Fintech Revolut disclosed that it released sensitive customer data to attackers who sent a fraudulent information request from an email account operating inside a real government agency's domain. Because the message passed standard email-authentication checks, Revolut treated it as a genuine legal or government request and complied. The exposed data for a limited number of users included passport or driver's license copies, verification selfies, full identity and contact details, and complete transaction histories including Bitcoin activity. It was not a breach of Revolut's systems but an abuse of the trusted legal-request process. The combined identity and financial data enables convincing impersonation, SIM-swapping, and targeted attacks on cryptocurrency holders.
Have I Been Pwned has added Colombian buy-now-pay-later fintech Addi to its breach corpus with 34,532,941 unique email addresses. Addi acknowledged unauthorized activity on its platform back in March 2026 and warned customers that personal data might have been compromised. ShinyHunters then claimed responsibility and published the dataset, which goes well beyond emails: credit-scoring requests, credit bureau records, customer identity files, email-validation logs, Cedula de Ciudadania national ID numbers, estimated income, socioeconomic level, and purchase history. Addi is a Bogota-based BNPL lender with $1B+ in funding and is one of the larger Latin American fintech breaches publicly documented this year.
ANY.RUN and Dark Reading published research on Mach-O Man, a new macOS malware kit Lazarus is deploying against fintech and crypto executives. The chain begins on Telegram with what looks like a legitimate meeting invite from a known contact, leading to a fake Zoom/Teams/Meet page that displays a fake 'connection issue' and instructs the executive to copy-paste a command into Mac Terminal. That ClickFix command grabs credentials, browser sessions, and Keychain data and exfiltrates over Telegram bot APIs. Lazarus has used the same template across the Drift and KelpDAO compromises, totaling more than $500M stolen in two weeks.