ZeroHour

Search: “Prince Group”

27 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

US, Britain to coordinate on scam center takedowns

The US and UK signed an MOU to jointly investigate Southeast Asian scam compounds behind fraud that stole over $12 billion from Americans last year.

The DOJ and UK's National Crime Agency and Crown Prosecutor signed a memorandum of understanding on Thursday for parallel investigations and information sharing on scam centers, largely run by Chinese gangs using human trafficking victims in compounds across Myanmar, Cambodia, and Laos. The Scam Center Strike Force, with more than 150 personnel from the FBI, IRS, and US Postal Inspection Service, leads the effort; the FBI says cyber-enabled fraud accounted for almost 85% of reported losses, with over $12 billion stolen from Americans last year. An in-person disruption event with private industry partners is planned in London in early October. The initiative follows sanctions on Prince Group and a roughly $15 billion bitcoin seizure linked to its CEO Chen Zhi.

The Record · 12d agoPolicy & legal

280,000 Impacted by Premier Medical Group Data Breach

New York healthcare provider Premier Medical Group is notifying 282,075 patients that personal and medical information was stolen in a June breach.

New York healthcare provider Premier Medical Group is notifying 282,075 patients whose personal and medical data was stolen in a June breach. Attackers accessed certain files on June 14 after some systems were disrupted, but PMG has not disclosed how the attack occurred or who was responsible. Exposed data includes names, contact information, dates of birth, treatment and diagnostic details, medication information, and health insurance details. PMG reported the incident to HHS, which added it to its public breach portal this week.

SecurityWeek · 13h agoData breach in the wild

U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto

US DOJ and Treasury disrupt Xinbi Guarantee Telegram scam marketplace, sanctioning it and freezing $52.8M in USDT across 52 wallets.

The DOJ seized Xinbi Guarantee's Telegram channels and cryptocurrency wallets while OFAC sanctioned the marketplace, freezing $52.8 million in USDT from 52 wallets and bringing the Scam Center Strike Force's total restrained funds to roughly $938 million. Elliptic, which worked with the Secret Service, estimates Xinbi has processed $30 billion in transactions since around 2022, serving pig-butchering scam operators and links to North Korean hackers, Jin Bei Group, and Prince Group TCO. The strike force dismantled 13 scam compounds in Madagascar, seizing over 3,200 devices and interviewing roughly 400 arrestees, with about 30 Chinese compound leaders repatriated to China. After Tether froze funds, Xinbi began converting remaining USDT into the USDD stablecoin.

The Hacker News · 7d agoPolicy & legal

PurpleDelta's Fraudulent Employment Operations

Recorded Future details North Korean cluster PurpleDelta using AI-generated personas and ChatGPT assistants to infiltrate companies via fraudulent employment.

Recorded Future profiles PurpleDelta, a North Korean IT worker threat cluster, in a new research report. The group uses AI-generated personas, sophisticated tradecraft, and custom ChatGPT assistants to obtain employment at target organizations and operate covertly. The report includes key indicators of compromise and recommended mitigation strategies for defenders.

Recorded Future · Aug 18, 2026Threat actor

ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

Microsoft warns of Teams IT-impersonation intrusions deploying Node.js implants; Spring Ring vishing hit 150+ employees across 10 companies; The Gentlemen ransomware claims 683 victims.

Microsoft warned of a human-operated campaign abusing Teams external collaboration to impersonate IT help desk staff, deploy malicious MSI packages staging Node.js runtimes and obfuscated JavaScript implants, then pivot to domain controllers over WinRM. Unit 42 documented the Spring Ring vishing operation targeting over 150 employees across at least 10 companies using 26 attacker identities, including an NTLM relay variant against domain controllers. Sophos reported The Gentlemen ransomware (Gold Sherwood) reached 683 total victims by end of July 2026, adding 169 in July, with a playbook using BYOVD-based EDR killers and backup tampering. Group-IB found the Outsider phishing-as-a-service platform created 700+ new phishing pages within a month despite law enforcement takedowns.

The Hacker News · 13d agoThreat actor in the wild1

Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports

Manchester Airports Group breach exposed email addresses, phone numbers and vehicle registrations of about 8.7 million customers across three UK airports.

Manchester Airports Group (MAG) disclosed that an unauthorized third party accessed customer data for roughly 8.7 million people across Manchester, London Stansted and East Midlands airports. Exposed data covers car park, lounge and fast-track bookings and Wi-Fi sign-ups, including email addresses, phone numbers, vehicle registration numbers and postcodes; no bank or payment details were stored and no flight operations were disrupted. MAG learned of the incident on August 25 after attackers breached the system over the weekend, contained it, hired external security experts and suspended its Manage My Booking service as a precaution. The breach lands during peak summer travel and adds pressure on UK infrastructure operators after recent incidents at Jaguar Land Rover, M&S, Harrods, Co-op and a UK power plant.

Security Affairs · 19d agoData breach

Risky Bulletin: Russia tells data centers to deploy drone defenses

Russia ordered data center operators to deploy drone strike defenses under a Putin decree allowing temporary state takeover of unprotected critical infrastructure.

The Russian government instructed data center operators to deploy protections against drone strikes under a presidential decree signed by Putin that allows temporary state administration of critical infrastructure operators failing to defend against Ukrainian hacks and drone strikes. Although data centers are not formally critical infrastructure in Russia, the decree applies to them because other sectors depend heavily on cloud services; Russia has more than 180 data centers, over 80% in the European region within range of Ukrainian strikes. The digest also reports a Dropbox breach affecting nearly 5,000 accounts via the Lenovo ID integration, spyware attacks on at least 14 Serbians using NoviSpy or Pegasus, and a password recovery attack targeting hundreds of thousands of X accounts tied to the new X Money service. Other items include a 14-hour compromise of Coder's Cloudflare infrastructure delivering malicious Terraform modules, donor data breaches at Davayte and You Are Not Alone via the Stripe/WooCommerce integration, a $2.5M Aquifer crypto heist, and a TVING breach exposing data of almost 40 million accounts.

Risky Business News · 12d agoPolicy & legal

Brand Impersonation Takedown: From Whack-a-Mole to Managed Response

Mandiant-tracked group UNC3753 impersonated US professional services firms' brands in 2026; Cyble urges managed takedowns over manual abuse reports.

Cyble describes how Google Mandiant-tracked group UNC3753 targeted US professional services firms between January and May 2026 using brand impersonation, spoofed domains, and fake executive profiles. Manual takedowns fail because phishing pages damage brands within hours while removal takes days. A managed takedown program with continuous monitoring and pre-authorized removal cuts the exposure window from days to hours.

Cyble · Aug 17, 2026Phishing & fraud in the wild

North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales

North Korea's IT worker scheme (Famous Chollima/PurpleDelta) has expanded from IT into healthcare, sales, and financial services roles worldwide.

Huntress and Recorded Future documented DPRK-linked fraudulent workers landing remote jobs beyond IT, including at an Australian healthcare company, a financial services firm, and a sales hire with a stolen identity. The scheme, tracked as Famous Chollima, Jasper Sleet, Nickel Tapestry, PurpleDelta, UNC5267, and Wagemole, uses forged identity documents, VPNs, proxies, and laptop farms with PiKVM and capture cards to fund Pyongyang's weapons programs. Recorded Future found the PurpleDelta cluster applied to 1,100+ companies between late 2024 and early 2025 with 22 fabricated personas, some AI-generated, using ChatGPT and AI transcription during interviews. Analysts assess the activity is ongoing and likely to expand in scale and sophistication.

The Hacker News · 15d agoThreat actor in the wild

Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group

Recorded Future details Tajin Group, a Chinese-speaking vendor on Telegram guarantee marketplaces running phishing, carding, and money laundering operations targeting Chinese banks.

