❌

Reading view

There are new articles available, click to refresh the page.

Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies

A former Army soldier responsible for a series of attacks and extortion attempts on telecom companies, including AT&T, was sentenced to 70 months in prison, the Justice Department said Friday.

Cameron John Wagenius engaged in a cybercrime spree for years, including while he was on active duty on a base in Texas. Prior to his arrest in December 2024, Wagenius attempted to sell stolen sensitive data to a foreign intelligence service and sought information online about defecting to Russia.

“Cameron Wagenius spent more than a year and a half betraying the trust placed in him as an active duty soldier by carrying out a sweeping cybercrime campaign,” said A. Tysen Duva, assistant attorney general of the Justice Department’s Criminal Division, said in a statement.

Wagenius, who pleaded guilty in July 2025, leaked stolen call records of President Donald Trump as part of multiple failed attempts to extort $500,000 from AT&T, Allison Nixon, chief research officer at Unit 221B, previously told CyberScoop. 

Authorities did not name Wagenius’ alleged victims in court filings, but said he disclosed non-content call detail records belonging to a government official and family members of another former official. AT&T in July confirmed cybercriminals accessed the company’s Snowflake environment in April and stole six months of phone and text records of “nearly all” of its customers. 

Wagenius’ and one of his co-conspirators, Connor Moucka, attempted to extort more than 10 organizations after stealing credentials and breaking into cloud platforms used by AT&T and other major companies based in the United States and abroad. 

Moucka, a Canadian extradited to the United States in March 2025, pleaded guilty in August to playing a central role in one of the most far-reaching cyberattacks of 2024 — the widespread compromise of more than 165 Snowflake customer environments, resulting in massive data theft for extortion.

Wagenius, Moucka and their alleged co-conspirator John Erin Binns, who is not presently in U.S. custody, stole billions of sensitive records and received more than $2.5 million in extortion payments combined, according to prosecutors. Victims of the attack spree included AT&T, Ticketmaster, Advance Auto Parts and Santander.

Some of the records in Wagenius’ possession at the time of his arrest were stolen in the attack spree on Snowflake customer databases, according to cybercrime researchers. Officials said Wagenius was directly involved in attempted extortion attempts targeting multiple organizations for a combined total of more than $1 million. 

The 22-year-old was ordered to pay almost $295,000 in restitution for his crimes.

“His hacking schemes were not only aimed at getting rich, he was also motivated by a desire to achieve status within criminal hacking communities,” Charles Neil Floyd, first assistant attorney for the U.S. District Court for the Western District of Washington, said in a statement. “This sentence must impose real consequences to deter him, and hopefully other would-be hackers.”

Wagenius, who identified himself as “kiberphant0m” and “cyb3rph4nt0m” on online criminal forums, used a hacking tool he helped develop called SSH Brute to steal credentials while on active duty, officials said. Wagenius and his co-conspirators threatened the victim organizations privately and in public forms, officials added.

“It is especially shocking that a member of our armed forces, sworn to defend Americans and their constitutional rights, would engage in such a violation of privacy,” W. Mike Herrington, special agent in charge of the FBI Seattle field office, said in a statement.

When federal law enforcement seized Wagenius’ devices in December 2024, they found evidence indicating he had access to thousands of stolen identification documents and large amounts of cryptocurrency. Days later, Wagenius purchased a new laptop against his commanding officer’s order, according to officials, and used it every day over a five-day period in the barracks at Fort Cavazos in Texas with VPN software to hide his identity and location.

The post Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies appeared first on CyberScoop.

Ryuk ransomware operator sentenced to 2 years in prison

A 35-year-old Armenian national was sentenced to two years in prison for his involvement in a series of Ryuk ransomware attacks while living in Ukraine and Russia in 2019 and 2020, the Justice Department said Tuesday.

Karen Vardanyan was extradited from Ukraine to the United States last year and pleaded guilty to computer fraud and conspiracy to commit fraud and extortion in July. Vardanyan’s sentencing, which also calls for about $1.2 million in restitution to victims, matches terms of a plea agreement he reached with prosecutors.

Vardanyan and his co-conspirators’ victims include a Michigan-based company that paid a ransom of nearly $1.2 million in January 2020, a Watsonville, Oregon-based technology company that was attacked in December 2019 and a Texas-based school breached in February 2020, according to court records.

“Like Vardanyan, many cybercriminals are not masterminds of a complex ransomware or extortion scheme but nonetheless play an integral part in the success of these crimes,” read a memo signed by U.S. attorneys in the District of Oregon.

“Unfortunately, high rewards and a relatively low risk of detection are basic features of cybercrime. The only way to affect the cost-benefit analysis of these crimes is to impose meaningful sentences on those who are caught,” the U.S. attorneys added.

Prosecutors previously accused Vardanyan and his co-conspirators — Ukrainian nationals Oleg Nikolayevich Lyulyava and Andrii Leonydovich Prykhodchenko, and Armenian national Levon Georgiyovych Avetisyan — of illegally accessing computer networks to deploy Ryuk ransomware on hundreds of compromised servers and workstations between March 2019 and September 2020.

Ryuk ransomware was prevalent in 2019 and 2020, infecting thousands of victims globally across the private sector, state and local municipalities, local school districts and critical infrastructure, including a wave of attacks on U.S. hospitals.

Victims of Ryuk ransomware attacks include Hollywood Presbyterian Medical Center, Universal Health Services, Electronic Warfare Associates, a North Carolina water utility and multiple U.S. news outlets.

Justice Department officials said Vardanyan and his co-conspirators received about 1,160 bitcoins — valued at more than $15 million at the time — in ransom payments from victim companies.

Prosecutors said they found no evidence Vardanyan was still engaged in criminal activity at the time of his arrest. Vardanyan’s incarceration will be followed by three years of supervised release, and his conviction will have immigration consequences resulting in removal from the United States after serving his sentence.

The post Ryuk ransomware operator sentenced to 2 years in prison appeared first on CyberScoop.

ShinyHunters claims attack on FBI exposes almost all agents

The FBI is investigating an attack on its own systems after ShinyHunters claimed responsibility for the incident, putting the prolific cybercrime group in the most direct conflict yet with agents responsible for investigating data extortion attacks.

The Monday breach, first reported by 404 Media, allowed ShinyHunters to temporarily deface the FBI jobs site. The group claimed it stole “very sensitive data on almost all FBI agents and individuals who filed an application with the FBI for a job,” in a lengthy post on its data-leak site.

“The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,” a spokesperson for the agency said in a statement.

An alert on the FBI jobs site notes that apply.fbijobs.gov and the Special Agent Application Portal are currently unavailable.

The attack marks a sobering escalation by ShinyHunters, a notorious group that previously targeted major cloud platforms, healthcare organizations, universities, technology companies, retailers and education service providers. Previous victims of ShinyHunters this year include Instructure, Salesforce, Snowflake and McKesson.

“The ShinyHunters ransomware group appears to be actively trying to put a target on their back,” Cynthia Kaiser, senior vice president at Halcyon’s ransomware research center, told CyberScoop. 

ShinyHunters claims it targeted the FBI in response to a public service announcement it says contains false allegations about the group. The FBI issued the PSA following ShinyHunters’ May attack on Instructure, the company behind Canvas, a widely used central hub for K-12 and university coursework, exams and communication. 

The group responded with its own “PSA” on its data-leak site, insisting it is not affiliated with The Com, has never conducted swatting attacks or claimed it had sensitive or compromising information, including embarrassing photos or videos, to extort victims. 

The PSA was addressed to Brett Leatherman, assistant director of the FBI’s cyber division, and FBI Director Kash Patel. 

“While ShinyHunters has in the past been hyperbolic about the criticality of the data they’ve accessed, the group has established itself as a legitimate threat,” Flashpoint analysts told CyberScoop. 

“This attack benefits ShinyHunters by bolstering their reputation as a credible threat,” the analysts added. “In the group’s statement on their leak site regarding the breach, they portray the FBI’s PSA as an “attempt to ‘disrupt’ our operations and hinder clients’ trust in our organization hoping nobody pays us.”

The threat group typically uses social engineering, abuses weaknesses in identity systems or exploits vulnerabilities to gain access to cloud-hosted environments containing troves of sensitive or proprietary data, which it threatens to leak if the victim doesn’t pay a ransom.

ShinyHunters doesn’t appear to be seeking a payoff in this case, but rather a bid to coerce the FBI into amending or removing the May PSA. The group didn’t make any direct threat in the data-leak site post to release the stolen data, but it set a deadline of one week for action.

That coercive approach toward the FBI could backfire, according to experts. 

“Ransomware groups are largely successful because they operate like businesses,” said Kaiser, a former deputy assistant in the FBI’s cyber division. “Targeting other criminal groups or law enforcement — especially in ways intended to publicly shame — demonstrates a lack of discipline that historically has led to takedowns, takeovers or defections.”

