Sardine named a Leader in The Forrester Wave™: Financial Crime Management Solutions, Q3 2026

Learn More
Fraudology

政府機関を装ったメールフィッシング詐欺と身分証明書スキャン画像流出事件の続報

28 min

Fraudologyへようこそ。

今回は私一人でお届けするエピソードで、今週は2つの話題を取り上げます。まずは、先週フランク・マッケンナとお話しした身分証明書スキャンデータの漏えいについて、その後の状況を追っていきます。現在どうなっているのか、今も懸念すべきなのか、そして運転免許証データの漏えいが今後のKYCにおける不正防止にどのような影響を及ぼすのかを考えます。

そして次に、今週最大級の詐欺事件の一つを取り上げたいと思います。これは発覚したばかりの事件なので、できるだけ早く皆さんにお伝えしたいと思いました。正規の.govメールドメインに見せかけた政府機関のメールを使うフィッシング詐欺がRevolutを襲いました。要求は受理され、顧客データが開示されました。しかも、Revolutのシステムに侵入する必要はまったくありませんでした。本物と信じ込ませるほど巧妙に偽装されたメールだけで事足りたのです。

この件について、私は不正脅威インテリジェンスの情報源に話を聞いてきました。その中には、アルファベット3文字で呼ばれる政府機関の一つに在籍していた人物もいます。彼の話を聞いて、この事件に対する私の見方は一変しました。これから、その全貌を詳しく掘り下げていきます。

今回は詐欺ニュースのエピソードです。今日は手短にまとめます。それでは、さっそく本題に入りましょう。

このエピソードでお届けする内容:

  • IDスキャンデータ漏洩事件の続報。1億5,300万件の運転免許証データベースをめぐる現状、FBIによる摘発が重要な理由、そして今なおこれを進行中の脅威として捉えるべきかについて解説します。
  • IDスキャンデータの漏えいが、KYC詐欺や本人確認書類の不正検知にとってなぜこれほど危険だったのか。そして、なぜほとんどの本人確認サービス企業がそれを見抜けなかったのか。
  • サプライチェーンにおけるデータ侵害リスクの実態と、すべての金融機関が盛り込むべきベンダー契約条項。
  • Revolutにおける政府機関からの要請を装った詐欺事件を解説。どのようなデータが流出したのか、詐欺師がそのデータを使って何ができるのか、そしてなぜ個人情報の窃取やスパイ活動に悪用される可能性があるのかを説明します。
  • .govメールドメインの偽装が想像以上に難しい理由、CACカードとは何か、そしてそれが政府機関のメールセキュリティにとって重要な理由、さらに不正脅威インテリジェンスに詳しい私の情報源が実際には何が起きたと考えているのか。
  • この政府機関メールを悪用したフィッシング詐欺について、最も可能性の高い3つの説明。全体像を一変させる、外国の敵対勢力による詐欺という観点も含みます。
  • 金融機関における政府機関を装ったフィッシングメールの防止策、メール認証ツール、機密性の高い受信トレイへのアクセスに対する二要素認証、政府機関からの情報提供要請に対応するチームのトレーニング。
  • この種のメールドメイン偽装詐欺が再び試みられると考えられる理由と、ネオバンクの不正防止チームが具体的に整備しておくべき対策。

次のような方は、ぜひこのエピソードをお聴きください:

  • 銀行、ネオバンク、その他の金融機関で不正対策、コンプライアンス、またはリスク管理に携わっており、Revolutのインシデントが実際に自社のチームにとって何を意味するのかを理解したい方。
  • 金融機関におけるフィッシング対策を担当しており、今週すぐに持ち帰って実践できる具体的な提言を求めている方。
  • 政府機関を装った詐欺の仕組みと、.govドメインのメールだからといって正規のものとは限らない理由を理解したい方。
  • サプライチェーンにおけるデータ侵害の責任条項についてベンダー契約を見直しており、盛り込むべき内容の枠組みを求めている。
  • KYCの不正防止業務に携わっており、身分証明書のスキャンデータ漏えいが本人確認において特に危険だった理由を理解したい方。
  • 不正に関するニュースを追っており、LinkedInで拡散された話だけでなく、Revolutで実際に何が起きたのかについて実務家の見解を知りたい方。
エピソードノート

