Reading view

There are new articles available, click to refresh the page.

WhatsApp scam costs Hong Kong man $1.27 million after criminals used AI voice notes to impersonate his father — experts say secret codewords are the best way to stay safe

  • Scammers stole $1.27m from a Hong Kong man after tricking him with AI
  • The scheme impersonated his father using AI deepfake tech
  • Experts say using a secret codeword can thwart the fraudsters

A Hong Kong man was recently conned out of HK$10 million ($1.27 million) by scammers who used artificial intelligence (AI) on WhatsApp to impersonate his father and request the payments, highlighting the dangers of trusting increasingly realistic AI tools. Yet experts say there’s a simple trick that can save you from suffering a similar fate.

According to the Hong Kong police’s Cyberdefender platform (via the South China Morning Post), the fraudsters sent a WhatsApp voice message to the victim saying they urgently needed a transfer of HK$1 million ($127,000).

This was convincing to the target, the SCMP reported, because the “voice and manner of speech [of the message] matched his father’s.” The victim was repeatedly exploited this way until he had transferred the entirety of his savings.

Warning people against falling for AI trickery, the Hong Kong police force said: “Do not blindly trust voice messages. Even if the voice sounds similar, it does not necessarily mean it is accurate.”

If you’re unsure whether the message is genuine, put the phone down and call your friend or family member back so that you know with certainty who you are speaking to. The police also recommended enabling two-factor authentication on your devices and reviewing the list of devices connected to your accounts. If you see any suspicious devices, remove them immediately.

How to beat the fraudsters

The WhatsApp icon on an iPhone's display.

(Image credit: Brett Jordan / Unsplash)

Deepfake scams like this are so effective because they appear to come from a familiar, trustworthy source — even when they’re anything but. Yet experts have just published a proven way that you can beat the swindlers and keep everyone safe.

As reported by the BBC, setting a secret codeword to be used in emergencies can help you tell if the person on the call is actually a loved one or merely an AI impersonating them. As the BBC put it, “Deepfake scams might use your voice, but they don’t know what’s in your head.”

One tactic used by scammers is to use urgency in order to create panic and prevent you from thinking straight. That’s why it’s important to take a moment to think to ensure you remember to use the codeword and verify the caller’s identity.

When it comes to picking a codeword, “Pick something that’s easy to remember and hard to guess,” the BBC recommended. “Inside jokes are a safe bet.”

As Philadelphia lawyer and anti-scam activist Gary Schildhorn put it, there are three red flags to look out for: time pressure, a request for hard-to-trace funds (like cash, cryptocurrency or gift cards), and control over who you can speak to on the call. Experience any of those and you might be speaking to a malicious con artist.

Bear all that in mind and you stand a much better chance of protecting yourself from fraudsters. The next time you get an unusual message or call seemingly from a loved one, take a minute to breathe and remember your codeword.

FBI agent accused of stealing $1 million in crypto — and he even consulted ChatGPT on how to leave the country

  • A former FBI counterintelligence supervisor is accused of memorizing seed phrases from bureau systems
  • The agent moved roughly $1 million out of wallets tied to a foreign adversary without having to resort to any sort of hacking
  • Investigators recovered ChatGPT conversations in which he asked how to invest the money and how to gain EU residency, and the chatbot's replies recited his age, wife, child, and property plans back to him

Patrick Steven Yaroch, a supervisory special agent in the FBI's Counterintelligence and Espionage Division, has been arrested and charged with interstate transportation and receipt of stolen goods.

An affidavit filed in the Eastern District of Virginia, claims Yaroch took roughly a million dollars in cryptocurrency from wallets he encountered while investigating a foreign adversary and then used ChatGPT to determine what to do with it.

The theft, as described, required no technical sophistication whatsoever: Yaroch held a Top Secret clearance with SCI access and had spent 2017 to 2025 on a national security squad at the FBI's Boston division working against a single adversarial nation, which NBC News reports was Russia.

An atypical heist with the alleged mastermind acting out of "frustration"

Patrick Steven Yaroch encountered the cryptocurrency wallets tied to his work in November 2024. He had researched how wallets work, created one of his own, searched the FBI's holdings for the relevant account information, and memorized the recovery seed phrases.

He then made roughly 10-12 transfers to his own wallet. No encryption was broken, and no protocol was exploited because none was in place for a man with his security clearance; he simply read a phrase off an internal system and remembered it.

The incident is particularly interesting because he self-reported, effectively turning himself in to his colleagues: on July 28 2026, he contacted a Justice Department employee he had worked with in Boston over Signal, asking to meet. They met at FBI headquarters the next day, where Yaroch reportedly began breaking down almost immediately, and the conversation moved to the other man's office.

He said the situation was "eating him up inside" and that he wanted to give all the money back. He filed an online self-report to the FBI's Security Division and told headquarters personnel he had screwed up. When agents arrived at his Ashburn home that evening, he told them, unprompted and in blunter terms, that he had messed up.

His defense, as per the affidavit, however, is slightly different from what one would expect: His stated motive was not greed. He told his colleagues he had grown frustrated that the FBI could not or would not act against those accounts, described himself as "spinning out of control" at the time, and said he decided to take matters into his own hands.

Despite this, he seemingly had a change of heart after cooperating earlier, asking for a paper containing his wallet seed phrases, which he had volunteered to agents, while declining to continue the interview without a lawyer while asking for time over the next two days.

This culminated in agents obtaining warrants, executing them on July 31 with SWAT securing the house, and recovering an iPhone, a Trezor hardware wallet, the handwritten seed phrases, a Portuguese power of attorney dated June 15, and three passports, one of them diplomatic.

Man annoyed at laptop

(Image credit: Marjan Apostolovic / Shutterstock)

Ironically, the most potentially damning evidence of his intentions comes from his conversations with AI, still on his phone and directly linked to him.

His conversations with ChatGPT convey a very different thought process: On May 28, he asked how to invest or spend a million dollars to maximize profit and return. On June 4, he asked what someone with about a million dollars should do to leave the United States and become a resident or citizen of an EU country. On June 17 he asked whether an American connecting through Turkey needs a visa. On June 26 he asked for help drafting an email to an executive about a job opening and life in Greece.

There is more evidence that he might already have acted based on the answers he received: prosecutors have found a power of attorney authorizing two Portuguese lawyers to register him with the country's tax authority and obtain a Portuguese tax identification number, and unreported foreign travel to Germany in May, Portugal later that month, and Grenada in early July, all in breach of bureau reporting rules.

His current investments seem to be equally erratically reasoned: On July 23, five days before he first confessed, Yaroch moved roughly $1.02 million into Suilend, a lending protocol on the Sui blockchain, reaching it through the Slush wallet app, which he then deleted. He parked the funds there to earn interest. When asked why he chose that service, he said he liked its logo, a water droplet.

When agents looked, the position was worth $933,756, roughly 8% below its level a week earlier. His Kraken account held another $188,570, including about $5,000 in a token called Squid and $1.67 in Bitcoin. Agents ultimately swept $925,426 into government wallets, leaving about $165,582 behind because it was dollars and could not be moved to a crypto wallet.

Yaroch is charged under sections 2314 and 2315 of the federal criminal code, the general provisions on transporting and receiving stolen goods. He is not charged with espionage, with computer fraud, or with theft of government property.

The wallets were not the government's, and that might change how they are treated legally, even as it raises important questions about the security protocols at federal agencies regarding cryptocurrencies, since they both monitor and have seized increasingly large amounts of them over the past few years.

In Yaroch's case, if the allegations hold, government protocols failed to identify the theft for nearly eighteen months before the person responsible reported himself, making the case for a potential review by federal agencies about how they handle such matters.

Cybercrime is costing the world trillions every year - new report says victims lose an average of nearly $10,000 in every hit

  • New study puts average cybercrime victim losses at $9,468, making a global annual toll at just over $1.24 trillion across 130.9 million victims
  • Cybercrime is still massively underreported by both victims and authorities, so official numbers might be 'softer' than the underlying problem
  • Some of the countries published limited, if any, financial data regarding cybercrime, making losses an estimate at best

New figures have claimed cybercrime victims lose $9,468 in the average incident, showing the scale of an increasingly global problem.

The report from Comparitech claims 130.9 million people are hit each year, and that the annual global toll comes to just over $1.24 trillion.

A December 2023 study from the company put those figures at $8,069 per victim, 88.5 million people and $714 billion in total losses respectively, highlighting a growing trend that sees a mix of illegal activity moving the needle further.

A growing problem with regional caveats

The United States remains a favorite for cybercriminals, topping the charts with 6.7 million victims losing $138.9 billion, a per-victim loss amount of ~$20,731, more than twice that of the global average.

This is in stark contrast with the next four countries on the list (Spain, France, Sweden and Turkey), all of which offered an average of approximately $10,000 per victim.

Russia, coming in 6th, reports a much larger number of victims than the four countries ahead of it, but offers a much lower per-victim loss estimate of $3,659. Interestingly, the total number of cybercrimes committed in 2025 dropped to 663,000 from 775,000 in 2024, despite an ongoing conflict with Ukraine, which often sees cyberattacks at both the industrial and localized levels by both parties.

