// Blog

Browser security, without the fluff

Guides from the team building SafeBrowz. Phishing, wallet drainers, scam emails, and the browser-side protections that actually work.

BREAKING · FBI ADVISORY

FBI warns of FIFA World Cup 2026 ticket scam: 300+ Ghost Stadium phishing sites explained

FBI PSA260527 (May 27, 2026): Chinese-linked Ghost Stadium operates 300+ lookalike FIFA ticket sites harvesting card and PII data. Our 3-layer detection on typosquat domains + brand-pivot predictions (Olympics 2028, Champions League).

15 min read
Read post →
BREAKING · FBI ADVISORY

FBI Kali365 warning 2026: why OAuth device-code phishing slips past MFA

FBI PSA260521 (May 21, 2026): new Microsoft 365 phishing-as-a-service hijacks accounts via OAuth device-code abuse, bypassing MFA entirely. Our 3-layer detection analysis + what enterprises do right now.

15 min read
Read post →
NEW · UK GOV PHISHING

HMRC tax refund email scam: how UK taxpayers are tricked out of Government Gateway credentials in 2026

UK's #1 phishing topic — HMRC reports 200K+ complaints/year. Fake "£342.78 tax rebate" emails + Self Assessment lures + Marriage Allowance traps. Verify with Gov.uk Gateway only. Recovery via Action Fraud + Cifas.

12 min read
Read post →
NEW · UK GOV PHISHING

DVLA vehicle tax scam: how fake car tax payment failures steal UK driver details in 2026

"Your vehicle tax payment failed — £1,000 fine + clamp threat" SMS/email. DVLA never asks for payment by SMS. Lookalike domains (dvla-payment[.]uk). Verify via gov.uk/check-vehicle-tax. Recovery + Action Fraud.

11 min read
Read post →
NEW · UK GOV PHISHING

TV Licensing scam UK: how the "your licence has expired" email trap works in 2026

Fake TV Licensing emails: "Licence expired", "Direct Debit failed", refund offer, over-75 free-licence trap. TV Licensing won't ask for personal/payment info by email. Verify via tvlicensing.co.uk/check-it-s-us.

11 min read
Read post →
NEW · CANADA GOV PHISHING

CRA tax refund scam Canada: how $50M+ is stolen from Canadians in 2026

RCMP 2024: $50M+ CRA impersonation losses. Fake "$428.50 refund" emails + aggressive "send Bitcoin to avoid arrest" voicemails. Verify only via CRA My Account. Recovery via CAFC + credit freeze.

12 min read
Read post →
NEW · CANADA GOV PHISHING

Service Canada SIN scam in 2026: "your SIN has been suspended" is a lie, every time

Top scam targeting Canadian newcomers + seniors. Automated voicemail "SIN suspended" → fake officer → SIN/banking/identity extraction. Hang-up + look-up + call-back rule. Service Canada fraud + IDCare recovery.

12 min read
Read post →
NEW · AUSTRALIA GOV PHISHING

ATO tax refund scam Australia (2026 guide): how fake refunds and TFN traps work

ATO reports 30K+ phishing reports/year. Peak Jul-Sep (Australian tax year). Fake "$1,247 refund ready" + TFN suspension + BAS overdue templates. Verify only via myGov inbox + ATO ID 13 28 61.

13 min read
Read post →
NEW · AUSTRALIA GOV PHISHING

myGov account locked scam Australia 2026: the phishing trap that steals Medicare + Centrelink

One myGov password = access to Medicare, Centrelink, ATO, Immigration. Fake "account locked" emails route to phishing copies of my.gov.au. Verify only via my.gov.au. Recovery via Services Australia + IDCare.

13 min read
Read post →
NEW · FRANCE GOV PHISHING

Impôts.gouv tax refund scam France 2026: fake DGFiP refunds explained for expats

Cybermalveillance.gouv.fr 2024: €100M+ losses. Fake "Remboursement Impôts 384€" emails + Crédit d'impôt PAJE + TVA refund templates. Verify only via impots.gouv.fr espace particulier. EN guide for expats.

14 min read
Read post →
NEW · FRANCE GOV PHISHING

Ameli health insurance scam France 2026: fake Carte Vitale renewal explained for expats

French Assurance Maladie phishing top-5 in 2024. Fake Carte Vitale renewal + IBAN confirmation + refund-pending templates. Verify only via ameli.fr account. Recovery via 3646 + Cybermalveillance.gouv.fr.

13 min read
Read post →
NEW · FRANCE MARKETPLACE

Vinted + Leboncoin fake buyer scam France 2026: the "Vinted Pro secure link" trap explained

France's top consumer scam 2024 per Cybermalveillance. Fake "Vinted Pro" / "Leboncoin Securité" payment links route to phishing pages that drain seller cards. Vinted never uses external payment links.

12 min read
Read post →
NEW · PAYMENT FRAUD

Zelle fraud alert text scam: how the "did you authorize this transfer?" trick steals $440M (2026)

FBI's #1 P2P payment scam. Fake bank fraud-alert text + impersonator call walks victim through sending money "to themselves" via Zelle. Irreversible. $440M+ losses 2024. Recovery + protection steps.

12 min read
Read post →
NEW · GIVEAWAY SCAM

Cash App $750 free scam: how #CashAppFriday giveaway DMs drain accounts in 2026

Gen Z's #1 scam: fake celebrity-endorsed giveaways tag victims on TikTok/IG, then ask for "verification fee" or steal Cash App login. FTC 2024: $1.9B in social-media-contact fraud. 7 red flags + recovery.

11 min read
Read post →
NEW · PAYMENT FRAUD

Venmo "I sent you money by accident" scam: the chargeback trap explained (2026)

Scammer sends Venmo from stolen card, asks for refund. Days later card transaction reversed = victim loses everything. FTC 2024 P2P fraud $1.1B. Why Venmo has no purchase protection on peer-to-peer.

12 min read
Read post →
NEW · PAYMENT FRAUD

Apple Pay "request for payment" scam: how to spot it (2026)

Fake iCloud renewal + hijacked friend Apple Pay requests + "Apple Cash from Apple" wrong-direction scams. FBI IC3 2024: mobile payment fraud +87% YoY. Recovery steps + Apple Pay protection settings.

11 min read
Read post →
NEW · BANK PHISHING

Chase Bank phishing email scam: how to spot fake fraud alerts and login traps in 2026

Largest US bank (80M+ customers, $2.4T deposits) = biggest phishing target. Fake "suspicious login from Chicago" alerts + lookalike domains (chase-secure[.]com). FBI IC3: $1.2B bank-impersonation losses.

11 min read
Read post →
NEW · GAMING SCAM

Steam trade hijack scam: how CS skin theft and session-token attacks work in 2026

132M+ Steam users, $40B+ skin economy = massive target. Fake friend DM → phishing Steam login → session token steal bypasses SteamGuard 2FA. Valve doesn't restore most stolen items. Recovery flow.

13 min read
Read post →
NEW · GAMING SCAM

Roblox account hijack: a parent's 2026 guide to free Robux scams and account theft

70M+ daily users, mostly kids 8-17. "Free Robux" sites, Discord DM trades, OAuth phishing. 1M+ accounts compromised 2024. Written for parents to share with kids. Recovery + 2-step verify setup.

13 min read
Read post →
NEW · BRAND IMPERSONATION

Twitter/X blue verification scam: how the $8 checkmark phishing trap works in 2026

Fake X Premium suspension emails + @SupportTeam DM impersonators steal logins and payment info. Lookalike domains: x-premium[.]help, twitter-secure[.]net. 600M+ MAU = massive attack surface.

12 min read
Read post →
NEW · B2B PHISHING

Slack workspace invite phishing: the new B2B credential trap of 2026

Fake "[Company] invited you to Slack" emails route to phishing login pages capturing SSO + OAuth tokens. Initial access for ransomware crews. 65M+ daily users, 200K+ paid orgs targeted. Verify in 60s.

