All posts tagged: phishing

Amazon Order Email Change Raises Phishing Concerns

Amazon Order Email Change Raises Phishing Concerns

Amazon is making its order confirmation emails harder to trust, giving scammers another reason to make fake ones look legitimate. Instead of showing shoppers the exact product they purchased, Amazon’s newer order emails can display only broad categories, forcing customers to open the Amazon app or website to view the actual order details. An Amazon spokesperson told The Verge that the company made the change to simplify communications and reduce the amount of customer information shared outside its own channels. The Verge further pointed out that the move is tied to the company’s effort to prevent external AI shopping agents from accessing detailed purchase data via email. But the privacy move also removes details customers may use to distinguish legitimate order confirmations from generic phishing emails, making it more important to verify messages directly through Amazon. The paradox Amazon is trying to deal with Rather than resisting AI, Amazon is bringing it more deeply into its shopping business with Alexa for Shopping, which helps customers discover products, compare options, and make purchasing decisions. The distinction …

ChatGPT Enters Top 10 Phishing Brand Ranking

ChatGPT Enters Top 10 Phishing Brand Ranking

A new name in an old club. For the first time, ChatGPT has cracked the top 10 most impersonated brands in phishing attacks, according to Check Point’s Q2 2026 Brand Phishing Report. It’s a notable shift for a list that’s long been dominated by the same handful of household names — Microsoft, LinkedIn, Google, Apple and Amazon — which together account for more than half of all brand phishing attempts tracked this quarter. Microsoft alone made up 22.6% of attempts, nearly double any other brand. ChatGPT’s share is still small by comparison — about 1.1% of tracked attempts, putting it in the same tier as PayPal (1.3%), WhatsApp (1.4%) and Facebook (1.9%). But the milestone matters because it shows criminals have decided OpenAI’s chatbot is now mainstream enough to be worth faking. How the scams work One documented case from June involved a fake ChatGPT Plus payment failure email designed to mimic an official OpenAI billing notice. Clicking through led victims to a fraudulent page built to harvest full credit card numbers. Image: Check Point Check Point …

Govt mulls common messaging platform rules after WhatsApp row

Govt mulls common messaging platform rules after WhatsApp row

The Central government is considering introducing common regulatory standards for messaging platforms operating in India following the controversy surrounding WhatsApp’s proposed username feature, according to multiple reports. The proposed framework is aimed at creating a uniform regulatory approach for messaging services rather than taking platform-specific decisions. Disclaimer: We do not own any of the content, ideas, images, or text presented here. All rights belong to their respective owners. For more information and to view the original source, please visit the following link: Source link

CBI busts cyber fraud network that sent out bulk phishing messages, 3 arrested

CBI busts cyber fraud network that sent out bulk phishing messages, 3 arrested

MUMBAI: The Central Bureau of Investigation (CBI) has busted a cyber-fraud network’s illegal facility, through which hundreds of thousands of fraudulent, phishing SMSes were being sent across the country to dupe unsuspecting victims. Three persons allegedly linked to the network were arrested on Friday. CBI busts cyber fraud network that sent out bulk phishing messages, 3 arrested Phishing is a type of online scam where emails purporting to be from reputable companies are sent to deceive victims into divulging sensitive information such as login credentials and banking and credit card details. CBI officials said on Monday that the network’s facility, which was controlled by an online platform, was allegedly being used by cyber criminals located in India as well as abroad. The CBI probe is now investigating the involvement of the three arrested accused—S Singh, M Upreti and Himalaya—with the cyber-fraud network. The latter came under the CBI’s scanner as part of its ongoing drive, internally known as ‘Operation Chakra-V’, wherein it studied a huge number of fake SMS messages—threatening digital arrest, offering loans and …

Beware of this sneaky Google phishing scam

Beware of this sneaky Google phishing scam

Attackers are sending phishing emails that appear to be from “[email protected],” presented as an urgent subpoena alert about “law enforcement” seeking information from the target’s Google Account. Bleeping Computer reports that the scam utilizes Google’s “Sites” web-building app to create realistic-looking phishing websites and emails that aim to intimidate victims into giving up their credentials. As explained by EasyDMARC, an email authentication company, the emails manage to bypass the DomainKeys Identified Mail (DKIM) authentication that would normally flag fake emails, because they came from Google’s own tool. The scammers simply entered the full text of the email as the name of their fake app, which autofills that text into an email sent by Google to their own chosen address. When forwarded from the scammer to a user’s Gmail inbox, it remains signed and valid since DKIM only checks the message and headers. PayPal users were similarly targeted using the DKIM relay attack last month. Finally, it links to a real-looking support portal on sites.google.com instead of accounts.google.com, hoping the recipient won’t catch on. Etherem Name …

Better ‘Cyber Hygiene Among Small Businesses

Better ‘Cyber Hygiene Among Small Businesses

The proportion of businesses in the UK reporting cyber attacks and data breaches has dropped from 50% to 43% in the last year. A government study has attributed this to the “observed strengthening of cyber hygiene among small businesses.” The prevalence of cyber crime overall among UK businesses and charities of all sizes has remained consistent year-over-year, according to a recent government study. Phishing also remained the most common type of cyber crime, attack, or breach among organisations in the UK. Only 680,000 of the 8.58 million cyber crimes experienced by businesses were not categorised as phishing. Nevertheless, ransomware attacks in the UK have doubled from 0.5% of businesses experiencing them in 2024 to 1% in 2025. The results were published in the cyber breaches survey by the Department for Science, Innovation and Technology and Home Office. Its findings were based on responses from 180 businesses and 1,081 charities between August and December 2024. UK’s cyber crime stats by company size While the prevalence of cyber incidents among medium and large businesses has remained relatively …

Cybercriminals Offer Access to ‘Lucid’ Phishing Platform to Target iPhone, Android Phones in 88 Countries

Cybercriminals Offer Access to ‘Lucid’ Phishing Platform to Target iPhone, Android Phones in 88 Countries

Cybercriminals are using massive device farms that comprise iPhone and Android smartphones in order to send phishing messages to users in 88 countries, according to security researchers. The ‘Lucid’ phishing-as-a-service (PhaaS) platform is designed to deliver messages via iMessage and rich communication services (RCS) chats, with links that lead to phishing websites. These messages are capable of evading typical SMS spam filters due to end-to-end encryption (E2EE). The cybercriminals are also selling licences to use the Lucid platform via a Telegram channel. Lucid Platform Claimed to Deliver Over 100,000 Messages Every Day Unlike regular SMS, messages are delivered to users via iMessage or RCS on iPhone and Android smartphones, respectively. As these are E2EE messaging services, the messages have a higher delivery rate than SMS phishing messages, according to Prodaft’s report. These messages are also cheaper than SMS, as there are no operator charges. One of the alleged device farms used to send tests via iMessagePhoto Credit: Prodaft   In order to deliver a high volume of messages via iMessage, Lucid uses large iOS device …

Google Chrome Update Fixes Zero-Day Security Flaw That Targeted Media, Government and Educational Institutions

Google Chrome Update Fixes Zero-Day Security Flaw That Targeted Media, Government and Educational Institutions

Google has fixed a serious security vulnerability affecting its Google Chrome browser, that allowed attackers to bypass its security features. The flaw was discovered by Kaspersky’s Global Research and Analysis Team (GReAT), and was reportedly used to target media outlets, educational institutions, and government organisations. Google Chrome users should update their browser in order to remain protected against the vulnerability, and other Chromium-based browsers are also expected to receive an update that resolves the issue in the coming days. Attackers Sent Personalised Phishing Emails as Part of ‘Operation ForumTroll’ According to details shared by the security firm, an advanced persistent threat (APT) group is suspected to have run a campaign dubbed Operation ForumTroll to take advantage of a zero-day (previously unknown, undetected) vulnerability in Google Chrome for Windows, identifed as CVE-2025-2783. The attackers would send personalised phishing emails to persons from media outlets, educational institutions, and government organisations located in Russia. These emails would invite them to join the “Primakov Readings” forum. Kaspersky claims that the links would expire quickly, and would eventually send users to the real forum. …

Microsoft Adds Even More AI to Its Security Copilot

Microsoft Adds Even More AI to Its Security Copilot

Vasu Jakkal, corporate vice president, Microsoft Security. Image: Microsoft Microsoft is raising the bar in the cybersecurity game with a new wave of AI-driven security agents. The company announced an expansion of its Microsoft Security Copilot, introducing six AI agents designed to tackle cyber threats head-on. These agents, set to launch in April 2025, will assist overwhelmed security teams in handling phishing attacks, data breaches, and identity threats. Cyberattacks have reached unprecedented levels, with Microsoft detecting more than 30 billion phishing emails in 2024 and tracking 7,000 password attacks every second. The new Security Copilot agents aim to ease the burden on cybersecurity teams by automating threat detection and response, enabling faster and more effective protection. SEE: Next-Gen AI: Latest Microsoft and NVIDIA Collaboration is a ‘Significant Leap Forward’ AI agents to the rescue The new Microsoft Security Copilot agents include: Phishing triage agent: Filters phishing alerts, reducing false alarms. Alert triage agents: Prioritizes insider risk alerts for faster response. Conditional access optimization agent: Spots security gaps in identity systems. Vulnerability remediation agent: Fixes vulnerabilities …