However, a weakening economic situation, as well as Russia localizing many of its communication applications and restricting banking, might also mean that Russia's figures also remain inadvertently capped by policy decisions the country has taken.

With 18.8 million victims, India has the highest number of scam victims worldwide, even though its pro-rata number is considerably lower than the mean at ~$835 per victim, which may be attributable to the country's lower GDP per capita.

Interestingly, China, with 1.2 million victims, a fraction of its neighbor, managed to lose approximately $11.5 billion, a pro-rata number of approximately $9583, in line with global estimates by Comparitech and possibly fueled by the country's heavy-handed approach to cybercriminals, which saw it apply increasing amounts of pressure on neighboring Myanmar that culminated in it convicting and executing scammers arrested across the border.

Comparitech's $1.24 trillion figure is conservative, and the study acknowledges this, noting that it covers only victim losses. It notes that experts anticipated the global cost reaching $10.5 trillion in 2025 and calls its own $1.24 trillion a drop in the ocean by comparison.

That $10.5 trillion comes from Cybersecurity Ventures' 2016 report, which estimated $3 trillion for 2015 and projected it forward at an assumed 15 percent compound annual growth rate, describing the result as the greatest transfer of economic wealth in history.

At a time when AI automation offers better security, often allowing users to screen calls or leverage security applications that adapt on a case-by-case basis, the inverse is also true with hackers and cybercriminals considerably upping their game when it comes to bypassing security altogether; Comparitech's figures provide a sobering reality: if the industry estimates it has hold and are compared to the GDP of entire countries, the firm says it would rank 20th in the world in those terms alone.

Experts warn 2.2 million cars could be at risk of hijacking via Bluetooth

  • 2.2 million vehicles are susceptible to a Bluetooth-based attack in the state of California
  • The vulnerability is due to dealer-installed security systems
  • Researchers at the University of California San Diego found that the Acrisure-built security devices all rely on the same secure key

A vulnerability has been found in KARR and SWDS automobile security systems manufactured by Acrisure that enables remote control via Bluetooth. The vehicles had the security systems installed by car dealers in California, specifically as anti-theft and tracking devices. Thanks to this hack, however, it seems that vehicles can be unlocked, with some further control given to the attacker.

Researchers at the University of California San Diego found that the 2.2 million automobiles were purchased from Southern Californian dealers since 2017, although the secondary market means that the vehicles could be elsewhere in the US, and even as far afield as Japan.

Worryingly, the researchers also found a publicly-accessible database holding information about all vehicles with the security system equipped.

How Bluetooth controls these cars

The researchers determined that the automobiles were purchased from Honda, Toyota, Mazda, Ford, and Jeep dealerships, and the affected vehicles have the “KARR-SWDS” label on the driver-side window, with the anti-theft device mounted under the dashboard.

Usage is straightforward: a mobile app connects to the KARR security system over Bluetooth and includes functions such as locking and unlocking doors, controlling the horn, and flashing the headlamps. It can also prevent the car from starting, although this only works if it isn’t already running.

The problem is with the implementation, which the researchers discovered relied on the same secure key on the KARR security systems. Once cracked, all cars equipped with the same device were believed to be open to attack.

Changing the secure key isn’t an option, and neither is disabling the Bluetooth. Of particular concern is that researchers found that even if the buyer doesn’t pay for a subscription for the app and the KARR system, the hardware is still in place. Worse, it has the same access to the vehicle’s doors, ignition, horn, and headlamps.

“Removing the devices is not trivial,” UCSD compsci PhD candidate and paper co-author Yibo Wei said in the report on the research (which is fully released in August). “You have to open up the dashboard and cut and reconnect the wires that are deeply intertwined with the car’s computers and ignition system.”

The patch is in

Jerry Yu, also co-author, wrote “Instead of smashing a window to get access to a vehicle, thieves could simply connect remotely via Bluetooth to the device inside the vehicle, and make it unlock car doors.”

KARR has told media outlets that only vehicles installed “with certain Bluetooth-related components” are affected, and the company has issued a firmware update.

13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan

We analyzed a sustained tech support scam campaign that sent more than 13 million emails to Japanese addresses, with workplace-themed lures suggesting a possible expansion toward enterprise targets.

Fake FBI social media scams are on the rise — here's what to look out for

  • Scammers are pretending to offer FBI support to victims
  • Victims are becoming double-victims after falling for this trap
  • FBI's IC3 warns never to pay for support – support will come from law enforcement

Scammers are increasingly impersonating FBI personnel and the FBI's Internet Crime Complaint Center (IC3) to defraud people who have already lost money to cybercrime, ultimately leading to them being exploited twice in quick succession by capitalizing on their weaknesses.

