<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/cyber-crime" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Cyber-crime ]]></title>
                <link>https://www.itpro.com/security/cyber-crime</link>
        <description><![CDATA[ All the latest cyber-crime content from the ITPro team ]]></description>
                                    <lastBuildDate>Fri, 17 Jul 2026 15:30:13 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Cisco sounds alarm over new Russian malware campaign hitting firms in US and Europe ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/cisco-sounds-alarm-over-new-russian-malware-campaign-hitting-firms-in-us-and-europe</link>
                                                                            <description>
                            <![CDATA[ UAT-11795 is weaponizing legitimate software such as WebEx and Zoom to dupe victims ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5yiyuVZQcY8DoSF3hGWu2C</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 15:30:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:description>                                                            <media:text><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cisco Talos has uncovered a new Russian-speaking threat actor aggressively targeting victims across the United States and Europe. </p><p><a href="https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/" target="_blank"><u>Tracked as UAT-11795</u></a>, the group has been active since June last year, and uses trojanized installers for <a href="https://www.itpro.com/security/malware-free-attacks-surged-in-2024-as-attackers-drop-malicious-software-for-legitimate-tools">legitimate software</a> such as MobaXterm, WebEx, Zoom, DBeaver, and FaceIT to steal credentials and cryptocurrency.</p><p>A staple of the threat actor’s activities lies in deployment of two previously undocumented tools: Starland RAT and WLDR agent. The first of these is a Python-based remote access tool, while WLDR agent is a PowerShell-based C2 memory implant. </p><p>WLDR agent runs entirely in-memory, and features encrypted beaconing, task queuing, and a Runspace execution engine for executing additional payloads. </p><p>Both are built to steal credentials, browser data, and cryptocurrency wallet assets while keeping persistent access to victim machines. The group even hides a fallback command-and-control channel in a Polygon smart contract, Cisco Talos said.</p><p>UAT-11795 targets victims' credentials and cryptocurrency wallet assets, establishing a persistent connection to the victims' machines from the C2 server, with the potential to deliver and execute further payloads. </p><h2 id="how-uat-11795-operates">How UAT-11795 operates</h2><p>Most infections have been spotted in the US, according to Cisco Talos, although Germany, Romania, and Venezuela have also been hit.</p><p>UAT-11795 gains initial access to the victim machine through a ClickFix social engineering technique that entices the user to execute a command, which then stealthily downloads and executes a remotely hosted weaponized HTA file. </p><p>This runs an embedded VBScript that drops a Windows batch file into the user profile’s application temporary folder, containing instructions to first download and implant a trojanized installer from the attacker-controlled staging domain onto the victim machine. </p><p>Muhammad Yahya Patel, CISO and cybersecurity advisor at Huntress, said the campaign is the latest in a string of attacks by hackers using “the very tools our remote and <a href="https://www.itpro.com/business/business-strategy/hybrid-workers-aren-t-disconnected-from-office-colleagues-they-re-happier-more-productive-and-have-better-workplace-relationships">hybrid workers</a> rely on”. </p><p>"By hiding the Starland RAT inside trusted software and likely utilising deceptive <a href="https://www.itpro.com/security/clickfix-social-engineering-state-sponsored-hackers">ClickFix social engineering tactics</a>, these threat actors are completely bypassing traditional perimeter defenses to exploit human psychology rather than software vulnerabilities."</p><p>Talos’ research also uncovered a private live Telegram channel called “stuk komanda”, controlled by the same threat actor, created last June, and with three unknown subscribers.</p><h2 id="exercise-caution-when-using-video-conferencing-tools">Exercise caution when using video conferencing tools</h2><p>Gabrielle Hempel, security operations strategist at Exabeam, said while the campaign specifically targets popular video conferencing software, one needn't avoid using Zoom or WebEx. </p><p>They should, however, exercise caution. This includes making efforts to verify where software comes from, monitor for unexpected processes and persistence mechanisms. </p><p>Elsewhere, Hempel said users shouldn't assume that 'signed installer' means a program is safe.</p><p>"This story is so interesting, not because of the trojans, but because of the way it shifts how we need to think about vulnerability management," she said.</p><p>"We often measure a program’s security maturity by patch SLAs, but we’re seeing so many successful intrusions starting with users executing software they believe is legitimate and not just unpatched systems. If your security program can’t answer 'where did this binary come from?' as quickly as it can answer 'is this CVE patched?' then you are behind on your threat model." </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Working with the enemy: Ransomware negotiator-turned cyber criminal jailed after working with hackers to extort clients ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/working-with-the-enemy-ransomware-negotiator-turned-cyber-criminal-jailed-after-working-with-hackers-to-extort-clients</link>
                                                                            <description>
                            <![CDATA[ Angelo Martino was supposed to be negotiating on behalf of victims, but was secretly working for ransomware operators ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rEKtR8rJ65bFgXThPcm6mh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UjWjTqk5HiFp2xWB4yo93k-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Jul 2026 09:46:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UjWjTqk5HiFp2xWB4yo93k-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Insider threat hacker concept image showing man typing on keyboard in a dimly lit room. ]]></media:description>                                                            <media:text><![CDATA[Insider threat hacker concept image showing man typing on keyboard in a dimly lit room. ]]></media:text>
                                <media:title type="plain"><![CDATA[Insider threat hacker concept image showing man typing on keyboard in a dimly lit room. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UjWjTqk5HiFp2xWB4yo93k-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>negotiator has been sentenced to 70 months in prison after secretly conspiring with hackers to extort clients. </p><p>Angelo Martino, 41, of Land O’Lakes, Florida, worked at US-based cyber incident response company DigitalMint in April 2023 when he started conspiring with the operators of the BlackCat ransomware group. </p><p>BlackCat paid Martino to provide confidential information about the negotiating position and strategy of his employer’s clients, along with the details of their ransomware insurance, to help maximize the ransoms paid. </p><p>Notably, Martino also <a href="https://www.itpro.com/business/when-cyber-professionals-go-rogue-a-former-ransomware-negotiator-has-been-charged-amid-claims-they-attacked-and-extorted-businesses">conspired with two former cybersecurity professionals</a> between April 2023 and November 2023.</p><p>Kevin Martin, 36, of Texas, was hired as Martino’s co-worker at DigitalMint after the conspiracy began. Ryan Goldberg, 41, of Georgia, was manager of incident response at Sygnia. </p><p>All told, Martino was found to have extorted five different victims as part of his collaboration with the cyber crime syndicate while the trio also worked to deploy BlackCat ransomware against victims across the country. </p><p>Assistant attorney general A. Tysen Duva of the Justice Department’s Criminal Division, said victims had shared “heartbreaking accounts of how their businesses were nearly destroyed” during the trail. </p><p>“Today’s sentence accounts for the harm Martino caused and demonstrates that the Department of Justice can and will identify and prosecute cybercriminals to the fullest extent of the law.”</p><h2 id="working-with-the-enemy">Working with the enemy</h2><p>After successfully extorting one victim for around $1.2 million in Bitcoin, the men split their share of the ransom three ways and laundered the funds through various means. </p><p>Jason A. Reding Quiñones, attorney for the Southern District of Florida, said more than $10 million in criminal proceeds have been seized. These assets include digital currency, vehicles, a food truck, and a luxury fishing boat. </p><p>A separate hearing has been set for September 17 to decide the amount of restitution to be ordered against Martino. </p><p>The Justice Department started <a href="https://www.itpro.com/security/ransomware/alphv-leak-site-seized-by-law-enforcement-as-decryption-tool-released"><u>working to bring down BlackCat</u></a> three years ago, developing a decryption tool that allowed FBI field offices across the US and law enforcement partners around the world to help victims restore their systems. </p><p>The scheme has reportedly saved victims from paying out $99 million in ransom payments so far. The FBI also seized several BlackCat websites at the same time.</p><p>"This case sends a clear message: we will pursue the hackers who deploy ransomware, the insiders who enable them, and the money they steal from American victims,” Quiñones said. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘The risk to every organization has increased exponentially’: The FortiBleed campaign just took a turn for the worse ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/the-risk-to-every-organization-has-increased-exponentially-the-fortibleed-campaign-just-took-a-turn-for-the-worse</link>
                                                                            <description>
                            <![CDATA[ Reports suggest that FortiBleed-linked exposed credentials could put UK government and public services at huge risk ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">npiBchLKa4eriPG8MdEo5T</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bR33DDYEFNw8FhDqg6p8y5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Jul 2026 08:09:22 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bR33DDYEFNw8FhDqg6p8y5-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Plaque pictured at the Foreign, Commonwealth and Development Office building in Whitehall, London. ]]></media:description>                                                            <media:text><![CDATA[Plaque pictured at the Foreign, Commonwealth and Development Office building in Whitehall, London. ]]></media:text>
                                <media:title type="plain"><![CDATA[Plaque pictured at the Foreign, Commonwealth and Development Office building in Whitehall, London. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bR33DDYEFNw8FhDqg6p8y5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/28133/what-is-cyber-security">Cybersecurity </a>experts have issued an alert amid reports that hackers accessed login credentials belonging to UK government officials and Foreign Office staff. </p><p>The credentials, which are reportedly being sold on the dark web, were exposed as part of the ongoing FortiBleed attack campaign. </p><p>FortiBleed targets internet-facing Fortinet <a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/368103/best-business-vpn-in-2022">VPN </a>and <a href="https://www.itpro.com/security/firewalls">firewalls</a>, and is believed to have affected more than 70,000 devices spanning 194 countries since it was first uncovered last month. </p><p><a href="https://socradar.io/blog/fortibleed-fortinet-firewalls-compromised/" target="_blank"><u>Analysis from SOCRadar</u></a>, for example, identified a vast database containing login credentials. The threat intelligence firm has since attributed FortiBleed to the Lynx/<a href="https://www.itpro.com/security/ransomware/ransomware-group-publishes-stolen-nhs-scotland-data-to-dark-web">INC ransomware</a> group.</p><p>While this database was believed to have been limited to basic usernames and passwords, reports from <a href="https://www.telegraph.co.uk/news/2026/07/05/russian-hackers-steal-government-logins/" target="_blank"><u><em>The Telegraph</em></u></a><em> </em>suggest some exposed details include privileged Fortinet credentials. </p><p>Volodymyr Diachenko, a security researcher who first uncovered the threat campaign, told the publication these credentials could give bad actors access to the Foreign Office’s “core networks” along with other government departments.</p><p>Some Foreign Office credentials are now being sold on the <a href="https://www.itpro.com/security/32117/what-is-the-dark-web">dark web</a>, according to reports, going for up to £40,000. </p><p>Arctic Wolf CISO Adam Marrè warned that the incident could create a domino effect, impacting other government departments and also local authorities and public services. </p><p>According to <em>The Telegraph</em>, credentials at NHS trusts, energy companies, and local councils were also hosted in the illicit database. </p><p>“This major breach of email accounts of UK government officials and overseas Foreign Office workers is the latest development in the ongoing FortiBleed attack,” he said. </p><p>“While it may be tempting to think this is a simple <a href="https://www.itpro.com/security/theres-only-one-way-to-avoid-credential-stuffing-attacks">credential-stuffing</a> operation, our threat team found the threat actors have built a highly sophisticated and repeatable credential factory,” he said. </p><p>Marrè noted that analysis of the incident conducted by Arctic Wolf shows threat actors appear to have been using automated tools to harvest logins and target gateways at “exponential speed and volume”. </p><p>“This means while today it’s the Foreign Office which has been affected, the risk to every organization has increased exponentially.”</p><h2 id="back-and-forth-on-fortibleed">Back and forth on FortiBleed</h2><p>The discovery of the FortiBleed sparked somewhat of a back and forth between Fortinet and security researchers last month. After threat intelligence firm Hudson Rock published a <a href="https://www.hudsonrock.com/fortinet" target="_blank">blog detailing the campaign</a>, Fortinet disputed some of its claims. </p><p><a href="https://www.itpro.com/security/passwords-nicked-for-nearly-74-000-fortinet-devices"><u>Fortinet told </u><u><em>ITPro </em></u><u>at the time</u></a> that the exposed credentials weren’t the result of a fresh breach, insisting that those following best practices were safe from exposure.</p><p>"Fortinet is aware of a reported third-party credential-harvesting campaign targeting Fortinet firewalls and VPN gateways. We are committed to safeguarding our customers, and we diligently and continuously monitor threat actor darknet activity,” a spokesperson for the company said. </p><p>“Based on our initial analysis, the data involved is likely a resharing of data from previous incidents, as well as brute forcing of credentials, and not related to any current incident or advisory."</p><p>Hudson Rock, meanwhile, said the campaign went “beyond simply credential reuse,” highlighting that hundreds of organizations are thought to have been affected. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Alleged Scattered Spider hacker snared in Finland, extradited to US ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/alleged-scattered-spider-hacker-snared-in-finland-extradited-to-us</link>
                                                                            <description>
                            <![CDATA[ Teenager Peter Stokes has been extradited to the US on hacking charges ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pJG3tDAZcpJWzPuioJKoNQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EC3BuBnLtE6s8TqRFjZodG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 02 Jul 2026 09:37:19 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EC3BuBnLtE6s8TqRFjZodG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A CGI render of a circuitboard lined with red lines in the shape of a spider, representing the Scattered Spider threat group.]]></media:description>                                                            <media:text><![CDATA[A CGI render of a circuitboard lined with red lines in the shape of a spider, representing the Scattered Spider threat group.]]></media:text>
                                <media:title type="plain"><![CDATA[A CGI render of a circuitboard lined with red lines in the shape of a spider, representing the Scattered Spider threat group.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EC3BuBnLtE6s8TqRFjZodG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A teenager believed to be part of the <a href="https://www.itpro.com/security/cyber-attacks/scattered-spider-airline-industry-attacks">Scattered Spider hacking group</a> has been extradited from Finland to the United States. </p><p>Peter Stokes, 19, is the latest alleged member of the group to be nabbed by the FBI as part of Operation Riptide, an ongoing campaign targeting the criminals, infrastructure, and financial networks behind cyber crime.</p><p>Stokes, a dual citizen of the United States and Estonia, has been charged with conspiracy, computer intrusion, and fraud. He was arrested by Finnish authorities in April following an Interpol Red Notice, and extradited to the US last week. He made an initial appearance on Tuesday in federal court in Chicago.</p><p>“The criminal complaint charges Peter Stokes with membership in Scattered Spider, a hacking group that has been involved in over 100 network intrusions, resulting in more than $100 million in <a href="https://www.itpro.com/business/business-strategy/ransomware-victims-are-refusing-to-play-ball-with-hackers-just-17-percent-of-enterprises-have-paid-up-so-far-in-2025-marking-an-all-time-low">ransom payments</a> and millions more in damages to the victims,” said assistant attorney general A. Tysen Duva of the Justice Department’s Criminal Division. </p><p>“The charges unsealed today are the result of years of work by the Criminal Division, the US Attorney’s Office for the Northern District of Illinois, and the FBI. We will continue to partner to ensure that cybercriminals cannot evade the reach of the United States.”</p><p>According to the complaint, Stokes and his fellow criminals breached a luxury jewellery retailer’s computer system, exfiltrated data, and made a ransom demand of around $8 million in cryptocurrency in May last year. </p><p>The firm managed to successfully evict the hackers from its computer network and no ransom was paid. However, it suffered a loss of at least $2 million due to business disruption, investigation, and threat mitigation.</p><h2 id="the-walls-are-closing-in-on-scattered-spider">The walls are closing in on Scattered Spider</h2><p>The Scattered Spider group has been linked to more than 100 network intrusions, resulting in over $100 million in ransom payments and millions of dollars in damages to the victims. </p><p>The group targets companies across the US with social engineering and SIM swap attacks, encrypting data or exfiltrating it to remote servers. It then extorts <a href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining">cryptocurrency </a>from the companies in return for the return of their data or to prevent it being disseminated.</p><p>Scattered Spider has rapidly grown to become one of the most notorious threat groups worldwide, having claimed responsibility for <a href="https://www.itpro.com/security/cyber-attacks/m-and-s-reveals-massive-financial-hit-from-cyber-attack">attacks on UK retailers Marks & Spencer</a> and the <a href="https://www.itpro.com/security/cyber-attacks/co-op-chief-executive-very-proud-of-cyber-attack-response-despite-huge-financial-losses">Cooperative Group</a>, as well as <a href="https://www.itpro.com/security/cyber-attacks/mgm-resorts-back-online-after-suspected-ransomware-attack">MGM Resorts</a> in the US.</p><p>“Scattered Spider has repeatedly targeted US companies, extorting employees, inflicting millions of dollars in losses, and disrupting essential operations,” said assistant director Brett Leatherman of the FBI’s Cyber Division. </p><p>“Through strong domestic and international partnerships, the FBI will continue to identify, disrupt, and hold cybercriminals accountable, no matter where they are located.”</p><p>While the group has been repeatedly hit by law enforcement takedowns, it keeps emerging in different forms, for example teaming up with overlapping threat groups <a href="https://www.itpro.com/security/cyber-attacks/google-cyber-researchers-were-tracking-the-shinyhunters-groups-salesforce-attacks-then-realized-theyd-fallen-victim">ShinyHunters</a> and <a href="https://www.itpro.com/security/cyber-attacks/367199/what-is-the-lapsus-group-who-is-behind-the-criminal-operation">LAPSUS$</a> to form a unified collective.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why MSPs are now critical digital trust infrastructure and prime targets for modern cybercrime ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/why-msps-are-now-critical-digital-trust-infrastructure-and-prime-targets-for-modern-cybercrime</link>
                                                                            <description>
                            <![CDATA[ MSPs have become critical infrastructure in the digital economy — and that makes them real targets for those with malintent ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pQXtNmsidTspk8wrVutXM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4XZYfjMuoUwrLG8MTcaQBi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 02 Jul 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christoph Brecht ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/isjjUTQGjbhBsT59LjsXbk.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4XZYfjMuoUwrLG8MTcaQBi-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity concept image showing digital data storage modules with padlock symbols in a storage environment.]]></media:description>                                                            <media:text><![CDATA[Cybersecurity concept image showing digital data storage modules with padlock symbols in a storage environment.]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity concept image showing digital data storage modules with padlock symbols in a storage environment.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4XZYfjMuoUwrLG8MTcaQBi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Managed Service Providers (MSPs) were once viewed primarily as IT support partners. Today, they operate something far more critical: digital trust infrastructure.</p><p>MSPs manage identity systems, remote monitoring platforms, cloud environments, endpoint protection frameworks, and data backup architecture across dozens — sometimes hundreds — of client environments. In doing so, they have become central operational nodes in the digital economy.</p><p>That centrality also makes them strategically attractive to cybercriminals.</p><h2 id="from-service-providers-to-trust-custodians">From service providers to trust custodians</h2><p>Modern organizations depend on MSPs not just for operational efficiency, but for secure access management, infrastructure resilience, and regulatory alignment. MSP platforms sit at the intersection of customer networks, cloud services, SaaS applications, and identity environments.</p><p>This position makes MSPs stewards of inherited trust across entire business ecosystems.</p><p>When that trust is compromised, the consequences extend far beyond a single organization.</p><p>MSPs now operate critical digital infrastructure. When that trust is compromised, the impact multiplies across entire client ecosystems.</p><h2 id="why-attackers-are-targeting-msp-ecosystems">Why attackers are targeting MSP ecosystems</h2><p>Threat actors increasingly mirror the scale economics of managed services themselves. Rather than targeting organizations individually, attackers focus on centralized service environments that provide multiplier effects across downstream clients.</p><p>The logic is simple: compromising one MSO can provide access to dozens, sometimes hundreds, of connected organizations.</p><p>Remote monitoring and management platforms, multi-tenant administration consoles, and aggregated identity systems have become high-leverage entry points. Once inside, attackers can move laterally, harvest credentials, conduct reconnaissance, and deploy payloads across multiple customer environments simultaneously.</p><p>Campaigns attributed to groups such as DragonForce demonstrate how exploitation of MSP tooling can enable credential theft, data exfiltration, and ransomware deployment at scale.</p><p>Attackers have adopted the same logic as manager services: centralize access, standardize operations, and scale efficiently.</p><h2 id="the-industrialization-of-cybercrime-meets-the-managed-services-model">The industrialization of cybercrime meets the managed services model</h2><p>This convergence reflects a broader shift in cybercrime operations. Criminal groups now prioritize scalability, automation, and repeatable processes — principles that mirror the operational models used by MSPs.</p><p>Cybercrime has become industrialized, adopting structured affiliate programs, service platforms, and monetization strategies designed to maximize efficiency.</p><p>Managed service environments naturally align with this approach because they aggregate infrastructure, identities, and administrative access into centralized systems.</p><p>For attackers, this represents an opportunity. For MSPs, it raises the stakes of operational resilience.</p><h2 id="resilience-maturity-as-a-competitive-differentiator">Resilience maturity as a competitive differentiator</h2><p>As threat exposure grows, resilience maturity is becoming a defining factor that separates strategic MSP partners from commodity service providers.</p><p>Customers are increasingly evaluating MSPs based on governance transparency, identity security controls, incident readiness, and third-party risk management practices. Regulatory frameworks such as NIS2 are further reinforcing expectations around operational accountability and supply-chain oversight.</p><p>Security is no longer just a technical feature; it is a business trust signal.</p><p>Resilience maturity is becoming the dividing line between strategic MSPs and commodity providers</p><p>Forward-looking MSPs are strengthening privileged access controls, monitoring behavioral anomalies across multi-tenant environments, segmenting client infrastructure, and conducting continuous supply chain risk assessments.</p><p>These measures do more than reduce exposure; they demonstrate strategic commitment to protecting customer ecosystems.</p><h2 id="intelligence-led-defense-in-interconnected-ecosystems">Intelligence-led defense in interconnected ecosystems</h2><p>As digital environments grow more interdependent, reactive security models are proving insufficient. MSPs increasingly benefit from adversary-centric threat intelligence that tracks how specific attacker groups operate, which tools they exploit, and how campaigns typically unfold.</p><p>This approach enables earlier detection of suspicious behavior and faster disruption of attack chains before compromise spreads downstream.</p><p>Predictive threat intelligence also allows MSPs to anticipate emerging risks across their customer base, rather than responding only after incidents occur.</p><h2 id="the-future-role-of-msps-in-digital-trust">The future role of MSPs in digital trust</h2><p>The role of MSPs will continue expanding as organizations seek partners capable of managing both operational complexity and cybersecurity risk.</p><p>That reliance reinforces the MSP’s position as a custodian of digital trust — a role that extends beyond service delivery into governance, resilience, and ecosystem-wide risk management.</p><p>The providers that succeed in this environment will be those that recognize this responsibility and invest accordingly.</p><p>MSPs are no longer just managing infrastructure. They are safeguarding the trust architecture that modern business depends upon.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US offers $10m bounty for info on Russia-linked hackers behind Signal and WhatsApp attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/us-offers-usd10m-bounty-for-info-on-russia-linked-hackers-behind-signal-and-whatsapp-attacks</link>
                                                                            <description>
                            <![CDATA[ UNC5792 and UNC4221 have been targeting government officials through their Signal and WhatsApp accounts ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">J9nPQ3c6wnnTZ8dYQesqeA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 30 Jun 2026 09:58:58 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:description>                                                            <media:text><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US Department of State is offering a reward of up to $10 million to anyone that can help it identify and locate members of the Russia-linked UNC5792 and UNC4221 hacking groups.</p><p>UNC4221 works on behalf of the Russian military services while UNC5792 is associated with the Russian Federal Security Service (FSB), and has carried out <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaigns <a href="https://www.itpro.com/security/microsoft-and-ncsc-issue-alerts-over-hacker-campaigns-targeting-whatsapp-signal-messaging-apps">targeting the Signal and WhatsApp</a> accounts of US government officials, military leadership, and allied personnel.</p><p>"Using <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> techniques, these malicious cyber actors exploit legitimate device-linking features in these secure messaging applications to gain unauthorized access to sensitive government communications, contact lists, and group conversations," said the US Department of State. </p><p>"After compromising an account, the malicious actors were also able to send messages and conduct additional phishing against other accounts using those same commercial messaging applications."</p><p>In some cases, UNC5792 actors altered legitimate group invite pages to redirect users to a malicious URL that linked a hacker-controlled device to the victim’s Signal account. </p><p>Officials said that while these activities did not exploit vulnerabilities in either platforms’ encryption standards, they successfully compromised “thousands of individual commercial messaging application accounts”. </p><p>Targets included US government officials, diplomatic personnel and foreign affairs officials, defense and national security personnel, policy analysts and advisors, NATO member-state officials and diplomats, and allied intelligence and defense partners. </p><p>The group also went after investigative journalists covering Russia, Ukraine, and international affairs, NGOs providing support and assistance to Ukraine, and academic researchers in security studies and Russian affairs.</p><h2 id="valuable-intel">Valuable intel</h2><p>The announcement of the reward follows an <a href="https://www.ic3.gov/PSA/2026/PSA260626" target="_blank"><u>advisory</u></a> issued by the FBI and the <a href="https://www.itpro.com/security/what-is-cisa">Cybersecurity and Infrastructure Security Agency (CISA)</a> last week, which warned of continued activity by the two groups as well as a change in tactics aimed at harvesting victims' backup recovery keys.</p><p>"If a victim inadvertently shares their backup recovery key, that same key remains valid even if they create a new account following the compromise using the same phone number," the advisory warned. </p><p>"Consequently, the actor could potentially use the compromised key to take over the new account in the future as well."</p><p>The department gives a list of what information it seeks, including:</p><ul><li>Names</li><li>Locations</li><li>Biographical information on UNC5792 members</li><li>Affiliations with Russian intelligence services</li><li>Identities of personnel providing technical support</li><li>Contractors or third-party entities providing services</li></ul><p>It’s also seeking information on domain names, server locations, hosting providers, data storage and processing infrastructure, and technical tools, frameworks, and software used in operations.</p><p>Elsewhere, officials are keen to hear about the financial side of operations, including: </p><ul><li>Funding sources</li><li>Financial accounts and banking relationships</li><li>Cryptocurrency wallets</li><li>Payments for infrastructure</li><li>Financial networks supporting operations</li></ul><p>Anyone with dirt on either of the two groups can submit their tip <a href="https://rewardsforjustice.net/rewards/unc5792/" target="_blank"><u>here</u></a>, uploading relevant files such as photographs, videos, and documents. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Duo accused of role in TfL cyber attack plead guilty after ‘lengthy, highly complex, and painstaking investigation’ ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/duo-accused-of-role-in-tfl-cyber-attack-plead-guilty-after-lengthy-highly-complex-and-painstaking-investigation</link>
                                                                            <description>
                            <![CDATA[ Around 10 million people are believed to have been affected by the TfL cyber attack ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">99isQzP3Ggse8NRDUNdd7i</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/74qnvFg7TZirm7UfyeNWJH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Jun 2026 09:30:50 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                        <dc:contributor><![CDATA[ Ross Kelly ]]></dc:contributor>
                                                                    <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/74qnvFg7TZirm7UfyeNWJH-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Commuter standing on a train at a London underground tube station, which is run by Transport for London (TfL).]]></media:description>                                                            <media:text><![CDATA[Commuter standing on a train at a London underground tube station, which is run by Transport for London (TfL).]]></media:text>
                                <media:title type="plain"><![CDATA[Commuter standing on a train at a London underground tube station, which is run by Transport for London (TfL).]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/74qnvFg7TZirm7UfyeNWJH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Two young men have pleaded guilty to offenses under the Computer Misuse Act following a <a href="https://www.itpro.com/technology/artificial-intelligence/true-scale-of-tfl-cyber-attack-emerges-what-happened-who-was-responsible-and-how-many-people-were-impacted">cyber attack on Transport for London (TfL)</a> that caused months of disruption and millions in damages. </p><p>Thalha Jubair, 20, from East London, and Owen Flowers, 18, from Walsall in the West Midlands, were arrested following raids by the National Crime Agency (NCA) and City of London Police in September 2025.</p><p>The duo are alleged members of the notorious Scattered Spider cyber crime collective, believed to be responsible for a string of attacks in recent years. The group claimed responsibility for attacks on UK retailers <a href="https://www.itpro.com/security/cyber-attacks/m-and-s-reveals-massive-financial-hit-from-cyber-attack">Marks & Spencer</a> and the <a href="https://www.itpro.com/security/cyber-attacks/co-op-chief-executive-very-proud-of-cyber-attack-response-despite-huge-financial-losses">Cooperative Group</a>, as well as <a href="https://www.itpro.com/security/cyber-attacks/mgm-resorts-back-online-after-suspected-ransomware-attack">MGM Resorts</a> in the United States. </p><p>“The profile of offenders like Flowers and Jubair demonstrates the increasing threat from cyber criminals based in the UK and other English-speaking countries, epitomised by Scattered Spider," said Paul Foster, deputy director of the National Crime Agency and head of the NCA National Cyber Crime Unit.</p><p>Flowers was first arrested in September 2024, at which point NCA officers found evidence that the networks of US healthcare companies SSM Health Care Corporation and Sutter Health had also been infiltrated and damaged.</p><p>Investigators found a number of devices at Flowers' home, including laptops, tower computers, hard drives, and USB sticks. One Acer laptop contained a screenshot showing network connectivity to TfL infrastructure. </p><p>Flowers had also accessed an online platform selling credentials compromised in previous cyber attacks and data breaches. </p><p>Notably, the laptop contained a number of videos that Flowers had recorded, which showed Jubair accessing TfL systems during the attack. At the same time, the pair were messaging each other over Telegram, as well as communicating via an online work collaboration tool.</p><h2 id="what-happened-with-the-tfl-cyber-attack">What happened with the TfL cyber attack?</h2><p>TfL’s network was infiltrated at the beginning of September 2024, forcing all 28,000 employees to attend a TfL office for a password reset. The cyber attack caused widespread disruption for the rail operator. </p><p>Data from TfL’s Oyster refunds system was accessed while its customer refund system was also affected. Elsewhere, the attack shut down the Oyster photocard application system for children and young people. </p><p>Around 10 million people are believed to have been affected by the attack, making it one of the UK’s most devastating cyber attacks to date. </p><p>Jubair and Flowers are due to be sentenced at Woolwich Crown Court on 16 July.</p><h2 id="a-lengthy-investigation">A lengthy investigation</h2><p>Foster said the trial is the culmination of a “lengthy, highly complex and painstaking investigation” and hailed law enforcement colleagues for their role in apprehending the duo. </p><p>“The perseverance and meticulousness of our officers, and the work of our partner organizations, meant that Jubair and Flowers had no option other than to plead guilty and take responsibility for their offending," he commented.</p><p>“Cyber crime may appear faceless and distant compared to other crime types, but the infiltration of TfL’s systems shows it has real-world consequences and impacts hugely on the public. The attack caused millions of pounds in losses to a key part of the UK’s critical national infrastructure, and was a significant inconvenience for customers."</p><p>The NCA is urging victims of cyber crime to use the government’s Cyber Incident Signposting Site for direction on which agencies they should report incidents to.</p><p>“Today’s result would not have been possible if TfL had not engaged with law enforcement early, so I would urge any other organization to please do the same in such circumstances," said Foster.</p><h2 id="the-rise-of-youth-hackers">The rise of youth hackers</h2><p>Upon their arrest in September 2025, Jubair and Flowers were both teenagers, prompting concerns about a <a href="https://www.itpro.com/security/cyber-crime/the-rise-of-teen-hackers-makes-for-a-good-headline-but-cyber-crime-activities-peak-later-in-life"><u>potential wave of youth-related cyber crime</u></a>. As <a href="https://www.itpro.com/security/channel-their-curiosity-into-something-meaningful-cyber-expert-warns-an-uptick-of-youth-hackers-should-be-a-wake-up-call-after-teens-charged-over-tfl-attack"><u><em>ITPro </em></u><u>reported at the time</u></a>, cybersecurity experts described the incident as a “wake up call” for law enforcement, educators, and society at large. </p><p>Anna Chung, principal researcher for EMEA at Palo Alto Networks, said these incidents highlight a failure to “properly engage a generation growing up in a digital-first world”. </p><p>“Young people don’t usually turn to online mischief out of malice - it’s often down to a mixture of boredom, technical skills, and a lack of boundaries,” she told <em>ITPro </em>at the time.</p><p>So what’s the solution? Chung urged schools and parents to make a concerted effort toward teaching digital ethics, making this a “part of core education”. This, she noted, could be crucial to preventing future incidents. </p><p>Chung’s warning over teen hackers is by no means the first, or likely last, that we’ll hear about in coming years. </p><p>Indeed, the UK’s <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> published a report last year which <a href="https://www.itpro.com/security/kids-hacking-for-kicks-are-causing-security-headaches-at-schools"><u>highlighted a spate of cybersecurity incidents at schools across the country</u></a>, with students bypassing network security controls and gaining access to management systems. </p><p>Nipping these types of activities in the bud are crucial, the ICO warned, largely as they have the potential to evolve into more nefarious activities. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ransomware cartels are fragmenting into volatile splinter groups, warns Met Police cyber chief ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/ransomware-cartels-are-fragmenting-into-volatile-splinter-groups-warns-met-police-cyber-chief</link>
                                                                            <description>
                            <![CDATA[ Commoditized "cyber crime bazaars" and AI data mining are forcing law enforcement to rewrite its playbook ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iebQqT6UvKNF2JKXVQaiFd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/igtMHGaN9ZJo2kb9KB8CDG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 04 Jun 2026 08:29:01 +0000</pubDate>                                                                                                                                <updated>Thu, 04 Jun 2026 08:29:08 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rene Millman) ]]></author>                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/igtMHGaN9ZJo2kb9KB8CDG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Shattered glass fragmenting into a multitude of sharp splinters pictured against a black backdrop.]]></media:description>                                                            <media:text><![CDATA[Shattered glass fragmenting into a multitude of sharp splinters pictured against a black backdrop.]]></media:text>
                                <media:title type="plain"><![CDATA[Shattered glass fragmenting into a multitude of sharp splinters pictured against a black backdrop.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/igtMHGaN9ZJo2kb9KB8CDG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The global cyber threat landscape is undergoing a radical transformation, moving away from monolithic ransomware cartels toward highly volatile, fragmented splinter groups, a top UK police official has warned.</p><p>Speaking at Infosecurity Europe 2026, William Lyne, Head of Economic and Cybercrime at the Metropolitan Police Service, told IT and security leaders that the modern cyber crime ecosystem has evolved into a highly accessible space. </p><p>Lyne compared the underground landscape to a bar where threat actors can "get everything but a good drink."</p><p>"It felt like cyber threats were all quite stovepiped. You had hacktivists, you had hostile state actors," Lyne explained, reflecting on his early career. Today, however, those lines have blurred. "Those kind of stovepipes... no longer really exist."</p><p>Instead, Lyne described a blended ecosystem of products, goods, and services that has dramatically lowered the barrier to entry for prospective criminals. </p><p>This shift has been heavily accelerated by cryptocurrencies, which solved the traditional criminal bottleneck of "cashing out." </p><p>Previously, threat actors lost up to 75% of their profits navigating complex, expensive money-mule networks. Today, cryptocurrency allows them to realize illicit gains almost instantly and with very little risk.</p><h2 id="fragmentation-and-the-post-trust-era">Fragmentation and the 'post-trust' era</h2><p>While massive international law enforcement operations have successfully dismantled groups like <a href="https://www.itpro.com/security/ransomware/alleged-lockbit-developer-extradited-to-the-us">LockBit</a> and disrupted <a href="https://www.itpro.com/security/cyber-security/368284/what-is-phishing-as-a-service-phaas">phishing as a service (PhaaS)</a> platforms, Lyne cautioned that the criminal underground is rapidly adapting.</p><p>"It's getting more diverse... [and] also much more fragmented," Lyne said. Following high-profile law enforcement crackdowns, cybercriminals have realized that operating as a massive, centralized brand or <a href="https://www.itpro.com/security/29332/the-rise-of-ransomware-as-a-service">ransomware as a service</a> scheme is "actually quite bad for business."</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="JxzEa6dVuBxWeMWLv3oLWk" name="Infosec" alt="William Lyne, Head of Economic and Cybercrime at the Metropolitan Police Service, speaking on stage during a keynote presentation at Infosecurity Europe 2026 at the ExCel, London." src="https://cdn.mos.cms.futurecdn.net/JxzEa6dVuBxWeMWLv3oLWk.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="caption-text">Lyne told attendees the cyber crime landscape is becoming more fragmented and volatile. </span><span class="credit" itemprop="copyrightHolder">(Image credit: ITPro/Rene Millman)</span></figcaption></figure><p>As a result, major ransomware operators are breaking off into smaller, independent factions. </p><p>This fragmentation is leading to a dangerous "post-trust" trend within the criminal ecosystem. Without the strict moderation and internal rules previously enforced by large cartel administrators, smaller threat actors are exhibiting more extreme, aggressive, and unpredictable behaviors.</p><p>The demographics of these attackers are also shifting. Lyne noted that the threat landscape is moving beyond traditional Russian-speaking hubs to include actors from Brazil, Türkiye, and English-speaking groups like the notorious Scattered Spider collective.</p><h2 id="ai-weaponizing-hoarded-data">AI weaponizing hoarded data</h2><p>Addressing the inevitable topic of AI, Lyne dispelled fears of autonomous systems launching end-to-end cyber attacks, but highlighted a pressing new risk for enterprise data privacy.</p><p>"These guys are generally not innovative," Lyne noted, explaining they only change their methods if they are “systematically earning less money... or they spy an opportunity to make more money."</p><p>Having stolen and hoarded petabytes of corporate data over the last decade, data that was rarely deleted even when victims paid the ransom, cyber criminals are now using AI tools to operationalize these massive "treasure troves" and mining historic datasets for new extortion and revenue streams.</p><h2 id="rewriting-the-law-enforcement-playbook">Rewriting the law enforcement playbook</h2><p>Faced with this agile, commoditized threat, the Met Police and its international partners are adopting aggressive new disruptive strategies.</p><p>"We can't arrest our way out of this problem," Lyne admitted, citing the jurisdictional complexities of cross-border cybercrime. </p><p>Instead, policing has shifted toward systemic disruption, psychological operations designed to undermine criminal trust, and targeting the foundational infrastructure of the cybercrime supply chain.</p><p>Crucially, this requires unprecedented collaboration with the private sector. Lyne emphasized that the Met Police is increasingly sharing intelligence with enterprise IT security teams and even naming industry partners who assist in operations on their site takedown pages.</p><p>"Ultimately, like, lots of these things just come down to trust," Lyne concluded, addressing the security professionals in the room. </p><p>"We want to have meaningful, both strategic and tactical collaboration with industry partners that we know hold some of the keys to... the challenges that we have in this space. The cultural change that we have undertaken, I think will continue so that we collaborate better moving forward."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are turning up at law firms to gain physical access to machines ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/hackers-are-turning-up-at-law-firms-to-gain-physical-access-to-machines</link>
                                                                            <description>
                            <![CDATA[ The FBI is warning companies to look out for fake IT staff ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">RRTUidymkRvpRbyDRqH3Vg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LEn4RWFLrJ7FxZPhnQgKsP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 28 May 2026 11:14:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LEn4RWFLrJ7FxZPhnQgKsP-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[FBI seal and insignia pictured on the FBI headquarters building in Washington D.C., United States.]]></media:description>                                                            <media:text><![CDATA[FBI seal and insignia pictured on the FBI headquarters building in Washington D.C., United States.]]></media:text>
                                <media:title type="plain"><![CDATA[FBI seal and insignia pictured on the FBI headquarters building in Washington D.C., United States.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LEn4RWFLrJ7FxZPhnQgKsP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers posing as IT experts are showing up in person at law firms, the FBI has <a href="https://www.ic3.gov/CSA/2026/260526.pdf">warned</a>.</p><p>In the past, the Silent Ransom Group (SRG), also known as Luna Moth, Chatty Spider, and UNC3753, sent <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing emails</a> purportedly charging small 'subscription fees'. To cancel the fake subscription, the victim was instructed to call the threat actor, who then emailed the victim a link to download remote access software.</p><p>Now, though, the group is using phone calls and phishing emails to pose as IT support, gaining access to the victims' computers and exfiltrating data. </p><p>And while this is often done through legitimate <a href="https://www.itpro.com/mobile/remote-access/368050/best-free-remote-desktop-software-2023">remote access tools</a>, the group has also been sending individuals in person to the victim company's location to gain physical access to machines.</p><p>"This is a pretty natural evolution of extortion operations. We spent years building detections around <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a> and exploits, and now attackers are shifting toward social engineering, trusted tooling, and physical access," commented Gabrielle Hempel, security operations strategist at Exabeam. </p><p>"Physical security fell by the wayside when organizations began to move their data to the cloud, but if your security model assumes that the threat actor is always on the other side of the internet, you have a problem." </p><p>The group's first step is to either directly call or send phishing emails urging employees to call 'IT support'. While on the phone, the SRG actor directs the employee to grant access to a remote desktop session. </p><p>If that attempt fails, though, SRG sends a threat actor to the victim's location to gain access and insert a storage device into the victim's computer. The hacker tells the victim they need to image the device or create a <a href="https://www.itpro.com/backup/29847/best-free-backup-software">backup file</a> to address potential impacts from the phishing email.</p><p>Once they've got access to the victim's device, they minimally escalate privileges and quickly pivot to data exfiltration without encryption, using Windows Secure Copy ( WinSCP) or a hidden or renamed version of 'Rclone'.</p><p>"SRG actors use the exfiltrated victim data to extort the victim by sending a ransom email threatening to sell or post the data online," the FBI said. "SRG actors also call employees or clients of a victim company to pressure the victim to begin ransom negotiations." </p><p>While SRG has hit companies in a number of sectors, including the insurance, finance, and healthcare industries, it's consistently been targeting US-based law firms since spring 2023.</p><p>"The group is leaning into trust by posing as IT support, walking employees through remote access, then moving quickly to steal data before anyone realizes something is wrong," warned Nick Tausek, lead security automation architect at Swimlane.</p><p>"That makes this especially dangerous for law firms. These environments hold sensitive client records, privileged communications, financial details, and case information. If that data is stolen, the damage does not stop at the victim organization. Clients can be pressured, legal strategies can be exposed, and employees can become targets for follow-up scams."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Tycoon 2FA is down, but not out – researchers warn the phishing as a service operation is still a huge threat to businesses ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/tycoon-2fa-phishing-risk-takedown-barracuda</link>
                                                                            <description>
                            <![CDATA[ Millions of Tycoon 2FA attacks are still hitting businesses, according to research from Barracuda ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vXDsxDKKWbMUkuvkVXXwHC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Apr 2026 11:05:53 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                        <dc:contributor><![CDATA[ Ross Kelly ]]></dc:contributor>
                                                                    <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:description>                                                            <media:text><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security experts have issued a warning about the continued risk of Tycoon 2FA attacks, even after a law enforcement operation took down the <a href="https://www.itpro.com/security/cyber-security/368284/what-is-phishing-as-a-service-phaas">phishing as a service (PhaaS)</a> platform last month. </p><p>According to Barracuda, while attacks have since dropped by 77%, they still persist, with more than two million taking place each month. </p><p>Before the takedown, Tycoon 2FA was behind tens of millions of phishing messages, reaching over 500,000 organizations each month worldwide.</p><p>First spotted in August 2023, it used adversary in the middle (AitM) proxying to <a href="https://www.itpro.com/security/cyber-attacks/how-hackers-bypass-mfa-and-what-to-do-about-it">bypass traditional multi-factor authentication (MFA)</a> and capture session cookies in real time, leading to large-scale account compromise.</p><p>It was linked to more than 96,000 distinct phishing victims globally, including more than 55,000 Microsoft customers and around 5,350 in the UK, hitting sectors including education, healthcare, finance, and the public sector. </p><p>The takedown last month saw <a href="https://www.itpro.com/security/law-enforcement-and-security-firms-take-down-huge-phaas-platform"><u>Microsoft seize 330 domains forming the core infrastructure of the criminal service</u></a>, including phishing pages and control panels.</p><p>Yet Barracuda said its analysis shows the impact of the takedown has been largely restricted to Tycoon’s own brand name and visibility, along with a drop in the use of Tycoon-linked hosting and domain patterns.</p><p>"The ‘body’ of Tycoon: its tools and techniques, live on. They have migrated, been redistributed and diversified across competing platforms, or simply left where they are,” the company said in a <a href="https://blog.barracuda.com/2026/04/16/threat-spotlight-tycoon-2fa-scattered-everywhere" target="_blank">blog post</a>. </p><h2 id="pouncing-on-the-tycoon-2fa-takedown">Pouncing on the Tycoon 2FA takedown</h2><p>Notably, Barracuda found that other phishing kits have moved quickly to take Tycoon 2FA's place, with increased campaign activity involving the established platforms of Mamba 2FA and EvilProxy, as well as aggressive newcomers such as Sneaky 2FA and Whisper 2FA. </p><p>These kits have boosted their feature sets and infrastructure maturity, according to Barracuda, often leveraging tools formerly used by Tycoon 2FA.</p><p>"Tycoon 2FA was widely used by independent affiliates. This means that variants of Tycoon 2FA’s attack code that have been cloned or modified by individual adversaries continue circulating. It also means that independently hosted deployments remain active and that fragmented, low-volume campaigns persist," the firm said.</p><p>"For example, Barracuda recently detected a ‘device code’ phishing campaign that leveraged Tycoon’s stand-out features. Code similarities included Tycoon’s signature ‘noise’ of motivational style comments. In this incident, the comments all begin with the word ‘success’."</p><p>This campaign also featured Tycoon 2FA’s unique anti-analysis, anti-debugging and redirection capabilities. </p><h2 id="tycoon-2fa-is-still-alive-and-kicking">Tycoon 2FA is still alive and kicking</h2><p>Barracuda said the reasons for Tycoon 2FA’s persistence include the fact that attackers have reused and repurposed phishing code. </p><p>Meanwhile, attack domains remain active until expiry, backup hosting often evades immediate seizure, and some low-visibility phishing campaigns fall beneath alert thresholds.</p><p><a href="https://www.itpro.com/security/29093/what-is-phishing">Phishing</a> frameworks have built-in redundancy, researchers noted, while the disruption of infrastructure doesn't necessarily revoke victim access. </p><p>Stolen session cookies may remain valid, OAuth abuse can enable extended cloud access, and organizations may remain compromised after the end of the phishing campaign.</p><p>"This does not mean the takedown operation failed. Rather, it shows what happens when disruption hits a maturing underground economy, and why security defenses need to look more broadly than individual players," said Barracuda.</p><p>"The Tycoon 2FA takedown accelerated ecosystem diversification. Defensive strategies therefore need to focus on models for identity-based attacks, session abuse and adversary economics. Tycoon 2FA as a branded service has declined, but the techniques it popularized are now more widely distributed than before."</p><h2 id="cyber-crime-whack-a-mole">Cyber crime whack-a-mole</h2><p>Barracuda’s findings highlight a painful recurring theme for law enforcement agencies tackling cyber crime – these operations are very hard to kill outright. </p><p>While takedowns cripple infrastructure and hamper operations for a time, many groups simply dust themselves off and get back to it, and often in a far more aggressive way. </p><p>There have been repeated instances of cyber crime operations coming back from the dead in recent years despite hard crackdowns by industry stakeholders and law enforcement agencies. </p><p><a href="https://www.itpro.com/security/hacking/361340/what-is-emotet">Emotet</a> ranks among the best examples of this. The botnet was used to facilitate an eye-watering volume of attacks over its lifespan before being taken down by a Europol-led operation in January 2021. </p><p>Less than a year later, however, the botnet was back up and running, with <a href="https://www.itpro.com/security/cyber-attacks/369526/hundreds-of-thousands-of-emotet-attacks-spotted-daily-after-hiatus"><u>Analysis from November 2022</u></a> showing the cyber criminals behind the operation ramped up attacks to record levels. </p><p>Of course, that’s not to say law enforcement should just down tools and stop trying. The impact of these takedowns may have a limited shelf life, but they do provide a temporary reprieve for victims and deliver long-term benefits. </p><p>As <em>ITPro </em>reported in the wake of the <a href="https://www.itpro.com/security/cyber-crime/the-fbi-has-seized-the-ramp-hacking-forum-but-will-the-takedown-stick-history-tells-us-otherwise"><u>RAMP hacking forum takedown</u></a> last year, they enable law enforcement to gain vital intelligence on how these groups work and support other operations further down the line. </p><p>This cat and mouse game between hackers and law enforcement is as old as cyber crime itself, and shows no signs of slowing down. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ German authorities want your help finding the hackers behind GandCrab and REvil  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/german-authorities-want-your-help-finding-the-hackers-behind-gandcrab-and-revil</link>
                                                                            <description>
                            <![CDATA[ Daniil Maksimovich Shchukin and Anatoly Sergeevitsch Kravchuk are believed to have made millions from ransomware as a service schemes ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fdDCDsuwTqeNGjcqnLSn5n</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Apr 2026 11:12:24 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:description>                                                            <media:text><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>German police have identified two Russian hackers and are calling for help tracking them down.</p><p>The German Federal Criminal Police (BKA) said that 31-year-old Daniil Maksimovich Shchukin, who went by the handle 'UNKN', was behind the Russian ransomware groups GandCrab and REvil.</p><p>He is suspected of having carried out 130 incidents of gang-related extortion against German organizations, along with 43-year-old Anatoly Sergeevitsch Kravchuk, a Ukraine-born Russian citizen. </p><p>Kravchuk is accused of creating and further developing the dark web site used by the group to organize and manage extortion, as well as development of the malware itself.</p><p>Across 25 of the cases, the BKA said a total of €35.4 million was paid out in ransom payments.</p><p>"Based on investigations conducted so far, the wanted person is believed to be currently abroad, presumably in Russia. It is impossible to rule out potential travel," the BKA said.</p><p>"The police are interested in receiving a response to the following question: can you provide any information on the wanted person's current whereabouts?"</p><h2 id="revil-mastermind">REvil mastermind</h2><p>From the beginning of 2019 until at least July 2021, Shchukin acted as the head of one of the largest ransomware groups globally, known as GandCrab or, later, REvil. </p><p>"For the decryption and non-publication of data, the perpetrators demanded high ransoms," said the BKA. "In addition, in some cases, extensive data were also spied on and threatened with the publication of this, unless a ransom was paid."</p><p>GandCrab operated a <a href="https://www.itpro.com/security/29332/the-rise-of-ransomware-as-a-service">ransomware as a service (RaaS)</a> model, primarily through the use of spam emails. It's believed to have netted a total of more than $2 billion from ransomware attacks, before evolving into REvil, also known as Sodinokibi, in 2019. </p><p>“We are a living proof that you can do evil and get off scot-free,” GandCrab said as it bowed out. “We have proved that one can make a lifetime of money in one year. We have proved that you can become number one by general admission, not in your own conceit.”</p><p>The group claimed to have been making $2.5 million per week.</p><p>"We personally earned more than 150 million dollars per year," Shchukin claimed. "We successfully cashed in this money and legalized it in various spheres of white business both in real life and on the internet." </p><p>In its next incarnation as REvil, the group targeted large organizations including IT management software firm Kaseya in a 2021 <a href="https://www.itpro.com/security/ransomware/360122/up-to-1500-organizations-compromised-in-kaseya-ransomware-attack"><u>supply chain attack</u></a> that saw as many as 1,500 organizations compromised.</p><p>Law enforcement agencies including the FBI were eventually able to infiltrate the group’s infrastructure and get hold of its decryption keys, which were then distributed to victims. </p><p>The US Justice Department also seized cryptocurrency worth more than $317,000 linked to wallets allegedly controlled by Shchukin.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Dark web platforms taken down in international operation ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/dark-web-platforms-taken-down-in-international-operation</link>
                                                                            <description>
                            <![CDATA[ Operation Alice traced tens of thousands of CSAM and cybercrime-as-a-service sites back to one individual ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BdisyDLHNnfwtRmP3zyLj5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hNt2JaLuS3Ribvoh5XfgT8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 23 Mar 2026 12:16:15 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hNt2JaLuS3Ribvoh5XfgT8-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Image of a Europol sign affixed to its Amsterdam headquarters]]></media:description>                                                            <media:text><![CDATA[Image of a Europol sign affixed to its Amsterdam headquarters]]></media:text>
                                <media:title type="plain"><![CDATA[Image of a Europol sign affixed to its Amsterdam headquarters]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hNt2JaLuS3Ribvoh5XfgT8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>An international operation has taken down one of the largest networks of fraudulent platforms on the dark web, shutting down hundreds of thousands of websites. </p><p> Operation Alice, which kicked off in mid-2021, was led by German authorities and supported by Europol.</p><p>It initially focused on the dark web platform "Alice with Violence CP", which was found to be running more than 373,000 fraudulent websites advertising child sexual abuse material (CSAM) and cybercrime-as-a-service (CaaS) offerings.</p><p>The operation expanded after the identities of 440 customers who had used the operator's services were uncovered, leading to further examination; more than a hundred are still under investigation.</p><p>The team identified patterns among thousands of small and previously unnoticed dark web marketplaces that, individually, looked insignificant and which would normally evade detection. However, by correlating these sites with cryptocurrency transactions, analysts were able to join the dots to reveal a much larger, coordinated network that Europol said covered almost half of the dark web. </p><p>The person running the network has been identified as a 35-year-old man based in the People's Republic of China, who is now subject to an international arrest warrant. He's believed to have been running the sites since 2017 and to have made more than €345,000 in profits from around 10,000 customers worldwide.</p><p>Meanwhile, the websites have been shut down and 105 servers seized, along with electronic devices including computers, mobile phones and electronic data carriers.</p><p>"We are pleased to have disrupted this extensive dark web network," said Thomas Goger, representing the Bavarian authorities involved in the investigation.</p><p>"The perpetrator played a central role in a major criminal infrastructure. Dismantling this network marks a significant step forward in several respects: applying cutting-edge law enforcement technologies, prosecuting about 600 offenders and users, and, most importantly, protecting potential future victims."</p><p>Between February 2020 and July 2025, said Europol, the suspect advertised CSAM on different platforms, which were accessible through more than 90,000 onion domains. The "packages" on offer cost between €17 and €215, and promised data volumes ranging from a few gigabytes to several terabytes – but were never delivered.</p><p>Meanwhile, the sites promoted several cybercrime-as-a-service (CaaS) offerings, including credit card data and access to foreign systems - but again took payments without offering any service in return.</p><p>"Operation Alice sends a clear message: there is nowhere to hide for criminals when the international law enforcement community works hand in glove," said Europol executive director Catherine De Bolle. </p><p>"We will find them and hold them accountable. Europol will continue to protect children, support victims, and track down the perpetrators."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Tomorrow's fraud techniques ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/tomorrows-fraud-techniques</link>
                                                                            <description>
                            <![CDATA[ Leaders need to proactive as attackers launch more consistent, sophisticated attacks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YSt4fP3QNyRUV8QoGCFYTm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UhaTLQjGywjs4tCHCcVgoe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 13 Mar 2026 13:03:15 +0000</pubDate>                                                                                                                                <updated>Fri, 13 Mar 2026 16:01:09 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ rory.bathgate@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LFPWMoCGDVHowHbMpHJZkU.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rory Bathgate is the Features and Multimedia Editor at ITPro, overseeing all in-depth content and case studies. He is a subject expert on artificial intelligence and business networks but in his time at ITPro has also covered a wide range of areas including cyber security and hardware. Throughout his time at ITPro, Rory has charted the rise in popularity of generative AI and specifically companies such as Microsoft, OpenAI, and Google. &lt;/p&gt;&lt;p&gt;Alongside this, he has delved into increasing calls for ethical and responsible AI as global legislators circle the technology, as well as the latest in mobile networking technology, from 5G mmWave to the 3G sunset and how it will affect businesses.&lt;/p&gt;&lt;p&gt;He has provided coverage from high-profile tech conferences such as Dell Technologies World, SuiteWorld, and VMware Explore Europe. His on-the-ground coverage has included live blogs, extensive daily coverage of the most significant announcements, analysis pieces, and podcasts.&lt;/p&gt;&lt;p&gt;Indeed, Rory is also a full-time co-host of the ITPro Podcast alongside Jane McCallion, where he swaps a keyboard for a microphone to discuss the latest learnings in tech. Each week, a guest comes onto the show to discuss topics such as cyber security, productivity, or digital transformation in detail.&lt;/p&gt;&lt;p&gt;Rory has an MA in Eighteenth-Century Studies from King’s College London, as well as a BA in English and American Literature from the University of Kent. He joined ITPro in 2022 as a graduate, after four years in student journalism.&lt;/p&gt;&lt;p&gt;In his free time, Rory enjoys photography and video editing, and can often be found at the cinema or reading a good science fiction paperback.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UhaTLQjGywjs4tCHCcVgoe-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The text &quot;Tomorrow&#039;s fraud techniques&quot; against a glitched, green face on a dark background. The words &quot;fraud techniques&quot; are in yellow, the rest are in white. In the bottom-right corner, the ITPro Podcast logo is shown.]]></media:description>                                                            <media:text><![CDATA[The text &quot;Tomorrow&#039;s fraud techniques&quot; against a glitched, green face on a dark background. The words &quot;fraud techniques&quot; are in yellow, the rest are in white. In the bottom-right corner, the ITPro Podcast logo is shown.]]></media:text>
                                <media:title type="plain"><![CDATA[The text &quot;Tomorrow&#039;s fraud techniques&quot; against a glitched, green face on a dark background. The words &quot;fraud techniques&quot; are in yellow, the rest are in white. In the bottom-right corner, the ITPro Podcast logo is shown.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UhaTLQjGywjs4tCHCcVgoe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <iframe allow="" height="200px" width="100%" id="" style="" class="position-center" data-lazy-priority="high" data-lazy-src="https://player.captivate.fm/episode/0abd7be2-413d-4665-8b77-7ed3e296a2a6/"></iframe><p>Fraud has evolved in leaps and bounds over the past few years, with new technology and more digitally native businesses than ever providing the ideal attack surface for fraudsters.</p><p>As attackers look to lure in business professionals with new tech such as deepfakes and AI scams, enterprise cybersecurity teams and cybersecurity vendors are faced with the task of combatting cyber fraud more effectively.</p><p>How can we combat this new frontier of cyber fraud?</p><p>In this episode, Jane is joined by Paul Weathersby, chief product officer, Identity, Fraud & Financial Crime Compliance at Experian, to explore the increasing sophistication of cyber crime and fraud campaigns.</p><h2 id="highlights">Highlights</h2><p>"I think the challenge that it creates for, say, financial institutions as an example, is it's becoming much harder to manage the fraud due to the rising threat of AI. The impact that that's having is it isn't necessarily making it more sophisticated. So what an average bank is now seeing is that the the odd sophisticated attack that they used to see is now happening on a regular basis. They might have seen something that was very well coordinated, very well orchestrated, happening once in a while. Now those types of attack are being replicated using AI and happening all of the time."</p><p>"So behavioral analytics plays a big part in understanding whether the behavior of the user is that of a person. So a genuine person, not being coerced into performing actions on behalf of someone else, and is actually a bot. So one of the very simple rules that you can look at, for example, is if the interaction with the user is from a phone, to make sure  that the phone is held and used at an angle which would be normal."</p><p>"Now what we've seen is that AI has now been used to clone voices, which it can be done with as little as three seconds of audio of the from the genuine person to effectively clone the the voice pattern in order to get through those particular controls."</p><p>"What you actually see is sometimes these synthetic identities can be something which build up over years, so even sometimes as long as five years. So they look like real people, they transact like real people, and then on any given day, the fraudsters in control of these synthetic IDs decide to actually commit the fraud at that particular point."</p><h2 id="footnotes">Footnotes</h2><ul><li><a href="https://www.itpro.com/security/cyber-crime/interpol-teams-up-with-tech-firms-to-seize-45-000-malicious-ips-servers-in-global-cyber-crime-crackdown" target="_blank">Interpol teams up with tech firms to seize 45,000 malicious IPs, servers in global cyber crime crackdown</a></li><li><a href="https://www.itpro.com/security/is-your-new-hire-an-ai-clone-microsoft-says-north-korean-hackers-are-using-ai-to-impersonate-job-seekers-and-steal-company-secrets">Is your new hire an AI clone? Microsoft says North Korean hackers are using AI to impersonate job seekers and steal company secrets</a></li><li><a href="https://www.itpro.com/security/deepfake-business-risks-are-growing-what-leaders-need-to-know">Deepfake business risks are growing – here's what leaders need to know</a></li></ul><h2 id="subscribe">Subscribe </h2><ul><li><a href="https://apple.sjv.io/c/221109/473657/7613?subId1=itpro-gb-1243831151189624600&sharedId=itpro-gb&u=https%3A%2F%2Fpodcasts.apple.com%2Fgb%2Fpodcast%2Fthe-itpro-podcast%2Fid1483810154" target="_blank"><u>Subscribe to The IT Pro Podcast on Apple Podcasts</u></a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ" target="_blank"><u>Subscribe to The IT Pro Podcast on Spotify</u></a></li><li><a href="https://www.itpro.co.uk/newsletter-signup"><u>Subscribe to the IT Pro newsletter</u></a></li><li><a href="https://uk.linkedin.com/company/itpro-uk" target="_blank"><u>Join us on LinkedIn</u></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Interpol teams up with tech firms to seize 45,000 malicious IPs, servers in global cyber crime crackdown ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/interpol-teams-up-with-tech-firms-to-seize-45-000-malicious-ips-servers-in-global-cyber-crime-crackdown</link>
                                                                            <description>
                            <![CDATA[ Operation Synergia III saw 94 arrests - and counting - with malicious IP addresses used in phishing and fraud schemes seized ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XFNDAXHXAFtquRa5PNdCj4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iYKtddn8SPxwMyTSxMyxEK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 13 Mar 2026 11:48:22 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iYKtddn8SPxwMyTSxMyxEK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Interpol logo and insignia pictured on a building facade at a regional unit in Singapore. ]]></media:description>                                                            <media:text><![CDATA[Interpol logo and insignia pictured on a building facade at a regional unit in Singapore. ]]></media:text>
                                <media:title type="plain"><![CDATA[Interpol logo and insignia pictured on a building facade at a regional unit in Singapore. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iYKtddn8SPxwMyTSxMyxEK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Interpol has taken down more than 40,000 malicious IP addresses and servers as part of an international cyber crime operation targeting phishing, <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>and <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>activities. </p><p>Law enforcement bodies from 72 countries and territories took part in Operation Synergia III between July 2025 and the end of January this year, with 94 people arrested and another 110 still under investigation.</p><p>In all, 45,000 malicious IP addresses were taken down and 212 electronic devices and servers were seized.</p><p>“Cyber crime in 2026 is more sophisticated and destructive than ever before, but Operation Synergia III stands as a powerful testament to what global cooperation can achieve," said Neal Jetton, director of Interpol's Cybercrime Directorate. </p><p>"Interpol remains at the forefront of this fight, uniting law enforcement agencies and private sector experts to dismantle criminal networks, disrupt emerging threats and protect victims around the world.”</p><p>As investigations are still ongoing, some details are under wraps. However, the results include the identification of more than 33,000 <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>and fraudulent websites in Macau, China, related to fake casinos and critical infrastructure, such as official bank, government and payment service sites. </p><p>Victims are defrauded by topping up their accounts via the fraudulent sites, or by having their personal information and credit card details stolen.</p><p>Police in Togo, meanwhile, arrested 10 suspects operating a fraud ring from a residential area. Some specialized in technical crimes such as hacking social media accounts while others carried out <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> schemes including romance scams and sextortion. </p><p>In Bangladesh, police arrested 40 suspects and seized 134 electronic devices related to a wide range of cyber crime schemes, including loan and job scams, identity theft, and credit card fraud.</p><h2 id="hot-on-the-heels-of-tycoon-2fa-takedown">Hot on the heels of Tycoon 2FA takedown</h2><p>The operation follows the disruption last week of the the massive phishing<a href="https://www.itpro.com/security/cyber-security/368284/what-is-phishing-as-a-service-phaas"> as a service (PhaaS)</a> platform, Tycoon 2FA.</p><p>This saw threat actors use <a href="https://www.itpro.com/security/cyber-crime/adversary-in-the-middle-attacks-are-becoming-hackers-go-to-method-to-bypass-mfa">adversary in the middle (AitM)</a> proxying to <a href="https://www.itpro.com/security/cyber-attacks/how-hackers-bypass-mfa-and-what-to-do-about-it">bypass traditional multi-factor authentication (MFA)</a> and capture session cookies in real time, leading to large-scale account compromise.</p><p>In an <a href="https://www.itpro.com/security/law-enforcement-and-security-firms-take-down-huge-phaas-platform"><u>international operation</u></a>, 330 domains were seized, including parts of the core infrastructure, such as phishing pages and control panels. </p><p>Much like that action, Operation Synergia III was carried out in collaboration with a number of private sector organizations, including Trend Micro.</p><p>“This kind of international operation highlights the value of close collaboration between law enforcement and the cybersecurity community. Behind every malicious server or phishing kit sits a wider criminal ecosystem that needs to be mapped and understood before arrests become possible," said Robert McArdle, director of cybercrime research at Trend Micro business unit TrendAI. </p><p>"Our support for investigations such as Tycoon 2FA, and contributions to operations like this one led by Interpol, demonstrates how actionable threat intelligence can help authorities identify infrastructure, connect actors and disrupt cyber criminal networks at scale.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The rise of teen hackers ‘makes for a good headline’, but cyber crime activities peak later in life ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/the-rise-of-teen-hackers-makes-for-a-good-headline-but-cyber-crime-activities-peak-later-in-life</link>
