PrivacySignal
Breach

Spanish Police take down €140 million cyber fraud ring, arrest four

BleepingComputer · · International · Data Breaches

Spanish authorities arrested four people and dismantled a criminal network accused of generating approximately €140 million through investment fraud schemes and business email compromise attacks. The group is also alleged to have laundered the proceeds of those crimes.

Why this matters: Business email compromise is one of the most damaging scams running right now, and it works because it targets normal business processes — wire transfers, invoices, payroll. No exotic exploit needed. Someone just impersonates the right person at the right moment. €140 million across what is likely dozens or hundreds of victims means real companies and real people lost serious money. Arrests like this are rare enough that they matter. But the bigger issue is that BEC keeps scaling because the barrier to entry is low and the payoff is high.

Who should care: Cybersecurity · Privacy officers · Administrators

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
CyberScoop · · US Federal

ATF confirms cyberattack hit system containing info on its investigation targets

The prolific ransomware group Qilin claimed responsibility for the attack. ATF insists the incident was limited to a standalone system and hasn’t impacted critical operations. The post ATF confirms cyberattack hit system containing info on its investigation targets appeared first on CyberScoop.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement#security Read original →
Breach
DataBreaches.net · · International

Winona County paid more than $128K following January ransomware attack

WXOW in Minnesota reports: Winona County paid more than $128,000 following a January ransomware attack, according to a county news release. The county said it negotiated and paid $128,539.57 with assistance from its insurance carrier after ransomware was detected on its computer network Jan. 22, 2026. Officials said the decision was made after consultation with... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
DataBreaches.net · · International

UK: HIV charity has ‘sensitive’ health data stolen

George House Trust, a UK HIV charity, has notified service users that sensitive personal health data may have been stolen following a breach of Beacon CRM, a platform used by more than 1,000 charities and non-profits.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
BleepingComputer · · International

Over 8,300 Gitea servers vulnerable to code execution attacks

Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
HIPAA Journal · · US Federal

American Vision Partners Settles Data Breach Litigation for $1.75M

American Vision Partners, an eye care management company operating as Medical Management Resource Group LLC, has agreed to pay $1.75 million to settle a class action lawsuit tied to a data breach. The settlement resolves litigation brought by affected individuals whose information was exposed.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →