GADGET
Cyber News Weekly
EOFY Special: Follow the Money
Week ending 30 June 2026 | 5 minute CISO brief

Figure 1. The end of financial year threat map, where ransomware, fraud, cloud abuse and identity theft all meet the same thing: money.
| CISO translation: Cybercrime has always followed value. At end of financial year, it also follows timing. Finance teams are closing books, suppliers are chasing payment, executives are travelling, auditors are asking questions and everyone is allergic to delay. In that environment, an attacker does not need a cinematic hack. Sometimes they only need a plausible invoice and a busy approver. |
The signal this week
Financially motivated cybercrime is converging around identity, payment workflows and cloud capacity.
The useful story this week is not one incident. It is the shape of the market. In the United States, prosecutors charged two alleged operators of AudiA6, a cryptocurrency laundering service that the U.S. Department of Justice says laundered more than $389 million in unlawful transactions. Europol described the same ecosystem as a pipeline suspected of laundering more than EUR 336 million for ransomware gangs and wider cybercrime networks (Europol, 2026b; U.S. Department of Justice, 2026a).
Days later, law enforcement and private sector partners disrupted SocGholish, Amadey and StealC infrastructure. The Hacker News reported that the takedown covered 326 servers and 142 domains, recovered 27 million stolen credentials and restricted more than $47 million in criminal cryptocurrency assets (The Hacker News, 2026b). That reads like a police story, but CISOs should read it as a supply chain story. Infostealers and loaders are the wholesale market that feeds ransomware, BEC, data theft and resale.
At the same time, the softer financial scams kept doing what they do best: arriving as something ordinary. The FBI says business email compromise remains one of the most financially damaging online crimes, precisely because it abuses a tool every business trusts: email (Federal Bureau of Investigation, n.d.). At EOFY, “urgent payment” becomes less a suspicious phrase and more a calendar event. That is helpful for criminals and deeply unfair to accounts payable, which frankly has enough to do without becoming a SOC annex.

Figure 2. The profit motive view, showing how ransomware, invoice fraud, crypto laundering, cloud abuse and malware supply chains orbit the same business model.
What happened in the last week
The headlines were varied, but the revenue model was remarkably consistent.
The week ended with a sharp reminder that investment scams and crypto fraud are not merely consumer protection issues. The Hacker News reported new findings that more than 236,000 websites were using investment scam templates built with DCloud Uni-App, supporting bogus cryptocurrency exchanges, phishing and wallet drainers (The Hacker News, 2026c). For a CISO, that matters because customers, employees and executives live in the same online fraud economy. The scam that empties a retiree account today can become a credential theft path into a corporate mailbox tomorrow.
SecurityWeek also highlighted the continuing innovation of ransomware operators. A DragonForce ransomware attack reportedly used Microsoft Teams relay servers for command and control, while another SecurityWeek report said a new Mistic remote access trojan is being used by an initial access broker serving multiple ransomware families (SecurityWeek, 2026a, 2026b). The common theme is not just malware. It is normality. Threat actors are hiding inside normal collaboration platforms, normal admin tools and normal remote access patterns.
Australia had its own reminder. Cyber Daily and SecurityWeek both reported on the Mackay Sugar incident, with Cyber Daily noting that The Gentlemen ransomware group claimed the attack and SecurityWeek reporting that the incident shut down mills of Australia’s second-largest sugar producer (Cyber Daily, 2026a; SecurityWeek, 2026c). That is the sort of incident boards understand immediately. Cyber risk stops being abstract when it reaches payroll, production, power, freight or harvest windows.
The financial cybercrime chain
Fraud and ransomware are increasingly sequenced, not separate.
Most financially motivated incidents now look like a chain rather than a category. Initial access might come from phishing, infostealer logs, exposed edge devices, compromised software packages or a rented access broker. The next step might be session theft, mailbox compromise or a cloud admin token. After that, the attacker can choose the revenue path. They can redirect a payment, mine crypto on stolen compute, steal data, deploy ransomware, sell access or do all of the above while pretending to be very busy with “business transformation.”
Cyber Security News reported in June that OnyxC2 is being marketed like commercial software, with payload builders and panels designed to steal browser credentials, password manager data, two-factor codes and cryptocurrency wallet information from more than 210 applications (Cyber Security News, 2026a). That is a finance problem wearing a malware jacket. A stolen session cookie can bypass a password change. A stolen email token can approve a supplier change. A stolen wallet can monetise instantly.

