Visualização normal

Ontem — 8 de Setembro de 2026Cybersecurity News
  • ✇Cybersecurity News
  • Phantom Deal Scam Targets Executives With Fake NDAs Do Son
    The Phantom Deal campaign uses fake acquisition documents to target executives. Gen exposed the Phantom Deal fraud after tracking bogus payment demands. Related Posts: Outsider Phishing Kit Survives Operation Ghost Hook Takedown Microsoft Teams IT Support Impersonation Leads to Domain Takeover Chinese Actor Gambling Goblin Hijacks Brazilian Gov Sites The post Phantom Deal Scam Targets Executives With Fake NDAs appeared first on Daily CyberSecurity.
     
Antes de ontemCybersecurity News
  • ✇Cybersecurity News
  • BREEZE COMET Threat Actor Attacks Brazilian Banks Do Son
    Google warns the BREEZE COMET threat actor attacks Brazilian banks to execute mass financial fraud. Learn how to protect your payment systems. Related Posts: Dark Caracal Deploys New GoCaracal Malware Framework Cambodia Malware Campaign Uses PNG Files to Deliver SparkRAT AnonyMousKIT Uses AI Voice Calls to Unlock Stolen iPhones The post BREEZE COMET Threat Actor Attacks Brazilian Banks appeared first on Daily CyberSecurity.
     
  • ✇Security Affairs
  • Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams Pierluigi Paganini
    INTERPOL’s Operation Jackal IV made 58 arrests and exposed global networks laundering money from scams, fraud and sextortion. INTERPOL announced that Operation Jackal IV, running from November 2025 to June 2026, led to 58 arrests and identified 263 suspects tied to West African organized crime networks, groups like Black Axe that are responsible for a huge share of the world’s romance scams, crypto fraud, and business email compromise (BEC) schemes. “Operation Jackal IV (November 2025 – J
     

Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams

26 de Agosto de 2026, 04:17

INTERPOL’s Operation Jackal IV made 58 arrests and exposed global networks laundering money from scams, fraud and sextortion.

INTERPOL announced that Operation Jackal IV, running from November 2025 to June 2026, led to 58 arrests and identified 263 suspects tied to West African organized crime networks, groups like Black Axe that are responsible for a huge share of the world’s romance scams, crypto fraud, and business email compromise (BEC) schemes.

“Operation Jackal IV (November 2025 – June 2026) aimed to disrupt money laundering, identify high-value targets, seize assets, and support arrests and prosecution.” Interpol announced. “The operation, which brought together 22 countries from six continents, is a response to the escalating global threat posed by West African criminal networks – such as the Black Axe and other similar groups. These groups are responsible for a significant share of the world’s cyber-enabled financial fraud, typically through romance scams, cryptocurrency and investment scams or business email compromise fraud, as well as other serious and violent crimes.”

The goal wasn’t to chase individual scammers. Investigators followed the money behind the scams: shell companies, mule accounts and criminal services that help move and hide stolen funds. Tomonobu Kaya of INTERPOL’s Financial Crime and Anti-Corruption Centre explained the approach: By following illicit financial flows across borders, we are attacking the very lifeblood of organized crime.

Argentina turned up one of the operation’s biggest finds. Investigators identified 196 individuals connected to a crime-as-a-service network suspected of supplying website domains and laundering support specifically for West African criminal groups, resulting in 17 arrests. INTERPOL sent an Operational Support Team to help analyze seized data and map out the wider network of suspects, the kind of cross-border analytical work that individual national police forces usually can’t pull off on their own.

South African authorities raided seven locations in Johannesburg linked to a group running romance and investment scams against retirees in English-speaking countries.

The syndicate assigned members to specific roles, such as “conversion” and “retention” agents. The operation led to 39 arrests, $2.67 million seized and 257 bank accounts frozen, the largest number of arrests in the operation.

Italy’s case shows how much damage a single laundering account can absorb. One individual was tied to a pan-European laundering network moving money through shell companies and remittance services, and investigators traced €845,000 laundered through a single account across 560 separate transactions using 20 different financial instruments. That’s not a careless operator; that’s someone who understood exactly how to fragment a large sum into a pattern designed to look unremarkable at every individual step.

