Find notable cyber news and cases, enriched with sources, timelines, and signals.

Global Profit PhaaS logistics-fraud platform

Threat Actor Meta
First reported
Last updated
Happening score
H score 27
1 unique sources, 1 articles

Summary

Hide ▲

Global Profit (aka MC Profit Always) is a PhaaS operation tied to a Russian-Armenian threat actor that sells logistics-focused credential theft to other operators. The platform targets the freight and logistics sector, using bogus emails and impersonated daily-use services to harvest logins and MFA codes. It reportedly collected over 1,600 unique login credentials between September 2025 and February 2026, enabling downstream fraud such as invoice redirection and double-brokering.

Related Happenings

Cyber-enabled cargo theft is surging across transportation and logistics in 2025

Trend
H score42 First: 30.04.2026 19:32 Last: 30.04.2026 19:32 Sources 1

About this happening: Cyber-enabled cargo theft is surging across transportation and logistics, driving nearly $725 million in estimated losses in the U.S. and Canada and materially inc...

Tax-season credential phishing and RMM malware campaign

Campaign
H score42 First: 30.03.2026 18:00 Last: 30.03.2026 18:00 Sources 1

About this happening: A tax-themed cyber campaign is using credential phishing, remote monitoring and management (RMM) tools, and fraud lures to target people handling financial data*...

Diesel Vortex freight and logistics phishing campaign

Campaign
H score29 First: 25.02.2026 01:57 Last: 25.02.2026 01:57 Sources 1

About this happening: The Diesel Vortex phishing campaign is stealing freight-sector credentials across the U.S. and Europe, raising the risk of account compromise, cargo fraud, and downstream...

Timeline

  1. 24.09.2026 15:05 2 articles · 2h ago

    Global Profit PhaaS targets freight and logistics operators with bogus emails

    Initial Disclosure

    A Russian-Armenian threat actor is behind the Global Profit (aka MC Profit Always) phishing-as-a-service platform, which targets the freight and logistics sector with bogus emails and reportedly stole over 1,600 unique login credentials between September 2025 and February 2026. Have I Been Squatted also said the activity likely has an Armenian or Russian nexus.

    Show sources