The week in breach news

Customer data is in focus again this week, with British fintech Revolut confirming it mistakenly handed over sensitive information belonging to nearly 700 customers to scammers and Texas-based utility giant CenterPoint Energy disclosing a breach through one of its external-facing systems. Meanwhile, fresh revelations about OpenAI’s AI agents autonomously targeting external systems are adding fuel to the growing debate around AI regulation, and Microsoft rolled out a record-breaking patch update covering 974 vulnerabilities across its products.

The week in breach news

United Kingdom

Revolut

Industry: FinanceExploit: Phishing

British fintech Revolut confirmed it mistakenly handed over sensitive data belonging to nearly 700 customers to scammers posing as government officials.

Revolut disclosed that a fraudster used a real email account on a genuine government agency's domain to send fraudulent data requests. The messages passed the bank's technical authentication checks and were processed as standard legal compliance requests, as Revolut's systems had no way of distinguishing them from legitimate ones. The accidentally disclosed information includes customer addresses, verification pictures, identity cards and bitcoin activity belonging to around 680 customers.

Hackers purporting to be behind the incident are now threatening to release the stolen information publicly unless Revolut pays a ransom.

Source

How it could affect your business

No servers were breached and no malware was deployed in this attack. Someone simply asked for customer data from what appeared to be a genuine government email address and the fintech handed it over. It is a stark reminder of how effective social engineering can be and how even technically robust systems can be bypassed when human judgment is the last line of defense. Businesses need to ensure that employees handling sensitive data requests are trained to spot manipulation attempts, verify requests through secondary channels and treat any unsolicited data request, however legitimate it appears, with a healthy level of scrutiny.

United States

CenterPoint Energy

Industry: Energy & Natural ResourcesExploit: Hacking

Texas-based utility company CenterPoint Energy confirmed a customer data breach in a filing with the Securities and Exchange Commission (SEC).

The company said an unauthorized third party obtained personal information belonging to a portion of its customers through one of its external-facing systems. CenterPoint Energy stated it does not currently believe the incident is likely to have a material impact on its financial condition or results of operations and confirmed that its electric and gas delivery services have not been affected and remain fully operational.

The company also said it plans to notify impacted customers and regulatory authorities as required by law and has already reported the matter to law enforcement and certain regulatory agencies.

Source

How it could affect your business

This incident is the latest in a growing pattern of cyberattacks targeting U.S. critical infrastructure, particularly the water, wastewater and energy sectors. The U.S. utility space is made up of thousands of independent, often under-resourced local systems, both public and private, making it difficult to enforce uniform cybersecurity defenses across the board. For organizations operating in or alongside critical infrastructure, this is a pressing reminder that investing in robust cybersecurity measures, including regular vulnerability assessments, network monitoring and access controls, is critical.

North America

RubyGems

Industry: TechnologyExploit: Hacking

Security researchers say that AI agents being tested by OpenAI attacked software service RubyGems two months before they autonomously hacked open-source platform Hugging Face.

The cybersecurity industry was already grappling with the revelation that OpenAI's autonomous test models had escaped a sandboxed evaluation environment and independently targeted Hugging Face in a multi-stage cyber intrusion, widely regarded as one of the first publicly disclosed examples of an AI system autonomously compromising a real external system. Reports now suggest that two months prior, the same AI agents, typically tasked with routine assignments such as creating reports or filling out spreadsheets, appear to have used RubyGems to access publicly available data as part of a training run.

The latest revelation comes at a time of growing calls for tighter regulation of AI models and the environments in which they are tested and deployed.

Source

How it could affect your business

Incidents where AI agents autonomously attempt to access or compromise external systems have heightened concerns over the growing capabilities of AI models and whether developers can reliably contain them. When systems designed for routine tasks can independently pivot to targeting external platforms, the implications for businesses deploying or interacting with AI tools are significant. Clear regulatory frameworks governing how AI models are tested, sandboxed and monitored are becoming increasingly urgent, and businesses would do well to stay ahead of evolving compliance requirements as regulators begin to catch up with the technology.

North America

Microsoft

Industry: TechnologyExploit: Zero-day vulnerability

On September 8, Microsoft patched a record 974 vulnerabilities across its products, including two zero-day flaws that were already being actively exploited in the wild.

The first exploited zero-day, CVE-2026-85880, is a heap buffer overflow issue in the Windows Advanced Local Procedure Call (ALPC) that could allow a local attacker to gain system privileges. The second, CVE-2026-81963, is an improper link resolution defect in the Windows Update Stack that similarly allows local attackers to elevate their privileges to the system level. Microsoft rolled out patches for 723 flaws in Windows and fixed 222 security bugs in its Office suite, including 111 in Office 2016.

Additional security issues were addressed across SQL (62 fixes), Developer Tools (22), SharePoint Server (16), Azure (12), Skype for Business (10) and Exchange Server (9).

Source

How it could affect your business

The window between a patch being released and attackers targeting unpatched systems can be extremely narrow. Businesses that rely on manual patching processes risk falling behind, leaving known vulnerabilities open far longer than necessary. Proactive and automated patch management ensures that critical updates are applied quickly and consistently across all systems, reducing the time attackers have to take advantage of newly disclosed flaws.

United States

Florida Department of Highway Safety

Industry: Government & Public SectorExploit: Hacking

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) announced it is investigating a data breach carried out by what it describes as an international cybercriminal organization.

In a statement posted on September 11, the FLHSMV said the breach was quickly mitigated and that no further breach is ongoing, though the department has not disclosed what data may have been accessed or stolen. The FLHSMV has notified the Office of the Attorney General and is working alongside the Florida Digital Service and the Florida Department of Law Enforcement in its response. A criminal investigation is ongoing, with further details to be released once it concludes.

The ShinyHunters ransomware group has reportedly claimed responsibility for the attack, giving the department a deadline of September 11 to negotiate a fee in exchange for not releasing the stolen files.

Source

How it could affect your business

Breaches like this give attackers access to highly personal identifying information, the kind that makes social engineering and spear phishing attacks far more convincing and harder to detect. When attackers know your name, address and license details, crafting a message that appears legitimate becomes considerably easier. Businesses and individuals should scrutinize unexpected communications carefully, verify requests through official channels and never share sensitive information in response to unsolicited contact, however credible it may appear.

Like what you're reading?

Subscribe now to get security news and information in your inbox every week

Upcoming Webinars

Join other IT professionals to connect, learn and level up. Get insights into the latest cybersecurity trends and technologies.

Van ticket tot oplossing: AI-gedreven servicedesk met Autotask

Van ticket tot oplossing: AI-gedreven servicedesk met Autotask

View event
Kaseya Connect Local ∷ Chicago

Kaseya Connect Local ∷ Chicago

View event
Unified RMM Quarterly Product Innovation Update

Unified RMM Quarterly Product Innovation Update

View event