Sardine named a Leader in The Forrester Wave™: Financial Crime Management Solutions, Q3 2026

Learn More
Fraudology

A Government Email Phishing Scam and the ID Scan Breach Update

28 min

Welcome back to Fraudology.

This is a solo episode, and I’ve got two stories for you this week. I wanted to follow-up on the ID scan breach that Frank McKenna and I discussed last week. Where things stand now, whether we should still be worried, and what the driver’s license data breach means for KYC fraud prevention going forward.

And then I wanted to get into one of the biggest fraud stories this week. This one is brand new and I wanted to get it to you as soon as possible. A government email phishing scam hit Revolut using what appeared to be a legitimate .gov email domain. The request was fulfilled. Customer data was released. And it did not require a breach of Revolut at all. It required a spoofed email that looked real enough to pass.

I have been talking to my fraud threat intelligence sources about this, including someone with a background at one of the three-letter government agencies. What he told me changed how I’m thinking about this incident entirely. We are going to get into all of it.

This is a fraud news episode, and I’m going to keep it tight today. Let’s dive in.

What you’ll hear in this episode:

  • The ID scan data breach update. Where the 153 million driver’s license database stands now, why the FBI takedown matters, and whether we should still be treating this as an active threat.
  • Why the ID scan breach was so dangerous for KYC fraud and identity document fraud detection. And why most verification companies would not have caught it.
  • What supply chain data breach risk looks like in practice and the vendor contract language every financial institution should have in place.
  • The Revolut government request fraud incident explained. What data was released, what a fraudster can do with it, and why it could be used for identity theft and espionage.
  • Why a .gov email domain is harder to spoof than it sounds, what a CAC card is and why it matters for government email security, and what my fraud threat intelligence source actually thinks happened.
  • The three most likely explanations for this government email phishing scam. Including the foreign adversary fraud angle that changes the whole picture.
  • How to prevent government email phishing at your financial institution, email authentication tools, two factor authentication for sensitive inbox access, and training the team that handles government information requests.
  • Why this kind of email domain spooking fraud is going to be attempted again, and what neobank fraud prevention teams specifically need to have in place.

You should listen to this episode if you:

  • Work in fraud, compliance, or risk at a bank, neobank, or financial institution and want to understand what the Revolut incident actually means for your team.
  • Are responsible for financial institution phishing prevention and want practical recommendations you can bring back this week.
  • Want to understand how government impersonation fraud works and why a .gov email does not guarantee legitimacy.
  • Are evaluating your vendor contracts for supply chain data breach liability language and want a framework for what to include.
  • Work in KYC fraud prevention and want to understand why the ID scan data breach was uniquely dangerous for identity document verification.
  • Follow fraud news and want a practitioner's read on what actually happened with Revolut, not just the viral LinkedIn version.
Episode notes

The ID scan data breach: Where things stand

Frank McKenna and I covered this last week. The update is that the FBI appears to have taken it down quickly. The dark web forum copies that fraud threat intelligence contacts identified did not actually contain the full database. Buying individual licenses at the reported price would have cost over 15 billion dollars, which makes the copycat listings more likely to be empty shells than actual data.

Are we safe? Yes and no. The more important lesson is the supply chain data breach angle. Your vendor contracts matter. Know who owns the breach notification responsibility. Know whether your vendor is liable for credit monitoring and remediation costs. Know what your brand reputation exposure looks like if a vendor breach surfaces your customers’ data. Get the language in writing before you need it.

The Revolut government request fraud incident

This story broke on Saturday, September 12th. I am recording this the following day. There may be updates by the time you hear this, but here is what we know.

Revolut received a request from what appeared to be a legitimate US government agency that carried valid domain authentication credentials. The request was fulfilled under the reasonable belief it was authentic. The data that was released is a complete picture of an individual that can be used for financial fraud or even espionage, which is what makes the foreign adversary fraud angle so significant.

What my fraud intelligence source told me is that a genuine .gov system breach is extremely unlikely. His read is that this was most likely a foreign adversary creating an email domain that looked legitimate to the naked eye, but contained a character substitution. It could also have been an internal government actor submitting a request without going through the proper channels, or a government employee acting as a bad actor using real credentials. This was not a mass data pull. It was a small number of very specific individuals. That was an intelligence operation, not a fraud ring.

How to prevent government email phishing at your financial institution

The team that handles government information requests is your first line of defense. The same way customer service is your first line of defense for consumer-facing fraud. They need to know that a .gov email address is not enough to authenticate a request. They need training on email domain spoofing fraud, on what urgency signals look like in a fraudulent request, and on when to escalate before fulfilling.

On the tooling side, invest in an email authenticator that reads the metadata of incoming email, not just the visible domain. Two factor authentication for any inbox that handles sensitive government requests adds another layer. And review your government information requests process end to end. If it currently relies on a human reading a .gov email address and proceeding, that process needs to change.

Why this is going to happen again

If this attack worked on Revolut, it will be attempted elsewhere. Creating a domain that looks real to the naked eye requires technical skill but not exceptional resources. The payoff is extremely valuable for both fraud and intelligence purposes. Financial institutions should treat this as a category of attack that is now established, not a one-off. Update your government request verification process, train the team that handles those requests, and get the right email authentication tooling in place before the next attempt lands in your inbox.

Key takeaways
  • The ID scan data breach appears to be contained, but we should still operate as though this driver’s license data is accessible. It was accessed once and the conditions that allowed it have not changed.
  • Supply chain data breach risk is not theoretical. The ID scan incident is a direct example of a vendor breach exposing your customers’ data. Your contracts should define who owns breach notification, remediation, and brand reputation costs before you need to find out the hard way.
  • The Revolut government request fraud incident was almost certainly not a breach of the US government email system. Accessing a real .gov inbox requires a physical CAC card inserted into the device. That makes credential-based spear phishing of a .gov inbox extremely difficult.
  • The data released in the Revolut incident includes identity documents, facial verification images, full transaction history including Bitcoin, and is enough for more than just identity theft.
  • The team that handles government information requests at your institution is your first line of defense. Email authentication tooling is the most important technical control financial institutions can implement right now. Layer defenses together.
  • If this attack worked once, it will be attempted again.
Final takeaway

Two stories this week, and both of them come back to the same lesson. The weakest point in your fraud defense is often not your systems. It is the process a human follows when something looks legitimate. A driver's license scan that passes every check is not automatically real. A .gov email address is not automatically from the government. The people and the processes behind those verification steps are where the gap lives, and that is where the fraudsters are going to keep going until we close it.

Both of these stories had a version that spread fast and a version that looked a little different once you dug in a little further. Fraud news is more than the headlines. It is the community behind the story. The conversation, the connections, and the real answers that come from real people. Thanks for being here, and I will see you next week.

Connect with Karisse Hendrick | LinkedIn
Host of the Fraudology Podcast
Award-Winning Cyberfraud Expert
Ecommerce Fraud Prevention Consultant
Startup Advisor, Keynote Speaker, and
Consultant to Fortune 500 merchants

Episode transcript
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:07
Welcome back to Fraudology. I'm Karisse Hendrick. This is another solo episode. Um, we just had Frank McKenna on the podcast talking about the big ID scan uh data breach as well as digital arrests. This is something he's been talking about since uh the end of last year. And I mentioned on that episode that I was a little skeptical that they would ever come to the US or any western states but or countries, but they did. Um so that's a really interesting episode. Today I'm going to do a little bit of a followup on that ID scan breach and if we should still be worried and what we can do. And then I'm going to talk about uh the biggest news story of the week which um was with Revolute and it's a newer it's a really creative way of using GDPR against a company um to gain information and gain personal uh information that's usually private uh about specific individuals. So and this can be done at any financial institution. So, I'm going to dive into it a little bit. I'll share what it happened and then, you know, why we should worry about it and what it means and all of that. Um, so yeah, that's what today has in store for you. I'm just going to give you a 2 and 1/2 week notice that MFA is coming soon. I don't know how much boots on the ground I'm going to be able to record uh while at MFA just because got to be busy. Uh but I um will definitely be providing some behind the scenes uh information and that type of thing after the fact. Uh it won't be the same as attending obviously. And if you are, you know, in the Chicago area or you are just a short flight, you know, or you're willing to fly far uh to Chicago, it is October 6th and 7th in Chicago. Uh October 5th is a merchant-only um AI boot camp led by two people from PlayStation and one from GoDaddy uh sharing how the real world examples of how they use generative AI for fraud operations. And uh they're going to be providing some takeaways like some prompts and dashboards, things like that, so that it's very tactical and practical. And that's really what we want to provide with MFA is from each session something to walk away with. And I think we're gonna do that. I am so close to finalizing the agenda. I'm about three or four weeks later than I wanted to be. Uh but there were a few unforeseen circumstances. Um but you know that's okay. Uh thankfully we have you know a couple hundred people that are coming anyway.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
03:00
Um and we have some great brands coming and uh a very limited amount of solution providers uh as we don't sell vendor tickets. So, um, just want to give a little bit of an update with a 2 and 1/2 week countdown. I am, as my daughter would say, nervecited. I am both nervous and excited. Okay. Well, let's dive into the news. Uh, like I said, I'm just going to highlight two stories today. Uh, we're going to do a follow up on the ID scan breach that Frank McKenna and I talked about last week. It contained 153 million driver's licenses in the US. Uh we determined that that's about almost half of all uh adult the adult population in the US. So that's a lot of driver's licenses. Um primarily from car rental places and retailers, uh government, uh contracts, that type of thing. And the reason why it was so scary is because they're not just pictures of a driver's license. They're a scan of a driver's license. They include the holograph. They include, you know, all of that. Um, and if someone were to use that for, you know, KYC, like know your customer when they're onboarding an account, especially at a bank or, uh, as a seller, um, for a marketplace, that type of thing. They wouldn't be using a fake ID. So, most identity documentation verification companies, that's a quite the mouthful, uh wouldn't be able to detect that it was fraud. So, that was what was most scary. Um, what it seems like now, there haven't been as many articles about it, which is good. Uh, I do think it's in ID scans best interest for that to happen as well. Um, but we believe that it's been taken down by the FBI. Um, the FBI has said that it's been taken down. There were several copies made uh on in dark web forums that a friend of mine in fraud threat intel uh was able to find.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
05:06
However, those copies didn't actually contain the database because you had to pay $10 or $100 each for each driver's license. So, that would be assuming that someone paid 15.3 billion dollars. Am I doing the math right? Um to get all of those driver's licenses and then why would they make them public? So, chances are the copycats out there are just people that are selling uh kind of it's like selling the cover of a record but having no record inside, right? Or the cover of a book but no actual book attached. Um so we're not as worried. Um, are we safe? Yes and no. Uh, I would say we should still operate on the fact that these are out here. Um, I think that it's a little bit of a sigh of relief that the FBI took it down so quickly and that we haven't seen any more databases like this, but you just never know. Uh, and because they were accessed once, could they be accessed again? Hard to know. So, uh it's it's another good example of supply chain uh breaches and uh I talked a little bit about this on the last episode, but basically what that means is instead of going to your company directly, they go to your vendor and they breach your vendor. So, you really should have a lot of good contract language that keeps you safe from if this were to happen with a vendor. I know that there are various types of verbiage that you can uh have in those contracts. You know, some say that the vendor has to pay for credit repair or not credit repair but credit reports. Um the vendor has to own the the data breach. Others say that the merchant or the bank have to own the data breach. Um and when they own it, they have to do all the notifications to consumers. They have to offer the credit report, which is not much and doesn't do a lot, but it's something to provide a little bit of peace of mind to victims. Um, there's also the brand reputation cost and if you're going to have your vendor reimburse you for that. There's just a lot of different things that you can write in that contract. So, be very mindful of that. I think this was a very good example of the reason why that's important. So, as I mentioned, the biggest news story of the week uh broke on Saturday, September 12th. Uh full disclosure, I am recording this on the 13th, so just the day after. So, there may be more news coming out about this after I record. Uh so, you know, do a quick Google search or, you know, chatGPT it or whatever you want to do to learn the updates. But I think this is important because it's a new twist on a fraud scam and it's a new twist that we haven't really seen or heard of before. And whenever that happens, I want to get the news out as soon as possible so that it doesn't work anywhere else. Let me just pull up a notification that was post reposted on LinkedIn. So this is about Revolute. Revolute is a neobank that is mostly in the UK and the EU and they're very large. They're I mean I don't know if they would like this comparison, but I compare them to Chime in the US. Um I think they I don't think that they focus as much on the credit repair piece, but uh the neobanking side, especially for um a younger demographic. They as of September second are actually have a license to operate in the US. Um I kind of had a feeling that was coming because they posted for a head of fraud uh position out of I think Washington DC. I can't remember Boston or Washington DC, I don't know. Somewhere back east. Uh, and that was for the US and I was like, "Huh, I didn't know Revolute was in the US or maybe it's not yet.” And it wasn't until September 2nd. Um, but this actually doesn't have anything to do with operating in the US and I will explain that in just a second. I mean, it has to do with US information, but they could have gotten this another way.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
09:41
So, or that you they didn't have to be in the US to get this information is what I'm saying. So, what happened? Revolute received a request for customer information that appeared to come from a legitimate government agency. That request came from an unauthorized email account sent directly using the official government agency's email domain. As the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request. So, this is a little bit more than a GDPR request. I know I said that at the beginning, but this is, you know, government agencies can request information about individuals. Sometimes they need a warrant, sometimes they don't. Um, but it gives them very detailed information that's usually very secure um on specific individuals. So, it's kind of a one-off situation. It's not like they were able to get all the personal invitation or information of, you know, thousands, tens of thousands, hundreds of thousands of users of Revolute. Um, but very specific ones. So, as the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief belief that it was an authentic government agency request. I think I read that already. Sorry. Identity details. This included the full name, date of birth, and occupation. Also included contact details such as postal address, email address, and telephone number. The document and verification data included a copy of your identity document, so like a passport or a driver's license, and a facial verification image, the selfie you provided for verification. Please note that no biometric facial telemetry data was involved or compromised. You know that's one positive. Financial data was also released including account statements which included the IBAN, the account status, opening date, wallet reference number, withdrawal records, and full transaction history including Bitcoin. So, you could imagine if you want to just steal someone's identity, this would be very good information to have. You've got their identity document. You've got their their name, their date of birth, their occupation, their address, their email address, their phone number.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
12:07
You've got a copy of their passport or their driver's license. You've got the facial recognition or a facial verification image and you've got account statements that include account status, opening date, wallet reference number, and then withdrawal records and full transaction history that includes Bitcoin. That's a lot of information. It's not just for identity theft. You could also use it for espionage. Uh if you were trying to look into how much money has been deposited into somebody's bank account, uh whether they might be being paid by a government agency, whether it's yours or someone else's, you could find out, you know, where their money's come from coming from, how much money they have, at least with this financial institution. And then you know you might be able to find some uh transfers to another bank account at another financial institution and do the same thing. So this information really provides a full picture on a potential victim or target. There was some news uh you so the thing that's most concerning right is the fact that the email at domain was .gov. Now, they say that it uh carried valid domain authentication credentials. It's hard to know what they're doing to authenticate a domain. Some uh I don't know if you remember when I had Cy Khormaee on the podcast just a couple weeks ago. His company uh primarily now I know that they're growing into other use cases but right now they prevent against email phishing and spear phishing campaigns and they're able to determine the real domain the email address is coming from. Um but the fear and there was some information uh put out that same day. The fear was oh my gosh fraudsters can now hack into .gov email addresses. Oh, I guess I kind of buried the lead. The government agency was the US government. It was a US government agency with the domain of .gov.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
