customers – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sat, 23 Aug 2025 03:02:34 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 customers – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Murky Panda hackers exploit cloud trust to hack downstream customers https://earlybirdsinvest.com/murky-panda-hackers-exploit-cloud-trust-to-hack-downstream-customers/ https://earlybirdsinvest.com/murky-panda-hackers-exploit-cloud-trust-to-hack-downstream-customers/#respond Sat, 23 Aug 2025 03:02:33 +0000 https://earlybirdsinvest.com/murky-panda-hackers-exploit-cloud-trust-to-hack-downstream-customers/

Chinese hacker

A Chinese state-sponsored hacking group known as Murky Panda (Silk Typhoon) exploits trusted relationships in cloud environments to gain initial access to the networks and data of downstream customers.

Murky Panda, also known as Silk Typhoon (Microsoft) and Hafnium, is known for targeting government, technology, academic, legal, and professional services organizations in North America.

The hacking group, under its numerous names, has been linked to numerous cyberespionage campaigns, including the wave of Microsoft Exchange breaches in 2021 that utilized the ProxyLogon vulnerability. More recent attacks, include those on the U.S. Treasury’s Office of Foreign Assets Control (OFAC) and the Committee on Foreign Investment.

In March, Microsoft reported that Silk Typhoon had begun targeting remote management tools and cloud services in supply chain attacks to gain access to downstream customers’ networks.

Exploiting trusted cloud relationships

Murky Panda commonly gains initial access to corporate networks by exploiting internet-exposed devices and services, such as the CVE-2023-3519 flaw in Citrix NetScaler devices, ProxyLogin in Microsoft Exchange, and CVE-2025-0282 in Ivanti Pulse Connect VPN.

However, a new report by CrowdStrike demonstrates how the threat actors are also known to compromise cloud service providers to abuse the trust these companies have with their customers.

Because cloud providers are sometimes granted built-in administrative access to customer environments, attackers who compromise them can abuse this trust to pivot directly into downstream networks and data.

In one case, the hackers exploited zero-day vulnerabilities to break into a SaaS provider’s cloud environment. They then gained access to the provider’s application registration secret in Entra ID, which allowed them to authenticate as a service and log into downstream customer environments. Using this access, they were able to read customers’ emails and steal sensitive data.

In another attack, Murky Panda compromised a Microsoft cloud solution provider with delegated administrative privileges (DAP). By compromising an account in the Admin Agent group, the attackers gained Global Administrator rights across all downstream tenants. They then created backdoor accounts in customer environments and escalated privileges, enabling persistence and the ability to access email and application data.

CrowdStrike highlights that breaches via trusted-relationships are rare, they are less monitored than more common vectors such as credential theft. By exploiting these trust models, Murky Panda can more easily blend in with legitimate traffic and activity to maintain stealthy access for long periods.

In addition to their cloud-focused intrusions, Murky Panda also uses a variety of tools and custom malware to maintain access and evade detection.

The attackers commonly deploy the Neo-reGeorg open-source web shell and the China Chopper web shells, both widely associated with Chinese espionage actors, to establish persistence on compromised servers.

The group also has access to a custom Linux-based remote access trojan (RAT) called CloudedHope, which allows them to take control of infected devices and spread further in the network. 

Murky Panda also demonstrates strong operational security (OPSEC), including modifying timestamps and deleting logs to hinder forensic analysis.

The group is also known to use compromised small office and home office (SOHO) devices as proxy servers, allowing them to conduct attacks as if they were within a targeted country’s infrastructure. This allows their malicious traffic to blend in with normal traffic and evade detection.

Significant espionage threat

CrowdStrike warns that Murky Panda/Silk Typhoon is a sophisticated adversary with advanced skills and the ability to rapidly weaponize both zero-day and n-day vulnerabilities.

Their abuse of trusted cloud relationships poses a significant risk to organizations that utilize SaaS and cloud providers.

To defend against Murky Panda attacks, CrowdStrike recommends that organizations monitor for unusual Entra ID service principal sign-ins, enforce multi-factor authentication for cloud provider accounts, monitor Entra ID logs, and patch cloud-facing infrastructure promptly.

“MURKY PANDA poses a significant threat to government, technology, legal, and professional services entities in North America and to their suppliers with access to sensitive information,” concludes CrowdStrike.

