A person who had £165,000 stolen from his Revolut enterprise account by scammers has instructed BBC Panorama that he believes the corporate’s safety measures failed to stop the theft.
He mentioned criminals managed to bypass the authentication course of to entry his account.
Revolut has to date refused to refund the cash.
The BBC discovered that Revolut noticed extra fraud stories than any main excessive road financial institution within the final monetary yr.
The e-money firm, which has but to achieve full standing as a financial institution, mentioned it takes fraud very severely and has “strong controls” in place to satisfy its authorized and regulatory obligations.
The rise of neobanks
Revolut is one among a lot of new digital-only monetary establishments that supply all their companies on-line or by way of their app – no want to go to a department.
The corporate has grown quickly and has greater than 45 million prospects worldwide, 9 million of whom are within the UK. By 2023, the corporate’s income will virtually triple to £1.8 billion.
These options attracted Jack (who runs worldwide enterprise and desires to carry a number of totally different currencies) to Revolut.
Jack, who requested that we not use his final identify, instructed us that he additionally feels reassured by Revolut’s marketed security measures.
In February of this yr, Jack acquired a name from a scammer pretending to be Revolut at a shared workplace house. He was instructed he bought the decision as a result of his account might need been compromised resulting from his use of shared Wi-Fi.
Jack was tricked into handing over sufficient data for the scammers to switch his Revolut account to their gadget. That meant they may see all of his earlier transactions, together with a purchase order from the web retailer Etsy that morning.
Whereas Jack was nonetheless on the cellphone to the scammer, a textual content message got here from Revolut asking him to enter a six-digit safety code to verify the precise quantity he had spent – £21.98.
“Sure, that is me,” he mentioned, and skim the code to the scammer.
What Jack did not notice was that that they had already arrange their very own account (often known as Etsy), and by sharing the code Revolut despatched him, he approved new funds to their pretend account.
Two extra related texts later emerged authorizing small funds to 2 extra pretend accounts referred to as “Revolut Charges” and “Revolut Charges Care.” Jack accredited these too – which means he was tricked into organising three new payees.
This opened the floodgates and 1000’s of kilos began flying out.
When Jack realized he had been scammed, he instantly contacted Revolut, however there was no devoted helpline, simply an in-app chat operate.
“I despatched them a message saying, ‘I have been scammed, please freeze my account,'” he instructed the BBC.
It took us 23 minutes to get to the proper division the place we might freeze the account, throughout which era an additional £67,000 was stolen.
Jack has now misplaced £165,000. He believes Revolut’s system failed him in a number of methods.
He believes criminals managed to bypass facial recognition software program to entry his accounts on the gadget. Revolut requested for a selfie if organising an account on a brand new gadget, however Jack mentioned he did not present one.
Jack mentioned he requested Revolut to point out him pictures used to license new gadgets. They finally instructed him the photographs weren’t saved of their system, so there was no approach to show what the fraudster had carried out or which photographs have been used.
Panorama investigated the obvious vulnerability and located that it seems to have been mounted.
Jack additionally believes that the truth that 137 particular person funds have been made to 3 new recipients in a single hour must be trigger for concern for Revolut.
Most banks and monetary establishments monitor buyer accounts for uncommon exercise.
“If somebody is instantly processing lots of transactions and making massive funds to new accounts, that is a pink flag — banks ought to often begin investigating a few of this habits,” mentioned fraud knowledgeable Nina Kerkez, who works at information analytics agency LexisNexis Threat Options.
“[They should] Calling their prospects, texting them, by some means ensuring these transactions are reputable.
Revolutionary options in crime reporting
Final yr, the UK’s Nationwide Fraud and Cybercrime Motion Fraud Reporting Middle acquired practically 10,000 stories of fraud involving Revolut, based on a Freedom of Info (FOI) request submitted by Panorama.
That is 2,000 greater than Barclays, one of many UK’s largest banks, and twice as many as Revolut’s similarly-sized rival Monzo.
Panorama interviewed eight former workers to attempt to perceive Revolut’s work tradition, and two points got here up time and time once more: Revolut’s insatiable urge for food for progress and its high-pressure surroundings.
An unnamed insider instructed us: “Defending Revolut from getting used for monetary crime was at all times secondary to the will to launch new merchandise and get present prospects to make use of the product extra.”
Fraud is an issue for all banks, and regardless of advances in fraud-fighting know-how, it continues to value a whole lot of thousands and thousands of individuals.
To guard prospects, monetary corporations carry out extra checks, however typically these safety steps can get in the best way of a clean buyer expertise.
