Revolut Leak Shows the Cost of Constant ID Collection

Online bank Revolut has revealed that it gave out sensitive personal and financial information of an undisclosed number of its customers in response to a fake government request.

The information that was handed over to an “unauthorized third party” reportedly includes names, dates of birth, occupations, addresses, phone numbers, account numbers, transaction histories (including Bitcoin), and even copies of government-issued IDs and onboarding verification selfies.

Revolut claims that derived biometric face data was not.

The company said that the data was handed over in response to an email that came from a real government agency’s domain, but was not actually sent or authorized by that agency.

The email passed several authentication checks (SPF, DKIM, and DMARC) that are designed to establish the authenticity of a message’s origin and integrity, but do not verify the legitimacy of the legal request itself.

Revolut said that it complied with the request “under the reasonable belief that it was an authentic government agency request” – and only later found out that it was not.

Revolut said it later realized its mistake, blocked the email address, and reported the incident to the relevant authorities.

Revolut said that only a “limited” number of its customers were affected by the data leak, and that the company’s systems were not hacked, nor was any money stolen.

The story broke on September 11 when Revolut customers started receiving an email notice about a data leak, and the news was picked up by media outlets the following day.

Keep reading

A Single Firm is Behind OpenAI, Anthropic, and Meta Hacking Scandals

OpenAI, Anthropic, and Meta models hacked into several real world systems over the past three months. These models gained unauthorized access to web systemspublished malicious packages, and exploited unnamed vulnerabilities.

A single firm, Irregular, is responsible for hacking done by all three companies. Anthropic disclosed that Irregular was responsible for creating the tests that led to Claude hacking into real world targets and for providing the models with internet access. Irregular claims that it was unaware at the time that it provided internet access to those AI models.

In a more normal media ecosystem, the reactions to these cybersecurity issues would be obvious. American AI companies would reconsider doing business with Irregular, not only because of its failure to secure its systems, but because it is an Israeli firm potentially outside US oversight. Lawmakers would consider taking action against Irregular or against its American business partners, which include OpenAI, Anthropic, and Meta. They may consider strengthening liability against firms which instruct AI models to commit cyberattacks, and whose models then commit those cyberattacks.

Instead, Irregular, Anthropic, and their allies have begun a media campaign promoting a literally apocalyptic ideology with sensationalist language. Anthropic’s incident assessment blames their own AI’s “recklessness”; Irregular describes “the agent itself becoming a threat actor”; Anthropic CEO Dario Amodei warned, about a similar OpenAI–Hugging Face hack, that a future swarm “could be capable of taking over the entire internet”; and an Associated Press headline claimed bots are “going rogue”.

In one report from Anthropic, its Claude model breached a real company’s system through a simulated-name collision, publishing a malicious package, and scanning outside systems. In this test, Anthropic and Irregular incorrectly provided internet access to this model and did not instruct the model “which systems were in scope for the exercise”.

While Anthropic claims that their issues were caused by “rogue swarms” and “misalignment,” their later disclosure shows that exactly zero percent of the agents went “rogue”. In this experiment, Claude models’ real-world hacking dropped to zero percent once Anthropic employees told the models not to do real-world hacking. According to their own findings, Anthropic and Irregular bear all of the responsibility for the cybersecurity incidents they caused.

Keep reading

MASSIVE SPYWARE BREACH: Spain’s President Lost Millions of Messages, Emails, Photos and Audio to Pegasus

A new assessment of the Pegasus spyware attack on Spanish President Pedro Sánchez has revealed the extraordinary scale of information extracted from his cellphone, reigniting questions about who was behind the operation and what may have happened to sensitive government data.

Spain’s National Intelligence Centre, known as the CNI, has acknowledged that Pegasus extracted approximately 2.7 gigabytes of data from Sánchez’s phone during the 2021 cyberattack.

To illustrate the enormous volume of information represented by that amount of data, the CNI estimates it could correspond to roughly 5 million text messages, 100,000 emails, 1,200 photographs or 40 hours of recorded audio, according to reports published in Spain.

A Spyware Attack on the President

Sánchez’s phone was compromised by Pegasus in May 2021, with investigators determining that approximately 2.6 gigabytes of information were extracted during the first attack and another roughly 130 megabytes during a subsequent intrusion.

The phone of then-Defense Minister Margarita Robles was also targeted.

The Spanish government said at the time that the attacks were external and had not been authorized by Spanish authorities. But the identity of the person or organization responsible for the attacks has remained a major unresolved question.

Pegasus, developed by Israeli technology company NSO Group, is among the world’s most sophisticated commercial surveillance tools. Once a device is successfully compromised, attackers can potentially gain access to highly sensitive communications and information stored on the phone.

For a sitting president, that could include private conversations, diplomatic communications, government documents, photographs, contacts and information involving national-security matters.

One of the most troubling questions surrounding the case is not simply how much data was extracted, but what the attackers obtained.

Spanish authorities have previously acknowledged that forensic investigators could establish the amount of data removed from the devices but could not necessarily determine exactly which documents or pieces of information were taken.

That means the 2.7-gigabyte figure provides an indication of the scale of the breach without answering the more consequential question: What did the attackers actually see?

The uncertainty has fueled political controversy in Spain and prompted renewed scrutiny of the government’s handling of sensitive communications.

Keep reading

Hackers Withdraw 320 Million In Bitcoin From Blockstream’s Liquid Network Federation Reserves

The Liquid Network said Sunday that purported white-hat hackers withdrew about 4,000 bitcoin, worth about $320 million, from the federation wallet that backs L-BTC.

Bridge nodes were disabled, and the sidechain was paused. Other issued assets, including USDT, DePix and RWAs, were unaffected, the official account said on X.

The Liquid Network is a federated sidechain of Bitcoin, founded by Adam Back’s Blockstream. The Liquid chain issues a variety of assets such as LBTC, which it backs with BTC on the Bitcoin main chain, held in a large multisig of 15 corporate and known members. 11 of the 15 members need to sign a valid multi-signature transaction to move coins from the treasury. Before the hack, the treasury held over 4200 BTC; after the hack, Blockstream’s proof of reserves page reports a little over 207 BTC left. 

The hackers withdrew 4,019.4 BTC from the reserve address in a peg-out transaction using the SideSwap Peg-out Authorization Key. SideWap is a bridge exchange and a member of the Liquid Federation. While details on the mechanism of the hack are not confirmed yet, it appears an inflation bug on the LBTC side chain was exploited by the hackers to create over 4,000 LBTC that did not exist before, and cash them out for on-chain bitcoin from the federation. Because the transaction appeared as valid, given the consensus bug, the federation members’ HSM security servers signed the BTC withdrawal transaction, worth roughly 320 million at the time. 

The hacker moved the funds to an address ending in 6gyqjlte, from which they quickly signed a new transaction with a message on the OP_RETURN arbitrary data field saying “we are whitehats. contact us on chain.” Those coins were still at that address at the time of writing.

A small mainnet transaction to the hacker address followed by an OP_RETURN saying “Please contact security@blockstream.com”, presumably from a Blockstream public address, though that remains unconfirmed. A later OP_RETURN spend from the hacker address carried “Please contact us on Signal @m671aw.70”, however, this may be spam and does not share a link to the address with the stolen funds.

In response to the breach, exchanges were told to pause L-BTC deposits and withdrawals. Bridge nodes on the Liquid Network have been paused, limiting access to the side chain, which continues to produce blocks. 

JAN3 CEO Samson Mow said Aqua’s Liquid features were affected and that on-chain bitcoin still worked. Other wallets in the industry that use the Liquid Network are expected to be affected. Users holding LBTC now effectively have their savings at risk, since the underlying BTC is currently not redeemable. Given the private nature of the Liquid chain, user onchain analytics are scarce and not much public information is known about how much LBTC is held by retail users versus corporations of Blockstream itself. Nevertheless, should the funds not be returned, it would be a heavy blow to the Liquid Network’s user base.

