AI-generated fake websites and reservation hijacking are turning travel bookings into phishing lures. Attackers phish hotel staff for credentials, then use real reservation data to craft expected-looking messages that bypass user suspicion.
Source: thepeterboroughexaminer.com · wfmj.com
The onboarding process creates a social-engineering window that attackers exploit using fake welcome emails, fraudulent portals, and direct deposit redirection. With more than 1 million identity theft reports to the FTC in the latest year, cybersecurity teams should map the new-hire life cycle as a hostile attack surface.
Source: kiro7.com · hits973.com
Recovery scams are social engineering operations that reuse victim data to launch second-stage attacks. Cyber defenders should track impersonation of IC3, requests for bank details and Social Security numbers, and payment channels such as cryptocurrency, gift cards, wire transfers, cash, and payment apps.
Source: gulfcoastnewsnow.com · wesh.com
The FTC's investigation into how Epic restricts health data access could reshape API and data-sharing rules for platforms holding 310M patient records. Cybersecurity leaders face a balancing act between interoperability mandates and expanding attack surfaces.
Source: austinglobe.com · afghanistannews.net
The FTC's lawsuit against Hims & Hers alleges the telehealth giant shared sensitive health information of nearly 2.6 million subscribers with Meta and Snap, violating privacy promises. The case highlights critical gaps in health data protection and signals increased regulatory enforcement for digital health platforms.
Source: Li Zhou (au) · Li Zhou (us)
An AP/FRONTLINE probe reveals how a trafficked worker at a Myanmar scam center exploited American AI technology to run romance fraud against 50,000 victims across 17 countries in a single month, forcing a reckoning over AI model security and platform accountability.
Source: nbcphiladelphia.com · nbclosangeles.com
Impostor scams cost Americans $3.5B in 2025, nearly tripling in five years, and spike during summer. Cybercriminals exploit seasonal spending and travel to execute social engineering attacks. Understanding these tactics is critical for organizational and personal defense.
Source: actionnewsjax.com · kiro7.com
For cybersecurity teams, the FTC’s Q3 2025 data provides a blueprint of attack patterns: 14,263 travel fraud reports and $40M in losses, revealing persistent phishing and social engineering threats during peak travel season.
Source: wsbtv.com · 99jamzmiami.com
Cybersecurity professionals highlight how debit card use at gas pumps and other high-risk locations enables a $1 billion annual skimming industry. The liability gap between credit and debit magnifies consumer risk. Learn the five threat vectors and how tokenization and EMV upgrades are reshaping payment security.
Source: 1073theeagle.com · wsbradio.com
The AP/FRONTLINE investigation uncovers how US cloud, AI, and satellite internet services enable industrial-scale global scams, with over 200,000 logged connections from sanctioned scam compounds routing through American ISPs like Amazon, Cloudflare, and Akamai.
An AP investigation uncovers how trafficked scammers abuse American AI models and cloud infrastructure to industrialize romance fraud, with a single operator targeting 50,000 individuals monthly. This upstream exploitation presents a novel threat vector that cybersecurity defenders must urgently address.
The IRS and FTC have issued an urgent warning regarding a massive surge in tax-related identity theft driven by AI-enabled voice mimicry and sophisticated phishing. Scammers are using robocalls and malicious QR codes to steal Social Security numbers and intercept refunds before taxpayers can file.
Source: Cora Lewis (gb) · Cora Lewis (gb)
The Federal Trade Commission has issued a landmark policy statement providing enforcement flexibility for online platforms implementing age verification technologies. This shift aims to resolve the regulatory 'Catch-22' where services must collect data to verify age but are restricted from doing so under COPPA without prior parental consent.