In this article
- The short version
- 1. Ransomware: Change Healthcare (2024)
- 2. Supply-chain zero-day: the MOVEit mass hack (2023)
- 3. Deepfake video call: Arup in Hong Kong (2024)
- 4. Fake Microsoft and Amazon messages: Russian phishing against Ukraine (2024 to 2025)
- 5. Password manager breach: LastPass and its UK users (2022, fined 2025)
- 6. Crypto theft through a supplier: Bybit (2025)
- 7. Scam compounds and "pig butchering": Prince Group (2025)
- 8. SIM swap: the hacked SEC account on X (2024)
- 9. Bank breach: Shinhan Bank, South Korea (2026)
- 10. Counterfeit money: North Korea's fake US$100 bills (an older case)
- Sources
The short version
Most of the biggest losses since 2023 did not need clever new technology. They came from a stolen password on a system without two-factor sign-in, a fake login page, a convincing video call, or a phone number taken over at a shop counter. The ten cases below are grouped by type of attack. Facts are taken from official statements and reputable reporting, and anything that is only claimed or reported is labelled that way.
1. Ransomware: Change Healthcare (2024)
Type of attack: Ransomware with data theft.
How they did it
- Attackers logged in to a Change Healthcare remote-access (Citrix) portal on February 12, 2024 using stolen login details.
- UnitedHealth's chief executive told US senators: "The portal did not have multi-factor authentication."
- Nine days later, on February 21, 2024, they set off ransomware that locked Change's systems.
What was stolen
Health and personal data. On July 31, 2025 Change Healthcare told the US health department's Office for Civil Rights that about 192.7 million people were affected. UnitedHealth confirmed it paid a US$22 million ransom.
Who was behind it
UnitedHealth's chief executive named the criminal group "ALPHV" in his testimony. That is the company's attribution, not a government one.
- One password with no second step was enough. Turn on two-factor authentication everywhere it is offered, starting with email.
- If a company you use is breached, expect scam messages that quote your real details.
2. Supply-chain zero-day: the MOVEit mass hack (2023)
Type of attack: Mass exploitation of an unknown flaw (a "zero-day") in widely used file-transfer software.
How they did it
- From May 27, 2023 the Cl0p gang used a SQL injection flaw (CVE-2023-34362) in internet-facing MOVEit Transfer servers.
- They planted a hidden backdoor page called LEMURLOOT, disguised as a normal file named "human2.aspx".
- They used it to copy data out of the MOVEit databases, then threatened to publish it unless victims paid.
What was stolen
Files held by thousands of organisations, from governments to payroll firms. The security company Emsisoft counted 2,773 organisations and about 95.8 million people affected (as of June 28, 2024), noting some people were probably counted twice.
Who was behind it
The US cyber agency CISA and the FBI named the "CL0P Ransomware Gang, also known as TA505".
- You cannot patch a company's server, but you can limit what one breach exposes: use a different password for every account.
- Be wary of "your data was in a breach" messages that ask you to click or pay. Go to the company's own website instead.
3. Deepfake video call: Arup in Hong Kong (2024)
Type of attack: Deepfake "boss" fraud.
How they did it
- In January 2024 a finance employee at the engineering firm Arup in Hong Kong received a message, apparently from the company's UK chief financial officer, about a "confidential transaction".
- He joined a video call where the finance chief and other colleagues looked and sounded real. Hong Kong police said the fraudsters likely downloaded videos of real meetings and used AI to fake the voices.
- Reassured, he made 15 transfers into 5 Hong Kong bank accounts over about a week. The fraud was found when he checked with head office.
What was stolen
HK$200 million, about US$25.6 million. Arup confirmed "fake voices and images were used" and said none of its internal systems were compromised.
Who was behind it
Unknown. No arrests had been reported as of May 2024.
- Seeing and hearing someone on a call is no longer proof. Check any urgent money request through a number or channel you already trust.
- Agree a check word with family members for emergencies.
4. Fake Microsoft and Amazon messages: Russian phishing against Ukraine (2024 to 2025)
Type of attack: Spear-phishing (targeted fake messages) to steal logins and take remote control.
How they did it
- From about August 2024, emails were sent from real organisations that had already been hacked, so they looked trustworthy.
- The messages talked about "integration" with Amazon and Microsoft. Amazon says some sending domains were made to look like Amazon Web Services (AWS) addresses.
- Each email carried a Remote Desktop (.rdp) file. Opening it connected the victim's computer to the attackers' server, exposing drives, the clipboard and more, and letting them install malware.
- In a separate campaign in April 2025, a Russia-affiliated group Microsoft calls Void Blizzard used a fake Microsoft login page with a misspelt address, reached through a QR code in a PDF.
What was stolen
Windows login details and access to computers. Microsoft said the RDP campaign hit "thousands" of targets in more than 100 organisations. Ukraine's government cyber team, CERT-UA, warned that Ukrainian public authorities, major industries and military units were targeted.
Who was behind it
Amazon and Microsoft named APT29 (Midnight Blizzard), which the US and UK governments attribute to Russia's Foreign Intelligence Service (SVR). Amazon seized the fake AWS domains on October 24, 2024.
- Never open an attachment you were not expecting, even from someone you know. Their account may have been taken over.
- Type the web address for Microsoft or Amazon yourself instead of clicking a link or scanning a QR code in a message.
5. Password manager breach: LastPass and its UK users (2022, fined 2025)
Type of attack: Breach of a password manager through staff devices.
How they did it
- In August 2022 an attacker broke into a developer's work laptop and took part of LastPass's source code.
- The attacker then targeted a senior engineer's home computer through a flaw in a third-party streaming app, and a keylogger captured the engineer's master password.
- With that, the attacker got the keys needed to download LastPass's customer vault backups.
What was stolen
Customer vault backups and account details. The UK Information Commissioner's Office (ICO) said up to 1.6 million UK users were affected and fined LastPass UK £1.2 million on December 11, 2025. The ICO says there is no evidence passwords were decrypted, because master passwords are never shared with LastPass. Researchers have since traced more than US$35 million in crypto thefts they link to the breach, but say they cannot prove the connection.
Who was behind it
No official attribution for the 2022 break-in. The blockchain firm TRM Labs says the later crypto thefts are consistent with Russian cybercriminals.
- A password manager is still far safer than reusing passwords. Protect it with a long, unique master passphrase and two-factor authentication.
- Never store crypto wallet recovery phrases in a password manager or anywhere online.
6. Crypto theft through a supplier: Bybit (2025)
Type of attack: Supply-chain attack on a crypto wallet service.
How they did it
- Attackers compromised the laptop of a developer at Safe{Wallet}, a wallet service the exchange Bybit used.
- They used it to alter the Safe{Wallet} screen Bybit's staff relied on.
- On or about February 21, 2025 Bybit's staff approved what looked like a normal transfer. It actually handed control of Bybit's main Ethereum cold wallet to the attackers, who emptied it.
What was stolen
About US$1.5 billion in cryptocurrency, the largest crypto theft on record at the time.
Who was behind it
On February 26, 2025 the FBI said North Korea was responsible, calling the activity "TraderTraitor". Read our full Bybit story.
- Keep larger crypto amounts in a hardware wallet you control, not all on one exchange.
- Before approving any transaction, check the details on a second device or screen if you can.
7. Scam compounds and "pig butchering": Prince Group (2025)
Type of attack: Investment fraud run from forced-labour scam compounds.
How they did it
- Workers were lured to Cambodia with fake job offers, then held in walled compounds where their passports and phones were taken.
- Using "phone farms" of thousands of phones, they messaged victims on social media and messaging apps.
- Over weeks or months they built trust, then talked victims into "investing" in fake crypto platforms. The money was stolen.
What was stolen
Billions of dollars from victims worldwide. On October 14, 2025 the US Justice Department announced the forfeiture of about 127,271 bitcoin, worth about US$15 billion at the time, the largest forfeiture action in its history. The US Treasury says Americans lost at least US$10 billion to Southeast Asia-based scams in 2024.
Who was behind it
US prosecutors charged Prince Group chairman Chen Zhi with wire fraud and money laundering conspiracy. These are charges, not convictions. The US and UK sanctioned the group the same day. Cambodia says Chen Zhi was arrested on January 6, 2026 and sent to China.
- A stranger who becomes a friend online and then talks about investing is the classic pattern. Stop there.
- Never move money to a platform someone else recommended. Check it against your country's official regulator first.
8. SIM swap: the hacked SEC account on X (2024)
Type of attack: SIM swap (taking over someone's phone number).
How they did it
- Criminals got the personal details of the person whose phone number was linked to the US Securities and Exchange Commission's X account.
- On January 9, 2024 one of them, Eric Council Jr., used a fake ID in that person's name at a phone shop in Alabama to get a new SIM card for the number.
- With the number, the group took over the SEC's X account and posted a fake announcement about bitcoin funds.
What was stolen
Control of an official government account. The fake post pushed the bitcoin price up by more than US$1,000, before it fell by more than US$2,000 once the post was corrected. Council was paid about US$50,000 in bitcoin.
Who was behind it
Council pleaded guilty and was sentenced on May 16, 2025 to 14 months in prison. His co-conspirators have not been publicly named.
- Ask your mobile provider for a port-out PIN or account lock.
- Use an authenticator app or passkey instead of text-message codes for important accounts.
9. Bank breach: Shinhan Bank, South Korea (2026)
Type of attack: Data breach through a bypassed login check.
How they did it
- Between September 29, 2026 and September 30, 2026, an unauthorised party got around the login check on a Shinhan Bank mobile web page used by loan brokers.
- The bank detected it on the morning of September 29, 2026 and reported it to regulators the next day.
- How the attackers got in is still unclear. Some Korean media report AI tools may have been used. That is not confirmed.
What was stolen
Data on about 25,000 customers, including names, phone numbers, income and loan limits, plus 66 national ID numbers. The bank says no customer money was taken and logged-in banking services were not affected.
Who was behind it
Unidentified. South Korea's financial regulator sent inspectors, and the bank's chief executive apologised and promised to cover any customer losses. Separately, a Shinhan employee was sentenced to 7 years for embezzling more than ₩1.4 billion over about three years.
- After a bank breach, expect phone calls and texts that quote your real details. Hang up and call the number on your card.
- Turn on transaction alerts so you see any unexpected payment straight away.
10. Counterfeit money: North Korea's fake US$100 bills (an older case)
Type of attack: State-linked currency counterfeiting.
How they did it
North Korea is linked to very high-quality fake US$100 notes known as "supernotes". Researchers say they were printed with the same engraved-plate method the US uses, on paper matching real US banknote paper. A claim that North Korea bleached real US$1 bills and reprinted them as US$100 bills is not confirmed. It comes from defector accounts that the researchers themselves say cannot be verified, and a former head of the US Bureau of Engraving and Printing said they were not bleaching genuine notes.
What was stolen
US officials cited about US$45 million in fake notes in circulation since 1989. We found no new supernote seizures or cases reported between 2023 and 2026, which is why this one is older than the rest of the list.
Who was behind it
The US Secret Service said in 2004 that the notes "are coming from North Korea". The Congressional Research Service still describes North Korean state involvement as unproven.
- The US redesigned the $100 bill in 2013 to make it harder to copy. Check banknotes against the security features your central bank publishes.
- Be wary of anyone who pays large amounts in cash and wants change in a different form.
Sources
- HHS Office for Civil Rights: Change Healthcare cybersecurity incident FAQreviewed August 13, 2025
- The Register: UnitedHealth CEO testimony on the ransomApril 30, 2024
- CISA advisory AA23-158A: CL0P exploits the MOVEit flawupdated June 16, 2023
- Emsisoft: Unpacking the MOVEit breachfigures as of June 28, 2024
- South China Morning Post: Arup confirmed as victim of HK$200 million deepfake scamMay 17, 2024
- AWS Security Blog: Amazon identified internet domains abused by APT29October 24, 2024
- Microsoft: Midnight Blizzard spear-phishing campaign using RDP filesOctober 29, 2024
- Microsoft: New Russia-affiliated actor Void BlizzardMay 27, 2025
- ICO: Password manager provider finedDecember 11, 2025
- TRM Labs: Stolen crypto traced from the 2022 LastPass breachDecember 24, 2025
- FBI IC3: North Korea responsible for US$1.5 billion Bybit hackFebruary 26, 2025
- US Department of Justice: Chairman of Prince Group indictedOctober 14, 2025
- US Treasury: Largest action ever targeting cybercriminal networks in Southeast AsiaOctober 14, 2025
- OCCRP: Cambodia extradites Prince Group chairman to ChinaJanuary 7, 2026
- US Department of Justice: Alabama man sentenced over the SEC X account hackMay 16, 2025
- Korea Times: Shinhan Bank hit by data breach affecting 25,000 customersOctober 1, 2026
- Mediawatch: Shinhan employee sentenced over embezzlementJuly 1, 2026
- Congressional Research Service: North Korean Counterfeiting of U.S. Currency (RL33324)April 16, 2008
- Vice: North Korea's counterfeit Benjamins have vanishedMarch 16, 2016
Published October 9, 2026. We only include facts we could confirm in the sources above, and we say clearly where something is reported but not confirmed. Dollar amounts are in US dollars, as reported.
Frequently asked questions
What was the most common way in?
Stolen or weak logins. Change Healthcare, the Russian phishing campaigns, LastPass and the SEC account all started with someone's login details or phone number being taken.
Which single habit would have helped most?
Two-factor authentication with an authenticator app or passkey, plus checking any urgent money request through a channel you already trust.
Is the North Korean $1 bleaching story true?
It is not confirmed. It comes from defector accounts that cannot be verified, and a former head of the US Bureau of Engraving and Printing said genuine notes were not being bleached.