Since Im months away from my next trip I didnt immediately cancel the card and just left it on out of curiosity. I started blocking every attempted merchant. At some point, I started getting Netflix subscription attempts, and when I tried to block it, it said "We can't block payments to Netflix. If you have a subscription with them, you can cancel it directly." Makes me wonder what kind of rube goldberg machine their backend runs on.
It's very common for neobanks to have a high rates of fraud, but also lower negotiating leverage with merchants because they're not chase, Wells, etc.
So a specific arrangement with a specific merchant seems within the realm of normal to me.
(The way I know it: Local court or police officer shows up at our office later that day and hands over a printout matching the request that we had been unable to confirm, on request of federal authority, in turn on request of the authority demanding we hand over some customers data. Those two requests utilizing government agency-internal auth mechanisms we do not need to know or care about.)
Most likely:
> and the whole thing was PDFs from .gov-ish email addresses
But I guess this moves the liability for answering fake requests to the local branch.
Way to difficult for Revolut, evidently.
"Your personal data must be held until it is permissible to erase it in accordance with the law. Rest assured, it is totally secure and only held for this purpose."
This was in the same conversation where I sent them the article.
> Hi, me affected by your breach?
Them:
> "I have checked our records and can confirm that you have not received any notifications or communications regarding any security incidents or data breaches in the past 30 days.
> We take your privacy extremely seriously. All data transmissions between our mobile apps, servers, and third parties are fully encrypted, and your personal information is stored in secure data centres with restricted access. If there is ever any security incident that impacts your account, we will always contact you directly with instructions.
> Are you asking because you recently received a suspicious email, text message, or noticed an unusual transaction on your account? Let me know, and we can investigate that together."
... bot stuffs.
> A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to disclose the government agency involved.
Is the lack of transparency here about protecting the doxxed HNWIs or are they just trying to hide the incompetence?
It should be made impossible for someone at Revolut (and every other org) to deliver this data into the wrong hands by accident.
Why do they even keep those?
However, if the email relied solely on SPF, the situation is less clear. An attacker could potentially spoof SPF by compromising any service on a server sharing the same public IP address via NAT.
Good thing there's, at least EU wide, EUDI (EU Digital Identity Wallet) around the corner which legally allows using cryptographic proofs instead of just storing as much data as possible of the user.
This addresses exactly this issue of having to disclose this amount of information solely as proof.
What you're referring to is that a bank does not require to tell you whether your account is going through specific checks (anti laundering and such).
One spoofs an email domain and then is able to get trust from a "modern global fintech"? Absolutely ridiculous. Having worked for several global scale tech companies, I've seen first hand how security is at the absolutely bottom of the list. It does not translate to $$$ so it is uncared for.
Revolut keeps pestering me with requests for interviews and I keep running away from it. One more con (pun intended) to the list.
Most requests are digitally signed PDFs that come via email, require a response sent to another email.
Also I am surprised people do not see the different between isolated internal "old school" systems built on owned servers located at the bank property and modern vibe-coded microservices in kubernetes in a rented cloud with the widest attack surface possible.
Revolut are known to be a bit shady but in this case they're damned if they do and damned if they don't
Cybersecurity 101: Call back the bank at the official number and all that yada yada.
in 2018 they turned off basic money laundering detection
in 2019 they used job applicants as free labour to get people to sign up.
in 2023 they didn't freeze accounts they were supposed to when asked by the NCA (the uk's equivalent of the FBI, kinda)
again in 2024 they came bottom in the league table for reported fraud(action fraud). They had 10k reports, ahead of barclays, which at the time had a much large amount of active users.
Again in 2024, they also had the highest push payment fraud reports. now, this _could_ be bad controls, user incompetence, or data leak. it could be argued that they were part of the reason for the rule changes, meaning that banks are now 50/50 liable for this kind of fraud.
Either way, they have a history of being shady/incompetent/bastards. They've also only been a fully licensed bank for ~6 months.
My speculative mental model so far was: They fired the dept which was handling those "emails" and did let some agents handle it. Which backfired and seems to fit that history you presented.
They had an EU license in Lithuania for years.
Of course it might hurt legit users by making other banks treat Revolut as suspicious but im not sure if thats enough to outweigh the positive. Data breaches and cancelation fees, on the other hand...
Note: This is now 5+ years ago so things have probably changed since then.
I am not surprised at all that fake requests receive real responses, happens probably way more than anyone thinks.
But yeah there is always a downside when moving fast, oops
That's "legacy old bank stuff they will disrupt along all the regulations".
