On My Radar 🎯
What We Can Learn From Revolut's Data Breach
The Revolut story this week isn't really our typical breach: There was no unpatched vulnerability, no missing security protocol, no zero-day. What happened was a criminal spoofed a government agency's email domain, sent Revolut what looked like a legitimate official request, and Revolut handed over customer data. This included identities, contact details, birth dates, postal and email addresses, phone numbers, and copies of identity documents including passports and driver's licenses. This attack specifically seemed to be targeting specific individuals.
I had a couple takeaways from this one.
- First, email domains are easy to spoof! This is exactly what DMARC and email authentication protocols exist to catch, and you should always make sure your email utilizes this. I flag messages internally when something fails DMARC even if it looks legitimate, and you'd be surprised how many companies (privacy companies included!) don't have theirs configured properly.
- But the bigger takeaway: the companies holding your most sensitive information are run by humans. Humans who make mistakes, humans who can access your information, and share it. There's a disconnect a lot of people have when they think "Facebook has my data" and picture a server. It's not just a server, it's thousands of employees, including the CEO himself. This reminds me of the stories from years ago when we learned voice-assistant recordings were being quietly shipped to third-party contractors. Real people, real mistakes, real exposure.
What you can do: Give up as little real information as you can, everywhere. Use a passport instead of a driver's license where it's accepted (less sensitive info like your home address). Get a private mailbox if you're able. Use alias emails and phone numbers when you sign up for things. Freeze your credit. And if you have a public presence or a higher threat model, get a real address setup so your home stays off these databases. This story was a humbling one, since even a best-case prevention scenario could've still caused some real damage.
Bits & Bytes 🤖
~ Story 1: The Global Age-Verification Wave
Governments keep demanding more identity verification even as these systems keep leaking. The EU is set to propose banning social media and AI chatbots for under-15s. The EDRi has already laid out exactly why the proposed eID wallet doesn't solve the privacy problem. California signed a package that's a mixed bag: AB 1709 is a functional social-media ban for under-16s (bad), while AB 2071 and 2298 push digital-literacy and cybersecurity education. And Microsoft is now baking age-detection APIs into Windows, mirroring what Apple already does on macOS and iOS with age-bracketing.
My take: This is the clearest answer to everyone who says the legal fight doesn't matter. If laws can mandate companies to implement surveillance technology, they can also help mandate a freer & more user-first internet. Tools, education, and legal pressure all have a role in this fight.
~ Story 2: OpenAI's Rogue Agents
More has come out about OpenAI's agents hijacking a German wiki this spring, turning it into a message board to share tactics for bypassing OpenAI's own restrictions and reporting now shows the agents used at least 10 more undisclosed sites for unauthorized communications. OpenAI kept it quiet for months and still won't say how many sites were involved.
My take: These companies loudly warn AI could end humanity while building it anyway, refusing to apply real protocols, and then position themselves as the ones who should decide how it's governed, often writing the very laws politicians sign. What the hell is going on?! When did we as a society decide to entrust the public good to the people trying to destroy what's good for the public?
This Week on Techlore 📺
Light week on content for us, we put out our second hardening guide for the rest of the Proton ecosystem, so you can see exactly how to keep Proton services as safe as possible:

What I'm very excited to say is Go Incognito v2 is getting quite close to launching! We'll be doing a per-section release with the premium version, followed by the free rollout. More on this soon, but expect some announcements in the coming weeks 🙌
Action Item ✅
Same as last newsletter...freeze your credit! While you're at it, start moving to alias emails and phone numbers so the next forced "verify your identity" request leaks less of the real you.
