Scams & Fraud

Stories 76
Sources 152
Updated 2026.07.25
SourTrade malvertising campaign uses fake Solana, Luno, and TradingView sites to assemble malware inside victims’ browsers
A large online ad scam is sending retail traders and cryptocurrency users to fake Solana, Luno, and TradingView pages that build malware directly inside the victim’s browser before download. Confiant says the SourTrade campaign has run since late 2024 across 25 languages in 12 countries, mainly in Asia Pacific and Latin America, using JavaScript, SharedWorker, and Service Worker features to assemble a unique malicious executable in memory from a clean Bun binary and remote components so no finished file crosses the network. — People looking for trading or crypto software through ads or sponsored search results could end up downloading malware that steals passwords, wallet data, and other sensitive information. Users should avoid ad-linked downloads and get software only from official vendor sites, while defenders should watch for this same-origin browser download technique and fake finance-brand pages.
Sources: Malicious sites use JavaScript to build malware in browser memory, Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
Sextortion scammers use ShinyHunters breach data from Amtrak, Hallmark, Substack and others to demand $2,000 in Bitcoin
Scammers are using email addresses exposed in past ShinyHunters-linked breaches to send sextortion emails that demand $2,000 in Bitcoin. BleepingComputer says the campaign cites real breached companies including Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill to make the threats look credible, but there is no evidence the sender actually hacked recipients' devices or recorded them. — People whose email addresses were exposed in earlier breaches may now face more believable extortion emails, even if their devices were never compromised. Affected users should not pay, should treat messages claiming webcam compromise with skepticism, and should secure accounts exposed in prior breaches with password changes and phishing awareness.
Sources: ShinyHunters data leaks fuel $2,000 sextortion email scam
Europol flags 4,340 URLs tied to The Com extremist network in June-July 2026 crackdown
Europol says it flagged 4,340 URLs for removal during a June-July 2026 operation targeting online content linked to The Com, a decentralized extremist network that recruits and abuses young people online. The action was run by Europol's EU Internet Referral Unit and Spain's CITCO with investigators from nine countries, and focused on content tied to self-harm, child sexual abuse material, violent attacks, grooming, doxing, swatting, and attack manuals; Europol says The Com includes subgroups involved in cyber intrusions and ransomware. — This matters because The Com blends violent extremism with cyber-enabled abuse such as sextortion, doxing, swatting, and ransomware, often targeting minors through mainstream online platforms. Platforms, investigators, schools, and families should watch for coded recruitment content and coercion tactics, while defenders should note the group’s overlap with cybercrime activity.
Sources: Europol flags 4,340 URLs for removal in 'The Com' crackdown, Europol flags 4,340 'horrific' URLs linked to The Com
Abbott investigates ShinyHunters-linked breach of Cancer Diagnostics systems and a separate claimed LabCentral portal intrusion
Abbott says attackers got into a limited number of internal systems in its Cancer Diagnostics business, and it is separately investigating a claimed breach of its LabCentral customer portal. The confirmed incident followed extortion claims by ShinyHunters, which said it used a vishing attack and a compromised Microsoft Entra single sign-on account to access legacy Exact Sciences systems and steal data from services including SharePoint, ServiceNow, Databricks, and Coupa; Abbott said the LabCentral claim is unrelated. — This could affect patients, customers, and healthcare partners if the claimed theft of personal, medical, or contract data is confirmed. Healthcare organizations and Abbott customers should watch for notifications, review account security around Microsoft Entra and portal access, and be alert to follow-on phishing or fraud.
Sources: Abbott Laboratories probes two cyber incidents amid extortion claims, In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws
German-led operation dismantles Kratos phishing kit infrastructure and arrests alleged developer in Indonesia
German and Indonesian authorities say they dismantled the Kratos phishing-as-a-service platform, which was used to steal Microsoft account logins and session cookies from victims in more than 30 countries. Prosecutors and the BKA said the operation neutralized more than 200 servers and led to the arrest in Indonesia of the alleged developer and technical administrator. Authorities estimate more than 1,800 criminal customers used Kratos for roughly 15,000 phishing campaigns a month since 2024. — Kratos helped low-skill criminals run convincing Microsoft-themed phishing campaigns at scale, including attacks that could bypass multi-factor authentication by stealing session cookies. Organizations should review Microsoft 365 phishing defenses, hunt for token and session theft, and warn users about fake login pages and document lures.
Sources: Kratos phishing-as-a-service kit loses its battle with international law enforcement, Police dismantle Kratos phishing platform, arrest developer, Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA (+1 more)
Dolphin X Windows stealer and remote-access trojan targets 300+ apps and uses an AI profiler to rank victims
Researchers say a new Windows malware service called Dolphin X is being sold to criminals to steal passwords, enterprise secrets, and cryptocurrency from infected users. Varonis says the stealer and remote-access trojan (RAT) claims support for more than 300 applications and theft of browser credentials, SSH keys, cloud tokens, .env files, DevOps secrets, and crypto wallets, plus an 'AI Profiler' that scores victims by app use, browsing history, and installed software so operators can prioritize the most profitable targets. The seller also advertises loader, hidden virtual desktop control, and distributed denial-of-service capabilities. — This could increase the damage from commodity malware by helping criminals quickly identify which infected people or employees are worth deeper follow-on attacks. Organizations should treat stealer infections as high risk, watch for credential and token theft on Windows endpoints, and rotate exposed passwords, keys, and cloud secrets if compromise is suspected.
Sources: Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits, New Dolphin X malware uses AI to rank high-value targets, In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws
U.S. State Department imposes visa restrictions on foreign cyber scammers and their immediate family members
The U.S. State Department said it will deny visas to people tied to foreign cyber scam operations and to their immediate family members. Secretary of State Marco Rubio said the policy targets individuals responsible for or complicit in cybercrime and cyber-enabled crime, including cyberscams and sextortion, and highlighted scam-center networks in Southeast Asia, often linked by U.S. officials to Chinese transnational criminal groups involved in fraud, trafficking, and money laundering. — This matters because it is a new U.S. pressure tactic against industrial-scale scam networks that steal billions from victims and often rely on cross-border movement and support systems. It signals increased enforcement focus on scam compounds and related fraud ecosystems, especially in Southeast Asia.
Sources: State Department imposes visa restrictions on foreign cyber scammers, Uncle Sam tells overseas cybercrooks their visas are canceled
Illinois man gets prison sentence for phishing and hijacking more than 750 women’s Snapchat accounts
A U.S. court sentenced an Illinois man to 76 months in prison for using social engineering to break into hundreds of women’s Snapchat accounts and steal intimate photos. Prosecutors said Kyle Svara posed as Snap support between May 2020 and February 2021, used anonymized phone numbers to phish Snapchat access codes from more than 750 women, accessed about 517 accounts, and then enabled two-factor authentication to lock victims out. Court records also say he traded or sold stolen images online and advertised account-hacking services through Kik. — This shows how simple impersonation and one-time-code phishing can turn into large-scale account takeover and extortion-style abuse even without malware or software exploits. Snapchat users should be wary of messages claiming to be from support, never share login codes, and review account recovery and two-factor settings if they suspect compromise.
Sources: Man gets six years for hacking 750 women's Snapchat accounts
Upbound says stolen customer data was used to create $13 million in fraudulent Acima lease agreements
Upbound says hackers stole customer information and documents, then used that data to open fraudulent Acima lease-to-own agreements and obtain goods. In an SEC filing, the company said the misuse caused about $13 million in second-quarter losses in its Acima segment. The company described the stolen data as certain non-sensitive customer information and other documents, said it notified federal law enforcement, and has added stronger authentication, fraud detection, and monitoring while the investigation continues. — This matters to both customers and merchants because stolen identity details were turned into real financial fraud, not just exposed and left unused. People with Acima or related Upbound accounts should watch for suspicious lease activity, while defenders should treat this as a live post-breach fraud case requiring stronger identity and transaction controls.
Sources: Upbound says hack caused $13 million in fraudulent Acima leases, Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses
U.S. charges two New York suspects with laundering $43 million from online investment fraud scams
U.S. prosecutors charged two people in New York with helping launder $43 million stolen from victims in online investment fraud scams. The indictment says Zhuoying Chen and Haojie Zhang ran a Queens- and Brooklyn-based network from 2020 to 2022 that used about 140 bank accounts and roughly 45 shell companies to move scam proceeds to accounts in China. Prosecutors say the underlying fraud used social media and messaging apps to build trust, show fake investment profits, and steal additional deposits. — This highlights the scale and persistence of pig-butchering-style investment fraud that can drain victims’ life savings. Consumers should be wary of unsolicited investment pitches and profit screenshots, while banks, platforms, and investigators should watch for shell-company accounts and cross-border laundering patterns tied to scam operations.