The post ShinyHunters claims attack on FBI exposes almost all agents appeared first on CyberScoop.

Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud

Microsoft, along with a group of industry partners, disrupted EvilTokens, a short-lived but highly consequential cybercrime platform that investigators linked to more than 12,000 compromised Microsoft customer email inboxes across more than 10,000 organizations globally, the company said Tuesday.

Acting on federal court order Sept. 15, Microsoft and partners seized 50 websites the phishing-as-a-service used for operations and disabled more than 175 domains linked to EvilTokens’ supporting infrastructure. 

EvilTokens, launched in February 2026, was “a powerful cybercrime platform that used AI at every step of the attack chain — from compromising email accounts to designing intricate roadmaps for financial fraud and scams,” Steven Masada, associate general counsel and general manager of Microsoft’s Digital Crimes Unit, wrote in a blog post.

About 1,000 cybercriminals used EvilTokens over the course of its operation, a Microsoft spokesperson told CyberScoop.

The service was centered on an AI-style chatbot that cybercriminals used to analyze victims’ inboxes, identify trusted relationships, payment authorizations and other sensitive details that could facilitate fraud.

“AI was not simply helping attackers write more convincing messages. It helped them decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible,” Masada wrote. 

EvilTokens was one of the most widely used phishing-as-a-service platforms prior to its takedown. It facilitated business-email compromise campaigns by stealing session tokens that allowed cybercriminals to sift through a victim’s inbox and maintain persistent access.

“We cannot estimate the total fraud attributable to all EvilTokens activity. However, we were able to correlate at least 13 complaints filed with the FBI’s Internet Crime Complaint Center to EvilTokens-linked activity, representing approximately $1.7 million in reported losses,” a Microsoft spokesperson said. “Because many incidents go unreported and not all victims can be definitively linked to specific campaigns, we believe this is a conservative estimate.”

Victims of EvilTokens were largely concentrated in the United States, Canada, the United Kingdom, Australia, India and France, according to Microsoft. SpyCloud, which supported the takedown, identified compromised email domains spanning 79 countries.

Microsoft said it also identified two men behind EvilTokens — Felix Utomi and Waidi Segun Adams — and attributes the development and support of the platform to Storm-2992, a threat actor unaffiliated with any other known cybercrime groups.

The United Kingdom’s Metropolitan Police acted on that information Sept. 18 when it served warrants in the greater London area, arrested the men accused of making articles for use in fraud and money laundering and seized their digital devices.

The Metropolitan Police said it received information from Microsoft about EvilTokens’ administrators in August. Utomi and Adams were released on bail as the investigation continues. 

“The two primary operators identified in our investigation were residing in the U.K.,” a spokesperson for Microsoft told CyberScoop. “While our investigation focused on those individuals, we believe others may have supported the operation in various capacities.”

Microsoft’s legal filing in the U.S. District Court for the Eastern District of Virginia refers to five additional unidentified people allegedly acting as support personnel and users.

Microsoft and others involved in the EvilTokens takedown, including Health-ISAC, Cloudflare, OpenAI, Shadowserver and TRM Labs, didn’t fully quantify how much fraud the service enabled, but it gained popularity quickly among cybercriminals and was lucrative for its operators.

Coinbase, which also aided the investigation into EvilTokens, said it traced about $1.1 million in revenue for EvilTokens from its paying customers. The virtual currency company’s threat researchers found more than 1,000 deposits to EvilTokens from more than 700 distinct addresses through June 2026. 

Operators sold access to the service through Telegram for a $1,500 initiation fee and a recurring $500 subscription. EvilTokens significantly lowered the barrier to entry for cybercriminals by including specialized tools for identity attacks, cloud systems, social engineering and financial fraud in a single interface.

The service allowed cybercriminals to map organizational structure and permissions in Microsoft Graph, which enabled lateral movement, researchers said. With active tokens gained through a collection of highly-targeted phishing lures, cybercriminals consistently bypassed multi-factor authentication, email gateways and endpoint security tools.

Microsoft said the platform’s creators developed portions of the platform with AI and it uncovered capabilities from multiple AI models. 

“It packaged much of the criminal process into a commercially run service, complete with subscription pricing, customer support, management dashboards and tools designed to move customers from account access toward financial exploitation,” Masada added.

The companies and organizations involved in the globally-coordinated takedown identified and notified potential victims, shared indicators of compromise and shared intelligence with law enforcement about EvilToken’s operators and some of its customers.

Experts advised organizations and employees to treat unsolicited device codes as a red flag, assume compromised accounts are fully cataloged in minutes, and independently verify requests to change payment information or redirect funds.

“The infrastructure supporting EvilTokens has been disrupted, but the model it demonstrated will not disappear with it,” Masada warned.

The post Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud appeared first on CyberScoop.

Early Scattered Spider member pleads guilty to cybercrime spree

Another core member of the hacker subset of The Com involved in a spree of extortion attacks from at least 2021 to 2023 pleaded guilty to federal charges, according to court records released Tuesday.

Ahmed Hossam Eldin Elbadawy, a 24-year-old from Texas, pleaded guilty exactly one year ago to wire fraud conspiracy and aggravated identity theft. His guilty plea wasn’t shared publicly until prosecutors filed an order of forfeiture this week seeking proceeds from Elbadawy’s criminal activities. 

Elbadawy and his co-conspirators — Noah Michael Urban, a Florida man sentenced to 10 years in prison last year, and Tyler Robert Buchanan, a Scottish man who pleaded guilty to multiple cybercrimes in April and awaits sentencing — were part of an aggressive subset of The Com coined Scattered Spider. 

The financially-motivated crew obtained credentials via social engineering and stole sensitive company data to identify high net worth employees with virtual currency accounts containing millions of dollars, according to an indictment filed against Elbadawy and his co-conspirators in late 2024. 

Federal authorities filed charges against five individuals with links to the Scattered Spider cybercrime outfit, including Elbadawy, Urban, Buchanan, Evans Onyeaka Osiebo and Joel Martin Evans in 2024.

Elbadawy’s victims included large businesses in the entertainment, telecom, technology, business process outsourcing, IT, cloud and virtual currency sectors, officials said. Prosecutors linked Elbadawy and his co-conspirators to at least 12 victim companies in the indictment, including three businesses located in Southern California where he awaits sentencing. 

Authorities detailed 29 victims who were compromised by Elbadawy and his co-conspirators. The crew stole virtual currency from wallets controlled by many of those victims. The most high-value thefts included virtual currency worth nearly $6.35 million in September 2021, $571,000 in June 2022 and nearly $1.7 million in December 2022. 

Prosecutors are seeking significant property and asset forfeiture from Elbadawy, including Bitcoin valued at more than $14.19 million, Ethereum valued at more than $3.4 million and nearly $63,000 in cash. Officials also requested the forfeiture of a lifted golf cart, three luxury vehicles, a painting of Muhammad Ali, luxury watches, gold jewelry, a vast collection of designer bags and 150 pairs of shoes.

The terms of Elbadawy’s plea agreement haven’t been released. 

While early leaders of Scattered Spider have been arrested or sentenced for their crimes, others have filled those roles with even more exceptional impact.

The Com has grown to thousands of members, typically between 11 and 25 years old, splintered into three primary subsets the FBI describes as Hacker Com, In Real Life Com and Extortion Com.

Criminal acts committed by these multiple, interconnected networks include swatting, extortion and sextortion of minors, production and distribution of child sexual abuse material, violent crime and various other cybercrimes.

You can read the indictment against Elbadawy and some of his co-conspirators below.

The post Early Scattered Spider member pleads guilty to cybercrime spree appeared first on CyberScoop.

International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data

North Korean hackers are infiltrating tens of thousands of job seekers’ computer networks by posing as prospective employers, such as artificial intelligence firms, to steal sensitive information and millions of dollars worth of cryptocurrency, U.S. and allied governments warned Friday.

The security agencies behind the alert, attributed the group, known as WaterPlum or Contagious Interview, as operating under the 313 General Bureau of the Munitions Industry Department subordinate to the Central Committee of the Workers Party of Korea. The efforts dovetail with those of North Korean IT workers.

“WaterPlum actors pose as prospective employers to target software developers and IT professionals worldwide under the pretext of attractive job opportunities,” the agencies wrote. “They often impersonate legitimate Artificial Intelligence (AI), cryptocurrency, or Non-Fungible Token (NFT) companies and have also used recruiting services.”

Additionally, “Some WaterPlum actors also operate as North Korean IT workers performing web system design and development tasks on corporate web systems for clients,” read the alert from agencies in Japan, Australia and Germany, alongside the FBI and the Department of Defense’s Cyber Crime Center.

