Risky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandal

In other news: US accuses Chinese AI companies of industrial-scale distillation attacks; cyberattack hits Luxembourg doctors' clinics; Liquid Network attacker returns most funds, keeps $50m bounty.

Share
Risky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandal

This newsletter is brought to you by Authentik. You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.

Ukraine's top prosecutor Ruslan Kravchenko resigned on Monday over allegations that individuals in his office were taking bribes to protect scam call centers operating across the country.

His resignation comes after investigators from Ukraine's main anti-corruption body, the National Anti-Corruption Bureau (NABU), arrested Serhiy Kropyva, the Deputy Head of the Department of International Cooperation, a top lieutenant in Kravchenko's Office of the Prosecutor General.

In a report last week, NABU claimed it uncovered a major scheme in Kravchenko's office, where one of his department heads was taking bribes to look the other way when it came to a network of call centers that was calling Ukrainians and foreigners and luring them into fake investment platforms that stole their money.

NABU says the scheme began last year when the call center operators recruited "one of the heads of the structural units of the Prosecutor General's Office" and later other employees from the same office.

According to Ukrainian news outlet Ukrainska Pravda, and citing law enforcement sources, more than 100 call centers were sending $7,000/month to the Prosecutor General's Office as a protection fee, meaning the office's corrupt officials were making $700,000 from bribes each month.

Sometime this year, the number of call centers apparently exploded to 500, driving bribes up to $3.5 million.

This sudden explosion in the number of call centers is likely what drew more law enforcement attention to the scheme.

Over the past month, Ukrainian police have shut down more than 100 call centers across the country. They shut down 94 in August, then another one in Kyiv in September, in Dnipro, Nikolaev, and then another one in Kyiv.

NABU, together with the Specialised Anti-Corruption Prosecutor's Office (SAPO), had been allegedly tracking their operations for months as part of what they are now calling Project Carthage.

In a video published over the weekend, NABU shared some of the recorded phone calls made between the group's members.

The conversations suggest the official from the Prosecutor General's Office operated inside the group under the pseudonym Chancellor and he took orders from someone higher than him going by Chef. He also had accomplices named Muza, Flesh, and Kamrad, with some evidence suggesting they are also members of the office.

While no names were given in the video, Ukrainian news outlet Ukrainska Pravda says Chancellor is Kropyva and Chef is Kravchenko himself.

Kropyva has now been fired and placed under arrest until November, with a bail set at 120 million hryvnias ($2.7 million), and with a major investigation underway.

NABU has also searched Kravchenko's own office, in a night raid. The Prosecutor General's Office initially denied the searches, but later confirmed it after Kropyva was detained. 

Kravchenko filed his resignation letter on Monday, calling it a "political decision" and that he "committed no crimes." The letter came out of the blue because just hours before he met with President Volodymyr Zelenskyy and said he had no plans to resign.

On Monday, Ukrainian police also detained Kropyva's driver, a man named Serhii Kutsyi, thought to be Kamrad in the phone recordings, and Yelyzaveta Ivakhnenko, thought to be Muza.

NABU says it's currently only going after five individuals, which leaves Flesh, Chancellor's assistant, still at large.

Something similar to what's happening in Ukraine right now also happened in the country of Georgia at the end of last year, when authorities arrested the country's ex-spy chief in a similar probe of taking bribes to protect local scam call centers.

Risky Business Podcasts

In this edition of Between Two Nerds, Two Nerds Tom Uren and The Grugq talk about whether AI will help cyber defence in critical infrastructure and organisations that are below the cyber poverty line.


Breaches, hacks, and security incidents

Cyberattack hits Luxembourg doctors' clinics: A cyberattack has cripled more than 80 medical practices across Luxembourg. The attack hit BMS Engineering, the developer of a payment system used by the local medical sector. The company said it's still investigating if hackers stole patient data from its cloud servers. [Reporter.lu // RTL.lu]

Cyberattack takes down meteor tracking database: A cyberattack has knocked offline a website of the American Meteor Society that tracks falling meteors. The non-profit expects to restore its public site within a few weeks as it rebuilds its "aging infrastructure." The database keeps track of meteor sightings, where they occurred, trajectories, and how long they were visible. [Wayback Machine]

Cyberattack closes 64 schools in Massachusetts: The city of Springfield in Massachusetts has closed 64 public schools on Tuesday after a cyberattack hit the local school district. The district told teachers and students to stay off school networks until the incident is resolved. The district plans to use the closures to investigate and restore affected systems. It didn't say when schools will reopen. [DysruptionHub // City of Springfield // Springfield Public Schools]

