Visualização normal

Antes de ontemFirewall Daily – The Cyber Express
  • ✇Firewall Daily – The Cyber Express
  • Britain Gains Access to Ukraine’s ‘Goldmine’ of Battlefield AI Data Samiksha Jain
    The UK Ukraine AI partnership will give Britain access to Ukraine’s Avengers AI Labs, bringing together Ukrainian battlefield experience, operational data and engineering expertise with the UK’s AI ecosystem. The agreement, signed by President Volodymyr Zelenskyy and Prime Minister Andy Burnham in Ukraine, will focus initially on defence and national security. Under the partnership, British innovators and researchers will gain access to data and insights collected across the battlefield. The
     

Britain Gains Access to Ukraine’s ‘Goldmine’ of Battlefield AI Data

26 de Agosto de 2026, 02:26

UK Ukraine AI partnership

The UK Ukraine AI partnership will give Britain access to Ukraine’s Avengers AI Labs, bringing together Ukrainian battlefield experience, operational data and engineering expertise with the UK’s AI ecosystem. The agreement, signed by President Volodymyr Zelenskyy and Prime Minister Andy Burnham in Ukraine, will focus initially on defence and national security. Under the partnership, British innovators and researchers will gain access to data and insights collected across the battlefield. The UK government described Avengers AI Labs as a “goldmine of battlefield data,” offering researchers access to real-world operational information used to train AI models.

How Avengers AI Labs Uses Battlefield Data

The data is collected through thousands of daylight cameras and infrared sensors deployed across the battlefield. The systems capture images and information involving tanks, artillery, air defence systems, infantry and aerial targets, including Shahed drones and reconnaissance UAVs. The data is used to train AI models to recognize and classify battlefield objects. Ukraine’s Defense Ministry has previously said that systems trained using the Avengers Labs platform analyze more than 100,000 drone video feeds each month and help identify about 70% of enemy targets in real time. The UK’s access to the platform is intended to allow British startups, researchers and engineers to work with operational insights and develop technologies based on real-world datasets. The partnership will initially bring together engineers, academics, businesses and military operational expertise from both countries to address national security challenges. The two countries will also explore additional platforms for future collaboration.

UK Ukraine AI Partnership Test New Defence Technology

Several pilot projects involving British startups have already been rolled out as part of the agreement. The companies named are Bristol-based Sintela, Oxford’s Mind Foundry and London’s Skyral. The first technology is due to be deployed at a UK defence site to help protect bases from protestors and hostile actors seeking intelligence. The project combines Ukrainian data with UK technology and turns buried fibre-optic cables into an AI-enabled sensor. The technology could also be used in other critical locations, including airports, prisons, railways and energy plants, according to the information released about the partnership. A second project will examine the development of next-generation low-power AI chips designed for future drones, robotics and autonomous systems. If successful, the technology could support machines designed to operate for longer, respond faster and function in environments where conventional systems face limitations.

AI Sovereignty and Defence Innovation

The agreement forms part of the UK and Ukraine’s 100 Year Partnership and expands cooperation between the two countries in AI and defence technology. The UK will provide access to its universities, researchers, technology companies and AI ecosystem, while Ukraine will provide access to operational experience and datasets generated during the war. Minister for AI Kanishka Narayan described the arrangement as AI sovereignty in practice, focused on developing national capabilities and turning frontline experience into technologies for military and critical infrastructure protection. The partnership also follows the UK government’s announcement that defence firm MBDA can release classified information on UK components for the long-range SCALP missile to establish local assembly lines in Ukraine. The broader agreement is intended to combine Ukrainian battlefield data with British scientific, engineering and technology expertise, with the initial focus remaining on defence, national security and the development of future defence technology.
  • ✇Firewall Daily – The Cyber Express
  • Hackers Target Social Media Accounts to Steal Explicit Content, FBI Warns Samiksha Jain
    The FBI is warning the public about sexual exploitation actors illegally accessing social media and personal accounts to steal explicit images and videos from adult and underage victims. The stolen material, also known as non-consensual intimate images (NCII), is being posted or sold on criminal marketplaces, often without the victim's knowledge. According to the FBI, these actors use social engineering and cyber intrusion tactics to target specific individuals or general targets of opportunity
     

Hackers Target Social Media Accounts to Steal Explicit Content, FBI Warns

13 de Agosto de 2026, 03:10

sexual exploitation actors

The FBI is warning the public about sexual exploitation actors illegally accessing social media and personal accounts to steal explicit images and videos from adult and underage victims. The stolen material, also known as non-consensual intimate images (NCII), is being posted or sold on criminal marketplaces, often without the victim's knowledge.

According to the FBI, these actors use social engineering and cyber intrusion tactics to target specific individuals or general targets of opportunity. After gaining access to accounts, they steal explicit content and share it through community forums or illicit marketplaces.

The FBI said personally identifiable information, including a victim's name, date of birth, email address, phone number and social media username, is often posted alongside the stolen material. This can expose victims to continued harassment and re-victimization.

How Sexual Exploitation Actors Access Accounts

The FBI has identified several methods used by sexual exploitation actors to gain access to victims' accounts.

Password and PIN Targeting

In password/PIN targeting, actors use high-volume password and PIN attempts against social media and personal accounts. The information used in these attempts can come from data leak sites, social media and open-source information.

When victims are known to the actors, curated lists may include personal details such as names, date of birth or variations of those details.

Social Media Customer Service Impersonation

Another tactic involves social media customer service impersonation through text messages. Victims may receive messages claiming their account is being disabled or locked unless they provide a verification code.

The actor then requests a password reset, causing a code to be sent to the victim. If the victim shares the code, the actor can reset the password and access the account.

Phishing Emails

The FBI also warns about phishing campaigns using look-alike domains and email accounts designed to appear as social media customer support.

These messages may claim there has been a new login and contain an embedded link asking the victim to change their password. Clicking the malicious link can give the actor access to the account.

Stolen Content Can Lead to Further Attacks

Once explicit content is stolen, sexual exploitation actors may post or sell it while including personal information about the victim. The FBI said victims can subsequently face harassment, sextortion, stalking or other targeted attacks.

The actors may also advertise stolen content through a victim's own social media page, increasing the potential for further exposure.

FBI Shares Steps to Protect Accounts

The FBI advises people to avoid storing sensitive images or videos on social media platforms or other internet-accessible sites.

It recommends using unique, complex passphrases and PINs along with multi-factor authentication (MFA). Password information directly associated with a person's identity, including names or birthdays, should be avoided.

Users should also be cautious with links received through emails and text messages. The FBI recommends going directly to the relevant website to address account concerns and checking URLs before clicking.

Unrequested temporary passwords, PIN resets or access codes should also be treated with caution. The FBI advises users not to share login information, even when someone claims to represent a platform or service.

People who believe their explicit content was stolen or leaked can provide information through the FBI's NCII reporting site. The FBI also advises the public to continue reporting fraud, scams and cyber threats to the Internet Crime Complaint Center or a local FBI Field Office.
  • ✇Firewall Daily – The Cyber Express
  • Gunra Ransomware Builds a New Attack Network Through RaaS Samiksha Jain
    Gunra ransomware has expanded its operations through a structured ransomware-as-a-service (RaaS) affiliate program, prompting the FBI, CISA and other agencies to issue a joint advisory warning organizations about the threat. The Gunra ransomware variant uses a double-extortion model, encrypting victim data while threatening to publish stolen information on a dedicated leak site if ransom demands are not met. The FBI first observed Gunra in April 2025 as a double-extortion ransomware variant d
     

Gunra Ransomware Builds a New Attack Network Through RaaS

11 de Agosto de 2026, 08:01

Gunra ransomware

Gunra ransomware has expanded its operations through a structured ransomware-as-a-service (RaaS) affiliate program, prompting the FBI, CISA and other agencies to issue a joint advisory warning organizations about the threat. The Gunra ransomware variant uses a double-extortion model, encrypting victim data while threatening to publish stolen information on a dedicated leak site if ransom demands are not met. The FBI first observed Gunra in April 2025 as a double-extortion ransomware variant derived from leaked Conti ransomware source code.

Gunra Ransomware Shifts to Affiliate Model

By early 2026, the group had expanded through a formal ransomware-as-a-service affiliate program advertised on dark web forums. The program provides affiliates with a management panel, configurable ransomware builder, cross-platform locker payloads and affiliate documentation. The FBI also observed Gunra operating under new branding aliases, including Golden Community, while recruiting penetration testers and ethical hackers as initial access brokers. Gunra initially focused on Windows environments before introducing a Linux variant and moving toward broader cross-platform targeting. Victims observed on the group’s dedicated leak site include organizations across the Americas, Europe, the Middle East, Africa and the Asia-Pacific. Targeted sectors include healthcare and public health, financial services and insurance, critical manufacturing, transportation, government services, utilities, academia, media and communications, retail, and professional and nonprofit services. Gunra ransomware

VPN Vulnerabilities Used for Initial Access

According to the advisory, Gunra actors primarily gained initial access by exploiting known vulnerabilities in internet-facing devices, including firewall and VPN gateways. The FBI observed exploitation of CVE-2024-55591 and CVE-2025-24472, authentication bypass vulnerabilities affecting specific FortiOS and FortiProxy versions. The Republic of Korea’s National Police Agency also observed Gunra actors exploiting credential exposure and SSH access control weaknesses in internet-facing VPN gateways to obtain unauthorized remote access. After gaining access, attackers used tools including Impacket utilities to move laterally through victim networks using SMB. In one case, actors compromised an SSL-VPN appliance using default credentials where account lockout controls were absent. They later used stolen session information to access internal virtual desktop infrastructure and move through systems including Active Directory servers and IT personnel workstations.

