social engineering

Fake OpenAI Codex download tricks macOS users into installing malware

Fake OpenAI Codex download tricks macOS users into installing malware 2026-08-25 at 15:40 By Sinisa Markovic A malware campaign using a sponsored search ad and a fake OpenAI Codex download page to trick macOS users into pasting a malicious command into Terminal has been uncovered by Cato Networks. It’s a variation of ClickFix, a popular […]

Fake OpenAI Codex download tricks macOS users into installing malware Read More »

ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack

ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack 2026-08-25 at 12:24 By Sinisa Markovic Cybersecurity company ReliaQuest has confirmed that one of its own employees fell for a social engineering attack, handing attackers a password and a brief window into the company’s identity system. The admission came after the extortion group

ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack Read More »

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited 2026-08-24 at 20:38 By Eduard Kovacs A ReliaQuest employee fell victim to a phishing attack and the hackers gained access to a dashboard. The post ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited Read More »

Banks look for fraud signals in customer behavior

Banks look for fraud signals in customer behavior 2026-08-19 at 07:30 By Anamarija Pogorelec Banks are dealing with more fraud in which customers authorize payments after being manipulated by criminals. ThreatMark’s Fraud Readiness Benchmark 2026 describes a banking environment where social engineering, reimbursement requirements and growing case volumes are changing fraud operations. Social engineering moves

Banks look for fraud signals in customer behavior Read More »

Brand Impersonation Takedown: From Whack-a-Mole to Managed Response

Brand Impersonation Takedown: From Whack-a-Mole to Managed Response 2026-08-18 at 05:23 By Mihir Bagwe Manual brand impersonation takedowns fail because attackers move faster than ticket-based abuse reports can resolve — phishing pages and fake executive profiles often do their damage within hours of going live, while manual removal can take days. A managed takedown program

Brand Impersonation Takedown: From Whack-a-Mole to Managed Response Read More »

New Android malware relays bank cards to fraudsters while victims still hold them

New Android malware relays bank cards to fraudsters while victims still hold them 2026-08-14 at 14:08 By Sinisa Markovic Group-IB researchers discovered WindRelay, a new Android malware built to capture live payment card data over NFC (Near Field Communication) and relay it to attackers in real time. WindRelay is paired with the SpyNote remote access

New Android malware relays bank cards to fraudsters while victims still hold them Read More »

Fake IRS letters direct crypto holders to bogus compliance portal

Fake IRS letters direct crypto holders to bogus compliance portal 2026-08-04 at 07:30 By Sinisa Markovic Scammers are sending physical letters to cryptocurrency holders that copy the look of official IRS notices. The letters tell recipients they must enroll in something called a Digital Asset Compliance Portal before a deadline, or risk penalties. “If you

Fake IRS letters direct crypto holders to bogus compliance portal Read More »

Scammers weaponize FaceTime to drain bank accounts

Scammers weaponize FaceTime to drain bank accounts 2026-07-17 at 13:02 By Sinisa Markovic Apple is warning iPhone and iPad users that scammers are using FaceTime calls to trick them into handing over money and account details. The company says scammers use social engineering, posing as representatives of a trusted company or entity, and contacting people

Scammers weaponize FaceTime to drain bank accounts Read More »

Scattered Spider members jailed over Transport for London hack that cost £29 million

Scattered Spider members jailed over Transport for London hack that cost £29 million 2026-07-16 at 16:48 By Sinisa Markovic Two members of the notorious “Scattered Spider” hacking collective have been sentenced to five years and six months in prison each for a cyberattack on Transport for London (TfL) that disrupted services for thousands of commuters

Scattered Spider members jailed over Transport for London hack that cost £29 million Read More »

Most data brokers won’t tell you what happened to your deletion request

Most data brokers won’t tell you what happened to your deletion request 2026-07-10 at 09:30 By Sinisa Markovic Data brokers collect personal details on most adults in the United States and sell them to buyers that include employers, landlords, insurance companies, and government agencies. California gives residents a way to push back. You can ask

Most data brokers won’t tell you what happened to your deletion request Read More »

5,811 arrests, $293 million seized over social engineering scams

5,811 arrests, $293 million seized over social engineering scams 2026-07-09 at 14:14 By Sinisa Markovic Criminals who pose as police officers, romantic partners, and business suppliers have built fraud operations that reach across continents. A four-month enforcement campaign against these schemes wrapped up, and police in 97 countries and territories took part. Thousands of arrests

5,811 arrests, $293 million seized over social engineering scams Read More »

The fake report message that ends with a stolen Reddit account

The fake report message that ends with a stolen Reddit account 2026-07-09 at 08:30 By Anamarija Pogorelec A direct message arrives on Reddit from a stranger, and it invites a reply. That reply is the point. This scheme runs on social engineering, with no malware and no malicious links, and it has spread across Reddit,

The fake report message that ends with a stolen Reddit account Read More »

Malware attacks strip Roblox developers of entire games

Malware attacks strip Roblox developers of entire games 2026-06-18 at 15:41 By Sinisa Markovic Hackers who once focused on stealing valuable Roblox items are now taking over entire games. Although Roblox operates the service, users can create and publish their own games on it. Successful games can generate substantial revenue through in-game purchases. Some developers

Malware attacks strip Roblox developers of entire games Read More »

Fake Spotify Premium tutorials on TikTok and Instagram Reels spread malware

Fake Spotify Premium tutorials on TikTok and Instagram Reels spread malware 2026-06-11 at 16:51 By Sinisa Markovic Cybercriminals are using TikTok and Instagram Reels videos to spread Vidar, an infostealer malware, through fake downloads for popular paid software, according to ReversingLabs. The researchers uncovered two campaigns behind the activity, each using a different approach to

Fake Spotify Premium tutorials on TikTok and Instagram Reels spread malware Read More »

Scams now operate like real businesses with budgets and targets

Scams now operate like real businesses with budgets and targets 2026-06-10 at 07:23 By Anamarija Pogorelec Social media has overtaken email as a primary attack vector, showing changes in how people consume information and interact online, according to Bitdefender’s Global Scam Intelligence Report 2026. Fraud campaigns use advertisements, sponsored content, impersonation pages, and direct messages

Scams now operate like real businesses with budgets and targets Read More »

Hackers are knocking on office doors pretending to be IT staff

Hackers are knocking on office doors pretending to be IT staff 2026-05-27 at 18:09 By Sinisa Markovic The Silent Ransom Group (SRG) is targeting law firms using social engineering techniques and an unusual tactic for cybercriminals: showing up at victims’ offices in person while posing as IT staff, the FBI warns. The group, also known

Hackers are knocking on office doors pretending to be IT staff Read More »

The new economics of fraud: Cheaper, faster, more convincing

The new economics of fraud: Cheaper, faster, more convincing 2026-05-22 at 08:29 By Anamarija Pogorelec Scams have become one of the fastest-growing consumer risks, driven by AI-enabled impersonation, social engineering, and sophisticated attack methods, according to Visa’s Spring 2026 Biannual Threats Report. Criminals redirect efforts toward trust and third parties Fraud involves behavioral manipulation, fragmented

The new economics of fraud: Cheaper, faster, more convincing Read More »

Verizon DBIR: Vulnerability exploitation is the dominant initial access vector

Verizon DBIR: Vulnerability exploitation is the dominant initial access vector 2026-05-20 at 17:16 By Zeljka Zorz Vulnerability exploitation has overtaken stolen credentials as the most common way attackers gain initial access to target networks, according to the 2026 Verizon Data Breach Investigations Report. This is the first time credential theft has been knocked off the

Verizon DBIR: Vulnerability exploitation is the dominant initial access vector Read More »

New macOS infostealer impersonates Apple, Microsoft, and Google in a single attack chain

New macOS infostealer impersonates Apple, Microsoft, and Google in a single attack chain 2026-05-19 at 15:35 By Sinisa Markovic A SHub macOS infostealer variant called Reaper impersonates Apple, Microsoft, and Google to trick users into executing malicious code, then targets browser data, password managers, and cryptocurrency wallets while establishing persistence for continued access, SentinelOne found.

New macOS infostealer impersonates Apple, Microsoft, and Google in a single attack chain Read More »

Scroll to Top