11 min read
Read post →
NEW · B2B PHISHING

Dropbox shared file phishing: how legit-link phishing bypasses email security in 2026

Attacker uploads phishing HTML to Dropbox, sends real "shared a file" link. Passes SPF/DKIM/DMARC because dropbox.com IS the sender. 700M+ users at risk. Detection + 2FA + sharing-settings guide.

11 min read
Read post →
NEW · BRAND IMPERSONATION

Hulu account locked email scam: how to spot the fake suspension notice in 2026

Fake Hulu "subscription suspended due to payment problem" emails target 50M+ subscribers. AiTM proxy captures credentials + 2FA. Variants exploit Disney+/ESPN+ bundle confusion. 7 red flags + 5-step verification + recovery flow.

10 min read
Read post →
NEW · BRAND IMPERSONATION

HBO Max account locked email scam: how to spot the fake suspension notice in 2026

The Max (formerly HBO Max) account-locked email exploits the real Warner Bros Discovery rebrand confusion. Fake billing failure + AiTM proxy login. 7 red flags + recovery flow if you clicked.

11 min read
Read post →
NEW · BRAND IMPERSONATION

Peacock account locked email scam: how to spot the fake suspension notice in 2026

NBC Universal Peacock subscribers targeted with fake "billing failure" emails. Olympics + live sports access bait. 3 tier confusion (Free/Premium/Premium+) exploited. Recovery flow if card details entered.

10 min read
Read post →
NEW · BRAND IMPERSONATION

ESPN+ billing scam email: how to spot the fake subscription renewal notice in 2026

Sports fans targeted with fake ESPN+ "subscription failed before the big game" emails. UFC/F1/MLB PPV access bait drives panic. Disney bundle confusion exploited. 7 red flags + verification flow.

10 min read
Read post →
NEW · BRAND IMPERSONATION

Paramount+ subscription scam email: how to spot the fake billing failure in 2026

Star Trek + Yellowstone fans targeted with fake Paramount+ "subscription failed" emails. 2024 Showtime merger confusion exploited. Fake "annual plan switch" promo variants. Recovery flow.

11 min read
Read post →
NEW · B2B TUTORIAL

Add phishing detection to your AI agent: Hermes Agent, LangChain, AutoGen, CrewAI (2026 tutorial)

Real-time phishing detection for AI agents via SafeBrowz API. Working code examples for 7 frameworks (Hermes Agent, LangChain, AutoGen, CrewAI, OpenAI Assistants, Anthropic Claude, raw HTTP). $0.001 USDC per call via x402 on Solana/Base.

12 min read
Read post →
NEW · BRAND IMPERSONATION

Instagram verification badge scam: how "apply for verification" DMs steal accounts in 2026

Fake "Meta Verified team" DMs promise a blue check for $4.99 or via an "eligibility form". The real Meta Verified is only via Settings → Accounts Center - never via DM. 7 red flags, 5-step verification, full account recovery flow.

10 min read
Read post →
NEW · GAMING + CRYPTO

Discord Nitro free scam: how fake "gift link" DMs steal accounts and crypto in 2026

DM from a friend's hijacked account offering free Nitro / Steam keys. Lookalike domains, QR-login hijack, NFT-server raid variants that drop wallet drainer pages. Why gamers + crypto holders are the gold targets - and the 2FA defense that stops it.

10 min read
Read post →
NEW · CREATOR THREAT

YouTube copyright strike scam email: how fake DMCA notices steal creator accounts in 2026

"Your channel will be terminated in 24 hours" emails target monetized creators. Linus Tech Tips 2023 hijack case. Info-stealers (Redline, LummaC2) bypass 2FA via session cookies. Hardware-key MFA + Studio-only strike verification.

10 min read
Read post →
NEW · BRAND IMPERSONATION

Disney+ account locked email scam: how to spot the fake suspension notice in 2026

"Your Disney+ subscription has been suspended" emails ride the real household-sharing crackdown news. Variants for Hulu, ESPN+, HBO Max, Peacock, Paramount+. 7 red flags, in-app verification, recovery flow including reused-password rotation.

