GRC Report Staff

Revolut Disclosed Customer Data After Fraudulent Government Requests

Revolut handed sensitive customer records to an unauthorized third party after receiving fraudulent information requests that came from the legitimate email domain of a government agency, the British fintech confirmed to TechCrunch.

CBUAE, Mastercard Build Fraud Risk Capabilities to Strengthen Financial Resilience

The Central Bank of the UAE and Mastercard have completed a four-day program designed to sharpen the central bank’s expertise in fraud risk management, with 25 CBUAE employees receiving training on the risks emerging alongside new forms of digital payments and commerce.

When Controls Compete With Each Other

A critical system goes down, and the operations team needs an administrator inside it immediately. Privileged access, however, requires approval, and the designated approver is unavailable. A change may restore the system, but normal procedure requires testing before anything reaches production. Meanwhile, the recovery clock is running.

CFTC Sets 30% Presumption for Whistleblower Awards of $5 Million or Less

The Commodity Futures Trading Commission has approved a rule that could make the outcome of smaller whistleblower claims considerably easier to anticipate, establishing a presumption that qualifying awards of $5 million or less will be paid at the statutory maximum of 30%.

KPMG Survey Finds Compliance Chiefs Facing a Wider Risk Mandate

KPMG asked 725 chief ethics and compliance officers where they expect to put additional money. The answer was not subtle. Among respondents anticipating budget increases, 77% pointed to data analytics and 75% to cybersecurity and data privacy. AI or large language models came next at 50%, followed by process automation at 49%. Upskilling talent, at 34%, trailed considerably further behind.

Chemours, DuPont & Corteva Reach $455 Million Settlement Over North Carolina PFAS Claims

Chemours, DuPont and Corteva have agreed to pay $455 million over 15 years to settle a collection of North Carolina lawsuits over PFAS contamination, resolving claims that reach back through years of discharges from Chemours’ Fayetteville Works facility and extend to contamination the state says originated elsewhere.

EU Cyber Resilience Act Reporting Requirements Take Effect

For manufacturers selling connected products and software in the European Union, one of the Cyber Resilience Act’s first deadlines has arrived. Beginning September 11, manufacturers must report actively exploited vulnerabilities and severe incidents that affect the security of their products. The requirement reaches across the enormous category the EU calls “products with digital elements,” covering hardware and software from baby monitors and smartwatches to applications and computer programs.