โŒ

Normal view

There are new articles available, click to refresh the page.
Yesterday โ€” 15 September 2026Tech

CenterPoint Energy confirms intruder helped themselves to customer information

15 September 2026 at 10:14
Texas utility CenterPoint Energy has confirmed that an attacker broke in and stole customer information through one of its internet-facing systems. The company disclosed the breach in a Form 8-K filing with the Securities and Exchange Commission after a post on a cybercrime forum claimed to offer its customer data. Houston-based CenterPoint, which serves around 7 million customers, said its electricity and gas services remain operational and undisrupted. "While the investigation remains ongoing, the company has determined that an unauthorized third party obtained personal information relating to a portion of the company's customers through one of the company's external-facing systems," the filing said. "The company is continuing to work with third-party experts to determine the scope of customers and personal information affected by the incident and intends to notify affected customers and regulatory authorities as required by applicable law. "The company reported the matter to law enforcement authorities and has notified certain regulatory authorities of the issue." The person claiming responsibility said they extracted 7.49 million of CenterPoint's files from a poorly secured API. Among the data allegedly available to download are customer names and contact details, billing data, move-in dates, driver's license information, and the last four digits of Social Security numbers. The Register has not independently verified the contents of the alleged data dump. When we asked CenterPoint for comment on the veracity of the claims, it told us: "Our filing speaks for itself." CenterPoint said it does not believe the incident is reasonably likely to materially affect its financial condition or results of operations. For operators of critical infrastructure, cyberattacks can lead to far worse outcomes. Recently, disruptive attacks have been recorded at facilities in Poland and the UK, and more than 100 US water systems were affected by attacks in July. The US consistently warns about the cyber threat facing utility providers from hostile states because successful attacks can disrupt essential services. ยฎ

Before yesterdayTech

HBO Max Reddit account compromised to serve ClickFix attacks

14 September 2026 at 18:43
Someone compromised the official HBO Max Reddit account and used it to push more than 100 malicious ads serving up ClickFix attacks targeting both Windows and macOS devices with information-stealing malware. A Reddit user uncovered the infostealer ads on September 6, noting that the ad showed u/hbomax as the author โ€” this is the verified HBO Max account โ€” and advertised a macOS app for HBO Max. The streaming service does not offer a native client for the Mac. Anyone who clicked on the malicious ad would then be taken to a โ€œsomewhat-legitimateโ€ looking landing page (hbomaxx[.]us) that includes a join/download button. Clicking the button produced instructions telling the user to copy and paste a command into Terminal on macOS. The Reddit security sleuth described that as โ€œthe classic infostealer/clickfix paste this command to download,โ€ noting that they tested all of this in a sandboxed environment, and didnโ€™t actually run the executable on their machine. โ€œMy guess is that the Reddit account is compromised,โ€ they concluded. Three days later, Reddit paused the infostealer-dropping ads, and an admin said the social media platformโ€™s safety and security teams were investigating what happened. HBO Maxโ€™s parent company Warner Bros. Discovery didnโ€™t immediately respond to The Registerโ€™s inquiries about the account takeover - including who hijacked the streaming serviceโ€™s Reddit account and how they did it. Maybe someone who didnโ€™t like the House of the Dragon season 3 finale? We will update this story if and when we hear back. Researchers at Hudson Rock and ADAMnetworks analyzed the ads, and in a couple of reports said the HBO Max account hijacking was part of a โ€œmassive 48-hour malvertising blitzโ€ that pushed 108 distinct ads using multiple software lures. They named the campaign PasteSwitch, and said it serves up targeted malware aimed at victimsโ€™ operating system - either macOS or Windows. The payloads include infostealers, malware loaders, cryptocurrency clippers, and fake cryptocurrency wallet applications. The cryptocurrency clippers - PasteSwitch delivers either AnimateClipper or ZigClipper - also provide blockchain-based command-and-control fallbacks for the attackers. They use Binance Smart Chain (BSC) contracts to dynamically fetch whatever C2 domain the crooks are using at any given time. โ€œBetween March and July 2026, researchers observed 36 mainnet changes executed by the same attacker controller address,โ€ Hudson Rock said. โ€œBecause the C2 domain is hosted directly on the blockchain, the infrastructure demonstrates dynamic resilience, allowing the threat actors to easily rotate burned domains.โ€ In addition to HBO Max, the attackers used developer-tool, disk-cleaner, and AI-themed lures, including fake OpenAI Codex ads, which crims have previously used to push Mac malware. Of the 108 ads, 46 used an HBO Max lure, directing app seekers to either hbomaxx[.]app or hbomax-macos[.]com. Another 36 tried to trick prospective victims via an OpenAI Codex theme (with a codex-craft[.]com) landing page. Of the rest: 15 purported to be a macOS disk utility (apple.clean-disk-guide[.]com) and 11 used other developer tools as lures (code-desktop[.]com). โ€œThe campaign proves once again why trusted distribution channels are becoming prime targets for infostealer delivery,โ€ Hudson Rock co-founder and CTO Alon Gal said in a LinkedIn post. It also shows that miscreants continue to make heavy use of ClickFix attacks, so thereโ€™s little sign this social engineering method is going away anytime soon.ยฎ

Cyberattack sends International Meteor Organization crashing back to Earth

14 September 2026 at 12:00
The International Meteor Organization (IMO) is watching for fireballs again, but much of its website remains offline after a cyberattack that it says will take weeks to recover from. The Belgium-based nonprofit, which coordinates meteor observations and brings together amateur and professional astronomers worldwide, is currently serving visitors a stripped-down holding page explaining the outage. "We recently suffered a cyberattack that dealt a critical blow to aging infrastructure, taking much of our site offline," the organization said. "We expect several weeks of partial downtime as we transition to new infrastructure and services." IMO has not disclosed when the attack occurred, how the attackers gained access, or whether they accessed or encrypted any data. The organization collects reports from people who spot unusually bright meteors, or fireballs, and uses those observations to help document and analyze events. Its notice says it prioritized restoring that capability after the attack. "We prioritized restoring fireball reporting, and it is available again," IMO said. "If you saw a fireball or a bright light in the sky, you can still submit your observation." Other parts of the site remain unavailable while the organization rebuilds its infrastructure. IMO's warning that the process will take several weeks suggests this is more than a case of simply restoring a compromised web server, although the organization has not disclosed the extent of the damage. The incident also leaves some unanswered questions about the data held on the affected systems. IMO operates services used by meteor observers and members around the world, but has not said whether information belonging to users or contributors was exposed during the attack. The Register asked IMO when the attack occurred, which systems were affected, whether any data was compromised, and whether it has identified who was responsible, but has not yet received a response. IMO is used to documenting things that burn up spectacularly. It probably didn't expect its IT infrastructure to join them. ยฎ

Revolut falls for fake government requests, hands over customer data

14 September 2026 at 07:26
British bank Revolut exposed sensitive customer information after falling for fraudulent requests sent from a legitimate government agency's email domain. In a statement shared with The Register, Revolut confirmed the attack, but did not specify how many customers were affected. The company also did not provide a list of affected data types. However, blockchain investigator ZachXBT, who shared Revolut's customer notifications on Friday, claimed the exposed information includes know-your-customer (KYC) data. Whichever identity document customers submitted as part of the account registration process โ€“ passport or driver's license โ€“ was compromised, as was the verification selfie submitted through the app, according to the shared emails. The notifications also list account statements, IBANs, withdrawal records, and full transaction histories, including Bitcoin transactions, among the exposed data. Other exposed details include full names, dates of birth, home and email addresses, phone numbers, and occupations. Sources close to the fintech say only a small proportion of its customers were impacted. They say ongoing investigations and confidentiality obligations prevent Revolut from providing further details. Revolut said it exposed the data to an unauthorized third party after they submitted requests from a genuine government agency's email domain. The company, which received approval to launch its UK bank in March, did not identify the government agency, but said it informed the relevant officials of the findings. "Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information," the spokesperson said. "Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators. Revolut systems and customer funds are unaffected. "We have contacted the limited number of impacted individuals directly to inform them and provide support." People claiming responsibility for the attack have posted in multiple Telegram groups. Posts seen by The Register include snippets of data that appear to belong to high-profile individuals, including CEOs, sports professionals, and performing artists. The posters are also threatening to release "more and more data every day until Revolut pays for leaking their customers," and are demanding 10,000 Bitcoin as a ransom, equivalent to more than $782 million. Revolut did not comment on the alleged ransom demands when asked. The company currently serves more than 80 million personal customers globally, as well as more than 800,000 businesses. Its co-founder and CEO, Nik Storonsky, has hinted at taking the fintech public, but not before 2028, with a target valuation of around $200 billion. ยฎ

Sam Bankman-Fried, Former Crypto Billionaire, Appeals His Conviction To the US Supreme Court

