โŒ

Normal view

There are new articles available, click to refresh the page.
Today โ€” 13 September 2026Main stream

Sam Bankman-Fried, Former Crypto Billionaire, Appeals His Conviction To the US Supreme Court

13 September 2026 at 01:00
America's highest court heard Sam Bankman-Fried's request for a new trial on Thursday, CNN reports. But they add that "the former crypto mogul who was convicted of defrauding investors by secretly diverting billions of dollars of their money" also asked America's high court "to throw out a court order requiring him to pay $11 billion as part of his sentence." Bankman-Fried was sentenced to 25 years in prison in 2024 after prosecutors said he directed billions of dollars from the crypto exchange FTX to a hedge fund he controlled called Alameda Research, where the funds were used for risky investments, political donations and his own personal benefit. The Supreme Court appeal, which was reviewed by CNN, raises a technical question about evidence that was submitted at his trial, and whether Bankman-Fried should have been permitted to demonstrate that his investments were ultimately sound and would have covered any losses by FTX customers. He also argues that the $11 billion forfeiture violates the 8th Amendment's prohibition on excessive fines. "Where the government pursues a theory of fraud under which it doesn't matter whether any victims lost money, introducing evidence suggesting that people actually lost money is distracting and prejudicial," veteran Supreme Court attorney Jeffrey Fisher told CNN. "All the more so where the truth is the victims did not lose money, and the defendant is unable to make that clear." The 2nd US Circuit Court of Appeals rejected the arguments earlier this year.

Read more of this story at Slashdot.

Before yesterdayMain stream

Blockstream Tells Hackers To Return Remaining Bitcoin Stolen in Liquid Theft

11 September 2026 at 17:13

Bitcoin Magazine

Blockstream Tells Hackers To Return Remaining Bitcoin Stolen in Liquid Theft

Bitcoin infrastructure firm Blockstream has refused to negotiate further with hackers who last week stole 4,000 bitcoins from its Liquid network.ย 

Writing on X Friday, Blockstream said that the hackers still had time to return the funds before the company would work with law enforcement.ย 

White-hat hackers on Sunday withdrew about $320 million from the federation wallet that backs Liquid, a sidechain by Blockstream. After negotiating with Blockstream, they returned most of the funds but kept 598.5 coins worth over $46 million โ€” demanding it as ransom.ย 

โ€œBlockstream will not pay a ransom for the return of stolen funds,โ€ the post read. โ€œTaking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is theft.โ€

To those responsible for the theft of bitcoin from the Liquid Network:

Blockstream will not pay a ransom for the return of stolen funds. Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It isโ€ฆ

โ€” Blockstream (@Blockstream) September 11, 2026

It added: โ€œWe will work with law enforcement, exchanges, service providers, forensic specialists, and other relevant parties to trace and recover the assets and identify those responsible.โ€

โ€œWe will not pay for the return of stolen property. We will not abandon our users. The Bitcoin community will not stop pursuing the funds.โ€

Liquid, or L-BTC, is a layer-2 created by Blockstream that allows users to fast move assets backed 1:1 with bitcoin. One of the assets, LBTC, is a token backed by bitcoin that allows for quick settlement โ€” a bit like the Lightning Network.ย 

Hackers were able to get the funds by exploiting an inflation bug on the Liquid sidechain to create over 4,000 LBTC that did not exist before and cash them out for real, on-chain bitcoins.ย 

The hackers then had an exchange with Blockstream via messages written into Bitcoin blocks.ย 

In one message, the white hats wrote: โ€œPlease fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.โ€

In the latest message, the hackers slammed Blocksteam as โ€œdelusional, greedy, and arrogant,โ€ and threatened to reveal all of Blockstreamโ€™s encrypted messages in the exchange unless the company allowed thieves to keep 10% of the bitcoins.ย 

โ€œYou SHALL pay 10% using your own money as bug bounty or you will cause all your holders a 15% loss for your irresponsibility and stinginess,โ€ the message read.ย 

The Bitcoin community is still reeling after hackers in July were able to steal over 1,800 bitcoins worth close to $140 million from Coldcard wallet holders.ย 

Users of the popular hardware wallet, created by Coinkite, were targeted because the productโ€™s manufacturer did not use a true random number generator, allowing hackers to essentially guess investor seedphrases.ย 

This post Blockstream Tells Hackers To Return Remaining Bitcoin Stolen in Liquid Theft first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.

