Risky Bulletin Newsletter
September 07, 2026
Risky Bulletin: BEC campaign steals €35 million from French notaries
Written by
News Editor
This newsletter is brought to you by Authentik. You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.
Hackers have stolen more than €35 million from French notaries in a massive campaign over the past four years.
The attackers breached companies via phishing, took over their networks, and slowly and silently modified transaction details to hijack wired payments.
According to French newspaper Le Monde, the campaign hit more than 500 victims, or about 7% of all French notary offices, France's notary supervisory agency, the Conseil Supérieur du Notariat (CSN).
Government officials worried at one point that hackers might have issued fake notarized acts, or were selling access to a service that did this on demand. For example, they were worried hackers were issuing marriage certificates or forging real estate deals, which would be useful in illegal citizenship acquisition schemes.
None of the hacks were previously disclosed. France's cybersecurity agency ANSSI spent the last two years working behind the scenes to help notaries kick out the hackers and shore up their defenses.
According to ANSSI sources who spoke to Le Monde, the agency described the hackers as particularly persistent and with deep access.
The notaries have responded to the campaign by modifying their procedures. Many notary-specific operations now require two-factor authentication, while certain types of banking and financial details are not allowed to be sent by email anymore and require a physical presence.
Banks have also added extra procedural checks when processing notary transactions back in 2024, but the BEC attacks and illegal transactions continued.
So far, investigators say they have not found signs of any forged documents, but if this happened, it could take several years for them to show up.
Some notaries suffered the BEC losses directly while others used their cyber insurance to cover some of the costs, but after four years, the notary sector seems to be taking the attacks and cybersecurity way more seriously than before.
Risky Business Podcasts
The main Risky Business podcast is now on YouTube with video versions of our recent episodes. Below is our latest weekly show with Pat, James, and guest co-host The Grugq at the helm!
Breaches, hacks, and security incidents
Liquid Network paused after $320m incident: Cryptocurrency company Blockstream has paused the Liquid Network platform after unknown individuals extracted $320 million worth of Bitcoin. In a message left on the platform's blockchain, the attackers claimed they were white-hat security researchers and told the company to reach out. If the incident is confirmed to be a malicious hack, it would become the biggest crypto-heist of the year. [Liquid Network tweet // Web3 is going great]
JetBrains Cadence breach: Hackers have gained access to the JetBrains Cadence cloud-based LLM training platform. The breach took place last month. The hackers exploited a vulnerability in JetBrains' own TeamCity servers to get in. JetBrains says hackers likely stole any source code or credentials that customers were storing in Cadence instances. [JetBrains]
Two more US law firms disclose breaches: Another two major US law firms, Quinn Emanuel and McDermott, have disclosed security breaches. [Reuters]
Roanoke discloses breach after three months: The city of Roanoke, Virginia, took three months to notify residents of a data breach. Hackers accessed a local government department system in May for five days and stole internal documents. City officials are under fire for taking months to notify affected users, not saying what department was hacked, or how many residents were affected. [Cardinal News]
German government agency hacked via ClickFix: Hackers breached the Berlin city government after an employee solved a fake Cloudflare CAPTCHA and installed malware on the city's network. The intrusion was later weaponized to deploy the Rhysida ransomware. The Rhysida group eventually dumped the city's data after Berlin officials refused to pay a $2 million ransom demand. [BSI // Anadolu Ajansı]
Berkeley uni takes systems offline: The University of California, Berkeley has taken several systems offline after a cyberattack at the end of last month. The incident impacted the Department of Electrical Engineering and Computer Sciences. Central campus IT services were not affected and courses took place as normal. [DysruptionHub]
Trezor breach update: Hardware crypto-wallet maker Trezor has updated its data breach notification for a hack of shipping partner ShipMonk. The company says hackers stole the data of 67,000 customers instead of 14,000. [Trezor]
Polarsteps non-leak: Dutch travel app Polarsteps has denied a news report claiming that it leaked user data. The company says the news site scrapped data intentionally made public and shared by its users. [FTM // Polarsteps]
IDScan lawsuits pile up: IDScan, the New Orleans identity verification company who was allegedly hacked and had its data tapped by a hacker, is now being sued left and right by ambulance chasers. [PCMag]
