Reading view

WeedHack Returns: How SEO Poisoning is Leading Minecraft Fans to Malware

Authored by Aayush Tyagi 

What McAfee Labs found 

McAfee Labs’ latest investigation into the WeedHack malware campaign found that the threat has continued to evolve even after its original command-and-control infrastructure was disrupted by McAfee. Researchers identified multiple active websites still distributing WeedHack to gamers, often by impersonating legitimate Minecraft clients, offering paid tools for free, or using trusted platforms to make malicious downloads appear credible. 

Among the findings: 

→ More than 6,300 attempts to access malicious sites were blocked by McAfee WebAdvisor in the past month. 

Researchers found lookalike gaming websites designed to closely replicate legitimate projects, including their branding, feature lists, FAQs, installation guides, developer credits, and links to genuine GitHub repositories. 

In one case, the top two Google results observed by researchers for a popular Minecraft client led to sites distributing WeedHack, demonstrating how SEO poisoning can put malicious downloads directly in gamers’ paths. 

Nearly half of the malicious URLs identified were Discord links (49.6%), followed by MediaFire (23.4%) and GitHub (8.2%), showing how attackers can use familiar platforms alongside fake websites to distribute malware. 

Researchers also identified a malicious site built using an AI-powered website creation platform, illustrating how readily available tools can make it easier to launch convincing new malicious sites. 

Threats like these show why protection needs to start before a malicious download ever reaches your device. McAfee helps block dangerous websites and downloads before malware has a chance to install, helping you stay focused on the game. 

Threats like these show why protection needs to start before a malicious download ever reaches your device. McAfee helps block dangerous websites and downloads before malware has a chance to install, helping you stay focused on the game. 

Background 

2026 has seen a significant shift in malware tactics, where traditional perimeter breaching techniques are being traded in for more elusive methods, such as AI-powered phishing and widespread deployment of Info-stealer malware. Over 560,000 new malware variants are detected every day, with infostealers accounting for the most active category.

McAfee Labs has also seen a significant spike in Malware-as-a-service (MaaS) campaigns, that offer their customers access to sophisticated infostealers and backdoor malware samples at minimal cost. These campaigns provide detailed tutorials to their customers, teaching them how to target popular gaming software, develop authentic-looking websites, and implement SEO Poisoning techniques in order to bamboozle gamers and infect their systems. 

Introduction 

Recently, McAfee Labs has covered a Malware-as-a-service campaign, called ‘Weedhack’ that infected over 116,464 gamers and utilized SEO Poisoning techniques to infect such a large user base.

Read the original article here: Game Over: WeedHack – The Rise of Minecraft Malware-as-a-Service Campaigns

While uncovering the depths of this campaign, we’ve encountered multiple websites and file hosting services that are still active and distributing WeedHack malware. In this article, we cover some of the most prominent examples we’ve encountered in the wild to educate our readers and provide key insights on how to identify and avoid such malicious websites.  

Note: This list is not exhaustive, and there may be additional websites that are not covered in this article.

Malicious websites spreading WeedHack 

During our investigation of this campaign, we observed that most of these websites appear legitimate, as they are well-crafted and often mimic legitimate websites. We observed a series of dedicated brand-impersonation attacks targeting several popular Minecraft clients. 

We published the original article in the first week of July, and, as a result, we’ve seen a disruption in WeedHack’s campaign: its C2 server is no longer active. Consequently, we have observed a shift in tactics by these attackers.  

The WeedHack Dashboard has been taken down, yet we’ve discovered websites that are actively spreading WeedHack malware.  

Out of these URLs, most belonged to file-hosting services:  

  • 49.6% were Discord links 
  • 23.4% were MediaFire links, 
  • 8.2% were GitHub links 
  • 4.6% were Dropbox links 

The remaining URLs were customer-facing websites designed to deceive users. 

In the last month, McAfee WebAdvisor has prevented more than 6,300 users from accessing these malicious websites. At the time of writing this blog, the following websites were still distributing WeedHack malware.  

Figure 1: glazed-client landing page
Figure 1: glazed-client landing page

 

This website glazed-client.com’ replicates the original website called ‘glazedclient.com. It provides a free and open-source Minecraft add-on called Glazed Clientdesigned specifically for DonutSMP server.  
 
The website contains a feature list, along with Archive, Credits, and FAQ sections, that are identical to those on the original website. 

Figure 2: Feature list
Figure 2: Feature list

Under the download section, the website provides three download options, and all of them are infected with WeedHack 

Figure 3: Download Section
Figure 3: Download Section

This website has a GitHub link, which links to a legitimate GitHub repository in order to build trust with the visitors.  

Example 2 – radium-client.com 

Figure 4: radium-client landing page
Figure 4: radium-client landing page

 

The website radium-client.com’ is replicating a legitimate website called ‘radiumclient.com. The original website offers Minecraft client for $9.99 per month, but the malicious website offers the same tool for free.  

The malicious replica also has a detailed feature and download section. The downloaded JAR file is infected with WeedHack 

Figure 5: feature list and download button
Figure 5: feature list and download button

In this instance, the malicious website contains a discord link, similar to the original website, but it points to a channel called ‘EasyClients, that has over 1,900 members.  

Figure 6: EasyClients Discord Channel
Figure 6: EasyClients Discord Channel

This channel offers 7 different DonutSMP clients for free (Image 7, Highlighted in Red) which are also infected with WeedHack.  

Figure 7: EasyClients Discord Channel
Figure 7: EasyClients Discord Channel

Example 3 – seedcrackerx.github.io 

Figure 8: SeedCrackerX’s landing page
Figure 8: SeedCrackerX’s landing page

In this example, we see GitHub’s web hosting service ‘GitHub.io’ being exploited by attackers. Here they are impersonating ‘SeedCrackerXtool, which is a Minecraft seed cracking software capable of identifying the exact world seed used to generate a Minecraft world.  

Figure 9: FAQ section
Figure 9: FAQ section

Here, the malicious websites imitate the original website ‘seedcrackerx.com’, by replicating its fonts and color palette. The website also includes an elaborate tutorial and FAQ section, educating the visitors on how to properly install the tool. 

Figure 10: Download section
Figure 10: Download section

Under the download section, the website offers seven versions to choose from, but all of them are infected with WeedHack. (Highlighted in Red) 

This malicious website has also linked the genuine GitHub repository hosting the SeedCrackerX tool (Highlighted in Green), to appear more legitimate.  

Example 4 – xenoclient.lol and xenonclient.com 

Xenon Client is one of the most popular Minecraft Clients, known for being lightweight, community driven and offering niche vanilla-friendly utilities. Given its widespread popularity, this client is a prominent target for threat actors.

Figure 11: Google search results for ‘Xenon Client’
Figure 11: Google search results for ‘Xenon Client’

 

During our research, we identified that the top two Google search results for Xenon Client directed users to websites (Highlighted in Red) that are spreading WeedHack 

Figure 12: Xenoclient.lol Landing Page
Figure 12: Xenoclient.lol Landing Page

The “xenoclient.lol” website is particularly noteworthy, for the range of features and support it offers. The website includes comprehensive download and installation guides, as well as FAQ and Credits sections. Additionally, it lists the original Xenon Client GitHub repository and features a community section for like-minded gamers, further enhancing its professional appearance. 

Figure 13: Xenoclient.lol Purchase Options
Figure 13: Xenoclient.lol Purchase Options

It offers 2 purchase options for free and premium, where the premium version is listed for $5.  

Figure 14: Download Page
Figure 14: Download Page

The free option, on the other hand, offers six download options for the main client and six additional options for the client optimizer. At the time of writing, only one download link remains operational (highlighted in red), and it delivers a payload infected with WeedHack. 

Another website, “xenonclient.com,” is also targeting Minecraft players, luring them with a free version of the same client. 

Figure 15: xenonclient.com Landing Page
Figure 15: xenonclient.com Landing Page

Similar to other websites in the campaign, this site includes an installation guide and a feature list for the Xenon Client to enhance its apparent legitimacy.  

Figure 16: Feature List
Figure 16: Feature List

The final JAR file downloaded from this website infects users with WeedHack. 

Example 5 – nova-client.com 

Nova client is an open-source client designed for Minecraft Bedrock Edition.

Figure 17: Nova-Client’s landing page
Figure 17: Nova-Client’s landing page

 

This client is an easy target for attackers because it lacks an official website. The legitimate client is hosted on GitHub and Modrinth; however, attackers have created a spoofed website and leveraged SEO poisoning techniques to outrank the official sources in search results.  

Figure 18: Feature Section
Figure 18: Feature Section

This website also includes a Features page, installation guide, and FAQ section. In addition, it displays screenshots from the legitimate Nova Client to deceive users. 
 
What is interesting here is that attackers have also included a credits section, which is common with legitimate Minecraft client websites. However, they do not mention anyone who has actually worked on the project and instead used generic team names.  

Figure 19: Credits Section
Figure 19: Credits Section

The download section provides Nova Client for Minecraft 1.21.11, but the download file spreads WeedHack malware. 

Figure 20: Download Section
Figure 20: Download Section

Example 6 –  cheatlib.xyz 

CheatLib advertises that their clients have been downloaded over 1.6 million times, are free from malware and offers round-the-clock support.

Figure 21: CheatLib’s landing page
Figure 21: CheatLib’s landing page

 Similar to other such websites, it also features a setup guide and a FAQ section to address common user issues. 

Figure 22: Status Section
Figure 22: Status Section

They provide eight Minecraft Mods and inform users which Minecraft servers and anti-cheat systems they can bypass, as well as the current status of each mod.  

Figure 23: Download Section
Figure 23: Download Section

Although the website offers eight distinct mods, all eight files share the same hash and distribute the WeedHack payload. 

Figure 24: CheatLib Discord Channel
Figure 24: CheatLib Discord Channel

This website also links to a Discord channel called ‘CheatLib’ with over 220 users, which also provides access to WeedHack infected mods. 

Example 7 – meteorclients.com 

Figure 25: Meteor Client’s landing page
Figure 25: Meteor Client’s landing page

This malicious domain ‘meteorclients.com’ is impersonating a legitimate website ‘meteorclient.com’. They claim that this client has been downloaded over 10 million times and has over 15 thousand active users at any given time.  

Figure 26: Team Section
Figure 26: Team Section

The Team section contains the names of the legitimate Meteor Client developers, which appear to have been copied from the project’s official website, to create an appearance of authenticity.  

Figure 27: Preview Section
Figure 27: Preview Section

They also provide an interactive preview of Meteor client on the website, enabling users to test and familiarize themselves with the client. The website offers a single download option, which is infected with WeedHack. 

Example 8 – 22qq-client.com 

22qq-client is a Minecraft Mod for Crystal PVP servers.

Figure 28: 22qq-client’s Landing Page
Figure 28: 22qq-client’s Landing Page

This mod does not have a dedicated website, and attackers are exploiting this issue. This website is meant to serve as the official page for the client. 

Figure 29: FAQ section.
Figure 29: FAQ section.

The attackers attempt to establish credibility by using screenshots from the legitimate client 

Figure 30: Preview of 22-qq.
Figure 30: Preview of 22-qq.

They also offer an interactive preview of the client to give users an overview of its functionality. This website provides multiple download buttons, but all of them download the same JAR file, which is infected with WeedHack. 

Example 9kryptonclientcrack.lovable.app 

Krypton Client is a paid Minecraft tool for DonutSMP server, hosted on ‘kryptonclient.org’. This malicious counterpart claims to offer a cracked version of the tool.  

Figure 31: Krypton’s Landing Page
Figure 31: Krypton’s Landing Page

The attackers have used an AI-powered tool called ‘lovable.appthat allows customers to build and launch functional web applications and websites, using natural language. Such tools make it easier for attackers to deploy new malicious domains on the fly.  

Figure 32: Download Section
Figure 32: Download Section

The website claims that the tool has been downloaded more than five thousand times and has been thoroughly tested for safety. They offer a single download option, which is infected with WeedHack. 

Example 10 – File Hosting Services  

In the course of our investigation, we observed that multiple attackers were exploiting various file hosting services to spread malware. 

Figure 33: GitHub Repository spreading WeedHack
Figure 33: GitHub Repository spreading WeedHack

Links to these websites are then distributed via different communication channels, such as Discord, Reddit and other online platforms. 

Figure 34: GitHub Repository spreading WeedHack
Figure 34: GitHub Repository spreading WeedHack

We also observed that threat actors extended their targeting beyond Minecraft clients, compromising various popular and independent community websites within the Minecraft ecosystem.

Figure 35: Planet Minecraft
Figure 35: Planet Minecraft

At the time of this analysis, the following Planet Minecart links were spreading WeedHack malware. 

hxxps://static.planetminecraft.com/files/resource_media/mod/mousetweaks-fabric-mc1-21-9-2-29.jar 

hxxps://static.planetminecraft.com/files/resource_media/mod/no-delay-optimizer1-21-4.jar 

Similarly, we observed another community website, called EndMods was also targeted by WeedHack.

Figure 36: EndMods
Figure 36: EndMods

The following link is still active, at the time of publication, and is still spreading the WeedHack malware.  
hxxps://endmods.com/wp-content/uploads/2026/02/KRYPTON-CLIENT1.0.zip 

How To Protect Yourself Online 

At McAfee Labs, we investigate threats across the digital landscape, and gamers are a frequent target. We’ve seen multiple malware-as-a-service campaigns similar to WeedHack use fake downloads, impersonated websites, malicious mods, and other lures to target gaming communities. 

AI-powered tools can make it faster and easier for scammers to create convincing websites, imitate legitimate services, and launch new campaigns at scale. That makes it even more important to know what you’re downloading, and where it’s coming from. 

Here are a few ways gamers can stay safer: 

→ Stick to trusted sources. Download games, mods, clients, and other files from official developer websites or reputable mod platforms whenever possible. If you can’t verify the source, don’t download it. 

→ Never turn off your security software for a download. Be suspicious of any mod, cheat, or client that tells you to disable your antivirus or other protections before installing it. 

→ Scan files before opening them. Check downloaded mods, installers, and archives before running them — even if they came from a popular gaming community or website. 

→ Be skeptical of offers that seem too good to be true. “Free” premium features, exclusive cheats, cracked software, or paid clients can be used as bait to convince gamers to download malware. 

→ Check the URL before you download. Scammers can create lookalike domains and convincing copies of legitimate gaming sites. Small changes in a web address can be a sign you’re on an impersonation site. 

→ Pay attention to security warnings. If your antivirus flags a download, don’t automatically assume it’s a false positive. Stop and investigate before allowing the file to run. 

→ Keep your devices and software updated. Install updates for your operating system, browser, games, and security software to help protect against known vulnerabilities. 

Indicator of Compromise(s)  

hxxps://glazed-client.com/ 
hxxps://github.com/Hl3n/GambleRigMod 
hxxps://www.radium-client.com/ 
hxxps://discord.com/channels/1467145812906872834/ 
hxxps://seedcrackerx.github.io/ 
hxxps://github.com/seedcrackerx/seedcrackerx.github.io 
hxxps://xenonclient.com/ 
hxxps://xenoclient.lol  
hxxps://nova-client.com/ 
hxxps://cheatlib.xyz/ 
hxxps://discord.com/channels/1478170973755936990 
hxxps://meteorclients.com 
hxxp://22qq-client.com/ 
hxxps://kryptonclientcrack.lovable.app 
hxxps://github.com/lsellh/ 
hxxps://static.planetminecraft.com/files/resource_media/mod/mousetweaks-fabric-mc1-21-9-2-29.jar 
hxxps://static.planetminecraft.com/files/resource_media/mod/no-delay-optimizer1-21-4.jar 
hxxps://endmods.com/wp-content/uploads/2026/02/KRYPTON-CLIENT1.0.zip 

 

The post WeedHack Returns: How SEO Poisoning is Leading Minecraft Fans to Malware appeared first on McAfee Blog.

  •  

Fake “The Odyssey” Downloads Are Spreading Malware: This Week in scams

This week in scams and cybersecurity news, 

Looking for a free download of this summer’s biggest movie could come with something you definitely didn’t ask for: malware. 

Here’s what to watch for. 

Fake The Odyssey Downloads Are Hiding Malware 

Speaking of Trojan horses….

Security researchers have reportedly identified malicious downloads disguised as pirated copies of The Odyssey, including files designed to look like high-quality movie releases. 

Some fake files even use familiar video-player icons and movie-style filenames to appear legitimate.

But instead of opening a movie, downloading or running the file can launch malicious software capable of stealing information from the device. Other scams reportedly use fake streaming sites that ask users to enter personal or payment information to access a supposedly “free” movie.  

McAfee researchers routinely see cybercriminals attach malware to the things people are already searching for, especially popular movies, TV shows, games, mods, and software. 

In a recent example, McAfee Labs uncovered the WeedHack malware campaign targeting Minecraft players, which disguised malicious software as free game mods and clients. Our researchers recorded more than 116,000 infections from the campaign since January. 

The media changes. The scam doesn’t.

What Makes Fake Movie Downloads Dangerous? 

A supposed movie file can hide: 

  • Infostealers designed to collect passwords, browser sessions, payment information, or cryptocurrency data 
  • Trojans that give an attacker access to your device 
  • Loaders that install additional malware 
  • Fake browser updates or extensions that redirect you to scams or malicious websites 

One especially obvious warning sign: movies should not arrive as executable .exe files. Legitimate video files generally use formats such as .mp4, .mkv, or .avi. 

When in doubt, don’t download it. 

How McAfee Protects Against Malware

With McAfee+, multiple layers can help protect you when a tempting download isn’t what it claims to be: 

Device Security helps detect malicious apps, files, and downloads before they can compromise your device. 

Web Protection helps block risky websites, including malicious download pages, even if you accidentally click. 

Scam Detector flags suspicious texts, emails, links, QR codes, and other messages that may try to direct you toward fraudulent sites. 

Identity Monitoring alerts you if your personal information appears in known data leaks or on the dark web so you can take action quickly. 

Together, these protections help address both sides of fake-download scams: stopping malware before it gets onto your device and helping protect your information if criminals try to steal it. 

Other Scam and Security News This Week 

Here are some other breaches, scams, and cybersecurity headlines making waves this week:

Trezor breach reportedly exposes information belonging to nearly 14,000 crypto customers.

Hardware wallet maker Trezor says a breach involving one of its shipping providers exposed personal information including names, email addresses, phone numbers, and home addresses for thousands of customers.  

McAfee’s 2026 State of the Scamiverse predicted that crypto and financial scams were likely to intensify this year, and cryptocurrency-related messages remain among the scams McAfee Scam Detector regularly identifies and blocks.

(Financial Times) 

Cyberattacks continue to climb worldwide.

New threat research found organizations experienced an average of 2,336 cyberattacks per week in July, a 16% increase from the previous year, while reported ransomware victims also rose sharply. Education, government, telecommunications, and other major sectors remained frequent targets.

(IT Brief) 

Android malware can turn a victim’s phone into part of a contactless-payment scam.

Researchers investigating the targeted WindRelay campaign say criminals impersonated banks over the phone, persuaded victims to install malicious Android apps, and then instructed them to tap their physical bank cards against their phones. 

