Stories, guides, and threat reports from the team building SafeBrowz. Phishing, crypto wallet drainers, scam emails, news-driven scam alerts, and the browser-side protections that actually work.
Try a different keyword like , , or .
Apple never places unannounced FaceTime calls. Scammers use the trusted channel to talk you into codes, card details, and remote access before you think.
The fake closure warning leads to a counterfeit login page that captures your password and your 2FA code. Here is the 30-second check that beats it.
Fake charities, copycat Venmo handles, FEMA impostors, and cash-up-front contractors follow every disaster. Verify before any money moves.
You cannot judge a link you cannot read. The preview tricks that still work in 2026, and the checker that follows the chain to the final page.
A "Migrate to Coinbase Wallet" email that hands you a recovery phrase is a phishing scam. The phrase belongs to the attacker, so any crypto you deposit gets drained.
A LastPass email about updated security policies from [email protected] is a phishing scam, not LastPass. Here is how to spot it and stay safe.
Lidl's 2026 data breach leaked names, emails, phone numbers and dates of birth. Scammers now send convincing fake Lidl texts and emails. Here is how to spot them.
Got a RingGo text about an unpaid parking session or a parking charge? RingGo never asks for card details by text. Here is how to spot the fake payment link.
A brand sponsorship offer in your creator inbox pushes you to download a "media kit" that installs an info-stealer, steals your login session, and bypasses 2FA to take over the channel. How to spot the fake brief and verify a real deal.
A recruiter email impersonating Adobe, Netflix, and OpenAI routes you to a Browser-in-the-Browser fake Google login. How the popup fakes accounts.google.com, and how to spot a real sign-in window from a painted one.
Got a Bath & Body Works email about an unrecognized login? It is phishing. The verify-account button leads to a fake login page. How to check the alert safely and what the real sign-in looks like.
Five real detection APIs compared for developers: SafeBrowz, Google Safe Browsing, VirusTotal, IPQualityScore, and urlscan.io. Which fits a link shortener, a crypto wallet, or a SOC team, and what each really costs.
A text asks "Did you authorize this charge? Reply YES or NO." Reply, and a fake fraud-department caller talks you into reading back your security code, then drains the account. Here is the tell and what to do.
A text claims your Alberta health card is obsolete and you must re-register through a link, posing as Service Canada. It is a scam - health cards are provincial, not federal. Here are the tells and how to report it.
AI-built "Security Verification" gates use a real Cloudflare Turnstile CAPTCHA as a cloaking filter: pass it and you are redirected into a supplement-scam funnel. We pulled the live pages apart - usevicks.online and 4 sibling domains, now blocklisted.
A caller threatens to cut your power within the hour, then texts a barcode to pay cash at a store - the money loads a scammer's account. PG&E customers lost $211,000+ in half of 2026. The 30-second check that beats it, for any utility.
A letter from a "lawyer" says a stranger with your last name left millions in unclaimed life insurance to split. The FTC re-flagged it July 9, 2026: there is no policy - just SSN harvesting and advance fees. How to check real unclaimed money free.
A fake "verify your account" or W-8BEN email copies Questrade almost perfectly and links to a lookalike login built to drain your brokerage. How to tell the real alert from the phish, plus the Robinhood and Wealthsimple variants and what to do if you clicked.
An SMS about a pending traffic challan links to a fake Parivahan portal that only completes on your card, then drains it. echallan.cyou and parivahan.eu.cc are fakes; the one real site is echallan.parivahan.gov.in.
Two big Cash App scams: fake "support" that asks for your PIN or sign-in code, and a stranger's "accidental" payment you get baited to refund. How to spot both.
That "TSA PreCheck expiring, renew now" email or lookalike .com is a scam. It charges $140 for a ~$59 renewal and harvests your data. Renew only on .gov.
A phishing wave impersonating Amazon.co.jp asks you to "confirm" your Prime membership. The fake login loads only for Japanese IPs, so sandboxes miss it.
A text saying your ID Austria certificate is expiring links to a fake renewal page, then a "bank" calls to install AnyDesk and drain your account.
A WhatsApp saying your Indane, Bharat Gas or HP Gas connection needs urgent LPG e-KYC via a link or "gas KYC" APK is a bank-draining scam. How to spot it.
A Microsoft 365 email saying messages are "held" or "quarantined" with a button to release them is phishing. The button opens a fake Outlook login that steals your password.
Fake "Official 250th Anniversary Gold Coins" on Telegram and July 4 gift giveaways on WhatsApp are scams. Only the U.S. Mint sells real coins. Spot both fast.
That "Costco reward survey" offering a $500 gift card is a phishing scam. It steals your card and signs you up for hidden monthly charges. How to spot it fast.
Samsung Messages shuts down July 6, 2026 and scammers are sending fake "switch to Google Messages" texts with links. The real notice is in-app and never a link.
A "Walmart fraud department" robocall about a suspicious order, or a "you won a gift card" text, is an impersonation scam. How to spot the fake call and phishing link fast.
A DM from a verified friend asking you to "vote for me to co-host a Spotify and Google podcast" is a fake-login worm that steals your X account. Forensic breakdown of a live outbreak.
A "Signal support" message asking for your backup recovery key is a scam. The FBI warns it hands your whole chat history to attackers, and a reset does not fix it.
Getting an Evri text or email about a missed delivery or redelivery fee? Evri never charges a fee to redeliver by text. How to spot the fake link and verify safely.
An Argos order you did not make is a sign your account was taken over with a reused password. What to do right now and how to lock it down.
An email saying your Instagram broke Community Standards and will be disabled in 24 hours unless you appeal is phishing. Real appeals live in the app, not a link.
Getting a Purolator text about a held package or redelivery fee? Purolator never charges a fee by text. How to spot the fake link and verify safely.
Got a Temu order, reward, or refund text? Temu sends order updates, but never asks for your card or a fee for a free gift. How to spot the fake in 30 seconds.
Google's June 2026 advisory warns of fake "set up a crypto node for passive income" tutorials. The code you paste, or the transaction you sign, quietly drains your wallet.
A Reddit DM from the "moderation team" telling you to verify your account at a link is phishing. Reddit mods never DM you to a login page. How to spot the fake.
INTERPOL and Group-IB dismantled SniperDz, a phishing kit cloning PayPal, Netflix and 30+ brands across 20,000 domains. How to spot a templated fake login page.
Scammers inject fake Norton, McAfee, Apple and PayPal order alerts with a callback number into Shopify's trusted Shop app. The app is real, the receipt is not. How to spot it.
The FBI warns scammers cloak fake login pages behind redirect chains, showing scanners safe content and victims the trap. Why a clean-looking link can still steal your password.
A CAF data leak is fuelling fake "refund" and "RIB update" SMS and emails. The real CAF never asks for your bank card or password through a link. How to spot the scam.
Fake "buy your Crit'Air sticker" and "unpaid ZFE fine" texts lead to clone sites that overcharge or steal card data. Only certificat-air.gouv.fr is real, at 3.85 euros.
Fake Doctolib "refund" and "reschedule urgently" texts plus clone sites surged after a 2026 patient-data leak. Doctolib never refunds you by SMS link. How to verify.
An email from the "Police nationale" or "Gendarmerie" accusing you of a crime and threatening arrest in 72 hours is mass-sent scareware, not a real summons. Never reply or pay.
Scammers pose as Banque de France or ACPR agents, and deepfake the Governor, to push crypto fraud. The bank never recommends a platform or asks for your details by phone.
A fake EDF or Enedis "power cut in 24 hours" SMS links to a clone payment page. The real EDF warns of an unpaid bill by letter with a 30-day notice, never an SMS link.
FTC 2025 data: imposter scams are the number-one fraud, bank impersonation is the costliest, and $920M was lost to government imposters. How to tell a real bank or agency message from a scam.
Scammers plant fake "support" numbers so Google AI Overviews and chatbots surface them, and you reach a fake call center. How AI-search poisoning works and how to verify a real number.
Google does send real storage-limit emails, which is what makes this scam convincing. Tell the genuine google.com notice from the phishing "Drive will be suspended" lookalike.
Fortra found attackers abusing Microsoft 365 Groups, Outlook calendar invites and shared files to hide phishing inside routine work. How CalPhishing works and how to spot it.
A bank SMS in Spain telling you to call a number, then an AI-cloned "security department" rushing a transfer, is a scam INCIBE confirmed. Never call the number in the text.
Amazon's $2.5B FTC settlement is real, but a call, email or text asking for a fee or your bank details to "claim your Prime refund" is a scam. The real refund needs none of that, and the FTC never contacts you about it.
The Bluekit kit streams the real login page from the attacker's own browser, so you type your password and your MFA code straight into their session. Why SMS, app and push codes do not stop it, and what does.
India's I4C warns of the "Boss Scam": fraudsters hijack a CEO's WhatsApp or pose as the RBI, then order finance staff to wire an urgent, secret transfer. The one rule that stops it.
A WhatsApp "pending traffic challan, install the app to pay" message hides an e-Challan.apk banking trojan that reads your SMS, steals OTPs and drains your bank. Real challans are never an APK.
That "power will be cut tonight" SMS from a plain 10-digit number is a scam. It pushes a fake bill app (APK) that steals your OTPs and empties your bank. Here is how to spot it and the one DLT-header tell that exposes it.
Fake AI coding plugins and fake ad-blocker extensions quietly steal your OpenAI and DeepSeek API keys and your ChatGPT and Claude conversations. The June 2026 wave, and how to spot a malicious "AI" tool.
[email protected] is a real PayPal address, so why is the invoice a scam? Scammers abuse PayPal's own system to send a real-looking charge for a Coinbase purchase you never made, with a "call this number" trap. What to do instead of paying or calling.
Fake "claim your airdrop" pages on free hosts like pages.dev empty your wallet the moment you connect. Two real June 2026 examples (fake TokenSight and Tonkeeper airdrops) and the red flags that stop you before you click.
A site posing as an "Ethereum Genesis" airdrop fakes a wallet-connect error, then asks you to paste your recovery phrase, and drains everything. Ethereum has no Genesis airdrop. The one rule that stops it, and what to do if you already typed your seed.
A portable fake cell tower forces nearby phones to connect and blasts smishing texts, bypassing carrier filters and spoofing the sender so it lands on your bank's real message thread. Why reporting to 7726 does not help, and the one thing it cannot fake.
The #1 "Sponsored" result for health insurance or Medicare is often a paid impersonator dressed up as an official .gov site, built to harvest your info or charge junk fees. How to spot the fake ad and reach the real healthcare.gov and medicare.gov.
Fake Facebook and TikTok senior-activity ads lead to a WhatsApp APK that silently removes Singpass and ScamShield, then scammers posing as Ministry of Law or police officials drain the bank. SPF: 8 cases, S$69,000. Why you never sideload an APK from a link.
The 407 ETR unpaid-toll text now threatens your credit score, licence-plate renewal and court to rush you. A real 407 ETR text only ever links to 407etr.com, so a link to any other domain, or a request for your card or PIN, is the scam. The red flags.
A tiny surprise deposit lands in your account, then a disguised UPI collect request fires, and checking the balance is the trap. You never enter a UPI PIN to RECEIVE money, only to pay. How the SBI jumped-deposit scam works and how to stop it.
A site posing as ether.fi runs a fake "World Cup voting and rewards" promo that drains your wallet the moment you connect. ether.fi has no token airdrop. The only real site is ether.fi, and how SafeBrowz flags the lookalike connect page.
An Apple "Security Alert" or blocked Apple Pay text telling you to call a number is a callback scam. The fake "Apple fraud" line harvests your Apple ID, 2FA code and card. Apple never texts you to call. How to verify and report safely.
You never click a link or scan a QR to receive PayNow money. A message telling you to verify via Singpass or scan a code to get paid is a scam. How the Singapore PayNow and fake-bank-transfer scam works, and the one rule that stops it.
A Sparkasse email or SMS saying your pushTAN app must be re-activated or your account will be blocked is phishing. How the S-pushTAN scam takes over your account, why not every sparkasse-city.de domain is fake, and how to verify safely.
A wave of ~150 malicious extensions impersonated MetaMask, Exodus, Rabby and TronLink to drain wallets. How to verify the real wallet extension, the one seed-phrase rule, and how SafeBrowz flags the fake download and lookalike pages that push them.
Fake Trezor security-alert and firmware-update emails push a page that asks for your 12 or 24-word recovery seed, then drains the wallet. The one rule that stops it: Trezor never asks for your seed, and it is only ever entered on the device itself.