                                                                            <description>
                            <![CDATA[ With family responsibilities and mortgages to pay, it's not teenagers dishing out malware or carrying out cyber extortion ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">AixB4pKPDWgHro8HrA47Jg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 11 Mar 2026 10:56:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:description>                                                            <media:text><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>While much emphasis has been placed on the <a href="https://www.itpro.com/security/channel-their-curiosity-into-something-meaningful-cyber-expert-warns-an-uptick-of-youth-hackers-should-be-a-wake-up-call-after-teens-charged-over-tfl-attack">rise of youth cyber crime</a> over the last two years, new research shows hacker activity peaks much later. </p><p>Orange Cyberdefense looked at the numbers and found that it's actually thirty- and forty-somethings that are the greatest threat.  </p><p>The company’s intelligence team <a href="https://www.orangecyberdefense.com/uk/security-navigator"><u>analyzed</u></a> 418 publicly announced law enforcement activities between 2021 and mid-2025 and found that offenders’ activities peaked between the ages of 35 and 44. This age group, they said, accounted for 37% of cyber crime cases.</p><p>Put together, the combined age groups of 25-to-44 make up well over half (58%) of analyzed cyber crime cases. </p><p>Only one-in-five (21%) incidents were the work of 18-to-24-year-olds. Despite the bad press they get in movies and the news, 12-to-17s were behind fewer than 5% of cases.</p><p>“The surge in cyber offences committed by teenagers in recent years may be creating a false impression of the age of today's cyber criminals," said Charl van der Walt, head of security research at Orange Cyberdefense. </p><p>"The sensationalist interpretation of cyber crime's youthfulness makes for a good headline, but these findings appear to tell a different story."</p><h2 id="differing-motives">Differing motives</h2><p>One big difference between the kids and their elders is the underlying motivation behind attacks, researchers noted. As you might expect, younger hackers are frequently experimenting while the older cohort is in it primarily for financial gain. </p><p>Among 18-24-year-olds, cyber criminal activity is highly diverse, though there's a focus on hacking (30%) in particular, followed by selling stolen data and <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack">DDoS attacks</a> (10% each).</p><p>Things start to change among offenders aged between 25 and 34, who tend to focus on more profitable activities such as selling stolen data (21%), cyber extortion (14%) and <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>deployment (12%). </p><p>This trend continues among 35-to-44 year olds, where <a href="https://www.itpro.com/security/ransomware/369222/what-is-triple-extortion-ransomware">cyber extortion</a> (22%) is the crime of choice, followed by malware (19%) and <a href="https://www.itpro.com/security/28170/what-is-cyber-warfare">cyber espionage</a> (13%), hacking (10%), and money laundering (7%). </p><p>"While younger, less experienced hackers engage in highly diverse – and often noticed and reported – actions, they may be less likely to engage in calculated, profit seeking activity," said van der Walt. </p><p>"Instead, cyber crime careers appear to peak much later into adulthood, accompanied by vastly more sophisticated and intentional techniques.”</p><p>Some of those teen-related activities are very high profile indeed. Late last year, for example, a 15-year-old was <a href="https://www.itpro.com/security/cyber-crime/15-year-old-revealed-as-key-player-in-scattered-lapsus-usd-hunters">outed by security researcher Brian Krebs</a> as a member of Scattered LAPSUS$ Hunters – the group responsible for the Jaguar Land Rover (JLR) and M&S cyber attacks.</p><p>Two teenagers, meanwhile, are set to face charges for the 2024 <a href="https://www.itpro.com/security/cyber-attacks/everything-we-know-about-the-tfl-cyber-attack-so-far"><u>hack of Transport for London</u></a> (TfL), while another pair have been <a href="https://www.itpro.com/security/teens-arrested-over-nursery-chain-kido-hack"><u>arrested</u></a> for the data breach of the Kido chain of children's nurseries.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cloudflare warns state-backed hackers are ‘weaponizing legitimate enterprise ecosystems’ as ‘living off the land’ attacks surge ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/cloudflare-warns-state-backed-hackers-are-weaponizing-legitimate-enterprise-ecosystems-as-living-off-the-land-attacks-surge</link>
                                                                            <description>
                            <![CDATA[ Chinese, North Korean, and Russian-backed threat groups now favor longer-term compromises over brute force attacks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tDHyWXyTh5PSUqWYrFAqbV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 04 Mar 2026 09:23:15 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:description>                                                            <media:text><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>State-sponsored attackers are weaponizing legitimate software and infrastructure to lie in wait, shifting tactics away from data breaches to more sophisticated espionage and disruptive operations.  </p><p>That's according to a new report from Cloudflare that walked through a series of attacks from Chinese hacks against Google Calendar to North Korean IT worker scams – including a tactic that makes use of AI. </p><p>In that attack, the hackers snuck past traditional perimeter defenses by finding credentials hidden in code using secret scanning tools, such as TruffleHog. </p><p>"Once these keys to the kingdom were harvested, the actor leveraged generative AI in real time to navigate unfamiliar, complex SaaS environments," the report said. </p><p>Examples like this underline how <a href="https://www.itpro.com/security/cyber-crime/trend-micro-vibe-crime-agentic-ai-cyber-crime">AI is supporting cyber crime</a> operations, the report noted, making it easier for hackers to target legitimate tools and weaponize them against victims. </p><p>"The accessibility of <a href="https://www.itpro.com/technology/artificial-intelligence/generative-ai-vs-large-language-models">generative AI large language models (LLMs)</a> both increases unwitting user risk and significantly lowers the barrier to entry for highly effective operations," researchers said . </p><p>"Adversaries have moved beyond technically elegant code to 'offense by the system,' leveraging a victim’s own cloud, <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas">SaaS</a>, and <a href="https://www.itpro.com/infrastructure/ai-infrastructure-global-divide">AI infrastructure</a> to fund and scale missions."</p><h2 id="nation-state-attackers-shift-tactics">Nation-state attackers shift tactics</h2><p>Cloudflare said it has tracked four primary state actors over the last year, namely Russia, China, North Korea, and Iran. The security firm said it was seeing a blurring of strategic goals, with digital strikes increasingly backing up military actions in conflicts. </p><p>China, for example, has shifted away from bulk data theft to targeting legitimate infrastructure such as the cloud for longer-term compromises and strategic "pre positioning" tactics that are ideal for espionage and disruptive operations. </p><p>"By weaponizing legitimate enterprise ecosystems – such as FrumpyToad’s use of Google Calendar for C2 or PunyToad’s exploitation of F5 and VMware vCenter and ESXi – Beijing has created a resilient, living-off-the-cloud architecture that allows for rapid data exfiltration while remaining nearly invisible to standard perimeter defenses," the report noted. </p><p>Notorious Chinese state-backed hacker groups such as Salt Typhoon have employed living off the land techniques extensively over the last two years, most notably during <a href="https://www.itpro.com/security/cyber-attacks/all-us-forces-must-now-assume-their-networks-are-compromised-after-salt-typhoon-breach">attacks on US State National Guard networks</a> and <a href="https://www.itpro.com/security/cyber-attacks/salt-typhoon-us-congress-email-cyber-attack">US congressional email systems</a>. </p><p>Meanwhile, in Russia, groups like NastyShrew use "high-reputation cloud services" to mask their activities in order to continue targeting Ukrainian critical systems. </p><p>That includes tactical communication apps used by the Ukrainian military, and Cloudflare suggested that was "possibly in support of physical operations."</p><h2 id="the-rise-of-north-korean-it-workers">The rise of North Korean IT workers</h2><p>Cloudflare has also observed what it calls the "industrialization" of a scheme run by North Korea in which AI and other tools are used to <a href="https://www.itpro.com/security/cyber-attacks/north-korean-it-workers-the-growing-threat">pose as American workers to get jobs as remote IT workers</a>. </p><p>"These operatives infiltrate Western organizations by leveraging fraudulent identities and AI-driven deepfakes to bypass video interviews, ultimately funneling hundreds of millions of dollars in revenue back to the regime," the report notes. </p><p>Alongside using AI, threat actors often <a href="https://www.itpro.com/security/fake-north-korean-it-workers-are-rampant-on-linkedin-security-experts-warn-operatives-are-stealing-profiles-to-apply-for-jobs-and-infiltrate-firms">set up digital personas on LinkedIn</a> and GitHub for more legitimacy – sometimes even "renting" the accounts of real American citizens.  </p><p>Once employed, these North Korean workers use <a href="https://www.itpro.com/security/cyber-crime/us-charges-14-members-of-north-korean-it-worker-scam-that-bagged-usd88-million-in-six-years">American-based "laptop farms"</a> that are accessed via remote management and monitoring software from overseas. </p><p>As <em>ITPro </em>previously reported, the number of fake IT worker scams has surged over the last 18 months, prompting security agencies and the FBI to <a href="https://www.itpro.com/security/fbi-issues-guidance-for-enterprises-as-fake-north-korean-it-workers-wreak-havoc">issue advisories on how to tackle the issue</a>. </p><p>Cloudflare said it's possible to spot such behavior, however, and urged organizations to bolster identity checks. </p><p>"Despite these sophisticated tactics, several high-fidelity detection indicators have emerged, including 'impossible travel' login alerts, the presence of mouse-jiggling software, and specific video metadata micro-artifacts consistent with real-time deepfake rendering,” the company said. </p><p>Notably, Cloudflare advised shifting away from traditional perimeter defenses in favor of <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust"><u>zero trust</u></a> biometric verification and stricter geofencing for remote management tools. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ DIY hackers are turning to ‘flat-pack’ malware components to speed up attacks and cut costs ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/diy-hackers-are-turning-to-flat-pack-malware-components-to-speed-up-attacks-and-cut-costs</link>
                                                                            <description>
                            <![CDATA[ While these malware campaigns are very basic, researchers noted “they still work” ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9micgTJB6ymCrHncsBFWMm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/oo8cMGiY5DwjHYxKQ8VLsB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 03 Mar 2026 09:00:00 +0000</pubDate>                                                                                                                                <updated>Tue, 03 Mar 2026 11:24:46 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/oo8cMGiY5DwjHYxKQ8VLsB-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware vector image showing alert symbol with exclamation mark and &#039;malware&#039; written underneath imposed over a digital interface.]]></media:description>                                                            <media:text><![CDATA[Malware vector image showing alert symbol with exclamation mark and &#039;malware&#039; written underneath imposed over a digital interface.]]></media:text>
                                <media:title type="plain"><![CDATA[Malware vector image showing alert symbol with exclamation mark and &#039;malware&#039; written underneath imposed over a digital interface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/oo8cMGiY5DwjHYxKQ8VLsB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber criminals are using “modular <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>components” to create custom campaigns and speed up attacks, according to new research from HP. </p><p>Findings from HP Wolf Security's latest Threat Insights Report<em> </em>show hackers are combining off-the-shelf malware components, usually purchased via cyber crime forums, to wage attacks against enterprises globally. </p><p>Researchers at the firm noted that while early-stage lures and final payloads typically change, attackers are “reusing the same intermediate scripts and installers”. </p><p>This means that threat actors are able to build, customize, and scale campaigns with little effort and at a rapid pace – and it’s a trend that’s gaining traction. HP said it has observed multiple unrelated groups using the same basic building blocks in several campaigns. </p><p>The emergence of this ‘flat-pack’ malware trend aligns closely with the increased use of AI among threat actors, according to HP. Findings from the Threat Insights Report show attackers are also using AI to automate malware delivery as part of a focus on ‘<a href="https://www.itpro.com/security/cyber-crime/anthropic-admits-hackers-have-weaponized-its-tools-and-cyber-experts-warn-its-a-terrifying-glimpse-into-how-quickly-ai-is-changing-the-threat-landscape">vibe-hacking</a>’ techniques. </p><p>In one example cited by the company, threat actors used AI to create a fake invoice PDF which triggered a silent download from a compromised site. Thereafter, this redirected unsuspecting users to trusted platforms such as <a href="http://booking.com"><u>Booking.com</u></a> to curb their suspicions.</p><p>Alex Holland, principal threat researcher at HP Security Lab, said the increased use of AI in malware operations, combined with the focus on ‘flat-pack’ components, shows threat actors are prioritizing faster attacks and cheaper costs. </p><p>“It’s the classic project management triangle - speed, quality, and cost,” he said. “You often sacrifice one of them. What we’re seeing is many attackers are optimizing for speed and cost, not quality.”</p><p>“They are not using AI to raise the bar; they’re using it to move faster and reduce effort.”</p><p>Holland further warned that although these campaigns are often basic in nature, the “uncomfortable reality is they still work”. </p><h2 id="ai-malware-is-taking-off">AI malware is taking off</h2><p>The HP research comes in the wake of repeated warnings over the use of AI to build and fine-tune malware. As <em>ITPro </em>reported last month, research from Zscaler shows hackers are <a href="https://www.itpro.com/security/they-are-able-to-move-fast-now-ai-is-expanding-attack-surfaces-and-hackers-are-looking-to-reap-the-same-rewards-as-enterprises-with-the-technology"><u>leveraging the technology to create more potent malware strains</u></a>. </p><p>Google also warned that threat actors were found <a href="https://www.itpro.com/technology/artificial-intelligence/google-says-hacker-groups-are-using-gemini-to-augment-attacks-and-companies-are-even-stealing-its-models">abusing its Gemini AI models to build malware</a> in early February. </p><p>The use of AI in this instance also goes beyond building malware, however, with the technology also used during the early research and development stages. </p><p>Analysis from Trend Micro in September 2025 warned that <a href="https://www.itpro.com/security/hackers-are-using-ai-to-dissect-threat-intelligence-reports-and-vibe-code-malware"><u>hackers were ‘vibe coding’ malware</u></a> by using AI to dissect publicly available threat intelligence reports. </p><p>This, Trend Micro noted, allowed threat actors to essentially reverse engineer malware strains based on technical blogs from industry stakeholders, create “partial malicious” code, and even mimic other group’s TTPs. </p><p>Ian Pratt, global head of security for personal systems at HP, said the firm’s research highlights the significant risks now posed by threat actors using AI. </p><p>“When attackers can generate and repackage malware in minutes, detection-based defences can’t keep up,” he said. “Instead of trying to spot every variant, organizations need to reduce exposure.”</p><p>Reducing exposure in this sense can be as simple as “containing high-risk activities” such as warning staff not to open untrusted attachments or clicking unknown links - typical advice given by most enterprises yet often still the source of breaches. </p><p>Separate analysis from the firm showed 14% of email threats identified by HP Sure Click bypassed one or more email gateway scanners, underlining the increasing success rates of threat actors. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security expert warns Salt Typhoon is becoming 'more dangerous' after Norwegian authorities lift lid on critical infrastructure hacking campaign ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/salt-typhoon-norway-cyber-espionage-warning</link>
                                                                            <description>
                            <![CDATA[ The Chinese state-backed hacking group has waged successful espionage campaigns against an array of organizations across Norway. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5cKy9DBAE3N95B5r2F82im</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uvuxUyoNcxZTsTdMdbPFKG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 09 Feb 2026 10:51:15 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uvuxUyoNcxZTsTdMdbPFKG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Chinese hacker concept image symbolizing the Salt Typhoon threat group, with a man typing on keyboard with People&#039;s Republic of China (PRC) flag in background.]]></media:description>                                                            <media:text><![CDATA[Chinese hacker concept image symbolizing the Salt Typhoon threat group, with a man typing on keyboard with People&#039;s Republic of China (PRC) flag in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Chinese hacker concept image symbolizing the Salt Typhoon threat group, with a man typing on keyboard with People&#039;s Republic of China (PRC) flag in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uvuxUyoNcxZTsTdMdbPFKG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Chinese-backed hacking group known as Salt Typhoon has waged successful espionage campaigns against an array of organizations across Norway, according to the Norwegian Police Security Service. </p><p>No details have been published on which companies were targeted or how long the attackers were able to maintain access. </p><p>However, the report warned Chinese security and intelligence services are increasingly carrying out intelligence operations in Norway, including cyber operations and the collection of human intelligence.</p><p>"In 2026, China will collect intelligence, reconnoiter Norwegian digital infrastructure and threaten groups and individuals to prevent them from criticizing the Chinese Communist Party," the <a href="https://www.pst.no/wp-content/uploads/2026/02/National-Threat-Assessment-2026.pdf" target="_blank"><u>report </u></a>reads.</p><p>"An increasing number of operations are likely to be carried out by commercial <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>contractors and individuals who are not trained intelligence personnel but act on behalf of Chinese security and intelligence services."</p><p>Norwegian authorities warned any organizations holding sensitive information to be on the alert, particularly those operating in national infrastructure domains. </p><p>Salt Typhoon has mainly focused on targets in the US and Canada, but analysis shows the group is expanding operations globally. In September last year, the <a href="https://www.itpro.com/security/cyber-attacks/fbi-warns-indiscriminate-salt-typhoon-hacking-campaign-has-hit-organizations-in-more-than-80-countries">FBI warned the group had hit organizations in as many as 80 countries</a> altogether. </p><p>The <a href="https://www.itpro.com/security/what-is-cisa">US Cybersecurity and Infrastructure Security Agency (CISA)</a> said it was mainly targeting telecommunications, government, transportation, lodging, and military infrastructure networks.</p><p>Salt Typhoon typically targets large backbone routers of major telecommunications providers and network infrastructure companies, as well as provider edge (PE) and customer edge (CE) routers. </p><p>They also leverage compromised devices and trusted connections to pivot into other networks, modifying routers to maintain persistent, long-term access to networks.</p><h2 id="salt-typhoon-is-getting-bolder">Salt Typhoon is getting bolder</h2><p>Pete Luban, Field CISO at AttackIQ, warned the group is becoming “more dangerous with each successful infiltration” and has established itself as a key adversary for national security agencies globally. </p><p>Salt Typhoon gained notoriety after <a href="https://www.itpro.com/security/cyber-attacks/salt-typhoon-hacker-group-recorded-conversations-of-very-senior-us-political-figures"><u>compromising email systems belonging to “very senior” US political figures</u></a> as part of an intelligence gathering campaign. </p><p>These long-running campaigns have become a hallmark of the group, which also managed to <a href="https://www.itpro.com/security/cyber-attacks/all-us-forces-must-now-assume-their-networks-are-compromised-after-salt-typhoon-breach"><u>avoid detection in US National Guard networks for nearly a year</u></a>. </p><p>"Continued access into internal systems allows threat actors to establish long-term surveillance and position themselves to carry out destructive attacks with little to no advanced warning," Luban said. </p><p>"However, breaches like these also deal indirect damage by undermining the security of intelligence sharing networks. If Salt Typhoon can sow seeds of doubt into these networks, it could force allies to limit or restrict information sharing, ultimately weakening collective security."</p><p>Organizations are advised to identify where vulnerabilities might exist in their infrastructure and mitigate them before threat actors can exploit them. </p><p>These networks should be segmented from internet-facing systems, while enforcement of zero-trust access controls can also help contain any damages caused by Salt Typhoon if defenses are breached.</p><p>The report also warned that Chinese intelligence services are recruiting Norwegian nationals to gain access to sensitive and classified information.</p><p>Often, those being recruited don't know they're working for Chinese intelligence, thinking they're employed by a think tank, an international company, a consultancy firm or similar.</p><p>"Sources are initially asked to provide non-public information in exchange for payment, such as details on the activities or plans of companies, public sector organisations of political institutions," it said.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The FBI has seized the RAMP hacking forum, but will the takedown stick? History tells us otherwise ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/the-fbi-has-seized-the-ramp-hacking-forum-but-will-the-takedown-stick-history-tells-us-otherwise</link>
                                                                            <description>
                            <![CDATA[ Billing itself as the “only place ransomware allowed", RAMP catered mainly for Russian-speaking cyber criminals ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9MuHqZhvZQ6Bwhq8kvCxDk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RSjE8LWxBzgjnadXPUW8mB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 30 Jan 2026 10:56:12 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RSjE8LWxBzgjnadXPUW8mB-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker concept image showing a silhouetted person in a black hat with binary code in background. ]]></media:description>                                                            <media:text><![CDATA[Hacker concept image showing a silhouetted person in a black hat with binary code in background. ]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker concept image showing a silhouetted person in a black hat with binary code in background. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RSjE8LWxBzgjnadXPUW8mB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The FBI has seized the clearnet and <a href="https://www.itpro.com/security/32117/what-is-the-dark-web">dark web</a> domains of the RAMP underground hacking forum, used by <a href="https://www.itpro.com/security/29332/the-rise-of-ransomware-as-a-service">Ransomware as a Service (RaaS)</a> gangs and other cyber criminals.</p><p>While there's no official statement as yet, the domains now display banners reading "The Federal Bureau of Investigation has seized RAMP." </p><p>The notice adds that the action was carried out in coordination with the US Attorney's Office for the Southern District of Florida and the Computer Crime and Intellectual Property Section of the Department of Justice.</p><p>The takedown also appears to be confirmed by "Stallman", said to be one of RAMP's owners, in an XSS hacking forum post translated from Russian and <a href="https://x.com/DarkWebInformer/status/2016545523608539381" target="_blank"><u>shared on X</u></a>.</p><p>"With regret, I inform you that law enforcement agencies have gained control over the Ramp forum," it reads. </p><p>"Despite the fact that I no longer control Ramp and will not be creating a new forum from scratch, I will continue to buy accesses,” the statement adds. “My core business remains unchanged. If you have something you can offer me, the terms are listed in my signature, message me in private messages, and we will exchange via Jabber/Tox."</p><h2 id="what-you-need-to-know-about-ramp">What you need to know about RAMP</h2><p>RAMP - which originally stood for Russian Anonymous Marketplace - was a highly popular dark web forum that catered mainly for Russian-speaking cyber criminals, including RaaS gangs and initial access brokers. </p><p>It billed itself as the “only place ransomware allowed", and ransomware groups including Qilin, LockBit, DragonForce, RansomHub, and ALPHV/BlackCat promoted their RaaS services there. </p><p>The site also included discussion groups and cyber attack tutorials.</p><p>"The reason for its success was that it offered criminals a marketplace supporting the entire attack chain, from the ability to buy stolen credentials, promote malware or sell and purchase ransomware services," said Ben Clarke, SOC manager at CybaVerse.</p><h2 id="will-the-takedown-stick">Will the takedown stick?</h2><p>Clarke added that while the takedown will affect criminal activity for a while, the long-term impact could be minimal.</p><p>"Anything to disrupt this activity is a positive step for defenders. But we would be naive to believe it will a tangible impact on cyber crime," he said. "New marketplaces will be formed to take RAMP’s place, while threat actors will navigate to other platforms to buy and sell services."</p><p>Law enforcement takedowns in recent years have achieved mixed results. While they do disrupt operations, forums are often revived, as with the <a href="https://www.itpro.com/security/malware/358450/europol-takes-down-dangerous-emotet-botnet"><u>Emotet botnet takedown</u></a> in 2022. In this instance, the <a href="https://www.itpro.com/security/cyber-attacks/369526/hundreds-of-thousands-of-emotet-attacks-spotted-daily-after-hiatus"><u>botnet returned with a vengeance</u></a>.</p><p>This doesn't mean that these operations are futile, however. Daniel Wilcock, threat intelligence analyst at Talion, said takedowns are still a key tactic for law enforcement to stifle cyber criminal activities and gain vital intelligence. </p><p>"While this doesn't signal the end of ransomware, law enforcement will be able to gain valuable information from the seizure around the threat actors using the services, such as their emails and IP addresses plus access to the financial transactions that took place on the market," he said.</p><p>"This could support further law enforcement action against the threat actors that used the site, but given that RAMP was heavily used by Russian criminals it's highly unlikely we will see many actual arrests." </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft just took down notorious cyber crime marketplace RedVDS – and found hackers were using ChatGPT and its own Copilot tool to wage attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/redvds-cyber-crime-takedown-microsoft-chatgpt-copilot</link>
                                                                            <description>
                            <![CDATA[ Microsoft worked closely with law enforcement to take down the notorious RedVDS cyber crime service – and found tools like ChatGPT and its own Copilot were being used by hackers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xzuWPQywa2MVPA83CQJ2D5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7F8eeczqdKrpFNsWATj8VL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 15 Jan 2026 11:51:51 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7F8eeczqdKrpFNsWATj8VL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft logo illuminated on the side of a building a night time in Tromso, Norway.]]></media:description>                                                            <media:text><![CDATA[Microsoft logo illuminated on the side of a building a night time in Tromso, Norway.]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft logo illuminated on the side of a building a night time in Tromso, Norway.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7F8eeczqdKrpFNsWATj8VL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Notorious cyber crime marketplace RedVDS is no more after a Microsoft strike knocked the <a href="https://www.itpro.com/security/23200/crime-as-a-service-lowers-entry-barriers-to-cybercrime-world">Cybercrime as a Service</a> community offline. </p><p>While the name of the site may not be familiar, its impact has been felt widely across the globe in recent years. Microsoft said activity linked to RedVDS infrastructure had compromised more than 191,000 organizations globally since September, enabling $40 million in fraud in the US alone since March 2025. </p><p>RedVDS was an online subscription service that let hackers launch attacks using <a href="https://www.itpro.com/612016/what-is-virtualisation">virtual computers</a> – often running unlicensed versions of Windows. </p><p>Steven Masada, assistant general counsel for Microsoft’s Digital Crimes Unit, said the online community made fraud “cheap, scalable, and difficult to trace”.</p><div class="product"><a data-dimension112="4dd237b1-f40f-4197-bb0e-ab5deb029444" data-action="Deal Block" data-label="Make Password Security Your New Year's Resolution" data-dimension48="Make Password Security Your New Year's Resolution" href="https://click.linksynergy.com/deeplink?id=kXQk6%2AivFEQ&mid=42966&u1=itpro-gb-1046892004221913649&murl=https%3A%2F%2Fwww.keepersecurity.com%2Fen_GB%2Fnew-year-resolution.html" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://click.linksynergy.com/deeplink?id=kXQk6%2AivFEQ&mid=42966&u1=itpro-gb-1046892004221913649&murl=https%3A%2F%2Fwww.keepersecurity.com%2Fen_GB%2Fnew-year-resolution.html" target="_blank" rel="sponsored" data-dimension112="4dd237b1-f40f-4197-bb0e-ab5deb029444" data-action="Deal Block" data-label="Make Password Security Your New Year's Resolution" data-dimension48="Make Password Security Your New Year's Resolution" data-dimension25="">Make Password Security Your New Year's Resolution</a></p><p>Get 50% off Keeper Personal and Family plans, and 30% off Keeper Business Starter today!<a class="view-deal button" href="https://click.linksynergy.com/deeplink?id=kXQk6%2AivFEQ&mid=42966&u1=itpro-gb-1046892004221913649&murl=https%3A%2F%2Fwww.keepersecurity.com%2Fen_GB%2Fnew-year-resolution.html" target="_blank" rel="nofollow" data-dimension112="4dd237b1-f40f-4197-bb0e-ab5deb029444" data-action="Deal Block" data-label="Make Password Security Your New Year's Resolution" data-dimension48="Make Password Security Your New Year's Resolution" data-dimension25="">View Deal</a></p></div><p>"Services like these have quietly become a driving force behind today’s surge in cyber‑enabled crime, powering attacks that harm individuals, businesses, and communities worldwide,” Masada said in a <a href="https://blogs.microsoft.com/on-the-issues/2026/01/14/microsoft-disrupts-cybercrime/" target="_blank"><u>blog post</u></a> confirming the takedown.</p><h2 id="what-was-redvds">What was RedVDS?</h2><p>RedVDS started operations in 2019, offering hackers low-cost virtual services on a marketplace via a subscription service, with prices as low as $40 dollars in some instances.</p><p>"RedVDS is an infrastructure service that facilitated malicious activity, but unlike malware, it did not perform harmful actions itself; the threat came from how criminals used the servers after provisioning," <a href="https://www.microsoft.com/en-us/security/blog/2026/01/14/inside-redvds-how-a-single-virtual-desktop-provider-fueled-worldwide-cybercriminal-operations/" target="_blank"><u>Microsoft said</u></a>. </p><p>Criminals used tools available via RedVDS for spam and <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>emails to route traffic to evade detection or access criminal forums, and to run scripting or automation tools. </p><p>"In these schemes, attackers gain unauthorized access to email accounts, quietly monitor ongoing conversations, and wait for the right moment, such as an upcoming payment or wire transfer," Masada explained. </p><p>"At that point, they impersonate a trusted party and redirect funds, often moving the money within seconds."</p><p>Microsoft said it spotted plenty of legitimate tools being used on RedVDS hosts by criminals to build their malicious campaigns, including <a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/367994/vpn-or-virtual-private-networks-what-businesses">VPNs</a>, remote admin tool AnyDesk, and AI tools such as <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses">ChatGPT </a>and even its own <a href="https://www.itpro.com/technology/artificial-intelligence/microsoft-copilot-review-ai-baked-into-your-apps">Copilot</a>. </p><p>"RedVDS is frequently paired with <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai">generative AI</a> tools that help identify high‑value targets faster and generate more realistic, multimedia message email threads that mimic legitimate correspondences," Masada said. </p><p>"In hundreds of cases, Microsoft observed attackers further augment their deception by leveraging face-swapping, video manipulation, and voice cloning <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">AI tools</a> to impersonate individuals and deceive victims."</p><h2 id="redvds-victims-consider-legal-action">RedVDS victims consider legal action</h2><p>A host of major companies worldwide have been impacted by RedVDS in its seven-year history. Victims include H2-Pharma, an American pharmaceutical company that lost $7.3m. </p><p>Meanwhile, the Gatehouse Dock Condominium Association in Florida lost $500,000 in a scam. Both are plaintiffs in the civil action against RedVDS, Microsoft noted. </p><p>The takedown is the result of a far-reaching operation which saw coordinated legal action in the US and UK. The tech giant said it worked closely with law enforcement agencies such as Europol in the effort. </p><p>Microsoft and its partners have taken over "key malicious infrastructure", including two domains that host the marketplace.  </p><h2 id="how-microsoft-cracked-the-case">How Microsoft cracked the case</h2><p>RedVDS operated similarly to various other Cybercrime as a Service schemes. According to Microsoft, the site offered unlicensed Windows-based Remote Desktop Protocol (RDP) servers with full administrator control and no usage limits. </p><p>Hackers behind the service boasted that its system could set up a fresh host within minutes — offering scalability to its clients. </p><p>Notably, the scheme was blown open after Microsoft investigators found a “single, cloned Windows host image” that was being reused across the service. This, researchers explained, left “unique technical fingerprints that defenders could leverage for detection."</p><p>Microsoft noted that RedVDS provided virtual Windows cloud servers, but all were generated from a single Windows Server 2022 image via RDP – another mistake that gave researchers vital clues.</p><p>"All RedVDS instances identified by Microsoft used the same computer name, WIN-BUNS25TD77J, an anomaly that stood out because legitimate cloud providers randomize hostnames," Microsoft added. </p><p>RedVDS didn't own any data centers for its operations, instead renting servers from five hosting companies in the US, Canada, UK, France and Netherlands. That allowed RedVDS to offer services in different regions, helping to evade security filters, and more easily blend attacks with normal data centre traffic, Microsoft noted. </p><p>Microsoft said efforts were underway to identify the individuals who ran the site, but said it tracks the threat actor as Storm-2470. </p><h2 id="how-can-enterprises-protect-themselves">How can enterprises protect themselves?</h2><p>What can businesses do to avoid being subject to such attacks? Microsoft noted that most of RedVDS-related attacks involved <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a>, phishing operations, and <a href="https://www.itpro.com/security/cyber-attacks/what-is-business-email-compromise-bec">business email compromise (BEC)</a>.</p><p>To defend against phishing and BEC attacks, Microsoft said to focus on primary gateways such as email and authentication by hardening credentials and <a href="https://www.itpro.com/cloud/cloud-security/are-your-cloud-resources-at-risk">cloud identities</a>, and to invest in user awareness training such as phishing simulations. </p><p>"Simple steps can significantly reduce risk, including slowing down and questioning urgency, calling points of contact back using numbers that are already known to you, verifying payment requests using additional contact information, enabling multifactor authentication, watching carefully for subtle changes in email addresses, keeping software up to date, and reporting suspicious activity to law enforcement," Masada added. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hacked London council warns 100,000 households at risk of follow-up scams ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/kensington-and-chelsea-council-cyber-attack-data-breach</link>
                                                                            <description>
                            <![CDATA[ The council is warning residents they may be at increased risk of phishing scams in the wake of the cyber attack. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wZ7G9ZrPZjmFuj5WHFTupd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FAsuGpEyETVLrjxktBXe5B-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 08 Jan 2026 12:04:34 +0000</pubDate>                                                                                                                                <updated>Thu, 08 Jan 2026 13:55:21 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FAsuGpEyETVLrjxktBXe5B-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Fallen leaves pictured on the pavement outside residential townhouses in London&#039;s Kensington Gardens area, part of the Kensington and Chelsea Council district.]]></media:description>                                                            <media:text><![CDATA[Fallen leaves pictured on the pavement outside residential townhouses in London&#039;s Kensington Gardens area, part of the Kensington and Chelsea Council district.]]></media:text>
