Privacy
Revolut handed it all over, and the rules say it was right to
Passports, selfies, addresses, IBANs, full transaction histories. The request was forged. Nobody was required to check.
Lyudmyla Kozlovska spent the weekend making an argument that nobody on this page wanted to have, and the facts did most of the work for her.
This week #Revolut confirmed it handed over customers' passports, verification selfies, home addresses, IBANs and full transaction histories, including #Bitcoin, to a fake government request.
The mechanism is the part worth sitting with. The email came from a real government agency's domain, and Revolut complied because the rules told it to.
Under FATF rules written into US, EU and UK law, a regulated institution must keep this material and produce it promptly on a state request — with fines in the millions for delay, and none for handing over too much.
And then the sentence that turns a breach into a design: Nobody is required to check whether the state behind the request is legitimate.
Her reading of who benefits is unsentimental: The hackers and criminals are proxies of authoritarian governments.
The same pattern, she argues, now points at the data of Western citizens because it is free, easy, and nobody is held to account for it.
waxwing reported the only personal remedy available and its limits: Closed my Revolut account earlier this year, seems like I was a bit too late. Who am I kidding, they're all exactly the same.