Ran an LE request desk for a while and the whole thing was PDFs from .gov-ish email addresses. Only real control we had was calling the agency back on a number we looked up ourselves, not the one on the letterhead.
Is it uncommon/impossible to ask for the federally-brokered in-person procedure in the US?
(The way I know it: Local court or police officer shows up at our office later that day and hands over a printout matching the request that we had been unable to confirm, on request of federal authority, in turn on request of the authority demanding we hand over some customers data. Those two requests utilizing government agency-internal auth mechanisms we do not need to know or care about.)
I was thinking about exactly that and then I found this comment.
One spoofs an email domain and then is able to get trust from a "modern global fintech"? Absolutely ridiculous. Having worked for several global scale tech companies, I've seen first hand how security is at the absolutely bottom of the list. It does not translate to $$$ so it is uncared for.
Revolut keeps pestering me with requests for interviews and I keep running away from it. One more con (pun intended) to the list.
In the countries you are licensed in you are legally required to reply to law enforcement requests. In most places there is no official channel for this. It is literally stuff like LE@Fintech.com. Emails come from all over and random domains that appear official-ish. Most official domains do not have DKIM or SPIF setup, very easy to spoof. LE by and large do not take security seriously, they do not take data transfer seriously.
Most requests are digitally signed PDFs that come via email, require a response sent to another email.
Breach yes, but if they cannot 100% sure identify if your data was given out falsily, then they cannot say. They're not allowed to disclose that they provide your information to LE. So they can only inform you directly if they're 100% sure the specific information request response was sent to false entity. This is very hard to do.
This was a targeted attack towards specific individuals, probably carried out by a state actor or someone after data of very valuable individuals. Unless you're one of those (oligarch, etc), you're probably fine.
How can this happen to a modern fintech... Esp. handling identity verification so poorly?
> A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to disclose the government agency involved.
Is the lack of transparency here about protecting the doxxed HNWIs or are they just trying to hide the incompetence?
This can happen with modern fintech because of greed. There's a reason they can offer such cheap services. The customer takes a risk in return. Now that risk has materialized.
You could argue that the government agency is at fault. 1 for their breach, 2 more importantly: for mandating that personal information get handed over without an official court order which would have involved a far more stringent process with multiple parties involved.
I've processed government requests at a FinTech before. Some are pretty good and there are bespoke channels for them so that you can be sure their genuine. Other are literally random emails you get that you are required to reply to, many of them demanding information to be sent in the clear. We always declined to reply to those even though we legally had to, we offered them to set up PGP if they wanted the data via email, or we offered other secure mechanisms for them. Most of these (who I know were from real agencies) stopped asking for the data once we stood firm that we could only deliver it over an encrypted channel.
Note: This is now 5+ years ago so things have probably changed since then.
I am not surprised at all that fake requests receive real responses, happens probably way more than anyone thinks.
For a while, Comcast/XFinity required the FBI to show up at their offices and present their badge. No emails. But I'm guessing that's changed. At the very least, it's also possible to forge a badge.
Revolut has a history of being both halfarsed and shady
in 2018 they turned off basic money laundering detection
in 2019 they used job applicants as free labour to get people to sign up.
in 2023 they didn't freeze accounts they were supposed to when asked by the NCA (the uk's equivalent of the FBI, kinda)
again in 2024 they came bottom in the league table for reported fraud(action fraud). They had 10k reports, ahead of barclays, which at the time had a much large amount of active users.
Again in 2024, they also had the highest push payment fraud reports. now, this _could_ be bad controls, user incompetence, or data leak. it could be argued that they were part of the reason for the rule changes, meaning that banks are now 50/50 liable for this kind of fraud.
Either way, they have a history of being shady/incompetent/bastards. They've also only been a fully licensed bank for ~6 months.
My speculative mental model so far was was: They fired the dept which was handling those "emails" and did let some agents handle it. Which backfired and seems to fit that history you presented.
Only one of them is directly harmful to users (the job applicant scheme). Everything else is enabling their own users to break the law only if they want to, and I think that is a good public service.
Of course it might hurt legit users by making other banks treat Revolut as suspicious but im not sure if thats enough to outweigh the positive. Data breaches and cancelation fees, on the other hand...
Here is one of the replies I got during my conversation with their agent (unsure if human or automated):
"Your personal data must be held until it is permissible to erase it in accordance with the law. Rest assured, it is totally secure and only held for this purpose."
This was in the same conversation where I sent them the article.
> "I have checked our records and can confirm that you have not received any notifications or communications regarding any security incidents or data breaches in the past 30 days.
> We take your privacy extremely seriously. All data transmissions between our mobile apps, servers, and third parties are fully encrypted, and your personal information is stored in secure data centres with restricted access. If there is ever any security incident that impacts your account, we will always contact you directly with instructions.
> Are you asking because you recently received a suspicious email, text message, or noticed an unusual transaction on your account? Let me know, and we can investigate that together."
At the end of the day, a government request for private, sensitive information is ultimately a form of a backdoor, and there is no such thing as a backdoor only the good guys can use.
The funny thing about Revolut is, that they send you from the same "no-reply" address your payment receipts and a ton of spam. There is no link in the spam do stop it and no obvious scheme in the header which would allow to filter the spam from the relevant mails. Good luck recognizing this breach notification as an important one...