13 September 2026 at 01:00
America's highest court heard Sam Bankman-Fried's request for a new trial on Thursday, CNN reports. But they add that "the former crypto mogul who was convicted of defrauding investors by secretly diverting billions of dollars of their money" also asked America's high court "to throw out a court order requiring him to pay $11 billion as part of his sentence." Bankman-Fried was sentenced to 25 years in prison in 2024 after prosecutors said he directed billions of dollars from the crypto exchange FTX to a hedge fund he controlled called Alameda Research, where the funds were used for risky investments, political donations and his own personal benefit. The Supreme Court appeal, which was reviewed by CNN, raises a technical question about evidence that was submitted at his trial, and whether Bankman-Fried should have been permitted to demonstrate that his investments were ultimately sound and would have covered any losses by FTX customers. He also argues that the $11 billion forfeiture violates the 8th Amendment's prohibition on excessive fines. "Where the government pursues a theory of fraud under which it doesn't matter whether any victims lost money, introducing evidence suggesting that people actually lost money is distracting and prejudicial," veteran Supreme Court attorney Jeffrey Fisher told CNN. "All the more so where the truth is the victims did not lose money, and the defendant is unable to make that clear." The 2nd US Circuit Court of Appeals rejected the arguments earlier this year.

Read more of this story at Slashdot.

AT&T store worker gets 16 months inside for SIM-swap side hustle

11 September 2026 at 11:16
A former AT&T retail worker who used his system access to hijack customers' phone numbers for cybercriminals has been sentenced to 16 months in federal prison. Kenneth Carter, 44, carried out the SIM swaps at a store in Portland, Oregon, , allowing the criminals to intercept authentication codes and raid victims' bank accounts. Court documents show that Carter worked with at least three other people in the scheme, which ran between May 2018 and November 2019, and caused nearly $600,000 in intended losses. Co-conspirator One, described in court documents as the operation's main "hacker," identified victims with online bank accounts, gathered their personal data, and sent it to Carter, who could reassign their phone numbers. Carter abused his access to AT&T's systems to transfer victims' phone numbers to devices controlled by the other criminals. His role was described as "instrumental to the scheme." Co-conspirator Two and Co-conspirator Three would walk into the store and impersonate the victim whose number they planned to SIM-swap, and Carter would reassign the number to a phone they controlled โ€“ usually a "cheap flip phone." Once the swap was complete, the criminals could use the flip phone to intercept SMS-based 2FA codes and password reset messages, take over the victim's bank account, and steal funds. The intercepted codes were relayed to Co-conspirator One, who used them to access the victims' bank accounts. Court documents also refer to "an unnamed family member" who held a minor role in the scheme. They were described as someone "who occasionally passed along the two-step authentication codes" to Co-conspirator One. According to the Justice Department, three victims incurred combined intended losses of $593,963.77, and Carter admitted carrying out additional unauthorized SIM swaps. Carter's plea agreement [PDF] included details of three SIM swap attacks he helped execute. Only one victim suffered an actual loss: $99,528.33 transferred to a Portuguese bank account. The conspirators attempted to transfer $247,652.74 and $246,782.70 from the other two victims, but the banks' fraud controls blocked both transactions. Prosecutors said Carter was paid between $1,000 and $2,000 per swap, although he maintained that he earned less than $4,000 in total. Law enforcement raided Carter's residence in November 2019, finding copies of the personal data provided to him to carry out the SIM swaps, including the Social Security number of the one victim whose money was successfully stolen. AT&T terminated Carter's employment at an unspecified date in 2019. He pleaded guilty on March 24, 2026, to conspiracy to commit wire fraud and bank fraud. In a letter to United States District Judge Stanley Blumenfeld, Jr., Carter described his offending as "a one-off situation that truly was a mistake." He explained that he takes care of his mother-in-law, who spends much of her time in a hospital bed located in the family living room, and two daughters, one of whom has schizophrenia. Carter claimed that he was "propositioned by my in-law cousin with an opportunity for me to make a little extra money for my family." "I was told I wouldn't have to do anything but do my job," he added. "So, I was under the impression that this was a harmless act. As far as I knew at the time, I was never a part of a ring, nor was this an out-of-state matter. "My incident was isolated to just Portland, OR, and the incident occurred while I was employed by AT&T. I later learned that what I found myself a part of was criminal, and I also learned after the fact the severity of what my co-conspirators were doing with the flip phones I sold under customer accounts." Federal prosecutors were unmoved by Carter's letter. In their response [PDF], US attorneys argued that Carter had not provided enough evidence to show he was unaware of the criminal activity's scope or nature, or that he was less culpable than the "hacker" who coordinated the operation. In addition to the 16-month sentence, Judge Blumenfeld, Jr. ordered Carter to pay $99,528 in restitution. ยฎ

Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars

11 September 2026 at 08:15
A Ukrainian lawyer who wound up coding malware for the Conti ransomware gang has been sentenced to four years in a US prison. Oleksii Oleksiyovych Lytvynenko, 44, pleaded guilty in June to conspiracy to commit wire fraud over his role in Conti, the Russia-linked ransomware operation associated with more than 1,000 victims and at least $150 million in ransom payments. Lytvynenko took an unusual route into the ransomware business. The Ukrainian national, who later lived in Cork, Ireland, trained as a lawyer before joining Conti as an intruder and developer. According to his plea agreement [PDF], Lytvynenko operated under the handle "henry" and joined a team run by another Conti conspirator known as "silver" or "buza." He was recruited to help with coding and directed to work on a malware loader โ€“ software designed to get other malicious code running on a victim's machine. Prosecutors said his Google account showed he had also been doing some homework. Investigators found books and videos about malware and hacking alongside Conti malware, ransom notes, and stolen victim data. Prosecutors said he also used Google and ZoomInfo to research potential targets. Lytvynenko wasn't confined to writing code, according to the filing. Evidence from his online accounts showed that he possessed data stolen from eight US victims and four overseas, with the eight American victims reporting more than $1.5 million in losses. Court documents identify several Bitcoin transfers tied to his Conti work, including 0.4 BTC worth $25,042 that prosecutors traced back to one of his victims. He has been ordered to forfeit the same amount. Conti disbanded in 2022 after its internal chats and source code were leaked following the gang's public support for Russia's invasion of Ukraine. Lytvynenko apparently didn't take that as his cue to find another line of work. When Gardaรญ turned up at his County Cork home in July 2023, they said they found his laptop open, Cobalt Strike running and a Rocket.Chat session connected over Tor. Prosecutors said evidence recovered from the machine showed that his involvement in ransomware activity had continued after Conti disbanded. Lytvynenko was extradited from Ireland to the US in October 2025. The Justice Department says Conti attacked organizations across 47 US states, the District of Columbia, Puerto Rico, and 31 foreign countries between 2020 and 2022. By January 2022, the FBI estimated that victim payouts associated with Conti exceeded $150 million. Lytvynenko will now have four years to contemplate a career change. ยฎ

Top Seattle tech and business leaders demand 100-day public safety action plan from City Hall

10 September 2026 at 18:42
Tents in a vacant lot in Seattleโ€™s Belltown neighborhood. (GeekWire Photo / Kurt Schlosser)

A roster of top Seattle business leaders and regional CEOs is demanding urgent action from City Hall on public safety, calling on Mayor Katie Wilson and the City Council to roll out a concrete 100-day action plan backed by measurable goals and transparent progress tracking.

In a letter sent Thursday, executives from major area employers โ€” including Microsoft, Starbucks, Costco, F5, Alaska Airlines, Zillow, and others โ€” urged city leaders to protect and expand public safety funding amid growing skepticism that the city currently has an effective strategy to address crime and homelessness.

The push centers on findings from an August joint public-opinion poll of registered Seattle voters, which revealed that while every proposed safety measure drew at least 75% support across all demographics, only 34% of respondents expressed confidence in the cityโ€™s current strategy.

Pointing to severe staffing shortages โ€” noting Seattle has just 1.31 sworn officers per 1,000 residents, far below peer cities like Denver, San Francisco, and Boston โ€” the signatories argued that budget decisions must directly align with measurable safety outcomes.

The effort was spearheaded by major regional business leadership organizations, including the Seattle Metropolitan Chamber of Commerce, Challenge Seattle, and the Washington Roundtable. Their leaders โ€” Joe Nguyแป…n, former Gov. Chris Gregoire, and Rachel Smith โ€” jointly signed the appeal alongside dozens of local chief executives spanning technology, retail, healthcare, and sports franchises.

โ€œVoters are asking for action, on a timeline, with results they can measure,โ€ the coalition wrote in the letter, emphasizing that their recommendations reflect a broad consensus across the city. โ€œThis is not a narrow or partisan agenda, it is a shared baseline that Seattle residents and the business community are asking their elected leaders to deliver both now and as a sustained priority.โ€

The letter outlines a series of immediate and short-term actions the group is asking City Hall to enact, backed by overwhelming support in their poll:

The letter to Seattle city leaders calls for activation of CCTV cameras as well as increased officer patrols in areas including Pioneer Square, the Stadium District and Little Saigon. (GeekWire Photo / Kurt Schlosser)

CCTV surveillance: Activate CCTV cameras in Pioneer Square, the Stadium District, and other high-event areas to deter crime and assist law enforcement.

Foot and bike patrols: Establish regular police patrols on foot and bicycle in areas facing persistent public safety problems, specifically citing Little Saigon (90% poll support).

