Cybercrime
,
Fraud Management & Cybercrime
,
Incident & Breach Response
Also, Spain Fines 23andMe Over 2023 Data Breach

Every week, ISMG rounds up cybersecurity incidents and breaches around the world. This week: Zelle can’t transfer out of a New York state lawsuit alleging poor controls over rampant fraud, a hack wiped Romania’s land registry, Spain fined 23andMe, an apparent revenge hack against Australia’s Origin Energy and pirate World Cup streaming sites seized. Malware found hiding in Microsoft 365 calendars.
See Also: Know Thy Enemy: Threats to Cyber Resilience
Zelle Loses Bid to Dismiss NY AG Lawsuit
The bank-owned fintech company behind the Zelle money transfer system can’t transfer out of a lawsuit filed by the state of New York, a state judge decided Monday.
A decision by New York County Supreme Court Judge Phaedra Perry-Bond found that attempts by Early Warning Services, the company behind the money transfer app, to dismiss the lawsuit fell short. The firm “knew Zelle was not safe,” Perry-Bond wrote.
Early Warning Services’s largest owners are JPMorgan Chase Bank, Bank of America and Wells Fargo, although Capital One, PNC Bank, Truist Bank and U.S. Bank have shares.
The firm “also misled consumers that it was secure to ‘send and receive money fast’ when it is alleged that the instantaneous transfer of money meant consumers were often left without recourse as fraudsters could quickly dissipate transferred funds, and transfers were made irrevocable,” Perry-Bond said.
New York Attorney General Letitia James sued Zelle in August 2025 in a complaint alleging EWS ignored safeguards in a bid to outpace nonbank payment apps such as PayPal and Venmo. Zelle allowed more than $1 billion in fraud between 2019 and 2022, state prosecutors allege.
“We will keep fighting to hold big banks accountable and stop fraud in all of its forms,” James tweeted on social media network X.
EWS said it intends to appeal. “The attorney general is targeting our company for political gain,” a spokesperson said.
Hack Wipes Romania Land Registry
A cyberattack wiped Romania’s land registry database, disrupting real estate transactions nationwide after the hack destroyed production systems and backups following a failed extortion attempt.
Threat intelligence firm Kela attributed the attack, which began July 14, to a threat actor known as ByteToBreach. The attacker apparently gained access using valid credentials, allowing it to bypass perimeter defenses before conducting reconnaissance across the agency’s network.
After mapping internal systems, the attacker deleted critical data and disabled key services, including the land registry database, official applications, websites and email servers. The outage prevented notaries, government officials and citizens from accessing essential property records, effectively bringing Romania’s real estate market to a standstill.
Kela said the attacker also stole sensitive information, including employee credentials, internal documents and network details, before offering the stolen data for sale on a hacking forum. The destructive actions followed an unsuccessful attempt to extort the agency.
Romanian authorities have begun rebuilding the affected infrastructure using an offline backup. “This is arguably the most severe cybersecurity incident in Romania’s relatively short history of the digitalization of public administration,” said cybersecurity expert Andrei Avadanei, in remarks reported by Balkan Insight.
Spain Fines 23andMe Over 2023 Data Breach
Spain’s data protection authority fined genetic testing company 23andMe $2.7 million for cybersecurity failures that enabled its 2023 credential-stuffing attack, exposing the personal information of 6.9 million users worldwide, including more than 2,600 in Spain.
The Agencia Española de Protección de Datos said the company failed to implement adequate safeguards for highly sensitive genetic data, violating the European Union’s General Data Protection Regulation. Among the regulator’s findings were the absence of mandatory multifactor authentication and the lack of controls to limit repeated access, data requests or downloads from a single IP address, making the attack easier to execute.
According to the enforcement decision, 23andMe executives became aware of the breach only after a sample of the stolen data was offered for sale. The regulator also criticized the company for notifying Spanish authorities 12 days after learning of the incident.
