Revolut confirms customer data breach through fake government requests
183 points
• 1 day ago
• Article
Link
Revolut 已确认发生一起泄露敏感客户信息的数据事件。公司表示,因一名冒充政府机构的未经授权第三方利用政府域名发送邮件,误导公司应付了其关于敏感记录的欺诈性请求,从而导致私人数据被移交给该方。
受影响的数据范围广泛,包括客户姓名、出生日期、电子邮件、住址和电话号码等个人信息;还涉及高度敏感的身份证明文件,如护照和驾驶执照的复印件。根据不同个案,泄露内容可能还包括用于身份验证的自拍照、账户账单以及交易明细等。
公司发言人称,仅有少数客户受到这起手法复杂的诈骗影响,Revolut 已直接通知受影响客户。虽然未透露具体人数或被冒充的政府机构名称,但强调其内部系统和客户资金仍然安全。
在发现该骗局后,公司已屏蔽相关电子邮件地址,并向有关政府机构、执法机关和监管部门报案。此事发生在这家总部位于 London 的公司关键时期——公司近期获得了 U.S. 银行牌照的有条件批准,且据报正在推进潜在上市,估值可达 $200 billion 。
Revolut has confirmed a data breach involving the exposure of sensitive customer information. The fintech firm disclosed that it inadvertently handed over private data to an unauthorized third party that had successfully impersonated a legitimate government agency. By using a government domain for its email communications, the attacker was able to deceive the company into fulfilling fraudulent requests for sensitive records.
The compromised information covers a wide range of personal details, including customers' names, dates of birth, email addresses, residential addresses, and phone numbers. The breach also extended to highly sensitive identity documentation, such as copies of passports and driver's licenses. Depending on the individual case, the exposed data potentially included verification selfies, account statements, and detailed transaction histories.
A spokesperson for the company stated that a limited number of customers were impacted by this sophisticated scam. The firm has already reached out to the affected parties directly to notify them of the situation. While Revolut declined to specify the exact number of individuals involved or name the government agency that was impersonated, they emphasized that their internal systems and customer funds remain secure.
Upon uncovering the deception, the company blocked the attacker's email address and reported the incident to the relevant government agency, law enforcement, and regulatory bodies. The security breach comes at a significant time for the London-based firm, which recently secured conditional approval for a U.S. banking license and is reportedly eyeing a potential public listing with a valuation as high as $200 billion.
127 comments • Comments Link
• 金融机构在封锁特定商户时常常遭遇强烈阻力,有时因为既有商业协议将商户的便利性置于客户要求之上。
• 依赖电子邮件处理执法请求会留下危险漏洞,因为电子邮件协议缺乏通用的发件人验证机制,甚至".gov"域名也可能被伪造或篡改。
• 针对法律请求的验证流程常因依赖请求本身提供的信息而失效,而不是使用经验证的独立联系方式或标准化的安全提交门户。
• 现代金融科技公司常因优先追求增长和"快速行动"而非健全的安全措施而受到批评,这使它们容易成为社会工程攻击的目标;相比之下,传统机构通过更保守(尽管显得笨拙)的验证程序可能更能抵御此类攻击。
• 全面自动化的客服系统广泛采用反而加剧了安全事件,因为这些机器人常用模板式答复来搪塞有关泄露的询问,导致用户难以获得透明信息。
• 身份验证趋势(例如强制采集自拍和证件扫描)会存储大量敏感个人信息,这些数据在初次了解客户(KYC)流程完成后长期构成隐患。
• 监管环境造成一种"两难":机构在法律上被要求配合执法请求,但自身往往缺乏处理敏感数据所需的安全、经认证的基础设施。
• 安全专家建议,合法请求应依赖事先公布的沟通渠道、强制验证案件编号,并严格限制非紧急查询所能提供的数据范围。
• 一系列运营争议(从糟糕的反洗钱控制到激进的招聘做法)让人们认为某些金融科技公司本质上更容易出现治理与安全失误。
• 涉及身份或交易历史的数据泄露尤其令人担忧,因为与密码不同,泄露的生物识别或财务历史一旦曝光,就难以更换或重新保护。
此次讨论反映了人们对现代金融科技效率与陈旧、不安全行政做法相互交织的更广泛焦虑。普遍共识是,依赖电子邮件处理敏感的法律请求是一种系统性失败,凸显了数字创新与许多政府机构仍在使用的过时安全协议之间的鸿沟。有人认为金融科技公司因"快速行动"的文化和以发展优先的策略而特别脆弱,但也有观点指出这是行业性问题,且因缺乏安全数据传输的充分监管标准而被放大。归根结底,这一事件提醒人们,数字银行的便利往往掩盖重大潜在风险,一旦机构保障出现失误,最终承担后果的通常是客户。 • Financial institutions often face significant friction when blocking certain merchants, sometimes due to pre-existing commercial agreements that prioritize merchant convenience over customer request.
• The reliance on email for law enforcement requests creates a dangerous vulnerability, as email protocols lack universal sender verification, and even ".gov" domains can be spoofed or compromised.
• Verification processes for legal requests often fail due to reliance on information found within the request itself, rather than using verified, independently sourced contact channels or standardized, secure submission portals.
• Modern fintech companies are frequently criticized for prioritizing growth and "moving fast" over robust security, leaving them susceptible to social engineering attacks that legacy institutions might avoid through more conservative, albeit clunky, verification procedures.
• The widespread adoption of fully automated customer support systems exacerbates security incidents, as these bots often deflect inquiries about breaches with generic, canned responses, making it difficult for users to receive transparent information.
• Identity verification trends, such as mandatory "selfie" captures and document scans, store sensitive personal information that remains a liability long after the initial KYC process is complete.
• Regulatory environments create a "damned if you do, damned if you don't" scenario where institutions are legally required to comply with law enforcement requests, yet those same agencies often lack secure, authenticated infrastructure for handling sensitive data.
• Security experts suggest that legitimate request protocols should rely on pre-published communication channels, mandatory case reference verification, and strict limitations on the scope of data provided in response to non-emergency inquiries.
• A history of operational controversies, ranging from poor anti-money laundering controls to aggressive hiring practices, contributes to a perception that some fintechs are fundamentally more prone to management and security failures.
• The persistent nature of data breaches involving identity or transaction history is particularly alarming, as unlike a password, leaked biometric or financial history data cannot be easily rotated or secured once exposed.
The discussion reflects a broader anxiety regarding the intersection of modern fintech efficiency and archaic, insecure administrative practices. There is a clear consensus that the reliance on email-based communication for sensitive legal requests is a systemic failure, highlighting a gap between digital innovation and the outdated security protocols used by many government agencies. While some argue that fintechs are particularly vulnerable due to their "move fast" culture and prioritized growth, others note that the problem is industry-wide and exacerbated by inadequate regulatory standards for secure data transmission. Ultimately, the incident serves as a reminder that the convenience of digital banking often masks significant underlying risks, leaving customers to bear the consequences when institutional safeguards falter.