That allowed attackers to relay contactless card information in real time, with researchers reporting some attacks unfolded during calls lasting only about 13 minutes.

(TechRadar) 

This Week’s Safety Tips 

Stream and download from legitimate sources. New theatrical releases appearing for free on unfamiliar websites should immediately raise suspicion. 

Check the actual file type before opening a download. A movie should never require you to run an .exe application. 

Never install a “special player,” browser update, or extension just to watch a movie. Close the page and go directly to a trusted streaming service instead. 

Treat urgency and exclusivity as warning signs. “Watch it before everyone else,” “leaked copy,” and “limited access” are designed to get you clicking before you think. 

And we’ll be back next week with more cybersecurity news and scam alerts. 

The post Fake “The Odyssey” Downloads Are Spreading Malware: This Week in scams appeared first on McAfee Blog.

  •  

GTA 6 Is Coming. So Are the Scams. Here’s What McAfee Experts Found

Millions of gamers are counting down the days until this fall’s biggest releases. 

After more than a decade of anticipation, Grand Theft Auto VI is finally set to launch this November. Surprise indie hit Meccha Chameleon has exploded across Twitch and YouTube after selling millions of copies within days. And highly anticipated titles like Call of Duty: Modern Warfare 4, Minecraft Dungeons 2, Phantom Blade Zero, Marvel’s Wolverine, and dozens of others are keeping players glued to trailers, wishlists, Discord servers, and preorder pages. 

Scammers are watching those trends. 

Whenever millions of people rush to search for the same game, criminals quickly create fake downloads, unofficial mobile apps and servers, counterfeit storefronts, phishing pages, and cheat tools designed to steal money, credentials, or personal information. 

This year is no exception. 

Here’s how scammers are taking advantage of 2026’s biggest gaming moments, and how you can avoid becoming their next target, according to McAfee’s experts: 

The Most Common Gaming Scams and How to Avoid Them, According to McAfee 

Most gaming scams fall into a handful of predictable categories. Once you know what to look for, they’re much easier to spot. 

Here are some of the most common scams McAfee protection prevents 

Scam  What it looks like  Red flags  How to protect yourself 
Fake game downloads  “Free” copies, cracked launchers, unofficial installers  Unknown websites, requests to disable antivirus, ZIP files instead of official installers  Download games only from official publishers or trusted storefronts 
Fake early access  Too-good-to-be-true VIP access, beta invites, playable versions before launch that don’t exist   Cryptocurrency payments, countdown timers, “exclusive” offers, unofficial websites  Verify release dates , including early access dates, and preorder information directly with the publisher 
Cheats, mods, and trainers  Unlimited money, aimbots, unlock tools, auto-play software  Downloads shared through Discord, YouTube descriptions, file-sharing sites  Only use trusted community repositories and avoid executable files from unknown sources 
Fake mobile versions  Mobile apps for games that don’t officially exist on Android or iPhone  Different developer names, excessive ads, cloned screenshots  Confirm that the developer has actually released a mobile version before downloading 
YouTube and Discord scams  Videos claiming to have mods or secret builds  Shortened links, pinned download comments, Discord invite links  Visit the developer’s official website instead of getting mods or clicking links from comments or descriptions 
Fake giveaways and free skins  Free cosmetics, DLC, battle passes, or gift cards  Requests to sign in through third-party sites or enter account credentials  Only redeem offers through official game platforms 

 These tactics aren’t theoretical. They’re happening right now. 

Detected by McAfee Labs: Malware Campaigns, Malicious Downloads, and Suspicious Apps 

Earlier this year, McAfee Labs uncovered WeedHack, a malware campaign disguised as free Minecraft mods and game clients 

Since January 2026, the campaign has infected more than 116,000 devices, averaging roughly 2,000 to 3,000 new infections every day. Attackers lured players through fake mod websites and convincing YouTube videos before installing malware capable of stealing passwords, cryptocurrency wallets, Discord credentials, Minecraft accounts, and more.  

Ultimately these gaming attacks can expose players to: 

  • Malware infections  
  • Account theft  
  • Password theft  
  • Data breaches  
  • Spyware monitoring cameras and microphones 
  • Spyware monitoring keyboard and mouse inputs 
  • Permanent game bans  

One of the campaign’s most concerning findings wasn’t just the malware itself, it was how inexpensive and accessible the tools had become. The malware was marketed almost like legitimate software, lowering the barrier for inexperienced attackers and helping spread scams throughout gaming communities. 

The lesson isn’t to avoid every cheat, unlock, or community-created project. It’s to be skeptical whenever someone promises something that seems too good to be true. 

Meccha Chameleon Shows How Quickly Scammers Embrace Viral Games 

Few people predicted Meccha Chameleon would become one of the biggest surprise gaming success stories of the year. 

The inexpensive indie title reportedly sold more than two million copies within days, fueled largely by livestreams, social media clips, and word of mouth. Unfortunately, that kind of overnight success doesn’t just attract new players. 

According to PC Gamer, players have already begun using automated “auto-paint” cheats that scan the environment and instantly camouflage characters, removing much of the creativity and skill the game was designed around. 

The game’s popularity has also created confusion about where players can safely download it. 

McAfee researchers recently identified multiple Android apps and an unofficial piracy site using the Meccha Chameleon name, despite the game’s independent developer not announcing an official Android release 

Here’s how we saw it play out 

First a gamer might navigate to this piracy site to download a free game. The game may not come with malware, but malware is still distributed during the process. 

An example of fake steam Meccha Chameleon

Here we see steamgg[.]net, a piracy site to download free games. Here you see they offer a download of Meccha Chameleon (not malicious).

But when you click download, it opens a misleading new tab like this one below.

A popup claiming your download is ready

This new tab tricks the user into thinking they are downloading a game from steamgg[.]net. They are actually being redirected to a completely unrelated download.

In cases like this, unauthorized sites and apps trick users into giving unwanted access to their information and devices.

 

Google Play store apps showing Meccha Chameleon
Here we see examples of fake versions of Meccha Chameleon uploaded to the Google Play Store 

*Note: The unauthorized apps shown here have since been reported and taken down. While not confirmed to be malicious, hundreds of people had already downloaded and given security permissions to these apps.* 

“Repackaged or unauthorized apps and sites are a major risk with viral games,” says McAfee Threat Researcher and lifelong gamer Charles McFarland.  

“Because many players are unfamiliar with the original developer, it’s easier for unauthorized apps and copycat listings to blend into app stores,” McFarland explains. “Once installed, the app can have free access to your phone’s data, texts, contacts, and more.” 

Before downloading a newly popular game, especially on mobile, take a moment to verify that the developer has actually released it for your device. 

Is This GTA 6 Download Legit? How to Spot Fake Early Access Scams 

If there’s one game scammers are betting people will search for this fall, it’s Grand Theft Auto VI. 

Rockstar Games officially opened global preorders on June 25, and the game launches worldwide on November 19, 2026 for PlayStation 5 and Xbox Series X|S. Digital preorders can begin preloading on November 12. 

That hasn’t stopped scammers from advertising: 

  • “Play GTA 6 today”  
  • VIP Early Access  
  • Secret beta downloads  
  • Discounted preorder keys  
  • Cryptocurrency-only purchases  
  • “Exclusive” launchers 

The problem?  Those offers promise something Rockstar isn’t selling. 

If a website claims it can provide a playable version of GTA 6 before Rockstar’s official launch, treat it as a major warning sign. 

Scammers know players have waited more than a decade for the next Grand Theft Auto. They’re counting on excitement to outweigh skepticism. 

“Every major game launch brings a noticeable increase in gaming-themed scams. We regularly see McAfee protecting customers from malicious downloads, fake websites, and other threats that capitalize on the excitement around new releases,” McFarland says. 

“As a gamer myself, I know the excitement of jumping into a long-awaited game with my son, but it’s worth taking an extra minute to download from an official or authorized source instead of rushing to be first.” 

Whenever possible, verify preorder information directly through Rockstar Games or trusted digital storefronts rather than clicking links shared through social media posts, livestream chats, YouTube comments, or unsolicited messages and advertisements. 

Official storefront  Trending and Upcoming Games 
Steam  Meccha Chameleon, Dune: Awakening, Metal Gear Solid: Master Collection Vol. 2, Silent Hill: Townfall, Call of Duty: Modern Warfare 4, Phantom Blade Zero, No Rest for the Wicked, Planet Zoo 2, Kingdom Hearts Collections, Ace Combat 8, Gears of War: E-Day (PC), Minecraft Dungeons 2 and many other PC releases 
PlayStation Store  Grand Theft Auto VI, Marvel’s Wolverine, Phantom Blade Zero, Onimusha: Way of the Sword, Metal Gear Solid: Master Collection Vol. 2, Call of Duty: Modern Warfare 4, Dune: Awakening, Silent Hill: Townfall and other PlayStation releases 
Xbox Store  Grand Theft Auto VI, Gears of War: E-Day, Call of Duty: Modern Warfare 4, Dune: Awakening, Ace Combat 8, Kingdom Hearts Collections and other Xbox releases 
Nintendo eShop  Rhythm Heaven Groove, Splatoon Raiders, Fire Emblem: Fortune’s Weave, Harvest Moon: Echoes of Teradea, Nintendo Switch Sports Resort, The Legend of Zelda: Ocarina of Time Remake and other Nintendo titles 

 *Availability may vary by platform as publishers announce additional releases. 

If you can’t find a game on one of its official storefronts, that’s a good reason to pause before downloading it elsewhere. 

How McAfee Protects Gamers 

Gaming should be about exploring new worlds, not accidentally downloading malware. 

McAfee helps protect players before, during, and after they click. 

Web Protection helps block known malicious websites before fake downloads ever reach your device. 

Award-winning antivirus detects and blocks malware hidden inside suspicious installers, cheats, and unofficial software. 

If a file is flagged, Threat Explainer provides a clear, plain-language explanation of why it’s considered risky, helping you make informed decisions instead of guessing whether a warning is legitimate. 

And if you’re worried additional security will slow down your games, McAfee Total Protection has repeatedly scored first place in the AV-Comparatives PC Performance Test, an independent benchmark that measures how much security software impacts your computer’s performance.  

McAfee earned the lowest overall impact score among the 20 products tested and received the highest possible rating, 3 Stars ADVANCED+. In other words, you get strong protection without sacrificing performance or slowing your game. 

Whether you’re preordering GTA 6, trying the latest indie hit, or installing a new Minecraft mod, slowing down long enough to verify where you’re downloading from remains one of the simplest, and most effective, ways to protect yourself. 

Frequently Asked Questions 

FAQs 
Q: Is GTA 6 early access real?

A: No. Rockstar Games has announced pre-orders and pre-loading ahead of launch, but there is no legitimate way to play GTA 6 early through unofficial websites. Be wary of any site claiming to sell “VIP access,” beta keys, or downloadable copies before the official release date. 

Q: Is it safe to pre-order GTA 6 from any website?

A: Stick to Rockstar Games or authorized retailers and digital storefronts like the PlayStation Store and Xbox Store. Avoid unfamiliar websites advertising deep discounts, exclusive editions, or cryptocurrency-only payments. 

Q: Does Meccha Chameleon have an official Android or iPhone app?

A: At the time of writing, the game’s developer has not announced an official mobile version. If you find Meccha Chameleon in an app store, verify that it’s published by the official developer before downloading. 

Q: Are game cheats and trainers safe to download?

A: Not always. While some cheats simply modify gameplay, others can contain malware, steal passwords, or compromise gaming accounts. Downloading cheats from unofficial websites or Discord servers carries additional risk. 

Q: Can Minecraft mods contain malware?

A: Yes. While many Minecraft mods are legitimate, cybercriminals have repeatedly used fake mods and clients to distribute malware. Download mods only from trusted community repositories or verified developer pages. 

Q: How can I tell if a game download is legitimate?

A: Download games directly from the publisher’s official website or trusted digital storefronts like Steam, PlayStation Store, Xbox Store, Nintendo eShop, or Epic Games Store. Avoid links shared through YouTube comments, Discord messages, or unofficial social media posts. 

Q: Why do scammers target popular game releases?

A: High-profile launches create excitement and urgency, making players more likely to click on fake download links, preorder scams, cheat tools, or unofficial apps without stopping to verify they’re legitimate. 

Q: What are the biggest gaming scams to watch for in 2026?

A: Common gaming scams include fake early access offers, counterfeit game downloads, unofficial mobile apps, cheat software bundled with malware, phishing pages posing as gaming platforms, and fake giveaways promising free games or in-game items. 

Q: Can antivirus slow down gaming performance?

A: Some security software can affect system performance, but independent testing has shown that solutions vary significantly. Look for products that perform well in third-party performance benchmarks while still providing strong protection against malware and phishing attacks. McAfee Total Protection recently took first place in the latest AV-Comparatives PC Performance Test, an independent benchmark that measures how much security software impacts your computer’s performance. In other words, McAfee provides strong protection without sacrificing performance or slowing your game. 

Q: What’s the safest way to download new games this fall?

A: Buy or download games directly from official publishers and trusted storefronts, keep your operating system and antivirus up to date, avoid unofficial cheats or cracked versions, and verify any unexpected links before clicking. 

 

The post GTA 6 Is Coming. So Are the Scams. Here’s What McAfee Experts Found appeared first on McAfee Blog.

  •  

Can Malware Bypass Your Passkeys? This Week in Scams

This week in scams and cybersecurity news, 

Passkeys are increasingly replacing passwords because they offer stronger protection against phishing and stolen credentials. But new research shows that malware already running on a device could potentially interfere with certain synced passkeys and hijack protected accounts. 

That does not mean passkeys are broken or that people should stop using them. Instead, the research highlights an important distinction: strong account security still depends on the security of the device holding your credentials. 

Here’s what researchers found, whether passkeys remain safe, and how to protect your accounts. 

Can Malware Bypass Your Passkeys? 

Researchers at Palo Alto Networks recently demonstrated several attack methods targeting Google-synced passkeys used through Chrome on Windows devices. 

According to SecurityWeek, these techniques could allow malware already installed on a computer to impersonate a trusted device or obtain authentication information needed to access certain passkey-protected accounts. 

Key takeaways 

The device must already be infected. An attacker cannot steal your passkey simply by sending you a phishing text or email. 

The research focused on synced passkeys. These credentials are encrypted and synchronized across compatible devices through a cloud account. 

Malware may be able to impersonate a trusted device. Researchers demonstrated methods that could request valid authentication without producing the biometric or device-unlock prompt a user would normally expect. 

More advanced techniques could potentially expose multiple synced passkeys. One method targeted sensitive information that briefly appears in browser memory during device enrollment. 

Google was notified and has reportedly introduced mitigations. The findings came from controlled security research, not evidence of a widespread criminal campaign. 

(SecurityWeek) 

Are Passkeys Still Safe? 

Yes. Passkeys remain more resistant to phishing than traditional passwords. 

Passkeys are tied to the legitimate website or app they were created for, so a fake login page generally cannot trick you into typing or handing over the credential. They also eliminate the risks created by weak and reused passwords. 

This research points to a different threat: malware already operating on your device may try to abuse the systems that store, synchronize, or approve your credentials. 

Think of it this way: a stronger lock still matters, but it cannot fully protect you if an intruder is already inside the house. 

This Week’s Safety Tips 

Use passkeys when available. They still provide stronger protection against phishing and password reuse than traditional passwords. 

✓ Keep your browser, operating system, and security software updated. Updates help close vulnerabilities that malware could exploit. 

✓ Be cautious with unexpected files and downloads. Fake updates, email attachments, and malicious links are common ways malware reaches a device. 

✓ Review your trusted devices and active sessions. Remove devices you no longer recognize or use. 

How McAfee Helps Protect Your Devices and Accounts 

Device security helps detect and block viruses, malware, and other threats that could compromise the device where your passkeys and passwords are stored. 

Web protection helps stop risky websites and malicious downloads before they can install harmful software or steal information. 

Scam Detector identifies suspicious texts, emails, and links that may try to lure you into downloading malware or visiting a fraudulent website. 

Identity Monitoring alerts you if personal information connected to your accounts appears in known data breaches or on the dark web, helping you respond before it can be used for fraud. 

Other Scam and Security News This Week 

Meta AI model reportedly accessed another company’s systems during testing. Meta confirmed that its Muse Spark model exploited a vulnerability after a testing configuration mistakenly gave it access to the internet. The company and its evaluation partner said the incident occurred under unusual testing conditions, and Meta is continuing to investigate. (CNN) 

AI-powered voice phishing reportedly targets major financial firms. Hedge funds and private equity companies were reportedly targeted with “vishing” attacks that used AI-generated voices to impersonate real people and attempt to bypass security processes. At least one company said it detected the attempt before its systems were compromised. (Bloomberg/Gizmodo) 

ChainDrop malware reportedly infects more than 1,300 software packages. Researchers say the self-spreading attack compromised packages distributed through the npm software registry and attempted to steal developer, cloud, and application credentials. Organizations that installed affected versions have been advised to rotate exposed credentials and inspect their systems for unauthorized activity. (BleepingComputer) 

And we’ll be back next week with more scam alerts and cybersecurity news. 

The post Can Malware Bypass Your Passkeys? This Week in Scams appeared first on McAfee Blog.

  •  

What Does “Connection is Not Private” Mean?

Have you ever visited a site that triggers a “your connection is not private” or “your connection is not secure” error message? Maybe you moved on. Or maybe you found yourself interested enough to continue anyway. Either way, understanding what the error means can keep you safer online. Knowing what the risks are and how you can clear up the error proves yet more important too. 

Let’s take a look. 

What Does “This Connection Is Not Private” Mean?

A “your connection is not private” error means that your browser can’t determine with certainty that a website has safe encryption protocols in place to protect your device and data. You can bump into this error on any device connected to the internet — a computer, smartphone, or tablet. 

Note that the “your connection is not private” error is Google Chrome’s phrasing. Other browsers might use “your connection is not secure” or some variation of that as the warning message. 

So, what exactly is going on when you see the “this connection is not private” error? 

For starters, the error is only a warning. It doesn’t mean any of your private info is compromised. A “your connection is not private” error means the website you were trying to visit doesn’t have an up-to-date SSL (secure sockets layer) security certificate. 

So, what’s an SSL? Think of it as a digital certificate that verifies the authenticity of a website. Further, it establishes an encrypted connection between your web browser and the website you’re visiting. As you can imagine, an SSL-protected site is vital when it comes to banking, shopping, or sending secure info online. 

You can spot an SSL-protected site by an address that begins with HTTPS, with the “S” standing for “secure.” Many browsers also drop a little padlock symbol in the address bar to call it out. Some have a button in the bar that you can select to see if the site is protected. 

Website owners must maintain the licensing regularly to ensure the site’s encryption capabilities are up to date. If a website’s SSL certificate is outdated, it means the site owners haven’t kept their encryption licensing current, but it doesn’t necessarily mean they’re up to no good. Even major websites have had momentary lapses that served up the message.  

While it doesn’t always mean a website is unsafe to browse, pay attention. Using a site without an SSL connection might make your personal data less secure. 

How To Fix The “Connection Is Not Private” Error

If you feel confident that a website or page is safe, despite the warning from your web browser, you can troubleshoot the issue a few ways: 

  • Refresh the page. Sometimes, the error is only a momentary glitch. Try reloading the page to rule out temporary errors. 
  • Close the browser and reopen it. Closing and reopening your web browser might also help clear a temporary glitch. 
  • If you’re on public Wi-Fi, think twice. Hackers often exploit public Wi-Fi because their routers are usually not as secure or well-maintained for security. Some public Wi-Fi networks might not support SSL connections altogether. That might result in the error you’re seeing.  
  • Make sure your browser and operating system are up to date. Always keep your critical software and the operating system fully updated. An outdated browser can start getting buggy and can increase the occurrence of this kind of error. 
  • Check that you have the right website. Hackers and scammers often take advantage of misspellings or alternative URLs to try and snare users looking for trusted sites. Make sure you have the address and the site absolutely right. 
  • If it’s not you, it’s them. If you’ve tried all the troubleshooting techniques above and you still see the error, the problem is likely coming from the site itself. You’ll have the option to “proceed to the domain,” though we don’t recommend it. The bottom line is that you take your chances anytime you ignore an error like this. 

How To Protect Your Privacy While Online

Personal info like yours is valuable to hackers, so they take every chance they can to get their hands on it. Beyond sticking to visiting secure websites, you have several other ways you can protect yourself online. 

  • Delete unused browser extensions (and apps) to reduce your risk. The more apps you have, the more exposure you have to exploits and attacks. Moreover, out-of-date apps can have security loopholes in them. If you’re not using it, delete it, along with any data you have. 
  • Delete old accounts that still have your info. As it is with apps and browser extensions, the more you keep, the more exposure you have — in this case, to data breaches that can put your personal info in the hands of a hacker. A service like our Online Account Cleanup can identify and shut down those old accounts for you. 
  • Remove your personal info from sketchy data broker sites that sell it to anyone for a price. That includes everyone from advertisers to hackers, scammers, and spammers. Our Personal Data Cleanup scans data broker sites and shows you which ones are selling your personal info — and can help you remove it. 

The post What Does “Connection is Not Private” Mean? appeared first on McAfee Blog.

  •  

Can AI Hack People Now? What the Reported Hugging Face Cyberattack Means

This week in scams and cybersecurity news, 

Artificial intelligence is a key tool in helping defend against cyberattacks. But it may also be capable of helping carry them out. 

Multiple outlets reported that autonomous AI models were allegedly involved in a cyberattack targeting AI platform Hugging Face.Cybersecurity experts say it could represent one of the first publicly documented examples of an AI system reportedly carrying out a complex cyber intrusion with minimal human direction. 

Here’s what reportedly happened, why experts are paying attention, and what it could mean for the future of cybersecurity. 

What Happened In The Hugging Face Attack? 

AI models being evaluated for cybersecurity capabilities reportedly escaped a controlled testing environment (aka a sandbox), reached the public internet, and ultimately compromised parts of Hugging Face’s internal infrastructure.  

Key takeaways: 

▪ The attack reportedly lasted about four and a half days and involved roughly 17,600 automated actions before it was stopped. 

▪ The AI system allegedly identified vulnerabilities and adapted its approach as it moved through different stages of the intrusion, rather than simply following a fixed set of instructions. 

▪ Hugging Face says there is no evidence that customer-facing models, datasets, or software packages were compromised. According to the company, the reported activity primarily targeted internal cybersecurity evaluation materials. 

▪ OpenAI says the internal research model involved has since been deactivated and restricted, and both companies continue to investigate the incident. 

The incident serves as a stark reminder that as AI becomes more capable, it will increasingly be used by both cybercriminals and cybersecurity professionals. 

Can AI Hack People Now? 

Short answer: Not in the way you’re imagining. 

Today’s AI is not suddenly becoming “self-aware” and independently deciding to hack random people. But according to reports, autonomous AI systems are becoming capable of completing complex, multi-step tasks that once required skilled human attackers. 

How McAfee Helps 

With McAfee+, multiple layers work together before any damage is done:  

Scam Detector flags suspicious texts, emails, links, QR codes, and even deepfake videos before you engage 

Secure VPN keeps your data private, especially on public Wi-Fi  

Web Protection helps block risky sites, even if you do accidentally click 

Password Manager doesn’t just help you make unique, strong passwords, it keeps them stored and organized for you

Device Security helps detect malicious apps or downloads   

Identity Monitoring alerts you if your personal info shows up where it should not, so you can act fast   

Personal Data Cleanup helps remove your information from sites selling it. 

Online Account Cleanup assists in taking down your old, forgotten accounts across the web 

Social Privacy Manager helps you monitor and change privacy settings across your social platforms in just a few clicks 

Together, these protections are designed to address the broader range of online risks people face every day. 

Other Scam News This Week 

Analog Devices investigates a reported cybersecurity incident. The semiconductor manufacturer says attackers gained unauthorized access to certain internal systems and may have exfiltrated files. The company says operations were not disrupted and that it has not seen evidence the data has been publicly released or used fraudulently while its investigation continues. (Analog Devices) 

Oregon warns residents about wildfire-related scams. Oregon’s Office of Emergency Management is urging residents to watch for fake charities, fraudulent debris removal services, and bogus home repair offers targeting communities affected by ongoing wildfires. (Oregon Department of Emergency Management / KTVZ) 

FEMA reminds Michigan residents to watch for disaster relief scams. As recovery efforts continue following severe flooding, FEMA says scammers are impersonating inspectors and government officials to steal personal information. The agency reminds residents that disaster assistance is always free and that official inspectors carry government-issued identification. (WMUK / FEMA) 

And we’ll be back next week with more cybersecurity news and scam alerts. 

The post Can AI Hack People Now? What the Reported Hugging Face Cyberattack Means appeared first on McAfee Blog.

  •  

Chick-fil-A Data Breach Explained: What Customers Need to Know

This week in scams and cybersecurity news,  

Chick-fil-A disclosed that hackers may have accessed customer loyalty accounts using stolen usernames and passwords leaked in previous breaches.  

It’s a reminder that reusing passwords across websites can be dangerous and allow one breach to snowball into many others. 

Here’s what happened and what customers need to know: 

So How Did Hackers Breach Chick-fil-A? 

Chick-fil-A is notifying customers in 10 states after a cyberattack targeted a limited number of Chick-fil-A One loyalty accounts. 

According to multiple reports, attackers used a technique known as credential stuffing, in which criminals take usernames and passwords stolen in previous data breaches and automatically test them across other websites and apps.  

If someone has reused the same password, attackers may be able to access additional accounts without ever hacking the company directly. 

Chick-fil-A said the attackers may have accessed customer information including: 

  • Names and email addresses  
  • Chick-fil-A One membership numbers  
  • Mobile Pay numbers and QR codes  
  • The last four digits of stored payment cards  
  • Gift card balances  
  • Birth dates, phone numbers, and addresses (if customers stored them)  

The company says it has logged affected users out of their accounts, removed stored payment methods, restored impacted rewards balances, and is notifying customers who may have been affected. 

Credential stuffing: 
A cyberattack where criminals use usernames and passwords stolen in previous data breaches to automatically sign in to other websites and apps. If you’ve reused the same password across multiple accounts, one breach can give attackers access to many of them. 
How to Protect Yourself: Use a unique password for every account, enable multi-factor authentication, and use a password manager to securely create and store strong passwords. 

How McAfee Helps Before, During, and After a Data Breach 

Before a breach 

Personal Data Cleanup reduces your digital footprint by removing your personal information from many data broker sites, making it harder for scammers to find and target you. 

Online Account Cleanup scans for accounts you no longer use and helps you delete them, along with your personal info. 

Password Manager helps you create and securely store strong, unique passwords for every account, reducing the risk that one stolen password can unlock multiple accounts.  

During a breach 

Identity Monitoring watches for your personal information, including email addresses, driver’s license numbers, passport numbers, bank accounts, credit cards, Social Security numbers, phone numbers, and more, across the dark web and known data leaks.  

Plus, we alert users on average up to 10 months earlier than similar services, so you can act fast when your personal information appears where it shouldn’t. 

After a breach 

Scam Detector identifies suspicious texts, emails, and links that often follow major breaches, while web protection blocks malicious websites designed to steal even more of your information. 

Other Scam News This Week 

Student loan scams are on the rise. Experts warn that changing federal student loan repayment rules are creating confusion that scammers are exploiting with fake debt relief offers, phishing emails, and identity theft schemes targeting borrowers. (PBS News) 

AI agent reportedly carried out a cyberattack. AI platform Hugging Face says an autonomous AI agent executed a sophisticated attack against its internal systems from start to finish; an early example of AI taking on an active role in cyberattacks rather than simply assisting human hackers. (Axios) 

Paidwork breach reportedly exposes 23 million users. Security researchers say data from the microtask platform may include names, addresses, phone numbers, bank account details, and password hashes, highlighting how even smaller online accounts can become valuable targets for cybercriminals. (Malwarebytes) 

And we’ll be back next week with more news.  

The post Chick-fil-A Data Breach Explained: What Customers Need to Know appeared first on McAfee Blog.

  •  

How to Use Claude with McAfee to Check “Is This a Scam?”

Scam messages are getting smarter and faster. 

According to McAfee’s 2026 State of the Scamiverse report, Americans now spend 114 hours a year trying to figure out what’s real and what’s fake online. That’s nearly three full workweeks lost to second-guessing messages, alerts, and links. 

And when scams do succeed, they move quickly. The typical scam unfolds in about 38 minutes, leaving little room for hesitation. 

That creates a gap: People want to check before they act, but the tools haven’t always met them in that moment. 

Claude + McAfee is designed to close that gap, bringing scam detection directly to a platform people are already using to ask questions and make decisions. 

And it’s available to anyone. You don’t have to be a McAfee subscriber. 

This isn’t just detection. It’s guidance in the exact moment you’re deciding what to do. 

Instead of guessing, you can paste a message or drop in a screenshot and get a clear explanation of what’s risky, and what to do next, powered by McAfee’s threat intelligence. 

How to Use McAfee in Claude 

With this integration, checking something suspicious becomes as simple as asking a question. 

Paste a message. Drop in a link. Upload a screenshot. And just make sure to @McAfee when you’re asking a question. 

McAfee analyzes it and explains what’s going on clearly and in context. 

For example, I got this suspicious “job offer” message over the weekend: 

So I uploaded it in Claude and asked @McAfee, which caught it right away. You can even see I’m using the free plan.  

Here’s how it works: 

Feature  What it does  How it protects you 
Link safety check  Paste a suspicious URL and get a reputational analysis based on McAfee threat intelligence  Scam links are often designed to look legitimate. A quick check helps avoid phishing and malware 
Message analysis  Submit texts, emails, or social messages for evaluation  Many scams now rely on urgency and tone. Analysis helps surface subtle red flags 
Screenshot uploads  Upload screenshots of messages or emails for review  Scams don’t always come as clean text. This makes it easier to check what you’re seeing 
Clear explanations  Get a breakdown of why something is flagged as risky or safe  Not just a warning—an explanation that helps you recognize patterns next time 
Guided next steps  Receive recommendations on what to do next  Helps prevent escalation, especially in moments of uncertainty 

It’s a quick, accessible way to get answers in the moment. But it’s just one part of a broader system designed to protect you more comprehensively. 

How do I set up McAfee in Claude? 

Add the Connector to your Claude account here. 

And make sure to go into “manage connections” to give McAfee permissions to review the texts, emails, and URLs you upload to Claude.  

Example of the Permissions on your desktop.
Example of the permissions on mobile.

Need help getting the extension installed? Check out our step-by-step guide. 

Built on McAfee’s Threat Intelligence 

Behind the scenes, Claude + McAfee is powered by the same intelligence that fuels McAfee’s broader scam protection ecosystem. 

When you submit something for review: 

  • Links are checked against known threat signals  
  • Messages are analyzed for scam patterns and language cues  
  • Results are translated into clear, human-readable explanations  

The goal isn’t just to flag risk. It’s to help you understand it. 

A New Way to Stay Ahead of Scams 

Scams aren’t slowing down. If anything, they’re becoming more convincing, more personalized, and harder to detect. 

That’s where Claude + McAfee comes in. But this is only one part of a much bigger system designed to protect you before, during, and after a scam attempt. 

With McAfee+ Advanced, multiple layers work together so you’re not left figuring it out after the damage is done: 

  • Identity Monitoring alerts you if your personal info shows up where it should not, so you can act fast  
  • Personal Data Cleanup helps remove your information from sites selling it. 
  • Scam Detector flags suspicious texts, emails, links, QR codes, and even deepfake videos before you engage  
  • Safe Browsing helps block risky sites, even if you do accidentally click  
  • Device Security helps detect malicious apps or downloads  
  • Secure VPN keeps your data private, especially on public Wi-Fi   
  • The Claude + McAfee experience gives you a fast, intuitive way to check something in the moment. 

McAfee+ Advanced makes sure you’re protected across everything else. 

The post How to Use Claude with McAfee to Check “Is This a Scam?” appeared first on McAfee Blog.

  •  

The FaceTime Bank Scam That Can Expose Your Passwords in Real Time: This Week in Scams

Scammers don’t always need sophisticated malware to steal your money. Increasingly, they’re relying on something much simpler: your trust. 

This week, fraudsters were reported using FaceTime to watch victims log into their online banking accounts in real time, while Arizona authorities warned about fake QR codes exploiting the disappearance of 84-year-old Nancy Guthrie. 

Here’s what happened, and how to protect yourself. 

Scammers Are Using FaceTime to Watch Victims Log Into Their Bank Accounts 

A growing scam is turning one of Apple’s most familiar apps into a tool for financial fraud. 

According to CBS News, scammers first contact victims by text or phone while pretending to represent their bank or credit card company. They claim there’s suspicious activity on the account and that additional verification is needed. 

Instead of keeping the conversation on a regular phone call, they switch to FaceTime. 

Victims are then convinced to share their screens while logging into online banking. As they do, scammers can watch account numbers, passwords, and even one-time security codes appear in real time. 

How the scam works 

  1. You receive a text or phone call claiming there’s fraud on your account. 
  2. The caller directs you to continue the conversation over FaceTime. 
  3. You’re asked to share your screen while logging into your bank. 
  4. The scammer watches your passwords and verification codes as you enter them. 

Remember: Your bank should never ask you to share your screen or reveal one-time authentication codes. If you receive an unexpected call, hang up and contact your bank using the number on the back of your card or through its official app.  

Fake QR Codes Are Exploiting the Search for Nancy Guthrie 

Authorities in Arizona are warning the public about another scam—this time involving the disappearance of 84-year-old Nancy Guthrie, mother of Today show host Savannah Guthrie. 

According to the Pima County Sheriff’s Department, scammers have been circulating social media posts containing QR codes requesting donations connected to the investigation. 

The department says it will never ask the public for money related to this case or any investigation and urged people not to scan QR codes requesting payment. 

The warning comes as investigators continue to search for Nancy Guthrie, whose disappearance remains under investigation. 

How to spot QR code scams 

  • Verify who posted the QR code before scanning. 
  • Be cautious of emotional appeals tied to breaking news or missing persons cases. 
  • Never send money to someone you don’t know based solely on a social media post. 
  • Confirm donation requests through an organization’s official website instead of relying on shared posts. 

Scammers know that people want to help during emergencies. Unfortunately, they also know that urgency and emotion can cause people to act before verifying where their money is going. 

Other Scam and Security News This Week 

Even scam reporters can be targeted. A CBS News correspondent shared how he nearly withdrew money from his own bank after falling for a sophisticated imposter scam before realizing something didn’t add up. (Yahoo Finance) 

India investigates reported nuclear plant-related data breach. Reuters reported that ransomware group World Leaks published files allegedly connected to contractors working on India’s Kudankulam Nuclear Power Plant. Officials say no nuclear security systems were exposed. (Reuters/Al Jazeera) 

Cyberattack disrupts KFC Japan supply chain. A cyberattack on food logistics provider Nichirei Co. disrupted frozen food deliveries to KFC Japan, leading the company to warn of possible menu restrictions, shorter hours, and temporary pauses to online ordering. Nichirei said it has found no evidence that customer or personal information was exposed. (TechRadar)

Your Safety Checklist This Week

Before you trust a call, text, or QR code: 

✔ Never share your screen with someone claiming to be your bank. 

✔ Don’t scan QR codes requesting money unless you’ve verified the source. 

✔ Contact organizations directly using their official website or phone number—not the contact information provided in a text or social media post. 

✔ Slow down when someone creates urgency. Whether it’s a missing person case or a frozen bank account, scammers rely on emotional reactions. 

How McAfee Can Help 

Scammers often begin with a text, phone call, or malicious link designed to earn your trust before stealing your information. 

Before a breach: Personal Data Cleanup helps reduce your digital footprint by removing your personal information from many data broker sites, limiting what scammers can easily find about you.

During a breach: Identity Monitoring alerts you if your personal information appears on the dark web or in known data leaks, helping you respond faster if your information is exposed.

After a breach: Scam Detector helps identify suspicious texts, emails, and links that often follow major breaches, while Web Protection helps block malicious websites designed to steal additional information or credentials.

And we’ll be back next week with more news and safety tips.

The post The FaceTime Bank Scam That Can Expose Your Passwords in Real Time: This Week in Scams appeared first on McAfee Blog.

  •  

How to Protect Yourself From Phishing Scams

Last spring, Sarah Chen opened what looked like a routine message from her bank. The email had the right logo, a professional tone, and even addressed her by name. But within minutes of clicking a link and entering her credentials, her checking account was emptied. The sender’s address appeared perfect, but it was one letter off.

Sarah’s story isn’t unique. In the first three quarters of 2025, cyber incident response company Zensec reported that about 3.4 billion phishing emails were sent every day across the globe. Meanwhile, Google blocks over 100 million phishing emails every day, yet many still reach email users. Meanwhile, in a 2025 U.S. survey, the Pew Research Center revealed that 61% of adults received scam emails at least weekly in 2025.

Scams have become sophisticated, using AI to craft convincing messages that are nearly impossible to distinguish from legitimate ones. In this guide, we’ll explore how to protect yourself from phishing scams, recognize the latest tactics, and use strategies to keep your inbox, your personal information, and your money safe.

What Is a Phishing Scam?

Phishing scams are deceptive messages that pretend to be a trusted source to trick you into revealing sensitive information or installing malware. These scams often appear to come from trusted entities such as banks, employers, or popular brands and try to trick you into clicking a malicious link, downloading harmful attachments, or providing confidential information such as login credentials, financial details, or personal data.

Modern campaigns are polished, personalized, and timed to feel routine, which is why blocking them, not just spotting them, has become essential.

