Fraud Watch
660 subscribers
66 photos
1 video
2 links
Download Telegram
๐ŸŽ FUN FACT: AlphaBay's kingpin was unmasked by a welcome email that leaked his personal Hotmail in the header.

Early AlphaBay signup and password-reset messages carried "pimp_alex_91@hotmail.com" in the header, which pointed straight to Alexandre Cazes, the Canadian who ran the site as "Alpha02." He was arrested in Bangkok on July 5, 2017, and died in custody days later.

Years of opsec, undone by a mail header.
Please open Telegram to view this post
VIEW IN TELEGRAM
โš ๏ธ Welcome to @FraudWatcher

๐Ÿ’ญTracking & notifying you with the latest com, cybersecurity, fraud & other online threats.

โ—๏ธFrom major data breaches and ransomware attacks to phishing campaigns, crypto scams, arrests, and upcoming threat actors.

stay informed โ†’ @fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
โค2
โš ๏ธ JUST IN: Coinbase is warning crypto holders about a scam in which fraudsters mail physical letters impersonating the IRS. The letters direct recipients to a bogus "Digital Asset Compliance Portal," a site built to harvest phone numbers. Scammers then call victims while posing as IRS or Coinbase staff, using the earlier contact to build credibility before pressuring them into handing over account access or funds. The IRS does not require crypto holders to register on any such portal, and neither the agency nor Coinbase initiates unsolicited calls demanding wallet details.
Please open Telegram to view this post
VIEW IN TELEGRAM
โš ๏ธ JUST IN: A rare four-letter Telegram username, @baem, was destroyed after its owner burned it.

The handle was minted on July 22 via Fragment, with the buyer paying 5,310 $GRAM (~$8,000).

Shortly after the purchase, the username was banned on Fragment โ€” leaving the owner holding an unusable asset, which was then burned.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
โš ๏ธ JUST IN: South Korean agencies say Lazarus Group tools and infrastructure are turning up in ransomware attacks on domestic organizations.

The overlap suggests Pyongyang-backed operators are sharing โ€” or leasing โ€” attack kits and servers with criminal ransomware crews hitting South Korean targets.

It's more evidence of the blurring line between state-sponsored espionage and profit-driven extortion, complicating attribution for defenders and investigators.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
โš ๏ธ JUST IN: The Telegram username @police is up for auction on Fragment.

Bidding is being tracked in TON diamond tiers, with speculation ranging from 1,000 to over 20,000 ๐Ÿ’Ž.

Short, authority-flavored handles like this routinely draw premium bids โ€” and are prized by impersonation scammers for exactly that reason.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
โš ๏ธ JUST IN: BitRiver founder Igor Runets has been charged with fraud in Russia over an alleged $8 million mining equipment deal.

The case ties back to a transaction involving Russian billionaire Oleg Deripaska, a longtime backer of the data center operator.

BitRiver runs some of Russia's largest bitcoin mining facilities and has been under US sanctions since 2022.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
โš ๏ธ JUST IN: NetNut's residential proxy pool ran on 2 million+ malware-infected Android devices, and Google and the FBI just cut them off.Also known as Popa, NetNut consisted of more than 2 million Android devices โ€” smart TVs and streaming boxes โ€” infected via trojanized apps and malware like Badbox 2.0, and its operator, linked to Nasdaq-listed Israeli firm Alarum Technologies, rented those proxies to cybercriminal and espionage groups.

The takedown involved Google, the FBI, Lumen and Shadowserver; the FBI seized domains including netnut.com, while Google killed the accounts used for malware C2.

โ€ข 316 distinct threat clusters used NetNut in a single week in June for password-spray attacks
โ€ข Alarum disclosed the seizures on July 2, 2026, with more domains taken over July 3โ€“4
โ€ข The company warns a prolonged disruption could materially hit its operations

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
โš ๏ธ JUST IN: Lazarus just moved 120 BTC (~$7M) across multiple wallets.

The transfers were split across several addresses, a pattern typically used to break up and launder stolen funds before cash-out.

The North Korea-linked group is tied to more than $6B in crypto theft since 2017, largely through breaches of major exchanges.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
โš ๏ธ JUST IN: Coinkite is telling Coldcard Mk3 owners to move their funds after flagging a potential seed-generation flaw.

The hardware wallet maker says the issue could weaken key randomness on the legacy Mk3 model, and is advising migration to newer devices rather than waiting for a fix.

Separately, Bitcoin security researchers are picking apart an unexplained $38 million wallet drain. No confirmed link between the two has been established.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
โš ๏ธ EXPLOIT: A threat actor claims to have leaked an internal IDF C4I Corps personnel database, with references to Unit 8200.

The posted archive allegedly contains personnel profiles, deployment records and unit assignments โ€” data that, if genuine, would expose serving members of Israel's signals intelligence and communications branches.

The claim is unverified, and no confirmation has come from Israeli authorities. Leaks tied to IDF units are frequently recycled or fabricated for reputational effect, so the sample's authenticity remains the key open question.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
โš ๏ธ JUST IN: A threat actor claims to have breached SEKISUI Aerospace Corporation, a Tier-1 supplier to Boeing and U.S. defense programs.

The actor says it holds roughly 70 GB of data allegedly taken from the manufacturer's systems, which support commercial aviation and military production lines.

โ€ข Alleged haul: ~70 GB of internal data
โ€ข Sector: aerospace manufacturing, defense supply chain
โ€ข Status: claim unverified, no confirmation from SEKISUI

Breaches at Tier-1 suppliers are prized by attackers for engineering drawings, contracts and program data tied to primes further up the chain.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
โš ๏ธ EXPLOIT: A Rust player was left paralyzed after a swatting call โ€” and is now suing for $176 million.

A scammer he met on a Rust server tricked him into downloading malware, seized his accounts, then extorted him with threats to call in a SWAT team.

The gamer warned police in advance. A dispatcher told him "nothing will happen."

Two days later the scammer followed through, and the raid left the victim paralyzed. The lawsuit targets the response that he says he tried to prevent.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
โš ๏ธ JUST IN: The US has sanctioned a Dubai-based crypto exchange accused of anchoring a $4 billion Iranian sanctions-evasion network.

The platform allegedly moved funds for front companies tied to Iran's oil sales, converting proceeds into crypto to sidestep the banking system and dollar controls.

Designation freezes any US-linked assets and bars American persons from dealing with the exchange โ€” exposing counterparties and correspondent partners to secondary sanctions risk.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
๐ŸŽ‰ GIVEAWAY ๐ŸŽ‰

$300

๐Ÿ‘ฅ Entries: 170
โฐ Ends: Aug 31 ยท 1:05 PM

Tap Enter below to join!
โค12๐Ÿ”ฅ4๐Ÿ‘Ž3
$300 GIVEAWAY
Requirements: Be in @FraudWatcher
Click the button below to join.

โš ๏ธ Welcome to @FraudWatcher

๐Ÿ’ญTracking & notifying you with the latest news on com, cybersecurity, fraud & other online threats.

โ—๏ธFrom major data breaches and ransomware attacks to phishing campaigns, crypto scams, arrests, and upcoming threat actors.

stay informed โ†’ @fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
โš ๏ธ JUST IN: The FBI's 60-day crackdown on "The Com" is winding down with just 3 arrests.

The named suspects span SIM swapping and Scattered Spider-linked activity โ€” a thin haul for an operation billed as a sweep of the sprawling English-speaking cybercrime network.

Arrested so far:
โ€ข Merry โ€” SIM swapper
โ€ข Peter Stokes โ€” Scattered Spider
โ€ข Brandon Hiser

Whether the Bureau extends the push or announces further charges as sealed cases unseal remains unclear.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
โš ๏ธ JUST IN: ShinyHunters says it's back, posting a return announcement on an underground forum.

The group shared new Telegram and X accounts it claims will act as official channels, plus a fresh PGP key for future communications and verification.

No new victims or data leaks accompanied the announcement.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
โš ๏ธ JUST IN: MoneyFlip's CEO has been arrested in an alleged murder-for-hire plot.

He allegedly paid undercover federal agents $40,000 โ€” including 25,000 USDT โ€” to carry out the killing.

Prosecutors also say he laundered $750,000 in suspected drug proceeds through his own crypto exchange.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก๏ธ UPDATE: Galaxy Research puts losses from the Coldcard wallet incident at roughly $70M.

Analysts traced 1,196 addresses drained of 1,082.65 BTC inside a single 41-minute window โ€” a far wider scope than earlier estimates suggested.

โ€ข 1,196 affected addresses
โ€ข 1,082.65 BTC moved
โ€ข Drain completed in 41 minutes

The tight timeframe points to an automated sweep rather than isolated user error. Coldcard holders are being urged to verify balances and migrate funds to freshly generated seeds.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
Fraud Watch pinned ยซ๐ŸŽ‰ GIVEAWAY ๐ŸŽ‰ $300 ๐Ÿ‘ฅ Entries: 170 โฐ Ends: Aug 31 ยท 1:05 PM Tap Enter below to join!ยป