xxx
British fintech Revolut confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain.
The exposed data included customers’ identity and contact details, including their birth date, postal and email addresses, and phone numbers, as well as copies of their identity documents including passports and driver’s licenses, according to a notification emailed to affected customers and reviewed by TechCrunch. The data may have also included verification selfies, account statements, and transaction histories, the firm said in its notification.
From: Revolut confirms customer data breach through fake government requests | TechCrunch.
xxx
I had a vague memory of something similar having happened before, and a quick trip to LLM land confirmed by suspicions. A few years ago, hackers tricked tech companies, ranging from Apple and Meta to Discord, into turning given out sensitive personal data by complying with fake emergency data requests (EDRs) seeming to come from official sources.
(These EDRs are a shortcut that tech companies built for genuine crises, such when someone has been kidnapped. Law enforcement can ask a platform for detailed data such as names and phone numbers without the warrant. Companies built these channels on trust: a request arriving from a verified law-enforcement email domain is usually honored within hours.)
Hackers soon discovered they could obtain access to real law-enforcement email accounts via the usual means (eg, phishing) and then submit EDRs concerning bogus emergencies. Since the requests came from authentic government accounts the companies complied and the compromised data was used to enable significant crimes, including SIM-swapping attacks against cryptocurrency holders, which is I am sure the sort of thing that the Revolut data will be used for.
While I was thinking about this, I got a text from my pharmacy to say that there was a message waiting for me. The text did not contain a link, which is sound security practice. So I went to the pharmacy web site and logged in to read the message waiting for me. Surely Scotland Yard could come up with some similar system? In fact, surely someone already has?
I am not an expert on law enforcement systems, but it took about two seconds’ googling to discover that such system already exist.
Kodex and its main competitors
Kodex Global is a platform that verifies law-enforcement and government identities before companies release user data in response to legal requests — subpoenas, warrants, court orders, and emergency disclosure requests. It maintains a vetted global network of tens of thousands of agencies and investigators, and offers case management, secure exchange, audit trails, and cost-recovery tools for the crypto, financial-services, and telecom clients that use it.[kodexglobal]
Its closest direct competitors, per industry trackers, are Casepoint, Cytrio, and Virtru — all of which touch adjacent parts of the same problem: legal-request intake, data-privacy compliance, and secure encrypted file exchange respectively, though none replicate Kodex’s specific focus on verifying law-enforcement identity itself.[cbinsights]
Beyond dedicated vendors, the biggest “competitor” in practice is that large platforms — Meta, Google, Apple — mostly built their own in-house Law Enforcement Response System (LERS) portals rather than outsourcing verification to a third party, requiring police to register an account tied to a real agency before any request is processed. So the market splits between a few specialist verification platforms like Kodex and big companies simply running their own closed, proprietary equivalent.[ministryofcyberaffairs]