惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
爱范儿
爱范儿
GbyAI
GbyAI
博客园 - 叶小钗
Last Week in AI
Last Week in AI
Jina AI
Jina AI
Microsoft Security Blog
Microsoft Security Blog
云风的 BLOG
云风的 BLOG
C
Check Point Blog
H
Help Net Security
P
Proofpoint News Feed
酷 壳 – CoolShell
酷 壳 – CoolShell
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
大猫的无限游戏
大猫的无限游戏
H
Hackread – Cybersecurity News, Data Breaches, AI and More
B
Blog RSS Feed
Y
Y Combinator Blog
U
Unit 42
T
Tailwind CSS Blog
MyScale Blog
MyScale Blog
N
Netflix TechBlog - Medium
S
SegmentFault 最新的问题
J
Java Code Geeks
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知

Help Net Security

ChatGPT advanced account security adds passkeys and hardware keys Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Automating Pentest Delivery: A Step-by-Step Guide - PlexTrac Open-source privacy proxy masks PII before prompts reach external AI services Shadow AI risks deepen as 31% of users get no employer training Identity is the control plane for distributed infrastructure AI traffic is getting bigger, louder, and less predictable New infosec products of the month: April 2026 cPanel zero-day exploited for months before patch release (CVE-2026-41940) Cisco releases open-source toolkit for verifying AI model lineage Met Police face criticism for using AI to spy on their own officers Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security Acronis GenAI Protection gives MSPs control over AI usage and data risks - Help Net Security
Algerian national accused of running cybercrime marketpla...
Sinisa Markovic · 2026-06-24 · via Help Net Security

An Algerian national accused of running online marketplaces that sold phishing kits and fraud tools has been extradited from Spain to the United States to face bank fraud conspiracy charges.

Algerian cybercrime marketplace operator=

The investigation began in September 2020 when FBI agents discovered Market0Day, an online marketplace operated by a cybercriminal using the alias “SPOX.” Prosecutors later identified the administrator as Abdellah Belmili, who promoted the platform through his Telegram channel, @SpoxCoder.

Federal investigators say Belmili sold phishing kits, stolen financial data, compromised login credentials, malware tools, and other cybercrime-related services, accepting payment exclusively in Bitcoin.

To see what was being sold through the platform, FBI agents made undercover purchases from Market0Day in December 2020. Among the items obtained was a phishing kit designed to impersonate JPMorgan Chase, which investigators were able to download after completing the transaction.

Agents also paid for access to a compromised cPanel account, a web hosting management platform that can provide administrative control over a website and allow changes to its content. The credentials were never delivered.

By late 2020, customers had begun complaining that products purchased through Market0Day were not being delivered. Belmili allegedly responded by directing users to a new platform called Spoxy.us, which was marketed as a “new store for bulk SMS,” a service commonly linked to phishing campaigns conducted through text messages.

“During the course of the conspiracy, Belmili is accused of defrauding multiple institutions, including American Express, Bank of America, JPMorgan Chase, and Wells Fargo, as well as financial institutions in the United Kingdom,” the Justice Department said.

Investigators identified roughly 5,600 victims in the United States and abroad and traced approximately $900,000 in deposits to an account controlled by Belmili between January 2020 and January 2023.

Belmili was extradited to the United States on June 18 and appeared before a federal judge in Buffalo, New York. If convicted, he faces up to 30 years in prison.

“Cybercriminals often believe they can hide behind usernames and encrypted platforms. This arrest proves otherwise,” said Brendan Dunford, Acting Special Agent-in- Charge of the FBI Buffalo Field Office. “

“The FBI identified the individual behind this alleged cyber fraud scheme, followed the evidence across international borders, secured his extradition, and brought him to the United States to face justice,” concluded Dunford.

US seizes infrastructure linked to Huione Group

In a separate case, the U.S. government seized a cloud computing account tied to a Cambodia-based conglomerate accused of providing money laundering services used by cybercriminals, fraud networks, and scam operations.

Court documents link the seized account to Huione Guarantee, also known as Haowang Guarantee, a platform authorities say hosted Telegram channels advertising stolen credit card and identity data, proceeds from malware-related thefts, money laundering services, and services linked to human trafficking schemes.

“Huione Guarantee also provided escrow services for criminals transacting on its platforms to facilitate transactions, including money launderers laundering cryptocurrency. In doing so, Huione Guarantee facilitated the movement of considerable funds stolen by Southeast Asian scam centers,” authorities noted.

Last October, the Treasury Department’s Financial Crimes Enforcement Network (FinCEN) designated Huione Group as a primary money laundering concern and moved to cut the company off from the U.S. financial system.

According to the FBI’s Internet Crime Complaint Center (IC3), victims reported more than $7.2 billion in losses from cryptocurrency investment scams in 2025 alone.