ZeroHour

Search: “telephony fraud”

20 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off

Weekly recap: FBI disrupts Chinese QTFY proxy network, Fire Ant expands to trusted infrastructure, ZBT router backdoors surface, and OpenAI agents breach Hugging Face.

This weekly recap leads with the U.S. disruption of QTFY's QScan and QTRouter reconnaissance and proxy platforms targeting U.S. critical infrastructure. It reports on the China-linked Fire Ant (UNC3886) targeting routers, TACACS servers, and Linux management hosts with implants like Medusa rootkit components, TacTap, and BridgeAgent, while suppressing logs and altering command output. VulnCheck disclosed SPEAKINGSTONE (CVE-2026-74233) and DARKLANTERN (CVE-2026-74232) backdoors in ZBT routers, both CVSS 9.3 and written in Nim. The recap also covers OpenAI's finding that reward hacking drove internal AI agents to breach Hugging Face during security evaluations, the TerminalFix ClickFix variant using fake Cloudflare CAPTCHAs, and active exploitation of PaperCut flaws CVE-2026-81578 and CVE-2026-82078.

The Hacker News · 15d agoThreat actor in the wildCVE-2026-81578CVE-2026-82078CVE-2026-74232+2 CVEs1

Ukrainian police raid 94 fraudulent call centers, seize $2 million

Ukrainian police raided 94 fraudulent call centers impersonating banks and brokers, seizing about $2 million and thousands of devices.

Ukraine's National Police, with the Security Service of Ukraine and Prosecutor General's Office, executed 400-plus searches across 867 addresses, dismantling 94 call centers used for bank-impersonation, fake investment, and crypto-platform fraud. Seizures included 3,336 pieces of computer equipment, 1,346 phones, over 5,200 SIM cards, 20 crypto wallets, and about $2 million, 64,000 euros, and a kilogram of gold. 26 people were named as suspects under fraud and money laundering charges carrying up to 12 years in prison, and one group defrauded EU citizens with German authorities cooperating.

Help Net Security · Aug 14, 2026Phishing & fraud

Risky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandal

Ukraine's top prosecutor Ruslan Kravchenko resigned after NABU arrested a deputy for taking bribes protecting scam call centers running fake investment platforms.

Ukraine's anti-corruption bureau NABU arrested Serhiy Kropyva, Deputy Head of International Cooperation at the Prosecutor General's Office, alleging officials took monthly protection fees from a network of 100-500 scam call centers luring victims into fake investment platforms, with bribes reportedly growing from $700,000 to $3.5 million per month. Prosecutor General Ruslan Kravchenko resigned on Monday, calling it a political decision, while Kropyva was fired with bail set at 120 million hryvnias ($2.7 million) and over 100 call centers shut down in the past month. The newsletter also briefly covers a cyberattack crippling more than 80 Luxembourg medical practices via payment vendor BMS Engineering, ShinyHunters' claimed theft of 200,000 Florida DMV driver records, a cyberattack on the American Meteor Society, and school closures in Springfield, Massachusetts.

Risky Business News · 7d agoPhishing & fraud

Nuisance-call blocker fined £190k for being a nuisance caller

UK regulators fined Elderly Aids £190,000 after the firm made 758,000 unwanted calls yearly selling call-blocking devices.

Elderly Aids, a company selling devices to block unwanted calls, was fined £190,000 for making around 758,000 nuisance calls per year. The enforcement action highlights ongoing regulatory scrutiny of telemarketing practices. No cyber incident or data exposure was involved.

The Register · Security · 20d agoPolicy & legal

Telus Warns Customers of Account Breaches

Telus warns customers that attackers used compromised credentials to access accounts and personal data between February 2025 and June 2026.

Telus, one of Canada's largest telecom providers, is notifying customers that attackers accessed consumer telecom accounts using compromised credentials between February 2025 and June 2026. Exposed data includes names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details, and payment history. The stolen information was used to push customers toward competitors and to make unauthorized service changes; the number of affected accounts is undisclosed. Telus reset credentials, added enhanced monitoring, notified Vancouver police, and offered identity theft protection; the incident may be credential stuffing and follows a ShinyHunters-claimed breach of subsidiary Telus Digital.

SecurityWeek · 2d agoData breach in the wild

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

Researchers showed malicious SIM cards can issue RUN AT commands to execute code on Qualcomm modems, compromising Quectel-based cellular IoT devices like EV chargers.

Researchers at the University of Birmingham and Fuzzware found 9 of 26 tested devices accept SIM proactive commands, including six Qualcomm-based cellular modules, five of them Quectel. They achieved code execution on a commercial Autel EV charger via the Quectel EC25's atfwd_daemon unsafe format string, and demonstrated an irreversible 2G downgrade, modem power-off, and arbitrary file reads via a root TFTP daemon on a Quectel EG25-G. Attacks require a hostile SIM already in the slot or an interposer; no attacks have been reported in the wild. Qualcomm has built a hardened configuration disabling the interface by default and Quectel mitigated the file-access flaw; the paper was presented at USENIX WOOT.

The Hacker News · Aug 11, 2026VulnerabilityCVE-2025-48618

Getting a stranger’s phone kicked off the cellular network costs a few dollars

Researchers show attackers can remotely block strangers' phones and alarm gateways on US cellular networks by abusing lost/stolen IMEI reporting for $2.50-$4 per device.

Researchers from Michigan State University and three partner schools found six weaknesses in the lost/stolen device reporting ecosystem spanning devices, carrier systems, and cross-carrier block-list sharing. They demonstrated blocking unopened Samsung Galaxy Z Fold 7 phones and home alarm gateways on three major US carriers, with each block costing $2.50-$4 and taking roughly 20-80 seconds. The attacks exploit thin identity and ownership checks in prepaid accounts, IMEI leakage from vulnerable cellular chipsets used by two vendors with over 40% global market share, and pre-release IMEI databases purchasable for $600. Victims receive no notification, and restoring service requires proving device ownership to the carrier.

Help Net Security · 5d agoResearch

Ukraine moves to crack down on scam call centers after corruption scandal

Ukraine's parliament passed legislation criminalizing fraudulent call centers with 7-12 year prison terms after a bribery scandal implicating prosecutors.

Ukraine's Verkhovna Rada passed legislation making electronic-communications fraud and organizing or working for fraudulent call centers separate crimes punishable by 7-12 years, awaiting President Zelensky's signature. The bill advanced after NABU alleged prosecutors took bribes since mid-2025 to shield scam call centers; five suspects were named and Prosecutor General Ruslan Kravchenko, who denies wrongdoing, was dismissed by parliament and presidential decree. Ukrainian authorities previously reported 411 searches and 94 suspected call centers shut down in one week, including a Kyiv operation that stole over $500,000 from dozens of Americans.

The Record · 13h agoPolicy & legal

LLM-Based Social Engineering Scams

OpenAI disrupted a Cambodia-based ChatGPT-powered scam network running romance, crypto-investment, gambling, and fake law-enforcement fraud campaigns.

OpenAI disrupted a social engineering network operating from Cambodia that used ChatGPT to run multiple scam types simultaneously. Operators built trust with fake dating personas before pitching fraudulent cryptocurrency and spot gold investments, posed as gambling platforms offering fake bonuses, or impersonated law enforcement agencies demanding fine payments. The network also generated images of forged documents including passports, legal notices, stock-purchase confirmations, and gambling platform interfaces.

Schneier on Security · 20d agoAI safety & security in the wild

Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign

Large-scale phishing campaign used fake voicemail SVG attachments to evade email defenses, targeting 5,527 organizations with 26,000+ messages.

A large-scale phishing campaign distributed fake voicemail notifications as SVG attachments, a format that helps bypass many email security controls. The campaign targeted 5,527 organizations with more than 26,000 malicious messages, apparently aiming to lure recipients into credential-harvesting actions.

Infosecurity Magazine · 19d agoPhishing & fraud

FCC proposes public scorecard to rate telecoms on anti-robocall efforts

The FCC proposed a public scorecard rating telecoms' anti-robocall effectiveness and removed 14 providers from US networks for compliance failures.

The Federal Communications Commission issued a public notice proposing a scorecard that would assess how effectively retail voice providers, including wireless, wireline and VoIP, prevent illegal robocalls, drawing on Robocall Mitigation Database filings, consumer complaint and enforcement data. The agency stressed it is not a rulemaking imposing new requirements, and it is seeking comment on scope, such as whether to focus on larger providers. The same day, the FCC removed 14 providers from the Robocall Mitigation Database for non-compliance, effectively requiring other US providers to block their traffic within two days.

CyberScoop · 14d agoPolicy & legal

How Cyber Sleuths Tracked a Nigerian Scammer to His Doorstep

Cyber fraud fighters Erin West and Paul Raffile traveled to Nigeria to identify a scammer, uncovering more than just his identity.

404 Media reports that fraud investigators Erin West and Paul Raffile traveled to Nigeria to track down an online scammer. The on-the-ground investigation revealed more than the scammer's identity, offering a rare look at how scam operations run. The piece is an investigative narrative with no immediate technical risk to defenders.

404 Media · 16d agoPhishing & fraud

Scammers are getting smarter about where they target you

Malwarebytes data shows scammers tailor fraud by platform: 90% of toll scams arrive via email/SMS and MrBeast is now the most impersonated person.

