Visualização normal

Antes de ontemFirewall Daily – The Cyber Express
  • ✇Firewall Daily – The Cyber Express
  • Ukraine Makes History With First $8.3M Seized Crypto Transfer to ARMA Samiksha Jain
    Ukraine has transferred Seized Crypto Assets worth more than 8.3 million USDT to the country's Asset Recovery and Management Agency (ARMA), marking the first time virtual assets have been placed under the agency's management following a court decision. The transfer follows an investigation led by the State Bureau of Investigation into an international hacking group accused of carrying out cyberattacks, extortion, and money laundering across Europe and the United States. Accordin
     

Ukraine Makes History With First $8.3M Seized Crypto Transfer to ARMA

Seized Crypto Assets

Ukraine has transferred Seized Crypto Assets worth more than 8.3 million USDT to the country's Asset Recovery and Management Agency (ARMA), marking the first time virtual assets have been placed under the agency's management following a court decision. The transfer follows an investigation led by the State Bureau of Investigation into an international hacking group accused of carrying out cyberattacks, extortion, and money laundering across Europe and the United States.

According to Ukrainian authorities, the transferred cryptocurrency is valued at more than 372 million hryvnias and represents a milestone in the country's efforts to manage digital assets linked to criminal investigations.

Seized Crypto Assets Moved to ARMA After Court Order

The State Bureau of Investigation said the transfer was completed as part of an ongoing criminal investigation conducted in cooperation with the DVB of the National Police and U.S. law enforcement agencies.

Investigators determined that the virtual assets were stored in crypto wallets controlled by a member of the organized hacking group. Following a court order, more than 8.3 million USDT was transferred to ARMA's official crypto wallet.

Authorities said this is the first practical case in Ukraine where seized digital assets have been transferred to ARMA for management, demonstrating the country's ability to handle new categories of assets within the legal system.

Investigation Links Cryptocurrency to International Hacking Group

According to investigators, members of the international hacking group carried out large-scale cyberattacks against individuals and companies in Europe and the United States.

The investigation alleges the group stole confidential information, demanded ransom payments, and laundered criminal proceeds in Ukraine through the purchase of residential properties, vehicles, and other high-value assets.

Authorities estimate that the criminal group's activities caused losses exceeding $100 million.

As part of the pre-trial investigation, four members of the group, including its alleged organizer, were detained and placed in custody.

More Than $11 Million in Assets Seized

The investigation resulted in the cryptocurrency seizure and the confiscation of additional assets with a combined value exceeding $11.1 million.

According to the State Bureau of Investigation, the seized property includes residential buildings, apartments, vehicles, approximately $1 million in cash, and digital assets equivalent to more than $8.3 million.

The Office of the Prosecutor General is providing procedural oversight for the criminal proceedings.

Authorities Plan to Convert Crypto Into Military Bonds

The State Bureau of Investigation said that after converting the cryptocurrency into fiat currency, authorities plan to purchase military bonds.

According to the agency, the initiative is intended to support Ukraine's economy during martial law while ensuring that assets obtained through criminal activity are redirected for state purposes.

Officials described countering transnational cybercrime and ensuring effective mechanisms for the seizure and management of criminal assets as key priorities.

ARMA Expands Digital Asset Management

ARMA said receiving the cryptocurrency marks an important step in the evolution of Ukraine's asset management system.

The agency stated that the successful transfer reflects coordinated efforts between the State Bureau of Investigation and the Office of the Prosecutor General, enabling the execution of the court's decision and preserving the value of the seized assets.

ARMA added that it is continuing to develop mechanisms for managing all categories of seized property, including real estate, corporate rights, and virtual assets, to ensure their preservation in the interests of the state and society.

The agency said the case demonstrates that as cybercriminals increasingly use digital technologies to conceal illicit proceeds, authorities must also strengthen their ability to manage and preserve cryptocurrency and other digital assets seized during criminal investigations.

