📝 Show notes
CyberAware Daily — 2026-09-10
- Case File Thursday: the Xinbi Guarantee scam marketplace disrupted by U.S. authorities, with 52.8 million dollars in crypto frozen
- How scam supply chains work: stolen logins, infostealers, and why your details end up for sale
- New research on infostealer logs exposing reusable AI tokens that can bypass multi-factor authentication
- DarkWatch flags an active ransomware leak site: what leak sites are and why they exist
- Practical steps: unique passwords, two-factor everywhere, and the callback rule for bank calls
More at https://cyberawareuk.co.uk
📄 Full transcript
It's Thursday, and that means it's case file day.
We take one real scam, pull it apart, and show you exactly how to spot it before it costs you.
So what are we looking at today?
Today we're looking at the Sheenby Guarantee Marketplace.
It was a huge online scam bazaar, and this week US authorities announced they'd disrupted it and frozen $52.8 million in crypto.
$52 million. That's a lot of money taken from people.
It is. And the way Sheenby worked is the part that matters for us.
It was basically a shop where criminals bought and sold stolen data, fake documents, and scam tools.
So it's not one scammer calling your mum. It's a whole supply chain.
Exactly. And that's the lesson.
The person who rings you pretending to be from your bank isn't working alone.
They bought your details from a place like Sheenby.
How did they get those details in the first place?
Often through infostulars.
Little bits of software that sneak onto a device, grab saved passwords and logins, and ship them off to be sold.
And I saw a headline today about infostular logs exposing AI tokens that can bypass multi-factor authentication.
That's right.
If your login token is stolen, the bad guys can sometimes replay it and skip past the code sent to your phone.
That's why we keep saying don't reuse passwords and don't ignore updates.
What about the ransomware side?
Darkwatch has flagged an active dark web leak site today.
It's a ransomware group's shame page where they dump stolen files to pressure victims.
We won't name it, but it's live and responding.
So the takeaway from all this?
If your details are already out there, you can't undo that.
But you can make them useless.
Change reused passwords, turn on two-factor wherever you can, and never click a link in a message that's asking for money or logins.
And if someone calls claiming to be your bank?
Hang up, wait a minute, and call the number on the back of your card.
Every time.
That one habit beats almost every scam we talk about.
That's your one thing for today.
One thing.
Do it today, not tomorrow.
We'll be back tomorrow with more.
Stay sharp.