<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Krebs on Security</title>
	<atom:link href="https://krebsonsecurity.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://krebsonsecurity.com</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Sat, 10 Oct 2026 21:03:33 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.6.9</generator>
	<item>
		<title>FBI Arrests Executive at Ransomware Negotiation Firm</title>
		<link>https://krebsonsecurity.com/2026/10/fbi-arrests-founder-of-ransomware-negotiation-firm/</link>
					<comments>https://krebsonsecurity.com/2026/10/fbi-arrests-founder-of-ransomware-negotiation-firm/#comments</comments>
		
		<dc:creator><![CDATA[BrianKrebs]]></dc:creator>
		<pubDate>Sat, 10 Oct 2026 00:17:42 +0000</pubDate>
				<category><![CDATA[A Little Sunshine]]></category>
		<category><![CDATA[Breadcrumbs]]></category>
		<category><![CDATA[Ne'er-Do-Well News]]></category>
		<category><![CDATA[The Coming Storm]]></category>
		<category><![CDATA[Cyber Extortion Strategic Response]]></category>
		<category><![CDATA[CyberSteward]]></category>
		<category><![CDATA[Cypfer]]></category>
		<category><![CDATA[Edward Dubrovsky]]></category>
		<category><![CDATA[FBI Director Kash Patel]]></category>
		<category><![CDATA[ShinyHunters]]></category>
		<guid isPermaLink="false">https://krebsonsecurity.com/?p=74440</guid>

					<description><![CDATA[Agents with the Federal Bureau of Investigation (FBI) on Thursday arrested the co-founder of a Canadian cybersecurity firm in connection with an investigation into the ShinyHunters hacking group that recently relieved the FBI of sensitive data on thousands of agents, multiple sources tell KrebsOnSecurity.]]></description>
										<content:encoded><![CDATA[<p>Agents with the <strong>Federal Bureau of Investigation</strong> (FBI) on Thursday arrested an executive at a Canadian cybersecurity firm in connection with an investigation into the <strong>ShinyHunters</strong> hacking group that recently relieved the FBI of sensitive data on thousands of agents, multiple sources tell KrebsOnSecurity.</p>
<p>The New York Times <a href="https://www.nytimes.com/2026/10/09/us/politics/fbi-hack-shinyhunters-arrest.html" target="_blank" rel="noopener">reported today</a> that the FBI has arrested a Canadian man in Pennsylvania on suspicion of assisting ShinyHunters. The Times story did not identify the man, nor did <a href="https://x.com/FBIDirectorKash/status/2108566367011999780?s=46&amp;t=jxLTOF6G9gZnhmWqh93ZrA" target="_blank" rel="noopener">a statement</a> on Twitter/X about the arrest from <strong>FBI Director Kash Patel</strong>.</p>
<p>One source close to the investigation told KrebsOnSecurity the Canadian person arrested this week was visiting Pennsylvania for a cyber insurance conference, and that the suspect&#8217;s company specialized in handling ransomware negotiations with cybercrime groups. Another shared that control over the ShinyHunters investigation has been centralized at an FBI field office in Texas.</p>
<p>An online search reveals the <a href="https://netdiligence.com/conferences/cyber-risk-summit-philadelphia-2026/speakers" target="_blank" rel="noopener">Cyber Risk Summit</a> was held at the Loews Philadelphia Hotel between Oct. 5 and Oct. 7. The conference had several sponsors, but according to the summit&#8217;s website its <a href="https://netdiligence.com/conferences/cyber-risk-summit-philadelphia-2026/sponsors" target="_blank" rel="noopener">biggest sponsor</a> was a Canadian security company called <strong>Cypfer</strong>.</p>
<p>According to LinkedIn, one of Cypfer&#8217;s &#8220;ex-founders&#8221; was <strong>Edward Dubrovsky</strong>, who is now associated with another Canadian security firm and sponsor called <strong>CyberSteward</strong>. In a post to LinkedIn approximately one month ago, Dubrovsky said he had plans to attend the Cyber Risk Summit with the rest of the CyberSteward team.</p>
<p>[<strong>Update: Oct. 10, 9:58 a.m. ET:</strong> A spokesperson for Cypfer said Dubrovsky was not a founder or co-founder as his LinkedIn profile claims, but instead served as a managing director before resigning in November 2025].</p>
<div id="attachment_74445" style="width: 798px" class="wp-caption aligncenter"><img fetchpriority="high" decoding="async" aria-describedby="caption-attachment-74445" class="size-full wp-image-74445" src="https://krebsonsecurity.com/wp-content/uploads/2026/10/dubrovsky-li.png" alt="" width="788" height="495" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/10/dubrovsky-li.png 788w, https://krebsonsecurity.com/wp-content/uploads/2026/10/dubrovsky-li-768x482.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/10/dubrovsky-li-782x491.png 782w" sizes="(max-width: 788px) 100vw, 788px" /><p id="caption-attachment-74445" class="wp-caption-text">Edward Dubrovsky&#8217;s LinkedIn profile.</p></div>
<p>&#8220;Looking forward to continuing conversations around strategy &amp; compliant driven coercive (ransomware, extortion) advisory, negotiations and settlement services that are global and truly agnostic,&#8221; Dubrovsky wrote.</p>
<p>Federal court records show that on October 8, an Edward Dobrovsky (note the slight misspelling of the last name) was arrested in Pennsylvania on cyber extortion and conspiracy charges. Several of those documents &#8212; including the core complaint &#8212; are now sealed. But a handful of them were <a href="https://www.courtlistener.com/docket/74942095/united-states-v-dobrovsky/" target="_blank" rel="noopener">indexed at Courtlistener.com</a>, including a summary of the complaint, which charges the defendant with &#8220;conspiracy to threaten to impair the confidentiality of information with the intent to extort money,&#8221; and &#8220;interference with commerce by threats.&#8221;</p>
<div id="attachment_74446" style="width: 759px" class="wp-caption aligncenter"><img decoding="async" aria-describedby="caption-attachment-74446" class=" wp-image-74446" src="https://krebsonsecurity.com/wp-content/uploads/2026/10/dubrovsky-courtlistener.png" alt="" width="749" height="597" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/10/dubrovsky-courtlistener.png 842w, https://krebsonsecurity.com/wp-content/uploads/2026/10/dubrovsky-courtlistener-768x612.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/10/dubrovsky-courtlistener-782x623.png 782w" sizes="(max-width: 749px) 100vw, 749px" /><p id="caption-attachment-74446" class="wp-caption-text">Image: Courtlistener.com</p></div>
<p>The inmate locator at the <strong>U.S. Bureau of Prisons</strong> website reports that a 54-year-old Edward Dubrovsky is currently being held at a federal facility in Philadelphia. But <a href="https://www.courtlistener.com/docket/74942095/united-states-v-dobrovsky/" target="_blank" rel="noopener">the court records</a> indexed by CourtListener include a notice filed on October 9 that moved the case to the Eastern District of Texas, which sources say is now the epicenter of the FBI&#8217;s ShinyHunters investigation. The FBI declined to comment for this story.<span id="more-74440"></span></p>
<p>Dubrovsky&#8217;s <a href="https://www.linkedin.com/in/edubrovs/" target="_blank" rel="noopener">LinkedIn profile</a> states he is the author of <em>Cyber Extortion Strategic Response</em>, a 252-page book that promises to &#8220;take readers beyond the ransom note and into the decisions that determine how an organization responds, recovers, and protects what matters.&#8221;</p>
<div id="attachment_74441" style="width: 521px" class="wp-caption aligncenter"><img decoding="async" aria-describedby="caption-attachment-74441" class="size-full wp-image-74441" src="https://krebsonsecurity.com/wp-content/uploads/2026/10/dubrovskybook.png" alt="" width="511" height="745" /><p id="caption-attachment-74441" class="wp-caption-text">Edward Dubrovsky&#8217;s book, which centers on the intricacies of ransomware negotiations.</p></div>
<p>&#8220;At the heart of the book is a critical distinction: communicating with a criminal is not the same as negotiating a payment, and negotiating is not a commitment to pay,&#8221; reads an excerpt from the book&#8217;s listing on Amazon. &#8220;Engagement can serve other objectives, including testing claims, gathering information, creating time, and preserving options while the organization evaluates its next move.&#8221;</p>
<p>Mr. Dubrovsky could not be immediately reached for comment. KrebsOnSecurity also sought comment from other executives at CyberSteward, and will update this post in the event they respond. The available court records in Dubrovsky&#8217;s case show that he does not currently have an attorney and has yet to be appointed a public defender by the courts.</p>
<p>ShinyHunters typically uses phishing and stolen credentials to siphon data from corporate accounts at software-as-a-service companies, and then threatens to publish the stolen data online unless a ransom demand is paid. According to the FBI, the group has extorted more than $70 million from victims so far this year.</p>
<p>Sources tell KrebsOnSecurity the FBI has been poring over devices that were seized last month when the Dutch police <a href="https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/" target="_blank" rel="noopener">arrested the convicted cybercriminal Pepijn van der Stap</a> in connection with the ShinyHunters investigation, and that charges against principals at other companies that specialize in ransomware negotiation may be forthcoming.</p>
<p>Immediately after Van der Stap&#8217;s arrest, another member of ShinyHunters named &#8220;<strong>Rey</strong>&#8221; assumed control over the group and began taunting the FBI over data the group stole from the agency&#8217;s online recruitment portal, which included each’s person’s unit and specialization, as well as medical and psychiatric records.</p>
<p>Last week, Reuters reported that Rey &#8212; identified as a teenager named <strong>Saif Al-din Khader</strong> &#8212; had been detained and was cooperating with FBI investigators. On October 7, we <a href="https://krebsonsecurity.com/2026/10/shinyhunters-extorted-boeing-spin-off-prior-to-arrests/" target="_blank" rel="noopener">detailed</a> how Rey was apprehended as the cybercrime group allegedly sought to extort a navigation and digital aviation unit that was divested by Boeing in late 2025.</p>
<p><em>This is likely to be a fast-moving story. Updates will be noted along with timestamps.</em></p>
]]></content:encoded>
					
					<wfw:commentRss>https://krebsonsecurity.com/2026/10/fbi-arrests-founder-of-ransomware-negotiation-firm/feed/</wfw:commentRss>
			<slash:comments>14</slash:comments>
		
		
			</item>
		<item>
		<title>ShinyHunters Extorted Boeing Spin-off Prior to Arrests</title>
		<link>https://krebsonsecurity.com/2026/10/shinyhunters-extorted-boeing-spin-off-prior-to-arrests/</link>
					<comments>https://krebsonsecurity.com/2026/10/shinyhunters-extorted-boeing-spin-off-prior-to-arrests/#comments</comments>
		
		<dc:creator><![CDATA[BrianKrebs]]></dc:creator>
		<pubDate>Wed, 07 Oct 2026 13:48:45 +0000</pubDate>
				<category><![CDATA[A Little Sunshine]]></category>
		<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[Ne'er-Do-Well News]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[The Coming Storm]]></category>
		<category><![CDATA[Accenture]]></category>
		<category><![CDATA[Benjamin Korper]]></category>
		<category><![CDATA[Boeing]]></category>
		<category><![CDATA[CL0P]]></category>
		<category><![CDATA[CVE-2026-35273]]></category>
		<category><![CDATA[fbi]]></category>
		<category><![CDATA[Google Threat Intelligence Group]]></category>
		<category><![CDATA[Jeppesen ForeFlight]]></category>
		<category><![CDATA[Mandiant]]></category>
		<category><![CDATA[Neo Security]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[PeopleSoft]]></category>
		<category><![CDATA[Pepijn van der Stap]]></category>
		<category><![CDATA[Reuters]]></category>
		<category><![CDATA[Royal Jordanian Airlines]]></category>
		<category><![CDATA[Saif Al-Din Khader]]></category>
		<category><![CDATA[ShinyHunters]]></category>
		<category><![CDATA[Umbreon]]></category>
		<guid isPermaLink="false">https://krebsonsecurity.com/?p=74398</guid>

					<description><![CDATA[A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group ShinyHunters has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. KrebsOnSecurity has learned that the suspect, who uses the hacker handle "Rey," was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace company Boeing, which manufactures the fleet of planes used by the employer of Rey's father -- Royal Jordanian Airlines.]]></description>
										<content:encoded><![CDATA[<p>A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group <strong>ShinyHunters</strong> has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. KrebsOnSecurity has learned that the suspect, who uses the hacker handle &#8220;<strong>Rey</strong>,&#8221; was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace company <strong>Boeing</strong>, which manufactures the fleet of planes used by the employer of Rey&#8217;s father &#8212; <strong>Royal Jordanian Airlines</strong>.</p>
<div id="attachment_74418" style="width: 760px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74418" class=" wp-image-74418" src="https://krebsonsecurity.com/wp-content/uploads/2026/10/Jeppesen.png" alt="" width="750" height="679" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/10/Jeppesen.png 835w, https://krebsonsecurity.com/wp-content/uploads/2026/10/Jeppesen-768x695.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/10/Jeppesen-782x708.png 782w" sizes="(max-width: 750px) 100vw, 750px" /><p id="caption-attachment-74418" class="wp-caption-text">The logo for Jeppesen ForeFlight, a business unit divested last year by the aerospace firm Boeing.</p></div>
<p>On October 3, <strong>Reuters</strong> <a href="https://www.reuters.com/world/middle-east/key-shinyhunters-hacker-detained-jordan-is-cooperating-sources-say-2026-10-03/" target="_blank" rel="noopener">cited</a> three unnamed sources saying a suspected ShinyHunters member in Amman named <strong>Saif Al-din Khader</strong> was detained by Jordanian authorities and was cooperating with the FBI. KrebsOnSecurity identified Rey as Khader in <a href="https://krebsonsecurity.com/2025/11/meet-rey-the-admin-of-scattered-lapsus-hunters/" target="_blank" rel="noopener">a November 2025 profile</a>, in which the young man admitted working with multiple ransomware groups.</p>
<p>Rey was featured again in <a href="https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/" target="_blank" rel="noopener">a September 28 exclusive</a> about the Dutch police arresting 24-year-old convicted cybercriminal <strong>Pepijn van der Stap</strong> on suspicion of aiding in data thefts and extortions by ShinyHunters. The story noted that immediately following the Dutchman&#8217;s arrest on the evening of September 15, Rey assumed control over the ShinyHunters brand and boasted publicly about stealing highly sensitive data from the <strong>FBI</strong> and extorting the ransomware group <strong>Cl0p</strong>.</p>
<p>Rey taunted both the FBI and Cl0p with memes posted to his longtime account on Twitter/X, while simultaneously including images of the avatar used by Van Der Stap&#8217;s former hacker alias &#8220;<strong>Umbreon</strong>&#8221; in an apparent attempt to frame the Dutchman for both hacks.</p>
<div id="attachment_74362" style="width: 637px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74362" class="size-full wp-image-74362" src="https://krebsonsecurity.com/wp-content/uploads/2026/09/rey-cl0p-fbi.png" alt="" width="627" height="843" /><p id="caption-attachment-74362" class="wp-caption-text">A taunting meme uploaded to Twitter/X by Rey on Sept. 22. A giant sized version of the Pokemon character Umbreon can be seen in the bottom left.</p></div>
<p>As noted in our September 28 report, ShinyHunters gained access to the FBI site and other victims by exploiting a vulnerability (CVE-2026-35273) in <strong>PeopleSoft</strong>, a software-as-a-service platform from the tech giant <strong>Oracle</strong> that is broadly used by companies to manage hiring and human resources, benefits and payroll. Oracle quickly issued a fix for CVE-2026-35273, which ShinyHunters first began exploiting as a zero-day in June, and at the time Mandiant released web application firewall rules intended for organizations that couldn’t apply the security update quickly enough.</p>
<p>ShinyHunters <a href="https://www.bleepingcomputer.com/news/security/oracle-peoplesoft-servers-hacked-in-shinyhunters-data-theft-attacks/" target="_blank" rel="noopener">told BleepingComputer in June</a> that the original goal behind exploiting the PeopleSoft vulnerability was to breach the FBI&#8217;s own PeopleSoft database, but the hackers said those attacks were unsuccessful for some reason. In recent weeks, however, ShinyHunters <a href="https://www.bleepingcomputer.com/news/security/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks/" target="_blank" rel="noopener">turned to a well-known URL-encoding trick</a> to bypass Mandiant’s suggested web application firewall rules.</p>
<p>In <a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft" target="_blank" rel="noopener">a report</a> released Sept. 25, security experts at <strong>Mandiant</strong> and the <strong>Google Threat Intelligence Group</strong> (GTIG) confirmed that ShinyHunters had mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across a range of industries, including higher education, technology, healthcare, agriculture, transportation and government.</p>
<p>Reuters <a href="https://www.reuters.com/technology/accenture-contractor-removed-fbi-following-damaging-data-breach-sources-say-2026-10-06/" target="_blank" rel="noopener">reported October 5</a> that the FBI has removed a contractor at <strong>Accenture</strong> over their failure to patch the FBI recruitment website hacked by ShinyHunters, which exposed sensitive data on more than 5,000 FBI personnel, including each&#8217;s person&#8217;s unit and specialization, as well as medical and psychiatric records.</p>
<h2>&#8216;REY&#8217; MEANS KING, AS IN ROYAL</h2>
<p>According to two sources familiar with the ShinyHunters investigation, a navigation and digital aviation unit recently divested by the global aerospace company <strong>Boeing</strong> was among the victims that ShinyHunters was in the process of extorting when Rey was apprehended by Jordanian authorities.</p>
<p>Those sources said the FBI&#8217;s investigation into ShinyHunters gained renewed urgency with the group&#8217;s attempted extortion of the former Boeing unit, which allegedly included the theft of sensitive information that sources said could pose operational safety and security risks.</p>
<p>In a brief statement shared with KrebsOnSecurity, Boeing acknowledged the extortion attempts by ShinyHunters, and said the incident concerned data stolen from <strong>Jeppesen ForeFlight</strong>, a subsidiary that Boeing <a href="https://www.reuters.com/business/aerospace-defense/buyout-firm-thoma-bravo-nears-deal-boeings-jeppesen-unit-bloomberg-news-reports-2025-04-22/" target="_blank" rel="noopener">sold in November 2025</a> to the private equity firm Thoma Bravo for $10.55 billion.</p>
<p>&#8220;We are aware of claims by a threat actor regarding data allegedly associated with Boeing and our former subsidiary Jeppesen ForeFlight,&#8221; a Boeing spokesperson shared. &#8220;We are actively reviewing the matter with the Jeppesen ForeFlight team.”</p>
<p>A spokesperson for Jeppesen ForeFlight shared a written statement in response to questions, saying the company has seen no impact on their end. &#8220;Based on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products.&#8221;</p>
<p>Rey&#8217;s alleged involvement in attempting to extort the former Boeing unit is noteworthy because there is strong evidence that his father works for <strong>Royal Jordanian Airlines</strong>, which is mostly controlled by the Jordanian government and operates its long-haul fleet on passenger planes built by Boeing. Rey claimed on Telegram in early 2025 that his father was an airline pilot, although that could not be independently confirmed.</p>
<p>However, as noted in <a href="https://krebsonsecurity.com/2025/11/meet-rey-the-admin-of-scattered-lapsus-hunters/" target="_blank" rel="noopener">our November 2025 profile of Rey</a>, his family&#8217;s shared computer was at one point compromised by password-stealing malware, and the data collected by that malware clearly shows Rey&#8217;s father used the same credentials to log in at multiple online portals for Royal Jordanian Airlines employees.</p>
<p>Royal Jordanian Airlines has not yet responded to a request for comment. In advance of our September 28 story, KrebsOnSecurity once again emailed Rey&#8217;s father to seek comment and update him on his son&#8217;s alleged activities. Neither of the Khaders have responded. But just hours after that request was sent, Rey began deleting his various social media accounts, including the Twitter/X account he previously used to taunt the FBI, Cl0p, and other ShinyHunters victims.</p>
<p>Rey may have nixed many of his social media profiles, but his cybersecurity blog on GitHub somehow escaped the purge, and it shows that Rey was fixated on the leaders of the Cl0p ransomware group. In March 2026, Rey&#8217;s blog featured <a href="https://rmoskovy.github.io/posts/who-runs-clop-ransomware-investigation/" target="_blank" rel="noopener">a lengthy post</a> that identified two Russian men as the core developers and hackers behind Cl0p.</p>
<div id="attachment_74407" style="width: 758px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74407" class=" wp-image-74407" src="https://krebsonsecurity.com/wp-content/uploads/2026/10/rey-cl0p.png" alt="" width="748" height="462" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/10/rey-cl0p.png 1285w, https://krebsonsecurity.com/wp-content/uploads/2026/10/rey-cl0p-768x474.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/10/rey-cl0p-782x483.png 782w" sizes="(max-width: 748px) 100vw, 748px" /><p id="caption-attachment-74407" class="wp-caption-text">Rey&#8217;s blog on GitHub. This post doxes two Russian men as the core operators behind Cl0p, one of the oldest and most established ransomware groups still in operation today.</p></div>
<p><span id="more-74398"></span></p>
<h2>MURDER FOR HIRE?</h2>
<p>Meanwhile, news outlets in the Netherlands reported explosive new allegations leveled at Van der Stap, whose supposed personal transformation from convicted to reformed hacker has been widely covered in the tech news media. The Dutch daily <a href="https://www.rtl.nl/nieuws/binnenland/artikel/5656154/pepijn-van-der-s-verdacht-van-opdracht-geven-moorden" target="_blank" rel="noopener">RTL reported on Sept. 29</a> that investigators suspect Van der Stap tried to orchestrate at least two murders. According to RTL, the murders were allegedly to be committed abroad, and there are indications Van der Stap gave the order for these attacks.</p>
<p>Van der Stap was released from prison after serving the better part of a four year sentence for data theft and extortion activity that prosecutors said netted between €1.5 million and €2.7 million. In an interview with KrebsOnSecurity on September 9, Van der Stap described his new role as &#8220;offensive security lead&#8221; at the Dutch cybersecurity company <strong>Neo Security</strong>, saying the job involved probing client networks for security vulnerabilities.</p>
<p>Neo Security&#8217;s owner <strong>Benjamin Korper</strong> told Reuters he has hired an outside firm to investigate whether Van der Stap had hacked Neo Security or its customers, but that so far investigators have found no evidence he acted against his employer or clients. Korper said Dutch forensic investigators visited his office on September 15, the night Van der ⁠Stap was arrested in a dramatic police raid that reportedly involved <a href="https://www.at5.nl/artikelen/239945/speciale-eenheid-rivierenbuurt-amsterdam" target="_blank" rel="noopener">flash bang grenades</a>.</p>
<div id="attachment_74408" style="width: 776px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74408" class="size-full wp-image-74408" src="https://krebsonsecurity.com/wp-content/uploads/2026/10/at5-nl.png" alt="" width="766" height="628" /><p id="caption-attachment-74408" class="wp-caption-text">A screenshot of a Sept 16 story by the Dutch news outlet at5.nl, describing a police raid on Van Der Stap&#8217;s residence that reportedly used flash-bang grenades.</p></div>
<p>Prior to his first arrest in 2023, Van der Stap was working as a software engineer at the Amsterdam-based cybersecurity startup Hadrian, while volunteering at the Dutch Institute for Vulnerability Disclosure (DIVD) &#8212; even as he was hacking into and extorting a number of large organizations.</p>
<p>When asked in a recent interview why anyone should believe the word of a self-described &#8220;reformed&#8221; cybercriminal who had so casually deceived countless friends, co-workers and journalists for years, Van der Stap replied that his work spoke for itself and there was nothing he could say that would convince his worst critics.</p>
<p>&#8220;You can throw a bunch of nice words at someone, but you can&#8217;t convince them if they don&#8217;t want to be convinced,&#8221; Van der Stap told KrebsOnSecurity on Sept. 9. &#8220;I&#8217;m doing what I can to repay victims, and that&#8217;s all I can do. If someone doesn&#8217;t want to believe me, then that&#8217;s on them.&#8221;</p>
<h2>FRANCHISING AND BURNING A BRAND</h2>
<p>Cybercriminals aligned with ShinyHunters have been responsible for <a href="https://en.wikipedia.org/wiki/ShinyHunters" target="_blank" rel="noopener">dozens of data breaches</a> involving billions of stolen records, and breaches claimed by the group stretch back to at least 2019. But experts say the people recently operating behind the ShinyHunters name are not the same core members that populated the group in its early days, most of whom are French citizens who have been arrested (if not also imprisoned) on <a href="https://krebsonsecurity.com/wp-content/uploads/2026/10/k3l0t3x.png" target="_blank" rel="noopener">at least one prior occasion</a> for alleged cybercrime activity.</p>
<p>More to the point, ShinyHunters has become something of a franchise. Think the <a href="https://en.wikipedia.org/wiki/Dread_Pirate_Roberts" target="_blank" rel="noopener">Dread Pirate Roberts</a> character in the 1980s cult movie classic &#8220;The Princess Bride,&#8221; only succession by death is replaced with succession by arrest, and there can be multiple simultaneous Dread Pirate Robertses. Sources close to the investigation say the FBI is focusing on a remaining handful of cybercriminal freelancers or affiliates who have been feeding the group stolen credentials to various software-as-a-service (SaaS) platforms used by major companies in exchange for a cut of any data ransoms later paid by victims.</p>
<p>In the days after the news broke of Van der Stap&#8217;s arrest, a cybercrime-focused chat server on Telegram that was allegedly operated by Rey erupted with hot takes, with most participants heaping ridicule on the teenage hacker after he publicly backed down from threats against the FBI and Cl0p, and again when <a href="https://www.reuters.com/legal/government/shinyhunters-website-goes-offline-after-fbi-deadline-expires-2026-09-30/" target="_blank" rel="noopener">the ShinyHunters&#8217;s darknet website suddenly went offline</a>. Several commentators accused Rey of resurrecting the ShinyHunters brand after its core members were rounded up in France, and making a mockery of the group&#8217;s name and reputation ever since.</p>
<p>&#8220;He bought the old forum PGP key and used it to make new Breachforum websites and Telegram channels larping as ShinyHunters to ransom companies and then sell the used data or resell his forum when he goes broke,&#8221; one member recounted.</p>
<p>A relatively new Telegram channel called &#8220;The Battle&#8221; has been doxing and needling Rey and other alleged ShinyHunters members for several weeks, and it has gained a considerable readership among the cybercrime communities operating on Telegram. One of the coordinators of that harassment campaign repeatedly portrayed Rey as clueless greenhorn who sought to ride the coattails of a cybercriminal brand that has long enjoyed a reputation for ruthlessly selling or publishing data stolen from victim companies who refuse to give in to extortion demands.</p>
<p>&#8220;Rey (Saif Al-Din Khader) made a serious mistake when he started pretending to be a member of ShinyHunters,&#8221; wrote the administrators of The Battle server on Telegram. &#8220;That group had already been dismantled, with many of its members either arrested or imprisoned, yet Rey still chose to use its name while carrying out his crimes. We’re aware of claims that [Rey] caused over $200 million in damages and helped around 5–6 friend groups in the community make money by using Shiny Hunters group aliases to negotiate deals for a 25–30% cut over the past few months.&#8221;</p>
<p>In an interview with <a href="https://www.theregister.com/cyber-crime/2026/09/25/shinyhunters-tells-the-reg-we-hacked-the-fbi-to-protect-our-business/5299250" target="_blank" rel="noopener">The Register</a>, ShinyHunters claimed they hacked the FBI to counter the agency&#8217;s narrative in <a href="https://www.ic3.gov/PSA/2026/PSA260515" target="_blank" rel="noopener">a May 2026 alert</a> that advised victims against paying a ransom to the group, which came off looking unprofessional and capricious in the FBI&#8217;s advisory.</p>
<div id="attachment_74409" style="width: 758px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74409" class=" wp-image-74409" src="https://krebsonsecurity.com/wp-content/uploads/2026/10/fbi-sh-flashnotice.png" alt="" width="748" height="742" /><p id="caption-attachment-74409" class="wp-caption-text">A flash notice on ShinyHunters released by the FBI on May 15, 2026.</p></div>
<p>The public notice warned the group has been known to pursue a number of <a href="https://krebsonsecurity.com/2026/02/please-dont-feed-the-scattered-lapsus-shiny-hunters/" target="_blank" rel="noopener">different victim harassment strategies</a>, from sending threatening text messages and phone calls to victims and their family members to in some cases <a href="https://krebsonsecurity.com/tag/swatting/" target="_blank" rel="noopener">swatting</a> victims. The FBI warned ShinyHunters members &#8220;may also falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist.&#8221;</p>
<p>The hackers told The Register their attack on the FBI &#8220;demonstrated our technical capabilities and directly refuted the misinformation disseminated by the FBI, journalists, and industry researchers.&#8221; At the same time, the group&#8217;s leaders seemed to acknowledge that the FBI&#8217;s warning materially harmed their prospects for convincing victims to pay, saying &#8220;this was fundamentally a public relations and marketing initiative for our business.&#8221;</p>
]]></content:encoded>
					
					<wfw:commentRss>https://krebsonsecurity.com/2026/10/shinyhunters-extorted-boeing-spin-off-prior-to-arrests/feed/</wfw:commentRss>
			<slash:comments>20</slash:comments>
		
		
			</item>
		<item>
		<title>Dutch Police Arrest &#8216;Reformed&#8217; Hacker in Shiny Hunters Investigation</title>
		<link>https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/</link>
					<comments>https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/#comments</comments>
		
		<dc:creator><![CDATA[BrianKrebs]]></dc:creator>
		<pubDate>Mon, 28 Sep 2026 15:08:57 +0000</pubDate>
				<category><![CDATA[A Little Sunshine]]></category>
		<category><![CDATA[Latest Warnings]]></category>
		<category><![CDATA[Ne'er-Do-Well News]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[404 Media]]></category>
		<category><![CDATA[Bloomberg]]></category>
		<category><![CDATA[CL0P]]></category>
		<category><![CDATA[fbi]]></category>
		<category><![CDATA[Google Threat Intelligence Group]]></category>
		<category><![CDATA[KELA]]></category>
		<category><![CDATA[Mandiant]]></category>
		<category><![CDATA[Neo Security]]></category>
		<category><![CDATA[NL Times]]></category>
		<category><![CDATA[Odido]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[PeopleSoft]]></category>
		<category><![CDATA[Pepijn van der Stap]]></category>
		<category><![CDATA[Reuters]]></category>
		<category><![CDATA[ScatteredLapsussHunters]]></category>
		<category><![CDATA[ShinyHunters]]></category>
		<category><![CDATA[SLSH]]></category>
		<category><![CDATA[TeamPCP]]></category>
		<category><![CDATA[Umbreon]]></category>
		<category><![CDATA[wired]]></category>
		<guid isPermaLink="false">https://krebsonsecurity.com/?p=74341</guid>

					<description><![CDATA[Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p.]]></description>
										<content:encoded><![CDATA[<p>Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group <strong>ShinyHunters</strong>. In the days immediately following the suspect&#8217;s arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the <strong>FBI</strong> and extorting the Russian ransomware group <strong>Cl0p</strong>.</p>
<p>According to three sources familiar with the matter, the Dutch man arrested by authorities this month is <strong>Pepijn van der Stap</strong>, a convicted cybercriminal from Almere and Lelystad in the Netherlands. Van der Stap was previously convicted in 2023 in connection with a string of data thefts and extortions that prosecutors said earned between €1.5 million and €2.7 million.</p>
<p>At his trial in late 2023, van der Stap admitted that he lived a Dr. Jekyll and Mr. Hyde existence, secretly using the hacker handle &#8220;<strong>Umbreon</strong>&#8221; to extort victims and post their data on English language hacking communities like the now-defunct RaidForums and Breached. By day, however, van der Stap was working as a software engineer at the Amsterdam-based cybersecurity startup <strong>Hadrian</strong>, while volunteering at the <strong>Dutch Institute for Vulnerability Disclosure</strong> (DIVD), a nonprofit security research group.</p>
<div id="attachment_74364" style="width: 759px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74364" class=" wp-image-74364" src="https://krebsonsecurity.com/wp-content/uploads/2026/09/umbreon-nl-rf.png" alt="" width="749" height="852" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/09/umbreon-nl-rf.png 1556w, https://krebsonsecurity.com/wp-content/uploads/2026/09/umbreon-nl-rf-768x874.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/09/umbreon-nl-rf-1350x1536.png 1350w, https://krebsonsecurity.com/wp-content/uploads/2026/09/umbreon-nl-rf-782x890.png 782w" sizes="(max-width: 749px) 100vw, 749px" /><p id="caption-attachment-74364" class="wp-caption-text">Pepijn van der Stap&#8217;s alter ego &#8220;Umbreon&#8221; selling a database on RaidForums, offering information on 2.3 million people from The Netherlands in September 2021. This user&#8217;s avatar is a depiction of the Pokemon character Umbreon. Image: KELA.</p></div>
<p>Van der Stap confessed to his data theft and extortion activity, and was sentenced to four years in prison (one of which was suspended). During his trial, van der Stap opted to remain in custody for a time rather than at home, saying he could not find better treatment on the outside for his ongoing psychological issues, which he claimed included PTSD related to childhood trauma. He was released from prison in December 2025.</p>
<p>In an interview with KrebsOnSecurity on September 9, 2026, Van der Stap cast himself as a reformed hacker who was trying to turn his life around and make a positive contribution to society. Van der Stap is currently employed as offensive security lead at the Dutch company <strong>Neo Security</strong>, which did not respond to requests for comment.</p>
<p>Van der Stap said he was still dealing with civil lawsuits and restitution related to his previous cybercrime victims, and that he was trying his best to make amends. But not long after that interview, the Dutch hacker abruptly stopped replying to messages. Efforts by others close to him also repeatedly failed to elicit a response for the past two weeks.</p>
<div id="attachment_74374" style="width: 759px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74374" class=" wp-image-74374" src="https://krebsonsecurity.com/wp-content/uploads/2026/09/pvds-li.png" alt="" width="749" height="820" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/09/pvds-li.png 1574w, https://krebsonsecurity.com/wp-content/uploads/2026/09/pvds-li-768x841.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/09/pvds-li-1402x1536.png 1402w, https://krebsonsecurity.com/wp-content/uploads/2026/09/pvds-li-782x857.png 782w" sizes="(max-width: 749px) 100vw, 749px" /><p id="caption-attachment-74374" class="wp-caption-text">The LinkedIn profile for Pepijn van der Stap.</p></div>
<p>According to two sources with knowledge of the matter, Van der Stap was arrested by Dutch authorities on or around September 16, and has been held in custody for questioning since. One source said a colleague of theirs personally witnessed Dutch authorities carting items out of Van der Stap&#8217;s residence.</p>
<p>Authorities in the Netherlands have been <a href="https://www.politie.nl/nieuws/2026/september/7/11-stem-van-verdachte-odido-hack-te-horen-in-opsporing-verzocht.html" target="_blank" rel="noopener">asking the public for help</a> in identifying the voice in a recorded telephone call from February 2026 in which a native Dutch-speaking ShinyHunters member social engineered their way into <strong>Odido</strong>, the nation&#8217;s largest mobile telecommunications provider. In that intrusion, ShinyHunters tricked an Odido employee into logging in at a spoofed website, and then used that access to steal data on more than 6.2 million Dutch people.</p>
<p>Responding to Dutch news media, ShinyHunters confirmed that the suspect in the audio clip is indeed a member of the hacker collective.</p>
<p>&#8220;Our team member has our full support &#8211; emotionally, mentally, and financially,&#8221; the hackers said. &#8220;Everything has been arranged, including a criminal defense lawyer. We do not look down on our staff and members; we take excellent care of them,&#8221; reads a statement ShinyHunters shared with <a href="https://nltimes.nl/2026/09/08/shinyhunters-lawyer-police-release-audio-clip-suspect-odido-hack" target="_blank" rel="noopener">NL Times</a>. It remains unclear if the Dutch police have matched the Odido caller to a confirmed real-life identity. The Dutch police unit handling the Odido incident did not respond to requests for comment.</p>
<p>The group also lashed out at the authorities in the Netherlands. “The Dutch police will need all the luck in the world &#8211; and everyone’s prayers &#8211; if they want to catch him before we carry out another large-scale data theft in the Netherlands,&#8221; the ShinyHunters statement said. &#8220;Frankly, the Dutch police are a big joke; they are incapable of doing anything. Incompetent. Irrelevant. Unimportant. Useless.”<span id="more-74341"></span></p>
<h2>FBI, CL0P HACKS</h2>
<p>Just days after sources say Van der Stap was detained by Dutch authorities, ShinyHunters claimed credit for an unusually brazen breach at the FBI&#8217;s job application site apply.fbijobs.gov. According to <a href="https://archive.is/IQgWr" target="_blank" rel="noopener">reporting from 404 Media</a>, the data stolen from the FBI site includes Social Security numbers and <a href="https://www.bbc.com/news/articles/cw62me2vlj07o" target="_blank" rel="noopener">personal information</a> on more than 5,000 officials.</p>
<p>404 Media and <a href="https://archive.is/IQgWr" target="_blank" rel="noopener">Reuters reported</a> the FBI data included each person&#8217;s job title or team, such as special agent, threat intake examiner, major cybercrimes unit, and those investigating cyber threats from foreign state-backed actors. Reuters examined documents shared by ShinyHunters and found they included sensitive psychiatric and medical files of FBI staff. The FBI issued <a href="https://www.fbi.gov/news/press-releases/fbi-statement-on-compromise-of-fbijobsgov-portal-and-alleged-impact-to-fbi-employee-pii?utm_campaign=email-Immediate&amp;utm_medium=email&amp;utm_source=national-press-releases&amp;utm_content=%5B2249041%5D-%2Fnews%2Fpress-releases%2Ffbi-statement-on-compromise-of-fbijobsgov-portal-and-alleged-impact-to-fbi-employee-pii" target="_blank" rel="noopener">a brief statement</a> confirming the hack.</p>
<p>ShinyHunters said it gained access to the FBI site and other victims by exploiting a recently patched vulnerability (CVE-2026-35273) in <strong>PeopleSoft</strong>, a software-as-a-service platform from the software giant <strong>Oracle</strong> that is broadly used by companies to manage hiring and human resources, benefits and payroll. Oracle quickly issued a fix for the Peoplesoft vulnerability that ShinyHunters reportedly began exploiting as a zero-day in June, and at the time Mandiant released web application firewall rules intended for organizations who couldn&#8217;t apply the security update quickly enough.</p>
<p>But on Friday, BleepingComputer reported that ShinyHunters <a href="https://www.bleepingcomputer.com/news/security/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks/" target="_blank" rel="noopener">used a URL-encoding trick</a> to bypass Mandiant&#8217;s suggested web application firewall rules designed to mitigate the threat from the PeopleSoft flaw. In <a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft" target="_blank" rel="noopener">a report</a> released Sept. 25, security experts at <strong>Mandiant</strong> and the <strong>Google Threat Intelligence Group</strong> (GTIG) confirmed that ShinyHunters had mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across a range of industries, including higher education, technology, healthcare, agriculture, transportation and government.</p>
<p>Van der Stap&#8217;s former hacker alias Umbreon was hidden in plain sight throughout the imagery ShinyHunters used to spread news about the FBI hack: The defacement image that ShinyHunters left behind on the hacked FBI jobs site included an ASCII art design featuring the Pokemon character Umbreon. The message at the top read, &#8220;This site has been seized by ShinyHunters. rooting your systems since &#8217;19 ;)&#8221; The image appears identical to a defacement message ShinyHunters used in their <a href="https://reliaquest.com/blog/the-eeveelution-of-shinyhunters-from-data-leaks-to-extortions/" target="_blank" rel="noopener">2020 hack</a> of the English-language cybercrime community Hackforums.</p>
<div id="attachment_74359" style="width: 757px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74359" class=" wp-image-74359" src="https://krebsonsecurity.com/wp-content/uploads/2026/09/fbi-umbreon-sh.png" alt="" width="747" height="744" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/09/fbi-umbreon-sh.png 1316w, https://krebsonsecurity.com/wp-content/uploads/2026/09/fbi-umbreon-sh-768x766.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/09/fbi-umbreon-sh-782x780.png 782w" sizes="(max-width: 747px) 100vw, 747px" /><p id="caption-attachment-74359" class="wp-caption-text">The defacement message left by ShinyHunters on the FBI jobs site included an ASCII art rendition of the Pokemon character Umbreon. Image: Bleeping Computer.</p></div>
<p>Multiple sources close to the ShinyHunters investigation said the group&#8217;s recent risky attacks against the FBI and one of Russia&#8217;s most venerated ransomware groups amounted to a major pivot away from the more measured tenor of the hacking gang&#8217;s operations. Those sources said the sudden shift came about after ShinyHunters was taken over by <a href="https://krebsonsecurity.com/2025/11/meet-rey-the-admin-of-scattered-lapsus-hunters/" target="_blank" rel="noopener">a teenage cybercriminal from Amman, Jordan</a> who goes by the nickname <strong>Rey</strong> and operates as part of a cybercrime group called <strong>ScatteredLapsussHunters </strong>(SLSH), which experts say is an amalgamation of three hacking groups — <a href="https://krebsonsecurity.com/?s=scattered+spider" target="_blank" rel="noopener"><strong>Scattered Spider</strong></a>, <a href="https://krebsonsecurity.com/?s=lapsus%24" target="_blank" rel="noopener"><strong>LAPSUS$</strong></a> and <a href="https://krebsonsecurity.com/?s=shiny+hunters" target="_blank" rel="noopener"><strong>ShinyHunters</strong></a>.</p>
<p>Those sources said Rey had an ongoing beef with the Dutch hacker over control of the ShinyHunters brand and data, and that the inclusion of the oversized Umbreon Pokemon image in the FBI jobs site defacement was likely an attempt by Rey to pin the hack on the Dutchman.</p>
<p>Rey was <a href="https://www.kelacyber.com/blog/hellcat-hacking-group-unmasked-rey-and-pryx/" target="_blank" rel="noopener">first publicly identified</a> by the cybersecurity firm <strong>KELA</strong> in March 2025. In advance of our <a href="https://krebsonsecurity.com/2025/11/meet-rey-the-admin-of-scattered-lapsus-hunters/" target="_blank" rel="noopener">November 2025 profile of Rey</a>, KrebsOnSecurity messaged Rey&#8217;s father and asked for permission to interview his teenage son. Rey&#8217;s dad merely forwarded the message to his son, who admitted to participating in ransomware attacks and said he was trying to extricate himself from the SLSH hacker group.</p>
<h2>BLAMING UMBREON</h2>
<p>Immediately after news of the FBI jobs site hack was picked up in the media, Rey&#8217;s main account on Twitter/X (Ryan Moran/@rmoskovy) was taunting the Cl0p ransomware group and the FBI, crudely depicting them as the twin towers in New York being struck by planes labeled &#8220;cl0p drama&#8221; and &#8220;fbi breach claim.&#8221; In the foreground of the city is the giant Pokemon figure of Umbreon.</p>
<div id="attachment_74362" style="width: 637px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74362" class="size-full wp-image-74362" src="https://krebsonsecurity.com/wp-content/uploads/2026/09/rey-cl0p-fbi.png" alt="" width="627" height="843" /><p id="caption-attachment-74362" class="wp-caption-text">A taunting meme uploaded to Twitter/X by Rey&#8217;s now-defunct account on Sept. 22. A giant float-sized version of the Pokemon character Umbreon can be seen in the bottom left.</p></div>
<p>On Sept. 24, KrebsOnSecurity again contacted Rey&#8217;s dad, asking to interview him and his son for a story on Rey&#8217;s apparent ascendency as the head of ShinyHunters. Just hours after that request, Rey deleted his longtime Twitter/X account. Meanwhile, Rey&#8217;s dad, who works for the Royal Jordanian Airlines, has failed to respond to a half-dozen emailed requests for comment about his son&#8217;s alleged activities.</p>
<p>Where does the bad blood between SLSH and ShinyHunters come from? According to <a href="https://www.wired.com/story/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang/" target="_blank" rel="noopener">a story in Wired</a> this month, ShinyHunters and SLSH members briefly partnered earlier this year to help better monetize important stolen credentials collected by <strong>TeamPCP</strong>, an upstart group that was having great success compromising global code supply chains with malicious software but hadn&#8217;t been able to profit much from their stolen data (two alleged leaders of TeamPCP <a href="https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/" target="_blank" rel="noopener">were arrested last month in Australia</a>, and in an interview the TeamPCP leader claimed they made just $20,000).</p>
<p>The Wired story noted how Mandiant had infiltrated TeamPCP and was secretly responsible for having the crime group&#8217;s stolen credentials burned so quickly: Mandiant was secretly feeding those credentials to the major cloud providers like Amazon and Microsoft, who quickly invalidated the stolen keys. Meanwhile, the formerly cooperating hacker groups began to blame one another for causing the credentials to become worthless.</p>
<p>Wired&#8217;s <strong>Andy Greenberg</strong> reported that a few weeks after partnering with TeamPCP, &#8220;ShinyHunters went rogue, carrying out its own extortions with TeamPCP&#8217;s credentials but without giving the supply-chain hackers their cut.&#8221;</p>
<p>Mandiant researcher <strong>Austin Larsen</strong> told KrebsOnSecurity earlier this month that ShinyHunters has been enjoying a successful extortion spree so far this year, and is on track to pull in nearly $100 million in extortion payments from cybercrime victims in 2026.</p>
<p>Van der Stap claims he was never motivated by money and that his earlier hacker activity was driven by a desire to have the world&#8217;s most complete collection of stolen databases. Speaking with reporters from Bloomberg in 2024, Van der Stap said that singular focus in turn fueled his desire to carry out cyberattacks.</p>
<p>“The hacking was very easy for me, and it wasn’t a compulsion,” he <a href="https://archive.ph/K47wB#selection-1447.0-1447.321" target="_blank" rel="noopener">told Bloomberg</a>. “My habit was collecting. Collecting data, organizing data, downloading data, creating folders.”</p>
<p>DIVD, the nonprofit security research group where Van der Stap previously served as a volunteer, <a href="https://www.linkedin.com/feed/update/urn:li:activity:7508986131779088384/" target="_blank" rel="noopener">disclosed on LinkedIn last week</a> that the organization was dealing with an internal cybersecurity incident that appears to have involved the malicious use of artificial intelligence. DIVD has released few details about that incident, but a spokesperson for the nonprofit told KrebsOnSecurity it does not appear related to ShinyHunters, nor are there any signs the matter involves the work of a previous volunteer.</p>
<p><strong>Update: 3:44 p.m. ET:</strong> Corrected Van der Stap&#8217;s age, which is 24 (not 23).</p>
<p><strong>Update, 4:54 p.m. ET:</strong> The Dutch police have confirmed the arrest of a 24-year-old in connection with the ShinyHunters investigation. In <a href="https://x.com/Pol_Ops_Int/status/2104607979559342174" target="_blank" rel="noopener">a statement on Twitter/X</a>, the Dutch police said the man will appear on Tuesday, September 29 before the chambers of the Rotterdam District Court, and that it will provide more information tomorrow.</p>
<p><strong>Sept. 29, 9:42 a.m. ET:</strong> The Dutch news outlet <strong>RTL</strong> <a href="https://www.rtl.nl/nieuws/binnenland/artikel/5656154/pepijn-van-der-s-verdacht-van-opdracht-geven-moorden" target="_blank" rel="noopener">reports</a> that investigators suspect Van der Stap tried to orchestrate at least two murders. RTL reported the two murders were allegedly to be committed abroad, and that there are indications the suspect gave the order for this.</p>
<p>The FBI released <a href="https://x.com/FBICyberDiv/status/2104923994801553646?s=46" rel="noopener" target="_blank">a short video message</a> on the ShinyHunters investigation from Brett Leatherman, assistant director of the FBI&#8217;s cyber division, who thanked Dutch law enforcement partners for their assistance and urged remaining ShinyHunters members to turn themselves in.</p>
<p>&#8220;Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who&#8217;s left,&#8221; Leatherman said. &#8220;The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out to us while the choice is still yours.&#8221;</p>
]]></content:encoded>
					
					<wfw:commentRss>https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/feed/</wfw:commentRss>
			<slash:comments>37</slash:comments>
		
		
			</item>
		<item>
		<title>U.S. Soldier Gets 70 Months in Prison for AT&#038;T, Verizon Extortions</title>
		<link>https://krebsonsecurity.com/2026/09/u-s-soldier-gets-70-months-in-prison-for-att-verizon-extortions/</link>
					<comments>https://krebsonsecurity.com/2026/09/u-s-soldier-gets-70-months-in-prison-for-att-verizon-extortions/#comments</comments>
		
		<dc:creator><![CDATA[BrianKrebs]]></dc:creator>
		<pubDate>Fri, 25 Sep 2026 21:44:40 +0000</pubDate>
				<category><![CDATA[DDoS-for-Hire]]></category>
		<category><![CDATA[Ne'er-Do-Well News]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[AT&T]]></category>
		<category><![CDATA[Bureau of Prisons]]></category>
		<category><![CDATA[Cameron John Wagenius]]></category>
		<category><![CDATA[Connor Riley Moucka]]></category>
		<category><![CDATA[CVE-2023-45208]]></category>
		<category><![CDATA[Defense Criminal Investigative Service]]></category>
		<category><![CDATA[Judische]]></category>
		<category><![CDATA[Kenneth Schuchman]]></category>
		<category><![CDATA[Kiberphant0m]]></category>
		<category><![CDATA[Paul Russell]]></category>
		<category><![CDATA[Verizon]]></category>
		<guid isPermaLink="false">https://krebsonsecurity.com/?p=74335</guid>

					<description><![CDATA[A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&#038;T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.]]></description>
										<content:encoded><![CDATA[<p>A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million <strong>AT&amp;T</strong> customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.</p>
<div id="attachment_69974" style="width: 757px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-69974" class=" wp-image-69974" src="https://krebsonsecurity.com/wp-content/uploads/2024/12/camwagenius-selfie.png" alt="" width="747" height="740" srcset="https://krebsonsecurity.com/wp-content/uploads/2024/12/camwagenius-selfie.png 779w, https://krebsonsecurity.com/wp-content/uploads/2024/12/camwagenius-selfie-768x761.png 768w" sizes="(max-width: 747px) 100vw, 747px" /><p id="caption-attachment-69974" class="wp-caption-text">One of several selfies from the Facebook page of Cameron Wagenius.</p></div>
<p><strong>Cameron John Wagenius</strong>, 22, was stationed at a U.S. Army base in South Korea when he adopted the cybercriminal persona &#8220;<strong>Kiberphant0m</strong>.&#8221; Working with three alleged co-conspirators, Kiberphant0m downloaded data from several large customers of the cloud data storage service <strong>Snowflake</strong> that had exposed credentials and did not enforce multi-factor authentication (Snowflake has since mandated MFA on all accounts).</p>
<p>In October 2024, Kiberphant0m bragged on the cybercrime forums that he&#8217;d stolen the call and text metadata (e.g. source and destination number, timestamp, duration, etc.) for tens of millions of AT&amp;T customers. Kiberphant0m claimed to have hacked into more than dozen telecommunications companies worldwide, including Verizon&#8217;s Push-to-Talk business, and publicly extorted these companies in exchange for a promise not to publish the stolen data.</p>
<p>In late November 2025, KrebsOnSecurity warned that Kiberphant0m <a href="https://krebsonsecurity.com/2024/11/hacker-in-snowflake-extortions-may-be-a-u-s-soldier/" target="_blank" rel="noopener">was likely a U.S. soldier stationed in South Korea</a>. Less than a month later, Wagenius was <a href="https://krebsonsecurity.com/2024/12/u-s-army-soldier-arrested-in-att-verizon-extortions/" target="_blank" rel="noopener">arrested</a> and charged in two separate federal indictments, and soon pleaded guilty to all counts in both cases.</p>
<p>At his sentencing hearing in Seattle today, Wagenius was sentenced to nearly six years in federal prison, and ordered to pay $294,978 in restitution.</p>
<p>Federal prosecutors said Wagenius was assisted in his efforts to extort victim companies by <strong>Kenneth Schuchman</strong>, a 28-year old man from Vancouver, Washington who has a lengthy cybercriminal history. In 2019, Schuchman <a href="https://krebsonsecurity.com/2019/09/satori-iot-botnet-operator-pleads-guilty/" target="_blank" rel="noopener">pleaded guilty to operating the <strong>Satori</strong> botnet</a>, a vast collection of hacked Internet-of-Things (IoT) devices that was used for large-scale distributed denial-of-service (DDoS) attacks.</p>
<p>Two other alleged co-conspirators of Wagenius are still facing charges in connection with the Snowflake data thefts; <strong>Conor Riley Moucka</strong>, a.k.a. &#8220;Judische,&#8221; of Kitchener, Ontario was arrested in 2024 and <a href="https://krebsonsecurity.com/2026/08/canadian-man-pleads-guilty-in-snowflake-extortions/" target="_blank" rel="noopener">pleaded guilty in August 2026</a>; and <strong>John Erin Binns</strong>, an American man currently living in Turkey who is also wanted for <a href="https://krebsonsecurity.com/2021/08/t-mobile-investigating-claims-of-massive-data-breach/" target="_blank" rel="noopener">a 2021 data breach at T-Mobile</a> that exposed the personal information of at least 76 million customers.</p>
<p>Kiberphant0m also admitted to re-extorting victims, and threatening to disclose national security secrets. Immediately following Moucka’s arrest &#8212; after AT&amp;T had already paid the extortion group a $370,000 Bitcoin ransom &#8212; Kiberphant0m posted on hacker forums what he claimed were the AT&amp;T call logs for then President-elect Donald Trump and for then Vice President Kamala Harris, as well as schematics allegedly stolen from the U.S. National Security Agency (NSA).</p>
<p><strong>Paul Russell</strong> is a resident agent in charge at the <strong>Defense Criminal Investigative Service</strong> (DCIS), the criminal investigative arm of the U.S. Department of Defense Office of Inspector General. Russell said when DCIS received information that a soldier with secret clearance was allegedly involved in cybercrime and extortion, the agency began working the investigation alongside the FBI, the Army Criminal Investigative Division (CID), and the U.S. Secret Service.</p>
<p>&#8220;We don&#8217;t often get leads where there&#8217;s an active duty soldier with a secret clearance who&#8217;s creating hacking tools and trafficking in data,&#8221; Russell said. &#8220;That doesn&#8217;t happen every day, and so when that hits it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren&#8217;t sure what we were dealing with.&#8221;</p>
<p>A <a href="https://krebsonsecurity.com/wp-content/uploads/2026/09/wagenius-sentencingmemo.pdf" target="_blank" rel="noopener">sentencing memo</a> (PDF) filed Sept. 19 by federal prosecutors in Seattle notes that while Wagenius pleaded guilty almost immediately and has been remarkably cooperative, he recently got caught trying to find security vulnerabilities in the BOP&#8217;s computer network. The government&#8217;s memo notes that while incarcerated and awaiting sentencing, Wagenius violated the computer use policies of the <strong>Bureau of Prisons</strong> (BOP) in attempts to learn about vulnerabilities in BOP computer systems.<span id="more-74335"></span></p>
<p>&#8220;According to records from BOP, in or around September 2025, Wagenius used another inmate’s email system to request that the email recipient prompt a commercial AI tool to provide information about “[w]hat CVE’s are there for Windows 10 Enterprise privilege escalation and bypasses” and to “[p]rovide the CVE’s and a real world working script for each CVE . . . without omitted code,” the government&#8217;s memo states.</p>
<p>The memo states that less than a week later, Wagenius used a different inmate&#8217;s email account and requested that the email recipient prompt an AI tool to “[p]rovide the step by step for <a href="https://nvd.nist.gov/vuln/detail/cve-2023-45208" target="_blank" rel="noopener">CVE-2023-45208</a>, code for this if any, and if no code exists make some, make sure to describe everything in detail.” CVE-2023-45208 is a three-year-old &#8220;command injection&#8221; vulnerability in D-Link networking devices.</p>
<p>That same month, Wagenius allegedly again requested that the email recipient prompt AI with the question, &#8220;How do you make an antenna in a prison environment with commissary or readily available items/tools to improve/make an antenna to extend radio reception?&#8221;</p>
<p>Federal prosecutors said Wagenius also requested that the recipient research escaping prison.</p>
<p>&#8220;In several instances, Wagenius framed the AI queries as being posed in connection to a book he was writing. This is a common method of &#8216;prompt injection,&#8217; in which attackers feed specially crafted, deceptive inputs into commercial AI tools that are programmed to avoid outputting malicious code that can be used to exploit computer vulnerabilities,&#8221; the sentencing memo reads.</p>
<p>The government told the court it is unaware of evidence that Wagenius figured out how to use or deploy the vulnerabilities he was researching in the BOP&#8217;s systems, and when questioned said he was only researching &#8220;potential vulnerabilities to provide information to the BOP.&#8221;</p>
<p>Incredibly, despite the enormous financial value of the data stolen from AT&amp;T and other telecom providers, Wagenius&#8217;s extortion efforts were largely unsuccessful. The government&#8217;s sentencing memo says Wagenius made a whopping total of around $1,500 from selling stolen data.</p>
<p>&#8220;While Wagenius was not particularly financially successful as a cybercriminal, he both intended to and caused significant harm to numerous individual victims, U.S. companies, and the U.S. government,&#8221; the memo states.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://krebsonsecurity.com/2026/09/u-s-soldier-gets-70-months-in-prison-for-att-verizon-extortions/feed/</wfw:commentRss>
			<slash:comments>14</slash:comments>
		
		
			</item>
		<item>
		<title>Data Broker Radaris Loses Domains in Privacy Fight</title>
		<link>https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/</link>
					<comments>https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/#comments</comments>
		
		<dc:creator><![CDATA[BrianKrebs]]></dc:creator>
		<pubDate>Wed, 16 Sep 2026 18:14:22 +0000</pubDate>
				<category><![CDATA[A Little Sunshine]]></category>
		<category><![CDATA[Ne'er-Do-Well News]]></category>
		<category><![CDATA[Andtop Company]]></category>
		<category><![CDATA[Atlas Data Privacy]]></category>
		<category><![CDATA[Bitseller Expert Limited]]></category>
		<category><![CDATA[Dmitry Lubarsky]]></category>
		<category><![CDATA[Gary Norden]]></category>
		<category><![CDATA[Igor Lubarsky]]></category>
		<category><![CDATA[Justin Sherman]]></category>
		<category><![CDATA[Lifetime Value Company]]></category>
		<category><![CDATA[Matt Adkisson]]></category>
		<category><![CDATA[NumberGuru]]></category>
		<category><![CDATA[OneRep]]></category>
		<category><![CDATA[PEM Law]]></category>
		<category><![CDATA[PeopleLooker]]></category>
		<category><![CDATA[PeopleSmart]]></category>
		<category><![CDATA[Radaris]]></category>
		<category><![CDATA[Radaris.com]]></category>
		<category><![CDATA[Raj Parikh]]></category>
		<category><![CDATA[Val Gurvits]]></category>
		<category><![CDATA[Victor Worms]]></category>
		<guid isPermaLink="false">https://krebsonsecurity.com/?p=74300</guid>

					<description><![CDATA[The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides for hefty fines against data brokers that publish personal information on state law enforcement officials. In the face of repeated stonewalling and prevarication by attorneys for Radaris, the judge in the case ordered that radaris.com and more than a dozen other data broker domains be transferred to the plaintiffs.]]></description>
										<content:encoded><![CDATA[<p>The consumer data broker <strong>Radaris.com</strong> has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides for hefty fines against data brokers that publish personal information on state law enforcement officials. In the face of repeated stonewalling and prevarication by attorneys for Radaris, the judge in the case ordered that radaris.com and more than a dozen other data broker domains be transferred to the plaintiffs.</p>
<div id="attachment_67916" style="width: 759px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-67916" class="wp-image-67916" src="https://krebsonsecurity.com/wp-content/uploads/2024/06/radaris-home.png" alt="" width="749" height="335" srcset="https://krebsonsecurity.com/wp-content/uploads/2024/06/radaris-home.png 1841w, https://krebsonsecurity.com/wp-content/uploads/2024/06/radaris-home-768x343.png 768w, https://krebsonsecurity.com/wp-content/uploads/2024/06/radaris-home-1536x687.png 1536w, https://krebsonsecurity.com/wp-content/uploads/2024/06/radaris-home-782x350.png 782w" sizes="(max-width: 749px) 100vw, 749px" /><p id="caption-attachment-67916" class="wp-caption-text">The radaris.com website, prior to the domain transfer to Atlas.</p></div>
<p>In February 2024, Radaris was sued by <strong>Atlas Data Privacy Corp</strong>, a company that has been pursuing data brokers alleged to be violating a New Jersey statute called <a href="https://www.nj.com/news/2026/08/daniels-law-was-born-from-judges-family-tragedy-now-the-privacy-law-faces-its-biggest-test.html" target="_blank" rel="noopener">Daniel&#8217;s Law</a>. The statute allows state law enforcement officials, government personnel, judges and their families to have their information completely removed from commercial data brokers and people-search services, and provides for fines of $1,000 per violation against companies that ignore removal requests.</p>
<p>Less than a month after Atlas sued Radaris, KrebsOnSecurity published <a href="https://krebsonsecurity.com/2024/03/a-close-up-look-at-the-consumer-data-broker-radaris/" target="_blank" rel="noopener">a deep dive into the Radaris co-founders</a> &#8212; <strong>Igor</strong> and <strong>Dmitry Lubarsky</strong> (also spelled Lybarsky) &#8212; Russian-born brothers living in Massachusetts who operate a dizzying array of people-search companies as well as a number of Russian language dating services and affiliate programs.</p>
<p>Attorneys for the Lubarsky brothers threatened to sue for defamation if the story wasn&#8217;t removed and an apology issued. Their attorney asserted that our reporting was wildly inaccurate, and that the true owners of the company were Ukrainians living in Ukraine.</p>
<div id="attachment_66640" style="width: 740px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-66640" class=" wp-image-66640" src="https://krebsonsecurity.com/wp-content/uploads/2024/03/lybarskybros.png" alt="" width="730" height="647" /><p id="caption-attachment-66640" class="wp-caption-text">The Lubarsky brothers Dmitry or &#8220;Dan&#8221; (left) and Gary/Igor.</p></div>
<p>KrebsOnSecurity doubled down and showed how the Lubarsky brothers built and operated Radaris and other data broker companies <a href="https://krebsonsecurity.com/2024/06/krebsonsecurity-threatened-with-defamation-lawsuit-over-fake-radaris-ceo/" target="_blank" rel="noopener">using a fictitious CEO&#8217;s name</a>. Our follow-up story noted that Radaris&#8217;s attorney &#8212; a lawyer with the Boston Law Group named <strong>Val Gurvits</strong> &#8212; admitted his clients had invented the CEO pseudonym &#8220;<strong>Gary Norden</strong>,&#8221; and that Radaris also had issued multiple press releases over the years that quoted the fake CEO while seeking money from potential investors.</p>
<p>Attorneys for Radaris waited until the last minute to appear in court and contest what was all but certain to be a default judgment in favor of the plaintiffs, and then told the court that Atlas had failed to serve the real owners and operators of Radaris and several of its sister data broker companies.</p>
<p>Atlas re-filed the lawsuit in June 2025, this time dramatically expanding the number of Radaris family data brokers accused of violating Daniel&#8217;s Law. <strong>Matt Adkisson</strong>, president and CEO of Atlas, said Radaris turned to a tried-and-true playbook: Delaying in court until the last possible minute, and playing shell games with Radaris&#8217;s true country of origin and the individuals listed as owners and operators of these sites.</p>
<p>&#8220;We refer to this period as their island-hopping phase. Privacy policies changed constantly, and new entities kept appearing from places like the Marshall Islands, the British Virgin Islands, and Seychelles,&#8221; Adkisson told KrebsOnSecurity. &#8220;Behind the scenes, it felt like a shell game. Defense lawyers told the court that certain entities merely operated the domains and were the proper parties to sue. But by the time a judgment neared, those entities would be discarded and new entities would appear. Meanwhile, the lawyers claimed the other entities that actually owned the domains should not be held responsible.&#8221;</p>
<p>Adkisson said when the defendants updated their terms of service to state that Radaris was suddenly managed by a company in the Marshall Islands, Atlas hired an investigator in that country and soon learned the brand new entity that Radaris claimed was managing the company didn&#8217;t even exist yet.</p>
<p>Mr. Gurvits stepped forward as Radaris’s attorney in <a href="https://www.courtlistener.com/docket/5969712/huebner-v-radaris-llc/" target="_blank" rel="noopener">a class action lawsuit the company temporarily lost in 2017</a> because it never contested the claim in court. When the plaintiffs told the judge they couldn’t collect on the $7.5 million default judgment, the court ordered the domain registry Verisign to transfer the radaris.com domain name to the plaintiffs.</p>
<p>Mr. Gurvits appealed that verdict, arguing the lawsuit hadn’t named the actual owners of the Radaris domain name — a Cyprus company called <strong>Bitseller Expert Limited</strong> — and thus taking the domain away would be a violation of their due process rights.</p>
<p>The judge in the 2017 case ruled in Radaris’ favor — halting the domain transfer — and told the plaintiffs they could refile their complaint. Soon after, the operator of Radaris changed from Bitseller to <strong>Andtop Company</strong>, an entity <a href="https://krebsonsecurity.com/wp-content/uploads/2024/06/Andtop.pdf" target="_blank" rel="noopener">formed</a> (PDF) in the <a href="https://en.wikipedia.org/wiki/Marshall_Islands" target="_blank" rel="noopener">Marshall Islands</a> in Oct. 2020. The plaintiffs never re-filed their lawsuit.</p>
<div id="attachment_66716" style="width: 759px" class="wp-caption aligncenter"><a href="https://krebsonsecurity.com/wp-content/uploads/2024/03/radaris-mm.png" target="_blank" rel="noopener"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-66716" class="wp-image-66716" src="https://krebsonsecurity.com/wp-content/uploads/2024/03/radaris-mm.png" alt="" width="749" height="331" srcset="https://krebsonsecurity.com/wp-content/uploads/2024/03/radaris-mm.png 1714w, https://krebsonsecurity.com/wp-content/uploads/2024/03/radaris-mm-768x340.png 768w, https://krebsonsecurity.com/wp-content/uploads/2024/03/radaris-mm-1536x679.png 1536w, https://krebsonsecurity.com/wp-content/uploads/2024/03/radaris-mm-782x346.png 782w" sizes="(max-width: 749px) 100vw, 749px" /></a><p id="caption-attachment-66716" class="wp-caption-text">A mind map of various entities tied to Radaris and the company&#8217;s co-founders. Click to enlarge.</p></div>
<p>&#8220;That seemed to be their modus operandi,&#8221; said <strong>Raj Parikh</strong>, a partner at <strong>PEM Law</strong> in New Jersey who handles most of the Daniel&#8217;s Law litigation for Atlas. &#8220;In the past, they won by attrition. Plaintiffs&#8217; attorneys tired of the procedural games and just gave up. That strategy worked for a decade, and it probably would have worked in this case too, since any financial recovery from foreign actors will be difficult. But we were acutely aware of the threat this website posed to law enforcement officers and other public officials in New Jersey, and decided early on to commit whatever time and resources were necessary to remove that threat.&#8221;</p>
<p>On August 26, the judge in the New Jersey case found the defendants were given multiple chances to appear and defend the claims against them but had failed to do so. Mr. Gurvits declined to comment on the case, saying it had been assigned to another attorney, a <strong>Mr. Victor Worms</strong>. In response to questions, Mr. Worms asserted the New Jersey court transferred Radaris.com to Atlas as part of a default judgment against Radaris.com, which is not a legal entity.</p>
<p>&#8220;We have made a motion to vacate that default judgment on the grounds that it is void since a non-entity has no legal capacity to sue or be sued,&#8221; Worms replied. &#8220;We also intend to pursue all appropriate appeals because we believe the transfer of Radaris.com amounts to a forfeiture in violation of various constitutional principles.&#8221;</p>
<p>While radaris.com still comes up prominently in results when searching online for U.S. residents by name, the domain no longer sells detailed personal dossiers on millions of Americans. Its homepage now displays a notice from Atlas, as well as links to our previous reporting on Radaris.<span id="more-74300"></span></p>
<h2>EMAIL CONFIRMATIONS</h2>
<p>Atlas told KrebsOnSecurity that it has obtained more than 10,000 emails and documents in the course of litigation, and that those messages confirm our previous reporting on the owners and operators of Radaris and its myriad companies.</p>
<p>Atlas said the emails clearly establish that the nominal legal vehicles — <strong>Radaris America, Inc.</strong>; <strong>Bitseller Expert Limited</strong>; <strong>Digital Orbit Corp</strong>; <strong>Core Solutions Group Inc</strong>; <strong>Lucky Solutions Inc</strong>; <strong>Virtura Corp</strong>; <strong>Veripages Inc.</strong>; <strong>Nuform Solutions Inc.</strong>; <strong>Growth Data Advisors Inc.</strong>; <strong>Property Experts, Inc</strong> — are all administered by the same three or four people from the same mailboxes, share one bank or payment card set, and are all managed from one virtual office address.</p>
<p>&#8220;The corpus establishes, with documentary evidence generated independently by banks, payment processors, hosting providers, registrars, software-as-a-service vendors and the operators’ own systems, that radaris.com and at least twenty-five other people-search websites are one operation run by a small Boston-area group whose administrative, financial and technical functions sit on the difive.com mail domain and its successors (centerex.com, scienteco.com, eprofit.com, realmo.com, pub360.com),&#8221; reads a summary shared by Atlas.</p>
<p>Atlas said the emails show Radaris.com earns approximately $42,000 a month, while Veripages.com earns around $45,000 monthly via its partnership with the <strong>Lifetime Value Company</strong>, a marketing and advertising firm whose brands include <strong>PeopleLooker</strong>, <strong>PeopleSmart</strong>, <strong>NumberGuru</strong>, and <strong>Bumper</strong>, a car history site.</p>
<p>According to Atlas, the emails also showed the Radaris family of websites earns as much as $25,000 each month from their partnership with <strong>Onerep</strong>, a company that claims to help people remove their information from people-search sites. In March 2024, KrebsOnSecurity revealed how the Belarusian founder of Onerep had <a href="https://krebsonsecurity.com/2024/03/ceo-of-data-privacy-company-onerep-com-founded-dozens-of-people-search-firms/" target="_blank" rel="noopener">launched and operated dozens of people-search sites</a> over the years and was continuing to operate one of them (Nuwber), effectively spreading the disease and selling the cure.</p>
<div id="attachment_74324" style="width: 752px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74324" class="wp-image-74324" src="https://krebsonsecurity.com/wp-content/uploads/2026/09/atlas-radaris.png" alt="The domain radaris.com now redirects to this notice from Atlas about the court-ordered domain transfer." width="742" height="724" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/09/atlas-radaris.png 894w, https://krebsonsecurity.com/wp-content/uploads/2026/09/atlas-radaris-768x749.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/09/atlas-radaris-782x763.png 782w" sizes="(max-width: 742px) 100vw, 742px" /><p id="caption-attachment-74324" class="wp-caption-text">The domain radaris.com now redirects to this notice from Atlas about the court-ordered domain transfer.</p></div>
<p>All told, the New Jersey court has so far transferred 14 domain names from the Radaris family of companies to Atlas. Radaris.com now redirects to a notice of the court-ordered domain transfer.</p>
<h2>THE ROAD AHEAD</h2>
<p>The Radaris family of companies is still potentially facing fines of $1,000 per alleged violation of Daniel&#8217;s Law. For the time being, however, Daniel&#8217;s Law is facing a constitutional challenge from virtually all of the 150 other consumer data broker firms being sued by Atlas.</p>
<p>The data broker industry responded by having at least 70 of the Atlas lawsuits moved to federal court, challenging the New Jersey statute as overly broad and a violation of the First Amendment. The U.S. Court of Appeals for the Third Circuit has not yet issued a decision on the constitutional challenge, but either way the case is widely expected to be appealed all the way to the U.S. Supreme Court.</p>
<p>Meanwhile, at least 14 other states have now passed laws modeled after the New Jersey statute, with more states considering similar measures. However, West Virginia&#8217;s Daniel’s Law was <a href="https://www.troutman.com/insights/west-virginias-daniels-law-held-facially-unconstitutional/" target="_blank" rel="noopener">ruled facially unconstitutional</a> under the First Amendment by a federal district court in August 2025.</p>
<p><strong>Justin Sherman</strong> is a privacy expert and author of the forthcoming book &#8220;The Middlemen,&#8221; which examines how the data broker industry powers modern surveillance. Sherman said federal lawmakers have long faced intense lobbying by the technology industry against more restrictive U.S. data privacy laws, but that many powerful industries are now working against passing comprehensive data privacy legislation.</p>
<p>&#8220;These days at the federal level, add in the intense amount of lobbying against these laws from social media companies, big tech, cryptocurrency firms, and now AI proponents in the mix who claim that limiting their data scraping is somehow going to collapse the whole U.S. economy under Chinese rule,&#8221; he said.</p>
<p>Sherman said people-search companies will continue to thrive unless and until Congress enacts meaningful consumer privacy and data protection laws that are relevant to life in the 21st century. That&#8217;s because virtually all state privacy laws exempt records that might be considered “public” or “government” documents, including voting registries, property filings, marriage certificates, motor vehicle records, criminal records, court documents, death records, professional licenses, bankruptcy filings, and more.</p>
<p>At least 25 states have passed or implemented laws requiring age verification for residents seeking to access adult content online, but there is no federal law that limits how the companies that are scanning everyone&#8217;s drivers license can use, share or keep the data provided. Had such restrictions been enshrined in law, we may have avoided <a href="https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/" target="_blank" rel="noopener">the recent breach at IDScan.net</a>, which exposed the drivers license information on more than 153 million Americans when the records were briefly turned into a point-and-click identity theft service on the dark web.</p>
<p>&#8220;The average person can look at Daniel&#8217;s Law and have a perfectly normal reaction, which is that everyone should be covered, not just police and judges,&#8221; Sherman said. &#8220;But we don&#8217;t need more wake-up calls. We&#8217;ve had eight million wake-up calls already on the need for better privacy laws. The lack of comprehensive federal privacy law is not for a lack of knowledge, and anyone claiming otherwise is either not reading the news or kidding themselves.&#8221;</p>
]]></content:encoded>
					
					<wfw:commentRss>https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/feed/</wfw:commentRss>
			<slash:comments>30</slash:comments>
		
		
			</item>
		<item>
		<title>Microsoft Plugs Nearly 1,000 Security Holes</title>
		<link>https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/</link>
					<comments>https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/#comments</comments>
		
		<dc:creator><![CDATA[BrianKrebs]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 21:44:22 +0000</pubDate>
				<category><![CDATA[Latest Warnings]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Time to Patch]]></category>
		<category><![CDATA[CVE-2026-69730]]></category>
		<category><![CDATA[CVE-2026-69829]]></category>
		<category><![CDATA[CVE-2026-81963]]></category>
		<category><![CDATA[CVE-2026-85880]]></category>
		<category><![CDATA[Fortra]]></category>
		<category><![CDATA[Microsoft Patch Tuesday September 2026]]></category>
		<category><![CDATA[Satnam Narang]]></category>
		<category><![CDATA[Tenable]]></category>
		<category><![CDATA[Tyler Reguly]]></category>
		<guid isPermaLink="false">https://krebsonsecurity.com/?p=74277</guid>

					<description><![CDATA[Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.]]></description>
										<content:encoded><![CDATA[<p><strong>Microsoft Corp.</strong> today issued updates to plug at least 974 security holes in its <strong>Windows</strong> operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.</p>
<div id="attachment_74285" style="width: 760px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74285" class=" wp-image-74285" src="https://krebsonsecurity.com/wp-content/uploads/2026/09/shutterstock_278764853.jpg" alt="" width="750" height="498" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/09/shutterstock_278764853.jpg 1000w, https://krebsonsecurity.com/wp-content/uploads/2026/09/shutterstock_278764853-768x510.jpg 768w, https://krebsonsecurity.com/wp-content/uploads/2026/09/shutterstock_278764853-782x519.jpg 782w" sizes="(max-width: 750px) 100vw, 750px" /><p id="caption-attachment-74285" class="wp-caption-text">Image: Shutterstock.com, Kirill Makarov.</p></div>
<p>This month&#8217;s patch bundle obliterates the software giant&#8217;s <a href="https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/" target="_blank" rel="noopener">previous record set in July</a>, when it released updates for at least 570 security vulnerabilities. September&#8217;s Patch Tuesday brings this year&#8217;s total to more than 2,600, more than twice Microsoft&#8217;s previous record-setting patch year in 2020 (1,245) and with three more months to go.</p>
<p>There are two &#8220;zero-day&#8221; flaws fixed this month that are being actively exploited: both <a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81963" target="_blank" rel="noopener">CVE-2026-81963</a> and <a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-85880" target="_blank" rel="noopener">CVE-2026-85880</a> allow an attacker to elevate their privileges on Windows system.</p>
<p>Fully 113 of the bugs addressed today earned Microsoft&#8217;s &#8220;critical&#8221; rating, meaning they could be abused by malware or miscreants to seize control over a vulnerable Windows machine with little or no help from the user.<span id="more-74277"></span></p>
<p>Among the more serious critical flaws this month is <a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69730" target="_blank" rel="noopener">CVE-2026-69730</a>, a DNS weakness present in Windows Server 2012 onward and on Windows 10. Microsoft warns that an unauthenticated attacker could leverage this weakness simply by sending a specially crafted packet to an affected system, and that it is likely to be exploited.</p>
<p>Also scary is <a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69829" target="_blank" rel="noopener">CVE-2026-69829</a>, a critical, remote code execution flaw in the Windows Shell. This vulnerability has a CVSS base score of 9.8 (10 is the most severe), and can be exploited with low attack complexity, no privileges, and no user interaction.</p>
<div id="attachment_74289" style="width: 760px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74289" class=" wp-image-74289" src="https://krebsonsecurity.com/wp-content/uploads/2026/09/msrc-sug-sept2026.png" alt="" width="750" height="539" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/09/msrc-sug-sept2026.png 906w, https://krebsonsecurity.com/wp-content/uploads/2026/09/msrc-sug-sept2026-768x552.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/09/msrc-sug-sept2026-782x562.png 782w" sizes="(max-width: 750px) 100vw, 750px" /><p id="caption-attachment-74289" class="wp-caption-text">Microsoft&#8217;s summary of the security updates released today. Image: msrc.microsoft.com.</p></div>
<p>Microsoft is hardly alone in shipping monster patch bundles lately. Many other large software companies, including Adobe, Cisco, Google, Mozilla and Oracle, all have recently credited AI-assisted research with increasing their patch cadence and volume (Google said today it is now going to ship security updates every two weeks).</p>
<p><strong>Tyler Reguly</strong>, associate director of security research and development at <strong>Fortra</strong>, said one core challenge with deploying Windows updates is that they need to be tested before being installed across an organization because not all third-party software works seamlessly in the face of changes to the underlying operating system.</p>
<p>&#8220;It’s time to put our CISOs and CSOs on notice,&#8221; Reguly said. &#8220;How are you helping your teams through these difficult times? Do you have your teams deploy after hours and on weekends to avoid disruption to the business environment? Do you reward them for that effort? Time to dig into your budget and buy dinner for your teams that are working on Saturday to get patches rolled out before users return to work on Monday.&#8221;</p>
<p><strong>Satnam Narang</strong> is senior staff research engineer at <strong>Tenable</strong>. Narang said it&#8217;s important to recognize that while the number of vulnerabilities being patched by Microsoft is rising, the number of flaws that can and will affect most organizations remains quite low.</p>
<p>&#8220;AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn’t finding more needles,&#8221; he said. &#8220;It’s critical that organizations understand which vulnerabilities actually apply to them, whether they pose a threat by being reachable and exploitable, and prioritize remediation based on this risk context.&#8221;</p>
<p>Of course, regular Windows users don&#8217;t need to test patches before deploying them, but they still need to open Windows Update periodically or else assent to the program&#8217;s nag notices about pending updates. And at the rate these Windows patch releases are ballooning in size, it&#8217;s probably best not to let them pile up month after month.</p>
<p>Enterprise Windows admins will want to keep an eye on <a href="https://www.askwoody.com/2026/september-2026-windows-updates-are-released/" target="_blank" rel="noopener">askwoody.com</a> for news of any updates that appear to be causing problems. As always, the <strong>SANS Internet Storm Center</strong> has <a href="https://isc.sans.edu/diary/September%202026%20Microsoft%20Patch%20Tuesday/33320" target="_blank" rel="noopener">a per-patch breakdown</a> ordered by severity and urgency.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/feed/</wfw:commentRss>
			<slash:comments>51</slash:comments>
		
		
			</item>
		<item>
		<title>FBI Probes Service Selling 153M+ Drivers Licenses</title>
		<link>https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/</link>
					<comments>https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/#comments</comments>
		
		<dc:creator><![CDATA[BrianKrebs]]></dc:creator>
		<pubDate>Tue, 01 Sep 2026 22:40:28 +0000</pubDate>
				<category><![CDATA[A Little Sunshine]]></category>
		<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[The Coming Storm]]></category>
		<category><![CDATA[Web Fraud 2.0]]></category>
		<category><![CDATA[Cybera]]></category>
		<category><![CDATA[DecryptAds]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Hertz]]></category>
		<category><![CDATA[idscan.net]]></category>
		<category><![CDATA[Jillian Kossman]]></category>
		<category><![CDATA[Larry Baldwin]]></category>
		<category><![CDATA[Nexus]]></category>
		<category><![CDATA[Planet13]]></category>
		<category><![CDATA[Zach Edwards]]></category>
		<guid isPermaLink="false">https://krebsonsecurity.com/?p=74231</guid>

					<description><![CDATA[A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images.]]></description>
										<content:encoded><![CDATA[<p>A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the <strong>Federal Bureau of Investigation</strong> (FBI) today launched an official inquiry into the source of the images.</p>
<div id="attachment_74234" style="width: 760px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74234" class=" wp-image-74234" src="https://krebsonsecurity.com/wp-content/uploads/2026/09/nexus-phegseth.png" alt="" width="750" height="434" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/09/nexus-phegseth.png 1049w, https://krebsonsecurity.com/wp-content/uploads/2026/09/nexus-phegseth-768x444.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/09/nexus-phegseth-782x452.png 782w" sizes="(max-width: 750px) 100vw, 750px" /><p id="caption-attachment-74234" class="wp-caption-text">A record available at this identity theft service that includes the drivers license for U.S. Defense Secretary Pete Hegseth, one of several high-ranking U.S. government officials whose drivers licenses can be found for sale.</p></div>
<p>On Monday, Aug. 31, a source alerted KrebsOnSecurity to a service advertised by a new user on the Russian cybercrime forum <strong>Exploit</strong>, offering access to digital scans of identity documents on more than 170 million people in North America. The source brought it to my attention because the proprietor of this identity theft service offered my Virginia drivers license as a free sample in their initial sales thread on Exploit.</p>
<p>The service, dubbed <strong>Nexus</strong>, claims to have more than 153 million drivers licenses for people in the United States and Canada, as well as more than 10 million identification cards; more than three million travel documents and/or international IDs; and at least 579,000 medical cards.</p>
<p>A quick look around Nexus finds they are likely not exaggerating about that 153 million number: Running a blank search in Nexus (with no search parameters entered) returns approximately 11.5 million pages of results, with roughly 15 results displayed per page. It includes documents from people in both Canada and the United States, but the bulk of these records are on Americans: searching for just Canadian drivers licenses returns approximately 1.1 million results, with the largest concentration from Ontario (473,673 records).</p>
<p>Curiously, the identity records include not only drivers licenses but also marijuana dispensary cards. Some of the records list their &#8220;source&#8221; as &#8220;CDL,&#8221; presumably short for &#8220;commercial drivers license.&#8221; Other records carry the source notation of &#8220;CAC,&#8221; which may refer to Common Access Cards, government issued identity cards that grant physical access to government buildings and secure rooms.</p>
<p>The people behind Nexus claim the license images are coming from an active breach at &#8220;a major identity verification company&#8221; whose customers include multiple Fortune 500 companies.</p>
<div id="attachment_74241" style="width: 564px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74241" class="size-full wp-image-74241" src="https://krebsonsecurity.com/wp-content/uploads/2026/09/nexus-totals.png" alt="" width="554" height="491" /><p id="caption-attachment-74241" class="wp-caption-text">The record totals listed by the Nexus identity theft service. The number of drivers license records increased by nearly 400,000 in the span of just 24 hours.</p></div>
<p>&#8220;We have been continuously exfiltrating new data for over a year into our private database,&#8221; the service enthused in its introductory post on Exploit. &#8220;Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.&#8221;</p>
<p>Indeed, over the past 24 hours, the number of drivers license records listed as available in Nexus has increased by nearly 400,000, suggesting that freshly stolen license data is being harvested and uploaded to this service on a semi-regular basis.</p>
<p>The record featuring my drivers license includes six image files: three pairs of photos of the license&#8217;s front and back, a basic image scan, as well as infrared and ultraviolet versions of the same images. A date and timestamp is appended to each image file, and the timestamp on my license scan corresponds to a date in June 2025 when I took a flight to the midwest United States to attend a family funeral.</p>
<div id="attachment_74235" style="width: 760px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74235" class=" wp-image-74235" src="https://krebsonsecurity.com/wp-content/uploads/2026/09/nexus-bk.png" alt="" width="750" height="532" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/09/nexus-bk.png 1016w, https://krebsonsecurity.com/wp-content/uploads/2026/09/nexus-bk-768x545.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/09/nexus-bk-782x555.png 782w, https://krebsonsecurity.com/wp-content/uploads/2026/09/nexus-bk-100x70.png 100w" sizes="(max-width: 750px) 100vw, 750px" /><p id="caption-attachment-74235" class="wp-caption-text">Some of the 153 million+ license scans &#8212; including mine &#8212; feature six image files with date and timestamps appended to the filenames. Not all records include photos, and some that do feature photos do not display the associated filenames.</p></div>
<p>Intent on discovering the source of this data, KrebsOnSecurity asked more than a dozen friends and family members for permission to search for their licenses in this service. Each person whose license could be found (nine of them) confirmed having traveled on or very close to the dates in the timestamps attached to their images. It is unclear what timezone these timestamps are in, but from reviewing car rental records shared by several people who helped with this research, it appears the timezone is set to Greenwich Mean Time (GMT).</p>
<p>At first, I thought the source of the data might have something to do with airports. However, that theory went out the window when it became apparent there were no passports in this data set. Also, only some of those who helped with this research said they showed their drivers license at the airport on the day of their travel. One person whose license was in Nexus hadn&#8217;t flown at all recently, but was renting a car from <strong>Hertz</strong> for several months around the date of their timestamp.</p>
<p>Two of those who agreed to help are federal employees who said they shared other forms of government identification when passing through airport security. However, those individuals each said they shared their state-issued drivers licenses later that day when renting vehicles at their respective destinations, and that both rented their cars from Hertz.</p>
<p>After finding a note in my calendar for the day of my June 2025 flight reminding me to bring my passport, I remembered that I also never actually shared my drivers license when I went through security at Reagan National Airport on that day because I did not yet have a Real ID, a security-enhanced drivers license that is now required by the Transportation Security Administration (TSA) for all domestic travel. Instead, I showed the TSA agent my government-issued U.S. passport.</p>
<p>Here&#8217;s where it gets interesting: I was able to find my mother&#8217;s drivers license in this service as well, and the timestamps for her images are just a few seconds apart from mine. That&#8217;s notable because we both handed our licenses to the Hertz rental car representative at the same time.<span id="more-74231"></span></p>
<p>According to my mom, the only place she gave her drivers license to that day was the rental car company, and if memory serves that is also true for me. I don&#8217;t recall if the rental car representative inserted our licenses into any kind of machine, but I remember they held onto them for several minutes behind the counter while we were signing various forms. KrebsOnSecurity sought comment from Hertz and will update this story in the event they reply.</p>
<p><strong>Zach Edwards</strong> is a well-known security and privacy researcher who recently launched a service called <a href="https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/" target="_blank" rel="noopener">DecryptAds</a> to help people better understand how online advertisers are tracking them. A scan of Edwards&#8217;s drivers license is available for purchase on this identity theft service, and Edwards said the timestamp on his record corresponds to the middle of a trip last month to Las Vegas for the annual DEFCON security conference.</p>
<p>Edwards told KrebsOnSecurity that although he did not rent a car in Vegas, he did hand over his license at the TSA checkpoint, at a marijuana dispensary in Vegas, and at his hotel (the Aria). But he said the only one of those three that for sure scanned his ID in some kind of device was the dispensary.</p>
<div id="attachment_74250" style="width: 600px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74250" class="size-full wp-image-74250" src="https://krebsonsecurity.com/wp-content/uploads/2026/09/planet13.png" alt="" width="590" height="786" /><p id="caption-attachment-74250" class="wp-caption-text">To enter Planet13&#8217;s weed dispensary in Las Vegas, one must pass through a red telephone booth. Image: Zach Edwards.</p></div>
<p>Edwards said the dispensary he visited that day was <strong>Planet13</strong>, a multi-state chain with stores in California, Florida, Illinois and Nevada. In 2022, the New Orleans-based identity provider <strong>idscan.net</strong> published <a href="https://idscan.net/press-release/planet-13-partners-with-idscan-net/?srsltid=AfmBOooFV0QbsE8UCJBUhGP8mbYCl7j4iKJljXTf4NZA5n79ey00b5Qo" target="_blank" rel="noopener">a press release</a> announcing an exclusive identity verification agreement with Planet13&#8217;s dispensaries nationally. IDScan says it processes ID verification for more than 1,000 marijuana dispensaries in 19 U.S. states.</p>
<p>The &#8220;trust&#8221; page of idscan.net states that the company provides identity verification services for numerous big brands, including Hertz, <strong>Target</strong>, <strong>Fedex</strong>, <strong>Motorola Solutions</strong>, the financial services giant <strong>Jack Henry</strong>, and <strong>Caesars Entertainment</strong>. And as idscan.net&#8217;s own <a href="https://idscan.net/press-release/2025-id-fraud-report/" target="_blank" rel="noopener">documentation states</a>, the technology scans IDs with both infrared and ultraviolet light. Idscan.net says the company&#8217;s systems and technology perform more than 21 million verifications monthly, at more than 20,000 locations around the world.</p>
<div id="attachment_74242" style="width: 759px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74242" class=" wp-image-74242" src="https://krebsonsecurity.com/wp-content/uploads/2026/09/idscan-partners.png" alt="" width="749" height="314" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/09/idscan-partners.png 969w, https://krebsonsecurity.com/wp-content/uploads/2026/09/idscan-partners-768x322.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/09/idscan-partners-782x328.png 782w" sizes="(max-width: 749px) 100vw, 749px" /><p id="caption-attachment-74242" class="wp-caption-text">Image: idscan.net.</p></div>
<p>Contacted by KrebsOnSecurity, idscan.net said it was investigating the matter, but the company has not yet shared an official statement or a substantive reply to specific questions sent via email.</p>
<p>&#8220;At this point I&#8217;m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team&#8217;s investigation,&#8221; wrote <strong>Jillian Kossman</strong>, a marketing and operations leader at idscan.net.</p>
<p>During the course of my research for this story, word got around to the FBI that I was poking at the apparent source of this new identity theft service&#8217;s data. Probably they were tipped off when I shared with a trusted source that Nexus also is selling the drivers license information for the assistant director of the FBI (I did not find FBI Director Kash Patel&#8217;s license in Nexus).</p>
<p>Earlier this afternoon, I was added to a conference call with a half-dozen FBI agents, including senior leaders from the agency&#8217;s cyber division. During that call, the FBI shared that earlier today their New Orleans field office opened an official investigation into an apparent breach involving idscan.net.</p>
<p>Edwards said that as more in-person and online experiences require sharing drivers licenses, vendors who collect this sensitive data need to be held to a higher standard.</p>
<p>&#8220;This episode should further strengthen the resolve for people who are fighting back against online ID schemes which are requiring countless providers to ask for drivers licenses in order to access services under the guise of protecting kids,&#8221; Edwards told KrebsOnSecurity. &#8220;These systems are putting sensitive data into more and more 3rd party vendors, and we don’t have nearly the oversight to ensure they are safe.&#8221;</p>
<p><strong>Larry Baldwin</strong> is principal intelligence researcher at the cybersecurity firm <a href="https://www.cybera.io" target="_blank" rel="noopener">Cybera</a>. Baldwin said a front and back scan of his drivers license available at Nexus contains timestamps that correspond to the date of a car rental from Hertz on a recent vacation.</p>
<p>Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one&#8217;s identity when opening new lines of credit. Baldwin said the service could also dangerously expose many people who do not wish to be found but who cannot meaningfully change their appearance (or at least not enough to fool today&#8217;s AI-based image matching tools).</p>
<p>This category of people, he said, includes those fleeing domestic violence, and even people who have been assigned a whole new life and identity as part of the federal government&#8217;s witness protection program, which is generally reserved for criminal defendants in racketeering and conspiracy investigations who agree to cooperate with federal authorities.</p>
<p>“Just when it seems like we’re making some headway in improving authentication controls through drivers license verification systems, this happens and the very thing those improvements are dependent on are compromised,” Baldwin said.</p>
<p><strong>Update, Sept. 8:</strong> IDscan.net published <a href="https://idscan.net/notification-data-security-incident/" target="_blank" rel="noopener">a brief notice</a> saying it has &#8220;determined that an unauthorized third party may have accessed and/or copied certain customer information, including full names and drivers license or other government-issued identification numbers.&#8221; The statement said IDscan.net is notifying affected individuals and offering credit protection services.</p>
<p><strong>Update, Sept. 2, 6:05 p.m. ET:</strong> A spokesperson for Caesars Entertainment said Caesars has not been a client of IDScan.net and has not used VeriScan since February 2025, despite IDScan.net listing them as a client on their website. That person said Caesars had no active VeriScan accounts at the time of the incident and did not authorize IDScan.net to retain data from its accounts, and that IDScan.net said the incident should have no impact on Caesars Entertainment.</p>
<p><strong>Update, 8:56 p.m. ET:</strong> Shortly after this story was published, the Nexus identity theft service website vanished from the darkweb, replacing its login page with a plain text message that reads, &#8220;This service is no longer available.&#8221;</p>
<p><em>This is a potentially fast-moving story. Any changes or updates will be noted here along with a timestamp.</em></p>
]]></content:encoded>
					
					<wfw:commentRss>https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/feed/</wfw:commentRss>
			<slash:comments>133</slash:comments>
		
		
			</item>
		<item>
		<title>Two Alleged &#8216;TeamPCP&#8217; Hackers Arrested in Australia</title>
		<link>https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/</link>
					<comments>https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/#comments</comments>
		
		<dc:creator><![CDATA[BrianKrebs]]></dc:creator>
		<pubDate>Thu, 27 Aug 2026 11:04:15 +0000</pubDate>
				<category><![CDATA[Breadcrumbs]]></category>
		<category><![CDATA[Ne'er-Do-Well News]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[Aikido Security]]></category>
		<category><![CDATA[BulkDMT]]></category>
		<category><![CDATA[Charlie Eriksen]]></category>
		<category><![CDATA[Constella Intelligence]]></category>
		<category><![CDATA[cybercats]]></category>
		<category><![CDATA[domaintools]]></category>
		<category><![CDATA[Ellis]]></category>
		<category><![CDATA[Epieos]]></category>
		<category><![CDATA[Express]]></category>
		<category><![CDATA[Flashpoint]]></category>
		<category><![CDATA[GitHub]]></category>
		<category><![CDATA[Intel 471]]></category>
		<category><![CDATA[OPSEC Express]]></category>
		<category><![CDATA[pcpcats]]></category>
		<category><![CDATA[Persy_PCP]]></category>
		<category><![CDATA[Ruben Thomson]]></category>
		<category><![CDATA[ruben@securecomputing.au]]></category>
		<category><![CDATA[rubenthomson.com]]></category>
		<category><![CDATA[sheepstealing@gmail.com]]></category>
		<category><![CDATA[shitstickpp@gmail.com]]></category>
		<category><![CDATA[SpyCloud]]></category>
		<category><![CDATA[surfinup8@gmail.com]]></category>
		<category><![CDATA[TeamPCP]]></category>
		<category><![CDATA[Tensor Industries]]></category>
		<category><![CDATA[yolosolo17@gmail.com]]></category>
		<guid isPermaLink="false">https://krebsonsecurity.com/?p=73635</guid>

					<description><![CDATA[Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever.

In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a "sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses."

The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old suspect's real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP's self-described spokesperson, and examines clues left behind by the TeamPCP leader that likely led to his undoing.]]></description>
										<content:encoded><![CDATA[<p>Authorities in Australia have arrested two men believed to be members of <strong>TeamPCP</strong>, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever.</p>
<p>In <a href="https://www.afp.gov.au/news-centre/media-release/two-wa-men-charged-following-afp-fbi-wapf-disruption-alleged-global" target="_blank" rel="noopener">a statement</a> released today, the <strong>Australian Federal Police</strong> (AFP) said two men from Western Australia, aged 21 and 23, were arrested in connection with a &#8220;sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.&#8221;</p>
<p>The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old suspect&#8217;s real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP&#8217;s self-described spokesperson, and examines clues left behind by the TeamPCP leader that likely led to his undoing.</p>
<p>TeamPCP vaulted onto the cybercrime scene in late 2025, embedding malicious code in hundreds of open source software tools and extorting victims for profit. Members of the group made headlines by compromising corporate cloud environments using a self-propagating worm dubbed <strong>Shai-Hulud</strong>, which added malicious code to open source programs maintained by developers whose credentials at public code repositories like GitHub or NPM were phished or stolen.</p>
<p>Writing for <em>Wired</em>, journalist <strong>Andy Greenberg</strong> described TeamPCP&#8217;s core tactic as a kind of cyclical exploitation of software developers.</p>
<p>&#8220;The hackers gain access to a network where an open source tool commonly used by coders is being developed,&#8221; Greenberg <a href="https://www.wired.com/story/teampcp-software-supply-chain-attack-spree-github/" target="_blank" rel="noopener">wrote in May</a>. &#8220;The hackers plant malware in the tool that ends up on other software developers’ machines, including some who are writing other tools intended to be used by coders. The malware allows TeamPCP’s hackers to steal credentials that let them publish malicious versions of those software development tools, too. The cycle repeats, and TeamPCP’s collection of breached networks grows.&#8221;</p>
<p>TeamPCP also has practiced something akin to cyclical recruitment. In May, the source code for the third iteration of Shai-Hulud was published online, and TeamPCP soon after launched a contest offering $1,000 in virtual currency to whichever participant could conduct the largest supply chain operation using the worm&#8217;s code. According to the contest rules, participants were scored based on the number of weekly and monthly downloads of packages they compromised &#8212; directly incentivizing them to target the most popular code libraries.</p>
<div id="attachment_74036" style="width: 700px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74036" class="size-full wp-image-74036" src="https://krebsonsecurity.com/wp-content/uploads/2026/07/teampcp-shai-hulud.png" alt="" width="690" height="581" /><p id="caption-attachment-74036" class="wp-caption-text">A screenshot of a message from TeamPCP&#8217;s Telegram account, announcing the supply chain hacking contest. Image: dataminr.com.</p></div>
<p>&#8220;TeamPCP has stated the competition is a recruiting opportunity and they intend to purchase all meaningful access harvested from participants’ campaigns,&#8221; the security firm Dataminr <a href="https://www.dataminr.com/resources/cyber-intel-deep-dive-teampcp-shai-hulud-3-0/" target="_blank" rel="noopener">wrote</a>. &#8220;The $1,000 XMR (Monero) prize is a recruitment floor and has been dismissed by the actor as &#8216;just like participation trophy,&#8217; adding &#8216;if you find something good you will be paid way more,&#8217; confirming the contest’s true function as talent identification and malicious access acquisition at scale.&#8221;</p>
<p>In March, TeamPCP executed a supply chain attack targeting AI infrastructure by compromising the code for <strong>LiteLLM</strong>, an open source AI gateway that connects users to more than 100 different large language models. A <a href="https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines#" target="_blank" rel="noopener">recent analysis</a> by the security firm <strong>CloudSEK</strong> found TeamPCPs attack on LiteLLM harvested cloud service keys and other secrets from more than 2,500 organizations, including many of the world&#8217;s top technology companies.</p>
<p>In May, TeamPCP claimed credit for compromising at least 3,800 code repositories at the Microsoft-owned <strong>GitHub</strong>, after a GitHub developer installed a code extension that was compromised by TeamPCP&#8217;s malware.</p>
<h2>MEET THE CYBERCATS</h2>
<p>Security experts say TeamPCP is less of a hacker group than an amalgamation of threat actors from multiple cybercriminal gangs who sometimes work together toward similar goals.</p>
<p>&#8220;It is not a structured criminal crew with a single operator,&#8221; said <strong>Austin Larsen</strong>, a principal threat analyst with the <strong>Google Threat Intelligence Group</strong>. &#8220;It is a peer community of individually-skilled actors, with one clear center of gravity.&#8221;</p>
<p>That center of gravity is <strong>George Prepakis</strong>, an accomplished security researcher and self-described exploit developer who operates the Twitter/X profile <a href="https://x.com/kernelstub" target="_blank" rel="noopener">@kernelstub</a>. Earlier this year, @kernelstub tweeted a public invite link to a Matrix chat server he created and dubbed &#8220;Cybercats,&#8221; and TeamPCP and several other cybercrime entities have been using this server to communicate daily for the past several months.</p>
<div id="attachment_74165" style="width: 758px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74165" class=" wp-image-74165" src="https://krebsonsecurity.com/wp-content/uploads/2026/08/matrix-tpcp-xpl0itrs.png" alt="" width="748" height="590" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/08/matrix-tpcp-xpl0itrs.png 1018w, https://krebsonsecurity.com/wp-content/uploads/2026/08/matrix-tpcp-xpl0itrs-768x606.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/08/matrix-tpcp-xpl0itrs-782x617.png 782w" sizes="(max-width: 748px) 100vw, 748px" /><p id="caption-attachment-74165" class="wp-caption-text">A screenshot of the Matrix chat server &#8220;Cybercats,&#8221; whose members used hacker handles associated with multiple distinct cybercrime groups that have occasionally collaborated on a series of supply chain and data ransom attacks over the past nine months.</p></div>
<p>Kernelstub, like other administrators in the Cybercats chat, has been using his Twitter/X profile name as his handle in these Matrix communications, frequently tweeting references to other members and to conversations taking place in the Cybercats chat. In a number of cases, the corresponding X accounts for members of the Cybercats chat taunted cybercrime victims publicly before the incidents were reported in the news media.</p>
<p>The Cybercats administrator listed at the top of the screenshot above &#8212; &#8220;<strong>Boxturtle</strong>&#8221; &#8212; is a close associate of TeamPCP who has been tweeting about the group&#8217;s conquests under the name <a href="https://x.com/xploitrsturtle2/" target="_blank" rel="noopener">@xpl0itrsturtle</a>. This handle corresponds to a data breach broker active on Breachforums and Darkforums who has been selling data stolen in a wave of recent breaches at automobile manufacturers, including <strong>BMW Group</strong>, <strong>Audi</strong>, <strong>Honda</strong>, <strong>Mercedes-Benz</strong>, <strong>Volvo</strong> and <strong>Toyota</strong>, as well as data allegedly taken from <strong>Snapchat</strong> and <strong>SportRadar</strong>.</p>
<div id="attachment_74174" style="width: 760px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74174" class=" wp-image-74174" src="https://krebsonsecurity.com/wp-content/uploads/2026/08/xpl0itrs-dls.png" alt="" width="750" height="525" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/08/xpl0itrs-dls.png 1119w, https://krebsonsecurity.com/wp-content/uploads/2026/08/xpl0itrs-dls-768x538.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/08/xpl0itrs-dls-782x548.png 782w, https://krebsonsecurity.com/wp-content/uploads/2026/08/xpl0itrs-dls-100x70.png 100w" sizes="(max-width: 750px) 100vw, 750px" /><p id="caption-attachment-74174" class="wp-caption-text">The data leak site for the extortion group or handle &#8220;xpl0itrs.&#8221;</p></div>
<p>The Cybercats administrator &#8220;<strong>SeesawSec</strong>&#8221; in the screenshot above is the alias of whoever is behind the cybercrime group known as <strong>Fulcrumsec</strong>, which recently claimed credit for data extortion attacks against the pharmaceutical giant <strong>Novo Nordisk</strong>, the data broker <strong>LexisNexis</strong>, and <strong>Avnet</strong>, a Fortune 500 distributor of electronic components.</p>
<div id="attachment_74175" style="width: 686px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74175" class=" wp-image-74175" src="https://krebsonsecurity.com/wp-content/uploads/2026/08/fulcrumsec-dls.png" alt="" width="676" height="858" /><p id="caption-attachment-74175" class="wp-caption-text">The data leak site of Fulcrum Security, a.k.a. Fulcrumsec.</p></div>
<p>The Cybercats administrator &#8220;<strong>@pcpcasper</strong>&#8221; also has been using a similar name on X to discuss TeamPCP&#8217;s attacks and victims. This person has an extensive message history on Telegram, where their messages and shared videos show @pcpcasper is an active and vocal member of the National Socialist Network, a neo-Nazi political organization based in Australia.</p>
<p>At one point in these chats, @pcpcasper shared videos and images of what they claimed was their cat, and several of those videos place this user in Western Australia. One source close to the investigation told KrebsOnSecurity that @pcpcasper was one of the two arrested, a claim supported by messages that @kernelstub posted online this morning.</p>
<p>The Cybercats member roster pictured above also features an administrator with the username &#8220;<strong>T</strong>,&#8221; which is short for the now-banned Twitter/X profile <strong>@pcpcats</strong>, the account operated by the self-described TeamPCP spokesperson who was arrested today. As we&#8217;ll see in a moment, @pcpcats also is from Western Australia.</p>
<p>By the time @kernelstub tweeted a public invite link to the Cybercats Matrix server, T/@pcpcats was posting only infrequently to the group chat, with other members often inquiring as to his whereabouts and well-being. The group&#8217;s collective concern related to @pcpcats&#8217;s tendency to blame his increasingly extended absences on the use of hallucinogens and other narcotics that kept him awake for days on end, but also caused him to crash in bed for several days after the highs wore off.<span id="more-73635"></span></p>
<h2>WHO IS THE TEAMPCP LEADER?</h2>
<p>The Cybercats member @pcpcats has used multiple nicknames on the cybercrime forums, including <strong>EllisD25/LSD</strong> on Darkforums, <strong>BulkDMT</strong> on Breachstars, and <strong>Express</strong> on Breachforums. These accounts are linked because they all advertised the same Tox ID and/or Session ID as instant message contact handles in their cybercrime forum posts. BulkDMT was also known on the forums as <strong>DMT Host</strong>, which was a <a href="https://cloud.google.com/learn/what-is-a-virtual-private-server" target="_blank" rel="noopener">virtual private server</a> (VPS) hosting service that was peddled on Darkforums and Breachstars.</p>
<div id="attachment_74040" style="width: 760px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74040" class=" wp-image-74040" src="https://krebsonsecurity.com/wp-content/uploads/2026/07/dmthost.png" alt="" width="750" height="356" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/07/dmthost.png 950w, https://krebsonsecurity.com/wp-content/uploads/2026/07/dmthost-768x365.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/07/dmthost-782x371.png 782w" sizes="(max-width: 750px) 100vw, 750px" /><p id="caption-attachment-74040" class="wp-caption-text">DMT Host/EllisD25, posting on the English-language cybercrime community DarkForums in September 2025. Image: ke-la.com.</p></div>
<p>According to the cyber intelligence firm <strong>Intel 471</strong>, Express registered on Breachforums using the email address <strong>shitstickpp@gmail.com</strong>. Intel 471 finds Express posted on Breachforums across a two-month period in 2025 using four different Internet addresses located in <strong>South Africa</strong>. On July 30, 2025, Express announced on Breachforums they were selling access to 14 gigabytes of data stolen from South Africa&#8217;s State Information Technology Agency.</p>
<p>The threat intelligence platform <strong>Flashpoint</strong> recorded more than a year&#8217;s worth of messages from the TeamPCP leader&#8217;s alter ego on Telegram &#8212; <strong>Persy_PCP</strong> &#8212;  who claimed they split their life living between two countries [full disclosure: Flashpoint is an advertiser on this blog]. &#8220;I have these [files] as well, problem is these are in another country,&#8221; Persy_PCP explained to another user inquiring about a stolen data set in November 2025.</p>
<p>Later that month, Persy_PCP complained, &#8220;My whole country is racist and they want people like me dead.&#8221; Flashpoint records show BulkDMT shared in September 2025 that &#8220;this country is going to fucking starve when they take the farmers land,&#8221; a likely reference to white landowners in South Africa who <a href="https://www.pbs.org/newshour/world/a-hillside-of-white-crosses-fuels-a-misleading-story-about-south-africas-farm-killings" target="_blank" rel="noopener">claim to be targeted by an ongoing genocide campaign</a>.</p>
<p>This tracks with public reporting on TeamPCP. <em>Cyberscoop</em> <a href="https://cyberscoop.com/teampcp-breaks-open-source-software-trust-model/" target="_blank" rel="noopener">reported in June</a> that <strong>Google</strong> had traced TeamPCP&#8217;s residential and mobile Internet address connections to South Africa, &#8220;indicating the primary operator was located there during at least some of its attacks.&#8221;</p>
<p>BulkDMT also shared on the group chat at Breachforums that they were recovering from an addiction to methamphetamine. &#8220;My life is kinda fucked rn [right now], but that&#8217;s fine and there isn&#8217;t really a point in pouring so much emotional energy into that fact, my parents had money but I unfortunately got really addicted to some things so I don&#8217;t get to benefit from that. As long as I continue to survive, stay sober, and move closer towards my goals that&#8217;s enough drive and meaning.&#8221;</p>
<p>The identity threat protection company <strong>SpyCloud</strong> finds shitstickpp@gmail.com shows up in the registration of an account called <strong>ChristmasSnow</strong> on the cybercrime community <strong>Raidforums</strong> in 2022. Nearly all of the Internet addresses used to access that account came from ISPs in Perth, Australia, SpyCloud found.</p>
<p>KrebsOnSecurity looked up all of those Perth IP addresses in <a href="https://docs.domaintools.com/iris/investigate/data-panels/pdns/" target="_blank" rel="noopener">passive DNS</a> records maintained by <strong>DomainTools.com</strong>, and found one of them &#8212; <strong>211.27.196.111</strong> &#8212; for several years was used as a private file server by a family in Perth with the last name of <strong>Thomson</strong>. Those records show at least three hosts &#8212; ithomson.direct.quickconnect.to (a remote Synology server), kthomson0061.direct.quickconnect.to, and <strong>joshuawthomson39.myqnapcloud.com</strong> (a QNAP network storage device) &#8212; persisted at that address between 2022 and 2025.</p>
<p>Searching on &#8220;<strong>joshuathomson39</strong>&#8221; in the breach tracking service <strong>Constella Intelligence</strong> reveals an account at the freight forwarding company kwe.com created in the name of Joshua Thomson from Perth, Australia. The open source intelligence platform <strong>Epieos</strong> finds the phone number attached to that kwe.com account was used to register a Facebook profile for Josh Thomson, which says his family includes a brother named <strong>Ruben</strong>, his father <strong>Ian</strong>, and his mom Cindy.</p>
<p>That Facebook profile also says Josh and his family are originally from <a href="https://en.wikipedia.org/wiki/Pietermaritzburg" target="_blank" rel="noopener">Pietermaritzburg</a>, in KwaZulu-Natal, South Africa, but currently living in <a href="https://en.wikipedia.org/wiki/Cottesloe,_Western_Australia" target="_blank" rel="noopener">Cottesloe</a>, a beach-side suburb of Perth. A search in DomainTools for Ian Thomson and Australia unearthed five domains by the same registrant, including <strong>securecomputing.au</strong>, <strong>thomson.org.au</strong>, and <strong>thomsonfamily.net.au</strong>. Ian Thomson is a dentist in Cottesloe, and a biography says he graduated from The University of the Witwatersrand in Johannesburg, South Africa.</p>
<p>Constella finds a joshua@thomson.org.au registered a number of accounts online, but Josh doesn&#8217;t seem to have much of a connection to dodgy cybercrime forums. His brother Ruben, on the other hand, has quite the presence on these communities, dating back to at least 2018. Constella reports <strong>ruben@thomson.org.au</strong> frequently reused the password &#8220;joshuathomson1,&#8221; and Constella further finds that password was used by just a handful of accounts, including <strong>yolosolo17@gmail.com</strong> and <strong>surfinup8@gmail.com</strong>.</p>
<p>According to Intel 471, surfinup8@gmail.com was used to register the user <strong>Yolosolo17</strong> on the crime forum <strong>Altenen</strong> in 2018, and that user account was registered from the Perth address <strong>110.141.230.15</strong>. On Altenen, Yolosolo17 advertised free web proxies, as well as the domain rubenthomson.com, which was at one point used to sell steeply discounted iPhones. <strong>DomainTools</strong> says rubenthomson.com was hosted at 110.141.230.15 and registered to surfinup8@gmail.com.</p>
<div id="attachment_73723" style="width: 758px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-73723" class=" wp-image-73723" src="https://krebsonsecurity.com/wp-content/uploads/2026/05/rubenthomsondotcom.png" alt="" width="748" height="483" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/05/rubenthomsondotcom.png 1146w, https://krebsonsecurity.com/wp-content/uploads/2026/05/rubenthomsondotcom-768x496.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/05/rubenthomsondotcom-782x505.png 782w" sizes="(max-width: 748px) 100vw, 748px" /><p id="caption-attachment-73723" class="wp-caption-text">A cached copy of the domain rubenthomson.com from 2017 shows a login page underneath a banded stack of money. Image: archive.org.</p></div>
<p>SpyCloud reports 10.141.230.15 was used by the email address <strong>sheepstealing@gmail.com</strong> on Raidforums and surfinup8@gmail.com on Nulled, and that the same IP was used by the email addresses ian@thomsonfamily.net.au, jasper@yakuza.cc, and rubenthomson1@gmail.com. SpyCloud also shows that sheepstealing Gmail address is tied to the accounts <strong>Sheep420</strong>, <strong>YoloSolo117</strong> and <strong>Yakuza.cc</strong> on Raidforums, and to the account &#8220;Sheep Stealing&#8221; on Hackforums. Intel 471 says sheepstealing@gmail.com was used to register the account <strong>DingoFlour</strong> on Breachforums in October 2023, as well <strong>Sheepx</strong> on Altenen.</p>
<p>Epieos reports that <strong>ruben@securecomputing.au</strong> is tied to an <strong>Airbnb</strong> account for Ruben, who described himself as a Web developer who went to school at the University of Western Australia and was living outside the country. &#8220;Hey, I&#8217;m Ruben, my friends call me <strong>Ellis</strong>. I&#8217;m a Perth creative who occasionally books rooms when visiting family and for photography.&#8221;</p>
<p>Epieos also finds sheepstealing@gmail.com registered an upwork.com profile under the name Ruben, who said his main skills are setting up secure server hosting solutions and PHP full-stack Web development.</p>
<p>&#8220;I&#8217;m familiar with Linux, working with relational databases (SQL),&#8221; the Upwork profile reads. &#8220;I also script in Python mainly for writing social media bots.&#8221;</p>
<div id="attachment_74038" style="width: 760px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74038" class=" wp-image-74038" src="https://krebsonsecurity.com/wp-content/uploads/2026/07/upwork-thomson.png" alt="" width="750" height="397" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/07/upwork-thomson.png 1419w, https://krebsonsecurity.com/wp-content/uploads/2026/07/upwork-thomson-768x406.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/07/upwork-thomson-782x414.png 782w, https://krebsonsecurity.com/wp-content/uploads/2026/07/upwork-thomson-267x140.png 267w" sizes="(max-width: 750px) 100vw, 750px" /><p id="caption-attachment-74038" class="wp-caption-text">The Upwork profile for Ruben Thomson in Cottesloe, Australia.</p></div>
<p>Epieos further discovered sheepstealing@gmail.com is connected to a Microsoft account for Ruben Thomson, and to a now-defunct GitHub account called <a href="https://web.archive.org/web/*/https://github.com/XmasSnow*" target="_blank" rel="noopener">XmasSnow/XmasSnowisBack</a> that scammed people on the forums in 2022 by claiming to sell exclusive exploits for recently-released software patches (recall that shitstickpp@gmail.com was used to register a forum account named ChristmasSnow).</p>
<p>This same sheepstealing email address registered a Twitter/X account in 2026 called &#8220;Gone Fishing&#8221; that lists its location as South Africa. That Gmail account also <a href="https://www.google.com/maps/contrib/116139896651889086279/reviews/@-32.2179865,115.5244308,99089m/data=!3m2!1e3!4b1!4m3!8m2!3m1!1e1?entry=ttu&amp;g_ep=EgoyMDI2MDUxMS4wIKXMDSoASAFQAw%3D%3D" target="_blank" rel="noopener">left several reviews</a> for businesses listed on Google Maps over the past seven years, but all of those establishments are located on the west coast of Australia.</p>
<div id="attachment_74037" style="width: 760px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74037" class=" wp-image-74037" src="https://krebsonsecurity.com/wp-content/uploads/2026/07/gonefishing.png" alt="" width="750" height="547" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/07/gonefishing.png 1306w, https://krebsonsecurity.com/wp-content/uploads/2026/07/gonefishing-768x560.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/07/gonefishing-782x571.png 782w" sizes="(max-width: 750px) 100vw, 750px" /><p id="caption-attachment-74037" class="wp-caption-text">Business reviews in Western Australia left by the Google account sheepstealing at gmail.com.</p></div>
<p>The people search service <strong>Pipl</strong> finds a 21-year-old Ruben Thomson in Western Australia who has a phone number ending in 979. A lookup on that number at Epieos reveals it is connected to <a href="https://www.tiktok.com/@user7508029790800" target="_blank" rel="noopener">a TikTok account</a> under the name Ellis, and to a PayPal account in the name of Ruben Thomson.</p>
<p>Finally, a search on the name Ruben Thomson from Cottesloe at the Australian government&#8217;s record of registered businesses finds he has incorporated or served as an official in multiple companies created since 2024, including <strong>Secure Computing Solutions</strong>, <a href="https://connectonline.asic.gov.au/RegistrySearch/faces/landing/bySearchId.jspx?searchIdType=BUSN&amp;searchId=698546137" target="_blank" rel="noopener">Tensor Industries</a>, and another entity ironically named <a href="https://connectonline.asic.gov.au/RegistrySearch/faces/landing/bySearchId.jspx?searchIdType=BUSN&amp;searchId=684301513" target="_blank" rel="noopener">OPSEC Express</a>. Recall that Express was BulkDMT&#8217;s nickname on Breachforums.</p>
<div id="attachment_74206" style="width: 760px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74206" class=" wp-image-74206" src="https://krebsonsecurity.com/wp-content/uploads/2026/08/rthomson-companies.png" alt="" width="750" height="449" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/08/rthomson-companies.png 1333w, https://krebsonsecurity.com/wp-content/uploads/2026/08/rthomson-companies-768x460.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/08/rthomson-companies-782x468.png 782w" sizes="(max-width: 750px) 100vw, 750px" /><p id="caption-attachment-74206" class="wp-caption-text">Australian companies connected to Ruben Thomson. Image: abr.business.gov.au.</p></div>
<p>It&#8217;s ironic because OPSEC is short for the term &#8220;operational security,&#8221; which refers to techniques and behaviors used to obfuscate and compartmentalize one&#8217;s real-life identity online, and using your cybercrime handle as part of your own company name is very much the antithesis of that practice.</p>
<p>There is at least one other major opsec failure by Ruben that exposed a link to TeamPCP. In June 2025, someone using the name Ruben Thomson registered on <strong>HackerOne</strong>, a popular &#8220;bug bounty&#8221; program that seeks to reward and recognize researchers who agree to work with affected software vendors to help fix the flaws before publishing about their findings. What was Ruben Thomson&#8217;s chosen HackerOne username? <strong>Deadcatx3</strong>, a nickname that has been <a href="https://labs.cloudsecurityalliance.org/research/csa-research-note-teampcp-multi-ecosystem-supply-chain-20260/" target="_blank" rel="noopener">flagged by multiple security firms</a> as an alias used by TeamPCP.</p>
<div id="attachment_74167" style="width: 756px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74167" class=" wp-image-74167" src="https://krebsonsecurity.com/wp-content/uploads/2026/08/ruben-deadcatx3.png" alt="" width="746" height="415" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/08/ruben-deadcatx3.png 1627w, https://krebsonsecurity.com/wp-content/uploads/2026/08/ruben-deadcatx3-768x427.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/08/ruben-deadcatx3-1536x854.png 1536w, https://krebsonsecurity.com/wp-content/uploads/2026/08/ruben-deadcatx3-782x435.png 782w" sizes="(max-width: 746px) 100vw, 746px" /><p id="caption-attachment-74167" class="wp-caption-text">The HackerOne profile for &#8220;Ruben Thomson&#8221; uses the nickname Deadcatx3, which multiple security firms have concluded is an alias used by TeamPCP. Image credit: flare.io.</p></div>
<h2>INTERVIEW WITH ELLIS</h2>
<p>In early July 2026, not long after having discovered clues about Ellis&#8217;s real life identity, KrebsOnSecurity interviewed the TeamPCP leader via Signal, where he was remarkably open about his activities and personal struggles [for the sake of simplicity, the TeamPCP spokesperson will be referred to from here on as Ellis].</p>
<p>Ellis claims he stopped doing cybercrime for TeamPCP in March 2026 &#8212; just before the attacks that compromised LiteLLM &#8212; and that at least one other individual has taken over the group&#8217;s leadership since then. Ellis shared that a year earlier he had just completed the latest in a series of detox and sobriety programs, and was two months sober when he reconnected with some old friends from the malware development scene.</p>
<p>&#8220;One year ago I needed help monetizing some [GitHub credentials], I was two months sober and needed a distraction and something to keep busy as well as people to speak to,&#8221; Ellis said. &#8220;I had largely disconnected from my old circle, they had become very toxic and I needed to get away from the substances. Previously I had done some mass exploitation campaigns and grew up doing [malware development] and [capture the flag] contests. There were some friends who were also vending but had stopped a while, and one of them introduced me to some chats where I posted access for sale.&#8221;</p>
<p>Prior to that, Ellis said, he was homeless and hopping between &#8220;some very unstable places.&#8221;</p>
<p>&#8220;Blackhatting is fun,&#8221; he said. &#8220;There are actual rewards and incentives to learn and you grow with your team. Without qualifications, no employer will even take the time to hear you out.&#8221;</p>
<p>Ellis claims he&#8217;s earned a grand total of about $20,000 for his activities with TeamPCP, and that it was never about the money or fame for him. Asked whether his experiences with TeamPCP might prepare him for gainful employment in a legitimate IT job, Ellis said he doubted it.</p>
<p>&#8220;I am nowhere close to a skill level where I am comfortable, and this would take maybe half a decade of further experience,&#8221; he said. &#8220;I no longer have to choose between rent and food for that I&#8217;m grateful and so are the team members.&#8221;</p>
<p>Ellis expressed no remorse over his cybercrime activities, and said he was grateful for the friendships and relationships built throughout his engagement with TeamPCP. The young hacker also seemed resigned to his fate, and told KrebsOnSecurity that he&#8217;ll accept the consequences if he&#8217;s ever arrested.</p>
<p>&#8220;If I&#8217;ve already been found out then its out of my control, I&#8217;ll make peace with that,&#8221; he said. &#8220;Honestly, I think someone like me needs a lot of help that prison just can&#8217;t provide. If I had the funds to study different parts of the field and closer guidance, this would have turned out differently. But that&#8217;s a pipe dream and we both know this.&#8221;</p>
<p>It is clear from reading Ellis&#8217;s posts to the group&#8217;s Matrix server chats that his struggles with sobriety are ongoing. On Thursday, June 25, Ellis told @kernelstub he was about to &#8220;trip&#8221; with his &#8220;homie.&#8221;</p>
<p>&#8220;What kind,&#8221; @kernelstub inquired.</p>
<p>&#8220;Ketty and some DMT,&#8221; Ellis replied, referring to the dissociative anesthetic <a href="https://en.wikipedia.org/wiki/Ketamine" target="_blank" rel="noopener">ketamine</a> and <a href="https://en.wikipedia.org/wiki/Dimethyltryptamine" target="_blank" rel="noopener">dimethyltryptamine</a> (DMT), a powerful psychedelic compound that is found naturally in some plants but is also synthetically produced in underground lab environments. &#8220;There&#8217;s a little 2cb so we might throw that in the mix,&#8221; he continued, referring to <a href="https://en.wikipedia.org/wiki/2C-B" target="_blank" rel="noopener">another psychedelic compound</a> by its chemical shorthand.</p>
<p>Roughly two weeks before his arrest, Ellis told KrebsOnSecurity he was ready to leave his life of crime behind and was prepared to turn himself in, but that in the meantime he was making plans to tie up loose ends.</p>
<p>Less than 24 hours later, the TeamPCP leader posted an image on Telegram showing a yellowish powdered substance in a baggie and on a scale, possibly synthetic DMT. The image shows the powder being weighed next to a series of small vape cartridges, two of which are open on the table in front of the photographer.</p>
<div id="attachment_74171" style="width: 759px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74171" class=" wp-image-74171" src="https://krebsonsecurity.com/wp-content/uploads/2026/08/teampcp-dmtmaybe.png" alt="" width="749" height="412" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/08/teampcp-dmtmaybe.png 1449w, https://krebsonsecurity.com/wp-content/uploads/2026/08/teampcp-dmtmaybe-768x423.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/08/teampcp-dmtmaybe-782x431.png 782w" sizes="(max-width: 749px) 100vw, 749px" /><p id="caption-attachment-74171" class="wp-caption-text">An image posted by the TeamPCP leader to Telegram, advertising his acquisition of some type of psychoactive substance, most likely a synthetic version of the powerful hallucinogen known as DMT.</p></div>
<p>The two defendants were arrested Wednesday morning. The AFP said the men face a combined 14 cybercrime offenses and are scheduled to appear in Perth Magistrates Court today.</p>
<p><strong>Charlie Eriksen</strong> is a security researcher at <strong>Aikido Security</strong> who has closely followed TeamPCP&#8217;s cybercrime campaigns. Eriksen said TeamPCP are a good example of a new kind of threat actor that does not fit neatly into the usual categories.</p>
<p>&#8220;They are not a state actor, not quite organized cybercrime, and not purely ideological,&#8221; he said. &#8220;Their motivations seem to mix money, disruption, attention, and ideology.&#8221;</p>
<p>Eriksen said that historically there has always been a meaningful gap between reading about an attack technique and being able to reliably turn it into an operational campaign, but that large language models (LLMs) and artificial intelligence increasingly are helping threat actors to bypass that knowledge gap.</p>
<p>&#8220;You had to understand the research, adapt the code, troubleshoot it, build infrastructure around it, and then repeat that process across different targets,&#8221; he said. &#8220;LLMs have compressed that gap significantly.&#8221;</p>
<p>According to Eriksen, this creates an environment where threat actors suddenly have the ability to operate at significant scale without having developed the operational discipline that traditionally accompanies that level of capability. Put another way, it sets the stage for cybercriminals who are capable enough to cause significant damage, but not necessarily careful enough to understand or care about the consequences.</p>
<p>&#8220;They can be noisy, they can make mistakes,&#8221; he said. &#8220;They can leave evidence everywhere. They can take risks that a professional criminal group or intelligence service would consider completely unacceptable. But that does not necessarily make them less dangerous. In some ways, it can make them more dangerous.&#8221;</p>
<p>In a recent <a href="https://www.aikido.dev/blog/shai-hulud-trusted-publishing" target="_blank" rel="noopener">blog post</a>, Eriksen called TeamPCP&#8217;s Shai-Hulud worm the &#8220;best thing to happen to supply chain security,&#8221; because it forced GitHub and other public coding platforms to erect new security safeguards.</p>
<p>In direct response to TeamPCP&#8217;s broad success at pushing poisoned versions of popular software packages, GitHub in late July introduced a <a href="https://github.blog/security/supply-chain-security/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates/" target="_blank" rel="noopener">three-day &#8220;cooldown&#8221; mechanism</a> for Dependabot, the platform&#8217;s tool for auto-fetching newly shipped updates for any package dependencies. Cooldown periods are designed to help buy time for security tools and package maintainers to identify and remove any compromised versions. Other coding ecosystems like Python and various JavaScript platforms <a href="https://cooldowns.dev/" target="_blank" rel="noopener">also added support</a> for cooldown periods this year amid growing calls from security experts about the need for more widespread adoption of the safety feature.</p>
<p>Eriksen said TeamPCP&#8217;s legacy is that they achieved in the span of a few months what the supply chain security community has been unable to do for years.</p>
<p>&#8220;They managed to wake up Microsoft to the fact that they had become negligent in terms of security,&#8221; Eriksen said. &#8220;By compromising GitHub and stealing their source code, they humiliated Microsoft into action, making them finally act on what we had been asking them to do and take seriously for a while now.&#8221;</p>
<p><strong>Update, 10:08 a.m. ET:</strong> A <a href="https://www.abc.net.au/news/2026-08-27/two-wa-men-charged-after-investigation-into-alleged-cybercrime/107084796" target="_blank" rel="noopener">story</a> this morning from <strong>ABC News</strong> in Australia confirms Ruben Ian Thomson of Cottesloe was one of the two arrested. The 23-year-old suspect thought to be @pcpcasper, Michael Gaebler, also was arrested in Perth. ABC News reports that Thomson was denied bail (Mr. Gaebler&#8217;s attorney reportedly did not request bail for his client), and that both men will be held in custody until their next court appearance on September 18.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/feed/</wfw:commentRss>
			<slash:comments>31</slash:comments>
		
		
			</item>
		<item>
		<title>Who&#8217;s Tracking You? Use This New Service to Find Out</title>
		<link>https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/</link>
					<comments>https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/#comments</comments>
		
		<dc:creator><![CDATA[BrianKrebs]]></dc:creator>
		<pubDate>Fri, 14 Aug 2026 11:24:35 +0000</pubDate>
				<category><![CDATA[A Little Sunshine]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Web Fraud 2.0]]></category>
		<category><![CDATA[AdBlock]]></category>
		<category><![CDATA[AdBlock Plus]]></category>
		<category><![CDATA[Alfa Bank]]></category>
		<category><![CDATA[Between Digital]]></category>
		<category><![CDATA[BitSight]]></category>
		<category><![CDATA[DecryptAds]]></category>
		<category><![CDATA[Fengwo Group]]></category>
		<category><![CDATA[Infoblox]]></category>
		<category><![CDATA[opera]]></category>
		<category><![CDATA[Pi-hole]]></category>
		<category><![CDATA[Raspberry Pi]]></category>
		<category><![CDATA[uBlock Origin]]></category>
		<category><![CDATA[Zach Edwards]]></category>
		<guid isPermaLink="false">https://krebsonsecurity.com/?p=74105</guid>

					<description><![CDATA[It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.]]></description>
										<content:encoded><![CDATA[<p>It can be daunting to determine who&#8217;s responsible for showing ads on the websites we visit, or who&#8217;s harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called <strong>DecryptAds</strong> scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.</p>
<div id="attachment_74134" style="width: 760px" class="wp-caption aligncenter"><a href="https://krebsonsecurity.com/wp-content/uploads/2026/08/decryptads-ESPN.png" target="_blank" rel="noopener"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74134" class="wp-image-74134" src="https://krebsonsecurity.com/wp-content/uploads/2026/08/decryptads-ESPN.png" alt="" width="750" height="443" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/08/decryptads-ESPN.png 1346w, https://krebsonsecurity.com/wp-content/uploads/2026/08/decryptads-ESPN-768x454.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/08/decryptads-ESPN-782x462.png 782w" sizes="(max-width: 750px) 100vw, 750px" /></a><p id="caption-attachment-74134" class="wp-caption-text">A Decryptads summary of the advertising partnerships declared by espn.com.</p></div>
<p>The <a href="https://decryptads.com/blog/posts/ad-tech-transparency-launch.html" target="_blank" rel="noopener">newly launched</a> <strong>decryptads.com</strong> says it is constantly scraping the files that websites and apps make publicly available to disclose the companies that are permitted to run ads or collect user data. These files include:</p>
<p>&#8211;<strong>ads.txt</strong>: all of the adtech companies and data brokers that may run ads or harvest data from the site;<br />
&#8211;<strong>app-ads.txt</strong>: entities that can harvest data from or display ads on mobile and smart TV apps;<br />
&#8211;<strong>buyers.json/sellers.json</strong>: the entities buying, selling or reselling ad inventory for a given site or app.</p>
<p><strong>Zach Edwards </strong>is chief research officer for DecryptAds and a threat researcher at the security company <strong>Infoblox</strong>. Edwards said he and two other founders decided the service was needed because the adtech data in these files is generally only useful when it can be cross-referenced to build a more complete picture of the advertising ecosystem for each website or app.</p>
<p>&#8220;It&#8217;s an adtech tool but we&#8217;re trying to approach adtech from a security perspective,&#8221; Edwards said. &#8220;It&#8217;s really built for a lot of privacy and security use cases that have been dramatically underserved.&#8221;</p>
<p>Those use cases, he said, include tracking down the source of malicious ads that try to foist malware on targeted users, identifying ad networks located in adversarial nations, and detecting the fast growing swarms of AI-generated slop websites and apps. And as decryptads.com demonstrates, these potential security and privacy threats are near impossible to detect just by viewing a single apps.txt or app-ads.txt file.</p>
<p>&#8220;Supply-chain integrity issues rarely live in a single file,&#8221; the site <a href="https://decryptads.com/blog/posts/analytical-features.html" target="_blank" rel="noopener">explains</a>. &#8220;They show up as broken cross-references between ads.txt, app-ads.txt, and sellers.json files; as cloned declaration sets across unrelated domains; as seller removals that only make sense when viewed across exchanges; and even as supply paths in bid logs that never actually appear in any given publisher’s authorized-seller list.&#8221;</p>
<p>A search in DecryptAds for the hugely popular sports network <strong>espn.com</strong> reveals 143 ad partners and 19 registered data broker domains are listed within its <a href="https://www.espn.com/ads.txt" target="_blank" rel="noopener">ads.txt</a> and <a href="https://www.espn.com/app-ads.txt" target="_blank" rel="noopener">app-ads.txt</a> files. That data broker information is gradually becoming available because four states &#8212; California, Oregon, Texas and Vermont &#8212; have recently passed laws requiring data brokers to register if they buy or sell data on consumers from those states. DecryptAds reports that almost half of those data brokers are collecting geolocation data from espn.com visitors who aren&#8217;t blocking ads, while another three disclose that they collect device fingerprints and sensitive personal information.</p>
<div id="attachment_74131" style="width: 760px" class="wp-caption aligncenter"><a href="https://krebsonsecurity.com/wp-content/uploads/2026/08/espn-supplychain.png" target="_blank" rel="noopener"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74131" class="wp-image-74131" src="https://krebsonsecurity.com/wp-content/uploads/2026/08/espn-supplychain.png" alt="" width="750" height="230" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/08/espn-supplychain.png 1790w, https://krebsonsecurity.com/wp-content/uploads/2026/08/espn-supplychain-768x236.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/08/espn-supplychain-1536x472.png 1536w, https://krebsonsecurity.com/wp-content/uploads/2026/08/espn-supplychain-782x240.png 782w" sizes="(max-width: 750px) 100vw, 750px" /></a><p id="caption-attachment-74131" class="wp-caption-text">A visual representation of the complex ad supply chain declared by espn.com. Image: decryptads.com.</p></div>
<h2>HIGH-RISK AD PARTNERS</h2>
<p>DecryptAds also makes it easy to learn the beneficiaries and national origins of the advertising firms lurking in apps and websites, displaying a conspicuous warning when adtech partners of an app or website are based in <a href="https://decryptads.com/geo_risk" target="_blank" rel="noopener">&#8220;geo-risk&#8221;</a> areas like China and Russia, or in countries with strong financial and political ties to both &#8212; such as Cyprus and the United Arab Emirates (UAE).</p>
<p>According to DecryptAds, espn.com works with four different advertising entities that are based in either Russia, China or the UAE, including the adtech firm <strong>Between Digital</strong>, which lists a New York address. However, the <a href="https://decryptads.com/ad_system/betweendigital.com" target="_blank" rel="noopener">dossier on Between Digital</a> flags them as a Russian firm, showing that <a href="https://cp.betweendigital.com/files/PublisherOffer.pdf" target="_blank" rel="noopener">their publisher offers</a> (PDF) are processed through <strong>Alfa Bank</strong>, Russia&#8217;s largest private commercial bank and one of several financial institutions placed under U.S. sanctions in 2022 after Russia invaded Ukraine. KrebsOnSecurity sought comment from both Between Digital and the company&#8217;s founder, and will update this story in the event that either replies.</p>
<p>A search for several top U.S. military news websites &#8212; including <a href="https://decryptads.com/search/publisher/armytimes.com" target="_blank" rel="noopener">armytimes.com</a>, <a href="https://decryptads.com/publisher/airforcetimes.com" target="_blank" rel="noopener">airforcetimes.com</a>, <a href="https://decryptads.com/publisher/defensenews.com" target="_blank" rel="noopener">defensenews.com</a>, <a href="https://decryptads.com/publisher/navytimes.com" target="_blank" rel="noopener">navytimes.com</a>, <a href="https://decryptads.com/publisher/marinecorpstimes.com" target="_blank" rel="noopener">marinecorpstimes.com</a> and <a href="https://decryptads.com/publisher/federaltimes.com" target="_blank" rel="noopener">federaltimes.com</a> &#8212; shows they all allow Between Digital to serve ads and track users, as well as two entities in the UAE and another in the ownership secrecy haven of Panama. DecryptAds reports that Between Digital is collecting ad data on approximately 55,000 partner websites.</p>
<div id="attachment_74140" style="width: 758px" class="wp-caption aligncenter"><a href="https://krebsonsecurity.com/?attachment_id=74140" target="_blank" rel="noopener"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74140" class="wp-image-74140" src="https://krebsonsecurity.com/wp-content/uploads/2026/08/decryptads-georisk.png" alt="" width="748" height="374" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/08/decryptads-georisk.png 1750w, https://krebsonsecurity.com/wp-content/uploads/2026/08/decryptads-georisk-768x384.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/08/decryptads-georisk-1536x769.png 1536w, https://krebsonsecurity.com/wp-content/uploads/2026/08/decryptads-georisk-782x391.png 782w" sizes="(max-width: 748px) 100vw, 748px" /></a><p id="caption-attachment-74140" class="wp-caption-text">The &#8220;Geo Risk&#8221; section of decryptads.com.</p></div>
<p>Pivoting on Between Digital&#8217;s <a href="https://decryptads.com/ad_system_sites/betweendigital.com/app_ads_txt/all" target="_blank" rel="noopener">app-ads.txt file</a> reveals hundreds of domains featuring simple web-based games that are frequently interrupted by ads. Edwards said Between Digital&#8217;s own declarations show the company is listed as both a publisher and a reseller on approximately two-thirds of their portfolio.</p>
<p>&#8220;It means they are basically playing both sides of the bidding equation, which creates opportunities to direct client spend at your owned and operated properties or client infrastructure, essentially creating opportunities for conflicts of interest,&#8221; Edwards told KrebsOnSecurity. &#8220;The problem we have right now is that for years we&#8217;ve had almost no one policing these ads.txt and app-ads.txt files.&#8221;</p>
<p>The <strong>Opera</strong> Web browser remains quite popular, and probably many users are unaware that since 2016 it has been majority owned and controlled by the Chinese company Kunlun Tech (the operational headquarters of Opera remain in Oslo, Norway).</p>
<p>Opera.com&#8217;s <a href="https://decryptads.com/search/ad_system/opera.com" target="_blank" rel="noopener">profile at DecryptAds</a> identifies 27 registered data brokers collecting information, including 15 adtech partners in the UAE, six in China, three in Cyprus, two in Russia and one each in Hong Kong and Ukraine. DecryptAds makes clear, however, that these companies represent just seven percent of the adtech partners specified in Opera.com&#8217;s ads.txt and app-ads.txt files.<span id="more-74105"></span></p>
<h2>LEGAL DOSSIERS</h2>
<p>One feature of DecryptAds that sent this author down multiple hours-long research rabbit holes is its <a href="https://decryptads.com/legal_dossier" target="_blank" rel="noopener">Legal Dossier lookup</a>, which takes several minutes for each search but eventually churns out oodles of useful information about who owns a particular domain or app, when it was registered, and any aliases or relationships it may have to adtech companies and other websites or apps.</p>
<p>For example, last month KrebsOnSecurity wrote about researchers from <strong>Bitsight</strong> who found that an extremely popular line of TV streaming sticks called <strong>H96</strong> quietly rent out each user&#8217;s Internet connection to strangers. Bitsight also discovered that when these devices aren&#8217;t being used to stream pirated video content, they <a href="https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/" target="_blank" rel="noopener">are spoofing themselves as mobile phones clicking ads on AI-generated slop websites</a>.</p>
<p>Bitsight concluded that the same Chinese company that made several of the malicious apps common to all of these H96 streaming sticks &#8212; the <strong>Fengwo Group</strong> &#8212; also also ran the network of ads and AI slop websites being clicked on by tens of thousands of these devices that are pretending to be mobile phones.</p>
<div id="attachment_74063" style="width: 760px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74063" class=" wp-image-74063" src="https://krebsonsecurity.com/wp-content/uploads/2026/07/fengwogroupwebsites.png" alt="" width="750" height="229" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/07/fengwogroupwebsites.png 967w, https://krebsonsecurity.com/wp-content/uploads/2026/07/fengwogroupwebsites-768x234.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/07/fengwogroupwebsites-782x239.png 782w" sizes="(max-width: 750px) 100vw, 750px" /><p id="caption-attachment-74063" class="wp-caption-text">Examples of ad landing pages linked to the Fengwo Group. These sites were designed to show ads only to H96 devices that were spoofing their device type as mobile phones. Image: Bitsight.</p></div>
<p>A DecryptAds legal dossier on the (now dormant) Fengwo Group domain name for the AI slop website pictured on the left in the screenshot above (<a href="https://decryptads.com/search/publisher/medicalbeautyhub.com" target="_blank" rel="noopener">medicalbeautyhub dot com</a>) shows it shares a seller ID (<a href="https://decryptads.com/seller_id/1674071" target="_blank" rel="noopener">1674071</a>) with a gaming website &#8212; <a href="https://decryptads.com/publisher/giacoloredstones.com" target="_blank" rel="noopener">giacoloredstones[.]com</a> &#8212; which features yet another seller ID (<a href="https://decryptads.com/seller_id/103488000" target="_blank" rel="noopener">103488000</a>).</p>
<p>Pivoting on that latter seller ID reveals hundreds of active websites within Russia&#8217;s <strong>Yandex</strong> ad system featuring extremely low-quality games or simple utilities that pepper visitors with ads.</p>
<h2>QUIET REMOVALS</h2>
<p>Edwards said that when advertising networks suspect a given advertiser is engaged in unauthentic clicks or displaying malicious ads, very often those networks will quietly remove the offender from their list of approved partners without letting anyone else know about their suspicions.</p>
<p>This practice, he said, makes it easier for dodgy adtech firms to avoid accountability and continue victimizing others. To address that visibility gap, DecryptAds features a <a href="https://decryptads.com/quiet_removals_feed" target="_blank" rel="noopener">quiet removals feed</a> that records and correlates all of the sellers.json removals across ad exchanges for the same seller domain or name.</p>
<div id="attachment_74132" style="width: 760px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74132" class=" wp-image-74132" src="https://krebsonsecurity.com/wp-content/uploads/2026/08/quietremovalsfeed.png" alt="" width="750" height="471" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/08/quietremovalsfeed.png 1411w, https://krebsonsecurity.com/wp-content/uploads/2026/08/quietremovalsfeed-768x483.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/08/quietremovalsfeed-782x492.png 782w" sizes="(max-width: 750px) 100vw, 750px" /><p id="caption-attachment-74132" class="wp-caption-text">A screenshot of the Quiet Removals Feed at decryptads.com.</p></div>
<p>&#8220;The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won&#8217;t make it public,&#8221; Edwards said. &#8220;The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone. So if you&#8217;re trying to navigate who is suspicious, that&#8217;s usually tough to do because there are a lot of adtech companies removing things all at once.&#8221;</p>
<h2>MALVERTISING AND AI SLOP</h2>
<p>Malvertising, the term given to the practice of inserting malicious ads that foist malware or redirect visitors to phishing pages, remains an all-too-frequent occurrence in the modern adtech industry. But Edwards said these malicious ads are far more commonly found now on newly generated AI slop websites than on high traffic destinations that typically employ a variety of technologies and third party tools to quickly flag bad ads.</p>
<p>&#8220;None of these slop AI content farms are paying for that kind of protection,&#8221; he said. &#8220;They&#8217;re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads. Most malvertising attacks don&#8217;t happen on espn.com or huffpost.com, but rather [on] some lower quality content farm and someone just went there because it came up in a search.&#8221;</p>
<p>Edwards said the AI slop websites are populated with machine-generated blog posts and images, and cover a wide array of themes from home improvement and decorating to food recipes, hunting, cars and consumer technology. He said organizations that get hit with malicious ads are often at a loss for what to do next, unaware that in most cases the answer is one of the entities listed inside the website&#8217;s ads.txt or app-ads.txt file.</p>
<p>&#8220;A lot of serious organizations are starting to understand that if we&#8217;re not breaking down this ad data, we&#8217;re not going to know who&#8217;s targeting government people with zero-click payloads on an almost daily basis,&#8221; he said.</p>
<p>Edwards maintains that truly getting a handle on the malvertising and AI slop problems will require more data-sharing by the major ad networks. Specifically, he says those platforms do not broadly share what&#8217;s known as the &#8220;supply chain object&#8221; or SCO, structured data attached to each advertising bid request that lets buyers see every seller, reseller and intermediary involved in passing an ad impression from the publisher to the final buyer.</p>
<p>&#8220;That SCO tells you who sold it or resold it, and who was the final entity that bought the impression that served that malware payload,&#8221; Edwards explained. &#8220;You may see the malicious zero-click redirection, but without the supply chain object &#8212; which is only served server side &#8212; you won&#8217;t know who targeted your people with malware and won&#8217;t have a way to try and prevent it properly. But if we can encourage the adtech industry to expose that SCO, it will get easier to find the culprit behind any one bad ad.&#8221;</p>
<p>DecryptAds also offers an application programming interface (API) that allows researchers to automate queries and integrate the site&#8217;s functionality into popular AI platforms.</p>
<h2>WHAT CAN YOU DO?</h2>
<p>The only sane reaction to the examples described above is to block all online ads outright. This approach is broadly endorsed by security experts because it also makes it more difficult for adtech firms and data brokers to build detailed profiles on you and track your movements around the web and in the real world.</p>
<p>However, much depends on how you normally prefer to browse the Internet, and how much trust you place in third party browser plugins and extensions. For those primarily surfing via a regular desktop or laptop Web browser, <strong>uBlock Origin Lite</strong> is an excellent free and well-maintained open source option. uBlock Origin also should work with mobile browsers like Firefox, but apparently only on Android-based devices.</p>
<p><strong>Adblock Plus</strong> is a decent option for <strong>iPhone</strong> and <strong>iPad</strong> users. For power users, Adblock and uBlock Origin both support custom blocking rules from <a href="https://easylist.to/" target="_blank" rel="noopener">easylist.to</a>, which publishes a frequently updated list that removes most advertisements from webpages.</p>
<p>The well established browser extension <strong>NoScript</strong> blocks all non-approved Javascript code, and it generally does a fine job blocking most ads from loading. However, script blockers like NoScript may not be suitable for average users who don&#8217;t enjoy constantly having to referee which scripts should be allowed to load so that each site displays properly.</p>
<p>More technically inclined/adventuresome readers should strongly consider a hardware approach to blocking ads at the local network level, because that is easily the cheapest, most secure and scalable way to do it. A tiny, low-cost and broadly available computer known as a <strong>Raspberry Pi</strong> can be turned into <a href="https://www.raspberrypi.com/tutorials/running-pi-hole-on-a-raspberry-pi/" target="_blank" rel="noopener">a powerful ad blocker for all devices on a local network</a> when fitted with a microSD memory card and a free program called <a href="https://github.com/pi-hole/pi-hole" target="_blank" rel="noopener"><strong>Pi-hole</strong></a>. Once you&#8217;ve set it up properly and changed your router&#8217;s network settings to use the Pi-hole&#8217;s DNS sinkhole and DHCP servers, it should prevent ads from displaying on any devices connected to that network.</p>
<p>Bear in mind that ad blockers often do little to block ads and/or tracking that occurs from within mobile apps that users have chosen to install on their devices. Many websites now push users to install a mobile app, supposedly in order to more fully access and enjoy the site&#8217;s services and content. But in my experience, they&#8217;re not doing this because the user experience is somehow way better on the app (as LinkedIn tries to convince us non-app users several times a week via email). On the contrary, I find most mobile apps to be horribly designed, annoying, and/or completely unnecessary, and when given the option I will almost always choose to interact with a website or service directly in a Web browser.</p>
<p>No, the cold truth is that big web destinations tend to get pushy with their apps because they make it easier for these companies to keep you on their platforms longer and to collect (and in many cases resell) <a href="https://krebsonsecurity.com/2024/10/the-global-surveillance-free-for-all-in-mobile-ad-data/" target="_blank" rel="noopener">far more precise data</a> about who, what and where their users are. Also, companies pushing customers the hardest to install mobile apps always seem to liberally opt everyone in to having their data used to train large language models these days. So be cautious about the apps you install on your mobile devices (<a href="https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/" target="_blank" rel="noopener">including any smart TVs!</a>), and poke around their listings at DecryptAds if you want to learn more about their privacy practices and any relationships they may have to adtech firms.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/feed/</wfw:commentRss>
			<slash:comments>50</slash:comments>
		
		
			</item>
		<item>
		<title>Microsoft Plugs Nearly 400 Security Holes</title>
		<link>https://krebsonsecurity.com/2026/08/microsoft-plugs-nearly-400-security-holes/</link>
					<comments>https://krebsonsecurity.com/2026/08/microsoft-plugs-nearly-400-security-holes/#comments</comments>
		
		<dc:creator><![CDATA[BrianKrebs]]></dc:creator>
		<pubDate>Tue, 11 Aug 2026 21:28:35 +0000</pubDate>
				<category><![CDATA[Latest Warnings]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Time to Patch]]></category>
		<category><![CDATA[1Password]]></category>
		<category><![CDATA[afd.sys]]></category>
		<category><![CDATA[Automox]]></category>
		<category><![CDATA[CVE-2026-62832]]></category>
		<category><![CDATA[CVE-2026-68820]]></category>
		<category><![CDATA[CVE-2026-72971]]></category>
		<category><![CDATA[Ed Skoudis]]></category>
		<category><![CDATA[Landon Miles]]></category>
		<category><![CDATA[Microsoft Patch Tuesday August 2026]]></category>
		<category><![CDATA[Nightmare Eclipse]]></category>
		<category><![CDATA[SANS Technology Institute]]></category>
		<guid isPermaLink="false">https://krebsonsecurity.com/?p=74106</guid>

					<description><![CDATA[Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.]]></description>
										<content:encoded><![CDATA[<p><strong>Microsoft</strong> today released updates to remedy at least 398 security vulnerabilities in its <strong>Windows</strong> operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.</p>
<div id="attachment_74109" style="width: 758px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-74109" class=" wp-image-74109" src="https://krebsonsecurity.com/wp-content/uploads/2026/08/workingonpc.png" alt="" width="748" height="531" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/08/workingonpc.png 649w, https://krebsonsecurity.com/wp-content/uploads/2026/08/workingonpc-100x70.png 100w" sizes="(max-width: 748px) 100vw, 748px" /><p id="caption-attachment-74109" class="wp-caption-text">Image: Shutterstock, Mallika Home Studio.</p></div>
<p>August&#8217;s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of <a href="https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/" target="_blank" rel="noopener">more than 570 security updates last month</a>, but it is double June&#8217;s then-record batch of <a href="https://krebsonsecurity.com/2026/06/a-record-breaking-patch-tuesday-for-june-2026/#more-73788" target="_blank" rel="noopener">nearly 200 fixes</a>. Microsoft has attributed the recent patch deluge to vulnerability discoveries aided by artificial intelligence, and experts roundly agree that Windows users should get used to the idea of Patch Tuesdays (the second Tuesday of each month) covering hundreds of newly discovered security flaws.</p>
<p>Fully 42 of the 398 flaws that Microsoft patched today earned Redmond&#8217;s most-dire &#8220;critical&#8221; rating, meaning they are severe enough that malware or malcontents could exploit them to gain remote control over a Windows computer with little to no help from the user.</p>
<p>The sole known &#8220;zero day&#8221; bug fixed by Microsoft this month is <a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68820" target="_blank" rel="noopener">CVE-2026-68820</a>, a privilege escalation weakness in a core Windows component called <strong>afd.sys</strong>, which the security firm <strong>Automox</strong> describes as &#8220;the driver behind Windows socket connections on effectively every endpoint.&#8221;</p>
<p>&#8220;This isn&#8217;t a front-door bug,&#8221; Automox&#8217;s <strong>Landon Miles</strong> <a href="https://www.automox.com/blog/patch-fix-tuesday-august-2026" target="_blank" rel="noopener">wrote</a> in a Patch Tuesday blog post. &#8220;It&#8217;s step two in a chain: an attacker phishes their way into a low-privilege foothold, then uses the driver flaw to take the box. The 7.0 score reflects the high attack complexity, because race conditions are fiddly. The exploit has to be thrown over and over until the timing lands. Someone is clearly landing it anyway.&#8221;</p>
<p><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-62832" target="_blank" rel="noopener">CVE-2026-62832</a> is another privilege escalation flaw that Microsoft has labeled likely to be exploited; this flaw, in the Windows User Profile Service, may be related to the recent <a href="https://www.theregister.com/security/2026/07/15/microsofts-serial-tormentor-drops-legacyhive-0-day/5271723" target="_blank" rel="noopener">&#8220;LegacyHive&#8221; public disclosure</a> from the prolific bug hunter known as <strong>Nightmare Eclipse</strong>. The other publicly disclosed flaw is <a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72971" target="_blank" rel="noopener">CVE-2026-72971</a>, a low-impact local tampering vulnerability that Microsoft reckons is unlikely to be exploited.<span id="more-74106"></span></p>
<p>Other major software makers are likewise increasing their patch volumes and cadence thanks to AI, including <strong>Adobe</strong> which last month moved to twice-monthly security bulletins published on the 2nd and 4th Tuesday of each month. <strong>Cisco</strong>, <strong>Google</strong>, <strong>Mozilla</strong> and <strong>Oracle</strong> also are shipping updates far more frequently and abundantly.</p>
<p>By all accounts, AI is quite good at finding security holes in software. But for now at least, patching the resulting bugpocalypse remains a heavily human-centric endeavor, and the jury is still out on whether AI technologies will turn out to be as good at fixing vulnerabilities as they are at finding and exploiting them. This is an important question when one considers that these same AI technologies also are suggesting fixes for the vulnerabilities they find.</p>
<p>Researchers at <strong>1Password</strong> recently <a href="https://1password.com/blog/why-ai-generated-patches-still-require-human-review" target="_blank" rel="noopener">examined</a> what happens when different large language models (LLMs) generate vulnerability patches for newly disclosed, complex vulnerabilities. They found the LLMs produced patches that failed to fix the flaw or added a new weakness in the process (or both) more than half the time.</p>
<p><strong>Ed Skoudis</strong>, president of the <strong>SANS Technology Institute</strong>, said his team has seen excellent results using AI to generate patches, provided there are humans in the loop to test the suggested fixes and push for iterative improvements.</p>
<p>&#8220;AI is rapidly becoming astonishingly good at finding vulnerabilities, but this research shows that fixing them is a very different problem,&#8221; Skoudis wrote in a SANS newsletter today. &#8220;Don&#8217;t expect one-shot AI patching to work reliably. Instead, iterate, test, challenge, improve, and verify. AI can be an extraordinary patching partner, but today it still needs a skilled human at the keyboard.&#8221;</p>
<p><strong>Tyler Reguly</strong> at <strong>Fortra</strong> says while reports of Microsoft patching hundreds of vulnerabilities in one go have prompted some organizations to try to patch faster, it&#8217;s important to bear in mind that only one of the almost 400 bugs addressed today is known to be actively exploited. Reguly suggested security leaders check in with their teams to see how they&#8217;re handling the increasing workloads, which often involve testing fixes before deploying them in production environments.</p>
<p>&#8220;If you&#8217;re a chief security officer talk to your teams about how they are shifting or modifying their workflows to better accommodate the patching shift that we&#8217;re seeing and support them across various organizational units by enabling the changes they want to see made,&#8221; Reguly said. &#8220;There’s no need to rush these updates, no matter what various vendors and organizations try to tell you. You need to make sure that you are rolling out safe updates that will not negatively impact your systems.&#8221;</p>
<p>Speaking of the humans behind the keyboards, don&#8217;t neglect to backup your system and/or data before applying this month&#8217;s monster patch load. The day after each month&#8217;s Patch Tuesday is sometimes derisively referred to as Reboot Wednesday, but it generally doesn&#8217;t hurt to wait a few days to apply these huge update bundles because it sometimes takes a couple of days for the occasional misbehaving patch to get ironed out properly by Microsoft.</p>
<p>For a clickable, per-patch breakdown by severity and urgency, check out <a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20August%202026/33236" target="_blank" rel="noopener">this roundup</a> from the SANS Internet Storm Center.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://krebsonsecurity.com/2026/08/microsoft-plugs-nearly-400-security-holes/feed/</wfw:commentRss>
			<slash:comments>30</slash:comments>
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Object Caching 19/21 objects using Memcached
Page Caching using Memcached 
Database Caching using Memcached

Served from: krebsonsecurity.com @ 2026-10-10 17:52:33 by W3 Total Cache
-->