Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Cyber Crime. Show all posts

California Court Dismisses El Faro Journalists' Pegasus Spyware Lawsuit Against NSO Group for Second Time

 



A California federal judge has once again dismissed a lawsuit brought by journalists from Salvadoran investigative outlet El Faro against NSO Group, the Israeli company behind the Pegasus spyware allegedly used to surveil their phones for nearly two years. The ruling, issued Wednesday, marks the second time the case has been thrown out on jurisdictional grounds, though the journalists' legal team at the Knight First Amendment Institute at Columbia University has said it intends to appeal.

The case, Dada v. NSO Group, was the first lawsuit against NSO filed in any U.S. court when the Knight Institute took it on in November 2022 on behalf of 18 current and former El Faro journalists and staff. Between June 2020 and November 2021, Pegasus spyware was deployed against the outlet's employees at least 226 times, according to the Institute. Digital forensic analysis eventually confirmed that 22 members of El Faro's staff had their phones infected. The attacks were not random. Surveillance peaked during significant political moments and in the run-up to major investigations, including reporting on the Bukele administration's secret negotiations with criminal gangs, the theft of pandemic food relief, back-channel Bitcoin dealings, and the financial holdings of government officials.

The lead plaintiff, Carlos Dada, is the co-founder and director of El Faro, one of Central America's most prominent independent news organizations. El Faro was founded in El Salvador in 1998 and has built a reputation for independent investigative reporting. The outlet has paid a steep price for that journalism. Beyond the spyware attacks, El Faro says it has faced physical surveillance, advertiser harassment, and public defamation from government officials and ruling-party legislators. In 2023, the newsroom relocated its administrative and legal operations out of El Salvador entirely.

The core question before the court was whether Northern California was the right place to try this dispute. Dada and the plaintiffs argued it was, pointing to compromised U.S.-based infrastructure that was used as part of the attack chain. The judge was not persuaded. The court noted that there was no allegation Apple's California servers were actually exploited in delivering the Pegasus infections, even where the plaintiffs alleged the attacks moved through Apple's iMessage or iCloud systems. The same argument had failed once before: in March 2024, a California federal judge threw out the same lawsuit, saying the case was "entirely foreign" and that the journalists had no standing to sue in the U.S.

That first dismissal did not hold. The Ninth Circuit Court of Appeals reversed the March 2024 ruling in July 2025 and sent the case back to the Northern District of California, finding that the lower court erred in its analysis. The Ninth Circuit had concluded that the district judge failed to properly account for allegations that NSO created Apple ID accounts and engaged with California-based servers as part of the attack infrastructure. One factor that also came into play was a recent acquisition of NSO Group by a group of American investors, which El Faro's lawyers cited as further reason for trying the case on U.S. soil. After the Ninth Circuit's reversal, Dada called the outcome "good news." That window has now closed again.

The journalists had wanted specific remedies from the court. They asked the court to require NSO Group to identify, return, and delete all information obtained through the attacks, to prohibit the company from deploying Pegasus against them again, and to name the government client that commissioned the surveillance. That last demand was perhaps the most politically charged. NSO has never publicly identified its clients. The company maintains it sells Pegasus exclusively to government agencies for use against criminals and terrorists, subject to Israeli government authorization. El Salvador's government has repeatedly denied being an NSO client or playing any role in the surveillance.

With Apple having dropped its own case against NSO in September 2024, and WhatsApp having won a $167 million judgment against the company earlier in 2025, the El Faro lawsuit had become the last active case against NSO Group in U.S. courts. That distinction is now moot, at least temporarily.

The Knight First Amendment Institute plans to appeal. El Faro's director Carlos Dada said when the original lawsuit was filed that the outlet turned to the U.S. court system because justice in El Salvador was not possible. With the case now dismissed a second time and the appeal road still open, that search for accountability continues.

NSO Group did not respond to a request for comment.



ShinyHunters Hacker Reportedly Detained as FBI Seeks Cooperation


The FBI has reportedly detained a suspected ShinyHunters member known online as “Rey” and is cooperating with the government. Jordanian authorities captured a suspect identified as Saif al-Din Khader this week. According to two sources cited by Reuters, Khader is helping U.S. and international investigators identify other members of the hacking group. 


It is believed that Khader's cooperation will provide investigators with information regarding the group's activities and alleged co-conspirators, according to a source. He has shown investigators his electronic devices and digital communication to help locate other suspected members. The FBI has not responded to Khader's reported detention specifically, however it has stated that it is continuing to investigate the recent cyber incident allegedly involving ShinyHunters and is collaborating with international partners to resolve the matter. 

A series of law enforcement actions targeting individuals affiliated with ShinyHunters has led to this reported detention. Dutch authorities arrested a 24-year-old man in connection with an investigation into the group in September. Following the arrest, the FBI issued a warning encouraging other suspected members to surrender while they continued to investigate the matter. 

The developments are following the claim by ShinyHunters that a job portal breach had taken place. As claimed by the group, it obtained a significant amount of sensitive information from FBI systems. Particularly, it claimed to have acquired employee information, though the extent of the alleged theft has yet to be independently verified. During Khader's reported detention, the group's online activity was also disrupted. 

In addition to the disappearance of the group's data leak website, an account previously used to communicate with journalists no longer responded. Later, another ShinyHunters leak site appeared, indicating the group may continue to conduct activities. Moreover, Khader's reported cooperation strengthens the investigation, which has already been conducted by several individuals associated with the ShinyHunters network in general. 

Khader's identity was previously associated with the group until the latest detention was made. It has been reported that Brian Krebs identified Khader as a member of the Scattered Lapsus$ Hunters umbrella operation in 2025, which is affiliated with ShinyHunters, Lapsus$, and Scattered Spider. Aside from being linked to the HellCat leak site and BreachForums hacking forum, Khader had previously asserted that he was cooperating with law enforcement and had ceased all data theft and extortion activities. Those claims were not independently verified. 

While this was the case, ShinyHunters continued to conduct attacks in 2026, including attacks on Rockstar Games as well as Canvas, which disrupted schools across the country. Despite this, the group has continued to engage in data theft and extortion operations. ShinyHunters has recently begun targeting cloud-based services as well as third-party providers, resulting in incidents that are linked to organizations such as Google, Cisco, and Pornhub.

ShinyHunters has also been linked to the May 2026 breach involving Instructure Canvas, while previous investigations have resulted in arrests related to Snowflake-related attacks, PowerSchool and Breached hacking forums. It may be possible for investigators to gain a better understanding of how this loosely organized network operates and who remains active within it through the recent arrests. 

It has been reported that FBI agents have indicated that information obtained from arrests and seized infrastructure may be useful for identifying additional participants. However, the appearance of a new ShinyHunters leak site following the earlier closure indicates that the organization has not been completely dismantled. Furthermore, the case illustrates the difficulty of disrupting cybercrime groups that are built upon informal networks rather than a rigid organizational structure. 

