A new report by Wired states that customer data from “more than 350 hotels around the world may have been accessed as part of realistic reservation-hijacking scams.” According to the report, travelers’ information and booking data may have been stolen from the hotels and are being used by threat actors to launch social engineered phishing
Privacy Tip #494 – Signal Users Targeted with Phishing Scam
If you are a Signal user, be on the alert for a new phishing campaign that attempts to steal recovery keys used to access cloud backups.
If successful, the attackers could have access to entire message archives, conversations, photos and documents shared through the Signal platform. Signal is often used for highly sensitive communications, so…
Privacy Tip #489 – Social Media Scams #1 in 2025
The Federal Trade Commission (FTC) recently reported that, in 2025, social media scams were the costliest of all scams against consumers, with a whopping $2.1 billion lost. Thirty percent of those who reported losing funds in 2025 indicated that the scam started over social media.
The number of 2025 scams beginning on social media increased…
Privacy Tip #488 – Account Change Phishing Alerts from “Apple” Are Tricking Users
A new, yet old, scheme has been quite successful and users should beware. If you get an account change message from Apple, be on high alert that it is fake and malicious.
According to Bleeping Computer, the scheme involves a threat actor using an Apple support email (e.g., appleid@id.apple.com) to send phishing emails to…
Privacy Tip #485 – Preventing Identity Theft
According to Security.org, “every 4.9 seconds, someone becomes a victim of identity theft in the United States” and the Federal Trade Commission receives over 6.4 million reports of identity theft and fraud every year.
Identity theft incidents continue to climb, with the average amount lost reaching $400 per person. The highest number of cases are…
ShinyHunters Bypassing Multifactor Authentication
Security professionals rely on the implementation of multifactor authentication (MFA) to defend against phishing attacks and intrusions. Unfortunately, we can’t completely rely on MFA to protect us as threat actors (more specifically, ShinyHunters) are now targeting companies in technology, financial services, real estate, energy, healthcare, logistics, and retail with synchronized vishing-phishing attacks.
The newest attacks…
FBI Warns of Increase in AI-Generated Impersonations of Senior U.S. Officials
On December 19, 2025, the Federal Bureau of Investigation (FBI) published an Alert warning the public that it has data from as far back as 2023 that “malicious actors have impersonated senior U.S. state government, White House, and Cabinet level officials, as well as members of Congress to target individuals, including officials’ family members and…
Universal Music Group Takes Center Stage with Recent California Court Narrowing of CIPA Class Action
The recent decision in Wiley v. Universal Music Group highlights how courts are scrutinizing website operators’ privacy controls and representations, particularly regarding cookie banners and opt-out tools. 2025 WL 3654085 (N.D. Cal. Dec. 17, 2025). In a recent decision, although Universal Music Group (UMG) dodged most of the putative class claims over its handling of…
Privacy Tip #473 – Rental Scams Fleecing Consumers Out of $65 Million
An analysis by the Federal Trade Commission (FTC) shows that, since 2020, consumers have been swindled out of $65 million by rental scams. This statistic is particularly relevant during the holiday season when many people are traveling and renting places to stay.
According to the FTC, most of the scams involve fake rental listings…
FBI Warns of Account Takeover Fraud
On November 25, 2025, the Federal Bureau of Investigation (FBI) published a Public Service Announcement warning that cyber criminals are “impersonating financial institutions to steal money or information in Account Takeover (ATO) fraud schemes.” These schemes target individuals and businesses of all sizes across all sectors. According to the announcement, “Since January 2025, the FBI…