14 comments

  • hndhyc0bdt4 hours ago
    Ran an LE request desk for a while and the whole thing was PDFs from .gov-ish email addresses. Only real control we had was calling the agency back on a number we looked up ourselves, not the one on the letterhead.
    • edelbitter2 hours ago
      Is it uncommon&#x2F;impossible to ask for the federally-brokered in-person procedure in the US?<p>(The way I know it: Local court or police officer shows up at our office later that day and hands over a printout matching the request that we had been unable to confirm, on request of federal authority, in turn on request of the authority demanding we hand over some customers data. Those two requests utilizing government agency-internal auth mechanisms we do not need to know or care about.)
      • formerly_proven7 minutes ago
        &gt; Those two requests utilizing government agency-internal auth mechanisms we do not need to know or care about.<p>Most likely:<p>&gt; and the whole thing was PDFs from .gov-ish email addresses<p>But I guess this moves the liability for answering fake requests to the local branch.
    • chrisjj7 minutes ago
      [delayed]
    • znnajdla4 hours ago
      What is LE? Let’s Encrypt?
      • ericpauley4 hours ago
        Guessing Law Enforcement
      • nkrisc3 hours ago
        Law enforcement.
      • r_lee2 hours ago
        how would you come to that conclusion based on the context here?
      • guillybarres2 hours ago
        Swing and a miss.
    • sikozu3 hours ago
      You say .gov-ish, does this mean compromised gov email accounts, spoofed email addresses or domains that look like government domains?
      • Maxion3 hours ago
        .gov is a US thing, and not even all US agencies use .gov ending emails.
      • codedokode19 minutes ago
        You do not need to compromise anything, you can put any address in the &quot;from&quot; field. Email has no universal verification for sender address.
    • Maxion3 hours ago
      I&#x27;ve done that as well and this is what most of those do look like.
  • rawland4 hours ago
    How can this happen to a modern fintech... Esp. handling identity verification so poorly?<p>&gt; A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to disclose the government agency involved.<p>Is the lack of transparency here about protecting the doxxed HNWIs or are they just trying to hide the incompetence?
    • KaiserPro3 hours ago
      Revolut has a history of being both halfarsed and shady<p>in 2018 they turned off basic money laundering detection<p>in 2019 they used job applicants as free labour to get people to sign up.<p>in 2023 they didn&#x27;t freeze accounts they were supposed to when asked by the NCA (the uk&#x27;s equivalent of the FBI, kinda)<p>again in 2024 they came bottom in the league table for reported fraud(action fraud). They had 10k reports, ahead of barclays, which at the time had a much large amount of active users.<p>Again in 2024, they also had the highest push payment fraud reports. now, this _could_ be bad controls, user incompetence, or data leak. it could be argued that they were part of the reason for the rule changes, meaning that banks are now 50&#x2F;50 liable for this kind of fraud.<p>Either way, they have a history of being shady&#x2F;incompetent&#x2F;bastards. They&#x27;ve also only been a fully licensed bank for ~6 months.
      • rawland2 hours ago
        That&#x27;s some background. Thanks.<p>My speculative mental model so far was: They fired the dept which was handling those &quot;emails&quot; and did let some agents handle it. Which backfired and seems to fit that history you presented.
        • sam_lowry_2 hours ago
          Revolut is also run by a Russian with deep connections to wartime Russian elites, starting with his dad, who heads the biggest Gazprom R&amp;D center.
          • barrenko26 minutes ago
            Yeah, not sure if Revolut is the fintech that&#x27;s portrayed in the last season of The Industry.
      • wasfgwp2 hours ago
        &gt; been a fully licensed bank for ~6 months<p>They had an EU license in Lithuania for years.
        • jbs7892 hours ago
          Not a bank until 2018<p>And they clearly figured that was easier than going through the UK where they had previously been licensed
          • wasfgwp1 hour ago
            No, they had a standard bank license, no different than any other bank operating in the country. Of course it was only valid in the EU not Britain.<p><a href="https:&#x2F;&#x2F;www.lb.lt&#x2F;en&#x2F;news&#x2F;banking-licence-granted-to-revolut-bank-uab" rel="nofollow">https:&#x2F;&#x2F;www.lb.lt&#x2F;en&#x2F;news&#x2F;banking-licence-granted-to-revolut...</a><p>edit: Comment no longer makes much sense after the one above was edited
    • Maxion3 hours ago
      I&#x27;ve processed government requests at a FinTech before. Some are pretty good and there are bespoke channels for them so that you can be sure their genuine. Other are literally random emails you get that you are required to reply to, many of them demanding information to be sent in the clear. We always declined to reply to those even though we legally had to, we offered them to set up PGP if they wanted the data via email, or we offered other secure mechanisms for them. Most of these (who I know were from real agencies) stopped asking for the data once we stood firm that we could only deliver it over an encrypted channel.<p>Note: This is now 5+ years ago so things have probably changed since then.<p>I am not surprised at all that fake requests receive real responses, happens probably way more than anyone thinks.
      • xhkkffbf49 minutes ago
        For a while, Comcast&#x2F;XFinity required the FBI to show up at their offices and present their badge. No emails. But I&#x27;m guessing that&#x27;s changed. At the very least, it&#x27;s also possible to forge a badge.
    • hirako20003 hours ago
      You could argue that the government agency is at fault. 1 for their breach, 2 more importantly: for mandating that personal information get handed over without an official court order which would have involved a far more stringent process with multiple parties involved.
      • tmhrtly3 hours ago
        My understanding of the situation is that no government agency actually requested data at all, just that someone impersonated a government email address and this was enough for Revolut to reply with the requested data.
        • hirako200052 minutes ago
          The government did request the data. And since the announcement, it has requested highly sensitive data again, and to keep such data, backed by threats of violent repercussions, that businesses cease to operate or to even exist.<p>That&#x27;s a dangerous kind of threat to be making, and to act upon. for information that should remain private let alone owned by the bank itself.
        • rawland3 hours ago
          From the PR statement, it&#x27;s unclear if a gov. agency was hacked or it was a phishing attempt, from my point of view. Both cases are still not enough, even for a greasy spoon.
        • cluckindan3 hours ago
          It was probably an AI agent that handed it over.
    • tdrz3 hours ago
      This can happen with modern fintech because of greed. There&#x27;s a reason they can offer such cheap services. The customer takes a risk in return. Now that risk has materialized.
      • Jenk3 hours ago
        Yes, because it&#x27;s _only_ &quot;modern fintech&quot; that are susceptible to social engineering, right?<p>Oh.. <a href="https:&#x2F;&#x2F;edition.cnn.com&#x2F;2024&#x2F;02&#x2F;04&#x2F;asia&#x2F;deepfake-cfo-scam-hong-kong-intl-hnk" rel="nofollow">https:&#x2F;&#x2F;edition.cnn.com&#x2F;2024&#x2F;02&#x2F;04&#x2F;asia&#x2F;deepfake-cfo-scam-ho...</a>
      • rawland3 hours ago
        I see your point about greed. Thanks. Let me still contrast that: GPT6 has 99.9 in ARC-AGI 3 and multiple bug-bounty programs closed due to the sheer amount of automated attacks and reports.<p>And they are &quot;FinTech&quot;. &quot;Oh, that email looks legit, let&#x27;s just hand out the data.&quot;, like they have never witnessed phishing from the old days... am curious about the story here. That PR-spokesperson is more than damaging...
  • tdrz4 hours ago
    Here is one of the replies I got during my conversation with their agent (unsure if human or automated):<p>&quot;Your personal data must be held until it is permissible to erase it in accordance with the law. Rest assured, it is totally secure and only held for this purpose.&quot;<p>This was in the same conversation where I sent them the article.
    • rawland4 hours ago
      My dialogue:<p>&gt; Hi, me affected by your breach?<p>Them:<p>&gt; &quot;I have checked our records and can confirm that you have not received any notifications or communications regarding any security incidents or data breaches in the past 30 days.<p>&gt; We take your privacy extremely seriously. All data transmissions between our mobile apps, servers, and third parties are fully encrypted, and your personal information is stored in secure data centres with restricted access. If there is ever any security incident that impacts your account, we will always contact you directly with instructions.<p>&gt; Are you asking because you recently received a suspicious email, text message, or noticed an unusual transaction on your account? Let me know, and we can investigate that together.&quot;<p>... bot stuffs.
    • cluckindan3 hours ago
      Was it the same agent that released the data?
  • codedokode21 minutes ago
    This is a reminder about what happens to people happily uploading their passport and selfies into the app. Do not do it if you do not want to end up in a Russian underground forums.
  • cassianoleal4 hours ago
    &gt; The data may have also included verification selfies<p>Why do they even keep those?
