Sardine named a Leader in The Forrester Wave™: Financial Crime Management Solutions, Q3 2026

Learn More
Fraudology

Um golpe de phishing por e-mail governamental e uma atualização sobre a violação de dados de digitalização de documentos de identidade

28 min

Boas-vindas de volta ao Fraudology.

Este é um episódio a solo, e esta semana tenho duas histórias para partilhar convosco. Queria dar seguimento à violação de dados de digitalizações de documentos de identificação que eu e Frank McKenna discutimos na semana passada: em que ponto está a situação, se ainda devemos estar preocupados e o que a violação de dados de cartas de condução significa para a prevenção de fraudes nos processos KYC daqui para a frente.

Depois, queria abordar uma das maiores histórias de fraude desta semana. Esta acabou de acontecer e queria partilhá-la consigo o mais rapidamente possível. A Revolut foi alvo de um esquema de phishing por e-mail governamental, que utilizou o que parecia ser um domínio de e-mail .gov legítimo. O pedido foi atendido. Foram divulgados dados de clientes. E nem sequer foi necessário violar os sistemas da Revolut. Bastou um e-mail falsificado que parecia suficientemente autêntico para passar despercebido.

Tenho conversado sobre isso com minhas fontes de inteligência sobre ameaças de fraude, incluindo alguém que já trabalhou em uma das agências governamentais conhecidas por uma sigla de três letras. O que ele me disse mudou completamente a forma como encaro esse incidente. Vamos analisar tudo em detalhes.

Este é um episódio sobre notícias de fraude, e hoje vou ser breve. Vamos ao que interessa.

O que você vai ouvir neste episódio:

  • Atualização sobre o vazamento de dados de digitalização de documentos de identidade. A situação atual do banco de dados com 153 milhões de carteiras de habilitação, por que a operação do FBI é importante e se ainda devemos considerar isso uma ameaça ativa.
  • Por que o vazamento de dados de documentos de identidade digitalizados foi tão perigoso para a detecção de fraudes em processos de KYC e de fraudes com documentos de identidade. E por que a maioria das empresas de verificação não o teria detectado.
  • Como se apresenta, na prática, o risco de violação de dados na cadeia de fornecimento e quais cláusulas contratuais com fornecedores todas as instituições financeiras devem adotar.
  • O incidente de fraude envolvendo um pedido governamental à Revolut, explicado. Que dados foram divulgados, o que um fraudador pode fazer com eles e por que podem ser usados para roubo de identidade e espionagem.
  • Por que um domínio de e-mail .gov é mais difícil de falsificar do que parece, o que é um cartão CAC e por que ele é importante para a segurança dos e-mails governamentais, e o que a minha fonte de inteligência sobre ameaças de fraude realmente acha que aconteceu.
  • As três explicações mais prováveis para esse golpe de phishing por e-mail governamental, incluindo a possibilidade de fraude por parte de um adversário estrangeiro, que muda completamente o cenário.
  • Como prevenir o phishing por e-mail envolvendo órgãos governamentais na sua instituição financeira, usar ferramentas de autenticação de e-mail e autenticação de dois fatores para o acesso a caixas de entrada confidenciais e treinar a equipe responsável por solicitações governamentais de informações.
  • Por que esse tipo de fraude de falsificação de domínio de e-mail voltará a ser tentado e o que as equipes de prevenção a fraudes dos neobancos precisam especificamente implementar.

Você deveria ouvir este episódio se:

  • Trabalha nas áreas de fraude, conformidade ou risco num banco, neobanco ou instituição financeira e quer compreender o que o incidente da Revolut realmente significa para a sua equipa.
  • É responsável pela prevenção de phishing numa instituição financeira e procura recomendações práticas que possa implementar já esta semana.
  • Querem entender como funciona a fraude de falsificação de identidade de entidades governamentais e por que motivo um e-mail .gov não garante a sua legitimidade.
  • Estão avaliando os contratos com seus fornecedores quanto às cláusulas de responsabilidade por violações de dados na cadeia de suprimentos e desejam uma estrutura que indique o que incluir.
  • Trabalha na prevenção de fraudes em processos de KYC e quer entender por que a violação de dados de digitalizações de documentos de identidade foi especialmente perigosa para a verificação desses documentos.
  • Acompanhe as notícias sobre fraudes e conheça a análise de um especialista sobre o que realmente aconteceu com a Revolut, e não apenas a versão viral do LinkedIn.
Notas do episódio