A fake McAfee invoice says your subscription auto-renewed for $399 and tells you to call a number to cancel. That number is a refund-scam call center. Why the From line proves nothing, and the 30-second way to verify in your real McAfee account.
A text or email saying your data leaked in the 24-billion-record breach and to "check if you are affected" is a phishing lure that harvests your logins. How the scam works and the one safe way to check.
A text from the "DWP" about an unclaimed £200-£300 energy support allowance is a scam - the scheme does not exist. How the 2026 UK smishing works, the red flags, and what to do.
An email saying your ELSTER Steuerbescheid is ready or a Finanzamt refund is waiting is phishing. How the 2026 German tax-refund scam works, the fake domains, and what to do.
An Agenzia delle Entrate email about a tax refund or a "crypto declaration" form is phishing. How the 2026 Italian Revenue Agency twin-campaign scam works and what to do.
A WhatsApp voice note from a friend asks you to complete a Tikkie - the voice is AI-cloned and the link is fake. How the 2026 Dutch Tikkie scam drains accounts and the one rule that stops it.
A QR code or link that triggers a BankID signature to "verify" or "receive a Swish" is a scam. How the Sweden Swish and BankID phishing wave works and how to stay safe.
A "buyer" on Allegro Lokalnie wants to pay by courier and sends you a link to "confirm" the payment? It is a phishing scam that steals your card. How both variants work, the fake domains, and the one rule that stops it.
A phishing page steals your card and the code your bank texts you, then the scammer adds your card to their own Apple Pay or Google Wallet and mules tap it at stores to launder the money. The one rule that stops it.
Fake "digital yuan" wallet apps, "claim your e-CNY red packet" phishing pages, and promoter-recruitment pyramid schemes are spreading. China's central bank never airdrops red packets through a texted link. How the CBDC scam works and the red flags.
The FBI says crypto-investment scammers now dispatch couriers to victims' homes to collect cash, verified by a passphrase or a dollar-bill serial number. How the cash-pickup twist works, why elders are targeted, and what to do.
A texted link that shows a Cloudflare "Error 524" page, then loads a login or payment form, is a cloaking trick that hides phishing from scanners. How the decoy works, the lures that carry it, and how to stay safe.
Tagged in a GitHub issue saying you won $5,000 in CLAW tokens? It is a wallet drainer that abuses GitHub's trust. How the fake-airdrop bait works and the one rule that keeps your wallet safe.
The only real logins are chase.com and jpmorgan.com - any lookalike domain, free-host fake login page, or link from an email is phishing. How to spot a fake Chase or J.P. Morgan site, and what to do if you entered your details.
Pharming sends you to a fake website even when you type the correct address, by poisoning DNS through a hijacked router, hosts-file malware, or a bad resolver. How it works and how to defend.
Instead of a link, the phishing page is attached as an .html or .svg file. Opening it renders a fake login locally, so email scanners find no URL to catch. SVG can even run JavaScript.
Attackers buy real-looking Sponsored search ads that lead to brand-lookalike logins or trojanized downloads. The top ad for a brand or app is sometimes the scam, not the real site.
A call or text saying you missed jury duty and a warrant is out unless you pay a fine is always a scam. Real courts never call to demand payment. The tells, the AI-voice twist, and what to do.
Cloned Airbnb and VRBO listings paid by Zelle, plus lookalike airline sites from search ads. How the 2026 summer travel scams work and how to book safely.
A call or text saying your Social Security number is suspended and you must pay to reactivate it is a scam. SSA does not suspend SSNs. The red flags and what to do.
Got a call, text, or email offering student loan forgiveness for a fee? It is a scam. How the 2026 repayment-restart scam works, the red flags, and what to do.
The FBI, Google and Lumen disrupted "Outsider Enterprise", a China-based phishing-as-a-service that used AI to mass-produce 1M+ smishing URLs and steal 3.87M cards for $1.9B in losses. One operation gone, but AI makes brand-perfect scam texts cheap and endless. How to spot them, and the one rule AI cannot beat.
France's ANTS identity portal (ID cards, passports, permis, carte grise) was breached - up to 19 million records leaked through an IDOR flaw. Scammers now send hyper-personalised fake "renew your document" texts and emails using your real name and address. How to spot them, and why ants.gouv.fr is the only real domain.
This address is used by BOTH real Amazon notices AND scammers - the From line can be faked, so it proves nothing. If the email has urgency and a link (sign-in alert, account on hold, update payment), treat it as phishing. How to verify safely by signing in directly and checking your Message Center.
An email or text says your Roku account is locked or your billing failed, with a link to "reactivate". It is phishing for your Roku login and card. The real Roku only uses roku.com and never charges a reactivation fee. The tells, and what to do if you clicked.
A "your YouTube Premium payment failed" or "free membership gift" email leads to a fake Google sign-in that steals your whole Google account, not just YouTube. Why this one is more dangerous, and how to verify YouTube billing safely.
A Crunchyroll email saying your membership payment failed or your account is suspended is almost always a scam aimed at your login and card. The real domain is crunchyroll.com. How to verify safely and recover if you clicked.
A SiriusXM email, text or robocall says your radio subscription expired or offers a suspiciously cheap renewal, to steal your card. The real SiriusXM only uses siriusxm.com and never demands gift cards. Spot the fake and stay safe.
Ledger users are getting a paper letter with a QR code demanding a "post-quantum security update" by June 26. It is a scam - Ledger never mails you and never asks for your 24 words. How the QR drains the wallet, and how to verify.
Fake "free World Cup stream" Android apps hide the Massiv and Perseus banking trojans that overlay fake bank logins, steal OTP codes, and read your saved crypto seed phrase. Why you must never sideload a stream APK, and the accessibility-permission red flag.
One signature can delegate your entire wallet to a sweeper contract that drains everything. The CrimeEnjoyor drainer abuses EIP-7702 - one victim lost $1.54M. How it differs from Permit2, the signs, and how to check and revoke a delegation.
Xaman's founder warns of 10+ fake XRP wallet and airdrop domains a day. How the fake "XRP DeFi protocol" connect-wallet sites and lookalike XUMM/Xaman pages drain XRP, the signals that expose them, and why you should never "claim" an airdrop you did not expect.
