<!DOCTYPE html><html data-n-head-ssr="" lang="en-us" data-n-head="%7B%22lang%22:%7B%22ssr%22:%22en-us%22%7D%7D"><head><meta data-n-head="ssr" charset="utf-8"><meta data-n-head="ssr" name="viewport" content="width=device-width, initial-scale=1"><meta data-n-head="ssr" data-hid="description" name="description" content="News, views and insights from the Bitdefender experts"><meta data-n-head="ssr" data-hid="og:title" property="og:title" content="Consumer Insights"><meta data-n-head="ssr" data-hid="og:description" property="og:description" content="News, views and insights from the Bitdefender experts"><meta data-n-head="ssr" data-hid="og:url" property="og:url" content="https://www.bitdefender.com/en-us/blog/hotforsecurity/"><meta data-n-head="ssr" data-hid="og:image" property="og:image" content="https://download.bitdefender.com/resources/themes/draco/images/lite_v2/blog-images/image-hotforsecurity.jpg"><meta data-n-head="ssr" data-hid="og:type" property="og:type" content="website"><meta data-n-head="ssr" data-hid="og:site_name" property="og:site_name" content="Hot for Security"><meta data-n-head="ssr" data-hid="twitter:title" property="twitter:title" content="Consumer Insights"><meta data-n-head="ssr" data-hid="twitter:description" property="twitter:description" content="News, views and insights from the Bitdefender experts"><meta data-n-head="ssr" data-hid="twitter:url" property="twitter:url" content="https://www.bitdefender.com/en-us/blog/hotforsecurity/"><meta data-n-head="ssr" data-hid="twitter:image" property="twitter:image" content="https://download.bitdefender.com/resources/themes/draco/images/lite_v2/blog-images/image-hotforsecurity.jpg"><meta data-n-head="ssr" data-hid="author" name="author" content="Bitdefender"><meta data-n-head="ssr" data-hid="robots" name="robots" content="index,follow"><title>Consumer Insights</title><link data-n-head="ssr" rel="apple-touch-icon" sizes="57x57" href="https://download.bitdefender.com/resources/images/favicon/apple-touch-icon-57x57.png" nonce="DhcnhD3khTMePgXW"><link data-n-head="ssr" rel="apple-touch-icon" sizes="114x114" href="https://download.bitdefender.com/resources/images/favicon/apple-touch-icon-114x114.png" nonce="DhcnhD3khTMePgXW"><link data-n-head="ssr" rel="apple-touch-icon" sizes="72x72" href="https://download.bitdefender.com/resources/images/favicon/apple-touch-icon-72x72.png" nonce="DhcnhD3khTMePgXW"><link data-n-head="ssr" rel="apple-touch-icon" sizes="144x144" href="https://download.bitdefender.com/resources/images/favicon/apple-touch-icon-144x144.png" nonce="DhcnhD3khTMePgXW"><link data-n-head="ssr" rel="apple-touch-icon" sizes="60x60" href="https://download.bitdefender.com/resources/images/favicon/apple-touch-icon-60x60.png" nonce="DhcnhD3khTMePgXW"><link data-n-head="ssr" rel="apple-touch-icon" sizes="120x120" href="https://download.bitdefender.com/resources/images/favicon/apple-touch-icon-120x120.png" nonce="DhcnhD3khTMePgXW"><link data-n-head="ssr" rel="apple-touch-icon" sizes="76x76" href="https://download.bitdefender.com/resources/images/favicon/apple-touch-icon-76x76.png" nonce="DhcnhD3khTMePgXW"><link data-n-head="ssr" rel="apple-touch-icon" sizes="152x152" href="https://download.bitdefender.com/resources/images/favicon/apple-touch-icon-152x152.png" nonce="DhcnhD3khTMePgXW"><link data-n-head="ssr" rel="icon" sizes="196x196" href="https://download.bitdefender.com/resources/images/favicon/favicon-196x196.png" nonce="DhcnhD3khTMePgXW"><link data-n-head="ssr" rel="icon" sizes="96x96" href="https://download.bitdefender.com/resources/images/favicon/favicon-96x96.png" nonce="DhcnhD3khTMePgXW"><link data-n-head="ssr" rel="icon" sizes="32x32" href="https://download.bitdefender.com/resources/images/favicon/favicon-32x32.png" nonce="DhcnhD3khTMePgXW"><link data-n-head="ssr" rel="icon" sizes="16x16" href="https://download.bitdefender.com/resources/images/favicon/favicon-16x16.png" nonce="DhcnhD3khTMePgXW"><link data-n-head="ssr" data-hid="canonical" rel="canonical" href="https://www.bitdefender.com/en-us/blog/hotforsecurity/" nonce="DhcnhD3khTMePgXW"><link data-n-head="ssr" data-hid="hreflang-en-US" rel="alternate" hreflang="en-US" href="https://www.bitdefender.com/en-us/blog/hotforsecurity/" nonce="DhcnhD3khTMePgXW"><link data-n-head="ssr" data-hid="hreflang-en-GB" rel="alternate" hreflang="en-GB" href="https://www.bitdefender.com/en-gb/blog/hotforsecurity/" nonce="DhcnhD3khTMePgXW"><link data-n-head="ssr" data-hid="hreflang-en-AU" rel="alternate" hreflang="en-AU" href="https://www.bitdefender.com/en-au/blog/hotforsecurity/" nonce="DhcnhD3khTMePgXW"><link rel="stylesheet" href="/nuxt/_nuxt/css/6b42635.css" nonce="DhcnhD3khTMePgXW"><link rel="stylesheet" href="/nuxt/_nuxt/css/2bc6b32.css" nonce="DhcnhD3khTMePgXW"><link rel="stylesheet" href="/nuxt/_nuxt/css/7e582bf.css" nonce="DhcnhD3khTMePgXW"><script type="importmap" nonce="DhcnhD3khTMePgXW">{
      "imports": {
        "@repobit/dex-data-layer": "https://esm.sh/@repobit/dex-data-layer@1.6.1",
        "@repobit/dex-launch":     "https://esm.sh/@repobit/dex-launch@2.0.1",
        "@repobit/dex-target":     "https://esm.sh/@repobit/dex-target@2.2.0",
        "@repobit/dex-utils":      "https://esm.sh/@repobit/dex-utils@1.3.0",
        "@tsparticles/all":        "https://esm.sh/@tsparticles/all@3.8.1",
        "@tsparticles/engine":     "https://esm.sh/@tsparticles/engine@3.8.1"
      }
    }</script><script src="/nuxt/_nuxt/db93de1.js" defer="" nonce="DhcnhD3khTMePgXW"></script><script src="/nuxt/_nuxt/48d22ca.js" defer="" nonce="DhcnhD3khTMePgXW"></script><script src="/nuxt/_nuxt/4d47f24.js" defer="" nonce="DhcnhD3khTMePgXW"></script><script src="/nuxt/_nuxt/5952a61.js" defer="" nonce="DhcnhD3khTMePgXW"></script><script src="/nuxt/_nuxt/19a76b3.js" defer="" nonce="DhcnhD3khTMePgXW"></script><script src="/nuxt/_nuxt/28710ea.js" defer="" nonce="DhcnhD3khTMePgXW"></script></head><body><div data-server-rendered="true" id="__nuxt"><!----><div id="__layout"><div><header class="tw-bg-white tw-py-5 lg:tw-bg-black lg:tw-py-4 lg:tw-pt-0"><div class="tw-container tw-flex tw-justify-between lg:tw-hidden"><a href="/" aria-label="Bitdefender" title="Bitdefender" class="tw-block tw-w-[103px] sm:tw-w-[150px] md:tw-w-[180px]"><svg xmlns="http://www.w3.org/2000/svg" width="189.789" height="27.868" viewBox="0 0 189.789 27.868" class="tw-block tw-h-full tw-w-full"><path fill="black" d="M176.528 83.716a8.723 8.723 0 0 0-9.081 9.161c0 5.491 4.036 9.161 9.848 9.161a12.146 12.146 0 0 0 4.652-.865l2.477-4.146-.328-.192a14.073 14.073 0 0 1-6.407 1.694c-3 0-5.6-1.517-5.888-4.141h13.274v-1.2c0-6.067-3.678-9.485-8.536-9.485m-4.739 7.415a4.318 4.318 0 0 1 4.5-4.146c2.724 0 4.394 1.6 4.425 4.146zm95.177-7.4a8.718 8.718 0 0 0-9.081 9.161c0 5.491 4.036 9.161 9.848 9.161a12.086 12.086 0 0 0 4.642-.865l2.487-4.146-.328-.177a14.1 14.1 0 0 1-6.412 1.694c-3 0-5.59-1.517-5.883-4.141h13.264c.575-6.836-3.093-10.688-8.536-10.688m-4.737 7.417a4.314 4.314 0 0 1 4.49-4.146c2.724 0 4.394 1.6 4.43 4.146zm-56.1-7.417a8.723 8.723 0 0 0-9.081 9.161c0 5.491 4.036 9.161 9.848 9.161a12.126 12.126 0 0 0 4.652-.865l2.477-4.146-.333-.177a14.038 14.038 0 0 1-6.4 1.694c-3 0-5.6-1.517-5.888-4.141h13.279c.575-6.836-3.1-10.688-8.546-10.688m-4.732 7.417a4.318 4.318 0 0 1 4.5-4.146c2.719 0 4.394 1.6 4.425 4.146zM116.2 88.039v-.071a5.717 5.717 0 0 0 4.46-5.632c0-4.692-3.991-6.471-7.865-6.471H99.68v.384l1.32 1.122c1.584 1.294 1.786 1.542 1.786 2.71v21.528h9.258c4.853 0 9.722-1.744 9.722-7.346a6.128 6.128 0 0 0-5.55-6.219m-8.864-8.256h3.769c2.553 0 3.34.354 4.112 1.092a2.931 2.931 0 0 1 .858 2.22 2.885 2.885 0 0 1-.883 2.149c-.757.728-1.8 1.082-3.688 1.082h-4.167zm4.208 17.888h-4.208v-7.413h4.389c3.7 0 5.439.945 5.439 3.635 0 3.382-3.269 3.782-5.62 3.782m18.83-19.45a2.8 2.8 0 1 1-2.8-2.629 2.681 2.681 0 0 1 2.825 2.619m-7.336 5.936h6.695V101.6h-4.359V87.872c0-1.441-.081-1.673-1.645-2.882l-.691-.551zm34.65-9.06l1.367.88c1.241.794 1.428 1.173 1.428 2.28v8.089h-.106a7.158 7.158 0 0 0-5.913-2.654c-4.969 0-8.42 4-8.42 9.161s3.234 9.161 8.6 9.161a6.746 6.746 0 0 0 5.989-3.034h.071l.454 2.619h3.678V74.782h-7.147zm-2.174 23a5.234 5.234 0 1 1 5.121-5.233 5.059 5.059 0 0 1-5.121 5.233m92.473-23l.605.4c2.1 1.33 2.361 1.714 2.361 3.984v6.89h-.111a7.166 7.166 0 0 0-5.913-2.654c-4.969 0-8.415 4-8.415 9.161s3.229 9.161 8.577 9.161a6.734 6.734 0 0 0 5.989-3.034h.076l.459 2.619h3.678V74.782h-7.315zm-2.018 23a5.234 5.234 0 1 1 5.116-5.233 5.059 5.059 0 0 1-5.116 5.237m43.449-14.156v4.216a8.7 8.7 0 0 0-2.1-.329 4.391 4.391 0 0 0-4.682 4.4v9.343h-4.349V88.706c0-2.194-.116-2.528-1.887-3.645l-1.095-.723v-.192h7.341v2.771h.076a5.549 5.549 0 0 1 5.151-3.2 5.715 5.715 0 0 1 1.559.253m-96.673.11h4.036v3.72H192.8v13.8h-4.369V89.3c0-1.461-.293-1.785-2.018-3.155l-2.22-1.81v-.255h4.243V80.9c0-4.737 3.083-7.746 9.752-6.411l1.009 3.7-.212.172c-3.486-1.375-6.185-.506-6.185 2.528zm41.239 6.5v11.02h-4.354v-9.709c0-1.921-.5-4.247-3.532-4.247-2.866 0-3.991 2.108-3.991 4.434v9.522h-4.349V88.7c0-2.194-.116-2.528-1.887-3.645l-1.059-.723v-.192h7.114v2.66h.071a6.742 6.742 0 0 1 5.55-3.094c4.112 0 6.483 2.821 6.483 6.866m-89.345 7.523l.141.091s-2.164 3.468-2.159 3.468c-3.532.966-7.537-.061-7.537-5.764v-7.078c0-1.127-.182-1.067-2.623-3.084l-1.579-1.37v-.207h4.228L136.8 79.1h2.76v5.056h4.657v3.7h-4.657v7.912c0 3.15 2.154 3.226 5.186 2.326" transform="translate(-99.68 -74.171)"></path></svg></a> <button aria-label="Toggle menu" class="tw-block"><span class="tw-block tw-h-[3px] tw-w-[25px] tw-bg-black data-[menu-active=true]:tw-translate-y-[8px] data-[menu-active=true]:-tw-rotate-45"></span> <span class="tw-my-[5px] tw-block tw-h-[3px] tw-w-[25px] tw-bg-black data-[menu-active=true]:tw-invisible"></span> <span class="tw-block tw-h-[3px] tw-w-[25px] tw-bg-black data-[menu-active=true]:-tw-translate-y-[8px] data-[menu-active=true]:tw-rotate-45"></span></button></div> <div class="tw-hidden tw-flex-wrap data-[menu-active=true]:tw-flex lg:tw-block lg:data-[menu-active=true]:tw-block"><div class="tw-order-last tw-w-full tw-border-[#3c3c3c] lg:tw-border-b-2"><div class="tw-container"><ul class="tw-block tw-justify-end lg:tw-flex"><li class="tw-relative"><a aria-label="Company" title="Company" href="/en-us/company/" data-link="/en-us/company/" class="tw-relative tw-block tw-border-b-[1px] tw-border-[#000]/[0.2] tw-py-2.5 tw-font-medium before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:-tw-left-4 before:tw-m-auto before:tw-hidden before:tw-h-4 before:tw-w-0.5 before:tw-bg-[#616161] after:tw-absolute after:tw-bottom-0 after:tw-block after:tw-h-1 after:tw-w-full after:tw-origin-right after:tw-scale-x-0 after:tw-bg-[#006eff] after:tw-transition-transform after:tw-duration-300 hover:after:tw-origin-left lg:tw-mx-4 lg:tw-border-0 lg:tw-py-3 lg:tw-text-xs lg:tw-uppercase lg:tw-tracking-widest lg:tw-text-[#dedede] lg:before:tw-block lg:hover:after:tw-scale-x-100">Company
                  </a> <!----></li><li class="tw-relative"><a aria-label="Blog" title="Blog" href="/en-us/blog/" data-link="/en-us/blog/" class="tw-relative tw-block tw-border-b-[1px] tw-border-[#000]/[0.2] tw-py-2.5 tw-font-medium before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:-tw-left-4 before:tw-m-auto before:tw-hidden before:tw-h-4 before:tw-w-0.5 before:tw-bg-[#616161] after:tw-absolute after:tw-bottom-0 after:tw-block after:tw-h-1 after:tw-w-full after:tw-origin-right after:tw-scale-x-0 after:tw-bg-[#006eff] after:tw-transition-transform after:tw-duration-300 hover:after:tw-origin-left lg:tw-mx-4 lg:tw-border-0 lg:tw-py-3 lg:tw-text-xs lg:tw-uppercase lg:tw-tracking-widest lg:tw-text-[#dedede] lg:before:tw-block lg:hover:after:tw-scale-x-100">Blog
                  </a> <!----></li></ul></div></div> <div class="tw-container tw-mt-5 lg:tw-mt-3.5 lg:tw-flex xl:tw-mt-5"><a href="/" aria-label="Bitdefender" title="Bitdefender" class="tw-mr-3 tw-hidden tw-h-[30px] tw-w-[180px] lg:tw-block"><svg xmlns="http://www.w3.org/2000/svg" width="189.789" height="27.868" viewBox="0 0 189.789 27.868" class="tw-block tw-h-full tw-w-full"><path fill="#fff" d="M176.528 83.716a8.723 8.723 0 0 0-9.081 9.161c0 5.491 4.036 9.161 9.848 9.161a12.146 12.146 0 0 0 4.652-.865l2.477-4.146-.328-.192a14.073 14.073 0 0 1-6.407 1.694c-3 0-5.6-1.517-5.888-4.141h13.274v-1.2c0-6.067-3.678-9.485-8.536-9.485m-4.739 7.415a4.318 4.318 0 0 1 4.5-4.146c2.724 0 4.394 1.6 4.425 4.146zm95.177-7.4a8.718 8.718 0 0 0-9.081 9.161c0 5.491 4.036 9.161 9.848 9.161a12.086 12.086 0 0 0 4.642-.865l2.487-4.146-.328-.177a14.1 14.1 0 0 1-6.412 1.694c-3 0-5.59-1.517-5.883-4.141h13.264c.575-6.836-3.093-10.688-8.536-10.688m-4.737 7.417a4.314 4.314 0 0 1 4.49-4.146c2.724 0 4.394 1.6 4.43 4.146zm-56.1-7.417a8.723 8.723 0 0 0-9.081 9.161c0 5.491 4.036 9.161 9.848 9.161a12.126 12.126 0 0 0 4.652-.865l2.477-4.146-.333-.177a14.038 14.038 0 0 1-6.4 1.694c-3 0-5.6-1.517-5.888-4.141h13.279c.575-6.836-3.1-10.688-8.546-10.688m-4.732 7.417a4.318 4.318 0 0 1 4.5-4.146c2.719 0 4.394 1.6 4.425 4.146zM116.2 88.039v-.071a5.717 5.717 0 0 0 4.46-5.632c0-4.692-3.991-6.471-7.865-6.471H99.68v.384l1.32 1.122c1.584 1.294 1.786 1.542 1.786 2.71v21.528h9.258c4.853 0 9.722-1.744 9.722-7.346a6.128 6.128 0 0 0-5.55-6.219m-8.864-8.256h3.769c2.553 0 3.34.354 4.112 1.092a2.931 2.931 0 0 1 .858 2.22 2.885 2.885 0 0 1-.883 2.149c-.757.728-1.8 1.082-3.688 1.082h-4.167zm4.208 17.888h-4.208v-7.413h4.389c3.7 0 5.439.945 5.439 3.635 0 3.382-3.269 3.782-5.62 3.782m18.83-19.45a2.8 2.8 0 1 1-2.8-2.629 2.681 2.681 0 0 1 2.825 2.619m-7.336 5.936h6.695V101.6h-4.359V87.872c0-1.441-.081-1.673-1.645-2.882l-.691-.551zm34.65-9.06l1.367.88c1.241.794 1.428 1.173 1.428 2.28v8.089h-.106a7.158 7.158 0 0 0-5.913-2.654c-4.969 0-8.42 4-8.42 9.161s3.234 9.161 8.6 9.161a6.746 6.746 0 0 0 5.989-3.034h.071l.454 2.619h3.678V74.782h-7.147zm-2.174 23a5.234 5.234 0 1 1 5.121-5.233 5.059 5.059 0 0 1-5.121 5.233m92.473-23l.605.4c2.1 1.33 2.361 1.714 2.361 3.984v6.89h-.111a7.166 7.166 0 0 0-5.913-2.654c-4.969 0-8.415 4-8.415 9.161s3.229 9.161 8.577 9.161a6.734 6.734 0 0 0 5.989-3.034h.076l.459 2.619h3.678V74.782h-7.315zm-2.018 23a5.234 5.234 0 1 1 5.116-5.233 5.059 5.059 0 0 1-5.116 5.237m43.449-14.156v4.216a8.7 8.7 0 0 0-2.1-.329 4.391 4.391 0 0 0-4.682 4.4v9.343h-4.349V88.706c0-2.194-.116-2.528-1.887-3.645l-1.095-.723v-.192h7.341v2.771h.076a5.549 5.549 0 0 1 5.151-3.2 5.715 5.715 0 0 1 1.559.253m-96.673.11h4.036v3.72H192.8v13.8h-4.369V89.3c0-1.461-.293-1.785-2.018-3.155l-2.22-1.81v-.255h4.243V80.9c0-4.737 3.083-7.746 9.752-6.411l1.009 3.7-.212.172c-3.486-1.375-6.185-.506-6.185 2.528zm41.239 6.5v11.02h-4.354v-9.709c0-1.921-.5-4.247-3.532-4.247-2.866 0-3.991 2.108-3.991 4.434v9.522h-4.349V88.7c0-2.194-.116-2.528-1.887-3.645l-1.059-.723v-.192h7.114v2.66h.071a6.742 6.742 0 0 1 5.55-3.094c4.112 0 6.483 2.821 6.483 6.866m-89.345 7.523l.141.091s-2.164 3.468-2.159 3.468c-3.532.966-7.537-.061-7.537-5.764v-7.078c0-1.127-.182-1.067-2.623-3.084l-1.579-1.37v-.207h4.228L136.8 79.1h2.76v5.056h4.657v3.7h-4.657v7.912c0 3.15 2.154 3.226 5.186 2.326" transform="translate(-99.68 -74.171)"></path></svg></a> <a href="/en-us/consumer/" onclick="s_objectID='For Home';" aria-label="For Home" title="For Home" class="tw-relative tw-block tw-border-b-[1px] tw-border-[#000]/[0.2] tw-py-2.5 tw-font-medium after:tw-absolute after:tw-bottom-0 after:tw-left-0 after:tw-block after:tw-h-1 after:tw-w-full after:tw-origin-right after:tw-scale-x-0 after:tw-bg-[#006eff] after:tw-transition-transform after:tw-duration-300 hover:after:tw-origin-left lg:tw-border-0 lg:tw-px-5 lg:tw-pt-2 lg:tw-pb-4 lg:tw-text-[#dedede] lg:hover:after:tw-scale-x-100">For Home</a><a href="/en-us/business/" onclick="s_objectID='For Business';" aria-label="For Business" title="For Business" class="tw-relative tw-block tw-border-b-[1px] tw-border-[#000]/[0.2] tw-py-2.5 tw-font-medium after:tw-absolute after:tw-bottom-0 after:tw-left-0 after:tw-block after:tw-h-1 after:tw-w-full after:tw-origin-right after:tw-scale-x-0 after:tw-bg-[#006eff] after:tw-transition-transform