Users of LBTC don’t have many options but to wait for conversations with the hackers to resolve. Given the size of the hack, it would be difficult for the hackers to get away with stealing all that bitcoin, though perhaps not impossible.

What may happen is that the hackers ask for a finder’s fee and return the majority of the funds. 

Keep reading

ID Verification Breach Exposes Millions of Sensitive Identity Documents

If you ever needed more proof that governments pressuring companies to collect ID data from customers or users is a bad idea, you only have to look at what happened this week. A dark-web service advertised on August 31 has been offering over 153 million scans of driver’s licenses, more than 10 million other identity cards, over 3 million travel documents and/or international IDs, and at least 579,000 medical cards.

The data apparently stems from a company hired to verify people’s identities. The service, called Nexus, was advertised on the Russian-language cybercrime forum Exploit.

Security researcher Brian Krebs found that a blank search on Nexus returned about 11.5 million result pages with roughly 15 results per page. This would support the claim that there were over 153 million license scans in the database, and the number increased by nearly 400,000 in 24 hours.

Nexus itself claimed to have “continuously exfiltrated new data for over a year into our private database” – but this is not verified and could be an advertising claim.

What Krebs was able to verify is that his own Virginia license was among those available on the site. He searched with permission for the licenses of more than a dozen friends and relatives; nine people whose records appeared said that the attached timestamps matched or closely tracked their travels.

In the case of Krebs and his mother, the timestamps corresponded to a June 2025 car rental from Hertz. Their records were created seconds apart, matching their account that they handed both licenses to the rental representative at the same time.

Krebs’s record contained three pairs of images showing the front and back of the license in visible light, infrared, and ultraviolet.

Privacy researcher Zach Edwards also found his license on Nexus. Its timestamp matched a trip to Las Vegas, where he had presented the document to TSA, the Aria hotel and the Planet13 dispensary. Edwards said the dispensary was the only one of the three places where he knew the license had been scanned.

Keep reading

MASSIVE SECURITY NIGHTMARE: FBI Investigates Dark-Web Service Selling 153+ MILLION Driver’s License Scans — Including Secretary Pete Hegseth’s Information for $100

The FBI is investigating what could be one of the most devastating identity-data breaches ever uncovered in North America.

A newly launched dark-web service called “Nexus” claims to be selling actual digital scans of more than 153 million driver’s licenses belonging to people across the United States and Canada, according to cybersecurity journalist Brian Krebs, who first reported the incident.

This is not merely another database containing stolen names, email addresses, and passwords.

The criminals reportedly obtained digital images of government-issued identification documents, including front-and-back scans and, in some cases, the infrared and ultraviolet images used to authenticate them.

According to cybersecurity journalist Brian Krebs, the massive collection allegedly includes:

  • More than 153 million driver’s licenses
  • More than 10 million identification cards
  • More than 3 million travel documents and international IDs
  • At least 579,000 medical cards

The database reportedly contains the driver’s license of Secretary of War Pete Hegseth, along with identification documents belonging to other high-ranking federal officials, including an assistant director of the FBI. According to the report, the hacker offered Hegseth’s driver’s license for $100.

Krebs discovered that his own Virginia driver’s license was also in the database after the criminals behind Nexus displayed it as a free sample while advertising their service on the Russian-language cybercrime forum Exploit.

Keep reading

Chinese Hackers Broke Into NASA, Federal Reserve, DOJ & Senate: FBI Announces

The United States Department of Justice has on Wednesday announced US authorities thwarted a major state-sponsored hack which saw a temporary intrusion into NASA, the Federal Reserve, Senate, the DOJ, Department of Energy, and the Department of Health and Human services, along with four unnamed companies in the US and South Korea.

“Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure,” said FBI Director Kash Patel.

