search
Phish
Trends
- 1Scammers Trick Users into Bridging $2 Million to Fake GIWA Network●Scammers Fool Users into Bridging $2 Million to Fake GIWA Network
Fraudsters set up a counterfeit version of the GIWA network and convinced crypto users to bridge roughly $2 million into it, where the funds were effectively stolen. The scheme exploited trust in the GIWA name, catching victims who did not verify the bridge contract. Observers are warning users to double-check URLs and contract addresses before moving funds.
- 2Data breach exposes personal details of 23,500 Simba customers▼Personal information of over 23,500 Simba customers leaked in data breach
Personal information belonging to more than 23,500 customers of Singapore telecom provider Simba has been leaked in a data breach. Singapore media, including The Straits Times and The Business Times, reported the incident. The leaked details and how the breach occurred have not been fully detailed in initial reports, and customers may face risks such as phishing or identity fraud.
- 3SIMBA data breach exposes personal details of 23,000 customers▼SIMBA data breach exposes IC numbers and personal details of over 23,000 customers
Singapore telco SIMBA has suffered a data breach affecting more than 23,000 customers, with identity card numbers and other personal details exposed. The incident raises fresh concerns about how telecom operators safeguard sensitive customer information, and affected users may face heightened risks of identity theft and phishing attempts.
- 4
A phishing scam may have compromised thousands of court records in Arizona, according to Fox 10 Phoenix. The report suggests sensitive documents held by the state's court system could have been exposed, though details about the scale, the institutions affected, and whether personal data was accessed remain unclear.
- 5Group-IB uncovers RemControl Android banking trojan●Group-IB found the RemControl Android banking trojan, a new malware using AI phishing overlays and fake TVTap apps to st
Cybersecurity firm Group-IB has identified RemControl, a new Android banking trojan distributed through fake TVTap streaming apps. The malware uses AI-generated phishing overlays to trick users into entering banking PINs and credentials, which are then stolen. Security researchers are warning Android users to avoid unofficial app sources as the trojan spreads.
- 6Scammers target young Roblox players with fake login pages●Scammers are going after young Roblox players and their Robux Fake Roblox login pages are being used to steal passwords
Cybersecurity researchers are warning that scammers are targeting young Roblox players with fake Roblox login pages designed to steal passwords and two-factor authentication codes, giving attackers access to accounts and their Robux currency. Because many players are children, experts urge parents to talk to them about phishing links and enable extra account protections.
- 7Truecaller launches Scam Checker tool for fraud detection●Truecaller har lanserat ett nytt verktyg som ska hjälpa användare att upptäcka bedrägeriförsök genom att kontrollera län
Truecaller has launched a new tool called Scam Checker, designed to help users detect fraud attempts. The feature lets users check links, phone numbers and suspicious messages for signs of scams such as phishing. The tool is being discussed in connection with both iOS and Android versions of the app.
- 8
Phishing is in the spotlight as new reports detail a wave of scams and malware campaigns. Russian state hackers are said to be using a technique called RedFlick to spread malware, while Ukrainian authorities warn consumers about fake electricity bills. Researchers also flagged a remote access trojan distributed through fake Microsoft Store pages, and a report finds phishing exposure nearing 70% across key US industries.
- 9Simba data breach exposes 23,549 customers' ID numbers▼SIMBA Data Breach: 23,549 Customers' NRIC Numbers and Birth Dates Exposed, What to Do Now
Singapore telecom operator Simba has suffered a data breach affecting 23,549 customers, with their NRIC identification numbers and dates of birth exposed. Reports are advising affected customers on steps to take, such as staying alert to phishing attempts and monitoring for misuse of their personal information. The incident has raised fresh concerns about how telecom firms safeguard customer data.
- 10Chinese hackers impersonated ex-US official to target AI experts▼Chinese hackers impersonated ex-US official to steal emails from AI experts
Chinese-linked hackers posed as a former US official in a phishing scheme aimed at stealing emails from artificial intelligence specialists, Reuters reports. The operation used a spoofed identity to trick targets into handing over sensitive correspondence, highlighting growing concern over espionage campaigns targeting the AI sector and US expertise in the field.
- 11Filippo Bernardini, Publishing's Fake Manuscript Scammer, Reportedly Back●Filippo Bernardini Scammed the Book Business for Years. Is He Back?
Filippo Bernardini, the Italian man who posed as editors and agents to steal unpublished manuscripts from authors across the book world for years, is the subject of renewed attention over whether he is operating again. The New York Times revisits the scheme, which ensnared writers including Margaret Atwood, and asks whether the scammer, who faced US fraud charges, has resumed his activities.
- 12Trey Anastasio and Monica Bellucci mark September 30 birthdays▼Today’s famous birthdays list for September 30, 2026 includes celebrities Trey Anastasio, Monica Bellucci
Cleveland.com's daily celebrities birthdays feature for September 30, 2026 highlights Phish guitarist Trey Anastasio and Italian actress Monica Bellucci among the famous names celebrating. Such lists are a recurring fixture of entertainment coverage, offering readers a quick roundup of stars marking the day, along with brief notes on their careers and milestones.
- 13Warning issued over phishing link disguised as Google Docs presentation▼Possible Phishing 🎣 on: ⚠️hxxps[:]//docs[.]google[.]com/presentation/d/e/2PACX-1vQ4JqNki4NYPJowqvSnDa0dUaoYHsAeJBMw02Vtj
Cybersecurity researchers are flagging a possible phishing campaign hosted through a Google Docs presentation link. The URL, shared in defanged form, points to a public Google Slides page that may be used to lure victims into handing over credentials or personal data. A full technical analysis of the link has been published on a URL scanning service. Users are advised to treat unexpected Google Docs links with caution.
- 14Fake Facebook login page flagged in new phishing warning▼Possible Phishing 🎣 on: ⚠️hxxps[:]//facebooc-system[.]start[.]page 🧬 Analysis at: https:// urldna.io/scan/6abc5f333b7750
Security researchers are warning about a phishing site at the address facebooc-system.start.page, which imitates Facebook to steal login credentials. The deliberately misspelled domain on a free hosting service is a common scam pattern. An analysis of the site has been published on the URLDNA scanning platform, and the warning is circulating among infosec professionals.
- 15Woman mails new iPhone to scammers within hours of delivery▼Woman mailed away new iPhone to scammers less than two hours after delivery
A woman in the United States was tricked into mailing her brand-new iPhone to scammers less than two hours after it was delivered, according to WSB-TV. Reports say she fell for a phishing message impersonating a delivery company, which persuaded her to return the device to an address controlled by fraudsters. The case highlights how quickly criminals exploit fake parcel notifications to steal newly purchased phones.
- 16Bank's sloppy email raises phishing and branding concerns●Bank email today... * Shows up in Gmail inbox as coming from "statements" * No sender icon * No header image * No sign o
An Australian bank customer received an official email that arrived with no sender photo, no header image, no sign-off, and a dense wall of poorly punctuated text. It came from a domain on .bank rather than the bank's usual .com.au website address, deepening confusion. The recipient questioned why a legitimate institution would send such unprofessional correspondence, with many readers likely to mistake it for a phishing attempt.
- 17Pentagon, Renamed Department of War, Marks Cybersecurity Awareness Month▼Department of War Champions 'Brilliant at the Basics' for Cybersecurity Awareness Month
The U.S. Department of War is promoting the theme 'Brilliant at the Basics' for Cybersecurity Awareness Month, urging staff and the wider defense community to master fundamental cyber hygiene such as strong passwords, phishing awareness and software updates. The campaign highlights that basic practices remain the most effective defense against increasingly common cyber threats targeting government systems.
- 18SVG phishing attacks surge, Symantec warns●SVG phishing attacks jumped in August 2026. Symantec explains how SVG smuggling hides fake logins and malware inside ima
Symantec reports a sharp rise in phishing attacks using SVG image files in August 2026. Attackers embed fake login pages and malware inside SVG files smuggled through email attachments, bypassing conventional detection because the files look like harmless images. Symantec has published guidance on how the technique works and what defences organisations should deploy against it.
- 19Bulletproof hosting: the internet's criminal safe haven▼Bulletproof hosting, the Internet’s criminal safe haven # negativepid # digitalInvestigations # OSINT # cybersecurity #
A new explainer examines bulletproof hosting, the practice of internet providers knowingly renting server space to criminals and ignoring abuse complaints or takedown requests. The article outlines how these operators shield malware campaigns, phishing and other cybercrime, and looks at how investigators use open-source techniques to trace and identify the networks behind them.
- 20A closer look at how OneDrive phishing attacks work●Anatomy of a modern OneDrive phishing attack # negativepid # digitalInvestigations # OSINT # cybersecurity # AI # tech #
A cybersecurity blog has published a detailed breakdown of a modern phishing campaign abusing Microsoft OneDrive, walking through how attackers craft convincing file-sharing lures and what investigators can do to trace them. The write-up is aimed at digital forensics and OSINT practitioners, touching on the psychology behind cybercrime and the growing role of AI tools in both attacks and investigations.
- 21Warning issued over fake early iPhone Duo pre-order links▼PSA: Do not open links to an early iPhone Duo pre-order page
A warning is circulating telling people not to open links claiming to lead to an early pre-order page for a device referred to as the iPhone Duo. The advice suggests such pages are not legitimate and could be used to phish personal or payment details. Consumers are urged to pre-order only through Apple's official site or verified retailers.
- 22Security researchers flag Facebook phishing site on Blogspot▼Possible Phishing 🎣 on: ⚠️hxxps[:]//my-facebook-blog[.]blogspot[.]com/?m=1 🧬 Analysis at: https:// urldna.io/scan/6abda2
Cybersecurity observers are warning about a suspected phishing page hosted on a Blogspot address imitating Facebook, with the malicious link deliberately defanged as hxxps to prevent accidental clicks. A technical analysis of the site has been published on the URLDNA scanning service. The domain name 'my-facebook-blog' suggests a fake login or credential-harvesting scheme, a common tactic using free blog-hosting platforms to impersonate major services.
- 23Fake Exodus wallet support page flagged as phishing site▼Possible Phishing 🎣 on: ⚠️hxxps[:]//exodus-help-wlt-chiky[.]wasmer[.]app 🧬 Analysis at: https:// urldna.io/scan/6abc910c
Cybersecurity researchers are warning about a phishing site impersonating Exodus wallet support, hosted at exodus-help-wlt-chiky.wasmer.app. The domain was defanged and shared with a link to a URLDNA analysis so others can inspect it. The site follows a common pattern of fraudulent crypto wallet help pages designed to steal users' seed phrases or credentials.
- 24Security Researchers Flag Possible Phishing Site on Weebly▼Possible Phishing 🎣 on: ⚠️hxxps[:]//nnbxv[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/scan/6abc7b5a3b77500 00653a6c
Cybersecurity observers are warning about a suspected phishing page hosted at a Weebly web address, sharing a link to a detailed technical analysis of the site on the URLDNA scanning platform. The address has been defanged to prevent accidental clicks. The warning is being circulated in information security communities alongside standard scam and phishing alert tags.
- 25English schools recovering faster from cyber incidents●England's schools are getting better at mopping up cyber incidents Two-thirds report immediate recovery, although teache
Two-thirds of schools in England now report recovering immediately from cyber incidents, suggesting improved resilience to attacks such as ransomware and phishing. Despite the progress, teachers remain divided over who bears responsibility for security and whose job security is at risk when breaches occur, with staff often left handling technical problems outside their expertise.
