// Blog

Browser security, without the fluff

Stories, guides, and threat reports from the team building SafeBrowz. Phishing, crypto wallet drainers, scam emails, news-driven scam alerts, and the browser-side protections that actually work.

NEW · PILLAR GUIDE

How to tell if an email is really from PayPal, Apple, Disney+, Netflix, or Amazon (2026 Guide)

Verification pillar covering 10 brands. The 30-second universal check, exact official sender domains for PayPal / Apple / Disney+ / Hulu / Netflix / HBO Max / Spotify / Paramount+ / Amazon / Microsoft / DocuSign, and the 5-step recovery if you already clicked. Built for the moment a suspicious email lands in your inbox.

10 min read
Read the guide →
NEW · TRAVEL SCAM

Booking.com Reservation Hijack Scam (2026): Real-Thread Phishing

Scammers message you inside the real Booking.com app, quoting your actual reservation, then send a fake "verify your card" link. The Norton-documented hotel-partner breach, the tells, and how to pay safely.

9 min read
Read post →
NEW · FBI ACTIVE ALERT

Microsoft Device Code Phishing (2026): The Login-Code Scam That Beats MFA

An FBI warning flags a login-code scam that needs no password and gets past MFA. You enter a code on the real Microsoft page and hand your account to an attacker. How it works and the one rule that stops it.

9 min read
Read post →
NEW · WEB3 THREAT

Fake Jupiter $CJUP Airdrop Wallet Drainer (2026)

An unexpected $CJUP token lands in your Solana wallet impersonating Jupiter. The "claim" link drains it in minutes. Why a surprise airdrop is bait and the only real portal (jup.ag).

9 min read
Read post →
NEW · BRAND IMPERSONATION

Amazon Prime Day 2026 Scams: Fake Renewal Emails and Deal Traps (June)

Amazon moved Prime Day to June 23-26, so the fake "Prime renewal failed" emails and lookalike deal pages are landing early. The NJCCIC warning, the tells, and how to shop the sale safely.

10 min read
Read post →
NEW · CRYPTO MALWARE

Fake Meeting Link Malware Scam: The Zoom Call That Drains Your Wallet (2026)

A DM sends a Calendly link to a fake Zoom or Teams call that downloads wallet-draining malware, often from a compromised account you trust. ZachXBT flagged it on X. The one tell, the red flags, and what to do.

8 min read
Read post →
NEW · BRAND IMPERSONATION

Amazon Recall Text Scam: Is That "Item Recalled, Click for Refund" Text Real? (2026)

A text says an item from your recent Amazon order was recalled and offers a refund with no return, then phishes your Amazon password for account takeover. The FTC warning, the one tell, the red flags, and what to do if you already signed in.

8 min read
Read post →
NEW · BRAND IMPERSONATION

Fake Party Invitation Scam: Is That Evite or Paperless Post Email Real? (2026)

The FTC warned in May 2026 about fake Evite, Paperless Post, and Punchbowl invites that ask for your email password to steal Google and Microsoft logins. The one tell that exposes them, the red flags, and what to do if you already signed in.

8 min read
Read post →
BREAKING · WALLET DRAINER

Uniswap Google Ads scam: AngelFerno drainer stole $400K from one trader (May 2026)

A sponsored Google ad outranked the real uniswap.org link and pointed to a Cyrillic Punycode clone. One Permit2 signature drained roughly $400,000 in life savings. Hayden Adams called on Google to act. Anatomy of AngelFerno DaaS + how to revoke + 3-layer detection that catches the clone before the wallet popup.

10 min read
Read full investigation →
BREAKING · FBI ADVISORY

FBI warns of FIFA World Cup 2026 ticket scam: 300+ Ghost Stadium phishing sites explained

FBI PSA260527 (May 27, 2026): Chinese-linked Ghost Stadium operates 300+ lookalike FIFA ticket sites harvesting card and PII data. Our 3-layer detection on typosquat domains + brand-pivot predictions (Olympics 2028, Champions League).

15 min read
Read post →
BREAKING · FBI ADVISORY

FBI Kali365 warning 2026: why OAuth device-code phishing slips past MFA

FBI PSA260521 (May 21, 2026): new Microsoft 365 phishing-as-a-service hijacks accounts via OAuth device-code abuse, bypassing MFA entirely. Our 3-layer detection analysis + what enterprises do right now.

15 min read
Read post →
NEW · AI PLATFORM ABUSE

LLMShare malware on real chatgpt.com share links: the fake OpenAI outage scam (2026)

New phishing campaign abuses ChatGPT's share-link feature to display fake "OpenAI outage" pages on the real chatgpt.com domain. The download leads to openew[.]app - a cross-platform infostealer. Why URL filters fail here, the 30-second user check, and the pattern coming for Claude / Gemini / Perplexity next.

9 min read
Read post →
NEW · GOVERNMENT ADVISORY

India MHA warns: buepux.com Trust Wallet drainer scam targeting BNB users (2026 advisory)

India's MHA + I4C issued advisory TAU/ADV/013 on a Trust Wallet / BNB drainer. The fake "BNB Chain Verification" pivot from P2P platforms via WhatsApp to buepux.com. Why the third approval drains your wallet, plus the SafeBrowz Permit2 modal that warns before signing.

11 min read
Read post →
NEW · INDIA PAYMENTS

UPI scam guide for India 2026: Paytm, PhonePe, Google Pay attack patterns and how to spot them

Indian UPI users lost billions to digital fraud in 2025-2026. Cross-country guide breaks down the 8 most common UPI scams - fake collect requests, QR swap attacks, autopay mandate fraud, KYC expiry calls - with red flags, 30-second checks, and 1930 / cybercrime.gov.in recovery paths.

10 min read
Read post →
NEW · ACCOUNT TAKEOVER

SIM swap fraud explained (2026): how attackers steal your phone number, drain accounts, and how to lock the door

FBI IC3 reports thousands of SIM swap cases yearly with massive crypto + bank losses. This guide breaks down the 5-step attack chain, the FCC 2024 rule, the 6-step lockdown every phone user should do, and recovery steps if funds are already gone.

13 min read
Read post →
NEW · TECH SUPPORT SCAM

"Your iCloud has been compromised" popup scam (2026): how Apple tech support scams trap victims and how to break out

Browser popup locks the tab, plays an alarm, gives a 1-800 number. Real Apple never does this. Full anatomy of the 2026 wave, the remote-access trap, the exact key combo to escape, and recovery steps if you already called.

12 min read
Read post →
NEW · MULTI-COUNTRY TAX PHISHING

Got a tax refund text? Real or scam? UK / US / Canada 2026 verification guide

Cross-country tax-refund SMS phishing. Real-sender format per country (HMRC, IRS, CRA, ATO). The universal rule: no tax agency texts about refunds. 6 instant red flags, 30-second verification check, bank chargeback paths if you already entered card details.

9 min read
Read post →
NEW · UK GOV PHISHING

HMRC tax refund email scam: how UK taxpayers are tricked out of Government Gateway credentials in 2026

UK's #1 phishing topic - HMRC reports 200K+ complaints/year. Fake "£342.78 tax rebate" emails + Self Assessment lures + Marriage Allowance traps. Verify with Gov.uk Gateway only. Recovery via Action Fraud + Cifas.

12 min read
Read post →
NEW · UK GOV PHISHING

DVLA vehicle tax scam: how fake car tax payment failures steal UK driver details in 2026

"Your vehicle tax payment failed - £1,000 fine + clamp threat" SMS/email. DVLA never asks for payment by SMS. Lookalike domains (dvla-payment[.]uk). Verify via gov.uk/check-vehicle-tax. Recovery + Action Fraud.

11 min read
Read post →
NEW · UK GOV PHISHING

TV Licensing scam UK: how the "your licence has expired" email trap works in 2026

Fake TV Licensing emails: "Licence expired", "Direct Debit failed", refund offer, over-75 free-licence trap. TV Licensing won't ask for personal/payment info by email. Verify via tvlicensing.co.uk/check-it-s-us.

11 min read
Read post →
NEW · CANADA GOV PHISHING

CRA tax refund scam Canada: how $50M+ is stolen from Canadians in 2026

RCMP 2024: $50M+ CRA impersonation losses. Fake "$428.50 refund" emails + aggressive "send Bitcoin to avoid arrest" voicemails. Verify only via CRA My Account. Recovery via CAFC + credit freeze.

12 min read
Read post →
NEW · CANADA GOV PHISHING

Service Canada SIN scam in 2026: "your SIN has been suspended" is a lie, every time

Top scam targeting Canadian newcomers + seniors. Automated voicemail "SIN suspended" → fake officer → SIN/banking/identity extraction. Hang-up + look-up + call-back rule. Service Canada fraud + IDCare recovery.

12 min read
Read post →
NEW · AUSTRALIA GOV PHISHING

ATO tax refund scam Australia (2026 guide): how fake refunds and TFN traps work

ATO reports 30K+ phishing reports/year. Peak Jul-Sep (Australian tax year). Fake "$1,247 refund ready" + TFN suspension + BAS overdue templates. Verify only via myGov inbox + ATO ID 13 28 61.

13 min read
Read post →
NEW · AUSTRALIA GOV PHISHING

myGov account locked scam Australia 2026: the phishing trap that steals Medicare + Centrelink

One myGov password = access to Medicare, Centrelink, ATO, Immigration. Fake "account locked" emails route to phishing copies of my.gov.au. Verify only via my.gov.au. Recovery via Services Australia + IDCare.

13 min read
Read post →
NEW · DEEPFAKE VIDEO FRAUD

Deepfake Zoom CEO fraud 2026: the $25M Arup pattern

Daniel ran a $580K wire on a Friday Zoom with his CFO and CEO on camera. Both were deepfakes. Arup Hong Kong lost $25M to the same attack in Feb 2024. Pindrop 2024: deepfake voice attacks up 350%. The callback rule that stops it.

17 min read
Read post →
NEW · REMOTE JOB SCAM

Fake remote job laptop scam 2026: the equipment deposit trap

Tyler accepted a $68K remote offer and sent $1,800 for "equipment insurance." No laptop arrived. FTC 2024: $501M lost to job scams (up 118% YoY). The deepfake video interviewer angle and how to spot it.

15 min read
Read post →
NEW · TIKTOK SHOP COUNTERFEIT

TikTok Shop counterfeit scam 2026: the dupe trap explained

Jenna bought a $14 Stanley dupe from a viral TikTok creator. The lid leaked. The seller vanished. The $14 was the cover charge - your card data joined a marketplace database. CBP 2024 + FTC + DHS reports inside.

14 min read
Read post →
NEW · FAKE AI DOWNLOAD

Fake ChatGPT Sora download Google Ad scam 2026

Eric Googled "Sora 2 Mac download." The top ad delivered RedLine Stealer. Three days later his MetaMask drained, his Coinbase logged in from another country. OpenAI has no installer. ESET/Bitdefender 2024 inside.

16 min read
Read post →
NEW · COMPOUND REPORT

Pig butchering Southeast Asia compound 2026 report: inside the $63B pipeline

Megan was groomed for 4 months on Hinge and lost $48K. Vinh was trafficked into a Sihanoukville compound to run the scam. The two stories meet at UNODC's $63B 2024 estimate. Chainalysis traced $9.9B on-chain. The trafficking dimension.