Romania’s case was the biggest by dollar value, and arguably the most brutal in its simplicity. A call center ran a fake investment scheme promising big returns on stocks and crypto, funneling victims’ money into wallets the operators controlled, and by the time authorities dismantled it, the estimated theft and laundering total had climbed to around €143 million globally. Eleven arrests and roughly €379,000 in cash and crypto seized, plus six properties and several luxury watches, is a real result, but it’s a fraction of what actually got stolen.

“Beyond individual cases, Operation Jackal IV also enabled the analysis of critical and emerging trends, including a rise in West African organized crime groups using sextortion to target minors, with victims as young as 14. Offenders typically contact minors via social media, build trust and coerce them into sharing explicit images or videos.” concludes INTERPOL. “They then threaten to distribute this material to the victim’s contacts unless a ransom is paid.”

The report’s darkest finding sits outside any single country’s arrest count. INTERPOL flagged a rising trend of these same criminal networks using sextortion against minors as young as 14, building trust through social media before coercing victims into sharing explicit images and then threatening to distribute that material unless a ransom gets paid. Some of these groups were even observed buying crime-as-a-service support through the dark web specifically to outsource pieces of that operation, treating exploitation infrastructure as just another service line alongside laundering and fraud.

That’s the uncomfortable throughline connecting every case here: these aren’t scattered opportunists, they’re networks running organized business models with specialized roles, outsourced services, and financial engineering sophisticated enough to move hundreds of millions across borders. Twenty-two countries coordinating for eight months produced real numbers, real arrests, real frozen accounts. It also produced a fairly clear picture of how much more organized this side of cybercrime has become, and how much further there is to go.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Operation Jackal)

  • ✇Firewall Daily – The Cyber Express
  • Global Crackdown on West African Crime Networks Leads to 58 Arrests Samiksha Jain
    An eight-month international operation targeting West African organized crime groups has resulted in 58 arrests and the identification of 263 suspects across 22 countries, according to INTERPOL. Operation Jackal IV, conducted from November 2025 to June 2026, focused on disrupting criminal networks, tracing illicit funds, identifying high-value targets and supporting arrests and prosecutions. The operation brought together countries across six continents to tackle the growing global threat pos
     

Global Crackdown on West African Crime Networks Leads to 58 Arrests

26 de Agosto de 2026, 05:12

West African Organized Crime Groups

An eight-month international operation targeting West African organized crime groups has resulted in 58 arrests and the identification of 263 suspects across 22 countries, according to INTERPOL. Operation Jackal IV, conducted from November 2025 to June 2026, focused on disrupting criminal networks, tracing illicit funds, identifying high-value targets and supporting arrests and prosecutions. The operation brought together countries across six continents to tackle the growing global threat posed by West African criminal networks, including Black Axe and similar groups. These networks have been linked to a significant share of global cyber-enabled financial fraud, including romance scams, cryptocurrency and investment scams, and business email compromise fraud.

Operation Jackal IV Targets West African Organized Crime Groups

Operation Jackal IV also targeted money laundering activities used to move and conceal criminal proceeds across borders. INTERPOL coordinated cross-border intelligence sharing, analysis and operational support during the operation. It also provided specialized training to strengthen international investigations into financial crime. Tomonobu Kaya, Director of the INTERPOL Financial Crime and Anti-Corruption Centre, said the operation showed the importance of international cooperation in following illicit financial flows and disrupting criminal networks. [caption id="attachment_113806" align="aligncenter" width="600"]West African Organized Crime Groups Image Source: INTERPOL[/caption]

Major Arrests and Financial Crime Investigations

In Argentina, authorities identified 196 individuals linked to a major Crime-as-a-Service network suspected of providing website domains and money laundering support to West African organized crime groups. The investigation resulted in 17 arrests, with an INTERPOL Operational Support Team assisting with analysis of seized data and identification of suspects and criminal networks. South African authorities raided seven locations in Johannesburg linked to a syndicate involved in romance and investment scams targeting retirees in English-speaking countries. Investigators arrested 39 people, seized USD 2.67 million and blocked 257 bank accounts. In Italy, investigators identified an individual connected to a pan-European money laundering network that used shell companies, remittance services and cash withdrawals. One account processed EUR 845,000, or about USD 736,000, through 560 transactions involving 20 financial instruments. Romanian authorities dismantled a criminal group operating an investment scam through a call centre. The group promoted high returns from stocks and cryptocurrencies, with victims' money transferred to electronic wallets controlled by perpetrators. Authorities estimated that EUR 143 million had been stolen and laundered globally. Eleven people were arrested, while cash, cryptocurrency, six real estate properties and luxury watches were seized.

