Back to the notes

Revolut handed over customer data to scammers pretending to be cops

A fintech with 50 million users fell for spoofed government data requests. The weak link was not the encryption.

A black payment card with a chip on a white surface
Markus Winkler / Unsplash Unsplash License

Revolut confirmed last week that attackers impersonated law enforcement agencies and requested customer data through official channels. The company handed over sensitive information for an unknown number of users before catching the scam. The attack did not exploit a zero-day or crack encryption. It exploited the process every company builds to comply with lawful data requests. Someone forged government emails or legal documents convincingly enough that Revolut’s compliance team approved the handover. This is scarier than a database leak. A database leak is a technical failure you can patch. This is a social engineering attack that sits inside the same workflow banks use to respond to subpoenas and emergency disclosure requests. The Reuters piece does not say how many requests were fake or which jurisdictions the attackers impersonated, but the fact that it happened at all means the verification step failed. Most companies verify government requests by checking sender email domains and matching case numbers against public records. If the attackers compromised a real government email account or forged headers well enough to pass SPF and DKIM checks, that verification collapses. Add urgency (“this is an emergency request, lives at risk”) and the compliance officer approves it. Revolut has 50 million customers. The company did not disclose how many were affected, which suggests the number is not zero and not trivial. The fix is not better encryption. The fix is out-of-band verification for every single request, probably a phone call to a known number at the requesting agency. That adds friction, but the alternative is handing PII to whoever writes a convincing letter.


Source: Revolut confirms customer data breach, falling for fake government requests

Back to all notes

Behind the notes

Vikrant
Sharma.

Artificial Intelligence Engineer intern at Voxon Photonics in Adelaide. Studying a Master of Information and Communications Technology at UniSC, with a focus on data, machine learning and security.

Meet the person behind the work