jsonify-logo-light Designer: Matt Farley Open in Jsonify

I want to get continuous structured data on emerging fraud typologies, attack vectors, and associated threat intelligence from global cybersecurity forums, dark web marketplaces, and financial crime regulatory filings.

Gain instant insights into emerging fraud trends and attack vectors — automated intelligence from global sources, no manual effort needed

A saved example of what you can collect and monitor with Jsonify. Create your own version in Jsonify.

Build this in JsonifyYour original goal is prefilled.

Goal

I want to get continuous structured data on emerging fraud typologies, attack vectors, and associated threat intelligence from global cybersecurity forums, dark web marketplaces, and financial crime regulatory filings.

Source coverage

Sample data

Illustrative sample data from the original configuration, not live or verified results.

idSourceTitleSummaryThreat_TypeTTPsIndicatorsConfidencePublishedRegionSeveritySource_Type
1krebsonsecurity.comNew ATM Malware Variant Targets EMV TerminalsResearchers observed a new ATM skimmer malware that harvests EMV track 2 data and PINs via overlay injectionATM malwareEMV overlay, memory scraping, POS overlay skimmer["md5:9f1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d", "C2:atm-update[.]onion"]High2026-01-31GlobalCriticalInvestigation Article
2darkreading.comPhishing-as-a-Service Market Expands with Low-Cost SaaS KitsOperators selling turnkey phishing kits with auto-template builders and credential harvesting dashboardsPhishing-as-a-ServiceSaaS phishing kits, credential harvesting, template marketplace["phish-kit pricing:$49/month", "Payment: BTC/Tether"]Medium2026-02-01GlobalHighMarket Analysis
3threatpost.comNew Ransomware Strain 'GlassDoor' Encrypts Cloud BackupsGlassDoor targets misconfigured cloud backup APIs and exfiltrates before encryptionRansomwareAPI abuse, exfiltration, multi-stage encryption["ext: .gz.enc", ".onion leak site: glassdoor-leaks[.]onion"]High2026-02-02North America, EMEACriticalThreat Advisory
4cyberscoop.comCredential Stuffing Campaign Hits Financial InstitutionsLarge-scale credential stuffing campaign leveraging breached combo lists and residential proxiesCredential stuffingcombination lists, proxy chaining, account takeover["login-attempt-rate: 2500/hr", "IPs: rotating residential pools"]Medium2026-02-02GlobalHighNews Report
5bloomberg.comFraud Rings Exploit Faster Payments NetworksOrganized fraud groups exploiting instant payment rails for mule layering and rapid cash-outsPayment fraudinstant rail abuse, mule recruitment, synthetic IDs["suspicious-volume:$1.2M in 48h", "Payment channel: Faster PayNet"]Medium2026-01-30APAC, EMEAHighInvestigative Report
6fincen.govAdvisory: Emerging Trade-Based Money Laundering TechniquesFinCEN warns about trade invoice manipulation using shell companies and crypto-on-rampsTrade-based money launderinginvoice falsification, shell firms, crypto conversion["#SARs flagged: increase 18% Q4 2025", "Common commodities: electronics, textiles"]High2026-01-29US InternationalHighGovernment Advisory
7sans.orgBlueKeep 2.0 Proof-of-Concept Sparks Patch RushPoC exploit demonstrates remote RCE against legacy RDP stacks prompting emergency patchesRemote code executionRDP exploit, exploit chaining, wormable payload["CVE: pending CVE-2026-XXXXX", "Exploit repo: github[.]com/evil/bluekeep2"]High2026-02-01GlobalCriticalResearch Paper
8malwarebytes.comAndroid Dropper Distributes Multiple Banking TrojansNew Android dropper sideloads modular banking trojans after phishing SMS promptsMobile banking trojanSMS phishing, sideloading, accessibility abuse["package: com.payhelper.upd", "PlayStore: none (sideload)"]High2026-01-31EMEA, LATAMHighThreat Research
9us-cert.cisa.govAA22-XX: Mitigation for Supply Chain Compromise via CI/CD PipelinesCISA guidance for securing build artifacts and detecting pipeline tamperingSupply chain compromiseCI/CD artifact poisoning, compromised runners, malicious dependencies["IOC: altered checksum patterns in build artifacts", "Mitigation: sign artifacts, pipeline integrity checks"]High2026-02-02US GlobalHighAdvisory
10hackread.comDark Web Forum Offers 'Bank Bot' for Automated FraudForum thread selling an automated bot to test and cash out fraudulently opened bank accountsAutomated fraud toolingbot automation, mule account creation, SIM swap support["Price: $350/month", "Support: Telegram channel t[.]me/bankbot-support"]Medium2026-02-01GlobalHighDark Web Watch
11cyberscoop.comExchange Vulnerability Leads to Hot Wallet TheftHot wallet private keys exfiltrated after exploiting a third-party analytics pluginCryptocurrency theftplugin compromise, private key exfiltration, chain hopping["Stolen: 4,200 ETH (~$7.8M)", "Affected: exchange-xyz.com"]High2026-01-30GlobalCriticalIncident Report
12darkreading.comE-commerce Fraudsters Use AI-Generated Synthetic IDsThreat actors adopt generative tools to create high-quality synthetic identity profiles for credit fraudSynthetic identity fraudAI-generated faces, synthetic SSNs, layered mule networks["False KYC pass rate: 32% in testing", "Tools: generative face + deepfake voices"]Medium2026-01-31US, EMEAHighFeature Story
13krebsonsecurity.comSIM Swap Wave Targets High-Value Crypto HoldersCoordinated SIM swap attacks enabling account takeovers on exchanges and custodial servicesSIM swapSIM porting, social engineering, SS7 probing["Victims: 12 high-net-worth individuals", "Losses: ~$5.3M"]High2026-02-02GlobalCriticalVictim Report
14threatpost.comIoT Botnet 'Furnace' Repurposes Devices for DDoS and Crypto-miningFurnace uses zero-day in smart thermostats to recruit devices into a hybrid botnetIoT botnetzero-day exploit, cryptomining, DDoS amplification["Exploit: thermostatech CVE-2026-1001", "Ports scanned: 5555, 7547"]Medium2026-01-30North AmericaHighTechnical Analysis
15bloomberg.comCard-Not-Present Fraud Surges Ahead of Tax SeasonRetailers and payment processors report spike in CNP fraud using carding servicesCard-not-present fraudcarding shops, BIN attack, automated checkout bots["Losses: estimated $120M Q4 2025", "Top method: scripted checkout bots"]Medium2026-02-01USHighBusiness News
16fincen.govNotice: Increased SAR Filings Related to Crypto-MixersFinCEN notes uptick in suspicious activity reports involving centralized mixing services and tumblersCrypto mixingchain hopping, centralized mixers, OTC exchangers["#SARs increase: 42% YoY for mixers", "Common rails: ERC-20, Tornado-like services"]High2026-02-02US InternationalHighRegulatory Notice
17malwarebytes.comBrowser Extension Malware Steals 2FA CookiesMalicious Chrome extension exfiltrates session cookies and 2FA tokens to bypass MFAExtension malwarecookie theft, persistent persistence, exfil to cloud storage["extension id: jkfhdgpllmno4321", "Exfil endpoint: storage.googleapis[.]com/malware-lair"]High2026-02-01GlobalCriticalThreat Report
18us-cert.cisa.govAlert: Iranian-linked APT Observed Targeting Financial SectorCISA and partners track an APT conducting credential harvesting and spear-phishing against banksNation-state APTspear-phishing, credential harvesting, living-off-the-land binaries["malicious domains: securelogin-update[.]ir", "Malware: custom .NET loader"]High2026-01-29US, MEACriticalJoint Advisory
19hackread.comMarketplace Listing: Fullz Packs with Verified DOBs and SSNsVendor selling curated fullz bundles claiming high verification rates for KYC bypassIdentity fraud marketplacefullz distribution, verified DOBs, identity verification bypass["Price: $200 per 100 fullz", "Contact: X account @fullz_dealer"]Medium2026-01-30GlobalHighDark Market Listing
20cyberscoop.comInsider Threat: Contractor Steals Customer Data for SaleEx-contractor exfiltrated customer PII from fintech startup and listed it on private forumInsider data theftunauthorized export, encrypted exfil, forum sale["Records: 78k user profiles", "Sale price: $12k"]High2026-02-02USHighBreach Report
21darkreading.comCredential Leasing Service Offers Time-limited Bank AccessService rents out bank logins with rotating IPs and built-in cashout workflowsCredential leasingtimed credential access, proxy rotation, automated cashout modules["Rental rates: $20/hour for USD 10k-limit accounts", "Delivery: Telegram bot"]Medium2026-01-31GlobalHighInvestigative Feature
22krebsonsecurity.comCard Skimming Rings Upgrade to Bluetooth-enabled PadsSkimming gangs deploying Bluetooth-enabled overlay devices transmits stolen data in real timeCard skimmingBluetooth skimmer, overlay devices, remote data exfiltration["Device cost: $180/unit", "Bluetooth MAC patterns observed at multiple ATMs"]High2026-01-30EMEA, LATAMHighField Report
23threatpost.comSupply Chain Malware Found in Build Dependency of Popular SDKMalicious code introduced via compromised NPM package affecting thousands of appsSoftware supply chaindependency poisoning, exfil via telemetry, targeted rollout["package: sdk-logger v3.2.1", "Downloads impacted: ~120k projects"]High2026-02-02GlobalCriticalTechnical Advisory
24bloomberg.comOrganized Crime Funnels Illicit Proceeds Through Prepaid Cards and P2P AppsCriminal networks increasingly use prepaid cards and P2P payment apps for layeringMoney launderingprepaid card loading, P2P laundering loops, mule network["Typical load per mule:$2k-$10k", "Preferred apps: PayLink, QuickSend"]Medium2026-01-29GlobalHighBusiness Intelligence
25fincen.govAdvisory: Red Flags for Trade-Based Crypto LaunderingGuidance on indicators such as over/under invoicing and mismatched shipping documents tied to crypto brokersTrade-based crypto launderinginvoice mismatch, false bills of lading, crypto gateways integration["Red flags: frequent USD invoices to low-risk countries", "Published templates: included"]High2026-01-30US InternationalHighRegulatory Guidance
26malwarebytes.comMacOS Adware Campaign Uses Fake Updaters to Deploy BackdoorsAdware masquerading as legitimate updaters installs persistent backdoor componentsMacOS backdoorfake updater, notarization abuse, persistence via launch agents["Bundle id: com.apple.update.helper", "Installer SHA256: a1b2c3d4e5f67890..."]High2026-02-01GlobalHighMalware Analysis
27us-cert.cisa.govMitigation Bulletin: Hardening Public-Facing Web Apps Against SSRFRecommendations to detect and block SSRF abuse used to pivot to internal servicesSSRF exploitationServer-Side Request Forgery, internal port scanning, metadata API access["Observed attempts: 1200 SSRF probes/day", "Mitigation: strict allowlist, outbound filtering"]High2026-02-02GlobalHighSecurity Bulletin
28hackread.comVendor Offers 'Fraud-as-a-Service' with Compliance Evasion GuidesOperator sells end-to-end fraud packages with guides on evading AML/KYC controlsFraud-as-a-Servicecompliance evasion, mule automation, fake docs["Package price: $2,500 one-time", "Delivery: encrypted drop on forum"]Medium2026-01-31GlobalCriticalMarketplace Intelligence

Insights and analytics

Change notifications

Integrations and delivery

Make this your own

Start with this goal in Jsonify, then choose the sources and data you need.

Build this in Jsonify