AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit

Labor Day weekend means sales. And if you spend any time on Facebook, Instagram or TikTok, some of the biggest discounts may find you before you even start shopping.
That convenience comes with a catch: Not every deal in your feed is really from the brand it appears to be.
Scammers can create polished social media ads that impersonate familiar retailers, advertise steep discounts and send shoppers to convincing lookalike websites. According to the Federal Trade Commission, nearly 30% of people who reported losing money to a scam in 2025 said that it started on social media. And the reported losses hit a whopping $2.1 billion last year.
So before a Labor Day “80% off” deal stops your scroll, give it a second look.
A fake shopping ad often starts with something completely ordinary: a product you actually want.
Maybe it’s sneakers from a familiar brand. Patio furniture you’ve been researching. A handbag, grill or appliance marked down for Labor Day.
The ad may use the real company’s logo, product photography and branding. Click it, and the website can look remarkably similar to the retailer’s actual site.
That’s the trick.
This is a form of brand impersonation: A scammer copies the appearance of a company people already know and trust. Instead of convincing you to trust an unfamiliar store, the scammer borrows the reputation of a familiar one.
Sometimes these ads lead to completely fake storefronts. Other times shoppers receive counterfeit products, something dramatically different from what they ordered or nothing at all.
The FTC recently warned consumers specifically about social media ads advertising brand-name products at unusually low prices. And the problem isn’t limited to one platform. A convincing ad can reach you wherever you scroll.

One shopper who shared her story with McAfee learned just how convincing these scams can be.
A few years ago, Jen was scrolling through Facebook when she spotted an ad for the exact Wayfair patio chairs she and her husband had been considering. Normally around $800, the chairs were advertised at 80% off — just $135 with free shipping.
She clicked.
The experience looked enough like Wayfair that she continued with the purchase, even though a few things started to feel strange. A new tab opened when she tried to buy the chairs. The checkout mentioned PayPal even though she was using her credit card. Then she learned the order would be shipping from China and could take six to 12 weeks.
When she checked her credit card, the charge wasn’t from Wayfair. It appeared in Chinese characters.
Weeks later, a package finally arrived.
It wasn’t a set of patio chairs. Inside the small package was a ceiling-fan chain with a cheap ring.
Her credit card company eventually reversed the charges. But the experience illustrates something important about fake shopping ads: You don’t necessarily land on an obviously fake website filled with misspellings and broken images. A scammer’s goal is to make the experience feel normal long enough for you to complete the purchase.
Before buying something you find through Facebook, Instagram, TikTok or another social platform, look for these warning signs:
1. The discount is dramatically better than everywhere else.
A legitimate sale can be generous. But if one ad offers a popular $800 product for $135 while reputable retailers are nowhere close, investigate before buying.
2. The website address doesn’t match the retailer.
A fake site can copy a logo much more easily than it can copy a company’s official domain. Look carefully for extra words, misspellings or unusual endings in the web address.
3. Clicking takes you somewhere unexpected.
Watch for redirects, new tabs or checkout pages on a different domain. A change doesn’t automatically mean fraud, but it’s a reason to verify where you are before entering payment information.
4. The checkout process feels off.
Pay attention when the payment method, merchant name or checkout experience doesn’t match what the site told you to expect.
5. There’s pressure to buy immediately.
Countdown timers and “only two left” warnings can push you to act before checking the seller. Urgency is useful to scammers because it shortens the time you spend thinking.
6. You can’t independently verify the sale.
Open a new browser window or the retailer’s official app and search for the product yourself. If the incredible sale exists only through the social ad, that’s a warning sign.
7. The merchant on your credit card doesn’t match the company you thought you paid.
Check the transaction after buying. An unfamiliar merchant name or unexpected international charge deserves immediate attention.
Here’s a simple safety checklist for Labor Day weekend:
✓ Leave the social app and find the retailer yourself. Don’t let the ad choose your destination.
