The reports
Global Scam Report
What the major annual reports say about the state of online fraud, channel by channel.
Europol · ENISA · FBI 🤖Generative AI & voice deepfakes
How artificial intelligence changed the scale and realism of voice scams.
FBI · Pindrop 📡SIM farms & criminal call centers
The industry behind millions of fake numbers and fake accounts — dismantled in 2025.
Europol 🕵️Documented criminal networks: the Lazarus case
A group stealing billions in crypto assets by infiltrating real companies.
FBI · CISA · Microsoft 🗃️ZeroBytes: France's tax breach decoded
France's tax authority, Intermarché, EVA, handball — what's confirmed, what's only a hacker's claim.
DGFiP · FrenchBreaches 📡SFR: the breach confirmed, the number isn't
France's #2 carrier admits an intrusion; 2.1 million lines are a hacker's claim, never SFR's.
AFP · CNIL 🔧Free, Bouygues, SFR: the same fiber tool breached 3 times
The pattern linking three major French carriers in under two years — not just one incident.
CNIL · AFP 📵Bloctel: breached right before it shut down
600,000 registered numbers exposed, days before France's do-not-call registry closed for good.
DGCCRF 🏥CareCloud: disclosed 5 months after the breach
3.7 million patients, Social Security numbers included. Confirmed by the company — attacker unknown.
HHS · TechCrunch 📦CEVA Logistics: one breach, a dozen brands hit
Valve, Ajax, Bol.com — all clients of one subcontractor, none of them breached directly.
TechCrunch · The Record 🔓youX (Australia): flagged, left open for 10 months
An Australian database reported insecure in 2025, believed fixed — exploited anyway.
Security researchers ⚔️Gulf: the wave, barely any confirmations
15-25x normal attack volume — banks and telecoms named, zero official confirmation.
Regional threat intelligence 🏦MGP: 133,000 bank details stolen via a vendor
Confirmed by the insurer itself, complaint filed — not just a forum hacker's claim.
MGP · FrenchBreaches 🏛️Compte Asso: the ministry confirms
Association treasurers' IBANs and BIC codes exposed. Confirmed by France's Sports Ministry.
Sports Ministry ⚖️CFDT: 1.4 million union members exposed
Confirmed by the union itself. Union membership, sensitive data under GDPR.
CFDT statement 💬LFI / Action Populaire: acknowledged, unquantified
120,000 La France Insoumise activist emails claimed. LFI acknowledged the attack without confirming its scale.
Partially acknowledged claim 🔍HelloAsso: the claim that doesn't add up
160,000 IBANs claimed — the internal investigation finds neither a flaw nor a match.
Likely mistaken claim 🏋️Basic-Fit: 1 million accounts, 6 countries
Bank details exposed across six countries at once. Confirmed by the chain.
Basic-Fit statement ☁️V-Bank Munich: a cloud vendor was the target
Confirmed by the bank: no accounts or transfers affected, the attack hit an external vendor.
V-Bank statement ⚠️Lloyds Bank: a bug, not a hack
500,000+ customers saw other people's data — a software defect, no hacker involved.
Not a malicious leak 🏥Hospices Civils de Lyon: leak at a vendor
Confirmed by HCL: incident at a vendor, no patient data affected.
HCL statement 🧱Santé publique France: the isolated platform
80,000 contacts exposed, no health data affected.
Santé publique France 🔬Biosynex: confirmed cyberattack, scope under review
Intrusion acknowledged by the group, investigation ongoing.
Biosynex statement 🏗️Capgemini Engineering: Altran source code claimed
722,470 files claimed, unconfirmed, a different risk profile.
Unconfirmed claim 🧾WiziShop/Dropizi: invoices since 2009
Confirmed by the company, fixed the same day it was discovered.
WiziShop client notice 📊Experts Entreprendre: 1.13TB of accounting data claimed
IBANs, payroll, tax data from hundreds of client companies — unconfirmed.
Unconfirmed claim 🎯ExfilSquad: UK campaign
Police (scope widened), Education (confirmed), Wesco (confirmed, downplayed).
3 documented targets 👻Majinahanashi: Italian clinic, no evidence
135,426 files claimed, no sample, no statement.
Unconfirmed claim 🔍NoName057: Spanish security-force profiles
994 profiles claimed, under investigation by police and the CNI.
Under investigation, unconfirmed 🆔Solimut Mutuelle: national ID and IBANs claimed
1.24 million insured-member records claimed, unconfirmed.
Unconfirmed claim 🔢Declic Services: 6.2M rows, 15,000 accounts
WordPress → exposed ERP → prod database. Raw rows ≠ people.
