Revolut's customer got 30000 chf stolen


Sorry for the bad source first :slight_smile:

Anyway, apparently he had a limit of 15000chf but somehow someone was able to steal more than that.

He had his credit card connected to it (biig mistake) and wasn’t able to lock the card in time.

Revolut apparently isn’t helping/giving back anything. Let’s see what happens…

3 Likes

You are able to connect to credit card? Every time I top up, I need to validate a 3d Secure code

I don’t know and I don’t even want to try :smiley:

1 Like

Depends on your credit card I guess, with the cumulus it doesn’t ask for anything and you don’t notice it when it happens as well so it can be pretty bad.

so it seems they hacked his sim card, thus where able to login to revolut on his behalf. once that is done the rest is peanuts. they saw the ubs credit card registered for auto topup. then removed the 15000 limit (they had full revolut access). then started transferring money (dirham apparently) to some other place: perhaps a bank account somewhere or used the revolut credit card number (which is shown in the app, including cvv) to upload another service who knows.

i guess the key takeaway is: getting your sim card hacked is horrible. and ok, registering another credit card for auto topup is not the best idea either…

So from a security point of view is seems important to avoid any sim hacks. which might be resolved by having (a) dedicated sim card(s) for any (each?) of these online services…?!

1 Like

re sim card hacks: these phishing attacks only really work if they have your sim number, right? so why do they have it? because either someone of your contacts gave app permissions to access their contacts/phonebook where you where listed - or they hacked a web service where you gave your sim number. in both cases having dedicated separate sim cards only for the purpose of 1 or a few services and without sharing the number with anyone would help.

except if revolut itself would have a security leak indeed…

Thanks for sharing, I didn’t see this news.

That’s a good reminder that we should never save our credit card into the app. I just removed mine and I will add it / remove it every time I need. Since it’s once or twice a month, it’s not a big deal.

Isn’t it possible that some malware spied on the guy when he typed his revolut password and then they remote controlled his phone? Swisscom says the SIM wasn’t hacked and I believe it is a 1000 times easier to make people download malware than to hack a SIM…

1 Like

Wow, this is interesting. I was on the opinion that hijacking a sim card is mostly a US thing, that can not happen in CH, because people ask for ID. And Swisscom is saying it didn’t happen.

I use a corporate phone, that is technically registered in the name of my employer, which I am not sure if it is easier or harder to hijack.

1 Like

could be as well yea. you’re right swisscom says there was no sim hack so your version could be more realistic…

I don’t know exactly how sim hacking works, but IMHO it’s not easily doable. Also I have no idea which service might ask for your SIM information. Maybe all that dumb app that ask for “telephone permission”.
(I might start to rant how f$# the permissions on Android/iOS are both from the technical point (storage? why not more fine grained?) and from the way it is used (you can’t use the flashlight app if you don’t give contact permissions…)

One thing it’s not clear is if the guy had a second sim linked to the first one. For example in his car. I don’t know exactly how it works and how Android/iOS identify phones, The only thing I know is that swisscom can give you a second SIM card that will answer to the same phone number of the main one.

I was referring to https://en.m.wikipedia.org/wiki/SIM_swap_scam

but if swisscom says there was no swap then this can probably ruled out here

Even if the sim card was hacked as @male described. You need a password (or fingerprint) to access the Revolut app.
On my knowledge, a hacked sim card can’t control an application on the phone.

1 Like

Is it known which OS did the guy use? Because many people have their credit cards added to Apple Pay on iOS. For example, I added my Revolut Card, although I never even used it like this, paying with the phone. Theoretically, Apple Pay requires you to use Face ID and double click the button, but I wonder what else can be hacked…

Seriously, the tech World we live in makes me really anxious, most of my possessions seem so virtual.

Seems like this was a phising attack: https://insideparadeplatz.ch/2019/08/22/konto-hack-bei-revolut-alles-viel-schlimmer/

1 Like

So the guy has a cyber security company and gets hacked by phishing?

1 Like

Second that. I got myself SMS asking to login to my account via url which looked quite compelling and have to admit it takes few seconds to start questioning if this is legit… sad for other people are not aware of that.

…or it all started because the first involved with the news was connected to some other startup in the field… or big bank.

there is also a ‘forgot your passcode’ option where they probably send you a temporary passcode to your phone. just saying

So dude puts his revolut credentials into some random link he got via sms and then blames revolut for loosing his data?

If this was actually a SIM-Swap this would have been pretty worying since that would be the first one I have seen in the wild in switzerland. But as it looks this was just a regular old phishing attack.

Cyber-security is a big field, maybe his company specializes in foresics or wireless or something completely unrelated from phishing (or he is some kind of non technical manager or something).

2 Likes