ZeroHour

Search: “TechCrunch”

126 stories

Revolut Exposed KYC Data After Fraudulent Government Email Passed Security Checks

Revolut handed over KYC documents, selfies, and Bitcoin transaction histories to attackers after a fraudulent email from a genuine government domain passed authentication checks.

Revolut confirmed on September 12, 2026 that it disclosed sensitive customer KYC data to an unauthorized third party after a fraudulent information request was sent from an email account operating inside a real government agency's domain, carrying valid domain authentication credentials. The exposed data included identity documents (passports, driver's licenses), verification selfies, birth dates, contact details, IBANs, account statements, and full transaction histories including Bitcoin. Revolut discovered the fraud only after independently verifying with the agency, blocked the sender, and notified law enforcement and financial regulators, but did not disclose the number of affected customers or the agency involved. Researcher ZachXBT assessed the operation was targeted at high-net-worth users, useful for fraud, impersonation, or extortion.

Security Affairs · 3d agoData breach

Revolut confirms customer data breach through fake government requests

Revolut disclosed customer identity data, including passports and possibly selfies, to an attacker using a legitimate government email domain.

Attackers impersonating a government agency used a legitimate agency email domain to submit fraudulent information requests, prompting Revolut to disclose customer identity and contact data to an unauthorized third party. Exposed data included birth dates, postal and email addresses, phone numbers, passport and driver's license copies, and possibly verification selfies, account statements, and transaction histories. Revolut said a limited number of customers were affected, blocked the email address, and notified the agency, law enforcement, and regulators, adding that systems and customer funds were unaffected. Security researcher ZachXBT reported the scam appeared to target high net worth users of the fintech, which serves over 80 million customers.

TechCrunch · Securityupdated · 1d agofirst · 3d agoData breach in the wild 3 sources3

Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware

Apple sent mercenary spyware threat notifications to users in 110 countries, including Ukrainian military members, in what researchers call an unprecedented notification wave.

Apple notified an unspecified number of users in 110 countries that they may have been targeted by mercenary spyware attacks, bringing total notifications to over 150 countries since the program began in late 2021. Apple does not attribute the attacks but describes the alerts as high-confidence indicators of individual targeting against journalists, activists, politicians, and diplomats. Citizen Lab's John Scott-Railton called the geographic scale unprecedented, and Access Now reported a record number of help requests, with recipients including members of Ukraine's military. Apple advised users to update devices, enable 2FA and Lockdown Mode, and use Stolen Device Protection.

The Hacker News · 29d agoThreat actor in the wild

Apple warned hundreds of users of mercenary spyware attacks

Apple sent threat notifications to users in 110 countries warning of targeted mercenary spyware attacks and recommending Lockdown Mode.

Apple sent a new round of threat notifications warning users in 110 countries they may have been individually targeted by mercenary spyware, adding to alerts issued in more than 150 countries since the program began in 2021. The company says such attacks are vastly more sophisticated than criminal activity, cost millions of dollars, and typically target journalists, activists, politicians, diplomats, and lawyers. Apple recommends verifying notices directly at account.apple.com, enabling Lockdown Mode, keeping devices updated, and seeking expert help such as Access Now's Digital Security Helpline. Citizen Lab researchers note the alerts can reveal that entire communities are under targeted surveillance.

Security Affairs · Aug 14, 2026Malware in the wild

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

FBI, NCSC, and AIVD detail Iran MOIS spyware CHOSEN BRICK/HEAVYGRAM, Telegram-controlled Windows malware spying on dissidents since 2023.

A September 15 joint advisory from the FBI, UK NCSC, and Dutch AIVD attributes the Windows spyware HEAVYGRAM (NCSC name CHOSEN BRICK) to Iran's Ministry of Intelligence and Security, with the campaign dating to autumn 2023 and targeting dissidents, journalists, and activists in the UK, US, Netherlands, and worldwide. Delivered via messages impersonating known contacts or tech support, the malware assigns each victim a dedicated Telegram bot for command-and-control and exfiltration, and can take screenshots, record microphone audio, steal Telegram/WhatsApp data, saved passwords, and emails, download more malware, and wipe the computer. Persistence uses a registry Run key (SMQDService or winappx) plus Microsoft Defender exclusions, with stolen data exiting via Telegram and cloud storage services like Vultr and Storj. The US Justice Department seized four pro-Iranian leak sites in March that had published stolen victim data.

The Hacker News · 14h agoMalware in the wild