ZeroHour

Search: “data theft”

21 stories

Conti Ransomware Hacker Sentenced After Group Attacked Over 1,000 Victims Worldwide

Ukrainian national Oleksii Lytvynenko sentenced to four years in US prison for his role in Conti ransomware attacks on 1,000+ victims.

Oleksii Oleksiyovych Lytvynenko, 44, pleaded guilty to conspiracy to commit wire fraud for working as a developer and intruder in the Conti ransomware operation, coding a malware loader and handling data stolen from 12 victims. Conti compromised over 1,000 victims across 47 US states and 31 foreign countries between 2020 and 2022, generating more than $150 million in ransoms. He was arrested in County Cork, Ireland in July 2023 and extradited to the US. The sentencing is part of a wider US investigation into the Conti and TrickBot ecosystem.

Cyber Security Newsupdated · 5d agofirst · 6d agoPolicy & legal 7 sources

Risky Bulletin: The EU publishes its upcoming cybersecurity standards

ETSI releases 17 draft cybersecurity standards vendors must meet when the EU Cyber Resilience Act takes effect in December 2027.

The European Telecommunications Standards Institute published 17 interim draft standards covering operating systems, routers, firewalls, VPNs, SIEMs, browsers, password managers, smart home devices, toys and wearables. They mandate basic security features such as post-sale updates, shipped SBOMs, modern cryptography and secure-by-default settings; public comments run until November, with final versions expected in December, one year before CRA compliance begins in December 2027. The newsletter also reports Irregular taking responsibility for AI test-environment escapes involving Anthropic and Meta frontier models, a breach at France's tax agency exposing 678,000+ citizens' data claimed by hacker ZeroBytes, and Kazakhstan eGov data covering 15 million citizens listed for sale on an underground forum. Additional briefs cover a $3.2 million Harmony Protocol theft crashing the ONE token 40%, Columbus Police still restoring systems two years after ransomware, DDoS attacks on Threema's provider, and Ukraine's GUR claiming a cyberattack on Wildberries.

Risky Business News · Aug 17, 2026Policy & legal2

Russian national extradited to US for alleged involvement in bank-account takeover scheme

US extradited Russian national Sergei Filimonov over a bank-account takeover scheme using spoofed bank domains that defrauded two banks of $6.3 million.

US authorities extradited 36-year-old Russian national Sergei Anatolyevich Filimonov from the Republic of Georgia on charges including bank and wire fraud conspiracy and aggravated identity theft. He and unnamed co-conspirators allegedly ran spoofed bank domains, bought sponsored links to lure victims, and harvested over 5,000 victim login credentials starting in November 2023, causing unauthorized transfers of about $5.58 million and $735,000 from two banks in 2024. The FBI previously identified at least 19 US victims linked to the credential-storage domain, with roughly $28 million in attempted losses including $14.6 million confirmed. Filimonov faces up to 175 years in prison, pleaded not guilty on September 4, and remains detained in the Northern District of Georgia.

CyberScoop · 8d agoPolicy & legal

Jail time for Maine child in 764 marks turning point in federal law enforcement

A 17-year-old from Maine became the first minor federally adjudicated for 764 extremist crimes, including child exploitation, signaling a policy shift on prosecuting juveniles.

The FBI said a Maine teenager is the first child federally charged and adjudicated for crimes tied to the nihilistic violent extremist collective 764, part of The Com network. Charges include conspiracy to sexually exploit a child, distributing CSAM, interstate threats, cyberstalking, and identity theft. The case marks a turning point in federal policy on prosecuting juveniles and continues heightened enforcement: Kyle Spitze was sentenced to 77 years and Alexis Chavez to 40 years in related cases. The FBI is investigating more than 500 subjects connected to 764 and its offshoots nationwide.

CyberScoop · 14d agoPolicy & legal

FBI cyber chief worries private sector not sharing enough cyber threat information

FBI cyber chief Brett Leatherman urged companies to share breach information with the bureau as it publishes a victim-focused cyber strategy.

FBI Cyber Division assistant director Brett Leatherman said at the Billington CyberSecurity Summit that private-sector hesitancy to engage the FBI stems from misconceptions, including a belief that shared incident data is passed to regulators. He warned that organizations breached by PRC nation-state actors risk more by handling intrusions alone, since FBI involvement speeds eradication. The bureau published a new cyber strategy Wednesday emphasizing victim aid, adopting a 'share until it hurts' posture on releasing threat intelligence.

