| ▲ | halilBB 4 hours ago | |||||||||||||
The interesting failure here is not phishing, it is that "the email came from the real government domain" was accepted as authorization. A domain proves who sent the message, not that the sender was entitled to ask. Every compliance team I have worked with in payments had the same gap: the legal-request inbox verifies DKIM and the letterhead, then a human decides under time pressure with "law enforcement" in the subject line. What actually works is boring: a published list of the exact channels each authority uses, a callback to a number you looked up yourself rather than one in the email, a required case reference you can verify with the agency, and a hard rule that emergency requests get a minimal data set, never full KYC packages plus transaction history. The part that should worry Revolut customers more than the passport scans is the Bitcoin history: on-chain that data is permanent, so a leaked address-to-identity mapping does not expire. | ||||||||||||||
| ▲ | someoneeestis 3 hours ago | parent | next [-] | |||||||||||||
I was thinking about exactly that and then I found this comment. One spoofs an email domain and then is able to get trust from a "modern global fintech"? Absolutely ridiculous. Having worked for several global scale tech companies, I've seen first hand how security is at the absolutely bottom of the list. It does not translate to $$$ so it is uncared for. Revolut keeps pestering me with requests for interviews and I keep running away from it. One more con (pun intended) to the list. | ||||||||||||||
| ||||||||||||||
| ▲ | acedTrex an hour ago | parent | prev [-] | |||||||||||||
Thx claude | ||||||||||||||