Zelle Faces New York Lawsuit Over Fraud Controls; Global Breaches Mount
Zelle must face a New York lawsuit alleging inadequate fraud controls, while other incidents include a hack wiping Romania's land registry and a fine for 23andMe.

A New York judge has ruled that Zelle, the popular bank-owned money transfer service, must face a lawsuit alleging insufficient fraud controls. The decision by New York County Supreme Court Judge Phaedra Perry-Bond rejected Early Warning Services' (EWS) attempts to dismiss the case, stating that the firm "knew Zelle was not safe." EWS, whose major shareholders include JPMorgan Chase, Bank of America, and Wells Fargo, is accused of misleading consumers about the security of its "send and receive money fast" service, which allegedly allowed fraudsters to quickly dissipate funds, leaving victims with no recourse due to the irrevocability of transfers.
New York Attorney General Letitia James initiated the lawsuit in August 2025, alleging that EWS prioritized speed over safeguards to compete with nonbank payment apps. State prosecutors claim Zelle facilitated over $1 billion in fraudulent transactions between 2019 and 2022. EWS has stated its intention to appeal, with a spokesperson calling the lawsuit a "political gain" tactic. This legal challenge highlights ongoing concerns about the security of digital payment platforms and the responsibility of financial institutions in preventing fraud.
In a separate incident, Romania's national land registry database was effectively wiped by a cyberattack, severely disrupting real estate transactions. Threat intelligence firm Kela attributed the attack, which began on July 14, to a threat actor known as ByteToBreach. The attacker reportedly gained access using valid credentials, bypassed perimeter defenses, and then proceeded to delete critical data and disable essential services, including the registry database, official applications, websites, and email servers. This incident brought Romania's real estate market to a standstill.
The attack also involved the theft of sensitive information, including employee credentials and internal network details, which the attacker then offered for sale on a hacking forum. The destructive actions followed an unsuccessful extortion attempt. Romanian authorities are now working to rebuild the affected infrastructure using an offline backup. Cybersecurity experts have described the incident as one of the most severe cybersecurity events in Romania's public administration digitalization history.
Meanwhile, Spain's data protection authority has fined genetic testing company 23andMe approximately $2.7 million for cybersecurity failures that contributed to its 2023 credential-stuffing attack. This breach exposed the personal information of 6.9 million users globally, including over 2,600 in Spain. The Agencia Española de Protección de Datos found that 23andMe lacked adequate safeguards for sensitive genetic data, violating the EU's General Data Protection Regulation. Specific failures included the absence of mandatory multifactor authentication and insufficient controls to limit repeated access or data downloads from single IP addresses.
The Spanish penalty follows a significant settlement in the United States, where 23andMe agreed to a $46.75 million payout to victims as part of its bankruptcy proceedings. The regulator also criticized 23andMe for delaying its notification to Spanish authorities by 12 days after learning of the incident, underscoring the importance of timely breach reporting.
In Australia, Origin Energy, the country's second-largest energy company, confirmed a customer data breach. Hackers gained unauthorized access to and disclosed some customer data, affecting an unknown number of Origin's 4.8 million accounts. The company acknowledged the attack after a sample of compromised customer records, including names, addresses, and dates of birth, was reportedly shared with a national newspaper. The full scope and impact of this breach are still under investigation.
Finally, malware has been discovered hidden within Microsoft 365 calendars, posing a new threat vector. While details are still emerging, this discovery suggests a sophisticated method for delivering malicious payloads, potentially bypassing traditional security measures by leveraging a commonly used business application. This highlights the evolving tactics of threat actors seeking to infiltrate corporate environments.