Fraud Watch
660 subscribers
66 photos
1 video
2 links
Download Telegram
⚠️ JUST IN: A rare four-letter Telegram username, @baem, was destroyed after its owner burned it.

The handle was minted on July 22 via Fragment, with the buyer paying 5,310 $GRAM (~$8,000).

Shortly after the purchase, the username was banned on Fragment — leaving the owner holding an unusable asset, which was then burned.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: South Korean agencies say Lazarus Group tools and infrastructure are turning up in ransomware attacks on domestic organizations.

The overlap suggests Pyongyang-backed operators are sharing — or leasing — attack kits and servers with criminal ransomware crews hitting South Korean targets.

It's more evidence of the blurring line between state-sponsored espionage and profit-driven extortion, complicating attribution for defenders and investigators.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: The Telegram username @police is up for auction on Fragment.

Bidding is being tracked in TON diamond tiers, with speculation ranging from 1,000 to over 20,000 💎.

Short, authority-flavored handles like this routinely draw premium bids — and are prized by impersonation scammers for exactly that reason.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: BitRiver founder Igor Runets has been charged with fraud in Russia over an alleged $8 million mining equipment deal.

The case ties back to a transaction involving Russian billionaire Oleg Deripaska, a longtime backer of the data center operator.

BitRiver runs some of Russia's largest bitcoin mining facilities and has been under US sanctions since 2022.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: NetNut's residential proxy pool ran on 2 million+ malware-infected Android devices, and Google and the FBI just cut them off.Also known as Popa, NetNut consisted of more than 2 million Android devices — smart TVs and streaming boxes — infected via trojanized apps and malware like Badbox 2.0, and its operator, linked to Nasdaq-listed Israeli firm Alarum Technologies, rented those proxies to cybercriminal and espionage groups.

The takedown involved Google, the FBI, Lumen and Shadowserver; the FBI seized domains including netnut.com, while Google killed the accounts used for malware C2.

316 distinct threat clusters used NetNut in a single week in June for password-spray attacks
• Alarum disclosed the seizures on July 2, 2026, with more domains taken over July 3–4
• The company warns a prolonged disruption could materially hit its operations

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: Lazarus just moved 120 BTC (~$7M) across multiple wallets.

The transfers were split across several addresses, a pattern typically used to break up and launder stolen funds before cash-out.

The North Korea-linked group is tied to more than $6B in crypto theft since 2017, largely through breaches of major exchanges.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: Coinkite is telling Coldcard Mk3 owners to move their funds after flagging a potential seed-generation flaw.

The hardware wallet maker says the issue could weaken key randomness on the legacy Mk3 model, and is advising migration to newer devices rather than waiting for a fix.

Separately, Bitcoin security researchers are picking apart an unexplained $38 million wallet drain. No confirmed link between the two has been established.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ EXPLOIT: A threat actor claims to have leaked an internal IDF C4I Corps personnel database, with references to Unit 8200.

The posted archive allegedly contains personnel profiles, deployment records and unit assignments — data that, if genuine, would expose serving members of Israel's signals intelligence and communications branches.

The claim is unverified, and no confirmation has come from Israeli authorities. Leaks tied to IDF units are frequently recycled or fabricated for reputational effect, so the sample's authenticity remains the key open question.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: A threat actor claims to have breached SEKISUI Aerospace Corporation, a Tier-1 supplier to Boeing and U.S. defense programs.

The actor says it holds roughly 70 GB of data allegedly taken from the manufacturer's systems, which support commercial aviation and military production lines.

• Alleged haul: ~70 GB of internal data
• Sector: aerospace manufacturing, defense supply chain
• Status: claim unverified, no confirmation from SEKISUI

Breaches at Tier-1 suppliers are prized by attackers for engineering drawings, contracts and program data tied to primes further up the chain.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ EXPLOIT: A Rust player was left paralyzed after a swatting call — and is now suing for $176 million.

A scammer he met on a Rust server tricked him into downloading malware, seized his accounts, then extorted him with threats to call in a SWAT team.

The gamer warned police in advance. A dispatcher told him "nothing will happen."