Data Theft Precedes Encryption

The double-extortion ransomware operation involves stealing sensitive information before encrypting systems. The FBI observed Gunra actors collecting business-critical documents, databases, personally identifiable information, and internal email communications. In at least one case, the actors used a malicious executable called main.exe to exfiltrate data from Microsoft OneDrive and SharePoint. Compressed archives containing sensitive information were also transferred to the Mega file-sharing service, with the volume of exfiltrated data reaching tens of terabytes. For encryption, Gunra uses ChaCha20 and RSA-4096 algorithms and has been observed using the .ENCRT extension for encrypted files. A documented sample from July 2025 used the .CRYPT extension. The ransomware also uses Windows Management Instrumentation to delete volume shadow copies before encryption, while one victim had backup and archived data deleted from both primary and disaster recovery infrastructure.

Agencies Urge Patching and Network Segmentation

The authoring agencies recommend that organizations prioritize patching known exploited vulnerabilities in internet-facing systems, including VPN gateways and RDP-exposed infrastructure. They also advise implementing and testing offline, immutable backups stored in physically separate and segmented locations. Network segmentation is another key recommendation, intended to restrict lateral movement and limit the spread of ransomware between systems. The agencies also recommend reviewing domain controllers, servers, workstations and Active Directory environments for unrecognized accounts, auditing administrative privileges, requiring MFA where possible and testing security controls against the Gunra techniques mapped to the MITRE ATT&CK framework. The joint advisory was published August 10, 2026, as part of the ongoing #StopRansomware initiative.
  • ✇Firewall Daily – The Cyber Express
  • PNLD Data Breach Exposes Police and Government Contact Details on Dark Web Ashish Khaitan
    The PNLD data breach has exposed contact information belonging to police officers, government partners, criminal justice professionals and customers after data from the Police National Legal Database (PNLD) was published on the dark web. The data breach at PNLD, identified on July 26, 2026, also affected some users of Ask the Police, raising concerns about targeted phishing attacks.  PNLD Data Breach Exposes Police and Contact Details  According to PNLD, the compromised data includes names, or
     

PNLD Data Breach Exposes Police and Government Contact Details on Dark Web

PNLD data breach

The PNLD data breach has exposed contact information belonging to police officers, government partners, criminal justice professionals and customers after data from the Police National Legal Database (PNLD) was published on the dark web. The data breach at PNLD, identified on July 26, 2026, also affected some users of Ask the Police, raising concerns about targeted phishing attacks. 

PNLD Data Breach Exposes Police and Contact Details 

According to PNLD, the compromised data includes names, organizations and work email addresses of police officers, police staff, criminal justice professionals, government partners and customers. The incident also exposed the names and email addresses of some individuals who had previously submitted questions through Ask the Police. UK government guidance warns that such information could enable attackers to craft more convincing phishing emails targeting named officers and affected individuals.  In its official statement, PNLD said, "There is no evidence to suggest that passwords or other security credentials have been compromised." The organisation clarified that it provides legal information, products and services to UK police forces and criminal justice organisations. It also stressed that PNLD is not the Police National Computer or the Police National Database, is not a crime-recording system, and does not store confidential information relating to victims, witnesses or offenders. 

PNLD Notifies Authorities and Affected Users 

Following the PNLD data breach, the organization said it had contacted all affected organizations and provided additional guidance. Individuals impacted through Ask the Police have also received notification emails with further information PNLD confirmed that it has informed the Information Commissioner's Office (ICO) and is working with the National Crime Agency (NCA) and specialist cybersecurity organizations as the investigation continues.  Its statement noted: "We are continuing to investigate a data security incident affecting the Police National Legal Database (PNLD), which was identified on Sunday 26 July." It added that compromised information had been published on the dark web and reiterated that there is no evidence that passwords or other security credentials were accessed.  Regarding Ask the Police, PNLD said the platform was affected because it is hosted on the same infrastructure, resulting in the publication of some users' names and email addresses. 

Investigation Continues as Key Questions Remain 

As of August 3, 2026, PNLD had not disclosed how many people were affected by the data breach at PNLD, when the intrusion began, how long unauthorized access lasted or the total volume of data obtained. Its public breach notice lists the categories of exposed information but does not include a victim count.  PNLD's 2025-26 annual summary reported 108,429 police registrations and support for all 43 Home Office police forces. However, the organization emphasized that this figure represents its user base and should not be interpreted as the number of people affected by the breach.  The organization's 2023-24 annual summary stated that PNLD uses Microsoft Power Platform technology. On August 3, 2026, The Hacker News reported that the breach notification page referenced assets hosted on Microsoft's content.powerapps.com domain. While this supports the platform connection, it does not indicate how the attackers accessed or extracted the compromised data. 
  • ✇Firewall Daily – The Cyber Express
  • US Seizes 1,000+ Domains Used to Illegally Stream FIFA World Cup Samiksha Jain
    The U.S. Department of Justice has seized more than 1,000 illegal World Cup streaming domains accused of broadcasting FIFA World Cup 2026 matches without authorization, marking a major enforcement action against digital piracy during the tournament. The domains were seized in three separate actions under U.S. copyright law as part of Operation Offsides, an initiative targeting websites involved in unauthorized World Cup broadcasts. The latest action includes nearly 400 websites seized by the en
     

US Seizes 1,000+ Domains Used to Illegally Stream FIFA World Cup

illegal World Cup streaming domains

The U.S. Department of Justice has seized more than 1,000 illegal World Cup streaming domains accused of broadcasting FIFA World Cup 2026 matches without authorization, marking a major enforcement action against digital piracy during the tournament. The domains were seized in three separate actions under U.S. copyright law as part of Operation Offsides, an initiative targeting websites involved in unauthorized World Cup broadcasts.

The latest action includes nearly 400 websites seized by the end of June, according to the Department of Justice. The investigation was carried out by U.S. Immigration and Customs Enforcement Homeland Security Investigations (HSI) Washington Field Office and the National Intellectual Property Rights Coordination Center.

Illegal World Cup Streaming Domains Targeted

According to an affidavit filed in support of a seizure warrant in the U.S. District Court for the Eastern District of Virginia, the seized domains were used to offer copyright-protected content through real-time streams of 2026 World Cup matches as they were being played and first broadcast.

HSI special agents confirmed that the domains were actively broadcasting World Cup matches without authorization. The domains were identified with assistance from FIFA, with additional information provided by beIN Media Group, NBC Universal, the Motion Picture Association’s Alliance for Creativity and Entertainment (ACE), Ultimate Fighting Championship (UFC), and Warner Brothers.

FIFA holds the exclusive rights to sanction and stage the FIFA World Cup 2026, which is being hosted across multiple cities in the United States, Canada and Mexico.

Operation Offsides Targets Illegal Streaming

The U.S. action is part of Operation Offsides, which focuses on identifying and seizing websites facilitating unauthorized broadcasts of World Cup matches.

The operation is led by the National Intellectual Property Rights Coordination Center and is being conducted with HSI Washington, D.C., HSI Attaché offices, private sector organizations and law enforcement partners globally.

Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division said the effort to seize more than 1,000 domains was aimed at protecting intellectual property rights and reducing risks to consumers from malicious software associated with some illicit streaming services.

[caption id="attachment_113257" align="aligncenter" width="400"]illegal World Cup streaming domains Source: The U.S. Department of Justice[/caption]

HSI Deputy Executive Associate Director Matthew Millhollin also warned that users accessing unauthorized streaming platforms could face risks including malware and payment information theft.

Operation Red Card Expands Global Crackdown

The U.S. enforcement action was accompanied by international efforts under Operation Red Card, which targeted digital piracy and counterfeiting connected to the World Cup across the Western Hemisphere.

The Justice Department’s International Computer Hacking and Intellectual Property (ICHIP) program coordinated enforcement efforts involving Argentina, Brazil, Chile, Colombia, the Dominican Republic, Ecuador, Paraguay and Peru.

The coordinated actions resulted in hundreds of illegal streaming sites being blocked, including 14 in Argentina, 223 in Ecuador, 28 in Peru, 309 in Brazil, 256 in the Dominican Republic and 1,140 in Colombia.

Colombian authorities also conducted 13 nationwide search-and-seizure operations targeting counterfeit sports apparel, resulting in 11 arrests and convictions.

Cybercrime Group Arrested in Colombia

On July 10, authorities launched Phase II of Operation Red Card in Colombia, conducting simultaneous operations in Bogotá, Soacha, Maríalabaja, Manatí and Sincerín.

An ICHIP-mentored cybercrime prosecutorial team from the Colombian Attorney General’s Office arrested four members of the cybercriminal group Los Ciberinfiltrados. According to the Justice Department, the group had illegally accessed telecommunications systems since 2024 and sold pirated streaming content, including World Cup matches.

The group allegedly used fraudulent credentials, VPNs, interception of security codes and manipulation of corporate system profiles to distribute the pirated content.

In Europe, ICHIP Bucharest also coordinated with Europol and international counterparts to address illegal streaming activities during the World Cup.

World Cup Streaming Crackdown Intensifies

The latest action follows a June 2026 announcement by the U.S. Department of Justice involving the seizure of nearly 400 websites accused of illegally broadcasting FIFA World Cup 2026 matches.

That earlier enforcement action, also conducted under Operation Offsides, targeted websites accused of copyright infringement by offering unauthorized live streams of World Cup matches for profit.

With more than 1,000 domains now seized in the U.S. actions, authorities continue to target unauthorized streaming platforms and digital piracy networks linked to the tournament.

  • ✇Firewall Daily – The Cyber Express
  • Dubai Police Warns Against Online Scams Promising Work and Visit Visas Samiksha Jain
    The Dubai Police fraudulent visa ads warning has cautioned the public against scams offering work visas, residency visas, and visit visas in exchange for money. According to the Anti Fraud Centre at Dubai Police's General Department of Criminal Investigation, fraudsters are using social media platforms and messaging apps to circulate fake visa offers by impersonating official entities or using the names of unlicensed companies. The advisory was issued as part of Dubai Police's Be Aware of Fra
     

Dubai Police Warns Against Online Scams Promising Work and Visit Visas

Dubai Police fraudulent visa ads

The Dubai Police fraudulent visa ads warning has cautioned the public against scams offering work visas, residency visas, and visit visas in exchange for money. According to the Anti Fraud Centre at Dubai Police's General Department of Criminal Investigation, fraudsters are using social media platforms and messaging apps to circulate fake visa offers by impersonating official entities or using the names of unlicensed companies. The advisory was issued as part of Dubai Police's Be Aware of Fraud campaign, which aims to raise awareness about online scams and help residents identify fraudulent schemes.

