Phishing scams: latest cases and how to recognize them
Phishing remains the most common entry point for fraud across Europe. This page tracks recent confirmed cases reported by national CSIRTs and law-enforcement agencies, plus the patterns Mythos has identified in user-submitted messages.
Replying to a 'wrong number' text confirms your number is active and signals you're a polite, responsive person — exactly the profile scammers want. Large-scale operations use AI to hold thousands of...
Quishing , or QR-code phishing, has surged as attackers exploit the fact that QR codes move victims from a protected corporate computer onto a personal phone with weaker security controls. A...
Scammers impersonate legitimate "AML" (anti-money laundering) wallet-screening services such as AMLBot. Victims are invited to "check" their crypto wallet for ties to crime, but the site tricks them...
Dishonest companies buy paid search ads to impersonate legitimate bill payment sites, so a quick search for "pay my [utility] bill" can land you on a look-alike page that funnels your payment to a...
The FBI is warning that criminals are hijacking social media and personal accounts to steal intimate images, then posting or selling them alongside victims' contact details on criminal marketplaces....
The FBI is alerting the public that sexual exploitation actors are targeting adult and underage victims by illegally accessing social media and personal accounts to steal and distribute explicit...
Attackers are cloning the homepages of trusted brands like CNN, Avast, and Stremio to push a "free app" that is actually O&O Syspectr, a legitimate remote-administration tool already linked to the...
Steam hardware buyers across Europe are being warned: a cyberattack on logistics provider CEVA Logistics exposed names, home addresses, phone numbers, and order details for anyone who received a...
A new ready-made kit sold for just $500 lets low-skill operators launch convincing crypto presale scams on X (formerly Twitter). The package impersonates the Tesla brand and presents victims with a...
Scammers are cloning TikTok Shop's look, trust badges, and category layout into standalone websites that have no real connection to TikTok. Users who land on these sites through ads, DMs, or search...
Phishers are increasingly hosting fake login pages on trusted cloud platforms such as Cloudflare Workers, Vercel, Netlify, GitHub Pages and IPFS to steal credentials and bypass multi-factor...
A new WhatsApp scam tricks victims into giving attackers access to their accounts by posing as a friend asking for a vote online. The message—often sent from an already-compromised contact—links to a...
The Greatness phishing-as-a-service platform has added adversary-in-the-middle (AiTM) and device-code phishing flows to steal Microsoft 365 logins. Attackers send emails that appear to come from...
Phishing campaigns are increasingly impersonating AI service providers like ChatGPT, sending fake billing notices timed to the end-of-month billing cycle to pressure victims into "renewing" their...
Fake Walmart sites lure shoppers with 40 to 70 percent off liquor and electronics, then harvest full credit card details at checkout. A network of over 120 lookalike domains shares the same...
FBI Impersonation Scam Targets Previous Fraud Victims The FBI's Internet Crime Complaint Center (IC3) warns of an ongoing scheme in which scammers impersonate FBI personnel to re-victimize people who...
Travelers connecting to hotel or conference Wi-Fi networks are being silently redirected to fake Microsoft 365 login pages. Attackers compromise the Wi-Fi gateway's DNS settings so that the...
Cybercriminals are sending sextortion emails that impersonate the ShinyHunters extortion group, using email addresses exposed in earlier data breaches (Amtrak, Hallmark, Substack, CarGurus, ADT,...