ZeroHour

Search: “commerzbank”

28 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Investigation of banking hack leads to arrests in Europe, Brazil

German and Brazilian police arrested seven suspects over a 2023 hack that drained an estimated 30 million euros from German bank accounts.

Germany's BKA said three suspects were arrested in Europe and charged with fraud, while Brazil's federal police arrested four others and executed 21 search warrants under Operacao Klonen (Operation Clone). The November 2023 attack exploited a vulnerability at a payment provider and used cloned payment cards to make unauthorized withdrawals from German online banking users, draining an estimated 30 million euros (34.7 million dollars). Funds were laundered through Brazil and four European countries, and courts ordered seizure of assets worth more than 20 million dollars. Brazilian media identified the affected bank as Commerzbank, which said customers suffered no financial loss.

The Record · Aug 15, 2026Policy & legal in the wild

Hackers Expose Data of 1.2 Million Heights Finance Customers

Heights Finance is notifying over 1.2 million customers that hackers accessed a third-party cloud platform holding contact, bank and government ID data.

Heights Finance, a U.S. consumer lender, discovered unauthorized access on May 7, 2026 to a third-party cloud platform used to store customer data; its internal loan management systems and operations were not affected. Exposed data varies by person and may include contact details, financial and bank account information, government IDs and dates of birth for customers, loan applicants, inquirers, and former borrowers of Curo Management and related brands. The company is offering 24 months of free credit monitoring and identity protection; dark web monitoring found no evidence of publication and no threat actor has claimed responsibility.

Security Affairs · 28d agoData breach in the wild

A $25 template helped scammers build hundreds of phantom bank domains

Allure Security researchers found 838 live phantom bank sites sharing a $25 template, built to lend credibility to investment and romance scams.

Allure Security researchers discovered roughly 2,200 domains presenting invented banks, of which 1,095 returned working pages and 838 contained a shared phrase. 97% of those retained parts of the $25 Cuex front-end template and 94% ran Laravel, with a misspelled 'Curreny Charts' heading on 90% of sites. The sites presented login pages, session cookies, and anti-forgery tokens consistent with a fraud model where scam contacts direct victims to fake financial portals. A leftover 'Remedy bank' title and form submission to remedycodes[.]site linked some sites to already-flagged fraud infrastructure.

Help Net Security · 26d agoPhishing & fraud

More than 100,000 fake stores are out to steal your card details

Researchers uncovered DoppelCart, a network of roughly 119,000 cloned fake shops that harvest card details and one-time bank codes during checkout.

Researchers at German firm Nebty identified 118,787 .shop domains tied to cloned online stores, representing 2.72% of the TLD population examined and described as the largest publicly documented fake-shop network by domain count. The shops mimic more than 44,000 brands, advertise discounts up to 65%, and 96% of confirmed shops reportedly share identical build files using just 27 ecommerce backends. Fraudulent checkout pages send card numbers, CVVs, billing data and bank one-time confirmation codes to attacker-controlled servers in real time over WebSockets, allowing criminals to complete payments while victims are still checking out.

Malwarebytes Labs · 7d agoPhishing & fraud

X Money rollout linked to password-reset attacks

X is investigating bulk unsolicited password-reset emails as its X Money payments service expands, with no confirmed breaches or account takeovers yet.

X users began reporting unexpected password-reset emails and codes on September 1, and product engineer Mridul Singhai said attackers appear to believe newly widespread X Money access makes accounts worth targeting. X says it has found no evidence of any breach or successful account takeover, and completing a reset still requires access to the account's email or phone number. X Money offers eligible US users interest-bearing accounts, a Visa debit card, and P2P payments, with Cross River Bank providing banking infrastructure. Malwarebytes warns the reset flood can serve as cover for phishing and urges reset protection, 2FA, and unique passwords.

Malwarebytes Labs · 12d agoPhishing & fraud in the wild

KREMLIN Banking Malware Bypasses Chrome Security to Steal Banking Sessions

Elastic Security Labs details KREMLIN, a Brazilian banking malware that implants malicious Chrome and Edge extensions by forging Chromium integrity values to steal banking sessions.

