Topic: financial fraud

  • Upbound hack leads to $13M in fraudulent Acima leases

    Upbound hack leads to $13M in fraudulent Acima leases

    Upbound Group disclosed a cybersecurity breach that led to $13 million in fraudulent leases through its Acima brand, with threat actors using stolen non-sensitive customer data to create fake lease-to-own agreements and defaulting on payments. The company responded by implementing enhanced authen...

    Read More »
  • Financial Fraud Rises with Cloud Phone Adoption

    Financial Fraud Rises with Cloud Phone Adoption

    Cloud-based phone technology, which creates legitimate-seeming remote Android devices, is being exploited by criminals to bypass bank security and facilitate sophisticated financial fraud. These inexpensive, rentable cloud phone services allow fraudsters to manage numerous "dropper accounts" for ...

    Read More »
  • Ransomware, fraud, lawsuits push cyber insurance claims to record highs

    Ransomware, fraud, lawsuits push cyber insurance claims to record highs

    The 2026 InsurSec Report from At-Bay shows a 7% year-over-year increase in overall claim frequency and an all-time high average severity of $221,000, with ransomware severity reaching $508,000, a 16% jump from the previous year. Remote access weaknesses, particularly VPN compromises, were the dom...

    Read More »
  • Meta Scam Alert: How to Spot and Avoid This Global Investment Fraud

    Meta Scam Alert: How to Spot and Avoid This Global Investment Fraud

    A global investment scam uses paid social media ads, particularly on Meta platforms, to distribute fabricated news and emotionally manipulative videos, impersonating trusted brands and figures to trick victims. The fraudulent operation employs a structured process where victims are lured by sensa...

    Read More »
  • 1.2 Million French Bank Accounts Exposed in Data Breach

    1.2 Million French Bank Accounts Exposed in Data Breach

    A data breach at France's national bank account registry (FICOBA) exposed the personal and banking details of 1.2 million citizens after an attacker used a civil servant's stolen credentials. The exposed data, including IBANs and addresses, poses significant fraud risks, such as unauthorized dire...

    Read More »
  • Peruvian Scam Steals Card Details with Fake Loan Apps

    Peruvian Scam Steals Card Details with Fake Loan Apps

    A sophisticated loan scam in Peru uses fake bank websites and social media ads to harvest high-quality credit card details and banking passwords through a multi-stage verification process. The fraud employs psychological manipulation and technical checks, like real-time card number validation, to...

    Read More »
  • EU Probes Tech Giants Apple, Google, Microsoft Over Online Scams

    EU Probes Tech Giants Apple, Google, Microsoft Over Online Scams

    The EU is questioning Apple, Google, Microsoft, and Booking Holdings about their efforts to combat financial fraud as part of enforcing the Digital Services Act for a safer online environment. This scrutiny could lead to investigations and fines if companies fail to prove adequate measures agains...

    Read More »
  • Global operation disrupts cybercrime assembly line with one-two punch

    Global operation disrupts cybercrime assembly line with one-two punch

    International law enforcement and private tech firms have dismantled a cybercriminal "assembly line" that amassed millions of stolen credentials and extracted over $47 million through ransom payments and fraud. The operation targeted two key tools: Amadey, a malware-as-a-service platform for comp...

    Read More »
  • Microsoft, Cloudflare Shut Down Massive RaccoonO365 Phishing Operation

    Microsoft, Cloudflare Shut Down Massive RaccoonO365 Phishing Operation

    Microsoft and Cloudflare dismantled the RaccoonO365 phishing-as-a-service scheme, which harvested thousands of Microsoft 365 credentials through deceptive campaigns. The operation seized 338 websites and accounts, disrupting a group that compromised over 5,000 users across 94 countries and target...

    Read More »
  • Authorities shut down €336M crypto laundering hub for cybercriminals

    Authorities shut down €336M crypto laundering hub for cybercriminals

    An international operation dismantled the cryptocurrency laundering service "AudiA6", which processed over "€336 million" in illegal funds for ransomware groups between 2022 and 2025, and was linked to the dark web forum "Dark2Web". On June 10, two administrators were arrested in Georgia, w...

    Read More »
  • EU Probes Apple, Google, Microsoft Over Online Scam Response

    EU Probes Apple, Google, Microsoft Over Online Scam Response

    The EU is demanding that Apple, Google, Microsoft, and Booking Holdings provide information on their efforts to combat online scams under the Digital Services Act. Regulators are focusing on app stores and search engines to assess how they identify and remove fraudulent apps and deceptive search ...

    Read More »
  • Steam Game Pulled After $150K Crypto Heist

    Steam Game Pulled After $150K Crypto Heist

    A malicious game called BlockBlasters was removed from Steam after being exposed as a cryptodrainer that stole over $150,000 from players' cryptocurrency wallets. The game initially appeared legitimate with positive reviews but secretly integrated the cryptodrainer in an August update, with a Lat...

    Read More »
  • Scam Emails Spoofing Real Microsoft Addresses

    Scam Emails Spoofing Real Microsoft Addresses

    A sophisticated email scam exploits a legitimate Microsoft address ([email protected]) to send fake Power BI subscription invoices, tricking users into believing they've been charged $399. The campaign weaponizes Microsoft's own official guidance, as the address is genuinely used for...

    Read More »
  • Google's New Sideloading Feature Fights Scams

    Google's New Sideloading Feature Fights Scams

    Google is introducing a new, multi-step process for Android users to install apps from outside the Play Store, designed to balance user freedom with security by requiring actions like enabling developer mode and a one-day waiting period. The policy change follows an antitrust settlement and aims ...

    Read More »
  • Olympic Cybersecurity: A Prime Target for Attackers

    Olympic Cybersecurity: A Prime Target for Attackers

    The immense scale and rapid deployment of temporary digital infrastructure for the Olympics creates a uniquely vulnerable target for cyberattacks, driven by financial gain, espionage, and public disruption. Financially motivated threats include ransomware targeting critical systems and widespread...

    Read More »
  • Data Breach at Central Maine Healthcare Impacts 145,000+

    Data Breach at Central Maine Healthcare Impacts 145,000+

    A major cybersecurity breach at Central Maine Healthcare compromised the personal and medical data of over 145,000 patients and employees, with hackers having undetected access to systems for over two months in early 2023. The exposed data is highly sensitive, including Social Security numbers, h...

    Read More »
  • Claude Now Integrates with Excel: 7 New Connectors Added

    Claude Now Integrates with Excel: 7 New Connectors Added

    Anthropic has enhanced Claude with Excel integration, seven market data connectors, and six finance Skills to support financial professionals in data analysis and reporting. The Excel integration allows direct interaction within spreadsheets for queries and modifications, while new connectors pro...

    Read More »
  • Lessons from the Underground: Fighting Business Email Compromise

    Lessons from the Underground: Fighting Business Email Compromise

    Business Email Compromise (BEC) is a sophisticated multi-stage operation involving compromised accounts, targeted financial intelligence, and organized cash-out networks, evolving beyond simple phishing tricks. Attackers conduct extensive reconnaissance by purchasing access to compromised email a...

    Read More »
  • Seeking Cybersecurity Advice on Reddit Amid Fear and Confusion

    Seeking Cybersecurity Advice on Reddit Amid Fear and Confusion

    A surge in people are turning to Reddit for urgent cybersecurity help, with monthly help-seeking posts spiking over 66% in 2024, highlighting a gap in accessible support. The most common issues prompting these posts are scams, account access problems, and practical questions about privacy tools, ...

    Read More »