    • igsomething4 hours ago
      I am almost sure they don&#x27;t and instead they query selfies and documents on-demand from their KYC provider.
      • Maxion3 hours ago
        Yep, the KYC provider keeps them.
        • red_admiral2 hours ago
          Could they be put in what bitcoin people call &quot;cold storage&quot;? I can&#x27;t imagine they&#x27;re used every day.
          • Maxion1 hour ago
            They&#x27;re used pretty often, so not really. The KYC providers anyway wouldn&#x27;t code anything like that.
      • petre3 hours ago
        [flagged]
    • Numerlor4 hours ago
      Around banking it&#x27;s usually because they have to
      • tdrz4 hours ago
        Other banks do not require selfies, so there are other options
        • flyingcoder4 hours ago
          But they are verifying customers in person with account creation, this is an online bank
          • tdrz3 hours ago
            &gt; But they are verifying customers in person with account creation, this is an online bank<p>Revolut could do the same as they do with ATMs: make a partnership with local banks for the verification step.
            • orf2 hours ago
              Sure, but that would be like insanely stupid on pretty much every level though, so why would they do that?
              • shakna1 hour ago
                Trying to find a way to tip toe around KYC, whilst keeping their customers safe, has also turned out to only use insanely stupid methods, though. So why did they already do that?
                • orf1 hour ago
                  FYI it turns out that humans are pretty bad at comparing faces to ID documents. Like, really quite bad.<p>Automated methods, like the ones Revolut use, are significantly more effective at KYC than a Jane Doe working a 9-5 at a bank. In no way is it “tip-toeing around KYC”, and while really unfortunate leaking a selfie is pretty low down on the list of “bad stuff a bank could leak”.<p>The implication that the solution to this is to somehow convince your direct <i>competitors</i> to do inferior in-person KYC for you is the most ridiculous thing.
                  • sillyfluke1 hour ago
                    &gt;The implication that the solution to this is to somehow convince your direct competitors to do inferior in-person KYC for you is the most ridiculous thing.<p>People work with their competitors all the time (see Netfix vs Amazon). Whats ridiculuous is the claim that a scammer would prefer to show up physically at a bank and risk being exposed instead of operating remotely.<p>&gt;leaking a selfie is pretty low down on the list of “bad stuff a bank could leak”.<p>don&#x27;t some of them require a selfie while holding legible official documentation?
              • tdrz2 hours ago
                For security reasons, obviously! That way they wouldn&#x27;t leak selfies because they wouldn&#x27;t have any.
                • basisword32 minutes ago
                  Sending your new&#x2F;potential customers to your competitor doesn&#x27;t sound very sensible.
          • HPsquared3 hours ago
            Seems like a thing you should be able to do at the post office.
            • whatevaa3 hours ago
              What does post office have to do with identity verification?
              • SAI_Peregrinus3 hours ago
                In the USA they already take passport photos. Being able to receive mail addressed to a name is the closest thing to a national ID the USA has. They&#x27;re already depended on for identity verification quite a lot.
              • hvb22 hours ago
                Some post offices in the US also function as a so called notary public. Basically, they can verify your identity and attest that it&#x27;s you who sent&#x2F;did something.<p>This is used quite often for important things that don&#x27;t have offices themselves.
        • anthonj4 hours ago
          This is a 100% online bank account you typically open from an app. The typical clientele will just use the &quot;selfie&quot; auth.
          • tdrz3 hours ago
            The issue is that there is no alternative to the &quot;selfie&quot; auth in case of Revolut.
        • subscribed4 hours ago
          Most banks now require selfies, try shopping around. KYC requirements get tightened all the time.
          • tdrz3 hours ago
            I have accounts with 2 other banks. They never asked for a selfie.
            • subscribed41 minutes ago
              Same, they never asked for a selfie back then.<p>Try opening one now. Today it&#x27;s hard to get a hire purchase contract as an <i>existing custoner</i> (already known and verified) without photos of the ID and selfie.
    • dotancohen4 hours ago
      CYA in case of litigation.
  • Cider998639 minutes ago
    Are there any banks that are good at security? Obviously none have any privacy.
  • hrpnk4 hours ago
    Even if the trigger was spoofed, how come there is no secure channel that the govt provides to <i>receive</i> the data? Was this one also compromised?
    • edelbitter1 hour ago
      That may not matter that much, as even if you run a relatively strict policy about where you send the reply, you can still easily get bitten by external mistakes there: Because of the huge number of individually administered departments that might each become authorized recipient of such data, a malicious party only needs to find <i>one</i> suitably dangling DNS delegation to score a &quot;…@attacker-controlled-subdomain.legitimate.example&quot; mailbox. The sender would not be able to prevent this.. unless its regulatory oversight body is <i>very</i> patient about repeatedly delaying legitimate requests for seemingly-minuscule formal defects. (Mentioning just for context. <i>Probably</i> not the mechanism at play here, Revolut would have tried to shift blame in the press release if it was.)
    • ang_cire2 hours ago
      If people actually knew how much of a wild west this stuff is, a lot more would be cautious with their personal info.
  • tdrz4 hours ago
    I asked if my data was compromised, they said no, but how can I trust&#x2F;verify this?
    • Maxion3 hours ago
      You can&#x27;t, really. Banking legislation does not require them to tell you.
      • orf2 hours ago
        Banking legislation in the UK does require them to tell you for this kind of breach.
        • Maxion1 hour ago
          Breach yes, but if they cannot 100% sure identify if your data was given out falsily, then they cannot say. They&#x27;re not allowed to disclose that they provide your information to LE. So they can only inform you directly if they&#x27;re 100% sure the specific information request response was sent to false entity. This is very hard to do.
    • toyg1 hour ago
      This was a targeted attack towards specific individuals, probably carried out by a state actor or someone after data of very valuable individuals. Unless you&#x27;re one of those (oligarch, etc), you&#x27;re probably fine.
  • ma2kx2 hours ago
    The funny thing about Revolut is, that they send you from the same &quot;no-reply&quot; address your payment receipts and a ton of spam. There is no link in the spam do stop it and no obvious scheme in the header which would allow to filter the spam from the relevant mails. Good luck recognizing this breach notification as an important one...
  • sleepyguy1 hour ago
    If an email was authenticated with DKIM, you cannot really blame Revolut. The attacker would have had to compromise the government email server, making it the government&#x27;s fault.<p>However, if the email relied solely on SPF, the situation is less clear. An attacker could potentially spoof SPF by compromising any service on a server sharing the same public IP address via NAT.
    • f33d51731 hour ago
      Why did you copy paste a comment from 4chan? Is this a pasta I&#x27;m not aware of?
  • anonym293 hours ago
    At the end of the day, a government request for private, sensitive information is ultimately a form of a backdoor, and there is no such thing as a backdoor only the good guys can use.
  • ChrisArchitect2 hours ago
    Earlier: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49674666">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49674666</a>
  • halilBB4 hours ago
    The interesting failure here is not phishing, it is that &quot;the email came from the real government domain&quot; was accepted as authorization. A domain proves who sent the message, not that the sender was entitled to ask. Every compliance team I have worked with in payments had the same gap: the legal-request inbox verifies DKIM and the letterhead, then a human decides under time pressure with &quot;law enforcement&quot; in the subject line. What actually works is boring: a published list of the exact channels each authority uses, a callback to a number you looked up yourself rather than one in the email, a required case reference you can verify with the agency, and a hard rule that emergency requests get a minimal data set, never full KYC packages plus transaction history. The part that should worry Revolut customers more than the passport scans is the Bitcoin history: on-chain that data is permanent, so a leaked address-to-identity mapping does not expire.
    • someoneeestis3 hours ago
      I was thinking about exactly that and then I found this comment.<p>One spoofs an email domain and then is able to get trust from a &quot;modern global fintech&quot;? Absolutely ridiculous. Having worked for several global scale tech companies, I&#x27;ve seen first hand how security is at the absolutely bottom of the list. It does not translate to $$$ so it is uncared for.<p>Revolut keeps pestering me with requests for interviews and I keep running away from it. One more con (pun intended) to the list.
      • Maxion3 hours ago
        In the countries you are licensed in you are legally required to reply to law enforcement requests. In most places there is no official channel for this. It is literally stuff like LE@Fintech.com. Emails come from all over and random domains that appear official-ish. Most official domains do not have DKIM or SPIF setup, very easy to spoof. LE by and large do <i>not</i> take security seriously, they do <i>not</i> take data transfer seriously.<p>Most requests are digitally signed PDFs that come via email, require a response sent to another email.
      • throw-the-towel3 hours ago
        They also pay peanuts, and the culture is toxic.
    • acedTrex1 hour ago
      Thx claude
  • eitri1 hour ago
    [dead]