Sardine named a Leader in The Forrester Wave™: Financial Crime Management Solutions, Q3 2026

Learn More
Fraudology

Una estafa de phishing por correo electrónico gubernamental y novedades sobre la filtración de documentos de identidad escaneados

28 min

Bienvenidos de nuevo a Fraudology.

Este es un episodio en solitario y esta semana tengo dos historias para ustedes. Quería retomar el tema de la filtración de datos de escaneos de documentos de identidad que Frank McKenna y yo comentamos la semana pasada: cuál es la situación actual, si todavía deberíamos estar preocupados y qué implica la filtración de datos de licencias de conducir para la prevención del fraude en los procesos KYC de cara al futuro.

Y después quería abordar una de las mayores historias de fraude de esta semana. Esta acaba de conocerse y quería contártela lo antes posible. Revolut fue víctima de una estafa de phishing mediante un correo electrónico gubernamental que parecía proceder de un dominio .gov legítimo. La solicitud fue atendida. Se facilitaron datos de clientes. Y para ello no fue necesario vulnerar en absoluto los sistemas de Revolut. Bastó con un correo electrónico falsificado que parecía lo bastante auténtico como para pasar los controles.

He estado hablando sobre esto con mis fuentes de inteligencia sobre amenazas de fraude, entre ellas una persona con experiencia en una de las agencias gubernamentales de tres letras. Lo que me contó cambió por completo mi forma de ver este incidente. Vamos a analizarlo todo.

Este es un episodio de noticias sobre fraude, y hoy voy a ser breve. Entremos en materia.

Lo que escucharás en este episodio:

  • Actualización sobre la filtración de datos de escaneos de documentos de identidad. En qué situación se encuentra ahora la base de datos de 153 millones de licencias de conducir, por qué es importante la operación del FBI para desmantelarla y si aún debemos considerarla una amenaza activa.
  • Por qué la filtración de escaneos de documentos de identidad fue tan peligrosa para la detección del fraude en los procesos KYC y del fraude con documentos de identidad. Y por qué la mayoría de las empresas de verificación no la habrían detectado.
  • Cómo se manifiesta en la práctica el riesgo de filtración de datos en la cadena de suministro y qué cláusulas contractuales con proveedores debería establecer toda institución financiera.
  • Explicación del incidente de fraude relacionado con una solicitud gubernamental a Revolut: qué datos se divulgaron, qué puede hacer un estafador con ellos y por qué podrían utilizarse para el robo de identidad y el espionaje.
  • Por qué es más difícil suplantar un dominio de correo electrónico .gov de lo que parece, qué es una tarjeta CAC y por qué es importante para la seguridad del correo electrónico gubernamental, y qué cree realmente mi fuente de inteligencia sobre amenazas de fraude que ocurrió.
  • Las tres explicaciones más probables de esta estafa de phishing mediante correos electrónicos gubernamentales, incluida la posibilidad de que se trate de un fraude perpetrado por un adversario extranjero, lo que cambia por completo el panorama.
  • Cómo prevenir el phishing mediante correos electrónicos gubernamentales en su institución financiera, utilizar herramientas de autenticación de correo electrónico y autenticación de dos factores para acceder a bandejas de entrada con información confidencial, y capacitar al equipo que gestiona las solicitudes gubernamentales de información.
  • Por qué se volverá a intentar este tipo de fraude de suplantación de dominios de correo electrónico y qué medidas concretas deben implementar los equipos de prevención del fraude de los neobancos.

Deberías escuchar este episodio si:

  • Trabajas en las áreas de fraude, cumplimiento normativo o riesgos de un banco, neobanco o institución financiera y quieres entender qué implica realmente el incidente de Revolut para tu equipo.
  • Son responsables de prevenir el phishing en una entidad financiera y buscan recomendaciones prácticas que puedan aplicar esta misma semana.
  • Quieren entender cómo funciona el fraude por suplantación de organismos gubernamentales y por qué un correo electrónico con dominio .gov no garantiza que sea legítimo.
  • Está evaluando los contratos con sus proveedores en cuanto a las cláusulas de responsabilidad por filtraciones de datos en la cadena de suministro y desea contar con un marco que le indique qué incluir.
  • Trabaja en la prevención del fraude en procesos KYC y quiere entender por qué la filtración de datos de escaneos de documentos de identidad fue especialmente peligrosa para la verificación de dichos documentos.
  • Sigues las noticias sobre fraude y quieres conocer la opinión de un profesional sobre lo que realmente ocurrió con Revolut, no solo la versión viral de LinkedIn.
Notas del episodio

La filtración de datos de escaneos de documentos de identidad: situación actual

Frank McKenna y yo hablamos de esto la semana pasada. La novedad es que, al parecer, el FBI lo retiró rápidamente. Las copias publicadas en foros de la web oscura que identificaron los contactos de inteligencia sobre amenazas de fraude no contenían realmente la base de datos completa. Comprar licencias individuales al precio indicado habría costado más de 15.000 millones de dólares, por lo que es más probable que los anuncios de imitación fueran meras fachadas sin contenido que datos reales.

¿Estamos a salvo? Sí y no. La lección más importante tiene que ver con el riesgo de filtraciones de datos en la cadena de suministro. Los contratos con sus proveedores son importantes. Sepa quién tiene la responsabilidad de notificar una filtración. Sepa si su proveedor debe asumir los costes de supervisión crediticia y reparación. Sepa hasta qué punto podría verse afectada la reputación de su marca si una filtración de un proveedor expone los datos de sus clientes. Deje estas condiciones por escrito antes de que las necesite.

El incidente de fraude mediante solicitudes gubernamentales a Revolut

Esta noticia salió a la luz el sábado 12 de septiembre. Estoy grabando esto al día siguiente. Puede que haya novedades para cuando escuchen esto, pero esto es lo que sabemos.

Revolut recibió una solicitud de lo que parecía ser una agencia legítima del Gobierno de Estados Unidos, con credenciales válidas de autenticación de dominio. La solicitud fue atendida bajo la creencia razonable de que era auténtica. Los datos divulgados ofrecen un perfil completo de una persona que puede utilizarse para cometer fraude financiero o incluso espionaje, lo que hace que la posibilidad de un fraude perpetrado por un adversario extranjero sea tan relevante.

Mi fuente de inteligencia sobre fraudes me dijo que es extremadamente improbable que se haya producido una vulneración real de un sistema .gov. Según su análisis, lo más probable es que un adversario extranjero creara un dominio de correo electrónico que a simple vista parecía legítimo, pero que contenía un carácter sustituido. También podría haberse tratado de un agente interno del Gobierno que presentó una solicitud sin seguir los canales adecuados, o de un empleado público que actuó de forma maliciosa utilizando credenciales reales. No fue una extracción masiva de datos. Afectó a un reducido número de personas muy concretas. Fue una operación de inteligencia, no una red de fraude.

Cómo prevenir el phishing mediante correos electrónicos gubernamentales en su institución financiera

El equipo que gestiona las solicitudes gubernamentales de información es su primera línea de defensa, del mismo modo que el servicio de atención al cliente lo es frente al fraude dirigido a los consumidores. Deben saber que una dirección de correo electrónico con el dominio .gov no basta para autenticar una solicitud. Necesitan formación sobre el fraude mediante la suplantación de dominios de correo electrónico, sobre cómo identificar las señales de urgencia en una solicitud fraudulenta y sobre cuándo escalarla antes de atenderla.

En cuanto a las herramientas, invierta en un sistema de autenticación de correo electrónico que analice los metadatos de los mensajes entrantes, no solo el dominio visible. La autenticación de dos factores para cualquier bandeja de entrada que gestione solicitudes gubernamentales confidenciales añade otra capa de seguridad. Además, revise de principio a fin su proceso de gestión de solicitudes gubernamentales de información. Si actualmente depende de que una persona lea una dirección de correo electrónico .gov y proceda sin más, ese proceso debe cambiar.

Por qué esto volverá a ocurrir

Si este ataque funcionó con Revolut, se intentará en otros lugares. Crear un dominio que parezca auténtico a simple vista requiere conocimientos técnicos, pero no recursos excepcionales. El beneficio potencial es enorme, tanto para fines de fraude como de inteligencia. Las instituciones financieras deben considerar que este tipo de ataque ya está consolidado y no es un caso aislado. Actualice su proceso de verificación de solicitudes gubernamentales, capacite al equipo que las gestiona e implemente las herramientas adecuadas de autenticación de correo electrónico antes de que el próximo intento llegue a su bandeja de entrada.

