How can this happen to a modern fintech... Esp. handling identity verification so poorly?
> A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to disclose the government agency involved.
Is the lack of transparency here about protecting the doxxed HNWIs or are they just trying to hide the incompetence?
You could argue that the government agency is at fault. 1 for their breach, 2 more importantly: for mandating that personal information get handed over without an official court order which would have involved a far more stringent process with multiple parties involved.
My understanding of the situation is that no government agency actually requested data at all, just that someone impersonated a government email address and this was enough for Revolut to reply with the requested data.
From the PR statement, it's unclear if a gov. agency was hacked or it was a phishing attempt, from my point of view. Both cases are still not enough, even for a greasy spoon.
This can happen with modern fintech because of greed. There's a reason they can offer such cheap services. The customer takes a risk in return. Now that risk has materialized.
I see your point about greed. Thanks. Let me still contrast that: GPT6 has 99.9 in ARC-AGI 3 and multiple bug-bounty programs closed due to the sheer amount of automated attacks and reports.
And they are "FinTech". "Oh, that email looks legit, let's just hand out the data.", like they have never witnessed phishing from the old days... am curious about the story here. That PR-spokesperson is more than damaging...
Ran an LE request desk for a while and the whole thing was PDFs from .gov-ish email addresses. Only real control we had was calling the agency back on a number we looked up ourselves, not the one on the letterhead.
Here is one of the replies I got during my conversation with their agent (unsure if human or automated):
"Your personal data must be held until it is permissible to erase it in accordance with the law. Rest assured, it is totally secure and only held for this purpose."
This was in the same conversation where I sent them the article.
> "I have checked our records and can confirm that you have not received any notifications or communications regarding any security incidents or data breaches in the past 30 days.
> We take your privacy extremely seriously. All data transmissions between our mobile apps, servers, and third parties are fully encrypted, and your personal information is stored in secure data centres with restricted access. If there is ever any security incident that impacts your account, we will always contact you directly with instructions.
> Are you asking because you recently received a suspicious email, text message, or noticed an unusual transaction on your account? Let me know, and we can investigate that together."
In the USA they already take passport photos. Being able to receive mail addressed to a name is the closest thing to a national ID the USA has. They're already depended on for identity verification quite a lot.
The interesting failure here is not phishing, it is that "the email came from the real government domain" was accepted as authorization. A domain proves who sent the message, not that the sender was entitled to ask. Every compliance team I have worked with in payments had the same gap: the legal-request inbox verifies DKIM and the letterhead, then a human decides under time pressure with "law enforcement" in the subject line. What actually works is boring: a published list of the exact channels each authority uses, a callback to a number you looked up yourself rather than one in the email, a required case reference you can verify with the agency, and a hard rule that emergency requests get a minimal data set, never full KYC packages plus transaction history. The part that should worry Revolut customers more than the passport scans is the Bitcoin history: on-chain that data is permanent, so a leaked address-to-identity mapping does not expire.
I was thinking about exactly that and then I found this comment.
One spoofs an email domain and then is able to get trust from a "modern global fintech"? Absolutely ridiculous. Having worked for several global scale tech companies, I've seen first hand how security is at the absolutely bottom of the list. It does not translate to $$$ so it is uncared for.
Revolut keeps pestering me with requests for interviews and I keep running away from it. One more con (pun intended) to the list.
> A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to disclose the government agency involved.
Is the lack of transparency here about protecting the doxxed HNWIs or are they just trying to hide the incompetence?
Oh.. https://edition.cnn.com/2024/02/04/asia/deepfake-cfo-scam-ho...
And they are "FinTech". "Oh, that email looks legit, let's just hand out the data.", like they have never witnessed phishing from the old days... am curious about the story here. That PR-spokesperson is more than damaging...
"Your personal data must be held until it is permissible to erase it in accordance with the law. Rest assured, it is totally secure and only held for this purpose."
This was in the same conversation where I sent them the article.
> Hi, me affected by your breach?
Them:
> "I have checked our records and can confirm that you have not received any notifications or communications regarding any security incidents or data breaches in the past 30 days.
> We take your privacy extremely seriously. All data transmissions between our mobile apps, servers, and third parties are fully encrypted, and your personal information is stored in secure data centres with restricted access. If there is ever any security incident that impacts your account, we will always contact you directly with instructions.
> Are you asking because you recently received a suspicious email, text message, or noticed an unusual transaction on your account? Let me know, and we can investigate that together."
... bot stuffs.
Why do they even keep those?
Revolut could do the same as they do with ATMs: make a partnership with local banks for the verification step.
One spoofs an email domain and then is able to get trust from a "modern global fintech"? Absolutely ridiculous. Having worked for several global scale tech companies, I've seen first hand how security is at the absolutely bottom of the list. It does not translate to $$$ so it is uncared for.
Revolut keeps pestering me with requests for interviews and I keep running away from it. One more con (pun intended) to the list.