Network Abuses Leveraging High-Profile Events: Suspicious Domain Registrations and Other Scams
Unit 42 found scammers surge deceptive domain registrations around major events like the 2024 Paris Olympics to run phishing and counterfeit merchandise scams.
Unit 42 analyzed newly registered domains (over 200,000 detected daily from zone files, WHOIS, and passive DNS) containing event-specific keywords, using the 2024 Paris Summer Olympics as a case study. Threat actors register lookalike domains to sell counterfeit merchandise, push fraudulent services, and run phishing, as previously seen with COVID-19-themed and fake ChatGPT tool scams. The article recommends monitoring domain registrations, DNS and URL traffic trends, textual patterns, and verdict change requests to catch event-themed abuse early.
Tech contractor for Brightly Software sentenced to 2 years in prison for insider attack
Cameron Curry sentenced to two years for stealing Brightly Software employee data and extorting the Siemens-owned firm for $7,540.92.
Cameron Nicholas Curry, a 27-year-old data analyst contractor at Siemens-owned Brightly Software, stole corporate and sensitive payroll data between August and December 2023 and sent more than 60 threatening emails to employees after his contract ended. He demanded roughly $2.5 million but received $7,540.92 in late January 2024, and was convicted of six counts of extortion in March. He was sentenced to two years in prison plus one year of supervised release, less than the 12-year maximum, after investigators traced him via operational security mistakes including a Coinbase account linked to family debit cards.