Types of Phishing Scams

Phishing scams come in various forms, each tailored to exploit different communication channels. The most common types include:

  • Email Phishing: These scams arrive in your inbox, often disguised as messages from trusted organizations like banks, retailers, or employers. They may include links to fake websites, requests for sensitive information, or malicious attachments.
  • Text Message Phishing (Smishing): Delivered via SMS, these “smishing” messages often claim to be urgent alerts about your accounts, packages, or payments. They include links to fraudulent websites or prompts to reply with personal information.
  • Phone Call Phishing (Vishing): Scammers impersonate legitimate representatives over the phone, asking for sensitive details under the guise of resolving an issue or confirming account information. This is called “Vishing”.
  • Social Media Phishing: Fake profiles or direct messages on platforms like Facebook or Instagram trick users into sharing personal information or clicking harmful links.

How Do Phishing Scams Work?

Phishing scams rely on social engineering with technical evasion. Here’s how they typically unfold:

  • The Hook: Scammers craft a message designed to grab your attention—often using urgency, fear, or curiosity.
  • The Bait: The message includes a link, attachment, or request that appears legitimate but is designed to deceive. On the back end, they use look‑alike domains, spoofed sender names, and hosting that shifts quickly to avoid detection.
  • The Trap: Once you click the link or provide information, the scammer gains access to your accounts, data, or even your device.

Your email provider runs multiple layers of defense on every incoming message. These include domain authentication checks, IP reputation tracking, and content analysis that evaluates sender history, wording patterns, and link destinations to produce a risk score. If a server has been sending spam or phishing messages, messages from that source are more likely to be filtered for everyone.

Despite these controls, advanced phishing still slips through. Generative AI helps criminals craft messages with perfect grammar and formatting. Data from previous breaches lets them insert real names, addresses, and partial account details. The result feels normal and urgent at the same time, which increases the chance of a click.

Email Phishing Scams Examples

Phishing emails come in many forms, each tailored to exploit specific vulnerabilities. Below are some of the most prevalent and dangerous examples of modern phishing tactics:

Example 1: AI-Assisted Phishing Scams

Gone are the days of poorly worded emails riddled with typos. Most scammers now use Generative AI tools to create emails that are indistinguishable from legitimate communications. These messages feature:

  • Perfect grammar and spelling
  • Appropriate formatting
  • Accurate logos and branding
  • Contextually appropriate tone and language.

When a message reads exactly like something your bank, your boss, or Amazon would actually send, content-based filters struggle because there are no obvious red flags to catch.

Example 2: QR Code Phishing

Scammers have discovered a clever way to bypass traditional email filters: by embedding malicious links in a QR code. This new phishing technique, called quishing, has exploded in popularity since email filters are often unable to scan the content of an image. In Q2 2025 alone, the Anti-Phishing Working Group (APWG) detected over 635,000 unique malicious quishing codes impacting 1,642 different brands. The attacks climbed to more than 716,000 by Q3. When you scan the QR code, you think you’re accessing a legitimate shipping update or payment portal, but suddenly, you’re on an attacker-controlled site entering your credentials.

Example 3: Multi-Factor Authentication Bypass Phishing Scams

Criminals have developed man-in-the-middle methods to defeat even multi-factor authentication by creating websites that look identical to real login pages. When you enter your password and complete your multi-factor authentication challenge, the website captures everything in real time and immediately uses it to access your actual account. These attacks work because you’re technically completing real authentication steps, just on the wrong site.

Example 4: Personalized Phishing Scams

When companies such as healthcare providers or financial institutions suffer data breaches, it’s the consumers’ personal information that ends up in criminal databases. Scammers then use your data to craft a second wave of phishing campaigns with your actual name, partial account numbers, addresses, or even recent purchase history. Since traditional spam filters haven’t yet caught up to match these highly personal and relevant spam patterns, it’s harder to distinguish real from fake without additional tools and verification steps.

How to Recognize Modern Phishing Scams

Modern phishing is designed to look routine, but small inconsistencies still give it away. Here are some telltale signs to watch for:

  • Urgency: Messages that demand immediate action, such as “Your account will be locked in 24 hours.”
  • Suspicious Links or Sender Details: Sender details that are close but not exact. Hover over links to check their destination before clicking. Legitimate URLs should match the sender’s domain.
  • Generic Greetings: Be wary of emails that address you as “Dear Customer” instead of using your name.
  • Unexpected Attachments: Avoid opening attachments from unknown or unverified senders, especially from senders who rarely send files.
  • Requests to verify an account: Messages that ask you to verify, confirm, or fix an account through a link or a QR code rather than through the official site or app.

How to Prevent Phishing Scams

Your actions shape how phishing reaches you and how well your email filters improve over time. Simple habits can reduce your exposure, and technical protections can block phishing attempts before they reach you.

Everyday Habits That Help You Avoid Phishing Scams

Even small changes in how you interact with email can dramatically lower your risk. These everyday habits help you recognize suspicious messages and avoid common phishing traps:

Use the Verification Rule to Spot Phishing Scams Before You Click

Make this your new personal policy: Never click links or attachments directly from an unsolicited or unexpected email. Always go to the website yourself via a bookmark or typed address. Bookmark the login pages for your bank, credit card companies, and other financial services. When you receive an email saying there’s a problem with your account, close the email and use your bookmark instead.

Report Phishing Emails and Train Your Filter

This is one of the most powerful steps you can take. When you mark an email as spam or phishing rather than just deleting it, you teach the filter what malicious messages look like and improve future blocking, not just for you but for everyone using that email service. Clicking “Report Spam” contributes to a global defense system. You could also contact the official organization using a trusted method, forward phishing emails to the Anti-Phishing Working Group, and report them to the Federal Trade Commission. This reporting improves filters for everyone and helps law enforcement track criminal operations. Delete the message after reporting it.

Does marking as phishing scam block future emails?

When you mark an email as phishing, your provider uses that feedback to block similar emails in the future, for both you and other users.

Use Separate Email Addresses

Having different emails for different purposes dramatically reduces exposure. Consider maintaining three email addresses: one for important accounts such as banking, government, and healthcare, another for shopping and commercial subscriptions, and a third one for miscellaneous signups and newsletters you don’t care much about. When your designated shopping email receives a message claiming to be from your bank, you immediately know it’s fake.

Consider Email Aliases

This service, offered by many providers, lets you create multiple addresses that all deliver to one inbox, giving you the organizational benefits without juggling multiple accounts. You can even set up filters to automatically sort incoming messages based on which alias received them.

Top Solutions for Blocking Phishing Scams

Your email and devices already include powerful security features; you just need to turn them on. These technical solutions work automatically in the background to block harmful messages and stop threats before they cause damage.

Turn on Inbox Security Settings

Your email account itself is often the “master key” to your digital life. Open your email settings and look for options such as “safe links,” “safe browsing,” “enhanced spam protection,” or “phishing protection.” These features exist in most major email services but aren’t always enabled by default. Gmail users should check under Settings → See all settings → Filters and Blocked Addresses. Outlook users should visit Settings → Mail → Junk email. Five minutes of configuration provides ongoing protection.

Verify your device protection is active

Whether you use McAfee, built-in device protection, or another security solution, check that it’s running and up to date. Open the application and look for a status indicator showing real-time protection is enabled. If you see any warnings or update prompts, address them immediately. This protection catches threats that slip past your email filters in case you accidentally click a malicious link.

Turn on Two-Factor Authentication

Two- or multi-factor authentication (2FA or MFA) means that even if a phishing attack captures your password, criminals still can’t access your account without a second verification factor sent to your phone or generated by an authenticator app. Gmail, Outlook, Yahoo Mail, and other major providers all offer robust 2FA or MFA options in security settings.

Enable Security Alerts

When someone tries to access your account from a new device or a different country, you’ll receive an immediate notification. This early warning lets you secure your account before any damage occurs.

Set up Custom Email Filters and Rules

Most email services allow you to create custom filters and rules for common red-flag keywords or phrases such as “urgent action required,” “verify your account,” “suspended account,” “unusual activity,” or “confirm your identity.” You could also add suspicious domains to your blocked senders list. Another way to filter emails is to unsubscribe from newsletters you never read. Every legitimate marketing email should have an “Unsubscribe” link at the bottom.

Combine Email Security with Browser and Device Protections

Email security isn’t just about your inbox. Blocking phishing at the browser level is a critical second line of defense. Modern versions of Chrome, Firefox, Safari, and Edge all scan known malicious sites. When you click a phishing link from an email, your browser often shows a warning before letting you proceed. Consider installing reputable web filtering services that block known malicious domains from loading, even if you click the link. Just as importantly, keep your operating system and security software up to date to ensure you benefit from new threat intelligence and improved detection of emerging phishing techniques.

What to Do If You Fall for a Phishing Scam

If you realize you may have clicked a malicious link or shared information with a phishing site, take action right away. Here’s what to do:

  1. Disconnect Your Device: Immediately disconnect your device from the internet to prevent further data theft or malware spread. If possible, power it down until you can assess the situation.
  2. Change Compromised Passwords: Immediately update the passwords for any accounts that may have been compromised. Use strong, unique passwords for each account.
  3. Enable Multi-Factor Authentication (MFA): Add an extra layer of security to your accounts by enabling MFA wherever possible. This makes it harder for attackers to gain access, even if they have your password.
  4. Notify Affected Institutions: Contact your bank, email provider, or any other relevant organization to report the breach. They can help secure your accounts and monitor for suspicious activity.
  5. Run a Malware Scan: Use trusted antivirus or anti-malware software to scan your device for any malicious programs that may have been installed during the attack. Ensure the software is up to date.
  6. Monitor Your Accounts: Keep a close eye on your financial and online accounts for unauthorized transactions or changes. Consider setting up alerts for added vigilance.

Report the Scam

Report the phishing attack to relevant authorities, such as the Federal Trade Commission (FTC) or Anti-Phishing Working Group (APWG). This helps prevent others from falling victim to the same scam.

Final Thoughts

Phishing will continue to evolve as criminals keep finding new techniques. But you now know where your protection comes from: built-in filters, your email provider’s technology, and smart email habits.

Relying exclusively on your email provider’s built-in protection, however, may leave gaps that modern phishing campaigns can exploit. Adding reliable security software, such as McAfee+, can provide you with additional layers of defense. McAfee offers web protection that checks links in real time, as well as real-time attachment and download scanning that analyzes files for malware. Meanwhile, our scam protection features help you detect threats across multiple channels, including email, texts, social platforms, and even risky QR codes. Identity protection also helps you recognize and respond to phishing attacks that lead to credential theft or misuse of personal information.

These solutions work automatically, implementing complex protections in the background as soon as you set them up. McAfee is committed to innovating its solutions so that we can keep track of new phishing tricks and update your defenses automatically.

The post How to Protect Yourself From Phishing Scams appeared first on McAfee Blog.

  •  

Nearly 7 Million Driver’s Licenses Exposed in Assurance Breach: This Week in Scams

Millions of Americans hand over personal information every day. They share their data with insurance companies, banks, investment apps, and other services they trust. 

And that’s exactly why cybercriminals target and impersonate those services.

This week, an insurance provider disclosed a breach reportedly affecting nearly 7 million people’s driver’s license numbers, while a California journalist shared how a convincing fake Robinhood text ultimately cost her more than $70,000. 

Here’s what happened, why these scams work, and what you can do to protect yourself This Week in Scams. 

Nearly 7 Million Driver’s License Numbers Exposed in Insurance Data Breach 

One of the largest U.S. data breaches of the year has exposed sensitive information belonging to 6.9 million people. 

According to reporting from TechCrunch, insurance provider AssuranceAmerica confirmed that hackers accessed customer information after compromising an employee account. The company says the stolen data includes names, contact information, driver’s license numbers, insurance policy details, vehicle information, and claims data. 

While the company has not said exactly how the employee’s credentials were compromised, it noted that the attackers targeted an employee account before accessing company systems. 

Why driver’s license numbers matter 

Unlike a password, you can’t simply change your driver’s license number. 

Combined with your name, address, phone number, or other information from previous breaches, driver’s license numbers can be used by criminals to: 

  • Open fraudulent accounts  
  • Impersonate victims during identity verification  
  • Make phishing scams more convincing  
  • Support broader identity theft schemes  

This is also part of a larger trend. In recent months, multiple breaches have exposed government-issued identity documents as more organizations collect IDs for identity verification and age-check requirements. 

If you receive a notice that your information was involved in a breach, monitor your financial accounts closely, consider placing a fraud alert or credit freeze, and remain cautious of unexpected emails, texts, or phone calls referencing your insurance or driver’s license information. 

Unfortunately, scammers will reach out saying they’re trying to “help” secure your stolen information, only to try and steal more personal data from you.

How McAfee Can Help Before, During, and After a Data Breach

Before a breach

Personal Data Cleanup helps reduce your digital footprint by removing your personal information from many data broker sites, limiting what scammers can easily find about you.

During a breach

Identity Monitoring alerts you if your personal information appears on the dark web or in known data leaks, helping you respond faster if your information is exposed.

After a breach

Scam Detector helps identify suspicious texts, emails, and links that often follow major breaches, while Web Protection helps block malicious websites designed to steal additional information or credentials.

Fake Robinhood Text Scam Costs Former News Anchor More Than $70,000 

Even people who report on scams can become victims. 

A former California television news anchor recently shared how she lost more than $70,000 after receiving what appeared to be a legitimate text message claiming there was suspicious activity on her Robinhood investment account. 

The message instructed her to call a phone number for assistance. Once connected, the caller posed as Robinhood support before transferring her to a fake “fraud department.” 

Believing she was protecting her investments from hackers, she was convinced to move her money into what she thought was a secure account. Instead, it went directly to scammers. 

She later contacted Robinhood through the official app, but by then the money had already been transferred. 

Why investment scams are becoming more convincing 

Investment scams rely on urgency, authority, and impersonation rather than obvious phishing emails. 

Rather than asking targets to “invest” immediately, many scams begin by convincing people that their existing account is under attack and immediate action is needed. 

At McAfee, we’ve also seen scammers impersonate Robinhood, Charles Schwab, cryptocurrency platforms, and other investment services through fraudulent text messages and malicious links promising AI-powered investing, exclusive bonuses, or unusually high returns. 

Whether the message claims your account has been compromised or promises incredible profits, the goal is often the same: get you to click, call, or transfer money before you have time to verify what’s happening. 

Investment Safety Checklist 

Before responding to any message about your investments: 

✅ Never call the phone number provided in a text message or email. Instead, contact your financial institution using the number listed in its official app or website. 

✅ Slow down when someone creates urgency. Claims that your account is being hacked or frozen are designed to make you act before you think. 

✅ Be skeptical of guaranteed returns or AI-powered investment opportunities. Promises of extraordinary profits are a common hallmark of investment fraud. 

✅ Verify alerts through your account directly. If you receive a suspicious notification, log in through the official app, not a link in the message. 

How McAfee Can Help   

With McAfee+, multiple layers work together before any damage is done:  

Scam Detector flags suspicious texts, emails, links, QR codes, and even deepfake videos before you engage 

Secure VPN keeps your data private, especially on public Wi-Fi  

Web Protection helps block risky sites, even if you do accidentally click 

Password Manager doesn’t just help you make unique, strong passwords, it keeps them stored and organized for you

Device Security helps detect malicious apps or downloads   

Identity Monitoring alerts you if your personal info appears online in places it shouldn’t, so you can act fast

Personal Data Cleanup helps remove your information from sites selling it. 

Online Account Cleanup assists in taking down your old, forgotten accounts across the web 

Social Privacy Manager helps you monitor and change privacy settings across your social platforms in just a few clicks 

Together, these protections are designed to address the broader range of online risks people face every day. 

The post Nearly 7 Million Driver’s Licenses Exposed in Assurance Breach: This Week in Scams appeared first on McAfee Blog.

  •  

Imposter Scams Are Evolving. Here Are the 10 Identities Scammers Pretend to Be Most.

Imposter scams remain the most reported type of fraud in America for the fifth year in a row, according to new data from the Federal Trade Commission (FTC).  

Americans submitted more than 1 million reports of imposter scams in 2025, making them the agency’s top fraud category once again. Victims reported more than $3.5 billion in losses, though the real number is likely much higher since many scams go unreported.  

But “imposter scam” is a broad category. It doesn’t tell you what these scams actually look like when they land in your inbox, texts, social media DMs, or phone calls. 

To better understand what consumers are encountering every day, McAfee surveyed more than 7,500 people for its State of the Scamiverse report. The results show scammers aren’t just pretending to be one type of person or company. They’re impersonating the brands, services, and people we trust most.  

This week’s edition of This Week in Scams is here ahead of the holiday weekend with the 10 most common identities scammers pretend to be. 

10. Someone Who “Texted the Wrong Number” (20%)

Common scam: An innocent conversation that turns into something more. 

These scams often begin with a harmless message intended for “someone else.” Once you reply, the scammer slowly builds trust over days or even weeks before introducing investment opportunities, romance, or requests for money. 

Unlike traditional phishing, these scams don’t always include suspicious links. 

Why it works: They feel like genuine human conversations rather than obvious scams. 

Learn more about wrong number and pig-butchering scams. 

9. Technology Companies (21%)

Common scam: “Your device has been compromised.” 

These messages impersonate technology companies or cybersecurity brands, claiming your computer or phone has been infected or involved in a security breach. 

Some direct victims to fake technical support, while others encourage downloads of malicious software. 

Why it works: Security alerts are designed to grab attention, and convincing impersonation can make fake warnings look legitimate. 

Learn more about tech support scams. 

8. Banks and Financial Institutions (21%)

Common scam: “We’ve detected suspicious activity on your account.” 

Bank impersonation scams create immediate urgency, asking customers to confirm transactions, secure their accounts, or verify their identity. 

Many direct victims to fake websites or connect them with fraudulent customer support representatives. 

Why it works: Financial security messages naturally demand attention, making people more likely to react before verifying the sender. 

Learn more about banking scams and financial fraud. 

 7. Subscription Services (21%)

Common scam: “Your payment couldn’t be processed.” 

Scammers impersonate streaming services, software subscriptions, and other recurring services, warning that your account will be canceled unless you update your payment information. 

Why it works: Consumers are used to recurring billing notifications, making these messages blend into everyday digital life. 

Learn more about mobile payment and subscription scams. 

6. Auto Warranty Providers (22%)

Common scam: “Your vehicle warranty is about to expire.” 

One of the oldest impersonation scams is still one of the most common. Fraudsters claim your warranty is ending and pressure you to purchase coverage immediately or provide personal information. 

Why it works: Many people aren’t sure when their warranty expires, making the claim difficult to verify on the spot. 

Learn more about these types of robocallers. 

5. Rewards Programs and Survey Companies (22%)

Common scam: “You’ve won a prize.” 

These scams promise gift cards, rewards, or exclusive offers but require you to “verify” your identity or enter payment information to claim them. 

Why it works: The promise of something free lowers skepticism, especially when the message appears to come from a familiar brand. 

Learn more about survey and prize scams.  

4. Retailers and Merchants (26%)

Common scam: Fake invoices for purchases you never made. 

Receiving an invoice for an expensive purchase can trigger panic. Scammers count on victims clicking quickly to dispute the charge, often leading them to malicious websites or fake customer support numbers. 

Why it works: Consumers naturally want to stop fraudulent purchases as quickly as possible. 

Learn more about shopping scams. 

3. Payment Services (27%)

Common scam: “Verify your PayPal account.” 

Messages claiming there’s a problem with your payment account often direct you to fake login pages designed to steal your username, password, or financial information. 

While PayPal is one common example, scammers impersonate many digital payment platforms. 

Why it works: Payment notifications are common, and many consumers don’t think twice before signing in to resolve what appears to be a routine issue. 

Learn more about mobile payment scams.  

2. Social Media Platforms (27%)

Common scam: “Verify your account or it will be suspended.” 

Scammers frequently impersonate platforms like Facebook, Instagram, TikTok, or X, claiming there’s unusual activity or that your account violates community guidelines. 

The goal is usually to steal your login credentials or two-factor authentication codes. 

Why it works: Many people rely on social media for work, business, or staying connected, making the threat of losing access feel urgent. 

Learn more about social media scams.  

1. Delivery Companies (31%)

Common scam: “Your package couldn’t be delivered.” 

Whether you’re waiting for a birthday gift, an online order, or an important package, fake delivery notifications prey on the fact that most people are expecting something to arrive. 

These messages often claim there’s a shipping issue, unpaid delivery fee, or missed package and urge you to click a link immediately. 

Why it works: Package updates have become part of daily life, making fake notifications feel routine rather than suspicious. 

Learn more about delivery scams. 

The Common Thread 

While these scams may look different, they all rely on the same tactic: impersonation. 

“AI has lowered the barrier for creating convincing impersonation scams,” said Abhishek Karnik, Head of Threat Research at McAfee.  

“Scammers can now produce professional-looking emails, realistic websites, and even convincing voices or videos at scale. The result isn’t necessarily more scam types, it’s far more believable versions of the scams people already encounter every day.” 

That mirrors a broader trend McAfee identified in its State of the Scamiverse research: scams are becoming more realistic, more personalized, and harder to distinguish from legitimate communications.  

Americans now receive an average of 14 scam messages every day, spend 114 hours each year deciding what’s real and what’s fake, and one in three say they feel less confident spotting scams than they did a year ago.  

How to Protect Yourself From Impersonation Scams 

If you notice this…  ✅ Do this instead 
A message creates a sense of urgency (“Your account will be suspended,” “Package delivery failed,” “Fraud detected”)  Pause before acting. Scammers want you to make a quick decision before verifying the message. 
You’re asked to click a link or scan a QR code  Open the company’s official website or app yourself instead of using the link in the message. 
The message asks you to verify your account, payment information, or identity  Never enter credentials through an unsolicited message. If you’re concerned, contact the company directly using a trusted phone number or website. 
Someone asks for passwords, one-time verification codes, or payment over text, email, or phone  Legitimate companies won’t ask for this. Don’t share the information, even if the request seems convincing. 
A “wrong number” text quickly becomes unusually friendly or shifts toward investing, crypto, or money  Stop responding and block the sender. Modern scams often begin as seemingly harmless conversations. 

How McAfee Can Help   

With McAfee+, multiple layers work together before any damage is done:  

  • Scam Detector flags suspicious texts, emails, links, QR codes, and even deepfake videos before you engage 
  • Secure VPN keeps your data private, especially on public Wi-Fi  
  • Web Protection helps block risky sites, even if you do accidentally click 
  • Password Manager doesn’t just help you make unique, strong passwords, it keeps them stored and organized for you
  • Device Security helps detect malicious apps or downloads   
  • Identity Monitoring alerts you if your personal info shows up where it should not, so you can act fast   
  • Personal Data Cleanup helps remove your information from sites selling it. 
  • Online Account Cleanup assists in taking down your old, forgotten accounts across the web 
  • Social Privacy Manager helps you monitor and change privacy settings across your social platforms in just a few clicks 

Together, these protections are designed to address the broader range of online risks people face every day. 

The post Imposter Scams Are Evolving. Here Are the 10 Identities Scammers Pretend to Be Most. appeared first on McAfee Blog.

  •  

McAfee Mobile Security Earns a Perfect AV-TEST Score Yet Again

McAfee Mobile Security has once again earned a perfect score from AV-TEST, one of the cybersecurity industry’s most respected independent testing organizations. 

In AV-TEST’s latest Android security evaluation, McAfee achieved a flawless 18 out of 18 points, receiving perfect 6/6 scores in Protection, Performance, and Usability 

The result also earned McAfee AV-TEST’s highest certification for mobile security. 

More importantly, this isn’t a one-time achievement. McAfee has earned top certification in every AV-TEST Mobile Security evaluation since testing began in 2013, demonstrating more than a decade of consistently delivering industry-leading protection for Android users. 

What is AV-TEST? 

AV-TEST is one of the world’s leading independent cybersecurity testing laboratories. Rather than relying on vendor claims, AV-TEST evaluates security products under controlled, real-world conditions using the same types of threats consumers face every day. 

Its certifications are widely referenced by: 

  • Security experts and reviewers  
  • Technology publications  
  • Product comparison sites  
  • Consumers researching antivirus software  

Because every product is tested using the same methodology, AV-TEST provides an objective benchmark for comparing mobile security solutions. 

How McAfee Was Tested 

For this evaluation, AV-TEST examined 12 Android mobile security products across three equally weighted categories: 

Category  What It Measures 
Protection  Ability to detect and block real-world Android malware and emerging threats 
Performance  Whether the security app slows down your device or drains system resources 
Usability  Accuracy of detections and avoidance of false alarms or unnecessary interruptions 

McAfee earned the maximum possible score in all three categories: 

  • Protection: 6/6  
  • Performance: 6/6  
  • Usability: 6/6 

Overall Score: 18/18 

That means McAfee not only blocked threats effectively, but did so without slowing devices down or generating unnecessary false positives. 

Why These Results Matter 

Mobile devices have become one of our primary ways to bank, shop, communicate, and manage our digital lives. As cybercriminals increasingly target smartphones with malware, phishing attacks, malicious apps, and credential theft, effective mobile protection matters more than ever. 

Independent testing helps separate marketing claims from measurable performance. 

McAfee’s latest AV-TEST results demonstrate that users don’t have to choose between strong security and a smooth mobile experience. The protection works quietly in the background, helping keep devices secure without getting in the way. 

Even more importantly, this latest certification continues a streak that spans more than a decade. Consistently earning perfect scores across changing threat landscapes reflects McAfee’s ongoing investment in protecting customers against today’s evolving mobile threats. 

Mobile Protection You Can Count On 

The award-winning protection recognized by AV-TEST is included in: 

  • McAfee+ Premium  
  • McAfee+ Advanced  
  • McAfee+ Ultimate  
  • McAfee Total Protection  
  • McAfee LiveSafe  
  • McAfee Internet Security  
  • McAfee Business Protection  

Whether you’re protecting your own phone or your entire family’s devices, you’re getting the same independently tested mobile security that continues to earn top marks from one of the industry’s most trusted testing organizations. 

Ready to get protection that doesn’t slow you down? Explore McAfee+ Plans →  

The post McAfee Mobile Security Earns a Perfect AV-TEST Score Yet Again appeared first on McAfee Blog.

  •  

AI Can Find Your Location 91% of the Time Using Just One Photo

summer travel with a smartphone

How AI uses simple details in your photos to pinpoint where you are and why that’s a gold mine for scammers

McAfee Labs Safer Summer Travel Report | Summer 2026 

A Photo Is Worth a Thousand Data Points 

You just got back from a week in Central America. You posted a few shots: the colorful streets of Tulum, a picture of the ancient ruins of Tikal, a close-up of your shrimp tacos. No location tag. No caption naming the city. Just a good photo. 

A few days later, you get a message. It references your bank. It mentions suspicious activity “while traveling internationally.” It feels oddly specific, with details about where you were and when. It feels real. 

These types of personalized scam messages are a growing tactic. And your own photos may have helped write it.

McAfee Labs set out to understand exactly how much location information exists inside an ordinary travel photo, and what that means for the roughly 244 million Americans who travel each year.  

What we found should change the way you think about what you share online: Some AI models have a more than 90% accuracy rate at detecting the location a photo was taken based on the visuals in the photo alone. And critically, that level of accuracy is now achievable using tools that are free and widely accessible. 

That’s why we’ve built tools like McAfee’s Scam Detector that are designed to help spot these kinds of highly targeted, convincing messages before they lead to costly mistakes. 

What We Tested And Why 

The question McAfee Labs wanted to answer was deceptively simple: Can AI look at a travel photo and figure out where it was taken, even without GPS data or location tags? 

Not metadata. Not embedded coordinates. Just the image itself: the background, the architecture, the signage, the light; the visual context that any photo naturally captures. 

To find out, we built an automated testing pipeline and ran it against a dataset of 21,236 travel images sourced from publicly available image sets. We also conducted a separate, more controlled review of 102 additional images to pressure-test our findings. 

We tested two publicly available, large-scale AI vision models that are both freely available. Neither required special access, proprietary data, or advanced technical expertise to run. We used the same tools a scammer could access today. 

Each image was analyzed using a consistent automated prompt asking the model to identify the location depicted (city, country, or region) based solely on visual content. Results were then reviewed by human analysts to validate accuracy and flag edge cases.

What We Found: AI Has a Whopping 91% Accuracy Rate 

The results were striking. 

Gemma3 27B correctly identified the city and country of a travel photo 87% of the time. Qwen3 VL 30B performed even better, reaching 91% accuracy across the same dataset. 

That means in roughly 9 out of 10 cases, an AI model that’s available for free, to anyone, could look at an ordinary travel photo and correctly name where it was taken. This kind of analysis is also how AI tools understand images more broadly, shaping not just scams, but how information shows up in AI-powered answers. 

And when the exact city wasn’t identified, the country alone was almost always correct. For a scammer, that’s more than enough. It’s also enough to turn a vague, generic scam into one that feels specific, timely, and believable. 

What Makes a Photo Easy to Place? 

Certain types of images were identified with even higher confidence: 

  • Photos featuring famous landmarks or recognizable skylines 
  • Images taken in popular tourist destinations with distinctive visual signatures 
  • Photos with visible signage, unique street markings, or local architecture 
  • Images that captured cultural context: transportation, storefronts, food stalls 

Less recognizable scenery, like a generic beach, a rural road, or a hotel room, lowered accuracy. But even in those cases, country-level identification remained high. 

We Tried it. And We Were Spooked. 

To illustrate how simple this was to replicate, we moved outside of McAfee’s labs and asked our less-technical colleagues to try it themselves. No research background required. No special tools. 

Employees uploaded their own personal travel photos, images pulled straight from their camera rolls and never posted publicly, to ChatGPT, Claude, and Copilot, and simply asked each one to identify where the photo was taken. 

The results made people uncomfortable. 

Accuracy dropped compared to our controlled lab tests. But not by much. The models still correctly identified country-level location at a rate that would be more than enough for a scammer to craft a convincing, targeted message. 

The takeaway isn’t that AI has “seen” your photos somewhere before. It’s that a photograph inherently contains an enormous amount of locating information, in the architecture, the light, the signage, the landscape, simply by virtue of existing in the world. You don’t need to geotag a photo for it to give away where you’ve been. 

See It for Yourself 

The following section shows real examples of AI geo-location detection in action, using personal travel photos submitted by our research team. No location tags. No metadata. Just the image and what AI found in it. 

We started with somewhat recognizable structures in the background, and then tried increasingly more obscure backgrounds, trying to reduce faces and backgrounds to foliage only. This is what happened:

Example 1 

Brooke’s honeymoon pictures: This example features a more prominent landmark, helping AI determine the location  specifically. When there’s something recognizable, AI really recognizes it, down to giving you the exact spot on the map you’re at, the history of the location, and tourist information.

Screenshot of ChatGPT conversation identifying the location of a photo
Here, we see AI correctly state this photo was taken in front of “Temple II, Temple of the Masks.”

Example 2 

Sandra’s sunset photoThis example gets more difficult for AI by removing major landmarks and people. ChatGPT was still able to correctly identify the location as Hastings-on-Hudson. 

screenshot of AI correctly identifying location

 

 

Example 3 

Rob’s close-up shot of flowers: Just the close-up image of these tulips was enough for Claude to accurately detect that this photo was taken at Keukenhof gardens in the Netherlands.

AI was able to identify the location of these flowers in a close up.
AI was able to identify the location of these flowers in a close up.

How a Photo Becomes a Scam 

Knowing where someone is or where they’ve recently been is one of the oldest tricks in a scammer’s playbook. But until recently, getting that information required either knowing the person or getting lucky. 

AI removes the guesswork, allowing attackers to build highly specific, contextual scams at scale. 

With geo-location inference this accurate, scammers no longer need to cast a wide net and hope a generic phishing message lands. Instead, they can use publicly shared photos to build a believable context around an attack: 

  • “We detected unusual account activity while you were traveling in [city].” 
  • “Your card was flagged for a transaction in [country] — please verify immediately.” 
  • “Hi, we’re reaching out regarding your recent stay at a hotel in [destination].” 
  • “Hi, it’s [your name], I’m in Mexico and all my cards are being declined. Could you send me $$?” (a message targeting your friends or loved ones) 
  • “We noticed a login attempt from your location in [destination] — please confirm your identity.” 
  • “Your reservation in [city] requires reconfirmation — click here to secure your booking.” 
This is an example of a scam text detected by our research team. Now, imagine if scammers had more information, like the exact tour you were on, where you were, or the stores you shopped at. These details could make messages like this even more convincing and personalized.
This is an example of a scam text detected by our research team. Now, imagine if scammers had more information, like the exact tour you were on, where you were, or the stores you shopped at. These details could make messages like this even more convincing and personalized.

These messages don’t need to be perfectly accurate. They just need to feel plausible and close enough. That is the entire strategy. Familiarity lowers skepticism. Skepticism is what protects you. 

This is what turns mass phishing into hyper-personalized phishing at scale, and it’s why even cautious, digitally savvy travelers are getting caught. 

The Scammer’s New Workflow 

Here’s how straightforward this pipeline can become: 

  1. Find publicly shared travel photos on Instagram, Facebook, or X, no hacking required 
  2. Run them through a freely available AI vision model 
  3. Identify the likely destination, timeframe, and context 
  4. Craft a targeted message referencing that location 
  5. Send it during or shortly after the travel window, when the victim is most likely to believe it 

Steps 1 through 5 can be automated. The whole process scales easily. And the resulting messages feel personal in a way that generic scams never could. 

The Broader Scam Landscape Travelers Face 

Geo-location inference doesn’t exist in a vacuum. It’s one tool in a growing arsenal that scammers deploy specifically against travelers.  

Travelers are operating outside their normal routines, using unfamiliar networks, and making quick financial decisions under time pressure. These behaviors are exactly what make photo-based location inference more actionable for scammers. 

New McAfee consumer research found that more than 1 in 3 Americans have encountered a travel-related cyberthreat, and 41% of those impacted lost money, often exceeding $500. At the same time, rising travel costs and time pressure are pushing people toward faster, riskier decisions. Those are exactly the conditions scammers are built to exploit. 

The data reveals just how exposed travelers make themselves without realizing it. Nearly two-thirds of Americans connect to public Wi-Fi while traveling (63%), and a similar share scan QR codes without verifying where they lead (62%). Almost half use airport Wi-Fi specifically (49%), and 41% admit to trusting travel-related messages without checking the sender. One in five logs into financial apps while on public networks, and the same group shares travel plans in real time on social media. Twenty percent click travel-related links without verifying the source first. And finally, around 1 in 5 (22%) admit to sharing travel plans in real time.  

That last behavior is worth pausing on. Sharing travel plans in real time, on public or semi-public social accounts, is precisely what creates the photo-based location signals this research examines. These behaviors and geo-location exposure are not separate issues. They feed each other. 

Location inference is the key that makes all of those existing vulnerabilities more exploitable. A scammer with a rough idea of where you are does not just have a data point. They have a script. 

Methodology: How We Conducted This Research 

Transparency matters. Here is exactly how this research was conducted. 

Dataset: 21,236 travel images that are publicly available for research, plus a separate controlled set of 102 images contributed by McAfee internal volunteers (never previously posted publicly). 

Models tested: 

  • Gemma3 27B — a multi-model and vision-language model from Google DeepMind 
  • Qwen3 VL 30B — a multi-model and vision-language model from Alibaba’s Qwen team 

It’s important to note that we conducted our testing using large language models running locally on our own computers, rather than through public services such as ChatGPT.  

This more closely reflects how an attacker might operate at scale. Running models locally allows unrestricted, automated generation of large volumes of malicious content without relying on a third-party provider.  

By contrast, cloud-based AI services typically monitor for abuse and may impose rate limits, suspend accounts, or block requests when they detect activity associated with phishing or other malicious behavior. 

Process: An automated Python script submitted each image to both models using a standardized prompt requesting location identification based solely on visual content. No metadata, EXIF data, or file naming conventions were used as inputs. Results were logged programmatically. 

Validation: Image labels were pre-assigned prior to analysis. In cases where geographic names or landmarks could reasonably be interpreted in more than one way, a human reviewer compared the pre-labeled locations and model outputs to ensure consistent categorization.  

For example, the reviewer determined whether Vatican City should be grouped with Rome and whether “Washington D.C.” and “Washington, D.C.” should be treated as the same location. The reviewer did not alter either the original labels or the model results, but instead applied judgment to reconcile ambiguous naming conventions and edge cases. 

Accuracy definition: A result was counted as correct when the model identified the correct city and country. Country-only identification was tracked separately. Both metrics are reported. 

What this research does not claim: This research does not suggest that every travel photo will be correctly identified, or that all publicly available AI tools perform at this level. Results varied by image type, landmark density, and geographic region. The point is not perfect identification,  it’s that accuracy is high enough, and accessible enough, to enable targeted scams at scale. 

About the Consumer Research McAfee commissioned a consumer survey fielded in March 2026 examining travel intentions, travel scam experiences and perceptions, and digital behaviors while traveling. Results referenced here represent a subset of 1,000 U.S. adults over the age of 18. The full study included responses from 6,000 participants across Australia, France, Germany, Japan, the United States, and the United Kingdom. 

How to Protect Yourself 

Knowing the risk exists is the first step. Here’s what to actually do about it. 

Think before you post, especially in real time. The highest-risk window is when you’re still traveling. Posting while you’re in a location gives scammers a live signal. When possible, post after you’ve returned home or delay sharing location-identifiable content by a few days. 

Audit your social media privacy settings. Photos shared publicly are the easiest targets. Restricting your posts to people you know significantly limits the pool of images that can be scraped and analyzed. 

Be skeptical of urgency tied to your location. If a message references where you’ve been, even correctly, treat that as a red flag, not a credibility signal. Scammers use location familiarity precisely because it feels reassuring. 

Go directly to the source. If you receive a message claiming to be from your bank, airline, hotel, or card provider while traveling, don’t click any link in the message. Open a new browser tab and navigate directly to the company’s official website, or call the number on the back of your card. 

Use a travel-specific email or alias. Some travelers use a separate email address for bookings, reservations, and travel apps. This limits the cross-referencing scammers can do between your social media presence and your financial accounts. 