Unconfirmed claim 🎯iMapper.tech: 2,463 accounts via a named CVE
Small volume, precise B2B target, unconfirmed.
Unconfirmed claim 🏛️France's state cloud: severe headline, public data
Claimed, but the source report itself says "largely public data."
Claim to take with caution 📊Beauty Success: 5.17 million claimed
Huge figure, claimed by a hacker, not confirmed by the retailer.
Unconfirmed claim 🔁Bureau Vallée: 4.8 million, a 2nd incident
Second claim in 12 days, not to be confused with the first.
Unconfirmed claim 👶Allobébé/Made in Bébé: 2.1 million parents
Two baby-products retailers, unconfirmed claims the same day.
Unconfirmed claims 👶Civil Protection: volunteers, including minors
Confirmed by the FNPC: 525,000 potential profiles, minor cadets included.
FNPC 🔬IRD: confirmed intrusion, SSNs exposed
7,500 people, actual exfiltration not confirmed by the institute.
IRD statement ✉️John Paul: hacked email, 4,179 BPCE clients
Banking concierge service compromised by phishing, confirmed.
John Paul statement 🧮BlgCloud: 13 confirmed versus 159 claimed
Software vendor for Bergerat Rent and other SMEs, scale disputed.
BlgCloud 📢Géotec: confirmed, almost no detail
Exfiltration acknowledged, but no volume or data type disclosed.
Groupe Géotec 💧SUEZ Eau France: bank details and ID docs exposed
Confirmed with a caveat: incident at a vendor, individual completeness not guaranteed.
SUEZ client notice 🧭TERVEO: rebuilt and relaunched within a week
Confirmed, rare transparency on data exposed by customer profile.
TERVEO incident page ❓INSERM: health-professional profiles claimed
189,997 profiles claimed, unconfirmed, origin uncertain.
Unconfirmed claim 🚇The Transport for London hack
A helpdesk call, a reset password, £29 million in costs — the rare case that ended in conviction.
National Crime Agency 🏛️IntelBroker: Congress's exposed health data
Dozens of claimed breaches, one confirmed victim — the gap between what he said and what happened.
DC Health Link 📱Fake QR codes & quishing
A package, a parking meter, a poster — the QR code has become a fraud vector in its own right.
FBI · FTC 🇬🇧The UK's own "Chat Control"
Not the EU's Chat Control — the Online Safety Act, Ofcom's Technology Notice powers, and the Apple encryption standoff.
Status as of 26/07/2026 🔞UK under-16 social media ban
Announced June 2026, going further than Australia: platforms, penalties, and what's still just a consultation.
UK Government · Ofcom 🎲The Mathematics of Manipulation
Why scams work: the probability demonstration, official figures, one scenario at a time.
USPS · FTC · UK Finance · Australia Post 🧭Exposure Profiles
Not a risk profile — a situation. What your everyday life makes statistically probable, one profile at a time.
Senior · Teen · Professional · Job seeker 💼Recruitment fraud
Losses have multiplied fivefold in four years — the fake job offer that costs real money.
FTC · BBB 📈Why fraud is exploding right now
The synthesis: five documented factors combining at once, not just one.
Series synthesis 🔭Threats 2030
What cybersecurity agencies project for the coming years — sourced, no speculation.
ENISA 🧭Hybrid threats
How a hybrid threat works — the mechanism, not the geopolitics.
Hybrid CoE · ENISA 🕳️Dark web
What really sells on dark web markets, and how your credentials pass through them.
Europol 🕸️Emerging phishing techniques
Two techniques that now bypass two-factor authentication and automated filters.
Microsoft · Trustwave 💬The evolution of smishing
$470 million lost by text in 2024 in the US — five times more than in 2020.
FTC · FBI 📵Caller ID spoofing
How a number can show a fake identity, and why technical verification is still incomplete.
FCC 💔Romance scams
$1.16 billion in losses in nine months — what the numbers say, without judgment.
FTC · FBI 🇺🇸US Fraud Report
$20.9 billion lost, over 1 million complaints — what the FBI's IC3 and the FTC report for 2025.
FBI / IC3 · FTC 🗂️US Data Breaches
3,322 breaches tracked in 2025, a $177M AT&T settlement — how leaked data fuels personalized scams.
ITRC · HHS OCR 🔗From Leak to Scam
$3.5 billion lost to imposter scams in 2025 — the exact mechanism connecting a data breach to the call that empties an account.
FTC · FBI / IC3 🪙Crypto investment scams
$9.3 billion lost in 2024 — how rug pulls, pig-butchering platforms and fake exchanges actually work.
FBI / IC3 · SEC · CFTC · DOJ ✉️Phone harassment
What matters legally, and one concrete way to take back control when the harassment comes from someone you know.
