18 September 2026

8 min read

Revolut customer data exposed in government impersonation scam | Cyber Intelligence Briefing – 18 September 2026

September 2026
Cyber Intelligence Briefing

Top news stories this week

  1. False authority. Revolut customer data exposed in government impersonation scam
  2. Low score, high impact. Japanese digital agency’s data exposed through low-scored VPN flaw 
  3. Artificial suspect? Emerging breach report demonstrates how AI agents could expand the cyber threat landscape
  4. Power play. Texas-based utility company reports breach of customer data
  5. Max'd out. Hackers hijack HBO Max's Reddit account to push malware at scale
  6. Patch now. Threat actors actively exploit vulnerabilities in Cisco, ConnectWise and Acronis products

1. Revolut customer data exposed in government impersonation scam 

Financial technology firm Revolut disclosed a customer data breach after attackers used a compromised Italian government email account to submit fraudulent information requests that appeared legitimate. Revolut described the incident as a sophisticated impersonation scam and said its systems and customer funds were not compromised, although personal and account data relating to around 680 customers was reportedly exposed. 

So what?

Impersonation scams are becoming increasingly sophisticated, with threat actors combining detailed research, convincing pretexts, and carefully crafted communications to create highly believable social engineering campaigns. Rather than exploiting technical vulnerabilities, attackers are often seeking to exploit trust and established business processes.

[Researcher: Gabriella Nolan]  


2. Japanese digital agency’s data exposed through low-scored VPN flaw

Japan's Digital Agency disclosed a vulnerability in a VPN appliance which exposed approximately 246,000 personnel records, including information relating to government and public-sector workers. The incident reportedly stemmed from a low CVSS score, serving as a reminder that threat actors are often less concerned with severity ratings than whether a weakness can provide a foothold into a target environment.

So what?

A low-severity vulnerability can still deliver a high-impact breach. Organisations should therefore focus on exploitability and not just the CVSS score.

[Researcher: Jenny Eysert]  


3. Emerging breach report demonstrates how AI agents could expand the cyber threat landscape

The Spanish Data Regulator AEPD revealed what could be the first reported data breach involving an AI agent. The regulator alleges that an AI system identified vulnerabilities, accessed a platform, modified personal data and viewed invoices with limited human intervention. 

So what?

Organisations should treat AI agents as other potentially high-risk identities, subjecting them to the same access controls, monitoring and governance requirements as privileged human users. As highlighted in S-RM's recent cyber threat landscape analysis, increasingly autonomous AI agents represent a growing attack surface and source of cyber risk.

[Researcher: Jenny Eysert]


4. Texas-based utility company suffers data breach

CenterPoint Energy, a Houston, Texas-based utility company, has confirmed that an unauthorised party obtained customer information after a cybercriminal group claimed to have stolen more than 7 million records. The exposed information reported contains personal information of customers, though CenterPoint has not yet confirmed the full scope of the breach or how many customers were affected.

SO WHAT? 

The attackers claim to have breached CenterPoint by iterating through IDs on a public-facing API. Cyber security practitioners are encouraged to limit organisational exposure through internet-facing systems by applying fundamentals of authentication, authorisation, rate limiting, and protections against automated enumerations, especially as AI-enabled attacks continue to scale.

[Researcher: Steve Ross]


5. Hackers hijack HBO Max's Reddit account to push malware at scale

Attackers hijacked HBO Max's verified Reddit account and ran 108 malicious ads over 48 hours, using ClickFix tactics to trick Windows and macOS users into pasting malware-laden terminal commands. The campaign, dubbed PasteSwitch, also deployed infostealers, crypto clippers, and blockchain-based command-and-control infrastructure to dodge takedowns.

So What?

Cybercriminals weaponise trusted brand accounts to make malware delivery look routine. Organisations and their employees should heighten their alertness and treat any unexpected download prompt or copy-paste instruction as a red flag, even when the source looks legitimate.

[Researcher: Lawrence Copson]


6. Threat actors exploit vulnerabilities in Cisco, ConnectWise and Acronis products

Cisco has warned of active exploitation of Secure Email Gateway vulnerability CVE-2026-76461, which allows attackers to gain root access by sending a malicious email to a vulnerable appliance.


Separately, threat actors are exploiting the ConnectWise ScreenConnect vulnerability CVE-2026-84869 to transfer and execute files through active remote sessions without requiring user interaction.


Acronis has also identified active exploitation of CVE-2026-87886, a high-severity vulnerability affecting its backup plugins for cPanel/WHM and Plesk. The flaw allows a low-privileged attacker to escalate privileges and gain elevated access on vulnerable Linux servers without user interaction.

SO WHAT? 

Organisations should prioritise the remediation of vulnerabilities that are being actively exploited by threat actors to reduce the risk of unauthorised access and network compromise.

[Researcher: Milda Petraityte]

SUBSCRIBE TO RECEIVE OUR WEEKLY CYBER THREAT INTELLIGENCE BRIEFING VIA EMAIL

The S-RM Cyber Intelligence Briefing is a weekly round-up of the latest cyber security news, trends, and indicators, curated by our intelligence specialists.

To discuss this briefing or other industry developments, please reach out to one of our experts.

Editors

Share this post

Subscribe to our insights

Get industry news and expert insights straight to your inbox.