                                <media:title type="plain"><![CDATA[Fallen leaves pictured on the pavement outside residential townhouses in London&#039;s Kensington Gardens area, part of the Kensington and Chelsea Council district.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FAsuGpEyETVLrjxktBXe5B-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A London council has written to hundreds of thousands of residents to warn them that criminals may use details leaked via a cyber attack last year to target them for scams. </p><p>At the end of November, Kensington and Chelsea was one of a <a href="https://www.itpro.com/security/cyber-attacks/hammersmith-and-fulham-council-cyber-attacks"><u>trio of west London councils that suffered an outage</u></a> that was quickly <a href="https://www.itpro.com/security/cyber-attacks/ncsc-called-in-as-london-councils-grapple-with-cyber-attacks"><u>attributed to a cyber attack</u></a>. </p><p>A week later, the council confirmed that personal <a href="https://www.itpro.com/security/hacking/data-was-likely-leaked-in-council-hack"><u>data was likely leaked</u></a>, though it stressed it was only "historical data". </p><p>Now, a spokesperson for the council has said the attackers had "criminal intent", with the council's <a href="https://www.rbkc.gov.uk/newsroom/we-are-responding-cyber-security-issue" target="_blank"><u>website</u></a> adding that sensitive data and personal information that could impact residents had been accessed by the attackers. </p><p>Council leader Elizabeth Campbell said the "serious" breach required action from the council, with an update in the middle of December saying 100,000 households had already been contacted with warnings following the attack. </p><p>A spokesperson told <em>ITPro </em>the letters were sent out at the beginning of December, and the message references the attack of "two weeks ago". </p><p>"We decided to go out immediately and say to people this is what's happened, this data has been copied and it has been taken and you should be aware therefore you are at risk," she told the <a href="https://www.bbc.co.uk/news/articles/ce3knggd1lwo" target="_blank"><u><em>BBC</em></u></a>. </p><h2 id="written-warning">Written warning</h2><p>In a copy of the letter shared with <em>ITPro </em>by the council, recipients are advised to be wary of scam messages, check online accounts for unusual activity, and report any suspicious activity to the <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a>.</p><p>"Like any local authority, it was always possible that our systems could come under attack and therefore we had invested significantly in our digital, data and technology services over many years," Campbell said in the letter. </p><p>"This meant that we had a cyber defence system that was able to spot this attack quickly and protect much of our infrastructure, and the infrastructure of others, as best as possible."</p><p>Campbell added: "Despite this, we do believe that some data has been copied and taken. It is important to say we still have access to this information, but it is possible a copy could end up in the public domain. As a priority we are checking if this contains any personal or financial details of residents, customers, and service users. This may take months and we will update residents at every step."</p><p>The council is now "going through all the documentation" to spot any specific risks and will contact individuals directly if affected, though it noted that work may take months. </p><p>Similarly, the local authority said it was checking which details in files may have been accessed, admitting that work may yield nothing, but said "we want to make sure we turn over every stone."</p><h2 id="what-happened">What happened</h2><p>The attack began on the morning of 24 November, and was immediately spotted by staff at Kensington and Chelsea, who took steps to isolate systems. </p><p>A week later, that council admitted some data had been accessed, including sensitive information; however, it stressed the data wasn't encrypted by the attackers, such as in a <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>attack, and therefore remained accessible to the council. </p><p>Hammersmith and Fulham Council and Westminster City Council were the other two local authorities hit by the outage, as the three organizations share some systems. </p><p>Hammersmith has said it so far appears its systems were not compromised, while Westminster earlier this month <a href="https://www.bbc.co.uk/news/articles/czrke560ze3o.amp" target="_blank"><u>confirmed</u></a> that "limited data" had been breached. </p><p>Keven Knight, CEO of Talion, told <em>ITPro </em>last year that councils are a prime target for cyber criminals, largely due to the scope of personal and financial information they hold on residents.</p><p>"This is the type of information that can’t be changed easily. This means it's now in the hands of a threat actor, and victims will be exposed to an increased risk of <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a>," he said.</p><p>The <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner's Office (ICO)</a> has been informed of the incident, and the Metropolitan Police and NCSC are investigating. So far, there's no indication who is behind the attack. </p><p>"The Met is leading an investigation and we are working alongside them with the national cyber security centre and the NCC Group," a spokesperson for Kensington and Chelsea council said. </p><p>"We are taking steps to work through the data in accordance with ICO and legal rules."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cyber crime group claims successful attack on security firm, crows about it on Telegram – but it was all an elaborate honeypot ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime-group-claims-successful-attack-on-security-firm-crows-about-it-on-telegram-but-it-was-all-an-elaborate-honeypot</link>
                                                                            <description>
                            <![CDATA[ Scattered LAPSUS$ Hunters thought it had access to vast amounts of Resecurity's internal data, but the whole thing was just a set-up ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cHg8Yz29i5ZEo3y72PTUoM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 05 Jan 2026 10:33:02 +0000</pubDate>                                                                                                                                <updated>Mon, 05 Jan 2026 10:33:55 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:description>                                                            <media:text><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Notorious cyber crime group <a href="https://www.itpro.com/security/cyber-crime/15-year-old-revealed-as-key-player-in-scattered-lapsus-usd-hunters">Scattered LAPSUS$ Hunters</a> has been left red-faced after boasting about a data breach that turned out to be a <a href="https://www.itpro.com/cloud/362460/how-to-use-the-cloud-as-a-honeypot">honeypot</a>. </p><p>The group posted screenshots on Telegram, which have since been taken down, claiming to have gained full access to systems belonging to <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>firm Resecurity. </p><p>As reported by <a href="https://databreaches.net/2026/01/03/shinyhunters-claims-to-have-compromised-resecurity-but-it-looks-like-they-fell-for-a-honeypot/" target="_blank"><u><em>DataBreaches</em></u></a>, the post claimed Scattered LAPSUS$ Hunters had gained access to all internal chats and logs, employee data such as names and email addresses, as well as threat intelligence and client lists. </p><p>"They go around telling companies they will 'protect' them from cyber attacks, sell expensive services, act like experts... but in the end, just like we did with <a href="https://www.itpro.com/security/cyber-attacks/crowdstrike-insider-attack-wake-up-call">CrowdStrike </a>and the FBI, they got fully owned :(((," crowed the group.</p><p>The gloating by the cyber crime group was short-lived, however, with Scattered LAPSUS$ Hunters having fallen victim to a honeypot campaign conducted by researchers at Resecurity. </p><h2 id="how-the-honeypot-worked">How the honeypot worked</h2><p>In November, the company detected a threat actor attempting to conduct malicious activity, sniffing around various publicly facing services and applications. It also targeted one of the company's employees who had no sensitive data or privileged access.</p><p>"Understanding that the actor is conducting reconnaissance, our team has set up a honeytrap account. This led to a successful login by the threat actor to one of the emulated applications containing synthetic data," said the company in a <a href="https://www.resecurity.com/blog/article/synthetic-data-a-new-frontier-for-cyber-deception-and-honeypots"><u>blog</u></a>. </p><p>"While the successful login could have enabled the actor to gain unauthorized access and commit a crime, it also provided us with strong proof of their activity."</p><p>The honeypot scheme used <a href="https://www.itpro.com/technology/artificial-intelligence/what-is-synthetic-data">synthetic data</a> – purposely generated data with the patterns and characteristics of real-world data, but that doesn't contain any actual proprietary information.</p><p>In this case, this data included more than 28,000 synthetic consumer records and over 190,000 synthetic payment transaction records. </p><p>"In the context of threat hunting, previously breached data can be highly effective for designing deception models that appear extremely realistic and attract threat actors," said Resecurity. </p><p>"For example, a purposely planted honeypot — containing realistically looking (but practically useless) records — can motivate threat actors to attempt to steal it."</p><h2 id="patience-is-a-virtue">Patience is a virtue</h2><p>Researchers at Resecurity waited, and on December 12 the group resumed activity, making more than 188,000 requests attempting to dump the synthetic data over the next two weeks. It then aimed to scrape the data using malicious automation.</p><p>At one point, the threat actor inadvertently disclosed their real IP addresses. This misstep, along with other mistakes, allowed Resecurity to identify the exact servers being used for automation, despite the use of lists of residential IP proxies to spoof the source.</p><p>"The group called ShinyHunters, previously profiled by Resecurity, fell into a honeypot," Resecurity said. "In fact, we are dealing with their rebranded version, which calls itself "Scattered Lapsus$ Hunters," due to the alleged overlap between the threat actors ShinyHunters, Lapsus$, and <a href="https://www.itpro.com/security/cyber-attacks/scattered-spider-airline-industry-attacks">Scattered Spider</a>."</p><p>According to Resecurity, information on the threat actors acquired through the campaign has been provided to law enforcement agencies investigating the group. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cybersecurity experts face 20 years in prison following ransomware campaign ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/cybersecurity-experts-face-20-years-in-prison-following-ransomware-campaign</link>
                                                                            <description>
                            <![CDATA[ Two men used their tech expertise to carry out ALPHV BlackCat ransomware attacks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YwMMNB6gfVuwvTVR73aFEU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LEn4RWFLrJ7FxZPhnQgKsP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 02 Jan 2026 14:16:08 +0000</pubDate>                                                                                                                                <updated>Mon, 05 Jan 2026 09:09:08 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                        <dc:contributor><![CDATA[ Jane McCallion ]]></dc:contributor>
                                                                    <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LEn4RWFLrJ7FxZPhnQgKsP-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[FBI seal and insignia pictured on the FBI headquarters building in Washington D.C., United States.]]></media:description>                                                            <media:text><![CDATA[FBI seal and insignia pictured on the FBI headquarters building in Washington D.C., United States.]]></media:text>
                                <media:title type="plain"><![CDATA[FBI seal and insignia pictured on the FBI headquarters building in Washington D.C., United States.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LEn4RWFLrJ7FxZPhnQgKsP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Two US cybersecurity experts have pleaded guilty to using ALPHV BlackCat ransomware to extort businesses across the USA during a seven-month campaign in 2023.</p><p>40-year-old Ryan Goldberg of Georgia and 36-year-old Kevin Martin of Texas, admitted conspiring to obstruct, delay, or affect commerce through extortion <a href="https://www.justice.gov/opa/pr/two-americans-plead-guilty-targeting-multiple-us-victims-using-alphv-blackcat-ransomware"><u>in a federal district court in the Southern District of Florida</u></a>. </p><p>Goldberg was an incident response manager at the time he and Martin, as well as one other unnamed individual, turned their skills to nefarious activities. Martin, meanwhile, was a ransomware threat negotiator. </p><p>Their campaign, which ran from April to December 2023, saw the trio turn to ALPHV BlackCat ransomware as a service operators, who they agreed to pay 20% share of any ransoms received in exchange for access to the ransomware and extortion platform</p><p>They then successfully used the malware against numerous US targets, including a pharmaceutical company based in Maryland, an engineering company based in California, a drone manufacturer in Virginia, and a medical company from Florida, where the case was heard.</p><p>One victim paid the equivalent of $1.2 million in Bitcoin in order to put an end to the attack, with the proceeds split three ways between the conspirators after they had given the ALPHV BlackCat administrators their cut.</p><p>Assistant attorney general A. Tysen Duva of the Justice Department’s Criminal Division said: “These defendants used their sophisticated cybersecurity training and experience to commit ransomware attacks — the very type of crime that they should have been working to stop.” </p><h2 id="millions-of-dollars-saved-following-ransomware-disruption">Millions of dollars saved following ransomware disruption</h2><p>ALPHV BlackCat was active for 18 months before the FBI developed a decryption tool for the ransomware, extorting millions of dollars from businesses primarily in the US before going dark in December 2023. The law enforcement agency estimates it saved victims in the order of $99 million in ransomware payments.</p><p>“The FBI remains committed to working alongside its law enforcement partners to disrupt and dismantle criminal enterprises involved in ransomware attacks and to hold accountable not only the perpetrators but also anyone who knowingly enables or profits from them,” said special agent in charge Brett Skiles of the FBI Miami Field Office. </p><p>US attorney Jason A Reding Quiñones, representing the Southern District of Florida, said: “Goldberg and Martin used trusted access and technical skill to extort American victims and profit from digital coercion.”</p><p>“Their guilty pleas make clear that cybercriminals operating from within the United States will be found, prosecuted, and held to account,” he added.</p><p>The pair are set to be sentenced on 12 March 2026 and face a maximum penalty of 20 years in prison.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Trend Micro issues warning over rise of 'vibe crime' as cyber criminals turn to agentic AI to automate attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/trend-micro-vibe-crime-agentic-ai-cyber-crime</link>
                                                                            <description>
                            <![CDATA[ Trend Micro is warning of a boom in 'vibe crime' - the use of agentic AI to support fully-automated cyber criminal operations and accelerate attacks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ywnrH7u267qTjEXLD2mHkF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/288LYNa6Bw9URT5mvTzTkZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 11 Dec 2025 08:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/288LYNa6Bw9URT5mvTzTkZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Agentic AI cyber crime concept image showing digital system with padlock symbol with glowing data flow passing through.]]></media:description>                                                            <media:text><![CDATA[Agentic AI cyber crime concept image showing digital system with padlock symbol with glowing data flow passing through.]]></media:text>
                                <media:title type="plain"><![CDATA[Agentic AI cyber crime concept image showing digital system with padlock symbol with glowing data flow passing through.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/288LYNa6Bw9URT5mvTzTkZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Trend Micro is warning of a boom in 'vibe crime' - the use of <a href="https://www.itpro.com/technology/artificial-intelligence/practical-ai-the-age-of-agentic-ai">agentic AI</a> to support fully-automated cyber criminal operations that go way beyond today’s <a href="https://www.itpro.com/security/ransomware">ransomware </a>and phishing campaigns. </p><p>In a <a href="https://documents.trendmicro.com/assets/research-reports/crimininal-agentic-ai_research-paper.pdf" target="_blank"><u>new report</u></a>, the cybersecurity firm predicted that agentic AI will massively increase attack volume, with automated phishing, fraud, and breach exploitation becoming continuous background operations. </p><p>Criminal ecosystems will move from a traditional <a href="https://www.itpro.com/security/23200/crime-as-a-service-lowers-entry-barriers-to-cybercrime-world">Cybercrime as a Service</a> model to what Trend Micro called 'Cybercrime as a Servant’, relying on chained AI agents and autonomous orchestration layers to run criminal businesses end-to-end. </p><p>“Agentic AI gives criminals a ready-made arsenal that scales, adapts, and keeps working even when the humans disappear. The real risk is not a sudden AI-fueled explosion of crime, but the slow, unstoppable automation of attacks that used to require skill, time, and effort. This shift is already underway,” said Robert McArdle, director of forward-looking threat research at Trend Micro.</p><p>“We will see an optimization of today’s leading attacks, the amplification of attacks that previously had poor ROI, and the emergence of brand new ‘Black Swan’ cybercrime business models.”  </p><p>Researchers said they expect to see more attacks on enterprise cloud and <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>systems, as these provide cyber criminals scalable power, compute, AI capabilities, <a href="https://www.itpro.com/hardware/desktops/storage">storage</a>, and access to valuable information they can use to run their agentic architecture. </p><p>This, the company warned, will introduce new kinds of attacks – many of which are unprecedented, or expected to grow in scale. Meanwhile, agentic cyber crime will influence the overall setup of today’s criminal ecosystem, giving rise to new or enhanced criminal business models and trends.</p><p>Looking ahead, Trend Micro said defensive platforms and security solutions will need their own orchestrators and autonomous agents to counter the shift, or risk being overwhelmed. </p><p>“For enterprises, this means reassessing <a href="https://www.itpro.com/enterprise-security/34017/who-should-take-ownership-of-your-cyber-security-strategy">security strategy</a> now as well as investing in automation and AI-driven defence," McArdle said.</p><p>"Organizations also have to ensure resilience before criminals industrialize their own use of AI, or risk trying to catch up in an exponential arms race that will quickly separate those who were prepared and those were not.” </p><h2 id="agentic-ai-security-warnings-ramp-up">Agentic AI security warnings ramp up</h2><p>Trend Micro is by no means the first firm to warn of the looming threat of agentic AI-related cyber crime. </p><p>In September, for example, Anthropic <a href="https://www.itpro.com/security/cyber-crime/anthropic-admits-hackers-have-weaponized-its-tools-and-cyber-experts-warn-its-a-terrifying-glimpse-into-how-quickly-ai-is-changing-the-threat-landscape"><u>admitted</u></a> that its AI tools had been "weaponized" by hackers to conduct serious attacks against organizations.</p><p>The company warned agentic AI is being used across cyber criminal operations, particularly to identify victims, analyze stolen data, and to create ransomware and malware strains. </p><p>In a blog post detailing its findings, Anthropic pointed to examples where cyber criminals used <a href="https://www.itpro.com/software/development/claude-code-is-coming-to-slack-heres-how-to-use-it-what-it-can-do-and-how-to-get-access">Claude Code</a> to automate reconnaissance practices, harvest victim credentials, and penetrate networks at 17 organizations in the healthcare, emergency services, and government sectors. </p><p>A similar study from Malwarebytes in early 2025 also highlighted the growing threat posed by agentic AI in cyber criminal operations. </p><p>The company’s 2025 <a href="https://www.threatdown.com/typ-state-of-malware-2025/" target="_blank"><u><em>State of Malware</em></u><u> report</u></a> said this latest iteration of the technology will “further revolutionize cyber criminal tactics” and <a href="https://www.itpro.com/security/cyber-crime/agentic-ai-cybersecurity-risks"><u>enable threat actors to create more potent malware strains</u></a>. </p><p>While  warnings over the use of agentic AI among cyber criminals are growing, the use of the technology by defenders offers huge potential, industry stakeholders claim. </p><p>AWS CISO Amy Herzog, for example, recently told <em>ITPro </em>that agents <a href="https://www.itpro.com/security/aws-ciso-amy-herzog-thinks-ai-agents-will-be-a-boon-for-cyber-professionals-and-teams-at-amazon-are-already-seeing-huge-gains"><u>will herald a radical shift for cybersecurity practitioners</u></a>, enabling them to react to attacks in a more efficient manner. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/software/development/slopsquatting-is-a-new-risk-for-vibe-coding-developers-but-it-can-be-solved-by-focusing-on-the-fundamentals">‘Slopsquatting’ is a new risk for vibe coding developers</a></li><li><a href="https://www.itpro.com/security/hackers-are-using-ai-to-dissect-threat-intelligence-reports-and-vibe-code-malware">Hackers are using AI to dissect threat intelligence reports and ‘vibe code’ malware</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/agentic-ai-carries-huge-implications-for-security-teams-heres-what-leaders-should-know">Agentic AI carries huge implications for security teams</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 15-year-old revealed as key player in Scattered LAPSUS$ Hunters ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/15-year-old-revealed-as-key-player-in-scattered-lapsus-usd-hunters</link>
                                                                            <description>
                            <![CDATA[ 'Rey' says he's trying to leave Scattered LAPSUS$ Hunters and is prepared to cooperate with law enforcement ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zBxmT5CgDixJiMrXLmNAZf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9AjMFuVUqXnko5FNhrMuKC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 28 Nov 2025 13:23:42 +0000</pubDate>                                                                                                                                <updated>Fri, 28 Nov 2025 13:28:57 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9AjMFuVUqXnko5FNhrMuKC-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker concept image showing young man with hood covering face typing on a keyboard in a dark room.]]></media:description>                                                            <media:text><![CDATA[Hacker concept image showing young man with hood covering face typing on a keyboard in a dark room.]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker concept image showing young man with hood covering face typing on a keyboard in a dark room.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9AjMFuVUqXnko5FNhrMuKC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security researcher Brian Krebs has <a href="https://krebsonsecurity.com/2025/11/meet-rey-the-admin-of-scattered-lapsus-hunters/" target="_blank"><u>unmasked one of the apparent culprits</u></a> behind the Jaguar Land Rover and M&S cyber attacks as a Jordanian teenager. </p><p>Krebs approached the 15-year-old, who had been using the pseudonym ‘Rey’ on Telegram and confirmed his real identity. </p><p>The teenager said he has been in contact with various international law enforcement agencies, such as Europol, and hasn’t carried out any hacking activities since September.</p><p>“I’m already cooperating with law enforcement,” he said. “In fact, I have been talking to them since at least June,” he told Krebs.</p><p>Krebs noted that he was unable to confirm these details following contact with the individual. </p><p>Scattered LAPSUS$ Hunters, of which 'Rey' is just one of three administrators, has been behind numerous extortion attempts. According to Krebs, he was previously an administrator of the data leak website for Hellcat, a <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>group involved in <a href="https://www.itpro.com/security/cyber-attacks/schneider-electric-confirms-breach-after-hacker-claims-to-have-40gb-of-stolen-data">attacks on Schneider Electric</a>, Telefonica, and Orange Romania.</p><p>The teenager was also an administrator of the latest incarnation of English-language leak site, <a href="https://www.itpro.com/security/cyber-crime/fbi-seizes-breachforums-infrastructure-but-successor-sites-are-already-popping-up">BreachForums</a>.</p><p>While cyber crime groups like this are often portrayed as being part of organized crime, 'Rey' is one of a growing number of hackers who turn out to be normal teenagers.</p><h2 id="how-krebs-snared-rey">How Krebs snared ‘Rey’</h2><p>According to Krebs, a series of mistakes enabled him to track him down. While operating under the Telegram username <em>@wristmug</em>, Rey accidentally revealed his password in a screenshot - a password that Krebs was able to link to the email address <em>cybero5tdev@proton.me</em>. </p><p>Data from Spycloud then indicated that Rey’s computer was a shared Microsoft Windows device located in Amman, Jordan, and also used by other family members.</p><p>It's not clear what will happen now. But, Alon Gal, co-founder and <a href="https://www.itpro.com/strategy/28237/cto-job-description-what-does-a-cto-do">CTO </a>at Hudson Rock questioned why “no apparent action” had been taken by law enforcement. </p><p>“Rey is one of the most prolific threat actors of the past few years,” he wrote in a <a href="https://www.linkedin.com/feed/update/urn:li:activity:7399521191767564290/?originTrackingId=WRC4pjJDJ3JDywTf1jvdSQ%3D%3D" target="_blank"><u>post on LinkedIn</u></a>. “I genuinely don’t understand how they let him continue if the dox proves to be accurate."</p><p>In any case, Rey told Krebs: "I don’t really care, I just want to move on from all this stuff even if its going to be prison time or whatever they gonna say.” </p><h2 id="the-rise-of-teen-hackers">The rise of teen hackers</h2><p>It's not unusual for hackers - especially in the various groups associated with Scattered Spider - to turn out to be extremely young. In September, for example, 19-year-old Thalha Jubair and Owen Flowers, 18, were <a href="https://www.itpro.com/security/channel-their-curiosity-into-something-meaningful-cyber-expert-warns-an-uptick-of-youth-hackers-should-be-a-wake-up-call-after-teens-charged-over-tfl-attack"><u>charged</u></a> in the UK for their involvement in an attack on TfL last year.</p><p>Speaking to <em>ITPro </em>at the time, security experts said the uptick in youth-related cyber crime is a serious cause for concern and requires swift action from industry, academia, and law enforcement. </p><p>Anna Chung, principal researcher for EMEA at Palo Alto Networks, said the trend should be a “wake up call” for authorities and called for efforts to encourage tech-savvy teens toward legitimate careers in <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a>. </p><p>According to the UK's <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a>, the biggest cybersecurity risk faced by schools <a href="https://www.itpro.com/security/kids-hacking-for-kicks-are-causing-security-headaches-at-schools"><u>comes from the pupils themselves</u></a>, with around 5% of all 14-year-old boys and girls admitting to ‘hacking’ in some capacity.</p><p>William Wright, CEO of Closed Door Security, said the group boasts close ties to Russian threat actors, which has enabled it to wreak widespread havoc. </p><p>"There will be a lot of concern among the general public around how a 15-year-old could cause so much damage to some of the biggest organisations in the UK. But in reality, it's not so simple. Rey was collaborating with Russian threat actors, using their infrastructure to execute highly sophisticated attacks," he said. </p><p>"Rey claims to be working with law enforcement now, which is causing trouble across the Scattered Lapsus$ Hunter Telegram channel. This could lead to other members of the gang being identified, but Rey may get off lightly if he supports law enforcement enough."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/jaguar-land-rover-cyber-attack-financial-impact-cyber-monitoring-centre">Former NCSC head says the Jaguar Land Rover attack was the 'single most financially damaging cyber event ever to hit the UK'</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/m-and-s-reveals-massive-financial-hit-from-cyber-attack">M&S reveals massive financial hit from cyber attack</a></li><li><a href="https://www.itpro.com/security/hackers-behind-jaguar-land-rover-announce-their-retirement-should-we-believe-them">Hackers behind Jaguar Land Rover announce their 'retirement' – should we believe them?</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ November rundown: CrowdStrike's insider threat ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/podcast-crowdstrikes-insider-threat</link>
                                                                            <description>
                            <![CDATA[ As CrowdStrike grappled with a malicious employee, Cloudflare suffered a major outage ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9by3LAKy3RkFkKYHyr7WFT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YwZ4KQZ9beF2GcwMtqn8pD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 28 Nov 2025 07:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ rory.bathgate@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LFPWMoCGDVHowHbMpHJZkU.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rory Bathgate is the Features and Multimedia Editor at ITPro, overseeing all in-depth content and case studies. He is a subject expert on artificial intelligence and business networks but in his time at ITPro has also covered a wide range of areas including cyber security and hardware. Throughout his time at ITPro, Rory has charted the rise in popularity of generative AI and specifically companies such as Microsoft, OpenAI, and Google. &lt;/p&gt;&lt;p&gt;Alongside this, he has delved into increasing calls for ethical and responsible AI as global legislators circle the technology, as well as the latest in mobile networking technology, from 5G mmWave to the 3G sunset and how it will affect businesses.&lt;/p&gt;&lt;p&gt;He has provided coverage from high-profile tech conferences such as Dell Technologies World, SuiteWorld, and VMware Explore Europe. His on-the-ground coverage has included live blogs, extensive daily coverage of the most significant announcements, analysis pieces, and podcasts.&lt;/p&gt;&lt;p&gt;Indeed, Rory is also a full-time co-host of the ITPro Podcast alongside Jane McCallion, where he swaps a keyboard for a microphone to discuss the latest learnings in tech. Each week, a guest comes onto the show to discuss topics such as cyber security, productivity, or digital transformation in detail.&lt;/p&gt;&lt;p&gt;Rory has an MA in Eighteenth-Century Studies from King’s College London, as well as a BA in English and American Literature from the University of Kent. He joined ITPro in 2022 as a graduate, after four years in student journalism.&lt;/p&gt;&lt;p&gt;In his free time, Rory enjoys photography and video editing, and can often be found at the cinema or reading a good science fiction paperback.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YwZ4KQZ9beF2GcwMtqn8pD-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The text &quot;Crowdstrike&#039;s insider threat&quot; against an orange target symbol on a grey background. The words &quot;insider threat&quot; are in yellow, the rest are in white. In the bottom-right corner, the ITPro Podcast logo is shown.]]></media:description>                                                            <media:text><![CDATA[The text &quot;Crowdstrike&#039;s insider threat&quot; against an orange target symbol on a grey background. The words &quot;insider threat&quot; are in yellow, the rest are in white. In the bottom-right corner, the ITPro Podcast logo is shown.]]></media:text>
                                <media:title type="plain"><![CDATA[The text &quot;Crowdstrike&#039;s insider threat&quot; against an orange target symbol on a grey background. The words &quot;insider threat&quot; are in yellow, the rest are in white. In the bottom-right corner, the ITPro Podcast logo is shown.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YwZ4KQZ9beF2GcwMtqn8pD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <iframe allow="" height="200px" width="100%" id="" style="" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/14616280-6130-4088-921f-e20cfab2c851/"></iframe><p>As a business leader, you’d like to believe that your staff are entirely trustworthy. Effective enterprises run on workforce confidence – but in some cases, that trust can be misplaced.</p><p>In November, CrowdStrike admitted one of its own employees had provided screenshots of internal systems to hackers in exchange for a sizable payout. Industry experts have told ITPro the incident should act as a wake up call to the all-too-serious risk of insider threats.</p><p>Earlier in the month, websites all over the world went offline after a major outage at the content delivery network service provider Cloudflare. What was the cause of the incident: had Cloudflare fallen victim to the kind of DDoS attack it’s famous for preventing?</p><p>In this episode, Jane and Rory welcome back Ross Kelly, ITPro’s news and analysis editor, to explore some of November’s biggest stories.</p><h2 id="highlights-2">Highlights</h2><p>"The individual was believed to have been paid around $25,000 for this, which all things considered, I think, is quite low when you're risking being fired and, you know, a potential jail sentence in the aftermath of this. So these were leaked on Telegram. CrowdStrike, obviously, was made aware of this and they reacted pretty swiftly like we mentioned. That person has since been dismissed, I don't think it was too much of an issue for HR in that situation."</p><p>"A lot of organizations still lack formal insider threat programs. It's something that's just not really on their radar because a lot of the time, the headlines are based around you  ransomware attacks, malware, etc, etc. And so, you know, when you have an individual in your company that's potentially at risk, how do you deal with that?"</p><p>“An outage at Cloudflare, I think, is a worst case scenario for a lot of organizations, a lot of online services."</p><p>“The outage itself was a result of a bug in its bot management software. So, the software that essentially allows websites to allow bots onto their individual sites, or prevent bots from accessing their sites, a bug in that service and that software caused this, which created somewhat of a cascading effect where a lot of websites essentially just were bricked for a good couple of hours."</p><h2 id="footnotes-2">Footnotes</h2><ul><li><a href="https://www.itpro.com/security/cyber-attacks/crowdstrike-insider-attack-wake-up-call">If you're not taking insider threats seriously, then the CrowdStrike incident should be a big wake up call</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/insider-attack-finwise-american-first-finance-data-breach">Nearly 700,000 customers impacted after insider attack at US fintech firm</a></li><li><a href="https://www.itpro.com/security/ai-means-cyber-teams-are-rethinking-their-approach-to-insider-threats">AI means cyber teams are rethinking their approach to insider threats</a></li><li><a href="https://www.itpro.com/security/disgruntled-dev-malicious-code-insider-threat">‘Insiders don’t need to break in’: A developer crippled company networks with malicious code and a ‘kill switch’ after being sacked – and experts warn it shows the huge danger of insider threats</a></li><li><a href="https://www.itpro.com/cloud/32096/everything-you-need-to-know-about-cloudflare">Everything you need to know about Cloudflare</a></li><li><a href="https://www.itpro.com/infrastructure/networking/the-cloudflare-outage-explained-what-happened-who-was-impacted-and-what-was-the-root-cause">The Cloudflare outage explained: What happened, who was impacted, and what was the root cause?</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/cloudflare-says-ai-companies-have-been-scraping-content-without-limits-now-its-letting-website-owners-block-crawlers-by-default">Cloudflare says AI companies have been “scraping content without limits” – now it’s letting website owners block crawlers and force them to pay</a></li><li><a href="https://www.itpro.com/security/security-experts-issue-warning-over-the-rise-of-gray-bot-ai-web-scrapers">Security experts issue warning over the rise of 'gray bot' AI web scrapers</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/cloudflare-is-fighting-back-against-ai-web-scrapers">Cloudflare is fighting back against AI web scrapers</a></li><li><a href="https://www.itpro.com/business/digital-transformation/nearly-half-of-all-digital-initiatives-still-fail-heres-how-you-can-learn-from-the-digital-vanguard-and-deliver-success">Nearly half of all digital initiatives still fail – here’s how you can learn from the ‘digital vanguard’ and deliver success</a></li></ul><h2 id="subscribe-2">Subscribe </h2><ul><li><a href="https://apple.sjv.io/c/221109/473657/7613?subId1=itpro-gb-1243831151189624600&sharedId=itpro-gb&u=https%3A%2F%2Fpodcasts.apple.com%2Fgb%2Fpodcast%2Fthe-itpro-podcast%2Fid1483810154" target="_blank"><u>Subscribe to The IT Pro Podcast on Apple Podcasts</u></a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ" target="_blank"><u>Subscribe to The IT Pro Podcast on Spotify</u></a></li><li><a href="https://www.itpro.co.uk/newsletter-signup"><u>Subscribe to the IT Pro newsletter</u></a></li><li><a href="https://uk.linkedin.com/company/itpro-uk" target="_blank"><u>Join us on LinkedIn</u></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The US, UK, and Australia just imposed sanctions on a Russian cyber crime group – 'we are exposing their dark networks and going after those responsible' ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/the-us-uk-and-australia-just-imposed-sanctions-on-a-russian-cyber-crime-group-we-are-exposing-their-dark-networks-and-going-after-those-responsible</link>
                                                                            <description>
                            <![CDATA[ Media Land offers 'bulletproof' hosting services used for ransomware and DDoS attacks around the world ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jbcE8oNisiHJvQRxooNzLU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Aqeo3GHF5pnDS754K9ahY5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Nov 2025 10:55:00 +0000</pubDate>                                                                                                                                <updated>Fri, 21 Nov 2025 08:31:54 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Aqeo3GHF5pnDS754K9ahY5-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Russian cyber crime concept image showing Russian national flag with padlock symbol in background with smashed glass in foreground.]]></media:description>                                                            <media:text><![CDATA[Russian cyber crime concept image showing Russian national flag with padlock symbol in background with smashed glass in foreground.]]></media:text>