Sources: US charges two over laundering $43 million from investment fraud
ClickLock Stealer targets macOS users with fake Cloudflare checks to steal passwords and cryptocurrency
A newly reported macOS malware campaign is tricking users into infecting their own Macs and then stealing passwords, browser data, and cryptocurrency wallet information. Group-IB says ClickLock Stealer has targeted at least 100 users in 33 countries since late May 2026, likely via ClickFix-style fake Cloudflare verification pages that tell victims to paste a bash command into Terminal. The malware kills visible processes and NotificationCenter to suppress warnings, uses fake password prompts to capture credentials, steals Keychain and browser secrets, and exfiltrates data to a Telegram bot. — Mac users are affected even without a software exploit because the attack relies on social engineering and abuse of built-in tools. Organizations should warn users not to paste commands from websites into Terminal, review macOS detections and process-killing behavior, and treat exposed passwords, wallet secrets, and browser data as compromised.
Sources: ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing, New ClickLock macOS malware traps users into revealing login password
OkoBot malware framework uses ClickFix and fake GitHub software repos to steal credentials and cryptocurrency seed phrases
A malware framework called OkoBot is being used to steal passwords, browser cookies, cryptocurrency wallet files, and wallet recovery phrases from victims worldwide. Kaspersky says the campaign evolved from the TookPS activity seen since March 2025 and now uses multi-stage delivery through ClickFix social-engineering lures and trojanized GitHub repositories, including fake software offerings. More than 20 payloads are involved, including modules that inject into Chrome, Trezor Suite, Ledger Wallet, and Ledger Live, install malicious extensions, log keystrokes, and record activity in crypto wallets and password managers. — This can directly lead to drained crypto wallets and stolen accounts, and recovery may be impossible if seed phrases are captured. Organizations and users should avoid running code from untrusted GitHub repositories, treat ClickFix-style prompts as hostile, and hunt for the published indicators of compromise.
Sources: New OkoBot framework deploys 20 payloads to steal data, crypto
ClickFix campaign targets macOS users with Atomic macOS Stealer through silent DMG mounting
A new scam-style malware campaign is tricking Mac users into pasting a Terminal command that silently installs a password and crypto-stealing program. Palo Alto Networks says the ClickFix attack uses a fake CAPTCHA to get victims to run a command that downloads a malicious DMG disk image, mounts it with macOS hdiutil without showing it in Finder, and launches Atomic macOS Stealer (AMOS). The malware steals browser credentials, cookies, Keychain data, Telegram and Discord data, documents, and cryptocurrency wallet information, and can replace Ledger Live and Trezor Suite with trojanized versions. — This can lead directly to stolen passwords, drained crypto wallets, and account takeover for Mac users who follow the fake verification prompt. Users should never paste commands into Terminal from websites, and organizations should warn users about ClickFix lures and watch for AMOS-related activity.
Sources: New macOS ClickFix attack silently mounts DMGs to push infostealer, C'mon, just copy this text string and paste it into your macOS Terminal – it'll fix your computer, honest
Russian threat actor UAT-11795 uses trojanized Zoom, Webex, and other software installers to deploy Starland RAT
A Russian cybercrime group is spreading fake installers for popular software such as Zoom, Webex, MobaXterm, DBeaver, and FaceIT to infect Windows users with a new backdoor called Starland RAT. Cisco Talos says UAT-11795 has run the campaign since at least June 2025, mainly against U.S. users, using an HTA file and a trojanized NSIS installer to load Starland, persist via Registry and scheduled tasks, and in some cases deliver CastleStealer and Remcos. The malware steals browser and cryptocurrency-wallet data, gathers Active Directory information, and uses a fallback command-and-control method via a Polygon smart contract. — People and organizations can be compromised simply by installing what looks like legitimate remote-work or developer software, leading to stolen passwords, wallet theft, and deeper network access. Defenders should hunt for Talos indicators of compromise, restrict software downloads to verified vendor sources, and warn users against running pasted commands or unofficial installers.
Sources: Russian hackers trojanize WebEx, Zoom apps to push Starland malware
Dutch police arrest suspects tied to international investment fraud ring that used fake crypto platforms and call centers
Dutch police say they arrested multiple suspects tied to an international investment fraud network that allegedly stole from tens of thousands of victims through fake investment platforms. Investigators say the group ran about 20 call centers with more than 700 people posing as financial advisers, showed victims bogus profit dashboards, and pushed them to send more money, often in cryptocurrency. Police linked at least 550 reports and $28.6 million in reported losses to the ring, while estimating the broader operation made more than €100 million per month and had been active since at least 2021. — This is a large, organized social-engineering and investment-scam operation with worldwide victims, showing how convincing fake trading sites and phone-based pressure can drive major financial losses. Consumers should treat unsolicited investment pitches and crypto-transfer requests as high risk, and defenders at financial and telecom organizations should watch for fraud infrastructure and impersonation activity.
Sources: Dutch police bust investment fraud ring stealing over €100 million
Dutch police dismantle global fake cryptocurrency investment scam and arrest alleged mastermind
Dutch police say they dismantled an international fraud network that tricked tens of thousands of people into putting money into fake cryptocurrency investment platforms. Authorities said the group operated since at least 2021, ran about two dozen call centers in multiple countries, employed more than 700 people posing as financial advisers, and allegedly generated more than €100 million per month; a 46-year-old Israeli-Polish suspect was arrested in Poland and extradited to the Netherlands. — This matters to consumers and investigators because it shows the scale and professionalism of modern investment scams, which can build trust over weeks before stealing life savings. People should be wary of unsolicited investment pitches, especially crypto offers routed through call centers, messaging apps, or polished trading sites showing fake returns.
Sources: Dutch police dismantle global crypto investment scam, arrest alleged mastermind
U.S. unseals charges against alleged operators of Media Land and ML Cloud Russian bulletproof hosting service
The U.S. unsealed an indictment against three Russians accused of running Media Land and ML Cloud, hosting services that allegedly helped cybercriminals carry out attacks against victims in the United States and elsewhere. Prosecutors say Aleksandr Volosovik, Yulia Pankova, and Kirill Zatolokin provided infrastructure and technical support designed to shield criminal customers from law enforcement, enabling ransomware groups including LockBit, BlackSuit, and Play as well as stolen-card marketplaces such as Briansclub and Bidencash; the indictment cites 44 victims and about $62 million in losses. — Bulletproof hosting is a key enabler for ransomware, fraud, and stolen-data markets, so this case matters beyond the named defendants. Defenders should note the specific infrastructure and actor links, while affected organizations and the public should expect continued law-enforcement disruption efforts rather than an immediate end to related threats.
Sources: US unseals indictment against alleged operators of Russian bulletproof hosting service, US charges alleged operators of Russian bulletproof hosting service, US Charges Russian Individuals and Firms for Running Cybercrime Services
Spanish police dismantle €140 million cyber-fraud and BEC money-laundering network
Spanish police say they broke up a criminal network that made about €140 million from investment scams and business email compromise, a fraud in which attackers impersonate executives or vendors to divert payments. Authorities arrested four suspects in Spain, Portugal, and Panama and say the group used more than 800 bank accounts, 120 business accounts, and 67 money mules to move and hide proceeds; investigators linked €61 million specifically to 2024 BEC activity and froze €3 million for victim recovery. — This shows the scale and persistence of BEC and investment-fraud operations, which can drain businesses and individuals without using malware at all. Organizations should tighten payment-verification controls and train staff to independently verify invoice changes and executive payment requests.
Sources: Spanish Police take down €140 million cyber fraud ring, arrest four
Finland issues wanted notice for convicted Vastaamo hacker after Supreme Court lets psychotherapy breach sentence stand
Finnish authorities have issued a wanted notice for Aleksanteri Kivimäki, who was convicted over the Vastaamo psychotherapy breach and extortion case affecting tens of thousands of patients. Finland's Supreme Court refused to hear his appeal, leaving in place a nearly seven-year sentence for the 2018 hack and 2020 extortion campaign. The breach exposed data on about 33,000 patients, and more than 24,000 people reportedly received direct extortion demands before therapy notes were leaked online. — This updates one of Europe’s most serious medical-privacy breaches, where deeply sensitive therapy records were stolen and used to extort patients. Affected people and defenders get confirmation that the conviction is final, while the wanted notice shows the offender has not yet been taken back into custody.