Attackers pose as support for recovering lost money and assisting with IC3 complaints, but the real objective is to defraud victims out of even more money or sensitive information.

But savvy victims should be able to identify these scams relatively easy, because despite a rising volume, the attack vector remains highly suspicious.

Victims are being hit twice via fake FBI scams

Rather than targeting the FBI's website, scammers send direct messages to victims or attract them via posts or ads on social media. "Some individuals received an email or a phone call, while others were approached via social media or forums," the FBI explained.

In the post, the FBI warns that attackers meet victims where they are, such as on Facebook, then quickly move them away to other, more secure channels like Telegram and connect them with other associates.

"The IC3 will not ask for payment to recover lost funds," the bureau warned, noting that victims should be weary of being contacted after reporting an attack. "If further information is needed, individuals will be contacted by FBI employees from local field offices or other law enforcement officers."

Victims who have either been attacked once, or attacked for a second time while trying to report the first attack, should report it via www.ic3.gov. The DOJ Elder Justice Hotline (1-833-FRAUD-11) also offers support for citizens aged 60+.

Google logo on a black background next to text reading 'Click to follow TechRadar'

US sanctions on rogue VPN accidentally break Telegram's short links worldwide

  • The US Treasury sanctioned First VPN Service for aiding ransomware gangs
  • Complying with the sanctions, the .ME registry wrongly suspended Telegram's entire t.me domain
  • The domain was restored roughly 19 hours later after Telegram CEO Pavel Durov flagged the issue online

If you clicked a Telegram link on Monday and stared at a blank screen, you weren't alone. Every shortlink starting with 't.me' suddenly vanished from the global internet, breaking group invites, profile shares, and channel links for roughly a billion users worldwide.

But the outage wasn't caused by a technical glitch or a targeted cyberattack. Instead, it was the unintended collateral damage of a US government crackdown on a cybercriminal proxy network.

On July 13, the US Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned the administrators of a rogue proxy network called First VPN Service (1VPNS), aiming to cut off infrastructure used by ransomware operators.

While anyone shopping for the best VPN expects privacy, First VPN actively courted cybercriminals with promises of total anonymity, leading European law enforcement to pull the plug on the service earlier in May.

As part of the new sanctions, the US Treasury published a list of web addresses associated with the VPN. Buried in that list was a link to First VPN's public Telegram support channel: t.me/FirstVPNService.

A sledgehammer to crack a nut

This photograph shows a laptop screen displaying the website of Europol featuring the First VPN service website with a message reading,

(Image credit: Photo by Fred TANNEAU / AFP via Getty Images)

Because top-level domains operate under strict international compliance rules, domain registrars must act quickly when sanctioned entities use their infrastructure.

Identity Digital, the company managing the technical backend for the .me domain, confirmed that the t.me domain had been blocked at the request of OFAC.

However, because a domain registry cannot selectively disable a specific webpage or channel path — like a single Telegram group — the Montenegro-based registry Domain.Me applied a "serverHold" status to Telegram's entire t.me domain.

This sweeping action effectively erased the domain from the global Domain Name System (DNS). The core Telegram app continued to function, and the older telegram.me domain remained active, but the shortlinks the messaging platform is built upon went entirely dark.

The swift resolution

The sudden shutdown prompted immediate action from Telegram's leadership.

Unaware of the backend domain hold, Telegram CEO Pavel Durov took to X to publicly ask the registrar for an explanation: "Hey @domainME, t.me links stopped working. Can you look into it?"

Hey @domainME, https://t.co/9z6UC2o37U links stopped working. Can you look into it? 🙏July 14, 2026

Once the sanctions issue was identified, Telegram scrubbed the offending channels from its platform. The registry operator subsequently verified the compliance and brought the domain back online.

"On 13 July, 1VPNS was included as a sanctioned entity by the US Department of the Treasury. A Telegram channel using the t.me domain was among 1VPNS identified infrastructure. Accordingly, the t.me domain was suspended," domain.Me confirmed in a statement following the outage.

The registrar clarified that normal service resumed roughly a day later, after Telegram provided confirmation that it had removed its links and affiliations with 1VPNS. "We appreciate Telegram's prompt cooperation in resolving this matter," domain.Me added.

While the outage is now resolved, the incident highlights a glaring vulnerability in the modern web, where a single URL swept up in a government sanctions list can inadvertently silence an essential communication channel for millions.

81 million login attempts hit Microsoft 365 accounts as hackers try password-spraying to force entry using stolen credentials and OAuth to bypass authentication

  • A password-spraying attack successfully breached Microsoft 365 accounts
  • The hackers abused improperly configured conditional access policies to bypass MFA
  • Many organizations targeted had no MFA implemented

Hackers have used previously leaked credentials to target Microsoft 365 accounts in a password-spraying attack that resulted in over 81 million login attempts during a two-week period.

The attackers then abused the improperly implemented Conditional Access policies within the Resource Owner Password Credentials (ROPC) OAuth mechanism using Azure command-line interface (CLI), allowing the hackers to bypass authentication altogether when a matching username and password was discovered.

Cybersecurity company Huntress observed the attack campaign as it targeted customers and noted that 78 Microsoft accounts across 64 organizations were compromised between June 12 and 26 2026.

Hackers access 365 accounts without authentication

The success of the attack ultimately came down to how well organizations had implemented Conditional Access policies relating to multi-factor authentication.

“Many of the compromised businesses had implemented multi-factor authentication (MFA) via a Conditional Access Policy (CAP), but the MFA was not configured to cover this specific flow that attackers used,” Huntress explained, referring to the exploitation of ROPC.

“ROPC is considered problematic for several reasons, but one of those reasons is that it doesn't offer support for modern auth flows like MFA or SSO. That means, as we saw in this campaign, ROPC sends the password straight to the /token endpoint with no interactive MFA prompt.”

Several of the organizations that were breached did not enforce an MFA policy at all, with others only applying MFA for specific user groups such as administrators. In other cases, a login attempt only required MFA when the traffic was coming from an untrusted location, meaning that MFA was not enforced if the connection was coming from a trusted IP address. Additionally, some organizations had only enforced MFA in report-only mode, meaning that the MFA policies were never actually applied.

In order to protect against attacks of this kind of attack, Huntress recommended the following mitigations:

  • Organizations should implement MFA for All Users, All Cloud Apps, and All Client App types
  • The Azure CLI application should be restricted from use by non-admin users
  • Response to the attack should be made on credential validity, rather than spray volume

Via BleepingComputer

‘100% of Hide My Email addresses were exploitable’: Apple’s security feature can be duped into supplying the real contact info — and the bug has remained unpatched for over a year

  • Apple Hide My Email can reveal a user's authentic email address
  • The bug puts users at risk of identification, experts warned
  • It has been unpatched for over a year

A bug in Apple’s ‘Hide My Email’ feature allows for those with knowledge of the vulnerability to identify the real email address hidden behind the anonymous email address.

The bug was discovered by EasyOptOuts co-founder, Tyler Murphy, who shared the exploit with 404 Media after notifying Apple multiple times that the feature could be actively exploited.

“We reported the issue and replication instructions to Apple over a year ago. We don't know why it hasn't been fixed, but we don't feel comfortable waiting any longer,” Murphy said.

Hide My Email can be actively exploited

As the bug still hasn’t been patched, the details of how the exploit works have not been shared.

Apple’s Hide My Email feature was designed to anonymize email addresses, helping to prevent a user’s real email address from being leaked in a data breach, or to prevent a user’s email address from being linked to them personally in a way that could reveal their identity.

There lies the crux of the issue. By being able to identify the real email address by exploiting the bug, a malicious actor could uncover the real identity of the anonymized email.

“Free, publicly accessible people-search sites make it easy to link an email address to other personal details, so people relying on Hide My Email for safety may be at risk,” Murphy said. “We don't know the full scope of the issue, but in our limited tests with volunteers, 100% of Hide My Email addresses were exploitable.”

Users concerned about being identified via people-search sites can use a data removal service to have their data scrubbed from these sites, but the process can take a few days.

The issue was first reported to Apply by Murphy in June 2025, with Apple replying a month later that it was looking into the cause of the issue. Earlier this year, in March, Apple said that it had “addressed the reported issue in a recent system change,” but Murphy found that the bug could still be exploited.

Again, Murphy notified Apple, who replied in May 2026, stating, “We are still investigating this issue. To avoid placing our customers at risk, we would appreciate you not disclosing this information until our investigation is complete. We appreciate your assistance in helping us to maintain and improve the security of our products."

Later in the same month, Apply said a fix was “expected in the coming weeks."

FBI warns of Russian Intelligence phishing campaign abusing Signal support services to target VIPs and high-value government and military targets — this is how to secure your account

  • Russian Intelligence are targeting Signal accounts of officials based in Ukraine
  • They pose as Signal support services and ask users to submit their Backup Recovery Keys
  • Using these keys, the hackers can hijack the users account and any other accounts created using the same mobile phone number

The FBI has warned Russian Intelligence Services are posing as commercial messaging application support services in order to steal Backup Recovery Keys belonging to targets of high value in the military and government of the US, Europe, and Ukraine.

In a joint warning alongside the CISA and the Security Service of Ukraine (SSU), the FBI outlined the new phishing campaign which seeks to access messaging accounts in order to perform intelligence gathering of secret information.

Specifically, the FBI provided sample phishing lures targeting users of the Signal messaging app. If the hackers successfully lure a victim into sharing their Backup Recovery Key, they can access the account's message history, private and group messages, and fully take over the victim's account.

Russian Intelligence pose as Signal support services

In the FBI warning, the phishing techniques are further detailed. The Russian Federal Security Service (FSB) are targeting government officials, military personnel, political figures, journalists, and key officials from the US and Europe located in Ukraine.

The attackers send emails that appear to be automated messages from Signal, asking users to turn on their message backup using their Backup Recovery Key. Victims are provided with false instructions that instead send the Backup Recovery Key to the attacker, who can then use the key to take over the victim’s account.

Example phishing messages used by Russian Intelligence, supplied by the FBI

Example phishing messages used by Russian Intelligence to obtain Backup Recovery Keys (Image credit: FBI)

In order to establish urgency and trust that the message is legitimate, the attackers posed the phishing message as a protection against recent hacking attempts from “Iran and post-Soviet countries.” In another sample message, the attacker's message says that the victim’s account data “is at risk of permanent loss due to a sync issue.”

If a victim shares their unique Backup Recovery Key, it allows the attacker to hijack their current Signal account alongside any subsequent accounts made with the same phone number.

For users who may fear their Backup Recovery Key has been compromised, users are instructed to use Signal settings to create a new Backup Recovery Key. This new key will invalidate all previous Backup Recovery Keys and prevent account takeover if the previous key was leaked.

In order to avoid falling victim to phishing messages, there are several ways to stay safe:

  • Support services will generally only communicate with users via an official company email address. Always carefully check communications from the legitimate email address.
  • Customer support will never request that you supply your Backup Recovery Key via the application
  • You will never be asked to verify or restore your account via an automated customer support message

In order to further protect your Signal account, or other accounts, against phishing, users should consider the following:

  • Use a passkey wherever possible. This will use your device’s built in biometric verification methods to authenticate your login.
  • Use phishing resistant multi-factor authentication where possible
  • Always double check messages and emails are legitimate, and are using an official company email
  • Never supply your Backup Recovery Keys unless you are actively attempting to regain access to your account via a legitimate service

Over 14 million login credentials leaked from six ISPs in major data breach — here’s what we know

  • Tens of millions of credentials may have been leaked following an attack on one of Japan's largest ISPs
  • The attack leveraged a vulnerability in a third-party software used by KDDI
  • Five other ISPs were also affected in the attack

A data breach that has potentially exposed the email and password combinations for over 14 million customers across six internet service providers (ISPs) has been disclosed by Japanese telecoms provider KDDI Corporation.

According to the company, hackers exploited a vulnerability in a third-party software to access the database of credentials. KDDI said that it immediately blocked the hackers' access after discovering the intrusion on June 17, 2026.

“Although technical defensive measures have already been implemented for the system, there remains a possibility that customers' email addresses and passwords were obtained by unauthorized third parties as a result of the incident,” the company said in a statement.

Millions of credentials exposed

Unfortunately, the breach was not confined to just KDDI. The email services of five other ISPs were also affected by the breach:

  • STNet, Inc.
  • JCOM Co., Ltd.
  • Chubu Telecommunications C., Inc.
  • NIFTY Corporation
  • BIGLOBE Inc.

KDDI is yet to finish a formal investigation into the attack, but said that the hacker may have gained access to the emails addresses and passwords for 14.22 million current and former customers. The company also said that some of the passwords were stored in an encrypted format, and so will be inaccessible for the hackers, but the company did not say how many were stored in this manner.

Since discovering the breach, KDDI has also been working alongside the affected ISPs to secure systems and put in place mitigation measures to counter the abuse of exposed account credentials.

In order to stay protected, customers have been advised to change their account passwords and implement two-factor authentication.

Breaches such as these are particularly dangerous because they expose email and password combinations. As most people will have either one or two email addresses across their accounts, it increases the likelihood that hackers can attempt to use the exposed email and password combinations to try and access other accounts created with the same email.

This is especially true if the same password (or a variant thereof) is used across multiple accounts. Hackers can use brute force techniques to try hundreds of password combinations in a very short amount of time in order to crack weak or reused passwords.

When creating or updating a password for any account, no matter how infrequently it is used, always create a strong unique password. Password managers can create and suggest strong passwords, securely store them, and automatically fill login forms to take the hassle out of remembering passwords.

Alternatively, some services offer the ability to login using a passkey, which utilizes the built-in biometric authentication mechanisms of your device such as a facial scan or fingerprint. These login methods not only remove the need to type in passwords, but also reduce the possibility of hackers accessing your account through phishing attacks.

Via BleepingComputer

Watch out — that income tax form could actually be dangerous malware

  • Fake tax notices are becoming delivery vehicles for sophisticated remote access malware
  • Attackers hide malicious code behind convincing government branding and legal references
  • The malware quietly establishes encrypted communication with servers outside the country

A new phishing campaign is using fake income tax assessment notices to deliver dangerous malware to unsuspecting victims across India.

Researchers at CYFIRMA identified the operation, which relies on a fraudulent website built to resemble official communication from the Indian Income Tax Department closely.

The fake portal, hosted on a recently registered domain, presents a convincing assessment order complete with legal references, financial penalties, and urgent compliance language designed to pressure recipients into acting quickly.

How the infection unfolds

Victims who interact with the fake notice are prompted to download a ZIP archive disguised as official assessment documentation and supporting calculations.

Once extracted, that archive reveals a disk image file functioning as a container for the actual malicious payload.

Inside sits a loader program that quietly triggers a second component, a DLL file disguised to resemble a legitimate Windows service.

Researchers found that this loader uses reflection-based techniques specifically built to make automated detection and analysis considerably more difficult.

Both files were obfuscated using a known protection tool, further complicating efforts by security teams to inspect the code.

Once active, the payload behaves like a Remote Access Trojan, granting attackers persistent, encrypted access to the infected machine.

It can collect system details, monitor user activity, check which security software is installed, and silently load additional malicious components on command.

Communication with the attacker's server happens over an encrypted channel, using a hardcoded address traced to infrastructure based in Hong Kong.

These capabilities point toward a financially motivated operation, rather than one focused on immediate damage or disruption, and they closely resemble traits associated with known commodity RAT families such as XWorm.

However, researchers note that conclusive attribution to a specific threat actor remains unconfirmed at this stage.

Why this campaign matters

This is not an isolated phishing attempt but part of a broader pattern of attackers exploiting tax season anxiety to bypass user caution entirely.

CYFIRMA's findings show the same loader-and-payload architecture has previously been linked to ransomware operators, suggesting this infrastructure may serve more than one type of attack depending on the victim.

Up-to-date antivirus software with behavioral detection remains one practical defence against this kind of staged, multi-component malware delivery.

Security researchers recommend that individuals verify any tax-related correspondence directly through official government channels rather than clicking embedded links.

Organizations are advised to restrict the execution of unknown files arriving through archives or disk images, since this campaign relies heavily on that exact delivery method to succeed.

Google logo on a black background next to text reading 'Click to follow TechRadar'

GTA VI fans beware — experts warn 'a new wave of scam websites' is offering early access, but just stealing your bank details instead

  • Fake GTA VI beta keys are already draining cryptocurrency wallets worldwide
  • AI-generated scam websites now imitate Rockstar branding with alarming accuracy
  • Malware hidden inside fake game downloads can expose banking credentials instantly

Grand Theft Auto VI is not due on consoles until November 19 2026, but official preorders open soon, and cybersecurity researchers have warned criminals are already exploiting the wait with a coordinated wave of fraudulent websites.

Malwarebytes and NordVPN have both flagged sites promising "VIP early access" or exclusive beta keys to one of gaming's most anticipated releases.

The schemes ask victims to hand over money, personal information, or both, often before any real product changes hands.

How the scam works

Some fraudulent sites ask players to pay a few hundred dollars in cryptocurrency for a so-called VIP beta key. This method makes refunds or fraud reports practically impossible once the payment clears.

According to Stefan Dasic of Malwarebytes, GTA VI is "the perfect bait" that can be used by cybercriminals.

The franchise sold hundreds of millions of copies and went 13 years without a new entry — conditions that make hype, and therefore impatience, unusually intense.

Gerald Kasulis of NordVPN said scammers now use AI to mimic Rockstar's official branding so convincingly that polished emails and websites slip past a gamer's usual scepticism.

Some pages invoke the phrase "help us build Vice City," a reference to the game's fictional setting, to create a false sense of insider access.

Victims are sometimes directed to download software branded as an early build, including one fake file called GTA Mobile 6.

According to researchers, this file contains malware capable of letting fraudsters remotely access the victim's device, often bypassing antivirus software.

