Notorious Hacker Arrested for €100 Million Fraud Scheme
Article Content
- •Ehud Tenenbaum, a notorious hacker, was arrested for leading a €100 million fraud scheme.
- •The fraud operation employed over 700 people and ran for at least four years.
- •Tenenbaum has a long history of cybercrime, including notable hacks against U.S. military systems.
Dutch police arrested a 46-year-old man, identified as Ehud Tenenbaum, for his involvement in a large-scale investment fraud scheme that operated 20 call centers and employed over 700 people, generating over €100 million (A$164 million) monthly. Tenenbaum, known as 'The Analyzer,' has a history of hacking dating back to the 1990s and was previously prosecuted for significant cybercrimes, including the Solar Sunrise incident. The operation, named Operation Sunflower, lasted at least four years before being dismantled in July 2026. Tenenbaum was arrested on May 26, 2026, at a Polish airport after arriving from Dubai and was extradited to the Netherlands. Five additional suspects were arrested across Europe, with further captures not ruled out. His previous convictions include hacking into U.S. military systems and credit card fraud.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Knesset in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…