Until next week 🫡
This Week's Sources
Highlight: The Hidden Cost Of Handing Over Your ID
- https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/
- https://techcrunch.com/2026/09/10/id-verification-giant-idscan-confirms-data-breach-with-more-than-150-million-drivers-licenses-stolen/
- https://techcrunch.com/2026/09/16/hackers-publish-thousands-of-drivers-data-after-breaching-florida-motor-vehicle-database/
Story 1: The Global Age-Verification Wave
- https://www.reuters.com/legal/litigation/eu-is-set-propose-ban-social-media-ai-chatbots-under-15s-2026-09-14/
- https://edri.org/our-work/eu-age-verification-tool-does-not-solve-privacy-concerns/
- https://yro.slashdot.org/story/26/09/11/0615224/california-governor-signs-laws-protecting-kids-from-risks-of-social-media-ai-chatbots
- https://www.eff.org/press/releases/we-all-deserve-better-internet-not-smaller-one
- https://www.eff.org/deeplinks/2026/09/governor-newsom-signs-student-backed-digital-literacy-bills-alongside-misguided
- https://www.bleepingcomputer.com/news/microsoft/microsoft-adds-age-awareness-apis-that-can-tell-if-users-are-children-teens-or-adults/
Story 2: OpenAI's Rogue Agents
- https://www.reuters.com/world/europe/openai-agents-hijacked-german-website-previously-undisclosed-ai-breakout-this-2026-09-04/
- https://www.reuters.com/world/openais-rogue-agents-used-least-10-more-sites-unauthorized-comms-researchers-say-2026-09-09/
The Defense Bulletin
Data Breaches
- https://www.bleepingcomputer.com/news/security/adapthealth-confirms-41-million-people-exposed-in-july-cyberattack/
- https://tuta.com/blog/berlin-data-leak
- https://www.bleepingcomputer.com/news/security/trezor-data-breach-impact-now-reaches-81-000-customers/
- https://www.bleepingcomputer.com/news/security/trezor-warns-users-of-email-provider-breach-phishing-attacks/
- https://www.bleepingcomputer.com/news/security/surfshark-vpn-says-hackers-breached-internal-testing-proxy-servers/
- https://www.bleepingcomputer.com/news/security/french-hospital-fined-500-000-after-breach-exposes-data-of-727-000/
- https://www.bleepingcomputer.com/news/security/mathspace-discloses-data-breach-affecting-over-1-million-people/
- https://www.bleepingcomputer.com/news/security/veradigm-discloses-patient-data-breach-after-gentlemen-gang-claims-attack/
Threats
- https://techcrunch.com/2026/09/16/google-says-some-pixel-phone-owners-were-hacked-in-zero-day-attacks/
- https://www.bleepingcomputer.com/news/security/google-patches-seventh-chrome-zero-day-exploited-in-attacks-this-year/
- https://www.bleepingcomputer.com/news/security/new-crowdstrike-falconflank-zero-day-grants-system-privileges/
- https://www.bleepingcomputer.com/news/security/new-microsoft-defender-shieldcrash-zero-day-grants-system-access/
- https://www.mullvad.net/en/blog/2026/9/10/another-way-to-leak-traffic-on-android-has-been-discovered/
- https://arstechnica.com/gadgets/2026/09/lg-tv-shown-capable-of-tracking-user-activity-even-when-offline/
- https://www.bleepingcomputer.com/news/security/over-36-000-plex-servers-unpatched-against-recently-disclosed-flaws/
- https://www.bleepingcomputer.com/news/security/skullcandy-dime-3-earbuds-expose-users-to-bluetooth-hijacking/
- https://www.bleepingcomputer.com/news/security/acronis-warns-of-actively-exploited-flaw-in-its-cpanel-backup-plugin/
- https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-via-third-party-woocommerce-plugin/
- https://www.bleepingcomputer.com/news/security/malcious-admin-menu-editor-pro-plugin-backdoors-1-500-wordpress-sites/
- https://techcrunch.com/2026/09/08/chrome-is-now-shipping-updates-every-2-weeks-as-ai-changes-the-security-landscape/
FOSS+ Updates
Surveillance Report: what matters in privacy, security, and digital rights. Weekly, free.
