A former AT&T retail worker who used his system access to hijack customers' phone numbers for cybercriminals has been sentenced to 16 months in federal prison. Kenneth Carter, 44, carried out the SIM swaps at a store in Portland, Oregon, , allowing the criminals to intercept authentication codes and raid victims' bank accounts. Court documents show that Carter worked with at least three other people in the scheme, which ran between May 2018 and November 2019, and caused nearly $600,000 in intended losses. Co-conspirator One, described in court documents as the operation's main "hacker," identified victims with online bank accounts, gathered their personal data, and sent it to Carter, who could reassign their phone numbers. Carter abused his access to AT&T's systems to transfer victims' phone numbers to devices controlled by the other criminals. His role was described as "instrumental to the scheme." Co-conspirator Two and Co-conspirator Three would walk into the store and impersonate the victim whose number they planned to SIM-swap, and Carter would reassign the number to a phone they controlled – usually a "cheap flip phone." Once the swap was complete, the criminals could use the flip phone to intercept SMS-based 2FA codes and password reset messages, take over the victim's bank account, and steal funds. The intercepted codes were relayed to Co-conspirator One, who used them to access the victims' bank accounts. Court documents also refer to "an unnamed family member" who held a minor role in the scheme. They were described as someone "who occasionally passed along the two-step authentication codes" to Co-conspirator One. According to the Justice Department, three victims incurred combined intended losses of $593,963.77, and Carter admitted carrying out additional unauthorized SIM swaps. Carter's plea agreement [PDF] included details of three SIM swap attacks he helped execute. Only one victim suffered an actual loss: $99,528.33 transferred to a Portuguese bank account. The conspirators attempted to transfer $247,652.74 and $246,782.70 from the other two victims, but the banks' fraud controls blocked both transactions. Prosecutors said Carter was paid between $1,000 and $2,000 per swap, although he maintained that he earned less than $4,000 in total. Law enforcement raided Carter's residence in November 2019, finding copies of the personal data provided to him to carry out the SIM swaps, including the Social Security number of the one victim whose money was successfully stolen. AT&T terminated Carter's employment at an unspecified date in 2019. He pleaded guilty on March 24, 2026, to conspiracy to commit wire fraud and bank fraud. In a letter to United States District Judge Stanley Blumenfeld, Jr., Carter described his offending as "a one-off situation that truly was a mistake." He explained that he takes care of his mother-in-law, who spends much of her time in a hospital bed located in the family living room, and two daughters, one of whom has schizophrenia. Carter claimed that he was "propositioned by my in-law cousin with an opportunity for me to make a little extra money for my family." "I was told I wouldn't have to do anything but do my job," he added. "So, I was under the impression that this was a harmless act. As far as I knew at the time, I was never a part of a ring, nor was this an out-of-state matter. "My incident was isolated to just Portland, OR, and the incident occurred while I was employed by AT&T. I later learned that what I found myself a part of was criminal, and I also learned after the fact the severity of what my co-conspirators were doing with the flip phones I sold under customer accounts." Federal prosecutors were unmoved by Carter's letter. In their response [PDF], US attorneys argued that Carter had not provided enough evidence to show he was unaware of the criminal activity's scope or nature, or that he was less culpable than the "hacker" who coordinated the operation. In addition to the 16-month sentence, Judge Blumenfeld, Jr. ordered Carter to pay $99,528 in restitution. ®
A Ukrainian lawyer who wound up coding malware for the Conti ransomware gang has been sentenced to four years in a US prison. Oleksii Oleksiyovych Lytvynenko, 44, pleaded guilty in June to conspiracy to commit wire fraud over his role in Conti, the Russia-linked ransomware operation associated with more than 1,000 victims and at least $150 million in ransom payments. Lytvynenko took an unusual route into the ransomware business. The Ukrainian national, who later lived in Cork, Ireland, trained as a lawyer before joining Conti as an intruder and developer. According to his plea agreement [PDF], Lytvynenko operated under the handle "henry" and joined a team run by another Conti conspirator known as "silver" or "buza." He was recruited to help with coding and directed to work on a malware loader – software designed to get other malicious code running on a victim's machine. Prosecutors said his Google account showed he had also been doing some homework. Investigators found books and videos about malware and hacking