- 26Possible phishing site flagged impersonating Toronto Construction Association▼Possible Phishing 🎣 on: ⚠️hxxp[:]//tcaconnect[.]ac-page[.]com/toronto-construction-association-inc 🧬 Analysis at: https:
Cybersecurity researchers are warning of a possible phishing page hosted on a domain mimicking the Toronto Construction Association, shared via a defanged link and analyzed through the URLDNA scanning service. The alert circulates in infosec communities, urging recipients to avoid the link and verify any communications claiming to come from the association.
- 27Phish fans launch scholarship for Vermont music students▼Phish fans create new scholarship for Vermont college music students
Fans of the band Phish have established a new scholarship to support music students at a college in Vermont, the band's home state. The initiative reflects the group's devoted fan community and its ties to Vermont, where Phish formed in the early 1980s. Details on the scholarship's size and eligibility have not yet been widely reported.
- 28Security Researchers Flag Phishing Page Hosted on GitHub Pages▼Possible Phishing 🎣 on: ⚠️hxxp[:]//cryptgmxnavigator[.]github[.]io/Pages/gx[.]html 🧬 Analysis at: https:// urldna.io/sca
Cybersecurity observers are warning about a suspected phishing site hosted on a GitHub Pages address, flagged as an attempt to trick users into handing over credentials or sensitive data. The alert includes a link to a URL analysis so others can inspect the page's behaviour. The warnings, shared in infosec circles, underline how attackers continue to abuse legitimate free hosting services to distribute scams.
- 29UK rolls out passkeys on GOV.UK One Login●The UK is rolling out passkeys across GOV.UK One Login, bringing phishing-resistant logins to more than 23 million peopl
The UK government is introducing passkey support across GOV.UK One Login, giving more than 23 million users the option of phishing-resistant sign-ins for public services. Over 300,000 people already switched during the trial phase. Passwords are still required for now, with passkeys offered as an additional, more secure login method for accessing government accounts online.
- 30FIFA 18 coin site flagged as suspected phishing scam▼Possible Phishing 🎣 on: ⚠️hxxps[:]//coinsfifa18[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/scan/6abc897f3b77500 00
Security researchers are warning about a suspected phishing site hosted on a Weebly subdomain that offers FIFA 18 in-game coins, a common lure used to steal credentials or payment details from players. A technical analysis of the page has been published via a URL scanning service, defanging the link so others can inspect it safely. Users are urged to avoid entering account or card information on sites promising cheap game currency.
- 31Security researchers flag phishing site hosted on Weebly▼Possible Phishing 🎣 on: ⚠️hxxps[:]//esnetdeskfreenetserverservicesdkx[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/s
Cybersecurity researchers are warning about a possible phishing site operating through a Weebly-hosted page that impersonates network or helpdesk services. The suspicious link has been defused and shared with a technical analysis via urldna.io so that other security professionals can inspect the domain and its infrastructure. The report has circulated in infosec communities, which frequently post such alerts to warn the public about scam pages before they spread more widely.
- 32Security researcher flags suspected phishing site on Blogspot●Possible Phishing 🎣 on: ⚠️hxxps[:]//ivvvaaannaaalaaawiiiiifamilly[.]blogspot[.]com/ 🧬 Analysis at: https:// urldna.io/sc
A cybersecurity analyst has raised an alert over a suspected phishing page hosted on a Blogspot address with a deliberately distorted spelling designed to imitate a legitimate site. The suspicious link was shared with its characters broken up so it cannot be clicked accidentally, and a technical breakdown of the domain was published via a URL analysis service. The post circulated with phishing and scam hashtags among infosec followers.
