Day Lila

Cybersecurity · Friday, 18 September 2026

01 Briefing what happened

Revolut sent customers' passports to a hacker posing as a government agency. The hacker now wants $3m.

Cybersecurity 28 sources

Revolut, the app-only bank, answered requests from a real but stolen Italian government mailbox, reportedly for about five months. A hacker is now publicly demanding $3m. Also today: an attacked Cisco network gatekeeper, unpaid UK online-safety fines, a data broker losing its website, and hackers claiming to be inside Russia's election systems.

$3m

demanded in public by a hacker calling themselves IAmNotAVillain

Revolut says nobody has sent the demand to the company itself [1]

about 680

Revolut customers whose files were sent, as SecurityWeek understands it

Revolut itself says only a very limited number and gives no figure [1][5]

5 months

how long the fake requests were answered, according to the hacker

the hacker told this to investigators at the firm Duel; Revolut has not confirmed it [1]

300+

stolen logins for the Italian ministry's email system known to Hudson Rock

taken by password-stealing malware on staff computers [1]

The lead story — what happened

  • Revolut, a British bank that works only through a phone app, confirmed that it gave customer files to someone posing as a government agency. [2][5]
  • The requests came from a real government email address, so they passed the technical tests on the sender. Staff handled them as normal legal requests. [4]
  • Banks must answer legal requests from police and government agencies. [2] Because Revolut is required to respond, it complied. [1]
  • The files included passport and driving licence copies, the selfies customers take to prove who they are, bank statements, account numbers and full transaction histories, including Bitcoin. [2][3]
  • Revolut says only a very limited number of customers were affected. SecurityWeek understands it was about 680 people, reportedly holding large amounts of cryptocurrency. [5][1]
  • The requests went to Revolut Bank UAB, the company's arm in Lithuania. The hacker told investigators at the firm Duel that it answered them for roughly five months. [1]
  • The sending address appears to belong to an employee of Italy's Interior Ministry. [1] Italian authorities did not answer questions from The Record. [3]
  • Hudson Rock, a firm that tracks stolen logins, knows of more than 300 logins for that Italian ministry's email system. [1] They were taken by infostealers, malware that copies saved passwords off infected computers. [1]
  • On Wednesday a hacker calling themselves IAmNotAVillain publicly demanded $3m from Revolut and threatened to sell the files. [1] That is about 2.2m pounds. [6]
  • Revolut says no person or group has contacted it directly with a demand. [1] The hackers also claim they took 147GB from an Italian police agency, and Italian police have opened an investigation. [1]
  • Revolut says it blocked the email address and told the agency whose address was used, the police, and the data-protection and financial regulators. [5][3]
  • The same trick was used in 2021 and 2022, when a group called Lapsus$ sent fake emergency requests from police accounts to Apple, Meta and Discord. [3]

Who is involved

  • Revolut

    a British bank that works only through an app, with more than 80 million customers; it answered the fake requests [2][3]

  • IAmNotAVillain

    the name used by a hacker who claims the break-in and publicly asked Revolut for $3m [1]

  • Italy's Interior Ministry

    the Italian government department in charge of the police; the sending email address appears to belong to one of its staff [1]

  • Hudson Rock

    a company that tracks logins stolen by malware; it found hundreds of stolen logins for the Italian ministry's email system [1]

How it unfolded

  1. Earlier this year fake requests begin reaching Revolut's Lithuanian arm; the hacker says they ran for about five months [1]
  2. 11 Sep Revolut sends notices to affected customers [4]
  3. 12 Sep Revolut confirms the breach publicly [5]
  4. 16 Sep IAmNotAVillain demands $3m in public [1]
  5. 17 Sep the ransom demand is reported widely [6]

Where this points

Watch whether Italy's Interior Ministry confirms the account was its own, and whether any other bank says it received requests from the same address. [1][3]

What is pushing on the whole day

The bar and the word are our reading of how hard each one is pushing today. The arrow is where it is heading. The evidence is in the stories below.

