< ciso
brief />
Tag Banner

All news with #regulatory action tag

383 articles · page 2 of 20

Two Scattered Spider Members Sentenced for TfL Hack

🔒 Two leading members of the Scattered Spider collective were sentenced to five years and six months each for the August 2024 breach of Transport for London (TfL). The attack disrupted internal systems, affected services like Dial-a-Ride and contactless ticketing, and rendered 148 systems inoperable. Investigations led to arrests in September 2024, and authorities credited TfL's cooperation with enabling convictions.
read more →

US launches Gold Eagle to accelerate vulnerability response

🛡️ The US government has launched Gold Eagle, a program led by CISA, the Treasury and the Department of Defense to speed detection and remediation of software vulnerabilities. The initiative, previewed in Executive Order 14409, aims to centralize reporting and reduce duplicate scans, likely using the VINCE platform with public-private participation. Experts warn the plan may not address the core remediation capacity and coordination issues that limit patch deployment.
read more →

Spanish police dismantle €140M cyber fraud ring

🔍 Spanish police dismantled an industrial-scale cybercrime and money-laundering operation that stole €140 million via investment fraud and business email compromise. Four suspects were arrested across Spain, Portugal, and Panama after raids on multiple premises and an international operation with Interpol and Europol. Authorities seized digital devices, froze €3 million in proceeds, and identified hundreds of mule accounts used to launder funds.
read more →

DoD Suspends CMMC Phase II Pending Reform Review

🛡️ The US Department of Defense has paused the rollout of CMMC Phase II, originally due November 10, 2026, while it conducts a 60-day review to reduce compliance burdens and foster innovation in the defense industrial base. The DoD will rely on NIST SP 800-171 self-assessments and select government-led checks during the interim, and has formed a CMMC Reform Task Force to realign the program with acquisition priorities.
read more →

US Sanctions VPN and Malware Providers Linked to Ransomware

🔒 The U.S. Treasury's OFAC sanctioned virtual private network provider First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and a Belarusian cryptor vendor, Yegeniy Silayev, for enabling ransomware operations. Authorities say 1VPNS marketed no-logs service to cybercriminals and used false identities to obtain infrastructure, while Silayev sold tools to evade malware detection. The action follows a multinational takedown and server seizures tied to widespread cybercrime.
read more →

EU and UK announce joint cyber sanctions on Russia

🛡️ The EU and the UK issued coordinated sanctions targeting Russian individuals, entities, and intelligence units accused of orchestrating cyberattacks across Europe. Designations include GRU and FSB-linked officers, cybercriminals, and private firms alleged to recruit hackers and run malware operations. Officials cite sustained campaigns against government and critical infrastructure since 2010 and recent disruptive attempts in Poland. The measures follow broader EU proposals to strengthen cybersecurity and precede additional sanctions on foreign companies tied to attacks.
read more →

Google Cloud designated a UK critical third party

🛡️ Today Google Cloud announced that on July 10 the U.K. Treasury designated Google Cloud EMEA as a critical third party (CTP) to the U.K. financial sector. The designation acknowledges the systemic impact of services used by U.K. firms and places Google Cloud EMEA under direct oversight by the Bank of England, PRA, and FCA. Google Cloud commits to constructive engagement with regulators and to help customers meet operational resilience and third‑party risk requirements.
read more →

AWS designated a critical third party for UK finance

🔐 Amazon Web Services EMEA Sarl (AWS) has been designated a critical third party (CTP) to the UK financial sector under the CTP regime that came into force on January 1, 2025. The regime gives the Bank of England, PRA, and FCA powers to set requirements and exercise direct oversight over designated providers. AWS will self-assess its designated Systemic Third-Party Services (STPS) against the criteria and engage with regulators while supporting customers’ operational resilience.
read more →

Prisoner accused of stealing seized cryptocurrency

💼 A Bulgarian national, Rossen G. Iossifov, has been charged with removing $290,000 in government-seized cryptocurrency while serving a 121-month prison sentence for his role in laundering millions from U.S. fraud victims. He appeared in federal court in the Eastern District of Kentucky on counts of removal of property to prevent seizure and conspiracy to commit money laundering. Prosecutors allege he conspired in January 2024 to move funds through exchanges and mixers to evade seizure, and he faces up to 25 years if convicted.
read more →

EU extends controversial message scanning through 2028

🔎 Members of the European Parliament failed to block an interim measure that extends mass scanning of private communications through 2028. The motion to reject and an amendment requiring warrants both secured more votes in favor than against, but neither reached the necessary absolute majority due to many absences. The extension permits service providers to scan DMs and emails on platforms like Discord, Instagram, Gmail and iCloud without warrants, while end-to-end encrypted services remain unaffected. Supporters argue it combats child sexual abuse; critics warn it threatens privacy and could lead to false positives affecting enterprises.
read more →

Global Operation First Light 2026 Targets Cybercrime

🛡️ A global anti-fraud operation, Operation First Light 2026, ran from January 15 to April 30, 2026, coordinated by Interpol with support from regional partners and funding from China’s Ministry of Public Security. The crackdown targeted social engineering scams such as romance fraud and BEC, leading to over 5,800 arrests, identification of 15,606 suspects and interception of $293m in illicit assets. Actions included raids, freezing 31,014 bank accounts, seizing devices and using Interpol’s I-GRIP stop-payment mechanism.
read more →

Spain arrests suspected member of pro‑Russian hacktivists

🛡️ Spain's National Police arrested a man suspected of active roles in the pro‑Russian hacktivist groups CyberArmy of Russia Reborn and Z‑Pentest. Authorities say he provided logistical and operational support to a CARR-linked Ukrainian hacker and attempted to facilitate the hacker’s escape to Russia. Investigators seized computers and cryptocurrency devices during a March 2026 raid and froze wallets tied to stolen data sales. The suspect is under investigation for alleged links to terrorist group membership, glorification of terrorism, and computer damage.
read more →

France ends certification of non-quantum encryption

🔒 France’s cybersecurity agency ANSSI announced it will stop certifying security products that lack quantum-resistant encryption beginning in 2027, accelerating a national shift to post-quantum cryptography. ANSSI’s decision effectively forces French government bodies and critical operators to adopt quantum-safe solutions, as its approval is required for official use. The agency advised businesses to purchase only quantum-safe products by 2030 to ensure compliance and future-proofing.
read more →

CJEU upholds €4.1B antitrust fine against Google

📢 The Court of Justice of the European Union has dismissed Google's final appeal against a €4.1 billion antitrust fine related to Android. The ruling affirms that Google used pre-installation, anti-fragmentation agreements, and certain revenue-sharing deals to strengthen its dominant position and restrict competition. Google contests the decision, noting changes to its practices since 2018 and arguing that market realities have shifted.
read more →

FTC fines Amazon for withholding fraud victims’ records

🔎 The FTC says Amazon will pay a $2.25 million penalty after allegedly blocking identity-theft victims from obtaining transaction records required under Section 609(e) of the FCRA. The complaint claims Amazon customer service denied record requests citing "privacy" or "security," often delivered records after the 30-day statutory window, and sometimes refused law enforcement requests. The order requires Amazon to provide requested records within 30 days and notify affected consumers who previously requested records since April 2024.
read more →

Bill would require mandatory AI incident reporting

📝 A proposed AI Incident Reporting Act would obligate developers of designated high-capability models to report major safety and security incidents to the Commerce Department. Reports would be required within seven days of discovery, with 48-hour notifications to congressional leaders for imminent or ongoing serious harm. The bill tasks the Secretary of Commerce with defining capability thresholds and grants the department investigative and enforcement powers, including fines up to $2 million per violation.
read more →

Ten years of the GDPR: mixed outcomes and lessons

📄 Ten years after the GDPR came into force, data protection is far more established across Europe and beyond, raising consumer awareness and making privacy a competitive factor for businesses. Record fines against major tech firms underline enforcement seriousness, even as many penalties remain disputed. Companies increasingly view the regulation as burdensome and legally uncertain, complicating innovation, notably in AI development.
read more →

AI Liability and the Publisher–Carrier Distinction

📰 The German court found Google liable for AI-generated search summaries, rejecting defenses that users should verify AI output themselves. This ruling highlights the historical distinction between carriers and publishers and argues that AI summaries act like editorial content. Past cases, like Air Canada’s chatbot ruling, reinforce that organizations are responsible for their AI agents. The decision could force companies to improve AI accuracy or curtail certain commercial uses.
read more →

International takedown of Amadey and StealC networks

🛡️ A multinational law enforcement operation, coordinated with private-sector partners such as Bitdefender, ESET, and Microsoft, dismantled infrastructure powering the Amadey and StealC malware ecosystems. Authorities identified and restricted over $47 million in criminal cryptocurrency, recovered 27 million stolen credentials, and dismantled hundreds of servers and domains. The action disrupted loader-and-stealer chains used to fuel ransomware and fraud.
read more →

DOJ Seizes Cloud Account Linked to HuiOne Group

📰 The U.S. Department of Justice announced the seizure of a cloud computing account used by subsidiaries of Cambodia-based HuiOne Group, as the Treasury sanctioned individuals and entities tied to Prince Group. The account hosted backend infrastructure for illicit marketplaces, including HuiOne Guarantee, which facilitated large-scale crypto fraud, money laundering services, and the sale of crimeware and exploitative tools. Authorities say these platforms enabled conversion of stolen cryptocurrency into the legitimate banking sector and supported human trafficking and violent control measures at scam compounds.
read more →