They’ve used the stolen information to fuel other operations, and the overlap between WaterPlum and North Korean IT workers is substantial, the agencies said.

“WaterPlum actors and North Korean IT Workers used the same IP addresses when accessing laptop farms, using cloud-sourcing services, and applying for positions at the Japanese cryptocurrency exchange,” they wrote.

Collectively, WaterPlum has infected more than 30,000 devices in more than 100 countries, targeting IT professionals in Japan, the United States, Europe and other nations. Its operations have transferred the equivalent of nearly $11 million of cryptocurrency from over 7,000 crypto wallets to North Korea, according to the alert.

The law enforcement agencies said they have had some success tackling the group, but are seeking further cooperation and released details in the alert about WaterPlum’s tactics, techniques and procedures.

“For the first time in Japan, authorities successfully identified, investigated, and dismantled a ‘laptop farm’ operated by an enabler in Japan,” the alert reads. “Japanese authorities obtained evidence this cyber actor group transferred several hundred million Japanese yen in cryptocurrency to foreign locations outside of Japan. The FBI continues to identify and prosecute US-based actors providing illicit facilitation services to North Korean IT workers.”

The warning comes as the Multilateral Sanctions Monitoring Team, an international panel overseeing UN sanctions against North Korea, released a report exposing thousands of North Korean nationals employed in industries around the world.

The post International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data appeared first on CyberScoop.

Authorities seize popular, long-running DDoS-for-hire service domains

Authorities seized the primary domain and other websites linked to NightmareStresser, one of the longest-running and most popular distributed denial-of-service operations used by cybercriminals globally, the Justice Department said Tuesday. 

Cybercriminals of various motivations used the DDoS-for-hire service to launch hundreds of thousands of DDoS attacks or attempted attacks since at least 2022, officials said. 

The takedown, part of an ongoing globally coordinated effort dubbed “Operation PowerOFF,” marks law enforcement’s continued targeting of IP stressers or DDoS booters that inundate websites, servers and networks with junk traffic, rendering legitimate sites inaccessible. The seizures were executed by the FBI Anchorage field office and the Royal Canadian Mounted Police.

Officials didn’t name the operators of NightmareStresser or identify its country of origin, but the service claimed it operated under the laws of Russia, Zach Edwards, staff threat researcher at Infoblox told CyberScoop.

The court-ordered seizure of NightmareStresser’s primary domain, which operated openly on the public web and now displays a seizure notice, is a positive development in the fight against DDoS-for-hire threat actors, Edwards said. Yet, he added, “it’s somewhat shocking that it’s taken law enforcement this long to take action.”

Authorities said they’ve seized more than 100 domains associated with DDoS-for-hire services since 2018. 

Despite those efforts, DDoS-for-hire tools remain prolific and easily accessible, often including tutorials that allow non-tech savvy people to initiate attacks on various organizations. 

“The vast majority of people who actually use DDoS services like NightmareStresser are script kiddies, oftentimes for pranks or for some sort of obscure political agenda. These services have been heavily used against gaming servers and streamers,” Edwards said.

Officials said NightmareStresser’s customers targeted various victims in the United States and abroad, including educational institutions, government agencies, gaming platforms and millions of people.

The DDoS-for-hire service’s operators claimed tens of thousands of users, Edwards said. “NightmareStresser is unique because of how long they’ve operated, their aggressive marketing which was pretty open about supporting illegal use cases, and their affiliate program which was used to reward partners,” he added. 

Authorities are now likely attempting to identify the operators of NightmareStresser, its business partners and people who used the service, according to Edwards. 

“Unfortunately for law enforcement, threat actors behind NightmareStresser claimed they were operating under the laws of the Russian Federation, which is a strong sign that it may be challenging to bring these folks to justice, even if they are known and doxxed,” he said. 

The impact of the seizures may also be temporary, at best. “The reality is that these booter services are like playing a game of Whac-A-Mole,” Edwards said. “There’s always another suspicious service operating similar DDoS products, and these underground networks quickly shift to new providers when one is taken down.”

The post Authorities seize popular, long-running DDoS-for-hire service domains appeared first on CyberScoop.

Five alleged leaders of Black Axe’s operations in South Africa extradited to US

Five alleged leaders of the South African wing of Black Axe, a global cybercrime group with operations spanning dozens of countries, were extradited to the United States Friday to face multiple charges, the Justice Department said.

Officials accuse the five people, all originally from Nigeria, of running romance scams and advance fee scams from at least 2011 until they were all arrested in South Africa in 2021. The defendants were due Monday for initial court appearances and arraignments in a federal court in Trenton, N.J.

“Black Axe is a notoriously violent transnational criminal organization that also happens to dabble in romance scams to make money,” Stefanie Roddy, special agent in charge of the FBI Newark field office, said in a statement. “The ability of FBI Newark and our partner agencies to reach into South Africa illustrates our resolve to hold accountable any and every type of fraudster who preys on innocent victims here in the United States.”

The accused include Perry Osagiede, founder and leader of the Cape Town Zone of Black Axe; Franklyn Edosa Osagiede, the zone’s “chief ihaza” Osariemen Eric Clement, “assistant eye of the zone,” Collins Owhofasa Otughwor, the zone’s “chief eye,” and Musa Mudashiru, one of the group’s “assistant butchers.”

Prosecutors said the five defendants and their co-conspirators used fake identities to pose as a love interest, relatives, business partners or friends to trick victims into sending them money.

Many of the scams involved claims that the alleged cybercriminals needed money for work travel or to hold them over financially following a series of unfortunate events. This included requests for loans, often involving issues with a construction site, delayed inheritance, or expensive health costs for claimed relatives, according to an unsealed indictment filed in the U.S. District Court of New Jersey in 2021. 

Prosecutors said the co-conspirators also used business entities and gained access to the financial accounts of some victims to conceal the funds illegally obtained from other victims. In some cases, the alleged Black Axe members threatened to distribute sensitive photos of victims when they hesitated to send money, officials added.

The extradition follows a heightened period of law enforcement activity targeting Black Axe in multiple countries. 

Authorities arrested 34 alleged cybercriminals in Spain, including some Black Axe leaders, for adversary-in-the-middle scams such as business email compromise, money laundering and vehicle trafficking in January. 

Officials seized millions in assets, arrested 58 individuals and identified 263 suspects, including members of Black Axe, in a multi-country sting operation in August. 

Black Axe is a highly structured, hierarchical group that generates billions of dollars in criminal proceeds annually from many small-scale operations spanning dozens of countries. 

All five of the extradited individuals are charged with conspiracy to commit wire fraud and money laundering. Perry Osagiede and Franklyn Osagiede are also charged with wire fraud and aggravated identity theft. Officials also charged Clement with wire fraud and Otughwor with aggravated identity theft. The combined charges carry up to 62 years in prison. 

“This case reflects the result of a years-long effort by the U.S. Secret Service and our law enforcement partners to identify, investigate, and bring to justice those who allegedly preyed on victims through sophisticated online fraud and money laundering schemes,” Craig Marech, special agent in charge of the U.S. Secret Service’s Newark field office, said in a statement. 

The Justice Department published additional information about the Cape Town Zone wing of Black Axe, including multiple aliases and business entities used by the group’s members, and encouraged potential victims to contact the FBI.

The post Five alleged leaders of Black Axe’s operations in South Africa extradited to US appeared first on CyberScoop.

Conti ransomware crew member sentenced to four years in prison

A 44-year-old Ukrainian national was sentenced to four years in prison for his long-running participation in Conti, a ransomware group that attacked more than 1,000 organizations globally before it disbanded in 2022, the Justice Department said Thursday.

Oleksii Oleksiyovych Lytvynenko, also known as Alexsey Alexseevich Litvinenko, pleaded guilty in June to conspiracy to commit wire fraud as a result of some of those attacks. At that time, he admitted he joined the prolific cybercrime group in September 2021, developed malware and held data on 12 victims, including eight based in the United States.

“For years, the Conti ransomware group executed a sustained and sophisticated campaign that victimized hundreds of organizations across the United States and abroad, including critical infrastructure entities, causing losses in the millions of dollars,” A. Tysen Duva, assistant attorney general of the Justice Department’s criminal division, said in a statement. 

“Lytvynenko joined that conspiracy as both an intruder and a developer — personally harming at least 12 companies, storing stolen data from victims, and helping build the malicious tools Conti used to extort and threaten communities,” Duva added. “Even after the Conti conspiracy ended, he continued engaging in active ransomware operations until his arrest. Cybercriminals who build, deploy, or profit from malware like Conti — no matter where they operate — will face justice and meaningful consequences in U.S. courts.”

When Lytvynenko was arrested in Ireland, where he was living with temporary protective status in July 2023, authorities said he “was asleep but within arms’ reach of an open laptop running Cobalt Strike.” He was extradited to the United States in October 2025. 

Prosecutors said Lytvynenko and his co-conspirators extorted about $634,000 in Bitcoin from two victims in Tennessee, including an undisclosed government entity that resulted in the compromise of a sheriff’s department, local emergency medical services and a local police department. According to an indictment that was unsealed last fall, Lytvynenko and his co-conspirators also leaked data they stole from another Tennessee-based victim after it refused to pay a $3 million ransom demand.

Four of Lytvynenko’s alleged co-conspirators — Maksim Galochkin, Maksim Rudenskiy, Mikhail Mikhailovich Tsarev and Andrey Yuryevich Zhuykov — were indicted in 2023 in the same federal court for crimes related to their suspected involvement in Conti attacks from 2020 to 2022. 

Conti was among the most active ransomware groups globally, impacting hundreds of critical infrastructure providers, Costa Rica’s government in 2022, and ultimately leading the State Department to offer a $10 million reward for information related to Conti’s leaders. The group was notoriously resilient, bouncing back with new infrastructure and hitting new targets after a massive leak exposed chats between the group’s members in 2022.

Conti disbanded later that year, but members of the Cyrillic-language group rebranded under three subgroups: Zeon, Black Basta and Quantum, which quickly rebranded to Royal, before rebranding again to BlackSuit in 2024.

“Lytvynenko and his co-conspirators used Conti ransomware to attack computers and networks in nearly every state, and today’s sentence reflects the gravity and extent of those crimes,” Brett Leatherman, assistant director of the FBI’s cyber division, said in a statement. 

“Ransomware criminals should know they are not anonymous and operating from overseas does not mean operating without consequences,” he added. “The FBI and our partners will use every lawful tool to dismantle their infrastructure and bring them to justice.”

The post Conti ransomware crew member sentenced to four years in prison appeared first on CyberScoop.

Russian national extradited to US for alleged involvement in bank-account takeover scheme

Authorities extradited a 36-year-old Russian national from the Republic of Georgia under accusations of widespread bank-account takeover attacks, including a scheme to defraud two banks of more than $6.3 million, the Justice Department said Tuesday.

Sergei Anatolyevich Filimonov and unnamed co-conspirators ran an extensive operation starting in November 2023 to spoof domains of banks, obtain credentials of legitimate customers and use those details to steal money from accounts with large balances, according to court records. 

Filimonov and his co-conspirators allegedly collected more than 5,000 victim login credentials to various banks, including those assigned to employees with access to a company headquartered in Atlanta and another business with offices in Cumming, Ga.

Authorities said Filimonov and his co-conspirators registered and maintained spoofed domains of banks, purchased sponsored links to direct unsuspecting victims to those domains, and stole credentials from those banks’ customers when they attempted to log into the fraudulent sites.

The alleged bank-account takeover crew also created infrastructure to store victim login credentials and tricked victims into providing additional details to bypass security controls.

Prosecutors said Filimonov and his co-conspirators caused and attempted to cause the unauthorized transfer of nearly $5.58 million from one unnamed bank in June 2024 and $735,000 from another bank in November 2024. Both banks have local branches in the Northern District of Georgia and maintain headquarters in North Carolina, according to the indictment. 

Officials previously seized the domain, which the co-conspirators allegedly used to store credentials harvested from the spoofed banking sites in December 2025. The FBI at the time said it identified at least 19 victims in the U.S. linked to the domain and put total attempted losses at about $28 million, including confirmed losses of about $14.6 million. 

Filimonov is charged with conspiracy to commit bank and wire fraud, access device fraud conspiracy, multiple counts of bank and wire fraud, possession of unauthorized access devices and aggravated identity theft. He faces up to 175 years in prison. 

He pleaded not guilty Sept. 4 and remains detained in the Northern District of Georgia.

The post Russian national extradited to US for alleged involvement in bank-account takeover scheme appeared first on CyberScoop.

Jail time for Maine child in 764 marks turning point in federal law enforcement

The FBI said a 17-year-old from Maine is the first child federally charged and adjudicated for crimes stemming from their involvement in 764, a violent extremist collective.

A judge ordered the teen to remain detained after determining they committed multiple crimes, including conspiracy to sexually exploit a child, sexually exploiting and enticing a child, distributing child sexual abuse material, sending interstate threats, cyberstalking victims and identity theft.

“This first-in-the-nation case should make it crystal clear that if you conspire to commit violent, extremist crimes, your age will not shield you from accountability,” Ted Docks, special agent in charge of the FBI’s Boston Division, said in a statement Tuesday. “What this juvenile did would shock most people to their very core, and it is our hope that by publicizing this case, others will be deterred from making the same devastating choices this teen did.”

The nihilistic extremist group the teen participated in, 764, is more broadly affiliated with The Com, a sprawling network of thousands of people, typically between 11 and 25 years old, seeking to foster social unrest by destroying civilized society through the corruption and exploitation of children and other vulnerable populations.

The Justice Department’s resolve in this case — detaining and adjudicating a 764 member before they reach adulthood — marks a turning point and apparent change in internal policy against charging children for federal crimes linked to their involvement in violent extremist groups. 

“Crimes from 764 copycat groups in The Com are extremely serious and it speaks to how law enforcement prioritizes these things,” Allison Nixon, chief research officer at Unit 221B, told CyberScoop. “They recognize this loophole involving minors needs to be closed in order to tackle this social problem of violence arising from minors which crosses state lines.”

The first-of-its-kind case has a wider impact that will cause ripples across the landscape of violent extremist crime, she added. 

“If you sexually exploit a child, the fact that you yourself are a minor will not protect you from the consequences of your actions,” Andrew Benson, U.S. attorney for the District of Maine, said in a statement.

The Maine teenager, whose identity is being withheld, was ordered to serve a term of official detention followed by supervision, the FBI said. Officials did not provide details about the terms of detention.

Andrew McCormack, assistant U.S. attorney for the U.S. District of Maine, and a spokesperson for the FBI Boston Division, both said federal law restricts what law enforcement can share about cases involving underage criminals and declined to say where the teen lived, where they’re being detained and for how long. 

Nixon conveyed, with some reluctance, the need for more actions like this targeting underage members of 764 and similar groups. 

“I’m not advocating normalizing throwing kids in prison but we very much need to find a new balance to protect society from violent groups that are incentivized by this federal loophole to commit maximum harm before turning 18, and then after 18, to recruit and train kids to do dirty work for them,” she said. “I cannot understate how much this loophole specifically influenced this culture of maximizing harm.”

The teen’s ordered detention marks a continuation of consistently heightened law enforcement activity targeting members of 764 and affiliated groups. 

Kyle William Spitze, an original member of 764 and leader of one of its offshoots, was sentenced to 77 years in prison, the longest imprisonment ever imposed on a nihilistic violent extremist, in federal court in Tennessee in late August.

Alexis Aldair Chavez, who began associating with 764 as a child in 2022 before leading an offshoot 8884, was sentenced to 40 years in prison in July for blackmailing and coercing multiple girls to commit self-harm, torture animals and degrade themselves on camera to produce CSAM. 

Other alleged 764 members arrested since 2025  include: Leonidas Varagiannis and Prasan Nepal, Baron Cain Martin, Tony Christopher Long, Erik Lee Madison, Zachary Sweeney and Aaron Corey.

The FBI said it is currently investigating more than 500 subjects nationwide who are allegedly involved in 764 and its many offshoots. 

“These groups actively target minors and are made up of a large percentage of minors. They are intentionally recruiting juveniles here in the U.S. to conduct criminal acts because, simply put, they think they can get away with it because historically, the federal justice system has rarely prosecuted juveniles,” Docks said. 

“We’re here to tell you, they’re wrong, and if they don’t stop this abhorrent behavior, they too could find the FBI on their doorstep and themselves in federal court. We are going to do everything in our power to protect kids and ensure those who harm them don’t get away with it,” Docks added.

Nixon, who has studied the rise of these violent extremist groups and helped law enforcement identify some of its members, said she’s pleased with this development. 

“Right now the prevailing sentiment within these violent groups is that you can do anything you want with no accountability before you turn 18, so therefore you should commit the most heinous acts possible because it’s your last chance. That’s why there are so many 17 year olds who become a major public nuisance, because it’s their last hurrah — but for bomb threatening schools and abusing little kids,” Nixon said. 

“They slow down on their 18th birthday and pivot to using minors to hide behind, and teaching them this lifestyle,” she added. “Closing that loophole will do a ton to break this cycle. They pay close attention to law enforcement, and just one arrest shatters their sense of safety. I don’t think the FBI will stop at just one arrest.”

The post Jail time for Maine child in 764 marks turning point in federal law enforcement appeared first on CyberScoop.

Dogged Russia-based botnet dismantled after 23-year run

Sality, a Russia-based botnet that infected more than 11 million devices during a 23-year run of operations, was dismantled Monday by law enforcement, CrowdStrike and the Shadowserver Foundation. 

CrowdStrike, which announced the takedown Tuesday alongside authorities, said it played a crucial role dismantling the botnet’s technical infrastructure, rendering the malware-spreading operation irrecoverable. 

The peer-to-peer botnet was a persistent piece of criminal infrastructure that evaded disruption for an exceptionally long period because it lacked centralized architecture. 

Sality used infected machines to communicate peer-to-peer, creating a decentralized structure that made system-wide disruption efforts more difficult than botnets that rely on a core server. 

“The same properties that made Sality resilient also created the conditions for its undoing,” CrowdStrike wrote in a blog post. The company said it targeted Sality’s peer list of infected machines and tricked the network into permanently cutting off access to those devices.

“From the operator’s perspective, infected machines simply disappear,” CrowdStrike wrote, adding that the botnet is no longer under the operator’s control.

Sality’s domains were seized by a globally coordinated effort supported by the FBI, Justice Department and authorities from Europol, Bulgaria, Hungary and Romania, officials said. Shadowserver is working with internet service providers to identify devices infected by Sality and aid with remediation. 

“Cybercriminals, botnets, and malware are a clear and present danger to our nation’s security and economy,” Bill Essayli, first assistant U.S. attorney, said in a statement. 

Europol said the Sality takedown was the culmination of work spanning global law enforcement back to 2017. 

CrowdStrike said Sality’s operator was primarily financially motivated, but it attributed three DDoS attacks to Sality, suggesting the operator was occasionally willing to use the botnet for personal or political aims. 

The botnet enabled cryptocurrency theft and cyberattacks on victims in the United States and abroad, the Justice Department said. Officials did not name the person or cybercrime group behind Sality.

“This operation demonstrates that peer-to-peer architecture, long considered a shield against disruption, is not invincible,” CrowdStrike wrote. 

“Operating for decades without consequence does not mean operating without risk,” the company added. “The calculus has changed. We will find you, we will dismantle your infrastructure, and we will impose costs that make the enterprise untenable.”

The post Dogged Russia-based botnet dismantled after 23-year run appeared first on CyberScoop.

McKesson copes with fallout from data theft extortion attack

McKesson said its business and distribution centers remain operational in the wake of a cyberattack it disclosed Friday that resulted in data theft and temporary service interruptions.

Attackers gained access to some of the health care vendor’s third-party applications and stole data associated with a subset of customers in the company’s oncology, multispecialty and medical-surgical business units, Francisco Fraga, chief information and technology officer at McKesson, said in a statement Saturday. 

McKesson is a major player in the healthcare sector, claiming it distributes about one-third of all pharmaceuticals used throughout North America. It reported $403.4 billion in revenue for the one-year period ending in March. 

The company’s size and critical role it serves also makes it a high-profile target for cybercriminals. McKesson did not identify the group behind the attack, but ShinyHunters, a cybercrime group known for targeting large organizations with extortion demands after stealing massive amounts of sensitive data, claimed responsibility.

The company declined to answer questions about ShinyHunter’s claims. Yet, on Friday, McKesson disclosed the attack in a regulatory filing while ShinyHunters added the company to its data-leak site. 

McKesson said it discovered the attack Aug. 25. A period of widespread data theft was over by then, following a four-day intrusion beginning Aug. 21, according to researchers.

“Upon discovery, we immediately activated our incident response protocols, launched an investigation, and engaged leading cybersecurity industry experts to support our response,” Fraga said in a statement. 

“We have reasonable assurance of no ongoing unauthorized activity in our systems. Customers can continue to connect to and use our systems and services as intended,” he added. 

While McKesson’s investigation continues, it faces a more urgent deadline of Sept. 1 from ShinyHunters, which is reportedly seeking a ransom demand in excess of $55 million. 

The company did not answer questions about any ransom demand or whether it responded to the alleged attackers. 

The circumstances of the attack against McKesson are similar to other recent victims of ShinyHunters. The threat group typically uses social engineering or abuses weaknesses in identity to gain access to cloud-hosted environments containing troves of sensitive or proprietary data, which it threatens to leak if the victim doesn’t pay a ransom. 

“Opportunistic data extortionists have been able to identify weaknesses within identity and access management, making these campaigns both cheap and scalable,” said Ian Gray, vice president of cyber threat intelligence at Flashpoint. 

“These attacks are particularly difficult to detect early because they often occur entirely within vendor-hosted environments using valid, socially-engineered credentials,” he added. “Since this activity mimics normal support or data-warehouse tasks, it typically doesn’t trip traditional malware alerts or show anomalies, meaning organizations often remain unaware of the breach until the extortionists make contact.”

Researchers have linked ShinyHunters to multiple attack sprees targeting major cloud platforms, including Oracle, Salesforce and Snowflake. The decentralized crew of cybercriminals was also linked to an expansive compromise last summer impacting hundreds of Salesloft Drift customers that put any platform integrated with the AI chat agent at risk as well. 

In April, ShinyHunters broke into the systems of Canvas — a central hub for K-12 and university coursework, exams, grades and communication — causing widespread outages and data theft. When an early deadline passed without payment, ShinyHunters escalated its pressure on Instructure, the company behind Canvas, by defacing the platform’s login pages with an extortion message that was visible to hundreds of schools.

Instructure ultimately relented and said it reached an agreement with the cybercriminals, insisting the stolen data was returned with assurances that other copies were destroyed.

The FBI issued a public service announcement about ShinyHunters days later, warning potential downstream victims of the threat group’s pressure tactics and claims.

In late July, less than a month before McKesson was hit, Health-ISAC warned organizations in the sector of an increase in successful attacks by ShinyHunters.

The post McKesson copes with fallout from data theft extortion attack appeared first on CyberScoop.

Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos

Two men from Western Australia were arrested and charged Wednesday for their alleged roles in TeamPCP, a notorious cybercrime group responsible for inserting malicious code into widely used open-source software in a campaign that compromised more than 1,000 organizations worldwide.

Australian authorities did not formally name the men, but Australian media identified them as Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23. Police arrested both after searching properties, seizing electronic devices for forensic testing in the process. 

Thomson faces eight charges, including four counts of unauthorized data modification, dealing in criminal proceeds worth $100,000 or more, and refusal to comply with an order to hand over device passwords. Gaebler faces six related counts. 

The Australian Federal Police, which worked with the Western Australia Police Force (WAPF) and the Federal Bureau of Investigation, allege both men were part of a syndicate engaged in “data intrusion, identity crime and cryptocurrency-based money laundering.” Investigators said further arrests have not been ruled out.

“These men are allegedly members of the cybercriminal group TeamPCP, whose malicious code potentially compromised more than a thousand organizations worldwide,” said Brett Leatherman, assistant director of the FBI’s Cyber Division. “We are proud to work with the Australian Federal Police and the Western Australia Police Force to impose cost on criminal actors and combat the growing threat of software supply-chain attacks.”

Months of havoc

TeamPCP has been one of the most active cybercriminal groups in 2026. In late February, TeamPCP exploited a misconfigured workflow in Trivy, Aqua Security’s widely used vulnerability scanner, and stole a service-account token. Aqua replaced its credentials but missed some.

On March 19, the group pushed a malicious Trivy release through every distribution channel at once, placing malware inside thousands of automated build pipelines. Downstream victims included the European Commission and GitHub.

Investigators estimate the campaign exposed more than 500,000 credentials, removed at least 300 gigabytes of data and produced global cleanup costs in the hundreds of millions of dollars.

In May, a piece of self-replicating malware known as “mini Shai-Hulud” targeted prominent software libraries, including TanStack, UiPath, and MistralAI, embedding credential-stealing code into development tools downloaded millions of times a week.

Earlier this month, Oligo Security shared exclusive research with CyberScoop that dated the group’s attacks as far back as 2020. 

Cat photos and GitHub accounts

Alongside the arrests, researchers at the Canadian threat intelligence firm Flare published research that traced Ruben Thomson’s online presence. 

Working from a GitHub alias, DeadCatx3, the researchers found a bug-bounty account under the name Ruben Thomson and a profile listing masscan[.]cloud, a domain that served as command server for mini Shai-Hulud. From there, a password tied to a school email address led researchers to databases of stolen credentials and a trove of accounts: a personal Google account, a TikTok profile under Thomson’s name, and a Steam gaming page showing a cat seated before several monitors. The cat image appeared on a TeamPCP Telegram identity. Flare assessed with high confidence that Thomson ran the group and said it confirmed the findings with law enforcement.

