Small businesses operating near Melbourne tobacconists are being denied insurance or priced out of coverage following a surge in arson attacks linked to the illicit tobacco trade, according to Guardian Australia reporting.
Crime syndicates have been implicated in more than 200 firebombings across Australia since 2023 as rival groups compete for control of the market, government data shows, Guardian business reports.
North Korean hackers have stolen more than $10.5 million from job seekers across 100 countries in a cyber campaign dubbed "WaterPlum", the FBI and international law enforcement agencies said in an advisory.
The hackers infected at least 30,000 devices and stole credentials from about 7,000 cryptocurrency wallets between December 2025 and July 2026 by posing as AI or blockchain companies, according to the advisory released on Friday, The Record reports.
Nearly 2 million Quest Apartment Hotels customers have had their personal data compromised in a cyberattack involving a third-party technology provider, according to the accommodation provider.
David Mansfield, the managing director of parent company The Ascott Limited, said on Wednesday that a forensic analysis revealed information relating to 1,991,613 customers was affected in the incident, which involved records from before June 2025.
The compromised data includes credit card numbers, passport and driver licence details, Medicare numbers and vehicle registrations, according to AAP reports.
An Australian author has detailed losing $317,000 to serial fraudster Hamish McLaren after a 16-month relationship where he posed as a finance executive, Moneymag.com.au reports.
Tracy Hall said she discovered the fraud when she saw McLaren's face in a Crime Stoppers video, realising the man she knew as Max Tavita was a career criminal who had forged her investment documents, AU scams reports.
South Australian authorities are warning race fans to be on high alert after a fraudulent website surfaced posing as the official ticket vendor for the state's upcoming MotoGP event, Yahoo News Australia reports.
"It is very concerning that this page purporting to be an official MotoGP Adelaide website and containing misinformation and AI content is circulating on social media," said Michael Brown, South Australia's cabinet member for consumer and business affairs.
The illegitimate site, which features contact details with a Czechia area code and claims a company called TicketsGP is the official seller, is encouraging users to hand over personal information, according to the government.
The Federal Trade Commission took enforcement action on Tuesday against multilevel marketing operator Amway Corp. and two affiliates over alleged unfair and deceptive business practices, according to a press release from the agency.
A proposed order requires Amway, World Wide Group, L.L.C. and Leadership Team Development Inc. to pay $225 million, which the FTC said is the largest monetary recovery ever collected from a multilevel marketing company in an agency action, FTC press (US consumer protection) reports.
The Securities and Exchange Commission ordered AIQuest Trading and its operator to stop soliciting public investments immediately over an alleged unregistered securities offering, the Inquirer reports.
The agency's Enforcement and Investor Protection Department issued a cease and desist order against AIQuest Trading, Erica Aguilar, and their agents, according to the report. – With Inquirer business Inquirer business (PH) reports.
Western Australian consumers have been warned to watch for fake ticket scams targeting summer events through social media and online marketplaces, WA ScamNet reports.
WA ScamNet reported more than $1,000 in losses from fake ticket scams in the first few days of September, with more than 80% of last year's recorded losses occurring during the warmer months, according to the Department of Local Government, Industry Regulation and Safety's Consumer Protection division, Australasian Leisure Management Magazine reports.
Former Australian Competition and Consumer Commission chair Allan Fels has likened debt collection tactics targeting an 81-year-old woman to "Robodebt 2.0", as the consumer watchdog takes the firm to court over hundreds of thousands of notices.
Suncorp debt collector ARMA Group pursued Diane Walker for months over an insurance claim she was not responsible for, before ending the ordeal with an apology and financial compensation, according to ABC News reporting on Wednesday.
More than half of Australians are worried scams are becoming harder to spot, according to a survey of 2,000 adults released by Good Things Australia.
The research found just 30% of respondents feel confident avoiding online scams, while 28% feel confident managing privacy and safety settings.
Good Things Australia called for less digitally confident adults to remain a priority as the Australian Government develops its proposed Digital Duty of Care.
Get Online Week 2026 will run from 19 to 25 October with free community events across Australia providing practical support with digital skills, Medianet News Hub reports.
The Australian Competition and Consumer Commission and the Australian Federal Police signed a memorandum of understanding on 29 June 2026 to enhance information sharing on scam activity, the agencies said in a joint statement.
Scammers stole approximately $2.18 billion from Australian consumers in 2025, according to the ACCC's National Anti-Scam Centre, Mirage News reports.
Indonesian authorities detained 30 Malaysians and a Taiwanese national in a hotel raid in Pontianak, West Kalimantan, for allegedly running an online scam targeting fellow Malaysians.
Pontianak Immigration Office chief Sam Fernando told a press conference on Thursday that the suspects occupied 14 rooms at the hotel and were apprehended at about 11.15am on Tuesday in a joint operation with Pontianak City Police, Bernama reports.
Surfshark VPN disclosed on 10 September 2026 that hackers accessed an internal test server and a separate proxy server following a configuration error, according to BleepingComputer.
The company said the breach exposed service configurations, build-related credentials, system binaries and code history, but did not impact customer data, user traffic or production infrastructure.
Surfshark detected the unauthorized activity on 31 August and contained the incident on 2 September, before completing remediation three days later.
The VPN provider rotated impacted internal credentials, revoked exposed tokens and commissioned an independent security audit following the breach.
