Weekly Cyber Briefing 18.09.2026

Weekly Cyber Update: 18 September 2026

Revolut’s data breach; hackers target shipping; new Russian and Iranian campaigns; and CISA changes its vulnerability notifications.

The Cyber Threat Intelligence Briefing is a weekly round-up of the latest cybersecurity news, trends and indicators, curated by our CISO, Nick Harris. Here’s our pick of the top stories, and why you should care.


Revolut breached via fake government email

Probably the biggest news of the week, Revolut confirmed it handed sensitive customer records to an unauthorised third party after being deceived by fraudulent requests sent from a legitimate government agency’s email domain.

What was stolen?

The bank says its systems and customer funds were unaffected. Unverified reporting puts the data loss at approximately 680 customers, including full names, dates of birth, occupations, postal and email addresses, and phone numbers. Identity documents submitted at onboarding, such as passport or driving licence, were included, along with the verification selfies customers submitted through the app. Financial records included IBANs, account statements, withdrawal records, wallet reference numbers, and full transaction histories including Bitcoin activity. Passwords, login credentials, and one-time passcodes were not part of the dataset.

The threat actor (IAmNotAVillain) is threatening to release further data daily until Revolut pays a $3m ransom.

How did it happen?

The attacker appears to have specifically targeted Revolut Bank UAB, Revolut’s Lithuanian-regulated entity, because it is legally obligated to respond to European Investigation Orders. This is a formal cross-border judicial mechanism that requires regulated firms to disclose customer data to law enforcement on request. By submitting fraudulent European Investigation Orders from a genuine government domain that passed authentication checks, the attacker caused Revolut to hand over complete customer dossiers.

Individual(s) claiming responsibility in multiple Telegram groups have been identified under the handle IAmNotAVillain. Investigators at Duel and Hudson Rock have identified that the attacker accessed compromised Italian Ministry of the Interior email accounts (pec.interno.it addresses) using infostealer logs. They claim to have maintained persistent access to multiple Italian law enforcement systems for approximately six months and used those trusted systems to submit fraudulent data requests to Revolut. In this time, they added a recovery email address, monitored inboxes continuously, and deleted outgoing and incoming messages to avoid detection by the legitimate account owners.

DarkWeb Informer has separately flagged that the threat actor appears to be operating from a domain registered under GoDaddy. Posts on Telegram include snippets of data appearing to belong to high-profile individuals, including CEOs, sports professionals, and performing artists. The multiple countries involved mean that both the ICO and the Lithuanian supervisory authority are likely to be investigating.

This attack type is not new. The FBI warned in November 2024 that compromised government email accounts were being actively sold and used for fraudulent emergency data requests. Brian Krebs documented the same abuse mechanism in 2022 when Apple, Meta, Discord, and Snap were targeted with forged requests.


Hackers in the shipping lane

We don’t often see a shipping hack. It’s now known that two foreign-flagged commercial oil and gas tankers bound for the US were boarded by a joint FBI and US Coast Guard team on 21 and 24 August after indications their onboard networks had been compromised by foreign cyber actors.

One of the vessels, identified by Bloomberg as the VL Prosperity, has capacity for about 2.3 million barrels of crude. Having left Egypt on 1 August, it was first compromised in the Strait of Gibraltar on 7 August and lost communications for over 30 hours. The tanker continued its transit before being boarded in the Gulf of Mexico. The second vessel, which carried liquefied natural gas, has not been publicly identified. The joint FBI and Coast Guard statement confirmed the vessels’ networks were compromised but did not attribute the attacks to a specific threat actor.

Authorities are investigating whether Iran, or a group seeking to exploit the deteriorating relationship between Iran and the US, was responsible. Iranian state media amplified the story in the weeks following the attacks, which is a pattern security analysts note tends to accompany operations where Tehran wants to signal capability without formal acknowledgement. No formal attribution has been made at the time of writing.

We don’t yet know how this happened but we do know that maritime OT environments are notoriously difficult to secure. Legacy systems, satellite communications dependencies, mixed IT and OT architectures, and crews without dedicated cybersecurity training create a large attack surface. A tanker that cannot communicate is a navigation risk, a safety risk, and potentially an environmental one.


New Russian and Iranian campaigns

Two separate waves of state-sponsored cyber activity were revealed this week, featuring both Iranian and Russian actors.

Iran’s Chosen Brick

UK intelligence issued a warning this week of new Iranian cyber tactics targeting dissidents, activists, journalists, and political figures worldwide. Government advisories from multiple partner nations have highlighted the deployment of a new Windows malware framework dubbed Chosen Brick, designed to establish persistent access for espionage purposes.

Chosen Brick is not ransomware and does not appear financially motivated. Its targeting profile – including political opposition figures, media organisations and civil society groups – is consistent with the Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC) and similar Iranian intelligence-adjacent units that have historically sought to monitor perceived threats to the regime, particularly within diaspora communities.

Russia: APT28 and APT44

Cisco Talos, Sophos, and Recorded Future all publishing reports on continued GRU-linked offensive operations targeting European government, defence, and diplomatic networks.

Recorded Future’s research, tracking APT28 under the designation Blue Delta, identifies a campaign running between September 2025 and April 2026 targeting government, diplomatic, and defence entities across European countries including Romania and Spain. The delivery mechanism was straightforward: macro-enabled Word documents sent via phishing emails using diplomatically themed lures. The payload, however, is a new tool.

HookEdge appears to be a successor to APT28’s previously observed HeadLace malware. It is a lightweight batch script backdoor that establishes persistence via a scheduled task. It abuses Microsoft Edge browser and webhook.site infrastructure for command and control, payload staging, and data exfiltration. The use of webhook.site is deliberate: it is a usually benign developer tool, meaning HookEdge traffic blends with legitimate traffic and is harder to detect on network monitoring.

In separate but related reporting, Cisco Talos and Sophos have both documented a new variant of Cyclops Blink targeting Cisco Secure Firewall Management Centre appliances. The activity is being tracked under the cluster UAT-11823 and involves reverse shells, harvested device configurations, and an installed ELF implant assessed to be a new Cyclops Blink variant. That implant provides persistence, credential harvesting, network reconnaissance, packet sniffing, file transfer, and arbitrary command execution.

Attribution to APT44 at this stage is assessed linkage rather than definitively confirmed. Sophos and Cisco both express a similar hypothesis, but formal attribution has not been established. Worth noting: the original Cyclops Blink variant was formally attributed to Russia in a joint advisory in February 2022 by NCSC, CISA, NSA, and FBI. The 2026 version moves away from WatchGuard-specific targeting to a more generic x86-64 Linux and SysV persistence model, potentially broadening the range of devices it can target.

Both sets of activity (HookEdge for intelligence collection from government and defence targets, Cyclops Blink for persistent access to network edge infrastructure) reflect the same underlying Russian strategic priority. That is, long-term, quiet presence inside European institutions for espionage and future leverage.

The practical takeaway here sits at the intersection of geopolitics and defence. Any organisation with government, defence, diplomatic, or critical national infrastructure exposure should be treating the HookEdge and Cyclops Blink disclosures as live threat intelligence. These reports confirm that both Iran and Russia are actively investing in stealthy, persistent implants designed to evade detection, which has direct implications for dwell time assumptions. A threat actor present for six months before detection, as the HookEdge campaign suggests, will have accessed and potentially exfiltrated significantly more than one present for six days.


CISA pulls the plug on weekly vulnerability bulletin

CISA announced this week that its vulnerability bulletin will stop going out on Monday 28 September, as part of a broader shift away from severity-based vulnerability management towards what it describes as a “modern, risk-based approach”.

The decision is rooted in a Binding Operational Directive published by CISA in June, which sets out how US federal civilian agencies should prioritise security updates based on real-world risk rather than treating all vulnerabilities and systems equally. The new framework leaves behind the static CVSS scores that have underpinned vulnerability prioritisation for two decades, to move to a framework which weighs evidence of:

  • Active exploitation
  • The degree of control an attacker gains by exploiting a given vulnerability
  • Whether exploitation can be automated

The move reflects two converging pressures.

First, the sheer volume problem: AI-assisted security research is generating patches addressing rapidly growing numbers of vulnerabilities with every release cycle. Microsoft alone broke its own Patch Tuesday record this month with 974 CVEs in a single drop. Meanwhile the National Vulnerability Database continues to face a significant processing backlog, and the broader CVE ecosystem is increasingly having to filter out bogus AI-generated vulnerability reports to identify genuine ones. A weekly email digest of new CVEs is becoming structurally unmanageable.

Second, and more substantively, the risk-based BOD makes the static CVSS-driven format look like the wrong tool for the job. A vulnerability with a CVSS score of 9.8 that is not being actively exploited in the wild is a different risk proposition from a CVSS 6.5 flaw that has been weaponised in ransomware campaigns. The bulletin made no such distinction.

CISA has not explained why it chose to scrap the bulletin rather than adapt it to reflect the new framework, but has stated its replacement stack is the Known Exploited Vulnerabilities (KEV) catalogue of: cybersecurity alerts, advisories feed, and the CVE catalogue itself. It’s likely that security teams have already made this shift, recognising that chasing CVSS scores with little context is a fruitless task.

It is worth noting that CISA itself is under ongoing institutional pressure from budget and staffing constraints, which may be a more prosaic factor in this decision than the agency’s official framing suggests.

Latest articles

Be an insider. Sign up now!