身分証明書スキャンデータの漏えい:現状について

フランク・マッケナと私は先週、この件を取り上げました。その後の情報によると、FBIが速やかに削除したようです。不正脅威インテリジェンスの関係者が確認したダークウェブ上のフォーラムに出回っていたコピーには、実際にはデータベース全体は含まれていませんでした。報告されている価格で個別にライセンスを購入すると総額は150億ドルを超えるため、模倣した出品は実際のデータではなく、中身のない見せかけだった可能性が高いと考えられます。

私たちは安全なのでしょうか? 答えはイエスでもあり、ノーでもあります。より重要な教訓は、サプライチェーンにおけるデータ侵害という観点です。ベンダーとの契約内容は重要です。侵害発生時の通知責任を誰が負うのかを把握しておきましょう。信用情報の監視や被害修復にかかる費用について、ベンダーが責任を負うのかも確認してください。ベンダーでの侵害によって顧客データが流出した場合、自社ブランドの評判がどの程度のリスクにさらされるのかも把握しておく必要があります。必要になる前に、これらの条項を契約書に明記しておきましょう。

Revolutの政府要請を装った詐欺事件

このニュースが報じられたのは、9月12日土曜日のことです。私はその翌日にこれを収録しています。皆さんがお聞きになる頃には続報が出ているかもしれませんが、現時点で分かっていることをお伝えします。

Revolutは、有効なドメイン認証情報を備えた、正規の米国政府機関と思われる相手から要請を受けました。その要請は本物であるとの合理的な判断に基づき、対応されました。開示されたデータは個人の全体像を把握できるもので、金融詐欺やスパイ活動にさえ悪用される可能性があります。だからこそ、外国の敵対勢力による詐欺という観点が極めて重要なのです。

私の不正対策情報筋によると、本物の.govシステムが侵害された可能性は極めて低いとのことです。その人物の見立てでは、外国の敵対勢力が、一見すると正規のものに見えるものの、一部の文字を別の文字に置き換えたメールドメインを作成した可能性が最も高いとされています。また、政府内部の関係者が正規の手続きを経ずに要請を提出したか、政府職員が本物の認証情報を悪用した可能性もあります。これは大規模なデータ取得ではなく、ごく少数の特定の個人が標的となっていました。つまり、詐欺集団ではなく、諜報活動だったのです。

金融機関における政府機関を装ったフィッシングメールの防止方法

政府機関からの情報提供要請に対応するチームは、最初の防衛線です。顧客対応窓口が、消費者を狙った詐欺に対する最初の防衛線であるのと同じです。要請が正当なものかどうかを確認するには、.gov のメールアドレスだけでは不十分であることを理解しておく必要があります。また、メールドメインのなりすまし詐欺、不正な要請に見られる緊急性を装う兆候、要請に応じる前に上位担当者へ報告すべきタイミングについて、研修を受ける必要があります。

ツール面では、表示されているドメインだけでなく、受信メールのメタデータも読み取るメール認証ツールを導入してください。機密性の高い政府機関からの要請を扱うメールボックスには、二要素認証を設定することで、さらにセキュリティを強化できます。また、政府機関からの情報提供要請に対応するプロセスを最初から最後まで見直してください。現在、人が.govのメールアドレスを確認するだけで手続きを進めているのであれば、そのプロセスを変更する必要があります。

なぜこのようなことが再び起こるのか

この攻撃がRevolutに通用した以上、ほかでも試みられるでしょう。肉眼では本物に見えるドメインを作成するには技術的なスキルが必要ですが、並外れたリソースまでは必要ありません。詐欺と諜報のどちらの目的においても、得られる見返りは極めて大きいものです。金融機関は、これを単発の事例ではなく、すでに確立された攻撃手法の一種として捉えるべきです。次の攻撃メールが受信トレイに届く前に、政府機関からの要請を検証するプロセスを見直し、その対応チームを訓練し、適切なメール認証ツールを導入してください。

重要なポイント
  • 身分証明書のスキャンデータ流出は収束したように見えますが、この運転免許証データには依然としてアクセス可能であるという前提で対応すべきです。実際に一度アクセスされており、それを可能にした状況は変わっていません。
  • サプライチェーンにおけるデータ侵害のリスクは、決して机上の空論ではありません。身分証明書のスキャンデータ流出事件は、ベンダーの侵害によって顧客データが漏えいした直接的な事例です。実際に問題が起きてから痛い目を見る前に、侵害の通知、是正対応、ブランドの評判低下に伴う費用を誰が負担するのかを契約で明確に定めておく必要があります。
  • Revolutに対する政府機関からの要請を装った詐欺事件は、米国政府のメールシステムへの侵害ではなかった可能性が極めて高いと考えられます。実在する.govの受信トレイにアクセスするには、端末に物理的なCACカードを挿入する必要があります。そのため、認証情報を悪用したスピアフィッシングによって.govの受信トレイに侵入することは極めて困難です。
  • Revolutの事件で流出したデータには、本人確認書類、顔認証用画像、ビットコインを含む全取引履歴が含まれており、単なるなりすまし犯罪にとどまらない悪用が可能なほどの情報です。
  • 貴社で政府機関からの情報提供要請に対応するチームが、第一の防衛線となります。金融機関が今すぐ導入できる最も重要な技術的対策は、メール認証ツールです。複数の防御策を組み合わせてください。
  • この攻撃が一度成功した以上、再び試みられるでしょう。
最後に押さえておきたいポイント

今週取り上げるのは2つの事例ですが、どちらも同じ教訓に行き着きます。不正対策における最大の弱点は、多くの場合、システムそのものではありません。何かが正規のものに見えたときに、人が従う確認プロセスです。すべてのチェックを通過した運転免許証のスキャン画像が、本物だとは限りません。.govのメールアドレスだからといって、必ずしも政府機関から送られたものとは限りません。こうした確認手順を担う人とプロセスにこそ隙があり、その隙を塞がない限り、詐欺師はそこを狙い続けるでしょう。

今回取り上げた2つの話題には、瞬く間に広まった内容と、もう少し掘り下げると少し違って見えてくる実像がありました。不正に関するニュースは、見出しだけでは語れません。その背景には、物語を支えるコミュニティがあります。対話やつながり、そして実際の人々から得られる確かな答えです。お読みいただきありがとうございました。また来週お会いしましょう。

エピソードの参考資料とリンク

つながる:Karisse Hendrick | LinkedIn
Fraudologyポッドキャストのホスト
受賞歴のあるサイバー詐欺対策の専門家
Eコマース不正防止コンサルタント
スタートアップアドバイザー、基調講演者、
Fortune 500企業向けコンサルタント

Episode transcript
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:07
Welcome back to Fraudology. I'm Karisse Hendrick. This is another solo episode. Um, we just had Frank McKenna on the podcast talking about the big ID scan uh data breach as well as digital arrests. This is something he's been talking about since uh the end of last year. And I mentioned on that episode that I was a little skeptical that they would ever come to the US or any western states but or countries, but they did. Um so that's a really interesting episode. Today I'm going to do a little bit of a followup on that ID scan breach and if we should still be worried and what we can do. And then I'm going to talk about uh the biggest news story of the week which um was with Revolute and it's a newer it's a really creative way of using GDPR against a company um to gain information and gain personal uh information that's usually private uh about specific individuals. So and this can be done at any financial institution. So, I'm going to dive into it a little bit. I'll share what it happened and then, you know, why we should worry about it and what it means and all of that. Um, so yeah, that's what today has in store for you. I'm just going to give you a 2 and 1/2 week notice that MFA is coming soon. I don't know how much boots on the ground I'm going to be able to record uh while at MFA just because got to be busy. Uh but I um will definitely be providing some behind the scenes uh information and that type of thing after the fact. Uh it won't be the same as attending obviously. And if you are, you know, in the Chicago area or you are just a short flight, you know, or you're willing to fly far uh to Chicago, it is October 6th and 7th in Chicago. Uh October 5th is a merchant-only um AI boot camp led by two people from PlayStation and one from GoDaddy uh sharing how the real world examples of how they use generative AI for fraud operations. And uh they're going to be providing some takeaways like some prompts and dashboards, things like that, so that it's very tactical and practical. And that's really what we want to provide with MFA is from each session something to walk away with. And I think we're gonna do that. I am so close to finalizing the agenda. I'm about three or four weeks later than I wanted to be. Uh but there were a few unforeseen circumstances. Um but you know that's okay. Uh thankfully we have you know a couple hundred people that are coming anyway.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
03:00
Um and we have some great brands coming and uh a very limited amount of solution providers uh as we don't sell vendor tickets. So, um, just want to give a little bit of an update with a 2 and 1/2 week countdown. I am, as my daughter would say, nervecited. I am both nervous and excited. Okay. Well, let's dive into the news. Uh, like I said, I'm just going to highlight two stories today. Uh, we're going to do a follow up on the ID scan breach that Frank McKenna and I talked about last week. It contained 153 million driver's licenses in the US. Uh we determined that that's about almost half of all uh adult the adult population in the US. So that's a lot of driver's licenses. Um primarily from car rental places and retailers, uh government, uh contracts, that type of thing. And the reason why it was so scary is because they're not just pictures of a driver's license. They're a scan of a driver's license. They include the holograph. They include, you know, all of that. Um, and if someone were to use that for, you know, KYC, like know your customer when they're onboarding an account, especially at a bank or, uh, as a seller, um, for a marketplace, that type of thing. They wouldn't be using a fake ID. So, most identity documentation verification companies, that's a quite the mouthful, uh wouldn't be able to detect that it was fraud. So, that was what was most scary. Um, what it seems like now, there haven't been as many articles about it, which is good. Uh, I do think it's in ID scans best interest for that to happen as well. Um, but we believe that it's been taken down by the FBI. Um, the FBI has said that it's been taken down. There were several copies made uh on in dark web forums that a friend of mine in fraud threat intel uh was able to find.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
05:06
However, those copies didn't actually contain the database because you had to pay $10 or $100 each for each driver's license. So, that would be assuming that someone paid 15.3 billion dollars. Am I doing the math right? Um to get all of those driver's licenses and then why would they make them public? So, chances are the copycats out there are just people that are selling uh kind of it's like selling the cover of a record but having no record inside, right? Or the cover of a book but no actual book attached. Um so we're not as worried. Um, are we safe? Yes and no. Uh, I would say we should still operate on the fact that these are out here. Um, I think that it's a little bit of a sigh of relief that the FBI took it down so quickly and that we haven't seen any more databases like this, but you just never know. Uh, and because they were accessed once, could they be accessed again? Hard to know. So, uh it's it's another good example of supply chain uh breaches and uh I talked a little bit about this on the last episode, but basically what that means is instead of going to your company directly, they go to your vendor and they breach your vendor. So, you really should have a lot of good contract language that keeps you safe from if this were to happen with a vendor. I know that there are various types of verbiage that you can uh have in those contracts. You know, some say that the vendor has to pay for credit repair or not credit repair but credit reports. Um the vendor has to own the the data breach. Others say that the merchant or the bank have to own the data breach. Um and when they own it, they have to do all the notifications to consumers. They have to offer the credit report, which is not much and doesn't do a lot, but it's something to provide a little bit of peace of mind to victims. Um, there's also the brand reputation cost and if you're going to have your vendor reimburse you for that. There's just a lot of different things that you can write in that contract. So, be very mindful of that. I think this was a very good example of the reason why that's important. So, as I mentioned, the biggest news story of the week uh broke on Saturday, September 12th. Uh full disclosure, I am recording this on the 13th, so just the day after. So, there may be more news coming out about this after I record. Uh so, you know, do a quick Google search or, you know, chatGPT it or whatever you want to do to learn the updates. But I think this is important because it's a new twist on a fraud scam and it's a new twist that we haven't really seen or heard of before. And whenever that happens, I want to get the news out as soon as possible so that it doesn't work anywhere else. Let me just pull up a notification that was post reposted on LinkedIn. So this is about Revolute. Revolute is a neobank that is mostly in the UK and the EU and they're very large. They're I mean I don't know if they would like this comparison, but I compare them to Chime in the US. Um I think they I don't think that they focus as much on the credit repair piece, but uh the neobanking side, especially for um a younger demographic. They as of September second are actually have a license to operate in the US. Um I kind of had a feeling that was coming because they posted for a head of fraud uh position out of I think Washington DC. I can't remember Boston or Washington DC, I don't know. Somewhere back east. Uh, and that was for the US and I was like, "Huh, I didn't know Revolute was in the US or maybe it's not yet.” And it wasn't until September 2nd. Um, but this actually doesn't have anything to do with operating in the US and I will explain that in just a second. I mean, it has to do with US information, but they could have gotten this another way.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
09:41
So, or that you they didn't have to be in the US to get this information is what I'm saying. So, what happened? Revolute received a request for customer information that appeared to come from a legitimate government agency. That request came from an unauthorized email account sent directly using the official government agency's email domain. As the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request. So, this is a little bit more than a GDPR request. I know I said that at the beginning, but this is, you know, government agencies can request information about individuals. Sometimes they need a warrant, sometimes they don't. Um, but it gives them very detailed information that's usually very secure um on specific individuals. So, it's kind of a one-off situation. It's not like they were able to get all the personal invitation or information of, you know, thousands, tens of thousands, hundreds of thousands of users of Revolute. Um, but very specific ones. So, as the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief belief that it was an authentic government agency request. I think I read that already. Sorry. Identity details. This included the full name, date of birth, and occupation. Also included contact details such as postal address, email address, and telephone number. The document and verification data included a copy of your identity document, so like a passport or a driver's license, and a facial verification image, the selfie you provided for verification. Please note that no biometric facial telemetry data was involved or compromised. You know that's one positive. Financial data was also released including account statements which included the IBAN, the account status, opening date, wallet reference number, withdrawal records, and full transaction history including Bitcoin. So, you could imagine if you want to just steal someone's identity, this would be very good information to have. You've got their identity document. You've got their their name, their date of birth, their occupation, their address, their email address, their phone number.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
12:07
You've got a copy of their passport or their driver's license. You've got the facial recognition or a facial verification image and you've got account statements that include account status, opening date, wallet reference number, and then withdrawal records and full transaction history that includes Bitcoin. That's a lot of information. It's not just for identity theft. You could also use it for espionage. Uh if you were trying to look into how much money has been deposited into somebody's bank account, uh whether they might be being paid by a government agency, whether it's yours or someone else's, you could find out, you know, where their money's come from coming from, how much money they have, at least with this financial institution. And then you know you might be able to find some uh transfers to another bank account at another financial institution and do the same thing. So this information really provides a full picture on a potential victim or target. There was some news uh you so the thing that's most concerning right is the fact that the email at domain was .gov. Now, they say that it uh carried valid domain authentication credentials. It's hard to know what they're doing to authenticate a domain. Some uh I don't know if you remember when I had Cy Khormaee on the podcast just a couple weeks ago. His company uh primarily now I know that they're growing into other use cases but right now they prevent against email phishing and spear phishing campaigns and they're able to determine the real domain the email address is coming from. Um but the fear and there was some information uh put out that same day. The fear was oh my gosh fraudsters can now hack into .gov email addresses. Oh, I guess I kind of buried the lead. The government agency was the US government. It was a US government agency with the domain of .gov.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
