Paylogix

La société de gestion des avantages sociaux Paylogix a été victime d'une cyberattaque. Des pirates informatiques ont volé des informations sensibles, y compris des numéros de sécurité sociale, des données financières, des informations de santé et des numéros de passeport, appartenant à des dizaines de milliers de personnes. L'incident, qui a eu lieu entre le 13 et le 18 novembre, a été revendiqué par l'enseigne de ransomware Akira en janvier 2026.

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers

Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence

Ukrainian lawyer and Conti malware developer Oleksii Lytvynenko was sentenced to four years in U.S. prison for ransomware attacks. Oleksii Oleksiyovych Lytvynenko had, by most accounts, a fairly ordinary legal career in Ukraine before he switched to writing malware. A US federal court sentenced the 44-year-old to four years in prison this week for conspiracy to commit wire fraud, the Justice Department announced, tied to his role in Conti, the ransomware operation blamed for infecting over 1,000 organizations worldwide. “Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian national, was sentenced today to four years in prison for conspiracy to commit wire fraud in connection with a conspiracy to deploy Conti, a ransomware variant that infected the computers of more than 1,000 victims worldwide.” reads the announcement by DoJ. “According to court documents, Lytvynenko, formerly of Cork, Ireland, conspired with others to deploy Conti ransomware to extort victims and steal their data. From 2020 until 2022, Conti was used to attack computers and networks in 47 states, 31 foreign countries, the District of Columbia, and Puerto Rico. The FBI estimates that, as of January 2022, there had been victim payouts associated with Conti ransomware exceeding $150,000,000.” Conti’s numbers put it in a different league from most ransomware groups that end up in a US courtroom. Between 2020 and 2022, the group attacked networks across 47 US states, 31 foreign countries, Washington DC, and Puerto Rico, and the FBI estimates victim payouts topped $150 million before the operation shut down. Lytvynenko stood out because he handled both sides of Conti’s operations. He broke into victim networks and developed tools for attacks. He built a loader that helped deploy malware on compromised systems. Investigators found stolen data from eight US victims and four overseas organizations in his accounts. Prosecutors linked his actions to attacks on at least 12 companies, showing he played an active role rather than working on the sidelines. Specifically, he was assigned to code a “loader,” the kind of malware that opens the door for other malicious software to run once a machine is already compromised. Evidence recovered from his own online accounts showed he personally held stolen data from eight US victims and four more overseas, and prosecutors say his direct actions affected at least a dozen companies during his time with the group. That’s not someone on the periphery of the operation; that’s someone touching both the tools and the actual victims. The most striking detail in this case is what happened after Conti supposedly stopped existing. The gang shut down its operation in 2022 after its internal chat logs and source code leaked publicly, following the group’s public declaration of support for Russia’s invasion of Ukraine, a leak that exposed the entire operation to researchers and law enforcement simultaneously. Lytvynenko apparently didn’t take that as a signal to find a different line of work. When Irish police showed up at his home in County Cork in July 2023, they reportedly found his laptop still open, running Cobalt Strike, with an active Rocket. Chat session connected over Tor, the kind of setup that doesn’t belong to someone who’s quietly stepped away from cybercrime. Forensic evidence from that arrest demonstrated his ransomware activity had continued well past Conti’s collapse. He was extradited from Ireland to the US in October 2025, more than two years after that raid. Lytvynenko admitted to joining the group around September 2021. He acknowledged holding stolen data from multiple victims in the U.S. and abroad. Oleksii Lytvynenko pleaded guilty to conspiracy to commit wire fraud for his role in the Conti ransomware operation. In September 2023, four other Conti conspirators were indicted in Tennessee. “Lytvynenko pleaded guilty to wire fraud conspiracy on June 10. Evidence recovered from Lytvynenko’s online accounts showed he possessed data stolen from eight U.S. victims and four overseas victims. Lytvynenko further admitted to joining a team run by a Conti conspirator during which time Lytvynenko was directed to work on coding a “loader,” which is typically a type of malware, or malicious software, that is used to load programs necessary to execute other malicious attacks.” DoJ continues. “Forensic artifacts recovered at the time of his arrest in July 2023 in County Cork, Ireland, further demonstrated ongoing involvement in ransomware activity.” Lytvynenko pleaded guilty in June to a single count of wire fraud conspiracy, a charge that carried a statutory maximum of 20 years, making the four-year sentence a fraction of what he legally could have received. “Conti ransomware caused extraordinary harm, targeting victims across nearly every state and dozens of countries and disrupting critical operations for organizations across multiple industries,” said Assistant Director Brent Daniels of the U.S. Secret Service’s Office of Field Operations. “Today’s sentence is a measure of justice for the victims whose data, operations, and livelihoods were put at risk. It underscores the Secret Service’s commitment to pursuing ransomware actors and their networks wherever they operate and protecting the American people.” The sentence adds to a broader US crackdown on ransomware. The Ransom Cartel creator recently received 16 years, while a Karakurt negotiator got 8.5 years. Lytvynenko’s four-year sentence may look lighter, but it still shows that US courts are pursuing ransomware criminals who operate from abroad. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, Conti ransomware)

Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Zero trust AI agents demand a different kind of security In this interview, Chris Webber, VP, Product Marketing at Teleport, explains why zero trust principles need to change for AI agents. He covers how agents act fast, unpredictably, and continuously, and why old ideas like least privilege and point-in-time verification fall short. AI-Infra-Guard: Open-source security scanner for AI systems Tencent’s … More → The post Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited appeared first on Help Net Security.

Revolut Exposed KYC Data After Fraudulent Government Email Passed Security Checks

Revolut handed over KYC documents, selfies, and Bitcoin transaction histories after a fake government email with valid domain credentials passed its checks. Revolut confirmed on September 12, 2026, that it disclosed sensitive customer data to an unauthorized third party after receiving fraudulent information requests sent from an email address operating inside an actual government agency’s domain infrastructure. TechCrunch reported. The customer notification, which began circulating on September 11, stated that the communication carried valid domain authentication credentials, meaning the email passed the checks that are supposed to confirm a message genuinely comes from a government authority. “Revolut received a request for customer information that appeared to come from a legitimate government agency. The request came from an unauthorised email account sent directly using the official government agency’s email domain.” reads the Revolut’s notification. “As the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request.” “The exposed data included customers’ identity and contact details, including their birth date, postal and email addresses, and phone numbers, as well as copies of their identity documents including passports and driver’s licenses, according to a notification emailed to affected customers and reviewed by TechCrunch.” reported TechCrunch. “The data may have also included verification selfies, account statements, and transaction histories, the firm said in its notification.” Multiple outlets including CoinDesk and Crypto Times confirm the transaction histories covered Bitcoin. What Revolut handed over is essentially everything a regulated fintech is required to collect for identity verification, in one package, sent to the wrong people. Below are the details of the handed-over data reported in the notification: Identity details: full name, date of birth, occupation Contact details: postal address, email address, and telephone number Document and verification data: a copy of your identity document (passport and/or driver’s licence) and facial verification image (the selfie you provided for verification). Please note that no biometric facial telemetry data was involved or compromised Financial data: account statements (including IBAN, account status, opening date, wallet reference number), withdrawal records and full transaction history (including Bitcoin) This is not a technical breach in the usual sense. No systems were compromised, no malware was used, and Revolut’s servers were not accessed by an outsider. The attacker either created a rogue account within an official government agency’s domain or compromised an existing one, then used that account to submit what appeared to be a legitimate data request. Revolut staff processed it. The company only discovered the fraud afterward, by independently contacting the government agency to verify the request, at which point the agency confirmed it had not made it. Revolut said that the incident impacted a limited number of customers and immediately contacted them, but did not disclose the scope of the incident. Revolut also declined to name the government agency involved or specify whether the breach affected a particular country or market. Naming the agency would allow other regulated platforms to search their own legal-request logs for messages from the same mailbox. The silence on that point is a gap in the public record that matters for other fintechs who may have received similar requests. Crypto security researcher ZachXBT, who posted about Revolut’s notification to affected customers, assessed that the incident appeared to be targeted at high-net-worth users. Idk why I am blocked by both Revolut accounts. pic.twitter.com/wLd3IdmSF9— ZachXBT (@zachxbt) September 12, 2026 If this assessment is correct, this was not a large-scale data theft. It appears to have been a targeted operation aimed at building detailed profiles of wealthy individuals, using their KYC documents and cryptocurrency transaction history linked to their real identities. Combined with IBANs and account statements, this information could be very useful for fraud, impersonation, or extortion. Revolut says it blocked the email address, alerted the government agency involved, notified law enforcement, and reported the incident to financial regulators. Revolut also says its systems and customer funds were not affected. That may be technically true, but it misses the main point: the attackers did not need to hack Revolut’s systems to get the data. The breach comes as Revolut seeks greater regulatory credibility, TechCrunch argued. The company recently won conditional U.S. approval to become a national bank, is reportedly considering a $200 billion IPO, and serves 80 million customers worldwide. The incident also highlights weaknesses in fintech data-request processes: relying mainly on email authentication can allow attackers with access to a government domain to bypass checks and obtain sensitive customer data. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, Revolut)

Anthropic: AI Misuse Is Entering a New Phase: From Cybercrime to Surveillance, Propaganda and Weapons

AI is becoming an operational force for cybercrime, surveillance, propaganda, fraud and weapons development, lowering the cost and scale of attacks. Artificial intelligence (AI) is becoming more than a tool for people who want to do something malicious. It is increasingly becoming part of the operational machinery itself. That is the main message emerging from Anthropic ‘s latest Threat Intelligence report, which examines malicious activity identified and disrupted between December 2025 and August 2026. The cases cover cyber operations, influence campaigns, surveillance, fraud, biological research, conventional weapons and attempts to extract the capabilities of frontier AI models. The actors involved are equally diverse. Anthropic describes suspected state-sponsored groups, financially motivated criminals, commercial surveillance operators and politically motivated individuals. What connects many of these cases is not a new attack technique, but the way AI changes the economics, speed and scale of operations. AI is becoming an operational layer The report makes an important distinction from the usual discussion about AI-powered hacking. The biggest change may not be that AI can discover a new vulnerability or write malware. It is that models can now contribute across almost the entire attack chain, from reconnaissance and tool development to exploitation, credential theft, data processing and exfiltration. Anthropic observed operations in which AI systems executed commands against victim networks, harvested credentials and exfiltrated information. At the more autonomous end of the spectrum, multi-agent frameworks conducted reconnaissance, exploitation and data theft against several victims in parallel, sometimes for hours or days with limited human intervention. This has an important consequence for defenders. Sophisticated attacks no longer necessarily require sophisticated attackers. According to Anthropic, AI is reducing the gap that once separated well-funded state operations from smaller criminal groups. Reconnaissance, exploitation, coding and data analysis that previously required several specialists can increasingly be delegated to AI systems running at machine speed. The underlying attacks are often familiar. Stolen credentials, exposed services, vulnerable edge devices, phishing and SQL injection still play a central role. What has changed is the cost of putting them together at scale. Cybercrime becomes a production line One of the clearest examples involves a financially motivated operation that harvested credentials from software and online services. The attackers downloaded and analyzed 1.8 million Android application packages, searching for hardcoded secrets, while running a parallel process to collect GitHub-related credentials. The important point is not the number of apps. It is the automated pipeline connecting discovery, credential collection, validation and subsequent intrusion activity. “One French-speaking operator going by the aliases of (MeowSHA | frkoo | blazespider) ran a distributed credential-harvesting pipeline across a fleet of 10 AWS EC2 workers. This pipeline mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, decompiled them, and scanned for hardcoded secrets with Detecting and countering misuse of AI: September 2026 12 TruffleHog.” reads the report. “Verified findings were routed in real time to a Telegram group organized into over 100 source types. A parallel GitHub organization email harvester fed a second stream of stolen GitHub Personal Access Tokens. These two credential pipelines supplied the initial-access credentials for the bulk of the confirmed breaches associated with frkoo.” The same model appears elsewhere in the report. Attackers used AI to develop malware and phishing tools, analyze compromised environments, process stolen information and maintain access to victims. In one campaign, stolen tokens could be replayed against Microsoft services to access mailbox contents, including deleted messages. The attackers used techniques designed to make their traffic resemble legitimate Microsoft clients. Anthropic says Claude was used to engineer and test the tooling. This is what makes the development significant. AI does not need to invent a completely new attack for the threat level to increase. If it can automate enough of the existing process, a small team can attempt operations that previously required a much larger workforce. Surveillance at machine speed The report becomes even more striking when it moves beyond cybercrime. Anthropic identified nation-state actors and commercial surveillance operators using Claude to build systems for monitoring populations, profiling individuals and analyzing social media activity. The cases involve actors linked to China, Iran and West Africa, as well as the commercial surveillance-for-hire market. “These cases include threat actors from China, Iran, and West Africa, as well as the commercial “surveillance-for-hire” market, and range from operations carried out by a single individual to entire teams.” continues the report. “Anthropic’s Usage Policy prohibits using Claude to conduct non-consensual surveillance and profiling, and to use our services to violate individuals’ civil liberties and human rights. In every case we describe below, the threat actors violated our Usage Policy and attempted to circumvent controls designed to detect such misuse.” In one case, a consultant working for Malian national security authorities used Claude to engineer a mass-interception platform capable of monitoring communications across the country’s mobile operators and producing dossiers on targets. In another, Iranian actors used Claude to develop a malicious Firefox extension