The Financial Register.

Inward fraud & financial crime, explained for Gen Z

Live coverage / The Wire

Update · 09:53 am AEST · 14 August 2026

Chinese hacker group breaches 15 govt webmail accounts while running crypto fraud scheme

Chinese hacker group breaches 15 govt webmail accounts while running crypto fraud scheme
Photograph: BleepingComputer

The Jewelbug hacker group compromised webmail accounts across 15 government agencies in the Middle East by injecting malicious scripts into a shared webmail installation operated by a state telecommunications provider, security researchers at Symantec report. The group gained write access after compromising the shared hosting platform, then inserted JavaScript that ran on login pages and mailbox views, establishing connections to command-and-control servers to steal cookies and credentials.

Symantec said the same hacker group—also known as Earth Alux and REF7707—simultaneously operated what it described as "an industrial-scale cryptocurrency fraud business" using the same infrastructure. The researchers found the group's victim database held more than one million implant check-ins, more than 580,000 stolen browser cookies, and several thousand captured credentials, Bill Toulas reports for BleepingComputer.

Hackers breach govt webmail while running parallel crypto fraud The Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud. bleepingcomputer.com
cybersecuritycrypto-fraudhacker-groupgovernmentcryptocurrency-fraud

Follow the live coverage →

Chinese hacker group breaches 15 govt webmail accounts while running crypto fraud scheme | The Financial Register Inward Money