fraud reports. now, this _could_ be bad controls, user incompetence, or data leak. it could be argued that they were part of the reason for the rule changes, meaning that banks are now 50/50 liable for this kind of fraud.

Either way, they have a history of being shady/incompetent/bastards. They've also only been a fully licensed bank for ~6 months.

Re: Revolut confirms customer data breach through fake government requests

#45
post #7

Ran an LE request desk for a while and the whole thing was PDFs from .gov-ish email addresses. Only real control we had was calling the agency back on a number we looked up ourselves, not the one on the letterhead.

What is LE? Let’s Encrypt?

Law enforcement.

Re: Revolut confirms customer data breach through fake government requests

#46
post #2

Even if the trigger was spoofed, how come there is no secure channel that the govt provides to receive the data? Was this one also compromised?

If people actually knew how much of a wild west this stuff is, a lot more would be cautious with their personal info.

Re: Revolut confirms customer data breach through fake government requests

#48
post #12

How can this happen to a modern fintech... Esp. handling identity verification so poorly? > A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to…

Revolut has a history of being both halfarsed and shady in 2018 they turned off basic money laundering detection in 2019 they used job applicants as free labour to get people to sign up. in 2023 they didn't freeze accounts they were supposed to when asked by the NCA (the uk's equivalent of the FBI, kinda) again in 2024 they came bottom in the league table for reported fraud(action fraud). They had 10k reports, ahead…

That's some background. Thanks.

My speculative mental model so far was: They fired the dept which was handling those "emails" and did let some agents handle it. Which backfired and seems to fit that history you presented.

Re: Revolut confirms customer data breach through fake government requests

#49

Earlier quoted context omitted.

Seems like a thing you should be able to do at the post office.

What does post office have to do with identity verification?

Some post offices in the US also function as a so called notary public. Basically, they can verify your identity and attest that it's you who sent/did something.

This is used quite often for important things that don't have offices themselves.

Re: Revolut confirms customer data breach through fake government requests

#50
The funny thing about Revolut is, that they send you from the same "no-reply" address your payment receipts and a ton of spam. There is no link in the spam do stop it and no obvious scheme in the header which would allow to filter the spam from the relevant mails. Good luck recognizing this breach notification as an important one...
Post reply on HN