CyberScoop · 7d agoPolicy & legal

FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching

FBI officials said AI is accelerating adversary capabilities while its new cyber strategy emphasizes continuous patching, cyber hygiene, and AI-enabled defense.

At the Billington CyberSecurity Summit and ahead of a new FBI cyber strategy, deputy assistant director Jason Bilnoski said AI is boosting the speed and capability of both criminal and nation-state attackers, while stressing that basic controls like MFA would still prevent most attacks. Colleen Ferranti urged a shift from quarterly Patch Tuesday cycles to continuous, risk-based patching as AI accelerates vulnerability discovery. The strategy pledges AI-enabled triage, malware analysis, attribution support, agentic AI adoption, expanded Computer Network Operations, ICS Coordinators in every field office, and a pledge on victim relief and privacy.

CyberScoop · 8d agoPolicy & legal

CIA’s Michael Ellis says cyber intelligence is changing how the agency operates

CIA deputy director says cyber operations built the intelligence picture enabling US forces to capture Nicolás Maduro in Operation Absolute Resolve.

CIA Deputy Director Michael Ellis said at the Billington Cybersecurity Conference that cyber operations built the intelligence picture that let US special operations forces locate and apprehend Nicolás Maduro within four minutes of landing during Operation Absolute Resolve. He cited the elevation of the Center for Cyber Intelligence to a full mission center as key to aligning resources around the cyber mission. The agency also created a Directorate of Mission Systems and cut its technology acquisition cycle from two to three years to a six-month target, completing more than 400 purchases within that period. Ellis said AI brings unprecedented speed and scale to cyber operations and analysis.

CyberScoop · 8d agoPolicy & legal 2 sources

European parliament members call for slowdown of Serbia’s EU entry over spyware use

29 MEPs urge delaying Serbia's EU accession after researchers found Pegasus and NoviSpy spyware on student activists' phones.

Twenty-nine Members of the European Parliament sent a letter Friday demanding Serbia's EU accession be slowed until an investigation into its spyware use is completed. The letter follows a SHARE Foundation report, with Amnesty International and the Citizen Lab, documenting Pegasus and NoviSpy infections on Serbian student activists' phones; NoviSpy evidence pointed to Serbian government authorities, though Pegasus attribution was not assigned. The MEPs also urged European Commission President Ursula von der Leyen to cancel a planned visit to Serbia and called the surveillance 'a direct state attack on democracy' ahead of upcoming elections. The Serbian government did not respond to requests for comment.

CyberScoop · 12d agoPolicy & legal in the wild

The G7 tells industry to hurry up and prep for post-quantum encryption

A G7 working group report urges governments and industry to accelerate post-quantum cryptography migration, framing quantum risk as a near-term economic threat.

A cybersecurity working group formed at the June 2026 G7 Summit in France called on organizations to stop postponing migration of critical systems to post-quantum cryptography, warning that harvest-now-decrypt-later attacks against currently encrypted data exist today. The report was signed by CISA, the UK NCSC, France's ANSSI, Germany's BSI, Canada's CSE, Japan's NCO, and Italy's ACN. It also cautions that some NIST-selected PQC algorithms have already been broken on classical computers, reinforcing support for crypto-agility. The push aligns with a recent US executive order moving federal PQC migration timelines from 2035 to 2030, while Google and others target 2029.

CyberScoop · 13d agoPolicy & legal

FCC proposes public scorecard to rate telecoms on anti-robocall efforts

The FCC proposed a public scorecard rating telecoms' anti-robocall effectiveness and removed 14 providers from US networks for compliance failures.

The Federal Communications Commission issued a public notice proposing a scorecard that would assess how effectively retail voice providers, including wireless, wireline and VoIP, prevent illegal robocalls, drawing on Robocall Mitigation Database filings, consumer complaint and enforcement data. The agency stressed it is not a rulemaking imposing new requirements, and it is seeking comment on scope, such as whether to focus on larger providers. The same day, the FCC removed 14 providers from the Robocall Mitigation Database for non-compliance, effectively requiring other US providers to block their traffic within two days.

CyberScoop · 14d agoPolicy & legal

Wyden seeks upgraded NSA security guidance on commercial VPN use

Senator Ron Wyden asked the NSA to update public guidance on commercial VPN security risks and answer questions about foreign surveillance threats against single-hop VPNs.

