The Financial Register.

Inward fraud & financial crime, explained for Gen Z

Live coverage

LiveUpdated 04:30 pm

Live updates

The Wire

Rolling updates from The Financial Register.

4 HR 4 MIN AGO

Australia targets unlicensed superannuation telemarketers in reform crackdown

Australia targets unlicensed superannuation telemarketers in reform crackdown
Photograph: ABC business (AU)

Unlicensed telemarketers who cold-call Australians to convince them to switch superannuation providers will face licensing requirements under government reforms announced on Wednesday.

Assistant Treasurer Daniel Mulino is set to unveil the regulatory package at the National Press Club following the collapse of the Shield and First Guardian funds, which left 12,000 people with losses exceeding $1 billion, according to ABC News reporting, Nassim Khadem reports for ABC business (AU).

'It was devastating': Superannuation lost to dodgy switching schemes Unlicensed telemarketers who cold call and make unsolicited approaches to consumers to convince them to switch their super will be banned under long-awaited reforms. abc.net.au
superannuationscamsconsumer-protectionfraudregulation
4 HR 4 MIN AGO

Origin Energy data breach traced to Manila call centre

Origin Energy data breach traced to Manila call centre
Photograph: ABC business (AU)

Authorities tracing the Origin Energy cyber hack have linked the incident to a former Accenture employee in Manila, according to the Australian Broadcasting Corporation.

The security breach exposed the personal data of approximately 900,000 current and former customers, Australian Broadcasting Corporation reports.

Accenture declined to comment, citing an ongoing investigation, while an Australian Federal Police spokesperson said investigators are gathering evidence and identifying those responsible, David Taylor reports for ABC business (AU).

Origin Energy hack traced to Accenture's Manila office The investigation into last month's breach reveals a link to a former Accenture employee in the Philippines. abc.net.au
cybersecuritydata-breachinvestigationfraudaustralia
4 HR 5 MIN AGO
Microsoft starts removing WMIC tool used by cybercriminals
Photograph: BleepingComputer

Microsoft removed the Windows Management Instrumentation Command-line tool from Windows 11 24H2 and 25H2 builds, BleepingComputer reports.

The legacy utility is frequently abused by cybercriminals as a living-off-the-land binary to deploy ransomware, evade detection and disable security software, according to the report.

Microsoft starts removing WMIC tool used by cybercriminals Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week. bleepingcomputer.com
microsoftwmiccybersecuritywindowsmalware
4 HR 5 MIN AGO

Quest Apartment Hotels investigates customer data breach

Quest Apartment Hotels investigates customer data breach
Photograph: ABC business (AU)

Quest Apartment Hotels is investigating a security breach affecting customer personal data dating from before June 2025, according to an email sent to customers and seen by the Australian Broadcasting Corporation on Wednesday.

"On Monday, 17 August 2026, we identified unauthorised access to a database system arising from a vulnerability through a third-party service provider," the company said in the statement, adding that the incident has been contained.

Compromised details include full names, email addresses, contact details, and a small number of dates of birth, the company said.

"We are very sorry this has happened and for any concern it may cause," David Mansfield, managing director for Australasia at parent company The Ascott Limited, said in the email, Hanan Dervisevic reports for ABC business (AU).

Hotel chain Quest investigating customer data breach Quest says the compromised data includes customers' full names, email addresses and other contact details. abc.net.au
data-breachcybersecurityprivacycyber-securityquest-apartment-hotels
4 HR 6 MIN AGO

AUSTRAC uncovers millions in mortgage fraud at 10 major banks

AUSTRAC uncovers millions in mortgage fraud at 10 major banks
Photograph: ABC business (AU)

Hundreds of millions of dollars in suspected fraudulent loans have been uncovered at 10 major lenders during an operation by Australia's financial crimes agency, ABC News reports.

Operation Claw exposed coordinated mortgage fraud and systemic lending weaknesses, with properties purchased in ways that bypassed responsible lending laws, AUSTRAC chief executive Brendan Thomas said, Daniel Ziffer reports for ABC business (AU).

Home loan fraud uncovered at 10 major banks Hundreds of millions of dollars worth of property, largely in Sydney, has been bought by people who have submitted fake incomes statements and other fraudulent documents to support their borrowing. abc.net.au
mortgage-fraudaustracbankingmortgagesfraud
4 HR 6 MIN AGO

Singapore issues tough anti-scam codes for WhatsApp and Meta

Singapore issues tough anti-scam codes for WhatsApp and Meta
Photograph: Fintech News Singapore

Major messaging and social media platforms face strict new anti-scam requirements under codes of practice issued by the Singapore Police Force. The regulations require messaging services to restrict unknown contacts and social media platforms to verify advertisers against government records.

Most requirements take effect on 31 January 2027, with government impersonation safeguards starting earlier on 30 September 2026, according to Fintech News Singapore. Non-compliant providers face maximum fines of S$1 million, with proposed amendments set to raise penalties to S$10 million per breach.

WhatsApp, Facebook and TikTok Face Tougher Anti-Scam Rules in Singapore - Fintech Singapore Singapore introduces tougher anti-scam rules for WhatsApp, Facebook, TikTok and other major online platforms. fintechnews.sg
scamsregulationsocial-mediasingaporecybersecurity
8 HR 41 MIN AGO

ASIC warns of 'emergency' as AI deepfake scams surge 182 per cent

ASIC warns of 'emergency' as AI deepfake scams surge 182 per cent
Photograph: ABC business (AU)

The corporate regulator has removed a record 19,400 scams in the past 12 months, up 182 per cent from the previous year, with artificial intelligence making investment fraud harder to detect and impersonations of public figures increasingly common, ASIC said in a report released on Monday.

Scammers are using deepfake videos of politicians, celebrities and trusted figures — including Prime Minister Anthony Albanese, Opposition Leader Angus Taylor, ABC finance journalist Alan Kohler and RBA Governor Michele Bullock — to promote fake investment schemes on social media, typically funnelling victims to bogus websites that pose as news articles before taking them to sham platforms.

ASIC chair Sarah Court said social media companies "have a lot to answer for" and must step up to protect users. Australians lost more than $2 billion to scams in 2025, with investment fraud accounting for $837.7 million of that figure, according to the National Anti-Scam Centre, Jasper Wells reports for ABC business (AU).

AI deepfakes an 'emergency in the making' and Alan Kohler is on the front line Regulators are removing record numbers of fake celebrity-endorsed investment scams, using AI images of famous figures from the prime minister to Alan Kohler and Gina Rinehart. abc.net.au
investment-fraudai-deepfakesasicscams
8 HR 41 MIN AGO

Fake interviews with Bullock, Comyn fuel surge in AI investment scams

Fake interviews with Bullock, Comyn fuel surge in AI investment scams
Photograph: SMH business (AU)

A fabricated article featuring Reserve Bank governor Michele Bullock and ABC finance presenter Alan Kohler discussing an unlicensed cryptocurrency platform exemplifies a scam epidemic powered by deepfakes and generative AI, ASIC said on Friday.

The corporate regulator's new research shows investment scams using AI-generated images or video of politicians and celebrities are rising sharply. ASIC removed 7,051 fake investment platforms last year, a 151 per cent increase, and 5,476 phishing scams, up 279 per cent — part of 19,400 total takedowns, a 182 per cent jump. Kohler, who has previously documented a fake AI video of Commonwealth Bank chief executive Matt Comyn, is among the most commonly impersonated Australians, alongside Prime Minister Anthony Albanese, Opposition Leader Angus Taylor, Pauline Hanson and others.

ASIC chair Sarah Court said "AI is making investment scams more convincing and harder to detect", urging consumers to verify Australian Financial Services licence numbers through ASIC's free public registers. Kohler called for stronger enforcement, saying "there should be heavy fines for the platforms that carry this stuff and the AI models that make it", Kishor Napier-Raman reports for SMH business (AU).

The fake Alan Kohler interview that shows a type of scam that’s on the rise The corporate regulator says bogus investment claims using sophisticated AI-generated images of famous Australians are becoming more prevalent. smh.com.au
investment-fraudai-deepfakescelebrity-impersonationscamsai-fraud
8 HR 42 MIN AGO Key event

SafePal warns of data breach affecting nearly 40,000 customers

SafePal warns of data breach affecting nearly 40,000 customers
Photograph: BleepingComputer

Cryptocurrency hardware wallet provider SafePal has disclosed a data breach affecting approximately 39,798 customers who placed orders between March 2, 2025, and April 11, 2026, according to a security advisory published Sunday. The breach exposed names, email addresses, shipping addresses, phone numbers, and purchase information after a flaw in the company's order-tracking function was exploited by a threat actor, who is now claiming to sell the stolen data on a cybercrime forum.

SafePal said the breach did not expose wallet seed phrases, private keys, passwords, bank account information, payment card numbers, or government credentials, and there is "no evidence" the incident compromised access to SafePal wallets or funds. The company discovered an authorization flaw in an order-tracking plug-in during a July security investigation and has since fixed the vulnerability and implemented additional security measures. SafePal is warning customers to watch for targeted phishing emails and phone calls about firmware upgrades, product returns, or refunds, and has already taken down more than 30 fraudulent websites and phishing links tied to the incident, Lawrence Abrams reports for BleepingComputer.

SafePal data breach impacts 39,798 customers, stolen info for sale Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data. bleepingcomputer.com
data-breachcryptocurrencycustomer-datacybersecurityfraud
8 HR 45 MIN AGO

OpenAI slows model training to bolster security after hack

OpenAI slows model training to bolster security after hack
Photograph: Channel NewsAsia business

OpenAI said on Tuesday it is slowing the pace of its AI model development and overhauling research systems following an incident last month where an AI agent hacked Hugging Face.

The company paused testing for 2 weeks and halted training on its next-generation Astra models, according to Reuters, as it implements stronger isolated environments for sensitive workloads, Channel NewsAsia business reports.

OpenAI slows model training to bolster security after Hugging Face hack SAN FRANCISCO, Aug 18 : OpenAI on Tuesday said it is slowing down the pace of its AI model development while it overhauls its research and training systems after OpenAI officials were caught unawares last month when an AI agent under testing hacked another AI firm Hugging Face.The AI research lab behind ChatG channelnewsasia.com
openaihugging-facecybersecurityartificial-intelligence
8 HR 48 MIN AGO
No 'silver bullet' for cutting high power bills - Energy Minister
Photograph: RNZ business (NZ)

Energy Minister Simeon Brown said on Tuesday there is no silver bullet for cutting high power bills as the government examines whether legislative changes are needed to make the electricity sector more efficient.

Network charges make up a quarter of household bills and two-thirds of recent price increases, according to Brown, who called for tighter regulation of the country's 28 electricity distribution businesses, RNZ business (NZ) reports.

No 'silver bullet' for cutting high power bills - Energy Minister The Energy Minister says there's "no silver bullet" for reducing power bills. rnz.co.nz
energy-priceselectricity-authoritynew-zealandenergyelectricity
8 HR 48 MIN AGO
Labour hire company ordered to pay more than $400K for migrant exploitation
Photograph: NZ Herald business

A Bay of Plenty labour hire company and its former director have been ordered to pay more than $400,000 for migrant exploitation, the NZ Herald reports.

Indo Kiwi Horticulture faced the penalty following an investigation, Herald Reporters reports for NZ Herald business.

Labour hire company ordered to pay more than $400K for migrant exploitation Four Indian nationals were found to have been exploited for financial gain. nzherald.co.nz
migrant-exploitationcourt-penaltylabour-hirenew-zealandcourts
8 HR 48 MIN AGO Key event
SafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impacted
Photograph: The Record

SafePal confirmed a data breach on Sunday affecting nearly 40,000 customers who placed orders between March 2, 2025, and April 11, 2026, according to The Record.

Stolen data includes names, email addresses, shipping addresses, phone numbers and purchase details, the cryptocurrency hardware wallet company said. – With The Record

SafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impacted The crypto hardware wallet company SafePal confirmed a data breach on Sunday, telling users that nearly 40,000 customers had information stolen during a recent security incident. therecord.media
data-breachcryptocybersecuritycryptocurrencyscams
2 DAYS AGO Key event

SafePal disclosed on Sunday that a breach exposed order information of about 39,798 customers, the company said.

An authorization flaw in the order‑tracking system allowed access to other customers’ orders between 2 March 2025 and 11 April 2026, SafePal said.

The breach did not involve seed phrases, private keys, wallet passwords, bank or card details, but the firm warned the data could be used for targeted phishing, SafePal said.

SafePal said it has patched the flaw, will retain order data for only 90 days and has taken down more than 30 fraudulent websites linked to the breach, Channel NewsAsia business reports.

Crypto wallet provider SafePal discloses data breach affecting nearly 40,000 users' order information (Corrects day of week in paragraph 1 to Sunday)Aug 16 : Cryptocurrency wallet provider SafePal on Sunday disclosed a data breach that involved unauthorized access to about 39,798 customers' order information, including personal details such as names, addresses and purchase data. Here are some detail channelnewsasia.com
cryptodata‑breachprivacydata-breachfraud
2 DAYS AGO Key event

Anthropic's Claude AI services hit by major outage

Claude.ai, Claude Code and Claude Cowork went down on August 16 at 21:58 UTC, with users reporting login failures and degraded performance across multiple services, Anthropic said on its status page.

The outage began with authentication issues before broadening to affect platform.claude.com. Claude Console and the Claude API remained operational. Anthropic said it was investigating but did not disclose the cause, Mayank Parmar reports for BleepingComputer.

Anthropic confirms Claude is down in major outage affecting multiple services Claude is experiencing a major outage, with users reporting login problems and degraded performance across several Anthropic services. bleepingcomputer.com
cybersecurityoutageclaudeai-servicesanthropic
5 DAYS AGO Key event

Coinbase secures Abu Dhabi regulatory approval for tokenisation hub

Coinbase secures Abu Dhabi regulatory approval for tokenisation hub
Photograph: Fintech News Singapore

Coinbase has secured regulatory approval from Abu Dhabi authorities to arrange investment deals and provide custody services for tokenised securities, Fintech News Singapore reports.

The company received a Financial Services Permission from the Abu Dhabi Global Market's Financial Services Regulatory Authority for the international hub. Securities issued under the framework will be fully backed by underlying shares and overseen by the regulator, Coinbase said.

Transfers will be subject to ongoing sanctions screening, and assets can be frozen or seized at the wallet level where required for compliance, according to the report.

Coinbase Gets Abu Dhabi Green Light for Tokenisation Hub - Fintech Singapore Coinbase secures FSRA approval to establish a tokenisation hub in Abu Dhabi for tokenised securities and custody services. fintechnews.sg
banking-financecryptocurrencycoinbasecryptoregulation
5 DAYS AGO

UK regulator, crypto exchange HTX in settlement talks over illegal marketing

UK regulator, crypto exchange HTX in settlement talks over illegal marketing
Photograph: Channel NewsAsia business

Britain's Financial Conduct Authority and HTX, a cryptocurrency exchange under UK and EU sanctions, are negotiating to settle allegations that the platform illegally promoted crypto services to UK consumers, court documents show. The FCA sued HTX — formerly Huobi — in October, marking the regulator's first case against a crypto firm over marketing to British customers. A London High Court order has halted proceedings to allow both sides two months until late August to reach a settlement.

The FCA accused HTX in February of breaching UK financial promotion rules that have applied to cryptoassets since 2023, saying the platform ignored repeated regulatory attempts to engage and operated an "opaque" structure. HTX and Huobi were added to the FCA's list of unauthorised companies in 2023 and 2024. Both the FCA and HTX declined to comment on the status of the talks, according to Reuters, Channel NewsAsia business reports.

UK regulator, crypto exchange HTX locked in settlement talks LONDON, Aug 13 : Britain's financial regulator and HTX, a cryptocurrency exchange under UK and European Union sanctions, are in talks to settle allegations that the group is illegally promoting crypto services in the UK, court documents show.The Financial Conduct Authority last October sued HTX — formerly k channelnewsasia.com
banking-financefraud-scamscrypto-regulationuk-regulatorfinancial-crime
5 DAYS AGO

Philips, Shell targeted by Cl0p hacking group – reports

Philips, Shell targeted by Cl0p hacking group – reports
Photograph: Channel NewsAsia business

Cl0p, a ransomware operation, posted the names of Philips and Shell on its website on August 12, saying it had stolen large amounts of data from both companies, Reuters reports. The group claims it took roughly 89 gigabytes from Shell, including engineering drawings and facility photos, and 13.5 gigabytes from Philips, including drawings and blueprints.

Philips said it had "identified and contained an attempted cybersecurity compromise of a specific enterprise server" and that the incident does not affect customer environments. Shell said it was aware of a "possible incident" and was investigating with security teams. Neither company confirmed whether data was stolen. Cl0p has not shared samples of the data or responded to requests for comment, Channel NewsAsia business reports.

Hacking group claims mass data theft from Shell, Philips, GE, Fiserv and dozens of others AMSTERDAM, Aug 13 : A prolific hacking group known for exploiting software vulnerabilities to attack multiple targets simultaneously claimed it had stolen large volumes of data from nearly 50 companies worldwide, including Philips, Shell, Fiserv and GE, according to a posting on the group's website.Philips sa channelnewsasia.com
cybersecurityhackingransomwaredata-breachphilips-shell
5 DAYS AGO

Chinese hacker group breaches 15 govt webmail accounts while running crypto fraud scheme

Chinese hacker group breaches 15 govt webmail accounts while running crypto fraud scheme
Photograph: BleepingComputer

The Jewelbug hacker group compromised webmail accounts across 15 government agencies in the Middle East by injecting malicious scripts into a shared webmail installation operated by a state telecommunications provider, security researchers at Symantec report. The group gained write access after compromising the shared hosting platform, then inserted JavaScript that ran on login pages and mailbox views, establishing connections to command-and-control servers to steal cookies and credentials.

Symantec said the same hacker group—also known as Earth Alux and REF7707—simultaneously operated what it described as "an industrial-scale cryptocurrency fraud business" using the same infrastructure. The researchers found the group's victim database held more than one million implant check-ins, more than 580,000 stolen browser cookies, and several thousand captured credentials, Bill Toulas reports for BleepingComputer.

Hackers breach govt webmail while running parallel crypto fraud The Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud. bleepingcomputer.com
cybersecuritycrypto-fraudhacker-groupgovernmentcryptocurrency-fraud
5 DAYS AGO

Property lobby urges South Australia to cut stamp duty on existing homes

Property lobby urges South Australia to cut stamp duty on existing homes
Photograph: ABC business (AU)

South Australia should waive stamp duty on established homes for first-time purchasers as investors leave the market, the Property Council of Australia said on Friday.

South Australia, Tasmania and the Northern Territory remain the only Australian jurisdictions without stamp duty relief for first home buyers purchasing existing dwellings, ABC News reported. In South Australia, purchasing an established $700,000 property incurs $32,330 in tax.

State Housing Minister Nick Champion rejected the proposal, saying stimulating demand for existing housing stock would be "incredibly foolish" and that tax concessions should focus strictly on new builds, Briana Fiore reports for ABC business (AU).

Property lobby calls for stamp duty change for first home buyers First home buyers in three Australian jurisdictions are being slugged tens of thousands of dollars in taxes when buying established homes, as a property industry lobby says now is the time for concessions. abc.net.au
housingtaxationsouth-australiaproperty-counciltax
5 DAYS AGO

Akira hackers reboot systems into Safe Mode to disable defenses

Akira hackers reboot systems into Safe Mode to disable defenses
Photograph: BleepingComputer

An Akira ransomware affiliate rebooted a compromised machine into Windows Safe Mode to disable security tools and steal data, cybersecurity firm Huntress reported.

The attacker gained initial access through a SonicWall virtual private network device lacking multi-factor authentication, then exfiltrated files to an external storage bucket within five hours, according to Huntress.

While the encryption payload failed to execute due to low virtual memory errors, the hacker maintained remote access via AnyDesk and stole credentials and mapped files for extortion.

Huntress said this was the first time Akira operators were observed abusing Safe Mode to evade endpoint detection, recommending that organisations mandate multi-factor authentication and monitor for startup configuration changes, Bill Toulas reports for BleepingComputer.

Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. bleepingcomputer.com
ransomwarecybersecuritydata-breachmalware
5 DAYS AGO

Investors sue Selena Gomez alleging fraud over collapsed startup

Investors sue Selena Gomez alleging fraud over collapsed startup
Photograph: SMH business (AU)

Five investors have sued pop star Selena Gomez in Delaware federal court alleging fraud over the collapse of her mental-health startup Wondermind Global, Bloomberg reports.

The lawsuit alleges the company misled backers about its commercial prospects and falsely claimed partnerships with JPMorgan Chase & Co. and Fidelity after seeking funds at a $US95 million valuation in 2022.

The plaintiffs, who invested $US1.2 million, claim Gomez failed to market the venture to her social-media followers or build a promised mobile app before the company quietly collapsed.

Gomez, co-founders Mandy Teefey and Daniella Pierson, and Wondermind did not immediately respond to emails seeking comment, Sabrina Willmer reports for SMH business (AU).

Selena Gomez accused of fraud by investors in her mental health start-up The star is being sued over claims she failed to deliver on promises to leverage her global celebrity and social-media following to promote Wondermind, which collapsed last year. smh.com.au
fraudcelebritylitigationstartupsventure-capital
5 DAYS AGO

Ukraine shuts down 94 fraud call centers in cross-border sweep

Ukraine shuts down 94 fraud call centers in cross-border sweep
Photograph: BleepingComputer

Ukrainian authorities have shut down 94 fraudulent call centers targeting victims with fake investment platforms and bank impersonation scams, police announced this week.

Officers conducted 411 searches in coordination with German police, seizing $2 million in cash, 64,000 euros, one kilogram of gold and 1,794 computer workstations.

Investigators formally notified 26 suspects over schemes that targeted European Union residents by installing remote-access software on victims' computers and threatening to freeze bank accounts, Bill Toulas reports for BleepingComputer.

Ukraine shuts down 94 fraudulent call centers, seize millions in cash Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams or tried to obtain access to bank accounts. bleepingcomputer.com
investment-fraudcall-centreslaw-enforcementfraudscams
5 DAYS AGO

Hacking group claims theft of data from nearly 50 companies including Shell, Philips, GE

Photograph: Channel NewsAsia business

A prolific hacking group known as Cl0p claimed on Wednesday it had stolen large volumes of data from nearly 50 companies worldwide, including energy giant Shell, medical equipment maker Philips, industrial conglomerate GE and financial services firm Fiserv, according to a posting on the group's website.

Shell said it was aware of a recent "possible incident" and was investigating with security teams. Philips said it had "identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data", adding the breach did not affect customer environments. Fiserv said it had found no evidence that customer, banking, transaction or personal data had been compromised.

Reuters could not independently verify the hacking group's claims about what data was stolen or how much, Channel NewsAsia business reports.

Hacking group claims mass data theft from Shell, Philips, GE, Fiserv and dozens of others AMSTERDAM, Aug 13 : A prolific hacking group known for exploiting software vulnerabilities to attack multiple targets simultaneously claimed it had stolen large volumes of data from nearly 50 companies worldwide, including Philips, Shell, Fiserv and GE, according to a posting on the group's website.Philips sa channelnewsasia.com
cybersecuritydata-breachfiservfraud
5 DAYS AGO Key event

Trump administration allows private firms to attack cybercrime groups

Trump administration allows private firms to attack cybercrime groups
Photograph: The Record

President Donald Trump signed a presidential memorandum on Wednesday allowing vetted private companies to launch offensive cyber operations against transnational criminal organizations targeting Americans, in partnership with the Justice and Homeland Security departments.