- 33Security Researchers Flag Phishing Site Impersonating Bancolombia▼Possible Phishing 🎣 on: ⚠️hxxps[:]//segurocardiffbancolh360[.]vercel[.]app/ 🧬 Analysis at: https:// urldna.io/scan/6abc9
Cybersecurity observers are warning of a phishing site hosted on a Vercel subdomain that imitates Bancolombia's customer portal, using a URL designed to look like the Colombian bank's official 'seguro' security page. The link has been defanged and shared with a public URL analysis scan so people can review its infrastructure. The alert circulates with standard infosec and scam warnings.
- 34Experts urge skepticism to avoid online scams●Be skeptical, avoid on-line scams. # cybersecurity https:// cromwell-intl.com/cybersecurit y/basics/09-scams.html?s=mb
Cybersecurity guidance circulating online urges internet users to be skeptical of unsolicited messages and offers in order to avoid falling victim to online scams. The reminder points readers to basic security advice on recognizing fraud attempts, a perennial concern as phishing and social engineering scams continue to target people through email, social media and messaging platforms.
- 35Phish Fans Launch Scholarship for Vermont Music Students▼Phish Fans Launch Scholarship for Undergraduate Music Students in Vermont
Fans of the band Phish have created a new scholarship to support undergraduate music students in Vermont. The initiative, reported by NYS Music, channels the band's passionate fan community into direct support for young musicians pursuing higher education in the state Phish has long called home. Details on donation amounts and eligibility have not yet been widely reported.
- 36Security researchers flag possible phishing site hosted on Weebly▼Possible Phishing 🎣 on: ⚠️hxxps[:]//yournexttwcindex[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/scan/6abd72293b775
Cybersecurity watchers are warning about a suspected phishing website hosted on a Weebly subdomain, sharing a defanged link and pointing to a public URL analysis scan that breaks down the page's infrastructure. The alert is being circulated in infosec communities as an example of scammers abusing free website builders to host fraudulent pages.
- 37A cyber awareness professional shares phishing training lessons●True stories of Cyber Awareness: Phishing I ran the company and customer wide cyber awareness programs where I developed
A security practitioner who ran company-wide and customer-facing cyber awareness programmes has described how the work was organised, with the first weeks of each month devoted to specific training sessions and the latter part of the month used for simulated phishing campaigns. The account offers a practical look at how organisations try to prepare staff to recognise phishing attempts before real attacks succeed.
- 38Fake Wells Fargo login page flagged as phishing site▼Possible Phishing 🎣 on: ⚠️hxxps[:]//sites[.]google[.]com/view/wellsfargologinu 🧬 Analysis at: https:// urldna.io/scan/6a
Security researchers are flagging a fraudulent Wells Fargo login page hosted on a Google Sites address, designed to steal customers' banking credentials. The link has been defanged to prevent accidental clicks, and a public scan on URLDNA lets others inspect the site's characteristics. The warning has circulated among infosec community members tracking phishing campaigns.
- 39Security researchers flag suspected Amazon phishing domain●Possible Phishing 🎣 on: ⚠️hxxp[:]//amazoninvit[.]com 🧬 Analysis at: https:// urldna.io/scan/6abb5baf3b77500 0050fcbb3 #
Cybersecurity researchers are warning about a suspected phishing site at the domain amazoninvit.com, which impersonates Amazon, likely luring victims through fake invitation or delivery messages. The domain has been submitted for technical analysis on the URLdna scanning platform, and the warning is circulating in information security communities with phishing and scam alerts.
- 40Security researchers flag suspected phishing link hosted on Google Slides●Possible Phishing 🎣 on: ⚠️hxxps[:]//docs[.]google[.]com/presentation/d/e/2PACX-1vSfSt3nJ0uVveK4eEMXIV2XhgC73PaPvYaCWb1Ij
Cybersecurity analysts are warning of a suspected phishing operation using a publicly published Google Slides presentation to host or deliver malicious content. The link has been defanged to prevent accidental clicks, and a scan of the address has been published on the URL analysis service urlDNA so others can inspect what the page does before it is taken down.