Visualização normal

Antes de ontemStream principal
  • ✇Cybersecurity News
  • BREEZE COMET Threat Actor Attacks Brazilian Banks Do Son
    Google warns the BREEZE COMET threat actor attacks Brazilian banks to execute mass financial fraud. Learn how to protect your payment systems. Related Posts: Dark Caracal Deploys New GoCaracal Malware Framework Cambodia Malware Campaign Uses PNG Files to Deliver SparkRAT AnonyMousKIT Uses AI Voice Calls to Unlock Stolen iPhones The post BREEZE COMET Threat Actor Attacks Brazilian Banks appeared first on Daily CyberSecurity.
     
  • ✇Security Affairs
  • Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams Pierluigi Paganini
    INTERPOL’s Operation Jackal IV made 58 arrests and exposed global networks laundering money from scams, fraud and sextortion. INTERPOL announced that Operation Jackal IV, running from November 2025 to June 2026, led to 58 arrests and identified 263 suspects tied to West African organized crime networks, groups like Black Axe that are responsible for a huge share of the world’s romance scams, crypto fraud, and business email compromise (BEC) schemes. “Operation Jackal IV (November 2025 – J
     

Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams

26 de Agosto de 2026, 04:17

INTERPOL’s Operation Jackal IV made 58 arrests and exposed global networks laundering money from scams, fraud and sextortion.

INTERPOL announced that Operation Jackal IV, running from November 2025 to June 2026, led to 58 arrests and identified 263 suspects tied to West African organized crime networks, groups like Black Axe that are responsible for a huge share of the world’s romance scams, crypto fraud, and business email compromise (BEC) schemes.

“Operation Jackal IV (November 2025 – June 2026) aimed to disrupt money laundering, identify high-value targets, seize assets, and support arrests and prosecution.” Interpol announced. “The operation, which brought together 22 countries from six continents, is a response to the escalating global threat posed by West African criminal networks – such as the Black Axe and other similar groups. These groups are responsible for a significant share of the world’s cyber-enabled financial fraud, typically through romance scams, cryptocurrency and investment scams or business email compromise fraud, as well as other serious and violent crimes.”

The goal wasn’t to chase individual scammers. Investigators followed the money behind the scams: shell companies, mule accounts and criminal services that help move and hide stolen funds. Tomonobu Kaya of INTERPOL’s Financial Crime and Anti-Corruption Centre explained the approach: By following illicit financial flows across borders, we are attacking the very lifeblood of organized crime.

Argentina turned up one of the operation’s biggest finds. Investigators identified 196 individuals connected to a crime-as-a-service network suspected of supplying website domains and laundering support specifically for West African criminal groups, resulting in 17 arrests. INTERPOL sent an Operational Support Team to help analyze seized data and map out the wider network of suspects, the kind of cross-border analytical work that individual national police forces usually can’t pull off on their own.

South African authorities raided seven locations in Johannesburg linked to a group running romance and investment scams against retirees in English-speaking countries.

The syndicate assigned members to specific roles, such as “conversion” and “retention” agents. The operation led to 39 arrests, $2.67 million seized and 257 bank accounts frozen, the largest number of arrests in the operation.

Italy’s case shows how much damage a single laundering account can absorb. One individual was tied to a pan-European laundering network moving money through shell companies and remittance services, and investigators traced €845,000 laundered through a single account across 560 separate transactions using 20 different financial instruments. That’s not a careless operator; that’s someone who understood exactly how to fragment a large sum into a pattern designed to look unremarkable at every individual step.

Romania’s case was the biggest by dollar value, and arguably the most brutal in its simplicity. A call center ran a fake investment scheme promising big returns on stocks and crypto, funneling victims’ money into wallets the operators controlled, and by the time authorities dismantled it, the estimated theft and laundering total had climbed to around €143 million globally. Eleven arrests and roughly €379,000 in cash and crypto seized, plus six properties and several luxury watches, is a real result, but it’s a fraction of what actually got stolen.

“Beyond individual cases, Operation Jackal IV also enabled the analysis of critical and emerging trends, including a rise in West African organized crime groups using sextortion to target minors, with victims as young as 14. Offenders typically contact minors via social media, build trust and coerce them into sharing explicit images or videos.” concludes INTERPOL. “They then threaten to distribute this material to the victim’s contacts unless a ransom is paid.”

The report’s darkest finding sits outside any single country’s arrest count. INTERPOL flagged a rising trend of these same criminal networks using sextortion against minors as young as 14, building trust through social media before coercing victims into sharing explicit images and then threatening to distribute that material unless a ransom gets paid. Some of these groups were even observed buying crime-as-a-service support through the dark web specifically to outsource pieces of that operation, treating exploitation infrastructure as just another service line alongside laundering and fraud.

That’s the uncomfortable throughline connecting every case here: these aren’t scattered opportunists, they’re networks running organized business models with specialized roles, outsourced services, and financial engineering sophisticated enough to move hundreds of millions across borders. Twenty-two countries coordinating for eight months produced real numbers, real arrests, real frozen accounts. It also produced a fairly clear picture of how much more organized this side of cybercrime has become, and how much further there is to go.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Operation Jackal)

  • ✇Firewall Daily – The Cyber Express
  • Global Crackdown on West African Crime Networks Leads to 58 Arrests Samiksha Jain
    An eight-month international operation targeting West African organized crime groups has resulted in 58 arrests and the identification of 263 suspects across 22 countries, according to INTERPOL. Operation Jackal IV, conducted from November 2025 to June 2026, focused on disrupting criminal networks, tracing illicit funds, identifying high-value targets and supporting arrests and prosecutions. The operation brought together countries across six continents to tackle the growing global threat pos
     

Global Crackdown on West African Crime Networks Leads to 58 Arrests

26 de Agosto de 2026, 05:12

West African Organized Crime Groups

An eight-month international operation targeting West African organized crime groups has resulted in 58 arrests and the identification of 263 suspects across 22 countries, according to INTERPOL. Operation Jackal IV, conducted from November 2025 to June 2026, focused on disrupting criminal networks, tracing illicit funds, identifying high-value targets and supporting arrests and prosecutions. The operation brought together countries across six continents to tackle the growing global threat posed by West African criminal networks, including Black Axe and similar groups. These networks have been linked to a significant share of global cyber-enabled financial fraud, including romance scams, cryptocurrency and investment scams, and business email compromise fraud.

Operation Jackal IV Targets West African Organized Crime Groups

Operation Jackal IV also targeted money laundering activities used to move and conceal criminal proceeds across borders. INTERPOL coordinated cross-border intelligence sharing, analysis and operational support during the operation. It also provided specialized training to strengthen international investigations into financial crime. Tomonobu Kaya, Director of the INTERPOL Financial Crime and Anti-Corruption Centre, said the operation showed the importance of international cooperation in following illicit financial flows and disrupting criminal networks. [caption id="attachment_113806" align="aligncenter" width="600"]West African Organized Crime Groups Image Source: INTERPOL[/caption]

Major Arrests and Financial Crime Investigations

In Argentina, authorities identified 196 individuals linked to a major Crime-as-a-Service network suspected of providing website domains and money laundering support to West African organized crime groups. The investigation resulted in 17 arrests, with an INTERPOL Operational Support Team assisting with analysis of seized data and identification of suspects and criminal networks. South African authorities raided seven locations in Johannesburg linked to a syndicate involved in romance and investment scams targeting retirees in English-speaking countries. Investigators arrested 39 people, seized USD 2.67 million and blocked 257 bank accounts. In Italy, investigators identified an individual connected to a pan-European money laundering network that used shell companies, remittance services and cash withdrawals. One account processed EUR 845,000, or about USD 736,000, through 560 transactions involving 20 financial instruments. Romanian authorities dismantled a criminal group operating an investment scam through a call centre. The group promoted high returns from stocks and cryptocurrencies, with victims' money transferred to electronic wallets controlled by perpetrators. Authorities estimated that EUR 143 million had been stolen and laundered globally. Eleven people were arrested, while cash, cryptocurrency, six real estate properties and luxury watches were seized.

Sextortion and Crime-as-a-Service Emerge

Beyond individual investigations, the operation highlighted emerging threats involving sextortion and Crime-as-a-Service. INTERPOL identified an increase in West African organized crime groups using sextortion to target minors, including victims as young as 14. In these cases, offenders typically contacted minors through social media, established trust and persuaded them to share explicit images or videos. They then threatened to distribute the material to the victim's contacts unless a ransom was paid. Investigators also found that some criminal syndicates were procuring Crime-as-a-Service from external providers, including through the dark web. These services were used to outsource activities such as money laundering and other operational functions. While several cases from Operation Jackal IV remain under investigation, the preliminary results demonstrate the scale and international reach of the networks targeted during the eight-month operation. The participating countries were Austria, Argentina, Australia, Canada, Côte d'Ivoire, France, Germany, Indonesia, Ireland, Italy, Japan, Malaysia, the Netherlands, Nigeria, Portugal, South Africa, Spain, Sweden, Switzerland, the United Arab Emirates, the United Kingdom and the United States.
  • ✇Cybersecurity News
  • Balonx Sistema: Mexican PhaaS Adds AI Vishing and RAT Do Son
    Group-IB exposed Balonx Sistema, a Mexican PhaaS platform bundling real-time phishing, an Android RAT, and AI-driven vishing against 20+ banks. Related Posts: Core Werewolf Deploys New CoreRAT Malware Against Russian Targets StopAndProtect Malware Turns Hacked WordPress Sites Into a Botnet Cisco Talos Exposes UAT-10147 Agentic AI Attacks The post Balonx Sistema: Mexican PhaaS Adds AI Vishing and RAT appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Operation ASTERIX: Crypto Scam Used AI and Fake Wallets Do Son
    Rapid7 exposed Operation ASTERIX, a crypto fraud operation using AI, vishing, and fake wallet apps to steal seed phrases from validated holders. Related Posts: Cisco Talos Exposes UAT-10147 Agentic AI Attacks Operation QUICSILVER Targets Myanmar Government With Go Backdoor arrayref Rust Crate Hijacked in Supply Chain Attack With DPRK Infrastructure Overlap The post Operation ASTERIX: Crypto Scam Used AI and Fake Wallets appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Jewelbug APT Group Operations Combine Espionage and Fraud Do Son
    The Jewelbug APT group runs espionage alongside cryptocurrency scams. Read our report on Jewelbug APT group operations. Related Posts: Cisco Talos Discovers JWR Phishing Framework US Agencies Warn of AI-Generated Exploits Targeting Siemens S7 PLCs PATCHCORD Malware Hits Afghan Telecom in New APT36 Campaign The post Jewelbug APT Group Operations Combine Espionage and Fraud appeared first on Daily CyberSecurity.
     
  • ✇@BushidoToken Threat Intel
  • UK Cybercrime Journal: Carding Tactics & Youth Money Muling BushidoToken
    What HappenedRecent operational successes by UK law enforcement have exposed sophisticated domestic carding networks and the growing threat of youth-targeted money muling syndicates.In June 2026, a major cross-border investigation concluded with the sentencing of a serial fraudster who targeted small businesses, including veterinary clinics and hotels, across 22 different counties in England and Wales.The individual executed over 64 frauds and two thefts, accumulating losses totalling £462,000.
     

UK Cybercrime Journal: Carding Tactics & Youth Money Muling

19 de Agosto de 2026, 05:00

What Happened

  • Recent operational successes by UK law enforcement have exposed sophisticated domestic carding networks and the growing threat of youth-targeted money muling syndicates.
  • In June 2026, a major cross-border investigation concluded with the sentencing of a serial fraudster who targeted small businesses, including veterinary clinics and hotels, across 22 different counties in England and Wales.
  • The individual executed over 64 frauds and two thefts, accumulating losses totalling £462,000. The threat actor utilised stolen payment card details to buy goods and explicitly manipulating transaction values to inflate the amounts charged before requesting rapid refunds directly into bank accounts under his control.
  • Following his arrest, investigators seized an array of high-value items, including designer clothing and mobile devices. Financial telemetry revealed the illicit proceeds were being spent on luxury goods, gambling, hotels, and vehicle hire. Crucially, investigators uncovered an expansive network of money mule accounts specifically set up to layer and obfuscate the stolen funds.
  • Separately, regional policing teams executed a series of targeted strikes aimed directly at these types of laundering networks, resulting in the arrest of three men (aged 18, 22, and 26) on suspicion of conspiracy to defraud and for money laundering, along with the seizure of £14,000 in cash.
  • Law enforcement issued a stark warning following the raids, noting an aggressive operational shift where organised crime groups (OCGs) are actively leveraging social media platforms like Snapchat and Instagram, alongside popular online gaming ecosystems, to systematically recruit young teenagers into mule networks.

Analyst Comment

This twin set of enforcement actions illustrates the complete lifecycle of a modern domestic fraud operation. The acquisition and monetisation of stolen data (also known as Carding), followed by the immediate mobilisation of a decentralised laundering infrastructure (also known as Money Muling). The carding scheme highlighted in the 22-county campaign demonstrates that threat actors are moving away from simple e-commerce checkout abuse and are instead focusing on the operational blind spots of small, brick-and-mortar or service-oriented businesses. 

By manipulating transaction values and exploiting refund protocols, the fraudster successfully weaponised point-of-sale or card-not-present (CNP) systems to manufacture clean cash flows. However, the scale of this carding activity requires a highly liquid laundering pipeline to survive traditional banking fraud detection. This is where the recruitment of money mules becomes a vital asset for OCGs.

The pivot toward social media, such as Snapchat and Instagram as well as online gaming platforms to recruit teenage money mules is a calculated tactic by syndicates. 

Young demographics are highly susceptible to social media advertisements that mask the severe criminal realities of money laundering, framing it instead as a quick, victimless side-hustle. Many young people do not understand that allowing someone to route funds through their personal bank account is a serious criminal offense that can result in first-party fraud markers (such as a CIFAS marker), effectively destroying their financial future before it begins.

Further, a widespread lack of proactive parental supervision, combined with missing or unconfigured digital parental controls on mobile devices and gaming accounts, allows recruiters to directly message minors entirely undetected.

Defensive Takeaways

  • Harden Refund Protocols for Small Businesses: Businesses in vulnerable service sectors must enforce strict multi-factor verification for all card-not-present transactions and mandate that any processed refunds should only return to the exact card used for the initial purchase.
  • Proactive Parental Monitoring & Platform Safety: Parents must actively utilise device level and application-specific parental controls on social media and gaming networks. Conversations regarding digital safety must expand past cyberbullying to include the tactical red flags of financial grooming and "easy cash" offers.
  • Targeted School and Community Education: Educational institutions and financial bodies should collaborate more often on mandatory cyber-hygiene campaigns that explicitly outline the legal penalties of money muling, illustrating how a compromised bank account can permanently restrict access to student loans, mobile contracts, and future employment.

Relevant Sources

  1. https://www.rocu.police.uk/news/2026/june/serial-fraudsters-jailed-after-targeting-businesses-across-england-and-wales/
  2. https://www.rocu.police.uk/news/2026/june/suspected-money-mules-arrested

  • ✇Blog – Cyble
  • Brand Impersonation Takedown: From Whack-a-Mole to Managed Response Mihir Bagwe
    Manual brand impersonation takedowns fail because attackers move faster than ticket-based abuse reports can resolve — phishing pages and fake executive profiles often do their damage within hours of going live, while manual removal can take days. A managed takedown program pairs continuous, verified monitoring with pre-authorized removal (in-certain cases), cutting the exposure window from days to hours. This matters most for consulting and professional services firms, where a spoofed domain o
     

Brand Impersonation Takedown: From Whack-a-Mole to Managed Response

17 de Agosto de 2026, 11:32

Brand Impersonation Takedown, Managed Takedown

Manual brand impersonation takedowns fail because attackers move faster than ticket-based abuse reports can resolve — phishing pages and fake executive profiles often do their damage within hours of going live, while manual removal can take days. A managed takedown program pairs continuous, verified monitoring with pre-authorized removal (in-certain cases), cutting the exposure window from days to hours. This matters most for consulting and professional services firms, where a spoofed domain or fake executive profile can compromise the client trust the business is built on.

How UNC3753 targeted US professional services firms in 2026

Between January and May of 2026, Google's Mandiant threat intelligence team tracked a financially motivated extortion campaign — attributed to a group known as UNC3753, or "Luna Moth," or "Silent Ransom Group" — working its way through dozens of professional, legal, and financial services organizations across the United States. The approach was almost old-fashioned. A benign-looking email about a data migration or an unpaid invoice, a follow-up phone call from someone posing as IT support, and a request to install "remote monitoring" software to fix the problem. No exploit. No malware dropped on day one. Just a firm's own trust in its brand and its people, turned against it.

It's a useful — if unsettling — reminder of why brand and executive impersonation isn't a side issue for professional services firms. It's often the entry point.

How much does phishing and impersonation actually cost US businesses

The scale of the problem, in dollar terms, is no longer subtle. The FBI's Internet Crime Complaint Center logged just over one million complaints in 2025 — the highest volume in the program's history — with phishing and spoofing making up roughly a fifth of all reports. Losses tied to phishing alone roughly tripled year-over-year, and business email compromise, which almost always starts with an attacker impersonating someone the victim trusts, accounted for over $3 billion in reported losses on its own. The mechanics of that damage matter too: the overwhelming majority of BEC losses move through wire transfer or ACH, rails that are fast, largely irreversible, and unforgiving of a slow response.

Put those two facts together and a pattern emerges. Impersonation attacks — of a brand, a partner, an executive, a vendor invoice — aren't rare or exotic. They're the default opening move. And once the fraudulent domain, profile, or listing is live, the clock the defender is racing isn't measured in days. It's measured in hours, sometimes less, before money moves or credentials are harvested.

Why are consulting and professional services firms specifically targeted?

Professional services firms occupy a strange position in the threat landscape. They're rarely the most technically fortified target, but they're consistently one of the most valuable ones. A consulting firm doesn't just protect its own data — it holds engagement records, financial models, and confidential strategy documents belonging to dozens of clients across industries. About 29% of U.S. law firms reported having experienced a security breach at some point, according to the ABA's most recent Legal Technology Survey — up from 25% just two years earlier. The same dynamic applies to consultancies. The firm is a single point of entry into a much larger web of client relationships.

That's precisely the exposure described in Cyble's case study of a U.S. consulting organization managing highly sensitive engagement data, confidential client information, and a large, distributed workforce operating across the country. As the case study describes it, the firm's brand, executives, and digital infrastructure were frequent targets specifically because of the trust clients placed in them as an advisor. Senior partners were likely of being impersonated through fake social profiles and spoofed domains. Fraudulent job postings and phishing campaigns leaned on the firm's own credibility to look legitimate. The attacker doesn't need to breach the firm's network if a client can be convinced, through a look-alike domain or a cloned executive profile, to simply hand over what the attacker wants.

That's the mechanism UNC3753 exploited nationally in 2026, and it's the exact exposure this consulting firm was trying to close.

Also read: Ransomware Threats in the Americas H1 2026: Dissecting the Regional Attack Patterns and Dominant Actors

What is the "whack-a-mole" problem in brand protection?

Here's where most brand protection programs quietly fail, and it isn't a detection problem — it's a speed problem.

A typical manual takedown workflow looks something like this: someone on the security or marketing team spots a phishing page or a fake LinkedIn profile impersonating a partner. They file an abuse report with the registrar or the platform. They wait. Maybe they follow up. Eventually, the page comes down — but by then, a new one has often already gone live, sometimes registered by the same actor under a slightly different domain.

This was exactly the challenge the consulting firm faced before its engagement with Cyble. Identifying and removing phishing pages, fraudulent job postings, and impersonating domains was, in the case study's own words, reactive and resource-intensive, leaving the brand exposed for longer than the firm considered acceptable. It's a program that looks active — tickets filed, pages eventually removed — while the actual window of exposure, the hours where a client or job candidate could act on the fake page, stays wide open. Volume of takedowns filed is an easy number to report. Speed of resolution is the number that actually protects anyone.

What does managed takedown response actually involve

The shift the case study describes isn't just "faster takedowns" — it's a change in the operating model, from reactive point-solution to continuous, managed coverage. Three pieces work together in the deployment:

  • Brand and Executive Monitoring continuously scans for phishing domains, fraudulent job postings, and impersonation attempts using the firm's name, alongside dedicated monitoring of senior leadership profiles across social platforms — catching the fake partner LinkedIn account or spoofed domain before it's had time to circulate.
  • Verification before escalation means the security team isn't drowning in unconfirmed alerts. Threats are validated as genuine before they ever reach someone's desk, which is what separates consolidated intelligence from just another noisy dashboard.
  • Managed Takedown Services then handle the actual removal — confirmed phishing pages, impersonating domains, and fraudulent listings — without the internal team having to individually chase registrars and platforms one abuse ticket at a time.

The outcome is a meaningfully shortened window between detection and removal — turning a slow, manual, ticket-by-ticket grind into something closer to continuous coverage. That's the real distinction between a takedown service and a takedown program: one reacts when someone happens to notice a fake page; the other is built to notice, verify, and resolve on a timeline that assumes attackers move fast, because they do.

Why client trust is the real asset at risk

For a consulting firm, the financial cost of an impersonation attack is rarely the headline risk. The deeper cost is what it does to the relationship a firm's entire business is built on. When a client, a job candidate, or a prospective hire can't tell the difference between a legitimate email from the firm and a spoofed one, the firm's advisory credibility — the thing it's actually selling — starts to erode. That's a slower, quieter kind of damage than a wire fraud loss, but for a professional services firm, it may be the more expensive one.

The lesson from both the national threat data and this specific engagement is the same – brand and executive impersonation isn't a marketing nuisance to be cleaned up occasionally. It's a live attack surface, moving at a speed that manual, ad hoc takedown processes were never built to match. Firms that treat it that way — with continuous monitoring, verified alerts, and managed resolution — are the ones that keep the exposure window measured in hours instead of days.


Frequently asked questions (FAQs)

What is a brand impersonation takedown service?

A brand impersonation takedown service identifies fraudulent domains, phishing pages, fake social media profiles, and impersonating job listings that misuse a company's name or logo, then works with registrars, hosting providers, and platforms to have that content removed.

How long does it take to take down a phishing site?

Timelines vary by registrar and hosting provider, but manual, ticket-based takedown requests commonly take days to resolve. Managed takedown programs that pre-verify threats and maintain direct relationships with providers can shorten that window to hours.

Why do manual takedown processes fail against brand impersonation?

Manual processes fail because they're reactive: a person has to notice the fake page, file a report, and wait for a third party to act, while attackers can register replacement domains faster than any single report gets resolved. The volume of tickets filed can look productive even while the actual exposure window stays open.

What's the difference between takedown volume and takedown speed?

Takedown volume measures how many fraudulent pages were reported or removed over time. Takedown speed measures how quickly a live threat is detected, verified, and taken down after it appears. Speed is the metric that actually limits damage, since most harm from a phishing page happens in its first hours online.

How can consulting and professional services firms protect executives from impersonation?

Dedicated executive monitoring tracks senior leaders' names and likenesses across social platforms and the web to catch fake profiles, spoofed communications, and impersonation attempts early, ideally paired with managed takedown so confirmed threats are removed without requiring the executive or internal team to handle it themselves.


Sources:

FBI Internet Crime Complaint Center, 2025 Internet Crime Report;
Cyble, "How Cyble Delivered Unified Multi-Layered Threat Intelligence to a U.S. Consulting Organization";
Google/Mandiant, "Ongoing Targeted Campaign Against US Law Firms" (2026);
American Bar Association Legal Technology Survey.

The post Brand Impersonation Takedown: From Whack-a-Mole to Managed Response appeared first on Cyble.

  • ✇@BushidoToken Threat Intel
  • UK Cybercrime Journal: Evolution of Courier Fraud Campaigns BushidoToken
    What HappenedNew data published by the City of London Police in June 2026 reveals that courier fraud losses exceeded £21 million in 2025, with individuals aged over 70 being heavily targeted. The highest concentration of these offenses was recorded in London and the Home Counties.Cybercriminals and fraud syndicates are actively evolving their operational tactics, increasingly pivoting to messaging platforms like WhatsApp to contact their victims and remotely paying for third-party courier servic
     

UK Cybercrime Journal: Evolution of Courier Fraud Campaigns

12 de Agosto de 2026, 05:00

What Happened

  • New data published by the City of London Police in June 2026 reveals that courier fraud losses exceeded £21 million in 2025, with individuals aged over 70 being heavily targeted. The highest concentration of these offenses was recorded in London and the Home Counties.
  • Cybercriminals and fraud syndicates are actively evolving their operational tactics, increasingly pivoting to messaging platforms like WhatsApp to contact their victims and remotely paying for third-party courier services to facilitate physical collections.
  • UK law enforcement also highlighted a dangerous shift in 2025 toward high-value physical goods. Victims are being systematically manipulated into visiting multiple jewellers over an extended period to purchase gold and expensive jewellery, which they then hand directly to fraud couriers.

Recent operational crackdowns by UK Regional Organised Crime Units (ROCUs) showcase the nationwide scale of these networks:

  • North West ROCU Operations (July 2026): Police executed coordinated search warrants in Huddersfield and Manchester, arresting two men (aged 21 and 25) on suspicion of Conspiracy to Defraud and Money Laundering. In this specific series, the suspects impersonated bank fraud departments, convinced a victim her card was compromised, sent a courier to collect it, and immediately exploit the physical card to make numerous fraudulent transactions.
  • North East ROCU (NEROCU) Sentencing (June 2026): A complex, cross-country courier fraud operation spanning March to May 2022 concluded with a prison sentence for a primary operative. The network targeted 14 separate victims, convincing them to hand over physical bank cards and PIN numbers under the guise of an internal "investigation" by their bank's fraud department. The group scammed a total of £56,000, which was then rapidly laundered through the high street purchase of smartphones, designer clothing, and luxury jewellery.

Analyst Comment

Courier fraud is effectively a hybrid cyber-physical social engineering campaign. While the final phase relies on a physical courier arriving at a victim’s doorstep, the initial approach relies heavily on psychological manipulation and email, message, or phone call-based deception.

This type of fraud is notable as it follows a structured cybercriminal playbook that bypasses detection systems and takes advantage of the vulnerable in society. The victim is instructed to bypass normal banking security controls by withdrawing cash, disclosing sensitive credentials (like PINs), or purchasing high-value physical commodities like gold or luxury jewellery. This makes it difficult to proactively detect and prevent.

The other concerning factor is the couriers themselves. According to reports, they can be an unwitting third-party courier service that is paid to go to the victim's home to collect the assets. Online services enable cybercriminals to organise these pickups remotely, lowering their risk of being caught.

The £21 million sizeable loss metric from 2025 shows how profitable this low-tech, high manipulation vector remains. The recent shift to targeting gold and luxury jewellery is a deliberate evasion tactic against traditional anti-money laundering (AML) and banking fraud detection algorithms. While banks have grown adept at flagging unusual rapid bank transfers, they cannot easily stop an account holder from physically withdrawing funds or using a card over several days at different brick-and-mortar luxury retailers. This tactic serves as a highly liquid physical laundering pipeline for these syndicates that remains a challenge to prevent.

Defensive Takeaways

  • Implement Bank Transfer and Purchase Outlier Alerts: Financial institutions can focus on further behavioural monitoring for elderly demographics, looking specifically for sudden, consecutive high-value transactions at physical luxury retail or jewellery establishments and flag patterns on unusual activity for review.
  • Public Awareness on Cross-Media Scams: Security awareness campaigns must make it clear that legitimate institutions, specifically the Police and Banking Fraud teams, will never send a courier to a residential address to collect cash, PIN numbers, bank cards, or purchased items.
  • Vetting of Courier Logistics: Commercial courier services are increasingly being abused as infrastructure by these threat groups. Logistics firms must implement logging and analysis systems to detect unusual residential pickups booked via suspicious accounts and forged identities.

Relevant Sources

  1. https://www.cityoflondon.police.uk/news/city-of-london/news/2026/june/over-70s-targeted-as-courier-fraud-exceeds-21-million-in-2025-with-london-and-home-counties-hit-hardest/
  2. https://www.rocu.police.uk/news/2026/july/two-suspected-fraudsters-arrested-after-cross-border-strikes/
  3. https://www.rocu.police.uk/news/2026/june/a-courier-fraud-conman-has-been-jailed/

  • ✇ASEC BLOG
  • July 2026 Dark Web Issue Trend Report ATCP
    Note The July 2026 Dark Web Issue Trend Report summarizes major issues that occurred on the deep web and dark web. Due to the nature of some sources, it may be difficult to fully verify the accuracy of certain information; therefore, it is necessary to cross-check these details against official announcements. Major Issues RaidForums changed […]
     

July 2026 Dark Web Issue Trend Report

Por:ATCP
10 de Agosto de 2026, 12:00
Note The July 2026 Dark Web Issue Trend Report summarizes major issues that occurred on the deep web and dark web. Due to the nature of some sources, it may be difficult to fully verify the accuracy of certain information; therefore, it is necessary to cross-check these details against official announcements. Major Issues RaidForums changed […]
  • ✇@BushidoToken Threat Intel
  • UK Cybercrime Journal: H1 2026 Social Media Fraud Trends BushidoToken
    What HappenedHMRC Issues Warning to TikTok UsersOn 4 June 2026, HM Revenue and Customs (HMRC) uncovered a suspected £153 million tax fraud scam involving TikTok.The scheme allegedly involved individuals posting advertisements on the TikTok, enticing users to hand over sensitive tax information, including business VAT registration details or personal self-assessment credentials for a financial reward.Using the stolen tax details, the fraudsters could file bogus repayment requests with HMRC.The wa
     

UK Cybercrime Journal: H1 2026 Social Media Fraud Trends

29 de Julho de 2026, 05:00

What Happened

HMRC Issues Warning to TikTok Users

  • On 4 June 2026, HM Revenue and Customs (HMRC) uncovered a suspected £153 million tax fraud scam involving TikTok.
  • The scheme allegedly involved individuals posting advertisements on the TikTok, enticing users to hand over sensitive tax information, including business VAT registration details or personal self-assessment credentials for a financial reward.
  • Using the stolen tax details, the fraudsters could file bogus repayment requests with HMRC.
  • The warning comes after two Romanian men, aged 22 and 25, were apprehended by HMRC officers in east London on 23 April 2026 in connection with the alleged fraud.

