#Cybercrime

Every story tagged Cybercrime, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.

20 stories · open in the command center

  • Security & PrivacyHacker News3m

    AI fuels more than half of cybercrime in Africa as scams surge – Interpol

    AI now powers over 55% of cybercrime across Africa, enabling criminals to execute faster and more sophisticated attacks while financial losses have surged from $192 million to $484 million year-over-year, driven by deepfakes, synthetic identities, and AI-generated phishing campaigns. This escalating threat is compounded by inadequate law enforcement preparedness, weak cross-sector coordination between banks and telecom providers, and fragmented information-sharing mechanisms that allow criminals to exploit jurisdictional gaps. IT leaders must recognize that Africa's expanding digital economy (1.1 billion mobile subscribers) presents both growth opportunities and critical security vulnerabilities requiring immediate investment in threat detection capabilities and ecosystem-wide collaboration.

  • Security & PrivacyTechCrunchConnie Loizos2m

    The ‘first’ AI-run ransomware attack still needed a human

    Researchers documented the first known case of "agentic ransomware" where an AI agent autonomously executed a cyberattack (JadePuffer), but critical human involvement remained in victim selection, infrastructure setup, and initial credential acquisition—highlighting that AI automation amplifies attack scalability primarily by reducing technical execution time rather than eliminating human coordination. This development signals that future ransomware campaigns could scale exponentially as attack costs drop, though current bottlenecks around human operational decisions may temporarily constrain widespread proliferation. IT leaders must anticipate a threat landscape where AI-accelerated attacks can adapt in real-time to network defenses and exploit known vulnerabilities at machine speed, fundamentally changing incident response requirements.

  • Security & PrivacyTechMemeJoe Warminski2m

    The US DOJ says Peter Stokes, a 19-year-old dual US-Estonian citizen, was extradited from Finland to face charges of participating in Scattered Spider hacks (Joe Warminsky/The Record)

    A 19-year-old dual US-Estonian citizen was extradited to face charges related to Scattered Spider, a sophisticated hacking group known for targeting critical infrastructure and enterprise systems, demonstrating law enforcement's expanding international capabilities to pursue cybercriminals. This case underscores the growing threat from organized cybercriminal groups and signals that jurisdictional boundaries are no longer protective for threat actors, with implications for how organizations must approach incident response and threat intelligence sharing. IT leaders should expect continued law enforcement engagement on major breaches and recognize that sophisticated cyber attacks increasingly carry criminal prosecution risks that extend beyond national borders.

  • Security & PrivacyTechMemeLorelei Smillie2m

    Microsoft's Digital Crimes Unit says AI helped it link two separate hacking tools, Amadey and StealC, and file a single civil lawsuit to help take them down (Lorelei Smillie/Bloomberg)

    Microsoft's Digital Crimes Unit leveraged AI to identify connections between two previously unrelated malware tools (Amadey and StealC), enabling a unified legal action to dismantle both threats simultaneously. This demonstrates how AI-powered threat intelligence can accelerate attack pattern recognition and strengthen enforcement actions against cybercriminals. For IT organizations, this signals that AI-enhanced security tools are becoming critical for identifying sophisticated, multi-vector threats that traditional analysis might miss.

  • Security & PrivacyTechMemeZack Whittaker2m

    Market intelligence company Klue confirms it has suffered a breach, for which cybercrime group Icarus takes credit; Jamf, HackerOne, and others are affected (Zack Whittaker/TechCrunch)

    Market intelligence platform Klue suffered a significant breach attributed to the Icarus cybercrime group, with downstream impacts affecting multiple high-profile SaaS vendors including Jamf and HackerOne, exposing the vulnerability of third-party service providers in your technology stack. This incident highlights the critical risk of supply chain compromises where breaches at single vendors can cascade across multiple dependent organizations, requiring IT leaders to reassess vendor security postures and their own data protection measures. The breach underscores the need for enhanced third-party risk management and access control strategies to limit organizational exposure when key vendors are compromised.

  • Security & PrivacyTechCrunchLorenzo Franceschi-Bicchierai2m

    Chinese cybercrime operation that used AI to scam ‘hundreds of thousands of victims’ sued by Google

    A sophisticated Chinese cybercrime operation called Outsider Enterprise has defrauded hundreds of thousands of victims using AI-powered phishing at scale, stealing an estimated $1.9 billion and 3.87 million credit cards globally through a democratized, subscription-based software platform that enables low-skill criminals to launch attacks. This incident underscores a critical strategic vulnerability for IT leaders: adversaries are now operationalizing AI to accelerate social engineering attacks with unprecedented volume and sophistication, requiring organizations to fundamentally upgrade threat detection, user authentication, and incident response capabilities. The case demonstrates that traditional security defenses are insufficient against coordinated, well-resourced criminal ecosystems, and highlights the urgent need for AI-augmented security tools, zero-trust architecture, and collaboration between enterprises and infrastructure providers to counter this emerging threat landscape.

  • Security & PrivacyTechCrunchLorenzo Franceschi-Bicchierai2m

    Google sues alleged Chinese cybercrime operation that used AI to send scam texts

    Google is suing a Chinese cybercrime operation (Outsider Enterprise) that leveraged AI to conduct massive-scale SMS phishing scams, impacting hundreds of thousands of victims with millions in losses across 9,000 fake websites and 2.5 million fraudulent texts. This incident demonstrates that AI-enabled social engineering attacks are rapidly escalating in sophistication and scale, requiring IT organizations to evolve their security posture beyond traditional defenses to include AI-powered threat detection and cross-industry collaboration. For technology leaders, this highlights both the emerging threat landscape and the strategic importance of investing in advanced security tools, user education on AI-driven scams, and establishing partnerships with carriers and law enforcement to combat coordinated cybercriminal operations.

  • Security & PrivacyArs TechnicaRyan Whitwam2m

    Google sues Chinese cybercrime network that used Gemini to automate scams

    Google has sued Chinese cybercrime network Outsider Enterprise for using its Gemini AI to automate large-scale phishing scams that impacted 2.5 million Android users and compromised thousands of fraudulent websites, highlighting a critical vulnerability in generative AI systems being weaponized by threat actors. This incident demonstrates that even with built-in security controls, AI tools can be repurposed for sophisticated fraud at scale, requiring IT organizations to reassess their AI governance, user authentication protocols, and threat detection capabilities. The case underscores an emerging business risk: as AI becomes more capable, distinguishing legitimate from malicious content becomes exponentially harder, necessitating both technological solutions and regulatory frameworks that most organizations are not yet prepared to implement.

  • Security & PrivacyTechMemeCecilia Kang2m

    Google sues Chinese cybercrime network Outsider Enterprise, accusing it of using Gemini AI to create fake websites and scam hundreds of thousands of Americans (Cecilia Kang/New York Times)

    Google has filed suit against a Chinese cybercrime network (Outsider Enterprise) for weaponizing Gemini AI to generate convincing fake websites that defrauded hundreds of thousands of Americans, highlighting a critical vulnerability in how generative AI tools can be exploited at scale for financial crimes. This case demonstrates that AI-enabled threat actors can now operate with significantly higher sophistication and velocity, creating a new category of risk that extends beyond traditional cybersecurity into customer trust, brand protection, and regulatory exposure for organizations. IT leaders must urgently reassess their security posture, third-party AI tool governance, and customer authentication mechanisms to combat AI-accelerated fraud campaigns that will increasingly target their industries.

  • Security & PrivacyWiredMatt Burgess2m

    Your iPhone Gets Stolen. Then the Hacking Begins

    A thriving underground ecosystem of cybercrime services has emerged to unlock stolen iPhones, with phishing kits and jailbreak tools available for under $10 on platforms like Telegram, making stolen devices worth 5-10x more when unlocked and creating significant fraud risks to users' financial accounts and personal data. The sophistication of these operations—including AI-powered phishing, social engineering targeting Apple's Find My feature, and coordinated supply chains—represents a critical vulnerability that extends beyond device security to enterprise identity and access management concerns. IT organizations must recognize that employee mobile devices are increasingly targeted attack vectors that can compromise corporate networks, financial systems, and sensitive data through compromised personal devices used for work purposes.

  • Security & PrivacyTechCrunchZack Whittaker2m

    Police arrest SMS blaster crew that sent malicious messages to thousands across Toronto

    Toronto Police arrested three individuals operating the first known SMS blaster in Canada, which exploited 2G network vulnerabilities to send phishing messages to tens of thousands of devices and steal banking credentials, while also disrupting 911 emergency services. This emerging threat demonstrates a critical gap in cellular infrastructure security that IT leaders must address through employee awareness training and mobile device security policies, particularly given the device's mobility and ability to target multiple locations. Organizations should prioritize disabling 2G connectivity on company devices and implementing multi-factor authentication to mitigate the risk of credential theft from SMS-based phishing attacks.

  • Security & PrivacyTechMemeJason Meisner2m

    US prosecutors allege Peter Stokes, a 19-year-old dual US-Estonian citizen known as Bouquet, is a Scattered Spider member; he was arrested in a Helsinki airport (Jason Meisner/Chicago Tribune)

    A 19-year-old member of the Scattered Spider cybercriminal group was arrested, highlighting the persistent threat of sophisticated threat actors targeting enterprise infrastructure and data. This incident underscores the critical need for IT organizations to strengthen their security posture against advanced persistent threats, particularly those exploiting social engineering and supply chain vulnerabilities. For CIOs, this represents a stark reminder that cyber threats are increasingly international in scope and perpetrated by younger, digitally-native threat actors who require enterprise-grade detection and incident response capabilities.

  • Security & PrivacyTechCrunchAisha Malik2m

    Consumers lost $2.1 billion to social media scams in 2025, FTC reports

    Social media scams cost consumers $2.1 billion in 2025 with losses increasing eightfold, representing a significant cybersecurity and reputational risk for enterprises whose platforms and brands are exploited by scammers. Facebook-based scams accounted for the largest share of losses, with investment and shopping fraud schemes dominating, indicating that IT organizations must strengthen platform security, authentication controls, and fraud detection mechanisms to protect both customers and brand integrity. This surge in social engineering attacks underscores the need for enhanced security architecture, threat intelligence capabilities, and cross-platform monitoring to mitigate enterprise liability and maintain customer trust.

  • Security & PrivacyTechCrunch2m

    Ransomware negotiator pleads guilty to helping ransomware gang

    A former ransomware negotiator has pleaded guilty to colluding with cybercriminals, marking the third incident response professional arrested for betraying clients by feeding sensitive negotiation data and insurance information to the ALPHV/BlackCat ransomware gang in exchange for a cut of extorted ransom payments. This represents a critical insider threat vulnerability in the incident response supply chain, exposing organizations to compromised third-party advisors who can amplify ransomware attack success and payouts by up to $1.2+ million per victim. IT leaders must reassess vendor vetting procedures, implement stricter access controls and monitoring for incident response partners, and establish independent verification protocols to prevent similar breaches of trust in crisis situations.

  • Security & PrivacyTechCrunch2m

    North Korea hackers blamed for $290M crypto theft

    North Korean state-sponsored hackers stole $290M in cryptocurrency from Kelp DAO by exploiting weak multi-signature security controls in cross-blockchain bridge infrastructure, marking the largest crypto theft of 2026. This attack underscores the escalating sophistication of nation-state threat actors targeting financial systems, with North Korea having stolen over $6 billion in crypto since 2017 to fund its regime. The incident highlights critical vulnerabilities in third-party integrations and multi-party verification systems that extend beyond cryptocurrency to any distributed digital asset infrastructure.

  • Security & PrivacyArs Technica2m

    Russia-friendly exchange says "western special service" behind $15 million cyberattack

    A US-sanctioned cryptocurrency exchange with ties to Russia suffered a $15 million cyberattack, claiming it was conducted by 'western special services,' though blockchain researchers cannot confirm attribution. The exchange, which processed over $6 billion in transactions and allegedly facilitated ransomware operations, has suspended operations following the breach that drained approximately 70 wallet addresses. This incident highlights the ongoing cyber conflict between state actors and the vulnerabilities in cryptocurrency infrastructure used by sanctioned entities.

  • Security & PrivacyTechCrunch2m

    European police email 75,000 people asking them to stop DDoS attacks

    Europol's Operation PowerOFF sent warning notices to 75,000 users of DDoS-for-hire services, signaling heightened law enforcement focus on easily accessible cyber-attack tools that enable non-technical actors to disrupt business operations. The coordinated action resulted in 53 domain takedowns and four arrests, demonstrating that authorities are now actively pursuing both DDoS service providers and their customers. This operation underscores the continuing business risk from DDoS attacks, which remain prevalent due to low barriers to entry, with recent attacks reaching record levels of 29.7 terabits per second.

  • Security & PrivacyTechCrunch2m

    Two Americans sentenced for helping North Korea steal $5 million in fake IT worker scheme

    North Korean operatives successfully infiltrated over 100 U.S. companies, including Fortune 500 firms, by using laptop farms and stolen identities to place fake remote IT workers who not only collected $5 million in salaries but also stole trade secrets, source code, and export-controlled AI data. This scheme, which operated from 2021-2024, represents a significant supply chain and insider threat that bypassed traditional security controls, with funds directly supporting North Korea's weapons program. The successful prosecution demonstrates growing regulatory and legal risk for companies that fail to properly verify remote worker identities and monitor for anomalous access patterns.

  • Security & PrivacyTechCrunch2m

    FBI announces takedown of phishing operation that targeted thousands of victims

    The FBI dismantled W3LL, a global phishing-as-a-service operation that sold phishing kits for $500, enabling cybercriminals to steal credentials and MFA codes from over 17,000 victims and attempt more than $20 million in fraud. The takedown highlights the continued industrialization of cybercrime, where low-cost toolkits make sophisticated attacks accessible to less-skilled criminals. This case demonstrates that even multi-factor authentication can be compromised through well-designed phishing kits, requiring IT organizations to reassess their authentication and security awareness strategies.

  • Security & PrivacyWired2m

    China Is Cracking Down on Scams. Just Not the Ones Hitting Americans

    China's selective enforcement against scam operations targeting Chinese citizens while tolerating those targeting foreigners has inadvertently incentivized criminal syndicates to pivot toward American victims, with US fraud losses increasing 40% while China's decreased 30% between 2023-2024. This geopolitically fragmented approach to cybercrime enforcement mirrors challenges in ransomware prosecution and creates a critical vulnerability for US organizations and citizens that demands coordinated international pressure and domestic defensive strategies. IT leaders must recognize this represents a systemic threat landscape where nation-state enforcement dynamics directly impact organizational risk exposure.

Browse all tags