Never attribute to malice what can be explained by incompetence. But it surely looks like incompetence at a malicious scale.
Payment biz pulls plug on open source charity after KYC spat
The Free Software Foundation Europe says its electronic-payments provider Nexi Group unexpectedly "cancelled" its account – cutting the charity off from around 450 donors. The latest blog post from the charity, which helps to support free software, claims that over the past few months, Nexi requested "access to private data, …
COMMENTS
-
-
Saturday 21st March 2026 19:10 GMT elsergiovolador
Never attribute to malice what can be explained by incompetence
This is such a stupid quote. It exists to kill the follow-up question. And the follow-up question is always: why are you incompetent? Because usually the answer involves someone who deliberately underfunded, understaffed, or hired mates - and that's not incompetence. That's malice with plausible deniability.
-
-
Saturday 21st March 2026 11:19 GMT An_Old_Dog
Wait, What?
... access to private data, which we understood to be specifically the usernames and passwords of our supporters.
"Understood to be"? There is no "understood" here! Either the processor did ask/demand the username/password info, exclusive-or, they did not. It's a binary condition, and FSFE having received the emails from their payment processor, must absolutely know the facts.
The "we understood" phrasing smacks of weasel-wording and hand-waving/lying, though it may be due to the quotee's knowing English as a secondary language.
Why did the quotee not themselves quote, or forward to The Reg, the relevant email(s) FSFE received from their payment processor?
-
Saturday 21st March 2026 12:19 GMT Alan Mackenzie
Re: Wait, What?
It is quite likely the request from the payment processor was couched in vague language, and attempts to clarify it failed. As though the PP wanted to demand the usernames/passwords, but in a plausibly deniable fashion. "We understood" might be an accurate statement of the FSFE's situation.
-
Saturday 21st March 2026 17:10 GMT doublelayer
Re: Wait, What?
It is possible, but in that case, there'd be attempts to clarify what the data needed to be, subsets which the bank rejected, and plenty to back up that understanding. That is evidence that could have been provided. We're faced with two claims at most one of which can be true. Neither of the statements makes much sense to me so far, and the theory that the company intentionally wrote a vague thing which the FSFE nonetheless correctly and completely understood to mean something specific which the company explicitly denied here requires too many implausible assumptions for me to accept it without that evidence.
-
-
-
Saturday 21st March 2026 14:57 GMT JLV
KYC Know your customers laws make sense, but not in this context.
They’re mostly in the banking and money-in,valuables/ money-out businesses, like casinos. You know, the mom and pop jewelry store that suddenly 3x their weekly intake and the extra is mostly badly used low denomination bills. Watching for money laundering, though they may look for spying and terrorism as well.
It’s unclear what that type of overwatch would be looking for wrt donations to charities. And asking for passwords is not KYC stuff, IF that happens legally that will be law enforcement.
Now FSF itself could be being checked out, but, errr, that’s just kinda bizarre due to it being so well known.
-
-
Saturday 21st March 2026 15:20 GMT JLV
It doesn't have to be all that well known to the general public to fall well with the "known" parameters of KYC laws. A bank isn't expected to have deep expertise of its customers with them, merely report strange happenings and sudden unexplained increases of cash flow that could relate to money laundering to the appropriate authorities.
The only thing that would make sense in a KYC context is if FSFE spent a good deal of its money financing dud consultancies that do little actual work, i.e. money in, money out. But that, again, isn't really something the bank / payment providers, at the entry end, would be looking into, that's more something law enforcement would have flagged, possibly through FSFE's accountants raising KYC concerns from exit side of things. And even then, a non-crypto donation coming in through credit cards and regular financial instruments looks like pretty clean money already, so not typically what KYC is concerned with.
-
-
-
Saturday 21st March 2026 15:28 GMT JLV
Re: percentages and counts, and counters
At least in Canada, where I had to take the test 3 years running due to working in a bank's IT, that is really not how KYC works. It's not a percentage of customers, it's 100% of transactions and situations that meet some very specific concern patterns. If you are in a regulated industry for it and you test 90% of your customers, but are found willfully ignoring a small number of recurring events they stated should be a red flag, you could be in trouble.
-
Sunday 22nd March 2026 13:05 GMT OhForF'
Re: percentages and counts, and counters
Are banks although expected to ask their customer receiving the funds to identify the source if the bank can not?
Is the bank expected to cut off the well known customer when they receive money from a number of sources the bank can't properly identify?
I think the logical thing to do is to block the credit cards/accounts providing the money if those can't be properly identified, not the account the try to send money to.
-
Sunday 22nd March 2026 13:49 GMT Anonymous Coward
Re: percentages and counts, and counters
> Are banks although expected to ask their customer receiving the funds to identify the source if the bank can not?
Expected? Yes.
The powers that be very much want citizens snooping around in each others' lives and reporting even the most mildest of suspicions (or perceived suspicions) to the "proper authorities." That becomes exponentially easier when money is involved somehow.
Even those who don't directly feel the suspicion still experience the environment and worry about permission.
-
Sunday 22nd March 2026 16:42 GMT JLV
Re: percentages and counts, and counters
Typical things KYC Canada:
- government IDs/biz registrations to be presented
- EFTs > $10cad have special reporting reqs
- multiple EFTs < $10k looking to fall under above limits: suspicious
- large unusual cash deposits: suspicious
- asking too much about KYC limits…
Everyone - not “auditors” - customer facing is supposed to be watchful. Then there are compliance people who will look more closely and reporting mechanisms to liaise with authorities. Not cutting off customers, no. That would be counterproductive to catching actual criminals.
I understand cynicism, to an extent, but we have so much damage here from hard drugs (no, weed doesn’t count) that a bit of inconvenience can be put up with. And, honestly, the patterns looked for are NOT typical money flows: that is the point. If you have a pizza stand you’re still expected to bring in tons of low denomination cash. Not regularly so if you sell new cars.
The emphasis is on cash or foreign EFTs getting in, not tracking regular cheques or deposits emanating from actors already in the banking system. Scale matters: if you had $1M in $20 bills, how can you put them into sellable goods or “clean” bank accounts?
As a normal individual, you can reasonably be expected to hit nominal flags from time to time, without tripping alarms. The teller will ask you some questions, at most. As a professional “mule”, you’re only worthwhile if you do this a lot more frequently.
In any case internationally Chinese triads are undercutting laundering these days, charging 2-3%, instead of the usual 8-10%.
-
Sunday 22nd March 2026 17:13 GMT Anonymous Coward
Re: percentages and counts, and counters
> I understand cynicism, to an extent, but we have so much damage here from hard drugs (no, weed doesn’t count) that a bit of inconvenience can be put up with.
Equating invasive KYC with minor inconveniences normalizes a culture of pervasive, baseless suspicion, in which people who have done nothing wrong do have to worry about proving their innocence after tripping secret "flags" and inviting some degree of interrogation or account restriction. That's not minorly inconvenient, like waiting in a long bank line on a busy day.
It's also corrosive to privacy when finances -- one of a person's most private spheres -- are treated as an open book for others to rifle through, interrogate, and demand justifications.
> The teller will ask you some questions, at most.
At most they don't like the answers, and freeze/take your money. Or nosy people get their jollies invading someone else's privacy.
When it comes to finances, there really are a lot of things which are legitimately none of anyone's business. KYC snitch culture upends that.
-
-
-
-
-
-
-
Saturday 21st March 2026 21:55 GMT JacobZ
...or worse
Im fact, if they wanted to do that check, the LAST thing they should do is to ask FSFE for test credentials.
If FSFE were up to any funny business, they could rig their portal so that the test credentials would be recognized and take the user through acceptable cancellation flows, while continuing to do whatever shenanigans Nexi is worried about for everybody else.
Far better to, as you suggest, to anonymously set up an account like a real contributor without announcing their intentions to FSFE.
Everything about this smells.
-
Sunday 22nd March 2026 16:47 GMT FeRDNYC
Even PayPal verifies bank-account access by posting, and then reversing, two small (sub-$1) deposit transactions via the provided routing and account numbers; you then submit the randomized dollar (or, really, cents) amounts of the two transactions to verify that you've provided the correct bank account details. Because, you're right: as with email-address verification, also, any type of transactional validation is best performed by making use of the actual system under examination.
I suppose Nexi could claim that's what they were trying to do, but they wanted FSFE to go through the work of creating the accounts for them because they're too busy to bother with that half of the process when they only want to test the other half. They can say that, and I can say it sounds like they're full of shit.
-
Sunday 22nd March 2026 08:43 GMT xyz123
Nexi has been doing this a LOT lately.
Literally asking for usernames, passwords, dates of birth, home addresses, full financial records and emails received by donors from a LOT of charities and organizations etc etc
Check https://en.wikipedia.org/wiki/Nexi for info on this company as it now has some VERY suspect Iranian, Russian and Chinese ownership........
The company has collapsed from over $20 billion valuation to just over $5 billion. This looks like a last-ditch attempt to grab some data to sell to foreign governments.
Probably doesn't help it was created by/for the Fascist Mussolini government in 1939......
-
Sunday 22nd March 2026 10:44 GMT MachDiamond
Why not other ways to donate
There's loads of payment services that support automatic monthly payments. YouTubers often use Patreon. Churches use plenty of others as a way to "prevent people from forgetting" to bring some money to put in the collection box/plate. If one payment service is getting a bit weedy, use another or several others. I know that one problem can be getting people to switch over since they might just decide to continue support, but that loss is better than losing the whole stream all at once. If there are several ways to donate, it spreads the risk of this sort of thing happening again in a large way. For the YouTube channels I like, I try to support them directly rather than through a service. More of my donation gets to them rather than being nibbled or nommed by a payment service. I don't do auto-pay.
-
Sunday 22nd March 2026 17:18 GMT FeRDNYC
Re: Why not other ways to donate
Well, FSFE have already contracted with a new payments processing service and migrated their donations form to use that service instead, so there is indeed now another way to donate. As for why not offer multiple ways to donate, well...
- Patreon, specifically, is not generally considered a good fit for charities or non-creative endeavors. There are a (very limited) few software developers who use it as a donations platform, but for the most part the typical Patreon page is a showcase for the work of a creative artist and that's where the expectations of its community of donors tend to fall. Plus, like Kickstarter (which is a very different platform in many ways, and slightly more popular for engineering/software projects) the expectation with Patreon is that you'll regularly provide your donors with updates on the work they're supporting — it's basically a blogging platform with a paywall component. The amount of effort required to maintain that line of communication with the donors is a potentially significant drain on a charity's already limited resources.
- Offering multiple options can actually discourage donors, who (having chosen to part with some of their hard-earned cash to support an organization) don't want to then be asked to put in the extra effort of deciding how to donate.
- Splitting the funding streams among multiple services also makes it harder for the organization receiving the funds, which then has to contend with managing relationships with multiple providers, each of which may have different percentages, timeframes, policies, and requirements.
-
Sunday 22nd March 2026 18:00 GMT Anonymous Coward
Re: Why not other ways to donate
> As for why not offer multiple ways to donate, well...
FSFE also must consider:
*Donor with too many accounts skips $PLATFORM they're not on to avoid registering another.
*Annoying registration process.
*Left $PLATFORM for bad service or spam.
*Donor has an issue with $PLATFORM's privacy practices.
*$PLATFORM is in the wrong country.
*$PLATFORM's politics.
*$PLATFORM has obnoxious or intrusive verification/anti-fraud policies.
*$PLATFORM asks to confirm identity.
*$PLATFORM's past controversies.
*Who $PLATFORM does or doesn't do business with.
*Etc.
Donors can be a picky bunch in general. Free software donors probably even more so.
-
Sunday 22nd March 2026 20:22 GMT MachDiamond
Re: Why not other ways to donate
"Patreon, specifically, is not generally considered a good fit for charities or non-creative endeavors. "
I don't use them so you could be right. I know they do have automatic ongoing donations so it could be made to work in a pinch.
I wouldn't suggest a dozen avenues for donations, but 3-4 might cover some bases including a way to mail in a donation for those that don't wish to use an online service. I know I skip loads of things through sign-up/app fatigue and I am not going to give my financial/payment information out willy nilly.
The issue is solving a downside of having a single donation mechanism that is operated by an an outside entity. If that means some a bit of management, that's a cost of having some redundancy. To have donations suddenly stop is more worrisome than spending a wee bit of time setting up another account. There isn't "managing relationships with providers" as an ongoing and time consuming process. You sign up if you agree with their terms and monitor any changes to their policies and that's it.
-