Ransomware Attacks Surge 30% in 2026 as Qilin and INC Ransom Intensify Operations

Qilin

Ransomware attacks surged 30% in the first half of 2026 compared to the same period in 2025, with Qilin and INC Ransom emerging as two of the most prolific and dangerous operators in a crowded criminal ecosystem. Healthcare continues to be the top targeted industry, with 27 incidents in January 2026 alone, a figure that reflects both the sector's operational sensitivity and the premium value of health records on darknet markets.

Qilin: The Dominant Force

Qilin — also known as Agenda — is a ransomware group that entered 2026 accelerating, not slowing down. By early 2026, Qilin had already posted 55 confirmed victims, placing it ahead of its own 2025 pace. By June 2026, tracking data, Qilin had accumulated 168 confirmed victims in the healthcare sector alone, behind only manufacturing (291) and business services (245) in overall victim count. Qilin operates as a Ransomware-as-a-Service (RaaS) platform, recruiting affiliates who conduct attacks using Qilin's ransomware builder and infrastructure in exchange for a percentage of ransom proceeds. This model allows the core group to expand operational throughput without directly executing every attack. The group's double extortion model — encrypting victim data while simultaneously exfiltrating it and threatening public release on their leak site — has proven effective at pressuring victims into paying ransom demands even when robust backups exist. Public exposure of sensitive patient records creates regulatory, legal, and reputational pressure that many healthcare organisations find more immediately damaging than operational downtime. A notable recent case involves Covenant Health, which suffered a Qilin ransomware breach that exposed 478,188 patient records. The Covenant Health incident highlights Qilin's willingness to attack hospitals and health systems regardless of the direct patient safety implications.

INC Ransom: Targeting Critical Sectors

INC Ransom is another highly active operator that was among the top ransomware groups by victim count in January 2026, with 47 known attacks that month. The group targets organisations across multiple sectors, including healthcare, legal services, and public administration. INC Ransom gained significant attention in 2025 for its attack on NHS Scotland, which exposed 3 terabytes of patient data. The group continues to operate aggressively in 2026, targeting entities including healthcare practices, municipal agencies, and regional service providers. Recent INC Ransom victims include healthcare organisations such as Lymphedema Therapy Specialists, Inc. (February 2026, affecting 378 Texas patients) and various municipal and public sector entities, including Champaign-Urbana Public Health District.

The 2026 Ransomware Landscape

Beyond Qilin and INC Ransom, the broader 2026 ransomware ecosystem is characterised by:
  • AI-assisted operations: Multiple ransomware groups are now using AI tools to accelerate phishing campaign creation, target research, and initial access operations, reducing the operational cost of launching attacks.
  • Healthcare as a premium target: Patient records sell for up to 10 times as much as financial records on darknet markets, making it a persistently attractive target. Operational disruption of healthcare services also creates patient-safety leverage that can pressure organisations to make faster payment decisions.
  • The Play and SafePay operators were also confirmed in recent June 2026 attack disclosures, targeting organisations including Clínica Maitenes and various regional businesses.

Why It Matters

The 30% year-over-year increase in ransomware incidents confirms that neither law enforcement action nor improved defensive capabilities has materially reduced the operational tempo of ransomware criminal enterprises. The professionalisation of RaaS platforms, combined with AI-assisted tooling and shortened attack timelines, is creating conditions in which even well-defended organisations face materially elevated risk. For healthcare specifically, the combination of operational sensitivity, high data value, and historically underfunded security programmes creates a structural vulnerability that the industry has not yet resolved despite years of high-profile attacks.

The Cyber Express Weekly Roundup: AI Threat Escalation, Ransomware Disruption, Supply Chain Attacks, and Expanding Cybersecurity Risks

TCE weekly roundup TCE

In this weekly roundup from The Cyber Express, the global cybersecurity landscape in 2026 continues to shift rapidly as emerging technologies and evolving cyber threats reshape the digital environment. Governments are increasing oversight of artificial intelligence and data practices, while ransomware groups, nation-state actors, and cybercriminal networks are refining their tactics to target enterprises, critical infrastructure, and software supply chains.

This week’s developments highlight how modern cyber risks are becoming more interconnected across industries, with AI-driven attacks, ransomware operations, privacy concerns, and software supply chain compromises continuing to place pressure on organizations worldwide.

The Cyber Express Weekly Roundup 

AI Cyberattacks Surge Across the Americas in Early 2026 

Americas cyber threat landscape Cyber activity linked to artificial intelligence has intensified across the Americas during Q1 2026, with attackers increasingly leveraging AI-driven tools to scale ransomware campaigns, automate reconnaissance, and enhance social engineering operations. A scheduled webinar on May 28 by Cyble will bring together security specialists to examine emerging cyber trends, including ransomware evolution, nation-state activity, and defensive strategies to improve cyber resilience. Read more... 

Foxconn Confirms Cyberattack Amid Ransomware Claims of Massive Data Theft 

Manufacturing giant Foxconn confirmed a cyberattack that disrupted operations at several North American facilities following claims from the Nitrogen ransomware group. The attackers alleged they had stolen more than 8TB of corporate data, including over 11 million files. Foxconn activated incident response procedures and stated that operations were gradually returning to normal. Read more... 

Microsoft Patches 120 Vulnerabilities in May 2026 Security Update 

In its May 2026 Patch Tuesday release, Microsoft addressed approximately 120 security vulnerabilities across a wide range of products, including Windows, Office, SharePoint, DNS services, and enterprise platforms. Among these were 17 classified as critical severity issues. Although no actively exploited zero-day vulnerabilities were reported in this cycle, multiple high-risk remote code execution flaws prompted security researchers to recommend immediate patch deployment across enterprise environments. Read more... 

California Issues Record $12.75 Million Privacy Settlement Against GM 

California regulators reached a $12.75 million settlement with General Motors over allegations tied to violations of the California Consumer Privacy Act (CCPA). Authorities claimed the company collected, retained, and sold driver data without proper consent. The investigation alleged that General Motors shared sensitive geolocation and driving behavior data from its OnStar platform with data brokers LexisNexis and Verisk between 2020 and 2024. Read more... 

Malicious npm Packages Fuel JavaScript Supply Chain Attack 

Security researchers have identified a supply chain compromise targeting the widely used node-ipc npm package ecosystem. Several versions—including 9.1.6, 9.2.3, and 12.0.1—were found to contain malicious code designed to act as a credential-stealing backdoor. The compromised packages reportedly collected sensitive system information, developer credentials, and CI/CD pipeline secrets from affected environments. Read more... 

Weekly cybersecurity takeaway 

This week’s The Cyber Express weekly roundup highlights how modern cybersecurity threats are increasingly interconnected across technology, regulation, and supply chains. AI-driven attacks are expanding operational scale; ransomware groups continue to rely on data theft and disruption, and software supply chain compromises are increasingly targeting developer ecosystems. At the same time, regulatory and legal responses, from privacy settlements to vulnerability patch cycles, continue to evolve in parallel. The overall landscape suggests that cyber risk in 2026 is no longer confined to individual incidents but is instead shaped by continuous pressure across infrastructure, software, and data governance layers.
  • ✇Firewall Daily – The Cyber Express
  • Toronto Police Bust Mobile Smishing Network Targeting Thousands Samiksha Jain
    A major Canada SMS blaster cybercrime case has come to light as Toronto Police charge three men with 44 offences in what authorities describe as a first-of-its-kind investigation in the country. The case, part of Project Lighthouse, highlights a growing threat where cybercriminals use mobile technology to target thousands of people at once. The investigation began in November 2025 after a security partner alerted police to a suspected SMS blaster operating in downtown Toronto. What followed w
     