alongside Conti malware, ransom notes, and stolen victim data. Prosecutors said he also used Google and ZoomInfo to research potential targets. Lytvynenko wasn't confined to writing code, according to the filing. Evidence from his online accounts showed that he possessed data stolen from eight US victims and four overseas, with the eight American victims reporting more than $1.5 million in losses. Court documents identify several Bitcoin transfers tied to his Conti work, including 0.4 BTC worth $25,042 that prosecutors traced back to one of his victims. He has been ordered to forfeit the same amount. Conti disbanded in 2022 after its internal chats and source code were leaked following the gang's public support for Russia's invasion of Ukraine. Lytvynenko apparently didn't take that as his cue to find another line of work. When Gardaí turned up at his County Cork home in July 2023, they said they found his laptop open, Cobalt Strike running and a Rocket.Chat session connected over Tor. Prosecutors said evidence recovered from the machine showed that his involvement in ransomware activity had continued after Conti disbanded. Lytvynenko was extradited from Ireland to the US in October 2025. The Justice Department says Conti attacked organizations across 47 US states, the District of Columbia, Puerto Rico, and 31 foreign countries between 2020 and 2022. By January 2022, the FBI estimated that victim payouts associated with Conti exceeded $150 million. Lytvynenko will now have four years to contemplate a career change. ®
Crypto hardware wallet maker Trezor says the third-party email service provider it uses to send newsletters has been breached, and customers are now being sent phishing messages. There is good and bad news. The good news is that the emails appear easy to spot. They are not bespoke to each recipient and resemble a spray-and-pray campaign rather than sophisticated targeting that uses customer-specific data to enhance the email's perceived authenticity. All known examples of the scam email are titled "Critical Security Alert: STM32 Entropy Vulnerability," and the body explains that an estimated one in four Trezor devices are affected by a "hardware factory defect." The email warns customers that wallet seeds are exposed to brute-force attacks due to "insufficient randomness" and a "critically low 40-bit entropy." The email asks recipients to share their wallet backups. Trezor said: "Do not click it or interact with it. Never enter your wallet backup anywhere. Always confirm every action with your Trezor physically." The bad news is that because the attackers allegedly compromised the legitimate email provider, the messages can pass authentication checks and bypass some of the usual protections deployed by receiving email services. According to those who have shared copies of the emails, they appear to be sent from "mailing@trezor.io." Trezor has issued the warning across its social media channels and Trezor Suite, the companion app for its hardware wallets. The Register asked Trezor for more information. The third party email provider Brevo – formerly known as Sendinblue – said in a statement that a "security incident" had "allowed an attacker to access 120 Brevo accounts." It added that the "bad actor used the access to send phishing emails to the client's contactbase," and promised a "full post mortem later today." Swiss hardware wallet maker BitBox also appears to be affected, having shared an image of an email nearly identical to the one targeting Trezor's newsletter subscribers. The email similarly warns of entropy weaknesses affecting BitBox devices, although it is titled slightly differently: "Critical Security Alert: Microcontroller Entropy Bug Identified." The company said on X: "Our preliminary review of the phishing mail that was sent out to our newsletter subscribers about an hour ago found that it is very likely that our newsletter provider got compromised. "Multiple other Bitcoin companies got targeted as well, and it appears that we all share the same newsletter provider. "We sent out a phishing warning to all our newsletter subscribers, contacted the provider and reported the phishing domains. Most of the phishing links appear to have been taken down already. "We are still actively investigating this situation and will update you once we know more." Crypto tax and portfolio-tracking company CoinTracking also disclosed the compromise of its third-party email provider, which it named as Brevo, around the same time as Trezor and BitBox. CoinTracking shared a copy of the phishing email targeting its users and, since it does not offer hardware wallets, the message uses a different lure, asking customers to follow a link to refresh their API keys. Tough times in Trezorland The latest security snafu comes less than a month after Trezor announced that thousands of customers' details had been compromised following a breach at logistics partner ShipMonk. The hardware vendor initially estimated that around 13,000 people were affected. Those who ordered Trezor products between May 10 and August 8 had their names, email addresses, phone numbers, and shipping addresses breached. Compounding the problem for a company whose brand centers on security, Trezor confirmed on September 4 that the total number of affected customers had risen to 80,000. Trezor said ShipMonk later informed it that an additional 67,000 US customers who purchased products between November 2019 and August 2021 were affected. "Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications," said Trezor. "We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems." ®