According to Reuters, investigations and prosecutions can become complicated by the young age of some suspects, the fluid nature of related groups, and the limited cooperation of victims. While ShinyHunters' continued online activity suggests that law enforcement efforts are ongoing, the reported detention and cooperation may provide investigators with valuable insight into ShinyHunters' wider network.

Bitget Hack Climbs to $387.5 Million as Exchange Launches Recovery Bounty and Points to North Korea

 



Crypto exchange Bitget confirmed on September 25 that hackers stole approximately $387.5 million from its hot and warm wallets a day earlier, revising an initial estimate upward as investigators traced funds across multiple blockchains and accounting for assets on Zcash and TRON that were missed in the first tally. The exchange has since launched a structured bounty program for anyone who helps freeze or recover stolen funds, and has brought in independent cybersecurity firms Mandiant and SlowMist to assist with the investigation.

Bitget's security systems first flagged the unauthorized transfers at 18:31 UTC on September 24. By the time the exchange confirmed the breach publicly, the damage figure had already reached $351.6 million. The revised total of $387.5 million reflects a more complete accounting of transfers that occurred during the incident, adding affected assets on Zcash and TRON not captured in the initial estimate. The exchange confirmed no further unauthorized transfers occurred after the incident was contained.


How the Attack Worked

Bitget CEO Gracy Chen clarified that attackers did not steal private keys or forge user withdrawal requests. Instead, they broke into a backend system inside Bitget's wallet infrastructure and used it to spoof transaction data, tricking the exchange's own authorization process into approving payouts that looked routine.

The mechanics were methodical. The attacker's first transfer was a small 0.84 ETH test payment to a fresh address, after which Bitget's main Ethereum hot wallet made roughly 380 transactions during the attack. Every time the hot wallets refilled from the warm wallet layer, the attacker drained them again. The warm wallet, which normally only pays the exchange's own hot wallets, sent 13,966 ETH worth approximately $37 million to an address less than an hour old, with no approved list check and no secondary authorization on a wallet holding over $40 million.

The single largest piece of the haul was roughly 103 million XRP, valued at approximately $157 million at the time of the theft. About $75 million of the stolen funds were held in stablecoins including USDT and USDC.

Some of that ETH moved quickly into mixers: on-chain analysis shows around 6,300 ETH, close to $19 million, funneled through Tornado Cash within hours of the breach.

The confirmed affected assets span XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX, spread across Ethereum and several EVM-compatible networks, the XRP Ledger, Zcash, and TRON.


User Funds and the Protection Fund

Bitget operates a three-tier wallet architecture, and the breach touched only portions of the hot and warm wallet layers. Cold wallets remained fully secure throughout the attack. Bitget's User Protection Fund, which holds more than $464 million, will cover the full loss, meaning customer account balances stay intact even though the funds themselves were taken. The protection fund was set aside in 2023 specifically to cover hacks and theft so users would not absorb the impact.


North Korea in the Frame

During a three-hour livestream on X, CEO Gracy Chen said Bitget suspects North Korean attackers exploited the backend authentication system, making fraudulent withdrawals appear legitimate. Chen added that she has personally been targeted by the same group before, losing about $80,000 from a personal wallet unconnected to Bitget. North Korea's Lazarus Group, also tracked under the codename TraderTraitor, has been blamed for the industry's biggest thefts, including Bybit's $1.4 billion hack in February 2025, which the FBI confirmed weeks later was North Korean work.


The Recovery Bounty

Bitget has launched a Recovery Bounty Program covering eligible voluntary actions that have already resulted in affected funds being frozen, as well as future actions that directly contribute to freezing or recovering funds. The structure is straightforward: 5% of successfully frozen funds goes to the eligible person or entity whose efforts directly caused the freeze, and 5% of successfully recovered funds is available on the same terms. Bitget will also use Bybit's LazarusBounty initiative as a core channel for the effort.

To support the hunt, Bitget published a real-time fund tracing dashboard at trace.bgblockchain.xyz, an API tracking attacker-controlled addresses updated continuously, and a submission portal for anyone with freezing or recovery information. Exchanges, stablecoin issuers, bridges, custodians, and other infrastructure providers have been encouraged to monitor the flagged addresses and report relevant information through the recovery portal.

The attack is the largest cryptocurrency breach of the year to date and lands in an already turbulent stretch for the industry. Earlier in September, Liquid Network suffered a $319 million security breach, and in late July, hardware wallet maker Coldcard was hit in a separate incident that drained around $116 million in Bitcoin.

Bitget said it will publish a full incident report including root-cause analysis once technical teams complete remediation. Withdrawal restoration was expected to be announced by September 26, 4:00 AM UTC.


$13 Billion in Losses Since 2023, Treasury Asks Banks to File Cyber Scam Reports


The federal government has asked financial organizations to be more careful in detecting and reporting scams done by overseas scammers. 

The Treasury Department’s Financial Crimes Enforcement Network (FinCEN) launched and alert to the financial industry besides a detailed study of over 33,000 cyber fraud cases reported between September 2023 and December 2025. According to the report, around $12.7 billion was stolen in a cryptocurrency investment scam from American victims in the US.

As per Treasury Department official Gene Lange, “The transnational criminal organizations behind these scams exploit both emerging technologies and human vulnerabilities, resulting in devastating financial losses for innocent American victims.”

The report is prepared on the basis of reports given by around 1,300 financial organizations and is linked to a 2023 alert from the Treasury about pig butchering scams. FinCen discovered that the rate of scam operations is rising as the schemes go beyond centers in Laos, Myanmar, and Cambodia. 

Scammers use distinct profiles, from financial adviser to romantic partner, and force people into sending money, either via cryptocurrency or with traditional bank transfers.

Significant reports were received from cryptocurrency firms, which found around $5.5 billion in suspicious scam activity. 

Traditional banks reported around $6.4 billion in possible friends, saying they “often detected schemes when a victim sent funds to an [financial institution] in the digital asset sector to purchase digital assets, or when a customer sent a wire transfer to a scam-affiliated beneficiary, frequently referencing digital asset investments.”

The report finds that few victims sent applications for second mortgages and loans as part of their involvement in a scam.

More financial institutions note thousands of incidents where targets liquidated their investment accounts to try wiring transfers or fund digital assess to scammer-related accounts. According to the report, “[A financial institution] involved in the digital assets sector reported an older adult victim transferred nearly $640,000 from her retirement fund to send to a suspected scammer in connection with an apparent digital asset investment scheme.”

“The victim stated she met an individual over social media who instructed her to invest in an apparently fictitious digital asset-related company.”

Another victim took out around $150,000 from his retirement account, withdrew credit on his home, and withdrew a personal loan to send the money to a scammer who pretended to be his digital romantic partner, and wanted to invest the money in a venture.

The filings noted the use of coins like USD Coin (USDC), Ethereum, and Tether (USDT), but 18 more coins were found in the reports.

US Disrupts Xinbi Guarantee Marketplace Linked to Cyber Scams

 

A Telegram-based marketplace known as Xinbi Guarantee has been sued by U.S. authorities for providing services to scam centers engaged in cyber fraud and money laundering. This operation involved seizing Telegram channels and cryptocurrency wallets connected to the marketplace, as well as freezing digital assets worth more than $52 million. 

A U.S. Department of Justice announcement was made in conjunction with a broader operation led by the Scam Center Strike Force. Authorities also deployed teams to Madagascar to support the disruption of 13 scam compounds that were allegedly operated by Chinese organized crime groups. According to the Justice Department, approximately $52 million in cryptocurrency tied to scam-related money laundering has been restrained in a single day.

The strike force has therefore restrained about $938 million in total assets. The Xinbi Guarantee platform became a major marketplace for the cybercrime ecosystem after other similar services, such as HuiOne Guarantee and Tudou Guarantee, were discontinued. Through the use of Telegram, the platform enabled scam operators to connect with vendors providing services required for large-scale fraud schemes. 

As reported by the marketplace, services offered include the creation of fraudulent investment sites, the laundering of proceeds from wire fraud, and recruitment of individuals for scam compounds in Southeast Asia. Additionally, Xinbi served as an intermediary, holding payments until vendors completed the requested services. Using blockchain analytics, Elliptic identified and frozen wallets holding $52.8 million in Tether's USDT stablecoin in coordination with the United States Secret Service. 

According to Xinbi's estimates, it has processed approximately $30 billion in transactions since its emergence around 2022, ranking among the top illicit marketplaces to date. Also linked to U.S. sanctions are entities involved in this marketplace. 

A US Treasury official indicated that Xinbi's infrastructure had been used by North Korean hackers and sanctioned groups related to the Prince Group. Two cryptocurrency wallets containing approximately $12 million were seized from Xinbi that were used to receive vendor payments directly. In addition, two companies accused of supporting Xinbi's operations were sanctioned. 

SafeW Technology of Singapore was sanctioned based on its role as a provider of encrypted communications, whereas Anwen Technologies of Cambodia was sanctioned for its association with XinbiPay, also known as NewPay, an application for digital wallets. 

It was discovered by blockchain intelligence firm TRM Labs that Xinbi's network offers a wide range of services, including stolen personal information, counterfeit identification documents, artificial intelligence-driven deep fake tools, satellite internet equipment and over-the-counter cryptocurrency exchanges. These services provided scam groups with the technical and financial resources necessary for large-scale fraud campaigns.

According to TRM Labs, Xinbi may have handled more than $36 billion in transactions, higher than the U.S. government estimate of over $24 billion. As a result of the decline in HuiOne Guarantee and Tudou Guarantee, daily inflows almost doubled between May and December 2025, according to the firm's analysis. 

Elliptic reported Xinbi appeared offline in response to the latest action, and Telegram removed its main channels and banned the platform's usernames, thereby negatively affecting the marketplace's online presence. This disruption poses a direct threat to a marketplace that relies on communication channels, vendor connections, and cryptocurrency payments for its operation. 

A larger U.S. effort is being made to disrupt the infrastructure underlying Southeast Asia's scam economy. The Scam Center Strike Force has expanded its activities beyond financial seizures, with teams sent to Madagascar to assist with the closure of 13 scam compounds allegedly operated by Chinese criminal groups. 

In addition to drawing attention to the financial threat, the U.S. government has also emphasized its scale. During 2024, Americans lost at least $10 billion to scams originating from Southeast Asia, according to a March report published by the U.S.-China Economic and Security Review Commission; losses are expected to increase in 2025. The commission noted that criminal groups are maintaining their operations in spite of enforcement efforts by using advanced technology and cryptocurrency. 

Separate investigations conducted by the House Select Committee on China have indicated that scam compounds in Cambodia and Myanmar are part of a larger criminal ecosystem which includes money laundering, cyber fraud, and human trafficking. 

The findings show that online scam operations are increasingly supported by interconnected financial, technological, and physical infrastructures rather than isolated fraud groups. An action against Xinbi Guarantee demonstrates the growing focus on dismantling the financial, technological, and communication infrastructure that supports large-scale cyberfraud schemes.

Browser Memory Becomes New Target in JavaScript Malware Campaign


 

Security researchers have discovered a large-scale malvertising campaign that uses fake cryptocurrency and trading websites to assemble malware inside the web browser of the victim, making it increasingly difficult to detect using traditional security tools. 

A security firm named Confiant claims the operation has been in operation since late 2024 and primarily targets retail traders and cryptocurrency investors in 12 countries. Asia-Pacific and Latin America regions are particularly targeted. In addition to supporting 25 languages, the campaign employs sophisticated filtering techniques to prevent researchers, automated scanners, and security bots from reaching malicious sites, as well as redirecting researchers and automated scanners to harmless blank pages to avoid damage. 

Security researchers, automated scanners, and bots are served empty pages before the fake websites are displayed in order to determine whether or not the users are legitimate targets. In contrast, retail traders and cryptocurrency investors receive convincing replicas of legitimate platforms when using selective filtering. By doing so, routine security scans are significantly reduced in the likelihood of detecting the infrastructure. 

Users are presented with websites that appear legitimate that offer software downloads by impersonating popular platforms such as Solana, Luno, and TradingView. By utilizing JavaScript techniques, the websites construct malware locally within the victim's browser memory rather than delivering a malicious file directly to the victim. It is said that the browser acts as a "local assembly pipeline" because it is capable of assembling malware rather than downloading a complete executable file.

As part of the attack, a Service Worker is registered to manage the download process, whereas a SharedWorker is created directly from JavaScript embedded within the webpage, so that the source code does not appear as a separate network request. 

After receiving the configuration file, the worker requests instructions for assembling the malware, including a template, randomized session values, and instructions. Each download is uniquely generated based on randomized parameters, thus producing a unique file hash for each victim. By utilizing this approach, the malware can bypass static detection methods that depend upon identifying known file signatures. 

Browsers download legitimate Bun runtimes from a secondary domain as part of the assembly process, and they combine them with attacker-controlled executable components and locally generated data as part of the assembly process. Since Bun is a legitimate component for building standalone Windows applications, attackers exploit this feature to disguise the final executable. 

Each session generates a unique file hash based on a random seed and file size, reducing the effectiveness of hash-based malware detection. By delivering the executable through the same domain that the website uses, the download appears legitimate from the browser's perspective, so that the download appears legitimate. 

Despite receiving Microsoft's Mark-of-the-Web security tag, network-based detection and forensic analysis are significantly more difficult without a fully transmitted malicious file. According to Confident, earlier versions of the campaign, tracked as SourTrade, used the open-source StreamSaver project to deliver malware.

Since April 2026, however, the operators have switched to using more sophisticated Service Worker-based delivery mechanisms. Researchers did not publicly identify the malicious payload for this campaign, but they linked it to Bitdefender's previous findings, which documented malware capable of intercepting internet traffic, stealing passwords and browser cookies, logging keystrokes, capturing screenshots, harvesting cryptocurrency wallet data, and maintaining persistence on compromised systems for a period of time. 