Lloyds Bank found Two Thirds of Fraud Cases Started on Meta 

  • On 6 June 2026, Liz Ziegler, the Lloyds fraud prevention director disclosed that 68% of fraud reports from their customers started on a Meta platform, including Facebook, Instagram, and WhatsApp.
  • The average claim value submitted to Lloyds Bank is now above £500, an increase of about £100 from last year. Plus, victims were sending up to £66 million a year to fraudsters after falling victim to a scam advert via Meta, up from £27 million in 2023.
  • The most common scams involve fake tickets for concerts, festivals and sporting events. Meta’s Facebook Marketplace is also plagued by fake adverts for cars, bikes, campervans and mobility vehicles.
  • Other categories of fraud on Meta platforms, collected by Lloyds between March 2025 and 2026, include: wedding photobooths, tattoo deposits, vapes, wigs, Moncler jackets, football shirts, Dyson products and Amazon Alexas. Fraudulent transactions for deposits for flats, mobile phones, household furniture and gym equipment have also been observed.

UK Finance Recorded £221.5m Lost to Investment Scams

  • In June 2026, UK Finance's Annual Fraud Report recorded the highest loss total ever recorded and the highest total number of cases ever reported at 14,893, which was 26% higher than 2025.
  • Up to £221.5m was lost to scams in which victims were persuaded to transfer funds to a fake investment or fictitious fund. This figure also marked a 40% rise more than 2025.
  • The primary observed tactics involved in investment scams include traditional cold calling to pressurise victims into acting quickly to claim an opportunity before it expires, as well as adverts on social media offering unrealistic rates of returns on investments, and hand-delivered letters.
  • The types of investments fraudsters used as bait in 2026 involved gold, property, carbon credits, cryptocurrencies, land banks, and wine.

Fraudsters arrested in Nigeria following NCA intelligence sharing

  • In February 2026, the National Crime Agency (NCA) announced that seven men were arrested in Nigeria after intelligence identified an online investment scam compound targeting UK victims. These arrests were the result of co-operation between the National Crime Agency, Meta and the Nigerian Police.
  • Using hundreds of fake Facebook accounts accounts to impersonate cryptocurrency traders, the Nigeria-based scammers targeted people who used legitimate investment platforms.
  • The scam compound was also allegedly recruiting and training young people in targeting victims for future investment frauds and phishing attacks. A total of 26 phones, 42 sim cards and a laptop were seized on 13 January.

Analyst Comment 

H1 2026 reinforces the transition from email-centric fraud campaigns to social-media-powered fraud operations, with platforms increasingly serving as the primary source of victims for organised cybercriminal groups. Fraudsters are also adapting scams to the culture and user behaviour of individual platforms, such as generate short promotional videos on TikTok or listing fake items for sale on Facebook Marketplace. Rather than deploying identical scams everywhere, criminals tailor campaigns to the platform's intended purpose. Recommendation algorithms and advertising ecosystems provide fraudsters with scalable victim acquisition channels that were previously unavailable through traditional phishing campaigns.

Advances in artificial intelligence (AI) and large language models (LLMs) has also meant it is much easier for cybercriminals to carry out scams on a much larger scale than they were previously able to. Autonomous systems can enable them to send out messages at scale and contact users by telephone at scale. Plus the scam attempts are also more convincing as they can mimic voices and appearance of celebrities or even a target’s friends and family.

The scale of fraudulent activities across social media is so large, it requires vast resources and expertise to monitor, detect, and prevent. At the same time, the response from HMRC, banks, social media companies, the NCA, and international law enforcement suggests increasing recognition that combating social media fraud requires coordinated action.

The volume of fake accounts on social media used for scams does also validate the calls for increased verification and security checks on such platforms. The UK Government's proposal to introduce a national digital ID system, however, was met with fierce opposition. Up to 2.9 million people signed a UK parliament petition to show their disagreement with such a system.

Defensive Takeaways 

  • Reduce Public Exposure: Fraudsters increasingly use information shared on social media to personalise scams and identify potential victims. Consider making profiles private or limiting visibility to trusted contacts and if you no longer actively use a social media platform, consider deleting the account entirely.
  • Be on Guard for Scams: Sponsored advertisements should not automatically be considered legitimate. Refuse any financial rewards in exchange for your login credentials. Be cautious of investment opportunities promoted solely through social media. Assume Facebook Marketplace listings can be fraudulent.
  • Report Suspicious Activity: Reporting scams helps remove fraudulent content and supports law enforcement investigations. Useful UK reporting channels include Report Fraud and the UK NCSC's Suspicious Email Reporting Service report@phishing.gov.uk.
  • Seek Support after a Scam: Victims should not assume financial losses are unrecoverable. It can be possible to get funds returned if they contact their bank immediately, preserve screenshots and transactions records, and report the incident to Report Fraud. Further, if a victim is dissatisfied with how their bank handled their case, they can complain to the Financial Ombudsman Service.

Relevant Sources 

  1. https://www.independent.co.uk/news/uk/crime/tiktok-hmrc-tax-fraud-scam-b2989914.html
  2. https://www.thetimes.com/article/840020a8-1210-47c9-9262-e3139116b652?shareToken=771d08288cd2ac9d0ba13194f43d75a0
  3. https://www.theguardian.com/money/2026/jun/15/investment-fraud-uk-more-than-220m-lost-last-year-scams-ai
  4. https://www.ukfinance.org.uk/system/files/2026-06/UK%20Finance%20Fraud%20Report%202026.pdf
  5. https://www.nationalcrimeagency.gov.uk/news/fraudsters-arrested-in-nigeria-following-nca-intelligence-sharing 

  • ✇Malwarebytes
  • What’s your data worth on the dark web? (Lock and Code S07E15)
    This week on the Lock and Code podcast… Twenty years ago, a British mathematician named Clive Humby popularized a phrase that came to describe data’s relationship with the entire global economy: “Data is the new oil.” Pithy as the phrase sounds, it is undeniably true. Data steers decisions at businesses of every size. Data created entirely new industries built around its capture. And, for a select number of companies, data has produced billions—if not trillions—of dollars in value.
     

What’s your data worth on the dark web? (Lock and Code S07E15)

27 de Julho de 2026, 11:35

This week on the Lock and Code podcast…

Twenty years ago, a British mathematician named Clive Humby popularized a phrase that came to describe data’s relationship with the entire global economy: “Data is the new oil.”

Pithy as the phrase sounds, it is undeniably true.

Data steers decisions at businesses of every size. Data created entirely new industries built around its capture. And, for a select number of companies, data has produced billions—if not trillions—of dollars in value.

So how is it that, on the dark web, your stolen identity can be purchased for just 95 cents?

That’s what a Malwarebytes researcher found last month after spending 48 hours inside the dark web to investigate cybercrime. Across a variety of forums and directories, he found subscription plans for malware that steals information once implanted on a device. He found guides for deploying social engineering scams. He found people selling their services to build fake websites that trick people into handing over their usernames and passwords. And he found one of the dark web’s most traded commodities—personal data, packaged together about individual people, to help a cybercriminal commit identity fraud.

These packages are called “fullz.” For victims in the United States, a fullz contains a full name, Social Security Number, date of birth, address, and other personal details. That is enough, on its own, for a cybercriminal to potentially open a bogus line of credit, file a fake tax return, access financial accounts, or obtain medical services under someone else’s name.

