A major fintech data breach demonstrates how impersonation attacks bypass technical defences entirely, whilst a maximum-severity GitLab vulnerability enters active exploitation. This episode examines Revolut’s disclosure of customer financial and passport data released following a fraudulent government agency impersonation, highlighting the procedural failures that enable social engineering at scale. We cover CISA’s addition of a GitLab path traversal flaw to the Known Exploited Vulnerabilities catalogue, the supply chain implications for UK SMBs, and practical verification procedures that prevent data disclosure to unauthorised parties. Operational updates include Microsoft’s September patches breaking Remote Desktop Services on Windows Server, and the UK government’s passkey rollout across 23 million GOV.UK accounts. The episode focuses on verification protocols, out-of-band confirmation procedures, and supply chain questioning as practical defences against non-technical attack vectors that compromise organisations with significant security resources.