Hackers breach Florida DMV: The ShinyHunters hacking group claimed to have breached the state of Florida's Department of Motor Vehicles. The hackers say they stole more than 200,000 driver records from the department's internal database which they plan to release unless the DMV pays a ransom. To prove their claims, ShinyHunters have released the driving record of deceased sex offender Jeffrey Epstein. [SAN]

Major APIS leak in Vietnam: A misconfigured Elasticsearch database cluster has leaked the personal details of more than 220 million passengers and airline crew members. The data is believed to have leaked from an Advance Passenger Information System, a database that stores information on people traveling through an airport. According to Kinryū Labs, the database was run out of Vietnam for one of its airports but they were unable to tell which. [BleepingComputer]

JLR fires 4k after hack: British automaker Jaguar Land Rover will fire 4,000 employees over the next two years, with the company citing a recent cyberattack and US tariffs as the main reason. [CNBC]

Notional Finance crypto-heist: Hackers have stolen $1.73 million from DeFi platform Notional Finance by exploiting a vulnerability in its old legacy v1 contracts. [Notional // SlowMist]

Mathspace data breach: Hackers have stolen more than 1 million user details from math tutoring platform Mathspace. The attackers breached the company's Metabase database last month as part of a global hacking campaign that hit hundreds of other companies. The stolen data includes information on students, their parents or guardians, and school staff. Only users in Australia and New Zealand had their data stolen. [Mathspace]

Liquid Network attacker returns most funds: The individual who hacked the Liquid Network cryptocurrency platform and stole $320 million over the weekend has returned 85% of the funds. Liquid has allowed the attacker to keep almost $50 million as a bug bounty reward. The company says it also patched the blockchain nodes that allowed the hack. The attacker claimed they are a white-hat security researchers. [The Block]

Source

General tech, AI, and privacy

Autistici/Inventati shuts down: Italian hacktivist and hacker collective Autistici/Inventati has shut down its online platform after the US declared it a terrorist organization last month. The group built and operated encrypted chats and email, web hosting, secure video conferencing and streaming, and other anonymity tools. The US State Department claimed Inventati's platforms were used by violent Antifa cells and far-left militants. The US Treasury also sanctioned the group. [Autistici/Inventati]

LibreOffice says "no AI": The Document Foundation has released a new LibreOffice version and managed to do something that most companies can't these days, meaning releasing a product with "no generative AI features." [The Document Foundation]

Meta still shows CSAM ads: Internet safety researchers have found 350 new Meta ads that used AI-generated child sexual abuse images to promote shady services. This happened even if Meta said it rolled out protections against these types of ads after an initial discovery earlier this year. Meta's system is apparently so bad that the advertisers used an image of a minor from a European royal family as part of the ads. [Tech Transparency Project // WIRED]

"Most of the CSAM ads ran in the European Union and/or the United Kingdom. Because Meta retains ads that run in those regions for a year, they remain visible to researchers even when they are not active. In the U.S., unless Meta ads pertain to “social issues, elections or politics,” they disappear from the Ad Library as soon as they finish running."

LG TVs are recording while they appear to be turned off: LG smart TVs are constantly scanning their local WiFi networks and recording nearby audio conversations even when the TV is set in stand-by mode. The devices store the conversations until the device is turned on again and the data can be sent over the internet to its manufacturer. The devices also ship with Automatic Content Recognition (ACR), a system to track what owners are watching on their TVs. The researchers who found the behavior recommend permanently disconnecting the devices from the internet. [Gamer Nexus YouTube // Gadget Review]

Government, politics, and policy

Switzerland launches sovereign office platform: The Swiss government plans to gradually replace Microsoft365 with European office platform openDesk. The switch will begin in late 2027, with openDesk initially running in parallel with Microsoft 365. The platform will be used by roughly 3,000 employees and will cost the Swiss government around $11 million. OpenDesk will include email, calendar, documents, presentations, telephony, and audio and video conferencing.  [Admin.ch]

Roskomnadzor says it blocked 1,700 DDoS attacks: Russia's internet watchdog, the Roskomnadzor, says it blocked almost 1,700 DDoS attacks in August. The largest attacks peaked at more than 560 Gbps and 52 million packets per second. The longest one lasted almost 10 days. [Interfax]

ANSSI launches REACTIV team: France's cybersecurity agency has established a new incident response team dedicated to dealing with security incidents at government agencies. The new team is named REACTIV, the French acronym of Interministerial Response & Action against Data Breaches. ANSSI launched the new team after several breaches at French government agencies this year—where hackers got in, stole data, and then sold it online. [ANSSI]

France urges EU-wide <15 social media ban: After its own social media ban for kids under 15 hit a roadblock at the French Supreme Court, French President Emmanuel Macron has sent a letter to European Commission President Ursula von der Leyen urging the bloc to pass a similar EU-wide ban. [Reuters]

Australia's My Feed, My Way rules: The Albanese government in Australia has proposed a draft law that would require tech companies to allow users to configure their social media algorithms. [Prime Minister of Australia]

US accuses Chinese AI companies of industrial-scale distillation attacks: The US government says Chinese AI companies have carried out industrial-scale distillation attacks to steal proprietary model features from US AI companies. In a joint advisory on Tuesday, CISA, the FBI, and the NSA say the attacks likely took place with "Chinese government awareness." The advisory names six companies of attacks—DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. Targeted models include Claude, GPT, Gemini, and Grok. [CISA // NSA // FBI, PDF]

In this Risky Business sponsor interview, James Wilson chats with Authentik Security CEO Fletcher Heisler about how AI is driving a need for privileged access management to adapt.

Arrests, cybercrime, and threat intel

Bank account hacker extradited to US: The US has extradited a Russian national from the country of Georgia to face hacking charges. Sergei Anatolyevich Filimonov is accused of using phishing pages to collect e-banking credentials, access victims accounts, and steal their funds. Filimonov successfully stole 5,000 login credentials and attempted to steal millions of US dollars. The DOJ didn't say if he was successful. [DOJ]

Crypto-whale phishers detained: A Singapore man has pleaded guilty in the US to stealing $245 million from a cryptocurrency investor in 2024. Malone Lam was part of a group that called the victim posing as Google Support to hijack their Google account. The group used the victim's private crypto-wallet key to steal their funds. They spent the stolen funds on international travel, nightclubs, luxury cars, watches, jewelry, designer handbags, and rental homes in Los Angeles and Miami. Lam was arrested in September 2024. [DOJ]

Belgium warns of CEO fraud: Belgium's cybersecurity agency warns of an increase in CEO fraud attempts carried out via Microsoft Teams. [SafeOnWeb]

Odido hacker's voice played on TV: Dutch police have published a recording of the voice phishing attack that allowed hackers to breach Dutch ISP Odido this year. Authorities are looking for new clues and tips on the attackers. Police have yet to identify the hackers more than seven months after the breach. The recording was also played on Dutch TV station NPO2. [Politie.nl // Politie.nl]

ClickFix WebDAV campaign: Cisco has spotted a ClickFix campaign executing its payloads from WebDAV storage. While the campaign hit some Ukrainian government orgs, Cisco Talos says it is not espionage related. [Cisco Talos]

Shai-Hulud is back after 111 days: The Shai-Hulud worm has been spotted on npm again after a hiatus of 111 days (May 19, 2026). [Aikido Security]

NoName057(16) goes after Japan: Days after Japanese officials have criticized the Kremlin, its toady faketivist group NoName057(16) has announced plans to target Japanese web infrastructure with DDoS attacks. [Check Point]

DoppelCart campaign: Security researchers have found a giant cluster of more than 119,000 domains that were hosting fake online shops designed to defraud buyers. [Nebty]

Malware technical reports

PEEP: SOCRadar has identified and analyzed PEEP, a Chromium-based emerging post-exploitation toolkit. [SOCRadar]

BigBear 2.0 PhaaS: Security researchers have uncovered a new phishing kit used in the wild to target M365 accounts. CloudSEK described BigBear as a "rebranded Evilginx2-based phishing-as-a-service framework." [CloudSEK]

PivotC2: SOCRadar has spotted a hacking campaign targeting FortiGate devices and deploying PivotC2, a FortiGate-specific RAT. [SOCRadar]

RevStealer popularity grows: There's another report, this one from Elastic, on the new infostealer that emerged this summer. The stealer is currently spread using GitHub repos and YouTube videos advertising gaming cheats. Per Elastic, it's becoming very popular with 4,700 samples uploaded on VirusTotal this year. [Elastic //Morphisec // Gen Digital]

Bee Stealer: And speaking of new infostealers, BlackFog researchers have spotted another one named Bee Stealer, which comes with the ability to steal credentials and chat histories from Codex and Claude. [BlackFog]

Authentik is an open-source identity provider that is also offered with paid enterprise features. In this demo, CEO Fletcher Heisler and CTO Jens Langhammer walk Risky Business host Patrick Gray through an overview and a demo of the technology. 

