POST Why is Revolut storing copies of identity documents:

You have undoubtedly read the story about Revolut. The fintech has confirmed that it disclosed sensitive customer information to an “unauthorized third party” after receiving fraudulent requests sent from a legitimate government agency email domain. The exposed data included customers’ personally identifiable information (PII) including contact details, birth date, email, address and phone numbers. Worse, it also included copies of their identity documents including passports and driver’s licenses. The data “may” have also included verification selfies, account statements and transaction histories!

I had a vague memory of something similar having happened before, and a quick trip to LLM land confirmed by suspicions. A few years ago, hackers tricked tech companies, ranging from Apple and Meta to Discord, into turning given out sensitive personal data by complying with fake emergency data requests (EDRs) seeming to come from official sources. Hackers soon discovered they could obtain access to real law-enforcement email accounts via the usual means (eg, phishing) and then submit EDRs concerning bogus emergencies. Since the requests came from authentic government accounts the companies complied and the compromised data was used to enable significant crimes, including SIM-swapping attacks against cryptocurrency holders, which is I am sure the sort of thing that the Revolut data will be used for.

While I was thinking about this, I got a text from Amazon to say that there was a message waiting for me. So I went to Amazon and logged in to read the message waiting for me. Surely the FBI or the police or whoever could come up with some similar system? In fact, surely someone already has? In fact, while I am not an expert on law enforcement systems, but it took about two seconds’ googling to discover that they already have.

(In fact it turns out that there are several! Kodex Global, Casepoint, Cytrio and Virtu, amongst others).

The platforms (eg, Meta, Google and Apple) tend to run their own in-house Law Enforcement Response System (LERS) portals rather than outsourcing verification to a third party, requiring police to register an account tied to a real agency before any request is processed, which seems sensible. I wonder if they might also demand 2FA for any account that presents a request.

You do have to wonder why, of course, Revolut are storing all of this toxic waste in the first place. I can see why Revolut might need to store 

The Real-Time Rail Paradox: Instant Payments, Real Risk

I remember talking about this with Rowan Akin-Smith at EBA Day earlier this year. Rowan is with Vyntra, one of. my advisory clients, and he’s written a good piece about this in the context of Canada’s immininet instant payments launch. Noting that overly cautious controls can introduce friction that erodes customer confidence almost as effectively as a fraud does, he goes on to say that the banks managing this well will be be the ones “making better decisions earlier, so legitimate payments keep moving while genuine risk gets caught”. Indeed.

So what is needed to make better decisions? We all know the answer to this is: it’s data, shared data.

Revolut Handed Customers’ Passports and Bitcoin Records to a Fake Government Request. Are You Affected?

xxx

Quick Read

Revolut’s compliance team released customer files to an attacker using a spoofed government email domain, exposing IDs, KYC selfies, and Bitcoin histories.

No funds were stolen and no systems were breached, but the stolen files enable highly personalized phishing attacks against identified customers.

The limited, targeted data set suggests attackers deliberately chose high-net-worth accounts; Revolut is notifying affected customers individually rather than issuing a broad disclosure.

From: Revolut Handed Customers’ Passports and Bitcoin Records to a Fake Government Request. Are You Affected?.

xxx

POST The future of shopping is new business models

A recent Mastercard survey of 13,000 parent-and-teen pairs across 13 European markets together with Israel and the UK found that a third of all teenagers already use AI on a weekly basis to find and compare products and services, compared to a fifth of their parents. What’s more, more than a third say that they would happily hand over to a fully AI-run shopping assistant that chooses (and, crucially, pays for) products and services.

Well, yeah, whatever, I can hear you thinking, of coruse they do. But based on some workshops I’ve been in recently, I’m not sure if the implications of this transition are really being taken on board by strategists across commerce and finance. Hence I was very interested to read 

The Real-Time Rail Paradox: Instant Payments, Real Risk

xxx

For businesses, this isn’t an abstract infrastructure issue. Payroll, supplier payments, liquidity management, and customer refunds all increasingly depend on an institution’s ability to prevent, detect and recover from disruption in real time. Treasurers are scrutinizing how banks communicate during incidents, how quickly they recover, and how transparent they are about what went wrong. Increasingly, reliability will be measured by a less quantifiable standard: confidence.

From: The Real-Time Rail Paradox: Instant Payments, Real Risk.

xxx

The stablecoin era: The history and future of stablecoins: Ingenta Connect

There’s a good paper in the latest issue of the Journal of Payments Strategy & Systems 20(2), pp. 179-193 (Summer 2026). It’s called “The stablecoin era: The history and future of stablecoins” and it’s written by me and noted fintech commentator Simon Taylor. A “preview” presentation of the paper went down so well at Money 20/20 in Amsterdam earlier this year that I decided to head out to Simon’s upcoming Fintech Nerdcon in San Diego on November

The untold story of Stripe, the secretive $20bn startup driving Apple, Amazon and Facebook | WIRED

When Tim Berners-Lee and his team were designing the World Wide Web, they included error codes such as “500: internal server error”, or “404: page not found”. One such code is “402: payment required”. The original intention was that this code would be used to transact using digital cash or micropayments. It was never implemented and the Collisons argue this is the reason tech went from an equal access opportunity to an oligopoly controlled by five companies now worth more than $3 trillion.

Crypto gang who held Bitcoin millionaires captive and tortured them are jailed for more than 30 years | Daily Mail Online

xxx

Five members of a London gang who held two French cryptocurrency millionaires captive and forced them to strip naked have been jailed for more than 30 years.

The two men’s lifestyles of excess were said to have made them targets for extortion, with the pair kidnapped while visiting London from France.

The pair, who were aged in their 20s and had a combined fortune of £50million, were captured by three masked men armed with guns after travelling to buy cannabis.

From: Crypto gang who held Bitcoin millionaires captive and tortured them are jailed for more than 30 years | Daily Mail Online.

xxx

Ant International, Visa and Mastercard to develop ‘Know-Your-Agent’ framework

xxx

Ant International, Mastercard, and Visa have begun collaboration on a Know-Your-Agent (KYA) interoperability framework, designed to help card networks, digital wallet ecosystems, agent platforms and marketplaces streamline agent onboarding and identification across networks.

The three organizations have previously rolled out their respective protocols — Visa’s Trusted Agent Protocol, Mastercard Verifiable Intent, and Ant International’s Agentic Mobile Protocol — and will now explore opportunities to work towards common principles.

To achieve this, the companies will work through BuildFin.ai, an industry collaboration platform convened by the Monetary Authority of Singapore (MAS) with the aim of developing common approaches for AI agent verification, accountability and risk management across payment ecosystems in Singapore.

From: Ant International, Visa and Mastercard to develop ‘Know-Your-Agent’ framework.

xxx

Design a site like this with WordPress.com
Get started