Phishing
Ongoing coverage on Phishing.
Latest coverage
13,689 Trezor Customers Caught Up in Data Leak at Third-Party Shipping Partner
A data breach at Trezor's third-party shipping partner, ShipMonk, has exposed the personal information of 13,689 customers, including names, addresses, and phone numbers. While Trezor's own infrastructure remains secure, the leaked data increases the risk of targeted phishing attacks. The company plans to introduce an 'Anonymous Delivery' feature by the end of 2026 to enhance customer privacy.
Rogue Wi-Fi Network Onboard Delta Flight 591 Points to Departing DEF CON Attendees
Delta Flight 591 experienced a 30-minute Wi-Fi outage due to an unauthorized "evil twin" network set up by passengers attending a cybersecurity conference. The fake "Delta WiFi Fast" hotspot was designed to harvest credentials. Delta confirmed the incident, stating flight safety was never compromised, and the FBI is reviewing the matter.
Bought Steam Hardware Recently? Valve Says Your Personal Data May Have Been Stolen
Valve has alerted customers who recently purchased Steam hardware that their personal data may have been compromised due to a cyberattack on their delivery partner, CEVA. The company advises users to be vigilant against potential phishing attempts using the stolen information.
Portal Confirms Short-Lived X Account Takeover That Pushed a Wallet Phishing Link
The cryptocurrency project Portal reported that its X (formerly Twitter) account was temporarily compromised overnight, during which an attacker posted a phishing link designed to target connected wallets. The team quickly regained control, locked down the account, and removed the malicious post. It remains unclear how the breach occurred, how long the link was visible, or if any users' wallets were drained.
Vatican scrambles to patch 'phishing goldmine' app promoted by the Pope: 'Prayer infrastructure on the framework you learn in week 2 of a Node.js bootcamp'
The Vatican's official 'Click To Pray' app, promoted by Pope Francis, was found to have significant security vulnerabilities exposing over 700,000 user emails and personal data. A white-hat hacker revealed the issue, which remained unaddressed for months until public disclosure, turning the app into a 'phishing goldmine' for malicious actors targeting less tech-savvy users.
Håll ditt Discord-konto säkert!
This guide provides essential security tips for Discord users to protect their accounts from scams and unauthorized access. Key recommendations include enabling two-factor authentication, using unique passwords, being cautious of suspicious links, and regularly reviewing connected applications.
Evening Safety Dance
Hackers utilized Google Cloud links and fabricated New York Times web pages to operate a large-scale global phishing operation. This method was employed to distribute malicious content and deceive users.
How to Stay Safe When Paying for Online Services
This guide provides practical advice on staying safe when making online payments, emphasizing the importance of vigilance before entering payment details. It recommends direct access to payment pages, verifying web addresses, avoiding saving payment data on shared devices, and reading reviews before purchasing services.
Morning Safety Dance
Microsoft 365 Copilot has successfully passed another AI security audit. The article also highlights how scammers are exploiting real hotel reservations to conduct spear-phishing attacks.
Memorial Day Safety Dance
The FBI has issued a warning regarding the Kali365 phishing service, which is actively targeting Microsoft 365 accounts. This service aims to compromise user credentials and potentially gain unauthorized access to sensitive data.
Interpol's 'Operation Ramz' has arrested over 200 people for phishing scams, malware threats, and all sorts of internet ne’er-do-well behaviour
Interpol announced the arrest of 201 individuals across 13 countries as part of "Operation Ramz," a multinational effort targeting cybercriminals involved in phishing, malware, and cyber scams in the Middle East and North Africa. The operation also resulted in the seizure of 53 servers and confirmed 3,867 victims of cybercrime.
France's national agency for managing IDs and passports suffered a data breach last week
France Titres, the French agency responsible for national IDs and passports, confirmed a data breach detected on April 15. A hacker claimed responsibility and is attempting to sell up to 19 million records, including names, emails, dates of birth, and phone numbers. While direct portal access was not compromised, the exposed data could be used for phishing attacks.
Fake Windows Support website offers 'cumulative update' for version 24H2 but delivers password-stealing malware that can avoid anti-virus detection
A sophisticated phishing scam is distributing password-stealing malware disguised as a 'cumulative update' for Windows Update version 24H2. The fake update, offered through a fraudulent Microsoft support website, can evade antivirus detection due to its obfuscated JavaScript within an Electron shell. Cybersecurity firm Malwarebytes has updated its antivirus to detect this threat and advises users to be wary of unofficial download sources.
US victims lost nearly $21 billion to cybercrime last year says FBI with crypto and AI 'complaints among the…
The FBI reported that US victims lost nearly $21 billion to cybercrime in 2025, with cryptocurrency and artificial intelligence-related complaints being among the costliest. Over one million complaints were filed, a nearly 20% increase from the previous year. AI-led scams, including deepfake impersonations and sophisticated phishing attempts, are becoming increasingly prevalent and effective.
MalwareBytes Alert: Counterfeit Pudgy Penguins Scam Site
Cybercriminals have created a fake website for the Pudgy Penguins' Pudgy World game, attempting to steal cryptocurrency wallet credentials. The phishing site, pudgypengu-gamegifts[.]live, mimics legitimate wallet interfaces to deceive users, particularly newcomers. Malwarebytes Labs has issued an alert, urging users to only access official sites and verify all URLs to prevent significant financial losses.
Dutch intelligence services warn of Russian hackers targeting Signal and WhatsApp
Dutch intelligence services have issued a warning about a global cyber campaign by Russian hackers targeting Signal and WhatsApp accounts of dignitaries, military personnel, and civil servants. The hackers are reportedly impersonating support chatbots to trick targets into revealing their PINs, enabling access to communications. This follows similar warnings in the US, highlighting the ongoing threat of phishing scams.
Morning Safety Dance
This guide provides information on how to prevent being locked out of your Google account. It also touches upon instances of Russian criminals gaining access to official Signal and WhatsApp accounts through phishing methods.
The Cybersecurity Threats Endangering The Gaming Industry
The rapidly growing gaming industry faces significant cybersecurity threats, including phishing, account takeovers, supply chain attacks, and insider threats. These risks impact developers, publishers, and players alike, necessitating robust security strategies such as multi-factor authentication and real-time monitoring. Companies are increasingly seeking managed IT services to bolster their defenses against these evolving dangers.