<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
<channel>
<title>Computer Crime Research Center — News</title>
<link>https://www.crime-research.org/news/</link>
<description>Daily news about computer crime, internet fraud and cyber security.</description>
<language>en-us</language>
<item>
<title>Alleged ShinyHunters Hacker 'Rey' Detained in Jordan, Reportedly Cooperating With FBI</title>
<link>https://www.crime-research.org/news/05.10.2026/shinyhunters-suspect-rey-detained-jordan-fbi/</link>
<guid>https://www.crime-research.org/news/05.10.2026/shinyhunters-suspect-rey-detained-jordan-fbi/</guid>
<pubDate>Mon, 05 Oct 2026 09:10:00 GMT</pubDate>
<description>A suspect tied to the ShinyHunters extortion collective was detained in Jordan and is reportedly helping the FBI identify other members.</description>
</item>
<item>
<title>Warlock Ransomware Group Expands SharePoint Attacks on Critical Infrastructure Across Latin America and Iberia</title>
<link>https://www.crime-research.org/news/05.10.2026/warlock-ransomware-sharepoint-critical-infrastructure/</link>
<guid>https://www.crime-research.org/news/05.10.2026/warlock-ransomware-sharepoint-critical-infrastructure/</guid>
<pubDate>Mon, 05 Oct 2026 09:05:00 GMT</pubDate>
<description>A China-based ransomware group is exploiting Microsoft SharePoint flaws to hit water, telecom and government networks across Latin America and Iberia.</description>
</item>
<item>
<title>Teenage Ransomware Leader Among Three Arrested as Police Dismantle KillSec in Operation KillSwitch</title>
<link>https://www.crime-research.org/news/05.10.2026/killsec-ransomware-teen-leader-arrested-operation-killswitch/</link>
<guid>https://www.crime-research.org/news/05.10.2026/killsec-ransomware-teen-leader-arrested-operation-killswitch/</guid>
<pubDate>Mon, 05 Oct 2026 09:00:00 GMT</pubDate>
<description>International police seized KillSec's leak site and servers and arrested a 16-year-old alleged ringleader plus two other suspected members.</description>
</item>
<item>
<title>U.S. Army Soldier Sentenced to Nearly 6 Years for Hacking AT&amp;T, Verizon in Extortion Scheme</title>
<link>https://www.crime-research.org/news/28.09.2026/us-soldier-sentenced-att-verizon-extortion/</link>
<guid>https://www.crime-research.org/news/28.09.2026/us-soldier-sentenced-att-verizon-extortion/</guid>
<pubDate>Mon, 28 Sep 2026 09:10:00 GMT</pubDate>
<description>Cameron Wagenius, known online as 'Kiberphant0m,' was sentenced for stealing call records from over 100 million AT&amp;T customers and extorting telecom firms.</description>
</item>
<item>
<title>Microsoft Dismantles EvilTokens, an AI-Powered Phishing Service Tied to 12,000 Compromised Inboxes</title>
<link>https://www.crime-research.org/news/28.09.2026/microsoft-takes-down-eviltokens-phishing-service/</link>
<guid>https://www.crime-research.org/news/28.09.2026/microsoft-takes-down-eviltokens-phishing-service/</guid>
<pubDate>Mon, 28 Sep 2026 09:05:00 GMT</pubDate>
<description>A court-authorized takedown disrupted the EvilTokens device-code phishing platform, which used AI throughout its attack chain against organizations worldwide.</description>
</item>
<item>
<title>Bitget Says Suspected North Korean Hackers Stole Over $350 Million in Exchange Hack</title>
<link>https://www.crime-research.org/news/28.09.2026/bitget-hack-north-korean-hackers-steal-350-million/</link>
<guid>https://www.crime-research.org/news/28.09.2026/bitget-hack-north-korean-hackers-steal-350-million/</guid>
<pubDate>Mon, 28 Sep 2026 09:00:00 GMT</pubDate>
<description>Cryptocurrency exchange Bitget says attackers linked to North Korea's TraderTraitor group breached backend wallet infrastructure to steal hundreds of millions in crypto.</description>
</item>
<item>
<title>Screenshot Service Gyazo Confirms Breach Exposing 23.6 Million User Records</title>
<link>https://www.crime-research.org/news/22.09.2026/gyazo-data-breach-23-million-records/</link>
<guid>https://www.crime-research.org/news/22.09.2026/gyazo-data-breach-23-million-records/</guid>
<pubDate>Tue, 22 Sep 2026 09:10:00 GMT</pubDate>
<description>Gyazo, a widely used screenshot-sharing platform, took its service offline after attackers exploited a server flaw to steal tens of millions of records.</description>
</item>
<item>