designed to harvest information about social-media users. Chinese operators used AI to analyze large volumes of social-media content, identify potential targets and generate intelligence reports. One particularly revealing operation targeted Uyghur communities in Syria. An actor without Arabic-language skills used Claude to draft messages in the appropriate dialect, translate replies in real time, role-play as an expert to evaluate the operation and prepare the resulting information for a suspected human case officer. This shows another important shift. AI is not merely analyzing surveillance data after it has been collected. It can become part of the system that decides whom to watch, how to approach them and how to turn raw information into intelligence. Propaganda can also be industrialized The same automation is appearing in influence operations. Anthropic describes an operation linked with high confidence to UAE government officials in which AI supported a network of roughly 300 inauthentic social-media accounts. The operation also created a front NGO using the identity of a real organization, produced apparently independent human-rights material and ghost-wrote testimony intended for presentation to the UN Human Rights Council. The actors also profiled 18 members of the European Parliament and journalists and prepared dossiers on UN Special Rapporteurs who had criticized UAE conduct in Sudan. The significance is not simply that AI can generate propaganda. Political actors have been producing propaganda for centuries. The difference is that AI can make the process much cheaper and more scalable while allowing operators to generate different narratives, personas and documents for different audiences. The line between genuine grassroots activity and centrally coordinated influence therefore becomes harder to see. Fraud gets a human face without the human The report also provides a remarkably concrete example of AI-powered consumer fraud. A China-based app studio built more than 20 dating applications and used AI personas to communicate with users while advertising the services as fully human. During a two-week period, Anthropic identified more than 4,700 AI personas that interacted with at least 25,000 people. “A China-based app studio used Claude to both build a network of over 20 dating apps and power the AI personas used to converse with users–despite advertising their service as fully human.” states Anthropic. “Over a two-week window in April 2026, we discovered more than 4,700 distinct AI personas that engaged in conversations with at least 25,000 unique individuals.” The operation combined AI and human workers. The bots handled large volumes of conversations, while real people performed activities such as video calls and social-media interactions designed to convince victims that they were dealing with genuine users. The reported ratio was roughly three AI personas for every real person. Claude generated around 2.36 million messages during the period examined. This is an important preview of how AI could change online fraud. The attacker no longer needs thousands of people to maintain thousands of conversations. A small human operation can supervise a much larger artificial workforce. The terrorism risk deserves attention The report does not identify a confirmed terrorist attack conducted with Claude. It does, however, document activity that illustrates why AI-assisted weapons development deserves attention from counterterrorism and national-security agencies. Anthropic identified six cases involving weapons development, procurement or intelligence gathering in China, Russia and Yemen. The cases include guided rockets, ballistic-missile simulations, anti-torpedo systems, autonomous drone swarms, electronic-warfare targeting and directed-energy weapons. “We identified a cell of threat actors based in northern Yemen running three weapons development programs: a guided rocket that used a commodity phone-class flight computer with final-phase homing guidance; a multi-stage ballistic missile with a stated range goal above 2,000 km; and a multi-variant missile (referred to as the “R2000” set) that included a hypersonic glide vehicle variant.” continues the report. The Yemen case is particularly significant from a terrorism perspective, even though Anthropic does not establish that the actors were a terrorist organization. A weapons-development cell used Claude Code to work on guidance, navigation and control software for a guided rocket. Multiple AI instances were assigned different roles, including coding, research and code review. The group also carried out a real-world test of a guided rocket and returned to the model afterward to analyze the failure. That distinction matters. AI is not necessarily giving a terrorist group the ability to build an advanced weapons system from nothing. What it can do is reduce the amount of specialized engineering expertise required to modify, integrate and troubleshoot technologies that the group already possesses. For counterterrorism agencies, this creates a potential new problem: the proliferation of technical capability may no longer depend entirely on recruiting highly specialized engineers. Weapons development is not limited to missiles The report provides several other examples. One China-based actor used Claude to develop documentation and software for an anti-torpedo system, including a technical proposal of more than 200 pages and comparative analysis of US naval systems. The actor repeatedly asked the model to act as a hostile expert and criticize its own work, effectively creating an automated review process. A Russia-based operation worked on an autonomous FPV drone swarm using Claude Code and simulation infrastructure. Other cases involved electronic warfare, air-defense suppression and intelligence