14:22
Uh .gov is only used for government agencies. It's not available for anyone else. So, this is what, you know, kind of made the hair on arms stick up was, oh, how are they able to hack a government email address? Because it's a lot more secure than typical inboxes. They require a lot of things to authenticate yourself before you can access your email. So, the fear was how did they get access to that email? Now, as I've talked to one of my best sources for fraud threat intelligence information, I don't believe that that's what happened. I don't I mean I guess it is possible that maybe someone with a .gov email address clicked on a spear phishing link handed over their you know email access to someone through malware and then that request was sent through that way. I think that that's possible. Uh but there's just so much security and I asked my buddy who's in fraud threat intel what he'd been hearing on the dark web or what he thought. I think it's also important to know that he used to work for one of the government agencies that uh has three letters in their name. I don't know if I can say anything else other than that, but it's a big one. And he and he would know, right? Um he was in signal intelligence in the army and then went on to work for one of the three letter uh a government agencies in the US. So he knows his stuff. And what he said was, I'm still not convinced this is real. The attack flow described in a LinkedIn post that I saw um is not possible. So what is much likely happening is a foreign adversary created a. gov URL. So maybe it was instead of a period it was a comma or instead of a O it was actually a U or it was or they were using the international alphabets that look like an O or a V but they're not or used a real name um and was collecting intelligence by claiming to be US government officials. We the US can do that to other countries as well. He referenced which ones but I'm not going to say it especially now that I'm on YouTube. I don't want to get shut down.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
16:45
Uh, you can't just breach a.gov system like they're describing as you need a CAC card, a CAC card to access the emailer. So, I looked up what CAC card was uh on Google cuz I was like, what is this? Um, and it's through the DoD, the Department of Defense. So, it's known as a common access card, and it's a credit card- sized smart card used as a standard identification for active duty military personnel, selected reserves, Department of Defense, civilian employees, and eligible contractors. So, it's got like a smart chip in it, and you have to insert it into a laptop or, you know, the device that you're using in order to access your email. So, what he's saying is even if someone sent a spear phishing email to someone with a .gov email address and bad actors got a hold of that, they couldn't access the inbox because they would need the CAC card inserted into their device in order to access the inbox. So, I thought that was really interesting. He went on to say a few more things. So, this is either someone in the government that wanted to pull user data without authorization. He said that some administrations uh do this often or have done this often. So they don't want to get a warrant, but they want bank information about a target. They may submit this asking for this information without going through the proper channels. Um or it's a foreign adversary creating or using their .gov credentials. If they actually give the emails of the users, you can tell which of the two it is in like one second. But just be coming from a .gov email does not mean it was fraud or that the .gov website was breached. The third and final option would be that it's just a government employee that happened to be a bad actor and was trying to gain access to PII and using their real government credentials, which is also totally possible. But again, that would not be like a third-party fraudster or a breach of the government website or email system.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
19:03
The fact that there was no loss and that they were clearly targeting a small handful of identities tells me it was likely a foreign adversary targeting on an intel op, which not only do we do in the US, but uh he's been very aware of those. Uh, another fun fact, some foreign governments all have access to us .gov accounts and they will use them to collect intelligence like this, too. So, that I thought was really interesting. It's not a data breach. Uh, it's most likely someone who created a website that looked like.gov to the naked eye. Um I don't know if they use a spear phishing tool as sophisticated as can't remember the name of Cy's company but Cy Khormaee's company um where they can tell the metadata about an email but I would hope that the US government would do that but this is a huge issue for Revolute because they've uh it's you know not a huge number of consumers but they're specific and if this is you perpetrated by a foreign national. Well, that's the list of people that they want to target that they want to understand like are they low on money? Can we flip them, you know, for money? Are they this that and the other? So, it's still scary, but it's not as scary as if Revolute was breached altogether, as was kind of implied in a post that went pretty viral. So, I already talked about why this is a big deal. I talked about what can be done with this information. It can be used for espionage. It can be used for identity theft. It can be used for all types of things. How can financial companies prevent this from happening to them? Well, I think it's really important to have an email authenticator that looks at the metadata of email and not just a human looking at it and saying, "Oh, it says .gov." Because chances are they may have used a different letter of the alphabet from another country to create a domain that looks like .gov as I mentioned before, so having something like that set up is important. Requiring