Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Warning: Replying to a "Wrong Number" Text Marks You as a Target for Scams

Attackers are using “wrong-number” texts to identify potential targets for scams, according to researchers at Malwarebytes. These texts appear to be harmless messages meant for another person, such as “Are we still on for dinner tomorrow?” or “Where’s the PowerPoint?” Recipients often try to be helpful by replying to let the person know they’ve got the wrong number.

The .vu Surge: How Threat Actors Are Exploiting Vanuatu's Domain Extension

Phishing infrastructure is built to be thrown away. When a domain gets blocklisted, scrutinized, or too hot to handle, the attackers don't stop. They just move. To them, a domain extension is just a cheap tool. They go wherever it is easiest to strike. That pattern is visible in our own telemetry. In late 2024 and early 2025, KnowBe4 Threat Lab documented a 98% spike in phishing campaigns abusing.ru domains. 1,500 unique domains, over 13,000 malicious emails, with an average domain age of just 7.4 days.

Brand Impersonation Protection Software: What to Look For Beyond Domain Takedown

Brand Impersonation protection software should do more than find and remove impersonating assets. Buyers should also examine what a platform helps their organization understand and do about the customer and business risk created while the campaign remains active. The Anti-Phishing Working Group recorded 971,181 phishing attacks in Q1 2026, up 13.8% from the previous quarter. Across monitored social platforms, impersonation accounted for 43.8% of threats. Takedown is necessary.

Report: AI Chatbots Are More Effective at Building Trust Than Human Scammers

A study has found that AI chatbots can be more effective at social engineering than human scammers, WIRED reports. The researchers looked at a form of romance scam commonly known as “pig butchering,” in which scammers spend weeks or months building a relationship with the victim before tricking them into sending money for a phony investment scheme.

Report: Americans Lose an Estimated $148 Billion to Scams Each Year

Americans are now losing an estimated $148 billion each year to online scams, a 22% increase compared to 2024, according to a new report from the Consumer Federation of America (CFA). The FBI’s Internet Crime Complaint Center (IC3) tracked $20.8 billion in losses last year, but the CFA notes that the actual losses are much higher.

Top tips: How to spot a scammer pretending to be your boss

Top tips is a weekly column where we highlight what's trending in the tech world and share practical ways to navigate these shifts. This week, we're looking at spear-phishing: how cybercriminals weaponize social engineering, why your natural instinct can act as a security blind spot, and practical steps to verify suspicious requests before you take action. I would like to make a confession: I’m a well-versed tech expert, but I almost fell for a phishing scam.

Report: Scams Are Surging as Attackers Abuse Trusted Workflows

Threat actors are increasingly abusing trusted workflows to carry out attacks, according to a new report from Gen Digital. “ are not only sending malicious links or dropping malware,” the report says. “They are abusing context, sessions, workflows, brands, update systems, advertising platforms and delegated authority.

Your Invoice Fraud Controls Probably Never Look at the Signature

Business email compromise took $3 billion in reported losses during 2025, the second-largest category in the FBI's Internet Crime Complaint Center annual report after investment fraud. The same report logged 1,008,597 complaints and $20.877 billion in total losses, up 26% on the year before. The control most organisations built in response is a callback procedure. Payment details changed? Phone the supplier on a number you already had. That control works, and it's worth having.

Report: Employees Are Overconfident in Their Ability to Spot Scams

A survey from Trustmi found that most employees believe they’d be able to spot a social engineering attack, but those same employees still rely primarily on outdated guidance to spot red flags. Generative AI has given attackers the ability to craft extremely convincing, error-free phishing emails.

How to Identify Users Exposed to Brand Impersonation Attacks

Most organizations have become better at finding brand impersonation attacks. They can detect fake domains, identify cloned websites, report phishing pages, initiate takedowns, and warn customers when an impersonation campaign becomes visible. That work matters. But it does not answer the question that often matters most once the attack is live: Which users were exposed? Finding fake sites is only half the problem. Understanding who encountered them is where effective protection begins.