Un SIM swap dura minuti: un addetto corrotto o un'ingegneria sociale al supporto, e l'attaccante riceve ogni OTP via SMS della banca, email ed exchange crypto. Tracciamo le regioni con picchi 2024-2025 e le firme SS7.
La Polizia Postale lancia l'allarme su una nuova ondata di compromissioni di account WhatsApp tramite attacchi "zero-click" su iOS non aggiornato. I criminali, senza che la vittima clicchi nulla,...
La Polizia Postale segnala una truffa diffusa su WhatsApp: i criminali sottraggono o compromettono account di contatti noti e, spacciandosi per amici o familiari presenti in rubrica, inviano messaggi...
Email/SMS dice che l'account Amazon è bloccato per 'attività sospetta' e chiede di confermare password + carta di credito su link. Una variante recente usa Amazon Music/Prime in scadenza con rinnovo...
Truffatore compromette la casella email del tuo fornitore (phishing/credential stuffing) e da lì invia fattura/richiesta di pagamento con IBAN cambiato. La email PROVIENE realmente dal fornitore...
OAuth consent phishing is a sophisticated scam where attackers send direct messages impersonating government officials, media figures, or event coordinators, then trick victims into granting app...
The FBI is warning that criminals are hijacking social media and personal accounts to steal intimate images, then posting or selling them alongside victims' contact details on criminal marketplaces....
The FBI is alerting the public that sexual exploitation actors are targeting adult and underage victims by illegally accessing social media and personal accounts to steal and distribute explicit...
A new WhatsApp scam tricks victims into giving attackers access to their accounts by posing as a friend asking for a vote online. The message—often sent from an already-compromised contact—links to a...
Fast-food chain Chick-fil-A has disclosed a credential stuffing attack that hijacked customer loyalty accounts between June 17-19, 2026. Attackers used usernames and passwords leaked from other...
Attackers are using a clever phishing trick that abuses Microsoft’s own legitimate login page (microsoft.com/devicelogin). Instead of sending you to a fake site, they trick you into visiting the real...
Email accounts are a top target because they control password resets for nearly every other online service you use. With a single compromised inbox, attackers can intercept banking codes, impersonate...
The false report scam is a pure social engineering attack targeting Reddit and Discord users. A stranger claims someone reported your account (or that they accidentally reported you), then sends a...
A new active malware campaign is spreading through WhatsApp Web and Desktop, using hijacked user accounts to send malicious VBScript (.vbs) files to contact lists worldwide. Victims receive a message...
Meta's AI-powered support chatbot was tricked by attackers into changing the email addresses on Instagram accounts, effectively handing over account control. The bot failed to verify the true owner's...
Scammers are sending fake "You're invited" texts and emails tied to graduation and summer party season. The message pressures you to enter your email address and password (or a one-time passcode) to...
Hackers are exploiting Meta's new AI customer-support chatbot to hijack Instagram accounts, including high-profile handles like the Obama White House and a US Space Force chief. The trick: an...
Attacker bribes / social-engineers a T-Mobile / AT&T / Verizon rep (or uses insider) to port the victim's number to attacker's SIM, then resets bank, exchange (Coinbase, Kraken) and email passwords...