Sextortion and Crime-as-a-Service Emerge

Beyond individual investigations, the operation highlighted emerging threats involving sextortion and Crime-as-a-Service. INTERPOL identified an increase in West African organized crime groups using sextortion to target minors, including victims as young as 14. In these cases, offenders typically contacted minors through social media, established trust and persuaded them to share explicit images or videos. They then threatened to distribute the material to the victim's contacts unless a ransom was paid. Investigators also found that some criminal syndicates were procuring Crime-as-a-Service from external providers, including through the dark web. These services were used to outsource activities such as money laundering and other operational functions. While several cases from Operation Jackal IV remain under investigation, the preliminary results demonstrate the scale and international reach of the networks targeted during the eight-month operation. The participating countries were Austria, Argentina, Australia, Canada, Côte d'Ivoire, France, Germany, Indonesia, Ireland, Italy, Japan, Malaysia, the Netherlands, Nigeria, Portugal, South Africa, Spain, Sweden, Switzerland, the United Arab Emirates, the United Kingdom and the United States.
  • ✇Cybersecurity News
  • Balonx Sistema: Mexican PhaaS Adds AI Vishing and RAT Do Son
    Group-IB exposed Balonx Sistema, a Mexican PhaaS platform bundling real-time phishing, an Android RAT, and AI-driven vishing against 20+ banks. Related Posts: Core Werewolf Deploys New CoreRAT Malware Against Russian Targets StopAndProtect Malware Turns Hacked WordPress Sites Into a Botnet Cisco Talos Exposes UAT-10147 Agentic AI Attacks The post Balonx Sistema: Mexican PhaaS Adds AI Vishing and RAT appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Operation ASTERIX: Crypto Scam Used AI and Fake Wallets Do Son
    Rapid7 exposed Operation ASTERIX, a crypto fraud operation using AI, vishing, and fake wallet apps to steal seed phrases from validated holders. Related Posts: Cisco Talos Exposes UAT-10147 Agentic AI Attacks Operation QUICSILVER Targets Myanmar Government With Go Backdoor arrayref Rust Crate Hijacked in Supply Chain Attack With DPRK Infrastructure Overlap The post Operation ASTERIX: Crypto Scam Used AI and Fake Wallets appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Jewelbug APT Group Operations Combine Espionage and Fraud Do Son
    The Jewelbug APT group runs espionage alongside cryptocurrency scams. Read our report on Jewelbug APT group operations. Related Posts: Cisco Talos Discovers JWR Phishing Framework US Agencies Warn of AI-Generated Exploits Targeting Siemens S7 PLCs PATCHCORD Malware Hits Afghan Telecom in New APT36 Campaign The post Jewelbug APT Group Operations Combine Espionage and Fraud appeared first on Daily CyberSecurity.
     
  • ✇Firewall Daily – The Cyber Express
  • Four Men Admit to $2.2M Medicaid Fraud Scheme Using ChatGPT Samiksha Jain
    Four Minnesota men have pleaded guilty to a Minnesota Medicaid fraud scheme that allegedly stole approximately $2.2 million from the state’s Housing Stabilization Services (HSS) program and used artificial intelligence to fabricate records when insurance companies requested documentation. The defendants admitted to submitting thousands of claims for services they never provided or significantly inflating claims to obtain higher reimbursements. The case involves four Twin Cities-area men who o
     

Four Men Admit to $2.2M Medicaid Fraud Scheme Using ChatGPT

Minnesota Medicaid fraud

Four Minnesota men have pleaded guilty to a Minnesota Medicaid fraud scheme that allegedly stole approximately $2.2 million from the state’s Housing Stabilization Services (HSS) program and used artificial intelligence to fabricate records when insurance companies requested documentation. The defendants admitted to submitting thousands of claims for services they never provided or significantly inflating claims to obtain higher reimbursements. The case involves four Twin Cities-area men who operated Brilliant Minds Services LLC from the Griggs-Midway Building in St. Paul, Minnesota. According to court documents, the business enrolled as a Medicaid program provider and claimed to help people with disabilities, including seniors and individuals with mental illnesses and substance use disorders, find and maintain housing through the now-defunct HSS program.

