| ▲ | rawland 3 hours ago | ||||||||||||||||||||||||||||||||||||||||
How can this happen to a modern fintech... Esp. handling identity verification so poorly? > A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to disclose the government agency involved. Is the lack of transparency here about protecting the doxxed HNWIs or are they just trying to hide the incompetence? | |||||||||||||||||||||||||||||||||||||||||
| ▲ | KaiserPro 2 hours ago | parent | next [-] | ||||||||||||||||||||||||||||||||||||||||
Revolut has a history of being both halfarsed and shady in 2018 they turned off basic money laundering detection in 2019 they used job applicants as free labour to get people to sign up. in 2023 they didn't freeze accounts they were supposed to when asked by the NCA (the uk's equivalent of the FBI, kinda) again in 2024 they came bottom in the league table for reported fraud(action fraud). They had 10k reports, ahead of barclays, which at the time had a much large amount of active users. Again in 2024, they also had the highest push payment fraud reports. now, this _could_ be bad controls, user incompetence, or data leak. it could be argued that they were part of the reason for the rule changes, meaning that banks are now 50/50 liable for this kind of fraud. Either way, they have a history of being shady/incompetent/bastards. They've also only been a fully licensed bank for ~6 months. | |||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||
| ▲ | Maxion 3 hours ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||
I've processed government requests at a FinTech before. Some are pretty good and there are bespoke channels for them so that you can be sure their genuine. Other are literally random emails you get that you are required to reply to, many of them demanding information to be sent in the clear. We always declined to reply to those even though we legally had to, we offered them to set up PGP if they wanted the data via email, or we offered other secure mechanisms for them. Most of these (who I know were from real agencies) stopped asking for the data once we stood firm that we could only deliver it over an encrypted channel. Note: This is now 5+ years ago so things have probably changed since then. I am not surprised at all that fake requests receive real responses, happens probably way more than anyone thinks. | |||||||||||||||||||||||||||||||||||||||||
| ▲ | hirako2000 3 hours ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||
You could argue that the government agency is at fault. 1 for their breach, 2 more importantly: for mandating that personal information get handed over without an official court order which would have involved a far more stringent process with multiple parties involved. | |||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||
| ▲ | tdrz 3 hours ago | parent | prev [-] | ||||||||||||||||||||||||||||||||||||||||
This can happen with modern fintech because of greed. There's a reason they can offer such cheap services. The customer takes a risk in return. Now that risk has materialized. | |||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||