The Spanish penalty follows a separate regulatory settlement in the United States. Earlier this month, 23andMe reached a $46.75 million settlement with victims after a California bankruptcy judge approved a compensation plan tied to the genetic testing firm’s bankruptcy proceedings (see: Breach Roundup: 23andMe Breach Victims to Receive $46.75M Payout).
Australia’s Origin Energy Confirms Customer Data Breach
Australia’s second largest energy company confirmed Thursday that hackers obtained “unauthorized access and disclosure of some customers’ data.”
Sydney-based Origin Energy serves more than 4.8 million accounts. The company acknowledged the attack after the apparent hacker contacted national broadsheet The Australian Tuesday with a sample of 50 customer records containing names, addresses, emails, dates of birth, phone numbers and bill history.
The suspected hacker told the newspaper the hack was made in revenge after Origin Energy offshored customer support roles. The hacker claimed to have gone undetected for three weeks in a company customer system containing the information of 2 million users – and to have used a valid employee’s logon for initial access. “They interviewed the employee whose credentials I used, even fired him and accused him of being behind it,” the hacker told The Australian. The hacker also claimed to have contacted board members and the security team before going public but didn’t receive a response.
The energy provider said the compromised data may include customer account details, the last four digits of payment cards and the last three digits of bank account numbers.
Origin CEO Frank Calabria said the company is working to secure its systems, prevent further unauthorized access and investigate the incident with the assistance of independent cybersecurity experts and law enforcement agencies.
“I’m sorry this has happened,” Calabria said.
US Seizes More Than 1K Illegal World Cup Streaming Sites
The U.S. Department of Justice seized more than 1,000 websites and blocked 1,970 domains used to illegally stream FIFA World Cup 2026 matches, as part of a global crackdown on online piracy.
Federal prosecutors said the operation was aimed at protecting copyrighted content while reducing consumer exposure to malware and other risks commonly associated with illicit streaming platforms. Pirate streaming services often embed malicious software or use insecure connections that can compromise users’ personal and financial information.
In parallel, law enforcement across the Western Hemisphere conducted “Operation Red Card” to block steaming sites, including 14 in Argentina, 223 in Ecuador, 28 in Peru, 309 in Brazil, 256 in the Dominican Republic and 1,140 in Colombia. A second phase of the operation in Colombia led to the arrest of four members of the Los Ciberinfiltrados cybercriminal group, accused of illegally accessing telecommunications systems and selling pirated streaming content since at least 2024.
The announcement follows an FBI warning published in May about fraudulent websites impersonating FIFA to sell fake World Cup tickets and hospitality packages, stealing victims’ personal and financial information. In June, Mexican authorities also dismantled 44 domains linked to the PirloTV sports piracy network, which had attracted an estimated 950 million annual visits, including about 230 million from Mexico.
Malware Hides in Microsoft 365 Calendars
Researchers discovered a new malware strain, dubbed Hollowgraph, that uses Microsoft 365 calendars as a covert command-and-control channel, enabling attackers to exchange commands and stolen data through trusted Microsoft cloud infrastructure.
Findings from Group-IB show the .NET-based malware abuses the Microsoft Graph API through a compromised Microsoft 365 account. Operators plant commands as calendar events, while the malware exfiltrates stolen files by creating encrypted calendar events containing malicious attachments. To avoid alerting users, all malicious events are scheduled for May 13, 2050, ensuring they never appear in the victim’s normal calendar view.
The malware also uses DNS tunneling via IPv6 AAAA record queries to the domain cloudlanecdn.com to refresh Microsoft Entra ID credentials, storing the updated tokens in a file masquerading as logAzure.txt.
Group-IB attributed Hollowgraph with high confidence to the Cavern backdoor framework, previously linked to the Iran-aligned threat actor tracked as Cavern Manticore. Researchers also found limited technical overlaps with Lyceum, another Iranian cyberespionage group, although that connection remains unconfirmed.
The campaign appears highly targeted, with only 12 compromised systems identified and active communications observed between June and July 2026, primarily targeting Israeli organizations.
More Stories From This Week
With reporting by ISMG’s David Perera in Northern Virginia.
