2026-08-16 08:55 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-16 18:35 UTC
France’s tax agency says hackers stole data on 678,000 taxpayers, including income and tax details, in a sophisticated cyberattack. A threat actor claimed to have breached France’s tax agency in late June. France’s tax administration confirmed that a cyberattack exposed personal data of 678,000 individuals and businesses, prompting an immediate criminal investigation. The cybercrime unit […]
P0
2026-08-14 20:31 UTC
Security Journalism
The Record · indexed 2026-08-15 18:55 UTC
Germany’s federal police agency, the BKA, said three suspects were picked up in Europe and charged with fraud, and Brazil’s federal police said four others were arrested on similar charges.
P0
2026-08-14 18:04 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-15 14:33 UTC
Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers' bank accounts. [...]
P0
2026-08-14 07:54 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC
The China-linked threat actor known as Jewelbug has been observed carrying out cyber espionage operations targeting governments and militaries, while simultaneously engaging in cryptocurrency fraud. "Both missions are administered from a single control panel, XG-Web, a browser-centric remote-access and information-stealing framework that turns a victim's browser into a full remote-control
P0
2026-08-13 21:12 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-15 14:33 UTC
Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams or tried to obtain access to bank accounts. [...]
P0
2026-08-13 18:15 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-15 14:33 UTC
The Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud. [...]
P0
2026-08-13 11:53 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC
A previously unseen Android near field communication (NFC) relay malware family dubbed WindRelay is being deployed in conjunction with a known remote access trojan (RAT) called SpyNote as part of a contactless payment fraud scheme. The purpose-built malware, according to Group-IB, is designed to capture live card data via NFC and transmit it to fraudsters in real time. It was first detected in
P0
2026-08-13 07:26 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
More than a quarter of stolen funds are gone within fifteen minutes of the fraudulent transfer. That number ends the case-file era — and points to where the time can be won back.
P0
2026-08-12 06:58 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
A new NFC relay malware designated as WindRelay, paired with SpyNote RAT enables live-call fraud, combining social engineering with dual digital and physical cash-out.
P0
2026-08-10 17:09 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-08-15 18:55 UTC
Sophisticated iPhone exploit chains previously limited to nation-states are spreading far and wide to organized cybercrime groups.
P0
2026-08-10 16:25 UTC
Security Journalism
Dark Reading · Arielle Waldman · indexed 2026-08-15 18:55 UTC
A public policy expert mapped global cybercrime laws to develop a five-point framework for protecting ethical hackers and good-faith security research.
P0
2026-08-10 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Go inside Huntress and the FBI’s five-year pursuit of Silk Typhoon, from 88,000 Exchange backdoors to an arrest and a wider fight against cybercrime.
P0
2026-08-06 21:42 UTC
Security Journalism
Dark Reading · Arielle Waldman · indexed 2026-08-15 18:55 UTC
The fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still operates in silos.
P0
2026-08-06 17:00 UTC
Independent Research
Krebs on Security · BrianKrebs · indexed 2026-08-15 14:33 UTC
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers.
P0
2026-08-05 23:35 UTC
Security Journalism
Dark Reading · Tara Seals · indexed 2026-08-15 18:55 UTC
Organized crime is convincingly scamming at scale, making billions thanks to AI-enabled voice cloning, deepfake real-time video overlays, LLM-driven persona management, and automated translation.
P0
2026-08-05 07:19 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Map any fraud campaign against your org chart and one stage of the attack has no owner. The adversary knows exactly which one — and the most expensive fraud cases live there.
P0
2026-07-31 13:30 UTC
Security Journalism
Dark Reading · Robert Lemos · indexed 2026-08-15 18:55 UTC
When a fraudulent transaction occurs, law enforcement agencies must work quickly to halt payments before cybercriminals cash out.
P0
2026-07-30 16:49 UTC
Independent Research
Krebs on Security · BrianKrebs · indexed 2026-08-15 14:33 UTC
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
P0
2026-07-30 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
Written by: Kelli Vanderlee, Stuart Carrera For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise of SolarWinds and North Korean cyber espionage actor UNC4736's 2023 compromise of 3CX. However, Google Threat Intelligence Group (GTIG) has been tracking growth in threat activity targeting open source software repositories to…
P15
2026-07-30 07:40 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Managed cyber-fraud protection is the most overlooked growth line in the MSSP playbook, and most of the capability is already sitting in your SOC.
P0
2026-07-28 13:00 UTC
Vendor Research
Rapid7 · Mikayla Wyman · indexed 2026-08-15 18:55 UTC
For years, security operations followed a familiar sequence: detect suspicious activity, investigate what happened, and respond before it caused significant harm. That model developed in a threat landscape where defenders had considerably more time to establish the facts and decide what to do next. In 2019, the average data breach took 206 days to identify and another 73 days to contain, creating a total breach lifecycle of 279 days.As the time between initial access and attacker movement conti…
P0
2026-07-27 09:32 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Most business email compromise (BEC) attacks start with stolen credentials, not a malicious email. Group-IB uses threat intelligence to detect compromised accounts before attackers log in — predicting BEC before it starts.
P0
2026-07-23 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Meet Channel Account Manager Andrew Schlemmer, and learn how his personal experience with cybercrime fueled his mission to make enterprise-grade security attainable and accessible for businesses of all sizes.
P0
2026-07-21 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Discover what initial access brokers (IABs) are, how they compromise networks to sell their access to other attackers, and how to protect your business.
P0
2026-07-14 08:18 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB discovers a sophisticated multi-layered scam scheme targeting fans with fake ticket sales on two fronts: social network platforms and fraudulent websites impersonating official distributors.
P0
2026-07-13 07:48 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover how Distributed Tokenization identifies compromised cards at pre-authorization without exposing raw card data — a technical deep-dive for fraud operations and risk teams.
P0
2026-07-08 12:31 UTC
Independent Research
Krebs on Security · BrianKrebs · indexed 2026-08-15 14:33 UTC
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.
P25
2026-07-07 08:26 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This blog covers Group-IB’s overview of Scattered Spider, backed by Group-IB’s proprietary intelligence, providing additional information to what has already been reported publicly, with added clarification on 0ktapus and how it is related to Scattered Spider.
P0
2026-07-03 12:36 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
AI is changing cybercrime, but SMB cyber readiness still largely depends on closing the familiar gaps
P0
2026-06-29 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Cybercriminals are hijacking Microsoft 365 accounts in seconds. Learn the 2026 hacker tactics, including ConsentFix, that bypass security training and exploit normal user behavior.
P0