As we wrote on Malwarebytes Labs:

“For less than the cost of a cup of coffee, a cybercriminal can buy enough information to devastate someone’s financial life.”

It’s the kind of risk that could scare anyone, especially considering the scale behind it. In just the first six months of 2026, Malwarebytes found more than 7,500 compromised data sets on the dark web containing more than 8.4 billion records.

And yet, even today, cybersecurity professionals still get asked why anyone should bother protecting their data.

The public, understandably, are exhausted. With data breaches happening every week—if not every day—cybersecurity can start to feel pointless. With young people unable to build financial security, they start believing that they have nothing worth stealing. And with Big Tech already collecting our every movement, behavior, click, and concern, people understandably feel powerless to fight any kind of data abuse, be it corporate or criminal.

So today’s episode approaches the question from a different direction. This isn’t about why you should protect yourself—plenty of company websites will tell you that, and most of them rely on fear. This is about why hackers want your data in the first place.

Today, on the Lock and Code podcast, host David Ruiz explains how cybercriminals turn a single repeated password into account takeover, how a screenshot of your house from Google Maps became a tool in extortion emails, and why the most benign information about you—an address, an age, one public photo—is often the most useful data a stranger can buy.

Tune in today to listen to the full episode.

Show notes and credits:

Intro Music: “Spellbound” by Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 4.0 License
http://creativecommons.org/licenses/by/4.0/
Outro Music: “Good God” by Wowa (unminus.com)


Listen up—Malwarebytes doesn’t just talk cybersecurity, we provide it.

Protect yourself from online attacks that threaten your identity, your files, your system, and your financial well-being with our exclusive offer for Malwarebytes Premium for Lock and Code listeners.

  • ✇Firewall Daily – The Cyber Express
  • Four Men Admit to $2.2M Medicaid Fraud Scheme Using ChatGPT Samiksha Jain
    Four Minnesota men have pleaded guilty to a Minnesota Medicaid fraud scheme that allegedly stole approximately $2.2 million from the state’s Housing Stabilization Services (HSS) program and used artificial intelligence to fabricate records when insurance companies requested documentation. The defendants admitted to submitting thousands of claims for services they never provided or significantly inflating claims to obtain higher reimbursements. The case involves four Twin Cities-area men who o
     

Four Men Admit to $2.2M Medicaid Fraud Scheme Using ChatGPT

Minnesota Medicaid fraud

Four Minnesota men have pleaded guilty to a Minnesota Medicaid fraud scheme that allegedly stole approximately $2.2 million from the state’s Housing Stabilization Services (HSS) program and used artificial intelligence to fabricate records when insurance companies requested documentation. The defendants admitted to submitting thousands of claims for services they never provided or significantly inflating claims to obtain higher reimbursements. The case involves four Twin Cities-area men who operated Brilliant Minds Services LLC from the Griggs-Midway Building in St. Paul, Minnesota. According to court documents, the business enrolled as a Medicaid program provider and claimed to help people with disabilities, including seniors and individuals with mental illnesses and substance use disorders, find and maintain housing through the now-defunct HSS program.

Minnesota Medicaid Fraud Scheme Targeted 350 Recipients

According to prosecutors, Moktar Hassan Aden, 31, Mustafa Dayib Ali, 29, Khalid Ahmed Dayib, 26, and Abdifitah Mohamud Mohamed, 27, signed up approximately 350 people for HSS. The defendants then billed Medicaid for services they allegedly did not provide to those recipients. The scheme reportedly operated from April 2022 through April 2025. During that period, the four men allegedly submitted thousands of HSS claims and fraudulently obtained approximately $2.2 million from Minnesota Medicaid. The case highlights the alleged misuse of a government program designed to provide housing-related support to vulnerable people. Authorities said the defendants exploited the program by claiming reimbursements for services that were never delivered or by submitting inflated claims.

Artificial Intelligence Used to Fabricate Records

The case also highlights the use of artificial intelligence in an alleged effort to conceal healthcare fraud. When insurance companies requested supporting documentation for the claims, the defendants used ChatGPT to fabricate records, according to court documents. The use of ChatGPT to create fake documentation adds another dimension to the health care fraud case, as authorities continue to investigate alleged schemes involving government-funded programs. The defendants allegedly used the fabricated records to conceal the fraudulent claims and support services they had claimed to provide. Assistant Attorney General Colin M. McDonald of the Justice Department’s National Fraud Enforcement Division said the defendants exploited vulnerable people and a vulnerable program for financial gain. U.S. Attorney for the District of Minnesota Daniel N. Rosen said Medicaid fraud carries serious consequences and that the funds involved were intended to support vulnerable Minnesotans relying on housing and recovery services.

Four Defendants Plead Guilty to Wire Fraud

In separate hearings held between July 7 and July 23, 2026, all four defendants pleaded guilty to one count of wire fraud. Each faces a maximum penalty of 20 years in prison. A federal district court judge will determine any sentence after considering the U.S. Sentencing Guidelines and other statutory factors. Sentencing dates have not yet been set. The FBI, the U.S. Internal Revenue Service, Criminal Investigation, and the U.S. Department of Health and Human Services, Office of Inspector General, are investigating the case. Trial Attorney Raymond E. Beckering III of the Criminal Division’s Fraud Section and Assistant U.S. Attorney Matthew Murphy for the District of Minnesota are prosecuting the case.

Health Care Fraud Strike Force Continues Investigations

The case is part of the ongoing collaboration between the U.S. Attorney’s Office for the District of Minnesota and the Health Care Fraud Strike Force to combat fraud targeting government programs. The Department of Justice’s Health Care Fraud Strike Force Program currently includes nine strike forces operating across federal districts. Since 2007, the program has charged more than 6,200 defendants who collectively billed federal health care programs and private insurers more than $45 billion. The case also comes as the Justice Department’s National Fraud Enforcement Division focuses on investigating and prosecuting fraud against the American people. Authorities said efforts to combat fraud remain part of broader work targeting fraud, waste, and abuse within federal benefit programs.

Fake FBI Agents Use IC3 Complaint Scams to Target Fraud Victims

Fake FBI agents are using deepfake videos, spoofed IC3 websites and false recovery claims to steal money and personal information from people who were scammed before, the FBI warns.
  • ✇Firewall Daily – The Cyber Express
  • Dubai Police Warns Against Online Scams Promising Work and Visit Visas Samiksha Jain
    The Dubai Police fraudulent visa ads warning has cautioned the public against scams offering work visas, residency visas, and visit visas in exchange for money. According to the Anti Fraud Centre at Dubai Police's General Department of Criminal Investigation, fraudsters are using social media platforms and messaging apps to circulate fake visa offers by impersonating official entities or using the names of unlicensed companies. The advisory was issued as part of Dubai Police's Be Aware of Fra
     

Dubai Police Warns Against Online Scams Promising Work and Visit Visas

Dubai Police fraudulent visa ads

The Dubai Police fraudulent visa ads warning has cautioned the public against scams offering work visas, residency visas, and visit visas in exchange for money. According to the Anti Fraud Centre at Dubai Police's General Department of Criminal Investigation, fraudsters are using social media platforms and messaging apps to circulate fake visa offers by impersonating official entities or using the names of unlicensed companies. The advisory was issued as part of Dubai Police's Be Aware of Fraud campaign, which aims to raise awareness about online scams and help residents identify fraudulent schemes.

Dubai Police Fraudulent Visa Ads Circulating on Social Media

According to Dubai Police, scammers are promoting visa services through advertisements and messages that claim to offer work, residency, or visit visas for a fee. The Anti Fraud Centre said these advertisements are designed to convince victims to transfer money by falsely claiming to represent government authorities or licensed visa service providers. Some also use the names of unlicensed companies or offices to appear legitimate. Dubai Police urged the public not to rely on such offers and reminded residents that all visa procedures should be completed only through competent authorities or legally approved offices.

Authorities Urge Public to Verify Visa Offers

The Anti Fraud Centre said verifying the source of a visa service is the first step in avoiding visa fraud. Residents have been advised to confirm the authenticity of any visa offer or application process through official channels before making payments or sharing personal information. The centre also warned against dealing with intermediaries or unknown individuals claiming they can arrange visas through unofficial means. Dubai Police said people should not be misled by promises of guaranteed visas or job opportunities that are offered outside the legal process.

How to Report Fraud Attempts

Dubai Police has asked members of the public to report any fraud or attempted fraud immediately. Reports can be submitted through the Dubai Police Smart App, the eCrime platform for cybercrime reports, or by calling 901. The Anti Fraud Centre reiterated that staying informed and verifying service providers through official channels remain the most effective ways to avoid falling victim to fraudulent visa schemes.

New FCC Proposal Pits Phone Privacy Against Fraud Prevention

17 de Julho de 2026, 11:39

The FCC has proposed requiring identity verification for phone activation, a move supporters say will fight fraud while critics warn it threatens privacy.

The post New FCC Proposal Pits Phone Privacy Against Fraud Prevention appeared first on TechRepublic.

  • ✇Firewall Daily – The Cyber Express
  • Dutch Police Arrest Key Suspect in €100M Global Crypto Investment Scam Samiksha Jain
    A major global crypto investment scam investigation has led to the arrest of an alleged key figure behind an international criminal organization accused of defrauding victims of more than €100 million every month. Dutch police announced multiple arrests across Europe following a long-running investigation into a fraud network that allegedly employed over 700 people operating from around 20 call centers worldwide. The main suspect, a 46-year-old dual Israeli and Polish national,
     

Dutch Police Arrest Key Suspect in €100M Global Crypto Investment Scam

global crypto investment scam

A major global crypto investment scam investigation has led to the arrest of an alleged key figure behind an international criminal organization accused of defrauding victims of more than €100 million every month. Dutch police announced multiple arrests across Europe following a long-running investigation into a fraud network that allegedly employed over 700 people operating from around 20 call centers worldwide.

The main suspect, a 46-year-old dual Israeli and Polish national, was arrested at an airport in Poland on May 26 at the request of Dutch authorities. Investigators believe he played an indispensable role in the organization, which allegedly carried out large-scale investment fraud targeting victims across multiple countries.

Global Crypto Investment Scam Network Operated Through Worldwide Call Centers

According to Dutch police, the organization functioned like a professional company with approximately 700 employees spread across nearly 20 offices globally. Individuals working as financial advisors scam operators allegedly contacted victims daily through online platforms and telephone calls while posing as legitimate investment professionals.

Authorities said the organization was structured with a central headquarters overseeing multiple teams, each assigned to target victims in specific countries. Employees reportedly worked under pseudonyms and used technical measures to hide their identities and locations.

[caption id="attachment_113134" align="aligncenter" width="600"]global crypto investment scam Excerpts from emails that victims sent to scammers[/caption]

As part of the investigation, Belgian police arrested five individuals believed to have worked as fraudulent financial advisors.

Multiple Arrests Made Across Europe

The investigation resulted in several coordinated arrests during May and July.

On July 7, authorities arrested two Dutch nationals aged 45 and 34, along with a 34-year-old Belgian, all residing in Cyprus. A 25-year-old suspect was also arrested in Belgium the same day. On July 10, police arrested a 44-year-old Dutch national in Athens.

The main suspect has since been extradited to the Netherlands, where an examining magistrate ordered 14 days of pre-trial detention. Dutch authorities indicated that additional arrests remain possible as the investigation continues.

How the Global Crypto Investment Scam Worked

Investigators said the online investment scam relied on building long-term trust with victims. Individuals posing as account managers or financial advisors maintained frequent contact through phone calls and online communication, sometimes over several months.

Victims were encouraged to begin with relatively small investments that appeared to generate immediate returns. Police said the investment platforms displayed convincing but fabricated profits, even though no actual investments were being made.

As confidence grew, victims were persuaded to transfer increasingly larger amounts, often in the form of cryptocurrency fraud payments. Instead of being invested, investigators said the funds were diverted directly to the criminal organization.

Authorities also warned that victims who stop investing may later be contacted by so-called recovery companies requesting upfront deposits to recover lost funds. Police believe these recovery operations may also be connected to the same fraud networks.

Hundreds of Complaints Linked to Investment Fraud

Dutch authorities have received approximately 550 reports connected to the organization, while Belgian police have recorded around 200 complaints. Investigators estimate the total number of victims worldwide could reach tens of thousands.

The financial losses reported by victims in the Netherlands alone amount to nearly €25 million, with many individuals losing well over €10,000.

Dutch police said officers proactively contacted some victims after discovering that many remained unaware they had fallen victim to cyber fraud.

Financial investigators are now examining whether assets linked to the suspects can be frozen or seized.

Digital Infrastructure Taken Offline

Investigators said the criminal organization remained active since at least 2021 and relied heavily on concealed digital infrastructure to evade law enforcement.

By tracing financial transactions, IP addresses, and other digital evidence, the Dutch police identified offices, suspects, and critical infrastructure supporting the operation. Authorities worked with commercial service providers to take key elements of the network offline.

The investigation also involved Europol, with intelligence shared across multiple countries to support ongoing criminal prosecutions.

Officials said the case demonstrates the scale and sophistication of modern investment fraud operations and highlighted continued international cooperation to dismantle cyber-enabled financial crime networks.

  • ✇The Cloudflare Blog
  • Announcing Cloudflare Account Abuse Protection: prevent fraudulent attacks from bots and humans Jin-Hee Lee
    Today, Cloudflare is introducing a new suite of fraud prevention capabilities designed to stop account abuse before it starts. We've spent years empowering Cloudflare customers to protect their applications from automated attacks, but the threat landscape has evolved. The industrialization of hybrid automated-and-human abuse presents a complex security challenge to website owners. Consider, for instance, a single account that’s accessed from New York, London, and San Francisco in the same five m
     

Announcing Cloudflare Account Abuse Protection: prevent fraudulent attacks from bots and humans

12 de Março de 2026, 02:00

Today, Cloudflare is introducing a new suite of fraud prevention capabilities designed to stop account abuse before it starts. We've spent years empowering Cloudflare customers to protect their applications from automated attacks, but the threat landscape has evolved. The industrialization of hybrid automated-and-human abuse presents a complex security challenge to website owners. Consider, for instance, a single account that’s accessed from New York, London, and San Francisco in the same five minutes. The core question in this case is not “Is this automated?” but rather “Is this authentic?” 

Website owners need the tools to stop abuse on their website, no matter who it’s coming from.

During our Birthday Week in 2024, we gifted leaked credentials detection to all customers, including everyone on a Free plan. Since then, we've added account takeover detection IDs as part of our bot management solution to help identify bots attacking your login pages. 

Now, we’re combining these powerful tools with new ones. Disposable email check and email risk help you enforce security preferences for users who sign up with throwaway email addresses, a common tactic for fake account creation and promotion abuse, or whose emails are deemed risky based on email patterns and infrastructure. We’re also thrilled to introduce Hashed User IDs — per-domain identifiers generated by cryptographically hashing usernames — that give customers better insight into suspicious account activity and greater ability to mitigate potentially fraudulent traffic, without compromising end user privacy.

The new capabilities we’re announcing today go beyond automation, identifying abusive behavior and risky identities among human users and bots. Account Abuse Protection is available in Early Access, and any Bot Management Enterprise customer can use these features at no additional cost for a limited period, until the general availability of Cloudflare Fraud Prevention later this year. If you want to learn more about this Early Access capability, sign up here.

