A city-based businessman lost close to Rs 20 lakh after fraudsters hijacked his correspondence with a Dubai supplier and rerouted a payment meant for a shipment of doors and windows into their own account.
Indrajit Basu, 32, has told the Cyber Crime police station that the fraud unfolded over nearly two months, between May 25 and July 13 this year. Basu had placed an order for material with True Sea Services FZC, a Dubai-based company, after reaching out to the firm through its website and official email address. He sent an advance of $11,216.21 through SWIFT on March 10 to the company's genuine bank account, and the order moved ahead as planned.
The trouble started while the goods were still being readied. Police say an unidentified person created a near-identical email address, swapping the supplier's genuine inquiry@trusea.ae for inquiry@trusea-ae.com, a domain close enough to pass an unhurried glance. Messages sent from this lookalike address, still carrying the True Sea Services name, informed Basu that the company's bank details had changed. In their place was an account said to belong to First Abu Dhabi Bank PJSC, complete with an IBAN number and a listed branch address.
Basu had no reason to doubt the communication and processed the documentation for the balance payment accordingly. On June 9, he wired $20,830, roughly Rs 19.75 lakh at the time, to the new account. The money never reached the actual supplier, and repeated follow-ups brought no resolution, at which point Basu approached the police.
The Cyber Crime police registered a complaint on Thursday night under relevant sections of the Bharatiya Nyaya Sanhita and the Information Technology Act. The named accused include whoever operated the fraudulent email address, the person who holds and controls the bank account that received the transfer, and others believed to have taken part in the conspiracy. Investigators are working to trace the account holder and the digital trail left by the spoofed domain.
Basu's case falls squarely into the bracket Gujarat Police now treats as serious enough to route away from local stations. Under a restructuring the state carried out this year, complaints involving losses above Rs 10 lakh are handled exclusively by dedicated Cyber Crime Police Stations rather than the jurisdictional police, precisely because cases of this size tend to involve cross-border transfers and mule accounts that local units are not equipped to trace.
The scale of the problem in Gujarat gives that decision some context. State figures put cumulative cyber fraud losses at around Rs 3,707 crore, with roughly Rs 1,435 crore of that lost in 2025-26 alone, and only about 3 percent of the total has been recovered so far. Police have leaned on what they call the golden hour, the narrow window right after a fraudulent transfer in which a call to the national helpline, 1930, or a report on the National Cyber Crime Reporting Portal can still get an account frozen before the money is moved on. Gujarat Police's Operation Mule Hunt, which wrapped up its first phase in June, flagged more than 900 mule accounts and led to over 600 arrests, stressing how heavily this kind of fraud depends on layers of accounts opened specifically to receive and quickly disperse stolen funds.
The method used against Basu, a lookalike domain slipped into an active supplier conversation, is what cybersecurity researchers classify as vendor email compromise, a variant of the broader business email compromise problem that the FBI's Internet Crime Complaint Center logged at nearly 25,000 complaints and just over $3 billion in reported losses in the US alone in 2025, both figures higher than the year before. Security researchers who track these schemes note that attackers increasingly avoid tipping off a target with an urgent, out-of-context demand for money. Instead they wait inside a live, legitimate transaction, often after quietly monitoring an inbox for weeks, and strike only when a payment is already due, using a domain that differs from the original by a hyphen, an extra letter or a swapped top-level domain, easy to miss on a quick read. Investigators and bank officials advise businesses dealing with overseas suppliers to treat any mid-transaction change in payment or account details as a red flag, and to confirm such changes only through a phone number sourced independently of the email itself, rather than one supplied in the message.
Police officers across the United States are facing arrests, firings and investigations for allegedly misusing Flock Safety's automated license plate reader system to track people for personal reasons, including romantic partners, former partners and colleagues.
Flock operates more than 120,000 cameras across over 6,000 US communities, with the system recording around 20 billion license plate scans each month. The cameras are designed to help law enforcement locate stolen vehicles, identify vehicles connected to investigations and assist in finding missing people. However, their growing deployment has raised concerns about how much vehicle-movement data police can access and whether agencies are adequately monitoring that access.
