:

HIDDEN RELAY MARKET FUELS TOKEN RESALE AND FRAUD

INDUSTRY DESK1 MIN READ
SUN, JUL 26, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A thriving underground market for token relays enables credential resellers and fraudsters to bypass security controls. The infrastructure bypasses authentication mechanisms designed to prevent unauthorized access.

Security researchers have exposed a relay market where attackers purchase and resell authentication tokens, circumventing traditional security barriers. These relays act as intermediaries, allowing stolen or compromised credentials to be used across multiple platforms and services. The market operates through specialized brokers who aggregate tokens from various sources—including credential theft, phishing, and compromised accounts. Buyers gain access to accounts without triggering suspicious login alerts, as requests appear to originate from legitimate sessions. Fraud operations exploit this infrastructure for account takeover, payment fraud, and identity theft. The relay market's accessibility and low barriers to entry have accelerated its growth. Security teams face challenges detecting relay-based attacks since they appear as legitimate session activity. Experts recommend implementing device fingerprinting, IP geolocation checks, and behavioral analysis alongside traditional two-factor authentication. Organizations should monitor for unusual token usage patterns and implement token binding to prevent relay attacks.

■ SOURCES

Hacker News

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A data theft campaign exploits misconfigured Salesforce Experience Cloud and ServiceNow customer portals to harvest sensitive information. The attackers use custom tools to access data exposed to anonymous users.

4H AGOIndustry Desk

A compromised AI package exposed credentials from 2,500 users in a large-scale supply-chain attack. Attackers scraped and exfiltrated terabytes of sensitive data.

5H AGOAI Desk

A new Android malware combo pairs NFC relay malware called WindRelay with the SpyNote remote administration tool to steal credit card data and conduct fraud in real time.

5H AGOSecurity Desk

Unknown actors are conducting widespread vulnerability scans while impersonating AI assistants like ClaudeBot, according to reports circulating in security communities.

6H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.