<title>FBI Seizes NightmareStresser, One of the Longest-Running DDoS-for-Hire Platforms</title>
<link>https://www.crime-research.org/news/22.09.2026/fbi-seizes-nightmarestresser-ddos-for-hire/</link>
<guid>https://www.crime-research.org/news/22.09.2026/fbi-seizes-nightmarestresser-ddos-for-hire/</guid>
<pubDate>Tue, 22 Sep 2026 09:05:00 GMT</pubDate>
<description>US authorities took down the NightmareStresser booter service, used since 2022 to launch hundreds of thousands of DDoS attacks worldwide.</description>
</item>
<item>
<title>Joint Advisory Ties North Korean 'WaterPlum' Group to 30,000 Infected Devices and $10.7M Crypto Theft</title>
<link>https://www.crime-research.org/news/22.09.2026/north-korea-waterplum-30000-devices-crypto-theft/</link>
<guid>https://www.crime-research.org/news/22.09.2026/north-korea-waterplum-30000-devices-crypto-theft/</guid>
<pubDate>Tue, 22 Sep 2026 09:00:00 GMT</pubDate>
<description>US, Japanese, Australian, and German authorities detail how North Korea's WaterPlum hackers used fake job interviews to steal cryptocurrency worldwide.</description>
</item>
<item>
<title>CISA Warns Ransomware Gangs Are Now Exploiting Critical VMware vCenter Flaw</title>
<link>https://www.crime-research.org/news/17.09.2026/vmware-vcenter-flaw-exploited-ransomware-gangs/</link>
<guid>https://www.crime-research.org/news/17.09.2026/vmware-vcenter-flaw-exploited-ransomware-gangs/</guid>
<pubDate>Thu, 17 Sep 2026 09:10:00 GMT</pubDate>
<description>CISA updates its exploited-vulnerabilities catalog to flag a critical VMware vCenter bug, patched in July, as now abused in ransomware attacks.</description>
</item>
<item>
<title>CenterPoint Energy Confirms Breach After Attacker Claims 7.49 Million Records Stolen</title>
<link>https://www.crime-research.org/news/17.09.2026/centerpoint-energy-data-breach-7-million-records/</link>
<guid>https://www.crime-research.org/news/17.09.2026/centerpoint-energy-data-breach-7-million-records/</guid>
<pubDate>Thu, 17 Sep 2026 09:05:00 GMT</pubDate>
<description>Texas utility CenterPoint Energy confirms customer data was stolen after a threat actor leaked records it says were pulled from an unprotected API.</description>
</item>
<item>
<title>Five Alleged Black Axe Syndicate Leaders Extradited to US on Fraud Charges</title>
<link>https://www.crime-research.org/news/17.09.2026/black-axe-leaders-extradited-to-us-cybercrime-charges/</link>
<guid>https://www.crime-research.org/news/17.09.2026/black-axe-leaders-extradited-to-us-cybercrime-charges/</guid>
<pubDate>Thu, 17 Sep 2026 09:00:00 GMT</pubDate>
<description>US prosecutors charge five suspected Black Axe leaders extradited from South Africa over a decade-long romance scam and money-laundering scheme.</description>
</item>
<item>
<title>Cybercriminals Use Blockchain Smart Contracts to Run ClickFix Malware Campaign Across 5,400+ Hacked Websites</title>
<link>https://www.crime-research.org/news/07.09.2026/blockchain-clickfix-campaign-5400-hacked-websites/</link>
<guid>https://www.crime-research.org/news/07.09.2026/blockchain-clickfix-campaign-5400-hacked-websites/</guid>
<pubDate>Mon, 07 Sep 2026 09:30:00 GMT</pubDate>
<description>Researchers found over 5,400 compromised sites serving ClickFix malware payloads hidden in BNB Smart Chain smart contracts, resisting takedown efforts.</description>
</item>
<item>
<title>Thomson Reuters Discloses Breach of Court Case-Management Platform, Risking Exposure of SSNs and Sealed Records</title>
<link>https://www.crime-research.org/news/07.09.2026/thomson-reuters-court-software-breach-exposes-sealed-records/</link>
<guid>https://www.crime-research.org/news/07.09.2026/thomson-reuters-court-software-breach-exposes-sealed-records/</guid>
<pubDate>Mon, 07 Sep 2026 09:15:00 GMT</pubDate>
<description>A breach at Thomson Reuters' C-Track court software may have exposed Social Security numbers and sealed case data across 11 U.S. states and Canada.</description>
</item>
<item>
<title>FBI Investigates Dark-Web Sale of 153 Million U.S. and Canadian Driver's Licenses Tied to IDScan Breach</title>
<link>https://www.crime-research.org/news/07.09.2026/idscan-breach-153-million-drivers-licenses-fbi-investigation/</link>
<guid>https://www.crime-research.org/news/07.09.2026/idscan-breach-153-million-drivers-licenses-fbi-investigation/</guid>
