One convincing email was all it took to get Revolut's data
Revolut has confirmed that an employee handed customer data to scammers after being fooled by a request that looked like it came from a genuine government agency. The scammer used an address tied to a real regional government office. That office has denied sending it.
Revolut's own systems were never breached, and the company says customer funds and devices are unaffected. The attacker's only tool was one convincing email, sent to one person with the authority to release data, and a plausible reason for asking.
Reports describe passport and driving licence copies, IBAN numbers, full transaction histories, and cryptocurrency wallet activity among the data disclosed, affecting several hundred customers across more than 30 European countries.
The attackers have reportedly begun publishing some of the data and are demanding a ransom to stop.
What to check in your own business
Any business that shares customer data with staff who make judgement calls on incoming requests, whether from regulators, law enforcement, or partners, carries some version of this exposure. Two things are worth reviewing:
- Does your team have a second channel to verify an unusual data request before acting on it, rather than trusting the email address alone?
- Does releasing sensitive data ever require more than one person's sign-off?
Our Phishing Simulations put a realistic, convincing request in front of your own team, safely, so you find out how they'd respond in a real event.
Trezor's shipping partner kept data it was told to delete, and 80,000 people paid for it
Trezor's fulfilment partner, ShipMonk, was breached in August after attackers exploited a vulnerability in a data analytics tool ShipMonk used internally. Attackers used the flaw to escalate to administrator access and pull customer order data.
Trezor disclosed the breach on 13 August, saying around 13,700 customers who'd ordered in the previous 90 days had names, emails, phone numbers and shipping addresses exposed.
Three weeks later, ShipMonk told Trezor it had also been holding order data from a previous arrangement between the two companies dating back to 2019, data it should have deleted years earlier. That added another 67,000 customers to the total, taking it past 80,000.
What to check in your own business
Even with your own systems fully secure, you can still be exposed through a supplier who didn't do what their contract said. Worth asking of any partner who holds your customer data:
- Do your contracts specify a data retention period, and do you ever ask for evidence that old data has actually been deleted?
- If that supplier were breached tomorrow, would you know what of yours they were still holding?
Our Supply Chain Security module lets you see and share risk scores with the businesses your data passes through, so this kind of gap is visible before it becomes a headline.
220 million passport records, no owner, no ransom note
Researchers at Kinryu Labs found a database sitting open on the internet, protected by nothing more than default login credentials. Inside were around 220 million records spanning nine years, including names, dates of birth, passport numbers, and full flight itineraries.
The database appears to have been visible for years before anyone raised the alarm. A separate internet-scanning service had spotted the same host back in 2022 and flagged it as a database in 2023, but nobody stepped in to secure it until researchers reported it directly in June.
Days after the story broke, no airline or government agency had come forward to claim it.
What to check in your own business
Most exposures like this aren't the result of an attack. They're a forgotten server, an old integration nobody remembered to shut down, or a default setting nobody thought to check, sitting open for years without anyone noticing.
- When did you last check what's actually reachable from the outside on your network, rather than what you assume is there?
- Do you have a process for decommissioning old systems, or do they just get left running?
Recon Scan shows you what's reachable on your network from the outside, so exposures like this get caught by you, not by a researcher or a journalist.
What these three have in common
None of this month's three stories started with a hacker breaking in.
One was a convincing email that looked official enough to work. One was a supplier who kept data it should have deleted. One was a server left open for years because nobody was watching for it.
Different modules would have caught each one. That's why coverage matters more than any single check.
Find out where you'd stand
See how your organisation would fare in similar circumstances with a free HackRisk Report. It's completely free and arrives within 24 hours.