Insikt Group analyzed Tajin Group, a Chinese-speaking threat actor operating on Telegram-based guarantee marketplaces Dabai Guarantee and, since May 2026, Xinbi Guarantee. The group conducts phishing, payment card theft, and money laundering targeting mainland Chinese citizens and banks, testing stolen cards from twelve countries on platforms like CCAvenue and Geidea. Operators bought and sold at least 100 Telegram usernames and anonymous virtual numbers via Fragment Market to strengthen OPSEC, linking multiple usernames to single Telegram accounts. Recorded Future warns Tajin Group's TTPs are likely to be replicated by other vendors on Chinese-language guarantee marketplaces at global scale.

Recorded Future · 2d agoThreat actor

Manchester Airports Group breached, millions of customers’ data stolen

Manchester Airports Group confirmed attackers stole customer booking and WiFi signup data affecting about 8.7 million customers across three UK airports.

Manchester Airports Group (MAG) confirmed an unauthorized third party obtained customer data tied to car park, lounge and Fast Track bookings and WiFi sign-ups at Manchester, Stansted and East Midlands airports. Stolen data includes email addresses, phone numbers, vehicle registrations and postcodes; no payment or banking details were held in the affected systems. UK media reported roughly 8.7 million customers affected. The Manage My Booking portal was disabled as a precaution, authorities were informed, and airport operations were not disrupted.

Help Net Security · 16d agoData breach in the wild

Love Electric Breach: 877,000 Driver Records Offered for $600

A forum seller is offering 877,000 driver records from UK EV salary-sacrifice broker Love Electric for $600; researchers found the sample looks authentic.

A seller named seraphims advertised 877,000 records from Love Electric Financial Services, an Edinburgh-based FCA-regulated EV salary sacrifice broker, for $600 in cryptocurrency. Ransomnews analysts verified a 999-row SQL Server export containing names, addresses, National Insurance numbers, and driving licence numbers, with internal relationships and licence-format checks consistent with genuine production data. The full record count remains unverified, and the company had not commented at publication; the breach highlights risks from third-party payroll-adjacent providers.

Security Affairs · 19d agoData breach

Grindr settles HIV status data-sharing lawsuit for $35 million

Grindr agreed to pay about $35 million to settle a UK privacy suit alleging it shared users' HIV status and sensitive data with advertisers without consent.

The claim, brought by London firm Austen Hays on behalf of roughly 12,000 UK users, alleges Grindr breached privacy and data-protection laws during a period ending in early 2020, when it was owned by Beijing Kunlun Tech. Shared data may have included ethnicity, HIV status, last HIV test date, and PrEP use. Per an SEC filing, Grindr will make two payments of £13 million (totaling about $35 million), one by December 31, 2026 and one by March 31, 2027, without admitting liability. The settlement follows a Norwegian Data Protection Authority enforcement finding over ad sharing without a valid legal basis.

Malwarebytes Labs · 8d agoPolicy & legal

Cybercrooks jet off with Manchester Airports Group customer data

Manchester Airports Group says cybercriminals took customer data affecting an estimated 8.7 million customers at the UK's largest airport operator.

The Register reports that Manchester Airports Group, the UK's largest airport operator, believes approximately 8.7 million customers were affected by a cyber incident. The attackers are described as cybercriminals, with data tied to bookings and Wi-Fi registrations at Manchester, Stansted and East Midlands airports. This report adds a scale estimate to the group's breach disclosure.

The Register · Security · 20d agoData breach in the wild

NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT

Unit 42 links NOKKI malware to North Korea's Reaper group, uncovering the Final1stspy dropper that deploys the DOGCALL RAT in politically motivated attacks.

Unit 42 analyzed the NOKKI malware family used in politically themed attacks against Russian and Cambodian speakers since July 2018. The researchers linked NOKKI to the Reaper group, publicly attributed to North Korea, whose custom DOGCALL RAT uses third-party hosting services to upload data and receive commands. A previously unreported family, Final1stspy, was found deploying DOGCALL, sharing a unique base64-to-hex deobfuscation routine with NOKKI droppers. Attacks used malicious Microsoft Word macros that download and execute payloads while opening decoy documents.

