{"id":25280,"date":"2025-07-12T08:42:11","date_gmt":"2025-07-12T05:42:11","guid":{"rendered":"https:\/\/forklog.com\/en\/brazilian-banks-lose-140m-telegram-outages-in-russia-and-other-cybersecurity-news\/"},"modified":"2025-07-12T08:42:11","modified_gmt":"2025-07-12T05:42:11","slug":"brazilian-banks-lose-140m-telegram-outages-in-russia-and-other-cybersecurity-news","status":"publish","type":"post","link":"https:\/\/forklog.com\/en\/brazilian-banks-lose-140m-telegram-outages-in-russia-and-other-cybersecurity-news\/","title":{"rendered":"Brazilian banks lose $140m, Telegram outages in Russia and other cybersecurity news"},"content":{"rendered":"<p>A round-up of the week\u2019s most important cybersecurity news.<\/p>\n<div class=\"wp-block-text-wrappers-keypoints article_keypoints\">\n<ul class=\"wp-block-list\">\n<li>Brazilian banks lost $140m after an employee handed over credentials.<\/li>\n<li>Russia\u2019s Faster Payments System and Telegram went down.<\/li>\n<li>A basketball player was suspected of ransomware extortion.<\/li>\n<li>A flaw in McDonald\u2019s AI hiring bot exposed a recruitment database.<\/li>\n<\/ul>\n<\/div>\n<h2 class=\"wp-block-heading\">Brazilian banks lose $140m after an insider hands over access<\/h2>\n<p>On July 7 <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/employee-gets-920-for-credentials-used-in-140-million-bank-heist\/\">it emerged<\/a> that one of the year\u2019s biggest cyberattacks on the banking sector had struck. Criminals stole about $140m from six Brazilian financial institutions using credentials belonging to an employee of <span data-descr=\"provides solutions for financial integration\" class=\"old_tooltip\">C&amp;M Software<\/span>.<\/p>\n<p>The incident occurred on June 30, when the attackers bribed Joao Nazareno Roque and obtained access to the system. According to police, he also provided instructions on specific actions that ensured the attack\u2019s success.<\/p>\n<p>He priced his part at $920. Later, following the attackers\u2019 guidance, he executed commands inside C&amp;M\u2019s infrastructure. For this, he earned an additional $1,850, the outlet reports.<\/p>\n<p>Roque tried to cover his tracks by changing mobile phones every 15 days. However, on July 3 he was detained in S\u00e3o Paulo.<\/p>\n<p>Rough estimates suggest at least $30\u201340m of the haul was converted into cryptoassets. According to an <a href=\"https:\/\/t.me\/Investigatons\/1919\">on-chain investigation<\/a> by ZachXBT, the attackers moved funds into BTC, ETH and USDT via Latin American over-the-counter desks and crypto exchanges.<\/p>\n<h2 class=\"wp-block-heading\">Russia\u2019s Faster Payments System and Telegram suffer outages<\/h2>\n<p>On July 10, the Faster Payments System (SBP) in Russia <a href=\"https:\/\/kod.ru\/sbp-sboi-rkn-nspk-jul-2025\">suffered an outage<\/a>. Complaints began at 16:00 (MSK) from St Petersburg, Moscow, the Yamalo-Nenets Autonomous Okrug, Tver and Nizhny Novgorod regions, and elsewhere.<\/p>\n<p>The Centre for Monitoring and Managing the Public Communications Network emphasised there were no DDoS attacks on the infrastructure of <span data-descr=\"National Payment Card System\" class=\"old_tooltip\">\u041d\u0421\u041f\u041a<\/span>.<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh7-qw.googleusercontent.com\/docsz\/AD_4nXcpt87IpD24givV1IjnFqV-5mjXcWAcbvX0itO1NyZ1p-Ruq7NlBoOoxovId4nNvaaPZ4C8eUCilmUlF9bYbO5rjM5sg-_5THP1E8MU25FDb3JzhthYUSKpmi-kEgWp45T4A02PXA?key=mzzaRZeoRBnHzj3gvzONqQ\" alt=\"\u041a\u0440\u0430\u0436\u0430 $140 \u043c\u043b\u043d \u0443 \u0431\u0430\u043d\u043a\u043e\u0432 \u0411\u0440\u0430\u0437\u0438\u043b\u0438\u0438, \u0441\u0431\u043e\u0438 Telegram \u0432 \u0420\u043e\u0441\u0441\u0438\u0438 \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 \u0441\u043e\u0431\u044b\u0442\u0438\u044f \u043a\u0438\u0431\u0435\u0440\u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438\"\/><figcaption class=\"wp-element-caption\">SBP outage chart as of July 11. Source: <a href=\"https:\/\/downdetector.su\/sbp\">Downdetector<\/a>.