10 min read
Read post →
NEW · BRAND IMPERSONATION

Spotify account suspended email scam: the fake Premium cancellation phishing of 2026

Targets 650M+ Spotify users with fake "payment failed" panic emails. Family-plan-member-removed variant, HiFi tier upgrade, refund offer. Real billing issues only show in-app banner. Same template used by Apple Music, YouTube Music, Tidal.

10 min read
Read post →
NEW · MALWARE INSTALL

Fake Chrome update scam: how the "your browser is outdated" popup installs malware in 2026

SocGholish / FakeUpdates framework injects fake Chrome update popups via compromised legitimate sites. Drops Redline + LummaC2 info-stealers that target MetaMask/Phantom wallet extensions. Real Chrome updates are ALWAYS silent + automatic. Never via website download.

10 min read
Read post →
NEW · BUSINESS EMAIL

DocuSign phishing scam: how fake signature requests steal business credentials in 2026

#2 most-clicked theme in corporate environments per Mandiant 2024. "[Coworker] sent you a document" leads to fake M365 / Google Workspace login. Variants: BEC pivot, fake HR onboarding, fake vendor invoice. Hardware-key MFA defeats AiTM proxy.

10 min read
Read post →
NEW · MOBILE MALWARE

Fake bank app Android APK scam: how WhatsApp SMS drops malware on phones in 2026

"Your bank app needs updating" WhatsApp link drops banking trojan (Anatsa/Hook/BlackRock/Cerberus). Accessibility Service permission overlays fake login on real bank app, reads SMS OTPs, executes silent UPI/IMPS/Pix transfers. Huge in India, SEA, Brazil, Nigeria.

10 min read
Read post →
NEW · BRAND IMPERSONATION

iCloud "signed out from all devices" scam email: how to verify it's actually from Apple in 2026

Different from Apple-locked variant - triggers "did someone steal my account?" panic. AiTM proxy captures 6-digit 2FA in real-time. Attackers reset recovery email then Mark as Lost your iPhone via Find My. iCloud Keychain = every saved password gone.

10 min read
Read post →
NEW · MARKETPLACE FRAUD

eBay and Marketplace Zelle scam: how "send me Zelle for the iPhone" steals thousands in 2026

$440M+ Zelle fraud reports 2024 per FTC. Seller scam (buyer reverses Zelle after shipping). Buyer scam (deposit then disappears). Why Zelle is the riskiest p2p payment. Safe alternatives: PayPal Goods & Services, eBay Managed Payments. CFPB Reg E protections.

10 min read
Read post →
NEW · AI THREAT 2026

AI voice cloning vishing scam: how scammers fake your family's voice to steal money in 2026

3 seconds of audio from social media is enough to clone a voice. FBI's fastest-growing phone scam. The grandparent scam, fake kidnapping, CEO fraud playbook — plus the "safe word" defense that stops it cold.

10 min read
Read post →
NEW · AI THREAT 2026

AI-written phishing emails are now grammatically perfect: 7 new tells to spot ChatGPT-crafted scams

The old "bad grammar = scam" rule is dead. ChatGPT writes phishing emails with perfect English in any language. The 7 new red flags security researchers actually use in 2026 — sender domain, payment rail, link mouseover, thread history.

10 min read
Read post →
NEW · FBI ACTIVE ALERT

Unpaid toll text scam (E-ZPass, FasTrak, SunPass): how to spot the FBI's #1 active text scam of 2026

60,000+ complaints to FBI IC3 in months. The "$2.99 unpaid toll" text targets every state — E-ZPass, FasTrak, SunPass, PikePass, TxTag. State-by-state verification table, real toll-notice format, and recovery if you entered card info.

11 min read
Read post →
NEW · BRAND IMPERSONATION

Norton renewal scam email: how to spot the fake $400 auto-charge invoice in 2026

Fake $399 Norton invoice triggers a panic call. Then the "agent" requests remote access via AnyDesk to "process the refund". McAfee, Best Buy, Microsoft Defender variants use the same play. Recovery flow if you already called the number.

10 min read
Read post →
NEW · ACCOUNT TAKEOVER

WhatsApp 6-digit code scam: how strangers hijack your account in 60 seconds and what to do

"Hey I sent a code to your number by mistake, can you share it?" The exact social-engineering playbook that hijacks WhatsApp accounts in under a minute. The two-step verification PIN defense + 30-second recovery flow.

10 min read
Read post →
NEW · CRYPTO THREAT

Telegram admin DM crypto scam: the "support" message that drains your wallet in 2026

You ask a question in a project group. Within minutes, "Admin" DMs you with a KYC link, airdrop form, or recovery prompt. The wallet-drain happens in one signature. How to verify the real admin in 60 seconds — every project's pinned "we never DM first" policy.

10 min read
Read post →
NEW · CRYPTO THREAT

Crypto address poisoning scam: how attackers trick you into sending USDT to the wrong wallet

$1B+ stolen via vanity-address lookups in transaction history. The zero-value transaction trick that puts a malicious address into your wallet's history — so you accidentally copy it next time you send. Real Bitfinex/OKX cases, defense, and the brutal recovery reality.

10 min read
Read post →
NEW · ASIA FRAUD

Telegram task job scam: how the "$300/day easy job" offer becomes a $50,000 loss in 2026

$1B+ lost across Asia in 2024 (UN ODC + Singapore Police data). The fake Amazon/TikTok recruiter, the small payouts that build trust, the "premium tasks" deposit trap, and the sunk-cost lockup. Plus what the Cambodia/Myanmar/Laos scam compounds actually are.

11 min read
Read post →
NEW · ROMANCE FRAUD

Dating app romance scam to crypto: how strangers go from "hi babe" to draining your savings in 6 weeks

FTC says $1.3B lost to romance scams in 2024. The exact 6-week emotional grooming timeline — Tinder/Bumble first contact, love bomb, crisis pivot, then crypto. Why high-income middle-aged singles are #1 targets. Recovery flow including the cut-off-contact reality.

11 min read
Read post →
NEW · CRYPTO BRAND

Coinbase account suspended email: how to verify it's actually from Coinbase in 2026

"Your Coinbase account has been suspended — verify within 24 hours." The AiTM proxy login page, the seed-phrase variant, the 2FA hijack flow. Plus Binance, Kraken, KuCoin, and Gemini variants of the same play. Recovery if you already clicked.

10 min read
Read post →
NEWS · WEB3 THREAT

Vercel free hosting abused for wallet drainer pages — how to spot the *.vercel.app phishing pattern

Vercel's free static-site hosting is one of the top abused platforms for crypto drainer pages. The lookalike-app on a .vercel.app subdomain pattern, why standard phishing blocklists miss it, and the brand-detection signals SafeBrowz uses to catch them.

9 min read
Read post →
GUIDE · GLOBAL FRAUD

Pig Butchering Crypto Scam Explained: the $75 billion romance + trading fraud (2026)

The largest crypto-adjacent scam category in the world. $75B estimated global losses. FBI Operation Level Up + 276 arrests in May 2026. Full 5-stage attack chain, 7 red flags, recovery flow via IC3, and how the approval-phishing endgame connects to Permit2 attacks.

12 min read
Read post →
NEWS · AI THREAT

Jailbroken Gemini AI drained crypto wallets — the bandcampro operation (May 2026)

TrendAI uncovered a Russian-speaking scammer who used jailbroken Google Gemini to automate crypto theft — impersonating a US veteran on a 17K Telegram channel, hacking 29 WordPress admins, and harvesting 40+ wallet addresses from a single victim. Template for the next generation of phishing.

10 min read
Read post →
GUIDE · ACCOUNT TAKEOVER

Amazon "Order Confirmation" Scam Email & Text: how the fake purchase phishing attack works

Amazon is the world's most-impersonated brand in 2026. The "you ordered $1,200 of AirPods" panic email triggers a click before users think. 8 message variants, the URL patterns, and how to recover if you entered your password.

10 min read
Read post →
GUIDE · TAX SEASON

IRS "Tax Refund" Scam Text & Email: how the phishing attack works and how to spot it

IRS named tax refund phishing in its 2026 Dirty Dozen list. Real IRS never initiates contact via text/email. 6 message variants, the QR-code-on-fake-letter angle, and what to do if you entered your SSN.

