FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

Commerzbank $30M Supply Chain Fraud via Service Provider Exploitation

In November 2023, an international cybercrime syndicate executed a four-day fraud campaign resulting in a $30 million loss for Commerzbank customers. The attackers bypassed primary banking controls by exploiting vulnerabilities—specifically API insecurities or broken access controls—within a trusted third-party service provider's infrastructure. By pivoting from the service provider to the banking transaction layer, the syndicate implemented rapid-fire withdrawal logic to exfiltrate funds within a 96-hour window. The campaign culminated in "Operation First Light," a coordinated effort by the BKA, Brazilian Federal Police, and Interpol, leading to seven arrests across Germany and Brazil.

Operation Vajra: Dismantling the Mule Account Ecosystem in Uttar Pradesh

Law enforcement agencies, led by the Rae Bareli Police and Uttar Pradesh's "Operation Vajra," have executed a coordinated crackdown on the financial infrastructure supporting regional cyber fraud syndicates. The operation targeted the "mule account" ecosystem, where illicitly obtained or fraudulently opened bank accounts are utilized to layer and launder stolen funds. By analyzing digital transaction logs, payment gateway trails, and mobile device forensics—specifically investigating recruitment via encrypted messaging apps like WhatsApp and Telegram—authorities have identified 1,240 mule accounts and frozen approximately ₹1.98 crore in assets. This action addresses the critical financial pipeline used by threat actors to obscure the movement of proceeds from cybercrime.

Dismantling the Kratos Phishing-as-a-Service Infrastructure Targeting Microsoft

A multinational law enforcement operation led by Germany's BKA and ZIT, in coordination with the US and Indonesia, has neutralized the Kratos (aka SneakyLog/Sneaky 2FA) Phishing-as-a-Service (PhaaS) infrastructure. The operation resulted in the seizure of over 200 servers and the arrest of a primary administrator in Indonesia. Kratos leveraged Adversary-in-the-Middle (AiTM) proxying to intercept Microsoft 365 authentication flows, enabling the theft of session tokens to bypass multi-factor authentication (MFA). While the backend infrastructure is offline, approximately 1,800 active affiliates retain access to target lists and may migrate to alternative PhaaS kits, maintaining the operational threat level.

The Dismantling of SniperDz Phishing-as-a-Service PhaaS Infrastructure

Operation Ramz, a coordinated international law enforcement initiative, successfully dismantled SniperDz, a prolific Phishing-as-a-Service (PhaaS) platform that maintained operational longevity for approximately one decade. Conducted between October 2025 and February 2026, the operation targeted the platform's core infrastructure and its extensive affiliate network across the Middle East and North Africa (MENA) region. The campaign resulted in the arrest of the primary developer and administrator, "Guedz," along with 201 affiliates. This takedown neutralizes a significant source of scalable phishing payloads and credential harvesting capabilities that have historically facilitated widespread identity theft and financial fraud.

Extradition of Alleged Scattered Spider Member Peter Stokes

The extradition of 19-year-old Peter Stokes from Finland to the United States marks a significant law enforcement milestone against the Scattered Spider threat actor group. Stokes, a dual U.S. and Estonian citizen, faces charges of conspiracy, computer intrusion, and fraud in the Northern District of Illinois. The group is recognized for advanced social engineering, identity theft, and unauthorized system access through fraudulent authentication bypasses. This apprehension demonstrates the increasing efficacy of international judicial cooperation in targeting digitally native operatives who exploit transnational boundaries to facilitate high-impact intrusion campaigns against enterprise environments.

US DOJ Charges Russian National Denis Obrezko for Facilitating Large-Scale Ransomware Operations

The U.S. Department of Justice has charged Denis Obrezko, a Russian national extradited from Thailand, for providing critical infrastructure to Russia-aligned ransomware syndicates. Obrezko allegedly managed Command and Control (C2) servers, proxy networks, and access brokerage tools used to compromise U.S. corporate entities, including industrial targets like Westinghouse. By facilitating initial access and maintaining persistence via specialized infrastructure, Obrezko enabled the deployment of ransomware strains and the subsequent extortion of victims via cryptocurrency. This operation specifically targets the "facilitator" layer of the cybercrime ecosystem to disrupt the supply chain of access brokerage used by APTs and ransomware groups.

DoJ, Coinbase, Meta, Microsoft, and Starlink Disrupt Southeast Asia Crypto Fraud Networks

On May 18, 2026, the U.S. Department of Justice (DoJ) initiated "Disruption Week," a coordinated multi-sector operation targeting transnational cryptocurrency fraud networks in Southeast Asia. The operation dismantled the operational infrastructure of "pig butchering" schemes by synchronizing the disabling of 1.4 million fraudulent accounts across Meta, Microsoft, and Starlink, while simultaneously freezing $3.8 million in assets via Coinbase. By targeting the intersection of communication, internet connectivity, productivity suites, and financial off-ramps, the operation shifted from individual arrests to systemic infrastructure neutralization, effectively severing the command-and-control (C2) and monetization capabilities of these fraud syndicates.

