Hackers demand 10,000 Bitcoin from Revolut following data breach
Revolut breach via spoofed government-agency email requests; attackers posted stolen data samples on Telegram and demand 10,000 Bitcoin.
Revolut disclosed that an unauthorized third party obtained sensitive customer information by sending fraudulent requests from the email domain of a legitimate government agency. People claiming responsibility have posted samples of the allegedly stolen data across several Telegram groups. The perpetrators are demanding 10,000 Bitcoin from Revolut.
Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack
Attackers hijacked HBO Max's verified Reddit account to push 108 malicious ads delivering AMOS and Amatera infostealers via ClickFix prompts.
Threat actors compromised the official u/hbomax Reddit account and ran 108 malicious ads over 48 hours in a campaign tracked as PasteSwitch, directing users to a fake hbomaxx[.]us site. ClickFix prompts tricked macOS users into running curl | zsh payloads (MacSync, AMOS Helper, fake wallets) and Windows users into executing MSHTA/PowerShell delivering Amatera Stealer. AnimateClipper and ZigClipper clipboard hijackers swapped cryptocurrency addresses using a blockchain-hosted C&C active since early 2026. Reddit suspended the ads after notification.