Visualização de leitura

Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN

While monitoring attack cases targeting MS-SQL servers, the AhnLab SEcurity intelligence Center (ASEC) identified an instance in which the Larva-26009 threat actor installed the XMRig CoinMiner. While the installation of CoinMiner is common in attack cases targeting MS-SQL servers, in this particular attack case, the attacker installed VShell and GotoHTTP to gain control over the […]

Statistical Report on Malware Targeting Windows Database Servers in Q2 2026

Contents The AhnLab SEcurity intelligence Center (ASEC) analyzed attack logs from the second quarter of 2026 targeting MS-SQL server and MySQL server installations on Windows. This report summarizes the damage status, attack status, and the classification of the malware and tools used in the attacks. Purpose and Scope The targets are MS-SQL servers and MySQL […]

Statistical Report on Malware Targeting Windows Web Servers in Q2 2026

Content In the second quarter of 2026, the AhnLab SEcurity intelligence Center (ASEC) compiled an analysis of the current attack status for poorly managed Windows web servers and classified the malware used in these attacks. The targets were Internet Information Services (IIS) web servers and Apache Tomcat web servers running in Windows environments. Purpose and […]

UK Cybercrime Journal: Argos Account Takeover Fraud


What Happened

  • On 3 June 2026, the City of London Police issued a warning stating Report Fraud has seen a significant increase in cases mentioning the retailer, reflecting how criminals are targeting well-known brands.
  • Report Fraud, which is run by the City of London Police, warned that cybercriminals are using leaked credentials from historical data breaches to hijack Argos user accounts.
  • Once on the account, the fraudsters order and then collect the goods in-person at a physical store. In some instances, the goods are paid for using payment details not connected to the victim of the compromised account.
  • Notably, the goods from fraudulent orders are often claimed via Click & Collect option that Argos allows, enabling the threat actors to retrieve goods in store.
  • In May, Report Fraud received 652 reports which mention Argos, a 323% increase compared to April, when 154 reports mentioning the retailer were made. Since the start of 2026, there have been 1,175 reports mentioning the retailer, with May seeing the highest number to date.
  • This alert is also not the first raised about Argos. On 18 November 2025, the East Midlands Cyber Resilience Center issued a warning about Argos and Currys accounts getting compromised and unauthorised purchases being made. In some instances, particularly with Currys, the Buy Now Pay Later (BNPL) option was used, leaving the account holder with finance plans in their names.

Analyst Comment

For both everyday UK consumers and UK retail risk teams, these alerts provide several layered insights. Retailers have spent years optimising Click & Collect to be as frictionless as possible to compete with online shopping giants like Amazon. However, this alert shows how Click & Collect can be a security liability. As Argos allows quick collections, criminals can buy an item online and pick it up at a local store before the real account owner notices an order confirmation email.


The police alerts also note that the items may even be paid for using payment details not connected to the victim. Criminals are mixing stolen accounts with stolen credit cards. This is likely due to an established Argos account with a multi-year history buying expensive items would look pretty normal to a fraud detection engines.


The combination of an Account Takeover (ATO) and Buy Now Pay Later (BNPL) fraud creates a difficult scenario for retailers, credit providers, and consumers. The regulatory and reputational fallout for a retailer under the rules of the UK Financial Conduct Authority (FCA) could be severe. If a retailer's poor account security allows fraudsters to easily spin up a finance plan in a victim's name, the FCA will view this as a systemic failure to protect consumers, resulting in massive fines.


These attacks are possible due to the practice of Argos users who are reusing the same previously leaked password across multiple accounts, plus users not having multi-factor authentication (MFA) turned on in their account settings. 


Campaigns like this can trigger a reputational hit to retailers as victims often do not suffer silently. They take to social media to share stories and the public narrative can shift to being about a retailer who is complicit in disrupting innocent people's financial lives.


Defensive Takeaways

  • User Account Hygiene Best Practices: Standard practices such as rotating passwords, using complex password, using a different password per service, using a password manager, using passkeys, and turning on MFA would all help mitigate this type of threat for users.
  • Credit Monitoring: If a user suspects their account has been compromised, they should consider using a credit monitoring service to help prevent unauthorised loans taken out in their name.
  • Cancel and Replace Payment Cards: If a user suspects their payment card data has been stolen, then they should contact their financial institution and have it cancelled and replaced.
  • Implement Click-and-Collect Controls: Retailers with click-and-click options should introduce controls such as requiring ID of the account owner or a single-use QR code or PIN via SMS/Email at the point of collection for high-value items to prevent this type of fraud.
  • Detecting Credential Stuff Attacks: If the cybercriminals were using credential stuffing attacks, then retailers should be able to detect unauthorised password guessing attempts against their online portals. It is recommended to use IP context analysis and perform source IP correlation. If one IP address tagged as a proxy or VPN is observed attempting to login to dozens of accounts simultaneously, then there’s an issue.
  • Leverage Stripe’s FT3 framework: If your organisation or team is tasked with combating fraud, then categorising these scammers TTPs is crucial. That’s why Stripe has developed the Fraud Tools, Tactics, and Techniques (FT3) framework. It’s designed to help security teams understand the landscape, spot gaps, develop detections, improve incident response, and foster collaboration.


Relevant Sources

  1. https://www.cityoflondon.police.uk/news/city-of-london/news/2026/june/report-fraud-alert-warning-for-argos-shoppers-after-323-per-cent-spike-in-fraud-reports-mentioning-the-retailer/report-fraud-alert-warning-for-online-shoppers-after-spike-in-criminals-gaining-unauthorised-access-to-retailer-accounts/
  2. https://www.emcrc.co.uk/post/currys-and-argos-account-warning-issued-by-police


Social Media Intelligence (SOCMINT)

  1. https://www.reddit.com/r/LegalAdviceUK/s/NbOWRfzvgm
  2. https://www.reddit.com/r/Argos/s/6uOo52UpHf
  3. https://www.reddit.com/r/Argos/s/eZTgBhhNzp
  4. https://x.com/donnaeenichols1/status/2060321697996161165
  5. https://x.com/lottyburns/status/1983581827127259558


Relevant CTI Resources

  1. https://www.cloudflare.com/learning/bots/what-is-credential-stuffing/

Statistics Report on Malware Targeting Windows Database Servers in Q1 2026

Description. analysis of ASEC’s ASD logs for Q1 2026 showed a consistent trend of attacks against MS-SQL and MySQL. the number of attacks tended to decrease temporarily in February before increasing again in March. Purpose and Scope. this report summarizes the statistics of attacks targeting MS-SQL and MySQL servers installed on Windows and the malware […]

Statistical Report on Malware Targeting Windows Web Servers in Q1 2026

Description. AhnLab SEcurity intelligence Center (ASEC) analyzed the attack status and malware statistics of Windows web servers in the first quarter of 2026 based on AhnLab Smart Defense (ASD) logs. the analysis covers Internet Information Services (IIS) and Apache Tomcat web servers in Windows environments. command execution through the web shell is the main path […]
❌