French hospital fined over hack: France's data protection agency CNIL fined the Private Hospital Loire €500,000 for failing to implement proper security measures, leading to hackers stealing the data of more than 720,000 patients and their families in a hack last summer. [CNIL]
DaVita settles ransomware lawsuit: Kidney dialysis service DaVita has settled a class-action lawsuit over its 2025 ransomware attack for $15 million. [HealthcareDive]
Wales' national resource agency leaks employee data: Wales' national resources management agency has leaked the data of past employees after accidentally publishing a spreadsheet on its website. The file exposed the personal data of all employees who worked at the agency between April 2013 and March 2018. The agency has notified affected individuals. [Nation.Cymru] [h/t DataBreaches.net]
OpenAI agents escape testing again: OpenAI agents escaped their testing environments again and hacked a German wiki website at the end of August. The agents created a secret bulletin board for other AI agents where they could share details on tactics on how to escape environments, cheat on tasks, and evade OpenAI's monitoring. The agents shared more than 15,000 messages and the secret board was live for a week before it was discovered. OpenAI acknowledged the incident. [Collusion.wiki // Reuters // OpenAI]
The AIs we found were hyper-focused on succeeding at their tasks and were willing to take extreme actions in pursuit of that goal: pic.twitter.com/WolKz9JSU2
— Thomas Larsen (@thlarsen) September 4, 2026
General tech, AI, and privacy
C# 15 security feature: Microsoft is redesigning some of the memory-safety features of its C# programming language. The changes are now live in the C# 15 preview. [Microsoft]
Windows will infer your age and tell other apps: Microsoft will deploy a new Windows API to infer the age of its users to comply with upcoming age checking regulations. The Windows Age API will also share the inferred age of its users with local apps so they can modify their features based on a user's age category. The API will only be available on Windows 11. [Microsoft]
Project Zenith: Microsoft has announced Project Zenith, a developer-optimized version of Windows 11. Project Zenith devices will ship preinstalled with apps specifically built for software development. This will include Python, Node.js, the Azure and GitHub CLIs, PowerToys, Visual Studio Code, and more. Windows Settings will also be tweaked to ease coding and development tasks. [Microsoft]

Government, politics, and policy
US military turns off ad trackers: The US military has turned off advertising identifiers on phones and computers used by troops across several of its branches. The Air Force, the Army, and the Special Operations Command have disabled ad trackers after reports that Iran used location data to target troops across the Middle East. Several US military branches have also instructed troops to tighten up OpSec and their online presence since the start of the war. [Reuters]
2027 NDAA would allow military cyber contractors: Congress wants to allow the Pentagon to use private contractors to carry out military cyber operations. A provision authorizing the DOD to use cyber contractors was included in the National Defense Authorization Act for Fiscal Year 2027. Under the bill, Cyber Command would be tasked with creating a pilot program to test out the arrangement. Critics of the bill have called the provision the privatization of military hacking operations. Until now, only Cyber Command handled the military's cyber operations. [Bloomberg]
Five Eyes tells companies to drop PR spin: Cybersecurity agencies from the Five Eyes countries have told hacked companies to drop the marketing and PR spins and be more concise in their breach notifications. Companies are advised to be transparent and provide technical information and a clear timeline of what happened. The agencies warn that misleading notifications can increase the damage and customer disruptions from the initial incident. [CISA // ACSC // CCCS]
EU MEPs call to stop Serbia's EU application over spyware use: Twenty-nine members of the EU Parliament have signed an open letter calling for the bloc to suspend Serbia's EU membership application over its repeated spyware use. The letter calls for the EU to stop any pre-ascension investments and official visits until rule of law returns. Multiple reports have blamed the government of using NoviSpy and Pegasus spyware against student protesters, journalists, and political activists. [Hannah Neumann, MEP]
EU 🇪🇺 must act. No EU money for accession process without rule of law. We call on the @EU_Commission to: ➡️ FREEZE EU Growth Plan & IPA III payments ➡️ CANCEL upcoming official visits to Belgrade ➡️ CONDITION accession progress on accountability & reform of MUP and BIA
— Hannah Neumann (@hneumannmep.bsky.social) September 4, 2026 at 6:16 PM
Sponsor section
In this Risky Business sponsor interview, James Wilson chats with Authentik Security CEO Fletcher Heisler about how AI is driving a need for privileged access management to adapt.
Arrests, cybercrime, and threat intel
France arrests ZeroBytes: French authorities have arrested two suspects for hacking the country's tax agency last month. The first suspect was arrested on August 18, a day after the hack became public. A second suspect was arrested a week later, on August 26. The first suspect is believed to be ZeroBytes, the hacker who publicly took credit for the intrusion. Paris prosecutors say the suspect is 18 and was also indicted for two other hacking cases in 2024 and 2025. [FranceInfo]
ClickFix cluster: Netskope has discovered a cluster of more than 5,400 sites that were hacked and used to host ClickFix-style campaigns. [Netskope]

Malware technical reports
Drama RAT: Positive Technologies has discovered a new dual Android RAT + banking trojan targeting the Russian market. [Positive Technologies]
NodeStealer: The developers of the NodeStealer malware appear to have used an AI coding assistant to expand their infostealer into a full blown spyware. New features include the ability to log keystrokes, monitor the clipboard, take screenshots of the user's screen, and steal WiFi passwords. Security firm Netskope says the massive set of features were added in a recent update out of the blue and that the new code exhibits the characteristics of LLM-generated code. [Netskope]
Angry Birds backdoor: The Toy Ghouls e-crime group (or Labubu, Bearlyfly) is deploying a new backdoor named Angry Birds in its ransomware attacks targeting Russian orgs. The coolest features of this new tool is its use of the HiveMQ MQTT broker and the Matrix-based Element messenger as C2 channels. [Kaspersky]
Rustbot: Iru researchers look at the malware deployed on macOS hosts during a supply chain attack on the Rust repo Crates on August 20. On macOS, this was a new RAT the company named Rustbot. [Iru]
DarkSword spotted in the wild again: Security researchers have spotted the leaked iOS exploit framework DarkSword used in the wild again, this time in a campaign offering free VPS services but deploying the iOS hacking kit to steal crypto-wallet data. [SlowMist]
Sponsor section
Authentik is an open-source identity provider that is also offered with paid enterprise features. In this demo, CEO Fletcher Heisler and CTO Jens Langhammer walk Risky Business host Patrick Gray through an overview and a demo of the technology.
APTs, cyber-espionage, and info-ops
YouTube network attacks Democrats: A new report has exposed a network of paid YouTube accounts attacking Democrats ahead of the US Midterms. [Semafor // Yahoo News]
"Notably, while the videos are presented as laypeople giving straight-to-camera ideological news recaps, they feature actors and spokespeople paid small amounts of money to read nearly identical scripts laced with misleading claims and outright falsehoods."
Disinformation laundering: Reporters at BalkanInsight are looking at the rising trend of "disinformation laundering," where shady local news media organizations are acting as intermediaries to launder the Kremlin's talking points. Some of these news sites function right on top of the same servers of old Kremlin state-backed disinformation orgs, with a new domain on top. The report looks at Greece, but this can be applied to anywhere across Europe. [BalkanInsight]
Matryoshka targets Germany: Just as one of its states was holding a major regional election, Russian disinfo group Matryoshka was busy pushing disinformation attacking all the German political parties except the far-right AfD and the far-left BSW. I wonder why! [ISD]

Another Chinese AI campaign: A Chinese threat actor has used AI assistants like Claude Code and DeepSeek to breach systems across four countries. Victims include Indonesia's Ministry of Foreign Affairs, Taiwan's Kuomintang Party, industrial companies in Da Nang, Vietnam, and multiple government and education systems in China. Researchers found the campaign in internet-exposed directories from an AI orchestration host. [Hunt Intelligence]
APT-C-56: Qihoo researchers look at new APT-C-56 (Transparent Tribe) campaigns delivering the CrimsonRAT. [Qihoo360]
Kimsuky adopts AI: North Korean APT group has used the Opencode AI agent to create decoy PDF files while its malicious code connects to GitHub to retrieve and run malicious PowerShell code. [Genians]
NewDPRK APT malware: A North Korean APT has been hacking groupware apps to plant a new Linux malware toolkit they use to breach orgs in South Korea's media and automotive sectors. The two main tools that are part of this toolkit are the curlRAT and the Ted backdoor. [Rapid7]

Vulnerabilities, security research, and bug bounty
Security updates: 7-Zip, AMD, ASUS, AWS, Chrome, Elastic, Mikrotik, N-able, n8n, Rockwell Automation, SUSE.
