<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Threats Without Borders]]></title><description><![CDATA[
Explore the Nexus of Cyber-Financial Crime Investigation, Cybersecurity, and Tactical Cyber Threat Intelligence — All Delivered in One Dynamic Newsletter!
]]></description><link>https://www.threatswithoutborders.com</link><image><url>https://substackcdn.com/image/fetch/$s_!lkkz!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07f3f957-f680-4ee2-b274-e8ca2ac66a24_600x600.png</url><title>Threats Without Borders</title><link>https://www.threatswithoutborders.com</link></image><generator>Substack</generator><lastBuildDate>Fri, 31 Jul 2026 14:21:57 GMT</lastBuildDate><atom:link href="https://www.threatswithoutborders.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Matt Dotts]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[cyficrime@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[cyficrime@substack.com]]></itunes:email><itunes:name><![CDATA[Matt Dotts]]></itunes:name></itunes:owner><itunes:author><![CDATA[Matt Dotts]]></itunes:author><googleplay:owner><![CDATA[cyficrime@substack.com]]></googleplay:owner><googleplay:email><![CDATA[cyficrime@substack.com]]></googleplay:email><googleplay:author><![CDATA[Matt Dotts]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Threats Without Borders - Issue 297]]></title><description><![CDATA[Cybersecurity Investigation Newsletter, week ending July 26, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-297</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-297</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 28 Jul 2026 10:48:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>If you can dodge a wrench, you can dodge a ball... maybe not.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QqSy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F368d9985-db9b-4ea8-bbe6-2c017b404a86_742x976.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QqSy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F368d9985-db9b-4ea8-bbe6-2c017b404a86_742x976.jpeg 424w, https://substackcdn.com/image/fetch/$s_!QqSy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F368d9985-db9b-4ea8-bbe6-2c017b404a86_742x976.jpeg 848w, https://substackcdn.com/image/fetch/$s_!QqSy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F368d9985-db9b-4ea8-bbe6-2c017b404a86_742x976.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!QqSy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F368d9985-db9b-4ea8-bbe6-2c017b404a86_742x976.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QqSy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F368d9985-db9b-4ea8-bbe6-2c017b404a86_742x976.jpeg" width="742" height="976" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/368d9985-db9b-4ea8-bbe6-2c017b404a86_742x976.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:976,&quot;width&quot;:742,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:428816,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/208661964?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F368d9985-db9b-4ea8-bbe6-2c017b404a86_742x976.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QqSy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F368d9985-db9b-4ea8-bbe6-2c017b404a86_742x976.jpeg 424w, https://substackcdn.com/image/fetch/$s_!QqSy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F368d9985-db9b-4ea8-bbe6-2c017b404a86_742x976.jpeg 848w, https://substackcdn.com/image/fetch/$s_!QqSy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F368d9985-db9b-4ea8-bbe6-2c017b404a86_742x976.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!QqSy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F368d9985-db9b-4ea8-bbe6-2c017b404a86_742x976.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The term &#8220;wrench attacks,&#8221; referring to physical coercion to steal cryptocurrencies, increased by 33% in the first half of 2026 compared to the previous year, with losses reaching $124 million. This CertiK report states that these incidents involve violence, intimidation, or threats against victims or their loved ones, such as spouses, children, or employees, to force them to hand over digital assets, private keys, or wallet access. </p><p>The Europeans need to learn how to dodge a wrench.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xJPs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a8e9633-b466-4a8b-b55c-291d7b32c513_1334x874.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xJPs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a8e9633-b466-4a8b-b55c-291d7b32c513_1334x874.jpeg 424w, https://substackcdn.com/image/fetch/$s_!xJPs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a8e9633-b466-4a8b-b55c-291d7b32c513_1334x874.jpeg 848w, https://substackcdn.com/image/fetch/$s_!xJPs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a8e9633-b466-4a8b-b55c-291d7b32c513_1334x874.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!xJPs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a8e9633-b466-4a8b-b55c-291d7b32c513_1334x874.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xJPs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a8e9633-b466-4a8b-b55c-291d7b32c513_1334x874.jpeg" width="1334" height="874" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1a8e9633-b466-4a8b-b55c-291d7b32c513_1334x874.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:874,&quot;width&quot;:1334,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:84410,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/208661964?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a8e9633-b466-4a8b-b55c-291d7b32c513_1334x874.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xJPs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a8e9633-b466-4a8b-b55c-291d7b32c513_1334x874.jpeg 424w, https://substackcdn.com/image/fetch/$s_!xJPs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a8e9633-b466-4a8b-b55c-291d7b32c513_1334x874.jpeg 848w, https://substackcdn.com/image/fetch/$s_!xJPs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a8e9633-b466-4a8b-b55c-291d7b32c513_1334x874.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!xJPs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a8e9633-b466-4a8b-b55c-291d7b32c513_1334x874.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.certik.com/certik-report/intel3d/intel3d-wrench-h1-2026">https://www.certik.com/certik-report/intel3d/intel3d-wrench-h1-2026</a></p><div><hr></div><h4>This will be fine&#8230;</h4><p>Shawn Ryan, the podcaster, partnered to create a privacy and security-focused communications app that promises to:</p><blockquote><p><em>Make calls anonymously - Private calling keeps your number hidden and your conversations untraceable&#8212;so your identity always stays protected</em></p></blockquote><p>I hope they have their legal demand response team fully staffed.  </p><p><a href="https://www.theglacierapp.com/#intro">https://www.theglacierapp.com/#intro</a></p><div><hr></div><h4>Nothing is new under the sun&#8230;</h4><p>Once, a long time ago, I worked as an unloader on the UPS docks. We had to move around 800 packages per hour and yes, they audited us. It was a terrible job, and I only lasted about six months. </p><p>One night, the police arrived and arrested several people involved in a scheme where they placed their own delivery labels over authentic ones to redirect packages to themselves. </p><p>Brilliant, I thought, considering how easy it would be to bring labels with my address into the truck and stick them on some Sharper Image boxes. Of course, I didn&#8217;t do it, and a few months later, I realized I wasn&#8217;t made for physical labor.</p><p>A criminal gang in Tennessee demonstrates that everything that goes around comes around again. Twelve individuals have been indicted for their role in stealing at least $2 million worth of Nike products from Nike&#8217;s North American Logistics Center in Memphis between July 2021 and June 2024. </p><p>How were they doin it&#8230; &#8220;<em>the defendants would identify product that they wanted to resell, locate it in the Nike warehouse, and place shipping labels to predetermined locations throughout the United States where they would retrieve and resell the stolen product.</em>&#8221;</p><p><a href="https://www.justice.gov/usao-wdtn/pr/twelve-indicted-national-cargo-theft-conspiracy-targeting-nike-west-tennessee">https://www.justice.gov/usao-wdtn/pr/twelve-indicted-national-cargo-theft-conspiracy-targeting-nike-west-tennessee</a></p><div><hr></div><h4>The News</h4><p>Device code phishing attacks are all the rage, and this TrustedSec breakdown explains the technique's mechanics.  <a href="https://trustedsec.com/blog/the-new-hotness-in-phishing-device-code-attacks-in-m365">https://trustedsec.com/blog/the-new-hotness-in-phishing-device-code-attacks-in-m365</a></p><p>The Microsoft Q2 Trends and Insights Report again proves that email is your number one threat vector. The company detected 7.6 billion email-based phishing messages in the quarter. But Teams-based phishing attacks gained traction, with significant increases in both DMs and Calls, and the most prominent lure was impersonation of technical support. <a href="https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/">https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/</a></p><p>The cyber threat group name game is a mess, so the Google Threat Intelligence Group is adopting a unified naming schema to track threat actors for a more intuitive, standardized approach. This new system replaces the previous parallel naming schemas used by Mandiant and Google&#8217;s Threat Analysis Group.  OK, but it would be better if the industry reached a collective agreement.  <a href="https://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-system/">https://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-system/</a></p><p>A Louisiana man was convicted of wire fraud, access device fraud, and obstruction of a federal investigation for defrauding two churches he led, obtaining over $340,000 for personal use and obstructing a federal investigation.  <a href="https://www.justice.gov/usao-edla/pr/pastor-found-guilty-jury-wire-fraud-access-device-fraud-and-obstruction-federal">https://www.justice.gov/usao-edla/pr/pastor-found-guilty-jury-wire-fraud-access-device-fraud-and-obstruction-federal</a></p><p>I&#8217;m not sure what triggered a new alert, but this is a well-known, documented fraud problem.  Maybe it&#8217;s the utilization of AI tools? FinCEN issued an alert warning financial institutions about fraud rings targeting Federal Student Aid programs through &#8220;ghost students&#8221; (stolen or synthetic identities) and &#8220;straw students&#8221; (complicit individuals paid to enroll fraudulently). These schemes are known to involve AI-generated documents and AI-powered chatbots to complete coursework, have resulted in significant losses, with the Department of Education preventing over $1 billion in fraud in 2025 alone. <a href="https://www.fincen.gov/system/files/2026-07/FinCEN-Alert-Fraud-Schemes-Targeting-Federal-Student-Aid.pdf">https://www.fincen.gov/system/files/2026-07/FinCEN-Alert-Fraud-Schemes-Targeting-Federal-Student-Aid.pdf</a></p><p>What&#8217;s the Pope know about security?  Probably not much, but the company running his prayer app seems to know even less since it&#8217;s been leaking user data &#8220;for months&#8221;.  <a href="https://san.com/cc/the-popes-prayer-app-has-been-leaking-its-users-info-for-months/">https://san.com/cc/the-popes-prayer-app-has-been-leaking-its-users-info-for-months/</a></p><p>There is an absurd number of security updates and patches in the upcoming macOS 26.6 release.  The effects of AI-enabled security research.  For the better, I suppose.  <a href="https://support.apple.com/en-us/128067">https://support.apple.com/en-us/128067</a></p><div><hr></div><h4>Feedback</h4><p>Send Feedback to matt(at)threatswithoutborders.com</p><div><hr></div><h4>dfir</h4><p>Seth Enoka examines persistence on the Windows OS.  <a href="https://sethenoka.com/persistence-artefacts-services-scheduled-tasks-and-intentional-longevity/">https://sethenoka.com/persistence-artefacts-services-scheduled-tasks-and-intentional-longevity/</a></p><div><hr></div><p style="text-align: center;">No Subscriptions.  No ads. No paid endorsements. The snark is free. And we keep our selfies out of your LinkedIn feed. How about giving us a share!</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>Cool Jobs</h4><p>Senior Manager of Fraud Risk Mitigation, Paylocity.  <a href="https://2000recruiting.paylocity.com/Recruiting/Jobs/Details/46419">https://2000recruiting.paylocity.com/Recruiting/Jobs/Details/46419</a></p><p>Senior Manager of Global Fraud Strategy, Live Nation/Ticketmaster.  <a href="https://livenation.wd503.myworkdayjobs.com/en-US/TMExternalSite/job/Work-From-Home---Texas/Senior-Manager--Global-Fraud-Strategy_JR-91628">https://livenation.wd503.myworkdayjobs.com/en-US/TMExternalSite/job/Work-From-Home---Texas/Senior-Manager--Global-Fraud-Strategy_JR-91628</a></p><h4>Cool Tools</h4><p>Search usernames across 3000 different platforms <a href="https://usersearch.org/index.php">https://usersearch.org/index.php</a></p><p>For those of us iPhone users who need to take pills to keep living.  <a href="https://apps.apple.com/us/app/medication-tracker-dosis/id6758015175">https://apps.apple.com/us/app/medication-tracker-dosis/id6758015175</a></p><div><hr></div><h4>Irrelevant</h4><p>Are autonomous vehicles or Uber drivers more dangerous on the road?  <a href="https://www.city-journal.org/article/autonomous-cars-uber-lyft-drivers-taxis-safety">https://www.city-journal.org/article/autonomous-cars-uber-lyft-drivers-taxis-safety</a></p><div><hr></div><h4>Sign Off</h4><p>You still have time to plan your travel to attend the 2026 IAFCI International Training Conference, being held in Nashville, August 25-27, 2026. A little time in Nash-Vegas is always great for the spirit, and you&#8217;ll probably meet some great people at the conference.</p><p>Thanks for reading another week, and I&#8217;ll see you all next Tuesday.</p><p>Matt</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 296]]></title><description><![CDATA[Cybercrime Investigation Newsletter, week ending July 19, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-296</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-296</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 21 Jul 2026 10:07:32 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Block, Cash App&#8217;s parent company, has reached a $45 million settlement to resolve a multi-state investigation into its fraud protection measures. 46 of the fifty states were listed as plaintiffs.  The probe examined whether the company adequately safeguarded users against fraud, and the settlement aims to address these concerns without an admission of wrongdoing.  <a href="https://www.reuters.com/legal/government/cash-app-parent-settles-states-probe-over-fraud-protections-45-million-2026-07-08/">https://www.reuters.com/legal/government/cash-app-parent-settles-states-probe-over-fraud-protections-45-million-2026-07-08/</a></p><p>Of course, this brings about a common question I get asked, &#8220;What is the difference between the various Peer-to-Peer apps?&#8221;.  Or the most common, &#8220;What&#8217;s the difference between Zelle and the other P2P apps?&#8221; </p><p>Venmo, Cash App, PayPal, Apple Cash and other digital wallet apps create a &#8220;stored-value&#8221; account. When someone sends you money, it lands in the app&#8217;s internal ecosystem, not your bank account. The money stays there until you manually initiate a transfer to your bank.</p><p>Zelle is not a wallet and maintains no internal balance. It is owned by a consortium of major banks, operating under the business name Early Warning Services.<strong> </strong>When a Zelle transfer occurs, it moves funds directly from the sender&#8217;s checking account to the recipient&#8217;s checking account via the banks&#8217; internal clearing networks.</p><p>A great explainer of the services that I keep bookmarked is this NerdWallet article: <a href="https://www.nerdwallet.com/banking/learn/peer-to-peer-p2p-money-transfers">https://www.nerdwallet.com/banking/learn/peer-to-peer-p2p-money-transfers</a></p><div><hr></div><h4>Like Textbooks</h4><p>Regular readers know I advocate studying the affidavits of both arrest and search warrants of significant cybercrime investigations. Fortunately, the suspects don&#8217;t share this view, as these literal &#8220;textbooks&#8221; reveal extensive investigative insights and tips. </p><p>Earlier this month, a member of the &#8220;Scattered Spider&#8221; cybercrime group was arrested and extradited to the United States. The criminal complaint is insightful to say the least, and Tom Kopchak from Hurricane Labs analyzes the affidavit to highlight how extensively Microsoft Windows tracks its users. Clearly, Microsoft doesn&#8217;t activate these features for criminal investigations, but good investigators never say no to free evidence.  </p><p>Some of the highlights include:</p><ul><li><p>Microsoft&#8217;s Global Device ID (GDID) is a persistent identifier that tracks devices across networks and services</p></li><li><p>Investigators correlated multiple accounts, social media profiles, and cloud services using these embedded device identifiers</p></li><li><p>The complaint revealed that Windows users are tracked through persistent identifiers regardless of VPN use or network changes</p></li></ul><p><a href="https://hurricanelabs.com/blog/the-doj-just-proved-that-windows-is-spying-on-you/">https://hurricanelabs.com/blog/the-doj-just-proved-that-windows-is-spying-on-you/</a></p><div><hr></div><h4>Waiting on the call</h4><p>Oklahoma created a new statewide fraud and cybercrime unit to <em>i</em>nvestigate AI-enabled scams and cryptocurrency fraud, and to strengthen law enforcement efforts to address these issues across the state.</p><p>The commander of the new unit specified one duty of the team will be training: <em>&#8220;York said the unit will provide specialized training for police departments and prosecutors throughout the state, helping frontline officers recognize cyber-enabled fraud and collect the evidence necessary for successful investigations.&#8221;</em></p><p>What are we waiting for, Pennsylvania?  Call me.</p><p><a href="https://oklahoma.gov/osbi/about/inside-the-bureau/osbi-fraud-and-cybercrime-unit.html">https://oklahoma.gov/osbi/about/inside-the-bureau/osbi-fraud-and-cybercrime-unit.html</a></p><div><hr></div><h4>The News</h4><p>Flashpoint&#8217;s Intel Team explains that the &#8220;dark web&#8221; is not a single marketplace but a complex, interconnected supply chain of specialized forums organized into a three-tiered ecosystem based on entry barriers, technical expertise, trade quality, and operational security. Low-tier forums are easily accessible hubs for novices sharing low-cost data and tools, while mid-tier forums require some vetting and focus on large-scale fraud like carding and malware distribution with built-in reputation systems. Top-tier forums are exclusive, invitation-only platforms where professional threat actors trade high-value assets like zero-day exploits and ransomware-as-a-service partnerships. <a href="https://flashpoint.io/blog/understanding-illicit-ecosystems-dark-web-forums-cybercrime/">https://flashpoint.io/blog/understanding-illicit-ecosystems-dark-web-forums-cybercrime/</a></p><p>No milk for you!  Coca-Cola&#8217;s Fairlife dairy subsidiary was hit by a ransomware attack, temporarily suspending production operations across the United States. <a href="https://techcrunch.com/2026/07/16/coca-cola-suspended-production-at-its-fairlife-dairy-after-a-ransomware-attack/">https://techcrunch.com/2026/07/16/coca-cola-suspended-production-at-its-fairlife-dairy-after-a-ransomware-attack/</a></p><p>A data breach at AssuranceAmerica exposed the personal data and license numbers of 6.9 million drivers. The company has confirmed the breach, which resulted from malicious activity targeting an employee and included sensitive information such as contact details, insurance information, and claims records.  <a href="https://www.documentcloud.org/documents/28433184-assuranceamerica-data-breach-notice/#document/p5">https://www.documentcloud.org/documents/28433184-assuranceamerica-data-breach-notice/#document/p5</a></p><p>Point Wild exposed that the Phorpiex botnet has been repurposed for a global sextortion spam campaign. The extortionists use the infrastructure to send &#8220;We infection your device and have been recording you&#8221; emails. They demand cryptocurrency in exchange for &#8220;delete everything&#8221;.   <a href="https://www.pointwild.com/threat-intelligence/phorpiex-inside-the-botnet-powering-global-sextortion-spam-operations/">https://www.pointwild.com/threat-intelligence/phorpiex-inside-the-botnet-powering-global-sextortion-spam-operations/</a></p><p>&#8220;Macs don&#8217;t get malware.&#8221; Ah, yes they do, and the Moonlock mid-2026 Threat Report details the current state of macOS malware.  <a href="https://moonlock.com/mid-2026-macos-threat-report">https://moonlock.com/mid-2026-macos-threat-report</a></p><p>Q2 Ransomware Report from ReliaQuest.  <a href="https://reliaquest.com/blog/threat-spotlight-ransomware-and-cyber-extortion-in-q2-2026/">https://reliaquest.com/blog/threat-spotlight-ransomware-and-cyber-extortion-in-q2-2026/</a></p><p>The Internet Crime Complaint Center (IC3) issued a warning about scammers impersonating the Internet Crime Complaint Center.  They suggest you report criminal impersonations to the - Internet Crime Complaint Center.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ONw9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85de7c37-0f16-46db-b404-92b9788178f5_1288x1012.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ONw9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85de7c37-0f16-46db-b404-92b9788178f5_1288x1012.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ONw9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85de7c37-0f16-46db-b404-92b9788178f5_1288x1012.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ONw9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85de7c37-0f16-46db-b404-92b9788178f5_1288x1012.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ONw9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85de7c37-0f16-46db-b404-92b9788178f5_1288x1012.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ONw9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85de7c37-0f16-46db-b404-92b9788178f5_1288x1012.jpeg" width="1288" height="1012" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/85de7c37-0f16-46db-b404-92b9788178f5_1288x1012.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1012,&quot;width&quot;:1288,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:648926,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/207719599?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85de7c37-0f16-46db-b404-92b9788178f5_1288x1012.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ONw9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85de7c37-0f16-46db-b404-92b9788178f5_1288x1012.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ONw9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85de7c37-0f16-46db-b404-92b9788178f5_1288x1012.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ONw9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85de7c37-0f16-46db-b404-92b9788178f5_1288x1012.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ONw9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85de7c37-0f16-46db-b404-92b9788178f5_1288x1012.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.ic3.gov/PSA/2026/PSA260720">https://www.ic3.gov/PSA/2026/PSA260720</a></p><div><hr></div><h4>Feedback</h4><p>Send Feedback to matt(at)threatswithoutborders.com</p><div><hr></div><h4>dfir</h4><p>Magnet Forensics filed a lawsuit against a former employee who left with information about a proprietary exploit available for the Graykey tool and leaked it on a blog for his new company, Paradigm Shift.  <a href="https://www.courtlistener.com/docket/73584326/magnet-forensics-llc-v-del-gaudio/">https://www.courtlistener.com/docket/73584326/magnet-forensics-llc-v-del-gaudio/</a></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>Cool Jobs</h4><p>Lead Risk Investigator, Tilt.  <a href="https://jobs.ashbyhq.com/tilthq/8663dae9-4bc2-4485-b6cd-077701077c3f">https://jobs.ashbyhq.com/tilthq/8663dae9-4bc2-4485-b6cd-077701077c3f </a></p><p>Vice-President of Cybersecurity Strategy and Engagement, Mastercard.  <a href="https://careers.mastercard.com/us/en/job/MASRUSR281394EXTERNALENUS/Vice-President-Cybersecurity-Strategy-and-Engagement">https://careers.mastercard.com/us/en/job/MASRUSR281394EXTERNALENUS/Vice-President-Cybersecurity-Strategy-and-Engagement</a></p><h4>Cool Tools</h4><p>Monitor online prices and get alerts when prices drop. (You can monitor 3 products for free).  <a href="https://spycost.com/en">https://spycost.com/en</a></p><p>LookyLoo is a web interface that captures a webpage and then displays a tree of the domains that call each other.  <a href="https://lookyloo.circl.lu/capture">https://lookyloo.circl.lu/capture</a></p><div><hr></div><h4>Irrelevant</h4><p>The OnePlus 5 was possibly the most impactful smartphone I've ever owned. It featured excellent hardware and a sleek version of Android known as OxygenOS. This custom OS demonstrated Android's potential when all the unnecessary bloatware installed by the phone companies was removed. I quickly upgraded to the 5T, then the 7, before switching back to iOS to be fully integrated in the Apple ecosystem. Over time, however, OnePlus lost its way and is now ceasing operations in North America and Europe. <a href="https://community.oneplus.com/thread/2170715118587871237">https://community.oneplus.com/thread/2170715118587871237</a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9VIL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c47e5ff-0e8d-4b29-a019-e9390becc667_1202x1194.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9VIL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c47e5ff-0e8d-4b29-a019-e9390becc667_1202x1194.jpeg 424w, https://substackcdn.com/image/fetch/$s_!9VIL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c47e5ff-0e8d-4b29-a019-e9390becc667_1202x1194.jpeg 848w, https://substackcdn.com/image/fetch/$s_!9VIL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c47e5ff-0e8d-4b29-a019-e9390becc667_1202x1194.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!9VIL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c47e5ff-0e8d-4b29-a019-e9390becc667_1202x1194.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9VIL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c47e5ff-0e8d-4b29-a019-e9390becc667_1202x1194.jpeg" width="1202" height="1194" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3c47e5ff-0e8d-4b29-a019-e9390becc667_1202x1194.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1194,&quot;width&quot;:1202,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:130161,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/207719599?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c47e5ff-0e8d-4b29-a019-e9390becc667_1202x1194.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9VIL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c47e5ff-0e8d-4b29-a019-e9390becc667_1202x1194.jpeg 424w, https://substackcdn.com/image/fetch/$s_!9VIL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c47e5ff-0e8d-4b29-a019-e9390becc667_1202x1194.jpeg 848w, https://substackcdn.com/image/fetch/$s_!9VIL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c47e5ff-0e8d-4b29-a019-e9390becc667_1202x1194.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!9VIL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c47e5ff-0e8d-4b29-a019-e9390becc667_1202x1194.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h4>Sign Off</h4><p>I wish I had a purpose for all these AI Agents everyone is using. I want to experiment, learn, and make them work for me, but I haven't found a real use case. I read, write, talk, attend meetings, keep a calendar, and manage a to-do list. I receive some emails and respond to some. Yet, at no point in my daily routine have I ever felt overwhelmed to the point I need to implement automation. Using several AI tools has boosted my effectiveness and productivity, but I haven't found a genuine reason to integrate agents into my workflows.  </p><p>Thanks for reading another issue and I&#8217;ll see you all next Tuesday!</p><p>Matt</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p><p>cybercrime cybersecurity investigations financial crime fraud osint cyficrime</p><p></p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 295]]></title><description><![CDATA[Cybersecurity Investigation Newsletter, week ending July 12, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-295</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-295</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 14 Jul 2026 10:09:33 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;ve been reading Marcus Aurelius. In Meditations, he writes that &#8220;the impediment to action advances action, that what stands in the way becomes the way&#8221;.  He wasn&#8217;t thinking about cybercrime investigations, but he could have been.</p><p>In cybercrime investigation, the obstacle isn&#8217;t standing between you and the job. The obstacle is the job.</p><p>In traditional investigations, you build pattern recognition over a career. Burglary rings repeat, fraud schemes repeat, sexual predators repeat. Over time you learn these patterns, and eventually the patterns start doing some of the work for you. Experience compounds.</p><p>Cyber doesn&#8217;t let you have that. The tactics, techniques, and procedures of the bad guys you learned eighteen months ago are already half-obsolete. The threat actor you tracked last quarter has rebranded, retooled, and moved infrastructure twice. You don&#8217;t get to coast on accumulated pattern-recognition, because the patterns don&#8217;t hold still long enough to accumulate.</p><p>Investigators and practitioners new to the cyber game walk in expecting the traditional model where you learn the rules, then apply the rules.  But that ultimately fails, and they get frustrated when the rules keep changing under them. </p><p>Every investigation that doesn&#8217;t fit the last one isn&#8217;t a deviation from the curriculum. It is the curriculum. </p><p>What stands in the way IS THE WAY!  </p><div><hr></div><h4>Have a .beer with that malware</h4><p>While reviewing web filter reports at my organization this week, I was reminded of a report by AlphaMountain because we are seeing .beer domains in our logs.  </p><p>AlphaMountain analyzed domain risk ratings and identified the ten top-level domains with the highest percentage of risky domains. The analysis focused on namespaces most compromised by malicious or high-risk registrations.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ueuf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c909092-379f-4f07-869e-664207001dac_1816x1064.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ueuf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c909092-379f-4f07-869e-664207001dac_1816x1064.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ueuf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c909092-379f-4f07-869e-664207001dac_1816x1064.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ueuf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c909092-379f-4f07-869e-664207001dac_1816x1064.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ueuf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c909092-379f-4f07-869e-664207001dac_1816x1064.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ueuf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c909092-379f-4f07-869e-664207001dac_1816x1064.jpeg" width="1456" height="853" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6c909092-379f-4f07-869e-664207001dac_1816x1064.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:853,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:163272,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/206778650?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c909092-379f-4f07-869e-664207001dac_1816x1064.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ueuf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c909092-379f-4f07-869e-664207001dac_1816x1064.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ueuf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c909092-379f-4f07-869e-664207001dac_1816x1064.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ueuf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c909092-379f-4f07-869e-664207001dac_1816x1064.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ueuf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c909092-379f-4f07-869e-664207001dac_1816x1064.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.alphamountain.ai/10-riskiest-tlds/">https://www.alphamountain.ai/10-riskiest-tlds/</a></p><div><hr></div><h4>Crypto Recover Scams</h4><p>While reviewing the latest Internet Crime Report, I noticed a graphic about crypto recovery scams mentioning &#8220;Fictitious Law Firms." I often see Reddit posts where people say, &#8220;I was scammed trying to recover my funds," but I haven't come across any where scammers pretended to be law firms specializing in crypto recovery. Has anyone encountered this or has a case involving such scammers?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GHTq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F011653f8-0471-46af-a126-30d40f492d7c_1300x652.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GHTq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F011653f8-0471-46af-a126-30d40f492d7c_1300x652.jpeg 424w, https://substackcdn.com/image/fetch/$s_!GHTq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F011653f8-0471-46af-a126-30d40f492d7c_1300x652.jpeg 848w, https://substackcdn.com/image/fetch/$s_!GHTq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F011653f8-0471-46af-a126-30d40f492d7c_1300x652.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!GHTq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F011653f8-0471-46af-a126-30d40f492d7c_1300x652.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GHTq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F011653f8-0471-46af-a126-30d40f492d7c_1300x652.jpeg" width="1300" height="652" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/011653f8-0471-46af-a126-30d40f492d7c_1300x652.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:652,&quot;width&quot;:1300,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:462443,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/206778650?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F011653f8-0471-46af-a126-30d40f492d7c_1300x652.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GHTq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F011653f8-0471-46af-a126-30d40f492d7c_1300x652.jpeg 424w, https://substackcdn.com/image/fetch/$s_!GHTq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F011653f8-0471-46af-a126-30d40f492d7c_1300x652.jpeg 848w, https://substackcdn.com/image/fetch/$s_!GHTq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F011653f8-0471-46af-a126-30d40f492d7c_1300x652.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!GHTq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F011653f8-0471-46af-a126-30d40f492d7c_1300x652.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h4>The News</h4><p>Richard Bejtlich wrote a new E-Book titled &#8220;NDR Essentials: A Practical Guide to Network Detection and Response&#8221;.  And it&#8217;s free!  <a href="https://8645105.fs1.hubspotusercontent-na1.net/hubfs/8645105/resources/ebooks/corelight-ndr-essentials-bk.pdf">https://8645105.fs1.hubspotusercontent-na1.net/hubfs/8645105/resources/ebooks/corelight-ndr-essentials-bk.pdf</a></p><p>CrowdStrike identifies five new AI prompt-injection attacks.  <a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-uncovers-new-prompt-injection-techniques/">https://www.crowdstrike.com/en-us/blog/crowdstrike-uncovers-new-prompt-injection-techniques/</a></p><p>Holy polygamy. A Las Vegas woman orchestrated a massive fraud scheme by marrying 14 men simultaneously since March 2019 to fund her gambling addiction at the Wynn casino. She convinced her victims to send her over $100,000 by fabricating stories about sick relatives in China, only to lose more than $300,000 gambling and cut off contact shortly after receiving the funds. <a href="https://www.dailymail.com/news/article-15962045/vegas-woman-married-multiple-men-china-fraud-gambling.html">https://www.dailymail.com/news/article-15962045/vegas-woman-married-multiple-men-china-fraud-gambling.html</a></p><p>Of course, this is happening.  A new study reveals that terrorist groups like ISIS and Boko Haram are actively exploiting major AI chatbots, including ChatGPT, Claude, and Gemini, for attack planning, weapons development, and operational security. The research, based on 57 interviews with former members, details how these groups have established dedicated AI units to bypass safety filters and use AI for purposes ranging from building explosive devices to replicating dangerous motorcycle stunts, with some factions even considering mass-casualty weapons. <a href="https://the-decoder.com/terrorist-groups-are-using-every-major-ai-chatbot-for-attack-planning-and-weapons-development/">https://the-decoder.com/terrorist-groups-are-using-every-major-ai-chatbot-for-attack-planning-and-weapons-development/</a></p><p>The Federal Reserve Board proposed a rule to establish risk-based anti-money laundering and counterterrorism financing (AML/CFT) program requirements for Board-supervised banks. <a href="https://www.federalreserve.gov/newsevents/pressreleases/bcreg20260707a.htm">https://www.federalreserve.gov/newsevents/pressreleases/bcreg20260707a.htm</a></p><div><hr></div><h4>Feedback</h4><p><em>&#8220;I have been doing this job for almost two decades, and even now, I still see officers and detectives using photos or videos of a monitor when trying to identify suspects. I honestly cannot remember whether you have already covered why getting the original video surveillance footage and still images is so important, not just for evidentiary purposes but also for anything involving facial recognition.  If this fits anywhere in your newsletter universe, I would love to see a full TWOBized breakdown of why this practice is still alive and why it is long overdue to be put out to pasture. Maybe with your level of reach and expertise, you can finally convince some people to stop sending out RFIs with photos that look like they were taken during a sighting of Bigfoot.&#8221;</em></p><p>Thanks for the suggestion, Patrick, and it&#8217;s on the agenda!</p><p>Send Feedback to matt(at)threatswithoutborders.com</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>Cool Jobs</h4><p>Director of Fraud, Gemini.  <a href="https://job-boards.greenhouse.io/embed/job_app?for=gemini&amp;token=7954981&amp;gh_jid=7954981&amp;gh_src=jqrn2aif1us">https://job-boards.greenhouse.io/embed/job_app?for=gemini&amp;token=7954981&amp;gh_jid=7954981&amp;gh_src=jqrn2aif1us</a></p><p>Chief Information Security Officer, HACC.  <a href="https://careers.hacc.edu/jobs/vice-president-information-technology-and-chief-information-security-officer-harrisburg-pa-pennsylvania-united-states-college-wide">https://careers.hacc.edu/jobs/vice-president-information-technology-and-chief-information-security-officer-harrisburg-pa-pennsylvania-united-states-college-wide</a></p><h4>Cool Tools</h4><p>Turn an iPhone into a dumb phone.  Perfect for the kids or grandma.  <a href="https://www.wired.com/story/this-buried-apple-feature-turns-an-iphone-into-the-perfect-kids-dumb-phone/">https://www.wired.com/story/this-buried-apple-feature-turns-an-iphone-into-the-perfect-kids-dumb-phone/</a></p><p>Track over 30K satellites <a href="https://satellitemap.space/">https://satellitemap.space/</a></p><div><hr></div><h4>Irrelevant</h4><p>This company just received FCC approval to test a satellite system that will redirect sunlight to dark areas of the Earth.  The goal is to illuminate dark areas without the use of electric lighting.  It&#8217;s so crazy it might just work!  <a href="https://spacenews.com/fcc-approves-first-reflect-orbital-satellite/">https://spacenews.com/fcc-approves-first-reflect-orbital-satellite/</a></p><h4>Really Irrelevant</h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!o7IO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab5f67b4-cdf7-4c40-8530-8e67e6bf9f3b_1454x776.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!o7IO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab5f67b4-cdf7-4c40-8530-8e67e6bf9f3b_1454x776.jpeg 424w, https://substackcdn.com/image/fetch/$s_!o7IO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab5f67b4-cdf7-4c40-8530-8e67e6bf9f3b_1454x776.jpeg 848w, https://substackcdn.com/image/fetch/$s_!o7IO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab5f67b4-cdf7-4c40-8530-8e67e6bf9f3b_1454x776.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!o7IO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab5f67b4-cdf7-4c40-8530-8e67e6bf9f3b_1454x776.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!o7IO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab5f67b4-cdf7-4c40-8530-8e67e6bf9f3b_1454x776.jpeg" width="1454" height="776" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ab5f67b4-cdf7-4c40-8530-8e67e6bf9f3b_1454x776.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:776,&quot;width&quot;:1454,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:145013,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/206778650?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab5f67b4-cdf7-4c40-8530-8e67e6bf9f3b_1454x776.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!o7IO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab5f67b4-cdf7-4c40-8530-8e67e6bf9f3b_1454x776.jpeg 424w, https://substackcdn.com/image/fetch/$s_!o7IO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab5f67b4-cdf7-4c40-8530-8e67e6bf9f3b_1454x776.jpeg 848w, https://substackcdn.com/image/fetch/$s_!o7IO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab5f67b4-cdf7-4c40-8530-8e67e6bf9f3b_1454x776.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!o7IO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab5f67b4-cdf7-4c40-8530-8e67e6bf9f3b_1454x776.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h4>Sign Off</h4><p>Congratulations to the newly elected 2027-2028 Executive Board of the IAFCI.</p><ul><li><p>President : Steve Lenderman</p></li><li><p>1st VP: Nina Berbiglia</p></li><li><p>2nd VP: Con Nikolaou</p></li><li><p>Secretary: Sam Fadel</p></li><li><p>Treasurer: Stuart Levine</p></li></ul><p>Thank you for reading this issue, and I&#8217;ll see you all next Tuesday!</p><p>Matt</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 294]]></title><description><![CDATA[Cybersecurity Investigation Newsletter, week ending July 5, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-294</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-294</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 07 Jul 2026 11:36:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Every company that&#8217;s sustained a data breach, or worse, had a vendor lose customer data on their behalf, eventually meets the same angry customer. It might be weeks, months, or years later, but the accusation is always the same.</p><p>I&#8217;m a victim of identity theft. You lost my data. This is your fault.</p><p>In their mind, it&#8217;s simple. A to B. Cause and effect.</p><p>William of Ockham laid out the logic back in the 14th century. You know it as Occam&#8217;s razor: the simplest explanation is usually the right one. So the company with the most recent breach must be the cause of Jane&#8217;s identity theft crisis. Of course, it&#8217;s so simple.</p><p>Except probably not.</p><p>Let me introduce you to Dr. John Hickam. In medicine, Occam&#8217;s razor tells doctors to look for one diagnosis that explains all the symptoms. Hickam pushed back and declared that a &#8220;patient can have as many diseases as they damn well please&#8221;. Multiple symptoms don&#8217;t require a single cause; they might just mean multiple things are wrong at once.</p><p>Maybe the comparison between disease and identity theft isn&#8217;t the best, but the theory transfers cleanly. We&#8217;ve all lived through so many breaches, across so many companies, that most of us have PII scattered across the internet and the dark web several times over. When Jane&#8217;s identity gets used, the cause might not be any single breach. It might be all of them, or one nobody&#8217;s found yet.</p><p>Of course, Hickam&#8217;s dictum is not a liability shield. You can&#8217;t say &#8220;sure we lost your data, but so did six other companies, so technically it&#8217;s not our fault.&#8221; That&#8217;s hardly taking responsibility its hiding behind statistics. If your breach exposed something unique such as an account number, a specific internal identifier, something that shows up nowhere else and that exact detail turns up in the fraud, then William of Ockham was right all along. </p><p>Hickam&#8217;s dictum applies in just about everything else. The ones where five different breaches all exposed the same email, social security number, and phone number, and there&#8217;s no way to trace which leak was actually used. That&#8217;s when multiple causes are not just possible, they&#8217;re probable.</p><p>People without investigative training tend to follow Occam&#8217;s razor. Those with experience know that attribution is hard and that most patients... have a lot of disease.</p><div><hr></div><h4>The News</h4><p>&#8220;For more than a decade, EagleBank knowingly allowed favored clients to operate a check kiting scheme, even as compliance personnel repeatedly tried to stop it,&#8221;  Ah, yeah, thats not something you want to hear a U.S. Attorney say about your business.  EagleBank agreed to pay over $9.7 million to resolve a Justice Department investigation into violations of the Bank Secrecy Act. The bank admitted to willfully failing to establish an anti-money laundering program and to allowing a check-kiting scheme to persist for over a decade.  <a href="https://www.justice.gov/opa/pr/eaglebank-agrees-pay-more-97-million-resolve-bank-secrecy-act-investigation">https://www.justice.gov/opa/pr/eaglebank-agrees-pay-more-97-million-resolve-bank-secrecy-act-investigation</a></p><p>Snapchat holds significant account data and metadata, generating content through proper processes despite its temporary design. The key difficulty is obtaining the correct data from the right source within the limited window before it disappears. <a href="https://lucidtruthtechnologies.com/snapchat-evidence-subpoena/">https://lucidtruthtechnologies.com/snapchat-evidence-subpoena/</a></p><p>I believe the SCOTUS got this correct. Location data from a third party is protected by the Fourth Amendment.  In the case Chatrie V. United States, the Supreme Court ruled that &#8220;geofence warrants&#8221; are a constitutional &#8220;search&#8221; under the Fourth Amendment.  <a href="https://reason.com/2026/06/29/in-big-win-for-fourth-amendment-advocates-the-supreme-court-says-geofence-warrants-count-as-a-search/">https://reason.com/2026/06/29/in-big-win-for-fourth-amendment-advocates-the-supreme-court-says-geofence-warrants-count-as-a-search/</a></p><p>End-to-end encryption means the data is secure while in transit.  That protection ends once its unencrypted on the device.  Something some anti-ICE agitators learned the hard way.  <a href="https://theintercept.com/2026/06/17/signal-messages-minneapolis-ice-protests/">https://theintercept.com/2026/06/17/signal-messages-minneapolis-ice-protests/</a></p><p>iOS 27&#8217;s new Trust Insights feature claims to protect users from scams by analyzing interaction patterns, timing, context, and sensor data. If suspicious activity is detected, the feature will flag it, slow down the process, or require additional verification before allowing actions like payments.  <a href="https://www.cultofmac.com/news/ios-27-trust-insights-feature">https://www.cultofmac.com/news/ios-27-trust-insights-feature</a></p><p><em>"For nearly four years, Le Van Hung oversaw an operation that stole the identities of thousands of Americans for use in a sprawling money laundering conspiracy,"</em> said United States Attorney Jay Clayton. <a href="https://thefederalnewswire.com/vietnamese-national-pleads-guilty-in-67-million-identity-theft-and-money-laundering-case"> https://thefederalnewswire.com/vietnamese-national-pleads-guilty-in-67-million-identity-theft-and-money-laundering-case</a></p><div><hr></div><h4>Feedback</h4><p>&#8220;<em>Matt, I just read your explanation of how attackers are using traffic distribution systems and want to thank you for the effort you put into the email each week.  When most people are just creating noise, you add value.&#8221; - </em>Ken.</p><p>Send Feedback to matt(at)threatswithoutborders.com</p><div><hr></div><h4>Training and Events</h4><p>IAFCI International Conference: August 25-27, 2026, Nashville, Tennessee h<a href="https://iafci.connectedcommunity.org/event-home/registration-page">ttps://iafci.connectedcommunity.org/event-home/registration-page</a></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>Cool Jobs</h4><p>Dream job alert: Head of Fraud Intelligence, SentiLink.  <a href="https://jobs.ashbyhq.com/sentilink/3aa87c92-1dfa-4959-ad79-c87ec55f4b4c">https://jobs.ashbyhq.com/sentilink/3aa87c92-1dfa-4959-ad79-c87ec55f4b4c</a></p><h4>Cool Tools</h4><p>Check your files and URLs through a free malware analysis service from Crowdstrike. <a href="https://hybrid-analysis.com/"> https://hybrid-analysis.com/</a></p><div><hr></div><h4>Irrelevant</h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yp1K!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F938e95cb-d10c-471c-bbca-fcb6dea8bc83_998x846.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yp1K!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F938e95cb-d10c-471c-bbca-fcb6dea8bc83_998x846.jpeg 424w, https://substackcdn.com/image/fetch/$s_!yp1K!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F938e95cb-d10c-471c-bbca-fcb6dea8bc83_998x846.jpeg 848w, https://substackcdn.com/image/fetch/$s_!yp1K!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F938e95cb-d10c-471c-bbca-fcb6dea8bc83_998x846.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!yp1K!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F938e95cb-d10c-471c-bbca-fcb6dea8bc83_998x846.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yp1K!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F938e95cb-d10c-471c-bbca-fcb6dea8bc83_998x846.jpeg" width="998" height="846" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/938e95cb-d10c-471c-bbca-fcb6dea8bc83_998x846.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:846,&quot;width&quot;:998,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:98128,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/205429182?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F938e95cb-d10c-471c-bbca-fcb6dea8bc83_998x846.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yp1K!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F938e95cb-d10c-471c-bbca-fcb6dea8bc83_998x846.jpeg 424w, https://substackcdn.com/image/fetch/$s_!yp1K!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F938e95cb-d10c-471c-bbca-fcb6dea8bc83_998x846.jpeg 848w, https://substackcdn.com/image/fetch/$s_!yp1K!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F938e95cb-d10c-471c-bbca-fcb6dea8bc83_998x846.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!yp1K!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F938e95cb-d10c-471c-bbca-fcb6dea8bc83_998x846.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h4>Sign Off</h4><p>In response to the forecast of storms over the Fourth of July weekend, I repeatedly mentioned, &#8220;Yeah, but we really could use a good soaker.&#8221; When the rain finally arrived, it was no doubt a soaker. My region received about 4 to 5 inches of rain in just one hour. Such a large amount of water in a short period, especially over a small area, is an uncontrollable force. These storms affected a broad area across the mid-Atlantic and northeast. I pray everyone is able to recover from the impact.</p><p>Matt</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 293]]></title><description><![CDATA[Cybercrime Investigation Newsletter, week ending June 28, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-293</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-293</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 30 Jun 2026 11:24:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I was recently asked what is the best bang-for-the-buck policy the government could implement to curtail cybercrime.</p><p>Without hesitation, and so quickly it took me by surprise, I said: &#8220;Eliminate voice over IP phone calling.&#8221; I followed up, well, not eliminate, because legitimate businesses are too reliant on the technology, but we can certainly regulate the hell out of it!</p><p>Voice over IP telephony (VOIP) is a primary delivery mechanism for fraud. Banking scams. IRS impersonation. Grandparent scams. Tech support fraud. Romance scams that end in wire transfers. Many of these schemes begin with a phone call, and that call originates from a foreign criminal infrastructure that routes through American telecom networks with almost no friction.</p><p>And it&#8217;s not just the overt scam attempts; it&#8217;s the non-stop stress of dealing with the calls. Many older adults aren&#8217;t getting 5 calls per day; they&#8217;re getting 5 calls per hour&#8230; every hour.  </p><p>We already regulate who can move money. We regulate who can sell securities, who can dispense drugs, and who can sell firearms. We have an entire army working in the name of anti-money laundering. Yet, we do not meaningfully regulate who can provision thousands of American phone numbers and point them at elderly citizens in Kansas.</p><p>When a fraud call reaches an American consumer, nobody in the telecom chain faces meaningful consequences. The upstream carrier made money, the reseller made money, and the number provisioner made money.  But the victim lost money, and none of the commercial businesses that facilitated it are ever held accountable. </p><p>Let&#8217;s make upstream carriers jointly liable for the volume of fraud originating on their infrastructure when they cannot demonstrate they performed adequate due diligence on their customers. This is not a novel concept. It is how banking regulators treat financial institutions under the Bank Secrecy Act. The bank didn&#8217;t launder the money, but the bank faces consequences if it can&#8217;t show it tried to prevent it. Telecoms should work the same way.</p><p>A criminal call center in Southeast Asia can acquire thousands of U.S. area code numbers through layered resellers with essentially no identity verification that would survive scrutiny. This is a regulatory gap, not a technical limitation.</p><p>Mandate KYC standards for bulk number provisioning that mirror what we already require for financial accounts. If you want to provision more than the defined threshold, you verify who you are, where you operate, and what you&#8217;re using them for. If you&#8217;re a legitimate business, this is a minor compliance cost, but if you&#8217;re a fraud operation, this is a huge obstacle.</p><p>Well, we have STIR/SHAKEN, right? Most STIR/SHAKEN enforcement focuses on domestic origination, but most fraudulent calls don&#8217;t originate domestically. They come in through international gateways, where authentication requirements are weaker and oversight is thinner.</p><p>How about we treat inbound international VoIP traffic as its own regulatory category? Require carriers to label it as such at the point of delivery so consumers know that the call claiming to be from their local bank actually originated overseas. And impose strict accountability on the gateway carriers who accept that traffic. If you&#8217;re the bridge between a foreign VoIP network and the American phone system, you bear responsibility for what crosses that bridge.</p><p>The bad guys are operating in a space where the cost of access is minimal and the cost of getting caught is effectively zero. Let&#8217;s change the economics, shift the liability upstream, and require the Telcom industry to know its customers the way every bank in America is required to know its account holders.</p><p>Cue the telecom meltdown in 3..2..1...</p><p>I&#8217;m not suggesting we require Telcoms to solve this complex technical problem. VOIP providers just need to know who their customers are and take responsibility for the traffic on their network. Every other regulated industry in America does exactly that.</p><div><hr></div><h4>Criminal doorbells</h4><p><span>One of the most common things I hear from small business owners is: "I'm not a target. I don't have anything worth stealing." Do you have an email account or website? I ask. That's enough. They'll use those resources to attack others who do have financial resources.<br><br>And as this new report from the Digital Citizens Alliance and </span><strong><a href="https://www.linkedin.com/company/risk3sixty/"><span>risk3sixty</span></a></strong><span> shows, they'll be just as happy with access to your Internet connection as with access to your bank account. The report highlights how vulnerable IoT devices such as doorbells, security cameras, and other smart home technology can be hijacked to route criminal traffic and help attackers hide their true location.<br><br>Even if you don't have money to steal, turning your home Internet connection into a proxy server is a win for the bad guys.</span></p><p><a href="https://23693881.hs-sites.com/hubfs/resproxy/DCA_Cybercrime-by-Doorbell-Report.pdf?hsCtaAttrib=215683707287">https://23693881.hs-sites.com/hubfs/resproxy/DCA_Cybercrime-by-Doorbell-Report.pdf?hsCtaAttrib=215683707287</a></p><div><hr></div><h4>The News</h4><p>And now we have Sandwich Bots.  Named after an infamous pedophile, no less. What the hell is a sandwich bot?  The JaredfromSubway.eth sandwich-attack bot lost at least $7.5 million in a reverse honeypot exploit. The attacker tricked the bot into granting approvals for token spending and stole its assets.  <a href="https://www.chainalysis.com/blog/sandwich-attack-jaredfromsubway-hack/">https://www.chainalysis.com/blog/sandwich-attack-jaredfromsubway-hack/</a></p><p>A task force comprising private technology companies and international law enforcement executed a major operation to dismantle the infrastructure of three &#8220;cybercrime as a service&#8221; malware operations, SocGholish, Amadey, and StealC, which are critical components of the cyberattack supply chain. The effort seized 326 servers and 142 domains, disrupting the highways criminals use to deploy ransomware, commit financial fraud, and compromise critical infrastructure. <a href="https://blogs.microsoft.com/on-the-issues/2026/06/24/scaling-cybercrime-disruption-through-innovation-and-ai/">https://blogs.microsoft.com/on-the-issues/2026/06/24/scaling-cybercrime-disruption-through-innovation-and-ai/</a></p><p>Google is implementing hand-gesture verification to ensure you&#8217;re not a bot.  But testing shows it can be beaten by using stock images of hands.  <a href="https://www.neowin.net/news/googles-new-hand-wave-recaptcha-can-be-bypassed-with-a-stock-photo/">https://www.neowin.net/news/googles-new-hand-wave-recaptcha-can-be-bypassed-with-a-stock-photo/</a></p><p>A recent study shows that US adults now spend an average of $111 per month, totaling $1,332 annually, on services such as streaming platforms like Youtube, Netflix, Hulu, and Prime. The authors point out the problem of &#8220;subscription creep,&#8221; where Americans waste about $21 each month ($252 annually) on unused subscriptions an increase from the previous year. Millennials spend the most, at $125 per month.  <a href="https://www.cnet.com/tech/services-and-software/subscription-survey-2026/">https://www.cnet.com/tech/services-and-software/subscription-survey-2026/</a></p><div><hr></div><h4>The the best thing I read this week&#8230;</h4><p><em>&#8220;AI, this cutting-edge technology, actually makes the oldest skills more valuable than ever. Reading. Thinking. Knowing things. Empathy. Having taste. Understanding context. Detecting lies or nonsense.&#8221;</em> - Ryan Holiday.</p><p><a href="https://ryanholiday.net/39-or-so-lessons-on-the-way-to-39/">https://ryanholiday.net/39-or-so-lessons-on-the-way-to-39/</a></p><div><hr></div><h4>dfir</h4><p>Sans instructor Ovie Carroll agrees with me (Issue 290) that AI agents will provide cover for cybercriminals, or as he puts it, a defense of &#8220;Some Artificial Intelligence Did It&#8221;.  <a href="https://ovie.coffee/f/ai-did-it-why-digital-investigative-analysts-must-not-outsource">https://ovie.coffee/f/ai-did-it-why-digital-investigative-analysts-must-not-outsource</a></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>Cool Jobs</h4><p>Manager of Cybersecurity Operations, Dutch Bros Coffee.  <a href="https://careers.dutchbros.com/us/en/job/DUTDBCUSREQ18645EXTERNALENUS/Manager-Cybersecurity-Operations">https://careers.dutchbros.com/us/en/job/DUTDBCUSREQ18645EXTERNALENUS/Manager-Cybersecurity-Operations</a></p><p>Director of Field Loss Prevention, Dicks Sporting Goods.  <a href="https://dickssportinggoods.wd1.myworkdayjobs.com/DSG/job/Remote---US/Director-of-Field-Loss-Prevention_202609785">https://dickssportinggoods.wd1.myworkdayjobs.com/DSG/job/Remote---US/Director-of-Field-Loss-Prevention_202609785</a></p><p>Senior Investigation Partner, QVC.  <a href="https://qvc.wd5.myworkdayjobs.com/QRG/job/Pennsylvania-Remote/Senior-Investigations-Partner_R82560">https://qvc.wd5.myworkdayjobs.com/QRG/job/Pennsylvania-Remote/Senior-Investigations-Partner_R82560</a></p><h4>Cool Tools</h4><p>Carrier look-up service.  <a href="https://www.freecarrierlookup.com/">https://www.freecarrierlookup.com/</a></p><div><hr></div><h4>Irrelevant</h4><p>Clearly inspired by Lenderman, Darius Foroux emphasizes the importance of personal branding, particularly in the era of AI.  <a href="https://dariusforoux.com/why-your-personal-brand-is-your-most-valuable-asset-in-the-ai-era/?">https://dariusforoux.com/why-your-personal-brand-is-your-most-valuable-asset-in-the-ai-era/?</a></p><div><hr></div><h4>Sign Off</h4><p>I&#8217;m never quite sure how to refer to Pennsylvania in general. It&#8217;s not exactly part of the Northeast, and it&#8217;s not really Mid-Atlantic, which is why it&#8217;s called the &#8220;Keystone State.&#8221; However you refer to it, one thing to agree on: it&#8217;s HOT here. And I know many of you are experiencing the same. Stay cool!</p><p>Happy 250th America!  Let&#8217;s do it for 250 more.</p><p>See you all next week.</p><p>Matt</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 292]]></title><description><![CDATA[Cybercrime Investigations Newsletter, week ending June 21, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-292</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-292</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 23 Jun 2026 11:30:46 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Last week, the FBI&#8217;s Internet Crime Complaint Center issued a PSA warning the public about criminal use of Traffic Distribution Systems (TDS) to redirect users to phishing pages, malware, and financial fraud schemes. The PSA does a surprisingly decent job explaining the concept. But let me give you a better one.</p><p>Think of a TDS as an air traffic controller for web traffic. Every time you click a link, the system takes a fraction of a second to analyze your connection, your operating system, your browser, your IP address, your geographic location, and then routes you to the most appropriate version of whatever resource you&#8217;re trying to reach. You click a link, the TDS profiles you, and sends you somewhere.</p><p>You&#8217;ve experienced this for most of your online life and never noticed. It&#8217;s how you land on a mobile-optimized page when you&#8217;re on your phone and the full desktop version when you&#8217;re on your laptop. It&#8217;s how the website knows to serve you content in English instead of French. The web publishing and digital marketing industries rely heavily on these systems.</p><p>And of course, the bad guys flip it.</p><p>When criminals gain access to TDS infrastructure or build their own, the same capability becomes a precision-targeting mechanism. A malicious TDS selectively redirects users to compromised or fake login sites hosting phishing pages designed for financial fraud, or prompts them to download malware disguised as software updates. The user thinks they followed a normal link. The TDS decides where they actually land.</p><p>This is also how the scammers get their payloads right. A Windows user receives a pop-up that impersonates Microsoft Defender. A Mac user gets a generic Apple security alert. Someone on a desktop trying to follow a link from an SMS message simply goes nowhere; the TDS drops them because the setup doesn&#8217;t fit the target profile. Same link. Different outcomes, based entirely on what the system learned about you in that invisible half-second before anything loaded.</p><p>The filtering capability is where this gets really insidious.</p><p>Malicious TDS operators collect your IP address, operating system, location, device type, and browser information to determine whether you&#8217;re worth attacking. They can display completely harmless content to unwanted visitors, like us security researchers, analysts, and investigators, while routing future victims to the fraud infrastructure.</p><p>Here&#8217;s roughly how that triage looks in practice:</p><ul><li><p>The connection is coming from a known VPN or Tor browser exit node? Drop it. This could be a researcher.</p></li><li><p>The user is on a M5 MacBook Pro running Tahoe 26.5 and the Brave browser.<span> </span>Drop.<span> </span>They are an advanced user.</p></li><li><p>The traffic originates from a Dell Latitude 5520 running Windows 10 and Chrome 111.<span> </span>PERFECT, send them on through!</p></li></ul><p>The criminals aren&#8217;t spraying and praying. They&#8217;re running a filtering operation. They&#8217;re actively discarding sophisticated users and security professionals to concentrate their attacks on the most vulnerable, least-defended people in the pool.</p><p>So how does this affect us, the investigators and prevention professionals?</p><p>First, the bad guys professionals. They are using legitimate enterprise technology at its full capability, the same tools the digital marketing industry uses to optimize ad spend, and redirecting it toward fraud. This is not groundbreaking news, but we need to acknowledge it.</p><p>Second, non-technical users are completely outmatched by this. There is nothing for them to see. No warning. No obvious sign that something went wrong. The most dangerous part of the attack happens before a single pixel loads on their screen. They clicked a link. The system made a decision about them. And they went where they were sent.</p><p>I&#8217;d like to close with something uplifting other than the notion that the average user is absolutely cooked.<span> </span>But I think we all know where we&#8217;re at.</p><p>Instead, I&#8217;ll direct you to the PSA, which does offer helpful prevention tips.</p><p><a href="https://www.ic3.gov/PSA/2026/PSA260618">https://www.ic3.gov/PSA/2026/PSA260618</a></p><div><hr></div><h4>Funny&#8230;not funny</h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yw-Z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3357fe61-67dc-44e8-81e0-5dcf4c86756c_1548x1302.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yw-Z!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3357fe61-67dc-44e8-81e0-5dcf4c86756c_1548x1302.jpeg 424w, https://substackcdn.com/image/fetch/$s_!yw-Z!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3357fe61-67dc-44e8-81e0-5dcf4c86756c_1548x1302.jpeg 848w, https://substackcdn.com/image/fetch/$s_!yw-Z!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3357fe61-67dc-44e8-81e0-5dcf4c86756c_1548x1302.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!yw-Z!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3357fe61-67dc-44e8-81e0-5dcf4c86756c_1548x1302.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yw-Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3357fe61-67dc-44e8-81e0-5dcf4c86756c_1548x1302.jpeg" width="1456" height="1225" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3357fe61-67dc-44e8-81e0-5dcf4c86756c_1548x1302.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1225,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:542017,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/203078803?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3357fe61-67dc-44e8-81e0-5dcf4c86756c_1548x1302.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yw-Z!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3357fe61-67dc-44e8-81e0-5dcf4c86756c_1548x1302.jpeg 424w, https://substackcdn.com/image/fetch/$s_!yw-Z!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3357fe61-67dc-44e8-81e0-5dcf4c86756c_1548x1302.jpeg 848w, https://substackcdn.com/image/fetch/$s_!yw-Z!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3357fe61-67dc-44e8-81e0-5dcf4c86756c_1548x1302.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!yw-Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3357fe61-67dc-44e8-81e0-5dcf4c86756c_1548x1302.