Revolut Data Breach: Trusted Channel Abuse

Revolut data breach report showing customer information exposed through fraudulent government requests

A recent Revolut data breach shows how attackers can exploit trust without breaking into a bank’s core infrastructure. By using a compromised Italian government email account to submit fraudulent customer-data requests, attackers reportedly persuaded Revolut staff to disclose sensitive information linked to roughly 680 customers across several European countries. The incident exposed a second problem:…

Read More

TerminalFix ClickFix Attack Campaign Hits Germany

A TerminalFix ClickFix attack campaign compromised a German state institution, BSI confirms — heise links it to Berlin's Rhysida actor cluster.

A TerminalFix ClickFix attack campaign has compromised a German state institution’s network, Germany’s Federal Office for Information Security (BSI) confirmed on September 4. TerminalFix is an evolution of the ClickFix social-engineering technique: a fake CAPTCHA tricks a user into pasting a command, but instead of the old single-machine Run-dialog trick, it opens Windows Terminal and…

Read More

Device Code Phishing: What SMEs Need to Know

Device code phishing abuses real Microsoft logins and working MFA, leaving few warning signs. Here's what SMEs need to know in 2026.

Cybercriminals have started exploiting a login shortcut millions of people already trust. Rather than sending victims to a fake login page or trying to steal a password outright, they persuade employees to authorise an attacker-controlled device through a completely legitimate identity provider — Microsoft, most often. The result is a fast-growing form of social engineering…

Read More

Microsoft Teams Vishing Ransomware Hits in 17 Hours

A Microsoft Teams vishing ransomware campaign, STAC4749, breached dozens of firms via fake IT-helpdesk calls, encrypting networks within 17 hours.

A Microsoft Teams vishing ransomware campaign has hit dozens of North American organizations since February 2026, using two-minute fake IT-helpdesk phone calls to gain a foothold that, in the fastest confirmed case, ended in full Chaos ransomware encryption within 17 hours of first contact. What Happened Security vendor Sophos tracked the campaign to a financially…

Read More

World Cup Cybersecurity: What SMEs Need to Know

World Cup cybersecurity — cyber risks for SMEs in major sporting event ecosystems

World Cup cybersecurity risks do not begin and end with FIFA. The 2026 World Cup has captured the attention of billions of fans globally — and that same visibility attracts cybercriminals, hacktivists, fraudsters, and potentially nation-state actors. The risks extend far beyond the official organisers, the large ticketing companies, and the stadium operators. Large global…

Read More