I am speaking at a conference in one of my favorite cities (okay, it’s Chicago) and I was having dinner at the bar when the patron next to me asked me what I do for a living. I am a friendly sort of person and like to meet new people, so I told her what I do and she asked me for three cybersecurity tips. I started with my first one, which is about online banking. After a brief explanation, she commented that I am very scary. No, I am not scary—bad guys and gals make my profession scary.

This Privacy Tip is a bit scary, but it’s not my fault.

Security professionals are all about multi-factor authentication and I am a believer as well. Multi-factor authentication is when there is a second level of authentication to prove that you are actually you and not some hacker who is pretending to be you. Most companies implement multi-factor authentication for consumers to get into sensitive accounts, such as bank accounts, mobile telephone accounts, and other financial accounts where fraud can occur, and organizations use multi-factor authentication for employees to get access to company information. Many companies use customers’ or employees’ mobile telephone numbers for the second authentication and will send a text or code in order to get into the account. The thinking is that you are the only one who has access to your mobile phone and therefore, it is really you and they can trust that it is you and give you access if you have the code.

Well, criminals will continue to come up with ways around security measures, and they have done so with using mobile phone numbers as the second authentication validator.

The fraud is the SIM card swap. Several individuals were arrested recently for using the SIM card swap fraud to steal millions of dollars of cryptocurrency, including one individual who lost over $24 million from a SIM card swap.

Here’s how it works: every cell phone has a SIM card. That’s basically the guts of your phone that makes it work. That SIM card can be popped into any compatible phone, so when you buy a new phone, the SIM card is swapped out to the new phone, so you can use the new phone. A SIM card swap happens when the SIM card of your phone is taken and put into someone else’s phone, and now your phone is hijacked.

Okay, it can’t be done online. But it is done more frequently than you think—with the help of employees at the mobile telephone stores who are paid by the fraudsters to swap the SIM cards.

How do you know if your SIM card has been swapped? Your phone goes dead. And now the criminal has your mobile phone number which has been linked to your bank account, your employer’s VPN, your social media accounts, your music and video accounts, etc. and can change all of the passwords and credentials linked to the mobile phone number.

Three tips to prevent SIM card swapping or limit its risk: 1) Don’t let the employee at the mobile telephone store have access to your SIM card outside of your presence and witness the swap in person; and 2) protect your mobile account from SIM card swapping by activating a personal identification number with your mobile telephone provider; and 3) Don’t attach your mobile telephone number to high risk accounts.

Scary, but better to be armed with solutions than be a victim.

Gift cards are a perennial favorite for holiday shoppers. They’re easy to wrap, universally appreciated, and always the right size. But as gift-giving season approaches, it’s important to remember that gift cards are also a common target for scams. In 2024, Governor Phil Murphy signed into law new requirements governing the sale and display of physical gift cards in New Jersey, aiming to combat the growing threat of gift card fraud. The legislation, P.L.2024, c.39 (S3587), places new obligations on merchants and manufacturers, including prominent consumer fraud notices and specific display protocols. The law applies to both in-person and online sales of physical gift cards. The law took effect October 1, 2025, but the state’s Division of Consumer Affairs has agreed to delay enforcement until February 1, 2026.

The law defines a “retail mercantile establishment” as any place where merchandise is offered for retail sale to the public. The gift card requirements apply to tangible devices with prepaid value issued in exchange for payment that promise the bearer merchandise up to the value of the card.

Key Requirements

One key component of the new legislation is the required Fraud Warning Notice. Retailers in New Jersey must now display a warning notice at the point of sale to inform consumers about the risks of gift card scams. The state requires retailers to display its form notice.

This notice must be posted and maintained at or near any physical location where gift cards are displayed or sold, in clear and conspicuous typeface. For online sales, it must also be provided to any consumer who purchases a physical gift card online by displaying it on the webpage where the gift card is offered for sale or before the sale is finalized.

Under the law, retailers may not display or sell a gift card unless:

  1. The card, or its packaging, prominently displays a tampering warning such as “Do not sell or purchase if the gift card or its packaging has been broken or indicates tampering,” or substantially similar language;
  2. If in packaging, the gift card is sealed so it cannot be easily opened, removed, or replaced without clear signs of tampering; and
  3. All visible sensitive card information (card number, CVV, PIN, etc.) is fully concealed or covered prior to sale.

The law exempts certain cards from the packaging and concealment rules, including chip-enabled, numberless cards that must be activated by the consumer after online registration and cards sold exclusively for use at one retailer and secured so only employees can access them.

In addition, every retail mercantile establishment that sells and displays gift cards in New Jersey must train employees on how to identify and respond to gift card fraud in accordance with guidelines issued by the Division of Consumer Affairs.

Violations of the display/packaging requirements or training requirements are subject to a civil penalty of $1,000, enforceable by the Director of the Division of Consumer Affairs. However,

violations are not considered “unlawful practices” under the broader New Jersey Consumer Fraud Act, so they do not trigger a private rights of action.

Takeaways

Given the sustained rise in gift card scams targeting consumers nationwide, New Jersey’s law underscores a growing policy trend to involve retailers more directly in fraud prevention. To prepare, retailers should begin by updating signage in stores and online platforms to ensure that the required Consumer Fraud Notice is clearly visible at all gift card display and sales locations and at every point of online sale, using the official language provided by the Division of Consumer Affairs. It’s also important to review all gift card packaging and display practices, making sure cards are sealed securely in tamper-evident packaging, warning labels about tampering are visible, and that all sensitive card details are fully concealed prior to sale. Retailers should also develop or update employee training to equip all staff involved in the sale or handling of gift cards with the knowledge to detect, prevent, and respond to potential fraud. Reviewing gift card offerings and sales protocols now will position retailers for compliance well ahead of the February 2026 enforcement deadline. 

A new commercial has hit the airwaves in Israel. It begins with a door swinging open to reveal a beautiful seaside patio with a couple awaiting their dinners as a voiceover says, “How much have we missed going out with friends?” Well, with the Green Pass “a door simply opens in front of you” and we can “return[ ] to life.” This commercial is advertising Israel’s version of a digital vaccine passport.

Although there are still lots of unknowns, there are many countries and industries considering vaccine passport programs like Israel’s, including  Japan, the United Kingdom and the European Union, as well as airlines and some concert venues, to name a few.

Israel’s vaccine passport was released on February 21.  There, vaccinated people can download an app that displays their Green Pass when they are asked to show it. The app also can display proof that someone has recently recovered from COVID-19, which also allows passage. Other proposed ”passport systems” offer several ways to show you are not a threat, such as proof of a negative COVID-19 test. Israel hopes this technology will encourage more citizens to get vaccinated.

However, the Green Pass and other passport programs may also bring up some big privacy concerns. Orr Dunkelman, a computer science professor at Haifa University, says that the Green Pass displays more information than simply whether the individual has been vaccinated or has recently recovered from COVID-19. The pass also displays the date of the recovery and the date of the vaccine and uses outdated encryption technology that is potentially vulnerable to security breaches and hackers. Orr also says that because the app is not open source, no third parties can test whether these concerns are founded.

In the United States, PathCheck Foundation at MIT is working with Ideo on a low-tech solution that may address these privacy concerns before any kind of ”passport” is available here. The prototype uses a paper card similar to the one that individuals are currently receiving once they are vaccinated. However, to avoid fraudulent cards, the paper card being developed by PathCheck Foundation and Ideo would use multiple forms of verification such as QR codes for scanning (maybe at the gate of a concert or movie theater entrance) that only displays an individual’s vaccination status, while other entities (such as health care providers) would be able to scan the card and receive more detailed information (e.g., the type of vaccination received, the date, the location it was administered, etc.). Additionally, PathCheck Foundation points out that privacy is important to those who are undocumented or simply don’t have trust in the government, and we don’t want to create yet another repository that is hackable (and may potentially contain entire state populations).

