<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Threats Without Borders]]></title><description><![CDATA[
Explore the Nexus of Cyber-Financial Crime Investigation, Cybersecurity, and Tactical Cyber Threat Intelligence — All Delivered in One Dynamic Newsletter!"
]]></description><link>https://www.threatswithoutborders.com</link><image><url>https://substackcdn.com/image/fetch/$s_!lkkz!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07f3f957-f680-4ee2-b274-e8ca2ac66a24_600x600.png</url><title>Threats Without Borders</title><link>https://www.threatswithoutborders.com</link></image><generator>Substack</generator><lastBuildDate>Tue, 16 Jun 2026 11:47:03 GMT</lastBuildDate><atom:link href="https://www.threatswithoutborders.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Matt Dotts]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[cyficrime@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[cyficrime@substack.com]]></itunes:email><itunes:name><![CDATA[Matt Dotts]]></itunes:name></itunes:owner><itunes:author><![CDATA[Matt Dotts]]></itunes:author><googleplay:owner><![CDATA[cyficrime@substack.com]]></googleplay:owner><googleplay:email><![CDATA[cyficrime@substack.com]]></googleplay:email><googleplay:author><![CDATA[Matt Dotts]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Threats Without Borders - Issue 291]]></title><description><![CDATA[Cybercrime Investigation Newsletter, week ending June 14, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-291</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-291</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 16 Jun 2026 09:40:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lkkz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07f3f957-f680-4ee2-b274-e8ca2ac66a24_600x600.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>There&#8217;s a question that circulates endlessly through every fraud conference, LinkedIn threads, and panel discussions. <strong>What&#8217;s the biggest fraud threat facing organizations right now?</strong> You already know the answer, because it&#8217;s always the same answer, delivered with the same misplaced confidence, almost like a reflex. AI. Of course, it&#8217;s AI.</p><p>Nobody ever mentions the telephone. Which is how my organization and it&#8217;s customers get attacked multiple times every day. Yeah, the phone. Scammers are calling the business, pretending to be customers, and calling our customers to pretend to be the business. Classic social engineering, zero sophistication required, and highly effective. </p><p>And I pay attention enough to know that&#8217;s the correct answer for a lot of organizations, too. But the telephone doesn&#8217;t trend, so here we are.</p><p>Fine. Let&#8217;s say the answer is AI.  The problem isn&#8217;t the answer, and it&#8217;s probably more correct than not. It&#8217;s what happens immediately afterward when someone asks the inevitable follow-up: Can you give me an example? Panic. What you usually get is something vague about phishing emails and voice cloning. Sure, but that&#8217;s not an answer so much as a category, and categories don&#8217;t hold up when someone actually pushes back.</p><p>Google recently filed a lawsuit against a Chinese cybercrime network operating under the name Outsider Enterprise, alleging the group used Google&#8217;s own Gemini AI to automate a phishing campaign at genuinely impressive scale. The network operated primarily through Telegram, offered phishing-as-a-service to other criminals, and provided nearly 300 ready-to-deploy templates along with instructions on how to use Gemini to generate convincing fake websites impersonating Google, YouTube, and the New York E-ZPass system, among others. Google identified roughly 9,000 fraudulent sites and over a million malicious URLs tied to the campaign. The group sent more than 2.5 million scam text messages to Android users.</p><p>And the FBI and its partners, including Google, just took the operation offline.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Srcv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e891032-8942-4f1a-ae66-a4b011850eff_984x1264.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Srcv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e891032-8942-4f1a-ae66-a4b011850eff_984x1264.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Srcv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e891032-8942-4f1a-ae66-a4b011850eff_984x1264.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Srcv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e891032-8942-4f1a-ae66-a4b011850eff_984x1264.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Srcv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e891032-8942-4f1a-ae66-a4b011850eff_984x1264.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Srcv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e891032-8942-4f1a-ae66-a4b011850eff_984x1264.jpeg" width="984" height="1264" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8e891032-8942-4f1a-ae66-a4b011850eff_984x1264.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1264,&quot;width&quot;:984,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:385108,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/202052480?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e891032-8942-4f1a-ae66-a4b011850eff_984x1264.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Srcv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e891032-8942-4f1a-ae66-a4b011850eff_984x1264.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Srcv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e891032-8942-4f1a-ae66-a4b011850eff_984x1264.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Srcv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e891032-8942-4f1a-ae66-a4b011850eff_984x1264.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Srcv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e891032-8942-4f1a-ae66-a4b011850eff_984x1264.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The lawsuit itself is worth a moment&#8217;s attention. Google isn&#8217;t the first to take this approach, as Microsoft, Cloudflare, and others have pursued civil litigation against cybercrime actors who abused their platforms. It&#8217;s an interesting strategy, and the practical ceiling is obvious. Bringing meaningful legal consequences against a criminal operating out of China, North Korea, or Russia is less a law-enforcement action and more a very expensive message. Whether anyone receives it is another question entirely.</p><p>So, the next time someone asks us to name the biggest fraud threat and expects us to perform the AI genuflection, we can do better than a generic response. Say Outsider Enterprise. Explain what they built, how they used it, and what it produced. Answer like someone who actually follows this space, not like someone who learned the buzzword and stopped there.</p><p>Read the complaint here:  <a href="https://fingfx.thomsonreuters.com/gfx/legaldocs/byvrdoelzve/GOOGLE%20SCAMMER%20LAWSUIT%20outsidercomplaint.pdf">https://fingfx.thomsonreuters.com/gfx/legaldocs/byvrdoelzve/GOOGLE%20SCAMMER%20LAWSUIT%20outsidercomplaint.pdf</a></p><p>It&#8217;s really well written and worth your time to read.  Among other nuggets, on page 20, they explain the process for bypassing MFA.</p><div><hr></div><h4>Ok&#8230; let&#8217;s go!</h4><blockquote><p><em>At least 13 federal agencies work on countering scams and each one largely works independent of the others. Eight of these agencies receive complaints about scams, which can lead to confusion and frustration for Americans who want to report a scam. For example, an American who has been targeted by a tax-related scam could potentially report the scam to the FBI&#8217;s internet crimes website, the Federal Trade Commission&#8217;s fraud reporting website, the IRS&#8217;s tax fraud and scams reporting website, or by contacting the Treasury Inspector General for Tax Administration. The federal government needs a comprehensive, unified plan to deal with scams, and the American people deserve a clear, easy way to report scams and get connected with help.</em></p></blockquote><p>U.S. Senators Hassan from Florida and Scott from Florida introduced the &#8220;reportscams.gov Act&#8221; which aims to consolidate the fraud-fighting efforts of the federal government.  <a href="https://www.hassan.senate.gov/imo/media/doc/reportscamsgovonepager.pdf">https://www.hassan.senate.gov/imo/media/doc/reportscamsgovonepager.pdf</a></p><div><hr></div><h4>The News</h4><p>This question is being asked more often and with greater urgency&#8212;are anti-money laundering (AML) efforts justifiable given their costs? AML frameworks face increased criticism for high compliance costs, generating unused data, raising privacy concerns, and lacking clear evidence of effectiveness in preventing illicit transactions. Recent studies indicate that high compliance rates do not always correlate with reduced illegal activity. In this article, the authors examine the future of AML efforts.  <a href="https://www.theregreview.org/2026/06/13/seminar-are-anti-money-laundering-regulations-effective-and-worth-the-cost/">https://www.theregreview.org/2026/06/13/seminar-are-anti-money-laundering-regulations-effective-and-worth-the-cost/</a></p><p>Is this the end of &#8220;burner phones&#8221;? The FCC has proposed new rules intended to combat robocalls by requiring phone carriers to collect extensive personal data, including government ID, physical addresses, and alternative phone numbers, before activating service.  <a href="https://docs.fcc.gov/public/attachments/DOC-421309A1.pdf">https://docs.fcc.gov/public/attachments/DOC-421309A1.pdf</a></p><p>The FBI has initiated &#8220;Operation Riptide,&#8221; a nationwide effort to break down cybercrime networks by targeting the criminals, their infrastructure, and financial systems, especially following over $20 billion in losses from more than 1 million cybercrime complaints last year.  <a href="https://www.fbi.gov/video-repository/operation-riptide-060926.mp4/view">https://www.fbi.gov/video-repository/operation-riptide-060926.mp4/view</a></p><p>An international law enforcement operation dismantled a popular money-laundering service known as &#8216;AudiA6&#8217;, believed to have laundered over EUR 336 million from 2022 to 2025. The service, associated with the &#8216;Dark2Web&#8217; forum, was investigated by US and Polish authorities in collaboration with international partners.  <a href="https://www.europol.europa.eu/media-press/newsroom/news/ransomware-gangs-cut-eur-336-million-audia6-crypto-laundering-pipeline">https://www.europol.europa.eu/media-press/newsroom/news/ransomware-gangs-cut-eur-336-million-audia6-crypto-laundering-pipeline</a></p><p>The Bank Policy Institute urged federal regulators to clarify oversight of stablecoin transactions after issuance. Current AML rules fail to adequately impose compliance obligations on DeFi firms, certain crypto custodians, and exchanges.  <a href="https://www.pymnts.com/cpi-posts/banking-groups-pitch-anti-money-laundering-rules-for-stablecoins/">https://www.pymnts.com/cpi-posts/banking-groups-pitch-anti-money-laundering-rules-for-stablecoins/</a></p><p>The U.S. government tells Anthropic to hit the brakes on their latest release.  <a href="https://www.anthropic.com/news/fable-mythos-access">https://www.anthropic.com/news/fable-mythos-access</a></p><div><hr></div><h4>Feedback</h4><p>Send Feedback to matt(at)threatswithoutborders.com</p><div><hr></div><h4>A vote that actually matters</h4><p>A long time ago, I watched a guy turn a hotel room key card into a working Visa card. Before you shrug, this was well before card fraud became a punchline in every breach notification email and the fear of every ATM user. To a young detective freshly assigned to financial crimes, seeing this done was like watching magic.</p><p>That guy was Steve Lenderman. And now he&#8217;s running for President of the International Association of Financial Crime Investigators. Not the Delaware Valley Chapter, which he&#8217;s led for the past seven years. The whole organization.</p><p>Regular Tw/oB readers know my opinion on the IAFCI as an organization has been, well, complicated. That&#8217;s a diplomatic way of saying the past few years of leadership have been disappointing. </p><p>Which is exactly why this endorsement isn&#8217;t a formality. It&#8217;s a correction.</p><p>You&#8217;d be hard-pressed to find anyone more committed to fraud and financial crime prevention than Steve. He&#8217;s held leadership roles simultaneously in the IAFCI Delaware Valley Chapter, the Delaware chapter of ACFE, and the Delaware Fraud Working Group. That&#8217;s not resume padding, that&#8217;s someone who actually shows up.</p><p>I served as a Vice President under Steve for four of his seven years leading the Del-Val chapter. I can tell you firsthand that he is the embodiment of getting shit done. Not performative leadership. Not committee theater. Actual results.</p><p>IAFCI members receive ballots this week, including Steve&#8217;s full credentials. I&#8217;m not going to rehash them here.</p><p>What I will say is this: if five years of <em>Threats Without Borders</em> has earned me any credibility with you (there must be some reason you&#8217;re still reading), then take this for what it&#8217;s worth. The IAFCI needs forward-thinking and action-oriented leadership. <strong>I&#8217;m voting for Steve Lenderman</strong>. I hope you will, too.</p><div><hr></div><h4>dfir</h4><p>The team at Unit 42 highlights a new macOS artifact, App.MenuItem, that logs user menu selections, providing granular data on user intent and actions across the operating system. <a href="https://unit42.paloaltonetworks.com/new-macos-artifact-discovered/">https://unit42.paloaltonetworks.com/new-macos-artifact-discovered/</a></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>Cool Jobs</h4><p>Fraud Countermeasures Specialist - Veriff.  <a href="https://www.veriff.com/careers/position/8590317002">https://www.veriff.com/careers/position/8590317002</a></p><h4>Cool Tools</h4><p>Remove the background from an image.  <a href="https://www.remove.bg/">https://www.remove.bg/</a></p><p>How loud is your workspace?  In-browser decibel meter.  <a href="https://noisedecibelmeter.com/">https://noisedecibelmeter.com/</a></p><div><hr></div><h4>Irrelevant</h4><p>Paul Graham explains how to become a billionaire (and why all these eat-the-rich politicians are so wrong).  <a href="https://paulgraham.com/earn.html">https://paulgraham.com/earn.html</a></p><div><hr></div><h4>Sign Off</h4><p>I don&#8217;t understand <s>football</s> soccer.  One of the happiest days of my early parenting was when my youngest son said he was done with it. Needless to say, I could not care less about the World Cup tournament.  But I am completely enthralled with the abject glee of the foreign soccer fans currently visiting America to see the games. Everything from the beauty of our natural resources to the kindness of our people to the sheer excess of our eateries has created must-see social media content.  A group of Norwegians tasting a brisket sandwich at Buc-ee's, or the Germans experiencing a Waffle House at 1 am, is absolutely heart-warming!</p><p>Matt</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 290]]></title><description><![CDATA[Cybersecurity Investigation Newsletter, week ending June 7, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-290</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-290</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 09 Jun 2026 11:46:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I want to give full credit to Jay Dubina for sparking my thoughts on this topic. He&#8217;s the first person I&#8217;ve heard delve into the idea of agentic AI commerce fraud to this extent. I&#8217;ve been aware of the concept, but I heard Jay discuss it last week, and he really brought it to life for me. </p><p>We know how to investigate cyber-fraud:  Follow the money. Find the device. Put the bad guy behind the keyboard.</p><p>What happens when there&#8217;s no keyboard?</p><p>Agentic AI is here, and it&#8217;s changing how commerce works at a fundamental level. These aren&#8217;t chatbots answering questions, they&#8217;re autonomous systems with tools, stored credentials, and decision-making authority. You give them a goal and they execute it.</p><p>And so we&#8217;re all on the same page, an agent is &#8220;<em>an autonomous software system powered by AI that can perceive its environment, make decisions, and execute multi-step tasks to achieve a specific goal without constant human intervention.</em>&#8221;  </p><p>Consider this. You tell your AI agent, &#8220;Buy me a battery-powered lawn mower. Budget is $500. Prioritize reviews, price, and shipping time. Deliver to my home address.&#8221; The agent searches, evaluates, selects, and purchases, all without you touching a browser. Two days later, a mower shows up at your door. You spent thirty seconds on a task that used to take hours.</p><p>It&#8217;s brilliantly useful. It&#8217;s also a fraud investigator&#8217;s nightmare.</p><p>Now run that same scenario with a stolen identity, a compromised credit card, and a drop address. The bad guy doesn&#8217;t search for anything. Doesn&#8217;t visit any merchant site. Doesn&#8217;t enter a single piece of payment data manually. He gives the agent an instruction and walks away. The agent does the rest, across ten stolen identities, simultaneously, without getting tired.</p><p>What does the merchant see? An API call, a billing address that matches the stolen card, a gift shipping address. The transaction looks clean in isolation. The velocity looks odd across accounts, but individually? Nothing flags.</p><p>But eventually the cardholder recognizes the fraud and files a report.  So you open an investigation.</p><p>The communication chain runs like this: actor &gt; agent &gt; merchant API &gt; payment processor &gt; fulfillment. Every hop is a potential evidence gap. The merchant has a transaction record. The payment processor has an authorization. The shipping carrier has a delivery scan. And what nobody has is an idea of what the agent platform logs, what they retain, and what legal framework applies when you ask for it.</p><p>Is an AI agent platform an Internet service provider? A bank? A phone carrier? A search engine? The search warrant process hasn&#8217;t caught up to the question. And some platforms are built privacy-forward by design, which means the logs you need may not exist at all.</p><p>Even if you get the logs, you have a new attribution problem. You can prove the agent made the purchase. But can you prove that the human gave the instruction? The session that initiated the task might be behind a residential proxy. Might be a stolen session token. Might be another automated layer entirely.</p><p>The bad guys&#8217; defense writes itself: &#8220;I didn&#8217;t choose those items. I didn&#8217;t enter that payment data. Maybe the system did that, but it wasn&#8217;t me.&#8221;</p><p>Technically? They&#8217;re not wrong.</p><p>The investigative frameworks we have were built around one assumption: a human made each decision in a transaction. Agentic AI destroys that assumption completely.  Yes, a human may have &#8220;set it off,&#8221; but what exactly is &#8220;it&#8221;?  How much control did the human actually have once the agent took the wheel?</p><p>It&#8217;s probably good we start talking about this because the future is here.</p><div><hr></div><h4>The News</h4><p>Maybe (probably not) I&#8217;ll have to start suggesting older adults look at Android again&#8230;Google&#8217;s June Android update introduces improved scam detection features aimed at fighting AI-driven impersonation and deepfake voice scams. This new system, available on Android 12 and above, requires users to install Google&#8217;s Phone, Contacts, and Messages apps to verify incoming calls from contacts. If a call appears to be spoofed via an online relay, the user will receive an alert. <a href="https://arstechnica.com/gadgets/2026/06/google-announces-deepfake-call-detection-for-android-new-airdrop-device-support/">https://arstechnica.com/gadgets/2026/06/google-announces-deepfake-call-detection-for-android-new-airdrop-device-support/</a></p><p>You&#8217;ll be hard-pressed to name a group that provides a better threat intelligence write-up than the team at Flare. In this article, they profile a new stealer malware: &#8220;<em>For $40 and a tutorial video, anyone can deploy a fully functional information stealer with credential harvesting, screen capture, Wi-Fi password extraction, file collection, persistence installation, and remote access, all controlled through a Telegram bot. KeyCat is a Python-based, multi-platform infostealer and remote access toolkit targeting both Windows and Linux environments.&#8221; </em><a href="https://flare.io/learn/resources/blog/keycat-stealer-multi-platform-infostealer">https://flare.io/learn/resources/blog/keycat-stealer-multi-platform-infostealer</a></p><p>Yes, passkeys are better security.  Yes, most people reject using them.  Microsoft is forcing the issue and will no longer provide codes through SMS.  <a href="https://support.microsoft.com/en-us/accounts-billing/manage/microsoft-to-stop-sending-sms-codes-for-personal-accounts">https://support.microsoft.com/en-us/accounts-billing/manage/microsoft-to-stop-sending-sms-codes-for-personal-accounts</a></p><p>Here's an interesting statistic for your next dinner party: between 10% and 20% of all domains registered in 2025 were created by cybercriminals. Even on the lower end, that means there are approximately 8.5 million malicious domains available for criminal activity.  Great reporting by Interisle.  <a href="https://static1.squarespace.com/static/63dbf2b9075aa2535887e365/t/6a20724a659b821142b48388/1780511306582/FullReport_MaliciousRegistrationsintheDomainNameMarket_2026_rev.pdf">https://static1.squarespace.com/static/63dbf2b9075aa2535887e365/t/6a20724a659b821142b48388/1780511306582/FullReport_MaliciousRegistrationsintheDomainNameMarket_2026_rev.pdf</a></p><p>Proving there is no floor to the prospect of insider threats, this Pennsylvania government employee threw away her job and reputation over $6,000.  <a href="https://www.wtaj.com/crime/former-rush-township-employee-facing-forgery-charge-after-stealing-6k/">https://www.wtaj.com/crime/former-rush-township-employee-facing-forgery-charge-after-stealing-6k/</a></p><p>A North Carolina man was sentenced to 121 months in prison for selling lists of elderly Americans&#8217; personal information to Jamaican lottery fraud scammers. His lists were so good that his pseudonym, &#8220;Steve Dixon,&#8221; became synonymous with the scam, to the point that it was dropped in rap music. It is alleged he earned over $5.2 million from the scheme, which victimized over seven million elderly Americans and resulted in losses exceeding $9.5 million.  <a href="https://www.justice.gov/opa/pr/fraudster-who-sold-personal-information-over-7-million-elderly-americans-jamaican-scammers">https://www.justice.gov/opa/pr/fraudster-who-sold-personal-information-over-7-million-elderly-americans-jamaican-scammers</a></p><p>Troy Hunt believes the data breach disclosure lag is worse than ever.  And he&#8217;s the authority on the issue.  <a href="https://www.troyhunt.com/1000-data-breaches-later-the-disclosure-lag-is-worse-than-ever/">https://www.troyhunt.com/1000-data-breaches-later-the-disclosure-lag-is-worse-than-ever/</a></p><p>FinCEN has issued a warning to banks to look out for &#8220;red flags&#8221; suggesting payroll schemes involving individuals living illegally in the country. This marks an important step in the Trump administration&#8217;s immigration enforcement. After President Trump signed an executive order in May, which instructs regulators to check the citizenship status of bank customers without making it mandatory to collect such data, the advisory highlights more than twelve signs of identity theft, payroll tax fraud, and money laundering associated with unauthorized workers. <a href="https://www.fincen.gov/system/files/2026-06/FinCEN-Advisory-Non-Work-Authorized-Populations.pdf">https://www.fincen.gov/system/files/2026-06/FinCEN-Advisory-Non-Work-Authorized-Populations.pdf</a></p><p>The FBI released an unserious "Most Wanted Fraudster&#8221; list. While the individuals included are certainly deserving, not a single politician made the list. Which politician? Any of them, I suppose.  <a href="https://www.fbi.gov/wanted/most-wanted-fraudsters">https://www.fbi.gov/wanted/most-wanted-fraudsters</a></p><div><hr></div><h4>Feedback</h4><p><em>Hey Matt, saw in Issue 286 where you asked the rhetorical question &#8220;how do you leverage your existing network to find a new job without broadcasting to your current employer that you&#8217;re looking to leave. Any additional insights on that? - </em>Keith </p><p>For context, that question was part of a larger conversation, and I wasn&#8217;t asking for myself (in case my current employer might be reading this). But, no, Keith, I don&#8217;t have any additional ideas. It&#8217;s a valid question&#8212;what&#8217;s the point of having a big social media network if you can&#8217;t leverage it? Except when you're already unemployed. Let&#8217;s try an experiment: someone who is employed should activate their &#8220;open to work&#8221; banner and report back the results.</p><p>Send Feedback to matt(at)threatswithoutborders.com</p><div><hr></div><h4>dfir</h4><p>Andrea Fortune examines a study tracking hired crime and intelligence analysts at a UK law enforcement agency over three interview periods: at six, twelve, and eighteen months. A total of sixty-three interviews were conducted. These analysts handled cases involving sexual assault, homicide, and serious crimes, frequently reviewing investigative reports, interview transcripts, recordings, and crime scene or autopsy images. The findings indicate that their mental health declined as expected. <a href="https://andreafortuna.org/2026/06/05/dfir-analyst-psychological-impact/">https://andreafortuna.org/2026/06/05/dfir-analyst-psychological-impact/</a></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>Cool Jobs</h4><p>Director of Fraud Risk Oversight, Fidelity.  <a href="https://jobs.fidelity.com/en/jobs/2125543/director-fraud-risk-oversight/">https://jobs.fidelity.com/en/jobs/2125543/director-fraud-risk-oversight/</a></p><p>Technology Services Specialist, Hershey Entertainment and Resorts.  <a href="https://hersheypa.rec.pro.ukg.net/HER1020HERS/JobBoard/035cdc57-c54b-48c9-8c4d-f30e022675e5/OpportunityDetail?opportunityId=9a55dff5-4337-4489-93af-e8ff0a4f93b3">https://hersheypa.rec.pro.ukg.net/HER1020HERS/JobBoard/035cdc57-c54b-48c9-8c4d-f30e022675e5/OpportunityDetail?opportunityId=9a55dff5-4337-4489-93af-e8ff0a4f93b3</a></p><h4>Cool Tools</h4><p>Supported in-flight Wi-Fi portals expose a flight manifest. CabinLink uses it to show your location, altitude, speed, and how long until you land. It keeps working when the cabin signal does not. (I have not personally used this app, but it looks cool.) <a href="https://www.vishrutjha.com/cabinlink">https://www.vishrutjha.com/cabinlink</a></p><p>Long for the days of Windows 95?  Want to get nostalgic about MacOS Puma?  This emulator has over 1700 operating systems pre-loaded and ready to run.  <a href="https://virtualosmuseum.org/">https://virtualosmuseum.org/</a></p><div><hr></div><h4>Irrelevant</h4><p>Statistics show many parolees are sent back to prison for &#8220;technical parole violations,&#8221; not committing new crimes.  But a closer examination reveals they are committing new crimes, yet are sent back to prison for the TPV and never charged for the new offenses.  Why?  The authors of the study conclude: </p><blockquote><p><em>The candid answer: it&#8217;s faster, easier, and more likely to pay off for prosecutors to send someone back to prison through a parole-violation hearing rather than through the courts. The parole hearing is held before representatives of the parole board, without any need to seat a jury, and the standard of proof is lower (&#8220;preponderance of the evidence,&#8221; not &#8220;beyond a reasonable doubt&#8221;).</em></p></blockquote><div class="embedded-post-wrap" data-attrs="{&quot;id&quot;:199456820,&quot;url&quot;:&quot;https://cityjournal.substack.com/p/the-hidden-crimes-of-parolees&quot;,&quot;publication_id&quot;:6236832,&quot;publication_name&quot;:&quot;City Journal Substack&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!rO7N!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0aec2978-c0e6-4514-a875-f9c0535aa7b8_256x256.png&quot;,&quot;title&quot;:&quot;The Hidden Crimes of Parolees&quot;,&quot;truncated_body_text&quot;:&quot;By Barry Latzer and Kristofer Bret Bucklen&quot;,&quot;date&quot;:&quot;2026-05-27T14:31:07.509Z&quot;,&quot;like_count&quot;:12,&quot;comment_count&quot;:1,&quot;bylines&quot;:[],&quot;utm_campaign&quot;:null,&quot;belowTheFold&quot;:true,&quot;type&quot;:&quot;newsletter&quot;,&quot;language&quot;:&quot;en&quot;,&quot;source&quot;:null}" data-component-name="EmbeddedPostToDOM"><a class="embedded-post" native="true" href="https://cityjournal.substack.com/p/the-hidden-crimes-of-parolees?utm_source=substack&amp;utm_campaign=post_embed&amp;utm_medium=web"><div class="embedded-post-header"><img class="embedded-post-publication-logo" src="https://substackcdn.com/image/fetch/$s_!rO7N!,w_56,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0aec2978-c0e6-4514-a875-f9c0535aa7b8_256x256.png" loading="lazy"><span class="embedded-post-publication-name">City Journal Substack</span></div><div class="embedded-post-title-wrapper"><div class="embedded-post-title">The Hidden Crimes of Parolees</div></div><div class="embedded-post-body">By Barry Latzer and Kristofer Bret Bucklen&#8230;</div><div class="embedded-post-cta-wrapper"><span class="embedded-post-cta">Read more</span></div><div class="embedded-post-meta">20 days ago &#183; 12 likes &#183; 1 comment</div></a></div><div><hr></div><h4>Sign Off</h4><p>I received a lot of feedback over the last few weeks, especially about the editorial and the term &#8220;touch grass.&#8221; I can&#8217;t take credit for that, but I do subscribe to it. I spent my past Saturday outside, pretty much doing nothing but sitting in a chair, looking at trees, grass, and animals, and feeling the sun. I&#8217;m still a nutcase, but for that day, at least, it was a small dose of peace. And it felt good.     </p><p>And I hope you all find some of it during your week.</p><p>Matt</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SocL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dac6b91-0ecf-4643-a45c-7b8c3b7e0bd8_1378x1380.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SocL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dac6b91-0ecf-4643-a45c-7b8c3b7e0bd8_1378x1380.jpeg 424w, https://substackcdn.com/image/fetch/$s_!SocL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dac6b91-0ecf-4643-a45c-7b8c3b7e0bd8_1378x1380.jpeg 848w, https://substackcdn.com/image/fetch/$s_!SocL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dac6b91-0ecf-4643-a45c-7b8c3b7e0bd8_1378x1380.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!SocL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dac6b91-0ecf-4643-a45c-7b8c3b7e0bd8_1378x1380.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SocL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dac6b91-0ecf-4643-a45c-7b8c3b7e0bd8_1378x1380.jpeg" width="1378" height="1380" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7dac6b91-0ecf-4643-a45c-7b8c3b7e0bd8_1378x1380.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1380,&quot;width&quot;:1378,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:269207,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/201080905?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dac6b91-0ecf-4643-a45c-7b8c3b7e0bd8_1378x1380.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SocL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dac6b91-0ecf-4643-a45c-7b8c3b7e0bd8_1378x1380.jpeg 424w, https://substackcdn.com/image/fetch/$s_!SocL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dac6b91-0ecf-4643-a45c-7b8c3b7e0bd8_1378x1380.jpeg 848w, https://substackcdn.com/image/fetch/$s_!SocL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dac6b91-0ecf-4643-a45c-7b8c3b7e0bd8_1378x1380.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!SocL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dac6b91-0ecf-4643-a45c-7b8c3b7e0bd8_1378x1380.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 289]]></title><description><![CDATA[Cybercrime Investigation Newsletter, week ending May 31, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-289</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-289</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 02 Jun 2026 10:02:57 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Although paper documents used for the promise of financial payment date back to the Romans, the invention of the pre-printed consumer check with serial numbers is credited to an English banker in 1762. Fraudulent checks probably started appearing three days later. </p><p>And here we are, 264 years in the future, still fighting check fraud, and it might even be a worse problem than it ever has been.</p><p>At least three of the talks I heard at the BSides Harrisburg cybersecurity conference last week prominently discussed mental health and the need for self-care.  It&#8217;s not being selfish or being fragile.  It&#8217;s necessary to keep you fit for the job, which ultimately makes you more effective.</p><p>The cybersecurity field is getting really good at talking about this.  And demanding management recognizes it and provides resources for it.  Coming together as a community and saying, &#8220; Hey, we&#8217;re going to make mental health wellness part of our group identity.</p><p>Fraud - not so much.  In fact, I feel like it&#8217;s gotten worse. A recurring mantra shared at conferences and shouted across social media of &#8220;mount up fraud fighters and get locked-the-fuck-in because THIS is the year we take it to the fraudsters!&#8221;</p><p>So everyone gets hyped, puts on their armor, works 58 hours a week for months, only to get absolutely steamrolled by the bad guys.  And you all end up right back at disappointment and burnout.  </p><p>Because the lack of diligence, knowledge, and hard work is not the problem.  It&#8217;s a resource problem and a human psychology problem.</p><p>Remember the old fraud triangle?  Three elements come together to create a situation of fraud: Opportunity, Rationalization, and Pressure.  Well, there are a hell of lot of people out there with the pressure to get money, our societal decay and low moral standards make it easy to rationalize criminality, and the Internet - oh, the great facilitator - is giving more and more people the opportunity every day.</p><p>I spent twelve of my twenty-four-year law enforcement career in the criminal investigation room with a case docket. And guess what, I never got to Casleoad 0.  Regardless of how much overtime I worked, or how many birthdays and kids&#8217; sporting events I missed to &#8220;get caught up&#8221;.  And for what?  So I could determine that some ass-hole in Romania stole some files from a company in Pennsylvania.  Well, the company didn&#8217;t get their files back, the suspect is still in Romania, and I missed making memories with my kids.  Duplicate this story dozens and dozens of times.  Ask my wife, she spent a lot of time as a single mother. </p><p>The reality is that macro-level fraud is essentially unsolvable, so stop thinking you&#8217;re going to be the one to do it.</p><p>We are never going to work hard enough to expel all the adversaries.  Like weeds in the garden, no matter how many we pull, there will be more next week.</p><p>Listen up, and don&#8217;t hear what I&#8217;m not saying. Yes, we should be working hard, continuously training, and accepting every effort to learn.  Absolutely, go to fraud conferences to get recharged and socialized.  Post your catchy slogans to LinkedIn.  Get yourself locked in and down for the effort.  </p><p>But remember, we&#8217;re not going to solve this problem.  You&#8217;re going to have three more cases Monday morning, whether you work Saturday or not.</p><p>Prioritize your well-being by taking a mental health day, visiting the park with your kids, enjoying a nice dinner with your spouse, or spending a few days digging your toes in the sand. </p><p>Take a break. Or as the kids like to say, touch earth.</p><p>The fraud will be there when you return.</p><div><hr></div><h4>The News</h4><p>This article is not interesting because of the subject itself but because of how the author analyzed the probable cause affidavit written by the charging investigator. Sometimes, we overlook this aspect in the name of &#8220;probable cause," but we often provide suspects with details that improve their chances of not getting caught. This results in us only catching the&#8221; low-hanging fruit&#8221; and inadvertently empowering the more dangerous individuals.  <a href="https://arstechnica.com/tech-policy/2026/05/fbi-easily-nabs-man-selling-sexy-deepfakes-who-used-his-own-photo-in-profile/">https://arstechnica.com/tech-policy/2026/05/fbi-easily-nabs-man-selling-sexy-deepfakes-who-used-his-own-photo-in-profile/</a></p><p>US law enforcement and intelligence agencies are increasingly labeling dissent against artificial intelligence and data centers as &#8220;anti-tech extremism,&#8221;. Yeah, well, I don&#8217;t want a 24/7 data center in my backyard and I&#8217;m certainly not an anti-tech extremist.  <a href="https://www.wired.com/story/us-law-enforcement-warns-of-anti-tech-extremism/">https://www.wired.com/story/us-law-enforcement-warns-of-anti-tech-extremism/</a></p><p>A Google employee has been charged with fraud for allegedly using insider information to profit $1.2 million from bets on Polymarket.  <a href="https://www.cnbc.com/2026/05/27/google-employee-polymarket-insider-trading.html">https://www.cnbc.com/2026/05/27/google-employee-polymarket-insider-trading.html</a></p><p>Microsoft is not happy that several vulnerability researchers have released reports on bugs and exploits in Microsoft systems without first giving the compani&#8217;s PR teams time<s> to spin the news </s>, err, to create a patch.  <a href="https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure">https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure</a></p><p>Attackers are abusing the shared content features of AI chatbot platforms like ChatGPT and Claude to deliver malware by hosting malicious pages on trusted domains such as `chatgpt.com` and `claude.ai`, effectively bypassing standard URL reputation checks. <a href="https://pushsecurity.com/blog/llmshare-malvertising-campaign">https://pushsecurity.com/blog/llmshare-malvertising-campaign</a></p><p>Researchers from Unit 42 are recognizing a significant shift in the cyber extortion landscape, in which threat actors are increasingly abandoning ransomware encryption in favor of pure data theft and extortion, a trend driven by improved organizational backup capabilities and the severe financial leverage of modern regulatory frameworks like GDPR and SEC disclosure rules. This &#8220;data-only&#8221; approach has surged, with incidents rising from 2% in 2020 to 15% in 2025, particularly targeting mid-sized firms in healthcare, professional services, and construction, where the average cost of a breach now exceeds $5 million. <a href="https://unit42.paloaltonetworks.com/cyber-extortion-economy/">https://unit42.paloaltonetworks.com/cyber-extortion-economy/</a></p><p>The Supreme Court will soon decide the legality of geofence warrants. It heard arguments in Chatrie v. United States, a case about geofence warrants and Fourth Amendment privacy concerns. Tech Policy Press fellow Jake Laperruque discussed the case with Michael Price from the Fourth Amendment Center.  <a href="https://www.techpolicy.press/whats-at-stake-in-chatrie-v-united-states/">https://www.techpolicy.press/whats-at-stake-in-chatrie-v-united-states/</a></p><div><hr></div><h4>Feedback</h4><p><em>&#8220;I agree with your take that most of us would probably pay the ransom, but I think you missed an important caveat. At this point, the business isn&#8217;t making the decision; the insurance company is, or at least an attorney and a bean counter working for the insurance company is. The business owner makes that single phone call, and it&#8217;s on autopilot from there. Incident response team, ransom negotiator, legal, finance &#8212; it&#8217;s all pre-packaged. It is now standard for attackers to demand insurance documents to prove the payment limits before they lower their demands.&#8221; - </em>Jack B.  </p><p>Send Feedback to matt(at)threatswithoutborders.com</p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!V9Ox!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F601a9ee2-16de-494d-8eaf-331a128f9fde_1084x1508.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!V9Ox!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F601a9ee2-16de-494d-8eaf-331a128f9fde_1084x1508.jpeg 424w, https://substackcdn.com/image/fetch/$s_!V9Ox!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F601a9ee2-16de-494d-8eaf-331a128f9fde_1084x1508.jpeg 848w, https://substackcdn.com/image/fetch/$s_!V9Ox!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F601a9ee2-16de-494d-8eaf-331a128f9fde_1084x1508.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!V9Ox!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F601a9ee2-16de-494d-8eaf-331a128f9fde_1084x1508.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!V9Ox!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F601a9ee2-16de-494d-8eaf-331a128f9fde_1084x1508.jpeg" width="1084" height="1508" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/601a9ee2-16de-494d-8eaf-331a128f9fde_1084x1508.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1508,&quot;width&quot;:1084,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:238983,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/200127034?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F601a9ee2-16de-494d-8eaf-331a128f9fde_1084x1508.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!V9Ox!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F601a9ee2-16de-494d-8eaf-331a128f9fde_1084x1508.jpeg 424w, https://substackcdn.com/image/fetch/$s_!V9Ox!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F601a9ee2-16de-494d-8eaf-331a128f9fde_1084x1508.jpeg 848w, https://substackcdn.com/image/fetch/$s_!V9Ox!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F601a9ee2-16de-494d-8eaf-331a128f9fde_1084x1508.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!V9Ox!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F601a9ee2-16de-494d-8eaf-331a128f9fde_1084x1508.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p style="text-align: center;">No subscription fees, no ads, no paid product placements. Free, for real.  How about helping the newsletter grow?  Share it with your network.  </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>DFIR</h4><p>The digital forensics lab at Neumann University (just outside Philadelphia) led by Prof. Joe Walsh is winning at everything.  Fantastic experience for students and actually helping law enforcement solve crimes.  Awesome work, Joe.  </p><p><em>To date, that team has assisted in 988 cases across 64 departments and agencies since the center&#8217;s inception in May 2024, including 424 forensic investigations of digital devices and 528 incidents of real-time crime.</em></p><p><a href="https://www.govtech.com/education/higher-ed/neumann-university-helps-law-enforcement-with-digital-forensics">https://www.govtech.com/education/higher-ed/neumann-university-helps-law-enforcement-with-digital-forensics</a></p><h4>Cool Jobs</h4><p>Sr. Manager of Cybersecurity, Washington Commanders Football.  <a href="https://www.teamworkonline.com/football-jobs/washington-commanders-jobs/washington-commanders-jobs/cyber-security-sr-manager-2161458">https://www.teamworkonline.com/football-jobs/washington-commanders-jobs/washington-commanders-jobs/cyber-security-sr-manager-2161458</a></p><h4>Cool Tools</h4><p>Chrome, Edge, Brave, Vivaldi, and Helium are all browsers built on Chromium.  This site tests to ensure your browser of choice is built on the most up-to-date version of Chromium.  <a href="https://chromiumchecker.com/">https://chromiumchecker.com/</a></p><p>Network investigations toolbox.  <a href="https://robtex.com/">https://robtex.com/</a></p><div><hr></div><h4>Irrelevant</h4><p>The Costco theory of the Internet.  <a href="https://www.joanwestenberg.com/the-costco-theory-of-the-internet/">https://www.joanwestenberg.com/the-costco-theory-of-the-internet/</a></p><div><hr></div><h4>Just under the wire&#8230;</h4><p>Published just in time to make this issue, David Maimon traces how the online fake document economy has evolved from the centralized, physical-forgeries marketplace of the Silk Road period (2011&#8211;2017) to an automated, AI-powered process accessible to anyone with a browser. The current &#8220;AI Era&#8221; has removed the last obstacle by employing generative AI to produce synthetic faces and evade liveness checks, rendering the entire fraud cycle, from identity creation to verification, completely automated. <a href="https://resources.sentilink.com/blog/the-evolution-of-the-online-fake-document-economy">https://resources.sentilink.com/blog/the-evolution-of-the-online-fake-document-economy</a></p><div><hr></div><h4>Sign Off</h4><p>They informed me that the attendance at the BSides Harrisburg Cybersecurity Conference this year was lower than usual, but I couldn&#8217;t tell. The rooms appeared packed, at least during the morning sessions. However, attendance at the presentations significantly declined in the afternoon, which was disappointing and something I never quite comprehend. Why pay to attend an event only to spend half of the day there? If I ever organize a conference, I&#8217;ll definitely schedule the most anticipated speaker at 3 p.m.</p><p>It was wonderful to meet so many readers and reconnect with those I&#8217;ve known.  </p><p>Matt</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 288]]></title><description><![CDATA[Cybercrime Investigation Newsletter, week ending May 24, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-288</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-288</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 26 May 2026 10:06:16 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h4>Plausible Diligence: Why Instructure paid the ransom, and you would too!</h4><p>I give a talk called &#8220;DARVO: The Psychological Manipulation of Ransomware Victims&#8221;.  If you&#8217;ve seen it, you know the basic thesis is that ransomware actors are not just technical adversaries. They are expert manipulators who understand pressure, timing, and human psychology better than most Fortune 500 marketing teams. </p><p>When ransomware group ShinyHunters attacked Instructure, the maker of Canvas used by almost every K-12 and higher education institution, and Instructure paid the ransom, the internet responded as expected. Security &#8220;experts&#8221; jumped on X and piously voiced their concerns, law enforcement officials anxiously wrung their hands and expressed curt disapproval, and countless others posted their opinions on blogs and news sites about why paying the ransom was such a bad idea.</p><p><strong>And almost all of them were written by people who have never had to make that decision.</strong></p><p>The anti-ransom crowd occupies a particularly comfortable perch. They&#8217;re mostly law enforcement administration, government agencies, security vendors, and journalists.  People whose jobs don&#8217;t end if the data gets leaked. People who don&#8217;t have to look shareholders, school boards, or parents in the eye the next morning. </p><p>Instructure paid. And you probably would too. </p><p>ShinyHunters breached Instructure&#8217;s systems in late April 2026, exploiting a vulnerability in the Free-for-Teacher version of Canvas. They walked out with 3.65 terabytes of data, including names, email addresses, student ID numbers, course enrollments, and private messages between students and teachers. Records on roughly 275 million individuals across nearly 9,000 schools. </p><p>And this is not Instructure&#8217;s first visit to the octagon with this particular crew. ShinyHunters had already compromised Instructure through social engineering back in September 2025. A different system, and a different method, same attackers. Same company getting hit twice inside of eight months.  Ouch.</p><p>But for now, let&#8217;s talk about what makes this case different from your standard corporate ransomware incident. What makes this one harder. What cranks the pressure up to a level that changes the decision calculus entirely.</p><p>It&#8217;s the kids.</p><p>There is a psychological dimension to ransomware targeting that doesn&#8217;t get discussed enough outside my talk. These groups are not randomly opportunistic. They pick timing the way surgeons pick incisions. ShinyHunters hit Instructure at the end of the academic year, during final exams, during AP testing season. Canvas went dark for thousands of colleges, universities, and K-12 schools at the exact moment those schools needed it most. That&#8217;s not an accident. </p><p>And the data! Private messages between students and teachers. Not just names and email addresses which are bad enough. Actual Messages.  The kind of information that, if leaked, doesn&#8217;t just cause embarrassment. It causes real harm to children who cannot protect themselves, who didn&#8217;t choose to be in this system, and who had no say in whether their school used Canvas or not.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5-0P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f08ffe6-075a-4817-9aae-6f108a6d1e49_1576x662.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5-0P!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f08ffe6-075a-4817-9aae-6f108a6d1e49_1576x662.jpeg 424w, https://substackcdn.com/image/fetch/$s_!5-0P!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f08ffe6-075a-4817-9aae-6f108a6d1e49_1576x662.jpeg 848w, https://substackcdn.com/image/fetch/$s_!5-0P!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f08ffe6-075a-4817-9aae-6f108a6d1e49_1576x662.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!5-0P!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f08ffe6-075a-4817-9aae-6f108a6d1e49_1576x662.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5-0P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f08ffe6-075a-4817-9aae-6f108a6d1e49_1576x662.jpeg" width="1456" height="612" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5f08ffe6-075a-4817-9aae-6f108a6d1e49_1576x662.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:612,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:166587,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/199095352?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f08ffe6-075a-4817-9aae-6f108a6d1e49_1576x662.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5-0P!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f08ffe6-075a-4817-9aae-6f108a6d1e49_1576x662.jpeg 424w, https://substackcdn.com/image/fetch/$s_!5-0P!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f08ffe6-075a-4817-9aae-6f108a6d1e49_1576x662.jpeg 848w, https://substackcdn.com/image/fetch/$s_!5-0P!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f08ffe6-075a-4817-9aae-6f108a6d1e49_1576x662.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!5-0P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f08ffe6-075a-4817-9aae-6f108a6d1e49_1576x662.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Ask the Minneapolis Public Schools district how this plays. They got hit in 2023. The attackers eventually released the data. It included psychological evaluations of students. Abuse documentation. It was a catastrophe measured in human damage, not just data records. Law enforcement &#8220;investigated&#8221;. No ransomware actor went to prison for it. No administrator held responsible. No family got their child&#8217;s records back.</p><p>There is no cavalry coming. <strong>Check me on that</strong>. Law enforcement might call you back. If your organization is important enough, someone might show up and deliver some nicely worded victim care. Your incident response firm is just there to put the pieces back together.  Neither will recover your data. Neither will stop the leak. When you are staring down a countdown clock and the data on that clock belongs to other people&#8217;s children, the abstraction of &#8220;don&#8217;t reward criminals&#8221; has a hard time competing with the concrete reality of what happens if you don&#8217;t.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nqYz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08126354-fc40-4f28-9912-a651be2ff86b_1510x758.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nqYz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08126354-fc40-4f28-9912-a651be2ff86b_1510x758.jpeg 424w, https://substackcdn.com/image/fetch/$s_!nqYz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08126354-fc40-4f28-9912-a651be2ff86b_1510x758.jpeg 848w, https://substackcdn.com/image/fetch/$s_!nqYz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08126354-fc40-4f28-9912-a651be2ff86b_1510x758.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!nqYz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08126354-fc40-4f28-9912-a651be2ff86b_1510x758.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nqYz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08126354-fc40-4f28-9912-a651be2ff86b_1510x758.jpeg" width="1456" height="731" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/08126354-fc40-4f28-9912-a651be2ff86b_1510x758.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:731,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:146490,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/199095352?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08126354-fc40-4f28-9912-a651be2ff86b_1510x758.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nqYz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08126354-fc40-4f28-9912-a651be2ff86b_1510x758.jpeg 424w, https://substackcdn.com/image/fetch/$s_!nqYz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08126354-fc40-4f28-9912-a651be2ff86b_1510x758.jpeg 848w, https://substackcdn.com/image/fetch/$s_!nqYz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08126354-fc40-4f28-9912-a651be2ff86b_1510x758.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!nqYz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08126354-fc40-4f28-9912-a651be2ff86b_1510x758.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I hold Instructure responsible for being compromised. Absolutely. Not once, but twice, by the same group. That&#8217;s not bad luck; that&#8217;s a systemic failure in security posture. The first breach in September 2025 should have been a wake-up call. It apparently wasn&#8217;t, or wasn&#8217;t loud enough. Being compromised twice by the same threat actor in eight months is a process and leadership problem, not a technology problem. That&#8217;s on them.</p><p>But the payment? No hate there. That&#8217;s a business decision made under extraordinary pressure by people who had to live with the consequences. If you were sitting in that CEO chair, with 275 million records on the table and a countdown clock ticking down during finals week at 9,000 schools.</p><p>But here&#8217;s the part nobody wants to say out loud. The part that&#8217;s been quietly driving corporate ransom decisions for years, while the security industry pretends otherwise.</p><p><strong>Paying the ransom buys something that isn&#8217;t data recovery or system restoration. It buys documentation. It buys a paper trail. It buys what I&#8217;m calling  &#8220;plausible diligence&#8221;.</strong></p><p>Most of us have experience with plausible deniability. The art of having enough distance to say &#8220;don&#8217;t blame me, I didn&#8217;t know.&#8221; Plausible diligence is its corporate cousin. It&#8217;s having enough documentation to say &#8220;Don&#8217;t blame us, we tried our hardest.&#8221; It is the deliberate practice of checking every box, engaging every vendor, exhausting every option, and generating a paper trail of effort , so that when the thing fails anyway, the failure attaches to circumstances rather than to negligence.</p><p>Yes, Instructure paid the ransom. In exchange, they received, per their own statement, the return of the stolen data and &#8220;digital confirmation of data destruction.&#8221; They were also informed that none of their customers would be separately extorted. They said they believed &#8220;it was important to take every step <strong>within our control</strong> to give customers additional peace of mind.&#8221;</p><p><em>&#8220;Every step is within our control&#8221;</em>, think about that.  </p><p><strong>That is not a security statement, it&#8217;s a legal statement. That is the founding sentence of a liability defense.</strong></p><p>When the lawsuits come, and they will come, because 275 million records across 9,000 schools is not a quiet incident, Instructure&#8217;s lawyers will walk into that courtroom and say: we detected the breach, we contained it, we engaged expert forensic vendors, we negotiated to recover the data, we obtained confirmation of destruction, and we notified our customers. &#8220;<strong>We did everything. The criminals lied to us. Blame them.&#8221;</strong></p><p>Fully understand that the data is still out there. That&#8217;s how this works. ShinyHunters doesn&#8217;t actually delete anything, or, if they do, another group with a different name and the same data surfaces six months later. The &#8220;confirmation of destruction&#8221; is not a guarantee any serious security professional believes. Instructure&#8217;s own statement acknowledged there is &#8220;never complete certainty when dealing with cyber criminals.&#8221;</p><p><strong>They paid anyway. Because plausible diligence isn&#8217;t about what actually happens to the data. It&#8217;s about what you can document you did about it.</strong></p><p>Instructure did what cornered organizations do. They paid for something real, protection from immediate harm, and something less real but arguably more important: a documented record of having tried everything. A paper trail of effort that says, to regulators, to plaintiffs, to school boards and parents and lawyers, &#8220;Don&#8217;t blame us. We paid for an assurance and received documentation of its destruction. </p><p>That&#8217;s not justice, it&#8217;s not good security policy, but it&#8217;s how the game is actually played.</p><p>Until we fix the conditions that create the game, such as inadequate security investment by business leadership, the complete vacuum of real government response, and the absence of consequences for attackers, companies will keep playing it. </p><p>Paying the ransom makes the problem worse. But I&#8217;d probably pay it.  And you would too!</p><div><hr></div><h4>News&#8230;</h4><p>First&#8230; the Verizon DBIR was released.  I didn&#8217;t miss it.  There just isn&#8217;t room in this issue for me to talk about.  Come back next week.</p><p>This report by HPE Threat Labs claims it studied 44.5 million connection attempts from 372,800 unique IP addresses and determined that the &#8220;top threat actor country by IP count&#8221; was&#8230; drumroll&#8230; the United States.  Wait what?  Are you saying the number-one source of criminal intrusion attempts is the United States?  I must be misunderstanding that.  Or they are only claiming that most threat actors are exiting from nodes based here in the states.  <a href="https://www.hpe.com/psnow/doc/a50014950enw">https://www.hpe.com/psnow/doc/a50014950enw</a></p><p>Cofense details how attackers are using Zoom-themed phishing emails to trick victims into installing ConnectWise ScreenConnect. <a href="https://cofense.com/blog/click-install-compromised-the-new-wave-of-zoom-themed-attacks">https://cofense.com/blog/click-install-compromised-the-new-wave-of-zoom-themed-attacks</a></p><p>Apple claims to have prevented 2.2 billion dollars in potentially fraudulent transactions through the App Store and deactivated 40.4 million accounts for fraud and abuse. <a href="https://9to5mac.com/2026/05/20/apple-gives-update-on-the-app-store-and-its-key-protections/"> https://9to5mac.com/2026/05/20/apple-gives-update-on-the-app-store-and-its-key-protections/</a></p><p>The FBI has issued an advisory warning about Kali365, a &#8220;Phishing-as-a-Service&#8221; platform distributed via Telegram that enables attackers to compromise Microsoft 365 accounts by capturing OAuth tokens instead of stealing passwords. The tool delivers AI-generated phishing lures that impersonate trusted services such as Adobe and SharePoint, tricking users into authorizing malicious device sessions on legitimate Microsoft login pages. <a href="https://therecord.media/fbi-warns-of-kali365-phishing-attacks">https://therecord.media/fbi-warns-of-kali365-phishing-attacks</a></p><div><hr></div><h4>Feedback</h4><p>Send Feedback to matt(at)threatswithoutborders.com</p><div><hr></div><h4>dfir</h4><p>The evidence of an Apple FaceTime call and what Apple can provide.  <a href="https://lucidtruthtechnologies.com/facetime-evidence-apple-subpoena/">https://lucidtruthtechnologies.com/facetime-evidence-apple-subpoena/</a></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>Cool Jobs</h4><p>Intelligence Specialist - FinCEN.  <a href="https://www.usajobs.gov/job/869413300">https://www.usajobs.gov/job/869413300</a></p><p>Director of Security - Politico.  <a href="https://politico.wd108.myworkdayjobs.com/politico/job/Arlington-VA/Director-of-Security_JR100411">https://politico.wd108.myworkdayjobs.com/politico/job/Arlington-VA/Director-of-Security_JR100411</a></p><h4>Cool Tools</h4><p>OFAC Sanctions Search.  <a href="https://sanctionssearch.ofac.treas.gov/">https://sanctionssearch.ofac.treas.gov/</a></p><p>Bookmark this so you don&#8217;t have to keep asking for it on some email listserv - Bank Identification Number (BIN) search. <a href="https://binlist.net/">https://binlist.net/</a></p><div><hr></div><h4>Irrelevant</h4><p>Top 100 valued Bitcoin wallets.  <a href="https://bitinfocharts.com/top-100-richest-bitcoin-addresses.html">https://bitinfocharts.com/top-100-richest-bitcoin-addresses.html</a></p><div><hr></div><h4>Sign Off</h4><p>The BSides Harrisburg 2026 conference is happening this Friday, May 26th, at the Farm Show Complex in Harrisburg. This marks my fourth year volunteering and my third year as a room emcee. </p><p>Please find me in the Track 1 room and say hi. I&#8217;ll be the person on stage introducing speakers and gently cutting them off if they go over time. Despite how stressed I might look, meeting TWoB readers is always a top priority for me. Please come and introduce yourself.</p><p>And tickets are still available.  <a href="https://www.bsideshbg.com/">https://www.bsideshbg.com/</a></p><p>Matt</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cNlp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d8bd00-db28-4254-bdbd-a9e0877a38fd_1160x878.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cNlp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d8bd00-db28-4254-bdbd-a9e0877a38fd_1160x878.jpeg 424w, https://substackcdn.com/image/fetch/$s_!cNlp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d8bd00-db28-4254-bdbd-a9e0877a38fd_1160x878.jpeg 848w, https://substackcdn.com/image/fetch/$s_!cNlp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d8bd00-db28-4254-bdbd-a9e0877a38fd_1160x878.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!cNlp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d8bd00-db28-4254-bdbd-a9e0877a38fd_1160x878.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cNlp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d8bd00-db28-4254-bdbd-a9e0877a38fd_1160x878.jpeg" width="1160" height="878" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/31d8bd00-db28-4254-bdbd-a9e0877a38fd_1160x878.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:878,&quot;width&quot;:1160,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:121920,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/199095352?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d8bd00-db28-4254-bdbd-a9e0877a38fd_1160x878.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cNlp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d8bd00-db28-4254-bdbd-a9e0877a38fd_1160x878.jpeg 424w, https://substackcdn.com/image/fetch/$s_!cNlp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d8bd00-db28-4254-bdbd-a9e0877a38fd_1160x878.jpeg 848w, https://substackcdn.com/image/fetch/$s_!cNlp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d8bd00-db28-4254-bdbd-a9e0877a38fd_1160x878.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!cNlp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31d8bd00-db28-4254-bdbd-a9e0877a38fd_1160x878.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 287]]></title><description><![CDATA[Cybercrime Investigation Newsletter, Week ending May 17, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-287</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-287</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 19 May 2026 10:07:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-lzX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf58a56-6633-4da2-ac32-797c85eacf37_986x776.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Few individuals in our niche have the credibility to publish opinion pieces through major news organizations like Fox. David Maimon is one.  </p><p>In this piece, he details how hostile state actors, including Iran, North Korea, Russia, and China, are systematically exploiting the US banking and employment systems by leveraging fraud infrastructure sourced from the dark web. His team has observed that these nations purchase stolen identity components, such as Social Security numbers and compromised bank credentials, to create synthetic identities and shell companies that bypass traditional compliance checks and sanctions screenings. </p><p>By routing transactions through correspondent banks with limited transparency and employing domestic US facilitators to conceal foreign IT workers or carry out financial grooming scams, these adversaries effectively funnel billions of dollars into the US financial system and infiltrate sensitive institutions. He emphasizes that current detection methods often fall short because the fraudulent entities look legitimate on paper, using forged documents and complex corporate structures to hide the true state-sponsored operators.</p><p><a href="https://www.foxnews.com/opinion/adversaries-even-using-us-banking-system-heres-get-away">https://www.foxnews.com/opinion/adversaries-even-using-us-banking-system-heres-get-away</a></p><div><hr></div><h4>Can they make this any easier? </h4><p>I&#8217;ve discussed this before, probably ad nauseam. But the bad guys are endlessly abusing the Payroll Protection Program (PPP) loans database. The pointy-head bureaucrat who decided this information should be made public should be made to sit in a dunk tank in the lobby of the IAFCI International conference.  </p><p>And if they couldn&#8217;t make the database any easier to navigate, someone turned it into an interactive map.  Awesome.</p><p><a href="https://www.ppploanmap.com/">https://www.ppploanmap.com/</a></p><div><hr></div><h4>The News</h4><p>A BitLocker bypass vulnerability was discovered.  You must have physical access to the device, and it only works on Windows 11 machines.  <a href="https://github.com/Nightmare-Eclipse/YellowKey">https://github.com/Nightmare-Eclipse/YellowKey</a></p><p>Tech-Support attacks are increasingly using the Quick Assistant tool, which is installed on Windows 10 and 11.  Thomas Miller of TrustedSec shows how to identify and respond to attacks using this tool.  <a href="https://trustedsec.com/blog/slamming-the-door-on-quick-assist-tech-support-scams-and-abuse">https://trustedsec.com/blog/slamming-the-door-on-quick-assist-tech-support-scams-and-abuse</a></p><p>Capital One takes an offensive position by filing a federal lawsuit in Virginia against unidentified operators behind large-scale robocall scams. The bank accuses them of trademark infringement by misusing its and Discover&#8217;s names in deceptive impersonation schemes. Using civil litigation enables the bank to leverage the discovery process to identify these scammers and dismantle their operations. This strategy, increasingly employed by major tech companies, aims to supplement traditional law enforcement efforts. <a href="https://www.cnbc.com/2026/05/13/capital-one-lawsuit.html">https://www.cnbc.com/2026/05/13/capital-one-lawsuit.html</a></p><p>Meta introduces Incognito Chat with Meta AI on WhatsApp and the Meta AI app, offering a fully private AI interaction. These conversations occur in a secure environment that Meta cannot access, and they are set to disappear automatically.  <a href="https://about.fb.com/news/2026/05/incognito-chat-whatsapp-meta-ai/">https://about.fb.com/news/2026/05/incognito-chat-whatsapp-meta-ai/</a></p><p>The Dutch police have turned to shaming, and I&#8217;m completely onboard. The &#8220;Game Over?!&#8221; campaign, publicly named 100 of the country&#8217;s most wanted scammers, which led to the identification of 74 suspects. During this campaign, fraudsters were given a two-week period to surrender voluntarily while their blurred images were displayed; after the deadline, the police unblurred the faces on social media and billboards, prompting 34 individuals to turn themselves in and helping identify 40 more through over 500 public tips. The effort focused on scams targeting the elderly, like bank helpdesk impersonation and fake police visits. It reached nearly 90 million people on social media and has led to 38 interrogations and 6 arrests, with investigators noting that the average age of suspects is only 22.  <a href="https://www.theregister.com/cyber-crime/2026/05/18/dutch-cops-shame-games-nets-74-wanted-fraudsters/5241980">https://www.theregister.com/cyber-crime/2026/05/18/dutch-cops-shame-games-nets-74-wanted-fraudsters/5241980</a></p><p>Proofpoint launches a managed service provider (MSP) unit, which they are calling Proofpoint 365.  No.  <a href="https://www.proofpoint.com/us/newsroom/press-releases/proofpoint-launches-dedicated-msp-business-unit-and-introduces-365-total">https://www.proofpoint.com/us/newsroom/press-releases/proofpoint-launches-dedicated-msp-business-unit-and-introduces-365-total</a></p><p>A 25-year-old former Penn State student and auxiliary police officer, has been held on $2 million bail after being charged with felony computer crimes involving the unauthorized manipulation of police dispatch systems containing sensitive personal and criminal data. <a href="https://www.centredaily.com/news/local/crime/article315752921.html">https://www.centredaily.com/news/local/crime/article315752921.html</a></p><p>OpenAI released Daybreak, its AI-powered cybersecurity and vulnerability management platform.  <a href="https://openai.com/daybreak/">https://openai.com/daybreak/</a></p><div><hr></div><h4>Feedback</h4><p>Send Feedback to matt(at)threatswithoutborders.com</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-lzX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf58a56-6633-4da2-ac32-797c85eacf37_986x776.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-lzX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf58a56-6633-4da2-ac32-797c85eacf37_986x776.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-lzX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf58a56-6633-4da2-ac32-797c85eacf37_986x776.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-lzX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf58a56-6633-4da2-ac32-797c85eacf37_986x776.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-lzX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf58a56-6633-4da2-ac32-797c85eacf37_986x776.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-lzX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf58a56-6633-4da2-ac32-797c85eacf37_986x776.jpeg" width="986" height="776" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/adf58a56-6633-4da2-ac32-797c85eacf37_986x776.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:776,&quot;width&quot;:986,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:98999,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/198260936?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf58a56-6633-4da2-ac32-797c85eacf37_986x776.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-lzX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf58a56-6633-4da2-ac32-797c85eacf37_986x776.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-lzX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf58a56-6633-4da2-ac32-797c85eacf37_986x776.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-lzX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf58a56-6633-4da2-ac32-797c85eacf37_986x776.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-lzX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf58a56-6633-4da2-ac32-797c85eacf37_986x776.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h4>dfir</h4><p>It appears that files synced to iCloud Drive are now stripped of their metadata.  <a href="https://eclecticlight.co/2026/05/11/does-icloud-drive-now-lose-almost-all-metadata/">https://eclecticlight.co/2026/05/11/does-icloud-drive-now-lose-almost-all-metadata/</a></p><div><hr></div><p>No subscriptions, no ads, no paid product promotions. Some issues better than others.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>Cool Jobs</h4><p>IT Security Analyst - Baltimore Orioles Baseball Club.  <a href="https://www.teamworkonline.com/baseball-jobs/orioles-jobs/baltimore-orioles-jobs/it-security-analyst-2169873">https://www.teamworkonline.com/baseball-jobs/orioles-jobs/baltimore-orioles-jobs/it-security-analyst-2169873</a></p><p>Director of Information Security - Penn Community Bank.  <a href="https://penncommunitybank.wd501.myworkdayjobs.com/ExternalCareers/job/Bristol-PA/Director-of-Information-Security--ISO-_R-100099">https://penncommunitybank.wd501.myworkdayjobs.com/ExternalCareers/job/Bristol-PA/Director-of-Information-Security--ISO-_R-100099</a></p><h4>Cool Tools</h4><p>Python tool that digs deep for email addresses and usernames across hundreds of online resources.  <a href="https://github.com/kaifcodec/user-scanner">https://github.com/kaifcodec/user-scanner</a></p><p>Barcode reader.  <a href="https://online-barcode-reader.inliteresearch.com/">https://online-barcode-reader.inliteresearch.com/</a></p><p>What&#8217;s happening - right now? <a href="https://trends.google.com/trending?geo=US">https://trends.google.com/trending?geo=US</a></p><div><hr></div><h4>Irrelevant</h4><p>This guy keeps a running tab on Apple&#8217;s neglect of its base applications.  As a longtime Mac user, I agree with all of this.  Honestly, it&#8217;s pretty bad.  Am I switching to Windows?  Hell no.  But if someone can get me a clean install of Linux on my M4 Mac Air, I&#8217;m gone.  <a href="https://taoofmac.com/space/blog/2026/05/18/1320?utm_content=atom">https://taoofmac.com/space/blog/2026/05/18/1320</a></p><div><hr></div><h4>Sign Off</h4><p>Welcome, new subscribers!  There&#8217;s always pressure after we gather a load of new subs, and I always feel like I&#8217;m letting everyone down.  The newsletter gets hyped at an event, people subscribe, and this is what they get!  The product always looks better in the ad, I guess.  But hopefully, enough of you stay around for next week.  </p><p>It&#8217;s hot here in Central PA, and I know the Midwest has been raked by violent storms.  Stay cool and safe!</p><p>Matt</p><p>&#8220;DON&#8217;T RUIN A GOOD TODAY BY THINKING ABOUT A BAD YESTERDAY. LET IT GO.&#8221;</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 286]]></title><description><![CDATA[Cyber-Financial Crime Investigation Newsletter, week ending May 10, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-286</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-286</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 12 May 2026 10:47:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>There&#8217;s a special kind of confidence that exists on LinkedIn. Someone shares an article with a dramatic headline, adds &#8220;Important read!&#8221; or &#8220;Everyone needs to see this,&#8221; and suddenly the post starts bouncing from connection to connection like a digital game of phone-a-friend.</p><p>And this week, I almost fell for it myself.</p><p>One of my connections shared a post from a well-known anti-fraud organization that is usually pretty solid. Buried inside was a link to an article about how cybercriminals are using AI to craft scams and phishing attacks. On the surface, it sounded reasonable as AI is being used by criminals. So I was about two clicks away from hitting the repost button myself.</p><p>But then I did something crazy, I read the article.</p><p>Not the headline.  Not the summary.  Not the one-line hot-take above the share. The actual article.</p><p>The piece was written by a company selling an AI detection product for fraud prevention.  Their &#8220;research&#8221; conveniently supported the urgent need for the exact service they happen to sell. The article sprinkled in just enough truth to sound credible, then fired up the hype machine and drifted straight into panic-porn marketing.</p><p>It wasn&#8217;t education. It was advertising dressed up as analysis.</p><p>I&#8217;m sure the person who shared it trusted the person they got it from. And that person probably trusted their connection. By the time it reached my feed, it was basically a share of a share of a share of a share, with everyone assuming someone else had done the homework.</p><p>Nobody did, and this happens constantly on LinkedIn. Content becomes heavily nested through reposts, and eventually, the original source becomes little more than a decorative attachment. People aren&#8217;t evaluating the information anymore. They&#8217;re evaluating the social credibility of the person sharing it.</p><p>&#8220;If Bob gave it a red 100 emoji, it must be good.&#8221; Meanwhile, Bob read exactly three sentences and a bullet point.</p><p>That&#8217;s why I read every article I include in the newsletter. Including an article doesn&#8217;t mean I endorse it or the author. I don&#8217;t always agree with what&#8217;s written, and many times that&#8217;s exactly why I include it. </p><p>But at the very least, I can honestly say I read it to make sure it&#8217;s not complete trash before passing it on. </p><p>You would think that would be the standard in 2026, but here we are.</p><p>So the next time your favorite LinkedIn warrior shares an article with fifteen fire emojis and the phrase &#8220;So True!&#8221; take an extra minute before you hit repost. Open the article and read it. </p><p>If you want to read an actual article about the criminal use of AI: Dr. Ben Collier from the Center for Emerging Technology and Security at the Alan Turing Institute explores generative AI adoption in the criminal underground.  <a href="https://cetas.turing.ac.uk/publications/cybercrime-vibercrime-assessing-generative-ai-adoption-criminal-underground">https://cetas.turing.ac.uk/publications/cybercrime-vibercrime-assessing-generative-ai-adoption-criminal-underground</a></p><div><hr></div><h4>And sometimes&#8230;</h4><p>That article posted to LinkedIn is gold!  Steve Lenderman shared a link to a report on card fraud this week that turned out to be the best thing I&#8217;ve read in a while.</p><p>No, not that card fraud, the other card fraud.  Counterfeit trading cards.  Who knew an original Charizard was in such demand, or worth so much money???</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Sp4J!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7f347c-15e9-4150-be4d-502362e34cd8_1446x1430.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Sp4J!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7f347c-15e9-4150-be4d-502362e34cd8_1446x1430.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Sp4J!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7f347c-15e9-4150-be4d-502362e34cd8_1446x1430.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Sp4J!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7f347c-15e9-4150-be4d-502362e34cd8_1446x1430.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Sp4J!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7f347c-15e9-4150-be4d-502362e34cd8_1446x1430.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Sp4J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7f347c-15e9-4150-be4d-502362e34cd8_1446x1430.jpeg" width="1446" height="1430" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3e7f347c-15e9-4150-be4d-502362e34cd8_1446x1430.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1430,&quot;width&quot;:1446,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:254621,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/197169482?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7f347c-15e9-4150-be4d-502362e34cd8_1446x1430.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Sp4J!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7f347c-15e9-4150-be4d-502362e34cd8_1446x1430.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Sp4J!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7f347c-15e9-4150-be4d-502362e34cd8_1446x1430.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Sp4J!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7f347c-15e9-4150-be4d-502362e34cd8_1446x1430.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Sp4J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7f347c-15e9-4150-be4d-502362e34cd8_1446x1430.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The 2025 Card Fraud Report from collectible authentication company PSA is a must-read, if for nothing more than to broaden your view of the fraud landscape. For someone immersed in cyber fraud, the topic is fascinating. A whole different world.  </p><p><a href="https://downloads.ctfassets.net/l40e281thfxr/72ZJooe31lk9KGBklfQFOu/4a3bf368f91a364fad3ccc2eca077a17/PSA_Fraud-Report_2025.pdf">https://downloads.ctfassets.net/l40e281thfxr/72ZJooe31lk9KGBklfQFOu/4a3bf368f91a364fad3ccc2eca077a17/PSA_Fraud-Report_2025.pdf</a></p><div><hr></div><h4>The News</h4><p>An investigation uncovered &#8220;Department 4&#8217; at Russia&#8217;s Bauman Moscow State Technical University, which allegedly acts as a secret recruitment hub for the GRU, Russia&#8217;s military intelligence. Masked as an elite academic program, it trains students in advanced cyberwarfare skills such as password hacking, virus creation, and physical espionage, with the GRU controlling admissions, tests, and the placement of graduates into notorious hacking groups. The leaked 2,000 documents reveal that talented students are spotted as early as secondary school and assigned to units responsible for major cyberattacks worldwide. This is essentially a &#8220;hacker factory&#8217;. <a href="https://www.bitdefender.com/en-us/blog/hotforsecurity/inside-department-4-russias-secret-school-for-hackers">https://www.bitdefender.com/en-us/blog/hotforsecurity/inside-department-4-russias-secret-school-for-hackers</a></p><p>This makes me smile.  Kids are beating age verification checks by wearing fake mustaches!  <a href="https://www.theregister.com/security/2026/05/04/kids-can-bypass-some-age-checks-with-a-drawn-on-mustache/5224601">https://www.theregister.com/security/2026/05/04/kids-can-bypass-some-age-checks-with-a-drawn-on-mustache/5224601</a></p><p>Securonix Threat Research has uncovered a phishing campaign that targets over 80 organizations primarily in the US by exploiting legitimate Remote Monitoring and Management (RMM) tools. The attack begins with impersonation emails mimicking the U.S. Social Security Administration, directing victims to compromised Mexican websites to download a malicious executable disguised as a government document.  <a href="https://www.securonix.com/blog/venomous-helper-phishing-campaign/">https://www.securonix.com/blog/venomous-helper-phishing-campaign/</a></p><p>You&#8217;re Invited! Psyche, how about some victimization instead?  Fake invitations delivered via e-greeting cards are compromising accounts.  <a href="https://tidbits.com/2026/05/11/beware-greeting-card-scams-from-trusted-senders/">https://tidbits.com/2026/05/11/beware-greeting-card-scams-from-trusted-senders/</a></p><p>And of course, Instructure, also known as Canvas, got hit, again. I won't spend time discussing it; a quick Google search can provide more details or the latest update on your school's likely recovery timeline.  </p><div><hr></div><h4>Feedback</h4><p>Send Feedback to matt(at)threatswithoutborders.com</p><div><hr></div><h4>dfir</h4><p>Andrea Fortuna examines the challenges of cloud forensics, in which digital evidence is spread across multiple jurisdictions worldwide, forming a &#8220;jurisdictional labyrinth&#8221; that our traditional investigative techniques don&#8217;t easily navigate. Legal systems are increasingly in conflict, as seen in the conflict between the U.S. CLOUD Act, which claims jurisdiction based on the provider, even if data is stored elsewhere, and the EU&#8217;s GDPR, which limits cross-border data transfers unless there are specific international agreements. <a href="https://andreafortuna.org/2026/05/06/cloud-forensics-jurisdictional-labyrinth/">https://andreafortuna.org/2026/05/06/cloud-forensics-jurisdictional-labyrinth/</a></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>Cool Jobs</h4><p>Fraud Manager, Everence Federal Credit Union.  <a href="https://www.everence.com/about-everence/careers/current-positions/current-positions/2026/may/fraud-manager">https://www.everence.com/about-everence/careers/current-positions/current-positions/2026/may/fraud-manager</a></p><h4>Cool Tools</h4><p>Has this image been edited?  Use this to find out. <a href="https://imageedited.com/"> https://imageedited.com/</a></p><p>Track flights from your desktop.  <a href="https://flightradar.live/en/">https://flightradar.live/en/</a></p><p>Find a blog to follow.  <a href="https://blogosphere.app/">https://blogosphere.app/</a></p><div><hr></div><h4>Irrelevant</h4><p>Joan Westenberg argues that the modern outrage cycle is intentionally crafted as a business strategy to generate engagement through provoked anger. She suggests that high-intensity anger is the most effective way to drive viral content, transforming digital platforms into &#8220;slot machines&#8221; that deliver outrage to keep users engaged and advertising revenue flowing. The best safeguard, she proposes, is **procedural emotional resistance**: resisting the algorithm's emotional pull by asking who gains from your reaction and remembering that your attention is the actual product being sold. <a href="https://www.joanwestenberg.com/outrag/">https://www.joanwestenberg.com/outrag/</a></p><div><hr></div><h4>Sign Off</h4><p>I attended several events around a college graduation this weekend and heard multiple speakers emphasize the importance of &#8220;your network&#8221;. There&#8217;s plenty of advice on how to build connections with co-workers, colleagues, and like-minded professionals. However, what seems to be missing from most advice is how to leverage that network effectively, how to make it work for you. Once you&#8217;ve built your network, what should you do with it?  That&#8217;s the real nugget.</p><p>For example, a large and active network is useful if you&#8217;re unemployed. It&#8217;s easy to contact colleagues and post on social media, saying, &#8220;Hey everyone, I need a job.&#8221; But what if you&#8217;re already employed but low-key seeking a new opportunity? How do you leverage your network then? You can&#8217;t exactly broadcast that you&#8217;re looking for a new job, nor is it wise to post &#8220;open to work&#8221; on LinkedIn. Well, you could, but it would be best to submit your resignation to your current employer along with such a post.  Is a large network really only an insurance policy in the event you become unemployed? </p><p>Thanks for reading another week.  See you next Tuesday.</p><p>Matt</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 285]]></title><description><![CDATA[Cybersecurity Investigations Newsletter - Week ending May 3, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-285</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-285</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 05 May 2026 10:26:16 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m frequently asked in my community presentations if PDFs are &#8220;safe&#8221; to open.  As usual, my answer is something to the effect of &#8220;maybe&#8221;.</p><p>As the Q1 2026 Email Threats Landscapes Report from Microsoft details, PDFs are becoming one of the main malicious payloads for attackers, second only to HTML files</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6lk5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe997ed88-971f-4586-b337-18336b3d9cf3_1290x952.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6lk5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe997ed88-971f-4586-b337-18336b3d9cf3_1290x952.jpeg 424w, https://substackcdn.com/image/fetch/$s_!6lk5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe997ed88-971f-4586-b337-18336b3d9cf3_1290x952.jpeg 848w, https://substackcdn.com/image/fetch/$s_!6lk5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe997ed88-971f-4586-b337-18336b3d9cf3_1290x952.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!6lk5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe997ed88-971f-4586-b337-18336b3d9cf3_1290x952.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6lk5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe997ed88-971f-4586-b337-18336b3d9cf3_1290x952.jpeg" width="1290" height="952" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e997ed88-971f-4586-b337-18336b3d9cf3_1290x952.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:952,&quot;width&quot;:1290,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:95851,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/196312027?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe997ed88-971f-4586-b337-18336b3d9cf3_1290x952.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6lk5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe997ed88-971f-4586-b337-18336b3d9cf3_1290x952.jpeg 424w, https://substackcdn.com/image/fetch/$s_!6lk5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe997ed88-971f-4586-b337-18336b3d9cf3_1290x952.jpeg 848w, https://substackcdn.com/image/fetch/$s_!6lk5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe997ed88-971f-4586-b337-18336b3d9cf3_1290x952.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!6lk5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe997ed88-971f-4586-b337-18336b3d9cf3_1290x952.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>PDFs have become one of the most effective tools for the cybercriminal, not because they look dangerous, but because they look normal. We all use them every day!  In most workplaces, PDFs are the default format for invoices, resumes, reports, and contracts. That familiarity creates trust, and attackers take full advantage of it.</p><p>But a PDF isn&#8217;t just a simple document. It&#8217;s a &#8220;rich&#8221; file format capable of running code, embedding other files, and interacting with users. That means a PDF can behave more like a small program than a static page.</p><p>Attackers exploit this in several ways, including embedded JavaScript that runs automatically when the file is opened. If the user&#8217;s PDF reader has a vulnerability, that script can attempt to exploit it and gain control of the system. In other situations, the PDF acts as a delivery mechanism, sometimes called a &#8220;dropper.&#8221; The file itself may appear harmless, but it triggers a download of malware from an external server once opened.</p><p>The most common method, however, isn&#8217;t a technical exploit; it&#8217;s simple visual deception.  Examples include fake buttons, where a PDF displays a message like &#8220;This content is encrypted. Click here to decrypt.&#8221; Clicking the button redirects the user to a counterfeit login page (such as a spoofed Microsoft 365 portal) to steal credentials. Another method is the favorite tool of every marketer, URL shorteners. Malicious links are often concealed behind shortened URLs or legitimate-looking text to avoid detection by email security systems.</p><p>From a security standpoint, PDFs are difficult to detect and block for a few key reasons. First, attackers can hide or encrypt parts of the file, making it hard for email security tools to inspect the contents. Second, PDFs can be large and complex, and some systems limit how deeply they scan files to avoid slowing down email delivery.  </p><p>The result is a perfect storm: a trusted file type, powerful built-in features, and technical complexity that challenges traditional defenses.</p><p>So, back to the question, is that PDF safe to open?  </p><p>The default test for the everyday email users is, do you know the sender? But you need to consider that even a known sender might have a compromised account. The better test is, were you expecting the document? If not, use the phone and call the sender. Oh, and don&#8217;t call the contact number included in the email. You might be calling the bad guys!</p><p>Read the full Microsoft Report:  <a href="https://www.microsoft.com/en-us/security/blog/2026/04/30/email-threat-landscape-q1-2026-trends-and-insights/">https://www.microsoft.com/en-us/security/blog/2026/04/30/email-threat-landscape-q1-2026-trends-and-insights/</a></p><div><hr></div><h4>The News</h4><p>Varonis Threat Labs discovered Bluekit, a phishing kit offering 40+ website templates, automated domain services, and add-ons, including AI assistants and voice cloning. While the platform is good, it&#8217;s not as good as promised. <a href="https://www.varonis.com/blog/bluekit">https://www.varonis.com/blog/bluekit</a></p><p>Scott Lang from Spur contends that relying solely on a single off-the-shelf fraud score to assess IP risk is restrictive. This approach tends to condense complex, multidimensional data into a static &#8220;black box&#8221; number that lacks necessary context and adaptability. He argues that security teams should focus on detailed IP intelligence features, such as data center locations, VPN links, and geographic discrepancies, to develop transparent and customizable risk models aligned with their specific organizational needs and risk tolerance. By moving away from a universal score towards a &#8220;glass box&#8221; methodology, organizations can make finer decisions, like initiating additional authentication steps or blocking traffic, based on genuine underlying signals rather than an opaque overall score.  <a href="https://spur.us/blog/ip-risk-scoring-vs-ip-context">https://spur.us/blog/ip-risk-scoring-vs-ip-context</a></p><p>The FBI issued a PSA warning that cyber threat actors are impersonating legitimate businesses to hijack freight and steal high-value shipments. Since 2024, these actors have gained unauthorized access to computer systems, posing as victim companies and redirecting goods for resale.  In 2025, estimated cargo theft losses in the United States and Canada surged to nearly $725 million.  <a href="https://www.ic3.gov/PSA/2026/PSA260430">https://www.ic3.gov/PSA/2026/PSA260430</a></p><p>I&#8217;m more concerned about having my voice recorded in a permanent file, but these authors argue that patients should refuse consent for &#8220;AI&#8221; scribing tools in healthcare settings due to significant privacy risks, the potential for reduced openness during consultations, and the likelihood of automation bias leading to inaccurate medical records. They contend that charting is an essential part of the care process itself, and that replacing it with automated drafts degrades both immediate and long-term patient outcomes. <a href="https://buttondown.com/maiht3k/archive/why-you-should-refuse-to-let-your-doctor-record/">https://buttondown.com/maiht3k/archive/why-you-should-refuse-to-let-your-doctor-record/</a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4sfS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930f8b6d-d55b-475a-ae99-d27b8a36745f_994x308.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4sfS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930f8b6d-d55b-475a-ae99-d27b8a36745f_994x308.jpeg 424w, https://substackcdn.com/image/fetch/$s_!4sfS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930f8b6d-d55b-475a-ae99-d27b8a36745f_994x308.jpeg 848w, https://substackcdn.com/image/fetch/$s_!4sfS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930f8b6d-d55b-475a-ae99-d27b8a36745f_994x308.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!4sfS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930f8b6d-d55b-475a-ae99-d27b8a36745f_994x308.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4sfS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930f8b6d-d55b-475a-ae99-d27b8a36745f_994x308.jpeg" width="994" height="308" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/930f8b6d-d55b-475a-ae99-d27b8a36745f_994x308.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:308,&quot;width&quot;:994,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:76777,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/196312027?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930f8b6d-d55b-475a-ae99-d27b8a36745f_994x308.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4sfS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930f8b6d-d55b-475a-ae99-d27b8a36745f_994x308.jpeg 424w, https://substackcdn.com/image/fetch/$s_!4sfS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930f8b6d-d55b-475a-ae99-d27b8a36745f_994x308.jpeg 848w, https://substackcdn.com/image/fetch/$s_!4sfS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930f8b6d-d55b-475a-ae99-d27b8a36745f_994x308.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!4sfS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F930f8b6d-d55b-475a-ae99-d27b8a36745f_994x308.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h4>It&#8217;s Conference Season</h4><p>I originally published this back in 2024, but since it&#8217;s conference season, let me remind you of the most terrible conference attendee &#8211; Conference Question Guy. And it&#8217;s always a guy.</p><p><strong>Gotcha Guy</strong> attempts to put the speaker in a bad spot by asking a question about some obscure or little-known technical aspect of the speaker&#8217;s topic. The question&#8217;s intent isn&#8217;t to elicit more knowledge or spur conversation but to trick the speaker and make them look poor in front of the audience.</p><p><strong>Test the Speaker&#8217;s Knowledge Guy</strong>, much like Gotcha Guy, this question asker is already knowledgeable about the topic and asks a question that he already knows the answer to. He&#8217;s a more benign version of Gotcha guy.</p><p>You can immediately spot <strong>Look How Smart I Am Guy </strong>as he&#8217;s on the edge of his seat the whole talk, and only an ounce of self-restraint is keeping him from stepping up on stage. His head is nodding or shaking throughout the entire talk, and he usually makes statements to those around him. His hand will be the first one up after the talk. His proposed question is usually a softball, but will be constructed to allow him to follow up with a more detailed and technical retort to demonstrate his mastery of the speaker&#8217;s topic.</p><p>While<strong> Mask Guy&#8217;s</strong> commitment to public health is admirable, no one can hear the question, including the speaker. The easy solution is just slightly to pull the mask down when asking the question, but since they don&#8217;t, they just come across as a virtue-signaling asshole.</p><p><strong>Mansplaining Guy</strong> is a particularly dreadful species; the Mansplaining Guy targets female speakers and uses their questions as a way to lecture about a particular topic point he feels the speaker didn&#8217;t thoroughly explain or doesn&#8217;t completely understand.</p><p><strong>Political Statement Guy</strong> usually wears the requisite noble cause t-shirt or some slogan buttons on his jacket. &#8220;How will this be interpreted by the [insert politician] government, considering their failure to&#8230;&#8221;, &#8220;Don&#8217;t you think this is all irrelevant, considering there are children dying on C&#244;te d&#8217;Ivoire<strong> </strong>cocoa farms?&#8220;, &#8220;Isn&#8217;t this an assault on the 1<sup>st</sup> Amendment?&#8221; &#8220;Have you seen any evidence that this might lead to the loss of the Arctic ice shelf&#8230;&#8221;, AHHHHHH &#8211; Please just stop.</p><p><strong>Complain About My Employer Guy</strong> uses their question to passively-aggressively criticize their own employer or supervisor, framing it to get the speaker to agree with their assertion.</p><p>To clarify, speakers crave questions. There&#8217;s nothing worse than finishing your conference talk with &#8220;and now I&#8217;ll take any questions!&#8221; only to get blank stares and silence. Questions from your audience show they were listening to your words, and your ideas resonated, or at least got them thinking.</p><p>Please challenge your conference speakers, but do it for the right reasons.</p><p>Don&#8217;t be <strong>Conference Question Guy</strong>. Everyone hates that guy.</p><div><hr></div><h4>Feedback</h4><p>Send Feedback to matt(at)threatswithoutborders.com</p><div><hr></div><h4>dfir</h4><p>Steve Whalen from Sumuri digs into Mac metadata.  <a href="https://sumuri.com/what-your-mac-forensic-tool-isnt-telling-you-about-metadata/">https://sumuri.com/what-your-mac-forensic-tool-isnt-telling-you-about-metadata/</a></p><div><hr></div><p style="text-align: center;">No subscription fees.  No ads.  No sponsored posts.  Even the snark is free. </p><p style="text-align: center;">How about helping us grow? </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>Cool Jobs</h4><p>Director of Risk and Payment Options, BetMGM.  <a href="https://betmgminc.wd5.myworkdayjobs.com/en-US/BetMGM/job/Director--Risk-and-Payments-Ops_JR100645">https://betmgminc.wd5.myworkdayjobs.com/en-US/BetMGM/job/Director--Risk-and-Payments-Ops_JR100645</a></p><h4>Cool Tools</h4><p>Obtain the results from 100 different search engines with a single search:  <a href="https://www.100searchengines.com/">https://www.100searchengines.com/</a></p><div><hr></div><h4>Irrelevant</h4><p>The end of an era&#8230;Jeve&#8217;s retires as Ask shuts down after 25 years.  <a href="https://www.ask.com/">https://www.ask.com/</a></p><div><hr></div><h4>Sign Off</h4><p>I've likely been the most persistent squeaky voice regarding the locations of the Keystone Connection conferences over the years&#8212;almost as much as my ongoing complaints about the event&#8217;s name. This year, however, Steve Lenderman and his team got it right, hosting the event at a fantastic venue in a prime location. And of course, I won't be able to attend due to other commitments.  </p><p>Anyways&#8230;you should attend.  And you still have time to register!</p><p><a href="https://keystonekonnection.com/">https://keystonekonnection.com/</a></p><p>Matt</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 284]]></title><description><![CDATA[Cyber-Financial Crime Investigation Newsletter, week ending April 26, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-284</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-284</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 28 Apr 2026 10:30:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Gviy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73fe6406-6532-4aed-abf9-5fc5eb77311c_1170x2532.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I had a fun conversation this week.  </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Gviy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73fe6406-6532-4aed-abf9-5fc5eb77311c_1170x2532.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Gviy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73fe6406-6532-4aed-abf9-5fc5eb77311c_1170x2532.png 424w, https://substackcdn.com/image/fetch/$s_!Gviy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73fe6406-6532-4aed-abf9-5fc5eb77311c_1170x2532.png 848w, https://substackcdn.com/image/fetch/$s_!Gviy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73fe6406-6532-4aed-abf9-5fc5eb77311c_1170x2532.png 1272w, https://substackcdn.com/image/fetch/$s_!Gviy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73fe6406-6532-4aed-abf9-5fc5eb77311c_1170x2532.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Gviy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73fe6406-6532-4aed-abf9-5fc5eb77311c_1170x2532.png" width="1170" height="2532" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/73fe6406-6532-4aed-abf9-5fc5eb77311c_1170x2532.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cbca72dd-d9b7-432e-814e-d7e09455eabc_1170x2532.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2532,&quot;width&quot;:1170,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:396868,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/195475678?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbca72dd-d9b7-432e-814e-d7e09455eabc_1170x2532.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Gviy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73fe6406-6532-4aed-abf9-5fc5eb77311c_1170x2532.png 424w, https://substackcdn.com/image/fetch/$s_!Gviy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73fe6406-6532-4aed-abf9-5fc5eb77311c_1170x2532.png 848w, https://substackcdn.com/image/fetch/$s_!Gviy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73fe6406-6532-4aed-abf9-5fc5eb77311c_1170x2532.png 1272w, https://substackcdn.com/image/fetch/$s_!Gviy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73fe6406-6532-4aed-abf9-5fc5eb77311c_1170x2532.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It&#8217;s called a cash-flipping scam, and this version has been dressed up with an artificial-intelligence angle to make it sound sophisticated. It isn&#8217;t. But the people running it are smarter than you might think, and the way they&#8217;ve structured it creates some real challenges for victims and investigators.</p><p>The target gets an unsolicited text from a stranger promising easy money. The script goes something like this: send me $25, I&#8217;ll use my AI tool to flip it, and I&#8217;ll send you back $250. Simple, fast, and painless. Of course, the moment the money moves, the scammer either disappears or comes back asking for a little more before the payout arrives. There is no AI. There is no payout. Only fraud.</p><p>The $25 is important because the low dollar amount is not random. It&#8217;s a calculated decision. The people running these scams have figured out something that works in their favor at almost every level of the criminal justice system.</p><p>At $25, most victims are embarrassed, frustrated, and ultimately unwilling to take time out of their day to file a police report over a loss that won&#8217;t even cover their gas to get to the station. And honestly, can you blame them? </p><p>So the <strong>first filter</strong> is self-reporting; most of these never get reported at all.</p><p>The <strong>second filter</strong> is law enforcement. Even when a report is filed, no investigator opens an active investigation into a $25 fraud. The caseload doesn&#8217;t allow for it.</p><p>The <strong>third filter</strong> is the prosecutors. Even if someone handed a DA a complete, airtight case involving a $25 theft by a non-local suspect, no prosecutor would entertain charging, let alone extraditing,  a defendant over such a de minimis loss. The scammers know this. They have built their entire business model around staying below the threshold that triggers a system response.</p><p>Live on the West coast of the country and scam people on the East coast for low dollar amounts... bulletproof.</p><p>What they&#8217;re actually doing is running this scheme at volume. A hundred victims at $25 each is $2,500. A thousand victims is $25,000. The individual loss is invisible to the system, but the aggregate is very real money.</p><p>These scams almost always use peer-to-peer payment apps like Cash App, Venmo, or Zelle, and that choice is deliberate too. P2P transfers are fast, feel casual, and are extremely difficult to reverse once completed. There&#8217;s no effective dispute process, unlike with a credit card. When the money moves, it&#8217;s gone.</p><p>But these accounts don&#8217;t exist in isolation. Cash App accounts must be verified with real identity details, including name, date of birth, and Social Security number. Additionally, they are connected to a real bank account. Somewhere within this chain, there&#8217;s a real person involved. It could be the scammer themselves or a money mule, but in either case, a person is associated with a financial institution that keeps records. Law enforcement with proper legal authority can serve a search warrant on Cash App and the linked bank to access this information (Yeah, I know, don&#8217;t hold your breath). The data is available; the key question is whether pursuing it is worth the effort, and that leads me to the most crucial point.</p><p>A single $25 case will go nowhere. But if you bring a prosecutor a case showing that the same Cash App tag, the same phone number, or the same script was used against 200 victims across multiple jurisdictions, resulting in $5,000 or $50,000 in total losses, that is a different conversation entirely. </p><p>Investigators need to connect with each other early and often. When you see one of these cases, get it into IC3 at ic3.gov and the FTC at reportfraud.ftc.gov immediately and make sure your victims do too. Include the Cash App tag, the phone number, the exact wording of the message, and any transaction IDs. Then reach out laterally&#8212;to investigators in neighboring jurisdictions, to fraud units in other agencies, and to your financial crime information networks. Ask whether anyone else is seeing the same tag or the same number.</p><p>The scammer is betting that each of us will look at $25 and walk away. The way we beat that bet is by refusing to work in silos. The case that can&#8217;t be built by one investigator on one complaint can absolutely be built when ten investigators across five states are looking at the same actor. Aggregate the losses, aggregate the evidence, and suddenly the math changes for everyone.  </p><div><hr></div><h4>The News</h4><p>Tennessee joins Indiana in banning cryptocurrency ATMs.  <a href="https://www.yahoo.com/news/articles/tennessee-becomes-second-state-outlaw-204113466.html">https://www.yahoo.com/news/articles/tennessee-becomes-second-state-outlaw-204113466.html</a></p><p>Toronto Police have arrested and charged three men with 44 offenses following an investigation into the first known use of a mobile SMS blaster device in Canada. This technology mimics cellular towers to intercept phone calls and send fraudulent text messages that appear to come from trusted organizations such as banks, often directing victims to fake websites to steal personal and financial information.  The investigation, called Project Lighthouse, began last November and detected thousands of device connections and over 13 million network disruptions across the Greater Toronto Area. <br><a href="https://torontosun.com/news/local-news/toronto-cops-cybercrime-tool-sms-blaster-spam-phones">https://torontosun.com/news/local-news/toronto-cops-cybercrime-tool-sms-blaster-spam-phones</a></p><p>A man from Baltimore faces charges including wire fraud, mail fraud, aggravated identity theft, theft of government property, and making false statements. As a former Social Security Administration (SSA) customer service representative, he had access to sensitive SSA databases with personally identifiable information of benefit claimants. The indictment reveals that between February and April 2023, he planned and carried out a scheme to defraud the SSA. He fraudulently obtained Supplemental Security Income (SSI) benefits intended for others, using them for himself and his associates. He targeted claimants with mental health diagnoses, modifying their records to include bank accounts he controlled and his residential address, enabling him to divert their SSI payments. Additionally, he altered the benefit payment dates in SSA&#8217;s system, creating back payments in the claimants&#8217; names, and redirected these payments to his accounts.   <a href="https://www.justice.gov/usao-md/pr/former-social-security-administration-worker-charged-disability-funds-theft-scheme">https://www.justice.gov/usao-md/pr/former-social-security-administration-worker-charged-disability-funds-theft-scheme</a></p><p>Holy insider threat! A US special forces soldier was arrested for allegedly betting on the capture of Venezuelan President Nicol&#225;s Maduro, earning $400,000. Prosecutors claim he was involved in planning the mission and used insider information to place the bet.<a href="https://www.cnn.com/2026/04/23/politics/us-special-forces-soldier-arrested-maduro-raid-trade"> https://www.cnn.com/2026/04/23/politics/us-special-forces-soldier-arrested-maduro-raid-trade </a></p><p>It&#8217;s Spy vs. Spy. Apple has introduced a software update for iPhones and iPads to fix a serious bug that let law enforcement recover deleted or expiring messages by accessing cached notification content stored on the device for up to a month. The flaw, revealed when the FBI used forensic tools to retrieve deleted Signal messages, was caused by notifications that kept message content in the OS database even after the messages were deleted. Apple fixed this by making sure notifications marked for deletion are no longer stored unexpectedly. The update has also been applied to older iOS 18 versions to enhance user privacy.  <a href="https://techcrunch.com/2026/04/22/apple-fixes-bug-that-cops-used-to-extract-deleted-chat-messages-from-iphones/">https://techcrunch.com/2026/04/22/apple-fixes-bug-that-cops-used-to-extract-deleted-chat-messages-from-iphones/</a></p><p>Kudos to law enforcement in Pittsburgh, PA, for their successful effort. Over two days, federal, state, and local authorities collaborated in the Pittsburgh area, resulting in the seizure of nine illegal card-skimming devices. This operation potentially prevented over $9 million in fraud losses for the public. The U.S. Secret Service, in coordination with Allegheny County Police, Pittsburgh police, the state attorney general, the U.S. Postal Inspection Service, and the state inspector general, visited 272 locations on Monday and Tuesday. During these visits, they examined 883 point-of-sale terminals, 775 gas pumps, and 170 ATM terminals.  <a href="https://triblive.com/local/secret-service-led-operation-nets-9-credit-card-skimming-devices-in-pittsburgh-area/">https://triblive.com/local/secret-service-led-operation-nets-9-credit-card-skimming-devices-in-pittsburgh-area/</a></p><p>The Talos group reports that phishing has reemerged as the most commonly observed means of gaining initial access, accounting for over a third of their engagements in which initial access could be determined. Phishing has not been the top vector for initial access since Q2 2025. <a href="https://blog.talosintelligence.com/ir-trends-q1-2026/"> https://blog.talosintelligence.com/ir-trends-q1-2026/</a></p><p>ADT confirmed a data breach that resulted on the loss of customer data, including names, contact details, dates of birth, and the last four digits of Social Security numbers. ShinyHunters has claimed to possess 10 million records and threatened to leak them unless a ransom is paid. <a href="https://therecord.media/ADT-data-breach-cyberattack">https://therecord.media/ADT-data-breach-cyberattack</a></p><div><hr></div><h4>Feedback</h4><p>Send Feedback to matt(at)threatswithoutborders.com</p><div><hr></div><h4>Investigations</h4><p>The Supreme Court will hear oral arguments in <em>Chatrie v. United States</em>, a case examining the use of &#8220;geofence warrants&#8221; by law enforcement to obtain location data from tech companies like Google. The case centers on Okello Chatrie, who was convicted of bank robbery after authorities used a geofence warrant to identify his cellphone location near the crime scene. Chatrie argues that the warrant violated the Fourth Amendment by conducting a search without sufficient probable cause and that he had a reasonable expectation of privacy in his location data, which the government should not be able to access without a warrant. The government contends that Chatrie had no such privacy expectation because he voluntarily shared his location data with Google, and that the warrant was not a general search but a targeted request. <br><a href="https://www.scotusblog.com/2026/04/court-to-hear-argument-on-law-enforcements-use-of-geofence-warrants/">https://www.scotusblog.com/2026/04/court-to-hear-argument-on-law-enforcements-use-of-geofence-warrants/</a></p><p>I absolutely endorse this message:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fQlA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefd8c8b3-6180-4b62-93ad-92493066eb0a_1238x562.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fQlA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefd8c8b3-6180-4b62-93ad-92493066eb0a_1238x562.jpeg 424w, https://substackcdn.com/image/fetch/$s_!fQlA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefd8c8b3-6180-4b62-93ad-92493066eb0a_1238x562.jpeg 848w, https://substackcdn.com/image/fetch/$s_!fQlA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefd8c8b3-6180-4b62-93ad-92493066eb0a_1238x562.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!fQlA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefd8c8b3-6180-4b62-93ad-92493066eb0a_1238x562.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fQlA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefd8c8b3-6180-4b62-93ad-92493066eb0a_1238x562.jpeg" width="1238" height="562" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/efd8c8b3-6180-4b62-93ad-92493066eb0a_1238x562.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:562,&quot;width&quot;:1238,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:147685,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/195475678?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefd8c8b3-6180-4b62-93ad-92493066eb0a_1238x562.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fQlA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefd8c8b3-6180-4b62-93ad-92493066eb0a_1238x562.jpeg 424w, https://substackcdn.com/image/fetch/$s_!fQlA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefd8c8b3-6180-4b62-93ad-92493066eb0a_1238x562.jpeg 848w, https://substackcdn.com/image/fetch/$s_!fQlA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefd8c8b3-6180-4b62-93ad-92493066eb0a_1238x562.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!fQlA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefd8c8b3-6180-4b62-93ad-92493066eb0a_1238x562.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>Cool Jobs</h4><p>Manager of Security Awareness and Learning, Vanguard.  <a href="https://vanguard.wd5.myworkdayjobs.com/en-US/vanguard_external/job/Malvern-PA/Manager--Security-Awareness-and-Learning_177094">https://vanguard.wd5.myworkdayjobs.com/en-US/vanguard_external/job/Malvern-PA/Manager--Security-Awareness-and-Learning_177094</a></p><p>Lead Investigator, National Basketball League.  <a href="https://careers.nba.com/job/NBANBAUSJR000581EXTERNALENUS/Lead-Investigator">https://careers.nba.com/job/NBANBAUSJR000581EXTERNALENUS/Lead-Investigator</a></p><h4>Cool Tools</h4><p>&#8220;Upload a screenshot or photo and get clue-based location reasoning in seconds&#8221;.  Probably not.  But it&#8217;s currently free, so give it a try.  <a href="https://reverseimagelocation.com/">https://reverseimagelocation.com/</a></p><p>DorkEye is an advanced automated dorking and OSINT recon tool that leverages DuckDuckGo.  (Fantastic documentation!)  <a href="https://github.com/xPloits3c/DorkEye">https://github.com/xPloits3c/DorkEye</a></p><div><hr></div><h4>Irrelevant</h4><p>Are you an Advil person or a Tylenol person?  Acetaminophen, ibuprofen, and what doctors probably want you to know.  <a href="https://asteriskmag.com/issues/14/the-mystery-in-the-medicine-cabinet">https://asteriskmag.com/issues/14/the-mystery-in-the-medicine-cabinet</a></p><div><hr></div><h4>Sign Off</h4><p>Thanks for reading this far. Recently, Google started blocking email tracking pixels, which Substack relies on to track open rates. Many other email services have also blocked these trackers, and now Google Gmail has joined them. My open rate was already inconsistent due to these controls, and now it&#8217;s completely useless metric. I really don't know how many subscribers read the newsletter each week. So, I&#8217;ll just keep throwing it at the wall and hoping for the best.  </p><p>Matt</p><p>&#8220;THAT SHIT THAT HAPPENED YESTERDAY, HAPPENED YESTERDAY. MOVE ON.&#8221;</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p><p>cybercrime cyficrime financial fraud investigations osint aml cybersecurity </p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 283]]></title><description><![CDATA[Cybercrime Investigation Newsletter, week ending April 19, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-283</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-283</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 21 Apr 2026 10:31:27 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I recently had a question about an IP address that resolved back to &#8220;iCloud Private Relay,&#8221; which is more information than is usually provided, since most of the time addresses just resolve to &#8220;Cloudflare&#8221; or &#8220;Akamai.&#8221; Unfortunately, for most investigations, this also resolves to a roadblock.</p><p>Apple introduced Private Relay as part of iCloud+, and most people think it&#8217;s Apple&#8217;s VPN service.   It isn&#8217;t a VPN. It&#8217;s more accurate to call it a dual-hop proxy. The service is designed to make sure no single entity, not even Apple, knows both who you are and what you&#8217;re looking at. Apple's inclusion in that &#8220;no single entity&#8221; part is either admirable or politically convenient, depending on your level of cynicism.</p><p>When a user browses in Safari with Private Relay enabled, their traffic takes a two-stop detour before reaching its destination. First, it hits an Apple server. Apple sees the user&#8217;s real IP address, but can&#8217;t see where they&#8217;re going because the DNS request is encrypted. The traffic is then handed off to a second relay server operated by a third-party partner like Cloudflare, Akamai, or Fastly. That server knows the destination but has no idea who the user is. The website at the end of that chain sees a generic, temporary IP address shared by potentially thousands of other users in the same general region.</p><p>Nobody has the whole picture. That&#8217;s the whole point.</p><p>Private Relay protects only Safari browsing and encrypts DNS queries on the device. </p><p>It does not protect Third-party browsers like Chrome, Edge, or Firefox.  Instagram, Facebook, email, banking apps, and most other apps on the device are also unprotected. In the absence of some additional masking technology, those will still phone home with the user&#8217;s real IP address.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Cuu0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd6e0e24-51bb-4e0d-94f5-9f3414b75d9b_898x728.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Cuu0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd6e0e24-51bb-4e0d-94f5-9f3414b75d9b_898x728.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Cuu0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd6e0e24-51bb-4e0d-94f5-9f3414b75d9b_898x728.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Cuu0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd6e0e24-51bb-4e0d-94f5-9f3414b75d9b_898x728.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Cuu0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd6e0e24-51bb-4e0d-94f5-9f3414b75d9b_898x728.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Cuu0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd6e0e24-51bb-4e0d-94f5-9f3414b75d9b_898x728.jpeg" width="898" height="728" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fd6e0e24-51bb-4e0d-94f5-9f3414b75d9b_898x728.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:728,&quot;width&quot;:898,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:108029,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/194723683?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd6e0e24-51bb-4e0d-94f5-9f3414b75d9b_898x728.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Cuu0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd6e0e24-51bb-4e0d-94f5-9f3414b75d9b_898x728.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Cuu0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd6e0e24-51bb-4e0d-94f5-9f3414b75d9b_898x728.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Cuu0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd6e0e24-51bb-4e0d-94f5-9f3414b75d9b_898x728.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Cuu0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd6e0e24-51bb-4e0d-94f5-9f3414b75d9b_898x728.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>So when trying to unmask a web browser user, our standard move -- get the IP, search warrant to the ISP, get the subscriber -- hits a wall. The destination logs a relay egress IP shared by thousands of users. The ISP can see the device was connected to Apple, but has no record of which sites were visited. And the relay partner doesn&#8217;t store the incoming Apple IP in a way that ties it to the outgoing destination. Nobody has the full picture. By design.</p><p>There are still some investigative avenues.</p><p>First, Apple publishes a list of all Private Relay egress IP ranges at https://mask-api.icloud.com/egress-ip-ranges.csv. Run any suspicious source IP against that list before spending resources on an ISP subpoena. Know what you&#8217;re dealing with upfront.</p><p>Second, Private Relay only masks the IP and DNS. Browser fingerprinting artifacts such as canvas fingerprinting, screen resolution, and installed fonts can still tie a specific Safari instance to activity across multiple sessions.</p><p>Third, look for cross-app leakage. If your subject used any other app on that same device, such as a different browser, a social media app, or any other service for communication across the Internet, those connections bypassed the relay entirely and may have logged the real IP with those respective servers.</p><p>iCloud Private Relay is a headache, a roadblock for sure, but maybe not a dead end. It breaks the attribution chain rather than eliminating it, but sometimes broken chains can still be put back together.</p><div><hr></div><h4>The News</h4><p>Microsoft explains how to prevent domain compromises through &#8220;predictive shielding&#8221;.  Predictive shielding in Microsoft Defender&#8217;s automatic attack disruption helps prevent the spread of identity-based attacks by acting before stolen credentials are fully exploited. Rather than waiting for malicious activity on an account, it detects early signs of credential exposure, such as high-confidence signals of credential theft, and proactively restricts potentially compromised accounts.  <a href="https://www.microsoft.com/en-us/security/blog/2026/04/17/domain-compromise-predictive-shielding-shut-down-lateral-movement/">https://www.microsoft.com/en-us/security/blog/2026/04/17/domain-compromise-predictive-shielding-shut-down-lateral-movement/</a></p><p>Think you won&#8217;t get bitten by a malicious insider? Cryptocurrency exchange, Kraken, is standing up to extortionists and refusing to pay their ransom demands.  Kraken experienced two extortion attempts stemming from &#8220;inappropriate&#8221; access by support team members, not external breaches. Approximately 2,000 accounts were potentially compromised.  <a href="https://www.blockhead.co/2026/04/14/kraken-refuses-extortion-demands-after-criminal-group-films-internal-systems/">https://www.blockhead.co/2026/04/14/kraken-refuses-extortion-demands-after-criminal-group-films-internal-systems/</a></p><p>I recently shared a report from another threat intel company that claimed Docusign is now the most imitated brand in phishing attacks.  Checkpoint doesn&#8217;t even list them in the top ten.  Regardless, I&#8217;m sure this list is applicable. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rRV4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8fdd743-1e24-441d-a1dc-424b750ef8f3_1878x898.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rRV4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8fdd743-1e24-441d-a1dc-424b750ef8f3_1878x898.jpeg 424w, https://substackcdn.com/image/fetch/$s_!rRV4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8fdd743-1e24-441d-a1dc-424b750ef8f3_1878x898.jpeg 848w, https://substackcdn.com/image/fetch/$s_!rRV4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8fdd743-1e24-441d-a1dc-424b750ef8f3_1878x898.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!rRV4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8fdd743-1e24-441d-a1dc-424b750ef8f3_1878x898.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rRV4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8fdd743-1e24-441d-a1dc-424b750ef8f3_1878x898.jpeg" width="1456" height="696" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f8fdd743-1e24-441d-a1dc-424b750ef8f3_1878x898.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:696,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:117080,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/194723683?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8fdd743-1e24-441d-a1dc-424b750ef8f3_1878x898.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rRV4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8fdd743-1e24-441d-a1dc-424b750ef8f3_1878x898.jpeg 424w, https://substackcdn.com/image/fetch/$s_!rRV4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8fdd743-1e24-441d-a1dc-424b750ef8f3_1878x898.jpeg 848w, https://substackcdn.com/image/fetch/$s_!rRV4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8fdd743-1e24-441d-a1dc-424b750ef8f3_1878x898.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!rRV4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8fdd743-1e24-441d-a1dc-424b750ef8f3_1878x898.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://blog.checkpoint.com/research/the-phishing-paradox-the-worlds-most-trusted-brands-are-cyber-criminals-entry-point-of-choice/">https://blog.checkpoint.com/research/the-phishing-paradox-the-worlds-most-trusted-brands-are-cyber-criminals-entry-point-of-choice/ </a></p><p>So, you want to be a darknet drug lord?  <a href="https://pastebin.com/raw/GrV3uYh5">https://pastebin.com/raw/GrV3uYh5</a></p><p>The TidBITS public Slack group (SlackBITS) is being closed after a social engineering attack where the attacker impersonated author Glenn Fleishman by duplicating his profile and display name, then sent a direct message to another user to trick him into installing the OSX.Odyssey infostealer malware. <a href="https://tidbits.com/2026/04/18/shutting-down-slackbits-after-impersonation-based-malware-attack/">https://tidbits.com/2026/04/18/shutting-down-slackbits-after-impersonation-based-malware-attack/</a></p><p>Wine Fraud - Yep. A 59-year-old UK citizen was sentenced to 10 years in federal prison for orchestrating a $97 million wine fraud scheme. Posing as the CFO of a fictitious company, the man and a co-conspirator deceived over 140 investors worldwide by falsely claiming to broker loans secured by high-value wine collections. In reality, the operation was a Ponzi scheme that used new investor funds to pay fake interest to earlier investors. Of the $97 million collected, only ~$14 million was returned, leaving victims with losses exceeding $83 million.  <a href="https://www.justice.gov/usao-edny/pr/united-kingdom-citizen-sentenced-10-years-prison-97-million-wine-fraud-scheme">https://www.justice.gov/usao-edny/pr/united-kingdom-citizen-sentenced-10-years-prison-97-million-wine-fraud-scheme</a></p><div><hr></div><h4>Feedback</h4><p>Send Feedback to matt(at)threatswithoutborders.com</p><div><hr></div><h4>Losing Argument</h4><p>This is for anyone who denies a connection between the rise in cryptocurrency use for fraud and the proliferation of cryptocurrency ATMs. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EBTn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cc40a83-c80a-4110-aa42-f0c71a063ef0_1242x714.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EBTn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cc40a83-c80a-4110-aa42-f0c71a063ef0_1242x714.jpeg 424w, https://substackcdn.com/image/fetch/$s_!EBTn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cc40a83-c80a-4110-aa42-f0c71a063ef0_1242x714.jpeg 848w, https://substackcdn.com/image/fetch/$s_!EBTn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cc40a83-c80a-4110-aa42-f0c71a063ef0_1242x714.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!EBTn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cc40a83-c80a-4110-aa42-f0c71a063ef0_1242x714.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EBTn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cc40a83-c80a-4110-aa42-f0c71a063ef0_1242x714.jpeg" width="1242" height="714" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6cc40a83-c80a-4110-aa42-f0c71a063ef0_1242x714.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:714,&quot;width&quot;:1242,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:278139,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/194723683?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cc40a83-c80a-4110-aa42-f0c71a063ef0_1242x714.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!EBTn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cc40a83-c80a-4110-aa42-f0c71a063ef0_1242x714.jpeg 424w, https://substackcdn.com/image/fetch/$s_!EBTn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cc40a83-c80a-4110-aa42-f0c71a063ef0_1242x714.jpeg 848w, https://substackcdn.com/image/fetch/$s_!EBTn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cc40a83-c80a-4110-aa42-f0c71a063ef0_1242x714.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!EBTn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cc40a83-c80a-4110-aa42-f0c71a063ef0_1242x714.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Cryptocurrency complaints were relatively flat until the first jump in 2021.  And then it skyrockets over the next four years.  </p><p>And sure enough, the Gemini tells us there was a huge influx, or &#8220;Hyper Saturation,&#8221; of machines beginning in 2021.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZYQC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b45c99-2dba-41c2-a09e-8d0ba96ffc5e_1248x670.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZYQC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b45c99-2dba-41c2-a09e-8d0ba96ffc5e_1248x670.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZYQC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b45c99-2dba-41c2-a09e-8d0ba96ffc5e_1248x670.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZYQC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b45c99-2dba-41c2-a09e-8d0ba96ffc5e_1248x670.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZYQC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b45c99-2dba-41c2-a09e-8d0ba96ffc5e_1248x670.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZYQC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b45c99-2dba-41c2-a09e-8d0ba96ffc5e_1248x670.jpeg" width="1248" height="670" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f8b45c99-2dba-41c2-a09e-8d0ba96ffc5e_1248x670.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:670,&quot;width&quot;:1248,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:114823,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/194723683?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b45c99-2dba-41c2-a09e-8d0ba96ffc5e_1248x670.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZYQC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b45c99-2dba-41c2-a09e-8d0ba96ffc5e_1248x670.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZYQC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b45c99-2dba-41c2-a09e-8d0ba96ffc5e_1248x670.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZYQC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b45c99-2dba-41c2-a09e-8d0ba96ffc5e_1248x670.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZYQC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b45c99-2dba-41c2-a09e-8d0ba96ffc5e_1248x670.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>Cool Jobs</h4><p>Director of IT Security - Denver Broncos Football Team.  h<a href="https://job-boards.greenhouse.io/denverbroncosteamllc/jobs/5191274008">ttps://job-boards.greenhouse.io/denverbroncosteamllc/jobs/5191274008</a></p><h4>Cool Tools</h4><p>Those who attended my recent talk on quickly triaging websites to determine legitimacy or attribution know that Whois has been replaced by RDAP.  The name changed, but the data remains the same.  And you might need to go back in history to find out not Who Is, but Who Was!  ARIN&#8217;s WhoWas service provides historical registration information for IP addresses and ASNs.  (Registration required)  <a href="https://www.arin.net/reference/research/whowas/">https://www.arin.net/reference/research/whowas/</a></p><div><hr></div><h4>Irrelevant</h4><p>Claude can&#8217;t use a typewriter.  College instructor turns to old school typewriters to curb the use of AI for assignments. </p><blockquote><p>&#8220;What&#8217;s the point of me reading it if it&#8217;s already correct anyway, and you didn&#8217;t write it yourself? Could you produce it without your computer?&#8221; said Phelps.</p></blockquote><p> <a href="https://sentinelcolorado.com/uncategorized/a-college-instructor-turns-to-typewriters-to-curb-ai-written-work-and-teach-life-lessons/">https://sentinelcolorado.com/uncategorized/a-college-instructor-turns-to-typewriters-to-curb-ai-written-work-and-teach-life-lessons/</a></p><div><hr></div><h4>Sign Off</h4><p>I&#8217;ve come to the realization that I&#8217;m a domain hoarder. Domain-rich but cash-poor, I guess.  Every time I think of an awesome web domain name, I purchase it, usually with the idea of starting a business someday. But that never happens, and I just keep paying the yearly domain registration fees. It&#8217;s become expensive enough that I&#8217;ve come to a reckoning. I need to give up some, but it feels like giving up on ideas.  </p><p>Oh, that&#8217;s a great name&#8230;domainhoarder.com!</p><p>Have a great week.  See you all next Tuesday.</p><p>Matt</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p><p>cybercrime cybersecurity cyficime cyber fraud investigations aml osint  </p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 282]]></title><description><![CDATA[Cybersecurity Investigation Newsletter - week ending April 12, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-282</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-282</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 14 Apr 2026 11:49:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I generally enjoy AI tools and have found many uses for them. However, it can definitely be a joy killer.</p><p>One of my favorite yearly events is the release of the IC3 Internet Crime Report. I love diving into it to uncover insights that often go unnoticed by most. I call these insights 'nuggets,' a term familiar to regular newsletter readers. This year, things were different. The report was published on Monday afternoon, and within a few hours, I saw detailed analyses appearing on LinkedIn and X. Gary Warner, David Maimon, and a very few others in our field can craft such perfect summaries in just 90 minutes. For everyone else... It&#8217;s likely that a well-designed AI prompt played a significant role in generating many of those impressive analyses.</p><p>And that&#8217;s OK. It&#8217;s one of the things AI does best, breaking down long, complex, highly dense PDFs into something more digestible. </p><p>I&#8217;m not mad about it.  But I am selfishly disappointed.  </p><p>The proliferation of AI-generated analysis takes a little bit of the joy away from those of us who really love doing that type of work&#8230; old-school. And it renders us afterthoughts because by the time we get around to producing something worth publishing, every cybersecurity content mill has already flooded the zone with AI-created &#8220;hot-takes&#8221;.</p><p>I&#8217;m sure you&#8217;ve seen the highlights by now. But you really should take the time to actually read the report yourself.</p><p><a href="https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf">https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf</a></p><div><hr></div><h4>I can&#8217;t help myself&#8230; consider this nugget</h4><p>It is well known that most victims do not report their victimization and subsequent losses to any authorities, let alone the Internet Crime Complaint Center. In the 2025 report, the IC3 explicitly states that its figures only represent reports to the FBI via IC3 and do not account for other reporting channels. They also acknowledge that missing data and underreporting can result in &#8220;artificially low&#8221; loss estimates. However, they make no assumptions beyond this.</p><p>In contrast, the recent &#8220;<a href="https://www.ftc.gov/system/files/ftc_gov/pdf/P144400-OlderAdultsReportDec2025.pdf">Protecting Older Consumers 2024-2025</a>&#8221; report by the Federal Trade Commission clearly states, &#8220;we assume Sentinel includes only 2% of all losses from consumers who lost under $1,000 and 6.7% of all losses from consumers who lost $1,000 or more.&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6G5e!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5635b5c5-11ce-47f1-8910-4c705b8fcc6a_1326x148.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6G5e!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5635b5c5-11ce-47f1-8910-4c705b8fcc6a_1326x148.jpeg 424w, https://substackcdn.com/image/fetch/$s_!6G5e!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5635b5c5-11ce-47f1-8910-4c705b8fcc6a_1326x148.jpeg 848w, https://substackcdn.com/image/fetch/$s_!6G5e!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5635b5c5-11ce-47f1-8910-4c705b8fcc6a_1326x148.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!6G5e!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5635b5c5-11ce-47f1-8910-4c705b8fcc6a_1326x148.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6G5e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5635b5c5-11ce-47f1-8910-4c705b8fcc6a_1326x148.jpeg" width="1326" height="148" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5635b5c5-11ce-47f1-8910-4c705b8fcc6a_1326x148.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:148,&quot;width&quot;:1326,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:75162,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/193960442?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5635b5c5-11ce-47f1-8910-4c705b8fcc6a_1326x148.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6G5e!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5635b5c5-11ce-47f1-8910-4c705b8fcc6a_1326x148.jpeg 424w, https://substackcdn.com/image/fetch/$s_!6G5e!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5635b5c5-11ce-47f1-8910-4c705b8fcc6a_1326x148.jpeg 848w, https://substackcdn.com/image/fetch/$s_!6G5e!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5635b5c5-11ce-47f1-8910-4c705b8fcc6a_1326x148.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!6G5e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5635b5c5-11ce-47f1-8910-4c705b8fcc6a_1326x148.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Page 28 for reference.  </p><p>So the FTC &#8220;officially&#8221; assumes its reporting rate is somewhere between 2% and 7%.</p><p>Maybe IC3 is better known, and people are more inclined to report their victimization to them because it&#8217;s a division of the FBI. But can it be that much higher? Maybe a 15% reporting rate?</p><p>The IC3 reports that the total loss from Internet-enabled fraud in 2025 is $ 20.8 billion.</p><p>Imagine if that is only 15% of the true loss. What if it&#8217;s only 2-7%?</p><div><hr></div><h4>Speaking of AI tools&#8230;</h4><p>The cybersecurity world is going through a mind melt over the release, and potential public release, of &#8220;Mythos&#8221;.  </p><p>Anthropic&#8217;s Mythos is a highly advanced AI model focused on cybersecurity, particularly on identifying and analyzing software vulnerabilities.</p><p>Mythos finds exploitable vulnerabilities in software, systems, and networks at scale.</p><p>Think of a house. Every window, door, and air vent is a vulnerability that allows unwanted people to get into the house. We use security measures such as locks, shatterproof glass, reverse hinges, and other safeguards to ensure those vulnerabilities are secure and that only authorized people can enter and exit through them. Mythos finds that one window with a finicky lock, where, if you push a specific-style butter knife between the upper and lower panes, you can just reach the lock lever and pop it. And then it explains what materials you need and provides complete instructions on how to do it.</p><p>So does this mean the end of the vulnerability researcher? Are security companies specializing in this all going to go out of business? Maybe, maybe not. It will come down to cost.</p><p>Running these AI models isn&#8217;t free. While ChatGPT can generate some AI slop for your LinkedIn Hero account at no cost, operating a system that scans a corporate network and compares it against a comprehensive bug library requires substantial computation power, which will incur significant token costs.</p><p>And someone needs to pay real money for that usage. The impact of Mythos on the cybersecurity profession will, as with everything else, come down to economics. If the machine becomes more efficient and less expensive than a human, then we&#8217;ll see movement. But I don&#8217;t see that happening in the near future.</p><p>And I think maybe just the opposite.</p><p>So, a team at Anthropic created this model. Do you really think that China, Russia, North Korea, Iran, and other well-funded nation-state cyber teams won&#8217;t swiftly develop similar capabilities?</p><p>Certainly, and cybersecurity experts will continue to be essential in patching the vulnerabilities before these nation-states and criminal groups can exploit them.</p><p>Should your child still go to college for Cybersecurity? Meh, it&#8217;s still better than Journalism, but I don&#8217;t think tools like Mythos will be the immediate downfall of the entire field.</p><div><hr></div><h4>The News</h4><p>Do you use plugins on your WordPress site?  Someone purchased 30 different plugins and planted backdoors in each.  This author argues &#8220;the WordPress plug-in market has a trust issue.&#8221;  And further claims that <em>WordPress.org has no mechanism to flag or review plugin ownership transfers. There is no &#8220;change of control&#8221; notification to users. No additional code review triggered by a new committer. The Plugins Team responded quickly once the attack was discovered. But 8 months passed between the backdoor being planted and being caught.</em> <a href="https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/">https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/</a></p><p>The Financial Crimes Enforcement Network (FinCEN) has proposed a new rule to reform how financial institutions manage their anti-money laundering (AML) and counter-terrorism financing (CFT) programs under the Bank Secrecy Act. The reform aims to shift the focus from high-volume paperwork compliance to risk-based, effective programs that actually combat illicit finance, while reducing regulatory burden on banks. Maybe, I won&#8217;t hold my breath.  <a href="https://www.fincen.gov/news/news-releases/fincen-proposes-rule-fundamentally-reform-financial-institution-programs">https://www.fincen.gov/news/news-releases/fincen-proposes-rule-fundamentally-reform-financial-institution-programs</a></p><p>The FBI successfully recovered deleted Signal messages from a suspect&#8217;s iPhone by extracting data from the device&#8217;s internal notification storage, even after the Signal app had been removed. This was possible because the defendant had not enabled Signal&#8217;s setting to hide message content from notifications, allowing the full text to be cached locally by iOS. However, Apple recently changed how iOS 26.4 validates push notification tokens, so this method may no longer work.   <a href="https://9to5mac.com/2026/04/09/fbi-used-iphone-notification-data-to-retrieve-deleted-signal-messages/">https://9to5mac.com/2026/04/09/fbi-used-iphone-notification-data-to-retrieve-deleted-signal-messages/ </a></p><p>The CIA is increasingly deploying artificial intelligence to enhance its core intelligence analysis mission. The agency has already produced its first autonomous intelligence report and plans to integrate AI &#8220;co-workers&#8221; across all of its analytic platforms within the next few years to help analysts with tasks such as drafting assessments, testing conclusions, and identifying trends. The agency claims humans will remain responsible for key decisions, but it also noted that it tested 300 AI projects last year and is working to bring AI capabilities to field officers. <a href="https://www.politico.com/news/2026/04/09/cia-ai-intelligence-analysis-00865893">https://www.politico.com/news/2026/04/09/cia-ai-intelligence-analysis-00865893</a></p><p>The first step a skilled attacker takes after gaining unauthorized access to a Microsoft 365 account is to abuse mailbox rules. Rather than deploying malware, they use native M365 features to create rules that automatically forward, hide, delete, or archive emails, enabling covert data exfiltration, suppressing security alerts, and maintaining persistence even after password changes. Proofpoint explains that these rules can be deployed in as little as 5 seconds after compromise and can be fully automated at scale via the Microsoft Graph API. <a href="https://www.proofpoint.com/us/blog/threat-insight/mailbox-rules-o365-post-exploitation-tactic-cloud-ato">https://www.proofpoint.com/us/blog/threat-insight/mailbox-rules-o365-post-exploitation-tactic-cloud-ato</a></p><p>Don&#8217;t end up on the &#8220;Sucker List&#8221;.  <a href="https://www.welivesecurity.com/en/scams/recovery-scammers-hit-when-down-avoid-second-strike/">https://www.welivesecurity.com/en/scams/recovery-scammers-hit-when-down-avoid-second-strike/</a></p><div><hr></div><h4>Feedback</h4><p>Send Feedback to matt(at)threatswithoutborders.com</p><div><hr></div><h4>Evidence</h4><p>Why screenshots fail in court.  <a href="https://lucidtruthtechnologies.com/authenticate-social-media-evidence/">https://lucidtruthtechnologies.com/authenticate-social-media-evidence/</a></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>Cool Jobs</h4><p>Security Operations Associate - National Football League.  <a href="https://job-boards.greenhouse.io/nflcareers/jobs/5127529008">https://job-boards.greenhouse.io/nflcareers/jobs/5127529008</a></p><p>Why MLB?  Why are you still making people work in New York City?  Ugh.  Incident Response and Intel Analyst, Major League Baseball.  <a href="https://hub.globalsportsjobs.com/vacancy/incident-response-intel-analyst-us-glap119784">https://hub.globalsportsjobs.com/vacancy/incident-response-intel-analyst-us-glap119784 </a></p><h4>Cool Tools</h4><p>2026 DIY Opt-Out Manual For Removal From Over 400 Sites.  <a href="https://github.com/thumpersecure/opt-out-manual-2026">https://github.com/thumpersecure/opt-out-manual-2026</a></p><p>Little Snitch (iykyk) but for Linux.  <a href="https://obdev.at/products/littlesnitch-linux/index.html">https://obdev.at/products/littlesnitch-linux/index.html</a></p><div><hr></div><h4>Irrelevant</h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KdhA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed7a14a8-0eb5-47ee-9f00-819df36ebe84_1330x760.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KdhA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed7a14a8-0eb5-47ee-9f00-819df36ebe84_1330x760.jpeg 424w, https://substackcdn.com/image/fetch/$s_!KdhA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed7a14a8-0eb5-47ee-9f00-819df36ebe84_1330x760.jpeg 848w, https://substackcdn.com/image/fetch/$s_!KdhA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed7a14a8-0eb5-47ee-9f00-819df36ebe84_1330x760.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!KdhA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed7a14a8-0eb5-47ee-9f00-819df36ebe84_1330x760.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KdhA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed7a14a8-0eb5-47ee-9f00-819df36ebe84_1330x760.jpeg" width="1330" height="760" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ed7a14a8-0eb5-47ee-9f00-819df36ebe84_1330x760.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:760,&quot;width&quot;:1330,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:122816,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/193960442?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed7a14a8-0eb5-47ee-9f00-819df36ebe84_1330x760.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KdhA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed7a14a8-0eb5-47ee-9f00-819df36ebe84_1330x760.jpeg 424w, https://substackcdn.com/image/fetch/$s_!KdhA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed7a14a8-0eb5-47ee-9f00-819df36ebe84_1330x760.jpeg 848w, https://substackcdn.com/image/fetch/$s_!KdhA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed7a14a8-0eb5-47ee-9f00-819df36ebe84_1330x760.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!KdhA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed7a14a8-0eb5-47ee-9f00-819df36ebe84_1330x760.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h4>Sign Off</h4><p>I thought I wrote a pretty good newsletter last week, but I somehow finished the week with fewer subscribers than I started with. Tough crowd. I sincerely appreciate everyone who stays with me.</p><p>Enjoy the warmer weather! Those of you in the Midwest should stay in your storm cellars. I&#8217;ll see you all next week.  </p><p>Matt</p><p>&#8220;IT TAKES LESS TIME TO DO A THING RIGHT THAN TO EXPLAIN WHY YOU DID IT WRONG.