Tag: U.S. Department of Justice (DoJ)

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit
News

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

ByteDance-owned TikTok will pay $400 million to resolve a 2024 lawsuit alleging the firm violated the nation's kid privacy laws, the U.S. Department of Justice (DoJ) said on Friday. According to a press release from the Department of Justice, as part of the settlement, the social media platform will pay $300 million up front and an additional $100 million after an order dismissing a previous consent decree against TikTok's predecessor, Musical.ly, is entered. In August 2024, the Federal Trade Commission (FTC) filed a lawsuit accusing the firm of widespread violations of children's privacy, including permitting minors under the age of 13 to register for TikTok accounts and illegally gathering information from users in Kids Mode. It further claimed that parents' requests to have th...
DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks
News

DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

As part of a court-authorized law enforcement investigation, the U.S. Department of Justice (DoJ) stated on Thursday that it has disrupted the command-and-control (C2) infrastructure utilized by a number of Internet of Things (IoT) botnets, including AISURU, Kimwolf, JackSkid, and Mossad. A number of private sector companies, including Akamai, Amazon Web Services, Cloudflare, DigitalOcean, Google, Lumen, Nokia, Okta, Oracle, PayPal, SpyCloud, Synthient, Team Cymru, Unit 221B, and QiAnXin XLab, assisted in the investigation efforts as Canadian and German authorities targeted the botnet operators. According to the DoJ, the four botnets launched distributed denial-of-service (DDoS) attacks against victims worldwide. Some of these attacks broke records, with speeds of about 30 Terabits ...
Authorities Disrupt SocksEscort Proxy Botnet Exploiting 369,000 IPs Across 163 Countries
News

Authorities Disrupt SocksEscort Proxy Botnet Exploiting 369,000 IPs Across 163 Countries

SocksEscort, a criminal proxy service that enslaved thousands of home routers globally into a botnet for widespread fraud, has been taken down by a court-authorized multinational law enforcement operation. The U.S. Department of Justice (DoJ) reported that SocksEscort infiltrated home and small business internet routers with malware. SocksEscort was able to redirect internet traffic through the compromised routers thanks to the virus. Customers purchased this access from SocksEscort. Since the summer of 2020, SocksEscort ("socksescort[.]com") has reportedly offered to sell access to about 369,000 distinct IP addresses across 163 countries; as of February 2026, the service listed almost 8,000 compromised routers. 2,500 of these were found in the United States. According to SocksEs...
DoJ Seizes $61 Million in Tether Linked to Pig Butchering Crypto Scams
News

DoJ Seizes $61 Million in Tether Linked to Pig Butchering Crypto Scams

This week, the U.S. Department of Justice (DoJ) stated that $61 million worth of Tether had been seized after it was reportedly linked to fraudulent cryptocurrency scams known as "pig butchering." According to the department, the seized money were linked to cryptocurrency addresses that were used to launder illegally obtained profits that were taken from victims of cryptocurrency investment scams. According to HSI Charlotte Acting Special Agent in Charge Kyle D. Burns, professional money launderers and criminal actors utilize cyber-enabled fraud schemes to defraud their victims and hide their illicit riches. In order to disrupt and dismantle the transnational criminal organizations that aim to swindle industrious Americans, HSI special agents painstakingly trace the illicit proce...
DOJ Resentences BreachForums Founder to 3 Years for Cybercrime and Possession of CSAM
News

DOJ Resentences BreachForums Founder to 3 Years for Cybercrime and Possession of CSAM

The former administrator of BreachForums was resentenced by the U.S. Department of Justice (DoJ) on Tuesday to three years in prison for his involvement in the operation of the cybercrime forum and his possession of child sexual abuse material (CSAM). Conor Brian Fitzpatrick (also known as Pompompurin), a 22-year-old Peekskill, New York resident, entered a guilty plea to one count each of conspiring to use an access device, soliciting an access device, and possessing material related to child sexual abuse. Fitzpatrick entered a guilty plea later in July after being first taken into custody in March 2023. Fitzpatrick allegedly consented to surrender more than 100 domain names used in the BreachForums operation, more than a dozen electronic equipment used to carry out the plan, and bi...
U.S. Seizes $7.74M in Crypto Tied to North Korea’s Global Fake IT Worker Network
News