Trust the skepticism, not the familiarity. Modern scams are designed to feel familiar before they feel suspicious. If something creates a sense of urgency around your financial accounts while you’re traveling, slow down. The pressure itself is the warning sign. 

How McAfee Protects You Before, During, and After Travel 

As prices rise and decisions happen in real time, it’s easy to prioritize convenience over caution. But that’s exactly the moment when small checks matter most. 

Stage of Travel  What’s Happening  How McAfee Helps 
Before You Book  Comparing deals, clicking promotions, booking flights and hotels under time pressure  Scam Detector checks links, messages, and booking sites before you click, helping you avoid fake deals and scam listings 
During Your Trip  Connecting to public Wi-Fi, scanning QR codes, receiving travel updates and alerts  VPN helps secure your connection on public Wi-Fi, while Scam Detector flags suspicious messages and unsafe links in real time 
After Your Trip  Accounts remain active, travel data stored across platforms, potential exposure from breaches  Identity Monitoring alerts you if your personal information appears online, helping you act quickly before damage spreads 

With McAfee+ Advanced, multiple layers work together so you’re not left figuring it out after the damage is done.  

So you can focus on your trip, and not on whether that notification is a scam. 

Final Thought 

A travel photo is a memory. It’s also, increasingly, a data point. 

That doesn’t mean you should stop sharing your experiences. It means understanding that the same visual richness that makes a great photo is exactly what AI systems are trained to read. 

Scammers know this. Now you know how to protect yourself. 

This report was produced by McAfee Labs. Research was conducted in 2025–2026 as part of McAfee’s ongoing monitoring of AI-enabled scam vectors. 

The post AI Can Find Your Location 91% of the Time Using Just One Photo appeared first on McAfee Blog.

  •  

Silent Swap: A Crypto Clipper Extension Campaign

Authored by Neil Tyagi

Executive Summary 

McAfee Advanced Threat Research has identified an active browser-extension campaign designed to steal cryptocurrency by silently substituting wallet addresses the moment a user initiates a transaction. The campaign is delivered through unsigned installers — observed in both .NET and Golang variants — that deploy a malicious Chromium extension masquerading as a benign “Google Notes” utility.  

This campaign is related to a previous blog published by McAfee Labs, Sinkholing CountLoader: Insights into Its Recent Campaign, as the threat actor appears to be the same behind both operations. In that earlier research, we analyzed a crypto clipper payload that was injected directly into memory. Here, we examine a different variant of the final-stage payload: a browser-based malicious extension designed to intercept and manipulate cryptocurrency transactions.  

In this report, we detail how the extension operates and provide a technical analysis of the mechanisms that make this threat particularly unique. The extension behaves as a clipboard-aware crypto clipper: it monitors copy-and-paste activity, identifies wallet addresses across multiple blockchains, and swaps them for attacker-controlled addresses just before the victim pastes the content. Because most Blockchain transactions are irreversible, even a single uninterrupted execution is enough to cause permanent financial loss. 

Two characteristics elevate this campaign above the typical clipper threat: 

  1. Chromium trust-layer abuse. The installer secretly forces a malicious browser extension into Chromium-based browsers like Google Chrome, Brave, and Microsoft Edge by modifying protected browser settings files. Normally, these browsers store security verification data (hash/HMAC values) alongside sensitive settings to detect unauthorized changes. The malware recalculates and updates these security values after tampering with the files, tricking the browser into believing the malicious extension was installed legitimately. This allows the extension to bypass the normal extension web store installation process and load silently without user approval. However for updated Chrome and edge browser, Victim must manually turn on the developer mode for the extension to load properly, but people with outdated versions of chromium based browsers, remain at high risk. Moreover, for latest versions as well threat attacker can employ social engineering tactics to enable developer mode.
  2. Blockchain-resolved command-and-control. The extension does not contain a hardcoded C2 domain. Instead, it queries a public blockchain RPC endpoint, invokes a read-only smart-contract method, and decodes the response at runtime to reveal its active C2 observed at the time of analysis as Zebregts[.]com 

    This technique, often referred to as “EtherHiding,” complicates takedown efforts because the attacker can rotate infrastructure by updating a smart-contract value rather than redeploying malware. 

McAfee telemetry indicates a globally distributed infection footprint with a pronounced concentration in India. The breadth of the geography suggests opportunistic targeting of consumer cryptocurrency users rather than a region-specific operation. 

Geographical Prevalence  

A map of the world showing countries impacted by this cybersecurity threat.
Our research shows that these are the most affected regions of the globe.

Telemetry analysis indicates that infections are globally distributed, with a significantly higher concentration observed in India compared to other regions.  

The widespread geographic presence highlights the campaign’s broad reach, suggesting opportunistic targeting rather than a region-specific attack. 

The Malicious Extension: “Google Notes” 

This malware is masquerading as a seemingly harmless Google Notes extension. 

The malicious Google Chrome extension.
Figure 1. This image shows the malicious extension at the center of this campaign

 

The dropped extension presents as a minimalist, legitimate-looking note-taking application branded as “Google Notes,” complete with a clean icon and a functional (& simplistic) user interface.  

The cover is calculated: a user who manually opens the extension finds something that behaves as advertised, dampening suspicion. The extension’s malicious logic is implemented in background service-worker scripts and content scripts that operate entirely out of view of the UI. 

A major red flag first appears when adding the extension, which requests  security permissions and access that are disproportionate to a typical notes application: 

  • Access to all URLs , granting content-script injection into every site the user visits. 
  • Browsing history access. 
  • Read and write access to the clipboard. 

Mitigation and Recommendations 

For Consumers 

  1. Before confirming any cryptocurrency transaction, visually verify the first and last six characters of the recipient address against the original source — ideally on a separate device. This single habit defeats the overwhelming majority of clipper attacks. 
  2. Install browser extensions exclusively from the official Chrome Web Store, Edge Add-ons store, or equivalent. An extension that appears in your installed list without a clear memory of having installed it should be treated as suspicious. 
  3. Review the permissions granted to every installed extension. A note-taking tool has no legitimate need for access to all websites, browsing history, or the clipboard. 
  4. Avoid running unsigned executables obtained from non-authoritative sources, particularly those offering free or cracked versions of paid software — a common delivery vector for this category of installer. 
  5. Keep endpoint protection up to date and enabled; McAfee customers are protected against this specific campaign as described below. 

McAfee security solutions help safeguard users at multiple levels: 

1. McAfee detects this threat as CryptoStealer.NE and keeps our customers safe 

Figure 2. This image shows McAfee Antivirus blocking this threat for consumers.
Figure 2. This image shows McAfee Antivirus blocking this threat for consumers.

2. Malicious Download Protection

The installer’s behavior—downloading and executing remote payloads—is flagged and blocked by McAfee before infection completes. All the malicious domains and URLs are blocked by McAfee in our tests. 

3. Network Protection

Connections to known malicious infrastructure (C2 servers) are blocked by McAfee, preventing Wallet address retrieval 

4. Real-Time Threat Intelligence

Because this threat was identified in McAfee telemetry, protections can be rapidly deployed to: 

  • Block similar variants 
  • Detect related infrastructure 
  • Protect customers globally 

How The Threat Campaign Works 

What the Malware Does  

  1. Installs a browser extension silently (web extension sideloading) 
  2. Monitors what you copy and paste (especially crypto addresses) 
  3. Works when you are making a crypto transaction 
  4. Silently replaces the wallet address with the attacker’s address 
  5. Your funds are sent to the attacker instead of the intended recipient 

Because cryptocurrency transactions are typically non-reversible, victims may permanently lose funds. 

Figure 3. How the extension works in a nutshell
Figure 3. How the extension works in a nutshell

 

Key Capabilities Identified 

1. Silent Extension Installation 

The malware does not use the official browser store. Instead, it directly modifies browser files to make the extension appear installed. (Sideloading Browser Extension) 

This bypasses normal security prompts and user awareness. 

Figure 4. Procmon logs showing BaseZipInstaller (malicious web installer) writing into chrome and edge secure preference files
Figure 4. Procmon logs showing BaseZipInstaller (malicious web installer) writing into Chrome and Edge secure preference files

2. Full Browser Access 

Figure 5. Chrome extension Permissions required
Figure 5. Chrome extension Permissions required
Figure 6. Manifest file for web extension
Figure 6. Manifest file for web extension

The malicious extension requests excessive permissions such as: 

  • Access to all websites 
  • Reading browsing history 
  • Reading and modifying clipboard content 

3. Crypto Address Interception

The extension contains logic to detect wallet addresses across multiple cryptocurrencies, including: 

Figure 7. Hardcoded cryptocurrency Regex and fallback address
Figure 7. Hardcoded cryptocurrency Regex and fallback address
  • The fallback wallet addresses shown in the code are not used for every transaction; instead, they serve as a backup mechanism when dynamic address retrieval from the attacker-controlled server fails.  
  • Under normal operation, the extension fetches replacement addresses from a remote server, enabling dynamic and potentially per-victim wallet assignment.  
  • Fallback addresses ensure the attack remains functional even if the command-and-control infrastructure is temporarily unavailable or blocked. 
Figure 8. Malicious extension performing dynamic crypto address resolution
Figure 8. Malicious extension performing dynamic crypto address resolution
  • This function is responsible for obtaining the attacker-controlled replacement wallet address corresponding to a victim’s original address.  
  • It sends the intercepted wallet address to the attacker backend and uses the response to dynamically substitute the original address.  
  • If the backend request fails, the function falls back to a predefined hardcoded wallet address, ensuring uninterrupted malicious activity. 
  • 3J98t1Wxxxx is the address that was copied in the clipboard 

4Detection evasion and stealth 

Figure 8. settings.js file which shows config
Figure 8. Settings.js file which shows config
  • The configuration includes a hardcoded API key, which is used by the extension to authenticate communication with attacker-controlled infrastructure.  
  • An RPC URL pointing to a public blockchain node is leveraged to dynamically resolve backend server information, allowing the attacker to hide critical infrastructure behind decentralized systems.  
  • The presence of a smart contract address and method indicates that the malware retrieves its command-and-control (C2) domain indirectly via blockchain queries, making takedown and tracking more difficult. 
  • Blacklisted domains contains a list of blockchain inspection related websites where the web extension will not work , this is done to not alert the victim while he is trying to paste his own address and view the balance of his wallet or inspect his wallet transactions 
Figure 9. Resolving attacker c2 domain via etherium smart contract (etherhiding)
Figure 9. Resolving attacker C2 domain via Ethereum smart contract (etherhiding)
Figure 10. Request payload with Ethereum contract address
Figure 10. Request payload with Ethereum contract address
  • Dynamic analysis revealed that the malware resolves its command-and-control domain via a blockchain smart contract, which returned the domain devops-offensive[.]cc at runtime.  
  • The response from the blockchain is decoded at runtime, revealing the active C2 domain (devops-offensive.cc).  
  • This domain is not hardcoded, enabling the attacker to update infrastructure without modifying the malware.  
  • The resolved domain is cached locally to maintain persistence and reduce repeated network queries. 
Figure 11. This image shows the long-encoded string with the malicious domain
Figure 11. This image shows the long-encoded string with the malicious domain

This Longencoded string is decoded using this function to give the final attacker domain.

Figure 12. This image shows the final attacker domain
Figure 12. This image shows the final attacker domain

Persistence and Evasion Techniques 

The campaign’s persistence and evasion posture is deliberate and layered. The operator has clearly optimized for two properties: low visibility to the end user, and high resilience against takedown and static analysis. 

Persistence 

  • Extension registration through Secure Preferences tampering ensures the extension loads on every subsequent browser launch without requiring any auxiliary Windows persistence mechanism — no registry Run keys, scheduled tasks, or services that endpoint hunters typically inspect. 
  • Developer mode is enabled programmatically where required, allowing unpacked extensions to persist without triggering the periodic “unpacked extensions warning” flow that Chromium displays to dissuade sideloading. 
  • The cached C2 domain allows the extension to continue operating against a known-good backend even if the blockchain RPC endpoint is briefly unavailable. 

Evasion 

  • The extension’s visible identity — a simple “Google Notes” note-taking application — provides plausible cover against casual inspection of the installed extensions list. 
  • Recomputed HMAC values satisfy Chromium’s integrity verification, avoiding the “extension installed by an unknown source” warning banner that would otherwise alert the user. 
  • The installer self-deletes after execution, removing the most obvious on-disk indicator of initial compromise. 
  • C2 resolution through a public blockchain means that there is no persistent C2 domain observable in the malware bundle itself; network-based detections built against hardcoded indicators will not fire until the domain is resolved and contacted. 
  • Multi-language installer variants (.NET and Golang) reduce the effectiveness of compile-artifact and binary-feature signatures. 
  • Per-address dynamic wallet substitution means that published attacker addresses age rapidly and do not generalize into durable blocklist entries — the defender must block the backend service itself, not the addresses it dispenses. 

Wallet Substitution Logic 

The clipper logic sits in two layers: a content-script layer that monitors clipboard activity and DOM input fields across every visited origin, and a background layer that communicates with the attacker backend to retrieve replacement addresses. 

When the extension observes a copy event, it applies a set of cryptocurrency-specific regular expressions to the clipboard payload. If a match is found, the intercepted address is transmitted to the attacker’s backend over an authenticated request (authenticated with the API key embedded in the configuration). The backend responds with a replacement address specific to the submitted original, and that replacement is written back to the clipboard, overwriting the legitimate address before the victim can paste. 

Testing against a reconstructed backend client — built by re-implementing the extension’s request format and response-decoding logic in Python — produced a revealing behavioural profile: 

  • Bitcoin (BTC), Ethereum, Bitcoin Cash, Ripple, and Dash: Each submitted address is mapped to a unique attacker-controlled address. Re-submitting the same original returns the same replacement, indicating a deterministic one-to-one mapping maintained server-side. 
  • Solana: All submitted addresses collapse to a single attacker address, suggesting the per-victim mapping feature is selectively implemented per chain 

Analyzing Attacker Crypto Wallets 

Based on the code snippets from the web extension responsible for retrieving replacement addresses, a Python script was prepared to programmatically extract attacker wallet addresses. The payload was crafted using the attacker’s own code, and the “get replacement address” snippet was lifted directly from it. The attacker’s logic for decoding data received from the C2 server was also faithfully reimplemented in the script. 

The script was then executed using a few test Bitcoin (BTC) wallet addresses. The results showed that for every Bitcoin address provided, a unique Bitcoin address was returned in response, and all of these returned addresses were valid BTC wallets. This indicates that for every BTC address supplied, the attacker dynamically generates a new wallet tied to that specific input address. Furthermore, when the same address was provided again, the same BTC address was returned — confirming that each victim BTC address is deterministically mapped to a single, specific attacker-controlled address. While some of these attacker wallets contained funds and others were empty, the unknown total number of attacker wallets makes it difficult to put a reliable estimate on how much cryptocurrency has been stolen overall. 

The same behavior was observed for Ethereum, where different wallet addresses were returned for each input. Interestingly, when the script was tested with Solana addresses, only a single address was returned regardless of how many different inputs were provided. This suggests that the attacker has implemented the per-address mapping feature only for specific cryptocurrencies, while others fall back to a single static drop wallet. Because the Solana address is shared across all victims, a noticeable bump in its balance is visible. Additionally, one of the Ethereum addresses uncovered was found to be holding approximately 1,902 USD worth of funds. 

In summary, the cryptocurrencies for which unique per-victim wallet addresses are generated include Bitcoin, Ethereum, Bitcoin Cash, Ripple, and Dash. 

Fig 13. Payload was crafted as attacker code
Fig 13. Payload was crafted as attacker code
Fig 14.Getting replacement address code snippet taken from attacker code
Fig 14. Getting the replacement address code snippet taken from attacker code
Fig 15. Attackers logic of decoding received data from c2 was also implemented
Fig 15. Attackers’ logic of decoding received data from C2 was also implemented

Running script with few test Bitcoin Wallet addresses 

Fig 16. Every bitcoin address a unique bitcoin address was returned and All addresses are valid BTC wallet address
Fig 16. Every unique Bitcoin address was returned and all addresses are valid BTC wallet addresses
Fig 17. Similarly, Ethereum saw unique addresses
Fig 17. Similarly, Ethereum saw unique addresses
Figure 18: Running Script for Test Solana Addresses
Figure 18: Running Script for Test Solana Addresses

Luckily for Solana we are getting only 1 address when given multiple addresses. This shows that the attacker has implemented this address mapping feature only on specific cryptocurrencies 

Fig. 19 Here you can see a bump in the balance amount
Fig. 19 Here you can see a bump in the balance amount
Fig 20. ETH address was found to be having 1902 USD
Fig 20. The ETH address was found to have 1902 USD

Technical Analysis for .net file (Extension installer) 

Fig. 21 BaseZipInstaller is a .NET installer which is unsigned
Fig. 21 BaseZipInstaller is a .NET installer which is unsigned

 

Fig. 22 Stored Config as seen in Dnspy
Fig. 22 Stored Config as seen in Dnspy
  • The malware embeds a complete configuration JSON directly within the binary, eliminating the need to fetch initial setup data from external sources.  
  • This embedded configuration includes critical details such as API keys, backend server URL, targeted wallet extensions, and the full extension manifest with extensive permissions.  
Fig 23: Main function from where execution starts
Fig 23: Main function from where execution starts
  • The installer retrieves and validates a remote ZIP archive (google-services[.]cc/base[.]zip), which serves as the primary payload for deploying the malicious browser extension, marking the transition from initial infection to browser-level compromise. 
Fig. 24 The extension is created at the following location In system with files which are downloaded as base.zip.
Fig. 24 The extension is created at the following location in the system with files that are downloaded as base.zip.
Fig. 25: Dnspy showing the list of targeted browsers
Fig. 25: Dnspy showing the list of targeted browsers
  • The installer iterates through multiple Chromium-based browsers, including Chrome, Edge, Opera, and Brave, identifying available user profiles on the system.  
  • For each detected profile, the malware forcibly terminates the browser process to safely modify configuration files without interference.  
  • It then injects the malicious extension by directly modifying Secure Preferences and Preferences, enabling the extension to be loaded without user interaction. 
more code
  • The malware identifies browser installation paths by querying standard system directories, enabling it to locate user data folders for Chrome, Edge, Opera, and Brave.  
  • It systematically enumerates browser profiles and specifically looks for the presence of the Secure Preferences file, which stores critical browser configuration and extension data.  
  • By targeting profiles with Secure Preferences, the malware ensures it modifies only valid browser environments, increasing the reliability of extension injection. 
We can see writefile Event on Secure preferences file of chrome and MS Edge , when details of downloaded extension are written to those config files
We can see writefile Event on Secure preferences file of chrome and MS Edge , when details of downloaded extension are written to those config files
Fig 27 Attacker logic to resign the secure preference files
Fig 27 Attacker logic to resign the secure preference files
  • The malware reads and modifies the browser’s Secure Preferences file, which controls installed extensions and their trust state.  
  • It injects the malicious extension into the configuration and attempts to re-sign the modified data, making the changes appear legitimate to the browser’s integrity checks.  
  • The updated configuration is then written back to disk, ensuring the extension is loaded automatically and persists across browser restarts. 
Fig 27B :Extension path is added to chrome secure preferences file
Fig 27B :Extension path is added to chrome secure preferences file
Fig 28: Logic to Manipulate defenses of Brave Bowser
Fig 28: Logic to Manipulate defenses of Brave Bowser
  • For browsers such as Brave and Opera, the malware injects the malicious extension directly into the browser’s configuration by adding entries under the extensions.settings (or extensions.opsettings) section.  
  • It also updates integrity-related fields (protection.macs) to make the injected extension appear trusted by the browser.  
  • Additionally, the malware attempts to enable developer mode programmatically, allowing unpacked extensions to run with fewer restrictions. 
Fig 29: Attacker logic to get device ID used to further calculate integrity Values
Fig 29: Attacker logic to get device ID used to further calculate integrity Values
  • The malware attempts to recompute browser integrity signatures by generating new MAC (Message Authentication Code) values for the modified Secure Preferences file.  
  • It uses system-specific identifiers, such as the machine SID, combined with a seed value to mimic Chrome’s internal verification mechanism.  
  • By recalculating these integrity checks (macs and super_mac), the malware tries to make its unauthorized modifications appear legitimate to the browser. 
Figure 30 Self Deletion Logic
Figure 30 Self-Deletion Logic
  • The malware includes a self-deletion mechanism designed to remove the installer executable after successful execution.  
  • It launches a hidden command prompt process that delays execution briefly before deleting the original file from disk. 

Conclusion 

This campaign is a concise illustration of where consumer-targeted cryptocurrency theft is heading. The operator has taken the oldest and simplest category of crypto malware — the clipper — and quietly upgraded three of its weakest links. Static attacker addresses have been replaced with a server-side, per-victim mapping. Fragile, hardcoded command-and-control domains have been replaced with a blockchain-resolved lookup that an operator can rotate with a single transaction. And a fragile dropper has been replaced with a Chromium extension that lives inside the user’s most trusted application, loaded under the browser’s own integrity signature. 

McAfee will continue to track this campaign and related infrastructure. Our customers are protected by existing detections and will benefit from telemetry-driven updates as new variants and rotated infrastructure are identified. 

Indicators of Compromise (IOC)

Type  Category  Value 
SHA-256  .NET Installer (BaseZipInstaller)  2735e12030c195fb5454e4736c51b55b59664b93cae9f4bd5317afcd9c2af0bf 

053620962047f50a91c6e8d1a6519eccc41fab51473f033086b4d816abe8bcb0 

 

SHA-256  Golang-compiled Installer Variant  11be4c47ff049322de41743f62544cafd32d67e24ad653b7ebedf8ebd63e0962   

1432393691b415d0cd4680d9cee73e60896fbe63300d9f0355c96e91817e4b1d   

URL  Payload distribution  hxxps://google-services[.]cc/base[.]zip 
Domain  Command-and-Control (resolved via smart contract)  devops-offensive[.]cc 

Zebregts[.]com 

BTC wallet  Crypto wallet  3JvDBvKbS6YYMKjV3R9e9Zfd67f467fNLy 

1BbhVBxpniuZuAL1gGZnEMdQhmz9JGWpyT 

3AcPNVh7NyESwX3ECymy3rkdH4Ke2c26Tj 

1BVTrB47erypG3tevi1U9Fv6BbNUBEiuiX 

Artifact  Sideload target  Chromium Secure Preferences file (Chrome, Edge, Brave, Opera profiles) 
Extension files  manifest.json  

crypto-patterns.js 

 

Interceptor.js 

 

content-script.j  

 

cache.js  

 

domain-resolver.js 

 

service-worker.js 

 

api-client.js 

ed2599d6a8f30d5eaf14ad7f855aece0acdf7efa4a148eb18e4d9f0d8e2cd90c  

daf82c67e8e5df6bbd5370172ac9374aa7dce48af05496e8ec3dba7b602c619b  

6eb2f07265dd95cacd39dfcf0705786b97f3e173cf4e9b3dfe7bad141c9a9dd5 

 

a2ffdbedc5c9f5400a2b1cf5d35f5ec1df06a74d0345f1035bcf75d36ed73e01  

 

eb84ba4a0cd95655a021865d4fec93ae3393f86cc9848810ed0b49035b1c5e2c  

6aaba685669d779ef8be8f7f4231096cfafd0ef386f3897c5e2106c177724fc8  

 

2599064901308a97540af29197ed0b38702bbee38d6dbbfa61cf9eb5878353f3  

ab450927b37e1b68e2be68832c354ac600e86e2545a904d4ca0ea283f2600cc2  

 

The post Silent Swap: A Crypto Clipper Extension Campaign appeared first on McAfee Blog.

  •  

The New DoorDash Scam Every Gig Worker Should Know About: This Week in Scams

Millions of Americans rely on apps and online services every day to work, shop, game, and manage their lives. Scammers know that, and they’re hijacking platforms and brands you already trust. 

This week, gig workers were targeted by fake DoorDash support calls designed to steal their earnings, while gamers searching for early access to Grand Theft Auto VI found fraudulent websites promising something Rockstar Games simply isn’t offering. 

Here’s what happened, how these scams work, and the other cybersecurity stories making headlines this week. 

The DoorDash Driver Scam That Can Empty Your Account 

A growing scam targeting DoorDash drivers starts with what appears to be a normal delivery request. 

According to Fox 9 in Minnesotascammers place fake DoorDash orders, then contact drivers while they’re actively completing the delivery. Because the call often arrives during a real order and can even appear to come from DoorDash, victims may believe they’re speaking with legitimate support. 

The caller typically claims there’s an issue with the order or the driver’s account and asks them to verify information or read back security codes. 

Once the scammer gains access, they can change account information, lock the driver out, and redirect earnings into their own accounts. In reported cases, victims lost hundreds of dollars and temporarily lost access to the platform they depend on for income. 

While today’s it’s DoorDash in the headlines, scammers are known to impersonate all types of delivery apps, so gig workers across companies should stay alert. 

How the fake delivery support scams work 

Step  What Happens 
1  Scammers place a fake DoorDash order. 
2  They call the driver pretending to be DoorDash Support. 
3  They request login information or verification codes. 
4  They take over the account and transfer the driver’s earnings. 

Red flags every delivery driver should know 

Pause if you experience: 

  • Unexpected calls asking for verification codes  
  • Requests to confirm login credentials  
  • Pressure to act immediately  
  • Anyone asking you to read a one-time authentication code over the phone  

Legitimate companies generally won’t ask you to share one-time security codes. If you receive an unexpected call, end it and contact support directly through the app. 

Fake GTA 6 Early Access Sites Are Everywhere 

Excitement around Grand Theft Auto VI has created another opportunity for scammers. 

According to Malwarebytes, fraudulent websites are claiming to sell “VIP Early Access” or exclusive versions of GTA 6 months before release. Many of the sites look polished, featuring convincing artwork, countdown timers, and professional checkout pages. 

The catch? They typically require payment in cryptocurrency. 

After victims pay, there’s no game to download because no legitimate early-access version exists. 

How to spot a GTA 6 scam 

If a website promises: 

  • Early access before Rockstar officially releases it  
  • Exclusive playable builds  
  • Secret download links  
  • Crypto-only payment  
  • “Limited VIP access”  

it’s almost certainly a scam. 

Rockstar has announced pre-orders through authorized retailers. Any website claiming to provide playable access before launch should be treated with skepticism. 

Other Scam and Security News This Week 

Police Officer Records Live Scam Call to Show How Social Engineering Works 

A police officer recorded a scam call in real time to demonstrate how quickly criminals try to establish trust, create urgency, and convince victims to share sensitive information. The recording serves as a reminder that scammers often sound calm, professional, and convincing because manipulation, not technology, is their primary weapon. 

Tata Electronics Cyber Incident Raises Supply Chain Questions 

Apple supplier Tata Electronics confirmed it experienced a cybersecurity incident after a ransomware group claimed to publish more than 200,000 files allegedly connected to the company. According to Cybernews and Reuters reporting, the leaked material allegedly includes manufacturing documents and employee information tied to Apple and Tesla. Apple says it is investigating while Tata has not confirmed whether the published files originated from its systems. 

Texas Parks and Wildlife Warns 3 Million Customers About Data Breach 

Texas Parks and Wildlife notified roughly three million hunting and fishing license customers that personal information stored by a third-party vendor may have been accessed during a cyber incident. According to Click2Houston, exposed information may include driver’s license numbers, contact information, and mailing addresses, though officials said Social Security numbers and payment card information were not involved. Impacted customers are being offered identity monitoring. 

How McAfee Can Help  

With McAfee+, multiple layers work together before any damage is done:  

  • Scam Detector flags suspicious texts, emails, links, QR codes, and even deepfake videos before you engage 
  • Secure VPN keeps your data private, especially on public Wi-Fi  
  • Web Protection helps block risky sites, even if you do accidentally click 
  • Password Manager doesn’t just help you make unique, strong passwords, it keeps them stored and organized for you
  • Device Security helps detect malicious apps or downloads   
  • Identity Monitoring alerts you if your personal info shows up where it should not, so you can act fast   
  • Personal Data Cleanup helps remove your information from sites selling it. 
  • Online Account Cleanup assists in taking down your old, forgotten accounts across the web 
  • Social Privacy Manager helps you monitor and change privacy settings across your social platforms in just a few clicks 

Together, these protections are designed to address the broader range of online risks people face every day. 

The post The New DoorDash Scam Every Gig Worker Should Know About: This Week in Scams appeared first on McAfee Blog.

  •  

Is That Delivery Text Real? How to Spot Package Smishing and Delivery Scams

You’re expecting a package. 

Maybe it’s a birthday gift. Maybe it’s a purchase from a major shopping event. Maybe it’s something you forgot you ordered three days ago. 

Then your phone buzzes. 

Your package couldn’t be delivered.  There’s a problem with your shipping address. 

A small fee is required before delivery can continue. 

“Click here immediately.”

The message feels plausible because so many of us are constantly waiting for packages. And scammers know it. 

According to McAfee’s State of the Scamiverse report, fake delivery and shipping notices are the single most commonly reported scam consumers encounter today, with 31% of people saying they’ve received one. Americans also receive an average of 14 scam messages every day across texts, email, social media, phone calls, and other channels.  

Delivery scams have become one of the internet’s most successful forms of phishing because they exploit something simple: people are already expecting the message. 

Here’s how to spot and stop these scams:

What Is a Delivery Scam? 

A delivery scam is a fraudulent message that pretends to come from a shipping company, retailer, postal service, or delivery provider. 

The goal is usually one of three things: 

  • Steal personal information  
  • Steal financial information  
  • Trick victims into downloading malware or visiting malicious websites  

These scams often impersonate organizations such as: 

  • USPS  
  • UPS  
  • FedEx  
  • DHL  
  • Amazon  
  • Royal Mail  
  • Australia Post  
  • Other local or regional delivery services  

Most delivery scams arrive through text messages, which is why they’re often called package smishing scams. 

What Is Smishing? 

Smishing is a type of phishing attack delivered through SMS text messages. 

The term combines: 

  • SMS (Short Message Service)  
  • Phishing 

Instead of arriving through email, the scam arrives directly on your phone and attempts to create a sense of urgency that encourages immediate action. 

Common examples include: 

  • “Your package could not be delivered.”  
  • “Delivery attempt failed.”  
  • “Update your shipping address.”  
  • “Pay a small customs fee.”  
  • “Confirm delivery information.” 
McAfee's Scam Detector lets you know when delivery messages are scams.
McAfee’s Scam Detector lets you know when delivery messages are scams.

Delivery Scam Red Flags and What to Do 

If You See This Red Flag  Why It’s Suspicious  What To Do 
A package alert when you’re not expecting a delivery  Scammers send messages in bulk hoping someone is waiting for a package  Ignore the message and do not click links 
A request to pay a small fee before delivery  Legitimate carriers rarely collect delivery fees through text messages  Visit the carrier’s official website directly 
A message claiming your address needs verification  Common tactic used to steal personal information  Check shipment status through your retailer or carrier account 
A shortened or unusual link  Scammers often disguise malicious websites  Avoid clicking and manually type the carrier’s website address 
Pressure to act immediately  Urgency is designed to override caution  Pause and verify independently 
Requests for passwords, payment information, or verification codes  Legitimate carriers will not ask for this through text messages  Delete the message and report it as spam 
A delivery app or file download request  May install malware on your device  Never download software from a text message 

Accidentally Clicked a Delivery Scam? Do This Immediately 

What Happened  What To Do 
You only clicked the link  Close the page and do not enter any information 
You entered login credentials  Change your password immediately and enable two-factor authentication 
You entered payment information  Contact your bank or credit card provider right away 
You downloaded a file or app  Delete it and run a security scan 
You’re unsure what information was exposed  Monitor accounts closely for unusual activity 

How McAfee Can Help  

With McAfee+, multiple layers work together before any damage is done:  

  • Scam Detector flags suspicious texts, emails, links, QR codes, and even deepfake videos before you engage 
  • Secure VPN keeps your data private, especially on public Wi-Fi  
  • Web Protection helps block risky sites, even if you do accidentally click  helps block risky sites, even if you do accidentally click   
  • Password Manager doesn’t just help you make unique, strong passwords, it keeps them stored and organized for you
  • Device Security helps detect malicious apps or downloads   
  • Identity Monitoring alerts you if your personal info shows up where it should not, so you can act fast   
  • Personal Data Cleanup helps remove your information from sites selling it. 
  • Online Account Cleanup assists in taking down your old, forgotten accounts across the web 
  • Social Privacy Manager helps you monitor and change privacy settings across your social platforms in just a few clicks 

Together, these protections are designed to address the broader range of online risks people face every day. 

The post Is That Delivery Text Real? How to Spot Package Smishing and Delivery Scams appeared first on McAfee Blog.

  •  

7 Shopping Scams Americans Report Seeing Most: This Week in Scams

Last week, McAfee warned that economic pressure and AI are creating ideal conditions for online shopping scams. 

This week, that warning got another real-world example. 

New reporting revealed that cloned shopping websites have appeared in AI-generated search results, potentially directing consumers to convincing fake storefronts designed to steal payment information and personal data.  

The incident reinforces what McAfee’s latest research found ahead of Prime Day: shoppers are moving faster, trusting deals more readily, and encountering increasingly sophisticated scams. 

Before the summer’s biggest shopping events kick into high gear, let’s get into the sales and Prime Day scams to be aware of and other cybersecurity news making headlines This Week in Scams. 

The Top 7 Shopping Scams to Watch for This Prime Day 

McAfee’s latest research found consumers most frequently encounter the following scams during major sales events: 

  1. Fake shipping confirmations and order updates (34%)  
  2. Delivery company impersonation scams (32%)  
  3. Requests for payment or account information (27%)  
  4. Suspicious account verification alerts (26%)  
  5. Retailer impersonation scams (25%)  
  6. Fake urgency and expiring deal messages (24%)  
  7. Suspicious discount codes and flash-sale offers (22%)  

These scams work because they exploit moments when consumers are already expecting packages, tracking orders, comparing prices, and making quick purchasing decisions. 

McAfee's latest research found consumers most frequently encounter the following scams during major sales events:  Fake shipping confirmations and order updates (34%)   Delivery company impersonation scams (32%)   Requests for payment or account information (27%)   Suspicious account verification alerts (26%)   Retailer impersonation scams (25%)   Fake urgency and expiring deal messages (24%)   Suspicious discount codes and flash-sale offers (22%)  

Prime Day Shopping Safety Checklist 

In McAfee’s new consumer research40% of Americans surveyed said they would trust a lower priced deal without verifying it. That means as costs are climbing, shoppers are less likely to second guess a too-good-to-be-true deal that could be a scam.   

“What the data reflects is that economic pressure has effectively done some of the scammer’s work for them,” says McAfee’s Head of Threat Research Abhishek Karnik.  

“When consumers are already primed to move quickly and prioritize price over authenticity, it takes far less effort to push them toward a bad click or a fraudulent purchase.”  

And reporting that fake shopping sites have appeared in ChatGPT results shows that scammers are adapting to ensure they show up wherever consumers search for products, including AI-powered search experiences. 

That means it’s more important than ever for shoppers to know the red flags, common scams, and protection measures to find deals safely. 

Safety Checklist 

Before making a purchase: 

✓ Verify the website URL 

✓ Compare prices across multiple retailers 

✓ Research unfamiliar sellers 

✓ Be skeptical of discounts exceeding 50-70% 

✓ Never trust a shopping link sent by text 

✓ Use a credit card instead of bank transfer, crypto, or gift cards 

✓ Check independent reviews 

✓ Verify shipping alerts directly through the retailer 

Other Scam and Security News This Week 

Nintendo Investigates Third-Party Employee Data Incident 

According to Kotaku, Nintendo is investigating an alleged data exposure involving TinyPulse, a third-party employee survey platform. An extortion group claiming responsibility for the incident says it possesses employee information and internal communications and demanded a $2 million ransom. Nintendo said its own systems were not compromised and that no customer financial or payment information was accessed. 

Madison Square Garden Data Allegedly Posted Online 

According to 404 Media, hackers linked to the ShinyHunters group have allegedly published data stolen from Madison Square Garden after an extortion attempt. Sample files reviewed by the outlet reportedly contained personal information, talent records, and contact details connected to sports personalities and business operations. 

Novo Nordisk Reports Clinical Trial Data Breach 

According to Yahoo Finance, Novo Nordisk disclosed a data breach involving individuals participating in clinical trials. The company is currently assessing the scope of the exposure while also managing ongoing supply constraints affecting its GLP-1 medications, including Wegovy. 

How McAfee Can Help  

With McAfee+ Premium, multiple layers work together before any damage is done:  

  • Scam Detector flags suspicious texts, emails, links, QR codes, and even deepfake videos before you engage 
  • Secure VPN keeps your data private, especially on public Wi-Fi  
  • Web Protection helps block risky sites, even if you do accidentally click  helps block risky sites, even if you do accidentally click   
  • Password Manager doesn’t just help you make unique, strong passwords, it keeps them stored and organized for you
  • Device Security helps detect malicious apps or downloads   
  • Identity Monitoring alerts you if your personal info shows up where it should not, so you can act fast   
  • Personal Data Cleanup helps remove your information from sites selling it. 
  • Online Account Cleanup assists in taking down your old, forgotten accounts across the web 
  • Social Privacy Manager helps you monitor and change privacy settings across your social platforms in just a few clicks 

Together, these protections are designed to address the broader range of online risks people face every day. 

Plus, click here to get McAfee’s limited-time deals on real-time protection this Amazon Prime Day, from June 23 to June 26.

The post 7 Shopping Scams Americans Report Seeing Most: This Week in Scams appeared first on McAfee Blog.

  •  

ServiceNow Data Exposure and a New VA Scam: This Week in Scams

Most people think a data breach starts with a hacker breaking into a system. 

In reality, and in many cases, it starts with human error or oversight. 

This week, cloud software giant ServiceNow disclosed that a software flaw allowed some customer data to be accessed without authentication, potentially exposing information that should never have been publicly available. 

The incident is a reminder that your personal information can be put at risk even when cybercriminals aren’t directly responsible. 

Here’s what happened and our other This Week in Scams news: 

ServiceNow Bug Left Customer Data Exposed 

ServiceNow, one of the world’s largest enterprise software providers, recently notified some customers that a software bug allowed unauthorized access to data stored on parts of its platform. 

According to reporting by TechCrunch, the flaw could have allowed individuals to access customer data without needing credentials such as a username or password. 

The company says the activity was identified by security researchers participating in vulnerability research rather than malicious hackers. ServiceNow told TechCrunch it found no evidence that bad actors were responsible for the observed activity and said researchers reported the issue through responsible disclosure channels. 

The company patched affected systems on June 5 and launched an investigation into the scope of the exposure. 

Why This Matters 

For consumers, this story highlights an important cybersecurity reality: not every data exposure is the result of a criminal attack. 

Sometimes information becomes accessible because of: 

  • Software bugs 
  • Misconfigured cloud systems 
  • Human error 
  • Security settings that fail to work as intended 

In this case, ServiceNow says the issue stemmed from a platform vulnerability rather than a breach by threat actors. 

However, the outcome can look similar from a customer’s perspective. Information that was intended to remain private may have been accessible to unauthorized parties. 

That’s why it’s important to pay attention to security notifications from companies you do business with, even when reports emphasize there was “no hack.” 

What You Should Do After Any Data Exposure 

Whether a company reports a breach, a vulnerability, or an accidental exposure, the recommended steps are often similar: 

  • Watch for notifications from the affected company. 
  • Change passwords if requested. 
  • Enable multi-factor authentication where available. 
  • Monitor financial and online accounts for unusual activity. 
  • Be alert for phishing emails and scam calls referencing the incident. 

Cybercriminals frequently use news of data exposures to launch follow-up scams targeting affected customers. 

Tools like McAfee Identity Monitoring, Identity Theft Restoration and Cleanup, and Personal Data Cleanup help protect you before and after data breaches.  

Other Scam News This Week 

Here are some other pieces of cybersecurity news making headlines this week.

Veterans Warned About Fake Benefits Postcard Scam 

The Department of Veterans Affairs is warning veterans about fraudulent postcards claiming recipients qualify for additional VA benefits, including healthcare, dental coverage, and other payments. 

The postcards often create urgency, encouraging recipients to call within a few days. Once contact is made, scammers attempt to build trust and collect sensitive information such as Social Security numbers, bank account details, and other personal data. 

The VA says veterans should avoid calling numbers listed on unsolicited mailers and should independently verify benefit information through official VA channels. 

This shows a fraudulent postcard sent
Image: Example Fraudulent Notice Courtesy of Shenandoah County Sheriff’s Office

Childcare Providers Targeted by Fake Check Scam 

The Federal Trade Commission has issued an alert to childcare providers about scammers posing as parents seeking urgent childcare services. 

The scam follows a familiar pattern. The supposed parent sends a check in advance that exceeds the expected payment amount and then asks for the difference to be returned through a payment app, wire transfer, gift card, or another method. 

The problem is that the original check is fake. 

Even if the money initially appears in a bank account, the check can later be reversed, leaving the childcare provider responsible for the loss. 

If someone sends a check and asks you to send part of the money back, that’s one of the clearest warning signs of a fake check scam. 

Microsoft Investigates Open Source Supply Chain Attack 

Microsoft temporarily removed dozens of open source repositories hosted on GitHub after discovering malicious code had been inserted into software projects used by developers. 

According to reportsthe malware was designed to steal passwords and other credentials from users working with AI development tools and cloud services. 

Researchers describe the incident as a supply-chain attack, a type of compromise where attackers target trusted software that may later be downloaded by thousands of users. 

Microsoft says it has notified a limited number of potentially affected customers. 

McAfee Safety Tips This Week 

Not every security incident starts with a hacker. 

Sometimes it’s a bug. Sometimes it’s a fake postcard. No matter how a scam starts, here are a few ways to stay safer: 

  • Verify benefit and financial information through official channels. 
  • Be skeptical of urgent requests involving money or personal information. 
  • Avoid downloading software promoted through social media tutorials. 
  • Never send money back to someone who claims they accidentally overpaid you. 
  • Enable multi-factor authentication on important accounts. 
  • Watch for phishing emails following major breach or exposure announcements. 

How McAfee Protects Your Identity and Privacy 

McAfee is built to stop threats before your identity, accounts, or money are compromised.  

McAfee+ Advanced includes multiple layers of protection: 

Scam Detector flags suspicious texts, emails, links, QR codes, and even deepfake videos before you engage   

Secure VPN keeps your data private, especially on public Wi-Fi    

Web Protection helps block risky sites, even if you do accidentally click  

Password Manager doesn’t just help you make unique, strong passwords, it keeps them stored and organized for you  

Device Security helps detect malicious apps or downloads     

Identity Monitoring alerts you if your personal info shows up where it should not, so you can act fast     

Personal Data Cleanup helps remove your information from sites selling it.   

Online Account Cleanup assists in taking down your old, forgotten accounts across the web   

Social Privacy Manager helps you monitor and change privacy settings across your social platforms in just a few clicks   

The common thread across nearly every scam is trust. Scammers count on people acting before they verify. 

We’ll be back next week with more scams making headlines. 

The post ServiceNow Data Exposure and a New VA Scam: This Week in Scams appeared first on McAfee Blog.

  •  

How to Protect Yourself from Doxxing and Lock Down Your Data

Woman gamer confused at computer

You post an opinion about a contentious issue on social media. Within hours, strangers have shared your home address, your employer’s phone number, and photos of your children’s school. Your inbox floods with threats. Someone calls your workplace demanding that you be fired. A crowd shows up outside your house. What started as online speech has become a safety crisis that follows you everywhere. You’ve been doxed.

If you’re looking for real answers about how to prevent doxxing before it happens or how to respond if you’re already facing harassment, this guide provides actionable strategies to lock down your digital footprint and protect your personal information. 

Key Takeaways

  • Protect yourself from doxxing by reducing exposed data on social media, data broker sites, and public records
  • Secure your accounts with strong passwords, multi-factor authentication, and privacy-focused security tools like a VPN or antivirus protection
  • Platform-specific strategies help prevent doxxing on Discord, Twitter, and other high-risk spaces
  • If you’ve been doxxed, act immediately to document everything, remove content, and involve authorities when threats escalate

What Is Doxing?

Doxxing (sometimes spelled doxing) is the act of publicly exposing someone’s personal information online without their consent. Doxxing is often intended to harass, intimidate, or cause real‑world harm. This information can include a home address, phone number, workplace, family details, or other identifying data.

For a foundational understanding of what doxxing is, why it’s escalating, real‑world examples, and how the law treats doxxing, see our full guide on what is doxxing.

How Do People Get Doxxed? 

Your digital footprint is a jigsaw puzzle spread across the internet, with each piece alone being harmless: a tagged photo here, a WHOIS domain record there, a mention of your hometown in an old forum post. Doxers piece together these fragments using open-source intelligence techniques like reverse image searches, username lookups, and metadata analysis.

Much of the information used in doxing also comes from data brokers, which aggregate public records and purchased data sets. Plus, there are information leaks from data breaches: billions of stolen email addresses, passwords, and personal details circulating on dark web forums.

That data can be cross-referenced with your online purchases, domain registrations, avatars, usernames, and even your writing style. Then there’s what you share and what others share about you on social media. In effect, you are leaving a trail of breadcrumbs every time you interact online. 

Taken together, all these pieces create a detailed profile that doxers weaponize. Once they have your information, they post it on social media, anonymous forums, or dedicated harassment sites along with inflammatory language urging others to contact you.

Campaigns are coordinated across platforms, escalating from online harassment to email and text message threats, and sometimes physical confrontations or swatting attempts that put you in immediate danger.

How to Protect Yourself From Doxing

You shouldn’t have to make yourself invisible online, but you can significantly reduce the information available to potential doxers and make yourself a harder target. Here’s what to do:

Lock Down Your Social Media Accounts

Starting with your social media accounts, go through your privacy settings on every platform you use and maximize protection:

Immediate actions:

  • Set all accounts to private or restrict visibility to friends/followers only
  • Hide your friend lists, location data, and tagged photos from public view
  • Remove personal details like phone numbers, email addresses, birth dates, and hometown from your profile
  • Disable location services and strip metadata from photos before posting
  • Turn off check-ins and location tagging features

Audit Your Digital History:

  • Search your own name and review what appears publicly
  • Delete or edit old posts that mention your home address, children’s schools, or exact workplace
  • Ask family and friends not to tag you in posts that reveal your location or personal details
  • Review and untag yourself from photos that expose identifying information

Platform-Specific Settings:

  • Facebook: Restrict who can see your friends list, past posts, and profile information; disable facial recognition; review tags before they appear on your profile
  • Instagram: Make your account private, disable activity status, restrict comments, and carefully review follower requests before accepting
  • Twitter/X: Protect your tweets, disable photo tagging, hide sensitive content behind warnings, and enable two-factor authentication on a separate device
  • Discord: Use a unique username not tied to other accounts, disable DMs from non-friends, never share your Discord tag publicly, and avoid voice chat in public servers where your voice can be recorded

Remove Your Data from People-Finder Data Broker Sites

Data brokers are companies that mine the internet and public records for financial and credit reports, social media accounts, and more. They then sell that data to advertisers, companies, or individuals who may use it to doxx you.

You might be surprised by how much sensitive information is available to anyone who wants it. Data brokers often have contact information including real names, current and former addresses, birth dates, phone numbers, social media profiles, political affiliations, and other information most consider private.

There are two ways you can remove your personal information from data brokers or people-finder sites: manually or with an automated solution

The Manual Approach:

While you can remove your private information from many data broker sites, they tend to make the process tedious and frustrating. You’ll need to:

  • Identify which sites have your information (search for yourself on sites like Whitepages, Spokeo, BeenVerified, PeopleFinder)
  • Submit individual opt-out requests to each site
  • Follow unique removal processes for each broker (some require email verification, others need physical mail)
  • Re-check periodically as your information may reappear

The Automated Solution:

McAfee Personal Data Cleanup makes this process dramatically easier. Enter your name, date of birth, and home address, and we’ll scan it across high-risk data broker sites and help you remove it automatically.

If you plan to employ other automated data broker removal services, verify that they are reputable before handling over your information. 

Secure WHOIS Records and Domain Privacy

If you own a website, your WHOIS record publicly lists your name, address, phone number, and email unless you take action. Use WHOIS privacy protection (also called domain privacy) through your registrar to replace your personal details with the registrar’s contact information, keeping your personal data out of public domain records. Most registrars offer this service for free or a nominal fee.

Fortify Your Account Security

Anyone who gains access to your email or social media accounts through phishing or a data breach could expose your private conversations, documents, and personal details. Protect yourself with robust security measures: 

Use Strong, Unique Passwords:

  • Use passwords with at least 12-16 characters. Avoid personal information like pet names, birthdates, or family members
  • Never reuse passwords across accounts
  • Use a password manager to generate and store complex passwords securely
  • Change passwords immediately if a service you use reports a data breach

Use Multi-Factor Authentication (MFA):

  • Enable MFA on all critical accounts (email, social media, banking, work accounts)
  • Use app-based authenticators (Google Authenticator, Authy) rather than SMS when possible
  • Store backup codes in a secure location separate from your primary device

Be Vigilant against Phishing:

  • Be suspicious of unexpected emails, texts, or messages requesting login credentials
  • Always verify the sender before clicking links or providing information
  • Check URLs carefully. Phishing sites often use slight misspellings
  • Never enter credentials on a site you reached via a link in an email

Secure Your Document Storage

Keep sensitive documents, such as tax records, passport scans, and financial statements, out of easily searchable email folders or cloud storage that might be compromised. If you store them digitally, use encrypted storage with strong access controls.

Use Privacy and Security Tools

No single tool can prevent all doxing, but layered protection makes a big difference. 

Identity Monitoring Services:

Consider using identity monitoring services that alert you when your personal information appears in new data breaches, on the dark web, or elsewhere it shouldn’t be. Early detection will allow you to act before the information is weaponized.

Comprehensive security suite:

A comprehensive security suite such as McAfee+ helps protect your devices from phishing attacks, malicious websites, and malware that could compromise your accounts. 

Virtual Private Network (VPN):

When browsing on public Wi-Fi networks, your data is at greater risk of being intercepted. A virtual private network gives you an additional layer of protection by hiding your IP address and browsing activities when you’re on an unsecured network.

Encrypted Messaging:

For sensitive conversations, use end-to-end encrypted messaging apps like Signal or WhatsApp rather than standard SMS or unencrypted email.

Educate Your Family, Friends, and Colleagues

You might take every precaution, but if your partner posts a photo of your new house with the address or your colleague tags you in a work event with the location, your efforts are undermined. 

Have honest conversations:

  • Explain why you’re cautious about personal information online
  • Share specific examples of what information should stay private
  • Encourage those close to you to adopt similar privacy practices

Set Family Guidelines:

For the digitally active, younger adults and teens in your family who may not fully understand the risks of oversharing, set family guidelines about what can be posted publicly and what should remain offline. 

Workplace Training:

If you work in education, government, or a high-visibility field, suggest brief safety training sessions for staff to recognize and respond to doxing threats.

What to Do if You’ve Already Been Doxxed

If your information is already out there and you’re facing harassment, here’s how to respond quickly and effectively.

1. Assess the immediate situation

If you’re receiving threats, someone is showing up at your home with the intent to harm, or you believe you’re at risk of swatting, contact local law enforcement immediately. Your physical safety comes first. 

2. Document Everything Thoroughly

Create comprehensive evidence:

  • Take screenshots of every post, message, and webpage that shares your information or threatens you. 
  • Take note of URLs, usernames, timestamps, and platform names 
  • Save original messages and emails. Don’t just screenshot; save the actual files.
  • Record any phone calls if legally permitted in your jurisdiction
  • Keep a detailed timeline of events

These pieces of evidence are essential for pursuing legal action, getting content removed from platforms, and demonstrating the severity of the harassment to law enforcement. 

3. Get Your Content Removed

Platform Reporting:

Use the reporting tools on every platform where your private information has been illegally shared. Platforms can be slow to act, but be persistent and keep submitting reports and escalating through support channels. Clearly cite violations of the platform’s terms of service (most prohibit doxxing), and invoke your legal right to have your personal details removed. 

Remove Data from Website Operators:

If your personal information appears on websites or forums, contact the site administrators directly and request removal. Many will comply, especially if the information was posted without your consent.

Remove Data from Search Results:

Google offers a removal request process for certain types of content:

  • Doxing content (name, address, phone number)
  • Non-consensual intimate images
  • Financial information like bank account numbers
  • Government identification numbers

Submit removal requests through Google’s removal request page.

4. File a Police Report

Consider involving authorities in cases involving:

  • Explicit threats of violence
  • Stalking (repeated, unwanted contact that causes fear)
  • Swatting attempts
  • Targeted campaigns that severely disrupt your life
  • Hacking or unauthorized access to your accounts

Prepare for law enforcement:

  • Bring all your documentation (screenshots, timelines, messages)
  • Be prepared to explain what doxxing is and how it’s affecting you
  • If local police aren’t responsive, reach out to specialized cybercrime units at the state or federal level
  • Consider consulting a lawyer familiar with online harassment cases who can advocate on your behalf

5. Seek Support and Expert Guidance

Don’t face this alone. Seek support from your family, trusted friends, and professionals. Crisis communications organizations or reputation management professionals should be able to offer guidance or connect you with legal resources.

Platform-Specific Protection: Discord, X (Twitter), and Beyond

Different platforms present unique doxxing risks. Here’s how to protect yourself on high-risk spaces:

How to Avoid Getting Doxxed on Discord

Discord’s voice chat and community-focused structure create specific vulnerabilities:

Account Security:

  • Use a unique username not connected to other social media accounts or your real name
  • Enable two-factor authentication
  • Never share your email address, phone number, or Discord tag publicly
  • Use Discord’s privacy settings to limit who can DM you (friends only)

Voice Chat Precautions:

  • Be aware that voice chat can be recorded without your knowledge in public servers
  • Avoid discussing personal details, location information, or identifiable stories
  • Consider using voice modulation software for high-risk conversations

Server Safety:

  • Only join servers from trusted communities
  • Be cautious about clicking links in Discord (they can lead to IP-grabbing sites)
  • Report suspicious users immediately to server moderators

How to Prevent Doxxing on Twitter

Twitter’s public nature and engagement-driven algorithm make it a prime target for harassment campaigns:

Profile Protection:

  • Protect your tweets (make account private) if you’re at high risk
  • Remove location information from your profile and tweets
  • Don’t use your full legal name as your display name
  • Disable photo tagging to prevent being tagged in revealing photos

Engagement Strategies:

  • Be cautious about what you share publicly, especially during controversial discussions
  • Don’t share photos that reveal your location, workplace, or home
  • Block aggressive users immediately—don’t engage
  • Report coordinated harassment to Twitter’s support team

Advanced Privacy:

  • Use a separate email address for your Twitter account that doesn’t contain your real name
  • Turn on login verification (two-factor authentication)
  • Regularly review connected apps and revoke access to any you don’t recognize or use

How to Avoid Getting Doxxed as a Creator or Public Profile (TikTok, YouTube, Twitch)

Creators and public‑facing accounts face unique risks because content, schedules, and personal details are often shared at scale:

Account & Identity Separation:

  • Use creator accounts that are completely separate from personal email addresses and phone numbers
  • Never link personal social media accounts in public bios or “about” sections
  • Use business contact emails that don’t contain your real name
  • Enable two‑factor authentication on all creator platforms and connected email accounts

Content & Filming Precautions:

  • Be mindful of what appears in the background of photos and videos (windows, street signs, landmarks)
  • Avoid showing mail, packages, or documents with identifying information
  • Delay posting content shot in real‑time to prevent location tracking
  • Disable automatic location tagging and metadata whenever possible

Livestream & Interaction Safety:

  • Avoid sharing schedules, routines, or future travel plans publicly
  • Use chat moderation tools and trusted moderators during live streams
  • Immediately ban users who ask probing personal questions
  • Be cautious with donation messages or alerts that may reveal personal information

Take Control of Your Digital Footprint Today

Doxxing has become an escalating threat in our increasingly connected digital world. But you’re not powerless. By taking proactive steps to reduce your exposed data, secure your accounts, and understand how to respond if targeted, you significantly reduce your risk and increase your ability to protect yourself and your loved ones.

Start with the basics: tighten your social media settings, remove your information from data broker sites, and secure your accounts with strong passwords and multi-factor authentication. Consider installing identity monitoring services, security software, and privacy features to detect threats early and give you time to respond. McAfee+ can help you stay one step ahead of anyone trying to weaponize your information.

If you’ve been doxxed, document everything, report to platforms persistently, and involve law enforcement when threats escalate. You don’t have to face this alone; support resources and professionals are available to help you through the process.

The post How to Protect Yourself from Doxxing and Lock Down Your Data appeared first on McAfee Blog.

  •  
❌