Palo Alto Unit 42 · Aug 17, 2026Malware

A Vinyl Bar in Shibuya is a startup from a former Spotify leader for making music apps

Former Spotify innovation head raises $5.5M pre-seed for A Vinyl Bar in Shibuya, a startup building playful music-creation apps with selective generative AI features.

A Vinyl Bar in Shibuya, founded by former Spotify head of innovation Máuhan M Zonoozy, raised a $5.5M pre-seed round from Mantis VC, SV Angel, Boxgroup, Quiet Capital and others. The startup ships small music-play apps including Speed Surfer, Usersound, Stacks, Drops, Sampler, and the iOS mixer app bop, plus a new prompt-based sound creation feature. Zonoozy says the company deliberately avoids infusing AI into every product, arguing human taste and participation become more valuable as AI-generated content grows abundant.

TechCrunch · AI · 2d agoAI industry 2 sources

Crooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Million People

FulcrumSec leaked about 550 GB of Manchester Airports Group data, exposing emails, phones and vehicle registrations of roughly 8.8 million people after a refused ransom.

Manchester Airports Group, operator of Manchester, London Stansted and East Midlands airports, confirmed a breach of a third-party database after extortion group FulcrumSec leaked roughly 550 GB of data. The exposed data includes about 8.8 million email addresses and phone numbers, 108,077 vehicle registration plates, 2.48 million purchases and 1.16 billion email events, with no payment-card data accessed. FulcrumSec claims it gained access using Iterable admin keys hardcoded in the frontend JavaScript of all three airport websites, a claim MAG has not confirmed. Have I Been Pwned added the incident to its breach database.

Security Affairs · 12d agoData breach

Korea raises data breach fines to 10% of revenue

South Korea's privacy regulator will impose fines up to 10% of revenue for data breaches leaking personal data of 10 million or more people.

South Korea's privacy regulator is sharply raising penalties for data breaches, with fines reaching 10% of a company's revenue. The higher fines take effect Friday for companies found to have leaked personal data of 10 million or more people through intent or gross negligence. The regulator aims to push companies to treat data protection as a preventive investment rather than a routine cost of doing business.

DataBreaches.net · 6d agoPolicy & legal

ICE Wants to Know Everyone Who Bought a Certain Green Beanie From REI in the Last 2 Years

DHS subpoenaed REI for all Minneapolis-area customers who bought a specific green beanie since 2024, part of an investigation into 39 ICE protest defendants.

Court filings allege Homeland Security Investigations agents subpoenaed REI in March for transaction records of all persons in the greater Minneapolis–St. Paul area who purchased a specific dark green beanie since 2024. The subpoena was one of 92 sent in a federal case against 39 people, including journalists, who attended an ICE protest at a church. Companies responded differently: T-Mobile handed over six months of a defendant's call and text logs, Google refused a request for YouTube viewers, Reddit withdrew after a First Amendment objection, and Meta pushed back on at least one summons. The 1509 customs summonses require no judicial oversight, and the total number issued under the Trump administration is unknown.

WIRED · Security · 12d agoPolicy & legal

31st August – Threat Intelligence Report

Manchester Airports Group disclosed a cyberattack exposing contact details of about 8.7 million customers across Manchester, Stansted, and East Midlands airports.

Manchester Airports Group, the UK operator of Manchester, London Stansted, and East Midlands airports, disclosed a cyberattack that exposed data belonging to roughly 8.7 million customers. Check Point's weekly threat intelligence bulletin reports the compromised information includes contact details. The disclosure appeared in Check Point's 31 August Threat Intelligence Report covering the week's top attacks and breaches.

