Back to News
Advertisement
Advertisement

⚡ Community Insights

Discussion Sentiment

75% Positive

Analyzed from 2838 words in the discussion.

Trending Topics

#data#email#revolut#bank#government#requests#fintech#agency#those#banks

Discussion (117 Comments)Read Original on HackerNews

neither_color•about 10 hours ago
I had an interesting experience with my Revolut card. I only top it up when traveling, and the rest of the time it sits nearly empty, with like $3-4. At some point I started getting occasional notifications about transactions declining. Stuff like video game points and random little online shops. Clearly my card's been skimmed or otherwise leaked somehow. Bummer.

Since Im months away from my next trip I didnt immediately cancel the card and just left it on out of curiosity. I started blocking every attempted merchant. At some point, I started getting Netflix subscription attempts, and when I tried to block it, it said "We can't block payments to Netflix. If you have a subscription with them, you can cancel it directly." Makes me wonder what kind of rube goldberg machine their backend runs on.

LoganDark•about 9 hours ago
What kind of financial institution has a special deal with Netflix to prevent blocking their charges? Did Netflix threaten to block Revolut or something?
calderwoodra•about 8 hours ago
If a merchant gets a lot of charge backs from a specific card issuer or acquirer, they can block them specifically. A company at Netlifx's size could be doing this, but I've heard specific instances of it happening with grocery stores, gas stations and convenience stores.

It's very common for neobanks to have a high rates of fraud, but also lower negotiating leverage with merchants because they're not chase, Wells, etc.

So a specific arrangement with a specific merchant seems within the realm of normal to me.

LoganDark•about 8 hours ago
My card issuer just gives me a credit when I want to chargeback. They're like, oh you don't want to deal with a real chargeback, just have your money back for free. I would've pressed it since I kinda wanted the company to regret ripping me off, but I already got my money back so it wasn't worth the extra effort.
hndhyc0bdt•about 14 hours ago
Ran an LE request desk for a while and the whole thing was PDFs from .gov-ish email addresses. Only real control we had was calling the agency back on a number we looked up ourselves, not the one on the letterhead.
edelbitter•about 12 hours ago
Is it uncommon/impossible to ask for the federally-brokered in-person procedure in the US?

(The way I know it: Local court or police officer shows up at our office later that day and hands over a printout matching the request that we had been unable to confirm, on request of federal authority, in turn on request of the authority demanding we hand over some customers data. Those two requests utilizing government agency-internal auth mechanisms we do not need to know or care about.)

SoftTalker•about 9 hours ago
You'd still want to verify that with the court or authority? I've been served before and sometimes it's just a person in street clothes who hands you an envelope. And even if it's a court bailiff or officer or something like that, would you be able to distinguish a real uniform, ID and badge from a fake one?
edelbitter•about 8 hours ago
The uniformed woman with the pistol is whatever the stitching on the chest pocket say she is. Is that not true just the same even in places where other people may routinely open-carry?
formerly_proven•about 10 hours ago
> Those two requests utilizing government agency-internal auth mechanisms we do not need to know or care about.

Most likely:

> and the whole thing was PDFs from .gov-ish email addresses

But I guess this moves the liability for answering fake requests to the local branch.

sikozu•about 13 hours ago
You say .gov-ish, does this mean compromised gov email accounts, spoofed email addresses or domains that look like government domains?
Maxion•about 13 hours ago
.gov is a US thing, and not even all US agencies use .gov ending emails.
codedokode•about 10 hours ago
You do not need to compromise anything, you can put any address in the "from" field. Email has no universal verification for sender address.
haakon•about 9 hours ago
I would sincerely hope .gov addresses use SPF/DKIM/DMARC. That makes spoofing impossible. In Revolut's case, the sender's email system had been compromised.
znnajdla•about 14 hours ago
What is LE? Let’s Encrypt?
ericpauley•about 14 hours ago
Guessing Law Enforcement
nkrisc•about 13 hours ago
Law enforcement.
r_lee•about 12 hours ago
how would you come to that conclusion based on the context here?
LoganDark•about 9 hours ago
Uh, not knowing otherwise? Which is why they were asking?
guillybarres•about 12 hours ago
Swing and a miss.
Maxion•about 13 hours ago
I've done that as well and this is what most of those do look like.
chrisjj•about 10 hours ago
> Only real control we had was calling the agency back on a number we looked up ourselves

Way to difficult for Revolut, evidently.

entropyneur•about 8 hours ago
Here in Latvia, anything the government ever sends you of any importance is cryptographicaly signed. Not bulletproof, but that should be a baseline we demand in this age.
rawland•about 14 hours ago
How can this happen to a modern fintech... Esp. handling identity verification so poorly?

> A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to disclose the government agency involved.

Is the lack of transparency here about protecting the doxxed HNWIs or are they just trying to hide the incompetence?

KaiserPro•about 13 hours ago
Revolut has a history of being both halfarsed and shady

in 2018 they turned off basic money laundering detection

in 2019 they used job applicants as free labour to get people to sign up.

in 2023 they didn't freeze accounts they were supposed to when asked by the NCA (the uk's equivalent of the FBI, kinda)

again in 2024 they came bottom in the league table for reported fraud(action fraud). They had 10k reports, ahead of barclays, which at the time had a much large amount of active users.

Again in 2024, they also had the highest push payment fraud reports. now, this _could_ be bad controls, user incompetence, or data leak. it could be argued that they were part of the reason for the rule changes, meaning that banks are now 50/50 liable for this kind of fraud.

Either way, they have a history of being shady/incompetent/bastards. They've also only been a fully licensed bank for ~6 months.

rawland•about 12 hours ago
That's some background. Thanks.

My speculative mental model so far was: They fired the dept which was handling those "emails" and did let some agents handle it. Which backfired and seems to fit that history you presented.

sam_lowry_•about 12 hours ago
Revolut is also run by a Russian with deep connections to wartime Russian elites, starting with his dad, who heads the biggest Gazprom R&D center.
tancop•about 10 hours ago
Only one of them is directly harmful to users (the job applicant scheme). Everything else is enabling their own users to break the law only if they want to, and I think that is a good public service.

Of course it might hurt legit users by making other banks treat Revolut as suspicious but im not sure if thats enough to outweigh the positive. Data breaches and cancelation fees, on the other hand...

KaiserPro•about 7 hours ago
> Only one of them is directly harmful to users

You do understand what push fraud is right? One person lost ~ÂŁ160k, a large chunk of it waiting for a human to answer.

also, its not like there aren't alternatives.

wasfgwp•about 12 hours ago
> been a fully licensed bank for ~6 months

They had an EU license in Lithuania for years.

jbs789•about 12 hours ago
Not a bank until 2018

And they clearly figured that was easier than going through the UK where they had previously been licensed

Maxion•about 13 hours ago
I've processed government requests at a FinTech before. Some are pretty good and there are bespoke channels for them so that you can be sure their genuine. Other are literally random emails you get that you are required to reply to, many of them demanding information to be sent in the clear. We always declined to reply to those even though we legally had to, we offered them to set up PGP if they wanted the data via email, or we offered other secure mechanisms for them. Most of these (who I know were from real agencies) stopped asking for the data once we stood firm that we could only deliver it over an encrypted channel.

Note: This is now 5+ years ago so things have probably changed since then.

I am not surprised at all that fake requests receive real responses, happens probably way more than anyone thinks.

xhkkffbf•about 11 hours ago
For a while, Comcast/XFinity required the FBI to show up at their offices and present their badge. No emails. But I'm guessing that's changed. At the very least, it's also possible to forge a badge.
hirako2000•about 14 hours ago
You could argue that the government agency is at fault. 1 for their breach, 2 more importantly: for mandating that personal information get handed over without an official court order which would have involved a far more stringent process with multiple parties involved.
tmhrtly•about 13 hours ago
My understanding of the situation is that no government agency actually requested data at all, just that someone impersonated a government email address and this was enough for Revolut to reply with the requested data.
hirako2000•about 11 hours ago
The government did request the data. And since the announcement, it has requested highly sensitive data again, and to keep such data, backed by threats of violent repercussions, that businesses cease to operate or to even exist.

That's a dangerous kind of threat to be making, and to act upon. for information that should remain private let alone owned by the bank itself.

rawland•about 13 hours ago
From the PR statement, it's unclear if a gov. agency was hacked or it was a phishing attempt, from my point of view. Both cases are still not enough, even for a greasy spoon.
gumby•about 9 hours ago
> How can this happen to a modern fintech…?

It’s a modern fintech that’s most likely to be vulnerable. Banks tend to have a long history (either themselves or with the infrastructure they buy) of security, from physical to electronic. It’s what makes them often so clunky…there’s little incentive to streamline too much, and their insurance providers are reluctant to insure anything excitingly new.

Hell, banking is so conservative that their language is frozen in 14th century Italian from when banks were personally owned by rich families: the words “debit” (“give”) and “credit” (“take”) are from the bank owner’s perspective, not the customers’. But you tend not to see the kinds of breaches you see in modern fintech.

But, you know, move fast and break things, right?

Scoundreller•about 9 hours ago
I remember doing an account closure at a legacy bank and the paperwork said they'd "disperse" my money instead of disburse it...
tdrz•about 14 hours ago
This can happen with modern fintech because of greed. There's a reason they can offer such cheap services. The customer takes a risk in return. Now that risk has materialized.
Jenk•about 13 hours ago
Yes, because it's _only_ "modern fintech" that are susceptible to social engineering, right?

Oh.. https://edition.cnn.com/2024/02/04/asia/deepfake-cfo-scam-ho...

rawland•about 13 hours ago
I see your point about greed. Thanks. Let me still contrast that: GPT6 has 99.9 in ARC-AGI 3 and multiple bug-bounty programs closed due to the sheer amount of automated attacks and reports.

And they are "FinTech". "Oh, that email looks legit, let's just hand out the data.", like they have never witnessed phishing from the old days... am curious about the story here. That PR-spokesperson is more than damaging...

epolanski•about 10 hours ago
It's fintech, it's all about growth, not customer care.

That's "legacy old bank stuff they will disrupt along all the regulations".

tdrz•about 14 hours ago
Here is one of the replies I got during my conversation with their agent (unsure if human or automated):

"Your personal data must be held until it is permissible to erase it in accordance with the law. Rest assured, it is totally secure and only held for this purpose."

This was in the same conversation where I sent them the article.

rawland•about 14 hours ago
My dialogue:

> Hi, me affected by your breach?

Them:

> "I have checked our records and can confirm that you have not received any notifications or communications regarding any security incidents or data breaches in the past 30 days.

> We take your privacy extremely seriously. All data transmissions between our mobile apps, servers, and third parties are fully encrypted, and your personal information is stored in secure data centres with restricted access. If there is ever any security incident that impacts your account, we will always contact you directly with instructions.

> Are you asking because you recently received a suspicious email, text message, or noticed an unusual transaction on your account? Let me know, and we can investigate that together."

... bot stuffs.

ifwinterco•about 9 hours ago
Revolut are well known for using automated systems for all support and it being difficult/impossible to talk to an actual human
cluckindan•about 13 hours ago
Was it the same agent that released the data?
hrpnk•about 14 hours ago
Even if the trigger was spoofed, how come there is no secure channel that the govt provides to receive the data? Was this one also compromised?
edelbitter•about 11 hours ago
That may not matter that much, as even if you run a relatively strict policy about where you send the reply, you can still easily get bitten by external mistakes there: Because of the huge number of individually administered departments that might each become authorized recipient of such data, a malicious party only needs to find one suitably dangling DNS delegation to score a "…@attacker-controlled-subdomain.legitimate.example" mailbox. The sender would not be able to prevent this.. unless its regulatory oversight body is very patient about repeatedly delaying legitimate requests for seemingly-minuscule formal defects. (Mentioning just for context. Probably not the mechanism at play here, Revolut would have tried to shift blame in the press release if it was.)
ang_cire•about 13 hours ago
If people actually knew how much of a wild west this stuff is, a lot more would be cautious with their personal info.
hrpnk•about 7 hours ago
If you are forced to ID check with the bank via a 3rd party, the only way is to ask for removal of data after the ID check. Do you see other ways?
codedokode•about 10 hours ago
This is a reminder about what happens to people happily uploading their passport and selfies into the app. Do not do it if you do not want to end up in a Russian underground forums.
dgellow•about 8 hours ago
What else are you supposed to do? All bank require BYC and will ask you to control your identity. We shouldn’t blame customers for the fintech company mistakes
codedokode•about 5 hours ago
Some banks, I assume, allow showing the documents in person and without a selfie.
kioleanu•about 5 hours ago
You assume wrong if you’re taking about old-school banks. They’ll still scan your id and it ends up in the same system
attendant3446•about 5 hours ago
Just showing documents? I never saw a bank that will do this. They always make a copy.
cassianoleal•about 14 hours ago
> The data may have also included verification selfies

Why do they even keep those?

igsomething•about 14 hours ago
I am almost sure they don't and instead they query selfies and documents on-demand from their KYC provider.
Maxion•about 13 hours ago
Yep, the KYC provider keeps them.
red_admiral•about 12 hours ago
Could they be put in what bitcoin people call "cold storage"? I can't imagine they're used every day.
Numerlor•about 14 hours ago
Around banking it's usually because they have to
tdrz•about 14 hours ago
Other banks do not require selfies, so there are other options
flyingcoder•about 14 hours ago
But they are verifying customers in person with account creation, this is an online bank
anthonj•about 14 hours ago
This is a 100% online bank account you typically open from an app. The typical clientele will just use the "selfie" auth.
rjsw•about 8 hours ago
At least one traditional UK bank requires a selfie and a passport scan.
subscribed•about 14 hours ago
Most banks now require selfies, try shopping around. KYC requirements get tightened all the time.
dotancohen•about 14 hours ago
CYA in case of litigation.
autotune•about 10 hours ago
I lost access to my Revolut account a while back and recovery did not work after losing access to my primary email address and MFA. They also removed the ability to deposit checks on their mobile app. For these reasons I can not treat it like a real bank anymore as much as I love their 4% APY savings account rate. Unlike gmail, which had recovery options with a secondary email address. They could have implemented something similar.
janandonly•about 10 hours ago
Storing identification data (like a scanned passport) is not necessary. The question is “did you check the customer identity?” And if the answer is Yes, then you can mark it as such. You don’t need to store these scans at all.
mrbnprck•about 5 hours ago
Actually you do have to store those, as proof (but MUST be destroyed after 10 years). This is very typical in AML (Anti Money Laundering) laws.

Good thing there's, at least EU wide, EUDI (EU Digital Identity Wallet) around the corner which legally allows using cryptographic proofs instead of just storing as much data as possible of the user.

This addresses exactly this issue of having to disclose this amount of information solely as proof.

seydor•about 10 hours ago
in which country?
Cider9986•about 10 hours ago
Are there any banks that are good at security? Obviously none have any privacy.
Advertisement
tdrz•about 14 hours ago
I asked if my data was compromised, they said no, but how can I trust/verify this?
Maxion•about 13 hours ago
You can't, really. Banking legislation does not require them to tell you.
orf•about 12 hours ago
Banking legislation in the UK does require them to tell you for this kind of breach.
Maxion•about 12 hours ago
Breach yes, but if they cannot 100% sure identify if your data was given out falsily, then they cannot say. They're not allowed to disclose that they provide your information to LE. So they can only inform you directly if they're 100% sure the specific information request response was sent to false entity. This is very hard to do.
epolanski•about 10 hours ago
Data laws in EU mandate that a company has to tell you every single entity it has shared your data with, regardless of the sector they operate in.

What you're referring to is that a bank does not require to tell you whether your account is going through specific checks (anti laundering and such).

toyg•about 11 hours ago
This was a targeted attack towards specific individuals, probably carried out by a state actor or someone after data of very valuable individuals. Unless you're one of those (oligarch, etc), you're probably fine.
anonym29•about 13 hours ago
At the end of the day, a government request for private, sensitive information is ultimately a form of a backdoor, and there is no such thing as a backdoor only the good guys can use.
ma2kx•about 12 hours ago
The funny thing about Revolut is, that they send you from the same "no-reply" address your payment receipts and a ton of spam. There is no link in the spam do stop it and no obvious scheme in the header which would allow to filter the spam from the relevant mails. Good luck recognizing this breach notification as an important one...
sleepyguy•about 11 hours ago
If an email was authenticated with DKIM, you cannot really blame Revolut. The attacker would have had to compromise the government email server, making it the government's fault.

However, if the email relied solely on SPF, the situation is less clear. An attacker could potentially spoof SPF by compromising any service on a server sharing the same public IP address via NAT.

f33d5173•about 11 hours ago
Why did you copy paste a comment from 4chan? Is this a pasta I'm not aware of?
ChrisArchitect•about 13 hours ago
halilBB•about 14 hours ago
The interesting failure here is not phishing, it is that "the email came from the real government domain" was accepted as authorization. A domain proves who sent the message, not that the sender was entitled to ask. Every compliance team I have worked with in payments had the same gap: the legal-request inbox verifies DKIM and the letterhead, then a human decides under time pressure with "law enforcement" in the subject line. What actually works is boring: a published list of the exact channels each authority uses, a callback to a number you looked up yourself rather than one in the email, a required case reference you can verify with the agency, and a hard rule that emergency requests get a minimal data set, never full KYC packages plus transaction history. The part that should worry Revolut customers more than the passport scans is the Bitcoin history: on-chain that data is permanent, so a leaked address-to-identity mapping does not expire.
someoneeestis•about 14 hours ago
I was thinking about exactly that and then I found this comment.

One spoofs an email domain and then is able to get trust from a "modern global fintech"? Absolutely ridiculous. Having worked for several global scale tech companies, I've seen first hand how security is at the absolutely bottom of the list. It does not translate to $$$ so it is uncared for.

Revolut keeps pestering me with requests for interviews and I keep running away from it. One more con (pun intended) to the list.

Maxion•about 13 hours ago
In the countries you are licensed in you are legally required to reply to law enforcement requests. In most places there is no official channel for this. It is literally stuff like LE@Fintech.com. Emails come from all over and random domains that appear official-ish. Most official domains do not have DKIM or SPIF setup, very easy to spoof. LE by and large do not take security seriously, they do not take data transfer seriously.

Most requests are digitally signed PDFs that come via email, require a response sent to another email.

ifwinterco•about 9 hours ago
Yeah the secure thing is to ignore all requests from domains without DKIM, but that would mean ignoring a lot of legitimate requests which is illegal.

Revolut are known to be a bit shady but in this case they're damned if they do and damned if they don't

someoneeestis•about 6 hours ago
But that's the thing, they have the money to have people chasing down the official channels of whatever email that comes from to confirm their authenticity.

Cybersecurity 101: Call back the bank at the official number and all that yada yada.

throw-the-towel•about 13 hours ago
They also pay peanuts, and the culture is toxic.
acedTrex•about 12 hours ago
Thx claude