ICE Locks Up Three Guatemalan Illegal Aliens in Tennessee for Stealing Americans’ Social Security Numbers — One Was Already Deported THREE TIMES

Federal immigration authorities arrested three Guatemalan illegal aliens in Tennessee during an investigation into the alleged fraudulent use of stolen identities and Social Security numbers.

ICE officers arrested Magdalena Gomez-Garcia, Elias Gomez-Garcia, and Eulalia Ordonez-Carmelo on August 4.

All three Guatemalan nationals were reportedly already subject to final orders of removal from the United States, Border Hawk first reported.

Magdalena Gomez-Garcia is accused of stealing the identity of a New York resident and using the victim’s Social Security number to obtain employment in Tennessee.

According to Border Hawk, the American victim discovered that wages earned by someone else were being reported under her Social Security number. She was then forced to contact authorities repeatedly to correct her records.

Gomez-Garcia was first encountered by Border Patrol near San Luis, Arizona, in 2018. She was issued a notice to appear before an immigration judge and received a final removal order in absentia in April 2019.

Yet she allegedly remained in the country and found employment using another person’s identity.

Keep reading

Grand jury indicts former community school superintendent, business partner in $8 million fraud scheme

A federal grand jury has indicted the former superintendent and operator of a local community school and a business partner with wire fraud and other crimes related to an $8 million fraud and kickback scheme.

Leondo Ramone Davenport, 50, of Cincinnati, and Jonathan Larry Ballew, 62, of Phoenix, Arizona, were arrested this morning by federal agents. 

“We’re putting an end to fraudsters exploiting public trust and profiting off of the American taxpayer,” said U.S. Attorney Dominick S. Gerace II. “Offenders should know that my Office will work hard to ensure that those responsible for fraud end up paying the price and come to understand that the juice is not worth the squeeze.”

“This indictment alleges a brazen scheme that stole from both taxpayers and students,” said Assistant Attorney General Colin McDonald of the Justice Department’s National Fraud Enforcement Division. “Education dollars exist to support the learning and development of American children—not to fund the lifestyles of unscrupulous school officials. The Fraud Division commends the work of our federal and state partners whose efforts were essential in bringing these charges and ensuring that those who abuse positions of trust are held accountable.”

“Fraud against the government is fraud against every taxpayer and we are all victims of these schemes,” stated FBI Cincinnati Special Agent in Charge Jason Cromartie. “The FBI and Department of Justice are committed to rooting out fraud and holding accountable those who conduct illegal activities.” 

“This was an egregious kickback scheme by individuals using taxpayer resources to enrich themselves,” Auditor Faber said. “Thanks to the good work of the U.S. Attorney, the FBI and our other partners in law enforcement for pursuing justice in this case. Our investigation also continues, and we look forward to working alongside the Hamilton County Prosecutor’s Office to ensure everyone involved in these crimes is held accountable for their actions.”

Davenport served as the superintendent of Dohn Community High School from 2015 to 2019. Through an  LLC he incorporated, Dohn served as the operator of the school from 2019 until 2024.

Dohn was incorporated in Ohio as a not-for-profit organization around 1999 to serve as an addiction recovery program for high school students. It operated as a community school under Ohio law from approximately 2001 until 2025. In Ohio, a community school created under state law is a public school, independent of any school district.

Ballew incorporated at least four entities allegedly purporting to provide educational services, training, technology, staffing, and school construction and remodeling services to Dohn. 

The eight-count indictment alleges that, from 2021 to 2024, Davenport and Ballew participated in a kickback scheme to defraud the school. Ballew allegedly submitted false and fraudulent invoices to Dohn on behalf of the entities he controlled. Davenport allegedly authorized Dohn to pay the invoices and received a kickback in return. In total, during this time, Davenport allegedly authorized Dohn to pay over $8 million to Ballew and Ballew correspondingly paid over $4 million back to Davenport.

