search
Phish
Trends
- 1Scammers Trick Users into Bridging $2 Million to Fake GIWA Network●Scammers Fool Users into Bridging $2 Million to Fake GIWA Network
Fraudsters set up a counterfeit version of the GIWA network and convinced crypto users to bridge roughly $2 million into it, where the funds were effectively stolen. The scheme exploited trust in the GIWA name, catching victims who did not verify the bridge contract. Observers are warning users to double-check URLs and contract addresses before moving funds.
- 2
A phishing scam may have compromised thousands of court records in Arizona, according to Fox 10 Phoenix. The report suggests sensitive documents held by the state's court system could have been exposed, though details about the scale, the institutions affected, and whether personal data was accessed remain unclear.
- 3SIMBA data breach exposes personal details of 23,000 customers▼SIMBA data breach exposes IC numbers and personal details of over 23,000 customers
Singapore telco SIMBA has suffered a data breach affecting more than 23,000 customers, with identity card numbers and other personal details exposed. The incident raises fresh concerns about how telecom operators safeguard sensitive customer information, and affected users may face heightened risks of identity theft and phishing attempts.
- 4Data breach exposes personal details of 23,500 Simba customers▼Personal information of over 23,500 Simba customers leaked in data breach
Personal information belonging to more than 23,500 customers of Singapore telecom provider Simba has been leaked in a data breach. Singapore media, including The Straits Times and The Business Times, reported the incident. The leaked details and how the breach occurred have not been fully detailed in initial reports, and customers may face risks such as phishing or identity fraud.
- 5Group-IB uncovers RemControl Android banking trojan●Group-IB found the RemControl Android banking trojan, a new malware using AI phishing overlays and fake TVTap apps to st
Cybersecurity firm Group-IB has identified RemControl, a new Android banking trojan distributed through fake TVTap streaming apps. The malware uses AI-generated phishing overlays to trick users into entering banking PINs and credentials, which are then stolen. Security researchers are warning Android users to avoid unofficial app sources as the trojan spreads.
- 6Scammers target young Roblox players with fake login pages●Scammers are going after young Roblox players and their Robux Fake Roblox login pages are being used to steal passwords
Cybersecurity researchers are warning that scammers are targeting young Roblox players with fake Roblox login pages designed to steal passwords and two-factor authentication codes, giving attackers access to accounts and their Robux currency. Because many players are children, experts urge parents to talk to them about phishing links and enable extra account protections.
- 7Truecaller launches Scam Checker tool for fraud detection●Truecaller har lanserat ett nytt verktyg som ska hjälpa användare att upptäcka bedrägeriförsök genom att kontrollera län
Truecaller has launched a new tool called Scam Checker, designed to help users detect fraud attempts. The feature lets users check links, phone numbers and suspicious messages for signs of scams such as phishing. The tool is being discussed in connection with both iOS and Android versions of the app.
- 8Simba data breach exposes 23,549 customers' ID numbers▼SIMBA Data Breach: 23,549 Customers' NRIC Numbers and Birth Dates Exposed, What to Do Now
Singapore telecom operator Simba has suffered a data breach affecting 23,549 customers, with their NRIC identification numbers and dates of birth exposed. Reports are advising affected customers on steps to take, such as staying alert to phishing attempts and monitoring for misuse of their personal information. The incident has raised fresh concerns about how telecom firms safeguard customer data.
- 9
New reporting says nearly 70% of organisations across key US industries are exposed to phishing attacks, prompting warnings for security teams to strengthen email defences, employee training and incident response. The figures are drawing attention among cybersecurity professionals in the US and Europe, where phishing remains one of the most common entry points for ransomware and data breaches.
- 10Filippo Bernardini, Publishing's Fake Manuscript Scammer, Reportedly Back●Filippo Bernardini Scammed the Book Business for Years. Is He Back?
Filippo Bernardini, the Italian man who posed as editors and agents to steal unpublished manuscripts from authors across the book world for years, is the subject of renewed attention over whether he is operating again. The New York Times revisits the scheme, which ensnared writers including Margaret Atwood, and asks whether the scammer, who faced US fraud charges, has resumed his activities.
- 11Warning issued over phishing link disguised as Google Docs presentation▼Possible Phishing 🎣 on: ⚠️hxxps[:]//docs[.]google[.]com/presentation/d/e/2PACX-1vQ4JqNki4NYPJowqvSnDa0dUaoYHsAeJBMw02Vtj
Cybersecurity researchers are flagging a possible phishing campaign hosted through a Google Docs presentation link. The URL, shared in defanged form, points to a public Google Slides page that may be used to lure victims into handing over credentials or personal data. A full technical analysis of the link has been published on a URL scanning service. Users are advised to treat unexpected Google Docs links with caution.
