San Mateo, CA, April 28, 2025 — Stories, events, and developments that impacted the cybersecurity landscape last week, including emerging threats, policy changes, and industry responses.
Cybercrime cost the U.S. $16.6 billion in 2024
According to the FBI’s annual Internet Crime Complaint Center (IC3) report, cybercriminals stole a record $16.6 billion in 2024, representing a 33% increase from 2023. IC3 recorded 859,532 complaints, with the average loss being $19,372. The losses impacted older Americans over 60 the most, who suffered $4.8 billion in losses across 147,127 complaints. Fraud represented the bulk of reported losses in 2024, and ransomware was again the most pervasive threat to critical infrastructure, with complaints rising 9% from 2023,” said B. Chad Yarbrough, the FBI’s Operations Director for Criminal and Cyber. It is worth noting that the FBI’s data only includes online crime cases that were either reported by victims or discovered by law enforcement, meaning that the total published monetary amount may only be a fraction of what Americans had stolen in 2024. Read more.
Darcula phishing toolkit now features generative AI
The Darcula phishing-as-a-service platform has been updated to include generative AI capabilities. “This addition lowers the technical barrier for creating phishing pages, enabling less tech-savvy criminals to deploy customized scams in minutes,” Netcraft said in a report shared with The Hacker News, “The new AI-assisted features amplify Darcula’s threat potential by simplifying the process to build tailored phishing pages with multi-language support and form generation — all without any programming knowledge.” Netcraft says that it has taken down over 25,000 Darcula pages, blocked almost 31,000 IP addresses, and flagged more than 90,000 phishing domains since March 2024. According to security researcher Harry Everett, Darcula’s new features allow a novice attacker to “build and deploy a customized phishing site in minutes.” Read more.
SMBs increasingly targeted by nation-state threat actors
Small and medium-sized businesses, particularly those that supply goods or services to large companies, are increasingly being targeted by state-sponsored threat actors who view them as the most vulnerable point of entry in supply chains. SMBs tend not to focus as much on cybersecurity as large corporations, making them vulnerable targets for nation-state actors seeking to penetrate the networks of major financial or technology companies and government organizations. “Your average SMB — especially manufacturing where we see a lot of impact — just doesn’t think they’re on the firing line at all,” says Eric Chien, a cybersecurity fellow for the Symantec Threat Hunter team at global technology firm Broadcom. “You don’t realize that you are part of that supply chain — you’re providing something to someone who’s providing something to someone… The average organization out there doesn’t think Iran or Russia or North Korea — well, maybe they think China — are really going after them as a target, but that actually simply is not the case.” Read more.
Threat actors abuse Zoom to steal crypto
Zoom is being exploited by a hacking group called Elusive Comet. The group uses social engineering tactics that abuse Zoom’s remote control feature to fool victims into giving them access to their devices. The campaign was discovered by cybersecurity firm Trail of Bits, who say that the group is using techniques employed by North Korea’s Lazarus hacking group. “The ELUSIVE COMET methodology mirrors the techniques behind the recent $1.5 billion Bybit hack in February, where attackers manipulated legitimate workflows rather than exploiting code vulnerabilities,” explains the Trail of Bits report. The firm learned of this attack campaign after Elusive Comet targeted their CEO on X. Read more.
Blue Shield shared private health data of millions with Google for years
Blue Shield of California is sending notifications to millions of people, reporting that the health insurance giant has been sharing patients’ private health data with Google since 2021. While the company stated that sharing stopped in January of 2024, a misconfiguration allowed Google to collect personal and health information from Blue Shield customers, which may have been used to “conduct focused ad campaigns back to those individual members.” Blue Shield said the exposed data also included “insurance plan names, types and group numbers, along with personal information such as patients’ city, zip code, gender and family size. Details of Blue Shield-assigned member account numbers, claim service dates and service providers, patient names and patients’ financial responsibility were also shared.” Blue Shield had 4.5 million members as of 2022, and it is believed that this breach affects most of them. Read more.
Verizon reports huge spike in ransomware and exploited vulnerabilities
Verizon has released its 2025 Data Breach Investigations Report, which reveals a significant increase in the sophistication, impact, and activity of threat actors. The rate of ransomware detected in breaches spiked by 37%. It was found in 44% of 12,195 breaches reviewed for the report. Payments to ransomware attackers are down, with 64% of victims refusing to pay up, but ransomware continues to grow in popularity. Exploited vulnerabilities also increased by 34% over the last year. The spike is attributed partly to zero-day exploits targeting edge devices and virtual private networks. “The percentage of edge devices and VPNs as a target on our exploitation of vulnerabilities action was 22%, and it grew almost eightfold from the 3% found in last year’s report,” Verizon said in the report. Read more.
FBI: Beware of scammers posing as IC3 employees
The FBI is warning of a scam in which threat actors impersonate FBI Internet Crime Complaint Center (IC3) employees and offer to assist victims of fraud in recovering stolen funds. However, according to the agency, “the claim is a ruse to revictimize those who have already lost money to scams” by gaining access to their financial accounts. “Complainants report initial contact from the scammers can vary. Some individuals received an email or a phone call, while others were approached via social media or forums,” the law enforcement agency warned in a public service announcement. “Almost all complainants indicated the scammers claimed to have recovered the victim’s lost funds or offered to assist in recovering funds.” The FBI is reminding the public that IC3 will never contact victims directly via phone calls, text messages, email, social media, or public forums. Read more.
Southeast Asian scam sectors expanding rapidly
A new report from the UN Office on Drugs and Crime (UNODC) titled “Inflection Point: Global Implications of Scam Centres, Underground Banking and Illicit Online Marketplaces in Southeast Asia” has resulted in the UN issuing a warning regarding the rapid expansion of Southeast Asian cyber fraud operations. The report says that scam centers are run by “sophisticated transnational syndicates and interconnected networks of money launderers, human traffickers, data brokers, and a growing number of other specialist service providers and facilitators.” The report also says that scam centers tend to be located in “vulnerable” border regions, such as in Myanmar and Cambodia, and that consolidated groups of gangs are building “industrial and science and technology parks as well as casinos and hotels.” The report warns that “it is now increasingly clear that a potentially irreversible spillover has occurred in Southeast Asia, leaving criminal groups free to pick, choose, and relocate jurisdictions, operations, and value as needed, with the resulting situation rapidly outpacing the capacity of governments to contain it.” Read more.
ClickFix social engineering tactic favored by state-sponsored threat actors
State-sponsored hackers from North Korea, Iran, and Russia are popularizing ClickFix attacks in their espionage campaigns. A social engineering technique that uses malicious websites to spoof legitimate software or document-sharing platforms, ClickFix attackers lure victims with phishing or malvertising that displays a fake error message with instructions to click a “fix” button. When clicked, a PowerShell or command-line script executes malware on their system. A report from Proofpoint indicates that, between late 2024 and early 2025, Kimsuky (North Korea), MuddyWater (Iran), as well as APT28 and UNK_RemoteRogue (Russia), all utilized ClickFix in their operations. Read more.
Toll fraud campaign targeting U.S. drivers powered by Chinese smishing kit
Cisco Talos researchers Azim Khodjibaev, Chetan Raghuprasad, and Joey Chen are warning of a “widespread and ongoing” SMS phishing campaign targeting U.S. toll road users with malicious text messages. The campaign, according to the researchers, is being “carried out by multiple financially motivated threat actors using the smishing kit developed by ‘Wang Duo Yu.'” The attackers have been impersonating electronic toll collection systems, such as E-ZPass, since October 2024, sending out SMS messages and Apple iMessages that contain a link to a fake landing page designed to steal credentials. “Wang Duo Yu has crafted and designed specific smishing kits and has been selling access to these kits on their Telegram channels,” Talos researchers said. “The kits are available with different infrastructure options, priced at US$ $50 each for a full-feature development, $30 each for proxy development (when the customer has a personal domain and server), $20 each for version updates, and $20 for all other miscellaneous support.” Read more.
More cybersecurity news
- Last week’s news
- More cybersecurity news
- All articles sponsored by NetworkTigers
About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, which built and re-architected data centers for Fortune 500 firms, NetworkTigers provides consulting and network equipment to global governmental agencies, Fortune 2000, and healthcare companies. www.networktigers.com.