Stolen logins opening doors High

Revolut's fake requests came from a government mailbox whose login had been stolen. [1] Kaspersky says a spy group broke into Russian companies mostly with real stolen logins for their remote-access links. [24] Spain's first reported AI-run break-in also began with a successful login. [20]

Fines nobody can collect High

Ofcom, Britain's media regulator, says most of the online-safety fines it has issued are unpaid. [12] A US court threw out 4chan's lawsuit to stop Ofcom, but any UK penalty would still have to be enforced in the US. [13] A people-search site ignored a New Jersey privacy law for years until a judge took its website name. [14]

Holes attacked before fixes land High

Cisco's network gatekeeper ISE was under attack before a fix existed. [7] Google says a flaw in Pixel phones' mobile modem was used in targeted attacks. [15] Ransomware gangs have joined attacks on a VMware flaw fixed in July. [17]

Hackers aiming at Russia Building

A group calling itself CikLeak says it got into systems behind Russia's election days before the vote. [11] Kaspersky, a Russian security company, says a pro-Ukraine group called Hacking Cat has moved from defacing websites to destroying files. [23]

AI in the attacker's hands Building

Spain's privacy regulator received its first report of a break-in carried out by an AI agent. [19] Kaspersky says Hacking Cat's ransomware changed so fast that AI may have helped write it. [23]

The rest of the day

16 more stories on this beat.

Each with its own sources. None of these is a link to the story above.

  1. 02

    Cisco's network gatekeeper attacked before any fix

    Cisco said on Wednesday that attackers were already using a flaw in ISE, its Identity Services Engine. [7] ISE is the system many organisations use to decide which people and devices may join their network. The flaw scored 10 out of 10 for severity and lets an attacker in without a password. [8] Cisco says there is no workaround, only the update. [9] An attacker who gets in gains full control and can erase the signs of it. [7]

    Why it matters — A break-in here reaches the part of a company that decides who else is trusted. Cisco also released fixes for 20 ISE flaws the same day, 12 of them critical. [10]

  2. 03

    Hackers claim they got into Russia's election systems

    A group calling itself CikLeak says it broke into systems of Russia's Central Election Commission and companies that build Vybory, the state platform that runs elections. [11] It claims it took internal papers, server settings, passwords and staff chats. [11] Important Stories, an independent Russian news outlet, says the documents are real. [11] It is unclear whether the hackers reached anything used to cast or count votes. [11] Voting for all 450 seats in Russia's lower house of parliament runs for three days from Friday. [11]

    Why it matters — Ella Pamfilova, who chairs the commission, said attacks on election systems have never been this intense. [11] The group urged Russians to vote in person, saying that makes results harder to change. [11]

  3. 04

    Britain's online-safety fines mostly unpaid

    Ofcom, Britain's media regulator, told a House of Lords committee that most of the fines it has issued under the Online Safety Act have not been paid. [12] The law is meant to protect children and other users from illegal content online. [13] Ofcom has fined 11 services more than 7m pounds in all. [12] It cannot close a website worldwide, only ask a court to block it in the UK. [12] It cannot use a block just to collect an unpaid fine. [12]

    Why it matters — A company with no money or offices in Britain can ignore a British fine, because Ofcom has nothing of it to seize. Ofcom says it is working with the UK government on stronger powers. [12]

  4. 05

    US court throws out 4chan's case against Ofcom

    A court in Washington DC dismissed a lawsuit by 4chan and Kiwi Farms, two US online forums, against Ofcom. [13] The forums had called Ofcom's letters threats to their rights under the US constitution. [13] Ofcom fined 4chan 20,000 pounds last October for not answering its legal requests for information. [13] The judge said the case did not belong in a US court. [13] Any British judgment against the forums would most likely have to be enforced in the US, where they could fight it. [13]

    Why it matters — The ruling lets Ofcom keep investigating. It does not put the fine within Ofcom's reach, because the forums have no presence in Britain. [13]

  5. 06

    A data broker loses its website to a court

    A New Jersey judge ordered radaris.com and more than a dozen sister websites handed to Atlas Data Privacy, which had sued them. [14] Radaris sold detailed files on millions of Americans through people-search websites. [14] New Jersey's Daniel's Law lets police officers, judges and their families have their details removed, with fines of $1,000 for each ignored request. [14] Radaris stonewalled for years and kept moving its paperwork to companies in places like the Marshall Islands. [14]

