✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Law Enforcement
Breach intelligence, attack campaigns, and threat reports targeting the Law Enforcement sector.
Explore Other Sectors
Law Enforcement Threat Reports
Predator Spyware: New Evasion and Troubleshooting Capabilities Outpace Defenders
In June 2024, cybersecurity researchers at Jamf Threat Labs uncovered advanced anti-analysis and troubleshooting features in Predator spyware, developed by the Intellexa alliance. The spyware's sophisticated error code system enables operators to pinpoint why an infection attempt failed, such as detecting the presence of security tools (error code 304) or security researchers' activities. Predator also detects common investigation tools like netstat and automatically aborts installation, suppressing crash logs to thwart forensic analysis. These features demonstrate the spyware's focus on evading both defensive products and researcher scrutiny. This incident highlights a significant escalation in the arms race between threat actors and defenders, as commercial spyware rapidly evolves more effective evasion and detection-resistance capabilities. Organizations and individuals must recognize the ongoing advancement of targeted surveillance malware and enhance endpoint and network defenses accordingly.
6 months ago
Kill Chain
BreachForums 2024 Breach: Cybercrime’s Biggest Exposure Yet
In early May 2024, the hacker platform BreachForums was itself breached, resulting in the exposure of sensitive data belonging to over 324,000 registered users, including administrators and prominent cybercriminals. Attackers leveraged vulnerabilities in the forum’s backend to exfiltrate user registration details, encrypted password hashes, internal conversations, and potentially identifying metadata. Security researchers confirmed that the data dump contained real names, email addresses, and operational details, upending the anonymity of users who trafficked in illicit data and network access. This breach is highly significant because it marks a trend of threat actors targeting not just businesses, but the very enclaves where cybercrime is organized. It highlights a growing climate of infighting, doxxing, and exposure in the criminal underground, and signals increased scrutiny by law enforcement and vigilante hackers.
6 months ago
Kill Chain
Spanish Police Disrupt Black Axe BEC Ring, Arresting Key Leaders in 2024 Crackdown
In early June 2024, Spanish National Police, supported by Europol and German authorities, arrested 34 individuals—among them top leaders of Black Axe, a notorious Nigerian-backed cybercrime syndicate. The tightly coordinated operation targeted Black Axe’s business email compromise (BEC) activities, which since September 2023 exploited corporate email channels to orchestrate multi-million-dollar fraud, money laundering, and shell company schemes across Europe. Authorities seized $77,000 in cash, froze $139,000 in bank accounts, and confiscated electronic devices and vehicles used for illicit activities. Black Axe’s operations were sophisticated and involved extensive networks of money mules and international laundering techniques. This disruption is highly relevant as BEC attacks grow in frequency, scale, and organizational complexity. Recent law enforcement action highlights the evolving threats posed by criminal syndicates who weaponize digital channels and exploit human and technical vulnerabilities, prompting urgent review of security controls and detection capabilities.
6 months ago
Kill Chain
One Click IP Exposure: How Telegram Proxy Links Created a Privacy Vulnerability in 2026
In January 2026, security researchers revealed that Telegram users could have their real IP address exposed by clicking specially crafted proxy links disguised as regular usernames or harmless URLs. When users clicked these links in Telegram's Android or iOS apps, the app would automatically attempt to connect to the attacker-controlled proxy server, revealing the user's actual IP without further confirmation. This behavior, demonstrated across various public channels, posed targeted privacy risks, including location tracking and the potential for follow-on attacks. Telegram acknowledged the issue and stated they would introduce warnings to alert users about proxy links but did not commit to a timeline for deployment. This incident highlights a growing trend of information disclosure vulnerabilities related to messaging apps and link-based attacks, demonstrating the persistent risk of metadata and IP leaks in platforms used for privacy and circumvention. It brings renewed urgency to strengthen client security and increase user awareness, especially amid rising concerns over digital privacy and targeted cyber threats.
6 months ago
Kill Chain
BreachForums 2025 Breach: 324,000 Accounts and PGP Keys Leaked in Cybercrime Forum Incident
In August 2025, BreachForums—the notorious hacking forum—suffered a major data leak when an unsecured backup of its user database was exposed online during site restoration activities. Threat actors, including a site impersonating the ShinyHunters gang, published the database containing nearly 324,000 account records. Most member IP addresses were obfuscated, but over 70,000 exposed real public IPs, along with usernames, emails, registration dates, and other metadata. Also leaked was a PGP private key used by forum admins, which later became accessible after the passphrase was posted online. This breach occurred shortly after law enforcement actions against the forum and the shutdown of its .hn domain following the arrest of its operators. This incident underscores the persistent risk of sensitive data exposure even among cybercriminal communities and highlights evolving law enforcement tactics. The leak fuels ongoing debate over forum honeypots, operational security failures, and the volatility of underground forums, while serving as a timely reminder of the dangers of unprotected data backups and shifting threat actor TTPs.
6 months ago
Kill Chain
Europol Arrests 34 Black Axe Members in Massive 2026 Organized Cyber-Fraud Takedown
In January 2026, Europol and Spanish authorities arrested 34 suspected members of the Black Axe organized crime syndicate in Spain, dismantling a major transnational cyber-fraud operation. The group, originating from Nigeria but operating internationally, orchestrated a series of sophisticated cyber-enabled crimes, including business email compromise, romance and inheritance scams, credit card and tax fraud, and extensive money laundering. Law enforcement seized over €185,000 ($216,000) in assets and disrupted fraud estimated at more than €5.9 million ($6.9M), highlighting Black Axe's role in global financial crime and cyber-enabled offenses. This incident underscores the growing intersection of traditional organized crime with advanced cyber-fraud tactics, as law enforcement faces increasingly complex, multi-jurisdictional threats. The reliance on cyber-enabled fraud techniques by such syndicates reflects an urgent need for organizations to adapt their security posture to address sophisticated, persistent, and highly organized threats.
6 months ago
Kill Chain
Illinois Man Phishes 570 Snapchat Accounts in Major 2026 Breach
In early 2026, U.S. authorities charged Illinois resident Kyle Svara for orchestrating a large-scale phishing and account takeover operation targeting Snapchat users. Between May 2020 and February 2021, Svara used social engineering tactics, including impersonating Snap representatives, to solicit access codes from over 4,500 individuals. He successfully compromised credentials for approximately 570 victims and accessed at least 59 accounts without permission, stealing private images and selling his hacking services online via forums like Reddit and encrypted channels such as Kik. Affected organizations included Northeastern University and Colby College, with the breach exposing significant privacy and security risks for hundreds of women. This breach highlights the escalating threat of identity-driven attacks leveraging social engineering and phishing to gain unauthorized access to sensitive accounts. The incident underscores increased regulatory and public scrutiny of platforms' ability to safeguard user credentials, as well as the evolving risks posed by credential harvesting and account takeover methods.
6 months ago
Kill Chain
Bitfinex 2016 Hack: Anatomy of a Record Crypto Heist and Its Aftermath
In 2016, cryptocurrency exchange Bitfinex suffered one of the largest crypto thefts to date when hackers, including Ilya Lichtenstein, exploited security weaknesses to steal nearly 120,000 Bitcoins, worth billions of dollars at the time. Lichtenstein laundered the stolen funds through a sophisticated network of wallets and exchanges to obscure the assets' origin. Following a lengthy investigation, U.S. authorities arrested Lichtenstein in 2022, later convicting and sentencing him for money laundering tied to this high-profile breach. The Bitfinex hack has become a landmark case in cryptocurrency security and digital money laundering tactics. Its legacy persists as the industry faces increased regulatory scrutiny and ongoing threats targeting exchanges via increasingly sophisticated cyber methods.