22 min read
Read post →
NEW · TAX SEASON GUIDE

2026 tax season scams: TurboTax + IRS + H&R Block variants

The same wave hits every January through April. 7 active 2026 variants of TurboTax/H&R Block/IRS impersonation, the exact phrases, IRS Dirty Dozen 2024 alignment, and the Form 14039 + IP PIN recovery routine.

15 min read
Read post →
NEW · 2FA UPGRADE

Salt Typhoon 2FA upgrade 2026: TOTP beats SMS now

CISA flagged carrier-level SMS interception in Dec 2024. SMS 2FA is now the weakest link. The 12-minute upgrade: switch Google, Apple, Microsoft, Coinbase, X, Instagram, Discord, GitHub from SMS to TOTP. Hardware tier guide.

14 min read
Read post →
NEW · MEDICARE SCAM

Medicare open enrollment scam 2026: the card reissue trap

Linda gave her Medicare number to a friendly caller named "Karen." Three weeks later $3,400 of medical equipment was billed to her account from Texas. October to December is peak season. 5 active variants + 1-800-MEDICARE recovery.

13 min read
Read post →
NEW · TICKET SCAM

Concert ticket reselling scam 2026: active variants

Mia Zelled $1,160 for Beyoncé tickets via a Twitter DM. The seller blocked her in 2 hours. 5 active 2026 variants from PDF screenshots to fake StubHub lookalikes to Ticketmaster credential phishing. The 4-minute verification routine.

13 min read
Read post →
NEW · HOLIDAY DELIVERY SCAM

Holiday package customs scam 2026: November to January wave

Rebecca paid a €4.50 USPS "customs fee" on December 22. By February she had $1,800 in fraud charges. Nov-Jan is peak delivery scam season. 5 active variants + the virtual-card defense from the safe payments guide.

14 min read
Read post →
NEW · PAYMENT SAFETY GUIDE

Safe online payments in 2026: how to stop the Google Ad scam with a virtual card

Rachel paid her parents' phone bill on the top Google ad. Three weeks later $2,400 vanished to Amsterdam and Singapore. Google Ads Safety 2024: 5.5B ads blocked. Two-step defense: SafeBrowz + virtual card (RedotPay, Revolut, Wise, Crypto.com). Available in EN/AR/ES/ZH.

15 min read
Read post →
NEW · VOICE CLONE STORY

Voice cloning fake arrest scam 2026: how oversharing on social media made it possible

The night Mike sent $4,500 to a voice he had known for ten years. Forty seconds of TikTok voice + a tagged Lisbon trip = the call. FBI IC3 2024 $16.6B losses, ITRC 2025 voice clone reports up 250%. Per-platform privacy reset + family code word inside.

14 min read
Read post →
NEW · FRANCE CPF FRAUD

Mon Compte Formation CPF scam in France 2026: how the training credit fraud works

Every French worker has €500-€8000 of CPF training credit. Scammers call claiming it expires (it does not), then bill fake training providers against your balance. Real CPF only at moncompteformation.gouv.fr.

14 min read
Read post →
NEW · FRANCE BANK FRAUD

Faux Conseiller Bancaire scam in France 2026: how the fake bank advisor steals €40,000 per call

Banque de France #1 fraud by losses. Scammer pretends to be your bank's fraud team and tricks you into validating their own transactions. Real banks never ask you to validate transactions by phone.

15 min read
Read post →
NEW · FRANCE DELIVERY SMS

Colissimo and La Poste scam text in France 2026: 5 variants and how to spot them

"Votre colis est en attente, frais de douane €1.99" lures. 5 active variants from customs fee to fake redelivery. Real La Poste tracking lives only at laposte.fr or suivi.laposte.fr.

13 min read
Read post →
NEW · FRANCE FAKE FINE

ANTAI fake parking fine scam in France 2026: how the "amende impayée" fraud works

"Amende €35, doublée à €75 si non payée en 24h" emails feel routine to French drivers. Real ANTAI fines arrive by paper post first. The only real payment portal is amendes.gouv.fr.

12 min read
Read post →
NEW · FRANCE GOV SUBSIDY

MaPrimeRénov' renovation aid scam in France 2026: how fake auditors steal government subsidies

€5K-€15K government renovation subsidies. Fake auditors and cold callers harvest France Connect credentials and redirect ANAH subsidies to scammer accounts. Apply only via maprimerenov.gouv.fr.

14 min read
Read post →
NEW · FRANCE GOV SSO

France Connect and Mon Espace Santé phishing in France 2026: when one login unlocks everything

France Connect is the master key to 1,400+ public services. One stolen login = taxes + health + pension + CPF + driver license. Real France Connect never sends suspension threat emails.

14 min read
Read post →
NEW · FRANCE GOV PHISHING

Impôts.gouv tax refund scam France 2026: fake DGFiP refunds explained for expats

Cybermalveillance.gouv.fr 2024: €100M+ losses. Fake "Remboursement Impôts 384€" emails + Crédit d'impôt PAJE + TVA refund templates. Verify only via impots.gouv.fr espace particulier. EN guide for expats.

14 min read
Read post →
NEW · FRANCE GOV PHISHING

Ameli health insurance scam France 2026: fake Carte Vitale renewal explained for expats

French Assurance Maladie phishing top-5 in 2024. Fake Carte Vitale renewal + IBAN confirmation + refund-pending templates. Verify only via ameli.fr account. Recovery via 3646 + Cybermalveillance.gouv.fr.

