A person who had £165,000 stolen from his Revolut enterprise account by fraudsters has advised BBC Panorama he believes the corporate’s safety measures failed to stop the theft.
He says criminals managed to bypass the ID verification course of to realize entry to his account.
To date, Revolut has refused to refund this cash.
The BBC has discovered that Revolut was named in additional experiences of fraud within the final monetary 12 months than any of the most important Excessive Road banks.
The e-money agency – which has not but been granted full standing as a financial institution – says it takes fraud extremely significantly and that it has “strong controls” to fulfill its authorized and regulatory obligations.
Rise of recent sort of banks
Revolut is amongst quite a lot of new digital-only monetary establishments that provide all their providers on-line or by an app – there are not any branches to go to.
The agency has grown quickly and amassed greater than 45 million clients worldwide, of which 9 million are within the UK. It nearly tripled its income to £1.8bn in 2023. Its accounts are fast to open and provide aggressive overseas trade charges in an easy-to-use app.
These have been the options that attracted Jack – who runs a world enterprise and wishes to carry a number of completely different currencies – to Revolut.
Jack, who requested us to not use his surname, advised us he was additionally reassured by the security measures Revolut promote of their promoting.
In February, Jack was in a co-working area when he acquired a telephone name from a scammer pretending to be from Revolut. He was advised he was being referred to as as a result of his account may need been compromised by being on shared Wi-Fi.
Jack was tricked into handing over sufficient data to permit the scammers to place his Revolut account onto their machine. This meant they might see all his earlier transactions, together with a purchase order on the on-line retailer Etsy that morning.
Whereas Jack was nonetheless on the telephone to the scammers, a textual content message from Revolut arrived, asking him to verify the very same quantity he had spent – £21.98 – by typing in a six-digit safety code.
He stated, “Sure, that was me,” and skim out the code to the scammers.
What Jack didn’t realise was that they’d arrange their very own account – additionally referred to as Etsy – and by sharing the code Revolut had despatched him, he was authorising a brand new fee to their pretend account as an alternative.
Two comparable texts adopted to authorise funds of small quantities to 2 additional pretend accounts, referred to as “Revolut charges” and “Revolut charges care”. Jack additionally authorised these – which meant he had been tricked into establishing three new payees.
This opened the floodgates and hundreds of kilos started to fly out.
As quickly as Jack realised he was being scammed, he contacted Revolut – however there was no devoted helpline, only a chat operate deep inside the app.
“I messaged them saying, ‘I’ve been scammed, please freeze my account,’” he advised the BBC.
It took 23 minutes to succeed in the fitting division that might freeze the account, throughout which era one other £67,000 had been taken.
Jack is now out of pocket by £165,000. He thinks Revolut’s methods failed him in a number of methods.
He believes criminals managed to bypass facial-recognition software program to realize entry to his account on their machine. If an account is ready up on a brand new machine, Revolut asks for a selfie, which Jack says he didn’t present.
Jack says he requested Revolut to point out him the picture used to authorised the brand new machine. They finally advised him that it wasn’t saved of their system, so there was no manner of proving what the fraudsters had completed, or what photograph was used.
Panorama investigated this obvious vulnerability and located that it appeared to have been mounted.
Jack additionally believes the truth that 137 particular person funds have been being made to 3 new payees within the area of an hour, ought to have raised issues with Revolut.
Most banks and monetary establishments monitor clients’ accounts for uncommon exercise.
“If any person is out of the blue processing an unlimited quantity of transactions and a ton of funds to a brand new account, it’s one thing that could be a pink flag – and banks ought to usually begin to examine a few of that behaviour,” says Nina Kerkez, a fraud specialist at information analytics firm LexisNexis Threat Options.
“[They should] name their buyer, ship them a textual content message, interact not directly to make sure these transactions are reliable.”
Revolut options in crime experiences
Final 12 months, the UK’s nationwide reporting centre for fraud and cyber-crime Motion Fraud, acquired nearly 10,000 experiences of fraud wherein Revolut was named, based on a Freedom of Info (FOI) request submitted by Panorama.
That’s 2,000 greater than Barclays, one of many largest banks within the UK, and double that of Monzo, a competitor of comparable measurement to Revolut.
Panorama spoke to eight former staff to attempt to perceive Revolut’s work tradition, and two points got here up repeatedly – Revolut’s insatiable urge for food for development, and a high-pressure surroundings.
“Defending Revolut from getting used for monetary crime all the time performed second fiddle to the need to launch new merchandise and to get present clients to make use of merchandise extra,” an insider, who wished to stay nameless, advised us.
Fraud is an issue for all banks and scams proceed to web a whole bunch of thousands and thousands even whereas the expertise to defeat them improves.