Minnesota Medicaid Fraud Scheme Targeted 350 Recipients

According to prosecutors, Moktar Hassan Aden, 31, Mustafa Dayib Ali, 29, Khalid Ahmed Dayib, 26, and Abdifitah Mohamud Mohamed, 27, signed up approximately 350 people for HSS. The defendants then billed Medicaid for services they allegedly did not provide to those recipients. The scheme reportedly operated from April 2022 through April 2025. During that period, the four men allegedly submitted thousands of HSS claims and fraudulently obtained approximately $2.2 million from Minnesota Medicaid. The case highlights the alleged misuse of a government program designed to provide housing-related support to vulnerable people. Authorities said the defendants exploited the program by claiming reimbursements for services that were never delivered or by submitting inflated claims.

Artificial Intelligence Used to Fabricate Records

The case also highlights the use of artificial intelligence in an alleged effort to conceal healthcare fraud. When insurance companies requested supporting documentation for the claims, the defendants used ChatGPT to fabricate records, according to court documents. The use of ChatGPT to create fake documentation adds another dimension to the health care fraud case, as authorities continue to investigate alleged schemes involving government-funded programs. The defendants allegedly used the fabricated records to conceal the fraudulent claims and support services they had claimed to provide. Assistant Attorney General Colin M. McDonald of the Justice Department’s National Fraud Enforcement Division said the defendants exploited vulnerable people and a vulnerable program for financial gain. U.S. Attorney for the District of Minnesota Daniel N. Rosen said Medicaid fraud carries serious consequences and that the funds involved were intended to support vulnerable Minnesotans relying on housing and recovery services.

Four Defendants Plead Guilty to Wire Fraud

In separate hearings held between July 7 and July 23, 2026, all four defendants pleaded guilty to one count of wire fraud. Each faces a maximum penalty of 20 years in prison. A federal district court judge will determine any sentence after considering the U.S. Sentencing Guidelines and other statutory factors. Sentencing dates have not yet been set. The FBI, the U.S. Internal Revenue Service, Criminal Investigation, and the U.S. Department of Health and Human Services, Office of Inspector General, are investigating the case. Trial Attorney Raymond E. Beckering III of the Criminal Division’s Fraud Section and Assistant U.S. Attorney Matthew Murphy for the District of Minnesota are prosecuting the case.

Health Care Fraud Strike Force Continues Investigations

The case is part of the ongoing collaboration between the U.S. Attorney’s Office for the District of Minnesota and the Health Care Fraud Strike Force to combat fraud targeting government programs. The Department of Justice’s Health Care Fraud Strike Force Program currently includes nine strike forces operating across federal districts. Since 2007, the program has charged more than 6,200 defendants who collectively billed federal health care programs and private insurers more than $45 billion. The case also comes as the Justice Department’s National Fraud Enforcement Division focuses on investigating and prosecuting fraud against the American people. Authorities said efforts to combat fraud remain part of broader work targeting fraud, waste, and abuse within federal benefit programs.

Fake FBI Agents Use IC3 Complaint Scams to Target Fraud Victims

Fake FBI agents are using deepfake videos, spoofed IC3 websites and false recovery claims to steal money and personal information from people who were scammed before, the FBI warns.
  • ✇Firewall Daily – The Cyber Express
  • Dubai Police Warns Against Online Scams Promising Work and Visit Visas Samiksha Jain
    The Dubai Police fraudulent visa ads warning has cautioned the public against scams offering work visas, residency visas, and visit visas in exchange for money. According to the Anti Fraud Centre at Dubai Police's General Department of Criminal Investigation, fraudsters are using social media platforms and messaging apps to circulate fake visa offers by impersonating official entities or using the names of unlicensed companies. The advisory was issued as part of Dubai Police's Be Aware of Fra
     

Dubai Police Warns Against Online Scams Promising Work and Visit Visas

Dubai Police fraudulent visa ads

The Dubai Police fraudulent visa ads warning has cautioned the public against scams offering work visas, residency visas, and visit visas in exchange for money. According to the Anti Fraud Centre at Dubai Police's General Department of Criminal Investigation, fraudsters are using social media platforms and messaging apps to circulate fake visa offers by impersonating official entities or using the names of unlicensed companies. The advisory was issued as part of Dubai Police's Be Aware of Fraud campaign, which aims to raise awareness about online scams and help residents identify fraudulent schemes.