Dubai Police Fraudulent Visa Ads Circulating on Social Media

According to Dubai Police, scammers are promoting visa services through advertisements and messages that claim to offer work, residency, or visit visas for a fee. The Anti Fraud Centre said these advertisements are designed to convince victims to transfer money by falsely claiming to represent government authorities or licensed visa service providers. Some also use the names of unlicensed companies or offices to appear legitimate. Dubai Police urged the public not to rely on such offers and reminded residents that all visa procedures should be completed only through competent authorities or legally approved offices.

Authorities Urge Public to Verify Visa Offers

The Anti Fraud Centre said verifying the source of a visa service is the first step in avoiding visa fraud. Residents have been advised to confirm the authenticity of any visa offer or application process through official channels before making payments or sharing personal information. The centre also warned against dealing with intermediaries or unknown individuals claiming they can arrange visas through unofficial means. Dubai Police said people should not be misled by promises of guaranteed visas or job opportunities that are offered outside the legal process.

How to Report Fraud Attempts

Dubai Police has asked members of the public to report any fraud or attempted fraud immediately. Reports can be submitted through the Dubai Police Smart App, the eCrime platform for cybercrime reports, or by calling 901. The Anti Fraud Centre reiterated that staying informed and verifying service providers through official channels remain the most effective ways to avoid falling victim to fraudulent visa schemes.
  • ✇Firewall Daily – The Cyber Express
  • Dutch Police Arrest Key Suspect in €100M Global Crypto Investment Scam Samiksha Jain
    A major global crypto investment scam investigation has led to the arrest of an alleged key figure behind an international criminal organization accused of defrauding victims of more than €100 million every month. Dutch police announced multiple arrests across Europe following a long-running investigation into a fraud network that allegedly employed over 700 people operating from around 20 call centers worldwide. The main suspect, a 46-year-old dual Israeli and Polish national,
     

Dutch Police Arrest Key Suspect in €100M Global Crypto Investment Scam

global crypto investment scam

A major global crypto investment scam investigation has led to the arrest of an alleged key figure behind an international criminal organization accused of defrauding victims of more than €100 million every month. Dutch police announced multiple arrests across Europe following a long-running investigation into a fraud network that allegedly employed over 700 people operating from around 20 call centers worldwide.

The main suspect, a 46-year-old dual Israeli and Polish national, was arrested at an airport in Poland on May 26 at the request of Dutch authorities. Investigators believe he played an indispensable role in the organization, which allegedly carried out large-scale investment fraud targeting victims across multiple countries.

Global Crypto Investment Scam Network Operated Through Worldwide Call Centers

According to Dutch police, the organization functioned like a professional company with approximately 700 employees spread across nearly 20 offices globally. Individuals working as financial advisors scam operators allegedly contacted victims daily through online platforms and telephone calls while posing as legitimate investment professionals.

Authorities said the organization was structured with a central headquarters overseeing multiple teams, each assigned to target victims in specific countries. Employees reportedly worked under pseudonyms and used technical measures to hide their identities and locations.

[caption id="attachment_113134" align="aligncenter" width="600"]global crypto investment scam Excerpts from emails that victims sent to scammers[/caption]

As part of the investigation, Belgian police arrested five individuals believed to have worked as fraudulent financial advisors.

Multiple Arrests Made Across Europe

The investigation resulted in several coordinated arrests during May and July.

On July 7, authorities arrested two Dutch nationals aged 45 and 34, along with a 34-year-old Belgian, all residing in Cyprus. A 25-year-old suspect was also arrested in Belgium the same day. On July 10, police arrested a 44-year-old Dutch national in Athens.

The main suspect has since been extradited to the Netherlands, where an examining magistrate ordered 14 days of pre-trial detention. Dutch authorities indicated that additional arrests remain possible as the investigation continues.

How the Global Crypto Investment Scam Worked

Investigators said the online investment scam relied on building long-term trust with victims. Individuals posing as account managers or financial advisors maintained frequent contact through phone calls and online communication, sometimes over several months.

Victims were encouraged to begin with relatively small investments that appeared to generate immediate returns. Police said the investment platforms displayed convincing but fabricated profits, even though no actual investments were being made.

As confidence grew, victims were persuaded to transfer increasingly larger amounts, often in the form of cryptocurrency fraud payments. Instead of being invested, investigators said the funds were diverted directly to the criminal organization.

Authorities also warned that victims who stop investing may later be contacted by so-called recovery companies requesting upfront deposits to recover lost funds. Police believe these recovery operations may also be connected to the same fraud networks.

Hundreds of Complaints Linked to Investment Fraud

Dutch authorities have received approximately 550 reports connected to the organization, while Belgian police have recorded around 200 complaints. Investigators estimate the total number of victims worldwide could reach tens of thousands.

The financial losses reported by victims in the Netherlands alone amount to nearly €25 million, with many individuals losing well over €10,000.

Dutch police said officers proactively contacted some victims after discovering that many remained unaware they had fallen victim to cyber fraud.

Financial investigators are now examining whether assets linked to the suspects can be frozen or seized.

Digital Infrastructure Taken Offline

Investigators said the criminal organization remained active since at least 2021 and relied heavily on concealed digital infrastructure to evade law enforcement.

By tracing financial transactions, IP addresses, and other digital evidence, the Dutch police identified offices, suspects, and critical infrastructure supporting the operation. Authorities worked with commercial service providers to take key elements of the network offline.

The investigation also involved Europol, with intelligence shared across multiple countries to support ongoing criminal prosecutions.

Officials said the case demonstrates the scale and sophistication of modern investment fraud operations and highlighted continued international cooperation to dismantle cyber-enabled financial crime networks.

  • ✇Firewall Daily – The Cyber Express
  • Nihon Kotsu Cyberattack Disrupts Japan’s Largest Taxi Operator Ashish Khaitan
    The Nihon Kotsu cyberattack has disrupted operations at Japan's largest taxi operator after the company confirmed that its internal systems were compromised by a malware-related security incident. The cyberattack on Nihon Kotsu forced the company to shut down parts of its IT infrastructure, leaving key Japan taxi service operations, including its taxi dispatch system, unavailable.  According to the company, the incident occurred early on Saturday, July 11, 2026. After detecting unauthorized a
     

Nihon Kotsu Cyberattack Disrupts Japan’s Largest Taxi Operator

Nihon Kotsu cyberattack

The Nihon Kotsu cyberattack has disrupted operations at Japan's largest taxi operator after the company confirmed that its internal systems were compromised by a malware-related security incident. The cyberattack on Nihon Kotsu forced the company to shut down parts of its IT infrastructure, leaving key Japan taxi service operations, including its taxi dispatch system, unavailable.  According to the company, the incident occurred early on Saturday, July 11, 2026. After detecting unauthorized access, Nihon Kotsu immediately shut down affected systems to contain the attack and prevent additional damage. The taxi dispatch service operated via telephone, the hire car web ordering and reservation management system, and several internal systems remain temporarily offline. 

Nihon Kotsu Shuts Down Systems 

Nihon Kotsu, Japan's largest taxi and chauffeur operator by group revenue, generates approximately ¥155 billion (around $1 billion) annually. The company employs 18,228 people and operates a fleet of 8,558 taxis alongside more than 2,000 chauffeur vehicles, making the disruption significant for the country's Japan taxi service sector.  In a statement, the company said, "We have confirmed that our internal systems were subjected to unauthorized external access (malware infection)." It also apologized for the incident, stating, "We sincerely apologize for the great inconvenience and concern this has caused to our customers, business partners, and all other parties involved." 

Japan Taxi Service Affected as Dispatch Operations Remain Offline 

The company explained that emergency measures were implemented immediately after the breach was detected. "Upon detecting the unauthorized access, we immediately took emergency measures, including shutting down systems, to prevent further damage," the statement said. It added that the disruption has affected web-based hire car reservations, telephone taxi dispatch services, and certain internal systems.  As the cyberattack on Nihon Kotsu continues to be investigated, customers requiring taxis have been advised to use the GO taxi application, nearby taxi stands, or hail a cab directly from the street. Users of the GO app can still request a Nihon Kotsu vehicle by selecting the company within the application.  The company said it is working with external cybersecurity specialists to determine the cause of the incident, analyze system logs, and assess the overall impact. According to the statement, the internal network has been isolated, and "further spread of the damage has been contained." 

Investigation into the Nihon Kotsu Cyberattack Continues 

Investigators are also examining whether any personal or corporate data was exposed during the Nihon Kotsu cyberattack. The company stated that no information leak has been confirmed at this stage.   However, it noted that a detailed investigation is ongoing with specialized agencies to determine whether any data was compromised. If customer or partner information is found to have been exposed, Nihon Kotsu said it will make a public announcement and individually notify affected parties in accordance with applicable laws.  The company said restoring systems securely remains its highest priority. It also pledged to provide updates on both the investigation and recovery process as more information becomes available. In the meantime, Nihon Kotsu urged customers to remain cautious of fraudulent emails or messages claiming to originate from the company and advised them not to open suspicious attachments or click unknown links. 
  • ✇Firewall Daily – The Cyber Express
  • EU, UK Attribute Russia Cyberattack to FSB, Announce Sanctions Samiksha Jain
    The Russia cyberattack targeting Poland's critical infrastructure has been formally attributed to Russia's Federal Security Service (FSB), with the European Union and the United Kingdom announcing a coordinated package of cyber sanctions against Russian-linked hackers and organizations. The move follows an attempted disruption of Poland's energy sector last winter that officials said came close to triggering a major blackout affecting nearly half a million people. According to statements releas
     

EU, UK Attribute Russia Cyberattack to FSB, Announce Sanctions

Russia cyberattack

The Russia cyberattack targeting Poland's critical infrastructure has been formally attributed to Russia's Federal Security Service (FSB), with the European Union and the United Kingdom announcing a coordinated package of cyber sanctions against Russian-linked hackers and organizations. The move follows an attempted disruption of Poland's energy sector last winter that officials said came close to triggering a major blackout affecting nearly half a million people.