APTs, cyber-espionage, and info-ops

Several APTs abuse Gemini for intrusions: Google says its Gemini AI assistant is seeing increased adoption among the cybercrime, APT, and the influence operations ecosystem. Over the past quarter, threat actors used Gemini for target reconnaissance, phishing lure creation, C2 development, and data exfiltration. APTs from China, Russia, Iran, and North Korea, as well as groups like TeamPCP and ShinyHunters have regularly used Gemini. Google says there's a growing demand for AI access among threat actors, mostly for its automation and autonomy features. [Google Cloud]

Lazarus top view: Kudelski and Sekoia researchers look at how the Lazarus Group is now operating from six distinct sub-clusters after a major reorganization of the North Korean intel service two years ago. [Kudelski Security // Sekoia]

Vulnerabilities, security research, and bug bounty

Patch Tuesday: Yesterday was the September 2026 Patch Tuesday. We had security updates from Adobe, Microsoft, Ubuntu, Cisco, SAP, IBM, HPE, Dell, Ivanti, AMD, ASUS, TP-Link, Fortinet, WatchGuard, Schneider Electric, Siemens, Kubernetes, cPanel, Qualcomm, AWS, SUSE, and NVIDIA. Other projects and companies like Android, Samsung, Chrome, Firefox, MikroTik, SonicWall, VMware, N-able, Kubernetes, Drupal, Plex, Plesk, RoundCube, Jenkins, MongoDB, Proxmox, Elastic, 7-Zip, Grafana, n8n, ABB, Rockwell Automation, HP, and GitHub released security updates earlier this month. 

Microsoft patches two zero-days: Microsoft's Patch Tuesday this month fixed 974 vulnerabilities, including two actively exploited zero-days. [Microsoft]

  • CVE-2026-81963 - Windows Update Stack Elevation of Privilege Vulnerability
  • CVE-2026-85880 - Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

New N-able N-central zero-day: Software maker N-able has released a security update to patch an actively exploited zero-day in its N-central platform. Tracked as CVE-2026-86218, the zero-day is different from the two critical vulnerabilities the company patched on Friday last week. The company's N-central products were also targeted with a zero-day last month. [N-able]

Adobe patches StyleSmuggler zero-day: Adobe has released an out-of-band security update to patch the StyleSmuggler zero-day used in attacks last week against Magento and Adobe Commerce stores. This is now tracked as CVE-2026-75650. [Adobe patches // StyleSmuggler]

WeChat worm: Security researchers have developed the first zero-click worm that spreads via WeChat voice calls. The worm works across both Android and iOS and doesn't require users to answer the incoming call. It is powered by a RCE exploit that Tencent has now patched. [Calif]

Telerik UI RCE: Tanto researchers have published a write-up of how they found a remote code execution chain with the help of AI in the Telerik UI for ASP.NET AJAX component. There are four bugs, all patched in July.  [Tanto Security // Telerik patches]

OVERPASS and S4GET vulnerabilities: Onapsis researchers have published write-ups on two major bugs SAP patched this week. OVERPASS is an unauth RCE in the SAP kernel (CVE-2026-44756) and S4GET is a preauth RCE in the SAP NetWeaver's Message Server (CVE-2026-58240). Both have a very high CVSS and are likely to be exploited. [Onapsis // OVERPASS // S4GET]

PostGREShell vulnerability: Cyera has published a technical analysis of PostGREShell, a code exec vulnerability (CVE-2026-6471) in PostgreSQL that was patched last month. [Cyera]

Cross-account data leakage in ChatGPT: Check Point researchers have found a hidden channel that lets a ChatGPT session under one account send tasks to a completely separate ChatGPT session under another account. This doesn't show up in any account's conversation history. [Check Point]

Infosec industry

Threat/trend reports: APWG [PDF], Censys, CyFirma, FraudeHelpdesk [PDF], Google Cloud, Group-IB, and Human Security have recently published reports and summaries covering various emerging threats and industry trends.

New tool—TATS: SpecterOps has open-sourced TATS (Token Analysis and Tracking System), a tool to track OAuth 2.0, OIDC, and Microsoft Entra ID tokens across captured network traffic.

New tool—numbat: AI company Perplexity has released numbat, a tool for endpoint visibility into AI agent activity, with local detection, optional pre-action blocking, and forensic reconstruction.

New tool—pktz: Immanuel Tikhonov has published pktz, an eBPF-powered network traffic monitor, per process, per connection, and live.

fwd:cloudsec Europe 2026 streams: Live streams from the fwd:cloudsec Europe 2026 security conference, which took place this week, are available on YouTube.

Risky Business podcasts

In this episode of Risky Business Features, Brad Arkin joins James Wilson to chat about the Trump administration’s call to let private entities conduct cyber operations against criminal groups.