Sen. Ron Wyden sent a letter to NSA Director Gen. Joshua Rudd urging the agency to revise public guidance on commercial VPNs, following earlier letters to federal agencies in March and July. He argues single-hop VPNs offer little protection against sophisticated adversaries able to compel or compromise the single provider, citing a Congressional Research Service paper favoring multi-hop and mixnet architectures. The letter references a September NSA advisory on a China-sponsored campaign against telecom, government and military networks and asks unclassified questions about multi-hop systems such as Apple Private Relay, Tor and Nym versus mixnets.

CyberScoop · 14d agoPolicy & legal

Ukraine moves to crack down on scam call centers after corruption scandal

Ukraine's parliament passed legislation criminalizing fraudulent call centers with 7-12 year prison terms after a bribery scandal implicating prosecutors.

Ukraine's Verkhovna Rada passed legislation making electronic-communications fraud and organizing or working for fraudulent call centers separate crimes punishable by 7-12 years, awaiting President Zelensky's signature. The bill advanced after NABU alleged prosecutors took bribes since mid-2025 to shield scam call centers; five suspects were named and Prosecutor General Ruslan Kravchenko, who denies wrongdoing, was dismissed by parliament and presidential decree. Ukrainian authorities previously reported 411 searches and 94 suspected call centers shut down in one week, including a Kyiv operation that stole over $500,000 from dozens of Americans.

The Record · 1d agoPolicy & legal

Australia charges two men for TeamPCP supply

Australia charged two Perth men over TeamPCP supply-chain attacks compromising 1,000+ organizations and exposing 500,000+ credentials.

The AFP charged two Perth-based men with a combined 14 offences for their alleged roles in TeamPCP, with payments in cryptocurrency for data intrusion, identity crime, and money laundering. The group's supply-chain attacks targeted developer tools including TanStack, Trivy, and LiteLLM, with downstream victims including the European Commission and GitHub. Investigators estimate the campaign compromised over 1,000 organizations, exposed more than 500,000 credentials, and led to theft of at least 300 GB of data, with remediation costs in the hundreds of millions of dollars. The men could face a combined 82 years if given maximum sentences, though sentences are typically served concurrently.

The Record · 21d agoPolicy & legal

Retail theft bill spurs ‘very large and very dangerous’ surveillance fears

The Combating Organized Retail Crime Act advances toward Senate attachment to the defense bill, drawing ACLU warnings of expanded ICE surveillance powers.

The Combating Organized Retail Crime Act (CORCA) passed the House 348-60 in June, and Senate supporters including Chuck Grassley are pushing to attach it to the annual defense policy bill. The bill would create an Organized Retail and Supply Chain Crime Coordination Center within ICE's Homeland Security Investigations, add criminal penalties for laundering stolen-goods proceeds with a $5,000 charging threshold, and broaden data sharing with retailers. The ACLU, NAACP LDF, and allied groups warn the vaguely drafted provisions would effectively grant DHS access to retail surveillance feeds such as cameras and license plate readers, while industry backers say it only enhances existing information sharing and could help fight cyber-enabled crime.

CyberScoop · 27d agoPolicy & legal1

Man Charged With 3 Felonies For Breaking 3D

Oviedo, Florida police charged a man with three felonies for cutting down an officer's 3D-printed decoy Flock surveillance camera.

After several real Flock Safety cameras were stolen in Oviedo between July 23 and August 3, 2026, police replaced them with 3D-printed decoys built by an officer at home and monitored the fakes. Evan Meyer was arrested after midnight and charged with attempted grand theft, criminal mischief over $1,000, and property crimes against computer equipment, despite the decoy costing only a few dollars of filament. Mayor Megan Sladek said she had no idea the sting was underway, and the department claims no records of the decoy's creation exist, citing an ongoing investigation.

404 Media · 22d agoPolicy & legal

Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands

US DoJ charged extradited Russian Searzhudin Aktulaev for a 2016-2017 Excel macro campaign infecting ~80,000 freelance platform users with TVRAT and DarkVNC.

Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025 and extradited to the US on August 28, facing charges including wire fraud conspiracy and aggravated identity theft. The indictment alleges ~255 fake freelance-platform accounts were used to send Excel macro attachments to about 80,000 users in 2016-2017, deploying TVRAT (TeamSpy/TVSPY) and DarkVNC RATs for remote access and data theft. Thousands of infected machines called back to a US-hosted C2 domain, with stolen credentials and PII stored in the shared email account used in the scheme.

The Hacker News · 15d agoPolicy & legal

Risky Bulletin: Dutch intel services to get extensive new powers

Netherlands proposed a bill granting AIVD and MIVD expanded warrantless tapping, faster hacking powers, and forced data disclosure, citing Russia, China, and Iran threats.

The Dutch government introduced a bill greatly expanding surveillance powers of intelligence agencies AIVD and MIVD, allowing up to one year of tapping without pre-approval and simplified hacking operations against 'foreign adversaries'. Agencies could compel Dutch companies or citizens to provide data under threat of charges, share data with the private sector, and oversight bodies would merge into a new CTT board. The bill follows similar overhauls in Ireland, Germany, and France after Russia's invasion of Ukraine. The newsletter also reports Moonwell hacked for $8.7M, a Cosmos EVM bug exploited for ~$3M, ShinyHunters listing McKesson with claimed hundreds of millions of records, and a pro-Kremlin DDoS claim against Norway's government network.

Risky Business News · 17d agoPolicy & legal

UK Government Enables Passkey Login for 23 Million Users to Fight Phishing Attacks

UK Government enables optional passkey login for GOV.UK One Login, offering 23 million users phishing-resistant FIDO authentication.

The UK government has rolled out passkey authentication for GOV.UK One Login, the single sign-on for services like tax, State Pension, and driver's license renewals, available to over 23 million users. Passkeys are device-bound, unlocked via fingerprint, Face ID, or device PIN, and the government reports they are up to eight times faster than password plus two-step verification. During the initial trial over 300,000 users adopted passkeys, with nearly one in ten daily sign-ins already using them, saving roughly £600 per day in SMS costs. The NCSC endorses passkeys as phishing-resistant credentials that cannot be intercepted or reused, and biometric data never leaves the user's device.

GBHackers · 2d agoPolicy & legal

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

U.S. Treasury sanctioned nearly 60 Iran-linked entities, including MOIS-affiliated Mabna Institute hackers behind breaches of U.S. critical infrastructure and millions in crypto theft.

The U.S. Treasury launched Operation Economic Outcast, designating nearly 60 Iran-linked entities, individuals, and vessels across nuclear, missile, oil, cyber, and digital asset networks. Five sanctioned individuals are members of the Tehran-based Mabna Institute indicted last week; three allegedly breached and exfiltrated data from U.S. energy, defense, healthcare, IT, and financial organizations since late 2023. TRM Labs traced roughly $16.8 million across 30 wallets tied to the members, and the State Department announced a reward of up to $10 million. The action follows Iranian hacking of FBI Director Kash Patel's email and attacks on over 30 U.S. water and wastewater utilities.

The Hacker News · 22d agoPolicy & legal in the wild

Grindr settles HIV status data-sharing lawsuit for $35 million

Grindr agreed to pay about $35 million to settle a UK privacy suit alleging it shared users' HIV status and sensitive data with advertisers without consent.

The claim, brought by London firm Austen Hays on behalf of roughly 12,000 UK users, alleges Grindr breached privacy and data-protection laws during a period ending in early 2020, when it was owned by Beijing Kunlun Tech. Shared data may have included ethnicity, HIV status, last HIV test date, and PrEP use. Per an SEC filing, Grindr will make two payments of £13 million (totaling about $35 million), one by December 31, 2026 and one by March 31, 2027, without admitting liability. The settlement follows a Norwegian Data Protection Authority enforcement finding over ad sharing without a valid legal basis.

Malwarebytes Labs · 9d agoPolicy & legal

Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute

US prosecutors unsealed a superseding indictment charging 17 Iranians in the Mabna Institute's state-sponsored theft of 31.5 terabytes from universities and companies.

The superseding indictment unsealed in the Southern District of New York charges 17 people affiliated with Tehran's Mabna Institute, adding eight defendants to the 2018 indictment of nine. The institute allegedly compromised over 100,000 professor email accounts worldwide, including 8,000 accounts at 144 US universities, and stole at least 31.5 terabytes of academic journals, dissertations, and e-books. US universities spent approximately $3.4 billion procuring the stolen data, and victims also included at least five federal and state agencies, 42 US companies, and 11 foreign companies including HBO. The State Department's Rewards for Justice program is offering up to $10 million for information on four of the defendants.

CyberScoop · 29d agoPolicy & legal