Legal evidence guidance 🗃️Aix-Marseille: 84,000 students targeted, fake €450 tuition fee
Confirmed phishing campaign: fake emails impersonating Aix-Marseille University demand €450 in tuition fees. Fifteen days, university denies a hack.
franceinfo · French press 🗃️Axess: 18,875 accounts claimed, plaintext passwords
A hacker claims 67 databases at Axess: emails, plaintext passwords, IBANs, SIRET numbers. Not confirmed by the company. The factual point, sourced.
X-VDP-X's claim · Cyberattaque.org 🗃️US water and energy: the federal advisory on Iran-linked hackers
FBI, NSA, CISA and the Department of Energy warn of intrusions into industrial controllers at water and energy utilities. Twelve states affected, sourced.
TechCrunch · Washington Post · Forescout 🗃️Klark.ai: up to 500,000 people potentially exposed
A hacker claims 140 GB from 4 databases at Klark.ai, a French AI customer service platform: conversations, IBANs, API keys. Unconfirmed. Sourced.
Cyberattaque.org · 0xSec's claim 🗃️NETIM: a French registrar targeted by a new extortion group
The DYSPHOR1A group claims an intrusion at NETIM: server configs, client data, PayPal and Stripe. Not confirmed, no encryption observed.
DYSPHOR1A's claim · ZATAZ 🗃️Operation Jackal IV: 58 arrests, and the figure nobody sources
Interpol reports 58 arrests against Black Axe across 22 countries. What the press release really says, and the two figures the media add without a source.
Interpol 🗃️OTEIS: a group's claim, no data published
CoinbaseCartel claims an intrusion at OTEIS. No volume, no data published to date. What a listing on an extortion site really lets you conclude.
Ransomware.live · FrenchBreaches · Halcyon 🗃️ReliaQuest: the confirmed attack that didn't go further
Vishing, a cloned SSO page, MFA approved — then blocked. ReliaQuest confirms the attack and explains why ShinyHunters got nothing more. Sourced timeline.
ReliaQuest statement 🗃️Fake banking sites: fooling Google and your instincts
Fortra documents a technique that ranks fake banking sites above real ones and hides from security scanners. Up 40% in Q2 2026. The mechanism, sourced.
Fortra · Help Net Security 🗃️SMS & call bombing: when a number overwhelms you
Hundreds of texts or calls in minutes, with no apparent reason. Bombing isn't a bug: it's an automated harassment or diversion tool, and how to stop it.
🗃️Strasbourg food aid: 10,073 beneficiary records claimed
A hacker claims a database of food aid beneficiaries in Strasbourg, France, including children. Not confirmed. The factual point, with the caution this deserves.
Cyberattaque.org 🗃️Wangiri: the "one ring" phone scam
A missed call from an unknown number, a single ring. Calling back can cost you dearly: how the wangiri (one-ring) scam works, and what the FCC says.
🗃️YouFid: nearly 1.9 million loyalty profiles claimed
A hacker claims 1,899,454 YouFid loyalty program profiles: names, addresses, QR codes. Not confirmed by the company. The factual point, sourced.
Cybercriminal forum post · FrenchBreaches 🗃️Zimbra: critical flaw exploited, 270+ servers already breached
CISA and Poland's CERT confirm active exploitation of a critical Zimbra flaw. Over 12,000 servers exposed. What it means for your email.
Zimbra · BleepingComputer · CISA 🗃️153M driving licence scans for sale: what is actually proven
A dark web service claims 153 million US and Canadian driving licence scans. The FBI is investigating. The company named has not confirmed a breach. What is established, and what is not.
Krebs on Security 🗃️McKesson breach: 284 million patient records claimed
McKesson confirms a breach. ShinyHunters claims 284 million patient records, including Social Security and Medicaid numbers. What is confirmed, what is only claimed.
Help Net Security · TechCrunch · Privacy Guides 🗃️Egypt: a wave of leak claims, not one official confirmation
Six Egyptian universities, an insurer and the football federation are named in forum claims. No organisation has confirmed anything.
Claims reported by ZATAZ · Claim reported by ZATAZ · Egidio 🗃️Aesto Health: 9.5 million patients hit through a vendor they never picked
Aesto Health confirms 9.54 million patients affected by a December 2025 AWS breach, disclosed to HHS in 2026. 29 healthcare providers relied on the vendor.
BleepingComputer · HIPAA Journal · SecurityWeekMore reports follow regularly, along with country-specific reports and coverage in additional languages. This page grows with each new publication.
Our method
Every figure cited in The Threat Laboratory comes from a real, identified report, organization or authority — never a vague "gut feel" estimate. The full list of dated sources is public.
Go further
Our sourcing methodology → read it here.