❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

FBI claims fake cop scams are costing victims billions β€”here's what to look out for

  • $1.6 billion has been claimed by scammers impersonating police and government officials
  • The FBI’s Internet Crime Complaint Center (IC3) received almost 61,000 complaints concerning such scams between January 2025 and July 2026
  • Some scams targeted foreign nationals and immigrants, threatening to cancel passports or impose extradition, unless payment is made

Between January 2025 and July 2026, the FBI’s Internet Crime Complaint Center received almost 61,000 complaints concerning scams using police and government official impersonation tactics. As a result, around $1.6 billion is believed to have been scammed and extorted.

Tactics used by scammers included unsolicited phone calls and in some cases video calls, with victims losing an average of $26,000 per scam.

Particularly concerning is the targeting of foreign nationals, international students, and immigrant citizens, often with threats to cancel visas and home country passports. Incredibly, 10% of all losses were traced to a single scam, one that targeted fewer than 3% of the victims.

Foreign national victims

According to the FBI, the fake cop/fake government official scam has various angles, from alleging missed jury duty to threatening arrest due to circumstantial links to an alleged crime.

The demand from the scammers, inevitably, is payment.

Making a commitment to extreme lengths of scamming and extortion, the criminals took things to a new level when it came to targeting victims. International students, visiting foreign nationals, and other immigrant citizens were given special treatment. Not only were they threatened with extradition, there was also the implication of victims losing their home country passport.

To convince the target, scammers built actual studio sets, donned uniforms or suits, and appeared in video calls to the victims, who were convinced they were talking to foreign law enforcement agents or US-based diplomats. Creating the illusion of officialdom to sell the scam, victims paid whatever necessary to stay in their adopted country.

How to spot the scam

It is important to note that not all fraud of this type takes place in the US. These may be online or offline, but the so-called fake cop scam is an international criminal phenomenon. So, how do you avoid it?

We’ll assume you’ve answered a call inadvertently rather than having spam calls blocked (that should be set already).

First, remain calm. These situations are designed to impose stress and heightened anxiety. Scammers rely on these factors to cloud their victim’s judgement and force the narrative they are selling (β€œyou missed jury duty”/β€œyour presence in the country is illegal.”)

Second, it is vital to request credentials. Failure to provide these is the first red flag that the person communicating with you is not what they seem. That’s your cue to end the conversation.

Third, check the credentials. It doesn’t matter how long this takes – a legitimate caller will not mind waiting for you to do the necessary background check, even if it means them calling back.

Finally, and most importantly: neither law enforcement, security services, nor the FBI will demand money. If that is happening, it’s time to end the call.

Mistral denies a fresh security breach, but the code on sale looks a lot like May's leak

  • Seller claims to be offering Mistral AI's full source code and says the company was breached again after May 2026 attack
  • Mistral says an investigation found no evidence of new unauthorized access but has not stated whether the listed code is genuine
  • No customer data has surfaced in analyzed samples, and nobody has shown files created after the May incident

A seller on a cybercrime forum says French giant Mistral AI has been hacked again and is offering what they call the company's full source code for sale.

The September 16 2026 post by an account using the handle "mrwho" consists of a listing titled "Selling mistral.ai Source Code" on an English-language cybercrime forum, according to The CyberSec Guru, pricing the material in Monero only before it attempted to steer potential buyers to Session or Telegram.

Mistral AI's own team has refuted this, stating it has "found no evidence to support this claim."

Not Mistral's first hacking-centric PR problem

Mistral's earlier hacking incident is undisputed - in May 2026, the Mini Shai-Hulud supply chain campaign, attributed to the TeamPCP group, spread from compromised TanStack packages to hundreds of npm and PyPI projects.

Mistral's own security advisory MAI-2026-002 says an automated worm led to compromised versions of its SDKs being published for a few hours on May 11 and 12, and that an affected developer device was involved. Microsoft Threat Intelligence found that a poisoned Mistral AI Python package fetched a second-stage credential stealer that allowed the attack to exploit users.

Mistral went further in statements to reporters than in its advisory. It told BleepingComputer that attackers had compromised a codebase management system and "contaminated some of our SDK packages for a brief period," while insisting that hosted services, managed user data, and research and testing environments were untouched. It also told HackRead that only certain non-core repositories were accessed.

TeamPCP, meanwhile, advertised roughly 450 repositories, about 5GB in total, for $25,000, and threatened to dump them for free if no buyer appeared within a week. One can therefore contend that this could be the same dump being remarketed by a different account, and the seller's profile is already suspect.

The CyberSec Guru noted that the account joined in September 2026 and had four posts and a reputation score of 30, despite displaying a top-tier "GOD User" rank. That profile could fit a scam in the making, but as the outlet pointed out, it could also fit a broker fronting for someone else or a freshly minted alias.

HackRead published 24 sample repository names from TeamPCP's May post. FrenchBreaches, which examined the 339-file tree mrwho shared in September, lists several of the same names. At least four of these appear in both: mistral-inference-private, mistral-inference-internal, mistral-finetune-internal, and mistral-common-internal.

This makes it hard to tell whether the purported 'hack' is just a rehash of an existing dump from Mistral's previous breach or a second successful hacking attempt. There is a straightforward test, however: If the September archives contain commits, files, or credentials dated after May 12, or secrets that were still valid after Mistral's cleanup, the seller's claim of a second breach gains real weight. If everything predates the May incident, this is a resale, which is embarrassing for Mistral but not a new security failure.

Of course, locating the archives or examining them would involve paying the ransom in crypto, as required by what could potentially be a scam in the making- a tremendous leap of faith for an account that was created earlier this month, making this essentially a lottery ticket at best for any security researcher attempting to take a closer look.

More and more workers are feeling stressed at work due to security risks

  • More workers are worried about security issues than they were this time last year
  • Three in four say their recovery tools are too difficult for them to use
  • This report says having strong data storage could help

While many of us typically see security as an IT or a leadership issue, it's actually impacting us more than we'd initially thought. New Object First data found that 91% of workers feel uncomfortably stressed at work because of IT security risks – a seven percentage point increase over last year.

But unfortunately, it's a double-edged sword because it all boils down to AI. Nine in 10 say AI tools have improved their productivity, but seven in 10 say the growth of AI-powered threats is a key driver behind their stress.

Additionally, fewer than one-quarter (24%) believe their organisation is suitably equipped to deal with those threats.

AI-driven security threats are actually impacting you and I

While the risk of cyberattacks (50%) is a leading cause for stress at work, high workloads and understaffing (50%) land in joint-first place. Gaps in backup and recovery effectiveness (41%) and pressure to maintain uptime (44%) are also big headaches for workers, implying pressure isn't coming from direct attacks alone, but workload and operations.

For example, three in four (74%) say that their recovery tools are difficult to use without security expertise, leaving regular knowledge workers at a loss. One in five (19%) even say they feel hopeless and overwhelmed during and after an incident.

Naturally, this stress is impacting productivity, with four in five (78%) remarking that stress negatively affected their job performance. Two in five (39%) even said they'd thought about quitting.

"As critical as technology is to cyber resilience, those responsible for protecting and recovering an organization’s data are just as essential," company CEO David Bennett concluded.

Google logo on a black background next to text reading 'Click to follow TechRadar'

Hackers are hiding malware on blockchains that are nearly impossible to take down, and unrestricted AI models have pushed these attacks up 440%

  • Hackers are using blockchains to keep malware instructions available after servers disappear
  • AI is making blockchain-based malware infrastructure easier for less experienced hackers
  • Blockchain traffic is difficult to block without disrupting legitimate cryptocurrency services worldwide

Hackers are increasingly hiding malware instructions inside public blockchains, creating communication channels that can survive the removal of conventional infrastructure.

New figures from Chainalysis claim malicious blockchain activity increased 440%, with daily entries rising from 2.06 to 11.1 after newer AI systems emerged.

The technique gives attackers another way to maintain communication with compromised computers without relying entirely on conventional servers controlled by hosting providers.

Blockchain networks become malware dead drops

Blockchain dead drops use transaction data or smart contracts as lookup points, allowing infected computers to retrieve commands, addresses, or configuration information.

Because blockchain records are distributed across networks, removing a conventional server does not erase information already stored on the ledger.

A North Korean-linked operation associated with UNC5342 uses TRON and Aptos as alternate routes before retrieving encrypted instructions through the BNB Chain.

Its malware can check one network, switch to another when necessary, and retrieve updated addresses without receiving another malware package.

Iranian actors suspected of links to the country's intelligence ministry have embedded encoded routing information inside Bitcoin transactions used for malware retrieval.

Russian-speaking cybercriminals have also commercialized the technique, using Polygon contracts to provide blockchain-backed infrastructure for malware campaigns operated by different customers.

One related operator controls more than 50 BNB Chain resolver contracts while also conducting activity involving fraudulent tokens and clipboard-monitoring malware.

These operations show how blockchain records can function as persistent lookup infrastructure rather than merely serving their conventional financial and transactional purposes.

AI lowers the technical barrier

Chainalysis said the sharp increase in this malicious activity followed the arrival of high-capacity Chinese open models, which placed fewer restrictions on malware development requests.

Before those systems appeared, building reliable blockchain-based malware infrastructure required expertise across malicious software, cryptocurrency networks, and distributed communication systems.

AI tools can reduce that knowledge barrier by helping less experienced operators understand unfamiliar technologies and produce components needed for blockchain communication.

In the second quarter of 2026, state-linked groups accounted for roughly two-thirds of newly observed activity.

Those groups also represent about half of overall observed activity, indicating that blockchain-based malware infrastructure extends beyond conventional cybercriminal operations.

Defenders face difficulties because blocking blockchain traffic could also disrupt legitimate wallets, decentralized applications, exchanges, and decentralized finance services used worldwide.

Attackers can further complicate disruption by operating their own blockchain nodes, reducing dependence on external providers that defenders might otherwise pressure or disable.

Some operators have hidden server addresses inside wallet identifiers without usable private keys, then used zero-value transfers to trigger malware retrieval.

Those transactions leave public records that investigators can examine, potentially providing useful clues even when attackers attempt to conceal their infrastructure.

"While the exploitation of blockchain by state-linked organizations such as North Korea is becoming more sophisticated, on-chain records left by attackers can actually serve as important clues to track them," said Kwon Jun-hyeok, General Manager of Chainalysis Korea.

"Tracking these traces and identifying attackers and related infrastructure through blockchain intelligence will become increasingly important in responding to new cyber threats."

Google logo on a black background next to text reading 'Click to follow TechRadar'

Microsoft, Google took down $66 million cybercrime marketplace that sold virtual machines with free software

  • So-called signal sharing between Microsoft and Google uncovered the RedVDS marketplace was behind large-scale cyber fraud
  • RedVDS sold access to virtual machines running unlicensed software from which cybercriminals launched scams and directed attacks
  • Threat data was shared securely via the Global Signal Exchange (GSE), a non-profit organization

A major cybercrime marketplace has been taken out of action thanks to cooperation between Microsoft and Google via a secure threat data sharing platform.

Known as the Global Signal Exchange, the collaboration led to the take-down of the RedVDS, an online cybercrime mall supplying virtual machines for launching phishing, business email compromise attacks, and more.

The marketplace – which provided quickly-deleted and therefore virtually untraceable VMs – was meticulously monitored by Microsoft’s security team, Digital Crimes Unit, with both Microsoft and Google suspending the operation and action taken to seize domains and servers.

A secondary case featuring the GSE identified a Microsoft-impersonating tech support scam, resulting, highlighting the importance of secure thread data collaboration platforms.

Digital Crimes Unit

Finding massive scams is not easy. Even with its own Digital Crimes Unit, Microsoft has to rely on information sharing with third party organizations. In this case, the RedVDS marketplace was identified ahead of disruptive action taken by Microsoft in January 2026, which applied to courts in the UK and US to have the RedVDS web domains seized.

Data shared via the GSE enabled Google to follow suit, identifying related accounts on its networks and suspending them. Meanwhile, servers were impounded in Germany, and Europol took action against Europe-based RedVDS servers.

