❌

Reading view

There are new articles available, click to refresh the page.

Five alleged leaders of Black Axe’s operations in South Africa extradited to US

Five alleged leaders of the South African wing of Black Axe, a global cybercrime group with operations spanning dozens of countries, were extradited to the United States Friday to face multiple charges, the Justice Department said.

Officials accuse the five people, all originally from Nigeria, of running romance scams and advance fee scams from at least 2011 until they were all arrested in South Africa in 2021. The defendants were due Monday for initial court appearances and arraignments in a federal court in Trenton, N.J.

“Black Axe is a notoriously violent transnational criminal organization that also happens to dabble in romance scams to make money,” Stefanie Roddy, special agent in charge of the FBI Newark field office, said in a statement. “The ability of FBI Newark and our partner agencies to reach into South Africa illustrates our resolve to hold accountable any and every type of fraudster who preys on innocent victims here in the United States.”

The accused include Perry Osagiede, founder and leader of the Cape Town Zone of Black Axe; Franklyn Edosa Osagiede, the zone’s “chief ihaza” Osariemen Eric Clement, “assistant eye of the zone,” Collins Owhofasa Otughwor, the zone’s “chief eye,” and Musa Mudashiru, one of the group’s “assistant butchers.”

Prosecutors said the five defendants and their co-conspirators used fake identities to pose as a love interest, relatives, business partners or friends to trick victims into sending them money.

Many of the scams involved claims that the alleged cybercriminals needed money for work travel or to hold them over financially following a series of unfortunate events. This included requests for loans, often involving issues with a construction site, delayed inheritance, or expensive health costs for claimed relatives, according to an unsealed indictment filed in the U.S. District Court of New Jersey in 2021. 

Prosecutors said the co-conspirators also used business entities and gained access to the financial accounts of some victims to conceal the funds illegally obtained from other victims. In some cases, the alleged Black Axe members threatened to distribute sensitive photos of victims when they hesitated to send money, officials added.

The extradition follows a heightened period of law enforcement activity targeting Black Axe in multiple countries. 

Authorities arrested 34 alleged cybercriminals in Spain, including some Black Axe leaders, for adversary-in-the-middle scams such as business email compromise, money laundering and vehicle trafficking in January. 

Officials seized millions in assets, arrested 58 individuals and identified 263 suspects, including members of Black Axe, in a multi-country sting operation in August. 

Black Axe is a highly structured, hierarchical group that generates billions of dollars in criminal proceeds annually from many small-scale operations spanning dozens of countries. 

All five of the extradited individuals are charged with conspiracy to commit wire fraud and money laundering. Perry Osagiede and Franklyn Osagiede are also charged with wire fraud and aggravated identity theft. Officials also charged Clement with wire fraud and Otughwor with aggravated identity theft. The combined charges carry up to 62 years in prison. 

“This case reflects the result of a years-long effort by the U.S. Secret Service and our law enforcement partners to identify, investigate, and bring to justice those who allegedly preyed on victims through sophisticated online fraud and money laundering schemes,” Craig Marech, special agent in charge of the U.S. Secret Service’s Newark field office, said in a statement. 

The Justice Department published additional information about the Cape Town Zone wing of Black Axe, including multiple aliases and business entities used by the group’s members, and encouraged potential victims to contact the FBI.

The post Five alleged leaders of Black Axe’s operations in South Africa extradited to US appeared first on CyberScoop.

Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems

Researchers say they have discovered thousands of malicious software packages uploaded to an online public software repository that were left by a “swarm” of OpenAI agents.

According to an incident timeline published Friday by researchers Spencer Kitts, Thomas Larsen and Sydney Von Arx, the campaign began May 5 when they observed a handful of suspicious packages being uploaded to RubyGems, a public library for the Ruby programming language. By May 11 and 12, the site saw more than 2,000 malicious uploads from the same actors before RubyGems maintainers halted new user sign-ups for four days to stop the flow.