                                <media:title type="plain"><![CDATA[Russian cyber crime concept image showing Russian national flag with padlock symbol in background with smashed glass in foreground.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Aqeo3GHF5pnDS754K9ahY5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK, US, and Australia have imposed sanctions on a Russian cyber crime group offering so-called 'bulletproof' <a href="https://www.itpro.com/network-internet/web-hosting/368170/best-web-hosting-services-in-2022">hosting services</a> for hackers worldwide. </p><p>Media Land provides online infrastructure to support <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> and <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>operations, and is believed to have played a key role in a spate of devastating cyber attacks in recent years. </p><p>Ransomware victims of the outfit include UK <a href="https://www.itpro.com/security/cyber-attacks/why-attacks-against-critical-national-infrastructure-cni-are-such-a-threat">critical national infrastructure</a> organizations and it's also been used for <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>and phishing campaigns targeting UK taxpayers.</p><div class="product"><a data-dimension112="d3621f22-76d8-423e-9d21-6425e3c7656d" data-action="Deal Block" data-label="Catch the price drop today to get 30% OFF for Enterprise and Business plans" data-dimension48="Catch the price drop today to get 30% OFF for Enterprise and Business plans" href="https://go.nordpass.io/aff_c?offer_id=754&aff_id=3013&url_id=31981" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="8aurHnFJraWhwkrtyVHwtD" name="NP-affiliate-black-friday-campaign-1200x1200" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/8aurHnFJraWhwkrtyVHwtD.jpg" mos="" align="middle" fullscreen="" width="1200" height="1200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p>Boost password security and keep your business safe with NordPass B2B.</p><p><a href="https://go.nordpass.io/aff_c?offer_id=754&aff_id=3013&url_id=31981" target="_blank" rel="sponsored" data-dimension112="d3621f22-76d8-423e-9d21-6425e3c7656d" data-action="Deal Block" data-label="Catch the price drop today to get 30% OFF for Enterprise and Business plans" data-dimension48="Catch the price drop today to get 30% OFF for Enterprise and Business plans" data-dimension25="">Catch the price drop today to get 30% OFF for Enterprise and Business plans</a><a class="view-deal button" href="https://go.nordpass.io/aff_c?offer_id=754&aff_id=3013&url_id=31981" target="_blank" rel="nofollow" data-dimension112="d3621f22-76d8-423e-9d21-6425e3c7656d" data-action="Deal Block" data-label="Catch the price drop today to get 30% OFF for Enterprise and Business plans" data-dimension48="Catch the price drop today to get 30% OFF for Enterprise and Business plans" data-dimension25="">View Deal</a></p></div><p>In the US, Media Land infrastructure has been used in <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack">distributed denial of service (DDoS)</a> attacks against companies and critical infrastructure. Meanwhile, in Australia, the group has helped criminals to carry out attacks against financial institutions, businesses, their customers, and critical infrastructure. </p><p>"Cyber criminals think that they can act in the shadows, targeting hard working British people and ruining livelihoods with impunity," said UK foreign secretary Yvette Cooper.</p><p>"But they are mistaken – together with our allies, we are exposing their dark networks and going after those responsible."</p><p>The measures target Media Land’s ringleader, Alexander Volosovik, also known as Yalishanda, who has been active since at least 2010 and is known to have worked with some of the most notorious cyber criminal groups, including Evil Corp, <a href="https://www.itpro.com/security/ransomware/lockbit-remains-most-dangerous-ransomware-despite-fall-in-attacks">LockBit</a>, and <a href="https://www.itpro.com/security/ransomware/royal-hive-black-basta-ransomware-gangs-collaborating-on-cyber-attacks">Black Basta</a>. </p><p>Also sanctioned is Kirill Zatolokin, a Media Land employee responsible for collecting payment from customers and coordinating with other cyber actors, as well as Yulia Pankova, who has helped Volosovik with legal issues and handled his finances.</p><h2 id="sanctions-target-media-land-sister-outfits">Sanctions target Media Land sister outfits</h2><p>The sanctions also target ML Cloud, a Media Land sister company whose technical infrastructure is often used in conjunction with Media Land, including in ransomware and <a href="https://www.itpro.com/security/cyber-attacks/cyber-experts-have-been-warning-about-ai-powered-ddos-attacks-now-theyre-becoming-a-reality">DDoS attacks</a>.</p><p>Hypercore, a UK company registered and utilized by Aeza Group, has also been targeted in the international campaign. </p><p>The sanctions block access to any assets held in the sanctioning countries, and bar businesses and individuals there from engaging with the listed entities or people. Financial institutions that violate these restrictions can face penalties themselves.</p><p>"These sanctions don’t just impose costs on criminals, they dismantle the infrastructure that enables cyber crime," said Australian deputy prime minister Richard Marles. </p><p>"By disrupting these networks, we make it harder for others to launch attacks and it strengthens Australia’s resilience against future threats."</p><h2 id="will-the-sanctions-work">Will the sanctions work?</h2><p>The move marks the latest in a string of actions by governments to crack down on cyber crime-related hosting services. </p><p>In July this year, the US Treasury <a href="https://www.itpro.com/security/ransomware/aeza-group-ransomware-hosting-us-sanctions">announced plans to impose sanctions on Azea Group</a>, another bulletproof hosting service for its activities. US officials revealed the group has been selling access to specialized services and infrastructure used in a series of ransomware and infostealer malware campaigns. </p><p>While this fresh crackdown has been welcomed by security industry stakeholders, John Binns, partner and head of the sanctions practice at BCL Solicitors, said these typically have a limited effect. </p><p>"The evidential threshold for designation under the regulations is significantly lower than any in the criminal process, and the real-world impact on sophisticated actors operating primarily in hostile jurisdictions can be modest," he said.</p><p>"While sanctions are undoubtedly a valuable addition to the law-enforcement toolkit against transnational cyber crime, they deliver a form of administrative rather than criminal justice and are best viewed as potentially complementing - rather than supplanting - efforts to secure arrests, prosecutions, and asset forfeiture through the courts."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/russia-is-targeting-unpatched-vulnerabilities-what-to-do">Russia is targeting unpatched vulnerabilities – what can tech leaders do to shore up defenses?</a></li><li><a href="https://www.itpro.com/security/is-sector-cyber-awareness-crisis-workforce">Are we in a cyber awareness crisis?</a></li><li><a href="https://www.itpro.com/security/enterprises-need-to-acknowledge-the-importance-of-basic-cyber-hygiene">Enterprises need to acknowledge the importance of basic cyber hygiene</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Europol hails triple takedown with Rhadamanthys, VenomRAT, and Elysium sting operations ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/europol-hails-triple-takedown-with-rhadamanthys-venomrat-and-elysium-sting-operations</link>
                                                                            <description>
                            <![CDATA[ The Rhadamanthys infostealer operation is one of the latest victims of Europol's Operation Endgame, with more than a thousand servers taken down ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">84rf84B6USKP3XsAAbyTHC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hNt2JaLuS3Ribvoh5XfgT8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Nov 2025 12:08:54 +0000</pubDate>                                                                                                                                <updated>Mon, 17 Nov 2025 12:09:39 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hNt2JaLuS3Ribvoh5XfgT8-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Image of a Europol sign affixed to its Amsterdam headquarters]]></media:description>                                                            <media:text><![CDATA[Image of a Europol sign affixed to its Amsterdam headquarters]]></media:text>
                                <media:title type="plain"><![CDATA[Image of a Europol sign affixed to its Amsterdam headquarters]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hNt2JaLuS3Ribvoh5XfgT8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In the latest stage of its Operation Endgame campaign, Europol has seriously disrupted the Rhadamanthys infostealer, VenomRAT, and Elysium <a href="https://www.itpro.com/botnets/1644/what-is-a-botnet">botnet </a>malware operations.</p><p>More than 1,000 servers used by the groups to infect hundreds of thousands of victims worldwide with <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>were last week taken down.</p><p>Law enforcement searched one location in Germany, one in Greece, and nine in the Netherlands, seizing 20 domains. One arrest, related to the VenomRAT tool, has been made in Greece.</p><p>"The dismantled malware infrastructure consisted of hundreds of thousands of infected computers containing several million stolen credentials. Many of the victims were not aware of the infection of their systems," Europol said. </p><p>"The main suspect behind the infostealer had access to over 100,000 crypto wallets belonging to these victims, potentially worth millions of euros."</p><p>These hadn't yet been used to steal assets, Europol said. However, it's recommended checking <a href="http://politie.nl/checkyourhack" target="_blank"><u><em>politie.nl/checkyourhack</em></u></a> and <a href="http://haveibeenpwned.com" target="_blank"><u><em>haveibeenpwned.com</em></u></a> to find out whether computers have been hacked and learn what to do.</p><p>The Rhadamanthys infostealer harvests browser-resident data, including credentials, browser data, autofill information, and cryptocurrency wallet artifacts from browsers, password managers, and crypto wallets. </p><p><a href="https://www.proofpoint.com/us/blog/threat-insight/operation-endgame-quakes-rhadamanthys" target="_blank"><u>According to Proofpoint</u></a>, it costs between $300 and $500 a month, with options for a higher price point for customized uses. The firm said it appears that the threat actor behind Rhadamanthys was not only facilitating information stealer operations but also stealing sensitive data from Rhadamanthys affiliates. </p><p>"In addition to the infrastructure disruption, it’s likely that this operation will also negatively affect the criminals’ reputation, leading affiliates to mistrust them," the firm pointed out.</p><p><a href="https://www.shadowserver.org/news/rhadamanthys-historical-bot-infections-special-report/" target="_blank"><u>According to the Shadowserver Foundation</u></a>, which assisted in the operation, Rhadamanthys has grown to become one of the leading infostealers since Operation Endgame 2.0 disrupted the infostealer landscape earlier this year.   </p><p>"It is important to note that Rhadamanthys may have been used to drop additional malware on infected systems, so other malware infections may also be active on these systems and require further local remediation efforts," the Shadowserver Foundation warned. </p><p>"These victim systems may also have been used in historic or recent intrusions and ransomware incidents." </p><p>VenomRAT, which first appeared in 2020, generally arrives through malicious email attachments or links, also using fake <a href="https://www.itpro.com/security/antivirus/367785/best-business-antivirus">antivirus </a>pages. </p><p>It gives its operators remote desktop-style control, allowing the theft of files, browser data, cryptocurrency wallets, credit card details, account passwords, and authentication cookies.</p><p>While it's mainly been used to target Latin American organizations, it has also claimed victims in North America and Western Europe. </p><p>The Elysium botnet meanwhile, carries out data theft, payload delivery and other tasks.</p><p>Operation Endgame, launched in 2024, has now led to total  seizures of more than €21 million. This latest action follows an Operation Endgame raid in May that saw 300 servers taken down and 650 domains seized, along with €3.5 million. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/botnets-are-being-sold-on-the-dark-web-for-as-little-as-dollar99">Botnets are being sold on the dark web for as little as $99</a></li><li><a href="https://www.itpro.com/security/malware/what-is-polymorphic-malware">What is polymorphic malware?</a></li><li><a href="https://www.itpro.com/security/malware/malware-as-a-service-explained-what-it-is-and-why-businesses-should-take-note">Everything you need to know about Malware as a Service</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Europol takes down SIM farm network that scammed thousands of victims ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/europol-takes-down-sim-farm-network-scammed-thousands</link>
                                                                            <description>
                            <![CDATA[ The sophisticated operation led to crimes from simple phishing to investment fraud ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">EmFW94M7jHtP8jqXoXAj7V</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Lq6brmg8jRUNyRnyv5SBxe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Oct 2025 11:27:29 +0000</pubDate>                                                                                                                                <updated>Mon, 20 Oct 2025 11:28:08 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Lq6brmg8jRUNyRnyv5SBxe-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A glowing shield formed from glowing points and lines in an abstract landscape to represent security controls.]]></media:description>                                                            <media:text><![CDATA[A glowing shield formed from glowing points and lines in an abstract landscape to represent security controls.]]></media:text>
                                <media:title type="plain"><![CDATA[A glowing shield formed from glowing points and lines in an abstract landscape to represent security controls.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Lq6brmg8jRUNyRnyv5SBxe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Latvian police have arrested seven people over a cybercrime as a service operation that had been defrauding thousands of victims across Europe.</p><p>The group had set up technically sophisticated infrastructure for a series of fraud schemes, offering telephone numbers registered to people from more than 80 countries for use in criminal activities. </p><p>Fraudsters set up almost 50 million fake accounts for social media and communications platforms, which were then used for a range of different cybercrimes.</p><p>The law enforcement operation, codenamed SIMCartel, was carried out by authorities from Austria, Estonia, Finland, Europol and Eurojust and took place on 10 October. Law enforcement took down five servers and seized 1,200 SIM box devices and 40,000 active SIM cards.</p><p>Two websites that had been offering the illegal service – gogetsms.com and apisim.com – have now been taken over by law enforcement, while €431,000 ($374,500) in bank accounts and $333,000 in crypto accounts has also been frozen.</p><p>Law enforcement also seized four luxury vehicles as part of the operation.</p><p>Europol said the outfit was professionally organized, featuring a sophisticated website and an efficient logistics operation. </p><p>"The criminal network offering this service enabled its clients to commit a multitude of serious crimes that would not have been possible at all without masking the perpetrators’ identities," said Europol. </p><p>The service was mainly used for <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a> and <a href="https://www.itpro.com/security/phishing/361625/what-is-smishing"><u>smishing</u></a>, with some perpetrators specializing in fraud on second-hand marketplaces. They used the SIM card service to create a vast number of fake accounts, which then served as starting points for <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself"><u>social engineering</u></a> campaigns.</p><p>Other frauds include the daughter-son scam – persuading victims that their child needs financial help – along with investment fraud. Fake investment websites were set up, and, once serious investors showed interest, they were encouraged to pay large sums for alleged good business opportunities.</p><p>The criminals also set up fake online shops and fake bank websites, even impersonating police officers with the use of forged IDs, personally collecting funds from the victims.</p><p>"Other offences facilitated by this criminal service include fraud, extortion, migrant smuggling and the distribution of child sexual abuse material," Europol added. </p><p>More than 1,700 people in Austria fell victim to the scams, with losses of around $5.3 million, along with more than 1,500 in Latvia, who lost a total of $490,000 .</p><p>"Measured by volume, more than 49 million online accounts were created on the basis of the illegal service provided by suspects. The damage caused by the renters of the telephone numbers to their victims amounts to several million euros," said Europol. "The true scale of this network is still being uncovered."</p><iframe allow="" height="200px" width="100%" id="" style="" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/9ef7f02f-466f-4466-ae02-cbd718efa275/"></iframe><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/77-percent-of-security-leaders-say-theyd-fire-staff-who-fall-for-phishing-scams-even-though-theyve-done-the-same-thing">77% of security leaders say they'd fire staff who fall for phishing scams, even though they've done the same thing</a></li><li><a href="https://www.itpro.com/security/thousands-of-exposed-civil-servant-passwords-are-up-for-grabs-online">Thousands of exposed civil servant passwords are up for grabs online</a></li><li><a href="https://www.itpro.com/security/phishing/been-offered-a-job-at-google-think-again-this-new-phishing-scam-is-duping-tech-workers-looking-for-a-career-change">Been offered a job at Google? Think again. This new phishing scam is duping tech workers looking for a career change</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ DNS Security 101: Safeguarding your business from cyber threats ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/dns-security-101-safeguarding-your-business-from-cyber-threats</link>
                                                                            <description>
                            <![CDATA[ What strategies can businesses implement to strengthen defenses against the increased threat landscape? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fn9WGWCsjNj45T7uw7JCuf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aSbfsNzaNX7t8ueawAP2xZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 Oct 2025 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ram Mohan ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/4B66McCaU8AXuKtcsbGpCZ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;A seasoned executive with a strong strategy orientation, Ram works closely with the CEO, board members, and executives to achieve Identity Digital’s long-term vision. Ram served as COO and co-founder at Afilias, acquired by Donuts in 2020, where he launched the .info and .org registries, building the world’s second-largest domain name registry.&lt;/p&gt;&lt;p&gt;Ram’s previous positions include co-founder of TurnTide (acquired by Symantec 2001) and COO of Infonautics (publicly traded ed-tech company). His board positions include Global Commission on the Stability of Cyberspace (GCSC) and ICANN (2008-2018). Ram also co-founded ICANN’s Security and Stability Advisory Committee (SSAC).&lt;/p&gt;&lt;p&gt;He is an inventor of 19 US patents in internet technology, recipient of InfoWorld&#039;s &#039;Premier 100 Technology Leaders&#039; award, a CIO100 honoree, and Guinness World Record holder (2018).&lt;/p&gt;&lt;p&gt;Ram enjoys running (9 marathons and counting), playing with his two girls, and living with his wife in picturesque Bucks County, Pennsylvania.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aSbfsNzaNX7t8ueawAP2xZ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Attack]]></media:description>                                                            <media:text><![CDATA[Attack]]></media:text>
                                <media:title type="plain"><![CDATA[Attack]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aSbfsNzaNX7t8ueawAP2xZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cybercrime continues to make headlines, with <a href="https://www.itpro.com/security/cyber-attacks/scattered-spider-airline-industry-attacks"><u>major brands and institutions</u></a> recently forced to suspend online operations in the wake of attacks. Bad actors can exploit the Domain Name System (DNS) in schemes like phishing and ransomware, using fraudulent or lookalike domains to deceive consumers and carry out malicious activity.</p><p>The DNS is the backbone of the internet and enables everything from website access to email and other forms of digital communication. Securing the DNS is critical to protecting the digital infrastructure we depend on. Yet, a recent <a href="https://www.cscdbs.com/en/resources-news/domain-security-report/"><u>report</u></a> revealed that 72% of companies have implemented fewer than half of the recommended DNS security measures. </p><p>These gaps leave businesses vulnerable, and cybercriminals are always looking to exploit internet users by launching phishing campaigns, distributing malware, and carrying out other malicious activities. To combat this, strengthening DNS defenses is no longer optional; it’s essential.</p><h2 id="identifying-the-risks-and-attack-methods-aimed-at-the-dns">Identifying the risks and attack methods aimed at the DNS</h2><p>Cybersecurity threats that exploit domains and the DNS are not new, yet limited awareness among business leaders and everyday internet users continues to create vulnerabilities. When coupled with the common tendency for organizations to underestimate the scope of their digital footprint, these gaps can leave the door wide open to significant security risks.</p><p>When attackers target a domain, their objective is often to deceive individuals into revealing sensitive information through tactics such as phishing or spoofing. Two prevalent forms of DNS-related cybercrime include:</p><ul><li>Domain hijacking – An unauthorized party gains control of a domain by altering its DNS records, often by exploiting weak credentials or tricking a registrar into transferring ownership.</li><li>Subdomain hijacking – Cybercriminals seize control of legitimate but abandoned or overlooked subdomains, enabling them to exploit trusted brand identities to distribute malware or conduct phishing campaigns.</li></ul><h2 id="businesses-are-continually-being-targeted">Businesses are continually being targeted</h2><p>The consequences of a successful cyberattack can be severe, as recent incidents demonstrate. For example, the “Scattered Spider” group launched phishing attacks that compromised <a href="https://www.itpro.com/security/cyber-crime/scattered-spider-group-marks-and-spencer"><u>Marks & Spencer's</u></a> domain, ultimately leading to a ransomware breach. The attack forced the temporary suspension of online operations, exposed customer data, and caused a significant drop in sales.</p><p>Such incidents can cause lasting damage to a brand, eroding customer trust and straining critical business relationships. While cyberattacks can affect any organization, the risk is particularly high for companies that rely on secure digital infrastructure to operate.</p><p>The good news: there are practical, DNS-focused measures businesses can take today to strengthen their defenses.</p><h2 id="practical-strategies-to-strengthen-dns-security">Practical strategies to strengthen DNS security</h2><p>Effectively mitigating against cybercrime is a collective effort, but businesses can strengthen their defenses by taking several key actions:</p><ul><li><strong>Enable multifactor authentication (MFA)</strong> through your domain registrar and request a domain lock to prevent unauthorized transfers or changes.</li><li><strong>Use strong, unique passwords</strong> to protect credentials and reduce the risk of data breaches.</li><li><strong>Educate employees</strong> on domain-related threats and attack methods to improve organizational awareness and resilience.</li><li><strong>Monitor DNS traffic</strong> for anomalies, spikes, or unusual behavior to detect and mitigate potential threats early.</li><li><strong>Adopt advanced security protocols like DNSSEC</strong>, which adds cryptographic verification to DNS queries to guard against spoofing and tampering.</li></ul><p>By implementing these steps, businesses can significantly reduce their exposure to cybercrime and enhance resilience against threats that could disrupt operations and damage their reputation.</p><h2 id="vigilance-begins-with-awareness">Vigilance begins with awareness</h2><p>Cybercrime is an issue that can affect any internet user, meaning that everyone should improve their awareness of the dangers. This includes businesses taking a full 360-degree view of their digital footprint and their digital defenses. </p><p>By taking straightforward but high-impact steps like educating workforces, providing unique passwords, monitoring, and adopting the latest security systems, companies can significantly strengthen their defenses. With better awareness, we can all benefit from a safer internet.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Channel their curiosity into something meaningful’: Cyber expert warns an uptick of youth hackers should be a ‘wake-up call’ after teens charged over TfL attack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/channel-their-curiosity-into-something-meaningful-cyber-expert-warns-an-uptick-of-youth-hackers-should-be-a-wake-up-call-after-teens-charged-over-tfl-attack</link>
                                                                            <description>
                            <![CDATA[ Encouraging youths to engage in positive tech initiatives will guide them down the right path and away from nefarious activities ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WugG4wEK5H8nQyf7wGFg8M</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/S2Ccb42WNY5VTpTYRAM3Wj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 19 Sep 2025 15:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/S2Ccb42WNY5VTpTYRAM3Wj-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Youth hacker concept image showing teenage boy coding on a laptop in a dimly-lit room.]]></media:description>                                                            <media:text><![CDATA[Youth hacker concept image showing teenage boy coding on a laptop in a dimly-lit room.]]></media:text>
                                <media:title type="plain"><![CDATA[Youth hacker concept image showing teenage boy coding on a laptop in a dimly-lit room.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/S2Ccb42WNY5VTpTYRAM3Wj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>expert has warned that an uptick in <a href="https://www.itpro.com/security/cyber-attacks">cyber attacks</a> conducted by youths should be a “wake-up call” after two teens were charged following an attack on TfL last year. </p><p>Thalha Jubair, 19, and Owen Flowers, 18, were arrested following raids by the National Crime Agency (NCA) and City of London Police earlier this week. </p><p>The duo appeared at Westminster Magistrates Court on Thursday and were charged under the Computer Misuse Act for their alleged targeting of the rail operator.. </p><div class="product"><a data-dimension112="178d92ed-5930-464f-a223-124a2ab7de84" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="178d92ed-5930-464f-a223-124a2ab7de84" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="178d92ed-5930-464f-a223-124a2ab7de84" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p><a href="https://www.itpro.com/security/cyber-attacks/everything-we-know-about-the-tfl-cyber-attack-so-far"><u>TfL fell victim to a cyber attack last year</u></a> which severely disrupted systems and cost the rail operator upwards of £31 million in damages. In a statement coinciding with the arrests this week, the NCA said it believes the attack was carried out by the notorious cyber crime group, Scattered Spider. </p><p>“Today’s charges are a key step in what has been a lengthy and complex investigation,” said Paul Foster, deputy director and head of the NCA’s National Cyber Crime Unit.</p><p>“This attack caused significant disruption and millions in losses to TfL, part of the UK’s critical national infrastructure. Earlier this year, the NCA warned of an increase in the threat from cyber criminals based in the UK and other English-speaking countries, of which <a href="https://www.itpro.com/security/ransomware/the-scattered-spider-ransomware-group-is-infiltrating-slack-and-microsoft-teams-to-target-vulnerable-employees">Scattered Spider</a> is a clear example.”</p><p>Jubair and Flowers have both been remanded in custody and are set to appear at Southwark Crown Court at a later date. </p><h2 id="tech-savvy-teens-need-a-positive-outlet">Tech-savvy teens need a positive outlet</h2><p>Anna Chung, principal researcher for EMEA at <a href="https://www.itpro.com/security/okta-and-palo-alto-networks-are-teaming-up-to-fight-ai-with-ai">Palo Alto Networks</a>, said the arrests should serve as a “wake-up call” for authorities and highlights a failure to “properly engage a generation growing up in a digital-first world”. </p><p>“Young people don’t usually turn to online mischief out of malice - it’s often down to a mixture of boredom, <a href="https://www.itpro.com/business/business-strategy/in-the-age-of-ai-finding-staff-with-soft-skills-has-become-a-critical-enterprise-focus">technical skills</a>, and a lack of boundaries,” she said. </p><p>“They’re driven by a desire for challenge, recognition, and control. And if no one offers them a positive outlet, the internet becomes their playground—and eventually, their battlefield. So, how do we break the cycle?”</p><p>Chung said a concerted effort toward teaching young people digital ethics and making it a “part of core education” will be crucial to preventing future incidents. </p><p>“Give them a mission,” she said. “Channel their curiosity into something meaningful: <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">ethical hacking</a> challenges, <a href="https://www.itpro.com/security/zero-day-exploit/362258/google-doubles-bug-bounty-linux-kubernetes-exploits">capture-the-flag</a> competitions, and <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> contributions. Let them see that their skills have real value.”</p><h2 id="schools-are-dealing-with-a-wave-of-kid-hackers">Schools are dealing with a wave of kid hackers</h2><p>Gupta’s call to action comes just weeks after a report from the Information Commissioner's Office (ICO) warned <a href="https://www.itpro.com/security/kids-hacking-for-kicks-are-causing-security-headaches-at-schools"><u>tech-savvy kids have caused havoc at schools across the country</u></a>. </p><p>A report by the data protection watchdog highlighted security failings across the education sector, but emphasized that many incidents were caused by kids themselves. </p><p>The ICO found students were using techniques to bypass security and network controls. In one incident, three Year 11 students accessed a secondary school’s information management system which held personal information on around 1,400 students. </p><p>Another saw a student access a college’s information management system then viewed, amended and deleted personal information. The system stored details on more than 9,000 staff, students, and applicants. </p><p>Echoing Gupta’s comments, Heather Toomey, principal cyber specialist at the ICO, warned the trend ultimately has the potential to snowball into more nefarious activities further down the line. </p><p>“What starts out as a dare, a challenge, a bit of fun in a school setting can ultimately lead to children taking part in damaging attacks on organizations or critical infrastructure."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/business-strategy/careers-training/358117/the-top-online-cyber-security-courses">The best online cybersecurity courses to kickstart your career</a></li><li><a href="https://www.itpro.com/business-strategy/careers-training/370054/cyber-security-certification-vs-degree">Cybersecurity certification vs degree: Which is best for your career?</a></li><li><a href="https://www.itpro.com/business-strategy/careers-training/358235/10-best-free-coding-boot-camps">Want to get into coding? Here's our top picks for free online bootcamps</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ BreachForums founder resentenced to three years in prison ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/breachforums-founder-resentenced-to-three-years-in-prison</link>
                                                                            <description>
                            <![CDATA[ A US appeals court vacated his previous sentence and remanded the case for resentencing ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">89c6NL7kU77oCJUB2tkVgV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UjWjTqk5HiFp2xWB4yo93k-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Sep 2025 07:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UjWjTqk5HiFp2xWB4yo93k-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Insider threat hacker concept image showing man typing on keyboard in a dimly lit room. ]]></media:description>                                                            <media:text><![CDATA[Insider threat hacker concept image showing man typing on keyboard in a dimly lit room. ]]></media:text>
                                <media:title type="plain"><![CDATA[Insider threat hacker concept image showing man typing on keyboard in a dimly lit room. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UjWjTqk5HiFp2xWB4yo93k-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Conor Brian Fitzpatrick, the founder and admin of the <a href="https://www.itpro.com/security/cyber-crime/fbi-seizes-breachforums-infrastructure-but-successor-sites-are-already-popping-up">BreachForums</a>, has been resentenced to three years in prison after his earlier sentence was overturned in January this year. </p><p>Fitzpatrick, who operated under the alias <em>Pompompurin</em>, created the notorious forum after an FBI sting operation took down RaidForums in 2022. </p><p>In March 2023, Fitzpatrick identified himself as <em>Pompompurin </em>and admitted to running the forum <a href="https://www.itpro.com/security/370295/hacker-who-ran-breachforums-could-face-20-years-in-prison"><u>following his arrest</u></a>. In July that year, the BreachForums founder pleaded guilty to conspiracy to commit access device fraud, access device solicitation, and possession of child sexual abuse material. </p><div class="product"><a data-dimension112="9268cd91-b264-4f21-942c-a7144351b2d4" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="9268cd91-b264-4f21-942c-a7144351b2d4" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="9268cd91-b264-4f21-942c-a7144351b2d4" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>While prosecutors originally pursued a sentence of more than 15 years, Fitzpatrick was handed a sentence of 17 days (time served) and 20 years of supervised release.</p><p>According to the US Department of Justice (DOJ), this latest development came after a US appeals court vacated his prior sentence and remanded the case for resentencing. </p><p>“Today’s sentence demonstrates the Justice Department’s unwavering commitment to bringing to justice those who seek to sell stolen data to the highest bidder,” said acting assistant attorney general Matthew R. Galeotti of the Justice Department’s Criminal Division.</p><p>“To those seeking to operate a similar forum, take note: we will tirelessly investigate those who commit these crimes.”</p><p>BreachForums quickly became a haven for cyber criminals after <a href="https://www.itpro.com/security/hacking/367417/authorities-finally-confirm-leading-hacker-platform-raidforums-has-been">RaidForums</a> was taken down in 2022, boasting over 330,000 members and selling stolen data to the highest bidder. </p><p>Data hosted on the site included an array of personal information according to court documents, including bank account details, social security numbers, and usernames and passwords for various online accounts. </p><p>“BreachForums also maintained and offered access to at least 888 dataset of stolen information containing over 14 billion individual records of PII,” according to the DOJ. </p><p>Analysis of data hosted on the site was found to include a database containing the names and contact information for around 200 million users of a “major US-based social networking site”. </p><p>Another, the DOJ said, included details on over 87,000 members of InfraGard, an information sharing partnership between the FBI and private sector organizations.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/business-strategy/careers-training/358117/the-top-online-cyber-security-courses">Best online cyber security courses</a></li><li><a href="https://www.itpro.com/security/hacking/hacking-is-not-a-crime-criminal-activity-is">Hacking is not a crime, criminal activity is</a></li><li><a href="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools">The best malware removal tools</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Jaguar Land Rover “did the right thing” shutting down systems to thwart cyber attack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/jaguar-land-rover-did-the-right-thing-shutting-down-systems-to-thwart-cyber-attack</link>
                                                                            <description>
                            <![CDATA[ The attack on Jaguar Land Rover highlights the growing attractiveness of the automotive sector ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">D57UajELbiS6N9VR6p5zoH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9pwYva8LtuzWuM93eM7TCd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 03 Sep 2025 10:14:36 +0000</pubDate>                                                                                                                                <updated>Wed, 03 Sep 2025 10:15:07 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9pwYva8LtuzWuM93eM7TCd-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Jaguar Land Rover dealership with Jaguar and Land Rover logos pictured on a sign. ]]></media:description>                                                            <media:text><![CDATA[Jaguar Land Rover dealership with Jaguar and Land Rover logos pictured on a sign. ]]></media:text>