Sources: Finland issues wanted notice for hacker behind massive psychotherapy data breach
Welsh Doxbin administrator jailed for helping coordinate and promote swatting attacks in the UK, US, and Canada
A Welsh man was jailed after investigators said he helped encourage and support swatting attacks linked to the doxing platform Doxbin. Authorities said Callum Dare, an administrator on Doxbin, used the platform’s #deadnet channel to assist and incite hoax emergency calls, shared montage videos of armed-police responses to encourage copycats, and was tied through seized chat logs, a PayPal account, and device forensics to multiple incidents including threats against a Cardiff hotel, a University of California lecture theater, and victims in Canada. — Swatting can get armed police sent to innocent people’s homes or workplaces and has caused real injuries and deaths. The case highlights how doxing forums can enable harassment and violent hoaxes at scale, so organizations and individuals targeted by online harassment should treat leaked personal data and threat escalation as an immediate safety issue.
Sources: Welsh Doxbin admin jailed for egging on swatters from behind a screen
TrendAI says Russian-speaking scammer used jailbroken Gemini to target QAnon and MAGA users with wallet theft and WordPress credential attacks
A Russian-speaking threat actor allegedly used a jailbroken Google Gemini account to run a months-long scam and theft campaign aimed at QAnon and MAGA communities, stealing WordPress admin credentials and draining at least one victim's cryptocurrency wallets. TrendAI says the operation ran from September 2025 to May 2026 through a Telegram channel with about 17,000 subscribers, used 73 likely stolen Gemini API keys, pushed a fake StellarMonster wallet app that actually installed the GoToResolve remote access tool, and captured victims' seed phrases through a bogus wallet-import screen. — This matters because it blends political-community targeting, AI-assisted social engineering, malware, and direct crypto theft in a way ordinary users can fall for and defenders may miss. Users should avoid wallet apps and recovery prompts promoted in Telegram channels, while organizations should investigate exposed WordPress credentials and watch for abuse of stolen API keys.
Sources: A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets, 'The bots are alive!' Jailbroken Gemini spun up new C2 server for Russian fraudster in just 6 minutes
Klue OAuth breach let Icarus extortion group steal Salesforce customer data from multiple organizations
Klue says attackers abused its Salesforce-connected Battlecards app to steal CRM data from multiple customer organizations, and victims are now receiving extortion demands from the Icarus group. According to ReliaQuest, Huntress, and BleepingComputer, the attackers used compromised Klue service accounts and associated OAuth tokens to access customer Salesforce instances, enumerate objects through Salesforce REST API endpoints, and exfiltrate records over hours; Salesforce has disabled the Klue Battlecards integration while the incident is investigated. — Organizations that connected Klue Battlecards to Salesforce may have had sensitive sales, customer, or internal business data stolen without a malware outbreak or password spray. Affected teams should urgently review Salesforce OAuth-connected apps and token activity, check for unusual API queries, and prepare for extortion emails tied to this campaign.
Sources: Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks, Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data, Cybersecurity Firms Impacted by Klue Supply Chain Attack (+7 more)
Pink extortion group uses fake help-desk calls and MFA phishing to steal Microsoft 365 and cloud data
A newly identified extortion group called Pink is calling employees while pretending to be IT support, then stealing account credentials and company data to demand payment. Palo Alto Networks Unit 42 says the group, tracked as CL-CRI-1147 and likely linked to the criminal network known as The Com, uses voice phishing and fake help-desk interactions to capture passwords and multifactor authentication (MFA) approvals, then raids services such as SharePoint, OneDrive, and Microsoft Teams. Unit 42 said Pink's leak site went live on May 31 and published domains and IP addresses tied to the campaign as indicators of compromise. — This matters to organizations that rely on cloud productivity tools because attackers do not need malware or software flaws if they can talk staff into handing over access. Companies should warn staff about unsolicited help-desk calls, tighten help-desk identity checks, review Microsoft 365 logs, and block or investigate the listed phishing infrastructure immediately.
Sources: Pink is the latest goon squad to use fake helpdesk calls to steal creds, Entra passkey enrollment vishing targets Microsoft 365 users, Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers
Ohio county reportedly paid Kairos extortion group $1 million after 2025 data-theft attack
A small Ohio county government reportedly paid $1 million to a cyber extortion group to stop stolen records from being published. Ransom-ISAC says Kairos stole more than 2 terabytes of data, about 1.6 million files, in a May 2025 intrusion that began with a brute-force attack, then negotiated down from a $3 million demand; the incident reportedly involved data theft and extortion rather than file encryption. The victim appears to be Union County, Ohio, which previously disclosed that 45,487 people were affected and that exposed data included Social Security numbers, passport and driver's license details, financial and payment-card data, fingerprint data, and medical information. — This matters because a local government reportedly lost highly sensitive resident data and paid a large ransom despite no way to verify deletion. Government organizations should review exposed remote access points for brute-force weaknesses, harden authentication, and prepare for theft-and-extortion incidents even when ransomware encryption is not used.
Sources: County Government Reportedly Paid $1 Million to Cyber Extortion Group, An unnamed US county – perhaps in Ohio – paid $1M extortion demand to cybercriminals
Forg365 phishing service targets Microsoft 365 accounts with device-code login tricks and cookie-stealing browser extension
Researchers identified a phishing-as-a-service platform called Forg365 that is built to steal Microsoft 365 accounts and keep access to them after login. The service combines OAuth device-code phishing and adversary-in-the-middle (a login proxy that captures session tokens), uses AI inside its operator dashboard to generate lures, and includes a Chrome-, Edge-, and Brave-compatible extension called ForgCookie that refreshes stolen Microsoft single sign-on cookies for persistent access. — Microsoft 365 users and administrators should treat this as an active account-takeover threat, especially because it abuses legitimate Microsoft authentication flows instead of only stealing passwords. Organizations should harden device-code and OAuth app controls, review suspicious consent grants and session tokens, and warn users not to enter Microsoft verification codes from unsolicited emails.
Sources: New Forg365 phishing platform uses AI to target Microsoft 365 accounts
INTERPOL says Operation First Light 2026 led to 5,811 arrests and $293 million seized in global anti-fraud crackdown
INTERPOL says police in 97 countries arrested 5,811 suspects and seized $293 million in a coordinated crackdown on online fraud and related money laundering. Operation First Light 2026 ran from January 15 to April 30 and targeted business email compromise, sextortion, impersonation, romance, and investment scams; authorities said they identified more than 142,000 victims, blocked 31,014 bank accounts, reviewed 152,808 cases, and identified 15,606 additional suspects. — This shows the scale of social-engineering fraud hitting consumers, businesses, and governments worldwide. People and organizations should treat unsolicited payment requests, investment pitches, romance approaches, and account-verification messages with caution, and strengthen payment verification and anti-fraud controls.
Sources: Police arrests 5,800 suspects in global anti-fraud crackdown
Block will pay $45 million to states over Cash App security and fraud-protection failures
Block, the owner of Cash App, agreed to pay $45 million to 46 U.S. states over allegations that the app misled users about its security and left them exposed to scams. State attorneys general said Cash App lacked basic identity checks such as Social Security number or date-of-birth requirements at signup, allowed multiple accounts per person, had no real customer-support phone line until 2021, and failed to adequately investigate fraud or help victims recover funds. The settlement also requires 24/7 live support and reinforces a related 2025 federal consent order. — This matters to millions of payment-app users because weak verification and poor support can make scams easier and recovery harder after money is stolen. Cash App users should be cautious of support-number scams and review account protections, while regulators and fintech firms may face higher pressure to strengthen fraud controls.
Sources: Cash App owner to pay $45 million to settle allegations of lax security
U.S. extradites alleged Scattered Spider member over social-engineering breach and $8 million extortion attempt against jewelry retailer
A 19-year-old accused Scattered Spider member was extradited from Finland to the United States to face charges tied to hacking and extortion. The FBI says Peter Stokes helped breach an unnamed luxury jewelry retailer around May 12, 2025 by calling the IT help desk from Google Voice numbers, posing as employees, and getting password and multifactor authentication resets; the attackers allegedly compromised three accounts, including two IT administrator accounts, used ngrok for persistent access, stole data, and demanded $8 million in cryptocurrency. — This matters because it gives defenders a concrete look at how Scattered Spider is still using help-desk impersonation to break into companies without exploiting software flaws. Organizations, especially those with privileged IT accounts, should harden help-desk identity checks, review MFA reset procedures, and monitor for unauthorized remote-access tools such as ngrok.