“These tools were used by PRC cyber actors to hide the origin of their attacks. Thanks to the work of FBI San Diego, FBI Cyber Division, and DOJ partners, we seized adversary infrastructure and shut these platforms down,” he added.

Domains utilized by two hacking platforms identified as “QScan” and “QTRouter” were seized by the DOJ in the large scale counter-cyberespionage operation.

Describing a pervasive botnet which was ultimately believed to be backed by Chinese state actors, The Wall Street Journal details that the “goal was to blend in with legitimate networking traffic, making the hacking activity hard to trace, federal officials say.”

“The group exploited software vulnerabilities to launch cyberattacks against U.S. government agencies, power companies and hospital systems, and operated a worldwide network of hacked devices—known as a botnet—to conduct its hacking campaigns, according to Brett Leatherman, the Federal Bureau of Investigation’s top cyber official,” WSJ continues.

As for the specific allegation that this had state backing, the DOJ press release states:

People’s Republic of China (PRC) state-sponsored group known as “QTFY,” employed by China-based Nanjing Xinjiuwei Network Technology Company, created and operated QScan and QTRouter.

The DOJ announcement additionally outlines efforts at concealment and ‘plausible deniability’ in the following:

QTRouter consists of these compromised IoT devices, as well as commercial proxy service devices and leased virtual private servers. QTRouter then serves as an “obfuscation network” – meaning it allows QTFY and other malicious cyber actors to conceal the PRC-origin of their computer intrusion activities because the malicious communications appear to originate from computers (such as those compromised by QScan) that are outside of the PRC and may even be local to the targeted networks. Because the seized domains were hard-coded into both the QScan and QTRouter malware and used for essential tasks such as communication and authentication, the court-authorized seizures made QScan and QTRouter inoperable. 

Neither Beijing’s foreign ministry nor the Chinese embassy in Washington have officially responded to the allegations, and as has been the pattern in the past is likely to reject the US charge altogether.

Earlier this year Google was among those warning of imminent stepped-up Chinese and Russian targeting of US defense companies. 

Google’s prior report seemed to preview some of the techniques on display in this latest hack. The report cited observations of “more China-nexus cyber espionage missions directly targeting defense and aerospace industry than from any other state-sponsored actors over the last two years.”

Keep reading

German Spy Agency Sends Scouts to Gamescom 2026, Looking To Hire Gamers As Secret Agents: THE TELEGRAPH

BND wants hackers capable of waging cyberwar on Russia.

The newly beefed-up German foreign intelligence service is trying to get a leg up on its Russian foes by tapping a younger, radically different class of agents: gamers.

The BND has launched a recruitment drive for game enthusiasts, eying a ‘new generation of tech-savvy secret agents.’

The Telegraph reported:

“The Telegraph understands that agents from the Bundesnachrichtendienst (BND), the German equivalent of Britain’s MI6, will attend the world’s largest video game festival to recruit young spies.

BND officials said there was a ‘significant overlap’ between the skills possessed by gaming fans and those the agency needs to retaliate against Russian hackers targeting critical infrastructure in Germany.”

This is not the first time the BND has tackled gamers, because the exact same drive was enacted last year.

“The recruiting operation, at Gamescom 2026 in Cologne, is part of a historic rearmament drive in Germany that seeks to turn the once-toothless BND into a rival of MI6 and Mossad.

An intelligence source said gamers at the festival who fit the BND’s profile would be invited to take a five-step challenge that tests their aptitude for cyber-security and hacking.”

Keep reading

US Government Warns: Hackers Attacking Vulnerable Water Systems With AI Help

Several U.S. government agencies have said that cyber actors are attempting to hack into devices made by industrial systems company Siemens that are used to monitor water and other critical infrastructure systems.

In an advisory published on Wednesday, the FBI, National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and other U.S. agencies informed “owners and operators of industrial control systems” that there is an “active cyber threat to Siemens S7 Series PLCs,” or programmable logic controllers—an industrial automation system.