&#8221;</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 281]]></title><description><![CDATA[Cybercrime Investigation Newsletter, week ending April 5, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-281</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-281</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 07 Apr 2026 10:05:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-qyh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c5132c-9044-4ab4-9d03-393c688aeedf_1508x440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-qyh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c5132c-9044-4ab4-9d03-393c688aeedf_1508x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-qyh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c5132c-9044-4ab4-9d03-393c688aeedf_1508x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-qyh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c5132c-9044-4ab4-9d03-393c688aeedf_1508x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-qyh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c5132c-9044-4ab4-9d03-393c688aeedf_1508x440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-qyh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c5132c-9044-4ab4-9d03-393c688aeedf_1508x440.jpeg" width="1456" height="425" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/26c5132c-9044-4ab4-9d03-393c688aeedf_1508x440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:425,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:102396,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/193308066?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c5132c-9044-4ab4-9d03-393c688aeedf_1508x440.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-qyh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c5132c-9044-4ab4-9d03-393c688aeedf_1508x440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-qyh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c5132c-9044-4ab4-9d03-393c688aeedf_1508x440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-qyh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c5132c-9044-4ab4-9d03-393c688aeedf_1508x440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-qyh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c5132c-9044-4ab4-9d03-393c688aeedf_1508x440.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This was a DTMF attack. And it&#8217;s so damn clever!</p><p>When you press a key on your phone&#8217;s keypad, it generates a specific pair of audio tones. This system is called DTMF, or Dual-Tone Multi-Frequency signaling. Each key, 0 through 9, along with the asterisk and pound, produces a unique combination of two tones that phone systems use to identify what was pressed. It&#8217;s the same technology that lets you &#8220;press 1 for English&#8221; or enter your account number on an automated line. But those tones are just sounds, and anyone on the call with you can hear, record, and decode them.</p><p>That&#8217;s exactly what the scammer did.</p><p>When this Redditor called the balance verification number using three-way calling with the buyer on the line, they entered the card number and PIN using their keypad. Those DTMF tones traveled directly through the call to the scammer&#8217;s end in real time. The scammer either recorded the call or used software to decode the tones as the victim pressed them, translating each beep back into the exact digits entered. Once they had the card number and PIN, they hung up, logged into the gift card issuer&#8217;s website or called the automated line themselves, and drained the balance. The entire process likely took just minutes.</p><p>The technology behind this isn&#8217;t complex. Tools for recording and decoding DTMF tones are readily available and free. However, what made this attack so effective wasn&#8217;t the technology; it was the social engineering. The scammer didn&#8217;t hack anything; they simply created a situation where the victim willingly entered the credentials while they listened. The three-way call seemed like a normal, cooperative action. A buyer wanting to verify a balance before purchasing makes complete sense. That&#8217;s exactly why it succeeded. Social engineering attacks don&#8217;t target systems; they exploit trust.</p><p><a href="https://en.wikipedia.org/wiki/DTMF_signaling">https://en.wikipedia.org/wiki/DTMF_signaling</a></p><p><a href="https://nhollmann.github.io/DTMF-Tool/">https://nhollmann.github.io/DTMF-Tool/</a></p><div><hr></div><h4>Wilmington? </h4><p>Last week, I spoke at the Delaware Fraud Working Group conference in Wilmington, Delaware. What a pleasant event! I&#8217;m disappointed I had another commitment and couldn&#8217;t spend the entire day.</p><p>The host venue at Delaware Technical Community College was fantastic&#8212;truly one of the best places I&#8217;ve spoken at. I was also pleasantly surprised by Wilmington. I&#8217;ve long written off cities like Philadelphia and New York and generally refuse to attend any event hosted there. Heavy traffic, limited parking, panhandlers, dirt, and chaos make the inconveniences and costs too high to justify the effort.  </p><p>Wilmington probably has those issues, but I didn&#8217;t experience them. The drive into the city from the West was smooth, and parking was straightforward and, best of all, free. The only problem I faced was the haze of marijuana smoke in the parking garage stairwell.  </p><p>I&#8217;m not sure whether the DFWG will host next year's event at DelTech, but if you&#8217;re within a reasonable drive, attend.</p><div><hr></div><h4>Reader Mail</h4><p><em>Matt, your take on the Darksword exploit is one of the most balanced I&#8217;ve read. You should push that to a publication with a much wider reach. It&#8217;s genuinely better than most things I&#8217;ve seen in any of the major news outlets. </em> - JohnS</p><p><em>I was an examiner with a 3 letter agency for eight years, and now I work for an incident response firm. I can&#8217;t stress enough how important it is for people to keep their devices updated. We recently had an incident in which the owner of a business was using an iPhone XR running iOS 17.7. How does that happen? It&#8217;s really that simple. Keep your devices on the most recent version, and you eliminate 99.9% of remote exploits. </em>- KS</p><p>See Issue 280 for context.</p><div><hr></div><h4>The News&#8230;</h4><p>David Maimon explains the fraud known as &#8220;Pell Running&#8221; that is crushing the American federal student loan system.  <a href="https://resources.sentilink.com/blog/inside-pell-running-the-federal-student-aid-fraud-congress-is-trying-to-stop">https://resources.sentilink.com/blog/inside-pell-running-the-federal-student-aid-fraud-congress-is-trying-to-stop</a></p><p>AI-generated deepfake audio has raised concerns about the integrity of evidence. With voice cloning tools becoming affordable and widely available, it&#8217;s now simple to produce realistic fake audio recordings of voicemails, calls, or confessions that can be used as evidence in legal proceedings, insurance claims, or business disagreements. <a href="https://www.forbes.com/sites/larsdaniel/2026/03/15/beyond-cybersecurity-deepfake-audio-is-an-evidence-crisis/">https://www.forbes.com/sites/larsdaniel/2026/03/15/beyond-cybersecurity-deepfake-audio-is-an-evidence-crisis/</a></p><p>It&#8217;s tax season and that means tax scam season. Proofpoint has identified over 100 malicious campaigns using tax-themed lures to deliver malware, Remote Monitoring &amp; Management tools, credential phishing, and fraud. <a href="https://www.proofpoint.com/us/blog/threat-insight/security-brief-tax-scams-aim-steal-funds-taxpayers">https://www.proofpoint.com/us/blog/threat-insight/security-brief-tax-scams-aim-steal-funds-taxpayers</a></p><p>A recently identified phishing-as-a-service platform is targeting C-suite executives using highly personalized, QR-code-based emails that impersonate SharePoint notifications. These emails bypass detection using techniques such as randomized HTML noise, fake email threads, and Unicode QR codes that evade image scanners. When scanned, victims are led through a multi-layered &#8220;gate&#8221; that prevents automated tools and researchers from proceeding, before being redirected to credential harvesters. More worrisome, the exploit functions within Microsoft&#8217;s authentication system, making traditional MFA ineffective as a key line of defense.  <a href="https://abnormal.ai/blog/venom-phishing-campaign-mfa-credential-theft">https://abnormal.ai/blog/venom-phishing-campaign-mfa-credential-theft</a></p><p>I currently hold two SANS/GIAC certifications and recently let a third (GSEC) expire. The exams and their preparation are quite demanding. The crucial aspect is really the preparation process itself. Although the exams are open book, spending too much time looking up answers will result in you running out of time. You will need to look up some answers quickly, and this is where the index becomes essential. Here is a good take on creating an effective index.  <a href="https://aerobytes.io/writeups/giac-indexing-guide/">https://aerobytes.io/writeups/giac-indexing-guide/</a></p><p>Two individuals have pleaded guilty in federal court in Rhode Island for their roles in a transnational fraud and money laundering scheme targeting elderly victims across the U.S. and Canada. The scheme involved fraudsters posing as representatives of financial institutions and government agencies, such as the FTC and the Federal Reserve, convincing victims that their accounts were compromised and directing them to transfer funds via wire transfers, cryptocurrency, cash, or gold bars. The scheme defrauded approximately 300 victims across 37 states, with known losses exceeding $5 million. <a href="https://www.justice.gov/usao-ri/pr/two-defendants-plead-guilty-transnational-fraud-scheme-targeting-elderly-victims">https://www.justice.gov/usao-ri/pr/two-defendants-plead-guilty-transnational-fraud-scheme-targeting-elderly-victims</a></p><p>Uno is a good boy.  <a href="https://cdapress.com/news/2026/apr/01/coffee-with-a-k9/">https://cdapress.com/news/2026/apr/01/coffee-with-a-k9/</a></p><div><hr></div><h4>DFIR</h4><p>Tsurugi Linux released update version 26.03 on iso or ova.  <a href="https://tsurugi-linux.org/downloads.php">https://tsurugi-linux.org/downloads.php</a></p><div><hr></div><h4>Cool Tools</h4><p>FTC Sentinel Fraud Dashboard.  <a href="https://public.tableau.com/app/profile/federal.trade.commission/viz/FraudReports/FraudFacts">https://public.tableau.com/app/profile/federal.trade.commission/viz/FraudReports/FraudFacts</a></p><p>Who is giving money to whom?  <a href="https://www.opensecrets.org/">https://www.opensecrets.org/</a></p><h4>Cool Job</h4><p>Card Fraud Manager, Members 1st Federal Credit Union.  <a href="https://careers.members1st.org/jobs/2682/Card%20Fraud%20Manager">https://careers.members1st.org/jobs/2682/Card%20Fraud%20Manager</a></p><p>Vice President of Consumer and Banking Fraud Strategy. JP Morgan Chase <a href="https://jpmc.fa.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1001/job/210699592">https://jpmc.fa.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1001/job/210699592</a></p><div><hr></div><h4>Irrelevant</h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ivhR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa064f124-1173-457e-a0ce-40df43c53d77_1340x1288.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ivhR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa064f124-1173-457e-a0ce-40df43c53d77_1340x1288.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ivhR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa064f124-1173-457e-a0ce-40df43c53d77_1340x1288.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ivhR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa064f124-1173-457e-a0ce-40df43c53d77_1340x1288.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ivhR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa064f124-1173-457e-a0ce-40df43c53d77_1340x1288.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ivhR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa064f124-1173-457e-a0ce-40df43c53d77_1340x1288.jpeg" width="1340" height="1288" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a064f124-1173-457e-a0ce-40df43c53d77_1340x1288.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1288,&quot;width&quot;:1340,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:333897,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/193308066?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa064f124-1173-457e-a0ce-40df43c53d77_1340x1288.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ivhR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa064f124-1173-457e-a0ce-40df43c53d77_1340x1288.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ivhR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa064f124-1173-457e-a0ce-40df43c53d77_1340x1288.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ivhR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa064f124-1173-457e-a0ce-40df43c53d77_1340x1288.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ivhR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa064f124-1173-457e-a0ce-40df43c53d77_1340x1288.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Credit: Varun.ch</p><div><hr></div><h4>Feedback</h4><p>matt (at) threatswithoutborders.com</p><div><hr></div><h4>Sign Off</h4><p>Wow, a lot of new subscribers this week. </p><p>So, what&#8217;s this all about? See that issue number, 281&#8212;that&#8217;s how many consecutive weeks the Threats Without Borders Newsletter has been published. Yep, every Tuesday morning for five years and four months. Never a miss. What I lack in quality, substance, and style, I make up for in tenacity.  </p><p>Welcome.  And when your email provider drops the newsletter or your company decides newsletters are a time-suck and creates a &#8220;unsubscribe and delete&#8221; rule, you can always find every issue published at www.threatswithoutborders.com.</p><p>Or install the Substack app on your smartphone and ensure delivery each week.  </p><div class="install-substack-app-embed install-substack-app-embed-web" data-component-name="InstallSubstackAppToDOM"><img class="install-substack-app-embed-img" src="https://substackcdn.com/image/fetch/$s_!lkkz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07f3f957-f680-4ee2-b274-e8ca2ac66a24_600x600.png"><div class="install-substack-app-embed-text"><div class="install-substack-app-header">Get more from Matt Dotts in the Substack app</div><div class="install-substack-app-text">Available for iOS and Android</div></div><a href="https://substack.com/app/app-store-redirect?utm_campaign=app-marketing&amp;utm_content=author-post-insert&amp;utm_source=cyficrime" target="_blank" class="install-substack-app-embed-link"><button class="install-substack-app-embed-btn button primary">Get the app</button></a></div><p>Thanks for checking us out and I hope to see you all next week.  </p><p>Matt</p><p>&#8220;DON&#8217;T LET A BAD DAY MAKE YOU FEEL LIKE YOU HAVE A BAD LIFE.&#8221;</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 280]]></title><description><![CDATA[Cybercrime Investigation Newsletter, week ending March 29, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-280</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-280</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 31 Mar 2026 10:46:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A few weeks ago, I addressed a concern in this space about Apple iPhone users claiming, &#8220;Wasn&#8217;t me, my phone was hacked.&#8221; My response was straightforward: unless they are a direct target of a nation-state, the iPhone was not secretly compromised.</p><p>Well... news recently broke about an iPhone exploit called Darksword, and it has me reevaluating my stance on the issue.    </p><h4><strong>Yes, your iPhone can be hacked; no, you&#8217;re probably not interesting enough to justify the price tag.</strong></h4><p>That tension, between what&#8217;s possible and what&#8217;s probable, is getting lost in the conversation around advanced mobile exploits like DarkSword. Headlines and social media chatter tend to flatten everything into the same message: your phone is vulnerable at any time. Technically, that&#8217;s true. Practically, it&#8217;s sensational trash.</p><p>DarkSword isn&#8217;t a typical piece of malware you download or install. It&#8217;s an exploit chain, a carefully engineered sequence of vulnerabilities that allows an attacker to break into an iPhone, escalate privileges, and extract data. It&#8217;s not a virus but a master key that unlocks multiple doors in sequence. Once inside, it can deploy tools to collect messages, access apps, or monitor activity, often without leaving much evidence behind.</p><p>That kind of capability has not just been rare, but elite. Building something like this requires deep expertise, time, and significant financial investment. For years, these tools were almost exclusively in the hands of nation-states and a small number of highly specialized surveillance vendors. And because they were so valuable, they were used sparingly, against very specific, high-value targets.</p><h4>The ceiling hasn&#8217;t changed. These are still highly sophisticated, expensive, and complex attacks. But the floor has dropped.</h4><p>The challenge of developing these capabilities remains very high, but the difficulty of accessing them is decreasing. We&#8217;re observing the same trend that has occurred in other areas of cybercrime. There was a time when launching a ransomware attack required significant technical skill. Now, ransomware-as-a-service has made it much more accessible. The expertise hasn&#8217;t disappeared; it has been packaged, productized, and distributed.</p><p>Bad guys who previously could not develop an iPhone exploit chain can now sometimes access or lease that capability. This doesn&#8217;t mean &#8220;anyone&#8221; can do it, but it does expand the pool of potential attackers. It&#8217;s no longer limited to intelligence agencies and top-tier operators; it may now include smaller governments, private intelligence firms, and well-funded criminal groups. </p><p>Yes, it is now more possible for a broader range of attackers to use these tools. No, it is still not probable that they will be used against the average person.</p><p>There are a few reasons for that.</p><p><strong>First, these exploits remain costly assets.</strong> Even as access becomes more available, it&#8217;s not free or simple. Using one involves risk for the attacker. Each deployment raises the likelihood that the exploit will be discovered, analyzed, and patched. Burning a valuable capability on a random target offers little economic or operational benefit.</p><p><strong>Second, these attacks still require targeting.</strong> Even a &#8220;one-click&#8221; exploit&#8212;where a user simply taps a link&#8212;relies on getting that link in front of the right person at the right time. That involves reconnaissance, delivery methods, and often some level of social engineering. This is not spray-and-pray activity. It&#8217;s intentional.</p><p><strong>Third, and what I&#8217;ve been saying for a long time, is that there are far easier ways to compromise people.</strong></p><p>Most cybercriminals don&#8217;t need a complicated exploit chain to succeed. Phishing emails, fake login pages, password reuse, SIM swapping, and social engineering are much cheaper and easier to scale. If they aim for financial gain, these methods provide a higher return on investment. Why invest heavily in a complex iPhone exploit when a convincing text message can trick someone into giving up their credentials?</p><p>This is why, for the average iPhone user, the biggest risks remain the same as they were before: scams, phishing, weak passwords, and account takeovers. Not zero-day exploits.</p><p>But that doesn&#8217;t mean nothing has changed.</p><p><strong>The important shift is in who might now be considered &#8220;worth it.&#8221;</strong></p><p>Previously, the range of targets for these attacks was very limited. Now, it has expanded, not to include everyone, but to include more individuals than before. Those now at risk include journalists, business leaders, government workers, activists, and anyone with access to confidential information or financial assets, even if they don&#8217;t operate internationally.</p><p>Additionally, there is a risk of spillover. As these tools become more widely used, there&#8217;s an increased chance of errors&#8212;such as incorrect numbers, misidentified devices, or infrastructure that unintentionally exposes unintended users. This doesn&#8217;t suddenly make everyone a target, but it does add more unpredictability to where these capabilities might be exploited.</p><p><strong>So where does that leave the everyday iPhone user?</strong></p><p><em>The iPhone is not under constant threat from elite hackers. It is not being silently compromised at random. But it is also no longer accurate to assume that these capabilities exist only in distant, highly controlled environments.</em></p><p>Understand that advanced attacks exist. Recognize that they are becoming more accessible to a wider range of actors. But also keep in perspective that attackers are still making decisions based on cost, value, and likelihood of success. Most people simply do not present a target that justifies the use of such a tool. </p><p>And importantly, many of the protections against these advanced threats are straightforward.</p><p><strong>Keeping your iPhone updated is one of the most effective things you can do.</strong> These exploit chains rely on vulnerabilities, and once those vulnerabilities are patched, the window of opportunity closes. Delaying updates means leaving the door open longer than necessary.</p><p>Apple has also introduced built-in protections designed specifically for high-risk scenarios, such as <strong>Lockdown Mode</strong>. While not necessary for most users, it&#8217;s a powerful option for those who may be more likely to be targeted.</p><p>Yes, an iPhone can be hacked.</p><p>But what matters far more is whether it&#8217;s likely - and for most people, it still isn&#8217;t.</p><p>So in your investigations, it&#8217;s something you need to account for&#8230; but probably not.  </p><div><hr></div><h4>Speaking of Lockdown Mode</h4><p>Nearly four years after its 2022 debut, Apple&#8217;s Lockdown Mode remains undefeated by mercenary spyware, with both Apple and independent investigators such as Amnesty International confirming that no devices with the feature activated have been successfully attacked. Citizen Lab researchers have documented instances where Lockdown Mode effectively prevented Pegasus and Predator spyware attacks. <a href="https://techcrunch.com/2026/03/27/apple-says-no-one-using-lockdown-mode-has-been-hacked-with-spyware/">https://techcrunch.com/2026/03/27/apple-says-no-one-using-lockdown-mode-has-been-hacked-with-spyware/</a></p><h4>Skimming Report</h4><p>I&#8217;ll write more about this report, but I just don&#8217;t have the space today.  FICO released the report &#8220;The State of Card Skimming in the US: 2025 Year In Review&#8221;.  <a href="https://www.fico.com/blogs/state-card-skimming-us-2025-year-review">https://www.fico.com/blogs/state-card-skimming-us-2025-year-review</a></p><div><hr></div><h4>Cool Job</h4><p>Data Scientist, Predictive Fraud Intelligence - VISA.  <a href="https://jobs.smartrecruiters.com/Visa/744000117342711-data-scientist-predictive-fraud-intelligence">https://jobs.smartrecruiters.com/Visa/744000117342711-data-scientist-predictive-fraud-intelligence</a></p><p>Fraud Risk Governance Lead - Customers Bank.  <a href="https://customersbank.wd1.myworkdayjobs.com/customersbankcareers/job/Malvern-PA/Fraud-Risk-Governance-Lead_REQ-2026-851">https://customersbank.wd1.myworkdayjobs.com/customersbankcareers/job/Malvern-PA/Fraud-Risk-Governance-Lead_REQ-2026-851</a></p><h4>Cool Tool</h4><p>IRS charity search -  <a href="https://apps.irs.gov/app/eos/">https://apps.irs.gov/app/eos/</a></p><p>How charitable is a charity? Charity Navigator - <a href="https://www.charitynavigator.org/">https://www.charitynavigator.org/</a></p><p>International phone number look-up.  <a href="https://www.thisnumber.com/">https://www.thisnumber.com/</a></p><div><hr></div><h4>Irrelevant</h4><p>The U.S. Army increased its maximum enlistment age to 42. Meh, I&#8217;m still too old, but of course, I couldn't have done it at 42 either. Kudos to anyone over 40 who accepts this challenge!    <a href="https://abcnews.com/Politics/army-extends-maximum-recruitment-age-42-allowing-older/story?id=131411519">https://abcnews.com/Politics/army-extends-maximum-recruitment-age-42-allowing-older/story?id=131411519</a></p><div><hr></div><h4>Sign Off</h4><p>I had to cut the news section today due to space limitations.  It will be back next week. </p><p>Do you know what a DTMF attack is?  Or how they use it to steal the balance from gift cards?  Come back next week to learn more.</p><p>Matt</p><p>&#8220;IF YOU WAIT FOR EVERYTHING TO FALL INTO PLACE BEFORE YOU ACT, YOU WILL NEVER MOVE.&#8221;</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 279]]></title><description><![CDATA[Cybercrime Investigation Newsletter, Week ending March 22, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-279</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-279</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 24 Mar 2026 11:20:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>So many times when we think of &#8220;cybercrime&#8221; or crime facilitated through the use of technology and the Internet, we think of the usual suspects - network intrusions with data theft, ransomware, DDOS attacks, investment and romance scams, email phishing&#8230; or any of the other crimes detailed in the Internet Crime Complaint Center&#8217;s yearly report.  </p><p>Rarely do we ever think of music fraud.  And certainly not music fraud involving AI-created music and a massive botnet that generates millions of &#8220;listens&#8221; across a dozen streaming services.</p><p>A North Carolina man has admitted guilt in a widespread music streaming fraud that occurred from 2017 to 2024. He used AI-generated songs and up to 10,000 bot accounts simultaneously to artificially inflate streaming counts on platforms such as Spotify, Apple Music, Amazon Music, and YouTube Music, resulting in billions of fake streams. To evade detection, he used VPNs and distributed activity across hundreds of thousands of tracks. Through this operation, he generated over $8 million in royalties. </p><p>Posting AI-generated music on streaming services isn&#8217;t illegal. The crime lies in using countless zombie machines to &#8220;listen&#8221; to the music. </p><p>He exploited technology and the Internet to set up a situation where victim businesses paid him money that he didn't legitimately earn.  And 8 million dollars isn&#8217;t chump change.  </p><p>Fraud is as old as time, and most schemes are not new, but the convergence of financial crime and the Internet continually takes us into new territory and pushes the boundaries of &#8220;cybercrime&#8221;.  </p><p><a href="https://www.justice.gov/usao-sdny/pr/north-carolina-man-pleads-guilty-music-streaming-fraud-aided-artificial-intelligence-0">https://www.justice.gov/usao-sdny/pr/north-carolina-man-pleads-guilty-music-streaming-fraud-aided-artificial-intelligence-0</a></p><div><hr></div><h4>Audit PTO </h4><p>When providing fraud-prevention training to business owners and executives, I emphasize the importance of job rotation and mandated paid time off (PTO). </p><p>I often cite an investigation I was involved in where the suspect employee hadn&#8217;t taken any vacation for seven years. Although she took occasional days off around holidays, she never scheduled a full week off during that period. </p><p>She operated a sophisticated refund scheme, funneling refunds into her own accounts, and she knew that anyone who stepped into her role could uncover her fraud. Her eventual exposure came when a new accounting software flagged irregularities during a routine audit. </p><p>Over those seven years, she embezzled more than $200,000 from her employer. </p><p>This case from a Pennsylvania casino is the latest example of an insider executing a scam that could have been quickly uncovered if someone else had briefly stepped into the role. In fact, that&#8217;s precisely how she was caught: </p><blockquote><p><em>When Petrillo was on medical leave, an employee at the casino&#8217;s horse racing office assisted with the office paperwork. Police said that&#8217;s when the employee discovered the discrepancies.</em></p></blockquote><p>At least once a year, every financial role in the organization should be temporarily filled by another person for a few days. This practice not only helps prevent fraud but also enhances redundancy and recovery options. If someone refuses to take a week off, it should be forced. </p><p>An employee who refuses to use their Paid Time Off is a huge red flag&#8230; in more ways than one.</p><p>This employee stole over $700,000.  And it&#8217;s so preventable.</p><p><a href="https://www.pennlive.com/crime/2026/03/hollywood-casino-employee-accused-of-stealing-over-700k-in-fraud-scheme.html">https://www.pennlive.com/crime/2026/03/hollywood-casino-employee-accused-of-stealing-over-700k-in-fraud-scheme.html</a></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>The News&#8230;</h4><p>Holy... we&#8217;re smoked. Although hype for their own product, this article by Sublime Security describes a new attack that masquerades as a Zoom meeting invite but results in the recipient installing malware on their Windows PC. The extent to which the attackers go to pull this off is impressive. They even run a JavaScript-enabled Zoom meeting simulation in the browser session - complete with technical difficulties. Anyone who has ever worked at a Help Desk or in a role involving regular interaction with non-technical users knows this issue will have a significant impact on unsecured organizations that use Zoom.   <a href="https://sublime.security/blog/advanced-fake-zoom-installer-used-for-delivering-malware/">https://sublime.security/blog/advanced-fake-zoom-installer-used-for-delivering-malware/</a></p><p>Keep your iPhone updated, and these exploits will not be so bothersome. In fact, not at all.  The Google Threat Intelligence Group reports the &#8220;DarkSword&#8221; exploit for Apple iPhone devices has been adopted by multiple threat actors since November 2025. The exploit chain uses six zero-day vulnerabilities to fully compromise iOS devices running versions 18.4-18.7.  For the record, you should be on some version of iOS 26, preferably 26.3.1 (at the time of this writing).  <a href="https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain">https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain</a></p><p>SEC will vote on reducing the quarterly reporting requirement to twice a year.  <a href="https://www.reuters.com/business/finance/us-sec-preparing-eliminate-quarterly-reporting-requirement-wsj-says-2026-03-16/">https://www.reuters.com/business/finance/us-sec-preparing-eliminate-quarterly-reporting-requirement-wsj-says-2026-03-16/</a></p><p>Ok, this scam needed to be shut down, but are there actual victims here? Law enforcement authorities from 23 countries carried out *Operation Alice*, a major crackdown on a dark web network run by a 35-year-old in China. Over five years, he operated more than 373,000 fraudulent Tor domains, promoting child sexual abuse material (CSAM) and cybercrime-as-a-service (CaaS). He defrauded around 10,000 customers of over $345,000 in Bitcoin, without ever delivering the promised content. While the sites claimed to offer CSAM &#8220;packages&#8221; ranging from gigabytes to terabytes, they were entirely fake and victims were never supplied with the material.  Europol coordinated international intelligence efforts, tracked cryptocurrency transactions, and helped identify the operator, who used up to 287 servers worldwide. <a href="https://www.europol.europa.eu/media-press/newsroom/news/global-cybercrime-crackdown-over-373-000-dark-web-sites-shut-down">https://www.europol.europa.eu/media-press/newsroom/news/global-cybercrime-crackdown-over-373-000-dark-web-sites-shut-down</a></p><p>Pennsylvania Attorney General Dave Sunday announced that the leader of a criminal organization that defrauded central Pennsylvania banks and their customers of more than $3 million has been sentenced to prison and ordered to pay more than half-a-million dollars in restitution. <a href="https://www.attorneygeneral.gov/taking-action/ringleader-in-multi-million-dollar-central-pa-bank-fraud-scheme-sentenced-to-prison/">https://www.attorneygeneral.gov/taking-action/ringleader-in-multi-million-dollar-central-pa-bank-fraud-scheme-sentenced-to-prison/</a></p><p>Bank and credit union compliance software provider Marquis confirmed that a data breach discovered in August 2025 affected approximately 672,000 individuals, which is much less than the previously estimated 1.6 million. Of course, that doesn&#8217;t make it any better, just less impactful. The attackers stole sensitive personal and financial information, including names, addresses, Social Security numbers, dates of birth, and payment card numbers from dozens of the financial institutions Marquis serves. <a href="https://www.securityweek.com/marquis-data-breach-affects-672000-individuals/">https://www.securityweek.com/marquis-data-breach-affects-672000-individuals/</a></p><div><hr></div><h4>DFIR</h4><p>Andrea Fortuna introduces the DFIR Toolkit.  <a href="https://andreafortuna.org/2026/03/17/dfir-toolkit">https://andreafortuna.org/2026/03/17/dfir-toolkit</a></p><div><hr></div><h4>Cool Job</h4><p>Criminal Intelligence Analyst, Group 9.  <a href="https://groupnine.us/careers/">https://groupnine.us/careers/</a></p><h4>Cool Tool</h4><p>I was a longtime user of Evernote, but left when it was bought by Bending Spoons, and they priced it out of reality. I&#8217;ve since switched to the fantastic notes app Bear, but it's only available on Apple devices. So, for you Windows users still feeling the loss of Evernote - try Cimanote.  &#8220;<em>Cimanote is the fast, clean note-taking app for people tired of Evernote's bloat and price hikes. Sign up today &#8212; your first year is completely on us.&#8221;   </em><a href="https://cimanote.com/">https://cimanote.com/</a></p><div><hr></div><h4>Irrelevant</h4><p>More evidence that not all addictions are bad. This long-term study discovered that moderate intake of caffeinated coffee or tea was associated with an 18% lower risk of dementia and improved cognitive performance over time.  <a href="https://www.sciencedaily.com/releases/2026/03/260318033138.htm">https://www.sciencedaily.com/releases/2026/03/260318033138.htm</a></p><div><hr></div><h4>Get Learned</h4><p>SLEUTHCON is a forum for identifying and exploring cybercrime and financially-motivated threats.  Friday, June 5, 2026.  Arlington, VA and Virtual.  <a href="https://www.sleuthcon.com/">https://www.sleuthcon.com/</a></p><p>Delaware Fraud Working Group, Full-Day Fraud Prevention Summit.  Thursday, April 2, 2026.  Wilmington, DE.  <a href="https://www.eventbrite.com/e/delaware-fraud-working-group-full-day-fraud-prevention-summit-tickets-1982375409213">https://www.eventbrite.com/e/delaware-fraud-working-group-full-day-fraud-prevention-summit-tickets-1982375409213</a></p><div><hr></div><h4>Late Breaking</h4><p>If you think you need a new router, buy one now. The FCC plans to ban all foreign-made routers. While this isn&#8217;t necessarily a bad thing and will certainly benefit the American tech industry, the issue is that nearly every router is made entirely, or at least with parts from, outside the U.S. Once this rule is enforced, American manufacturers won't be able to meet the demand for a long time.  When I searched for American-made routers, the only one I found that is made entirely in the U.S. is Starlink.  Hmm.  Is that a coincidence?    <a href="https://docs.fcc.gov/public/attachments/DOC-420034A1.pdf">https://docs.fcc.gov/public/attachments/DOC-420034A1.pdf</a></p><div><hr></div><h4>Sign Off</h4><p>The best news of the week is that by Friday, the RSAC Conference will be over, and our inboxes will be free from the daily influx of emails from salespeople asking to &#8220;connect&#8221; during the event.  </p><p>Thanks again for opening another issue of the newsletter.  Cheers to sunshine and warmer weather!</p><p>Matt</p><p>&#8220;YOU WILL NEVER START ANYTHING IF YOU ALWAYS WAIT UNTIL YOU ARE FULLY READY.&#8221;</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 278]]></title><description><![CDATA[Cybercrime Investigation Newsletter, week ending March 15, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-278</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-278</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 17 Mar 2026 11:20:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!AwOR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b17363-731f-4ef4-9d3a-1794924e0af3_1268x1424.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><p>I&#8217;m old enough to remember when ATM&#8217;s arrived on the scene.  Of course, we called them &#8220;MAC Machines&#8221;.  I recall a local bank holding a contest to see who could withdraw the most money in a set amount of time to highlight the ease of use.  </p><p>I also remember the concern that such technology raised about the future of banking.  Well, the ATM didn&#8217;t replace the teller.  But as this excellent article highlights, the smartphone is.</p><div class="embedded-post-wrap" data-attrs="{&quot;id&quot;:190553382,&quot;url&quot;:&quot;https://davidoks.blog/p/why-the-atm-didnt-kill-bank-teller&quot;,&quot;publication_id&quot;:4554783,&quot;publication_name&quot;:&quot;David Oks&quot;,&quot;publication_logo_url&quot;:null,&quot;title&quot;:&quot;Why ATMs didn&#8217;t kill bank teller jobs, but the iPhone did&quot;,&quot;truncated_body_text&quot;:&quot;A few months ago, J. D. Vance, sitting vice president of the United States, gave an interview to Ross Douthat of the New York Times. During that interview, Vance and Douthat had an interesting exchange:&quot;,&quot;date&quot;:&quot;2026-03-10T22:29:42.275Z&quot;,&quot;like_count&quot;:1116,&quot;comment_count&quot;:86,&quot;bylines&quot;:[{&quot;id&quot;:2088240,&quot;name&quot;:&quot;David Oks&quot;,&quot;handle&quot;:&quot;doks&quot;,&quot;previous_name&quot;:&quot;Stylite&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/553a38f8-f363-424f-8648-742af2eacc8d_1024x1024.png&quot;,&quot;bio&quot;:&quot;Essays on economics, technology, history&quot;,&quot;profile_set_up_at&quot;:&quot;2021-04-25T15:01:09.752Z&quot;,&quot;reader_installed_at&quot;:&quot;2023-06-18T14:21:19.283Z&quot;,&quot;publicationUsers&quot;:[{&quot;id&quot;:4646174,&quot;user_id&quot;:2088240,&quot;publication_id&quot;:4554783,&quot;role&quot;:&quot;admin&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:true,&quot;publication&quot;:{&quot;id&quot;:4554783,&quot;name&quot;:&quot;David Oks&quot;,&quot;subdomain&quot;:&quot;davidoks&quot;,&quot;custom_domain&quot;:&quot;davidoks.blog&quot;,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;The world is what it is.&quot;,&quot;logo_url&quot;:null,&quot;author_id&quot;:2088240,&quot;primary_user_id&quot;:2088240,&quot;theme_var_background_pop&quot;:&quot;#FF6719&quot;,&quot;created_at&quot;:&quot;2025-03-30T23:49:08.700Z&quot;,&quot;email_from_name&quot;:&quot;David Oks&quot;,&quot;copyright&quot;:&quot;doks&quot;,&quot;founding_plan_name&quot;:&quot;Founding Member&quot;,&quot;community_enabled&quot;:true,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;enabled&quot;,&quot;language&quot;:null,&quot;explicit&quot;:false,&quot;homepage_type&quot;:&quot;newspaper&quot;,&quot;is_personal_mode&quot;:false,&quot;logo_url_wide&quot;:null}}],&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null,&quot;status&quot;:{&quot;bestsellerTier&quot;:null,&quot;subscriberTier&quot;:1,&quot;leaderboard&quot;:null,&quot;vip&quot;:false,&quot;badge&quot;:{&quot;type&quot;:&quot;subscriber&quot;,&quot;tier&quot;:1,&quot;accent_colors&quot;:null},&quot;paidPublicationIds&quot;:[1071360,159185,1063960,1198116],&quot;subscriber&quot;:null}}],&quot;utm_campaign&quot;:null,&quot;belowTheFold&quot;:false,&quot;type&quot;:&quot;newsletter&quot;,&quot;language&quot;:&quot;en&quot;,&quot;source&quot;:null}" data-component-name="EmbeddedPostToDOM"><a class="embedded-post" native="true" href="https://davidoks.blog/p/why-the-atm-didnt-kill-bank-teller?utm_source=substack&amp;utm_campaign=post_embed&amp;utm_medium=web"><div class="embedded-post-header"><span></span><span class="embedded-post-publication-name">David Oks</span></div><div class="embedded-post-title-wrapper"><div class="embedded-post-title">Why ATMs didn&#8217;t kill bank teller jobs, but the iPhone did</div></div><div class="embedded-post-body">A few months ago, J. D. Vance, sitting vice president of the United States, gave an interview to Ross Douthat of the New York Times. During that interview, Vance and Douthat had an interesting exchange&#8230;</div><div class="embedded-post-cta-wrapper"><span class="embedded-post-cta">Read more</span></div><div class="embedded-post-meta">3 months ago &#183; 1116 likes &#183; 86 comments &#183; David Oks</div></a></div><p>And when you combine the smartphone with an ebanking platform and the ATM, you get the perfect fraud workflow.</p><div><hr></div><h4>Proxy takedown</h4><p>Law enforcement from eight countries seized 23 servers and 34 domains, froze $3.5M in crypto, and identified more than 124,000 users. Known as &#8220;SocksEscort&#8221;, the network, powered by the AVRecon botnet, has co-opted more than 369,000 IPs since 2020.  </p><p>This service essentially took control of unsecured residential and business routers and sold access to them. This enabled an attacker to route their malicious Internet traffic through the router in a residential home or (small) business.  </p><p>Untrained investigators often assume that tracing an IP address back to an ISP subscriber indicates that a user physically on the property who connected to the Internet through the router was responsible for the activity. Poor assumption. You must consider the possibility of an infected router being used as a proxy.  </p><p><a href="https://www.justice.gov/usao-edca/pr/authorities-dismantle-global-malicious-proxy-service-deployed-malware-and-defrauded">https://www.justice.gov/usao-edca/pr/authorities-dismantle-global-malicious-proxy-service-deployed-malware-and-defrauded</a></p><p>And not by coincidence, I&#8217;m sure, the Internet Crime Complaint Center (IC3) published a document titled &#8220;Evading Residential Proxy Networks: Protecting Your Devices From Becoming a Tool for Criminals&#8221;.  <a href="https://www.ic3.gov/PSA/2026/PSA260312">https://www.ic3.gov/PSA/2026/PSA260312</a></p><div><hr></div><h4>More News&#8230;</h4><p>This executive order, signed by President Trump, outlines a U.S. government strategy to combat cybercrime, fraud, and predatory schemes targeting American citizens, particularly those orchestrated by transnational criminal organizations (TCOs), sometimes with foreign state support. It directs multiple federal agencies to review and strengthen defenses, establish a coordinated operational cell within the National Coordination Center, enhance victim support through a proposed Victims Restoration Program, and engage internationally to pressure nations that harbor these criminal groups. The order emphasizes law enforcement, diplomacy, and potential offensive actions to disrupt and dismantle these threats.  <a href="https://www.whitehouse.gov/presidential-actions/2026/03/combating-cybercrime-fraud-and-predatory-schemes-against-american-citizens/">https://www.whitehouse.gov/presidential-actions/2026/03/combating-cybercrime-fraud-and-predatory-schemes-against-american-citizens/</a></p><p>C&#8217;mon, where are the controls?  A Catholic bishop in the San Diego area resigned after being arrested and charged with embezzling $270,000 from St. Peter Chaldean Catholic Cathedral in El Cajon, California. He faces 16 felony charges, including money laundering, with prosecutors alleging he misappropriated monthly rental payments exceeding $30,000 from a church tenant. <a href="https://www.ncronline.org/news/pope-announces-resignation-us-bishop-accused-embezzling-270k-california-parish">https://www.ncronline.org/news/pope-announces-resignation-us-bishop-accused-embezzling-270k-california-parish</a></p><p>Not a good week for men of the cloth.  The head priest of Trinity Episcopal Cathedral in Pittsburgh was arrested on February 27 after being accused of stealing over $1,000 in baseball cards from a Walmart in Economy Borough. Police say he was caught leaving the store with 27 packs of baseball cards concealed on his person, and security footage allegedly showed him stealing from the same store on five separate occasions. The very reverend faces charges of receiving stolen property and retail theft.  <a href="https://abcnews.com/US/wireStory/head-priest-episcopal-church-pittsburgh-accused-stealing-baseball-130976273">https://abcnews.com/US/wireStory/head-priest-episcopal-church-pittsburgh-accused-stealing-baseball-130976273</a></p><p>Crypto traders - &#8220;Slippage&#8221; will kill you.  Or cost you 50 million dollars.  &#8220;<em>Slippage is the difference between the price a trader would expect to get in a trade and the price they receive once the transaction executes. This can happen in large orders or when liquidity is weak.&#8221;  </em><a href="https://www.theblock.co/post/393466/crypto-whale-loses-nearly-50-million-swapping-usdt-for-aave">https://www.theblock.co/post/393466/crypto-whale-loses-nearly-50-million-swapping-usdt-for-aave</a></p><p>  A ransomware negotiator working for an incident response firm has been accused by the Department of Justice of secretly collaborating with the ALPHV/BlackCat cybercrime group while helping victims negotiate ransoms. The man and two colleagues allegedly carried out at least 10 ransomware attacks and shared confidential negotiation details with criminals to increase ransom payments in exchange for a share of the proceeds, with ransoms reaching up to $26 million. <a href="https://therecord.media/ransomware-blackcat-doj-incident-responder">https://therecord.media/ransomware-blackcat-doj-incident-responder</a></p><div><hr></div><h4>Bonus</h4><p>Anthropic is doubling the usage limits for Claude during off-hours.  So do your heavy work at 2 am.  <a href="https://support.claude.com/en/articles/14063676-claude-march-2026-usage-promotion">https://support.claude.com/en/articles/14063676-claude-march-2026-usage-promotion</a></p><div><hr></div><h4>Cool Job</h4><p>Head of Digital Financial Crimes Compliance,  State Street.  <a href="https://statestreet.wd1.myworkdayjobs.com/Global/job/Boston-Massachusetts/Head-of-Digital-Financial-Crimes-Compliance--Managing-Director_R-781812">https://statestreet.wd1.myworkdayjobs.com/Global/job/Boston-Massachusetts/Head-of-Digital-Financial-Crimes-Compliance--Managing-Director_R-781812</a></p><p>Financial Crimes Investigations Specialist, DraftKings.  <a href="https://draftkings.wd1.myworkdayjobs.com/draftkings/job/Remote---US/Financial-Crimes-Investigations-Specialist_JR13845-3">https://draftkings.wd1.myworkdayjobs.com/draftkings/job/Remote---US/Financial-Crimes-Investigations-Specialist_JR13845-3</a></p><h4>Cool Tool</h4><p>Notes as easy as texting. <a href="https://prism.you/"> https://prism.you/</a></p><p>ABA Routing Number Look-up/Search.  <a href="https://routingnumber.aba.com/Search1.aspx">https://routingnumber.aba.com/Search1.aspx</a></p><div><hr></div><h4>DFIR</h4><p>The forensic value of Apple Spotlight artifacts.  <a href="https://forensafe.com/blogs/apple-spotlight.html">https://forensafe.com/blogs/apple-spotlight.html</a></p><div><hr></div><h4>Young people&#8230;</h4><p>Claude assessed itself and identified the jobs it will replace. Pivot and adapt as needed. Don&#8217;t be like the wagon wheel maker who kept making wagon wheels after seeing the automobile pass through town. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AwOR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b17363-731f-4ef4-9d3a-1794924e0af3_1268x1424.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AwOR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b17363-731f-4ef4-9d3a-1794924e0af3_1268x1424.jpeg 424w, https://substackcdn.com/image/fetch/$s_!AwOR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b17363-731f-4ef4-9d3a-1794924e0af3_1268x1424.jpeg 848w, https://substackcdn.com/image/fetch/$s_!AwOR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b17363-731f-4ef4-9d3a-1794924e0af3_1268x1424.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!AwOR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b17363-731f-4ef4-9d3a-1794924e0af3_1268x1424.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AwOR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b17363-731f-4ef4-9d3a-1794924e0af3_1268x1424.jpeg" width="1268" height="1424" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d7b17363-731f-4ef4-9d3a-1794924e0af3_1268x1424.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1424,&quot;width&quot;:1268,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:216396,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/191067327?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b17363-731f-4ef4-9d3a-1794924e0af3_1268x1424.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AwOR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b17363-731f-4ef4-9d3a-1794924e0af3_1268x1424.jpeg 424w, https://substackcdn.com/image/fetch/$s_!AwOR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b17363-731f-4ef4-9d3a-1794924e0af3_1268x1424.jpeg 848w, https://substackcdn.com/image/fetch/$s_!AwOR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b17363-731f-4ef4-9d3a-1794924e0af3_1268x1424.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!AwOR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b17363-731f-4ef4-9d3a-1794924e0af3_1268x1424.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.anthropic.com/research/labor-market-impacts"> https://www.anthropic.com/research/labor-market-impacts</a></p><div><hr></div><h4>Irrelevant</h4><p>Sending employees back into the office isn&#8217;t going well.  <a href="https://thehill.com/opinion/technology/5775420-remote-first-productivity-growth/">https://thehill.com/opinion/technology/5775420-remote-first-productivity-growth/</a></p><div><hr></div><h4>Sign Off</h4><p>My good will, positive vibes, and prayers will be offered to anyone traveling this week. What a mess. Get to the airport early and bring an extra dose of patience. I try to keep politics out of the newsletter, but damn, what do we even have these people for? If our elected officials can&#8217;t agree to ensure our essential security personnel, like TSA, get paychecks, then the system is graveyard dead. They all need to go, regardless of whether they have a D or R behind their name. </p><p>Thanks, </p><p>Matt</p><p>&#8220;TRY BEING INFORMED INSTEAD OF JUST OPINIONATED.&#8221;</p><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 277]]></title><description><![CDATA[Cybercrime Investigation Newsletter, week ending March 8, 2028]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-277</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-277</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 10 Mar 2026 10:53:47 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>How to find a company&#8217;s email provider based on the domain.  </p><p>It&#8217;s a 50/50 task. If you solve it correctly on the first try, it&#8217;s straightforward. Otherwise, it can become endlessly complex, and you might never find the answer. As I began preparing this piece and designing a workflow to help with your investigations, I realized this isn&#8217;t just a simple few-paragraph reply suitable for a newsletter.</p><p>So, I&#8217;ll give you the easy option first.</p><p>The first step in identifying an organization&#8217;s email provider is to check the MX record for the domain, which stands for Mail Exchanger. This record is publicly published in the Internet&#8217;s Domain Name System for every organization that receives email, indicating the mail server responsible for accepting their incoming messages. Since it&#8217;s publicly accessible, you can look it up without contacting the organization or leaving traces of your search.</p><p>To examine it, visit MXToolbox at mxtoolbox.com, enter the organization&#8217;s domain name and perform an MX Lookup. The large majority of all business organizations use either Microsoft or Google for email. If the record includes mail.protection.outlook.com, the organization uses Microsoft 365. If it points to google.com or contains aspmx.l.google.com, they use Google Workspace. That&#8217;s your answer, and you&#8217;re done.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RO_T!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef58e44f-88d2-4f97-9bc1-713c91690636_2140x660.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RO_T!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef58e44f-88d2-4f97-9bc1-713c91690636_2140x660.jpeg 424w, https://substackcdn.com/image/fetch/$s_!RO_T!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef58e44f-88d2-4f97-9bc1-713c91690636_2140x660.jpeg 848w, https://substackcdn.com/image/fetch/$s_!RO_T!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef58e44f-88d2-4f97-9bc1-713c91690636_2140x660.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!RO_T!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef58e44f-88d2-4f97-9bc1-713c91690636_2140x660.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RO_T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef58e44f-88d2-4f97-9bc1-713c91690636_2140x660.jpeg" width="1456" height="449" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ef58e44f-88d2-4f97-9bc1-713c91690636_2140x660.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:449,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:333813,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/190318852?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef58e44f-88d2-4f97-9bc1-713c91690636_2140x660.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RO_T!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef58e44f-88d2-4f97-9bc1-713c91690636_2140x660.jpeg 424w, https://substackcdn.com/image/fetch/$s_!RO_T!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef58e44f-88d2-4f97-9bc1-713c91690636_2140x660.jpeg 848w, https://substackcdn.com/image/fetch/$s_!RO_T!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef58e44f-88d2-4f97-9bc1-713c91690636_2140x660.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!RO_T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef58e44f-88d2-4f97-9bc1-713c91690636_2140x660.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Problems arise if the MX record points to a third-party security gateway instead of Microsoft or Google. Services like Mimecast, Proofpoint, and Barracuda act as intermediaries, filtering spam and malware before forwarding messages. In those cases, the MX record only reveals the gateway used, not the actual mail hosting provider. If your lookup shows hostnames like mimecast.com, pphosted.com, or barracudanetworks.com, you&#8217;ll need to investigate further.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_nIs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9b4ebcc-3131-4af2-a85d-dce34211d42f_2138x686.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_nIs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9b4ebcc-3131-4af2-a85d-dce34211d42f_2138x686.jpeg 424w, https://substackcdn.com/image/fetch/$s_!_nIs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9b4ebcc-3131-4af2-a85d-dce34211d42f_2138x686.jpeg 848w, https://substackcdn.com/image/fetch/$s_!_nIs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9b4ebcc-3131-4af2-a85d-dce34211d42f_2138x686.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!_nIs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9b4ebcc-3131-4af2-a85d-dce34211d42f_2138x686.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_nIs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9b4ebcc-3131-4af2-a85d-dce34211d42f_2138x686.jpeg" width="1456" height="467" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e9b4ebcc-3131-4af2-a85d-dce34211d42f_2138x686.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:467,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:451650,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/190318852?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9b4ebcc-3131-4af2-a85d-dce34211d42f_2138x686.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_nIs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9b4ebcc-3131-4af2-a85d-dce34211d42f_2138x686.jpeg 424w, https://substackcdn.com/image/fetch/$s_!_nIs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9b4ebcc-3131-4af2-a85d-dce34211d42f_2138x686.jpeg 848w, https://substackcdn.com/image/fetch/$s_!_nIs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9b4ebcc-3131-4af2-a85d-dce34211d42f_2138x686.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!_nIs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9b4ebcc-3131-4af2-a85d-dce34211d42f_2138x686.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>When a security gateway obscures the MX record, we often turn to the SPF record. SPF, or Sender Policy Framework, lists all authorized email sending services for a domain. It aims to prevent email fraud by confirming which servers are legitimate senders, helping mail systems verify message authenticity. Importantly, the list must include the actual mailbox provider; otherwise, legitimate emails could be marked as spam or blocked. This makes the SPF record especially useful during investigations.</p><p>To check it, go back to MXToolbox, click the dropdown next to the search button, and select SPF Record Lookup. Enter the same domain and run the search. Although the results may look like a string of technical text, focus on entries starting with &#8220;include:&#8221;. These indicate external services trusted to send mail for the domain. For example, include:spf.protection.outlook.com suggests Microsoft 365, while include:_spf.google.com indicates Google Workspace &#8212; regardless of the MX record.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-t5n!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ecfba5a-c697-4eef-aea5-1b1aba826f03_2128x1020.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-t5n!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ecfba5a-c697-4eef-aea5-1b1aba826f03_2128x1020.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-t5n!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ecfba5a-c697-4eef-aea5-1b1aba826f03_2128x1020.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-t5n!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ecfba5a-c697-4eef-aea5-1b1aba826f03_2128x1020.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-t5n!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ecfba5a-c697-4eef-aea5-1b1aba826f03_2128x1020.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-t5n!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ecfba5a-c697-4eef-aea5-1b1aba826f03_2128x1020.jpeg" width="1456" height="698" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1ecfba5a-c697-4eef-aea5-1b1aba826f03_2128x1020.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:698,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:684631,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/190318852?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ecfba5a-c697-4eef-aea5-1b1aba826f03_2128x1020.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-t5n!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ecfba5a-c697-4eef-aea5-1b1aba826f03_2128x1020.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-t5n!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ecfba5a-c697-4eef-aea5-1b1aba826f03_2128x1020.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-t5n!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ecfba5a-c697-4eef-aea5-1b1aba826f03_2128x1020.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-t5n!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ecfba5a-c697-4eef-aea5-1b1aba826f03_2128x1020.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A security gateway can block incoming mail and hide its destination, but it cannot hide the outbound authorization record. The SPF record must list the real provider, and since it&#8217;s public, we can access and read it. Usually, if Phase 1 yields no results, Phase 2 might provide the answer.</p><p>The problem is when organizations obscure third-party hosting services or run their own email server.  We&#8217;ll look at some of those next week.  </p><div><hr></div><h4>The News&#8230;</h4><p>The FBI warns of a phishing scam in which criminals impersonate city and county officials to solicit fraudulent permit payments. Victims receive emails containing accurate permit information that request payment via wire transfer, peer-to-peer payment, or cryptocurrency.  <a href="https://www.ic3.gov/PSA/2026/PSA260309">https://www.ic3.gov/PSA/2026/PSA260309</a></p><p>The White House released its cybersecurity policy in the new document &#8220;President Trump&#8217;s Cyber Strategy for America." Normally, I&#8217;d respond with "Meh," since government policies, papers, and promises are pretty worthless. However, President Trump has established a pretty good track record of following through on his commitments, for better or worse. We should digest this document and prepare to work within its guidelines because it&#8217;s likely to be carried out.  <a href="https://www.whitehouse.gov/wp-content/uploads/2026/03/President-Trumps-Cyber-Strategy-for-America.pdf">https://www.whitehouse.gov/wp-content/uploads/2026/03/President-Trumps-Cyber-Strategy-for-America.pdf</a></p><p>Tycoon 2FA was a major &#8220;Phishing-as-a-Service (PhaaS)&#8221; platform that appeared in 2023 and was developed in 2024 to evade multi-factor authentication using adversary-in-the-middle attacks, capturing live session cookies to access accounts illegally. It was associated with more than 64,000 phishing incidents, affecting nearly 100,000 organizations worldwide. At its height, it accounted for approximately 62% of all phishing attempts blocked by Microsoft. In early 2026, a coordinated operation led by Europol, involving Microsoft, Intel 471, Cloudflare, Coinbase, and others, dismantled the platform&#8217;s infrastructure, seizing 330 domains and arresting the alleged ringleader.   <a href="https://www.intel471.com/blog/born-to-bypass-mfa-taking-down-tycoon-2fa">https://www.intel471.com/blog/born-to-bypass-mfa-taking-down-tycoon-2fa</a></p><p>BLUF: Keep your device updated to the most recent version of iOS.  Security researchers at Google discovered an iPhone hacking toolkit called Coruna, originally used by a government customer, that has since leaked and spread to cybercriminals. The kit can compromise iPhones running iOS 13 through 17.2.1 by chaining together 23 vulnerabilities, requiring only that a target visit a malicious website. After its initial discovery in February 2025, the same toolkit was found being used by a Russian espionage group targeting Ukrainians and later by a financially motivated hacker in China. Mobile security firm iVerify linked the tools to the U.S. government, drawing parallels to previously attributed American hacking frameworks. <a href="https://cloud.google.com/blog/topics/threat-intelligence/coruna-powerful-ios-exploit-kit">https://cloud.google.com/blog/topics/threat-intelligence/coruna-powerful-ios-exploit-kit</a></p><p>The FBI has extradited a 28-year-old Bangladeshi from Malaysia to Alaska to face charges related to an international child sexual exploitation ring. Indicted in 2022 by an Alaska federal grand jury, the man is accused of using Instagram and Snapchat to coercively obtain sexually explicit material from hundreds of minors across the U.S. and internationally. He faces multiple charges, including conspiracy to produce child pornography, child exploitation enterprise, cyberstalking, and wire fraud. If convicted, he could face 20 years to life imprisonment. Kudos to the BU, Alaska State Police, and Anchorage PD for wrapping this guy up.  <a href="https://www.justice.gov/usao-ak/pr/bangladeshi-national-make-initial-appearance-following-arrest-fbi-international">https://www.justice.gov/usao-ak/pr/bangladeshi-national-make-initial-appearance-following-arrest-fbi-international</a></p><p>Who says crime doesn&#8217;t pay?  Retail crime certainly seems to pay.  This Ohio woman defrauded Home Depot of $266,699 through 1700 fraudulent returns. She was sentenced to 180 days in jail and five years of community supervision.  Oh, and restitution, but we all know that will likely never happen.  So, a quarter of a million dollars to sit in jail for 180 days?  Some might say that&#8217;s a steal.  <a href="https://www.cleveland19.com/2026/03/05/ohio-womans-multi-state-retail-fraud-scheme-created-266699-fake-store-credit-police/">https://www.cleveland19.com/2026/03/05/ohio-womans-multi-state-retail-fraud-scheme-created-266699-fake-store-credit-police/</a></p><div><hr></div><h4>DFIR</h4><p>I once testified as an expert witness in a trial concerning the recovery of dashcam video evidence.  I removed the microSD card from the device, cloned it, and then played the mp4 file to isolate the time period of the vehicle crash.  It takes an expert to explain that process, I guess.  In this post, SalvationData goes a little deeper into the process.  <a href="https://www.salvationdata.com/product-tips/dashcam-video-recovery/">https://www.salvationdata.com/product-tips/dashcam-video-recovery/</a></p><div><hr></div><h4>Mail Call</h4><p><em>&#8220;Matt, don&#8217;t hate the player, hate the game.  Personal branding is now a professional requirement, and LinkedIn is the most efficient place to do it.&#8221;</em> - TF</p><div><hr></div><h4>Speaking of LinkedIn</h4><p>I&#8217;ve been notably resistant to freaking out about AI being used to facilitate cybercrime, noting that the old methods still work just fine. But every day I become more bullish.  </p><p>TrendAI researchers demonstrate how publicly available LinkedIn data can be rapidly weaponized into highly targeted phishing attacks using AI tools. The researchers built a proof-of-concept system that automates the collection of public LinkedIn posts and images, analyzes them for contextual insights, and generates detailed employee profiles. Using AI, the tool identifies key professional interests, creates personalized marketing emails, discovers likely email addresses, and even generates realistic phishing websites tailored to the target&#8217;s expertise&#8212;all within 30 minutes. </p><p><a href="https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/from-linkedin-to-tailored-attack-in-30-minutes-how-ai-accelerates-target-profiling-for-cybercrime">https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/from-linkedin-to-tailored-attack-in-30-minutes-how-ai-accelerates-target-profiling-for-cybercrime</a></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3-9a!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d20f5ae-2ed7-4165-91dd-e4ecab8e2fd8_1212x430.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3-9a!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d20f5ae-2ed7-4165-91dd-e4ecab8e2fd8_1212x430.jpeg 424w, https://substackcdn.com/image/fetch/$s_!3-9a!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d20f5ae-2ed7-4165-91dd-e4ecab8e2fd8_1212x430.jpeg 848w, https://substackcdn.com/image/fetch/$s_!3-9a!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d20f5ae-2ed7-4165-91dd-e4ecab8e2fd8_1212x430.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!3-9a!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d20f5ae-2ed7-4165-91dd-e4ecab8e2fd8_1212x430.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3-9a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d20f5ae-2ed7-4165-91dd-e4ecab8e2fd8_1212x430.jpeg" width="1212" height="430" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2d20f5ae-2ed7-4165-91dd-e4ecab8e2fd8_1212x430.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:430,&quot;width&quot;:1212,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:109097,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/190318852?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d20f5ae-2ed7-4165-91dd-e4ecab8e2fd8_1212x430.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3-9a!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d20f5ae-2ed7-4165-91dd-e4ecab8e2fd8_1212x430.jpeg 424w, https://substackcdn.com/image/fetch/$s_!3-9a!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d20f5ae-2ed7-4165-91dd-e4ecab8e2fd8_1212x430.jpeg 848w, https://substackcdn.com/image/fetch/$s_!3-9a!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d20f5ae-2ed7-4165-91dd-e4ecab8e2fd8_1212x430.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!3-9a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d20f5ae-2ed7-4165-91dd-e4ecab8e2fd8_1212x430.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h4>Cool Job</h4><p>Fraud Investigator, PSECU.  <a href="https://psecu.wd12.myworkdayjobs.com/PSECU/job/Harrisburg-PA/Fraud-Investigator_JR100773">https://psecu.wd12.myworkdayjobs.com/PSECU/job/Harrisburg-PA/Fraud-Investigator_JR100773</a> </p><p>Security Investigations Manager, Anduril.  <a href="https://job-boards.greenhouse.io/andurilindustries/jobs/5051653007">https://job-boards.greenhouse.io/andurilindustries/jobs/5051653007</a></p><h4>Cool Tool</h4><p>Find Flock cameras.  <a href="https://deflock.org/">https://deflock.org/</a></p><div><hr></div><h4>Irrelevant</h4><p>System76 makes computers that run the Linux operating system and they are the publisher and maintainer of the pop_os! operating system.  I&#8217;ve used both, hardware and software.  </p><p>Colorado&#8217;s Senate Bill 26-051 and California&#8217;s Assembly Bill No. 1043 mandate that operating systems must report age brackets to app stores and websites. When someone creates an account on a computer, they are expected to be 18 or older and confirm their age, whether for themselves or their child. In reality, this regulation implies that individuals under 18 are generally not supposed to set up their own computer accounts.</p><p>The law requires technology providers to verify that all users are of legal age. While the Internet has harmful content and children need protection, it is ultimately the parents&#8217; responsibility to provide guardrails. Stop expecting technology and Internet Service Providers to act as parents.</p><p>The CEO of Colorado-based System76 offers a clearer, better-argued case for why we should probably oppose these age-verification laws.</p><p><a href="https://blog.system76.com/post/system76-on-age-verification">https://blog.system76.com/post/system76-on-age-verification</a></p><div><hr></div><h4>Sign Off</h4><p>I felt something I haven&#8217;t in a long time this week.  The warmth of the sun.  Yeah, that big yellow orange thing in the sky.  It&#8217;s still there and doing well.  And the microdose of vitamin D has given me some hope we&#8217;ll pull out of the long cold winter season.</p><p>Thanks for staying with me each week, even when the newsletter is trash.</p><p>See you all next week.</p><p>Matt</p><p>&#8220;EVERY DAY YOU WAIT IS ANOTHER DAY YOU WON&#8217;T GET BACK.&#8221;</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 276]]></title><description><![CDATA[Cybersecurity Investigation Newsletter, Week ending March 1, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-276</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-276</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 03 Mar 2026 12:44:46 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Sometimes, I manage to get it right&#8212;recognizing trends, catching the right wave. I've been emphasizing TOAD attacks (Telephone Oriented Attack Delivery), also known as Call Back Fraud, for over two years. I've written about this attack multiple times in the newsletter and included it professionally in my security awareness trainings.  </p><p>This new report from StrongestLayer confirms that my prediction about the attack's prevalence was accurate. </p><p>TOAD is no longer an emerging tactic; it&#8217;s become one of the dominant ways attackers bypass enterprise email security.</p><p>StrongestLayer shows that more than one in four successful phishing emails now use a phone number as the payload. That means no malicious link. No malware attachment. No exploit kit. Just a callback number.</p><p>And that&#8217;s precisely why it works.</p><p>Traditional Secure Email Gateways (SEGs) are designed to scan URLs, detonate attachments, and score message content for known malicious indicators. TOAD attacks contain none of those. The &#8220;weapon&#8221; is a string of digits, indistinguishable from a legitimate business contact number. Blocking financial language plus a phone number would cripple normal accounts payable traffic. From an architectural standpoint, these attacks operate in a structural blind spot.</p><p>Understanding TOAD requires understanding its layered evasion model.</p><p>Layer One: Trusted Delivery. Messages are often sent through legitimate infrastructure such as SendGrid or other reputable platforms. Reputation filtering sees clean domains and allows delivery.</p><p>Layer Two: Anti-Scanner. Some campaigns add QR codes inside PDFs or use CAPTCHA gates. Automated sandboxes follow the link, hit a challenge page, and mark the message safe because they never reach the malicious content.</p><p>Layer Three: Channel Shift. This is the core of TOAD. The victim calls the number. The social engineering happens over the voice. Credential harvesting, remote access installation, or gift card fraud can unfold during a 20&#8211;30-minute conversation. By design, this occurs outside the email system and outside our endpoint detection tools.  </p><p>For investigators, this means the crime scene is not the inbox. It is the phone call and the subsequent cloud authentication logs. As attackers deliberately move away from malware and toward human exploitation, investigators must adapt accordingly.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!96XP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34304538-9727-4c37-a000-2ec23a4faad4_1594x1976.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!96XP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34304538-9727-4c37-a000-2ec23a4faad4_1594x1976.jpeg 424w, https://substackcdn.com/image/fetch/$s_!96XP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34304538-9727-4c37-a000-2ec23a4faad4_1594x1976.jpeg 848w, https://substackcdn.com/image/fetch/$s_!96XP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34304538-9727-4c37-a000-2ec23a4faad4_1594x1976.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!96XP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34304538-9727-4c37-a000-2ec23a4faad4_1594x1976.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!96XP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34304538-9727-4c37-a000-2ec23a4faad4_1594x1976.jpeg" width="1456" height="1805" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/34304538-9727-4c37-a000-2ec23a4faad4_1594x1976.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1805,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:700474,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/189522013?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34304538-9727-4c37-a000-2ec23a4faad4_1594x1976.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!96XP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34304538-9727-4c37-a000-2ec23a4faad4_1594x1976.jpeg 424w, https://substackcdn.com/image/fetch/$s_!96XP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34304538-9727-4c37-a000-2ec23a4faad4_1594x1976.jpeg 848w, https://substackcdn.com/image/fetch/$s_!96XP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34304538-9727-4c37-a000-2ec23a4faad4_1594x1976.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!96XP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34304538-9727-4c37-a000-2ec23a4faad4_1594x1976.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This TOAD attack is designed to make me believe I was wrongly charged for a Geek Squad Protection plan for someone else. But if I act quickly enough, I can cancel the transaction. No links, no email addresses, just a phone number. I just need to call them!</p><p>Read the StrongestLayer report: <a href="https://cdn.prod.website-files.com/692908f21a0929f1fb06bc04/699df5313a4d214a1d53bd72_2026_Evasion_Technique_Combinations_Research_final.pdf">https://cdn.prod.website-files.com/692908f21a0929f1fb06bc04/699df5313a4d214a1d53bd72_2026_Evasion_Technique_Combinations_Research_final.pdf</a></p><div><hr></div><h4>Unlinking from LinkedIn</h4><p>I received several comments concerning my take on LinkedIn, included in last week&#8217;s issue (275).  </p><p>Sometimes I think LinkedIn has quietly evolved into professional performance art. It&#8217;s just a theater.</p><p>People spend enormous amounts of time crafting long-form posts explaining concepts to&#8230; other professionals in the exact same field. If most of your network consists of peers who do what you do, who exactly is the audience?</p><p>It can feel a bit like delivering a keynote at a firefighter convention about the dangers of smoke inhalation. Important? Absolutely. Groundbreaking? Not so much.</p><p>That doesn&#8217;t make the content wrong. But it does raise an interesting question: are we sharing insight, or signaling expertise? Are we advancing the conversation, or just making sure everyone sees us advancing it?