A newly discovered Android malware strain called Mantax Otax combines ransomware, spyware and harassment capabilities to target mobile users, according to mobile security company Zimperium.
Indonesian operators distribute the malicious APKs outside the official Google Play store using phishing messages, BleepingComputer reports.
Cryptocurrency hardware wallet maker Trezor warned customers on Wednesday that attackers who breached its third-party email provider are targeting them with phishing emails. The fraudulent messages falsely claim a microcontroller vulnerability could expose wallet seeds to cracking, BleepingComputer reports.
Trezor said it is investigating the breach and has taken the domain down to halt the attacks, warning users not to click any links in the emails.
Identity verification company IDScan confirmed that hackers accessed customer data on its cloud platform, following reports linking the firm to a database containing more than 153 million stolen driver's license scans.
The company disclosed the incident in a September 4 security notice, stating it learned around September 1 that data may have been accessed without authorization, according to BleepingComputer.
A threat actor used hundreds of AI agents to launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers across 48 countries, according to BleepingComputer.
GreyNoise data indicates the campaign compromised at least 440 instances linked to 395 distinct organizations, with the education sector accounting for roughly half of the breaches.
Malaysian authorities have apprehended the owner and an admin manager of Dermacare upon their arrival in the Philippines following an Interpol red notice, the Securities and Exchange Commission reported on Thursday.
The two officers face charges for allegedly soliciting unauthorized investments without registration, committing investment fraud and engaging in syndicated estafa, according to the SEC, Inquirer business (PH) reports.
A Sydney crime syndicate has allegedly defrauded Australian banks of up to $600 million through large-scale fraudulent loan applications, NSW Police said on Thursday.
Police charged three people on Wednesday, including an accounting firm director and two accountants from Bankstown, bringing the total number of people charged by Strike Force Myddleton to 33.
A 36-year-old Russian web developer accused of participating in a multimillion-dollar bank account takeover scheme has been extradited to the United States, federal authorities said Tuesday.
Sergei Anatolyevich Filimonov appeared in an Atlanta federal court on Sept. 4 and pleaded not guilty to charges including fraud and identity theft, prosecutors said.
“Filimonov allegedly used spoofed domains and fraudulent login pages to target unsuspecting online banking customers, stealing millions from victims,” said Marlo Graham, FBI Atlanta’s special agent in charge, according to The Record.
A massive fraud network known as DoppelCart operates more than 119,000 fake e-commerce domains to harvest credit card details, according to BleepingComputer.
German cybersecurity startup Nebty discovered the network and described it as the largest publicly documented fake-shop cluster by domain count, BleepingComputer reports. More than 105,000 of the sites remain active.
Victorians made more than $300 million in theft-related insurance claims during the 2025-26 financial year, according to new data from the Insurance Council of Australia.
That total included $240 million claimed over 12,300 motor vehicle thefts or burglaries, alongside 3,900 property-related claims costing more than $56 million, the council said on Thursday, ABC business (AU) reports.
Property settlement scams cost Australians $166.8 million in 2025, marking an increase of more than 9% from the previous year, according to Scamwatch data published by Australian Conveyancer on Tuesday.
A survey by property settlement company PEXA found that 99% of Australians failed to identify a fraudulent email address even when informed the document was a scam.
A foreign network of hundreds of Facebook pages has used AI deepfakes to target dozens of Australian politicians in what researchers describe as a commercially motivated influence campaign. Research organisation Reset Tech tracked more than 200 Facebook pages impersonating political figures over an eight-month period, linking the campaign to an influencer business in Sri Lanka.
About 10 per cent of the network's pages had been monetised through Facebook's creator payment scheme, according to the report. Reset Tech chief research officer Rys Farthing said the operation demonstrated foreign influence driven by financial gain rather than traditional state-based interference, ABC News & reports.
The Australian Signals Directorate issued a warning on Wednesday that a substantial number of local Adobe Commerce and Magento Open Source stores face active exploitation from a zero-day vulnerability.
Tracked as CVE-2026-75650 and rated 10.0 on the Common Vulnerability Scoring System, the flaw allows unauthenticated remote code execution, iTnews reports.
AUSTRAC cancelled, suspended or refused the renewal of 45 remittance and virtual asset service provider registrations over the past year, removing the businesses from its registers, FX News Group reports.
"Businesses with cancelled registrations can no longer operate and where appropriate, we've referred individuals behind these businesses to law enforcement and regulatory partners locally and overseas," AUSTRAC CEO Brendan Thomas said.
South Korean police referred Hybe founder Bang Si-hyuk to prosecutors on Wednesday over allegations he misled investors ahead of the company's 2020 public listing.
Authorities froze 263.1 billion won in suspected illicit gains, according to Yonhap News.
Bang denies wrongdoing and his legal team expects a transparent resolution through the legal process, Yonhap reports.
Google issues urgent Chrome update for actively exploited zero-day
Google has released an urgent browser update to patch a high-severity zero-day vulnerability in its Chrome browser that is actively being exploited in attacks, BleepingComputer reports.
The security issue, tracked as CVE-2026-85046, is a type confusion flaw in the V8 JavaScript and WebAssembly engine reported by researcher Salvatore Gulizia, according to the advisory cited by BleepingComputer.