Fraud & Social Engineering
Cybersecurity news in this category

Beeline Subscribers Targeted in Mass SIM Hijacking via Remote eSIM Issuance

Yandex Rolls Out Universal Anti-Fraud Platform to Block Bots and Manipulation Schemes

Protecting C-Suite Leaders: Defending Executives Against Targeted Cyberattacks
IPA Reports Record High Fake Warning Scam Consultations in Q2 2026
The Information Processing Promotion Agency (IPA) recorded 3,832 personal security consultations in the second quarter of 2026, marking an 8.5 percent increase from the previous quarter. Fake warning scams, which display fabricated malware alerts to frighten users into contacting fraudsters, rose sharply to 1,428 cases, a 23.7 percent jump and the highest figure in two years. These scams carry risks of financial loss and device compromise through fake support services. Consultations dipped temporarily after arrests in May 2025 but have now exceeded levels seen before those arrests. Phishing reports also increased slightly to 146 cases, including schemes impersonating the National Tax Agency. The trend of rising fake warning incidents has continued for three consecutive quarters, underscoring the need for ongoing public vigilance.
macOS Users Encounter Phishing and Scams More Often Than Windows Users but Adopt Fewer Protections, Kaspersky Study Reveals
A new study from Kaspersky Lab shows that macOS users report higher rates of phishing encounters and various scams compared to Windows users, yet they are less likely to implement basic security measures. Over the past year, 12 percent of macOS users faced phishing attempts versus 9 percent of Windows users, while 16 percent encountered investment fraud schemes compared to 13 percent. Privacy violations and personal data theft were also reported more frequently by Mac owners at 11 percent and 12 percent respectively, against 8 percent and 7 percent for Windows. Security habits differ notably, with only 51 percent of macOS users avoiding suspicious links and emails versus 62 percent of Windows users, and just 35 percent installing additional protection tools compared to 42 percent. Password practices and multi-factor authentication usage follow the same pattern, with Mac users trailing in creating unique or complex passwords and enabling 2FA. Kaspersky notes that while macOS built-in defenses handle many threats effectively, they offer limited protection against social engineering and platform-specific attacks, underscoring that the Apple brand does not serve as automatic security.
Scammers Impersonate Russian Post to Lure Victims into Fake Telegram Bots
Fraudsters have developed a new scheme targeting Russian citizens by impersonating Russian Post over the phone. They claim that a registered letter or parcel requires additional address details and direct victims to a counterfeit Telegram bot. The bot then requests personal information, bank card data, or SMS verification codes. State Duma deputy Anton Nemkin highlighted how the criminals exploit trust in the well-known postal service and create urgency around expected deliveries. Victims are advised to avoid any links or contacts provided by callers and instead verify information directly through official Russian Post channels. The scheme relies on automatic reactions from people who may be expecting packages, making them more likely to follow instructions without suspicion. No actual parcel exists, but the risk of account takeover or financial loss remains very real.
From Free Game Cheats to Arson: Cybercriminals Recruit Children for Espionage and Violent Crimes
Cybercriminals are increasingly targeting children not only to steal money from parents but also to turn them into unwitting accomplices in dangerous criminal activities. During school holidays, teenagers spend more time in games and messengers where scammers offer free in-game currency, mods, cheats, and pirated game versions to build trust. Once access is gained, fraudsters extract SMS codes, bank card details, or device control, escalating to threats and blackmail when initial tactics fail. Kaspersky Lab recorded over 19 million attempts to distribute malware disguised as popular games between April 2024 and April 2025, installing spyware and RAT trojans that monitor chats, keystrokes, cameras, and microphones. In severe cases, children are manipulated into believing they assist law enforcement, leading to real-world crimes such as photographing apartments, handing over keys, setting fires, or attacking people. Specific incidents include a 12-year-old boy from Leningrad Oblast forced to assault a police officer and a 13-year-old from Podolsk ordered to ignite a gas pump at a filling station. Izvestia reporting highlights that parents should watch for signs like hidden screens or strange tasks and teach children that no stranger can demand codes, money, or secret missions.
Google Quietly Rolls Out Android Developer Verifier App to Curb APK Sideloading Fraud
Android users are discovering a new system application called Android Developer Verifier with the package identifier com.google.android.verifier that Google installs automatically through system updates without any separate consent prompt. The service prepares devices for upcoming restrictions on installing APK files from unknown sources by checking whether an app is registered to a verified developer who has passed identity verification and supplied legal information to Google. This verification does not guarantee an application is safe but allows Google to associate it with a specific individual or company, helping combat social-engineering scams in which fraudsters pressure victims into disabling protections and installing malicious APKs. To install software from an unverified developer, users will need to enable developer mode, confirm they are not under duress, reboot the device, wait 24 hours, and re-authenticate with PIN or biometrics. The new requirements begin on 30 September in Brazil, Indonesia, Singapore, and Thailand, with worldwide expansion planned for 2027 and later. While the app can currently be removed, it is unclear whether future updates will restore it, and advanced users retain the option to sideload via ADB, which bypasses the new checks entirely.
Protecting Your Credit History: How to Check for Unauthorized Microloans and Set Up Self-Bans in Russia
Russians often discover fraudulent loans taken out in their name only when banks reject their applications, revealing unknown debts in their credit reports. The article explains how to obtain a list of credit bureaus via Gosuslugi or the Central Bank of Russia, download free reports twice a year from each BKI, and thoroughly review contracts, applications, and creditor inquiries rather than focusing solely on credit scores. It details the new self-ban mechanism available from March 2025 on Gosuslugi and September 2025 via MFC, which blocks remote lending while allowing exceptions for mortgages and education loans. Practical advice covers pre-travel preparations, immediate actions after losing documents or phones, and the step-by-step process of disputing fraudulent entries with creditors, police, and the Central Bank. The guide also includes a table of common red flags and a checklist of ongoing security habits to prevent identity theft and financial fraud.
Aurorium Anti-Detect Browser Uses AI Fingerprinting Linked to Real Hardware and User Profiles to Evade Modern Anti-Fraud Systems
Aurorium is an anti-detect browser that differentiates itself from competitors by embedding spoofing directly into the browser kernel rather than relying on JavaScript patches. The product generates fingerprints using AI that analyzes the operator’s actual device hardware and matches it to a realistic social profile including age, income, occupation, and geography. Network routing is handled at the kernel level so that WebRTC and DNS traffic is forced through proxies without disabling features that anti-fraud systems flag. The company also published a detailed Cure53 security audit that identified and subsequently fixed four critical vulnerabilities. Team-oriented features include built-in CRM, task management, multi-team support, and a mobile application. The review highlights that Aurorium’s approach reduces the common mismatch between generated fingerprints and the supposed user’s real-world context that often triggers detection.
CACTER Upgrades PhishSim Anti-Phishing Simulation System to Help Enterprises Reduce Phishing Risks in Four Easy Steps
CACTER has released an updated version of its PhishSim anti-phishing drill system designed to replace traditional theoretical training with realistic, immersive phishing simulations. The platform can replicate common attack vectors including fake links, malicious attachments, and disguised QR codes while impersonating legitimate senders and official domains to mimic both APT and spear-phishing campaigns. Organizations using the system have reportedly lowered their average employee click rate from 23.88% to 4.16% through regular, customized exercises. Key features include a continuously updated template library tailored to specific industries and business scenarios, automated visual reports that rank departments and classify employee risk levels, and actionable remediation recommendations. The entire workflow is completed in just four steps—selecting templates, grouping employees, launching drills, and reviewing reports—allowing companies to run ongoing training without dedicated security specialists. The solution emphasizes measurable results and a closed-loop process of simulation, analysis, and improvement to strengthen email security posture.