Conclusiones clave
  • La filtración de datos de escaneos de documentos de identidad parece estar contenida, pero aun así debemos actuar como si estos datos de licencias de conducir siguieran siendo accesibles. Ya se accedió a ellos una vez y las condiciones que lo permitieron no han cambiado.
  • El riesgo de una filtración de datos en la cadena de suministro no es teórico. El incidente relacionado con el escaneo de documentos de identidad es un ejemplo directo de cómo una brecha de seguridad de un proveedor puede exponer los datos de sus clientes. Sus contratos deben definir quién asume la responsabilidad de notificar la filtración, subsanarla y cubrir los costes derivados del daño a la reputación de la marca antes de que tengan que descubrirlo por las malas.
  • Es casi seguro que el incidente de fraude mediante una solicitud gubernamental dirigido a Revolut no se debió a una vulneración del sistema de correo electrónico del Gobierno de Estados Unidos. Para acceder a una bandeja de entrada .gov real, es necesario insertar físicamente una tarjeta CAC en el dispositivo. Esto hace que el spear phishing basado en credenciales contra una bandeja de entrada .gov sea extremadamente difícil.
  • Los datos divulgados en el incidente de Revolut incluyen documentos de identidad, imágenes de verificación facial y el historial completo de transacciones, incluidas las de Bitcoin, y permiten cometer delitos que van más allá del robo de identidad.
  • El equipo que gestiona las solicitudes gubernamentales de información en su institución es su primera línea de defensa. Las herramientas de autenticación del correo electrónico son el control técnico más importante que las instituciones financieras pueden implementar en este momento. Combine varias capas de defensa.
  • Si este ataque funcionó una vez, volverán a intentarlo.
Conclusión final

Dos historias esta semana, y ambas nos llevan a la misma conclusión. El punto más débil de sus defensas contra el fraude no suelen ser sus sistemas, sino el proceso que sigue una persona cuando algo parece legítimo. El escaneo de una licencia de conducir que supera todas las comprobaciones no es necesariamente auténtico. Una dirección de correo electrónico con dominio .gov no pertenece necesariamente al Gobierno. La brecha se encuentra en las personas y los procesos que hay detrás de esos pasos de verificación, y ahí es donde los estafadores seguirán atacando hasta que la cerremos.

Ambas historias tuvieron una versión que se difundió rápidamente y otra que se veía un poco distinta al profundizar un poco más. Las noticias sobre fraude son mucho más que los titulares. Son la comunidad que hay detrás de cada historia: la conversación, las conexiones y las respuestas auténticas que aportan personas reales. Gracias por estar aquí. Nos vemos la próxima semana.

Recursos y enlaces del episodio

Conecta con Karisse Hendrick | LinkedIn
Presentadora del pódcast Fraudology
Experta galardonada en fraude cibernético
Consultora en prevención del fraude en el comercio electrónico
Asesora de startups, conferenciante principal y
consultora para empresas de la lista Fortune 500

Episode transcript
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:07
Welcome back to Fraudology. I'm Karisse Hendrick. This is another solo episode. Um, we just had Frank McKenna on the podcast talking about the big ID scan uh data breach as well as digital arrests. This is something he's been talking about since uh the end of last year. And I mentioned on that episode that I was a little skeptical that they would ever come to the US or any western states but or countries, but they did. Um so that's a really interesting episode. Today I'm going to do a little bit of a followup on that ID scan breach and if we should still be worried and what we can do. And then I'm going to talk about uh the biggest news story of the week which um was with Revolute and it's a newer it's a really creative way of using GDPR against a company um to gain information and gain personal uh information that's usually private uh about specific individuals. So and this can be done at any financial institution. So, I'm going to dive into it a little bit. I'll share what it happened and then, you know, why we should worry about it and what it means and all of that. Um, so yeah, that's what today has in store for you. I'm just going to give you a 2 and 1/2 week notice that MFA is coming soon. I don't know how much boots on the ground I'm going to be able to record uh while at MFA just because got to be busy. Uh but I um will definitely be providing some behind the scenes uh information and that type of thing after the fact. Uh it won't be the same as attending obviously. And if you are, you know, in the Chicago area or you are just a short flight, you know, or you're willing to fly far uh to Chicago, it is October 6th and 7th in Chicago. Uh October 5th is a merchant-only um AI boot camp led by two people from PlayStation and one from GoDaddy uh sharing how the real world examples of how they use generative AI for fraud operations. And uh they're going to be providing some takeaways like some prompts and dashboards, things like that, so that it's very tactical and practical. And that's really what we want to provide with MFA is from each session something to walk away with. And I think we're gonna do that. I am so close to finalizing the agenda. I'm about three or four weeks later than I wanted to be. Uh but there were a few unforeseen circumstances. Um but you know that's okay. Uh thankfully we have you know a couple hundred people that are coming anyway.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
03:00
Um and we have some great brands coming and uh a very limited amount of solution providers uh as we don't sell vendor tickets. So, um, just want to give a little bit of an update with a 2 and 1/2 week countdown. I am, as my daughter would say, nervecited. I am both nervous and excited. Okay. Well, let's dive into the news. Uh, like I said, I'm just going to highlight two stories today. Uh, we're going to do a follow up on the ID scan breach that Frank McKenna and I talked about last week. It contained 153 million driver's licenses in the US. Uh we determined that that's about almost half of all uh adult the adult population in the US. So that's a lot of driver's licenses. Um primarily from car rental places and retailers, uh government, uh contracts, that type of thing. And the reason why it was so scary is because they're not just pictures of a driver's license. They're a scan of a driver's license. They include the holograph. They include, you know, all of that. Um, and if someone were to use that for, you know, KYC, like know your customer when they're onboarding an account, especially at a bank or, uh, as a seller, um, for a marketplace, that type of thing. They wouldn't be using a fake ID. So, most identity documentation verification companies, that's a quite the mouthful, uh wouldn't be able to detect that it was fraud. So, that was what was most scary. Um, what it seems like now, there haven't been as many articles about it, which is good. Uh, I do think it's in ID scans best interest for that to happen as well. Um, but we believe that it's been taken down by the FBI. Um, the FBI has said that it's been taken down. There were several copies made uh on in dark web forums that a friend of mine in fraud threat intel uh was able to find.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
05:06
However, those copies didn't actually contain the database because you had to pay $10 or $100 each for each driver's license. So, that would be assuming that someone paid 15.3 billion dollars. Am I doing the math right? Um to get all of those driver's licenses and then why would they make them public? So, chances are the copycats out there are just people that are selling uh kind of it's like selling the cover of a record but having no record inside, right? Or the cover of a book but no actual book attached. Um so we're not as worried. Um, are we safe? Yes and no. Uh, I would say we should still operate on the fact that these are out here. Um, I think that it's a little bit of a sigh of relief that the FBI took it down so quickly and that we haven't seen any more databases like this, but you just never know. Uh, and because they were accessed once, could they be accessed again? Hard to know. So, uh it's it's another good example of supply chain uh breaches and uh I talked a little bit about this on the last episode, but basically what that means is instead of going to your company directly, they go to your vendor and they breach your vendor. So, you really should have a lot of good contract language that keeps you safe from if this were to happen with a vendor. I know that there are various types of verbiage that you can uh have in those contracts. You know, some say that the vendor has to pay for credit repair or not credit repair but credit reports. Um the vendor has to own the the data breach. Others say that the merchant or the bank have to own the data breach. Um and when they own it, they have to do all the notifications to consumers. They have to offer the credit report, which is not much and doesn't