The charging document details that the defendants allegedly spent the money on luxury automobiles and rental properties. For example, in October 2023, Davenport and Ballew both signed a two-year rental agreement for a luxury vacation property near Miami, Florida, for $30,000 per month.

Davenport and Ballew are each charged with wire fraud, a federal crime punishable by up to 20 years in prison and engaging in monetary transactions in property derived from unlawful activity, which carries a potential penalty of up to 10 years in prison.

Dominick S. Gerace II, United States Attorney for the Southern District of Ohio; Jason Cromartie, Special Agent in Charge, Federal Bureau of Investigation (FBI), Cincinnati Division; and Ohio Auditor of State Keith Faber announced the charges. Assistant United States Attorney Matthew C. Singer is representing the United States in this case.

On April 7, the Department of Justice announced the creation of the National Fraud Enforcement Division (“Fraud Division”). The Fraud Division is investigating and prosecuting those who commit fraud against the American people. The Department’s work to combat fraud supports President Trump’s Task Force to Eliminate Fraud, a whole-of-government effort chaired by Vice President J.D. Vance to eliminate fraud, waste, and abuse within Federal benefit programs.

An indictment merely contains allegations, and defendants are presumed innocent unless proven guilty in a court of law.

Keep reading

CrowdStrike and Federal Authorities Dismantle Russian Malware That Secretly Stole Crypto for 8 Years

A campaign of malware operated by Russian cybercriminals for eight years was dismantled by federal authorities in conjunction with the cybersecurity firm CrowdStrike on Thursday. The malware, identified by the security firm as “EggJagger” or as Sality malware, preyed upon thousands of users of virtual currency by engaging in “clipboard hijacking.” The most common method that users of virtual currencies such as Bitcoin and Ethereum employ in order to send currency is to copy a virtual currency address from a web page to a computer’s clipboard and then later to paste the virtual currency address into the corresponding field of a wallet application. The malware sat idle on a user’s computer and then, before the user had a chance to discover the substitution, would change the virtual currency address that had been placed in the user’s clipboard to an address controlled by the cybercriminals, reported CoinDesk.

Once the compromised address was pasted into the user’s wallet software, and the resulting transaction had been confirmed, the cryptocurrency was transferred irretrievably to the attacker. While there was no particular attack functionality that triggered any alerts, the single defense against such an attack was for the user to manually verify the address that they had pasted into the sending field. Typically the first and last characters of a wallet address would be verified against what was expected, but in this case all would need to be checked. The reason for this type of attack to have persisted for some eight years is that it is an easy one to implement, and places the onus of security on the end user to perform correctly in these situations.

Analysis by CrowdStrike has uncovered the malfeit cryptocurrency operators amassed 12.1 million rubles ($150,000) in the years the malware was active and operating, however most of the stolen cryptocurrency had been deposited into online wallets, remained untouched by the cybercriminals. However with the recent and ongoing surge in value of many of the world’s most popular cryptocurrencies the hacker’s abandoned stash has appreciated significantly to an estimated $1.35m. The returns on such a relatively simple attack vector to extract cryptocurrency from individuals is significant and in this instance highlights that such malware, whilst still active after eight years, continues to reap significant returns on little more than foraging for victims, capitalizing on default settings and exploiting human nature of individuals utilizing online cryptocurrency services.

A major weakness of the botnet infrastructure behind EggJagger was the minimal security controls in place around the network of infected computers. As long as a compromised computer was responding to commands appropriately, it could be included in the botnet of other compromised systems. In a live demonstration of the vulnerability on Monday at CrowdStrike’s Day Zero summit in Las Vegas, the security team of researchers used the same hole to subvert EggJagger and replace the legitimate peer addresses embedded in the malware with the IP addresses of their own servers. Suddenly, more than 15,000 computers infected with EggJagger around the world lost connection to their command-and-control servers in an instant, bringing the whole operation crashing down.