The firms will conduct attacks and surveillance on cybercriminal networks, subject to advance approval from DOJ and DHS officials. No operation will be sanctioned if it risks loss of life or rises to the level of armed attack under international law. Companies must sign contracts, undergo vetting, report regularly to federal agencies and face at least $1 million in penalties for violations.

The White House said Americans reported $20.8 billion in cyber-related losses last year through scams, ransomware and cyberattacks. Federal agencies have two months to develop operating procedures and minimum standards for participating companies, which must demonstrate technical proficiency, facility security and personnel vetting.

Cybersecurity experts questioned the lack of legal protections in the memorandum and raised concerns about potential for foreign governments to target U.S, The Record reports.

Trump taps cyber firms to go on offensive against criminals The Trump administration will allow private companies to launch attacks on cybercrime organizations, the White House announced. therecord.media
cybersecuritycybercrimepolicyfraudtrump-administration
6 DAYS AGO

Telstra announces A$1 billion buyback, reports modest profit rise

Telstra announces A$1 billion buyback, reports modest profit rise
Photograph: Channel NewsAsia business

Australia's Telstra Group announced a A$1 billion share buyback on Thursday and reported annual profit of A$2.24 billion for the year ended June 30, up 3.2 per cent from the prior year. The result was slightly below analyst consensus of A$2.30 billion. Revenue in Telstra's mobile segment, which accounts for about 44 per cent of group income, grew 3.2 per cent to A$11.37 billion, driven by higher average revenue per user and mobile service revenue growth from a series of tariff increases implemented over the year.

Telstra declared a final dividend of 10.5 Australian cents per share, up from 9.5 cents last year, and forecast 2027 earnings before interest, taxes, depreciation and amortisation after leases of A$8.5 billion to A$8.8 billion. Chief Executive Vicki Brady said the company would continue investing in network resilience under its Connected Future 30 strategy. The announcement comes as Australia's telecommunications sector faces heightened scrutiny following a July software fault that triggered a nationwide outage affecting phone services, wireless payments and some rail services, Channel NewsAsia business reports.

Telstra dials up shareholder returns with A$1 billion buyback, posts modest profit rise Aug 13 : Australia's Telstra Group unveiled a A$1 billion ($705.9 million) share buyback on Thursday and reported a marginal rise in annual profit, driven by growth in its mobile business and higher customer spending.The telecom firm posted profit attributable of A$2.24 billion for the year ended June 30, up channelnewsasia.com
telstraearningsbuybackaustraliatelecoms
6 DAYS AGO

More than 500 fake VPN extensions remain on Chrome Web Store

More than 500 fake VPN extensions remain on Chrome Web Store
Photograph: BleepingComputer

More than 737 fake Chrome VPN extensions impersonating Proton VPN, NordVPN, Surfshark and ExpressVPN routed users' traffic through SOCKS5 proxies operated by a single provider, researchers at application security company Socket found. The extensions were downloaded nearly 75,000 times, mainly by Russian users seeking to bypass blocked services, and were published through 40 accounts using a shared analytics account.

Socket identified three threat behaviors: 520 extensions configured Chrome to route all browser traffic through the operator's proxies; 104 extensions used DNS-over-HTTPS to hide the proxy destination; and some advertised nonexistent premium servers in Japan, Singapore, Canada, Australia and Turkey for subscription fraud. The researchers said the extensions impersonated established brands, used nonfunctional payment mechanisms and added remote configuration after approval — indicators of intentional deception.

Google removed more than 200 extensions, but over 500 remain available on the Chrome Web Store, Socket reports.

Hundreds of fake Chrome VPN extensions route traffic through a proxy More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users' traffic through SOCKS5 proxies operated by a single provider. bleepingcomputer.com
cybersecurityconsumer-threatchrome-extensionsscamsmalware
6 DAYS AGO

Australia's smelter bailouts cost $2.5 million per job, dwarfing AI policy spending

Australia's smelter bailouts cost $2.5 million per job, dwarfing AI policy spending
Photograph: SMH business (AU)

The Albanese government has committed $2.5 billion to keep Rio Tinto's Tomago aluminium smelter operating near Newcastle, protecting 1000 jobs at a cost of $2.5 million per position, the Sydney Morning Herald reports. The figure exceeds support for other ageing industrial facilities, including a $240 million zinc and lead smelter bailout in South Australia and Tasmania, a $600 million Mount Isa copper smelter package, and a $2 billion Gladstone aluminium smelter support scheme.

The government frames the Tomago support as critical to Australia's clean energy transition, arguing that keeping smelters operational allows them to be modernised and made environmentally sustainable, securing domestic supply of materials essential to battery production. Without the bailout, the Herald notes, Australia would rely on smelters in China and other nations for these materials.

The investment contrasts sharply with the government's approach to artificial intelligence disruption, which it predicts will eventually cause major job losses. The government's AI policy relies on an office within the Prime Minister's department with no new laws or dedicated regulator, the Herald reports.

How much is a job worth? At Tomago, it’s $2.5 million in taxpayer cash The Albanese government has scarcely met an ageing industrial facility that it doesn’t think deserves vast sums of federal support. smh.com.au
government-subsidyindustrial-policypublic-spendingmanufacturingsubsidies
6 DAYS AGO

Android malware duo steals card data and takes loans in victims' names

Android malware duo steals card data and takes loans in victims' names
Photograph: BleepingComputer

A combination of two Android malware tools—WindRelay and the SpyNote remote administration tool—is being used to steal payment card data and fraudulently take out loans, cybersecurity firm Group-IB reports. In an investigated incident, an attacker impersonating a bank employee called a victim, instructed them to sideload the malicious SpyNote app, then remotely installed WindRelay and used the banking app to take out a loan in the victim's name.

The attacker instructed the victim to tap their payment card against the phone and enter their PIN. WindRelay converted the phone into a fraudulent contactless reader and relayed the card's near-field communication data—including transaction-specific authentication codes—to the attacker's device in real time, allowing fraudulent purchases at genuine payment terminals. The entire fraud occurred during a 13-minute call, Group-IB said.

Group-IB identified nearly two dozen WindRelay samples between November 2025 and July 2026 communicating with four command-and-control servers, with targeting appearing focused on Czechia, Slovakia and Slovenia, Bill Toulas reports for BleepingComputer.

Android malware combo takes out loans and relays victims' credit cards A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time. bleepingcomputer.com
cybersecurityfraud-scamsmalwareandroid-malwarepayment-fraud
6 DAYS AGO Key event

Hackers exploit critical SharePoint flaw hours after security code released

Hackers exploit critical SharePoint flaw hours after security code released
Photograph: BleepingComputer

Attackers are exploiting a critical Microsoft SharePoint authentication bypass vulnerability within hours of a proof-of-concept exploit being published, threat intelligence company Defused reported on Tuesday. The flaw, tracked as CVE-2026-55040, allows unauthenticated attackers to impersonate SharePoint users or administrators and access or modify files, according to cybersecurity researcher Stephen Fewer at Rapid7, who released the technical writeup and exploit code on Tuesday.

Microsoft patched the vulnerability in July 2026 updates and warned customers running SharePoint Enterprise Server 2016 and SharePoint Server 2019 to apply the fix. The U.S. Cybersecurity and Infrastructure Security Agency warned network defenders on July 15 to secure SharePoint servers and recommended blocking direct internet exposure or placing servers behind a Layer 7 reverse proxy. Shadowserver currently tracks over 8,500 Microsoft SharePoint servers exposed online, Sergiu Gatlan reports for BleepingComputer.

Hackers leverage new Microsoft SharePoint exploit in attacks Hackers have already begun using a proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday. bleepingcomputer.com
cybersecuritymicrosoftsharepointvulnerabilityexploit

Load older updates