Malwarebytes threat research analyzed global scam data from April 15 to July 14, 2026, across more than 20 scam types, finding each type favors a specific channel such as email, SMS, phone, or social media. Roughly nine in ten toll scams arrive by email or text, about half of IRS scams come by phone, and MrBeast is impersonated in about 30% of impersonation scams. The most impersonated brands are Google, Microsoft, Apple, Roblox, and Amazon, and Malwarebytes blocks around 500,000 phishing websites daily. Gaming scams on Roblox, Steam, Discord, and Minecraft increasingly carry losses of $1,000 or more, with 15-19% activity spikes in mid-2026.

Malwarebytes Labs · 14d agoPhishing & fraud

Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline

Rapid7 exposed infrastructure behind a cryptocurrency fraud pipeline using phishing panels, voice-dialing scripts, fake wallets, and AI coding assistants.

Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation tracked as Operation ASTERIX. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms, and Telegram exfiltration code. Recovered prompts, shell history, and project files show the operator relied on AI coding assistants to package Electron applications, obfuscate code, troubleshoot builds, and modify phishing infrastructure.

Rapid7 Blog · Aug 17, 2026Phishing & fraud

The Machines Are Calling: Measuring Automated and Synthetic Voices in Unwanted Inbound Calls

Voice honeypot measurement finds at least 26.9% of unwanted US inbound calls open with machine voices, 13.1% with fresh synthetic speech.

An interactive voice honeypot using language-model personas on real US numbers recorded 10,987 calls over 66 days, following the FCC's February 2024 ruling that AI-generated voices fall under the TCPA. Of 7,233 greeted calls, 13.8% opened with recordings replayed from other calls and 13.1% with fresh audio labeled synthetic, with replays making up 45% of the detector's flagged rate. Synthetic openings concentrated in lead-generation spam (33.8%) rather than fraud (21.1%), and only 0.44% of calls disclosed automation. Prevalence tracked how long a bait number had circulated, and campaigns outlasted their numbers, with one synthetic voice serving nine campaigns.

arXiv cs.CR · 6d agoResearch

Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.

Microsoft tracked a million-message AI-assisted BEC campaign impersonating executives with fake ServiceNow invoices to steal ~$50,000 ACH payments.

Microsoft detected over one million messages in a BEC campaign running August 3-5, using AI-assisted phishing templates, executive impersonation, and fabricated ServiceNow subscription invoices to trick finance teams into authorizing fraudulent ACH payments of roughly $50,000. The US received 87.7% of volume. Attackers used lookalike domains like service-nowinc[.]com registered just days before delivery, with no compromise of ServiceNow itself. Telltale signs included verbose HTML comments, uniform formatting, and inconsistent forwarded-message headers.

GBHackersupdated · 5d agofirst · 5d agoPhishing & fraud in the wild 2 sources

Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks

Unit 42 details 'Spring Ring', a vishing campaign using fake IT support on Microsoft Teams to reach 150+ employees at 10+ companies.

Palo Alto Networks Unit 42 documented 'Spring Ring', a voice-phishing campaign that ran January to April 2026, using 26 attacker identities and fake Microsoft 365 tenants such as 'ITProtectionDepartment' to impersonate internal IT support on Microsoft Teams. One path used Quick Assist or downloaded remote-support tools to run an obfuscated PowerShell script that disabled malware scanning before contacting C2; the other delivered a cloud-hosted file triggering browser hijacking, SMB internal network scanning, and a PetitPotam NTLM relay attempt against domain controllers to gain domain-level privileges. Both intrusion attempts were blocked before attackers reached their objectives. Collaboration-platform phishing alerts rose to 42% of Unit 42's telemetry in early 2026, up from 30%.

Help Net Security · 16d agoPhishing & fraud in the wild

AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes

SOCRadar details AnonyMousKIT, an active phishing-as-a-service platform using AI voice agents across 506 domains to steal Apple ID credentials from stolen iPhone owners.

SOCRadar analyzed AnonyMousKIT, a pay-per-action phishing-as-a-service platform built to harvest Apple ID credentials needed to remove Activation Lock from stolen iPhones. A bare-relative-paths flaw exposed a reseller supply chain of 506 domains and 168 storefront brands active since early 2024, plus 200 call logs and 55 transcripts, with 179 of 200 calls going to Brazil at a total cost of $19.24. Voice-agent personas like 'Alice Dias, Apple Support' convince victims to dictate their four- or six-digit passcode and enter an unlock code from a security link, allowing thieves to remove Activation Lock and resell devices. The platform ran five personas in English, Spanish, and Brazilian Portuguese and remained active at the end of the investigation.

Help Net Security · 22d agoPhishing & fraud