Justice Department records and corporate disclosures reveal a Google engineer’s search-data scheme and significant security failures at 7-Eleven, GitHub, and the Hugh Hefner Foundation.
Federal prosecutors in the Southern District of New York have unsealed a criminal complaint against Michele Spagnuolo, a 36-year-old Google information security engineer, alleging a sophisticated insider trading scheme involving decentralized prediction markets. According to court filings, Spagnuolo utilized his access to internal Google Search trend dashboards to gain an unfair advantage on Polymarket, where users wager on real-world outcomes. The DOJ asserts that Spagnuolo, an Italian national residing in Switzerland, operated under the handle “AlphaRaccoon” and routed funds through multiple digital wallets to obscure his activity.
Investigators allege that Spagnuolo placed roughly $2.7 million in bets across 25 outcomes, specifically targeting predictions regarding who would be the most-searched person of 2025. By leveraging non-public search data, he reportedly cleared approximately $1.2 million in profit. This case represents only the second federal criminal prosecution targeting prediction-market insider trading. Spagnuolo now faces charges of commodities fraud, wire fraud, and money laundering, with the Commodity Futures Trading Commission filing a parallel civil case. The records suggest a multi-decade prison exposure if he is convicted on all counts.
While federal authorities track digital footprints in the trading sector, major corporations are managing the fallout of documented system intrusions. 7-Eleven has confirmed an April 8 breach into systems utilized for franchisee documents. Breach notification letters and Have I Been Pwned analysis indicate that approximately 185,300 individuals were affected. The threat actor group ShinyHunters claimed responsibility, asserting the theft of over 600,000 records from a Salesforce environment. The leaked 9.4 GB archive, released after failed ransom talks, includes names, unique email addresses, phone numbers, and dates of birth. Although 7-Eleven maintains there is no reason to believe customer payment data was touched, the exposure of franchisee personal details is likely to invite regulatory scrutiny.
Simultaneously, GitHub has confirmed a separate security incident in which attackers compromised an employee device via a malicious Visual Studio Code extension, likely a poisoned Nx Console update. This breach resulted in the exfiltration of roughly 3,800 internal repositories. While GitHub is rotating critical secrets and insists there is no evidence of broad exposure to customer or public repositories, the TeamPCP group has already begun advertising the stolen source code for a minimum of $50,000. This incident underscores a rising trend in supply-chain attacks, further highlighted by recent reports of an AI-authored malicious package that accidentally leaked its own private GitHub token, creating a new operational-security failure mode for automated malware.
Transparency concerns have also extended to the Hugh M. Hefner Foundation. Crystal Hefner has filed formal complaints with the California and Illinois attorneys general regarding the management of approximately 3,000 scrapbooks and diaries. The filings allege these archives contain explicit images, including potential images of minors, which are currently being digitized. The complaints highlight the acute risk of cyber-extortion or public leaks if these sensitive historical records, stored in private residences and off-site facilities, are ever compromised by hackers. This follows separate accounts from former models describing the survival-level wages and brutal audition processes within the Hefner empire.
Finally, the intersection of criminal proceedings and public records continues to evolve in the case of the artist known as d4vd. While the LAPD previously secured a secrecy hold on medical examiner records, the subsequent release of the autopsy for Celeste Rivas Hernandez has provided clarity on the prosecution’s narrative. Court records describe “multiple penetrating injuries,” with prosecutors alleging the 14-year-old was killed to prevent the disclosure of an underlying sexual relationship. These disclosures illustrate the ongoing tension between law enforcement’s desire for investigative secrecy and the public interest in primary source documentation as the case moves toward trial.

