Tag: cybercrime

  • Army Soldier Sentenced for Telecom Data Theft and Extortion

    Army Soldier Sentenced for Telecom Data Theft and Extortion

    A U.S. Army soldier has been sentenced to 70 months in federal prison for hacking telecommunications companies and stealing call and text metadata linked to more than 100 million AT&T customers. Cameron John Wagenius, 22, was also ordered to pay $294,978 in restitution.

    Wagenius, who was stationed in South Korea, used the online alias “Kiberphant0m.” Prosecutors said he worked with alleged co-conspirators to access data held by companies using Snowflake’s cloud storage service, exploiting exposed credentials and accounts that lacked multi-factor authentication.

    In 2024, Wagenius claimed on cybercrime forums that he had stolen AT&T call and text records, including phone numbers, timestamps and call durations. He also allegedly targeted other telecommunications companies, including Verizon’s Push-to-Talk business, and threatened to release stolen data unless companies paid him.

    After his arrest, Wagenius pleaded guilty to charges in two federal cases. Prosecutors said he cooperated with investigators but also attempted, while awaiting sentencing, to identify vulnerabilities in Bureau of Prisons computer systems.

    The investigation involved the FBI, Army Criminal Investigation Division, U.S. Secret Service and Defense Criminal Investigative Service. Prosecutors said Wagenius was assisted by Kenneth Schuchman, who previously pleaded guilty to operating the Satori botnet. Two other defendants, Conor Riley Moucka and John Erin Binns, have also been linked to the Snowflake-related data thefts.

    According to the article, Wagenius also admitted to re-extorting victims and threatening to disclose national security information. The investigation and related prosecutions continue.

  • Federal Authorities Forfeit $372,583 in Iowa Business Email Scam Case

    Federal Authorities Forfeit $372,583 in Iowa Business Email Scam Case

    Federal authorities have obtained a court order forfeiting about $375,000 connected to a 2022 business email scam targeting an Iowa company.

    The U.S. District Court for the Northern District of Iowa issued the judgment Tuesday. Prosecutors said investigators traced the money to a Wells Fargo account held by Manuel and Ibrahim Hazim.

    In the scam, someone allegedly impersonated the company’s vendors and persuaded an employee to send payments to an account controlled by the fraudster. The company believed the requests were for legitimate invoices and transferred more than $800,000 in mid-2022. The money was then moved through several accounts to make it harder to track.

    Authorities seized $372,583.77 from the Hazims’ account. Checks deposited there referred to “Mack Truck,” “procurement” and “payment,” but investigators found no legitimate business activity connected to the deposits. The Hazims claimed they innocently owned the funds and said they came from a currency-exchange arrangement, but they did not submit the required sworn statements.

    U.S. Attorney Leif Olson said investigators found no evidence the Hazims owned or sold a Mack Truck or had conducted another legitimate transaction with the person who deposited the money.

    Olson urged people and businesses to check email addresses carefully, verify payment-change requests in person or by phone, and report suspected scams to their bank, law enforcement or the FBI’s Internet Crime Complaint Center. He said authorities would use available tools to identify scammers and recover stolen funds.

  • Chinese Hackers Target Latin America with “SparroWocky” Backdoor

    Chinese Hackers Target Latin America with “SparroWocky” Backdoor

    Alleged Chinese hackers are targeting Latin American government agencies with a new backdoor called “SparroWocky,” according to ESET researcher Alexandre Côté Cyr. Since August 2025, the campaign has affected countries including Guatemala, Honduras, Puerto Rico, Panama, Venezuela, Peru, and Argentina. This long-running operation, linked to the Chinese group FamousSparrow, is unusual because Chinese cyber espionage usually targets multiple regions simultaneously. ESET suggests the campaign aims to monitor U.S. influence in Latin America, especially as the U.S. under Trump has increased pressure on Chinese investments in the region. One Panama target involved in a dispute over ports is notable, as Trump has sought to challenge Chinese control of port operations and the Panama Canal.

    The malware, named SparroWocky after the “Jabberwocky” poem by Lewis Carroll, is sophisticated and designed to hinder analysis. It can exfiltrate files, take screenshots, and gather system info like IP addresses and usernames. The campaign has been active since at least 2019, initially targeting hotels before shifting focus to governments, trade groups, and international organizations. FamousSparrow, the group behind the campaign, has been linked to Salt Typhoon, a Chinese cyber espionage operation accused of breaching U.S. government and corporate targets.

  • Cybercriminal Group Demands $3 Million Ransom from Revolut After Stealing Data of Over 680 Customers

    Cybercriminal Group Demands $3 Million Ransom from Revolut After Stealing Data of Over 680 Customers

    A cybercriminal group known as iamnotavillain has issued a threatening ransom demand after allegedly stealing sensitive customer data from Revolut, a major digital banking platform. The group is demanding approximately $3 million worth of Monero (XMR) in cryptocurrency to prevent the sale of the stolen information.

    According to reports from Traders Union, the hackers claim to have compromised the accounts of at least 680 Revolut customers. The stolen data reportedly includes passports, driver’s licenses, identity verification images used for know-your-customer checks, and detailed transaction histories. The cybercriminals posted an online ultimatum, demanding the ransom payment to be made in 6,000 Monero, a privacy-focused cryptocurrency.

    The Financial Times reports that the hackers gained access by infiltrating an Italian government email system and then impersonating law enforcement officials over several months. During this period, they allegedly requested information on specific Revolut accounts. The group used blockchain analysis techniques to identify accounts with significant cryptocurrency holdings, making them high-value targets.

    A brief video screenshot provided to the Financial Times appears to show access to what seem to be Revolut documents matching the categories of stolen customer records. Revolut has not issued an official comment regarding the ransom demand. However, the company has assured affected customers that it is providing support and collaborating closely with law enforcement and regulatory agencies to address the breach.

    At this stage, there are no reports of negotiations taking place. The hackers have warned that if their demands are not met, the stolen data will be sold to other criminal groups, potentially leading to further misuse or fraud.

    Revolut, which serves approximately 80 million customers across more than 30 countries, recently achieved a valuation of $115 billion through a secondary share sale. The incident adds to the growing concerns over cybersecurity threats targeting financial services firms. Previously, reports indicated that attackers had begun publicly posting some of the stolen customer data and demanding ongoing payments, raising alarm over the security of digital banking platforms.

  • Hackers Using Stealthy Chrome and Edge Extensions to Steal Data from Brazilian Bank Users

    Hackers Using Stealthy Chrome and Edge Extensions to Steal Data from Brazilian Bank Users

    Elastic Security Labs reports that hackers are covertly force-installing malicious browser extensions in Chrome and Edge to steal passwords, cookies, and session data without user approval. The malware, linked to the KREMLIN bank toolkit, has launched at least seven campaigns targeting 12 Brazilian banks since May 2025.

    The infection begins when users open disguised JavaScript files resembling bank receipts or invoices. The malware then copies extensions into browser profiles, modifies security files, and tricks browsers into loading them as trusted. These extensions, such as AVSync, can steal cookies, keylog inputs, capture screenshots, intercept traffic, and manipulate web pages. Researchers temporarily disrupted over 1,500 infections by blocking a related domain, mostly affecting Brazilian banking customers.

    follow us on telegram for daily news

  • Former Bank Employee Sentenced to 10 Years for Stealing Over $1 Million from Elderly Customers

    Former Bank Employee Sentenced to 10 Years for Stealing Over $1 Million from Elderly Customers

    A former bank employee, Yue Cao, has been sentenced to 10 years in federal prison for stealing over $1 million from elderly customers. Cao, a keyBank analytics manager from 2015 to 2022, used his position to create fake emails, enroll victims in online banking without their knowledge, and transfer money into accounts he controlled. Victims, aged 90 to 103 across multiple states, were chosen for their age and unlikely reporting. The theft, totaling about $2 million, was uncovered after suspicious transfers at Charles Schwab, where Cao later worked. Cao, a Chinese national and permanent resident, faces deportation after his sentence.

Home
No KYC
News