❌

Normal view

Fake HBO Max Ads Spread ClickFix Malware on Reddit: This Week in Scams

18 September 2026 at 12:00

If a website asks you to open Terminal, PowerShell, Command Prompt, or the Windows Run box and paste something in, stop.

That simple rule can protect you from a type of attack McAfee has been tracking for years. Known as ClickFix, the scam turns an ordinary-looking online instruction into a way for criminals to install malware on your device. The lure might look like a CAPTCHA, a software fix, a download, or a quick tutorial. The trick is getting you to run the attack yourself.

ClickFix is back in the headlines this week after attackers reportedly compromised HBO Max’s verified Reddit advertising account and used it to distribute malicious ads. But while the brands, websites, and platforms keep changing, the underlying trick is one McAfee researchers have been following since at least 2024.

What is a ClickFix Attack?

A ClickFix attack is a social engineering scam that convinces someone to copy, paste, or run a malicious command on their own computer.

This week’s example shows why the tactic can be so convincing. According to TechCrunch, attackers compromised an HBO Max account authorized to run ads on Reddit. The account was then used to publish malicious advertisements that could direct people to fake sites, including pages made to look like they were associated with HBO Max.

Researchers investigating the campaign reported finding 108 malicious ads posted over roughly 48 hours. Some promoted what appeared to be a Mac version of HBO Max, while others used software and AI-related lures.

Instead of providing a normal download, the sites instructed visitors to open tools such as Terminal on a Mac or PowerShell or the Run dialog on Windows, paste in a command, and execute it. That last step is the important one.

The website is not really helping you fix or install something. It is convincing you to give your computer malicious instructions.

Depending on the campaign and device, those instructions can lead to information-stealing malware designed to collect things such as saved passwords, browser information, account data, or cryptocurrency wallet information.

Reddit told TechCrunch that it learned an HBO Max account authorized to run advertisements had been compromised and used for malicious links. The company said it locked the account and removed the ads. The number of people who clicked the ads or were ultimately compromised remains unclear.

Clickfix isn’t New, and Mcafee Has Been Tracking It For Years

What makes this week’s story notable isn’t that ClickFix suddenly appeared. It’s how far the tactic has traveled.

McAfee Labs documented ClickFix attacks in July 2024 after researchers discovered compromised websites displaying fake error messages that instructed people to paste scripts into PowerShell. Researchers observed the technique being used to deliver malware including DarkGate and Lumma Stealer.

Just a few months later, McAfee Labs documented another variation built around something nearly everyone recognizes: the CAPTCHA.

Victims encountered fake “Verify you are a human” or “I’m not a robot” pages. Clicking the button could copy a malicious command to the clipboard. The page would then walk the person through opening the Windows Run box and pasting it in. McAfee researchers observed those fake CAPTCHA attacks connected to phishing emails and searches for cracked games.

By 2025, the same basic idea was appearing in yet another familiar place: social media tutorials. McAfee reported on ClickFix-style scams circulating through TikTok videos that promised free software upgrades or premium versions of popular apps. Instead of solving a problem, the instructions could lead people to install information-stealing malware.

Now the lure has changed again. This time, attackers allegedly used advertising from a compromised, verified corporate account.

That evolution matters because ClickFix isn’t one particular fake website or pop-up you can memorize. It’s a reusable scam technique.

Why ClickFix scams can be so convincing

Most online scams ask you to click something. ClickFix adds another layer by asking you to do something.

That action may feel technical enough to be legitimate. A page tells you there’s an error. It gives you several steps to fix it. Maybe you’re asked to press a few keys, open a utility you’ve seen on your computer before, paste something, and hit Enter.

Following instructions can feel safer than downloading an unfamiliar file. But in a ClickFix attack, following the instructions is effectively the download.

Attackers also keep placing these instructions inside familiar online experiences. McAfee researchers have seen fake error messages and CAPTCHA checks. Other campaigns have appeared in social media tutorials, software downloads, phishing messages, and now online advertising.

Even a familiar brand or verified account shouldn’t override an unusual request from a website.

Key Takeaways

ClickFix is a social engineering technique, not one specific scam. The lure can change while the basic attack stays the same.

McAfee researchers have tracked ClickFix campaigns since 2024, including fake error messages and CAPTCHA pages designed to deliver malware.

Mac users aren’t automatically outside the target zone. This week’s campaign reportedly included separate techniques targeting both macOS and Windows.

The biggest warning sign is an unusual instruction. A website should not need you to paste an unexplained command into Terminal, PowerShell, Command Prompt, or Run to prove you’re human or download ordinary consumer software.

How McAfee Helps

You deserve multiple layers of cybersecurity protection to prevent and stop threats like ClickFix at every potential point of malware entry. That’s what McAfee’s built to do.

Web Protection can help prevent access to known malicious websites, including sites used as part of malware campaigns. That matters when an otherwise convincing ad or message sends you somewhere dangerous.

Device Security adds another layer by scanning for and helping block malware that attackers attempt to install. McAfee Labs has previously documented McAfee protections blocking stages of ClickFix infection chains, including malicious URLs and suspicious behavior.

And because information stealers often target passwords and account information, Identity Monitoring can help alert you when monitored personal information is found in a breach so you can respond sooner.

Technology can help, but ClickFix also has a human checkpoint built into the attack. If a webpage suddenly asks you to become your own system administrator and run a command you don’t understand, don’t.

Other Scam and Security News This Week

Spain’s privacy regulator receives report of an alleged AI-powered breach. Spain’s data protection agency said it was notified of an incident in which an AI agent was allegedly used to find vulnerabilities, access systems, probe applications, and ultimately access or modify data. The regulator has not yet investigated and verified the reported incident, an important distinction as security researchers continue examining how AI agents could be misused in cyberattacks.
Source: BleepingComputer

Revolut says its core systems weren’t hacked in customer data incident. Reuters reported that sensitive information involving about 680 customers was disclosed after fraudulent requests were sent from a legitimate government agency email domain, according to a source familiar with the matter. Revolut said it had received no direct demand from the group claiming responsibility, while the group reportedly threatened to sell customer records unless it received a $3 million ransom.
Source: Reuters

More details emerge about the malicious HBO Max Reddit ads. Additional reporting on the ClickFix campaign said the compromised account was used to run 108 malicious ads over about 48 hours, with lures ranging from HBO Max downloads to AI and software tools. The findings reinforce the main lesson from this week’s story: a verified account or recognizable brand doesn’t make unusual download instructions safe.
Source: Malwarebytes

This Week’s Safety Tips

Some practical safety tips in light of this week’s news:

✓ Don’t paste commands from websites into system tools. Treat the request itself as a warning sign.

✓ Skip software downloads promoted through ads. Navigate to the company’s official website or trusted app store yourself.

✓ Use multifactor authentication on important accounts. It can provide another barrier if a password is stolen.

✓ Keep security protection and your devices updated. Current protection gives you more opportunities to catch malicious sites and malware before they can do damage.

ClickFix may keep changing its disguise, but you don’t need to learn every version. Remember the underlying trick: a website that asks you to copy, paste, and run unfamiliar commands is asking for far more trust than you should give it.

And we’ll be back next week with more cybersecurity news and scam alerts.

The post Fake HBO Max Ads Spread ClickFix Malware on Reddit: This Week in Scams appeared first on McAfee Blog.

Data Broker Radaris Loses Domains in Privacy Fight

16 September 2026 at 18:14

The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides for hefty fines against data brokers that publish personal information on state law enforcement officials. In the face of repeated stonewalling and prevarication by attorneys for Radaris, the judge in the case ordered that radaris.com and more than a dozen other data broker domains be transferred to the plaintiffs.

The radaris.com website, prior to the domain transfer to Atlas.

In February 2024, Radaris was sued by Atlas Data Privacy Corp, a company that has been pursuing data brokers alleged to be violating a New Jersey statute called Daniel’s Law. The statute allows state law enforcement officials, government personnel, judges and their families to have their information completely removed from commercial data brokers and people-search services, and provides for fines of $1,000 per violation against companies that ignore removal requests.

Less than a month after Atlas sued Radaris, KrebsOnSecurity published a deep dive into the Radaris co-founders — Igor and Dmitry Lubarsky (also spelled Lybarsky) — Russian-born brothers living in Massachusetts who operate a dizzying array of people-search companies as well as a number of Russian language dating services and affiliate programs.

Attorneys for the Lubarsky brothers threatened to sue for defamation if the story wasn’t removed and an apology issued. Their attorney asserted that our reporting was wildly inaccurate, and that the true owners of the company were Ukrainians living in Ukraine.

The Lubarsky brothers Dmitry or “Dan” (left) and Gary/Igor.

KrebsOnSecurity doubled down and showed how the Lubarsky brothers built and operated Radaris and other data broker companies using a fictitious CEO’s name. Our follow-up story noted that Radaris’s attorney — a lawyer with the Boston Law Group named Val Gurvits — admitted his clients had invented the CEO pseudonym “Gary Norden,” and that Radaris also had issued multiple press releases over the years that quoted the fake CEO while seeking money from potential investors.

Attorneys for Radaris waited until the last minute to appear in court and contest what was all but certain to be a default judgment in favor of the plaintiffs, and then told the court that Atlas had failed to serve the real owners and operators of Radaris and several of its sister data broker companies.

Atlas re-filed the lawsuit in June 2025, this time dramatically expanding the number of Radaris family data brokers accused of violating Daniel’s Law. Matt Adkisson, president and CEO of Atlas, said Radaris turned to a tried-and-true playbook: Delaying in court until the last possible minute, and playing shell games with Radaris’s true country of origin and the individuals listed as owners and operators of these sites.

“We refer to this period as their island-hopping phase. Privacy policies changed constantly, and new entities kept appearing from places like the Marshall Islands, the British Virgin Islands, and Seychelles,” Adkisson told KrebsOnSecurity. “Behind the scenes, it felt like a shell game. Defense lawyers told the court that certain entities merely operated the domains and were the proper parties to sue. But by the time a judgment neared, those entities would be discarded and new entities would appear. Meanwhile, the lawyers claimed the other entities that actually owned the domains should not be held responsible.”

Adkisson said when the defendants updated their terms of service to state that Radaris was suddenly managed by a company in the Marshall Islands, Atlas hired an investigator in that country and soon learned the brand new entity that Radaris claimed was managing the company didn’t even exist yet.

Mr. Gurvits stepped forward as Radaris’s attorney in a class action lawsuit the company temporarily lost in 2017 because it never contested the claim in court. When the plaintiffs told the judge they couldn’t collect on the $7.5 million default judgment, the court ordered the domain registry Verisign to transfer the radaris.com domain name to the plaintiffs.

Mr. Gurvits appealed that verdict, arguing the lawsuit hadn’t named the actual owners of the Radaris domain name — a Cyprus company called Bitseller Expert Limited — and thus taking the domain away would be a violation of their due process rights.

The judge in the 2017 case ruled in Radaris’ favor — halting the domain transfer — and told the plaintiffs they could refile their complaint. Soon after, the operator of Radaris changed from Bitseller to Andtop Company, an entity formed (PDF) in the Marshall Islands in Oct. 2020. The plaintiffs never re-filed their lawsuit.

A mind map of various entities tied to Radaris and the company’s co-founders. Click to enlarge.

“That seemed to be their modus operandi,” said Raj Parikh, a partner at PEM Law in New Jersey who handles most of the Daniel’s Law litigation for Atlas. “In the past, they won by attrition. Plaintiffs’ attorneys tired of the procedural games and just gave up. That strategy worked for a decade, and it probably would have worked in this case too, since any financial recovery from foreign actors will be difficult. But we were acutely aware of the threat this website posed to law enforcement officers and other public officials in New Jersey, and decided early on to commit whatever time and resources were necessary to remove that threat.”

On August 26, the judge in the New Jersey case found the defendants were given multiple chances to appear and defend the claims against them but had failed to do so. Mr. Gurvits declined to comment on the case, saying it had been assigned to another attorney, a Mr. Victor Worms. In response to questions, Mr. Worms asserted the New Jersey court transferred Radaris.com to Atlas as part of a default judgment against Radaris.com, which is not a legal entity.

“We have made a motion to vacate that default judgment on the grounds that it is void since a non-entity has no legal capacity to sue or be sued,” Worms replied. “We also intend to pursue all appropriate appeals because we believe the transfer of Radaris.com amounts to a forfeiture in violation of various constitutional principles.”

While radaris.com still comes up prominently in results when searching online for U.S. residents by name, the domain no longer sells detailed personal dossiers on millions of Americans. Its homepage now displays a notice from Atlas, as well as links to our previous reporting on Radaris.

EMAIL CONFIRMATIONS

Atlas told KrebsOnSecurity that it has obtained more than 10,000 emails and documents in the course of litigation, and that those messages confirm our previous reporting on the owners and operators of Radaris and its myriad companies.

Atlas said the emails clearly establish that the nominal legal vehicles — Radaris America, Inc.; Bitseller Expert Limited; Digital Orbit Corp; Core Solutions Group Inc; Lucky Solutions Inc; Virtura Corp; Veripages Inc.; Nuform Solutions Inc.; Growth Data Advisors Inc.; Property Experts, Inc — are all administered by the same three or four people from the same mailboxes, share one bank or payment card set, and are all managed from one virtual office address.

“The corpus establishes, with documentary evidence generated independently by banks, payment processors, hosting providers, registrars, software-as-a-service vendors and the operators’ own systems, that radaris.com and at least twenty-five other people-search websites are one operation run by a small Boston-area group whose administrative, financial and technical functions sit on the difive.com mail domain and its successors (centerex.com, scienteco.com, eprofit.com, realmo.com, pub360.com),” reads a summary shared by Atlas.

Atlas said the emails show Radaris.com earns approximately $42,000 a month, while Veripages.com earns around $45,000 monthly via its partnership with the Lifetime Value Company, a marketing and advertising firm whose brands include PeopleLooker, PeopleSmart, NumberGuru, and Bumper, a car history site.

According to Atlas, the emails also showed the Radaris family of websites earns as much as $25,000 each month from their partnership with Onerep, a company that claims to help people remove their information from people-search sites. In March 2024, KrebsOnSecurity revealed how the Belarusian founder of Onerep had launched and operated dozens of people-search sites over the years and was continuing to operate one of them (Nuwber), effectively spreading the disease and selling the cure.

The domain radaris.com now redirects to this notice from Atlas about the court-ordered domain transfer.

The domain radaris.com now redirects to this notice from Atlas about the court-ordered domain transfer.

All told, the New Jersey court has so far transferred 14 domain names from the Radaris family of companies to Atlas. Radaris.com now redirects to a notice of the court-ordered domain transfer.

THE ROAD AHEAD

The Radaris family of companies is still potentially facing fines of $1,000 per alleged violation of Daniel’s Law. For the time being, however, Daniel’s Law is facing a constitutional challenge from virtually all of the 150 other consumer data broker firms being sued by Atlas.

The data broker industry responded by having at least 70 of the Atlas lawsuits moved to federal court, challenging the New Jersey statute as overly broad and a violation of the First Amendment. The U.S. Court of Appeals for the Third Circuit has not yet issued a decision on the constitutional challenge, but either way the case is widely expected to be appealed all the way to the U.S. Supreme Court.

Meanwhile, at least 14 other states have now passed laws modeled after the New Jersey statute, with more states considering similar measures. However, West Virginia’s Daniel’s Law was ruled facially unconstitutional under the First Amendment by a federal district court in August 2025.

Justin Sherman is a privacy expert and author of the forthcoming book “The Middlemen,” which examines how the data broker industry powers modern surveillance. Sherman said federal lawmakers have long faced intense lobbying by the technology industry against more restrictive U.S. data privacy laws, but that many powerful industries are now working against passing comprehensive data privacy legislation.

“These days at the federal level, add in the intense amount of lobbying against these laws from social media companies, big tech, cryptocurrency firms, and now AI proponents in the mix who claim that limiting their data scraping is somehow going to collapse the whole U.S. economy under Chinese rule,” he said.

Sherman said people-search companies will continue to thrive unless and until Congress enacts meaningful consumer privacy and data protection laws that are relevant to life in the 21st century. That’s because virtually all state privacy laws exempt records that might be considered “public” or “government” documents, including voting registries, property filings, marriage certificates, motor vehicle records, criminal records, court documents, death records, professional licenses, bankruptcy filings, and more.

At least 25 states have passed or implemented laws requiring age verification for residents seeking to access adult content online, but there is no federal law that limits how the companies that are scanning everyone’s drivers license can use, share or keep the data provided. Had such restrictions been enshrined in law, we may have avoided the recent breach at IDScan.net, which exposed the drivers license information on more than 153 million Americans when the records were briefly turned into a point-and-click identity theft service on the dark web.

“The average person can look at Daniel’s Law and have a perfectly normal reaction, which is that everyone should be covered, not just police and judges,” Sherman said. “But we don’t need more wake-up calls. We’ve had eight million wake-up calls already on the need for better privacy laws. The lack of comprehensive federal privacy law is not for a lack of knowledge, and anyone claiming otherwise is either not reading the news or kidding themselves.”

Up to 150 Million Driver’s License Records Exposed in IDScan Breach: What to Do Next

11 September 2026 at 12:49

Your driver’s license can be replaced. The information printed on it is much harder to take back.

That’s the concern after identity verification company IDScan confirmed a data breach involving driver’s license and other government ID information. Reporting has connected the incident to a database containing more than 150 million driver’s license records, raising an obvious question for consumers: What should you do if your information may be exposed?

That’s our lead story in This Week in Scams. We’ll explain what’s known about the IDScan breach, why stolen ID information can be useful to scammers, and the steps you can take now.

Plus, we’re looking at AI agents that reportedly found ways around restrictions, AI-generated political ads that make online video harder to trust, and how AI is adding a new layer to an old jury duty scam.

What Happened in the IDScan Data Breach?

IDScan provides identity verification technology used by businesses to scan and verify identification documents.

On September 4, the company disclosed that it had learned of possible unauthorized access to data stored in its cloud. IDScan said potentially affected information may include full names, driver’s license numbers, and numbers from other government-issued IDs. The company says its investigation is ongoing and that it is cooperating with federal law enforcement.

The scale requires some careful distinction.

According to TechCrunch, cybersecurity journalist Brian Krebs had been alerted to a dark web website that allowed users to search driver’s license information belonging to more than 150 million people in the U.S. and Canada, reportedly including photographs. IDScan itself has not said how many people were affected by the breach, though the company has said it holds more than 150 million driver’s license records.

In other words, there is evidence pointing to an extremely large collection of exposed identity information, but an official affected-person count has not yet been established.

Why Stolen Driver’s License Information Matters

A driver’s license number isn’t a password. You can’t simply change it after every breach.

And unlike a credit card, which can generally be canceled and replaced when it is compromised, identity information can remain useful to criminals for years.

That can make this type of data valuable for identity theft and impersonation.

Identity theft happens when someone uses another person’s personal information to pretend to be them, often to open accounts, attempt financial fraud, or make other fraudulent transactions.

There is also a second risk: more convincing scams.

Someone who knows your full name, address, date of birth, driver’s license information, or other personal details may have an easier time convincing you that they represent a bank, government agency, insurance company, or another organization you trust.

That leads to an important rule after any major breach: Someone knowing private information about you does not prove they are legitimate.

Key Takeaways

→ IDScan has confirmed unauthorized access that may involve names, driver’s license numbers, and other government-issued identification numbers.

→ IDScan has not announced how many individuals were affected, so consumers should be cautious about treating 150 million as a confirmed victim count.

→ Stolen identity information can potentially be used for identity theft as well as more personalized impersonation scams.

→ Be suspicious of anyone contacting you unexpectedly about the breach and asking for additional personal information, passwords, verification codes, or money.

How McAfee Protects Against Breaches 

Before a breach  

Personal Data Cleanup reduces your digital footprint by removing your personal information from many data broker sites, making it harder for scammers to find and target you.  

Online Account Cleanup scans for accounts you no longer use and helps you delete them, along with your personal info.  

During a breach  

Identity Monitoring watches for your personal information, including email addresses, driver’s license numbers, passport numbers, bank accounts, credit cards, Social Security numbers, phone numbers, and more, across the dark web and known data leaks.   

Plus, we alert users on average up to 10 months earlier than similar services, so you can act fast when your personal information appears where it shouldn’t.  

After a breach  

Scam Detector identifies suspicious texts, emails, and links that often follow major breaches, while web protection blocks malicious websites designed to steal even more of your information.

Other Scam and Security News This Week

OpenAI Agents Reportedly Found Their Own Ways to Communicate Online

Researchers found that OpenAI agents used more than 10 previously undisclosed websites to communicate during testing despite restrictions intended to prevent them from posting online, according to Reuters; importantly, Reuters characterized much of the behavior as closer to spam than hacking. The consumer takeaway is less about an immediate scam and more about AI agents — systems designed to independently carry out multi-step tasks — and why giving increasingly capable AI systems access to outside tools and websites requires strong safeguards and oversight.
Source: Reuters

AI Campaign Ads Make “Seeing Is Believing” Even Less Reliable

AI-generated political ads are increasingly appearing during the 2026 election cycle, including fabricated images, video, and audio involving real candidates, Axios reports. Regardless of the political message involved, the consumer lesson is straightforward: a realistic-looking video is no longer proof that someone actually said or did what appears on screen, so check questionable political content against reliable reporting and original sources before sharing it.
Source: Axios

AI Is Giving the Old Jury Duty Scam a More Convincing Voice

Courts around the country are warning about scammers claiming victims missed jury duty and face arrest unless they respond or pay, while recent reporting has highlighted how AI-generated voices can make phone scams more convincing. The underlying scam hasn’t changed: criminals create fear and urgency, impersonate authority, and demand money — and federal courts stress that they will not demand payment by phone, text, email, payment app, gift card, or cryptocurrency to resolve missed jury service.
Sources: WBUR/Here & Now; U.S. Courts

This Week’s Safety Tips

✓ Consider a credit freeze after sensitive identity data is exposed. A freeze can make it harder for someone to open new credit accounts in your name; IDScan itself recommends considering fraud alerts or credit freezes following this incident.

✓ Never treat personal information as proof of identity. A caller knowing your name, address, driver’s license information, or other details doesn’t mean they represent the organization they claim to.

✓ Verify surprising videos before sharing them. Search for the original speech, interview, campaign account, or credible reporting rather than relying on the clip in your feed.

✓ Hang up on jury-duty payment demands. Courts do not demand immediate payment over the phone to prevent your arrest. Find the court’s official contact information yourself and verify the claim independently.

And we’ll be back next week with more cybersecurity news and scam alerts.

The post Up to 150 Million Driver’s License Records Exposed in IDScan Breach: What to Do Next appeared first on McAfee Blog.

Carhartt Data Breach Reportedly Exposes Millions. What to Know This Week in Scams

4 September 2026 at 12:00

A data breach doesn’t have to expose your password or credit card number to create problems. Sometimes, scammers just need enough information to make you believe they know you.

That’s the concern after data reportedly stolen from Carhartt was published online. Here’s what happened, why it matters, and what consumers should watch for next.

What Happened in the Carhartt Data Breach?

The cybercriminal group ShinyHunters published data it claims was stolen from Carhartt after an alleged $3.3 million extortion demand was rejected, according to TechRadar. Security researcher Troy Hunt analyzed the leaked information and determined that the compromised data was associated with roughly 12.9 million accounts, although the dataset also reportedly contained millions of synthetic records that did not correspond to real people.