If an email was authenticated with DKIM, you cannot really blame Revolut. The attacker would have had to compromise the government email server, making it the government's fault.
However, if the email relied solely on SPF, the situation is less clear. An attacker could potentially spoof SPF by compromising any service on a server sharing the same public IP address via NAT.
This is a reminder about what happens to people happily uploading their passport and selfies into the app. Do not do it if you do not want to end up in a Russian underground forums.
Storing identification data (like a scanned passport) is not necessary. The question is “did you check the customer identity?” And if the answer is Yes, then you can mark it as such. You don’t need to store these scans at all.
I had an interesting experience with my Revolut card. I only top it up when traveling, and the rest of the time it sits nearly empty, with like $3-4. At some point I started getting occasional notifications about transactions declining. Stuff like video game points and random little online shops. Clearly my card's been skimmed or otherwise leaked somehow. Bummer.
Since Im months away from my next trip I didnt immediately cancel the card and just left it on out of curiosity. I started blocking every attempted merchant. At some point, I started getting Netflix subscription attempts, and when I tried to block it, it said "We can't block payments to Netflix. If you have a subscription with them, you can cancel it directly." Makes me wonder what kind of rube goldberg machine their backend runs on.
I lost access to my Revolut account a while back and recovery did not work after losing access to my primary email address and MFA. They also removed the ability to deposit checks on their mobile app. For these reasons I can not treat it like a real bank anymore as much as I love their 4% APY savings account rate. Unlike gmail, which had recovery options with a secondary email address. They could have implemented something similar.
56 comments
[ 0.23 ms ] story [ 4.5 ms ] threadWhy do they even keep those?
(The way I know it: Local court or police officer shows up at our office later that day and hands over a printout matching the request that we had been unable to confirm, on request of federal authority, in turn on request of the authority demanding we hand over some customers data. Those two requests utilizing government agency-internal auth mechanisms we do not need to know or care about.)
Most likely:
> and the whole thing was PDFs from .gov-ish email addresses
One spoofs an email domain and then is able to get trust from a "modern global fintech"? Absolutely ridiculous. Having worked for several global scale tech companies, I've seen first hand how security is at the absolutely bottom of the list. It does not translate to $$$ so it is uncared for.
Revolut keeps pestering me with requests for interviews and I keep running away from it. One more con (pun intended) to the list.
Most requests are digitally signed PDFs that come via email, require a response sent to another email.
What you're referring to is that a bank does not require to tell you whether your account is going through specific checks (anti laundering and such).
> A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to disclose the government agency involved.
Is the lack of transparency here about protecting the doxxed HNWIs or are they just trying to hide the incompetence?
Oh.. https://edition.cnn.com/2024/02/04/asia/deepfake-cfo-scam-ho...
Note: This is now 5+ years ago so things have probably changed since then.
I am not surprised at all that fake requests receive real responses, happens probably way more than anyone thinks.
in 2018 they turned off basic money laundering detection
in 2019 they used job applicants as free labour to get people to sign up.
in 2023 they didn't freeze accounts they were supposed to when asked by the NCA (the uk's equivalent of the FBI, kinda)
again in 2024 they came bottom in the league table for reported fraud(action fraud). They had 10k reports, ahead of barclays, which at the time had a much large amount of active users.
Again in 2024, they also had the highest push payment fraud reports. now, this _could_ be bad controls, user incompetence, or data leak. it could be argued that they were part of the reason for the rule changes, meaning that banks are now 50/50 liable for this kind of fraud.
Either way, they have a history of being shady/incompetent/bastards. They've also only been a fully licensed bank for ~6 months.
My speculative mental model so far was was: They fired the dept which was handling those "emails" and did let some agents handle it. Which backfired and seems to fit that history you presented.
They had an EU license in Lithuania for years.
And they clearly figured that was easier than going through the UK where they had previously been licensed
Of course it might hurt legit users by making other banks treat Revolut as suspicious but im not sure if thats enough to outweigh the positive. Data breaches and cancelation fees, on the other hand...
That's "legacy old bank stuff they will disrupt along all the regulations".
"Your personal data must be held until it is permissible to erase it in accordance with the law. Rest assured, it is totally secure and only held for this purpose."
This was in the same conversation where I sent them the article.
> Hi, me affected by your breach?
Them:
> "I have checked our records and can confirm that you have not received any notifications or communications regarding any security incidents or data breaches in the past 30 days.
> We take your privacy extremely seriously. All data transmissions between our mobile apps, servers, and third parties are fully encrypted, and your personal information is stored in secure data centres with restricted access. If there is ever any security incident that impacts your account, we will always contact you directly with instructions.
> Are you asking because you recently received a suspicious email, text message, or noticed an unusual transaction on your account? Let me know, and we can investigate that together."
... bot stuffs.
However, if the email relied solely on SPF, the situation is less clear. An attacker could potentially spoof SPF by compromising any service on a server sharing the same public IP address via NAT.
Since Im months away from my next trip I didnt immediately cancel the card and just left it on out of curiosity. I started blocking every attempted merchant. At some point, I started getting Netflix subscription attempts, and when I tried to block it, it said "We can't block payments to Netflix. If you have a subscription with them, you can cancel it directly." Makes me wonder what kind of rube goldberg machine their backend runs on.