911 response accountability: Recommit to a standard 7-minute priority 911 response time, backed by transparent reporting when targets are missed (90% support). The letter noted data from Nordstrom showing only 29% of 911 calls from its flagship downtown store yielded a police response, compared to 100% at its Bellevue and Southcenter locations.

Drug treatment and diversion: Direct CARE Department specialists to offer treatment and shelter first, but require law enforcement to arrest and prosecute repeat offenders who repeatedly refuse help (82% support).

Open-air drug markets: Require SPD and the City Attorney to establish a clear, prioritized pathway for shutting down open-air drug markets (81% support).

Encampment bans and timelines: Institute a policy banning encampments within 250 feet of parks, playgrounds, or schools, and mandate that the city clear encampments in those zones within 72 hours (79% support).

Among those who signed the letter: Brad Smith, Vice Chair & President of Microsoft; Jeremy Wacksman, CEO of Zillow; Franรงois Locoh-Donou, CEO of F5; Matt McIlwain, Managing Director at Madrona Venture Group; Julie Sandler, Co-founder & Venture Partner at PSL Ventures; Matt Oppenheimer, Chairman of Remitly; Erik Nordstrom, CEO & Co-President of Nordstrom; Brian Niccol, Chairman & CEO of Starbucks; Ron Vachris, CEO & President of Costco; Ben Minicucci, CEO & President of Alaska Air Group; Mike Sievert, Vice Chairman of T-Mobile; and Ada Healey, Chief Real Estate Officer at Vulcan Real Estate.

The business communityโ€™s coordinated push arrives during a pivotal moment for public safety policy in City Hall, where political tensions over policing and crime response have flared in recent weeks.

While overall violent crime and homicides in Seattle dropped during the first half of 2026 compared to last year, high-profile violent incidents continue to fuel public and commercial anxiety. Downtown, Belltown, and high-foot-traffic corridors have experienced recent spikes in gun violence and fatal altercations โ€” including multiple homicides in Belltown and Westlake Park in early September alone.

At the same time, the Seattle Police Department continues to grapple with acute staffing shortages following years of officer departures exceeding hiring goals. The persistent deficit has left response times stretched thin, prompting deep frustration from major employers and pushing retail hubs to demand a more visible police presence.

Policy friction between the Council and Wilsonโ€™s administration has also intensified. Debate has centered on the rollout of public surveillance technologies โ€” where the mayorโ€™s office recently paused CCTV camera expansions pending a data privacy audit โ€” as well as ongoing friction surrounding the leadership of the police department.

Responding to the letter, Wilson told GeekWire that her administration shares the business communityโ€™s commitment to public safety, noting that โ€œmany of the specific requests they made are well underway.โ€

Wilson highlighted expanded foot and bicycle patrols in neighborhoods like Little Saigon and Belltown, 3,500 police officer applications currently in the queue, and an upcoming gun violence reduction strategy set to roll out next week. While noting that SPD data shows homicides and shootings at 10-year lows, Wilson acknowledged public impatience.

โ€œWe have far too much crime and public disorder and people have a right to be frustrated,โ€ she said. โ€œI, like everyone in Seattle, want to see that progress happen faster and steadier.โ€

The safety campaign comes on the heels of a 127-page independent economic study commissioned by the city, which warned that while Seattle boasts an โ€œalmost peerlessโ€ tech workforce and key AI assets, its economy is in a fragile position due to heavy corporate concentration and tax policies that penalize senior hiring.

The study noted that Seattleโ€™s tax base remains vulnerable if major employers opt to relocate or grow outside the city limits, reinforcing the business coalitionโ€™s argument that public safety is closely tied to the cityโ€™s long-term economic stability.