FBI Alert: OAuth Consent Phishing is Targeting Users of Messaging Apps

11 September 2026 at 16:00

The U.S. Federal Bureau of Investigation (FBI) has issued an advisory warning of a wave of OAuth consent phishing attacks targeting โ€œprominent victims, their family members, and personal acquaintances.โ€

OAuth phishing is an increasingly popular social engineering tactic that tricks users into granting access to their accounts without handing over their passwords.

AT&T store worker gets 16 months inside for SIM-swap side hustle

11 September 2026 at 11:16
A former AT&T retail worker who used his system access to hijack customers' phone numbers for cybercriminals has been sentenced to 16 months in federal prison. Kenneth Carter, 44, carried out the SIM swaps at a store in Portland, Oregon, , allowing the criminals to intercept authentication codes and raid victims' bank accounts. Court documents show that Carter worked with at least three other people in the scheme, which ran between May 2018 and November 2019, and caused nearly $600,000 in intended losses. Co-conspirator One, described in court documents as the operation's main "hacker," identified victims with online bank accounts, gathered their personal data, and sent it to Carter, who could reassign their phone numbers. Carter abused his access to AT&T's systems to transfer victims' phone numbers to devices controlled by the other criminals. His role was described as "instrumental to the scheme." Co-conspirator Two and Co-conspirator Three would walk into the store and impersonate the victim whose number they planned to SIM-swap, and Carter would reassign the number to a phone they controlled โ€“ usually a "cheap flip phone." Once the swap was complete, the criminals could use the flip phone to intercept SMS-based 2FA codes and password reset messages, take over the victim's bank account, and steal funds. The intercepted codes were relayed to Co-conspirator One, who used them to access the victims' bank accounts. Court documents also refer to "an unnamed family member" who held a minor role in the scheme. They were described as someone "who occasionally passed along the two-step authentication codes" to Co-conspirator One. According to the Justice Department, three victims incurred combined intended losses of $593,963.77, and Carter admitted carrying out additional unauthorized SIM swaps. Carter's plea agreement [PDF] included details of three SIM swap attacks he helped execute. Only one victim suffered an actual loss: $99,528.33 transferred to a Portuguese bank account. The conspirators attempted to transfer $247,652.74 and $246,782.70 from the other two victims, but the banks' fraud controls blocked both transactions. Prosecutors said Carter was paid between $1,000 and $2,000 per swap, although he maintained that he earned less than $4,000 in total. Law enforcement raided Carter's residence in November 2019, finding copies of the personal data provided to him to carry out the SIM swaps, including the Social Security number of the one victim whose money was successfully stolen. AT&T terminated Carter's employment at an unspecified date in 2019. He pleaded guilty on March 24, 2026, to conspiracy to commit wire fraud and bank fraud. In a letter to United States District Judge Stanley Blumenfeld, Jr., Carter described his offending as "a one-off situation that truly was a mistake." He explained that he takes care of his mother-in-law, who spends much of her time in a hospital bed located in the family living room, and two daughters, one of whom has schizophrenia. Carter claimed that he was "propositioned by my in-law cousin with an opportunity for me to make a little extra money for my family." "I was told I wouldn't have to do anything but do my job," he added. "So, I was under the impression that this was a harmless act. As far as I knew at the time, I was never a part of a ring, nor was this an out-of-state matter. "My incident was isolated to just Portland, OR, and the incident occurred while I was employed by AT&T. I later learned that what I found myself a part of was criminal, and I also learned after the fact the severity of what my co-conspirators were doing with the flip phones I sold under customer accounts." Federal prosecutors were unmoved by Carter's letter. In their response [PDF], US attorneys argued that Carter had not provided enough evidence to show he was unaware of the criminal activity's scope or nature, or that he was less culpable than the "hacker" who coordinated the operation. In addition to the 16-month sentence, Judge Blumenfeld, Jr. ordered Carter to pay $99,528 in restitution. ยฎ

Survey: Companies Cite Phishing as their Top AI-Enabled Fraud Concern

11 September 2026 at 12:00

A recent survey from Experian found that 60% of companies report fraud losses that are โ€œsomewhat or significantly higherโ€ than in previous years, with a majority of respondents citing AI-generated phishing attacks as their top AI-related fraud concern.

Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars

11 September 2026 at 08:15
A Ukrainian lawyer who wound up coding malware for the Conti ransomware gang has been sentenced to four years in a US prison. Oleksii Oleksiyovych Lytvynenko, 44, pleaded guilty in June to conspiracy to commit wire fraud over his role in Conti, the Russia-linked ransomware operation associated with more than 1,000 victims and at least $150 million in ransom payments. Lytvynenko took an unusual route into the ransomware business. The Ukrainian national, who later lived in Cork, Ireland, trained as a lawyer before joining Conti as an intruder and developer. According to his plea agreement [PDF], Lytvynenko operated under the handle "henry" and joined a team run by another Conti conspirator known as "silver" or "buza." He was recruited to help with coding and directed to work on a malware loader โ€“ software designed to get other malicious code running on a victim's machine. Prosecutors said his Google account showed he had also been doing some homework. Investigators found books and videos about malware and hacking alongside Conti malware, ransom notes, and stolen victim data. Prosecutors said he also used Google and ZoomInfo to research potential targets. Lytvynenko wasn't confined to writing code, according to the filing. Evidence from his online accounts showed that he possessed data stolen from eight US victims and four overseas, with the eight American victims reporting more than $1.5 million in losses. Court documents identify several Bitcoin transfers tied to his Conti work, including 0.4 BTC worth $25,042 that prosecutors traced back to one of his victims. He has been ordered to forfeit the same amount. Conti disbanded in 2022 after its internal chats and source code were leaked following the gang's public support for Russia's invasion of Ukraine. Lytvynenko apparently didn't take that as his cue to find another line of work. When Gardaรญ turned up at his County Cork home in July 2023, they said they found his laptop open, Cobalt Strike running and a Rocket.Chat session connected over Tor. Prosecutors said evidence recovered from the machine showed that his involvement in ransomware activity had continued after Conti disbanded. Lytvynenko was extradited from Ireland to the US in October 2025. The Justice Department says Conti attacked organizations across 47 US states, the District of Columbia, Puerto Rico, and 31 foreign countries between 2020 and 2022. By January 2022, the FBI estimated that victim payouts associated with Conti exceeded $150 million. Lytvynenko will now have four years to contemplate a career change. ยฎ

In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

11 September 2026 at 10:19

Noteworthy stories that might have slipped under the radar: Invisible Unicode slips past phishing filters, US puts $10 million bounty on Iranian cyber official, military ties of Chinese hacking group QTFY.

The post In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review appeared first on SecurityWeek.

Top Seattle tech and business leaders demand 100-day public safety action plan from City Hall

10 September 2026 at 18:42
Tents in a vacant lot in Seattleโ€™s Belltown neighborhood. (GeekWire Photo / Kurt Schlosser)

A roster of top Seattle business leaders and regional CEOs is demanding urgent action from City Hall on public safety, calling on Mayor Katie Wilson and the City Council to roll out a concrete 100-day action plan backed by measurable goals and transparent progress tracking.

In a letter sent Thursday, executives from major area employers โ€” including Microsoft, Starbucks, Costco, F5, Alaska Airlines, Zillow, and others โ€” urged city leaders to protect and expand public safety funding amid growing skepticism that the city currently has an effective strategy to address crime and homelessness.

The push centers on findings from an August joint public-opinion poll of registered Seattle voters, which revealed that while every proposed safety measure drew at least 75% support across all demographics, only 34% of respondents expressed confidence in the cityโ€™s current strategy.

Pointing to severe staffing shortages โ€” noting Seattle has just 1.31 sworn officers per 1,000 residents, far below peer cities like Denver, San Francisco, and Boston โ€” the signatories argued that budget decisions must directly align with measurable safety outcomes.

The effort was spearheaded by major regional business leadership organizations, including the Seattle Metropolitan Chamber of Commerce, Challenge Seattle, and the Washington Roundtable. Their leaders โ€” Joe Nguyแป…n, former Gov. Chris Gregoire, and Rachel Smith โ€” jointly signed the appeal alongside dozens of local chief executives spanning technology, retail, healthcare, and sports franchises.

โ€œVoters are asking for action, on a timeline, with results they can measure,โ€ the coalition wrote in the letter, emphasizing that their recommendations reflect a broad consensus across the city. โ€œThis is not a narrow or partisan agenda, it is a shared baseline that Seattle residents and the business community are asking their elected leaders to deliver both now and as a sustained priority.โ€

The letter outlines a series of immediate and short-term actions the group is asking City Hall to enact, backed by overwhelming support in their poll:

The letter to Seattle city leaders calls for activation of CCTV cameras as well as increased officer patrols in areas including Pioneer Square, the Stadium District and Little Saigon. (GeekWire Photo / Kurt Schlosser)

CCTV surveillance: Activate CCTV cameras in Pioneer Square, the Stadium District, and other high-event areas to deter crime and assist law enforcement.

Foot and bike patrols: Establish regular police patrols on foot and bicycle in areas facing persistent public safety problems, specifically citing Little Saigon (90% poll support).

911 response accountability: Recommit to a standard 7-minute priority 911 response time, backed by transparent reporting when targets are missed (90% support). The letter noted data from Nordstrom showing only 29% of 911 calls from its flagship downtown store yielded a police response, compared to 100% at its Bellevue and Southcenter locations.

Drug treatment and diversion: Direct CARE Department specialists to offer treatment and shelter first, but require law enforcement to arrest and prosecute repeat offenders who repeatedly refuse help (82% support).

Open-air drug markets: Require SPD and the City Attorney to establish a clear, prioritized pathway for shutting down open-air drug markets (81% support).

Encampment bans and timelines: Institute a policy banning encampments within 250 feet of parks, playgrounds, or schools, and mandate that the city clear encampments in those zones within 72 hours (79% support).

Among those who signed the letter: Brad Smith, Vice Chair & President of Microsoft; Jeremy Wacksman, CEO of Zillow; Franรงois Locoh-Donou, CEO of F5; Matt McIlwain, Managing Director at Madrona Venture Group; Julie Sandler, Co-founder & Venture Partner at PSL Ventures; Matt Oppenheimer, Chairman of Remitly; Erik Nordstrom, CEO & Co-President of Nordstrom; Brian Niccol, Chairman & CEO of Starbucks; Ron Vachris, CEO & President of Costco; Ben Minicucci, CEO & President of Alaska Air Group; Mike Sievert, Vice Chairman of T-Mobile; and Ada Healey, Chief Real Estate Officer at Vulcan Real Estate.

The business communityโ€™s coordinated push arrives during a pivotal moment for public safety policy in City Hall, where political tensions over policing and crime response have flared in recent weeks.

While overall violent crime and homicides in Seattle dropped during the first half of 2026 compared to last year, high-profile violent incidents continue to fuel public and commercial anxiety. Downtown, Belltown, and high-foot-traffic corridors have experienced recent spikes in gun violence and fatal altercations โ€” including multiple homicides in Belltown and Westlake Park in early September alone.

At the same time, the Seattle Police Department continues to grapple with acute staffing shortages following years of officer departures exceeding hiring goals. The persistent deficit has left response times stretched thin, prompting deep frustration from major employers and pushing retail hubs to demand a more visible police presence.

Policy friction between the Council and Wilsonโ€™s administration has also intensified. Debate has centered on the rollout of public surveillance technologies โ€” where the mayorโ€™s office recently paused CCTV camera expansions pending a data privacy audit โ€” as well as ongoing friction surrounding the leadership of the police department.

Responding to the letter, Wilson told GeekWire that her administration shares the business communityโ€™s commitment to public safety, noting that โ€œmany of the specific requests they made are well underway.โ€

Wilson highlighted expanded foot and bicycle patrols in neighborhoods like Little Saigon and Belltown, 3,500 police officer applications currently in the queue, and an upcoming gun violence reduction strategy set to roll out next week. While noting that SPD data shows homicides and shootings at 10-year lows, Wilson acknowledged public impatience.

