pull down to refresh

As if you needed any further evidence that KYC is the illicit activity, here are two tweets about the recent Revolut hack -- the first is about how it was achieved and the second is about its scope. Even if we granted that KYC could exist, it is clear that governments are leaky seives and there is zero chance that they will be able to safely store the data they have access to.

Our investigations team at Duel is in contact with the Revolut hacker, and we've found out a lot more about how he did what he did.
  • The hacker got access to government employee accounts using an infostealer. After gaining access to an employee's email, they would log in, add their own recovery email, start to log everything, and silently listen in.
  • To not get caught, they would instantly delete any email sent that was not intended for the original employee. The inbox was checked 24/7 for any new response to the hacker's sent emails. Upon receiving one, the hacker would instantly download it as a .eml and delete it before the original employee noticed
  • The hacker says that at first he used to forge court orders (presumably when targeting other companies), but quickly realised that this wouldn't work for Revolut. After some research, they decided the best entity to target was Revolut's Lithuania-based Revolut Bank UAB, which would respond to a European Investigation Order (as shown in the images).
  • With this stolen email, the hacker sent one request, originally 5 months ago, attached below. Revolut believed it, thinking it was the Italian government, and complied with the order.
  • From the hacked email, the hacker was able to control and end emails that looked like they genuinely came from multiple Italian government email addresses.
  • The hacker continuously sent out requests over the course of 5 months. Not once did Revolut ask questions or not send over the information. In one incident, the hacker accidentally sent the wrong document. Instead of realising what was going on, Revolut's support guided them on what to change (shown in an image below)
We remain in contact with the hacker and we've requested exclusivity of information related to the story to be kept with Duel. We believe it is in the public's best interest for EVERY piece of information related to this to be released, so that the extent of Revolut's failure can be brought to light, as well as the sheer stupidity of the manner in which the KYC paradigm is currently conducted.

The Duel team hopes that Revolut will be held accountable for their lack of due diligence and betraying their customers in such a severe manner, especially given the breadth and depth of the breach. Lives are now at risk. I'm personal friends with one of the victims, and he'll probably have to move houses due to the continued (credible) kidnap threats.

We hope to soon release a much more detailed article with more information, emails, screenshots and more.

source

The scope of the Revolut data breach is stunning.

Hackers are confirmed to have bank statements spanning back YEARS, which can disclose a surprising amount of information about a person.

Taking the example of Felix Romer (this analysis has been posted with his consent), there's a lot to unpack.

The bank statements released by the hackers go from Jan 2024 all the way until July 2026. Firstly, you can establish all of the destinations Felix frequents: Malta, Dubai, London, Bangkok, and more. It's a complete travel pattern dox, showing every point and place you went to. From the stores and restaurants, you can triangulate people's real locations pretty easily.

Felix also has expenses out to Reputation Rhino (a reputation management company), large payments to his girlfriend, payments to a payment processor known for adult content, and a charge to "Face IQ" for a "facial attractiveness assessment." The point here is that everyone on the list will have their most intimate and secret purchases exposed.

The more normal purchases: tens of thousands to Cartier, Chopard, luxury spas and clinics, Bryan Johnson's Blueprint, fine dining... While not directly harmful, provide a treasure trove of data into Felix's lifestyle, location, and viability as a target for all sorts of schemes, both online and irl.

There's also payments to various people. His girlfriend and assistants, but also smaller payments to unknown women. While in Felix's case, there's nothing he wants to hide, this could be absolutely disastrous for other high net worth individuals, as it reveals all of their closest contacts. Their best employees, girlfriends, mistresses, family members they care about, all of those are seen through a rich person's payments.

So other than just someone's ID and address... Revolut has essentially leaked their closest people and closest ties, some intimate secrets, granular location data derivable through cross referencing the locations of purchases made, the ability to cross reference existing evidence or leads against confirmation from the bank statements, and various other known and unknown risks that will compound through the lives of these unfortunate individuals for many years to come.

It's staggering how negligent Revolut has been with this data, how they didn't disclose the breach immediately when they knew it had happened, the sheer scope of the danger they have put their customers and their customers' loved ones in, and also how little we still know.

source

471 sats \ 9 replies \ @optimism 20h
The hacker got access to government employee accounts using an infostealer.

I had a call with someone today who (correctly) asked me why I was sounding hesitant to talk to them, and whether I didn't trust them. I told them that because they report everything I say into their Salesforce database, it is not a matter of trust towards them, but that I don't trust their security. Thus, we're communicating on "what in the movies they call a need-to-know basis".

They got pretty pissed at me.

reply

I wonder how many EU employees have access to an email address to which financial institutions are legally obligated to provide customer KYC data. Clearly, at least one of them was compromised. I certainly don't believe that no other email addresses are compromised.

