Threats Without Borders - Issue 296
Cybercrime Investigation Newsletter, week ending July 19, 2026
Block, Cash App’s parent company, has reached a $45 million settlement to resolve a multi-state investigation into its fraud protection measures. 46 of the fifty states were listed as plaintiffs. The probe examined whether the company adequately safeguarded users against fraud, and the settlement aims to address these concerns without an admission of wrongdoing. https://www.reuters.com/legal/government/cash-app-parent-settles-states-probe-over-fraud-protections-45-million-2026-07-08/
Of course, this brings about a common question I get asked, “What is the difference between the various Peer-to-Peer apps?”. Or the most common, “What’s the difference between Zelle and the other P2P apps?”
Venmo, Cash App, PayPal, Apple Cash and other digital wallet apps create a “stored-value” account. When someone sends you money, it lands in the app’s internal ecosystem, not your bank account. The money stays there until you manually initiate a transfer to your bank.
Zelle is not a wallet and maintains no internal balance. It is owned by a consortium of major banks, operating under the business name Early Warning Services. When a Zelle transfer occurs, it moves funds directly from the sender’s checking account to the recipient’s checking account via the banks’ internal clearing networks.
A great explainer of the services that I keep bookmarked is this NerdWallet article: https://www.nerdwallet.com/banking/learn/peer-to-peer-p2p-money-transfers
Like Textbooks
Regular readers know I advocate studying the affidavits of both arrest and search warrants of significant cybercrime investigations. Fortunately, the suspects don’t share this view, as these literal “textbooks” reveal extensive investigative insights and tips.
Earlier this month, a member of the “Scattered Spider” cybercrime group was arrested and extradited to the United States. The criminal complaint is insightful to say the least, and Tom Kopchak from Hurricane Labs analyzes the affidavit to highlight how extensively Microsoft Windows tracks its users. Clearly, Microsoft doesn’t activate these features for criminal investigations, but good investigators never say no to free evidence.
Some of the highlights include:
Microsoft’s Global Device ID (GDID) is a persistent identifier that tracks devices across networks and services
Investigators correlated multiple accounts, social media profiles, and cloud services using these embedded device identifiers
The complaint revealed that Windows users are tracked through persistent identifiers regardless of VPN use or network changes
https://hurricanelabs.com/blog/the-doj-just-proved-that-windows-is-spying-on-you/
Waiting on the call
Oklahoma created a new statewide fraud and cybercrime unit to investigate AI-enabled scams and cryptocurrency fraud, and to strengthen law enforcement efforts to address these issues across the state.
The commander of the new unit specified one duty of the team will be training: “York said the unit will provide specialized training for police departments and prosecutors throughout the state, helping frontline officers recognize cyber-enabled fraud and collect the evidence necessary for successful investigations.”
What are we waiting for, Pennsylvania? Call me.
https://oklahoma.gov/osbi/about/inside-the-bureau/osbi-fraud-and-cybercrime-unit.html
The News
Flashpoint’s Intel Team explains that the “dark web” is not a single marketplace but a complex, interconnected supply chain of specialized forums organized into a three-tiered ecosystem based on entry barriers, technical expertise, trade quality, and operational security. Low-tier forums are easily accessible hubs for novices sharing low-cost data and tools, while mid-tier forums require some vetting and focus on large-scale fraud like carding and malware distribution with built-in reputation systems. Top-tier forums are exclusive, invitation-only platforms where professional threat actors trade high-value assets like zero-day exploits and ransomware-as-a-service partnerships. https://flashpoint.io/blog/understanding-illicit-ecosystems-dark-web-forums-cybercrime/
No milk for you! Coca-Cola’s Fairlife dairy subsidiary was hit by a ransomware attack, temporarily suspending production operations across the United States. https://techcrunch.com/2026/07/16/coca-cola-suspended-production-at-its-fairlife-dairy-after-a-ransomware-attack/
A data breach at AssuranceAmerica exposed the personal data and license numbers of 6.9 million drivers. The company has confirmed the breach, which resulted from malicious activity targeting an employee and included sensitive information such as contact details, insurance information, and claims records. https://www.documentcloud.org/documents/28433184-assuranceamerica-data-breach-notice/#document/p5
Point Wild exposed that the Phorpiex botnet has been repurposed for a global sextortion spam campaign. The extortionists use the infrastructure to send “We infection your device and have been recording you” emails. They demand cryptocurrency in exchange for “delete everything”. https://www.pointwild.com/threat-intelligence/phorpiex-inside-the-botnet-powering-global-sextortion-spam-operations/
“Macs don’t get malware.” Ah, yes they do, and the Moonlock mid-2026 Threat Report details the current state of macOS malware. https://moonlock.com/mid-2026-macos-threat-report
Q2 Ransomware Report from ReliaQuest. https://reliaquest.com/blog/threat-spotlight-ransomware-and-cyber-extortion-in-q2-2026/
The Internet Crime Complaint Center (IC3) issued a warning about scammers impersonating the Internet Crime Complaint Center. They suggest you report criminal impersonations to the - Internet Crime Complaint Center.
https://www.ic3.gov/PSA/2026/PSA260720
Feedback
Send Feedback to matt(at)threatswithoutborders.com
dfir
Magnet Forensics filed a lawsuit against a former employee who left with information about a proprietary exploit available for the Graykey tool and leaked it on a blog for his new company, Paradigm Shift. https://www.courtlistener.com/docket/73584326/magnet-forensics-llc-v-del-gaudio/
Cool Jobs
Lead Risk Investigator, Tilt. https://jobs.ashbyhq.com/tilthq/8663dae9-4bc2-4485-b6cd-077701077c3f
Vice-President of Cybersecurity Strategy and Engagement, Mastercard. https://careers.mastercard.com/us/en/job/MASRUSR281394EXTERNALENUS/Vice-President-Cybersecurity-Strategy-and-Engagement
Cool Tools
Monitor online prices and get alerts when prices drop. (You can monitor 3 products for free). https://spycost.com/en
LookyLoo is a web interface that captures a webpage and then displays a tree of the domains that call each other. https://lookyloo.circl.lu/capture
Irrelevant
The OnePlus 5 was possibly the most impactful smartphone I've ever owned. It featured excellent hardware and a sleek version of Android known as OxygenOS. This custom OS demonstrated Android's potential when all the unnecessary bloatware installed by the phone companies was removed. I quickly upgraded to the 5T, then the 7, before switching back to iOS to be fully integrated in the Apple ecosystem. Over time, however, OnePlus lost its way and is now ceasing operations in North America and Europe. https://community.oneplus.com/thread/2170715118587871237
Sign Off
I wish I had a purpose for all these AI Agents everyone is using. I want to experiment, learn, and make them work for me, but I haven't found a real use case. I read, write, talk, attend meetings, keep a calendar, and manage a to-do list. I receive some emails and respond to some. Yet, at no point in my daily routine have I ever felt overwhelmed to the point I need to implement automation. Using several AI tools has boosted my effectiveness and productivity, but I haven't found a genuine reason to integrate agents into my workflows.
Thanks for reading another issue and I’ll see you all next Tuesday!
Matt
Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.
Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn’t represent the official viewpoint of my employer or any associated organization. Blame me, not them.
cybercrime cybersecurity investigations financial crime fraud osint cyficrime