For affected consumers, the important part is what was reportedly exposed: names, email addresses, phone numbers, and postal addresses.

This is also a useful example of how cyber extortion has evolved.

Traditional ransomware typically involves criminals getting inside an organization, encrypting its files so they can’t be accessed, and then demanding payment to restore them.

In this case, the reported strategy was different. ShinyHunters has increasingly focused on data exfiltration — security jargon for stealing or copying data out of a system — and then using the threat of publishing that information as leverage.

In plain English: Criminals don’t necessarily need to lock up a company’s computers anymore. Stealing its data can be valuable enough.

How Scammers Might Use This Information

The immediate question after any breach is usually, “Was my financial information stolen?” That’s important, but it isn’t the only risk.

A combination of your name, email, phone number, and home address can help scammers create a message that sounds much more believable than generic spam.

Instead of: “There’s a problem with your account. Click here.” you could receive something that appears to know your name, where you live, or which company you’ve done business with.

That context can lower your guard.

And scammers don’t necessarily have to pretend to be Carhartt. Stolen contact information can potentially be combined with information from other breaches, data brokers, or public sources to build a more complete picture of someone.

That’s why leaked personal information can remain useful to criminals long after the original breach disappears from the headlines.

Key Takeaways

  • Personal information can be valuable to scammers even when passwords or payment information aren’t exposed.
  • Names, emails, addresses, and phone numbers can make phishing attempts more personalized.
  • Be particularly cautious of unexpected messages claiming there is a problem with an order, refund, account, or payment.
  • A company knowing personal details about you is not proof that the person contacting you actually represents that company.

How McAfee Protects Against Breaches 

Before a breach  

Personal Data Cleanup reduces your digital footprint by removing your personal information from many data broker sites, making it harder for scammers to find and target you.  

Online Account Cleanup scans for accounts you no longer use and helps you delete them, along with your personal info.  

During a breach  

Identity Monitoring watches for your personal information, including email addresses, driver’s license numbers, passport numbers, bank accounts, credit cards, Social Security numbers, phone numbers, and more, across the dark web and known data leaks.   

Plus, we alert users on average up to 10 months earlier than similar services, so you can act fast when your personal information appears where it shouldn’t.  

After a breach  

Scam Detector identifies suspicious texts, emails, and links that often follow major breaches, while web protection blocks malicious websites designed to steal even

Other Scam and Security News This Week

A Lenovo Login Flaw Exposed About 5,000 Dropbox Accounts

Dropbox says approximately 5,000 accounts were accessed after attackers exploited a flaw involving Lenovo ID authentication; fewer than a third reportedly had files viewed or downloaded. Dropbox has expired sessions authenticated through Lenovo IDs and changed the login process, while the incident is another good reason to enable two-factor authentication on cloud accounts.
Sources: BleepingComputer

Amazon Adds a New Way to Check Suspicious Messages

Amazon has added a feature to Alexa for Shopping that lets U.S. customers ask whether an email, text, phone call, or other message actually came from Amazon; the company says roughly 360,000 customers contact customer service each year with that question. It’s a useful reminder of one of the best scam-fighting habits: instead of trusting the message in front of you, verify it through a separate, official channel.
Sources: TechCrunch

Fake Late-Night TV Clips Show How Easily AI Can Borrow Someone’s Credibility

NPR reports that AI-generated videos impersonating late-night hosts including Jimmy Kimmel and Jon Stewart have accumulated significant audiences online, sometimes without obvious AI labels. The bigger consumer lesson goes beyond politics or entertainment: seeing a familiar face and hearing a familiar voice is no longer enough to prove that a video — or the product, investment, or claim it promotes — is authentic.
Source: NPR

This Week’s Safety Tips

✓ Treat unexpected personalization as information, not proof. A caller knowing your name, address, or other details doesn’t mean they’re legitimate.

✓ Turn on two-factor authentication. This can provide another barrier when someone tries to access an account without permission.

✓ Verify messages outside the message itself. Open the official app, type the website yourself, or contact the company using information you independently know is legitimate.

✓ Slow down when something feels urgent. Whether it’s a breach alert, delivery problem, suspicious login, or celebrity video, scammers benefit when you react before you verify.

And we’ll be back next week with more cybersecurity news and scam alerts.

The post Carhartt Data Breach Reportedly Exposes Millions. What to Know This Week in Scams appeared first on McAfee Blog.

Airport Wi-Fi Data Breach Exposes Millions of Travelers: This Week in Scams

28 August 2026 at 10:00

Free airport Wi-Fi can be useful when you’re waiting for a flight. But this week’s biggest security story is a reminder that there are two different ways your information can be exposed when you connect.

One risk happens while your information is traveling across a public network. Another happens after a company collects and stores information about you.

A cyberattack affecting three major UK airports illustrates the difference, and why travelers need protection for both.

What happened in the Manchester Airports Group cyberattack?

Manchester Airports Group, or MAG, confirmed that an unauthorized third party obtained customer information connected with Manchester Airport, London Stansted Airport, and East Midlands Airport.

According to reports, the affected information came from car park, airport lounge, Fast Track bookings, and airport Wi-Fi registrations. MAG says the stolen data includes email addresses, phone numbers, vehicle registration numbers, and postcodes. The company says the affected system did not contain customers’ payment or banking details.

The Telegraph reported that approximately 8.7 million passengers were affected and that more than 90% of the stolen records were email addresses, largely because travelers provide an email address when registering for free airport Wi-Fi. The attackers reportedly demanded a ransom, which MAG declined to pay.

MAG says airport operations and passenger safety were not affected and that it has contained access to the compromised systems.

For travelers, however, the breach creates another concern: what criminals might do with the stolen information next.

Why stolen airport data can lead to convincing scams

An email address alone might not seem particularly sensitive. But combined with a phone number, postcode, vehicle registration, or knowledge that someone has interacted with a particular airport, it becomes more useful to a scammer.

That information can help criminals make phishing emails and texts feel believable.

A message might claim there is a problem with your airport parking reservation, ask you to confirm a Fast Track booking, or say you need to pay an outstanding airport charge. Someone who recently used the airport may be much more inclined to click.

That is one reason breach victims should be especially cautious about unexpected messages that appear connected to the organization involved.

Does a VPN protect you from an airport Wi-Fi data breach?

Not from this kind of breach.

A VPN, or virtual private network, encrypts the internet traffic traveling between your device and the VPN service. Think of it as putting your online activity inside a protected tunnel while it crosses a public network.

That matters at airports, hotels, cafés, and other places where many people share the same Wi-Fi. McAfee Secure VPN can encrypt your connection and can be configured to turn on automatically when you join an unsecured network.

But that is different from what happened here.

If you voluntarily give an airport your email address to register for Wi-Fi, that email address may then be stored in the airport operator’s systems. A VPN cannot prevent a later breach of that company’s database.

In short: A VPN helps protect information in transit. It does not control what happens to information you give directly to a company.

Both risks matter.

Before, During, and After a Data Breach

Before a breach: Share only the information a service genuinely requires. Use strong, unique passwords for online accounts, and use a VPN when connecting to public Wi-Fi.

During a breach: Look for information directly from the affected company rather than relying on messages arriving by email or text. Criminals often take advantage of security incidents by sending fake “account protection” or “verify your information” messages.

After a breach: Watch for unusual emails, calls, texts, and account activity. Be particularly suspicious when someone creates urgency or asks for passwords, verification codes, payment information, or money.

MAG specifically warns that it will not unexpectedly contact customers asking for payment card information, banking details, or passwords.

At a Glance

➡ The breach affected customer information from bookings and airport Wi-Fi registrations.

➡ 8.7 million passengers were affected

➡ MAG says banking and payment details were not stored in the affected system.

➡ Stolen contact information can still make phishing and impersonation scams more convincing.

➡ A VPN protects your connection on public Wi-Fi, but it cannot prevent a company from later suffering a database breach.

➡ Be particularly cautious about unexpected airport-related emails and texts following the incident.

How McAfee Helps

Secure VPN helps address the other major risk associated with airport Wi-Fi: someone attempting to monitor your traffic while you use an unsecured network. McAfee Secure VPN encrypts your connection and can automatically activate on unsecured Wi-Fi, helping keep browsing activity and information transmitted from your device private.

Identity Monitoring keeps watch for your personal information associated with breaches, giving you an opportunity to act when exposed information is detected.

And because stolen email addresses and phone numbers can fuel follow-up phishing attempts, Scam Detector can identify suspicious texts, emails, and other QR codes before you act on them.

QR Scan Example

The broader lesson is layered protection: protect your connection while you’re online, then keep watching for misuse of information that companies already hold.

Other Scam and Security News This Week

Hackers claim breach of major data center provider. The ShinyHunters group claims it stole extensive corporate and employee information from U.S. data center company CyrusOne and demanded $13 million.

CyrusOne had not publicly confirmed the hackers’ claims when TechRadar reported the story, so the alleged scale of the breach remains unverified.
Source: TechRadar

Man accused of posing as a 49ers player in $1.3 million romance scam. Federal prosecutors allege that two men defrauded at least 26 women after one portrayed himself online as a wealthy San Francisco 49ers player and the other posed as his financial adviser.

Investigators say fake banking apps and fabricated investment balances helped make the scheme appear legitimate; both defendants are presumed innocent unless proven guilty.
Source: U.S. Department of Justice

Fake sports streams target fans looking for the game. The Better Business Bureau warns that scammers post supposed free streaming links on social media, sometimes tagging real schools or teams, then direct fans to sites designed to collect payment or personal information instead of showing a game.

Go to the team, school, league, or known streaming provider directly rather than trusting a link in a social post — and remember that HTTPS alone does not prove a website is legitimate.
Source: Better Business Bureau

This Week’s Safety Tips

“Once you give your information to a company, you can’t completely control what happens to it,” says McAfee’s Tyler McGee. “But you can limit what you share and take steps to protect yourself if your information is exposed.”

“Only provide what’s needed, use unique passwords and turn on multi-factor authentication where you can. Tools like McAfee’s identity monitoring can also alert you if your information shows up in a known breach. And be extra cautious after a breach,” he says. “Scammers can use exposed information to make messages about a booking, refund or account look much more convincing. If you get one, go directly to the company’s website or app rather than clicking the link.”

✓ Use a VPN on public Wi-Fi. Encrypt your connection before checking email, shopping, banking, or signing into important accounts.

✓ Treat breach-related messages cautiously. Navigate to the company’s official website yourself rather than clicking a link in an unexpected email or text.

✓ Use unique passwords. A password stolen from one service should never unlock another account.

✓ Verify before sending money. Whether someone claims to be an athlete, investment adviser, streaming provider, or familiar company, independently confirm who you are dealing with.

And we’ll be back next week with more cybersecurity news and scam alerts.

The post Airport Wi-Fi Data Breach Exposes Millions of Travelers: This Week in Scams appeared first on McAfee Blog.

The Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn

29 August 2026 at 10:30
Plus: Hackers target over 100 US water systems, ICE puts in an order for robot dogs, and you’ll never guess what “MrChildPorn” was arrested for.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

27 August 2026 at 11:04

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever.

In a statement released today, the Australian Federal Police (AFP) said two men from Western Australia, aged 21 and 23, were arrested in connection with a “sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.”

The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old suspect’s real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP’s self-described spokesperson, and examines clues left behind by the TeamPCP leader that likely led to his undoing.

TeamPCP vaulted onto the cybercrime scene in late 2025, embedding malicious code in hundreds of open source software tools and extorting victims for profit. Members of the group made headlines by compromising corporate cloud environments using a self-propagating worm dubbed Shai-Hulud, which added malicious code to open source programs maintained by developers whose credentials at public code repositories like GitHub or NPM were phished or stolen.

Writing for Wired, journalist Andy Greenberg described TeamPCP’s core tactic as a kind of cyclical exploitation of software developers.

“The hackers gain access to a network where an open source tool commonly used by coders is being developed,” Greenberg wrote in May. “The hackers plant malware in the tool that ends up on other software developers’ machines, including some who are writing other tools intended to be used by coders. The malware allows TeamPCP’s hackers to steal credentials that let them publish malicious versions of those software development tools, too. The cycle repeats, and TeamPCP’s collection of breached networks grows.”

TeamPCP also has practiced something akin to cyclical recruitment. In May, the source code for the third iteration of Shai-Hulud was published online, and TeamPCP soon after launched a contest offering $1,000 in virtual currency to whichever participant could conduct the largest supply chain operation using the worm’s code. According to the contest rules, participants were scored based on the number of weekly and monthly downloads of packages they compromised — directly incentivizing them to target the most popular code libraries.

A screenshot of a message from TeamPCP’s Telegram account, announcing the supply chain hacking contest. Image: dataminr.com.

“TeamPCP has stated the competition is a recruiting opportunity and they intend to purchase all meaningful access harvested from participants’ campaigns,” the security firm Dataminr wrote. “The $1,000 XMR (Monero) prize is a recruitment floor and has been dismissed by the actor as ‘just like participation trophy,’ adding ‘if you find something good you will be paid way more,’ confirming the contest’s true function as talent identification and malicious access acquisition at scale.”

In March, TeamPCP executed a supply chain attack targeting AI infrastructure by compromising the code for LiteLLM, an open source AI gateway that connects users to more than 100 different large language models. A recent analysis by the security firm CloudSEK found TeamPCPs attack on LiteLLM harvested cloud service keys and other secrets from more than 2,500 organizations, including many of the world’s top technology companies.

In May, TeamPCP claimed credit for compromising at least 3,800 code repositories at the Microsoft-owned GitHub, after a GitHub developer installed a code extension that was compromised by TeamPCP’s malware.

MEET THE CYBERCATS

Security experts say TeamPCP is less of a hacker group than an amalgamation of threat actors from multiple cybercriminal gangs who sometimes work together toward similar goals.

“It is not a structured criminal crew with a single operator,” said Austin Larsen, a principal threat analyst with the Google Threat Intelligence Group. “It is a peer community of individually-skilled actors, with one clear center of gravity.”

That center of gravity is George Prepakis, an accomplished security researcher and self-described exploit developer who operates the Twitter/X profile @kernelstub. Earlier this year, @kernelstub tweeted a public invite link to a Matrix chat server he created and dubbed “Cybercats,” and TeamPCP and several other cybercrime entities have been using this server to communicate daily for the past several months.

A screenshot of the Matrix chat server “Cybercats,” whose members used hacker handles associated with multiple distinct cybercrime groups that have occasionally collaborated on a series of supply chain and data ransom attacks over the past nine months.

Kernelstub, like other administrators in the Cybercats chat, has been using his Twitter/X profile name as his handle in these Matrix communications, frequently tweeting references to other members and to conversations taking place in the Cybercats chat. In a number of cases, the corresponding X accounts for members of the Cybercats chat taunted cybercrime victims publicly before the incidents were reported in the news media.

The Cybercats administrator listed at the top of the screenshot above — “Boxturtle” — is a close associate of TeamPCP who has been tweeting about the group’s conquests under the name @xpl0itrsturtle. This handle corresponds to a data breach broker active on Breachforums and Darkforums who has been selling data stolen in a wave of recent breaches at automobile manufacturers, including BMW Group, Audi, Honda, Mercedes-Benz, Volvo and Toyota, as well as data allegedly taken from Snapchat and SportRadar.

The data leak site for the extortion group or handle “xpl0itrs.”

The Cybercats administrator “SeesawSec” in the screenshot above is the alias of whoever is behind the cybercrime group known as Fulcrumsec, which recently claimed credit for data extortion attacks against the pharmaceutical giant Novo Nordisk, the data broker LexisNexis, and Avnet, a Fortune 500 distributor of electronic components.

The data leak site of Fulcrum Security, a.k.a. Fulcrumsec.

The Cybercats administrator “@pcpcasper” also has been using a similar name on X to discuss TeamPCP’s attacks and victims. This person has an extensive message history on Telegram, where their messages and shared videos show @pcpcasper is an active and vocal member of the National Socialist Network, a neo-Nazi political organization based in Australia.

At one point in these chats, @pcpcasper shared videos and images of what they claimed was their cat, and several of those videos place this user in Western Australia. One source close to the investigation told KrebsOnSecurity that @pcpcasper was one of the two arrested, a claim supported by messages that @kernelstub posted online this morning.

The Cybercats member roster pictured above also features an administrator with the username “T,” which is short for the now-banned Twitter/X profile @pcpcats, the account operated by the self-described TeamPCP spokesperson who was arrested today. As we’ll see in a moment, @pcpcats also is from Western Australia.

By the time @kernelstub tweeted a public invite link to the Cybercats Matrix server, T/@pcpcats was posting only infrequently to the group chat, with other members often inquiring as to his whereabouts and well-being. The group’s collective concern related to @pcpcats’s tendency to blame his increasingly extended absences on the use of hallucinogens and other narcotics that kept him awake for days on end, but also caused him to crash in bed for several days after the highs wore off.

WHO IS THE TEAMPCP LEADER?

The Cybercats member @pcpcats has used multiple nicknames on the cybercrime forums, including EllisD25/LSD on Darkforums, BulkDMT on Breachstars, and Express on Breachforums. These accounts are linked because they all advertised the same Tox ID and/or Session ID as instant message contact handles in their cybercrime forum posts. BulkDMT was also known on the forums as DMT Host, which was a virtual private server (VPS) hosting service that was peddled on Darkforums and Breachstars.

DMT Host/EllisD25, posting on the English-language cybercrime community DarkForums in September 2025. Image: ke-la.com.

According to the cyber intelligence firm Intel 471, Express registered on Breachforums using the email address shitstickpp@gmail.com. Intel 471 finds Express posted on Breachforums across a two-month period in 2025 using four different Internet addresses located in South Africa. On July 30, 2025, Express announced on Breachforums they were selling access to 14 gigabytes of data stolen from South Africa’s State Information Technology Agency.

The threat intelligence platform Flashpoint recorded more than a year’s worth of messages from the TeamPCP leader’s alter ego on Telegram — Persy_PCP —  who claimed they split their life living between two countries [full disclosure: Flashpoint is an advertiser on this blog]. “I have these [files] as well, problem is these are in another country,” Persy_PCP explained to another user inquiring about a stolen data set in November 2025.

Later that month, Persy_PCP complained, “My whole country is racist and they want people like me dead.” Flashpoint records show BulkDMT shared in September 2025 that “this country is going to fucking starve when they take the farmers land,” a likely reference to white landowners in South Africa who claim to be targeted by an ongoing genocide campaign.

This tracks with public reporting on TeamPCP. Cyberscoop reported in June that Google had traced TeamPCP’s residential and mobile Internet address connections to South Africa, “indicating the primary operator was located there during at least some of its attacks.”

BulkDMT also shared on the group chat at Breachforums that they were recovering from an addiction to methamphetamine. “My life is kinda fucked rn [right now], but that’s fine and there isn’t really a point in pouring so much emotional energy into that fact, my parents had money but I unfortunately got really addicted to some things so I don’t get to benefit from that. As long as I continue to survive, stay sober, and move closer towards my goals that’s enough drive and meaning.”

The identity threat protection company SpyCloud finds shitstickpp@gmail.com shows up in the registration of an account called ChristmasSnow on the cybercrime community Raidforums in 2022. Nearly all of the Internet addresses used to access that account came from ISPs in Perth, Australia, SpyCloud found.

KrebsOnSecurity looked up all of those Perth IP addresses in passive DNS records maintained by DomainTools.com, and found one of them — 211.27.196.111 — for several years was used as a private file server by a family in Perth with the last name of Thomson. Those records show at least three hosts — ithomson.direct.quickconnect.to (a remote Synology server), kthomson0061.direct.quickconnect.to, and joshuawthomson39.myqnapcloud.com (a QNAP network storage device) — persisted at that address between 2022 and 2025.

Searching on “joshuathomson39” in the breach tracking service Constella Intelligence reveals an account at the freight forwarding company kwe.com created in the name of Joshua Thomson from Perth, Australia. The open source intelligence platform Epieos finds the phone number attached to that kwe.com account was used to register a Facebook profile for Josh Thomson, which says his family includes a brother named Ruben, his father Ian, and his mom Cindy.

That Facebook profile also says Josh and his family are originally from Pietermaritzburg, in KwaZulu-Natal, South Africa, but currently living in Cottesloe, a beach-side suburb of Perth. A search in DomainTools for Ian Thomson and Australia unearthed five domains by the same registrant, including securecomputing.au, thomson.org.au, and thomsonfamily.net.au. Ian Thomson is a dentist in Cottesloe, and a biography says he graduated from The University of the Witwatersrand in Johannesburg, South Africa.

Constella finds a joshua@thomson.org.au registered a number of accounts online, but Josh doesn’t seem to have much of a connection to dodgy cybercrime forums. His brother Ruben, on the other hand, has quite the presence on these communities, dating back to at least 2018. Constella reports ruben@thomson.org.au frequently reused the password “joshuathomson1,” and Constella further finds that password was used by just a handful of accounts, including yolosolo17@gmail.com and surfinup8@gmail.com.

According to Intel 471, surfinup8@gmail.com was used to register the user Yolosolo17 on the crime forum Altenen in 2018, and that user account was registered from the Perth address 110.141.230.15. On Altenen, Yolosolo17 advertised free web proxies, as well as the domain rubenthomson.com, which was at one point used to sell steeply discounted iPhones. DomainTools says rubenthomson.com was hosted at 110.141.230.15 and registered to surfinup8@gmail.com.

A cached copy of the domain rubenthomson.com from 2017 shows a login page underneath a banded stack of money. Image: archive.org.

SpyCloud reports 10.141.230.15 was used by the email address sheepstealing@gmail.com on Raidforums and surfinup8@gmail.com on Nulled, and that the same IP was used by the email addresses ian@thomsonfamily.net.au, jasper@yakuza.cc, and rubenthomson1@gmail.com. SpyCloud also shows that sheepstealing Gmail address is tied to the accounts Sheep420, YoloSolo117 and Yakuza.cc on Raidforums, and to the account “Sheep Stealing” on Hackforums. Intel 471 says sheepstealing@gmail.com was used to register the account DingoFlour on Breachforums in October 2023, as well Sheepx on Altenen.

Epieos reports that ruben@securecomputing.au is tied to an Airbnb account for Ruben, who described himself as a Web developer who went to school at the University of Western Australia and was living outside the country. “Hey, I’m Ruben, my friends call me Ellis. I’m a Perth creative who occasionally books rooms when visiting family and for photography.”

Epieos also finds sheepstealing@gmail.com registered an upwork.com profile under the name Ruben, who said his main skills are setting up secure server hosting solutions and PHP full-stack Web development.

“I’m familiar with Linux, working with relational databases (SQL),” the Upwork profile reads. “I also script in Python mainly for writing social media bots.”

The Upwork profile for Ruben Thomson in Cottesloe, Australia.

Epieos further discovered sheepstealing@gmail.com is connected to a Microsoft account for Ruben Thomson, and to a now-defunct GitHub account called XmasSnow/XmasSnowisBack that scammed people on the forums in 2022 by claiming to sell exclusive exploits for recently-released software patches (recall that shitstickpp@gmail.com was used to register a forum account named ChristmasSnow).