According to statements released by the EU and UK on Monday, the FSB's Center 16 was responsible for attempted cyber sabotage against Poland's heating and power infrastructure, as well as cyber intrusions targeting water treatment facilities. The allies also accused the agency of conducting broader cyber operations against governments and critical infrastructure across Europe.

Russia Cyberattack Linked to FSB's Center 16 Operations

The European Union said Center 16, the signals intelligence arm of the FSB, has conducted malicious cyber activities affecting multiple member states and international partners. According to the bloc, these operations have included infiltration of government networks, cyber espionage, and sabotage targeting critical infrastructure in France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania, and Finland.

The EU also stated that Center 16 controls several cyber threat groups, including TURLA, and has been involved in cyber operations against strategic government entities in France since 2010 and the country's defense industry in 2025. In Germany, it allegedly targeted government institutions, while in Poland it carried out disruptive operations against combined heating and power plants.

British authorities described last December's attempted attack on Poland's energy grid as "reckless," saying it was another example of Russia's attempts to create disruption across Europe.

Poland Attack Nearly Triggered Major Blackout

The cyber incident targeting Poland's energy infrastructure last winter was initially linked by cybersecurity firms ESET and Dragos to Sandworm, a threat group associated with Russia's military intelligence agency.

However, Poland's national cybersecurity agency, CERT Polska, later disputed that assessment after tracing the attack infrastructure and connecting it to a cluster associated with the FSB.

Separately, Poland's domestic intelligence service warned in May that cyber intrusions targeting the country's water treatment facilities posed a direct risk to the continuity of water supply.

EU and UK Expand Cyber Sanctions

In response, the European Union imposed restrictive measures on nine individuals and four entities linked to Russia's cyber ecosystem. The sanctions target intelligence officers, cybercriminals, self-proclaimed hacktivists, and private companies accused of supporting or facilitating malicious cyber operations.

The wider sanctions package announced by European partners targets more than 30 individuals and organizations, including operators behind the Lumma Stealer malware, companies accused of recruiting hackers from Russian universities, and individuals associated with the pro-Kremlin Rybar military blog.

EU foreign policy chief Kaja Kallas said Russia continues to rely on intelligence agencies, cybercriminal groups, hacktivists, and private companies to conduct malicious cyber operations against Europe and its partners.

She added that the bloc strongly condemns the misuse of this cyber ecosystem, which has targeted public services and critical infrastructure, resulting in operational disruptions and financial losses.

France Details FSB Activities

France also announced additional sanctions and said it would summon the Russian ambassador over what it described as persistent malicious cyber activities conducted for espionage purposes.

A technical report from France's Cyber Crisis Coordination Center (C4) identified 11 interception centers operated by Center 16 across Russia, including Unit 61240, which it said specifically focused on France.

French authorities alleged that the unit targeted government ministry systems in 2014, compromised the French Embassy network in Moscow in 2018, and stole significant volumes of data from a research institute working with the French defense industry in February 2025.

France also stated that one newly sanctioned group had claimed responsibility for destabilization efforts targeting the 2024 Paris Olympic and Paralympic Games.

Allied Advisory Warns of Ongoing Threats

Alongside the sanctions, the United States and intelligence agencies from a dozen allied countries published a joint cybersecurity advisory warning that Russian operators linked to Center 16 have been scanning internet-connected devices protected by weak or default credentials.

The United Kingdom separately sanctioned individuals connected to Lumma Stealer, describing it as one of the world's most widely used information-stealing malware families. British officials said credentials stolen through the malware have been used to support Russian espionage operations globally. According to the UK's National Crime Agency, more than 2,100 victims in the country were infected by Lumma Stealer during the past six months.

British Foreign Secretary Yvette Cooper said the sanctions are intended to disrupt the cybercriminal ecosystem supporting Moscow's intelligence services, while emphasizing that the coordinated measures send a clear message against the use of proxy cyber groups.

The Kremlin has repeatedly denied conducting offensive cyber operations. Russian President Vladimir Putin has dismissed European allegations of sabotage and cyberattacks as baseless, saying they are intended to justify aggressive policies against Russia.

  • ✇Firewall Daily – The Cyber Express
  • Alleged Scattered Spider Member Arrested in Finland, Extradited to U.S. Samiksha Jain
    An alleged member of the Scattered Spider cybercrime group has been extradited from Finland to the United States to face federal charges related to conspiracy, cyber intrusion, and fraud. U.S. authorities said the case marks another step in their ongoing efforts to prosecute individuals accused of participating in high-profile cybercrime operations linked to the notorious hacking group. Peter Stokes, 19, a dual U.S. and Estonian citizen, made his initial appearance in federal court in Chicago a
     

Alleged Scattered Spider Member Arrested in Finland, Extradited to U.S.

Scattered Spider

An alleged member of the Scattered Spider cybercrime group has been extradited from Finland to the United States to face federal charges related to conspiracy, cyber intrusion, and fraud. U.S. authorities said the case marks another step in their ongoing efforts to prosecute individuals accused of participating in high-profile cybercrime operations linked to the notorious hacking group.

Peter Stokes, 19, a dual U.S. and Estonian citizen, made his initial appearance in federal court in Chicago after being extradited from Finland.

According to the U.S. Department of Justice, Stokes was arrested by Finnish authorities in April following an Interpol Red Notice and was transferred to the United States last week. A criminal complaint filed in the Northern District of Illinois accuses him of participating in cyberattacks carried out as part of the Scattered Spider group.

Scattered Spider Linked to More Than 100 Network Intrusions

According to the complaint, Scattered Spider, also known as Octo Tempest, UNC3944, and 0ktapus, has been associated with more than 100 network intrusions. Authorities allege the group's activities have resulted in over $100 million in ransom payments and millions of dollars in additional damages suffered by victims.

Investigators said the group targeted companies across the United States by obtaining access to employee accounts through fraudulent methods.

Once inside corporate networks, the attackers allegedly encrypted data or exfiltrated sensitive information to remote servers before demanding cryptocurrency payments to restore access or prevent the public release of stolen data.

Complaint Details Alleged Luxury Retailer Cyberattack

The criminal complaint describes an alleged cyber intrusion that occurred in May 2025 involving a luxury jewelry retailer.

Federal prosecutors allege that Stokes and other co-conspirators breached the retailer's computer systems, exfiltrated company data, and demanded approximately $8 million in cryptocurrency as ransom. According to court documents, the retailer's security team successfully removed the threat actors from its network before any ransom payment was made.

Although the company did not pay the ransom, authorities said it still incurred losses of at least $2 million due to business disruption, investigation costs, and mitigation efforts following the incident.

Operation Riptide Targets Cybercrime Networks

The extradition and criminal charges were announced by the Department of Justice, the U.S. Attorney's Office for the Northern District of Illinois, and the FBI. The investigation also involved the FBI's Copenhagen Law Enforcement Attaché Office, the FBI Las Vegas Field Office, the Justice Department's Office of International Affairs, and Finland's National Bureau of Investigation.

Officials said the case forms part of Operation Riptide, an ongoing FBI campaign focused on disrupting cybercriminal actors, infrastructure, financial networks, and fraud schemes targeting Americans.

According to the FBI, Americans reported more than $20 billion in cybercrime losses last year, representing a 26% increase compared with the previous year.

Authorities Cite International Cooperation

Assistant Attorney General A. Tysen Duva said the charges stem from years of investigative work by the Justice Department, the U.S. Attorney's Office, and the FBI, adding that authorities would continue working together to pursue cybercriminals operating across international borders.

U.S. Attorney Andrew S. Boutros said the alleged attacks caused significant disruption to businesses across the United States and emphasized the government's commitment to prosecuting individuals involved in cyber intrusions.

FBI Special Agent-in-Charge Douglas S. DePodesta also highlighted the role of international law enforcement partnerships in identifying alleged members of the hacking group and pursuing cross-border cybercrime investigations.

Recent Guidance on Scattered Spider Threat

The arrest follows recent law enforcement efforts targeting the Scattered Spider threat group. In July 2025, the FBI and CISA released updated guidance describing the group's latest attack techniques, including the use of DragonForce ransomware to encrypt VMware ESXi servers.

The advisory urged organizations to maintain isolated offline backups, implement phishing-resistant multifactor authentication (MFA), and apply application controls to manage software execution.

Separately, in November 2025, two alleged Scattered Spider members appeared before Southwark Crown Court in the United Kingdom and pleaded not guilty to charges related to the August 2024 cyberattack on Transport for London (TfL).

The Department of Justice emphasized that the complaint against Stokes contains allegations only. As with all criminal cases, he is presumed innocent unless and until proven guilty in court.

  • ✇Firewall Daily – The Cyber Express
  • U.S. Seizes Nearly 400 Illegal FIFA World Cup Streaming Domains Samiksha Jain
    The Illegal World Cup Streaming Domains crackdown has intensified as the U.S. Department of Justice announced the seizure of nearly 400 websites that were illegally broadcasting FIFA World Cup 2026 matches. The enforcement action, launched ahead of the tournament's knockout stage, targets websites accused of violating copyright infringement laws by offering unauthorized live streams of World Cup matches for profit. According to the Justice Department, the domains were seized und
     

U.S. Seizes Nearly 400 Illegal FIFA World Cup Streaming Domains

Illegal World Cup Streaming Domains

The Illegal World Cup Streaming Domains crackdown has intensified as the U.S. Department of Justice announced the seizure of nearly 400 websites that were illegally broadcasting FIFA World Cup 2026 matches. The enforcement action, launched ahead of the tournament's knockout stage, targets websites accused of violating copyright infringement laws by offering unauthorized live streams of World Cup matches for profit.

According to the Justice Department, the domains were seized under U.S. copyright law as part of Operation Offsides, an international initiative focused on disrupting digital piracy networks linked to the World Cup.

