:

TELEGRAM HOSTS SANCTIONED $21B CRYPTO SCAM MARKETPLACE

INDUSTRY DESK1 MIN READ
TUE, APR 14, 2026

■ AI-SUMMARIZED FROM 2 SOURCES ▸ TIMELINE

The UK designated Xinbi Guarantee as an enabler of cryptocurrency scams and human trafficking weeks ago. The operation continues operating openly on Telegram.

Xinbi Guarantee, a platform facilitating crypto fraud schemes worth $21 billion, remains active on Telegram despite recent UK sanctions. British authorities designated the operation as an enabler of scammers and human trafficking, yet the marketplace persists in plain view on the messaging platform. The designation underscores persistent gaps in content moderation across messaging apps used for illicit financial activity. Telegram has faced repeated criticism for hosting black markets and criminal networks, though the platform maintains policies against such activity. Xinbi Guarantee allegedly connects scammers with victims through organized networks, with proceeds linked to human trafficking operations. The continued presence highlights challenges law enforcement faces in shutting down decentralized criminal infrastructure on platforms designed for privacy. It remains unclear whether Telegram has received formal requests to remove the operation or what steps, if any, the platform plans to take.

■ SOURCES

WiredBloomberg Tech

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware groups are actively exploiting a high-severity Windows Task Host vulnerability. The flaw was previously flagged as under active exploitation in April.

1H AGOSecurity Desk

Microsoft has begun removing the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11, citing widespread abuse by cybercriminals. The tool is being eliminated from Windows 11 versions 24H2 and 25H2.

4H AGOSecurity Desk

Israel has established a fabricated think tank apparently designed to influence AI chatbot outputs and shape how these systems respond to queries about Israeli policy. The scheme highlights vulnerabilities in how large language models source and validate information.

9H AGOAI Desk

A threat actor claims to have stolen employee databases from Microsoft Azure infrastructure across multiple Fortune 500 companies using compromised credentials. The stolen records are now being offered for sale.

16H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.