Remix.run Logo
rawland 3 hours ago

How can this happen to a modern fintech... Esp. handling identity verification so poorly?

> A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to disclose the government agency involved.

Is the lack of transparency here about protecting the doxxed HNWIs or are they just trying to hide the incompetence?

KaiserPro 2 hours ago | parent | next [-]

Revolut has a history of being both halfarsed and shady

in 2018 they turned off basic money laundering detection

in 2019 they used job applicants as free labour to get people to sign up.

in 2023 they didn't freeze accounts they were supposed to when asked by the NCA (the uk's equivalent of the FBI, kinda)

again in 2024 they came bottom in the league table for reported fraud(action fraud). They had 10k reports, ahead of barclays, which at the time had a much large amount of active users.

Again in 2024, they also had the highest push payment fraud reports. now, this _could_ be bad controls, user incompetence, or data leak. it could be argued that they were part of the reason for the rule changes, meaning that banks are now 50/50 liable for this kind of fraud.

Either way, they have a history of being shady/incompetent/bastards. They've also only been a fully licensed bank for ~6 months.

rawland 2 hours ago | parent | next [-]

That's some background. Thanks.

My speculative mental model so far was: They fired the dept which was handling those "emails" and did let some agents handle it. Which backfired and seems to fit that history you presented.

sam_lowry_ 2 hours ago | parent [-]

Revolut is also run by a Russian with deep connections to wartime Russian elites, starting with his dad, who heads the biggest Gazprom R&D center.

wasfgwp 2 hours ago | parent | prev [-]

> been a fully licensed bank for ~6 months

They had an EU license in Lithuania for years.

jbs789 an hour ago | parent [-]

Not a bank until 2018

And they clearly figured that was easier than going through the UK where they had previously been licensed

wasfgwp an hour ago | parent [-]

No, they had a standard bank license, no different than any other bank operating in the country. Of course it was only valid in the EU not Britain.

https://www.lb.lt/en/news/banking-licence-granted-to-revolut...

edit: Comment no longer makes much sense after the one above was edited

Maxion 3 hours ago | parent | prev | next [-]

I've processed government requests at a FinTech before. Some are pretty good and there are bespoke channels for them so that you can be sure their genuine. Other are literally random emails you get that you are required to reply to, many of them demanding information to be sent in the clear. We always declined to reply to those even though we legally had to, we offered them to set up PGP if they wanted the data via email, or we offered other secure mechanisms for them. Most of these (who I know were from real agencies) stopped asking for the data once we stood firm that we could only deliver it over an encrypted channel.

Note: This is now 5+ years ago so things have probably changed since then.

I am not surprised at all that fake requests receive real responses, happens probably way more than anyone thinks.

hirako2000 3 hours ago | parent | prev | next [-]

You could argue that the government agency is at fault. 1 for their breach, 2 more importantly: for mandating that personal information get handed over without an official court order which would have involved a far more stringent process with multiple parties involved.

tmhrtly 3 hours ago | parent [-]

My understanding of the situation is that no government agency actually requested data at all, just that someone impersonated a government email address and this was enough for Revolut to reply with the requested data.

hirako2000 2 minutes ago | parent | next [-]

The government did request the data. And since the announcement, it has requested highly sensitive data again, and to keep such data, backed by threats of violent repercussions, that businesses cease to operate or to even exist.

That's a dangerous kind of threat to be making, and to act upon. for information that should remain private let alone owned by the bank itself.

rawland 3 hours ago | parent | prev | next [-]

From the PR statement, it's unclear if a gov. agency was hacked or it was a phishing attempt, from my point of view. Both cases are still not enough, even for a greasy spoon.

cluckindan 3 hours ago | parent | prev [-]

It was probably an AI agent that handed it over.

tdrz 3 hours ago | parent | prev [-]

This can happen with modern fintech because of greed. There's a reason they can offer such cheap services. The customer takes a risk in return. Now that risk has materialized.

Jenk 3 hours ago | parent | next [-]

Yes, because it's _only_ "modern fintech" that are susceptible to social engineering, right?

Oh.. https://edition.cnn.com/2024/02/04/asia/deepfake-cfo-scam-ho...

rawland 3 hours ago | parent | prev [-]

I see your point about greed. Thanks. Let me still contrast that: GPT6 has 99.9 in ARC-AGI 3 and multiple bug-bounty programs closed due to the sheer amount of automated attacks and reports.

And they are "FinTech". "Oh, that email looks legit, let's just hand out the data.", like they have never witnessed phishing from the old days... am curious about the story here. That PR-spokesperson is more than damaging...