</p><p>There&#8217;s nothing inherently wrong with visibility. Thought leadership has its place. But when all of the applause comes from people who already know the script, it&#8217;s worth asking whether we&#8217;re educating&#8230; or performing.</p><p>And there&#8217;s nothing wrong with performing&#8212;obviously, it's something I do every week, but only in the appropriate place.  </p><div><hr></div><h4>The News&#8230;</h4><p>Oklahoma man will serve 46 months in federal prison for bank fraud and money laundering. He exploited insider access at multiple financial services companies and a banking software company to steal over $588,000 from accounts at three of the financial institutions.  <a href="https://www.cutimes.com/2026/02/09/former-credit-union-employee-sentenced-in-588000-insider-fraud-case/">https://www.cutimes.com/2026/02/09/former-credit-union-employee-sentenced-in-588000-insider-fraud-case/</a></p><p>An unknown attacker exploited Anthropic&#8217;s Claude AI chatbot to breach multiple Mexican government agencies between December and January, stealing 150 gigabytes of sensitive data,  including 195 million taxpayer records, voter information, and government employee credentials. The attacker used Spanish-language prompts to instruct Claude to act as an elite hacker, finding vulnerabilities and automating data theft. Although Claude initially refused some requests, the hacker eventually &#8220;jailbroken&#8221; it by framing the attacks as legitimate penetration testing and providing a detailed playbook. <a href="https://www.siliconvalley.com/2026/02/25/hacker-used-anthropics-claude-to-steal-sensitive-mexican-data/">https://www.siliconvalley.com/2026/02/25/hacker-used-anthropics-claude-to-steal-sensitive-mexican-data/</a></p><p>The AirSnitch attack is a newly discovered Wi-Fi vulnerability that bypasses client isolation, a security feature meant to prevent direct communication between connected devices, by exploiting weaknesses at the lowest network layers. Rather than breaking encryption itself, the attack allows an attacker with access to the Wi-Fi network (or even connected infrastructure) to perform man-in-the-middle attacks, intercept unencrypted traffic, steal credentials, and manipulate data across home, office, and enterprise networks. While the vulnerability affects routers from major manufacturers like Netgear, Cisco, and D-Link, it requires more technical skill than some previous Wi-Fi attacks and can be partially mitigated through VPNs, zero-trust security models, or avoiding untrusted networks, though no complete immediate fix is currently available.  <a href="https://arstechnica.com/security/2026/02/new-airsnitch-attack-breaks-wi-fi-encryption-in-homes-offices-and-enterprises/">https://arstechnica.com/security/2026/02/new-airsnitch-attack-breaks-wi-fi-encryption-in-homes-offices-and-enterprises/</a></p><p>A new federal anti-money laundering rule, effective March 1, 2026, requires reporting of beneficial ownership details (names, addresses, SSNs) for all-cash or non-financed residential real estate purchases made by entities or trusts. The report must be filed with FinCEN within 30&#8211;60 days of closing, typically by the closing agent, and title companies may refuse to close without this info. While real estate agents aren&#8217;t directly responsible, they should inform clients. FinCEN estimates 800,000&#8211;850,000 annual transactions will be affected.  <a href="https://www.nar.realtor/magazine/real-estate-news/anti-money-laundering-rule-aimed-at-all-cash-buyers-goes-into-effect-march-1">https://www.nar.realtor/magazine/real-estate-news/anti-money-laundering-rule-aimed-at-all-cash-buyers-goes-into-effect-march-1</a></p><p>Not victim-blaming here, but how did this situation escalate to the point where you&#8217;re paying over 4 million dollars to help your daughter become a model? A photographer was charged with wire fraud and money laundering after allegedly swindling a family out of $4.6 million. Prosecutors say Coyne falsely claimed she was securing modeling gigs for the family&#8217;s daughter, but instead used the money for personal expenses such as gambling.  <a href="https://petapixel.com/2026/03/02/fbi-charge-photographer-with-4-6-million-child-modeling-fraud/">https://petapixel.com/2026/03/02/fbi-charge-photographer-with-4-6-million-child-modeling-fraud/</a></p><div><hr></div><h4>DFIR</h4><p>The forensic value of Apple Maps.  <a href="https://forensafe.com/blogs/apple-maps.html">https://forensafe.com/blogs/apple-maps.html</a></p><div><hr></div><h4>Cool Job</h4><p>Director of Security Services - Ford Motor Company.  <a href="https://efds.fa.em5.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/job/59407">https://efds.fa.em5.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/job/59407</a></p><h4>Cool Tool</h4><p>De-Google yourself - a complete Android-based mobile device operating system that removes all things Google.  <a href="https://e.foundation/e-os/">https://e.foundation/e-os/</a></p><div><hr></div><h4>Irrelevant</h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3TqG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7d5760a-35f8-448c-b8a6-35398fb3bea1_1070x1086.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3TqG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7d5760a-35f8-448c-b8a6-35398fb3bea1_1070x1086.jpeg 424w, https://substackcdn.com/image/fetch/$s_!3TqG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7d5760a-35f8-448c-b8a6-35398fb3bea1_1070x1086.jpeg 848w, https://substackcdn.com/image/fetch/$s_!3TqG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7d5760a-35f8-448c-b8a6-35398fb3bea1_1070x1086.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!3TqG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7d5760a-35f8-448c-b8a6-35398fb3bea1_1070x1086.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3TqG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7d5760a-35f8-448c-b8a6-35398fb3bea1_1070x1086.jpeg" width="1070" height="1086" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d7d5760a-35f8-448c-b8a6-35398fb3bea1_1070x1086.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1086,&quot;width&quot;:1070,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:150610,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/189522013?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7d5760a-35f8-448c-b8a6-35398fb3bea1_1070x1086.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3TqG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7d5760a-35f8-448c-b8a6-35398fb3bea1_1070x1086.jpeg 424w, https://substackcdn.com/image/fetch/$s_!3TqG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7d5760a-35f8-448c-b8a6-35398fb3bea1_1070x1086.jpeg 848w, https://substackcdn.com/image/fetch/$s_!3TqG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7d5760a-35f8-448c-b8a6-35398fb3bea1_1070x1086.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!3TqG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7d5760a-35f8-448c-b8a6-35398fb3bea1_1070x1086.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h4>Sign Off</h4><p>Thanks for coming back after last week&#8217;s trash heap of a newsletter. So many typos, including the misspelling of my own domain. Well, I guess it shows that I&#8217;m actually writing the newsletter and not AI.  </p><p>So let&#8217;s try this again.  You can email me at [matt (at) threatswithoutborders.com]</p><p>Matt</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 275]]></title><description><![CDATA[Cybercrime Investigation Newsletter, week ending February 22, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-275</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-275</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 24 Feb 2026 11:17:06 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>RSAC is coming up, and I don&#8217;t even need a calendar to realize it. The evidence is in the flood of salespeople spamming my inbox with invitations to &#8220;Meet-up at RSAC?" </p><p>It feels so pretentious&#8212;every email seems to assume, "Of course, you're attending RSAC." There's a hint of condescension, too, implying that if you're not there, you're either not among the cool kids or you're low budget.  </p><p>Well, I&#8217;m not in the cool-kids group, and I'm very low-budget.  So I&#8217;ll gladly meet you in exchange for airfare, hotel, and a conference pass.  </p><p>Otherwise, keep your spam to yourself.  </p><div><hr></div><h4>No more BSA? </h4><blockquote><p><em>At a minimum, all the thresholds for reports required under the Bank Secrecy Act should be adjusted for inflation. Congress could go further and eliminate the reporting requirements. Even better, Congress could also do away with the Bank Secrecy Act regime entirely.</em></p></blockquote><p>Interesting take from the Cato Institute.  </p><p>The authors of  &#8220;From Writs to Wires: The Surveillance State&#8217;s Long War on Privacy&#8221; explore how modern surveillance in the U.S. has evolved from colonial-era warrantless searches into an invisible digital system that &#8220;undermines constitutional privacy rights.&#8221; It alleges that government agencies exploit third-party data, weaken encryption, and use technologies such as facial recognition and financial tracking to monitor citizens.  </p><blockquote><p><em>All those records held by your bank, financial planner, and similar entities are fair game for prying eyes&#8212;as long as those eyes belong to the government.</em></p></blockquote><p>Although this article was originally aimed at privacy advocates and perhaps conspiracy theorists, those working in BSA/AML should also pay attention - but for an entirely different reason. </p><p><a href="https://www.cato.org/free-society/winter-2026/writs-wires-surveillance-states-long-war-privacy">https://www.cato.org/free-society/winter-2026/writs-wires-surveillance-states-long-war-privacy</a></p><div><hr></div><h4>Mail</h4><p><em>Thanks for linking to the study that tells my wife it&#8217;s ok for me to drink a lot of coffee.</em> -JS</p><p><em>Matt, I suspect you would be very successful if you started your own business, and you are correct, paid bank holidays are a very nice perk. </em> - K</p><p><em>This week, I attended two presentations, and both could have benefited from your advice on avoiding lengthy problem explanations. In one, a speaker spent 20 minutes describing the problem to the group, who then identified it and submitted a ticket requesting it be fixed.</em>  - JohnB (See Issue 272 for reference) </p><div><hr></div><h4>The News&#8230;</h4><p>Obviously, I support the Bureau and the Internet Crime Complaint Center (IC3), but sometimes I wonder what the point is. The information they release often feels outdated. Cybersecurity and fraud organizations share information in real time, but the analytical and content creation processes within any government agency, not just IC3, are so time-consuming that by the time the content is ready and approved, it's already old news.  Anyway, they released a &#8220;Flash&#8221; report about malware-enabled ATM jackpotting, which most of us knew about long before the flash.  <a href="https://www.ic3.gov/CSA/2026/260219.pdf">https://www.ic3.gov/CSA/2026/260219.pdf</a></p><p>A recent cyberattack campaign impersonates Google Meet invitations to spread malware. Victims receive a fake meeting invite from a newly registered domain, and clicking the &#8220;Join&#8221; button redirects them to a convincing fake Google Meet page hosted on an impersonated Microsoft Store site. They are then prompted to download a fake &#8220;update&#8221; installer (`.secretly installs the **Teramind remote monitoring tool**, allowing attackers full control over the victim&#8217;s system and transmitting device details (IP, location, OS, etc.) to the attacker via Telegram. Important warning signs include a lookalike domain with intentional typos, a sender domain less than a month old, failed DKIM authentication, and poor HTML branding&#8212;all tactics aimed at deceiving both humans and security scanners.  <a href="https://sublime.security/blog/fake-google-meet-invitation-fake-microsoft-store-real-malware-attack/">https://sublime.security/blog/fake-google-meet-invitation-fake-microsoft-store-real-malware-attack/</a></p><p>Signal launched Version 8 of its secure backups.  <a href="https://aboutsignal.com/news/signal-launches-version-8-0-with-signal-secure-backups/">https://aboutsignal.com/news/signal-launches-version-8-0-with-signal-secure-backups/</a></p><p>This guy laundered 2.3 million dollars through gift cards.  Seriously, most gift cards limit out at $500.  He purchased 460,000 gift cards?  <a href="https://cbs6albany.com/news/local/chinese-man-found-guilty-in-money-laundering-conspiracy-involving-229m-in-gift-cards-fraud-jun-wang">https://cbs6albany.com/news/local/chinese-man-found-guilty-in-money-laundering-conspiracy-involving-229m-in-gift-cards-fraud-jun-wang</a></p><p>LayerX, a cybersecurity company, identified 30 malicious Chrome extensions that mimic popular AI tools like Gemini and ChatGPT, with over 260,000 downloads. These extensions appear to provide legitimate AI chat interfaces but covertly send user data to attacker-controlled servers, capturing sensitive information such as emails, browser content, and pasted text. The threat is heightened by users' tendency to share sensitive info with AI tools and the extensions' use of hidden iframes, making detection difficult during reviews. Even after the discovery was made public, several of these malicious extensions remained available on the Chrome Web Store.  <a href="https://layerxsecurity.com/blog/aiframe-fake-ai-assistant-extensions-targeting-260000-chrome-users-via-injected-iframes/">https://layerxsecurity.com/blog/aiframe-fake-ai-assistant-extensions-targeting-260000-chrome-users-via-injected-iframes/</a></p><p>Starkiller is a sophisticated phishing-as-a-service (PhaaS) tool that bypasses traditional security measures, including MFA, by live-proxying legitimate login pages instead of mimicking them. This allows attackers to capture credentials and session tokens in real time, making detection extremely difficult since victims interact with actual websites. The tool&#8217;s user-friendly interface and automation lower the technical barrier for cybercriminals, forcing organizations to shift from static detection methods to behavioral and identity-aware monitoring.  <a href="https://www.darkreading.com/threat-intelligence/starkiller-phishing-kit-mfa">https://www.darkreading.com/threat-intelligence/starkiller-phishing-kit-mfa</a></p><div><hr></div><p>Message me:  matt (at) threatswithourborders.com</p><div><hr></div><h4>DFIR</h4><p>I haven&#8217;t used this, so please test it in a safe space first, but it is interesting, and I&#8217;ll be giving it some more attention shortly.  </p><blockquote><p><em>Fuji is a free, open-source program for performing forensic acquisition of Mac computers. It should work on any modern Intel or Apple Silicon device, as it leverages standard executables provided by macOS.  Fuji performs a so-called live acquisition (the computer must be turned on) of logical nature, i.e. it includes only existing files. The tool generates a DMG file that can be imported in several digital forensics programs.</em></p></blockquote><p><a href="https://github.com/Lazza/Fuji/releases/tag/1.2.0">https://github.com/Lazza/Fuji/releases/tag/1.2.0</a></p><div><hr></div><h4><code>Cool</code> Job</h4><p>Director of Safety and Security, Vanderbilt University.  <a href="https://ecsr.fa.us2.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/job/10007897">https://ecsr.fa.us2.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/job/10007897</a></p><p>Security Intelligence Operations Specialist, Tesla.  <a href="https://www.tesla.com/careers/search/job/256471">https://www.tesla.com/careers/search/job/256471</a></p><h4>Cool Tool</h4><p>Hate Apple?  Hate Google?  Graphene OS might be your huckleberry.  Tomasz Dunia created a list of currently supported mobile devices and a full tutorial on getting up and running with Graphene as the OS.  <a href="https://blog.tomaszdunia.pl/grapheneos-eng/#list-of-supported-devices-february-2026">https://blog.tomaszdunia.pl/grapheneos-eng/#list-of-supported-devices-february-2026</a></p><p><em>&#8220;Spackle is a macOS menu bar app for inline AI rewrites. Select text in any app, press a keyboard shortcut, and Spackle replaces your selection with an AI-rewritten version &#8212; right in place. You never leave the app you&#8217;re working in.  It works anywhere macOS Accessibility can reach: Mail, Notes, Slack, browser text areas, and more.&#8221;  </em><a href="https://aisatsu.co/spackle/">https://aisatsu.co/spackle/</a></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qeOX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7549fda2-e27a-49e1-a81d-9f42371311c9_1250x338.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qeOX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7549fda2-e27a-49e1-a81d-9f42371311c9_1250x338.jpeg 424w, https://substackcdn.com/image/fetch/$s_!qeOX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7549fda2-e27a-49e1-a81d-9f42371311c9_1250x338.jpeg 848w, https://substackcdn.com/image/fetch/$s_!qeOX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7549fda2-e27a-49e1-a81d-9f42371311c9_1250x338.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!qeOX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7549fda2-e27a-49e1-a81d-9f42371311c9_1250x338.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qeOX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7549fda2-e27a-49e1-a81d-9f42371311c9_1250x338.jpeg" width="1250" height="338" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7549fda2-e27a-49e1-a81d-9f42371311c9_1250x338.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:338,&quot;width&quot;:1250,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:122326,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/188858964?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7549fda2-e27a-49e1-a81d-9f42371311c9_1250x338.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qeOX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7549fda2-e27a-49e1-a81d-9f42371311c9_1250x338.jpeg 424w, https://substackcdn.com/image/fetch/$s_!qeOX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7549fda2-e27a-49e1-a81d-9f42371311c9_1250x338.jpeg 848w, https://substackcdn.com/image/fetch/$s_!qeOX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7549fda2-e27a-49e1-a81d-9f42371311c9_1250x338.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!qeOX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7549fda2-e27a-49e1-a81d-9f42371311c9_1250x338.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h4>Irrelevant</h4><p>Something everyone in law enforcement and counseling has known for, well, ever.</p><blockquote><p><em>Researchers found that the teens who reported using cannabis in the past year were at a higher risk of being diagnosed with several mental health conditions a few years later, compared to teens who didn&#8217;t use cannabis.</em></p><p><em>Teens who reported using cannabis had twice the risk of developing two serious mental illnesses: bipolar, which manifests as alternating episodes of depression and mania, and psychotic disorders, such as schizophrenia which involve a break with reality.</em></p></blockquote><p><a href="https://text.npr.org/nx-s1-5719338">https://text.npr.org/nx-s1-5719338</a></p><div><hr></div><h4>Sign Off</h4><p>I spent some time in Buffalo, NY, last week. I&#8217;ve discussed the city in the newsletter before, and I believe I&#8217;ve finally figured out why people choose to live there. It&#8217;s self-hate. That&#8217;s the only explanation that fits. Yes, I&#8217;ve heard it&#8217;s beautiful in the summer.  </p><p>Shout at me M&amp;T friends.  </p><p>Thanks for reading another issue.  See you all next week.</p><p>Matt</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uz-r!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42f3568f-457f-415c-bd40-eee122414c0c_996x1126.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uz-r!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42f3568f-457f-415c-bd40-eee122414c0c_996x1126.jpeg 424w, https://substackcdn.com/image/fetch/$s_!uz-r!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42f3568f-457f-415c-bd40-eee122414c0c_996x1126.jpeg 848w, https://substackcdn.com/image/fetch/$s_!uz-r!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42f3568f-457f-415c-bd40-eee122414c0c_996x1126.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!uz-r!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42f3568f-457f-415c-bd40-eee122414c0c_996x1126.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uz-r!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42f3568f-457f-415c-bd40-eee122414c0c_996x1126.jpeg" width="996" height="1126" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/42f3568f-457f-415c-bd40-eee122414c0c_996x1126.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1126,&quot;width&quot;:996,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:140965,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/188858964?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42f3568f-457f-415c-bd40-eee122414c0c_996x1126.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uz-r!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42f3568f-457f-415c-bd40-eee122414c0c_996x1126.jpeg 424w, https://substackcdn.com/image/fetch/$s_!uz-r!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42f3568f-457f-415c-bd40-eee122414c0c_996x1126.jpeg 848w, https://substackcdn.com/image/fetch/$s_!uz-r!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42f3568f-457f-415c-bd40-eee122414c0c_996x1126.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!uz-r!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42f3568f-457f-415c-bd40-eee122414c0c_996x1126.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 274]]></title><description><![CDATA[Cybersecurity Investigations Newsletter, week ending February 15, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-274</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-274</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 17 Feb 2026 11:15:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I am often asked why, when looking at a Bitcoin transaction where one address sends funds to another, there are sometimes two addresses on the output side -  and sometimes it even looks like the sending address sent funds back to itself. It seems strange at first glance. Is something going wrong? Is it some kind of error?</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TyzJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe5475a3-054c-4f12-99e2-5584786bdb74_2286x450.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TyzJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe5475a3-054c-4f12-99e2-5584786bdb74_2286x450.jpeg 424w, https://substackcdn.com/image/fetch/$s_!TyzJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe5475a3-054c-4f12-99e2-5584786bdb74_2286x450.jpeg 848w, https://substackcdn.com/image/fetch/$s_!TyzJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe5475a3-054c-4f12-99e2-5584786bdb74_2286x450.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!TyzJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe5475a3-054c-4f12-99e2-5584786bdb74_2286x450.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TyzJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe5475a3-054c-4f12-99e2-5584786bdb74_2286x450.jpeg" width="1456" height="287" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/be5475a3-054c-4f12-99e2-5584786bdb74_2286x450.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:287,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:337810,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/188068614?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe5475a3-054c-4f12-99e2-5584786bdb74_2286x450.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TyzJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe5475a3-054c-4f12-99e2-5584786bdb74_2286x450.jpeg 424w, https://substackcdn.com/image/fetch/$s_!TyzJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe5475a3-054c-4f12-99e2-5584786bdb74_2286x450.jpeg 848w, https://substackcdn.com/image/fetch/$s_!TyzJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe5475a3-054c-4f12-99e2-5584786bdb74_2286x450.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!TyzJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe5475a3-054c-4f12-99e2-5584786bdb74_2286x450.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>One of the best analogies I&#8217;ve heard for explaining cryptocurrency transactions is doing business with gold bars.</p><p>Imagine you own a single 10 oz gold bar.  You want to buy something from a merchant that costs 3 ounces of gold. Here is the problem: you physically cannot chip a 3-oz piece off a gold bar. You cannot hand over exactly 3 ounces from a 10-ounce bar. The whole bar has to go somewhere.</p><p>So what happens? The gold bar goes to the smelter. The smelter melts the gold bar down and pours the molten gold into new, smaller bars. Out come three new bars:</p><ul><li><p>A 3-ounce bar that goes to the merchant -- this is your payment.</p></li><li><p>A 6.9-ounce bar that comes back to you -- this is your change.</p></li><li><p>A 0.1 ounce nugget is the fee paid to the smelter for their work.</p></li></ul><p>The original 10-ounce bar no longer exists. It has been consumed, and three brand new bars have been created in its place.</p><p>In Bitcoin, your funds are not stored as a simple running balance like a bank account. Instead, they exist as individual chunks called UTXOs, which stand for Unspent Transaction Outputs. Think of each UTXO as one of those gold bars. You might have several of them of different sizes sitting in your digital wallet.</p><p>When you want to send Bitcoin to someone, your wallet picks one (or more) of those UTXOs to spend. Just like the gold bar, the entire UTXO must be consumed. You cannot spend just part of it. So the transaction does exactly what the smelter did:</p><ol><li><p>The UTXO is fully spent as an input to the transaction.</p></li><li><p>A new output is created, sending the correct amount to the recipient.</p></li><li><p>A second new output is created, sending the leftover amount back to you -- this is your change.</p></li><li><p>A small amount is claimed by the miners (the people who process Bitcoin transactions) as their fee.</p></li></ol><p>When you look at a Bitcoin transaction on a block explorer and see two output addresses, you are almost always looking at the recipient and the change going back to the sender.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1K-0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45732663-054a-4384-b481-0599be361ccf_2290x1078.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1K-0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45732663-054a-4384-b481-0599be361ccf_2290x1078.jpeg 424w, https://substackcdn.com/image/fetch/$s_!1K-0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45732663-054a-4384-b481-0599be361ccf_2290x1078.jpeg 848w, https://substackcdn.com/image/fetch/$s_!1K-0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45732663-054a-4384-b481-0599be361ccf_2290x1078.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!1K-0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45732663-054a-4384-b481-0599be361ccf_2290x1078.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1K-0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45732663-054a-4384-b481-0599be361ccf_2290x1078.jpeg" width="1456" height="685" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/45732663-054a-4384-b481-0599be361ccf_2290x1078.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:685,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:558838,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/188068614?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45732663-054a-4384-b481-0599be361ccf_2290x1078.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1K-0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45732663-054a-4384-b481-0599be361ccf_2290x1078.jpeg 424w, https://substackcdn.com/image/fetch/$s_!1K-0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45732663-054a-4384-b481-0599be361ccf_2290x1078.jpeg 848w, https://substackcdn.com/image/fetch/$s_!1K-0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45732663-054a-4384-b481-0599be361ccf_2290x1078.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!1K-0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45732663-054a-4384-b481-0599be361ccf_2290x1078.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>So why does the change sometimes go back to the same address, but sometimes a new one?  The answer is simple: it depends entirely on which wallet software is being used.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vI-L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb57f0f86-e302-48ef-8728-380e43b58ef3_2338x466.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vI-L!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb57f0f86-e302-48ef-8728-380e43b58ef3_2338x466.jpeg 424w, https://substackcdn.com/image/fetch/$s_!vI-L!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb57f0f86-e302-48ef-8728-380e43b58ef3_2338x466.jpeg 848w, https://substackcdn.com/image/fetch/$s_!vI-L!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb57f0f86-e302-48ef-8728-380e43b58ef3_2338x466.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!vI-L!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb57f0f86-e302-48ef-8728-380e43b58ef3_2338x466.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vI-L!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb57f0f86-e302-48ef-8728-380e43b58ef3_2338x466.jpeg" width="1456" height="290" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b57f0f86-e302-48ef-8728-380e43b58ef3_2338x466.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:290,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:339829,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/188068614?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb57f0f86-e302-48ef-8728-380e43b58ef3_2338x466.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vI-L!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb57f0f86-e302-48ef-8728-380e43b58ef3_2338x466.jpeg 424w, https://substackcdn.com/image/fetch/$s_!vI-L!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb57f0f86-e302-48ef-8728-380e43b58ef3_2338x466.jpeg 848w, https://substackcdn.com/image/fetch/$s_!vI-L!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb57f0f86-e302-48ef-8728-380e43b58ef3_2338x466.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!vI-L!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb57f0f86-e302-48ef-8728-380e43b58ef3_2338x466.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Older, less technical wallets, and some exchange platforms will send your change right back to the address you sent from. It is the equivalent of the smelter handing your change bar back to you in exactly the same labeled pouch you gave them. Easy to track, easy to understand.</p><p>You will also see this with some business accounts and exchange-managed wallets, where the platform keeps things neat by always cycling funds back to a known address.</p><p>More modern (secure) wallets automatically generate a brand new, never-before-used address to receive your change. This address still belongs entirely to you and is controlled by the same wallet and the same seed phrase. You do not need to do anything special to access those funds. Your wallet knows about it automatically.</p><div><hr></div><h4>Blow your whistle</h4><p>The U.S. Treasury has introduced a new website for whistleblowers to report fraud, money laundering, and sanctions violations. Rewards will range from 10% to 30% of collected fines from successful enforcement actions. FinCEN will oversee the program, which includes violations of the Bank Secrecy Act, U.S. sanctions, and other financial laws, while the IRS will create a dedicated task force to investigate misuse of funds by tax-exempt organizations.  <a href="https://www.fincen.gov/whistleblower/">https://www.fincen.gov/whistleblower/</a></p><div><hr></div><h4>Timely</h4><p>Back in <strong><a href="https://www.threatswithoutborders.com/p/threats-without-borders-issue-271">Issue 271</a></strong>, we looked at Pastebin sites and examined how criminals use them to facilitate cybercrime.  </p><p>A new crypto scam exploits Pastebin comments to spread a ClickFix-style attack targeting crypto users. Scammers post comments with links to fake guides promising a profitable arbitrage opportunity. They trick victims into manually running malicious JavaScript code in their browser&#8217;s address bar. Once executed, the code hijacks the legitimate swap interface by replacing Bitcoin deposit addresses with wallets controlled by attackers and adjusting exchange rates to make the fake exploit seem real, leading to theft of victims&#8217; cryptocurrencies. <a href="https://www.bleepingcomputer.com/news/security/pastebin-comments-push-clickfix-javascript-attack-to-hijack-crypto-swaps/">https://www.bleepingcomputer.com/news/security/pastebin-comments-push-clickfix-javascript-attack-to-hijack-crypto-swaps/</a></p><div><hr></div><h4>The News&#8230;</h4><p>Chainalysis reports that cryptocurrency flows to suspected human trafficking services surged 85% in 2025, reaching hundreds of millions of dollars, primarily through Southeast Asian operations linked to Chinese-language money laundering networks on Telegram. <a href="https://www.chainalysis.com/blog/crypto-human-trafficking-2026/">https://www.chainalysis.com/blog/crypto-human-trafficking-2026/</a></p><p>It seems like only yesterday we were discussing Lockbit 2.0 and now we&#8217;re faced with Lockbit 5.0.  What&#8217;s that saying, time flies when we&#8217;re&#8230; <a href="https://www.acronis.com/en/tru/posts/lockbit-strikes-with-new-50-version-targeting-windows-linux-and-esxi-systems/">https://www.acronis.com/en/tru/posts/lockbit-strikes-with-new-50-version-targeting-windows-linux-and-esxi-systems/</a></p><p>A warning for all Mac &#8220;fanboys&#8221; (myself included): A thriving macOS infostealer economy is emerging, with attackers innovating specifically for Apple&#8217;s ecosystem.  Flare explains that the assumption that Macs are immune to viruses is outdated and dangerous. <a href="https://flare.io/learn/resources/blog/the-macos-stealer-gold-rush-how-cybercriminals-are-racing-to-exploit-apples-ecosystem"> https://flare.io/learn/resources/blog/the-macos-stealer-gold-rush-how-cybercriminals-are-racing-to-exploit-apples-ecosystem</a></p><p>To absolutely no one&#8217;s surprise, cybercriminals are using AI website builders to clone major brands, creating convincing fake sites to lure victims. These sites are used for credential harvesting, payment fraud, and malware delivery. The ease of use and lack of robust security measures in AI website builders enable attackers to create and deploy these scams rapidly.  <a href="https://www.malwarebytes.com/blog/news/2026/02/criminals-are-using-ai-website-builders-to-clone-major-brands">https://www.malwarebytes.com/blog/news/2026/02/criminals-are-using-ai-website-builders-to-clone-major-brands</a></p><p>Bitcoin exchange Paxful has been fined $4 million for transferring funds tied to money laundering, fraud, and sex trafficking.  <a href="https://www.justice.gov/opa/pr/virtual-asset-trading-platform-sentenced-violating-travel-act-and-other-federal-criminal">https://www.justice.gov/opa/pr/virtual-asset-trading-platform-sentenced-violating-travel-act-and-other-federal-criminal</a></p><p>There isn&#8217;t much left of CISA, but the remaining holdouts published the agency&#8217;s 2025 Year-In-Review report.  <a href="https://www.cisa.gov/about/2025YIR">https://www.cisa.gov/about/2025YIR</a></p><p>Posted without comment.  <a href="https://techcrunch.com/2026/02/13/sex-toys-maker-tenga-says-hacker-stole-customer-information/">https://techcrunch.com/2026/02/13/sex-toys-maker-tenga-says-hacker-stole-customer-information/</a></p><div><hr></div><h4>Cool Job</h4><p>For those that like snow&#8230; Fraud Coordinator - Erie Federal Credit Union.  <a href="https://eriefcu.acquiretm.com/job_details_clean.aspx?id=1676">https://eriefcu.acquiretm.com/job_details_clean.aspx?id=1676</a></p><h4>Cool Tool</h4><p>Reverse image search (you might get ads depending on your browser) <a href="https://picdetective.com/">https://picdetective.com/</a></p><div><hr></div><h4>DFIR</h4><p>Jordan Mussman provides &#8220;a practical field guide to macOS security architecture and forensic artifacts for incident responders investigating compromised MacBooks in 2026&#8221;.  <a href="https://jmussman.net/posts/mac_dfir/">https://jmussman.net/posts/mac_dfir/</a></p><div><hr></div><h4>Irrelevant</h4><p>The best science I&#8217;ve read in a long time.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JI3a!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc91d3dec-1cc0-41e8-b67e-68b33a8535d1_1510x710.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JI3a!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc91d3dec-1cc0-41e8-b67e-68b33a8535d1_1510x710.jpeg 424w, https://substackcdn.com/image/fetch/$s_!JI3a!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc91d3dec-1cc0-41e8-b67e-68b33a8535d1_1510x710.jpeg 848w, https://substackcdn.com/image/fetch/$s_!JI3a!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc91d3dec-1cc0-41e8-b67e-68b33a8535d1_1510x710.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!JI3a!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc91d3dec-1cc0-41e8-b67e-68b33a8535d1_1510x710.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JI3a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc91d3dec-1cc0-41e8-b67e-68b33a8535d1_1510x710.jpeg" width="1456" height="685" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c91d3dec-1cc0-41e8-b67e-68b33a8535d1_1510x710.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:685,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:400747,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/188068614?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc91d3dec-1cc0-41e8-b67e-68b33a8535d1_1510x710.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JI3a!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc91d3dec-1cc0-41e8-b67e-68b33a8535d1_1510x710.jpeg 424w, https://substackcdn.com/image/fetch/$s_!JI3a!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc91d3dec-1cc0-41e8-b67e-68b33a8535d1_1510x710.jpeg 848w, https://substackcdn.com/image/fetch/$s_!JI3a!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc91d3dec-1cc0-41e8-b67e-68b33a8535d1_1510x710.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!JI3a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc91d3dec-1cc0-41e8-b67e-68b33a8535d1_1510x710.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://jamanetwork.com/journals/jama/fullarticle/2844764">https://jamanetwork.com/journals/jama/fullarticle/2844764</a></p><div><hr></div><h4>Sign off</h4><p>I was told twice last week that I should consider teaching technology investigations full-time. Maybe. But I fear people wouldn&#8217;t pay to listen to me run my mouth for a day or three. I expect to issue refunds around 2:30PM on the first day.  </p><p>Besides, if I worked for myself, I wouldn&#8217;t get paid time off for bank holidays! </p><p>Have a great week. </p><p>Matt</p><p>matt @ threatswithoutborders.com</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YnbZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3a0b089-c1db-49f9-b286-4f4ce6e58832_1268x1252.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YnbZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3a0b089-c1db-49f9-b286-4f4ce6e58832_1268x1252.jpeg 424w, https://substackcdn.com/image/fetch/$s_!YnbZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3a0b089-c1db-49f9-b286-4f4ce6e58832_1268x1252.jpeg 848w, https://substackcdn.com/image/fetch/$s_!YnbZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3a0b089-c1db-49f9-b286-4f4ce6e58832_1268x1252.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!YnbZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3a0b089-c1db-49f9-b286-4f4ce6e58832_1268x1252.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YnbZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3a0b089-c1db-49f9-b286-4f4ce6e58832_1268x1252.jpeg" width="1268" height="1252" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f3a0b089-c1db-49f9-b286-4f4ce6e58832_1268x1252.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1252,&quot;width&quot;:1268,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:291344,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/188068614?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3a0b089-c1db-49f9-b286-4f4ce6e58832_1268x1252.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YnbZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3a0b089-c1db-49f9-b286-4f4ce6e58832_1268x1252.jpeg 424w, https://substackcdn.com/image/fetch/$s_!YnbZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3a0b089-c1db-49f9-b286-4f4ce6e58832_1268x1252.jpeg 848w, https://substackcdn.com/image/fetch/$s_!YnbZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3a0b089-c1db-49f9-b286-4f4ce6e58832_1268x1252.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!YnbZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3a0b089-c1db-49f9-b286-4f4ce6e58832_1268x1252.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p><p></p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 273]]></title><description><![CDATA[Cybercrime Investigation Newsletter, week ending February 8, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-273</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-273</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 10 Feb 2026 10:47:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lkkz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07f3f957-f680-4ee2-b274-e8ca2ac66a24_600x600.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Over the past week, two separate but critically connected events occurred. </p><p>First, the newsletter saw an unusually high number of unsubscribes. Perhaps I said something last week that offended some readers, or maybe it&#8217;s just the new year's resolution to declutter inboxes. I&#8217;m not sure. </p><p>But for the first time, I just said, Good.  F* you, anyway. I dedicate hours weekly to this newsletter, and if you choose not to read it for free, fine. I don&#8217;t want to share my knowledge and experience with you anyway</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7DcG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb372d436-681e-4785-925f-3557274597d6_1184x318.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7DcG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb372d436-681e-4785-925f-3557274597d6_1184x318.jpeg 424w, https://substackcdn.com/image/fetch/$s_!7DcG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb372d436-681e-4785-925f-3557274597d6_1184x318.jpeg 848w, https://substackcdn.com/image/fetch/$s_!7DcG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb372d436-681e-4785-925f-3557274597d6_1184x318.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!7DcG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb372d436-681e-4785-925f-3557274597d6_1184x318.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7DcG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb372d436-681e-4785-925f-3557274597d6_1184x318.jpeg" width="1184" height="318" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b372d436-681e-4785-925f-3557274597d6_1184x318.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:318,&quot;width&quot;:1184,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:75460,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/187329192?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb372d436-681e-4785-925f-3557274597d6_1184x318.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7DcG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb372d436-681e-4785-925f-3557274597d6_1184x318.jpeg 424w, https://substackcdn.com/image/fetch/$s_!7DcG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb372d436-681e-4785-925f-3557274597d6_1184x318.jpeg 848w, https://substackcdn.com/image/fetch/$s_!7DcG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb372d436-681e-4785-925f-3557274597d6_1184x318.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!7DcG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb372d436-681e-4785-925f-3557274597d6_1184x318.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>And I&#8217;d rather have 50 truly invested readers who value my time and writing than 5000 people who sign up only to mark the newsletter as spam until they eventually figure out the unsubscribe process.</p><p>Terrible attitude, right?  Yeah, I know.</p><p><strong>Secondly, I read &#8220;How to Stop Being Boring&#8221; by JA Westenberg.  </strong></p><blockquote><p><em>I&#8217;ve come to believe that boring = personality edited down to nothing. Somewhere along the way, too many of us learned to sand off our weird edges, to preemptively remove anything that might make someone uncomfortable or make us seem difficult to be around.</em></p><p><em>And the result = boredom.</em></p></blockquote><p>It&#8217;s a powerful conviction about the dangers of self-editing to avoid being different,  offensive, or controversial, and just becoming performative.</p><blockquote><p><em>Erving Goffman wrote in 1959 about how we all perform versions of ourselves depending on context. What's less normal is when the performance becomes the only thing left. When you've been editing yourself for so long that you've forgotten what the original draft looked like.</em></p></blockquote><p>Maybe that&#8217;s it!  What if it&#8217;s not what I&#8217;m saying, but the things that I&#8217;m not saying?  </p><p>Maybe I&#8217;ve just become&#8230; boring.</p><p>Please take two minutes to read this blog post.  </p><p><a href="https://www.joanwestenberg.com/how-to-stop-being-boring/">https://www.joanwestenberg.com/how-to-stop-being-boring/</a></p><p>And let&#8217;s agree to stop being boring!</p><div><hr></div><h4>Wasn&#8217;t me, my iPhone was hacked&#8230;</h4><p>The first question should be, &#8220;Are you a target of a nation-state? North Korea, Iran, or maybe Russia (or maybe the U.S.).&#8221; If the answer is probably not, then the iPhone was probably not hacked. No, the device most definitely wasn&#8217;t hacked.</p><p>Apple released its 2026 <strong>Apple Platform Security</strong> update, so let&#8217;s see if remote access software can be covertly installed on an iPhone. (I do this every year).</p><p>I&#8217;m not referring to a corporate device with Mobile Device Management (MDM) installed, which allows employers to control various functions but remains heavily restricted by Apple.  Even then, the MDM software manager doesn&#8217;t have carte blanche over the device.  And these devices aren&#8217;t getting &#8220;hacked&#8221; either.</p><p>We&#8217;ve all heard the claim: &#8220;Someone must have secretly installed a remote monitoring or remote desktop app on my phone.&#8221; But given Apple&#8217;s security architecture, this isn&#8217;t usually realistic for a personal, unmanaged iPhone.</p><p>Two main points:</p><ol><li><p>Apps can&#8217;t silently install themselves; all code must be signed and installed through Apple-controlled methods.</p></li><li><p>No supported way exists for hidden background installs, drive-by downloads, or invisible services.</p></li></ol><p>If such software exists on the device, it was installed intentionally - usually by the device owner.</p><p>Apple explicitly prevents apps from recording screens without the user's permission. Screen recording needs a user consent prompt before starting. Therefore:</p><ul><li><p>no silent recording</p></li><li><p>no invisible broadcasting</p></li><li><p>no hidden monitoring</p></li></ul><p>The user must approve any such activity.</p><p>And don&#8217;t come at me with &#8220;colluding apps.&#8221; They stopped doing that a long time ago. Apps are sandboxed, so one can&#8217;t directly access another&#8217;s activity unless permissions are strictly approved.</p><p>So when someone says &#8220;It wasn&#8217;t me&#8221; because their device is infected, what really happened is usually:</p><ul><li><p>a password was phished</p></li><li><p>credentials were reused and leaked</p></li><li><p>a fake login page captured information</p></li><li><p>a malicious MFA prompt was approved</p></li><li><p>email or Apple ID was accessed</p></li><li><p>or they were socially engineered</p></li></ul><p>Of course, with Android devices, all bets are off. And if you happen to be in the crosshairs of an elite hacking unit of a government, Google search Pegasus.</p><p><a href="https://help.apple.com/pdf/security/en_US/apple-platform-security-guide.pdf">https://help.apple.com/pdf/security/en_US/apple-platform-security-guide.pdf</a></p><div><hr></div><h4>The News&#8230;</h4><p>Speaking of iPhone security, turns out Lockdown mode is legit.  The FBI could not bypass the security feature to access the internal data of a seized iPhone.  Lockdown Mode is a security feature introduced by Apple in 2022 to protect against sophisticated cyber attacks. While the FBI extracted limited data from the SIM card, the iPhone&#8217;s Lockdown Mode restricted access to most apps, websites, and features. <a href="https://arstechnica.com/tech-policy/2026/02/fbi-stymied-by-apples-lockdown-mode-after-seizing-journalists-iphone/">https://arstechnica.com/tech-policy/2026/02/fbi-stymied-by-apples-lockdown-mode-after-seizing-journalists-iphone/</a></p><p>A former Pennsylvania State Police corporal and compliance director for the skill games company Pace-O-Matic has pleaded guilty to money laundering and tax fraud after accepting hundreds of thousands of dollars in kickbacks from illegal gambling machine operators. The man used his position to suppress complaints about illegal gaming machines and falsely claimed the proceeds as business expenses to evade over $100,000 in taxaccepting hundreds of thousands of dollars in kickbacks from illegal gambling machine operators. He suppressed complaints about illegal gaming machines and falsely claimed the proceeds as business expenses to evade over $100,000 in taxes. <a href="https://www.attorneygeneral.gov/taking-action/former-executive-of-pace-o-matic-pleads-guilty-to-money-laundering-payments-from-gaming-machine-operators/">https://www.attorneygeneral.gov/taking-action/former-executive-of-pace-o-matic-pleads-guilty-to-money-laundering-payments-from-gaming-machine-operators/</a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fLiO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec9002ca-1ab7-4c2a-9d08-2dc1ed23ae73_1096x471.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fLiO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec9002ca-1ab7-4c2a-9d08-2dc1ed23ae73_1096x471.webp 424w, https://substackcdn.com/image/fetch/$s_!fLiO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec9002ca-1ab7-4c2a-9d08-2dc1ed23ae73_1096x471.webp 848w, https://substackcdn.com/image/fetch/$s_!fLiO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec9002ca-1ab7-4c2a-9d08-2dc1ed23ae73_1096x471.webp 1272w, https://substackcdn.com/image/fetch/$s_!fLiO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec9002ca-1ab7-4c2a-9d08-2dc1ed23ae73_1096x471.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fLiO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec9002ca-1ab7-4c2a-9d08-2dc1ed23ae73_1096x471.webp" width="1096" height="471" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ec9002ca-1ab7-4c2a-9d08-2dc1ed23ae73_1096x471.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:471,&quot;width&quot;:1096,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fLiO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec9002ca-1ab7-4c2a-9d08-2dc1ed23ae73_1096x471.webp 424w, https://substackcdn.com/image/fetch/$s_!fLiO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec9002ca-1ab7-4c2a-9d08-2dc1ed23ae73_1096x471.webp 848w, https://substackcdn.com/image/fetch/$s_!fLiO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec9002ca-1ab7-4c2a-9d08-2dc1ed23ae73_1096x471.webp 1272w, https://substackcdn.com/image/fetch/$s_!fLiO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec9002ca-1ab7-4c2a-9d08-2dc1ed23ae73_1096x471.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Sublime Security details a specific phishing scheme targeting real estate agents, where scammers impersonate prospective clients via contact forms or direct contact. They gradually earn the agents' trust through credible-sounding conversations, then deceive them into joining fake Zoom calls. These malicious &#8220;meeting links' often use lookalike domains such as webzoom[.]im instead of zoom[.]us, which download remote access tools like ScreenConnect, granting attackers control over the victim&#8217;s computer. This campaign is distinguished by its sophisticated social engineering tactics, including multi-message dialogues to build credibility before deploying malware. Additionally, the attackers prefer to host the meetings themselves rather than pass legitimate links to the agents.</p><p>I had always believed that cryptocurrency and gift cards were the preferred methods for criminals to move dirty money. However, according to this author, the latest trend seems to be watches and designer handbags. <a href="https://www.thetimes.com/culture/books/article/everybody-loves-our-dollars-how-money-laundering-won-oliver-bullough-review-z3p2wbf03">https://www.thetimes.com/culture/books/article/everybody-loves-our-dollars-how-money-laundering-won-oliver-bullough-review-z3p2wbf03</a></p><p>An Illinois man admitted guilt for hacking nearly 600 women&#8217;s Snapchat accounts from May 2020 to February 2021, stealing nude photos that he then kept, sold, or traded online. He employed social engineering tactics, impersonating Snapchat representatives to trick more than 4,500 victims into revealing their access codes. This strategy led to the compromise of about 570 victims&#8217; credentials and the illegal access to at least 59 accounts without authorization per<a href="https://storage.courtlistener.com/recap/gov.uscourts.mad.293918/gov.uscourts.mad.293918.1.0.pdf">https://storage.courtlistener.com/recap/gov.uscourts.mad.293918/gov.uscourts.mad.293918.1.0.pdf</a></p><p>Is this Irony?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NLwr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0a2df17-6922-42bb-81b2-bf5e6ec480d6_984x436.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NLwr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0a2df17-6922-42bb-81b2-bf5e6ec480d6_984x436.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NLwr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0a2df17-6922-42bb-81b2-bf5e6ec480d6_984x436.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NLwr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0a2df17-6922-42bb-81b2-bf5e6ec480d6_984x436.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NLwr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0a2df17-6922-42bb-81b2-bf5e6ec480d6_984x436.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NLwr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0a2df17-6922-42bb-81b2-bf5e6ec480d6_984x436.jpeg" width="984" height="436" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a0a2df17-6922-42bb-81b2-bf5e6ec480d6_984x436.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:436,&quot;width&quot;:984,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:86891,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/187329192?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0a2df17-6922-42bb-81b2-bf5e6ec480d6_984x436.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NLwr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0a2df17-6922-42bb-81b2-bf5e6ec480d6_984x436.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NLwr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0a2df17-6922-42bb-81b2-bf5e6ec480d6_984x436.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NLwr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0a2df17-6922-42bb-81b2-bf5e6ec480d6_984x436.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NLwr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0a2df17-6922-42bb-81b2-bf5e6ec480d6_984x436.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I think this is irony.</p><p>Google search is offering up links to download malware for macOS.  <a href="https://eclecticlight.co/2026/01/30/more-malware-from-google-search/">https://eclecticlight.co/2026/01/30/more-malware-from-google-search/</a></p><div><hr></div><h4>Cool Job</h4><p>Director of Fraud Prevention - TopStep.  <a href="https://job-boards.greenhouse.io/topsteptrader/jobs/7615888003">https://job-boards.greenhouse.io/topsteptrader/jobs/7615888003</a></p><h4>Cool Tool</h4><p>Your target may not have an online presence but their relatives might.  <a href="https://www.familytreenow.com/">https://www.familytreenow.com/</a></p><p>theHarvester is a very simple, yet effective tool designed to be used in the early<br>stages of a penetration test. Use it for open source intelligence gathering and helping<br>to determine a company's external threat landscape on the internet. The tool gathers<br>emails, names, subdomains, IPs, and URLs.  <a href="https://pypi.org/project/theHarvester/">https://pypi.org/project/theHarvester/</a></p><div><hr></div><h4>Be Alert</h4><p>Yeah, so, Substack had a little oopsie and lost some user data. They claim to have notified affected users, but it seems the breach is much larger than initially acknowledged.</p><p>The good thing, if there is such a thing, when it comes to losing user information, is that it doesn&#8217;t appear that the scraped data would enable account takeovers.</p><p>As this HackRead <strong><a href="https://hackread.com/substack-breach-user-records-leak-cybercrime-forum/">article</a></strong> notes, the real danger is from a social engineering attack by someone pretending to be Substack and referencing your account. </p><div><hr></div><h4>Irrelevant</h4><p>Being successful isn&#8217;t random.  <a href="https://dariusforoux.com/the-big-5-predictors-of-success/">https://dariusforoux.com/the-big-5-predictors-of-success/</a></p><div><hr></div><h4>Learning</h4><p>The Delaware Fraud Working Group is sponsoring a full-day training event on April 2, 2026, in Wilmington, Delaware.  Best of all, it&#8217;s FREE.  </p><p>No, even better, I&#8217;m speaking.  </p><p><a href="https://www.eventbrite.com/e/delaware-fraud-working-group-full-day-fraud-prevention-summit-tickets-1982375409213">https://www.eventbrite.com/e/delaware-fraud-working-group-full-day-fraud-prevention-summit-tickets-1982375409213</a></p><div><hr></div><h4>Sign Off</h4><p>Someone suggested I do that viral thing where you ask ChatGPT to make a caricature of you and post it to LinkedIn. Ugh, I&#8217;d rather stick a fork in my face. </p><p>So I asked ChatGPT to create that image instead.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BYFp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57a253f1-1c9a-4068-8fd6-248d35450e49_1604x570.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BYFp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57a253f1-1c9a-4068-8fd6-248d35450e49_1604x570.jpeg 424w, https://substackcdn.com/image/fetch/$s_!BYFp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57a253f1-1c9a-4068-8fd6-248d35450e49_1604x570.jpeg 848w, https://substackcdn.com/image/fetch/$s_!BYFp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57a253f1-1c9a-4068-8fd6-248d35450e49_1604x570.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!BYFp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57a253f1-1c9a-4068-8fd6-248d35450e49_1604x570.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BYFp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57a253f1-1c9a-4068-8fd6-248d35450e49_1604x570.jpeg" width="1456" height="517" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/57a253f1-1c9a-4068-8fd6-248d35450e49_1604x570.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:517,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:116646,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/187329192?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57a253f1-1c9a-4068-8fd6-248d35450e49_1604x570.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BYFp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57a253f1-1c9a-4068-8fd6-248d35450e49_1604x570.jpeg 424w, https://substackcdn.com/image/fetch/$s_!BYFp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57a253f1-1c9a-4068-8fd6-248d35450e49_1604x570.jpeg 848w, https://substackcdn.com/image/fetch/$s_!BYFp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57a253f1-1c9a-4068-8fd6-248d35450e49_1604x570.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!BYFp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57a253f1-1c9a-4068-8fd6-248d35450e49_1604x570.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Too bad, that wouldn&#8217;t be boring.</p><p>Thanks for reading another week.  Come back next week to see if I write something useful.</p><p>Matt</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p>]]></content:encoded></item><item><title><![CDATA[Threats Without Borders - Issue 272]]></title><description><![CDATA[Cybercrime Investigation Newsletter, week ending February 1, 2026]]></description><link>https://www.threatswithoutborders.com/p/threats-without-borders-issue-272</link><guid isPermaLink="false">https://www.threatswithoutborders.com/p/threats-without-borders-issue-272</guid><dc:creator><![CDATA[Matt Dotts]]></dc:creator><pubDate>Tue, 03 Feb 2026 09:58:59 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gnGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec11d95e-ced3-4599-874c-6076838cd6ca_800x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>When so many organizations hide their reports behind information-collection barriers that require you to give away your professional contact information and then endure relentless sales calls&#8230; TRM Labs continues to share its knowledge freely and openly. And they don&#8217;t publish a vanilla product that simply rehashes common industry knowledge.  </p><p>TRM Labs' 2026 Crypto Crime Report shows illicit crypto flows hit a record $158 billion in 2025, ending a multi-year decline. This rise was mainly due to three factors: new sanctions designations, better detection tools, and large hacks like the $1.46 billion Bybit breach. Despite the overall increase, illicit activity as a share of total crypto activity fell to 1.2%, suggesting that legitimate crypto use expanded faster than criminal activity. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Dlk1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c57e1e9-f23e-46e3-824b-97e3ef65a28e_1690x936.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Dlk1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c57e1e9-f23e-46e3-824b-97e3ef65a28e_1690x936.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Dlk1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c57e1e9-f23e-46e3-824b-97e3ef65a28e_1690x936.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Dlk1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c57e1e9-f23e-46e3-824b-97e3ef65a28e_1690x936.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Dlk1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c57e1e9-f23e-46e3-824b-97e3ef65a28e_1690x936.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Dlk1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c57e1e9-f23e-46e3-824b-97e3ef65a28e_1690x936.jpeg" width="1456" height="806" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9c57e1e9-f23e-46e3-824b-97e3ef65a28e_1690x936.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:806,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:118712,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/186552679?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c57e1e9-f23e-46e3-824b-97e3ef65a28e_1690x936.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Dlk1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c57e1e9-f23e-46e3-824b-97e3ef65a28e_1690x936.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Dlk1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c57e1e9-f23e-46e3-824b-97e3ef65a28e_1690x936.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Dlk1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c57e1e9-f23e-46e3-824b-97e3ef65a28e_1690x936.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Dlk1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c57e1e9-f23e-46e3-824b-97e3ef65a28e_1690x936.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The report highlights how state-aligned actors are institutionalizing crypto infrastructure for sanctions evasion, how ransomware and scam operations have become more sophisticated and organized, and how Chinese money-laundering networks have evolved into massive settlement layers that process over $103 billion. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3rKX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4ae919b-ca07-4369-8157-e5e691c42ff5_1690x896.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3rKX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4ae919b-ca07-4369-8157-e5e691c42ff5_1690x896.jpeg 424w, https://substackcdn.com/image/fetch/$s_!3rKX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4ae919b-ca07-4369-8157-e5e691c42ff5_1690x896.jpeg 848w, https://substackcdn.com/image/fetch/$s_!3rKX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4ae919b-ca07-4369-8157-e5e691c42ff5_1690x896.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!3rKX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4ae919b-ca07-4369-8157-e5e691c42ff5_1690x896.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3rKX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4ae919b-ca07-4369-8157-e5e691c42ff5_1690x896.jpeg" width="1456" height="772" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d4ae919b-ca07-4369-8157-e5e691c42ff5_1690x896.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:772,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:113246,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.threatswithoutborders.com/i/186552679?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4ae919b-ca07-4369-8157-e5e691c42ff5_1690x896.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3rKX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4ae919b-ca07-4369-8157-e5e691c42ff5_1690x896.jpeg 424w, https://substackcdn.com/image/fetch/$s_!3rKX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4ae919b-ca07-4369-8157-e5e691c42ff5_1690x896.jpeg 848w, https://substackcdn.com/image/fetch/$s_!3rKX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4ae919b-ca07-4369-8157-e5e691c42ff5_1690x896.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!3rKX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4ae919b-ca07-4369-8157-e5e691c42ff5_1690x896.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The findings highlight that crypto crime has become a core part of both legitimate and illicit financial systems, emphasizing the need for improved enforcement coordination and specialized crypto-investigation tools.</p><p>This is a great report and well worth your time to read and digest.  </p><p><a href="https://www.trmlabs.com/reports-and-whitepapers/2026-crypto-crime-report">https://www.trmlabs.com/reports-and-whitepapers/2026-crypto-crime-report</a></p><div><hr></div><h4>Because like security, duh.</h4><p>I debated how to title this:  &#8220;<strong>Because we suck at security</strong>&#8221; or &#8220;<strong>This is why you respond to every alarm</strong>&#8221;.</p><p>A federal grand jury indicted 31 people for stealing millions from ATMs using Ploutus malware. The gang surveilled ATMs, opened them to test alarms, and replaced hard drives or connected thumb drives with malware to dispense cash.</p><p>Two key points: 1) The attackers forced open the ATMs and then retreated to safety. If police arrived, they fled the scene. They continued the attack if there was no police response. 2) Ploutus malware has been active since 2013. Yes, thirteen years ago. While it has evolved, technology and protections exist to prevent it.  </p><p>And it isn&#8217;t a stealthy attack.  It&#8217;s a physical intrusion into the machine.  It&#8217;s noisy and makes a mess.  Here is an <strong><a href="https://cloud.google.com/blog/topics/threat-intelligence/new-ploutus-variant">article </a></strong>the Google Threat Intelligence Team published in 2017 that explains the effort required to attack an ATM with Ploutus.</p><p>These types of attacks are preventable.  Of course, we suck at security.</p><p>Anyways, kudos to the law enforcement teams that coordinated to shut this group down.</p><p><a href="https://www.justice.gov/opa/pr/investigation-international-atm-jackpotting-scheme-and-tren-de-aragua-results-additional">https://www.justice.gov/opa/pr/investigation-international-atm-jackpotting-scheme-and-tren-de-aragua-results-additional</a></p><div><hr></div><h4>Presenter Pro-Tip</h4><p>When speaking to industry peers about a relevant topic, avoid wasting time explaining "how bad it is&#8221;. They already know. Being on the front lines, they recognize the problem; that's why they're listening to you.  </p><p>Unless you&#8217;re speaking to beginners, a non-peer group, or presenting entirely new material based on your own research, avoid starting with five slides filled with numbers and statistics about the problem&#8217;s prevalence. By the time you finish outlining the industry landscape, most of your audience&#8217;s attention will have drifted.   And honestly, it&#8217;s insulting.  </p><p>I sat through a presentation this week in which the speaker spent the first ten minutes highlighting well-known fraud statistics from regularly cited sources like the Internet Crime Complaint Center. You're speaking to an audience of financial crime investigators. It&#8217;s ugly out there&#8212;we get it. That&#8217;s why we&#8217;re willing to give you thirty minutes of our time. Tell us something we don&#8217;t know!</p><div><hr></div><h4>The News&#8230;</h4><p>$2.5 million has been secured for a new cybercrime training facility in Madisonville, Kentucky. The facility, the largest police training academy in the state, will focus on cybercrime investigations and expand training to include computers, drones, and vehicle data systems. The investment aims to address the growing threat of cybercrime and position Madisonville as a leader in prevention and response. Kudos to them.  Hopefully, someone there will invite me for a visit!  <a href="https://spectrumnews1.com/ky/louisville/news/2026/01/26/cyber-crime-training-center">https://spectrumnews1.com/ky/louisville/news/2026/01/26/cyber-crime-training-center</a></p><p>Scammers are using a legitimate Microsoft email address (no-reply-powerbi@microsoft.com) associated with Power BI. They send fraudulent emails claiming fake $399 charges and direct victims to call a phone number, where they are instructed to install remote access software. This scam exploits Power BI&#8217;s feature that allows external email addresses to subscribe to reports, making the emails appear trustworthy without suspicious links or attachments that could trigger spam filters. Microsoft has temporarily disabled the scorecard email subscription feature while working on a permanent fix. This incident underscores how scammers can misuse legitimate business platforms to enhance the credibility of their social engineering schemes.  <a href="https://arstechnica.com/information-technology/2026/01/theres-a-rash-of-scam-spam-coming-from-a-real-microsoft-address/">https://arstechnica.com/information-technology/2026/01/theres-a-rash-of-scam-spam-coming-from-a-real-microsoft-address/</a></p><p>Research by Chainalysis reveals Chinese-language money laundering groups laundered an estimated $16.1 billion in illicit cryptocurrency daily in 2025, totaling $82 billion annually. These groups utilize guarantee platforms, money mules, and Black U services to launder funds, including those stolen in <s>pig butchering</s> financial grooming scams.  <a href="https://www.chainalysis.com/blog/2026-crypto-money-laundering/">https://www.chainalysis.com/blog/2026-crypto-money-laundering/</a></p><p>The Google Threat Analysis Group (TAG) released its 4Q2025 Threat Report.  <a href="https://blog.google/threat-analysis-group/tag-bulletin-q4-2025/">https://blog.google/threat-analysis-group/tag-bulletin-q4-2025/</a></p><p>The FBI has seized the domains for the RAMP cybercrime forums.  <a href="https://www.bleepingcomputer.com/news/security/fbi-seizes-ramp-cybercrime-forum-used-by-ransomware-gangs/">https://www.bleepingcomputer.com/news/security/fbi-seizes-ramp-cybercrime-forum-used-by-ransomware-gangs/</a></p><p>Trend Micro examines the maturation of criminal AI in 2025, revealing a shift from experimentation to industrialization. The criminal AI ecosystem has consolidated around established services offering &#8220;jailbreak-as-a-service&#8221; that exploit commercial AI models rather than building independent systems.  While AI-generated malware remains limited by practical constraints, deepfake technology has become alarmingly accessible and weaponized across multiple fronts,from &#8220;nudifying&#8221; apps enabling image-based abuse to sophisticated corporate infiltration schemes where North Korean operatives use AI-enhanced identities to gain employment at tech companies, and banking fraud targeting KYC verification systems.  <a href="https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/the-state-of-criminal-ai">https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/the-state-of-criminal-ai</a></p><p>The government seized over $400 million in assets from Larry Dean Harmon, operator of the darknet mixing service Helix. Harmon, who processed over $300 million in cryptocurrency transactions for Helix, pleaded guilty to money laundering and was sentenced to 36 months in prison.  <a href="https://www.justice.gov/opa/pr/government-forfeits-over-400m-assets-tied-helix-darknet-cryptocurrency-mixer">https://www.justice.gov/opa/pr/government-forfeits-over-400m-assets-tied-helix-darknet-cryptocurrency-mixer</a></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share Threats Without Borders&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.threatswithoutborders.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share Threats Without Borders</span></a></p><div><hr></div><h4>Reader Mail</h4><p><em>Matt, thanks for the piece on paste sites. It brought back memories of an insider threat (corporate espionage) case I had about ten years ago, in which the employee used a paste site to send information to his handler. Using a prepaid cell phone, he&#8217;d paste his info into the same note every Tuesday. The handler would then go to the same note to retrieve the information. This was way before encrypted chat apps. We could never build a link to those he was communicating with.  - </em>RussK</p><p>Send email:  matt (at) threatswithoutborders.com </p><div><hr></div><h4>Cool Job</h4><p>Fraud Program Manager - Vervent.  <a href="https://recruiting.paylocity.com/recruiting/jobs/Details/3821568/Vervent-Inc/Fraud-Program-Manager">https://recruiting.paylocity.com/recruiting/jobs/Details/3821568/Vervent-Inc/Fraud-Program-Manager</a></p><h4>Cool Tool</h4><p>Search for people, Fast. <a href="https://www.fastpeoplesearch.com/"> https://www.fastpeoplesearch.com/</a></p><p>If Wal-Mart is closed, you know the weather is bad.  Someone created a Wal-Mart store status dashboard.  <a href="https://www.arcgis.com/apps/dashboards/4e573c79e1224081805165d25b4f33c7">https://www.arcgis.com/apps/dashboards/4e573c79e1224081805165d25b4f33c7</a></p><div><hr></div><h4>Someone I like</h4><p>There are not many people writing or podcasting in the Cyber/Fraud/AML space who I like enough to recommend in the newsletter. Check that, there are very few people that I like.  </p><p>But I like Sarah Beth Felix!  She writes a great LinkedIn newsletter focused on BSA and AML, titled &#8220;Dirty Money&#8221;.  Give her a follow.</p><p><a href="https://www.linkedin.com/pulse/problem-streamline-act-sarah-beth-felix-uxt7e/">https://www.linkedin.com/pulse/problem-streamline-act-sarah-beth-felix-uxt7e/</a></p><div><hr></div><h4>Irrelevant </h4><p>Sunshine and Salmon.   This study reveals that positive levels of Vitamin D and Omega-3 have a greater effect on a person than antidepressants.  <a href="https://blog.ncase.me/on-depression/">https://blog.ncase.me/on-depression/</a></p><div><hr></div><h4>Closing</h4><p>I wake up every morning at 5am. The other day, at 5 am, I started a pot of coffee. It was 12 degrees outside, and I heard the fire siren go off. I thought, &#8216;I&#8217;m glad I don&#8217;t need to leave this warm house and hot coffee to handle that.&#8217; But, of course, someone did have to go out and handle it. And in my area, these selfless souls don&#8217;t get paid for it.</p><p>My deepest thanks to all the local emergency services volunteers who leave the comfort and safety of their homes, and a freshly poured cup of hot coffee, every day to help others. Thank you!</p><p>Matt</p><div><hr></div><p>Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.threatswithoutborders.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Threats Without Borders! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn&#8217;t represent the official viewpoint of my employer or any associated organization. Blame me, not them.</p><p>aml cybercrime cybersecurity financial fraud investigation osint cyficrime </p>]]></content:encoded></item></channel></rss>