Dutch Police Arrest Leader of 700-Person Investment Scam Network That Stole Over €100 Million Monthly
Dutch authorities have arrested the suspected leader of a massive international investment fraud operation that employed more than 700 people across roughly 20 offices in multiple countries. The 46-year-old Israeli-Polish citizen, described as a known hacker, was detained in Poland while traveling from Dubai and later extradited to the Netherlands. The group posed as financial consultants, using fake trading platforms to convince victims to invest increasingly large sums, primarily in cryptocurrency, while never actually placing the funds. Victims in the Netherlands alone reported nearly €25 million in losses across 550 complaints, with many losing over €10,000 and suffering severe consequences including inability to buy food and suicidal thoughts. Additional arrests occurred in Belgium, Cyprus, and Greece, while Europol assisted in disrupting the network's infrastructure and identifying further suspects.
Interpol Dismantles €140 Million BEC Fraud Network Impersonating Executives Across Spain, Portugal and Panama
Police have dismantled an international criminal network that used Business Email Compromise (BEC) techniques to steal €140 million through investment fraud and the substitution of corporate correspondence. The operation, conducted simultaneously in Spain, Portugal, and Panama with support from Interpol and Europol, resulted in the arrest of four suspected organizers. Investigators found the group controlled more than 800 bank accounts and 120 corporate accounts while relying on 67 intermediaries to move funds. The scheme involved impersonating company executives or sending fake invoices to trick employees into transferring money to accounts controlled by the criminals. Rapid layering of transfers across multiple countries obscured the money trail, with at least €94 million confirmed to have passed through the network. Authorities froze €3 million and seized 15 computers plus over 170 smartphones during raids on six premises in Barcelona, Girona, Tarragona, and Porto.
Microsoft Permanently Locks Hacked Account After Security Changes, Erasing 25 Years of OneDrive Data and Purchases
A streamer named Joshua Kane lost access to his Microsoft account containing 25 years of digital files, family photos, and purchased content after it was compromised by an attacker who altered security settings. Microsoft confirmed the account belonged to him and had been breached but refused to restore access, citing internal policies that prevent manual recovery once security information is changed by an unauthorized party. The company stated that OneDrive content cannot be extracted due to its encryption architecture and privacy protections, leaving the data permanently inaccessible even to Microsoft engineers. Kane was advised to create a new account and repurchase games and services, while the incident quickly gained over two million views on social media and prompted other users to share similar experiences. The case underscores the risks of insufficient account protection and the permanent consequences of account takeovers when two-factor authentication and backup strategies are not properly implemented.
Phishers Launch Dark Web Platform to Spoof Real Corporate Email Addresses from Major Companies
A new phishing platform has emerged on the dark web that enables attackers to send mass emails appearing to originate from legitimate corporate addresses of well-known organizations. The tool relies on advanced email spoofing techniques, making the sender’s domain and company name look authentic to recipients. According to research from BI.ZONE Threat Intelligence reported by Izvestia, the service is actively advertised on underground forums as a ready-to-use solution for large-scale campaigns. It also automatically scrapes official websites to replicate logos, branding, and email styling, significantly increasing the credibility of the fraudulent messages. Victims may receive messages disguised as invoices, security alerts, contractor proposals, or urgent data confirmation requests. Traditional advice to verify the sender address is now insufficient, as the displayed domain genuinely belongs to the targeted company. Security experts warn that users must now scrutinize links, unexpected requests, and any demands to download files or provide credentials.