<\/figcaption><\/figure>\n<p>On social media, users complained about bank services and being unable to transfer funds or pay via SBP.<\/p>\n<p>NSPK, the system\u2019s developer and operator, linked the incident to a provider. Service was restored near midnight.<\/p>\n<p>On June 7 a large-scale <a href=\"https:\/\/t.me\/fontankaspb\/85513\">Telegram outage occurred<\/a>. Russian users <a href=\"https:\/\/frankmedia.ru\/209393\">complained<\/a> about unavailable notifications, problems sending messages and loading the app.<\/p>\n<h2 class=\"wp-block-heading\">Basketball player suspected of cyber extortion&nbsp;<\/h2>\n<p>On July 9 <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/russian-pro-basketball-player-arrested-for-alleged-role-in-ransomware-attacks\/\">it became known<\/a> that Russian professional basketball player Daniil Kasatkin had been detained. According to media reports, he was arrested on June 21 at Charles de Gaulle airport in France at the request of US authorities. He is accused of serving as a negotiator for a hacker network that used ransomware.<\/p>\n<p>Kasatkin is currently in custody, and US representatives are seeking his extradition to face charges. His lawyer has asserted his innocence.<\/p>\n<p>The gang\u2019s name has not been disclosed. It is known only that between 2020 and 2022 the attackers carried out more than 900 attacks on various organisations, including two federal agencies.<\/p>\n<h2 class=\"wp-block-heading\">A flaw in McDonald\u2019s AI bot exposed its hiring database<\/h2>\n<p>According to <a href=\"https:\/\/www.wired.com\/story\/mcdonalds-ai-hiring-chat-bot-paradoxai\/\">Wired<\/a>, on June 9 researchers Ian Carroll and Sam Curry discovered critical vulnerabilities in the McHire system. The platform recruits employees for McDonald\u2019s using an AI bot named Olivia.<\/p>\n<p>Using rudimentary passwords such as \u201c123456\u201d, the researchers gained access to the admin panel of the platform\u2019s developer, Paradox.ai. It contained a database with 64m records, including applicants\u2019 names, emails and phone numbers. Access had been open since 2019 without two-factor authentication.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">When applying for a job at McDonald&#39;s, over 90% of franchises use &quot;Olivia,&quot; an AI-powered chatbot. We (<a href=\"https:\/\/twitter.com\/iangcarroll?ref_src=twsrc%5Etfw\">@iangcarroll<\/a> and I) discovered a vulnerability that could allow an attacker to access the over 64 million chat records using the password &quot;123456&quot;.<a href=\"https:\/\/t.co\/dBqpRpdp9T\">https:\/\/t.co\/dBqpRpdp9T<\/a><\/p>\n<p>\u2014 Sam Curry (@samwcyo) <a href=\"https:\/\/twitter.com\/samwcyo\/status\/1943032841631338742?ref_src=twsrc%5Etfw\">July 9, 2025<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Paradox.ai acknowledged the leak and said the account was not used by third parties other than the researchers. The company promised to introduce a bug-bounty programme to prevent similar incidents in future. McDonald\u2019s, for its part, said the flaw was fixed on the day it was discovered.<\/p>\n<p>Carroll noted that he learned about this \u201chorrifying level of security\u201d only because he was intrigued by screening potential workers via an AI bot and a personality test.<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>\u201cIt seemed especially dystopian to me compared to the usual hiring process, right? That is exactly what prompted me to dig deeper. I started applying for a job, and within 30 minutes we had full access to almost all the applications ever submitted to McDonald\u2019s in recent years,\u201d<\/em> he stressed in a comment to Wired.