ZeroFox Daily Intelligence Brief - September 10, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - September 10, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Xinbi Infrastructure Disrupted for Supporting Transnational Scam Operations
- INC Ransomware Group Claims Westfield Public Schools Outage
- Scammers Extort Instagram Creators Using Fake Copyright Claims
Xinbi Infrastructure Disrupted for Supporting Transnational Scam Operations
What we know: The U.S. Treasury has sanctioned Xinbi Guarantee, a Chinese-language marketplace for scam services, and seized its Telegram infrastructure and crypto wallets. The action also targeted two other entities for providing encrypted communications and cryptocurrency payment services that allegedly helped Xinbi maintain its criminal operations.
Context: Xinbi Guarantee operated a Telegram-based marketplace connecting scam operators with vendors offering money laundering, scam-site creation, and trafficking-related services, with some U.S. victims’ funds traced to vendors on the platform. The marketplace has processed more than USD 24 billion and supported scam centers, cyber crime, and money laundering. In March 2026, the United Kingdom had also sanctioned Xinbi Guarantee.
Analyst note: Xinbi's operators, following the disruption, are likely to attempt to restore disrupted services under replacement infrastructure or a different name. However, the targeting of the two support entities, are likely to complicate efforts to replace the communications and payment infrastructure that supported Xinbi, forcing operators to diversify providers, rebuild components, and establish new cryptocurrency channels.
INC Ransomware Group Claims Westfield Public Schools Outage
Source: https://cloud.zerofox.com/intelligence_new/advanced_dark_web/110428
What we know: Westfield Public Schools in New Jersey reportedly faced a network outage that disrupted its digital operations. INC Ransom group had claimed to have targeted the community public school district on its leak site.
Context: The outage disabled internet and Wi-Fi access, online instructional tools, telephone lines, clocks, and the student information system. INC Ransom published two screenshots as proof of the claimed intrusion. The district has not confirmed a cyberattack, schools reportedly remained open, and emergency communications continued to function.
Analyst note: The timing of the disruption–coinciding with the critical first week of school–is very likely intended to maximize operational disruption and institutional pressure to pay, given the dependency on digital systems. The available evidence alone is unlikely to conclusively establish INC Ransom as the responsible actor, particularly as the district has not confirmed a cyberattack. If the claim is validated, the incident could almost certainly result in operational disruptions, exposure of sensitive student and staff data, and additional legal consequences.
Scammers Extort Instagram Creators Using Fake Copyright Claims
Source: https://www.bbc.com/news/articles/cjw54ww73qjo
What we know: Scammers are reportedly targeting Instagram creators with fraudulent copyright claims threatening content removals, account suspensions, or demonetization, before demanding money to withdraw the claims. The activity has affected creators with large audiences, including one account with more than 1.5 million followers whose owner paid USD 50 in cryptocurrency to regain access after the account was temporarily suspended.
Context: The scammers exploited Instagram’s copyright-reporting process by submitting repeated claims and then contacting affected users through private messaging platforms such as Telegram to demand payment. Three individuals admitted filing copyright strikes despite not being the rights holders, while one claimant reportedly demanded USD 900 to withdraw a complaint. Meta reportedly says it restored affected creators' content and added protections.
Analyst note: Use of AI tools is likely to help threat actors scale this campaign further, echoing prior copyright-strike extortion against YouTube creators. Affected creators should document and report attempts rather than pay, as payment has not reliably stopped renewed strikes.
DEEP AND DARK WEB INTELLIGENCE
Telegram user APT IRAN: Pro-Iran threat actor group "APT IRAN" has warned of an escalating cyberattack campaign targeting U.S. critical infrastructure ahead of the 9/11 anniversary. The group also claimed responsibility for cyberattacks against AT&T internet services and water utilities in Texas. An AT&T internet outage affecting North Texas was reported on September 7, but the telecom company refuted claims of a cyberattack, instead attributing the outage to an attempted cable theft.
- APT IRAN is closely linked to the Islamic Revolutionary Guard Corps (IRGC)-affiliated threat actor “CyberAv3ngers” and has previously claimed attacks on water systems across at least six U.S. states. If legitimate, the attacks very likely represent an escalation of Iran-linked retaliatory cyber operations in response to U.S. military actions against Iran.
VULNERABILITY AND EXPLOIT INTELLIGENCE
Fortinet patches 10 vulnerabilities: Fortinet has patched 10 vulnerabilities, including two flaws that could enable remote, unauthenticated attackers to bypass authentication or proxy users’ browser traffic through malicious websites, while other issues could expose sensitive information or enable man-in-the-middle attacks. The remaining vulnerabilities could enable arbitrary code execution, denial-of-service, process termination, and other disruptive actions.
Affected products: Fortinet’s FortiMonitorOnSight, FortiPAM, FortiSandbox, FortiOS, FortiProxy, FortiManager, and other products.
Tags: DIB, tlp:green