                                <media:title type="plain"><![CDATA[Jaguar Land Rover dealership with Jaguar and Land Rover logos pictured on a sign. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9pwYva8LtuzWuM93eM7TCd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Jaguar Land Rover was forced to shut down production systems over the weekend after being hit with a cyber attack, the company has revealed. </p><p>The car manufacturer said it acted immediately to mitigate the attack by proactively shutting down systems in a move that thwarted attackers. </p><p>"We are now working at pace to restart our global applications in a controlled manner," JLR said in a statement. "At this stage there is no evidence any customer data has been stolen but our retail and production activities have been severely disrupted."</p><div class="product"><a data-dimension112="9eb7d05c-dec8-4651-832b-7c874bbcc5ac" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="9eb7d05c-dec8-4651-832b-7c874bbcc5ac" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="9eb7d05c-dec8-4651-832b-7c874bbcc5ac" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p><a href="https://www.bbc.co.uk/news/articles/c9wywvllq7wo" target="_blank"><u>According to the </u><u><em>BBC</em></u></a>, the attack took place on Sunday, with employees at the company's plants in Halewood, Merseyside, and Solihull in the West Midlands sent home or told not to come into work the following day.</p><p>"JLR's decision to proactively shut down global manufacturing suggests this attack may have been targeting their operational systems, not just customer data," said Oakley Cox, director of operational technology of product at Darktrace.</p><p>"The speed of their response is telling - you don't typically halt production across multiple sites unless there's genuine concern about operational impact."</p><p>The attack appears to have been carefully timed, coming just as new registration plates are launched - the company's busiest time of year. Attacking over the weekend, meanwhile, meant that Jaguar Land Rover was less likely to able to respond and contain the threat.</p><p>No <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>group has claimed responsibility. However, the automotive sector is becoming a highly attractive sector for hackers, thanks to increasing digitization and growing integration between IT and operational technology (OT).</p><p>According to Upstream Security’s <a href="https://upstream.auto/reports/global-automotive-cybersecurity-report/" target="_blank"><u>2025 </u><u><em>Automotive & Smart Mobility Cybersecurity</em></u></a> report, attacks against the automotive sector are on the rise - and getting bigger. The number of 'massive-scale' incidents, impacting millions of vehicles, more than tripled between 2021 and 2023, rising from 5% to 19%.</p><h2 id="jaguar-land-rover-did-the-right-thing">Jaguar Land Rover “did the right thing”</h2><p>Nivedita Murthy, senior security consultant at Black Duck, said Jaguar Land Rover “did the right thing” by shutting down IT systems, which likely helped prevent the attack from spreading further and causing additional damage. </p><p>“As part of the post-incident activity, they would be able to identify how the attackers were able to access the systems and take advantage of them,” Murthy added. </p><p>Conversely, Nick Tausek, lead security automation architect at Swimlane, said the move raises serious questions about how organizations should react to security incidents. </p><p>"It is tentatively reassuring to see that, as of yet, no impact on customer data has been reported. However, entirely shutting down production and retail operations is not a sustainable countermeasure for cyber attacks," he said. </p><p>"JLR, as well as other automobile manufacturing organizations, should use this as a lesson in the importance of proactive cybersecurity."</p><p>This isn’t the first time the car manufacturer has fallen victim to a cyber attack. Earlier this year, it was hit by a breach that saw the theft of several gigabytes of sensitive data. </p><p>That particular incident exposed more than 700 proprietary documents, along with source code and employee and partner data.</p><p>"It raises the question of whether vulnerabilities from the prior attack still exist and were exploited to breach the company this time around," suggested Tausek.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/ransomware-attack-on-it-supplier-disrupts-hundreds-of-swedish-municipalities">Ransomware attack on IT supplier disrupts hundreds of Swedish municipalities</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/google-says-claims-of-a-major-gmail-security-warning-are-false-following-recent-media-reports">Google says 'claims of a major Gmail security warning are false' following recent media reports</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/warning-issued-to-salesforce-customers-after-hackers-stole-salesloft-drift-data">Warning issued to Salesforce customers after hackers stole Salesloft Drift data</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Anthropic admits hackers have 'weaponized' its tools – and cyber experts warn it's a terrifying glimpse into 'how quickly AI is changing the threat landscape' ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/anthropic-admits-hackers-have-weaponized-its-tools-and-cyber-experts-warn-its-a-terrifying-glimpse-into-how-quickly-ai-is-changing-the-threat-landscape</link>
                                                                            <description>
                            <![CDATA[ Security experts say Anthropic's recent admission that hackers have "weaponized" its AI tools gives us a terrifying glimpse into the future of cyber crime. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sNQmBcMMc3ECxbQp7Yd5qE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nBgbYBKj4tUofQNaYdx3mX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 02 Sep 2025 10:10:53 +0000</pubDate>                                                                                                                                <updated>Tue, 02 Sep 2025 10:11:24 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nBgbYBKj4tUofQNaYdx3mX-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Anthropic logo symbol on a smartphone screen with Claude AI model logo and branding pictured in background.]]></media:description>                                                            <media:text><![CDATA[Anthropic logo symbol on a smartphone screen with Claude AI model logo and branding pictured in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Anthropic logo symbol on a smartphone screen with Claude AI model logo and branding pictured in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nBgbYBKj4tUofQNaYdx3mX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Anthropic admits its <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">AI tools</a> have been "weaponized" by hackers to conduct serious attacks against organizations – and security experts warn it's a sign of things to come as cyber criminal groups flock to the technology. </p><p>The AI developer revealed the details as part of a trio of case studies in its <a href="https://www-cdn.anthropic.com/b2a76c6f6992465c09a6f2fce282f6c0cea8c200.pdf" target="_blank"><u><em>Threat Intelligence</em></u><u> report</u></a>, highlighting an employment scam by <a href="https://www.itpro.com/security/cyber-attacks/north-korean-it-workers-the-growing-threat">fake North Korean IT workers</a>, as well as "large-scale extortion" using Claude Code and <a href="https://www.itpro.com/software/development/vibe-coding-best-ai-models-secure-code-generation"><u>vibe-coded</u></a> ransomware for sale on the <a href="https://www.itpro.com/security/identity-theft/356578/a-simple-guide-to-the-dark-web">dark web</a>.</p><p>"<a href="https://www.itpro.com/security/cyber-crime/agentic-ai-cybersecurity-risks">Agentic AI</a> has been weaponized," the company said in a <a href="https://www.anthropic.com/news/detecting-countering-misuse-aug-2025"><u>blog post</u></a>. "AI models are now being used to perform sophisticated cyber attacks, not just advise on how to carry them out."</p><div class="product"><a data-dimension112="3022cdd9-c8ee-490b-8930-5088efbd1efd" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="3022cdd9-c8ee-490b-8930-5088efbd1efd" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="3022cdd9-c8ee-490b-8930-5088efbd1efd" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p><a href="https://www.itpro.com/software/development/anthropic-claude-opus-4-software-development"><u>Anthropic</u></a> said AI is being used throughout hacking operations, including finding victims, analyzing stolen data, and creating personas to hide behind — as well as creating ransomware. </p><p>Crucially, the post warned that the technology is lowering the barriers of entry for up-and-coming hackers, enabling criminals with few or even no technical skills to conduct major operations, create dangerous ransomware strains, or simply get a job at an American company. </p><p>Kevin Curran, IEEE senior member and professor of cybersecurity at Ulster University, said the admission from Anthropic shows “just how quickly AI is changing the threat landscape”. </p><p>"It is already speeding up the process of turning proof-of-concepts – often shared for research or testing – into weaponized tools, shrinking the gap between disclosure and attack,” he said. </p><p>"The bigger issue is accessibility. Innovation has made it easier than ever to create and adapt software, which means even relatively low-skilled actors can now launch sophisticated attacks," Curran added. </p><p>"At the same time, we might see nation-states using generative AI for disinformation, information warfare and advanced persistent threats."</p><h2 id="ai-has-sparked-a-cyber-crime-renaissance">AI has sparked a cyber crime renaissance</h2><p>Anthropic laid out details of three different instances of its systems being used in cyber criminal activities. </p><p>The first saw 17 organizations targeted across healthcare, emergency services, and government, with criminals threatening to leak stolen data if a ransom wasn't paid. </p><p>This particular hacker used <a href="https://www.itpro.com/software/development/anthropic-claude-opus-4-software-development">Claude Code</a> to "an unprecedented degree”, allowing them to automate reconnaissance practices, harvest victims’ credentials, and penetrate networks.</p><p>"Claude was allowed to make both tactical and strategic decisions, such as deciding which data to exfiltrate, and how to craft psychologically targeted extortion demands,” the blog post noted. </p><p>“Claude analyzed the exfiltrated financial data to determine appropriate ransom amounts, and generated visually alarming ransom notes that were displayed on victim machines."</p><p>While the Anthropic post sounds almost impressed with the efforts, it was quick to not only ban the accounts used in the attacks, but also develop ways to prevent similar use in the future, rolling out screening tools and a new detection method. </p><p>It's no surprise that attackers are turning to AI and automation to improve the success of their criminal endeavors, noted Nivedita Murthy, senior security consultant at Black Duck. </p><p>"In this case, it is interesting to note that Claude Code had a wealth of information on which organizations were vulnerable and where," Murthy said. "It also freely gave away this information in the form of an attack vector."</p><p>That suggests that companies may feeding too much internal data into the AI tools they're currently using. </p><p>"What organizations need to really look into is how much the AI tools they use know about their company and where that information goes," Murthy said. </p><p>"While <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>usage has been highly beneficial to all, organisations need to understand that AI is a repository of confidential information that requires protection, just like any other form of storage system.</p><p>"Accountability and compliance are core requirements of doing business. While embracing AI at scale, these two factors need to be kept in mind."</p><h2 id="ai-is-hard-at-work-for-north-korea">AI is hard at work...for North Korea</h2><p>Alongside large-scale automated attacks, Anthropic also detailed an operation run by North Korean hackers, who used Claude secure roles at Fortune 500 companies in the US, working as front-end developers and in programming more widely. </p><p>"This involved using our models to create elaborate false identities with convincing professional backgrounds, complete technical and coding assessments during the application process, and deliver actual technical work once hired," the post said. </p><p>The <a href="https://www.itpro.com/networking/27171/what-is-a-chatbot">chatbot </a>was used to conduct mock interviews, but also to answer questions in actual interviews, create personas, as well as to complete the actual work once hired. </p><p>This particular scam wasn't designed to fool those companies, however. Instead, it was designed to earn money by doing the work. </p><p>"These employment schemes were designed to generate profit for the North Korean regime, in defiance of international sanctions," the post said. "This is a long-running operation that began before the adoption of LLMs, and has been reported by the FBI."</p><p>The report noted that such work is worth hundreds of millions of dollars for North Korea annually. Previously, North Koreans hoping to get jobs overseas would need to actually train to do the technical work, stifling the effort to dodge sanctions. </p><p>However, AI has "eliminated this constraint”, the blog post added. </p><p>"Operators who cannot otherwise write basic code or communicate professionally in English are now able to pass technical interviews at reputable technology companies and then maintain their positions. This represents a fundamentally new phase for these employment scams."</p><p>Anthropic has since banned the accounts and improved how it spots such scams. </p><h2 id="vibe-coded-ransomware">Vibe-coded ransomware</h2><p>In another incident, a criminal turned to Claude to create <a href="https://www.itpro.com/security/29332/the-rise-of-ransomware-as-a-service">Ransomware as a Service (RaaS)</a> variants complete with evasion capabilities, encryption, and anti-recovery tools, selling them on the dark web for $100 to $1,200 each. </p><p>"This actor appears to have been dependent on AI to develop functional malware," Anthropic said in its blog post. "Without Claude’s assistance, they could not implement or troubleshoot core <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>components, like encryption algorithms, anti-analysis techniques, or Windows internals manipulation."</p><p>Anthropic has since banned the account and implemented new ways to <a href="https://www.itpro.com/security/malware/microsoft-quietly-launched-an-ai-agent-that-can-reverse-engineer-and-detect-malware">detect malware</a> generation. </p><p>"While specific to <a href="https://www.itpro.com/technology/artificial-intelligence/anthropic-just-released-claude-21-and-it-offers-more-than-double-the-token-capacity-of-gpt-4">Claude</a>, the case studies presented below likely reflect consistent patterns of behaviour across all <a href="https://www.itpro.com/technology/artificial-intelligence/openai-says-its-charting-a-path-to-agi-with-its-next-frontier-ai-model">frontier AI models</a>," the report noted, adding further reports on the topic would be forthcoming. </p><p>Indeed, <a href="https://www.itpro.com/technology/artificial-intelligence/openai-says-hackers-keep-trying-to-use-its-services-for-cyber-attacks"><u>OpenAI has released a similar report</u></a>, laying out how cyber criminals are making use of its AI — and how the company is proactively stopping such attacks. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/ai-security-blunders-have-cyber-professionals-scrambling">AI security blunders have cyber professionals scrambling</a></li><li><a href="https://www.itpro.com/security/cyber-crime/the-rise-of-ghostgpt-why-cybercriminals-are-turning-to-generative-ai">Why cybercriminals are turning to generative AI</a></li><li><a href="https://www.itpro.com/security/ai-means-cyber-teams-are-rethinking-their-approach-to-insider-threats">AI means cyber teams are rethinking their approach to insider threats</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The Allianz Life data breach just took a huge turn for the worse ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/allianz-life-data-breach-customer-accounts-impacted</link>
                                                                            <description>
                            <![CDATA[ Around 1.1 million Allianz Life customers are believed to have been impacted in a recent data breach, making up the vast majority of the insurer's North American customers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ADG2qEJ4qjUX9B5Uh9ZWSX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WyQDsXrph78RGRusAv8L7g-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 20 Aug 2025 10:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WyQDsXrph78RGRusAv8L7g-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo of Allianz, parent company of Allianz Life, pictured in Berlin city center.]]></media:description>                                                            <media:text><![CDATA[Logo of Allianz, parent company of Allianz Life, pictured in Berlin city center.]]></media:text>
                                <media:title type="plain"><![CDATA[Logo of Allianz, parent company of Allianz Life, pictured in Berlin city center.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WyQDsXrph78RGRusAv8L7g-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The true scale of the Allianz Life data breach has been laid bare, with leaked credential notification site <em>Have I Been Pwned</em> putting the number of affected accounts at 1.1 million.</p><p>The numbers represent the vast majority of the company's  1.4 million customers in the North America region, along with the data of financial professionals and some Allianz Life employees contained in Salesforce Accounts and Contacts databases.</p><p>Data exposed in the incident is <a href="https://haveibeenpwned.com/Breach/AllianzLife" target="_blank"><u>believed to include</u></a> dates of birth, email addresses, genders, names, phone numbers, and physical addresses. According to Allianz, Social Security numbers were also taken.</p><p>More than seven-in-ten of the exposed email addresses had already been affected by previously-disclosed data breaches. </p><p>When the <a href="https://www.itpro.com/security/data-breaches/everything-we-know-about-the-allianz-life-data-breach-so-far">breach was first confirmed</a>, Allianz Life said that 'most' of its North American customers had been affected, but that its core network and policy administration systems didn't appear to have been accessed.</p><p>The insurer said it would provide a full consumer notice once it has finished identifying and contacting affected individuals.</p><p>Jon Abbott, CEO of ThreatAware, described the scale of the breach as “significant”, noting that the data leaked represents a treasure trove of information to target victims. </p><p>"The sensitive and valuable information held in CRM tools is exactly why it’s targeted by attackers,” he said. “The data can be used by other cyber criminals for identity theft and <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaigns."</p><h2 id="what-happened-with-the-allianz-life-data-breach">What happened with the Allianz Life data breach?</h2><p>The breach, which took place on July 16 and was discovered a day later, is believed to have involved a <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> attack that involved impersonating IT support staff.</p><p>This saw hackers ask employees to accept a connection to a Salesforce Data Loader, which was then used to exfiltrate data from the <a href="https://www.itpro.com/desktop-software/28214/what-is-crm">CRM </a>system. </p><p>The attackers used malicious OAuth applications to infiltrate Salesforce instances, before downloading the company databases.</p><p>The attack has since been claimed by <a href="https://www.itpro.com/security/hacking/369967/us-extradites-french-shinyhunters-hacker-faces-123-years-in-prison">the notorious ShinyHunters threat group</a>, which is believed to overlap with the <a href="https://www.itpro.com/security/cyber-crime/scattered-spider-group-marks-and-spencer">Scattered Spider</a> and Lapsus groups. They are now believed to be preparing a data leak site to pressure Allianz and other victims into making a ransom payment.</p><p>The group, which first emerged in 2020, is also believed to be responsible for attacks on Salesforce systems at several retailers, as well as at <a href="https://www.itpro.com/security/cyber-attacks/google-cyber-researchers-were-tracking-the-shinyhunters-groups-salesforce-attacks-then-realized-theyd-fallen-victim">Google</a>, Cisco, <a href="https://www.itpro.com/security/cyber-attacks/qantas-cyber-attack-six-million-customers-exposed">Qantas</a>, Santander, Ticketmaster, Tokopedia, AT&T and most recently Workday. </p><p><a href="https://www.itpro.com/security/data-breaches/workday-data-breach-what-we-know-so-far">Workday confirmed it had fallen victim to an attack</a> last week, warning customers that exposed information could then be used in follow-up social engineering attacks - a common tactic for threat actors. </p><p>"Groups such as ShinyHunters rely on fast moving social engineering tactics – this typically involves calling and emailing employees of the victim organization and attempting to extort them. If this does not work, they then launch a leak site with the aim of pressuring victims into payment," said Abbott.</p><p>"This pattern in their attacks is why the security fundamentals are so important. Accurate asset inventories, tamper-proof identity verification and hardened service desk processes are all essential.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/phishing/employee-phishing-training-is-working-but-dont-get-complacent">Employee phishing training is working – but don’t get complacent</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/phishing-tactics-the-top-attacks-trends-in-year">Phishing tactics: The top attack trends</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/phishing-kits-cyber-crime-dark-web">Cheap cyber crime kits can be bought on the dark web for less than $25</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Warning issued as new Pakistan-based malware group hits millions globally ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/warning-issued-as-new-pakistan-based-malware-group-hits-millions-globally</link>
                                                                            <description>
                            <![CDATA[ Tempting people in with offers of pirated software, the network installs commodity infostealers, according to CloudSEK ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">R8wUYjv2NQWMDuhdKvRn5n</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wtsGxk4n6oHAkbWZ7YpcKF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 15 Aug 2025 11:59:20 +0000</pubDate>                                                                                                                                <updated>Fri, 15 Aug 2025 11:59:39 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wtsGxk4n6oHAkbWZ7YpcKF-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware concept image showing a shield with a red-colored, locked padlock place on top.]]></media:description>                                                            <media:text><![CDATA[Malware concept image showing a shield with a red-colored, locked padlock place on top.]]></media:text>
                                <media:title type="plain"><![CDATA[Malware concept image showing a shield with a red-colored, locked padlock place on top.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wtsGxk4n6oHAkbWZ7YpcKF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Researchers at cybersecurity firm CloudSEK have issued a warning about a Pakistan-based <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>syndicate carrying out <a href="https://www.itpro.com/security/malware/infostealer-malware-exposed-credentials">infostealer attacks</a> on millions of victims worldwide. </p><p>The group commands a sprawling network of operators, affiliates, and infrastructure, according to CloudSEK, adding up to a multi-million-dollar cyber crime business.</p><p>With many operators sharing the same family surname, researchers even suggested the group could be a multi-generational, family-run cyber crime outfit. </p><p>Their roles appear to be divided between primary operators - network management and finances - affiliates, generating traffic via warez sites, and financial facilitators handling payouts and settlements.</p><p>The group lures its victims in through Search Engine Optimization (SEO) poisoning and spam posted on legitimate online forums. Alongside this, the operators also ran paid ads through legitimate traffic services to drive even more users to malicious domains. </p><p>Blending malicious activity with normal web marketing traffic also made detection and takedown more difficult.</p><p>Links to cracked versions of high-demand software — such as Adobe After Effects and Internet Download Manager (IDM) — also led users to malicious WordPress sites. </p><p>“This investigation shows that cyber crime today is no longer a dark-web-only phenomenon," said Nivya Ravi, director of products at CloudSEK. </p><p>"It’s hiding in plain sight, using <a href="https://www.itpro.com/network-internet/web-hosting/368182/what-is-seo">SEO</a>, legitimate payment processors and publicly accessible forums, to operate with alarming efficiency." </p><p>The WordPress sites distributed commodity infostealers, including Lumma Stealer, Meta Stealer, and, more recently, AMOS, all of which were concealed inside password-protected archives to evade detection.</p><p>Once installed, the malware exfiltrated credentials, browser data, <a href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining">cryptocurrency</a> wallets, and other sensitive information — data that was later monetized through resale and secondary fraud.</p><h2 id="a-sprawling-malware-network">A sprawling malware network </h2><p>The CloudSEK research revealed that the network involved 5,239 registered affiliates operating 3,883 malware distribution sites. Its lifetime revenue is estimated to be at least $4.67 million - although it may well be more, thanks to undocumented 'off-ledger' settlements. </p><p>Between May and October 2020 alone, the network paid out $130,560 to affiliates at an average Effective Cost Per Install (eCPI) of $0.0693. Payments were made via Payoneer in two-thirds of cases, with Bitcoin accounting for almost all the rest.</p><p>CloudSEK believes that the network may have hit 10 million victims worldwide.</p><p>"This is not a small-time hacking group — it’s an industrial-scale cybercrime enterprise that has been operating for years, infecting millions of devices across the globe," said Ravi. </p><p>"By hijacking the demand for pirated software, they have turned unsuspecting users into a steady revenue stream."</p><p>The group launched a big campaign ahead of India’s Independence Day this month, with coordinated attacks targeting the government, finance and defense sectors and including <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a>, <a href="https://www.itpro.com/security/22658/25-fake-government-websites-closed-down">fake websites</a>, data breaches, and scams. </p><p>CloudSEK recommends a multi-pronged disruption strategy combining domain takedowns targeting the 383 long-haul sites, as well as a financial ban in collaboration with Payoneer and other payment processors.</p><p>Similarly, the company urged for search engine de-indexing of warez sites hosting malware and user education campaigns warning about cracked software risks.</p><p>"The scale and sophistication of this network underscore the urgent need for coordinated, cross-border action to dismantle such operations before they cause irreversible damage to individuals, businesses, and critical infrastructure,” said Ravi.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/malware/why-malware-as-a-service-is-becoming-a-serious-problem">Why ‘malware as a service’ is becoming a serious problem</a></li><li><a href="https://www.itpro.com/security/malware/developers-face-a-torrent-of-malware-threats-as-malicious-open-source-packages-surge-188-percent">Devs face a torrent of malware threats as malicious open source packages surge 188%</a></li><li><a href="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools">The best malware removal tools for businesses in 2025</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The rise of GhostGPT – Why cybercriminals are turning to generative AI ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/the-rise-of-ghostgpt-why-cybercriminals-are-turning-to-generative-ai</link>
                                                                            <description>
                            <![CDATA[ GhostGPT is not an AI tool - It has been explicitly repurposed for criminal activity ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qU3TtqDgfUCVggCaKa5tR5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/XXVBViWyi8AEAdzh2ktnvQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 01 Aug 2025 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ryan Estes ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/D8MuDwajXAYPrwfaKaFJ3R.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/XXVBViWyi8AEAdzh2ktnvQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A small plastic cartoon-style ghost, sat on an orange background. The ghost resembles a white bedsheet with black eyeholes cut at the top.]]></media:description>                                                            <media:text><![CDATA[A small plastic cartoon-style ghost, sat on an orange background. The ghost resembles a white bedsheet with black eyeholes cut at the top.]]></media:text>
                                <media:title type="plain"><![CDATA[A small plastic cartoon-style ghost, sat on an orange background. The ghost resembles a white bedsheet with black eyeholes cut at the top.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/XXVBViWyi8AEAdzh2ktnvQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>While many businesses are still trying to understand how to use generative artificial intelligence (AI) to drive productivity and efficiency, malicious actors have moved rapidly. Their approach is not theoretical; it's increasingly practical and dangerously effective. One of the clearest examples of this shift is <a href="https://abnormal.ai/blog/ghostgpt-uncensored-ai-chatbot"><u>GhostGPT</u></a>, an AI-powered chatbot that was discovered in late 2024 and is already reshaping the cyber threat landscape.</p><p>GhostGPT is not a general-purpose AI tool. It has been explicitly developed, or more likely, repurposed for criminal activity. Unlike public-facing large language models (LLMs) such as ChatGPT, which are constrained by security safeguards and ethical restrictions, GhostGPT operates free from such boundaries. It is widely believed to be a “wrapper” around a jailbroken LLM or an open-source model that has had its safety features stripped out. This enables it to respond freely to prompts for malware, phishing content, and attack strategies, effectively putting offensive cyber capabilities in the hands of anyone with a web browser and an illicit link.</p><p>More concerning still is the fact that GhostGPT deliberately avoids logging user interactions. This makes attribution extremely difficult and adds a further layer of anonymity for cybercriminals. Notably, mainstream tools like OpenAI’s ChatGPT are bound by usage policies and traceability, whereas GhostGPT is being marketed and seemingly used as a ‘black box’ for illegal digital activity.</p><h2 id="phishing-in-seconds">Phishing in seconds</h2><p>One of the key threats presented by GhostGPT is its ability to produce high volumes of convincing phishing content in just seconds. This is not limited to generic spam. GhostGPT can create personalized email messages that mimic internal tone, corporate templates, and even the linguistic quirks of specific individuals. Where previous phishing attempts relied on crude templates and clumsy spelling errors, generative AI enables far more persuasive messaging, tailored to the target and delivered at unprecedented speed.</p><p>According to the UK government’s <a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2024/cyber-security-breaches-survey-2024"><u>Cyber Security Breaches Survey 2024</u></a>, phishing remains the most commonly identified type of cyber-attack affecting British organizations. Among those that detected a breach or attack in the past 12 months, 84% of businesses and 83% of charities cited phishing as the root cause. The report notes that phishing is particularly disruptive due to its sheer volume and the investigative effort required to respond. </p><p>Cyber experts are now suggesting we face such an intense barrage of critical national infrastructure attacks, too - it’s now a case of <a href="https://www.independent.co.uk/tech/cyber-attacks-big-one-aisuru-botnet-b2755263.html"><u>not</u><u><em> if </em></u><u>such attacks happen, but </u><u><em>when</em></u><u>.</u></a></p><p>Add tools like GhostGPT to the equation, and the scale and sophistication of these campaigns are likely to increase sharply.</p><p>In parallel, GhostGPT can also be used to create highly realistic fake login portals. These spoofed web pages, generated in response to basic prompts, are nearly indistinguishable from genuine ones, especially when paired with email lures or SMS phishing (smishing) tactics. Once victims enter their credentials, attackers can gain access to critical systems or sell the data on underground markets.</p><h2 id="lowering-attack-barriers">Lowering attack barriers</h2><p>Perhaps even more worrying is GhostGPT’s ability to generate malicious code. It allows users to request ransomware samples, write scripts to exfiltrate data, or even build polymorphic malware, a type of software that continually changes its code to evade detection. Polymorphic malware has been around for over a decade, but its creation previously required technical expertise. Now, with AI’s help, that barrier has been drastically lowered.</p><p>Cybersecurity specialists have long warned of the risks associated with AI-generated malware. A 2023 study by <a href="https://www.ibm.com/blogs/think/2023/11/malware-generation-llms"><u>IBM’s X-Force team</u></a> demonstrated that LLMs can be prompted to create viable malicious code with only a few lines of instruction, even on public models with supposed safeguards. GhostGPT, lacking any ethical brakes, removes those barriers entirely.</p><h2 id="attacks-now-with-detailed-instructions">Attacks - now with detailed instructions</h2><p>Beyond content and code generation, GhostGPT also offers step-by-step attack advice. Security researchers have observed it providing detailed instructions for setting up command-and-control infrastructure, bypassing endpoint detection systems, and exploiting specific software vulnerabilities. While such information has long been accessible via dark web forums, the difference here is the ease of access and contextualization. Instead of searching static posts, users can ask GhostGPT direct questions and receive real-time responses adapted to their goals.</p><p>This development fundamentally changes the economics of cybercrime. In the past, launching sophisticated attacks required coordination, specialized knowledge, and sometimes a team of actors. Now, with a tool like GhostGPT, a lone individual with a limited technical background can initiate campaigns that previously required weeks of preparation.</p><p>For UK organizations, particularly small and medium-sized businesses (SMEs) with limited internal cybersecurity resources, the risks are significant. According to the Department for Science, Innovation and Technology’s <a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2024"><u>2024 Cyber Security Breaches Survey</u></a>, 32% of businesses reported being attacked at least once in the previous 12 months. As threat actors continue to adopt AI tools, the real figure may rise considerably, especially if firms are slow to adapt.</p><h2 id="what-to-do">What to do</h2><p>So, what can be done? While no single technology can neutralize the threat, there are measures that organizations can adopt to reduce their exposure. </p><p>First, the basics matter more than ever: regular software patching, the use of multi-factor authentication (MFA), and employee awareness training are essential. The sophistication of phishing emails may be increasing, but so too can the ability of staff to detect them if properly trained.</p><p>Beyond these fundamentals, it’s increasingly important to deploy AI-enhanced defensive tools. Endpoint Detection and Response (EDR) and Extended Detection and Response (XDR) systems are capable of identifying anomalous behaviors that signal compromise, even if the initial attack evades traditional defenses. DNS filtering, too, can reduce exposure to malicious links embedded in phishing emails or messaging apps.</p><p>Threat intelligence is also crucial. As tools like GhostGPT proliferate, staying ahead of the curve requires real-time awareness of tactics, techniques, and procedures (TTPs) used by attackers. Security providers and their channel partners must be capable of feeding this intelligence into automated systems that can act in near real time.</p><h2 id="a-shift-in-the-cyber-threat-landscape">A shift in the cyber threat landscape</h2><p>The emergence of GhostGPT signals a shift in the cyber threat landscape. Generative AI is no longer the exclusive domain of innovation labs or marketing departments; it has been weaponized. As this technology becomes more accessible, the lines between state-backed threats, organized cybercrime, and amateur experimentation will continue to blur.</p><p>For the UK channel community, this is both a challenge and an opportunity. Clients will increasingly look to service providers not just for protection, but for clarity. Understanding how tools like GhostGPT work and how to defend against them will become a differentiator. As ever, those who stay informed will be best placed to lead.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Arrests made after huge HMRC scam campaign hit 100,000 accounts ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/arrests-made-after-huge-hmrc-scam-campaign-hit-100-000-accounts</link>
                                                                            <description>
                            <![CDATA[ The Romanian nationals are accused of having used stolen data to make fraudulent claims ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">To4PxGYrHF5DJUWxqWiHmj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xP6A8Prw5RKCLWiZNrCaNT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 14 Jul 2025 12:37:13 +0000</pubDate>                                                                                                                                <updated>Mon, 14 Jul 2025 12:37:34 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xP6A8Prw5RKCLWiZNrCaNT-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[HM Revenue &amp; Customs (HMRC) letter pictured on a table top. ]]></media:description>                                                            <media:text><![CDATA[HM Revenue &amp; Customs (HMRC) letter pictured on a table top. ]]></media:text>
                                <media:title type="plain"><![CDATA[HM Revenue &amp; Customs (HMRC) letter pictured on a table top. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xP6A8Prw5RKCLWiZNrCaNT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Romanian police have arrested 13 people believed to have been behind a phishing campaign on HM Revenue and Customs (HMRC) that cost millions in bogus tax refunds. </p><p>The men and women, aged between 23 and 53, are suspected of having stolen data then used to submit millions of pounds worth of fraudulent PAYE claims, as well as VAT repayments and child benefit payments. </p><p>The arrests were carried out by criminal investigators from HMRC, together with more than 100 Romanian police officers, in the Romanian counties of Ilfov, Giurgiu, and Calarasi. </p><div class="product"><a data-dimension112="f69b1d50-e283-4800-874b-8e54bd6e8f0b" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="f69b1d50-e283-4800-874b-8e54bd6e8f0b" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="f69b1d50-e283-4800-874b-8e54bd6e8f0b" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>“These arrests show we work across borders with our international partners to combat tax crime in all its forms. We have a number of live criminal investigations, and we are grateful to our Romanian partners for their support," said Simon Grunwell, operational lead in HMRC’s Fraud Investigation Service.</p><p>“We have already acted to protect customers after identifying attempts to access a very small minority of tax accounts, and we continue to work with other law enforcement agencies both in the UK and overseas to bring those responsible to justice.”</p><p>Two other men, aged 27 and 36, were arrested in Bucharest in November on suspicion of cyber crime and fraud offences, with investigations still ongoing.</p><p>Last month, HMRC revealed that scammers had apparently netted £47 million by compromising around 100,000 taxpayer accounts. The tax office revealed a 38-year-old man has been arrested in Preston, apparently in connection with that attack. </p><p>“This was organized crime phishing for identity data outwith of HMRC systems, so stuff that banks and others will also unfortunately experience, and then trying to use that data to create PAYE accounts to pay themselves a repayment and/or access an existing account,” said HMRC chief executive, John-Paul Marks.</p><h2 id="what-happened-with-the-hmrc-campaign">What happened with the HMRC campaign?</h2><p>The attack, which took place last year, was only revealed in June - <a href="https://www.itpro.com/security/hmrc-scam-account-campaign">drawing criticism from treasury select committee chair Dame Meg Hillier</a>, who told HMRC that its failure to report details of the breach was ‘unacceptable’.</p><p>HMRC said it wrote to those affected in June and that it had locked down affected accounts and deleted login credentials - including Government Gateway user ID and passwords - to prevent future unauthorized access. </p><p>The tax office also revealed it removed any incorrect information from tax records. </p><p>"Tax scams are one of the biggest risks to citizens in the UK as criminals are adopting tactics to make them highly convincing, often using a mix of emails, post and SMS to send out fraudulent comms," said William Wright, CEO of Closed Door Security.</p><p>"The correspondence often looks genuine and it takes a very savvy consumer to question its authenticity, especially as criminals often hijack on key tax dates, such as the self-assessment deadline in January."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/hackers-are-using-pdfs-to-impersonate-big-brands-like-microsoft-and-docusign-in-a-new-threat-campaign">Hackers are using PDFs to impersonate big brands in a new threat campaign</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/phishing-tactics-the-top-attacks-trends-in-year">Phishing tactics: The top attack trends</a></li><li><a href="https://www.itpro.com/security/phishing/employee-phishing-training-is-working-but-dont-get-complacent">Employee phishing training is working – but don’t get complacent</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Millions of customers have been exposed in the Qantas cyber attack – here’s everything we know so far ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/qantas-cyber-attack-six-million-customers-exposed</link>
