Origin Energy and Early Warning Services: Breach Roundup: Zelle Must Face NY Lawsuit Over Fraud

Origin Energy and Early Warning Services: Breach Roundup: Zelle Must Face NY Lawsuit Over Fraud

Cybersecurity Breach Roundup: Zelle Lawsuit, Romania Land Registry Hack, and Global Threats

This week’s cybersecurity incidents highlight escalating fraud risks, destructive attacks on critical infrastructure, and regulatory crackdowns on data protection failures.

Zelle Faces NY Lawsuit Over Fraud Controls

A New York judge ruled that Early Warning Services (EWS), the bank-owned operator of the Zelle payment network, must face a lawsuit filed by New York Attorney General Letitia James. The complaint alleges EWS ignored security safeguards to compete with nonbank apps like PayPal and Venmo, enabling over $1 billion in fraud between 2019 and 2022. Judge Phaedra Perry-Bond criticized EWS for misleading consumers about Zelle’s security, noting that instant, irrevocable transfers left victims with little recourse. Major banks including JPMorgan Chase, Bank of America, and Wells Fargo are among EWS’s largest shareholders. EWS plans to appeal, calling the lawsuit politically motivated.

Romania’s Land Registry Wiped in Destructive Cyberattack

A cyberattack by the threat actor ByteToBreach destroyed Romania’s land registry database, halting real estate transactions nationwide. The attack, which began on July 14, used stolen credentials to bypass defenses, delete critical data, and disable backups after a failed extortion attempt. The outage paralyzed property records, affecting notaries, government officials, and citizens. Kela, a threat intelligence firm, reported that the attacker also stole sensitive data, including employee credentials and internal documents, later offered for sale on a hacking forum. Authorities are rebuilding the system using offline backups, with cybersecurity expert Andrei Avadanei calling it "the most severe incident in Romania’s digital public administration history."

Spain Fines 23andMe $2.7M Over 2023 Data Breach

Spain’s data protection authority imposed a $2.7 million fine on genetic testing company 23andMe for failing to secure user data during a 2023 credential-stuffing attack that exposed 6.9 million users’ information, including 2,600 in Spain. The regulator found that 23andMe lacked mandatory multifactor authentication and controls to limit suspicious access, violating GDPR. The company only learned of the breach after stolen data appeared for sale. Spain’s penalty follows a $46.75 million U.S. settlement with breach victims, part of 23andMe’s bankruptcy proceedings.

Origin Energy Confirms Customer Data Breach

Australia’s Origin Energy, serving 4.8 million accounts, confirmed a breach after a hacker leaked 50 customer records to The Australian. The attacker, claiming revenge for offshored jobs, accessed data including names, addresses, and partial payment details via a compromised employee account. The hacker alleged undetected access for three weeks and criticized the company’s response. Origin CEO Frank Calabria apologized and said the incident is under investigation with cybersecurity experts and law enforcement.

U.S. Seizes 1,000+ Pirate World Cup Streaming Sites

The U.S. Department of Justice seized over 1,000 websites and blocked 1,970 domains used to illegally stream FIFA World Cup 2026 matches. The operation, part of a global crackdown, aimed to protect copyrighted content and reduce malware risks tied to pirate platforms. Parallel actions in Latin America dubbed Operation Red Card led to arrests in Colombia, where four members of the Los Ciberinfiltrados group were detained for selling pirated streams. The FBI had previously warned of fake FIFA ticket scams, while Mexican authorities dismantled 44 domains linked to the PirloTV piracy network.

Malware Abuses Microsoft 365 Calendars for Covert Operations

Researchers uncovered Hollowgraph, a new malware strain using Microsoft 365 calendars as a command-and-control (C2) channel. The .NET-based malware, attributed to the Iran-aligned Cavern Manticore group, exploits the Microsoft Graph API to hide commands in calendar events scheduled for May 13, 2050 ensuring they remain invisible to users. It also uses DNS tunneling to refresh credentials and exfiltrate data via encrypted attachments. The campaign, active between June and July 2026, targeted 12 Israeli organizations, with possible ties to the Lyceum cyberespionage group.

