ZeroHour

Source: DataBreaches.net

13 stories in the last 30d

Members of ‘Black Axe’ cybercriminal group extradited from South Africa

Five alleged Black Axe members extradited from South Africa face US charges over romance scams defrauding more than 100 victims.

Five alleged members of the Black Axe cybercriminal organization were extradited from South Africa and will make their first US court appearance Monday. Prosecutors unsealed a 2021 indictment accusing them of running romance scams that stole thousands of dollars from more than 100 people. Named defendants include Perry Osagiede and Franklyn Edosa Osagiede.

Delaware Consumer Privacy and Data-Breach Law Updates

Delaware's governor signed HB 380 and HB 381 amending the state privacy act and breach notification law.

On September 2, 2026, Delaware's Governor signed House Bill 380 and HB 381. HB 380 amends the Delaware Personal Data Privacy Act (DPDPA), enacted in 2023 and effective January 1, 2025. HB 381 separately amends Delaware's computer security breach notification law. Joseph J. Lazzarotti of JacksonLewis summarizes the changes.

DataBreaches.net · 2d agoPolicy & legal

AT&T store worker gets 16 months inside for SIM-swap side hustle

Former AT&T store worker Kenneth Carter sentenced to 16 months for SIM-swapping customers for cybercriminals.

Kenneth Carter, 44, a former AT&T retail employee in Portland, Oregon, used his internal system access to perform SIM swaps on customers' phone numbers for cybercriminals. The swaps allowed criminals to intercept authentication codes and raid victims' bank accounts. Carter was sentenced to 16 months in federal prison.

DataBreaches.net · 2d agoPolicy & legal1· 1 read

NYS DFS Issues New Cybersecurity Guidance on Risk Assessments for Financial Services Entities

New York DFS issued cybersecurity guidance defining expectations for risk assessments that regulated financial services entities must conduct.

On September 10, 2026, NYS DFS Acting Superintendent Kaitlin Asrow issued new cybersecurity guidance on conducting risk assessments sufficient to inform cybersecurity programs. The guidance covers scope, frequency, and the role of assessments for DFS-regulated financial services entities. It does not describe any incident or vulnerability, but sets regulatory compliance expectations under DFS cybersecurity rules.

DataBreaches.net · 3d agoPolicy & legal

TX: Two Lamesa ISD employees arrested over security breach

Two Lamesa ISD employees in Texas were arrested over an alleged computer security breach investigated with the Texas Rangers.

Lamesa Independent School District announced that two employees were arrested in connection with a law enforcement investigation involving allegations of a breach of computer security. The Lamesa Police Department said the arrests were carried out alongside the Texas Rangers. The district has not disclosed the nature, scope, or impact of the alleged breach.

DataBreaches.net · 4d agoPolicy & legal1

Ukrainian National Sentenced to Four Years in Prison for Wire Fraud Conspiracy in Connection with Conti Ransomware

Ukrainian national Oleksii Lytvynenko sentenced to four years for wire fraud conspiracy deploying Conti ransomware that infected over 1,000 computers.

Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian national, was sentenced to four years in prison for conspiracy to commit wire fraud related to deploying the Conti ransomware variant. The US Department of Justice said the conspiracy infected the computers of more than 1,000 victims. The sentencing is an update to a previously reported case.

DataBreaches.net · 4d agoPolicy & legal 7 sources

FTC Withdraws Obsolete Policy Statement

The FTC rescinded its 2021 policy statement that applied the Health Breach Notification Rule to health apps and connected devices collecting consumer health data.

The Federal Trade Commission formally rescinded its 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices. The statement had purported to apply the FTC's Health Breach Notification Rule to health apps and connected devices that collect consumer health information. The Commission considers the statement obsolete following its 2024 update to the Health Breach Notification Rule.

DataBreaches.net · 5d agoPolicy & legal 2 sources

Korea raises data breach fines to 10% of revenue

South Korea's privacy regulator will impose fines up to 10% of revenue for data breaches leaking personal data of 10 million or more people.

South Korea's privacy regulator is sharply raising penalties for data breaches, with fines reaching 10% of a company's revenue. The higher fines take effect Friday for companies found to have leaked personal data of 10 million or more people through intent or gross negligence. The regulator aims to push companies to treat data protection as a preventive investment rather than a routine cost of doing business.

DataBreaches.net · 5d agoPolicy & legal

Russian suspect in bank account takeovers is extradited to US

Russian developer Sergei Filimonov was extradited to the U.S. and pleaded not guilty to multimillion-dollar bank account takeover fraud.

Sergei Anatolyevich Filimonov, a 36-year-old Russian web developer, has been extradited to the United States to face an indictment in a multimillion-dollar bank account takeover scheme. He appeared in Atlanta federal court on September 4 and pleaded not guilty to fraud charges. Federal authorities announced the extradition on Tuesday.

DataBreaches.net · 6d agoPolicy & legal1

Singaporean Ringleader of $245 Million Cryptocurrency Racketeering Enterprise Pleads Guilty in Washington D.C.

Singaporean Malone Lam pleaded guilty in Washington D.C. to leading a social-engineering conspiracy that stole and laundered over $245 million in cryptocurrency.

Malone Lam, a 22-year-old Singaporean citizen residing in Miami, pleaded guilty in U.S. District Court in Washington D.C. for his role as ringleader of an international cybercrime conspiracy. The group used social engineering to steal cryptocurrency valued at more than $245 million and launder the proceeds. U.S. Attorney Jeanine announced the plea, which marks a major milestone in the prosecution of the crypto theft ring.

DataBreaches.net · 7d agoPolicy & legal

Party’s over for scammers who went on spending spree after $240M bitcoin theft

AP report on scammers' spending spree after a $240 million bitcoin social engineering theft, as ringleader Malone Lam nears a plea agreement.

DataBreaches.net syndicates AP reporting on the $240 million bitcoin theft from a Washington, D.C. resident via social engineering calls impersonating Google and Gemini. Alleged ringleader Malone Lam, 22, faces a plea hearing; the scam network spent stolen funds on cars, jets, and mansions before FBI arrests. Crypto investment fraud complaints to the FBI rose nearly 50% in 2025.

DataBreaches.net · 7d agoPolicy & legal

Japan’s Health Ministry to Strengthen Cybersecurity Measures at Hospitals

Japan's Health Ministry requested ¥13.7 billion for fiscal 2027 to strengthen hospital cybersecurity with network protections and dedicated specialists amid rising attacks.

Japan's Health, Labor and Welfare Ministry included ¥13.7 billion in its fiscal 2027 budget request to strengthen cybersecurity at hospitals. The measures aim to protect hospital networks and deploy cybersecurity specialists, responding to a surge in cyberattacks on medical institutions. The plan was reported by The Yomiuri Shimbun.

DataBreaches.net · 8d agoPolicy & legal

NYS Comptroller DiNapoli releases more municipal cybersecurity audits

NY Comptroller DiNapoli released municipal audits including three cybersecurity reviews covering local government controls.

New York State Comptroller Thomas DiNapoli released a batch of municipal audits, three of which address cybersecurity practices in local governments. The public excerpts include the Town of Wilton cybersecurity audit (2026M-48), covering January 1, 2024 through August 8, 2025, for a workforce of 56 full-time and 13 part-time employees.

DataBreaches.net · 9d agoPolicy & legal