Browsing: Scams & Fraud

Learn about the newest online scams, phishing attempts, and fraud tactics, along with tips to recognize them and protect your accounts and identity.

Spanish police arrested a 20-year-old hacker who manipulated a hotel booking website, allowing him to pay just one cent for luxury hotel rooms. This cyberattack altered the payment validation system, costing the hotel over €20,000 ($23,608) in losses. The hacker was caught after an online booking site reported suspicious activity, revealing the fraudulent transactions.

From late December 2025 to late January 2026, scammers used Atlassian Jira’s email notification feature to send localized scam emails to organizations. These emails, appearing to come from legitimate Jira addresses, targeted users familiar with Jira notifications, promising gifts or bonuses. The attackers set up trial accounts and used automation features to send these emails, which led recipients to investment scams and online casino sites, affecting multiple language speakers including English, French, and Russian.

A phishing campaign is using a fake Google Forms site to harvest Google account logins under the guise of job offers. The scam employs a deceptive URL, forms.google.ss-o.com, to impersonate the legitimate Google Forms site. Victims are lured with job opportunities and prompted to submit personal information, including their Google credentials, through a fraudulent form.

Scammers are using a fake chatbot claiming to be Google’s Gemini AI to sell a non-existent cryptocurrency called ‘Google Coin.’ The chatbot engages users with convincing sales pitches, projecting unrealistic returns on investments. Google has not launched any cryptocurrency, and this scam highlights the growing use of AI in fraudulent schemes, which can lead to significant financial losses for victims.

Malwarebytes has launched Scam Guard, a free AI-powered scam detection assistant for Windows and Mac, expanding from its previous mobile-only availability. This tool helps users assess the risk of messages, links, and pop-ups, providing real-time threat intelligence and comprehensive scam detection. With scams becoming increasingly sophisticated, Scam Guard aims to empower users to make informed decisions and avoid falling victim to scams.

Threat actors are sending fraudulent letters to Trezor and Ledger users, impersonating official communications to steal recovery phrases. These letters create urgency by claiming users must complete an ‘Authentication Check’ or ‘Transaction Check’ by specific dates, such as February 15, 2026, for Trezor. The letters lead victims to phishing sites designed to steal sensitive information, a significant risk given past data breaches that exposed customer information.

Over 30 malicious Chrome extensions, posing as AI assistants, have been installed by at least 260,000 users. These extensions steal sensitive data, including API keys and emails, and many remain available on the Chrome Web Store. LayerX Security discovered this campaign, named AiFrame, which utilizes a common codebase across the extensions and targets Gmail users specifically.

Online dating scams are increasingly using AI technologies, making them harder to detect. In 2023, reported losses to romance scams reached $1.14 billion, with 15% of U.S. adults affected. The use of deepfake images and AI chatbots is transforming how scammers operate, leading to significant emotional and financial manipulation of victims.

Cybercriminals are using AI tools like Vercel to create convincing fake websites that impersonate established brands like Malwarebytes. Recent data shows over 18,000 holiday-themed domains were registered, with at least 750 confirmed as malicious. This trend highlights the ease with which attackers can exploit AI technology to conduct credential harvesting, payment fraud, and malware distribution, posing significant risks to users and organizations alike.

The Netherlands Police arrested a 21-year-old man from Dordrecht for selling access to the JokerOTP phishing automation tool, which intercepts one-time passwords (OTP). This arrest is part of a larger investigation that began three years ago, leading to the dismantling of the JokerOTP phishing-as-a-service operation in April 2025. The tool has allegedly caused over $10 million in losses across 28,000 attacks in 13 countries, targeting users of platforms like PayPal and Amazon.