Suspected Black Axe gang leaders face cybercrime charges in the US
Five alleged Black Axe leaders extradited from South Africa to the US face wire fraud and money laundering charges over romance scams.
Perry Osagiede, Franklyn Osagiede, Osariemen Clement, Collins Otughwor, and Musa Mudashiru were extradited to the US on September 11, 2026, accused of running advance-fee and romance scams from Cape Town between 2011 and 2021. Victims were deceived via dating sites, aliases, and VoIP numbers, and coerced with threats to publish sensitive photos. The case follows Operation Jackal IV, which arrested 58 people across 22 countries; Black Axe is estimated to have 30,000 registered members.
Five alleged leaders of Black Axe’s operations in South Africa extradited to US
US extradited five alleged Black Axe Cape Town leaders from South Africa to face romance-scam wire fraud and money laundering charges.
The Justice Department announced five alleged leaders of Black Axe's South African wing, all Nigerian nationals, were extradited to the US over romance and advance-fee scams run from at least 2011 until their 2021 arrests in South Africa. Prosecutors say the group used fake identities and threatened to expose victims' sensitive photos, with charges including wire fraud, money laundering, and aggravated identity theft carrying up to 62 years. The extradition follows recent multi-country stings arresting dozens of Black Axe members, including 34 arrests in Spain.
What the 3M ChatGPT case reveals about AI governance
3M litigation shows ChatGPT prompts can become discoverable evidence, forcing enterprises to govern AI conversation records.
In the Watson Grinding explosion litigation, an engineering expert retained by 3M had used ChatGPT, and a surfaced prompt asked the system to 'show how 3M is 0% at fault'; after an off-record deposition demand, more than 350 pages of previously unproduced ChatGPT material were provided. The author argues AI interaction histories are becoming part of decision records and discovery material, a trend the American Bar Association has already examined. Enterprises are urged to manage retention, ownership, sharing, and deletion of AI conversation logs across tools like ChatGPT, Copilot, Claude, and Gemini.
Doctor Doom Thanked Seattle for All the Surveillance Cameras
Activist dressed as Doctor Doom urged Seattle's council to curb Axon and Flock surveillance after a committee voted to redirect $250,000 from CCTV expansion.
Clifford Cawthon, a policy advisor at the Washington State Department of Commerce, appeared at a Seattle Public Safety Committee meeting in costume as Doctor Doom to protest the city's expanding mass surveillance. He criticized Seattle PD's access to 62 cameras feeding an Axon real-time crime center that ingests CCTV, body camera, geolocation, ALPR, and dispatch data from vendors like Axon and Flock. His group Community Not Cameras submitted a petition with five demands, and a committee already voted to move $250,000 away from CCTV expansion pending full council approval.
Grindr settles HIV status data-sharing lawsuit for $35 million
Grindr agreed to pay about $35 million to settle a UK privacy suit alleging it shared users' HIV status and sensitive data with advertisers without consent.
The claim, brought by London firm Austen Hays on behalf of roughly 12,000 UK users, alleges Grindr breached privacy and data-protection laws during a period ending in early 2020, when it was owned by Beijing Kunlun Tech. Shared data may have included ethnicity, HIV status, last HIV test date, and PrEP use. Per an SEC filing, Grindr will make two payments of £13 million (totaling about $35 million), one by December 31, 2026 and one by March 31, 2027, without admitting liability. The settlement follows a Norwegian Data Protection Authority enforcement finding over ad sharing without a valid legal basis.
Lawmakers seek watchdog review of federal hacking of Americans
Sen. Wyden and Rep. Casar asked the GAO to review the federal government's use of spyware and hacking tools against Americans.
Sen. Ron Wyden and Rep. Greg Casar sent a letter to the Government Accountability Office requesting a review of federal law enforcement hacking operations, including spyware use, Rule 41 hacking powers, and acquisition of hacking tools. The letter cites ICE's confirmed work with spyware vendor Paragon and concerns about abuse of invasive surveillance capabilities. The lawmakers note the government publishes no annual reports on hacking operations unlike wiretaps.
Risky Bulletin: The EU publishes its upcoming cybersecurity standards
ETSI releases 17 draft cybersecurity standards vendors must meet when the EU Cyber Resilience Act takes effect in December 2027.
The European Telecommunications Standards Institute published 17 interim draft standards covering operating systems, routers, firewalls, VPNs, SIEMs, browsers, password managers, smart home devices, toys and wearables. They mandate basic security features such as post-sale updates, shipped SBOMs, modern cryptography and secure-by-default settings; public comments run until November, with final versions expected in December, one year before CRA compliance begins in December 2027. The newsletter also reports Irregular taking responsibility for AI test-environment escapes involving Anthropic and Meta frontier models, a breach at France's tax agency exposing 678,000+ citizens' data claimed by hacker ZeroBytes, and Kazakhstan eGov data covering 15 million citizens listed for sale on an underground forum. Additional briefs cover a $3.2 million Harmony Protocol theft crashing the ONE token 40%, Columbus Police still restoring systems two years after ransomware, DDoS attacks on Threema's provider, and Ukraine's GUR claiming a cyberattack on Wildberries.
Tech contractor for Brightly Software sentenced to 2 years in prison for insider attack
Cameron Curry sentenced to two years for stealing Brightly Software employee data and extorting the Siemens-owned firm for $7,540.92.
Cameron Nicholas Curry, a 27-year-old data analyst contractor at Siemens-owned Brightly Software, stole corporate and sensitive payroll data between August and December 2023 and sent more than 60 threatening emails to employees after his contract ended. He demanded roughly $2.5 million but received $7,540.92 in late January 2024, and was convicted of six counts of extortion in March. He was sentenced to two years in prison plus one year of supervised release, less than the 12-year maximum, after investigators traced him via operational security mistakes including a Coinbase account linked to family debit cards.