Looking for Gasoline? Hand Over Your Account: Scammers Launch Fake Gas Station Card Phishing Sites Targeting Fuel Shortages
Cybercriminals have created more than 60 phishing websites that impersonate gas station locator services, game platforms, marketplaces, and video hosting sites to exploit fuel shortages and user demand for bonuses. The primary scheme involves promising users real-time information on available gasoline, electronic fuel coupons, or free in-game rewards in exchange for providing a phone number and confirming it with an SMS code. Once the code is entered, attackers gain full access to the victim's messenger account, allowing them to read conversations, download media and documents, view contacts, and send messages on the victim's behalf. The fraudulent sites often appear highly convincing, prompting users to select fuel type and region before redirecting them to a fake verification form instead of displaying actual station data. F6 specialists identified that over half of the sites mimic marketplace brands, 19% pose as social platforms, and the remainder target gas station maps, games like Brawl Stars, video services, and classifieds boards using domains such as .site, .click, .shop, .lol, and .xyz. The same campaign also targets children by offering free Brawl Stars loot boxes and virtual currency. F6 has already submitted the malicious domains for blocking, though new phishing pages continue to emerge regularly.
Interpol’s Operation First Light 2026: 5,811 Arrests, $293 Million Seized in Global Crackdown on Social Engineering Fraud
Law enforcement agencies from 97 countries and territories conducted Interpol’s Operation First Light 2026 between 15 January and 30 April 2026, resulting in 5,811 arrests and the seizure of $293 million in illicit assets. The operation targeted social engineering scams—including business email compromise, fake investment schemes, romance fraud, and blackmail—and the associated money laundering networks that have turned personal trust into a multi-million-dollar criminal enterprise. Over 152,000 cases were examined, more than 31,000 bank accounts were frozen, and nearly 24,000 crimes were solved, leading to the identification of 15,600 suspects and 142,000 victims worldwide. One of the most striking discoveries was a fully equipped fake Brazilian police station built in Eswatini, where 82 people were arrested and 240 electronic devices seized. In Thailand, investigators traced over $122.5 million in romance-scam proceeds through a single 20-year-old suspect’s cryptocurrency wallets, while coordinated efforts in Singapore, Oman, and Macau prevented multimillion-dollar losses in real time.
GC Solar and SEG-T Launch Development of AI-Powered Security Email Gateway SEG-T to Counter Advanced Phishing Campaigns
GC Solar and co-founder of Secure-T Khariton Nikishkin have initiated the development of SEG-T, a new Security Email Gateway solution designed to protect corporate email systems using multi-agent AI. The project responds to the growing sophistication of phishing attacks that leverage ready-made toolkits, infrastructure, anti-bot mechanisms, and AI-generated content to create convincing messages at scale. Unlike traditional filters, SEG-T will analyze both technical indicators and semantic elements such as tone, manipulation tactics, attempts to build trust, instill fear, or create urgency. The system will block suspicious attachments including links, archives, PDFs, executables, and SVGs while focusing primarily on social engineering rather than relying on a built-in sandbox. SEG-T is planned for deployment across cloud, on-premises, and Kubernetes environments with rapid 15-minute setup times and will integrate with Solar webProxy and Solar Dozor for enhanced traffic inspection and data loss prevention. GC Solar holds a 49% stake in the project following its earlier acquisition of a controlling interest in Secure-T.
Scammers Impersonate Neighbors to Lure Residents into Fake Bomb Shelter Chat Groups for Data Theft
Fraudsters have launched a new social engineering scheme that exploits public anxiety by impersonating neighbors and inviting victims to join Telegram chats supposedly dedicated to organizing bomb shelters in residential buildings. The callers claim an urgent residents’ meeting is taking place and insist that the target must share personal details and join the group chat to be included on the attendance list. In reality, decisions about creating official bomb shelters are governed by strict state regulations and cannot be made through informal neighbor votes, making the entire premise a clear red flag. Once the victim engages, scammers quickly pivot from the supposed shelter topic to requesting names, phone numbers, and other sensitive information. Victims who continue the conversation may later receive follow-up calls from fraudsters posing as government officials who claim the victim’s data has been compromised, pressuring them into transferring money or taking other harmful actions. The scheme is easily identified by callers who refuse in-person meetings, push for immediate chat enrollment, and avoid any verifiable details about the building or meeting. Security experts recommend ending such calls immediately and never sharing personal information with unknown individuals over the phone.