Trezor, BitBox users targeted in newsletter phishing spree

10 September 2026 at 07:30
Crypto hardware wallet maker Trezor says the third-party email service provider it uses to send newsletters has been breached, and customers are now being sent phishing messages. There is good and bad news. The good news is that the emails appear easy to spot. They are not bespoke to each recipient and resemble a spray-and-pray campaign rather than sophisticated targeting that uses customer-specific data to enhance the email's perceived authenticity. All known examples of the scam email are titled "Critical Security Alert: STM32 Entropy Vulnerability," and the body explains that an estimated one in four Trezor devices are affected by a "hardware factory defect." The email warns customers that wallet seeds are exposed to brute-force attacks due to "insufficient randomness" and a "critically low 40-bit entropy." The email asks recipients to share their wallet backups. Trezor said: "Do not click it or interact with it. Never enter your wallet backup anywhere. Always confirm every action with your Trezor physically." The bad news is that because the attackers allegedly compromised the legitimate email provider, the messages can pass authentication checks and bypass some of the usual protections deployed by receiving email services. According to those who have shared copies of the emails, they appear to be sent from "mailing@trezor.io." Trezor has issued the warning across its social media channels and Trezor Suite, the companion app for its hardware wallets. The Register asked Trezor for more information. The third party email provider Brevo โ€“ formerly known as Sendinblue โ€“ said in a statement that a "security incident" had "allowed an attacker to access 120 Brevo accounts." It added that the "bad actor used the access to send phishing emails to the client's contactbase," and promised a "full post mortem later today." Swiss hardware wallet maker BitBox also appears to be affected, having shared an image of an email nearly identical to the one targeting Trezor's newsletter subscribers. The email similarly warns of entropy weaknesses affecting BitBox devices, although it is titled slightly differently: "Critical Security Alert: Microcontroller Entropy Bug Identified." The company said on X: "Our preliminary review of the phishing mail that was sent out to our newsletter subscribers about an hour ago found that it is very likely that our newsletter provider got compromised. "Multiple other Bitcoin companies got targeted as well, and it appears that we all share the same newsletter provider. "We sent out a phishing warning to all our newsletter subscribers, contacted the provider and reported the phishing domains. Most of the phishing links appear to have been taken down already. "We are still actively investigating this situation and will update you once we know more." Crypto tax and portfolio-tracking company CoinTracking also disclosed the compromise of its third-party email provider, which it named as Brevo, around the same time as Trezor and BitBox. CoinTracking shared a copy of the phishing email targeting its users and, since it does not offer hardware wallets, the message uses a different lure, asking customers to follow a link to refresh their API keys. Tough times in Trezorland The latest security snafu comes less than a month after Trezor announced that thousands of customers' details had been compromised following a breach at logistics partner ShipMonk. The hardware vendor initially estimated that around 13,000 people were affected. Those who ordered Trezor products between May 10 and August 8 had their names, email addresses, phone numbers, and shipping addresses breached. Compounding the problem for a company whose brand centers on security, Trezor confirmed on September 4 that the total number of affected customers had risen to 80,000. Trezor said ShipMonk later informed it that an additional 67,000 US customers who purchased products between November 2019 and August 2021 were affected. "Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications," said Trezor. "We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems." ยฎ

Cryptocrook ringleader, 22, who met crew on Minecraft admits role in $245M heist

9 September 2026 at 09:39
The ringleader of a sprawling cybercrime operation has pleaded guilty in the US after helping to steal and launder hundreds of millions of dollars in cryptocurrency. Malone Lam, 22, a Singaporean national and Miami resident, spearheaded the scheme to steal cryptocurrency from wealthy individuals between October 2023 and May 2025. He first visited the US in 2023 after meeting two of the group's earliest alleged members โ€“ Jeandiel Serrano and Veer Chetal โ€“ while playing Minecraft online. Lam performed various functions within the group, although court documents [PDF] identify victim selection and social engineering support as his principal roles. The ringleader was responsible for obtaining databases of high-net-worth individuals who had cryptocurrency holdings to inform the group's targeting. He would also trigger account access notifications on victims' devices to convince them that their accounts were under attack. He was also involved in laundering the proceeds through exchanges that, according to court documents, had lax KYC requirements. Other group members carried out the social engineering calls, claiming to represent Google, Yahoo, Coinbase, Gemini (the crypto exchange, not the AI chatbot), and other online platforms. Their job was to convince victims to surrender personal information and "access codes" that could be used to access their accounts. Once they secured access, Lam's crew would look for cryptocurrency accounts, seed phrases, and passwords they could use to steal victims' assets. In most cases, social engineering techniques were enough to meet the thieves' goals, although in one case involving a victim who stored their holdings in a hardware wallet, Lam's gang arranged for Marlon Ferro to physically break into a house and steal it. The Register covered Ferro's sentencing earlier this year. He was brought into Lam's fold when he was just a teenager, tasked with carrying out multiple burglaries across the US when remote social engineering attacks lacked the necessary reach. During the crew's nearly two-year operation, its members stole hundreds of millions of dollars' worth of cryptocurrency. The individual thefts ranged from about $800,000 to tens of millions of dollars, while one victim lost more than $245 million, according to court documents. Lam's crew, allegedly comprising at least 12 individuals, knew how to spend their illicit gains. Prosecutors claim they splurged up to $500,000 on a single evening at a nightclub, dished out handbags worth tens of thousands of dollars to partygoers, and bought luxury clothing and watches priced between $100,000 and $500,000. They rented expensive properties in Miami, Los Angeles, and the Hamptons, chartered private jets, hired a team of private bodyguards, and splashed out on exotic cars, with some worth up to $3.8 million. Lam was arrested at a rented property in Miami on September 18, 2024. His sentencing hearing has not yet been scheduled. The court has set a status hearing for December 8. Lam pleaded guilty to one count of participating in a racketeering conspiracy, an offense carrying a maximum sentence of 20 years in prison. "If you build a cybercrime empire, we will find you, dismantle your operation, and hold you accountable," said US Attorney Jeanine Ferris Pirro. "This defendant led an international network that preyed on victims through deception, invaded their privacy, and stole hundreds of millions of dollars in cryptocurrency. "Working with our partners at the FBI and IRS-CI, we will continue to hunt down the criminals who weaponize technology to steal from innocent people." ยฎ