Sources: Teen suspect in Scattered Spider hacks is extradited to US, Alleged Scattered Spider hacker extradited to the United States, Alleged Scattered Spider Hacker Extradited to US (+1 more)
Google sues alleged China-based 'Outsider Enterprise' over mass phishing texts and fake brand websites
Google says a China-based fraud network used phishing kits and automated content generation to send millions of scam text messages and steer people to fake websites that stole passwords, payment-card data, and other sensitive information. In a civil complaint, Google linked the Telegram-based 'Outsider Enterprise' to more than 9,000 fraudulent sites and over 1 million malicious URLs, and said Android telemetry saw about 2.5 million related messages in a two-week period in May. — This is a high-volume smishing and credential-theft operation affecting everyday phone users, not just a niche enterprise target set. People should be wary of text messages claiming to be from trusted brands, avoid logging in through SMS links, and carriers and mobile defenders should watch for the cited infrastructure and lures.
Sources: Google fires sueball at alleged Chinese phishers over AI-powered fraud ops, FBI disrupts massive AI-powered phishing service using a million URLs, FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service (+1 more)
BonkDAO says attackers used a malicious governance vote to drain $20 million in BONK cryptocurrency
BonkDAO says attackers stole about $20 million in BONK by pushing through a malicious governance proposal that voted more tokens into wallets they controlled. The attackers reportedly bought a large BONK position in advance to gain voting power inside the decentralized autonomous organization, then used that leverage to approve the transfer. Upbit temporarily suspended BONK deposits and withdrawals while the incident is investigated. — This is a direct loss event affecting BONK holders and users of services that support the token. Anyone exposed to BONK should watch exchange and project notices, review custody risk, and expect possible freezes, volatility, or recovery actions.
Sources: Attackers vote themselves $20 million in BONK cryptocurrency
Zscaler says prompt-injection websites trick some AI agents into making crypto payments and trusting fake DeBank pages
Researchers found two live scam campaigns that hide instructions in web pages to manipulate autonomous AI agents, including one that got some agents to initiate cryptocurrency payments and another that made some models trust a fake DeBank site. Zscaler says the first campaign used search-result poisoning and fake API documentation for a bogus Python package, with hidden prompts in schema markup and HTML telling agents to pay for an API key; the second used typosquatting and search optimization to impersonate DeBank. In tests across 26 large language models, four executed a payment and two misidentified the fake site as legitimate. — Organizations experimenting with AI agents that can browse the web or make transactions could have those agents manipulated by hostile content. Treat web content as untrusted input for AI agents, restrict payment and external-action permissions, and add human approval before any financial or account-trust decision.
Sources: Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments
Researchers link Popa Android TV box botnet and residential proxy network to NetNut and Alarum Technologies
Researchers say a sprawling Android TV box botnet called Popa has been turning millions of consumer streaming devices into residential proxies that relay malicious traffic. KrebsOnSecurity, citing Qurium and earlier XLAB findings, says Popa is associated with the Vo1d malware ecosystem and has been used for advertising fraud, account-takeover activity, and mass data scraping; newly analyzed command-and-control domains including ninjatech[.]io are linked to NetNut, a proxy provider owned by Alarum Technologies. — People who bought unofficial streaming boxes may have unknowingly exposed their home internet connections and possibly local networks to abuse by third parties. Consumers should disconnect suspect devices, replace them with trusted hardware, and monitor accounts and network activity; defenders should block known Popa infrastructure and scrutinize traffic from Android-based set-top boxes and residential proxy sources.
Sources: ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm, In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum, FBI Seizes NetNut Proxy Platform, Popa Botnet (+3 more)
ARToken phishing service tied to EvilTokens expands Microsoft 365 token theft and business email compromise attacks
Researchers say a phishing service called ARToken is tied to the EvilTokens platform and is being used to break into Microsoft 365 accounts and steal long-lived access tokens. Cisco Talos found a React-based ARToken management panel with more than 80 API endpoints, including the same Microsoft OAuth 2.0 device-code phishing and Primary Refresh Token (PRT) workflows previously linked to EvilTokens. The toolkit can access Outlook, SharePoint, and OneDrive, create inbox rules, send mail from victim accounts, and deploy phishing infrastructure through Cloudflare Workers. — This matters because the attacks use Microsoft's legitimate device login flow, which can trick users into handing over access even when multi-factor authentication is enabled. Organizations using Microsoft 365 should urgently review device-code sign-in activity, tighten controls around OAuth and token use, monitor for suspicious inbox rules and mail forwarding, and warn users about unexpected prompts to enter device codes.
Sources: ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit
India temporarily blocks Telegram and disables message editing over NEET medical exam cheating scams
India temporarily restricted Telegram nationwide ahead of the rerun of its medical entrance exam after authorities said scammers were using the app to sell fake leaked test papers. The National Testing Agency said access would be blocked until June 22 and Telegram's message-editing feature disabled in India until June 30; officials said fraudsters used edited posts to make it appear they had advance access to real NEET-UG questions, and police in Ahmedabad arrested suspects tied to eight Telegram channels in a scheme that moved about 15 million rupees. — This affects millions of Telegram users in India and shows how governments may impose platform-level restrictions in response to fraud and rumor campaigns. Students and families should be wary of Telegram channels offering leaked exam papers, while defenders and rights groups should track the censorship and platform-governance implications of disabling communications tools to address scams.
Sources: India temporarily blocks Telegram over medical exam cheating fears, India's Telegram ban draws criticism from Durov as company challenges order in court, India's Telegram ban hit the UAE too. Here's how to get around it (+2 more)
India orders WhatsApp to explain and pause username rollout over impersonation and scam fears
India told WhatsApp to justify its planned username feature within three days and asked the company to halt the rollout until regulators review it. The Ministry of Electronics and Information Technology said letting people contact others by username instead of phone number could increase impersonation, phishing, and 'digital arrest' scams, especially by attackers posing as officials, banks, or government departments; WhatsApp said the feature is not yet live and will roll out later this year with account-age, shared-group, and country signals plus reserved high-profile names. — This could affect WhatsApp users in its biggest market and signals a direct government intervention in a messaging platform feature over fraud and account-trust concerns. Users should be cautious about new first-contact messages when usernames launch, and defenders should watch for impersonation scams that exploit name-based discovery.
Sources: India gives WhatsApp three days to defend username rollout amid security fears
FBI warns Kali365 phishing service is hijacking Microsoft 365 accounts through OAuth device-code logins
The FBI says criminals are using a Telegram-based service called Kali365 to trick people into granting access to their Microsoft 365 accounts. The phishing-as-a-service platform, first seen in April 2026, abuses Microsoft's legitimate device-code login flow so victims authorize attacker-initiated sessions; the stolen OAuth access and refresh tokens can then be reused to access Outlook, Teams and OneDrive without needing the victim's password or another multi-factor authentication prompt. — This matters because victims can lose control of email, files and collaboration accounts even if multi-factor authentication is enabled. Organizations using Microsoft 365 should urgently review device-code login controls and token protections, monitor for suspicious inbox rules and token use, and warn users not to enter login codes from unsolicited emails.
Sources: FBI warns of Kali365 phishing-as-a-service after April Microsoft 365 attacks, FBI warns of Kali365 phishing service targeting Microsoft 365 accounts, From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services (+2 more)
FTC fines Amazon $2.25 million for denying identity-theft victims records of fraudulent transactions
The U.S. government says Amazon must pay $2.25 million after failing to give identity-theft victims records tied to fraudulent purchases made in their names. The Federal Trade Commission said Amazon violated Section 609(e) of the Fair Credit Reporting Act by refusing or delaying requests from consumers and authorized law-enforcement agencies, sometimes citing "privacy" or "security" reasons, and must now provide records within the law’s 30-day deadline. — People trying to prove fraud and clear their names can be blocked if companies withhold transaction records. This also signals that large platforms face enforcement risk if they fail to meet legal obligations around identity-theft response and consumer access to evidence.
Sources: Amazon fined $2.25M for withholding evidence from fraud victims
Uni-App scam framework is powering more than 200,000 fake investment, crypto, gambling, and phishing websites
Researchers say criminals have used templates built with DCloud's Uni-App framework to launch more than 200,000 scam websites targeting internet users. Infoblox identified over 236,000 second-level domains tied to the ecosystem, including fake crypto exchanges, pig-butchering investment sites, gambling and prediction-market impersonators, WhatsApp phishing pages, and credential-harvesting sites; the activity has grown since mid-2022 and accelerated after late 2024. — This is a mass-scale fraud and phishing infrastructure that can steal money, passwords, and cryptocurrency from ordinary users. Consumers should be wary of unsolicited investment offers and crypto platforms, while defenders can use the shared framework fingerprints and domain patterns to block or investigate related sites.
