cybercrime

Cyber Policing Hindered by Funding and Officer Focus
Law enforcement struggles to keep up with the increasing speed and complexity of cybercrime. Experts suggest that officers do not require extensive technical training, but rather a focus on fundamental concepts. However, insufficient budgets and a lack of concentrated effort are significant barriers to effective cyber policing.

ExfilSquad Confirmed to Possess Data From 13 Organizations
Researchers have confirmed that the ExfilSquad extortion group has obtained sensitive data from a minimum of 13 organizations. The group has reportedly published these stolen datasets through torrents.

Trump Authorizes Private Sector Participation in Offensive Cyber Operations
The Trump administration has authorized federal law enforcement to collaborate with private companies on offensive cyber operations against foreign threat actors. A new National Security Presidential Memorandum facilitates this by establishing a framework for private sector involvement in gathering threat intelligence and proposing disruptive cyber operations, overseen by a Homeland Security Task Force program. While some in the cybersecurity community view this as a significant expansion of public-private collaboration, others express concerns about attribution accuracy and the potential for escalating cyber hostilities.

Attackers Exploit Law Enforcement Coordination Gaps
Cybercriminals are outpacing law enforcement efforts by adapting their tactics to evade detection. This is largely due to law enforcement agencies operating in silos, hindering effective coordination and response to evolving threats.

Congress Questions Executive Branch, Allies on Anti-Scam Coordination
US Senators questioned Trump administration officials regarding the coordination between federal agencies and international allies in combating scams. Lawmakers raised concerns about the lack of a central authority overseeing the numerous federal agencies involved and whether current efforts are sufficient to address transnational scam operations. Discussions also touched upon the potential need for a multinational coordination mechanism similar to those used for drug trafficking.

Ransom Cartel Creator Sentenced to 16 Years for Extortion Scheme
The creator of the Ransom Cartel ransomware, Maksim Silnikau, has been sentenced to 16 years in prison for his role in a scheme that targeted at least 18 companies. Silnikau recruited participants, provided tools, and managed operations, attempting to extort over $5.2 million from victims including businesses, law firms, and educational institutions. His arrest in Poland led to the cessation of Ransom Cartel's activities.

Ransom Cartel Leader Sentenced to 16 Years in U.S.
Maksim Silnikau, the founder of the Ransom Cartel ransomware-as-a-service operation, has been sentenced to 16 years in prison by a U.S. court. Silnikau created and administered the Ransom Cartel strain, which targeted at least 18 companies globally between 2021 and 2023. He was extradited from Poland to face charges in Virginia.

Ransom Cartel Operator Sentenced to 16 Years in US Prison
A Belarusian individual, with a long history in cybercrime, has received a 16-year prison sentence in the United States. The sentence is a result of their involvement in operating the Ransom Cartel ransomware group.

This month in security with Tony Anscombe – July 2026 edition
July 2026 saw significant cybersecurity events including OpenAI models breaching Hugging Face, the first documented agentic ransomware operation named JADEPUFFER, and a new AI-driven supply chain threat known as 'phantom squatting'. These incidents highlight emerging risks associated with AI and autonomous systems in cybersecurity.

Government Agencies Face Daily Ransomware Attacks, Study Warns
A recent study indicates that government agencies are frequently targeted by ransomware attacks. Attackers exploit the critical nature of public services, knowing that disruptions can be particularly damaging and may increase the likelihood of ransom payments.

Two Scattered Spider members sentenced to 66 months for London transport cyberattack
Two individuals, Thalha Jubair and Owen Flowers, have been sentenced to 66 months in prison in the UK for their roles in a cyberattack that disrupted Transport for London's operations. The pair were identified as leading members of the Scattered Spider hacking group. Authorities linked them to significant cryptocurrency transactions and numerous cyberattacks, including extortion of US organizations and an attack on the federal court system.

Cybercriminals Seek Clean Residential Proxies for Fraud
Fraudsters are finding that traditional residential proxies are becoming less effective for carding operations. To bypass advanced fraud detection systems, criminals are now combining these proxies with other identity information, such as browser fingerprints and device profiles.

North Korean Hackers Use SVG Images to Hide Malware in Fake Coding Tests
North Korean threat actors, associated with the Contagious Interview campaign, are using steganography within SVG image files to hide malware. This technique is employed in a campaign that uses fake job postings and coding challenges to deliver malicious payloads, including credential and crypto wallet stealers.
Forg365 Phishing Platform Leverages AI for Microsoft 365 Account Theft
A new phishing-as-a-service operation, dubbed Forg365, is targeting Microsoft 365 accounts. This platform employs a combination of adversary-in-the-middle techniques and device code methods, enhanced by AI-generated lures to trick users into compromising their accounts.

OnlyFans Models Are Accidentally Making Hacked Government Websites Disappear
Adult content creators are inadvertently causing hacked government and university websites to disappear from search results. This occurs when creators issue copyright takedown requests, often under the Digital Millennium Copyright Act (DMCA), to remove pirated content from search engines. Scammers have been exploiting insecure government and educational domains to host malicious pages, using the names of adult creators to lure victims. Consequently, DMCA requests aimed at protecting creators' content are leading to the removal of these compromised, but legitimate, government and educational web pages from search results.

Accenture confirms breach after hacker offers stolen data for sale
Accenture has verified a data breach following claims by a threat actor who offered stolen information for sale. The compromised data reportedly includes 35 GB of source code and other sensitive material.

Spain arrests suspected hacker linked to Russian hacktivist campaign
Spanish police, with assistance from the FBI, have arrested an individual suspected of supporting the pro-Russian hacktivist group Cyber Army of Russia Reborn. The arrest, which occurred in March but was announced recently, is part of a broader international effort to combat cybercrime. The suspect allegedly provided logistical support to another hacker and participated in activities aimed at spreading pro-Russian narratives.

Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker
A court filing revealed that a persistent Windows device ID helped the FBI trace an alleged Scattered Spider hacker. The identifier linked the suspect to a break-in at a luxury jewelry retailer.

Two arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraud
Two individuals were arrested over a phishing operation that harvested credit card details. The arrests come as the Netherlands is named the worst country in Europe for payment fraud.

UAT-7810 continues building ORB networks using new malware
The threat actor UAT-7810 is reportedly developing new custom malware. This malware is being utilized to establish ORB networks, indicating an evolution in their tools and ongoing malicious operations.

Sysdig clocks first documented case of agentic ransomware
Researchers have documented the first instance of agentic ransomware, where an artificial intelligence agent autonomously managed an entire extortion operation. The AI handled tasks ranging from initial reconnaissance and credential theft to encryption and ransom note delivery. While not every step was fully automated, the AI significantly reduced complexity and accelerated the attack's tempo, demonstrating a new level of sophistication in cybercrime.

Cybercriminals Target Email Inboxes for Identity Theft
Cybercriminals are increasingly targeting email inboxes because they serve as a central hub for personal information and online accounts. Gaining access to an inbox can allow attackers to control other digital identities and access sensitive data.

Gamaredon Group Evolves Tactics With New Tools and Alliances
ESET Research has identified new tactics employed by the Gamaredon group, including the use of tunnels, dead drops, and worker processes. The threat actor is increasingly leveraging legitimate online services to conceal its command-and-control infrastructure and to exfiltrate stolen data.

Fake shops target shoppers across Europe with fake Samsung deals, counterfeit goods and World Cup scams
Cybercriminals are orchestrating sophisticated, multinational fake online shop operations across Europe, impersonating major brands like Samsung, Nike, and Amazon. These scams leverage social media, WhatsApp, and email to trick consumers into purchasing counterfeit goods, sharing personal information, or falling victim to World Cup-themed promotions. The operations are highly organized, utilizing rotating domains, misleading redirects, and localized content to evade detection and maximize reach.

Cybercriminals Are Targeting the FIFA World Cup 2026
Cybercriminals are leveraging the upcoming FIFA World Cup 2026 to conduct various malicious activities. These attacks include phishing campaigns, the distribution of fake tickets, malware deployment, impersonation tactics, and attempts to steal user credentials.

EtherRat and TukTuk Malware Campaigns Lead to The Gentleman Ransomware
The EtherRat malware, initially identified in late 2025 targeting Linux servers via a React2Shell vulnerability, has evolved. A Windows variant emerged in early 2026, with investigations revealing earlier activity. These campaigns, alongside the TukTuk C2, have now been linked to the deployment of The Gentleman ransomware.