โ€œWe have far too much crime and public disorder and people have a right to be frustrated,โ€ she said. โ€œI, like everyone in Seattle, want to see that progress happen faster and steadier.โ€

The safety campaign comes on the heels of a 127-page independent economic study commissioned by the city, which warned that while Seattle boasts an โ€œalmost peerlessโ€ tech workforce and key AI assets, its economy is in a fragile position due to heavy corporate concentration and tax policies that penalize senior hiring.

The study noted that Seattleโ€™s tax base remains vulnerable if major employers opt to relocate or grow outside the city limits, reinforcing the business coalitionโ€™s argument that public safety is closely tied to the cityโ€™s long-term economic stability.

Ringleader of $245M Crypto Theft Pleads Guiltyย 

10 September 2026 at 18:24

Bitcoin Magazine

Ringleader of $245M Crypto Theft Pleads Guiltyย 

The man behind one of the biggest bitcoin thefts in history this week pleaded guilty.

Malone Lam, 22, a Miami resident from Singapore, on Tuesday admitted his role as ringleader of the international crime group which stole 4,100 bitcoins โ€” worth over $230 million at the time โ€” to fund a life of luxury.ย 

The U.S. Department of Justice said that from October 2023 and through at least May 2025, Lam and others hacked databases to steal crypto usersโ€™ information and con them into providing user logins and private keys. Bitcoin and other cryptocurrencies worth $245 million were taken in the theft.ย 

On one occasion, a co-defendant broke into a residence in New Mexico and stole a hardware wallet while Lam monitored the victimโ€™s movements by hacking their iCloud account.

โ€œThis defendant led an international network that preyed on victims through deception, invaded their privacy, and stole hundreds of millions of dollars in cryptocurrency,โ€ U.S. Attorney Jeanine Ferris Pirro said in a statement.ย 

โ€œIf you build a cybercrime empire, we will find you, dismantle your operation, and hold you accountable,โ€ Attorney Pirro added.ย 

The DOJ said: โ€œThe Racketeer Influenced and Corrupt Organizations Act conspiracy used social engineering and occasional home break-ins to obtain information that allowed the conspirators to drain their victimsโ€™ cryptocurrency wallets.โ€ย 

The crimes started after a group of online gamers became friends before working together to commit the cybercrimes, the indictment read.

Lam and co-defendants laundered the stolen bitcoin and spent it on bottle service parties, private jet rentals, security guards, luxury handbags and watches, and properties in Los Angeles, the Hamptons, and Miami.ย 

The defendants would spend up to $500,000 a night on parties and give away designer handbags worth tens of thousands of dollars, Tuesdayโ€™s announcement read.ย 

Lam was arrested in 2024 at his rental home in Miami.ย 

This post Ringleader of $245M Crypto Theft Pleads Guiltyย  first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.