Dubai Police Fraudulent Visa Ads Circulating on Social Media

According to Dubai Police, scammers are promoting visa services through advertisements and messages that claim to offer work, residency, or visit visas for a fee. The Anti Fraud Centre said these advertisements are designed to convince victims to transfer money by falsely claiming to represent government authorities or licensed visa service providers. Some also use the names of unlicensed companies or offices to appear legitimate. Dubai Police urged the public not to rely on such offers and reminded residents that all visa procedures should be completed only through competent authorities or legally approved offices.

Authorities Urge Public to Verify Visa Offers

The Anti Fraud Centre said verifying the source of a visa service is the first step in avoiding visa fraud. Residents have been advised to confirm the authenticity of any visa offer or application process through official channels before making payments or sharing personal information. The centre also warned against dealing with intermediaries or unknown individuals claiming they can arrange visas through unofficial means. Dubai Police said people should not be misled by promises of guaranteed visas or job opportunities that are offered outside the legal process.

How to Report Fraud Attempts

Dubai Police has asked members of the public to report any fraud or attempted fraud immediately. Reports can be submitted through the Dubai Police Smart App, the eCrime platform for cybercrime reports, or by calling 901. The Anti Fraud Centre reiterated that staying informed and verifying service providers through official channels remain the most effective ways to avoid falling victim to fraudulent visa schemes.

New FCC Proposal Pits Phone Privacy Against Fraud Prevention

17 de Julho de 2026, 11:39

The FCC has proposed requiring identity verification for phone activation, a move supporters say will fight fraud while critics warn it threatens privacy.

The post New FCC Proposal Pits Phone Privacy Against Fraud Prevention appeared first on TechRepublic.

  • ✇Firewall Daily – The Cyber Express
  • Dutch Police Arrest Key Suspect in €100M Global Crypto Investment Scam Samiksha Jain
    A major global crypto investment scam investigation has led to the arrest of an alleged key figure behind an international criminal organization accused of defrauding victims of more than €100 million every month. Dutch police announced multiple arrests across Europe following a long-running investigation into a fraud network that allegedly employed over 700 people operating from around 20 call centers worldwide. The main suspect, a 46-year-old dual Israeli and Polish national,
     

Dutch Police Arrest Key Suspect in €100M Global Crypto Investment Scam

global crypto investment scam

A major global crypto investment scam investigation has led to the arrest of an alleged key figure behind an international criminal organization accused of defrauding victims of more than €100 million every month. Dutch police announced multiple arrests across Europe following a long-running investigation into a fraud network that allegedly employed over 700 people operating from around 20 call centers worldwide.

The main suspect, a 46-year-old dual Israeli and Polish national, was arrested at an airport in Poland on May 26 at the request of Dutch authorities. Investigators believe he played an indispensable role in the organization, which allegedly carried out large-scale investment fraud targeting victims across multiple countries.

Global Crypto Investment Scam Network Operated Through Worldwide Call Centers

According to Dutch police, the organization functioned like a professional company with approximately 700 employees spread across nearly 20 offices globally. Individuals working as financial advisors scam operators allegedly contacted victims daily through online platforms and telephone calls while posing as legitimate investment professionals.

Authorities said the organization was structured with a central headquarters overseeing multiple teams, each assigned to target victims in specific countries. Employees reportedly worked under pseudonyms and used technical measures to hide their identities and locations.

[caption id="attachment_113134" align="aligncenter" width="600"]global crypto investment scam Excerpts from emails that victims sent to scammers[/caption]

As part of the investigation, Belgian police arrested five individuals believed to have worked as fraudulent financial advisors.

Multiple Arrests Made Across Europe

The investigation resulted in several coordinated arrests during May and July.

On July 7, authorities arrested two Dutch nationals aged 45 and 34, along with a 34-year-old Belgian, all residing in Cyprus. A 25-year-old suspect was also arrested in Belgium the same day. On July 10, police arrested a 44-year-old Dutch national in Athens.

The main suspect has since been extradited to the Netherlands, where an examining magistrate ordered 14 days of pre-trial detention. Dutch authorities indicated that additional arrests remain possible as the investigation continues.