A violação de dados de digitalização de documentos de identificação: ponto da situação

Frank McKenna e eu abordámos este assunto na semana passada. A novidade é que o FBI parece tê-lo retirado rapidamente. As cópias encontradas em fóruns da dark web, identificadas por contactos na área da inteligência sobre ameaças de fraude, não continham, na verdade, a base de dados completa. Comprar licenças individuais ao preço anunciado teria custado mais de 15 mil milhões de dólares, o que torna mais provável que os anúncios de imitação fossem apenas fachadas sem conteúdo, e não dados reais.

Estamos seguros? Sim e não. A lição mais importante diz respeito à vertente das violações de dados na cadeia de abastecimento. Os contratos com os seus fornecedores são importantes. Saiba quem é responsável pela notificação de uma violação. Saiba se o seu fornecedor é responsável pelos custos de monitorização de crédito e de reparação dos danos. Saiba qual é o risco para a reputação da sua marca caso uma violação num fornecedor exponha os dados dos seus clientes. Formalize estas cláusulas por escrito antes de precisar delas.

O incidente de fraude envolvendo um pedido governamental à Revolut

Esta história veio a público no sábado, 12 de setembro. Estou a gravar isto no dia seguinte. Poderá haver novidades quando ouvir isto, mas eis o que sabemos.

A Revolut recebeu um pedido do que parecia ser uma agência legítima do governo dos EUA, com credenciais válidas de autenticação de domínio. O pedido foi atendido por se acreditar, de forma razoável, que era autêntico. Os dados divulgados constituem um retrato completo de uma pessoa, que pode ser usado para fraude financeira ou até mesmo espionagem, o que torna tão relevante a possibilidade de fraude por parte de um adversário estrangeiro.

O que a minha fonte de informações sobre fraude me disse é que uma violação genuína de um sistema .gov é extremamente improvável. Na sua avaliação, o mais provável é que um adversário estrangeiro tenha criado um domínio de e-mail que parecia legítimo à primeira vista, mas continha a substituição de um caráter. Também pode ter sido um agente interno do governo a apresentar um pedido sem seguir os canais adequados, ou um funcionário público mal-intencionado a utilizar credenciais reais. Não se tratou de uma extração de dados em massa. Foi visado um pequeno número de indivíduos muito específicos. Tratou-se de uma operação de informações, não de uma rede de fraude.

Como prevenir o phishing por e-mails governamentais em sua instituição financeira

A equipa responsável por tratar os pedidos de informação governamentais é a sua primeira linha de defesa, tal como o apoio ao cliente é a sua primeira linha de defesa contra fraudes dirigidas aos consumidores. A equipa precisa de saber que um endereço de e-mail .gov não é suficiente para autenticar um pedido. Precisa de formação sobre fraudes de falsificação de domínios de e-mail, sobre como identificar sinais de urgência num pedido fraudulento e sobre quando encaminhar o pedido para uma instância superior antes de lhe dar seguimento.

No que diz respeito às ferramentas, invista num autenticador de e-mail que analise os metadados das mensagens recebidas, e não apenas o domínio visível. A autenticação de dois fatores em qualquer caixa de entrada que processe pedidos governamentais sensíveis acrescenta uma camada adicional de segurança. Reveja também, de ponta a ponta, o seu processo de tratamento de pedidos governamentais de informação. Se atualmente esse processo depender de uma pessoa que lê um endereço de e-mail .gov e dá seguimento ao pedido, terá de ser alterado.

Por que isso vai acontecer novamente

Se este ataque funcionou com a Revolut, será tentado noutros locais. Criar um domínio que pareça verdadeiro a olho nu exige conhecimentos técnicos, mas não recursos excecionais. O retorno é extremamente valioso, tanto para fins de fraude como de recolha de informações. As instituições financeiras devem encarar isto como uma categoria de ataque já estabelecida, e não como um caso isolado. Atualize o seu processo de verificação de pedidos governamentais, forme a equipa responsável por esses pedidos e implemente as ferramentas adequadas de autenticação de e-mail antes que a próxima tentativa chegue à sua caixa de entrada.

