search
fintech security
Trends
- 1Another data breach hits Revolut, this time via DriveWealth▼Neues Datenleck bei Revolut Es ist noch keine zwei Wochen her, dass ich über ein Datenleck bei Revolut berichten musste.
A second data breach affecting Revolut within two weeks has been reported. The new incident reportedly occurred on 5 and 6 September 2026 but was only disclosed now, and it involved DriveWealth, a US financial firm linked to Revolut's stock trading service. Observers are questioning how quickly the company is handling customer data security.
- 2AI agents used to steal 600,000 credit card records●Security company Gambit says an attacker used three open-source # AI agents to breach 27 companies and steal more than 6
Security company Gambit reports that an attacker used three open-source AI agents to breach 27 companies and steal more than 600,000 credit card records. According to the firm, each automated scan cost roughly $25, making the operation cheap and highly scalable. The case is raising alarm about how easily accessible AI tools can be repurposed for large-scale cybercrime against financial targets.
- 3ECB launches Pontes platform for digital securities settlements▼ECB launches Pontes platform for settlements in digital securities — Cyprus Mail
The European Central Bank has launched Pontes, a new platform for settling transactions in digital securities. The move is part of the Eurosystem's broader work on blockchain and digital market infrastructure, aiming to let financial institutions settle digital asset trades using central bank money. The initiative is drawing attention across European banking and fintech circles as a step toward modernising euro-area settlement systems.
- 4Revolut Gains Argentina Banking Licence via Banco Cetelem Deal●Revolut Secures Argentina Banking License with Banco Cetelem Acquisition Approval
Revolut has secured approval to operate as a bank in Argentina, with regulators clearing its acquisition of Banco Cetelem, the local lender previously owned by BNP Paribas. The move gives the UK fintech a full banking licence in one of Latin America's largest markets, deepening its push into the region alongside rivals like Nubank. Analysts see it as a major step in Revolut's global expansion beyond its European base.
- 5Revolut reports another data breach affecting customers▼Another week, another data breach for Revolut customers
Revolut customers are facing another reported data breach, adding to a pattern of security incidents at the London-based fintech company. The news is drawing attention to how customer information is protected at major digital banks and renewing criticism of the firm's track record on data security. Commenters are questioning whether the company is doing enough to safeguard personal details and what steps affected customers should take.
- 6Fintech Startup Tundr Raises €11.6 Million Series A▼Fintech Startup Tundr Secures €11.6 Million Series A Funding
Fintech startup Tundr has secured €11.6 million in Series A funding. The round gives the company fresh capital to grow its financial technology business, though details on the investors, the startup's specific services, and its plans for the money have not been made clear in early coverage. It is one of the notable European fintech fundraising announcements circulating in startup circles.
- 7
SBI Holdings, the Japanese financial services group led by CEO Yoshitaka Kitao, is seeing a spike in search interest. No specific event has been confirmed behind the trend; the company is known for its securities business, banking operations and heavy involvement in crypto and fintech ventures, so attention may relate to any of these areas.
- 8Mercury CEO says bank charter is fintech's top priority▼Charter must be ‘top priority’ for fintechs pursuing it: Mercury exec The fintech has always wanted a charter, according
Mercury CEO Jon Auxier says obtaining a bank charter has long been a goal for the fintech and is now its top priority, telling industry publication Banking Dive that "now is the right moment to go after it" after years of groundwork. His comments signal growing ambition among fintechs to secure federal banking status, a move that would let them operate with fewer reliance on partner banks and greater regulatory standing.
- 9How to tie an AI agent's payment to an accepted offer●A supplier page can describe a product. It cannot approve a payment. Suppose an agent is asked to... # architecture # se
Engineers are debating how to design AI agents that handle payments safely. The core argument: a supplier's web page can only describe a product, never authorise a charge, so an agent asked to buy something must tie any payment strictly to an accepted, verified offer rather than trusting whatever a page claims. The discussion, tagged across security, fintech and software architecture circles, highlights the risks of giving autonomous agents spending power.
- 10Software Cryptography Audits Must Name Modules, Not Just Code Lines▼Most of the cryptography your program runs was written by somebody else. A scan that stops at... # python # fintech # cr
Developers are being reminded that most cryptographic code running in modern programs was written by someone else, usually in third-party libraries. A cryptography inventory that only lists lines in a project's own source misses these dependencies. The argument is that proper audits must name the actual module providing each cryptographic function, a point seen as increasingly important for fintech and security-sensitive software.
- 11PDF invoice redaction done right: sign after removing data▼Short answer: treat redaction as a destructive data transformation, then sign the transformed invoice... # pdf # redacti
A software discussion is making the case that true redaction of PDF invoices must be treated as a destructive transformation: remove the sensitive text first, then apply the digital signature to the altered document. Drawing black boxes over content, by contrast, leaves the underlying data intact and recoverable. The point matters in fintech and banking contexts, where invoices are shared widely and hidden text can leak confidential information despite appearing covered.
- 12DriveWealth Data Breach Exposes Personal Data of 62,074●DriveWealth Data Breach Affects 62,074: PII Exposed
DriveWealth, a US-based investment infrastructure firm, has disclosed a data breach affecting 62,074 people whose personally identifiable information was exposed. The company provides trading technology to brokerages and fintech apps, raising concerns about how the incident may ripple through its partners. Details on what data was taken and how remain limited as the company investigates.
- 13London fintech founders face tougher venture capital scrutiny●For years, forming a fintech startup in London was enough to dazzle venture capital firms. Now, founders are having to s
London fintech startups can no longer attract venture capital simply by existing, according to reporting carried by The Japan Times. Founders in the UK capital are now expected to demonstrate real commercial success to secure funding, and those who cannot are being forced to change their strategies. The shift marks the end of an era in which a London fintech label alone was enough to dazzle investors.
- 14Coordinated bot automation evades standard mobile fintech security▼Why valid authentication, genuine apps, and clean devices are not enough to stop coordinated automation in mobile FinTec
Security commentary argues that even valid authentication, genuine apps and uncompromised devices cannot stop coordinated automated abuse in mobile fintech. The piece warns that fraudsters use machine clients that mimic legitimate app traffic, so traditional controls fail to distinguish real users from automation. The discussion highlights a gap between app-level security architecture and the reality that fraud now operates with machines that pass every normal check.
- 15CertiK and Kyrgyzstan's Central Bank Team Up on Digital Currency Security▼How Central Banks Secure Digital Currency before Launch: Inside the CertiK and NBKR Deal
Security firm CertiK is working with the National Bank of the Kyrgyz Republic (NBKR) to secure the country's digital currency ahead of its launch. The deal highlights how central banks are bringing in outside auditors to test and protect central bank digital currency systems before they go live, an increasingly common step as more governments pilot digital money.
- 16Spotixx and Roseman Labs build privacy-safe fraud detection platform●Spotixx und Roseman Labs entwickeln mit MPC eine Plattform, die bankenübergreifend Betrugsmuster analysiert, ohne sensib
Spotixx and Roseman Labs are jointly developing a platform that uses multi-party computation (MPC) to analyse fraud patterns across banks without exposing sensitive customer data. The Eurostars-backed project is set to launch in 2026 and promises new approaches to secure, collaborative data analysis in the financial sector, drawing attention from banking and fintech observers.
- 17
Mona, a fintech company, has raised $3.5 million in funding aimed at broadening access to capital for small businesses. The round is expected to support the company's growth and its mission to make financing more accessible to smaller enterprises that often struggle to secure traditional credit. Details on the investors or deployment plans have not been disclosed.