Weekly Cybersecurity Digest [September, Week 2]
Posted on September 15, 2026
Dear Valued Clients,
Welcome to this week’s cybersecurity digest from Make Sense. Across Europe, recent developments show how cyber risk increasingly exploits trusted processes and infrastructure rather than relying only on obvious technical compromise.
Revolut disclosed sensitive customer information after fraudulent requests arrived through a legitimate government email domain, a German municipal utility faced an attack that encrypted its internal IT environment, and NATO allies revealed an operation involving threats to critical subsea communications infrastructure.
At the same time, threat research shows AI becoming more deeply integrated into state-linked cyber operations, while vulnerabilities in remote-access and trusted email infrastructure continue to create new attack paths. On the regulatory side, Cyber Resilience Act reporting obligations are now operational, as ENISA also begins testing advanced AI models from a cybersecurity perspective.
✅ Top Stories of the Week
i. Revolut Discloses Customer Data After Fraudulent Government Requests
British fintech company Revolut confirmed that sensitive customer information was disclosed to an unauthorised third party after fraudulent requests were sent from a legitimate government-agency email domain. Revolut said the breach affected a “very limited” number of customers and that its systems and customer funds were unaffected. Reuters reported that the exposed information included birth dates, postal and email addresses, phone numbers, and copies of identity documents, citing TechCrunch. The incident shows why even requests arriving through authentic official channels still require independent verification before sensitive information is released. [Read more via Reuters]
ii. Cyberattack Encrypts Systems at Bavarian Municipal Utility
Germany’s Stadtwerke Landsberg said attackers encrypted its central IT network, disrupting office systems and limiting staff availability by phone and email. Electricity, water and other essential services continued operating, while the utility disconnected affected systems and launched a forensic investigation. The incident demonstrates the value of separating operational infrastructure from corporate IT so that a compromise does not automatically interrupt essential services. [Read more via The Record]
iii. NATO Allies Reveal Foiled Russian Subsea Cable Sabotage Operation
New reporting revealed that Britain, Norway and the United States interceptehttps://therecord.media/cyberattack-bavaria-germany-utility?utm_source=chatgpt.comd a Russian operation near Svalbard involving technology designed to disable critical undersea cables. No cables were damaged, but officials said the exercise involved infrastructure carrying major volumes of satellite and internet data between Svalbard and mainland Norway. The episode reinforces the strategic importance of protecting subsea communications infrastructure as geopolitical and digital-security risks increasingly overlap. [Read more via Reuters]
✅ Industry Trends & Insights
AI Becomes More Integrated Into State-Linked Cyber Operations
Anthropic reported that a Russia-linked espionage group used Claude across several stages of operations targeting government, diplomatic, intelligence and defence organisations, particularly in Ukraine and Europe. AI was used to support phishing infrastructure, analyse stolen technology and repeatedly modify malware when security products detected it. The findings suggest that AI is increasingly reducing the time and effort required for sophisticated attackers to adapt their tooling and maintain operational tempo. [Read more via The Record]
Remote-Access Infrastructure Remains a High-Risk Attack Surface
The Netherlands’ National Cyber Security Centre warned organisations to urgently patch two critical Check Point VPN vulnerabilities, assessing both the likelihood of exploitation and potential impact as high. VPN and remote-access platforms remain attractive targets because successful compromise can provide attackers with direct access into internal environments. The warning reinforces the need to prioritise vulnerabilities based on exposure and threat intelligence rather than relying only on standard patching schedules. [Read more via BleepingComputer]
Brevo SSO Breach Sends Phishing Emails to Hundreds of Thousands of Crypto Users
Brevo, a French email/CRM provider, confirmed that an attacker exploited a SAML SSO flaw to access 138 customer accounts. Six were used to send phishing emails, and contacts were exported from 43. Trezor said roughly 347,000 subscribers received phishing emails, with about 2,500 users clicking the malicious link before it was disabled. Because the messages were sent through legitimate infrastructure, they passed normal email-authentication checks. [Read more via Brevo Status]
✅ Regulatory & Policy Updates
Cyber Resilience Act Reporting Obligations Become Operational
From September 11, manufacturers of products with digital elements placed on the EU market are required to report actively exploited vulnerabilities and severe security incidents under the Cyber Resilience Act. ENISA simultaneously launched its Single Reporting Platform, allowing manufacturers to submit notifications through one EU-wide mechanism, with early warnings required within 24 hours and fuller notifications within 72 hours. The change moves CRA incident reporting from future preparation into an active operational obligation. [Read more via ENISA]
ENISA Begins Testing Advanced AI Models for Cybersecurity
The EU Agency for Cybersecurity (ENISA) has been granted access to Anthropic’s Mythos 5 and OpenAI’s GPT-6-Astra models and has begun testing their capabilities. The development reflects the EU’s growing focus on understanding how advanced AI systems may affect cybersecurity, including both defensive use cases and emerging risks. For European organisations, it also signals that AI security evaluation is moving closer to formal institutional oversight rather than remaining solely with technology providers. [Read more via Reuters]
✅ Cyber IQ Challenge + Proactive Security Hacks
Quick Quiz: Your organisation receives an urgent request for sensitive customer information from what appears to be a legitimate government email address. What is the strongest response?
A) Provide the information because the email domain is authentic
B) Reply to the email asking the sender to confirm the request
C) Independently verify the requester, legal authority and request through an established official channel before releasing data
D) Forward the information to management and assume approval if nobody objects
(Answer below)
Smart Security Moves of the Week:
- Verify official data requests independently: Establish procedures for validating law-enforcement, regulator and government requests through known contacts or official channels before sensitive information is disclosed.
- Map critical communications dependencies: Identify business services that rely on subsea connectivity, telecom providers or other concentrated infrastructure and include outages in continuity scenarios.
- Separate IT and operational environments: Use segmentation and controlled access paths so compromises of corporate networks do not automatically affect essential operational services.
- Monitor AI-enabled threat evolution: Update detection and incident-response processes to account for attackers modifying malware, phishing infrastructure and tactics faster than traditional static indicators may capture.
- Prioritise exposed remote-access systems: Patch VPNs, gateways and other internet-facing infrastructure rapidly when national cybersecurity authorities identify a high likelihood of exploitation.
- Review CRA reporting workflows: Manufacturers in scope should ensure vulnerability, product, legal and incident-response teams know who triggers reporting and how the 24- and 72-hour timelines will be met.
Answer: C) Independently verify the requester, legal authority and request through an established official channel before releasing data.
An authentic email domain proves something about the communication channel, but it does not necessarily prove that the request itself is legitimate. The Revolut incident demonstrates why sensitive-data disclosure processes need their own verification controls.
✅ Conclusion
This week’s developments show how trusted systems and communication channels can themselves become part of the attack path. Legitimate government and email infrastructure was abused to make fraudulent activity appear authentic, while attacks against utilities and critical communications infrastructure reinforced the importance of resilience beyond traditional IT environments.
Attackers are also becoming more adaptive, using AI to support espionage operations and continuing to target remote-access technologies that provide direct routes into organisational networks.
European cyber policy is evolving alongside these threats. Cyber Resilience Act reporting obligations are now active, while ENISA’s testing of advanced AI models signals growing institutional focus on understanding both the opportunities and security risks of increasingly capable AI systems.
Final reflection: When something appears legitimate because it comes through a trusted domain, supplier, platform or infrastructure provider, what additional evidence does your organisation require before it acts?
At Make Sense, we help organisations translate cyber complexity into practical resilience across Europe’s evolving threat, technology, and regulatory landscape.
Stay secure,
The Make Sense SRL Team & CyberTania
