The Financial Register.

Inward fraud & financial crime, explained for Gen Z

Live coverage

LiveUpdated 07:30 pm

Live updates

The Wire

Rolling updates from The Financial Register.

As tobacconist firebombings intensify in Melbourne, nearby stores are being denied insurance
Photograph: Guardian business

Small businesses operating near Melbourne tobacconists are being denied insurance or priced out of coverage following a surge in arson attacks linked to the illicit tobacco trade, according to Guardian Australia reporting.

Crime syndicates have been implicated in more than 200 firebombings across Australia since 2023 as rival groups compete for control of the market, government data shows, Guardian business reports.

As tobacconist firebombings intensify in Melbourne, nearby stores are being denied insurance Arson attacks related to illegal tobacco trade are also causing revenue and reputation problems for neighbouring businesses theguardian.com
insurancesmall-businessarsoncrimeaustralia
Trust or non-profitThe GuardianScott Trust (Guardian Media Group)Trust-owned: no shareholders and no proprietor.

North Korean hackers infect 30,000 devices in $10.5m global crypto scam

North Korean hackers infect 30,000 devices in $10.5m global crypto scam
Photograph: The Record

North Korean hackers have stolen more than $10.5 million from job seekers across 100 countries in a cyber campaign dubbed "WaterPlum", the FBI and international law enforcement agencies said in an advisory.

The hackers infected at least 30,000 devices and stole credentials from about 7,000 cryptocurrency wallets between December 2025 and July 2026 by posing as AI or blockchain companies, according to the advisory released on Friday, The Record reports.

North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign The FBI and Defense Department partnered with Japan’s National Police Agency and law enforcement agencies in Australia and Germany on a new advisory about “WaterPlum” — a group of cyber actors allegedly stealing cryptocurrency from job applicants by posing as AI or blockchain companies. therecord.media
cybersecuritycryptocurrencyfbicryptoscams
CommercialThe RecordRecorded Future · trade pressPublished by a cybersecurity vendor that sells threat intelligence.

Quest Apartment Hotels data breach affects nearly two million customers

Quest Apartment Hotels data breach affects nearly two million customers
Photograph: SBS

Nearly 2 million Quest Apartment Hotels customers have had their personal data compromised in a cyberattack involving a third-party technology provider, according to the accommodation provider.

David Mansfield, the managing director of parent company The Ascott Limited, said on Wednesday that a forensic analysis revealed information relating to 1,991,613 customers was affected in the incident, which involved records from before June 2025.

The compromised data includes credit card numbers, passport and driver licence details, Medicare numbers and vehicle registrations, according to AAP reports.

Nearly two million Quest Apartment Hotels customers affected by data breach Experts say the incident raises fresh questions about how long companies are retaining customer data for. sbs.com.au
data-breachcybersecurityconsumer-protectionaustraliaprivacy
Publicly fundedSBS NewsSpecial Broadcasting Service · publicly funded

Author details romance scam after losing $317,000 to serial fraudster

Author details romance scam after losing $317,000 to serial fraudster
Photograph: AU scams

An Australian author has detailed losing $317,000 to serial fraudster Hamish McLaren after a 16-month relationship where he posed as a finance executive, Moneymag.com.au reports.

Tracy Hall said she discovered the fraud when she saw McLaren's face in a Crime Stoppers video, realising the man she knew as Max Tavita was a career criminal who had forged her investment documents, AU scams reports.

She thought she For 16 months, Tracy Hall believed she moneymag.com.au
scamsromance-fraudfraudromance-scamaustralia
Not ratedmoneymag.com.auNo ownership record held

Fake MotoGP Adelaide ticketing website targets fans over a year out

Fake MotoGP Adelaide ticketing website targets fans over a year out
Photograph: Yahoo News Australia

South Australian authorities are warning race fans to be on high alert after a fraudulent website surfaced posing as the official ticket vendor for the state's upcoming MotoGP event, Yahoo News Australia reports.

"It is very concerning that this page purporting to be an official MotoGP Adelaide website and containing misinformation and AI content is circulating on social media," said Michael Brown, South Australia's cabinet member for consumer and business affairs.

The illegitimate site, which features contact details with a Czechia area code and claims a company called TicketsGP is the official seller, is encouraging users to hand over personal information, according to the government.

– With Yahoo News Australia

New Aus MotoGP race hit by scam scandal Authorities have issued a warning to MotoGP fans about a scam website falsely claiming to be the official ticket vendor for Adelaide’s debut race. au.news.yahoo.com
motogpscamsfraudaustraliaconsumer-protection
Not ratedau.news.yahoo.comNo ownership record held

The Federal Trade Commission took enforcement action on Tuesday against multilevel marketing operator Amway Corp. and two affiliates over alleged unfair and deceptive business practices, according to a press release from the agency.

A proposed order requires Amway, World Wide Group, L.L.C. and Leadership Team Development Inc. to pay $225 million, which the FTC said is the largest monetary recovery ever collected from a multilevel marketing company in an agency action, FTC press (US consumer protection) reports.

FTC Takes Historic Action Against Multilevel Marketing Operator Amway for Unfair and Deceptive Business Practices Amway Corp., one of the largest multilevel marketing companies in the U.S., and two of its affiliates—World Wide Group, L.L.C. (WWG) and Leadership Team Development Inc. ftc.gov
amwayftcfraudconsumer-protection
Not ratedftc.govNo ownership record held

The Securities and Exchange Commission ordered AIQuest Trading and its operator to stop soliciting public investments immediately over an alleged unregistered securities offering, the Inquirer reports.

The agency's Enforcement and Investor Protection Department issued a cease and desist order against AIQuest Trading, Erica Aguilar, and their agents, according to the report. – With Inquirer business Inquirer business (PH) reports.

https://business.inquirer.net/611512/sec-shuts-down-aiquest-tradings-unregistered-offering business.inquirer.net
secinvestment-fraudphilippinesfraudregulators
CommercialPhilippine Daily InquirerInquirer Group
Western Australian consumers warned of rising ticket scams for summer events
Photograph: Australasian Leisure Management Magazine

Western Australian consumers have been warned to watch for fake ticket scams targeting summer events through social media and online marketplaces, WA ScamNet reports.

WA ScamNet reported more than $1,000 in losses from fake ticket scams in the first few days of September, with more than 80% of last year's recorded losses occurring during the warmer months, according to the Department of Local Government, Industry Regulation and Safety's Consumer Protection division, Australasian Leisure Management Magazine reports.

Western Australian consumers warned of rising ticket scams for summer events ausleisure.com.au
ticket-scamswestern-australiaconsumer-warningscamsconsumer-protection
Not ratedausleisure.com.auNo ownership record held

Former ACCC chair condemns debt collector over false claims

Former ACCC chair condemns debt collector over false claims
Photograph: ABC News &

Former Australian Competition and Consumer Commission chair Allan Fels has likened debt collection tactics targeting an 81-year-old woman to "Robodebt 2.0", as the consumer watchdog takes the firm to court over hundreds of thousands of notices.

Suncorp debt collector ARMA Group pursued Diane Walker for months over an insurance claim she was not responsible for, before ending the ordeal with an apology and financial compensation, according to ABC News reporting on Wednesday.

Suncorp's debt collector engaging in 'worst kind' of bullying, former ACCC chair says Insurance giant Suncorp's debt collector spent months using AI to harass an 81-year-old woman into paying a claim she was not responsible for. abc.net.au
suncorpdebt-collectionbankingscamsaccc
Publicly fundedABC NewsAustralian Broadcasting Corporation · publicly fundedStatutory corporation, funded by the Commonwealth.

53% of Australians worry scams are harder to spot, survey shows

53% of Australians worry scams are harder to spot, survey shows
Photograph: Medianet News Hub

More than half of Australians are worried scams are becoming harder to spot, according to a survey of 2,000 adults released by Good Things Australia.

The research found just 30% of respondents feel confident avoiding online scams, while 28% feel confident managing privacy and safety settings.

Good Things Australia called for less digitally confident adults to remain a priority as the Australian Government develops its proposed Digital Duty of Care.

