An Impostor Used a Real Government Email to Get Revolut’s Customer Records

A fraudulent request from a genuine government email domain persuaded Revolut to disclose sensitive customer records. The failure was in verifying who had authority to ask.

A fraudulent request from a genuine government email domain persuaded Revolut to disclose sensitive customer records. The failure was in verifying who had authority to ask.

Florida identified one compromised police login, improperly stored on an employee's personal device, as the route into its systems. The claimed scale of exposure remains unconfirmed.

One compromised contractor session opened cloud applications, patient systems and external health-record portals. HHS says the AdaptHealth breach affected 4,115,802 people.

The attacker did not need broad network access. Veradigm says credentials stolen from a third-party vendor were enough to copy patient data through one customer-service API.

The documents collected to stop fraud may now enable it. IDScan confirmed possible unauthorised access, while a vanished dark-web service claimed 153 million driver's licence records.

Separate social-engineering breaches at Quinn Emanuel and McDermott show how one compromised identity can expose exceptionally sensitive legal records.

A breach at Aesto Health reached 9.5 million people across at least two dozen providers, exposing medical, financial and identity data stored in AWS.

A breach of Thomson Reuters’ C-Track cloud may have exposed sealed and confidential court records across at least 12 US jurisdictions and Ontario.

Jack Henry says ShinyHunters used vishing to enter a non-production environment, exposing PII associated with fewer than ten clients.

Berlin says Rhysida released a further stolen-data package containing access credentials, forcing additional safeguards and possible service restrictions.