Revolut has a history of being both halfarsed and shady
in 2018 they turned off basic money laundering detection
in 2019 they used job applicants as free labour to get people to sign up.
in 2023 they didn't freeze accounts they were supposed to when asked by the NCA (the uk's equivalent of the FBI, kinda)
again in 2024 they came bottom in the league table for reported fraud(action fraud). They had 10k reports, ahead of barclays, which at the time had a much large amount of active users.
Again in 2024, they also had the highest push payment fraud reports. now, this _could_ be bad controls, user incompetence, or data leak. it could be argued that they were part of the reason for the rule changes, meaning that banks are now 50/50 liable for this kind of fraud.
Either way, they have a history of being shady/incompetent/bastards. They've also only been a fully licensed bank for ~6 months.
That's some background. Thanks.
My speculative mental model so far was: They fired the dept which was handling those "emails" and did let some agents handle it. Which backfired and seems to fit that history you presented.
Revolut is also run by a Russian with deep connections to wartime Russian elites, starting with his dad, who heads the biggest Gazprom R&D center.
Yeah, not sure if Revolut is the fintech that's portrayed in the last season of The Industry.
Only one of them is directly harmful to users (the job applicant scheme). Everything else is enabling their own users to break the law only if they want to, and I think that is a good public service.
Of course it might hurt legit users by making other banks treat Revolut as suspicious but im not sure if thats enough to outweigh the positive. Data breaches and cancelation fees, on the other hand...
> been a fully licensed bank for ~6 months
They had an EU license in Lithuania for years.
Not a bank until 2018
And they clearly figured that was easier than going through the UK where they had previously been licensed
I've processed government requests at a FinTech before. Some are pretty good and there are bespoke channels for them so that you can be sure their genuine. Other are literally random emails you get that you are required to reply to, many of them demanding information to be sent in the clear. We always declined to reply to those even though we legally had to, we offered them to set up PGP if they wanted the data via email, or we offered other secure mechanisms for them. Most of these (who I know were from real agencies) stopped asking for the data once we stood firm that we could only deliver it over an encrypted channel.
Note: This is now 5+ years ago so things have probably changed since then.
I am not surprised at all that fake requests receive real responses, happens probably way more than anyone thinks.
For a while, Comcast/XFinity required the FBI to show up at their offices and present their badge. No emails. But I'm guessing that's changed. At the very least, it's also possible to forge a badge.
You could argue that the government agency is at fault. 1 for their breach, 2 more importantly: for mandating that personal information get handed over without an official court order which would have involved a far more stringent process with multiple parties involved.
My understanding of the situation is that no government agency actually requested data at all, just that someone impersonated a government email address and this was enough for Revolut to reply with the requested data.
The government did request the data. And since the announcement, it has requested highly sensitive data again, and to keep such data, backed by threats of violent repercussions, that businesses cease to operate or to even exist.
That's a dangerous kind of threat to be making, and to act upon. for information that should remain private let alone owned by the bank itself.
> The government did request the data.
What's your source?
That is not what the news says.
Also, you know you can easily impersonate any email? That's a flaw of the email protocol.
From the PR statement, it's unclear if a gov. agency was hacked or it was a phishing attempt, from my point of view. Both cases are still not enough, even for a greasy spoon.
It was probably an AI agent that handed it over.
> How can this happen to a modern fintech…?
It’s a modern fintech that’s most likely to be vulnerable. Banks tend to have a long history (either themselves or with the infrastructure they buy) of security, from physical to electronic. It’s what makes them often so clunky…there’s little incentive to streamline too much, and their insurance providers are reluctant to insure anything excitingly new.
Hell, banking is so conservative that their language is frozen in 14th century Italian from when banks were personally owned by rich families: the words “debit” (“give”) and “credit” (“take”) are from the bank owner’s perspective, not the customers’. But you tend not to see the kinds of breaches you see in modern fintech.
But, you know, move fast and break things, right?
I remember doing an account closure at a legacy bank and the paperwork said they'd "disperse" my money instead of disburse it...
It's fintech, it's all about growth, not customer care.
That's "legacy old bank stuff they will disrupt along all the regulations".
This can happen with modern fintech because of greed. There's a reason they can offer such cheap services. The customer takes a risk in return. Now that risk has materialized.
I see your point about greed. Thanks. Let me still contrast that: GPT6 has 99.9 in ARC-AGI 3 and multiple bug-bounty programs closed due to the sheer amount of automated attacks and reports.
And they are "FinTech". "Oh, that email looks legit, let's just hand out the data.", like they have never witnessed phishing from the old days... am curious about the story here. That PR-spokesperson is more than damaging...