Charlie Eriksen, lead malware researcher at Aikido Security, called the arrests a “relief,” but warned that the actions won’t mean the threat toward open-source software suddenly vanishes.

“The conditions that produced them haven’t gone away, so there will be another TeamPCP,” he told CyberScoop in an email. “We just don’t know their name yet.”

The two men will appear in Australian court Thursday. 

The post Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos appeared first on CyberScoop.

The GTA VI leaks are breaking the internet. Security researchers have seen this before.

Grand Theft Auto VI, widely heralded as the game event of the decade, took a significant hit last week after a cybercriminal sent much of the internet into pandemonium after publishing gameplay footage a week before the game’s publisher planned to reveal core portions of the game to the public.  

The files posted by the online persona “CyberLeek” indicate either a hacker had direct access to Rockstar Games’ most sensitive systems or was given proprietary data by an insider, eventually becoming one of the highest-profile data extortion attacks of the year — a vexing, almost-daily occurrence hitting industries of all types.

While most data extortion attacks rattle companies due to regulatory or privacy concerns, this particular incident has caused an outsized response from Rockstar’s parent company, Take-Two Interactive Software, because it has an audience. While no lives are at risk, as they would be in an attack on critical infrastructure, the financial and reputational stakes are magnified precisely because people are watching every drip of stolen footage become a news story or a trending topic. 

“IP theft — whether it’s conducted by a cybercriminal, an insider, or even potentially [an artificial intelligence] model — rips away the hard work, passion, and livelihood among employees and companies that created the product in the first place,” Cynthia Kaiser, senior vice president of Halycon’s ransomware research center, told CyberScoop.

The game’s prior release, GTA V, along with its online component, has sold over 230 million copies and earned Take-Two over $11 billion since its release in 2013. Industry analysts say GTA VI is on pace to make between $3.3 billion to $5.2 billion in cumulative global sales by the end of its launch week in November. 

“The crown jewels of a company are whatever makes it differentiated and special,” said Kaiser, the former deputy assistant director of the FBI’s cyber division. “For some, that means customer data or source. For a studio in the final stretch before launch, the crown jewel is the surprise.”

While Take-Two hasn’t said anything publicly about the leaks, it has responded feverishly via its legal team. The company petitioned a federal court for subpoenas under the Digital Millennium Copyright Act against Discord, Google, Microsoft and X, seeking the identity of CyberLeeks and other user accounts it accuses of copyright infringement.

Federal judges granted the subpoenas against Discord, Microsoft and X, but the petition against Google remained unapproved as of Monday. Take-Two’s legal representatives also sent copyright notices to the four companies, informing them of the copyrighted material published on their platforms, but it’s unclear if any of the tech companies have been formally served with the signed subpoenas. 

Take-Two and Rockstar did not respond to a request for comment.

The subpoenas may have been enough to spook those responsible for the leaked footage. As of Monday, the websites where those behind CyberLeek were posting leaked information and links to a memecoin were offline.

Zach Edwards, staff threat researcher at Infoblox and a self-proclaimed fan of the series, initially thought the leaks were part of a Rockstar guerrilla marketing campaign. But the company’s response “confirms that this is a real investigation, and the content being shared is likely real to some degree,” he said. 

Take-Two’s actions thus far indicate the company is approaching the breach and leaks like an insider threat investigation, Edwards said. Whoever leaked the footage may have had access to an actual build of the game, he added. That could point to an insider, someone who could have saved a copy to a cloud service, uploaded it to a file-hosting site, or walked out with it on an external drive.

CyberLeek’s conflicting motivations

The hacker or group behind CyberLeek claim they are releasing the gameplay videos to protest Rockstar’s decision to not release physical copies of the game. Yet, watermarks on the leaked videos include addresses to crypto wallets, which indicate CyberLeek is also, and perhaps primarily, seeking a payout. 

“The persona behind the leaks, CyberLeek, published an anti-corporate manifesto targeting digital pre-orders and disc-less releases to frame the breach as hacktivism,” Ben Bernstein, manager of Huntress’ cybersecurity advisors team, told CyberScoop. “Yet behind the political posturing, there’s clear financial monetization and clout-chasing.”

Kaiser draws the same conclusion. “Let’s separate stated motive from observed behavior,” she said. “Threat actors who talk about principle while running a monetization channel are usually only telling you what they think will land with an audience, not actually what is driving them.”

Katie Moussouris said “this is what the alternative vulnerability economy looks like.” The founder and CEO at Luta Security has spent decades building legitimate channels for people who find security problems to get paid without turning to crime.

“The leaker launched a cryptocurrency token, watermarked stolen footage with a buy link, and offered to sell ad space on future leaks. Each of those pays out in proportion to how many people are watching. The manifesto is what keeps them watching,” Moussouris said. 

“That is a genuinely new monetization model for stolen pre-release content, and it means the usual playbook of negotiating a ransom payment quietly or paying to make it stop won’t work,” she added.

Different flavor, same crime

Despite its unique characteristics, the rhythm of the attack and its fallout is familiar territory for cybersecurity experts. 

“Steal, publish a sample, promise more, deliver, repeat. Just like ransomware attacks, in cases like these criminals use every lever of pressure they can against a company — including the fear of what is coming next — to profit from their actions,” Kaiser said. 

“The attackers are crowdsourcing their pressure tactics. A meaningful share of the player base is treating the leaks as free content and amplifying them,” she added.

Kaiser also sees some clear parallels with previous attacks targeting major entertainment companies, including the 2014 attack on Sony Pictures and the HBO hack in 2017. 

“The Sony comparison is useful for how these things escalate, but this incident reminds me more of the Iranian hackers’ leak of ‘Game of Thrones’ episodes a few years back,” she said. “North Korea attacked Sony for political purposes, destroying its data along the way; Iranian threat actors compromised HBO, along with hundreds of universities and over forty other companies, in a hacking-for-hire scheme stealing American intellectual property.”

Federal authorities earlier this month unsealed a second wave of indictments against 17 Iranians affiliated with the tech firm Mabna Institute who allegedly stole troves of data from government agencies and dozens of companies, including HBO.

This isn’t the first time Rockstar has been hit with a security incident. In 2022, an 18-year old British man who was a member of the Lapsus$ cybercriminal gang was sentenced to an indefinite hospital order after leaking gameplay footage. According to the BBC, the incident cost Rockstar, along with ridehauling company Uber and chipmaker Nvidia, over $10 million. 

The subpoena that worries security experts

Security professionals expect the situation to escalate on all sides. Leaks have hit the internet daily for the past eight days, including a series of leaks Tuesday morning. Meanwhile, Take-Two has not relented on its subpoenas. Its broadest move was a subpoena against Discord, seeking identifying data on CyberLeek, two other users and every member of three Discord servers where the copyrighted material was posted.  

Moussouris said the scope of that inquiry should worry people well beyond this case. 

“Take-Two asked for Windows device identifiers, login records, and cloud storage contents for every person who spoke in three Discord servers going back to June,” she said. “The people with the best chance of uncovering the culprits are those doing the unglamorous investigation forensics work of figuring out how the build may have leaked.”

Discord would not say whether it had been formally served or what it has done in response. A company spokesperson said it reviews and complies with valid subpoenas when they are received. 

While the breach and leak of ‘GTA VI’ material is a serious matter, Edwards noted that Take-Two is also benefiting from greater interest in the unreleased game on a daily basis. 

“The threat actor leaking these videos has failed by essentially creating a successful underground marketing campaign for the game while also putting themselves at serious risk of being eventually caught,” he said. 

“This incident is playing out like a classic insider threat exploitation scheme. Someone got access to sensitive data, they had a political agenda which clashed with the owner of the sensitive data, and they decided to do something stupid to try and force a change,” Edwards added. “This attack has done nothing but spread ‘GTA VI’ content further than it would have otherwise, and it’s creating ripples across other industries like cybersecurity who would have never covered ‘GTA 6’ issues previously.”

The post The GTA VI leaks are breaking the internet. Security researchers have seen this before. appeared first on CyberScoop.

Interpol targets Black Axe’s illicit financial web in latest international sting

An international law enforcement operation carried out against organized crime groups in West Africa resulted in 58 arrests and identified 263 suspects, Interpol announced Tuesday.

The operation, known as Operation Jackal IV, aimed to disrupt money laundering, locate high-value targets, seize assets and support prosecutions tied to various Africa-based criminal groups, including Black Axe. 

Black Axe is a highly structured, hierarchical group that generates billions of dollars in criminal proceeds annually from many small-scale operations spanning dozens of countries. The group’s leaders are Nigerian nationals, according to a Europol release issued earlier this year. In January, European law enforcement arrested dozens of the group’s members for adversary-in-the-middle scams such as business email compromise, money laundering and vehicle trafficking. 

“Operation Jackal IV demonstrates the power of international cooperation,” Tomonobu Kaya, director of Interpol’s Financial Crime and Anti-Corruption Centre, said in a release. “By following illicit financial flows across borders, we are attacking the very lifeblood of organized crime and making it increasingly difficult for criminal networks to profit from their activities.”

The agency said it will continue to work to unravel the full details of each case, but detailed several preliminary discoveries from partner organizations Tuesday.

Romanian authorities broke up a group that ran an investment scam from a call center promising high returns in stocks or cryptocurrencies. Victim payments were routed to electronic wallets controlled by the operators, with police estimating the full value at 143 million euros (approximately $166 million). They arrested 11 people and seized about 330,000 euros ($379,000) in cash and cryptocurrency, six properties and several luxury watches.

In South Africa, where 39 of the 58 arrests occurred, police raided seven sites in Johannesburg tied to a syndicate that targeted retirees in English-speaking countries with romance and investment scams. Investigators seized $2.67 million and blocked 257 bank accounts.

Authorities in Argentina identified 196 people linked to a Crime-as-a-Service network suspected of supplying website domains and laundering support to West African groups, making 17 arrests. 

In Italy, one person was identified in connection with a pan-European laundering network built on shell companies, remittance services and cash withdrawals. A single account moved 845,000 euros ($736,000) through 560 transactions.

Investigators also noted the group’s growing focus on sextortion, with victims as young as 14. Similar to actions taken by The Com, Interpol says offenders are contacting teenagers on social media, coercing them into taking explicit images, then demanding payment to keep the material private.

This is not the first time Interpol has taken measures to disrupt African-based groups. In 2024, a similar Interpol operation led to 300 arrests, $3 million in assets seized and 720 blocked bank accounts.

The post Interpol targets Black Axe’s illicit financial web in latest international sting appeared first on CyberScoop.

Apollo discloses data breach from ongoing wave of attacks hitting financial sector

Apollo Global Management confirmed it was among several financial institutions impacted by a string of social engineering attacks that hit the sector last month, the company said Friday. 

Attackers gained unauthorized access to some of the private equity firm’s cloud platforms between July 6 and July 10, the company said in a data breach notification filed in California. Apollo did not say when or how it became aware of the intrusion and did not respond to a request for comment.

Apollo is the first victim to formally disclose that sensitive personal data under its care was compromised by a wave of attacks that have hit large private equity firms, law firms, financial rating agencies and medical technology companies. 

The company did not name the group responsible for the attack. Yet, Google earlier this month attributed the ongoing campaign to BlackFile, a threat group affiliated with The Com, that recently split its extortion operations across four brands with shared infrastructure: Redact, Pink, Helix and Falcon. 

“Upon detecting the incident, we promptly notified law enforcement, engaged leading outside cybersecurity and forensic experts, enhanced our security protocols, and launched an investigation,” Matthew Breitfelder, global head of human capital at Apollo, wrote in the disclosure notice. 

As part of its ongoing investigation, Apollo said it determined on Aug. 12 that personal data including names, dates of birth, contact information, home addresses and Social Security numbers were compromised. The company did not say how many people were impacted, but noted it’s thus far found no evidence any data was posted online or used for identity theft or fraud.

Apollo is one of the world’s largest private equity firms, with $1.05 trillion in assets under its management at the end of June, according to a regulatory filing.

Researchers previously told CyberScoop some of Apollo’s largest competitors, including Blackstone and Bain Capital, were also targeted with malicious infrastructure, but it’s unclear if those firms were compromised.

BlackFile and its various affiliates have impacted organizations in multiple industries, including healthcare, technology, transportation, logistics, wholesale, and retail and hospitality since the beginning of this year.

The extortion group shifts from one sector to the next, impersonating IT support in voice-phishing and social-engineering attacks before threatening its alleged victims with extortion demands, which often start around $3 million and are typically negotiated down to less than $1 million.

Google researchers also previously said some of the group’s recent victims have been subject to threatening messages and other forms of escalation, including swatting incidents, a tactic adopted by several subsets of The Com.

The post Apollo discloses data breach from ongoing wave of attacks hitting financial sector appeared first on CyberScoop.

Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist

An original member of 764 and leader of one of its offshoots was sentenced to 77 years in prison, the longest imprisonment ever imposed on a nihilistic violent extremist, the Justice Department said Wednesday.

Kyle William Spitze pleaded guilty in December 2024 to two counts of producing child sexual abuse material, possession of CSAM and distributing animal crush videos. A federal judge in the U.S. District Court for the Eastern District of Tennessee sentenced Spitze to the maximum punishment for each count and ordered him to serve all terms consecutively.

The 27-year-old of Friendsville, Tenn., victimized dozens of girls and coerced multiple victims under threats of doxing and swatting to produce CSAM of themselves, self-mutilate and produce Spitze’s online moniker in their blood. 

When investigators obtained Spitze’s cell phone under a search warrant in February 2024, they found about 25 photo albums titled with nicknames or first names containing the same images and videos he uploaded to his Telegram channel depicting some of these acts. Officials also found videos of dogs, rabbits and chickens being decapitated by his victims under coercion.

In Spitze’s plea agreement, he admitted he had a terrorist motive in committing his crimes. 

“These types of crimes are the worst of the worst: preying on vulnerable children in the name of a violent and twisted ideology. Federal law enforcement will not stop until nihilistic violent extremist groups and their depraved members are identified and prosecuted to the fullest extent of the law,” Attorney General Todd Blanche said in a statement.

Spitze, also known as “Chrimhn,” “Criminal,” and “Criminaloli,” was also an administrator of the 764 network “Harm Nation.” 

The groups, which are affiliated with The Com, are part of a sprawling network of thousands of people, typically between 11 and 25 years old, seeking to foster social unrest by destroying civilized society through the corruption and exploitation of children and other vulnerable populations.

“Today’s sentence of 77 years, the longest federal sentence ever imposed on a nihilistic violent extremist, sends a strong message that civil society will not tolerate such depravity,” John A. Eisenberg, assistant attorney general for national security, said in a statement Wednesday. 

Allison Nixon, chief research officer at Unit 221B, applauded the long sentence. “I wish other countries could recognize that these people are not the kind that rehabilitate, and adjust sentences accordingly,” she said. 

Spitze’s sentencing follows a period of heightened law enforcement activity, which has netted arrests and lengthy prison terms for multiple alleged 764 leaders and members. 

Alexis Aldair Chavez, who began associating with 764 as a child in 2022 before leading an offshoot 8884, was sentenced to 40 years in prison last month for blackmailing and coercing multiple girls to commit self-harm, torture animals and degrade themselves on camera to produce CSAM. 

Other alleged 764 members arrested since 2025  include: Leonidas Varagiannis and Prasan Nepal, Baron Cain Martin, Tony Christopher Long, Erik Lee Madison, Zachary Sweeney and Aaron Corey.

The FBI said it began investigating Harm Nation in December 2023 after Discord sent the agency a report about the group, including members and victims’ use of the platform. Investigators quickly identified Spitze as one of the most prolific members of Harm Nation and the administrator of an affiliated Telegram channel. 

“Today’s sentencing sends a strong message that this FBI and our Department of Justice partners will relentlessly hold accountable any individual who preys on children,” FBI Director Kash Patel said in a statement. 

“This FBI is laser focused on identifying, locating, and arresting any participants in nihilistic violent extremist (NVE) networks — and we have dedicated personnel across all 50 states working on these high-priority investigations,” Patel added. “We arrested 500% more NVE offenders with our partners last year for a reason — because we have a renewed mission to bring these predators to justice, and that’s exactly what we’ll do.”

The post Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist appeared first on CyberScoop.

Retail theft bill spurs ‘very large and very dangerous’ surveillance fears

A bill to battle organized retail theft has wide bipartisan support and momentum on Capitol Hill, even as opponents say it threatens to dangerously expand surveillance centered in Immigration and Customs Enforcement at a time when the agency’s aggressive conduct is under scrutiny.

Backers counter that critics are wrong about the bill that they say only would enhance existing information sharing arrangements, and could play a role in fighting cyber-enabled crime, too.

At its core, the Combating Organized Retail Crime Act (CORCA) establishes an Organized Retail and Supply Chain Crime Coordination Center within ICE’s Homeland Security Investigations division. It also would create criminal penalties for money laundering proceeds from selling stolen goods, and a $5,000 threshold for the combined total value of stolen property over a year for charging purposes.

It passed the House in June by a vote of 348-60, and Senate supporters are pushing for its inclusion in the annual defense policy bill, considered “must-pass” legislation that Congress has cleared for more than 60 consecutive years.