13 min read
Read post →
NEW · FRANCE MARKETPLACE

Vinted + Leboncoin fake buyer scam France 2026: the "Vinted Pro secure link" trap explained

France's top consumer scam 2024 per Cybermalveillance. Fake "Vinted Pro" / "Leboncoin Securité" payment links route to phishing pages that drain seller cards. Vinted never uses external payment links.

12 min read
Read post →
NEW · PAYMENT FRAUD

Zelle fraud alert text scam: how the "did you authorize this transfer?" trick steals $440M (2026)

FBI's #1 P2P payment scam. Fake bank fraud-alert text + impersonator call walks victim through sending money "to themselves" via Zelle. Irreversible. $440M+ losses 2024. Recovery + protection steps.

12 min read
Read post →
NEW · GIVEAWAY SCAM

Cash App $750 free scam: how #CashAppFriday giveaway DMs drain accounts in 2026

Gen Z's #1 scam: fake celebrity-endorsed giveaways tag victims on TikTok/IG, then ask for "verification fee" or steal Cash App login. FTC 2024: $1.9B in social-media-contact fraud. 7 red flags + recovery.

11 min read
Read post →
NEW · PAYMENT FRAUD

Venmo "I sent you money by accident" scam: the chargeback trap explained (2026)

Scammer sends Venmo from stolen card, asks for refund. Days later card transaction reversed = victim loses everything. FTC 2024 P2P fraud $1.1B. Why Venmo has no purchase protection on peer-to-peer.

12 min read
Read post →
NEW · PAYMENT FRAUD

Apple Pay "request for payment" scam: how to spot it (2026)

Fake iCloud renewal + hijacked friend Apple Pay requests + "Apple Cash from Apple" wrong-direction scams. FBI IC3 2024: mobile payment fraud +87% YoY. Recovery steps + Apple Pay protection settings.

11 min read
Read post →
NEW · BANK PHISHING

Chase Bank phishing email scam: how to spot fake fraud alerts and login traps in 2026

Largest US bank (80M+ customers, $2.4T deposits) = biggest phishing target. Fake "suspicious login from Chicago" alerts + lookalike domains (chase-secure[.]com). FBI IC3: $1.2B bank-impersonation losses.

11 min read
Read post →
NEW · GAMING SCAM

Steam trade hijack scam: how CS skin theft and session-token attacks work in 2026

132M+ Steam users, $40B+ skin economy = massive target. Fake friend DM → phishing Steam login → session token steal bypasses SteamGuard 2FA. Valve doesn't restore most stolen items. Recovery flow.

13 min read
Read post →
NEW · GAMING SCAM

Roblox account hijack: a parent's 2026 guide to free Robux scams and account theft

70M+ daily users, mostly kids 8-17. "Free Robux" sites, Discord DM trades, OAuth phishing. 1M+ accounts compromised 2024. Written for parents to share with kids. Recovery + 2-step verify setup.

13 min read
Read post →
NEW · BRAND IMPERSONATION

Twitter/X blue verification scam: how the $8 checkmark phishing trap works in 2026

Fake X Premium suspension emails + @SupportTeam DM impersonators steal logins and payment info. Lookalike domains: x-premium[.]help, twitter-secure[.]net. 600M+ MAU = massive attack surface.

12 min read
Read post →
NEW · B2B PHISHING

Slack workspace invite phishing: the new B2B credential trap of 2026

Fake "[Company] invited you to Slack" emails route to phishing login pages capturing SSO + OAuth tokens. Initial access for ransomware crews. 65M+ daily users, 200K+ paid orgs targeted. Verify in 60s.

11 min read
Read post →
NEW · B2B PHISHING

Dropbox shared file phishing: how legit-link phishing bypasses email security in 2026

Attacker uploads phishing HTML to Dropbox, sends real "shared a file" link. Passes SPF/DKIM/DMARC because dropbox.com IS the sender. 700M+ users at risk. Detection + 2FA + sharing-settings guide.

11 min read
Read post →
NEW · BRAND IMPERSONATION

Hulu account locked email scam: how to spot the fake suspension notice in 2026

Fake Hulu "subscription suspended due to payment problem" emails target 50M+ subscribers. AiTM proxy captures credentials + 2FA. Variants exploit Disney+/ESPN+ bundle confusion. 7 red flags + 5-step verification + recovery flow.

10 min read
Read post →
NEW · BRAND IMPERSONATION

HBO Max account locked email scam: how to spot the fake suspension notice in 2026

The Max (formerly HBO Max) account-locked email exploits the real Warner Bros Discovery rebrand confusion. Fake billing failure + AiTM proxy login. 7 red flags + recovery flow if you clicked.

11 min read
Read post →
NEW · BRAND IMPERSONATION

Peacock account locked email scam: how to spot the fake suspension notice in 2026

NBC Universal Peacock subscribers targeted with fake "billing failure" emails. Olympics + live sports access bait. 3 tier confusion (Free/Premium/Premium+) exploited. Recovery flow if card details entered.

10 min read
Read post →
NEW · BRAND IMPERSONATION

ESPN+ billing scam email: how to spot the fake subscription renewal notice in 2026

Sports fans targeted with fake ESPN+ "subscription failed before the big game" emails. UFC/F1/MLB PPV access bait drives panic. Disney bundle confusion exploited. 7 red flags + verification flow.

10 min read
Read post →
NEW · BRAND IMPERSONATION

Paramount+ subscription scam email: how to spot the fake billing failure in 2026

Star Trek + Yellowstone fans targeted with fake Paramount+ "subscription failed" emails. 2024 Showtime merger confusion exploited. Fake "annual plan switch" promo variants. Recovery flow.

11 min read
Read post →
NEW · B2B TUTORIAL

Add phishing detection to your AI agent: Hermes Agent, LangChain, AutoGen, CrewAI (2026 tutorial)

Real-time phishing detection for AI agents via SafeBrowz API. Working code examples for 7 frameworks (Hermes Agent, LangChain, AutoGen, CrewAI, OpenAI Assistants, Anthropic Claude, raw HTTP). $0.001 USDC per call via x402 on Solana/Base.

12 min read
Read post →
NEW · BRAND IMPERSONATION

Instagram verification badge scam: how "apply for verification" DMs steal accounts in 2026

Fake "Meta Verified team" DMs promise a blue check for $4.99 or via an "eligibility form". The real Meta Verified is only via Settings → Accounts Center - never via DM. 7 red flags, 5-step verification, full account recovery flow.

10 min read
Read post →
NEW · GAMING + CRYPTO

Discord Nitro free scam: how fake "gift link" DMs steal accounts and crypto in 2026

DM from a friend's hijacked account offering free Nitro / Steam keys. Lookalike domains, QR-login hijack, NFT-server raid variants that drop wallet drainer pages. Why gamers + crypto holders are the gold targets - and the 2FA defense that stops it.

10 min read
Read post →
NEW · CREATOR THREAT

YouTube copyright strike scam email: how fake DMCA notices steal creator accounts in 2026

"Your channel will be terminated in 24 hours" emails target monetized creators. Linus Tech Tips 2023 hijack case. Info-stealers (Redline, LummaC2) bypass 2FA via session cookies. Hardware-key MFA + Studio-only strike verification.

10 min read
Read post →
NEW · BRAND IMPERSONATION

Disney+ account locked email scam: how to spot the fake suspension notice in 2026

"Your Disney+ subscription has been suspended" emails ride the real household-sharing crackdown news. Variants for Hulu, ESPN+, HBO Max, Peacock, Paramount+. 7 red flags, in-app verification, recovery flow including reused-password rotation.

10 min read
Read post →
NEW · BRAND IMPERSONATION

Spotify account suspended email scam: the fake Premium cancellation phishing of 2026

Targets 650M+ Spotify users with fake "payment failed" panic emails. Family-plan-member-removed variant, HiFi tier upgrade, refund offer. Real billing issues only show in-app banner. Same template used by Apple Music, YouTube Music, Tidal.

10 min read
Read post →
NEW · MALWARE INSTALL

Fake Chrome update scam: how the "your browser is outdated" popup installs malware in 2026

SocGholish / FakeUpdates framework injects fake Chrome update popups via compromised legitimate sites. Drops Redline + LummaC2 info-stealers that target MetaMask/Phantom wallet extensions. Real Chrome updates are ALWAYS silent + automatic. Never via website download.

10 min read
Read post →
NEW · BUSINESS EMAIL

DocuSign phishing scam: how fake signature requests steal business credentials in 2026

#2 most-clicked theme in corporate environments per Mandiant 2024. "[Coworker] sent you a document" leads to fake M365 / Google Workspace login. Variants: BEC pivot, fake HR onboarding, fake vendor invoice. Hardware-key MFA defeats AiTM proxy.

10 min read
Read post →
NEW · MOBILE MALWARE

Fake bank app Android APK scam: how WhatsApp SMS drops malware on phones in 2026

"Your bank app needs updating" WhatsApp link drops banking trojan (Anatsa/Hook/BlackRock/Cerberus). Accessibility Service permission overlays fake login on real bank app, reads SMS OTPs, executes silent UPI/IMPS/Pix transfers. Huge in India, SEA, Brazil, Nigeria.

10 min read
Read post →
NEW · BRAND IMPERSONATION

iCloud "signed out from all devices" scam email: how to verify it's actually from Apple in 2026

Different from Apple-locked variant - triggers "did someone steal my account?" panic. AiTM proxy captures 6-digit 2FA in real-time. Attackers reset recovery email then Mark as Lost your iPhone via Find My. iCloud Keychain = every saved password gone.

10 min read
Read post →
NEW · MARKETPLACE FRAUD

eBay and Marketplace Zelle scam: how "send me Zelle for the iPhone" steals thousands in 2026

$440M+ Zelle fraud reports 2024 per FTC. Seller scam (buyer reverses Zelle after shipping). Buyer scam (deposit then disappears). Why Zelle is the riskiest p2p payment. Safe alternatives: PayPal Goods & Services, eBay Managed Payments. CFPB Reg E protections.

10 min read
Read post →
NEW · AI THREAT 2026

AI voice cloning vishing scam: how scammers fake your family's voice to steal money in 2026

3 seconds of audio from social media is enough to clone a voice. FBI's fastest-growing phone scam. The grandparent scam, fake kidnapping, CEO fraud playbook - plus the "safe word" defense that stops it cold.

10 min read
Read post →
NEW · AI THREAT 2026

AI-written phishing emails are now grammatically perfect: 7 new tells to spot ChatGPT-crafted scams

The old "bad grammar = scam" rule is dead. ChatGPT writes phishing emails with perfect English in any language. The 7 new red flags security researchers actually use in 2026 - sender domain, payment rail, link mouseover, thread history.

10 min read
Read post →
NEW · FBI ACTIVE ALERT

Unpaid toll text scam (E-ZPass, FasTrak, SunPass): how to spot the FBI's #1 active text scam of 2026

60,000+ complaints to FBI IC3 in months. The "$2.99 unpaid toll" text targets every state - E-ZPass, FasTrak, SunPass, PikePass, TxTag. State-by-state verification table, real toll-notice format, and recovery if you entered card info.

11 min read
Read post →
NEW · BRAND IMPERSONATION

Norton renewal scam email: how to spot the fake $400 auto-charge invoice in 2026

Fake $399 Norton invoice triggers a panic call. Then the "agent" requests remote access via AnyDesk to "process the refund". McAfee, Best Buy, Microsoft Defender variants use the same play. Recovery flow if you already called the number.

10 min read
Read post →
NEW · ACCOUNT TAKEOVER

WhatsApp 6-digit code scam: how strangers hijack your account in 60 seconds and what to do

"Hey I sent a code to your number by mistake, can you share it?" The exact social-engineering playbook that hijacks WhatsApp accounts in under a minute. The two-step verification PIN defense + 30-second recovery flow.

10 min read
Read post →
NEW · CRYPTO THREAT

Telegram admin DM crypto scam: the "support" message that drains your wallet in 2026

You ask a question in a project group. Within minutes, "Admin" DMs you with a KYC link, airdrop form, or recovery prompt. The wallet-drain happens in one signature. How to verify the real admin in 60 seconds - every project's pinned "we never DM first" policy.

10 min read
Read post →
NEW · CRYPTO THREAT

Crypto address poisoning scam: how attackers trick you into sending USDT to the wrong wallet

$1B+ stolen via vanity-address lookups in transaction history. The zero-value transaction trick that puts a malicious address into your wallet's history - so you accidentally copy it next time you send. Real Bitfinex/OKX cases, defense, and the brutal recovery reality.

10 min read
Read post →
NEW · ASIA FRAUD

Telegram task job scam: how the "$300/day easy job" offer becomes a $50,000 loss in 2026

$1B+ lost across Asia in 2024 (UN ODC + Singapore Police data). The fake Amazon/TikTok recruiter, the small payouts that build trust, the "premium tasks" deposit trap, and the sunk-cost lockup. Plus what the Cambodia/Myanmar/Laos scam compounds actually are.

11 min read
Read post →
NEW · ROMANCE FRAUD

Dating app romance scam to crypto: how strangers go from "hi babe" to draining your savings in 6 weeks

FTC says $1.3B lost to romance scams in 2024. The exact 6-week emotional grooming timeline - Tinder/Bumble first contact, love bomb, crisis pivot, then crypto. Why high-income middle-aged singles are #1 targets. Recovery flow including the cut-off-contact reality.

11 min read
Read post →
NEW · ACCOUNT RECOVERY

How to safely recover your Coinbase account in 2026 (without falling for scams)

Locked out of Coinbase? Safe recovery walkthrough using only official channels. Coinbase.com (custodial, recoverable) vs Coinbase Wallet (self-custody, mathematically unrecoverable without seed phrase). 5 recovery-scam traps - fake Twitter support, YouTube tutorials, wallet validators. What real Coinbase support never does.

11 min read
Read post →
NEW · CRYPTO BRAND

Coinbase account suspended email: how to verify it's actually from Coinbase in 2026

"Your Coinbase account has been suspended - verify within 24 hours." The AiTM proxy login page, the seed-phrase variant, the 2FA hijack flow. Plus Binance, Kraken, KuCoin, and Gemini variants of the same play. Recovery if you already clicked.

10 min read
Read post →
NEWS · WEB3 THREAT

Vercel free hosting abused for wallet drainer pages - how to spot the *.vercel.app phishing pattern

Vercel's free static-site hosting is one of the top abused platforms for crypto drainer pages. The lookalike-app on a .vercel.app subdomain pattern, why standard phishing blocklists miss it, and the brand-detection signals SafeBrowz uses to catch them.

9 min read
Read post →
GUIDE · GLOBAL FRAUD

Pig Butchering Crypto Scam Explained: the $75 billion romance + trading fraud (2026)

The largest crypto-adjacent scam category in the world. $75B estimated global losses. FBI Operation Level Up + 276 arrests in May 2026. Full 5-stage attack chain, 7 red flags, recovery flow via IC3, and how the approval-phishing endgame connects to Permit2 attacks.

12 min read
Read post →
NEWS · AI THREAT

Jailbroken Gemini AI drained crypto wallets - the bandcampro operation (May 2026)

TrendAI uncovered a Russian-speaking scammer who used jailbroken Google Gemini to automate crypto theft - impersonating a US veteran on a 17K Telegram channel, hacking 29 WordPress admins, and harvesting 40+ wallet addresses from a single victim. Template for the next generation of phishing.

10 min read
Read post →
GUIDE · ACCOUNT TAKEOVER

Amazon "Order Confirmation" Scam Email & Text: how the fake purchase phishing attack works

Amazon is the world's most-impersonated brand in 2026. The "you ordered $1,200 of AirPods" panic email triggers a click before users think. 8 message variants, the URL patterns, and how to recover if you entered your password.

10 min read
Read post →
GUIDE · TAX SEASON

IRS "Tax Refund" Scam Text & Email: how the phishing attack works and how to spot it

IRS named tax refund phishing in its 2026 Dirty Dozen list. Real IRS never initiates contact via text/email. 6 message variants, the QR-code-on-fake-letter angle, and what to do if you entered your SSN.

10 min read
Read post →
GUIDE · SMS PHISHING

FedEx "Missed Delivery" Text Scam: how the smishing attack works and how to spot it

FedEx smishing is the second-most-reported delivery scam after USPS. International shipment + customs duty variants push bigger dollar amounts than USPS. 7 message variants and the 10-second check that catches them all.

10 min read
Read post →
GUIDE · INDIA · WHATSAPP

TRAI "Free Recharge" WhatsApp Scam: how the fake telecom offer steals your bank OTP

India's most-reported phishing scam in 2026. TRAI issued public WhatsApp advisory. 6 message variants (festival-themed, operator-impersonation, government scheme), the OTP-harvesting flow, and recovery via cybercrime.gov.in + 1930 helpline.

