Egidio
98 sourced dossiers — ongoing analysis

The Threat Laboratory

How scams evolve, who documents them, and why they're exploding right now. An analysis sourced from the organizations that track these phenomena every day — no sensationalism, just what's documented.

Download Egidio

The reports

🌍

Global Scam Report

What the major annual reports say about the state of online fraud, channel by channel.

Europol · ENISA · FBI
🤖

Generative AI & voice deepfakes

How artificial intelligence changed the scale and realism of voice scams.

FBI · Pindrop
📡

SIM farms & criminal call centers

The industry behind millions of fake numbers and fake accounts — dismantled in 2025.

Europol
🕵️

Documented criminal networks: the Lazarus case

A group stealing billions in crypto assets by infiltrating real companies.

FBI · CISA · Microsoft
🗃️

ZeroBytes: France's tax breach decoded

France's tax authority, Intermarché, EVA, handball — what's confirmed, what's only a hacker's claim.

DGFiP · FrenchBreaches
📡

SFR: the breach confirmed, the number isn't

France's #2 carrier admits an intrusion; 2.1 million lines are a hacker's claim, never SFR's.

AFP · CNIL
🔧

Free, Bouygues, SFR: the same fiber tool breached 3 times

The pattern linking three major French carriers in under two years — not just one incident.

CNIL · AFP
📵

Bloctel: breached right before it shut down

600,000 registered numbers exposed, days before France's do-not-call registry closed for good.

DGCCRF
🏥

CareCloud: disclosed 5 months after the breach

3.7 million patients, Social Security numbers included. Confirmed by the company — attacker unknown.

HHS · TechCrunch
📦

CEVA Logistics: one breach, a dozen brands hit

Valve, Ajax, Bol.com — all clients of one subcontractor, none of them breached directly.

TechCrunch · The Record
🔓

youX (Australia): flagged, left open for 10 months

An Australian database reported insecure in 2025, believed fixed — exploited anyway.

Security researchers
⚔️

Gulf: the wave, barely any confirmations

15-25x normal attack volume — banks and telecoms named, zero official confirmation.

Regional threat intelligence
🏦

MGP: 133,000 bank details stolen via a vendor

Confirmed by the insurer itself, complaint filed — not just a forum hacker's claim.

MGP · FrenchBreaches
🏛️

Compte Asso: the ministry confirms

Association treasurers' IBANs and BIC codes exposed. Confirmed by France's Sports Ministry.

Sports Ministry
⚖️

CFDT: 1.4 million union members exposed

Confirmed by the union itself. Union membership, sensitive data under GDPR.

CFDT statement
💬

LFI / Action Populaire: acknowledged, unquantified

120,000 La France Insoumise activist emails claimed. LFI acknowledged the attack without confirming its scale.

Partially acknowledged claim
🔍

HelloAsso: the claim that doesn't add up

160,000 IBANs claimed — the internal investigation finds neither a flaw nor a match.

Likely mistaken claim
🏋️

Basic-Fit: 1 million accounts, 6 countries

Bank details exposed across six countries at once. Confirmed by the chain.

Basic-Fit statement
☁️

V-Bank Munich: a cloud vendor was the target

Confirmed by the bank: no accounts or transfers affected, the attack hit an external vendor.

V-Bank statement
⚠️

Lloyds Bank: a bug, not a hack

500,000+ customers saw other people's data — a software defect, no hacker involved.

Not a malicious leak
🏥

Hospices Civils de Lyon: leak at a vendor

Confirmed by HCL: incident at a vendor, no patient data affected.

HCL statement
🧱

Santé publique France: the isolated platform

80,000 contacts exposed, no health data affected.

Santé publique France
🔬

Biosynex: confirmed cyberattack, scope under review

Intrusion acknowledged by the group, investigation ongoing.

Biosynex statement
🏗️

Capgemini Engineering: Altran source code claimed

722,470 files claimed, unconfirmed, a different risk profile.

Unconfirmed claim
🧾

WiziShop/Dropizi: invoices since 2009

Confirmed by the company, fixed the same day it was discovered.

WiziShop client notice
📊

Experts Entreprendre: 1.13TB of accounting data claimed

IBANs, payroll, tax data from hundreds of client companies — unconfirmed.

Unconfirmed claim
🎯

ExfilSquad: UK campaign

Police (scope widened), Education (confirmed), Wesco (confirmed, downplayed).

3 documented targets
👻

Majinahanashi: Italian clinic, no evidence

135,426 files claimed, no sample, no statement.

Unconfirmed claim
🔍

NoName057: Spanish security-force profiles

994 profiles claimed, under investigation by police and the CNI.

Under investigation, unconfirmed
🆔

Solimut Mutuelle: national ID and IBANs claimed

1.24 million insured-member records claimed, unconfirmed.

Unconfirmed claim
🔢

Declic Services: 6.2M rows, 15,000 accounts

WordPress → exposed ERP → prod database. Raw rows ≠ people.

Unconfirmed claim
🎯

iMapper.tech: 2,463 accounts via a named CVE

Small volume, precise B2B target, unconfirmed.

Unconfirmed claim
🏛️

France's state cloud: severe headline, public data

Claimed, but the source report itself says "largely public data."

Claim to take with caution
📊

Beauty Success: 5.17 million claimed

Huge figure, claimed by a hacker, not confirmed by the retailer.

Unconfirmed claim
🔁

Bureau Vallée: 4.8 million, a 2nd incident

Second claim in 12 days, not to be confused with the first.

Unconfirmed claim
👶

Allobébé/Made in Bébé: 2.1 million parents

Two baby-products retailers, unconfirmed claims the same day.

Unconfirmed claims
👶

Civil Protection: volunteers, including minors

Confirmed by the FNPC: 525,000 potential profiles, minor cadets included.

FNPC
🔬

IRD: confirmed intrusion, SSNs exposed

7,500 people, actual exfiltration not confirmed by the institute.

IRD statement
✉️

John Paul: hacked email, 4,179 BPCE clients

Banking concierge service compromised by phishing, confirmed.

John Paul statement
🧮

BlgCloud: 13 confirmed versus 159 claimed

Software vendor for Bergerat Rent and other SMEs, scale disputed.

BlgCloud
📢

Géotec: confirmed, almost no detail

Exfiltration acknowledged, but no volume or data type disclosed.

Groupe Géotec
💧

SUEZ Eau France: bank details and ID docs exposed

Confirmed with a caveat: incident at a vendor, individual completeness not guaranteed.

SUEZ client notice
🧭

TERVEO: rebuilt and relaunched within a week

Confirmed, rare transparency on data exposed by customer profile.

TERVEO incident page

INSERM: health-professional profiles claimed

189,997 profiles claimed, unconfirmed, origin uncertain.

Unconfirmed claim
🚇

The Transport for London hack

A helpdesk call, a reset password, £29 million in costs — the rare case that ended in conviction.

National Crime Agency
🏛️

IntelBroker: Congress's exposed health data

Dozens of claimed breaches, one confirmed victim — the gap between what he said and what happened.

DC Health Link
📱

Fake QR codes & quishing

A package, a parking meter, a poster — the QR code has become a fraud vector in its own right.

FBI · FTC
🇬🇧

The UK's own "Chat Control"

Not the EU's Chat Control — the Online Safety Act, Ofcom's Technology Notice powers, and the Apple encryption standoff.

Status as of 26/07/2026
🔞

UK under-16 social media ban

Announced June 2026, going further than Australia: platforms, penalties, and what's still just a consultation.

UK Government · Ofcom
🎲

The Mathematics of Manipulation

Why scams work: the probability demonstration, official figures, one scenario at a time.

USPS · FTC · UK Finance · Australia Post
🧭

Exposure Profiles

Not a risk profile — a situation. What your everyday life makes statistically probable, one profile at a time.

Senior · Teen · Professional · Job seeker
💼

Recruitment fraud

Losses have multiplied fivefold in four years — the fake job offer that costs real money.

FTC · BBB
📈

Why fraud is exploding right now

The synthesis: five documented factors combining at once, not just one.

Series synthesis
🔭

Threats 2030

What cybersecurity agencies project for the coming years — sourced, no speculation.

ENISA
🧭

Hybrid threats

How a hybrid threat works — the mechanism, not the geopolitics.

Hybrid CoE · ENISA
🕳️

Dark web

What really sells on dark web markets, and how your credentials pass through them.

Europol
🕸️

Emerging phishing techniques

Two techniques that now bypass two-factor authentication and automated filters.

Microsoft · Trustwave
💬

The evolution of smishing

$470 million lost by text in 2024 in the US — five times more than in 2020.

FTC · FBI
📵

Caller ID spoofing

How a number can show a fake identity, and why technical verification is still incomplete.

FCC
💔

Romance scams

$1.16 billion in losses in nine months — what the numbers say, without judgment.

FTC · FBI
🇺🇸

US Fraud Report

$20.9 billion lost, over 1 million complaints — what the FBI's IC3 and the FTC report for 2025.

FBI / IC3 · FTC
🗂️

US Data Breaches

3,322 breaches tracked in 2025, a $177M AT&T settlement — how leaked data fuels personalized scams.

ITRC · HHS OCR
🔗

From Leak to Scam

$3.5 billion lost to imposter scams in 2025 — the exact mechanism connecting a data breach to the call that empties an account.

FTC · FBI / IC3
🪙

Crypto investment scams

$9.3 billion lost in 2024 — how rug pulls, pig-butchering platforms and fake exchanges actually work.

FBI / IC3 · SEC · CFTC · DOJ
✉️

Phone harassment

What matters legally, and one concrete way to take back control when the harassment comes from someone you know.

Legal evidence guidance
🗃️

Aix-Marseille: 84,000 students targeted, fake €450 tuition fee

Confirmed phishing campaign: fake emails impersonating Aix-Marseille University demand €450 in tuition fees. Fifteen days, university denies a hack.

franceinfo · French press
🗃️

Axess: 18,875 accounts claimed, plaintext passwords

A hacker claims 67 databases at Axess: emails, plaintext passwords, IBANs, SIRET numbers. Not confirmed by the company. The factual point, sourced.

X-VDP-X's claim · Cyberattaque.org
🗃️

US water and energy: the federal advisory on Iran-linked hackers

FBI, NSA, CISA and the Department of Energy warn of intrusions into industrial controllers at water and energy utilities. Twelve states affected, sourced.

TechCrunch · Washington Post · Forescout
🗃️

Klark.ai: up to 500,000 people potentially exposed

A hacker claims 140 GB from 4 databases at Klark.ai, a French AI customer service platform: conversations, IBANs, API keys. Unconfirmed. Sourced.

Cyberattaque.org · 0xSec's claim
🗃️

NETIM: a French registrar targeted by a new extortion group

The DYSPHOR1A group claims an intrusion at NETIM: server configs, client data, PayPal and Stripe. Not confirmed, no encryption observed.

DYSPHOR1A's claim · ZATAZ
🗃️

Operation Jackal IV: 58 arrests, and the figure nobody sources

Interpol reports 58 arrests against Black Axe across 22 countries. What the press release really says, and the two figures the media add without a source.

Interpol
🗃️

OTEIS: a group's claim, no data published

CoinbaseCartel claims an intrusion at OTEIS. No volume, no data published to date. What a listing on an extortion site really lets you conclude.

Ransomware.live · FrenchBreaches · Halcyon
🗃️

ReliaQuest: the confirmed attack that didn't go further

Vishing, a cloned SSO page, MFA approved — then blocked. ReliaQuest confirms the attack and explains why ShinyHunters got nothing more. Sourced timeline.

ReliaQuest statement
🗃️

Fake banking sites: fooling Google and your instincts

Fortra documents a technique that ranks fake banking sites above real ones and hides from security scanners. Up 40% in Q2 2026. The mechanism, sourced.

Fortra · Help Net Security
🗃️

SMS & call bombing: when a number overwhelms you

Hundreds of texts or calls in minutes, with no apparent reason. Bombing isn't a bug: it's an automated harassment or diversion tool, and how to stop it.

🗃️

Strasbourg food aid: 10,073 beneficiary records claimed

A hacker claims a database of food aid beneficiaries in Strasbourg, France, including children. Not confirmed. The factual point, with the caution this deserves.

Cyberattaque.org
🗃️

Wangiri: the "one ring" phone scam

A missed call from an unknown number, a single ring. Calling back can cost you dearly: how the wangiri (one-ring) scam works, and what the FCC says.

🗃️

YouFid: nearly 1.9 million loyalty profiles claimed

A hacker claims 1,899,454 YouFid loyalty program profiles: names, addresses, QR codes. Not confirmed by the company. The factual point, sourced.

Cybercriminal forum post · FrenchBreaches
🗃️

Zimbra: critical flaw exploited, 270+ servers already breached

CISA and Poland's CERT confirm active exploitation of a critical Zimbra flaw. Over 12,000 servers exposed. What it means for your email.

Zimbra · BleepingComputer · CISA
🗃️

153M driving licence scans for sale: what is actually proven

A dark web service claims 153 million US and Canadian driving licence scans. The FBI is investigating. The company named has not confirmed a breach. What is established, and what is not.

Krebs on Security
🗃️

McKesson breach: 284 million patient records claimed

McKesson confirms a breach. ShinyHunters claims 284 million patient records, including Social Security and Medicaid numbers. What is confirmed, what is only claimed.

Help Net Security · TechCrunch · Privacy Guides
🗃️

Egypt: a wave of leak claims, not one official confirmation

Six Egyptian universities, an insurer and the football federation are named in forum claims. No organisation has confirmed anything.

Claims reported by ZATAZ · Claim reported by ZATAZ · Egidio
🗃️

Aesto Health: 9.5 million patients hit through a vendor they never picked

Aesto Health confirms 9.54 million patients affected by a December 2025 AWS breach, disclosed to HHS in 2026. 29 healthcare providers relied on the vendor.

BleepingComputer · HIPAA Journal · SecurityWeek

More reports follow regularly, along with country-specific reports and coverage in additional languages. This page grows with each new publication.

Our method

Every figure cited in The Threat Laboratory comes from a real, identified report, organization or authority — never a vague "gut feel" estimate. The full list of dated sources is public.

Europol ENISA FBI / IC3 CISA Microsoft Google Threat Intelligence Pindrop FTC FCC Hybrid CoE EEAS Trustwave TNS ITRC HHS OCR
🔒 Understanding these threats is half the work — the other half is the protection itself. Egidio connects calls and messaging apps to recognize these patterns before they reach you. See how Medusa, Egidio's engine, works.

Go further

Our sourcing methodology → read it here.