Mastodon Digest
for the past
scorer
threshold
Posts

Today's story is the result of an ungodly amount of research, and I am very glad to finally be able to share it with you.

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever.

In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a “sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.”

The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old suspect’s real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP’s self-described spokesperson, and examines clues left behind by the TeamPCP leader that likely led to his undoing.

krebsonsecurity.com/2026/08/tw

Geai du matin

Geai

🇬🇧 Manchester Airports Group (magairports.com) a été victime d'une cyberattaque autour du 26 août 2026.

Le groupe Manchester Airports Group (MAG), propriétaire des aéroports de Manchester, Stansted et East Midlands, a subi une cyberattaque. Un tiers non autorisé a accédé à des données clients liées au stationnement, aux salons, aux réservations Fast Track et aux inscriptions au Wi-Fi. Les informations compromises incluent les adresses e-mail, les numéros de téléphone, les immatriculations de véhicules et les codes postaux. MAG a confirmé que les détails bancaires ou de paiement des clients n'ont pas été exposés. Les clients affectés sont contactés pour les avertir de la nécessité d'être vigilants face aux communications suspectes.

👉 the-european.eu/story-65173/cy

🚨🇬🇧 Loveelectric employee and driver dataset allegedly offered for sale on a cybercrime forum, 877K records claimed

Loveelectric, a UK-based electric vehicle leasing and employee benefits platform specializing in EV salary sacrifice schemes, is allegedly affected by a data exposure after a threat actor advertised a dataset containing approximately 877,000 records.

The actor claims the information was obtained in August 2026 through a zero-day vulnerability in a third-party system.

The advertised data includes:

• First and last names
• Email addresses
• Phone numbers
• Dates of birth
• Street addresses
• Cities and countries
• Postcodes
• National Insurance numbers
• Driving licence numbers
• Driving licence countries
• User IDs
• Quote IDs
• Weekly working hours
• Occupation information
• Titles

The listing includes a sample of the alleged dataset and is being offered for $600, with the price described as negotiable.

The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

Brian Krebs put together a good article that goes into depth on TeamPCP... "Two Alleged ‘TeamPCP’ Hackers Arrested in Australia"

krebsonsecurity.com/2026/08/tw

🚨🇺🇸 FLA Wireless dataset reposted on a cybercrime forum, 57K+ order records included

FLA Wireless, which operates under Florida-based Techy and provides phone accessories, pre-owned devices and device resale services, is the subject of a previously circulated leak that has been reposted on a cybercrime forum.

The actor states the material was originally posted by another threat actor and contains five CSV files covering orders, invoices, shipments, products and discount codes.

The advertised data includes:

• 57,120 order records
• 3,250 invoice records
• 2,065 shipment records
• 14,244 product records
• Customer names
• Email addresses
• Phone and mobile numbers
• Billing and shipping addresses
• Cities, states and ZIP codes
• Payment provider information
• Order and payment status
• Product and pricing information
• Shipping methods and tracking-related fields
• Customer and invoice identifiers
• Discount code information

The post includes samples from each portion of the alleged dataset and states the material is being reposted after previously being publicly available, rather than presented as a newly obtained breach.

The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

🚨 All DarkForums sites are suspended/down including knox's personal site.

darkforums[.]su
darkforums[.]ru
knox[.]hn

🚨🇦🇺 Australian authorities have arrested two alleged TeamPCP members in Perth: Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23.

TeamPCP has been linked to a series of npm supply chain compromises, including activity involving the Shai-Hulud worm.

Boosts

Always the first stop on any trip to Liverpool...

📍 The Museum of Liverpool - Designed by 3XN (Denmark) and opened in 2011.

📷 iPhone
💻 Photomator

#monochrome #architecture #photography #iphone #shotoniphone

A

Plug-in solar panels are now legal in Great Britain!

Hopefully this reduces the barrier to people getting solar at home.

gov.uk/government/news/househo