Cyber Cookie mascotCyber Cookie
Menu ▾
← LatestIssue #89September 14, 2026

Revolut Gave Your Data to Fraudsters

Revolut disclosed that fraudsters used a legitimate government email address to trick the company into handing over sensitive customer data, targeting crypto-linked high-net-worth accounts. A critical flaw in ConnectWise ScreenConnect is being actively exploited in worm-like attacks — patch to version 26.6.5 immediately if you use it. The NSA is also reorganising itself around five new mission centres, with cybersecurity and AI each getting dedicated divisions.

Breach of the Day

Revolut Handed Customer Data to Fraudsters Posing as Government Officials

Revolut, the British fintech app with over 80 million customers worldwide, confirmed it handed sensitive customer data to fraudsters after being fooled by a fake emergency data request sent from a real government email account, according to The Record.

The attackers appear to have compromised a legitimate government domain — likely Italian, based on posts that circulated briefly on Telegram — and used it to submit what looked like an authorised request for user information. Because the email came from a trusted address, Revolut complied.

The exposed data is extensive: birth dates, home and email addresses, phone numbers, passport and driving licence copies, verification selfies, bank statements, IBAN numbers, and full transaction histories including Bitcoin activity.

The targets were not random. The attackers focused on high-net-worth individuals with ties to crypto businesses. Cryptocurrency entrepreneur Marc Zeller and Mark Karpelès, former CEO of the Mt. Gox bitcoin exchange, were among those publicly confirming their data was taken.

The attackers subsequently demanded an extortion payment, threatening to release the stolen data if Revolut refused. Revolut declined to confirm or deny whether any payment was made.

This technique — using compromised law enforcement or government accounts to extract user data under false pretences — is not new. The Lapsus$ group used the same playbook against Apple, Meta and Discord in 2021 and 2022.

What you should do: If you use Revolut, monitor your account for unusual activity and be alert to phishing attempts using your personal details. Consider placing a fraud alert with your bank if you hold significant assets through the platform.

Emerging Threats

Pro-Ukraine Hackers Are Building AI-Assisted Malware to Hit Russian Infrastructure

The pro-Ukraine hacktivist group Hacking Cat has moved well beyond website defacements, according to a report by The Record. Researchers at Kaspersky identified two new malware families linked to the group: Gorilla RAT, a remote-access tool that lets attackers control a victim's machine from a distance by tunnelling network traffic inside corporate systems, and Monkey Ransomware, which encrypts files and appends a ".monkey" extension.

The group exploited vulnerabilities in Microsoft Exchange servers to gain an initial foothold before deploying these tools. Kaspersky noted the unusually rapid development of multiple ransomware variants across different programming languages, suggesting generative AI may have assisted in writing or modifying the code.

Several hacktivist groups appear to be sharing the same custom tools and infection chains — making it harder to pinpoint who is behind any individual attack.

What to watch for: Organisations using Microsoft Exchange should ensure all available patches are applied and monitor for unexpected outbound network connections.

Vulnerability Watch

CVE-2026-84869 — ConnectWise ScreenConnect (versions below 26.6.5)

What ScreenConnect is: ConnectWise ScreenConnect is a remote support and access tool used by IT teams to connect to and manage computers remotely.

What it is: A missing authorisation flaw allows files to be transferred and executed through an active ScreenConnect session without the host's knowledge or approval.

Who's at risk: Anyone running ScreenConnect below version 26.6.5, particularly IT support teams and managed service providers. Active exploitation has been confirmed since August 20, per SecurityWeek.

CVSS: 9.9 — Critical. Patch today.

Root cause: The software fails to properly verify whether a user has permission before allowing file transfers and execution during a remote session. Think of it like a hotel key card that opens any room on the floor rather than just your own — the system trusts the session without checking what that session is actually allowed to do.

Attack vector: Attackers used social engineering (manipulating people into trusting something malicious) to trick victims into running modified ScreenConnect clients. Once installed, the rogue client checked for active sessions and pushed four VBScript payload files to connected machines, establishing persistence and spreading further — worm-like behaviour that jumps from machine to machine without further human interaction.

Detection strategies:

  1. Look for unexpected VBScript file creation or execution in system logs
  2. Audit active ScreenConnect sessions for connections you did not initiate
  3. Check for new scheduled tasks or startup entries added around August 20 onward

Recommended actions:

  1. Upgrade ScreenConnect to version 26.6.5 immediately
  2. As a temporary measure, disable the TransferFiles permission in ScreenConnect settings
  3. Review session logs for signs of unauthorised file transfers since August 20
CVE-2026-84869criticalCVSS 9.9

ConnectWise ScreenConnect (versions below 26.6.5)

ConnectWise ScreenConnect is a remote support and access tool used by IT teams to connect to and manage computers remotely.

Defender's Corner

Check Whether Your Email Address Has Already Been Exposed

The Revolut breach is a reminder that personal data — once out — gets reused. Fraudsters who hold your name, address, and email are far better equipped to craft convincing follow-up scams.

Have I Been Pwned is a free, widely trusted tool run by security researcher Troy Hunt. Enter your email address and it checks it against hundreds of known data breaches to tell you whether your details have already been leaked and from where.

If your email appears in a breach, change the password for that account immediately, enable two-factor authentication (a second verification step beyond your password), and be extra sceptical of any emails that reference your personal details. Familiarity is not proof of legitimacy.

Compliance Pulse

NSA Restructures Around Five Mission Centres, Including Dedicated Cyber and AI Divisions

The National Security Agency is reorganising itself into five mission centres focused on China, cybersecurity, artificial intelligence, combat support, and global intelligence, according to The Record. NSA Director General Joshua Rudd set a 30-day implementation timeline, with full operational capability expected by January.

For everyday users, a dedicated NSA cybersecurity centre signals increased federal attention to domestic threat defence. Whether that translates to faster public advisories and threat warnings remains to be seen.

Fraudsters now have your bank statements, your selfies, and your Bitcoin history — and all it cost them was one compromised email address.

Cyber Cookie is AI-assisted. Always verify critical information with official sources before acting.