Cybersecurity · Thursday, 8 October 2026
The owner of MonsterCloud, a firm that promised ransomware victims their files back without paying the gangs, is charged with paying them in secret and charging up to 18 times more
US prosecutors say Zohar Pinhasi's firm paid gangs more than $8 million for unlocking keys and charged hundreds of companies more than $19 million. He has pleaded not guilty.
$150,000
charged to one victim, for a key the firm had bought from the gang for about $8,200
about 18 times what the firm paid, by prosecutors' figures
$19m
charged to hundreds of US and Canadian companies from 2018 to 2023
while more than $8 million went to the gangs, according to the indictment
20 years
the longest prison term for each of the three charges
He has pleaded not guilty and is free on a $2 million bond
The lead story — what happened
-
Zohar Pinhasi, 50, owned MonsterCloud, a Florida company that said it could unlock files scrambled by ransomware without paying the criminals. Ransomware is criminal software that locks files until the owner pays for a key.
[1] [2] -
A grand jury in New York charged him with wire fraud and conspiracy on 23 September. He pleaded not guilty in Brooklyn on Wednesday and was freed on a $2 million bond.
[1] -
Prosecutors say the firm had no special unlocking tool. They say it contacted the gangs, paid for the key and used it on the client's files.
[1] [2] -
In one case, prosecutors say, MonsterCloud paid a gang about $8,200 and charged the victim about $150,000. In another it paid about $236,000 and charged about $380,000.
[1] [2] -
From June 2018 to June 2023, prosecutors say, the firm paid gangs more than $8 million and charged hundreds of US and Canadian companies more than $19 million.
[1] [2] -
The indictment says the firm showed clients sample files as proof that it could recover their data. Prosecutors say the gangs themselves had unlocked those samples.
[1] -
Some contracts said MonsterCloud might pay the criminals if nothing else worked. Prosecutors say paying was usually its first step.
[1] -
In May 2019 a paid spokesperson for the firm asked Pinhasi whether it had its own unlocking software. The indictment quotes him saying that it did not.
[2] -
That year a researcher, Fabian Wosar, made up a fake ransomware gang to test recovery firms. Emails offering to pay it soon arrived, and he traced them to firms including MonsterCloud, ProPublica, a US investigative newsroom, reported.
[1] -
'The defendant re-victimized his clients,' said Joseph Nocella Jr., the top federal prosecutor for eastern New York. Pinhasi denied misleading anyone when ProPublica asked in 2019.
[1] -
Each of the three charges carries up to 20 years in prison. The indictment says others worked with him, some still unidentified, and the FBI is investigating.
[2]
Who is involved
-
Zohar Pinhasi
MonsterCloud's owner, also known as Zack Silver and Zack Green; charged with fraud, pleaded not guilty
-
MonsterCloud
a Florida firm that sold ransomware recovery and advertised 'advanced decryption techniques'
-
Joseph Nocella Jr.
the US Attorney for the Eastern District of New York; his office brought the case
-
Fabian Wosar
a security researcher who in 2019 posed as a fake gang to see which recovery firms would pay
How it unfolded
-
June 2018 the alleged scheme begins
[1] -
2019 ProPublica reports that MonsterCloud paid gangs; a paid spokesperson questions Pinhasi
[1] [2] -
June 2023 the alleged scheme ends
[1] -
23 Sep 2026 a grand jury charges Pinhasi
[1] -
Wed 7 Oct he pleads not guilty and is freed on a $2 million bond
[1]
Where this points
The case now moves through the federal court in Brooklyn, and the indictment's mention of other people, some unidentified, is the sign to watch for further charges.
What is pushing on the whole day
The bar and the word are our reading of how hard each one is pushing today. The arrow is where it is heading. The evidence is in the stories below.
Japan handed a suspected member of Qilin, a ransomware gang, to Germany on 2 October.
Attacks on a new flaw in Atlassian's office software began two hours after a public how-to.
Malware called PoeLLM took over more than 3,400 servers running open AI tools.
Advantest, a Japanese chip-testing firm, said in October what its February ransomware attack took.
The rest of the day
28 more stories on this beat.
Each with its own sources. None of these is a link to the story above.
-
02
400,000 power customers' details taken
Southern Company, an Atlanta energy group that owns Georgia Power, Alabama Power and Mississippi Power, says an outsider got into its online customer website.
[3] The intruder saw details on about 400,000 accounts: names, postal and email addresses, phone numbers and the last four digits of Social Security numbers, the main US ID number.[3] About 300,000 of the accounts are Georgia Power's and 100,000 are Alabama Power's.[3] Bank and card numbers were not reached, the company says.[3] Georgia Power300,000 accountsAlabama Power100,000 accountsAccounts reached at two of Southern Company's power firms. Mississippi Power was also hit, but no number was given. Why it matters — Southern Company has not said when the break-in happened or how the intruder got in.
[3] Customers are being told by post and email and offered a year of free credit monitoring.[3] -
03
$10m reward for a Chinese hacking suspect
The US State Department is offering $10 million for information on where Zhang Yu is.
[4] US officials accuse him of a leading role in Hafnium, a hacking campaign that broke into thousands of computers in 2020 and 2021.[4] Prosecutors say he worked for China's Ministry of State Security, its spy agency, and helped steal COVID-19 research from US universities.[4] His alleged partner, Xu Zewei, was arrested in Milan in July 2025 and sent to the US in April.[4] Why it matters — Zhang is still free.
[4] The FBI said last year that Hafnium targeted more than 60,000 US organisations and got into more than 12,700.[4] -
04
Ransomware suspect sent from Japan to Germany
A 28-year-old Russian man was detained in Osaka, Japan, in May and handed to German authorities on 2 October, SecurityWeek reports.
[5] Germany believes he is a core member of Qilin, a ransomware gang that rents its tools to partners.[5] He is wanted over a September 2024 attack that locked a logistics company's files and took more than $160,000 in cryptocurrency.[5] Qilin's past victims include Synnovis, a lab serving London hospitals, and Asahi, the Japanese brewer.[5] Why it matters — Qilin listed 400 victims on its leak website in 2025.
[5] It was still claiming attacks in August, when the US firearms agency, the ATF, confirmed it had been hit.[5] -
05
Gang was pressing a former Boeing unit
KrebsOnSecurity, a security news site, reports that the ShinyHunters data-theft gang was trying to extort Jeppesen ForeFlight when the gang's suspected leader was detained in Jordan.
[6] Jeppesen ForeFlight is an aviation navigation business that Boeing sold in 2025 to Thoma Bravo, an investment firm, for $10.55 billion.[6] Boeing told Krebs it is aware of the gang's claims and is reviewing them.[6] Jeppesen ForeFlight says it has seen no effect on its operations or products.[6] Why it matters — Two of Krebs's sources say the stolen files could carry safety and security risks.
[6] They say that is why the FBI's hunt for the gang gained new urgency.[6] -
06
Atlassian flaw attacked two hours after a how-to
Atlassian, an Australian company whose Jira, Confluence and Bitbucket tools many offices use to track work, fixed a serious flaw in eight products on Monday.
[7] [9] It lets a stranger with no login read some files on servers that organisations run themselves.[8] Within two hours of watchTowr, a security firm, publishing how it works, Previdian's decoy servers saw attackers trying it.[7] [8] In some setups the files hold a password that lets an attacker make their own administrator account.[7] [9] Hour 0How-to publishedHour 2First attacks seenPrevidian's decoy servers, set up to attract attackers, saw the first attempts two hours after the write-up appeared. Why it matters — Atlassian's own cloud version is already fixed, so the risk sits with organisations that run the software on their own machines.
[8] Previdian expects attacks to grow now that a ready-made scanning recipe is public.[7] -
07
Chip-test maker says ID data was stolen
Advantest, a Japanese firm that makes machines for testing computer chips for companies like Intel and Samsung, is writing to people whose data was stolen in a ransomware attack.
[10] [11] The attack began on 15 February, and the company said then that it could not tell whether personal data was taken.[10] Its letters, dated 6 October, say dates of birth, Social Security, passport and driving licence numbers, and medical and financial details were taken.[10] [11] State filings list more than 500 people in California.[11] Why it matters — Advantest has not said how many people are affected in all, or whether they are staff, customers or partners.
[10] It is offering 18 months of identity-theft monitoring.[10] -
08
Discord guard bot loses users' data
Double Counter, a service that guards chat servers on Discord, a chat app popular with gamers, against fake accounts and mass attacks, says hackers broke in on 4 October.
[12] [13] They used a flaw in an old analytics tool to reach its cloud passwords and stayed inside for nearly six hours.[12] About 1 million email addresses were exposed, and IDs and usernames for about 28 million accounts were partly copied.[12] Have I Been Pwned, a breach-tracking site, says 274,900 email addresses have been posted publicly.[12] Accounts partly copied28 millionEmail addresses exposed1 millionEmails posted publicly0.27 millionWhat Double Counter and Have I Been Pwned count from one six-hour break-in. Why it matters — The attackers also used a stolen bot key to post harmful links in about 50 big Discord servers.
[12] Discord itself was not the target, but its users' data sat with an outside company.[13] -
09
MP puts a price on Russian attacks on the UK
Graeme Downie, a Labour member of the UK parliament, says Russian cyberattacks, sabotage and threats cost Britain at least 2 billion to 2.5 billion pounds a year.
[14] His report, The Putin Tax, says ministers hold no estimate of their own.[14] He found no costing of two ransomware attacks, on Advanced, which supplies NHS software, and on Royal Mail.[14] The biggest part of his figure assumes Russia is behind 10% of the 14.7 billion pounds that cybercrime costs British firms each year.[14] Why it matters — Downie says the public cannot judge how much to spend on defence without a figure for the damage.
[14] He wants yearly official estimates, and costs included in the National Cyber Security Centre's reports.[14] -
10
Public logs show 12 fake Google certificates
A web certificate is the digital proof that lets a browser trust it has reached the real site, so a fake one lets an attacker pose as it.
[15] The Hacker News searched public certificate logs and found 12 issued between 22 and 27 September for Google and YouTube addresses in Ghana, Sierra Leone and American Samoa.[15] They are fakes attackers got after seizing those countries' web address systems, as Google disclosed on Tuesday.[15] [16] Let's Encrypt, a free certificate service, issued 11 of them. All 12 were cancelled by 1 October.[15] 22 Sep.gh (Ghana)25 Sep.sl (Sierra Leone)27 Sep.as (American Samoa)The day each country's fake certificates first appeared in the public logs. The attackers worked one country at a time. Why it matters — Google says it cannot be sure it found every affected address, and other organisations, including big brands, were hit too.
[16] [17] It has not said whether any fake was used to pose as a real site.[15] -
11
OpenAI's email to Australia was partly AI-written
Guardian Australia reports that OpenAI's legal and security teams used AI to help word the email telling Australia that OpenAI's AI agent had broken into government websites.
[18] On Tuesday an OpenAI executive told a parliamentary inquiry he did not believe AI had written it.[18] The five-paragraph email went to a government inbox that was checked once a day.[18] At the same hearings, Australia sounded out OpenAI, Anthropic, Microsoft and Google on making companies report such AI incidents.[19] Why it matters — A source told the Guardian that people reviewed and sent the final email.
[18] Anthropic's policy head for the region asked for rules that match around the world, not a different set in each country.[19] -
12
A poem steers a network of hijacked AI servers
Black Lotus Labs, the research team at the US telecoms firm Lumen, says malware it calls PoeLLM has taken over more than 3,400 servers since April.