It’s a modern fintech that’s most likely to be vulnerable. Banks tend to have a long history (either themselves or with the infrastructure they buy) of security, from physical to electronic. It’s what makes them often so clunky…there’s little incentive to streamline too much, and their insurance providers are reluctant to insure anything excitingly new.
Hell, banking is so conservative that their language is frozen in 14th century Italian from when banks were personally owned by rich families: the words “debit” (“give”) and “credit” (“take”) are from the bank owner’s perspective, not the customers’. But you tend not to see the kinds of breaches you see in modern fintech.
But, you know, move fast and break things, right?
Oh.. https://edition.cnn.com/2024/02/04/asia/deepfake-cfo-scam-ho...
And they are "FinTech". "Oh, that email looks legit, let's just hand out the data.", like they have never witnessed phishing from the old days... am curious about the story here. That PR-spokesperson is more than damaging...
Revolut could do the same as they do with ATMs: make a partnership with local banks for the verification step.
This is used quite often for important things that don't have offices themselves.
Try opening one now. Today it's hard to get a hire purchase contract as an existing custoner (already known and verified) without photos of the ID and selfie.
You're discussing this as some inachievable science fiction that would require every employee to learn how to use gpg. In reality this could be achieved through a simple to use website.
In fact this is a solved problem. My doctor is not legally allowed to email me my own medical records, not even the most mundane blood test result. Instead they send them through the government-operated portal which employs suitable authentication and prevents any sort of transport-level hijacking.
There is no excuse to be using non-e2ee email for this in 2026. None.
Except, it makes the user experience worse: I can certainly make it infinitely more tedious to open the document exchange site of $superimportantcompany on superimportantcompany.co (or was it .com? or .co.uk? or important-company-le.ai?), and spread out "my" inbox across 30 different sites and spend additional time navigating their unique interfaces to not just read, but also add each document into the appropriate local archive. But what have I gained in making it more likely that each correspondence is kept confidential between the only parties that should read it? Nothing beyond what I started with. Could have stayed with email, no?
I can see the appeal of mitigating part of the usability problem by pivoting straight to bundling up all thematically related messages into centralized repositories to limit the number of pseudo-mailboxes one has to maintain simultaneously, as done in the recent "everything medical related" cases. But someone would grab a full copy in the inevitable compromise, and that is a risk that should rather stay scoped to smaller groups of senders and/or recipients. It seems like a bad tradeoff to force every blood test of everyone into the danger zone for that, given that one could have instead spent 3% of the budget on.. merely policing away the DNS warts in public authorities (or, in the medical example, insurance companies) while keeping data custody unchanged.
And they clearly figured that was easier than going through the UK where they had previously been licensed
https://www.lb.lt/en/news/banking-licence-granted-to-revolut...
edit: Comment no longer makes much sense after the one above was edited
but compare that to their competitors who got a license at the very start
You do understand what push fraud is right? One person lost ~£160k, a large chunk of it waiting for a human to answer.
also, its not like there aren't alternatives.
That's a dangerous kind of threat to be making, and to act upon. for information that should remain private let alone owned by the bank itself.
What's your source?
That is not what the news says.
Also, you know you can easily impersonate any email? That's a flaw of the email protocol.
So when a company is requested to hand over sensitive data, they do. For sure when the origin of the request is the government itself (pawned email in this case)
Automated methods, like the ones Revolut use, are significantly more effective at KYC than a Jane Doe working a 9-5 at a bank. In no way is it “tip-toeing around KYC”, and while really unfortunate leaking a selfie is pretty low down on the list of “bad stuff a bank could leak”.
The implication that the solution to this is to somehow convince your direct competitors to do inferior in-person KYC for you is the most ridiculous thing.
People work with their competitors all the time (see Netfix vs Amazon). Whats ridiculuous is the claim that a scammer would prefer to show up physically at a bank and risk being exposed instead of operating remotely.
>leaking a selfie is pretty low down on the list of “bad stuff a bank could leak”.
don't some of them require a selfie while holding legible official documentation?
> Whats ridiculuous is the claim that a scammer would prefer to show up physically at a bank and risk being exposed instead of operating remotely.
Of course they wouldn’t prefer to show physically. What does that mean though? Are you saying no scammers showed up physically to banks, therefore banking fraud rates are less? Do you have a source for that?
> don't some of them require a selfie while holding legible official documentation?
You can of course do KYC as stupidly as you like (zoom calls anyone?) - Revolut (and their providers) obviously separate document presentation from the liveness check (and fyi this is a short video, not a selfie. The selfie they are talking about is just a capture from the video)
Is your argument supposed to be more convincing because you added the word "patently"?
>What does that mean though?
It means that when you find a way to bypass purely online identity verification checks executing fraud at scale is easier than the physical alternative. As you would say, this is patently obvious.