FBI Seizure of NetNut Residential Proxy Platform and Popa Botnet

The FBI and Google Threat Analysis Group (TAG) have dismantled the NetNut residential proxy platform and the associated Popa botnet, which compromised approximately two million home IoT devices, including Smart TVs. The operation leveraged malicious SDKs embedded in legitimate software to transform residential hardware into a for-hire relay network, masking malicious traffic and supporting broader cyber operations. This disruption involved the seizure of hundreds of command-and-control (C2) and proxy domains. The infrastructure was managed by Alarum Technologies, a publicly traded company, highlighting a sophisticated abuse of the residential proxy business model to facilitate botnet-scale traffic obfuscation.

Kimwolf IoT Botnet: Dismantling of the AISURU-based DDoS-for-Hire Infrastructure

An international law enforcement operation, spearheaded by the U.S. Department of Justice and Canadian authorities, has dismantled the Kimwolf IoT botnet and its associated DDoS-for-hire ecosystem. The botnet, operated by Jacob Butler (alias 'Dort'), utilized the AISURU malware strain to weaponize millions of vulnerable, internet-exposed IoT devices. The infrastructure facilitated massive volumetric attacks, reaching unprecedented peaks of 31.4 Tbps, and was managed through 45 seized web-based command platforms. By seizing the Command and Control (C2) infrastructure and over 25,000 attack command logs, this operation effectively neutralized a major segment of the global 'booter' market and mitigated systemic threats to global internet stability.

Global Law Enforcement Disruption of PirloTV Sports Piracy Network

A coordinated international law enforcement and industry-led operation has dismantled the PirloTV sports piracy network, targeting unauthorized broadcast distribution in Latin America. Through a partnership involving the Alliance for Creativity and Entertainment (ACE), UEFA, and Mexican authorities, 44 domains associated with the PirloTV infrastructure were seized and neutralized. This action coincides with broader US Department of Justice (DOJ) efforts to seize approximately 400 domains related to illegal World Cup streaming. The operation highlights a strategic pivot in anti-piracy enforcement, moving from reactive, single-domain shutdowns toward proactive, large-scale infrastructure-level disruptions of redirection networks and mass-scale streaming platforms.

Dutch Authorities Seize 800 Servers Linked to Stark Industries Solutions and Russian Intelligence Operations

Dutch financial crime investigators (FIOD) have dismantled a massive hosting infrastructure comprising over 800 servers used by Russian-aligned actors to facilitate state-sponsored cyberattacks and disinformation campaigns. This operation disrupts a critical nexus of sanction evasion and intelligence activity, specifically targeting a proxy network that absorbed the infrastructure of the EU-sanctioned ISP, Stark Industries Solutions.

The CINEMAGOAL Evolution: From Piracy App to Credential Harvesting Engine

Italian law enforcement, including the Polizia Postale and Guardia di Finanza, has successfully disrupted the CINEMAGOAL ecosystem, a sophisticated mobile operation that evolved from a simple piracy application into a high-scale credential-harvesting platform. By leveraging malicious mobile binaries (APK/IPA) to perform session hijacking and Man-in-the-Middle (MitM) attacks, the app exfiltrated authentication tokens and session codes from legitimate users of major streaming services like Netflix, Disney+, and Spotify. This shift from content redistribution to active identity theft poses a significant threat to the streaming economy, necessitating enhanced scrutiny of mobile application behavior and session management protocols to prevent large-scale account takeovers.

Saydel Independent School District: Insider Threat via Offboarding Failure

A former Senior IT Support Specialist, Ezekiel Dean Potter, executed an 18-month cyber sabotage campaign against the Saydel Independent School District after his termination in April 2023. The attacker leveraged retained administrative credentials that were not revoked during the offboarding process to gain unauthorized access to district systems. This persistence enabled the deletion of critical user accounts and the disruption of classroom operational telemetry. The breach resulted in tens of thousands of dollars in financial losses and culminated in a 21-month federal prison sentence following a forensic audit of authentication logs and system telemetry.

Sky ECC Decryption Dismantles EUR 80 Million Kosovar Organized Crime Network

International law enforcement operations, coordinated by Europol, successfully compromised the Sky ECC encrypted communication platform, leading to the dismantlement of a sophisticated Kosovar-based criminal syndicate. By leveraging decrypted chat logs and message metadata harvested from modified encrypted handsets, investigators identified the "Inal" group's operational infrastructure. The breach exposed a multi-layered criminal ecosystem specializing in large-scale narcotics trafficking, illicit weapons distribution, money laundering, and fraudulent identity procurement. The exploitation of the platform's perceived security through systemic decryption capabilities has effectively neutralized an EUR 80 million criminal empire spanning Kosovo and multiple European Union member states.

ICO Secures £355K Confiscation Order in Motor Insurance Insider Threat Case

The Information Commissioner's Office (ICO) has successfully secured a £355,880.10 confiscation order against Rizwan Manjra, a former motor insurance employee convicted of unauthorized theft of sensitive personal data. Manjra abused legitimate credentials to exfiltrate "car crash" PII, bypassing standard security protocols to exploit highly sensitive customer information for illicit gain. This enforcement action, executed under the Proceeds of Crime Act, marks a significant escalation in the ICO's strategy to strip perpetrators of financial profits derived from data crimes (Databreaches.net).


LINK COPIED TO CLIPBOARD