do a lot, but it's something to provide a little bit of peace of mind to victims. Um, there's also the brand reputation cost and if you're going to have your vendor reimburse you for that. There's just a lot of different things that you can write in that contract. So, be very mindful of that. I think this was a very good example of the reason why that's important. So, as I mentioned, the biggest news story of the week uh broke on Saturday, September 12th. Uh full disclosure, I am recording this on the 13th, so just the day after. So, there may be more news coming out about this after I record. Uh so, you know, do a quick Google search or, you know, chatGPT it or whatever you want to do to learn the updates. But I think this is important because it's a new twist on a fraud scam and it's a new twist that we haven't really seen or heard of before. And whenever that happens, I want to get the news out as soon as possible so that it doesn't work anywhere else. Let me just pull up a notification that was post reposted on LinkedIn. So this is about Revolute. Revolute is a neobank that is mostly in the UK and the EU and they're very large. They're I mean I don't know if they would like this comparison, but I compare them to Chime in the US. Um I think they I don't think that they focus as much on the credit repair piece, but uh the neobanking side, especially for um a younger demographic. They as of September second are actually have a license to operate in the US. Um I kind of had a feeling that was coming because they posted for a head of fraud uh position out of I think Washington DC. I can't remember Boston or Washington DC, I don't know. Somewhere back east. Uh, and that was for the US and I was like, "Huh, I didn't know Revolute was in the US or maybe it's not yet.” And it wasn't until September 2nd. Um, but this actually doesn't have anything to do with operating in the US and I will explain that in just a second. I mean, it has to do with US information, but they could have gotten this another way.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
09:41
So, or that you they didn't have to be in the US to get this information is what I'm saying. So, what happened? Revolute received a request for customer information that appeared to come from a legitimate government agency. That request came from an unauthorized email account sent directly using the official government agency's email domain. As the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request. So, this is a little bit more than a GDPR request. I know I said that at the beginning, but this is, you know, government agencies can request information about individuals. Sometimes they need a warrant, sometimes they don't. Um, but it gives them very detailed information that's usually very secure um on specific individuals. So, it's kind of a one-off situation. It's not like they were able to get all the personal invitation or information of, you know, thousands, tens of thousands, hundreds of thousands of users of Revolute. Um, but very specific ones. So, as the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief belief that it was an authentic government agency request. I think I read that already. Sorry. Identity details. This included the full name, date of birth, and occupation. Also included contact details such as postal address, email address, and telephone number. The document and verification data included a copy of your identity document, so like a passport or a driver's license, and a facial verification image, the selfie you provided for verification. Please note that no biometric facial telemetry data was involved or compromised. You know that's one positive. Financial data was also released including account statements which included the IBAN, the account status, opening date, wallet reference number, withdrawal records, and full transaction history including Bitcoin. So, you could imagine if you want to just steal someone's identity, this would be very good information to have. You've got their identity document. You've got their their name, their date of birth, their occupation, their address, their email address, their phone number.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
12:07
You've got a copy of their passport or their driver's license. You've got the facial recognition or a facial verification image and you've got account statements that include account status, opening date, wallet reference number, and then withdrawal records and full transaction history that includes Bitcoin. That's a lot of information. It's not just for identity theft. You could also use it for espionage. Uh if you were trying to look into how much money has been deposited into somebody's bank account, uh whether they might be being paid by a government agency, whether it's yours or someone else's, you could find out, you know, where their money's come from coming from, how much money they have, at least with this financial institution. And then you know you might be able to find some uh transfers to another bank account at another financial institution and do the same thing. So this information really provides a full picture on a potential victim or target. There was some news uh you so the thing that's most concerning right is the fact that the email at domain was .gov. Now, they say that it uh carried valid domain authentication credentials. It's hard to know what they're doing to authenticate a domain. Some uh I don't know if you remember when I had Cy Khormaee on the podcast just a couple weeks ago. His company uh primarily now I know that they're growing into other use cases but right now they prevent against email phishing and spear phishing campaigns and they're able to determine the real domain the email address is coming from. Um but the fear and there was some information uh put out that same day. The fear was oh my gosh fraudsters can now hack into .gov email addresses. Oh, I guess I kind of buried the lead. The government agency was the US government. It was a US government agency with the domain of .gov.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