Revolut mentioned it has a “excessive efficiency tradition” and “expects to ship good outcomes for patrons” and that each one new product launches contain a complete danger evaluation and governance approval course of.
The corporate additionally mentioned it has made a “important funding” in its monetary crime prevention crew, which now accounts for greater than a 3rd of its world workforce.
UK’s latest bank: Is your money safe?
Journalist Catrin Nye investigates the tales of Revolut prospects who say scammers stole tens of 1000’s of kilos from their accounts and Revolut failed to guard them.
watch BBC iPlayer Or Monday 14 October 20:00 BBC One (Wales and Northern Eire 20:30)
No refunds
Revolut mentioned it couldn’t touch upon Jack’s case as it’s below investigation by the Monetary Ombudsman Service.
The ombudsman acquired round 3,500 complaints about Revolut in 2023, greater than another financial institution or e-money firm.
“[This] It reveals that in truth Revolut is just not doing sufficient on this space.
Which one did he say? It isn’t really useful to deposit massive quantities of cash with the corporate.
“They’ve a file of not offering compensation to those that have fallen sufferer to fraud or discovered themselves in extraordinarily tough circumstances. [and] Even after the fraudulent exercise was reported, funds have been nonetheless being withdrawn from the account.
Revolut says each potential case of fraud is rigorously investigated in order that the complete circumstances may be assessed and probably the most knowledgeable determination may be made.
Earlier this month, new guidelines have been launched requiring all banks and e-money establishments to supply compensation to victims of fraud.
Most fraud victims will now robotically obtain refunds value as much as £85,000, break up 50-50 between the refunding firm and the receiving firm.
This might be pricey for Revolut.
“We regularly hear from prospects that once they fell sufferer to fraud, they have been instructed to arrange a Revolut account,” mentioned Will Ayles of Refundee, which focuses on fraud restoration.
“The takeaway from that is that it’s in all probability secure to say that fraud victims are suggested to arrange a Revolut account as fraudsters discover it simpler to maneuver funds by way of Revolut than another financial institution.”
When somebody is tricked into transferring cash to a fraudster, it is referred to as approved push cost (APP) fraud. That is the commonest kind of monetary fraud within the UK.
Final yr, figures from the Cost Techniques Regulator confirmed that for each £1 million paid right into a Revolut account, £756 was attributed to APP fraud.
That is greater than 10 occasions the quantity at Barclays and greater than 4 occasions that at Monzo.
Revolut mentioned it takes fraud very severely and has options in place, together with deferring funds, to “give prospects pause, assume and full extra checks”.
It additionally mentioned it not too long ago introduced “a brand new biometric characteristic” and “a complicated AI fraud detection characteristic to guard prospects from card fraud.”
Britain’s latest financial institution?
In July this yr, the UK banking regulator granted Revolut a provisional banking license, and the corporate is presently transferring in direction of turning into a full-fledged financial institution.
Which means that if Revolut goes bust, as much as £85,000 of every buyer’s deposit will likely be assured.
Till then, it would proceed to function as an digital cash establishment or digital cash firm.
Nonetheless, turning into a financial institution means will probably be in a position to lengthen credit score to prospects by way of bank cards, overdrafts and mortgages.
“This implies prospects are at larger danger if they’re focused by scammers,” mentioned Rob Lilley-Jones.
“I believe there could also be political components to Revolut’s licensing as a result of it’s turning into sufficiently big to problem industrial banks,” mentioned Frances Coppola, a monetary journalist and knowledgeable on banking danger and regulation.
“I do not assume any authorities would need to enable an company of this dimension to comply with the principles at will.” Nonetheless, she added: “Given the variety of complaints, I suppose you would possibly query whether or not Revolut ought to have been given a license.”
The Finance Ministry mentioned the choice on whether or not to grant Revolut a banking license rests with the unbiased regulator. They declined to remark to Panorama.
Revolut mentioned it adheres to the identical regulatory requirements as any excessive road financial institution and regrets any state of affairs the place a buyer is focused by criminals.
The corporate mentioned fraud dropped by 20% final yr however acknowledged that “extra must be carried out”.
Methods to make a criticism in case you are a sufferer of fraud
- Clients can complain to any regulated agency Financial Ombudsman Servicecan resolve disputes and order companies to pay compensation
- Necessary reimbursement requirement rules launched on 7 October 2024
- They are going to cowl the overwhelming majority of remittances within the UK as much as £85,000, apart from worldwide transfers or these involving cryptocurrency
- New measures shield people, micro-businesses with fewer than 10 workers and charities with annual income of lower than £1 million
- BBC Mobile has more resources