The ringleader of a sprawling cybercrime operation has pleaded guilty in the US after helping to steal and launder hundreds of millions of dollars in cryptocurrency. Malone Lam, 22, a Singaporean national and Miami resident, spearheaded the scheme to steal cryptocurrency from wealthy individuals between October 2023 and May 2025. He first visited the US in 2023 after meeting two of the group's earliest alleged members – Jeandiel Serrano and Veer Chetal – while playing Minecraft online. Lam performed various functions within the group, although court documents [PDF] identify victim selection and social engineering support as his principal roles. The ringleader was responsible for obtaining databases of high-net-worth individuals who had cryptocurrency holdings to inform the group's targeting. He would also trigger account access notifications on victims' devices to convince them that their accounts were under attack. He was also involved in laundering the proceeds through exchanges that, according to court documents, had lax KYC requirements. Other group members carried out the social engineering calls, claiming to represent Google, Yahoo, Coinbase, Gemini (the crypto exchange, not the AI chatbot), and other online platforms. Their job was to convince victims to surrender personal information and "access codes" that could be used to access their accounts. Once they secured access, Lam's crew would look for cryptocurrency accounts, seed phrases, and passwords they could use to steal victims' assets. In most cases, social engineering techniques were enough to meet the thieves' goals, although in one case involving a victim who stored their holdings in a hardware wallet, Lam's gang arranged for Marlon Ferro to physically break into a house and steal it. The Register covered Ferro's sentencing earlier this year. He was brought into Lam's fold when he was just a teenager, tasked with carrying out multiple burglaries across the US when remote social engineering attacks lacked the necessary reach. During the crew's nearly two-year operation, its members stole hundreds of millions of dollars' worth of cryptocurrency. The individual thefts ranged from about $800,000 to tens of millions of dollars, while one victim lost more than $245 million, according to court documents. Lam's crew, allegedly comprising at least 12 individuals, knew how to spend their illicit gains. Prosecutors claim they splurged up to $500,000 on a single evening at a nightclub, dished out handbags worth tens of thousands of dollars to partygoers, and bought luxury clothing and watches priced between $100,000 and $500,000. They rented expensive properties in Miami, Los Angeles, and the Hamptons, chartered private jets, hired a team of private bodyguards, and splashed out on exotic cars, with some worth up to $3.8 million. Lam was arrested at a rented property in Miami on September 18, 2024. His sentencing hearing has not yet been scheduled. The court has set a status hearing for December 8. Lam pleaded guilty to one count of participating in a racketeering conspiracy, an offense carrying a maximum sentence of 20 years in prison. "If you build a cybercrime empire, we will find you, dismantle your operation, and hold you accountable," said US Attorney Jeanine Ferris Pirro. "This defendant led an international network that preyed on victims through deception, invaded their privacy, and stole hundreds of millions of dollars in cryptocurrency. "Working with our partners at the FBI and IRS-CI, we will continue to hunt down the criminals who weaponize technology to steal from innocent people." ®
Security researcher Scott Helme says his analysis supports FulcrumSec's claim that Manchester Airports Group (MAG) exposed privileged API keys in client-side JavaScript. Helme says he reached that conclusion after using information provided by the cyber extortion group to reconstruct how data belonging to roughly 8.8 million MAG customers was allegedly stolen last month. The crooks behind the attack described MAG's security failure as "tragi-comical." They claimed MAG exposed overprivileged API keys for Iterable, a marketing automation platform, in front-end JavaScript served by the websites of MAG's three airports: Manchester, Stansted, and East Midlands. Helme used the Internet Archive's Wayback Machine to retrieve older versions of the JavaScript and found that the three keys first appeared across the airport websites in June and July 2022. The same values remained exposed until August 2026, he said. "Read the timeline the other way round and it's