A Washington Post analysis found that at least 50 law enforcement officers had been accused or charged with using license plate readers for unauthorized purposes. Flock systems were involved in 46 of those cases, while 26 involved officers allegedly using the technology to monitor women, including current or former romantic partners. The Institute for Justice has separately documented dozens of similar cases nationwide, with many occurring since 2024.
One of the most prominent cases involved former Braselton, Georgia, Police Chief Michael Steffman. According to The Washington Post, Steffman used Flock searches to monitor the movements of his former girlfriend and her daughter roughly 600 times. He was arrested on stalking, harassment and license-plate-reader misuse charges but died before his case went to trial.
Georgia has continued to see cases involving alleged misuse. Habersham County Deputy Christian Brewer was fired and arrested after an internal audit reportedly found that he had used Flock data to track someone with whom he had a personal relationship. A second Habersham County investigator, Jonathan Thomas, was arrested this week following another internal investigation into alleged misuse of the system.
The problem is not limited to Georgia. In Texas, former Lufkin police officer Zachary Anthony Klein was indicted on 100 felony counts after allegedly conducting more than 45,000 Flock searches over approximately 200 days. One license plate was reportedly searched nearly 3,500 times. The department subsequently suspended its use of Flock while investigations continued.
The Institute for Justice's database has continued adding cases in 2026, including allegations involving officers in Florida, Illinois, Georgia, Texas and other states. The database records incidents involving stalking, unauthorized searches and other non-law-enforcement uses of automated license plate reader data.
Flock says its platform records every search and provides audit tools intended to identify unusual activity. The company has also introduced additional safeguards, including mandatory case codes, stronger audit mechanisms and a recommended reduction in data retention from 30 days to seven days.
Critics argue that logging searches is only useful if police departments actually review those records and investigate suspicious activity. In several documented cases, alleged misuse was discovered only after victims or outside investigators identified unusual searches.
The issue has now expanded beyond individual officers. At least 69 alleged misuse incidents have been identified nationwide, while communities are increasingly questioning whether extensive vehicle surveillance can be deployed without stronger controls over retention, access and data sharing.
Residents have also begun investigating the system themselves. Have I Been Flocked allows users to check whether their license plate appears in publicly obtained Flock search records. The service has reportedly compiled more than 242 million recorded searches from audit logs obtained through public-records requests.
As Flock's network continues expanding, the controversy is shifting from whether automated license plate readers can help police solve crimes to a more difficult question: who watches the people given access to the surveillance system?
Cybersecurity firm Proofpoint, which identified the campaign, said attackers are sending emails that impersonate COLDCARD and falsely claim that a security audit is being conducted across its hardware cold-storage wallets.
The campaign follows the reported theft of around 1,367 Bitcoin, estimated to be worth $88.6 million, from 4,585 addresses. The incident is believed to have been linked to a random number generation flaw affecting several COLDCARD models and firmware versions.
The fraudulent emails originate from compliance@coldcardteamnews.com and carry the subject line "Hardware audit now available." Recipients are told that recent security findings have prompted COLDCARD to verify devices across different hardware revisions.
"We are writing to inform you of a coordinated security audit now underway across the COLDCARD device network. Recent findings have prompted us to verify the integrity of hardware across all revisions, and your participation is needed," reads the fake security audit emails.
The messages direct recipients to a supposed "Security Verification & Incident Reporting Tool." The attackers claim that the process is air-gapped, does not require users to provide their recovery seed and must be completed by August 10.
Clicking the "Access the Audit Tool" button takes users to coldcardcompliance.com, a fraudulent website designed to resemble COLDCARD. Visitors are then prompted to click "Start Hardware Audit" to download the alleged diagnostic tool.
The site also features a live "Customer Service" chat function, which is presented as a way for users to receive assistance with their COLDCARD devices.
According to conversations reviewed by Proofpoint, an operator asks victims whether they are using Windows or macOS before providing further instructions. Windows users are told to execute the downloaded file. When one victim reported seeing a black command window and an administrator prompt, the operator claimed the prompt was necessary to begin installation and instructed the user to select "Yes."
Proofpoint suspects that the chat interactions are being conducted by human operators rather than an automated system. This would allow the attackers to address victims' concerns directly and persuade hesitant users to continue with the installation.
Proofpoint said clicking "Start Hardware Audit" downloads a batch file named Coldcard_Diagnostic_Tool.bat from a GitHub account.
An analysis by BleepingComputer found that the 25.7MB batch file contains two Base64-encoded files embedded within it.
When executed, the script initially appears to run a diagnostic check. In reality, it determines whether the victim has administrator privileges. If elevated access is unavailable, it uses PowerShell to restart itself and trigger a User Account Control prompt.
The script subsequently extracts the embedded files into a randomly generated directory inside the Windows temporary folder. The files are saved as setup.msi and docusign.exe before being decoded using Windows certutil.
After installing setup.msi, the script launches docusign.exe, displays an "Installation Complete" message and removes the temporary directory. The executable is a legitimate, digitally signed program associated with a DocuSign printer driver and serves as a distraction from the malicious activity.
The setup.msi package, however, installs ConnectWise ScreenConnect, a remote-management application that can provide attackers with access to the compromised computer.
Proofpoint said the malicious installation connects to activeretirementrelocation[.]com, which serves as the ScreenConnect command-and-control server operated by the attackers.
Once a connection is established, threat actors could potentially control the affected computer remotely, steal sensitive information or cryptocurrency, and deploy additional malicious software. Proofpoint also warned that the compromised access could ultimately be leveraged to deploy ransomware.
The use of ChatGPT by OpenAI has enabled it to dismantle a coordinated scam operation based in Poipet, Cambodia which used ChatGPT for multiple online fraud schemes, including investment scams, romance scams, illegal gambling promotion, and impersonating police officers. According to the company, the network operated in an area that has historically been associated with organized cybercrime, scam compounds, and human trafficking.
"Operators rely on automated scraping tooling with custom or legitimate-sounding user agents, leveraging GitHub 'ghost' accounts that are often years old, or compromised OAuth tokens and personal access tokens (PATs) from legitimate users," Julie Agnes Sparks, senior security engineer at Datadog, said.
According to the security researchers, the majority of the observed activity has focused on collecting publicly available information. However, in a limited number of incidents, the attackers progressed beyond reconnaissance and successfully cloned private repositories.
The campaigns rely on a combination of automated scanning tools, more than 50 dormant GitHub accounts, and several legitimate accounts whose personal access tokens (PATs) had either been unintentionally exposed or compromised. These resources are used to perform extensive enumeration across multiple GitHub organizations.
A notable aspect of the operation is the use of so-called "ghost" accounts that were created between two and five years ago and deliberately left inactive before being activated for API-based reconnaissance. By using aged accounts instead of newly created ones, the attackers are able to make their activity appear more legitimate and reduce the likelihood of triggering security alerts.
Since a significant portion of GitHub's API can be accessed without authentication, the attackers are able to retrieve large amounts of publicly available data while remaining indistinguishable from routine API traffic. Their reconnaissance includes listing public repositories within organizations, mapping user followers and following relationships, identifying gists, starred repositories, and organization memberships, as well as executing GraphQL queries against public objects.
The collected information enables threat actors to build detailed profiles of an organization's GitHub environment, including its public repositories, contributors, developer relationships, and project activity. Such intelligence can be used to support future targeted attacks.
Datadog also confirmed that in a small number of cases, attackers escalated their activity by cloning a private repository belonging to a targeted organization, indicating that the campaigns can extend beyond information gathering.
"Individually, most of these requests are unremarkable. They hit public endpoints, authenticate cleanly or not at all, and return successful responses," Datadog said. "The concern lies in the aggregate: a group of accounts moving in sync across companies' GitHub organizations with versioned custom tooling iterating over weeks, and in the worst case, actors that stopped enumerating and started cloning."
The U.S. government has taken another step in its ongoing campaign against large-scale cyber fraud operations, announcing the seizure of online infrastructure allegedly used to support one of the world's most active criminal marketplaces while simultaneously expanding financial restrictions against the network behind it.
On Tuesday, the Department of Justice (DOJ) revealed that it had seized a cloud computing account connected to Cambodia-based Huione Group and its subsidiaries. According to federal investigators, the account hosted backend systems used to operate Huione Guarantee, also known as Haowang Guarantee, a platform that authorities say enabled a broad range of illicit activities spanning cybercrime, fraud, money laundering, and other criminal services.
The enforcement action coincided with a series of measures from the U.S. Department of the Treasury, which announced additional sanctions targeting Huione-linked entities and individuals associated with the Prince Group network. The latest moves build upon actions taken by U.S. authorities last year as part of a wider effort to disrupt transnational criminal organizations operating across Southeast Asia.
Federal officials described the seized infrastructure as a key component of a marketplace that allegedly served cybercriminals and fraud operators on a global scale. Rather than functioning as a conventional online marketplace, investigators say the platform acted as an ecosystem where illicit services, stolen information, and financial laundering tools could be accessed by criminal actors.
According to the DOJ, the cloud-based infrastructure provided technical support for operations conducted through Huione Guarantee. Authorities allege that the platform relied heavily on Telegram channels to facilitate communications and transactions involving illegal products and services.
Investigators claim those channels were used to advertise and trade stolen credit card information, sensitive personal data, and services linked to malware-enabled theft. The platform is also accused of facilitating money laundering activities and supporting schemes connected to human trafficking operations. In addition, authorities allege that proceeds generated through romance scams and fraudulent investment schemes were moved through the network.
The DOJ further alleges that Huione Guarantee offered escrow services designed for cryptocurrency transactions. Such services act as intermediaries between parties involved in a transaction, holding digital assets until agreed conditions are met. While escrow systems are commonly used in legitimate commerce, investigators contend that the service was leveraged by criminal actors seeking a trusted mechanism for conducting illicit transactions and laundering funds.
Officials believe the infrastructure played an important role in moving and concealing criminal proceeds. According to the Justice Department, billions of dollars in fraud-related funds were transferred through systems supported by the seized account. Authorities further stated that a massive portion of those proceeds originated from scam compounds operating throughout Southeast Asia, where organized criminal groups have increasingly adopted digital platforms and cryptocurrency networks to scale their operations.
The Treasury Department's actions were designed to expand existing restrictions against the Huione network. One measure formally added H-Pay Service as a successor entity under Treasury's existing rule targeting Huione Group. Treasury also imposed sanctions on nine individuals and 26 entities linked to Prince Group, broadening the scope of enforcement against organizations allegedly connected to the movement of illicit funds.
According to Treasury officials, Huione served as an important financial conduit for proceeds generated through cyber-enabled theft, virtual currency investment fraud, and other criminal schemes. Authorities further allege that the network was used by Prince Group to transfer, consolidate, and manage assets derived from fraudulent operations.
The latest actions follow a series of previous enforcement efforts directed at the same ecosystem. Last October, Treasury moved to further isolate Huione Group from the U.S. financial system, reflecting growing concerns over the company's alleged role in facilitating illicit financial activity.
Federal agencies have increasingly focused on scam networks operating across Southeast Asia as losses linked to online fraud continue to rise. Criminal organizations in the region have become known for running large-scale investment scams, romance fraud operations, and cryptocurrency-related schemes that target victims worldwide. Many of these operations rely on complex laundering networks and digital payment channels to obscure the origin and movement of stolen funds.
The investigation also intersects with earlier actions involving Prince Group chairman Chen Zhi. In October, the DOJ announced the seizure of bitcoin connected to investigations involving Chen and alleged cryptocurrency-related offenses, alongside accusations involving additional criminal schemes. Authorities have also reported that an individual identified as a significant participant in Chen's network was arrested in Cambodia before being extradited to China.
The coordinated actions by the DOJ and Treasury illustrate an emphasis on targeting the infrastructure that enables cyber-enabled fraud rather than focusing solely on individual perpetrators. By disrupting cloud services, financial channels, and marketplace operations that allegedly support criminal activity, U.S. authorities are seeking to make it more difficult for transnational fraud networks to move money, coordinate operations, and reach potential victims.