CrewCrew
FeedSignalsMy Subscriptions
Get Started
Digital Privacy & Data Rights

Digital Privacy & Data Rights — 2026-09-14

  1. Signals
  2. /
  3. Digital Privacy & Data Rights

Digital Privacy & Data Rights — 2026-09-14

Digital Privacy & Data Rights|September 14, 2026(2h ago)4 min read8.0AI quality score — automatically evaluated based on accuracy, depth, and source quality
0 subscribers

This week’s biggest privacy story is the confirmed Revolut data breach, where a scammer using a spoofed government email domain tricked the fintech into exposing sensitive customer data. This incident highlights the vulnerability of Know Your Customer (KYC) processes to social engineering. Additionally, regulatory bodies like the FTC and EDPB continue to refine enforcement priorities, with the FTC actively enforcing the Take It Down Act and the EDPB focusing on transparency compliance for 2026.

Digital Privacy & Data Rights — 2026-09-14


This Week's Top Story


Revolut Confirms Customer Data Breach Through Fake Government Requests

Revolut Logo
Revolut Logo

  • What happened: Fintech company Revolut confirmed that a scammer used a real government email domain to request and receive sensitive customer data. The scammer successfully obtained KYC (Know Your Customer) information, including passports, selfies, IBANs, and Bitcoin transaction histories. Revolut has notified affected customers and alerted relevant government agencies, law enforcement, and financial regulators.
  • Who's affected: Revolut customers whose identity verification data was compromised. The breach specifically exposed highly sensitive personal identifiers and financial history.
  • Why it matters: This incident demonstrates a sophisticated social engineering attack vector targeting corporate compliance teams. It underscores the risk that even regulated financial institutions face when employees are manipulated by spoofed official communications, potentially leading to identity theft or targeted financial fraud.
techcrunch.com

techcrunch.com


Data Breaches & Incidents

Source image
Source image

pkware.com

2026 Data Breaches: Cybersecurity Incidents


Revolut — Social Engineering / Insider Compromise

  • Scope: Passports, selfie IDs, IBANs, and Bitcoin transaction histories of unknown numbers of customers.
  • Root cause: A scammer utilized a real government email domain to impersonate official requests, leading to unauthorized data disclosure by Revolut staff.
  • User action: Affected users should monitor for identity theft attempts, consider freezing credit if available in their jurisdiction, and change passwords for linked financial accounts.

Trezor — Hardware Wallet Breach

  • Scope: Details of two separate breaches affecting Trezor hardware wallet users were highlighted in recent privacy roundups.
  • Root cause: Specific technical vectors were not detailed in the summary, but the incidents involved compromised security protocols.
  • User action: Users should verify their device firmware is up to date and review any suspicious transaction history.

Dark Web ID Marketplace — Mass ID Leak

  • Scope: Over 153 million driver’s license scans and millions of other identification documents were put up for sale on a new dark web platform.
  • Root cause: The FBI is investigating a possible breach linked to the source of these scans.
  • User action: Individuals should be vigilant against phishing attempts that use personal details found in these leaks and consider identity theft protection services.

Regulatory & Enforcement Actions


FTC vs. Noncompliant Platforms (Take It Down Act)

  • Ruling: The Federal Trade Commission has begun enforcement actions under the Take It Down Act (TIDA), which requires covered platforms to establish processes for victims to request removal of intimate photos or videos shared without consent.
  • Penalty: Specific fines for this week's actions are not detailed, but non-compliance can lead to significant civil penalties and mandated remediation.
  • Precedent: This marks a shift toward active enforcement of non-consensual intimate imagery laws, placing a direct burden on platforms to have robust, accessible takedown mechanisms.

EDPB Coordinated Enforcement Framework (Transparency)

  • Ruling: The European Data Protection Board (EDPB) has selected "transparency and information obligations" (Articles 12, 13, and 14 GDPR) as the topic for its fifth coordinated enforcement action.
  • Penalty: National Data Protection Authorities will conduct parallel investigations; penalties vary by member state but can reach up to 4% of global annual turnover.
  • Precedent: Organizations must ensure their privacy notices are clear, accessible, and meet GDPR transparency standards, as this coordinated effort will likely result in simultaneous fines across multiple EU countries.

Legislation & Policy Moves

  • Australia — Privacy Amendment (Personal Data Protection) Bill 2026: The Australian Attorney-General's Department published initial proposals for the second wave of Privacy Act reforms, outlining details for a more robust regulatory framework. — Status: Consultation package released — Effective date: TBD
  • US — SECURE Data Act: Introduced by House Energy and Commerce Republicans, this bill proposes a uniform federal standard to preempt the current patchwork of state privacy laws. — Status: Introduced (April 2026) — Effective date: TBD

Advocacy & Civil Society

No fresh advocacy campaigns from EFF, NOYB, or Privacy International with dates after 2026-09-12 were found in the provided research results.


Industry & Tech Response

No specific new platform changes, encryption updates, or product launches from major tech companies (Apple, Google, Meta, Signal) dated after 2026-09-12 were found in the provided research results.


Reader Action Items

  • Check if you're affected: If you are a Revolut customer, check your registered email for notifications from Revolut regarding the data breach. Monitor your bank statements and Bitcoin wallets for unauthorized activity.
  • Settings to review: Review your privacy settings on social media and financial apps to limit what personal information is publicly visible. Enable two-factor authentication (2FA) on all financial accounts.
  • Rights you can exercise: Under GDPR (for EU residents) or similar state laws, you have the right to access your data. Contact Revolut’s Data Protection Officer to request a copy of the data they hold on you to verify what was exposed.

What to Watch Next Week

  • EDPB Transparency Investigations: Watch for initial findings or warnings from national DPAs as they begin the coordinated enforcement action on transparency obligations.
  • FTC TIDA Enforcement: Monitor FTC announcements for specific companies being cited or fined under the Take It Down Act.
  • Australian Privacy Reforms: Track the consultation period for the Privacy Amendment Bill 2026 as industry groups submit feedback.

Crew Digital Privacy & Data Rights — curated weekly from EFF, regulators (EDPB/FTC/ICO), IAPP, and tech media.

This content was collected, curated, and summarized entirely by AI — including how and what to gather. It may contain inaccuracies. Crew does not guarantee the accuracy of any information presented here. Always verify facts on your own before acting on them. Crew assumes no legal liability for any consequences arising from reliance on this content.

Explore related topics
  • QHow did the scammer access a real government domain?
  • QWhat specific steps is Revolut taking to secure data?
  • QHow can Trezor users verify their device security?
  • QWhich platforms are targeted by the FTC's new act?

Powered by

CrewCrew

Sources

Want your own AI intelligence feed?

Create custom signals on any topic. AI curates and delivers 24/7.