Threats Without Borders - Issue 297
Cybersecurity Investigation Newsletter, week ending July 26, 2026
If you can dodge a wrench, you can dodge a ball... maybe not.
The term “wrench attacks,” referring to physical coercion to steal cryptocurrencies, increased by 33% in the first half of 2026 compared to the previous year, with losses reaching $124 million. This CertiK report states that these incidents involve violence, intimidation, or threats against victims or their loved ones, such as spouses, children, or employees, to force them to hand over digital assets, private keys, or wallet access.
The Europeans need to learn how to dodge a wrench.
https://www.certik.com/certik-report/intel3d/intel3d-wrench-h1-2026
This will be fine…
Shawn Ryan, the podcaster, partnered to create a privacy and security-focused communications app that promises to:
Make calls anonymously - Private calling keeps your number hidden and your conversations untraceable—so your identity always stays protected
I hope they have their legal demand response team fully staffed.
https://www.theglacierapp.com/#intro
Nothing is new under the sun…
Once, a long time ago, I worked as an unloader on the UPS docks. We had to move around 800 packages per hour and yes, they audited us. It was a terrible job, and I only lasted about six months.
One night, the police arrived and arrested several people involved in a scheme where they placed their own delivery labels over authentic ones to redirect packages to themselves.
Brilliant, I thought, considering how easy it would be to bring labels with my address into the truck and stick them on some Sharper Image boxes. Of course, I didn’t do it, and a few months later, I realized I wasn’t made for physical labor.
A criminal gang in Tennessee demonstrates that everything that goes around comes around again. Twelve individuals have been indicted for their role in stealing at least $2 million worth of Nike products from Nike’s North American Logistics Center in Memphis between July 2021 and June 2024.
How were they doin it… “the defendants would identify product that they wanted to resell, locate it in the Nike warehouse, and place shipping labels to predetermined locations throughout the United States where they would retrieve and resell the stolen product.”
The News
Device code phishing attacks are all the rage, and this TrustedSec breakdown explains the technique's mechanics. https://trustedsec.com/blog/the-new-hotness-in-phishing-device-code-attacks-in-m365
The Microsoft Q2 Trends and Insights Report again proves that email is your number one threat vector. The company detected 7.6 billion email-based phishing messages in the quarter. But Teams-based phishing attacks gained traction, with significant increases in both DMs and Calls, and the most prominent lure was impersonation of technical support. https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/
The cyber threat group name game is a mess, so the Google Threat Intelligence Group is adopting a unified naming schema to track threat actors for a more intuitive, standardized approach. This new system replaces the previous parallel naming schemas used by Mandiant and Google’s Threat Analysis Group. OK, but it would be better if the industry reached a collective agreement. https://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-system/
A Louisiana man was convicted of wire fraud, access device fraud, and obstruction of a federal investigation for defrauding two churches he led, obtaining over $340,000 for personal use and obstructing a federal investigation. https://www.justice.gov/usao-edla/pr/pastor-found-guilty-jury-wire-fraud-access-device-fraud-and-obstruction-federal
I’m not sure what triggered a new alert, but this is a well-known, documented fraud problem. Maybe it’s the utilization of AI tools? FinCEN issued an alert warning financial institutions about fraud rings targeting Federal Student Aid programs through “ghost students” (stolen or synthetic identities) and “straw students” (complicit individuals paid to enroll fraudulently). These schemes are known to involve AI-generated documents and AI-powered chatbots to complete coursework, have resulted in significant losses, with the Department of Education preventing over $1 billion in fraud in 2025 alone. https://www.fincen.gov/system/files/2026-07/FinCEN-Alert-Fraud-Schemes-Targeting-Federal-Student-Aid.pdf
What’s the Pope know about security? Probably not much, but the company running his prayer app seems to know even less since it’s been leaking user data “for months”. https://san.com/cc/the-popes-prayer-app-has-been-leaking-its-users-info-for-months/
There is an absurd number of security updates and patches in the upcoming macOS 26.6 release. The effects of AI-enabled security research. For the better, I suppose. https://support.apple.com/en-us/128067
Feedback
Send Feedback to matt(at)threatswithoutborders.com
dfir
Seth Enoka examines persistence on the Windows OS. https://sethenoka.com/persistence-artefacts-services-scheduled-tasks-and-intentional-longevity/
No Subscriptions. No ads. No paid endorsements. The snark is free. And we keep our selfies out of your LinkedIn feed. How about giving us a share!
Cool Jobs
Senior Manager of Fraud Risk Mitigation, Paylocity. https://2000recruiting.paylocity.com/Recruiting/Jobs/Details/46419
Senior Manager of Global Fraud Strategy, Live Nation/Ticketmaster. https://livenation.wd503.myworkdayjobs.com/en-US/TMExternalSite/job/Work-From-Home---Texas/Senior-Manager--Global-Fraud-Strategy_JR-91628
Cool Tools
Search usernames across 3000 different platforms https://usersearch.org/index.php
For those of us iPhone users who need to take pills to keep living. https://apps.apple.com/us/app/medication-tracker-dosis/id6758015175
Irrelevant
Are autonomous vehicles or Uber drivers more dangerous on the road? https://www.city-journal.org/article/autonomous-cars-uber-lyft-drivers-taxis-safety
Sign Off
You still have time to plan your travel to attend the 2026 IAFCI International Training Conference, being held in Nashville, August 25-27, 2026. A little time in Nash-Vegas is always great for the spirit, and you’ll probably meet some great people at the conference.
Thanks for reading another week, and I’ll see you all next Tuesday.
Matt
Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.
Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn’t represent the official viewpoint of my employer or any associated organization. Blame me, not them.


