Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams or tried to obtain access to bank accounts. [...]

Ukrainian authorities have dismantled 94 fraudulent call centers across the country, seizing significant assets and apprehending suspects in an operation that involved the National Police, Ukraine's Security Service, the Prosecutor General's Office, and German police. The crackdown, which occurred this week, involved 411 searches and targeted various schemes designed to defraud individuals through investment scams or by gaining unauthorized access to bank accounts.
The fraudsters employed multiple tactics. Some operators impersonated bank officials, contacting victims about suspicious transactions and threatening to block accounts unless immediate payments were made. Others convinced victims to apply for loans, disclose payment card details, and install remote access tools on their devices. A common scheme involved luring individuals onto fake investment platforms, with operators posing as bankers or brokers. Some call centers even offered purportedly medicinal products for various diseases, despite these products lacking any actual therapeutic properties.
During the raids, law enforcement recovered a substantial amount of equipment and assets. This included 1,794 fully equipped workstations, 3,336 pieces of computer equipment, 1,346 phones, and 5,200 SIM cards. Authorities also seized 90 bank cards, access tools for 20 cryptocurrency wallets, and 22 vehicles. Financially, the haul included $2 million, 64,000 euros, and an unspecified amount of Ukrainian hryvnias in cash, along with one kilogram of bank gold in bars and jewelry.
Police confirmed that 26 individuals have been formally identified as suspects. Investigations revealed that some of these call centers specifically targeted citizens in foreign countries, particularly within the European Union, by tricking them into fake investment opportunities and installing remote-access software. In some instances, victims who had already lost money to fraudsters were targeted again with promises of assistance in recovering their losses, only to be scammed a second time.
The police noted that the call centers often had dedicated teams focused on identifying individuals genuinely interested in investing. Those implicated in these schemes could face charges under Parts 4 and 5 of Article 190 and Part 3 of Article 209 of the Criminal Code of Ukraine. These offenses carry potential penalties of up to 12 years in prison and property confiscation.
A forensic investigation of the seized equipment is currently underway. This examination is expected to help identify victims, determine the full extent of their losses, and gather evidence to incriminate the organizers of the scheme, as well as other participants such as money mules and money launderers.

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.