worse," said Helme. "Anyone who looked at that page source on any day between June 2022 and August 2026 could have taken the key. FulcrumSec just happen to be the ones who told us. "There is no way to know, from the outside, who else did, and the honest answer is that MAG can't know either without going back through four years of Iterable API logs, if they even have four years of Iterable API logs." The API keys were not embedded directly in the HTML, Helme explained, but anyone who examined the JavaScript bundles loaded by the sites could find them. This would explain how the vulnerability could go unnoticed by the airport's IT teams for over four years. Helme says the browser-delivered code was using the keys to authorize server-side API operations – something Iterable's documentation explicitly warns against. The requests should instead have passed through MAG's own servers, where the credentials could be kept secret and access restricted. MAG's alleged exposure of the credentials was not the only issue at play. The keys were vastly overprivileged for their intended job, which was to attribute page clicks to marketing emails, Helme said. The keys had read/write access to core Iterable endpoints, giving anyone who obtained them the ability to access data such as customer profiles, parking and lounge bookings, and Fast Track purchases. Helme said the structure and contents of the stolen data indicated that it had been exported from Iterable. He said he also found that the keys could access endpoints capable of deleting customer records and lists or rewriting profiles. "There's no indication FulcrumSec did any of this, and I'm glad, but they could have just nuked everything from orbit and MAG would have been really screwed," said Helme. "For four whole years, the capability to delete Manchester Airports Group's database was a view-source away. "This wasn't only a confidentiality exposure. It was a colossal integrity and availability exposure too, and MAG just got lucky. How do they now trust any of the data that remains in the database?" When it disclosed the incident, MAG described the cyberattack as "sophisticated" and said it was "a hack, not a lapse." The company declined to comment on Helme's conclusions. MAG is continuing its investigation alongside the Information Commissioner's Office (ICO) and supporting the National Crime Agency with its inquiries. It is understood that MAG maintains it was the victim of a crime and disputes Helme's "no hacking required" characterization. FulcrumSec released the company's data on September 2, a week after MAG confirmed it had refused to pay. According to the ICO, the group's extortion demand was lower than those typically made by cybercriminals. ®
Cybercriminals have reeled in password hashes and corresponding salts belonging to users of popular fishing app Fishbrain, opening the door to cracking attempts. Fishbrain AB, which says its eponymous app serves more than 20 million anglers, disclosed the August 19 breach to the California Attorney General's Office this week. The unknown perpetrators helped themselves to a trawl of user data, including names, dates of birth, email addresses, phone numbers, Fishbrain usernames, country information, password hashes, and salts. "Fishbrain passwords were not stored in plaintext; however, Fishbrain has determined that the compromised password hashes for some users may be susceptible to being decoded," the company said in its disclosure [PDF]. It added: "If you use your Fishbrain password for any other online accounts, you should promptly update those passwords and any associated security questions or answers. "You should also take other appropriate steps to protect any online accounts that use the same username or email address and password combination. We recommend using a strong, unique password for each of your accounts." With the hashes and salts in hand, attackers can make password guesses using their own hardware until they potentially recover the original credentials. Whether those attempts succeed depends on the strength of each password and the hashing algorithm Fishbrain used, which the company did not disclose. Fishbrain did not comment on the scale of the breach or how many of its claimed 20 million-plus users were affected. The Register asked Fishbrain for more information. After discovering the intrusion and conducting an initial forensic investigation, Fishbrain patched the vulnerability and reset every user's password. Customers must create a new one the next time they log in. Fishbrain also said it "restricted access to the affected environment," strengthened its security controls, and initiated "a broader review of our data security measures" while the investigation continues. Fisherfolk should also keep an eye out for phisherfolk using the stolen personal data to bait follow-on attacks. ®