At this point, it isn’t clear whether the United States will be able to implement a vaccine passport quickly because we don’t have a universal identity record or federal medical records system (which Israel does). However, whichever option eventually becomes widespread across the country, it will need to use a system that will be able to maintain certain individual privacy rights while also allowing businesses and venues to reopen safely.

It’s hard to believe that today’s post marks the publication of our 500th Privacy Tip. What a milestone!

We started publishing Tips because readers kept asking me about ways to protect themselves from scams, how to keep up with the latest threats, and how to stay informed about emerging technology. Feedback has been overwhelmingly positive, so we will continue publishing the Tips and helping readers navigate the technology landscape—an environment that often feels like the Wild West, with new developments emerging every day.

To commemorate the 500th Privacy Tip, I thought it apropos to recap the top ways to protect your privacy from a cybersecurity perspective.

  1. Update your devices with patches as soon as you get the notice from the manufacturer. Patching is necessary to protect your device from vulnerabilities.
  2. Maintain strong passphrases and change them often.
  3. Use multi-factor authentication on all your online accounts but beware of multifactor authentication fatigue.
  4. Limit use of public Wi-Fi networks and use virtual private networks whenever possible.
  5. Obtain your free credit report frequently to catch any fraudulently opened accounts .
  6. Properly dispose of all electronic devices, including SIM cards.
  7. Beware of imposter scams.
  8. Strengthen children’s privacy.
  9. Don’t give personal information to a generative AI tool.
  10. Beware of, and protect yourself from, threat actors using AI in attacks.

We hope these Tips continue to educate and provide practical solutions for navigating the rapidly evolving risk landscape that technology and AI create in our lives. To dive deeper into putting these Tips to work, check out this guide. We look forward to to providing another 500 practical tips on how to stay safe.

Interpol recently announced that it arrested 260 cybercrime suspects across 14 African countries in an operation dubbed Operation Contender 3.0 that targeted criminal networks involved in global romance scams and sextortion schemes.

According to Interpol, the operation dismantled 81 cybercrime infrastructure networks across Africa, with the seizure of USB drives, SIM cards, and forged documents that affected 1,500 victims with losses of up to $2.8 million.

The suspects used fake profiles, forged identities, and stolen images using different schemes, including “fake courier and customs shipment fees, and sextortion for blackmail.”

Romance scams and sextortion schemes continue to increase, affecting millions of victims. These schemes affect individuals of all ages and genders.

Here are some helpful resources to review to avoid becoming a victim:

On July 29, 2025, the Cybersecurity & Infrastructure Security Agency (CISA), along with the Federal Bureau of Investigation, Canadian Centre for Cyber Security, Royal Canadian Mounted Police, the Australian Cyber Security Centre’s Australian Signals Directorate, and the Australian Federal Police and National Cyber Security Centre, issued an updated advisory on threat actor Scattered Spider, which is presently “targeting commercial facilities sectors and subsectors.”

The advisory includes actions “to take today” to mitigate an attack from threat actors:

1.  Maintain offline backups of data that are stored separately from the source systems and tested regularly.

2.  Enable and enforce phishing-resistant multifactor authentication (MFA).

3.  Implement application controls to manage and control software execution.

According to the advisory, Scattered Spider is engaged in data theft for extortion and uses various ransomware variants, including DragonForce. Scattered Spider threat actors have continuously changed their tactics, techniques, and procedures (TTPs) “to remain undetected.”

The threat actors associated with Scattered Spider have targeted “large companies and their contracted information technology (IT) help desks.” The methods used include:

  • Posing as company IT and/or helpdesk staff using phone calls or SMS messages to obtain credentials from employees and gain access to the network.
  • Posing as company IT and/or helpdesk staff to direct employees to run commercial remote access tools enabling initial access.
  • Posing as IT staff to convince employees to share their one-time password (OTP), an MFA code.
  • Posing as employees to convince IT and/or helpdesk staff to provide sensitive information, reset the employee’s password, and transfer the employee’s MFA to a device they control on separate devices.
  • Sending repeated MFA notification prompts leading to employees pressing the “Accept” button (also known as MFA fatigue).
  • Convincing cellular carriers to transfer control of a targeted user’s phone number to a SIM card in their possession, gaining control over the phone and access to MFA prompts.
  • Monetized access to targeted organization’s networks in numerous ways including extortion enabled by ransomware and data theft.

The impersonation of company employees or IT professionals continues to be a successful way for threat actors, including Scattered Spider, to attack. It is important that employees are wary of requests from IT staff and to be highly suspicious of any request for credentials. It is critical that help desk staff and subcontractors who staff the help desk after hours are aware of the methods threat actors are using against them.

CISA and its partners provided the most recent TTPs of Scattered Spider, including that it is targeting the “organization’s Snowflake access to exfiltrate large volumes of data in a short time, often running thousands of queries immediately.” In addition, they create “new identities in the environment … often upheld with fake social media profiles to backstop newly created identities. Scattered Spider threat actors consistently use proxy networks and rotate machine names to further hamper detection and response.” Scary stuff.

A recent mitigation includes, “Look for ‘risky logins’ within environments where sign-in attempts have been flagged as potentially compromised due to suspicious activity or unusual behavior.”

The advisory is full of useful information and mitigations that are worthy of urgent consideration.

According to Security.org, “every 4.9 seconds, someone becomes a victim of identity theft in the United States” and the Federal Trade Commission receives over 6.4 million reports of identity theft and fraud every year.

Identity theft incidents continue to climb, with the average amount lost reaching $400 per person. The highest number of cases are attributed to financial fraud, including credit card fraud, including stolen credit cards and opening fraudulent new accounts, and fraudulent bank transfers.

Interestingly, age and residence have an impact on the prevalence of identity theft. Millennials are hit the hardest, with 42% of millennials becoming identity theft victims, compared to 24% of Generation X, 21% of Generation Z, and a mere 11% of Baby Boomers. That said, Baby Boomers suffer the largest losses per incident due to bank account fraud. If you live in Florida, you are at higher risk, which contrasts with South Dakota, which has the lowest geographic risk.

Security.org suggests that simple measures can be taken to prevent identity theft, including checking your credit report, setting up account alerts, and reviewing privacy settings on social media accounts. Additional measures I’d like to include are:

  • multi factor authentication on all financial accounts;
  • checking explanation of benefit statements;
  • being wary of vishing, phishing, smishing, and quishing requests;
  • avoiding providing your credentials to anyone;
  • avoiding any money transfer authentication through email;
  • limiting sharing on social media; and
  • staying informed of new fraud techniques.

An analysis by the Federal Trade Commission (FTC) shows that, since 2020, consumers have been swindled out of $65 million by rental scams. This statistic is particularly relevant during the holiday season when many people are traveling and renting places to stay.

According to the FTC, most of the scams involve fake rental listings on Facebook or Craigslist. The listings look real and copy information from legitimate listings like Air BnB and VRBO. Interestingly, “people ages 18 to 29 were three times more likely than other adults to report losing money to a rental scam.”

The scammers are able to swindle the victims by:

  • pressuring consumers to provide money upfront before seeing the rental property in person;
  • pushing consumers to prove they are creditworthy by sending screenshots of their credit scores. They send consumers affiliate links to websites to sign up for a credit check for little cost, but this may enroll the consumer in a paid membership with recurring fees; and
  • collecting personal information from consumers such as their Social Security number, driver’s license or paystubs to steal their identity.

Tips to avoid being scammed include:

  • search for the rental address online to see if the same property is listed with different prices, contact information, or is listed as being for sale;
  • avoid sharing personal information, particularly Social Security number, passport number or driver’s license number;
  • avoid sharing banking information that allows direct access to your bank account;
  • avoid providing financial information until they have agreed to rent a property and use a credit card;
  • avoid paying the full amount for the rental up front; and
  • check out typical rents paid in the area. If the advertised rent of a listing is much cheaper than rents for similar rentals in the same area, that could be a sign of a scam and a red flag.

Safe travels over the holidays and stay vigilant to avoid a rental scam.

