Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The MemcycoFM Show: Ep25 - How to Detect Brand Impersonation: Key Signals for Security Teams

In the recently published blog from @Memcyco titled 'How to Detect Brand Impersonation: Key Signals for Security Teams', we discussed brand impersonation detection, the process of identifying fake domains, cloned brand experiences, and the exposure signals that show attackers are using a trusted brand to deceive customers, employees, or partners. For security teams, the harder problem is not finding every impersonation asset. It is knowing which signals indicate live user exposure and which ones should change the response.

How to Avoid eBay Scams: What Buyers & Sellers Need to Know

eBay is one of the biggest online marketplaces in the world, but scammers are active on both sides of every transaction. Whether you're buying or selling, knowing what to look for can make all the difference. In this video, we break down: The most common eBay buyer scams — fake deals, missing items, phishing links How sellers get targeted — fake payments, overpayment scams, and false "item not received" claims.

Fake Bots, Fake Sites, Fake Trades: CS2 Scams to Watch For

Thousands of dollars move through CS2 every day. Skins pass from one account to another, trades happen by the minute, and the money flowing around them long ago outgrew simple in-Steam trading. The more money there is, the more people want to take it by deceiving players. These scammers don't hack directly; they don't write complex exploits or break into servers. Instead they copy what you already trust. Below are the three schemes that even experienced traders fall for, no fluff and no fiction, just what actually works against CS2 players today.

Using 100+ Signals to Capture 100M Fraudsters

Over 100 behavioral and technical risk signals can be captured in every verification. But knowing which ones to use and combine can be difficult. In this webinar, three fraud and identity practitioners break down how to stack signals to catch synthetic IDs and GenAI-driven fraud without blocking legitimate users.

FTC Report: Americans Lost $3.5 Billion to Imposter Scams Last Year

Imposter scams were the most commonly reported type of fraud in 2025, with Americans reporting $3.5 billion in losses, according to new data from the US Federal Trade Commission (FTC). Reported losses have increased nearly three times since 2020, and the true number is likely much higher since many scams go unreported. Losses across all types of fraud surged to $16 billion, a 25% increase compared to 2024.

What Is Agentic Threat Intelligence?

Agentic threat intelligence is an emerging CTI model where bounded agents support repetitive investigation work, such as collection, enrichment, prioritization, and evidence packaging, while analysts retain control over takedown and escalation decisions. Vendor briefings are full of “agentic AI” right now. Most of them describe the same thing: faster dashboards and smarter alerts. That is not agentic threat intelligence.

New Extortion Scam Uses IT Impersonation to Breach Organizations

A newly surfaced extortion brand called “Pink” is using voice phishing and fake IT support calls to breach organizations, the Register reports. The threat actor may be a rebrand of prior extortion groups, including BlackFile and Redact, though its tactics remain the same.

APWG Report: Social Media Phishing is Surging

Phishing scams surged across social media platforms during the first quarter of 2026, according to a new report from the Anti-Phishing Working Group (APWG). “Threat volume increased in Q1 2026 on every social media platform, predominantly in two formats: Scams (27.1 percent of all threats) and Impersonation (43.8 percent of all threats),” the report says. The APWG adds, “Impersonation became more prevalent than in the previous quarter.

Americans Lost $900 Million to AI-Powered Scams Last Year

The US Federal Bureau of Investigation (FBI) warns that Americans lost just under $900 million to AI-powered scams in 2025, Malwarebytes reports. Total reported losses to scams last year reached nearly $21 billion, a 26% increase from 2024. The researchers note that the true losses are likely much higher, since many attacks go unreported. “The main drivers behind the rise in AI-powered scams are voice cloning, deepfake images and videos, and AI‑generated scripts,” Malwarebytes says.

GenAI fraud detection in academia vs industry

Academic fraud datasets often lack real-world grounding and miss insights that you can only glean from defending against ongoing adversarial attacks. Just ask Zhaofeng Si, a PhD student in computer science at the University at Buffalo who studies the detection of AI-generated synthetic images. Three weeks ago, he joined Persona for a 12-week internship. Now, he’s working alongside Persona’s research scientists to build a benchmark for selfie fraud.

4 Hot Summer Travel Tips To Avoid Scams

When the weather starts to get warmer, it is a sign that summer time is around the corner. But just as the weather heats up and travel plans get booked, scammers capitalize on the season by performing nefarious schemes to separate victims from their money and other valuables. Recent McAfee research found that more than one in three Americans have experienced a travel-related cyberthreat, with 41% of those affected losing money, often costing victims over $500.

Green Sheet interviews INETCO's Ugan Naidoo

Article originally published in Green Sheet, June 15, 2026 As artificial intelligence rapidly reshapes the fraud landscape, financial institutions are under growing pressure to detect and stop increasingly sophisticated threats in real time. From AI-driven social engineering scams to evolving mule-account activity and instant payment fraud, traditional approaches to fraud prevention are being tested like never before.

From Brand Impersonation to Account Takeover: The ATO Attack Chain

Brand impersonation account takeover (ATO) happens when attackers use fake brand assets to expose customers, harvest credentials, and attempt access on the legitimate site. The impersonation stage happens outside the enterprise’s login environment, but the ATO risk appears when stolen credentials, attacker devices, or exposed users reach the legitimate login environment. That distinction matters because brand impersonation and account takeover are often handled as separate problems.

From Brand Impersonation to Account Takeover: The ATO Attack Chain

Brand impersonation account takeover (ATO) happens when attackers use fake brand assets to expose customers, harvest credentials, and attempt access on the legitimate site. The impersonation stage happens outside the enterprise’s login environment, but the ATO risk appears when stolen credentials, attacker devices, or exposed users reach the legitimate login environment. That distinction matters because brand impersonation and account takeover are often handled as separate problems.

Why know your transaction (KYT) is the AML capability financial institutions cannot afford to miss

The June arrests of Chilean bank workers accused of ties to an international criminal organization has again underscored the need for anti-money laundering (AML) detection to embrace real-time transaction intelligence. Authorities allege that a rogue Santander Chile employee was a key player in an $85-million USD money-laundering operation that channelled funds through accounts at almost every major bank in the country.

Stop AI-powered fraud rings with link analysis

Sophisticated fraudsters optimize and scale their systems to grow ROI. That's also a weakness you can exploit to shut down fraud rings before attacks scale. Fraud experts Nisreen Hussain, Irfan Faizullabhoy, and Ashley Fang show how pattern and link analysis stops AI-powered fraud, account takeovers, and large fraud rings. In the full webinar.

Why Visual Branding Combats Brand Impersonation Risks

Corporate identity theft happens fast online. A random criminal can copy a logo, launch a fake website, and trick regular customers within minutes. Many business owners forget that public visual design provides the first line of defense against online fraudsters. Brand protection blends security awareness with strict visual consistency.

A Fake MCP Server Just Exposed Your WhatsApp History

A security researcher introduced a malicious MCP server into an environment that already had a legitimate WhatsApp integration—and watched it silently expose message history without any user approval. The technique is called a rug pull. The server advertised one behavior at installation. On second usage, it switched to something else entirely. The approval was real. The thing you approved was not. This is what trust decay looks like in practice—and it passes every classical security check.

Fake Search Ads and Brand Impersonation: Why Takedown Alone Misses the Real Risk

Fake search ads are paid search placements that impersonate trusted brands, services, or login destinations to redirect users into fraudulent journeys. For enterprises, the risk is not only that attackers buy visibility. It is that they intercept customers at the exact moment those customers are trying to reach the real brand. That makes fake search ads different from many other phishing entry points. The user is not responding to a suspicious message.

What Is 'Business Identity Theft'? Corporate Security and Vendor Risk Management

Business identity theft occurs when criminals hijack a company's commercial credentials-such as its tax ID or registration details-to open fraudulent lines of credit, intercept vendor payments, or execute supply chain attacks. You do not just lose money. You lose your operational integrity.

Mythos access may be limited, but banking threats are there for all to see

Originally published in Vancouver Tech Journal, June 2, 2026. Bijan Sanii is CEO and founder at INETCO It may seem reassuring that JPMorganChase, the largest U.S. bank, is among the 12 launch partners involved in Anthropic’s Project Glasswing. But given the stark cybersecurity warning the initiative represents, including a single financial institution is nowhere near enough.

How to Detect Brand Impersonation: Key Signals for Security Teams

Brand impersonation detection is the process of identifying fake domains, cloned brand experiences, and exposure signals that show attackers are using a trusted brand to deceive customers, employees, or partners. For security teams, the harder problem is not finding every impersonation asset. It is knowing which signals indicate live user exposure and which ones should change the response.

The new reality for acquirers: blocking transactions that trigger card scheme penalties

Picture this: Your payments team starts the week with what looks like a routine performance review. Authorization rates are slightly off. A handful of merchants are seeing more retries than usual. Declines are climbing in one segment of the portfolio. But nothing looks catastrophic…yet. Then the warning signs start stacking up. An AI-driven BIN attack has quietly pushed enumeration activity higher. A few merchants are generating abnormal dispute patterns.

Athletes Are Increasingly Targeted by Social Engineering Attacks

Scammers are increasingly targeting athletes with advanced social engineering attacks, the Guardian reports. The Guardian cites a recent report from Ernst & Young that found that athletes and teams have lost nearly $1 billion to fraud over the past twenty years, and more than 40% of these losses were reported in the past six years.

Warning: Scammers are Exploiting Geopolitical Unrest

Scammers are taking advantage of the conflicts in the Middle East and Ukraine to exploit people’s emotions, according to researchers at ESET. “Geopolitical turmoil often leads to human misery, which tends to pull at the heartstrings,” ESET says. “Legitimate charities may solicit donations to help their efforts to support innocent citizens caught in the crossfire.