10 min read
Read post →
GUIDE · SMS PHISHING

FedEx "Missed Delivery" Text Scam: how the smishing attack works and how to spot it

FedEx smishing is the second-most-reported delivery scam after USPS. International shipment + customs duty variants push bigger dollar amounts than USPS. 7 message variants and the 10-second check that catches them all.

10 min read
Read post →
GUIDE · INDIA · WHATSAPP

TRAI "Free Recharge" WhatsApp Scam: how the fake telecom offer steals your bank OTP

India's most-reported phishing scam in 2026. TRAI issued public WhatsApp advisory. 6 message variants (festival-themed, operator-impersonation, government scheme), the OTP-harvesting flow, and recovery via cybercrime.gov.in + 1930 helpline.

10 min read
Read post →
GUIDE · SMS PHISHING

USPS "Failed Delivery" Text Scam: how the smishing attack works and how to spot it

The fake USPS delivery text is the most-reported phishing scam in the US in 2026. 7 message variants in active rotation, what the destination page actually steals, the 10-second check that catches every variant, and what to do if you already clicked.

9 min read
Read post →
NEWS · ACTIVE PHISHING

MetaMask "Mandatory Upgrade" Email Scam: hundreds of wallets drained for $107K+

ZachXBT flagged an active campaign draining hundreds of EVM wallets via a fake MetaMask upgrade email with a party-hat fox logo. Per-victim losses stay under $2K to delay detection. How the email works and how to spot it.

8 min read
Read post →
NEWS · THREAT

Fake Microsoft Popup Scam: DOJ just convicted two executives in 2026

On May 20, 2026 the DOJ secured guilty pleas from Ringba CEO and CSO for enabling tech-support fraud pipelines that drained elderly victims of life savings. Here is exactly how the fake popup → call center scam works and how browser defense stops it at step one.

8 min read
Read post →
CORNERSTONE · PSYCHOLOGY

The 6 emotions every phishing email targets (and the one that always wins)

The hub explainer. Why technical defenses keep losing to phishing. Kahneman's dual-system brain model + Cialdini's influence research applied to every phishing technique. Links to all 27 SafeBrowz attack-specific posts.

13 min read
Read post →
AUTHENTICATION ATTACKS · 2026

How attackers steal your 2FA code even with strong authentication

Microsoft Threat Intelligence: AiTM phishing up 146% in H1 2025. Evilginx2 + Modlishka + Muraena tool families. The reverse-proxy attack that captures password AND 2FA. FIDO2/passkeys are the only protocol-level defense.

11 min read
Read post →
BROWSER ATTACKS · TECHNICAL

The fake login window inside the real browser

Disclosed by mr.d0x in 2022. A phishing page draws a perfect HTML/CSS replica of an OS-level SSO popup INSIDE the page. The HTML/CSS recipe + the 2-second drag test that defeats it + password managers as the strongest defense.

10 min read
Read post →
MFA FATIGUE · AUTHENTICATION

47 fake login notifications until you tap "allow" just to stop them

Uber September 2022 — Lapsus$ flooded a contractor with 100+ push notifications until one was approved. The number-matching defense Microsoft/Duo/Okta deployed in 2022-2023 fixes this. Push and SMS 2FA do NOT protect against AiTM.

10 min read
Read post →
SCAREWARE · POP-UP · OLDER ADULTS

The "your computer has 5 viruses" popup IS the virus

Older Americans lost $3.4B to tech-support scams in 2024 (FBI IC3). The 6 popup variants in 2026 + the 3-key escape (Ctrl+W / Alt+F4) + browser settings that block 99% of these. DOJ Ringba conviction May 2026 ended a major call-center pipeline.

10 min read
Read post →
EMAIL PHISHING · BEC · SUPPLIER FRAUD

When a legitimate email comes back with one tiny change

Attacker takes a real email you received and re-sends with one element changed (bank account number, link). DKIM/DMARC pass. The 4 most damaging clone phishing patterns + the second-channel verification rule that beats them.