Toronto Police Bust Mobile Smishing Network Targeting Thousands

Canada SMS blaster cybercrime case

A major Canada SMS blaster cybercrime case has come to light as Toronto Police charge three men with 44 offences in what authorities describe as a first-of-its-kind investigation in the country. The case, part of Project Lighthouse, highlights a growing threat where cybercriminals use mobile technology to target thousands of people at once. The investigation began in November 2025 after a security partner alerted police to a suspected SMS blaster operating in downtown Toronto. What followed was a months-long probe into a sophisticated operation that combined mobility, deception, and large-scale disruption.

What Is the Canada SMS Blaster Cybercrime Case?

At the center of the Canada SMS blaster cybercrime case is a device that mimics a legitimate cellular tower. When nearby mobile phones connect to it, users receive fraudulent messages that appear to come from trusted organizations. These messages often include links to fake websites designed to steal sensitive information such as banking credentials and passwords. This method is widely known as “smishing,” a form of phishing carried out through text messages. However, the scale and mobility of the device used in this case set it apart from typical cyber fraud schemes. Deputy Chief Rob Johnson said the operation posed serious risks beyond financial fraud. He noted that the technology had the capability to reach thousands of devices simultaneously, raising concerns about public safety.

Large-Scale Disruption Across the Greater Toronto Area

Investigators found that the SMS blaster was not stationary. It was operated from vehicles, allowing suspects to move across the Greater Toronto Area and deploy the device in multiple locations. According to Detective Sergeant Lindsay Riddell, tens of thousands of devices connected to the rogue network over several months. Police also recorded more than 13 million network disruptions, during which affected devices were unable to connect to legitimate cellular networks. These disruptions had serious implications. During those moments, access to emergency services such as 9-1-1 could have been impacted, making the Canada SMS blaster cybercrime case not just a financial threat but also a public safety concern.

Arrests and Seizure of Devices

Toronto Police executed search warrants on March 31 at residences in Markham and Hamilton, leading to the arrest of two suspects. Authorities seized multiple SMS blasters along with a significant amount of electronic evidence. A third individual later turned himself in on April 21. All three now face a combined total of 44 charges linked to the operation. The Canada SMS blaster cybercrime case involved extensive coordination between multiple agencies, including the Royal Canadian Mounted Police National Cybercrime Coordination Centre, regional police services, financial institutions, and telecom providers. Officials say this collaboration was key to identifying and disrupting the activity.

A New Type of Cyber Threat in Canada

Law enforcement officials emphasized that this is the first known case of SMS blaster technology being used in Canada. The case reflects how cyber-enabled crimes are becoming more advanced and harder to detect. Authorities noted that while the technology is new, the objective remains the same: to gain unauthorized access to personal and financial information. The Canada SMS blaster cybercrime case shows how attackers are combining traditional fraud tactics with newer tools to scale their operations.

Public Advisory and Safety Measures

Police are urging the public to remain cautious when receiving unexpected text messages. Users are advised not to click on suspicious links or share personal information through unsolicited messages. Officials recommend accessing banking services only through official applications or by directly entering website addresses into browsers. Victims of suspected fraud are encouraged to report incidents to law enforcement. Deputy Chief Johnson also acknowledged the role of the Toronto Police Coordinated Cyber Centre and partner agencies in handling the investigation. He stressed that staying informed and vigilant remains one of the most effective defenses against such threats.
  • ✇Firewall Daily – The Cyber Express
  • Zimbabwe Boosts Cybersecurity as AI-Driven Cyber Fraud Surges Ashish Khaitan
    Zimbabwe is intensifying efforts to reinforce cybersecurity in Zimbabwe as the nation confronts a rise of digital crime. As internet access expands and digital financial services become more embedded in everyday life, authorities warn that these developments are simultaneously exposing weaknesses in Zimbabwe's cybersecurity systems.  At the Cyber Fraud & AI Conference in Nyanga, Information and Communication Technology Minister Tatenda Mavetera highlighted the rise of cyber fraud, noting
     

