08 September 2026

Security Alert: Bendigo Bank useless against cybercriminals/scammers!


Quite simply put the message is very clear: 

- IF you want to keep your money that’s their bank, take it OUT of Bendigo Bank!

This article is not going to have pages of attached PDFs explaining situations or how cybercriminals or scammers work.

While other banks work around the clock to protect ‘their’ cash that you gave them to be part of billion dollar profits for them, Bendigo Bank doesn’t have any (automated) systems that detect fraudulent activity, until their business day starts, that being at 9am.

So, how can you trust them with your hard earned cash, e.g. superannuation, pension etc.

The answer is - You can’t!

To make matters worse it was not even the Bendigo Bank that detected fraud, but rather the ANZ, which occurred at 3am, so they did NOTHING until it was too late!

Maybe they even outsourced their I.T. infrastructure to the scammer capital of the world, that being India?

From what is understood there are many victims of fraud from the Bendigo Bank, where realistically a class action lawsuit should occur against the bank, where Australia’s corrupt judicial system should not only make orders for compensation, but also the legal fees being fully remunerated .

Let’s see how this gross negligence by the Bendigo Bank fans out.

Bendigo Bank FAILED their customers, and the only way they can’t fail you is if you withdraw all YOUR cash from their premises.

06 September 2026

Biggest data breach ever? (IDScan.net) Governments Outsourcing Liability

"Never trust the government, it is NEVER for the children!!"

"This is all on purpose to take away our privacy and give big brother control over everything."


FBI Probes Service Selling 153M+ Drivers Licenses


A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images.


A record available at this identity theft service that includes the drivers license for U.S. Defense Secretary Pete Hegseth, one of several high-ranking U.S. government officials whose drivers licenses can be found for sale.

On Monday, Aug. 31, a source alerted KrebsOnSecurity to a service advertised by a new user on the Russian cybercrime forum Exploit, offering access to digital scans of identity documents on more than 170 million people in North America. The source brought it to my attention because the proprietor of this identity theft service offered my Virginia drivers license as a free sample in their initial sales thread on Exploit.

The service, dubbed Nexus, claims to have more than 153 million drivers licenses for people in the United States and Canada, as well as more than 10 million identification cards; more than three million travel documents and/or international IDs; and at least 579,000 medical cards.

A quick look around Nexus finds they are likely not exaggerating about that 153 million number: Running a blank search in Nexus (with no search parameters entered) returns approximately 11.5 million pages of results, with roughly 15 results displayed per page. It includes documents from people in both Canada and the United States, but the bulk of these records are on Americans: searching for just Canadian drivers licenses returns approximately 1.1 million results, with the largest concentration from Ontario (473,673 records).

Curiously, the identity records include not only drivers licenses but also marijuana dispensary cards. Some of the records list their “source” as “CDL,” presumably short for “commercial drivers license.” Other records carry the source notation of “CAC,” which may refer to Common Access Cards, government issued identity cards that grant physical access to government buildings and secure rooms.

The people behind Nexus claim the license images are coming from an active breach at “a major identity verification company” whose customers include multiple Fortune 500 companies.


The record totals listed by the Nexus identity theft service. The number of drivers
license records increased by nearly 400,000 in the span of just 24 hours.

“We have been continuously exfiltrating new data for over a year into our private database,” the service enthused in its introductory post on Exploit. “Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.”

Indeed, over the past 24 hours, the number of drivers license records listed as available in Nexus has increased by nearly 400,000, suggesting that freshly stolen license data is being harvested and uploaded to this service on a semi-regular basis.

The record featuring my drivers license includes six image files: three pairs of photos of the license’s front and back, a basic image scan, as well as infrared and ultraviolet versions of the same images. A date and timestamp is appended to each image file, and the timestamp on my license scan corresponds to a date in June 2025 when I took a flight to the midwest United States to attend a family funeral.

Some of the 153 million+ license scans — including mine — feature six image files with date and timestamps appended to the filenames. Not all records include photos, and some that do feature photos do not display the associated filenames.

Intent on discovering the source of this data, KrebsOnSecurity asked more than a dozen friends and family members for permission to search for their licenses in this service. Each person whose license could be found (nine of them) confirmed having traveled on or very close to the dates in the timestamps attached to their images. It is unclear what timezone these timestamps are in, but from reviewing car rental records shared by several people who helped with this research, it appears the timezone is set to Greenwich Mean Time (GMT).

At first, I thought the source of the data might have something to do with airports. However, that theory went out the window when it became apparent there were no passports in this data set. Also, only some of those who helped with this research said they showed their drivers license at the airport on the day of their travel. One person whose license was in Nexus hadn’t flown at all recently, but was renting a car from Hertz for several months around the date of their timestamp.

Two of those who agreed to help are federal employees who said they shared other forms of government identification when passing through airport security. However, those individuals each said they shared their state-issued drivers licenses later that day when renting vehicles at their respective destinations, and that both rented their cars from Hertz.

After finding a note in my calendar for the day of my June 2025 flight reminding me to bring my passport, I remembered that I also never actually shared my drivers license when I went through security at Reagan National Airport on that day because I did not yet have a Real ID, a security-enhanced drivers license that is now required by the Transportation Security Administration (TSA) for all domestic travel. Instead, I showed the TSA agent my government-issued U.S. passport.

Here’s where it gets interesting: I was able to find my mother’s drivers license in this service as well, and the timestamps for her images are just a few seconds apart from mine. That’s notable because we both handed our licenses to the Hertz rental car representative at the same time.

According to my mom, the only place she gave her drivers license to that day was the rental car company, and if memory serves that is also true for me. I don’t recall if the rental car representative inserted our licenses into any kind of machine, but I remember they held onto them for several minutes behind the counter while we were signing various forms. KrebsOnSecurity sought comment from Hertz and will update this story in the event they reply.

Zach Edwards is a well-known security and privacy researcher who recently launched a service called DecryptAds to help people better understand how online advertisers are tracking them. A scan of Edwards’s drivers license is available for purchase on this identity theft service, and Edwards said the timestamp on his record corresponds to the middle of a trip last month to Las Vegas for the annual DEFCON security conference.

Edwards told KrebsOnSecurity that although he did not rent a car in Vegas, he did hand over his license at the TSA checkpoint, at a marijuana dispensary in Vegas, and at his hotel (the Aria). But he said the only one of those three that for sure scanned his ID in some kind of device was the dispensary.


To enter Planet13’s weed dispensary in Las Vegas, one must pass through a red telephone booth. Image: Zach Edwards.

Edwards said the dispensary he visited that day was Planet13, a multi-state chain with stores in California, Florida, Illinois and Nevada. In 2022, the New Orleans-based identity provider idscan.net published a press release announcing an exclusive identity verification agreement with Planet13’s dispensaries nationally. IDScan says it processes ID verification for more than 1,000 marijuana dispensaries in 19 U.S. states.

The “trust” page of idscan.net states that the company provides identity verification services for numerous big brands, including Hertz, Target, Fedex, Motorola Solutions, the financial services giant Jack Henry, and Caesars Entertainment. And as idscan.net’s own documentation states, the technology scans IDs with both infrared and ultraviolet light. Idscan.net says the company’s systems and technology perform more than 21 million verifications monthly, at more than 20,000 locations around the world.


Image: idscan.net.

Contacted by KrebsOnSecurity, idscan.net said it was investigating the matter, but the company has not yet shared an official statement or a substantive reply to specific questions sent via email.

“At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation,” wrote Jillian Kossman, a marketing and operations leader at idscan.net.

During the course of my research for this story, word got around to the FBI that I was poking at the apparent source of this new identity theft service’s data. Probably they were tipped off when I shared with a trusted source that Nexus also is selling the drivers license information for the assistant director of the FBI (I did not find FBI Director Kash Patel’s license in Nexus).

Earlier this afternoon, I was added to a conference call with a half-dozen FBI agents, including senior leaders from the agency’s cyber division. During that call, the FBI shared that earlier today their New Orleans field office opened an official investigation into an apparent breach involving idscan.net.

Edwards said that as more in-person and online experiences require sharing drivers licenses, vendors who collect this sensitive data need to be held to a higher standard.

“This episode should further strengthen the resolve for people who are fighting back against online ID schemes which are requiring countless providers to ask for drivers licenses in order to access services under the guise of protecting kids,” Edwards told KrebsOnSecurity. “These systems are putting sensitive data into more and more 3rd party vendors, and we don’t have nearly the oversight to ensure they are safe.”

Larry Baldwin is principal intelligence researcher at the cybersecurity firm Cybera. Baldwin said a front and back scan of his drivers license available at Nexus contains timestamps that correspond to the date of a car rental from Hertz on a recent vacation.

Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s identity when opening new lines of credit. Baldwin said the service could also dangerously expose many people who do not wish to be found but who cannot meaningfully change their appearance (or at least not enough to fool today’s AI-based image matching tools).

This category of people, he said, includes those fleeing domestic violence, and even people who have been assigned a whole new life and identity as part of the federal government’s witness protection program, which is generally reserved for criminal defendants in racketeering and conspiracy investigations who agree to cooperate with federal authorities.

“Just when it seems like we’re making some headway in improving authentication controls through drivers license verification systems, this happens and the very thing those improvements are dependent on are compromised,” Baldwin said.

Update, Sept. 2, 6:05 p.m. ET: A spokesperson for Caesars Entertainment said Caesars has not been a client of IDScan.net and has not used VeriScan since February 2025, despite IDScan.net listing them as a client on their website. That person said Caesars had no active VeriScan accounts at the time of the incident and did not authorize IDScan.net to retain data from its accounts, and that IDScan.net said the incident should have no impact on Caesars Entertainment.

Update, 8:56 p.m. ET: Shortly after this story was published, the Nexus identity theft service website vanished from the darkweb, replacing its login page with a plain text message that reads, “This service is no longer available.”

This is a potentially fast-moving story. Any changes or updates will be noted here along with a timestamp.

Source:KrebsonSecurity.

See also short explanation by Matt Johansen on this topic:


https://www.youtube.com/watch?v=FRbDaQQwWlY


SO, WHEN WILL THE AUSTRALIAN GOVERNMENT COMPENSATE YOU WHEN (NOT 'IF') YOUR PRIVATE AND CONFIDENTIAL INFORMATION GET BREACHED?

AFTER IT'S 'THEIR' LAWS.

SORRY? THEY'RE NOT GOING TO OFFER YOU A REMEDY, AT LAW?



01 September 2026

National Face Database - Why New South Wales is Scanning Every Driver's Face

See (11m28s) video by Tech Win Cyber of the title:

Why New South Wales Is Scanning Every Driver's Face


The next stage of the Orwellian dystopia is upon us.

Enjoy your freedom to breathe air, for now.

That's life in the FiveEyes (penal) colony.

30 August 2026

Google Serving You Brain Rot AI Slop!



Google is literally littering the internet with garbage, AI generated garbage.


If Google wasn’t a tech company where it would be a ‘fast’ food or rather junk food corporation it’d be McDonald’s.


The ‘best' part about these corporations is that there is no regulation about how much shit they can feed you.


Google making you consume AI trash in your ‘feeds’ (how appropriate) on its media platform YouTube, is about as good for your brain as McChuck’s is good for your body, where you can refer to the ‘experiment’ by Morgan Spurlock, in Super Size Me



(https://www.youtube.com/watch?v=wSZWxjeua3g)

A mental torture tactic used on ‘persons of interest’ by military forces was to bombard the interrogated person with random, questions/facts until their brain goes to mush, a bit like you doom scrolling on social media.



Apparently the world's governments are there to ‘protect the children’, but there is no limitation/legislation on brain rot products by Google (and others).


In many feeds as much as two thirds to seventy percent of content is either AI slop or plain and simple false information contained in the ‘shorts’.


In any event Google and other corporations have invested billions of dollars in AI hardware which at the end of the day, has hurt ‘consumers’ (of hardware) where memory prices have risen six fold to purchase despite costing the same to produce as before the ‘AI crisis’.

Therefore Google (and others) have to serve you AI slop in order to obtain a decent ROI (Return On Investment) in their business endeavours.

The internet has really turned to crap as a result of a few corporations and it's very clear that governments are supporting this. 

Viva la ‘Free’ World.

28 August 2026

Retailer’s con job for tying your phone number to warranty.


Today we live in world that revolves around big data, as it’s more valuable than gold.

One of the problems that many people are ignorant of is; how is that data handled, where does it go, and how is it secured?

Because eventually [meaning when and not if] your data will be compromised, where your personal details will make it on the deep web.

Retailers like Harvey Norman and JB Hi-Fi, con you into giving them your phone number for ‘warranty purposes’.

That implies that if you do not hand over your phone number you will not receive a warranty on the product.

Name, phone number and email address are important parameters in order to dox your person.

They will tell you that they ‘require’ those details, but you do not have to provide them with those details, where in fact there is no such subsection in Australia’s Consumer law directing you to do so.

It is through the general population’s ignorance and compliance to corporate lies, that is paving way to a dystopian society.

Pretty close to every single cashier at every transaction at HN or JB will ask for your phone number.

For more information, see Business Reform's Stop Giving Everyone Your Real Phone Number :



or Naomi Brockwell's : They Asked for My Cell Number. I Don’t Have One.




26 August 2026

Australia’s governments LOVE criminals (and most importantly - repeat offenders)






The colonialists are (still) in charge of this dumpster fire called Australia.

Some people may be of the opinion that the authorities want to stamp out crime, but that’s not actually correct, as actions speak louder than words.

The federal government’s immigration policy is that it imports criminals into the colony, where they continue to commit criminal activity on this land, where it’s all about the ‘economy’.

Keeping in mind that what's good for the economy, may not be good for the people.

The more criminals, the better for the judicature, i.e. the administration of so called ‘justice’, but that may be not so good for the victims of those criminal activities.

IF or when you go to court, you are a ‘customer’, period.

And that is true even if you do not hire a lawyer.

Let’s just say that if you’ve got a shoe shop, where you’re open 7 days a week, and you have 5 customers per day you may not be making enough profit to stay open from 35 customers per week.

If conditions changed, where you’re guaranteed 70,000 customers for a whole year, then you’d be ‘raking’ it in.

The same goes for the courts and their ‘officers of the court’, that being the lawyer that you hired to represent you.

It is unclear of what the intention of the article was whether is was supposed to make the reader feel sorry for the system or whether it was a brag.

In any event it is not good for the community to have that many (alleged) criminalsin one state, unless they’re all speeding 3km/h over some arbitrary speed limit which changes depending on what some ignorant bureaucrat sees fit the speed limit to be.

The low quality people in Australia’s governments do what serves them the best and not the community at large.

IF the colony’s governments where truly serious about having a low crime rate, then there are a fair few nations on this planet that have perfectly functioning society with very low crime rates, which the colonialists could have modelled this nations laws on, where this action would have been done generations ago.

The judiciary wants/needs repeat ‘customers’ where their court orders reflect this.

Australia has become a low quality low value society, as a result of federal and state government's actions.

Australia, the shithouse colony, "run mainly by second rate people who share its luck. It lives on other people's ideas, and, although its ordinary people are adaptable, most of its leaders (in all fields) so lack curiosity about the events that surround them that they are often taken by surprise."

20 August 2026

Migration Tracker - A City Larger Than Hobart EVERY YEAR

In the United States of America a study was done into a city the (population) side of what Melbourne was a couple of decades ago where it was found that an importation of people more than 700 per week was unsustainable, from an infrastructure/resources point of view.

In Australia, at that time the authorities were allowing immigration from abroad to the tune of approx. 2,500 corporate fodder into Melbourne, alone.


 See: https://www.reviveaus.com/tracker

The authorities have caused austerity on the good people of Australia, by over populating the colony with low quality humans that are of little benefit to Australian society in general, where as a result crime has exponentially risen due to the low quality imports.

 Source:supplied

17 August 2026

Dave Hughes UNLOADS on former Premier Dan Andrews

It's been established a long time ago what Australia is, and it's only gotten worse since it was first inked.

In the 1960's, author Donald Horne put pen to paper in his book "The Lucky Country" published in 1964, referring to Australia as the "lucky country".

There are a few problems with this.

First and foremost, the book  "The Lucky Country" was never meant to be a complement about Australia, but rather a dig at the low lives running the place.

His sentence describing Australia, was deliberately misquoted and popularised into pop culture, as an alleged complement about this sun burnt land. 

The full quote is as follows:

“Australia is a lucky country run mainly by second rate people who share its luck. It lives on other people’s ideas, and, although its ordinary people are adaptable, most of its leaders (in all fields) so lack curiosity about the events that surround them that they are often taken by surprise.”

It's also quite clear that Mr. Horne did not have a quick peruse at the Constitution, which brings up the next point.

Another 'small' technicality, yet quite a significant legal one is that on the second page of the 'original' Commonwealth of Australia Constitution Act 1900 (UK), it is stated that:

"... the Commonwealth shall be taken to be a self-governing colony for the purpose of that Act"

This was the case in 1964 and still is so today, meaning the Imperial Act has not been repealed.

Now that the technicalities are out of the way... or maybe not there is still one more important aspect the general population may not be aware, that being that 'faceless men' run this nation.

The so called 'elected' leaders, meaning "We the people" did not elect, e.g. Mr. Daniel Michael Andrews as a premier of Victoria, nor the current puppet Mr. Benjamin Alan Carroll, but rather the 'faceless men' put the clowns in a 'Punch & Judy' clown show on display.

So here's what Dave Hughes had to say about the hit and run driver which Victoria Police support:


SO, Google censors our posts on YouTube and Google Reviews on corporations.

Let us know in the comments if you cannot see this response:



13 August 2026

Census fine about as ‘lawful’ as a Covid fine?


Australia’s authorities are corrupt to the core.

During a normal business day they practice deception, coercion, intimidation, fear of incarceration, but most importantly pressure you, the serfs into submission, or rather ‘consent’.

Australia’s governments, federal state/territorial are also human rights abusers, where they truly do not care unless it becomes public knowledge headed for the courts, but that topic is for another day.

So, during ‘Covid’, across Australia the authorities had no lawfully (as opposed to ‘legally') enacted ‘instrument’ to issue a covid related fine, but they still did anyway, preying on the ignorance of the general population.

Heavily monitoring social media during this time, once the authorities figured out that people were aware how to successfully challenge the lawfulness (under Section 78B, of the Judiciary Act 1903), they started to drop or withdraw the person’s fine.

SO, now as similarly with the Covid situation, the mainstream media is reporting that failure to comply with the Census will result in a 'huge'* fine.

First and foremost, as with ANY 'fine' or rather allegation of wrongdoing/criminal activity, the burden of proof is on the accuser, period.




You, the plebs/serfs/general population are told that if you lie or skip the census, you ‘could’ face a fine of up to $3640 AND $364 per day it goes incomplete.

(Show us the 'lawfully' enacted instrument for the fine, as opposed to a legal statute).

Therefore such a ‘*cruel and unusual punishment’ MUST be challenged in the appropriate court under a ‘question of law’, that being a Section 78B, where the burden of proof is on this business called the Australian Bureau of Statistics.

An important aspect is also to consider, is that did your ‘person’ get lawfully notified?

Merely stating the the ABS is enacted under the Australian Bureau of Statistics Act 1975 is zero proof of its lawfulness.

Subpoena the head of power for that Act, or even write an FOI to the government for this, and put your response on social media.

If it is stated that your ‘person’ is lying, how is this information obtained?

It must be proven that you 'lied', where just merely one ‘cannot remember’ like (Victorian premier Daniel) Andrews stated on the public record, is sufficient as in the Andrews example.

There are a few other intricacies that need to be dealt with, where is it advisable to obtain the ‘correct’ legal information prior to the matter being brought before the courts.

From the information that has been obtained, the federal government is not acting ‘lawfully’ for not only carrying out the census, but also implementing fines on those who do not participate.

What is certain also, that this is another con job by the government.

Keep in mid that they SOLD 'your' data in a previous census.

Can a department 'lawfully' sell your data for profit, and if so, where is this stated in a 'lawfully' enacted instrument?


In their 'spam' letter, to you, the ABS or rather Jenny Telford states that "The Census is compulsory*", where the asterisk points to a privacy website link, which the nothing to do with proving that it is "compulsory".

A typical gaslighting tactic by the governments of Australia.


10 August 2026

Warning! Revolut wins Australian banking licence. Don't use it as it's not safe nor secure!

Just because a corporation is allowed to trade in Australia does not mean that it's good for the people.

It may be good for 'business' but not necessarily for the 'consumer' or corporate fodder.

Revolut is apparently Europe's largest private financial technology company started by Nik Storonsky and Vladimir Yatsenko.

Nik Storonsky is the chief executive of Revolut

From industry sources, it runs on Android 9 with no security patches since 2018, where this no way any sane person should do banking with their app.

Prior to conducting any banking on a mobile platform the system must be up to date with security patches in order to mitigate any threats or exploits.

For a few years, GrapheneOS has been the most secure Android mobile phone operating system, period.

So much so that the Israeli based Cellebrite phone hacking tool cannot penetrate an up to date GrapheneOS based phone in the BFU (Before First Unlock) state.

Revolut previously did run on GrapheneOS but has recently stopped its app from being run, citing security reasons, yet they allow it to run on a mobile phone operating system, where security updates stopped in 2018, or 8 years ago.

It's quite clear that this corporation does not have the best security practices in play, where they should not be trusted with you data or cash, irrespective of their previous financial performance.

Revolut is based in Lithuania, so when/if things go awry, then good luck getting your money out from within their app.

Buyer beware!

Edit:

See complaint from a user:

Good morning,

I am writing to raise a formal complaint regarding Revolut's apparent ongoing rollout of changes to its Android application which prevent, or will prevent, the app from operating on devices running GrapheneOS.

My understanding is that this change is currently being rolled out to only a proportion of users. It has not affected my account yet, but reports from other users indicate that Revolut is testing or progressively deploying this restriction. I am therefore raising this complaint now, before I am potentially locked out of access to my bank account.

I object to this decision in the strongest possible terms for several reasons.

  1. GrapheneOS is not an insecure or compromised operating system

The restriction does not appear simply to be identifying genuinely insecure devices. GrapheneOS has specifically reported Revolut detecting and rejecting GrapheneOS devices.

This distinction matters.

GrapheneOS is a security- and privacy-focused Android operating system designed specifically for supported Google Pixel devices. It retains verified boot and supports a locked bootloader, while adding substantial security hardening beyond standard Android.

Blocking such a device merely because it does not run Google's stock operating system is not a meaningful assessment of whether that device is secure.

To use a simple analogy, it is rather like an insurance company refusing to insure a house because the customer's front-door lock is too secure.

If Revolut genuinely requires device integrity verification, GrapheneOS provides mechanisms by which applications can perform hardware-backed attestation and verify legitimate GrapheneOS installations. A blanket refusal to support the operating system is therefore neither the only nor, in my view, the most sensible security option available.

2. The policy produces an absurd security contradiction

Revolut currently supports Android versions going back many years.

This means that the Revolut application may operate on an old Android phone which is no longer receiving current operating-system security patches, while refusing to operate on a modern Google Pixel running an actively maintained, security-hardened version of Android.

It is very difficult to reconcile those two positions with an assertion that this restriction is necessary for customer security.

A modern Pixel running an up-to-date GrapheneOS installation with verified boot and a locked bootloader is clearly not inherently less secure simply because the operating system is not Google's stock Pixel firmware.

Security decisions should be based upon the actual security properties and integrity of a device, rather than an arbitrary list of approved operating-system vendors.

3. Revolut has apparently provided no viable alternative means of accessing my money

I have already contacted Revolut customer support regarding this issue.

I was advised that, should my device become unsupported, I could either use Revolut's web application or use another mobile phone.

Neither suggestion provides a reasonable solution.

Firstly, the web application itself requires authentication using the Revolut mobile application. If Revolut deliberately prevents that application from running on my device, telling me to use a website which requires approval from the application I can no longer use is circular and plainly does not solve the problem.

Secondly, I was effectively advised that I could obtain or borrow another person's phone, install Revolut on it, and log into my bank account there.

I find it extraordinary that this can seriously be proposed as the more secure alternative.

Revolut would apparently prefer me to enter my banking credentials and establish access to my account on a friend's device — a device over which I have no long-term control and whose security I cannot independently establish — rather than allow me to use my own modern Pixel with a locked bootloader and a security-focused operating system.

That appears directly contrary to the stated security objective of this change.

4. This risks depriving an existing customer of practical access to their bank account

This is not merely a question of whether Revolut chooses to support an optional feature on a particular platform.

I am an existing customer. I receive my salary into Revolut, use it as a significant part of my everyday banking arrangements, and pay for a Metal subscription.

Revolut has encouraged customers to treat its service as their bank. It is therefore entirely reasonable for customers to expect that Revolut will not deliberately remove their primary means of accessing their accounts without providing a genuinely functional alternative.

If Revolut introduces a technical restriction which it knows will prevent an existing customer from using the application, while its alternative web interface itself depends upon that application for authentication, that raises a much more serious question of effective access to the customer's financial services.

I should not be forced to purchase and carry a second mobile telephone solely because Revolut has chosen to reject a secure operating system which my existing hardware is perfectly capable of running.

Resolution requested

I would therefore like Revolut to:

confirm whether it intends to block, directly or indirectly, correctly installed GrapheneOS devices from accessing the Revolut application;

reconsider this policy and implement an appropriate method of supporting GrapheneOS, including hardware-backed device attestation where Revolut considers integrity verification necessary;

confirm that existing customers will not be deprived of access to their accounts solely because they use GrapheneOS on an otherwise supported device with a locked bootloader; and

if Revolut nevertheless intends to impose this restriction, provide a fully functional method of accessing and administering a Revolut account which does not itself require authorisation from the mobile application that Revolut has chosen to block.

I would also appreciate an explanation of the security rationale for permitting the application to operate on older Android devices which may no longer receive security updates while rejecting a current, supported Pixel running a hardened Android operating system.

Please treat this correspondence as a formal complaint, rather than general product feedback, and provide me with Revolut's formal written response.

If Revolut proceeds with this restriction without providing a reasonable means for affected customers to continue accessing their accounts, or if I do not receive a satisfactory response to this complaint, I intend to refer the matter to the Bank of Lithuania, as the competent out-of-court dispute resolution authority identified in Revolut Bank UAB's terms for Maltese customers. I will also consider seeking assistance through the Maltese Office of the Arbiter for Financial Services and the FIN-NET cross-border consumer complaints framework where appropriate.

I sincerely hope escalation will not be necessary. I have been a loyal Revolut customer for years and have been sufficiently satisfied with the service to entrust Revolut with my salary payments and pay for a Metal subscription. That makes it particularly disappointing to face the prospect of being arbitrarily excluded from my own banking application despite using a modern and demonstrably security-focused device.

I would much prefer Revolut to address the underlying technical issue properly rather than force otherwise satisfied customers to choose between replacing their operating system, purchasing an unnecessary second phone, or moving their banking elsewhere.

I look forward to your formal response.

Kind regards,

See response from Revolut:


     Source:supplied