Operation Master: Stolen Data Sold Online, Then Reused for Automated Invoice Fraud
SOCRadar's Threat Research Unit has exposed a cybercrime campaign called Operation Master, which combined network intrusion, data theft and financial fraud into a single pipeline. The attackers compromised enterprise networks and VPN systems, stole customer and billing databases, and initially sold portions of this data on underground forums under a criminal persona.
Later, the same threat actor repurposed the stolen data to power a multi-tenant, automated phishing and invoice fraud platform, effectively monetising the information twice. The operation ran from April to mid-September 2026 and spanned multiple countries, evolving from early AI-assisted tooling and stolen energy-sector data sales to more advanced network exploitation and large-scale email and SMS fraud campaigns. Researchers traced the operation back to a single misconfigured server, which ultimately revealed three generations of infrastructure used throughout the campaign.
The case illustrates how stolen corporate data does not simply disappear after a breach: it can be resold on dark web markets and then reused to build automated fraud schemes targeting other victims, extending the damage well beyond the original intrusion.