PayPal is a organization tracked across 20 threat clusters and 31 intelligence report mentions on ThreatCluster. First observed October 29, 2025; most recent activity July 24, 2026.
A coordinated investigation led by INTERPOL and the Algerian National Police resulted in the dismantling of SniperDz, a phishing-as-a-service (PhaaS) platform that operated since at least 2015. Group-IB played a crucial…
Refund fraud has evolved into a structured underground marketplace where techniques are sold as digital products. Researchers from Flare have identified a thriving ecosystem where fraudsters advertise refund methods,…
On April 13, 2026, a coordinated international law enforcement operation named 'Operation PowerOFF' targeted the DDoS-for-hire ecosystem, resulting in the takedown of 53 domains and the arrest of four individuals.…
UK small and medium-sized enterprises (SMEs) are increasingly vulnerable to sophisticated AI-driven scams, as highlighted by recent reports. The emergence of 'AI scams 2.0' combines traditional social engineering…
PayPal has reported a data breach affecting its PayPal Working Capital loan application, where a coding error led to the exposure of sensitive personal information, including Social Security numbers, from July 1, 2025,…
In Q2 2026, ChatGPT became one of the top 10 most impersonated brands in phishing attacks, according to Check Point's report. OpenAI's ChatGPT accounted for 1.1% of all brand phishing attempts, reflecting its rapid…
A woman from Uckfield reported that her Ocado account was hacked, leading to unauthorized orders placed using her PayPal account. Trish, the victim, received multiple emails indicating that her account details had been…
The ShinyHunters extortion group published personal information from over 12 million records allegedly stolen from CarGurus, a digital auto platform. The breach includes sensitive data from both personal and corporate…
A significant outage at Cloudflare has resulted in numerous major websites and applications going offline. The incident has particularly impacted financial services firms that rely on Cloudflare's network and security…
The cybercriminal group TA584 has intensified its operations by deploying Tsundere Bot malware through ClickFix social engineering tactics. This initial access broker has significantly increased its campaign volume,…