الوسم: cybercrime

  • US Turns to Private ‘Pirates’ in Bold Cybercrime Fight

    US Turns to Private ‘Pirates’ in Bold Cybercrime Fight

    A hooded man is depicted gripping a laptop computer, with cyber code projected onto him in this illustrative image — Reuters

    The U.S. is set to permit private companies to hack foreign cybercriminal groups, a move that’s sparking debate among experts. This initiative, seemingly without precedent, could either succeed or lead to chaos.

    On Wednesday, President Donald Trump issued a memorandum instructing the Justice and Homeland Security departments to authorize certain American companies to monitor and target international criminal organizations.

    The White House justified this stance by highlighting the substantial damage caused by ransomware, sextortion, and online fraud, which reportedly cost Americans over $20 billion in 2025.

    The directive allows private entities to take actions such as dismantling hackers’ servers or deploying spyware to infiltrate their systems. All operations will require prior government approval, and companies must post a security bond of at least $1 million.

    Activities that could result in death or injury are off-limits, as are any actions that would constitute “use of force” under international law.

    This approach resembles 18th-century privateering, where governments authorized private ships and sailors to raid enemy vessels. Ari Redbord, a former federal prosecutor now working at TRM Labs, explains, “The private sector controls the data, and the government holds the authority. This memorandum combines both.”

    Redbord sees a historical parallel in maritime privateering, noting, “Back then, once a ship left port, oversight was impossible. Today, technology allows continuous oversight from start to finish.”

    However, some experts express skepticism. University of Surrey cybersecurity professor Alan Woodward notes, “You can grant a commission, but obedience isn’t guaranteed. Historically, privateering was eventually considered problematic because it became more trouble than it was worth.”

    The memo marks a change in the White House’s stance. Previously, a senior U.S. official in March suggested the U.S. wasn’t interested in fighting cybercriminals with cybercriminals. Still, within five months, the administration reversed course.

    Columbia University researcher and former cybersecurity official Jason Healey sees some safeguards, stating, “They’re supporting this under the rule of law, so I don’t see it as reckless.” Yet, he cautions, “The current administration has systematically weakened agencies like the Office of the Director of National Intelligence that are supposed to oversee such actions.”

    Major U.S. tech companies already invest heavily in cybersecurity. The new program could extend their capabilities, enabling operations without judicial oversight, relying solely on government approval. Microsoft declined to comment, and Google did not respond to requests for comment.

    Redbord warns that companies engaging in government-sanctioned hacking could lose their neutrality and become targets themselves.

    The White House has 60 days to finalize the program’s specifics, though some details will remain classified. Its ultimate success or failure remains uncertain.

    Over time, Washington will need to weigh the program’s costs against potential benefits, such as the risk of misattributions, foreign prosecutions, and diplomatic issues, as Woodward points out.

    Cybercrimes continue to grow despite these efforts. Redbord emphasizes that, ultimately, unless victims recover their funds, most of the other concerns are secondary.

  • UN: Crime Gangs Steal Over $88B in Asia-Pacific Scams

    UN: Crime Gangs Steal Over $88B in Asia-Pacific Scams

    In 2025, scam operations in Asia-Pacific caused losses estimated between $88.3 billion and $114.1 billion, according to a United Nations agency. These criminal groups are continuously refining their methods to evade law enforcement, leveraging artificial intelligence, exploiting corruption, and diversifying their sources of income. Southeast Asia, largely dominated by Chinese-origin cyberfraud networks, has become a hotspot for these activities, with schemes expanding across borders and sharing resources across various illegal markets.

    Such networks resemble corporate franchises, featuring specialized departments for money laundering, human trafficking, migrant smuggling, and data harvesting, all interconnected through service-based systems. Scam centers operate illegal online platforms that defraud individuals worldwide and often employ trafficked foreign nationals under oppressive conditions.

    People from over 80 countries and territories are believed to be involved in scam operations across the region. Recruitment networks utilize transit hubs in Asia, the Middle East, and Africa to attract foreign recruits, targeting those with skills in major European and American languages. Despite increased law enforcement pressures leading to relocations of these illicit operations, gangs continue to shift to regions with weaker governance, such as East Timor, Pacific islands, and parts of Africa.

    These syndicates often engage in “jurisdiction shopping,” choosing areas with minimal oversight, facilitated by corruption, which remains the primary enabler of sophisticated tech-driven organized crime in the area. Criminal organizations are expected to increasingly utilize autonomous AI systems to identify victims, conduct social engineering, and facilitate cybercrimes like cryptocurrency theft and laundering. This rapidly expanding illegal ecosystem also encompasses money laundering services, underground banking, and data trading.

    The scope and complexity of this organized crime economy are surpassing current responses, which are not equipped to handle such advanced activities, according to UNODC analysts.

  • Your Smart Home Devices Might Be Part Of A Cybercrime Network

    Your Smart Home Devices Might Be Part Of A Cybercrime Network

    Smart home gadgets and devices are now a common feature in many contemporary households. Security cameras monitor front doors, streaming devices power up TVs, and connected appliances continuously share data over the internet. While many people are concerned about corporations gathering too much personal information, a rising cybersecurity threat indicates that consumers might face an even larger problem.

    Security experts are warning that some internet-connected devices may harbor hidden software backdoors or critical security vulnerabilities that could allow outside parties to access home networks. In certain cases, these devices can covertly transform a household’s internet connection into a tool for cybercriminals without the homeowner’s awareness.

    How compromised smart devices are being exploited

    Many of these compromised devices are connected to what are known as residential proxy networks. These services reroute internet traffic through actual household connections, making online activities appear as if they originate from an ordinary home rather than a data center, VPN, or suspicious network.

    While residential proxies serve legitimate purposes, such as testing websites or ads from different regions, problems arise when consumers unknowingly become part of these networks.

    According to a recent Wall Street Journal investigation, some digital picture frames and streaming media players appeared to contain software that automatically connected them to residential proxy services. Experts interviewed in the report believe certain manufacturers might be paid to embed this software before the devices reach consumers.

    Once connected, these devices can silently transmit internet traffic for third parties. Monitoring of several test units revealed activity linked to gambling sites, cryptocurrency platforms, adult content, and online account access attempts.

    Why this presents a concern for users

    Having strangers route traffic through your home internet creates significant privacy and security risks. Malicious actors using a household’s connection can make it look like the house itself is involved in illegal activity. Security experts associate these networks with fraud, ticket scalping, ad fraud, and unauthorized account usage.

    The risk escalates further when cybercriminals gain direct control over vulnerable devices. Evidence shows hackers repeatedly attempt to access internet-connected gadgets, sometimes turning them into parts of massive botnets used to orchestrate distributed denial-of-service attacks (DDoS). Industry estimates suggest tens of millions, possibly hundreds of millions, of devices worldwide could be at risk.

    Steps you can take to safeguard yourself

    Individuals can lower their risk by purchasing devices from trusted manufacturers, regularly updating device firmware, and steering clear of suspiciously cheap products from unknown brands. Experts also advise avoiding unverified apps and sideloaded software, as these can introduce malware into your smart devices. Placing smart home devices on a separate guest network can help contain potential damage if a device becomes compromised and prevent hackers from accessing your phones, laptops, or other sensitive gadgets on the same network.

  • Hackers $2.5M Breach Targets Sri Lanka Finance Ministry

    A cyber attack has compromised Sri Lanka’s finance ministry computer network, resulting in the theft of $2.5 million. The government announced this on Thursday, marking the largest amount ever stolen from a government agency in the country, which is heavily burdened by debt.

    This breach is a severe setback for Sri Lanka, which has been struggling to recover from a severe economic crisis in 2022 after defaulting on $46 billion in external debt.

    The funds taken were meant for debt repayment to Australia, according to Harshana Suriyapperuma, the secretary of the finance ministry, who spoke to reporters in the capital.

    Following the breach, four senior officials at the Public Debt Management Office (PDMO) were suspended.

    Authorities detected an unauthorized attempt to access the ministry’s email server, and subsequent investigation revealed that a payment of $2.5 million owed to Australia had gone missing.

    “Investigators are examining the situation, and we can’t share further details at this moment,” Suriyapperuma stated. He also mentioned that Sri Lankan officials are seeking assistance from international law enforcement agencies.

    The PDMO was established earlier this year as part of Sri Lanka’s response to its economic turmoil, aided by an IMF-approved bailout package totaling $2.9 billion issued in early 2023.

    Matthew Duckworth, Australia’s High Commissioner to Sri Lanka, confirmed that Canberra was aware of “irregularities” concerning payments it was owed.

    “Authorities in Sri Lanka are investigating and coordinating with Australian officials, who are assisting with the inquiry,” Duckworth added on social media platform X.

    He reaffirmed Australia’s commitment, emphasizing ongoing support for Sri Lanka’s efforts to restore debt sustainability.

    Earlier this year, Sri Lanka’s central bank and finance ministry launched a campaign in local newspapers warning residents about cyber scams, likely in response to the increasing digital threats facing the country.

  • Pakistanis among hundreds fleeing to Thailand after Myanmar scam bust

    Pakistanis among hundreds fleeing to Thailand after Myanmar scam bust

    Almost 700 foreigners, including Pakistanis, have escaped Myanmar and crossed into Thailand, according to the Thai military. This surge follows a military operation targeting KK Park, a well-known cybercrime hub.

    Thailand has detained 677 individuals—618 men and 59 women—who entered Tak province at the border. The military stated that Myanmar’s armed forces have taken control of KK Park and are conducting inspections in the area, which has prompted many residents to flee into Thailand.

    The Thai authorities are processing these arrivals legally and are screening them thoroughly. Extra detention centers have been prepared in case current facilities become overcrowded, the military added.

    A video from Thai PBS captured on October 22, 2025, and shared with AFP shows people crossing the Moei River near KK Park from Myanmar into Thailand. The area is recognized internationally for its involvement with cyber scams.

    KK Park’s expansive complex is primarily operated by Chinese criminal groups, with local militia factions aligned with Myanmar’s military guards. The border zones among Thailand, Myanmar, Laos, and Cambodia have become hotspots for online scam operations since the COVID-19 pandemic began. The United Nations reports that billions of dollars have been generated from trafficking hundreds of thousands of people forced to work in these illicit scam factories.

  • Egyptian TikTok Star Suzy El Ordoneya Arrested in Major Money Laundering Case

    Egyptian TikTok Star Suzy El Ordoneya Arrested in Major Money Laundering Case

    Digital Phablet – TikTok star Suzy El Ordoneya detained over money laundering allegations.

    Also Read: Why TikToker Modahm was detained in Egypt—The shocking reason will surprise you
    The Ministry of Interior announced the detention of content creator “Suzy El Ordoneya,” also known as “Maryam A,” as part of a major crackdown on cybercrime and money laundering activities. The investigation linked her to large-scale laundering schemes generated from illegal online activities on social media platforms, particularly TikTok.

    Legal Penalties for Money Laundering

    Attorney Noha El-Gendy clarified in a statement to “News Room” that under Egyptian law, individuals convicted of money laundering face imprisonment for up to seven years and a fine of no less than five million Egyptian pounds, or the amount equivalent to the laundered funds, whichever is greater.

    Instagram — sozy__ayman1

    El-Gendy further noted that the penalties are applicable if the origins of the funds are unknown or obtained through unlawful means. Authorities are also empowered to freeze, seize assets, and return them to the state or relevant parties in accordance with legal procedures.

    Details of the Investigation

    The Anti-Money Laundering and Organized Crime Sector provided detailed insights into the case. Security officials revealed that the accused accumulated nearly 15 million Egyptian pounds through inappropriate and illicit content that violated public morals and social norms. Law enforcement was able to trace the source of the funds generated from her online activities.

    According to their findings, Suzy El Ordoneya attempted to conceal the true origin of her earnings by purchasing residential properties and using them ostensibly for legitimate purposes.

    Behaviors and Social Media Activity

    The Ministry of Interior stated that the suspect maintained social media accounts where she posted videos that blatantly went against societal morals and norms in an effort to illegally amass significant wealth.

    While she was being referred to investigative authorities, legal proceedings were initiated against Suzy El Ordoneya. Authorities continue to pursue individuals engaging in online activities that threaten societal stability or infringe on fundamental social principles.

    Instagram post example

    According to reports, her illicit earnings totaling nearly 15 million Egyptian pounds stemmed from content deemed immoral and offensive by societal standards. The authorities were able to track her financial trail back to her online content.

    The investigation continues, and security forces remain committed to targeting online activities that undermine social order and safety. Anyone involved in such unlawful online behavior is subject to arrest and prosecution under Egyptian law.

  • Ransomware Became Hackers’ Choice in 2024 for Quick Attacks

    Ransomware Became Hackers’ Choice in 2024 for Quick Attacks

    A recent research study has revealed a troubling trend: ransomware attacks are not only increasing in frequency but are also being executed at an unprecedented speed. Experts indicate that malicious actors are launching attacks even quicker than security teams can address them.

    Ransomware-as-a-service is a prevalent method used by cybercriminals, offering a variety of harmful tools and services to customers on a subscription basis. The latest comprehensive analysis from the Barracuda Managed XDR team indicates that the number of ransomware assaults in 2024 surged fourfold compared to the previous year.

    2024 Cyberattacks statistics by Barracuda Managed XDR.
    Barracuda Managed XDR

    In their investigation, researchers analyzed 11 trillion IT events in 2024, identifying 1 million as potentially risky. Among these, 16,812 events were classified as “high-severity threats that required immediate defensive measures.”

    While the availability of Ransomware-as-a-Service offerings may contribute to this upward surge in attacks, the Barracuda Managed XDR team noted that the rapid evolution of ransomware is particularly striking when compared to other forms of cyber threats.

    According to their findings, actors attempting ransomware deployments typically operate undetected for periods ranging from 74 minutes to 2 hours before their activities are uncovered. “This operational model not only broadens the landscape of individuals who can access and execute ransomware but also enhances the complexity and sophistication of the attacks,” the team added.

    Data suggests that while malicious actors can implement malware in just over a minute, the Barracuda Managed XDR can effectively monitor up to 350,000 IT events every second to spot significant threats. Yet despite ongoing advancements in cybersecurity methodologies, hackers are consistently employing more advanced and expedited tactics.

    The security professionals emphasize that organizations can still adopt crucial safety strategies. Implementing multifactor authentication, robust access controls, regular patch management, data protection measures, and conducting cybersecurity awareness training for staff are all effective ways to bolster defenses against these fast-evolving threats.

  • Worldwide Sweep Targets ‘Ghost’ Cybercrime Network: 51 Arrested

    Worldwide Sweep Targets ‘Ghost’ Cybercrime Network: 51 Arrested

    Law enforcement agencies from several countries have taken down an encrypted communication platform known as Ghost, which had become a vital resource for criminal groups involved in drug trafficking and money laundering.

    Coordinated by Europol, this operation led to the arrest of 51 suspects across various nations, and more arrests are expected to follow.

    Ghost was notorious for its sophisticated security features, allowing criminals to operate discreetly while planning extensive illegal activities.

    The platform’s shutdown marks a major blow to international organized crime networks that depended on it for their operations.

    Jean-Philippe Lecouffe, the Deputy Executive Director of Europol, referred to the operation as “a global game of cat and mouse,” stressing that this round has come to an end. The crackdown successfully dismantled the platform and disrupted numerous criminal operations.

    Authorities have confiscated weapons, drugs, and over 1 million euros (approximately $1.11 million) in cash. Furthermore, the operation led to the shutdown of a drug lab in Australia and helped avert several potential public safety threats.

    Catherine De Bolle, Europol’s Executive Director, underscored the significance of the operation, stating that Ghost served as “a lifeline for serious organized crime.”

    She assured the public that no matter how concealed they think their activities are, criminal networks cannot escape the united efforts of international law enforcement.

    This extensive operation involved collaboration from law enforcement agencies in Australia, Canada, France, Iceland, Ireland, Italy, the Netherlands, Sweden, and the United States.

    This global teamwork highlights a shared commitment to fighting international organized crime.

    As the investigation progresses, additional disruptions to illegal activities are expected, representing a significant victory in the battle against global criminal networks.