Episode
A Government Email Phishing Scam and the ID Scan Breach Update
- Published
- Sep 17, 2026
- Duration seconds
- 1532
- Processing state
not_requested
Actions
POST https://stenobird.com/v1/public/podcasts/fraudology-podcast-with-karisse-hendrick-1368872/episodes/a-government-email-phishing-scam-and-the-id-scan-breach-update/transcription-requests
Idempotently request low-priority transcript generation for this episode.GET https://stenobird.com/podcast/fraudology-podcast-with-karisse-hendrick-1368872/a-government-email-phishing-scam-and-the-id-scan-breach-update.md
Read the agent-friendly Markdown representation of this episode resource.
Summary
Welcome back to Fraudology. This is a solo episode, and I’ve got two stories for you this week. I wanted to follow-up on the ID scan breach that Frank McKenna and I discussed last week. Where things stand now, whether we should still be worried, and what the driver’s license data breach means for KYC fraud prevention going forward. And then I wanted to get into one of the biggest fraud stories this week. This one is brand new and I wanted to get it to you as soon as possible. A government email phishing scam hit Revolute using what appeared to be a legitimate .gov email domain. The request was fulfilled. Customer data was released. And it did not require a breach of Revolute at all. It required a spoofed email that looked real enough to pass. I have been talking to my fraud threat intelligence sources about this, including someone with a background at one of the three-letter government agencies. What he told me changed how I’m thinking about this incident entirely. We are going to get into all of it. This is a fraud news episode, and I’m going to keep it tight today. Let’s dive in. What you’ll hear in this episode: The ID scan data breach update. Where the 153 million driver’s license database stands now, why the FBI takedown matters, and whether we should still be treating this as an active threat. Why the ID scan breach was so dangerous for KYC fraud and identity document fraud detection. And why most verification companies would not have caught it. What supply chain data breach risk looks like in practice and the vendor contract language every financial institution should have in place. The Revolute government request fraud incident explained. What data was released, what a fraudster can do with it, and why it could be used for identity theft and espionage. Why a .g…