Hackers Exploit GlobalProtect Flaw and Turn Stolen Data Into 2.4 Million Fraud Messages
Key Takeaways A sophisticated cybercrime operation, dubbed “Operation Master,” leveraged a GlobalProtect VPN flaw to infiltrate corporate networks and steal sensitive customer data. The...
Key Takeaways
- A sophisticated cybercrime operation, dubbed “Operation Master,” leveraged a GlobalProtect VPN flaw to infiltrate corporate networks and steal sensitive customer data.
- The stolen information was then used to fuel a massive invoice fraud scheme, primarily targeting Brazilian customers, sending millions of fraudulent emails and SMS messages.
- The attack chain involved exploiting CVE-2026-0257, a critical authentication bypass vulnerability in GlobalProtect, alongside SQL injection attacks on web applications.
- While the campaign generated over 2.4 million fraudulent messages, the exact financial impact on victims remains unconfirmed.
- Organizations are urged to patch vulnerable systems, implement robust monitoring, and educate customers about sophisticated phishing tactics.
A complex cybercrime campaign, dubbed “Operation Master,” successfully breached corporate networks, exfiltrated customer records, and subsequently weaponized this sensitive data to dispatch highly convincing fraudulent invoices. The operation seamlessly integrated a VPN login bypass, targeted web application attacks, and a large-scale invoice fraud system primarily aimed at consumers in Brazil.
Table Of Content
This malicious activity spanned from April to mid-September 2026. Investigators uncovered evidence of unauthorized access across seven GlobalProtect gateways situated in four distinct countries. Furthermore, stolen records were identified from at least nine separate database systems, highlighting the breadth of the data compromise.
The attackers meticulously repurposed the acquired customer information to craft personalized and credible fraudulent payment requests. Security researchers from SOCRadar unearthed the intricate details of this operation after tracing an exposed server back through a series of attacker-controlled systems. SOCRadar said in a report that these intrusions fed a sophisticated platform capable of disseminating millions of messages via both email and SMS channels.
Despite the substantial scale of the messaging campaign, the total financial gains for the perpetrators are not yet clear. By September 16, the fraud management panel recorded a staggering 2,468,335 emails and 1,487,294 SMS messages sent. However, the recorded payment attempts do not definitively confirm that victims transferred the full amounts requested by the fraudsters.
Hackers Exploit GlobalProtect Flaw
The attackers initiated their incursions by exploiting CVE-2026-0257, an authentication bypass vulnerability affecting GlobalProtect. This flaw enabled them to establish VPN sessions without requiring valid user credentials. Their methodology involved scanning hundreds of millions of IP addresses, identifying potentially vulnerable gateways, and then feeding these candidates into an automated exploitation routine. Previous analyses of the GlobalProtect bypass vulnerability have detailed the specific configuration conditions that render this flaw exploitable.
Forensic analysis of recovered connection logs, including assigned VPN addresses and network routes, conclusively demonstrated successful sessions on seven distinct gateways. In parallel, automated SQL injection attacks were deployed to extract information from at least nine other systems. On one particular billing server, the threat actor utilized database command execution capabilities to read sensitive records and exfiltrate data through unusually structured DNS requests.
One reconstructed data theft incident alone yielded 24,558 debtor records, complete with contact information that could facilitate future targeting. Beyond this, the attacker also harvested credential-related files and leveraged the AdaptixC2 framework to establish control over at least two Windows server identities. Those familiar with reporting on AdaptixC2 abuse will understand how such an established remote-control framework can significantly extend the persistence and capabilities of an intrusion following initial access.
Investigators established a link between an operator persona actively selling stolen energy-sector data and the subsequent fraud infrastructure. Intriguingly, the same organizations whose data was being offered for sale appeared in the fraud campaign listings merely weeks later. This sequence of events strongly suggests a dual monetization strategy: initially selling the stolen records, and then directly leveraging them to extort payments. The exposed systems unequivocally demonstrated the speed with which stolen business records could transition from a network intrusion to personalized, large-scale fraudulent messages delivered directly to unsuspecting customers.
Fake Bills at Industrial Scale
The attackers constructed a sophisticated, shared fraud panel designed to dynamically alter its branding and message templates, enabling it to impersonate various utility providers. This infrastructure utilized approximately 12 compromised Microsoft 365 mailboxes for email distribution and eight messaging gateways for SMS delivery. Additionally, WhatsApp templates were employed, often containing links directing recipients to fraudulent invoice documents.
By September 14, the fraud panel had generated 622,666 personalized short links, logging 317,696 click events. Certain payment pages were meticulously designed to display genuine customer details and mirror authentic invoice documents, making it exceedingly difficult for victims to discern their fraudulent nature. The cumulative value of logged invoices totaled R$150.4 million, with clicked invoices representing an exposure of R$38.9 million; however, these figures do not confirm actual money received by the attackers.
Investigators also discovered evidence of Microsoft 365 device-code phishing and phone-based attempts to obtain verification codes. These methods diverge from simple fake-bill links, as they require victims to approve access via a legitimate sign-in page or during a live phone call. Separate reports on device-code phishing underscore why familiar login screens do not inherently guarantee the safety of a request. Organizations affected by data theft should proactively issue warnings to their customers regarding these highly convincing impersonation tactics.
What You Should Do
- Patch Vulnerabilities Immediately: Ensure all remote-access devices, especially GlobalProtect gateways, are patched against known vulnerabilities like CVE-2026-0257.
- Review Authentication Configurations: Verify if authentication override is necessary for any systems and, if not, disable it to prevent bypasses.
- Monitor VPN Sessions: Implement robust monitoring for unusual or unauthorized VPN sessions and investigate any suspicious activity promptly.
- Limit Database Privileges: Restrict database command execution capabilities to only essential users and processes to mitigate the impact of SQL injection attacks.
- Inspect DNS Traffic: Monitor DNS traffic for unusual patterns or exfiltration attempts, which can indicate data theft.
- Watch for Cloud Sync Anomalies: Keep an eye on unexpected cloud synchronization activity, as this can be a sign of compromised accounts.
- Review Device-Code Approvals: Scrutinize all device-code approvals and bulk mail originating from institutional accounts for signs of phishing or compromise.
- Educate Customers: If your organization has experienced a data breach, proactively warn customers about potential impersonation attempts and advise them to verify unexpected bills or requests through trusted, pre-established communication channels.
- Verify Unexpected Bills: As a consumer, always verify unexpected bills or payment requests directly with the service provider using official contact information, not links or numbers provided in suspicious messages.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.