Google sued the China-based "Outsider Enterprise" over 9,000 fake sites, 1M+ fraudulent URLs and 2.5M scam texts, and is backing seven bipartisan anti-scam bills. Our honest read: the lawsuit and laws are good but reactive, and the one gap they leave is the moment you click the link.
Fake police, CBI or court officers keep you on a video call, say you are under "digital arrest", and pressure you to transfer money to "verify" funds. How the scam works, the red flags, and exactly what to do and where to report in India.
A password pop-up on a site you trust can be fake, injected by a hijacked third-party script like polyfill. How to tell a real login box from a fake one, why you should hit Cancel and sign in directly, and what to do if you typed your password.
A receipt email showing a charge and a phone number but no clickable link is callback phishing (TOAD). How the no-link invoice trap evades email filters, why a verified-sender checkmark is meaningless, and what to do.
Verification pillar covering 10 brands. The 30-second universal check, exact official sender domains for PayPal / Apple / Disney+ / Hulu / Netflix / HBO Max / Spotify / Paramount+ / Amazon / Microsoft / DocuSign, and the 5-step recovery if you already clicked. Built for the moment a suspicious email lands in your inbox.
Flare and BleepingComputer exposed Lucifer, a crypto wallet drainer sold as a service - Permit2 abuse, a 20% affiliate cut, and a cloning feature that floods the web with near-identical phishing sites. How it works, and how to spot a clone before you sign.
A QR code is just a URL you cannot read with your eyes. The exact check to run before you scan: preview the decoded link, spot sticker-over-sticker attacks, and read the scan-to-pay and scan-to-verify red flags.
Unpaid toll and traffic fine texts are surging worldwide in 2026, run by one syndicate hitting the US, UK, Australia, Japan, Taiwan and Korea with the same kit. How it works, the red flags, and how to check a link before you tap.
That text saying the DMV will suspend your license over an unpaid traffic ticket is a scam. How the 2026 DMV smishing wave works, the QR-code variant, the red flags, and exactly what to do if you got one.
Fake tickets, free-stream traps, giveaway and sponsor impersonation, counterfeit jerseys, travel fraud, smishing - every World Cup 2026 scam in one place, with the rules that keep you safe.
"You won World Cup tickets" from a sponsor you never entered. How fake FIFA, Coca-Cola, adidas and Visa giveaways harvest your card and data, and how to verify a real promo.
"Watch the World Cup free in HD" sites harvest cards and logins or push malware. How the fake-stream traps work, how to spot them, and the official broadcasters to watch safely.
A second friend request from someone you already know, with 12 mutual friends - but some of those mutuals are clones too. How the manufactured-social-proof scam works, and how to spot it.
Attackers weaponize Meta's own notifications - a "partner request" makes Meta send you a genuine, signed email carrying the scam in the page name. Why checking the sender fails, and how to stay safe.
A 9 PM call, her son's crying voice, a lawyer demanding bail tonight. She almost paid, then texted the real Daniel. How AI voice-clone family-emergency scams work, and the one rule (a family safe word) that stops them.
Fake virus popups, Microsoft/Apple "support" calls, remote-access fraud, search-ad scam numbers, and gift-card refund traps. How to spot, stop, and report tech support scams.
Bank "safe account" calls, fake IRS/police, tech-support callbacks, AI voice clones, OTP theft, robocalls. How every phone scam works, the one rule that stops them, and where to report.
Just got scammed? A calm step-by-step plan: stop the loss, recover by payment method (card, bank, Zelle, gift card, crypto), secure your accounts, report it, and dodge the second "recovery" scam.
Is that TV Licensing email or text real? Fake TV licence and cable-bill scams across the UK, US, Germany, Ireland and Japan - the 30-second check and how to report.
The complete employment-scam reference: fake remote jobs, "like and earn" task scams, overpayment and fake-check tricks, advance-fee equipment scams, money-mule reshipping, fake recruiters on LinkedIn and Telegram, and crypto fake-interview malware. The universal red flags, how to verify a real employer, and how to report it. Cites FTC, FBI IC3, ITRC, FlexJobs.
Is this store legit or fake? How fake stores and sellers operate, the universal 60-second check (domain age, reverse image, payment method, off-site reviews, contact and returns), safe ways to pay, what to do if you already paid, and how to report. Cites FTC, BBB, Action Fraud, Europol.
Every text scam in one place - fake delivery, unpaid toll, bank alert, tax refund, prize, wrong number. The 30-second check and how to report.
The complete guide to AI-powered scams - deepfake video, cloned voices, AI-written phishing, and fake AI app downloads. How they work and the defenses that still beat them.
Is the "verify your account" email really from Amazon? Amazon sends real sign-in prompts, but one asking for your password or card through a link is phishing. The verdict and the 30-second check.
Scammers message you inside the real Booking.com app, quoting your actual reservation, then send a fake "verify your card" link. The Norton-documented hotel-partner breach, the tells, and how to pay safely.
An FBI warning flags a login-code scam that needs no password and gets past MFA. You enter a code on the real Microsoft page and hand your account to an attacker. How it works and the one rule that stops it.
An unexpected $CJUP token lands in your Solana wallet impersonating Jupiter. The "claim" link drains it in minutes. Why a surprise airdrop is bait and the only real portal (jup.ag).
Amazon moved Prime Day to June 23-26, so the fake "Prime renewal failed" emails and lookalike deal pages are landing early. The NJCCIC warning, the tells, and how to shop the sale safely.
A DM sends a Calendly link to a fake Zoom or Teams call that downloads wallet-draining malware, often from a compromised account you trust. ZachXBT flagged it on X. The one tell, the red flags, and what to do.
A text says an item from your recent Amazon order was recalled and offers a refund with no return, then phishes your Amazon password for account takeover. The FTC warning, the one tell, the red flags, and what to do if you already signed in.
The FTC warned in May 2026 about fake Evite, Paperless Post, and Punchbowl invites that ask for your email password to steal Google and Microsoft logins. The one tell that exposes them, the red flags, and what to do if you already signed in.
A sponsored Google ad outranked the real uniswap.org link and pointed to a Cyrillic Punycode clone. One Permit2 signature drained roughly $400,000 in life savings. Hayden Adams called on Google to act. Anatomy of AngelFerno DaaS + how to revoke + 3-layer detection that catches the clone before the wallet popup.
FBI PSA260527 (May 27, 2026): Chinese-linked Ghost Stadium operates 300+ lookalike FIFA ticket sites harvesting card and PII data. Our 3-layer detection on typosquat domains + brand-pivot predictions (Olympics 2028, Champions League).
FBI PSA260521 (May 21, 2026): new Microsoft 365 phishing-as-a-service hijacks accounts via OAuth device-code abuse, bypassing MFA entirely. Our 3-layer detection analysis + what enterprises do right now.
New phishing campaign abuses ChatGPT's share-link feature to display fake "OpenAI outage" pages on the real chatgpt.com domain. The download leads to openew[.]app - a cross-platform infostealer. Why URL filters fail here, the 30-second user check, and the pattern coming for Claude / Gemini / Perplexity next.
India's MHA + I4C issued advisory TAU/ADV/013 on a Trust Wallet / BNB drainer. The fake "BNB Chain Verification" pivot from P2P platforms via WhatsApp to buepux.com. Why the third approval drains your wallet, plus the SafeBrowz Permit2 modal that warns before signing.
Indian UPI users lost billions to digital fraud in 2025-2026. Cross-country guide breaks down the 8 most common UPI scams - fake collect requests, QR swap attacks, autopay mandate fraud, KYC expiry calls - with red flags, 30-second checks, and 1930 / cybercrime.gov.in recovery paths.
FBI IC3 reports thousands of SIM swap cases yearly with massive crypto + bank losses. This guide breaks down the 5-step attack chain, the FCC 2024 rule, the 6-step lockdown every phone user should do, and recovery steps if funds are already gone.
Browser popup locks the tab, plays an alarm, gives a 1-800 number. Real Apple never does this. Full anatomy of the 2026 wave, the remote-access trap, the exact key combo to escape, and recovery steps if you already called.
Cross-country tax-refund SMS phishing. Real-sender format per country (HMRC, IRS, CRA, ATO). The universal rule: no tax agency texts about refunds. 6 instant red flags, 30-second verification check, bank chargeback paths if you already entered card details.
UK's #1 phishing topic - HMRC reports 200K+ complaints/year. Fake "£342.78 tax rebate" emails + Self Assessment lures + Marriage Allowance traps. Verify with Gov.uk Gateway only. Recovery via Action Fraud + Cifas.
"Your vehicle tax payment failed - £1,000 fine + clamp threat" SMS/email. DVLA never asks for payment by SMS. Lookalike domains (dvla-payment[.]uk). Verify via gov.uk/check-vehicle-tax. Recovery + Action Fraud.
Fake TV Licensing emails: "Licence expired", "Direct Debit failed", refund offer, over-75 free-licence trap. TV Licensing won't ask for personal/payment info by email. Verify via tvlicensing.co.uk/check-it-s-us.
RCMP 2024: $50M+ CRA impersonation losses. Fake "$428.50 refund" emails + aggressive "send Bitcoin to avoid arrest" voicemails. Verify only via CRA My Account. Recovery via CAFC + credit freeze.
Top scam targeting Canadian newcomers + seniors. Automated voicemail "SIN suspended" → fake officer → SIN/banking/identity extraction. Hang-up + look-up + call-back rule. Service Canada fraud + IDCare recovery.
ATO reports 30K+ phishing reports/year. Peak Jul-Sep (Australian tax year). Fake "$1,247 refund ready" + TFN suspension + BAS overdue templates. Verify only via myGov inbox + ATO ID 13 28 61.
One myGov password = access to Medicare, Centrelink, ATO, Immigration. Fake "account locked" emails route to phishing copies of my.gov.au. Verify only via my.gov.au. Recovery via Services Australia + IDCare.
Daniel ran a $580K wire on a Friday Zoom with his CFO and CEO on camera. Both were deepfakes. Arup Hong Kong lost $25M to the same attack in Feb 2024. Pindrop 2024: deepfake voice attacks up 350%. The callback rule that stops it.
Tyler accepted a $68K remote offer and sent $1,800 for "equipment insurance." No laptop arrived. FTC 2024: $501M lost to job scams (up 118% YoY). The deepfake video interviewer angle and how to spot it.
Jenna bought a $14 Stanley dupe from a viral TikTok creator. The lid leaked. The seller vanished. The $14 was the cover charge - your card data joined a marketplace database. CBP 2024 + FTC + DHS reports inside.
Eric Googled "Sora 2 Mac download." The top ad delivered RedLine Stealer. Three days later his MetaMask drained, his Coinbase logged in from another country. OpenAI has no installer. ESET/Bitdefender 2024 inside.
Megan was groomed for 4 months on Hinge and lost $48K. Vinh was trafficked into a Sihanoukville compound to run the scam. The two stories meet at UNODC's $63B 2024 estimate. Chainalysis traced $9.9B on-chain. The trafficking dimension.
The same wave hits every January through April. 7 active 2026 variants of TurboTax/H&R Block/IRS impersonation, the exact phrases, IRS Dirty Dozen 2024 alignment, and the Form 14039 + IP PIN recovery routine.
CISA flagged carrier-level SMS interception in Dec 2024. SMS 2FA is now the weakest link. The 12-minute upgrade: switch Google, Apple, Microsoft, Coinbase, X, Instagram, Discord, GitHub from SMS to TOTP. Hardware tier guide.
Linda gave her Medicare number to a friendly caller named "Karen." Three weeks later $3,400 of medical equipment was billed to her account from Texas. October to December is peak season. 5 active variants + 1-800-MEDICARE recovery.
Mia Zelled $1,160 for Beyoncé tickets via a Twitter DM. The seller blocked her in 2 hours. 5 active 2026 variants from PDF screenshots to fake StubHub lookalikes to Ticketmaster credential phishing. The 4-minute verification routine.
Rebecca paid a €4.50 USPS "customs fee" on December 22. By February she had $1,800 in fraud charges. Nov-Jan is peak delivery scam season. 5 active variants + the virtual-card defense from the safe payments guide.
Rachel paid her parents' phone bill on the top Google ad. Three weeks later $2,400 vanished to Amsterdam and Singapore. Google Ads Safety 2024: 5.5B ads blocked. Two-step defense: SafeBrowz + virtual card (RedotPay, Revolut, Wise, Crypto.com). Available in EN/AR/ES/ZH.
The night Mike sent $4,500 to a voice he had known for ten years. Forty seconds of TikTok voice + a tagged Lisbon trip = the call. FBI IC3 2024 $16.6B losses, ITRC 2025 voice clone reports up 250%. Per-platform privacy reset + family code word inside.
Every French worker has €500-€8000 of CPF training credit. Scammers call claiming it expires (it does not), then bill fake training providers against your balance. Real CPF only at moncompteformation.gouv.fr.
Banque de France #1 fraud by losses. Scammer pretends to be your bank's fraud team and tricks you into validating their own transactions. Real banks never ask you to validate transactions by phone.
"Votre colis est en attente, frais de douane €1.99" lures. 5 active variants from customs fee to fake redelivery. Real La Poste tracking lives only at laposte.fr or suivi.laposte.fr.
"Amende €35, doublée à €75 si non payée en 24h" emails feel routine to French drivers. Real ANTAI fines arrive by paper post first. The only real payment portal is amendes.gouv.fr.
€5K-€15K government renovation subsidies. Fake auditors and cold callers harvest France Connect credentials and redirect ANAH subsidies to scammer accounts. Apply only via maprimerenov.gouv.fr.
France Connect is the master key to 1,400+ public services. One stolen login = taxes + health + pension + CPF + driver license. Real France Connect never sends suspension threat emails.
Cybermalveillance.gouv.fr 2024: €100M+ losses. Fake "Remboursement Impôts 384€" emails + Crédit d'impôt PAJE + TVA refund templates. Verify only via impots.gouv.fr espace particulier. EN guide for expats.
French Assurance Maladie phishing top-5 in 2024. Fake Carte Vitale renewal + IBAN confirmation + refund-pending templates. Verify only via ameli.fr account. Recovery via 3646 + Cybermalveillance.gouv.fr.
France's top consumer scam 2024 per Cybermalveillance. Fake "Vinted Pro" / "Leboncoin Securité" payment links route to phishing pages that drain seller cards. Vinted never uses external payment links.
FBI's #1 P2P payment scam. Fake bank fraud-alert text + impersonator call walks victim through sending money "to themselves" via Zelle. Irreversible. $440M+ losses 2024. Recovery + protection steps.
Gen Z's #1 scam: fake celebrity-endorsed giveaways tag victims on TikTok/IG, then ask for "verification fee" or steal Cash App login. FTC 2024: $1.9B in social-media-contact fraud. 7 red flags + recovery.
Scammer sends Venmo from stolen card, asks for refund. Days later card transaction reversed = victim loses everything. FTC 2024 P2P fraud $1.1B. Why Venmo has no purchase protection on peer-to-peer.
Fake iCloud renewal + hijacked friend Apple Pay requests + "Apple Cash from Apple" wrong-direction scams. FBI IC3 2024: mobile payment fraud +87% YoY. Recovery steps + Apple Pay protection settings.
Largest US bank (80M+ customers, $2.4T deposits) = biggest phishing target. Fake "suspicious login from Chicago" alerts + lookalike domains (chase-secure[.]com). FBI IC3: $1.2B bank-impersonation losses.
132M+ Steam users, $40B+ skin economy = massive target. Fake friend DM → phishing Steam login → session token steal bypasses SteamGuard 2FA. Valve doesn't restore most stolen items. Recovery flow.
70M+ daily users, mostly kids 8-17. "Free Robux" sites, Discord DM trades, OAuth phishing. 1M+ accounts compromised 2024. Written for parents to share with kids. Recovery + 2-step verify setup.
Fake X Premium suspension emails + @SupportTeam DM impersonators steal logins and payment info. Lookalike domains: x-premium[.]help, twitter-secure[.]net. 600M+ MAU = massive attack surface.
Fake "[Company] invited you to Slack" emails route to phishing login pages capturing SSO + OAuth tokens. Initial access for ransomware crews. 65M+ daily users, 200K+ paid orgs targeted. Verify in 60s.
Attacker uploads phishing HTML to Dropbox, sends real "shared a file" link. Passes SPF/DKIM/DMARC because dropbox.com IS the sender. 700M+ users at risk. Detection + 2FA + sharing-settings guide.
Fake Hulu "subscription suspended due to payment problem" emails target 50M+ subscribers. AiTM proxy captures credentials + 2FA. Variants exploit Disney+/ESPN+ bundle confusion. 7 red flags + 5-step verification + recovery flow.
The Max (formerly HBO Max) account-locked email exploits the real Warner Bros Discovery rebrand confusion. Fake billing failure + AiTM proxy login. 7 red flags + recovery flow if you clicked.
NBC Universal Peacock subscribers targeted with fake "billing failure" emails. Olympics + live sports access bait. 3 tier confusion (Free/Premium/Premium+) exploited. Recovery flow if card details entered.
Sports fans targeted with fake ESPN+ "subscription failed before the big game" emails. UFC/F1/MLB PPV access bait drives panic. Disney bundle confusion exploited. 7 red flags + verification flow.
Star Trek + Yellowstone fans targeted with fake Paramount+ "subscription failed" emails. 2024 Showtime merger confusion exploited. Fake "annual plan switch" promo variants. Recovery flow.
Real-time phishing detection for AI agents via SafeBrowz API. Working code examples for 7 frameworks (Hermes Agent, LangChain, AutoGen, CrewAI, OpenAI Assistants, Anthropic Claude, raw HTTP). $0.01 USDC per call via x402 on Solana/Base.
Fake "Meta Verified team" DMs promise a blue check for $4.99 or via an "eligibility form". The real Meta Verified is only via Settings → Accounts Center - never via DM. 7 red flags, 5-step verification, full account recovery flow.
DM from a friend's hijacked account offering free Nitro / Steam keys. Lookalike domains, QR-login hijack, NFT-server raid variants that drop wallet drainer pages. Why gamers + crypto holders are the gold targets - and the 2FA defense that stops it.
"Your channel will be terminated in 24 hours" emails target monetized creators. Linus Tech Tips 2023 hijack case. Info-stealers (Redline, LummaC2) bypass 2FA via session cookies. Hardware-key MFA + Studio-only strike verification.
"Your Disney+ subscription has been suspended" emails ride the real household-sharing crackdown news. Variants for Hulu, ESPN+, HBO Max, Peacock, Paramount+. 7 red flags, in-app verification, recovery flow including reused-password rotation.
Targets 650M+ Spotify users with fake "payment failed" panic emails. Family-plan-member-removed variant, HiFi tier upgrade, refund offer. Real billing issues only show in-app banner. Same template used by Apple Music, YouTube Music, Tidal.
SocGholish / FakeUpdates framework injects fake Chrome update popups via compromised legitimate sites. Drops Redline + LummaC2 info-stealers that target MetaMask/Phantom wallet extensions. Real Chrome updates are ALWAYS silent + automatic. Never via website download.
#2 most-clicked theme in corporate environments per Mandiant 2024. "[Coworker] sent you a document" leads to fake M365 / Google Workspace login. Variants: BEC pivot, fake HR onboarding, fake vendor invoice. Hardware-key MFA defeats AiTM proxy.
"Your bank app needs updating" WhatsApp link drops banking trojan (Anatsa/Hook/BlackRock/Cerberus). Accessibility Service permission overlays fake login on real bank app, reads SMS OTPs, executes silent UPI/IMPS/Pix transfers. Huge in India, SEA, Brazil, Nigeria.
Different from Apple-locked variant - triggers "did someone steal my account?" panic. AiTM proxy captures 6-digit 2FA in real-time. Attackers reset recovery email then Mark as Lost your iPhone via Find My. iCloud Keychain = every saved password gone.
$440M+ Zelle fraud reports 2024 per FTC. Seller scam (buyer reverses Zelle after shipping). Buyer scam (deposit then disappears). Why Zelle is the riskiest p2p payment. Safe alternatives: PayPal Goods & Services, eBay Managed Payments. CFPB Reg E protections.
3 seconds of audio from social media is enough to clone a voice. FBI's fastest-growing phone scam. The grandparent scam, fake kidnapping, CEO fraud playbook - plus the "safe word" defense that stops it cold.
The old "bad grammar = scam" rule is dead. ChatGPT writes phishing emails with perfect English in any language. The 7 new red flags security researchers actually use in 2026 - sender domain, payment rail, link mouseover, thread history.
60,000+ complaints to FBI IC3 in months. The "$2.99 unpaid toll" text targets every state - E-ZPass, FasTrak, SunPass, PikePass, TxTag. State-by-state verification table, real toll-notice format, and recovery if you entered card info.
Fake $399 Norton invoice triggers a panic call. Then the "agent" requests remote access via AnyDesk to "process the refund". McAfee, Best Buy, Microsoft Defender variants use the same play. Recovery flow if you already called the number.
"Hey I sent a code to your number by mistake, can you share it?" The exact social-engineering playbook that hijacks WhatsApp accounts in under a minute. The two-step verification PIN defense + 30-second recovery flow.
You ask a question in a project group. Within minutes, "Admin" DMs you with a KYC link, airdrop form, or recovery prompt. The wallet-drain happens in one signature. How to verify the real admin in 60 seconds - every project's pinned "we never DM first" policy.
$1B+ stolen via vanity-address lookups in transaction history. The zero-value transaction trick that puts a malicious address into your wallet's history - so you accidentally copy it next time you send. Real Bitfinex/OKX cases, defense, and the brutal recovery reality.
$1B+ lost across Asia in 2024 (UN ODC + Singapore Police data). The fake Amazon/TikTok recruiter, the small payouts that build trust, the "premium tasks" deposit trap, and the sunk-cost lockup. Plus what the Cambodia/Myanmar/Laos scam compounds actually are.
FTC says $1.3B lost to romance scams in 2024. The exact 6-week emotional grooming timeline - Tinder/Bumble first contact, love bomb, crisis pivot, then crypto. Why high-income middle-aged singles are #1 targets. Recovery flow including the cut-off-contact reality.
Locked out of Coinbase? Safe recovery walkthrough using only official channels. Coinbase.com (custodial, recoverable) vs Coinbase Wallet (self-custody, mathematically unrecoverable without seed phrase). 5 recovery-scam traps - fake Twitter support, YouTube tutorials, wallet validators. What real Coinbase support never does.
"Your Coinbase account has been suspended - verify within 24 hours." The AiTM proxy login page, the seed-phrase variant, the 2FA hijack flow. Plus Binance, Kraken, KuCoin, and Gemini variants of the same play. Recovery if you already clicked.
Vercel's free static-site hosting is one of the top abused platforms for crypto drainer pages. The lookalike-app on a .vercel.app subdomain pattern, why standard phishing blocklists miss it, and the brand-detection signals SafeBrowz uses to catch them.
The largest crypto-adjacent scam category in the world. $75B estimated global losses. FBI Operation Level Up + 276 arrests in May 2026. Full 5-stage attack chain, 7 red flags, recovery flow via IC3, and how the approval-phishing endgame connects to Permit2 attacks.
TrendAI uncovered a Russian-speaking scammer who used jailbroken Google Gemini to automate crypto theft - impersonating a US veteran on a 17K Telegram channel, hacking 29 WordPress admins, and harvesting 40+ wallet addresses from a single victim. Template for the next generation of phishing.
Amazon is the world's most-impersonated brand in 2026. The "you ordered $1,200 of AirPods" panic email triggers a click before users think. 8 message variants, the URL patterns, and how to recover if you entered your password.
IRS named tax refund phishing in its 2026 Dirty Dozen list. Real IRS never initiates contact via text/email. 6 message variants, the QR-code-on-fake-letter angle, and what to do if you entered your SSN.
FedEx smishing is the second-most-reported delivery scam after USPS. International shipment + customs duty variants push bigger dollar amounts than USPS. 7 message variants and the 10-second check that catches them all.
India's most-reported phishing scam in 2026. TRAI issued public WhatsApp advisory. 6 message variants (festival-themed, operator-impersonation, government scheme), the OTP-harvesting flow, and recovery via cybercrime.gov.in + 1930 helpline.
The fake USPS delivery text is the most-reported phishing scam in the US in 2026. 7 message variants in active rotation, what the destination page actually steals, the 10-second check that catches every variant, and what to do if you already clicked.
ZachXBT flagged an active campaign draining hundreds of EVM wallets via a fake MetaMask upgrade email with a party-hat fox logo. Per-victim losses stay under $2K to delay detection. How the email works and how to spot it.