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h4>The News</h4><p>Rule 1: Revoke access before they leave the building. A former Iowa school district IT support specialist received a 21-month prison sentence for a cyberattack carried out over 21 months after retaining unauthorized credentials post-departure in April 2023. The individual disrupted classroom activities by deleting the district&#8217;s Facebook page, revoking employees&#8217; access to platforms like Apple School Manager and Schoology, and erasing nine Gmail accounts, including those of the IT director and superintendent. This caused tens of thousands of dollars in damages and major educational disruptions. Holy DFIR failure! Why did it take 21 months to identify that the activity stemmed from a single account&#8212;belonging to a former employee? <a href="https://www.bleepingcomputer.com/news/security/ex-school-district-employee-jailed-for-hacks-on-former-employer/">https://www.bleepingcomputer.com/news/security/ex-school-district-employee-jailed-for-hacks-on-former-employer/</a></p><p>I teach a class that demonstrates how to convert an IP address to binary (1s and 0s) using binary math. I also explain Network Address Translation (NAT), which is essential because IPv4 addresses are running out. A common question I get is whether this will become unnecessary once we transition to IPv6. Maybe, but I plan to be retired long before that happens. Currently, IPv6 usage is only about 50%. <a href="https://blog.apnic.net/2026/04/28/google-hits-50-ipv6/">https://blog.apnic.net/2026/04/28/google-hits-50-ipv6/</a></p><p>The job market is already challenging! The U.S. Department of Justice and FBI confiscated 13 websites run by alleged Chinese agents. These sites targeted current and former U.S. security clearance holders with fake &#8220;consulting&#8221; job offers to obtain sensitive or classified information. The seized domains, including names like Centrik Global Consulting and SafeSec Group, appeared legitimate with fake contracts and confidentiality agreements, while they were actually used for international money laundering and identity theft. <a href="https://www.justice.gov/opa/pr/justice-department-fbi-disable-13-websites-backed-suspected-chinese-agents-sought-sensitive">https://www.justice.gov/opa/pr/justice-department-fbi-disable-13-websites-backed-suspected-chinese-agents-sought-sensitive</a></p><p>The criminals need to come to America and eat some brisket.  The FIFA World Cup 2026 is being exploited by cybercriminals through fraudulent domains, social media, and activity on crime forums. Threat actors are using fake ticket offers, VIP schemes, and unauthorized streaming platforms to lure victims into payment fraud and identity theft.<a href="https://cyble.com/blog/operation-fantrap-fifa-2026-fraud-ecosystem/">  https://cyble.com/blog/operation-fantrap-fifa-2026-fraud-ecosystem/</a></p><p>Vinnie Liu from Bishop Fox describes the progression of cyber offensive strategies across three distinct eras, asserting that we've recently entered a new, perilous stage fueled by artificial intelligence. The initial phase, &#8220;Low and Slow,&#8221; emphasized stealth and patience, with attackers such as Volt Typhoon remaining within networks for years to map environments unnoticed. The second phase, &#8220;Loud is the Point,&#8221; coincided with the rise of ransomware, where attackers adopted performative tactics, leveraging encryption and data leaks to negotiate extortion and industrialize their operations via Ransomware-as-a-Service. The current and emerging third phase, &#8220;Smash and Grab,&#8221; discards both patience and negotiation, focusing instead on rapid, parallel attacks. Liu also introduces the term &#8220;LLM-as-C2,&#8221; referring to command and control through Large Language Models (AI). <a href="https://bishopfox.com/blog/the-smash-and-grab-era">https://bishopfox.com/blog/the-smash-and-grab-era</a></p><div><hr></div><h4>Feedback</h4><p>For context, see the feedback section of Issue 290, where I challenged someone to turn on their LinkedIn &#8220;open to work&#8221; flag to see what happens at their current workplace.</p><p><em>&#8220;Good morning, Matt.  Saw your newsletter this morning and I thought I&#8217;d share my experience. I&#8217;m currently employed with a state agency but I&#8217;m in a, let&#8217;s say, complicated situation, so it&#8217;s time to move on. I activated my &#8220;Open to Work&#8221; banner and initially got some nibbles from scammers, but so far, nothing from any co-workers I&#8217;m connected to. I should point out that one is within a few years of retirement, a second took an offer with a different agency, and the third is looking for a new job elsewhere. Two already knew I was looking and I&#8217;m sure it&#8217;s not surprising to anyone else in the office that I&#8217;m looking. I guess my point is that either no one cares or it&#8217;s obvious you&#8217;re looking so no one is surprised when you make it LinkedIn official. Take from that what you will</em>.&#8221; </p><p>Yikes,  unfortunately, it sounds like there is a management issue at this workplace.  I hope you land somewhere better.</p><p>Send Feedback to matt(at)threatswithoutborders.com</p><div><hr></div><h4>dfir</h4><p>This expert on deepfakes says we&#8217;ve reached the point where you can&#8217;t trust what you see on a screen.  <a href="https://www.nytimes.com/2026/06/14/us/ai-deepfake-hany-farid.html">https://www.nytimes.com/2026/06/14/us/ai-deepfake-hany-farid.html</a></p><div><hr></div><p style="text-align: center;">Sharing is caring.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>Cool Jobs</h4><p>Digital Forensics Expert Witness, LevelBlue.  <a href="https://jobs.dayforcehcm.com/en-US/twh/CANDIDATEPORTAL/jobs/3110">https://jobs.dayforcehcm.com/en-US/twh/CANDIDATEPORTAL/jobs/3110</a></p><h4>Cool Tools</h4><p>Listen to radio stations from around the world. <a href="https://radio.garden/"> https://radio.garden/</a></p><p>Search various sanction lists for people and persons <a href="https://www.opensanctions.org/">https://www.opensanctions.org/</a></p><div><hr></div><h4>Irrelevant</h4><p>Learn something - 1700 online courses from top universities, for free.  <a href="https://www.openculture.com/freeonlinecourses">https://www.openculture.com/freeonlinecourses</a></p><div><hr></div><h4>Sign Off</h4><p>I&#8217;ve enjoyed this year&#8217;s NCAA Baseball World Series.  I know we&#8217;re currently in the throes of soccer mania, but baseball is still the greatest game.  Congratulations to the Oklahoma Sooners on their win!</p><p>See you all next week.</p><p>Matt</p><p>&#8220;A LIFE SPENT MAKING MISTAKES IS NOT ONLY MORE HONORABLE, BUT MORE USEFUL THAN A LIFE SPENT DOING NOTHING.&#8221;</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 291]]></title><description><![CDATA[Cybercrime Investigation Newsletter, week ending June 14, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-291</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-291</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 16 Jun 2026 09:40:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lkkz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07f3f957-f680-4ee2-b274-e8ca2ac66a24_600x600.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>There&#8217;s a question that circulates endlessly through every fraud conference, LinkedIn threads, and panel discussions. <strong>What&#8217;s the biggest fraud threat facing organizations right now?</strong> You already know the answer, because it&#8217;s always the same answer, delivered with the same misplaced confidence, almost like a reflex. AI. Of course, it&#8217;s AI.</p><p>Nobody ever mentions the telephone. Which is how my organization and it&#8217;s customers get attacked multiple times every day. Yeah, the phone. Scammers are calling the business, pretending to be customers, and calling our customers to pretend to be the business. Classic social engineering, zero sophistication required, and highly effective. </p><p>And I pay attention enough to know that&#8217;s the correct answer for a lot of organizations, too. But the telephone doesn&#8217;t trend, so here we are.</p><p>Fine. Let&#8217;s say the answer is AI.  The problem isn&#8217;t the answer, and it&#8217;s probably more correct than not. It&#8217;s what happens immediately afterward when someone asks the inevitable follow-up: Can you give me an example? Panic. What you usually get is something vague about phishing emails and voice cloning. Sure, but that&#8217;s not an answer so much as a category, and categories don&#8217;t hold up when someone actually pushes back.</p><p>Google recently filed a lawsuit against a Chinese cybercrime network operating under the name Outsider Enterprise, alleging the group used Google&#8217;s own Gemini AI to automate a phishing campaign at genuinely impressive scale. The network operated primarily through Telegram, offered phishing-as-a-service to other criminals, and provided nearly 300 ready-to-deploy templates along with instructions on how to use Gemini to generate convincing fake websites impersonating Google, YouTube, and the New York E-ZPass system, among others. Google identified roughly 9,000 fraudulent sites and over a million malicious URLs tied to the campaign. The group sent more than 2.5 million scam text messages to Android users.</p><p>And the FBI and its partners, including Google, just took the operation offline.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Srcv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e891032-8942-4f1a-ae66-a4b011850eff_984x1264.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Srcv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e891032-8942-4f1a-ae66-a4b011850eff_984x1264.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Srcv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e891032-8942-4f1a-ae66-a4b011850eff_984x1264.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Srcv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e891032-8942-4f1a-ae66-a4b011850eff_984x1264.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Srcv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e891032-8942-4f1a-ae66-a4b011850eff_984x1264.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Srcv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e891032-8942-4f1a-ae66-a4b011850eff_984x1264.jpeg" width="984" height="1264" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8e891032-8942-4f1a-ae66-a4b011850eff_984x1264.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1264,&quot;width&quot;:984,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:385108,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/202052480?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e891032-8942-4f1a-ae66-a4b011850eff_984x1264.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Srcv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e891032-8942-4f1a-ae66-a4b011850eff_984x1264.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Srcv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e891032-8942-4f1a-ae66-a4b011850eff_984x1264.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Srcv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e891032-8942-4f1a-ae66-a4b011850eff_984x1264.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Srcv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e891032-8942-4f1a-ae66-a4b011850eff_984x1264.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The lawsuit itself is worth a moment&#8217;s attention. Google isn&#8217;t the first to take this approach, as Microsoft, Cloudflare, and others have pursued civil litigation against cybercrime actors who abused their platforms. It&#8217;s an interesting strategy, and the practical ceiling is obvious. Bringing meaningful legal consequences against a criminal operating out of China, North Korea, or Russia is less a law-enforcement action and more a very expensive message. Whether anyone receives it is another question entirely.</p><p>So, the next time someone asks us to name the biggest fraud threat and expects us to perform the AI genuflection, we can do better than a generic response. Say Outsider Enterprise. Explain what they built, how they used it, and what it produced. Answer like someone who actually follows this space, not like someone who learned the buzzword and stopped there.</p><p>Read the complaint here:  <a href="https://fingfx.thomsonreuters.com/gfx/legaldocs/byvrdoelzve/GOOGLE%20SCAMMER%20LAWSUIT%20outsidercomplaint.pdf">https://fingfx.thomsonreuters.com/gfx/legaldocs/byvrdoelzve/GOOGLE%20SCAMMER%20LAWSUIT%20outsidercomplaint.pdf</a></p><p>It&#8217;s really well written and worth your time to read.  Among other nuggets, on page 20, they explain the process for bypassing MFA.</p><div><hr></div><h4>Ok&#8230; let&#8217;s go!</h4><blockquote><p><em>At least 13 federal agencies work on countering scams and each one largely works independent of the others. Eight of these agencies receive complaints about scams, which can lead to confusion and frustration for Americans who want to report a scam. For example, an American who has been targeted by a tax-related scam could potentially report the scam to the FBI&#8217;s internet crimes website, the Federal Trade Commission&#8217;s fraud reporting website, the IRS&#8217;s tax fraud and scams reporting website, or by contacting the Treasury Inspector General for Tax Administration. The federal government needs a comprehensive, unified plan to deal with scams, and the American people deserve a clear, easy way to report scams and get connected with help.</em></p></blockquote><p>U.S. Senators Hassan from Florida and Scott from Florida introduced the &#8220;reportscams.gov Act&#8221; which aims to consolidate the fraud-fighting efforts of the federal government.  <a href="https://www.hassan.senate.gov/imo/media/doc/reportscamsgovonepager.pdf">https://www.hassan.senate.gov/imo/media/doc/reportscamsgovonepager.pdf</a></p><div><hr></div><h4>The News</h4><p>This question is being asked more often and with greater urgency&#8212;are anti-money laundering (AML) efforts justifiable given their costs? AML frameworks face increased criticism for high compliance costs, generating unused data, raising privacy concerns, and lacking clear evidence of effectiveness in preventing illicit transactions. Recent studies indicate that high compliance rates do not always correlate with reduced illegal activity. In this article, the authors examine the future of AML efforts.  <a href="https://www.theregreview.org/2026/06/13/seminar-are-anti-money-laundering-regulations-effective-and-worth-the-cost/">https://www.theregreview.org/2026/06/13/seminar-are-anti-money-laundering-regulations-effective-and-worth-the-cost/</a></p><p>Is this the end of &#8220;burner phones&#8221;? The FCC has proposed new rules intended to combat robocalls by requiring phone carriers to collect extensive personal data, including government ID, physical addresses, and alternative phone numbers, before activating service.  <a href="https://docs.fcc.gov/public/attachments/DOC-421309A1.pdf">https://docs.fcc.gov/public/attachments/DOC-421309A1.pdf</a></p><p>The FBI has initiated &#8220;Operation Riptide,&#8221; a nationwide effort to break down cybercrime networks by targeting the criminals, their infrastructure, and financial systems, especially following over $20 billion in losses from more than 1 million cybercrime complaints last year.  <a href="https://www.fbi.gov/video-repository/operation-riptide-060926.mp4/view">https://www.fbi.gov/video-repository/operation-riptide-060926.mp4/view</a></p><p>An international law enforcement operation dismantled a popular money-laundering service known as &#8216;AudiA6&#8217;, believed to have laundered over EUR 336 million from 2022 to 2025. The service, associated with the &#8216;Dark2Web&#8217; forum, was investigated by US and Polish authorities in collaboration with international partners.  <a href="https://www.europol.europa.eu/media-press/newsroom/news/ransomware-gangs-cut-eur-336-million-audia6-crypto-laundering-pipeline">https://www.europol.europa.eu/media-press/newsroom/news/ransomware-gangs-cut-eur-336-million-audia6-crypto-laundering-pipeline</a></p><p>The Bank Policy Institute urged federal regulators to clarify oversight of stablecoin transactions after issuance. Current AML rules fail to adequately impose compliance obligations on DeFi firms, certain crypto custodians, and exchanges.  <a href="https://www.pymnts.com/cpi-posts/banking-groups-pitch-anti-money-laundering-rules-for-stablecoins/">https://www.pymnts.com/cpi-posts/banking-groups-pitch-anti-money-laundering-rules-for-stablecoins/</a></p><p>The U.S. government tells Anthropic to hit the brakes on their latest release.  <a href="https://www.anthropic.com/news/fable-mythos-access">https://www.anthropic.com/news/fable-mythos-access</a></p><div><hr></div><h4>Feedback</h4><p>Send Feedback to matt(at)threatswithoutborders.com</p><div><hr></div><h4>A vote that actually matters</h4><p>A long time ago, I watched a guy turn a hotel room key card into a working Visa card. Before you shrug, this was well before card fraud became a punchline in every breach notification email and the fear of every ATM user. To a young detective freshly assigned to financial crimes, seeing this done was like watching magic.</p><p>That guy was Steve Lenderman. And now he&#8217;s running for President of the International Association of Financial Crime Investigators. Not the Delaware Valley Chapter, which he&#8217;s led for the past seven years. The whole organization.</p><p>Regular Tw/oB readers know my opinion on the IAFCI as an organization has been, well, complicated. That&#8217;s a diplomatic way of saying the past few years of leadership have been disappointing. </p><p>Which is exactly why this endorsement isn&#8217;t a formality. It&#8217;s a correction.</p><p>You&#8217;d be hard-pressed to find anyone more committed to fraud and financial crime prevention than Steve. He&#8217;s held leadership roles simultaneously in the IAFCI Delaware Valley Chapter, the Delaware chapter of ACFE, and the Delaware Fraud Working Group. That&#8217;s not resume padding, that&#8217;s someone who actually shows up.</p><p>I served as a Vice President under Steve for four of his seven years leading the Del-Val chapter. I can tell you firsthand that he is the embodiment of getting shit done. Not performative leadership. Not committee theater. Actual results.</p><p>IAFCI members receive ballots this week, including Steve&#8217;s full credentials. I&#8217;m not going to rehash them here.</p><p>What I will say is this: if five years of <em>Threats Without Borders</em> has earned me any credibility with you (there must be some reason you&#8217;re still reading), then take this for what it&#8217;s worth. The IAFCI needs forward-thinking and action-oriented leadership. <strong>I&#8217;m voting for Steve Lenderman</strong>. I hope you will, too.</p><div><hr></div><h4>dfir</h4><p>The team at Unit 42 highlights a new macOS artifact, App.MenuItem, that logs user menu selections, providing granular data on user intent and actions across the operating system. <a href="https://unit42.paloaltonetworks.com/new-macos-artifact-discovered/">https://unit42.paloaltonetworks.com/new-macos-artifact-discovered/</a></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>Cool Jobs</h4><p>Fraud Countermeasures Specialist - Veriff.  <a href="https://www.veriff.com/careers/position/8590317002">https://www.veriff.com/careers/position/8590317002</a></p><h4>Cool Tools</h4><p>Remove the background from an image.  <a href="https://www.remove.bg/">https://www.remove.bg/</a></p><p>How loud is your workspace?  In-browser decibel meter.  <a href="https://noisedecibelmeter.com/">https://noisedecibelmeter.com/</a></p><div><hr></div><h4>Irrelevant</h4><p>Paul Graham explains how to become a billionaire (and why all these eat-the-rich politicians are so wrong).  <a href="https://paulgraham.com/earn.html">https://paulgraham.com/earn.html</a></p><div><hr></div><h4>Sign Off</h4><p>I don&#8217;t understand <s>football</s> soccer.  One of the happiest days of my early parenting was when my youngest son said he was done with it. Needless to say, I could not care less about the World Cup tournament.  But I am completely enthralled with the abject glee of the foreign soccer fans currently visiting America to see the games. Everything from the beauty of our natural resources to the kindness of our people to the sheer excess of our eateries has created must-see social media content.  A group of Norwegians tasting a brisket sandwich at Buc-ee's, or the Germans experiencing a Waffle House at 1 am, is absolutely heart-warming!</p><p>Matt</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 290]]></title><description><![CDATA[Cybersecurity Investigation Newsletter, week ending June 7, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-290</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-290</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 09 Jun 2026 11:46:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I want to give full credit to Jay Dubina for sparking my thoughts on this topic. He&#8217;s the first person I&#8217;ve heard delve into the idea of agentic AI commerce fraud to this extent. I&#8217;ve been aware of the concept, but I heard Jay discuss it last week, and he really brought it to life for me. </p><p>We know how to investigate cyber-fraud:  Follow the money. Find the device. Put the bad guy behind the keyboard.</p><p>What happens when there&#8217;s no keyboard?</p><p>Agentic AI is here, and it&#8217;s changing how commerce works at a fundamental level. These aren&#8217;t chatbots answering questions, they&#8217;re autonomous systems with tools, stored credentials, and decision-making authority. You give them a goal and they execute it.</p><p>And so we&#8217;re all on the same page, an agent is &#8220;<em>an autonomous software system powered by AI that can perceive its environment, make decisions, and execute multi-step tasks to achieve a specific goal without constant human intervention.</em>&#8221;  </p><p>Consider this. You tell your AI agent, &#8220;Buy me a battery-powered lawn mower. Budget is $500. Prioritize reviews, price, and shipping time. Deliver to my home address.&#8221; The agent searches, evaluates, selects, and purchases, all without you touching a browser. Two days later, a mower shows up at your door. You spent thirty seconds on a task that used to take hours.</p><p>It&#8217;s brilliantly useful. It&#8217;s also a fraud investigator&#8217;s nightmare.</p><p>Now run that same scenario with a stolen identity, a compromised credit card, and a drop address. The bad guy doesn&#8217;t search for anything. Doesn&#8217;t visit any merchant site. Doesn&#8217;t enter a single piece of payment data manually. He gives the agent an instruction and walks away. The agent does the rest, across ten stolen identities, simultaneously, without getting tired.</p><p>What does the merchant see? An API call, a billing address that matches the stolen card, a gift shipping address. The transaction looks clean in isolation. The velocity looks odd across accounts, but individually? Nothing flags.</p><p>But eventually the cardholder recognizes the fraud and files a report.  So you open an investigation.</p><p>The communication chain runs like this: actor &gt; agent &gt; merchant API &gt; payment processor &gt; fulfillment. Every hop is a potential evidence gap. The merchant has a transaction record. The payment processor has an authorization. The shipping carrier has a delivery scan. And what nobody has is an idea of what the agent platform logs, what they retain, and what legal framework applies when you ask for it.</p><p>Is an AI agent platform an Internet service provider? A bank? A phone carrier? A search engine? The search warrant process hasn&#8217;t caught up to the question. And some platforms are built privacy-forward by design, which means the logs you need may not exist at all.</p><p>Even if you get the logs, you have a new attribution problem. You can prove the agent made the purchase. But can you prove that the human gave the instruction? The session that initiated the task might be behind a residential proxy. Might be a stolen session token. Might be another automated layer entirely.</p><p>The bad guys&#8217; defense writes itself: &#8220;I didn&#8217;t choose those items. I didn&#8217;t enter that payment data. Maybe the system did that, but it wasn&#8217;t me.&#8221;</p><p>Technically? They&#8217;re not wrong.</p><p>The investigative frameworks we have were built around one assumption: a human made each decision in a transaction. Agentic AI destroys that assumption completely.  Yes, a human may have &#8220;set it off,&#8221; but what exactly is &#8220;it&#8221;?  How much control did the human actually have once the agent took the wheel?</p><p>It&#8217;s probably good we start talking about this because the future is here.</p><div><hr></div><h4>The News</h4><p>Maybe (probably not) I&#8217;ll have to start suggesting older adults look at Android again&#8230;Google&#8217;s June Android update introduces improved scam detection features aimed at fighting AI-driven impersonation and deepfake voice scams. This new system, available on Android 12 and above, requires users to install Google&#8217;s Phone, Contacts, and Messages apps to verify incoming calls from contacts. If a call appears to be spoofed via an online relay, the user will receive an alert. <a href="https://arstechnica.com/gadgets/2026/06/google-announces-deepfake-call-detection-for-android-new-airdrop-device-support/">https://arstechnica.com/gadgets/2026/06/google-announces-deepfake-call-detection-for-android-new-airdrop-device-support/</a></p><p>You&#8217;ll be hard-pressed to name a group that provides a better threat intelligence write-up than the team at Flare. In this article, they profile a new stealer malware: &#8220;<em>For $40 and a tutorial video, anyone can deploy a fully functional information stealer with credential harvesting, screen capture, Wi-Fi password extraction, file collection, persistence installation, and remote access, all controlled through a Telegram bot. KeyCat is a Python-based, multi-platform infostealer and remote access toolkit targeting both Windows and Linux environments.&#8221; </em><a href="https://flare.io/learn/resources/blog/keycat-stealer-multi-platform-infostealer">https://flare.io/learn/resources/blog/keycat-stealer-multi-platform-infostealer</a></p><p>Yes, passkeys are better security.  Yes, most people reject using them.  Microsoft is forcing the issue and will no longer provide codes through SMS.  <a href="https://support.microsoft.com/en-us/accounts-billing/manage/microsoft-to-stop-sending-sms-codes-for-personal-accounts">https://support.microsoft.com/en-us/accounts-billing/manage/microsoft-to-stop-sending-sms-codes-for-personal-accounts</a></p><p>Here's an interesting statistic for your next dinner party: between 10% and 20% of all domains registered in 2025 were created by cybercriminals. Even on the lower end, that means there are approximately 8.5 million malicious domains available for criminal activity.  Great reporting by Interisle.  <a href="https://static1.squarespace.com/static/63dbf2b9075aa2535887e365/t/6a20724a659b821142b48388/1780511306582/FullReport_MaliciousRegistrationsintheDomainNameMarket_2026_rev.pdf">https://static1.squarespace.com/static/63dbf2b9075aa2535887e365/t/6a20724a659b821142b48388/1780511306582/FullReport_MaliciousRegistrationsintheDomainNameMarket_2026_rev.pdf</a></p><p>Proving there is no floor to the prospect of insider threats, this Pennsylvania government employee threw away her job and reputation over $6,000.  <a href="https://www.wtaj.com/crime/former-rush-township-employee-facing-forgery-charge-after-stealing-6k/">https://www.wtaj.com/crime/former-rush-township-employee-facing-forgery-charge-after-stealing-6k/</a></p><p>A North Carolina man was sentenced to 121 months in prison for selling lists of elderly Americans&#8217; personal information to Jamaican lottery fraud scammers. His lists were so good that his pseudonym, &#8220;Steve Dixon,&#8221; became synonymous with the scam, to the point that it was dropped in rap music. It is alleged he earned over $5.2 million from the scheme, which victimized over seven million elderly Americans and resulted in losses exceeding $9.5 million.  <a href="https://www.justice.gov/opa/pr/fraudster-who-sold-personal-information-over-7-million-elderly-americans-jamaican-scammers">https://www.justice.gov/opa/pr/fraudster-who-sold-personal-information-over-7-million-elderly-americans-jamaican-scammers</a></p><p>Troy Hunt believes the data breach disclosure lag is worse than ever.  And he&#8217;s the authority on the issue.  <a href="https://www.troyhunt.com/1000-data-breaches-later-the-disclosure-lag-is-worse-than-ever/">https://www.troyhunt.com/1000-data-breaches-later-the-disclosure-lag-is-worse-than-ever/</a></p><p>FinCEN has issued a warning to banks to look out for &#8220;red flags&#8221; suggesting payroll schemes involving individuals living illegally in the country. This marks an important step in the Trump administration&#8217;s immigration enforcement. After President Trump signed an executive order in May, which instructs regulators to check the citizenship status of bank customers without making it mandatory to collect such data, the advisory highlights more than twelve signs of identity theft, payroll tax fraud, and money laundering associated with unauthorized workers. <a href="https://www.fincen.gov/system/files/2026-06/FinCEN-Advisory-Non-Work-Authorized-Populations.pdf">https://www.fincen.gov/system/files/2026-06/FinCEN-Advisory-Non-Work-Authorized-Populations.pdf</a></p><p>The FBI released an unserious "Most Wanted Fraudster&#8221; list. While the individuals included are certainly deserving, not a single politician made the list. Which politician? Any of them, I suppose.  <a href="https://www.fbi.gov/wanted/most-wanted-fraudsters">https://www.fbi.gov/wanted/most-wanted-fraudsters</a></p><div><hr></div><h4>Feedback</h4><p><em>Hey Matt, saw in Issue 286 where you asked the rhetorical question &#8220;how do you leverage your existing network to find a new job without broadcasting to your current employer that you&#8217;re looking to leave. Any additional insights on that? - </em>Keith </p><p>For context, that question was part of a larger conversation, and I wasn&#8217;t asking for myself (in case my current employer might be reading this). But, no, Keith, I don&#8217;t have any additional ideas. It&#8217;s a valid question&#8212;what&#8217;s the point of having a big social media network if you can&#8217;t leverage it? Except when you're already unemployed. Let&#8217;s try an experiment: someone who is employed should activate their &#8220;open to work&#8221; banner and report back the results.</p><p>Send Feedback to matt(at)threatswithoutborders.com</p><div><hr></div><h4>dfir</h4><p>Andrea Fortune examines a study tracking hired crime and intelligence analysts at a UK law enforcement agency over three interview periods: at six, twelve, and eighteen months. A total of sixty-three interviews were conducted. These analysts handled cases involving sexual assault, homicide, and serious crimes, frequently reviewing investigative reports, interview transcripts, recordings, and crime scene or autopsy images. The findings indicate that their mental health declined as expected. <a href="https://andreafortuna.org/2026/06/05/dfir-analyst-psychological-impact/">https://andreafortuna.org/2026/06/05/dfir-analyst-psychological-impact/</a></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>Cool Jobs</h4><p>Director of Fraud Risk Oversight, Fidelity.  <a href="https://jobs.fidelity.com/en/jobs/2125543/director-fraud-risk-oversight/">https://jobs.fidelity.com/en/jobs/2125543/director-fraud-risk-oversight/</a></p><p>Technology Services Specialist, Hershey Entertainment and Resorts.  <a href="https://hersheypa.rec.pro.ukg.net/HER1020HERS/JobBoard/035cdc57-c54b-48c9-8c4d-f30e022675e5/OpportunityDetail?opportunityId=9a55dff5-4337-4489-93af-e8ff0a4f93b3">https://hersheypa.rec.pro.ukg.net/HER1020HERS/JobBoard/035cdc57-c54b-48c9-8c4d-f30e022675e5/OpportunityDetail?opportunityId=9a55dff5-4337-4489-93af-e8ff0a4f93b3</a></p><h4>Cool Tools</h4><p>Supported in-flight Wi-Fi portals expose a flight manifest. CabinLink uses it to show your location, altitude, speed, and how long until you land. It keeps working when the cabin signal does not. (I have not personally used this app, but it looks cool.) <a href="https://www.vishrutjha.com/cabinlink">https://www.vishrutjha.com/cabinlink</a></p><p>Long for the days of Windows 95?  Want to get nostalgic about MacOS Puma?  This emulator has over 1700 operating systems pre-loaded and ready to run.  <a href="https://virtualosmuseum.org/">https://virtualosmuseum.org/</a></p><div><hr></div><h4>Irrelevant</h4><p>Statistics show many parolees are sent back to prison for &#8220;technical parole violations,&#8221; not committing new crimes.  But a closer examination reveals they are committing new crimes, yet are sent back to prison for the TPV and never charged for the new offenses.  Why?  The authors of the study conclude: </p><blockquote><p><em>The candid answer: it&#8217;s faster, easier, and more likely to pay off for prosecutors to send someone back to prison through a parole-violation hearing rather than through the courts. The parole hearing is held before representatives of the parole board, without any need to seat a jury, and the standard of proof is lower (&#8220;preponderance of the evidence,&#8221; not &#8220;beyond a reasonable doubt&#8221;).</em></p></blockquote><div class="embedded-post-wrap" data-attrs="{&quot;id&quot;:199456820,&quot;url&quot;:&quot;https://cityjournal.substack.com/p/the-hidden-crimes-of-parolees&quot;,&quot;publication_id&quot;:6236832,&quot;embedding_publication_id&quot;:null,&quot;publication_name&quot;:&quot;City Journal Substack&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!rO7N!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0aec2978-c0e6-4514-a875-f9c0535aa7b8_256x256.png&quot;,&quot;title&quot;:&quot;The Hidden Crimes of Parolees&quot;,&quot;truncated_body_text&quot;:&quot;By Barry Latzer and Kristofer Bret Bucklen&quot;,&quot;date&quot;:&quot;2026-05-27T14:31:07.509Z&quot;,&quot;like_count&quot;:12,&quot;comment_count&quot;:1,&quot;bylines&quot;:[],&quot;utm_campaign&quot;:null,&quot;belowTheFold&quot;:true,&quot;type&quot;:&quot;newsletter&quot;,&quot;language&quot;:&quot;en&quot;,&quot;source&quot;:null}" data-component-name="EmbeddedPostToDOM"><a class="embedded-post" native="true" href="https://cityjournal.substack.com/p/the-hidden-crimes-of-parolees?utm_source=substack&amp;utm_campaign=post_embed&amp;utm_medium=web"><div class="embedded-post-header"><img class="embedded-post-publication-logo" src="https://substackcdn.com/image/fetch/$s_!rO7N!,w_56,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0aec2978-c0e6-4514-a875-f9c0535aa7b8_256x256.png" loading="lazy"><span class="embedded-post-publication-name">City Journal Substack</span></div><div class="embedded-post-title-wrapper"><div class="embedded-post-title">The Hidden Crimes of Parolees</div></div><div class="embedded-post-body">By Barry Latzer and Kristofer Bret Bucklen&#8230;</div><div class="embedded-post-cta-wrapper"><span class="embedded-post-cta">Read more</span></div><div class="embedded-post-meta">2 months ago &#183; 12 likes &#183; 1 comment</div></a></div><div><hr></div><h4>Sign Off</h4><p>I received a lot of feedback over the last few weeks, especially about the editorial and the term &#8220;touch grass.&#8221; I can&#8217;t take credit for that, but I do subscribe to it. I spent my past Saturday outside, pretty much doing nothing but sitting in a chair, looking at trees, grass, and animals, and feeling the sun. I&#8217;m still a nutcase, but for that day, at least, it was a small dose of peace. And it felt good.     </p><p>And I hope you all find some of it during your week.</p><p>Matt</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SocL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dac6b91-0ecf-4643-a45c-7b8c3b7e0bd8_1378x1380.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SocL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dac6b91-0ecf-4643-a45c-7b8c3b7e0bd8_1378x1380.jpeg 424w, https://substackcdn.com/image/fetch/$s_!SocL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dac6b91-0ecf-4643-a45c-7b8c3b7e0bd8_1378x1380.jpeg 848w, https://substackcdn.com/image/fetch/$s_!SocL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dac6b91-0ecf-4643-a45c-7b8c3b7e0bd8_1378x1380.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!SocL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dac6b91-0ecf-4643-a45c-7b8c3b7e0bd8_1378x1380.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SocL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dac6b91-0ecf-4643-a45c-7b8c3b7e0bd8_1378x1380.jpeg" width="1378" height="1380" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7dac6b91-0ecf-4643-a45c-7b8c3b7e0bd8_1378x1380.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1380,&quot;width&quot;:1378,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:269207,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/201080905?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dac6b91-0ecf-4643-a45c-7b8c3b7e0bd8_1378x1380.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SocL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dac6b91-0ecf-4643-a45c-7b8c3b7e0bd8_1378x1380.jpeg 424w, https://substackcdn.com/image/fetch/$s_!SocL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dac6b91-0ecf-4643-a45c-7b8c3b7e0bd8_1378x1380.jpeg 848w, https://substackcdn.com/image/fetch/$s_!SocL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dac6b91-0ecf-4643-a45c-7b8c3b7e0bd8_1378x1380.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!SocL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dac6b91-0ecf-4643-a45c-7b8c3b7e0bd8_1378x1380.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 289]]></title><description><![CDATA[Cybercrime Investigation Newsletter, week ending May 31, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-289</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-289</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 02 Jun 2026 10:02:57 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Although paper documents used for the promise of financial payment date back to the Romans, the invention of the pre-printed consumer check with serial numbers is credited to an English banker in 1762. Fraudulent checks probably started appearing three days later. </p><p>And here we are, 264 years in the future, still fighting check fraud, and it might even be a worse problem than it ever has been.</p><p>At least three of the talks I heard at the BSides Harrisburg cybersecurity conference last week prominently discussed mental health and the need for self-care.  It&#8217;s not being selfish or being fragile.  It&#8217;s necessary to keep you fit for the job, which ultimately makes you more effective.</p><p>The cybersecurity field is getting really good at talking about this.  And demanding management recognizes it and provides resources for it.  Coming together as a community and saying, &#8220; Hey, we&#8217;re going to make mental health wellness part of our group identity.</p><p>Fraud - not so much.  In fact, I feel like it&#8217;s gotten worse. A recurring mantra shared at conferences and shouted across social media of &#8220;mount up fraud fighters and get locked-the-fuck-in because THIS is the year we take it to the fraudsters!&#8221;</p><p>So everyone gets hyped, puts on their armor, works 58 hours a week for months, only to get absolutely steamrolled by the bad guys.  And you all end up right back at disappointment and burnout.  </p><p>Because the lack of diligence, knowledge, and hard work is not the problem.  It&#8217;s a resource problem and a human psychology problem.</p><p>Remember the old fraud triangle?  Three elements come together to create a situation of fraud: Opportunity, Rationalization, and Pressure.  Well, there are a hell of lot of people out there with the pressure to get money, our societal decay and low moral standards make it easy to rationalize criminality, and the Internet - oh, the great facilitator - is giving more and more people the opportunity every day.</p><p>I spent twelve of my twenty-four-year law enforcement career in the criminal investigation room with a case docket. And guess what, I never got to Casleoad 0.  Regardless of how much overtime I worked, or how many birthdays and kids&#8217; sporting events I missed to &#8220;get caught up&#8221;.  And for what?  So I could determine that some ass-hole in Romania stole some files from a company in Pennsylvania.  Well, the company didn&#8217;t get their files back, the suspect is still in Romania, and I missed making memories with my kids.  Duplicate this story dozens and dozens of times.  Ask my wife, she spent a lot of time as a single mother. </p><p>The reality is that macro-level fraud is essentially unsolvable, so stop thinking you&#8217;re going to be the one to do it.</p><p>We are never going to work hard enough to expel all the adversaries.  Like weeds in the garden, no matter how many we pull, there will be more next week.</p><p>Listen up, and don&#8217;t hear what I&#8217;m not saying. Yes, we should be working hard, continuously training, and accepting every effort to learn.  Absolutely, go to fraud conferences to get recharged and socialized.  Post your catchy slogans to LinkedIn.  Get yourself locked in and down for the effort.  </p><p>But remember, we&#8217;re not going to solve this problem.  You&#8217;re going to have three more cases Monday morning, whether you work Saturday or not.</p><p>Prioritize your well-being by taking a mental health day, visiting the park with your kids, enjoying a nice dinner with your spouse, or spending a few days digging your toes in the sand. </p><p>Take a break. Or as the kids like to say, touch earth.</p><p>The fraud will be there when you return.</p><div><hr></div><h4>The News</h4><p>This article is not interesting because of the subject itself but because of how the author analyzed the probable cause affidavit written by the charging investigator. Sometimes, we overlook this aspect in the name of &#8220;probable cause," but we often provide suspects with details that improve their chances of not getting caught. This results in us only catching the&#8221; low-hanging fruit&#8221; and inadvertently empowering the more dangerous individuals.  <a href="https://arstechnica.com/tech-policy/2026/05/fbi-easily-nabs-man-selling-sexy-deepfakes-who-used-his-own-photo-in-profile/">https://arstechnica.com/tech-policy/2026/05/fbi-easily-nabs-man-selling-sexy-deepfakes-who-used-his-own-photo-in-profile/</a></p><p>US law enforcement and intelligence agencies are increasingly labeling dissent against artificial intelligence and data centers as &#8220;anti-tech extremism,&#8221;. Yeah, well, I don&#8217;t want a 24/7 data center in my backyard and I&#8217;m certainly not an anti-tech extremist.  <a href="https://www.wired.com/story/us-law-enforcement-warns-of-anti-tech-extremism/">https://www.wired.com/story/us-law-enforcement-warns-of-anti-tech-extremism/</a></p><p>A Google employee has been charged with fraud for allegedly using insider information to profit $1.2 million from bets on Polymarket.  <a href="https://www.cnbc.com/2026/05/27/google-employee-polymarket-insider-trading.html">https://www.cnbc.com/2026/05/27/google-employee-polymarket-insider-trading.html</a></p><p>Microsoft is not happy that several vulnerability researchers have released reports on bugs and exploits in Microsoft systems without first giving the compani&#8217;s PR teams time<s> to spin the news </s>, err, to create a patch.  <a href="https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure">https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure</a></p><p>Attackers are abusing the shared content features of AI chatbot platforms like ChatGPT and Claude to deliver malware by hosting malicious pages on trusted domains such as `chatgpt.com` and `claude.ai`, effectively bypassing standard URL reputation checks. <a href="https://pushsecurity.com/blog/llmshare-malvertising-campaign">https://pushsecurity.com/blog/llmshare-malvertising-campaign</a></p><p>Researchers from Unit 42 are recognizing a significant shift in the cyber extortion landscape, in which threat actors are increasingly abandoning ransomware encryption in favor of pure data theft and extortion, a trend driven by improved organizational backup capabilities and the severe financial leverage of modern regulatory frameworks like GDPR and SEC disclosure rules. This &#8220;data-only&#8221; approach has surged, with incidents rising from 2% in 2020 to 15% in 2025, particularly targeting mid-sized firms in healthcare, professional services, and construction, where the average cost of a breach now exceeds $5 million. <a href="https://unit42.paloaltonetworks.com/cyber-extortion-economy/">https://unit42.paloaltonetworks.com/cyber-extortion-economy/</a></p><p>The Supreme Court will soon decide the legality of geofence warrants. It heard arguments in Chatrie v. United States, a case about geofence warrants and Fourth Amendment privacy concerns. Tech Policy Press fellow Jake Laperruque discussed the case with Michael Price from the Fourth Amendment Center.  <a href="https://www.techpolicy.press/whats-at-stake-in-chatrie-v-united-states/">https://www.techpolicy.press/whats-at-stake-in-chatrie-v-united-states/</a></p><div><hr></div><h4>Feedback</h4><p><em>&#8220;I agree with your take that most of us would probably pay the ransom, but I think you missed an important caveat. At this point, the business isn&#8217;t making the decision; the insurance company is, or at least an attorney and a bean counter working for the insurance company is. The business owner makes that single phone call, and it&#8217;s on autopilot from there. Incident response team, ransom negotiator, legal, finance &#8212; it&#8217;s all pre-packaged. It is now standard for attackers to demand insurance documents to prove the payment limits before they lower their demands.&#8221; - </em>Jack B.  </p><p>Send Feedback to matt(at)threatswithoutborders.com</p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!V9Ox!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F601a9ee2-16de-494d-8eaf-331a128f9fde_1084x1508.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!V9Ox!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F601a9ee2-16de-494d-8eaf-331a128f9fde_1084x1508.jpeg 424w, https://substackcdn.com/image/fetch/$s_!V9Ox!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F601a9ee2-16de-494d-8eaf-331a128f9fde_1084x1508.jpeg 848w, https://substackcdn.com/image/fetch/$s_!V9Ox!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F601a9ee2-16de-494d-8eaf-331a128f9fde_1084x1508.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!V9Ox!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F601a9ee2-16de-494d-8eaf-331a128f9fde_1084x1508.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!V9Ox!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F601a9ee2-16de-494d-8eaf-331a128f9fde_1084x1508.jpeg" width="1084" height="1508" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/601a9ee2-16de-494d-8eaf-331a128f9fde_1084x1508.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1508,&quot;width&quot;:1084,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:238983,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/200127034?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F601a9ee2-16de-494d-8eaf-331a128f9fde_1084x1508.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!V9Ox!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F601a9ee2-16de-494d-8eaf-331a128f9fde_1084x1508.jpeg 424w, https://substackcdn.com/image/fetch/$s_!V9Ox!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F601a9ee2-16de-494d-8eaf-331a128f9fde_1084x1508.jpeg 848w, https://substackcdn.com/image/fetch/$s_!V9Ox!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F601a9ee2-16de-494d-8eaf-331a128f9fde_1084x1508.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!V9Ox!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F601a9ee2-16de-494d-8eaf-331a128f9fde_1084x1508.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p style="text-align: center;">No subscription fees, no ads, no paid product placements. Free, for real.  How about helping the newsletter grow?  Share it with your network.  </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>DFIR</h4><p>The digital forensics lab at Neumann University (just outside Philadelphia) led by Prof. Joe Walsh is winning at everything.  Fantastic experience for students and actually helping law enforcement solve crimes.  Awesome work, Joe.  </p><p><em>To date, that team has assisted in 988 cases across 64 departments and agencies since the center&#8217;s inception in May 2024, including 424 forensic investigations of digital devices and 528 incidents of real-time crime.</em></p><p><a href="https://www.govtech.com/education/higher-ed/neumann-university-helps-law-enforcement-with-digital-forensics">https://www.govtech.com/education/higher-ed/neumann-university-helps-law-enforcement-with-digital-forensics</a></p><h4>Cool Jobs</h4><p>Sr. Manager of Cybersecurity, Washington Commanders Football.  <a href="https://www.teamworkonline.com/football-jobs/washington-commanders-jobs/washington-commanders-jobs/cyber-security-sr-manager-2161458">https://www.teamworkonline.com/football-jobs/washington-commanders-jobs/washington-commanders-jobs/cyber-security-sr-manager-2161458</a></p><h4>Cool Tools</h4><p>Chrome, Edge, Brave, Vivaldi, and Helium are all browsers built on Chromium.  This site tests to ensure your browser of choice is built on the most up-to-date version of Chromium.  <a href="https://chromiumchecker.com/">https://chromiumchecker.com/</a></p><p>Network investigations toolbox.  <a href="https://robtex.com/">https://robtex.com/</a></p><div><hr></div><h4>Irrelevant</h4><p>The Costco theory of the Internet.  <a href="https://www.joanwestenberg.com/the-costco-theory-of-the-internet/">https://www.joanwestenberg.com/the-costco-theory-of-the-internet/</a></p><div><hr></div><h4>Just under the wire&#8230;</h4><p>Published just in time to make this issue, David Maimon traces how the online fake document economy has evolved from the centralized, physical-forgeries marketplace of the Silk Road period (2011&#8211;2017) to an automated, AI-powered process accessible to anyone with a browser. The current &#8220;AI Era&#8221; has removed the last obstacle by employing generative AI to produce synthetic faces and evade liveness checks, rendering the entire fraud cycle, from identity creation to verification, completely automated. <a href="https://resources.sentilink.com/blog/the-evolution-of-the-online-fake-document-economy">https://resources.sentilink.com/blog/the-evolution-of-the-online-fake-document-economy</a></p><div><hr></div><h4>Sign Off</h4><p>They informed me that the attendance at the BSides Harrisburg Cybersecurity Conference this year was lower than usual, but I couldn&#8217;t tell. The rooms appeared packed, at least during the morning sessions. However, attendance at the presentations significantly declined in the afternoon, which was disappointing and something I never quite comprehend. Why pay to attend an event only to spend half of the day there? If I ever organize a conference, I&#8217;ll definitely schedule the most anticipated speaker at 3 p.m.</p><p>It was wonderful to meet so many readers and reconnect with those I&#8217;ve known.  </p><p>Matt</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 288]]></title><description><![CDATA[Cybercrime Investigation Newsletter, week ending May 24, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-288</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-288</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 26 May 2026 10:06:16 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h4>Plausible Diligence: Why Instructure paid the ransom, and you would too!</h4><p>I give a talk called &#8220;DARVO: The Psychological Manipulation of Ransomware Victims&#8221;.  If you&#8217;ve seen it, you know the basic thesis is that ransomware actors are not just technical adversaries. They are expert manipulators who understand pressure, timing, and human psychology better than most Fortune 500 marketing teams. </p><p>When ransomware group ShinyHunters attacked Instructure, the maker of Canvas used by almost every K-12 and higher education institution, and Instructure paid the ransom, the internet responded as expected. Security &#8220;experts&#8221; jumped on X and piously voiced their concerns, law enforcement officials anxiously wrung their hands and expressed curt disapproval, and countless others posted their opinions on blogs and news sites about why paying the ransom was such a bad idea.</p><p><strong>And almost all of them were written by people who have never had to make that decision.</strong></p><p>The anti-ransom crowd occupies a particularly comfortable perch. They&#8217;re mostly law enforcement administration, government agencies, security vendors, and journalists.  People whose jobs don&#8217;t end if the data gets leaked. People who don&#8217;t have to look shareholders, school boards, or parents in the eye the next morning. </p><p>Instructure paid. And you probably would too. </p><p>ShinyHunters breached Instructure&#8217;s systems in late April 2026, exploiting a vulnerability in the Free-for-Teacher version of Canvas. They walked out with 3.65 terabytes of data, including names, email addresses, student ID numbers, course enrollments, and private messages between students and teachers. Records on roughly 275 million individuals across nearly 9,000 schools. </p><p>And this is not Instructure&#8217;s first visit to the octagon with this particular crew. ShinyHunters had already compromised Instructure through social engineering back in September 2025. A different system, and a different method, same attackers. Same company getting hit twice inside of eight months.  Ouch.</p><p>But for now, let&#8217;s talk about what makes this case different from your standard corporate ransomware incident. What makes this one harder. What cranks the pressure up to a level that changes the decision calculus entirely.</p><p>It&#8217;s the kids.</p><p>There is a psychological dimension to ransomware targeting that doesn&#8217;t get discussed enough outside my talk. These groups are not randomly opportunistic. They pick timing the way surgeons pick incisions. ShinyHunters hit Instructure at the end of the academic year, during final exams, during AP testing season. Canvas went dark for thousands of colleges, universities, and K-12 schools at the exact moment those schools needed it most. That&#8217;s not an accident. </p><p>And the data! Private messages between students and teachers. Not just names and email addresses which are bad enough. Actual Messages.  The kind of information that, if leaked, doesn&#8217;t just cause embarrassment. It causes real harm to children who cannot protect themselves, who didn&#8217;t choose to be in this system, and who had no say in whether their school used Canvas or not.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5-0P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f08ffe6-075a-4817-9aae-6f108a6d1e49_1576x662.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5-0P!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f08ffe6-075a-4817-9aae-6f108a6d1e49_1576x662.jpeg 424w, https://substackcdn.com/image/fetch/$s_!5-0P!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f08ffe6-075a-4817-9aae-6f108a6d1e49_1576x662.jpeg 848w, https://substackcdn.com/image/fetch/$s_!5-0P!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f08ffe6-075a-4817-9aae-6f108a6d1e49_1576x662.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!5-0P!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f08ffe6-075a-4817-9aae-6f108a6d1e49_1576x662.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5-0P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f08ffe6-075a-4817-9aae-6f108a6d1e49_1576x662.jpeg" width="1456" height="612" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5f08ffe6-075a-4817-9aae-6f108a6d1e49_1576x662.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:612,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:166587,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/199095352?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f08ffe6-075a-4817-9aae-6f108a6d1e49_1576x662.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5-0P!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f08ffe6-075a-4817-9aae-6f108a6d1e49_1576x662.jpeg 424w, https://substackcdn.com/image/fetch/$s_!5-0P!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f08ffe6-075a-4817-9aae-6f108a6d1e49_1576x662.jpeg 848w, https://substackcdn.com/image/fetch/$s_!5-0P!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f08ffe6-075a-4817-9aae-6f108a6d1e49_1576x662.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!5-0P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f08ffe6-075a-4817-9aae-6f108a6d1e49_1576x662.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Ask the Minneapolis Public Schools district how this plays. They got hit in 2023. The attackers eventually released the data. It included psychological evaluations of students. Abuse documentation. It was a catastrophe measured in human damage, not just data records. Law enforcement &#8220;investigated&#8221;. No ransomware actor went to prison for it. No administrator held responsible. No family got their child&#8217;s records back.</p><p>There is no cavalry coming. <strong>Check me on that</strong>. Law enforcement might call you back. If your organization is important enough, someone might show up and deliver some nicely worded victim care. Your incident response firm is just there to put the pieces back together.  Neither will recover your data. Neither will stop the leak. When you are staring down a countdown clock and the data on that clock belongs to other people&#8217;s children, the abstraction of &#8220;don&#8217;t reward criminals&#8221; has a hard time competing with the concrete reality of what happens if you don&#8217;t.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nqYz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08126354-fc40-4f28-9912-a651be2ff86b_1510x758.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nqYz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08126354-fc40-4f28-9912-a651be2ff86b_1510x758.jpeg 424w, https://substackcdn.com/image/fetch/$s_!nqYz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08126354-fc40-4f28-9912-a651be2ff86b_1510x758.jpeg 848w, https://substackcdn.com/image/fetch/$s_!nqYz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08126354-fc40-4f28-9912-a651be2ff86b_1510x758.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!nqYz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08126354-fc40-4f28-9912-a651be2ff86b_1510x758.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nqYz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08126354-fc40-4f28-9912-a651be2ff86b_1510x758.jpeg" width="1456" height="731" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/08126354-fc40-4f28-9912-a651be2ff86b_1510x758.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:731,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:146490,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/199095352?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08126354-fc40-4f28-9912-a651be2ff86b_1510x758.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nqYz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08126354-fc40-4f28-9912-a651be2ff86b_1510x758.jpeg 424w, https://substackcdn.com/image/fetch/$s_!nqYz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08126354-fc40-4f28-9912-a651be2ff86b_1510x758.jpeg 848w, https://substackcdn.com/image/fetch/$s_!nqYz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08126354-fc40-4f28-9912-a651be2ff86b_1510x758.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!nqYz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08126354-fc40-4f28-9912-a651be2ff86b_1510x758.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I hold Instructure responsible for being compromised. Absolutely. Not once, but twice, by the same group. That&#8217;s not bad luck; that&#8217;s a systemic failure in security posture. The first breach in September 2025 should have been a wake-up call. It apparently wasn&#8217;t, or wasn&#8217;t loud enough. Being compromised twice by the same threat actor in eight months is a process and leadership problem, not a technology problem. That&#8217;s on them.</p><p>But the payment? No hate there. That&#8217;s a business decision made under extraordinary pressure by people who had to live with the consequences. If you were sitting in that CEO chair, with 275 million records on the table and a countdown clock ticking down during finals week at 9,000 schools.</p><p>But here&#8217;s the part nobody wants to say out loud. The part that&#8217;s been quietly driving corporate ransom decisions for years, while the security industry pretends otherwise.</p><p><strong>Paying the ransom buys something that isn&#8217;t data recovery or system restoration. It buys documentation. It buys a paper trail. It buys what I&#8217;m calling  &#8220;plausible diligence&#8221;.</strong></p><p>Most of us have experience with plausible deniability. The art of having enough distance to say &#8220;don&#8217;t blame me, I didn&#8217;t know.&#8221; Plausible diligence is its corporate cousin. It&#8217;s having enough documentation to say &#8220;Don&#8217;t blame us, we tried our hardest.&#8221; It is the deliberate practice of checking every box, engaging every vendor, exhausting every option, and generating a paper trail of effort , so that when the thing fails anyway, the failure attaches to circumstances rather than to negligence.</p><p>Yes, Instructure paid the ransom. In exchange, they received, per their own statement, the return of the stolen data and &#8220;digital confirmation of data destruction.&#8221; They were also informed that none of their customers would be separately extorted. They said they believed &#8220;it was important to take every step <strong>within our control</strong> to give customers additional peace of mind.&#8221;</p><p><em>&#8220;Every step is within our control&#8221;</em>, think about that.  </p><p><strong>That is not a security statement, it&#8217;s a legal statement. That is the founding sentence of a liability defense.</strong></p><p>When the lawsuits come, and they will come, because 275 million records across 9,000 schools is not a quiet incident, Instructure&#8217;s lawyers will walk into that courtroom and say: we detected the breach, we contained it, we engaged expert forensic vendors, we negotiated to recover the data, we obtained confirmation of destruction, and we notified our customers. &#8220;<strong>We did everything. The criminals lied to us. Blame them.&#8221;</strong></p><p>Fully understand that the data is still out there. That&#8217;s how this works. ShinyHunters doesn&#8217;t actually delete anything, or, if they do, another group with a different name and the same data surfaces six months later. The &#8220;confirmation of destruction&#8221; is not a guarantee any serious security professional believes. Instructure&#8217;s own statement acknowledged there is &#8220;never complete certainty when dealing with cyber criminals.&#8221;</p><p><strong>They paid anyway. Because plausible diligence isn&#8217;t about what actually happens to the data. It&#8217;s about what you can document you did about it.</strong></p><p>Instructure did what cornered organizations do. They paid for something real, protection from immediate harm, and something less real but arguably more important: a documented record of having tried everything. A paper trail of effort that says, to regulators, to plaintiffs, to school boards and parents and lawyers, &#8220;Don&#8217;t blame us. We paid for an assurance and received documentation of its destruction. </p><p>That&#8217;s not justice, it&#8217;s not good security policy, but it&#8217;s how the game is actually played.</p><p>Until we fix the conditions that create the game, such as inadequate security investment by business leadership, the complete vacuum of real government response, and the absence of consequences for attackers, companies will keep playing it. </p><p>Paying the ransom makes the problem worse. But I&#8217;d probably pay it.  And you would too!</p><div><hr></div><h4>News&#8230;</h4><p>First&#8230; the Verizon DBIR was released.  I didn&#8217;t miss it.  There just isn&#8217;t room in this issue for me to talk about.  Come back next week.</p><p>This report by HPE Threat Labs claims it studied 44.5 million connection attempts from 372,800 unique IP addresses and determined that the &#8220;top threat actor country by IP count&#8221; was&#8230; drumroll&#8230; the United States.  Wait what?  Are you saying the number-one source of criminal intrusion attempts is the United States?  I must be misunderstanding that.  Or they are only claiming that most threat actors are exiting from nodes based here in the states.  <a href="https://www.hpe.com/psnow/doc/a50014950enw">https://www.hpe.com/psnow/doc/a50014950enw</a></p><p>Cofense details how attackers are using Zoom-themed phishing emails to trick victims into installing ConnectWise ScreenConnect. <a href="https://cofense.com/blog/click-install-compromised-the-new-wave-of-zoom-themed-attacks">https://cofense.com/blog/click-install-compromised-the-new-wave-of-zoom-themed-attacks</a></p><p>Apple claims to have prevented 2.2 billion dollars in potentially fraudulent transactions through the App Store and deactivated 40.4 million accounts for fraud and abuse. <a href="https://9to5mac.com/2026/05/20/apple-gives-update-on-the-app-store-and-its-key-protections/"> https://9to5mac.com/2026/05/20/apple-gives-update-on-the-app-store-and-its-key-protections/</a></p><p>The FBI has issued an advisory warning about Kali365, a &#8220;Phishing-as-a-Service&#8221; platform distributed via Telegram that enables attackers to compromise Microsoft 365 accounts by capturing OAuth tokens instead of stealing passwords. The tool delivers AI-generated phishing lures that impersonate trusted services such as Adobe and SharePoint, tricking users into authorizing malicious device sessions on legitimate Microsoft login pages. <a href="https://therecord.media/fbi-warns-of-kali365-phishing-attacks">https://therecord.media/fbi-warns-of-kali365-phishing-attacks</a></p><div><hr></div><h4>Feedback</h4><p>Send Feedback to matt(at)threatswithoutborders.com</p><div><hr></div><h4>dfir</h4><p>The evidence of an Apple FaceTime call and what Apple can provide.  <a href="https://lucidtruthtechnologies.com/facetime-evidence-apple-subpoena/">https://lucidtruthtechnologies.com/facetime-evidence-apple-subpoena/</a></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>Cool Jobs</h4><p>Intelligence Specialist - FinCEN.  <a href="https://www.usajobs.gov/job/869413300">https://www.usajobs.gov/job/869413300</a></p><p>Director of Security - Politico.  <a href="https://politico.wd108.myworkdayjobs.com/politico/job/Arlington-VA/Director-of-Security_JR100411">https://politico.wd108.myworkdayjobs.com/politico/job/Arlington-VA/Director-of-Security_JR100411</a></p><h4>Cool Tools</h4><p>OFAC Sanctions Search.  <a href="https://sanctionssearch.ofac.treas.gov/">https://sanctionssearch.ofac.treas.gov/</a></p><p>Bookmark this so you don&#8217;t have to keep asking for it on some email listserv - Bank Identification Number (BIN) search. <a href="https://binlist.net/">https://binlist.net/</a></p><div><hr></div><h4>Irrelevant</h4><p>Top 100 valued Bitcoin wallets.  <a href="https://bitinfocharts.com/top-100-richest-bitcoin-addresses.html">https://bitinfocharts.com/top-100-richest-bitcoin-addresses.html</a></p><div><hr></div><h4>Sign Off</h4><p>The BSides Harrisburg 2026 conference is happening this Friday, May 26th, at the Farm Show Complex in Harrisburg. This marks my fourth year volunteering and my third year as a room emcee. </p><p>Please find me in the Track 1 room and say hi. I&#8217;ll be the person on stage introducing speakers and gently cutting them off if they go over time. Despite how stressed I might look, meeting TWoB readers is always a top priority for me. Please come and introduce yourself.</p><p>And tickets are still available.  <a href="https://www.bsideshbg.com/">https://www.bsideshbg.com/</a></p><p>Matt</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cNlp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d8bd00-db28-4254-bdbd-a9e0877a38fd_1160x878.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cNlp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d8bd00-db28-4254-bdbd-a9e0877a38fd_1160x878.jpeg 424w, https://substackcdn.com/image/fetch/$s_!cNlp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d8bd00-db28-4254-bdbd-a9e0877a38fd_1160x878.jpeg 848w, https://substackcdn.com/image/fetch/$s_!cNlp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d8bd00-db28-4254-bdbd-a9e0877a38fd_1160x878.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!cNlp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d8bd00-db28-4254-bdbd-a9e0877a38fd_1160x878.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cNlp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d8bd00-db28-4254-bdbd-a9e0877a38fd_1160x878.jpeg" width="1160" height="878" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/31d8bd00-db28-4254-bdbd-a9e0877a38fd_1160x878.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:878,&quot;width&quot;:1160,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:121920,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/199095352?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d8bd00-db28-4254-bdbd-a9e0877a38fd_1160x878.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cNlp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d8bd00-db28-4254-bdbd-a9e0877a38fd_1160x878.jpeg 424w, https://substackcdn.com/image/fetch/$s_!cNlp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d8bd00-db28-4254-bdbd-a9e0877a38fd_1160x878.jpeg 848w, https://substackcdn.com/image/fetch/$s_!cNlp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d8bd00-db28-4254-bdbd-a9e0877a38fd_1160x878.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!cNlp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d8bd00-db28-4254-bdbd-a9e0877a38fd_1160x878.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 287]]></title><description><![CDATA[Cybercrime Investigation Newsletter, Week ending May 17, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-287</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-287</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 19 May 2026 10:07:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-lzX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf58a56-6633-4da2-ac32-797c85eacf37_986x776.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Few individuals in our niche have the credibility to publish opinion pieces through major news organizations like Fox. David Maimon is one.  </p><p>In this piece, he details how hostile state actors, including Iran, North Korea, Russia, and China, are systematically exploiting the US banking and employment systems by leveraging fraud infrastructure sourced from the dark web. His team has observed that these nations purchase stolen identity components, such as Social Security numbers and compromised bank credentials, to create synthetic identities and shell companies that bypass traditional compliance checks and sanctions screenings. </p><p>By routing transactions through correspondent banks with limited transparency and employing domestic US facilitators to conceal foreign IT workers or carry out financial grooming scams, these adversaries effectively funnel billions of dollars into the US financial system and infiltrate sensitive institutions. He emphasizes that current detection methods often fall short because the fraudulent entities look legitimate on paper, using forged documents and complex corporate structures to hide the true state-sponsored operators.</p><p><a href="https://www.foxnews.com/opinion/adversaries-even-using-us-banking-system-heres-get-away">https://www.foxnews.com/opinion/adversaries-even-using-us-banking-system-heres-get-away</a></p><div><hr></div><h4>Can they make this any easier? </h4><p>I&#8217;ve discussed this before, probably ad nauseam. But the bad guys are endlessly abusing the Payroll Protection Program (PPP) loans database. The pointy-head bureaucrat who decided this information should be made public should be made to sit in a dunk tank in the lobby of the IAFCI International conference.  </p><p>And if they couldn&#8217;t make the database any easier to navigate, someone turned it into an interactive map.  Awesome.</p><p><a href="https://www.ppploanmap.com/">https://www.ppploanmap.com/</a></p><div><hr></div><h4>The News</h4><p>A BitLocker bypass vulnerability was discovered.  You must have physical access to the device, and it only works on Windows 11 machines.  <a href="https://github.com/Nightmare-Eclipse/YellowKey">https://github.com/Nightmare-Eclipse/YellowKey</a></p><p>Tech-Support attacks are increasingly using the Quick Assistant tool, which is installed on Windows 10 and 11.  Thomas Miller of TrustedSec shows how to identify and respond to attacks using this tool.  <a href="https://trustedsec.com/blog/slamming-the-door-on-quick-assist-tech-support-scams-and-abuse">https://trustedsec.com/blog/slamming-the-door-on-quick-assist-tech-support-scams-and-abuse</a></p><p>Capital One takes an offensive position by filing a federal lawsuit in Virginia against unidentified operators behind large-scale robocall scams. The bank accuses them of trademark infringement by misusing its and Discover&#8217;s names in deceptive impersonation schemes. Using civil litigation enables the bank to leverage the discovery process to identify these scammers and dismantle their operations. This strategy, increasingly employed by major tech companies, aims to supplement traditional law enforcement efforts. <a href="https://www.cnbc.com/2026/05/13/capital-one-lawsuit.html">https://www.cnbc.com/2026/05/13/capital-one-lawsuit.html</a></p><p>Meta introduces Incognito Chat with Meta AI on WhatsApp and the Meta AI app, offering a fully private AI interaction. These conversations occur in a secure environment that Meta cannot access, and they are set to disappear automatically.  <a href="https://about.fb.com/news/2026/05/incognito-chat-whatsapp-meta-ai/">https://about.fb.com/news/2026/05/incognito-chat-whatsapp-meta-ai/</a></p><p>The Dutch police have turned to shaming, and I&#8217;m completely onboard. The &#8220;Game Over?!&#8221; campaign, publicly named 100 of the country&#8217;s most wanted scammers, which led to the identification of 74 suspects. During this campaign, fraudsters were given a two-week period to surrender voluntarily while their blurred images were displayed; after the deadline, the police unblurred the faces on social media and billboards, prompting 34 individuals to turn themselves in and helping identify 40 more through over 500 public tips. The effort focused on scams targeting the elderly, like bank helpdesk impersonation and fake police visits. It reached nearly 90 million people on social media and has led to 38 interrogations and 6 arrests, with investigators noting that the average age of suspects is only 22.  <a href="https://www.theregister.com/cyber-crime/2026/05/18/dutch-cops-shame-games-nets-74-wanted-fraudsters/5241980">https://www.theregister.com/cyber-crime/2026/05/18/dutch-cops-shame-games-nets-74-wanted-fraudsters/5241980</a></p><p>Proofpoint launches a managed service provider (MSP) unit, which they are calling Proofpoint 365.  No.  <a href="https://www.proofpoint.com/us/newsroom/press-releases/proofpoint-launches-dedicated-msp-business-unit-and-introduces-365-total">https://www.proofpoint.com/us/newsroom/press-releases/proofpoint-launches-dedicated-msp-business-unit-and-introduces-365-total</a></p><p>A 25-year-old former Penn State student and auxiliary police officer, has been held on $2 million bail after being charged with felony computer crimes involving the unauthorized manipulation of police dispatch systems containing sensitive personal and criminal data. <a href="https://www.centredaily.com/news/local/crime/article315752921.html">https://www.centredaily.com/news/local/crime/article315752921.html</a></p><p>OpenAI released Daybreak, its AI-powered cybersecurity and vulnerability management platform.  <a href="https://openai.com/daybreak/">https://openai.com/daybreak/</a></p><div><hr></div><h4>Feedback</h4><p>Send Feedback to matt(at)threatswithoutborders.com</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-lzX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf58a56-6633-4da2-ac32-797c85eacf37_986x776.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-lzX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf58a56-6633-4da2-ac32-797c85eacf37_986x776.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-lzX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf58a56-6633-4da2-ac32-797c85eacf37_986x776.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-lzX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf58a56-6633-4da2-ac32-797c85eacf37_986x776.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-lzX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf58a56-6633-4da2-ac32-797c85eacf37_986x776.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-lzX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf58a56-6633-4da2-ac32-797c85eacf37_986x776.jpeg" width="986" height="776" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/adf58a56-6633-4da2-ac32-797c85eacf37_986x776.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:776,&quot;width&quot;:986,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:98999,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/198260936?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf58a56-6633-4da2-ac32-797c85eacf37_986x776.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-lzX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf58a56-6633-4da2-ac32-797c85eacf37_986x776.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-lzX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf58a56-6633-4da2-ac32-797c85eacf37_986x776.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-lzX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf58a56-6633-4da2-ac32-797c85eacf37_986x776.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-lzX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf58a56-6633-4da2-ac32-797c85eacf37_986x776.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h4>dfir</h4><p>It appears that files synced to iCloud Drive are now stripped of their metadata.  <a href="https://eclecticlight.co/2026/05/11/does-icloud-drive-now-lose-almost-all-metadata/">https://eclecticlight.co/2026/05/11/does-icloud-drive-now-lose-almost-all-metadata/</a></p><div><hr></div><p>No subscriptions, no ads, no paid product promotions. Some issues better than others.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>Cool Jobs</h4><p>IT Security Analyst - Baltimore Orioles Baseball Club.  <a href="https://www.teamworkonline.com/baseball-jobs/orioles-jobs/baltimore-orioles-jobs/it-security-analyst-2169873">https://www.teamworkonline.com/baseball-jobs/orioles-jobs/baltimore-orioles-jobs/it-security-analyst-2169873</a></p><p>Director of Information Security - Penn Community Bank.  <a href="https://penncommunitybank.wd501.myworkdayjobs.com/ExternalCareers/job/Bristol-PA/Director-of-Information-Security--ISO-_R-100099">https://penncommunitybank.wd501.myworkdayjobs.com/ExternalCareers/job/Bristol-PA/Director-of-Information-Security--ISO-_R-100099</a></p><h4>Cool Tools</h4><p>Python tool that digs deep for email addresses and usernames across hundreds of online resources.  <a href="https://github.com/kaifcodec/user-scanner">https://github.com/kaifcodec/user-scanner</a></p><p>Barcode reader.  <a href="https://online-barcode-reader.inliteresearch.com/">https://online-barcode-reader.inliteresearch.com/</a></p><p>What&#8217;s happening - right now? <a href="https://trends.google.com/trending?geo=US">https://trends.google.com/trending?geo=US</a></p><div><hr></div><h4>Irrelevant</h4><p>This guy keeps a running tab on Apple&#8217;s neglect of its base applications.  As a longtime Mac user, I agree with all of this.  Honestly, it&#8217;s pretty bad.  Am I switching to Windows?  Hell no.  But if someone can get me a clean install of Linux on my M4 Mac Air, I&#8217;m gone.  <a href="https://taoofmac.com/space/blog/2026/05/18/1320?utm_content=atom">https://taoofmac.com/space/blog/2026/05/18/1320</a></p><div><hr></div><h4>Sign Off</h4><p>Welcome, new subscribers!  There&#8217;s always pressure after we gather a load of new subs, and I always feel like I&#8217;m letting everyone down.  The newsletter gets hyped at an event, people subscribe, and this is what they get!  The product always looks better in the ad, I guess.  But hopefully, enough of you stay around for next week.  </p><p>It&#8217;s hot here in Central PA, and I know the Midwest has been raked by violent storms.  Stay cool and safe!</p><p>Matt</p><p>&#8220;DON&#8217;T RUIN A GOOD TODAY BY THINKING ABOUT A BAD YESTERDAY. LET IT GO.&#8221;</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 286]]></title><description><![CDATA[Cyber-Financial Crime Investigation Newsletter, week ending May 10, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-286</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-286</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 12 May 2026 10:47:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>There&#8217;s a special kind of confidence that exists on LinkedIn. Someone shares an article with a dramatic headline, adds &#8220;Important read!&#8221; or &#8220;Everyone needs to see this,&#8221; and suddenly the post starts bouncing from connection to connection like a digital game of phone-a-friend.</p><p>And this week, I almost fell for it myself.</p><p>One of my connections shared a post from a well-known anti-fraud organization that is usually pretty solid. Buried inside was a link to an article about how cybercriminals are using AI to craft scams and phishing attacks. On the surface, it sounded reasonable as AI is being used by criminals. So I was about two clicks away from hitting the repost button myself.</p><p>But then I did something crazy, I read the article.</p><p>Not the headline.  Not the summary.  Not the one-line hot-take above the share. The actual article.</p><p>The piece was written by a company selling an AI detection product for fraud prevention.  Their &#8220;research&#8221; conveniently supported the urgent need for the exact service they happen to sell. The article sprinkled in just enough truth to sound credible, then fired up the hype machine and drifted straight into panic-porn marketing.</p><p>It wasn&#8217;t education. It was advertising dressed up as analysis.</p><p>I&#8217;m sure the person who shared it trusted the person they got it from. And that person probably trusted their connection. By the time it reached my feed, it was basically a share of a share of a share of a share, with everyone assuming someone else had done the homework.</p><p>Nobody did, and this happens constantly on LinkedIn. Content becomes heavily nested through reposts, and eventually, the original source becomes little more than a decorative attachment. People aren&#8217;t evaluating the information anymore. They&#8217;re evaluating the social credibility of the person sharing it.</p><p>&#8220;If Bob gave it a red 100 emoji, it must be good.&#8221; Meanwhile, Bob read exactly three sentences and a bullet point.</p><p>That&#8217;s why I read every article I include in the newsletter. Including an article doesn&#8217;t mean I endorse it or the author. I don&#8217;t always agree with what&#8217;s written, and many times that&#8217;s exactly why I include it. </p><p>But at the very least, I can honestly say I read it to make sure it&#8217;s not complete trash before passing it on. </p><p>You would think that would be the standard in 2026, but here we are.</p><p>So the next time your favorite LinkedIn warrior shares an article with fifteen fire emojis and the phrase &#8220;So True!&#8221; take an extra minute before you hit repost. Open the article and read it. </p><p>If you want to read an actual article about the criminal use of AI: Dr. Ben Collier from the Center for Emerging Technology and Security at the Alan Turing Institute explores generative AI adoption in the criminal underground.  <a href="https://cetas.turing.ac.uk/publications/cybercrime-vibercrime-assessing-generative-ai-adoption-criminal-underground">https://cetas.turing.ac.uk/publications/cybercrime-vibercrime-assessing-generative-ai-adoption-criminal-underground</a></p><div><hr></div><h4>And sometimes&#8230;</h4><p>That article posted to LinkedIn is gold!  Steve Lenderman shared a link to a report on card fraud this week that turned out to be the best thing I&#8217;ve read in a while.</p><p>No, not that card fraud, the other card fraud.  Counterfeit trading cards.  Who knew an original Charizard was in such demand, or worth so much money???</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Sp4J!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7f347c-15e9-4150-be4d-502362e34cd8_1446x1430.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Sp4J!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7f347c-15e9-4150-be4d-502362e34cd8_1446x1430.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Sp4J!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7f347c-15e9-4150-be4d-502362e34cd8_1446x1430.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Sp4J!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7f347c-15e9-4150-be4d-502362e34cd8_1446x1430.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Sp4J!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7f347c-15e9-4150-be4d-502362e34cd8_1446x1430.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Sp4J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7f347c-15e9-4150-be4d-502362e34cd8_1446x1430.jpeg" width="1446" height="1430" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3e7f347c-15e9-4150-be4d-502362e34cd8_1446x1430.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1430,&quot;width&quot;:1446,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:254621,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/197169482?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7f347c-15e9-4150-be4d-502362e34cd8_1446x1430.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Sp4J!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7f347c-15e9-4150-be4d-502362e34cd8_1446x1430.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Sp4J!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7f347c-15e9-4150-be4d-502362e34cd8_1446x1430.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Sp4J!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7f347c-15e9-4150-be4d-502362e34cd8_1446x1430.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Sp4J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7f347c-15e9-4150-be4d-502362e34cd8_1446x1430.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The 2025 Card Fraud Report from collectible authentication company PSA is a must-read, if for nothing more than to broaden your view of the fraud landscape. For someone immersed in cyber fraud, the topic is fascinating. A whole different world.  </p><p><a href="https://downloads.ctfassets.net/l40e281thfxr/72ZJooe31lk9KGBklfQFOu/4a3bf368f91a364fad3ccc2eca077a17/PSA_Fraud-Report_2025.pdf">https://downloads.ctfassets.net/l40e281thfxr/72ZJooe31lk9KGBklfQFOu/4a3bf368f91a364fad3ccc2eca077a17/PSA_Fraud-Report_2025.pdf</a></p><div><hr></div><h4>The News</h4><p>An investigation uncovered &#8220;Department 4&#8217; at Russia&#8217;s Bauman Moscow State Technical University, which allegedly acts as a secret recruitment hub for the GRU, Russia&#8217;s military intelligence. Masked as an elite academic program, it trains students in advanced cyberwarfare skills such as password hacking, virus creation, and physical espionage, with the GRU controlling admissions, tests, and the placement of graduates into notorious hacking groups. The leaked 2,000 documents reveal that talented students are spotted as early as secondary school and assigned to units responsible for major cyberattacks worldwide. This is essentially a &#8220;hacker factory&#8217;. <a href="https://www.bitdefender.com/en-us/blog/hotforsecurity/inside-department-4-russias-secret-school-for-hackers">https://www.bitdefender.com/en-us/blog/hotforsecurity/inside-department-4-russias-secret-school-for-hackers</a></p><p>This makes me smile.  Kids are beating age verification checks by wearing fake mustaches!  <a href="https://www.theregister.com/security/2026/05/04/kids-can-bypass-some-age-checks-with-a-drawn-on-mustache/5224601">https://www.theregister.com/security/2026/05/04/kids-can-bypass-some-age-checks-with-a-drawn-on-mustache/5224601</a></p><p>Securonix Threat Research has uncovered a phishing campaign that targets over 80 organizations primarily in the US by exploiting legitimate Remote Monitoring and Management (RMM) tools. The attack begins with impersonation emails mimicking the U.S. Social Security Administration, directing victims to compromised Mexican websites to download a malicious executable disguised as a government document.  <a href="https://www.securonix.com/blog/venomous-helper-phishing-campaign/">https://www.securonix.com/blog/venomous-helper-phishing-campaign/</a></p><p>You&#8217;re Invited! Psyche, how about some victimization instead?  Fake invitations delivered via e-greeting cards are compromising accounts.  <a href="https://tidbits.com/2026/05/11/beware-greeting-card-scams-from-trusted-senders/">https://tidbits.com/2026/05/11/beware-greeting-card-scams-from-trusted-senders/</a></p><p>And of course, Instructure, also known as Canvas, got hit, again. I won't spend time discussing it; a quick Google search can provide more details or the latest update on your school's likely recovery timeline.  </p><div><hr></div><h4>Feedback</h4><p>Send Feedback to matt(at)threatswithoutborders.com</p><div><hr></div><h4>dfir</h4><p>Andrea Fortuna examines the challenges of cloud forensics, in which digital evidence is spread across multiple jurisdictions worldwide, forming a &#8220;jurisdictional labyrinth&#8221; that our traditional investigative techniques don&#8217;t easily navigate. Legal systems are increasingly in conflict, as seen in the conflict between the U.S. CLOUD Act, which claims jurisdiction based on the provider, even if data is stored elsewhere, and the EU&#8217;s GDPR, which limits cross-border data transfers unless there are specific international agreements. <a href="https://andreafortuna.org/2026/05/06/cloud-forensics-jurisdictional-labyrinth/">https://andreafortuna.org/2026/05/06/cloud-forensics-jurisdictional-labyrinth/</a></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>Cool Jobs</h4><p>Fraud Manager, Everence Federal Credit Union.  <a href="https://www.everence.com/about-everence/careers/current-positions/current-positions/2026/may/fraud-manager">https://www.everence.com/about-everence/careers/current-positions/current-positions/2026/may/fraud-manager</a></p><h4>Cool Tools</h4><p>Has this image been edited?  Use this to find out. <a href="https://imageedited.com/"> https://imageedited.com/</a></p><p>Track flights from your desktop.  <a href="https://flightradar.live/en/">https://flightradar.live/en/</a></p><p>Find a blog to follow.  <a href="https://blogosphere.app/">https://blogosphere.app/</a></p><div><hr></div><h4>Irrelevant</h4><p>Joan Westenberg argues that the modern outrage cycle is intentionally crafted as a business strategy to generate engagement through provoked anger. She suggests that high-intensity anger is the most effective way to drive viral content, transforming digital platforms into &#8220;slot machines&#8221; that deliver outrage to keep users engaged and advertising revenue flowing. The best safeguard, she proposes, is **procedural emotional resistance**: resisting the algorithm's emotional pull by asking who gains from your reaction and remembering that your attention is the actual product being sold. <a href="https://www.joanwestenberg.com/outrag/">https://www.joanwestenberg.com/outrag/</a></p><div><hr></div><h4>Sign Off</h4><p>I attended several events around a college graduation this weekend and heard multiple speakers emphasize the importance of &#8220;your network&#8221;. There&#8217;s plenty of advice on how to build connections with co-workers, colleagues, and like-minded professionals. However, what seems to be missing from most advice is how to leverage that network effectively, how to make it work for you. Once you&#8217;ve built your network, what should you do with it?  That&#8217;s the real nugget.</p><p>For example, a large and active network is useful if you&#8217;re unemployed. It&#8217;s easy to contact colleagues and post on social media, saying, &#8220;Hey everyone, I need a job.&#8221; But what if you&#8217;re already employed but low-key seeking a new opportunity? How do you leverage your network then? You can&#8217;t exactly broadcast that you&#8217;re looking for a new job, nor is it wise to post &#8220;open to work&#8221; on LinkedIn. Well, you could, but it would be best to submit your resignation to your current employer along with such a post.  Is a large network really only an insurance policy in the event you become unemployed? </p><p>Thanks for reading another week.  See you next Tuesday.</p><p>Matt</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 285]]></title><description><![CDATA[Cybersecurity Investigations Newsletter - Week ending May 3, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-285</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-285</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 05 May 2026 10:26:16 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m frequently asked in my community presentations if PDFs are &#8220;safe&#8221; to open.  As usual, my answer is something to the effect of &#8220;maybe&#8221;.</p><p>As the Q1 2026 Email Threats Landscapes Report from Microsoft details, PDFs are becoming one of the main malicious payloads for attackers, second only to HTML files</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6lk5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe997ed88-971f-4586-b337-18336b3d9cf3_1290x952.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6lk5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe997ed88-971f-4586-b337-18336b3d9cf3_1290x952.jpeg 424w, https://substackcdn.com/image/fetch/$s_!6lk5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe997ed88-971f-4586-b337-18336b3d9cf3_1290x952.jpeg 848w, https://substackcdn.com/image/fetch/$s_!6lk5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe997ed88-971f-4586-b337-18336b3d9cf3_1290x952.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!6lk5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe997ed88-971f-4586-b337-18336b3d9cf3_1290x952.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6lk5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe997ed88-971f-4586-b337-18336b3d9cf3_1290x952.jpeg" width="1290" height="952" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e997ed88-971f-4586-b337-18336b3d9cf3_1290x952.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:952,&quot;width&quot;:1290,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:95851,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/196312027?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe997ed88-971f-4586-b337-18336b3d9cf3_1290x952.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6lk5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe997ed88-971f-4586-b337-18336b3d9cf3_1290x952.jpeg 424w, https://substackcdn.com/image/fetch/$s_!6lk5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe997ed88-971f-4586-b337-18336b3d9cf3_1290x952.jpeg 848w, https://substackcdn.com/image/fetch/$s_!6lk5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe997ed88-971f-4586-b337-18336b3d9cf3_1290x952.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!6lk5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe997ed88-971f-4586-b337-18336b3d9cf3_1290x952.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>PDFs have become one of the most effective tools for the cybercriminal, not because they look dangerous, but because they look normal. We all use them every day!  In most workplaces, PDFs are the default format for invoices, resumes, reports, and contracts. That familiarity creates trust, and attackers take full advantage of it.</p><p>But a PDF isn&#8217;t just a simple document. It&#8217;s a &#8220;rich&#8221; file format capable of running code, embedding other files, and interacting with users. That means a PDF can behave more like a small program than a static page.</p><p>Attackers exploit this in several ways, including embedded JavaScript that runs automatically when the file is opened. If the user&#8217;s PDF reader has a vulnerability, that script can attempt to exploit it and gain control of the system. In other situations, the PDF acts as a delivery mechanism, sometimes called a &#8220;dropper.&#8221; The file itself may appear harmless, but it triggers a download of malware from an external server once opened.</p><p>The most common method, however, isn&#8217;t a technical exploit; it&#8217;s simple visual deception.  Examples include fake buttons, where a PDF displays a message like &#8220;This content is encrypted. Click here to decrypt.&#8221; Clicking the button redirects the user to a counterfeit login page (such as a spoofed Microsoft 365 portal) to steal credentials. Another method is the favorite tool of every marketer, URL shorteners. Malicious links are often concealed behind shortened URLs or legitimate-looking text to avoid detection by email security systems.</p><p>From a security standpoint, PDFs are difficult to detect and block for a few key reasons. First, attackers can hide or encrypt parts of the file, making it hard for email security tools to inspect the contents. Second, PDFs can be large and complex, and some systems limit how deeply they scan files to avoid slowing down email delivery.  </p><p>The result is a perfect storm: a trusted file type, powerful built-in features, and technical complexity that challenges traditional defenses.</p><p>So, back to the question, is that PDF safe to open?  </p><p>The default test for the everyday email users is, do you know the sender? But you need to consider that even a known sender might have a compromised account. The better test is, were you expecting the document? If not, use the phone and call the sender. Oh, and don&#8217;t call the contact number included in the email. You might be calling the bad guys!</p><p>Read the full Microsoft Report:  <a href="https://www.microsoft.com/en-us/security/blog/2026/04/30/email-threat-landscape-q1-2026-trends-and-insights/">https://www.microsoft.com/en-us/security/blog/2026/04/30/email-threat-landscape-q1-2026-trends-and-insights/</a></p><div><hr></div><h4>The News</h4><p>Varonis Threat Labs discovered Bluekit, a phishing kit offering 40+ website templates, automated domain services, and add-ons, including AI assistants and voice cloning. While the platform is good, it&#8217;s not as good as promised. <a href="https://www.varonis.com/blog/bluekit">https://www.varonis.com/blog/bluekit</a></p><p>Scott Lang from Spur contends that relying solely on a single off-the-shelf fraud score to assess IP risk is restrictive. This approach tends to condense complex, multidimensional data into a static &#8220;black box&#8221; number that lacks necessary context and adaptability. He argues that security teams should focus on detailed IP intelligence features, such as data center locations, VPN links, and geographic discrepancies, to develop transparent and customizable risk models aligned with their specific organizational needs and risk tolerance. By moving away from a universal score towards a &#8220;glass box&#8221; methodology, organizations can make finer decisions, like initiating additional authentication steps or blocking traffic, based on genuine underlying signals rather than an opaque overall score.  <a href="https://spur.us/blog/ip-risk-scoring-vs-ip-context">https://spur.us/blog/ip-risk-scoring-vs-ip-context</a></p><p>The FBI issued a PSA warning that cyber threat actors are impersonating legitimate businesses to hijack freight and steal high-value shipments. Since 2024, these actors have gained unauthorized access to computer systems, posing as victim companies and redirecting goods for resale.  In 2025, estimated cargo theft losses in the United States and Canada surged to nearly $725 million.  <a href="https://www.ic3.gov/PSA/2026/PSA260430">https://www.ic3.gov/PSA/2026/PSA260430</a></p><p>I&#8217;m more concerned about having my voice recorded in a permanent file, but these authors argue that patients should refuse consent for &#8220;AI&#8221; scribing tools in healthcare settings due to significant privacy risks, the potential for reduced openness during consultations, and the likelihood of automation bias leading to inaccurate medical records. They contend that charting is an essential part of the care process itself, and that replacing it with automated drafts degrades both immediate and long-term patient outcomes. <a href="https://buttondown.com/maiht3k/archive/why-you-should-refuse-to-let-your-doctor-record/">https://buttondown.com/maiht3k/archive/why-you-should-refuse-to-let-your-doctor-record/</a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4sfS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930f8b6d-d55b-475a-ae99-d27b8a36745f_994x308.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4sfS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930f8b6d-d55b-475a-ae99-d27b8a36745f_994x308.jpeg 424w, https://substackcdn.com/image/fetch/$s_!4sfS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930f8b6d-d55b-475a-ae99-d27b8a36745f_994x308.jpeg 848w, https://substackcdn.com/image/fetch/$s_!4sfS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930f8b6d-d55b-475a-ae99-d27b8a36745f_994x308.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!4sfS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930f8b6d-d55b-475a-ae99-d27b8a36745f_994x308.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4sfS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930f8b6d-d55b-475a-ae99-d27b8a36745f_994x308.jpeg" width="994" height="308" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/930f8b6d-d55b-475a-ae99-d27b8a36745f_994x308.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:308,&quot;width&quot;:994,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:76777,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/196312027?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930f8b6d-d55b-475a-ae99-d27b8a36745f_994x308.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4sfS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930f8b6d-d55b-475a-ae99-d27b8a36745f_994x308.jpeg 424w, https://substackcdn.com/image/fetch/$s_!4sfS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930f8b6d-d55b-475a-ae99-d27b8a36745f_994x308.jpeg 848w, https://substackcdn.com/image/fetch/$s_!4sfS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930f8b6d-d55b-475a-ae99-d27b8a36745f_994x308.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!4sfS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930f8b6d-d55b-475a-ae99-d27b8a36745f_994x308.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h4>It&#8217;s Conference Season</h4><p>I originally published this back in 2024, but since it&#8217;s conference season, let me remind you of the most terrible conference attendee &#8211; Conference Question Guy. And it&#8217;s always a guy.</p><p><strong>Gotcha Guy</strong> attempts to put the speaker in a bad spot by asking a question about some obscure or little-known technical aspect of the speaker&#8217;s topic. The question&#8217;s intent isn&#8217;t to elicit more knowledge or spur conversation but to trick the speaker and make them look poor in front of the audience.</p><p><strong>Test the Speaker&#8217;s Knowledge Guy</strong>, much like Gotcha Guy, this question asker is already knowledgeable about the topic and asks a question that he already knows the answer to. He&#8217;s a more benign version of Gotcha guy.</p><p>You can immediately spot <strong>Look How Smart I Am Guy </strong>as he&#8217;s on the edge of his seat the whole talk, and only an ounce of self-restraint is keeping him from stepping up on stage. His head is nodding or shaking throughout the entire talk, and he usually makes statements to those around him. His hand will be the first one up after the talk. His proposed question is usually a softball, but will be constructed to allow him to follow up with a more detailed and technical retort to demonstrate his mastery of the speaker&#8217;s topic.</p><p>While<strong> Mask Guy&#8217;s</strong> commitment to public health is admirable, no one can hear the question, including the speaker. The easy solution is just slightly to pull the mask down when asking the question, but since they don&#8217;t, they just come across as a virtue-signaling asshole.</p><p><strong>Mansplaining Guy</strong> is a particularly dreadful species; the Mansplaining Guy targets female speakers and uses their questions as a way to lecture about a particular topic point he feels the speaker didn&#8217;t thoroughly explain or doesn&#8217;t completely understand.</p><p><strong>Political Statement Guy</strong> usually wears the requisite noble cause t-shirt or some slogan buttons on his jacket. &#8220;How will this be interpreted by the [insert politician] government, considering their failure to&#8230;&#8221;, &#8220;Don&#8217;t you think this is all irrelevant, considering there are children dying on C&#244;te d&#8217;Ivoire<strong> </strong>cocoa farms?