“Organizations that rely heavily on cloud environments are innately vulnerable to trusted-relationship compromises in the cloud. China-nexus adversaries such as MURKY PANDA continue to leverage sophisticated tradecraft to facilitate their espionage operations, targeting numerous sectors globally.”

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/murky-panda-hackers-exploit-cloud-trust-to-hack-downstream-customers/feed/ 0 54647
Google confirms data breach exposed potential Google Ads customers’ info https://earlybirdsinvest.com/google-confirms-data-breach-exposed-potential-google-ads-customers-info/ https://earlybirdsinvest.com/google-confirms-data-breach-exposed-potential-google-ads-customers-info/#respond Mon, 11 Aug 2025 01:20:14 +0000 https://earlybirdsinvest.com/google-confirms-data-breach-exposed-potential-google-ads-customers-info/

Google Ads

Google has confirmed that a recently disclosed data breach of one of its Salesforce CRM instances involved the information of potential Google Ads customers.

“We’re writing to let you know about an event that affected a limited set of data in one of Google’s corporate Salesforce instances used to communicate with prospective Ads customers,” reads a data breach notification shared with BleepingComputer.

“Our records indicate basic business contact information and related notes were impacted by this event.”

Google says the exposed information includes business names, phone numbers, and “related notes” for a Google sales agent to contact them again.

The company says that payment information was not exposed and that there is no impact on Ads data in Google Ads Account, Merchant Center, Google Analytics, and other Ads products.

The breach was conducted by threat actors known as ShinyHunters, who have been behind an ongoing wave of data theft attacks targeting Salesforce customers.

While Google has not shared how many individuals were impacted, ShinyHunters says the stolen information contains approximately 2.55 million data records. It is unclear if there are duplicates within these records.

ShinyHunters further told BleepingComputer that they are also working with threat actors associated with “Scattered Spider, who are responsible for first gaining initial access to targeted systems.

“Like we have said repeatedly already, ShinyHunters and Scattered Spider are one and the same,” ShinyHunters told BleepingComputer.

“They provide us with initial access and we conduct the dump and exfiltration of the Salesforce CRM instances. Just like we did with Snowflake.”

The threat actors are now referring to themselves as “Sp1d3rHunters,” to illustrate the overlapping group of people who are involved in these attacks.

As part of these attacks, the threat actors conduct social engineering attacks against employees to gain access to credentials or trick them into linking a malicious version of Salesforce’s Data Loader OAuth app to the target’s Salesforce environment.

The threat actors then download the entire Salesforce database and extort the companies via email, threatening to release the stolen data if a ransom is not paid.

These Salesforce attacks were first reported by the Google Threat Intelligence Group (GTIG) in June, with the company suffering the same fate a month later.

Databreaches.net reported that the threat actors have already sent an extortion demand to Google. After publishing the story, ShinyHunters told BleepingComputer that they demanded 20 Bitcoins, or approximately $2.3 million, from Google to not leak the data.

“I don’t care about ransoming Google anyway, I just sent them a bogus email for the lulz of it,” said the threat actor.

ShinyHunters says they have since switched to a new custom tool that makes it easier and quicker to steal data from compromised Salesforce instances.

In an update, Google recently acknowledged the new tooling, stating that they have seen Python scripts used in the attacks instead of the Salesforce Data Loader.

Update 8/9/25: Added further information about the extortion demand.

Picus Red Report 2025

Malware targeting password stores surged 3X as attackers executed stealthy Perfect Heist scenarios, infiltrating and exploiting critical systems.

Discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/google-confirms-data-breach-exposed-potential-google-ads-customers-info/feed/ 0 52579
New Executive Order to Punish US Banks for Dropping Crypto Customers https://earlybirdsinvest.com/new-executive-order-to-punish-us-banks-for-dropping-crypto-customers/ https://earlybirdsinvest.com/new-executive-order-to-punish-us-banks-for-dropping-crypto-customers/#respond Tue, 05 Aug 2025 05:40:45 +0000 https://earlybirdsinvest.com/new-executive-order-to-punish-us-banks-for-dropping-crypto-customers/

The White House order will involve banks being fined if they drop customers for political reasons or discriminate against digital asset firms and organizations.