Trezor, BitBox users targeted in newsletter phishing spree

10 September 2026 at 07:30
Crypto hardware wallet maker Trezor says the third-party email service provider it uses to send newsletters has been breached, and customers are now being sent phishing messages. There is good and bad news. The good news is that the emails appear easy to spot. They are not bespoke to each recipient and resemble a spray-and-pray campaign rather than sophisticated targeting that uses customer-specific data to enhance the email's perceived authenticity. All known examples of the scam email are titled "Critical Security Alert: STM32 Entropy Vulnerability," and the body explains that an estimated one in four Trezor devices are affected by a "hardware factory defect." The email warns customers that wallet seeds are exposed to brute-force attacks due to "insufficient randomness" and a "critically low 40-bit entropy." The email asks recipients to share their wallet backups. Trezor said: "Do not click it or interact with it. Never enter your wallet backup anywhere. Always confirm every action with your Trezor physically." The bad news is that because the attackers allegedly compromised the legitimate email provider, the messages can pass authentication checks and bypass some of the usual protections deployed by receiving email services. According to those who have shared copies of the emails, they appear to be sent from "mailing@trezor.io." Trezor has issued the warning across its social media channels and Trezor Suite, the companion app for its hardware wallets. The Register asked Trezor for more information. The third party email provider Brevo โ€“ formerly known as Sendinblue โ€“ said in a statement that a "security incident" had "allowed an attacker to access 120 Brevo accounts." It added that the "bad actor used the access to send phishing emails to the client's contactbase," and promised a "full post mortem later today." Swiss hardware wallet maker BitBox also appears to be affected, having shared an image of an email nearly identical to the one targeting Trezor's newsletter subscribers. The email similarly warns of entropy weaknesses affecting BitBox devices, although it is titled slightly differently: "Critical Security Alert: Microcontroller Entropy Bug Identified." The company said on X: "Our preliminary review of the phishing mail that was sent out to our newsletter subscribers about an hour ago found that it is very likely that our newsletter provider got compromised. "Multiple other Bitcoin companies got targeted as well, and it appears that we all share the same newsletter provider. "We sent out a phishing warning to all our newsletter subscribers, contacted the provider and reported the phishing domains. Most of the phishing links appear to have been taken down already. "We are still actively investigating this situation and will update you once we know more." Crypto tax and portfolio-tracking company CoinTracking also disclosed the compromise of its third-party email provider, which it named as Brevo, around the same time as Trezor and BitBox. CoinTracking shared a copy of the phishing email targeting its users and, since it does not offer hardware wallets, the message uses a different lure, asking customers to follow a link to refresh their API keys. Tough times in Trezorland The latest security snafu comes less than a month after Trezor announced that thousands of customers' details had been compromised following a breach at logistics partner ShipMonk. The hardware vendor initially estimated that around 13,000 people were affected. Those who ordered Trezor products between May 10 and August 8 had their names, email addresses, phone numbers, and shipping addresses breached. Compounding the problem for a company whose brand centers on security, Trezor confirmed on September 4 that the total number of affected customers had risen to 80,000. Trezor said ShipMonk later informed it that an additional 67,000 US customers who purchased products between November 2019 and August 2021 were affected. "Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications," said Trezor. "We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems." ยฎ

Cryptocrook ringleader, 22, who met crew on Minecraft admits role in $245M heist

9 September 2026 at 09:39
The ringleader of a sprawling cybercrime operation has pleaded guilty in the US after helping to steal and launder hundreds of millions of dollars in cryptocurrency. Malone Lam, 22, a Singaporean national and Miami resident, spearheaded the scheme to steal cryptocurrency from wealthy individuals between October 2023 and May 2025. He first visited the US in 2023 after meeting two of the group's earliest alleged members โ€“ Jeandiel Serrano and Veer Chetal โ€“ while playing Minecraft online. Lam performed various functions within the group, although court documents [PDF] identify victim selection and social engineering support as his principal roles. The ringleader was responsible for obtaining databases of high-net-worth individuals who had cryptocurrency holdings to inform the group's targeting. He would also trigger account access notifications on victims' devices to convince them that their accounts were under attack. He was also involved in laundering the proceeds through exchanges that, according to court documents, had lax KYC requirements. Other group members carried out the social engineering calls, claiming to represent Google, Yahoo, Coinbase, Gemini (the crypto exchange, not the AI chatbot), and other online platforms. Their job was to convince victims to surrender personal information and "access codes" that could be used to access their accounts. Once they secured access, Lam's crew would look for cryptocurrency accounts, seed phrases, and passwords they could use to steal victims' assets. In most cases, social engineering techniques were enough to meet the thieves' goals, although in one case involving a victim who stored their holdings in a hardware wallet, Lam's gang arranged for Marlon Ferro to physically break into a house and steal it. The Register covered Ferro's sentencing earlier this year. He was brought into Lam's fold when he was just a teenager, tasked with carrying out multiple burglaries across the US when remote social engineering attacks lacked the necessary reach. During the crew's nearly two-year operation, its members stole hundreds of millions of dollars' worth of cryptocurrency. The individual thefts ranged from about $800,000 to tens of millions of dollars, while one victim lost more than $245 million, according to court documents. Lam's crew, allegedly comprising at least 12 individuals, knew how to spend their illicit gains. Prosecutors claim they splurged up to $500,000 on a single evening at a nightclub, dished out handbags worth tens of thousands of dollars to partygoers, and bought luxury clothing and watches priced between $100,000 and $500,000. They rented expensive properties in Miami, Los Angeles, and the Hamptons, chartered private jets, hired a team of private bodyguards, and splashed out on exotic cars, with some worth up to $3.8 million. Lam was arrested at a rented property in Miami on September 18, 2024. His sentencing hearing has not yet been scheduled. The court has set a status hearing for December 8. Lam pleaded guilty to one count of participating in a racketeering conspiracy, an offense carrying a maximum sentence of 20 years in prison. "If you build a cybercrime empire, we will find you, dismantle your operation, and hold you accountable," said US Attorney Jeanine Ferris Pirro. "This defendant led an international network that preyed on victims through deception, invaded their privacy, and stole hundreds of millions of dollars in cryptocurrency. "Working with our partners at the FBI and IRS-CI, we will continue to hunt down the criminals who weaponize technology to steal from innocent people." ยฎ