6 months ago
Kill Chain
US Treasury Lifts Sanctions on Key Intellexa Predator Spyware Figures
In December 2025, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) removed three individuals previously sanctioned for their involvement with Intellexa and its Predator commercial spyware from the Specially Designated Nationals (SDN) list. The individuals—Merom Harpaz, Andrea Nicola Constantino Hermes Gambazzi, and Sara Aleksandra Fayssal Hamou—were linked to leadership and distribution roles within the Intellexa Consortium. Their removal followed a petition and OFAC’s evaluation that they had separated themselves from the Intellexa ecosystem, but no underlying details or independent confirmation were disclosed. The original sanctions stemmed from their roles in developing, distributing, and enabling Predator software, a tool implicated in high-profile surveillance of civil society figures, including journalists and activists, through stealth zero-day and social engineering attacks. This case underscores the continued risks posed by commercial spyware vendors and associated compliance exposures. Ongoing public reporting highlights Predator’s persistent activity despite regulatory efforts, as well as geopolitical pressures that drive international balkanization and new attack trends targeting sensitive sectors. With regulatory frameworks evolving and threat actors shifting tactics, the risk of spyware misuse for human rights abuses and espionage remains acute.
6 months ago
Kill Chain
INTERPOL’s Landmark Crackdown: 574 Cybercrime Arrests across Africa in Operation Sentinel
In November 2025, INTERPOL coordinated Operation Sentinel across 19 African nations, resulting in the arrest of 574 suspected cybercriminals and recovery of $3 million. The operation targeted major cybercrime networks involved in business email compromise (BEC), digital extortion, and related ransomware campaigns. Notably, a Ukrainian national associated with ransomware operations pled guilty, highlighting the global breadth of these criminal networks. The operation uncovered sophisticated use of encrypted communication and lateral movement tactics to evade detection, impacting financial institutions and businesses across the continent. The crackdown underscores the evolving nature of cybercrime, with attackers leveraging advanced techniques and international collaboration among law enforcement agencies rising in response. Increased BEC and ransomware threats have pressed organizations in Africa and globally to evaluate existing cybersecurity and compliance controls.
6 months ago
Kill Chain
CISA Flags Active Exploitation of Digiever Authorization Vulnerability (CVE-2023-52163)
In December 2023, CISA added CVE-2023-52163 to its Known Exploited Vulnerabilities Catalog after identifying active exploitation of a missing authorization vulnerability in Digiever DS-2105 Pro network video recorders. Malicious actors leveraged this flaw to gain unauthorized access to sensitive functions and video data, bypassing authentication controls. The exploitation exposed affected organizations to privacy breaches, potential lateral movement within networks, and possible compromise of video surveillance infrastructure. The vulnerability is particularly concerning for agencies required to comply with Binding Operational Directive 22-01, raising enterprise risks related to data integrity, operational continuity, and regulatory responsibility. This incident underscores a broader trend of attackers exploiting well-known yet unpatched vulnerabilities in internet-connected devices. Recent months have seen an increase in targeting of IoT and NVR platforms, highlighting the urgency for prioritized vulnerability management as threat actors continue to shift focus towards overlooked or legacy systems.
6 months ago
Kill Chain
US DOJ Indicts 54 for Ploutus Malware ATM Jackpotting: Tren de Aragua’s US Crime Wave, 2025
In December 2025, the U.S. Department of Justice charged 54 individuals associated with the Tren de Aragua criminal gang in a far-reaching ATM jackpotting operation across the United States. By deploying Ploutus malware onto automated teller machines, the group manipulated hardware to force cash withdrawals—ultimately stealing millions of dollars. The multi-state scheme involved coordinated physical access to ATMs, installation of malicious software, and cash-out teams, highlighting significant vulnerabilities in banking infrastructure and ATM security controls. This incident underscores an escalating wave of financially motivated attacks leveraging sophisticated malware and organized criminal networks. With jackpotting attacks resurging globally and law enforcement intensifying their response, organizations must prioritize layered defenses, real-time anomaly detection, and compliance with evolving regulatory requirements.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports