Critical

Police bust cybercrime ring accused of stealing €30 million in four-day spree

Help Net Security
Actively Exploited

Overview

German and Brazilian police recently dismantled a cybercrime ring linked to a €30 million bank fraud that targeted a German financial institution. The operation, named 'Klonen,' led to the arrest of four suspects in Brazil, with additional suspects being pursued in Spain and Bulgaria. The investigation began in late 2023 after attackers exploited a flaw in the booking process of the bank. On August 13, law enforcement executed 21 search warrants across several Brazilian cities, including Rio de Janeiro and Goiânia. This incident underscores the ongoing risks of cybercrime, especially in the banking sector, and highlights the need for stronger security measures to protect financial institutions from sophisticated attacks.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: German financial institution
  • Action Required: Strengthen security protocols, conduct regular audits of booking processes, and implement advanced monitoring systems.
  • Timeline: Ongoing since late 2023

Original Article Summary

German and Brazilian police dismantled an international bank fraud ring blamed for a €30 million cyberattack on a German financial institution, arresting four people in Brazil and pursuing three more suspects in Spain and Bulgaria. Brazilian police named the operation “Klonen.” On August 13, agents executed 21 search-and-seizure warrants across seven cities, including Rio de Janeiro, Goiânia, and Guarulhos. The case traces back to late 2023, when attackers exploited a flaw in the booking process … More → The post Police bust cybercrime ring accused of stealing €30 million in four-day spree appeared first on Help Net Security.

Impact

German financial institution

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Ongoing since late 2023

Remediation

Strengthen security protocols, conduct regular audits of booking processes, and implement advanced monitoring systems.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Coverage

40,000 Impacted by SafePal Data Breach

SecurityWeek

SafePal, a cryptocurrency wallet provider, has reported a data breach that has affected approximately 40,000 customers. Hackers took advantage of a vulnerability found in the order-tracking feature of a plugin, allowing them to access sensitive customer information. This breach raises significant concerns for users, as it may expose personal data and financial information. SafePal has not specified what particular data was compromised, but the incident highlights ongoing vulnerabilities within digital wallet services. Users are advised to monitor their accounts for any suspicious activity and take necessary precautions to protect their information.

Aug 17, 2026

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

The Hacker News

Researchers have discovered a new Linux botnet called Evooo1Bot, which builds upon the Mirai botnet's source code. This botnet can exploit known vulnerabilities to convert internet-facing devices into SOCKS5 proxies. The malware not only incorporates the DDoS capabilities of Mirai but also adds several new features that enhance its functionality. This poses a significant risk as it can affect various edge devices that are often less secure and can be used for malicious activities like distributed denial-of-service attacks. Users and companies with exposed devices need to take immediate action to protect their systems from this emerging threat.

Aug 17, 2026

SafePal Data Breach Hits Tens of Thousands of Customers

Infosecurity Magazine

SafePal, a company known for its hardware wallets, has reported a data breach that has affected nearly 40,000 customers. The breach involved unauthorized access to customer data, raising concerns about the security of sensitive information. Users of SafePal's products may be at risk of identity theft or fraud as a result of this incident. The company has not yet disclosed the specific nature of the data that was compromised. This situation serves as a reminder for users to remain vigilant about their online security and consider updating their passwords and monitoring their accounts for any unusual activity.

Aug 17, 2026

Microsoft working on Defender patch for ShieldBreak zero-day

BleepingComputer

Microsoft is currently developing a security patch for a zero-day vulnerability known as 'ShieldBreak,' which was disclosed last week by researcher Nightmare Eclipse. This vulnerability is tracked as CVE-2026-69414 and poses a significant risk, as it can potentially allow attackers to exploit Microsoft Defender, an essential security tool for many users and organizations. The information about this vulnerability is particularly concerning because it could be leveraged by cybercriminals to bypass security measures, compromising systems and data. Microsoft is urging users to stay vigilant while they work on a fix to mitigate the threat. As the situation develops, it’s crucial for users of Microsoft Defender to monitor for updates and implement any recommended patches as soon as they are available.

Aug 17, 2026

Recent macOS Screen Sharing Vulnerability Exploited in Attacks

SecurityWeek

Recently, a vulnerability in macOS screen sharing has been exploited by attackers to gain root access to affected systems. Once inside, they deployed a Monero miner, which utilizes the system's resources to mine the cryptocurrency without the owner's consent. This incident raises concerns for macOS users, particularly those who rely on screen sharing features for remote work or support. The exploitation of this vulnerability not only compromises the integrity of the systems involved but also highlights the need for users to stay vigilant about software updates and security practices. As the attacks are ongoing, users should be particularly cautious and monitor their systems for unusual activity.

Aug 17, 2026

Invisible AI Prompts Trigger Court Sanctions

Security Affairs

A litigant in a case against the New York Bariatric Group attempted to manipulate a court ruling by including AI prompt injections in his filing. These prompts were designed to instruct any AI reviewing the documents to rule in his favor. The presiding judge noticed this unusual tactic and responded by banning the individual from submitting electronic filings. This incident raises concerns about the misuse of AI in legal proceedings and the potential for similar tactics in future cases. Judges and courts may need to implement stricter guidelines to prevent such manipulative practices, ensuring that legal processes remain fair and unbiased.

Aug 17, 2026