Security boffin claims airport group left API keys in client-side JavaScript for four years

9 September 2026 at 07:14
Security researcher Scott Helme says his analysis supports FulcrumSec's claim that Manchester Airports Group (MAG) exposed privileged API keys in client-side JavaScript. Helme says he reached that conclusion after using information provided by the cyber extortion group to reconstruct how data belonging to roughly 8.8 million MAG customers was allegedly stolen last month. The crooks behind the attack described MAG's security failure as "tragi-comical." They claimed MAG exposed overprivileged API keys for Iterable, a marketing automation platform, in front-end JavaScript served by the websites of MAG's three airports: Manchester, Stansted, and East Midlands. Helme used the Internet Archive's Wayback Machine to retrieve older versions of the JavaScript and found that the three keys first appeared across the airport websites in June and July 2022. The same values remained exposed until August 2026, he said. "Read the timeline the other way round and it's worse," said Helme. "Anyone who looked at that page source on any day between June 2022 and August 2026 could have taken the key. FulcrumSec just happen to be the ones who told us. "There is no way to know, from the outside, who else did, and the honest answer is that MAG can't know either without going back through four years of Iterable API logs, if they even have four years of Iterable API logs." The API keys were not embedded directly in the HTML, Helme explained, but anyone who examined the JavaScript bundles loaded by the sites could find them. This would explain how the vulnerability could go unnoticed by the airport's IT teams for over four years. Helme says the browser-delivered code was using the keys to authorize server-side API operations โ€“ something Iterable's documentation explicitly warns against. The requests should instead have passed through MAG's own servers, where the credentials could be kept secret and access restricted. MAG's alleged exposure of the credentials was not the only issue at play. The keys were vastly overprivileged for their intended job, which was to attribute page clicks to marketing emails, Helme said. The keys had read/write access to core Iterable endpoints, giving anyone who obtained them the ability to access data such as customer profiles, parking and lounge bookings, and Fast Track purchases. Helme said the structure and contents of the stolen data indicated that it had been exported from Iterable. He said he also found that the keys could access endpoints capable of deleting customer records and lists or rewriting profiles. "There's no indication FulcrumSec did any of this, and I'm glad, but they could have just nuked everything from orbit and MAG would have been really screwed," said Helme. "For four whole years, the capability to delete Manchester Airports Group's database was a view-source away. "This wasn't only a confidentiality exposure. It was a colossal integrity and availability exposure too, and MAG just got lucky. How do they now trust any of the data that remains in the database?" When it disclosed the incident, MAG described the cyberattack as "sophisticated" and said it was "a hack, not a lapse." The company declined to comment on Helme's conclusions. MAG is continuing its investigation alongside the Information Commissioner's Office (ICO) and supporting the National Crime Agency with its inquiries. It is understood that MAG maintains it was the victim of a crime and disputes Helme's "no hacking required" characterization. FulcrumSec released the company's data on September 2, a week after MAG confirmed it had refused to pay. According to the ICO, the group's extortion demand was lower than those typically made by cybercriminals. ยฎ

โŒ
โŒ