If you don't fall for these extortionists' calls, they'll show up with USB sticks

One gaming cyberattack this week exposed nearly 64,000 users.
Another has already infected more than 116,000 players.
Both are connected by the same common gaming behavior: looking for a cheat, mod, or shortcut.
This week in scam news, a popular Grand Theft Auto V cheat service was hacked, exposing tens of thousands of users. At the same time, McAfee researchers uncovered a massive malware campaign spreading through fake Minecraft mods, cheats, and game clients.
The takeaway is simple: some of the biggest threats facing gamers aren’t happening inside games. They’re hiding in the downloads, websites, and tools players use around them.
Let’s start with the GTA breach.
Atlas Menu, a cheat service for Grand Theft Auto V, was reportedly hacked, exposing data belonging to nearly 64,000 users.
According to reports, the leaked information included:
The hacker who claimed responsibility later posted the data online.
Many players think of cheats as harmless tools that unlock special abilities, provide advantages, or simply make games more entertaining.
But unofficial cheat services often operate outside the protections offered by legitimate gaming platforms.
That means users may be:
And that brings us to an even bigger threat.
McAfee researchers recently uncovered a large-scale malware operation targeting gamers searching for Minecraft mods, clients, and cheats.
The campaign is called WeedHack.
WeedHack is a type of Malware-as-a-Service (MaaS).
That means cybercriminals package malware into a subscription service that other attackers can use.
Researchers found that:
Premium versions reportedly cost as little as $5 per month and include tools that allow attackers to remotely access victims’ devices and webcams.
Once installed, the malware can collect:
Premium versions can also provide:
Gaming malware campaigns rely on three things:
With McAfee+ Advanced, multiple layers work together before any damage is done:
Together, these protections are designed to address the broader range of online risks people face every day.
Here are some other important headlines to be aware of:
Carnival Corporation disclosed a data breach affecting nearly six million customers after a social engineering attack allowed an unauthorized individual to gain access to part of the company’s IT systems.
Exposed information may include:
Affected customers should be alert for phishing emails, fake customer support calls, and identity theft attempts.
Instagram says it has fixed an issue that reportedly allowed attackers to manipulate its AI-powered support chatbot and gain access to other users’ accounts.
According to reports, attackers were allegedly able to influence the account recovery process and associate new email addresses with targeted accounts.
The incident highlights a growing challenge for AI-powered customer support systems: convenience cannot come at the expense of identity verification.
Voice cloning scams continue to grow as AI tools make it easier than ever to imitate friends, family members, and coworkers.
According to FBI data cited this week, Americans lost more than $893 million to AI-related scams last year.
These scams included:
If someone calls claiming to be a loved one in distress and urgently requests money, verify the situation through another communication channel before taking action.
Whether you’re downloading a Minecraft mod or answering an unexpected phone call, the same rule applies:
Slow down before you click, download, or share information.
Here are a few ways to stay safer:
We’ll be back next week with more scams making headlines.
The post GTA Cheat Users Exposed in Breach as Minecraft Malware Hits 116,000 Players appeared first on McAfee Blog.

Today, we welcome the 46th government onboarded to Have I Been Pwned’s free gov service: the Philippines.
The Philippines’ National CERT, working with the Department of Information and Communications Technology, now has access to monitor official government domains against the data in HIBP. This gives their Cyber Threat Intel and Monitoring Section the ability to identify exposure across government email addresses and respond quickly when those accounts appear in new data breach.
This is precisely what the HIBP government service was built for: helping national cyber teams better understand credential exposure across their government domain space, monitor for compromised accounts on demand via API, and receive notifications when government domains are impacted by newly loaded breach data.
The Philippines joins a growing list of national CERTs and government cybersecurity teams using HIBP to help strengthen national cyber defense, protect government departments and resources, and reduce the risk posed by compromised credentials before attackers can take advantage.