U.S. Seizes $7.74M in Crypto Tied to North Korea’s Global Fake IT Worker Network

A civil forfeiture case targeting approximately $7.74 million in cryptocurrencies, non-fungible tokens (NFTs), and other digital assets purportedly connected to a global IT worker scheme hatched by North Korea has been filed in federal court, according to the U.S. Department of Justice (DoJ). According to Sue J. Bai, Head of the Justice Department's National Security Division, North Korea has been using cryptocurrency ecosystems and international remote IT contracting for years to circumvent U.S. sanctions and finance its weapons development. According to the Justice Department, the money were initially blocked in relation to an indictment filed in April 2023 against Sim Hyon-Sop, a representative of the North Korean Foreign Trade Bank (FTB), who is suspected of plotting with the IT...
DoJ Seizes 145 Domains Tied to BidenCash Carding Marketplace in Global Takedown
News

DoJ Seizes 145 Domains Tied to BidenCash Carding Marketplace in Global Takedown

The seizure of cryptocurrency money and over 145 clearnet and dark web domains linked to the illegal carding marketplace BidenCash was disclosed by the U.S. Department of Justice (DoJ) on Wednesday. The BidenCash marketplace's administrators use the platform to make it easier to acquire and sell credit cards that have been stolen and the personal data that goes with them," the DoJ stated. Administrators of BidenCash assessed a fee for each transaction made on the website. In March 2022, BidenCash was introduced to bridge the gap created by the closure of several carding forums, including UniCC, and Joker's Stash a year earlier. According to estimates, the illegal bazaar ("bidencash[.]asia," "bidencash[.]bd," and "bidencash[.]ws") has supported over 117,000 customers since it open...
U.S. DoJ Seizes 4 Domains Supporting Cybercrime Crypting Services in Global Operation
News

U.S. DoJ Seizes 4 Domains Supporting Cybercrime Crypting Services in Global Operation

An online cybercrime syndicate that provided threat actors with services to keep their dangerous software hidden from security software has been taken down as a result of a multinational law enforcement investigation. Accordingly, on May 27, 2025, the U.S. Department of Justice (DoJ) announced that, working with Dutch and Finnish authorities, it had taken control of four domains and the server that supported the crypting service. These include Cryptor[.]biz, Crypt[.]guru, and AvCheck[.]net, all of which currently show a seizure notice. France, Germany, Denmark, Portugal, and Ukraine were among the other nations that took part in the endeavor. According to the DoJ, crypting is the technique of employing software to make malware harder for antivirus software to detect. Counter-anti...
FBI and Europol Disrupt Lumma Stealer Malware Network Linked to 10 Million Infections
News

FBI and Europol Disrupt Lumma Stealer Malware Network Linked to 10 Million Infections

Global law enforcement agencies and a group of private sector companies launched a massive operation that disrupted the online infrastructure of Lumma, a commodity information stealer (also known as LummaC or LummaC2). The operation took control of 2,300 domains that served as the command-and-control (C2) backbone for commandeering infected Windows systems. According to a statement from the U.S. Department of Justice (DoJ), malware such as LummaC2 is used to steal private data, including user login passwords, from millions of victims in order to enable a variety of crimes, such as cryptocurrency theft and fraudulent bank transfers. Through affiliates and other cybercriminals, the seized infrastructure has been utilized to attack millions of people worldwide. Since its launch in late...
U.S. Charges Yemeni Hacker Behind Black Kingdom Ransomware Targeting 1500 Systems
News

U.S. Charges Yemeni Hacker Behind Black Kingdom Ransomware Targeting 1500 Systems

A 36-year-old Yemeni individual was charged by the U.S. Department of Justice (DoJ) on Thursday for allegedly using the Black Kingdom ransomware to target international targets, including American hospitals, schools, and companies. One case of conspiracy, one count of purposeful damage to a protected computer, and one count of threatening damage to a protected computer have been brought against Rami Khaled Ahmed of Sana'a, Yemen. According to the assessment, Ahmed resides in Yemen at the moment. A medical billing services company in Encino, a ski resort in Oregon, a school district in Pennsylvania, and a health clinic in Wisconsin were among the U.S.-based victims whose computer networks were compromised by Ahmed and others between March 2021 and June 2023, according to a statement ...