< Back to situations

We’ll email you as it develops, and you can follow the whole thread from day one.

[SITUATION] · [ACTIVE]

8 clusters · 56 sources · 61 days · First seen · Last updated

Categories: TECHNOLOGY · CRIME

AI-driven phishing, ransomware and fraud surge continues

Entities: German insurer · ReliaQuest · Sextortion campaign · Booking.com · Kratos phishing service

Overview

AI‑enhanced phishing, ransomware and fraud remain on the rise, with Germany still the EU hotspot. The BSI reports that AI tools now automate vulnerability discovery and exploit creation, prompting firms to expand phishing‑simulation programmes and upgrade endpoint protections. Operation Endgame dismantled the Amadey and StealC families, and Microsoft’s Digital Crimes Unit employed Copilot to neutralise additional servers and recover stolen credentials. A German court clarified partial bank liability for phishing‑related losses, and U.S. data show internet‑related crime losses reaching €20.9 billion in 2025.

In late July 2026, the multinational “Olympus Blade” operation crippled the Kratos phishing‑as‑a‑service platform, shutting down more than 200 servers and leading to the arrest of its presumed developer in Indonesia. Authorities reported roughly 850 victims across 35 countries and highlighted newly disclosed SharePoint and Exchange vulnerabilities (e.g., CVE‑2026‑58644, CVSS 9.8). They urged organisations to replace compromised machine keys, activate anti‑malware interfaces and scan for lingering web shells.

Further incidents underline the expanding threat surface. A German insurer suffered a breach after a mis‑configured server was scraped by an AI‑driven web crawler, exposing customer details. Fraudsters targeting Booking.com users have deployed fake hotel‑payment pages to harvest credit‑card data. A large sextortion campaign, amplified by AI‑generated images, has leveraged stolen data from companies such as Amtrak and Panera Bread to extort teenage boys. Researchers also uncovered DNS‑hijacking of hotel and conference‑center Wi‑Fi networks in the United States, India and Saudi Arabia, redirecting users to counterfeit Microsoft‑365 login portals and bypassing multi‑factor authentication.

These developments reinforce the need for coordinated international law‑enforcement action, rapid patching, key rotation and robust credential‑protective controls.

Timeline

  1. 3 days ago

    [TECHNOLOGY] 5 sources
    Europe Leads Global Effort to Dismantle Phishing Service and Halt Cyberattacks

    Global law‑enforcement dismantles the “Kratos” phishing service, while Europe sees related cyber incidents: a German insurer’s data breach, Booking.com payment scams, a sextortion wave targeting teens, and DNS‑

  2. 6 days ago

    [TECHNOLOGY] 5 sources
    US, German, Indonesian forces dismantle Kratos phishing-as-a-service platform

    Operation Olympus Blade by US, German and Indonesian agencies disabled the Kratos phishing‑as‑a‑service platform, shutting down 200+ servers, arresting its developer and halting thousands of Microsoft‑365 theft

  3. 8 days ago

    [CRIME] 15 sources
    German and US authorities dismantle global Kratos phishing service

    German and U.S. agencies seized 200 servers and arrested Kratos’s developer in Indonesia, ending a phishing‑as‑a‑service that enabled ~1,800 criminals to run 15,000 monthly attacks affecting victims in over 30

  4. 22 days ago

    [CRIME] 3 sources
    Phishing Fraud Liability Clarified as Banks May Share Responsibility

    German courts say banks can share blame for phishing fraud if monitoring fails, while US internet crime losses hit €20.9 bn in 2025, with seniors most affected.

  5. about 1 month ago

    [CRIME] 11 sources
    Microsoft AI operation dismantles global malware networks

    Microsoft’s Copilot AI helped Europol and dozens of police forces shut down 326 servers, 142 domains and recover 27 M credentials in a massive malware takedown.

  6. about 1 month ago

    [TECHNOLOGY] 18 sources
    Operation Endgame crackdown disrupts major malware as Europe and US boost cyber defenses

    Operation Endgame dismantled Amadey and StealC servers across Europe and the US; Censys released an Enrichment API; Germany sees a ransomware surge linked to Russia; BSI flags AI‑boosted attacks; firms expandph

  7. about 2 months ago

    [CRIME] 5 sources
    India Telecom Ruling and Global Phishing Surge Heighten Banking Fraud Risks

    An Indian court fines BSNL over a €1 million SIM‑swap fraud, while global phishing attacks using AI and QR‑codes cause €442 billion in banking losses in Q1 2026.

  8. 2 months ago

    [TECHNOLOGY] 2 sources
    AI‑Powered Mobile Phishing Costs €442 Billion, Banking Trojans Spike Worldwide

    AI‑driven mobile phishing inflicts €442 bn losses, with 3.4 bn daily fraudulent messages; banking‑trojan cases jump 196 % to 1.24 m, prompting regulator and tech‑company shifts to stronger device authentication

Sources

allgaeuhit.de · attivonetworks.com · berlin-mitte-zeitung.de · bilder1.n-tv.de · blogspan.net · bnn.de · borncity.com · buddhistlibrary.org.au · careelite.de · charlottenburg-wilmersdorf-zeitung.de · cybersecurity-news.de · cybersecuritynews.com · deutscherpresseindex.de · dicpas.es · digital-magazin.de · digital.t-online.de · elektronikpraxis.de · ensemblepourlaville.be · festival-cinema.com · finanzen.ch · friedrichshain-kreuzberg-zeitung.de · genderandhealth.org · generation-nt.com · hier-luebeck.de · in-und-um-schweinfurt.de · infoguerra.com.br · informationsverbund.ch · inside-it.ch · it-boltwise.de · it-daily.net · itiko.de · langenhagener-news.de · librered.net · linux-magazin.de · moneybox.de · mundoenlinea.cl · netzpalaver.de · netzwelt.de · neue-pressemitteilungen.de · newsfeed.zeit.de · nihonbashi-pub.co.jp · niubie.com · nn.de · noticiasdemalaga.es · pankower-allgemeine-zeitung.de · pda.teltarif.de · plazamayormadrid4c.es · pressnetwork.de

This summary has been updated 1 time: see revision history