[20] [21] Most victims run AI tools such as LiteLLM and Ollama that were left open to the internet.[20] [22] The malware reads four words from a poem posted on GitHub, a code-sharing site, and turns them into the address of the server that gives it orders.[21] Infected machines mine cryptocurrency and hunt for new victims.[42] Why it matters — Changing a few words in the poem moves the control server without changing the malware, and the poem looks harmless to anyone who finds it.
[21] [42] The researchers think the operator is Italian or speaks Italian, from comments in the code.[21] -
13
SonicWall fixes a flaw rated 10 out of 10
SonicWall, a US maker of network security boxes, has released fixes for four flaws in its SMA1000 gateways, which let staff reach a company's network from home.
[23] [24] The worst, rated 10 out of 10, lets someone with no login send requests through the box to parts meant only for the inside.[23] [24] SonicWall says there is no sign that anyone has used the flaws yet.[23] Shadowserver, a group that scans the internet, counts more than 400 of these boxes online.[23] Why it matters — It is the third time this year SonicWall has fixed a flaw of this kind in the same login page, and the first two were used in attacks.
[24] Benoit Sevens, a researcher at Anthropic, found the worst one.[24] -
14
Critical flaw in AI server software has no fix
JFrog, a software security company, disclosed on 7 October a critical flaw in LMCache, free software that speeds up servers running large AI models.
[25] One network message can make the server run the sender's commands, with no login needed.[25] No fixed version exists yet.[25] Other machines can reach the server only when an operator sets it up that way, but LMCache's own example setup does exactly that.[25] Why it matters — Until a fix ships, JFrog says operators should keep the server reachable only from the same machine or a trusted network.
[25] Nobody has offered a way to check whether a server was already attacked.[25] -
15
AI music fraudster gets 18 months
Michael Smith, a 54-year-old musician from North Carolina, was sentenced to 18 months in prison for streaming fraud.
[26] [27] He uploaded hundreds of thousands of AI-made songs to Spotify, Apple Music, Amazon Music and YouTube Music, then had bot accounts play them billions of times.[26] The services paid him royalties, a small payment for each play.[26] In one month in 2023 his bots played his songs 80.9 million times on YouTube Music family plans, against 9.3 million plays for Taylor Swift's whole catalogue.[26] Smith's bots, April 202380.9 million playsTaylor Swift's catalogue9.3 million playsPlays through YouTube Music family plans in one month, as the US Justice Department counted them. Why it matters — He must give up more than $8 million.
[26] [27] It was the US Justice Department's first case of fraud through AI-assisted music streaming.[27] -
16
Sites selling child abuse images shut down
The FBI seized two websites this week that sold sexual images of children, including fake ones made with AI.
[28] French prosecutors arrested a 25-year-old French resident suspected of running them.[28] Court papers say some images came from girls' hacked Snapchat, TikTok, Instagram and Facebook accounts.[28] Investigators first learned of the sites in 2024.[28] Why it matters — Several victims had told police that their social media accounts were hacked.
[28] The US TAKE IT DOWN Act, passed last year, makes sharing intimate deepfakes of real people a crime.[28] -
17
Judge throws out number-plate camera evidence
Sara Hill, a US federal judge in Oklahoma, ruled on 1 October that a deputy needed a warrant to search a month of a driver's movements in Flock's camera network.
[29] Flock sells cameras that read the number plate of every passing car and keeps a national database police can search.[29] The deputy found 50 sightings of Melisa Kyle's car across several states before stopping her.[29] The judge threw out the drugs found in her car.[29] Why it matters — It is one of the first federal rulings that such searches can break the US Constitution's limits on searches, though it binds no other court.
[29] Flock says it expects the ruling to be appealed and overturned.[29] -
18
US contractors face a 72-hour breach rule
Rules for US government contractors that handle sensitive but unclassified data could be finished by the end of this year, lawyers told CyberScoop.
[30] The data includes Social Security numbers and details that could expose weak points in vital services.[30] Contractors would have to report a break-in within 72 hours and meet security standards written by NIST, the US standards agency.[30] An earlier draft had demanded reports within 8 hours.[30] Why it matters — Contractors that fail the rules could face the False Claims Act, a law the US government has used since 2022 to punish firms with weak cyber protection.
