Operation Master Leverages GlobalProtect Flaw for Massive Invoice Fraud Campaign
Hackers exploited a GlobalProtect authentication bypass to steal customer data and launch a large-scale invoice fraud campaign, sending over 2.4 million fraudulent messages primarily targeting Brazil.

A sophisticated cybercriminal operation dubbed "Operation Master" has been uncovered, which combined a critical authentication bypass vulnerability in Palo Alto Networks' GlobalProtect VPN with extensive data theft and a massive invoice fraud scheme. The campaign, active from April to mid-September 2026, targeted businesses by gaining unauthorized access to their networks and subsequently leveraging stolen customer data to send millions of fraudulent invoices via email and SMS, predominantly affecting customers in Brazil.
Researchers from SOCRadar identified the operation after tracing an exposed server to a chain of attacker-controlled systems. The attackers exploited CVE-2026-0257, a GlobalProtect authentication bypass flaw, to establish VPN sessions without valid user credentials. This allowed them to scan for and exploit vulnerable gateways, gaining initial access to corporate networks. Evidence of unauthorized access was found on seven GlobalProtect gateways across four countries.
Beyond the VPN compromise, the threat actors also conducted automated SQL injection attacks against at least nine database systems, exfiltrating sensitive customer information. In one instance, a single billing server yielded 24,558 debtor records, including contact details ripe for exploitation. The attackers also harvested credential-related files and utilized AdaptixC2, a known remote-access framework, to maintain control over compromised Windows servers, indicating a persistent presence within victim environments.
The stolen data was not merely for sale; it formed the backbone of a large-scale invoice fraud operation. The attackers deployed a shared fraud panel capable of impersonating various utility providers, customizing its branding and message templates. This platform was used to send a staggering volume of communications: by September 16, it had recorded 2,468,335 emails and 1,487,294 SMS messages, alongside templates for WhatsApp messages containing links to fraudulent invoices.
The fraudulent invoices were designed to appear highly convincing, often incorporating genuine customer details and mimicking legitimate billing documents. The panel generated hundreds of thousands of personalized short links, with a significant number of clicks recorded, indicating successful engagement with potential victims. While the total attempted fraud value reached over R$150 million, it remains unclear how much of this was successfully collected by the attackers.
Operation Master also employed more advanced social engineering tactics, including Microsoft 365 device-code phishing and vishing (voice phishing) attempts to obtain verification codes. These methods aimed to bypass multi-factor authentication and gain direct access to user accounts or sensitive information, further complicating defense efforts.
While the exposed infrastructure went offline in mid-September, it is uncertain whether the operation has ceased or simply relocated. SOCRadar recommends that organizations patch GlobalProtect devices, review VPN session logs, limit database command execution, and monitor for suspicious DNS traffic. Consumers are advised to verify unexpected invoices through trusted channels before making payments.
The campaign highlights a dangerous convergence of network intrusion techniques and large-scale fraud, demonstrating how stolen credentials and customer data can be weaponized to conduct sophisticated, high-volume attacks with a significant potential for financial gain.