after:tw-duration-300 hover:after:tw-origin-left lg:tw-border-0 lg:tw-px-5 lg:tw-pt-2 lg:tw-pb-4 lg:tw-text-[#dedede] lg:hover:after:tw-scale-x-100">For Business</a><a href="/en-us/partners/" onclick="s_objectID='For Partners';" aria-label="For Partners" title="For Partners" class="tw-relative tw-block tw-border-b-[1px] tw-border-[#000]/[0.2] tw-py-2.5 tw-font-medium after:tw-absolute after:tw-bottom-0 after:tw-left-0 after:tw-block after:tw-h-1 after:tw-w-full after:tw-origin-right after:tw-scale-x-0 after:tw-bg-[#006eff] after:tw-transition-transform after:tw-duration-300 hover:after:tw-origin-left lg:tw-border-0 lg:tw-px-5 lg:tw-pt-2 lg:tw-pb-4 lg:tw-text-[#dedede] lg:hover:after:tw-scale-x-100">For Partners</a></div></div></header> <div><nav data-fetch-key="BlogMenu:0" class="tw-bg-black tw-py-4"><div class="tw-container tw-flex tw-space-x-7"><div class="tw-flex tw-w-6/12 tw-items-center sm:tw-w-8/12"><a href="/en-us/blog/hotforsecurity/" aria-current="page" title="Consumer Insights" class="tw-relative tw-mr-4 tw-text-center tw-text-xs tw-font-bold tw-uppercase tw-text-[#7e8b9f] after:tw-absolute after:tw-left-0 after:tw--bottom-2 after:tw-block after:tw-h-[1px] after:tw-w-0 after:tw-bg-[#7e8b9f] after:tw-transition-all after:tw-duration-300 after:tw-ease-in-out hover:after:tw-w-full sm:tw-text-left md:tw-text-sm router-link-exact-active router-link-active">Consumer Insights
            </a><a href="/en-us/blog/labs/" title="Labs" class="tw-relative tw-mr-4 tw-text-center tw-text-xs tw-font-bold tw-uppercase tw-text-[#7e8b9f] after:tw-absolute after:tw-left-0 after:tw--bottom-2 after:tw-block after:tw-h-[1px] after:tw-w-0 after:tw-bg-[#7e8b9f] after:tw-transition-all after:tw-duration-300 after:tw-ease-in-out hover:after:tw-w-full sm:tw-text-left md:tw-text-sm">Labs
            </a><a href="/en-us/blog/businessinsights/" title="Business Insights" class="tw-relative tw-mr-4 tw-text-center tw-text-xs tw-font-bold tw-uppercase tw-text-[#7e8b9f] after:tw-absolute after:tw-left-0 after:tw--bottom-2 after:tw-block after:tw-h-[1px] after:tw-w-0 after:tw-bg-[#7e8b9f] after:tw-transition-all after:tw-duration-300 after:tw-ease-in-out hover:after:tw-w-full sm:tw-text-left md:tw-text-sm">Business Insights
            </a><!----></div> <div class="tw-flex tw-w-6/12 tw-items-center tw-justify-end sm:tw-w-4/12"><a aria-label="show rss feed" title="show rss feed" href="/nuxt/api/en-us/rss/hotforsecurity/" target="_blank" class="tw-w-5 tw-text-white tw-mr-4"><svg width="20" aria-hidden="true" focusable="false" data-prefix="far" data-icon="rss-square" role="img" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 448 512" class="svg-inline--fa fa-rss-square fa-w-14"><path fill="currentColor" d="M400 32H48C21.49 32 0 53.49 0 80v352c0 26.51 21.49 48 48 48h352c26.51 0 48-21.49 48-48V80c0-26.51-21.49-48-48-48zm-6 400H54a6 6 0 0 1-6-6V86a6 6 0 0 1 6-6h340a6 6 0 0 1 6 6v340a6 6 0 0 1-6 6zm-218-88c0 22.091-17.909 40-40 40s-40-17.909-40-40 17.909-40 40-40 40 17.909 40 40zm93.566 30.405c-4.774-88.343-75.534-159.193-163.971-163.971-5.22-.282-9.595 3.912-9.595 9.14v27.468c0 4.808 3.709 8.841 8.507 9.153 63.904 4.162 115.127 55.258 119.298 119.298.313 4.798 4.345 8.507 9.153 8.507h27.468c5.228 0 9.422-4.375 9.14-9.595zm82.428.165c-4.796-133.612-112.3-241.744-246.564-246.564-5.159-.185-9.43 3.983-9.43 9.146v27.467c0 4.929 3.906 8.94 8.83 9.142 109.245 4.479 196.93 92.181 201.408 201.408.202 4.925 4.213 8.83 9.142 8.83h27.467c5.164.001 9.332-4.27 9.147-9.429z"></path></svg></a> <button aria-label="Open bookmarks list" class="tw-relative tw-text-xl tw-mr-4"><svg xmlns="http://www.w3.org/2000/svg" width="20" viewBox="0 0 50.9 52.1" overflow="visible" class="tw-w-[1em] tw-h-[1em]"><path d="M3.4 2.5h34.3c.4 0 .7.4.7.8v45.2c0 .6-.6.9-.9.5L21.1 37.3c-.4-.3-.8-.3-1.2 0L3.4 49.5c-.4.4-.9.1-.9-.5l.2-45.7c0-.4.3-.8.7-.8z" fill="#fff" stroke="#adb5b9" stroke-width="5" stroke-miterlimit="10"></path></svg> <!----> <!