Fraud Watch
612 subscribers
66 photos
1 video
2 links
Download Telegram
Channel created
⚠️ JUST IN: Russia is moving to place Telegram founder Pavel Durov on an international wanted list, accusing him of aiding terrorism. Investigators claim Ukrainian intelligence used the messaging app to organize attacks and run espionage operations inside Russia. Durov, a Russian-born citizen who left the country in 2014, already faces separate criminal proceedings in France.
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ EXPLOIT: The LULA token on BNB Chain was drained of $578,000 in a flash loan attack. The attacker abused the token's privileged recycle() function, using a $237 million flash loan to manipulate pool reserves before draining liquidity from the PancakeSwap pair. The incident highlights how privileged smart contract functions remain a critical attack surface when access controls and reserve checks are weak.
Please open Telegram to view this post
VIEW IN TELEGRAM
🎁 FUN FACT: AlphaBay's kingpin was unmasked by a welcome email that leaked his personal Hotmail in the header.

Early AlphaBay signup and password-reset messages carried "pimp_alex_91@hotmail.com" in the header, which pointed straight to Alexandre Cazes, the Canadian who ran the site as "Alpha02." He was arrested in Bangkok on July 5, 2017, and died in custody days later.

Years of opsec, undone by a mail header.
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ Welcome to @FraudWatcher

💭Tracking & notifying you with the latest com, cybersecurity, fraud & other online threats.

❗️From major data breaches and ransomware attacks to phishing campaigns, crypto scams, arrests, and upcoming threat actors.

stay informed → @fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
2
⚠️ JUST IN: Coinbase is warning crypto holders about a scam in which fraudsters mail physical letters impersonating the IRS. The letters direct recipients to a bogus "Digital Asset Compliance Portal," a site built to harvest phone numbers. Scammers then call victims while posing as IRS or Coinbase staff, using the earlier contact to build credibility before pressuring them into handing over account access or funds. The IRS does not require crypto holders to register on any such portal, and neither the agency nor Coinbase initiates unsolicited calls demanding wallet details.
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: A rare four-letter Telegram username, @baem, was destroyed after its owner burned it.

The handle was minted on July 22 via Fragment, with the buyer paying 5,310 $GRAM (~$8,000).

Shortly after the purchase, the username was banned on Fragment — leaving the owner holding an unusable asset, which was then burned.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: South Korean agencies say Lazarus Group tools and infrastructure are turning up in ransomware attacks on domestic organizations.

The overlap suggests Pyongyang-backed operators are sharing — or leasing — attack kits and servers with criminal ransomware crews hitting South Korean targets.

It's more evidence of the blurring line between state-sponsored espionage and profit-driven extortion, complicating attribution for defenders and investigators.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: The Telegram username @police is up for auction on Fragment.

Bidding is being tracked in TON diamond tiers, with speculation ranging from 1,000 to over 20,000 💎.

Short, authority-flavored handles like this routinely draw premium bids — and are prized by impersonation scammers for exactly that reason.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: BitRiver founder Igor Runets has been charged with fraud in Russia over an alleged $8 million mining equipment deal.

The case ties back to a transaction involving Russian billionaire Oleg Deripaska, a longtime backer of the data center operator.

BitRiver runs some of Russia's largest bitcoin mining facilities and has been under US sanctions since 2022.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: NetNut's residential proxy pool ran on 2 million+ malware-infected Android devices, and Google and the FBI just cut them off.Also known as Popa, NetNut consisted of more than 2 million Android devices — smart TVs and streaming boxes — infected via trojanized apps and malware like Badbox 2.0, and its operator, linked to Nasdaq-listed Israeli firm Alarum Technologies, rented those proxies to cybercriminal and espionage groups.

The takedown involved Google, the FBI, Lumen and Shadowserver; the FBI seized domains including netnut.com, while Google killed the accounts used for malware C2.

316 distinct threat clusters used NetNut in a single week in June for password-spray attacks
• Alarum disclosed the seizures on July 2, 2026, with more domains taken over July 3–4
• The company warns a prolonged disruption could materially hit its operations

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: Lazarus just moved 120 BTC (~$7M) across multiple wallets.

The transfers were split across several addresses, a pattern typically used to break up and launder stolen funds before cash-out.

The North Korea-linked group is tied to more than $6B in crypto theft since 2017, largely through breaches of major exchanges.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: Coinkite is telling Coldcard Mk3 owners to move their funds after flagging a potential seed-generation flaw.

The hardware wallet maker says the issue could weaken key randomness on the legacy Mk3 model, and is advising migration to newer devices rather than waiting for a fix.

Separately, Bitcoin security researchers are picking apart an unexplained $38 million wallet drain. No confirmed link between the two has been established.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ EXPLOIT: A threat actor claims to have leaked an internal IDF C4I Corps personnel database, with references to Unit 8200.

The posted archive allegedly contains personnel profiles, deployment records and unit assignments — data that, if genuine, would expose serving members of Israel's signals intelligence and communications branches.

The claim is unverified, and no confirmation has come from Israeli authorities. Leaks tied to IDF units are frequently recycled or fabricated for reputational effect, so the sample's authenticity remains the key open question.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: A threat actor claims to have breached SEKISUI Aerospace Corporation, a Tier-1 supplier to Boeing and U.S. defense programs.

The actor says it holds roughly 70 GB of data allegedly taken from the manufacturer's systems, which support commercial aviation and military production lines.

• Alleged haul: ~70 GB of internal data
• Sector: aerospace manufacturing, defense supply chain
• Status: claim unverified, no confirmation from SEKISUI

Breaches at Tier-1 suppliers are prized by attackers for engineering drawings, contracts and program data tied to primes further up the chain.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ EXPLOIT: A Rust player was left paralyzed after a swatting call — and is now suing for $176 million.

A scammer he met on a Rust server tricked him into downloading malware, seized his accounts, then extorted him with threats to call in a SWAT team.

The gamer warned police in advance. A dispatcher told him "nothing will happen."

Two days later the scammer followed through, and the raid left the victim paralyzed. The lawsuit targets the response that he says he tried to prevent.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: The US has sanctioned a Dubai-based crypto exchange accused of anchoring a $4 billion Iranian sanctions-evasion network.

The platform allegedly moved funds for front companies tied to Iran's oil sales, converting proceeds into crypto to sidestep the banking system and dollar controls.

Designation freezes any US-linked assets and bars American persons from dealing with the exchange — exposing counterparties and correspondent partners to secondary sanctions risk.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
🎉 GIVEAWAY 🎉

$300

👥 Entries: 170
Ends: Aug 31 · 1:05 PM

Tap Enter below to join!
12🔥4👎3
$300 GIVEAWAY
Requirements: Be in @FraudWatcher
Click the button below to join.

⚠️ Welcome to @FraudWatcher

💭Tracking & notifying you with the latest news on com, cybersecurity, fraud & other online threats.

❗️From major data breaches and ransomware attacks to phishing campaigns, crypto scams, arrests, and upcoming threat actors.

stay informed → @fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM