2026-09-23 13:56 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-23 14:20 UTC
ShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet. The popular cybercrime group ShinyHunters is claiming that it breached the U.S. Federal Bureau of Investigation (FBI) and stole sensitive information belonging to FBI employees and job applicants. The group says the operation was not financially motivated and was instead […]
P25
2026-09-23 11:23 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-23 11:30 UTC
The cybercrime platform leveraged AI at every step of the attack chain, including writing social engineering messages and deciding targets. The post AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft appeared first on SecurityWeek.
P0
2026-09-23 07:13 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-23 07:30 UTC
The cybercrime group is unhappy with its description in an FBI report and threatens to leak stolen information. The post ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report appeared first on SecurityWeek.
P0
2026-09-22 15:51 UTC
Security Journalism
The Record · indexed 2026-09-22 16:00 UTC
Available on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts, analyze breached inboxes and find the best methods for monetizing their access through fraud.
P0
2026-09-21 20:07 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-09-21 20:30 UTC
ShinyHunters defaced Cl0p's Dark Web site and claims to have stolen victim data, potentially exposing organizations that paid ransoms to renewed extortion attempts.
P0
2026-09-21 14:00 UTC
Security Journalism
The Record · indexed 2026-09-21 14:15 UTC
The ShinyHunters extortion group hijacked the dark web leak site of the prolific Cl0p ransomware gang, according to material posted on the site over the weekend.
P15
2026-09-17 05:59 UTC
Other
Group-IB · indexed 2026-09-17 08:35 UTC
Most fraud platforms only see a threat once it becomes a transaction. This guide compares the top 5 fraud prevention platforms for banks and fintechs in 2026, including Group-IB, Feedzai, Sift, DataVisor, and Kount, and what actually separates them.
P0
2026-09-16 12:45 UTC
Security Journalism
The Record · indexed 2026-09-16 13:00 UTC
Ukraine’s parliament has approved tougher criminal penalties for involvement in fraudulent call centers and the theft of personal data, following a corruption scandal in which prosecutors were accused of taking bribes to protect scam operations.
P0
2026-09-16 07:00 UTC
Other
Group-IB · indexed 2026-09-16 08:20 UTC
Attacks now are cheap, fast, and outsourced. The recent research shows what it changes and how organizations should strategy defense.
P0
2026-09-15 14:22 UTC
Security Journalism
The Record · indexed 2026-09-15 14:40 UTC
Houston-based CenterPoint Energy notified federal regulators about an incident that exposed some customer data on the dark web.
P0
2026-09-15 09:50 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-15 10:00 UTC
Five alleged leaders of the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud, have been extradited to the United States to face wire fraud and money laundering charges. [...]
P0
2026-09-14 12:00 UTC
Security Journalism
The Record · indexed 2026-09-14 12:20 UTC
British fintech company Revolut confirmed disclosing sensitive customer data to fraudsters who submitted emergency data requests from a legitimate government email account.
P0
2026-09-14 09:56 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-14 10:10 UTC
Stolen credentials were used in a multi-month campaign to access subscriber personal data and billing records. The post Telus Warns Customers of Account Breaches appeared first on SecurityWeek.
P0
2026-09-13 10:11 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-13 10:25 UTC
Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers
P0
2026-09-12 21:05 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-12 22:10 UTC
Revolut handed over KYC documents, selfies, and Bitcoin transaction histories after a fake government email with valid domain credentials passed its checks. Revolut confirmed on September 12, 2026, that it disclosed sensitive customer data to an unauthorized third party after receiving fraudulent information requests sent from an email address operating inside an actual government agency’s […]
P0
2026-09-12 16:46 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-12 17:20 UTC
AI is becoming an operational force for cybercrime, surveillance, propaganda, fraud and weapons development, lowering the cost and scale of attacks. Artificial intelligence (AI) is becoming more than a tool for people who want to do something malicious. It is increasingly becoming part of the operational machinery itself. That is the main message emerging from […]
P0
2026-09-11 20:00 UTC
Security Journalism
The Record · indexed 2026-09-11 20:20 UTC
The Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters, saying it originated with the theft of credentials stored on a police officer's personal device.
P0
2026-09-11 19:21 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-09-11 19:50 UTC
Cybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI.
P0
2026-09-11 18:40 UTC
Security Journalism
The Record · indexed 2026-09-11 17:50 UTC
Researchers analyzed a flood of fraudulent business emails and found that the threat actors had doubled-up on tactics to make them appear legitimate, including help from AI.
P0
2026-09-11 13:33 UTC
Vendor Research
Rapid7 · Gal Givon · indexed 2026-09-11 15:05 UTC
IntroductionThe surge in emerging threat actors directly correlates with the rapid escalation of victim counts and stolen financial resources. Simultaneously, this growth has spurred the proliferation of specialized supply storefronts across social media platforms, dark web channels, and various smaller niche marketplaces. Security teams today face evolving challenges, requiring them to continuously refine monitoring channels, adjust operational strategies, and foster cross-functional internal …
P0
2026-09-10 17:23 UTC
Vendor Research
Microsoft Security Blog · Microsoft Security Research · indexed 2026-09-10 19:15 UTC
Microsoft examines an AI-assisted business email compromise campaign that used executive impersonation and fake invoices to target finance teams with ACH payment fraud. The post Protecting organizations from AI-assisted executive impersonation and invoice fraud appeared first on Microsoft Security Blog.
P0
2026-09-10 16:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn what credential theft is, how attackers steal credentials, and how to prevent credential-based attacks with identity-focused defenses from Huntress.
P0
2026-09-09 15:37 UTC
Security Journalism
The Record · indexed 2026-09-09 15:55 UTC
The first public cybersecurity strategy issued by the FBI "directs our teams, our field offices, our global presence" to align their efforts on countering malicious hackers and cybercrime groups, senior official Brett Leatherman says.
P0
2026-09-09 08:44 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-09 08:45 UTC
An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims using AI-generated sexually explicit content. [...]
P0
2026-09-08 20:35 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-08 20:40 UTC
A massive operation dubbed "DoppelCart" uses more than 119,000 domains to run a network of fake e-shops that steal payment card details. [...]
P0
2026-09-07 19:40 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-07 19:55 UTC
Condé Nast user data from 32.8 million accounts is reportedly for sale, raising risks of targeted phishing, fraud and scams. A database said to contain 32.8 million Condé Nast user records is being offered for $15,000 on a Russian-language cybercrime forum. Ransomnews reviewed a 5,000-record sample and concluded that it is consistent with genuine Condé […]
P0
2026-09-07 11:50 UTC
Security Journalism
The Record · indexed 2026-09-07 12:05 UTC
Another trove of data from Berlin's government has appeared online, authorities said. Germany's information security agency separately warned about the Rhysida cybercrime group.
P0
2026-09-07 07:19 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-07 08:30 UTC
Berlin refused a 30 Bitcoin ransom, leading hackers to leak 6TB of sensitive state administration and national defense data on the dark web. When a ransomware gang dumps nearly six terabytes of state administration files onto the dark web, ignoring them does not make the problem go away. The Rhysida ransomware group recently carried out […]
P15
2026-09-04 07:02 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-04 07:55 UTC
FBI probes suspected breach at IDScan.net after dark web service Nexus offered 153M+ US and Canadian driver’s license scans. A dark web identity theft service called Nexus appeared on September 1, 2026, offering searchable access to more than 153 million scanned driver’s licenses belonging to people in the United States and Canada. The FBI’s New […]
P0
2026-09-03 15:26 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 16:45 UTC
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial
P0