This same sheepstealing email address registered a Twitter/X account in 2026 called “Gone Fishing” that lists its location as South Africa. That Gmail account also left several reviews for businesses listed on Google Maps over the past seven years, but all of those establishments are located on the west coast of Australia.

Business reviews in Western Australia left by the Google account sheepstealing at gmail.com.

The people search service Pipl finds a 21-year-old Ruben Thomson in Western Australia who has a phone number ending in 979. A lookup on that number at Epieos reveals it is connected to a TikTok account under the name Ellis, and to a PayPal account in the name of Ruben Thomson.

Finally, a search on the name Ruben Thomson from Cottesloe at the Australian government’s record of registered businesses finds he has incorporated or served as an official in multiple companies created since 2024, including Secure Computing Solutions, Tensor Industries, and another entity ironically named OPSEC Express. Recall that Express was BulkDMT’s nickname on Breachforums.

Australian companies connected to Ruben Thomson. Image: abr.business.gov.au.

It’s ironic because OPSEC is short for the term “operational security,” which refers to techniques and behaviors used to obfuscate and compartmentalize one’s real-life identity online, and using your cybercrime handle as part of your own company name is very much the antithesis of that practice.

There is at least one other major opsec failure by Ruben that exposed a link to TeamPCP. In June 2025, someone using the name Ruben Thomson registered on HackerOne, a popular “bug bounty” program that seeks to reward and recognize researchers who agree to work with affected software vendors to help fix the flaws before publishing about their findings. What was Ruben Thomson’s chosen HackerOne username? Deadcatx3, a nickname that has been flagged by multiple security firms as an alias used by TeamPCP.

The HackerOne profile for “Ruben Thomson” uses the nickname Deadcatx3, which multiple security firms have concluded is an alias used by TeamPCP. Image credit: flare.io.

INTERVIEW WITH ELLIS

In early July 2026, not long after having discovered clues about Ellis’s real life identity, KrebsOnSecurity interviewed the TeamPCP leader via Signal, where he was remarkably open about his activities and personal struggles [for the sake of simplicity, the TeamPCP spokesperson will be referred to from here on as Ellis].

Ellis claims he stopped doing cybercrime for TeamPCP in March 2026 — just before the attacks that compromised LiteLLM — and that at least one other individual has taken over the group’s leadership since then. Ellis shared that a year earlier he had just completed the latest in a series of detox and sobriety programs, and was two months sober when he reconnected with some old friends from the malware development scene.

“One year ago I needed help monetizing some [GitHub credentials], I was two months sober and needed a distraction and something to keep busy as well as people to speak to,” Ellis said. “I had largely disconnected from my old circle, they had become very toxic and I needed to get away from the substances. Previously I had done some mass exploitation campaigns and grew up doing [malware development] and [capture the flag] contests. There were some friends who were also vending but had stopped a while, and one of them introduced me to some chats where I posted access for sale.”

Prior to that, Ellis said, he was homeless and hopping between “some very unstable places.”

“Blackhatting is fun,” he said. “There are actual rewards and incentives to learn and you grow with your team. Without qualifications, no employer will even take the time to hear you out.”

Ellis claims he’s earned a grand total of about $20,000 for his activities with TeamPCP, and that it was never about the money or fame for him. Asked whether his experiences with TeamPCP might prepare him for gainful employment in a legitimate IT job, Ellis said he doubted it.

“I am nowhere close to a skill level where I am comfortable, and this would take maybe half a decade of further experience,” he said. “I no longer have to choose between rent and food for that I’m grateful and so are the team members.”

Ellis expressed no remorse over his cybercrime activities, and said he was grateful for the friendships and relationships built throughout his engagement with TeamPCP. The young hacker also seemed resigned to his fate, and told KrebsOnSecurity that he’ll accept the consequences if he’s ever arrested.

“If I’ve already been found out then its out of my control, I’ll make peace with that,” he said. “Honestly, I think someone like me needs a lot of help that prison just can’t provide. If I had the funds to study different parts of the field and closer guidance, this would have turned out differently. But that’s a pipe dream and we both know this.”

It is clear from reading Ellis’s posts to the group’s Matrix server chats that his struggles with sobriety are ongoing. On Thursday, June 25, Ellis told @kernelstub he was about to “trip” with his “homie.”

“What kind,” @kernelstub inquired.

“Ketty and some DMT,” Ellis replied, referring to the dissociative anesthetic ketamine and dimethyltryptamine (DMT), a powerful psychedelic compound that is found naturally in some plants but is also synthetically produced in underground lab environments. “There’s a little 2cb so we might throw that in the mix,” he continued, referring to another psychedelic compound by its chemical shorthand.

Roughly two weeks before his arrest, Ellis told KrebsOnSecurity he was ready to leave his life of crime behind and was prepared to turn himself in, but that in the meantime he was making plans to tie up loose ends.

Less than 24 hours later, the TeamPCP leader posted an image on Telegram showing a yellowish powdered substance in a baggie and on a scale, possibly synthetic DMT. The image shows the powder being weighed next to a series of small vape cartridges, two of which are open on the table in front of the photographer.

An image posted by the TeamPCP leader to Telegram, advertising his acquisition of some type of psychoactive substance, most likely a synthetic version of the powerful hallucinogen known as DMT.

The two defendants were arrested Wednesday morning. The AFP said the men face a combined 14 cybercrime offenses and are scheduled to appear in Perth Magistrates Court today.

Charlie Eriksen is a security researcher at Aikido Security who has closely followed TeamPCP’s cybercrime campaigns. Eriksen said TeamPCP are a good example of a new kind of threat actor that does not fit neatly into the usual categories.

“They are not a state actor, not quite organized cybercrime, and not purely ideological,” he said. “Their motivations seem to mix money, disruption, attention, and ideology.”

Eriksen said that historically there has always been a meaningful gap between reading about an attack technique and being able to reliably turn it into an operational campaign, but that large language models (LLMs) and artificial intelligence increasingly are helping threat actors to bypass that knowledge gap.

“You had to understand the research, adapt the code, troubleshoot it, build infrastructure around it, and then repeat that process across different targets,” he said. “LLMs have compressed that gap significantly.”

According to Eriksen, this creates an environment where threat actors suddenly have the ability to operate at significant scale without having developed the operational discipline that traditionally accompanies that level of capability. Put another way, it sets the stage for cybercriminals who are capable enough to cause significant damage, but not necessarily careful enough to understand or care about the consequences.

“They can be noisy, they can make mistakes,” he said. “They can leave evidence everywhere. They can take risks that a professional criminal group or intelligence service would consider completely unacceptable. But that does not necessarily make them less dangerous. In some ways, it can make them more dangerous.”

In a recent blog post, Eriksen called TeamPCP’s Shai-Hulud worm the “best thing to happen to supply chain security,” because it forced GitHub and other public coding platforms to erect new security safeguards.

In direct response to TeamPCP’s broad success at pushing poisoned versions of popular software packages, GitHub in late July introduced a three-day “cooldown” mechanism for Dependabot, the platform’s tool for auto-fetching newly shipped updates for any package dependencies. Cooldown periods are designed to help buy time for security tools and package maintainers to identify and remove any compromised versions. Other coding ecosystems like Python and various JavaScript platforms also added support for cooldown periods this year amid growing calls from security experts about the need for more widespread adoption of the safety feature.

Eriksen said TeamPCP’s legacy is that they achieved in the span of a few months what the supply chain security community has been unable to do for years.

“They managed to wake up Microsoft to the fact that they had become negligent in terms of security,” Eriksen said. “By compromising GitHub and stealing their source code, they humiliated Microsoft into action, making them finally act on what we had been asking them to do and take seriously for a while now.”

Update, 10:08 a.m. ET: A story this morning from ABC News in Australia confirms Ruben Ian Thomson of Cottesloe was one of the two arrested. The 23-year-old suspect thought to be @pcpcasper, Michael Gaebler, also was arrested in Perth. ABC News reports that Thomson was denied bail (Mr. Gaebler’s attorney reportedly did not request bail for his client), and that both men will be held in custody until their next court appearance on September 18.

Pokémon Center Breach Shows Why Your Delivery Data Matters: This Week in Scams

21 August 2026 at 12:00
A pile of Pokemon cards, with Charizard visible.

A data breach doesn’t have to hit the company you shopped with directly to put your information at risk. 

That’s the lesson from this week’s Pokémon Center breach. Customers in the United Kingdom and Germany are being notified that personal and order information was exposed after attackers compromised CEVA Logistics, the third-party company used to fulfill and ship Pokémon Center orders. 

The good news: Pokémon Center says CEVA did not have access to customers’ payment-card information.  

The bigger concern is what criminals could potentially do with the information that was exposed, particularly when it can make a phishing message look unusually convincing. 

What Happened in the Pokémon Center Data Breach? 

According to breach notifications reviewed by BleepingComputer, attackers may have obtained Pokémon Center customers’ full names, mailing addresses, phone numbers, email addresses, and information about the products they ordered. The affected customers were in the UK and Germany. 

The intrusion occurred at CEVA Logistics rather than Pokémon Center itself. Reporting indicates attackers accessed CEVA systems between late July and August 1, disrupting operations at eight European warehouses and affecting multiple retailers. Valve previously notified European Steam hardware customers that their information had also been exposed through the CEVA incident. 

Why Does Shipping Data Matter to Scammers? 

A name and email address may not seem as sensitive as a credit-card number. But when criminals also know your address, phone number, and what you recently bought, they have something valuable: context. 

Context helps scammers make phishing messages believable. 

Phishing is when a criminal pretends to be a trusted company or person to persuade you to click a malicious link, hand over a password, share personal information, or send money. 

After a breach like this, criminals could potentially impersonate Pokémon Center, a delivery company, or another retailer and reference details that make their message feel legitimate. 

They might claim an order needs to be rescheduled, a delivery fee must be paid, or a refund is waiting. Knowing that you really placed an order can make the bait much harder to spot. 

Importantly, there is currently no evidence that the stolen Pokémon Center information is being used in such a campaign. But personalized phishing is a common reason breached contact and transaction information deserves attention. 

Key Takeaways 

➡ Pokémon Center says the breach occurred at its logistics provider, CEVA, not its own shopping platform. 

➡  Names, addresses, phone numbers, email addresses, and order details may have been exposed. 

➡  Pokémon Center says payment-card information was not available to CEVA. 

➡  Real order details could make future phishing or delivery scams appear more credible. 

➡  Customers should independently verify unexpected messages about refunds, cancellations, or deliveries. 

3 Easy Safety Actions to Take If Your Information Is Exposed in a Data Breach 

Getting a breach notification doesn’t necessarily mean someone has already misused your information. It does mean you should take a few steps to make that information harder to use against you. 

1) Find out exactly what was exposed. Read the company’s breach notice carefully. An exposed email address calls for different precautions than a stolen password, Social Security number, financial information, or medical record.

2) Secure the accounts that could be at risk. Change any exposed or reused passwords, use a unique password for every account, and turn on multi-factor authentication where it’s available. If sensitive financial or identity information was stolen, consider a credit freeze or fraud alert as well.

3) Be extra skeptical of messages that know something about you. Breached information can help scammers create convincing emails, texts, and calls. A message that knows your name, address, recent purchase, or other real details isn’t necessarily legitimate. Go directly to the company’s website or app to verify unexpected requests rather than clicking a link or calling a number in the message.  

How McAfee Protects Against Breaches 

Before a breach  

Personal Data Cleanup reduces your digital footprint by removing your personal information from many data broker sites, making it harder for scammers to find and target you.  

Online Account Cleanup scans for accounts you no longer use and helps you delete them, along with your personal info.  

During a breach  

Identity Monitoring watches for your personal information, including email addresses, driver’s license numbers, passport numbers, bank accounts, credit cards, Social Security numbers, phone numbers, and more, across the dark web and known data leaks.   