Source: https://www.govinfosecurity.com/breach-roundup-zelle-must-face-ny-lawsuit-over-fraud-a-32313

Origin Energy TPRM report: https://www.rankiteo.com/company/origin-bank

Early Warning Services TPRM report: https://www.rankiteo.com/company/early-warning-services

"id": "earori1784838549",
"linkid": "early-warning-services, origin-bank",
"type": "Breach",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Financial Services',
                        'location': 'United States',
                        'name': 'Early Warning Services (Zelle)',
                        'size': 'Major (owned by JPMorgan Chase, Bank of '
                                'America, Wells Fargo)',
                        'type': 'Payment Network Operator'},
                       {'customers_affected': 'Notaries, government officials, '
                                              'citizens',
                        'industry': 'Public Administration',
                        'location': 'Romania',
                        'name': 'Romania Land Registry',
                        'size': 'National',
                        'type': 'Government Agency'},
                       {'customers_affected': '6.9 million users (2,600 in '
                                              'Spain)',
                        'industry': 'Healthcare/Technology',
                        'location': 'United States (with users in Spain)',
                        'name': '23andMe',
                        'size': 'Large',
                        'type': 'Genetic Testing Company'},
                       {'customers_affected': '50 customer records leaked',
                        'industry': 'Utilities',
                        'location': 'Australia',
                        'name': 'Origin Energy',
                        'size': 'Large (4.8 million accounts)',
                        'type': 'Energy Provider'},
                       {'industry': 'Piracy',
                        'location': 'Global (U.S., Latin America)',
                        'name': 'FIFA World Cup 2026 Streaming Platforms',
                        'size': '1,000+ websites seized',
                        'type': 'Pirate Websites'},
                       {'industry': 'Multiple',
                        'location': 'Israel',
                        'name': 'Israeli Organizations',
                        'size': '12 organizations',
                        'type': 'Various'}],
 'attack_vector': ['Stolen Credentials',
                   'Credential Stuffing',
                   'Compromised Employee Account',
                   'Microsoft Graph API Exploitation',
                   'DNS Tunneling'],
 'customer_advisories': ['Origin Energy (public apology)',
                         '23andMe (breach disclosure)'],
 'data_breach': {'data_exfiltration': ['Romania Land Registry (sold on hacking '
                                       'forum)',
                                       '23andMe (stolen data appeared for '
                                       'sale)'],
                 'number_of_records_exposed': '6.9 million (23andMe), 50 '
                                              '(Origin Energy)',
                 'personally_identifiable_information': ['Names, addresses, '
                                                         'partial payment '
                                                         'details (Origin '
                                                         'Energy)',
                                                         'Genetic data '
                                                         '(23andMe)'],
                 'sensitivity_of_data': ['High (genetic data, PII, payment '
                                         'details)'],
                 'type_of_data_compromised': ['Genetic data (23andMe)',
                                              'Customer records (Origin '
                                              'Energy)',
                                              'Employee credentials and '
                                              'internal documents (Romania)']},
 'description': 'This week’s cybersecurity incidents highlight escalating '
                'fraud risks, destructive attacks on critical infrastructure, '
                'and regulatory crackdowns on data protection failures.',
 'impact': {'brand_reputation_impact': ['Zelle (misleading security claims)',
                                        '23andMe (GDPR violations)',
                                        'Origin Energy (data breach)'],
            'data_compromised': '6.9 million users (23andMe), 50 customer '
                                'records (Origin Energy), Employee credentials '
                                'and internal documents (Romania Land '
                                'Registry)',
            'downtime': 'Romania Land Registry (halted real estate '
                        'transactions nationwide)',
            'financial_loss': '$1 billion (Zelle fraud), $2.7M fine (23andMe), '
                              '$46.75M U.S. settlement (23andMe)',
            'identity_theft_risk': '6.9 million users (23andMe), 2,600 users '
                                   'in Spain (23andMe)',
            'legal_liabilities': ['Zelle (lawsuit by NY Attorney General)',
                                  '23andMe (GDPR fine and U.S. settlement)'],