In one instance, the agents attempted to exploit a very recent vulnerability that had only been discovered this past July that would have given them access to RubyGem user API keys. According to Colby Swandale, the technical lead at RubyGems, the flaw involved an improper cache configuration. While initial access logs showed no evidence of malicious key use, Swandale acknowledged the review was limited in scope and inconclusive. 

According to the report published Friday, the agents also used “disposable” email addresses and exploited another bug in RubyGems platform (since patched) that allowed them to register new accounts and gain API keys without verifying their email address.

The researchers said their understanding, based on discussions with “people in the RubyGems community,” is that OpenAI had yet to disclose the involvement of their agents in the May campaign.

An OpenAI spokesperson told CyberScoop that the company is aware of the incident and said they were in contact with both the researchers and RubyGems to conduct a broader review. The company characterized the episode as “benign,” describing it as routine training runs where agents attempt to access publicly available data.

“Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information,” the spokesperson said. “We’ll continue to investigate as part of our broader review of agent activity during training and evaluation.”

In many ways, the agents were not subtle about their identities or goals.

Days into the campaign, researchers noticed that some of the packages had “oai” in their filenames, while fifteen of them had “oai” set as their author and another listed the email “openaixyz65947@gmail.com” as their point of contact.

They also “clearly regarded what they were doing as hacking,” naming some of their files “hack.rb,” “evil.rb,” “inject.rb” and “exploit.rb.” Other packages were given names like “pwnp999,” “exfiltestwand3,” and “hacksvn,” and comments referring to things like a “malicious probe” or “#hack” are present through the files.

They also said the actors’ behavior was extremely similar to another incident revealed earlier this month where OpenAI agents flooded a German wiki  with thousands of hacking-related posts. OpenAI has confirmed their agents were involved in that incident.

The RubyGems campaign used some of the same retrieval methods as the German Wiki agents, while thousands of malicious packages uploaded included a similar snippet, r.jini.ai, that was contained in the German posts.

Cybersecurity company Socket first flagged the campaign in a threat intelligence report posted May 13, but it does not mention or attribute any of the activity to OpenAI or AI agents.

However, the researchers said they had only limited visibility over the model’s actions and how successful some of them were, noting only OpenAI had the full details.

“This analysis is entirely based on the publicly available RubyGems packages uploaded by these agents,” the researchers wrote. “However, we do not have access to the rest of the AI behavior, in particular the chain-of-thought produced by the model during the incident, which is internal to OpenAI. Therefore, we do not know why the AI agents chose this strategy or whether it was successful.”

OpenAI’s spokesperson told CyberScoop that to date, they have not been able to verify the specific claims about malicious packages or exploitation detailed in the report and are continuing to investigate.

The post Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems appeared first on CyberScoop.

Lawmakers call on Commerce to sanction hackers-for-hire

A bipartisan trio of lawmakers is asking the Commerce Department to sanction three India-based mercenary hack-for-hire groups that have reportedly stolen data from thousands of American citizens and companies.

Democratic Sens. Ron Wyden of Oregon and Sheldon Whitehouse of Rhode Island and Rep. Pat Harrigan, R-N.C., sought in a letter to Secretary Howard Lutnick Wednesday to have the mercenary firms added to the Treasury Department’s Entity List, which would limit their access to American software, cybersecurity tools and cloud infrastructure.

“Several India-based cyber-mercenary groups have spent more than fifteen years conducting targeted espionage against U.S. citizens, businesses and the lawyers representing them,” Wyden, Harrigan and Whitehouse wrote. “Compounding this security threat, these cyber mercenaries and their associates have engaged in an aggressive campaign of global lawfare to censor investigative reporting by prominent American media organizations. This coordinated effort effectively allows foreign entities to use foreign courts to keep the American public in the dark about cyber threats to their own country and undermines the fundamental constitutional rights of U.S. citizens.”

The three firms are Sunkissed Organic Farms, BellTroX and CyberRoot. The first of those three was formerly known as Appin and has been the subject of investigative reports and criminal probes. The Citizen Lab at the University of Toronto has delved into the work of BellTroX, and journalists also have reported on the activity of CyberRoot.

“The threat is further heightened by evidence that these groups have operated at the behest of the Qatari government, targeting opponents of Qatar’s World Cup bid and even the family of a former Republican Chairman of the House Permanent Select Committee on Intelligence,” the lawmakers wrote. “While one of these operatives has been indicted by the Department of Justice, the foreign hackers continue to operate with impunity.”

Reuters reported in 2023 that the family member was Kristi Rogers, wife of former House Intelligence Chairman Mike Rogers, now running for Senate as the GOP candidate against one of the midterms’ most important and contested races against Democrat Abdul El-Sayed.

Some of the hacking groups also have sought to censor reporting on their hacking activities, the lawmakers noted.

CyberScoop couldn’t reach the companies for comment. The Commerce Department also didn’t immediately respond to a request for comment, and the government of Qatar didn’t immediately respond to an email seeking comment on the letter. TechCrunch first reported on the letter.

Corrected 9/10/2026: to reflect department to which the lawmakers addressed the letter.

The post Lawmakers call on Commerce to sanction hackers-for-hire appeared first on CyberScoop.

FCC proposes public scorecard to rate telecoms on anti-robocall efforts

The Federal Communications Commission wants to set up a new scorecard system that would allow rate telecoms’ ability to prevent or deter unwanted robocalls.

According to the agency, the scorecard “will empower consumers and encourage providers to continue to combat illegal robocalls by providing the public with an assessment of the effectiveness of voice service providers’ efforts to protect consumers from illegal robocalls,” the FCC said in a Wednesday public notice.

The notice does not prescribe or define technical solutions or systems for the scorecard, instead laying out broad goals for the project. Those include creating a public guide for evaluating how well providers prevent robocalls, and how transparent they are with their metrics.

The agency expressed a desire for more than “a simple administrative checklist,” such as whether the provider offered the right tools or filed the right paperwork, but rather “a composite set of metrics that reflects both operational practices and measurable outcomes, including how often legitimate calls are blocked.”

The scorecard would apply only to domestic voice service providers with retail customers, including wireless, wireline, VoIP providers and hybrid networks, but the agency is seeking comment from the public on whether to focus on larger providers, exclude small or regional networks and other questions around who would be evaluated.

The FCC says it intends to publish the scorecard results, but characterized it as a tool to help consumers understand how effectively voice service providers address robocalls on their networks and “not a rulemaking that will result in new rules or requirements for voice service providers.”

However, the notice does flag a number of federal data systems built around enforcement that the agency said it believes would be “best” for evaluating companies, including Robocall Mitigation Database filings, FCC Consumer Complaints Center data, and FCC enforcement action data, along with third-party or industry sources like Industry Traceback Group data and Federal Trade Commission complaint data.

Peter Hyun, former acting head of enforcement at the FCC, endorsed the general concept behind the idea, likening it to the Department of Transportation’s creation of an airline customer service dashboard in 2024.

That transparency “helped foster adoption of improved practices and a strong focus on better outcomes for consumers,” Hyun told CyberScoop in a text message. “With recent legal and policy fights over FCC enforcement, this is a creative effort to use other tools to combat what is an ever-tormenting issue for consumers: illegal calls.”

FCC officials have emphasized that the most frequent complaints they hear from consumers are around robocalling, and they are seeking to address that demand in a variety of ways.

On the same day the scorecard was unveiled, the FCC announced it had booted 14 telecommunications providers from the Robocall Mitigation Database. The federal system is used by companies to document their compliance with anti-robocalling standards — like STIR/SHAKEN protocols — that FCC officials say are vital to helping them validate legitimate network traffic moving through the U.S. and identify bad actors.

Removing a company from the database effectively cuts it off from connecting to U.S. telecom networks. FCC regulations give other U.S. providers two days to block all traffic coming from violators.

“Today’s action pushes more than a dozen providers off of U.S. networks for failing to abide by our robocall rules,” said FCC Chair Brendan Carr. “The FCC continues to attack the problem of illegal robocalls at every point along the call path, and everyone in this ecosystem has an obligation to step up and do what they can to protect consumers against fraud and scammers.”

According to the FCC, the 14 companies failed to respond to take necessary steps when informed that their database certifications were out of compliance. The list of affected companies includes Apps Communications, CFX Business Solutions, Conference America, Convergence Technology Solutions, CSB Technologies, Digital Division, Dixie Net Communications, HighComm, Inatech Solutions, makrodepot, Opex Communications, ReachME, SECURE, and SkyCom Healthcare.

The post FCC proposes public scorecard to rate telecoms on anti-robocall efforts appeared first on CyberScoop.

A California county wants to hire Tina Peters to help run its elections

Clint Curtis, the registrar for voters in Shasta County, Calif. said he plans to hire convicted felon and election denialist Tina Peters as one of his top deputies.

Curtis said he plans to hire Peters next month as an assistant registrar, according to local news outlets, which cited text exchanges with Curtis.

CyberScoop has reached out to Shasta County’s elections office for comment.

If Peters is hired, it would represent a marriage between a conspiracy-minded election official from another state and an equally distrusting electorate.

Donald Trump won Shasta County approximately two-thirds of voters in the county in all three presidential elections dating back to 2016. Its conservative residents have adopted Trump’s rhetoric that election fraud, voting machine hacks, noncitizen voting and other problems plagued the system, and have turned their anger at local officials.

Cathy Darling Allen, Shasta County’s former registrar of voters, told CyberScoop in 2024 that she retired after decades of administering elections in the county due to persistent attacks and harassment from voters who embraced baseless election fraud conspiracy theories. 

Peters, a former Mesa County, Colo. election official, had been serving a 9-year sentence for seven felonies, including identity theft, breaking into an election office, disabling surveillance cameras, and stealing voting system software.

Peters’ prosecutor, Colorado’s state clemency advisory board, and Mesa County officials have all defended her sentence and described her as entirely unrepentant for her crimes.

Election experts have called Peters’ theft of voting system software one of the most serious breaches of election systems in history. She shared the stolen code with conservative activists, and the code eventually surfaced online.

Governor Jared Polis, a Democrat, commuted Peters’ sentence earlier this year, citing pressure from the Trump administration and arguing that her punishment violated her First Amendment rights. In doing so, Polis intervened before an appeals court could decide whether Peters deserved a reduced sentence.

“She may continue making claims about elections that I believe are false,” Polis wrote in a May Substack post defending the decision. “She may continue promoting ideas that I strongly disagree with. I hope she doesn’t. But in America, people are not sent to prison for expressing political views, however misguided those views may be.”

In response to questions about Peters, Polis’ press office referred CyberScoop to the Colorado Department of Corrections.

Department of Corrections spokesperson Alondra Gonzalez told CyberScoop in an email that as part of her parole conditions, Peters is required to get a job or participate in a full time educational or vocational program and reside in Colorado. Parolees can request to transfer to another state, but those requests would be subject to rules and procedures under the Interstate Compact for Adult Offender Supervision and require approval from both states.
Gonzalez told CyberScoop that the department has not received a request for an interstate transfer from Peters at this time.

The Shasta County board of supervisors formally censured Curtis earlier this month following investigations by the county and outside consultant firm The Oppenheimer Group found he was verbally abusive or physically threatening toward staff.

At an Aug. 11 public meeting, Shasta County Supervisor Matt Plummer cited more than 700 pages of evidence and more than half a dozen eyewitnesses.

The investigations included claims that Curtis at times threatened to “punch,” “slap in the face,” “kill” or “execute” his subordinates. Another claim alleges Curtis once threatened to remove a door where an employee was allegedly hiding from him and have the person pulled out by their hair.

Plummer prefaced his comments by saying the board’s action is “not about election integrity” and that Curtis retains all of his authority to carry out budgeted election administration for the county.

“This is about determining when a department head allegedly and through two investigations, has substantiated allegations of violating personnel codes, the codes that guide how we as a county intend to interact with our employees, what do we do about it?” Plummer said.

Senators Alex Padilla, D-Calif., and Adam Schiff, D-Calif., wrote to California Secretary of State Shirley Weber to express their “grave concern” over the possibility that Peters would have access to state election systems.