two-factor authentication for your employees to access their email inbox depending on the sensitivity of what may be in their inbox could be helpful. Uh just knowing about this possibility is important. And I think talking to the departments that fulfill the requests for information, they should be your first line of defense. Just like customer service is your first line of defense for so many other types of fraud. The department that looks over requests for information, they need to be the first line of defense for that as well. So, that is my biggest piece of advice. You know, there's really two there, right? Invest in an email authenticator for uh requests so that you really, you know, the true domain that they're using. Uh don't just go off of, oh, it says .gov, so I should do it. But then also, you know, training up your team that responds to these to know how to identify signs of fraud. Maybe they're in a real big hurry, you know, because they just stole the card and they want to use it before they get caught. You know, there's so many different things there. So, I wanted to talk about it because it's fairly new and I could see them using the GDPR process for that, too, where, you know, you can request to be deleted. Um, you could request to have, you know, foreign officials be deleted from the records or other types of scenarios because then they wouldn't be able to fulfill those, you know, requests. So, uh, I do think it's important for banks to be aware of. Like I said before, if they try it with Revolute, they're going to try it again. The other thing is is at the time of the these requests, they didn't share the date, but at the time of these requests, they weren't requesting the banking information of Americans. They were questioning the information provided to the government agency um or to Revolute to uh you know verify how much money they have and what they've been spending it on and all of those other things um because that can lead to being able to manipulate someone or be able to steal from them. So, those are really important. You know, I haven't looked at the time recently.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
23:49
This is probably going to be a shorter episode than usual. It is. Um, lately, my solo episodes have been like 45 minutes, 50 minutes, but I was trying to make it a short one this week. I know everybody's kind of getting back in the swing of things after a long summer. And I didn't want to take up all of your time, but I can see into the future. And uh I happen to know that next week's guest is really good and you're going to want to listen. It's SudhirLanka from GrubHub. He is in fraud strategy for GrubHub. He loves fraud strategy. We geeked out on it. Uh but he talks a lot about the different fraud vendors that delivery companies make or or experience. And I was thinking about it the other day. I think the reason why I really enjoy e-commerce fraud, maybe over banking fraud or government fraud or insurance fraud or whatever else, is probably because of my ADHD. I just love like things being different all the time and learning all the time about new things. And in e-commerce, just because a company's in e-commerce does not mean that they're going to see the same type of fraud. They may see completely opposite types of fraud, right? It really depends on what they sell, how they sell it, you know, how they deliver the items. Is it digital? Is it, you know, physical delivery, their business model? So many things make up what typologies you're going to have um with fraud depending on the the type of company you are. So even within Sudhir's company, a company called Wonder bought out Door Dash as well as HelloF is HelloFresh or Plated. It's one of the uh food delivery companies. And then they also have an in-person uh market that uh is called Wonder. Um and Sudhir oversees all three. And he talks about how all three are different. Uh because the business models are different from each other, you know, how things are delivered, when things are charged, just all those different things, how you know, the quality of the food, all of those things. He has three different companies underneath him, so he can move from one thing to the next to the next, which I think is a great opportunity. Uh you can know, you know, what GrubHub's risk signals are, but completely miss it for Wonder or the other one. So, that was a really good conversation. We dove in deep. Uh, I do know there's been a little bit of talk online about how difficult it is to get current merchants to be interviewed on a podcast. And I'm really grateful that I haven't had that much of a problem. I think and I hope it's because people know they'll they can trust me. If they accidentally say something that they can't say because of their company, I'll have my editor delete it. Um, I want this to be the best experience for them. So, with that said, I mean, I wasn't planning on saying this, but I'll say it because it's a good reminder, uh, if you ever want to share your fraud story or gain a little more exposure internationally even, uh, let me know and we can I'm pretty good at thinking of topics that, you know, I know people want to learn from and that, you know, how to talk to them. Even if I just talk to you for 15 minutes, I can usually say, "Okay, this is the kind of session I'm envisioning in my mind." I just did that last week with someone uh where they really weren't sure what format they should have and what title they should have and what the focus should be and within like 25 minutes, we busted it out and had a really good session title and session description and he had a road map for the slides he needed to create. So anyway, I with that I am going to let you guys go and maybe move on to another fraud podcast. Maybe Fraud Forward with Hailey or Scam Rangers with Ayelet. Uh both of those are really good. So is um Stolen by Erin West. That's also a good one. So um I will leave you to it at that. So, thanks so much for joining me today and I look forward to speaking with you more next week.