<pubDate>Mon, 07 Sep 2026 09:00:00 GMT</pubDate>
<description>A dark-web service called Nexus advertised scans of 153M+ driver's licenses traced to identity-verification firm IDScan, prompting an FBI probe and lawsuits.</description>
</item>
<item>
<title>Berlin State Government Refuses Ransom After Data Theft From Administrative Network</title>
<link>https://www.crime-research.org/news/31.08.2026/berlin-refuses-to-pay-hackers-state-network-extortion/</link>
<guid>https://www.crime-research.org/news/31.08.2026/berlin-refuses-to-pay-hackers-state-network-extortion/</guid>
<pubDate>Mon, 31 Aug 2026 09:10:00 GMT</pubDate>
<description>Berlin confirmed an extortion attempt tied to an August breach of its state administrative network and said it will not pay the attackers' demand.</description>
</item>
<item>
<title>Australian Police Arrest Two Alleged Members of TeamPCP Hacking Group</title>
<link>https://www.crime-research.org/news/31.08.2026/two-alleged-teampcp-hackers-arrested-in-australia/</link>
<guid>https://www.crime-research.org/news/31.08.2026/two-alleged-teampcp-hackers-arrested-in-australia/</guid>
<pubDate>Mon, 31 Aug 2026 09:05:00 GMT</pubDate>
<description>The Australian Federal Police arrested two Perth men accused of running the TeamPCP software supply-chain extortion operation tied to the Shai-Hulud worm.</description>
</item>
<item>
<title>McKesson Discloses Data Breach Amid ShinyHunters Extortion Claim</title>
<link>https://www.crime-research.org/news/31.08.2026/mckesson-breach-shinyhunters-284-million-patient-records/</link>
<guid>https://www.crime-research.org/news/31.08.2026/mckesson-breach-shinyhunters-284-million-patient-records/</guid>
<pubDate>Mon, 31 Aug 2026 09:00:00 GMT</pubDate>
<description>Healthcare distributor McKesson confirms a cybersecurity incident after the ShinyHunters group claimed to have stolen roughly 284 million patient-related data records.</description>
</item>
<item>
<title>Over 9,300 Leaked AWS Access Keys Found Still Active, Giving Full Control of Corporate Accounts</title>
<link>https://www.crime-research.org/news/24.08.2026/9300-leaked-aws-keys-corporate-accounts/</link>
<guid>https://www.crime-research.org/news/24.08.2026/9300-leaked-aws-keys-corporate-accounts/</guid>
<pubDate>Mon, 24 Aug 2026 09:30:00 GMT</pubDate>
<description>Truffle Security found thousands of exposed AWS keys, many years old and never rotated, still granting administrator access to company cloud accounts.</description>
</item>
<item>
<title>US Agencies Warn of AI-Generated Exploit Scripts Targeting Siemens S7 PLCs in Critical Infrastructure</title>
<link>https://www.crime-research.org/news/24.08.2026/ai-generated-exploits-siemens-s7-plc-critical-infrastructure/</link>
<guid>https://www.crime-research.org/news/24.08.2026/ai-generated-exploits-siemens-s7-plc-critical-infrastructure/</guid>
<pubDate>Mon, 24 Aug 2026 09:15:00 GMT</pubDate>
<description>CISA, NSA, FBI and DOE warn of an active campaign using AI-generated scripts to probe and manipulate Siemens S7 industrial controllers.</description>
</item>
<item>
<title>TikTok and ByteDance Agree to $400 Million Settlement Over Children's Privacy Violations</title>
<link>https://www.crime-research.org/news/24.08.2026/tiktok-400-million-doj-settlement-child-privacy/</link>
<guid>https://www.crime-research.org/news/24.08.2026/tiktok-400-million-doj-settlement-child-privacy/</guid>
<pubDate>Mon, 24 Aug 2026 09:00:00 GMT</pubDate>
<description>DOJ settlement resolves claims TikTok let millions of children under 13 use adult accounts and collected their data without parental consent.</description>
</item>
<item>
<title>Cybercriminals Arrested Over €30 Million Commerzbank Fraud Scheme</title>
<link>https://www.crime-research.org/news/17.08.2026/commerzbank-eur30-million-fraud-arrests/</link>
<guid>https://www.crime-research.org/news/17.08.2026/commerzbank-eur30-million-fraud-arrests/</guid>
<pubDate>Mon, 17 Aug 2026 09:00:00 GMT</pubDate>
<description>Brazilian and German police arrested suspects behind a 2023 scheme that exploited a service-provider flaw to drain Commerzbank customer accounts.</description>
</item>
<item>
<title>RingCentral Data Breach Exposes Personal Information of 1.6 Million Accounts</title>
<link>https://www.crime-research.org/news/17.08.2026/ringcentral-data-breach-shinyhunters/</link>