            'operational_impact': 'Paralyzed property records in Romania, '
                                  'halted real estate transactions',
            'payment_information_risk': 'Partial payment details (Origin '
                                        'Energy)',
            'systems_affected': ['Zelle Payment Network',
                                 'Romania Land Registry Database',
                                 '23andMe User Data',
                                 'Origin Energy Customer Records',
                                 'Pirate Streaming Websites']},
 'initial_access_broker': {'data_sold_on_dark_web': ['Romania Land Registry '
                                                     '(employee credentials, '
                                                     'internal documents)'],
                           'entry_point': ['Compromised employee account '
                                           '(Origin Energy)',
                                           'Stolen credentials (Romania Land '
                                           'Registry)'],
                           'reconnaissance_period': 'Three weeks (Origin '
                                                    'Energy)'},
 'investigation_status': ['Ongoing (Origin Energy)',
                          'Completed (U.S. DOJ piracy operation)'],
 'motivation': ['Financial Gain',
                'Extortion',
                'Revenge',
                'Cyberespionage',
                'Piracy'],
 'post_incident_analysis': {'corrective_actions': ['Multifactor authentication '
                                                   '(23andMe)',
                                                   'Enhanced monitoring '
                                                   '(Origin Energy)',
                                                   'Rebuilding system from '
                                                   'offline backups (Romania)'],
                            'root_causes': ['Lack of MFA (23andMe)',
                                            'Insufficient access controls '
                                            '(23andMe)',
                                            'Stolen credentials (Romania Land '
                                            'Registry)',
                                            'Compromised employee account '
                                            '(Origin Energy)']},
 'ransomware': {'data_encryption': ['Romania Land Registry (data deleted after '
                                    'failed extortion)'],
                'data_exfiltration': ['Romania Land Registry']},
 'references': [{'source': 'New York Attorney General Letitia James'},
                {'source': 'Kela Threat Intelligence'},
                {'source': 'Spain’s Data Protection Authority'},
                {'source': 'The Australian'},
                {'source': 'U.S. Department of Justice'},
                {'source': 'Cybersecurity Researchers (Hollowgraph Malware)'}],
 'regulatory_compliance': {'fines_imposed': '$2.7M (Spain, 23andMe)',
                           'legal_actions': ['Lawsuit by NY Attorney General '
                                             '(Zelle)',
                                             'U.S. settlement (23andMe)'],
                           'regulations_violated': ['GDPR (23andMe)']},
 'response': {'communication_strategy': ['Apology from Origin Energy CEO',
                                         'Public disclosure by 23andMe'],
              'containment_measures': ['Domain seizures (U.S. DOJ)',
                                       'Rebuilding system from offline backups '
                                       '(Romania)'],
              'enhanced_monitoring': ['Origin Energy'],
              'law_enforcement_notified': ['U.S. Department of Justice '
                                           '(piracy)',
                                           'Australian law enforcement (Origin '
                                           'Energy)'],
              'recovery_measures': ['Rebuilding land registry database '
                                    '(Romania)'],
              'remediation_measures': ['Enhanced monitoring (Origin Energy)',
                                       'Multifactor authentication (23andMe '
                                       'post-breach)'],
              'third_party_assistance': ['Cybersecurity experts (Origin '
                                         'Energy)',
                                         'Threat intelligence firm Kela '
                                         '(Romania)']},
 'threat_actor': ['ByteToBreach',
                  'Cavern Manticore',
                  'Los Ciberinfiltrados',
                  'PirloTV Operators',
                  'Iran-aligned Group (Lyceum)'],
 'title': 'Cybersecurity Breach Roundup: Zelle Lawsuit, Romania Land Registry '
          'Hack, and Global Threats',
 'type': ['Fraud',
          'Destructive Cyberattack',
          'Data Breach',
          'Credential Stuffing',
          'Malware',
          'Piracy'],
 'vulnerability_exploited': ['Lack of Multifactor Authentication',
                             'Insufficient Access Controls',
                             'Unsecured Backups']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.