International law enforcement agencies, working with CrowdStrike and Shadowserver Foundation, have disrupted Sality, a 23-year-old peer-to-peer botnet used to deliver malware to more than 15,000 machines worldwide. The botnet has operated since 2003 and distributed all types of malicious code to victims, spanning credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks. For the past eight years, Sality’s primary payload has been EggJagger, a tool that monitors clipboards for cryptocurrency wallet addresses, then silently replaces them with attacker-controlled addresses. When a victim copies a bitcoin or ethereum address to make a payment, the malware redirects funds into the criminals’ wallets. CrowdStrike estimates Sality's operator stole at least $150,000 in cryptocurrency using EggJagger alone. On Monday, CrowdStrike's Counter Adversary Operations team, working with international law enforcement agencies and industry partners, disrupted Sality by executing a peer-to-peer sinkhole operation. This operation isolated infected machines, which broke the criminal operator’s ability to communicate with devices on its network. Once isolated, the bots can no longer receive payload download instructions or direct payload transfers, effectively breaking the botnet. “In practice, the operation targeted the data structure at the heart of every bot's network awareness: its peer list,” CrowdStrike Counter Adversary Operations team said in a technical writeup about the takedown. Each Sality bot maintains a list of known super peers – publicly reachable infected machines that form the backbone of the P2P network. Every 40 minutes, the bots check to see if their peers are still online. Peers that fail to respond are purged from the network. The counterattack took advantage of this by removing legitimate super peers in each bot’s peer list, continually isolating more infected machines in the network, and inserting purpose-built sinkhole entries into peer lists. That approach gave police and cyber operatives visibility into the operation’s progress and helped them notify victims. In addition to the sinkhole operation, the US Justice Department, FBI, and Department of Defense Office of Inspector General’s Defense Criminal Investigative Service seized Sality-linked domains in the US. Meanwhile, international law enforcement in Bulgaria, Hungary, and Romania took action against additional Sality-linked domains hosted in Europe. Meanwhile, the Shadowserver Foundation is working with internet service providers and Computer Security Incident Response Teams (CSIRTs) to identify infections and aid in victim notification and remediation.®
US hospital operator Nutex Health says attackers stole private or confidential patient, employee, provider, business, and financial information during the cyberattack it disclosed last week. In an updated filing submitted to the Securities and Exchange Commission (SEC) on Monday, Nutex also said an unauthorized third party had threatened to publish the stolen information. Nutex initially disclosed the intrusion on August 24 under Item 8.01 of Form 8-K, the catch-all category for "Other Events." Although it already believed some private or confidential information had been exfiltrated, it had not determined whether the stolen material included patient, employee, provider, business, financial, or intellectual property data. The company has now reported the incident under Item 1.05, the section reserved for material cybersecurity incidents, as its investigation continues to determine precisely what was taken and who was affected. Nutex did not identify the intruders. However, The Gentlemen ransomware-as-a-service (RaaS) operation added the company to its leak site on Monday and claimed responsibility for the attack. The gang offered no evidence or details to substantiate its claim. Naming victims on a leak site and threatening to publish their data is a standard pressure tactic in double-extortion attacks. Nutex's hospital division now operates 28 facilities across 12 states. A proposed class action was filed against the company on August 27 on behalf of people whose personally identifiable information or protected health information was allegedly accessed or acquired during the intrusion. Nutex said it could not predict the litigation's outcome and had not identified any material impact on its operations or financial reporting systems. The Gentlemen emerged in mid-2025, reportedly after former Qilin affiliates fell out with that gang's leadership and launched a rival RaaS operation. Researchers describe it as a primarily Russian-speaking operation whose victims are generally located outside the Commonwealth of Independent States. In May, Microsoft detailed a self-propagating encryptor used by the gang's affiliates. The malware combines multiple lateral-movement techniques, Microsoft warned, "increasing the likelihood of widespread impact once initial access is achieved." ®