Get Online Week 2026 will run from 19 to 25 October with free community events across Australia providing practical support with digital skills, Medianet News Hub reports.

More Than Half Of Australians Say Scams Are Becoming Harder To Spot – News Hub newshub.medianet.com.au
scamsconsumer-protectionfraudcybersecurityaustralia
Not ratednewshub.medianet.com.auNo ownership record held
ACCC And AFP Strengthen Collaboration To Combat Scams
Photograph: Mirage News

The Australian Competition and Consumer Commission and the Australian Federal Police signed a memorandum of understanding on 29 June 2026 to enhance information sharing on scam activity, the agencies said in a joint statement.

Scammers stole approximately $2.18 billion from Australian consumers in 2025, according to the ACCC's National Anti-Scam Centre, Mirage News reports.

ACCC And AFP Strengthen Collaboration To Combat Scams On 29 June 2026, the Australian Competition and Consumer Commission (ACCC) and the Australian Federal Police (AFP) have signed a Memorandum of miragenews.com
scamsfraudconsumer-protectionacccafp
Not ratedmiragenews.comNo ownership record held
7 DAYS AGO Key event Share

Indonesian police detain 30 Malaysians in Pontianak hotel scam raid

Indonesian police detain 30 Malaysians in Pontianak hotel scam raid
Photograph: Malay Mail

Indonesian authorities detained 30 Malaysians and a Taiwanese national in a hotel raid in Pontianak, West Kalimantan, for allegedly running an online scam targeting fellow Malaysians.

Pontianak Immigration Office chief Sam Fernando told a press conference on Thursday that the suspects occupied 14 rooms at the hotel and were apprehended at about 11.15am on Tuesday in a joint operation with Pontianak City Police, Bernama reports.

https://www.malaymail.com/news/malaysia/2026/09/11/malaysians-scamming-malaysians-indonesia-nab-30-in-pontianak-hotel-raid/234852 malaymail.com
scamsindonesiamalaysialaw-enforcement
Not ratedmalaymail.comNo ownership record held

Surfshark says hackers breached internal testing and proxy servers

Surfshark says hackers breached internal testing and proxy servers
Photograph: BleepingComputer

Surfshark VPN disclosed on 10 September 2026 that hackers accessed an internal test server and a separate proxy server following a configuration error, according to BleepingComputer.

The company said the breach exposed service configurations, build-related credentials, system binaries and code history, but did not impact customer data, user traffic or production infrastructure.

Surfshark detected the unauthorized activity on 31 August and contained the incident on 2 September, before completing remediation three days later.

The VPN provider rotated impacted internal credentials, revoked exposed tokens and commissioned an independent security audit following the breach.

Surfshark VPN says hackers breached internal testing, proxy servers Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. bleepingcomputer.com
surfsharkvpncybersecuritydata-breach
CommercialBleepingComputerBleepingComputer LLC · trade press

New Android malware combines ransomware, spyware and harassment tactics

New Android malware combines ransomware, spyware and harassment tactics
Photograph: BleepingComputer

A newly discovered Android malware strain called Mantax Otax combines ransomware, spyware and harassment capabilities to target mobile users, according to mobile security company Zimperium.

Indonesian operators distribute the malicious APKs outside the official Google Play store using phishing messages, BleepingComputer reports.

New Android malware encrypts files, steals data, and harasses victims A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. bleepingcomputer.com
malwareandroidransomwarecybersecurityfraud
CommercialBleepingComputerBleepingComputer LLC · trade press
Malicious Mobile Banking Software Proliferates - Fintech Singapore
Photograph: Fintech News Singapore

Kaspersky detected 162,275 new mobile banking Trojan installation packages globally in the first quarter of 2026, according to Fintech News Singapore.

The figure amounts to more than twice the total recorded across the entirety of 2024, the publication reports, citing the cybersecurity firm.

Malicious Mobile Banking Software Proliferates - Fintech Singapore Mobile banking Trojans and other malicious mobile software have proliferated and spread rapidly over the past years as attackers shift their focus to mobile devices for greater profits. fintechnews.sg
mobile-bankingmalwarecybersecuritybanking-trojanskaspersky
CommercialFintech News SingaporeFintech News Network · trade press

Trezor warns users of email provider breach, phishing attacks

Trezor warns users of email provider breach, phishing attacks
Photograph: BleepingComputer

Cryptocurrency hardware wallet maker Trezor warned customers on Wednesday that attackers who breached its third-party email provider are targeting them with phishing emails. The fraudulent messages falsely claim a microcontroller vulnerability could expose wallet seeds to cracking, BleepingComputer reports.

Trezor said it is investigating the breach and has taken the domain down to halt the attacks, warning users not to click any links in the emails.

Trezor warns users of email provider breach, phishing attacks Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks. bleepingcomputer.com
trezorphishingcybersecuritycryptocurrencydata-breach
CommercialBleepingComputerBleepingComputer LLC · trade press

IDScan confirms data breach linked to 153 million driver's licenses

IDScan confirms data breach linked to 153 million driver's licenses
Photograph: BleepingComputer

Identity verification company IDScan confirmed that hackers accessed customer data on its cloud platform, following reports linking the firm to a database containing more than 153 million stolen driver's license scans.

The company disclosed the incident in a September 4 security notice, stating it learned around September 1 that data may have been accessed without authorization, according to BleepingComputer.

IDScan confirms breach tied to 153 million stolen driver’s licenses Identity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver's license scans. bleepingcomputer.com
data-breachidentity-theftcybersecurityunited-states
CommercialBleepingComputerBleepingComputer LLC · trade press

AI-powered attack exploits PaperCut flaws to hack 395 organizations

AI-powered attack exploits PaperCut flaws to hack 395 organizations
Photograph: BleepingComputer

A threat actor used hundreds of AI agents to launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers across 48 countries, according to BleepingComputer.

GreyNoise data indicates the campaign compromised at least 440 instances linked to 395 distinct organizations, with the education sector accounting for roughly half of the breaches.

AI-powered attack exploited PaperCut flaws to hack 395 organizations A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers. bleepingcomputer.com
cybersecurityartificial-intelligencevulnerabilitiespapercut
CommercialBleepingComputerBleepingComputer LLC · trade press
9 DAYS AGO Key event Share

Malaysian authorities arrest Dermacare executives over alleged investment scam

Malaysian authorities arrest Dermacare executives over alleged investment scam
Photograph: Inquirer business (PH)

Malaysian authorities have apprehended the owner and an admin manager of Dermacare upon their arrival in the Philippines following an Interpol red notice, the Securities and Exchange Commission reported on Thursday.

The two officers face charges for allegedly soliciting unauthorized investments without registration, committing investment fraud and engaging in syndicated estafa, according to the SEC, Inquirer business (PH) reports.

Dermacare execs arrested over alleged investment fraud SEC head office—PHOTO FROM SEC WEBSITE MANILA, Philippines — The Securities and Exchange Commission (SEC) reported that authorities have arrested the owner and a key officer of Dermacare for business.inquirer.net
investment-fraudsecarrestsphilippinesmalaysia
CommercialPhilippine Daily InquirerInquirer Group

Sydney syndicate allegedly defrauds banks of $600m in loans

Sydney syndicate allegedly defrauds banks of $600m in loans
Photograph: ABC business (AU)

A Sydney crime syndicate has allegedly defrauded Australian banks of up to $600 million through large-scale fraudulent loan applications, NSW Police said on Thursday.

Police charged three people on Wednesday, including an accounting firm director and two accountants from Bankstown, bringing the total number of people charged by Strike Force Myddleton to 33.

– ABC business (AU)

'Perfect storm': How banks allegedly defrauded of up to $600m NSW police say one of Australia's largest fraud syndicates has fleeced banks of up to $600 million in fraudulent loans in what one investigator described as the largest financial crime he has seen. abc.net.au
fraudbankscrime
Publicly fundedABC NewsAustralian Broadcasting Corporation · publicly fundedStatutory corporation, funded by the Commonwealth.

