KYC is good for humanity and also super secure and also has never lead to anything bad happening and also can’t possibly be exploited in any way
thisisfine.gif
‼️ BREAKING: Our investigations team at Duel is in contact with the Revolut hacker, and we've found out a lot more about how he did what he did.
- The hacker got access to government employee accounts using an infostealer. After gaining access to an employee's email, they would log in, add their own recovery email, start to log everything, and silently listen in.
- To not get caught, they would instantly delete any email sent that was not intended for the original employee. The inbox was checked 24/7 for any new response to the hacker's sent emails. Upon receiving one, the hacker would instantly download it as a .eml and delete it before the original employee noticed
- The hacker says that at first he used to forge court orders (presumably when targeting other companies), but quickly realised that this wouldn't work for Revolut. After some research, they decided the best entity to target was Revolut's Lithuania-based Revolut Bank UAB, which would respond to a European Investigation Order (as shown in the images).
- With this stolen email, the hacker sent one request, originally 5 months ago, attached below. Revolut believed it, thinking it was the Italian government, and complied with the order.
- From the hacked email, the hacker was able to control and end emails that looked like they genuinely came from multiple Italian government email addresses.
- The hacker continuously sent out requests over the course of 5 months. Not once did Revolut ask questions or not send over the information. In one incident, the hacker accidentally sent the wrong document. Instead of realising what was going on, Revolut's support guided them on what to change (shown in an image below)
We remain in contact with the hacker and we've requested exclusivity of information related to the story to be kept with Duel. We believe it is in the public's best interest for EVERY piece of information related to this to be released, so that the extent of Revolut's failure can be brought to light, as well as the sheer stupidity of the manner in which the KYC paradigm is currently conducted.
The Duel team hopes that Revolut will be held accountable for their lack of due diligence and betraying their customers in such a severe manner, especially given the breadth and depth of the breach. Lives are now at risk. I'm personal friends with one of the victims, and he'll probably have to move houses due to the continued (credible) kidnap threats.
We hope to soon release a much more detailed article with more information, emails, screenshots and more.