FBI – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sun, 14 Sep 2025 22:57:24 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 FBI – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 FBI warns of UNC6040, UNC6395 hackers stealing Salesforce data https://earlybirdsinvest.com/fbi-warns-of-unc6040-unc6395-hackers-stealing-salesforce-data/ https://earlybirdsinvest.com/fbi-warns-of-unc6040-unc6395-hackers-stealing-salesforce-data/#respond Sun, 14 Sep 2025 22:57:24 +0000 https://earlybirdsinvest.com/fbi-warns-of-unc6040-unc6395-hackers-stealing-salesforce-data/

FBI cyber

The FBI has issued a FLASH alert warning that two threat clusters, tracked as UNC6040 and UNC6395, are compromising organizations’ Salesforce environments to steal data and extort victims.

“The Federal Bureau of Investigation (FBI) is releasing this FLASH to disseminate Indicators of Compromise (IOCs) associated with recent malicious cyber activities by cyber criminal groups UNC6040 and UNC6395, responsible for a rising number of data theft and extortion intrusions,” reads the FBI’s FLASH advisory.

“Both groups have recently been observed targeting organizations’ Salesforce platforms via different initial access mechanisms. The FBI is releasing this information to maximize awareness and provide IOCs that may be used by recipients for research and network defense.”

UNC6040 was first disclosed by Google Threat Intelligence (Mandiant) in June, who warned that since late 2024, threat actors were using social engineering and vishing attacks to trick employees into connecting malicious Salesforce Data Loader OAuth apps to their company’s Salesforce accounts.

In some cases, the threat actors impersonated corporate IT support personnel, who used renamed versions of the application called “My Ticket Portal.”

Once connected, the threat actors used the OAuth application to mass-exfiltrate corporate Salesforce data, which was then used in extortion attempts by the ShinyHunters extortion group.

In these early data theft attacks, ShinyHunters told BleepingComputer that they primarily targeted the “Accounts” and “Contacts” database tables, which are both used to store data about a company’s customers.

These data theft attacks were widespread, impacting large and well-known companies, such as Google, Adidas, Qantas, Allianz Life, Cisco, Kering, Louis Vuitton, Dior, and Tiffany & Co.

Later data theft attacks in August also targeted Salesforce customers, but this time utilized stolen Salesloft Drift OAuth and refresh tokens to breach customers’ Salesforce instances.

This activity is tracked as UNC6395 and is believed to have occurred between August 8th and 18th, with the threat actors using the tokens to target the company’s support case information that was stored in Salesforce.

The exfiltrated data was then analyzed to extract secrets, credentials, and authentication tokens shared in support cases, including AWS keys, passwords, and Snowflake tokens. These credentials could then be used to pivot to other cloud environments for additional data theft.

Salesloft worked with Salesforce to revoke all Drift tokens and required customers to reauthenticate to the platform.

It was later revealed that the threat actors also stole Drift Email tokens, which were used to access emails for a small number of Google Workspace accounts.

An investigation by Mandiant determined the attack originated in March, when Salesloft’s GitHub repositories were compromised, allowing attackers to ultimately steal the Drift OAuth tokens.

Like the previous attacks, these new Salesloft Drift data theft attacks impacted numerous companies,  including Cloudflare, Zscaler, Tenable, CyberArk, Elastic, BeyondTrust, Proofpoint, JFrog, Nutanix, Qualys, Rubrik, Cato Networks, Palo Alto Networks, and many more.

While the FBI did not name the groups behind these campaigns, BleepingComputer was told by the ShinyHunters extortion group that they and other threat actors calling themselves “Scattered Lapsus$ Hunters, were behind both clusters of activity.

This group of hackers claims to have originated from and overlap with the Lapsus$, Scattered Spider, and ShinyHunters extortion groups.

On Thursday, the threat actors announced via a domain associated with BreachForums that they planned to “go dark” and stop discussing operations on Telegram.

However, in a parting post, the hackers claimed to have gained access to the FBI’s E-Check background check system and Google’s Law Enforcement Request system, publishing screenshots as proof.

If legitimate, this access would allow them to impersonate law enforcement and pull sensitive records of individuals.

When contacted by BleepingComputer, the FBI declined to comment, and Google did not respond to our email.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/fbi-warns-of-unc6040-unc6395-hackers-stealing-salesforce-data/feed/ 0 58467
Fraudsters Pose as Lawyers to Target Cryptocurrency Losses, FBI Says https://earlybirdsinvest.com/fraudsters-pose-as-lawyers-to-target-cryptocurrency-losses-fbi-says/ https://earlybirdsinvest.com/fraudsters-pose-as-lawyers-to-target-cryptocurrency-losses-fbi-says/#respond Sat, 16 Aug 2025 16:23:42 +0000 https://earlybirdsinvest.com/fraudsters-pose-as-lawyers-to-target-cryptocurrency-losses-fbi-says/

The Federal Bureau of Investigation (FBI) has warned that criminals are posing as lawyers to steal money from people who have already lost funds in cryptocurrency scams.

According to an August 13 FBI advisory, some scammers pretended they worked with government agencies or financial regulators. Others claimed to have partnerships with organizations that do not exist.

A common tactic is to ask for payment in cryptocurrency or gift cards, methods no genuine law firm would accept. Many victims are persuaded because the scammers know how much money they lost before and when those transactions happened.

What is Olympus DAO? (OHM Crypto Animated Explainer)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Sometimes victims are told to contact a so-called “crypto recovery law firm” and open an account with a foreign bank. The website they are directed to often looks real but is designed to collect personal information and account details.

Other red flags include demands for “bank fees” to confirm identity, refusal to provide credentials, and avoidance of video calls.

The FBI recommended following a “zero trust” approach with any unexpected phone calls, emails, or messages. People should ask for a photo of a law license and verify it with the issuing authority.

Additional precautions include using only trusted phone numbers and websites, avoiding links from unknown senders, and taking time before transferring money or sharing personal data.

The advisory added:

Contact with scammers impersonating law firms continues to pose many risks, including the theft of personal data and funds from unsuspecting victims, to the reputational harm of actual lawyers being impersonated.

Meanwhile, Wisconsin legislators introduced Senate Bill 386 on August 11 to address scams involving crypto ATMs. What does the bill include? Read the full story.


]]>
https://earlybirdsinvest.com/fraudsters-pose-as-lawyers-to-target-cryptocurrency-losses-fbi-says/feed/ 0 53514
FBI drops probe into Kraken founder Jesse Powell, returns seized devices https://earlybirdsinvest.com/fbi-drops-probe-into-kraken-founder-jesse-powell-returns-seized-devices/ https://earlybirdsinvest.com/fbi-drops-probe-into-kraken-founder-jesse-powell-returns-seized-devices/#respond Tue, 22 Jul 2025 18:42:06 +0000 https://earlybirdsinvest.com/fbi-drops-probe-into-kraken-founder-jesse-powell-returns-seized-devices/

The US Justice Department has closed its investigation into Kraken’s founder Jesse Powell, and returned dozens of laptops and mobile phones agents seized during an FBI raid two years ago, Fortune reported on July 22.

The federal case did not revolve around Kraken’s operations, but rather a bitter governance fight at the Verge Center for the Arts, a Sacramento nonprofit Powell founded in 2008.

News of the raid first surfaced in The New York Times, which reported that agents were probing allegations Powell had “hacked and cyber-stalked” the nonprofit.

Court filings since then depict something far less cinematic: a dispute over who controlled Slack and Google Workspace accounts after Powell was pushed off Verge’s board. 

Powell insisted he never cut off anyone’s access and argues instead that Verge insiders quietly created a new domain and parallel work accounts before moving to oust him. 

He is pursuing a civil lawsuit in state court, accusing former colleagues of defamation and wrongful removal.

Justice Department drops the case

Documents Powell filed this week include a so-called declination letter from prosecutors, confirming the Justice Department has walked away from the case.

His attorney said he requested the letter to counter the reputational damage caused by the raid and to reassure banks and regulators that Kraken’s leadership is not under federal scrutiny. 

Powell called the search “devastating” personally and professionally, maintaining that discovery in his lawsuit has already shown the accusations to be baseless.

The government’s exit does not resolve lingering questions. Neither the Justice Department nor the FBI would comment on how the Times obtained details of the investigation.

Powell’s latest filings also accuse two Verge board members, one of them attorney Phil Cunningham, of withholding key documents during discovery. 

Verge, meanwhile, continues to operate as a fixture of Sacramento’s arts scene, supported over the years by more than $1 million in donations and extensive tech assistance from Powell. 

Notably, Powell declined to say whether the returned devices held Bitcoin or other digital assets. When agents seized the hardware, Bitcoin (BTC) traded near $23,000. As of press time, BTC trades near $119,000.

Mentioned in this article
]]>
https://earlybirdsinvest.com/fbi-drops-probe-into-kraken-founder-jesse-powell-returns-seized-devices/feed/ 0 49074
Fake Trump-Vance Inaugural Email Nets $250,300 in USDT, FBI Gets $40,300 Back https://earlybirdsinvest.com/fake-trump-vance-inaugural-email-nets-250300-in-usdt-fbi-gets-40300-back/ https://earlybirdsinvest.com/fake-trump-vance-inaugural-email-nets-250300-in-usdt-fbi-gets-40300-back/#respond Fri, 04 Jul 2025 15:08:44 +0000 https://earlybirdsinvest.com/fake-trump-vance-inaugural-email-nets-250300-in-usdt-fbi-gets-40300-back/

The US Department of Justice has recovered $40,300 in cryptocurrency that was stolen in a scam involving a fake Trump-Vance Inaugural Committee email.

On December 24, 2024, a donor received an email that appeared to come from Steve Witkoff, the committee’s co-chair, according to the Department of Justice’s press release on July 2.

The message used a nearly identical domain name to the real one, which swapped the letter “i” for a lowercase “l” in “t47lnaugural.com”.

The Most Rewarding Play-to-Earn Project? BitDegree Explained (ANIMATED)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

The victim transferred $250,300 in USDT, and the scammers immediately moved the funds through multiple crypto wallets to make it harder to trace.

Investigators at the FBI’s Washington Field Office used blockchain analysis to follow the trail of transactions. They were able to locate and recover $40,300 of the stolen funds. Prosecutors have filed a civil forfeiture case to return the recovered amount to the victim.

Steven Jensen of the FBI stated, “Impersonation scams take many forms and cost Americans billions in losses each year”. He advised the public to carefully verify email addresses and never send money or crypto to individuals they do not know personally.

He added that scammers often rely on small details, including minor changes in email addresses or domains, to trick victims into believing fraudulent messages are legitimate.

On June 18, the Department of Justice seized $225 million in crypto linked to scams that misled over 400 people into fake investment schemes. How? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/fake-trump-vance-inaugural-email-nets-250300-in-usdt-fbi-gets-40300-back/feed/ 0 45742
FBI Warns: AI Scammers Pretend to Be US Government Officials https://earlybirdsinvest.com/fbi-warns-ai-scammers-pretend-to-be-us-government-officials/ https://earlybirdsinvest.com/fbi-warns-ai-scammers-pretend-to-be-us-government-officials/#respond Sat, 17 May 2025 19:01:29 +0000 https://earlybirdsinvest.com/fbi-warns-ai-scammers-pretend-to-be-us-government-officials/

Criminals have started using artificial intelligence (AI) to trick people by pretending to be senior US government officials, according to a warning from the FBI issued on May 15.

The FBI explained that attackers are sending deepfake voice recordings and text messages that appear to come from federal or state officials.

The agency warned, “If you receive a message claiming to be from a senior US official, do not assume it is authentic”.

What is a Cryptocurrency: For Beginners (Animated Explainer)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Once the scammers make contact, they often send links to websites or platforms they control. These sites are set up to steal login details, passwords, and other private information. In some cases, they may also ask for money or try to get more details by pretending to be someone the victim knows.

The FBI warned that if a real official’s account is taken over, the damage could spread quickly. Hackers could then use that person’s contact list to reach other government workers or their partners. They added:

Contact information acquired through social engineering schemes could also be used to impersonate contacts to elicit information or funds.

To avoid falling for these scams, the FBI recommends checking the sender’s details carefully. Look for spelling mistakes or small changes in email addresses that could signal something is off.

They also advised against sharing sensitive information, opening links from unfamiliar sources, or relying on just one password to protect accounts.

Recently, the FBI highlighted cryptocurrency scams in its 2024 annual report. What did it say? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/fbi-warns-ai-scammers-pretend-to-be-us-government-officials/feed/ 0 36788
FBI Points to North Korean Hackers in $1.5 Billion Crypto Breach at Bybit https://earlybirdsinvest.com/fbi-points-to-north-korean-hackers-in-1-5-billion-crypto-breach-at-bybit/ https://earlybirdsinvest.com/fbi-points-to-north-korean-hackers-in-1-5-billion-crypto-breach-at-bybit/#respond Fri, 28 Feb 2025 03:44:23 +0000 https://earlybirdsinvest.com/fbi-points-to-north-korean-hackers-in-1-5-billion-crypto-breach-at-bybit/

The Federal Bureau of Investigation has implicated North Korean-backed hacking groups in a major cryptocurrency heist involving $1.5 billion in digital assets.

The cyberattack targeted Bybit, a Dubai-based cryptocurrency exchange, making it one of the largest crypto thefts publicly known. This incident has drawn attention to North Korea’s ongoing role in cyber-enabled financial crimes.

FBI Blames North Korean Hackers for $1.5 Billion Crypto Heist

The hackers—identified as TraderTraitor and the Lazarus Group—allegedly deployed malware through modified cryptocurrency trading applications, allowing them to seize Ethereum and convert it into other cryptocurrencies, according to an FBI statement released on Wednesday.

The stolen funds were rapidly transferred to thousands of wallet addresses across multiple blockchains. The FBI suspects these assets will eventually be laundered and converted into fiat currency.

While the North Korean government has not acknowledged the theft, reports from South Korea’s intelligence agencies suggest that North Korea has stolen $1.2 billion in cryptocurrency over the past five years.

The Washington Post reporting this noted:

It represents a rare source of badly needed foreign currency to support its fragile economy and fund its nuclear program in the face of intense U.N. sanctions and North Korea’s strict border closures during the coronavirus pandemic. A UN experts panel separately said it was investigating 58 suspected cyberattacks by North Korea between 2017 to 2023 that saw some $3 billion stolen to “reportedly help to fund the country’s development of weapons of mass destruction.”

Bybit’s Response and Industry Implications

Bybit’s co-founder and CEO, Ben Zhou, addressed the FBI’s accusations by linking to a site offering bounties to track and freeze the stolen assets.

The exchange revealed that the attack involved a sophisticated exploit targeting their offline or “cold” wallets, which are generally considered more secure than online storage. According to blockchain analytics firm Certik, this breach ranks as the largest blockchain-related hack to date.

Blockchain analyst Manuel Villegas explained that the attackers used a “blind signing” exploit. This method involves a fake user interface mimicking the legitimate platform, tricking users into authorizing unauthorized transactions.

The repercussions of this breach have extended beyond Bybit’s ecosystem, triggering a decline in overall cryptocurrency prices. Bitcoin has so far faced significant plunge falling to as low as $82,000 levels on Wednesday.

Industry observers suggest that this incident will increase regulatory scrutiny on cryptocurrency exchanges and their security measures.

The global crypto market cap value on TradingView
The global digital currency market cap value on the 1-day chart. Source: TradingView.com

Featured image created with DALL-E, Chart from TradingView

]]>
https://earlybirdsinvest.com/fbi-points-to-north-korean-hackers-in-1-5-billion-crypto-breach-at-bybit/feed/ 0 22334
FBI initiative saves thousands from crypto scams, recovers $285 million https://earlybirdsinvest.com/fbi-initiative-saves-thousands-from-crypto-scams-recovers-285-million/ https://earlybirdsinvest.com/fbi-initiative-saves-thousands-from-crypto-scams-recovers-285-million/#respond Thu, 13 Feb 2025 22:22:32 +0000 https://earlybirdsinvest.com/fbi-initiative-saves-thousands-from-crypto-scams-recovers-285-million/

The FBI’s initiative to counter crypto investment fraud has helped thousands of victims avoid losing millions of dollars since its launch, according to a Feb. 13 press release.

Dubbed Operation Level Up, the program proactively identifies individuals in the midst of being scammed and intervenes before they lose their money.

Since its launch, the initiative has saved more than 4,300 potential victims from collectively losing an estimated $285 million, according to the FBI’s Criminal Investigative Division.

James Barnacle, deputy assistant director of the division, said:

“It’s a growing problem, and it’s a big problem affecting many Americans.”

Identifying victims before losses

Crypto investment fraud, often referred to as “pig butchering,” involves scammers cultivating online relationships — romantic, professional, or platonic — before luring victims into fraudulent investment schemes.

These fraudsters use fabricated trading platforms that display inflated returns, leading victims to pour more money into the scam. When they attempt to withdraw their funds, they are denied access.

Under Operation Level Up, the FBI tracks these scams in real-time and directly contacts victims before they commit additional funds. One targeted investor, planning to invest another $1 million, was warned in time by the FBI, while another was about to sell her home for a $500,000 investment before receiving an intervention call.

Beyond financial losses, victims often face emotional devastation. Some require support services or suicide intervention, underscoring the psychological toll of these scams, according to the FBI.

The FBI is urging the public to be cautious of unsolicited investment opportunities, especially those involving crypto. Operation Level Up not only warns potential victims but also gathers intelligence to track and dismantle the criminal networks behind these frauds.

The FBI is collaborating with domestic and international partners to shut down illicit domains and accounts. Financial institutions and private companies receive alerts on fraudulent platforms to prevent further transactions.

Multi-billion dollar industry

The FBI’s Internet Crime Complaint Center (IC3) reported $3.9 billion in crypto investment fraud losses in 2023. Meanwhile, “pig butchering” alone accounted for $3.6 billion in losses globally in 2024.

Officials believe the true figure is even higher, as many victims do not report or underreport their losses. On average, 3,200 complaints related to crypto scams are filed with IC3 each month.

Scammers target victims through social media, professional networking sites, text messages, investment groups, and dating platforms, often convincing even tech-savvy individuals to invest. Many victims, aged 30 to 60, are drawn in by the promise of financial security and high returns.

For those who suspect they are victims of crypto fraud, the FBI advises contacting their bank immediately and filing a complaint with the relevant law enforcement agencies. It also encouraged individuals to discuss potential scams with friends and family to prevent further victimization.

Blocscale
]]>
https://earlybirdsinvest.com/fbi-initiative-saves-thousands-from-crypto-scams-recovers-285-million/feed/ 0 19298