Chrome zero-day: Google has released a security update to patch a Chrome zero-day exploited in the wild. Tracked as CVE-2026-85046, the zero-day is a type confusion in Chrome's V8 JavaScript engine. The vulnerability was discovered by Italian security researcher Salvatore Gulizia. It is the sixth Chrome zero-day patched this year. [Chrome]
Mikrotik zero-day: Hackers are exploiting two zero-day vulnerabilities to take over MikroTik routers without authentication and create backdoor admin accounts. Only devices with their SSH service accessible from public networks are vulnerable. Attacks have been spotted last week by the CERTs of Poland and Latvia. MikroTik released security patches for the bugs on Thursday. [CERT-PL // Mikrotik // Reddit // CERT-LV]
StyleSmuggler zero-day in Magento stores: Hackers are using a new zero-day to take over Adobe Commerce and Magento online stores. A successful attack allows attackers to start a backdoored background process on hacked stores. Security firm Sansec discovered the zero-day but says it saw no indication that the backdoor has been weaponized for other malicious actions. It tracks the zero-day as StyleSmuggler. [Sansec]
N-able patches major bug: Software maker N-able has released a security update to patch a major bug that can let attackers hijack N-central servers. The vulnerability is a pre-authentication remote code execution with a severity of 10. N-able says the bug has not been exploited in the wild but recommends that customers apply the patches as soon as possible. The company's N-central products are highly sought after by hackers and were also targeted with a zero-day last month. [N-able // N-able // Huntress]
New Citrix bug exploited in the wild: Threat actors have begun exploiting a new vulnerability in Citrix ADC and NetScaler gateway devices. The vulnerability (CVE-2026-19490) was patched in August and allows attackers to bypass authentication and run commands on the device. Security firm Previdian detected in the wild exploitation last week. [Previdian // Citrix patch]
Super Forms bug gets exploited: Hackers have started exploiting an Unauthenticated Arbitrary File Upload vulnerability in the Super Forms WordPress plugin. This was patched back in July. [Wordfence]
ConnectWise warns of ScreenConnect remote access bug: Software maker ConnectWise has discovered a bug in its ScreenConnect remote management app that can let hackers gain remote access to managed systems. The company promised a CVE and patch would be released this week. [ConnectWise]
OpenAI GPT-6 Astra attempted a supply chain attack: According to pre-release testing, OpenAI's new GPT-6 Astra model attempted to conduct supply chain attacks against open-source projects. Luckily, this happened in a simulated environment. [OpenAI]
Infosec industry
Threat/trend reports: Booz Allen, Report Fraud, and Rostelecom have recently published reports and summaries covering various emerging threats and industry trends.
New tool—Ephemora Cell: Software engineer Michael S. has released Ephemora Cell, an execution layer for untrusted AI-generated code.
New tool—Mythic Ornn: Security researcher Adrian D. Medero has published Mythic Ornn, a LLM tool for writing Mythic agents, C2 protocols, and payload types.
New tool—0xM0nCrush: Security researcher Syed Wajeeh-ul-Hassan Rizvi has released 0xM0nCrush, a cross-version Windows process terminator.
TROOPERS 2026 videos: Talks from the TROOPERS 2026 security conference, which took place in June, are available on YouTube.
Risky Business podcasts
In this episode of Risky Business Features, Brad Arkin joins James Wilson to chat about the Trump administration’s call to let private entities conduct cyber operations against criminal groups.