“If Shasta County puts Ms. Peters in a position to again violate election laws following her convictions, county taxpayers could be burdened with unwelcomed and potentially hefty expenses,” Padilla and Schiff wrote. “If county officials proceed with this misguided plan, we request that you provide the maximum oversight possible to ensure that Ms. Peters does not improperly access ballots, voting systems, or sensitive information that could impact the rights and privacy of the over 100,000 registered voters in Shasta County in violation of…state or federal election law.”

The post A California county wants to hire Tina Peters to help run its elections appeared first on CyberScoop.

Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams

Senators from both parties Thursday probed Trump administration officials about whether federal agencies and foreign governments are coordinated enough in the battle against scammers, something witnesses told the Foreign Relations Committee they were working to remedy.

At least 13 federal agencies have authorities to counter scams, raising questions about whether someone needs to be in charge of all those efforts. And while there was some bipartisan sentiment at Thursday’s hearing that the Trump administration has taken good actions to battle scammers, both lawmakers and administration officials said that scam operations have demonstrated that cracking down on them in one place often just leads to them going elsewhere.

Sen. Pete Ricketts, R-Neb., compared the situation to an international initiative that gained prominence in the 1990s to counter drug trafficking, Joint Interagency Task Force South.

“Given that today’s scam centers are similarly transnational, combining cybercrime, human trafficking, money laundering and cryptocurrency, has the threat reached the point that we should establish a comparable multinational coordination mechanism?” he asked.

Sen. Jeanne Shaheen, D-N.H., focused on federal coordination: She paraphrased a former federal official who said, “there is nobody that is heading that effort up across agencies. We need to treat this like combat, and so we need somebody in charge.”

Shaheen, the top Democrat on the panel, is a co-sponsor of the bipartisan Scam Compound Accountability and Mobilization (SCAM) Act, which seeks to unify federal efforts on the subject.

A State Department official told Shaeen scammers were a national security priority for President Donald Trump, and that his executive order on the topic sought to tackle coordination.

“I do understand that this is a whole-of-government approach, and many agencies are focused on this,” said David Bedard, deputy assistant secretary at State’s Bureau of International Narcotics and Law Enforcement Affairs “The Action plan that was directed by the president is currently in the interagency review process to deconflict some of the concerns that you have raised. We certainly think the task force that will be implanted through the executive order will solve the problems you might be referencing.”

There’s also an international plan under the task force, he said. Currently, the administration shares intelligence on scammers with foreign allies, and Interpol has “productive” channels to work through there and is setting up its own task force, Bedard said, but there are concerns about other countries taking similar, duplicative action.

There have been signs of progress on the international front, Bedard and another State Department witness told the panel.

Michael DeSombre, assistant secretary at the Bureau of East Asian and Pacific Affairs, said Trump has raised the subject with Chinese President Xi Jinping, and that China has used its influence in Asia as its own citizens have become scam victims. Still, there’s been more progress in countries where the United States has stronger relations, such as Cambodia, than in those where ties aren’t as close, like Burma and Laos.

In Cambodia, one key has been pursuing scam center bosses first and foremost, Bedard said.

The post Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams appeared first on CyberScoop.

Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world

President Donald Trump blamed Minnesota Friday for the cyberattacks its water systems have suffered in recent days, saying the state was “behind it.”

Trump said the state being “incompetent” was the issue, but it wasn’t clear whom he thought actually conducted cyberattacks that U.S. investigators have attributed to Iran — if, perhaps, somehow Minnesota incompetently cyberattacked itself. The White House referred a request for clarification back to Trump’s remarks.

“I think that Minnesota is behind it,” Trump told reporters Friday. “Because they’re grossly incompetent. I don’t think there was an Iranian cyberattack. I think Minnesota ought to get its act together.”

The White House also didn’t clarify whom the president believed was behind similar attacks in other states, when asked for comment. Trump has repeatedly used federal power aggressively in Minnesota, a state led by Gov. Tim Walz, a Democrat who was on the ticket that ran against him in 2024 as the vice presidential nominee. Trump also has downplayed Iranian attacks amid the war he launched against the nation with Israel in February.

A number of cyber experts quickly pushed back on Trump’s comments after he made them.

“Victim blaming in cyber is so 2000 and late,” cybersecurity pioneer Chris Wysopal, Veracode co-founder and chief security evangelist, said on the Bluesky social media platform. Said Jake Williams, a member of the IANS faculty: “His own intelligence services are attributing this to Iran.”

Andy Jabbour — founder and CEO of Gate 15, a cybersecurity firm which provides support to the water sector — told CyberScoop that, “speaking candidly, I’m not even sure what he was actually saying or suggesting Minnesota’s government did or didn’t do.”

“Attribution is tricky business,” he continued, referencing recent alerts from the Cybersecurity and Infrastructure Security Agency and others. “But logically, given an ongoing war with Iran, recent statements made by Iran-aligned threat groups, with assessments that the recent activity is aligned with recent CISA warnings, given yesterday’s statements from CISA and the FBI, random unsubstantiated allegations aimed at political opponents seem reckless and are a disservice to the American people.”

Walz struck back at Trump in a Facebook post, noting steps from his Department of Government Efficiency to slash federal funding. CISA has shrunken considerably under Trump, and his administration has pushed states to defend against cyberattacks that feds once countered.

“Trump knows exactly who is responsible for this attack, and knows that other states were hit too,” Walz said. “This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran.”

“DOGE took an axe to CISA and left the U.S. exposed to cyber attacks,” he continued. “Thankfully, our experts in Minnesota were able to identify the vulnerability quickly and work with local communities to stop it.”

A spokesperson for Minnesota IT Services, a state agency that has been responding to the water cyberattacks, declined to address Trump’s remarks.

“We remain focused on supporting affected communities, securing critical infrastructure and coordinating with local partners and federal officials as the investigation continues,” the spokesperson, Emily Zimmer, told CyberScoop. “We will not comment on political statements or speculate about attribution.”

Other cyber professionals declined to comment directly on Trump’s remarks, but offered thoughts on who was behind the attacks and their motives.

Bryson Bort, CEO and founder of Scythe said the evidence supports the attribution with Iran, and that it looks like hackers there found something they could exploit on the internet and seized the chance.

“This was a target of opportunity,” said Bort, co-founder of the ICS Village, a non-profit advancing awareness of industrial control system security; such systems are common in the water sector. “It wasn’t that Minnesota did something as a state to raise Iran’s ire.”

Cynthia Kaiser, a former top FBI cyber official, said that when the bureau conducts attributions, it looks at technical indicators but also who has the capability, who has conducted similar attacks in the past and what the purpose of the attacks is.

“Iran ticks all these kinds of things,” Kaiser, now senior vice president at cybersecurity firm Halcyon, told CyberScoop. “My view is, if it walks like a duck, if it talks like a duck, I strongly suspect it’s a duck. I’d be shocked if we found out it wasn’t Iran.”

Just last week, CISA updated an advisory about how Iranian hackers were targeting programmable logic controllers in the water sector and other sectors, a warning that the water industry’s information sharing and analysis center said it believed.

“WaterISAC is confident in our government partners’ assessment that the confirmed activity is aligned with the joint Cybersecurity Advisory (CSA) AA26-097A ‘Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across U.S. Critical Infrastructure’ published and recently updated by CISA,” Tom Dobbins, executive director, WaterISAC, told CyberScoop. “We have evidence of earlier attacks from Iran even before this current conflict. Cyber attacks are the most viable way that Iran can directly attack our homeland, and it is logical that they would do so, especially given the challenges of absolute attribution.”

The water sector is often viewed as one of the most vulnerable critical infrastructure sectors, and Dobbins called on Congress to provide funding to provide funding for the ISAC.

Sen. Tina Smith, D-Minn., also took issue with Trump’s comments.

“The President provided an unserious response that is beneath the dignity of the office he holds. Iran’s purported cyberattack on Minnesota’s water infrastructure must be taken as a serious threat to our national security.  Smith said in a statement, adding that she’s been in touch with CISA and the FBI and was grateful to Minnesota’s IT experts. “The entire situation serves as a stark reminder of the danger this war puts us in the longer it drags on.”

Fellow Minnesota Democratic Sen. Amy Klobuchar had earlier been in touch with Sean Cairncross, the national cyber director and a Minnesota native, about the incident.

Trump has previously displayed a laissez-faire view toward other cyberattacks on the United States, such as when he’s been asked about Chinese and Russian cyberattacks and Trump shrugs them off as something America does, too.

He also has cast doubt before on his government officials’ assessments of who’s responsible for cyberattacks on the United States, such as when he asserted China rather than Russia was behind the landmark SolarWinds breach.

Updated 8/3/2026: with comments from Minnesota’s senators.

The post Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world appeared first on CyberScoop.

Ghanaian national sentenced to 7 years in prison for stealing $10M from romance scam victims

A 41-year-old Ghanaian national was sentenced to 85 months in prison for stealing more than $10 million from mostly older, lonely and vulnerable victims via romance scams, the Justice Department said Tuesday. 

Derrick Van Yeboah was a longtime and high-ranking member of a criminal organization primarily based in Ghana linked to more than $100 million stolen from romance scams and business email compromises, officials said. Van Yeboah served as a “sakawa boy,” impersonating fake romantic partners and directly interacting with victims online from February 2015 to October 2024.

“Romance scammers do not simply steal money — they weaponize trust,” Jay Clayton, U.S. attorney for the Southern District of New York, said in a statement. 

Van Yeboah was arrested in Ghana in June 2025, acting on a request from the Justice Department, and extradited to the United States two months later. He pleaded guilty to conspiracy to commit wire fraud and agreed to forfeit $10.15 million in fraudulent proceeds as part of a plea agreement in March.

Authorities said they identified at least 20 of Van Yeboah’s victims, noting that some were deceived into sending their money to the criminal organization, creating companies and using those entities to unwittingly launder funds from other victims. 

Victims include a woman from Delaware who either sent or laundered $1.9 million, a woman from Ohio who sent or laundered $2.3 million and another woman who sent or laundered about $1 million. Van Yeboah also tricked a North Carolina man to send $123,000, claiming he needed a loan to pay for his mother’s funeral expenses and to remove imaginary gold and diamonds from storage in Italy, according to court records.

Officials said Van Yeboah received a substantial amount of money from his criminal acts. He told pretrial services his assets include a house worth $1.5 million and jewelry worth $515,000. When he was arrested, Ghanaian police found him in possession of two vehicles stolen from the United States and Canada.

“Victims lost large portions of their life savings, money they had counted on for retirement. They were emotionally devastated to learn that the personas they had been talking to every day, personas who claimed to be in love with them, were in fact frauds,” Clayton wrote in a pre-sentencing letter to the court. 

Van Yeboah’s conduct was cruel, and he fully understood the financial and emotional harm he was causing to his victims, he added. 

“Van Yeboah’s conduct was far from an aberration. Van Yeboah engaged in the fraud scheme for nine years. It wasn’t isolated conduct; it wasn’t a blip,” Clayton wrote. “Indeed, it appears to be the only real job Van Yeboah has ever had. Day after day, for years, he targeted vulnerable victims, lied to them, and stole from them.”

The post Ghanaian national sentenced to 7 years in prison for stealing $10M from romance scam victims appeared first on CyberScoop.

Rubio restricts visas for sextortionists, cyber scammers

The State Department will restrict visas for cybercriminals like scammers to sextortionists, and in some cases even their family members, Secretary of State Marco Rubio said Thursday.

The Trump administration has sought to make a crackdown on foreign-based scams one of the signature issues of his second term. An executive order that the president signed in March indicated that visa restrictions would be on the table as one response.

“By restricting visa issuance to those who are responsible for or complicit in these criminal enterprises, we are sending a clear message: The United States will go after those who prey on our citizens,” Rubio said.

