| ▲ | Wicher a day ago | |
> sent from a legitimate government agency email domain, DMARC-verified-sent from a legitimate [...] domain? -> Someone pwned a mailbox at an agency? I'm sure they would've spun the story into "the government was hacked, not us" in that case. Or "sent from" a legitimate [...] domain? -> Spoofed envelope sender / FROM? Then Revolut's simply been had by the nose. If the domain is indeed a government domain, and does not publish DMARC records, then a due diligence check on who they're sending such personal info (ie, call that purported government agency up on the phone) would suit them. After all, they're very pedantic about me running their app on a phone with an unlocked bootloader. I'd then hope that they'd be symmetrically pedantic about verifying whoever they're sending my info to. | ||