14:22
Uh .gov is only used for government agencies. It's not available for anyone else. So, this is what, you know, kind of made the hair on arms stick up was, oh, how are they able to hack a government email address? Because it's a lot more secure than typical inboxes. They require a lot of things to authenticate yourself before you can access your email. So, the fear was how did they get access to that email? Now, as I've talked to one of my best sources for fraud threat intelligence information, I don't believe that that's what happened. I don't I mean I guess it is possible that maybe someone with a .gov email address clicked on a spear phishing link handed over their you know email access to someone through malware and then that request was sent through that way. I think that that's possible. Uh but there's just so much security and I asked my buddy who's in fraud threat intel what he'd been hearing on the dark web or what he thought. I think it's also important to know that he used to work for one of the government agencies that uh has three letters in their name. I don't know if I can say anything else other than that, but it's a big one. And he and he would know, right? Um he was in signal intelligence in the army and then went on to work for one of the three letter uh a government agencies in the US. So he knows his stuff. And what he said was, I'm still not convinced this is real. The attack flow described in a LinkedIn post that I saw um is not possible. So what is much likely happening is a foreign adversary created a. gov URL. So maybe it was instead of a period it was a comma or instead of a O it was actually a U or it was or they were using the international alphabets that look like an O or a V but they're not or used a real name um and was collecting intelligence by claiming to be US government officials. We the US can do that to other countries as well. He referenced which ones but I'm not going to say it especially now that I'm on YouTube. I don't want to get shut down.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
16:45
Uh, you can't just breach a.gov system like they're describing as you need a CAC card, a CAC card to access the emailer. So, I looked up what CAC card was uh on Google cuz I was like, what is this? Um, and it's through the DoD, the Department of Defense. So, it's known as a common access card, and it's a credit card- sized smart card used as a standard identification for active duty military personnel, selected reserves, Department of Defense, civilian employees, and eligible contractors. So, it's got like a smart chip in it, and you have to insert it into a laptop or, you know, the device that you're using in order to access your email. So, what he's saying is even if someone sent a spear phishing email to someone with a .gov email address and bad actors got a hold of that, they couldn't access the inbox because they would need the CAC card inserted into their device in order to access the inbox. So, I thought that was really interesting. He went on to say a few more things. So, this is either someone in the government that wanted to pull user data without authorization. He said that some administrations uh do this often or have done this often. So they don't want to get a warrant, but they want bank information about a target. They may submit this asking for this information without going through the proper channels. Um or it's a foreign adversary creating or using their .gov credentials. If they actually give the emails of the users, you can tell which of the two it is in like one second. But just be coming from a .gov email does not mean it was fraud or that the .gov website was breached. The third and final option would be that it's just a government employee that happened to be a bad actor and was trying to gain access to PII and using their real government credentials, which is also totally possible. But again, that would not be like a third-party fraudster or a breach of the government website or email system.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
19:03
The fact that there was no loss and that they were clearly targeting a small handful of identities tells me it was likely a foreign adversary targeting on an intel op, which not only do we do in the US, but uh he's been very aware of those. Uh, another fun fact, some foreign governments all have access to us .gov accounts and they will use them to collect intelligence like this, too. So, that I thought was really interesting. It's not a data breach. Uh, it's most likely someone who created a website that looked like.gov to the naked eye. Um I don't know if they use a spear phishing tool as sophisticated as can't remember the name of Cy's company but Cy Khormaee's company um where they can tell the metadata about an email but I would hope that the US government would do that but this is a huge issue for Revolute because they've uh it's you know not a huge number of consumers but they're specific and if this is you perpetrated by a foreign national. Well, that's the list of people that they want to target that they want to understand like are they low on money? Can we flip them, you know, for money? Are they this that and the other? So, it's still scary, but it's not as scary as if Revolute was breached altogether, as was kind of implied in a post that went pretty viral. So, I already talked about why this is a big deal. I talked about what can be done with this information. It can be used for espionage. It can be used for identity theft. It can be used for all types of things. How can financial companies prevent this from happening to them? Well, I think it's really important to have an email authenticator that looks at the metadata of email and not just a human looking at it and saying, "Oh, it says .gov." Because chances are they may have used a different letter of the alphabet from another country to create a domain that looks like .gov as I mentioned before, so having something like that set up is important. Requiring