The high-profile takedown of the long-running Russian malware operation highlighted the persistent cyber threats to financial infrastructure emanating from Russia, as well as the growing role of the private cybersecurity sector working in conjunction with law enforcement to counter threats to the financial system. Despite having developed sophisticated operational security measures over an eight-year period, Sality ultimately relied on a relatively simple vector to steal cryptocurrency from thousands of individuals and businesses – that of exploiting routine human practices. The botnet’s vulnerability to having its peer connections severed by not authenticating the connections was identified by law enforcement and subsequently exploited to dismantle the operation in a single action, bringing an end to a threat that had affected thousands of individuals and businesses across South Florida and the country.

Keep reading

Accused Murderer Out on $600K Bond Recruited USPS Carriers to Steal Nearly $24 MILLION in Checks — Then Sold Them on Telegram

A 28-year-old Houston man already free on a $600,000 bond in a murder case is now accused of running a nearly $24 million check-theft ring, by recruiting U.S. Postal Service mail carriers to steal checks off their own routes and selling the loot on Telegram.

Tryston Tremaine Vaughn, 28, is alleged to have recruited USPS mail carriers to steal checks on their delivery routes, the DOJ said in an August 25 statement.

Those checks were then allegedly bought from the postal workers by Vaughn and others, advertised on a Telegram channel called “slipsandchips,” and shipped to buyers across the country via FedEx.

Prosecutors say the haul totaled approximately $23,973,338.15. One stolen check was for $1.5 million.

And the man accused of running the operation was not locked in a cell while this was happening. He was walking around on bond after a fatal shooting.

A federal grand jury in the Southern District of Texas returned a nine-count indictment charging five people:

  • Tryston Tremaine Vaughn, 28 — alleged recruiter and ringleader
  • Alyssa Nadine Bryant, 27 — accused of helping buy, sell, and ship the stolen checks
  • Catherine Clauzelle Kilpatrick, 29 — USPS mail carrier (Greens North Station)
  • Drakkor Jamar Alexander, 34 — USPS mail carrier (Spring Main Post Office)
  • Malcolm Tiree Joubert, 35 — USPS mail carrier (Windmill Station)

All five face conspiracy to commit bank fraud and bank fraud. The three carriers also face theft of mail matter by a postal employee.

Keep reading

Toronto homeowner charged after opening fire during potential car theft

The case has raised the issue of how Canadians can protect themselves, their families and their property when faced with a potential break-in or theft.

Earlier this year in Vaughan, a homeowner got his gun out to protect himself and his family during a home invasion. York Regional Police did not press charges in that case.

The Toronto case has also renewed attention on “Castle Law” protections in Canada. The idea has gained support from some Canadians who believe people should be able to defend themselves and their property when police cannot respond immediately.

Police response times can be 10 to 12 minutes, and an armed attacker can do significant harm during that time.

The broader concern raised was that Canadians defending themselves, their families, homes and businesses can face criminal charges while dealing with people who have entered their property.

Keep reading

Thieves Steal Four Renaissance Artworks in Sicilian Museum Heist

Thieves stole four works attributed to the Sicilian Renaissance painter Antonello da Messina from a regional museum in the Sicilian city of Messina on the Italian Ferragosto holiday, the news agency LaPresse reported Sunday.

The thieves bypassed alarm and security systems Saturday evening at the MuMe regional museum to make off with three of the five surviving panels of the San Gregorio Polyptych, dated from 1473, as well as the double-sided panel depicting the Virgin Mary and dead Christ in Pietà, which was removed from an armored display case, LaPresse reported.

“We are devastated by what happened. They were two of Antonello da Messina´s most important and best-known works. It is a tremendous loss for the museum, the city, the community and the art world,” MuMe director Marisa Mercurio told the ANSA news agency. She said the theft occurred just before 10 p.m.

The Italian government in March bought a devotional painting titled “Ecce Homo” by da Messina for $14.9 million from Sotheby’s auction house in New York – raising the profile of the early Renaissance painter.

Lynda Albertson, an art-crime analyst, said the works are instantly recognizable, impeding any effort to sell them through reputable channels.

