Accused PII seller faces jail for running underground fraud op

January 23, 2024 at 11:10AM Baltimore man accused of running online service selling personal data for fraud faces up to 20 years in prison. Chouby Charleron allegedly operated a TLO service, providing victims’ personally identifiable information for a fee. The U.S. Postal Service filed charges based on evidence linking Charleron to the operation from his … Read more

Payoneer accounts in Argentina hacked in 2FA bypass attacks

January 19, 2024 at 03:28PM Many Payoneer users in Argentina woke up to find their 2FA-protected accounts hacked, with funds stolen after receiving SMS OTP codes while sleeping. Suspected hacking methods include a potential Movistar data leak or a breached SMS provider. Payoneer has not provided specific answers but acknowledged the fraud and advised users … Read more

DoJ Charges 19 Worldwide in $68 Million xDedic Dark Web Marketplace Fraud

January 8, 2024 at 01:46AM The U.S. Department of Justice charged 19 individuals globally in connection with the xDedic Marketplace, accused of facilitating over $68 million in fraud. The transnational operation involved law enforcement cooperation from several countries. The marketplace allowed cybercriminals to buy or sell stolen credentials to over 700,000 hacked computers and servers, … Read more

Nigerian hacker arrested for stealing $7.5M from charities

January 3, 2024 at 02:35PM Nigerian national Olusegun Samson Adejorin was arrested in Ghana for wire fraud and identity theft, related to $7.5 million embezzlement from US charitable organizations. The fraud scheme involved unauthorized access to email accounts and impersonation of employees to trick one charity into transferring funds to accounts controlled by the attacker. … Read more

SMS Phishing Messages Target UAE Citizens, Visitors

December 21, 2023 at 10:24AM A malicious SMS campaign targeting citizens and visitors to the United Arab Emirates is run by the Smishing Triad Gang, impersonating official authorities to collect personal and credit card details. The campaign uses URL-shortening tools to disguise links and is believed to have access to private channels for obtaining information. … Read more

Malicious Apps Disguised as Banks and Government Agencies Targeting Indian Android Users

November 21, 2023 at 03:18AM A new malware campaign in India targets Android smartphone users through social engineering. Attackers send messages on platforms like WhatsApp and Telegram, impersonating banks and government services. They entice users to install a fraudulent app that steals sensitive data and banking details. The app also intercepts one-time passwords (OTPs) and … Read more

Israeli Man Who Made $5M From Hacking Scheme Sentenced to Prison in US

November 17, 2023 at 08:09AM Israeli private investigator Aviram Azari has been sentenced to 80 months in prison in the US for hacking companies and individuals, earning him nearly $5 million. Azari owned an Israeli intelligence firm, Aviram Hawk or Aviram Netz, and hired hacking groups to access online accounts and steal information. Targets included … Read more

FTX crypto-villain Sam Bankman-Fried convicted on all charges

November 2, 2023 at 09:17PM Sam Bankman-Fried, founder and former CEO of FTX and Alameda Research, has been found guilty of seven criminal charges related to fraud and money laundering. FTX, once valued at $32 billion, filed for bankruptcy in 2022 after funds were shifted to Alameda, resulting in losses for FTX investors. Bankman-Fried faces … Read more

34 Cybercriminals Arrested in Spain for Multi-Million Dollar Online Scams

October 24, 2023 at 08:09AM Spanish law enforcement has arrested 34 members of a criminal group that conducted online scams, resulting in €3 million ($3.2 million) in illegal profits. The arrests were made in multiple locations, and authorities seized weapons, cash, vehicles, and electronic material. The group infiltrated financial and credit institution databases and conducted … Read more

‘Log in with…’ Feature Allows Full Online Account Takeover for Millions

October 24, 2023 at 08:05AM Flaws in the OAuth standard implementation across Grammarly, Vidio, and Bukalapak may have allowed attackers to take over user accounts and engage in fraudulent activities. The Salt Labs researchers discovered API misconfigurations, which could potentially affect other compromised sites. This issue, referred to as a “Pass-The-Token” flaw, allows attackers to … Read more