Figure 3. A simplified EOFY financial cybercrime chain, from initial access to identity compromise, cloud hijack, data theft and cash out.
Australia: the financial year in review
Official FY2025-26 cyber reporting is not yet complete, so the best current picture combines 2025 scam data, FY2024-25 cyber reporting and early 2026 signals.
The Australian story is not subtle. The National Anti-Scam Centre and ACCC reported that combined scam losses exceeded $2 billion in 2025. Investment scams led losses at $837.7 million, payment redirection reached $166.8 million, phishing reached $97.6 million and remote access scams reached $69.9 million. The top five scam categories accounted for 60 percent of total losses (ACCC, 2026a, 2026b).
The cyber picture points in the same direction. ASD’s ACSC reported more than 84,700 cybercrime reports in FY2024-25, which is roughly one every six minutes. It also made more than 1,700 proactive notifications to entities about potentially malicious activity, an 83 percent increase from the prior year, and reported that nearly half of confirmed incidents arising from those proactive engagements were associated with malware or ransomware (ASD’s ACSC, 2025).
The June policy environment also matters. The Australian Government launched Horizon 2 of the 2023-2030 Australian Cyber Security Strategy with 19 actions and 64 initiatives to be delivered by the end of 2028, aimed at strengthening cyber maturity across the economy, society and digital infrastructure (Department of Home Affairs, 2026a). Around the same time, Australia and Microsoft signed a memorandum of understanding on digital resilience covering secure cloud, cybersecurity, AI and critical infrastructure protection (ITBrief Australia, 2026). The message is clear: cyber resilience is being treated as economic infrastructure, not just technical hygiene.

Figure 4. Australia’s financial crime review, combining scam loss categories with the broader cyber resilience shift.
Threat actors and tactics to watch
The names change. The incentives do not.
| Threat area | This week’s signal | What CISOs should take from it |
| The Gentlemen and ransomware affiliates | Krebs reported that The Gentlemen has become one of the most active ransomware groups by victim count, attracting affiliates with a high revenue share. Cyber Daily linked the group to the Mackay Sugar claim. | Ransomware recruitment economics matter. If affiliates are paid well, the group can scale quickly. Treat exposed VPNs, firewalls, backups and admin consoles as revenue opportunities for attackers. |
| Scattered Spider style social engineering | Krebs reported that two key Scattered Spider members pleaded guilty over the Transport for London attack. The group’s playbook blends social engineering, identity abuse and operational disruption. | Identity incidents are not low severity just because no malware detonated. Help desks, finance staff and outsourced support desks are all part of the attack surface. |
| Infostealers and loaders | Operation Endgame disrupted SocGholish, Amadey and StealC infrastructure, but the recovered credentials show how large the access market has become. | Do not wait for ransomware. Treat infostealer detections, impossible travel, OAuth grants and new mailbox rules as possible pre-ransomware indicators. |
| Cloud hijack and cryptomining | Cyber Security News and The Hacker News continue to track cloud and developer ecosystem abuse, including worms, package compromise and cloud credential theft. | Cloud cost anomalies belong in the security queue. Stolen compute can become mining, staging, scanning, exfiltration or all four. |
| AI-assisted fraud | Darktrace found that 87 percent of security leaders say AI is significantly increasing threats requiring attention, and Five Eyes agencies warned that adversaries are already using AI to move faster. | The control question is not whether a message looks real. It is whether the requested action is allowed, verified and logged. AI makes content cheaper. Governance must make action harder to abuse. |
What did we learn
EOFY is not merely a reporting period. It is a threat model.
The first lesson is that the boundary between fraud and cybercrime is dissolving. A payment redirection scam may begin with a compromised mailbox. A ransomware attack may begin with an infostealer log purchased from a marketplace. A crypto scam may be delivered through a polished web template and laundered through a professionalised service. The labels are useful for reporting. They are less useful for defence.
The second lesson is that timing is an exploitable control weakness. EOFY creates natural urgency, higher transaction volume and process exceptions. It also creates a perfectly believable reason for executives, finance staff and suppliers to ask for things quickly. Attackers do not need to invent urgency. The calendar kindly supplies it.