Security boffin claims airport group left API keys in client-side JavaScript for four years

9 September 2026 at 07:14
Security researcher Scott Helme says his analysis supports FulcrumSec's claim that Manchester Airports Group (MAG) exposed privileged API keys in client-side JavaScript. Helme says he reached that conclusion after using information provided by the cyber extortion group to reconstruct how data belonging to roughly 8.8 million MAG customers was allegedly stolen last month. The crooks behind the attack described MAG's security failure as "tragi-comical." They claimed MAG exposed overprivileged API keys for Iterable, a marketing automation platform, in front-end JavaScript served by the websites of MAG's three airports: Manchester, Stansted, and East Midlands. Helme used the Internet Archive's Wayback Machine to retrieve older versions of the JavaScript and found that the three keys first appeared across the airport websites in June and July 2022. The same values remained exposed until August 2026, he said. "Read the timeline the other way round and it's worse," said Helme. "Anyone who looked at that page source on any day between June 2022 and August 2026 could have taken the key. FulcrumSec just happen to be the ones who told us. "There is no way to know, from the outside, who else did, and the honest answer is that MAG can't know either without going back through four years of Iterable API logs, if they even have four years of Iterable API logs." The API keys were not embedded directly in the HTML, Helme explained, but anyone who examined the JavaScript bundles loaded by the sites could find them. This would explain how the vulnerability could go unnoticed by the airport's IT teams for over four years. Helme says the browser-delivered code was using the keys to authorize server-side API operations โ€“ something Iterable's documentation explicitly warns against. The requests should instead have passed through MAG's own servers, where the credentials could be kept secret and access restricted. MAG's alleged exposure of the credentials was not the only issue at play. The keys were vastly overprivileged for their intended job, which was to attribute page clicks to marketing emails, Helme said. The keys had read/write access to core Iterable endpoints, giving anyone who obtained them the ability to access data such as customer profiles, parking and lounge bookings, and Fast Track purchases. Helme said the structure and contents of the stolen data indicated that it had been exported from Iterable. He said he also found that the keys could access endpoints capable of deleting customer records and lists or rewriting profiles. "There's no indication FulcrumSec did any of this, and I'm glad, but they could have just nuked everything from orbit and MAG would have been really screwed," said Helme. "For four whole years, the capability to delete Manchester Airports Group's database was a view-source away. "This wasn't only a confidentiality exposure. It was a colossal integrity and availability exposure too, and MAG just got lucky. How do they now trust any of the data that remains in the database?" When it disclosed the incident, MAG described the cyberattack as "sophisticated" and said it was "a hack, not a lapse." The company declined to comment on Helme's conclusions. MAG is continuing its investigation alongside the Information Commissioner's Office (ICO) and supporting the National Crime Agency with its inquiries. It is understood that MAG maintains it was the victim of a crime and disputes Helme's "no hacking required" characterization. FulcrumSec released the company's data on September 2, a week after MAG confirmed it had refused to pay. According to the ICO, the group's extortion demand was lower than those typically made by cybercriminals. ยฎ

CrowdStrike Disrupts Sality Botnet After More Than 20 Years

3 September 2026 at 17:36

Cybersecurity expert Ken Underhill reports from CrowdStrike on the disruption of the 20-year-old Sality botnet and what security teams need to know.

The post CrowdStrike Disrupts Sality Botnet After More Than 20 Years appeared first on TechRepublic.

Cybercrooks trawl Fishbrain to net password hashes

3 September 2026 at 08:45
Cybercriminals have reeled in password hashes and corresponding salts belonging to users of popular fishing app Fishbrain, opening the door to cracking attempts. Fishbrain AB, which says its eponymous app serves more than 20 million anglers, disclosed the August 19 breach to the California Attorney General's Office this week. The unknown perpetrators helped themselves to a trawl of user data, including names, dates of birth, email addresses, phone numbers, Fishbrain usernames, country information, password hashes, and salts. "Fishbrain passwords were not stored in plaintext; however, Fishbrain has determined that the compromised password hashes for some users may be susceptible to being decoded," the company said in its disclosure [PDF]. It added: "If you use your Fishbrain password for any other online accounts, you should promptly update those passwords and any associated security questions or answers. "You should also take other appropriate steps to protect any online accounts that use the same username or email address and password combination. We recommend using a strong, unique password for each of your accounts." With the hashes and salts in hand, attackers can make password guesses using their own hardware until they potentially recover the original credentials. Whether those attempts succeed depends on the strength of each password and the hashing algorithm Fishbrain used, which the company did not disclose. Fishbrain did not comment on the scale of the breach or how many of its claimed 20 million-plus users were affected. The Register asked Fishbrain for more information. After discovering the intrusion and conducting an initial forensic investigation, Fishbrain patched the vulnerability and reset every user's password. Customers must create a new one the next time they log in. Fishbrain also said it "restricted access to the affected environment," strengthened its security controls, and initiated "a broader review of our data security measures" while the investigation continues. Fisherfolk should also keep an eye out for phisherfolk using the stolen personal data to bait follow-on attacks. ยฎ

Gamescom Crime Spree? Three Exhibitors Report Their Laptops Were Stolen

30 August 2026 at 20:38
From the gaming news site Aftermath" Game developer and consultant Ryan Laley traveled to Cologne, Germany from Essex, England to showcase his upcoming horror social deduction game Mimic at the annual Gamescom event. He paid "thousands of pounds" to get a booth at the show, where other game developers and press could try the game ahead of its October release. But Laley's Gamescom was cut short when he realized Friday morning that his brand new Alienware laptop, purchased for the event, was missing. The laptop was stored in a cupboard in the booth, and Laley started asking nearby vendors to see if someone had moved it. That's when he realized it was stolen โ€” and that he wasn't alone. Laley's booth in Gamescom's business area, specifically in the International Game Developers Association Lounge, had been hit in what appears to be a string of thefts at the convention center. The business area of the convention is not open to the public, only press and others with specific tickets. Laley said Gamescom advertised this area as having 24/7 security and limited access after hours... Publisher and merchandiser iam8bit, in a nearby booth showcasing Escape Academy 2: Back 2 School and Petal Runner, had two laptops with game builds stolen Thursday night from its booth, a representative confirmed to Aftermath. "Meanwhile, Tessera Studios had two laptops and a Steam Deck taken from its cabinet," reports Tom's Hardware: Gamescom organizers responded to the issues, saying that although they have arranged for uniformed guards to provide general security, individual booth security must be booked separately. They've also advised exhibitors to have insurance against theft, and said these warnings are noted in the terms and conditions for participants, as well as in the event's technical guidelines. "All cases have been reported to us and to the police, and investigations are already underway," the organizers' statement read. They also said that security is one of their priorities at the event, but also added, "At an event of this size, however, there will always be individuals attempting to take advantage of the situation."

Read more of this story at Slashdot.

Alabama Launches Investigation Into OpenAI's Hack of Hugging Face

By: BeauHD
25 August 2026 at 19:00
Alabama's attorney general has subpoenaed OpenAI as part of an investigation into whether inadequate safeguards contributed to an incident in which an unreleased cybersecurity model escaped its isolated environment and hacked Hugging Face. TechCrunch reports: The investigation comes weeks after OpenAI admitted that one of its unreleased and guardrail-free cybersecurity models had escaped an isolated environment, connected to the internet, and hacked AI dataset platform Hugging Face. As Reuters first reported, Hugging Face was only one of four victims of what was supposed to be "an internal evaluation" of a model with "maximal cyber capabilities," as OpenAI put it. The press release announcing the subpoena (PDF) sent by the state's attorney general Steve Marshall said that the state was seeking to understand if OpenAI's "inability or unwillingness to ensure the safety of its products" violated the state's consumer protection laws. Earlier this month, Marshall, along with the attorneys general of 14 other states, including Florida, Missouri, Pennsylvania, and Texas, sent a letter (PDF) to OpenAI's CEO Sam Altman, requesting that he and his company preserve all records related to the Hugging Face incident. The letter also asked OpenAI to "immediately cease and desist" from any internal cybersecurity evaluations. OpenAI said in a statement: "The Hugging Face incident marked an important moment for AI safety and we are conducting a thorough review along with external advisors. Once the review is complete, we will share a technical report with relevant government authorities and publish our findings publicly."

Read more of this story at Slashdot.

โŒ
โŒ