I want to get continuous structured data on emerging fraud typologies, attack vectors, and associated threat intelligence from global cybersecurity forums, dark web marketplaces, and financial crime regulatory filings.
Gain instant insights into emerging fraud trends and attack vectors — automated intelligence from global sources, no manual effort needed
A saved example of what you can collect and monitor with Jsonify. Create your own version in Jsonify.
Build this in JsonifyYour original goal is prefilled.
Goal
I want to get continuous structured data on emerging fraud typologies, attack vectors, and associated threat intelligence from global cybersecurity forums, dark web marketplaces, and financial crime regulatory filings.
Source coverage
- cyberscoop.com
- darkreading.com
- krebsonsecurity.com
- threatpost.com
- bloomberg.com
- finextra.com
- cybersecurityventures.com
- malwarebytes.com
- us-cert.cisa.gov
- sans.org
- fincen.gov
- hackread.com
Sample data
Illustrative sample data from the original configuration, not live or verified results.
| id | Source | Title | Summary | Threat_Type | TTPs | Indicators | Confidence | Published | Region | Severity | Source_Type |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 | krebsonsecurity.com | New ATM Malware Variant Targets EMV Terminals | Researchers observed a new ATM skimmer malware that harvests EMV track 2 data and PINs via overlay injection | ATM malware | EMV overlay, memory scraping, POS overlay skimmer | ["md5:9f1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d", "C2:atm-update[.]onion"] | High | 2026-01-31 | Global | Critical | Investigation Article |
| 2 | darkreading.com | Phishing-as-a-Service Market Expands with Low-Cost SaaS Kits | Operators selling turnkey phishing kits with auto-template builders and credential harvesting dashboards | Phishing-as-a-Service | SaaS phishing kits, credential harvesting, template marketplace | ["phish-kit pricing:$49/month", "Payment: BTC/Tether"] | Medium | 2026-02-01 | Global | High | Market Analysis |
| 3 | threatpost.com | New Ransomware Strain 'GlassDoor' Encrypts Cloud Backups | GlassDoor targets misconfigured cloud backup APIs and exfiltrates before encryption | Ransomware | API abuse, exfiltration, multi-stage encryption | ["ext: .gz.enc", ".onion leak site: glassdoor-leaks[.]onion"] | High | 2026-02-02 | North America, EMEA | Critical | Threat Advisory |
| 4 | cyberscoop.com | Credential Stuffing Campaign Hits Financial Institutions | Large-scale credential stuffing campaign leveraging breached combo lists and residential proxies | Credential stuffing | combination lists, proxy chaining, account takeover | ["login-attempt-rate: 2500/hr", "IPs: rotating residential pools"] | Medium | 2026-02-02 | Global | High | News Report |
| 5 | bloomberg.com | Fraud Rings Exploit Faster Payments Networks | Organized fraud groups exploiting instant payment rails for mule layering and rapid cash-outs | Payment fraud | instant rail abuse, mule recruitment, synthetic IDs | ["suspicious-volume:$1.2M in 48h", "Payment channel: Faster PayNet"] | Medium | 2026-01-30 | APAC, EMEA | High | Investigative Report |
| 6 | fincen.gov | Advisory: Emerging Trade-Based Money Laundering Techniques | FinCEN warns about trade invoice manipulation using shell companies and crypto-on-ramps | Trade-based money laundering | invoice falsification, shell firms, crypto conversion | ["#SARs flagged: increase 18% Q4 2025", "Common commodities: electronics, textiles"] | High | 2026-01-29 | US International | High | Government Advisory |
| 7 | sans.org | BlueKeep 2.0 Proof-of-Concept Sparks Patch Rush | PoC exploit demonstrates remote RCE against legacy RDP stacks prompting emergency patches | Remote code execution | RDP exploit, exploit chaining, wormable payload | ["CVE: pending CVE-2026-XXXXX", "Exploit repo: github[.]com/evil/bluekeep2"] | High | 2026-02-01 | Global | Critical | Research Paper |
| 8 | malwarebytes.com | Android Dropper Distributes Multiple Banking Trojans | New Android dropper sideloads modular banking trojans after phishing SMS prompts | Mobile banking trojan | SMS phishing, sideloading, accessibility abuse | ["package: com.payhelper.upd", "PlayStore: none (sideload)"] | High | 2026-01-31 | EMEA, LATAM | High | Threat Research |
| 9 | us-cert.cisa.gov | AA22-XX: Mitigation for Supply Chain Compromise via CI/CD Pipelines | CISA guidance for securing build artifacts and detecting pipeline tampering | Supply chain compromise | CI/CD artifact poisoning, compromised runners, malicious dependencies | ["IOC: altered checksum patterns in build artifacts", "Mitigation: sign artifacts, pipeline integrity checks"] | High | 2026-02-02 | US Global | High | Advisory |
| 10 | hackread.com | Dark Web Forum Offers 'Bank Bot' for Automated Fraud | Forum thread selling an automated bot to test and cash out fraudulently opened bank accounts | Automated fraud tooling | bot automation, mule account creation, SIM swap support | ["Price: $350/month", "Support: Telegram channel t[.]me/bankbot-support"] | Medium | 2026-02-01 | Global | High | Dark Web Watch |
| 11 | cyberscoop.com | Exchange Vulnerability Leads to Hot Wallet Theft | Hot wallet private keys exfiltrated after exploiting a third-party analytics plugin | Cryptocurrency theft | plugin compromise, private key exfiltration, chain hopping | ["Stolen: 4,200 ETH (~$7.8M)", "Affected: exchange-xyz.com"] | High | 2026-01-30 | Global | Critical | Incident Report |
| 12 | darkreading.com | E-commerce Fraudsters Use AI-Generated Synthetic IDs | Threat actors adopt generative tools to create high-quality synthetic identity profiles for credit fraud | Synthetic identity fraud | AI-generated faces, synthetic SSNs, layered mule networks | ["False KYC pass rate: 32% in testing", "Tools: generative face + deepfake voices"] | Medium | 2026-01-31 | US, EMEA | High | Feature Story |
| 13 | krebsonsecurity.com | SIM Swap Wave Targets High-Value Crypto Holders | Coordinated SIM swap attacks enabling account takeovers on exchanges and custodial services | SIM swap | SIM porting, social engineering, SS7 probing | ["Victims: 12 high-net-worth individuals", "Losses: ~$5.3M"] | High | 2026-02-02 | Global | Critical | Victim Report |
| 14 | threatpost.com | IoT Botnet 'Furnace' Repurposes Devices for DDoS and Crypto-mining | Furnace uses zero-day in smart thermostats to recruit devices into a hybrid botnet | IoT botnet | zero-day exploit, cryptomining, DDoS amplification | ["Exploit: thermostatech CVE-2026-1001", "Ports scanned: 5555, 7547"] | Medium | 2026-01-30 | North America | High | Technical Analysis |
| 15 | bloomberg.com | Card-Not-Present Fraud Surges Ahead of Tax Season | Retailers and payment processors report spike in CNP fraud using carding services | Card-not-present fraud | carding shops, BIN attack, automated checkout bots | ["Losses: estimated $120M Q4 2025", "Top method: scripted checkout bots"] | Medium | 2026-02-01 | US | High | Business News |
| 16 | fincen.gov | Notice: Increased SAR Filings Related to Crypto-Mixers | FinCEN notes uptick in suspicious activity reports involving centralized mixing services and tumblers | Crypto mixing | chain hopping, centralized mixers, OTC exchangers | ["#SARs increase: 42% YoY for mixers", "Common rails: ERC-20, Tornado-like services"] | High | 2026-02-02 | US International | High | Regulatory Notice |
| 17 | malwarebytes.com | Browser Extension Malware Steals 2FA Cookies | Malicious Chrome extension exfiltrates session cookies and 2FA tokens to bypass MFA | Extension malware | cookie theft, persistent persistence, exfil to cloud storage | ["extension id: jkfhdgpllmno4321", "Exfil endpoint: storage.googleapis[.]com/malware-lair"] | High | 2026-02-01 | Global | Critical | Threat Report |
| 18 | us-cert.cisa.gov | Alert: Iranian-linked APT Observed Targeting Financial Sector | CISA and partners track an APT conducting credential harvesting and spear-phishing against banks | Nation-state APT | spear-phishing, credential harvesting, living-off-the-land binaries | ["malicious domains: securelogin-update[.]ir", "Malware: custom .NET loader"] | High | 2026-01-29 | US, MEA | Critical | Joint Advisory |
| 19 | hackread.com | Marketplace Listing: Fullz Packs with Verified DOBs and SSNs | Vendor selling curated fullz bundles claiming high verification rates for KYC bypass | Identity fraud marketplace | fullz distribution, verified DOBs, identity verification bypass | ["Price: $200 per 100 fullz", "Contact: X account @fullz_dealer"] | Medium | 2026-01-30 | Global | High | Dark Market Listing |
| 20 | cyberscoop.com | Insider Threat: Contractor Steals Customer Data for Sale | Ex-contractor exfiltrated customer PII from fintech startup and listed it on private forum | Insider data theft | unauthorized export, encrypted exfil, forum sale | ["Records: 78k user profiles", "Sale price: $12k"] | High | 2026-02-02 | US | High | Breach Report |
| 21 | darkreading.com | Credential Leasing Service Offers Time-limited Bank Access | Service rents out bank logins with rotating IPs and built-in cashout workflows | Credential leasing | timed credential access, proxy rotation, automated cashout modules | ["Rental rates: $20/hour for USD 10k-limit accounts", "Delivery: Telegram bot"] | Medium | 2026-01-31 | Global | High | Investigative Feature |
| 22 | krebsonsecurity.com | Card Skimming Rings Upgrade to Bluetooth-enabled Pads | Skimming gangs deploying Bluetooth-enabled overlay devices transmits stolen data in real time | Card skimming | Bluetooth skimmer, overlay devices, remote data exfiltration | ["Device cost: $180/unit", "Bluetooth MAC patterns observed at multiple ATMs"] | High | 2026-01-30 | EMEA, LATAM | High | Field Report |
| 23 | threatpost.com | Supply Chain Malware Found in Build Dependency of Popular SDK | Malicious code introduced via compromised NPM package affecting thousands of apps | Software supply chain | dependency poisoning, exfil via telemetry, targeted rollout | ["package: sdk-logger v3.2.1", "Downloads impacted: ~120k projects"] | High | 2026-02-02 | Global | Critical | Technical Advisory |
| 24 | bloomberg.com | Organized Crime Funnels Illicit Proceeds Through Prepaid Cards and P2P Apps | Criminal networks increasingly use prepaid cards and P2P payment apps for layering | Money laundering | prepaid card loading, P2P laundering loops, mule network | ["Typical load per mule:$2k-$10k", "Preferred apps: PayLink, QuickSend"] | Medium | 2026-01-29 | Global | High | Business Intelligence |
| 25 | fincen.gov | Advisory: Red Flags for Trade-Based Crypto Laundering | Guidance on indicators such as over/under invoicing and mismatched shipping documents tied to crypto brokers | Trade-based crypto laundering | invoice mismatch, false bills of lading, crypto gateways integration | ["Red flags: frequent USD invoices to low-risk countries", "Published templates: included"] | High | 2026-01-30 | US International | High | Regulatory Guidance |
| 26 | malwarebytes.com | MacOS Adware Campaign Uses Fake Updaters to Deploy Backdoors | Adware masquerading as legitimate updaters installs persistent backdoor components | MacOS backdoor | fake updater, notarization abuse, persistence via launch agents | ["Bundle id: com.apple.update.helper", "Installer SHA256: a1b2c3d4e5f67890..."] | High | 2026-02-01 | Global | High | Malware Analysis |
| 27 | us-cert.cisa.gov | Mitigation Bulletin: Hardening Public-Facing Web Apps Against SSRF | Recommendations to detect and block SSRF abuse used to pivot to internal services | SSRF exploitation | Server-Side Request Forgery, internal port scanning, metadata API access | ["Observed attempts: 1200 SSRF probes/day", "Mitigation: strict allowlist, outbound filtering"] | High | 2026-02-02 | Global | High | Security Bulletin |
| 28 | hackread.com | Vendor Offers 'Fraud-as-a-Service' with Compliance Evasion Guides | Operator sells end-to-end fraud packages with guides on evading AML/KYC controls | Fraud-as-a-Service | compliance evasion, mule automation, fake docs | ["Package price: $2,500 one-time", "Delivery: encrypted drop on forum"] | Medium | 2026-01-31 | Global | Critical | Marketplace Intelligence |
Insights and analytics
- Total Fraud Reports Monitored (metric)
- Emerging Fraud Typologies Over Time (line)
- Top Attack Vectors Identified (horizontal_bar)
- Distribution of Threat Sources (donut)
- Recent Threat Intelligence Reports (table)
- Volume of Regulatory Filings Over Time (area)
- Fraud Incidents by Region (bar)
- New Attack Patterns This Month (metric)
- Key Observations from Cybersecurity Forums (insights)
- Top Dark Web Marketplaces for Fraud (table)
- Trends in Financial Crime Regulatory Actions (line)
- Types of Fraud by Frequency (donut)
Change notifications
- New Fraud Typology Detected — recently reported in forums cyberscoop.com
- Emerging Attack Vector Found — new method identified krebsonsecurity.com
- Threat Intelligence Update — latest intelligence available threatpost.com
- New Regulatory Filing — from FinCEN available fincen.gov
- Dark Web Listing Updated — new listings found darkreading.com
Integrations and delivery
- api
- snowflake
- slack
Make this your own
Start with this goal in Jsonify, then choose the sources and data you need.
Build this in Jsonify