14:22
Uh .gov is only used for government agencies. It's not available for anyone else. So, this is what, you know, kind of made the hair on arms stick up was, oh, how are they able to hack a government email address? Because it's a lot more secure than typical inboxes. They require a lot of things to authenticate yourself before you can access your email. So, the fear was how did they get access to that email? Now, as I've talked to one of my best sources for fraud threat intelligence information, I don't believe that that's what happened. I don't I mean I guess it is possible that maybe someone with a .gov email address clicked on a spear phishing link handed over their you know email access to someone through malware and then that request was sent through that way. I think that that's possible. Uh but there's just so much security and I asked my buddy who's in fraud threat intel what he'd been hearing on the dark web or what he thought. I think it's also important to know that he used to work for one of the government agencies that uh has three letters in their name. I don't know if I can say anything else other than that, but it's a big one. And he and he would know, right? Um he was in signal intelligence in the army and then went on to work for one of the three letter uh a government agencies in the US. So he knows his stuff. And what he said was, I'm still not convinced this is real. The attack flow described in a LinkedIn post that I saw um is not possible. So what is much likely happening is a foreign adversary created a. gov URL. So maybe it was instead of a period it was a comma or instead of a O it was actually a U or it was or they were using the international alphabets that look like an O or a V but they're not or used a real name um and was collecting intelligence by claiming to be US government officials. We the US can do that to other countries as well. He referenced which ones but I'm not going to say it especially now that I'm on YouTube. I don't want to get shut down.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
16:45
Uh, you can't just breach a.gov system like they're describing as you need a CAC card, a CAC card to access the emailer. So, I looked up what CAC card was uh on Google cuz I was like, what is this? Um, and it's through the DoD, the Department of Defense. So, it's known as a common access card, and it's a credit card- sized smart card used as a standard identification for active duty military personnel, selected reserves, Department of Defense, civilian employees, and eligible contractors. So, it's got like a smart chip in it, and you have to insert it into a laptop or, you know, the device that you're using in order to access your email. So, what he's saying is even if someone sent a spear phishing email to someone with a .gov email address and bad actors got a hold of that, they couldn't access the inbox because they would need the CAC card inserted into their device in order to access the inbox. So, I thought that was really interesting. He went on to say a few more things. So, this is either someone in the government that wanted to pull user data without authorization. He said that some administrations uh do this often or have done this often. So they don't want to get a warrant, but they want bank information about a target. They may submit this asking for this information without going through the proper channels. Um or it's a foreign adversary creating or using their .gov credentials. If they actually give the emails of the users, you can tell which of the two it is in like one second. But just be coming from a .gov email does not mean it was fraud or that the .gov website was breached. The third and final option would be that it's just a government employee that happened to be a bad actor and was trying to gain access to PII and using their real government credentials, which is also totally possible. But again, that would not be like a third-party fraudster or a breach of the government website or email system.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
19:03
The fact that there was no loss and that they were clearly targeting a small handful of identities tells me it was likely a foreign adversary targeting on an intel op, which not only do we do in the US, but uh he's been very aware of those. Uh, another fun fact, some foreign governments all have access to us .gov accounts and they will use them to collect intelligence like this, too. So, that I thought was really interesting. It's not a data breach. Uh, it's most likely someone who created a website that looked like.gov to the naked eye. Um I don't know if they use a spear phishing tool as sophisticated as can't remember the name of Cy's company but Cy Khormaee's company um where they can tell the metadata about an email but I would hope that the US government would do that but this is a huge issue for Revolute because they've uh it's you know not a huge number of consumers but they're specific and if this is you perpetrated by a foreign national. Well, that's the list of people that they want to target that they want to understand like are they low on money? Can we flip them, you know, for money? Are they this that and the other? So, it's still scary, but it's not as scary as if Revolute was breached altogether, as was kind of implied in a post that went pretty viral. So, I already talked about why this is a big deal. I talked about what can be done with this information. It can be used for espionage. It can be used for identity theft. It can be used for all types of things. How can financial companies prevent this from happening to them? Well, I think it's really important to have an email authenticator that looks at the metadata of email and not just a human looking at it and saying, "Oh, it says .gov." Because chances are they may have used a different letter of the alphabet from another country to create a domain that looks like .gov as I mentioned before, so having something like that set up is important. Requiring