RSSAmplifier

Blog

@BushidoToken Threat Intel

blog.bushidotoken.netRSS feed ↗20 posts

Latest posts

UK Cybercrime Journal: Evolution of Courier Fraud Campaigns

What Happened New data published by the City of London Police in June 2026 reveals that courier fraud losses exceeded £21 million in 2025, with individuals aged over 70 being heavily targeted. The highest concentration of these offenses was recorded in London and the Home Counties. Cybercriminals and fraud syndicates are actively evolving their operational tactics, increasingly pivoting to…

UK Cybercrime Journal: Qilin Ransomware Rampage in H1 2026

What Happened Throughout H1 2026, the Qilin ransomware-as-a-service (RaaS) Tor data leak site (DLS) listed the most UK-based victims out of all ransomware gangs, with up to 37 British organisations hit in total. Qilin's victim count is followed by DragonForce with 21 victims listed, and TheGentlemen with 18 listed. The fallout from the Qilin attack on the UK National Health Service (NHS) supplier,…

UK Cybercrime Journal: H1 2026 Social Media Fraud Trends

What Happened HMRC Issues Warning to TikTok Users On 4 June 2026, HM Revenue and Customs (HMRC) uncovered a suspected £153 million tax fraud scam involving TikTok. The scheme allegedly involved individuals posting advertisements on the TikTok, enticing users to hand over sensitive tax information, including business VAT registration details or personal self-assessment credentials for a financial…

Project ORBITAL

Introduction The modern cyber threat landscape has seen a fundamental shift in how threat actors manage and deploy their infrastructure. Advanced persistent threats (APTs) have almost completely moved away from static command-and-control (C2) servers, opting instead to build complex, multi-layered botnets known as Operational Relay Box (ORB) networks. Project ORBITAL (which stands for Operational…

UK Cybercrime Journal: H1 2026 Dark Web Seizures & Arrests

What Happened Nemesis Dark Web Drug Dealers Arrested On 14 May 2026, two Cambridgeshire drug dealers were sentenced after being arrested in July 2024 by the Eastern Region Special Operations Unit (ERSOU). ERSOU officers recovered Royal Mail parcel labels, order lists, Gorgonites-branded packaging, and a USB memory stick containing login credentials for multiple dark web marketplace accounts. The…

UK Cybercrime Journal: University of Nottingham Breached by ShinyHunters

What Happened On 9 June 2026, the University of Nottingham was listed as a victim on the ShinyHunters Tor data leak site. The attackers leaked over 40GB of billing and payment records, student finance data, and campus portal exports from the University of Nottingham and its Malaysia and China campuses. The data stolen includes contact information, transaction amounts, IP addresses, full names,…

UK Cybercrime Journal: SMS Blaster Gang Convicted

What Happened Officers from the Dedicated Card and Payment Crime Unit (DCPCU), jointly run by the London Met Police and City of London Police, secured the conviction of a man who used an SMS Blaster device to send fraudulent text messages as part of an organised criminal operation in London. The conviction relates to an investigation that previously led to the sentencing of Ruichen Xiong in July…

UK Cybercrime Journal: Argos Account Takeover Fraud

What Happened On 3 June 2026, the City of London Police issued a warning stating Report Fraud has seen a significant increase in cases mentioning the retailer, reflecting how criminals are targeting well-known brands. Report Fraud, which is run by the City of London Police, warned that cybercriminals are using leaked credentials from historical data breaches to hijack Argos user accounts. Once on…

UK Cybercrime Journal: Hargreaves Landsdown Extortion Attempt by Bashe

What Happened Over the course of September 2025 to May 2026, Hargreaves Lansdown the UK-based investment platform has been the subject of IT glitches, hacker claims, and technical outages that have triggered rumours and customer concerns. On 11 September 2025, Hargreaves Lansdown customers reported discrepancies in the balances for their pension and ISA accounts, appearing as if huge sums had been…