Principais conclusões
  • A violação de dados de digitalização de documentos de identificação parece estar contida, mas ainda devemos agir como se os dados desta carteira de motorista estivessem acessíveis. Eles já foram acessados uma vez, e as condições que permitiram esse acesso não mudaram.
  • O risco de violação de dados na cadeia de fornecimento não é meramente teórico. O incidente envolvendo a digitalização de documentos de identificação é um exemplo direto de uma violação por parte de um fornecedor que expôs os dados dos seus clientes. Os seus contratos devem definir quem é responsável pela notificação da violação, pelas medidas corretivas e pelos custos associados à reputação da marca, antes que tenha de descobrir isso da pior forma.
  • O incidente de fraude envolvendo uma solicitação governamental à Revolut quase certamente não resultou de uma violação do sistema de e-mail do governo dos EUA. Para acessar uma caixa de entrada .gov legítima, é necessário inserir um cartão CAC físico no dispositivo. Isso torna extremamente difícil realizar spear phishing baseado em credenciais contra uma caixa de entrada .gov.
  • Os dados divulgados no incidente da Revolut incluem documentos de identidade, imagens de verificação facial e o histórico completo de transações, incluindo Bitcoin, e são suficientes para muito mais do que apenas roubo de identidade.
  • A equipe responsável por atender às solicitações de informações governamentais em sua instituição é sua primeira linha de defesa. As ferramentas de autenticação de e-mail são o controle técnico mais importante que as instituições financeiras podem implementar neste momento. Combine várias camadas de defesa.
  • Se este ataque funcionou uma vez, será tentado novamente.
Conclusão final

Duas histórias esta semana, e ambas nos levam à mesma lição. Muitas vezes, o ponto mais fraco da sua defesa contra fraudes não são os seus sistemas, mas sim o processo seguido por uma pessoa quando algo parece legítimo. A digitalização de uma carta de condução que passa em todas as verificações não é automaticamente autêntica. Um endereço de e-mail .gov não pertence automaticamente ao governo. É nas pessoas e nos processos por detrás dessas etapas de verificação que reside a falha, e é aí que os autores de fraudes continuarão a atuar até conseguirmos eliminá-la.

Ambas as histórias tiveram uma versão que se espalhou rapidamente e outra que pareceu um pouco diferente quando se investigou mais a fundo. As notícias sobre fraudes vão além das manchetes. O que importa é a comunidade por trás da história: a conversa, as conexões e as respostas verdadeiras que vêm de pessoas reais. Obrigado por estar aqui. Até a próxima semana.

Conecte-se com Karisse Hendrick | LinkedIn
Apresentadora do podcast Fraudology
Especialista premiada em fraudes cibernéticas
Consultora de prevenção a fraudes no comércio eletrônico
Conselheira de startups, palestrante e
consultora de empresas da Fortune 500

Episode transcript
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:07
Welcome back to Fraudology. I'm Karisse Hendrick. This is another solo episode. Um, we just had Frank McKenna on the podcast talking about the big ID scan uh data breach as well as digital arrests. This is something he's been talking about since uh the end of last year. And I mentioned on that episode that I was a little skeptical that they would ever come to the US or any western states but or countries, but they did. Um so that's a really interesting episode. Today I'm going to do a little bit of a followup on that ID scan breach and if we should still be worried and what we can do. And then I'm going to talk about uh the biggest news story of the week which um was with Revolute and it's a newer it's a really creative way of using GDPR against a company um to gain information and gain personal uh information that's usually private uh about specific individuals. So and this can be done at any financial institution. So, I'm going to dive into it a little bit. I'll share what it happened and then, you know, why we should worry about it and what it means and all of that. Um, so yeah, that's what today has in store for you. I'm just going to give you a 2 and 1/2 week notice that MFA is coming soon. I don't know how much boots on the ground I'm going to be able to record uh while at MFA just because got to be busy. Uh but I um will definitely be providing some behind the scenes uh information and that type of thing after the fact. Uh it won't be the same as attending obviously. And if you are, you know, in the Chicago area or you are just a short flight, you know, or you're willing to fly far uh to Chicago, it is October 6th and 7th in Chicago. Uh October 5th is a merchant-only um AI boot camp led by two people from PlayStation and one from GoDaddy uh sharing how the real world examples of how they use generative AI for fraud operations. And uh they're going to be providing some takeaways like some prompts and dashboards, things like that, so that it's very tactical and practical. And that's really what we want to provide with MFA is from each session something to walk away with. And I think we're gonna do that. I am so close to finalizing the agenda. I'm about three or four weeks later than I wanted to be. Uh but there were a few unforeseen circumstances. Um but you know that's okay. Uh thankfully we have you know a couple hundred people that are coming anyway.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
03:00
Um and we have some great brands coming and uh a very limited amount of solution providers uh as we don't sell vendor tickets. So, um, just want to give a little bit of an update with a 2 and 1/2 week countdown. I am, as my daughter would say, nervecited. I am both nervous and excited. Okay. Well, let's dive into the news. Uh, like I said, I'm just going to highlight two stories today. Uh, we're going to do a follow up on the ID scan breach that Frank McKenna and I talked about last week. It contained 153 million driver's licenses in the US. Uh we determined that that's about almost half of all uh adult the adult population in the US. So that's a lot of driver's licenses. Um primarily from car rental places and retailers, uh government, uh contracts, that type of thing. And the reason why it was so scary is because they're not just pictures of a driver's license. They're a scan of a driver's license. They include the holograph. They include, you know, all of that. Um, and if someone were to use that for, you know, KYC, like know your customer when they're onboarding an account, especially at a bank or, uh, as a seller, um, for a marketplace, that type of thing. They wouldn't be using a fake ID. So, most identity documentation verification companies, that's a quite the mouthful, uh wouldn't be able to detect that it was fraud. So, that was what was most scary. Um, what it seems like now, there haven't been as many articles about it, which is good. Uh, I do think it's in ID scans best interest for that to happen as well. Um, but we believe that it's been taken down by the FBI. Um, the FBI has said that it's been taken down. There were several copies made uh on in dark web forums that a friend of mine in fraud threat intel uh was able to find.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
05:06
However, those copies didn't actually contain the database because you had to pay $10 or $100 each for each driver's license. So, that would be assuming that someone paid 15.3 billion dollars. Am I doing the math right? Um to get all of those driver's licenses and then why would they make them public? So, chances are the copycats out there are just people that are selling uh kind of it's like selling the cover of a record but having no record inside, right? Or the cover of a book but no actual book attached. Um so we're not as worried. Um, are we safe? Yes and no. Uh, I would say we should still operate on the fact that these are out here. Um, I think that it's a little bit of a sigh of relief that the FBI took it down so quickly and that we haven't seen any more databases like this, but you just never know. Uh, and because they were accessed once, could they be accessed again? Hard to know. So, uh it's it's another good example of supply chain uh breaches and uh I talked a little bit about this on the last episode, but basically what that means is instead of going to your company directly, they go to your vendor and they breach your vendor. So, you really should have a lot of good contract language that keeps you safe from if this were to happen with a vendor. I know that there are various types of verbiage that you can uh have in those contracts. You know, some say that the vendor has to pay for credit repair or not credit repair but credit reports. Um the vendor has to own the the data breach. Others say that the merchant or the bank have to own the data breach. Um and when they own it, they have to do all the notifications to consumers. They have to offer the credit report, which is not much and doesn't