Plus, we alert users on average up to 10 months earlier than similar services, so you can act fast when your personal information appears where it shouldn’t.  

After a breach  

Scam Detector identifies suspicious texts, emails, and links that often follow major breaches, while web protection blocks malicious websites designed to steal even more of your information. 

Other Scam and Security News This Week 

FBI warns about callers impersonating federal agents. The FBI’s Boston Division is warning about scammers who spoof its real phone number, pretend victims are connected to crimes, and then try to move conversations onto encrypted messaging apps. The key reminder: caller ID can be faked, and the FBI says it will not call private citizens to demand payment, threaten arrest, or request sensitive information. 

(Source: FBI Boston) 

CareCloud breach grows to more than 3.75 million patients. Healthcare technology company CareCloud has confirmed with federal regulators that hackers stole personal and medical information belonging to more than 3.75 million people, including Social Security numbers, health information, government-issued ID numbers, and some financial data. Because medical and identity information cannot simply be replaced like a password, affected people should take breach notifications particularly seriously. 

(Source: TechCrunch) 

Hacker claims millions of corporate directory records were stolen. A cybercriminal known as “TheHatman” is offering databases allegedly taken from the Microsoft Azure and Entra environments of several major companies, although some named organizations dispute that their current systems were breached and say portions of the information appear old. Even older employee information can still be useful for impersonation and targeted phishing, so the claims are worth watching without treating every advertised dataset as independently confirmed. 

(Source: TechRadar) 

This Week’s Safety Tips 

✓ Treat unexpected delivery messages with caution. Open the retailer or carrier’s official app or website instead of following a link in a text or email. 

✓ Don’t trust caller ID alone. Scammers can spoof a legitimate organization’s real phone number. 

✓ Use unique passwords and multi-factor authentication. Stolen personal information becomes more dangerous when criminals can also get into your accounts. 

✓ Pay attention to breach notices. Knowing exactly what information was exposed helps you recognize the scams criminals may try next. 

And we’ll be back next week with more cybersecurity news and scam alerts. 

The post Pokémon Center Breach Shows Why Your Delivery Data Matters: This Week in Scams appeared first on McAfee Blog.

WeedHack Returns: How SEO Poisoning is Leading Minecraft Fans to Malware

20 August 2026 at 12:00

Authored by Aayush Tyagi 

What McAfee Labs found 

McAfee Labs’ latest investigation into the WeedHack malware campaign found that the threat has continued to evolve even after its original command-and-control infrastructure was disrupted by McAfee. Researchers identified multiple active websites still distributing WeedHack to gamers, often by impersonating legitimate Minecraft clients, offering paid tools for free, or using trusted platforms to make malicious downloads appear credible. 

Among the findings: 

→ More than 6,300 attempts to access malicious sites were blocked by McAfee WebAdvisor in the past month. 

→ Researchers found lookalike gaming websites designed to closely replicate legitimate projects, including their branding, feature lists, FAQs, installation guides, developer credits, and links to genuine GitHub repositories. 

→ In one case, the top two Google results observed by researchers for a popular Minecraft client led to sites distributing WeedHack, demonstrating how SEO poisoning can put malicious downloads directly in gamers’ paths. 

→ Nearly half of the malicious URLs identified were Discord links (49.6%), followed by MediaFire (23.4%) and GitHub (8.2%), showing how attackers can use familiar platforms alongside fake websites to distribute malware. 

→ Researchers also identified a malicious site built using an AI-powered website creation platform, illustrating how readily available tools can make it easier to launch convincing new malicious sites. 

Threats like these show why protection needs to start before a malicious download ever reaches your device. McAfee helps block dangerous websites and downloads before malware has a chance to install, helping you stay focused on the game. 

Threats like these show why protection needs to start before a malicious download ever reaches your device. McAfee helps block dangerous websites and downloads before malware has a chance to install, helping you stay focused on the game. 

Background 

2026 has seen a significant shift in malware tactics, where traditional perimeter breaching techniques are being traded in for more elusive methods, such as AI-powered phishing and widespread deployment of Info-stealer malware. Over 560,000 new malware variants are detected every day, with infostealers accounting for the most active category.

McAfee Labs has also seen a significant spike in Malware-as-a-service (MaaS) campaigns, that offer their customers access to sophisticated infostealers and backdoor malware samples at minimal cost. These campaigns provide detailed tutorials to their customers, teaching them how to target popular gaming software, develop authentic-looking websites, and implement SEO Poisoning techniques in order to bamboozle gamers and infect their systems. 

Introduction 

Recently, McAfee Labs has covered a Malware-as-a-service campaign, called ‘Weedhack’ that infected over 116,464 gamers and utilized SEO Poisoning techniques to infect such a large user base.

Read the original article here: Game Over: WeedHack – The Rise of Minecraft Malware-as-a-Service Campaigns

While uncovering the depths of this campaign, we’ve encountered multiple websites and file hosting services that are still active and distributing WeedHack malware. In this article, we cover some of the most prominent examples we’ve encountered in the wild to educate our readers and provide key insights on how to identify and avoid such malicious websites.  

Note: This list is not exhaustive, and there may be additional websites that are not covered in this article.

Malicious websites spreading WeedHack 

During our investigation of this campaign, we observed that most of these websites appear legitimate, as they are well-crafted and often mimic legitimate websites. We observed a series of dedicated brand-impersonation attacks targeting several popular Minecraft clients. 

We published the original article in the first week of July, and, as a result, we’ve seen a disruption in WeedHack’s campaign: its C2 server is no longer active. Consequently, we have observed a shift in tactics by these attackers.  

The WeedHack Dashboard has been taken down, yet we’ve discovered websites that are actively spreading WeedHack malware.  

Out of these URLs, most belonged to file-hosting services:  

  • 49.6% were Discord links 
  • 23.4% were MediaFire links, 
  • 8.2% were GitHub links 
  • 4.6% were Dropbox links 

The remaining URLs were customer-facing websites designed to deceive users. 

In the last month, McAfee WebAdvisor has prevented more than 6,300 users from accessing these malicious websites. At the time of writing this blog, the following websites were still distributing WeedHack malware.  

Figure 1: glazed-client landing page
Figure 1: glazed-client landing page

 

This website ‘glazed-client.com’ replicates the original website called ‘glazedclient.com’. It provides a free and open-source Minecraft add-on called ‘Glazed Client’ designed specifically for DonutSMP server.  
 
The website contains a feature list, along with Archive, Credits, and FAQ sections, that are identical to those on the original website. 

Figure 2: Feature list
Figure 2: Feature list

Under the download section, the website provides three download options, and all of them are infected with WeedHack.  

Figure 3: Download Section
Figure 3: Download Section

This website has a GitHub link, which links to a legitimate GitHub repository in order to build trust with the visitors.  

Example 2 – radium-client.com 

Figure 4: radium-client landing page
Figure 4: radium-client landing page

 

The website ‘radium-client.com’ is replicating a legitimate website called ‘radiumclient.com’. The original website offers Minecraft client for $9.99 per month, but the malicious website offers the same tool for free.  

The malicious replica also has a detailed feature and download section. The downloaded JAR file is infected with WeedHack.  

Figure 5: feature list and download button
Figure 5: feature list and download button

In this instance, the malicious website contains a discord link, similar to the original website, but it points to a channel called ‘EasyClients’, that has over 1,900 members.  

Figure 6: EasyClients Discord Channel
Figure 6: EasyClients Discord Channel

This channel offers 7 different DonutSMP clients for free (Image 7, Highlighted in Red) which are also infected with WeedHack.  

Figure 7: EasyClients Discord Channel
Figure 7: EasyClients Discord Channel

Example 3 – seedcrackerx.github.io 

Figure 8: SeedCrackerX’s landing page
Figure 8: SeedCrackerX’s landing page

In this example, we see GitHub’s web hosting service ‘GitHub.io’ being exploited by attackers. Here they are impersonating ‘SeedCrackerX’ tool, which is a Minecraft seed cracking software capable of identifying the exact world seed used to generate a Minecraft world.  

Figure 9: FAQ section
Figure 9: FAQ section

Here, the malicious websites imitate the original website ‘seedcrackerx.com’, by replicating its fonts and color palette. The website also includes an elaborate tutorial and FAQ section, educating the visitors on how to properly install the tool. 

Figure 10: Download section
Figure 10: Download section

Under the download section, the website offers seven versions to choose from, but all of them are infected with WeedHack. (Highlighted in Red) 

This malicious website has also linked the genuine GitHub repository hosting the SeedCrackerX tool (Highlighted in Green), to appear more legitimate.  

Example 4 – xenoclient.lol and xenonclient.com 

Xenon Client is one of the most popular Minecraft Clients, known for being lightweight, community driven and offering niche vanilla-friendly utilities. Given its widespread popularity, this client is a prominent target for threat actors.

Figure 11: Google search results for ‘Xenon Client’
Figure 11: Google search results for ‘Xenon Client’

 

During our research, we identified that the top two Google search results for ‘Xenon Client’ directed users to websites (Highlighted in Red) that are spreading WeedHack.  

Figure 12: Xenoclient.lol Landing Page
Figure 12: Xenoclient.lol Landing Page

The “xenoclient.lol” website is particularly noteworthy, for the range of features and support it offers. The website includes comprehensive download and installation guides, as well as FAQ and Credits sections. Additionally, it lists the original Xenon Client GitHub repository and features a community section for like-minded gamers, further enhancing its professional appearance. 

Figure 13: Xenoclient.lol Purchase Options
Figure 13: Xenoclient.lol Purchase Options

It offers 2 purchase options for free and premium, where the premium version is listed for $5.  

Figure 14: Download Page
Figure 14: Download Page

The free option, on the other hand, offers six download options for the main client and six additional options for the client optimizer. At the time of writing, only one download link remains operational (highlighted in red), and it delivers a payload infected with WeedHack. 

Another website, “xenonclient.com,” is also targeting Minecraft players, luring them with a free version of the same client. 

Figure 15: xenonclient.com Landing Page
Figure 15: xenonclient.com Landing Page

Similar to other websites in the campaign, this site includes an installation guide and a feature list for the Xenon Client to enhance its apparent legitimacy.  

Figure 16: Feature List
Figure 16: Feature List

The final JAR file downloaded from this website infects users with WeedHack. 

Example 5 – nova-client.com 

Nova client is an open-source client designed for Minecraft Bedrock Edition.

Figure 17: Nova-Client’s landing page
Figure 17: Nova-Client’s landing page

 

This client is an easy target for attackers because it lacks an official website. The legitimate client is hosted on GitHub and Modrinth; however, attackers have created a spoofed website and leveraged SEO poisoning techniques to outrank the official sources in search results.  

Figure 18: Feature Section
Figure 18: Feature Section

This website also includes a Features page, installation guide, and FAQ section. In addition, it displays screenshots from the legitimate Nova Client to deceive users. 
 
What is interesting here is that attackers have also included a credits section, which is common with legitimate Minecraft client websites. However, they do not mention anyone who has actually worked on the project and instead used generic team names.  

Figure 19: Credits Section
Figure 19: Credits Section

The download section provides Nova Client for Minecraft 1.21.11, but the download file spreads WeedHack malware. 

Figure 20: Download Section
Figure 20: Download Section

Example 6 –  cheatlib.xyz 

CheatLib advertises that their clients have been downloaded over 1.6 million times, are free from malware and offers round-the-clock support.

Figure 21: CheatLib’s landing page
Figure 21: CheatLib’s landing page

 Similar to other such websites, it also features a setup guide and a FAQ section to address common user issues. 

Figure 22: Status Section
Figure 22: Status Section

They provide eight Minecraft Mods and inform users which Minecraft servers and anti-cheat systems they can bypass, as well as the current status of each mod.  

Figure 23: Download Section
Figure 23: Download Section

Although the website offers eight distinct mods, all eight files share the same hash and distribute the WeedHack payload. 

Figure 24: CheatLib Discord Channel
Figure 24: CheatLib Discord Channel

This website also links to a Discord channel called ‘CheatLib’ with over 220 users, which also provides access to WeedHack infected mods. 

Example 7 – meteorclients.com 

Figure 25: Meteor Client’s landing page
Figure 25: Meteor Client’s landing page

This malicious domain ‘meteorclients.com’ is impersonating a legitimate website ‘meteorclient.com’. They claim that this client has been downloaded over 10 million times and has over 15 thousand active users at any given time.  

Figure 26: Team Section
Figure 26: Team Section

The Team section contains the names of the legitimate Meteor Client developers, which appear to have been copied from the project’s official website, to create an appearance of authenticity.  

Figure 27: Preview Section
Figure 27: Preview Section

They also provide an interactive preview of Meteor client on the website, enabling users to test and familiarize themselves with the client. The website offers a single download option, which is infected with WeedHack. 

Example 8 – 22qq-client.com 

22qq-client is a Minecraft Mod for Crystal PVP servers.

Figure 28: 22qq-client’s Landing Page
Figure 28: 22qq-client’s Landing Page

This mod does not have a dedicated website, and attackers are exploiting this issue. This website is meant to serve as the official page for the client. 

Figure 29: FAQ section.
Figure 29: FAQ section.

The attackers attempt to establish credibility by using screenshots from the legitimate client.  

Figure 30: Preview of 22-qq.
Figure 30: Preview of 22-qq.

They also offer an interactive preview of the client to give users an overview of its functionality. This website provides multiple download buttons, but all of them download the same JAR file, which is infected with WeedHack. 

Example 9 – kryptonclientcrack.lovable.app 

Krypton Client is a paid Minecraft tool for DonutSMP server, hosted on ‘kryptonclient.org’. This malicious counterpart claims to offer a cracked version of the tool.  

Figure 31: Krypton’s Landing Page
Figure 31: Krypton’s Landing Page

The attackers have used an AI-powered tool called ‘lovable.app’ that allows customers to build and launch functional web applications and websites, using natural language. Such tools make it easier for attackers to deploy new malicious domains on the fly.  

Figure 32: Download Section
Figure 32: Download Section

The website claims that the tool has been downloaded more than five thousand times and has been thoroughly tested for safety. They offer a single download option, which is infected with WeedHack. 

Example 10 – File Hosting Services  

In the course of our investigation, we observed that multiple attackers were exploiting various file hosting services to spread malware. 

Figure 33: GitHub Repository spreading WeedHack
Figure 33: GitHub Repository spreading WeedHack

Links to these websites are then distributed via different communication channels, such as Discord, Reddit and other online platforms. 

Figure 34: GitHub Repository spreading WeedHack
Figure 34: GitHub Repository spreading WeedHack

We also observed that threat actors extended their targeting beyond Minecraft clients, compromising various popular and independent community websites within the Minecraft ecosystem.

Figure 35: Planet Minecraft
Figure 35: Planet Minecraft

At the time of this analysis, the following Planet Minecart links were spreading WeedHack malware. 

hxxps://static.planetminecraft.com/files/resource_media/mod/mousetweaks-fabric-mc1-21-9-2-29.jar 

hxxps://static.planetminecraft.com/files/resource_media/mod/no-delay-optimizer1-21-4.jar 

Similarly, we observed another community website, called EndMods was also targeted by WeedHack.

Figure 36: EndMods
Figure 36: EndMods

The following link is still active, at the time of publication, and is still spreading the WeedHack malware.  
hxxps://endmods.com/wp-content/uploads/2026/02/KRYPTON-CLIENT1.0.zip 

How To Protect Yourself Online 

At McAfee Labs, we investigate threats across the digital landscape, and gamers are a frequent target. We’ve seen multiple malware-as-a-service campaigns similar to WeedHack use fake downloads, impersonated websites, malicious mods, and other lures to target gaming communities. 

AI-powered tools can make it faster and easier for scammers to create convincing websites, imitate legitimate services, and launch new campaigns at scale. That makes it even more important to know what you’re downloading, and where it’s coming from. 

Here are a few ways gamers can stay safer: 

→ Stick to trusted sources. Download games, mods, clients, and other files from official developer websites or reputable mod platforms whenever possible. If you can’t verify the source, don’t download it. 

→ Never turn off your security software for a download. Be suspicious of any mod, cheat, or client that tells you to disable your antivirus or other protections before installing it. 

→ Scan files before opening them. Check downloaded mods, installers, and archives before running them — even if they came from a popular gaming community or website. 

→ Be skeptical of offers that seem too good to be true. “Free” premium features, exclusive cheats, cracked software, or paid clients can be used as bait to convince gamers to download malware. 

→ Check the URL before you download. Scammers can create lookalike domains and convincing copies of legitimate gaming sites. Small changes in a web address can be a sign you’re on an impersonation site. 

→ Pay attention to security warnings. If your antivirus flags a download, don’t automatically assume it’s a false positive. Stop and investigate before allowing the file to run. 

→ Keep your devices and software updated. Install updates for your operating system, browser, games, and security software to help protect against known vulnerabilities. 

Indicator of Compromise(s)  

hxxps://glazed-client.com/ 
hxxps://github.com/Hl3n/GambleRigMod 
hxxps://www.radium-client.com/ 
hxxps://discord.com/channels/1467145812906872834/ 
hxxps://seedcrackerx.github.io/ 
hxxps://github.com/seedcrackerx/seedcrackerx.github.io 
hxxps://xenonclient.com/ 
hxxps://xenoclient.lol  
hxxps://nova-client.com/ 
hxxps://cheatlib.xyz/ 
hxxps://discord.com/channels/1478170973755936990 
hxxps://meteorclients.com 
hxxp://22qq-client.com/ 
hxxps://kryptonclientcrack.lovable.app 
hxxps://github.com/lsellh/ 
hxxps://static.planetminecraft.com/files/resource_media/mod/mousetweaks-fabric-mc1-21-9-2-29.jar 
hxxps://static.planetminecraft.com/files/resource_media/mod/no-delay-optimizer1-21-4.jar 
hxxps://endmods.com/wp-content/uploads/2026/02/KRYPTON-CLIENT1.0.zip 

 

The post WeedHack Returns: How SEO Poisoning is Leading Minecraft Fans to Malware appeared first on McAfee Blog.

Meta Ran Ads for an App That Promised to Nudify Female Politicians

18 August 2026 at 14:45
One advertisement featured a pornographic video with a deepfake closely resembling a prominent US politician. Apple removed the app from the App Store after an inquiry from WIRED.

Fake “The Odyssey” Downloads Are Spreading Malware: This Week in Scams

14 August 2026 at 12:00

This week in scams and cybersecurity news, 

Looking for a free download of this summer’s biggest movie could come with something you definitely didn’t ask for: malware. 

Here’s what to watch for. 

Fake The Odyssey Downloads Are Hiding Malware 

Speaking of Trojan horses….

Security researchers have reportedly identified malicious downloads disguised as pirated copies of The Odyssey, including files designed to look like high-quality movie releases. 

Some fake files even use familiar video-player icons and movie-style filenames to appear legitimate.

But instead of opening a movie, downloading or running the file can launch malicious software capable of stealing information from the device. Other scams reportedly use fake streaming sites that ask users to enter personal or payment information to access a supposedly “free” movie.  

McAfee researchers routinely see cybercriminals attach malware to the things people are already searching for, especially popular movies, TV shows, games, mods, and software. 

In a recent example, McAfee Labs uncovered the WeedHack malware campaign targeting Minecraft players, which disguised malicious software as free game mods and clients. Our researchers recorded more than 116,000 infections from the campaign since January. 

The media changes. The scam doesn’t.

What Makes Fake Movie Downloads Dangerous? 

A supposed movie file can hide: 

  • Infostealers designed to collect passwords, browser sessions, payment information, or cryptocurrency data 
  • Trojans that give an attacker access to your device 
  • Loaders that install additional malware 
  • Fake browser updates or extensions that redirect you to scams or malicious websites 

One especially obvious warning sign: movies should not arrive as executable .exe files. Legitimate video files generally use formats such as .mp4, .mkv, or .avi. 

When in doubt, don’t download it. 

How McAfee Protects Against Malware

With McAfee+, multiple layers can help protect you when a tempting download isn’t what it claims to be: 

Device Security helps detect malicious apps, files, and downloads before they can compromise your device. 

Web Protection helps block risky websites, including malicious download pages, even if you accidentally click. 

Scam Detector flags suspicious texts, emails, links, QR codes, and other messages that may try to direct you toward fraudulent sites. 

Identity Monitoring alerts you if your personal information appears in known data leaks or on the dark web so you can take action quickly. 

Together, these protections help address both sides of fake-download scams: stopping malware before it gets onto your device and helping protect your information if criminals try to steal it. 

Other Scam and Security News This Week 

Here are some other breaches, scams, and cybersecurity headlines making waves this week:

Trezor breach reportedly exposes information belonging to nearly 14,000 crypto customers.

Hardware wallet maker Trezor says a breach involving one of its shipping providers exposed personal information including names, email addresses, phone numbers, and home addresses for thousands of customers.  

McAfee’s 2026 State of the Scamiverse predicted that crypto and financial scams were likely to intensify this year, and cryptocurrency-related messages remain among the scams McAfee Scam Detector regularly identifies and blocks.

(Financial Times) 

Cyberattacks continue to climb worldwide.

New threat research found organizations experienced an average of 2,336 cyberattacks per week in July, a 16% increase from the previous year, while reported ransomware victims also rose sharply. Education, government, telecommunications, and other major sectors remained frequent targets.

(IT Brief) 

Android malware can turn a victim’s phone into part of a contactless-payment scam.

Researchers investigating the targeted WindRelay campaign say criminals impersonated banks over the phone, persuaded victims to install malicious Android apps, and then instructed them to tap their physical bank cards against their phones. 

That allowed attackers to relay contactless card information in real time, with researchers reporting some attacks unfolded during calls lasting only about 13 minutes.

(TechRadar) 

This Week’s Safety Tips 

✓ Stream and download from legitimate sources. New theatrical releases appearing for free on unfamiliar websites should immediately raise suspicion. 

✓ Check the actual file type before opening a download. A movie should never require you to run an .exe application. 

✓ Never install a “special player,” browser update, or extension just to watch a movie. Close the page and go directly to a trusted streaming service instead. 

✓ Treat urgency and exclusivity as warning signs. “Watch it before everyone else,” “leaked copy,” and “limited access” are designed to get you clicking before you think. 

And we’ll be back next week with more cybersecurity news and scam alerts. 

The post Fake “The Odyssey” Downloads Are Spreading Malware: This Week in Scams appeared first on McAfee Blog.

CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues

13 August 2026 at 09:30
Records obtained by WIRED detail hundreds of allegations of Customs and Border Protection workers misusing internal tools to look up romantic interests and track colleagues’ cell phones.

GTA 6 Is Coming. So Are the Scams. Here’s What McAfee Experts Found

12 August 2026 at 12:00

Millions of gamers are counting down the days until this fall’s biggest releases. 

After more than a decade of anticipation, Grand Theft Auto VI is finally set to launch this November. Surprise indie hit Meccha Chameleon has exploded across Twitch and YouTube after selling millions of copies within days. And highly anticipated titles like Call of Duty: Modern Warfare 4, Minecraft Dungeons 2, Phantom Blade Zero, Marvel’s Wolverine, and dozens of others are keeping players glued to trailers, wishlists, Discord servers, and preorder pages. 

Scammers are watching those trends. 

Whenever millions of people rush to search for the same game, criminals quickly create fake downloads, unofficial mobile apps and servers, counterfeit storefronts, phishing pages, and cheat tools designed to steal money, credentials, or personal information. 