Sources: Chinese Framework Powers 200,000 Scam Sites
Polymarket says third-party vendor compromise injected malicious script and stole about $3 million from users
Polymarket says hackers compromised a third-party vendor and used it to inject malicious code into the prediction market’s website, leading to theft from some users. The company said it removed the affected dependency and will refund impacted users. Blockchain tracking cited in the report says about $3 million in pUSD was stolen from at least 11 victims, then bridged from Polygon to Ethereum and swapped into about 1,893 ETH. — Users who connected wallets to Polymarket may have been exposed to a website-based theft campaign even if Polymarket itself was not directly breached. Affected users should watch for official notification, review wallet activity, and be cautious of follow-up phishing or refund scams tied to the incident.
Sources: $3 Million Reportedly Stolen in Polymarket Hack, Polymarket customers lose $3 million in supply-chain attack
Polish authorities arrest SIM-swapping gang accused of breaching telecom partners and stealing millions in cryptocurrency
Polish authorities arrested four people accused of stealing millions by hijacking victims’ phone numbers and taking over their cryptocurrency accounts. Investigators say the group breached entities working with telecommunications operators and compromised employee email accounts using software and social engineering, then intercepted SMS messages and email traffic to conduct SIM-swapping attacks; the operation involved support from the FBI and Homeland Security Investigations. — SIM swapping can let criminals bypass text-message security codes and seize control of email, financial, and crypto accounts. Telecom-adjacent organizations should review partner access and employee email protections, and users should move high-value accounts away from SMS-based authentication where possible.
Sources: Poland busts SIM-swapping gang tied to millions in crypto theft
Scammers abuse Shopify's Shop app to plant fake order receipts and run callback phishing attacks
Attackers are abusing Shopify's Shop order-tracking app by inserting fake purchase receipts into users' order histories, then using the listed phone numbers to trick people into calling scammers. The fake receipts impersonate brands including Norton, McAfee, Apple, and PayPal, and the callback phishing flow aims to steal credentials, payment-card details, and one-time passcodes; some victims are also persuaded to install remote-access software. Researchers said they found no evidence that Shop, Shopify, or the impersonated brands were breached, and the insertion method is still unclear. — This matters because the scam appears inside a trusted shopping app rather than email, making it more believable and more likely to fool consumers. Users should avoid calling numbers shown on unexpected Shop receipts, verify charges directly with their bank or merchant, and reset credentials and contact their card issuer if they already engaged with the scammers.
Sources: Order-tracking app Shop abused to push callback phishing attacks
DOJ, Thai police and tech firms disrupt 1.4 million scam accounts tied to Southeast Asia fraud compounds
Law enforcement and major tech companies say they disrupted more than 1.4 million accounts and related infrastructure used by scam networks operating from Southeast Asia. The operation, called Disruption Week, involved the US Department of Justice, Royal Thai Police, and firms including Apple, Google, Meta, Microsoft, Coinbase, SpaceX, Silent Push, TRM Labs, and Zenlayer; it led to 63 arrests, the freezing of over $3.8 million in cryptocurrency, and takedowns of social-media accounts, Microsoft accounts, Starlink kits, servers, and malicious network infrastructure linked to fraud compounds in Cambodia, Laos, and Burma. — This matters because the operation targeted industrial-scale scam networks that steal money from victims worldwide and rely on mainstream platforms and connectivity to operate. Users should remain cautious of investment and impersonation scams, while defenders and platforms should watch for follow-on account rebuilds, infrastructure shifts, and related fraud activity.
Sources: Over 1.4 Million Accounts Disrupted in Cybercrime Crackdown, Local Police Collusion Hampers Crackdown on Asian Scam Centers
Third defendant sentenced over 2022 DraftKings credential-stuffing attack that hijacked 60,000 betting accounts
A third man has been sentenced for his role in the 2022 attack that broke into thousands of DraftKings customer accounts and stole or resold access to them. The Justice Department said the group used credential stuffing, meaning reused usernames and passwords from other breaches, to access more than 60,000 accounts on the fantasy sports and betting platform; Nathan Austad was sentenced to 18 months and ordered to pay about $1.8 million, while the scheme stole roughly $600,000 from 1,600 accounts. — This highlights the ongoing risk of password reuse and account takeover for consumer financial and betting accounts. Affected users should reset reused passwords, enable phishing-resistant multi-factor authentication where available, and review account balances and withdrawal history.
Sources: Third DraftKings Hacker Sentenced to 18 Months in Prison, DraftKings hacker 'Snoopy' sentenced to 18 months in prison
DOJ seizes cloud infrastructure allegedly used by Cambodia's Huione Group to support online scams and money laundering
The U.S. government says it seized a cloud computing account used by subsidiaries of Cambodia-based Huione Group to run backend systems for cyber-enabled scam operations. DOJ said the infrastructure supported Telegram channels advertising stolen credit-card and identity data, malware-theft proceeds, human-trafficking procurement, and laundering help for romance and investment scams. The action follows earlier U.S. financial restrictions after FinCEN alleged Huione laundered at least $4 billion in illicit funds from 2021 to 2025, including proceeds tied to North Korean cyber theft. — This is a significant disruption of infrastructure tied to industrialized scam networks that victimize consumers and help move criminal proceeds across borders. It matters to the public because these operations power romance and investment fraud at scale, and to defenders because it shows the specific platforms and laundering ecosystem authorities are targeting.
Sources: Feds seize alleged cyber-scam infrastructure connected to Southeast Asian company, DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money Laundering
U.S. extradites alleged Market0Day and Spoxy operator over phishing-kit and smishing marketplace scheme
A 26-year-old Algerian man was extradited to the United States after prosecutors accused him of running two cybercrime marketplaces that sold phishing tools and mass-texting services. The Justice Department says Abdellah Belmili, also known as Spox, administered Market0Day in 2020 and later launched Spoxy, where criminals could buy phishing kits, access to compromised email servers, and bulk SMS services for large-scale smishing campaigns. Prosecutors say the scheme targeted major banks including JPMorgan Chase, Bank of America, Wells Fargo, and American Express, involved about 5,600 victims, and brought roughly $900,000 into an account he controlled between 2020 and 2023. — This matters because it shows the infrastructure behind phishing and bank-fraud campaigns, not just individual scams, and names the services used to enable them. Financial institutions and consumers should stay alert for bank-themed phishing emails and text messages, while defenders can use the marketplace names and actor alias to support threat tracking and fraud investigations.
Sources: Algerian Man Extradited to US for Running Cybercrime Marketplaces
JaredFromSubway Ethereum MEV bot lost $15 million after attacker used fake trading pools and token approvals
The JaredFromSubway Ethereum trading bot lost about $15 million after an attacker tricked it into approving malicious contracts and then drained its funds. According to Blockaid and JaredFromSubway, the attacker created fake MEV (maximal extractable value) opportunities using bogus pools and tokens so the bot would grant ERC-20 spending approvals to attacker-controlled helper contracts; the attacker later used those lingering approvals and the transferFrom function to withdraw WETH, USDC, and USDT. — This is a major crypto theft that shows how automated on-chain trading systems can be manipulated even without directly breaking a blockchain. Crypto firms, bot operators, and smart-contract developers should review approval logic, route validation, and allowance revocation controls immediately.
Sources: JaredFromSubway MEV bot hacked in $15 million crypto theft
FTC says Americans lost a record $3.5 billion to impersonation scams in 2025, with social media driving much of the fraud
The FTC says Americans lost $3.5 billion to impersonation scams in 2025, making them the most reported fraud category and one of the costliest threats facing the public. The agency said losses tied to social media exceeded $2.1 billion, while victims lost nearly $1 billion to business impersonators and about $920 million to government impersonators; common lures arrived by text, phone, email, social media, and search results, often posing as banks or government agencies. — This is a large-scale public safety and fraud story: ordinary people are losing billions after being tricked by fake banks, businesses, and government officials. People should treat unsolicited messages and calls as suspect, avoid moving money based on "security alerts," and verify requests through official contact channels.
Sources: FTC warns of record $3.5 billion losses to imposter scams in 2025, In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum
Microsoft says CryptoBandits Windows malware steals cryptocurrency and uses Tor as a backdoor
Microsoft says a Windows malware family called CryptoBandits is infecting systems and stealing cryptocurrency by swapping copied wallet addresses, while also giving attackers remote access. The campaign has been active since February 2026 and spreads through malicious .lnk shortcut files and infected USB devices. It drops a portable Tor client, uses a local SOCKS5 proxy for hidden command-and-control traffic, achieves persistence with scheduled tasks, and can steal seed phrases, private keys, clipboard data, and screenshots while receiving follow-on commands. — This matters to both consumers and organizations because an infection can silently redirect crypto payments and provide attackers with ongoing access to a Windows device. Defenders should watch for suspicious .lnk files, USB-based propagation, unexpected local SOCKS5/Tor activity, and script execution via Windows Script Host, while users should avoid opening untrusted shortcut files and verify wallet addresses before sending funds.