&#8220;, &#8220;Isn&#8217;t this an assault on the 1<sup>st</sup> Amendment?&#8221; &#8220;Have you seen any evidence that this might lead to the loss of the Arctic ice shelf&#8230;&#8221;, AHHHHHH &#8211; Please just stop.</p><p><strong>Complain About My Employer Guy</strong> uses their question to passively-aggressively criticize their own employer or supervisor, framing it to get the speaker to agree with their assertion.</p><p>To clarify, speakers crave questions. There&#8217;s nothing worse than finishing your conference talk with &#8220;and now I&#8217;ll take any questions!&#8221; only to get blank stares and silence. Questions from your audience show they were listening to your words, and your ideas resonated, or at least got them thinking.</p><p>Please challenge your conference speakers, but do it for the right reasons.</p><p>Don&#8217;t be <strong>Conference Question Guy</strong>. Everyone hates that guy.</p><div><hr></div><h4>Feedback</h4><p>Send Feedback to matt(at)threatswithoutborders.com</p><div><hr></div><h4>dfir</h4><p>Steve Whalen from Sumuri digs into Mac metadata.  <a href="https://sumuri.com/what-your-mac-forensic-tool-isnt-telling-you-about-metadata/">https://sumuri.com/what-your-mac-forensic-tool-isnt-telling-you-about-metadata/</a></p><div><hr></div><p style="text-align: center;">No subscription fees.  No ads.  No sponsored posts.  Even the snark is free. </p><p style="text-align: center;">How about helping us grow? </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>Cool Jobs</h4><p>Director of Risk and Payment Options, BetMGM.  <a href="https://betmgminc.wd5.myworkdayjobs.com/en-US/BetMGM/job/Director--Risk-and-Payments-Ops_JR100645">https://betmgminc.wd5.myworkdayjobs.com/en-US/BetMGM/job/Director--Risk-and-Payments-Ops_JR100645</a></p><h4>Cool Tools</h4><p>Obtain the results from 100 different search engines with a single search:  <a href="https://www.100searchengines.com/">https://www.100searchengines.com/</a></p><div><hr></div><h4>Irrelevant</h4><p>The end of an era&#8230;Jeve&#8217;s retires as Ask shuts down after 25 years.  <a href="https://www.ask.com/">https://www.ask.com/</a></p><div><hr></div><h4>Sign Off</h4><p>I've likely been the most persistent squeaky voice regarding the locations of the Keystone Connection conferences over the years&#8212;almost as much as my ongoing complaints about the event&#8217;s name. This year, however, Steve Lenderman and his team got it right, hosting the event at a fantastic venue in a prime location. And of course, I won't be able to attend due to other commitments.  </p><p>Anyways&#8230;you should attend.  And you still have time to register!</p><p><a href="https://keystonekonnection.com/">https://keystonekonnection.com/</a></p><p>Matt</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 284]]></title><description><![CDATA[Cyber-Financial Crime Investigation Newsletter, week ending April 26, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-284</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-284</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 28 Apr 2026 10:30:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Gviy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73fe6406-6532-4aed-abf9-5fc5eb77311c_1170x2532.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I had a fun conversation this week.  </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Gviy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73fe6406-6532-4aed-abf9-5fc5eb77311c_1170x2532.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Gviy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73fe6406-6532-4aed-abf9-5fc5eb77311c_1170x2532.png 424w, https://substackcdn.com/image/fetch/$s_!Gviy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73fe6406-6532-4aed-abf9-5fc5eb77311c_1170x2532.png 848w, https://substackcdn.com/image/fetch/$s_!Gviy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73fe6406-6532-4aed-abf9-5fc5eb77311c_1170x2532.png 1272w, https://substackcdn.com/image/fetch/$s_!Gviy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73fe6406-6532-4aed-abf9-5fc5eb77311c_1170x2532.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Gviy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73fe6406-6532-4aed-abf9-5fc5eb77311c_1170x2532.png" width="1170" height="2532" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/73fe6406-6532-4aed-abf9-5fc5eb77311c_1170x2532.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cbca72dd-d9b7-432e-814e-d7e09455eabc_1170x2532.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2532,&quot;width&quot;:1170,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:396868,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/195475678?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbca72dd-d9b7-432e-814e-d7e09455eabc_1170x2532.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Gviy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73fe6406-6532-4aed-abf9-5fc5eb77311c_1170x2532.png 424w, https://substackcdn.com/image/fetch/$s_!Gviy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73fe6406-6532-4aed-abf9-5fc5eb77311c_1170x2532.png 848w, https://substackcdn.com/image/fetch/$s_!Gviy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73fe6406-6532-4aed-abf9-5fc5eb77311c_1170x2532.png 1272w, https://substackcdn.com/image/fetch/$s_!Gviy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73fe6406-6532-4aed-abf9-5fc5eb77311c_1170x2532.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It&#8217;s called a cash-flipping scam, and this version has been dressed up with an artificial-intelligence angle to make it sound sophisticated. It isn&#8217;t. But the people running it are smarter than you might think, and the way they&#8217;ve structured it creates some real challenges for victims and investigators.</p><p>The target gets an unsolicited text from a stranger promising easy money. The script goes something like this: send me $25, I&#8217;ll use my AI tool to flip it, and I&#8217;ll send you back $250. Simple, fast, and painless. Of course, the moment the money moves, the scammer either disappears or comes back asking for a little more before the payout arrives. There is no AI. There is no payout. Only fraud.</p><p>The $25 is important because the low dollar amount is not random. It&#8217;s a calculated decision. The people running these scams have figured out something that works in their favor at almost every level of the criminal justice system.</p><p>At $25, most victims are embarrassed, frustrated, and ultimately unwilling to take time out of their day to file a police report over a loss that won&#8217;t even cover their gas to get to the station. And honestly, can you blame them? </p><p>So the <strong>first filter</strong> is self-reporting; most of these never get reported at all.</p><p>The <strong>second filter</strong> is law enforcement. Even when a report is filed, no investigator opens an active investigation into a $25 fraud. The caseload doesn&#8217;t allow for it.</p><p>The <strong>third filter</strong> is the prosecutors. Even if someone handed a DA a complete, airtight case involving a $25 theft by a non-local suspect, no prosecutor would entertain charging, let alone extraditing,  a defendant over such a de minimis loss. The scammers know this. They have built their entire business model around staying below the threshold that triggers a system response.</p><p>Live on the West coast of the country and scam people on the East coast for low dollar amounts... bulletproof.</p><p>What they&#8217;re actually doing is running this scheme at volume. A hundred victims at $25 each is $2,500. A thousand victims is $25,000. The individual loss is invisible to the system, but the aggregate is very real money.</p><p>These scams almost always use peer-to-peer payment apps like Cash App, Venmo, or Zelle, and that choice is deliberate too. P2P transfers are fast, feel casual, and are extremely difficult to reverse once completed. There&#8217;s no effective dispute process, unlike with a credit card. When the money moves, it&#8217;s gone.</p><p>But these accounts don&#8217;t exist in isolation. Cash App accounts must be verified with real identity details, including name, date of birth, and Social Security number. Additionally, they are connected to a real bank account. Somewhere within this chain, there&#8217;s a real person involved. It could be the scammer themselves or a money mule, but in either case, a person is associated with a financial institution that keeps records. Law enforcement with proper legal authority can serve a search warrant on Cash App and the linked bank to access this information (Yeah, I know, don&#8217;t hold your breath). The data is available; the key question is whether pursuing it is worth the effort, and that leads me to the most crucial point.</p><p>A single $25 case will go nowhere. But if you bring a prosecutor a case showing that the same Cash App tag, the same phone number, or the same script was used against 200 victims across multiple jurisdictions, resulting in $5,000 or $50,000 in total losses, that is a different conversation entirely. </p><p>Investigators need to connect with each other early and often. When you see one of these cases, get it into IC3 at ic3.gov and the FTC at reportfraud.ftc.gov immediately and make sure your victims do too. Include the Cash App tag, the phone number, the exact wording of the message, and any transaction IDs. Then reach out laterally&#8212;to investigators in neighboring jurisdictions, to fraud units in other agencies, and to your financial crime information networks. Ask whether anyone else is seeing the same tag or the same number.</p><p>The scammer is betting that each of us will look at $25 and walk away. The way we beat that bet is by refusing to work in silos. The case that can&#8217;t be built by one investigator on one complaint can absolutely be built when ten investigators across five states are looking at the same actor. Aggregate the losses, aggregate the evidence, and suddenly the math changes for everyone.  </p><div><hr></div><h4>The News</h4><p>Tennessee joins Indiana in banning cryptocurrency ATMs.  <a href="https://www.yahoo.com/news/articles/tennessee-becomes-second-state-outlaw-204113466.html">https://www.yahoo.com/news/articles/tennessee-becomes-second-state-outlaw-204113466.html</a></p><p>Toronto Police have arrested and charged three men with 44 offenses following an investigation into the first known use of a mobile SMS blaster device in Canada. This technology mimics cellular towers to intercept phone calls and send fraudulent text messages that appear to come from trusted organizations such as banks, often directing victims to fake websites to steal personal and financial information.  The investigation, called Project Lighthouse, began last November and detected thousands of device connections and over 13 million network disruptions across the Greater Toronto Area. <br><a href="https://torontosun.com/news/local-news/toronto-cops-cybercrime-tool-sms-blaster-spam-phones">https://torontosun.com/news/local-news/toronto-cops-cybercrime-tool-sms-blaster-spam-phones</a></p><p>A man from Baltimore faces charges including wire fraud, mail fraud, aggravated identity theft, theft of government property, and making false statements. As a former Social Security Administration (SSA) customer service representative, he had access to sensitive SSA databases with personally identifiable information of benefit claimants. The indictment reveals that between February and April 2023, he planned and carried out a scheme to defraud the SSA. He fraudulently obtained Supplemental Security Income (SSI) benefits intended for others, using them for himself and his associates. He targeted claimants with mental health diagnoses, modifying their records to include bank accounts he controlled and his residential address, enabling him to divert their SSI payments. Additionally, he altered the benefit payment dates in SSA&#8217;s system, creating back payments in the claimants&#8217; names, and redirected these payments to his accounts.   <a href="https://www.justice.gov/usao-md/pr/former-social-security-administration-worker-charged-disability-funds-theft-scheme">https://www.justice.gov/usao-md/pr/former-social-security-administration-worker-charged-disability-funds-theft-scheme</a></p><p>Holy insider threat! A US special forces soldier was arrested for allegedly betting on the capture of Venezuelan President Nicol&#225;s Maduro, earning $400,000. Prosecutors claim he was involved in planning the mission and used insider information to place the bet.<a href="https://www.cnn.com/2026/04/23/politics/us-special-forces-soldier-arrested-maduro-raid-trade"> https://www.cnn.com/2026/04/23/politics/us-special-forces-soldier-arrested-maduro-raid-trade </a></p><p>It&#8217;s Spy vs. Spy. Apple has introduced a software update for iPhones and iPads to fix a serious bug that let law enforcement recover deleted or expiring messages by accessing cached notification content stored on the device for up to a month. The flaw, revealed when the FBI used forensic tools to retrieve deleted Signal messages, was caused by notifications that kept message content in the OS database even after the messages were deleted. Apple fixed this by making sure notifications marked for deletion are no longer stored unexpectedly. The update has also been applied to older iOS 18 versions to enhance user privacy.  <a href="https://techcrunch.com/2026/04/22/apple-fixes-bug-that-cops-used-to-extract-deleted-chat-messages-from-iphones/">https://techcrunch.com/2026/04/22/apple-fixes-bug-that-cops-used-to-extract-deleted-chat-messages-from-iphones/</a></p><p>Kudos to law enforcement in Pittsburgh, PA, for their successful effort. Over two days, federal, state, and local authorities collaborated in the Pittsburgh area, resulting in the seizure of nine illegal card-skimming devices. This operation potentially prevented over $9 million in fraud losses for the public. The U.S. Secret Service, in coordination with Allegheny County Police, Pittsburgh police, the state attorney general, the U.S. Postal Inspection Service, and the state inspector general, visited 272 locations on Monday and Tuesday. During these visits, they examined 883 point-of-sale terminals, 775 gas pumps, and 170 ATM terminals.  <a href="https://triblive.com/local/secret-service-led-operation-nets-9-credit-card-skimming-devices-in-pittsburgh-area/">https://triblive.com/local/secret-service-led-operation-nets-9-credit-card-skimming-devices-in-pittsburgh-area/</a></p><p>The Talos group reports that phishing has reemerged as the most commonly observed means of gaining initial access, accounting for over a third of their engagements in which initial access could be determined. Phishing has not been the top vector for initial access since Q2 2025. <a href="https://blog.talosintelligence.com/ir-trends-q1-2026/"> https://blog.talosintelligence.com/ir-trends-q1-2026/</a></p><p>ADT confirmed a data breach that resulted on the loss of customer data, including names, contact details, dates of birth, and the last four digits of Social Security numbers. ShinyHunters has claimed to possess 10 million records and threatened to leak them unless a ransom is paid. <a href="https://therecord.media/ADT-data-breach-cyberattack">https://therecord.media/ADT-data-breach-cyberattack</a></p><div><hr></div><h4>Feedback</h4><p>Send Feedback to matt(at)threatswithoutborders.com</p><div><hr></div><h4>Investigations</h4><p>The Supreme Court will hear oral arguments in <em>Chatrie v. United States</em>, a case examining the use of &#8220;geofence warrants&#8221; by law enforcement to obtain location data from tech companies like Google. The case centers on Okello Chatrie, who was convicted of bank robbery after authorities used a geofence warrant to identify his cellphone location near the crime scene. Chatrie argues that the warrant violated the Fourth Amendment by conducting a search without sufficient probable cause and that he had a reasonable expectation of privacy in his location data, which the government should not be able to access without a warrant. The government contends that Chatrie had no such privacy expectation because he voluntarily shared his location data with Google, and that the warrant was not a general search but a targeted request. <br><a href="https://www.scotusblog.com/2026/04/court-to-hear-argument-on-law-enforcements-use-of-geofence-warrants/">https://www.scotusblog.com/2026/04/court-to-hear-argument-on-law-enforcements-use-of-geofence-warrants/</a></p><p>I absolutely endorse this message:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fQlA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefd8c8b3-6180-4b62-93ad-92493066eb0a_1238x562.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fQlA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefd8c8b3-6180-4b62-93ad-92493066eb0a_1238x562.jpeg 424w, https://substackcdn.com/image/fetch/$s_!fQlA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefd8c8b3-6180-4b62-93ad-92493066eb0a_1238x562.jpeg 848w, https://substackcdn.com/image/fetch/$s_!fQlA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefd8c8b3-6180-4b62-93ad-92493066eb0a_1238x562.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!fQlA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefd8c8b3-6180-4b62-93ad-92493066eb0a_1238x562.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fQlA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefd8c8b3-6180-4b62-93ad-92493066eb0a_1238x562.jpeg" width="1238" height="562" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/efd8c8b3-6180-4b62-93ad-92493066eb0a_1238x562.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:562,&quot;width&quot;:1238,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:147685,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/195475678?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefd8c8b3-6180-4b62-93ad-92493066eb0a_1238x562.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fQlA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefd8c8b3-6180-4b62-93ad-92493066eb0a_1238x562.jpeg 424w, https://substackcdn.com/image/fetch/$s_!fQlA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefd8c8b3-6180-4b62-93ad-92493066eb0a_1238x562.jpeg 848w, https://substackcdn.com/image/fetch/$s_!fQlA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefd8c8b3-6180-4b62-93ad-92493066eb0a_1238x562.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!fQlA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefd8c8b3-6180-4b62-93ad-92493066eb0a_1238x562.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>Cool Jobs</h4><p>Manager of Security Awareness and Learning, Vanguard.  <a href="https://vanguard.wd5.myworkdayjobs.com/en-US/vanguard_external/job/Malvern-PA/Manager--Security-Awareness-and-Learning_177094">https://vanguard.wd5.myworkdayjobs.com/en-US/vanguard_external/job/Malvern-PA/Manager--Security-Awareness-and-Learning_177094</a></p><p>Lead Investigator, National Basketball League.  <a href="https://careers.nba.com/job/NBANBAUSJR000581EXTERNALENUS/Lead-Investigator">https://careers.nba.com/job/NBANBAUSJR000581EXTERNALENUS/Lead-Investigator</a></p><h4>Cool Tools</h4><p>&#8220;Upload a screenshot or photo and get clue-based location reasoning in seconds&#8221;.  Probably not.  But it&#8217;s currently free, so give it a try.  <a href="https://reverseimagelocation.com/">https://reverseimagelocation.com/</a></p><p>DorkEye is an advanced automated dorking and OSINT recon tool that leverages DuckDuckGo.  (Fantastic documentation!)  <a href="https://github.com/xPloits3c/DorkEye">https://github.com/xPloits3c/DorkEye</a></p><div><hr></div><h4>Irrelevant</h4><p>Are you an Advil person or a Tylenol person?  Acetaminophen, ibuprofen, and what doctors probably want you to know.  <a href="https://asteriskmag.com/issues/14/the-mystery-in-the-medicine-cabinet">https://asteriskmag.com/issues/14/the-mystery-in-the-medicine-cabinet</a></p><div><hr></div><h4>Sign Off</h4><p>Thanks for reading this far. Recently, Google started blocking email tracking pixels, which Substack relies on to track open rates. Many other email services have also blocked these trackers, and now Google Gmail has joined them. My open rate was already inconsistent due to these controls, and now it&#8217;s completely useless metric. I really don't know how many subscribers read the newsletter each week. So, I&#8217;ll just keep throwing it at the wall and hoping for the best.  </p><p>Matt</p><p>&#8220;THAT SHIT THAT HAPPENED YESTERDAY, HAPPENED YESTERDAY. MOVE ON.&#8221;</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p><p>cybercrime cyficrime financial fraud investigations osint aml cybersecurity </p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 283]]></title><description><![CDATA[Cybercrime Investigation Newsletter, week ending April 19, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-283</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-283</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 21 Apr 2026 10:31:27 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I recently had a question about an IP address that resolved back to &#8220;iCloud Private Relay,&#8221; which is more information than is usually provided, since most of the time addresses just resolve to &#8220;Cloudflare&#8221; or &#8220;Akamai.&#8221; Unfortunately, for most investigations, this also resolves to a roadblock.</p><p>Apple introduced Private Relay as part of iCloud+, and most people think it&#8217;s Apple&#8217;s VPN service.   It isn&#8217;t a VPN. It&#8217;s more accurate to call it a dual-hop proxy. The service is designed to make sure no single entity, not even Apple, knows both who you are and what you&#8217;re looking at. Apple's inclusion in that &#8220;no single entity&#8221; part is either admirable or politically convenient, depending on your level of cynicism.</p><p>When a user browses in Safari with Private Relay enabled, their traffic takes a two-stop detour before reaching its destination. First, it hits an Apple server. Apple sees the user&#8217;s real IP address, but can&#8217;t see where they&#8217;re going because the DNS request is encrypted. The traffic is then handed off to a second relay server operated by a third-party partner like Cloudflare, Akamai, or Fastly. That server knows the destination but has no idea who the user is. The website at the end of that chain sees a generic, temporary IP address shared by potentially thousands of other users in the same general region.</p><p>Nobody has the whole picture. That&#8217;s the whole point.</p><p>Private Relay protects only Safari browsing and encrypts DNS queries on the device. </p><p>It does not protect Third-party browsers like Chrome, Edge, or Firefox.  Instagram, Facebook, email, banking apps, and most other apps on the device are also unprotected. In the absence of some additional masking technology, those will still phone home with the user&#8217;s real IP address.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Cuu0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd6e0e24-51bb-4e0d-94f5-9f3414b75d9b_898x728.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Cuu0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd6e0e24-51bb-4e0d-94f5-9f3414b75d9b_898x728.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Cuu0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd6e0e24-51bb-4e0d-94f5-9f3414b75d9b_898x728.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Cuu0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd6e0e24-51bb-4e0d-94f5-9f3414b75d9b_898x728.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Cuu0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd6e0e24-51bb-4e0d-94f5-9f3414b75d9b_898x728.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Cuu0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd6e0e24-51bb-4e0d-94f5-9f3414b75d9b_898x728.jpeg" width="898" height="728" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fd6e0e24-51bb-4e0d-94f5-9f3414b75d9b_898x728.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:728,&quot;width&quot;:898,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:108029,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/194723683?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd6e0e24-51bb-4e0d-94f5-9f3414b75d9b_898x728.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Cuu0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd6e0e24-51bb-4e0d-94f5-9f3414b75d9b_898x728.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Cuu0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd6e0e24-51bb-4e0d-94f5-9f3414b75d9b_898x728.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Cuu0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd6e0e24-51bb-4e0d-94f5-9f3414b75d9b_898x728.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Cuu0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd6e0e24-51bb-4e0d-94f5-9f3414b75d9b_898x728.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>So when trying to unmask a web browser user, our standard move -- get the IP, search warrant to the ISP, get the subscriber -- hits a wall. The destination logs a relay egress IP shared by thousands of users. The ISP can see the device was connected to Apple, but has no record of which sites were visited. And the relay partner doesn&#8217;t store the incoming Apple IP in a way that ties it to the outgoing destination. Nobody has the full picture. By design.</p><p>There are still some investigative avenues.</p><p>First, Apple publishes a list of all Private Relay egress IP ranges at https://mask-api.icloud.com/egress-ip-ranges.csv. Run any suspicious source IP against that list before spending resources on an ISP subpoena. Know what you&#8217;re dealing with upfront.</p><p>Second, Private Relay only masks the IP and DNS. Browser fingerprinting artifacts such as canvas fingerprinting, screen resolution, and installed fonts can still tie a specific Safari instance to activity across multiple sessions.</p><p>Third, look for cross-app leakage. If your subject used any other app on that same device, such as a different browser, a social media app, or any other service for communication across the Internet, those connections bypassed the relay entirely and may have logged the real IP with those respective servers.</p><p>iCloud Private Relay is a headache, a roadblock for sure, but maybe not a dead end. It breaks the attribution chain rather than eliminating it, but sometimes broken chains can still be put back together.</p><div><hr></div><h4>The News</h4><p>Microsoft explains how to prevent domain compromises through &#8220;predictive shielding&#8221;.  Predictive shielding in Microsoft Defender&#8217;s automatic attack disruption helps prevent the spread of identity-based attacks by acting before stolen credentials are fully exploited. Rather than waiting for malicious activity on an account, it detects early signs of credential exposure, such as high-confidence signals of credential theft, and proactively restricts potentially compromised accounts.  <a href="https://www.microsoft.com/en-us/security/blog/2026/04/17/domain-compromise-predictive-shielding-shut-down-lateral-movement/">https://www.microsoft.com/en-us/security/blog/2026/04/17/domain-compromise-predictive-shielding-shut-down-lateral-movement/</a></p><p>Think you won&#8217;t get bitten by a malicious insider? Cryptocurrency exchange, Kraken, is standing up to extortionists and refusing to pay their ransom demands.  Kraken experienced two extortion attempts stemming from &#8220;inappropriate&#8221; access by support team members, not external breaches. Approximately 2,000 accounts were potentially compromised.  <a href="https://www.blockhead.co/2026/04/14/kraken-refuses-extortion-demands-after-criminal-group-films-internal-systems/">https://www.blockhead.co/2026/04/14/kraken-refuses-extortion-demands-after-criminal-group-films-internal-systems/</a></p><p>I recently shared a report from another threat intel company that claimed Docusign is now the most imitated brand in phishing attacks.  Checkpoint doesn&#8217;t even list them in the top ten.  Regardless, I&#8217;m sure this list is applicable. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rRV4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8fdd743-1e24-441d-a1dc-424b750ef8f3_1878x898.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rRV4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8fdd743-1e24-441d-a1dc-424b750ef8f3_1878x898.jpeg 424w, https://substackcdn.com/image/fetch/$s_!rRV4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8fdd743-1e24-441d-a1dc-424b750ef8f3_1878x898.jpeg 848w, https://substackcdn.com/image/fetch/$s_!rRV4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8fdd743-1e24-441d-a1dc-424b750ef8f3_1878x898.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!rRV4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8fdd743-1e24-441d-a1dc-424b750ef8f3_1878x898.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rRV4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8fdd743-1e24-441d-a1dc-424b750ef8f3_1878x898.jpeg" width="1456" height="696" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f8fdd743-1e24-441d-a1dc-424b750ef8f3_1878x898.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:696,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:117080,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/194723683?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8fdd743-1e24-441d-a1dc-424b750ef8f3_1878x898.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rRV4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8fdd743-1e24-441d-a1dc-424b750ef8f3_1878x898.jpeg 424w, https://substackcdn.com/image/fetch/$s_!rRV4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8fdd743-1e24-441d-a1dc-424b750ef8f3_1878x898.jpeg 848w, https://substackcdn.com/image/fetch/$s_!rRV4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8fdd743-1e24-441d-a1dc-424b750ef8f3_1878x898.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!rRV4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8fdd743-1e24-441d-a1dc-424b750ef8f3_1878x898.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://blog.checkpoint.com/research/the-phishing-paradox-the-worlds-most-trusted-brands-are-cyber-criminals-entry-point-of-choice/">https://blog.checkpoint.com/research/the-phishing-paradox-the-worlds-most-trusted-brands-are-cyber-criminals-entry-point-of-choice/ </a></p><p>So, you want to be a darknet drug lord?  <a href="https://pastebin.com/raw/GrV3uYh5">https://pastebin.com/raw/GrV3uYh5</a></p><p>The TidBITS public Slack group (SlackBITS) is being closed after a social engineering attack where the attacker impersonated author Glenn Fleishman by duplicating his profile and display name, then sent a direct message to another user to trick him into installing the OSX.Odyssey infostealer malware. <a href="https://tidbits.com/2026/04/18/shutting-down-slackbits-after-impersonation-based-malware-attack/">https://tidbits.com/2026/04/18/shutting-down-slackbits-after-impersonation-based-malware-attack/</a></p><p>Wine Fraud - Yep. A 59-year-old UK citizen was sentenced to 10 years in federal prison for orchestrating a $97 million wine fraud scheme. Posing as the CFO of a fictitious company, the man and a co-conspirator deceived over 140 investors worldwide by falsely claiming to broker loans secured by high-value wine collections. In reality, the operation was a Ponzi scheme that used new investor funds to pay fake interest to earlier investors. Of the $97 million collected, only ~$14 million was returned, leaving victims with losses exceeding $83 million.  <a href="https://www.justice.gov/usao-edny/pr/united-kingdom-citizen-sentenced-10-years-prison-97-million-wine-fraud-scheme">https://www.justice.gov/usao-edny/pr/united-kingdom-citizen-sentenced-10-years-prison-97-million-wine-fraud-scheme</a></p><div><hr></div><h4>Feedback</h4><p>Send Feedback to matt(at)threatswithoutborders.com</p><div><hr></div><h4>Losing Argument</h4><p>This is for anyone who denies a connection between the rise in cryptocurrency use for fraud and the proliferation of cryptocurrency ATMs. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EBTn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cc40a83-c80a-4110-aa42-f0c71a063ef0_1242x714.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EBTn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cc40a83-c80a-4110-aa42-f0c71a063ef0_1242x714.jpeg 424w, https://substackcdn.com/image/fetch/$s_!EBTn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cc40a83-c80a-4110-aa42-f0c71a063ef0_1242x714.jpeg 848w, https://substackcdn.com/image/fetch/$s_!EBTn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cc40a83-c80a-4110-aa42-f0c71a063ef0_1242x714.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!EBTn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cc40a83-c80a-4110-aa42-f0c71a063ef0_1242x714.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EBTn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cc40a83-c80a-4110-aa42-f0c71a063ef0_1242x714.jpeg" width="1242" height="714" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6cc40a83-c80a-4110-aa42-f0c71a063ef0_1242x714.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:714,&quot;width&quot;:1242,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:278139,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/194723683?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cc40a83-c80a-4110-aa42-f0c71a063ef0_1242x714.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!EBTn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cc40a83-c80a-4110-aa42-f0c71a063ef0_1242x714.jpeg 424w, https://substackcdn.com/image/fetch/$s_!EBTn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cc40a83-c80a-4110-aa42-f0c71a063ef0_1242x714.jpeg 848w, https://substackcdn.com/image/fetch/$s_!EBTn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cc40a83-c80a-4110-aa42-f0c71a063ef0_1242x714.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!EBTn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cc40a83-c80a-4110-aa42-f0c71a063ef0_1242x714.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Cryptocurrency complaints were relatively flat until the first jump in 2021.  And then it skyrockets over the next four years.  </p><p>And sure enough, the Gemini tells us there was a huge influx, or &#8220;Hyper Saturation,&#8221; of machines beginning in 2021.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZYQC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b45c99-2dba-41c2-a09e-8d0ba96ffc5e_1248x670.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZYQC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b45c99-2dba-41c2-a09e-8d0ba96ffc5e_1248x670.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZYQC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b45c99-2dba-41c2-a09e-8d0ba96ffc5e_1248x670.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZYQC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b45c99-2dba-41c2-a09e-8d0ba96ffc5e_1248x670.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZYQC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b45c99-2dba-41c2-a09e-8d0ba96ffc5e_1248x670.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZYQC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b45c99-2dba-41c2-a09e-8d0ba96ffc5e_1248x670.jpeg" width="1248" height="670" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f8b45c99-2dba-41c2-a09e-8d0ba96ffc5e_1248x670.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:670,&quot;width&quot;:1248,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:114823,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/194723683?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b45c99-2dba-41c2-a09e-8d0ba96ffc5e_1248x670.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZYQC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b45c99-2dba-41c2-a09e-8d0ba96ffc5e_1248x670.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZYQC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b45c99-2dba-41c2-a09e-8d0ba96ffc5e_1248x670.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZYQC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b45c99-2dba-41c2-a09e-8d0ba96ffc5e_1248x670.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZYQC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b45c99-2dba-41c2-a09e-8d0ba96ffc5e_1248x670.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>Cool Jobs</h4><p>Director of IT Security - Denver Broncos Football Team.  h<a href="https://job-boards.greenhouse.io/denverbroncosteamllc/jobs/5191274008">ttps://job-boards.greenhouse.io/denverbroncosteamllc/jobs/5191274008</a></p><h4>Cool Tools</h4><p>Those who attended my recent talk on quickly triaging websites to determine legitimacy or attribution know that Whois has been replaced by RDAP.  The name changed, but the data remains the same.  And you might need to go back in history to find out not Who Is, but Who Was!  ARIN&#8217;s WhoWas service provides historical registration information for IP addresses and ASNs.  (Registration required)  <a href="https://www.arin.net/reference/research/whowas/">https://www.arin.net/reference/research/whowas/</a></p><div><hr></div><h4>Irrelevant</h4><p>Claude can&#8217;t use a typewriter.  College instructor turns to old school typewriters to curb the use of AI for assignments. </p><blockquote><p>&#8220;What&#8217;s the point of me reading it if it&#8217;s already correct anyway, and you didn&#8217;t write it yourself? Could you produce it without your computer?&#8221; said Phelps.</p></blockquote><p> <a href="https://sentinelcolorado.com/uncategorized/a-college-instructor-turns-to-typewriters-to-curb-ai-written-work-and-teach-life-lessons/">https://sentinelcolorado.com/uncategorized/a-college-instructor-turns-to-typewriters-to-curb-ai-written-work-and-teach-life-lessons/</a></p><div><hr></div><h4>Sign Off</h4><p>I&#8217;ve come to the realization that I&#8217;m a domain hoarder. Domain-rich but cash-poor, I guess.  Every time I think of an awesome web domain name, I purchase it, usually with the idea of starting a business someday. But that never happens, and I just keep paying the yearly domain registration fees. It&#8217;s become expensive enough that I&#8217;ve come to a reckoning. I need to give up some, but it feels like giving up on ideas.  </p><p>Oh, that&#8217;s a great name&#8230;domainhoarder.com!</p><p>Have a great week.  See you all next Tuesday.</p><p>Matt</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p><p>cybercrime cybersecurity cyficime cyber fraud investigations aml osint  </p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 282]]></title><description><![CDATA[Cybersecurity Investigation Newsletter - week ending April 12, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-282</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-282</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 14 Apr 2026 11:49:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I generally enjoy AI tools and have found many uses for them. However, it can definitely be a joy killer.</p><p>One of my favorite yearly events is the release of the IC3 Internet Crime Report. I love diving into it to uncover insights that often go unnoticed by most. I call these insights 'nuggets,' a term familiar to regular newsletter readers. This year, things were different. The report was published on Monday afternoon, and within a few hours, I saw detailed analyses appearing on LinkedIn and X. Gary Warner, David Maimon, and a very few others in our field can craft such perfect summaries in just 90 minutes. For everyone else... It&#8217;s likely that a well-designed AI prompt played a significant role in generating many of those impressive analyses.</p><p>And that&#8217;s OK. It&#8217;s one of the things AI does best, breaking down long, complex, highly dense PDFs into something more digestible. </p><p>I&#8217;m not mad about it.  But I am selfishly disappointed.  </p><p>The proliferation of AI-generated analysis takes a little bit of the joy away from those of us who really love doing that type of work&#8230; old-school. And it renders us afterthoughts because by the time we get around to producing something worth publishing, every cybersecurity content mill has already flooded the zone with AI-created &#8220;hot-takes&#8221;.</p><p>I&#8217;m sure you&#8217;ve seen the highlights by now. But you really should take the time to actually read the report yourself.</p><p><a href="https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf">https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf</a></p><div><hr></div><h4>I can&#8217;t help myself&#8230; consider this nugget</h4><p>It is well known that most victims do not report their victimization and subsequent losses to any authorities, let alone the Internet Crime Complaint Center. In the 2025 report, the IC3 explicitly states that its figures only represent reports to the FBI via IC3 and do not account for other reporting channels. They also acknowledge that missing data and underreporting can result in &#8220;artificially low&#8221; loss estimates. However, they make no assumptions beyond this.</p><p>In contrast, the recent &#8220;<a href="https://www.ftc.gov/system/files/ftc_gov/pdf/P144400-OlderAdultsReportDec2025.pdf">Protecting Older Consumers 2024-2025</a>&#8221; report by the Federal Trade Commission clearly states, &#8220;we assume Sentinel includes only 2% of all losses from consumers who lost under $1,000 and 6.7% of all losses from consumers who lost $1,000 or more.&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6G5e!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5635b5c5-11ce-47f1-8910-4c705b8fcc6a_1326x148.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6G5e!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5635b5c5-11ce-47f1-8910-4c705b8fcc6a_1326x148.jpeg 424w, https://substackcdn.com/image/fetch/$s_!6G5e!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5635b5c5-11ce-47f1-8910-4c705b8fcc6a_1326x148.jpeg 848w, https://substackcdn.com/image/fetch/$s_!6G5e!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5635b5c5-11ce-47f1-8910-4c705b8fcc6a_1326x148.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!6G5e!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5635b5c5-11ce-47f1-8910-4c705b8fcc6a_1326x148.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6G5e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5635b5c5-11ce-47f1-8910-4c705b8fcc6a_1326x148.jpeg" width="1326" height="148" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5635b5c5-11ce-47f1-8910-4c705b8fcc6a_1326x148.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:148,&quot;width&quot;:1326,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:75162,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/193960442?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5635b5c5-11ce-47f1-8910-4c705b8fcc6a_1326x148.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6G5e!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5635b5c5-11ce-47f1-8910-4c705b8fcc6a_1326x148.jpeg 424w, https://substackcdn.com/image/fetch/$s_!6G5e!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5635b5c5-11ce-47f1-8910-4c705b8fcc6a_1326x148.jpeg 848w, https://substackcdn.com/image/fetch/$s_!6G5e!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5635b5c5-11ce-47f1-8910-4c705b8fcc6a_1326x148.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!6G5e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5635b5c5-11ce-47f1-8910-4c705b8fcc6a_1326x148.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Page 28 for reference.  </p><p>So the FTC &#8220;officially&#8221; assumes its reporting rate is somewhere between 2% and 7%.</p><p>Maybe IC3 is better known, and people are more inclined to report their victimization to them because it&#8217;s a division of the FBI. But can it be that much higher? Maybe a 15% reporting rate?</p><p>The IC3 reports that the total loss from Internet-enabled fraud in 2025 is $ 20.8 billion.</p><p>Imagine if that is only 15% of the true loss. What if it&#8217;s only 2-7%?</p><div><hr></div><h4>Speaking of AI tools&#8230;</h4><p>The cybersecurity world is going through a mind melt over the release, and potential public release, of &#8220;Mythos&#8221;.  </p><p>Anthropic&#8217;s Mythos is a highly advanced AI model focused on cybersecurity, particularly on identifying and analyzing software vulnerabilities.</p><p>Mythos finds exploitable vulnerabilities in software, systems, and networks at scale.</p><p>Think of a house. Every window, door, and air vent is a vulnerability that allows unwanted people to get into the house. We use security measures such as locks, shatterproof glass, reverse hinges, and other safeguards to ensure those vulnerabilities are secure and that only authorized people can enter and exit through them. Mythos finds that one window with a finicky lock, where, if you push a specific-style butter knife between the upper and lower panes, you can just reach the lock lever and pop it. And then it explains what materials you need and provides complete instructions on how to do it.</p><p>So does this mean the end of the vulnerability researcher? Are security companies specializing in this all going to go out of business? Maybe, maybe not. It will come down to cost.</p><p>Running these AI models isn&#8217;t free. While ChatGPT can generate some AI slop for your LinkedIn Hero account at no cost, operating a system that scans a corporate network and compares it against a comprehensive bug library requires substantial computation power, which will incur significant token costs.</p><p>And someone needs to pay real money for that usage. The impact of Mythos on the cybersecurity profession will, as with everything else, come down to economics. If the machine becomes more efficient and less expensive than a human, then we&#8217;ll see movement. But I don&#8217;t see that happening in the near future.</p><p>And I think maybe just the opposite.</p><p>So, a team at Anthropic created this model. Do you really think that China, Russia, North Korea, Iran, and other well-funded nation-state cyber teams won&#8217;t swiftly develop similar capabilities?</p><p>Certainly, and cybersecurity experts will continue to be essential in patching the vulnerabilities before these nation-states and criminal groups can exploit them.</p><p>Should your child still go to college for Cybersecurity? Meh, it&#8217;s still better than Journalism, but I don&#8217;t think tools like Mythos will be the immediate downfall of the entire field.</p><div><hr></div><h4>The News</h4><p>Do you use plugins on your WordPress site?  Someone purchased 30 different plugins and planted backdoors in each.  This author argues &#8220;the WordPress plug-in market has a trust issue.&#8221;  And further claims that <em>WordPress.org has no mechanism to flag or review plugin ownership transfers. There is no &#8220;change of control&#8221; notification to users. No additional code review triggered by a new committer. The Plugins Team responded quickly once the attack was discovered. But 8 months passed between the backdoor being planted and being caught.</em> <a href="https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/">https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/</a></p><p>The Financial Crimes Enforcement Network (FinCEN) has proposed a new rule to reform how financial institutions manage their anti-money laundering (AML) and counter-terrorism financing (CFT) programs under the Bank Secrecy Act. The reform aims to shift the focus from high-volume paperwork compliance to risk-based, effective programs that actually combat illicit finance, while reducing regulatory burden on banks. Maybe, I won&#8217;t hold my breath.  <a href="https://www.fincen.gov/news/news-releases/fincen-proposes-rule-fundamentally-reform-financial-institution-programs">https://www.fincen.gov/news/news-releases/fincen-proposes-rule-fundamentally-reform-financial-institution-programs</a></p><p>The FBI successfully recovered deleted Signal messages from a suspect&#8217;s iPhone by extracting data from the device&#8217;s internal notification storage, even after the Signal app had been removed. This was possible because the defendant had not enabled Signal&#8217;s setting to hide message content from notifications, allowing the full text to be cached locally by iOS. However, Apple recently changed how iOS 26.4 validates push notification tokens, so this method may no longer work.   <a href="https://9to5mac.com/2026/04/09/fbi-used-iphone-notification-data-to-retrieve-deleted-signal-messages/">https://9to5mac.com/2026/04/09/fbi-used-iphone-notification-data-to-retrieve-deleted-signal-messages/ </a></p><p>The CIA is increasingly deploying artificial intelligence to enhance its core intelligence analysis mission. The agency has already produced its first autonomous intelligence report and plans to integrate AI &#8220;co-workers&#8221; across all of its analytic platforms within the next few years to help analysts with tasks such as drafting assessments, testing conclusions, and identifying trends. The agency claims humans will remain responsible for key decisions, but it also noted that it tested 300 AI projects last year and is working to bring AI capabilities to field officers. <a href="https://www.politico.com/news/2026/04/09/cia-ai-intelligence-analysis-00865893">https://www.politico.com/news/2026/04/09/cia-ai-intelligence-analysis-00865893</a></p><p>The first step a skilled attacker takes after gaining unauthorized access to a Microsoft 365 account is to abuse mailbox rules. Rather than deploying malware, they use native M365 features to create rules that automatically forward, hide, delete, or archive emails, enabling covert data exfiltration, suppressing security alerts, and maintaining persistence even after password changes. Proofpoint explains that these rules can be deployed in as little as 5 seconds after compromise and can be fully automated at scale via the Microsoft Graph API. <a href="https://www.proofpoint.com/us/blog/threat-insight/mailbox-rules-o365-post-exploitation-tactic-cloud-ato">https://www.proofpoint.com/us/blog/threat-insight/mailbox-rules-o365-post-exploitation-tactic-cloud-ato</a></p><p>Don&#8217;t end up on the &#8220;Sucker List&#8221;.  <a href="https://www.welivesecurity.com/en/scams/recovery-scammers-hit-when-down-avoid-second-strike/">https://www.welivesecurity.com/en/scams/recovery-scammers-hit-when-down-avoid-second-strike/</a></p><div><hr></div><h4>Feedback</h4><p>Send Feedback to matt(at)threatswithoutborders.com</p><div><hr></div><h4>Evidence</h4><p>Why screenshots fail in court.  <a href="https://lucidtruthtechnologies.com/authenticate-social-media-evidence/">https://lucidtruthtechnologies.com/authenticate-social-media-evidence/</a></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>Cool Jobs</h4><p>Security Operations Associate - National Football League.  <a href="https://job-boards.greenhouse.io/nflcareers/jobs/5127529008">https://job-boards.greenhouse.io/nflcareers/jobs/5127529008</a></p><p>Why MLB?  Why are you still making people work in New York City?  Ugh.  Incident Response and Intel Analyst, Major League Baseball.  <a href="https://hub.globalsportsjobs.com/vacancy/incident-response-intel-analyst-us-glap119784">https://hub.globalsportsjobs.com/vacancy/incident-response-intel-analyst-us-glap119784 </a></p><h4>Cool Tools</h4><p>2026 DIY Opt-Out Manual For Removal From Over 400 Sites.  <a href="https://github.com/thumpersecure/opt-out-manual-2026">https://github.com/thumpersecure/opt-out-manual-2026</a></p><p>Little Snitch (iykyk) but for Linux.  <a href="https://obdev.at/products/littlesnitch-linux/index.html">https://obdev.at/products/littlesnitch-linux/index.html</a></p><div><hr></div><h4>Irrelevant</h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KdhA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed7a14a8-0eb5-47ee-9f00-819df36ebe84_1330x760.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KdhA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed7a14a8-0eb5-47ee-9f00-819df36ebe84_1330x760.jpeg 424w, https://substackcdn.com/image/fetch/$s_!KdhA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed7a14a8-0eb5-47ee-9f00-819df36ebe84_1330x760.jpeg 848w, https://substackcdn.com/image/fetch/$s_!KdhA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed7a14a8-0eb5-47ee-9f00-819df36ebe84_1330x760.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!KdhA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed7a14a8-0eb5-47ee-9f00-819df36ebe84_1330x760.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KdhA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed7a14a8-0eb5-47ee-9f00-819df36ebe84_1330x760.jpeg" width="1330" height="760" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ed7a14a8-0eb5-47ee-9f00-819df36ebe84_1330x760.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:760,&quot;width&quot;:1330,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:122816,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/193960442?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed7a14a8-0eb5-47ee-9f00-819df36ebe84_1330x760.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KdhA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed7a14a8-0eb5-47ee-9f00-819df36ebe84_1330x760.jpeg 424w, https://substackcdn.com/image/fetch/$s_!KdhA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed7a14a8-0eb5-47ee-9f00-819df36ebe84_1330x760.jpeg 848w, https://substackcdn.com/image/fetch/$s_!KdhA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed7a14a8-0eb5-47ee-9f00-819df36ebe84_1330x760.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!KdhA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed7a14a8-0eb5-47ee-9f00-819df36ebe84_1330x760.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h4>Sign Off</h4><p>I thought I wrote a pretty good newsletter last week, but I somehow finished the week with fewer subscribers than I started with. Tough crowd. I sincerely appreciate everyone who stays with me.</p><p>Enjoy the warmer weather! Those of you in the Midwest should stay in your storm cellars. I&#8217;ll see you all next week.  </p><p>Matt</p><p>&#8220;IT TAKES LESS TIME TO DO A THING RIGHT THAN TO EXPLAIN WHY YOU DID IT WRONG.&#8221;</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 281]]></title><description><![CDATA[Cybercrime Investigation Newsletter, week ending April 5, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-281</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-281</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 07 Apr 2026 10:05:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-qyh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c5132c-9044-4ab4-9d03-393c688aeedf_1508x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-qyh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c5132c-9044-4ab4-9d03-393c688aeedf_1508x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-qyh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c5132c-9044-4ab4-9d03-393c688aeedf_1508x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-qyh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c5132c-9044-4ab4-9d03-393c688aeedf_1508x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-qyh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c5132c-9044-4ab4-9d03-393c688aeedf_1508x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-qyh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c5132c-9044-4ab4-9d03-393c688aeedf_1508x440.jpeg" width="1456" height="425" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/26c5132c-9044-4ab4-9d03-393c688aeedf_1508x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:425,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:102396,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/193308066?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c5132c-9044-4ab4-9d03-393c688aeedf_1508x440.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-qyh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c5132c-9044-4ab4-9d03-393c688aeedf_1508x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-qyh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c5132c-9044-4ab4-9d03-393c688aeedf_1508x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-qyh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c5132c-9044-4ab4-9d03-393c688aeedf_1508x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-qyh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c5132c-9044-4ab4-9d03-393c688aeedf_1508x440.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This was a DTMF attack. And it&#8217;s so damn clever!</p><p>When you press a key on your phone&#8217;s keypad, it generates a specific pair of audio tones. This system is called DTMF, or Dual-Tone Multi-Frequency signaling. Each key, 0 through 9, along with the asterisk and pound, produces a unique combination of two tones that phone systems use to identify what was pressed. It&#8217;s the same technology that lets you &#8220;press 1 for English&#8221; or enter your account number on an automated line. But those tones are just sounds, and anyone on the call with you can hear, record, and decode them.</p><p>That&#8217;s exactly what the scammer did.</p><p>When this Redditor called the balance verification number using three-way calling with the buyer on the line, they entered the card number and PIN using their keypad. Those DTMF tones traveled directly through the call to the scammer&#8217;s end in real time. The scammer either recorded the call or used software to decode the tones as the victim pressed them, translating each beep back into the exact digits entered. Once they had the card number and PIN, they hung up, logged into the gift card issuer&#8217;s website or called the automated line themselves, and drained the balance. The entire process likely took just minutes.</p><p>The technology behind this isn&#8217;t complex. Tools for recording and decoding DTMF tones are readily available and free. However, what made this attack so effective wasn&#8217;t the technology; it was the social engineering. The scammer didn&#8217;t hack anything; they simply created a situation where the victim willingly entered the credentials while they listened. The three-way call seemed like a normal, cooperative action. A buyer wanting to verify a balance before purchasing makes complete sense. That&#8217;s exactly why it succeeded. Social engineering attacks don&#8217;t target systems; they exploit trust.</p><p><a href="https://en.wikipedia.org/wiki/DTMF_signaling">https://en.wikipedia.org/wiki/DTMF_signaling</a></p><p><a href="https://nhollmann.github.io/DTMF-Tool/">https://nhollmann.github.io/DTMF-Tool/</a></p><div><hr></div><h4>Wilmington? </h4><p>Last week, I spoke at the Delaware Fraud Working Group conference in Wilmington, Delaware. What a pleasant event! I&#8217;m disappointed I had another commitment and couldn&#8217;t spend the entire day.</p><p>The host venue at Delaware Technical Community College was fantastic&#8212;truly one of the best places I&#8217;ve spoken at. I was also pleasantly surprised by Wilmington. I&#8217;ve long written off cities like Philadelphia and New York and generally refuse to attend any event hosted there. Heavy traffic, limited parking, panhandlers, dirt, and chaos make the inconveniences and costs too high to justify the effort.  </p><p>Wilmington probably has those issues, but I didn&#8217;t experience them. The drive into the city from the West was smooth, and parking was straightforward and, best of all, free. The only problem I faced was the haze of marijuana smoke in the parking garage stairwell.  </p><p>I&#8217;m not sure whether the DFWG will host next year's event at DelTech, but if you&#8217;re within a reasonable drive, attend.</p><div><hr></div><h4>Reader Mail</h4><p><em>Matt, your take on the Darksword exploit is one of the most balanced I&#8217;ve read. You should push that to a publication with a much wider reach. It&#8217;s genuinely better than most things I&#8217;ve seen in any of the major news outlets. </em> - JohnS</p><p><em>I was an examiner with a 3 letter agency for eight years, and now I work for an incident response firm. I can&#8217;t stress enough how important it is for people to keep their devices updated. We recently had an incident in which the owner of a business was using an iPhone XR running iOS 17.7. How does that happen? It&#8217;s really that simple. Keep your devices on the most recent version, and you eliminate 99.9% of remote exploits. </em>- KS</p><p>See Issue 280 for context.</p><div><hr></div><h4>The News&#8230;</h4><p>David Maimon explains the fraud known as &#8220;Pell Running&#8221; that is crushing the American federal student loan system.  <a href="https://resources.sentilink.com/blog/inside-pell-running-the-federal-student-aid-fraud-congress-is-trying-to-stop">https://resources.sentilink.com/blog/inside-pell-running-the-federal-student-aid-fraud-congress-is-trying-to-stop</a></p><p>AI-generated deepfake audio has raised concerns about the integrity of evidence. With voice cloning tools becoming affordable and widely available, it&#8217;s now simple to produce realistic fake audio recordings of voicemails, calls, or confessions that can be used as evidence in legal proceedings, insurance claims, or business disagreements. <a href="https://www.forbes.com/sites/larsdaniel/2026/03/15/beyond-cybersecurity-deepfake-audio-is-an-evidence-crisis/">https://www.forbes.com/sites/larsdaniel/2026/03/15/beyond-cybersecurity-deepfake-audio-is-an-evidence-crisis/</a></p><p>It&#8217;s tax season and that means tax scam season. Proofpoint has identified over 100 malicious campaigns using tax-themed lures to deliver malware, Remote Monitoring &amp; Management tools, credential phishing, and fraud. <a href="https://www.proofpoint.com/us/blog/threat-insight/security-brief-tax-scams-aim-steal-funds-taxpayers">https://www.proofpoint.com/us/blog/threat-insight/security-brief-tax-scams-aim-steal-funds-taxpayers</a></p><p>A recently identified phishing-as-a-service platform is targeting C-suite executives using highly personalized, QR-code-based emails that impersonate SharePoint notifications. These emails bypass detection using techniques such as randomized HTML noise, fake email threads, and Unicode QR codes that evade image scanners. When scanned, victims are led through a multi-layered &#8220;gate&#8221; that prevents automated tools and researchers from proceeding, before being redirected to credential harvesters. More worrisome, the exploit functions within Microsoft&#8217;s authentication system, making traditional MFA ineffective as a key line of defense.  <a href="https://abnormal.ai/blog/venom-phishing-campaign-mfa-credential-theft">https://abnormal.ai/blog/venom-phishing-campaign-mfa-credential-theft</a></p><p>I currently hold two SANS/GIAC certifications and recently let a third (GSEC) expire. The exams and their preparation are quite demanding. The crucial aspect is really the preparation process itself. Although the exams are open book, spending too much time looking up answers will result in you running out of time. You will need to look up some answers quickly, and this is where the index becomes essential. Here is a good take on creating an effective index.  <a href="https://aerobytes.io/writeups/giac-indexing-guide/">https://aerobytes.io/writeups/giac-indexing-guide/</a></p><p>Two individuals have pleaded guilty in federal court in Rhode Island for their roles in a transnational fraud and money laundering scheme targeting elderly victims across the U.S. and Canada. The scheme involved fraudsters posing as representatives of financial institutions and government agencies, such as the FTC and the Federal Reserve, convincing victims that their accounts were compromised and directing them to transfer funds via wire transfers, cryptocurrency, cash, or gold bars. The scheme defrauded approximately 300 victims across 37 states, with known losses exceeding $5 million. <a href="https://www.justice.gov/usao-ri/pr/two-defendants-plead-guilty-transnational-fraud-scheme-targeting-elderly-victims">https://www.justice.gov/usao-ri/pr/two-defendants-plead-guilty-transnational-fraud-scheme-targeting-elderly-victims</a></p><p>Uno is a good boy.  <a href="https://cdapress.com/news/2026/apr/01/coffee-with-a-k9/">https://cdapress.com/news/2026/apr/01/coffee-with-a-k9/</a></p><div><hr></div><h4>DFIR</h4><p>Tsurugi Linux released update version 26.03 on iso or ova.  <a href="https://tsurugi-linux.org/downloads.php">https://tsurugi-linux.org/downloads.php</a></p><div><hr></div><h4>Cool Tools</h4><p>FTC Sentinel Fraud Dashboard.  <a href="https://public.tableau.com/app/profile/federal.trade.commission/viz/FraudReports/FraudFacts">https://public.tableau.com/app/profile/federal.trade.commission/viz/FraudReports/FraudFacts</a></p><p>Who is giving money to whom?  <a href="https://www.opensecrets.org/">https://www.opensecrets.org/</a></p><h4>Cool Job</h4><p>Card Fraud Manager, Members 1st Federal Credit Union.  <a href="https://careers.members1st.org/jobs/2682/Card%20Fraud%20Manager">https://careers.members1st.org/jobs/2682/Card%20Fraud%20Manager</a></p><p>Vice President of Consumer and Banking Fraud Strategy. JP Morgan Chase <a href="https://jpmc.fa.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1001/job/210699592">https://jpmc.fa.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1001/job/210699592</a></p><div><hr></div><h4>Irrelevant</h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ivhR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa064f124-1173-457e-a0ce-40df43c53d77_1340x1288.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ivhR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa064f124-1173-457e-a0ce-40df43c53d77_1340x1288.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ivhR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa064f124-1173-457e-a0ce-40df43c53d77_1340x1288.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ivhR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa064f124-1173-457e-a0ce-40df43c53d77_1340x1288.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ivhR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa064f124-1173-457e-a0ce-40df43c53d77_1340x1288.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ivhR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa064f124-1173-457e-a0ce-40df43c53d77_1340x1288.jpeg" width="1340" height="1288" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a064f124-1173-457e-a0ce-40df43c53d77_1340x1288.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1288,&quot;width&quot;:1340,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:333897,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/193308066?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa064f124-1173-457e-a0ce-40df43c53d77_1340x1288.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ivhR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa064f124-1173-457e-a0ce-40df43c53d77_1340x1288.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ivhR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa064f124-1173-457e-a0ce-40df43c53d77_1340x1288.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ivhR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa064f124-1173-457e-a0ce-40df43c53d77_1340x1288.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ivhR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa064f124-1173-457e-a0ce-40df43c53d77_1340x1288.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Credit: Varun.ch</p><div><hr></div><h4>Feedback</h4><p>matt (at) threatswithoutborders.com</p><div><hr></div><h4>Sign Off</h4><p>Wow, a lot of new subscribers this week. </p><p>So, what&#8217;s this all about? See that issue number, 281&#8212;that&#8217;s how many consecutive weeks the Threats Without Borders Newsletter has been published. Yep, every Tuesday morning for five years and four months. Never a miss. What I lack in quality, substance, and style, I make up for in tenacity.  </p><p>Welcome.  And when your email provider drops the newsletter or your company decides newsletters are a time-suck and creates a &#8220;unsubscribe and delete&#8221; rule, you can always find every issue published at www.threatswithoutborders.com.</p><p>Or install the Substack app on your smartphone and ensure delivery each week.  </p><div class="install-substack-app-embed install-substack-app-embed-web" data-component-name="InstallSubstackAppToDOM"><img class="install-substack-app-embed-img" src="https://substackcdn.com/image/fetch/$s_!lkkz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07f3f957-f680-4ee2-b274-e8ca2ac66a24_600x600.png"><div class="install-substack-app-embed-text"><div class="install-substack-app-header">Get more from Matt Dotts in the Substack app</div><div class="install-substack-app-text">Available for iOS and Android</div></div><a href="https://substack.com/app/app-store-redirect?utm_campaign=app-marketing&amp;utm_content=author-post-insert&amp;utm_source=cyficrime" target="_blank" class="install-substack-app-embed-link"><button class="install-substack-app-embed-btn button primary">Get the app</button></a></div><p>Thanks for checking us out and I hope to see you all next week.  </p><p>Matt</p><p>&#8220;DON&#8217;T LET A BAD DAY MAKE YOU FEEL LIKE YOU HAVE A BAD LIFE.&#8221;</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 280]]></title><description><![CDATA[Cybercrime Investigation Newsletter, week ending March 29, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-280</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-280</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 31 Mar 2026 10:46:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A few weeks ago, I addressed a concern in this space about Apple iPhone users claiming, &#8220;Wasn&#8217;t me, my phone was hacked.&#8221; My response was straightforward: unless they are a direct target of a nation-state, the iPhone was not secretly compromised.</p><p>Well... news recently broke about an iPhone exploit called Darksword, and it has me reevaluating my stance on the issue.    </p><h4><strong>Yes, your iPhone can be hacked; no, you&#8217;re probably not interesting enough to justify the price tag.</strong></h4><p>That tension, between what&#8217;s possible and what&#8217;s probable, is getting lost in the conversation around advanced mobile exploits like DarkSword. Headlines and social media chatter tend to flatten everything into the same message: your phone is vulnerable at any time. Technically, that&#8217;s true. Practically, it&#8217;s sensational trash.</p><p>DarkSword isn&#8217;t a typical piece of malware you download or install. It&#8217;s an exploit chain, a carefully engineered sequence of vulnerabilities that allows an attacker to break into an iPhone, escalate privileges, and extract data. It&#8217;s not a virus but a master key that unlocks multiple doors in sequence. Once inside, it can deploy tools to collect messages, access apps, or monitor activity, often without leaving much evidence behind.</p><p>That kind of capability has not just been rare, but elite. Building something like this requires deep expertise, time, and significant financial investment. For years, these tools were almost exclusively in the hands of nation-states and a small number of highly specialized surveillance vendors. And because they were so valuable, they were used sparingly, against very specific, high-value targets.</p><h4>The ceiling hasn&#8217;t changed. These are still highly sophisticated, expensive, and complex attacks. But the floor has dropped.</h4><p>The challenge of developing these capabilities remains very high, but the difficulty of accessing them is decreasing. We&#8217;re observing the same trend that has occurred in other areas of cybercrime. There was a time when launching a ransomware attack required significant technical skill. Now, ransomware-as-a-service has made it much more accessible. The expertise hasn&#8217;t disappeared; it has been packaged, productized, and distributed.</p><p>Bad guys who previously could not develop an iPhone exploit chain can now sometimes access or lease that capability. This doesn&#8217;t mean &#8220;anyone&#8221; can do it, but it does expand the pool of potential attackers. It&#8217;s no longer limited to intelligence agencies and top-tier operators; it may now include smaller governments, private intelligence firms, and well-funded criminal groups. </p><p>Yes, it is now more possible for a broader range of attackers to use these tools. No, it is still not probable that they will be used against the average person.</p><p>There are a few reasons for that.</p><p><strong>First, these exploits remain costly assets.</strong> Even as access becomes more available, it&#8217;s not free or simple. Using one involves risk for the attacker. Each deployment raises the likelihood that the exploit will be discovered, analyzed, and patched. Burning a valuable capability on a random target offers little economic or operational benefit.</p><p><strong>Second, these attacks still require targeting.</strong> Even a &#8220;one-click&#8221; exploit&#8212;where a user simply taps a link&#8212;relies on getting that link in front of the right person at the right time. That involves reconnaissance, delivery methods, and often some level of social engineering. This is not spray-and-pray activity. It&#8217;s intentional.</p><p><strong>Third, and what I&#8217;ve been saying for a long time, is that there are far easier ways to compromise people.</strong></p><p>Most cybercriminals don&#8217;t need a complicated exploit chain to succeed. Phishing emails, fake login pages, password reuse, SIM swapping, and social engineering are much cheaper and easier to scale. If they aim for financial gain, these methods provide a higher return on investment. Why invest heavily in a complex iPhone exploit when a convincing text message can trick someone into giving up their credentials?</p><p>This is why, for the average iPhone user, the biggest risks remain the same as they were before: scams, phishing, weak passwords, and account takeovers. Not zero-day exploits.</p><p>But that doesn&#8217;t mean nothing has changed.</p><p><strong>The important shift is in who might now be considered &#8220;worth it.&#8221;</strong></p><p>Previously, the range of targets for these attacks was very limited. Now, it has expanded, not to include everyone, but to include more individuals than before. Those now at risk include journalists, business leaders, government workers, activists, and anyone with access to confidential information or financial assets, even if they don&#8217;t operate internationally.</p><p>Additionally, there is a risk of spillover. As these tools become more widely used, there&#8217;s an increased chance of errors&#8212;such as incorrect numbers, misidentified devices, or infrastructure that unintentionally exposes unintended users. This doesn&#8217;t suddenly make everyone a target, but it does add more unpredictability to where these capabilities might be exploited.</p><p><strong>So where does that leave the everyday iPhone user?</strong></p><p><em>The iPhone is not under constant threat from elite hackers. It is not being silently compromised at random. But it is also no longer accurate to assume that these capabilities exist only in distant, highly controlled environments.</em></p><p>Understand that advanced attacks exist. Recognize that they are becoming more accessible to a wider range of actors. But also keep in perspective that attackers are still making decisions based on cost, value, and likelihood of success. Most people simply do not present a target that justifies the use of such a tool. </p><p>And importantly, many of the protections against these advanced threats are straightforward.</p><p><strong>Keeping your iPhone updated is one of the most effective things you can do.</strong> These exploit chains rely on vulnerabilities, and once those vulnerabilities are patched, the window of opportunity closes. Delaying updates means leaving the door open longer than necessary.</p><p>Apple has also introduced built-in protections designed specifically for high-risk scenarios, such as <strong>Lockdown Mode</strong>. While not necessary for most users, it&#8217;s a powerful option for those who may be more likely to be targeted.</p><p>Yes, an iPhone can be hacked.</p><p>But what matters far more is whether it&#8217;s likely - and for most people, it still isn&#8217;t.</p><p>So in your investigations, it&#8217;s something you need to account for&#8230; but probably not.  </p><div><hr></div><h4>Speaking of Lockdown Mode</h4><p>Nearly four years after its 2022 debut, Apple&#8217;s Lockdown Mode remains undefeated by mercenary spyware, with both Apple and independent investigators such as Amnesty International confirming that no devices with the feature activated have been successfully attacked. Citizen Lab researchers have documented instances where Lockdown Mode effectively prevented Pegasus and Predator spyware attacks. <a href="https://techcrunch.com/2026/03/27/apple-says-no-one-using-lockdown-mode-has-been-hacked-with-spyware/">https://techcrunch.com/2026/03/27/apple-says-no-one-using-lockdown-mode-has-been-hacked-with-spyware/</a></p><h4>Skimming Report</h4><p>I&#8217;ll write more about this report, but I just don&#8217;t have the space today.  FICO released the report &#8220;The State of Card Skimming in the US: 2025 Year In Review&#8221;.  <a href="https://www.fico.com/blogs/state-card-skimming-us-2025-year-review">https://www.fico.com/blogs/state-card-skimming-us-2025-year-review</a></p><div><hr></div><h4>Cool Job</h4><p>Data Scientist, Predictive Fraud Intelligence - VISA.  <a href="https://jobs.smartrecruiters.com/Visa/744000117342711-data-scientist-predictive-fraud-intelligence">https://jobs.smartrecruiters.com/Visa/744000117342711-data-scientist-predictive-fraud-intelligence</a></p><p>Fraud Risk Governance Lead - Customers Bank.  <a href="https://customersbank.wd1.myworkdayjobs.com/customersbankcareers/job/Malvern-PA/Fraud-Risk-Governance-Lead_REQ-2026-851">https://customersbank.wd1.myworkdayjobs.com/customersbankcareers/job/Malvern-PA/Fraud-Risk-Governance-Lead_REQ-2026-851</a></p><h4>Cool Tool</h4><p>IRS charity search -  <a href="https://apps.irs.gov/app/eos/">https://apps.irs.gov/app/eos/</a></p><p>How charitable is a charity? Charity Navigator - <a href="https://www.charitynavigator.org/">https://www.charitynavigator.org/</a></p><p>International phone number look-up.  <a href="https://www.thisnumber.com/">https://www.thisnumber.com/</a></p><div><hr></div><h4>Irrelevant</h4><p>The U.S. Army increased its maximum enlistment age to 42. Meh, I&#8217;m still too old, but of course, I couldn't have done it at 42 either. Kudos to anyone over 40 who accepts this challenge!    <a href="https://abcnews.com/Politics/army-extends-maximum-recruitment-age-42-allowing-older/story?id=131411519">https://abcnews.com/Politics/army-extends-maximum-recruitment-age-42-allowing-older/story?id=131411519</a></p><div><hr></div><h4>Sign Off</h4><p>I had to cut the news section today due to space limitations.  It will be back next week. </p><p>Do you know what a DTMF attack is?  Or how they use it to steal the balance from gift cards?  Come back next week to learn more.</p><p>Matt</p><p>&#8220;IF YOU WAIT FOR EVERYTHING TO FALL INTO PLACE BEFORE YOU ACT, YOU WILL NEVER MOVE.&#8221;</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 279]]></title><description><![CDATA[Cybercrime Investigation Newsletter, Week ending March 22, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-279</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-279</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 24 Mar 2026 11:20:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>So many times when we think of &#8220;cybercrime&#8221; or crime facilitated through the use of technology and the Internet, we think of the usual suspects - network intrusions with data theft, ransomware, DDOS attacks, investment and romance scams, email phishing&#8230; or any of the other crimes detailed in the Internet Crime Complaint Center&#8217;s yearly report.  </p><p>Rarely do we ever think of music fraud.  And certainly not music fraud involving AI-created music and a massive botnet that generates millions of &#8220;listens&#8221; across a dozen streaming services.</p><p>A North Carolina man has admitted guilt in a widespread music streaming fraud that occurred from 2017 to 2024. He used AI-generated songs and up to 10,000 bot accounts simultaneously to artificially inflate streaming counts on platforms such as Spotify, Apple Music, Amazon Music, and YouTube Music, resulting in billions of fake streams. To evade detection, he used VPNs and distributed activity across hundreds of thousands of tracks. Through this operation, he generated over $8 million in royalties. </p><p>Posting AI-generated music on streaming services isn&#8217;t illegal. The crime lies in using countless zombie machines to &#8220;listen&#8221; to the music. </p><p>He exploited technology and the Internet to set up a situation where victim businesses paid him money that he didn't legitimately earn.  And 8 million dollars isn&#8217;t chump change.  </p><p>Fraud is as old as time, and most schemes are not new, but the convergence of financial crime and the Internet continually takes us into new territory and pushes the boundaries of &#8220;cybercrime&#8221;.  </p><p><a href="https://www.justice.gov/usao-sdny/pr/north-carolina-man-pleads-guilty-music-streaming-fraud-aided-artificial-intelligence-0">https://www.justice.gov/usao-sdny/pr/north-carolina-man-pleads-guilty-music-streaming-fraud-aided-artificial-intelligence-0</a></p><div><hr></div><h4>Audit PTO </h4><p>When providing fraud-prevention training to business owners and executives, I emphasize the importance of job rotation and mandated paid time off (PTO). </p><p>I often cite an investigation I was involved in where the suspect employee hadn&#8217;t taken any vacation for seven years. Although she took occasional days off around holidays, she never scheduled a full week off during that period. </p><p>She operated a sophisticated refund scheme, funneling refunds into her own accounts, and she knew that anyone who stepped into her role could uncover her fraud. Her eventual exposure came when a new accounting software flagged irregularities during a routine audit. </p><p>Over those seven years, she embezzled more than $200,000 from her employer. </p><p>This case from a Pennsylvania casino is the latest example of an insider executing a scam that could have been quickly uncovered if someone else had briefly stepped into the role. In fact, that&#8217;s precisely how she was caught: </p><blockquote><p><em>When Petrillo was on medical leave, an employee at the casino&#8217;s horse racing office assisted with the office paperwork. Police said that&#8217;s when the employee discovered the discrepancies.</em></p></blockquote><p>At least once a year, every financial role in the organization should be temporarily filled by another person for a few days. This practice not only helps prevent fraud but also enhances redundancy and recovery options. If someone refuses to take a week off, it should be forced. </p><p>An employee who refuses to use their Paid Time Off is a huge red flag&#8230; in more ways than one.</p><p>This employee stole over $700,000.  And it&#8217;s so preventable.</p><p><a href="https://www.pennlive.com/crime/2026/03/hollywood-casino-employee-accused-of-stealing-over-700k-in-fraud-scheme.html">https://www.pennlive.com/crime/2026/03/hollywood-casino-employee-accused-of-stealing-over-700k-in-fraud-scheme.html</a></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>The News&#8230;</h4><p>Holy... we&#8217;re smoked. Although hype for their own product, this article by Sublime Security describes a new attack that masquerades as a Zoom meeting invite but results in the recipient installing malware on their Windows PC. The extent to which the attackers go to pull this off is impressive. They even run a JavaScript-enabled Zoom meeting simulation in the browser session - complete with technical difficulties. Anyone who has ever worked at a Help Desk or in a role involving regular interaction with non-technical users knows this issue will have a significant impact on unsecured organizations that use Zoom.   <a href="https://sublime.security/blog/advanced-fake-zoom-installer-used-for-delivering-malware/">https://sublime.security/blog/advanced-fake-zoom-installer-used-for-delivering-malware/</a></p><p>Keep your iPhone updated, and these exploits will not be so bothersome. In fact, not at all.  The Google Threat Intelligence Group reports the &#8220;DarkSword&#8221; exploit for Apple iPhone devices has been adopted by multiple threat actors since November 2025. The exploit chain uses six zero-day vulnerabilities to fully compromise iOS devices running versions 18.4-18.7.  For the record, you should be on some version of iOS 26, preferably 26.3.1 (at the time of this writing).  <a href="https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain">https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain</a></p><p>SEC will vote on reducing the quarterly reporting requirement to twice a year.  <a href="https://www.reuters.com/business/finance/us-sec-preparing-eliminate-quarterly-reporting-requirement-wsj-says-2026-03-16/">https://www.reuters.com/business/finance/us-sec-preparing-eliminate-quarterly-reporting-requirement-wsj-says-2026-03-16/</a></p><p>Ok, this scam needed to be shut down, but are there actual victims here? Law enforcement authorities from 23 countries carried out *Operation Alice*, a major crackdown on a dark web network run by a 35-year-old in China. Over five years, he operated more than 373,000 fraudulent Tor domains, promoting child sexual abuse material (CSAM) and cybercrime-as-a-service (CaaS). He defrauded around 10,000 customers of over $345,000 in Bitcoin, without ever delivering the promised content. While the sites claimed to offer CSAM &#8220;packages&#8221; ranging from gigabytes to terabytes, they were entirely fake and victims were never supplied with the material.  Europol coordinated international intelligence efforts, tracked cryptocurrency transactions, and helped identify the operator, who used up to 287 servers worldwide. <a href="https://www.europol.europa.eu/media-press/newsroom/news/global-cybercrime-crackdown-over-373-000-dark-web-sites-shut-down">https://www.europol.europa.eu/media-press/newsroom/news/global-cybercrime-crackdown-over-373-000-dark-web-sites-shut-down</a></p><p>Pennsylvania Attorney General Dave Sunday announced that the leader of a criminal organization that defrauded central Pennsylvania banks and their customers of more than $3 million has been sentenced to prison and ordered to pay more than half-a-million dollars in restitution. <a href="https://www.attorneygeneral.gov/taking-action/ringleader-in-multi-million-dollar-central-pa-bank-fraud-scheme-sentenced-to-prison/">https://www.attorneygeneral.gov/taking-action/ringleader-in-multi-million-dollar-central-pa-bank-fraud-scheme-sentenced-to-prison/</a></p><p>Bank and credit union compliance software provider Marquis confirmed that a data breach discovered in August 2025 affected approximately 672,000 individuals, which is much less than the previously estimated 1.6 million. Of course, that doesn&#8217;t make it any better, just less impactful. The attackers stole sensitive personal and financial information, including names, addresses, Social Security numbers, dates of birth, and payment card numbers from dozens of the financial institutions Marquis serves. <a href="https://www.securityweek.com/marquis-data-breach-affects-672000-individuals/">https://www.securityweek.com/marquis-data-breach-affects-672000-individuals/</a></p><div><hr></div><h4>DFIR</h4><p>Andrea Fortuna introduces the DFIR Toolkit.  <a href="https://andreafortuna.org/2026/03/17/dfir-toolkit">https://andreafortuna.org/2026/03/17/dfir-toolkit</a></p><div><hr></div><h4>Cool Job</h4><p>Criminal Intelligence Analyst, Group 9.  <a href="https://groupnine.us/careers/">https://groupnine.us/careers/</a></p><h4>Cool Tool</h4><p>I was a longtime user of Evernote, but left when it was bought by Bending Spoons, and they priced it out of reality. I&#8217;ve since switched to the fantastic notes app Bear, but it's only available on Apple devices. So, for you Windows users still feeling the loss of Evernote - try Cimanote.  &#8220;<em>Cimanote is the fast, clean note-taking app for people tired of Evernote's bloat and price hikes. Sign up today &#8212; your first year is completely on us.&#8221;   </em><a href="https://cimanote.com/">https://cimanote.com/</a></p><div><hr></div><h4>Irrelevant</h4><p>More evidence that not all addictions are bad. This long-term study discovered that moderate intake of caffeinated coffee or tea was associated with an 18% lower risk of dementia and improved cognitive performance over time.  <a href="https://www.sciencedaily.com/releases/2026/03/260318033138.htm">https://www.sciencedaily.com/releases/2026/03/260318033138.htm</a></p><div><hr></div><h4>Get Learned</h4><p>SLEUTHCON is a forum for identifying and exploring cybercrime and financially-motivated threats.  Friday, June 5, 2026.  Arlington, VA and Virtual.  <a href="https://www.sleuthcon.com/">https://www.sleuthcon.com/</a></p><p>Delaware Fraud Working Group, Full-Day Fraud Prevention Summit.  Thursday, April 2, 2026.  Wilmington, DE.  <a href="https://www.eventbrite.com/e/delaware-fraud-working-group-full-day-fraud-prevention-summit-tickets-1982375409213">https://www.eventbrite.com/e/delaware-fraud-working-group-full-day-fraud-prevention-summit-tickets-1982375409213</a></p><div><hr></div><h4>Late Breaking</h4><p>If you think you need a new router, buy one now. The FCC plans to ban all foreign-made routers. While this isn&#8217;t necessarily a bad thing and will certainly benefit the American tech industry, the issue is that nearly every router is made entirely, or at least with parts from, outside the U.S. Once this rule is enforced, American manufacturers won't be able to meet the demand for a long time.  When I searched for American-made routers, the only one I found that is made entirely in the U.S. is Starlink.  Hmm.  Is that a coincidence?    <a href="https://docs.fcc.gov/public/attachments/DOC-420034A1.pdf">https://docs.fcc.gov/public/attachments/DOC-420034A1.pdf</a></p><div><hr></div><h4>Sign Off</h4><p>The best news of the week is that by Friday, the RSAC Conference will be over, and our inboxes will be free from the daily influx of emails from salespeople asking to &#8220;connect&#8221; during the event.  </p><p>Thanks again for opening another issue of the newsletter.  Cheers to sunshine and warmer weather!</p><p>Matt</p><p>&#8220;YOU WILL NEVER START ANYTHING IF YOU ALWAYS WAIT UNTIL YOU ARE FULLY READY.&#8221;</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 278]]></title><description><![CDATA[Cybercrime Investigation Newsletter, week ending March 15, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-278</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-278</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 17 Mar 2026 11:20:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!AwOR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b17363-731f-4ef4-9d3a-1794924e0af3_1268x1424.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><p>I&#8217;m old enough to remember when ATM&#8217;s arrived on the scene.  Of course, we called them &#8220;MAC Machines&#8221;.  I recall a local bank holding a contest to see who could withdraw the most money in a set amount of time to highlight the ease of use.  </p><p>I also remember the concern that such technology raised about the future of banking.  Well, the ATM didn&#8217;t replace the teller.  But as this excellent article highlights, the smartphone is.</p><div class="embedded-post-wrap" data-attrs="{&quot;id&quot;:190553382,&quot;url&quot;:&quot;https://davidoks.blog/p/why-the-atm-didnt-kill-bank-teller&quot;,&quot;publication_id&quot;:4554783,&quot;embedding_publication_id&quot;:null,&quot;publication_name&quot;:&quot;David Oks&quot;,&quot;publication_logo_url&quot;:null,&quot;title&quot;:&quot;Why ATMs didn&#8217;t kill bank teller jobs, but the iPhone did&quot;,&quot;truncated_body_text&quot;:&quot;A few months ago, J. D. Vance, sitting vice president of the United States, gave an interview to Ross Douthat of the New York Times. During that interview, Vance and Douthat had an interesting exchange:&quot;,&quot;date&quot;:&quot;2026-03-10T22:29:42.275Z&quot;,&quot;like_count&quot;:1116,&quot;comment_count&quot;:86,&quot;bylines&quot;:[{&quot;id&quot;:2088240,&quot;name&quot;:&quot;David Oks&quot;,&quot;handle&quot;:&quot;doks&quot;,&quot;previous_name&quot;:&quot;Stylite&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/553a38f8-f363-424f-8648-742af2eacc8d_1024x1024.png&quot;,&quot;bio&quot;:&quot;Essays on economics, technology, history&quot;,&quot;profile_set_up_at&quot;:&quot;2021-04-25T15:01:09.752Z&quot;,&quot;reader_installed_at&quot;:&quot;2023-06-18T14:21:19.283Z&quot;,&quot;publicationUsers&quot;:[{&quot;id&quot;:4646174,&quot;user_id&quot;:2088240,&quot;publication_id&quot;:4554783,&quot;role&quot;:&quot;admin&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:true,&quot;publication&quot;:{&quot;id&quot;:4554783,&quot;name&quot;:&quot;David Oks&quot;,&quot;subdomain&quot;:&quot;davidoks&quot;,&quot;custom_domain&quot;:&quot;davidoks.blog&quot;,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;The world is what it is.&quot;,&quot;logo_url&quot;:null,&quot;author_id&quot;:2088240,&quot;primary_user_id&quot;:2088240,&quot;theme_var_background_pop&quot;:&quot;#FF6719&quot;,&quot;created_at&quot;:&quot;2025-03-30T23:49:08.700Z&quot;,&quot;email_from_name&quot;:&quot;David Oks&quot;,&quot;copyright&quot;:&quot;doks&quot;,&quot;founding_plan_name&quot;:&quot;Founding Member&quot;,&quot;community_enabled&quot;:true,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;enabled&quot;,&quot;language&quot;:null,&quot;explicit&quot;:false,&quot;homepage_type&quot;:&quot;newspaper&quot;,&quot;is_personal_mode&quot;:false,&quot;logo_url_wide&quot;:null}}],&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null,&quot;status&quot;:{&quot;bestsellerTier&quot;:null,&quot;subscriberTier&quot;:1,&quot;leaderboard&quot;:null,&quot;vip&quot;:false,&quot;badge&quot;:{&quot;type&quot;:&quot;subscriber&quot;,&quot;tier&quot;:1,&quot;accent_colors&quot;:null},&quot;paidPublicationIds&quot;:[1071360,159185,1063960,1198116],&quot;subscriber&quot;:null}}],&quot;utm_campaign&quot;:null,&quot;belowTheFold&quot;:false,&quot;type&quot;:&quot;newsletter&quot;,&quot;language&quot;:&quot;en&quot;,&quot;source&quot;:null}" data-component-name="EmbeddedPostToDOM"><a class="embedded-post" native="true" href="https://davidoks.blog/p/why-the-atm-didnt-kill-bank-teller?utm_source=substack&amp;utm_campaign=post_embed&amp;utm_medium=web"><div class="embedded-post-header"><span></span><span class="embedded-post-publication-name">David Oks</span></div><div class="embedded-post-title-wrapper"><div class="embedded-post-title">Why ATMs didn&#8217;t kill bank teller jobs, but the iPhone did</div></div><div class="embedded-post-body">A few months ago, J. D. Vance, sitting vice president of the United States, gave an interview to Ross Douthat of the New York Times. During that interview, Vance and Douthat had an interesting exchange&#8230;</div><div class="embedded-post-cta-wrapper"><span class="embedded-post-cta">Read more</span></div><div class="embedded-post-meta">5 months ago &#183; 1116 likes &#183; 86 comments &#183; David Oks</div></a></div><p>And when you combine the smartphone with an ebanking platform and the ATM, you get the perfect fraud workflow.</p><div><hr></div><h4>Proxy takedown</h4><p>Law enforcement from eight countries seized 23 servers and 34 domains, froze $3.5M in crypto, and identified more than 124,000 users. Known as &#8220;SocksEscort&#8221;, the network, powered by the AVRecon botnet, has co-opted more than 369,000 IPs since 2020.  </p><p>This service essentially took control of unsecured residential and business routers and sold access to them. This enabled an attacker to route their malicious Internet traffic through the router in a residential home or (small) business.  </p><p>Untrained investigators often assume that tracing an IP address back to an ISP subscriber indicates that a user physically on the property who connected to the Internet through the router was responsible for the activity. Poor assumption. You must consider the possibility of an infected router being used as a proxy.  </p><p><a href="https://www.justice.gov/usao-edca/pr/authorities-dismantle-global-malicious-proxy-service-deployed-malware-and-defrauded">https://www.justice.gov/usao-edca/pr/authorities-dismantle-global-malicious-proxy-service-deployed-malware-and-defrauded</a></p><p>And not by coincidence, I&#8217;m sure, the Internet Crime Complaint Center (IC3) published a document titled &#8220;Evading Residential Proxy Networks: Protecting Your Devices From Becoming a Tool for Criminals&#8221;.  <a href="https://www.ic3.gov/PSA/2026/PSA260312">https://www.ic3.gov/PSA/2026/PSA260312</a></p><div><hr></div><h4>More News&#8230;</h4><p>This executive order, signed by President Trump, outlines a U.S. government strategy to combat cybercrime, fraud, and predatory schemes targeting American citizens, particularly those orchestrated by transnational criminal organizations (TCOs), sometimes with foreign state support. It directs multiple federal agencies to review and strengthen defenses, establish a coordinated operational cell within the National Coordination Center, enhance victim support through a proposed Victims Restoration Program, and engage internationally to pressure nations that harbor these criminal groups. The order emphasizes law enforcement, diplomacy, and potential offensive actions to disrupt and dismantle these threats.  <a href="https://www.whitehouse.gov/presidential-actions/2026/03/combating-cybercrime-fraud-and-predatory-schemes-against-american-citizens/">https://www.whitehouse.gov/presidential-actions/2026/03/combating-cybercrime-fraud-and-predatory-schemes-against-american-citizens/</a></p><p>C&#8217;mon, where are the controls?  A Catholic bishop in the San Diego area resigned after being arrested and charged with embezzling $270,000 from St. Peter Chaldean Catholic Cathedral in El Cajon, California. He faces 16 felony charges, including money laundering, with prosecutors alleging he misappropriated monthly rental payments exceeding $30,000 from a church tenant. <a href="https://www.ncronline.org/news/pope-announces-resignation-us-bishop-accused-embezzling-270k-california-parish">https://www.ncronline.org/news/pope-announces-resignation-us-bishop-accused-embezzling-270k-california-parish</a></p><p>Not a good week for men of the cloth.  The head priest of Trinity Episcopal Cathedral in Pittsburgh was arrested on February 27 after being accused of stealing over $1,000 in baseball cards from a Walmart in Economy Borough. Police say he was caught leaving the store with 27 packs of baseball cards concealed on his person, and security footage allegedly showed him stealing from the same store on five separate occasions. The very reverend faces charges of receiving stolen property and retail theft.  <a href="https://abcnews.com/US/wireStory/head-priest-episcopal-church-pittsburgh-accused-stealing-baseball-130976273">https://abcnews.com/US/wireStory/head-priest-episcopal-church-pittsburgh-accused-stealing-baseball-130976273</a></p><p>Crypto traders - &#8220;Slippage&#8221; will kill you.  Or cost you 50 million dollars.  &#8220;<em>Slippage is the difference between the price a trader would expect to get in a trade and the price they receive once the transaction executes. This can happen in large orders or when liquidity is weak.&#8221;  </em><a href="https://www.theblock.co/post/393466/crypto-whale-loses-nearly-50-million-swapping-usdt-for-aave">https://www.theblock.co/post/393466/crypto-whale-loses-nearly-50-million-swapping-usdt-for-aave</a></p><p>  A ransomware negotiator working for an incident response firm has been accused by the Department of Justice of secretly collaborating with the ALPHV/BlackCat cybercrime group while helping victims negotiate ransoms. The man and two colleagues allegedly carried out at least 10 ransomware attacks and shared confidential negotiation details with criminals to increase ransom payments in exchange for a share of the proceeds, with ransoms reaching up to $26 million. <a href="https://therecord.media/ransomware-blackcat-doj-incident-responder">https://therecord.media/ransomware-blackcat-doj-incident-responder</a></p><div><hr></div><h4>Bonus</h4><p>Anthropic is doubling the usage limits for Claude during off-hours.  So do your heavy work at 2 am.  <a href="https://support.claude.com/en/articles/14063676-claude-march-2026-usage-promotion">https://support.claude.com/en/articles/14063676-claude-march-2026-usage-promotion</a></p><div><hr></div><h4>Cool Job</h4><p>Head of Digital Financial Crimes Compliance,  State Street.  <a href="https://statestreet.wd1.myworkdayjobs.com/Global/job/Boston-Massachusetts/Head-of-Digital-Financial-Crimes-Compliance--Managing-Director_R-781812">https://statestreet.wd1.myworkdayjobs.com/Global/job/Boston-Massachusetts/Head-of-Digital-Financial-Crimes-Compliance--Managing-Director_R-781812</a></p><p>Financial Crimes Investigations Specialist, DraftKings.  <a href="https://draftkings.wd1.myworkdayjobs.com/draftkings/job/Remote---US/Financial-Crimes-Investigations-Specialist_JR13845-3">https://draftkings.wd1.myworkdayjobs.com/draftkings/job/Remote---US/Financial-Crimes-Investigations-Specialist_JR13845-3</a></p><h4>Cool Tool</h4><p>Notes as easy as texting. <a href="https://prism.you/"> https://prism.you/</a></p><p>ABA Routing Number Look-up/Search.  <a href="https://routingnumber.aba.com/Search1.aspx">https://routingnumber.aba.com/Search1.aspx</a></p><div><hr></div><h4>DFIR</h4><p>The forensic value of Apple Spotlight artifacts.  <a href="https://forensafe.com/blogs/apple-spotlight.html">https://forensafe.com/blogs/apple-spotlight.html</a></p><div><hr></div><h4>Young people&#8230;</h4><p>Claude assessed itself and identified the jobs it will replace. Pivot and adapt as needed. Don&#8217;t be like the wagon wheel maker who kept making wagon wheels after seeing the automobile pass through town. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AwOR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b17363-731f-4ef4-9d3a-1794924e0af3_1268x1424.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AwOR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b17363-731f-4ef4-9d3a-1794924e0af3_1268x1424.jpeg 424w, https://substackcdn.com/image/fetch/$s_!AwOR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b17363-731f-4ef4-9d3a-1794924e0af3_1268x1424.jpeg 848w, https://substackcdn.com/image/fetch/$s_!AwOR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b17363-731f-4ef4-9d3a-1794924e0af3_1268x1424.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!AwOR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b17363-731f-4ef4-9d3a-1794924e0af3_1268x1424.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AwOR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b17363-731f-4ef4-9d3a-1794924e0af3_1268x1424.jpeg" width="1268" height="1424" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d7b17363-731f-4ef4-9d3a-1794924e0af3_1268x1424.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1424,&quot;width&quot;:1268,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:216396,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/191067327?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b17363-731f-4ef4-9d3a-1794924e0af3_1268x1424.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AwOR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b17363-731f-4ef4-9d3a-1794924e0af3_1268x1424.jpeg 424w, https://substackcdn.com/image/fetch/$s_!AwOR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b17363-731f-4ef4-9d3a-1794924e0af3_1268x1424.jpeg 848w, https://substackcdn.com/image/fetch/$s_!AwOR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b17363-731f-4ef4-9d3a-1794924e0af3_1268x1424.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!AwOR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b17363-731f-4ef4-9d3a-1794924e0af3_1268x1424.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.anthropic.com/research/labor-market-impacts"> https://www.anthropic.com/research/labor-market-impacts</a></p><div><hr></div><h4>Irrelevant</h4><p>Sending employees back into the office isn&#8217;t going well.  <a href="https://thehill.com/opinion/technology/5775420-remote-first-productivity-growth/">https://thehill.com/opinion/technology/5775420-remote-first-productivity-growth/</a></p><div><hr></div><h4>Sign Off</h4><p>My good will, positive vibes, and prayers will be offered to anyone traveling this week. What a mess. Get to the airport early and bring an extra dose of patience. I try to keep politics out of the newsletter, but damn, what do we even have these people for? If our elected officials can&#8217;t agree to ensure our essential security personnel, like TSA, get paychecks, then the system is graveyard dead. They all need to go, regardless of whether they have a D or R behind their name. </p><p>Thanks, </p><p>Matt</p><p>&#8220;TRY BEING INFORMED INSTEAD OF JUST OPINIONATED.&#8221;</p><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item></channel></rss>