Tag: fraud
-
KI-gestützte Aufklärung: Warum jeder ein potenzielles Ziel für Betrug sein könnte
Für Cyberkriminelle wird es immer günstiger und einfacher, potenzielle Opfer ausfindig zu machen. Hier erfahren Sie, was Sie noch selbst tun können. First seen on welivesecurity.com Jump to article: www.welivesecurity.com/de/privatsphare/ki-gestutzte-aufklarung-warum-jeder-ein-potenzielles-ziel-fur-betrug-sein-konnte/
-
How TruthScan’s New Technology Stops AI-Enabled Return Fraud
From 2024 to 2025, fraudulent returns cost retailers nearly $200 billion. Some experts believe that the increase in return (or refund) fraud is directly related to AI-generated image models creating fake evidence. Michael Reitblat, CEO and cofounder of Forter, told Wired that AI fraud has increased as “image-generation tools have become widely accessible and incredibly…The…
-
Cryptohack Roundup: Term Finance Hack
Also: Fraud Convictions for Profit Connect and Block Bits Capital. This week, hackers stole $8.5M from Term Finance, BounceBit to shutter blockchain after hack, Profit Connect and Block Bits Capital founders convicted in fraud cases, Roman Storm’s retrial delayed and AI use in crypto-linked crime jumped 40%. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/cryptohack-roundup-term-finance-hack-a-32668
-
Socure Secures $156M, Buys Fravity to Automate Fraud Reviews
Agents Aim to Reduce Deep Fraud Investigations From More Than an Hour to Seconds. Socure raised $156 million from Summit Partners at a $5.2 billion valuation and acquired startup Fravity to deploy AI agents that gather and analyze evidence across fragmented risk systems, potentially cutting fraud investigations from more than an hour to seconds. First…
-
Android Malware Hijacks Update System for Car Head Units
Threat actors behind a notorious click-fraud botnet have set their sights on vehicle infotainment modules and are abusing legitimate functionality to spread infections. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/android-malware-hijacks-update-system-car-head-units
-
Being Right Is the Easy Part
Tags: ai, banking, business, cloud, compliance, container, control, country, crypto, cryptography, data, email, encryption, endpoint, fraud, ibm, intelligence, jobs, strategy, technologyHome Blog <!– PKWARE Blog, "Being Right Is the Easy Part" – STYLES Design tokens + .pk-article class rules. Paste into a Code Block (or move the token layer to the child theme and keep only the .pk-article rules here). tags included. –> Guest Perspective Being Right Is the Easy Part The question I asked…
-
INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown
An eight-month INTERPOL operation targeting West African organized crime groups has led to arrests of 58 people and the identification of 263 suspects.”The operation, which brought together 22 countries from six continents, is a response to the escalating global threat posed by West African criminal networks such as the Black Axe and other similar groups,”…
-
Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams
INTERPOL’s Operation Jackal IV made 58 arrests and exposed global networks laundering money from scams, fraud and sextortion. INTERPOL announced that Operation Jackal IV, running from November 2025 to June 2026, led to 58 arrests and identified 263 suspects tied to West African organized crime networks, groups like Black Axe that are responsible for a…
-
AI-Powered Balonx Sistema PhaaS Harvests Credentials From Over 1,100 Banking Users
Mexico’s financial sector is facing an industrialized phishing Balonx Sistema, a Mexico-focused Phishing-as-a-Service (PhaaS) platform that has harvested credentials and financial data from more than 1,100 banking users since at least October 2025. The service targets over 20 Mexican financial institutions and combines live phishing, Android malware, and AI-driven voice fraud in one subscription-based operation.…
-
Banks Face the Penalty But Scammers Exploit the Gaps
Australian Scam Rules Impose Tough Penalties But Leave Critical Players Unregulated Australia’s new Scams Prevention Framework promises shared responsibility for scam prevention. But gaps in coverage could leave banks exposed and victims asking who ultimately reimburses the for their fraud losses. The rules take effect in March 2027. First seen on govinfosecurity.com Jump to article:…
-
Can You Hear Me Now? Show Me Your Papers
The FCC’s proposed phone-service KYC rules could reduce fraud but also turn mobile numbers into identity-linked credentials with major privacy implications. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/can-you-hear-me-now-show-me-your-papers/
-
Scammers Impersonate Microsoft to Push Fake Security Scans and Refund Fraud
A cluster of fraudulent websites impersonating Microsoft is using fake “security scans” to pressure victims into uninstalling antivirus products, disclosing personal and banking information, and granting remote access to their computers. The sites, branded as SysScan, claim to assess whether an antivirus product is functioning properly. Their conclusion is predetermined: the victim’s computer is allegedly…
-
AnMed Confirms Data Theft, Warns Patients of Criminal Scams
Ransomware Gang Gentlemen Says It Stole 6TB of Sensitive Patient Info. Nonprofit health system AnMed has confirmed cybercriminals stole information in a July cyberattack that disrupted its IT environment and patient services for several weeks. The organization is also warning patients not to fall for potential fraud, payment and other scams by criminals. First seen…
-
Australian Regs Make Scam Victims Prove Lapses by Banks
Fraud Expert Ken Palla on Why It’s So Hard to Show a Bank’s Controls Have Failed. Australia ties scam reimbursement to whether banks, telecoms and digital platforms have met their obligations for anti-fraud controls. Fraud expert Ken Palla says many of the roughly 30 required controls are hard to define, making compliance and victim reimbursement…
-
Australian Regs Make Scam Victims Prove Lapses by Banks