Unnamed “threat actors are conducting reconnaissance and capability development against U.S.-based Siemens PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools,” the advisory said.

It added that the hackers use services to find PLCs connected to the internet that run what the agencies said is “outdated software” or are “otherwise poorly protected.”

“The U.S. critical infrastructure sectors most targeted by this threat activity include Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities,” the advisory reads.

“This is not a theoretical risk—it is an active threat.”

The agencies further warned that “exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems.”

Organizations using Siemens systems are encouraged to apply relevant security updates, isolate devices and systems from the internet where possible, implement strong security protocols, and strengthen monitoring for potential malicious activity, according to the advisory.

“These mitigations are particularly important for owners and operators who work with third-party service providers or system integrators who may have remote access to PLCs, as the asset owners may not realize that their systems are exposed and at risk,” they added.

The advisory did not provide the name of a specific group, country, or actor that may be involved in attempting to hack the Siemens systems. Nor did it name companies that may have been targeted by the threat actors.

The warning ‌comes amid U.S. cyber incidents ⁠targeting local water systems in several states in recent weeks. The FBI said earlier this month that from July 27 to July 30, water and wastewater utility companies in seven states reported security-related incidents.

In July, CISA and other agencies said Iran-linked hackers have targeted PLCs made by Rockwell Automation, Schneider Electric, Siemens, and potentially others.

A cybersecurity risk organization, Encrygma, said on Wednesday that a group linked to Iran’s Islamic Revolutionary Guard Corps, known as the CyberAv3ngers, has attacked water systems in the United States and displayed political messaging. CISA linked the group to cyberattacks on PLCs in late 2024.

Since February, the United States and Iran have traded strikes as the Trump administration has demanded that Tehran give up its nuclear program and reopen the Strait of Hormuz, a crucial waterway that allows for the transportation of significant amounts of the world’s traded oil.

Other agencies that were involved in the release of Wednesday’s advisory included the Department of Energy and the Environmental Protection Agency.

The NSA, FBI, CISA, and other U.S. agencies have long said that the Chinese regime, Iran, North Korea, and Russia have engaged in malicious cyber activity against U.S. infrastructure networks, collecting intelligence and engaging in cyber espionage.

Keep reading

Cyberattack Cripples California City’s 911 System, Forces Emergency Shutdown

A Northern California city of roughly 30,000 residents was forced to shut down its entire computer network Friday after a cyberattack knocked out its 911 system, the latest sign of how vulnerable American municipalities remain to digital assaults.

Suisun City, located about 45 miles from San Francisco, declared a state of emergency Saturday after malicious software infiltrated its network shortly before 6 p.m. Friday, the California Post reported.

“Officials shut down the entire network to stop the threat from spreading and protect evidence for a federal investigation,” the outlet reported.

City officials scrambled to prevent the outage from endangering residents, rerouting 911 calls through the Solano County dispatch center. Police and fire personnel remained active and able to respond to calls for service despite the loss of the city’s own systems.

The breach reached well beyond emergency dispatch.

City services including building permits and other municipal records were rendered inaccessible, and residents were unable to pay bills online while the network remained offline.

The Suisun City Council voted unanimously to pull the plug on the network and declare a state of emergency during a special meeting Saturday morning, an extraordinary step that underscores the severity of the threat local officials believed they were facing.

The incident lands amid heightened concern over foreign cyber threats to American infrastructure since the outbreak of the Iran war.

U.S. authorities issued an “urgent warning” in April that hackers linked to Iran’s Islamic Revolutionary Guard Corps were actively working to disrupt critical American computer networks, a threat national security officials have long cautioned could extend to local governments with limited cybersecurity resources.

It remains unclear whether the Suisun City attack is connected to Iran-backed hacking operations.

Investigators are still working to determine how the malicious software breached the network and who is responsible, according to news reports.

City officials have not said when full network functionality is expected to be restored.

Keep reading