As a way to shield clients, monetary firms do further checks however typically these safety steps can get in the way in which of a easy buyer expertise.
Revolut says it has a “excessive efficiency tradition” with an “expectation to ship good buyer outcomes” and that every one new product launches contain complete danger evaluation and governance approval processes.
It additionally says it has “invested closely” in its monetary crime prevention group, which now makes up greater than a 3rd of its whole world workforce.
Britain’s Latest Financial institution: How Protected Is Your Cash?
Reporter Catrin Nye investigates the tales of Revolut clients who say scammers took tens of hundreds of kilos from their accounts, and that Revolut failed to guard them.
Watch on BBC iPlayer or on BBC One on Monday 14 October at 20:00 (20:30 in Wales and Northern Eire)
No refunds
Revolut says it can not touch upon Jack’s case as it’s being checked out by the Monetary Ombudsman Service.
In 2023 the ombudsman acquired about 3,500 complaints about Revolut, greater than another financial institution or e-money agency.
“[This] reveals that really Revolut aren’t doing sufficient to behave on this space,” says Rob Lilley-Jones, from client group Which?
He says that Which? doesn’t advocate banking giant sums of cash with the agency.
“They’ve a observe file of not reimbursing individuals who fall sufferer to fraud or discover themselves on this extremely troublesome scenario, [and] of cash being taken from accounts even after rip-off exercise has been reported.”
Revolut says that every potential fraud case is fastidiously investigated so it might probably consider the total circumstances and take advantage of knowledgeable determination.
Earlier this month new guidelines got here in to make all banks and digital cash establishments reimburse victims of fraud.
Nearly all of rip-off victims will now be reimbursed their cash robotically as much as the worth of £85,000, with refunds cut up 50-50 between sending and receiving companies.
This might show pricey for Revolut.
“We hear from clients persistently that they are advised to arrange Revolut accounts when they’re turning into the sufferer of a rip-off,” says Will Ayles from Refundee, an organization specialising in fraud restoration.
“It is perhaps secure to attract the conclusion from that, that fraud victims are advised to arrange Revolut accounts as a result of fraudsters discover it simpler to maneuver cash by Revolut than another financial institution.”
When somebody is tricked into transferring cash to a fraudster it is named an authorised push fee (APP) fraud. It is the most typical sort of economic rip-off within the UK.
Final 12 months, figures from the Cost Techniques Regulator present that for each million kilos paid into Revolut accounts, £756 was from APP fraud.
That’s greater than 10 instances the quantity for Barclays and 4 instances greater than Monzo.
Revolut says it takes fraud extremely significantly, and has approaches to sort out it, together with delaying funds, “to permit clients to cease, suppose and full further checks”.
It additionally says it has not too long ago introduced “a brand new biometric identification characteristic” and “a complicated AI-scam detection characteristic that protects clients towards card scams”.
The UK’s latest financial institution?
In July this 12 months, the UK banking regulator granted Revolut a provisional banking licence, and it’s now on its approach to turning into a fully-fledged financial institution.
Because of this if Revolut have been to go bust, clients’ deposits could be assured as much as £85,000 per particular person.
Till then, it’s going to proceed to function as an digital cash establishment or e-money agency.
Nonetheless, turning into a financial institution means it is going to be capable of lengthen credit score to clients through bank cards, overdrafts and mortgages.
“This implies the stakes are larger for his or her clients in the event that they’re focused by a scammer,” says Rob Lilley-Jones.
“I feel there is perhaps a political ingredient to Revolut’s licensing, as a result of it is turning into of a measurement to problem Excessive Road banks,” says Frances Coppola, a monetary journalist and professional on banking dangers and rules.
“I feel no authorities would wish to have one thing of that measurement enjoying quick and unfastened with the foundations.” Nonetheless, she provides: “I suppose you possibly can query, given there are such a lot of complaints, whether or not Revolut ought to have a licence.”
The Treasury says the choice on whether or not to grant Revolut a banking license lies with the impartial regulators. They declined to remark to Panorama.
Revolut says that it abides by the identical regulatory requirements as any Excessive Road financial institution, and it’s sorry to listen to of any occasion the place clients have been focused by criminals.
It says it minimize fraud by 20% final 12 months however acknowledges “there may be all the time extra to do”.
complain in case you are a sufferer of fraud
- Clients can complain about any regulated agency to the Monetary Ombudsman Service, which might settle disputes and order companies to pay compensation
- Necessary Reimbursement Requirement rules have been introduced in on 7 October 2024
- They are going to cowl the overwhelming majority of UK cash transfers as much as £85,000, apart from worldwide transfers or these involving cryptocurrencies
- The brand new measures shield people, microenterprises – with fewer than 10 staff – and charities with an annual revenue of lower than £1m
- BBC Motion Line has extra sources