Britain Gains Access to Ukraine’s ‘Goldmine’ of Battlefield AI Data
![]()

![]()

![]()
The FBI is warning the public about sexual exploitation actors illegally accessing social media and personal accounts to steal explicit images and videos from adult and underage victims. The stolen material, also known as non-consensual intimate images (NCII), is being posted or sold on criminal marketplaces, often without the victim's knowledge.
According to the FBI, these actors use social engineering and cyber intrusion tactics to target specific individuals or general targets of opportunity. After gaining access to accounts, they steal explicit content and share it through community forums or illicit marketplaces.
The FBI said personally identifiable information, including a victim's name, date of birth, email address, phone number and social media username, is often posted alongside the stolen material. This can expose victims to continued harassment and re-victimization.
The FBI has identified several methods used by sexual exploitation actors to gain access to victims' accounts.
In password/PIN targeting, actors use high-volume password and PIN attempts against social media and personal accounts. The information used in these attempts can come from data leak sites, social media and open-source information.
When victims are known to the actors, curated lists may include personal details such as names, date of birth or variations of those details.
Another tactic involves social media customer service impersonation through text messages. Victims may receive messages claiming their account is being disabled or locked unless they provide a verification code.
The actor then requests a password reset, causing a code to be sent to the victim. If the victim shares the code, the actor can reset the password and access the account.
The FBI also warns about phishing campaigns using look-alike domains and email accounts designed to appear as social media customer support.
These messages may claim there has been a new login and contain an embedded link asking the victim to change their password. Clicking the malicious link can give the actor access to the account.
Once explicit content is stolen, sexual exploitation actors may post or sell it while including personal information about the victim. The FBI said victims can subsequently face harassment, sextortion, stalking or other targeted attacks.
The actors may also advertise stolen content through a victim's own social media page, increasing the potential for further exposure.
The FBI advises people to avoid storing sensitive images or videos on social media platforms or other internet-accessible sites.
It recommends using unique, complex passphrases and PINs along with multi-factor authentication (MFA). Password information directly associated with a person's identity, including names or birthdays, should be avoided.
Users should also be cautious with links received through emails and text messages. The FBI recommends going directly to the relevant website to address account concerns and checking URLs before clicking.
Unrequested temporary passwords, PIN resets or access codes should also be treated with caution. The FBI advises users not to share login information, even when someone claims to represent a platform or service.
People who believe their explicit content was stolen or leaked can provide information through the FBI's NCII reporting site. The FBI also advises the public to continue reporting fraud, scams and cyber threats to the Internet Crime Complaint Center or a local FBI Field Office.
![]()
.ENCRT extension for encrypted files. A documented sample from July 2025 used the .CRYPT extension. The ransomware also uses Windows Management Instrumentation to delete volume shadow copies before encryption, while one victim had backup and archived data deleted from both primary and disaster recovery infrastructure.

![]()