do a lot, but it's something to provide a little bit of peace of mind to victims. Um, there's also the brand reputation cost and if you're going to have your vendor reimburse you for that. There's just a lot of different things that you can write in that contract. So, be very mindful of that. I think this was a very good example of the reason why that's important. So, as I mentioned, the biggest news story of the week uh broke on Saturday, September 12th. Uh full disclosure, I am recording this on the 13th, so just the day after. So, there may be more news coming out about this after I record. Uh so, you know, do a quick Google search or, you know, chatGPT it or whatever you want to do to learn the updates. But I think this is important because it's a new twist on a fraud scam and it's a new twist that we haven't really seen or heard of before. And whenever that happens, I want to get the news out as soon as possible so that it doesn't work anywhere else. Let me just pull up a notification that was post reposted on LinkedIn. So this is about Revolute. Revolute is a neobank that is mostly in the UK and the EU and they're very large. They're I mean I don't know if they would like this comparison, but I compare them to Chime in the US. Um I think they I don't think that they focus as much on the credit repair piece, but uh the neobanking side, especially for um a younger demographic. They as of September second are actually have a license to operate in the US. Um I kind of had a feeling that was coming because they posted for a head of fraud uh position out of I think Washington DC. I can't remember Boston or Washington DC, I don't know. Somewhere back east. Uh, and that was for the US and I was like, "Huh, I didn't know Revolute was in the US or maybe it's not yet.” And it wasn't until September 2nd. Um, but this actually doesn't have anything to do with operating in the US and I will explain that in just a second. I mean, it has to do with US information, but they could have gotten this another way.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
09:41
So, or that you they didn't have to be in the US to get this information is what I'm saying. So, what happened? Revolute received a request for customer information that appeared to come from a legitimate government agency. That request came from an unauthorized email account sent directly using the official government agency's email domain. As the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request. So, this is a little bit more than a GDPR request. I know I said that at the beginning, but this is, you know, government agencies can request information about individuals. Sometimes they need a warrant, sometimes they don't. Um, but it gives them very detailed information that's usually very secure um on specific individuals. So, it's kind of a one-off situation. It's not like they were able to get all the personal invitation or information of, you know, thousands, tens of thousands, hundreds of thousands of users of Revolute. Um, but very specific ones. So, as the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief belief that it was an authentic government agency request. I think I read that already. Sorry. Identity details. This included the full name, date of birth, and occupation. Also included contact details such as postal address, email address, and telephone number. The document and verification data included a copy of your identity document, so like a passport or a driver's license, and a facial verification image, the selfie you provided for verification. Please note that no biometric facial telemetry data was involved or compromised. You know that's one positive. Financial data was also released including account statements which included the IBAN, the account status, opening date, wallet reference number, withdrawal records, and full transaction history including Bitcoin. So, you could imagine if you want to just steal someone's identity, this would be very good information to have. You've got their identity document. You've got their their name, their date of birth, their occupation, their address, their email address, their phone number.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
12:07
You've got a copy of their passport or their driver's license. You've got the facial recognition or a facial verification image and you've got account statements that include account status, opening date, wallet reference number, and then withdrawal records and full transaction history that includes Bitcoin. That's a lot of information. It's not just for identity theft. You could also use it for espionage. Uh if you were trying to look into how much money has been deposited into somebody's bank account, uh whether they might be being paid by a government agency, whether it's yours or someone else's, you could find out, you know, where their money's come from coming from, how much money they have, at least with this financial institution. And then you know you might be able to find some uh transfers to another bank account at another financial institution and do the same thing. So this information really provides a full picture on a potential victim or target. There was some news uh you so the thing that's most concerning right is the fact that the email at domain was .gov. Now, they say that it uh carried valid domain authentication credentials. It's hard to know what they're doing to authenticate a domain. Some uh I don't know if you remember when I had Cy Khormaee on the podcast just a couple weeks ago. His company uh primarily now I know that they're growing into other use cases but right now they prevent against email phishing and spear phishing campaigns and they're able to determine the real domain the email address is coming from. Um but the fear and there was some information uh put out that same day. The fear was oh my gosh fraudsters can now hack into .gov email addresses. Oh, I guess I kind of buried the lead. The government agency was the US government. It was a US government agency with the domain of .gov.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
