Malware Bytes
Fake parcel delivery messages steal your card and bank details
Parcel delivery phishing campaigns appear around the world under different courier names. In the United States, the messages commonly impersonate USPS and claim that a package has an invalid address or could not be delivered. Similar messages impersonate Colissimo and Chronopost in France, Correos in Spain, Poste Italiane in Italy, and PostNL in the Netherlands.
The details vary, but the aim is usually the same: to persuade you to visit a fake courier website and provide personal and financial information.
A fake bpost delivery emailA recent campaign targeting customers of the Belgian postal service bpost begins with an email claiming that a package could not be delivered because €4.95 in customs duties has not been paid.
A phishing email, in Dutch, pretending to be from bpost.In English, the subject and message read:
Undelivered package—customs duties due (tracking no. 3232116291*******).
Your package could not be delivered on September 9, 2026, because the customs duties (€4.95) have not been paid.
The amount is small enough that recipients may pay without giving it much thought. However, the website does not stop at collecting the supposed fee. It asks for personal information, card details, and banking information.
How the scam worksThe link first passes through a URL-shortening service (hxxps://qr[.]paps[.]jp/1GWsa) before redirecting to a fake bpost site. The campaign used several fake bpost domains, including:
hxxps://bpost[.]be-pakje-ontvangen-nl-recevoir-colis-fr[.]my[.]id/
bpost[.]center, which is the domain shown in the screenshots below.
The page copies bpost’s branding and displays security claims such as “Secure SSL connection,” “256-bit SSL,” “SEPA compliant,” and “Secure payment.” These labels were added by the scammers and do not prove that the page or payment is secure.
We’ve translated the screenshots below from the original Dutch into English.
The first page asks for the recipient’s name, phone number, email address, and age:
That reference to receiving funds does not match the email’s claim that a customs fee must be paid. The next page asks for an IBAN, card number, expiry date, and payment amount:
Then it asks for the real target: full card and bank details.
The original Dutch version contained another mistake: One of its buttons read “Indian search” instead of “Betaal,” the Dutch word for “Pay.” Mistakes like this can expose a scam, but many phishing pages are built carefully enough that there will be no obvious typo or mistranslation.
Once submitted, card details may be used for fraudulent purchases or sold to other criminals. The personal and banking information may also be used to make later scams more convincing.
How to protect yourself- Check delivery claims independently. Open the courier’s official app or type its website address into your browser, then use your tracking number to check the delivery.
- Check the sender and destination. A message may use a courier’s name while coming from an unrelated email address or linking to a different domain.
- Be wary of unexpected fees or refunds. A small payment or promised refund can be used to persuade you to provide much more valuable information.
- Be wary of requests for extensive financial information. A request for an IBAN as well as card details should be treated with suspicion, particularly when it supposedly relates to a small delivery fee.
If you entered your card or banking information on a suspicious site, contact your bank or card provider immediately. Freeze the affected card if your banking app allows it, monitor your accounts for unfamiliar transactions, and change any password you entered on the site.
Malwarebytes tracks and blocks these campaigns as they appear. If you’re unsure about a message, Scam Guard—built into Malwarebytes for Windows, Mac, Android, and iOS—can check it for you. Paste in the message or link, or upload a screenshot, for an instant assessment.
Scam Guard can analyze a suspicious email, text, link, or screenshot and tell you whether it may be a scam. Something feel off? Check it before you click.Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.
Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
Flock cameras are tracking people as well as cars
Flock Safety’s cameras are automated license plate readers (ALPRs) designed to help police find stolen cars or wanted suspects.
A joint investigation by 404 Media and WIRED, based on data recovered from a physically removed Flock camera, found that its on-device software explicitly detects people as well as vehicles, bicycles, and license plates.
Separately, Washington DC’s police union says the Metropolitan Police Department used Flock data to track officers under Internal Affairs investigation without their knowledge.
Together, these reports illustrate a privacy problem: A network built to record the movements of vehicles can readily be used to follow almost anyone.
The latest reporting adds an important technical detail to that debate.
What Flock cameras collectA group of hackers reportedly removed a Flock camera from a roadway, copied its storage, and recovered an encryption key stored on the device. That allowed them to unlock videos of thousands of vehicle detections despite Flock’s claim that its devices are protected by on-device encryption. Flock said it could not assess the claims without more detail.
The recovered camera files reportedly contained software models that detect people, even though public discussion of Flock has usually focused on cars and license plates. The researchers found no evidence that face-recognition features were actively used. Reassuring, but it should not be mistaken for a clean privacy bill of health.
Even without facial recognition, a system that records repeated sightings can potentially reveal sensitive patterns of movement, including where someone lives, works, worships, seeks healthcare, attends protests, visits family, or spends time with other people. When a person is matched to a vehicle, vehicle-based tracking can become person-based tracking in practice.
As an example of how widely the data can be shared, WIRED found that records from the city of Alpharetta, Georgia:
“were accessible to more than 2,000 agencies, including police departments, colleges, airports, and, inexplicably, the Office of Inspector General for the federal General Services Administration.”
Targeted tracking of peopleThe Washington DC dispute shows what happens when the power to follow people is turned inward.
The DC Police Union says it learned in July that MPD’s Internal Affairs investigators had used Flock license-plate-reader data to track sworn officers under investigation without their knowledge. The union filed a complaint and asked the department to stop, arguing that MPD lacked adequate controls for a system with such extensive surveillance capabilities.
MPD defended the use, saying its position is that the use of license-plate-reader data in the misconduct investigation was appropriate. It said the labor dispute is headed to arbitration.
If police officers themselves are concerned that the system can be used to monitor them without transparent rules, the public should ask an obvious follow-up question: What prevents the same tools from being used to follow residents, employees, journalists, activists, former partners, or other people with no meaningful ability to challenge the search?
Even when Flock wants privacy to meet surveillance halfway, its measures do not eliminate the underlying civil-liberties issue.
The recovered camera software and the DC dispute make the same point from different directions. Flock’s network is not merely a collection of roadside plate readers. It is a distributed system for recording movement, identifying patterns, and making those records available for search.
Meaningful safeguards should include:
- Public approval before cameras are deployed, with clear maps showing their locations and stated purposes.
- Strict limits on collection, retention, searches, and cross-jurisdictional sharing.
- A requirement for documented investigative justification before a search, with elevated approval for sensitive investigations.
- Independently reviewable audit logs, regular public transparency reports, and meaningful penalties for misuse.
- Clear bans on searches related to protected activity, immigration enforcement where local law forbids cooperation, abortion-related investigations, political surveillance, and personal purposes.
- Independent security assessments covering the cameras, cloud services, identity controls, key management, and third-party integrations.
- Automatic deletion that cannot be overridden merely because data could someday be useful.
Privacy cannot depend on authorized users always following rules, vendors configuring every setting correctly, or abuses being discovered the hard way. The first safeguard should be limiting the system’s ability to build a searchable record of ordinary people’s lives at all.
Browse like no one’s watching.
Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free →
Revolut phishing texts appear days after data breach
Only days after Revolut acknowledged that it disclosed sensitive customer records to an unauthorized party, affected customers are receiving phishing texts. However, we don’t know yet if the phishing texts are linked to the breach.
The company had accepted fraudulent information requests sent from an email address on a legitimate government agency domain.
Through this social engineering attack, rather than by gaining access to Revolut’s systems, the criminals obtained the following types of information about customers:
- Identity and contact information such as dates of birth, postal addresses, email addresses, and phone numbers
- Copies of IDs such as passports and driver’s licenses
- Verification selfies
- Account statements and transaction histories
Revolut has said only that a “limited” or “very limited” number of customers were affected, and that it contacted them directly.
One affected customer received a phishing text on Monday, September 14, two days after Revolut publicly acknowledged the data breach. The message appeared in the same conversation as other Revolut texts, making it look as though it had come from the bank.
Phishing text to a Revolut customerAccording to VirusTotal, the phishing domain was first scanned that same day.
In a separate example, another customer said that opening the link took them to a web page that requested access to their device’s camera. If you tap Allow, the page reportedly imitates Revolut’s live-video “turn your head” identity check before prompting you to enter a password.
This makes the phishing page appear more authentic. It may also allow the scammers to collect a selfie or video that could be used for further social engineering, identity fraud, or to make subsequent scams more convincing.
A convincing fake liveness check followed by a password screen is a common way to lower suspicion and obtain the information attackers need to attempt a real login or account-recovery flow.
If the campaign is connected to the breach, the information obtained from Revolut, combined with login details entered by victims or their approval of a login request, could be enough to take over their accounts.
How to stay safeWe don’t yet know whether the phishing campaign is using data exposed in the breach or whether unrelated scammers are exploiting news of the incident to target Revolut customers more broadly.
Either way, treat unexpected messages about your account with caution:
- Don’t follow links in unsolicited messages. If a message concerns your account, open the official Revolut app directly.
- Check the actual domain in your browser’s address bar to see if it corresponds with what you expect.
- Use an up-to-date, real-time anti-malware solution on your device, preferably with a web protection component.
- Malwarebytes Scam Guard can help you determine whether a message is a scam and advise you on what to do next.
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
12 celebrity deepfake websites seized by Manhattan DA
The Manhattan District Attorney’s Office has seized the domains of 12 deepfake websites in what it called the largest known seizure of celebrity deepfake sites in history.
The sites, which marketed themselves as deepfake pornography platforms, hosted AI-generated videos of over 1,200 people, including those in the public eye, ranging from politicians to actors, musicians, and social justice advocates. At least one allowed users to create their own deepfakes by grafting real faces and bodies onto sexual imagery.
The term non-consensual intimate imagery (NCII) is increasingly used instead of pornography when the person depicted has not given permission. Deepfake NCII is growing, due in part to the ease with which it can be created. It only takes one photo to generate it, as we discussed on the Lock and Code podcast in June.
MrDeepFakes was previously the largest site for this kind of content. Its operators shut it down in May 2025, citing data loss. An Australian man who posted explicit deepfakes to the site was arrested, fined for contempt of court, and charged with publishing obscene material.
But other deepfake NCII sites continue to compete for attention online.
Deepfake technology can cause real harm when misused, and its effects continue to spread. Manhattan District Attorney Alvin Bragg warned that domestic abusers are threatening to release deepfake NCII depicting their victims. The FBI has also warned that sextortion attackers are using AI to turn social media photos of minors into sexually explicit images.
Legal action is growingLaw enforcement has been working hard to stem the flood of deepfake NCII sites. In June, the Department of Justice and the Department of Homeland Security seized two domains hosting hundreds of thousands of forged images and videos. San Francisco City Attorney David Chiu’s office also sued 16 deepfake sites in August 2024, managing to get ten of them taken offline or made inaccessible in California. New York state also passed legislation prohibiting the distribution of intimate deepfake images and videos in 2023.
At the federal level, the TAKE IT DOWN Act, enacted in May 2025, made certain intentional publication of NCII, including sexual deepfakes, a federal crime.
Seizing a deepfake site stops the immediate distribution of its content, but operators can migrate quickly to other infrastructure. A report from the Institute for Strategic Dialogue (ISD) found that the deepfake ecosystem is made of many parts, from AI tool providers through to hosting companies and cryptocurrency payment processors. It called for a multi-sector collaboration to stop the production and spread of this material.
Bragg’s office said it will continue monitoring the seized websites to stop them reappearing under different domains.
What can you do?If someone creates or threatens to share intimate deepfakes of you, save the evidence and report it to the police. Do not pay someone who threatens to publish the images, as payment does not guarantee that the threats will stop.
Bragg’s office said many of the victims it approached did not realize that action could be taken. It urged anyone affected by the seized websites to contact its Cyber Crime Bureau at 212-335-9600.
You can learn more in the Malwarebytes guide to deepfakes. UN Women also provides useful resources for people affected by AI-powered abuse.
Scammers don’t need to hack you. They just need you to click once.
Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.
T-Mobile rewards points expiry texts are a phishing scam
Since early May 2026, we’ve been monitoring a large phishing campaign based on T-Mobile rewards points.
The messages falsely warn that a customer’s rewards points are about to expire. They aren’t legitimate account notices: They use urgency, invented point balances, and phishing links to push recipients into acting before they can verify the claim.
A typical message says that a T-Mobile Rewards account holds 18,400 points, gives an imminent expiry date, and states that unused points will be removed under the program’s terms. These details make the message look as though it was written specifically for the recipient, even though it was sent to many people.
“T-Mobile Rewards Points Reminder: Your Points Are About to Expire
Dear Customer,
We are hereby reminding you that your T-Mobile Rewards account points are about to expire. You currently have 18,400 points, which will expire on June 4, 2026, if unused.
Your Points Overview:
Current Balance: 18,400 Points
Expiry Date: {today or tomorrow}
Points will not be recovered after this date.
Redeem Points:
Visit:
https://t-mobile.{rotating domains}.top/pay
Use the T-Mobile App: Account > Rewards & Benefits
Our points expiry policy aims to ensure the fairness of the program and encourage active participation. Please don’t let these valuable points go to waste.
Thank you for choosing T-Mobile.
Customer Service Team”
This phishing operation does not rely on a single, identical SMS. We found more than 1,000 closely related campaign templates with a semantic similarity score of at least 0.60. The 199 closest matches all scored at least 0.95.
This means the variations only change superficial elements, such as the salutation, headline, expiry date, point balance, and whether the message is called a “reminder,” “alert,” or “important update.” The central story remains the same: T-Mobile rewards points are supposedly expiring, and the recipient must follow a link to redeem them as soon as possible.
The messages use formal but generic language, such as “Dear T-Mobile Customer,” “Dear Valued Customer,” or “T-Mobile User,” rather than naming the recipient or providing verifiable account information.
Detection events for the T-Mobile rewards phishing campaignThe campaign began slowly before producing two huge spikes in activity. The green line shows detections of message variants seen previously, while the red line shows messages detected on the first day that particular variant appeared. We’re still seeing messages from the campaign, although activity has fallen considerably since those spikes.
The scam relies on a familiar social engineering formula: a valuable-looking reward, a deadline, and a simple action that supposedly protects the customer from losing out. A recipient who has a T-Mobile account may click first and question the message later.
The links use rotating domains designed to look as though they belong to T-Mobile. Their purpose is to persuade recipients to follow the link to supposedly redeem their points. Do not enter login credentials, personal information, payment details, or verification codes after following a link in an unsolicited message.
How to stay safeThe anonymized data used in this analysis was gathered through Text Protection in Malwarebytes Mobile Security, which alerts users to potentially malicious or scam text messages.
You can also reduce your risk by following these tips:
- Don’t follow links in unsolicited messages. Instead, open the alleged sender’s website or app independently and check for notifications there.
- Check the domain in your browser’s address bar to make sure it matches the site you expected to visit.
- Use an up-to-date, real-time anti-malware solution with web protection.
- Malwarebytes Scam Guard can help you determine whether a message is a scam and advise you on what to do next.
The URLs in this campaign are very short-lived. The criminals used at least 81 domains over four months, but the domains follow a recognizable pattern that is blocked in Malwarebytes Browser Guard.
IOCsExample domains showing the pattern used by the campaign:
t-mobile.biktpw[.]top
t-mobile.cugbjl[.]top
t-mobile.cymfjd[.]top
t-mobile.gdikxv[.]top
t-mobile.hdzcnb[.]top
t-mobile.koxetp[.]top
t-mobile.nxdcfp[.]top
t-mobile.pkrbai[.]top
t-mobile.qfrhkt[.]top
t-mobile.qscizj[.]top
t-mobile.tmfncb[.]top
t-mobile.vmnqsu[.]top
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
Google Pixel owners urged to patch actively exploited modem flaw
Google has released its September 2026 Pixel Update Bulletin, fixing 110 vulnerabilities, including one that it says “may be under limited, targeted exploitation.”
The bug is not described as a simple remote takeover, but as a vulnerability that could give an attacker who already has a foothold on a phone more power than they should have.
Although Pixel devices also run Android, they receive separate security updates and bug fixes from the standard monthly patches distributed to Android manufacturers because of the unique hardware platform Google controls directly and its exclusive features and capabilities.
To apply this month’s security updates, Pixel users should go to Settings > Security & privacy > System & updates > Security update, tap Install, and restart their device to complete the update process.
A supported device with the 2026-09-05 patch level is up to date. After updating, check that the Android security update level shows September 5, 2026, or later.
Technical detailsGoogle says it there are indications that the vulnerability, tracked as CVE-2026-58704, may be under limited, targeted exploitation. Found in the cellular modem, it is a possible permission bypass caused by a logic error in the code. This could lead to remote escalation of privilege (EoP) with no additional execution privileges or user interaction needed.
The vulnerability affects the modem component of Pixel devices and is rated high severity. The modem is the part of a smartphone that handles communication with mobile networks. It allows a phone to connect for calls, texts, and mobile data. Because it is such an important component, a flaw affecting it deserves attention, even if the conditions needed to exploit it limit the number of potential victims.
The vulnerability does not mean every unpatched Pixel can be hacked from anywhere on the internet, nor has Google said that simply being within wireless range of a phone is enough. The available information indicates that an attacker needs access to an adjacent network and basic privileges on the targeted device, but it does not explain how those privileges are obtained.
Attackers commonly need more than one step to compromise a well-protected device. One weakness may give them a limited foothold, while another lets them escape restrictions and gain access to more sensitive functions or data.
This is why bugs like this can be especially useful in targeted operations. An attacker may combine the modem vulnerability with another exploit, a malicious app, stolen credentials, or physical access to the device. Each part of the chain brings the attacker one step closer to compromising the device: getting in, gaining more privileges, and accessing the information or functions they’re after.
While Android users should always install the latest update offered by their device manufacturer, this particular zero-day appears in the Pixel-specific bulletin. Google’s Pixel phones use hardware and software components that other Android manufacturers do not necessarily share, including the affected modem component. If you have another Android brand, you won’t receive this specific Pixel fix, but you should still check for your manufacturer’s latest monthly security update.
Scammers know more about you than you think.
Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in.
AI helps scammers build convincing antivirus renewal pages
Antivirus renewal scams often begin with a message claiming that your subscription has automatically renewed. When you follow the instructions to cancel it, you are taken to a fake page designed to collect your contact details. The renewal charge never existed.
Receiving a message that names the antivirus software you use does not necessarily mean the sender has access to your device or account. Scammers impersonate popular brands and send the same message to large numbers of people, knowing that some recipients will be customers.
As we’ve reported before, simply responding to a scam message can make your contact details more valuable because it confirms that your number is active and that you are willing to engage. Filling in this form gives scammers even more: your name, email address, phone number, and an indication that you may respond to a call about a supposed antivirus payment.
Those details can be sold to other scammers or used for the next stage of the scam: a phone call from someone who tries to persuade you to install remote access software or help them reverse a payment that never happened.
A closer look at a fake Avast siteDuring our scam-hunting activity, we saw one renewal scam site impersonating Avast, aimed at users in Belgium. It was noticeably more polished than most scam sites and contained several signs that it had been produced with the help of AI.
The page tells you that your Avast Premium Security subscription has renewed for €129.99, that it covers five devices, and that it will renew again the following February. There is a green tick, a status badge reading Active, and a tidy summary table laying out the amount, the payment method, and the dates.
None of it is real. There is no subscription and no charge, and the page has no connection to Avast, whose branding is being used without permission.
The page is written in French for a Belgian audience. The screenshots below have been machine-translated into English so the layout and wording are easier for you to follow.
Alongside the renewal summary is the part the scammers actually care about. A cancellation form asks for your full name, email address, and Belgian mobile number, but nothing else.
There is no password field or request for card details, which may be deliberate. A form asking only for a name, email address, and phone number can feel harmless and is far easier to fill in than a login page. A working mobile number attached to a real name is exactly what a scammer needs for the next stage: calling the victim and posing as support staff. The form is the lure, and the call is where the real danger begins.
The signs of AI involvementThe page was left with two notes in its code that were never meant for victims. Both were written in polite French and addressed to whoever had commissioned the work, explaining that the form did not yet send anything anywhere and that a real submission process would need to be connected later.
They read like a contractor handing over an unfinished job rather than a scammer leaving themselves a reminder, and that courteous, second-person summary of what still needs doing is very much how an AI assistant signs off.
Other clues are also consistent with AI-generated code. The code contained unused styling for a section that had been removed, suggesting that the page had been created in stages without a final review. The copy was grammatically correct but vague. It described the benefits of the subscription across four paragraphs without mentioning any specific Avast features, such as its firewall, VPN, or ransomware protection.
Taken together, these signs suggest that the page was built with the help of AI. Generated code carries no watermark, so that cannot be proven from the files alone.
The page was never finishedAs the comments in the code explain, the form on this page sent nothing at all. Someone built a convincing fake, got the difficult parts right, and then stopped before connecting the piece that actually sends the data anywhere.
Other signs in the code suggest nobody had even opened the page in a browser to check it, since two pieces of text would have displayed as visible gibberish if they had. What we were looking at was most likely half-built, or possibly a template waiting to be sold on to someone who would add a destination for the stolen details.
Building a page like this used to take a certain amount of skill, which limited how many of them could be made. AI has lowered that barrier. Whoever made this could ask for a version in Dutch or German, or one aimed at an entirely different brand, and have it within minutes.
How to spot an antivirus renewal scamThe old advice was to look for mistakes: bad grammar, the wrong currency, a clumsy layout, or a stretched logo. That advice is less useful now because AI can produce fluent copy and polished layouts, while scammers can easily copy real logos. A page that looks professional is no longer evidence that it is genuine.
But the structure of the scam hasn’t changed. It still needs you to arrive somewhere unexpected, worry about losing money, and provide a way to contact you. Judge the situation rather than the appearance of the page.
- Check whether you were charged. If the message says a payment has already been taken, check your bank or card statement directly. If the payment is not there, there is nothing to cancel.
- Check the subscription through the official app or website. Don’t click the link in the message. Open the company’s app or website independently and sign in. Your account will show whether you have an active subscription and when your next payment is due.
- Be wary of a cancellation form that mainly wants your phone number. Legitimate cancellations usually happen inside your account, and a company you already pay knows how to reach you.
- Treat the follow-up call as the real danger. If you have filled in a form like this, you may receive a scam call next. You are under no obligation to answer or engage.
- Don’t install remote access software for someone who called you. It gives them control of your device and could put your accounts, passwords, and money at risk.
If you have already been on a call and installed something, disconnect the device from the internet, remove the software they asked you to install, and change your passwords from a different device. If you sent money or shared card details, contact your bank straight away.
Block and check suspected scamsThe best protection is to stop scam pages before they open. Malwarebytes Browser Guard is a free extension for Chrome, Edge, Firefox, and Safari that blocks malicious websites, phishing attempts, and scam ads before they can do any harm.
Not sure whether something is a scam? Share a screenshot, message, phone number, or link with Scam Guard. It checks it in seconds and recommends what to do next. Scam Guard is built into Malwarebytes Premium Security for Windows, Mac, iOS, and Android.
If you received a call after filling in a form like this, enter the number into Malwarebytes Scam Number Check to see whether it has been linked to scam activity.
“One of the best cybersecurity suites on the planet.”According to CNET. Read their review →
How to opt out of AI chatbot training
The tech journalists at 404 Media learned that OpenAI is hiring hundreds of contractors to read and review a massive stream of real users’ ChatGPT prompts and responses.
“Project Lily” is reportedly a program that asks contractors to score or critique ChatGPT’s answers to improve the chatbot’s quality and behavior.
The fact that prompts may sometimes be reviewed by humans should not come as a complete surprise. AI companies also monitor conversations for safety reasons. Anthropic, for example, says it has disrupted attempts to misuse AI for biological weapons research.
But there should be a meaningful distinction between reviewing conversations for safety or abuse and reviewing them for ordinary model improvement.
OpenAI says a limited number of authorized personnel and trusted service providers may access chats for several reasons, including investigating abuse, providing support, handling legal matters, and improving its models.
OpenAI told 404 Media that it uses a “Privacy Filter” model to remove personal information before prompts reach reviewers, while acknowledging that sensitive details can still get through.
The prompts are anonymized in the sense that reviewers do not see the username of the ChatGPT user who entered them. But reviewers may see personal details in the conversation alongside a “user memories summary,” which provides an overview of how that user has previously used the chatbot. Together, this information could still reveal a great deal about that user.
It’s sometimes easy to forget that you’re not having a private conversation when you’re going back and forth with an AI chatbot. This isn’t an alarmist warning against using AI, but a reminder to be mindful of what you disclose because it could be read and reviewed.
How to opt out of AI chatbot training ChatGPTOpenAI told 404 Media that users’ chats won’t be used to improve the company’s models if they turn off the “Improve the model for everyone” setting. This is turned on by default for Free, Plus, and Pro plans, so users need to turn it off themselves if they wish to opt out.
However, opting out does not prevent all human access. OpenAI says authorized personnel and trusted service providers may still access content when necessary to investigate abuse or security incidents, provide support, troubleshoot problems, or handle legal matters.
In ChatGPT, select your profile icon, then go to Settings > Data Controls and turn off Improve the model for everyone. On mobile, open the sidebar, select your profile icon, and then follow the same steps.
PerplexityIn Perplexity, go to Settings > Preferences > AI data retention and turn off the setting.
Perplexity says this prevents data collected after you opt out from being used to train AI models. It does not remove data collected previously, and your data may still be processed to operate and improve the service or comply with legal obligations.
ClaudeIn Claude, select your name and go to Settings > Privacy. Under Help Improve our AI Models, turn off the setting.
Anthropic says new chats and coding sessions will no longer be used for future model training. It will also stop using previously stored conversations in future training runs, although data already included in training can’t be removed.
Anthropic also notes one important exception:
If our safety classifiers flag your conversations, they may still be used to improve our internal trust and safety models, detect harmful content, enforce our policies, or advance our safety research.
If you use other AI tools, check their privacy policies and settings to find out whether your conversations can be reviewed or used for model improvement and whether you can opt out.
Browse like no one’s watching.
Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free →
HBO Max’s verified Reddit account hijacked to spread malware
Researchers at Hudson Rock found that cybercriminals hijacked HBO Max’s verified Reddit account and used it to run 108 malicious ads over roughly 48 hours.
The ads used HBO Max’s trusted corporate account to promote fake AI tools, developer software, and macOS utilities, lowering potential victims’ guards.
Some ads directed users to convincing HBO lookalike sites that claimed to offer a native HBO Max app for macOS or a promotional download. But instead of providing an installer, the sites instructed visitors to open Terminal on their Mac or, on Windows, the Run dialog or PowerShell, and paste in a command.
This is the hallmark of a growing social engineering technique known as ClickFix.
ClickFix attacks disguise malicious instructions as a routine technical step, such as fixing an error, completing a CAPTCHA, verifying that you are human, or installing software. A web page may silently copy a command to the clipboard, then guide the victim through pasting and running it, by which they will infect their own device.
Researchers at ADAMnetworks have dubbed the operation behind the HBO Max ads “PasteSwitch.” Its infrastructure appears to tailor the next stage to the visitor’s device and the lure being used.
Observed macOS payloads included MacSync and AMOS infostealers designed to steal browser credentials and profiles, Telegram data, Apple Notes, saved passwords, and cryptocurrency wallet recovery phrases.
Windows users could end up with the Amatera infostealer, which runs in memory. The operation has also been linked to cryptocurrency clipboard hijackers, which monitor copied wallet addresses and replace them with an attacker-controlled address before a transaction is sent.
How to stay safeReddit admins paused the ads and opened a security investigation after reports came in, but it is important to remain vigilant. Reportedly, ClickFix was responsible for more than half of all malware loader activity in 2025.
One reason for its success is that campaigns continue to add new methods for tricking users and different commands for avoiding detection.
Users of macOS Tahoe 26.4 or later may be warned when pasting text into Terminal, but it doesn’t appear for everyone, so you shouldn’t rely on that alone.
Malwarebytes can provide additional protection at several stages of a ClickFix attack. Browser Guard warns when a website tries to copy something to your clipboard, web protection blocks known malicious sites, and real-time protection can detect malware delivered by the campaign.
With ClickFix running rampant and inventing new methods all the time, it’s important to be aware, careful, and protected:
- Treat ads with caution. A verified account does not guarantee that an ad is safe. Visit the company’s official website directly instead of downloading software through an advertisement.
- Slow down. Don’t rush to follow instructions on a webpage or prompt, especially if it asks you to run commands on your device or copy-paste code. Attackers may use countdowns, user counters, or other pressure tactics to make you act quickly.
- Don’t run commands from untrusted sources. Never run code or commands copied from websites, emails, ads, or messages unless you trust the source and understand what the command does. Check the instructions against official documentation or contact the company’s support team.
- Secure your devices. Use an up-to-date, real-time anti-malware solution with a web protection component. Malwarebytes blocks ember-bridge.com, which is part of the PasteSwitch infrastructure.
- Educate yourself on evolving attack techniques. Understanding that attacks may come from unexpected vectors and evolve helps maintain vigilance. Keep reading our blog!
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
Meta AI builds detailed profiles of children from years of family posts
If you’re still OK with posting pictures of your kids on social media, take a minute to hear from mother of two Kalie Robins. At the start of September, she did something that hundreds of thousands of parents do every day. She posted a video of her young daughter on Facebook.
Under the video of Robins and her daughter singing in a car, Facebook’s Meta AI system displayed a suggested question: “Who is the child passenger?”
Robins was shocked that Facebook would ask this question about a minor, so curiosity prompted her to click it. That’s when a flood of automated stalker-type behavior began.
In Instagram post, an enraged Robins described what happened:
“It starts pulling completely separate information for each of my kids.”
That included names, birth dates, and videos of them.
The site also pulled up a picture of her newborn daughter that Robins’ mother had posted on Facebook years ago, along with a long-deleted picture that Robins said had once been in her own account.
Things got weirder. The site then presented another question: “Where does Kalie Robins live?”
An increasingly outraged Robins clicked that question. She described the results:
“[Facebook] started digging through completely unrelated sh*t from years of my life.”
It dug through old posts that hinted at where she had lived in the past and newer posts that connected her to her current home. It finished by attempting to pinpoint her location.
Robins complained:
“I didn’t ask Facebook to build a profile of my family.”
She expressed shock that Facebook would piece together snippets of personal information from historical posts and package them into a detailed profile for other users.
You can watch Kalie Robins’ Instagram video here:
.kadence-column465357_a378ee-2f > .kt-inside-inner-col{display:flex;}.kadence-column465357_a378ee-2f{max-width:558px;margin-left:auto;margin-right:auto;}.wp-block-kadence-column.kb-section-dir-horizontal:not(.kb-section-md-dir-vertical)>.kt-inside-inner-col>.kadence-column465357_a378ee-2f{-webkit-flex:0 1 558px;flex:0 1 558px;max-width:unset;margin-left:unset;margin-right:unset;}.kadence-column465357_a378ee-2f > .kt-inside-inner-col,.kadence-column465357_a378ee-2f > .kt-inside-inner-col:before{border-top-left-radius:0px;border-top-right-radius:0px;border-bottom-right-radius:0px;border-bottom-left-radius:0px;}.kadence-column465357_a378ee-2f > .kt-inside-inner-col{column-gap:var(--global-kb-gap-sm, 1rem);}.kadence-column465357_a378ee-2f > .kt-inside-inner-col{flex-direction:column;align-items:center;}.kadence-column465357_a378ee-2f > .kt-inside-inner-col > .kb-image-is-ratio-size{align-self:stretch;}.kadence-column465357_a378ee-2f > .kt-inside-inner-col > .wp-block-kadence-advancedgallery{align-self:stretch;}.kadence-column465357_a378ee-2f > .kt-inside-inner-col > .aligncenter{width:100%;}.kadence-column465357_a378ee-2f > .kt-inside-inner-col:before{opacity:0.3;}.kadence-column465357_a378ee-2f{position:relative;}@media all and (min-width: 1025px){.wp-block-kadence-column.kb-section-dir-horizontal>.kt-inside-inner-col>.kadence-column465357_a378ee-2f{-webkit-flex:0 1 558px;flex:0 1 558px;max-width:unset;margin-left:unset;margin-right:unset;}}@media all and (max-width: 1024px){.kadence-column465357_a378ee-2f > .kt-inside-inner-col{flex-direction:column;justify-content:center;align-items:center;}}@media all and (max-width: 767px){.wp-block-kadence-column.kb-section-sm-dir-vertical:not(.kb-section-sm-dir-horizontal):not(.kb-section-sm-dir-specificity)>.kt-inside-inner-col>.kadence-column465357_a378ee-2f{max-width:558px;-webkit-flex:1;flex:1;margin-left:auto;margin-right:auto;}.kadence-column465357_a378ee-2f > .kt-inside-inner-col{flex-direction:column;justify-content:center;align-items:center;}} View this post on InstagramA post shared by Kalie | Travel Mom Creator (@kontheinside)
Meta’s responseMeta launched Meta AI in April 2024 and has since built it into Facebook, Instagram, WhatsApp, and Messenger. It operates across Facebook, Instagram, and WhatsApp. The assistant can answer questions, generate images, and help users create or retrieve information.
Meta admitted in a statement to the Verge:
“The feature never should have prompted the individual with questions like that.”
The company said the feature had “missed the mark” and that it had fixed the issue that caused Meta AI to suggest questions about personal topics.
In a classic “yes, but” non-apology, a Meta spokesperson also pointed out that the AI only surfaced information drawn from posts the person asking could already access. Although that doesn’t seem to explain why it reportedly surfaced a photo she had deleted years ago.
A pattern of Meta AI failuresMeta AI hasn’t always respected privacy. In June last year, we reported that users were publicly sharing conversations, often without realizing it. A separate bug we reported the following month could have allowed people to view other users’ private Meta AI chats by simply guessing their IDs. Late last year, Meta also started targeting people with ads based on their Meta AI conversations.
What can users do?Parents get understandably irate when they discover just how much sites like Facebook can learn about their kids. While Robins regularly posted pictures and videos of her children, she had no idea that the service could aggregate information from years of posts to profile them. She’s not alone.
So what can people do about it? Perhaps the better question is: What should people not do? The clearest answer is not to post identifiable pictures of your kids (or other people’s) on social media. Not just to stop them being tracked in a privacy hellscape, but also to reduce the risk of even darker outcomes.
Robins described what she planned to do next:
“I’m done. I’m removing any identifiable pictures and videos of our kids.”
She added that she’ll ask her friends to do the same because, if they don’t, Facebook would still be able to harvest her children’s pictures from their accounts and use them in the profiles it builds.
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
Search results are sending people to fake Bitrefill checkouts
Bitrefill is a legitimate company that sells gift cards for popular stores like Amazon, Deliveroo, Apple, Nintendo, and thousands of others. They also sell eSIMs, and mobile top-ups. You can pay on their website for all of these with cryptocurrency.
The scam is designed to catch people searching for Bitrefill or something it sells, like a gift card. Victims see a search result that appears to lead to Bitrefill but actually points to a lookalike domain. The fake site then takes them through what appears to be a normal purchase. The fake sites are not operated by or affiliated with Bitrefill; scammers have copied its branding and checkout process.
The victim chooses an amount and a cryptocurrency before receiving a QR code and payment address. But instead of paying Bitrefill, they send the cryptocurrency directly to an address controlled by the scammers. They receive nothing in return, and recovering the payment is extremely unlikely.
Why fake crypto checkouts work so wellPhishing typically involves several steps. First, an attacker has to steal a password. Then, they may have to get past two-factor authentication (2FA), log in to the account without tripping a fraud check, and find some way to turn account access into money. Plenty of scams fall apart somewhere in that chain.
This payment scam avoids those hurdles by persuading victims to send money directly to the scammers. There is no account to break into and no stolen card to use. The victim sends cryptocurrency straight to an address the scammers control, and cryptocurrency payments generally cannot be reversed or charged back.
The payment request also fits the situation. A demand for cryptocurrency might look suspicious on many websites, but Bitrefill genuinely accepts it. On a convincing copy of its checkout, paying with cryptocurrency appears completely normal.
All this may explain why we found a cluster of fake sites rather than a single page, with checkouts allowing payments of up to $1,990.
What the fake checkout looks likeThe site we examined is a close copy of Bitrefill’s checkout, hosted on a domain built by bolting a word onto the brand name. Everything a customer would expect is present. The branding is right, the layout matches, the page is quick and polished, and the payment flow behaves exactly the way the real one does.
The fake checkout asks for an email address and links to terms of service and a privacy policy, helping it look legitimate.You’re asked for an email address for order updates, with links to terms of service and a privacy policy. You then choose how to pay, from a list offering Bitcoin, Ethereum, USDC, USDT, Solana, and Litecoin. The site also offers card payments for a small surcharge.
The fake checkout offers several cryptocurrencies and appears to support card payments.Next, you pick an amount, with preset buttons and a maximum of $1,990, although inconsistent currency symbols offer a small clue that something is wrong.
The fake checkout accepts payments of up to $1,990.Finally, you reach a payment screen showing a QR code, an address marked for one-time use, the amount converted into your chosen cryptocurrency, and a countdown clock giving you just under an hour to send the funds.
The final screen provides a cryptocurrency address and QR code, along with a countdown timer .None of those elements is a red flag on its own. Unique addresses, expiry timers, and currency conversion are all normal for crypto checkouts, which is exactly why the copy is convincing. Every pressure cue on the page is borrowed from legitimate payment systems.
The only meaningful difference is the address the money goes to, and by the time the victim sends the cryptocurrency, getting it back is extremely unlikely.
How people are reaching these pagesThe distribution here does not appear to rely on email. Bitrefill has said publicly that sites copying its checkout and using similar names have been turning up in search engine results, and that its security team has been working with takedown specialists to have them removed.
The site’s configuration supports that. The fake checkout hands visitors back to a second domain in the same family, and the link it uses carries a parameter naming a search engine, suggesting the operators are tagging incoming traffic by where it came from.
There’s a detail here that deserves more attention than it usually gets. The fake checkout has commercial analytics software installed on it, the same kind of product a legitimate e-commerce team uses to measure how many visitors abandon a cart. Its presence suggests the operators want to measure and improve the number of visitors who complete a payment.
These campaigns are not opportunistic one-offs thrown together by someone hoping for a lucky hit. They’re run as businesses, measured and tuned like any other funnel, with the victim in the role of the customer.
A brand name is not a destinationThe domains in this cluster use several tricks to make their addresses look convincing. Some swap one letter for a visually similar character, making the brand appear correct unless you look closely. Others add a plausible word such as pay or gift, producing addresses that resemble official payment sites. Some do both.
Several use internationalized domain names, which can contain characters from different alphabets or accented versions of Latin letters. Browsers translate these domains into an ASCII format beginning with xn--, known as Punycode. To the eye, the displayed versions can be almost indistinguishable from the genuine name.
Different domain names display as variations of “Bitrefill,” while their Punycode versions begin with xn--.The answer is not simply to become better at spotting tiny differences. These domains are designed to defeat visual inspection, and they can be especially difficult to recognize on a phone screen. Recognizing a company name somewhere in a web address does not tell you who owns it.
Remember, seeing the right company name in a URL is not enough. Check that the actual domain is exactly the one the company uses.
What to do- Start at the website you already trust. Use a saved bookmark or carefully enter bitrefill.com yourself. If you are already making a purchase on the legitimate site, stay within that session instead of opening a checkout page from a separate search.
- Treat search results for payment and checkout pages with suspicion. Scammers can buy search ads or manipulate their sites into appearing prominently. The first result is not necessarily the safest one.
- Check the address bar before you send. Cryptocurrency payments generally cannot be reversed or charged back. Confirm that the main domain is exactly bitrefill.com before approving a payment.
- Be wary of domains containing a brand followed by an extra word. A legitimate subdomain would place the additional wording before the company’s main domain, as in pay.example.com. An address such as example-pay.com is a completely separate domain that anyone could register.
- Don’t approve wallet requests on a site you have not verified. Simply connecting a wallet does not normally transfer funds, but a fraudulent site may ask you to sign a transaction or grant token permissions that allow assets to be stolen.
- If you have already sent funds, act quickly, although recovery is unlikely. Report the destination address to the exchange or wallet provider you used, report the incident to your national fraud reporting service, and notify Bitrefill so it can add the domain to its takedown efforts. Recovery services that promise to retrieve stolen cryptocurrency for an upfront fee are often follow-up scams.
The simplest protection against a page like this is to avoid reaching it. Malwarebytes Browser Guard is a free browser extension that blocks known scam and phishing sites, along with malicious ads and search results that lead to them.
Got a screenshot or URL of a suspected scam? Upload it to Scam Guard—built into Malwarebytes Premium Security on Windows, Mac, iOS, and Android—and you’ll get a verdict and safety tips in seconds.
Indicators of compromise (IOCs)Domains:
biterflll[.]com
bitigift[.]com
bitrefall[.]com
bitrefill-payments[.]com
bitrefill-pays[.]com
bitregift[.]com
bitregill[.]com
bitretill[.]com
bitrgift[.]com
bitrgifts[.]com
bitrnfill[.]com
bitruflli[.]com
butrefill[.]com
pay-bitregill[.]com
pay-bitrgift[.]com
pay-bitrgifts[.]com
pay-butrefill[.]com
pay-bitigift[.]com
xn--bitrefll-71a[.]com
xn--bitrefll-h2a[.]com
xn--bitrefll-pay-kfb[.]com
xn--bitrefll-pay-xfb[.]com
xn--bitrefll-q2a[.]com
xn--bitreill-cz9c[.]com
xn--bitreill-pay-yq4f[.]com
xn--btrefill-l2a[.]com
xn--pay-bitrefll-fgb[.]com
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
Google’s new search redirects make links harder to check before you click
Google is changing how some links in its search results work.
Instead of linking directly to the destination, Google has started routing some search result links through opaque google.com/goto?url=... redirects. The url parameter does not show a readable version of the destination but uses a custom, Google-specific encoding.
Google confirmed the rollout to Search Engine Roundtable:
“We have a long history of deploying technical measures against evolving forms of abuse, and we regularly take steps to protect our services and users.”
Google has not said precisely what abuse the change is intended to prevent. However, the most likely reason is that the redirects are designed to make bulk extraction of destination URLs from Google search results more difficult and costly. Automated tools must now ask Google to resolve each result separately.
Since the rollout has apparently not reached my neck of the woods yet, I had to grab an image from another source.
Image courtesy of seroundtable.comSome Reddit users find the change ironic: Google built its search business by automatically collecting information from other websites, but is now making it harder for others to collect information from Google.
Other users have complained about the collateral damage to legitimate tools. Rank tracking, SEO auditing, research, archival, accessibility, and alternate-index services may all face the same rate limits and costs as abusive scrapers.
Search results data provider Autom reports that the final destination is viewable only through the redirect response’s Location header. This means bulk collectors must make an additional request for every result.
SecurityThe first thing that popped into my one-track mind was the security downside. We often tell users to hover over a link before clicking it so they can check where it leads. That advice is less useful when hovering reveals an encoded Google redirect rather than the destination website.
Google still displays the claimed destination above each search result, but users can no longer use the link preview as an independent check.
So, Google, where does this leave our advice? We already tell people not to click Sponsored search results. Should we now tell them to avoid goto?url links too? Or will you give users an easy way to check where a link leads before they click it?
Safer. Cleaner. Ad-free browsing.Revolut gave customer IDs and financial data to a government impostor
Revolut has acknowledged that it disclosed sensitive customer records to an unauthorized party. The company had accepted fraudulent information requests sent from an email address on a legitimate government agency domain, according to TechCrunch.
Revolut is a London-based banking and financial platform with more than 80 million customers globally, according to the company.
Revolut describes this as an external impersonation scam, not an intrusion into its systems. It also says customer funds were not affected. Revolut has not identified the government agency or disclosed its email domain.
The attacker appears to have abused the trust attached to a real government email domain to make bogus requests for customer information. Revolut detected the activity, blocked the sending address, and says it notified the relevant agency, law enforcement, data protection authorities, and financial regulators.
“Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators.”
Through this social engineering attack, rather than by gaining access to Revolut’s systems, the criminals obtained the following types of information about customers:
- Identity and contact information like dates of birth, postal address, email address, and phone number.
- Copies of IDs such as passports and driver’s licenses.
- Verification selfies.
- Account statements and transaction histories.
Revolut has said only that a “limited” or “very limited” number of customers were affected, and that it contacted them directly.
Those customers have received or will receive an email specifying which of their personal data was disclosed:
How to stay safeThe likely consumer impact will be second-stage fraud attempts rather than immediate unauthorized transfers. Here are some guidelines to help keep your money safe:
Treat any unexpected Revolut-related contact as suspicious, especially calls, emails, WhatsApp messages, or text messages claiming you need to “secure” an account, reverse a transfer, or replace documents. Do not use links or phone numbers supplied in the message. Revolut advises ending contact with suspected scammers and contacting the company through official channels.
IDs and other exposed information could be used for identity theft. Monitor your accounts and credit reports for unfamiliar account openings or credit applications, and consider placing a fraud alert or using credit monitoring where available in your country.
If you received a notification email, check your balances, cards, beneficiaries, recent transfers, account statements, and linked devices. Report any unfamiliar activity immediately through Revolut’s secure in-app chat.
If you were involved in a data breach, read our blog Involved in a data breach? Here’s what you need to know for more recommendations.
Pro tip: Use Malwarebytes Scam Guard to analyze any suspicious communications. It can help you determine whether a message is a scam and advise you on what to do next.
Let’s face it, an incognito window can only do so much.
Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance.
A week in security (September 7 – September 13)
Last week on Malwarebytes Labs:
- Crypto customers targeted by scammers after email marketing provider breach
- Android malware creates a hidden copy of your banking app
- BlueMoon exploit kit turns Chrome and Windows flaws into attacks
- Will AI kill us all within the next decade?
- Update Chrome now to protect against an actively exploited vulnerability
- Copyright scammers get Instagram accounts suspended and demand payment
- More than 100,000 fake stores are out to steal your card details
- Microsoft fixes record 964 flaws, including 2 exploited zero-days
- The push to stop algorithms controlling social media feeds has begun
- Grindr settles HIV status data-sharing lawsuit for $35 million
- MikroTik router flaws allow takeover without a password
- Loyalty points fraud is funding hacker holidays (Lock and Code S07E18)
- LG TV flaws could let attackers listen in, even in standby mode
- Flirty OnlyFans promoters on X may be using AI to appear human
Stay safe!
What do cybercriminals know about you?
Use Malwarebytes’ free Digital Footprint scan to see whether your personal information has been exposed online.
Crypto customers targeted by scammers after email marketing provider breach
An attacker breached an email marketing platform and launched targeted attacks against the newsletter subscribers of some of its customers, especially those working in cryptocurrency and adjacent fields.
The incident was a supply-chain phishing campaign carried out through Brevo, an email marketing provider used by several cryptocurrency companies and other firms.
Brevo initially said an attacker had gained access to 120 customer accounts, some of which were used to send phishing emails to the customers’ contact lists.
Brevo later said 138 customer accounts had been accessed in its postmortem:
“On September 10th at 6:30 AM UTC we identified a security issue where an attacker exploited a flaw in the way Brevo handles SAML SSO to gain access to 138 Brevo accounts. 6 of those accounts were used to send phishing emails to the contacts stored there, and for 43 accounts they exported the contacts. 93 accounts have no meaningful activity.”
According to reports, popular cryptocurrency companies Trezor, CoinTracking, and BitBox confirmed that phishing emails were sent to customers subscribed to their newsletters. Trezor warned its roughly 347,000 newsletter subscribers that a security incident at a third-party provider had resulted in a massive phishing campaign.
Trezor makes hardware wallets that store cryptocurrency private keys offline. Its customers received a phishing email titled “Critical Security Alert: STM32 Entropy Bug Identified.”
The subtitle read: “Urgent update regarding hardware microcontroller vulnerability.”
The email said:
“Dear customer,
We have some difficult news to share. Unfortunately, our engineering team has identified a critical hardware-level vulnerability in the STM32 microcontrollers used in a range of Trezor devices.
Currently we believe the majority of defective devices were initialized prior to 2023, however some newer devices also may be vulnerable. The bug is a hardware factory defect present in an estimated 1 in 4 devices.
The vulnerability results in:
- Insufficient randomness in recovery phrase generation
- Exposure of seeds to brute-force cracking
- Seeds with as little as 40 bits of entropy”
That phishing email also contained a link that prompted recipients to download an app and enter their wallet backup.
CoinTracking said the attackers sent its customers an email titled “Data Breach Notice: Please refresh API Keys as soon as possible,” which also contained a malicious link.
Because the emails came from legitimate company domains and looked convincing, some recipients may have fallen for them. The exact number is not currently known.
How to stay safeIt can be difficult to recognize a phishing email when it comes from a legitimate company domain and looks convincing. But there are a few things to keep in mind:
- If a company emails you about an urgent security problem, check its official website or app for confirmation.
- Do not install apps through links in unsolicited emails, no matter how urgent the message claims to be.
- Never enter your recovery phrase anywhere other than on your physical device.
- Reputable companies will not ask for recovery phrases, API keys, or login details by email.
- Use Malwarebytes Scam Guard to check whether a message might be a scam and get guidance on what to do next.
- Keep an eye out for further information about other Brevo customers that have been affected. The attackers exported contacts from 43 accounts, which could be used in future targeted phishing attacks.
Trezor advises moving your funds to a new wallet if you entered your wallet backup in any form. If you followed a link in a similar email from another provider, contact that company directly for advice.
Something feel off? Check it before you click.Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.
Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
Android malware creates a hidden copy of your banking app
Researchers at Group-IB found that the Android banking Trojan Gigabud can create a separate work profile on an infected phone and run a cloned banking app inside it. The attacker can then carry out fraudulent transactions in the new profile, potentially separating them from signs of malware detected elsewhere on the device.
To do this, Gigabud installs Vwork, a malicious version of the legitimate open-source tool Shelter. Shelter normally lets Android users isolate apps or run second copies of them in a work profile. Vwork modifies those functions so that Gigabud can control them remotely.
The aim is to clone a target banking app into the new work profile, then let the operator commit fraud there. Group-IB says this can break the connection between malware detected in the personal profile and a risky transaction originating from the work profile, potentially weakening bank-side anti-fraud or in-app malware-detection systems that do not correlate activity across Android profiles.
Android work profiles are normally used to keep work apps and data separate from personal ones. Because apps in different profiles are isolated from each other, a banking app or security tool may not connect malware detected in the personal profile with something taking place in a cloned app in the work profile.
How an attack worksVictims are lured into sideloading a fake airline, tax, or government app through phishing sites, messages, or social media.
To take over the device, Gigabud asks for Accessibility access, overlay permission to display over other apps, and an exemption from battery-optimization. These permissions enable remote interaction and credential-theft techniques such as overlays.
The sideloaded app checks which other apps are installed and tells the operator which relevant banking targets are present.
Fake banking-login overlays steal both banking credentials and the device’s PIN.
The operator installs Vwork, which creates a new work profile on the device and clones the selected banking app. Vwork differs from Shelter in ways that make it useful to malware. It removes protections on cross-profile interaction, exposes components that can be used to set up a profile, clone and list apps, and open apps, and hides its launcher icon.
The operator can then remotely carry out transactions from the newly created profile, with the option to hide activity behind a black screen.
This is how Gigabud turns Android’s profile separation into a fraud tool: after compromising a phone, it creates a second profile, places a cloned banking app inside it, and performs the transaction from there. The result can be a dangerous gap between a malware alert in one profile and a fraudulent banking session in another.
How to stay safeThe immediate protection advice is familiar but important:
Sideloading. Install banking and other apps only from the official store or a direct link to the publisher’s website.
Install requests. Treat unsolicited requests to install an APK as a likely scam. If you’re unsure whether something’s a scam, run it through Malwarebytes Scam Guard.
Permissions. Do not enable Accessibility or “display over other apps” for a supposed airline, tax, delivery, or government app. Overlays require explicit user approval on modern Android, so a request like this is a red flag.
Protection. Use an up-to-date real-time anti-malware solution for your Android devices. Malwarebytes detects components of Gigabud as Android/Trojan.Banker.ACR577B2BA2H61, Android/Trojan.Banker.ACRF6CE8D30H46, Android/Trojan.Banker.ACR6C67829FH20, Android/Trojan.Banker.SIB02FFFFFF1112H106, Android/Trojan.Banker.SIB0181193e44H71, Android/Trojan.Banker.AUR2f2f4fb5C95, and Android/Trojan.Spy.Gigabud.xc.
Anyone who has installed a suspicious APK and granted it Accessibility access should contact their bank through a trusted channel, revoke the app’s special permissions, uninstall it, and consider a factory reset after preserving only known-good data.
A second instance of a banking app merits particular scrutiny. A separate work profile by itself is not proof of compromise because work profiles also have legitimate uses. But the presence of a cloned banking app definitely is suspicious.
Scammers know more about you than you think.
Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in.
BlueMoon exploit kit turns Chrome and Windows flaws into attacks
BlueMoon, a shared Chrome and Windows exploit kit, shows why “patch later” is becoming a dangerous gamble.
Security updates are easy to put off. The browser still opens, Windows still works, and choosing to relaunch your browser or restart your computer later can feel harmless.
But a newly documented exploit kit called “BlueMoon” shows how quickly patching delays can become dangerous. Proofpoint Researchers found four espionage groups using the same exploit chain against Chrome browsers running on Windows within days of one another.
The campaign is a timely reminder that once a security flaw, or even its fix, becomes public, attackers may move faster than many users expect.
The attacks began with phishing emails. A victim who clicked a malicious link could be sent to a web page designed to exploit two vulnerabilities in Chrome’s V8 JavaScript engine, followed by a Windows vulnerability to break out of the browser’s protections and gain higher privileges on the computer.
The Chrome vulnerabilities used by BlueMoon were patched in the Stable channel on September 3 and September 8, 2026. The first was already actively exploited when Google released its update. Microsoft addressed the Windows vulnerability in its September Patch Tuesday updates, by which point it was also being exploited.
CISA has since added all three flaws to its Known Exploited Vulnerabilities (KEV) catalog, which lists vulnerabilities known to have been exploited in real-world attacks.
The notable part is not just that BlueMoon exploited the flaws, but how quickly the capability appears to have spread. Publicly visible upstream fixes can give attackers clues before downstream browser updates reach users, allowing a weaponized chain to be developed and adopted by multiple groups very quickly.
Does that mean that patches can no longer be tested before they are released to the public? No, but we may need to rethink how they are tested and deployed, because it appears some cybercriminals are effectively beta-testing the patches themselves.
The researchers also found clues, but no conclusive evidence, that the exploit kit was developed with AI assistance. The broader concern is credible: AI tools can help attackers interpret source-code changes, write and modify code, document test results, and learn from failed attempts.
In practical terms, the gap between “a flaw is fixed upstream” and “most people are protected” may be increasingly valuable to attackers. We should try to minimize that gap.
How to stay safeNot every security update needs to be installed the moment it appears. In organizations especially, updates may need testing, staged deployment, and contingency plans. But vulnerabilities known to be actively exploited deserve greater priority. That is precisely why CISA’s KEV catalog is so important: It helps organizations identify the vulnerabilities they should address first.
For home users:
- Install browser and operating-system updates promptly. Use the few minutes they take to grab a drink rather than repeatedly postponing them.
- Don’t click links in unsolicited emails.
- Use up-to-date, real-time anti-malware protection to help catch the malware that exploit kits attempt to deliver.
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
Will AI kill us all within the next decade?
The Wall Street Journal reports that concerns are rising inside AI labs that competition is pushing tech companies to race toward self-improving models that could spiral out of human control.
Jacob Coxon, an AI researcher who has worked at Anthropic and OpenAI, said:
“The people building AI earnestly believe that it could kill us all by the end of the decade.”
Evan Hubinger, Anthropic’s Alignment Science lead, who also worked at OpenAI, responded in a post on X:
“We really do earnestly believe AI could kill all humans! I personally think it is >10% within the next decade.”
Hubinger added:
“What I am worried about is superintelligence arising from recursive self-improvement, as we have said is happening faster than we thought.”
That figure should be treated as Hubinger’s personal assessment. It is not a forecast, an established fact, or evidence that today’s chatbots are about to become dangerous on their own. Nor is it something I know enough about to endorse or dismiss.
Researchers are actively studying whether highly capable systems could act in unintended ways, exploit vulnerabilities, or be used to automate cyberattacks.
A BBC report notes that Hubinger described the risk from current models as low. His concerns focus on possible future systems with far greater autonomy and capability.
As companies and governments weigh the pace of AI development, we need sensible safeguards, including independent testing, limits on high-risk autonomous uses, transparency from developers, and accountability when AI systems cause harm.
Those measures should also address the problems we already face as cybercriminals use AI for fraud, privacy abuse, and other cybercrimes. Like many powerful technologies, AI can be used as a weapon, particularly when safeguards lag behind its capabilities.
Extreme predictions can be emotionally compelling, especially when made by people closely involved in the technology. But uncertainty cuts both ways: Serious warnings deserve scrutiny, not unquestioning belief.
The practical message is neither “ignore AI safety” nor “prepare for a robot apocalypse.” Companies, governments, and researchers need to work together to ensure that safety measures keep pace with rapid development.
Cooperation can complement competition, and in this case, it could be crucial.
Your name, address, and phone number may already be for sale.
Data brokers collect and sell your personal details to anyone willing to pay. Malwarebytes Personal Data Remover finds them and gets your information removed, then keeps watch so it stays that way.
Update Chrome now to protect against an actively exploited vulnerability
Chrome is rolling out an update for its desktop browser. The update includes 230 security fixes, one of which is known to be actively exploited.
The stable channel has been updated to 153.0.8010.36/.37 for Windows and Mac, and 153.0.8010.36 for Linux.
How to update ChromeIf you don’t want to wait for the rollout to reach you, manually updating is easy.
The easiest option is to allow Chrome to update automatically. But you can end up lagging behind on updates if you never close your browser or if something goes wrong, such as an extension preventing the update.
To update manually, click the More menu (three dots), then go to Settings > About Chrome. If an update is available, Chrome will start downloading it automatically. Restart Chrome to complete the update, and you’ll be protected against these vulnerabilities.
Chrome 153.0.8010.36/.37 is up to dateYou can find an explanation of the version numbering system and step-by-step instructions in our guide: How to update Chrome on every operating system.
Technical detailsThe actively exploited vulnerability is tracked as CVE-2026-87491. The description says it’s an out-of-bounds write vulnerability in Chrome’s V8 engine that could allow a remote attacker to execute arbitrary code inside the browser’s sandbox via a crafted HTML page.
This means the bug was found in the part of Chrome that runs JavaScript. A malicious website could exploit it by getting someone to load a specially designed web page, causing Chrome’s JavaScript engine to mishandle memory and run attacker-chosen instructions. Those instructions would initially run within Chrome’s security sandbox rather than with unrestricted access to the whole device.
Chrome’s sandbox is intended to limit that code’s access to the rest of the device, but the flaw is still serious because it gives an attacker a foothold simply by getting a target to view a malicious web page. Emails are unlikely to trigger the flaw because most reputable email clients sanitize incoming HTML before displaying it. They strip or disable active web features that would let a sender run code in the inbox, such as JavaScript. However, an email could contain a link that takes the recipient to a malicious website.
Besides this medium-severity flaw, the update fixes five vulnerabilities rated Critical, four of which were found in WebGL (Web Graphics Library). WebGL is a JavaScript programming interface used to render interactive 2D and 3D graphics inside the browser without needing extra plugins.
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
Copyright scammers get Instagram accounts suspended and demand payment
Scammers are abusing Meta’s copyright-reporting system to suspend people’s Instagram accounts and then hold them for ransom, according to the BBC.
Criminals file fake copyright complaints with Instagram, claiming that an account is using material it doesn’t own. Repeated complaints can trigger a temporary account suspension from the platform, locking out the victim even though they haven’t done anything wrong. The criminal then moves the conversation to another platform, such as Telegram, and demands a ransom to withdraw the complaint.
We’ve reported on a similar scheme before. In that case, scammers abused Instagram’s reporting system to get accounts taken down and then charged their owners to restore them.
The BBC interviewed the owner of a history-focused Instagram account who said that he had been hit by copyright claims multiple times from the same email address. Repeated copyright claims can eventually result in an account being disabled, making this particularly damaging for people who use Instagram to generate income.
The account holder eventually paid $50 in cryptocurrency because he said it could take weeks for Meta to deal with his claim and that they were unhelpful to begin with. However, the scammers targeted him again immediately afterward.
Users do have free support routes, including the appeal option that comes with the copyright notification and Instagram’s in-app Help section. Paid options include the 24/7 access to a support agent that comes with Meta Verified, while Meta Business Support is available to some eligible business and advertising accounts.
The scam works because Meta has automated much of its processing of copyright complaints. It doesn’t verify the authenticity of complaints when they are filed, and repeated complaints can result in an account being temporarily taken down. Its policy says that only rights holders or their authorized representatives can file a complaint, but it doesn’t check their ID before acting. That means criminals can pretend to be rights holders or their lawyers and get away with it.
AI could make it easier for scammers to file these fraudulent complaints at scale, turning the attack into a trawling exercise. If they convince just a few victims to pay a ransom, it can become worth their while, especially if Meta takes too long to resolve the problem manually.
The BBC spoke to one Instagram account owner who said that he had lost brand contracts over the issue. Meta hadn’t been able to assure him that the problem wouldn’t happen again, he said.
This problem is drawing legal scrutiny. In India, the Delhi High Court is examining whether social media platforms can legally suspend user accounts over copyright violations. In a separate case, Meta acknowledged in court that 13 copyright strike notices against one Instagram user were fraudulent and restored the account.
Meta told the BBC that it fights deceptive behavior intended to scam people. After reviewing the accounts identified by the BBC, it restored affected content and added unspecified protections intended to prevent similar attacks. However, the company hasn’t announced any blanket protections designed to fix its “suspend first, verify later” approach.
Law enforcement advises victims not to pay the ransom because that feeds the scammers. It also doesn’t guarantee that they won’t hit you again. In fact, it might make them more likely to do so if they know that you are willing to cough up.
Copyright complaints are also commonly used as phishing lures. We have previously reported on scammers sending fake copyright warnings to X users and convincing copyright notices to YouTube creators. Those attacks tried to steal people’s login details. In this case, the scammers are abusing Instagram’s genuine complaints system to get accounts suspended.
How to protect your Instagram account- Turn on two-factor authentication. This will not prevent fraudulent complaints, but it can help protect your account if scammers also try to steal your login.
- Check copyright complaints in Instagram. Don’t rely on links or screenshots sent by email, Telegram, or another messaging service.
- Don’t pay to have a complaint withdrawn. Paying does not guarantee that the scammer will withdraw it or leave your account alone.
- Don’t share login details or verification codes. A scammer may use the copyright complaint to steer you toward a fake Instagram login page.
- Use Instagram’s official appeal process. Keep copies of the complaint, ransom demands, usernames, email addresses, and payment requests as evidence.
Scammers don’t need to hack you. They just need you to click once.
Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.