Opponents are trying to beat back CORCA, which arose from fears of mass theft during the COVID-19 pandemic.

“Its design actually creates a very large and very dangerous surveillance network,” said Nina Patel, senior policy counsel at the justice division of the American Civil Liberties Union. “You would hear the words ‘organized retail crime’ and think that this might be about shoplifting, and you would be surprised to learn that much of the apparatus is concentrated within the Department of Homeland Security.”

The objections

Patel and Jina John, her colleague at the ACLU, said the bill inadequately defines key terms: “organized retail crime,” even, as well as “retailers,” and what kind of data can be shared.

“It’s very broadly and vaguely drafted, and so the way it’s done is that it establishes all these mechanisms for data sharing among these entities, including getting data directly from retailers,” said John, senior policy counsel for AI, privacy and technology. “The data sharing is for any threats related to retail and supply chain crime. That’s it, just: threats. …That’s the biggest concern, is that this is basically giving DHS access to retail surveillance,” she said, like surveillance cameras at malls and train stations, Flock cameras and automated license plate readers.

Rather than the federal government purchasing data from brokers for surveillance purposes — already a contentious practice — CORCA gives them an avenue to get it freely, John said.

A variety of civil liberties and civil rights organizations are among the coalition trying to defeat CORCA. A key issue for many of them is the fusion center at ICE, which has collated data like cell phone location, health and other information, said Spencer Reynolds, senior counsel at the Justice in Public Safety Project at the NAACP Legal Defense and Education Fund. Adding retail data makes that worse, he said. 

“Together, this information allows ICE to hunt down people, find their families and associates, and pull them from their communities,”  he said. “The agency, over the last couple of years, especially, has been openly engaging in racial profiling, and poor Black and Brown people are likely to feel the impact of this the most.”

Reynolds continued: “The entire model that CORCA is going to impose allows government and industry participants to overcome protections, safeguards, guardrails, and use government to target their opposition.”

The support

Backers argue that the bill poses no risk to anyone but organized retail crime leaders.

“Over the years, organized retail crime has evolved into a deadly, multi-jurisdictional threat to American lives, the United States’ economy and our national security,” Senate Judiciary Chairman Chuck Grassley, R-Iowa, said in a statement. “My Combating Organized Retail Crime Act is a targeted, bipartisan bill that would crack down on large-scale retail theft by coordinating federal, state and local law enforcement efforts, while aligning existing resources.” 

A Senate Judiciary Committee spokesperson said the bill doesn’t give DHS any additional enforcement authorities, and is housed within DHS’s Homeland Security Investigations to build on the role they currently have in addressing transnational and organized criminal activity.

The American Trucking Associations supports the bill, and its legislative director Alex Rosen disputed opponents’ claims about its surveillance risks. 

“When you can’t argue the merits of the legislation, it’s easy to revert back to stale, overused buzzwords and an attempt to rile up opposition,” she said. “The idea that this would increase government surveillance is nutty because what this does is it creates within HSI a kind of central reporting repository for industry to report high-level crimes, crimes that are part of big organized criminal theft groups … The idea that this would somehow give the government more authority to surveil Americans is crazy because nowhere in the text does it say that.”

David Johnston, vice president of asset protection and retail operations for the National Retail Federation, noted the difference between ICE’s HSI, focused on a variety of criminal investigations including cybercrime, and its Enforcement and Removal Operations division that’s focused on finding and evicting those who violate U.S. immigration laws.

The bill could be one answer to rising cybercrime, he said.

“There has really been a substantial increase in not only the activity but the methods, the tactics, and as retail has evolved into the digital environment as much as it is in the physical store environment — we’ve seen the criminal, the organization, the structure, the convergence between how cyber and physical thieves operate,” he said, mentioning gift card fraud, or e-commerce fraud that started from a phishing or account takeover. “It’s really become a substantial issue for retailers, consumers, communities across the board.”

Cyber means have also aided cargo theft with the creation of false personas and more, Johnston said: “They’re not going and stealing these trucks with physical violence. They’re driving them right out of the yard, waving to the security officer because they’ve got this whole organization behind them that are using these cybercriminal tactics.”

Where it’s headed

Both sides are optimistic that they’re making progress on the bill. Kristina Roth, the senior policy associate leading the NAACP LDF’s criminal legal system policy portfolio, said a number of lawmakers who actually sponsored the legislation voted against it on the floor.

That points to lawmakers becoming more educated on the bill, which moved swiftly this year from committee to a full vote. “I think the connections that this legislation has through DHS were maybe not well enough described as they could have been,” Roth said.

Patel said there’s more work to be done.

“What is really disturbing about this bill is the way it’s been presented to a number of legislators, and it keeps getting this moniker of being a bipartisan bill,” she said. “But I think few people recognize just how much power is being given to ICE, the complete lack of accountability from DHS and ICE under this administration and in the past, and empowering them to reach into Main Street and into consumer spaces.”

Rosen pointed to the wide House vote as well as bipartisan support from leaders of key committees, such as the Judiciary and the Senate Homeland Security and Government Affairs committees, to include the bill in the annual National Defense Authorization Act. The nature of the support has supporters optimistic about the chances for CORCA to become law.

The defense legislation often wins passage around the end of each calendar year. 

The post Retail theft bill spurs ‘very large and very dangerous’ surveillance fears appeared first on CyberScoop.

The long tail of Clop’s PTC hack is just beginning to emerge

A notorious cybercrime group has once again exploited a critical zero-day vulnerability on a large scale, claiming it stole data from dozens of organizations, including some of the world’s largest publicly traded companies.

Clop, a prolific but calculated data theft extortion group that’s been active since 2020, began sending threatening emails to its alleged victims in mid-July, according to researchers. 

The fallout from the attack spree, which followed a familiar pattern for Clop and its targeted pool of victims, is still evolving as companies hunt for potential signs of compromise.

The vulnerability at the center of Clop’s latest campaign affects a pair of software products from PTC — Windchill and FlexPLM — which manufacturers and retailers, particularly in the manufacturing, aerospace, and automotive industries, use to automate supply chain systems and manage product lifecycles.

“This continues Clop’s trend of targeting SaaS logistics companies’ platforms with zero-days and carrying out mass-exploitation campaigns,” Allan Liska, field chief information security officer at Recorded Future, told CyberScoop.

PTC disclosed the vulnerability — CVE-2026-12569 — on June 17 and issued a patch and initial indicators of compromise the following day. 

Yet, that was too late for some of Clop’s known victims who were likely compromised by exploitation of the zero-day in early June, according to Ransom-ISAC.

The Cybersecurity and Infrastructure Security Agency added the defect, which allows unauthenticated attackers to execute code remotely, to its known exploited vulnerabilities catalog June 25.

PTC consistently added new indicators of compromise as they were discovered by researchers. But the company hasn’t said how it first became aware of the vulnerability and ensuing attacks, when the earliest known instance of exploitation occurred or how many customers are known to be compromised. 

PTC did not respond to a request for comment. 

Clop’s claimed victim set is diverse. The point-of-sale restaurant management platform Toast and software vendor Zebra both told CyberScoop they detected and contained system intrusions, but claimed limited impacts. Other alleged victims, including GE, Philips and Shell, did not respond to requests for comment. 

Researchers continue to uncover new details about the tools Clop used once it exploited and gained access to PTC customer systems. ReliaQuest said the group used a custom web shell that gave attackers a direct path to credential theft and large-scale data theft.

The fully equipped extortion platform, which was purpose-built for Windchill, decrypts credentials, delivers malware, and includes tools for sustained access, network traversal and data encryption, ReliaQuest researchers wrote in a report Tuesday.

The toolkit allows attackers to move quickly from initial access to data theft and additional post-exploitation activity without executing manual commands — a framework that mimics Windchill’s standard functions and limits defenders’ ability to detect any malicious activity.

“This campaign is another reminder that Clop remains a sleeping dragon, always looking and preparing to mass exploit vulnerabilities in software that holds sensitive data,” ReliaQuest researchers wrote in the report. “The group commonly goes inactive between campaigns but springs to life with custom-built web shells whenever there is another opportunity for mass extortion.” 

The drawn-out impact of Clop’s latest attack spree also mirrors some of its previous campaigns. The threat group has successfully exploited zero-days across multiple technology vendors’ systems, allowing it to steal sensitive data for weeks — sometimes months — from many downstream customers.

Clop targeted dozens of Oracle E-Business Suite customers for more than three months, beginning in the summer of 2025, before it started bombarding victims with extortion emails. The group also achieved mass exploitation as it infiltrated MOVEit environments in 2023, ultimately exposing data from more than 2,300 organizations, making it the largest and most significant cyberattack that year.

The post The long tail of Clop’s PTC hack is just beginning to emerge appeared first on CyberScoop.

❌