14:22
Uh .gov is only used for government agencies. It's not available for anyone else. So, this is what, you know, kind of made the hair on arms stick up was, oh, how are they able to hack a government email address? Because it's a lot more secure than typical inboxes. They require a lot of things to authenticate yourself before you can access your email. So, the fear was how did they get access to that email? Now, as I've talked to one of my best sources for fraud threat intelligence information, I don't believe that that's what happened. I don't I mean I guess it is possible that maybe someone with a .gov email address clicked on a spear phishing link handed over their you know email access to someone through malware and then that request was sent through that way. I think that that's possible. Uh but there's just so much security and I asked my buddy who's in fraud threat intel what he'd been hearing on the dark web or what he thought. I think it's also important to know that he used to work for one of the government agencies that uh has three letters in their name. I don't know if I can say anything else other than that, but it's a big one. And he and he would know, right? Um he was in signal intelligence in the army and then went on to work for one of the three letter uh a government agencies in the US. So he knows his stuff. And what he said was, I'm still not convinced this is real. The attack flow described in a LinkedIn post that I saw um is not possible. So what is much likely happening is a foreign adversary created a. gov URL. So maybe it was instead of a period it was a comma or instead of a O it was actually a U or it was or they were using the international alphabets that look like an O or a V but they're not or used a real name um and was collecting intelligence by claiming to be US government officials. We the US can do that to other countries as well. He referenced which ones but I'm not going to say it especially now that I'm on YouTube. I don't want to get shut down.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
16:45
Uh, you can't just breach a.gov system like they're describing as you need a CAC card, a CAC card to access the emailer. So, I looked up what CAC card was uh on Google cuz I was like, what is this? Um, and it's through the DoD, the Department of Defense. So, it's known as a common access card, and it's a credit card- sized smart card used as a standard identification for active duty military personnel, selected reserves, Department of Defense, civilian employees, and eligible contractors. So, it's got like a smart chip in it, and you have to insert it into a laptop or, you know, the device that you're using in order to access your email. So, what he's saying is even if someone sent a spear phishing email to someone with a .gov email address and bad actors got a hold of that, they couldn't access the inbox because they would need the CAC card inserted into their device in order to access the inbox. So, I thought that was really interesting. He went on to say a few more things. So, this is either someone in the government that wanted to pull user data without authorization. He said that some administrations uh do this often or have done this often. So they don't want to get a warrant, but they want bank information about a target. They may submit this asking for this information without going through the proper channels. Um or it's a foreign adversary creating or using their .gov credentials. If they actually give the emails of the users, you can tell which of the two it is in like one second. But just be coming from a .gov email does not mean it was fraud or that the .gov website was breached. The third and final option would be that it's just a government employee that happened to be a bad actor and was trying to gain access to PII and using their real government credentials, which is also totally possible. But again, that would not be like a third-party fraudster or a breach of the government website or email system.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
19:03
The fact that there was no loss and that they were clearly targeting a small handful of identities tells me it was likely a foreign adversary targeting on an intel op, which not only do we do in the US, but uh he's been very aware of those. Uh, another fun fact, some foreign governments all have access to us .gov accounts and they will use them to collect intelligence like this, too. So, that I thought was really interesting. It's not a data breach. Uh, it's most likely someone who created a website that looked like.gov to the naked eye. Um I don't know if they use a spear phishing tool as sophisticated as can't remember the name of Cy's company but Cy Khormaee's company um where they can tell the metadata about an email but I would hope that the US government would do that but this is a huge issue for Revolute because they've uh it's you know not a huge number of consumers but they're specific and if this is you perpetrated by a foreign national. Well, that's the list of people that they want to target that they want to understand like are they low on money? Can we flip them, you know, for money? Are they this that and the other? So, it's still scary, but it's not as scary as if Revolute was breached altogether, as was kind of implied in a post that went pretty viral. So, I already talked about why this is a big deal. I talked about what can be done with this information. It can be used for espionage. It can be used for identity theft. It can be used for all types of things. How can financial companies prevent this from happening to them? Well, I think it's really important to have an email authenticator that looks at the metadata of email and not just a human looking at it and saying, "Oh, it says .gov." Because chances are they may have used a different letter of the alphabet from another country to create a domain that looks like .gov as I mentioned before, so having something like that set up is important. Requiring