Operation Master: Large-Scale Invoice Fraud Campaign Targets Brazilian Customers
Between April and mid-September 2026, cybercriminals executed Operation Master, a sophisticated campaign combining VPN exploits, database breaches, and large-scale invoice fraud primarily targeting Brazilian customers. Researchers at SOCRadar uncovered the operation after tracing an exposed server to attacker-controlled infrastructure.
The attackers exploited CVE-2026-0257, a GlobalProtect authentication bypass vulnerability, to gain unauthorized VPN access across seven gateways in four countries. Using automated scans and SQL injection attacks, they extracted data from at least nine database systems, including 24,558 debtor records with contact details. Stolen credentials and the AdaptixC2 remote-control framework were later used to maintain persistence and escalate intrusions.
The campaign’s second phase involved fraudulent billing at industrial scale. Hackers built a shared fraud panel capable of sending millions of personalized messages via email and SMS, impersonating utility providers. By mid-September, the system had generated 2.4 million emails and 1.4 million SMS messages, along with 622,666 personalized short links 317,699 of which were clicked. Fraudulent invoices, mirroring legitimate documents, displayed real customer details, with logged values totaling R$150.4 million (though actual losses remain unconfirmed).
Attackers also employed Microsoft 365 device-code phishing and vishing (voice-based phishing) to obtain verification codes, further enhancing the credibility of their scams. The operation’s infrastructure, including lookalike domains (e.g., igreenfaturas[.]to) and hijacked mailboxes, was dismantled by mid-September, though investigators could not determine if the campaign had fully ceased or relocated.
Key indicators of compromise (IoCs), including domains, IP addresses, and file hashes, were published to aid detection. The incident highlights the rapid transition from network intrusion to large-scale financial fraud, leveraging stolen data for both resale and direct monetization.
Source: https://cybersecuritynews.com/hackers-exploit-globalprotect-flaw/
Microsoft Security cybersecurity rating report: https://www.rankiteo.com/company/microsoft-security
"id": "MIC1790583993",
"linkid": "microsoft-security",
"type": "Cyber Attack",
"date": "4/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '24,558+ (debtor records)',
'industry': 'Utilities (implied)',
'location': 'Brazil',
'type': 'Customers'}],
'attack_vector': ['VPN Exploit (CVE-2026-0257)',
'SQL Injection',
'Device-Code Phishing',
'Vishing'],
'data_breach': {'data_exfiltration': 'Yes',
'number_of_records_exposed': '24,558',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'Personally Identifiable Information '
'(PII)',
'type_of_data_compromised': ['Debtor records',
'Contact details']},
'date_detected': '2026-09-15',
'description': 'Between April and mid-September 2026, cybercriminals executed '
'Operation Master, a sophisticated campaign combining VPN '
'exploits, database breaches, and large-scale invoice fraud '
'primarily targeting Brazilian customers. The attackers '
'exploited CVE-2026-0257 to gain unauthorized VPN access, '
'extracted data from at least nine database systems, and used '
'stolen credentials to send millions of fraudulent invoices '
'via email and SMS, impersonating utility providers. The '
'campaign generated 2.4 million emails, 1.4 million SMS '
'messages, and 622,666 personalized short links, with '
'fraudulent invoices totaling R$150.4 million.',
'impact': {'data_compromised': '24,558 debtor records with contact details',
'financial_loss': 'R$150.4 million (unconfirmed)',
'identity_theft_risk': 'High',
'operational_impact': 'Large-scale fraudulent billing operations',
'payment_information_risk': 'High',
'systems_affected': ['VPN gateways',
'Database systems',
'Mailboxes']},
'initial_access_broker': {'backdoors_established': 'AdaptixC2 remote-control '
'framework',
'entry_point': 'VPN exploit (CVE-2026-0257)'},
'investigation_status': 'Ongoing (campaign may have relocated)',
'lessons_learned': 'The incident highlights the rapid transition from network '
'intrusion to large-scale financial fraud, leveraging '
'stolen data for both resale and direct monetization.',
'motivation': ['Financial Gain'],
'post_incident_analysis': {'root_causes': ['Exploitation of CVE-2026-0257',
'SQL Injection attacks',
'Stolen credentials']},
'references': [{'source': 'SOCRadar'}],
'response': {'containment_measures': 'Infrastructure dismantled '
'(mid-September 2026)',
'third_party_assistance': 'SOCRadar (investigation)'},
'title': 'Operation Master: Large-Scale Invoice Fraud Campaign Targets '
'Brazilian Customers',
'type': ['Invoice Fraud', 'Data Breach', 'Phishing'],
'vulnerability_exploited': 'CVE-2026-0257 (GlobalProtect authentication '
'bypass)'}