✓ Compare the price elsewhere. A discount that’s wildly out of line with other retailers deserves extra scrutiny.
✓ Check the URL and merchant name. Make sure you’re dealing with the company you think you’re dealing with.
✓ Use a credit card when possible. And save screenshots, receipts and order confirmations in case you need to dispute the purchase.
Act quickly, but don’t panic.
Save screenshots of the ad, website, receipt and any emails or messages from the seller. Check your credit card or bank statement to see how the transaction appears.
If you believe the purchase was fraudulent, contact your card issuer or financial institution and explain what happened. Ask about disputing the transaction and whether your card information should be replaced.
If you created an account on the fake website and reused a password you use elsewhere, change that password anywhere you’ve used it. Unique passwords matter because a scammer who captures one password may try the same email-and-password combination on other accounts.
You can also report fraudulent ads to the social platform and report the scam to the FTC.
Spotting every fake yourself is getting harder. Scammers can copy legitimate branding, product photos and storefront designs closely enough that a quick visual check isn’t always enough.
McAfee Scam Detector can help identify suspicious links, messages and websites and alert you when something may be a scam. Plus it has social media tools to help detect scams originating from your favorite platforms. That can provide another check when an attractive offer lands in a social message or sends you toward a questionable site.
Web Protection can also help warn you about risky websites as you browse, adding protection at the moment a convincing ad tries to move you away from the social platform and onto a malicious destination.
The goal isn’t to stop shopping the sales you see online. It’s to make sure the store getting your money is the store you intended to pay.
The post Is That TikTok Ad Legit? How to Spot Fake Ads on Social Media During Major Sales Events appeared first on McAfee Blog.

Free airport Wi-Fi can be useful when you’re waiting for a flight. But this week’s biggest security story is a reminder that there are two different ways your information can be exposed when you connect.
One risk happens while your information is traveling across a public network. Another happens after a company collects and stores information about you.
A cyberattack affecting three major UK airports illustrates the difference, and why travelers need protection for both.
Manchester Airports Group, or MAG, confirmed that an unauthorized third party obtained customer information connected with Manchester Airport, London Stansted Airport, and East Midlands Airport.
According to reports, the affected information came from car park, airport lounge, Fast Track bookings, and airport Wi-Fi registrations. MAG says the stolen data includes email addresses, phone numbers, vehicle registration numbers, and postcodes. The company says the affected system did not contain customers’ payment or banking details.
The Telegraph reported that approximately 8.7 million passengers were affected and that more than 90% of the stolen records were email addresses, largely because travelers provide an email address when registering for free airport Wi-Fi. The attackers reportedly demanded a ransom, which MAG declined to pay.
MAG says airport operations and passenger safety were not affected and that it has contained access to the compromised systems.
For travelers, however, the breach creates another concern: what criminals might do with the stolen information next.
An email address alone might not seem particularly sensitive. But combined with a phone number, postcode, vehicle registration, or knowledge that someone has interacted with a particular airport, it becomes more useful to a scammer.
That information can help criminals make phishing emails and texts feel believable.
A message might claim there is a problem with your airport parking reservation, ask you to confirm a Fast Track booking, or say you need to pay an outstanding airport charge. Someone who recently used the airport may be much more inclined to click.
That is one reason breach victims should be especially cautious about unexpected messages that appear connected to the organization involved.
Not from this kind of breach.
A VPN, or virtual private network, encrypts the internet traffic traveling between your device and the VPN service. Think of it as putting your online activity inside a protected tunnel while it crosses a public network.
That matters at airports, hotels, cafés, and other places where many people share the same Wi-Fi. McAfee Secure VPN can encrypt your connection and can be configured to turn on automatically when you join an unsecured network.
But that is different from what happened here.
If you voluntarily give an airport your email address to register for Wi-Fi, that email address may then be stored in the airport operator’s systems. A VPN cannot prevent a later breach of that company’s database.
In short: A VPN helps protect information in transit. It does not control what happens to information you give directly to a company.
