

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- If an email was authenticated with DKIM, you cannot really blame Revolut. The attacker would have had to compromise the government email server, making it the government's fault.
However, if the email relied solely on SPF, the situation is less clear. An attacker could potentially spoof SPF by compromising any service on a server sharing the same public IP address via NAT.
by sleepyguy - Why did you copy paste a comment from 4chan? Is this a pasta I'm not aware of?by f33d5173
- They should start doing like Google, publishing a Transparency Report https://transparencyreport.google.com/by nicolinox
- At the end of the day, a government request for private, sensitive information is ultimately a form of a backdoor, and there is no such thing as a backdoor only the good guys can use.by anonym29
- I lost access to my Revolut account a while back and recovery did not work after losing access to my primary email address and MFA. They also removed the ability to deposit checks on their mobile app. For these reasons I can not treat it like a real bank anymore as much as I love their 4% APY savings account rate. Unlike gmail, which had recovery options with a secondary email address. They could have implemented something similar.by autotune
- This is a reminder about what happens to people happily uploading their passport and selfies into the app. Do not do it if you do not want to end up in a Russian underground forums.by codedokode
- What else are you supposed to do? All bank require BYC and will ask you to control your identity. We shouldn’t blame customers for the fintech company mistakesby dgellow
- > The data may have also included verification selfies
Why do they even keep those?
by cassianoleal - CYA in case of litigation.by dotancohen
- Around banking it's usually because they have toby Numerlor
- I am almost sure they don't and instead they query selfies and documents on-demand from their KYC provider.by igsomething
- Even if the trigger was spoofed, how come there is no secure channel that the govt provides to receive the data? Was this one also compromised?by hrpnk
- If people actually knew how much of a wild west this stuff is, a lot more would be cautious with their personal info.by ang_cire
- That may not matter that much, as even if you run a relatively strict policy about where you send the reply, you can still easily get bitten by external mistakes there: Because of the huge number of individually administered departments that might each become authorized recipient of such data, a malicious party only needs to find one suitably dangling DNS delegation to score a "…@attacker-controlled-subdomain.legitimate.example" mailbox. The sender would not be able to prevent this.. unless its regulatory oversight body is very patient about repeatedly delaying legitimate requests for seemingly-minuscule formal defects. (Mentioning just for context. Probably not the mechanism at play here, Revolut would have tried to shift blame in the press release if it was.)by edelbitter
- How can this happen to a modern fintech... Esp. handling identity verification so poorly?
> A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to disclose the government agency involved.
Is the lack of transparency here about protecting the doxxed HNWIs or are they just trying to hide the incompetence?
by rawland - This can happen with modern fintech because of greed. There's a reason they can offer such cheap services. The customer takes a risk in return. Now that risk has materialized.by tdrz
- Revolut is built on move-fast-break-things. They make things cheaply, quickly, and it (mostly) works.
But yeah there is always a downside when moving fast, oops
by karel-3d - > How can this happen to a modern fintech…?
It’s a modern fintech that’s most likely to be vulnerable. Banks tend to have a long history (either themselves or with the infrastructure they buy) of security, from physical to electronic. It’s what makes them often so clunky…there’s little incentive to streamline too much, and their insurance providers are reluctant to insure anything excitingly new.
Hell, banking is so conservative that their language is frozen in 14th century Italian from when banks were personally owned by rich families: the words “debit” (“give”) and “credit” (“take”) are from the bank owner’s perspective, not the customers’. But you tend not to see the kinds of breaches you see in modern fintech.
But, you know, move fast and break things, right?
by gumby - It's fintech, it's all about growth, not customer care.
That's "legacy old bank stuff they will disrupt along all the regulations".
by epolanski - You could argue that the government agency is at fault. 1 for their breach, 2 more importantly: for mandating that personal information get handed over without an official court order which would have involved a far more stringent process with multiple parties involved.by hirako2000
- I've processed government requests at a FinTech before. Some are pretty good and there are bespoke channels for them so that you can be sure their genuine. Other are literally random emails you get that you are required to reply to, many of them demanding information to be sent in the clear. We always declined to reply to those even though we legally had to, we offered them to set up PGP if they wanted the data via email, or we offered other secure mechanisms for them. Most of these (who I know were from real agencies) stopped asking for the data once we stood firm that we could only deliver it over an encrypted channel.
Note: This is now 5+ years ago so things have probably changed since then.
I am not surprised at all that fake requests receive real responses, happens probably way more than anyone thinks.
by Maxion - Revolut has a history of being both halfarsed and shady
in 2018 they turned off basic money laundering detection
in 2019 they used job applicants as free labour to get people to sign up.
in 2023 they didn't freeze accounts they were supposed to when asked by the NCA (the uk's equivalent of the FBI, kinda)
again in 2024 they came bottom in the league table for reported fraud(action fraud). They had 10k reports, ahead of barclays, which at the time had a much large amount of active users.
Again in 2024, they also had the highest push payment fraud reports. now, this _could_ be bad controls, user incompetence, or data leak. it could be argued that they were part of the reason for the rule changes, meaning that banks are now 50/50 liable for this kind of fraud.
Either way, they have a history of being shady/incompetent/bastards. They've also only been a fully licensed bank for ~6 months.
by KaiserPro - Here is one of the replies I got during my conversation with their agent (unsure if human or automated):
"Your personal data must be held until it is permissible to erase it in accordance with the law. Rest assured, it is totally secure and only held for this purpose."
This was in the same conversation where I sent them the article.
by tdrz - My dialogue:
> Hi, me affected by your breach?
Them:
> "I have checked our records and can confirm that you have not received any notifications or communications regarding any security incidents or data breaches in the past 30 days.
> We take your privacy extremely seriously. All data transmissions between our mobile apps, servers, and third parties are fully encrypted, and your personal information is stored in secure data centres with restricted access. If there is ever any security incident that impacts your account, we will always contact you directly with instructions.
> Are you asking because you recently received a suspicious email, text message, or noticed an unusual transaction on your account? Let me know, and we can investigate that together."
... bot stuffs.
by rawland - Was it the same agent that released the data?by cluckindan
- Here in Latvia, anything the government ever sends you of any importance is cryptographicaly signed. Not bulletproof, but that should be a baseline we demand in this age.by entropyneur
- Ran an LE request desk for a while and the whole thing was PDFs from .gov-ish email addresses. Only real control we had was calling the agency back on a number we looked up ourselves, not the one on the letterhead.by hndhyc0bdt
- I've done that as well and this is what most of those do look like.by Maxion
- What is LE? Let’s Encrypt?by znnajdla
- > Only real control we had was calling the agency back on a number we looked up ourselves
Way to difficult for Revolut, evidently.
by chrisjj