Zimbabwe Boosts Cybersecurity as AI-Driven Cyber Fraud Surges

cyber fraud in Zimbabwe

Zimbabwe is intensifying efforts to reinforce cybersecurity in Zimbabwe as the nation confronts a rise of digital crime. As internet access expands and digital financial services become more embedded in everyday life, authorities warn that these developments are simultaneously exposing weaknesses in Zimbabwe's cybersecurity systems.  At the Cyber Fraud & AI Conference in Nyanga, Information and Communication Technology Minister Tatenda Mavetera highlighted the rise of cyber fraud, noting that cybercriminals are no longer relying on simple tactics. Instead, they are leveraging cutting-edge tools such as deepfake voice cloning, automated phishing platforms, and adaptive malware to exploit individuals, businesses, and public systems.  “The enemy now has artificial intelligence. You cannot fight an intelligent machine with a manual rulebook — you must fight AI with AI,” Mavetera said. 

Rising Cyber Fraud Threats Challenge Zimbabwe's Cybersecurity Systems 

The scale of the problem is further highlighted by recent data. Authorities estimate that mobile money-related cyber fraud costs Zimbabwe more than US$30 million annually. Meanwhile, phishing and social engineering attacks have surged by over 40% in recent years. Across Africa, cybercrime is estimated to cost more than US$4 billion each year, while global losses are projected to exceed US$10 trillion annually.  Mavetera denoted that the impact of cyber fraud extends beyond financial losses. “Cyber fraud erodes trust in digital systems, and without trust, there is no digital transformation,” she said. This erosion of trust threatens not only individuals and businesses but also the broader stability of the digital economy. 

Government Expands Cybersecurity in Zimbabwe with AI-Driven Solutions 

In response to these challenges, the government is implementing a range of measures aimed at strengthening cybersecurity in Zimbabwe. A National Security Operations Centre is nearing completion, with progress estimated at 85%, and is expected to centralize threat monitoring and response.  Additionally, a Computer Incident Response Team is being established to coordinate national responses to cyberattacks. These institutional developments are intended to improve the country’s ability to detect, manage, and mitigate cyber fraud and other digital threats.  A key initiative is the planned launch of the “Zimbabwe AI Cyber Shield” within the next 12 months. This AI-powered platform will focus on real-time fraud detection, representing a major step forward in modernizing Zimbabwe's cybersecurity capabilities.  Alongside technological investments, the government is prioritizing skills development. Training programs are underway to prepare 10,000 cybersecurity professionals, supported by broader digital literacy initiatives aimed at strengthening public awareness and resilience against cyber fraud. 

Policy and Collaboration Key to Strengthening Zimbabwe Cybersecurity 

Zimbabwe is also working to enhance its legal and policy frameworks. Authorities are introducing legislation to criminalize the misuse of artificial intelligence, particularly in cases involving deepfakes and identity-related cyber fraud. A National Cybersecurity Strategy has been finalized and is awaiting cabinet approval, while the National Artificial Intelligence Strategy (2026–2030), introduced in March, seeks to balance innovation with security.  Despite these efforts, Zimbabwe continues to face structural challenges. The country is currently ranked in the fourth tier of the International Telecommunication Union’s Global Cybersecurity Index, with a score of 39.85 out of 100. While legal measures are relatively strong, gaps remain in technical capacity, organizational readiness, international cooperation, and skills development.  Mavetera stressed that addressing these gaps will require coordinated action from multiple stakeholders. She called for stronger collaboration between the government, the private sector, academia, and citizens to build a resilient digital ecosystem.  She reiterated that cyber fraud is not just a financial issue but a threat to national progress. Without trust in digital systems, the country’s broader digital transformation goals could be undermined. 
❌
❌