Threat Intelligence

Operation Master: Stolen Data Sold Online, Then Reused for Automated Invoice Fraud

SOCRadar · 24 Sept 2026
Key Takeaway Small businesses should monitor for their data appearing on dark web forums and treat any breach notification seriously, since stolen records can be reused for follow-on fraud long after the initial theft.

SOCRadar's Threat Research Unit has exposed a cybercrime campaign called Operation Master, which combined network intrusion, data theft and financial fraud into a single pipeline. The attackers compromised enterprise networks and VPN systems, stole customer and billing databases, and initially sold portions of this data on underground forums under a criminal persona.

Later, the same threat actor repurposed the stolen data to power a multi-tenant, automated phishing and invoice fraud platform, effectively monetising the information twice. The operation ran from April to mid-September 2026 and spanned multiple countries, evolving from early AI-assisted tooling and stolen energy-sector data sales to more advanced network exploitation and large-scale email and SMS fraud campaigns. Researchers traced the operation back to a single misconfigured server, which ultimately revealed three generations of infrastructure used throughout the campaign.

The case illustrates how stolen corporate data does not simply disappear after a breach: it can be resold on dark web markets and then reused to build automated fraud schemes targeting other victims, extending the damage well beyond the original intrusion.

data breach dark web invoice fraud threat intelligence SOCRadar

Summarised by CISO AI from SOCRadar. We link back to every original so you can read it yourself.