Security Issues Reported in EU Age-Verification App and Multiple Data Breaches
A security consultant identified vulnerabilities in the EU's new age-verification app, allowing access in under two minutes. Data breaches were confirmed at a European gym chain and a global hotel reservation company, affecting customer information. Additional incidents include a DDoS attack on a social media platform and a cryptocurrency exchange hack.
WiredEU App Vulnerabilities Exposed A security consultant reported finding security issues in the EU's new age-verification app, enabling access in less than two minutes, according to Politico.
The issues involve the storage of a user-created PIN, which could allow an attacker to take over a user's profile. A whitehat hacker confirmed the vulnerability to Politico. The consultant concluded, “This product will be the catalyst for an enormous breach at some point. It's just a matter of time.”
Data
Breaches at Gym Chain and Hotel Company Europe's largest gym chain, Basic-Fit, confirmed a data breach on Monday, affecting bank details of approximately one million customers.
The breach impacted around 200,000 members in the Netherlands, along with customers in Belgium, France, Germany, Luxembourg, and Spain. Stolen data included names, home and email addresses, phone numbers, and dates of birth, but no passwords were compromised as the company does not store them.
com confirmed suspicious activity that may have led to the extraction of customer data, including names, email addresses, phone numbers, and booking details.
The company stated it took action to contain the issue and noted that no financial information was lost. Company notices posted by purported customers on Reddit appear to disclose a breach touching on “anything” the users “may have shared with the accommodation.”
DDoS Attack on Social Media Platform Social media platform Bluesky experienced intermittent failures on Thursday due to a distributed denial-of-service attack, as confirmed by the company.
The attack began around 8:40 pm ET on April 15 and affected feeds, notifications, and search. No evidence of unauthorized access to user data was reported. The outages impacted Bluesky's infrastructure but not independent communities running on the same protocol.
A community reported a significant spike in migration requests following the incident. Bluesky's status page indicated full operational status by Friday afternoon.
Cryptocurrency
Exchange Hack Russian cryptocurrency exchange Grinex announced on Thursday that it would suspend operations after a breach resulting in the theft of more than a billion rubles, equivalent to over $13 million in user funds.
The exchange attributed the attack to special services of a foreign country, citing digital traces and the nature of the attack. Grinex, which was sanctioned by U.S. financial authorities, succeeded another sanctioned exchange and was reported to aid sanctions evasion.
A crypto-tracing firm indicated it was likely created by the same owners and inherited funds and customers. No public evidence was provided to support the claim of state-sponsored involvement.
Key Facts
Story Timeline
5 events- Thursday
Grinex announced suspension of operations after a hack stealing over $13 million in user funds.
1 sourceWired - Thursday
Bluesky confirmed a DDoS attack causing intermittent failures starting April 15.
1 sourceWired - Monday
Basic-Fit and Booking.com confirmed data breaches affecting customer information.
1 sourceWired - Recent
Security consultant reported hacking EU age-verification app in under two minutes.
1 sourceWired - January
DHS press release stated ICE hired over 12,000 officers and agents in less than a year.
1 sourceWired
Potential Impact
- 01
Suspension of Grinex operations affecting Russian crypto users.
- 02
Potential identity theft risks for affected gym and hotel customers.
- 03
Increased migration to alternative social platforms following Bluesky outages.
- 04
Regulatory scrutiny on EU app leading to security updates.
- 05
Review of ICE hiring processes due to background check findings.
Transparency Panel
Related Stories
AxiosWorld Announces Integrations with Zoom, DocuSign and Others for Iris-Scanning Identity Tool
A company co-founded by OpenAI's Sam Altman unveiled expanded integrations for its World ID protocol with platforms including Zoom, Tinder and Shopify. The firm, known for iris-scanning orbs, upgraded its identity tool and plans to open-source it for broader app authentication. A…
2 sourcesWhite House Announces NASA Plan for Nuclear Reactors on Moon and in Orbit
The White House has directed NASA to collaborate with the Departments of Defense and Energy on developing nuclear reactors for the moon's surface and orbit. The initiative aims to provide sustained power for future space missions. Technologies are targeted to produce at least 20…
App Store Sees Surge in New App Launches in 2026, Possibly Driven by AI Tools
Data from Appfigures indicates an increase in new app releases on the App Store in 2026, with certain categories showing notable growth. Analysts suggest AI tools may be contributing to this trend by enabling faster app development. Recent incidents highlight challenges in app re…