How the Global Crypto Investment Scam Worked

Investigators said the online investment scam relied on building long-term trust with victims. Individuals posing as account managers or financial advisors maintained frequent contact through phone calls and online communication, sometimes over several months.

Victims were encouraged to begin with relatively small investments that appeared to generate immediate returns. Police said the investment platforms displayed convincing but fabricated profits, even though no actual investments were being made.

As confidence grew, victims were persuaded to transfer increasingly larger amounts, often in the form of cryptocurrency fraud payments. Instead of being invested, investigators said the funds were diverted directly to the criminal organization.

Authorities also warned that victims who stop investing may later be contacted by so-called recovery companies requesting upfront deposits to recover lost funds. Police believe these recovery operations may also be connected to the same fraud networks.

Hundreds of Complaints Linked to Investment Fraud

Dutch authorities have received approximately 550 reports connected to the organization, while Belgian police have recorded around 200 complaints. Investigators estimate the total number of victims worldwide could reach tens of thousands.

The financial losses reported by victims in the Netherlands alone amount to nearly €25 million, with many individuals losing well over €10,000.

Dutch police said officers proactively contacted some victims after discovering that many remained unaware they had fallen victim to cyber fraud.

Financial investigators are now examining whether assets linked to the suspects can be frozen or seized.

Digital Infrastructure Taken Offline

Investigators said the criminal organization remained active since at least 2021 and relied heavily on concealed digital infrastructure to evade law enforcement.

By tracing financial transactions, IP addresses, and other digital evidence, the Dutch police identified offices, suspects, and critical infrastructure supporting the operation. Authorities worked with commercial service providers to take key elements of the network offline.

The investigation also involved Europol, with intelligence shared across multiple countries to support ongoing criminal prosecutions.

Officials said the case demonstrates the scale and sophistication of modern investment fraud operations and highlighted continued international cooperation to dismantle cyber-enabled financial crime networks.

  • ✇The Cloudflare Blog
  • Announcing Cloudflare Account Abuse Protection: prevent fraudulent attacks from bots and humans Jin-Hee Lee
    Today, Cloudflare is introducing a new suite of fraud prevention capabilities designed to stop account abuse before it starts. We've spent years empowering Cloudflare customers to protect their applications from automated attacks, but the threat landscape has evolved. The industrialization of hybrid automated-and-human abuse presents a complex security challenge to website owners. Consider, for instance, a single account that’s accessed from New York, London, and San Francisco in the same five m
     

Announcing Cloudflare Account Abuse Protection: prevent fraudulent attacks from bots and humans

12 de Março de 2026, 02:00

Today, Cloudflare is introducing a new suite of fraud prevention capabilities designed to stop account abuse before it starts. We've spent years empowering Cloudflare customers to protect their applications from automated attacks, but the threat landscape has evolved. The industrialization of hybrid automated-and-human abuse presents a complex security challenge to website owners. Consider, for instance, a single account that’s accessed from New York, London, and San Francisco in the same five minutes. The core question in this case is not “Is this automated?” but rather “Is this authentic?” 

Website owners need the tools to stop abuse on their website, no matter who it’s coming from.

During our Birthday Week in 2024, we gifted leaked credentials detection to all customers, including everyone on a Free plan. Since then, we've added account takeover detection IDs as part of our bot management solution to help identify bots attacking your login pages. 

Now, we’re combining these powerful tools with new ones. Disposable email check and email risk help you enforce security preferences for users who sign up with throwaway email addresses, a common tactic for fake account creation and promotion abuse, or whose emails are deemed risky based on email patterns and infrastructure. We’re also thrilled to introduce Hashed User IDs — per-domain identifiers generated by cryptographically hashing usernames — that give customers better insight into suspicious account activity and greater ability to mitigate potentially fraudulent traffic, without compromising end user privacy.

The new capabilities we’re announcing today go beyond automation, identifying abusive behavior and risky identities among human users and bots. Account Abuse Protection is available in Early Access, and any Bot Management Enterprise customer can use these features at no additional cost for a limited period, until the general availability of Cloudflare Fraud Prevention later this year. If you want to learn more about this Early Access capability, sign up here.