Two major healthcare businesses, Boston Scientific and McKesson, disclosed more details over the weekend about separate cyberattacks that disrupted global operations and resulted in stolen patient data, respectively. Medical-device maker Boston Scientific, whose IT systems were hacked by unknown intruders last week, said the cyberattack remains ongoing. It also noted that pacemakers and other heart devices implanted after the August 25 breach cannot provide remote monitoring and data transmission as intended. “New remote monitoring communicators cannot be activated, thus available device data will NOT be transmitted to remote patient management systems until the communicator can be activated,” the medtech firm said in a late Friday update. This applies to all new cardiac rhythm management implants other than insertable cardiac monitors (ICM). ICM devices must be activated using the Boston Scientific Clinic Assistant app to ensure the device correctly records patients’ heart rhythms, the company added. Because of the cyberattack, “new ICMs are unable to pair to the patient remote monitoring mobile phone, therefore available episode data recorded by the ICM will NOT be transmitted to the remote monitoring system until the ICM can be paired to the patient mobile app,” according to the update. The devices will still record any episodes, and patients can transmit these to the remote monitoring system by in-person transmission via the Clinic Assistant app. This is done by selecting the “interrogate” button, according to the company. Once its IT systems are back up and running, and the heart devices can pair with home monitoring equipment, they will again transmit recorded data to the remote systems. However, the company does not have a timeline for full restoration. “We are currently working on restoring affected functions and systems access,” Boston Scientific said on Saturday. The digital intrusion also affected the firm’s manufacturing, shipping, and ordering, it noted. “We are expeditiously working towards partial restoration for the shipping of some products this week,” according to a Sunday update. “Once we can demonstrate the restoration is fully operable, we anticipate ordering and shipping will ramp up to full capacity.” Boston Scientific has hired CrowdStrike to assist with the investigation and restoration efforts, and said the attack did not affect its cloud-based systems and apps - just “certain on-premise systems” - and added that it has seen no indication of unauthorized IT activity since August 25. The firm has repeatedly declined to answer The Register’s questions about the compromise, including whether it was a ransomware infection and which criminal crew is responsible. McKesson confirms breach as ShinyHunters claims responsibility Meanwhile, in another cybersecurity incident that has been very publicly claimed by the criminal perpetrator: pharmaceutical and medical supply giant McKesson over the weekend confirmed an intrusion after ShinyHunters on Friday told The Register it broke into the company’s Snowflake and Salesforce instances and stole millions of patients’ data. “Based on our investigation thus far, including assessments by leading cybersecurity industry experts supporting our response, we’ve confirmed that the unauthorized access to certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units,” Francisco Fraga, McKesson executive VP, chief information officer and chief technology officer, said in a Saturday statement. The medical firm did not immediately respond to The Register’s questions, including how many patients were affected and what “certain data” was stolen. McKesson supports about 3,300 oncology providers in 29 states, according to its website. Fraga’s statement noted that distribution centers remain operational and McKesson continues to ship products. The firm has “reasonable assurance” that the digital intruders have been kicked out of the third-party environments and aren’t lurking around McKesson’s systems, he added. A ShinyHunters spokesperson told us that the notorious extortion group compromised more than 284 million records of patient data, and demanded McKesson pay $55.2 million or else they would leak the stolen data. However, as Have I Been Pwned boss Troy Hunt recently reminded everyone: Don’t confuse criminals’ claims with gospel truth, and “take headline numbers with a grain of salt unless you're confident in the processes of those making the claims." This was after Hunt’s HIBP service reported 12.9 million individuals affected by retailer Carhartt’s alleged breach. This number was around half of what ShinyHunters claimed when they leaked the company’s data earlier this month. The McKesson records, according to the ShinyHunters spokesperson, include patients’ full names, home and email addresses, phone numbers, dates of birth, Social Security numbers, appointment dates and notes, and sensitive illness details including cancer locations on people’s bodies. The group also claims to have swiped emails containing private information from doctors to patients. The spokesperson told us they accessed the company’s Snowflake and Salesforce instances by voice phishing “multiple employees.” This is a tried-and-true method popularized by the data-theft-and-extortion gang, which has victimized other medical providers in recent months. These include pacemaker manufacturer Medtronic in April, and cancer diagnostics business Exact Sciences in July. ®