Other departments have also made efforts to reduce foreign-run scams. In June, the Department of Justice seized infrastructure used by subsidiaries of the Huione Group, a Cambodia-based corporate conglomerate tied to one of the world’s most prolific criminal marketplaces used to commit cyber scams and other crimes.

Rubio authorized the visa restrictions under a 1952 law that gives the State Department the ability to deport or rule as inadmissible someone who poses “potentially serious adverse foreign policy consequences.”

Critics have accused the Trump administration of abusing that provision of the law for political purposes.

Rubio’s statement on the visa restrictions mentions “individuals responsible for, or complicit in, cybercrime and cyber-enabled crime, such as those involved in cyberscams, and sextortion.”  Furthermore, he said, “Immediate family members of individuals engaged in such illicit activities may also be subjected to visa restrictions.”

Betsy Cooper, Founding Director of the Aspen Policy Academy, said the visa restrictions on cybercriminals could be valuable, but offered a caveat.

“Scamming people is a growing global enterprise, and it is a laudable goal to penalize those who scam and defraud people since they so rarely suffer consequences for their actions,” she said in a statement to CyberScoop. “So long as the new visa controls are used narrowly and deployed only against verified scammers and fraudsters, this is a positive step toward combatting cyber-enabled crime.”

While some cyber experts have questioned how much visa restrictions, prosecutions and other punishments of cyber miscreants who are based overseas will affect them, others maintain that it can serve as a deterrent to those who would consider getting into the line of work but want freedom to travel the globe.

FightCyberCrime.org, a nonprofit that seeks to help cybercrime victims, applauded the restrictions on the cybercriminals.

“We welcome efforts to hold cybercriminals accountable across borders. Cryptocurrency investment scams, romance scams, and sextortion cause devastating financial and emotional harm to victims,” it said in a statement to CyberScoop. “Meaningful disruption of these transnational criminal networks is an essential part of the response.”

But there’s still a long way to go in the fight, the statement continued.

“At the same time, we must invest more in victim support, prevention, and recovery resources,” the organization said. “Accountability is critical, but ensuring victims have access to trauma-informed support and resources is equally important.”

The post Rubio restricts visas for sextortionists, cyber scammers appeared first on CyberScoop.

Interpol cybercrime crackdown nets 5,800 arrests across 97 countries

Authorities arrested more than 5,800 alleged cybercriminals and seized $293 million in a global operation targeting social-engineering scams and money laundering across 97 countries, Interpol said Thursday.

The anti-fraud crackdown, dubbed Operation First Light, identified more than 142,000 victims, including people, businesses and governments, officials said. 

“Social engineering scams continue to pose a significant threat to our society. Criminal syndicates exploit human psychology to manipulate their targets, and no nation can stay safe unless all countries are equipped and committed to jointly fighting back,” Tomonobu Kaya, director of Interpol’s Financial Crime and Anti-Corruption Centre, said in a statement.

Police identified more than 15,500 cybercrime suspects during the operation, which spanned more than three months ending in late April, according to Interpol. Officials also analyzed more than 152,800 cases of cybercrime, including business email compromise, sextortion, romance scams, impersonation and investment schemes. 

Interpol said nearly 24,000 cases of cybercrime were solved and investigators blocked more than 31,000 bank accounts linked to malicious activity during the crackdown.

Authorities involved in the globally coordinated operation seized a high volume of devices and other equipment used to allegedly facilitate cybercrime. 

In Eswatini, police seized a replica of a Brazilian police station, including fake uniforms, signage and equipment that cybercriminals allegedly used to deceive targets into thinking they were victims of a crime, duping them into transferring funds.

While uncovering a romance scam money laundering operation in Thailand, investigators identified a 20-year-old suspect that allegedly processed more than $122.5 million in 10 months, according to Interpol. Officials in Palau identified and deported 22 people allegedly involved in a pair of scam centers operating from hotels.

“Interpol is dedicated to supporting member countries in building a comprehensive, coordinated strategy to tackle cyber-enabled financial crimes, organized criminal networks and the money laundering that fuels them,” Kaya said.

The post Interpol cybercrime crackdown nets 5,800 arrests across 97 countries appeared first on CyberScoop.

❌