❌

Reading view

There are new articles available, click to refresh the page.

Russian national extradited to US for alleged involvement in bank-account takeover scheme

Authorities extradited a 36-year-old Russian national from the Republic of Georgia under accusations of widespread bank-account takeover attacks, including a scheme to defraud two banks of more than $6.3 million, the Justice Department said Tuesday.

Sergei Anatolyevich Filimonov and unnamed co-conspirators ran an extensive operation starting in November 2023 to spoof domains of banks, obtain credentials of legitimate customers and use those details to steal money from accounts with large balances, according to court records. 

Filimonov and his co-conspirators allegedly collected more than 5,000 victim login credentials to various banks, including those assigned to employees with access to a company headquartered in Atlanta and another business with offices in Cumming, Ga.

Authorities said Filimonov and his co-conspirators registered and maintained spoofed domains of banks, purchased sponsored links to direct unsuspecting victims to those domains, and stole credentials from those banks’ customers when they attempted to log into the fraudulent sites.

The alleged bank-account takeover crew also created infrastructure to store victim login credentials and tricked victims into providing additional details to bypass security controls.

Prosecutors said Filimonov and his co-conspirators caused and attempted to cause the unauthorized transfer of nearly $5.58 million from one unnamed bank in June 2024 and $735,000 from another bank in November 2024. Both banks have local branches in the Northern District of Georgia and maintain headquarters in North Carolina, according to the indictment. 

Officials previously seized the domain, which the co-conspirators allegedly used to store credentials harvested from the spoofed banking sites in December 2025. The FBI at the time said it identified at least 19 victims in the U.S. linked to the domain and put total attempted losses at about $28 million, including confirmed losses of about $14.6 million. 

Filimonov is charged with conspiracy to commit bank and wire fraud, access device fraud conspiracy, multiple counts of bank and wire fraud, possession of unauthorized access devices and aggravated identity theft. He faces up to 175 years in prison. 

He pleaded not guilty Sept. 4 and remains detained in the Northern District of Georgia.

The post Russian national extradited to US for alleged involvement in bank-account takeover scheme appeared first on CyberScoop.

Apollo discloses data breach from ongoing wave of attacks hitting financial sector

Apollo Global Management confirmed it was among several financial institutions impacted by a string of social engineering attacks that hit the sector last month, the company said Friday. 

Attackers gained unauthorized access to some of the private equity firm’s cloud platforms between July 6 and July 10, the company said in a data breach notification filed in California. Apollo did not say when or how it became aware of the intrusion and did not respond to a request for comment.

Apollo is the first victim to formally disclose that sensitive personal data under its care was compromised by a wave of attacks that have hit large private equity firms, law firms, financial rating agencies and medical technology companies. 

The company did not name the group responsible for the attack. Yet, Google earlier this month attributed the ongoing campaign to BlackFile, a threat group affiliated with The Com, that recently split its extortion operations across four brands with shared infrastructure: Redact, Pink, Helix and Falcon. 

“Upon detecting the incident, we promptly notified law enforcement, engaged leading outside cybersecurity and forensic experts, enhanced our security protocols, and launched an investigation,” Matthew Breitfelder, global head of human capital at Apollo, wrote in the disclosure notice. 

As part of its ongoing investigation, Apollo said it determined on Aug. 12 that personal data including names, dates of birth, contact information, home addresses and Social Security numbers were compromised. The company did not say how many people were impacted, but noted it’s thus far found no evidence any data was posted online or used for identity theft or fraud.

Apollo is one of the world’s largest private equity firms, with $1.05 trillion in assets under its management at the end of June, according to a regulatory filing.

Researchers previously told CyberScoop some of Apollo’s largest competitors, including Blackstone and Bain Capital, were also targeted with malicious infrastructure, but it’s unclear if those firms were compromised.

BlackFile and its various affiliates have impacted organizations in multiple industries, including healthcare, technology, transportation, logistics, wholesale, and retail and hospitality since the beginning of this year.

The extortion group shifts from one sector to the next, impersonating IT support in voice-phishing and social-engineering attacks before threatening its alleged victims with extortion demands, which often start around $3 million and are typically negotiated down to less than $1 million.

Google researchers also previously said some of the group’s recent victims have been subject to threatening messages and other forms of escalation, including swatting incidents, a tactic adopted by several subsets of The Com.

The post Apollo discloses data breach from ongoing wave of attacks hitting financial sector appeared first on CyberScoop.

Details emerge on BlackFile’s recent attacks on financial companies

A cybercrime group responsible for a string of recent attacks against private equity firms, law firms and financial rating agencies remains active and continued to target new victims as of late last week, according to researchers.

BlackFile, which Google Threat Intelligence Group tracks as UNC6671 and associates more broadly with The Com, has been active since the start of the year, shifting its focus from one sector to the next. 

“We have seen continued targeting against the financial sector with additional targeting of other organizations including in the med tech space,” Austin Larsen, principal threat analyst at GTIG, told CyberScoop.

The extortion group impersonates IT support in voice-phishing and social engineering attacks, and recently split its extortion operations across four brands with shared infrastructure: Redact, Pink, Helix and Falcon.

Several organizations received new extortion demands from Redact in the last week, according to Google. 

BlackFile and its various affiliates have impacted organizations in multiple industries, including healthcare, technology, transportation, logistics, wholesale, retail and hospitality.

“BlackFile does go after some of the largest organizations in the sectors that they go for. They’re not going after small companies,” Larsen said. “This is big-game hunting.”

The group’s extortion demands often start around $3 million and payments, including several in the past few weeks, have typically been negotiated down to less than $1 million, according to Google.

Flashpoint researchers told CyberScoop they have observed malicious infrastructure targeting Blackstone, Bain Capital, Moody’s, CME and Apollo, but it’s unclear if any of those firms were compromised. 

BlackFile’s steady pace of activity underscores the persistent threat it poses, as it targets an average of 1.5 new victims daily, researchers said.

Some of the group’s recent victims have been subject to threatening messages and other forms of escalation, including swatting incidents, a tactic adopted by several subsets of The Com, according to Google. 

The attackers use hundreds of callers, often lower-level people that are recruited for a small fee or an opportunity to earn goodwill with the group, who make the voice phishing calls to obtain initial access. Larsen estimates less than a dozen core operators run the different brands under the BlackFile umbrella.

“From the intrusion data that we’re seeing, this does appear to be essentially the same group,” he said, adding that different people may be operating the various brands, but they’re all linked back to the same threat cluster using shared infrastructure.

Mandiant incident responders encounter BlackFile often, having been engaged by more than two dozen organizations successfully compromised by the threat group since January. New victims in the financial sector were calling Mandiant in for help earlier this month.

Voice-based phishing attacks for data theft extortion aren’t sophisticated or novel, but BlackFile and other cybercrime groups consistently prove their continued effectiveness across virtually any sector or organization. “They’re really hitting on the human weakness element here,” Larsen said.

The post Details emerge on BlackFile’s recent attacks on financial companies appeared first on CyberScoop.

Treasury sanctions First VPN Service, others for abetting ransomware gangs

The Treasury Department is slapping sanctions on First VPN and its administrator for allegedly selling services to ransomware operators, as well as another person aiding ransomware gangs.

First VPN Services, or 1VPNS, was “deeply embedded in the cybercriminal ecosystem” and appeared in virtually every Europol investigation in recent years, the law enforcement body said after a sting targeting the service in May.

Treasury’s Office of Foreign Assets Control (OFAC) sanctioned 1VPNS as well as its alleged administrator, Ukrainian citizen Dmytro Rashevskyi, Monday in conjunction with the United Kingdom. The outfit provided anonymity services that could be legitimate in some instances, but 1VPNS advertised itself in online cybercrime forums for more than a decade, touting its refusal to cooperate with law enforcement, the office said.

“Numerous ransomware groups have purchased infrastructure from 1VPNS, which they have leveraged in attacks on U.S. companies and institutions — including to hide the origins of their attacks, deploy malware, and manage exfiltrated data,” OFAC said. “Victims of ransomware attacks that involved the use of 1VPNS infrastructure have included U.S. businesses, financial services companies, hospitals, and municipal governments.”

Treasury also sanctioned Belarus national Yegeniy Vladimirovich Silayev for allegedly selling “cryptors,” tools used to disguise ransomware and other malware, to ransomware operators.

“Unlike legitimate encryption tools, which are designed to protect data and the privacy of the people that own it, cryptors are built specifically to make malware stealthier and more effective by disguising it as harmless files,” OFAC said.

Treasury’s sanctions designations dovetail with separate, unrelated cyber sanctions that European governments from Monday. The FBI has previously issued an alert about First VPN Service. 

Blockchain intelligence firm TRM Labs said it has seen 1VPNS selling its services to ransomware operators for prices ranging from $723 for Anubis to $58 Sinobi.

“The amounts are small because infrastructure subscriptions are small,” Ari Redbord, global head of policy and government affairs for the company, wrote on LinkedIn. “A named ransomware group paying a named enabler on public chains still leaves a trail investigators can follow after the fact.”

Victims tied to First VPN Service infrastructure include U.S. municipalities, hospitals and financial services companies.

Europol said it had arrested the administrator of 1VPNS in its May sting, but did not name them. 

The Treasury Department did not immediately respond to a question about whether its sanctions targeted that same arrested person.

The post Treasury sanctions First VPN Service, others for abetting ransomware gangs appeared first on CyberScoop.

❌