“Stealing an Antonello may be far easier than selling one. If these are ordinary thieves, they will soon discover that – to their cost,” Albertson, who is the chief executive of the ARCA art crimes research association, told the Italian daily La Repubblica. She said such famous artworks often pass from one criminal to another, serving as collateral for other illicit activity.

The museum was closed Sunday while investigators gathered evidence. Neither museum officials nor the Carabinieri could immediately be reached for comment.

The Ferragosto holiday, which marks the feast of the Assumption of Mary, marks the height of the Italian summer holiday season.

The theft comes just days after police in the northern Italian city of Parma announced that they had recovered three stolen artworks by Renoir, Cézanne and Matisse worth about 10 million euros ($11.5 million). Five people have been detained in the March 22-23 theft from the Magnani Rocca Foundation located in the Parma province.

Keep reading

Valuable Stolen Picasso Found Hanging on Milwaukee Apartment Wall After Tenant Was Evicted

A stolen Pablo Picasso print worth $50,000 has been claimed by its rightful owner after it was discovered by a landlord in Wisconsin while cleaning out a vacant apartment.

Gallery owner Bill DeLind thought the print by the iconic Spanish artist was gone for good after it was stolen in 2018 from his Milwaukee showroom.

Then, last week, he got a call from police. They wanted him to took at the reduction-style image that a Milwaukee landlord had discovered while turning around one of his apartments.

DeLind knew immediately what he was looking at. It was his stolen “Torero” print, one of 30 known to exist signed by Picasso, the New York Post and other outlets reported.

“I was overwhelmed,” DeLind said Friday. “I was at a loss for words. It was an overwhelming moment for me.”

“It was indeed mine,” he added. “It came back full circle.”

The landlord, Tim Dertz, told WISN-TV that he found the print while cleaning out an apartment of a tenant he had to evict.

“It was kind of in a weird spot hanging on a wall,” Tim Dertz told the station, per the Post’s report. “It looked like it had been there for a long, long time because it had tons of dust across the top of it.”

The landlord said he showed it to an antique dealer friend who recognized it as an authentic Picasso.

Dertz handed it over to police, who then contacted DeLind.

The Milwaukee Police Department told the Post Friday that the statute of limitations for theft and property crimes is generally six years. Still, the case remains under investigation, the department said.

Keep reading

Former FBI Agent Charged With Stealing Nearly $1 Million In Crypto, Asked ChatGPT How To Hide It

A supervising U.S. FBI agent who worked in intelligence at the national headquarters has been arrested and accused in a federal court filing of stealing more than $1 million in cryptocurrency.

The high-level special agent, identified as Patrick Steven Yarmoch, allegedly turned himself in to agency colleagues, reporting that he dug crypto keys from FBI systems to make as many as a dozen transfers to himself from accounts tied to foreign individuals he’d investigated, according to an August 1 account filed with the U.S. District Court for the Eastern District of Virginia.

“During the afternoon of July 28, 2026, Yaroch contacted DOJ Employee 1 via Signal and requested to meet to discuss personal matters,” prosecutors said in the complaint.

“Upon meeting DOJ Employee 1 at FBI headquarters, Yaroch immediately started to break down as he told his story.”

Yarmoch — who held a “top secret” security clearance — had worked in counterintelligence, specifically with an investigative unit that focused on an unnamed “adversary nation,” according to the court filing, which noted he was suspended for a couple of days before being fired and arrested on July 31.

The resident of Ashburn, Virginia, had worked as a supervisory special agent at FBI headquarters in Washington, specifically in its counterintelligence and espionage division. He’d previously worked for years out of Boston, where he’d been in a national-security unit investigating the adversary nation referenced in the court filing.

In handling the digital assets, Yarmoch was said to use accounts with Kraken and also Suilend, the decentralized finance (DeFi) ecosystem for the Sui blockchain, via a Slush wallet.

The FBI searches of his computer and phone records revealed some of his recent questions to AI apps, including, “If you had a bucket of money (around $1 million) and you wanted to leave the USA and become a resident or citizen of an EU country, what would you do?”

To which the app allegedly recommended Portugal as a favored destination.

Investigators also located travel plans for Yarmoch and his family to go to Portugal next month, and located the power of attorney forms for Portugal.

“Yaroch stated he was not planning to funnel money into Portugal,” the complaint said.

“Yaroch told FBI WF Agents that his family had a trip planned to Portugal in September 2026 to meet friends. Yaroch realized he might not be able to attend the trip but stated he hoped his wife and child would still go on the trip.”

Later searches included whether Americans need a visa when connecting through Turkey and help drafting a follow-up email about a job opportunity and life in Greece.

He was also said to take recent trips to Germany, and Grenada that he hadn’t reported internally, in violation of FBI rules.

Yarmoch was placed in detention in Alexandria, Virginia.

Keep reading

“Nothing Is 100%”: CZ Warns Bitcoin Holders After $89 Million Coldcard Wallet Exploit

A third wave of thefts against Bitcoin wallets built on flawed Coldcard firmware ran through Saturday morning, lifting observed losses to roughly 1,367 BTC – close to $89 million – drained from 4,585 addresses since Thursday.

As Cyberkendra.com reports, the size is not the interesting part. The third wave is the first one designed to be hard to follow, and that shift tells self-custody holders more about what happens next than any dollar figure does.

Galaxy Research published the wave-three findings early Sunday. Between 12:23 UTC on July 31 and 06:42 UTC on August 1, across blocks 960,396 to 960,471, another 207.73 BTC left 1,912 addresses. That is roughly a tenth of a coin per victim.

Wave one, which opened at 01:10 UTC on July 30 and closed 41 minutes later, took 1,082.65 BTC from 1,195 addresses — nearly a full coin each.

Wave two, on July 31, collected just 76.16 BTC from 1,478 addresses.

Median losses tell the same story more bluntly: 0.270 BTC in wave one, 0.010 in wave two, 0.013 in wave three. The operator is now emptying wallets worth a few thousand dollars apiece and still finding enough of them to spend ten hours sweeping.

Waves one and two were easy to map because the attacker made them easy.

Both funneled coins through a handful of shared collector addresses into P2WPKH holding wallets (pay-to-witness-public-key-hash — plain single-key SegWit outputs, fully visible on chain).

Wave three abandoned that.

Each victim’s coins went to their own destination, and the proceeds now sit in 293 separate P2WSH vaults (pay-to-witness-script-hash, a format that keeps its spending conditions hidden until the first time the coins move). The sweeper also batched an average of 6.37 victims per transaction, where wave one took exactly one at a time, and scanned only the default derivation path instead of testing several branches per seed. Even the fee constant changed — 30 sat/vB in wave one, 50 and 10 in wave two, roughly 200 then exactly 10 in wave three.

That is either the same crew rebuilding after being enumerated in public, or a second crew grinding the same broken key space on its own.

The falling average haul suggests the profitable end of the vulnerable key space is picked over. That is cold comfort. Wave three’s median take of 0.013 BTC is the clearest evidence yet that no balance is now small enough to be beneath the scanner’s notice — and the sweeping had not stopped three days in.

Keep reading

California Man Arrested After Police Catch Him Stealing Unvoted Ballots in Maricopa County, Arizona

A man from California was arrested in Scottsdale, Arizona, on felony charges after US Postal Inspectors caught him stealing mail, including unvoted mail-in ballots, from a USPS collection box.

The suspect, 26-year-old Richard Anthony Ramos Jr. of Stockton, California, was arrested on July 21 with several ballots in his car.

Notably, the Primary elections in Arizona were also held on July 21.

The scheme reportedly involved using a cardboard box into the collection bin to trap outgoing mail, which he would then fish out.

It is unclear whether his target was the mail-in ballots and what he intended to do with them.

Keep reading