On November 13, 2025, Anthropic, the developer of an artificial intelligence model (“AI”) known as Claude, announced that it had detected and helped disrupt what it believes to be the first cyber espionage campaign orchestrated primarily by autonomous AI agents.1 Anthropic stated that it had “high confidence” that the campaign was orchestrated by a
Discerning Data
Blog Authors
Latest from Discerning Data
Pig Butchering, Phone Farms, and a $15 Billion Forfeiture—Key Takeaways from the Prince Group Cybercrime Indictment
On October 14, 2025, the United States Attorney’s Office in the Eastern District of New York announced the indictment of a corporate executive of a Cambodian-based company for wire fraud and money laundering arising out of a near decade-long “pig butchering” cybercrime scheme, alongside a corresponding civil forfeiture action seeking approximately 12,271 bitcoin—worth approximately $15…
The Lumma Seizure: International Efforts to Take Down a Global Malware Network and How to Reduce Your Risk of Infection
On May 21, 2025, the United States Department of Justice (“DOJ”) announced it had obtained warrants authorizing the seizure of five internet domains used to operate a family of malware known as LummaC2, also referred to as LummaStealer (“Lumma”) that targets customers of the Windows operating system developed by Microsoft Corporation (“Microsoft”). The warrants were…
DHS Playbook for Public Sector GenAI Deployment – Insights for the Private Sector
In January 2025, the Department of Homeland Security (DHS) released its “Playbook for Public Sector Generative Artificial Intelligence Deployment” (the “Playbook”). The Playbook provides valuable insights and actionable steps that can be adapted by the private sector looking to leverage generative artificial intelligence (“GenAI”) technologies.1 The Playbook was drafted under the Biden administration,…
The Wallet Inspectors: The DPRK’s Sophisticated Campaign to Steal Cryptocurrency and How to Protect Yourself
On February 21, 2025, Bybit, one of the world’s largest cryptocurrency exchanges, suffered a cyberattack resulting in the theft of approximately $1.5 billion in Ethereum tokens. This attack marked a new pinnacle in the criminal efforts of cyber actors tied to the Democratic People’s Republic of Korea (“North Korea” or the “DPRK”). In recent years,…
Lessons from PayPal’s $2 Million Cybersecurity Settlement with the New York State Department of Financial Services
Introduction
On January 23, 2025, PayPal settled an enforcement action brought by the New York State Department of Financial Services (NY DFS) for failing to comply with cybersecurity regulations required for financial services businesses under the Department’s supervision. The settlement, which included a $2 million fine and required remedial measures, arose out of a cybersecurity…
Oh No, Canada! Takeaways from the Indictment of a Canadian National Allegedly Responsible for $65 Million DeFi Cryptocurrency Theft
On February 3, 2025, the U.S. Attorney’s Office for the Eastern District of New York (EDNY) unsealed an indictment against Andean Medjedovic, a 22-year-old Canadian national, for allegedly stealing approximately $65 million in cryptocurrency from two decentralized finance (DeFi) protocols, KyberSwap and Indexed Finance. Medjedovic is charged with wire fraud, violation of the Computer Fraud…
The UK Cyber Security and Resilience Bill
Background
The UK government has recently announced that it plans to introduce a Cyber Security and Resilience Bill (Bill). The Bill seeks to update the 2018 Network and Information Security Regulations, which implemented the European Union (EU) NIS 1 Directive when the UK was a member of the EU.
A key driver behind the UK…
Countries Poised to Adopt New Cybersecurity Measures After UN Adopts Major Cybercrime Convention
On August 7, 2024, after three years of negotiation, the United Nation’s Ad Hoc Committee to Elaborate a Comprehensive International Convention on Countering the Use of Information and Communications Technologies for Criminal Purposes unanimously adopted the Convention Against Cybercrime. The Convention now goes to the General Assembly, where it is expected to be adopted.…
New UK Consumer Laws on Fake Reviews, Subscription Contracts and Drip Pricing: Impact on US Businesses
In May of this year, the UK Government passed the Digital Markets, Competition and Consumers Act (DMCC) into law. The DMCC is wide-ranging and covers three key areas: consumer law, digital markets, and merger and antitrust law.
In the first of our series of blog posts, we set out key points on the significant changes…