Sources: CryptoBandits Malware Doubles as a Backdoor, Abuses Tor
New York man charged with cyberstalking after using fake accounts and AI-generated nude images to harass a college student
A New York man was charged after prosecutors say he used fake social-media and email accounts to harass a Georgia college student with AI-generated nude images and false messages. Federal prosecutors say Anthony Belford created spoofed accounts on Instagram, LinkedIn, Reddit, X, Strava, and Yahoo between January and March 2025 to impersonate the victim, circulate fabricated racist and anti-Muslim statements, and send an AI-generated nude image to the victim's mother. — This is a concrete example of AI-generated intimate-image abuse and impersonation being used for targeted harassment, showing how synthetic media can intensify stalking and reputational attacks. It matters to the public because victims should preserve evidence, report abusive impersonation and nonconsensual intimate-image sharing quickly, and push platforms to remove content fast.
Sources: NY man charged after harassing college student with AI-generated nudes
Microsoft says USB shortcut worm is spreading crypto-stealing clipper malware through infected Windows drives
Microsoft says a Windows malware campaign is spreading through USB drives and stealing cryptocurrency by swapping copied wallet addresses with attacker-controlled ones. The malware uses malicious LNK shortcut files to launch from removable media, hides real documents and replaces them with lookalike shortcuts, propagates to newly connected USB devices, and uses Tor for command-and-control. It also looks for seed phrases and private keys, captures screenshots, and supports remote code execution through JavaScript fetched from a .onion address. — This can hit ordinary users and organizations that still share files by USB, especially anyone handling cryptocurrency wallets or recovery phrases. Defenders should watch for suspicious wscript.exe and cscript.exe activity, Tor proxy traffic such as localhost:9050, and unusual shortcut files on removable drives; users should avoid opening unexpected files from USB media and verify wallet addresses carefully.
Sources: USB worm spreads crypto-stealing malware via Windows shortcut files
Rokarolla Android banking trojan targets 217 banking and cryptocurrency apps through fake Chrome and TikTok downloads
A newly reported Android malware strain called Rokarolla is stealing financial data from people who install fake Chrome or TikTok apps from malicious websites. Zimperium says the trojan abuses Android Accessibility permissions, notifications, SMS, and call access, then checks for 217 targeted banking and crypto apps and downloads matching fake login overlays to capture credentials, card data, lock-screen PINs, contacts, SMS, and other device data. The malware also uses 137 command-and-control instructions and can disable Google Play Protect and hide its icon. — This can let criminals take over phones and drain financial accounts, especially when victims sideload apps outside Google Play. Android users should avoid APKs from unofficial sites, review Accessibility requests carefully, and treat unexpected prompts to install Chrome, TikTok, or security updates as suspicious.
Sources: New Rokarolla Android malware targets 217 banking, crypto apps, Rokarolla Banking Trojan Targets 200 Applications
Dutch police arrest six suspects tied to bank helpdesk scam call center that also sent visitors to victims’ homes
Dutch police arrested six suspects after raiding an Amsterdam home they say was being used as a makeshift call center for bank helpdesk fraud. Authorities said the group, whose members were aged 15 to 30, called victims while posing as bank staff and in some cases sent people to victims’ homes to supposedly help secure accounts, then stole money. Police seized laptops, phones, and bank cards and said the suspects were caught while speaking with a potential victim. — This shows social-engineering scams are blending phone fraud with in-person impersonation to make lies feel legitimate, especially for older targets. Banks, families, and potential victims should treat unsolicited calls or home visits about account security as suspicious and verify through official channels.
Sources: Helpdesk scammers are making house calls to make their lies feel more real
iRhythm says social-engineering breach let hackers steal patient health information from third-party business apps
iRhythm disclosed a data breach after hackers stole patient personal and health information from business applications hosted by a third party. The company said the attackers contacted it on June 9, 2026 with a ransom demand and it later confirmed data was exfiltrated; iRhythm says the intrusion involved social engineering and did not affect its cardiac monitoring devices, clinical systems, payment-card data, manufacturing, or distribution operations. — This affects healthcare patients whose protected health information may now be exposed or used in scams and identity abuse. Healthcare organizations and vendors should review third-party app access, harden staff against social-engineering attacks, and watch for follow-on extortion or phishing tied to stolen patient data.
Sources: iRhythm discloses data breach, says hackers stole patient info, Cardiac monitor maker's security skips a beat as data thieves go for the jugular, iRhythm Confirms Data Stolen in Hack
Novo Nordisk says attackers stole pseudonymized clinical-trial patient data and healthcare professional contact details
Novo Nordisk disclosed a security breach in which attackers copied non-public data from internal IT systems, including information tied to some clinical-trial participants and healthcare professionals. The exposed trial data included patient IDs, participation details, sex, year of birth, biomarkers, health and immunogenicity data, and lifestyle factors; the company said it was pseudonymized and not directly linked to names. Exposed healthcare professional data included names, registration numbers, email addresses, phone numbers, WhatsApp details, and office locations. Novo Nordisk has not said how many people were affected or how the intrusion happened. — This affects sensitive health-related research data and gives attackers contact details they can use for follow-on phishing or impersonation. Affected organizations and individuals should watch for suspicious emails, calls, and WhatsApp messages while Novo Nordisk investigates scope and attack path.
Sources: Pharma giant Novo Nordisk discloses breach of clinical trials data, Novo Nordisk reports cyberattack as UK gives Wegovy pill the nod, Ozempic Maker Novo Nordisk Says Hackers Breached IT Systems (+1 more)
DOJ seizes CFAKE and SOCFAKE deepfake porn sites in first publicly announced TAKE IT DOWN Act action
The U.S. Justice Department seized CFAKE.com and SOCFAKE.com, two sites accused of hosting nonconsensual AI-generated nude images and videos of identifiable women. U.S. authorities said the domains violated the TAKE IT DOWN Act, which criminalizes publication of intimate digital forgeries without consent and requires platforms to remove reported content within 48 hours. The operation involved Homeland Security Investigations and law-enforcement partners in Italy and France, and French authorities arrested a suspect in Nice and seized related cryptocurrency. — This shows the TAKE IT DOWN Act is now being used in real enforcement, which matters to victims, platforms that host user content, and anyone tracking abuse enabled by generative AI. Platforms should review takedown processes and compliance timelines, while users should report nonconsensual deepfake imagery quickly.
Sources: DOJ seizes CFAKE, SOCFAKE deepfake nude sites under TAKE IT DOWN Act
FBI warns pig-butchering scammers are sending couriers to collect cash from victims in person
The FBI says cryptocurrency investment scammers are now sending couriers to pick up cash directly from victims after banks or other financial institutions block suspicious transfers. The agency says the fraudsters, often running pig-butchering or romance-baiting scams through social media, dating sites, and messaging apps, authenticate the courier with a password or U.S. dollar bill serial number, then continue the scam by showing fake account gains and demanding more money for bogus taxes or penalties. — This matters because victims may believe an in-person handoff makes the investment scheme legitimate when it is part of the fraud. Consumers should not hand cash to strangers tied to online investment offers, and banks, local police, and fraud teams should watch for courier-based cash collection linked to crypto scams.
Sources: FBI: Fraudsters use couriers to steal money in crypto scams
Europol and DOJ dismantle AudiA6 crypto-laundering service tied to ransomware payments
Authorities say they shut down AudiA6, a cryptocurrency laundering service allegedly used by ransomware groups and other cybercriminals to wash more than $380 million. Europol said the operation was linked to more than 15 ransomware and large-scale crypto-theft investigations, while arrests in Georgia and earlier evidence from a 2025 arrest in Poland helped identify administrators, seize 25 domains, freeze cryptocurrency, and recover about 6,000 know-your-customer identity records tied to mule accounts. — This matters because ransomware profits only scale when criminals can cash out, and AudiA6 allegedly served as a central laundering hub for that process. Crypto platforms, investigators, and organizations tracking extortion activity should watch for related wallet exposure and mule-account abuse, while victims may gain new leads tying attacks to payment flows.
Sources: Authorities dismantle 'AudiA6' ransomware crypto-laundering service, In Other News: Google Security Layoffs, AudiA6 Takedown, $400 Million Coupang Fine
Group-IB links thousands of fake FIFA World Cup 2026 domains to fraud campaigns targeting ticket buyers
Researchers say multiple criminal groups have built fake FIFA websites to steal World Cup fans’ passwords, payment details, and money through bogus ticket sales. Group-IB identified four separate campaigns since August 2025, including a Chinese-speaking operation it calls GHOST STADIUM that uses more than 300 active lookalike domains and roughly 3,800 dormant ones. The phishing kit closely copies FIFA’s login flow, can trigger password-reset steps to lock victims out, and is being promoted through Facebook ads offering unrealistically cheap tickets. — Fans trying to buy 2026 World Cup tickets could lose their accounts, have legitimate tickets resold, or pay scammers for fake seats. Users should only type fifa.com directly into their browser, avoid ad-linked ticket offers, and treat lookalike FIFA domains as suspicious.
Sources: Chinese-speaking fraud gang could be stealing millions from 2026 World Cup fans, FBI warns of fake FIFA websites running World Cup fraud schemes, In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks (+2 more)
OnyxC2 stealer malware is being sold to cybercriminals as a subscription service
A newly analyzed malware service called OnyxC2 is being rented to criminals for as little as $250 a month, giving buyers a ready-made tool to steal passwords, cookies, wallet data, and other sensitive information from infected Windows systems. BlackFog says the stealer targets about 210 applications and browser extensions across browsers, password managers, cryptocurrency wallets, FTP and email clients, and some 2FA extensions, and uses encrypted payloads, DLL sideloading, in-memory execution, HVNC hidden remote control, keylogging, reverse proxying, and LSASS dumping to evade detection and maintain access. — This lowers the barrier for account theft and follow-on fraud or intrusion by packaging advanced credential-stealing and remote-access features as a commercial criminal product. Organizations and consumers should treat it as a high-risk infostealer threat: watch for suspicious installers, strengthen endpoint detection, and rotate credentials and session tokens if infection is suspected.
Sources: OnyxC2 Stealer Offers Cybercriminals Enterprise-Grade Theft for $250 a Month
Suspected North Korean phishing campaign sends fake developer job offers to steal credentials and cryptocurrency
A likely North Korean-linked group sent more than 250 fake job and code-review emails to developers at nearly 100 organizations, mainly in the United States, to steal login credentials and cryptocurrency wallets. Proofpoint tracks the activity as UNK_DeadDrop and says the attackers used spoofed company brands and attacker-controlled GitHub repositories posing as coding tests or crypto projects; victims were told to clone and open the repos in tools such as Visual Studio Code or Cursor, triggering cross-platform malware on macOS, Linux, and Windows. — Developers and the companies that employ them are the direct targets, and a single successful lure can expose source code, cloud access, and crypto assets. Organizations should warn staff about unsolicited recruiting emails, scrutinize GitHub-based coding tests, and isolate or block unknown repositories and scripts.
Sources: Norks blast 250+ fake job offers to developers over 6 weeks to try and snarf creds and crypto
NFCShare Android malware uses fake banking app updates on GitHub to steal payment card data from European bank customers
Attackers are tricking bank customers into installing fake Android banking app updates from GitHub so they can steal card data and PINs. D3Lab says newer NFCShare variants, seen since May 14, target banks mainly in Italy and Spain after victims visit phishing sites impersonating real banks. The malware abuses near-field communication (NFC) on Android to read card details via IsoDep and EMV commands, then sends the data to command-and-control servers over WebSocket. — This can lead directly to payment-card fraud because victims are persuaded to hand over both card details and their PIN during a fake security check. Android users should only install banking apps from Google Play and treat any request to scan a bank card with their phone or sideload an update from GitHub as suspicious.
Sources: NFCShare Android malware spreads via fake banking app updates on GitHub
FBI warns Silent Ransom Group is sending fake IT workers in person to law firms to plug in USB drives and steal data
The FBI says Silent Ransom Group is targeting U.S. law firms by pretending to be IT support, then stealing data and extorting victims without encrypting files. In 2026 attacks, the group reportedly used callback phishing emails, phone-based social engineering, remote desktop access, and in some cases sent an operative on site to insert a USB or external drive after a failed remote-access attempt; the attackers then used tools such as WinSCP and Rclone to exfiltrate data. — Law firms and other organizations should treat unsolicited IT calls, emails, and in-person support visits as potential attack vectors, not just remote phishing. The warning is urgent because the attackers use legitimate admin tools and leave few traces, so organizations should verify IT identities, restrict external-drive use, and harden remote-access workflows now.
Sources: FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data, FBI warns of in-person data theft attacks from extortion gang, FBI warns extortion hackers are visiting US law firms to steal data (+4 more)
Microsoft links GPU cryptojacking malware campaign to poisoned search results and AI chatbot software recommendations
Attackers are tricking people looking for popular PC utilities into installing malware that secretly uses their graphics cards to mine cryptocurrency. Microsoft says the campaign uses search-engine optimization (SEO) poisoning and, in some cases, attacker-controlled links surfaced in AI chatbot responses for tools such as CrystalDiskInfo, HWMonitor, FurMark, K-Lite Codec Pack, PDFgear, and Display Driver Uninstaller. The fake downloads bundle a legitimate program with a malicious dynamic-link library (DLL), install ScreenConnect for remote access, add multiple Windows persistence mechanisms, evade Microsoft Defender, and then deploy GPU miners including gminer, lolMiner, and SRBMiner-MULTI. — This campaign targets owners of powerful Windows systems and can leave victims with both hijacked hardware and a remote-access backdoor for follow-on attacks. Users and defenders should avoid downloading software from AI-generated or unfamiliar links, verify vendor domains, and hunt for the listed indicators of compromise and unauthorized ScreenConnect installs.
Sources: GPU mining malware spreads via SEO poisoning, AI chatbots, In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA
Magecart campaign uses Google Tag Manager and Stripe API to steal payment cards from Magento checkout pages
Researchers say a new Magecart card-skimming campaign is stealing shoppers’ payment details from compromised online stores and hiding both its malware and stolen data inside trusted Google Tag Manager and Stripe services. Sansec says the skimmer targets Magento and Adobe Commerce checkout pages, pulls JavaScript from a Google Tag Manager container, retrieves payload code from Stripe customer metadata tied to customer ID cus_TfFjAAZQNOYENR, and exfiltrates stolen card, billing, email, and phone data by creating fake Stripe customer records; a variant uses Google Firestore instead of Stripe. The Stripe record was reportedly created on December 24, 2025, suggesting the campaign may have been active for months. — This matters because stores may allow traffic to Google Tag Manager and Stripe by default, letting the skimmer blend in and evade common security controls while stealing card data from real customers. Online retailers using Magento or Adobe Commerce should urgently inspect GTM containers, Stripe API activity, and checkout-page scripts for unauthorized changes.
Sources: Credit card theft campaign abuses Stripe to host stolen payment info
Proofpoint says TA4922 is targeting European organizations with new Atlas RAT malware and phishing lures
A Chinese-speaking cybercrime group is using new malware and localized phishing messages to break into organizations in Europe and beyond. Proofpoint says TA4922, linked to activity overlaps with Silver Fox and Void Arachne, has targeted entities in Germany, Italy, the United Kingdom, South Africa, and parts of Southeast Asia since March 2026 using payroll, tax, VAT, invoice, and HR lures sent by email and messaging apps including WhatsApp, LINE, and Microsoft Teams. The campaigns deploy Atlas RAT, RomulusLoader, SilentRunLoader, and Winos4.0/ValleyRAT for remote access, file theft, credential theft, keylogging, screenshots, and webcam or audio capture. — Organizations in the targeted regions should treat this as an active intrusion and phishing threat, especially finance, HR, and compliance teams that may receive convincing local-language messages. Defenders should hunt for the named malware families and remote-management tools, tighten phishing controls, and warn staff to verify unexpected payroll, tax, invoice, or compliance messages across email and chat platforms.
Sources: Chinese hackers use new Atlas RAT malware in European cyberattacks, Chinese Cybercrime Group in Spotlight for Record Campaign Pace, China-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South Africa
Europol-backed Operation KRATOS 2 dismantles nine illegal streaming crime groups across 13 countries
Police in Europe and the United States say they broke up nine organized crime groups running illegal streaming services and arrested 29 suspects. The seven-month Operation KRATOS 2, led by Bulgaria with Europol support, involved 13 countries and led to the removal of more than 27,000 illegal streaming URLs, identification of 18,000 IP addresses tied to illegal services, 4,370 piracy-linked domains, nearly 400,000 additional URLs flagged for suspension, and 126,000 infringing objects. Investigators say the operators split public-facing sites from backend hosting across jurisdictions to evade takedowns. — People using pirate streaming services are not just risking copyright trouble; Europol says these platforms can also expose users to malware, spyware, and theft of personal data. The story matters because it shows the scale and international reach of the criminal infrastructure behind these services, and affected users should avoid such platforms and check devices for suspicious software if they used them.