two-factor authentication for your employees to access their email inbox depending on the sensitivity of what may be in their inbox could be helpful. Uh just knowing about this possibility is important. And I think talking to the departments that fulfill the requests for information, they should be your first line of defense. Just like customer service is your first line of defense for so many other types of fraud. The department that looks over requests for information, they need to be the first line of defense for that as well. So, that is my biggest piece of advice. You know, there's really two there, right? Invest in an email authenticator for uh requests so that you really, you know, the true domain that they're using. Uh don't just go off of, oh, it says .gov, so I should do it. But then also, you know, training up your team that responds to these to know how to identify signs of fraud. Maybe they're in a real big hurry, you know, because they just stole the card and they want to use it before they get caught. You know, there's so many different things there. So, I wanted to talk about it because it's fairly new and I could see them using the GDPR process for that, too, where, you know, you can request to be deleted. Um, you could request to have, you know, foreign officials be deleted from the records or other types of scenarios because then they wouldn't be able to fulfill those, you know, requests. So, uh, I do think it's important for banks to be aware of. Like I said before, if they try it with Revolute, they're going to try it again. The other thing is is at the time of the these requests, they didn't share the date, but at the time of these requests, they weren't requesting the banking information of Americans. They were questioning the information provided to the government agency um or to Revolute to uh you know verify how much money they have and what they've been spending it on and all of those other things um because that can lead to being able to manipulate someone or be able to steal from them. So, those are really important. You know, I haven't looked at the time recently.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
23:49
This is probably going to be a shorter episode than usual. It is. Um, lately, my solo episodes have been like 45 minutes, 50 minutes, but I was trying to make it a short one this week. I know everybody's kind of getting back in the swing of things after a long summer. And I didn't want to take up all of your time, but I can see into the future. And uh I happen to know that next week's guest is really good and you're going to want to listen. It's SudhirLanka from GrubHub. He is in fraud strategy for GrubHub. He loves fraud strategy. We geeked out on it. Uh but he talks a lot about the different fraud vendors that delivery companies make or or experience. And I was thinking about it the other day. I think the reason why I really enjoy e-commerce fraud, maybe over banking fraud or government fraud or insurance fraud or whatever else, is probably because of my ADHD. I just love like things being different all the time and learning all the time about new things. And in e-commerce, just because a company's in e-commerce does not mean that they're going to see the same type of fraud. They may see completely opposite types of fraud, right? It really depends on what they sell, how they sell it, you know, how they deliver the items. Is it digital? Is it, you know, physical delivery, their business model? So many things make up what typologies you're going to have um with fraud depending on the the type of company you are. So even within Sudhir's company, a company called Wonder bought out Door Dash as well as HelloF is HelloFresh or Plated. It's one of the uh food delivery companies. And then they also have an in-person uh market that uh is called Wonder. Um and Sudhir oversees all three. And he talks about how all three are different. Uh because the business models are different from each other, you know, how things are delivered, when things are charged, just all those different things, how you know, the quality of the food, all of those things. He has three different companies underneath him, so he can move from one thing to the next to the next, which I think is a great opportunity. Uh you can know, you know, what GrubHub's risk signals are, but completely miss it for Wonder or the other one. So, that was a really good conversation. We dove in deep. Uh, I do know there's been a little bit of talk online about how difficult it is to get current merchants to be interviewed on a podcast. And I'm really grateful that I haven't had that much of a problem. I think and I hope it's because people know they'll they can trust me. If they accidentally say something that they can't say because of their company, I'll have my editor delete it. Um, I want this to be the best experience for them. So, with that said, I mean, I wasn't planning on saying this, but I'll say it because it's a good reminder, uh, if you ever want to share your fraud story or gain a little more exposure internationally even, uh, let me know and we can I'm pretty good at thinking of topics that, you know, I know people want to learn from and that, you know, how to talk to them. Even if I just talk to you for 15 minutes, I can usually say, "Okay, this is the kind of session I'm envisioning in my mind." I just did that last week with someone uh where they really weren't sure what format they should have and what title they should have and what the focus should be and within like 25 minutes, we busted it out and had a really good session title and session description and he had a road map for the slides he needed to create. So anyway, I with that I am going to let you guys go and maybe move on to another fraud podcast. Maybe Fraud Forward with Hailey or Scam Rangers with Ayelet. Uh both of those are really good. So is um Stolen by Erin West. That's also a good one. So um I will leave you to it at that. So, thanks so much for joining me today and I look forward to speaking with you more next week.