The third lesson is that resilience needs to extend into the business workflow. The strongest security stack in the world does not help if a supplier bank account can be changed by one email, one Teams message or one tired approval after dinner. The attacker does not care whether the control owner sits in finance, procurement, IT, legal or cyber. The attacker is wonderfully non-siloed. We should take the hint.
| Board provocation: Which finance workflow could move money, expose data or create material disruption if a trusted identity were hijacked for 30 minutes? If nobody can answer, the next tabletop exercise just wrote itself. |
The next financial year: six predictions
The next year will reward organisations that treat money movement as part of the attack surface.
The next financial year is unlikely to be defined by a single spectacular threat actor. It is more likely to be shaped by the steady industrialisation of financially motivated operations. The criminal market is becoming faster, more modular and more comfortable mixing fraud, ransomware, data theft and cloud abuse inside one campaign.

Figure 5. FY2026-27 threat outlook for financially motivated cyber threats.
| Prediction | Why it is likely | Practical CISO move |
| AI-assisted invoice and payroll impersonation will improve | Five Eyes agencies warned that adversaries are already using AI to move faster, while Darktrace survey data shows widespread concern about AI-driven threat growth. | Move approvals from message trust to transaction trust. Use call backs, registered supplier portals and workflow controls that cannot be bypassed by a convincing email. |
| Identity-first extortion will grow | Credential theft, OAuth device-code phishing, infostealers and remote access brokers make identity the cheapest path to impact. | Prioritise phishing-resistant MFA, conditional access, session revocation, privileged access review and continuous monitoring of mailbox and SaaS changes. |
| Cloud compute theft will remain under-detected | Stolen compute is easy to monetise through cryptomining and useful for staging, scanning and hiding infrastructure. | Treat unexpected compute spend, new regions, unusual service principals and abnormal outbound connections as security telemetry, not just finance variance. |
| ERP and SaaS systems will become leverage points | SecurityWeek reported exploitation of PeopleSoft activity in June, while EOFY naturally concentrates attention on ERP, payroll and reporting systems. | Put ERP admin paths, payroll exports and financial master data changes into privileged monitoring. Finance workflow logging should be usable during incident response. |
| Access brokers will become more invisible to the business | Mistic RAT, infostealers and loader ecosystems show that initial access can be supplied as a service before any visible impact occurs. | Create pre-ransomware incident triggers. A credible infostealer or access broker signal should start containment, not a polite ticket queue. |
| Blended incidents will become normal | Ransomware, payment fraud and data theft share infrastructure, credentials and laundering channels. | Run one exercise that includes cyber, fraud, finance, legal, communications and executive decision makers. Criminals already integrated their functions. Defenders should too. |
People, process and technology for EOFY defence
The control stack needs to protect the moment when trust becomes money.
| Dimension | What to change now | Why it matters |
| People | Put CFO, CISO, procurement, payroll and legal in the same EOFY response room for one hour. Review who can approve supplier changes, emergency payments and payroll exceptions. | Financially motivated attacks move through people with authority. Knowing the approval map is as important as knowing the network map. |
| Process | Make bank-detail changes, payroll file changes and urgent vendor exceptions two-channel events. A reply in the same email thread should never be enough. | Attackers love one-channel trust because it lets them control both the request and the verification. |
| Technology | Monitor for OAuth grants, new mailbox forwarding rules, suspicious RMM use, anomalous cloud spend and new service principals. | These are the quiet signals that often arrive before money leaves, data moves or ransomware lands. |
| Data | Classify and protect finance exports, supplier master data, payroll files and ERP reports as high value data, not back-office paperwork. | These datasets are perfect for extortion, impersonation and fraud because they contain money context. |
| Recovery | Test whether the organisation can freeze suspicious payments, rotate credentials, revoke sessions, isolate finance systems and restore key workloads during close. | At EOFY, time lost is not just inconvenience. It can become reporting, revenue, disclosure and trust impact. |
The CISO move
Follow the money, then instrument the path.
The strategic move for CISOs is to stop treating financially motivated cybercrime as separate categories. Ransomware, BEC, invoice fraud, data theft, access brokerage, cryptomining and laundering are not siblings who refuse to sit together at dinner. They are parts of the same family business.
Start with the money paths. Where can a payment be redirected? Where can payroll be altered? Where can cloud compute be created at scale? Where can supplier data, finance exports or ERP reports be pulled without triggering a human conversation? Where can a trusted identity become an action? Those are the controls that matter most when attackers are profit-driven and the calendar is doing half their social engineering for them.
The fun part, if we are allowed to call any of this fun, is that the best EOFY cyber controls are also good business controls. Clear authority, strong verification, clean logs, tested recovery, visible exceptions and fewer mystery admin accounts will make auditors happier, finance calmer and criminals slightly more disappointed. That feels like a decent end-of-year result.
| A small but useful joke: If your finance workflow depends on everyone being calm, rested and suspicious at the exact moment EOFY makes them busy, tired and helpful, that is not a control. That is a hope with a spreadsheet. |
Research base
Core sources reviewed for this issue.
| Source group | How it shaped the article |
| Official Australia and international sources | ACCC and Scamwatch data framed the Australian scam picture. ASD’s ACSC informed the annual cyber threat context. CISA KEV updates, FBI IC3, DOJ and Europol provided U.S. and European enforcement, fraud and ransomware signals. |
| News and threat intelligence outlets | Cyber Daily, Cyber Security News, KrebsOnSecurity, The Hacker News and SecurityWeek informed the weekly threat actor and tactic view, including The Gentlemen, Scattered Spider, infostealers, ransomware operators and crypto scam infrastructure. |
| Australia policy and industry sources | Home Affairs Horizon 2, ITBrief Australia and Australian Cyber Security Magazine helped position cyber resilience as national economic infrastructure. |
| AI security thought leadership | Darktrace and the Five Eyes statement informed the outlook on AI-assisted attacks, defensive AI and the need for machine-speed containment. |
References
APA v7 style reference list.
Australian Competition and Consumer Commission. (2026a, March 30). Targeting scams: Report of the National Anti-Scam Centre on scams data and activity 2025. Scamwatch. https://www.scamwatch.gov.au/research-and-resources/targeting-scams-report
Australian Competition and Consumer Commission. (2026b, March 30). Continued action critical to combat fraud as annual scam losses exceed $2 billion. https://www.accc.gov.au/media-release/continued-action-critical-to-combat-fraud-as-annual-scam-losses-exceed-2-billion
Australian Competition and Consumer Commission. (2026c, June 5). Thousands of scam websites taken down as online scams continue to cost Australians. https://www.accc.gov.au/media-release/thousands-of-scam-websites-taken-down-as-online-scams-continue-to-cost-australians
Australian Signals Directorate’s Australian Cyber Security Centre. (2025). Annual cyber threat report 2024-25. https://www.cyber.gov.au/about-us/view-all-content/reports-and-statistics/annual-cyber-threat-report-2024-2025
Australian Cyber Security Magazine. (2026, June 12). Government launches Horizon 2 action plan for Australia’s cyber security strategy. https://australiancybersecuritymagazine.com.au/government-launches-horizon-2-action-plan-for-australias-cyber-security-strategy/
Cyber Daily. (2026a, June 16). Exclusive: Mackay Sugar cyber attack claimed by The Gentlemen ransomware. https://www.cyberdaily.au/security/13758-exclusive-mackay-sugar-cyber-attack-claimed-by-the-gentlemen-ransomware
Cyber Daily. (2026b, June 30). Investors warned as social media scams spike over winter. https://www.cyberdaily.au/security/13831-investors-warned-as-social-media-scams-spike-over-winter
Cyber Security News. (2026a, June 12). Hackers use OnyxC2 Malware-as-a-Service to steal browser credentials, 2FA codes and crypto wallets. https://cybersecuritynews.com/hackers-use-onyxc2-malware-as-a-service/
Cyber Security News. (2026b, June 8). New Pink hacking group attacking enterprise users to steal cloud credentials. https://cybersecuritynews.com/new-pink-hacking-group-attacking-enterprise-users/
Cyber Security News. (2026c, February 19). Advanced crypto mining malware spreads through external storage devices. https://cybersecuritynews.com/advanced-crypto-mining-malware/