Russian cybercrime suspect extradited to US over bank account takeovers

Russian cybercrime suspect extradited to US over bank account takeovers
Photograph: The Record

A 36-year-old Russian web developer accused of participating in a multimillion-dollar bank account takeover scheme has been extradited to the United States, federal authorities said Tuesday.

Sergei Anatolyevich Filimonov appeared in an Atlanta federal court on Sept. 4 and pleaded not guilty to charges including fraud and identity theft, prosecutors said.

“Filimonov allegedly used spoofed domains and fraudulent login pages to target unsuspecting online banking customers, stealing millions from victims,” said Marlo Graham, FBI Atlanta’s special agent in charge, according to The Record.

Russian suspect in bank account takeovers is extradited to US A Russian web developer who played a role in a multimillion-dollar bank account takeover scheme has been extradited to the U.S. to face an indictment. therecord.media
cybercrimebank-fraudextraditionfraudunited-states
CommercialThe RecordRecorded Future · trade pressPublished by a cybersecurity vendor that sells threat intelligence.

Doppelcart fraud network deploys 119,000 fake shops to steal cards

Doppelcart fraud network deploys 119,000 fake shops to steal cards
Photograph: BleepingComputer

A massive fraud network known as DoppelCart operates more than 119,000 fake e-commerce domains to harvest credit card details, according to BleepingComputer.

German cybersecurity startup Nebty discovered the network and described it as the largest publicly documented fake-shop cluster by domain count, BleepingComputer reports. More than 105,000 of the sites remain active.

– With BleepingComputer

DoppelCart fraud network uses 119,000 fake shops to steal credit cards A massive operation dubbed "DoppelCart" uses more than 119,000 domains to run a network of fake e-shops that steal payment card details. bleepingcomputer.com
credit-card-fraudfake-shopscybersecurityfraudscams
CommercialBleepingComputerBleepingComputer LLC · trade press

Victoria leads nation in theft-related insurance claims, ICA data shows

Victoria leads nation in theft-related insurance claims, ICA data shows
Photograph: ABC business (AU)

Victorians made more than $300 million in theft-related insurance claims during the 2025-26 financial year, according to new data from the Insurance Council of Australia.

That total included $240 million claimed over 12,300 motor vehicle thefts or burglaries, alongside 3,900 property-related claims costing more than $56 million, the council said on Thursday, ABC business (AU) reports.

Victoria leads nation for theft-related insurance claims, data shows The Insurance Council of Australia calls for urgent action to address crime in Victoria, with theft-related claims costing insurers more than $300 million in the last financial year. abc.net.au
insurancetheftvictoriafraudcrime
Publicly fundedABC NewsAustralian Broadcasting Corporation · publicly fundedStatutory corporation, funded by the Commonwealth.

Property settlement scams cost Australians $166.8 million last year

Property settlement scams cost Australians $166.8 million last year
Photograph: Australian Conveyancer

Property settlement scams cost Australians $166.8 million in 2025, marking an increase of more than 9% from the previous year, according to Scamwatch data published by Australian Conveyancer on Tuesday.

A survey by property settlement company PEXA found that 99% of Australians failed to identify a fraudulent email address even when informed the document was a scam.

Settlement scams getting harder and harder to detect - Australian Conveyancer Conveyancer says 'the traditional warning signs people associated with scams are no longer always present'. australianconveyancer.com.au
scamsfraudreal-estatepropertyaustralia
Not ratedaustralianconveyancer.com.auNo ownership record held

Foreign AI network deepfakes dozens of Australian politicians on Facebook

Foreign AI network deepfakes dozens of Australian politicians on Facebook
Photograph: ABC News &

A foreign network of hundreds of Facebook pages has used AI deepfakes to target dozens of Australian politicians in what researchers describe as a commercially motivated influence campaign. Research organisation Reset Tech tracked more than 200 Facebook pages impersonating political figures over an eight-month period, linking the campaign to an influencer business in Sri Lanka.

About 10 per cent of the network's pages had been monetised through Facebook's creator payment scheme, according to the report. Reset Tech chief research officer Rys Farthing said the operation demonstrated foreign influence driven by financial gain rather than traditional state-based interference, ABC News & reports.

Foreign 'AI slopaganda' network deepfakes dozens of Australian politicians Dozens of Australian politicians have been deepfaked by a "foreign influence" network operating on Facebook, and researchers say there are many more just like it. abc.net.au
deepfakesartificial-intelligencecybersecuritysocial-mediaaustralia
Publicly fundedABC NewsAustralian Broadcasting Corporation · publicly fundedStatutory corporation, funded by the Commonwealth.
10 DAYS AGO Key event Share

ASD warns Australian Adobe Commerce stores over critical zero-day bug

ASD warns Australian Adobe Commerce stores over critical zero-day bug
Photograph: iTnews

The Australian Signals Directorate issued a warning on Wednesday that a substantial number of local Adobe Commerce and Magento Open Source stores face active exploitation from a zero-day vulnerability.

Tracked as CVE-2026-75650 and rated 10.0 on the Common Vulnerability Scoring System, the flaw allows unauthenticated remote code execution, iTnews reports.

ASD warns Aussie Adobe Commerce and Magento stores under attack "StyleSmuggler" zero day vulnerability is a perfect 10. itnews.com.au
cybersecurityasdaustraliaacscadobe
CommercialiTnewsnextmedia · trade press

A phishing framework named BigBear 2.0 bypassed multi-factor authentication at 258 organizations, according to BleepingComputer.

The service was used to steal more than 5,000 Microsoft 365 credentials, BleepingComputer reports.

https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/ bleepingcomputer.com
phishingcybersecuritymicrosoft-365mfamicrosoft365
CommercialBleepingComputerBleepingComputer LLC · trade press
AUSTRAC cancels, suspends or refuses renewal of 45 remittance and VASP registrations
Photograph: FX News Group

AUSTRAC cancelled, suspended or refused the renewal of 45 remittance and virtual asset service provider registrations over the past year, removing the businesses from its registers, FX News Group reports.

"Businesses with cancelled registrations can no longer operate and where appropriate, we've referred individuals behind these businesses to law enforcement and regulatory partners locally and overseas," AUSTRAC CEO Brendan Thomas said.

AUSTRAC cancels, suspends or refuses renewal of 45 remittance and VASP registrations AUSTRAC cancelled, suspended or refused the renewal of 45 remittance and virtual asset service provider (VASP) registrations. fxnewsgroup.com
austracremittancevaspscamsregulation
Not ratedfxnewsgroup.comNo ownership record held
13 DAYS AGO Key event Share

South Korea police refer Hybe founder Bang to prosecutors over 2020 IPO

South Korea police refer Hybe founder Bang to prosecutors over 2020 IPO
Photograph: The Straits Times

South Korean police referred Hybe founder Bang Si-hyuk to prosecutors on Wednesday over allegations he misled investors ahead of the company's 2020 public listing.

Authorities froze 263.1 billion won in suspected illicit gains, according to Yonhap News.

Bang denies wrongdoing and his legal team expects a transparent resolution through the legal process, Yonhap reports.

Bang Si-hyuk, founder of BTS agency Hybe, referred to prosecutors: Report South Korean police referred Hybe founder Bang Si-hyuk to prosecutors over alleged fraudulent trading and illicit gains from the company’s 2020 listing. Read more at straitstimes.com. Read more at straitstimes.com. straitstimes.com
fraudhybeinvestorssouth-koreak-pop
CommercialThe Straits TimesSPH Media TrustReceives Singapore government funding.
14 DAYS AGO Key event Share

Google issues urgent Chrome update for actively exploited zero-day

Google has released an urgent browser update to patch a high-severity zero-day vulnerability in its Chrome browser that is actively being exploited in attacks, BleepingComputer reports.

The security issue, tracked as CVE-2026-85046, is a type confusion flaw in the V8 JavaScript and WebAssembly engine reported by researcher Salvatore Gulizia, according to the advisory cited by BleepingComputer.

Google warns of new Chrome zero-day flaw exploited in attacks Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. bleepingcomputer.com
cybersecuritychromezero-daygooglevulnerabilities
CommercialBleepingComputerBleepingComputer LLC · trade press

Load older updates