gathering related to directed-energy weapons. The pattern is consistent: AI can compress research, engineering, documentation and testing cycles. That does not mean the model independently created these weapons. In several cases, the actors already had expertise, hardware or access to the necessary infrastructure. The AI accelerated the work around them. Biology is an even harder problem Biological misuse presents a different challenge because intent is much harder to establish. Anthropic says today’s models are capable of assisting with increasingly complex scientific research, making it harder to guarantee that they cannot meaningfully support dangerous biological work. The report describes five cases involving potentially sensitive research. They include gain-of-function work involving chikungunya, planning related to mammalian adaptation of avian influenza, an orthopoxvirus immune-evasion research proposal, optimization of venom peptides and computational redesign of toxins. Anthropic is careful about what these cases prove. It does not claim that the researchers intended to develop biological weapons, nor that Claude enabled a biological weapon. The cases demonstrate something more subtle: dangerous research can look very similar to legitimate scientific research when viewed one request at a time. That makes traditional content filtering much harder. A sophisticated actor does not necessarily have to ask an AI model, “How do I build a biological weapon?” They can divide the work into apparently legitimate scientific tasks and combine the answers elsewhere. AI is also becoming the target Perhaps the most strategic part of the report concerns illicit distillation. Anthropic says several Chinese AI companies attempted to extract capabilities from Claude by creating large numbers of fraudulent accounts, routing enormous numbers of queries through proxy networks and collecting model outputs for training. Alibaba’s operation reached almost three million exchanges per day from more than 3,500 fraudulent accounts, with more than 151 million exchanges observed between May and July. The activity targeted agentic tasks, software engineering, kernel development and long-horizon reasoning. Zhipu used hundreds of fraudulent accounts to extract and process reasoning traces. Moonshot, meanwhile, allegedly forwarded customer requests to Claude while presenting Claude’s responses as if they came from its own Kimi models. The privacy implications are serious as well. Anthropic says some rerouted requests contained sensitive corporate information, live credentials and surveillance data. In one case, DeepSeek allegedly relayed requests containing internal AI-program specifications; another exposed credentials associated with a Russian government database. This creates a new category of AI supply-chain risk: an organization may think it is using one AI service while its data and workloads are actually being processed by another. The common thread is scale The cases in the report look very different, but they point in the same direction. AI is becoming a force multiplier for cybercriminals, intelligence services, propagandists, fraudsters, surveillance operators and potentially armed groups. It can automate the boring parts of an operation, accelerate the difficult parts and allow a small number of people to coordinate activity at a scale that would previously have required a much larger organization. This is why the most important finding is not that AI can hack systems or generate malicious code. The bigger issue is that AI is changing the economics of malicious activity. A criminal group can process millions of files. A surveillance unit can turn huge volumes of social-media posts into target profiles. A propaganda operation can maintain hundreds of artificial identities. A fraud operation can hold thousands of conversations simultaneously. A weapons program can use AI to accelerate software development and technical analysis. And in the most advanced cyber cases, AI systems can perform several of these tasks with little human intervention. Anthropic reports that humans still tend to retain the decisions that matter most, such as selecting targets and deciding how to monetize results. But the operational workload between those decisions can increasingly be delegated to machines. That may be the real security threshold we are crossing. The question is no longer simply whether AI can be abused. It clearly can. The more important question is how much of a malicious operation can now be delegated to AI before a human has to step in. Anthropic’s report suggests that the answer is already: quite a lot. “Sophisticated and persistent threat actors continuously test our safeguards and try to circumvent the technical measures we use to detect and prevent misuse.” concludes the report. “We’ll continue to evolve our safeguards and coordinate with our partners to improve our ability to detect, disrupt, and prevent future misuse.” Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, Anthropic)

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. Details of the vulnerabilities are as follows - CVE-2026-42016 (CVSS score: 8.1) - An incorrect authorization

Revolut confirms customer data breach through fake government requests

Revolut said it notified affected customers and alerted the relevant government agency, law enforcement, and financial regulators.

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. [...]

Debian xorg-server Important Privilege Escalation Fix DSA-6497-1

Several vulnerabilities were discovered in the Xorg X server, which may result in privilege escalation if the X server is running privileged. For the stable distribution (trixie), these problems have been fixed in version 2:21.1.16-1.3+deb13u4. We recommend that you upgrade your xorg-server packages.