NordVPN has separately traced some of these fraudulent domains to a wider network with a documented history of spreading banking trojans, infostealers, and ransomware.

Other variants simply harvest names, addresses, dates of birth, or existing GTA login credentials, data that can then be resold.

Several of these scam sites even target PC and Android users, despite Rockstar never confirming that those versions exist yet.

Who is being targeted?

The typical victim tends to be someone too young, too eager, or simply underinformed, and primarily driven by a desire to be first in line for the game.

However, Malwarebytes' assessment of the scam wave reveals that the trick itself is rarely sophisticated, yet it consistently fools people regardless of age.

The character of those falling for these scams goes beyond simple naivety, since urgency and curiosity are what scammers are really exploiting across these campaigns.

Younger players and newcomers to online gaming appear especially exposed, given their relative unfamiliarity with how official preorder and beta access processes normally function.

Neither company has data on exactly how many people have visited these sites or lost money so far.

Rockstar Games has not responded to requests for comment on the ongoing scam wave or its impact on players.

Security researchers are urging anyone tempted by claims of early GTA VI access to pause and verify the source before entering any personal or financial details.

Players who have already entered credentials or payment information are advised to change their passwords immediately.

They should also contact their bank without delay, since cryptocurrency payments in particular cannot be reversed once sent.

Via PCGAMER

Google logo on a black background next to text reading 'Click to follow TechRadar'

‘Travelers are getting better at spotting obvious scams' — but experts warn Airbnb scams are on the rise as summer arrives

  • Airbnb scams have surged 30x since 2023, including a sharp rise this year
  • Criminals hijack legitimate host accounts to to trick holidaymakers
  • Staying safe isn't so straightforward as threats evolve

Airbnb-related scam activity has increased 30x since the first half of 2023, according to new research from Saily and NordStellar, confirming that cybercriminals continue to go after holidaymakers seeking the best deals amid rising prices.

The report ultimately concludes that attackers are now targeting the trust built by larger platforms, saving them from having to build new identities from scratch.

And to top it all off, the nature of scams is also changing, as instead of using suspicious websites to obtain victim payments or information, criminals are now targeting legitimate Airbnb host accounts which have spent years amassing positive reviews and high ratings.

Exploiting legitimate accounts and hijacking trust

While the end goal remains high volumes of vulnerable consumers, scammers have added an extra layer of victim in their pipeline. Verified Airbnb hosts are now valuable assets for criminals because they already have identity verifications, positive reviews, booking histories, years of activity and established credibility.

Once the verified account is compromised, attackers can then go on to scam higher volumes of unsuspecting victims by posting – and charging for – fake property listings.

“Travelers are getting better at spotting obvious scams,” Saily Head of Product Matas Cenys said. “Criminals know this, so they are increasingly trying to steal trust instead of building fake trust from scratch.”

Where this type of attack differs from others, though, is that the victims never leave the platform. Rather than falling victim to phishing attacks and being redirected to malicious external sites, they interact fully with supposed legitimate hosts on the Airbnb platform.

While Airbnb attacks have seen a 30x increase in around three years and a sharp rise in the last year alone, they reflect a much broader trend of attackers compromising existing trusted accounts.

The recent ramp-up in attacks could also be tied to the summer season, with holidaymakers looking to book last-minute deals in the run-up to the summer season. Urgency and pressure to keep costs low also adds to criminals’ success.

“Everything looks normal until they arrive at their destination and discover the accommodation never existed," Cenys added.

How to protect yourself from booking scams

Saily is recommending that all communication stays within the booking platform and that customers avoid payment methods suggested outside of official channels. Unusually attractive listings in high-demand destinations could also be taken with a pinch of salt, and savvy shoppers may choose to reverse image search a property to double check its authenticity.

“As travel booking becomes increasingly digital, trust becomes one of the most valuable currencies in the travel ecosystem,” Cenys warned.

As for abusing victim trust, researchers also argue that AI has aided attacks by allowing criminals to produce better fake listings more quickly.

More generally, Airbnb revealed that two in five Americans have fallen victim for an online scam, with the average loss totalling nearly $2,000. The company has introduced measures to remind its users how to avoid scams, including introducing identity verification and reminders not to leave the platform, but account takeovers can still slip under the radar.

Airbnb also holds guest payments until 24 hours after check-in to ensure that everything is as described. Anti-fraud tech also prevented around 265,000 suspicious listings from appearing on the platform in 2025, the company boasted.

The company posted a comprehensive eight-step list of how to avoid scams on its platform online, calling out pressure tactics and unusual deals.

Google logo on a black background next to text reading 'Click to follow TechRadar'

❌