Both risks matter.
Before a breach: Share only the information a service genuinely requires. Use strong, unique passwords for online accounts, and use a VPN when connecting to public Wi-Fi.
During a breach: Look for information directly from the affected company rather than relying on messages arriving by email or text. Criminals often take advantage of security incidents by sending fake “account protection” or “verify your information” messages.
After a breach: Watch for unusual emails, calls, texts, and account activity. Be particularly suspicious when someone creates urgency or asks for passwords, verification codes, payment information, or money.
MAG specifically warns that it will not unexpectedly contact customers asking for payment card information, banking details, or passwords.
The breach affected customer information from bookings and airport Wi-Fi registrations.
8.7 million passengers were affected
MAG says banking and payment details were not stored in the affected system.
Stolen contact information can still make phishing and impersonation scams more convincing.
A VPN protects your connection on public Wi-Fi, but it cannot prevent a company from later suffering a database breach.
Be particularly cautious about unexpected airport-related emails and texts following the incident.
Secure VPN helps address the other major risk associated with airport Wi-Fi: someone attempting to monitor your traffic while you use an unsecured network. McAfee Secure VPN encrypts your connection and can automatically activate on unsecured Wi-Fi, helping keep browsing activity and information transmitted from your device private.
Identity Monitoring keeps watch for your personal information associated with breaches, giving you an opportunity to act when exposed information is detected.
And because stolen email addresses and phone numbers can fuel follow-up phishing attempts, Scam Detector can identify suspicious texts, emails, and other QR codes before you act on them.

The broader lesson is layered protection: protect your connection while you’re online, then keep watching for misuse of information that companies already hold.
Hackers claim breach of major data center provider. The ShinyHunters group claims it stole extensive corporate and employee information from U.S. data center company CyrusOne and demanded $13 million.
CyrusOne had not publicly confirmed the hackers’ claims when TechRadar reported the story, so the alleged scale of the breach remains unverified.
Source: TechRadar
Man accused of posing as a 49ers player in $1.3 million romance scam. Federal prosecutors allege that two men defrauded at least 26 women after one portrayed himself online as a wealthy San Francisco 49ers player and the other posed as his financial adviser.
Investigators say fake banking apps and fabricated investment balances helped make the scheme appear legitimate; both defendants are presumed innocent unless proven guilty.
Source: U.S. Department of Justice
Fake sports streams target fans looking for the game. The Better Business Bureau warns that scammers post supposed free streaming links on social media, sometimes tagging real schools or teams, then direct fans to sites designed to collect payment or personal information instead of showing a game.
Go to the team, school, league, or known streaming provider directly rather than trusting a link in a social post — and remember that HTTPS alone does not prove a website is legitimate.
Source: Better Business Bureau
“Once you give your information to a company, you can’t completely control what happens to it,” says McAfee’s Tyler McGee. “But you can limit what you share and take steps to protect yourself if your information is exposed.”
“Only provide what’s needed, use unique passwords and turn on multi-factor authentication where you can. Tools like McAfee’s identity monitoring can also alert you if your information shows up in a known breach. And be extra cautious after a breach,” he says. “Scammers can use exposed information to make messages about a booking, refund or account look much more convincing. If you get one, go directly to the company’s website or app rather than clicking the link.”
✓ Use a VPN on public Wi-Fi. Encrypt your connection before checking email, shopping, banking, or signing into important accounts.
✓ Treat breach-related messages cautiously. Navigate to the company’s official website yourself rather than clicking a link in an unexpected email or text.
✓ Use unique passwords. A password stolen from one service should never unlock another account.
✓ Verify before sending money. Whether someone claims to be an athlete, investment adviser, streaming provider, or familiar company, independently confirm who you are dealing with.
And we’ll be back next week with more cybersecurity news and scam alerts.
The post Airport Wi-Fi Data Breach Exposes Millions of Travelers: This Week in Scams appeared first on McAfee Blog.