    Why it matters — The judge took the one thing Radaris could not move out of reach, its web address. The site no longer sells personal files, and Radaris says it will appeal. [14]

  6. 07

    Google fixes a Pixel phone flaw already in use

    Google released its September update for its own Pixel phones, fixing 110 flaws. [15] One, in the part of the phone that talks to the mobile network, was already being used in targeted attacks. [15] An attacker nearby on the same network could use it to gain more control of the phone. [15] On 16 September CISA, the US cyber-defence agency, added it to its list of flaws known to be under attack. [16]

    Why it matters — US government offices are required to fix flaws on that list quickly. [16] Pixel phones get their fixes from Google directly, separately from other Android phones. [15]

  7. 08

    Ransomware gangs join attacks on a VMware flaw

    CISA says ransomware gangs are now exploiting a critical flaw in VMware vCenter, the console that runs a company's virtual servers. [17] Broadcom, which owns VMware, fixed it on 29 July and told customers to treat the update as urgent. [17] A spying group used it first, and a forensics firm counted 361 hacked addresses in 47 countries. [17] Shadowserver, which scans the internet, still counts more than 450 vCenter servers reachable online. [17]

    Why it matters — Nobody knows how many of those 450 are fixed. A console like this can open a whole company's network to a gang that wants to lock its files for ransom. [17]

  8. 09

    Check Point closes a flaw before attackers find it

    Check Point, which makes firewalls, fixed a critical flaw in the server that sets its firewall rules and administrator access. [18] Someone with no password could have run commands on it over the network. [18] The flaw scored 9.8 out of 10. [18] Check Point says it knows of no attacks, and CISA also recorded none. [18] Customers with automatic updates switched on were already protected. [18]

    Why it matters — The fix arrived before anyone was known to be using the hole, the opposite of the Cisco case the same week. One version, R82.20, still has no full update, according to the scanning firm Censys. [18]

  9. 10

    Spain gets its first report of an AI-run break-in

    Spain's data protection agency, the AEPD, says it has received its first report of a personal-data breach carried out by an AI agent. [19] An AI agent is a program that plans and carries out tasks on its own. [20] This one logged in, searched the system for weak points, then changed personal details and viewed invoices. [20] The agency has not named the victim or the AI model, and is still reviewing the case. [19]

    Why it matters — The agency says AI makes attacks faster, leaving less time to spot and stop them. [19] It says the use of a model does not mean the model's maker was hacked. [19]

  10. 11

    Premier Medical Group tells 282,000 patients

    Premier Medical Group, which runs doctors' offices in New York's Hudson Valley, is telling 282,075 patients that their files were taken. [21] Attackers reached the files on 14 June, when some of its systems were disrupted. [21] They held names, birth dates, diagnoses, medicines and health insurance details. [21] No ransomware group has claimed the attack. [21]

    Why it matters — Three months passed between the theft and the letters. The group says patients should look for charges for care they never received. [21]

  11. 12

    Banking malware in Brazil is cut off

    Elastic Security Labs, a security research team, described a malware kit called KREMLIN used against people in Brazil since May 2025. [22] It arrives as a fake bank receipt or invoice, and its lures copy 12 banks. [22] It quietly adds an extension to Chrome or Edge that records passwords typed into forms. [22] Elastic confirmed 1,515 infected computers, almost all in Brazil. [22]

    Why it matters — Elastic stopped the current campaign by registering a web address the malware relied on, which made it shut itself down. [22] Despite its name, the kit is linked to a Brazilian group. [22]

  12. 13

    Pro-Ukraine hackers move to destroying files

    Kaspersky, a Russian security company, says Hacking Cat, a pro-Ukraine group, has attacked Russian organisations since about February 2024. [23] By mid-2025 it moved from defacing websites to locking and wiping files. [23] In March it claimed a break-in at a contractor for Rosatom, Russia's state nuclear company. [23] Kaspersky also describes a spying group, NightEagle, that got into Russian firms mostly with stolen logins. [24]

