✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Law Enforcement
Breach intelligence, attack campaigns, and threat reports targeting the Law Enforcement sector.
Explore Other Sectors
Law Enforcement Threat Reports
UK Authorities Charge Five in Russian Coms Caller ID Spoofing Case
In July 2026, UK authorities charged five individuals in connection with Russian Coms, a caller ID spoofing platform implicated in over 1.8 million scam calls since its inception in 2020. The platform enabled criminals to impersonate trusted entities, leading to financial losses estimated in the tens of millions and affecting approximately 170,000 victims. The National Crime Agency (NCA) had previously dismantled Russian Coms in March 2024, arresting key figures believed to be its developers and administrators. The recent charges underscore the ongoing efforts to hold accountable those involved in facilitating large-scale fraud operations. This incident highlights the persistent threat posed by sophisticated social engineering tactics and the critical need for robust cybersecurity measures to protect individuals and organizations from such fraudulent schemes.
1 day ago
Kill Chain
ScamBuster: Revolutionizing Phishing Defense with AI
In July 2026, cybersecurity researcher Laurent Giovannoni introduced ScamBuster, an AI-driven system designed to counteract phishing attacks by engaging scammers with human-like personas. By simulating potential victims, ScamBuster collects critical data on cybercriminal operations, including financial details and infrastructure insights, which can be utilized by organizations and law enforcement to disrupt fraudulent activities. This proactive approach not only wastes scammers' time but also provides valuable intelligence to prevent future attacks. The emergence of ScamBuster highlights a significant shift towards offensive cybersecurity measures, leveraging artificial intelligence to turn the tables on cybercriminals. As phishing tactics become increasingly sophisticated, tools like ScamBuster offer a novel method to gather actionable intelligence, emphasizing the importance of adaptive and proactive defense strategies in the evolving threat landscape.
2 days ago
Kill Chain
Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
Between February 2024 and April 2026, cybersecurity researchers identified sustained cyber espionage activities targeting Pakistani law enforcement agencies, notably the Balochistan Police. These campaigns, attributed to threat actors linked to China and India, involved the compromise of servers hosting sensitive web applications managing police and citizen data. The attackers employed sophisticated techniques, including multi-stage malware deployment and exploitation of unpatched vulnerabilities, to infiltrate and maintain persistent access to these critical systems. The breaches resulted in unauthorized access to confidential information, posing significant risks to national security and public safety. This incident underscores a growing trend of state-sponsored cyber espionage targeting law enforcement and government institutions in South Asia. The convergence of multiple nation-state actors focusing on similar targets highlights the strategic importance of such entities and the escalating cyber threats they face. Organizations must enhance their cybersecurity posture to defend against increasingly sophisticated and persistent adversaries.
3 days ago
Kill Chain
Arrest of Pro-Russian Hacktivist in Spain Highlights Ongoing Cyber Threats
In July 2026, Spanish authorities, in collaboration with the FBI, arrested a suspected core member of pro-Russian hacktivist groups CyberArmy of Russia Reborn (CARR) and Z-Pentest in Palencia, Spain. The individual is accused of providing logistical support to a Ukrainian hacker affiliated with CARR and attempting to facilitate their escape to Russia. The suspect is also linked to coordinating cyber operations for the NoName057(16) group using encrypted messaging platforms. Seized items include multiple computers and frozen cryptocurrency wallets allegedly used to launder proceeds from stolen data sales. The suspect faces ongoing investigations for collaboration with a recognized terrorist organization and severe computer damage. ([es.euronews.com](https://es.euronews.com/my-europe/2026/07/06/la-policia-y-el-fbi-detienen-en-palencia-a-un-presunto-colaborador-de-hackers-prorrusos?utm_source=openai)) This arrest underscores the persistent threat posed by hacktivist groups targeting critical infrastructure across the United States and Europe. The incident highlights the importance of international cooperation in combating cybercrime and the need for organizations to bolster their cybersecurity defenses against such multifaceted threats.
5 days ago
Kill Chain
INTERPOL's Operation First Light 2026: A Major Blow to Global Fraud Networks
Between January 15 and April 30, 2026, INTERPOL coordinated 'Operation First Light 2026,' a global initiative targeting social engineering fraud and money laundering across 97 countries. The operation resulted in the arrest of 5,811 suspects, the seizure of $293 million in illicit assets, and the identification of over 142,000 victims. Authorities also blocked 31,014 bank accounts and analyzed 152,808 cases, highlighting the extensive reach of these fraudulent activities. This operation underscores the escalating threat of transnational social engineering scams, which have become increasingly sophisticated and widespread. The significant number of victims and the substantial financial impact emphasize the urgent need for enhanced international cooperation and proactive measures to combat such fraud.
5 days ago
Kill Chain
Expansion of Deepfake CSAM Lawsuit Targets xAI and Stability AI
In July 2026, a class-action lawsuit against xAI, the developer of the AI tool Grok, was expanded to include two additional plaintiffs. These individuals allege that Grok was used by acquaintances to generate nonconsensual deepfake child sexual abuse material (CSAM) based on their real photos. The lawsuit also names Stability AI as a defendant, claiming that its Stable Diffusion model facilitated the creation of such illicit content. The plaintiffs report significant emotional distress and a loss of control over the dissemination of these images. This incident underscores the urgent need for robust safeguards in AI technologies to prevent misuse, particularly in generating harmful content. It highlights the growing legal and ethical challenges companies face in ensuring their AI models are not exploited for creating nonconsensual and illegal material.
1 week ago
Kill Chain
European Parliament Member Targeted with Pegasus Spyware During Investigation
In October 2022 and March 2023, former Member of the European Parliament (MEP) Stelios Kouloglou's mobile device was infiltrated with Pegasus spyware while he was serving on the PEGA committee, which was investigating the misuse of such surveillance tools within the European Union. The Citizen Lab's forensic analysis confirmed these infections, indicating that attackers potentially accessed confidential committee documents and deliberations. The specific government or entity responsible for these attacks remains unidentified. ([citizenlab.ca](https://citizenlab.ca/research/member-of-committee-investigating-spyware-hacked-with-pegasus/?utm_source=openai)) This incident underscores the escalating threat of sophisticated spyware targeting high-profile individuals, including those involved in oversight and investigative roles. It highlights the urgent need for robust cybersecurity measures and regulatory frameworks to protect sensitive information and uphold democratic processes. ([theguardian.com](https://www.theguardian.com/world/2026/jul/03/spyware-used-against-mep-investigating-pegasus-abuses-report-finds?utm_source=openai))
1 week ago
Kill Chain
DHS HSIN Breach 2026: Cyberattack on Information-Sharing Platform
In late May to early June 2026, the Department of Homeland Security (DHS) experienced a cyberattack on the Homeland Security Information Network (HSIN), a platform for sharing sensitive but unclassified information among federal, state, local, and private-sector partners. An unknown threat actor accessed HSIN servers and a SharePoint system used for collaboration. DHS is investigating the breach to determine the extent of the intrusion and whether any documents were stolen. The department has not attributed the attack to any specific threat actor or foreign government. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/dhs-confirms-hackers-breached-hsin-info-sharing-platform/amp/?utm_source=openai)) This incident underscores the persistent threats to government information-sharing platforms and highlights the need for robust cybersecurity measures. As the United States oversees security for major events like the World Cup, ensuring the integrity of such systems is paramount to national security. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/dhs-confirms-hackers-breached-hsin-info-sharing-platform/amp/?utm_source=openai))
1 week ago
Kill Chain
FBI Issues Alert on Russian Hackers Targeting Signal Backup Recovery Keys
In June 2026, the FBI and CISA issued a warning about a sophisticated phishing campaign by Russian intelligence services targeting Signal users. The attackers impersonated Signal support teams, sending messages that prompted users to enable backups and share their 64-character recovery keys. With these keys, the attackers could decrypt victims' entire message histories, compromising sensitive communications. The campaign primarily targeted individuals of high intelligence value, including government officials, military personnel, political figures, journalists, and key officials in Ukraine. This incident underscores the evolving tactics of state-sponsored cyber actors and highlights the critical importance of user vigilance against social engineering attacks. The exploitation of backup recovery keys represents a significant escalation in phishing techniques, emphasizing the need for robust security practices and user education to prevent unauthorized access to encrypted communications.
2 weeks ago
Kill Chain
Persistent Cyber Scam Centers in Asia Despite Crackdowns
In June 2026, reports from INTERPOL and Amnesty International highlighted the persistent and escalating issue of cyber scam centers across Asia, particularly in Cambodia, Myanmar, Laos, and the Philippines. Despite high-profile crackdowns and arrests, these operations continue to thrive, generating an estimated $40 billion annually through schemes like romance fraud and investment scams. The resilience of these criminal enterprises is largely attributed to local corruption and collusion with law enforcement, which undermine efforts to dismantle them. ([interpol.int](https://www.interpol.int/News-and-Events/News/2026/New-INTERPOL-report-highlights-escalating-cyber-threats-across-Asia-and-South-Pacific?utm_source=openai)) This situation underscores the urgent need for enhanced international cooperation and robust anti-corruption measures. The continued operation of these scam centers not only results in significant financial losses globally but also involves severe human rights abuses, including human trafficking and forced labor. Addressing this issue is critical to protecting vulnerable populations and maintaining global cybersecurity. ([amnesty.org](https://www.amnesty.org/en/latest/news/2026/06/cambodia-evidence-suggests-scamming-compounds-bypassed-despite-high-profile-crackdown/?utm_source=openai))
2 weeks ago
Kill Chain
Russia's Unauthorized Use of Cellebrite Tools on Activist's iPhone
In June 2021, Russian authorities utilized Cellebrite's Universal Forensic Extraction Device (UFED) to access the iPhone of detained opposition activist Andrey Pivovarov. This occurred three months after Cellebrite announced the cessation of sales and services to Russian government clients in March 2021. Forensic evidence and Russian court documents confirm that investigators extracted data, including WhatsApp and Telegram messages, and searched for political terms and opposition figures. This incident underscores the challenges technology vendors face in controlling the use of their tools post-sale, especially when used by authoritarian regimes. The continued operation of Cellebrite's tools in Russia, despite the termination of official support, highlights the need for more robust mechanisms to prevent misuse of surveillance technologies.
2 weeks ago
Kill Chain
Russia's Continued Use of Cellebrite Tools Raises Concerns
In June 2021, Russian authorities utilized Cellebrite's Universal Forensic Extraction Device (UFED) to access the iPhone of detained human rights activist Andrey Pivovarov. This occurred despite Cellebrite's public announcement in March 2021 that it had ceased all sales and services to Russian government agencies. The extracted data reportedly included communications from encrypted messaging apps, which were subsequently used to surveil other dissidents. This incident underscores the challenges technology companies face in controlling the use of their tools post-sale, especially when they are employed for political repression. The case highlights the need for robust mechanisms to prevent the misuse of surveillance technologies by authoritarian regimes, even after contractual relationships have been terminated.
2 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports