US, UK and Canada disrupt $45M crypto theft in Operation Atlantic

2026-04-14T14:52:11Z4b8f55bb236066080c78004cb75c4f4a521cf976db9dd3955ea690d4c2e1c232
AdobeAppleBooking.com breach','signal forensics','iPhone forensics','data-CISACVE-2025-0520Claude impersonationCraft CMSDLL sideloadingFortinetKnown Exploited VulnerabilitiesLaravelMicrosoft ExchangeMicrosoft WindowsOperation AtlanticPlugXRCERockstar GamesShinyHuntersShowDoccrypto theftcryptocurrencydata leakfake installerlaw enforcementmalware

What happened

Multiple high-impact cyber incidents reported: international law enforcement (US/UK/Canada) disrupted a crypto theft network in ‘Operation Atlantic,’ identifying ~$45M in stolen assets and freezing ~$12M for victim restitution. ShinyHunters allegedly leaked an 8.1GB dataset tied to Rockstar Games (anti-cheat source, analytics, support data). A critical ShowDoc RCE (CVE-2025-0520, CVSS 9.4) is being actively exploited. CISA added multiple vendor flaws (Adobe, Fortinet, Microsoft Exchange/Windows, Apple/Laravel/Craft CMS referenced) to its Known Exploited Vulnerabilities catalog. A fake “Claude”

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
4b8f55bb236066080c78004cb75c4f4a521cf976db9dd3955ea690d4c2e1c232
Enrichment time
2026-04-14T14:52:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.