4 ms·
How can this happen to a modern fintech... Esp. handling identity verification so poorly? > A Revolut spokesperson confirmed to TechCrunch that a “limited” num
by rawland 20d ago
How can this happen to a modern fintech... Esp. handling identity verification so poorly?
> A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to disclose the government agency involved.
Is the lack of transparency here about protecting the doxxed HNWIs or are they just trying to hide the incompetence?
- karel-3d 19d agoRevolut is built on move-fast-break-things. They make things cheaply, quickly, and it (mostly) works. But yeah there is always a downside when moving fast, oops
- tdrz 20d agoThis can happen with modern fintech because of greed. There's a reason they can offer such cheap services. The customer takes a risk in return. Now that risk has materialized.
- rawland 20d agoI see your point about greed. Thanks. Let me still contrast that: GPT6 has 99.9 in ARC-AGI 3 and multiple bug-bounty programs closed due to the sheer amount of automated attacks and reports. And they are "FinTech". "Oh, that email looks legit, let's just hand out the data.", like they have never witnessed phishing from the old days... am curious about the story here. That PR-spokesperson is more than damaging...
- Jenk 20d agoYes, because it's _only_ "modern fintech" that are susceptible to social engineering, right? Oh.. https://edition.cnn.com/2024/02/04/asia/deepfake-cfo-scam-hong-kong-intl-hnk https://edition.cnn.com/2024/02/04/asia/deepfake-cfo-scam-ho...
- hirako2000 20d agoYou could argue that the government agency is at fault. 1 for their breach, 2 more importantly: for mandating that personal information get handed over without an official court order which would have involved a far more stringent process with multiple parties involved.
- tmhrtly 20d agoMy understanding of the situation is that no government agency actually requested data at all, just that someone impersonated a government email address and this was enough for Revolut to reply with the requested data.
- rawland 20d agoFrom the PR statement, it's unclear if a gov. agency was hacked or it was a phishing attempt, from my point of view. Both cases are still not enough, even for a greasy spoon.
- olejorgenb 20d agoIf the Revolut know the agency was hacked it surely would be in their interest to say so (unless the agency hold them at "gunpoint")
- cluckindan 20d ago[flagged]
- hirako2000 20d agoThe government did request the data. And since the announcement, it has requested highly sensitive data again, and to keep such data, backed by threats of violent repercussions, that businesses cease to operate or to even exist. That's a dangerous kind of threat to be making, and to act upon. for information that should remain private let alone owned by the bank itself.
- epolanski 20d ago
- Maxion 20d agoI've processed government requests at a FinTech before. Some are pretty good and there are bespoke channels for them so that you can be sure their genuine. Other are literally random emails you get that you are required to reply to, many of them demanding information to be sent in the clear. We always declined to reply to those even though we legally had to, we offered them to set up PGP if they wanted the data via email, or we offered other secure mechanisms for them. Most of these (who I know were from real agencies) stopped asking for the data once we stood firm that we could only deliver it over an encrypted channel. Note: This is now 5+ years ago so things have probably changed since then. I am not surprised at all that fake requests receive real responses, happens probably way more than anyone thinks.
- xhkkffbf 20d agoFor a while, Comcast/XFinity required the FBI to show up at their offices and present their badge. No emails. But I'm guessing that's changed. At the very least, it's also possible to forge a badge.
- KaiserPro 20d agoRevolut has a history of being both halfarsed and shady in 2018 they turned off basic money laundering detection in 2019 they used job applicants as free labour to get people to sign up. in 2023 they didn't freeze accounts they were supposed to when asked by the NCA (the uk's equivalent of the FBI, kinda) again in 2024 they came bottom in the league table for reported fraud(action fraud). They had 10k reports, ahead of barclays, which at the time had a much large amount of active users. Again in 2024, they also had the highest push payment fraud reports. now, this _could_ be bad controls, user incompetence, or data leak. it could be argued that they were part of the reason for the rule changes, meaning that banks are now 50/50 liable for this kind of fraud. Either way, they have a history of being shady/incompetent/bastards. They've also only been a fully licensed bank for ~6 months.
- rawland 20d agoThat's some background. Thanks. My speculative mental model so far was: They fired the dept which was handling those "emails" and did let some agents handle it. Which backfired and seems to fit that history you presented.
- sam_lowry_ 20d agoRevolut is also run by a Russian with deep connections to wartime Russian elites, starting with his dad, who heads the biggest Gazprom R&D center.
- 20d ago
- epolanski 20d agoIt's fintech, it's all about growth, not customer care. That's "legacy old bank stuff they will disrupt along all the regulations".
- gumby 20d ago> How can this happen to a modern fintech…? It’s a modern fintech that’s most likely to be vulnerable. Banks tend to have a long history (either themselves or with the infrastructure they buy) of security, from physical to electronic. It’s what makes them often so clunky…there’s little incentive to streamline too much, and their insurance providers are reluctant to insure anything excitingly new. Hell, banking is so conservative that their language is frozen in 14th century Italian from when banks were personally owned by rich families: the words “debit” (“give”) and “credit” (“take”) are from the bank owner’s perspective, not the customers’. But you tend not to see the kinds of breaches you see in modern fintech. But, you know, move fast and break things, right?
- Scoundreller 20d agoI remember doing an account closure at a legacy bank and the paperwork said they'd "disperse" my money instead of disburse it...