A Confident representative noted that the campaign does not exploit browser vulnerabilities or bypass Microsoft's Mark-of-the-Web (MotW) security features. Instead, it utilizes legitimate browser capabilities to deliver malware without transmitting a full executable over the network. In addition, researchers noted that there is currently no software patch available for this technique, which requires users to remain aware of and to practice safe software downloading practices to protect themselves. 

Earlier versions of the campaign used the open-source StreamSaver project hosted on GitHub to facilitate malware downloads, allowing investigators to trace its evolution from earlier versions. The operators replaced that approach in April 2026 with a Service Worker-based download mechanism, which encapsulates the entire delivery process within the impersonated website, making it increasingly difficult to analyze the network and detect malware. 

A security expert recommends downloading cryptocurrency and financial software from official vendor websites, avoiding sponsored advertisements or social media promotions, and verifying the digital signature and publisher of the application before installation. In light of the increasing stealthy techniques used by attackers to compromise users, these precautions remain critical. In light of the increasing sophistication of cybercriminals' malware delivery techniques, campaigns such as SourTrade underscore the challenges that defenders face. 

Through the use of legitimate browser functionality in order to assemble malware locally, attackers are able to bypass many traditional detection methods. It is recommended that you only download software from legitimate sources, verify digital signatures, and be wary of sponsored advertisements and promotional links relating to cryptocurrencies and financial institutions.

AI Is Fueling a New Wave of Cybercrime

 

Cybercriminals are increasingly turning to artificial intelligence, and the biggest barriers that once slowed adoption are rapidly disappearing. According to a recent Axios report, restricted access to models, high costs, and limited incentive to change old hacking methods are no longer holding attackers back. Open-weight AI models are becoming powerful enough to rival mainstream systems in some cyber tasks, while underground marketplaces are offering jailbroken tools, custom-built models, and AI-powered hacking services. That mix is making AI more practical for criminal use than ever before. 

The shift matters because hackers are no longer just experimenting with AI in isolated tests. They are now weaving it into existing workflows to speed up ransomware, fraud, phishing, and cloud intrusions. Axios cites recent cases showing how attackers are using AI to generate exploit code, steal data, and even negotiate with victims. In one example, a lone hacker used AI agents to automate most of a ransomware attack. In another, AI helped compress a cloud attack that would normally take weeks into just 72 hours. 

Researchers also say the threat is spreading across different types of crime. A separate case described by Axios involved a bank fraud scheme targeting Mexico-based financial organizations, where AI-generated malware played a role in the attack chain. These incidents suggest criminals are learning how to blend AI with traditional tactics instead of replacing human hackers entirely. That makes the attacks harder to predict, because AI is being used as an accelerator rather than a standalone weapon. 

For defenders, the most serious problem is time. AI is helping attackers move faster, which leaves organizations with fewer hours to detect suspicious behavior, investigate compromises, and patch weak spots before damage spreads. Security teams that once had days or weeks to respond may now have only a narrow window. That raises the pressure on companies to monitor systems more closely, strengthen access controls, and prepare for attacks that are increasingly automated and adaptive.

The broader message is clear: AI is lowering the cost and complexity of cybercrime while increasing the scale and speed of attacks. What once required a skilled team and long preparation can now be compressed into a shorter, more efficient operation. As criminal adoption grows, the cybersecurity industry will need to match that pace with faster detection, stronger resilience, and better incident response.

Boko Haram Used AI Chatbots to Support Attacks, Cambridge Study Finds

 

Boko Haram has reportedly exploited mainstream AI chatbots to support terror operations, according to a Cambridge University study cited by the South China Morning Post. The research suggests the group used both US and Chinese AI tools for bomb-making, attack planning, propaganda, and day-to-day operational support. 

The study is based on interviews with 27 former Boko Haram members in northeast Nigeria, giving researchers a rare inside look at how the insurgent group adapted to new technology. Former fighters said AI tools were used to answer practical questions about weapons, tactics, surveillance, and movement, showing that the technology was not used only for messaging or recruitment. 

One of the most concerning findings is that Boko Haram reportedly organized internal AI training and created specialized units to help members use chatbot systems more effectively. The report says outside trainers, likely linked to the Islamic State network, helped members learn how to use AI tools with VPNs and encryption software, while also teaching ways to bypass built-in safety restrictions. 

Researchers said the group used AI for operational tasks such as bomb construction, improving attacks, and troubleshooting weapons. Former commanders described using chatbots to solve battlefield problems, including how to modify motorcycles for raids and how to increase the destructive power of improvised explosives. This suggests that extremist groups are no longer treating AI as a novelty, but as a repeatable support system for violence. 

The findings raise a broader security concern for governments and AI companies. If militant groups can regularly extract harmful guidance from consumer chatbots, then safety filters alone may not be enough to stop misuse. The study also strengthens calls for tighter international coordination, especially between the US and China, because the major AI systems being exploited are built in those two countries. As AI becomes more advanced and more accessible, the risk is not just misinformation or fraud, but the possibility that extremist groups will use it to become faster, better organized, and harder to stop.

US Sanctions VPN Provider and Malware Service Operator Accused of Supporting Ransomware Campaigns

 



The US Department of the Treasury's Office of Foreign Assets Control (OFAC) has imposed sanctions on a virtual private network (VPN) provider, its administrator and a Belarusian malware service operator, accusing them of supplying infrastructure and tools that helped ransomware groups carry out attacks against organisations across the United States.

The sanctions target First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and Belarusian national Yegeniy Vladimirovich Silayev. US officials say the three played key roles in supporting the wider ransomware ecosystem by providing services that allowed threat actors to conceal their identities, evade security tools and sustain cybercriminal operations.

According to the Treasury Department, 1VPNS has been operating since 2014 and openly marketed its services on cybercrime forums frequented by ransomware operators and other malicious actors. The VPN provider reportedly promoted a strict no-logs policy, claiming it did not retain records of users' online activity or identities and would not cooperate with law enforcement requests. Investigators allege these assurances made the service particularly attractive to cybercriminals seeking to obscure their activities.

Authorities also accuse Rashevskyi of using fraudulent identities, including the aliases "Maksim Sorin" and "Roman Chabanenko," to obtain internet infrastructure from service providers that would otherwise have declined to host the operation because of repeated abuse complaints. Officials say the use of false identities enabled the VPN service to continue operating despite growing scrutiny from infrastructure providers.

The sanctions follow a multinational law enforcement operation that dismantled 1VPNS earlier this year. In May, European authorities, working alongside the FBI's Boston Field Office, seized the service's website and infrastructure as part of Operation Saffron, a coordinated investigation led by French and Dutch law enforcement agencies.

The investigation into 1VPNS began in December 2021, when authorities successfully infiltrated the VPN provider's infrastructure. Investigators quietly gathered intelligence, including access to the service's customer database, before ultimately dismantling the operation after several years of surveillance and evidence collection.

During the coordinated enforcement action, authorities seized 33 servers spread across 27 countries, arrested the service's administrator and identified thousands of users allegedly linked to ransomware operations, online fraud and other forms of cybercrime. Europol previously stated that 1VPNS had appeared in nearly every major cybercrime investigation it supported, underscoring the service's alleged role within the broader cybercriminal ecosystem.

US officials said organisations affected by ransomware attacks involving infrastructure provided by 1VPNS included businesses, hospitals, financial institutions and municipal governments. These sectors have increasingly become frequent targets of ransomware campaigns because operational disruption often places significant pressure on victims to pay extortion demands.

In a separate but related action, OFAC also sanctioned Silayev for allegedly developing and selling cryptors, also known as crypters, to cybercriminals. Cryptors are specialised software tools designed to modify malware so that it appears different to security products, making malicious code significantly harder for antivirus software and endpoint detection systems to identify. While cryptors do not carry out attacks themselves, they are widely used to help ransomware and other malware bypass detection during deployment.

The Treasury Department estimates that ransomware operations using services provided by 1VPNS and malware protected by Silayev's cryptors have collectively contributed to billions of dollars in losses suffered by US businesses and operators of critical infrastructure.

In announcing the sanctions, State Department spokesperson Thomas Pigott said the designated individuals supplied ransomware groups with services that concealed their identities, disguised malicious software and helped attackers avoid detection, ultimately enabling campaigns responsible for billions of dollars in damages. Pigott added that the United States and its international partners are increasingly focusing not only on ransomware operators themselves but also on the infrastructure providers and service suppliers that make these attacks possible.

The sanctions were coordinated with the United Kingdom's Foreign, Commonwealth and Development Office as part of a broader international effort to disrupt cybercriminal networks. Under OFAC sanctions, any property or financial interests belonging to the designated individuals or entities that fall under US jurisdiction are blocked. In addition, US individuals and organisations are generally prohibited from engaging in transactions involving the sanctioned parties.

The action forms part of a wider strategy aimed at disrupting the ransomware supply chain by targeting the businesses and technical service providers that support cybercriminal operations. Rather than focusing exclusively on the attackers who deploy ransomware, governments are increasingly using financial sanctions, infrastructure seizures and international law enforcement cooperation to dismantle the broader ecosystem that enables these campaigns.

The sanctions were announced as the European Union and the United Kingdom also introduced coordinated sanctions against dozens of Russian individuals and entities accused of supporting a network of hacking groups responsible for cyberattacks across Europe, reflecting continued international efforts to increase pressure on organisations and individuals believed to facilitate malicious cyber activity.

Sri Lanka Treasury’s USD 2.5 Million Loss Ruled Cybercrime Fraud

 

Sri Lanka’s recent finding that a USD 2.5 million Treasury loss was the result of cybercrime highlights how vulnerable government financial systems have become in the age of digital debt repayments. The case underlines that cybersecurity failures are no longer just technical glitches; they now directly translate into sovereign-level financial and reputational risks. 

In this incident, hackers infiltrated official communication channels linked to Sri Lanka’s Finance Ministry and Treasury during a foreign debt repayment to Australia. By compromising email systems in the Public Debt Management or related units, the attackers were able to alter payment instructions so that funds intended for a legitimate creditor were instead wired to accounts controlled by cybercriminals. The money formed part of a larger bilateral repayment package, but the redirected USD 2.5 million simply never reached the intended recipient, exposing serious weaknesses in verification and authorization workflows inside the ministry. 

A parliamentary oversight body, the Committee on Public Finance (COPF), was tasked with investigating the diversion and has now formally ruled it a cybercrime-driven fraud, not a technical debt default or routine accounting error. The panel’s report points to operational lapses within the ministry rather than a single rogue actor, suggesting that controls around email, payment approvals, and cross-checking beneficiary details were either inadequate or poorly enforced. Questions around possible internal collusion were raised in political debate, but COPF stressed that its mandate was limited to financial and procedural review, leaving any deeper criminal probe to law enforcement and cybersecurity agencies. 

For Sri Lanka, the stakes go beyond the immediate financial loss. The episode has unfolded in parallel with ongoing debt restructuring and negotiations with international creditors, making any hint of default or mismanagement politically sensitive. Officials have emphasized that creditors are likely to treat the incident as cyber fraud rather than a failure to honor obligations, yet the breach still damages confidence in the state’s ability to protect critical financial infrastructure. It also illustrates how attacks on public finance systems can ripple out into diplomatic relations, market perceptions, and domestic political narratives. 

The COPF report calls for stronger cybersecurity, a special audit of foreign debt repayment processes, and upgrades to public debt management systems so similar attacks can be detected and blocked early. For governments worldwide, the Sri Lankan case is a warning that protecting payment systems, official email, and inter-agency workflows is now a front-line national security issue, not a back-office IT concern. As cybercriminals increasingly target high-value sovereign transactions, robust multi-layer verification, staff training, and real-time threat monitoring must become standard practice in every finance ministry.

UK Warns Parents: Limit Online Sharing of Kids’ Photos Amid AI Abuse Risks

 

UK authorities have issued urgent warnings to parents about sharing children’s photos online, as AI tools increasingly enable digital abuse and exploitation. The National Crime Agency (NCA) and the Internet Watch Foundation (IWF) say that ordinary images of kids can be misused by predators to create realistic, sexually explicit material using “nudification” apps and deepfake technology. While officials stress they are not dictating parenting choices, they want families to understand a risk that many may not realize exists. 

The scale of the problem is growing fast. In 2025, the IWF identified 8,029 AI-generated images and videos classified as realistic child sexual abuse material (CSAM), a 14% rise from the previous year. AI-generated abuse videos jumped from just 13 in 2024 to 3,440 in 2025, showing how quickly the threat is escalating as imaging models improve. Because these fakes can be so convincing, it is becoming harder for platforms and investigators to distinguish them from real abuse content, complicating removal efforts and victim support. 

In response, the NCA and IWF have published new guidance urging parents and carers to limit who can see images of their children online. Their advice includes setting social media accounts to private, using “close friends” lists for sharing family photos, and regularly reviewing older posts that might expose children’s images to strangers. The guidance also recommends a “social media audit,” asking parents to check whether a child’s face, body, or school uniform is visible online and whether those images can be deleted or made private. The NSPCC similarly advises that minors keep their social media profiles on private settings to reduce exposure. 

The UK government is also tightening laws and platform responsibilities. It has made it illegal to create, possess, or distribute AI tools designed to generate child sexual abuse imagery, with offenders facing up to five years in prison. Under the Online Safety Act, tech platforms must proactively remove such content, and new powers will allow authorized testers to assess AI models for their ability to produce CSAM before they reach the market. A government spokesperson confirmed that AI-generated CSAM is treated the same as real imagery under UK law and must be taken down swiftly. 

Beyond privacy settings, experts recommend open conversations with young people about AI, “deepfake” nudes, and image consent. Children should understand that once a photo is online, it can be copied, altered, and misused—even if they trusted the original audience. Guidance also outlines steps to take if a child is targeted or if manipulated images appear, including reporting to platforms and contacting the IWF or police. As AI continues to turbocharge digital abuse risks, cautious sharing and strong privacy habits are becoming essential parts of modern parenting.

ED Charge Sheet Maps Sriki's Darknet Crypto Laundering Network

 

The Enforcement Directorate (ED) has filed a sprawling 3,500-page prosecution complaint before a special PMLA court in Bengaluru, laying out what it calls a “sophisticated network” blending high-level hacking, darknet operations, cyber extortion and multi-crore cryptocurrency laundering. The charge sheet names serial hacker Srikrishna Ramesh, alias “Sriki”, crypto trader Robin Khandelwal, businessman Sunish Hegde, a private IT firm and two of its officials as accused in a case that spans breached government portals, crypto exchanges and online gaming platforms. 

From government portals to poker sites: the alleged breach chain 

According to the ED, Sriki, described as a highly skilled software programmer, exploited vulnerabilities in national and international cryptocurrency exchanges, online gaming and poker platforms, and corporate servers. He is accused of breaching the Karnataka government’s e-procurement portal and siphoning off about ₹11.5 crore in two transactions, besides hacking the Unocoin exchange and several major online poker platforms. The agency alleges that stolen virtual digital assets such as Bitcoin were then “layered” and offloaded through multiple international crypto platforms to obscure their origin.

The prosecution complaint details how Robin Khandelwal allegedly acted as a key conduit, converting illicit digital assets into fiat currency through over-the-counter deals and crypto-trading channels. Investigators claim Sunish Hegde conspired with Sriki to extort money from hacked companies by negotiating with them after the breaches, while Infinzy Solutions and two officials are accused of facilitating the transfer of funds stolen from a poker site. The three main accused were arrested in May and are in judicial custody at Parappana Agrahara Central Prison, with the ED citing digital evidence, blockchain analysis and bank records to support its case. 

 Darknet links and ongoing money trail probes 

The 3,500-page document reportedly sketches connections between Sriki’s hacking operations and darknet marketplaces, building on earlier investigations that noted his use of the darknet to purchase drugs using Bitcoin. About ₹7 crore of the ₹11.5 crore siphoned from the e-procurement portal has been traced, with around ₹2 crore formally attached and another ₹5 crore frozen in various bank accounts; the remaining ₹4.5 crore is still being tracked. The ED says its probe into the movement and use of the alleged proceeds of crime is continuing, even as the prosecution complaint functions as the equivalent of a police charge sheet under PMLA. 


For regulators, the Sriki case underscores how advanced technical skills, weak spots in government and corporate platforms, and an evolving crypto ecosystem can intersect to create large-scale financial crime. The dossier highlights the need for stronger blockchain forensics capacity, tighter oversight of informal crypto-OCT channels, and better coordination between cybercrime units, the ED and financial intelligence agencies. As India’s digital economy expands, securing e-governance portals, exchanges and gaming platforms is becoming not just an IT issue, but a core element of financial integrity and national cybersecurity strategy.

FCRF Launches India’s Largest Cybercrime Hackathon for 2026

 

The Future Crime Research Foundation (FCRF) has announced what is being positioned as India’s largest cybercrime hackathon, a move that reflects the growing urgency around digital threats in the country. With cyber fraud, phishing, ransomware, and AI-driven deception becoming more sophisticated, the event aims to create a space where innovators can build practical solutions for real-world investigation and defense. Unlike ordinary coding contests, this hackathon is expected to focus on cybercrime response, digital forensics, and applied security ideas that can help law enforcement and security professionals. 

FCRF, an IIT Kanpur-incubated non-profit known for its work in cyber safety, training, and fraud risk management, has built a reputation as a serious player in India’s cybersecurity ecosystem. Its broader mission is to make India more resilient against evolving digital risks through research, awareness, and capacity building. The hackathon fits neatly into that mission by inviting participants to think beyond theory and build tools that can support investigations, evidence analysis, and cyber defense operations. 

The event is also notable for the kind of collaboration it encourages. By bringing together students, researchers, ethical hackers, developers, and cyber professionals, the hackathon creates a multidisciplinary environment where ideas can move quickly from concept to prototype. That matters because today’s cybercrime problems are no longer limited to one domain; they involve fake identities, financial fraud, social engineering, malware, and emerging AI threats. A challenge of this kind can help discover solutions that are both technically strong and operationally useful. 

For participants, the opportunity goes beyond competition. Hackathons like this can serve as launchpads for careers in cybersecurity, digital forensics, threat intelligence, and policy research. They also offer exposure to problem statements that mirror the pressure and complexity of real cyber investigations. In a country where digital adoption is expanding rapidly, events that combine innovation with public safety can play an important role in strengthening the national security ecosystem.

As FCRF continues to expand its influence through initiatives such as the FutureCrime Summit, this hackathon adds another layer to its growing impact. It signals a shift in how India is approaching cybercrime: not only by reacting to incidents, but by building talent and tools before attacks happen. That makes the event important not just as a competition, but as a serious step toward a more prepared and cyber-aware India.

Poland arrests four suspects in international SIM-swapping operation linked to multimillion-dollar cryptocurrency thefts

 



Polish law enforcement authorities have arrested four suspected members of an organized cybercrime group accused of orchestrating intricate SIM-swapping attacks that allegedly enabled the theft of millions of dollars in cryptocurrency from victims. The coordinated operation was led by Poland's Central Bureau for Combating Cybercrime (CBZC) with operational assistance from the U.S. Federal Bureau of Investigation (FBI) and Homeland Security Investigations (HSI), highlighting the cross-border nature of the investigation.

According to investigators, the group combined technical intrusions with social engineering techniques to compromise organizations working alongside telecommunications providers. By infiltrating partner infrastructure and gaining unauthorized access to employee email accounts, the suspects allegedly obtained sensitive information that enabled them to perform fraudulent SIM-swapping attacks.

A SIM-swap attack involves transferring a victim's mobile phone number to a SIM card controlled by an attacker. Once the transfer is completed, the attacker can intercept SMS messages, one-time verification codes, password reset requests, and other communications that rely on the victim's phone number for authentication.

Authorities allege that after taking control of victims' mobile numbers, the cybercriminals intercepted SMS-based authentication messages and email communications before using that access to seize control of cryptocurrency exchange accounts. The attackers then transferred digital assets from compromised accounts before attempting to conceal the proceeds through an extensive laundering operation.

Investigators estimate that the criminal scheme generated millions of U.S. dollars in stolen cryptocurrency. The illicit proceeds were allegedly moved through a distributed financial network consisting of multiple domestic and international bank accounts, international payment platforms, and multi-currency digital wallets in an effort to obscure the origin of the funds. Polish authorities estimate that the total amount laundered exceeded tens of millions of Polish złoty, equivalent to at least approximately US$5 million based on current exchange rates.

In a statement describing the operation, CBZC said the suspects relied on specialized software together with social engineering techniques to gain unauthorized access to infrastructure belonging to organizations cooperating with telecommunications operators, as well as employee email accounts. Investigators said the information obtained during those compromises enabled the illegal cloning and takeover of victims' phone numbers through SIM-swapping attacks.

Authorities further stated that the suspects allegedly treated the criminal enterprise as a continuous source of income, repeatedly moving stolen assets across numerous financial accounts and cryptocurrency wallets located in multiple jurisdictions to complicate financial tracing efforts.

All four suspects have been placed in pre-trial detention. They face allegations including participation in an organized criminal organization, unauthorized access to information systems to facilitate theft, and money laundering. If convicted, the offenses carry penalties of up to 25 years' imprisonment under Polish law.

While Polish authorities have not publicly identified the individuals arrested because of the ongoing international investigation, blockchain investigator ZachXBT claimed that one of the detainees is Wojtek Kulisz, also known online by the alias "Merry." The identification was reportedly based on items visible in official footage released during the police operation. Authorities have not independently confirmed that claim.

Investigators have also declined to disclose which cryptocurrency exchanges were affected or identify the victims, citing the continuing international investigation. Law enforcement agencies say efforts to identify additional victims, trace stolen assets, and pursue further investigative leads remain ongoing.

The case stresses the urgency of the risks associated with SMS-based authentication. Security professionals have long advised cryptocurrency investors and organizations to replace SMS-based two-factor authentication with authenticator applications or hardware security keys whenever possible, as SIM-swapping attacks remain an effective method for bypassing text message verification when attackers successfully compromise telecommunications systems or manipulate carrier processes.

Ransomware Gangs Splinter as Cyber Threat Becomes More Volatile

 

Cybercrime is moving through a major reset as the ransomware world shifts away from big, organized cartels and toward smaller, more volatile splinter groups. Speaking at Infosecurity Europe 2026, William Lyne, Head of Economic and Cybercrime at the Metropolitan Police Service, said the underground market has become a highly accessible ecosystem where criminals can buy tools, services, and stolen data with ease. He described it as a place where threat actors can get almost everything they need, except a good drink. 

The biggest driver behind this change is convenience. Cryptocurrencies have removed one of the oldest bottlenecks in cybercrime by making it much easier to cash out illegal profits, while underground marketplaces now provide ransomware kits, phishing services, infrastructure, and support on demand. That lower barrier to entry has blurred the old lines between hacktivists, criminal gangs, and state-linked actors, creating a blended threat environment that is far more crowded and harder to police.

Lyne warned that law enforcement crackdowns are also reshaping the market. When large, centralized groups such as LockBit are disrupted, their affiliates do not disappear; they scatter into smaller factions, each trying to rebuild revenue streams in a less visible way. The result is a more fragmented and “post-trust” criminal scene, where weaker internal controls and looser coordination can make attackers more aggressive, reckless, and unpredictable. 

The threat is also becoming more global. Lyne said the ransomware ecosystem is no longer dominated by traditional Russian-speaking hubs, with actors now emerging from Brazil, Türkiye, and English-speaking groups such as Scattered Spider. At the same time, criminals are increasingly using AI to search through hoarded corporate data, turning old thefts into fresh extortion opportunities and new monetization schemes. 

For police and security teams, the response must go beyond arrests alone. Lyne said the Met Police cannot “arrest its way out” of the problem and instead needs to focus on disrupting infrastructure, weakening trust inside criminal networks, and working more closely with private-sector defenders. In practical terms, that means security teams should expect a ransomware landscape that is smaller in structure but sharper in impact, where fragmented gangs may strike faster and with fewer rules than the cartels they replaced.

Crypto Exploit Losses Plummet 90% in May to $68.3 Million as Thieves Hit Security Wall

 

Crypto thieves are hitting a major wall, with exploit losses plunging nearly 90% in May 2026. Blockchain security firm CertiK reported that crypto platform losses fell to $68.3 million last month, a dramatic drop from the staggering $650 million stolen in April. This sharp decline signals improved security measures across the industry and represents the third month in 2026 where losses stayed below $100 million. 

Code vulnerabilities were responsible for the bulk of May's damage, accounting for roughly 66% of total losses at approximately $45 million. Cross-chain bridges took the heaviest hit by category, absorbing 42% of total losses or $28.6 million. Despite the marked decrease, the sector wasn't entirely free from high-profile incidents, though the overall attack success rate has significantly diminished compared to previous months. 

The positive trend reflects multiple factors working together to protect crypto assets. Improved security measures and rapid response capabilities are driving this improvement, even as vulnerabilities persist across the ecosystem. CertiK's data shows that attackers are facing stronger defenses, with platforms implementing more robust protection systems and responding faster to emerging threats. This defensive upgrade is forcing crypto thieves to "hit a wall" as their traditional exploit methods become less effective. 

May 2026's performance stands in stark contrast to the previous quarter's chaos. The nearly 90% drop demonstrates that the industry is learning from past mistakes and adapting quickly to attack vectors. While $68.3 million in losses remains concerning, the trajectory is clearly positive, with monthly losses trending downward consistently through early 2026. Investors and platform operators are seeing tangible benefits from increased security investments. 

This security improvement offers hope for the cryptocurrency industry's long-term viability. As platforms strengthen their defenses and response times, the success rate for exploits continues declining. The trend suggests that crypto thieves are struggling to adapt to newer security protocols, marking a turning point in the ongoing battle between attackers and defenders. While attacks will continue, the dramatic reduction in losses indicates the industry is finally building effective walls against digital theft.

Ransomware Revenues Climb as Criminal Networks Expand and Adapt like unwanted vines

 




Ransomware operators continue to generate substantial profits, with new research from Rapid7 indicating that several cybercrime groups are recording revenue growth that outpaces many publicly traded businesses.

According to the cybersecurity firm's analysis, ransomware groups collectively received an estimated $529.2 million during the first quarter of 2026. That figure represents a 39% increase compared with the same period a year earlier. Rapid7 noted that none of the companies within the FTSE 350 index reported year-over-year revenue growth exceeding 30% during that quarter, placing ransomware operators among the fastest-growing entities examined in the study.

Several well-established ransomware operations appear to be benefiting from this trend. Rapid7 estimates that the Qilin ransomware group generated approximately $193 million between July 2025 and March 2026. During the same period, the Gentleman group is estimated to have collected roughly $52 million in ransom payments.

Rapid7 researchers argue that modern ransomware operations bear little resemblance to the stereotype of small groups of hackers working independently. Instead, many function through interconnected networks of specialists who focus on specific stages of an attack. Some actors gain access to victim networks, others develop malware, while separate teams handle extortion demands and payment negotiations.

A major factor behind this growth is the emergence of Initial Access Brokers, or IABs. These actors specialize in obtaining access to corporate networks and then selling that access to other criminals. As a result, launching a ransomware attack no longer requires extensive technical expertise. Access to compromised systems, attack tools, and even managed cybercrime services can now be purchased through underground marketplaces.

Researchers say this division of labor has created a more structured criminal economy. Different groups contribute individual services, allowing ransomware campaigns to operate through networks that resemble commercial supply chains rather than isolated criminal crews.

The study also highlights the resilience of these operations. Infrastructure used by ransomware groups, including servers, data leak platforms, and victim negotiation portals, can often be restored quickly after disruptions. Law enforcement agencies, meanwhile, frequently require lengthy investigations and international coordination before conducting enforcement actions. This difference in speed allows many criminal networks to continue operating even when portions of their infrastructure are removed.

Rapid7 CTO EMEA Thom Langford said ransomware groups have demonstrated an ability to continue generating revenue despite disruptions because their operations are designed to function even when individual components are taken offline. In many cases, the removal of a single server or criminal group does not significantly affect the broader ecosystem supporting ransomware activity.

The findings come amid continued financial losses linked to cybercrime. According to the FBI's Internet Crime Complaint Center, organizations and individuals reported more than $16 billion in cybercrime losses during 2024, reflecting the growing economic impact of digital fraud, extortion, and network intrusions.

To reduce ransomware risk, Rapid7 recommends that organizations continuously review their exposed systems and identify weaknesses that could provide attackers with an entry point. Particular attention should be given to misconfigured services, overlooked assets, and internet-facing systems, which are frequently targeted by Initial Access Brokers seeking access to corporate environments.

The company also advises security teams to make greater use of threat intelligence to understand how attackers operate, including the infrastructure, tools, and access methods commonly used during intrusions. Researchers further recommend strengthening identity security through tighter access controls, least-privilege policies, and monitoring for signs that employee credentials have been stolen, resold, or abused.

According to Rapid7, disrupting ransomware attacks before attackers establish access remains one of the most effective defensive strategies. By identifying weaknesses early and restricting opportunities for credential theft, organizations may be able to prevent ransomware incidents before they progress to the extortion stage.

Stablecoins Replace Bitcoin as the Primary Cryptocurrency in Illicit Transactions, Industry Data Shows

 




For years, Bitcoin was widely associated with cryptocurrency-related crime. New industry data suggests that picture has changed astronomically, with stablecoins now accounting for the vast majority of identified illicit cryptocurrency activity.

The change of terms was accentuated by Bitcoin-focused financial services company River, which cited blockchain intelligence findings showing that Bitcoin's role in unlawful crypto transactions has declined sharply over the past several years. According to data attributed to Chainalysis, Bitcoin represented roughly 70% of illicit cryptocurrency transaction volume in 2020. By 2025, that figure had fallen to approximately 7%, while stablecoins had grown to account for around 84% of identified illicit transaction volume.

The numbers point to a drastic transformation in how cybercriminals, fraud operators, sanctioned entities, and money-laundering networks move digital funds across borders.


Why Stablecoins Are Becoming More Attractive to Criminal Networks

Unlike Bitcoin and many other cryptocurrencies, stablecoins are designed to maintain a relatively fixed value, typically by being linked to a traditional currency such as the U.S. dollar.

This stability removes one of the major risks associated with cryptocurrency transactions. A criminal group holding $1 million in Bitcoin today could see the value fluctuate significantly within days. Stablecoins largely eliminate that uncertainty, allowing illicit actors to move, store, and transfer funds without being exposed to major price swings.

Researchers say this makes stablecoins particularly useful in fraud schemes, investment scams, money-laundering operations, and cross-border transfers where predictable value is important.

The spike in acceptance of stablecoins across exchanges, payment services, and over-the-counter trading networks has also contributed to their increased use. Many stablecoins can be transferred globally within minutes while maintaining a value closely tied to fiat currency, making them practical for both legitimate and illegitimate financial activity.


Bitcoin Still Appears in Certain Criminal Operations

Despite its declining share, Bitcoin has not disappeared from the cybercrime infrastructure. It is still part of the overall pipeline in digital currency exchange. 

Blockchain investigators continue to observe Bitcoin being used in ransomware attacks, darknet marketplaces, and extortion schemes. In these environments, long-established infrastructure, existing payment workflows, and familiarity among threat actors continue to support Bitcoin's use.

However, analysts note that criminal organizations are increasingly treating Bitcoin as only one option within a much larger digital financial ecosystem rather than the default cryptocurrency for illicit transactions.


Illicit Crypto Activity Continues to Soar

The change in asset preference comes as blockchain intelligence firms report increases in the overall value of illicit cryptocurrency activity.

TRM Labs recently estimated that illicit cryptocurrency flows reached approximately $158 billion in 2025, representing the highest level recorded by the company. The firm reported a sharp increase from the previous year, attributing much of the growth to sanctions-related activity, sophisticated money-laundering operations, underground financial networks, and expanded use of cryptocurrency by state-linked actors.

A large portion of these transactions involved stablecoins in the grand scheme of carrying out cyber criminal activities. 

Researchers also observed that sanctions-evasion networks increasingly rely on stablecoins because of their liquidity, accessibility, and ability to move large sums through multiple jurisdictions with relative speed.


Compliance and Regulatory Pressure Expected to become more stringent

The developing concentration of illicit activity within stablecoin ecosystems is likely to intensify scrutiny from regulators and law-enforcement agencies.

Unlike decentralized cryptocurrencies, many major stablecoins are issued by identifiable companies that maintain reserve assets and have the technical ability to freeze certain wallets when required by legal authorities.

As a result, policymakers are increasingly examining how stablecoin issuers monitor suspicious transactions, respond to sanctions violations, and cooperate with criminal investigations.

Several stablecoin providers have already expanded collaboration with law enforcement agencies. Tether, the issuer of USDT, has publicly reported freezing wallets connected to suspected criminal activity, while blockchain analytics companies continue to develop tracking tools designed to identify suspicious transaction patterns across networks.


Criminal Use Remains a Small Portion of Overall Activity

Although illicit cryptocurrency volumes have risen in absolute terms, researchers caution against interpreting the data as evidence that most cryptocurrency activity is criminal.

Industry reports consistently show that unlawful transactions represent only a small fraction of total blockchain activity. Stablecoins process trillions of dollars in annual transaction volume, meaning the overwhelming majority of transactions are associated with legitimate uses such as payments, trading, remittances, and settlement activities.

Nevertheless, the latest findings draw a clearer picture into how criminal groups adapt quickly to changing financial technologies. While Bitcoin once dominated illicit cryptocurrency transactions, blockchain intelligence data now suggests that stablecoins have become the preferred vehicle for many forms of crypto-enabled financial crime due to their price stability, global accessibility, and ease of transfer.

The trend is expected to remain a driving focus for regulators, compliance teams, cryptocurrency exchanges, and law-enforcement agencies as governments continue developing rules for the rapidly expanding stablecoin sector.