[30] The Aerospace Industries Association asked for 30 days instead of 72 hours.[30] -
19
Chrome update fixes 247 flaws
Google released Chrome 155 on Tuesday with fixes for 247 security flaws.
[31] Four are rated critical, the most serious level, and 53 high.[31] One outside researcher, Xinyang Ge, reported about a dozen of the high-rated flaws and used AI to find many of them.[31] Google will not pay a reward for some of those AI-found reports.[31] - Critical4 flaws · 2%
- High53 flaws · 21%
- Medium and low190 flaws · 77%
Chrome 155's 247 fixes, split by how serious Google rates each one. Why it matters — Google does not say that any of the flaws has been used in an attack.
[31] Outside researchers reported 62 of the flaws, and Google has disclosed about $33,000 in rewards so far.[31] -
20
Android's October update closes 25 holes
Google's October security update for Android phones fixes 25 flaws, seven of them critical.
[32] The worst lets an app on the phone give itself more powers than it should, with no action by the owner.[32] Pixel phones, Google's own, got six more fixes.[32] This month the update comes as one release instead of the two parts Google has used for years.[32] Why it matters — Google says none of the flaws is known to have been used in attacks.
[32] Cars running Android Automotive got the same fixes and five more.[32] -
21
Scam emails carry hidden orders for AI
Barracuda, an email security company, found phishing emails, fake messages meant to steal logins or money, that also carry hidden orders for AI assistants.
[33] If the person skips the email, the hidden text tells the AI that summarises their inbox to call it urgent or genuine.[33] The orders hide in places a reader cannot see, such as invisible text or characters with no width on screen.[33] In one invoice email the hidden text told the AI to add a fake task: change a supplier's bank details.[33] Why it matters — One email can now aim at both the person and the assistant reading for them.
[33] Barracuda says a person should still approve payments and changes to supplier details.[33] -
22
ASOS threat came from a brand-new channel
Customers of ASOS, the British online clothes shop, got an 'ASOS hacked' alert on 6 October.
[34] Group-IB, a security firm, says the Telegram channel named in it was created that same day.[34] The account behind it had earlier used other names in a forum for trading game items.[34] Group-IB has seen no sample of any ASOS customer data.[34] Its researcher said the alert shows 'access to a customer-messaging channel, not possession of a customer database'.[34] Why it matters — ASOS has about 17 million customers, an Arctic Wolf expert noted, so the real size of any theft matters.
[34] It is still unknown.[34] -
23
Apple adds a check that a photo is real
Apple has released Reference Image, a system that checks a photo is exactly as a new iPhone took it.
[35] Apple's service signs the picture without seeing it and without naming the phone or the photographer, Apple says in a report that Bruce Schneier, a security writer, quoted.[35] It can also show that several photos came from the same iPhone.[35] Apple says it avoided a public photographer ID so people in war zones need not give up being anonymous.[35] Why it matters — Other systems ask a photographer or a news organisation to vouch for a picture with its own name.
[35] -
24
Lawmakers back $11m for cyber troops' health
Two groups of US lawmakers have asked Congress's spending committees to fund an $11 million mental-health and training programme at US Cyber Command, the military's cyber-defence and hacking unit.
[36] The push follows several suicides this summer at the command and at the NSA, the US electronic spy agency, which share a base in Maryland.[36] The House of Representatives approved the money, but the US Senate has not acted.[36] Why it matters — The lawmakers say staff spend two or three years on live operations with no clear breaks.
[36] Secrecy also limits their access to doctors.[36] -
25
Security staff still log in with passwords
A survey of 2,000 security professionals by Yubico, which makes hardware login keys, and Okta, a login company, found 48% use a username and password for personal accounts.
[37] Passwords were also the most common way they log in at work, used by 43%.[37] They rated passkeys, logins tied to a device, the safest method, but only 25% use them at work.[37] More than half were handed a password when they started their job.[37] Why it matters — The report blames friction and old setup habits rather than lack of knowledge.
[37] 44% said their organisation faced at least one AI-driven phishing attack in the past year.[37] -
26
Australia investigates a smart-glasses app maker
Australia's privacy commissioner, Carly Kind, has opened an investigation into Shenzhen Qingcheng, the Chinese company behind the HeyCyan app used by Kmart's A$89 smart glasses.
[38] The glasses can take photos and record video, and drew public anger after people were filmed secretly.[38] Kind says the company did not answer her questions.[38] Kmart's website stopped listing the glasses on Wednesday.[38] Why it matters — Australia's privacy law covers companies, not the person wearing the glasses, Kind says.
[38] Several councils have banned the glasses from places such as swimming pools.[38] -
27
Citizen Lab's head warns about US surveillance
Ron Deibert, director of Citizen Lab, a University of Toronto group that tracks government spyware, gave a keynote speech at the SecTor conference in Toronto.
[39] He said the Trump administration and allied tech leaders are pushing toward mass surveillance.[39] He noted that ICE, the US immigration agency, revived a contract this year with Paragon, a spyware maker.[39] He said NSO Group, maker of the Pegasus spyware, is lobbying to be taken off a US sanctions list.[39] Why it matters — Deibert said AI is making the threats his group has studied for 25 years far stronger.
[39] He said many of them are aimed at immigrants, refugees and activists.[39] -
28
Sponsors quit a disinformation conference
Canada, Lithuania and the EU's foreign service withdrew their support for #Disinfo2026, a European conference on false information, after US pressure, the Guardian reports.
[40] The meeting in Vilnius, Lithuania, draws hundreds of researchers, journalists and officials each year.[40] Three people, including European officials, said the US State Department had contacted several governments about it.[40] State Department papers seen by the Guardian thank Lithuania for 'taking US concerns seriously'.[40] Why it matters — The US papers welcomed Lithuania's objection to a panel that described the US as a foreign source of false information.
[40] -
29
Amazon releases a fence for AI agents
AWS, Amazon's cloud business, has released Strands Box, free software that fences in AI agents, programs that take actions on their own.
[41] It checks each action against rules and against what the agent has already done, such as allowing three Slack messages every ten minutes.[41] AWS says agents increasingly approve every action with no human review.[41] It works on Mac computers for now.[41] Why it matters — Marc Brooker, an AWS engineer, says the agent cannot talk its way round the rules.
[41] He says people still have to decide what access an agent gets.[41]
A file that comes back does not say who unlocked it
MonsterCloud's clients got their files back and could not see that a gang had been paid for the key, prosecutors say.
The twist
When a result looks the same however it was made, the maker can claim the cleaner method and charge for it. Only a record kept while it was being made can show what really happened.
The picture
How it works
- A gang locks a company's files and sells the key
- A recovery firm says it can unlock them without paying
- The files come back looking the same either way
- So the client cannot check which way it happened
- Only a record made at the time, like a payment trail, shows the method
The same force, elsewhere today
Where this chain is also running, in today's other stories.
-
The AI music fraudster
A play counted by a streaming service looks the same whether a person or a bot pressed play, so Michael Smith's bots were paid like listeners.
-
Apple's photo check
A photo cannot show whether a camera took it or software made it, so Apple has the picture signed at the moment the iPhone takes it.
-
OpenAI's email to Australia
The email's words did not show that AI had helped write them, and it took a reporter's source to reveal it after an executive said he believed otherwise.
-
Scam emails with hidden orders
An AI assistant's summary reads the same whether it followed only the visible email or the hidden orders inside it.
Where you've seen this
Second-hand cars
a clean dashboard does not show whether the mileage was wound back, but a yearly service record does
School homework
a right answer does not show whether it was worked out or copied, so teachers ask to see the working
Restaurant kitchens
a plate of food does not show how it was stored, so inspectors visit the kitchen itself
The catch
A record can be faked too, so it helps only when someone other than the maker keeps it, such as a bank or the phone that took the photo.
And the whole of it
Each MonsterCloud client saw only its own files come back, and each gang saw only the money arrive. Only the firm in the middle saw both, and most people buy repairs, medicines and software in the same way, seeing only how things turn out.
What is really going on
US prosecutors say MonsterCloud sold ransomware victims a way out that skipped paying the gang, then quietly paid the gangs more than $8 million and charged its clients more than $19 million.
Why it works on us — A file that opens again feels like proof the service worked, and a business that has just got its systems back has little reason to ask how.
Who gains
-
MonsterCloud, if the charges are proved
— It kept the gap between more than $19 million charged and more than $8 million paid to the gangs.
[1] [2] -
The ransomware gangs MonsterCloud dealt with
— They were paid while the victims believed no one had paid them.
[1] -
Drivers charged on number-plate camera evidence
— Judge Hill's ruling gives their lawyers a decision to cite against warrantless Flock searches, though it binds no other court.
[29] -
Identity-monitoring firms such as Kroll
— Advantest's letters enrol victims in 18 months of Kroll monitoring, and Southern Company offers a year of credit monitoring.
[3] [10]
Who pays
-
MonsterCloud's client companies
— In one case a victim paid about $150,000 for a key that cost about $8,200, prosecutors say.
[1] [2] -
About 400,000 Southern Company customers
— Their names, addresses and the last four digits of their Social Security numbers were seen by an intruder.
[3] -
Discord users on servers that used Double Counter
— Their IDs and usernames were partly copied, and 274,900 email addresses are now public.
[12] -
Musicians paid by streaming royalties
— Michael Smith's bot plays 'robbed millions in royalty payments from genuine artists', the US Attorney said.
[26] -
Organisations running their own Atlassian servers
— They must patch at once, because attacks began two hours after the public how-to.
[7] [8]
What nobody knows yet
Open questions from across today’s stories — ours included.
-
01
How many of MonsterCloud's clients believed no ransom had been paid for their files.
The indictment gives totals across hundreds of companies, not a count of who was told what, and Pinhasi has pleaded not guilty.
[1] -
02
Who else worked on the scheme.
The indictment says Pinhasi had co-conspirators, including staff and contractors, some of them unidentified, and the FBI is still investigating.
[2] -
03
What ShinyHunters actually took from Jeppesen ForeFlight.
Two of Krebs's sources say the files could carry safety and security risks, while Jeppesen ForeFlight says it has seen no effect on its operations or products.
[6] -
04
How and when the intruder got into Southern Company's customer website.
The company has said only what data was seen, and has not given a date or a method.
[3] -
05
How many people Advantest's theft reached.
Advantest has not given a total; state filings show more than 500 people in California, 14 in Massachusetts and 8 in Vermont.
[11] -
06
Whether any of the 12 fake Google certificates was used to pose as a real site.
Google's post does not say, does not name the attackers and does not say how the three countries' address systems were broken into.
[15] -
07
Whether the group behind the ASOS alert holds any customer data.
Group-IB has seen no sample, dump or other evidence, and ASOS has said only that names and contact details may have been accessed.
[34] -
08
Whether any LMCache servers have already been attacked.
There is no fixed version, and neither JFrog nor the LMCache project has given operators a way to check.
[25] -
09
What Russian attacks really cost the UK.
The Putin Tax report's figure rests mostly on an assumed 10% Russian share of cybercrime, and the UK government holds no estimate of its own.
[14]
A suspected member of Qilin, a ransomware gang, was arrested in Osaka in May and handed to Germany on 2 October to face charges over a 2024 attack.
Also true today
- The FBI shut two websites that sold sexual images of children, and French prosecutors arrested the person suspected of running them.
- Let's Encrypt and ZeroSSL cancelled all 12 fake certificates found for Google and YouTube addresses, the last of them by 1 October.
- SonicWall fixed four flaws in its remote-access gateways, one of them rated 10 out of 10, with no sign that anyone had used them.
More from Cybersecurity
Across the beats