Sources: Police dismantles 9 crime groups in illegal streaming crackdown
Google rolls out Android fake-call detection to warn users about AI voice-clone and caller-ID spoofing scams
Google is adding a new Android feature that warns people when a call may be a scammer pretending to be someone they know. The feature, called fake call detection, is rolling out globally this month on Android 12 and later, starting with Pixel devices, and is enabled by default. It works when both parties use Phone by Google, Contacts, and Google Messages with Rich Communication Services (RCS) enabled, using encrypted device-to-device verification to detect spoofed contact calls and trigger an on-screen warning. — This addresses a real-world fraud tactic that combines fake caller ID with AI-generated voice impersonation, which can trick people into sending money or revealing sensitive information. Android users should keep Google's phone and messaging apps updated and treat urgent calls asking for money, codes, or account access with caution.
Sources: Google adds Android protection against AI deepfake scam calls
WeedHack malware campaign infects more than 116,000 systems through fake Minecraft mods and cheats
A large malware campaign has infected more than 116,000 computers by tricking Minecraft players into downloading booby-trapped mods, cheat clients, and utilities. McAfee says the WeedHack operation has been active since January 2026, spreads via YouTube links and search-result manipulation, and uses thousands of malicious Java archive (JAR) files. The malware steals browser passwords and cookies, Minecraft session IDs, Discord, Steam and Telegram credentials, and crypto-wallet data, while paid tiers add remote-control features such as keylogging, webcam access, shell access, and file management. — This is a broad consumer-focused infostealer campaign hitting gamers at scale, with stolen passwords, session tokens, and wallet data creating immediate account-takeover and financial risk. Minecraft players and parents should avoid unofficial mod download sites, remove suspicious JAR files, run antivirus scans, and reset passwords for any accounts used on affected devices.
Sources: Over 116,000 Mincraft systems infected in WeedHack malware campaign, Over 116,000 Minecraft systems infected in WeedHack malware campaign
Scammers spoof Northern Ireland police phone number to pose as officers and demand bank details and gift-card payments
The Police Service of Northern Ireland warned that scammers spoofed its official switchboard number to call people while pretending to be police officers. In the reported case, the caller falsely claimed the target was tied to a money-transfer investigation, asked for bank-card information, and then requested gift cards and their codes; police said the number display was faked and no suspect has yet been arrested. The same police force also disclosed a separate crypto-investment fraud in which an elderly woman lost more than £250,000 after attackers persuaded her to install malware and took control of her devices. — People may trust a call that appears to come from a real police number, so this scam raises the risk of financial theft even for cautious users. Anyone receiving such a call should hang up, independently verify the number, and never provide banking details or gift-card codes to someone claiming to be law enforcement.
Sources: Northern Ireland cops issue PSA after official phone number spoofed by scammers
Researchers track 5,000+ election-themed domains and exposed political credentials ahead of the 2026 U.S. midterms
Security researchers say more than 5,000 election-themed internet domains were registered in recent weeks ahead of the 2026 U.S. midterms, raising the risk of fake voting sites, donation scams, and impersonation of election officials. Check Point said the registrations increased sharply between April and May and coincided with roughly 17,000 exposed credentials tied to ActBlue, WinRed, GOP, Democrats.org, and USA.gov accounts, creating infrastructure and account access that could support phishing, fraud, or influence operations. — This matters because voters, donors, campaigns, and election workers could be tricked by lookalike sites or targeted through reused or stolen passwords. People should verify election and donation websites carefully, avoid links in unsolicited messages, and reset passwords if they may have been exposed.
Sources: Election interlopers register 5K+ domains, hope to catch some voting phish
Charter confirms breach after ShinyHunters claims it stole customer data through a vishing attack
Charter Communications says it suffered a security incident after the ShinyHunters extortion group threatened to leak stolen data. The attackers claim they breached Charter on April 1 by using voice phishing (vishing) to compromise an employee's Microsoft Entra account, then used access to Charter's Salesforce environment to export about 40 million customer records, including names, contact details, plan information, support tickets, and some customer proprietary network information (CPNI); Charter disputes that sensitive personal data or CPNI was exfiltrated. — Charter serves tens of millions of customers, so even partial account and service data exposure could create follow-on phishing, fraud, and impersonation risks. Affected users should watch for targeted calls and emails referencing Spectrum or account details, while defenders should review identity-provider protections, help-desk verification, and Salesforce access logs.
Sources: Charter confirms data breach after ShinyHunters extortion threat, Charter Communications data breach affects 4.9 million accounts, ShinyHunters adds Charter to trophy shelf after 4.9M customer records leak (+1 more)
U.S. man sentenced for selling personal data of 7 million elderly Americans to Jamaican lottery scammers
A North Carolina man was sentenced to prison for selling elderly Americans' personal information to scammers who used it in lottery fraud schemes. Troy Murray pleaded guilty to conspiracy to commit wire fraud and was sentenced to 121 months after prosecutors said he sold at least 22,000 lead lists between 2016 and 2023 containing names, phone numbers, physical addresses, and email addresses of over 7 million seniors; authorities said the scheme generated more than $5.2 million for him and caused over $9.5 million in victim losses. — This matters because it shows how stolen or traded personal data directly fuels large-scale fraud against older adults. People, especially seniors and their families, should be wary of unsolicited calls or messages about prizes or lotteries, and defenders and policymakers can use the case as a concrete indicator of fraud infrastructure and data-broker abuse.
Sources: Man sent to prison for selling data of 7 millions elderly Americans
ESET warns BTMOB Android malware sold as a kit can steal data and remotely control infected phones
A newly highlighted Android malware family called BTMOB can give criminals broad control over infected phones, including stealing data and taking over the device. ESET says the remote access trojan (RAT) is spread through phishing pages and fake app stores, abuses Android Accessibility Services to gain elevated privileges, and is sold with an APK-building kit that lets buyers customize lures by country and brand. The campaign has mainly been observed in Latin America. — This is more serious than a typical banking trojan because it can turn an Android phone into a remotely controlled spying and theft tool. Android users should avoid app downloads from links in messages or fake stores, and defenders should watch for phishing infrastructure and abuse of Accessibility permissions.
Sources: New BTMOB Android Malware Enables Full Device Takeover, BTMOB Android malware service generates custom phishing payloads
Italy dismantles CINEMAGOAL app operation that stole Netflix, Disney+, Sky, DAZN and Spotify access codes
Italian authorities say they dismantled CINEMAGOAL, a piracy app operation that let customers watch paid streaming services by using stolen or fraudulently obtained access credentials. Investigators say the system used virtual machines in Italy to capture valid authentication and decryption codes from legitimate subscriptions every three minutes, then redistributed them through servers seized in France and Germany. The probe, coordinated with Eurojust, included 100 searches, identified more than 70 resellers, and also disrupted a related IPTV service. — This matters because it was not just copyright infringement but a large-scale unauthorized-access and fraud scheme built around stolen streaming credentials and infrastructure designed to hide users. Streaming providers and affected subscribers should watch for fraudulent account creation and abuse, while defenders should note the use of virtual machines, foreign servers, crypto payments, and fake identities to operate the service.
Sources: Italy disrupts CINEMAGOAL piracy app that stole streaming auth codes
Former C.A. Cloud executives plead guilty to helping tech-support scam networks route and hide fraudulent calls
Two former executives of call-tracking firm C.A. Cloud pleaded guilty to concealing a years-long tech-support scam operation that targeted victims worldwide. Prosecutors say the company knowingly provided phone numbers, call forwarding, recordings, and rotating number pools to fraudsters behind fake malware-warning pop-ups, including scammers impersonating Microsoft and Apple; the pair also allegedly ran a Tunisia call center where employees carried out similar fraud through remote computer access and false invoices. — This matters because it shows the infrastructure behind tech-support scams is being targeted, not just the callers themselves, and the scams often hit older and vulnerable people. Users should be wary of pop-ups or calls claiming their computer is infected, especially if they demand remote access or immediate payment.
Sources: Former US execs plead guilty to aiding tech support scammers
Two Americans plead guilty to helping India-based tech-support scam call centers target U.S. victims
Two U.S. men pleaded guilty to helping India-based tech-support scam centers steal millions from Americans, including elderly and disabled victims. Prosecutors said they provided phone numbers, call routing, tracking, and forwarding services for fake malware pop-up scams from 2016 to 2022, continued after learning customers were fraudulent, and advised scammers to rotate large pools of numbers to evade detection; some victims also gave remote access to their devices, leading to financial theft. — This shows how large tech-support scam operations rely on telecom and call-routing support inside the U.S., not just overseas call centers. People should be wary of pop-ups telling them to call for urgent computer help, and providers and defenders can use the case details to spot number rotation and call-forwarding tactics tied to fraud.
Sources: Two Americans plead guilty to assisting India-based tech support scam centers