The holidays are always a busy time—sending holiday cards, cooking, present shopping and giving, and spending time with family and friends. It’s also an opportune and busy time for scammers too.

A new report by KrebsonSecurity reminds us that fraudsters use the holidays to launch new campaigns, in this case, SMS phishing scams. According to Krebs, phishing groups out of China are promoting phishing kits designed to create “fake but convincing e-commerce websites that convert customer payment card data into mobile wallets from Apple and Google. Experts say these same phishing groups also are now using SMS lures that promise unclaimed tax refunds and mobile rewards points.”

To illustrate the point, Krebs notes that “Over the past week, thousands of domain names were registered for scam websites that purport to offer T-Mobile customers the opportunity to claim a large number of rewards points. The phishing domains are being promoted by scam messages sent via Apple’s iMessage service or the functionally equivalent RCS messaging service built into Google phones.” The phishing websites load when the recipient visits it with a mobile device, and the scammers ask the user for their name, address, telephone number and payment card data to claim the points.

Once the card data is provided, the malicious site then asks the user to share a one-time code sent via SMS text by their bank. When the user provides the code, the fraudster can then enroll the card details in a mobile wallet and link the card to a mobile device they control. In fact, the SMS text is sent to the user from the bank because the scammers attempted to enroll the credit card details into a mobile wallet and the bank is alerting the user. It’s a very clever way to get around multi-factor authentication. This scam is targeting both T-Mobile and AT&T customers.

In addition to the points scam, the fraudsters are also spoofing tax authorities, “telling recipients they have an unclaimed tax refund. Again, the goal is to phish the user’s payment card information and one-time code.”

They are also targeting e-commerce sites. In this case using a similar scam to set up a fake e-commerce storefront and advertise it through Google and Facebook, offering consumers deals on certain items. When the user “purchases” an item from the fake website, they provide their personal information and payment card information during checkout. The shopping site then requests a one-time code from their bank “to verify the transaction,” when in fact the scammers send it so they can enroll the card data in a mobile wallet. Customers don’t know they have been victimized until weeks later when they have not received the purchased item.

Krebs also offers tips for the holiday season.

To brush up on more holiday shopping tips, check out these previous posts (Privacy Tips 12, 166, 261, 262, 264, 308, 382, and 425) which are still applicable.

The Telephone Consumer Protection Act of 1991 (TCPA) is a federal law designed to protect consumers from unwanted telemarketing and intrusive solicitation practices. Many states have also enacted similar state laws governing telephone solicitations, so called “mini-TCPAs.” One such state is Texas, which has had a mini-TCPA in place since 2009.

The Texas mini-TCPA applies to businesses which engage in telemarketing from Texas or who telemarket to Texas residents. Senate Bill 140 recently passed in Texas, which amends the state’s telemarketing law in several significant ways. In this post, we outline the Texas mini-TCPA’s existing requirements, highlight the changes taking effect soon, and offer guidance for businesses on next steps.

Texas Mini-TCPA Overview

The Texas mini-TCPA statute is found across Chapters 301-305 of the state’s Business and Commerce Code.

Chapter 301 – Sales Call Requirements

Chapter 301 covers several requirements for telephone solicitors making sales calls, including:

  • Immediately providing the called party with the business name and an explanation of the call’s purpose;
  • Timing restrictions of 9am to 9pm from Monday through Saturday, and between 12pm-9pm on Sundays; and
  • If an autodialer is used to make a call, it must disconnect the consumer’s telephone line within 5 seconds after the call ends.

Chapter 301 also includes restrictions for businesses who make or submit a charge to consumers’ credit card accounts.

Texas’ definition of “automated dial announcing devices” (ADADs) is similar to the federal TCPA definition of an autodialer.

Similarly to the federal TCPA, the solicitation requirements do not apply to calls made in response to the consumer’s express request, in connection with an existing debt or contract where payment is incomplete, or where there is an existing business relationship with the consumer.

Chapter 302 – Registration Requirements

One of the most onerous requirements of the Texas mini-TCPA is that businesses soliciting in Texas must file a registration statement before making any solicitation from the state or to anyone in the state. The registration fee is $200 per business location and must be accompanied by a security deposit in the amount of $10,000 to cover payment of any penalties in the case of a violation. There are several ways for businesses to make the security deposit, including via surety bond and a certificate of deposit.

In addition, businesses must file a supplemental addendum to the registration statement every quarter and if there is a material change to the information submitted in a registration statement. Violations of Chapter 302 requirements could lead to up to $5,000 in civil penalties per violation.

Certain entities are exempt from the registration requirement, including educational and nonprofit organizations, companies that market food, and some brick-and-mortar chains. Entities regulated by other laws, such as publicly traded companies registered with the Securities and Exchange Commission, financial institutions, and businesses governed by the Commodity Futures Trading Commission, are also excluded from the registration requirement. The registration requirement also does not apply to solicitation of former or current customers.

Chapter 303 – Law Enforcement-Related Charitable Organizations

Special rules apply to law enforcement-related charitable organizations. These rules, however, do not apply to governmental law enforcement agencies themselves.

Chapter 304 – Do Not Call Rules

Businesses may not make telemarketing calls to telephone numbers published on the state’s no-call list. Consumers on the no-call list who receive more than one telemarketing solicitation are afforded a private right of action.

The chapter also lists requirements for facsimile telemarketing (which is now outdated and becoming largely obsolete) as well as a prohibition on businesses interfering with caller identification. Violations of Chapter 304 could result in civil penalties of up to $1,000 per violation.

Furthermore, under this chapter, businesses may not make telephone calls or use ADADs to make a sales call if the person making the call knows the recipient will be charged and if the called person has not consented to such a call. Chapter 305 violations could result in civil penalties ranging from $500 to $1,500 per violation.

September 2025 Amendments

Texas lawmakers recently passed amendments to the act, which take effect on September 1, 2025. The new amendments make some important changes, such as:

  • Inclusion of text messages for registration requirement – The amendments clarify that the term “telephone solicitation” for the purpose of the registration requirement in Chapter 302 includes “a transmission of a text or graphic message or of an image.” The nature of telemarketing has evolved significantly in the past decade, with businesses increasingly relying on text messaging for consumer marketing rather than phone calls. Previously, it was unclear whether businesses engaging in text messaging solicitations to Texas residents would need to register with the Secretary of State. The amendments clarify that such businesses are covered under the registration requirement of Chapter 302.
  • Tie-in to Deceptive Trade Practices Act (DTPA) – The amendments also allow for a more robust private right of action by allowing plaintiffs to seek remedies available under the Texas unfair and deceptive trade practices law for violations of Chapters 304 and 305. Available remedies under the DTPA include treble damages, mental-anguish damages, and mandatory attorneys’ fees. We anticipate increased class action because of this expansion of the private right of action.
  • Multiple recovery permitted – The amendments add language to Chapters 302, 304, and 305 that allows for claimants to recover on multiple counts in a private action, noting that “the fact that a claimant has recovered under a private action arising from a violation of this chapter more than once may not limit recovery in a future legal proceeding in any manner.” This clarification, too, is likely to result in a rising volume of telemarketing-related class actions in the state.

What’s Next?

The amendments will broadly impact businesses marketing to or from Texas. Businesses should consult with legal counsel regarding whether they are required to register. Although Section 302 exempts businesses who only telemarket to former or current customers, one of the biggest compliance challenges for the federal TCPA has been with wrong or reassigned numbers. Consider the case of a consumer accidentally providing the incorrect cell phone number and the business’ marketing text message reaching the wrong person who did not consent to the call. Similarly, a consumer may provide her correct phone number at the time of collection, but the number could be later reassigned. The businesses’ text message now reaches another individual who is not a former or current customer. Such instances could create significant liability with Texas’ mini-TCPA, especially in light of the expanded right of recovery now available to plaintiffs. The Texas mini-TCPA has long been recognized as one of the more stringent state telemarketing laws, and the new amendments raise the stakes considerably. If your business markets in Texas, now is the time to make telemarketing compliance a priority.