2026-06-23 16:12 UTC
Independent Research
Krebs on Security · BrianKrebs · indexed 2026-08-15 14:33 UTC
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.
P0
2026-06-18 07:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress was one of many vendors impacted by a recent incident at Klue. We dug into the incident to figure out what happened.
P0
2026-06-11 07:51 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This blog provides a deep-dive into SniperDz, a centralised PhaaS platform with more than 80 ready-made phishing templates impersonating over 30 global brands, and uncovers the hidden infrastructure behind this sophisticated and highly-organized fraud ecosystem.
P0
2026-06-01 08:23 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Learn the most common crypto scam types and how they work in practice. Understand how financial institutions can detect fraud earlier and prevent losses at the fiat-to-crypto boundary.
P0
2026-06-01 07:15 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Merchants face $53B in card fraud losses but lack access to compromised card data. Discover the three barriers keeping merchants in the dark — and the solution.
P0
2026-05-27 06:57 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
With the 2026 FIFA World Cup just weeks away, Group-IB researchers have uncovered six distinct fraud schemes, four independent threat actors, and over 4,300 fraudulent domains impersonating FIFA's official web presence — including a sophisticated phishing operation run by the Chinese-speaking threat actor GHOST STADIUM, whose campaign could cause losses reaching billions of dollars.
P0
2026-05-25 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
While Russian-speaking threat actors have historically dominated the phishing-as-a-service (PhaaS) landscape, a rival ecosystem is rapidly growing within the Chinese-language underground. Google Threat Intelligence Group (GTIG) analyzed a dozen current PhaaS offerings in the Chinese underground, all of them mature services and many likely tied intricately to the broader criminal ecosystem in that region. These services not only lower the barrier to entry for Chinese cyber criminals, but reveal …
P0
2026-05-22 09:13 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Learn what payment fraud is, how it unfolds, and the practical controls that organizations can use at every step of the payment process to reduce losses without harming customer trust.
P0
2026-05-20 06:56 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
An increasing number of data brokers active in Chinese-speaking dark web forums and Telegram channels are advertising large volumes of purportedly stolen data from organizations worldwide. But are they credible?
P0
2026-05-19 09:49 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
A candid conversation on fraud disguised as iGaming growth with Sarah Psaila, Head of Gaming at Group-IB.
P0
2026-05-15 11:28 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Digital brand protection helps organizations detect and disrupt external threats, such as phishing sites, fake social profiles, counterfeit listings, and leaked credentials, before they become customer-facing fraud or reputational damage.
P0
2026-05-15 08:50 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Conflict is a boon for opportunistic fraudsters. Look out for their ploys.
P0
2026-05-13 12:52 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This highly targeted scam scheme uses advanced phishing and social engineering cues, rely on brand recognition, event-based campaigns and emotional manipulation to defraud victims twice.
P0
2026-05-07 08:51 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
ESET researchers uncovered fraudulent apps on Google Play that claim to provide the call history “for any number” and had been downloaded more than seven million times before being taken down
P0
2026-05-06 08:07 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This blog examines how threat actors use deepfake impersonation and social media to manipulate real stocks, how a network of 208 connected fake investment platforms steals millions in cryptocurrency, and what a new approach to defence can do about it.
P0
2026-04-27 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
See how Huntress EDR/ITDR Correlations stop infostealer-driven attacks before stolen credentials can be reused, linking endpoint compromise to cloud identities for one coordinated response.
P0
2026-04-22 06:53 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
How corporate/retail accounts are exploited for financial fraud through sophisticated device fingerprinting and mule networks.
P0
2026-04-15 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
Written by: Jamie Collier, Robin Grunewald Germany has reclaimed its position as a primary focus for cyber extortion in Europe. While data leak site (DLS) posts rose almost 50% globally in 2025, Google Threat Intelligence (GTI) data shows that the surge is hitting German infrastructure harder and faster than its regional neighbors, marking a significant return to the high-pressure levels previously observed in the country during 2022 and 2023. Cyber Criminals Pivoting Back to Germany Germany mo…
P15
2026-04-10 09:00 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
If you’ve been a victim of fraud, you’re likely already a lead on a ‘sucker list’ – and if you’re not careful, your ordeal may be about to get worse.
P0
2026-04-09 17:07 UTC
Vendor Research
Google Online Security Blog · Google · indexed 2026-08-15 14:33 UTC
Posted by Ben Ackerman, Chrome team, Daniel Rubery, Chrome team and Guillaume Ehinger, Google Account Security team Following our April 2024 announcement, Device Bound Session Credentials (DBSC) is now entering public availability for Windows users on Chrome 146, and expanding to macOS in an upcoming Chrome release. This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape. Session theft t…
P0
2026-04-01 09:00 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Fraudsters often target the accounts of the deceased or their grieving relatives. Here’s how to keep the scammers at bay.
P0
2026-03-30 15:25 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Global regulators are mandating fraud intelligence sharing. Learn how financial institutions can collaborate in real-time while maintaining privacy compliance through Distributed Tokenization.
P0
2026-03-25 07:09 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Tracing the evolution of cloud phone technology from harmless social media engagement automation to industrial-scale financial fraud that’s invisible to modern detection systems.
P0
2026-03-23 15:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Uncover the dark economy of cybercrime, from organized scam centers and the criminal customer journey to the use of generative AI in scaling attacks.
P0
2026-03-12 05:00 UTC
Vendor Research
Cloudflare Security · Jin-Hee Lee · indexed 2026-08-15 18:58 UTC
Blocking bots isn’t enough anymore. Cloudflare’s new fraud prevention capabilities — now available in Early Access — help stop account abuse before it starts.
P0
2026-03-12 05:00 UTC
Vendor Research
Cloudflare Security · Jin-Hee Lee · indexed 2026-08-15 18:58 UTC
Blocking bots isn’t enough anymore. Cloudflare’s new fraud prevention capabilities — now available in Early Access — help stop account abuse before it starts.
P0
2026-03-05 08:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Cybercrime and RMM abuse is up 277% as attackers exploit trusted tools for stealthy access. Learn how to shift from overtrust to verifying behavior and secure your network.
P0
2026-02-26 08:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
From an IT job to forced underground cybercrime, Mohammad’s story exposes the global trafficking network behind massive crypto scams. Learn the signs to stay safe.
P0
2026-02-25 15:17 UTC
Vendor Research
Google Online Security Blog · Edward Fernandez · indexed 2026-08-15 14:33 UTC
Posted by Lyubov Farafonova, Product Manager, Phone by Google; Alberto Pastor Nieto, Sr. Product Manager Google Messages and RCS Spam and Abuse We’ve shared how Android’s proactive, multi-layered scam defenses utilize Google AI to protect users around the world from over 10 billion suspected malicious calls and messages every month1. While that scale is significant, the true impact of these protections is best understood through the stories of the individuals they help keep safe every day. This…
P0
2026-02-20 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
AI-driven deception is the new reality in hiring. Explore key statistics on deepfakes and resume fraud, and learn data-informed strategies to solidify your defense.
P0