Cybersecurity and Infrastructure Security Agency. (2026a, June 23). CISA adds four known exploited vulnerabilities to catalog. https://www.cisa.gov/news-events/alerts/2026/06/23/cisa-adds-four-known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency. (2026b, June 25). CISA adds two known exploited vulnerabilities to catalog. https://www.cisa.gov/news-events/alerts/2026/06/25/cisa-adds-two-known-exploited-vulnerabilities-catalog
Darktrace. (2026). The state of AI cybersecurity 2026. https://www.darktrace.com/resource/the-state-of-ai-cybersecurity-2026
Department of Home Affairs. (2026a, June 11). Horizon 2: Expanding our reach (2026-2028). https://www.homeaffairs.gov.au/about-us/our-portfolios/cyber-security/strategy/horizon-2
Department of Home Affairs. (2026b). Horizon 2 action plan. https://www.homeaffairs.gov.au/cyber-security-subsite/files/horizon-2-action-plan.pdf
Europol. (2026a). The evolving threat landscape: How encryption, proxies and AI are expanding cybercrime. Internet Organised Crime Threat Assessment 2026. https://www.europol.europa.eu/cms/sites/default/files/documents/IOCTA-2026.pdf
Europol. (2026b, June 11). Ransomware gangs cut off from EUR 336 million “AudiA6” crypto laundering pipeline. https://www.europol.europa.eu/media-press/newsroom/news/ransomware-gangs-cut-eur-336-million-audia6-crypto-laundering-pipeline
Europol. (2026c, June 24). Global cyber strike disrupts SocGholish, Amadey and StealC malware networks. https://www.europol.europa.eu/media-press/newsroom/news/global-cyber-strike-disrupts-socgholish-amadey-and-stealc-malware-networks
Federal Bureau of Investigation. (n.d.). Business email compromise. https://www.fbi.gov/how-we-can-help-you/scams-and-safety/common-frauds-and-scams/business-email-compromise
Federal Bureau of Investigation Internet Crime Complaint Center. (2026). 2025 IC3 annual report. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
ITBrief Australia. (2026, June 11). Microsoft and Australia sign digital resilience deal. https://itbrief.com.au/story/microsoft-australia-sign-digital-resilience-deal
Krebs, B. (2026a, June 10). Who runs the ransomware group The Gentlemen? KrebsOnSecurity. https://krebsonsecurity.com/2026/06/who-runs-the-ransomware-group-the-gentlemen/
Krebs, B. (2026b, June 23). Scattered Spider hackers plead guilty on day 1 of trial. KrebsOnSecurity. https://krebsonsecurity.com/2026/06/scattered-spider-hackers-plead-guilty-on-day-1-of-trial/
SecurityWeek. (2026a, June 17). Microsoft Teams relay servers abused in DragonForce ransomware attack. https://www.securityweek.com/microsoft-teams-relay-servers-abused-in-dragonforce-ransomware-attack/
SecurityWeek. (2026b, June 24). New Mistic RAT opens door to several ransomware families. https://www.securityweek.com/new-mistic-rat-opens-door-to-several-ransomware-families/
SecurityWeek. (2026c, June 15). Ransomware attack shuts down mills of Australia’s second-largest sugar producer. https://www.securityweek.com/ransomware-attack-shuts-down-mills-of-australias-second-largest-sugar-producer/
The Hacker News. (2026a, June 4). DoJ disrupts Southeast Asia crypto fraud networks. https://thehackernews.com/2026/06/doj-disrupts-southeast-asia-crypto.html
The Hacker News. (2026b, June 24). Amadey and StealC malware network disrupted, 27M stolen credentials recovered. https://thehackernews.com/2026/06/amadey-and-stealc-malware-network.html
The Hacker News. (2026c, June 29). 236,000 DCloud Uni-App sites used in crypto scams, phishing and wallet drainers. https://thehackernews.com/2026/06/236000-dcloud-uni-app-sites-used-in.html
United States Department of Justice, U.S. Attorney’s Office, Eastern District of Pennsylvania. (2026a, June 11). Two charged in connection with cryptocurrency money laundering service that allegedly laundered over $389 million in unlawful transactions. https://www.justice.gov/usao-edpa/pr/two-charged-connection-cryptocurrency-money-laundering-service-allegedly-laundered
United States Department of Justice. (2026b, June 23). Justice Department seizes backend infrastructure used by Huione Group money laundering services. https://www.justice.gov/opa/pr/justice-department-seizes-backend-infrastructure-used-huione-group-money-laundering-services