Leaked credentials make logins all too vulnerable

The barrier to entry for fraudulent behavior is dangerously low, especially with the availability of massive datasets and access to automated tools that commit account fraud at scale. Website owners aren’t just dealing with individual hackers, but industrialized fraud. Last year, we highlighted how 41% of logins across our network use leaked credentials. This number has only grown following the exposure of a database holding 16 billion records, and multiple high-profile breaches have since come to light. 

What’s more, users reuse passwords across multiple platforms, meaning a single leak from years ago can still unlock a high-value retail or even a bank account today. Our leaked credential check is a free feature that checks whether a password has been leaked in a known data breach of another service or application on the Internet. This is a privacy-preserving credential checking service that helps protect our users from compromised credentials, meaning Cloudflare performs these checks without accessing or storing plaintext end user passwords. Passwords are hashed — i.e., converted into a random string of characters using a cryptographic algorithm — for the purpose of comparing them against a database of leaked credentials. If you haven’t already turned on our leaked credential check, enable it now to keep your accounts safe from easy hacks!

Access to a large database of leaked credentials is only useful if an attacker can cycle through them quickly across many sites to identify which accounts are still vulnerable due to password reuse. In our Black Friday analysis in 2024, we observed that more than 60% of traffic to login pages across our network was automated. That’s a lot of bots trying to break in.

To help customers protect their login endpoints from constant bombardment, we added account takeover (ATO)-specific detections to highlight suspicious traffic patterns. This is part of our recent focus on per-customer detections, in which we provide behavioral anomaly detection unique to each bot management customer. Today, bot management customers can see and mitigate attempted ATO attacks in their login requests directly on the Security analytics dashboard.

In the card on the left within the Security analytics dashboard, you can view and address attempted account takeover attacks.

In the last week, our ATO detections combined caught an average of 6.9 billion suspicious login attempts daily, across our network. These ATO detections, along with the many other detection mechanisms in our bot management solution, create a layered defense against ATO and other malicious automated attacks.

From automation to intent and identity

To discern automation, or to discern intent and identity? That is the question. Our answer: yes and yes, as both are critical layers of a robust security posture. Attackers now operate at a scale previously reserved for enterprise services: they leverage massive credential leaks, use human-powered fraud farms to spoof devices and locations, and create synthetic identities to maintain thousands — even millions — of fake accounts for promotion and platform abuse. A human being with automated tools could be draining accounts, abusing promotions, committing payment fraud, or all of the above.

Beyond that, automation is accessible like never before, particularly as users become better acquainted with using AI agents and even long-standing, “traditional” browsers move toward having agentic capabilities by default. Whether it’s a lone actor using an AI agent or a coordinated fraud campaign, the threat isn’t as simple as a single script — it can involve human intent, with automated execution.

Consider the following scenarios we’ve heard from our customers:

  • We have 1,000 new users this month, but more than half of them are fake identities who benefit from a free trial, then disappear.
  • The attacker logged in with the correct password, so how do I know that it isn’t the real user?
  • This entity is acting at human pace, and they are draining accounts.

These problems can't be solved by only assessing automation; they require checking for authenticity and integrity. This is the gap that our dedicated fraud prevention capabilities address.

Assessing suspicious emails

Let’s start by assessing the earliest point of potential account abuse: account creation. Fake or bulk account creation is one of the biggest topics in conversations about website fraud, as it can open the door for attackers to access an application — or even an entire business model. 

Cloudflare is giving customers the tools to assess suspicious account creation at the source in two ways:

  1. Disposable email check: Detect when users sign up with disposable, or throwaway, email addresses commonly used for promotion abuse and fake account creation. These disposable email services allow attackers to spin up thousands of "unique" accounts without maintaining real infrastructure, particularly unauthenticated disposable emails that provide instant access without account creation or free unlimited email aliases. Customers can use this binary field as they build rules to enforce security preferences, choosing to block all disposable emails outright, or perhaps issuing a challenge to anyone attempting to create an account with a disposable email.
  1. Email risk: Cloudflare analyzes email patterns and infrastructure to provide risk tiers (low, medium, high) that customers can use in security rules. We know that not all email addresses are created equal; an address with the format firstname.lastname@knowndomain.com carries different risk characteristics than xk7q9m2p@newdomain.xyz. Email risk tiers allow customers to express their tolerance for risk and friction at the point of account creation. 

Both disposable email check and email risk are now available in security analytics and security rules, equipping website owners to protect their account creation flow. These detections address a fundamental problem: by the time an account is committing abuse, it's already too late. The website owner has already paid acquisition costs, the fraudulent user has consumed promotional credits, and remediation requires manual review. Mitigating suspicious emails means adding the appropriate friction at signup — the moment it matters most.

Introducing Hashed User IDs

Understanding patterns of abuse requires visibility: not only into the network, but of account activity. Traditionally, security has meant looking through the lens of IPs and isolated HTTP requests to spot automated activity, but website owners aren’t just thinking in terms of network signals; they are also considering their users and known accounts. That’s why we’re expanding our mitigation toolbox to match the way applications are actually structured, focusing on user-based detection of fraudulent activity.

Attackers can effortlessly rotate IPs to hide their tracks. But forcing them to repeatedly generate new, credible accounts introduces massive friction, especially when combined with account creation protections. When we look past the network layer and map fraudulent actions to a given compromised or abusive account, we can spot targeted behavior tied to a single, persistent actor and put a stop to the abuse. In this way, we’re shifting the defense strategy to the account level, instead of playing whack-a-mole with rotating IP addresses and residential proxies. This means that our customers can mitigate abusive behavior based on the way their applications separate identity.

To arm website owners with this capability, Cloudflare is releasing a Hashed User ID that customers can use in Security analytics, Security rules, and Managed Transforms. User IDs are per-domain, cryptographically hashed versions of the values in the username field, and each user ID is an encrypted, unique, and stable identifier generated for a given username on a customer application. Importantly, the actual username is not logged or stored by Cloudflare as part of this service. As with leaked credentials check and ATO detections, which identify login traffic and then encrypt credentials for comparison, we are prioritizing end user privacy while empowering our customers to take action against fraudulent behavior.

With access to Hashed User IDs, website owners can:

  • See top users: Which accounts have the most activity?
  • See when a unique user logs in from a country they usually don’t — or multiple countries in one day!
  • Mitigate traffic based on unique user, such as blocking a user with historically suspicious activity.
  • Combine fields to see when accounts are being targeted with leaked credentials.
  • See what network patterns or signals are associated with unique users.

The expanded view of a single Hashed User ID within the Security analytics dashboard, showing the activity details of that unique user, including their login location and their browser. 

This user-level visibility transforms how website owners can investigate and mitigate traffic. Instead of examining individual requests in isolation, our customers can see the full picture of how attackers are targeting and hiding among legitimate users.

Take the next step in account protection today

If you want to learn more about this Early Access capability, sign up here. All Bot Management Enterprise customers are eligible to add these new Account Abuse Protection features today, and we’d love to open the conversation with any and all prospective Bot Management customers.

While bot detections will continue to answer the question of automation and intent, fraud detections delve into the question of authenticity. Together, they give website owners comprehensive tools to fight against the full spectrum of account abuse. This suite is one step in our ongoing investment to protect the entire user journey — from account creation and login to secure checkouts and the integrity of every interaction.

Fake Céline Dion Paris Tickets Sold on Facebook and Ticketmaster Clones

Group-IB says scammers are targeting Céline Dion fans through Facebook, duplicate digital tickets and fake websites impersonating Ticketmaster, AXS and the venue site.
❌
❌