It’s an impressive account of cooperative, decisive action against cybercrime, a collaborative response to what has been described as a β€œ$66 million fraud marketplace.”

An incredible 130,000 organizations were targeted by RedVDS-provided virtual machines between September and December 2025, with 191,000 Microsoft email accounts compromised during this period. All of this access to cybercrime was available from just $24 a month for a basic scam-ready virtual machine.

The importance of collaboration

The Global Signal Exchange is a UK-based non-profit, co-founded with Google in 2025 with the aim of providing real-time monitoring of the cybercrime supply chain.

"Fraud does not respect company boundaries, and no single organization ever sees the whole picture," noted Emily Taylor, CEO at Oxford Information Labs and Co-Founder of the Global Signal Exchange.

"That is exactly why we built GSE: to give trusted partners a secure way to share what they know, quickly. These two cases are a good example of GSE doing exactly what it was designed to do."

The Global Signal Exchange’s role in the sharing of information between Google and Microsoft has highlighted the importance in such collaborations. Both organizations have stated they plan to continue sharing information through the GSE, whose other partners include Meta, Amazon, Google, among many others.

US inherits Venezuelan surveillance state built on banned Chinese tech and AI β€” and it shows no signs of switching

  • A new report has warned that efforts to install Chinese AI within Venezuela's surveillance network could still go ahead
  • The plans were drawn up before former-President NicolΓ‘s Maduro was ousted by the US
  • Report warns there has been no shift in policy, and calls on the US to take action

When the United States decided to oust and capture Venezuelan President NicolΓ‘s Maduro in a daring nighttime operation, the capital of Caracas was turned to complete darkness as the United States Cyber Command allegedly knocked power generation offline.

But this goes beyond giving US troops favorable conditions to infiltrate Maduro's compound. Since coming to power in 2013, Maduro had been building a huge surveillance network to help keep an eye on and - if necessary - quell opposition. A surveillance network that could capture the whole operation on tape.

But as a President at odds with the US, Maduro sourced much of the surveillance tech from China with future plans to integrate banned Chinese AI systems into the network. While Venezuela may have changed allegiances, a new report from the Australian Strategic Policy Institute (ASPI) has warned that the implementation of Chinese AI could still go ahead.

Venezuela looks to integrate Chinese AI into surveillance infrastructure

ASPI’s latest report, titled β€˜Warning signals: Venezuela and the risk of Chinese AI-enabled digital authoritarianism’ [PDF], warns that before the ousting of Maduro, then Vice-President Delcy RodrΓ­guez sought to sign β€œan agreement to adopt Chinese-built AI systems … to use Chinese AI to enhance existing state-sponsored surveillance.”

Following the operation to remove Maduro, RodrΓ­guez was installed as the Venezuelan President just two days after. But since then ASPI warns that there has been nothing to signal a change in direction from RodrΓ­guez’s plans, meaning that the US could be heading a nation filled with Chinese AI-assisted surveillance tech.

β€œVenezuela will become one of the first countries outside China to import China’s new generation of LLM-based AI systems for surveillance and control, and the most advanced adopter in the Western Hemisphere,” the report states.

In the immediate aftermath of the likely fixed 2024 Venezuelan presidential elections, protesters and dissidents were identified online and subsequently monitored using video and drone surveillance. Numerous protest leaders disappeared, likely captured by the authorities for their activities.

Plans to adopt Chinese AI technologies as part of Venezuela’s surveillance network would likely enable the state to continue repressing opposition. β€œChinese or other AI tools could strengthen a domestically directed apparatus already used to manage dissent, restrict information and preserve political power,” the report says.

One of the companies looking to provide its technology for use in Venezuela is iFlytek. The US held iFlytek as a responsible party during China’s attempts to round up and detain the Uyghur Muslim in the Xinjiang region, and banned the sale of the company’s products in the US in 2019.

Moving Venezuela away from China

The ASPI report calls upon US Secretary of State Marco Rubio to spearhead efforts to dismantle the surveillance network and prevent the import of Chinese AI systems into Venezuela’s apparatus.

β€œChina’s leaders appear to understand that assets and investments of its national champions are at risk in Venezuela. Beijing’s approach seems to be, in part, strengthening oversight of state-owned assets abroad to assist in risk protection and management,” the report states.

The report states that dismantling Venezuela’s surveillance infrastructure would align efforts to combat Chinese surveillance tech, and encourage others to dismantle mass-surveillance systems. The dismantling of Venezuela’s surveillance infrastructure would also help position the US’s image as a liberator, rather than just a new face of an old regime.

But the slight irony therein is juxtaposed with the US’s own current surveillance woes, especially in the wake of opposition to Flock camera systems, and AI companies refusing to provide government access to their models for domestic surveillance purposes.

US Treasury wants banks to be better at filing cyber scam reports after noting nearly $13 billion in losses since 2023

  • The US Treasury's FinCEN arm asks financial institutions to file scam center suspicious activity reports under a new keyword
  • FinCEN says that it flagged financial moves across 33,904 different filings, but actual losses might differ significantly, as the approach is prone to double-counting transactions
  • Only 1,300 institutions filed reports, with 10,082 (29.7%) of them centering around exploitation of the elderly by scammers

The US Treasury's Financial Crimes Enforcement Network has issuespublished an alert and a companion data analysis telling banks, credit unions, digital asset exchanges, and securities firms that it needs sharper reporting on the overseas scam centers that it says target Americans at an industrial scale.

FinCEN puts total damages, per its reporting mechanism, at roughly $12.7 billion linked to suspected digital asset investment scams between September 2023 and the end of 2025.

The number comes from adding up the dollar values of 33,904 Bank Secrecy Act filings that referenced the keyword from its 2023 "pig butchering" alert, which may be overstated, as it includes both attempted and successful transactions as well as both inbound and outbound reports, often of the same transactions, causing significant overlap.

FinCEN's new requirement is a keyword

While the $12.7 billion is a measure of what institutions have flagged and is prone to double-counting and errors, victim losses, a significant chunk of which go unreported, may be considerably higher.

This has prompted Gene Lange, who effectively works as the Under Secretary for Terrorism and Financial Intelligence, to call these scams "one of the most significant fraud threats facing Americans today."

It has also prompted a new suspicious activity report keyword: "FIN-2026-SCAMCENTERS," which institutions are expected to use to indicate that a scam center is potentially involved.

FinCEN also wants chat logs, scammer phone numbers, social media handles, wallet addresses, transaction hashes, and the URLs victims were told to deposit into, filed in the structured cyber indicator fields rather than left out.

Institutions to volunteer more information to stop scams

The move is part of its push to have institutions volunteer more information under the US Patriot Act, as it aims to confront what is a growing intelligence problem: scammers tend to route victims through several institutions in sequence; most filers see only one slice of a scam's lifecycle and often have difficulty tracing it all the way.

For example, a crypto exchange might see a customer buying USDT and sending it off-platform, a bank might see a wire to that exchange, and a brokerage might see a retirement account liquidated. None of them would have the bigger picture of what essentially happened or what triggered the transaction.

Combined, with properly linked information, it makes it much easier to identify a potential scam; separately, these incidents can inflate the number of reports, which often aren't linked, and investigations can lack insight into the origin or final destination of the funds.

FinCEN's Rapid Response Program has interdicted $1.8 billion and recovered just over $1 billion for 5,790 US victims since 2015, which, against the flagged totals, is a very limited recovery at best compared with the actual funds at stake. This highlights a larger fundamental problem: institutions mostly detect these schemes after the money is gone, and reporting them correctly and thoroughly may yield limited dividends at best against an industry that has morphed, relatively unchecked, into a multi-billion-dollar juggernaut.

Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet

TrendAIβ„’ Research analyzed an intrusion where threat actors used the EtherHiding technique to route ClearFake payload delivery through smart contracts on the BNB Smart Chain testnet. The attack chain ended with two simultaneously deployed stealers, SectopRAT and ACRStealer alongside an on-chain execution tracker that confirmed each victim compromise in real time.

❌
❌