Browsing: Scams & Fraud

Learn about the newest online scams, phishing attempts, and fraud tactics, along with tips to recognize them and protect your accounts and identity.

The ongoing interest in Ghislaine Maxwell and Jeffrey Epstein files has led to increased cybersecurity risks, including phishing attacks and misinformation campaigns. Cybercriminals exploit public curiosity, using tactics such as fake document dumps and malicious emails claiming access to sealed court files. This situation highlights the need for heightened awareness and caution among users and organizations regarding digital threats linked to high-profile cases.

AI is transforming social engineering attacks, making them cheaper and easier to execute. Miguel Fornés from Surfshark highlights how AI agents automate tasks like research and targeting, enabling scammers to conduct phishing campaigns with minimal human involvement. A notable incident involved a finance worker who was deceived into transferring millions to fake executives, underscoring the urgent need for verification procedures and checks in communications.

Germany’s BfV and BSI have issued warnings about a phishing campaign targeting politicians, military personnel, and journalists via the Signal app. The attackers impersonate Signal support to gain unauthorized access to accounts by tricking victims into providing their PIN or verification codes. This poses significant risks to confidential communications and network security, as compromised accounts can lead to broader network breaches.

Fraud prevention relies heavily on managing latency during online transactions, with systems typically requiring 50 to 100 milliseconds to make decisions. Organizations like LexisNexis Risk Solutions have successfully reduced decision latency from 120 milliseconds to 30 milliseconds, enhancing fraud detection. This reduction is crucial as fraudsters increasingly use automation and AI to exploit systems quickly, making timely decision-making essential for preventing losses.

German security authorities have issued warnings about state-backed phishing attacks targeting military officials, diplomats, and journalists via Signal. The attackers impersonate Signal support to trick users into revealing security PINs or scanning malicious QR codes, allowing them to take over accounts. This poses significant risks to sensitive communications and professional networks across Germany and Europe.

A new wave of spam emails is inundating users, with many receiving automated messages labeled ‘Activate your account’ from unsecured Zendesk support systems. This incident mirrors a similar attack from January, where attackers exploited Zendesk’s ticket submission feature to send mass spam. The ongoing abuse of these systems raises concerns about user privacy and the effectiveness of Zendesk’s security measures.

In 2025, phishing attacks have evolved significantly, with malicious emails detected on average every 19 seconds. AI systems now facilitate the generation and rollout of these campaigns, making detection more challenging for security teams. Credential phishing has notably increased, with a sharp rise in the use of the .es domain for credential theft, highlighting the need for heightened vigilance among users and organizations.

Avast has announced the global availability of Avast Scam Guardian and Scam Guardian Pro for mobile devices, along with Avast Deepfake Guard for Windows PCs. This AI-powered feature aims to detect malicious audio in video content, addressing the rising threat of deepfake scams. In Q4 2025, Gen Threat Labs identified 159,378 unique deepfake scams, emphasizing the urgency for enhanced protection against these sophisticated fraud tactics.

Scammers are increasingly using deepfake technology to commit fraud, including replicating voices in kidnapping hoaxes and impersonating executives for financial gain. These scams can lead to significant emotional distress and financial losses for victims. Tools like Avast Deepfake Guard are available to help users verify authenticity and protect against these threats.

Chinese money laundering networks (CMLNs) have laundered approximately $16.1 billion in illicit cryptocurrency in 2025, accounting for nearly 20% of all such funds globally. The U.S. Treasury has targeted entities like the Huione Group for their involvement in laundering operations linked to North Korean threat groups. This surge in laundering activity highlights the challenges law enforcement faces in combating sophisticated cybercrime operations that exploit cryptocurrency’s anonymity.