Browsing: Scams & Fraud

Learn about the newest online scams, phishing attempts, and fraud tactics, along with tips to recognize them and protect your accounts and identity.

Fraudulent High-Yield Investment Programs (HYIPs) are experiencing a global surge, with over 4,200 scam websites identified by CTM360. These scams promise unrealistic returns, such as ‘40% return in 72 hours,’ and often operate like Ponzi schemes. In December 2025 alone, there were over 485 incidents related to these scams, indicating a significant threat to potential investors.

Malwarebytes has launched Malwarebytes in ChatGPT, allowing users to receive security assistance directly within the ChatGPT platform. This integration aims to combat the growing scam crisis, which has cost consumers $442 billion in the past year, a figure that has surged over 600% in four years. By leveraging Malwarebytes’ threat intelligence, users can quickly assess potential scams and receive guidance on safer online practices.

Jason Rebholz, CEO of an AI security startup, experienced a deepfake job application for a security researcher role. The candidate’s profile raised multiple red flags, including an anime profile picture and a resume hosted on Vercel. This incident highlights the growing risk of deepfake scams targeting companies of all sizes, with significant implications for cybersecurity and privacy.

A large-scale cloud storage subscription scam has been targeting users globally with emails falsely claiming payment failures. The campaign has intensified over recent months, with recipients receiving multiple scam emails daily. These emails often use personalized subject lines and threaten account blockages or deletions, creating a sense of urgency to deceive users into providing payment information.

Helpdesk impersonation is a significant social engineering attack where attackers pose as IT support to manipulate users into revealing sensitive information. This type of scam can lead to unauthorized access to accounts and systems, putting organizations and individuals at risk. The article highlights the importance of awareness and vigilance against such tactics to protect personal and organizational data.

ESET researchers have uncovered an Android spyware campaign named GhostChat that employs romance scam tactics to target individuals in Pakistan. The malicious app masquerades as a chat service and is designed to steal data from infected devices. Victims are lured into downloading GhostChat from unofficial sources, as it is not available on Google Play, and the app runs in the background to monitor device activity and collect sensitive information.

McAfee has upgraded its Scam Detector to better protect users against QR code scams and suspicious messages across various apps. In 2025, Americans received an average of 14 scam messages daily, leading to significant time lost in identifying legitimate communications. The new features include instant QR safety checks and smarter social messaging protection, addressing evolving scam tactics that increasingly target users personally.

Email addresses ending in .eu.org may appear trustworthy, but they are increasingly used by fraudsters to create disposable accounts. The .eu.org domain is a public subdomain service that allows anyone to request free subdomains without identity verification. This has led to the rise of temporary email services that exploit the perceived credibility of the domain, making it crucial for users and organizations to verify the legitimacy of email addresses before trusting them.

Leaked documents reveal the harsh realities of life in the Boshang scam compound in Laos, where workers are trapped in debt bondage and forced to commit fraud. The operation, part of a larger trend of ‘pig butchering’ scams, has defrauded victims of approximately $2.2 million over 11 weeks. This situation highlights the severe risks of human trafficking and cybercrime in Southeast Asia, affecting both victims and the broader digital security landscape.

A new malware-as-a-service called ‘Stanley’ offers malicious Chrome extensions that can bypass Google’s review process. This service allows attackers to overlay phishing content on legitimate websites using full-screen iframes. With features like silent auto-installation on multiple browsers and geographic targeting, Stanley poses significant risks to users and organizations alike.