Shownotes
Welcome back to Fraudology.
This is a solo episode, and I’ve got two stories for you this week. I wanted to follow-up on the ID scan breach that Frank McKenna and I discussed last week. Where things stand now, whether we should still be worried, and what the driver’s license data breach means for KYC fraud prevention going forward.
And then I wanted to get into one of the biggest fraud stories this week. This one is brand new and I wanted to get it to you as soon as possible. A government email phishing scam hit Revolute using what appeared to be a legitimate .gov email domain. The request was fulfilled. Customer data was released. And it did not require a breach of Revolute at all. It required a spoofed email that looked real enough to pass.
I have been talking to my fraud threat intelligence sources about this, including someone with a background at one of the three-letter government agencies. What he told me changed how I’m thinking about this incident entirely. We are going to get into all of it.
This is a fraud news episode, and I’m going to keep it tight today. Let’s dive in.
What you’ll hear in this episode:
- The ID scan data breach update. Where the 153 million driver’s license database stands now, why the FBI takedown matters, and whether we should still be treating this as an active threat.
- Why the ID scan breach was so dangerous for KYC fraud and identity document fraud detection. And why most verification companies would not have caught it.
- What supply chain data breach risk looks like in practice and the vendor contract language every financial institution should have in place.
- The Revolute government request fraud incident explained. What data was released, what a fraudster can do with it, and why it could be used for identity theft and espionage.
- Why a .gov email domain is harder to spoof than it sounds, what a CAC card is and why it matters for government email security, and what my fraud threat intelligence source actually thinks happened.
- The three most likely explanations for this government email phishing scam. Including the foreign adversary fraud angle that changes the whole picture.
- How to prevent government email phishing at your financial institution, email authentication tools, two factor authentication for sensitive inbox access, and training the team that handles government information requests.
- Why this kind of email domain spooking fraud is going to be attempted again, and what neobank fraud prevention teams specifically need to have in place.
You should listen to this episode if you:
- Work in fraud, compliance, or risk at a bank, neobank, or financial institution and want to understand what the Revolute incident actually means for your team.
- Are responsible for financial institution phishing prevention and want practical recommendations you can bring back this week.
- Want to understand how government impersonation fraud works and why a .gov email does not guarantee legitimacy.
- Are evaluating your vendor contracts for supply chain data breach liability language and want a framework for what to include.
- Work in KYC fraud prevention and want to understand why the ID scan data breach was uniquely dangerous for identity document verification.
- Follow fraud news and want a practitioner's read on what actually happened with Revolute, not just the viral LinkedIn version.