Home › Cyber News › Biggest scams and hacks
CYBER NEWS · ROUND-UP

The biggest scams and hacks of the last 3 years, by type of attack

Ransomware, deepfakes, fake logins, SIM swaps and more. For each one: how it was done, what was taken, who was behind it, and the one or two habits that would have helped.

Published October 9, 2026 · Written and maintained by the cyberhygiene.tools team

In this article

  • The short version
  • 1. Ransomware: Change Healthcare (2024)
  • 2. Supply-chain zero-day: the MOVEit mass hack (2023)
  • 3. Deepfake video call: Arup in Hong Kong (2024)
  • 4. Fake Microsoft and Amazon messages: Russian phishing against Ukraine (2024 to 2025)
  • 5. Password manager breach: LastPass and its UK users (2022, fined 2025)
  • 6. Crypto theft through a supplier: Bybit (2025)
  • 7. Scam compounds and "pig butchering": Prince Group (2025)
  • 8. SIM swap: the hacked SEC account on X (2024)
  • 9. Bank breach: Shinhan Bank, South Korea (2026)
  • 10. Counterfeit money: North Korea's fake US$100 bills (an older case)
  • Sources

The short version

Most of the biggest losses since 2023 did not need clever new technology. They came from a stolen password on a system without two-factor sign-in, a fake login page, a convincing video call, or a phone number taken over at a shop counter. The ten cases below are grouped by type of attack. Facts are taken from official statements and reputable reporting, and anything that is only claimed or reported is labelled that way.

1. Ransomware: Change Healthcare (2024)

Type of attack: Ransomware with data theft.

How they did it

  1. Attackers logged in to a Change Healthcare remote-access (Citrix) portal on February 12, 2024 using stolen login details.
  2. UnitedHealth's chief executive told US senators: "The portal did not have multi-factor authentication."
  3. Nine days later, on February 21, 2024, they set off ransomware that locked Change's systems.

What was stolen

Health and personal data. On July 31, 2025 Change Healthcare told the US health department's Office for Civil Rights that about 192.7 million people were affected. UnitedHealth confirmed it paid a US$22 million ransom.

Who was behind it

UnitedHealth's chief executive named the criminal group "ALPHV" in his testimony. That is the company's attribution, not a government one.

What this means for you
  • One password with no second step was enough. Turn on two-factor authentication everywhere it is offered, starting with email.
  • If a company you use is breached, expect scam messages that quote your real details.

2. Supply-chain zero-day: the MOVEit mass hack (2023)

Type of attack: Mass exploitation of an unknown flaw (a "zero-day") in widely used file-transfer software.

How they did it

  1. From May 27, 2023 the Cl0p gang used a SQL injection flaw (CVE-2023-34362) in internet-facing MOVEit Transfer servers.
  2. They planted a hidden backdoor page called LEMURLOOT, disguised as a normal file named "human2.aspx".
  3. They used it to copy data out of the MOVEit databases, then threatened to publish it unless victims paid.

What was stolen

Files held by thousands of organisations, from governments to payroll firms. The security company Emsisoft counted 2,773 organisations and about 95.8 million people affected (as of June 28, 2024), noting some people were probably counted twice.

Who was behind it

The US cyber agency CISA and the FBI named the "CL0P Ransomware Gang, also known as TA505".

What this means for you
  • You cannot patch a company's server, but you can limit what one breach exposes: use a different password for every account.
  • Be wary of "your data was in a breach" messages that ask you to click or pay. Go to the company's own website instead.

3. Deepfake video call: Arup in Hong Kong (2024)

Type of attack: Deepfake "boss" fraud.

How they did it

  1. In January 2024 a finance employee at the engineering firm Arup in Hong Kong received a message, apparently from the company's UK chief financial officer, about a "confidential transaction".
  2. He joined a video call where the finance chief and other colleagues looked and sounded real. Hong Kong police said the fraudsters likely downloaded videos of real meetings and used AI to fake the voices.
  3. Reassured, he made 15 transfers into 5 Hong Kong bank accounts over about a week. The fraud was found when he checked with head office.

What was stolen

HK$200 million, about US$25.6 million. Arup confirmed "fake voices and images were used" and said none of its internal systems were compromised.

Who was behind it

Unknown. No arrests had been reported as of May 2024.

What this means for you
  • Seeing and hearing someone on a call is no longer proof. Check any urgent money request through a number or channel you already trust.
  • Agree a check word with family members for emergencies.

4. Fake Microsoft and Amazon messages: Russian phishing against Ukraine (2024 to 2025)

Type of attack: Spear-phishing (targeted fake messages) to steal logins and take remote control.

How they did it

  1. From about August 2024, emails were sent from real organisations that had already been hacked, so they looked trustworthy.
  2. The messages talked about "integration" with Amazon and Microsoft. Amazon says some sending domains were made to look like Amazon Web Services (AWS) addresses.
  3. Each email carried a Remote Desktop (.rdp) file. Opening it connected the victim's computer to the attackers' server, exposing drives, the clipboard and more, and letting them install malware.
  4. In a separate campaign in April 2025, a Russia-affiliated group Microsoft calls Void Blizzard used a fake Microsoft login page with a misspelt address, reached through a QR code in a PDF.

What was stolen

Windows login details and access to computers. Microsoft said the RDP campaign hit "thousands" of targets in more than 100 organisations. Ukraine's government cyber team, CERT-UA, warned that Ukrainian public authorities, major industries and military units were targeted.

Who was behind it

Amazon and Microsoft named APT29 (Midnight Blizzard), which the US and UK governments attribute to Russia's Foreign Intelligence Service (SVR). Amazon seized the fake AWS domains on October 24, 2024.

What this means for you
  • Never open an attachment you were not expecting, even from someone you know. Their account may have been taken over.
  • Type the web address for Microsoft or Amazon yourself instead of clicking a link or scanning a QR code in a message.

5. Password manager breach: LastPass and its UK users (2022, fined 2025)

Type of attack: Breach of a password manager through staff devices.

How they did it

  1. In August 2022 an attacker broke into a developer's work laptop and took part of LastPass's source code.
  2. The attacker then targeted a senior engineer's home computer through a flaw in a third-party streaming app, and a keylogger captured the engineer's master password.
  3. With that, the attacker got the keys needed to download LastPass's customer vault backups.

What was stolen

Customer vault backups and account details. The UK Information Commissioner's Office (ICO) said up to 1.6 million UK users were affected and fined LastPass UK £1.2 million on December 11, 2025. The ICO says there is no evidence passwords were decrypted, because master passwords are never shared with LastPass. Researchers have since traced more than US$35 million in crypto thefts they link to the breach, but say they cannot prove the connection.

Who was behind it

No official attribution for the 2022 break-in. The blockchain firm TRM Labs says the later crypto thefts are consistent with Russian cybercriminals.

What this means for you
  • A password manager is still far safer than reusing passwords. Protect it with a long, unique master passphrase and two-factor authentication.
  • Never store crypto wallet recovery phrases in a password manager or anywhere online.

6. Crypto theft through a supplier: Bybit (2025)

Type of attack: Supply-chain attack on a crypto wallet service.

How they did it

  1. Attackers compromised the laptop of a developer at Safe{Wallet}, a wallet service the exchange Bybit used.
  2. They used it to alter the Safe{Wallet} screen Bybit's staff relied on.
  3. On or about February 21, 2025 Bybit's staff approved what looked like a normal transfer. It actually handed control of Bybit's main Ethereum cold wallet to the attackers, who emptied it.

What was stolen

About US$1.5 billion in cryptocurrency, the largest crypto theft on record at the time.

Who was behind it

On February 26, 2025 the FBI said North Korea was responsible, calling the activity "TraderTraitor". Read our full Bybit story.

What this means for you
  • Keep larger crypto amounts in a hardware wallet you control, not all on one exchange.
  • Before approving any transaction, check the details on a second device or screen if you can.

7. Scam compounds and "pig butchering": Prince Group (2025)

Type of attack: Investment fraud run from forced-labour scam compounds.

How they did it

  1. Workers were lured to Cambodia with fake job offers, then held in walled compounds where their passports and phones were taken.
  2. Using "phone farms" of thousands of phones, they messaged victims on social media and messaging apps.
  3. Over weeks or months they built trust, then talked victims into "investing" in fake crypto platforms. The money was stolen.

What was stolen

Billions of dollars from victims worldwide. On October 14, 2025 the US Justice Department announced the forfeiture of about 127,271 bitcoin, worth about US$15 billion at the time, the largest forfeiture action in its history. The US Treasury says Americans lost at least US$10 billion to Southeast Asia-based scams in 2024.

Who was behind it

US prosecutors charged Prince Group chairman Chen Zhi with wire fraud and money laundering conspiracy. These are charges, not convictions. The US and UK sanctioned the group the same day. Cambodia says Chen Zhi was arrested on January 6, 2026 and sent to China.

What this means for you
  • A stranger who becomes a friend online and then talks about investing is the classic pattern. Stop there.
  • Never move money to a platform someone else recommended. Check it against your country's official regulator first.

8. SIM swap: the hacked SEC account on X (2024)

Type of attack: SIM swap (taking over someone's phone number).

How they did it

  1. Criminals got the personal details of the person whose phone number was linked to the US Securities and Exchange Commission's X account.
  2. On January 9, 2024 one of them, Eric Council Jr., used a fake ID in that person's name at a phone shop in Alabama to get a new SIM card for the number.
  3. With the number, the group took over the SEC's X account and posted a fake announcement about bitcoin funds.

What was stolen

Control of an official government account. The fake post pushed the bitcoin price up by more than US$1,000, before it fell by more than US$2,000 once the post was corrected. Council was paid about US$50,000 in bitcoin.

Who was behind it

Council pleaded guilty and was sentenced on May 16, 2025 to 14 months in prison. His co-conspirators have not been publicly named.

What this means for you
  • Ask your mobile provider for a port-out PIN or account lock.
  • Use an authenticator app or passkey instead of text-message codes for important accounts.

9. Bank breach: Shinhan Bank, South Korea (2026)

Type of attack: Data breach through a bypassed login check.

How they did it

  1. Between September 29, 2026 and September 30, 2026, an unauthorised party got around the login check on a Shinhan Bank mobile web page used by loan brokers.
  2. The bank detected it on the morning of September 29, 2026 and reported it to regulators the next day.
  3. How the attackers got in is still unclear. Some Korean media report AI tools may have been used. That is not confirmed.

What was stolen

Data on about 25,000 customers, including names, phone numbers, income and loan limits, plus 66 national ID numbers. The bank says no customer money was taken and logged-in banking services were not affected.

Who was behind it

Unidentified. South Korea's financial regulator sent inspectors, and the bank's chief executive apologised and promised to cover any customer losses. Separately, a Shinhan employee was sentenced to 7 years for embezzling more than ₩1.4 billion over about three years.

What this means for you
  • After a bank breach, expect phone calls and texts that quote your real details. Hang up and call the number on your card.
  • Turn on transaction alerts so you see any unexpected payment straight away.

10. Counterfeit money: North Korea's fake US$100 bills (an older case)

Type of attack: State-linked currency counterfeiting.

How they did it

North Korea is linked to very high-quality fake US$100 notes known as "supernotes". Researchers say they were printed with the same engraved-plate method the US uses, on paper matching real US banknote paper. A claim that North Korea bleached real US$1 bills and reprinted them as US$100 bills is not confirmed. It comes from defector accounts that the researchers themselves say cannot be verified, and a former head of the US Bureau of Engraving and Printing said they were not bleaching genuine notes.

What was stolen

US officials cited about US$45 million in fake notes in circulation since 1989. We found no new supernote seizures or cases reported between 2023 and 2026, which is why this one is older than the rest of the list.

Who was behind it

The US Secret Service said in 2004 that the notes "are coming from North Korea". The Congressional Research Service still describes North Korean state involvement as unproven.

What this means for you
  • The US redesigned the $100 bill in 2013 to make it harder to copy. Check banknotes against the security features your central bank publishes.
  • Be wary of anyone who pays large amounts in cash and wants change in a different form.

Sources

Published October 9, 2026. We only include facts we could confirm in the sources above, and we say clearly where something is reported but not confirmed. Dollar amounts are in US dollars, as reported.


Frequently asked questions

What was the most common way in?

Stolen or weak logins. Change Healthcare, the Russian phishing campaigns, LastPass and the SEC account all started with someone's login details or phone number being taken.

Which single habit would have helped most?

Two-factor authentication with an authenticator app or passkey, plus checking any urgent money request through a channel you already trust.

Is the North Korean $1 bleaching story true?

It is not confirmed. It comes from defector accounts that cannot be verified, and a former head of the US Bureau of Engraving and Printing said genuine notes were not being bleached.