    Why it matters — Kaspersky says several groups share the same tools, which makes it hard to say who did which attack. [23] Both reports come from Kaspersky, a Russian company describing attacks on Russia. [23][24]

  13. 14

    Microsoft repairs its own record update

    Microsoft issued extra fixes on Monday for problems caused by its record September update. [25] That update closed 974 security flaws, more than it fixed in all of 2023. [25] The new fixes repair Remote Desktop, which lets people use a computer from far away. [25] They also repair virtual machines and some USB sound devices. [25]

    Why it matters — A security chief at the firm SOCRadar told Dark Reading that the risk of faulty updates will grow as they get bigger. [25] AI tools finding more flaws is one reason they are getting bigger. [25]

  14. 15

    US agency tells defenders to lay decoys

    CISA published guidance on decoys for companies that run power, water and other essential services. [26] A decoy is a fake system, account or file that no real user should ever touch. [26] When an intruder touches one, defenders get an alert they can trust. [26] CISA says decoys can be added bit by bit, without rebuilding the network. [26]

    Why it matters — It starts from the view that an attacker may already be inside. A decoy turns that intruder's exploring into a warning sign. [26]

  15. 16

    Microsoft signs AI privacy rules for schools

    Microsoft agreed privacy and safety rules for its AI tools in US schools with the American Federation of Teachers, a large teachers' union. [27] It says it will not use student or teacher data to train AI, and the data cannot be sold or used for adverts. [27] The agreement bans AI features built to make students emotionally attached. [27] It is legally binding, with outside audits, from 1 November. [27]

    Why it matters — OpenAI and Anthropic say they are discussing similar deals. Google, the biggest supplier of school technology in the US, has not said. [27]

  16. 17

    A report counts more ransomware at factories

    SecurityWeek, reporting a study by the security company Black Kite, says ransomware attacks on manufacturers are up 40% on the same period last year. [28] Black Kite counted 5,237 disclosed victims in manufacturing and distribution from January 2023 to July 2026. [28] It says mid-sized suppliers take most of the attacks. [28] A stopped production line puts pressure on a victim to pay. [28]

    Why it matters — The count comes from a security firm's own report. SecurityWeek notes that the attack on Jaguar Land Rover in September 2025 hit more than 5,000 other companies. [28]

02 Lesson why it matters

Why a fake government request got answered and real fines went unpaid

A firm obeys a demand when refusing would cost it something within its reach, even when the demand is fake.

The twist

A firm obeys a demand when saying no would cost it something it cannot hide. Revolut answered because refusing a government agency looked risky, and nobody asked whether the sender really was that agency.

How it works

  1. A demand arrives: a request for files, a fine, a court order
  2. The one receiving it asks what they lose if they say no
  3. A bank must by law answer police and government requests, so it answers fast
  4. A website run from abroad has nothing in reach to lose, so it ignores even a real fine
  5. So a fake demand works on the firm that follows rules, and a real one fails on the firm that hides

The same force, elsewhere today

Where this chain is also running, in today's other stories.

  • Britain's online-safety fines mostly unpaid

    Companies with no money or offices in Britain can refuse Ofcom's fines, because Ofcom has nothing of theirs it can take.

  • A data broker loses its website to a court

    Radaris ignored real removal requests for years, until a judge took the one thing it could not move abroad, its web address.

  • US court throws out 4chan's case against Ofcom

    4chan sued instead of paying 20,000 pounds, and the court noted any British penalty would still have to be collected in the US.

Where you've seen this

Phone scams

a caller says they are the tax office, and people pay because arguing with the tax office feels riskier than paying

Parking tickets on foreign cars

a driver from another country can often ignore the ticket, because it cannot follow them home

Unpaid court awards

a winner in court collects nothing from a company whose money sits in another country

The catch

Questioning every request would slow down real police in real emergencies, and that delay is why banks answer fast in the first place.

And the whole of it

Revolut's customers gave the bank their passports because it asked for them to keep their accounts open. An Italian official's password was copied by malware on a computer. Revolut's staff in Lithuania saw a real government address and answered, and none of these people could see the others.

