[REVISION HISTORY]
AI-driven phishing, ransomware and fraud surge continues
Updated 1 time since CLSTR started tracking revisions of this situation.
What changed
2026-07-26 08:35 UTC → 2026-07-28 11:20 UTC ·
added
removed
AI‑enhanced phishing, ransomware and fraud continue to surge, remain on the rise, with Germany remaining still the EU hotspot. The BSI notes reports that AI tools now automate vulnerability discovery and exploit creation, prompting firms to expand phishing‑simulation programmes and upgrade endpoint protections. Operation Endgame dismantled the Amadey and StealC families, while and Microsoft’s Digital Crimes Unit used employed Copilot to neutralise additional servers and recover stolen credentials. A German court clarified partial bank liability for phishing‑related losses, and US U.S. data show internet‑related crime losses reaching €20.9 billion in 2025. In late July 2026, law‑enforcement actions further the multinational “Olympus Blade” operation crippled the Kratos phishing‑as‑a‑service platform. Operation “Olympus Blade”, coordinated by the United States, Germany and Indonesia, neutralised over platform, shutting down more than 200 servers and led leading to the arrest of the platform’s its presumed developer in Indonesia. Kratos had supplied a subscription service to Authorities reported roughly 1,800 affiliates, enabling about 15,000 phishing campaigns per month that harvested Microsoft 365 credentials 850 victims across more than 30 countries. A follow‑up operation announced by the German Federal Police on 25 July 35 countries and highlighted newly disclosed Microsoft SharePoint and Exchange vulnerabilities, including CVE‑2026‑58644 (CVSS vulnerabilities (e.g., CVE‑2026‑58644, CVSS 9.8). Authorities warned that patching alone is insufficient and They urged organisations to replace compromised machine keys, activate anti‑malware interfaces and scan for lingering web shells. These takedowns underscore Further incidents underline the expanding threat surface. A German insurer suffered a breach after a mis‑configured server was scraped by an AI‑driven web crawler, exposing customer details. Fraudsters targeting Booking.com users have deployed fake hotel‑payment pages to harvest credit‑card data. A large sextortion campaign, amplified by AI‑generated images, has leveraged stolen data from companies such as Amtrak and Panera Bread to extort teenage boys. Researchers also uncovered DNS‑hijacking of hotel and conference‑center Wi‑Fi networks in the United States, India and Saudi Arabia, redirecting users to counterfeit Microsoft‑365 login portals and bypassing multi‑factor authentication. These developments reinforce the need for coordinated international cooperation against criminal law‑enforcement action, rapid patching, key rotation and state‑backed groups exploiting zero‑click attacks on collaboration platforms. robust credential‑protective controls.
Versions
- 2026-07-28 11:20 UTC AI-driven phishing, ransomware and fraud surge continues
- 2026-07-26 08:35 UTC AI-driven phishing, ransomware and fraud surge continues
Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.