(In)Secure Digest: an NFT-funded DJ career, contractor revenge and an AI gym hack

02.09.2026

August's lessons, in short: don't fund your hobbies out of the company budget, keep corporate systems away from unsupervised AI, treat crypto with caution, and take up your grievances with the labour market rather than the customer database. The solutions to each puzzle are in the text.

Spinning the investors' money

What happened: The founder of an NFT startup misappropriated investor funds to bankroll his career as a DJ.

How it happened: In 2022 the NFT company Few and Far raised more than $10 million from investors to launch the FAR token and an NFT marketplace. Instead of building either, founder Taj Tarsha put the money into his hobbies: a DJ career, online casinos, crypto speculation and a luxury flat in Miami.

The misuse of funds first surfaced during a 2023 audit, but Tarsha convinced investors the spending was going into the project. To cover his tracks he laid off most of the staff. The company did eventually release the token in May 2024, but it fell sharply and stopped trading soon after.

Tarsha was not arrested until June 2026. Investigators showed that investment money had gone straight into the founder's personal accounts. Prosecutors charged him with securities fraud and wire fraud. Each count carries up to 20 years in prison.

Crime and confession

What happened: A former FBI special agent stole around a million dollars in cryptocurrency from the bureau.

How it happened: Between February 2025 and July 2026, Patrick Steven Yaroch used his official access to internal FBI databases, memorised the seed phrases of crypto wallets and moved the funds to a personal account. In July 2026 the agent turned himself in to the Department of Justice, saying the deed was "eating him alive". By his own account, he stole the money out of disillusionment with the job.

Case materials show that before confessing, the agent had discussed emigration plans with ChatGPT, looked for ways to move money across the border and bought tickets to Portugal. He now faces up to 20 years in prison.

An AI of our time

What happened: An AI assistant found a vulnerability in a gym's website and cancelled another person's booking so that its user could get into a class.

How it happened: Australian developer Andrew Bird decided to experiment with AI agent software and asked a model to book him a training session. The system only opens reservations a set time before each class, but the AI found a way around the rule and secured a slot weeks in advance. Bird then asked it to check whether he could get into the gym sooner. The assistant managed that too — by permanently cancelling another customer's booking. The gym's system never noticed.

Bird wrote about the accidental hack on his company's blog and the story was picked up by the media. The developer of the booking software did not comment on the incident.

Two months of anonymous emails

What happened: A disgruntled contractor stole confidential documents and spent two months blackmailing the company for a ransom.

How it happened: In December 2023 contractor Cameron Currie learned that the management of IT company Brightly Software did not intend to renew his contract. Before leaving he took employee personal data and corporate financial records. The next day Currie sent his former employer a series of anonymous threats, demanding $2.5 million or he would publish the data and report the breach to the authorities. He even put the company on a clock: every month the sum went up by $100,000.

The threatening emails continued for two months, until the end of January 2024. Brightly paid $7,540 in bitcoin and went to law enforcement. The FBI found the culprit quickly. Currie had made two serious mistakes: he sent the emails from a specific Outlook address, and he linked his account on the crypto exchange where he collected the ransom to his relatives' bank details. In August 2026 he was sentenced to two years in prison for extortion.

Revenge on the job market

What happened: An Origin Energy contractor stole the personal data of 900,000 customers in order to blackmail the company.

How it happened: A contractor working for the Australian energy company Origin Energy obtained access to customer personal data shortly before his departure and saved it to a personal laptop. The company lost the names, addresses, call recordings and card numbers of 900,000 current and former customers.

After the incident the man threatened Origin Energy that he would dump the database on the dark web unless he received a substantial ransom. He later contacted The Australian and said he had stolen the data in revenge for the state of the job market, but that he had reached an agreement with the company.

Amid the scandal, Origin Energy restricted internal access to its databases and offered affected customers a year of free credit monitoring.

196 loans that never existed

What happened: An employee of a microfinance organisation issued 196 fictitious loans and made 3.6 million rubles (around $43,000).

How it happened: A microfinance operations specialist assigned fake loans to real clients, falsifying contract details drawn from the internal database. To stop the company reaching the supposed borrowers, she swapped their phone numbers for ones she controlled.

Over a year she issued 196 fictitious loans worth 3.6 million rubles. Only about a million went on herself. The rest had to be ploughed back into repayments to keep the theft hidden.

She was caught in the end and  sentenced to six years in prison for the unlawful use of trade secrets and unauthorised interference with critical infrastructure.

Security Tip of the Month: August's cases show that legitimate access can become a threat when employees or contractors copy data, manipulate records or misuse corporate systems. AI agents can also exploit weak controls faster than security teams can react.

SearchInform Risk Monitor detects unusual behaviour, confidential data transfers and policy violations, while FileAuditor (DCAP) identifies sensitive files and risky access rights. Together, they help prevent insider theft, fraud and extortion before damage is done.

Book a Free Trial