Two days later the scammer followed through, and the raid left the victim paralyzed. The lawsuit targets the response that he says he tried to prevent.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: The US has sanctioned a Dubai-based crypto exchange accused of anchoring a $4 billion Iranian sanctions-evasion network.

The platform allegedly moved funds for front companies tied to Iran's oil sales, converting proceeds into crypto to sidestep the banking system and dollar controls.

Designation freezes any US-linked assets and bars American persons from dealing with the exchange — exposing counterparties and correspondent partners to secondary sanctions risk.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
🎉 GIVEAWAY 🎉

$300

👥 Entries: 170
Ends: Aug 31 · 1:05 PM

Tap Enter below to join!
12🔥4👎3
$300 GIVEAWAY
Requirements: Be in @FraudWatcher
Click the button below to join.

⚠️ Welcome to @FraudWatcher

💭Tracking & notifying you with the latest news on com, cybersecurity, fraud & other online threats.

❗️From major data breaches and ransomware attacks to phishing campaigns, crypto scams, arrests, and upcoming threat actors.

stay informed → @fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: The FBI's 60-day crackdown on "The Com" is winding down with just 3 arrests.

The named suspects span SIM swapping and Scattered Spider-linked activity — a thin haul for an operation billed as a sweep of the sprawling English-speaking cybercrime network.

Arrested so far:
Merry — SIM swapper
Peter Stokes — Scattered Spider
Brandon Hiser

Whether the Bureau extends the push or announces further charges as sealed cases unseal remains unclear.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: ShinyHunters says it's back, posting a return announcement on an underground forum.

The group shared new Telegram and X accounts it claims will act as official channels, plus a fresh PGP key for future communications and verification.

No new victims or data leaks accompanied the announcement.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: MoneyFlip's CEO has been arrested in an alleged murder-for-hire plot.

He allegedly paid undercover federal agents $40,000 — including 25,000 USDT — to carry out the killing.

Prosecutors also say he laundered $750,000 in suspected drug proceeds through his own crypto exchange.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚡️ UPDATE: Galaxy Research puts losses from the Coldcard wallet incident at roughly $70M.

Analysts traced 1,196 addresses drained of 1,082.65 BTC inside a single 41-minute window — a far wider scope than earlier estimates suggested.

1,196 affected addresses
1,082.65 BTC moved
• Drain completed in 41 minutes

The tight timeframe points to an automated sweep rather than isolated user error. Coldcard holders are being urged to verify balances and migrate funds to freshly generated seeds.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
Fraud Watch pinned «🎉 GIVEAWAY 🎉 $300 👥 Entries: 170 Ends: Aug 31 · 1:05 PM Tap Enter below to join!»
⚡️ UPDATE: A cold-wallet compromise has spread to roughly 4,500 Bitcoin addresses, with losses approaching $89 million.

Victims held funds in offline storage, long considered the safest option — suggesting keys or seed phrases were exposed at generation rather than by a live network breach.

~4,500 affected BTC addresses
~$89M in stolen funds so far
• Attack still expanding as new addresses are drained

Holders using wallets created from untrusted software or pre-generated seed phrases are urged to move funds to freshly generated keys.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: Spider-Man: Brand New Day was pirated on X, with a high-quality bootleg reaching 5.9 million accounts before takedown.Posted by an account named "Fredrick Bryan" at 6:05 a.m. PT, the leaked video drew over 143,000 likes and 10,000 reshares before being pulled around 3:25 p.m. PT.

Copies from several other X accounts followed, though most were removed quickly. It comes a week after a high-quality bootleg of The Odyssey leaked on the same platform.

• Leaked Friday morning, a day after the film hit theaters
• Opening day still projected at $167M–$173M, topping *Avengers: Endgame*'s $157.4M
• Sony has not commented

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: @Mist, a former staff member on OGUser, has been banned after failing to resolve a deal dispute.

The ban was issued by default following an open Deal Dispute thread filed against him on-site.

He may still settle up and appeal, but he's said to be leaving the com — leaving the outcome uncertain and raising questions about his disregard for the process.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM