✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Real Estate/Mortgage
Breach intelligence, attack campaigns, and threat reports targeting the Real Estate/Mortgage sector.
Explore Other Sectors
Real Estate/Mortgage Threat Reports
Spanish Authorities Dismantle €140 Million Cyber Fraud Network
In July 2026, Spanish authorities dismantled a cybercrime and money-laundering network responsible for defrauding €140 million through investment fraud and Business Email Compromise (BEC) schemes. The operation led to the arrest of four individuals across Spain, Portugal, and Panama. The criminals managed over 800 bank accounts, utilizing sophisticated social engineering tactics such as impersonating executives and issuing false invoices to divert funds into accounts they controlled. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/spanish-police-take-down-140-million-cyber-fraud-ring-arrest-four/?utm_source=openai)) This incident underscores the escalating threat of BEC attacks, which exploit organizational trust and email communications to execute financial fraud. The substantial financial impact highlights the necessity for organizations to implement robust email security measures, employee training, and stringent verification processes to mitigate such risks.
1 week ago
Kill Chain
FBI Issues Warning on Fake Permit Fee Phishing Scam
In March 2026, the FBI issued a public alert regarding a sophisticated phishing campaign where cybercriminals impersonated city and county planning officials to defraud property owners. By leveraging publicly accessible permit records, these actors sent emails to individuals with active applications, demanding payments for fictitious permit fees via wire transfers, peer-to-peer transfers, or cryptocurrency. The emails were meticulously crafted, incorporating real permit details to enhance credibility, leading victims to authorize payments that bypassed traditional fraud detection mechanisms. This scheme resulted in significant financial losses and highlighted vulnerabilities in existing payment verification processes. The urgency of this issue is underscored by the rapid escalation of government impersonation scams, which nearly doubled in reported losses to approximately $798 million in 2025. The increasing sophistication of these attacks, particularly their ability to exploit publicly available data and evade standard fraud detection systems, necessitates immediate attention and the development of more robust security measures to protect individuals and businesses from such fraudulent activities.
1 week ago
Kill Chain
Defending Against AI-Enhanced Business Email Compromise in 2026
In 2026, Business Email Compromise (BEC) attacks have evolved into sophisticated, multi-stage operations. Threat actors gain access to organizational mailboxes or SaaS accounts, meticulously analyze internal communications, and exploit financial processes to execute fraudulent transactions. The integration of AI technologies has enhanced the quality and efficiency of these scams, making them increasingly difficult to detect. The prevalence of BEC attacks has surged, with 74% of organizations reporting incidents in 2025, up from 63% in 2024. ([nacha.org](https://www.nacha.org/news/business-email-compromise-attempts-rose-sharply-2025-report-finds?utm_source=openai)) This trend underscores the urgent need for organizations to bolster their cybersecurity measures and employee training to mitigate the escalating threat posed by BEC schemes.
3 weeks ago
Kill Chain
Urgent Update: WP Maps Pro Vulnerability (CVE-2026-8732) Threatens WordPress Sites
In May 2026, a critical vulnerability (CVE-2026-8732) was discovered in the WP Maps Pro plugin for WordPress, affecting versions up to and including 6.1.0. This flaw allowed unauthenticated attackers to create administrator accounts by exploiting an insecure AJAX endpoint, leading to potential full site takeovers. The vulnerability stemmed from inadequate nonce protection, making it possible for attackers to bypass authentication mechanisms and gain elevated privileges. The exploitation of this vulnerability underscores the persistent risks associated with third-party plugins in content management systems. It highlights the necessity for website administrators to maintain rigorous update practices and implement robust security measures to mitigate such threats.
1 month ago
Kill Chain
Critical Vulnerability in ABB EIBPORT Devices Disclosed
In May 2026, ABB disclosed a critical vulnerability in its EIBPORT V3 KNX and KNX GSM devices, versions prior to 3.9.2. The flaw, identified as CVE-2021-22291, is a cross-site scripting (XSS) vulnerability that could allow attackers to access sensitive information and alter device configurations. ABB has released firmware updates to address this issue and recommends immediate application to mitigate potential risks. This incident underscores the persistent threat of web-based vulnerabilities in industrial control systems, emphasizing the need for continuous monitoring and timely patch management to protect critical infrastructure from evolving cyber threats.
1 month ago
Kill Chain
ADT Data Breach 2026: Lessons in SSO Security
In April 2026, home security company ADT experienced a data breach orchestrated by the ShinyHunters extortion group. The attackers gained unauthorized access to ADT's systems through a voice phishing (vishing) attack, compromising an employee's Okta single sign-on (SSO) account. This access allowed them to infiltrate ADT's Salesforce instance and exfiltrate personal information, including names, phone numbers, addresses, and, in some cases, dates of birth and partial Social Security numbers. Notably, no payment information or customer security systems were affected. ADT promptly terminated the intrusion, launched an investigation, and notified all affected individuals. This incident underscores the escalating threat posed by sophisticated social engineering attacks targeting SSO credentials. Organizations must enhance their security awareness training and implement robust multi-factor authentication protocols to mitigate such risks.
2 months ago
Kill Chain
ADT Data Breach 2026: Lessons in Cloud Security and Social Engineering
In April 2026, home security giant ADT experienced a significant data breach orchestrated by the cyber extortion group ShinyHunters. The attackers gained unauthorized access to ADT's cloud-based environments by compromising an employee's Okta single sign-on (SSO) account through a voice phishing (vishing) attack. This breach led to the exfiltration of personal information belonging to approximately 5.5 million individuals, including names, phone numbers, physical addresses, dates of birth, and partial Social Security numbers or Tax IDs. Notably, no payment information or customer security systems were compromised. This incident underscores the escalating threat posed by sophisticated social engineering tactics targeting SSO credentials. Organizations must bolster their defenses against such attacks, as the reliance on cloud-based services and centralized authentication systems continues to grow, making them attractive targets for cybercriminals.
2 months ago
Kill Chain
Cybercriminals Exploit Vacant Homes to Intercept Mail and Commit Fraud
In April 2026, cybersecurity analysts uncovered a sophisticated fraud scheme where adversaries exploit vacant residential properties to intercept sensitive mail, facilitating identity theft and financial fraud. Attackers identify unoccupied homes through real estate listings, register for postal services like Informed Delivery to monitor incoming mail, and use change-of-address requests to redirect mail to addresses under their control. This method combines open-source intelligence, legitimate postal services, and fake identities to gain persistent access to victims' correspondence. This incident highlights a growing trend where cybercriminals blend digital tactics with physical-world manipulation, exploiting legitimate services to bypass traditional cybersecurity defenses. The rise in such hybrid cybercrime underscores the need for enhanced vigilance and cross-domain monitoring to detect and prevent these evolving threats.
3 months ago
Kill Chain
Critical Security Flaws in Apeman Cameras: A 2025 Analysis
In late 2025, multiple critical vulnerabilities were identified in Apeman ID71 cameras, including hard-coded credentials (CVE-2025-11126), cross-site scripting (CVE-2025-11851), and missing authentication for critical functions (CVE-2025-11852). These flaws could allow remote attackers to gain unauthorized access, manipulate device settings, or intercept camera feeds. Despite early notifications, Apeman did not respond to these disclosures, leaving devices exposed to potential exploitation. The prevalence of IoT devices with unpatched vulnerabilities underscores the urgent need for manufacturers to implement robust security measures and for users to apply timely updates. This incident highlights the critical importance of proactive vulnerability management in safeguarding connected devices against emerging threats.
4 months ago
Kill Chain
FBI Issues Warning on Phishing Attacks Impersonating Local Government Officials
In March 2026, the FBI issued a warning about a phishing campaign where criminals impersonated U.S. city and county officials to target individuals and businesses applying for land-use permits. The attackers used publicly available information to craft convincing emails, instructing victims to pay fraudulent fees via wire transfer, peer-to-peer payment, or cryptocurrency. This scheme exploited the victims' trust in official communications, leading to financial losses and potential exposure of sensitive information. This incident underscores a growing trend of cybercriminals leveraging publicly accessible data to enhance the credibility of their phishing attacks. The increasing sophistication of such schemes highlights the urgent need for heightened vigilance and robust verification processes in all interactions involving sensitive transactions.
4 months ago
Kill Chain
Microsoft Dismantles RedVDS: Takedown of a Major Cybercrime Infrastructure in 2026
In January 2026, Microsoft, in collaboration with Europol and German authorities, disrupted RedVDS, a global cybercrime-as-a-service platform responsible for at least $40 million in fraud losses since March 2025. RedVDS provided criminals with affordable, disposable virtual Windows servers and administrator-level access, enabling mass phishing, business email compromise (BEC) scams, credential theft, and sophisticated social engineering—including attacks leveraging AI technologies. The takedown involved legal action, seizure of RedVDS infrastructure, and removal of its marketplace and customer portal, significantly impacting cybercriminal campaigns that leveraged these services to attack organizations and individuals worldwide. This incident underscores the increasing threat posed by cybercrime-as-a-service models, which drastically lower barriers for criminals to launch high-volume, geographically-targeted attacks leveraging cloud infrastructure. The rise of AI-generated phishing, deepfakes, and anonymized payment methods heightens risk, challenging both organizational defenses and global law enforcement.
6 months ago
Kill Chain
Microsoft & Law Enforcement Dismantle RedVDS Cybercrime Platform in 2026
In January 2026, Microsoft, in collaboration with U.S. and U.K. law enforcement, disrupted the RedVDS cybercrime infrastructure, dismantling a crimeware-as-a-service network that fueled millions in global fraud losses. Managed by the threat actor Storm-2470, RedVDS offered inexpensive, disposable Windows-based RDP servers with no logging, enabling cybercriminals to conduct mass phishing, business email compromise (BEC) schemes, account takeovers, and other online fraud at scale. RedVDS’s infrastructure was critical in facilitating over $40 million in reported fraud losses in the U.S. since March 2025, impacting at least 191,000 organizations across sectors like healthcare, legal, finance, manufacturing, and real estate. The incident underscores the rapidly growing risk posed by cybercrime subscription models that democratize access to sophisticated attack tools. As CaaS platforms pair with generative AI, threat actors are increasingly able to automate and scale targeted campaigns, elevating both regulatory risk and enterprise exposure across all industries.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports