Tag: Data breach

  • Crypto Casinos Face Doxxing Risk After Curaçao Regulator Hacked

    Crypto Casinos Face Doxxing Risk After Curaçao Regulator Hacked

    Key Highlights

    • Curaçao Gaming Authority (CGA) confirmed a cyberattack on its online gaming portal on September 17, with investigation ongoing into the scope of data accessed
    • Crypto casino operators licensed by CGA — including major brands like Stake and 1xBet — face potential exposure of sensitive KYC documents, corporate records, and beneficial ownership details
    • Curaçao’s regulatory framework has historically relied on minimal due diligence, though new anti-money laundering legislation was introduced this year to address reputation concerns

    Regulator Confirms Breach, Scope Unclear

    The Curaçao Gaming Authority (CGA) disclosed on September 17 that hackers had gained unauthorized access to its online gaming portal, the central system used for license applications, renewals, and ongoing compliance filings. In a public statement, the regulator acknowledged the intrusion but stopped short of detailing what specific datasets were compromised. “While the unauthorized access has been contained, the investigation remains ongoing and has not yet established the full scope of the incident,” the CGA said. “The CGA is currently assessing whether and which information was accessed, as well as the potential consequences arising from such access,” the regulator added. The authority pledged to directly notify any affected individuals, applicants, licensees, or other stakeholders should the investigation confirm material impact.

    Industry Speculation Centers on Operator Data Exposure

    The announcement triggered immediate speculation across industry forums and social media, where participants highlighted the sensitive nature of data routinely submitted to the CGA. On X, user @smokeylisa posted: “CGA investigates unauthorized access to its online gaming portal” Well that’s not good…Are we about to see the KYC of UBOs leaked for various CGA licensed casinos? pic.twitter.com/Lq0PZcobm5 The concern centers on Know Your Customer (KYC) dossiers for Ultimate Beneficial Owners (UBOs), which typically include government-issued photo identification, proof of address, corporate structure documents, and source-of-funds declarations. If exfiltrated, such information could enable identity theft, targeted phishing, or extortion campaigns against operators and their principals.

    Curaçao’s Regulatory History Under Scrutiny

    Curaçao has long served as a primary licensing jurisdiction for crypto-native casinos, attracting operators such as Stake, 1xBet, and — until its license was apparently revoked this month — Rollbit. The island’s appeal has rested on a streamlined, low-friction licensing process that critics argue prioritized volume over rigorous vetting. While the CGA has historically conducted only minimal background checks on applicants, the jurisdiction moved this year to introduce new legislation mandating transparent anti-money laundering (AML) procedures and strengthened identity verification requirements. The breach now raises questions about whether those reforms included commensurate investments in cybersecurity infrastructure commensurate with the sensitivity of the data collected.

    Why This Matters

    The CGA hack underscores a systemic vulnerability in offshore gambling regulation: regulators themselves become high-value targets because they aggregate the most sensitive personal and corporate data of every licensee they oversee. For the crypto casino sector — already navigating banking restrictions, advertising bans, and evolving global compliance standards — a mass doxxing of beneficial owners would represent a catastrophic operational and reputational blow. The incident also tests Curaçao’s credibility as it attempts to shed its reputation as a lax jurisdiction. Stakeholders will be watching closely for the CGA’s forensic findings, the timeline and completeness of breach notifications, and whether the regulator’s post-breach response aligns with the stricter AML and data-protection standards its new legislation promises.

    Frequently Asked Questions

    What data might have been exposed in the CGA breach?

    The CGA has not confirmed the specific datasets accessed. However, the portal processes license applications and compliance filings that typically contain KYC documents for beneficial owners (passports, proof of address), corporate registration records, source-of-funds evidence, and ongoing transaction monitoring reports.

    Which crypto casinos are licensed by Curaçao?

    Major operators historically licensed by the CGA include Stake, 1xBet, and formerly Rollbit — whose Curaçao license appears to have been revoked in September 2026. Dozens of smaller crypto casinos also hold Curaçao sub-licenses or master licenses.

    What should affected operators do now?

    Operators should monitor official CGA communications for breach notifications, engage independent cybersecurity firms to assess their own exposure, and prepare incident response plans for potential doxxing or extortion attempts targeting their principals. They should also verify whether their submitted KYC packages contain reusable credentials that should be rotated.

  • Revolut Hackers Demand 6,000 XMR as Italy Opens Data Probe

    Revolut Hackers Demand 6,000 XMR as Italy Opens Data Probe

    Key Highlights

    • Italian prosecutors and anti-mafia authorities have launched an investigation after hackers allegedly compromised an Italian government email account to steal sensitive data from at least 680 Revolut customers.
    • The group “iamnotavillain” demanded 6,000 Monero (XMR), valued at approximately $3 million, threatening to sell passports, driving licenses, identity photos, and transaction histories if the ransom was not paid by a September 16 deadline.
    • Revolut confirmed no internal systems or client funds were breached, stated it had not formally received a ransom demand, and is cooperating with regulators and law enforcement while offering support to affected customers.

    Italian Authorities Investigate Government Email Compromise Linked to Revolut Data Theft

    Italian prosecutors have opened a formal investigation following allegations that cybercriminals infiltrated a government email system to obtain confidential information on hundreds of Revolut customers. According to reports from the Financial Times and Euronews, the breach enabled attackers to pose as law enforcement officials and extract sensitive personal data, including passports, driving licenses, identity photographs, and detailed transaction histories. At least 680 customer accounts are confirmed to have been compromised in the operation.

    Ransom Demand and the Role of Monero

    The threat actor, identifying as “iamnotavillain,” published a ransom demand on September 16 accompanied by a 24-hour countdown timer. The group demanded payment of 6,000 Monero (XMR), worth roughly $3 million at the time, and threatened to auction the stolen records to other criminals if the deadline passed without payment. “They said that they identified customers with a lot of crypto holdings by doing blockchain analysis.” The attackers further claimed “They said they got the records after they compromised an Italian government email system and acted as if they were law enforcement officials.” As of the latest updates, it remains unclear whether Revolut paid the ransom or if the data has been sold on underground markets.

    Revolut Denies System Breach, Confirms Customer Support Measures

    Revolut has maintained that its own infrastructure and client funds remain secure. “Revolut responded by stating they had not formally heard back from the group nor received any ransom demands.” The company added, “They confirmed that none of its internal nor client funds had been affected nor breached.” In a further statement, Revolut emphasized its cooperation with authorities: “Revolut has said that they have been working closely with other regulators and law enforcement bodies, and have also offered to help and support any of its affected customers.” The neobank has not disclosed the specific number of impacted users beyond the 680 figure cited in media reports.

    Anti-Mafia and Counterterrorism Units Join the Probe

    The investigation has escalated beyond standard cybercrime channels. Italian prosecutors are now working alongside the country’s anti-mafia and counterterrorism authorities, signaling the potential involvement of organized crime networks or the severity of the government email compromise. The participation of these specialized units underscores the gravity with which Rome is treating the infiltration of state communications infrastructure for financial fraud.

    Why This Matters

    This incident highlights a growing threat vector in which criminals target trusted government communication channels to legitimize social engineering attacks against financial institutions and their customers. By compromising an official email account, the attackers bypassed traditional verification protocols, exploiting the inherent trust placed in law enforcement correspondence. The use of Monero as the ransom currency reflects a broader trend in ransomware operations: threat actors increasingly favor privacy-preserving cryptocurrencies to obscure transaction trails. While Monero’s protocol was not breached—its privacy features functioned as designed—the case illustrates how legitimate privacy tools can be co-opted for illicit finance. For Revolut and the broader fintech sector, the episode underscores the need for robust verification mechanisms that do not rely solely on email domain authenticity, as well as proactive customer notification frameworks when third-party data exposures occur.

    Frequently Asked Questions

    How did the attackers access Revolut customer data?

    The group allegedly compromised an Italian government email account and impersonated law enforcement officials to obtain sensitive customer records, including identity documents and transaction histories, from Revolut.

    Was Revolut’s own platform hacked?

    No. Revolut confirmed that its internal systems and client funds were not breached. The data was obtained through a compromised government email account, not through a direct intrusion into Revolut’s infrastructure.

    Why did the hackers demand payment in Monero (XMR)?

    Monero’s protocol obscures transaction amounts, sender addresses, and recipient addresses by default, making it significantly harder for law enforcement to trace ransom payments compared to transparent blockchains like Bitcoin.

  • Financial Times: Revolut Hackers Lower Ransom to $3M, Set 24-Hour Deadline

    Financial Times: Revolut Hackers Lower Ransom to $3M, Set 24-Hour Deadline

    Revolut Data Breach: Hackers Demand $3 Million in Monero, Threaten to Sell 680 Customer Records

    A cybercrime group styling itself “iamnotavillain” has escalated its extortion campaign against British fintech firm Revolut, demanding 6,000 Monero (XMR) tokens—valued at approximately $3 million as of September 16, 2026—in exchange for not selling confidential data belonging to roughly 680 customers. The attackers published a 24-hour countdown timer on an external website Wednesday, setting a deadline of Thursday, September 17, 2026, according to a Financial Times investigation.

    Ransom Demand and Cryptocurrency Choice

    The ransom note specifies payment in Monero, a privacy-focused cryptocurrency selected for its anonymity and cryptographic protocols that obscure transaction trails. A 60-second screen recording provided to the Financial Times reportedly displayed compromised documents including passports, driver’s licenses, and complete banking records.

    Revolut has stated officially that it has not received any direct demand from the extortionists. A company spokesperson confirmed that core infrastructure and primary databases suffered no unauthorized access, suggesting the breach may be limited to a specific compliance-related dataset.

    Breach Vector: Government Domain Impersonation

    The security incident originated from a fraudulent information request sent from a legitimate government domain. Compliance staff processed the request before identifying the identity spoofing, allowing the attackers to extract sensitive customer information. Revolut has since blocked the compromised domain and formally alerted law enforcement authorities.

    Scope of Compromised Data

    Official company disclosures indicate the leaked dataset includes:

    • Full names, residential addresses, and phone numbers
    • Identity verification photographs
    • IBAN numbers and account opening dates
    • Account statements referencing Bitcoin transfers

    The attackers told the Financial Times they used on-chain analytics to specifically target customers with significant digital asset holdings. Prior reporting by on-chain investigator ZachXBT suggests the affected accounts correspond to high-net-worth profiles, indicating a highly targeted operation rather than a broad data dump.

    Regulatory Response and Timeline

    The UK Information Commissioner’s Office (ICO) maintains an open formal investigation into the matter. UK and European Union regulators have scheduled supervisory hearings on the incident toward the end of the third quarter of 2026, signaling heightened regulatory scrutiny of fintech data protection practices.

    The extortionists’ ultimatum expires Thursday, September 17, 2026. Whether Revolut engages with the demand or relies on law enforcement intervention remains unresolved as the countdown continues.

  • CenterPoint Energy Confirms Customer Personal Information Compromised in Data Breach

    CenterPoint Energy Confirms Customer Personal Information Compromised in Data Breach

    CenterPoint Energy has disclosed a data breach affecting customer personal information, according to a securities filing made Monday. The utility company revealed that an unauthorized third party accessed customer data through one of its external-facing systems.

    Breach Discovered Through Online Post

    The company first became aware of the incident in September 2026 after discovering an online post by a third party claiming to have obtained a dataset containing customer information. Following an investigation, CenterPoint confirmed the claim was valid.

    Company Response and Investigation

    Upon learning of the breach, CenterPoint said it took immediate action, activating its cybersecurity incident response protocols and launching an investigation with assistance from third-party cybersecurity experts. The company also implemented additional measures to protect its systems.

    Electric and gas service delivery remains operational and undisrupted, according to the filing. The investigation is ongoing as the company works to determine the full scope of affected customers and the specific personal information compromised.

    Financial Impact and Insurance

    CenterPoint stated it does not believe the breach will have a material impact on its financial condition or results of operations. The company maintains cybersecurity insurance coverage that it believes will offset related costs, though it expects to continue incurring expenses associated with the incident response.

    Notification and Regulatory Compliance

    The company has reported the matter to law enforcement authorities and notified certain regulatory agencies. CenterPoint intends to notify affected customers and regulatory authorities as required by applicable law.

    Local Impact Unclear

    When asked whether Evansville-area customers were among those impacted, a company spokesperson provided a formal statement: “Our filing speaks for itself.”

    The full SEC filing is available for public review.

  • Swiss Bitcoin Pay Shuts Down Servers After Security Breach Exposes User Data

    Swiss Bitcoin Pay Shuts Down Servers After Security Breach Exposes User Data

    Swiss Bitcoin Pay Takes Servers Offline After Security Breach Exposes User Data

    Swiss Bitcoin Pay, a cryptocurrency payment processing provider, took all its servers offline on Monday following a security incident that raised concerns about unauthorized access to internal systems. The company announced the breach via its official X account, stating that email addresses, Bitcoin addresses, bank IBANs, transaction histories, and hashed user passwords may have been exposed.

    Company Response and Investigation Underway

    Despite the exposure of sensitive customer data, Swiss Bitcoin Pay assured users that no funds were at risk as a result of the incident. The company emphasized that it had not yet determined the full scope of the breach and disabled its servers as a precautionary measure while the investigation continues.

    As of publication, the firm has not disclosed how many customers were affected, the method used by the attacker to gain access, or whether any files were extracted or only viewed. No projected timeline for restoring services has been provided.

    Non-Custodial Design Limits Financial Exposure

    Swiss Bitcoin Pay highlighted that its non-custodial architecture prevents attackers from accessing customer funds directly, as payments flow from customer to merchant and remain isolated from internal systems. However, in a follow-up message on X, the company acknowledged it temporarily holds small user balances during routine operations.

    This temporary custody typically occurs when Lightning Network payments are aggregated into batch transactions for settlement via a single on-chain movement, executed daily, weekly, or monthly. The Lightning Network, a layer-2 protocol built on Bitcoin, enables fast and low-cost transactions by processing off-chain payment channels and settling only aggregate transactions on the main blockchain.

    Swiss Bitcoin Pay clarified that although this operational feature results in brief storage of customer assets, no unauthorized Bitcoin transactions have been identified in connection with the breach.

    Security Experts Warn of Phishing Risks

    Digital security experts have cautioned that the combination of stolen email addresses, Bitcoin addresses, bank IBANs, transaction histories, and hashed passwords poses a significant risk of targeted phishing attacks.

    Security analyst Pasquale Pillitteri described the exposed data as “textbook material for a tailored phishing attack” when these identifiers are combined.

    Another concern arises from the potential to link Bitcoin addresses to real-world identities, which could compromise user privacy and enable tracing of on-chain transaction histories.

    Context of Recent Industry Breaches

    The incident follows a series of high-profile data breaches in the digital asset sector that have heightened concerns about user data security. Blockstream’s Liquid Network was recently impacted by an exploit resulting in nearly 4,000 BTC being stolen. In a separate case, Japan’s Digital Agency reported a leak of 246,000 staff and contractor records, including names, email addresses, and phone numbers.

    Hardware wallet manufacturer Trezor also suffered a data breach exposing customer purchase and shipping information, while a flaw in a SafePal order-tracking plugin impacted nearly 40,000 users. Swiss Bitcoin Pay has not attributed its incident to any known vulnerability or similar exploit used in these earlier cases.

  • Swiss Bitcoin Pay Shuts Down Servers After Data Breach

    Swiss Bitcoin Pay Shuts Down Servers After Data Breach

    Swiss Bitcoin Pay Takes Servers Offline Following Data Breach

    Swiss Bitcoin Pay, a non-custodial bitcoin payment processor based in Neuchâtel, Switzerland, announced Monday that it had temporarily shut down its servers after detecting a data breach. The company stated that user funds remain secure, though customer email addresses, bitcoin addresses, IBANs, transaction histories, and hashed passwords are believed to have been compromised.

    Breach Details and Company Response

    According to a statement posted on X (formerly Twitter), the company confirmed that a malicious actor likely gained access to its internal systems. The full statement reads:

    “A malicious user has likely gained access to Swiss Bitcoin Pay’s internal systems. As a precaution, we are temporarily shutting down our servers while we investigate and secure our infrastructure.At this stage, we believe they may have accessed customer email addresses, Bitcoin…”

    In a follow-up announcement, Swiss Bitcoin Pay reiterated the situation and sought to reassure users:

    “A malicious user has likely gained access to Swiss Bitcoin Pay’s internal systems …As a precaution, we are temporarily shutting down our servers while we investigate and secure our infrastructure.” Swiss Bitcoin Pay said on Monday.

    “User funds are safe, and any amounts owed to users will be fully returned.”

    The company did not immediately respond to Bitcoin Magazine’s request for additional comment. Swiss Bitcoin Pay enables businesses to accept bitcoin payments using both on-chain transactions and the Lightning Network.

    Part of a Broader Trend in 2026

    The incident adds to a growing list of data breaches affecting bitcoin and fintech firms this year. Last week, Revolut confirmed it had provided customer passports, driver’s licenses, verification selfies, and transaction histories to an unauthorized party that sent fraudulent requests from a legitimate government agency’s email domain.

    Also last week, hardware wallet manufacturer Trezor warned customers that a data breach at a third-party marketing platform used for newsletter distribution had exposed user data, leading to targeted phishing attacks.

    Earlier in 2026, criminals obtained customer information through Ledger’s payment processor, Global-e, to conduct phishing campaigns. In August, crypto wallet provider SafePal disclosed a breach involving unauthorized access to approximately 39,798 customers’ order information, including names, addresses, and purchase data.

  • Revolut Attackers Threaten Daily Customer Data Leaks

    Revolut Attackers Threaten Daily Customer Data Leaks

    Threat actors who obtained sensitive Revolut customer information appear to have begun posting the data online and are threatening to release more information daily until the fintech company pays.

    High-Profile Individuals Among Leaked Data

    The newly leaked information reportedly includes selfies and copies of identity documents belonging to tennis player Alexander Shevchenko and Gamdom CEO Felix Römer, according to an X post from International Cyber Digest on Sunday.

    Attackers Issue Daily Release Threat

    “We’re going to start releasing more and more data everyday until revolut pays for leaking their customers,” the attackers reportedly said on Telegram. Cointelegraph reached out to Revolut and Römer for comment.

    Identity Theft Risks Escalate

    The exposed identity documents and facial-verification images could increase the risk of identity theft. Revolut on Friday told customers the leaked data also includes customers’ full name, date of birth, occupation, contact information, account statements and full transaction history, including records of Bitcoin transactions.

    Breach Origin: Government Email Impersonation

    Revolut told Cointelegraph on Saturday that the customer data was leaked due to a “sophisticated external impersonation scam” in which the attacker used an email address from a legitimate government agency domain email to submit fraudulent requests for information.

    Revolut later told Cointelegraph the breach affected a “⁠limited number” of customers, and its systems and customer funds are unaffected.

    Related: Revolut says customer data exposed through fake government email

  • Revolut Disclosed Customer Bitcoin Records Following Unauthorized Government Request, Report Says

    Revolut Disclosed Customer Bitcoin Records Following Unauthorized Government Request, Report Says

    A number of Revolut customers have reported receiving notifications that their personal and financial data — including Bitcoin transaction histories — was disclosed in response to a government request now believed to be fraudulent.

    Fraudulent Request Used Legitimate-Looking Credentials

    According to an email shared by onchain investigator ZachXBT, the request originated from an unauthorized email account that nevertheless used a government agency’s official domain and carried valid domain authentication credentials. The convincing appearance of the request may have led Revolut to process it without detecting the deception.

    Scope of Exposed Data

    The disclosed information is extensive. Personal details include customers’ full names, dates of birth, occupations, postal addresses, email addresses, and telephone numbers. Identity and verification records — such as passport or driver’s license copies and verification selfies — were also released.

    On the financial side, the data covers account statements, IBANs, withdrawal records, and full transaction histories, including Bitcoin activity. The email specified that biometric facial telemetry data was not shared.

    Experts Warn of Targeted Attack on High-Net-Worth Users

    Security experts suggest Revolut may have failed to recognize the fraudulent nature of the request before releasing customer information. “While the incident is likely limited in size it seems to have been targeted at high net worth users,” ZachXBT said.

    Revolut has not yet commented publicly on the reported data exposure.

  • 4.1 Million Affected in AdaptHealth Data Breach

    4.1 Million Affected in AdaptHealth Data Breach

    More than 4.1 million individuals had their personal, health, and insurance information stolen in a data breach at AdaptHealth, a healthcare company operating over 680 facilities across the United States. The network of medical equipment providers confirmed the incident after a threat actor gained access to its cloud-based applications in early June.

    How the AdaptHealth Breach Occurred

    According to the company, the attacker compromised a user session at a third-party contractor through social engineering. This provided access to internal systems used for patient management and document storage, including a password file associated with insurance billing.

    On August 14, AdaptHealth announced that the threat actor had exfiltrated names, contact and demographic details, as well as health and health insurance information. The company stated that Social Security numbers and financial information were not affected.

    At the time of disclosure, AdaptHealth notified the U.S. Department of Health and Human Services (HHS) that 4,115,802 individuals were impacted. HHS has since added the company to its official data breach portal.

    Baylor Genetics Breach Exposes 2.8 Million Records

    Another major healthcare breach reported to HHS on the same date, August 14, involves clinical genomics company Baylor Genetics. Like AdaptHealth, the Baylor Genetics intrusion occurred in June.

    Hackers stole patients’ names, dates of birth, medical test data, health insurance information, and Social Security numbers. The personally identifiable information (PII) of Baylor Genetics employees was also compromised, along with their financial data.

    Baylor Genetics reported to HHS that the electronic protected health information of 2,810,878 individuals was stolen in the incident.

    Growing Wave of Healthcare Data Breaches

    These incidents add to a mounting list of significant healthcare data breaches in recent months. Other notable cases include:

    • Manchester Airports Group: Data on 8.8 million people leaked after a ransom refusal.
    • Dark Web Listing: 153 million driver license images offered for sale.
    • Nutex Health: Ransomware gang claims responsibility for a data breach.
    • Aesto Health: 9.5 million individuals impacted by a data breach.

    The consecutive reporting of the AdaptHealth and Baylor Genetics breaches underscores the persistent vulnerability of healthcare organizations to cyberattacks targeting sensitive patient data.