Check Point Research · 16d agoData breach in the wild

North Korea-linked IT Workers Are Getting Hired Inside Western Companies

Huntress documented five DPRK-linked FAMOUS CHOLLIMA workers hired by Western companies in 2026 using fake identities, proxies and laptop farms.

Huntress published an investigation of five confirmed 2026 cases of North Korea-linked IT workers, tracked as FAMOUS CHOLLIMA, obtaining remote jobs at legitimate companies in IT, sales, marketing and healthcare. The workers use stolen or fabricated identity documents, VPNs and proxy services, and some were caught using PiKVM hardware-level control, travel routers and laptop farms to mask their true location. Detection relied on document forensics, behavioral anomalies and indicators like identical typo artifacts in electricity bills rather than network intrusions.

Security Affairs · 15d agoThreat actor in the wild

Grindr Settles UK Data Privacy Claims for £26m

Grindr will pay £26m ($35.2m) to settle UK group claims alleging unlawful sharing of sensitive data, including HIV status, before 2020, without admitting liability.

The settlement, reached on September 2 and disclosed to the US SEC, covers roughly 12,000 claimants represented by Austen Hays over the free app's 2016–2020 data practices when Grindr was owned by Chinese conglomerate Kunlun. Grindr will pay £13m by December 31, 2026 and £13m by March 31, 2027, and continues to dispute the allegations; the agreement contains no admission of liability. The claims concerned sharing HIV status, PrEP use, ethnicity, and sexual orientation data with analytics providers Apptimize and Localytics without adequate consent. Norway's data protection authority fined Grindr €6.5m in 2021, and the UK ICO reprimanded the company in July 2022.

Infosecurity Magazine · 8d agoPolicy & legal

Manchester Airports Group Hit by Cyber Incident

Manchester Airports Group disclosed that an unauthorized third party accessed customer data from bookings and airport Wi-Fi registrations.

Manchester Airports Group, which operates Manchester, Stansted and East Midlands airports, reported a cyber incident in which an unauthorized third party accessed customer data. Affected data is linked to bookings and airport Wi-Fi registrations. The number of affected customers was not stated in this report.

Infosecurity Magazine · 20d agoData breach in the wild

Researchers Link 'Jewelbug' Chinese APT to Hack-for-Hire Operations

Broadcom researchers link the Chinese APT group 'Jewelbug' to a lucrative crypto-fraud hack-for-hire operation.

Threat intelligence researchers at Broadcom reported that the known Chinese APT group tracked as Jewelbug may be connected to a profitable crypto fraud scheme. The findings suggest the group blends traditional espionage tradecraft with financially motivated hack-for-hire work. Victimology and operational scale were not detailed in the initial disclosure.

Infosecurity Magazine · Aug 14, 2026Threat actor

Only Half of UK Manufacturers Have a Cyber Incident Response Plan

Make UK survey finds only half of UK manufacturers have a cyber incident response plan; 30% report recent incidents.

A Make UK survey reveals major cyber resilience gaps across UK manufacturing. Only around half of UK manufacturers have a cyber incident response plan in place. Some 30% of manufacturers report experiencing a recent cyber incident.

Infosecurity Magazine · Aug 11, 2026Industry

FulcrumSec Claims Responsibility for Manchester Airport Group Breach

FulcrumSec leaked ~549GB of Manchester Airport Group data, claiming 8.7M customer profiles exposed via exposed Iterable admin keys.

FulcrumSec posted around 549GB of uncompressed stolen Manchester Airport Group (MAG) data on its leak site, claiming nearly 8.7 million customer profiles with email, name, phone, home town, postcode and residential IP. The group said initial access came from Iterable platform admin keys exposed in the root-domain JavaScript of the Manchester, Stansted and East Midlands airport websites. Allegedly stolen data also includes ~1.2 billion marketing events, 2.5 million bookings, 461,000 SMS records, 108,000 vehicle plates and ~191,000 future bookings. MAG has provided no update since August 27 and the claims remain unverified.

Infosecurity Magazine · 14d agoData breach