UK Cybercrime Journal: Sustained DragonForce Campaign

What Happened Throughout May 2026, affiliates of the DragonForce ransomware-as-a-service (RaaS) platform claimed seven UK-based companies as its victims by posting them on their Tor data leak site. On 27 May 2026 alone, DragonForce ended the month by posting 22 victims from around the world, four of which were UK-based firms. DragonForce’s UK-based victims from May spanned a diverse range of…

Ransomware Tool Matrix Project Updates: Three Groups To Track

Introduction This blog is a focused update on the latest updates to the Ransomware Tool Matrix (RTM) and the Ransomware Vulnerability Matrix (RVM) covering three groups that I have published profiles for to help defenders home in on the threats most relevant to them: TheGentlemen, DragonForce, and WarLock. Rather than write another broad ecosystem summary, the goal of this post is to introduce…

UK Cybercrime Journal: Arup Group Breached by FulcrumSec

What Happened: On 10 May 2026, the UK-based firm Arup Group was listed as a victim on the Tor data leak site of FulcrumSec. On their Tor data leak site, FulcrumSec stated that they have exposed 700GB of GitHub repos and 2TB of Azure and AWS S3 cloud, plus database backups. Other types of data the adversary claims to have stolen includes Neuron BMS client databases, Odoo ERP data, A66 landowner…

UK Cybercrime Journal: British Universities Struck by ShinyHunters Before Exam Season

What Happened: On 3 May 2026, ShinyHunters, the English-speaking adolescent cybercrime collective, claimed they breached Instructure by listing them on their Tor data leak site. Instructure is a US-based software provider behind the widely adopted Canvas Learning Management System (LMS). ShinyHunters reportedly exfiltrated 3.65 terabytes of data, spanning 275 million global records from up to…

UK Cybercrime Journal: £102 million Lost to Scams in 2025

What Happened On 5 May 2026, new data revealed that British romance scam victims were defrauded of a staggering £102 million last year, representing a 29% surge in reported cases. The figures come from information gathered by Report Fraud (f.k.a ActionFraud), which is a City of London Police-run service that logged 10,784 romance scam reports in 2025. According to the data, cybercriminals are…

UK Cybercrime Journal: Inside the Cl0p attack on South Staffs Water

What Happened: On 11 May 2026, the UK Information Commissioner’s Office (ICO) fined South Staffordshire Water £963,900 after the Cl0p ransomware group lurked completely undetected in its network for nearly two years. Initial access reportedly occurred via a malicious phishing email in September 2020, which downloaded Cl0p’s Get2Loader malware and their SDBBOT backdoor to establish persistence. The…

Lessons from the BlackBasta Ransomware Attack on Capita

Introduction When a company that manages data for millions of UK citizens falls victim to ransomware, the whole industry should pay attention to it. On 15 October 2025, the UK Information Commissioner’s Office (ICO) published a detailed 136 page report about the Capita breach. The aim of this blog is to extract actionable cybersecurity lessons from the ICO’s findings as well as open source reports…

Ransomware Tool Matrix Update: Community Reports

Introduction The Ransomware Tool Matrix continues to be a useful passion project that I am happy to continue maintaining. One piece of common feedback I've received for the Ransomware Tool Matrix was that individuals would like to contribute their observations to it, but do not have public links they can cite (such as a formal blog post on a company website). Therefore, I came up with a plan to…

Ransomware Tool Matrix Project Updates: May 2025

Introduction This blog is a summary and analysis of recent additions to the Ransomware Tool Matrix (RTM) as well as the Ransomware Vulnerability Matrix (RVM) . Feedback from the infosec community about these projects has been overwhelmingly positive and many researchers have contacted me to tell me how helpful they have found these to be. It makes me happy to hear how doing something in my spare…

Tracking Adversaries: EvilCorp, the RansomHub affiliate

Introduction This blog is part of a cyber threat intelligence (CTI) blog series called Tracking Adversaries that investigates prominent or new threat groups. The focus of this blog is EvilCorp, a sanctioned Russia-based cybercriminal enterprise known for launching ransomware attacks, and RansomHub, a prominent ransomware as a service (RaaS) operation run by Russian-speaking cybercriminals. These…

BlackBasta Leaks: Lessons from the Ascension Health attack