Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
Early AlphaBay signup and password-reset messages carried "pimp_alex_91@hotmail.com" in the header, which pointed straight to Alexandre Cazes, the Canadian who ran the site as "Alpha02." He was arrested in Bangkok on July 5, 2017, and died in custody days later.
Years of opsec, undone by a mail header.
Please open Telegram to view this post
VIEW IN TELEGRAM
stay informed → @fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
❤2
Please open Telegram to view this post
VIEW IN TELEGRAM
The handle was minted on July 22 via Fragment, with the buyer paying 5,310 $GRAM (~$8,000).
Shortly after the purchase, the username was banned on Fragment — leaving the owner holding an unusable asset, which was then burned.
@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
The overlap suggests Pyongyang-backed operators are sharing — or leasing — attack kits and servers with criminal ransomware crews hitting South Korean targets.
It's more evidence of the blurring line between state-sponsored espionage and profit-driven extortion, complicating attribution for defenders and investigators.
@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
Bidding is being tracked in TON diamond tiers, with speculation ranging from 1,000 to over 20,000 💎.
Short, authority-flavored handles like this routinely draw premium bids — and are prized by impersonation scammers for exactly that reason.
@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
The case ties back to a transaction involving Russian billionaire Oleg Deripaska, a longtime backer of the data center operator.
BitRiver runs some of Russia's largest bitcoin mining facilities and has been under US sanctions since 2022.
@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
The takedown involved Google, the FBI, Lumen and Shadowserver; the FBI seized domains including netnut.com, while Google killed the accounts used for malware C2.
• 316 distinct threat clusters used NetNut in a single week in June for password-spray attacks
• Alarum disclosed the seizures on July 2, 2026, with more domains taken over July 3–4
• The company warns a prolonged disruption could materially hit its operations
@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
The transfers were split across several addresses, a pattern typically used to break up and launder stolen funds before cash-out.
The North Korea-linked group is tied to more than $6B in crypto theft since 2017, largely through breaches of major exchanges.
@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
The hardware wallet maker says the issue could weaken key randomness on the legacy Mk3 model, and is advising migration to newer devices rather than waiting for a fix.
Separately, Bitcoin security researchers are picking apart an unexplained $38 million wallet drain. No confirmed link between the two has been established.
@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
The posted archive allegedly contains personnel profiles, deployment records and unit assignments — data that, if genuine, would expose serving members of Israel's signals intelligence and communications branches.
The claim is unverified, and no confirmation has come from Israeli authorities. Leaks tied to IDF units are frequently recycled or fabricated for reputational effect, so the sample's authenticity remains the key open question.
@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
The actor says it holds roughly 70 GB of data allegedly taken from the manufacturer's systems, which support commercial aviation and military production lines.
• Alleged haul: ~70 GB of internal data
• Sector: aerospace manufacturing, defense supply chain
• Status: claim unverified, no confirmation from SEKISUI
Breaches at Tier-1 suppliers are prized by attackers for engineering drawings, contracts and program data tied to primes further up the chain.
@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
A scammer he met on a Rust server tricked him into downloading malware, seized his accounts, then extorted him with threats to call in a SWAT team.
The gamer warned police in advance. A dispatcher told him "nothing will happen."
Two days later the scammer followed through, and the raid left the victim paralyzed. The lawsuit targets the response that he says he tried to prevent.
@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
The platform allegedly moved funds for front companies tied to Iran's oil sales, converting proceeds into crypto to sidestep the banking system and dollar controls.
Designation freezes any US-linked assets and bars American persons from dealing with the exchange — exposing counterparties and correspondent partners to secondary sanctions risk.
@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
🎉 GIVEAWAY 🎉
$300
👥 Entries: 170
⏰ Ends: Aug 31 · 1:05 PM
Tap Enter below to join!
$300
👥 Entries: 170
⏰ Ends: Aug 31 · 1:05 PM
Tap Enter below to join!
❤12🔥4👎3
$300 GIVEAWAY
Requirements: Be in @FraudWatcher
Click the button below to join.
⚠️ Welcome to @FraudWatcher
💭 Tracking & notifying you with the latest news on com, cybersecurity, fraud & other online threats.
❗️ From major data breaches and ransomware attacks to phishing campaigns, crypto scams, arrests, and upcoming threat actors.
stay informed → @fraudwatcher
Requirements: Be in @FraudWatcher
Click the button below to join.
stay informed → @fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM