Tag: FBI

FBI disrupts massive AI-powered phishing service using a million URLs
News

FBI disrupts massive AI-powered phishing service using a million URLs

In a concerted effort, the FBI, Google, and Black Lotus Labs have taken down Outsider Enterprise, a major Chinese phishing-as-a-service business that exploited thousands of phishing websites to steal passwords and credit card information. The cybercrime operation employed artificial intelligence (AI) and disseminated phishing kits for campaigns that impersonated a number of reputable firms in texts sent over Verizon, AT&T, and T-Mobile. Google has linked 9,000 phony websites and over a million false URLs to Outsider Enterprise, which has been operating on a vast scale since at least 2023. Authorities estimate that Outsider Enterprise-powered phishing efforts resulted in the theft of over 3.8 million credit card records, resulting in losses of $1.9 billion. The FBI's larger...
FBI warns of in-person data theft attacks from extortion gang
News

FBI warns of in-person data theft attacks from extortion gang

The extortion group Silent Ransom Group (SRG) is now focusing its in-person data theft activities on American legal firms, the FBI warned on Tuesday. As of spring 2026, SRG actors pretend to be employees of the victim's IT department through a social engineering strategy. The FBI issued a flash alert on Tuesday warning that SRG actors pose as IT help and either call employees directly or send phishing emails encouraging them to do so. The SRG actor instructs the staff member to provide access to a remote desktop session while they are on the phone. In the event that the effort is unsuccessful, SRG dispatches a threat actor to the victim's location in order to obtain access and implant a storage device into the victim's computer. Malicious actors can steal data by physically visit...
FBI warns of virtual kidnapping scams using altered social media photos
News

FBI warns of virtual kidnapping scams using altered social media photos

In virtual kidnapping ransom scams, the FBI warns of criminals who change photos posted on social media and use them as phony proof of existence. This is a portion of a public service advertisement that was released today regarding crooks texting victims to demand ransom payments after allegedly kidnapping a family member. But as the FBI clarified, there is no real kidnapping in virtual kidnapping frauds. Instead, thieves build plausible scenarios to coerce victims into paying ransoms before confirming that their loved ones are safe using altered photos from social media and publicly accessible information. According to the FBI on Friday, criminal actors usually use text messaging to contact their victims, claiming to have abducted a loved one and demanding payment of a ransom to...
FBI warns of UNC6040, UNC6395 hackers stealing Salesforce data
News

FBI warns of UNC6040, UNC6395 hackers stealing Salesforce data

Two threat clusters, identified as UNC6040 and UNC6395, are breaching Salesforce environments of enterprises in order to steal data and extort victims, according to a FLASH alert released by the FBI. According to the FBI's FLASH advisory, the agency is releasing this FLASH to share Indicators of Compromise (IOCs) linked to recent malevolent cyber activity by cybercriminal organizations UNC6040 and UNC6395, which are in charge of an increasing number of data theft and extortion intrusions. Both groups have lately been seen using various initial access methods to target Salesforce platforms used by enterprises. In order to raise awareness and give recipients IOCs that they may use for network defense and study, the FBI is making this information public. Google Threat Intelligence (...
CISA and FBI warn of escalating Interlock ransomware attacks
News

CISA and FBI warn of escalating Interlock ransomware attacks

On Tuesday, CISA and the FBI issued a warning about a surge in Interlock ransomware activity that targets critical infrastructure organizations and businesses through double extortion assaults. The Multi-State Information Sharing and Analysis Center (MS-ISAC) and the Department of Health and Human Services (HHS) collaborated to create today's advisory, which gives network defenders mitigation strategies to shield their networks from attacks by this ransomware gang as well as indicators of compromise (IOCs) gathered during incident investigations as recently as June 2025. Since its emergence in September 2024, the relatively new ransomware operation Interlock has targeted victims globally in a variety of industry sectors, with a particular emphasis on the healthcare sector. The th...
BADBOX 2.0 Android malware infects millions of consumer devices
News

BADBOX 2.0 Android malware infects millions of consumer devices

Over a million home Internet-connected devices have been infected by the BADBOX 2.0 malware campaign, which has turned consumer electronics into residential proxies used for nefarious activity, the FBI warns. Chinese Android-based smart TVs, streaming boxes, projectors, tablets, and other Internet of Things (IoT) devices are frequently infected with the BADBOX botnet. The FBI says that the BADBOX 2.0 botnet, which comprises of millions of compromised devices, maintains many backdoors to proxy services that cybercriminals take advantage of by selling or giving them free access to compromised home networks for use in a variety of illegal activities. The BADBOX 2.0 malware botnet is preinstalled on these devices, or they can get infected through firmware updates or malicious Android...
FBI warns of Luna Moth extortion attacks targeting law firms
News

FBI warns of Luna Moth extortion attacks targeting law firms

For the past two years, U.S. law firms have been the subject of callback phishing and social engineering attempts by an extortion organization called the Silent Ransom Group, the FBI warned. This threat organization, which has been active since 2022 and is also known by the names Luna Moth, Chatty Spider, and UNC3753, was responsible for the BazarCall campaigns that gave Ryuk and Conti ransomware assaults their first access to company networks. After Conti was shut down in March 2022, the threat actors broke away from the cybercrime syndicate and established the Silent Ransom Group (SRG). In recent attacks, SRG uses social engineering techniques to obtain access to the targets' networks by posing as their IT assistance via phone calls, phony websites, and emails. This extortio...
FBI and Europol Disrupt Lumma Stealer Malware Network Linked to 10 Million Infections
News

FBI and Europol Disrupt Lumma Stealer Malware Network Linked to 10 Million Infections

Global law enforcement agencies and a group of private sector companies launched a massive operation that disrupted the online infrastructure of Lumma, a commodity information stealer (also known as LummaC or LummaC2). The operation took control of 2,300 domains that served as the command-and-control (C2) backbone for commandeering infected Windows systems. According to a statement from the U.S. Department of Justice (DoJ), malware such as LummaC2 is used to steal private data, including user login passwords, from millions of victims in order to enable a variety of crimes, such as cryptocurrency theft and fraudulent bank transfers. Through affiliates and other cybercriminals, the seized infrastructure has been utilized to attack millions of people worldwide. Since its launch in late...
CISA and FBI Warn Fast Flux is Powering Resilient Malware, C2, and Phishing Networks
News

CISA and FBI Warn Fast Flux is Powering Resilient Malware, C2, and Phishing Networks

The United States, Canada, New Zealand, and Australia's cybersecurity authorities have released a joint advisory regarding the dangers of a method known as "fast flux," which threat actors have used to obfuscate a command-and-control (C2) channel. According to the agencies, "fast flux" is a technique that uses quickly changing Domain Name System (DNS) records linked to a single domain name to obscure the whereabouts of malicious computers. This attack takes use of a weakness in network defenses that makes it challenging to trace and stop harmful fast flux activity. The National Security Agency (NSA), Federal Bureau of Investigation (FBI), Australian Signals Directorate's Australian Cyber Security Centre, Canadian Centre for Cyber Security, New Zealand's National Cyber Security Centr...
CISA and FBI: Ghost ransomware breached orgs in 70 countries
News

CISA and FBI: Ghost ransomware breached orgs in 70 countries

Attackers using Ghost ransomware have compromised victims from a variety of industrial sectors in more than 70 countries, including critical infrastructure firms, according to CISA and the FBI. Healthcare, government, education, technology, manufacturing, and a large number of small and medium-sized enterprises are among the other industries affected. In a joint alert issued on Wednesday, CISA, the FBI, and the Multi-State Information Sharing and Analysis Center (MS-ISAC) stated that "Ghost actors started attacking victims whose internet-facing services ran outdated versions of software and firmware beginning in early 2021 read more about CISA and FBI Ghost ransomware breached orgs in 70 countries Get up to date on the latest cybersecurity news and enhance your knowledge of cyber...