Live data from Hacker News

Revolut confirms customer data breach through fake government requests

techcrunch.com

61–70 of 139 posts

Re: Revolut confirms customer data breach through fake government requests

#61
post #60
post #51

Earlier quoted context omitted.

> been a fully licensed bank for ~6 months They had an EU license in Lithuania for years.

Not a bank until 2018 And they clearly figured that was easier than going through the UK where they had previously been licensed

No, they had a standard bank license, no different than any other bank operating in the country. Of course it was only valid in the EU not Britain.

https://www.lb.lt/en/news/banking-licence-granted-to-revolut...

edit: Comment no longer makes much sense after the one above was edited

Re: Revolut confirms customer data breach through fake government requests

#63
post #6

The interesting failure here is not phishing, it is that "the email came from the real government domain" was accepted as authorization. A domain proves who sent the message, not that the sender was entitled to ask. Every compliance team I have worked with in payments had the same gap: the legal-request inbox verifies DKIM and the letterhead, then a human decides under time pressure with "law enforcement" in the subj…

Thx claude

Re: Revolut confirms customer data breach through fake government requests

#64
post #54
post #40

Earlier quoted context omitted.

You can't, really. Banking legislation does not require them to tell you.

Banking legislation in the UK does require them to tell you for this kind of breach.

Breach yes, but if they cannot 100% sure identify if your data was given out falsily, then they cannot say. They're not allowed to disclose that they provide your information to LE. So they can only inform you directly if they're 100% sure the specific information request response was sent to false entity. This is very hard to do.

Re: Revolut confirms customer data breach through fake government requests

#65
post #39

Earlier quoted context omitted.

Yep, the KYC provider keeps them.

Could they be put in what bitcoin people call "cold storage"? I can't imagine they're used every day.

They're used pretty often, so not really. The KYC providers anyway wouldn't code anything like that.

Re: Revolut confirms customer data breach through fake government requests

#66
post #52
post #20

Earlier quoted context omitted.

> But they are verifying customers in person with account creation, this is an online bank Revolut could do the same as they do with ATMs: make a partnership with local banks for the verification step.

Sure, but that would be like insanely stupid on pretty much every level though, so why would they do that?

Trying to find a way to tip toe around KYC, whilst keeping their customers safe, has also turned out to only use insanely stupid methods, though. So why did they already do that?

Re: Revolut confirms customer data breach through fake government requests

#68
post #66
post #52

Earlier quoted context omitted.

Sure, but that would be like insanely stupid on pretty much every level though, so why would they do that?

Trying to find a way to tip toe around KYC, whilst keeping their customers safe, has also turned out to only use insanely stupid methods, though. So why did they already do that?

FYI it turns out that humans are pretty bad at comparing faces to ID documents. Like, really quite bad.

Automated methods, like the ones Revolut use, are significantly more effective at KYC than a Jane Doe working a 9-5 at a bank. In no way is it “tip-toeing around KYC”, and while really unfortunate leaking a selfie is pretty low down on the list of “bad stuff a bank could leak”.

The implication that the solution to this is to somehow convince your direct competitors to do inferior in-person KYC for you is the most ridiculous thing.

Re: Revolut confirms customer data breach through fake government requests

#69
If an email was authenticated with DKIM, you cannot really blame Revolut. The attacker would have had to compromise the government email server, making it the government's fault.

However, if the email relied solely on SPF, the situation is less clear. An attacker could potentially spoof SPF by compromising any service on a server sharing the same public IP address via NAT.

Re: Revolut confirms customer data breach through fake government requests

#70
post #2

Even if the trigger was spoofed, how come there is no secure channel that the govt provides to receive the data? Was this one also compromised?

That may not matter that much, as even if you run a relatively strict policy about where you send the reply, you can still easily get bitten by external mistakes there: Because of the huge number of individually administered departments that might each become authorized recipient of such data, a malicious party only needs to find one suitably dangling DNS delegation to score a "…@attacker-controlled-subdomain.legitimate.example" mailbox. The sender would not be able to prevent this.. unless its regulatory oversight body is very patient about repeatedly delaying legitimate requests for seemingly-minuscule formal defects. (Mentioning just for context. Probably not the mechanism at play here, Revolut would have tried to shift blame in the press release if it was.)
Post reply on HN