two-factor authentication for your employees to access their email inbox depending on the sensitivity of what may be in their inbox could be helpful. Uh just knowing about this possibility is important. And I think talking to the departments that fulfill the requests for information, they should be your first line of defense. Just like customer service is your first line of defense for so many other types of fraud. The department that looks over requests for information, they need to be the first line of defense for that as well. So, that is my biggest piece of advice. You know, there's really two there, right? Invest in an email authenticator for uh requests so that you really, you know, the true domain that they're using. Uh don't just go off of, oh, it says .gov, so I should do it. But then also, you know, training up your team that responds to these to know how to identify signs of fraud. Maybe they're in a real big hurry, you know, because they just stole the card and they want to use it before they get caught. You know, there's so many different things there. So, I wanted to talk about it because it's fairly new and I could see them using the GDPR process for that, too, where, you know, you can request to be deleted. Um, you could request to have, you know, foreign officials be deleted from the records or other types of scenarios because then they wouldn't be able to fulfill those, you know, requests. So, uh, I do think it's important for banks to be aware of. Like I said before, if they try it with Revolute, they're going to try it again. The other thing is is at the time of the these requests, they didn't share the date, but at the time of these requests, they weren't requesting the banking information of Americans. They were questioning the information provided to the government agency um or to Revolute to uh you know verify how much money they have and what they've been spending it on and all of those other things um because that can lead to being able to manipulate someone or be able to steal from them. So, those are really important. You know, I haven't looked at the time recently.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
23:49
This is probably going to be a shorter episode than usual. It is. Um, lately, my solo episodes have been like 45 minutes, 50 minutes, but I was trying to make it a short one this week. I know everybody's kind of getting back in the swing of things after a long summer. And I didn't want to take up all of your time, but I can see into the future. And uh I happen to know that next week's guest is really good and you're going to want to listen. It's SudhirLanka from GrubHub. He is in fraud strategy for GrubHub. He loves fraud strategy. We geeked out on it. Uh but he talks a lot about the different fraud vendors that delivery companies make or or experience. And I was thinking about it the other day. I think the reason why I really enjoy e-commerce fraud, maybe over banking fraud or government fraud or insurance fraud or whatever else, is probably because of my ADHD. I just love like things being different all the time and learning all the time about new things. And in e-commerce, just because a company's in e-commerce does not mean that they're going to see the same type of fraud. They may see completely opposite types of fraud, right? It really depends on what they sell, how they sell it, you know, how they deliver the items. Is it digital? Is it, you know, physical delivery, their business model? So many things make up what typologies you're going to have um with fraud depending on the the type of company you are. So even within Sudhir's company, a company called Wonder bought out Door Dash as well as HelloF is HelloFresh or Plated. It's one of the uh food delivery companies. And then they also have an in-person uh market that uh is called Wonder. Um and Sudhir oversees all three. And he talks about how all three are different. Uh because the business models are different from each other, you know, how things are delivered, when things are charged, just all those different things, how you know, the quality of the food, all of those things. He has three different companies underneath him, so he can move from one thing to the next to the next, which I think is a great opportunity. Uh you can know, you know, what GrubHub's risk signals are, but completely miss it for Wonder or the other one. So, that was a really good conversation. We dove in deep. Uh, I do know there's been a little bit of talk online about how difficult it is to get current merchants to be interviewed on a podcast. And I'm really grateful that I haven't had that much of a problem. I think and I hope it's because people know they'll they can trust me. If they accidentally say something that they can't say because of their company, I'll have my editor delete it. Um, I want this to be the best experience for them. So, with that said, I mean, I wasn't planning on saying this, but I'll say it because it's a good reminder, uh, if you ever want to share your fraud story or gain a little more exposure internationally even, uh, let me know and we can I'm pretty good at thinking of topics that, you know, I know people want to learn from and that, you know, how to talk to them. Even if I just talk to you for 15 minutes, I can usually say, "Okay, this is the kind of session I'm envisioning in my mind." I just did that last week with someone uh where they really weren't sure what format they should have and what title they should have and what the focus should be and within like 25 minutes, we busted it out and had a really good session title and session description and he had a road map for the slides he needed to create. So anyway, I with that I am going to let you guys go and maybe move on to another fraud podcast. Maybe Fraud Forward with Hailey or Scam Rangers with Ayelet. Uh both of those are really good. So is um Stolen by Erin West. That's also a good one. So um I will leave you to it at that. So, thanks so much for joining me today and I look forward to speaking with you more next week.