Fraud Expert Ken Palla on Why It’s So Hard to Show a Bank’s Controls Have Failed. Australia ties scam reimbursement to whether banks, telecoms and digital platforms have met their obligations for anti-fraud controls. Fraud expert Ken Palla says many of the roughly 30 required controls are hard to define, making compliance and victim reimbursement…
-
Android car head units infected with proxy botnet malware through built-in software updaters
A newly discovered Android malware, distributed through the built-in updaters in affected Android-based car head units, turns infected devices into ad-fraud tools and nodes in … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/24/android-malware-car-head-unit-badbox/
-
First Android Malware Targeting Car Head Units Uses Firmware Updates to Build Proxy Botnet
A multi-stage Android malware campaign that abuses the firmware-update mechanism of Android-based automotive head units to deploy ad-fraud tooling and enroll vehicles into a residential proxy botnet. The activity, discovered in June 2026, is the first documented malware infection chain purpose-built for automotive head units and has been attributed with high confidence to the MoYu…
-
New malware targets Android car head units for ad fraud and botnet creation
First seen on scworld.com Jump to article: www.scworld.com/brief/new-malware-targets-android-car-head-units-for-ad-fraud-and-botnet-creation
-
Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
Cybersecurity researchers have flagged a new malware family that’s specifically designed to infect Android-based vehicle head unit firmware developed by DoFun.Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet.”The malware spread through the…
-
Deepfake Ads Funnel Investors Into WhatsApp Groups Controlled by Fake Financial Analysts
Investment fraud is increasingly exploiting the one action banks struggle most to block: a payment the customer actively wants to make. Deepfake advertisements, impersonated financial experts, and coordinated WhatsApp groups are now being used to steer retail investors into manipulated stock trades and fake investment platforms. In 2025, investment scams became the largest fraud-loss category…
-
UAT-10147 Compromises Web Servers to Deploy BadIIS for SEO Fraud and Data Theft
Tags: china, cyber, cybercrime, data, data-breach, finance, fraud, government, group, linux, malware, technology, theft, vulnerability, windowsA Chinese-speaking cybercrime group, tracked as UAT-10147, targeting vulnerable Windows and Linux web servers worldwide to deploy BadIIS malware, steal data, and manipulate search engine results for financial gain. Talos observed victims in Brazil, Bolivia, China, Canada, and Vietnam, spanning government, education, media, technology, and gaming organizations. An operational security lapse exposed an attacker download…
-
Peer2Profit Turns Employee Devices Into AstroProxy Nodes That Can Expose Internal Networks
Residential proxy networks have become a key enabler for fraud, credential stuffing, account takeover, spam, and large-scale automated abuse. New research shows that PEER2PROFIT, a bandwidth-sharing application, can turn employee or personal devices into commercial proxy exit nodes that are then monetized through ASTROPROXY potentially exposing corporate IP space and internally reachable resources. The relationship…
-
New Manic Android Malware Targets 169 Apps, Steals PINs and Exfiltrates Data via Wi-Fi Mesh
A newly discovered Android malware family called Manic, which combines banking fraud functions with advanced spyware and remote device control capabilities. The operation’s active infrastructure dates back to February 2026, with early wrappers and implants emerging in late May. Manic has rapidly evolved through July, incorporating stronger anti-analysis protections, in-memory DEX loading, lock-screen phishing, and…
-
Over 50,000 Stripe API keys exposed, highlighting fraud risks
First seen on scworld.com Jump to article: www.scworld.com/brief/over-50000-stripe-api-keys-exposed-highlighting-rapid-fraud-risks
-
Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline
Manic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline. ThreatFabric’s Mobile Threat Intelligence team has identified a new Android malware, dubbed Manic, which has been active in the wild since at least February 2026. The researchers state that the malware is still under development…
-
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications.”Manic sits at the intersection of Android banking malware and mobile spyware, combining financial-fraud First seen on thehackernews.com Jump to…
-
ToxicPanda 2.0 Steals PINs From 140+ Banking and Cryptocurrency Apps Using Invisible Overlays
ToxicPanda 2.0, an evolved Android banking Trojan that significantly expands its fraud, device control, and credential theft capabilities. The updated malware uses invisible overlays to capture PIN input from more than 140 banking and cryptocurrency applications, while its broader phishing framework targets 349 banking, financial, e-wallet, and crypto applications across 16 countries. ToxicPanda was previously…
-
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with “significant enhancements,” including a set of 167 remote commands and expands its targeting footprint globally.Zimperium zLabs, in a Wednesday report, said the Android malware also features a PIN harvesting workflow targeting more than 140 banking and cryptocurrency applications. First…
-
Hackers Create Hidden Microsoft 365 Inbox Rules to Conceal Vendor Payment Fraud
Threat actors are increasingly abusing Microsoft 365 identity sessions rather than deploying malware, as shown in a cloud-only business email compromise (BEC). The attackers used an adversary-in-the-middle (AiTM) phishing kit to capture an authenticated Microsoft 365 session token, bypass multi-factor authentication, and quietly redirect vendor payments to attacker-controlled bank accounts. The lure contained a “View…
-
AI is making fraud harder to spot and identity harder to prove
Online fraud has become a routine concern for consumers and businesses that rely on digital accounts, payments and customer service. Experian’s 2026 U.S. Identity Fraud … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/20/experian-digital-identity-fraud-risks-report/