![]()
The U.S. Department of Justice has seized more than 1,000 illegal World Cup streaming domains accused of broadcasting FIFA World Cup 2026 matches without authorization, marking a major enforcement action against digital piracy during the tournament. The domains were seized in three separate actions under U.S. copyright law as part of Operation Offsides, an initiative targeting websites involved in unauthorized World Cup broadcasts.
The latest action includes nearly 400 websites seized by the end of June, according to the Department of Justice. The investigation was carried out by U.S. Immigration and Customs Enforcement Homeland Security Investigations (HSI) Washington Field Office and the National Intellectual Property Rights Coordination Center.
According to an affidavit filed in support of a seizure warrant in the U.S. District Court for the Eastern District of Virginia, the seized domains were used to offer copyright-protected content through real-time streams of 2026 World Cup matches as they were being played and first broadcast.
HSI special agents confirmed that the domains were actively broadcasting World Cup matches without authorization. The domains were identified with assistance from FIFA, with additional information provided by beIN Media Group, NBC Universal, the Motion Picture Association’s Alliance for Creativity and Entertainment (ACE), Ultimate Fighting Championship (UFC), and Warner Brothers.
FIFA holds the exclusive rights to sanction and stage the FIFA World Cup 2026, which is being hosted across multiple cities in the United States, Canada and Mexico.
The U.S. action is part of Operation Offsides, which focuses on identifying and seizing websites facilitating unauthorized broadcasts of World Cup matches.
The operation is led by the National Intellectual Property Rights Coordination Center and is being conducted with HSI Washington, D.C., HSI Attaché offices, private sector organizations and law enforcement partners globally.
Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division said the effort to seize more than 1,000 domains was aimed at protecting intellectual property rights and reducing risks to consumers from malicious software associated with some illicit streaming services.
[caption id="attachment_113257" align="aligncenter" width="400"]HSI Deputy Executive Associate Director Matthew Millhollin also warned that users accessing unauthorized streaming platforms could face risks including malware and payment information theft.
The U.S. enforcement action was accompanied by international efforts under Operation Red Card, which targeted digital piracy and counterfeiting connected to the World Cup across the Western Hemisphere.
The Justice Department’s International Computer Hacking and Intellectual Property (ICHIP) program coordinated enforcement efforts involving Argentina, Brazil, Chile, Colombia, the Dominican Republic, Ecuador, Paraguay and Peru.
The coordinated actions resulted in hundreds of illegal streaming sites being blocked, including 14 in Argentina, 223 in Ecuador, 28 in Peru, 309 in Brazil, 256 in the Dominican Republic and 1,140 in Colombia.
Colombian authorities also conducted 13 nationwide search-and-seizure operations targeting counterfeit sports apparel, resulting in 11 arrests and convictions.
On July 10, authorities launched Phase II of Operation Red Card in Colombia, conducting simultaneous operations in Bogotá, Soacha, Maríalabaja, Manatí and Sincerín.
An ICHIP-mentored cybercrime prosecutorial team from the Colombian Attorney General’s Office arrested four members of the cybercriminal group Los Ciberinfiltrados. According to the Justice Department, the group had illegally accessed telecommunications systems since 2024 and sold pirated streaming content, including World Cup matches.
The group allegedly used fraudulent credentials, VPNs, interception of security codes and manipulation of corporate system profiles to distribute the pirated content.
In Europe, ICHIP Bucharest also coordinated with Europol and international counterparts to address illegal streaming activities during the World Cup.
The latest action follows a June 2026 announcement by the U.S. Department of Justice involving the seizure of nearly 400 websites accused of illegally broadcasting FIFA World Cup 2026 matches.
That earlier enforcement action, also conducted under Operation Offsides, targeted websites accused of copyright infringement by offering unauthorized live streams of World Cup matches for profit.
With more than 1,000 domains now seized in the U.S. actions, authorities continue to target unauthorized streaming platforms and digital piracy networks linked to the tournament.

![]()

![]()
A major global crypto investment scam investigation has led to the arrest of an alleged key figure behind an international criminal organization accused of defrauding victims of more than €100 million every month. Dutch police announced multiple arrests across Europe following a long-running investigation into a fraud network that allegedly employed over 700 people operating from around 20 call centers worldwide.
The main suspect, a 46-year-old dual Israeli and Polish national, was arrested at an airport in Poland on May 26 at the request of Dutch authorities. Investigators believe he played an indispensable role in the organization, which allegedly carried out large-scale investment fraud targeting victims across multiple countries.
According to Dutch police, the organization functioned like a professional company with approximately 700 employees spread across nearly 20 offices globally. Individuals working as financial advisors scam operators allegedly contacted victims daily through online platforms and telephone calls while posing as legitimate investment professionals.
Authorities said the organization was structured with a central headquarters overseeing multiple teams, each assigned to target victims in specific countries. Employees reportedly worked under pseudonyms and used technical measures to hide their identities and locations.
![]()
As part of the investigation, Belgian police arrested five individuals believed to have worked as fraudulent financial advisors.
The investigation resulted in several coordinated arrests during May and July.
On July 7, authorities arrested two Dutch nationals aged 45 and 34, along with a 34-year-old Belgian, all residing in Cyprus. A 25-year-old suspect was also arrested in Belgium the same day. On July 10, police arrested a 44-year-old Dutch national in Athens.
The main suspect has since been extradited to the Netherlands, where an examining magistrate ordered 14 days of pre-trial detention. Dutch authorities indicated that additional arrests remain possible as the investigation continues.
Investigators said the online investment scam relied on building long-term trust with victims. Individuals posing as account managers or financial advisors maintained frequent contact through phone calls and online communication, sometimes over several months.
Victims were encouraged to begin with relatively small investments that appeared to generate immediate returns. Police said the investment platforms displayed convincing but fabricated profits, even though no actual investments were being made.
As confidence grew, victims were persuaded to transfer increasingly larger amounts, often in the form of cryptocurrency fraud payments. Instead of being invested, investigators said the funds were diverted directly to the criminal organization.
Authorities also warned that victims who stop investing may later be contacted by so-called recovery companies requesting upfront deposits to recover lost funds. Police believe these recovery operations may also be connected to the same fraud networks.
Dutch authorities have received approximately 550 reports connected to the organization, while Belgian police have recorded around 200 complaints. Investigators estimate the total number of victims worldwide could reach tens of thousands.
The financial losses reported by victims in the Netherlands alone amount to nearly €25 million, with many individuals losing well over €10,000.
Dutch police said officers proactively contacted some victims after discovering that many remained unaware they had fallen victim to cyber fraud.
Financial investigators are now examining whether assets linked to the suspects can be frozen or seized.
Investigators said the criminal organization remained active since at least 2021 and relied heavily on concealed digital infrastructure to evade law enforcement.
By tracing financial transactions, IP addresses, and other digital evidence, the Dutch police identified offices, suspects, and critical infrastructure supporting the operation. Authorities worked with commercial service providers to take key elements of the network offline.
The investigation also involved Europol, with intelligence shared across multiple countries to support ongoing criminal prosecutions.
Officials said the case demonstrates the scale and sophistication of modern investment fraud operations and highlighted continued international cooperation to dismantle cyber-enabled financial crime networks.