Illegal World Cup Streaming Domains Targeted Under Operation Offsides

Assistant Attorney General A. Tysen Duva of the Justice Department's Criminal Division said the operation was designed to disrupt international networks profiting from the global popularity of the World Cup.

"We have seized hundreds of domains, used to illegally stream World Cup matches for profit, to disrupt the international networks that profit from the global popularity of the World Cup," Duva said.

He added that the Criminal Division will continue efforts to disrupt and, where appropriate, prosecute websites and individuals involved in the illegal activity.

[caption id="attachment_112952" align="aligncenter" width="602"]Illegal World Cup Streaming Domains Banner posted on seized sites[/caption]

The domain seizures are part of Operation Offsides, led by the National Intellectual Property Rights Coordination Center in coordination with HSI, HSI Attaché offices, private sector organizations, and international law enforcement agencies.

Investigation Supported by FIFA and Industry Partners

According to an affidavit filed in the Eastern District of Virginia, investigators found that the seized websites were providing unauthorized real-time streams of FIFA World Cup 2026 matches as they were being officially broadcast.

HSI special agents confirmed that the domains were actively streaming matches without authorization.

Authorities identified the domains with assistance from FIFA, while additional supporting information was provided by beIN Media Group, NBC Universal, the Motion Picture Association's Alliance for Creativity and Entertainment (ACE), Ultimate Fighting Championship (UFC), and Warner Brothers.

FIFA holds the exclusive rights to organize and stage the FIFA World Cup 2026, which is being hosted across cities in the United States, Canada, and Mexico.

Officials Warn of Copyright and Cybersecurity Risks

Director Ivan J. Arvelo of the National Intellectual Property Rights Coordination Center said unauthorized broadcasts violate intellectual property rights and financially benefit criminal organizations.

He said the operation disrupted networks responsible for stealing and distributing copyrighted content while helping ensure fans access matches through legitimate channels.

HSI Washington Field Office Special Agent in Charge Eric Weindorf also warned that illegal streaming sites may expose users to cybersecurity threats.

According to Weindorf, viewers using unauthorized streaming platforms could face malware risks, insecure connections, and the potential compromise of personal and financial information, in addition to the copyright violations committed by the operators of such sites.

International Enforcement Targets Online Piracy Networks

The domain seizure operation was coordinated with international partners through the International Computer Hacking and Intellectual Property (ICHIP) Network.

Authorities targeted servers and domains associated with online piracy in Peru and Bulgaria, which officials identified as known centers of illegal streaming activity. Additional ICHIP-supported enforcement actions took place in Croatia, Romania, Poland, and Colombia after U.S. authorities shared intelligence to help identify domains involved in unauthorized World Cup broadcasts.

The Justice Department said the operation demonstrates ongoing cooperation between domestic and international law enforcement agencies in combating cross-border piracy.

DOJ Continues Cybercrime and IP Enforcement

The Justice Department noted that its Computer Crime and Intellectual Property Section (CCIPS) investigates and prosecutes cybercrime and intellectual property offenses alongside domestic and international partners.

Since 2020, CCIPS has secured the conviction of more than 180 cybercrime and intellectual property offenders and obtained court orders returning more than $350 million in victim funds.

The latest enforcement follows a similar HSI-led operation during the 2022 FIFA World Cup, when authorities seized more than 70 websites involved in unauthorized streaming.

The Justice Department said Operation Offsides will continue to focus on identifying and shutting down websites that facilitate illegal broadcasts while protecting intellectual property during the FIFA World Cup.

TfL Hackers Plead Guilty After Breach Exposed Customer Data and Cost £29 Million

Transport for London cyberattack

Two alleged members of the cybercrime collective Scattered Spider have pleaded guilty to their roles in the Transport for London cyberattack, an incident that disrupted services, exposed customer data, and resulted in approximately £29 million in losses and recovery costs for London's transport authority. The guilty pleas were entered by Thalha Jubair, 20, from East London, and Owen Flowers, 18, from Walsall, West Midlands, on the opening day of proceedings at Woolwich Crown Court. The pair had been due to stand trial on June 22 but changed their pleas to guilty.

Transport for London Cyberattack Led to Major Disruption

According to the National Crime Agency (NCA) and City of London Police, TfL's network was infiltrated between August 31 and September 3, 2024. The breach forced all 28,000 employees to attend TfL offices for password resets and caused significant operational disruption across the organization. The TfL cyberattack also resulted in unauthorized access to data held within TfL's Oyster refunds system. The incident affected the authority's customer refund process, delaying reimbursements for some customers. In addition, the application system for Oyster photocards used by children and young people was temporarily shut down. Authorities said the attack caused substantial financial damage, with TfL reporting losses and recovery costs totaling approximately £29 million.

Investigation Linked Attackers to Scattered Spider

Jubair and Flowers were arrested at their homes on September 16, 2024, following a joint investigation conducted by the NCA and City of London Police. Investigators identified both individuals as members of Scattered Spider, a cybercriminal collective that has been linked to a number of high-profile intrusions. During searches of Flowers' residence, officers recovered laptops, desktop computers, hard drives, and USB storage devices. Evidence recovered from one Acer laptop included a screenshot showing connectivity to TfL infrastructure. [caption id="attachment_112868" align="aligncenter" width="600"]Transport for London cyberattack Source: NCA[/caption] Authorities also found evidence indicating Flowers had accessed an online marketplace that sold breached credentials. Investigators further discovered videos recorded by Flowers that allegedly showed Jubair accessing TfL systems during the attack. The investigation revealed that the two communicated through Telegram and collaborated using an online workspace platform that allowed multiple participants to work remotely on shared systems.

Additional Allegations Involving US Healthcare Networks

The investigation extended beyond the Transport for London cyberattack. When Flowers was first arrested on September 6, 2024, NCA officers identified evidence suggesting unauthorized activity targeting the networks of SSM Health Care Corporation and Sutter Health in the United States. Court records show Flowers pleaded guilty to charges related to a conspiracy to conduct unauthorized acts against SSM Health Care Corporation's computer systems with intent to impair operations. He also admitted attempting unauthorized acts against Sutter Health's systems with the same intent. Jubair additionally faced a charge for failing to disclose PINs or passwords associated with devices seized during the investigation. Authorities noted that Flowers breached bail conditions on two occasions in March and May 2025.

Law Enforcement Highlights Impact of Cybercrime

Paul Foster, Deputy Director and head of the NCA's National Cyber Crime Unit, described the case as a lengthy and highly complex investigation. He said the attack demonstrated that cybercrime has significant real-world consequences, affecting public services and causing millions of pounds in losses to critical national infrastructure. Foster also highlighted the growing threat posed by cybercriminal groups operating from the UK and other English-speaking countries, citing Scattered Spider as a notable example. Deputy Commissioner Nik Adams of the City of London Police said the cyberattack had a significant impact on essential public services and daily operations. He emphasized that individuals responsible for targeting critical organizations and causing financial harm would be pursued through coordinated law enforcement efforts. The investigation received support from the West Midlands Regional Organised Crime Unit and British Transport Police. Jubair and Flowers are scheduled to be sentenced at Woolwich Crown Court on July 16.
  • ✇Firewall Daily – The Cyber Express
  • Conti Ransomware Conspirator Pleads Guilty in $150M Scheme Samiksha Jain
    A Ukrainian national has pleaded guilty to his role in the Conti ransomware operation, one of the most prolific cybercrime campaigns in recent years. The U.S. Department of Justice announced that Oleksii Oleksiyovych Lytvynenko, 44, admitted to participating in a conspiracy that deployed Conti ransomware against more than 1,000 victims worldwide, resulting in at least $150 million in ransom payments. Lytvynenko entered his guilty plea after being extradited from Ireland to the United States.
     

Conti Ransomware Conspirator Pleads Guilty in $150M Scheme

Conti ransomware

A Ukrainian national has pleaded guilty to his role in the Conti ransomware operation, one of the most prolific cybercrime campaigns in recent years. The U.S. Department of Justice announced that Oleksii Oleksiyovych Lytvynenko, 44, admitted to participating in a conspiracy that deployed Conti ransomware against more than 1,000 victims worldwide, resulting in at least $150 million in ransom payments. Lytvynenko entered his guilty plea after being extradited from Ireland to the United States. He pleaded guilty to participating in a wire fraud conspiracy connected to the ransomware scheme that targeted organizations across the United States and dozens of other countries.

Conti Ransomware Targeted Victims Worldwide

According to court documents, the Conti ransomware group carried out attacks between 2020 and 2022, compromising computers and networks in 47 U.S. states, the District of Columbia, Puerto Rico, and 31 foreign countries. Investigators allege that members of the operation gained unauthorized access to victim networks, encrypted critical data, and demanded ransom payments in exchange for restoring access. Victims were also threatened with public exposure of stolen information if they refused to pay. The FBI estimates that, by January 2022, the ransomware campaign had generated at least $150 million in ransom proceeds, making Conti one of the most financially damaging ransomware operations ever investigated by U.S. authorities. Assistant Attorney General A. Tysen Duva said the defendants used the ransomware variant to terrorize businesses and individuals globally, causing extensive financial losses and operational disruption.

Defendant Admitted Role in Malware Development

Court filings show that Lytvynenko joined the conspiracy no later than September 2021. He admitted to possessing stolen data belonging to eight U.S. victims and four international victims whose information had been compromised by members of the group. Authorities also stated that he worked as part of a team directed by another Conti conspirator and assisted in developing a malware "loader." Such tools are commonly used to deploy malicious software and execute additional attacks on compromised systems. The admission provides investigators with further insight into the technical infrastructure behind the Conti ransomware operation and the roles played by individual members within the criminal enterprise.

