Wille Sutton, a famous USA bank robber, was quoted as saying, “I rob banks; that’s where the money is.” The “money” is now in cybercrime. Cybercrime continues to exact a heavy toll on the world economy, yet accurate figures remain elusive because so many incidents go unreported. A new Comparitech study of the top 100 countries by GDP has put the annual cost to victims at an estimated $1.24 trillion. For perspective, $1.24 trillion is about 3.8% of total nominal US Gross Domestic Product (GDP
cybercrime (35)
Ransomware attacks have increased dramatically during the second quarter of 2026, with undisclosed incidents surging 40% year-on-year, according to BlackFog's latest State of Ransomware Report. The cybersecurity firm documented 2,027 undisclosed attacks in Q2 2026, compared with 1,446 during the same period in 2025. The report, which provides comprehensive analysis of both publicly disclosed and undisclosed ransomware attacks worldwide, also recorded 306 publicly disclosed attacks during the q
A fugitive has been arrested in Thailand after hacking into a police database to delete his criminal record, cybercrime investigators have stated. Why does this sound like the 1986 comedy ‘Ferris Bueller’s Day Off’? The main character hacked the school computer system to change his grades and attendance records. Police said Sahachart Chuaybamrung, aged 26, had taught himself advanced computer skills using AI chatbots to help him break into the Royal Thai Police systems to delete his five arre
German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world's most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed and ran it. In a joint announcement on 20 July 2026, the Frankfurt public prosecutor's cybercrime unit (ZIT) and Germany's Federal Criminal Police Office (BKA) said they pulled more than 200 servers offline. Investigators estimate roughly 1,800 paying custo
Involvement in cybercrime is no longer a peripheral issue but has emerged as a significant social movement among young people. While the average age at arrest for general crimes in the United States is 37, the average age at arrest for cyber-related offenses drops significantly to 19. In the United Kingdom, the National Crime Agency (NCA) reports the average age is even lower, at just 17 years old. This shift is evidenced by high-profile incidents, such as the 2025 attack on Marks and Spencer
Artificial Intelligence is now fundamentally integrated into the planning and execution of cyber-attacks. Europol’s 2026 threat assessment report identifies the combination of automation and AI as a defining feature of modern criminal ecosystems. AI vulnerabilities and AI-enabled fraud are becoming primary concerns for global organizations. Phishing demonstrates this transition clearly. AI-generated messages are increasingly personalized and context-aware, accurately mirroring internal corpo
Hackers are increasingly exploiting trusted artificial intelligence (AI) platforms like ChatGPT and Claude to turn them against their own users. Recently, Hackread.com reported a flaw called ClaudeBleed, discovered by LayerX, which allowed unauthorized browser extensions to hijack Anthropic Claude’s interface. Now, hackers are reportedly abusing official features of these AI tools to spread malware while easily evading web filters and security checks.[1]
The Fake Outage Trick - These observati
Artificial intelligence has become integral to contemporary cyber-attack planning and execution. Recent research demonstrates how embedded AI systems now operate across organized cybercrime activities, fundamentally altering attack methodologies through increased speed and targeting precision. Europol's 2026 threat assessment identifies the integration of automation and AI as a defining characteristic of modern cybercrime. Industry reporting indicates that AI vulnerabilities and AI-enabled fra
A new report from Google Threat Intelligence Group (GTIG) reveals a coordinated campaign exploiting an AI-generated zero-day vulnerability. The attack targets an unnamed open-source web administration tool, using the flaw to bypass two-factor authentication (2FA). The researchers say they identified an active threat actor utilizing large language models (LLMs) to actively discover and weaponize software vulnerabilities in the wild.
As the targeted flaw involves a high-level semantic logic bug
A Florida man who worked as a ransomware negotiator at a US cyber incident response firm has pleaded guilty to conspiring with the BlackCat/ALPHV ransomware group, feeding the attackers confidential information about his own clients while simultaneously negotiating on their behalf. Angelo Martino, 41, of Land O'Lakes, Florida, admitted to providing BlackCat operators with clients' insurance policy limits and internal negotiation strategies without his employer's or clients' knowledge. The oper
Hewlett Packard Enterprise (HPE) has released its inaugural cyber threat report, titled 'In the Wild', revealing a significant shift in the operational strategies of modern cyber adversaries. Released on 17 March 2026, the research indicates that cybercrime groups are increasingly mirroring legitimate enterprise business models to maximize financial gain. The report, based on an analysis of 1,186 active threat campaigns observed globally throughout 2025, suggests that the threat landscape has
A new report from blockchain data platform Chainalysis has revealed a significant rise in the use of cryptocurrency for illicit activities related to human trafficking. The research indicates that cryptocurrency payments to suspected human trafficking services increased by 85% year-on-year in 2025, with the total value reaching hundreds of millions of dollars across the identified services. The findings shed light on how criminal networks are adapting their financial operations, using digital
Social media has overtaken email as the primary channel for online scams in the UK, accounting for 34% of reported incidents according to recent research. This shift highlights growing concerns over fraudulent content on platforms such as Facebook and Instagram, particularly in finance-related advertising. A new analysis by BrokerChooser examined over 1,200 active finance-related ads in the Meta Ads Library to assess exposure to high-risk promotions across multiple countries. The study classi
In 2025, the cybersecurity landscape revealed a pattern of opportunistic attacks exploiting familiar weaknesses, from unpatched devices to misconfigured cloud services. Criminal groups fragmented under pressure from law enforcement, while state actors amplified their reach through emerging tools. Geopolitical tensions fueled targeted operations, with Russia focusing on Europe and Ukraine, and China expanding influence in Africa and South America. Overall, the year saw a shift towards data thef
Europol has taken down the illegal cryptocurrency mixing service ‘Cryptomixer’, which is suspected of facilitating cybercrime and money laundering. During the operation, which was conducted in conjunction with Swiss and German law enforcement, €25m ($30m) worth of the cryptocurrency Bitcoin was seized. Action took place between 24-28 November 2025 in Zurich, Switzerland.
Three servers were seized, along with the cryptomixer.io domain. The operation resulted in the confiscation of over 12 tera
The Russian government's relationship with its cybercriminal ecosystem has transitioned from passive tolerance to active state management, marking a strategic shift. This report, covering 2024–2025, details the "Dark Covenant 3.0," characterized by selective enforcement, choreographed arrests, and direct coordination between criminal leaders and Russian intelligence intermediaries.
Insikt Group found that Russia leverages these criminal groups as geopolitical tools, with detentions and releases
Cybercriminals are targeting trucking and logistics companies with remote monitoring tools to hijack cargo freight, researchers at cybersecurity company Proofpoint have found. The hackers are collaborating with organized crime groups to compromise companies involved in the freight supply chain, the report stated, further fueling a significant increase in cargo theft in recent years. The theft of goods in transit in the US increased by 27% in 2024 and is expected to rise by another 22% this yea
The FBI warned that attackers are spoofing the official Crime Complaint Center (IC3) website to steal personal data and commit financial fraud, targeting users who report cybercrimes.
The fake websites mimic the real IC3 domain by making slight changes in spelling or top-level domains, tricking users into submitting sensitive details such as names, addresses, emails, and banking information. Victims may unknowingly land on these sites while trying to file cybercrime complaints, exposing them to
Cybersecurity researchers are warning of a "significant spike" in brute-force traffic aimed at Fortinet SSL VPN devices. The coordinated activity, per threat intelligence firm GreyNoise, was observed on 03 August 2025, with over 780 unique IP addresses participating in the effort. As many as 56 unique IP addresses have been detected over the past 24 hours. All the IP addresses have been classified as malicious, with the IPs originating from the United States, Canada, Russia, and the Netherlan
Why hack when hackers are willing to sell guaranteed access to breached networks? Increasingly, cybercrooks agree they would rather outsource than bother with the tedium of actual network penetration, leading to a flourishing initial access market. Remote access to a victim's network now retails for an average price of $2,700, although about 40% of what's being sold goes for much less $500 to $1,000, noted in a report from cybersecurity firm Rapid7. Research is based on listings posted over