A VPN bypass became a data pipeline
A financially motivated threat actor built an end-to-end operation that starts with a VPN vulnerability and ends in consumers' inboxes and text messages. The campaign, tracked under the name "masterblack," combined mass internet scanning, database attacks, and a purpose-built fraud panel to turn stolen business records into a bill-payment scam running at industrial scale.
What happened
The operator exploited CVE-2026-0257, an authentication bypass in Palo Alto Networks' GlobalProtect VPN, to open sessions on exposed gateways without valid credentials. Getting there took volume: hundreds of millions of IP addresses were scanned and filtered down to promising targets, which were then fed into an automated exploitation loop. Investigators confirmed working, credential-free sessions on seven separate gateways.
Once inside, the attacker pivoted to automated SQL injection, pulling data out of at least nine systems. On one billing server, database commands were used to read customer records, with the stolen data quietly exfiltrated through unusually structured DNS queries rather than a conventional upload — a technique built to slip past network monitoring. One reconstructed theft alone produced more than 24,000 debtor records complete with contact details. To maintain access, the operator used AdaptixC2, a command-and-control framework, to control at least two compromised Windows servers.
The stolen records didn't stay put. An operator persona had already been advertising stolen energy-sector data on underground forums weeks before the same organizations' details turned up loaded into fraud campaigns — a two-track model of selling data first, then using it directly.
Fake bills, real scale
The payoff was a fraud panel that could be rebranded on demand to impersonate different utility providers. It ran on roughly a dozen hijacked Microsoft 365 mailboxes for email, eight messaging gateways for SMS, and WhatsApp templates linking to fraudulent invoices. By mid-September, the panel had generated over 622,000 personalized short links and logged more than 317,000 clicks; it had sent north of 2.4 million fraudulent emails and close to 1.5 million SMS messages. Some payment pages displayed genuine customer names and mirrored real invoice formatting, making the fake bills harder to spot. Logged invoice values topped the equivalent of tens of millions of dollars in exposure — though neither the logged nor the clicked totals prove money actually changed hands.
The operation didn't stop at fake invoices. Investigators also found Microsoft 365 device-code phishing and phone-based social engineering (vishing) attempting to harvest live verification codes and login approvals — including a template impersonating a digital-identity app's fraud alert, designed to push a victim into approving a login on a real sign-in page.
The exposed infrastructure behind the campaign went dark in mid-September, but it remains unclear whether the operation shut down or simply relocated.
What to do
For organizations: confirm whether your GlobalProtect deployment is affected by CVE-2026-0257 and patch immediately; audit VPN logs for sessions that don't map to a real authentication event; restrict and monitor database command execution to limit the blast radius of SQL injection; and watch for unusual outbound DNS traffic, which is an increasingly common exfiltration channel. Review device-code sign-in approvals and any bulk mail sent from institutional accounts for signs of hijacked mailboxes.
For consumers: treat an unexpected bill arriving by text, email, or WhatsApp as a reason to slow down, not pay up. Verify the amount through a trusted, independently known channel — your account portal or a phone number from a previous statement — before paying anything. If you get an unsolicited "new device login" alert or call asking you to approve a sign-in or read out a code, don't act on it in the moment; check your account directly instead.