03 Truth what's really going on

What is really going on

Revolut sent customers' passports and bank histories to someone using a stolen Italian government email login, because banks must answer government requests and the address was real. [1][2] On the same day, Britain's media regulator said most of its online-safety fines are unpaid, because the websites it fined keep no money in Britain. [12]

Why it works on us — A request that looks like it comes from the police or a ministry makes saying no feel dangerous, so the person answering hurries instead of asking questions.

Who gains

  • Whoever holds the Revolut files — Passport copies, selfies and bank histories together can be used for identity fraud and targeted phishing, security experts told Infosecurity. [4]
  • Sellers of stolen logins — Hudson Rock knows of more than 300 logins for the Italian ministry's email system taken by malware. It thinks the hacker bought or reused logins someone else had already stolen. [1]
  • Websites fined by Ofcom that keep no money in Britain — Ofcom cannot use a UK block just to collect a fine, so a site that obeys the rules but does not pay faces a slow debt chase. [12]
  • 4chan and Kiwi Farms — The US court said any British judgment would most likely have to be enforced in the US, where the forums could fight it. [13]
  • Ransomware gangs using the VMware flaw — The fix has been out since 29 July, but more than 450 vCenter servers are still reachable online with no count of how many are fixed. [17]

Who pays

  • The Revolut customers whose files were sent — Their passports, selfies and full transaction histories are now outside the bank, and a hacker is offering to sell them. [1][2]
  • Revolut — It faces a public $3m demand and has reported the breach to financial and data-protection regulators. [1][5] This comes as it plans a stock market listing that could value it at up to $200 billion. [5]
  • Italy's Interior Ministry and its staff — A staff email login was stolen and used to send requests in the Italian government's name. [1]
  • Premier Medical Group's patients — 282,075 people had names, diagnoses, medicines and insurance details taken in June, and were told three months later. [21]
  • Organisations running Cisco ISE — There is no workaround. [9] Where a break-in is suspected, Cisco recommends wiping and rebuilding the machines. [7]

What nobody knows yet

Open questions from across today’s stories — ours included.

  • 01

    How many Revolut customers had their files sent, and which ones.

    Revolut says only a very limited number and gives no figure. [5] SecurityWeek understands it was about 680, reportedly large cryptocurrency holders. [1]

  • 02

    How long the fake requests ran.

    The hacker told investigators it was about five months, and separately claimed six. [1] Revolut has not said when the first request arrived.

  • 03

    Whether the stolen mailbox was used against other banks.

    The Record says it is not known whether the same address targeted other financial firms, and Italian authorities did not answer its questions. [3]

  • 04

    Whether the 147GB said to be taken from an Italian police agency is real.

    The claim comes from the hackers themselves. Italian police have opened an investigation but have said nothing about its findings. [1]

  • 05

    How deep CikLeak got into Russia's election systems.

    An independent Russian outlet says the documents are real, but it is unclear whether the hackers reached anything used to cast or count votes. [11]

  • 06

    Who is attacking Cisco's ISE, and how many networks they reached.

    Cisco has not said who is behind the attacks. [7] An attacker with full control can hide or delete the signs of the break-in. [7]

  • 07

    How many of Ofcom's online-safety fines have been paid.

    Ofcom says most are unpaid but refused to give the number. [12]

  • 08

    Which company suffered Spain's first AI-run break-in, and which AI model was used.

    Spain's data protection agency named neither and says the case is still under review. [19]

  • 09

    How many exposed VMware vCenter servers are still unfixed.

    Shadowserver counts more than 450 reachable online but cannot tell which are patched. [17]

04 Hope carry this

Elastic Security Labs shut down a banking malware campaign in Brazil by registering one web address the malware depended on. The malware had infected 1,515 computers, and on seeing that address it stopped itself.

Also true today

  • Check Point fixed a critical flaw in the server that runs its firewalls before anyone was known to be using it. Customers with automatic updates were already protected when the warning went out.
  • A New Jersey judge handed radaris.com to the company suing it. The site no longer sells detailed personal files on millions of Americans.
  • Microsoft agreed with a US teachers' union not to use students' data to train its AI or sell it, with outside audits from 1 November.

Across the beats