A major fraud scheme exploiting a vulnerability in GlobalProtect, Palo Alto Networks’ VPN, has surfaced. Dubbed “Operation Master,” the campaign ran from April through mid-September 2026, targeting Brazilian customers with large-scale fake bills built on stolen data. Attackers managed to compromise multiple systems using both credential bypasses and web-application flaws.
How the Attack Unfolded
The operation began with exploitation of vulnerability CVE-2026-0257, a bypass in GlobalProtect’s authentication mechanism. Attackers could establish VPN sessions without valid credentials. They scanned vast numbers of IP addresses, pinpointed exposed gateways, and conducted automated attacks that granted them access to seven GlobalProtect gateways across four countries. Simultaneously, SQL injection attacks against at least nine systems enabled extraction of sensitive customer records. One of the systems fell victim to command-execution attacks that siphoned data through oddly structured DNS requests. A sample theft revealed more than 24,500 debtor records, including names, contact information, and payment-related details. They also seized credential files and used a framework, AdaptixC2, to take control of Windows server identities.
Fake Billing at Massive Scale
After stealing the data, operators pivoted to convincing customers with fraudulent invoices delivered via email, SMS, and even WhatsApp. A shared platform allowed them to morph branding and invoice templates to impersonate utility providers. Email infrastructure leaned on hijacked Microsoft 365 accounts; eight SMS gateways augmented the reach. By mid-September, the operation had sent over 2.4 million messages—2,468,335 via email and 1,487,294 by SMS. Fraudulent invoices’ total logged value reached R$150.4 million (Brazilian reais), while clicked invoices suggested exposure of R$38.9 million. Importantly, those numbers represent attempts rather than confirmed payments made.
The fraud scheme grew more sophisticated with phishing via Microsoft 365 device-code prompts and phone-based verification-code thefts. Attackers impersonated familiar login pages and used social engineering to trick victims into approving access requests, even during calls.
Defending Against It
Security experts recommend several steps for organizations to protect themselves. First: patch any GlobalProtect gateways exposed to CVE-2026-0257 and reassess whether their configurations allow authentication bypass. Also, monitor for abnormal VPN sessions—especially those with unexpected network routes or VPN addresses. Limit execution of arbitrary database commands; keep an eye out for suspicious DNS traffic and abnormal cloud synchronization; review device-code approvals and bulk messaging from institutional email accounts. For ordinary users, any unanticipated bill or invoice should be verified through known channels before paying.
While the exposed infrastructure appeared to go offline in mid-September, investigators cannot confirm whether the fraudsters fully ceased operations or simply restructured them elsewhere.
Indicators of compromise tied to this scheme include lookalike domains such as “igreenfaturas[.]com,” impersonating utility-invoice services, as well as IP addresses connected to operation and control infrastructure. Several SHA-256 file hashes also traced back to malware tools used in the campaign.
What this means: This incident highlights how a single VPN authentication flaw, combined with web vulnerabilities and poor boundary controls, can ripple into a fraud giant. The speed at which records were stolen, weaponized into trustworthy invoices, and delivered en masse shows attackers growing confidence. It reinforces the importance of tightly managed remote access infrastructure, constant auditing of user credentials, and skepticism toward familiar-looking digital requests—even when the branding seems right. Keep software patched, minimize privilege, and treat every invoice with suspicion unless verified.