![]()

![]()
The Russia cyberattack targeting Poland's critical infrastructure has been formally attributed to Russia's Federal Security Service (FSB), with the European Union and the United Kingdom announcing a coordinated package of cyber sanctions against Russian-linked hackers and organizations. The move follows an attempted disruption of Poland's energy sector last winter that officials said came close to triggering a major blackout affecting nearly half a million people.
According to statements released by the EU and UK on Monday, the FSB's Center 16 was responsible for attempted cyber sabotage against Poland's heating and power infrastructure, as well as cyber intrusions targeting water treatment facilities. The allies also accused the agency of conducting broader cyber operations against governments and critical infrastructure across Europe.
The European Union said Center 16, the signals intelligence arm of the FSB, has conducted malicious cyber activities affecting multiple member states and international partners. According to the bloc, these operations have included infiltration of government networks, cyber espionage, and sabotage targeting critical infrastructure in France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania, and Finland.
The EU also stated that Center 16 controls several cyber threat groups, including TURLA, and has been involved in cyber operations against strategic government entities in France since 2010 and the country's defense industry in 2025. In Germany, it allegedly targeted government institutions, while in Poland it carried out disruptive operations against combined heating and power plants.
British authorities described last December's attempted attack on Poland's energy grid as "reckless," saying it was another example of Russia's attempts to create disruption across Europe.
The cyber incident targeting Poland's energy infrastructure last winter was initially linked by cybersecurity firms ESET and Dragos to Sandworm, a threat group associated with Russia's military intelligence agency.
However, Poland's national cybersecurity agency, CERT Polska, later disputed that assessment after tracing the attack infrastructure and connecting it to a cluster associated with the FSB.
Separately, Poland's domestic intelligence service warned in May that cyber intrusions targeting the country's water treatment facilities posed a direct risk to the continuity of water supply.
In response, the European Union imposed restrictive measures on nine individuals and four entities linked to Russia's cyber ecosystem. The sanctions target intelligence officers, cybercriminals, self-proclaimed hacktivists, and private companies accused of supporting or facilitating malicious cyber operations.
The wider sanctions package announced by European partners targets more than 30 individuals and organizations, including operators behind the Lumma Stealer malware, companies accused of recruiting hackers from Russian universities, and individuals associated with the pro-Kremlin Rybar military blog.
EU foreign policy chief Kaja Kallas said Russia continues to rely on intelligence agencies, cybercriminal groups, hacktivists, and private companies to conduct malicious cyber operations against Europe and its partners.
She added that the bloc strongly condemns the misuse of this cyber ecosystem, which has targeted public services and critical infrastructure, resulting in operational disruptions and financial losses.
France also announced additional sanctions and said it would summon the Russian ambassador over what it described as persistent malicious cyber activities conducted for espionage purposes.
A technical report from France's Cyber Crisis Coordination Center (C4) identified 11 interception centers operated by Center 16 across Russia, including Unit 61240, which it said specifically focused on France.
French authorities alleged that the unit targeted government ministry systems in 2014, compromised the French Embassy network in Moscow in 2018, and stole significant volumes of data from a research institute working with the French defense industry in February 2025.
France also stated that one newly sanctioned group had claimed responsibility for destabilization efforts targeting the 2024 Paris Olympic and Paralympic Games.
Alongside the sanctions, the United States and intelligence agencies from a dozen allied countries published a joint cybersecurity advisory warning that Russian operators linked to Center 16 have been scanning internet-connected devices protected by weak or default credentials.
The United Kingdom separately sanctioned individuals connected to Lumma Stealer, describing it as one of the world's most widely used information-stealing malware families. British officials said credentials stolen through the malware have been used to support Russian espionage operations globally. According to the UK's National Crime Agency, more than 2,100 victims in the country were infected by Lumma Stealer during the past six months.
British Foreign Secretary Yvette Cooper said the sanctions are intended to disrupt the cybercriminal ecosystem supporting Moscow's intelligence services, while emphasizing that the coordinated measures send a clear message against the use of proxy cyber groups.
The Kremlin has repeatedly denied conducting offensive cyber operations. Russian President Vladimir Putin has dismissed European allegations of sabotage and cyberattacks as baseless, saying they are intended to justify aggressive policies against Russia.

![]()
An alleged member of the Scattered Spider cybercrime group has been extradited from Finland to the United States to face federal charges related to conspiracy, cyber intrusion, and fraud. U.S. authorities said the case marks another step in their ongoing efforts to prosecute individuals accused of participating in high-profile cybercrime operations linked to the notorious hacking group.
Peter Stokes, 19, a dual U.S. and Estonian citizen, made his initial appearance in federal court in Chicago after being extradited from Finland.
According to the U.S. Department of Justice, Stokes was arrested by Finnish authorities in April following an Interpol Red Notice and was transferred to the United States last week. A criminal complaint filed in the Northern District of Illinois accuses him of participating in cyberattacks carried out as part of the Scattered Spider group.
According to the complaint, Scattered Spider, also known as Octo Tempest, UNC3944, and 0ktapus, has been associated with more than 100 network intrusions. Authorities allege the group's activities have resulted in over $100 million in ransom payments and millions of dollars in additional damages suffered by victims.
Investigators said the group targeted companies across the United States by obtaining access to employee accounts through fraudulent methods.
Once inside corporate networks, the attackers allegedly encrypted data or exfiltrated sensitive information to remote servers before demanding cryptocurrency payments to restore access or prevent the public release of stolen data.
The criminal complaint describes an alleged cyber intrusion that occurred in May 2025 involving a luxury jewelry retailer.
Federal prosecutors allege that Stokes and other co-conspirators breached the retailer's computer systems, exfiltrated company data, and demanded approximately $8 million in cryptocurrency as ransom. According to court documents, the retailer's security team successfully removed the threat actors from its network before any ransom payment was made.
Although the company did not pay the ransom, authorities said it still incurred losses of at least $2 million due to business disruption, investigation costs, and mitigation efforts following the incident.
The extradition and criminal charges were announced by the Department of Justice, the U.S. Attorney's Office for the Northern District of Illinois, and the FBI. The investigation also involved the FBI's Copenhagen Law Enforcement Attaché Office, the FBI Las Vegas Field Office, the Justice Department's Office of International Affairs, and Finland's National Bureau of Investigation.
Officials said the case forms part of Operation Riptide, an ongoing FBI campaign focused on disrupting cybercriminal actors, infrastructure, financial networks, and fraud schemes targeting Americans.
According to the FBI, Americans reported more than $20 billion in cybercrime losses last year, representing a 26% increase compared with the previous year.
Assistant Attorney General A. Tysen Duva said the charges stem from years of investigative work by the Justice Department, the U.S. Attorney's Office, and the FBI, adding that authorities would continue working together to pursue cybercriminals operating across international borders.
U.S. Attorney Andrew S. Boutros said the alleged attacks caused significant disruption to businesses across the United States and emphasized the government's commitment to prosecuting individuals involved in cyber intrusions.
FBI Special Agent-in-Charge Douglas S. DePodesta also highlighted the role of international law enforcement partnerships in identifying alleged members of the hacking group and pursuing cross-border cybercrime investigations.
The arrest follows recent law enforcement efforts targeting the Scattered Spider threat group. In July 2025, the FBI and CISA released updated guidance describing the group's latest attack techniques, including the use of DragonForce ransomware to encrypt VMware ESXi servers.
The advisory urged organizations to maintain isolated offline backups, implement phishing-resistant multifactor authentication (MFA), and apply application controls to manage software execution.
Separately, in November 2025, two alleged Scattered Spider members appeared before Southwark Crown Court in the United Kingdom and pleaded not guilty to charges related to the August 2024 cyberattack on Transport for London (TfL).
The Department of Justice emphasized that the complaint against Stokes contains allegations only. As with all criminal cases, he is presumed innocent unless and until proven guilty in court.

![]()
The Illegal World Cup Streaming Domains crackdown has intensified as the U.S. Department of Justice announced the seizure of nearly 400 websites that were illegally broadcasting FIFA World Cup 2026 matches. The enforcement action, launched ahead of the tournament's knockout stage, targets websites accused of violating copyright infringement laws by offering unauthorized live streams of World Cup matches for profit.
According to the Justice Department, the domains were seized under U.S. copyright law as part of Operation Offsides, an international initiative focused on disrupting digital piracy networks linked to the World Cup.
Assistant Attorney General A. Tysen Duva of the Justice Department's Criminal Division said the operation was designed to disrupt international networks profiting from the global popularity of the World Cup.
"We have seized hundreds of domains, used to illegally stream World Cup matches for profit, to disrupt the international networks that profit from the global popularity of the World Cup," Duva said.
He added that the Criminal Division will continue efforts to disrupt and, where appropriate, prosecute websites and individuals involved in the illegal activity.
[caption id="attachment_112952" align="aligncenter" width="602"]The domain seizures are part of Operation Offsides, led by the National Intellectual Property Rights Coordination Center in coordination with HSI, HSI Attaché offices, private sector organizations, and international law enforcement agencies.
According to an affidavit filed in the Eastern District of Virginia, investigators found that the seized websites were providing unauthorized real-time streams of FIFA World Cup 2026 matches as they were being officially broadcast.
HSI special agents confirmed that the domains were actively streaming matches without authorization.
Authorities identified the domains with assistance from FIFA, while additional supporting information was provided by beIN Media Group, NBC Universal, the Motion Picture Association's Alliance for Creativity and Entertainment (ACE), Ultimate Fighting Championship (UFC), and Warner Brothers.
FIFA holds the exclusive rights to organize and stage the FIFA World Cup 2026, which is being hosted across cities in the United States, Canada, and Mexico.
Director Ivan J. Arvelo of the National Intellectual Property Rights Coordination Center said unauthorized broadcasts violate intellectual property rights and financially benefit criminal organizations.
He said the operation disrupted networks responsible for stealing and distributing copyrighted content while helping ensure fans access matches through legitimate channels.
HSI Washington Field Office Special Agent in Charge Eric Weindorf also warned that illegal streaming sites may expose users to cybersecurity threats.
According to Weindorf, viewers using unauthorized streaming platforms could face malware risks, insecure connections, and the potential compromise of personal and financial information, in addition to the copyright violations committed by the operators of such sites.
The domain seizure operation was coordinated with international partners through the International Computer Hacking and Intellectual Property (ICHIP) Network.
Authorities targeted servers and domains associated with online piracy in Peru and Bulgaria, which officials identified as known centers of illegal streaming activity. Additional ICHIP-supported enforcement actions took place in Croatia, Romania, Poland, and Colombia after U.S. authorities shared intelligence to help identify domains involved in unauthorized World Cup broadcasts.
The Justice Department said the operation demonstrates ongoing cooperation between domestic and international law enforcement agencies in combating cross-border piracy.
The Justice Department noted that its Computer Crime and Intellectual Property Section (CCIPS) investigates and prosecutes cybercrime and intellectual property offenses alongside domestic and international partners.
Since 2020, CCIPS has secured the conviction of more than 180 cybercrime and intellectual property offenders and obtained court orders returning more than $350 million in victim funds.
The latest enforcement follows a similar HSI-led operation during the 2022 FIFA World Cup, when authorities seized more than 70 websites involved in unauthorized streaming.
The Justice Department said Operation Offsides will continue to focus on identifying and shutting down websites that facilitate illegal broadcasts while protecting intellectual property during the FIFA World Cup.

![]()

![]()

![]()

![]()
"This is effectively a Mini Shai-Hulud campaign: it uses the same core tactics of install-time execution, credential harvesting, CI/CD targeting, encrypted exfiltration, and potential downstream propagation," Socket said.
"It commits the encrypted result envelope through the GitHub API," Socket said. "The commit message can include: IfYouInvalidateThisTokenItWillNukeTheComputerOfTheOwner:."Researchers from OX Security identified the first commit containing the phrase "Miasma: The Spreading Blight" on May 29, 2026. This suggests either that the malware variant had already been active by that date or that attackers began testing the campaign around that time.
"runOn": "folderOpen" to ensure automatic execution whenever a project is opened."Because the malware includes background execution and potential developer-tool persistence mechanisms, uninstalling the npm package or deleting node_modules should not be considered sufficient cleanup," Socket explained.The company also urged organizations operating CI/CD pipelines to suspend affected workflows, invalidate any build artifacts created during the exposure period, and review whether software releases, container images, npm packages, or deployment artifacts were generated after installation of the malicious package.

![]()

![]()

![]()

![]()

![]()