10 min read
Read post →
MALVERTISING · SEARCH

The first Google ad for "MetaMask" is sometimes a drainer

Attackers buy paid Google Ads above the organic results for crypto and bank keywords. The 30-day attack cycle: register domain, get Ads approval, run until Google catches, repeat. Real cases: Lowe's/Amazon/KeePass/AnyDesk/Brave malvertising.

10 min read
Read post →
CALENDAR · GOOGLE · OUTLOOK

The Google Calendar invite that's actually phishing

Calendar invites bypass every spam filter because the invitation email really is from Google's servers (passes DKIM/DMARC). The phishing link lives inside the event description. Lockdown settings for Gmail + Outlook in 3 steps.

9 min read
Read post →
SOCIAL MEDIA PHISHING · CRYPTO

The fake Twitter support account draining wallets right now

Attackers monitor brand mentions on X. They DM you within minutes pretending to be official support. Phantom/Coinbase/MetaMask DM scams. Verified badges can be bought now (X Premium), so blue check is no longer proof. The 10-second sanity check.

10 min read
Read post →
WI-FI ATTACKS · TRAVEL

Why airport Wi-Fi named "Airport_Free_WiFi" is a trap

Attacker broadcasts a Wi-Fi network with the same name as the real one. Captive portal phishing, SSL stripping, DNS hijack. iOS/Android auto-rejoin networks with matching SSID. The 4 defenses + personal hotspot rule for sensitive work.

10 min read
Read post →
BROWSER ATTACKS · APT · REPORTS

Why hackers target the websites you already trust

Attackers compromise a website the target group visits regularly (industry forum, vendor portal), then serve malicious code from that trusted site. URL filtering allows it. Forbes 2014, Polish bank 2017, Holy Water 2019. The 5-signal check.

10 min read
Read post →
TARGETED PHISHING · REPORTS

How attackers profile you on LinkedIn before sending the perfect phishing email

Spear phishing makes up 65% of targeted attacks per FBI IC3 2025. The 6-step LinkedIn profiling playbook attackers use to make emails irresistible, why DKIM/DMARC do not stop it, and the 5-second second-channel verification that beats it.

11 min read
Read post →
BEC · WHALING · REPORTS

The $2.3M wire transfer email scam that targets only CEOs and CFOs

Named cases: Mattel $3M, Pathé $21M, FACC $47M, Ubiquiti $46.7M, Crelan Bank $75M. FBI IC3: $2.9B in BEC losses. The 7-day pattern, why the email passes DKIM/DMARC, and the FBI Financial Fraud Kill Chain 72-hour recovery window.

11 min read
Read post →
VISHING · PHONE · AI VOICE

Your bank will never call. The scammer always will.

Vishing up 30% YoY per FBI IC3. AI voice clones (3 seconds of audio = convincing clone). Arup engineering lost $25M to a deepfake CFO video call in Feb 2024. The "hang up and call back" rule + family safeword defense for voice-clone scams.

10 min read
Read post →
QR PHISHING · MOBILE · 2026

The QR code in the parking lot that empties your bank account

Microsoft Defender: quishing up 587% YoY. Real cases: Austin / Houston / Atlanta parking meter QR sticker fraud. Why QR phishing bypasses every email URL scanner (the URL is encoded as an image). 6 places quishing attacks show up + how to scan safely.

10 min read
Read post →
BROWSER ATTACK · TECHNICAL

That browser tab you forgot about just stole your Gmail password

Tab-nabbing exploits the Document Visibility API. When you switch away, the background tab silently rewrites itself as "Gmail" or your bank. Avast 2024: average user has 15-30 tabs open. The JavaScript that does it + why password managers are the strongest defense.

10 min read
Read post →
CRYPTO · LIVE THREAT

Stable.xyz lookalike sites are draining wallets — here is how the trap runs

StableChain is a new USDT-native L1, and drainer operators are already running fake claim and revoke pages that look identical. The 4-step trap, the JS that does the actual drain, and the 5-second verification that beats it.

10 min read
Read post →
PHONE · PSYCHOLOGY

Your phone is the new phishing target — here is exactly how the text scam works

Why scam texts bypass the email filters that catch them in your inbox. The 4-second psychology that gets you to tap before thinking. The 10-second check that beats every variant. Data from FBI IC3 + Proofpoint + FTC.

10 min read
Read post →
BRAND IMPERSONATION · APPLE

"Your Apple ID has been locked" email scam: how to spot it (2026)

Apple is the #1 most-impersonated brand globally. The "Apple ID locked" email triggers a click before users think. 8 variants, URL patterns, and recovery steps if you entered your password.

9 min read
Read post →
BRAND IMPERSONATION · NETFLIX

"Netflix account on hold" email scam: how to spot it (2026)

Fake Netflix payment-failed email is in the top 5 most-reported phishing scams of 2026. 7 message variants, the URL patterns, and what to do if you entered card details.

8 min read
Read post →
BRAND IMPERSONATION · PAYPAL

"PayPal account verification" email scam: spot it in 10 seconds

PayPal is in the top 3 most-impersonated brands every year since 2018. The "verify your account" and "unusual activity" emails. 7 templates including the fake-invoice variant that passes DMARC.

8 min read
Read post →
TECH SUPPORT SCAM · SURGING

Geek Squad invoice scam email: the $399 renewal trap

One of the fastest-growing tech-support scams of 2026. Fake $399-$899 Geek Squad renewal triggers a call to a fake support number → remote access → bank drain via gift cards. 6 variants and recovery steps.

8 min read
Read post →
SMS PHISHING · INTERNATIONAL

DHL package tracking text scam: the customs duty trap

Leading international smishing scam of 2026. The $2.99 "customs fee" is bait — the real harvest is your card. 7 templates, why it works in Europe / GCC / India / SE Asia, and what to do if you paid.

8 min read
Read post →
CRYPTO · BREAKING

Pink Drainer just shut down. The wallet-drainer world did not.

One of the biggest crypto wallet drainer kits closed at end of May 2026. Here is who picks up its customers (Inferno, Angel, MS, Atomic), why drainers keep working in 2026, and 5 things to do this week.

9 min read
Read post →
CRYPTO · TECHNICAL

Permit2 Signature Attack Explained: how one click drains your wallet

A Permit2 signature is not a transaction. It does not cost gas. It does not move funds immediately. That is exactly why it is the most successful crypto wallet drainer of 2026.

9 min read
Read post →
CRYPTO · LIVE THREAT

Hyperliquid Eligibility Airdrop Scam: how the fake checker drains your wallet

SafeBrowz caught hyperliquid-eligibility.xyz in user traffic. The fake "eligibility checker" drains wallets the moment users connect. Pattern + how to verify a real Hyperliquid airdrop.

7 min read
Read post →
PRODUCT · LAUNCH

We built a phishing detection API that AI agents can pay in USDC

SafeBrowz Detection API is live. Pay-per-request URL safety scans on x402, settled in USDC on Solana or Base. $0.001 per call, no signup.

8 min read
Read post →
GUIDE · BEGINNER

How to tell if a website is a scam

11 red flags that give away phishing sites, plus the browser checks most people miss.

9 min read
Read guide →
THREAT · ACTIVE

The fake CAPTCHA that empties your wallet (ClickFix)

Why "click this box to verify you're human" is now the #1 attack chain in 2026.

11 min read
Read guide →
GUIDE · BRAND

Microsoft phishing emails: 7 ways to spot them

Microsoft is the #1 impersonated brand. Here's what a real Microsoft email actually looks like.

8 min read
Read guide →
CRYPTO · RESCUE

My crypto wallet got drained. What do I do?

What's actually recoverable, what isn't, and how to move fast in the first 60 minutes.

12 min read
Read guide →
TECHNICAL

Pastejacking, explained

Why the thing you thought you copied isn't what you pasted. And why your terminal is especially at risk.

7 min read
Read guide →
CRYPTO · WARNING

Fake Ledger emails: what to check before clicking

The Ledger email scam family has been running for 3+ years. Here's how it actually works.

8 min read
Read guide →