Cybersecurity News

Filters
Tag
Reset

Filtered by tag: cybercrime × Clear

Two Australians Charged Over TeamPCP Supply-Chain Attacks That Hit 1,000+ Organizations

Matched: Australia, cryptocurrency

Two Western Australian men have been charged with 14 offenses over alleged supply-chain attacks attributed to TeamPCP. Investigators say the pair planted malicious code in open-source repositories, compromising over 1,000 organizations globally, stealing 500,000+ credentials and exfiltrating 300GB of data. Remediation costs are estimated in the hundreds of millions. Warrants were executed in Cottesloe, Hamilton Hill, and Mandurah on 26 August 2026, with FBI involvement. Both men appeared in Perth Magistrates Court on 27 August 2026.

Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks

Matched: Australia

Two Western Australian men have been charged with 14 offences over their alleged roles in TeamPCP, a cybercrime group accused of compromising open-source security tools Trivy, Checkmarx KICS, and AI gateway LiteLLM in March 2026. Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared in Perth Magistrates Court on August 27.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Matched: Australia

Two Australian men, aged 21 and 23, have been arrested by the Australian Federal Police over alleged ties to TeamPCP, a cybercrime group responsible for a prolonged series of software supply chain attacks. The group embedded malicious code in open source tools, using a self-propagating worm called Shai-Hulud to steal developer credentials and spread further. Investigators identified the 21-year-old as Ruben Thomson of Perth, whose online activity and poor operational security linked him to multiple cybercrime aliases. The pair face 14 combined charges and appeared in Perth Magistrates Court.

Two Aussies alleged to be "principal participants" of TeamPCP hacking group

Matched: Australia

Australian and US authorities have taken coordinated action against two Australians allegedly identified as principal participants in the TeamPCP hacking group. No further details about the nature of the charges, the individuals named, or the specific actions taken by authorities were provided beyond their alleged central roles in the group.

Two WA men charged after AFP-FBI-WAPF probe into alleged open-source supply-chain attack

Matched: Australia

Two Western Australian men have been charged with 14 offences following a joint investigation by the AFP, FBI, and WA Police into an alleged cybercrime syndicate. The group allegedly tampered with open-source software to gain unauthorised access to corporate networks, stealing data and extorting victims. The investigation highlights growing concerns about supply-chain vulnerabilities in widely used open-source tools.

Are employees to blame for rise in insider access threats? This new study claims so

Flashpoint research found roughly 34 daily dark web posts related to insider threats between July 2025 and 2026, with July 2026 alone seeing 12,653 posts. Notably, 75% originated from insiders actively selling access rather than criminals recruiting them. Telecom, retail, and finance were primary targets. Flashpoint warns that as security software improves, attackers increasingly exploit employees, recommending organizations monitor dark web forums and encrypted platforms for credential trading.

New 'AnonyMous' phishing campaign targets iPhone users with fake AI Apple support calls

AnonyMousKIT is a phishing kit targeting iPhone theft victims by exploiting Apple's Lost Mode contact feature. Attackers use victims' displayed contact info to impersonate Apple support via email, SMS, or AI-powered calls, directing them to fake Find My pages to steal credentials. Active since 2024, the operation runs 500+ domains, 150+ reseller brands, and AI voice agents costing $0.10 per call, primarily targeting Brazil, South Africa, India, Indonesia, Kenya, and Italy.

Busted! Interpol-led operation targeting West African cybercrime groups nets 58 arrests

Matched: Australia, cryptocurrency

An Interpol-led operation involving 22 countries across six continents resulted in 58 arrests targeting West African cybercrime groups. Operation Jackal IV focused on dismantling romance scam and cryptocurrency fraud networks. Australia was among the participating nations. The operation also led to the identification of hundreds of additional suspects and the seizure of assets linked to the criminal organizations.

Experts warn 2,000 hacked WordPress sites were secretly running a global crime ring

Around 2,000 hacked WordPress sites were used as infrastructure for a global cybercrime operation. The compromised sites served multiple roles: delivering malware to victims, acting as command-and-control servers for infected devices, and storing stolen data. Security experts warn the scheme exploited the sites' legitimacy to avoid detection, highlighting risks for website owners who neglect security updates.

Exclusive: Ransomware newcomers list South Australia’s Ramsey Bros as hacking victim

Matched: Australia

Ransomware group Storm claims to have hacked Ramsey Bros, a South Australian farm machinery supplier. The group says it has published stolen data as proof, including alleged customer information and vehicle inspection records. Ramsey Bros has not yet publicly commented. Storm is considered a newcomer among ransomware groups, which typically steal and threaten to leak data to pressure victims into paying.

No-Filter 'Kriminal' AI Platform Raises Cybercrime Concerns

Matched: cryptocurrency

A platform called "Kriminal" offers an AI service with no content restrictions, marketed toward cybercriminals. Accessible via cryptocurrency, it provides social engineering scripts, offensive hacking tools, and open-source intelligence scanning. Despite official terms prohibiting illegal use, researchers warn the guardrail-free system meaningfully lowers the barrier for cybercrime, enabling even unskilled actors to conduct sophisticated attacks.

US charges 17 Iranian nationals over “massive cyber theft campaign”

Matched: Australia

The US Justice Department has charged 17 Iranians linked to a company called Emennet Pasargad over a large-scale cyber theft campaign targeting academics worldwide, including in Australia. The hackers allegedly stole research, credentials, and other sensitive data. Several of those charged are also accused of previous interference in US elections.

Australia & Thailand to strengthen cooperation on fighting cybercrime

Matched: Australia

Australia and Thailand have agreed to strengthen cooperation on combating cybercrime and transnational crime, following talks between Prime Minister Anthony Albanese and Thai PM Anutin Charnvirakul. The two leaders released a joint statement outlining their commitment to deeper collaboration on cross-border criminal activity, reflecting shared security concerns in the region.

17th August – Threat Intelligence Report

Colombia's Ministry of Justice suffered a ransomware attack disrupting technology infrastructure and public services tied to drug monitoring and legal processes, with officials confirming file compromise. Other notable incidents include additional breaches and cyberattacks detailed in Check Point Research's weekly Threat Intelligence Bulletin, covering top attacks, emerging vulnerabilities, and threat actor activity for the week of 17th August.

The State of Ransomware Q2 2026

Ransomware activity in Q2 2026 shows signs of shifting dynamics, according to Check Point Research. While dominant ransomware-as-a-service operations continue leading the space, the previously consolidating landscape is beginning to fragment. Established groups maintain their dominance, but emerging players are increasingly challenging the concentration of power that has defined the ransomware ecosystem over the past year.

'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft

Matched: cryptocurrency

Researchers have identified a threat actor dubbed "Jewelbug," a hackers-for-hire group conducting both state-sponsored espionage and cryptocurrency theft through the same infrastructure. The dual-purpose operation — mixing intelligence gathering with financial crime — is unusual, suggesting the group serves government clients while simultaneously running independent profit-driven attacks, blurring the line between nation-state and cybercriminal activity.

Five Years, 88,000 Backdoors, and a Pair of Handcuffs: Inside the Global Manhunt That Ended in an Arrest

A five-year joint investigation by cybersecurity firm Huntress and the FBI culminated in an arrest connected to Silk Typhoon, a Chinese state-linked hacking group. The operation tracked the deployment of roughly 88,000 backdoors in Microsoft Exchange servers. The case highlights the growing collaboration between private security researchers and federal law enforcement in combating sophisticated, state-sponsored cybercrime.

Bank of America Phishing Email Delivers ScreenConnect Malware

A phishing campaign impersonating Bank of America delivers ScreenConnect remote access malware through a multi-stage infection chain. The convincing fake emails trick recipients into actions that ultimately install the legitimate remote access tool, which attackers abuse to control victims' systems. The campaign highlights how cybercriminals exploit trusted brand names and repurpose legitimate software to evade detection.

Report: Nearly half of Australians experienced cyber crime in 2025

Matched: Australia

Nearly half of Australians were affected by cybercrime in 2025, though overall victimisation rates fell slightly from the previous year, according to the Australian Cybercrime Survey. Online scams continued to rise despite the broader decline. Underreporting remains a significant concern, with most incidents never flagged to authorities, limiting the ability to fully assess the scale of the problem.

What Are Initial Access Brokers?

Initial access brokers are cybercriminals who specialize in breaking into corporate networks and selling that access to other attackers, such as ransomware groups, rather than exploiting it themselves. They typically gain entry through stolen credentials, phishing, or unpatched vulnerabilities. This division of labor has made cybercrime more efficient and increased the scale of attacks on businesses.