Elastic Security Labs tracks the KREMLIN banking malware operation as REF9334, active since at least May 2025 across seven campaigns primarily targeting 12 Brazilian banks. The malware is installed by a victim-run JavaScript loader, achieves scheduled-task persistence, and side-loads a malicious DLL via SentinelOne's SentinelMemoryScanner.exe. It modifies Chrome and Edge Secure Preferences files, enables developer mode, and regenerates Chromium MAC values to silently install extensions, while extracting browser encryption material including the newer App-Bound OSCrypt key. An Ethereum smart contract serves as a dead-drop resolver for C2 config; Elastic disrupted over 1,500 infections via a canary domain.

GBHackers · 12h agoMalware in the wild 2 sources

DoppelCart fraud network uses 119,000 fake shops to steal credit cards

DoppelCart, the largest documented fake-shop network, runs 119,000 domains impersonating 44,182 brands to steal payment card details via WebSocket-connected checkout pages.

German cybersecurity startup Nebty discovered DoppelCart, a network of more than 119,000 fake e-commerce domains, mostly in the .SHOP TLD, that harvest payment card details through fraudulent checkout pages. Over 105,000 shops remain active, impersonating 44,182 brands with discounts of up to 65%, and 96% of confirmed shops share identical build files resolving to 27 commerce backends. Checkout code exfiltrates card numbers, expiration dates, CVVs, cardholder names, contact details, and even bank one-time codes to attacker C2 over WebSockets in real time, potentially bypassing bank security controls. The network surpasses BogusBazaar, the previously largest documented fake-shop cluster with 75,000 sites and an estimated 850,000 fraudulent transactions.

BleepingComputer · 7d agoPhishing & fraud

Personal, Financial Info Exposed in Revolut Data Breach

Revolut says a scammer using a legitimate government agency email domain obtained affected users' PII, ID copies, selfies and full financial records.

Revolut, a London-based neobank serving over 80 million users in 160 countries, notified affected users that personal and financial data was exposed to a third party posing as a government agency. Exposed data included names, addresses, dates of birth, driver's licenses, passports, verification selfies, IBANs, account statements, withdrawal records and full transaction history including Bitcoin. Revolut blocked the attacker's email and notified the relevant agency, regulators and law enforcement, but did not disclose how many individuals were impacted.

SecurityWeek · 2d agoData breach

US disrupts Xinbi Guarantee marketplace fueling the cyber scam economy

US Treasury sanctions and DOJ seizures take down Xinbi Guarantee, a Telegram marketplace that processed $24B+ for cyber scams, freezing $52.8M.

The Treasury Department sanctioned the Chinese-language Telegram marketplace Xinbi Guarantee and two supporting firms, Anwen Technology (XinbiPay) and SafeW Technology, while the DOJ seized its Telegram channels and $52.8 million in USDT from 52 wallets. Blockchain intelligence firm Elliptic, which assisted the Secret Service, estimates Xinbi has processed at least $24 billion in transactions since 2022, making it the second-largest illicit online marketplace and a cornerstone of Southeast Asian cybercrime. Vendors sold money laundering, stolen personal data, deepfake technology, and other services for pig-butchering scams, with payments in Tether's USDT. The DOJ's Scam Center Task Force also dismantled 13 scam centers in Madagascar, arresting dozens of alleged leaders who were repatriated to China.

The Recordupdated · 5d agofirst · 6d agoPolicy & legal 4 sources

Russian suspect in bank account takeovers is extradited to US

Russian web developer Sergei Filimonov was extradited from Georgia to the US to face charges in a multimillion-dollar bank account takeover fraud.

Sergei Anatolyevich Filimonov, 36, appeared in an Atlanta federal court on September 4 and pleaded not guilty to bank fraud, wire fraud, access device fraud, and aggravated identity theft charges. Prosecutors say that from November 2023 to October 2025 his group bought sponsored search-engine links that diverted online banking customers to spoofed login pages, stole their credentials, and initiated unauthorized wire transfers. The FBI linked the scheme to the December 2025 seizure of the domain web3adspanels.org, identifying at least 19 victims, roughly $14.6 million in confirmed losses, and about $28 million in attempted losses.

The Record · 7d agoPolicy & legal

E-Commerce Access, Vedicline Data, Langflow RCE, ASUS Claim, and Energy Shell Access

SOCRadar reports underground posts claiming a Bangladeshi e-commerce database, Vedicline data leak, Langflow RCE, ASUS breach, and energy-sector shell access.

SOCRadar's Dark Web Team identified several new underground posts, including an alleged Bangladeshi e-commerce customer database offered for sale. The roundup also covers a claimed Vedicline data leak, Langflow remote code execution, an ASUS breach claim, and energy-sector shell access sales. Details on record counts and victims were not provided in the excerpt.

SOCRadar · 9d agoData breach

Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group

Recorded Future details Tajin Group, a Chinese-speaking vendor on Telegram guarantee marketplaces running phishing, carding, and money laundering operations targeting Chinese banks.

Insikt Group analyzed Tajin Group, a Chinese-speaking threat actor operating on Telegram-based guarantee marketplaces Dabai Guarantee and, since May 2026, Xinbi Guarantee. The group conducts phishing, payment card theft, and money laundering targeting mainland Chinese citizens and banks, testing stolen cards from twelve countries on platforms like CCAvenue and Geidea. Operators bought and sold at least 100 Telegram usernames and anonymous virtual numbers via Fragment Market to strengthen OPSEC, linking multiple usernames to single Telegram accounts. Recorded Future warns Tajin Group's TTPs are likely to be replicated by other vendors on Chinese-language guarantee marketplaces at global scale.

Recorded Future · 1d agoThreat actor

Wzmacniamy w Polsce ochronę przed oszustwami

Meta announces expanded anti-scam protections in Poland, citing rising fraud across dating apps, crypto platforms, online games and SMS messaging.

Meta says it is investing in new technologies and partnerships to better detect and fight scam content across its platforms in Poland. The company notes scam activity spans social platforms, dating apps, online games, cryptocurrency services and SMS messages. It also claims a recent campaign is distorting the picture of Meta's actions and motivations.

Meta Newsroom · 19d agoPhishing & fraud

ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries

Zimperium documents ToxicPanda 2.0, an Android banking trojan now targeting 349 financial institutions in 16 countries via ADB privilege escalation and overlay credential theft.

Zimperium's zLabs documented ToxicPanda 2.0, an Android banking trojan expanding from 16 targeted apps to 349 financial institutions across 16 countries, with 167 remote commands. It poses as a dropper, abuses VPN permissions to block Google Play Protect while installing a hidden payload, then uses the Accessibility Service for screen monitoring and overlay-based credential theft. It automates enabling Android Wireless Debugging and completes the pairing handshake to gain ADB shell access for privilege escalation, and overlays fake lock screens to steal device PINs. Previously unfinished commands are now operational and samples are served from AWS-hosted storage buckets.

Security Affairs · 25d agoMalware in the wild

Risky Bulletin: BEC campaign steals €35 million from French notaries

Hackers stole over €35 million from 500+ French notary offices in a four-year BEC campaign; ANSSI spent two years helping evict the attackers.

A business email compromise campaign breached more than 500 French notary offices — about 7% of all French notaries per the Conseil Supérieur du Notariat — over four years, stealing more than €35 million by phishing initial access and silently modifying wire transfer details. France's cybersecurity agency ANSSI worked for two years behind the scenes to help notaries remove the persistent attackers, who had deep access; officials also feared hackers could issue fake notarized acts such as marriage certificates or forged real estate deals. No forged documents have been found so far, but notaries have added two-factor authentication and in-person requirements for banking details, and banks added extra checks in 2024. The newsletter also notes other incidents, including a $320 million Bitcoin extraction from Blockstream's Liquid Network and a JetBrains Cadence breach via TeamCity servers.

Risky Business News · 9d agoPhishing & fraud in the wild1

Fake bank websites play dead to evade security scanners

Fortra uncovered Chameleon SEO Poisoning: cloaked typosquat bank sites rank on Google and Bing to steal credentials while evading scanners, with cases up 40% in Q2 2026.

Fortra's threat intelligence unit FIRE spent three months tracking Chameleon SEO Poisoning, a phishing method that ranks recently registered typosquat domains on second-level domains like .ph.com and .gr.com above legitimate bank sites on Google and Bing. The technique uses presentation control (cloaking by referrer): direct visits get a dead, offline-looking page, while search-referred clicks receive a convincing fake bank login page, letting poisoned results persist for days or weeks. Fortra recorded a 40% jump in cases during the second quarter of 2026 and recommends referrer-spoofed URL testing, faster SLD takedowns, and bookmarking bank logins.

Help Net Security · 23d agoPhishing & fraud in the wild

Trezor customers hit with phishing calls and letters after shipping-partner breach

A breach at shipping partner ShipMonk exposed data for about 67,000 additional US Trezor customers, who now face phishing calls and QR scam letters.

SatoshiLabs, maker of Trezor hardware wallets, confirmed the August 2026 ShipMonk breach exposed names, emails, phone numbers, and shipping addresses for roughly 67,000 US customers who ordered between November 2019 and August 2021, on top of 3,889 customers affected initially. ShipMonk attributed the intrusion to attackers exploiting an SQLi zero-day in Metabase's Cloud SaaS platform and retained data past the 90-day deletion requirement. Trezor's own systems were not compromised; customers are reporting phishing calls and QR-code phishing delivered via physical letters.

Help Net Security · 8d agoData breach

X says attackers are targeting user accounts after the launch of X Money

X is investigating a wave of unsolicited password reset emails targeting users after the X Money payments launch, with no confirmed breaches yet.

Numerous X users reported unsolicited password reset emails following the launch of X Money, the platform's new payments service with accounts held at FDIC-insured Cross River Bank. Product engineer Mridul Singhai said the company found no evidence of successful breaches or mass account takeovers, while the Grok chatbot confirmed attackers are mass-triggering resets using public usernames. Users are being advised to enable two-factor authentication and Password Reset Protect while the investigation continues.

TechCrunch · Security · 14d agoPhishing & fraud in the wild

Updated ToxicPanda Variant Targets 140+ Banking and Crypto Apps

Zimperium reports ToxicPanda 2.0, an updated Android banking trojan now targeting more than 140 banking and cryptocurrency apps.

Zimperium has published analysis of ToxicPanda 2.0, an updated Android banking trojan variant. The new variant expands its target list to over 140 banking and cryptocurrency applications. The report lifts the lid on the updated capabilities of the mobile malware family.

Infosecurity Magazine · 27d agoMalware

Nearly 750k had financial info, SSNs leaked in South Carolina loan company breach

Heights Finance breach of a third-party cloud platform exposed SSNs and banking data of 734,828 loan customers across 11 states.

Attackers breached a third-party cloud platform used by Heights Finance in May, exposing data on 734,828 customers, according to the company's filing with Texas regulators. Stolen data includes contact details, bank account and routing numbers, Social Security numbers, tax IDs and driver's license numbers. The breach, discovered on May 7, was limited to the cloud platform and did not affect loan management systems. No group has claimed the attack and dark web monitoring has found no evidence of the data being leaked.

The Record · 29d agoData breach

Panic builds over bankrupt Spirit’s looming data sale to Google

Startups object to Google's bankruptcy-auction purchase of Spirit Airlines operational data, claiming proprietary IP is being sold without consent.

Google won an auction to acquire a large enterprise dataset from bankrupt Spirit Airlines, which it says will help improve its products and AI models, with no personal information included. Springshot, whose airline logistics platform powered Spirit's stack, filed a limited objection arguing the vaguely defined data categories could transfer third-party IP and trade secrets it owns; International Aero Engines filed a similar objection. The EFF called it the first public bankruptcy proceeding over selling company and employee data as an asset, and objectors warn of a precedent letting large companies acquire startup IP through bankruptcy courts.

Ars Technica · AI · 5d agoAI industry

MFA's Weakest Link: Account Recovery Is the New Attack Path

Help desk account recovery is increasingly the weakest link in MFA-protected identities, as Scattered Spider's impersonation-driven Marks & Spencer attack demonstrated.

As MFA, conditional access, and phishing-resistant factors raise the cost of direct account takeover, attackers increasingly target the recovery process, convincing service desk staff to reset passwords or re-register MFA on attacker-controlled devices. CISA, FBI, and partner advisories describe Scattered Spider posing as employees to trigger such resets; the 2025 Marks & Spencer attack began this way and led to ransomware with an estimated £300 million profit impact. Microsoft now describes Entra ID account recovery as a high-assurance process, and the article promotes Specops Secure Service Desk for verified identity workflows.

BleepingComputer · 7d agoPhishing & fraud