- 12Fake Facebook login page flagged in new phishing warning▼Possible Phishing 🎣 on: ⚠️hxxps[:]//facebooc-system[.]start[.]page 🧬 Analysis at: https:// urldna.io/scan/6abc5f333b7750
Security researchers are warning about a phishing site at the address facebooc-system.start.page, which imitates Facebook to steal login credentials. The deliberately misspelled domain on a free hosting service is a common scam pattern. An analysis of the site has been published on the URLDNA scanning platform, and the warning is circulating among infosec professionals.
- 13SVG phishing attacks surge, Symantec warns●SVG phishing attacks jumped in August 2026. Symantec explains how SVG smuggling hides fake logins and malware inside ima
Symantec reports a sharp rise in phishing attacks using SVG image files in August 2026. Attackers embed fake login pages and malware inside SVG files smuggled through email attachments, bypassing conventional detection because the files look like harmless images. Symantec has published guidance on how the technique works and what defences organisations should deploy against it.
- 14A closer look at how OneDrive phishing attacks work●Anatomy of a modern OneDrive phishing attack # negativepid # digitalInvestigations # OSINT # cybersecurity # AI # tech #
A cybersecurity blog has published a detailed breakdown of a modern phishing campaign abusing Microsoft OneDrive, walking through how attackers craft convincing file-sharing lures and what investigators can do to trace them. The write-up is aimed at digital forensics and OSINT practitioners, touching on the psychology behind cybercrime and the growing role of AI tools in both attacks and investigations.
- 15Woman mails new iPhone to scammers within hours of delivery▼Woman mailed away new iPhone to scammers less than two hours after delivery
A woman in the United States was tricked into mailing her brand-new iPhone to scammers less than two hours after it was delivered, according to WSB-TV. Reports say she fell for a phishing message impersonating a delivery company, which persuaded her to return the device to an address controlled by fraudsters. The case highlights how quickly criminals exploit fake parcel notifications to steal newly purchased phones.
- 16Bulletproof hosting: the internet's criminal safe haven▼Bulletproof hosting, the Internet’s criminal safe haven # negativepid # digitalInvestigations # OSINT # cybersecurity #
A new explainer examines bulletproof hosting, the practice of internet providers knowingly renting server space to criminals and ignoring abuse complaints or takedown requests. The article outlines how these operators shield malware campaigns, phishing and other cybercrime, and looks at how investigators use open-source techniques to trace and identify the networks behind them.
- 17Fake Exodus wallet support page flagged as phishing site▼Possible Phishing 🎣 on: ⚠️hxxps[:]//exodus-help-wlt-chiky[.]wasmer[.]app 🧬 Analysis at: https:// urldna.io/scan/6abc910c
Cybersecurity researchers are warning about a phishing site impersonating Exodus wallet support, hosted at exodus-help-wlt-chiky.wasmer.app. The domain was defanged and shared with a link to a URLDNA analysis so others can inspect it. The site follows a common pattern of fraudulent crypto wallet help pages designed to steal users' seed phrases or credentials.
- 18Possible phishing site flagged impersonating Toronto Construction Association▼Possible Phishing 🎣 on: ⚠️hxxp[:]//tcaconnect[.]ac-page[.]com/toronto-construction-association-inc 🧬 Analysis at: https:
Cybersecurity researchers are warning of a possible phishing page hosted on a domain mimicking the Toronto Construction Association, shared via a defanged link and analyzed through the URLDNA scanning service. The alert circulates in infosec communities, urging recipients to avoid the link and verify any communications claiming to come from the association.
- 19Security Researchers Flag Possible Phishing Site on Weebly▼Possible Phishing 🎣 on: ⚠️hxxps[:]//nnbxv[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/scan/6abc7b5a3b77500 00653a6c
Cybersecurity observers are warning about a suspected phishing page hosted at a Weebly web address, sharing a link to a detailed technical analysis of the site on the URLDNA scanning platform. The address has been defanged to prevent accidental clicks. The warning is being circulated in information security communities alongside standard scam and phishing alert tags.
- 20FIFA 18 coin site flagged as suspected phishing scam▼Possible Phishing 🎣 on: ⚠️hxxps[:]//coinsfifa18[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/scan/6abc897f3b77500 00
Security researchers are warning about a suspected phishing site hosted on a Weebly subdomain that offers FIFA 18 in-game coins, a common lure used to steal credentials or payment details from players. A technical analysis of the page has been published via a URL scanning service, defanging the link so others can inspect it safely. Users are urged to avoid entering account or card information on sites promising cheap game currency.
- 21Phish fans launch scholarship for Vermont music students▼Phish fans create new scholarship for Vermont college music students
Fans of the band Phish have established a new scholarship to support music students at a college in Vermont, the band's home state. The initiative reflects the group's devoted fan community and its ties to Vermont, where Phish formed in the early 1980s. Details on the scholarship's size and eligibility have not yet been widely reported.
- 22Security researchers flag phishing site hosted on Weebly▼Possible Phishing 🎣 on: ⚠️hxxps[:]//esnetdeskfreenetserverservicesdkx[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/s
Cybersecurity researchers are warning about a possible phishing site operating through a Weebly-hosted page that impersonates network or helpdesk services. The suspicious link has been defused and shared with a technical analysis via urldna.io so that other security professionals can inspect the domain and its infrastructure. The report has circulated in infosec communities, which frequently post such alerts to warn the public about scam pages before they spread more widely.
- 23Monica Bellucci and Trey Anastasio mark September 30 birthdays●Today’s famous birthdays list for September 30, 2026 includes celebrities Trey Anastasio, Monica Bellucci
Cleveland.com has published its daily celebrity birthdays roundup for September 30, 2026, listing actress Monica Bellucci and Phish guitarist Trey Anastasio among the famous faces celebrating. The recurring feature highlights well-known figures born on the date each day. Little reaction beyond the listing itself, and exact ages and other names on the list were not detailed in the available information.
- 24UK rolls out passkeys on GOV.UK One Login●The UK is rolling out passkeys across GOV.UK One Login, bringing phishing-resistant logins to more than 23 million peopl
The UK government is introducing passkey support across GOV.UK One Login, giving more than 23 million users the option of phishing-resistant sign-ins for public services. Over 300,000 people already switched during the trial phase. Passwords are still required for now, with passkeys offered as an additional, more secure login method for accessing government accounts online.
- 25Fake Wells Fargo login page flagged as phishing site▼Possible Phishing 🎣 on: ⚠️hxxps[:]//sites[.]google[.]com/view/wellsfargologinu 🧬 Analysis at: https:// urldna.io/scan/6a
Security researchers are flagging a fraudulent Wells Fargo login page hosted on a Google Sites address, designed to steal customers' banking credentials. The link has been defanged to prevent accidental clicks, and a public scan on URLDNA lets others inspect the site's characteristics. The warning has circulated among infosec community members tracking phishing campaigns.
- 26Security researchers flag possible phishing site on weebly.com▼Possible Phishing 🎣 on: ⚠️hxxps[:]//general-trading[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/scan/6abc66db3b7750
Cybersecurity observers are warning about a suspected phishing page hosted at general-trading.weebly.com, sharing the address in defanged form so others do not accidentally visit it. A technical scan of the URL has been published on urldna.io for analysts to review. The alerts are circulating in infosec communities with tags for phishing, scams and general cybersecurity awareness.
- 27Phishing Warning Issued for Google Docs Drawing Link▼Possible Phishing 🎣 on: ⚠️hxxps[:]//docs[.]google[.]com/drawings/d/1gpJivSsThHrL10szmVZFyBMdW6Lmi6oghTnGmLmgQBk/edit 🧬 A
Cybersecurity researchers are flagging a malicious Google Docs Drawings link being used in a suspected phishing campaign. The URL has been defanged and submitted for automated analysis on the urlDNA scanning platform, which examines page behavior and infrastructure for signs of fraud. Security professionals are sharing the warning to alert others not to open the link and to illustrate how attackers abuse trusted Google services to lend credibility to scams.
- 28Russian hacking group Star Blizzard expands targets and tactics▼Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond
The Russia-aligned hacking group Star Blizzard is broadening its targeting beyond its usual victims and changing its tactics, extending operations from Ukraine to a wider range of countries. The group, previously linked to spear-phishing campaigns against researchers, journalists and government figures, is being monitored by cybersecurity analysts tracking its evolving methods and expanding reach.
- 29Security researchers flag suspected Amazon phishing domain●Possible Phishing 🎣 on: ⚠️hxxp[:]//amazoninvit[.]com 🧬 Analysis at: https:// urldna.io/scan/6abb5baf3b77500 0050fcbb3 #
Cybersecurity researchers are warning about a suspected phishing site at the domain amazoninvit.com, which impersonates Amazon, likely luring victims through fake invitation or delivery messages. The domain has been submitted for technical analysis on the URLdna scanning platform, and the warning is circulating in information security communities with phishing and scam alerts.
- 30Security researchers flag possible phishing link▼Possible Phishing 🎣 on: ⚠️hxxps[:]//tinyurl[.]com/e7exuktd 🧬 Analysis at: https:// urldna.io/scan/6abbd2873b77500 0034a0
Cybersecurity analysts are warning about a possible phishing campaign distributed through a shortened TinyURL link. A link-analysis service has published a scan of the address so that users can inspect where the redirect leads before clicking. Alerts like this circulate in information-security communities to warn people off suspicious links and demonstrate how shortened URLs can hide malicious destinations.
- 31Are Passkeys More Private, or Just More Secure?●Are Passkeys More Private, or Just More Secure? Passkeys stop phishing and breaches, but does that make them more privat
Security writers are weighing whether passkeys deliver real privacy gains alongside their well-known security benefits. Passkeys resist phishing and limit damage from data breaches, but questions remain about what websites can still learn about users and how synced passkeys across devices handle personal data. The debate centres on tradeoffs between convenience, security and data exposure.
- 32Security Researchers Flag Phishing Site Hosted on Google Sites▼Possible Phishing 🎣 on: ⚠️hxxps[:]//sites[.]google[.]com/view/oiuiruieor98490krejjkljklejkef/home 🧬 Analysis at: https:/
Cybersecurity researchers are warning about a phishing page hosted on Google Sites, sharing a defanged link and a scan report on urlDNA for analysis. The alerts circulated in infosec channels, with warnings that the site is designed to deceive visitors into handing over credentials or personal data. The use of a legitimate Google domain highlights how attackers exploit trusted hosting services.
- 33Security researchers flag possible phishing site 21argarena4.com▼Possible Phishing 🎣 on: ⚠️hxxp[:]//21argarena4[.]com 🧬 Analysis at: https:// urldna.io/scan/6abb5baa3b77500 004b4aab1 #
Cybersecurity observers are warning about a possible phishing website at 21argarena4.com. The domain, which imitates the Arena of Valor ARG Arena branding, has been defanged in warnings and submitted to the URLdna scanning service for analysis. The alert is being shared within infosec communities alongside tags for phishing, scams and general cybersecurity awareness.
- 34Spanish-Language Delivery Phishing Link Flagged by Researchers▼Possible Phishing 🎣 on: ⚠️hxxps[:]//qrco[.]de/modifica-tu-entrega 🧬 Analysis at: https:// urldna.io/scan/6abb155a3b77500
Security researchers have flagged a phishing link circulating via a QR-code shortener service, with a Spanish-language address ("modifica tu entrega", meaning "modify your delivery") suggesting a fake parcel-delivery scam. The link has been submitted for technical analysis on a URL-scanning platform. Cybersecurity observers warn that such QR-code delivery scams trick recipients into entering payment or personal details on fake courier sites.
- 35Security Researchers Flag Facebook Phishing Site on Blogspot●Possible Phishing 🎣 on: ⚠️hxxps[:]//facebok-facebook[.]blogspot[.]com/?m=1 🧬 Analysis at: https:// urldna.io/scan/6abae3
Cybersecurity observers are warning about a suspected phishing site impersonating Facebook, hosted at a lookalike Blogspot address. The domain 'facebok-facebook.blogspot.com' uses a misspelling of the platform's name to trick users. A scan of the URL has been published on URLDNA so others can review the technical details. The warning is circulating among infosec communities, with users urged to treat the link as a scam and avoid entering any credentials.
- 36Phish Fans Fund New Scholarship for Vermont Music Students●A new scholarship, powered by Phish fans, for music students attending college in Vermont
A new scholarship aimed at music students attending college in Vermont has been launched with backing from Phish fans. The initiative, reported by the Manchester Journal, draws on the band's devoted following, which has long ties to Vermont, where Phish formed. Details on eligibility and award amounts have not yet been widely reported.
- 37Ukraine's Supreme Court rules bank need not refund phishing victims●❗️ Шахраї вкрали гроші з картки — банк не поверне їх, якщо ви самі дали доступ до рахунку, — Верховний Суд Жінка втратил
Ukraine's Supreme Court has ruled that a bank is not obliged to return money stolen from a client's card if the client voluntarily gave access to her account. A woman lost almost 43,700 hryvnias after following a phishing link promising 6,500 hryvnias in aid and entering her login details, which gave fraudsters access to her account. The decision signals that responsibility can fall on customers who hand over credentials themselves.
- 38
Phish fans have pooled donations to establish a new music scholarship in Vermont, the home state of the band. The effort shows the fan community organizing around the band's legacy to support young musicians. Details about the scholarship's size, eligibility, and launch date have not yet been widely reported.