On May 20, 2026 the DOJ secured guilty pleas from Ringba CEO and CSO for enabling tech-support fraud pipelines that drained elderly victims of life savings. Here is exactly how the fake popup → call center scam works and how browser defense stops it at step one.
The hub explainer. Why technical defenses keep losing to phishing. Kahneman's dual-system brain model + Cialdini's influence research applied to every phishing technique. Links to all 27 SafeBrowz attack-specific posts.
Microsoft Threat Intelligence: AiTM phishing up 146% in H1 2025. Evilginx2 + Modlishka + Muraena tool families. The reverse-proxy attack that captures password AND 2FA. FIDO2/passkeys are the only protocol-level defense.
Disclosed by mr.d0x in 2022. A phishing page draws a perfect HTML/CSS replica of an OS-level SSO popup INSIDE the page. The HTML/CSS recipe + the 2-second drag test that defeats it + password managers as the strongest defense.
Uber September 2022 - Lapsus$ flooded a contractor with 100+ push notifications until one was approved. The number-matching defense Microsoft/Duo/Okta deployed in 2022-2023 fixes this. Push and SMS 2FA do NOT protect against AiTM.
Older Americans lost $3.4B to tech-support scams in 2024 (FBI IC3). The 6 popup variants in 2026 + the 3-key escape (Ctrl+W / Alt+F4) + browser settings that block 99% of these. DOJ Ringba conviction May 2026 ended a major call-center pipeline.
Attacker takes a real email you received and re-sends with one element changed (bank account number, link). DKIM/DMARC pass. The 4 most damaging clone phishing patterns + the second-channel verification rule that beats them.
Attackers buy paid Google Ads above the organic results for crypto and bank keywords. The 30-day attack cycle: register domain, get Ads approval, run until Google catches, repeat. Real cases: Lowe's/Amazon/KeePass/AnyDesk/Brave malvertising.
Calendar invites bypass every spam filter because the invitation email really is from Google's servers (passes DKIM/DMARC). The phishing link lives inside the event description. Lockdown settings for Gmail + Outlook in 3 steps.
Attackers monitor brand mentions on X. They DM you within minutes pretending to be official support. Phantom/Coinbase/MetaMask DM scams. Verified badges can be bought now (X Premium), so blue check is no longer proof. The 10-second sanity check.
Attacker broadcasts a Wi-Fi network with the same name as the real one. Captive portal phishing, SSL stripping, DNS hijack. iOS/Android auto-rejoin networks with matching SSID. The 4 defenses + personal hotspot rule for sensitive work.
Attackers compromise a website the target group visits regularly (industry forum, vendor portal), then serve malicious code from that trusted site. URL filtering allows it. Forbes 2014, Polish bank 2017, Holy Water 2019. The 5-signal check.
Spear phishing makes up 65% of targeted attacks per FBI IC3 2025. The 6-step LinkedIn profiling playbook attackers use to make emails irresistible, why DKIM/DMARC do not stop it, and the 5-second second-channel verification that beats it.
Named cases: Mattel $3M, Pathé $21M, FACC $47M, Ubiquiti $46.7M, Crelan Bank $75M. FBI IC3: $2.9B in BEC losses. The 7-day pattern, why the email passes DKIM/DMARC, and the FBI Financial Fraud Kill Chain 72-hour recovery window.
Vishing up 30% YoY per FBI IC3. AI voice clones (3 seconds of audio = convincing clone). Arup engineering lost $25M to a deepfake CFO video call in Feb 2024. The "hang up and call back" rule + family safeword defense for voice-clone scams.
Microsoft Defender: quishing up 587% YoY. Real cases: Austin / Houston / Atlanta parking meter QR sticker fraud. Why QR phishing bypasses every email URL scanner (the URL is encoded as an image). 6 places quishing attacks show up + how to scan safely.
Tab-nabbing exploits the Document Visibility API. When you switch away, the background tab silently rewrites itself as "Gmail" or your bank. Avast 2024: average user has 15-30 tabs open. The JavaScript that does it + why password managers are the strongest defense.
StableChain is a new USDT-native L1, and drainer operators are already running fake claim and revoke pages that look identical. The 4-step trap, the JS that does the actual drain, and the 5-second verification that beats it.
Why scam texts bypass the email filters that catch them in your inbox. The 4-second psychology that gets you to tap before thinking. The 10-second check that beats every variant. Data from FBI IC3 + Proofpoint + FTC.
Apple is the #1 most-impersonated brand globally. The "Apple ID locked" email triggers a click before users think. 8 variants, URL patterns, and recovery steps if you entered your password.
Fake Netflix payment-failed email is in the top 5 most-reported phishing scams of 2026. 7 message variants, the URL patterns, and what to do if you entered card details.
PayPal is in the top 3 most-impersonated brands every year since 2018. The "verify your account" and "unusual activity" emails. 7 templates including the fake-invoice variant that passes DMARC.
One of the fastest-growing tech-support scams of 2026. Fake $399-$899 Geek Squad renewal triggers a call to a fake support number → remote access → bank drain via gift cards. 6 variants and recovery steps.
Leading international smishing scam of 2026. The $2.99 "customs fee" is bait - the real harvest is your card. 7 templates, why it works in Europe / GCC / India / SE Asia, and what to do if you paid.
One of the biggest crypto wallet drainer kits closed at end of May 2026. Here is who picks up its customers (Inferno, Angel, MS, Atomic), why drainers keep working in 2026, and 5 things to do this week.
A Permit2 signature is not a transaction. It does not cost gas. It does not move funds immediately. That is exactly why it is the most successful crypto wallet drainer of 2026.
SafeBrowz caught hyperliquid-eligibility.xyz in user traffic. The fake "eligibility checker" drains wallets the moment users connect. Pattern + how to verify a real Hyperliquid airdrop.
SafeBrowz Detection API is live. Pay-per-request URL safety scans on x402, settled in USDC on Solana or Base. $0.01 per call, no signup.
11 red flags that give away phishing sites, plus the browser checks most people miss.
Why "click this box to verify you're human" is now the #1 attack chain in 2026.
Microsoft is the #1 impersonated brand. Here's what a real Microsoft email actually looks like.
What's actually recoverable, what isn't, and how to move fast in the first 60 minutes.
Why the thing you thought you copied isn't what you pasted. And why your terminal is especially at risk.
The Ledger email scam family has been running for 3+ years. Here's how it actually works.