- W3LL phishing kitPhishing-as-a-service toolkit sold for ~$500 used to create fake login pages and steal credentials
ThreatNoir Weekend Brief — April 12
Morning Review in IT Security — April 12, 2026
The cybersecurity landscape continues to face mounting pressure from insider threats, organized cybercrime operations, and state-sponsored actors. Today's review highlights critical incidents spanning financial institutions, government agencies, educational systems, and critical infrastructure, underscoring the persistent vulnerability of organizations across sectors and geographies.
UAE Central Bank Source Code Leaked by Insider Threat
The compliance framework source code for the Central Bank of the UAE has allegedly been leaked on a popular cybercrime forum, with the breach attributed to an insider threat. The threat actor XiaoSaoBi, also known as RACCOON, is credited with the source code leak. This incident represents a significant compromise of sensitive financial infrastructure and raises serious concerns about insider access controls within critical banking institutions. Source: ‼️🇦🇪 The compliance framework source code for the Central Bank of the UAE (CBUAE) has allegedly...
Global Phishing-as-a-Service Operation Dismantled
Law enforcement agencies including FBI Atlanta and Indonesian police have successfully dismantled a major global phishing operation responsible for over $20 million in fraud attempts. The operation centered on the W3LL phishing kit, a tool sold for approximately $500 that enabled criminals to construct fake login pages designed to steal usernames, passwords, and circumvent security mechanisms. The takedown demonstrates coordinated international law enforcement efforts against phishing-as-a-service infrastructure. Source: ‼️ FBI Atlanta & Indonesian police took down a major global phishing operation tied to $20M+...
US Mobile Carrier Breach Exposes Millions of Records
Access credentials to an unnamed USA prepaid mobile phone carrier are allegedly being sold on cybercrime forums, with the threat actor The_Auditors offering access to approximately 3 million customer records for $75,000. The breach includes capabilities to perform SIM swaps, representing a severe threat to customer account security and identity protection. This incident underscores the vulnerability of telecommunications infrastructure to insider threats and unauthorized access sales. Source: ‼️🇺🇸 Access to an unnamed USA prepaid mobile phone carrier is allegedly being sold on a popular...
Morgan County Georgia Targeted by INC Ransom Ransomware
Morgan County, Georgia has been claimed as a victim by the INC Ransom ransomware gang. This attack represents an ongoing trend of ransomware targeting government and municipal infrastructure, disrupting essential services and threatening public data security. Source: ‼️🇺🇸 Morgan County Georgia has been claimed a victim by INC Ransom Ransomware...
French Education System Database Breached
The database of Academie de Paris, the Parisian branch of France's national education system, has allegedly been leaked on a cybercrime forum by the threat actor Cybernox. This breach of educational infrastructure exposes sensitive student records and represents a significant privacy violation within the European education sector. Source: ‼️🇫🇷 The database of Academie de Paris, the Parisian branch of France's national education syst...
Hacktivist Group Downs Major US GPS Tracking Company
Ababil of Minab, the hacktivist group responsible for the Los Angeles Metro breach, has claimed responsibility for compromising Vyncs, one of the largest GPS tracking technology companies in the United States. The company has experienced a service outage lasting nearly a week, demonstrating the operational impact of hacktivist attacks on critical commercial infrastructure. Source: 1/3‼️🇺🇸 Ababil of Minab. the hacktivist group who took responsiblity of hacking Los Angeles Met...
FBI Recovers Deleted Signal Messages Through iPhone Notifications
A court case has revealed that Signal messages may persist in iPhone notification data, enabling law enforcement access even after deletion. This discovery highlights previously unknown forensic pathways through which encrypted communications can be recovered from mobile devices, raising significant privacy implications for users relying on encrypted messaging applications. Source: FBI Recovers Deleted Signal Messages Through iPhone Notifications
International Operation Identifies Over 20,000 Cryptocurrency Fraud Victims
An international law enforcement action led by the United Kingdom's National Crime Agency has identified over 20,000 victims of cryptocurrency fraud across Canada, the United Kingdom, and the United States. The operation has exposed the scale of organized cryptocurrency fraud networks utilizing approval phishing and other social engineering techniques to compromise victim accounts. Source: Over 20,000 crypto fraud victims identified in international crackdown
Today's incidents reflect a diverse threat landscape encompassing insider threats, organized cybercrime, hacktivist activities, and law enforcement forensic capabilities. Organizations across financial services, government, education, and critical infrastructure must strengthen access controls, implement advanced threat detection, and maintain robust incident response capabilities to address these evolving security challenges.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- INC RansomRansomware variant claiming responsibility for Morgan County, Georgia attack
academiedeparis.frVictim organization — Academie de Paris official domain
- CellebriteLaw enforcement forensic extraction tool used to recover deleted messages from seized devices
- approval phishingAttack method used to trick victims into granting wallet access via investment scams