                                                                            <description>
                            <![CDATA[ While details remain murky, cyber experts told ITPro the Qantas incident bears all the hallmarks of the Scattered Spider ransomware group. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SmrTMohCqqQDG6BMYm5eQb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hRSyexQrm5mG9MV3zQY4E9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Jul 2025 11:05:37 +0000</pubDate>                                                                                                                                <updated>Wed, 02 Jul 2025 11:18:49 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hRSyexQrm5mG9MV3zQY4E9-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A Qantas 787 Dreamliner pictured on the runway at John F Kennedy International Airport in New York City, USA.]]></media:description>                                                            <media:text><![CDATA[A Qantas 787 Dreamliner pictured on the runway at John F Kennedy International Airport in New York City, USA.]]></media:text>
                                <media:title type="plain"><![CDATA[A Qantas 787 Dreamliner pictured on the runway at John F Kennedy International Airport in New York City, USA.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hRSyexQrm5mG9MV3zQY4E9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Qantas has become the latest airline to suffer a cyber attack, with data belonging to around six million customers potentially exposed in the incident. </p><p>In a statement confirming the breach, the airline said compromised data includes some customer names, email addresses, phone numbers, dates of birth, and frequent flyer numbers. </p><p>The company insists that no credit card details, passport information, or assorted financial details have been exposed. Similarly, no account passwords, PIN numbers, or login details have been accessed. </p><div class="product"><a data-dimension112="dd63f7fd-cb98-4ef1-a907-316217b00d98" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://click.linksynergy.com/deeplink?id=kXQk6%2AivFEQ&mid=42966&u1=itpro-gb-2120491988756594962&murl=https%3A%2F%2Fwww.keepersecurity.com%2Fen_GB%2Faffiliate%2Fbusiness%2F" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://click.linksynergy.com/deeplink?id=kXQk6%2AivFEQ&mid=42966&u1=itpro-gb-2120491988756594962&murl=https%3A%2F%2Fwww.keepersecurity.com%2Fen_GB%2Faffiliate%2Fbusiness%2F" target="_blank" rel="sponsored" data-dimension112="dd63f7fd-cb98-4ef1-a907-316217b00d98" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://click.linksynergy.com/deeplink?id=kXQk6%2AivFEQ&mid=42966&u1=itpro-gb-2120491988756594962&murl=https%3A%2F%2Fwww.keepersecurity.com%2Fen_GB%2Faffiliate%2Fbusiness%2F" target="_blank" rel="nofollow" data-dimension112="dd63f7fd-cb98-4ef1-a907-316217b00d98" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>On Monday, Qantas spotted unusual activity on a third-party platform used by a Qantas airline contact center. The airline said it took immediate action upon discovery and is now implementing additional security measures to further restrict access. </p><p>Qantas said it has notified the Australian Cyber Security Centre and the Office of the Australian Information Commissioner, as well as the Australian Federal Police.</p><p>“We sincerely apologize to our customers and we recognize the uncertainty this will cause. Our customers trust us with their personal information and we take that responsibility seriously," said Qantas Group CEO Vanessa Hudson.</p><p>“We are contacting our customers today and our focus is on providing them with the necessary support."</p><h2 id="who-s-behind-the-qantas-cyber-attack">Who’s behind the Qantas cyber attack?</h2><p>While there's no official word on which group carried out the attack, <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>experts told <em>ITPro </em>all eyes will likely be pointing toward the notorious <a href="https://www.itpro.com/security/cyber-crime/scattered-spider-group-marks-and-spencer">Scattered Spider</a> group. </p><p>Scattered Spider has caused havoc in the retail sector in recent months, targeting UK retailers including Harrods, Co-op and <a href="https://www.itpro.com/business/m-and-s-calls-in-ncsc-after-cyber-incident-disrupts-customer-payments-online-orders">Marks & Spencer (M&S)</a>.</p><p>The group now appears to be shifting its attention, however. An FBI advisory last week warned <a href="https://www.itpro.com/security/cyber-attacks/scattered-spider-airline-industry-attacks">the group is now targeting organizations in the aviation industry</a>. </p><p>The <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>gang is believed to be responsible for recent attacks on Hawaiian Airlines and Canada's WestJet.</p><p>Toby Lewis, global head of threat analysis at <a href="https://www.itpro.com/business/business-strategy/darktrace-cleared-of-channel-stuffing-claims-by-ey-audit-announces-31-revenue-growth">Darktrace</a>, said the Qantas attack bears all the hallmarks of the group so far. </p><p>"The attack follows their typical playbook: steal legitimate login credentials to walk into systems where critical security protections often aren't enabled by default, while operating from Western countries to appear as legitimate users and bypass standard security filters," Lewis told <em>ITPro</em>.</p><p>"Expect the stolen customer data - names, emails, birthdates, frequent flyer numbers - to fuel convincing phishing campaigns targeting loyalty programs and tricking customers with fake payment requests using real booking details."</p><p>It's not known whether Qantas has received a ransom demand - and, if so, whether it's paying up. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/hackers-are-using-fake-tool-installers-to-dupe-victims-and-ai-tools-like-chatgpt-are-a-key-target">Hackers are using fake tool installers to dupe victims</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/legal-aid-agency-cyber-attack-breach">Criminal records, financial data exposed in cyber attack on Legal Aid Agency</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/cyber-attacks-cost-uk-firms-64-billion-each-year">Cyber attacks are costing UK firms billions every year</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ M&S aims for full online restoration within four weeks following major cyber attack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/m-and-s-aims-for-full-online-restoration-within-four-weeks-following-major-cyber-attack</link>
                                                                            <description>
                            <![CDATA[ M&S CEO Stuart Machin says the high street retailer plans to fully restore operations by August following a devastating cyber attack in April. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qT746VdLCB2QnNV476PyhM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aMsMu5LvrpDS6f9Gc4EPFa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Jul 2025 07:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rene Millman) ]]></author>                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aMsMu5LvrpDS6f9Gc4EPFa-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Pedestrians pictured walking past a Marks &amp; Spencer (M&amp;S) store front on Oxford Street, London.]]></media:description>                                                            <media:text><![CDATA[Pedestrians pictured walking past a Marks &amp; Spencer (M&amp;S) store front on Oxford Street, London.]]></media:text>
                                <media:title type="plain"><![CDATA[Pedestrians pictured walking past a Marks &amp; Spencer (M&amp;S) store front on Oxford Street, London.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aMsMu5LvrpDS6f9Gc4EPFa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Marks & Spencer (M&S) expects its online operations to be fully restored within the next four weeks as the retailer continues its recovery from a major cyber attack in April. </p><p>Speaking at the company’s annual general meeting, CEO Stuart Machin said the company hopes to have the “vast majority” of the incident’s impact resolved by August, the <em>BBC </em><a href="https://www.bbc.co.uk/news/articles/c9qxx34ngp5o" target="_blank"><u>reported</u></a>.</p><p>The attack, which the company has attributed to “human error” and estimated will cost around £300 million in lost profit, forced M&S to halt online sales and has significantly disrupted its supply chain, including operations at its key Castle Donington distribution centre. The breach also resulted in the theft of customer personal data.</p><div class="product"><a data-dimension112="659c5d52-64f7-4eac-82e6-3c97f54159e6" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="659c5d52-64f7-4eac-82e6-3c97f54159e6" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="659c5d52-64f7-4eac-82e6-3c97f54159e6" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>The announcement is the latest step in a multi-month recovery process. As <em>ITPro </em>has reported, the crisis first unfolded in April when <a href="https://www.itpro.com/business/m-and-s-calls-in-ncsc-after-cyber-incident-disrupts-customer-payments-online-orders"><u>M&S was forced to suspend all online orders</u></a>. </p><p>M&S later confirmed in May that <a href="https://www.itpro.com/security/cyber-attacks/m-and-s-customer-personal-data-stolen"><u>customer personal data had been compromised</u></a>, linking the breach to a supply chain partner. By June, the full financial scale of the incident was <a href="https://www.itpro.com/security/cyber-attacks/cyber-attacks-on-uk-retailers-financial-impact"><u>revealed</u></a>, with the warning of a £300 million profit hit and continued operational disruption.</p><p>While the main e-commerce site for Great Britain has partially resumed service, key functions like click-and-collect and next-day delivery remain offline. </p><p>The recovery timeline provides a critical update for a breach that has had a sustained operational and financial impact on one of the UK’s best-known retailers.</p><h2 id="m-s-fallout-may-continue-beyond-planned-restoration-date">M&S fallout may continue beyond planned restoration date</h2><p>Julius Cerniauskas, CEO of web intelligence firm Oxylabs, told <em>ITPro</em> that the incident highlights the persistent threat of social engineering. </p><p>“Investment alone isn’t a silver bullet," he said. "Attackers are constantly evolving their techniques, and social engineering – tricking people rather than systems – is still one of the most effective entry points.”</p><p>Cerniauskas noted that while a full operational recovery by August would be a “solid achievement,” the business impact can continue long after technical systems are restored. </p><p>"It’s not a question of if you'll be targeted - but when,” he added.</p><p>The fallout from the incident may also affect executive remuneration. According to reports from the <a href="https://www.standard.co.uk/business/business-news/archie-norman-m-s-scotland-england-london-b1235819.html" target="_blank"><u><em>Evening Standard</em></u></a>, chairman Archie Norman confirmed that any drop in performance caused by the attack "will be taken into account with regards to incentive pay". </p><p>Norman added that the recovery is progressing, with "new systems coming back" each week.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/cyber-attacks-on-uk-retailers-financial-impact">Financial impact of cyber attacks on UK retailers laid bare in new report</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/harrods-cyber-attack">Harrods hit by cyber attack as UK retailers battle threats</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/cyber-attacks-have-rocked-uk-retailers-heres-how-you-can-stay-safe">Cyber attacks have rocked UK retailers – here's how you can stay safe</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ British IT worker jailed for revenge attack on employer that caused a “ripple effect of disruption” for colleagues and customers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/british-it-worker-jailed-for-revenge-attack-on-employer-that-caused-a-ripple-effect-of-disruption-for-colleagues-and-customers</link>
                                                                            <description>
                            <![CDATA[ West Yorkshire man Mohammed Umar Taj was suspended from his job in Huddersfield in July 2022, and began taking revenge within hours. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KokdJ85bvAGL5Q55X3q3vK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UjWjTqk5HiFp2xWB4yo93k-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Jul 2025 09:58:48 +0000</pubDate>                                                                                                                                <updated>Tue, 01 Jul 2025 14:03:48 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UjWjTqk5HiFp2xWB4yo93k-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Insider threat hacker concept image showing man typing on keyboard in a dimly lit room. ]]></media:description>                                                            <media:text><![CDATA[Insider threat hacker concept image showing man typing on keyboard in a dimly lit room. ]]></media:text>
                                <media:title type="plain"><![CDATA[Insider threat hacker concept image showing man typing on keyboard in a dimly lit room. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UjWjTqk5HiFp2xWB4yo93k-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A disgruntled IT worker has been jailed after costing his employer £200,000 - and its good reputation - by exploiting his privileged network access.</p><p>West Yorkshire man Mohammed Umar Taj was suspended from his job in Huddersfield in July 2022, and began taking revenge within hours.</p><p>According to West Yorkshire Police, he went back to the company’s premises and accessed its computer systems, altering login credentials to disrupt the firm’s day to day activities.</p><div class="product"><a data-dimension112="ef6af1b3-415b-450f-803d-6597d17f357c" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" data-dimension112="ef6af1b3-415b-450f-803d-6597d17f357c" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">30% off Keeper Security's Business Starter and Business plans</a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="ef6af1b3-415b-450f-803d-6597d17f357c" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>A day later, he went further, changing access credentials and the company’s multi-factor authentication (MFA) - causing big problems for the firm’s clients both in the UK and overseas in Germany and Bahrain.  </p><p>However, Taj wasn’t exactly covert, having kept recordings of his activities and discussing the attack on the phone. These calls and recordings were later accessed by West Yorkshire Police’s cyber team and played a vital role in the case. </p><p>He has now been sentenced to seven months and 14 days in custody for committing unauthorized acts with intent to impair the operation of or hindering access to a computer.</p><p>“Taj set out to get revenge on his employer following his suspension from work. He did so by targeting their IT system, which he had privileged access to. By doing this he created a ripple effect of disruption far beyond the shores of the UK," said detective sergeant Lindsey Brants of West Yorkshire Police’s Cyber Crime Team.  </p><p>“Protecting your network prevents data loss and costly cyber attacks. It also maintains trust with clients and stakeholders. We urge all businesses to look at their network security.” </p><h2 id="why-you-should-always-be-wary-of-insider-threats">Why you should always be wary of insider threats</h2><p>According to a recent <a href="https://gurucul.com/2024-insider-threat-report/" target="_blank"><u>survey</u></a> of more than 400 IT and <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>professionals by Gurucul, 48% experienced a rise in <a href="https://www.itpro.com/security/cyber-attacks/cracking-open-insider-threats">insider attacks</a> in the previous 12 months, with 51% having six or more attacks in that time. </p><p>When it came to the cost of remediation, 32% said it was between $100,000 and $500,000 while 27% put it at anywhere between $500,000 and $1 million.</p><p>Companies are starting to take the risk seriously, however. Alternative <a href="https://www.dtexsystems.com/cost-of-insider-threats-global-report-2025" target="_blank"><u>research</u></a> from DTEX Systems found that organizations are spending 16.5% of their annual IT security budget on insider risk management – up from 8.2% in 2023.</p><p>More than eight-in-ten now have - or are planning to introduce - an insider risk management program. Of those that do, 65% said their program was the only security strategy that enabled them to pre-empt a data breach by detecting insider risk early. </p><p>"Insider-driven security incidents result in significant financial and reputational costs," said DTEX Systems CEO Marshall Heilman. </p><p>"However, organizations investing in dedicated insider risk management programs are achieving faster containment or preventing incidents entirely — a decisive win in the fight against data loss."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/why-you-should-always-be-wary-of-insider-threats-a-disgruntled-employee-at-a-us-industrial-firm-deleted-backups-and-locked-it-admins-out-of-workstations-in-a-failed-data-extortion-attempt">An employee at a US industrial firm deleted backups and locked IT admins out of workstations</a></li><li><a href="https://www.itpro.com/security/disgruntled-dev-malicious-code-insider-threat">Developer crippled company networks with malicious code and a ‘kill switch’ after being sacked</a></li><li><a href="https://www.itpro.com/security/cyber-crime/north-korean-insider-attacks-are-skyrocketing-dozens-of-us-firms-didnt-spot-the-hacker-in-their-midst">North Korean insider attacks are skyrocketing – dozens of US firms didn't spot the hacker in their midst</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The FBI thinks it's nailed the notorious 'IntelBroker' threat actor ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/the-fbi-thinks-its-nailed-the-notorious-intelbroker-threat-actor</link>
                                                                            <description>
                            <![CDATA[ A British man believed to be the notorious ‘IntelBroker’ hacker has been charged in the US following their arrest in France earlier this year. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XUAddJW5o7yFfH8sPqg4sb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4w6boC4sd6Rmk2mt6aw3Ud-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 30 Jun 2025 09:45:26 +0000</pubDate>                                                                                                                                <updated>Mon, 30 Jun 2025 09:45:42 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4w6boC4sd6Rmk2mt6aw3Ud-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber crime concept image showing hacker typing on keyboard in dimly-lit room with tablet pictured on desk. ]]></media:description>                                                            <media:text><![CDATA[Cyber crime concept image showing hacker typing on keyboard in dimly-lit room with tablet pictured on desk. ]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber crime concept image showing hacker typing on keyboard in dimly-lit room with tablet pictured on desk. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4w6boC4sd6Rmk2mt6aw3Ud-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A British man believed to be the notorious ‘<a href="https://www.itpro.com/security/cyber-attacks/intelbroker-leaks-2-9-tb-of-exposed-cisco-records-and-theres-more-to-come">IntelBroker</a>’ hacker has been charged in the US following their arrest in France earlier this year.</p><p>Kai West, 25, also known as Kyle Northern, is accused of carrying out a years-long hacking scheme, conspiring with an online group to steal data from a telecommunications company, a municipal health care provider, an internet service provider, and more than 40 other victims.  </p><p>The group offered the data - which included customer lists and company marketing information - for sale online for more than $2 million, and is believed to have caused more than $25 million in damage. </p><p>"The IntelBroker alias has caused millions in damages to victims around the world,” said US attorney Jay Clayton.  </p><p>“This action reflects the FBI’s commitment to pursuing cyber criminals around the world.  New Yorkers are all too often the victims of intentional cyber schemes and our office is committed to bringing these remote actors to justice.” </p><p>Between around 2023 and 2025, the FBI said West offered stolen data for sale more than 40 times and offered to distribute this data for free around 117 times. </p><p>On some occasions, stolen data was also offered in exchange for credits on the internet forum he and his co-conspirators used, according to the FBI. </p><p>In one case, West sold data from a telecommunications firm that he'd illegally accessed via a <a href="https://www.itpro.com/security/hacking/358261/misconfigured-git-servers-lead-to-nissan-data-leak">misconfigured server</a>.</p><p>In another, he offered patient data from a municipal healthcare provider which included names, Social Security numbers, dates of birth, genders, health plan information, employer information, and more. </p><p>An advisory from <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> firm Kela earlier this year noted that IntelBroker “distinguishes himself in the cyber crime underworld by combining technical expertise with a strong emphasis on operational security”.</p><p>"His approach involves exploiting vulnerabilities as a primary attack vector, while simultaneously utilizing advanced anonymity tools to maintain operational secrecy, solidifying his reputation as a trusted figure within the community,” the company added. </p><h2 id="intelbroker-sting-the-latest-blow-for-cyber-criminals">IntelBroker sting the latest blow for cyber criminals</h2><p>After first making an entrance on hacking forum BreachForums, IntelBroker worked as a ransomware operator, later taking over BreachForums. Over the years, he is believed to have breached organizations including HPE, Cisco, Nokia, Ford, AMD, Zscaler, and Europol.</p><p>"The arrest of the alleged British hacker known as IntelBroker and the recent takedown of BreachForums admins highlight a critical truth about cybersecurity: data theft is rarely a one-off event," Darren Guccione, CEO and co-founder of Keeper Security. </p><p>"The details of this story aptly demonstrate how once stolen, credentials and information can circulate, be aggregated and weaponized for months or even years in some cases."</p><p>"In this instance, the global criminal network’s sustained activity through dark web forums provides a pertinent example of how attackers rely on long-term access, collaboration and shared trust within illicit marketplaces.</p><p>West is charged with conspiracy to commit computer intrusions, which carries a maximum sentence of five years in prison and conspiracy to commit wire fraud, which carries a maximum sentence of 20 years in prison. </p><p>He is also accused of accessing a protected computer to obtain information, which carries a maximum sentence of five years in prison, and wire fraud, with a maximum sentence of 20 years.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/clickfix-social-engineering-state-sponsored-hackers">State-sponsored cyber groups are flocking to the 'ClickFix' social engineering technique</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/states-dont-do-hacking-for-fun-ncsc-expert-urges-businesses-to-follow-geopolitics-as-defensive-strategy">NCSC expert urges businesses to follow geopolitics as defensive strategy</a></li><li><a href="https://www.itpro.com/security/this-new-hacker-group-is-targeting-software-developers-with-phony-job-offers-and-fake-projects">This new hacker group is targeting software developers with phony job offers</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Financial impact of cyber attacks on UK retailers laid bare in new report ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/cyber-attacks-on-uk-retailers-financial-impact</link>
                                                                            <description>
                            <![CDATA[ Analysis from the Cyber Monitoring Centre shows the recent cyber attacks on a host of UK retailers could cost up to £440 million. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MML4cJS6ZT2N37UPMwASVi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ci8VLxJaLb7KFhVHy3RBE5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 25 Jun 2025 09:16:42 +0000</pubDate>                                                                                                                                <updated>Wed, 25 Jun 2025 09:16:57 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ci8VLxJaLb7KFhVHy3RBE5-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Store front of M&amp;S, one of the victims of a wave of cyber attacks on UK retailers, pictured at the Westfield Stratford City Shopping Centre .]]></media:description>                                                            <media:text><![CDATA[Store front of M&amp;S, one of the victims of a wave of cyber attacks on UK retailers, pictured at the Westfield Stratford City Shopping Centre .]]></media:text>
                                <media:title type="plain"><![CDATA[Store front of M&amp;S, one of the victims of a wave of cyber attacks on UK retailers, pictured at the Westfield Stratford City Shopping Centre .]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ci8VLxJaLb7KFhVHy3RBE5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber attacks against M&S and Co-op earlier this year cost anywhere between £270 million to £440m, according to <a href="https://cybermonitoringcentre.com/2025/06/20/cyber-monitoring-centre-statement-on-ransomware-incidents-in-the-retail-sector-june-2025/"><u>analysis by the Cyber Monitoring Centre</u></a>.</p><p>In April, British retailers were targeted with a series of ransomware attacks, with <a href="https://www.itpro.com/security/marks-and-spencer-cyber-incident-update"><u>M&S taking down online sales</u></a> and later admitting <a href="https://www.itpro.com/security/cyber-attacks/m-and-s-customer-personal-data-stolen"><u>customer data was stolen</u></a>. <a href="https://www.itpro.com/security/co-op-cyber-attack"><u>Co-op shut down</u></a> aspects of its own IT system to limit disruption when it was attacked in a similar way. </p><p>Alongside those two, <a href="https://www.itpro.com/security/cyber-attacks/harrods-cyber-attack"><u>Harrods</u></a> and other retailers were impacted by cyber incidents, but the CMC didn't include them in its assessment due to a lack of information. The attacks are believed to be the work of <a href="https://www.itpro.com/security/cyber-crime/scattered-spider-group-marks-and-spencer"><u>"Scattered Spider" hackers</u></a>. </p><p>The mooted figures include the financial impact on M&S and Co-op, as well as their partners and suppliers, taking in lost sales as well as incident response, IT restoration and legal costs. </p><p>"Although both of the targeted companies suffered business disruption, data loss, and costs for incident response and IT rebuild, business disruption drives the vast majority of the financial cost," the CMC said in a statement. </p><p>M&S managed to return to limited online sales late last month after several weeks of disruption. According to the CMS, the financial impact of the incident amounted to around £1.3 million in losses per day. </p><p>"This is less than the total loss in turnover as it takes into account reductions in orders, stock that can be resold later, and not having to pay other variable costs," CMC said. </p><p>“We have not included any <a href="https://www.itpro.com/security/ransomware/ransomware-attacks-reporting-fbi"><u>ransom payments</u></a> as there is no evidence at this point that a ransom was paid or not paid."</p><p>M&S said last month that it expected the incident to cost £300m this year, but that would be reduced through "management of costs, insurance and trading actions." </p><h2 id="narrow-and-deep-impact">Narrow and deep impact</h2><p>Despite the high cost of the incident, the CMC only rated it as a "category 2 systemic event," with the worst possible rating being category five. </p><p>The organization noted that while the implications were significant, the impact was largely limited to the targeted companies and their partners, making it a "narrow and deep" event. </p><p>For comparison, last year's CrowdStrike outage would be considered a "shallow and broad" event, as many businesses were hit, but the impact to each was smaller. </p><p>"We are yet to see a deep and broad category four or category five event impact the UK," the CMC noted in its analysis. </p><p>"Had there been further widespread disruption in the sector, the categorization could have been higher, but because the impact was confined to two companies and their partners, it is judged to be at the lower end of severity on the CMC’s scale."</p><h2 id="additional-disruptions">Additional disruptions</h2><p>CMC noted that M&S' own brand labelling added complexity, as such goods couldn't be rerouted to other retailers to sell before expiration dates, especially for prepared food and meats which have tightened regulations around packaging. </p><p>Another challenge was remote and rural areas, CMC noted, with Co-op one of the only food retailers in some regions. In the Scottish Highlands, for example, residents reported widespread disruption to food supply chains in the wake of the incident. </p><p>"Service disruption in these regions illustrates the broader societal impact cyber events can trigger through concentrated retail supply chains," CMC said. "Co-op are said to have prioritized supplying these stores."</p><p>More generally, CMC highlighted the risks of disruption to modern retail models. </p><p>"The event underscores retail sector vulnerabilities tied to just-in-time stock systems, lack of back-end storage, and high dependency on IT-driven order flows," the analysts said. "When systems fail, it is challenging to revert to manual processes."</p><p>The analysis recommended retail businesses stress-test their business continuity plans — including a fallback to manual ordering and inventory control as well as plans to maintain financial stability and be able to pay suppliers — and create a response plan for ransomware attacks. </p><p>To avoid such incidents, CMC said it was time to improve "cyber hygiene" across service providers and IT supply chain, in particular support desks — which are believed to be how the attackers accessed networks, using compromised credentials and "abuse of IT help desk processes."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/cyber-attacks-have-rocked-uk-retailers-heres-how-you-can-stay-safe">Cyber attacks have rocked UK retailers – here's how you can stay safe</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/north-face-cartier-among-latest-retail-cyber-attack-victims-heres-what-we-know-so-far">North Face, Cartier among latest retail cyber attack victims</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/dragonforce-growing-prominence-retailer-attacks-reputation">Why DragonForce is growing in prominence – with retailer attacks boosting its reputation</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A sneaky cyber espionage campaign is exploiting IoT devices and home office routers – here's what you need to know ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/lapdogs-cyber-espionage-campaign-iot-home-office-routers</link>
                                                                            <description>
                            <![CDATA[ Researchers at SecurityScorecard have issued a warning about a new China-linked threat campaign, dubbed 'LapDogs', targeting IoT devices and home routers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hnTamSnFiPKw4RfcFR3E7U</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4w6boC4sd6Rmk2mt6aw3Ud-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 23 Jun 2025 09:50:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4w6boC4sd6Rmk2mt6aw3Ud-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber crime concept image showing hacker typing on keyboard in dimly-lit room with tablet pictured on desk. ]]></media:description>                                                            <media:text><![CDATA[Cyber crime concept image showing hacker typing on keyboard in dimly-lit room with tablet pictured on desk. ]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber crime concept image showing hacker typing on keyboard in dimly-lit room with tablet pictured on desk. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4w6boC4sd6Rmk2mt6aw3Ud-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cybersecurity experts have issued an alert over a new cyber espionage network that’s believed to have compromised thousands of devices globally. </p><p>Dubbed 'LapDogs' by researchers at SecurityScorecard, the campaign has focused on the US, Japan, South Korea, Taiwan, and Hong Kong. </p><p>The use of Mandarin in developer notes within the startup script, along with the tools, techniques, and procedures (TTPs) used and the choice of targeted regions means it is likely to be run by a China-based group. </p><p>Victims recorded so far include <a href="https://www.itpro.com/infrastructure/networking/the-role-of-isps-in-the-connected-world-now-and-in-the-future">ISPs</a>, hardware vendors, and specific organizations in several sectors, including IT, <a href="https://www.itpro.com/business/business-strategy/367480/it-pro-panel-the-secret-art-of-networking">networking</a>, real estate, and media. </p><p>The campaign appears to have been running since September 2023, with infections remaining undetected for months, allowing for <a href="https://www.itpro.com/security/data-breaches/breached-for-years-how-long-term-cyber-attacks-are-allowed-to-linger">long-term surveillance and exploitation</a>.</p><p>It involves stealthy, <a href="https://www.itpro.com/security/hackers-are-lying-low-in-networks-to-wage-critical-infrastructure-attacks-heres-how-they-do-it">long-term intrusion campaigns</a>, and exploits <a href="https://www.itpro.com/cloud-computing/28037/what-is-iot">IoT </a>devices and Small Office/Home Office (Soho) routers, including legacy devices from vendors such as Ruckus Wireless and Buffalo Technology.</p><p>Unlike traditional <a href="https://www.itpro.com/botnets/1644/what-is-a-botnet">botnets</a>, researchers said the campaign leverages sophisticated Operational Relay Boxes (ORBs) — malicious nodes that route traffic through legitimate devices without triggering alarms, thereby masking the attackers' activities. </p><p>"This campaign shows a surging interest from China-Nexus threat actors in using ORB Networks to conduct covert intrusion campaigns both around the globe and tailored to specific victims of interest," researchers warned. </p><p>"With an increasing interest in this approach, security teams should be on alert that <a href="https://www.itpro.com/security/hacking/362169/news-corp-hack-linked-china">China-Nexus</a> threat actors are disrupting traditional playbooks for IOC tracking, response, and remediation."</p><p>A custom Linux- and Windows-compatible backdoor called ‘ShortLeash’ enables silent control, persistence, and lateral movement inside networks, researchers noted.</p><p>ShortLeash also generates TLS certificates that are spoofed as being signed by the Los Angeles Police Department (LAPD) to further obscure its origin.</p><h2 id="the-lapdogs-campaign-is-expanding-at-pace">The LapDogs campaign is expanding at pace</h2><p>Researchers warned that LapDogs has been spreading methodically, with attackers using it both to anonymize their operations and to establish beachheads into broader infrastructure, including enterprise networks.</p><p>“LapDogs reflects a strategic shift in how cyber threat actors are leveraging distributed, low-visibility devices to gain persistent access,” said Ryan Sherstobitoff, chief threat intelligence officer at SecurityScorecard. </p><p>“These aren’t opportunistic smash-and-grab attacks—these are deliberate, geo-targeted campaigns that erode the value of traditional IOCs (Indicators of Compromise).”</p><p>While there are similarities with PolarEdge, another China-linked ORB network, LapDogs operates independently and its TTPs do differ.</p><p>Researchers said they identified 162 discrete intrusion sets, with around a third sharing a common geographical location or ISP. This, they added, suggests that the operators are highly focused on several specific locations and that LapDogs is a goal-oriented actor. </p><p>"Overall, LapDogs is a vast, prolonged intrusion operation with clear intent and planning, emphasizing the need for vigilance in securing embedded devices," the researchers warned.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/china-cyber-threats">China cyber threats: What businesses can do to protect themselves</a></li><li><a href="https://www.itpro.com/security/cyber-crime/warning-issued-after-chinese-hacker-group-breaches-telco-firms-in-dozens-of-countries">Warning issued after Chinese hacker group breaches telco firms in "dozens of countries"</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/why-government-email-servers-are-top-targets-for-state-backed-hackers">Why government email servers are top targets for state-backed hackers</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ LockBit data dump reveals a treasure trove of intel on the notorious hacker group ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/lockbit-data-dump-reveals-a-treasure-trove-of-intel-on-the-notorious-hacker-group</link>
                                                                            <description>
                            <![CDATA[ An analysis of May's SQL database dump shows how much LockBit was really making ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">q6gHYYicEc4cCKCdXT2Hch</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LrXBU2G7X45b6NeaQsxQsN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 13 Jun 2025 09:37:21 +0000</pubDate>                                                                                                                                <updated>Fri, 13 Jun 2025 09:37:34 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LrXBU2G7X45b6NeaQsxQsN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ransomware concept image showing a warning symbol in red with binary code in background.]]></media:description>                                                            <media:text><![CDATA[Ransomware concept image showing a warning symbol in red with binary code in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Ransomware concept image showing a warning symbol in red with binary code in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LrXBU2G7X45b6NeaQsxQsN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>China and the US were hardest-hit by the LockBit <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>group between December 2024 and April this year, research shows, with affiliates targeting 156 organizations in all.</p><p>Trellix Advanced Research Center has released its <a href="https://www.trellix.com/blogs/research/inside-the-lockbits-admin-panel-leak-affiliates-victims-and-millions-in-crypto/"><u>analysis</u></a> of the LockBit SQL database dump it observed in May, noting that China was probably the greatest focus because of its large industrial base and manufacturing sector. </p><p>"Unlike <a href="https://www.itpro.com/security/ransomware/black-basta-may-have-exploited-microsoft-flaw-before-a-patch-was-issued">BlackBasta</a> and Conti RaaS groups that occasionally probe Chinese targets without encrypting them, LockBit appears willing to operate within Chinese borders and disregard potential political consequences, marking an interesting divergence in their approach," the researchers said.</p><p>Meanwhile, affiliates such as BaleyBeach, umarbishop47, and btcdrugdealer were active in the US, where attacks appeared to be more spread out among affiliates, suggesting a more opportunistic approach rather than specialized targeting. </p><p>Taiwan was the third most-targeted country, followed by Brazil and Turkey. One group, Swan, had a broad geographic reach, targeting multiple European countries including Austria, Czech Republic, and Switzerland. </p><p>This, researchers pointed out, indicates sophistication in the group's ability to navigate different regulatory environments. </p><p>"The victimology data reveals some unexpected targeting patterns. It's particularly surprising to see such a concentrated effort on Chinese and Taiwanese organizations," the researchers said. </p><p>"Unlike other ransomware groups that might shy away from such politically sensitive targets, LockBit appears to have operated with a different calculus."</p><h2 id="lockbit-affiliates-are-diversifying-targets">LockBit affiliates are diversifying targets</h2><p>Manufacturing was the most frequently targeted sector, followed by consumer services, the finance sector, and government services.</p><p>After analyzing LockBit negotiation chats, Trellix researchers discovered 18 confirmed payments to cryptocurrency wallets believed to be under the control of LockBit affiliates, netting them around $2,337,000. </p><p>"The data paints a picture of varying strategies, with initial ransom demands ranging from modest to exorbitant. What’s clear is that substantial discounts were the norm, often between 10% and 80%, highlighting the haggling that goes on behind the scenes of these cyber extortion attempts," researchers said. </p><p>"Affiliate success within LockBit varied significantly, indicating differences in skill and potentially specialization in specific familiar industries and/or countries."</p><p>The LockBit owner appears to have been charging affiliates 20% of ransom payments, adding up to around $456,000 over the period.</p><p>It made a lot less from auto-registration invitations, though - around $10,000 to $11,000. </p><p>"The assertion made by LockBit on the RAMP underground forum, which claimed monthly earnings of $100,000 from auto-registration, is thus considered to be significantly exaggerated," the researchers said.</p><h2 id="lockbit-is-still-causing-havoc">LockBit is still causing havoc</h2><p>LockBit was once one of the most prolific and successful ransomware-as-a-service groups, <a href="https://www.itpro.com/security/ransomware/lockbit-takedown-is-a-huge-win-for-law-enforcement-but-lets-not-celebrate-too-soon-security-experts-warn">but was disrupted early last year</a> by international law enforcement bodies. </p><p>Since then, a number of <a href="https://www.itpro.com/security/cyber-crime/lockbit-developer-snared-in-latest-blow-for-infamous-hacker-group">group members and affiliates have been arrested</a>. </p><p>The group's exaggerated claims of earnings, researchers said, shows how cyber criminals are inclined to hype up their successes and downplay their failures. </p><p>"What this leak truly shows is the complex and ultimately less glamorous reality of their illicit ransomware activities," they said. </p><p>"While profitable, it’s far from the perfectly orchestrated, massively lucrative operation they’d like the world to believe it is."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/ransomware/building-ransomware-resilience-to-avoid-paying-out">Building ransomware resilience to avoid paying out</a></li><li><a href="https://www.itpro.com/security/ransomware/medusa-ransomware-cisa-advisory">CISA issues warning over Medusa ransomware after 300 victims from critical sectors impacted</a></li><li><a href="https://www.itpro.com/security/ransomware/Uk-government-ransomware-payment-ban">UK government officials consider banning ransomware payments</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Disinformation security is a major concern for cyber teams – here's what your business can do ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/disinformation-security-concern-for-cyber-teams</link>
                                                                            <description>
                            <![CDATA[ Attackers can impersonate employees and fake data with increasing ease ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ubNUYZd6YC9jQk9tXr8LvF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Uk9apHytppNEVvCDTRHpAh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 09 Jun 2025 12:37:01 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keri Allan ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/oJZkdPii464j27ff4GCcoT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Uk9apHytppNEVvCDTRHpAh-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A digital illustration showing a portrait of a woman overlaid with a digital boxout of an eye and a mouth and a speech bubble above, surrounded by red and green glitched shapes, to represent deepfakes and digital disinformation.]]></media:description>                                                            <media:text><![CDATA[A digital illustration showing a portrait of a woman overlaid with a digital boxout of an eye and a mouth and a speech bubble above, surrounded by red and green glitched shapes, to represent deepfakes and digital disinformation.]]></media:text>
                                <media:title type="plain"><![CDATA[A digital illustration showing a portrait of a woman overlaid with a digital boxout of an eye and a mouth and a speech bubble above, surrounded by red and green glitched shapes, to represent deepfakes and digital disinformation.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Uk9apHytppNEVvCDTRHpAh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>While new for cybersecurity, disinformation is not new to the world overall. We’ve had misinformation, disinformation and propaganda for centuries, and <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself"><u>‘social engineering’</u></a> is an evolution of this with a cybersecurity bend.</p><p>People have been creating fake or falsified videos and images for as long as we’ve had cameras and editing software, notes Daniel Ayoub, senior director analyst at Gartner. He adds the challenge is growing thanks to the ease with which technology can now be used to enhance or perform these actions with high quality and low barriers to entry. </p><p>“Being able to <a href="https://www.itpro.com/technology/artificial-intelligence/why-i-think-the-scarlett-johansson-openai-scandal-shows-the-danger-of-ai-generated-voice-content"><u>imitate anyone’s voice</u></a> with only a few seconds of audio or create a nefarious video of someone with only a few pictures found online – that’s the scary part.”</p><h2 id="enterprise-vulnerabilities">Enterprise vulnerabilities </h2><p>Businesses, and enterprises in particular, are vulnerable to disinformation due to their reliance on public trust, reputation and digital infrastructure. </p><p>As Lisa Venture, a member of BCS, The Chartered Institute for IT and founder of the Cyber Security Unity community explains, an enterprise’s online presence creates multiple attack surfaces ripe for exploitation. This can include its social media platforms, websites, and digital marketing channels.</p><p>Additionally, organizations often operate in competitive environments where rivals or adversaries may seek to gain an edge by spreading false or misleading information. </p><p>“Their complex supply chains and partnerships also increase exposure, as disinformation campaigns may target associated entities, creating a cascading effect of reputational harm,” she says. </p><h2 id="insider-threats">Insider threats</h2><p>Employees can be another weak link, Venture adds, especially when <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> attacks, fake internal communications or impersonation campaigns exploit their access to sensitive data or systems. </p><p>Social media remains a major vector, where employees may unknowingly encounter and/or share false information about their organization, leadership or industry developments. Messaging apps and collaboration tools, such as <a href="https://www.itpro.com/collaboration/33647/slack-review-free-your-business-comms">Slack</a> and <a href="https://www.itpro.com/software/33703/microsoft-teams-review-a-no-brainer-for-microsoft-shops">Microsoft Teams</a>, have also emerged as internal disinformation conduits.</p><p>“This trend is <a href="https://www.itpro.com/security/why-remote-work-is-still-giving-cisos-security-headaches">amplified by remote and hybrid work </a>environments, where digital interactions dominate, making it easier for disinformation to blend seamlessly into regular communications channels,” Venture says.</p><p><a href="https://www.itpro.com/security/data-protection/disgruntled-ex-employees-are-using-weaponized-data-subject-access-requests-to-pester-firms">Disgruntled employees</a> can also have an impact, as it may not be possible to stop them from spreading disinformation. “Rumor mills will always exist within large organizations, exposing them to risk. These echo chambers of disinformation can amplify false narratives and erode employee confidence,” notes Amanda Finch, CEO at the Chartered Institute of Information Security (CIISec).</p><h2 id="the-impact-of-disinformation-on-businesses">The impact of disinformation on businesses</h2><p>Disinformation can pose a significant threat to companies of all sizes as, if left unchecked, it has the ability to damage reputations and operational integrity. </p><p>One of the biggest challenges is the speed and scale false information can spread, as the perpetrators create fake accounts and leverage bots to amplify their narrative across a variety of digital platforms. </p><p>These kinds of campaigns can undermine consumer confidence and trust, causing significant damage to a brand’s reputation. “At worst, cybercriminals can spread misleading and inaccurate information about share prices and financial results, which can have severe consequences for a company’s bottom line,” notes Finch. </p><p>“We’ve seen major consumer brands become the victims of boycotts due to mis- or disinformation campaigns online eroding their revenue and impacting share prices,” continues Ayoub. “We’ve also seen targeted disinformation attacks, like <a href="https://www.itpro.com/security/preventing-deepfake-attacks-how-businesses-can-stay-protected"><u>deepfakes</u></a>, lead to tens of millions of dollars in fraud from just a single incident.”</p><p>One example is that of the CEO of advertising group WPP, who was the <a href="https://www.theguardian.com/technology/article/2024/may/10/ceo-wpp-deepfake-scam" target="_blank"><u>victim of a deepfake campaign</u></a> where his likeness and voice were cloned to deceive customers into making payments and divulging personal details. Although this was unsuccessful, other companies haven’t been so lucky. Take Arup, for example, which saw <a href="https://www.itpro.com/security/financial-services-workers-are-facing-a-wave-of-deepfake-scams-and-its-only-going-to-get-worse"><u>one employee tricked into transferring approximately £20m</u></a> of company funds to cybercriminals via an AI-generated video call.</p><h2 id="how-businesses-can-fight-disinformation">How businesses can fight disinformation</h2><p>We’re still in the early stages of disinformation campaigns, says Ayoub, with attacks originating from both in- and outside a business. But there are several ways organizations can fight back. </p><p>In terms of technology, Gartner is seeing three main tools being adopted. The first is media monitoring, or narrative intelligence, which looks at how information is being spread online.</p><p>“Monitoring internal systems and tools to increase resilience is something most organizations are aware of, however less obvious is monitoring external sources that are outside the organization’s control. We’re seeing new tools emerging which aim to close these gaps, but the market is still in early stages,” Ayoub says. </p><p>“Narrative intelligence builds on <a href="https://www.itpro.com/business-strategy/data-insights/369981/machine-learning-vs-data-science-whats-the-difference"><u>sentiment analysis</u></a> techniques that would normally be used by marketing teams to gauge customer satisfaction and instead combines knowledge gaps, bot management and <a href="https://www.itpro.com/technology/artificial-intelligence/generative-ai-vs-large-language-models"><u>large language models</u></a> to track what’s being said, by whom, where and how it’s being spread.”</p><iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/bfcd6919-8e10-4119-8d56-8051b8b5ab76/"></iframe><p>Then there’s trust assessment, which builds upon fact checking but goes beyond to correlate information based on multiple public and private sources. “It also works with generative AI to prevent hallucinations or giving responses that are untrue,” Ayoub adds. </p><p>Lastly, there’s deepfake detection, which can be used to determine whether audio, video or images were created using generative AI to imitate real/authentic content. </p><p>While employees can often be the cause of disinformation, they can also be the solution to this problem. Just as companies prioritize employee training to defend against cyber attacks, says Finch, businesses should also equip their teams to recognise disinformation and how to respond effectively to minimise harm.</p><p>This focus on education should also extend to customers, she points out. “Banks serve as a strong example of how industries can tackle disinformation, offering clear and actionable guidance, such as instructing customers to never share personal information over the phone. If customers fall victim to disinformation, the resulting loss of trust can be as harmful to an organization as direct financial losses.</p><p>“Ultimately, governments will need to step in to regulate disinformation, particularly on platforms like social media, which often serve as testing grounds for malicious actors,” she adds. </p><h2 id="time-to-prepare">Time to prepare</h2><p>Disinformation is poised to evolve as a more pervasive and sophisticated cybersecurity threat in the next five years says Venture, driven by technological advancements and the increasing integration of digital ecosystems. </p><p>The good news, however, is that by 2030, Ayoub expects that a lot of the low hanging fruit, or easy gaps to be addressed, will be introduced within existing tools and platforms, making it harder to pull off these kinds of attacks. </p><p>Experts predict security-orientated features like digital watermarking, authenticated and secure communications, secret safety passphrases and sentiment analysis will fully penetrate the market, while at the same time governments and regulatory bodies are likely to respond with stricter frameworks.</p><p>The threat from disinformation may be growing but so are the necessary tools to safeguard reputations and operations. As these continue to become more readily available, now’s the time for enterprises to take a proactive approach to protecting their organisation. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI is clamping down on ChatGPT accounts used to spread malware ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/openai-is-clamping-down-on-chatgpt-accounts-used-to-spread-malware</link>
                                                                            <description>
                            <![CDATA[ Tools like ChatGPT are being used by threat actors to automate and amplify campaigns ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dvQ5V6ky8EKaaP74Xf5Upn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AM7ReJDhZZWMAqjKqACmJL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 09 Jun 2025 10:39:03 +0000</pubDate>                                                                                                                                <updated>Mon, 09 Jun 2025 10:39:15 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AM7ReJDhZZWMAqjKqACmJL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ChatGPT logo and branding pictured in white coloring against a black backdrop.]]></media:description>                                                            <media:text><![CDATA[ChatGPT logo and branding pictured in white coloring against a black backdrop.]]></media:text>
                                <media:title type="plain"><![CDATA[ChatGPT logo and branding pictured in white coloring against a black backdrop.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AM7ReJDhZZWMAqjKqACmJL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>OpenAI has taken down a host of ChatGPT accounts linked to state-sponsored threat actors as it continues to tackle malicious use of its AI tools. </p><p>The ten banned accounts, which have links to groups in China, Russia, and Iran, were used to support cyber crime campaigns, the company revealed late last week. </p><p>"By using <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>as a force multiplier for our expert investigative teams, in the three months since our last report we’ve been able to detect, disrupt, and expose abusive activity including social engineering, cyber espionage, deceptive employment schemes, covert influence operations and scams," OpenAI said in a <a href="https://cdn.openai.com/threat-intelligence-reports/5f73af09-a3a3-4a55-992e-069237681620/disrupting-malicious-uses-of-ai-june-2025.pdf" target="_blank"><u>blog post</u></a> detailing the takedown. </p><p>Four of the campaigns appear to have originated in China, generating posts in English, Chinese, and Urdu that were then posted on social media sites including TikTok, X, Reddit, and Facebook.</p><p>Topics included Taiwan, specifically targeting Reversed Front, a video and board game that depicts resistance against the Chinese Communist Party, along with posts on Pakistani activist Mahrang Baloch, who has publicly criticized China’s investments in Balochistan and the closure of the US Agency for International Development (USAID).</p><p>Meanwhile, a group of ChatGPT accounts apparently operated by a Russian-speaking threat actor were banned. OpenAI said these were being used to develop and refine malware strains aimed at targeting Windows devices. </p><p>Threat actors also used the chatbot to debug code in multiple languages and to set up their command-and-control infrastructure.</p><p>Other China-linked accounts - dubbed Uncle Spam - were used to create social media posts on US politics, particularly tariffs. </p><p>"We banned ChatGPT accounts that were generating short recruitment-style messages in English, Spanish, Swahili, Kinyarwanda, German, and Haitian Creole.” the company said. “These messages offered recipients high salaries for trivial tasks — such as liking social media posts —and encouraged them to recruit others." </p><p>Sam Rubin, SVP of Unit 42 at Palo Alto Networks, said the report aligned with what its own cybersecurity specialists have been seeing in recent months. </p><p>Threat actors are increasingly flocking to AI tools to support and ramp up operations and activities, he noted. </p><p>"Attacker use of LLMs is accelerating, and as these models become more advanced, we can expect attacks to increase in speed, scale, and sophistication. It’s no surprise that threat actors — from profit-driven cybercriminals to state-sponsored groups like those aligned with China — are embracing LLMs,” Rubin commented. </p><p>“They lower the barrier to entry and dramatically improve the believability of malicious content. In one model we tested, 51 out of 123 malicious prompts slipped past safety filters — a 41% failure rate that makes it clear today’s guardrails aren’t holding the line."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/business/ai-enabled-cyber-attacks-exacerbated-by-digital-divide-in-uk">AI-enabled cyber attacks exacerbated by digital divide in UK</a></li><li><a href="https://www.itpro.com/security/cyber-crime/agentic-ai-cybersecurity-risks">Agentic AI could be a blessing and a curse for cybersecurity</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/executives-ai-cybersecurity-teams-vs-analysts">Executives think AI can supercharge cybersecurity teams – analysts aren’t convinced</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘States don’t do hacking for fun’: NCSC expert urges businesses to follow geopolitics as defensive strategy ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/states-dont-do-hacking-for-fun-ncsc-expert-urges-businesses-to-follow-geopolitics-as-defensive-strategy</link>
                                                                            <description>
                            <![CDATA[ Paul Chichester, director of operations at the UK’s National Cyber Security Centre, urged businesses to keep closer tabs on geopolitical events to gauge potential cyber threats. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tWmWKKmQCWqZdQFyWWxsaA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TLqJdzSrYCkAScByVUwGaF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 05 Jun 2025 09:01:08 +0000</pubDate>                                                                                                                                <updated>Thu, 05 Jun 2025 09:01:17 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ rory.bathgate@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rory Bathgate is the Features and Multimedia Editor at ITPro, overseeing all in-depth content and case studies. He is a subject expert on artificial intelligence and business networks but in his time at ITPro has also covered a wide range of areas including cyber security and hardware. Throughout his time at ITPro, Rory has charted the rise in popularity of generative AI and specifically companies such as Microsoft, OpenAI, and Google.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Alongside this, he has delved into increasing calls for ethical and responsible AI as global legislators circle the technology, as well as the latest in mobile networking technology, from 5G mmWave to the 3G sunset and how it will affect businesses.&lt;/p&gt;
&lt;p&gt;He has provided coverage from high-profile tech conferences such as Dell Technologies World, SuiteWorld, and VMware Explore Europe. His on-the-ground coverage has included live blogs, extensive daily coverage of the most significant announcements, analysis pieces, and podcasts.&lt;/p&gt;
&lt;p&gt;Indeed, Rory is also a full-time co-host of the ITPro Podcast alongside Jane McCallion, where he swaps a keyboard for a microphone to discuss the latest learnings in tech. Each week, a guest comes onto the show to discuss topics such as cyber security, productivity, or digital transformation in detail.&lt;/p&gt;
&lt;p&gt;Rory has an MA in Eighteenth-Century Studies from King’s College London, as well as a BA in English and American Literature from the University of Kent. He joined ITPro in 2022 as a graduate, after four years in student journalism.&lt;/p&gt;
&lt;p&gt;In his free time, Rory enjoys photography and video editing, and can often be found at the cinema or reading a good science fiction paperback.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TLqJdzSrYCkAScByVUwGaF-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Russian hacker concept image showing a skulls and crossbones colored like the Russian Federation flag, made up of binary code, and imposed over a digital interface.]]></media:description>                                                            <media:text><![CDATA[Russian hacker concept image showing a skulls and crossbones colored like the Russian Federation flag, made up of binary code, and imposed over a digital interface.]]></media:text>
                                <media:title type="plain"><![CDATA[Russian hacker concept image showing a skulls and crossbones colored like the Russian Federation flag, made up of binary code, and imposed over a digital interface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TLqJdzSrYCkAScByVUwGaF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Business leaders need to stay up to date with geopolitics to keep their cybersecurity strategies up to date and mitigate the risks posed by state-backed hacker groups. </p><p>This is the message that Paul Chichester, director of operations at the UK’s <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do"><u>National Cyber Security Centre (NCSC)</u></a>, delivered to attendees at a keynote session of Infosecurity Europe 2025.</p><p>The call to action from Chichester came as states known to support threat actors and engage in cyber attacks of their own step up efforts to disrupt critical infrastructure</p><p>Chichester said Russia’s cyber capabilities in particular have improved in recent years, with its invasion of Ukraine used as an opportunity to hone offensive cyber techniques. Along with Russia, Chichester focused on the threat <a href="https://www.itpro.com/security/cyber-attacks/china-cyber-threats"><u>China-backed groups</u></a> pose to both public and private organizations.</p><p>“I'll come back to this a few times, but states don't do hacking for fun,” Chichester said.</p><p>“They do not do things for the sake of it. There is always a reason. We might not know the reason sometimes and that's quite a challenge for us, but we shouldn't assume that they're just doing it because they can.”</p><p>Chichester urged businesses who are being targeted by a state APT to carefully consider why and to assess how geopolitics feeds into their defensive strategies.</p><p>“At the end of the day, cyber isn't really just, or even, a technical thing. It's a tool that somebody uses, be it a criminal, be it a state. How does that risk manifest itself for you?”</p><p>The past few years have seen a number of high-profile attacks by <a href="https://www.itpro.com/security/cyber-attacks/state-sponsored-cyber-attacks-the-new-frontier"><u>state-sponsored groups</u></a> on organizations to achieve ideological and military aims. Chichester said Russia is increasingly targeting supply chains which feed into Ukraine, with defense, energy, and logistics companies firmly in its crosshairs.</p><p>In 2022, for example, Microsoft warned the Russia-backed group Seashell Blizzard was using the Prestige <a href="https://www.itpro.com/security/ransomware/new-ransomware-groups-worrying-security-researchers"><u>ransomware strain</u></a> to target organizations involved in the supply or transport of humanitarian aid and military shipments to Ukraine. </p><p>This is also coming from within the GRU military intelligence service, and Chichester cited the example of Unit 29155. This Russian military sabotage unit is known for its role in the 2018 Skripal poisonings, but it is now using cyber attacks to carry out its aims.</p><p>“Ultimately, if you want to target something in the real world, you need to understand them in the cyber world. You need to understand how they operate, you need to understand their movements, you need to understand what's going where,” Chichester explained.</p><p>“And we're seeing that merger of that real world sabotage being joined with that cyber espionage piece as well – and also cyber sabotage.”</p><p><a href="https://www.itpro.com/security/cyber-attacks/367634/five-eyes-and-us-governments-confirm-russia-behind-attacks"><u>Russia launched a major cyber attack on Viasat</u></a>, a US communications company, on 24 February 2022, the same day it invaded Ukraine. This triggered a widespread outage, impacting Ukrainian military command and control and causing knock-on outages for several thousand internet-connected German wind turbines. </p><p>Chichester said the attack was carefully-timed to hit hardest in the first 24-48 hours of the invasion and “might have been a deciding factor” in the war had events on the ground gone differently.</p><p>Despite the apparently unintentional effects on EU-based companies, Chichester used the attack as an example of how states are increasingly targeting private businesses to achieve military or ideological aims.</p><p>China is also heavily implicated in attacks on critical national infrastructure, with cyber experts Kevin Mandia and Nicole Perlroth having recently warned the nation state has <a href="https://www.itpro.com/security/china-has-almost-doubled-their-aggression-in-cyber-kevin-mandia-and-nicole-perlroth-warn-organizations-arent-waking-up-to-growing-apt-threats"><u>ramped up its cyber aggression</u></a>.</p><p>Chichester said attacks by Volt Typhoon, an <a href="https://www.itpro.com/security/cyber-attacks/what-is-an-apt"><u>advanced persistent threat (APT)</u></a> that <a href="https://www.itpro.com/security/cyber-attacks/volt-typhoon-threat-group-electric-grid"><u>successfully breached the US electric grid</u></a> for almost a year, as well as Salt Typhoon which <a href="https://www.itpro.com/security/fcc-tells-telcos-to-sharpen-up-security-after-salt-typhoon-chaos"><u>carried out major attacks on US telcos in 2024</u></a>, show groups ‘pre-positioning’ themselves inside critical infrastructure.</p><p>As <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a"><u>warned by CISA</u></a>, this could enable undetected groups to carry out devastating attacks in the event of conventional war in the long-term.</p><h2 id="for-profit-attacks-remain-king">For-profit attacks remain king</h2><p>Despite the growing threat posed by state-backed groups pursuing ideological and military aims, evidence suggests that businesses will still largely contend with traditional threat actors.</p><p>In a separate keynote talk at the event, James Lyne, office of the CEO at the SANS Institute and Ciaran Martin, director of CISO network at the SANS Institute and former head of the NCSC, balanced the real threat of state-backed groups with those of profit-motivated groups.</p><p>“Most people are interested in fraud,” said Lyne. “Most of this stuff is about making money, the average obsession of the average criminal gang is far more mundane.”</p><p>“I think that's probably largely going to continue to be the case,” he added.</p><p>Lyne noted that, like the German wind farm operators inadvertently impacted by Russia’s attack on Viasat, some serious cyber attacks are mere “collateral damage” from campaigns aimed at other targets.</p><p>Martin said this was seen in the worst period of his time at the NCSC: the six-week period in 2017 in which <a href="https://www.itpro.com/security/cyber-crime/north-korean-insider-attacks-are-skyrocketing-dozens-of-us-firms-didnt-spot-the-hacker-in-their-midst"><u>North Korea</u></a> launched the <a href="https://www.itpro.com/security/ransomware/367659/wannacry-five-years-on-part-two/2"><u>WannaCry</u></a> ransomware attack, while suspected Russian groups hit Ukrainian banks and other organizations with the <a href="https://www.itpro.com/malware/34381/what-is-notpetya"><u>NotPetya</u></a> malware.</p><p>“Between them, they [did] north of $10 billion of destruction and in my, sadly, favorite example from NotPetya, they’re attacking Ukrainian tax software and they end up stopping production at Cadbury’s chocolate factory in Tasmania, off the south coast of Australia.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/the-iran-cyber-threat">The Iran cyber threat: Breaking down attack tactics</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/why-government-email-servers-are-top-targets-for-state-backed-hackers">Why government email servers are top targets for state-backed hackers</a></li><li><a href="https://www.itpro.com/security/state-sponsored-cyber-crime-is-officially-out-of-control">State-sponsored cyber crime is officially out of control</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘I take pleasure in thinking I can rid society of at least some of them’: A cyber vigilante is dumping information on notorious ransomware criminals – and security experts say police will be keeping close tabs ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/ransomware-conti-trickbot-leaks-gangexposed</link>
                                                                            <description>
                            <![CDATA[ An anonymous whistleblower has released large amounts of data allegedly linked to the ransomware gangs ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3sqwxUBfDAXNBC4mxqQxnZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hm7qyYp9PbhjVaXbk3hMkE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 03 Jun 2025 23:04:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hm7qyYp9PbhjVaXbk3hMkE-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ransomware criminal concept image showing hacker in a hooded top working on a laptop in a dark room.]]></media:description>                                                            <media:text><![CDATA[Ransomware criminal concept image showing hacker in a hooded top working on a laptop in a dark room.]]></media:text>
                                <media:title type="plain"><![CDATA[Ransomware criminal concept image showing hacker in a hooded top working on a laptop in a dark room.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hm7qyYp9PbhjVaXbk3hMkE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A mysterious leaker going by the alias <em>GangExposed </em>has been revealing the identities of individuals linked to the Conti and Trickbot <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>groups.</p><p>The data includes aliases, photos, and videos of several group members and their front companies, along with thousands of chat logs, personal videos, and ransom negotiations with victims.</p><p><a href="https://www.theregister.com/2025/05/31/gangexposed_coni_ransomware_leaks/" target="_blank"><u><em>The Register</em></u></a><em> </em>has spoken to the whistleblower via Signal, who said the leaks were a "fight against an organized society of criminals known worldwide", adding, "I take pleasure in thinking I can rid society of at least some of them." </p><p>GangExposed claimed that Stern - the leader of TrickBot and Conti - is actually 36-year-old Russian national Vitaly Nikolaevich Kovalev. This was later confirmed by German police.</p><p>Another major player, Professor, has been named as 39-year-old Russian Vladimir Viktorovich Kvitko, who allegedly lives in Dubai.</p><p>"Kvitko maintains a modest lifestyle, with known property in Moscow and several vehicles registered to family members," GangExposed said. </p><p>"Income mostly originates from RM RAIL Management Company and Rosselkhozbank. In contrast, other Conti leaders (e.g., 'Target') display significant luxury assets, including a Moscow City apartment, Ferrari, and 2 multiple Maybach vehicles."</p><p>The Trickbot ransomware group, also known as Wizard Spider, has been active since at least 2016 and has used a number of other malware variants as well as the Trickbot malware after which it was named.</p><p><a href="https://www.itpro.com/security/ransomware/363893/conti-ransomware-data-leaked-ukranian-researcher">Conti</a>, meanwhile, was first observed in 2019, and is believed to have merged with <a href="https://www.itpro.com/cyber-security/34809/trickbot-trojan-named-the-most-dangerous-threat-to-healthcare">Trickbot </a>in the last two years.</p><p>GangExposed claims to have obtained the leaked data via semi-closed databases, dark web services, and purchased information. Similarly, the individual reportedly has access to a leaked FSB border control database being sold on the <a href="https://www.itpro.com/security/32117/what-is-the-dark-web">dark web</a>. </p><p>He said he plans to expose around 50 gang members in all.</p><h2 id="gangexposed-leaks-could-have-major-repercussions">GangExposed leaks could have major repercussions</h2><p>David Sancho, senior threat researcher at Trend Micro, said the leaks could have serious repercussions for members of the notorious ransomware groups. </p><p>"The GangExposed leak will have serious reverberations for those who led the Conti group in its active years. The individual behind the leaks is either an insider from the group or has managed to hack the inner circle," Sancho said. </p><p>"Either is damaging. If the individuals unmasked as key Conti figures are still in Dubai as the leak claims, then they will either be plotting their way back to Russia or already on their way. Past law enforcement action against cyber criminals has shown how Dubai can be cooperative with Western law enforcement."</p><p>Sancho added that the leak is likely to attract attention and follow-up from the authorities.</p><p>"Law enforcement isn’t always a fast-moving animal but when this kind of information is leaked, wheels start moving and law enforcement is unrelenting in tracking individuals down and making arrests," he said.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li>INSERT STORY LINK</li><li>INSERT STORY LINK</li><li>INSERT STORY LINK</li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AVCheck cyber crime service snared in police takedown  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/avcheck-cyber-crime-service-snared-in-police-takedown</link>
                                                                            <description>
                            <![CDATA[ Authorities have seized the domains of AVCheck, one of the largest counter antivirus services used by cybercriminals around the world ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rALJbRVnbo9BswhQRfVstH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mP59D9NhKL5dmDvk5CMAzZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 02 Jun 2025 14:53:36 +0000</pubDate>                                                                                                                                <updated>Mon, 02 Jun 2025 14:53:47 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mP59D9NhKL5dmDvk5CMAzZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Neptune RAT malware concept image showing a skull and crossbones in binary code against a red colored backdrop.]]></media:description>                                                            <media:text><![CDATA[Neptune RAT malware concept image showing a skull and crossbones in binary code against a red colored backdrop.]]></media:text>
                                <media:title type="plain"><![CDATA[Neptune RAT malware concept image showing a skull and crossbones in binary code against a red colored backdrop.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mP59D9NhKL5dmDvk5CMAzZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>An international law enforcement operation has disrupted an online software crypting syndicate which helps cyber criminals protect their malware from detection.</p><p>Four domains and their associated server offering counter-antivirus (CAV) tools have been seized by the FBI Houston Field Office, working with law enforcement partners in the Netherlands and Finland and the US Secret Service. </p><p>When used with crypting services that make malware difficult for antivirus programs to detect, CAV allows criminals to obfuscate the malware, making it undetectable and enabling unauthorized access to computer systems.</p><p>"Cyber criminals don’t just create malware; they perfect it for maximum destruction," said FBI Houston special agent in charge Douglas Williams.  </p><p>"By leveraging counter antivirus services, malicious actors refine their weapons against the world’s toughest security systems to better slip past firewalls, evade forensic analysis, and wreak havoc across victims’ systems."</p><p>The operation targeted AVCheck, one of the largest Counter Antivirus (CAV) services used by cybercriminals around the world. </p><p>The investigators made undercover purchases from seized websites and analyzed the services, confirming they were designed for cyber crime. They also reviewed linked email addresses and other data connecting the services to known ransomware groups that have targeted victims both in the US and other countries.  </p><p>Meanwhile, as well as taking down AVCheck, the Netherlands' High Tech Crime Team has made wider interventions, including creating a fake login page to deter users of AVCheck. Authorities said the investigation has also yielded 'key evidence' on the administrators and users of AVCheck and its related services Cryptor.biz and Crypt.guru.</p><p>"Modern criminal threats require modern law enforcement solutions. As cybercriminals have become more sophisticated in their schemes, they have likewise become more advanced in their efforts to avoid detection," said US attorney Nicholas J Ganjei.</p><p>"As such, our law enforcement efforts must involve striking not just at the individual fraudster or hacker, but the enablers of these cybercriminals as well. This investigation did exactly that. With this syndicate shut down, there is one less provider of malicious tools for cybercriminals out there."</p><p>The seizures were made as part of Operation Endgame, a multinational law enforcement initiative aimed at dismantling cyber criminal services. </p><p>This latest effort follows another <a href="https://www.itpro.com/security/europol-operation-endgame-botnet-follow-up-arrests">Operation Endgame</a> move last week in which hundreds of servers were taken down as part of an international operation against ransomware groups. Three hundred servers were taken down, 650 domains neutralized, and nearly two dozen international arrest warrants issued.</p><p>"Cyber criminals are often hard to track down, so it is important to invest in a broad approach so the authorities can keep a step ahead," said Matthijs Jaspers, team lead of the Netherlands' High Tech Crime Team.</p><p>"Joint interventions by national, international, and public-private partnerships are becoming increasingly important to prevent victims, stop crimes, and stop online crime in its tracks."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/malware/why-malware-as-a-service-is-becoming-a-serious-problem">Why ‘malware as a service’ is becoming a serious problem</a></li><li><a href="https://www.itpro.com/security/malware/what-is-polymorphic-malware">What is polymorphic malware?</a></li><li><a href="https://www.itpro.com/security/malware/infostealer-malware-threat-to-businesses">Infostealer malware: What’s the threat to businesses?</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>