Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
enforcement-actionstate-sponsored-espionagephishing-campaign-intelligencecryptocurrency-platform-risk

Year-End Cybersecurity Review: Major Law Enforcement Actions and Notable Incidents

Updated 3mo agoFirst seen Dec 26, 20252 sources

Law enforcement agencies worldwide achieved significant victories against cybercriminals in 2025, including the takedown of Ukrainian call centers defrauding Europeans of €10 million, the seizure of servers from the E-Note crypto exchange laundering $70 million, and the arrest of individuals aiding state-backed hacking groups. Authorities also dismantled infrastructure supporting ransomware and account takeover operations, with notable convictions such as the prison sentence for the "evil twin" WiFi hacker and the seizure of the Cryptomixer crypto mixer, which laundered €1.3 billion since 2016. These actions reflect a growing trend of international cooperation, combining legal, operational, and financial measures to disrupt cybercrime and hold perpetrators accountable.

In addition to law enforcement successes, 2025 saw a range of high-profile cyber incidents and campaigns. Notable events included a massive cyberattack on Venezuela’s oil and gas infrastructure, suspected to be linked to U.S. operations, and targeted phishing campaigns against Russian military personnel using malicious Excel files. Iranian hackers exploited known vulnerabilities to breach Israeli institutions outside the country’s critical infrastructure sector, exposing gaps in cybersecurity mandates for hospitals, universities, and government ministries. These incidents underscore the evolving tactics of both state and non-state actors and the persistent vulnerabilities in global cyber defenses.

Share:
Year-End Cybersecurity Review: Major Law Enforcement Actions and Notable Incidents
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Dec 22, 20256mo ago

Kuaishou breach hits China's tech sector

China's technology sector was affected by a major breach at Kuaishou. The incident was reported during the week of December 22-26, 2025.

Iranian hackers breach Israeli institutions via known vulnerabilities

Iranian hackers exploited known vulnerabilities to compromise Israeli institutions outside the country's critical infrastructure. The intrusions were reported during the week of December 22-26, 2025.

Russian military personnel targeted with fake concert invite phishing

A phishing campaign used fake New Year concert invitations to target Russian military personnel. The activity was reported during the week of December 22-26, 2025.

Venezuela's oil and gas infrastructure hit by major cyberattack

Venezuela's oil and gas infrastructure was struck by a massive cyberattack that experts suspected may have been a U.S. operation. The incident was described as a possible escalation in geopolitical cyber conflict during the week of December 22-26, 2025.

FBI expands its global biometrics reach

The FBI expanded its global biometrics capabilities or access, according to policy and security developments reported that week. The move was noted during the week of December 22-26, 2025.

South Korea passes controversial 'fake news' bill

South Korea enacted a controversial 'fake news' bill amid broader cyber and information security policy changes. The development was reported during the week of December 22-26, 2025.

Japan adopts active cyber defense law

Japan passed or adopted an active cyber defense law as part of cybersecurity policy developments reported that week. The measure was highlighted during the week of December 22-26, 2025.

Pakistan Consulate in the U.S. warns of visa phishing scam

The Pakistan Consulate in the United States issued a warning about a critical phishing scam targeting visa applicants. The warning was reported during the week of December 22-26, 2025.

Shinsegae Group discloses employee and subcontractor data breach

South Korea's Shinsegae Group experienced a data breach affecting about 80,000 employees and subcontractors. The breach was reported during the week of December 22-26, 2025.

France's La Poste disrupted by cyberattack claimed by Noname057(16)

France's postal service suffered operational disruption from a cyberattack that was claimed by the pro-Russian hacktivist group Noname057(16). The incident was reported during the week of December 22-26, 2025.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

44 LINKEDOpen in app
Affected products
1 linked
Thorium
Organizations
15 linked
Macquarie BankTeam CymruChevronResecurityKuaishou TechnologyIntezerDataDomeShinsegae I&CKorean RegisterGitHubSentinelOneGroup-IBMixpanelCryptomixer.ioE-Note
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.