3 ms·
The interesting failure here is not phishing, it is that "the email came from the real government domain" was accepted as authorization. A domain proves who sen
by halilBB 20d ago
The interesting failure here is not phishing, it is that "the email came from the real government domain" was accepted as authorization. A domain proves who sent the message, not that the sender was entitled to ask. Every compliance team I have worked with in payments had the same gap: the legal-request inbox verifies DKIM and the letterhead, then a human decides under time pressure with "law enforcement" in the subject line. What actually works is boring: a published list of the exact channels each authority uses, a callback to a number you looked up yourself rather than one in the email, a required case reference you can verify with the agency, and a hard rule that emergency requests get a minimal data set, never full KYC packages plus transaction history. The part that should worry Revolut customers more than the passport scans is the Bitcoin history: on-chain that data is permanent, so a leaked address-to-identity mapping does not expire.
- someoneeestis 19d agoI was thinking about exactly that and then I found this comment. One spoofs an email domain and then is able to get trust from a "modern global fintech"? Absolutely ridiculous. Having worked for several global scale tech companies, I've seen first hand how security is at the absolutely bottom of the list. It does not translate to $$$ so it is uncared for. Revolut keeps pestering me with requests for interviews and I keep running away from it. One more con (pun intended) to the list.
- throw-the-towel 19d agoThey also pay peanuts, and the culture is toxic.
- Maxion 19d agoIn the countries you are licensed in you are legally required to reply to law enforcement requests. In most places there is no official channel for this. It is literally stuff like LE@Fintech.com. Emails come from all over and random domains that appear official-ish. Most official domains do not have DKIM or SPIF setup, very easy to spoof. LE by and large do not take security seriously, they do not take data transfer seriously. Most requests are digitally signed PDFs that come via email, require a response sent to another email.
- ifwinterco 19d agoYeah the secure thing is to ignore all requests from domains without DKIM, but that would mean ignoring a lot of legitimate requests which is illegal. Revolut are known to be a bit shady but in this case they're damned if they do and damned if they don't
- someoneeestis 19d agoBut that's the thing, they have the money to have people chasing down the official channels of whatever email that comes from to confirm their authenticity. Cybersecurity 101: Call back the bank at the official number and all that yada yada.
- acedTrex 19d agoThx claude