Also, this went on for five months!

It really is astounding to me that lawmakers do not see the trainwreck they are creating when they continue to require ever more KYC. And for what? So they can catch some criminals...usually who have already committed some other crime which the state was incapable of preventing or successfully prosecuting them for.

Is law enforcement's reasoning: "look, we are really bad at our job of preventing crimes like human trafficking and ransom and all kinds of other things, and we don't have any way to actually catch people who commit these crimes, so what we are going to do is ask you all to take on a huge extra risk and expose your personal identifying information and financial details to millions of other people so that we can hopefully identify some of these criminals we failed to catch. Oh, and we don't know how to keep it secure. And we will hold you accountable if someone else uses your information to do something we don't like."

God damn. This system is broken.

reply
407 sats \ 2 replies \ @optimism 18h
at least one of them was compromised.

How I read it, that was low effort and more than one.

It's not even about the number of employees per se. You need one then you can privilege escalate inside azure/outlook because MS Azure, at least in the EU, rarely patches fast, and throws out many issues as "not-a-bug". The entire EU (and almost every national govt inside the EU) runs more than 70% of their infra on Azure. So within that environment, you basically only need to get in once. I've been given 2 demos in the past 18 months of what it's like on Azure mail servers in terms of exploitable "not-a-bug"s, and it's not pretty. So all you need is some dude with a login, or even hotter and concurrently easier targets: sysadmins.

The main issue is digital systems security across the entire chain. It's not just some Estonian regulator (or the DMV) that has poor security - that's just low hanging fruit. Everyone has poor security, even the people with high-end security, because the chains are interdependent and all you need is one weak link. That's why I claimed that after Bitcoin comes the banks. And here we are. The guy didn't even have to hack the bank.

law enforcement

I know a bunch of people in LE and the honest, knowledgeable, hard-working people among them are often as much against this crap as you or I. Same goes mostly for the few natsec people I know, on both continents. They're often very much aware of how poor the systems are, how bad the requirements were at the start and how even these were higher standards than what got delivered. In all aspects really, because it's not just security, it's also in the breadth of effectiveness of what these systems were intended for.

This system is broken.

Most of these ideas come from people that want to be re-elected / re-appointed their next term and thus cannot "look weak" by not addressing something for the sake of keeping the greater evil out, because it will be narrated against them no matter what. That means that we get completely leaky mandatory processes, that can often not be enforced and often cannot be secured without trustmebro bullshit. The KYC crap is one of the things where this is going very wrong very quickly now. It's not much worse in Europe than in the US tho, as the prescribed chains of information dissemination have, especially since 2020, been heavily maldesigned everywhere. I've since then worked on projects on both sides on the Atlantic where PII non-confidentiality is mandated rather than stricly forbidden.

reply
175 sats \ 1 reply \ @Scoresby OP 17h
Everyone has poor security, even the people with high-end security, because the chains are interdependent and all you need is one weak link.

I find this really depressing. The sense that if I have one weak link in my security, it's all for naught is scarily apparent to me in Bitcoin. But I know that much of my life is even more exposed. I'm not looking forward to navigating all this in the coming years.

reply
222 sats \ 0 replies \ @optimism 17h

The nice thing is though that no bank will send data to a government without an in-person visit for a while now!

reply
It really is astounding to me that lawmakers do not see the trainwreck they are creating when they continue to require ever more KYC.

...oor, alternative hypothesis: it was on purpose and they knew precisely what they were doing

reply
166 sats \ 1 reply \ @Scoresby OP 16h

but how does this mess benefit them? At this rate, kyc data will be so freely available that it will be entirely useless. So what's the play? Push us all towards biometrics?

reply

no clue. I don't really believe it, either.

Can't square this with anything else than malice. Stupidity and oops just doesn't seem to cut it

reply
82 sats \ 1 reply \ @optimism 16h

It doesn't take inside information to figure out that they're clueless though. But since you're a prestigious scholar and all, I'm sure you can get your butt into a Brussels expert group and report for us.

Maybe we can ~DIY you some spy cams and make a video show out of it. Undercover Stacker.

reply

that'd be insanely fun

reply

Insane that they are trying to make Revolut pay... like, what else was the company supposed to do but comply with an official data request order?? Would be great if some company like Revolut had the cojones to stand up to the KYC regime but whatever; a kid can dream

reply

Revolut are a truly useless shitty product.
Worse imo than standard fiat debt slavery bankers, and that's saying something.

reply
5 sats \ 1 reply \ @WaxLuw 20h -30 sats

Yeah, that’s scary. One hacked email and suddenly years of people’s bank data are out there. Kinda makes you think twice about giving all that info away.