----></button> <button aria-label="open search bar" class="tw-text-white tw-block tw-text-2xl"><svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 58.1 59.4" width="22" overflow="visible" class="tw-w-[1em] tw-h-[1em] icon-search"><circle cx="23" cy="23" r="20.5" class="icon-search-inner"></circle> <path d="M39.5 35.2l16.1 11.7" class="icon-search-inner"></path></svg></button> <!----></div></div></nav> <div></div> <header class="header tw-relative tw-bg-black tw-bg-cover tw-bg-center tw-py-12 after:tw-absolute after:tw-left-0 after:tw-top-0 after:tw-z-10 after:tw-block after:tw-h-full after:tw-w-full after:tw-bg-gradient-to-r after:tw-from-black after:tw-via-black/[0.8] after:tw-to-black/0 after:tw-opacity-90 lg:after:tw-w-3/4 xl:tw-pt-0" style="--bg-image-xl:url('https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w2000/2026/08/authorized-unauthorized-fraud.jpg');--bg-image-l:url('https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w1000/2026/08/authorized-unauthorized-fraud.jpg');--bg-image-m:url('https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w600/2026/08/authorized-unauthorized-fraud.jpg');--bg-image-s:url('https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w300/2026/08/authorized-unauthorized-fraud.jpg');" data-v-0e4cfc3c=""><div class="tw-container tw-relative tw-z-20 tw-text-white xl:tw-py-12" data-v-0e4cfc3c=""><div class="tw-my-6 tw-w-full md:tw-w-10/12 lg:tw-w-7/12" data-v-0e4cfc3c=""><!----> <h1 class="tw-mb-4 tw-text-xl tw-font-bold" data-v-0e4cfc3c="">Consumer Insights</h1> <div class="tw-mb-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-xs tw-font-bold tw-uppercase" style="color:#006DFF;" data-v-0e4cfc3c=""><a href="/en-us/blog/hotforsecurity/tag/finance" title="Finance" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Finance
      </a><a href="/en-us/blog/hotforsecurity/tag/scam" title="Scam" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Scam
      </a><!----> <!----></div> <a href="/en-us/blog/hotforsecurity/authorized-vs-unauthorized-fraud" title="Authorized vs unauthorized fraud and what it means for your refund rights" class="tw-block" data-v-0e4cfc3c=""><h2 class="md:tYeahw-text-3xl tw-text-2xl tw-font-bold md:tw-leading-snug lg:tw-text-4xl lg:tw-leading-snug xl:tw-text-5xl xl:tw-leading-tight" data-v-0e4cfc3c="">
               Authorized vs unauthorized fraud and what it means for your refund rights
            </h2></a> <div class="tw-mt-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-sm" data-v-0e4cfc3c=""><a href="/en-us/blog/hotforsecurity/author/vlad" title="Vlad CONSTANTINESCU" class="tw-overflow-hidden tw-rounded-full tw-h-11 tw-w-11"><img width="50" height="50" alt="Vlad CONSTANTINESCU" title="Vlad CONSTANTINESCU" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w100/2021/12/Vlad.jpg" class="tw-h-full tw-w-full tw-object-cover"></a> <div class="tw-pl-2"><div class="tw-flex tw-flex-wrap tw-gap-x-2"><a href="/en-us/blog/hotforsecurity/author/vlad" title="Vlad CONSTANTINESCU" class="tw-py-1 tw-mr-1.5 last:tw-mr-0">Vlad CONSTANTINESCU
         </a></div> <p style="color:#41485e;">
         August 18, 2026
      </p></div> <div class="tw-relative tw-ml-5 tw-flex tw-items-center before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959] sm:first:before:tw-hidden"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 23 23" overflow="visible" class="tw-text-[#595959]"><path d="M11.5 2c5.2 0 9.5 4.3 9.5 9.5S16.7 21 11.5 21 2 16.7 2 11.5 6.3 2 11.5 2m0-2C5.1 0 0 5.1 0 11.5S5.1 23 11.5 23 23 17.9 23 11.5 17.9 0 11.5 0z" style="fill: currentColor"></path> <path d="M11.5 6.6v4.5M12 12.1l3.5 3.2" class="st0"></path></svg> <span class="tw-pl-2">
             5 min read