The executive order directs bank regulators to investigate whether any banks or financial institutions might have violated the Equal Credit Opportunity Act, antitrust laws, or consumer financial protection laws, reported The Wall Street Journal on Monday.

The order threatens monetary penalties, consent decrees, and other disciplinary measures for violators and could be signed this week, the report added.

Big Banks Can’t Discriminate Against Crypto

“Cryptocurrency companies have said they were shut out of banking services under the Biden administration,” the report noted, though the order also includes being debanked on political grounds.

The banks claim their decisions are based on legal, regulatory, and financial risks, particularly anti-money laundering compliance, which has a wide scope, granting them a lot of control over people’s assets.

“We’ve provided detailed proposals and will continue to work with the administration and Congress to improve the regulatory framework,” a Bank of America spokesman told the outlet.

Banking regulators under Trump have already stopped assessing “reputational risk” from customers, which was seen as a boost for the crypto industry.

The move represents a significant shift from Biden-era banking oversight under Operation Chokepoint 2.0, with the Trump administration positioning itself as the protector of crypto interests against alleged financial industry bias.

There have been several cases in recent years where crypto industry experts or companies have been debanked, and the Trump administration clearly wants to put an end to this practice.

JPMorgan Chase informed Coinbase CEO Brian Armstrong in December 2023 that they would close accounts of individuals whose primary income stemmed from crypto.

Sam Kazemian, founder of Frax Finance, also said that JPMorgan told him they would close the accounts of anyone whose primary source of income or wealth was crypto.

Custodia Bank CEO Caitlin Long, Gemini co-founder Tyler Winklevoss, and the Bitcoin Foundation’s Charlie Shrem also said they were debanked.

In November 2024, Elon Musk posted evidence that 30 tech founders were debanked under the Biden administration.

Banks Still Hate Crypto

It is no surprise that banks harbor a lot of disdain against decentralized digital assets and companies that are part of the nascent industry.

Banks profit from lending out their customers’ money and impose high levels of control and restrictions on what customers can and cannot do with their own money. Crypto is the complete antithesis of this, enabling peer-to-peer transfers and freedom over finances.

Now that banks can see big profits in stablecoins, they appear to be warming to the industry (but for the wrong reasons).

In related news, the United Kingdom recently banned a Coinbase advertising campaign that was critical of its financial system.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

]]>
https://earlybirdsinvest.com/new-executive-order-to-punish-us-banks-for-dropping-crypto-customers/feed/ 0 51547
South Korean Crypto Exchanges Paid Customers $87M in Interest in Past Year https://earlybirdsinvest.com/south-korean-crypto-exchanges-paid-customers-87m-in-interest-in-past-year/ https://earlybirdsinvest.com/south-korean-crypto-exchanges-paid-customers-87m-in-interest-in-past-year/#respond Mon, 28 Jul 2025 01:22:40 +0000 https://earlybirdsinvest.com/south-korean-crypto-exchanges-paid-customers-87m-in-interest-in-past-year/

Author

Tim Alper

Author

Tim Alper

About Author

Tim Alper is a British journalist and features writer who has worked at Cryptonews.com since 2018. He has written for media outlets such as the BBC, the Guardian, and Chosun Ilbo. He has also worked…

Last updated: 


Why Trust Cryptonews

Cryptonews has covered the cryptocurrency industry topics since 2017, aiming to provide informative insights to our readers. Our journalists and analysts have extensive experience in market analysis and blockchain technologies. We strive to maintain high editorial standards, focusing on factual accuracy and balanced reporting across all areas – from cryptocurrencies and blockchain projects to industry events, products, and technological developments. Our ongoing presence in the industry reflects our commitment to delivering relevant information in the evolving world of digital assets. Read more about Cryptonews

South Korean crypto exchanges paid their customers $87 million worth of interest on their fiat deposits in the past 12 months.

Per the South Korean news agency Yonhap (via Daum), data on interest payments was submitted by the Financial Supervisory Service on July 27 after a freedom of information request from the Democratic Party lawmaker Heo Young.

Heo is a member of the National Assembly’s Political Affairs Committee.

South Korean Crypto Exchange Interest Fee Competition

The data shows that the nation’s five fiat-trading platforms have paid their customers interest worth a combined 120.26 billion won since the launch of the Virtual Asset User Protection Act in July last year.

A graph showing trading volumes on the Upbit crypto exchange over the past 12 months.

The law stipulates that the exchanges (Upbit, Bithumb, Coinone, Korbit, and GOPAX) must make reasonable interest payments on fiat deposits held on exchange platforms.

Prior to the law’s launch, platforms typically made nominal interest payments of just 0.1% per annum.

However, the act’s introduction sparked a wave of competition. Platforms began scrambling to draw in new customers with eye-wateringly high interest rates, paid quarterly.

A graph showing trading volumes on the GOPAX crypto exchange over the past 12 months.

This culminated in Bithumb announcing a 4% interest rate, only to perform a u-turn just 6 hours later.

Since this flurry of interest rate-related activity, platforms have slowly begun reducing their rates.

At the end of June this year, Upbit was offering 2.1%. Bithumb was offering 2.2%, with Coinone offeing 2.0%, Korbit 2.1%, and GOPAX setting rates of just 1.3%.

However, even GOPAX’s rate was still considerably higher than most commercial banks’ standard 1% account interest rates.

Interest Rates on Their Way Down?

Platforms have since begun responding to the Bank of Korea’s decision to cut base interest rates. Korbit lowered its usage fee rate to 1.9% this month. Coinone has also announced its decision to cut its rate to 1.77% starting next month.

A Financial Supervisory Service spokesperson said the regulator wants to “create a standard for calculating interest payments that does not “undermine competitive order.”

Heo, meanwhile, claimed that while the act provides a “safety net” for users, too much capital is still “concentrated in certain exchanges.”

These comments come after accusations that Upbit has been allowed to create a de facto monopoly in the exchange scene, commanding over 60% of the market share. The lawmaker said:

“We will continue to improve the system to protect users and establish a sound and competitive environment.”


]]>
https://earlybirdsinvest.com/south-korean-crypto-exchanges-paid-customers-87m-in-interest-in-past-year/feed/ 0 50043
Allianz Life confirms data breach impacts majority of 1.4 million customers https://earlybirdsinvest.com/allianz-life-confirms-data-breach-impacts-majority-of-1-4-million-customers/ https://earlybirdsinvest.com/allianz-life-confirms-data-breach-impacts-majority-of-1-4-million-customers/#respond Sun, 27 Jul 2025 07:36:22 +0000 https://earlybirdsinvest.com/allianz-life-confirms-data-breach-impacts-majority-of-1-4-million-customers/

Allianz logo

Insurance company Allianz Life has confirmed that the personal information for the “majority” of its 1.4 million customers was exposed in a data breach that occurred earlier this month.

“On July 16, 2025, a malicious threat actor gained access to a third-party, cloud-based CRM system used by Allianz Life Insurance Company of North America (Allianz Life),” an Allianz Life spokesperson told BleepingComputer.

“The threat actor was able to obtain personally identifiable data related to the majority of Allianz Life’s customers, financial professionals, and select Allianz Life employees, using a social engineering technique.”

“We took immediate action to contain and mitigate the issue and notified the FBI. Based on our investigation to-date, there is no evidence the Allianz Life network or other company systems were accessed, including our policy administration system.”

“Our investigation is ongoing and we began the process of reaching out to individuals impacted with dedicated resources to assist them. This incident is related only to Allianz Life, which currently has 1.4 million customers.”

Allianz Life is a US-based provider of annuities and life insurance for over 1.4 million Americans. The company is owned by Allianz SE, a global financial services group headquartered in Germany, serving more than 128 million customers.

The company first revealed the breach in a mandatory filing with Maine’s Attorney General’s Office on Saturday, issuing a placeholder notification alerting of the breach.

“The consumer notice will be provided once Allianz has identified the affected individuals,” reads the placeholder notification.

While Allianz Life declined to answer questions about the threat actor and whether they were being extorted, BleepingComputer has learned that the attack is believed to have been conducted by the ShinyHunters extortion group.

ShinyHunters is a group of threat actors who are linked to multiple high-profile data breaches and attacks, including those against PowerSchool and the SnowFlake attacks, which impacted Santander, Ticketmaster, AT&T, Advance Auto Parts, Neiman Marcus, and Cylance.

While multiple ShinyHunters members have been arrested over the past few years, including a recent arrest in France, the hacking group continues to conduct attacks.

Last month, Mandiant warned that ShinyHunters had begun to target Salesforce CRM customers in social engineering attacks.

During these attacks, the hackers impersonate IT support personnel, requesting the targeted employee accept a connection to Salesforce Data Loader, a client application that allows users to import, export, update, or delete data within Salesforce environments.

Once the connection is accepted, the threat actors use Salesforce Data Loader to exfiltrate data from Salesforce, which is then used to extort the company.

BleepingComputer asked Allianz Life if the CRM is Salesforce, but the spokesperson declined to comment.

Wiz

Contain emerging threats in real time – before they impact your business.

Learn how cloud detection and response (CDR) gives security teams the edge they need in this practical, no-nonsense guide.

]]>
https://earlybirdsinvest.com/allianz-life-confirms-data-breach-impacts-majority-of-1-4-million-customers/feed/ 0 49912
Bank Insider Drains $195,000 From Churches, Kids Museum and Customers, Fakes Own Death To Prevent Recovery of Incriminating Evidence: US Department of Justice https://earlybirdsinvest.com/bank-insider-drains-195000-from-churches-kids-museum-and-customers-fakes-own-death-to-prevent-recovery-of-incriminating-evidence-us-department-of-justice/ https://earlybirdsinvest.com/bank-insider-drains-195000-from-churches-kids-museum-and-customers-fakes-own-death-to-prevent-recovery-of-incriminating-evidence-us-department-of-justice/#respond Sat, 26 Jul 2025 15:15:47 +0000 https://earlybirdsinvest.com/bank-insider-drains-195000-from-churches-kids-museum-and-customers-fakes-own-death-to-prevent-recovery-of-incriminating-evidence-us-department-of-justice/

A bank employee is pleading guilty to stealing from the lender’s customers and lying to conceal her guilt, according to the US Attorney’s Office for the Eastern District of Virginia.

The Eastern District says Truist Bank employee, Ahshah Dior Martin, stole $195,000 from at least 70 Truist Bank accounts.

Martin started gathering banking information on her would-be victims in 2023 after improperly accessing the bank’s computer systems.

“Then, she initiated fraudulent debits and withdrawals from these accounts for her own benefit. For instance, Martin repeatedly initiated payments from customer bank accounts to a child support payment processor, through which Martin paid herself.”

The victims Martha stole from while working at Truist Bank were diverse and comprised of both individuals and entities, according to the Eastern District. They included “multiple churches, a children’s museum, an eye tissue bank non-profit organization, manufacturing and construction companies, a small business making customized holsters, and the North Carolina Wing of the Civil Air Patrol.”

Truist Bank fired Martin in April of 2024 but she frustrated efforts by the eighth-largest US bank by total assets to retrieve the computer she had been issued at work.

“To conceal her wrongdoing and prevent the return of her Truist laptop, Martin faked her own death. On April 17, 2024, in response to an email from Truist asking for the computer, Martin responded, “Sorry to inform you, she has passed away.””

The former Truist Bank employee spent the money she stole on “cosmetic products, clothing, travel expenses, dining, and at a hookah bar,” the Eastern District says.

Martin faces up to three decades in prison. She will be sentenced in November.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/bank-insider-drains-195000-from-churches-kids-museum-and-customers-fakes-own-death-to-prevent-recovery-of-incriminating-evidence-us-department-of-justice/feed/ 0 49792
$10,000 To Be Handed To US Bank’s Customers After ‘Extraordinary Losses’ Allegedly Triggered by Data Breach https://earlybirdsinvest.com/10000-to-be-handed-to-us-banks-customers-after-extraordinary-losses-allegedly-triggered-by-data-breach/ https://earlybirdsinvest.com/10000-to-be-handed-to-us-banks-customers-after-extraordinary-losses-allegedly-triggered-by-data-breach/#respond Sat, 26 Jul 2025 02:10:33 +0000 https://earlybirdsinvest.com/10000-to-be-handed-to-us-banks-customers-after-extraordinary-losses-allegedly-triggered-by-data-breach/

A US bank has agreed to pay up to $10,000 to customers affected by an alleged data breach that exposed personally identifying information.

According to a settlement administrator’s portal, The Bank of Canton will pay $300,000 to settle a lawsuit accusing the Canton, Massachusetts-based lender of negligent data security practices.

Class members in the lawsuit, defined as the existing, former and prospective clients of The Bank of Canton in the US impacted by the cybersecurity incident, will receive up to $2,500 for ordinary losses and up to $10,000 for extraordinary losses.

Claimants must provide documentation to prove the losses they suffered as a result of the data breach. Class members who choose not to file documentary evidence can opt for an alternative cash payment of $100.

Claims must be submitted by October 9th, with a final approval hearing for the settlement scheduled to be held in a Massachusetts court on October 21st. Payments will be made once the settlement is approved by a judge.

The Bank of Canton is settling the lawsuit a little over a year after the incident occurred. On or around May 27th of 2023, cybercriminals allegedly gained access to MOVEit Transfer, a file transfer software system used by a third-party service provider of the bank.

The lawsuit alleged the incident led to the sensitive data of the Bank of Canton’s customers, potentially including, account name, account number(s), and Social Security numbers being exposed. The lawsuit was subsequently filed in November of 2023.

Despite agreeing to settle, The Bank of Canton denies the allegations made in the lawsuit.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/10000-to-be-handed-to-us-banks-customers-after-extraordinary-losses-allegedly-triggered-by-data-breach/feed/ 0 49703
JPMorgan Chase, Citi and Wells Fargo Lose $5,361,000,000 To Bad Loans in One Quarter As Customers Fail To Pay Debt https://earlybirdsinvest.com/jpmorgan-chase-citi-and-wells-fargo-lose-5361000000-to-bad-loans-in-one-quarter-as-customers-fail-to-pay-debt/ https://earlybirdsinvest.com/jpmorgan-chase-citi-and-wells-fargo-lose-5361000000-to-bad-loans-in-one-quarter-as-customers-fail-to-pay-debt/#respond Sat, 19 Jul 2025 09:02:45 +0000 https://earlybirdsinvest.com/jpmorgan-chase-citi-and-wells-fargo-lose-5361000000-to-bad-loans-in-one-quarter-as-customers-fail-to-pay-debt/

JPMorgan Chase, Citi and Wells Fargo say they’ve lost $5.361 billion from customers who can no longer pay their debt.

In their Q2 2025 earnings reports, the three major banks disclosed billions of dollars in losses from “net charge-offs” — loans written off as uncollectible after all efforts to recover payments proved unsuccessful.

Among the trio, JPMorgan Chase reported the highest level of charge-offs at $2.4 billion, predominantly driven by bad credit card debt.

Meanwhile, Citi wiped $2.234 billion in bad loans off its books, including $1.889 billion tied to its retail credit card portfolio.

And Wells Fargo recorded $977 million in net charge-offs, fueled by $818 million in sour loans from its consumer banking and lending segment.

The figures come as fresh data from the Federal Reserve Bank of New York shows that US credit card balances reached $1.18 trillion by the end of March 2025.

Despite the losses, Citi reported a $225 million decline in net credit losses quarter-over-quarter, and Wells Fargo saw a $12 million decrease in net charge-offs over the same period. However, JPMorgan witnessed an increase of at $179 million in net charge-offs over the three-month period.

Additionally, the three banks reported strong earnings in Q2, with JPMorgan, Citi and Wells Fargo generating $15 billion, $4 billion and $5.5 billion in net income, respectively.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/jpmorgan-chase-citi-and-wells-fargo-lose-5361000000-to-bad-loans-in-one-quarter-as-customers-fail-to-pay-debt/feed/ 0 48496
Bank Insider Allegedly Obtains Customers’ Debit Card PINs, Drains $440,000 From Their Accounts in Just Two Months: DOJ https://earlybirdsinvest.com/bank-insider-allegedly-obtains-customers-debit-card-pins-drains-440000-from-their-accounts-in-just-two-months-doj/ https://earlybirdsinvest.com/bank-insider-allegedly-obtains-customers-debit-card-pins-drains-440000-from-their-accounts-in-just-two-months-doj/#respond Sun, 13 Jul 2025 13:34:15 +0000 https://earlybirdsinvest.com/bank-insider-allegedly-obtains-customers-debit-card-pins-drains-440000-from-their-accounts-in-just-two-months-doj/

An associate banker at a large national bank is accused of stealing hundreds of thousands of dollars from customers in a span of just two months.

According to the Northern District of California’s U.S. Attorney’s Office, Sixto Christopher Porras allegedly stole approximately $440,000 from two retail bank customers while stationed in San Francisco.

In each of the cases, Porras managed to drain the bank accounts using the customer’s existing debit cards or replacements.

The first incident occurred in August of 2023 after a customer walked into the bank to conduct a wire transfer, according to the Northern District of California’s U.S. Attorney’s Office.

“As the transfer was processed, Porras obtained from the customer the security personal identification number associated with the customer’s debit card. Unbeknownst to the customer, Porras kept the customer’s debit card. Porras allegedly proceeded to use the debit card to embezzle approximately $100,000 from the customer’s account.”

The second incident took place about a month later.

“In or about September 2023, another retail bank customer visited the branch to address a fraudulent charge. As Porras assisted the customer, he obtained the security PIN associated with the customer’s debit card. Porras then caused the customer’s debit card to be reissued and sent to Porras’ San Francisco residence. Porras allegedly proceeded to use the debit card to embezzle approximately $340,000 from the customer’s accounts.”

Porras, who currently no longer works with the unnamed bank, is now facing charges of embezzlement of bank funds and access device fraud. For the embezzlement charge, Porras could get a maximum of up to 30 years in prison and a $1 million fine if convicted. The access device fraud charge carries a maximum of 15 years in prison and a $250,000 fine if convicted.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/bank-insider-allegedly-obtains-customers-debit-card-pins-drains-440000-from-their-accounts-in-just-two-months-doj/feed/ 0 47402
JPMorgan Chase, Bank of America and Wells Fargo Refuse To Reimburse Customers After $22,450 Drained From Bank Accounts https://earlybirdsinvest.com/jpmorgan-chase-bank-of-america-and-wells-fargo-refuse-to-reimburse-customers-after-22450-drained-from-bank-accounts/ https://earlybirdsinvest.com/jpmorgan-chase-bank-of-america-and-wells-fargo-refuse-to-reimburse-customers-after-22450-drained-from-bank-accounts/#respond Sat, 12 Jul 2025 02:46:24 +0000 https://earlybirdsinvest.com/jpmorgan-chase-bank-of-america-and-wells-fargo-refuse-to-reimburse-customers-after-22450-drained-from-bank-accounts/

Customers at JPMorgan Chase, Bank of America and Wells Fargo say the banks have refused to reimburse after bad actors ripped cash from their accounts.

A Wells Fargo customer for nearly four decades says the lender refused to make him whole after scammers drained $20,000 from his account.

Scott Merovitch says he received a call from someone claiming to work at the bank, warning his account was flashing suspicious activity, reports FOX 26 Houston.

According to Merovitch, the caller was able to provide information about his recent transactions.

After the call, a woman pretending to work at Wells Fargo showed up at Merovitch’s front door, asked for his card and cut it into pieces.

Two hours later, Merovitch says $20,000 exited his account at ATM locations just a few miles from his residence.

When he filed for a reimbursement claim, Merovitch says the lender issued a letter telling him that the transactions were made by him or someone who had his permission.

Meanwhile, JPMorgan Chase is refusing to reimburse a man scammed by a fake Apple support text, reports the CBS-affiliated news station KOLD.

The phishing text, posing as Apple’s billing department, claimed unauthorized activity was underway.

The victim says he quickly called the number, and the scammer likely installed malware on his iPhone to tap into his bank account.

Chase says reimbursement is not happening.

“After further review, our claim denial stands as we found these transactions were authorized by the customer with no evidence of fraudulent account takeover or of a compromised device.”

Lastly, Bank of America refused to reimburse a customer who lost $450 to a taxi scam in Panama.

Keith Lee says he was charged $450 for a $10 cab ride, according to the Elliott Report.

The driver claimed Lee’s card didn’t process, so he paid cash.

Bank of America denied his dispute, saying a chip-verified “card-present” transaction was executed.

Consumer advocate Christopher Elliott then stepped in, contacting BofA on Lee’s behalf.

After hearing from Elliott, Bank of America finally reversed the charge. Elliott says the bank acknowledged such taxi scams are well-known.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/jpmorgan-chase-bank-of-america-and-wells-fargo-refuse-to-reimburse-customers-after-22450-drained-from-bank-accounts/feed/ 0 47139