<\/p>\n<\/blockquote>\n<h2 class=\"wp-block-heading\">Bitcoin Depot ATM operator failed to safeguard data of 27,000 customers<\/h2>\n<p>The operator of a network of bitcoin ATMs with more than 17,000 machines in the US, Canada and Australia, Bitcoin Depot notified customers of a personal-data breach.<\/p>\n<p>Suspicious activity on the network was first detected on June 23, 2023, and the company\u2019s internal investigation concluded in July 2024. US law-enforcement agencies asked that public disclosure be delayed until their own investigation was complete.<\/p>\n<p>According to a letter to victims, documents relating to about 27,000 customers who completed <span data-descr=\"know your customer\" class=\"old_tooltip\">KYC<\/span> procedures fell into the attackers\u2019 hands.<\/p>\n<p>The type of leaked data varies by person but may include:<\/p>\n<ul class=\"wp-block-list\">\n<li>full name;<\/li>\n<li>phone number;<\/li>\n<li>driver\u2019s licence number;<\/li>\n<li>residential address;<\/li>\n<li>date of birth;<\/li>\n<li>email.<\/li>\n<\/ul>\n<p>No financial compensation or identity-theft protection is offered, as the risks relate to cryptoassets. Instead, victims were advised to remain vigilant and monitor bank statements.<\/p>\n<p>Also on ForkLog:<\/p>\n<ul class=\"wp-block-list\">\n<li>A hacker <a href=\"https:\/\/forklog.com\/en\/news\/hacker-returns-40-million-stolen-from-gmx\">returned<\/a> $40m stolen from GMX.<\/li>\n<li>Researchers <a href=\"https:\/\/forklog.com\/en\/news\/researchers-avert-10-million-theft-from-defi-protocols\">prevented<\/a> the theft of $10m from DeFi protocols.<\/li>\n<li>A hacker <a href=\"https:\/\/forklog.com\/en\/news\/hacker-breaches-gmx-dex-for-42-million\">hacked<\/a> the GMX DEX for $42m.<\/li>\n<li>Data <a href=\"https:\/\/forklog.com\/en\/news\/data-as-an-asset-a-new-factor-of-production-with-chinese-characteristics\">as an asset<\/a>: a new factor of production with Chinese characteristics.<\/li>\n<li>Jack Dorsey <a href=\"https:\/\/forklog.com\/en\/news\/jack-dorsey-unveils-encrypted-bluetooth-chat\">unveiled<\/a> an encrypted Bluetooth chat.<\/li>\n<li>An expert <a href=\"https:\/\/forklog.com\/en\/news\/expert-suggests-possible-breach-of-bitcoin-wallets-holding-8-6-billion\">suggested<\/a> the hacking of bitcoin wallets holding $8.6bn.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\">What to read this weekend?<\/h2>\n<p>We examine how a corruption scandal linked to bitcoin sales could reshape the Czech Republic\u2019s political landscape.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A round-up of the week\u2019s most important cybersecurity news. Brazilian banks lost $140m after an employee handed over credentials. Russia\u2019s Faster Payments System and Telegram went down. A basketball player was suspected of ransomware extortion. A flaw in McDonald\u2019s AI hiring bot exposed a recruitment database. Brazilian banks lose $140m after an insider hands over [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":25279,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"","news_style_id":"","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1238,1233],"class_list":["post-25280","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-cybersecurity-digest","tag-industry-digests"],"aioseo_notices":[],"amp_enabled":true,"views":"68","promo_type":"","layout_type":"","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/25280","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/comments?post=25280"}],"version-history":[{"count":0,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/25280\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media\/25279"}],"wp:attachment":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media?parent=25280"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/categories?post=25280"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/tags?post=25280"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}