         </span></div> <!----> <div class="tw-py-1 tw-relative tw-ml-5 before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959]"><button aria-label="Add to bookmark" class="tw-block tw-text-base"><svg xmlns="http://www.w3.org/2000/svg" width="20" viewBox="0 0 50.9 52.1" overflow="visible" class="tw-w-[1em] tw-h-[1em]"><path d="M3.4 2.5h34.3c.4 0 .7.4.7.8v45.2c0 .6-.6.9-.9.5L21.1 37.3c-.4-.3-.8-.3-1.2 0L3.4 49.5c-.4.4-.9.1-.9-.5l.2-45.7c0-.4.3-.8.7-.8z" fill="#fff" stroke="#adb5b9" stroke-width="5" stroke-miterlimit="10"></path></svg> <!----></button></div></div> <h3 class="tw-relative tw-mt-12 tw-mb-6 tw-inline-block tw-pr-6 tw-text-lg tw-text-[#41485e] after:tw-absolute after:tw--right-24 after:tw-top-0 after:tw-bottom-0 after:tw-m-auto after:tw-block after:tw-h-2.5 after:tw-w-24 after:tw-bg-current" data-v-0e4cfc3c="">Top Stories</h3> <div class="tw-mb-4 last:tw-mb-0" data-v-0e4cfc3c=""><div class="tw-mb-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-xs tw-font-bold tw-uppercase" style="color:#006DFF;" data-v-0e4cfc3c=""><a href="/en-us/blog/hotforsecurity/tag/finance" title="Finance" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Finance
      </a><!----><!----> <!----></div> <a href="/en-us/blog/hotforsecurity/empty-bank-account-valuable-cybercriminals" title="Why an Empty Bank Account Is Valuable to Cybercriminals" class="tw-block tw-text-lg tw-font-bold" data-v-0e4cfc3c="">Why an Empty Bank Account Is Valuable to Cybercriminals</a></div><div class="tw-mb-4 last:tw-mb-0" data-v-0e4cfc3c=""><div class="tw-mb-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-xs tw-font-bold tw-uppercase" style="color:#006DFF;" data-v-0e4cfc3c=""><a href="/en-us/blog/hotforsecurity/tag/scam" title="Scam" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Scam
      </a><!----><!----> <!----></div> <a href="/en-us/blog/hotforsecurity/bank-scam-fraudsters-come-to-your-home" title="Police Warning: Your bank is not coming to your house for your card" class="tw-block tw-text-lg tw-font-bold" data-v-0e4cfc3c="">Police Warning: Your bank is not coming to your house for your card</a></div><div class="tw-mb-4 last:tw-mb-0" data-v-0e4cfc3c=""><div class="tw-mb-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-xs tw-font-bold tw-uppercase" style="color:#006DFF;" data-v-0e4cfc3c=""><a href="/en-us/blog/hotforsecurity/tag/scam" title="Scam" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Scam
      </a><!----><!----> <!----></div> <a href="/en-us/blog/hotforsecurity/steam-gift-scams-why-you-should-never-accept-one-from-an-unknown-user" title="Steam gift scams: Why you should never accept one from an unknown user" class="tw-block tw-text-lg tw-font-bold" data-v-0e4cfc3c="">Steam gift scams: Why you should never accept one from an unknown user</a></div></div></div></header> <section class="tw-overflow-hidden tw-bg-[#eff0f1] tw-py-12"><div class="tw-container tw-mb-6 tw-flex tw-w-full tw-flex-wrap"><div class="tw-w-1/2"><h2><span class="tw-block tw-text-sm tw-font-medium tw-uppercase lg:tw-text-sm" style="color:#696969;">
      latest
   </span> <span class="tw-block tw-text-xl tw-font-bold tw-uppercase lg:tw-text-2xl tw-text-black">
      Industry News
   </span></h2></div> <div class="tw-w-1/2 tw-text-right"><a href="/en-us/blog/hotforsecurity/tag/industry-news" class="tw-inline-block tw-cursor-pointer tw-border tw-border-[#d4d7d9] tw-bg-white tw-p-4 tw-text-sm tw-font-bold tw-text-[#265fc9] hover:tw-bg-[#d4d7d9] sm:tw-py-4 sm:tw-px-10">View all posts</a></div></div> <div class="tw-container md:tw-flex md:tw-space-x-7"><div class="tw-mb-4 tw-w-full md:tw-mb-12 md:tw-w-1/3"><div class="tw-mb-4 tw-flex tw-gap-4 md:tw-mb-0 md:tw-block"><a href="/en-us/blog/hotforsecurity/russian-hackers-google-whatsapp-phishing" title="Russian-linked hackers turn Google and WhatsApp logins into phishing traps" class="tw-block tw-w-1/4 md:tw-mb-3 md:tw-w-full"><img width="400" height="300" alt="Russian-linked hackers turn Google and WhatsApp logins into phishing traps" title="Russian-linked hackers turn Google and WhatsApp logins into phishing traps" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w600/2026/08/dimitri-karastelev-ynJaWgrwSlM-unsplash--1-.jpg" class="tw-h-36 tw-w-full tw-object-contain tw-object-top md:tw-object-cover lg:tw-h-52"></a> <div class="tw-w-3/4 md:tw-w-full"><div class="tw-mb-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-xs tw-font-bold tw-uppercase" style="color:#0065EB;"><a href="/en-us/blog/hotforsecurity/tag/industry-news" title="Industry News" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Industry News