This year is no exception. 

Here’s how scammers are taking advantage of 2026’s biggest gaming moments, and how you can avoid becoming their next target, according to McAfee’s experts: 

The Most Common Gaming Scams and How to Avoid Them, According to McAfee 

Most gaming scams fall into a handful of predictable categories. Once you know what to look for, they’re much easier to spot. 

Here are some of the most common scams McAfee protection prevents 

Scam  What it looks like  Red flags  How to protect yourself 
Fake game downloads  “Free” copies, cracked launchers, unofficial installers  Unknown websites, requests to disable antivirus, ZIP files instead of official installers  Download games only from official publishers or trusted storefronts 
Fake early access  Too-good-to-be-true VIP access, beta invites, playable versions before launch that don’t exist   Cryptocurrency payments, countdown timers, “exclusive” offers, unofficial websites  Verify release dates , including early access dates, and preorder information directly with the publisher 
Cheats, mods, and trainers  Unlimited money, aimbots, unlock tools, auto-play software  Downloads shared through Discord, YouTube descriptions, file-sharing sites  Only use trusted community repositories and avoid executable files from unknown sources 
Fake mobile versions  Mobile apps for games that don’t officially exist on Android or iPhone  Different developer names, excessive ads, cloned screenshots  Confirm that the developer has actually released a mobile version before downloading 
YouTube and Discord scams  Videos claiming to have mods or secret builds  Shortened links, pinned download comments, Discord invite links  Visit the developer’s official website instead of getting mods or clicking links from comments or descriptions 
Fake giveaways and free skins  Free cosmetics, DLC, battle passes, or gift cards  Requests to sign in through third-party sites or enter account credentials  Only redeem offers through official game platforms 

 These tactics aren’t theoretical. They’re happening right now. 

Detected by McAfee Labs: Malware Campaigns, Malicious Downloads, and Suspicious Apps 

Earlier this year, McAfee Labs uncovered WeedHack, a malware campaign disguised as free Minecraft mods and game clients.  

Since January 2026, the campaign has infected more than 116,000 devices, averaging roughly 2,000 to 3,000 new infections every day. Attackers lured players through fake mod websites and convincing YouTube videos before installing malware capable of stealing passwords, cryptocurrency wallets, Discord credentials, Minecraft accounts, and more.  

Ultimately these gaming attacks can expose players to: 

  • Malware infections  
  • Account theft  
  • Password theft  
  • Data breaches  
  • Spyware monitoring cameras and microphones 
  • Spyware monitoring keyboard and mouse inputs 
  • Permanent game bans  

One of the campaign’s most concerning findings wasn’t just the malware itself, it was how inexpensive and accessible the tools had become. The malware was marketed almost like legitimate software, lowering the barrier for inexperienced attackers and helping spread scams throughout gaming communities. 

The lesson isn’t to avoid every cheat, unlock, or community-created project. It’s to be skeptical whenever someone promises something that seems too good to be true. 

Meccha Chameleon Shows How Quickly Scammers Embrace Viral Games 

Few people predicted Meccha Chameleon would become one of the biggest surprise gaming success stories of the year. 

The inexpensive indie title reportedly sold more than two million copies within days, fueled largely by livestreams, social media clips, and word of mouth. Unfortunately, that kind of overnight success doesn’t just attract new players. 

According to PC Gamer, players have already begun using automated “auto-paint” cheats that scan the environment and instantly camouflage characters, removing much of the creativity and skill the game was designed around. 

The game’s popularity has also created confusion about where players can safely download it. 

McAfee researchers recently identified multiple Android apps and an unofficial piracy site using the Meccha Chameleon name, despite the game’s independent developer not announcing an official Android release.  

Here’s how we saw it play out 

First a gamer might navigate to this piracy site to download a free game. The game may not come with malware, but malware is still distributed during the process. 

An example of fake steam Meccha Chameleon

Here we see steamgg[.]net, a piracy site to download free games. Here you see they offer a download of Meccha Chameleon (not malicious).

But when you click download, it opens a misleading new tab like this one below.

A popup claiming your download is ready

This new tab tricks the user into thinking they are downloading a game from steamgg[.]net. They are actually being redirected to a completely unrelated download.

In cases like this, unauthorized sites and apps trick users into giving unwanted access to their information and devices.

 

Google Play store apps showing Meccha Chameleon
Here we see examples of fake versions of Meccha Chameleon uploaded to the Google Play Store 

*Note: The unauthorized apps shown here have since been reported and taken down. While not confirmed to be malicious, hundreds of people had already downloaded and given security permissions to these apps.* 

“Repackaged or unauthorized apps and sites are a major risk with viral games,” says McAfee Threat Researcher and lifelong gamer Charles McFarland.  

“Because many players are unfamiliar with the original developer, it’s easier for unauthorized apps and copycat listings to blend into app stores,” McFarland explains. “Once installed, the app can have free access to your phone’s data, texts, contacts, and more.” 

Before downloading a newly popular game, especially on mobile, take a moment to verify that the developer has actually released it for your device. 

Is This GTA 6 Download Legit? How to Spot Fake Early Access Scams 

If there’s one game scammers are betting people will search for this fall, it’s Grand Theft Auto VI. 

Rockstar Games officially opened global preorders on June 25, and the game launches worldwide on November 19, 2026 for PlayStation 5 and Xbox Series X|S. Digital preorders can begin preloading on November 12. 

That hasn’t stopped scammers from advertising: 

  • “Play GTA 6 today”  
  • VIP Early Access  
  • Secret beta downloads  
  • Discounted preorder keys  
  • Cryptocurrency-only purchases  
  • “Exclusive” launchers 

The problem?  Those offers promise something Rockstar isn’t selling. 

If a website claims it can provide a playable version of GTA 6 before Rockstar’s official launch, treat it as a major warning sign. 

Scammers know players have waited more than a decade for the next Grand Theft Auto. They’re counting on excitement to outweigh skepticism. 

“Every major game launch brings a noticeable increase in gaming-themed scams. We regularly see McAfee protecting customers from malicious downloads, fake websites, and other threats that capitalize on the excitement around new releases,” McFarland says. 

“As a gamer myself, I know the excitement of jumping into a long-awaited game with my son, but it’s worth taking an extra minute to download from an official or authorized source instead of rushing to be first.” 

Whenever possible, verify preorder information directly through Rockstar Games or trusted digital storefronts rather than clicking links shared through social media posts, livestream chats, YouTube comments, or unsolicited messages and advertisements. 

Official storefront  Trending and Upcoming Games 
Steam  Meccha Chameleon, Dune: Awakening, Metal Gear Solid: Master Collection Vol. 2, Silent Hill: Townfall, Call of Duty: Modern Warfare 4, Phantom Blade Zero, No Rest for the Wicked, Planet Zoo 2, Kingdom Hearts Collections, Ace Combat 8, Gears of War: E-Day (PC), Minecraft Dungeons 2 and many other PC releases 
PlayStation Store  Grand Theft Auto VI, Marvel’s Wolverine, Phantom Blade Zero, Onimusha: Way of the Sword, Metal Gear Solid: Master Collection Vol. 2, Call of Duty: Modern Warfare 4, Dune: Awakening, Silent Hill: Townfall and other PlayStation releases 
Xbox Store  Grand Theft Auto VI, Gears of War: E-Day, Call of Duty: Modern Warfare 4, Dune: Awakening, Ace Combat 8, Kingdom Hearts Collections and other Xbox releases 
Nintendo eShop  Rhythm Heaven Groove, Splatoon Raiders, Fire Emblem: Fortune’s Weave, Harvest Moon: Echoes of Teradea, Nintendo Switch Sports Resort, The Legend of Zelda: Ocarina of Time Remake and other Nintendo titles 

 *Availability may vary by platform as publishers announce additional releases. 

If you can’t find a game on one of its official storefronts, that’s a good reason to pause before downloading it elsewhere. 

How McAfee Protects Gamers 

Gaming should be about exploring new worlds, not accidentally downloading malware. 

McAfee helps protect players before, during, and after they click. 

Web Protection helps block known malicious websites before fake downloads ever reach your device. 

Award-winning antivirus detects and blocks malware hidden inside suspicious installers, cheats, and unofficial software. 

If a file is flagged, Threat Explainer provides a clear, plain-language explanation of why it’s considered risky, helping you make informed decisions instead of guessing whether a warning is legitimate. 

And if you’re worried additional security will slow down your games, McAfee Total Protection has repeatedly scored first place in the AV-Comparatives PC Performance Test, an independent benchmark that measures how much security software impacts your computer’s performance.  

McAfee earned the lowest overall impact score among the 20 products tested and received the highest possible rating, 3 Stars ADVANCED+. In other words, you get strong protection without sacrificing performance or slowing your game. 

Whether you’re preordering GTA 6, trying the latest indie hit, or installing a new Minecraft mod, slowing down long enough to verify where you’re downloading from remains one of the simplest, and most effective, ways to protect yourself. 

Frequently Asked Questions 

FAQs 
Q: Is GTA 6 early access real?

A: No. Rockstar Games has announced pre-orders and pre-loading ahead of launch, but there is no legitimate way to play GTA 6 early through unofficial websites. Be wary of any site claiming to sell “VIP access,” beta keys, or downloadable copies before the official release date. 

Q: Is it safe to pre-order GTA 6 from any website?

A: Stick to Rockstar Games or authorized retailers and digital storefronts like the PlayStation Store and Xbox Store. Avoid unfamiliar websites advertising deep discounts, exclusive editions, or cryptocurrency-only payments. 

Q: Does Meccha Chameleon have an official Android or iPhone app?

A: At the time of writing, the game’s developer has not announced an official mobile version. If you find Meccha Chameleon in an app store, verify that it’s published by the official developer before downloading. 

Q: Are game cheats and trainers safe to download?

A: Not always. While some cheats simply modify gameplay, others can contain malware, steal passwords, or compromise gaming accounts. Downloading cheats from unofficial websites or Discord servers carries additional risk. 

Q: Can Minecraft mods contain malware?

A: Yes. While many Minecraft mods are legitimate, cybercriminals have repeatedly used fake mods and clients to distribute malware. Download mods only from trusted community repositories or verified developer pages. 

Q: How can I tell if a game download is legitimate?

A: Download games directly from the publisher’s official website or trusted digital storefronts like Steam, PlayStation Store, Xbox Store, Nintendo eShop, or Epic Games Store. Avoid links shared through YouTube comments, Discord messages, or unofficial social media posts. 

Q: Why do scammers target popular game releases?

A: High-profile launches create excitement and urgency, making players more likely to click on fake download links, preorder scams, cheat tools, or unofficial apps without stopping to verify they’re legitimate. 

Q: What are the biggest gaming scams to watch for in 2026?

A: Common gaming scams include fake early access offers, counterfeit game downloads, unofficial mobile apps, cheat software bundled with malware, phishing pages posing as gaming platforms, and fake giveaways promising free games or in-game items. 

Q: Can antivirus slow down gaming performance?

A: Some security software can affect system performance, but independent testing has shown that solutions vary significantly. Look for products that perform well in third-party performance benchmarks while still providing strong protection against malware and phishing attacks. McAfee Total Protection recently took first place in the latest AV-Comparatives PC Performance Test, an independent benchmark that measures how much security software impacts your computer’s performance. In other words, McAfee provides strong protection without sacrificing performance or slowing your game. 

Q: What’s the safest way to download new games this fall?

A: Buy or download games directly from official publishers and trusted storefronts, keep your operating system and antivirus up to date, avoid unofficial cheats or cracked versions, and verify any unexpected links before clicking. 

 

The post GTA 6 Is Coming. So Are the Scams. Here’s What McAfee Experts Found appeared first on McAfee Blog.

❌