<guid>https://www.crime-research.org/news/17.08.2026/ringcentral-data-breach-shinyhunters/</guid>
<pubDate>Mon, 17 Aug 2026 09:00:00 GMT</pubDate>
<description>The ShinyHunters extortion group breached cloud communications provider RingCentral in July, exposing personal data tied to 1.6 million accounts.</description>
</item>
<item>
<title>Ukrainian Police Shut Down 94 Fraudulent Call Centers in Nationwide Sweep</title>
<link>https://www.crime-research.org/news/17.08.2026/ukraine-shuts-down-94-fraud-call-centers/</link>
<guid>https://www.crime-research.org/news/17.08.2026/ukraine-shuts-down-94-fraud-call-centers/</guid>
<pubDate>Mon, 17 Aug 2026 09:00:00 GMT</pubDate>
<description>Ukraine's National Police dismantled 94 scam call centers running investment fraud and bank-impersonation schemes, seizing cash, crypto access and gear.</description>
</item>
<item>
<title>Healthcare Software Firm Unlimited Technology Systems Discloses Breach Affecting 3.8 Million Patients</title>
<link>https://www.crime-research.org/news/10.08.2026/unlimited-technology-systems-breach-3-8-million/</link>
<guid>https://www.crime-research.org/news/10.08.2026/unlimited-technology-systems-breach-3-8-million/</guid>
<pubDate>Mon, 10 Aug 2026 09:30:00 GMT</pubDate>
<description>A months-delayed disclosure reveals hackers accessed patient records at a healthcare billing vendor for five days in October 2025, exposing data on 3.8 million people.</description>
</item>
<item>
<title>Canadian Man Pleads Guilty in Snowflake Cloud Extortion Campaign Affecting 100+ Million People</title>
<link>https://www.crime-research.org/news/10.08.2026/canadian-guilty-plea-snowflake-data-theft/</link>
<guid>https://www.crime-research.org/news/10.08.2026/canadian-guilty-plea-snowflake-data-theft/</guid>
<pubDate>Mon, 10 Aug 2026 09:15:00 GMT</pubDate>
<description>Connor Riley Moucka admitted to hacking Snowflake customer accounts and extorting victims, in a scheme US officials say affected over 100 million individuals.</description>
</item>
<item>
<title>Ransom Cartel Ransomware Creator Sentenced to 16 Years in US Prison</title>
<link>https://www.crime-research.org/news/10.08.2026/ransom-cartel-creator-sentenced-16-years/</link>
<guid>https://www.crime-research.org/news/10.08.2026/ransom-cartel-creator-sentenced-16-years/</guid>
<pubDate>Mon, 10 Aug 2026 09:00:00 GMT</pubDate>
<description>Belarusian national Maksim Silnikau was sentenced to 16 years for building and running Ransom Cartel, which extorted at least 18 companies worldwide.</description>
</item>
<item>
<title>Amazon Ties Years of npm Supply-Chain Attacks to North Korean Hacking Group</title>
<link>https://www.crime-research.org/news/03.08.2026/amazon-links-npm-supply-chain-attacks-to-north-korean-hackers/</link>
<guid>https://www.crime-research.org/news/03.08.2026/amazon-links-npm-supply-chain-attacks-to-north-korean-hackers/</guid>
<pubDate>Mon, 03 Aug 2026 09:30:00 GMT</pubDate>
<description>Amazon attributed a string of npm package compromises, including the widely used debug and chalk libraries, to the North Korea-linked Sapphire Sleet group.</description>
</item>
<item>
<title>Coordinated Cyberattack Disrupts 30+ Minnesota Water Utilities, CISA Warns of Wider Threat</title>
<link>https://www.crime-research.org/news/03.08.2026/coordinated-cyberattack-hits-minnesota-water-utilities-cisa-warns/</link>
<guid>https://www.crime-research.org/news/03.08.2026/coordinated-cyberattack-hits-minnesota-water-utilities-cisa-warns/</guid>
<pubDate>Mon, 03 Aug 2026 09:15:00 GMT</pubDate>
<description>Hackers targeted exposed industrial controllers at over 30 Minnesota water systems, prompting a CISA alert on internet-facing operational technology.</description>
</item>
<item>
<title>COLDCARD Hardware Wallet Flaw Linked to $88 Million Bitcoin Theft</title>
<link>https://www.crime-research.org/news/03.08.2026/coldcard-wallet-flaw-linked-to-88-million-bitcoin-theft/</link>
<guid>https://www.crime-research.org/news/03.08.2026/coldcard-wallet-flaw-linked-to-88-million-bitcoin-theft/</guid>
<pubDate>Mon, 03 Aug 2026 09:00:00 GMT</pubDate>
<description>A firmware bug in COLDCARD hardware wallets let attackers predict private keys, draining an estimated $88.6 million in Bitcoin from thousands of addresses.</description>
</item>
</channel>
</rss>
