German and Swiss law enforcement agencies have dismantled Cryptomixer, an illegal cryptocurrency mixer service, confiscating over 25 million euros (approximately $29 million) in Bitcoin. This operation targeted the infrastructure used to launder illicit funds, disrupting a key service leveraged by cybercriminals to anonymize the proceeds of ransomware, fraud, and other cyber-enabled crimes. The takedown is part of a broader international effort to combat the use of cryptocurrency mixers in facilitating money laundering and hindering law enforcement investigations.
The seizure of Cryptomixer's assets and infrastructure is expected to have a significant impact on the cybercrime ecosystem, as such services are frequently used to obscure the origin of stolen or illicitly obtained digital assets. The action underscores the increasing collaboration between European law enforcement agencies in targeting the financial infrastructure that supports cybercrime, and serves as a warning to operators of similar services that they are within the reach of international law enforcement operations.

See the reporting duties and controls this puts on the clock.
11 events from the most recent confirmed update back to the earliest known activity.
The U.S. Cybersecurity and Infrastructure Security Agency added several vulnerabilities to its Known Exploited Vulnerabilities catalog, including flaws in OpenPLC ScadaBR and the Android Framework. The additions signaled evidence of active exploitation.
Universities were reported as affected by follow-on breaches tied to an Oracle hack. The reporting indicated the compromise had spread impact beyond the initially affected environment.
A separate data breach at Marquis was reported to have exposed information on more than 780,000 individuals. The disclosure added to a series of significant breach notifications during the period.
A data breach involving Coupang was reported as affecting 33.7 million users. The incident was cited among major consumer-impacting breaches disclosed in early December 2025.
A maximum-severity XML external entity vulnerability, CVE-2025-66516, in Apache Tika was reported and urgent patching was recommended. The disclosure identified the flaw as a serious risk for affected deployments.
Cloudflare reported blocking a record 29.7 Tbps distributed denial-of-service attack attributed to the AISURU botnet. The event highlighted the growing scale of volumetric DDoS activity.
Researchers identified malicious Rust packages aimed at Web3 developers after they had accumulated thousands of downloads. The packages were subsequently removed from distribution.
The Iran-aligned MuddyWater threat group was reported conducting new cyberespionage operations targeting organizations in Israel and Egypt. The campaigns used updated backdoors and reflected continued evolution in the group's tooling.
A critical remote code execution vulnerability in React Server Components, tracked as CVE-2025-55182, was patched. Defenders were urged to update quickly because of the severity of the issue.
Google released fixes for 51 Android vulnerabilities, including CVE-2025-48633 and CVE-2025-48572, which were reportedly under targeted exploitation. The update addressed actively abused flaws in the Android ecosystem.
Law enforcement authorities in Germany and Switzerland took down the illegal Cryptomixer cryptocurrency laundering service and seized more than €25 million in Bitcoin. The action was reported as part of broader 2025 efforts to disrupt cybercrime infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.