two-factor authentication for your employees to access their email inbox depending on the sensitivity of what may be in their inbox could be helpful. Uh just knowing about this possibility is important. And I think talking to the departments that fulfill the requests for information, they should be your first line of defense. Just like customer service is your first line of defense for so many other types of fraud. The department that looks over requests for information, they need to be the first line of defense for that as well. So, that is my biggest piece of advice. You know, there's really two there, right? Invest in an email authenticator for uh requests so that you really, you know, the true domain that they're using. Uh don't just go off of, oh, it says .gov, so I should do it. But then also, you know, training up your team that responds to these to know how to identify signs of fraud. Maybe they're in a real big hurry, you know, because they just stole the card and they want to use it before they get caught. You know, there's so many different things there. So, I wanted to talk about it because it's fairly new and I could see them using the GDPR process for that, too, where, you know, you can request to be deleted. Um, you could request to have, you know, foreign officials be deleted from the records or other types of scenarios because then they wouldn't be able to fulfill those, you know, requests. So, uh, I do think it's important for banks to be aware of. Like I said before, if they try it with Revolute, they're going to try it again. The other thing is is at the time of the these requests, they didn't share the date, but at the time of these requests, they weren't requesting the banking information of Americans. They were questioning the information provided to the government agency um or to Revolute to uh you know verify how much money they have and what they've been spending it on and all of those other things um because that can lead to being able to manipulate someone or be able to steal from them. So, those are really important. You know, I haven't looked at the time recently.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
23:49
This is probably going to be a shorter episode than usual. It is. Um, lately, my solo episodes have been like 45 minutes, 50 minutes, but I was trying to make it a short one this week. I know everybody's kind of getting back in the swing of things after a long summer. And I didn't want to take up all of your time, but I can see into the future. And uh I happen to know that next week's guest is really good and you're going to want to listen. It's SudhirLanka from GrubHub. He is in fraud strategy for GrubHub. He loves fraud strategy. We geeked out on it. Uh but he talks a lot about the different fraud vendors that delivery companies make or or experience. And I was thinking about it the other day. I think the reason why I really enjoy e-commerce fraud, maybe over banking fraud or government fraud or insurance fraud or whatever else, is probably because of my ADHD. I just love like things being different all the time and learning all the time about new things. And in e-commerce, just because a company's in e-commerce does not mean that they're going to see the same type of fraud. They may see completely opposite types of fraud, right? It really depends on what they sell, how they sell it, you know, how they deliver the items. Is it digital? Is it, you know, physical delivery, their business model? So many things make up what typologies you're going to have um with fraud depending on the the type of company you are. So even within Sudhir's company, a company called Wonder bought out Door Dash as well as HelloF is HelloFresh or Plated. It's one of the uh food delivery companies. And then they also have an in-person uh market that uh is called Wonder. Um and Sudhir oversees all three. And he talks about how all three are different. Uh because the business models are different from each other, you know, how things are delivered, when things are charged, just all those different things, how you know, the quality of the food, all of those things. He has three different companies underneath him, so he can move from one thing to the next to the next, which I think is a great opportunity. Uh you can know, you know, what GrubHub's risk signals are, but completely miss it for Wonder or the other one. So, that was a really good conversation. We dove in deep. Uh, I do know there's been a little bit of talk online about how difficult it is to get current merchants to be interviewed on a podcast. And I'm really grateful that I haven't had that much of a problem. I think and I hope it's because people know they'll they can trust me. If they accidentally say something that they can't say because of their company, I'll have my editor delete it. Um, I want this to be the best experience for them. So, with that said, I mean, I wasn't planning on saying this, but I'll say it because it's a good reminder, uh, if you ever want to share your fraud story or gain a little more exposure internationally even, uh, let me know and we can I'm pretty good at thinking of topics that, you know, I know people want to learn from and that, you know, how to talk to them. Even if I just talk to you for 15 minutes, I can usually say, "Okay, this is the kind of session I'm envisioning in my mind." I just did that last week with someone uh where they really weren't sure what format they should have and what title they should have and what the focus should be and within like 25 minutes, we busted it out and had a really good session title and session description and he had a road map for the slides he needed to create. So anyway, I with that I am going to let you guys go and maybe move on to another fraud podcast. Maybe Fraud Forward with Hailey or Scam Rangers with Ayelet. Uh both of those are really good. So is um Stolen by Erin West. That's also a good one. So um I will leave you to it at that. So, thanks so much for joining me today and I look forward to speaking with you more next week.