International Cooperation Led to Arrest and Extradition

The case highlights the growing collaboration between international law enforcement agencies in combating cybercrime. U.S. authorities worked alongside multiple Irish agencies, including the Irish Department of Justice, Home Affairs and Migration, the Office of the Attorney General, and the Garda National Cyber Crime Bureau to secure Lytvynenko's arrest and extradition. Assistant Director Brett Leatherman of the FBI Cyber Division described the guilty plea as an important step toward holding cybercriminals accountable for the damage caused to victims around the world. The U.S. Secret Service also emphasized that international borders would not prevent authorities from pursuing individuals involved in ransomware operations. Officials said the case demonstrates a continued commitment to identifying and prosecuting every member of organized cybercriminal networks.

Part of Broader Operation Riptide Crackdown

The prosecution forms part of Operation Riptide, an ongoing FBI initiative targeting criminal actors, infrastructure, and financial networks involved in cyber-enabled crime and fraud. According to the Department of Justice, Americans reported more than $20 billion in cybercrime-related losses last year, representing a 26% increase from the previous year. Through Operation Riptide, authorities are focusing on dismantling ransomware groups, fraud operations, and other transnational cybercriminal organizations responsible for significant financial harm. Lytvynenko faces a maximum sentence of 20 years in federal prison. He is scheduled to be sentenced on September 10, 2026. A federal judge will determine the final sentence after considering federal sentencing guidelines and other statutory factors. The investigation was led by the FBI's San Diego, Nashville, and El Paso field offices, alongside the U.S. Secret Service. Prosecutors noted that the case remains part of a broader effort to identify and prosecute additional individuals linked to the Conti ransomware conspiracy.

Ransomware Attacks Surge 30% in 2026 as Qilin and INC Ransom Intensify Operations

Qilin

Ransomware attacks surged 30% in the first half of 2026 compared to the same period in 2025, with Qilin and INC Ransom emerging as two of the most prolific and dangerous operators in a crowded criminal ecosystem. Healthcare continues to be the top targeted industry, with 27 incidents in January 2026 alone, a figure that reflects both the sector's operational sensitivity and the premium value of health records on darknet markets.

Qilin: The Dominant Force

Qilin — also known as Agenda — is a ransomware group that entered 2026 accelerating, not slowing down. By early 2026, Qilin had already posted 55 confirmed victims, placing it ahead of its own 2025 pace. By June 2026, tracking data, Qilin had accumulated 168 confirmed victims in the healthcare sector alone, behind only manufacturing (291) and business services (245) in overall victim count. Qilin operates as a Ransomware-as-a-Service (RaaS) platform, recruiting affiliates who conduct attacks using Qilin's ransomware builder and infrastructure in exchange for a percentage of ransom proceeds. This model allows the core group to expand operational throughput without directly executing every attack. The group's double extortion model — encrypting victim data while simultaneously exfiltrating it and threatening public release on their leak site — has proven effective at pressuring victims into paying ransom demands even when robust backups exist. Public exposure of sensitive patient records creates regulatory, legal, and reputational pressure that many healthcare organisations find more immediately damaging than operational downtime. A notable recent case involves Covenant Health, which suffered a Qilin ransomware breach that exposed 478,188 patient records. The Covenant Health incident highlights Qilin's willingness to attack hospitals and health systems regardless of the direct patient safety implications.

INC Ransom: Targeting Critical Sectors

INC Ransom is another highly active operator that was among the top ransomware groups by victim count in January 2026, with 47 known attacks that month. The group targets organisations across multiple sectors, including healthcare, legal services, and public administration. INC Ransom gained significant attention in 2025 for its attack on NHS Scotland, which exposed 3 terabytes of patient data. The group continues to operate aggressively in 2026, targeting entities including healthcare practices, municipal agencies, and regional service providers. Recent INC Ransom victims include healthcare organisations such as Lymphedema Therapy Specialists, Inc. (February 2026, affecting 378 Texas patients) and various municipal and public sector entities, including Champaign-Urbana Public Health District.

The 2026 Ransomware Landscape

Beyond Qilin and INC Ransom, the broader 2026 ransomware ecosystem is characterised by:
  • AI-assisted operations: Multiple ransomware groups are now using AI tools to accelerate phishing campaign creation, target research, and initial access operations, reducing the operational cost of launching attacks.
  • Healthcare as a premium target: Patient records sell for up to 10 times as much as financial records on darknet markets, making it a persistently attractive target. Operational disruption of healthcare services also creates patient-safety leverage that can pressure organisations to make faster payment decisions.
  • The Play and SafePay operators were also confirmed in recent June 2026 attack disclosures, targeting organisations including Clínica Maitenes and various regional businesses.

Why It Matters

The 30% year-over-year increase in ransomware incidents confirms that neither law enforcement action nor improved defensive capabilities has materially reduced the operational tempo of ransomware criminal enterprises. The professionalisation of RaaS platforms, combined with AI-assisted tooling and shortened attack timelines, is creating conditions in which even well-defended organisations face materially elevated risk. For healthcare specifically, the combination of operational sensitivity, high data value, and historically underfunded security programmes creates a structural vulnerability that the industry has not yet resolved despite years of high-profile attacks.
  • ✇Firewall Daily – The Cyber Express
  • Miasma Malware Targets Red Hat npm Packages in New Supply Chain Attack Ashish Khaitan
    A newly discovered software supply chain campaign, dubbed Miasma, has emerged as the latest evolution of the Shai-Hulud supply chain attack, compromising several redhat-cloud-services npm packages to steal credentials, harvest secrets from developer systems, and spread through development environments using worm-like behavior. Security researchers at Socket described the operation as a smaller but highly capable successor to earlier Shai-Hulud campaigns, noting that it employs many of the sam
     

Miasma Malware Targets Red Hat npm Packages in New Supply Chain Attack

Miasma

A newly discovered software supply chain campaign, dubbed Miasma, has emerged as the latest evolution of the Shai-Hulud supply chain attack, compromising several redhat-cloud-services npm packages to steal credentials, harvest secrets from developer systems, and spread through development environments using worm-like behavior. Security researchers at Socket described the operation as a smaller but highly capable successor to earlier Shai-Hulud campaigns, noting that it employs many of the same techniques that made previous attacks effective against software development ecosystems.
"This is effectively a Mini Shai-Hulud campaign: it uses the same core tactics of install-time execution, credential harvesting, CI/CD targeting, encrypted exfiltration, and potential downstream propagation," Socket said.

Attribution Remains Unclear as TeamPCP Tools Continue to Circulate

The identity of the threat actor behind the latest Shai-Hulud supply chain attack remains uncertain. One major reason is the role of TeamPCP, a well-known cybercrime group that previously open-sourced tools associated with the original Shai-Hulud worm. By publicly releasing those resources, TeamPCP lowered the barrier for other attackers to launch similar operations, making attribution significantly more difficult. Researchers have not yet linked the Miasma campaign to any specific actor with confidence.

Affected redhat-cloud-services Packages

The attack targeted multiple packages published under the redhat-cloud-services namespace. The known compromised packages include:
  • @redhat-cloud-services/vulnerabilities-client
  • @redhat-cloud-services/tsc-transform-imports
  • @redhat-cloud-services/topological-inventory-client
  • @redhat-cloud-services/sources-client
  • @redhat-cloud-services/rule-components
  • @redhat-cloud-services/remediations-client
  • @redhat-cloud-services/rbac-client
The malicious code embedded within these packages was designed to execute during installation, allowing attackers to collect sensitive information from infected developer environments.

Encrypted Data Theft and GitHub-Based Propagation

Similar to earlier waves of the Shai-Hulud supply chain attack, the malware incorporates encrypted exfiltration capabilities. Stolen information is transmitted to the endpoint "api.anthropic[.]com:443/v1/api," while GitHub serves as a secondary communication and propagation channel. According to Socket, the malware can commit encrypted data packages directly through GitHub's API.
"It commits the encrypted result envelope through the GitHub API," Socket said. "The commit message can include: IfYouInvalidateThisTokenItWillNukeTheComputerOfTheOwner:."
Researchers from OX Security identified the first commit containing the phrase "Miasma: The Spreading Blight" on May 29, 2026. This suggests either that the malware variant had already been active by that date or that attackers began testing the campaign around that time.

GitHub Abuse Enables Verified Malicious Commits

The Miasma malware actively searches for repositories where stolen GitHub tokens possess write permissions. It then inspects action.yml and action.yaml files using GraphQL queries before injecting malicious workflows through GitHub's createCommitOnBranch mutation. This technique allows the resulting commits to appear as legitimate, verified, and signed changes, increasing the likelihood that malicious modifications will evade scrutiny. The malware is also capable of performing several additional actions, including:
  • Attempting privilege escalation by launching containers that bind-mount the host's /etc/sudoers.d directory and grant passwordless sudo access to CI runners.
  • Detecting endpoint protection products such as CrowdStrike, SentinelOne, Carbon Black, and StepSecurity Harden-Runner before executing malicious activities.
  • Establishing persistence by modifying Anthropic Claude Code through a SessionStart hook.
  • Creating Visual Studio Code tasks.json files configured with "runOn": "folderOpen" to ensure automatic execution whenever a project is opened.

Red Hat GitHub Account Believed to Be Initial Entry Point

Investigators believe the campaign originated from the compromise of a Red Hat employee's GitHub account. Evidence indicates that the account served as the patient zero event used to inject malicious code into the affected redhat-cloud-services packages. The compromised account reportedly pushed malicious orphan commits into two RedHatInsights repositories, allowing the attacker to bypass normal code review procedures and introduce the malicious payload.

Recommended Response and Remediation Steps

Security experts advise organizations that installed affected redhat-cloud-services package versions to immediately isolate impacted systems and remove compromised releases. Additional recommendations include:
  • Rotating all potentially exposed credentials.
  • Reviewing GitHub and npm activity for suspicious behavior.
  • Auditing environments for persistence mechanisms.
  • Investigating modifications to configuration files such as:
    • ~/.claude/settings.json
    • .vscode/tasks.json
    • .github/workflows/codeql.yml
    • .github/setup.js
  • Enforcing stronger access controls across development environments.
Socket warned that removing the malicious package alone is not sufficient.
"Because the malware includes background execution and potential developer-tool persistence mechanisms, uninstalling the npm package or deleting node_modules should not be considered sufficient cleanup," Socket explained.
The company also urged organizations operating CI/CD pipelines to suspend affected workflows, invalidate any build artifacts created during the exposure period, and review whether software releases, container images, npm packages, or deployment artifacts were generated after installation of the malicious package.
  • ✇Firewall Daily – The Cyber Express
  • UK Cybersecurity Innovation SilentGlass Goes Global After Licensing Deal Samiksha Jain
    The UK government has officially licensed SilentGlass, a government-developed cyber security device, for global commercial use, marking a major step in expanding public sector cybersecurity innovation into international markets. Developed by the National Cyber Security Centre, a part of Government Communications Headquarters, SilentGlass was originally designed to protect sensitive government systems from cyber threats linked to smart display connections. The technology is now being commercia
     

UK Cybersecurity Innovation SilentGlass Goes Global After Licensing Deal

cyber security device

The UK government has officially licensed SilentGlass, a government-developed cyber security device, for global commercial use, marking a major step in expanding public sector cybersecurity innovation into international markets. Developed by the National Cyber Security Centre, a part of Government Communications Headquarters, SilentGlass was originally designed to protect sensitive government systems from cyber threats linked to smart display connections. The technology is now being commercialized with support from the Government Office for Technology Transfer through a global intellectual property licensing agreement with a UK-based company. The launch highlights growing concerns around hardware-based cyber risks in modern workplaces, especially as organizations increasingly adopt hybrid work environments, shared office spaces, and connected devices.

SilentGlass Designed to Block Video Connection Cyber Threats

According to the NCSC, the cyber security device was created to address risks associated with modern smart monitors and digital video connections. Security experts have warned that video connections between laptops and monitors can potentially be exploited by attackers to compromise connected systems. The threat becomes more serious in environments where devices with different security levels are connected to shared displays. SilentGlass works as a small plug-and-play hardware device positioned between a laptop and monitor. Its primary role is to prevent the physical video connection from being used as a pathway for cyberattacks. By blocking that attack route, the cyber security device helps organizations reduce exposure to hardware-level threats while enabling safer flexible working arrangements, including hot desking and remote work setups. The NCSC stated that the technology was initially developed for internal government operations before demonstrating broader commercial potential across multiple sectors.

UK Government Expands Cyber Security Innovation to Global Market

Following a competitive commercial process, the UK government approved a global intellectual property licensing agreement for SilentGlass with a UK-based company. The agreement allows the cyber security device to be distributed internationally, expanding access to technology that was originally built for high-security government environments. Officials said the move reflects a wider effort to commercialize public sector innovation while ensuring strong governance and protection of government-developed intellectual property. The NCSC noted that SilentGlass could support:
  • Government departments
  • Public sector organizations
  • Critical national infrastructure operators
  • Businesses with advanced cybersecurity requirements
  • Employers supporting hybrid work environments
The technology is expected to benefit sectors where device trust, network security, and hardware protection are considered critical operational requirements.

GOTT Supported Commercialization of SilentGlass

The Government Office for Technology Transfer played a key role in helping the NCSC bring the cyber security device to market. According to officials, GOTT supported the project by advising on intellectual property licensing strategies, funding commercialization initiatives, and connecting the NCSC with technology transfer and investment experts. The organization also provided mentoring support for knowledge asset management and helped guide the licensing process through market engagement and competitive partner selection. The UK government has increasingly focused on turning public sector-developed technologies into commercially viable products that can deliver broader economic and security benefits.

Growing Focus on Hardware-Level Cybersecurity

The release of SilentGlass comes as cybersecurity experts continue raising concerns about hardware-level attack vectors that are often overlooked in traditional cybersecurity strategies. Modern monitors, docking stations, USB-connected devices, and display interfaces are increasingly viewed as potential entry points for attackers targeting enterprise and government systems. As hybrid work models expand globally, organizations are under pressure to secure not only software environments but also physical device connections used in day-to-day operations. The NCSC said SilentGlass was specifically designed to address these emerging risks without requiring complex deployment or major infrastructure changes.

NCSC Highlights Future Commercialization Plans

Ollie Whitehouse, Chief Technology Officer at the NCSC, described the commercialization of SilentGlass as an example of how government-developed innovation can support both national cybersecurity and economic growth. According to Whitehouse, the partnership demonstrates how UK government departments can derive greater value from intellectual property while making advanced security technologies more widely available. The NCSC also indicated that additional government-developed cybersecurity technologies could be commercialized in the future following the success of the SilentGlass initiative.

Dubai Police Warns Against Viral Energy Drink Videos Targeting Children on Social Media

Viral Energy Drink Videos

Dubai Police has issued a public warning about the growing spread of viral energy drink videos on social media platforms that encourage excessive consumption, particularly among children and teenagers. Authorities said many of these videos are designed solely to attract views and engagement while ignoring the serious health risks linked to overconsumption of energy drinks. The warning was issued by the Cybercrime Department under the General Department of Criminal Investigation at Dubai Police, which urged parents to closely monitor the type of online content their children are exposed to and educate them about the dangers of blindly imitating viral internet trends. According to Dubai Police, the increasing popularity of online challenges and influencer-driven content has made harmful behavior appear entertaining or harmless to young audiences. Officials stressed that some creators prioritize social media reach over public safety, exposing children to risky habits without discussing potential consequences. [caption id="attachment_112092" align="aligncenter" width="1024"]Energy Drink Videos Source: Dubai Police[/caption]

Energy Drink Videos Raise Serious Health Concerns

Dubai Police highlighted that excessive intake of energy drinks can lead to severe medical complications. Authorities warned that consuming high quantities of caffeine and stimulant-based beverages may cause heart rhythm disorders, convulsions, loss of consciousness, and in extreme cases, sudden cardiac arrest. Children and adolescents are considered particularly vulnerable to these effects because their bodies may react more strongly to stimulant ingredients commonly found in energy drinks. The police also noted that overconsumption can trigger a wide range of additional health issues, including poisoning, stomach disorders, anxiety, irritability, poor concentration, memory problems, sleep disturbances, high blood pressure, and rapid heartbeat. Officials said the concern is not limited to physical health alone. Repeated exposure to viral energy drink videos can normalize dangerous behavior among younger audiences who often attempt to replicate online trends without understanding the risks involved.

Dubai Police Urges Parents to Monitor Online Content

As part of the advisory, Dubai Police encouraged parents and guardians to maintain active supervision of the digital content consumed by children. Authorities emphasized the importance of discussing online safety and helping children identify misleading or harmful trends circulating on social media platforms. The force urged families to explain that not all viral content is trustworthy or safe, especially when it promotes unhealthy or dangerous actions for entertainment purposes. Dubai Police also advised the public to rely on verified medical and health sources for information regarding food, beverages, and wellness-related trends instead of depending on influencer content or unverified social media posts. The warning reflects broader concerns among authorities globally about how social media algorithms can rapidly amplify risky trends, especially among younger users who are highly engaged with short-form video platforms.

Public Asked to Report Harmful Online Content

Dubai Police called on community members to report any digital content that promotes dangerous behavior or threatens public safety. Authorities said reports can be submitted through the Dubai Police smart application, the dedicated E-Crime platform, or by contacting the non-emergency helpline at 901. Officials stressed that public reporting plays an important role in limiting the spread of harmful online material and protecting vulnerable groups from unsafe internet trends. The department also reminded social media users to think critically before participating in online challenges or consuming products promoted through viral content.

Dubai Police Expands Cyber Awareness Efforts

Alongside the warning, Dubai Police highlighted its ongoing efforts to improve public awareness around cyber safety and digital risks through its awareness e-platform. The online platform provides educational material in both Arabic and English and covers various topics related to cybercrime prevention, online fraud awareness, digital safety, and safe internet usage. According to Dubai Police, the platform is designed for all sections of society, including parents, children, employees, business owners, and regular internet users. Authorities said the initiative aims to help residents recognize online manipulation tactics, avoid cyber-related threats, and make safer decisions while using social media and digital platforms. The latest advisory on viral energy drink videos adds to growing efforts by law enforcement and public health authorities to address the real-world risks created by harmful social media trends targeting younger audiences.
  • ✇Firewall Daily – The Cyber Express
  • California Hits General Motors With Record $12.75 Million CCPA Privacy Settlement Samiksha Jain
    California Attorney General Rob Bonta and a coalition of state and local enforcement agencies have announced a $12.75 million settlement with General Motors over allegations that the automaker illegally collected and sold drivers’ personal data without proper consent, in violation of the California Consumer Privacy Act (CCPA). The California privacy settlement marks the largest CCPA penalty in California history so far and represents the state’s first enforcement action focused on data minimizat
     

California Hits General Motors With Record $12.75 Million CCPA Privacy Settlement

California Privacy Settlement

California Attorney General Rob Bonta and a coalition of state and local enforcement agencies have announced a $12.75 million settlement with General Motors over allegations that the automaker illegally collected and sold drivers’ personal data without proper consent, in violation of the California Consumer Privacy Act (CCPA). The California privacy settlement marks the largest CCPA penalty in California history so far and represents the state’s first enforcement action focused on data minimization requirements under California privacy law. The case centers on allegations that General Motors shared sensitive driver information, including geolocation data and driving behavior, with data brokers Verisk Analytics and LexisNexis Risk Solutions between 2020 and 2024.

California Privacy Settlement Targets Driver Data Sales

According to the complaint, GM collected data through its OnStar connected vehicle platform, which offers emergency assistance, navigation, and crash response services. Investigators alleged that the company sold names, contact details, precise location information, and driving behavior data of hundreds of thousands of Californians to the two data brokers. Authorities said the data was intended to help create driver-risk scoring products that could be used by insurance companies when setting premiums. The investigation was conducted jointly by the California Department of Justice, the California Privacy Protection Agency (CalPrivacy), and district attorneys from San Francisco, Los Angeles, Napa, and Sonoma counties. Attorney General Rob Bonta said the settlement sends a clear message about consumer control over personal data. “General Motors sold the data of California drivers without their knowledge or consent,” Bonta said in the announcement, adding that the data could reveal sensitive details about consumers’ daily routines and movements.

CCPA Violations and Data Minimization Concerns

A major part of the case focused on alleged violations of the CCPA’s data minimization and purpose limitation requirements, which were added to California law in 2023. Under these provisions, companies are required to collect and retain only the data necessary for a disclosed purpose. Investigators alleged that GM retained driving and location data long after it was needed to operate OnStar services and later sold that retained data to third parties. Authorities also alleged that GM failed to clearly inform consumers about how their information would be used. The complaint stated that GM’s privacy policies suggested driver data would only be used to provide requested OnStar services and even claimed the company did not sell driving or location information. Investigators said the company’s practices contradicted those statements. San Francisco District Attorney Brooke Jenkins described modern vehicles as “rolling data collection machines” and said consumers deserve transparency about what information is collected and how it is shared. Los Angeles County District Attorney Nathan J. Hochman said companies handling consumer data would be held accountable under California privacy laws, regardless of their size.

Connected Vehicle Privacy Under Scrutiny

The settlement follows growing regulatory scrutiny around connected vehicle privacy and automotive data collection practices. In 2023, CalPrivacy launched investigations into connected car manufacturers and their handling of consumer information. Public attention increased further in 2024 after a report by The New York Times highlighted how automakers were sharing driving behavior data with insurance companies. The reporting indicated that some consumers outside California had experienced increased insurance premiums tied to such data-sharing practices. California investigators later determined that California drivers were likely not directly affected through insurance rate increases because state insurance laws prohibit insurers from using driving behavior data to set premiums. However, regulators maintained that the collection, retention, and sale of the data itself violated California privacy requirements.

Settlement Terms for General Motors

Under the proposed California privacy settlement, General Motors must implement several privacy-related measures over the coming years. The company will be required to:
  • Pay $12.75 million in civil penalties.
  • Stop selling driving data to consumer reporting agencies for five years.
  • Delete retained driving data within 180 days unless consumers provide express consent for limited uses.
  • Request the deletion of driver data already shared with LexisNexis and Verisk.
  • Establish and maintain a comprehensive privacy compliance program.
  • Submit privacy assessments and compliance reports to California regulators and prosecutors.
The settlement also reinforces California’s broader push to strengthen consumer control over personal information under the CCPA. CalPrivacy Executive Director Tom Kemp said California privacy laws require businesses to collect only the information they genuinely need and to be transparent about how that data is handled. Alongside the settlement announcement, regulators also highlighted the state’s Delete Request and Opt-out Platform (DROP), which allows Californians to submit requests to delete personal information held by hundreds of registered data brokers.

Dubai Police Smash International Scam Empire in Massive FBI and China-Led Operation

Operation Tri-Force Sentinel

In a major international enforcement action, Operation Tri-Force Sentinel, led by Dubai Police, in coordination with the FBI and Chinese Police, has dismantled a large transnational fraud network involved in global financial scams. The Operation Tri-Force Sentinel crackdown resulted in the arrest of 276 individuals linked to organised cyber-enabled fraud activities spanning multiple countries, primarily involving suspects from Southeast Asia. The Operation Tri-Force Sentinel was carried out under the UAE Ministry of Interior and focused on disrupting criminal syndicates running high-yield investment scams, commonly known as HYIS, “pig butchering” schemes, and virtual currency fraud. Authorities confirmed that nine major fraud centres were dismantled during the coordinated action.

276 Arrests and Nine Fraud Centres Dismantled in Operation Tri-Force Sentinel

As part of the operation, law enforcement agencies executed synchronized raids that dismantled three major criminal syndicates operating fraud centres. These centres were responsible for large-scale financial deception campaigns targeting victims across several regions. The operation led to the arrest of 276 suspects, with authorities confirming that the network used advanced social engineering techniques. Victims were reportedly engaged through digital platforms, where trust was gradually built before financial exploitation took place. Dubai Police also confirmed the arrest of a key leader of one of the syndicates in Thailand, carried out in coordination with the Royal Thai Police. The enforcement action marked one of the most significant coordinated strikes against cyber-financial crime groups in recent times under Operation Tri-Force Sentinel. [caption id="attachment_111753" align="aligncenter" width="553"]Operation Tri-Force Sentinel Image Source: Dubai Police[/caption]

Dubai Police, FBI, and Chinese Police Coordination 

Dubai Police played a central role in directing and executing Operation Tri-Force Sentinel, enabling real-time intelligence sharing between international partners. The collaboration with the FBI and Chinese Police was described as critical to the success of the operation. Dubai Police stated that the operation reflects a proactive strategy to combat evolving transnational financial crime threats. The agency emphasized that coordinated international efforts were essential to dismantling complex criminal networks operating across borders. The FBI highlighted the significance of joint enforcement efforts, stating that the operation demonstrates the effectiveness of coordinated global action in disrupting large-scale fraud schemes. It further noted that the partnership with the UAE authorities, particularly the Dubai Police, played a key role in achieving operational success. Chinese Police also reaffirmed their commitment to combating telecom and financial fraud crimes. They emphasized continued cooperation with global law enforcement agencies to address emerging cross-border criminal activities targeted in Operation Tri-Force Sentinel.

Transnational Fraud Networks and Financial Crime Disruption

The dismantled network operated multiple fraud centres using structured and organised digital fraud models. These included investment scams and cryptocurrency-related fraud schemes that have increasingly affected victims across several countries. Authorities noted that the criminal groups involved in Operation relied heavily on psychological manipulation and digital engagement strategies to execute financial scams at scale. The coordinated enforcement action disrupted key operational infrastructure of these networks in a single phase.

International Cooperation Strengthened 

This operation highlights the growing importance of international cooperation in tackling financial crime networks that operate beyond national borders. The joint action between Dubai Police, the FBI, and the Chinese Police demonstrates strengthened coordination in intelligence sharing and enforcement execution. Officials involved in the operation emphasized that continued collaboration is essential to countering sophisticated fraud networks. The success of Operation reflects the ability of global law enforcement agencies to respond jointly to complex cyber-enabled financial threats. The operation marks a significant step in global efforts to combat organised fraud networks and reinforces the role of coordinated international enforcement in addressing cross-border financial crime.
  • ✇Firewall Daily – The Cyber Express
  • Toronto Police Bust Mobile Smishing Network Targeting Thousands Samiksha Jain
    A major Canada SMS blaster cybercrime case has come to light as Toronto Police charge three men with 44 offences in what authorities describe as a first-of-its-kind investigation in the country. The case, part of Project Lighthouse, highlights a growing threat where cybercriminals use mobile technology to target thousands of people at once. The investigation began in November 2025 after a security partner alerted police to a suspected SMS blaster operating in downtown Toronto. What followed w
     

Toronto Police Bust Mobile Smishing Network Targeting Thousands

Canada SMS blaster cybercrime case

A major Canada SMS blaster cybercrime case has come to light as Toronto Police charge three men with 44 offences in what authorities describe as a first-of-its-kind investigation in the country. The case, part of Project Lighthouse, highlights a growing threat where cybercriminals use mobile technology to target thousands of people at once. The investigation began in November 2025 after a security partner alerted police to a suspected SMS blaster operating in downtown Toronto. What followed was a months-long probe into a sophisticated operation that combined mobility, deception, and large-scale disruption.

What Is the Canada SMS Blaster Cybercrime Case?

At the center of the Canada SMS blaster cybercrime case is a device that mimics a legitimate cellular tower. When nearby mobile phones connect to it, users receive fraudulent messages that appear to come from trusted organizations. These messages often include links to fake websites designed to steal sensitive information such as banking credentials and passwords. This method is widely known as “smishing,” a form of phishing carried out through text messages. However, the scale and mobility of the device used in this case set it apart from typical cyber fraud schemes. Deputy Chief Rob Johnson said the operation posed serious risks beyond financial fraud. He noted that the technology had the capability to reach thousands of devices simultaneously, raising concerns about public safety.

Large-Scale Disruption Across the Greater Toronto Area

Investigators found that the SMS blaster was not stationary. It was operated from vehicles, allowing suspects to move across the Greater Toronto Area and deploy the device in multiple locations. According to Detective Sergeant Lindsay Riddell, tens of thousands of devices connected to the rogue network over several months. Police also recorded more than 13 million network disruptions, during which affected devices were unable to connect to legitimate cellular networks. These disruptions had serious implications. During those moments, access to emergency services such as 9-1-1 could have been impacted, making the Canada SMS blaster cybercrime case not just a financial threat but also a public safety concern.

Arrests and Seizure of Devices

Toronto Police executed search warrants on March 31 at residences in Markham and Hamilton, leading to the arrest of two suspects. Authorities seized multiple SMS blasters along with a significant amount of electronic evidence. A third individual later turned himself in on April 21. All three now face a combined total of 44 charges linked to the operation. The Canada SMS blaster cybercrime case involved extensive coordination between multiple agencies, including the Royal Canadian Mounted Police National Cybercrime Coordination Centre, regional police services, financial institutions, and telecom providers. Officials say this collaboration was key to identifying and disrupting the activity.

A New Type of Cyber Threat in Canada

Law enforcement officials emphasized that this is the first known case of SMS blaster technology being used in Canada. The case reflects how cyber-enabled crimes are becoming more advanced and harder to detect. Authorities noted that while the technology is new, the objective remains the same: to gain unauthorized access to personal and financial information. The Canada SMS blaster cybercrime case shows how attackers are combining traditional fraud tactics with newer tools to scale their operations.

Public Advisory and Safety Measures

Police are urging the public to remain cautious when receiving unexpected text messages. Users are advised not to click on suspicious links or share personal information through unsolicited messages. Officials recommend accessing banking services only through official applications or by directly entering website addresses into browsers. Victims of suspected fraud are encouraged to report incidents to law enforcement. Deputy Chief Johnson also acknowledged the role of the Toronto Police Coordinated Cyber Centre and partner agencies in handling the investigation. He stressed that staying informed and vigilant remains one of the most effective defenses against such threats.
❌
❌