Leaked credentials make logins all too vulnerable

The barrier to entry for fraudulent behavior is dangerously low, especially with the availability of massive datasets and access to automated tools that commit account fraud at scale. Website owners aren’t just dealing with individual hackers, but industrialized fraud. Last year, we highlighted how 41% of logins across our network use leaked credentials. This number has only grown following the exposure of a database holding 16 billion records, and multiple high-profile breaches have since come to light. 

What’s more, users reuse passwords across multiple platforms, meaning a single leak from years ago can still unlock a high-value retail or even a bank account today. Our leaked credential check is a free feature that checks whether a password has been leaked in a known data breach of another service or application on the Internet. This is a privacy-preserving credential checking service that helps protect our users from compromised credentials, meaning Cloudflare performs these checks without accessing or storing plaintext end user passwords. Passwords are hashed — i.e., converted into a random string of characters using a cryptographic algorithm — for the purpose of comparing them against a database of leaked credentials. If you haven’t already turned on our leaked credential check, enable it now to keep your accounts safe from easy hacks!

Access to a large database of leaked credentials is only useful if an attacker can cycle through them quickly across many sites to identify which accounts are still vulnerable due to password reuse. In our Black Friday analysis in 2024, we observed that more than 60% of traffic to login pages across our network was automated. That’s a lot of bots trying to break in.

To help customers protect their login endpoints from constant bombardment, we added account takeover (ATO)-specific detections to highlight suspicious traffic patterns. This is part of our recent focus on per-customer detections, in which we provide behavioral anomaly detection unique to each bot management customer. Today, bot management customers can see and mitigate attempted ATO attacks in their login requests directly on the Security analytics dashboard.

In the card on the left within the Security analytics dashboard, you can view and address attempted account takeover attacks.

In the last week, our ATO detections combined caught an average of 6.9 billion suspicious login attempts daily, across our network. These ATO detections, along with the many other detection mechanisms in our bot management solution, create a layered defense against ATO and other malicious automated attacks.

From automation to intent and identity

To discern automation, or to discern intent and identity? That is the question. Our answer: yes and yes, as both are critical layers of a robust security posture. Attackers now operate at a scale previously reserved for enterprise services: they leverage massive credential leaks, use human-powered fraud farms to spoof devices and locations, and create synthetic identities to maintain thousands — even millions — of fake accounts for promotion and platform abuse. A human being with automated tools could be draining accounts, abusing promotions, committing payment fraud, or all of the above.

Beyond that, automation is accessible like never before, particularly as users become better acquainted with using AI agents and even long-standing, “traditional” browsers move toward having agentic capabilities by default. Whether it’s a lone actor using an AI agent or a coordinated fraud campaign, the threat isn’t as simple as a single script — it can involve human intent, with automated execution.

Consider the following scenarios we’ve heard from our customers:

  • We have 1,000 new users this month, but more than half of them are fake identities who benefit from a free trial, then disappear.
  • The attacker logged in with the correct password, so how do I know that it isn’t the real user?
  • This entity is acting at human pace, and they are draining accounts.

These problems can't be solved by only assessing automation; they require checking for authenticity and integrity. This is the gap that our dedicated fraud prevention capabilities address.

Assessing suspicious emails

Let’s start by assessing the earliest point of potential account abuse: account creation. Fake or bulk account creation is one of the biggest topics in conversations about website fraud, as it can open the door for attackers to access an application — or even an entire business model. 

Cloudflare is giving customers the tools to assess suspicious account creation at the source in two ways:

  1. Disposable email check: Detect when users sign up with disposable, or throwaway, email addresses commonly used for promotion abuse and fake account creation. These disposable email services allow attackers to spin up thousands of "unique" accounts without maintaining real infrastructure, particularly unauthenticated disposable emails that provide instant access without account creation or free unlimited email aliases. Customers can use this binary field as they build rules to enforce security preferences, choosing to block all disposable emails outright, or perhaps issuing a challenge to anyone attempting to create an account with a disposable email.
  1. Email risk: Cloudflare analyzes email patterns and infrastructure to provide risk tiers (low, medium, high) that customers can use in security rules. We know that not all email addresses are created equal; an address with the format firstname.lastname@knowndomain.com carries different risk characteristics than xk7q9m2p@newdomain.xyz. Email risk tiers allow customers to express their tolerance for risk and friction at the point of account creation. 