10 min read
Read post →
GUIDE · SMS PHISHING

USPS "Failed Delivery" Text Scam: how the smishing attack works and how to spot it

The fake USPS delivery text is the most-reported phishing scam in the US in 2026. 7 message variants in active rotation, what the destination page actually steals, the 10-second check that catches every variant, and what to do if you already clicked.

9 min read
Read post →
NEWS · ACTIVE PHISHING

MetaMask "Mandatory Upgrade" Email Scam: hundreds of wallets drained for $107K+

ZachXBT flagged an active campaign draining hundreds of EVM wallets via a fake MetaMask upgrade email with a party-hat fox logo. Per-victim losses stay under $2K to delay detection. How the email works and how to spot it.

8 min read
Read post →
NEWS · THREAT

Fake Microsoft Popup Scam: DOJ just convicted two executives in 2026

On May 20, 2026 the DOJ secured guilty pleas from Ringba CEO and CSO for enabling tech-support fraud pipelines that drained elderly victims of life savings. Here is exactly how the fake popup → call center scam works and how browser defense stops it at step one.

8 min read
Read post →
CORNERSTONE · PSYCHOLOGY

The 6 emotions every phishing email targets (and the one that always wins)

The hub explainer. Why technical defenses keep losing to phishing. Kahneman's dual-system brain model + Cialdini's influence research applied to every phishing technique. Links to all 27 SafeBrowz attack-specific posts.

13 min read
Read post →
AUTHENTICATION ATTACKS · 2026

How attackers steal your 2FA code even with strong authentication

Microsoft Threat Intelligence: AiTM phishing up 146% in H1 2025. Evilginx2 + Modlishka + Muraena tool families. The reverse-proxy attack that captures password AND 2FA. FIDO2/passkeys are the only protocol-level defense.

11 min read
Read post →
BROWSER ATTACKS · TECHNICAL

The fake login window inside the real browser

Disclosed by mr.d0x in 2022. A phishing page draws a perfect HTML/CSS replica of an OS-level SSO popup INSIDE the page. The HTML/CSS recipe + the 2-second drag test that defeats it + password managers as the strongest defense.

10 min read
Read post →
MFA FATIGUE · AUTHENTICATION

47 fake login notifications until you tap "allow" just to stop them

Uber September 2022 - Lapsus$ flooded a contractor with 100+ push notifications until one was approved. The number-matching defense Microsoft/Duo/Okta deployed in 2022-2023 fixes this. Push and SMS 2FA do NOT protect against AiTM.

10 min read
Read post →
SCAREWARE · POP-UP · OLDER ADULTS

The "your computer has 5 viruses" popup IS the virus

Older Americans lost $3.4B to tech-support scams in 2024 (FBI IC3). The 6 popup variants in 2026 + the 3-key escape (Ctrl+W / Alt+F4) + browser settings that block 99% of these. DOJ Ringba conviction May 2026 ended a major call-center pipeline.

10 min read
Read post →
EMAIL PHISHING · BEC · SUPPLIER FRAUD

When a legitimate email comes back with one tiny change

Attacker takes a real email you received and re-sends with one element changed (bank account number, link). DKIM/DMARC pass. The 4 most damaging clone phishing patterns + the second-channel verification rule that beats them.

10 min read
Read post →
MALVERTISING · SEARCH

The first Google ad for "MetaMask" is sometimes a drainer

Attackers buy paid Google Ads above the organic results for crypto and bank keywords. The 30-day attack cycle: register domain, get Ads approval, run until Google catches, repeat. Real cases: Lowe's/Amazon/KeePass/AnyDesk/Brave malvertising.

10 min read
Read post →
CALENDAR · GOOGLE · OUTLOOK

The Google Calendar invite that's actually phishing

Calendar invites bypass every spam filter because the invitation email really is from Google's servers (passes DKIM/DMARC). The phishing link lives inside the event description. Lockdown settings for Gmail + Outlook in 3 steps.

9 min read
Read post →
SOCIAL MEDIA PHISHING · CRYPTO

The fake Twitter support account draining wallets right now

Attackers monitor brand mentions on X. They DM you within minutes pretending to be official support. Phantom/Coinbase/MetaMask DM scams. Verified badges can be bought now (X Premium), so blue check is no longer proof. The 10-second sanity check.

10 min read
Read post →
WI-FI ATTACKS · TRAVEL

Why airport Wi-Fi named "Airport_Free_WiFi" is a trap

Attacker broadcasts a Wi-Fi network with the same name as the real one. Captive portal phishing, SSL stripping, DNS hijack. iOS/Android auto-rejoin networks with matching SSID. The 4 defenses + personal hotspot rule for sensitive work.

10 min read
Read post →
BROWSER ATTACKS · APT · REPORTS

Why hackers target the websites you already trust

Attackers compromise a website the target group visits regularly (industry forum, vendor portal), then serve malicious code from that trusted site. URL filtering allows it. Forbes 2014, Polish bank 2017, Holy Water 2019. The 5-signal check.

10 min read
Read post →
TARGETED PHISHING · REPORTS

How attackers profile you on LinkedIn before sending the perfect phishing email

Spear phishing makes up 65% of targeted attacks per FBI IC3 2025. The 6-step LinkedIn profiling playbook attackers use to make emails irresistible, why DKIM/DMARC do not stop it, and the 5-second second-channel verification that beats it.

11 min read
Read post →
BEC · WHALING · REPORTS

The $2.3M wire transfer email scam that targets only CEOs and CFOs

Named cases: Mattel $3M, Pathé $21M, FACC $47M, Ubiquiti $46.7M, Crelan Bank $75M. FBI IC3: $2.9B in BEC losses. The 7-day pattern, why the email passes DKIM/DMARC, and the FBI Financial Fraud Kill Chain 72-hour recovery window.

11 min read
Read post →
VISHING · PHONE · AI VOICE

Your bank will never call. The scammer always will.

Vishing up 30% YoY per FBI IC3. AI voice clones (3 seconds of audio = convincing clone). Arup engineering lost $25M to a deepfake CFO video call in Feb 2024. The "hang up and call back" rule + family safeword defense for voice-clone scams.

10 min read
Read post →
QR PHISHING · MOBILE · 2026

The QR code in the parking lot that empties your bank account

Microsoft Defender: quishing up 587% YoY. Real cases: Austin / Houston / Atlanta parking meter QR sticker fraud. Why QR phishing bypasses every email URL scanner (the URL is encoded as an image). 6 places quishing attacks show up + how to scan safely.

10 min read
Read post →
BROWSER ATTACK · TECHNICAL

That browser tab you forgot about just stole your Gmail password

Tab-nabbing exploits the Document Visibility API. When you switch away, the background tab silently rewrites itself as "Gmail" or your bank. Avast 2024: average user has 15-30 tabs open. The JavaScript that does it + why password managers are the strongest defense.

10 min read
Read post →
CRYPTO · LIVE THREAT

Stable.xyz lookalike sites are draining wallets - here is how the trap runs

StableChain is a new USDT-native L1, and drainer operators are already running fake claim and revoke pages that look identical. The 4-step trap, the JS that does the actual drain, and the 5-second verification that beats it.

10 min read
Read post →
PHONE · PSYCHOLOGY

Your phone is the new phishing target - here is exactly how the text scam works

Why scam texts bypass the email filters that catch them in your inbox. The 4-second psychology that gets you to tap before thinking. The 10-second check that beats every variant. Data from FBI IC3 + Proofpoint + FTC.

10 min read
Read post →
BRAND IMPERSONATION · APPLE

"Your Apple ID has been locked" email scam: how to spot it (2026)

Apple is the #1 most-impersonated brand globally. The "Apple ID locked" email triggers a click before users think. 8 variants, URL patterns, and recovery steps if you entered your password.

9 min read
Read post →
BRAND IMPERSONATION · NETFLIX

"Netflix account on hold" email scam: how to spot it (2026)

Fake Netflix payment-failed email is in the top 5 most-reported phishing scams of 2026. 7 message variants, the URL patterns, and what to do if you entered card details.

8 min read
Read post →
BRAND IMPERSONATION · PAYPAL

"PayPal account verification" email scam: spot it in 10 seconds

PayPal is in the top 3 most-impersonated brands every year since 2018. The "verify your account" and "unusual activity" emails. 7 templates including the fake-invoice variant that passes DMARC.

8 min read
Read post →
TECH SUPPORT SCAM · SURGING

Geek Squad invoice scam email: the $399 renewal trap

One of the fastest-growing tech-support scams of 2026. Fake $399-$899 Geek Squad renewal triggers a call to a fake support number → remote access → bank drain via gift cards. 6 variants and recovery steps.

8 min read
Read post →
SMS PHISHING · INTERNATIONAL

DHL package tracking text scam: the customs duty trap

Leading international smishing scam of 2026. The $2.99 "customs fee" is bait - the real harvest is your card. 7 templates, why it works in Europe / GCC / India / SE Asia, and what to do if you paid.

8 min read
Read post →
CRYPTO · BREAKING

Pink Drainer just shut down. The wallet-drainer world did not.

One of the biggest crypto wallet drainer kits closed at end of May 2026. Here is who picks up its customers (Inferno, Angel, MS, Atomic), why drainers keep working in 2026, and 5 things to do this week.

9 min read
Read post →
CRYPTO · TECHNICAL

Permit2 Signature Attack Explained: how one click drains your wallet

A Permit2 signature is not a transaction. It does not cost gas. It does not move funds immediately. That is exactly why it is the most successful crypto wallet drainer of 2026.

9 min read
Read post →
CRYPTO · LIVE THREAT

Hyperliquid Eligibility Airdrop Scam: how the fake checker drains your wallet

SafeBrowz caught hyperliquid-eligibility.xyz in user traffic. The fake "eligibility checker" drains wallets the moment users connect. Pattern + how to verify a real Hyperliquid airdrop.

7 min read
Read post →
PRODUCT · LAUNCH

We built a phishing detection API that AI agents can pay in USDC

SafeBrowz Detection API is live. Pay-per-request URL safety scans on x402, settled in USDC on Solana or Base. $0.001 per call, no signup.

8 min read
Read post →
GUIDE · BEGINNER

How to tell if a website is a scam

11 red flags that give away phishing sites, plus the browser checks most people miss.

9 min read
Read guide →
THREAT · ACTIVE

The fake CAPTCHA that empties your wallet (ClickFix)

Why "click this box to verify you're human" is now the #1 attack chain in 2026.

11 min read
Read guide →
GUIDE · BRAND

Microsoft phishing emails: 7 ways to spot them

Microsoft is the #1 impersonated brand. Here's what a real Microsoft email actually looks like.

8 min read
Read guide →
CRYPTO · RESCUE

My crypto wallet got drained. What do I do?

What's actually recoverable, what isn't, and how to move fast in the first 60 minutes.

12 min read
Read guide →
TECHNICAL

Pastejacking, explained

Why the thing you thought you copied isn't what you pasted. And why your terminal is especially at risk.

7 min read
Read guide →
CRYPTO · WARNING

Fake Ledger emails: what to check before clicking

The Ledger email scam family has been running for 3+ years. Here's how it actually works.

8 min read
Read guide →