Content
01. News Bites
-
Revolut shares customer data with attacker posing as government agency
-
Spain reports first personal data breach caused by AI Agent Attack
-
Cyberattack takes International Meteor Organisation website offline
-
Cyberattacks hit nearly a third of organisations worldwide says new report
-
Iranian hackers target dissidents and journalists with CHOSEN BRICK malware
02. Conclusion
Revolut shares customer data with attacker posing as government agency
Revolut has disclosed a data breach after handing customer information to a threat actor impersonating a government agency. The company said the email request carried valid domain authentication credentials, leading staff to treat it as legitimate.
Exposed information included names, dates of birth, addresses and contact details, alongside copies of identity documents and facial verification images. Account statements, IBAN numbers, withdrawal records and full transaction histories, including Bitcoin transactions, were also shared.
Revolut said a limited number of customers were affected but declined to disclose the figure. The company blocked the email address and notified the relevant government agency, law enforcement and regulators. It said its systems and customer funds remained unaffected.
The incident highlights the risks of relying on email authentication alone to establish legitimacy. Organisations handling sensitive information need robust processes to verify requests independently, particularly when they appear to come from trusted authorities seeking access to customer records.
Spain reports first personal data breach caused by AI Agent Attack
Spain’s data protection agency, AEPD, has reported its first personal data breach resulting from an attack carried out by an autonomous AI agent.
According to the agency, an attacker deployed an agent using an unnamed large language model to target an organisation. It examined files and scanned for vulnerabilities, identifying weaknesses that enabled read and write access to documents containing personal information and invoices.
The agent successfully connected multiple stages of the attack, demonstrating how AI can support intrusions across an attack sequence. AEPD warned that organisations need detection, containment and response capabilities that can keep pace with increasingly rapid attacks, while retaining human oversight.
The agency urged organisations to review their security and data protection arrangements. Priorities include minimising stored data, restricting access, fixing vulnerabilities, managing supplier risks and preparing incident response procedures. The case highlights why organisations must account for AI agents when assessing threats to personal data.
Cyberattack takes International Meteor Organisation website offline
The International Meteor Organisation (IMO) has warned of several weeks of disruption after a cyberattack dealt a critical blow to its ageing infrastructure, taking much of its website offline.
The nonprofit, which coordinates amateur and professional meteor observations worldwide, said it is moving to new infrastructure and services. It is prioritising fireball reporting during the outage, with a dedicated reporting page remaining available and some updates shared through Facebook.
Founded in 1988, the IMO helps standardise meteor reporting and maintains databases containing observations, photographs and videos used by the astronomy community. The disruption limits access to resources that support scientific research and collaboration.
The attack’s motive remains unclear. No group has publicly claimed responsibility, and there are no known reports of a ransom demand or confirmed data theft.
The incident highlights the operational impact cyberattacks can have on scientific organisations, where ageing infrastructure can complicate recovery and prolong disruption to services.
Cyberattacks hit nearly a third of organisations worldwide says new report
Nearly a third (29%) of organisations worldwide experienced a successful cyberattack in the past year, according to the Hiscox Cyber Readiness Report 2026. Those affected reported an average of four incidents.
The survey of 6,800 security decision-makers found that cyber incidents cost organisations around $52,000 on average over the year, while downtime averaged 32.8 hours.
The effects extended beyond disruption. Among victims, 32% reported delays to growth or new business initiatives, 31% faced increased staffing or external expertise costs, and 29% lost business opportunities or partnerships.
Employees also felt the impact, with 69% of affected organisations reporting burnout, high stress or a toxic workplace culture following an attack.
Businesses are investing around $51,000 annually in cyber resilience, including employee training, recruitment and security tools. Almost a third (32%) now link executive compensation or performance measures directly to cybersecurity outcomes, reflecting growing recognition that cyber resilience requires accountability across the whole organisation.
Iranian hackers target dissidents and journalists With CHOSEN BRICK Malware
Government agencies have warned that Iranian state-linked hackers are using Windows malware called CHOSEN BRICK to spy on dissidents, activists and journalists worldwide.
A joint advisory from UK, US and Dutch authorities details attacks beginning with WhatsApp or Telegram messages impersonating trusted contacts or technical support. Victims are persuaded to open malicious files disguised as legitimate applications, sometimes on personal devices to bypass workplace security controls.
The malware can steal emails and messaging data, capture screenshots, record microphone audio and download additional malicious software. It can also delete files or wipe infected systems.
Attackers use Telegram bots to control the malware and transfer stolen information through messaging and cloud services. Authorities warned that stolen material sometimes appears on pro-Iranian leak sites, enabling harassment and increasing physical risks for those targeted.
Organisations should investigate suspicious activity against the advisory’s indicators of compromise and ensure staff independently verify unexpected messages and software requests.
If you are worried about any of the threats outlined in this bulletin or need help in determining what steps you should take to protect yourself from the most material threats facing your organisation, please contact your account manager, or alternatively Get in touch to find out how you can protect your organisation.
Disclaimer
The Threat Intel Roundup was prepared by Integrity360 summarising threat news as we observe it, current at the date of publishing. It should not be considered to be legal, consulting or any other professional advice. Any recommendations should be considered in the context of your own organisation. Integrity360 does not take any political stance in the information that we share. Moreover, the opinions expressed may not necessarily be the views of Integrity360.