Both disposable email check and email risk are now available in security analytics and security rules, equipping website owners to protect their account creation flow. These detections address a fundamental problem: by the time an account is committing abuse, it's already too late. The website owner has already paid acquisition costs, the fraudulent user has consumed promotional credits, and remediation requires manual review. Mitigating suspicious emails means adding the appropriate friction at signup — the moment it matters most.

Introducing Hashed User IDs

Understanding patterns of abuse requires visibility: not only into the network, but of account activity. Traditionally, security has meant looking through the lens of IPs and isolated HTTP requests to spot automated activity, but website owners aren’t just thinking in terms of network signals; they are also considering their users and known accounts. That’s why we’re expanding our mitigation toolbox to match the way applications are actually structured, focusing on user-based detection of fraudulent activity.

Attackers can effortlessly rotate IPs to hide their tracks. But forcing them to repeatedly generate new, credible accounts introduces massive friction, especially when combined with account creation protections. When we look past the network layer and map fraudulent actions to a given compromised or abusive account, we can spot targeted behavior tied to a single, persistent actor and put a stop to the abuse. In this way, we’re shifting the defense strategy to the account level, instead of playing whack-a-mole with rotating IP addresses and residential proxies. This means that our customers can mitigate abusive behavior based on the way their applications separate identity.

To arm website owners with this capability, Cloudflare is releasing a Hashed User ID that customers can use in Security analytics, Security rules, and Managed Transforms. User IDs are per-domain, cryptographically hashed versions of the values in the username field, and each user ID is an encrypted, unique, and stable identifier generated for a given username on a customer application. Importantly, the actual username is not logged or stored by Cloudflare as part of this service. As with leaked credentials check and ATO detections, which identify login traffic and then encrypt credentials for comparison, we are prioritizing end user privacy while empowering our customers to take action against fraudulent behavior.

With access to Hashed User IDs, website owners can:

  • See top users: Which accounts have the most activity?
  • See when a unique user logs in from a country they usually don’t — or multiple countries in one day!
  • Mitigate traffic based on unique user, such as blocking a user with historically suspicious activity.
  • Combine fields to see when accounts are being targeted with leaked credentials.
  • See what network patterns or signals are associated with unique users.

The expanded view of a single Hashed User ID within the Security analytics dashboard, showing the activity details of that unique user, including their login location and their browser. 

This user-level visibility transforms how website owners can investigate and mitigate traffic. Instead of examining individual requests in isolation, our customers can see the full picture of how attackers are targeting and hiding among legitimate users.

Take the next step in account protection today

If you want to learn more about this Early Access capability, sign up here. All Bot Management Enterprise customers are eligible to add these new Account Abuse Protection features today, and we’d love to open the conversation with any and all prospective Bot Management customers.

While bot detections will continue to answer the question of automation and intent, fraud detections delve into the question of authenticity. Together, they give website owners comprehensive tools to fight against the full spectrum of account abuse. This suite is one step in our ongoing investment to protect the entire user journey — from account creation and login to secure checkouts and the integrity of every interaction.

Fake Céline Dion Paris Tickets Sold on Facebook and Ticketmaster Clones

Group-IB says scammers are targeting Céline Dion fans through Facebook, duplicate digital tickets and fake websites impersonating Ticketmaster, AXS and the venue site.

Cybersecurity Negotiator Gets 70 Months for Helping BlackCat Extort Victims

Former ransomware negotiator Angelo Martino gets 70 months in prison for helping BlackCat extort US victims and misuse confidential client data in cyberattacks.

ClickFix Scams Abuse Google, Cloudflare Checks to Deliver 7 Malware Families

Malwarebytes links fake Google and Cloudflare verification pages to shared ClickFix infrastructure delivering StealC, NetSupport and other malware.

AI Can Forge Documents in Minutes – “Looks Right” Is No Longer Enough

Generative AI is making document fraud faster and harder to spot, pushing security teams to verify provenance, signatures and file integrity at intake securely.

Fake “Google Notes” Browser Extension Caught Swapping Crypto Wallet Addresses

McAfee says a Google Notes browser extension is replacing copied crypto payment details, putting wallet transfers at risk for Chrome, Brave, and Microsoft Edge users.

Fake Interpol Investigation Emails Push Ransomware at Small Businesses Globally

Fake Interpol investigation emails are targeting small businesses with Proton Drive links that deliver ransomware, encrypt files, and route victims to Tox chat.
❌
❌