      </a><!----> <!----></div> <a href="/en-us/blog/hotforsecurity/russian-hackers-google-whatsapp-phishing" title="Russian-linked hackers turn Google and WhatsApp logins into phishing traps" class="tw-text-lg tw-font-bold tw-leading-tight tw-line-clamp-2 lg:tw-text-xl xl:tw-text-2xl"><h3>Russian-linked hackers turn Google and WhatsApp logins into phishing traps</h3></a> <div><div class="tw-mt-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-sm"><a href="/en-us/blog/hotforsecurity/author/vlad" title="Vlad CONSTANTINESCU" class="tw-overflow-hidden tw-rounded-full tw-h-11 tw-w-11"><img width="50" height="50" alt="Vlad CONSTANTINESCU" title="Vlad CONSTANTINESCU" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w100/2021/12/Vlad.jpg" class="tw-h-full tw-w-full tw-object-cover"></a> <div class="tw-pl-2"><div class="tw-flex tw-flex-wrap tw-gap-x-2"><a href="/en-us/blog/hotforsecurity/author/vlad" title="Vlad CONSTANTINESCU" class="tw-py-1 tw-mr-1.5 last:tw-mr-0">Vlad CONSTANTINESCU
         </a></div> <p style="color:#6B6B6B;">
         August 21, 2026
      </p></div> <div class="tw-relative tw-ml-5 tw-flex tw-items-center before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959] sm:first:before:tw-hidden"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 23 23" overflow="visible" class="tw-text-[#595959]"><path d="M11.5 2c5.2 0 9.5 4.3 9.5 9.5S16.7 21 11.5 21 2 16.7 2 11.5 6.3 2 11.5 2m0-2C5.1 0 0 5.1 0 11.5S5.1 23 11.5 23 23 17.9 23 11.5 17.9 0 11.5 0z" style="fill: currentColor"></path> <path d="M11.5 6.6v4.5M12 12.1l3.5 3.2" class="st0"></path></svg> <span class="tw-pl-2">
             2 min read
         </span></div> <!----> <div class="tw-py-1 tw-relative tw-ml-5 before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959]"><button aria-label="Add to bookmark" class="tw-block tw-text-base"><svg xmlns="http://www.w3.org/2000/svg" width="20" viewBox="0 0 50.9 52.1" overflow="visible" class="tw-w-[1em] tw-h-[1em]"><path d="M3.4 2.5h34.3c.4 0 .7.4.7.8v45.2c0 .6-.6.9-.9.5L21.1 37.3c-.4-.3-.8-.3-1.2 0L3.4 49.5c-.4.4-.9.1-.9-.5l.2-45.7c0-.4.3-.8.7-.8z" fill="#fff" stroke="#adb5b9" stroke-width="5" stroke-miterlimit="10"></path></svg> <!----></button></div></div></div></div></div></div><div class="tw-mb-4 tw-w-full md:tw-mb-12 md:tw-w-1/3"><div class="tw-mb-4 tw-flex tw-gap-4 md:tw-mb-0 md:tw-block"><a href="/en-us/blog/hotforsecurity/sakura-internet-breach-1-36-million-accounts" title="Sakura Internet hack may affect 1.36 million accounts" class="tw-block tw-w-1/4 md:tw-mb-3 md:tw-w-full"><img width="400" height="300" alt="Sakura Internet hack may affect 1.36 million accounts" title="Sakura Internet hack may affect 1.36 million accounts" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w600/2026/08/david-brooke-martin-lFTtQqVfx6g-unsplash.jpg" class="tw-h-36 tw-w-full tw-object-contain tw-object-top md:tw-object-cover lg:tw-h-52"></a> <div class="tw-w-3/4 md:tw-w-full"><div class="tw-mb-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-xs tw-font-bold tw-uppercase" style="color:#0065EB;"><a href="/en-us/blog/hotforsecurity/tag/industry-news" title="Industry News" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Industry News
      </a><a href="/en-us/blog/hotforsecurity/tag/data-breach" title="Data Breach" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Data Breach
      </a><!----> <!----></div> <a href="/en-us/blog/hotforsecurity/sakura-internet-breach-1-36-million-accounts" title="Sakura Internet hack may affect 1.36 million accounts" class="tw-text-lg tw-font-bold tw-leading-tight tw-line-clamp-2 lg:tw-text-xl xl:tw-text-2xl"><h3>Sakura Internet hack may affect 1.36 million accounts</h3></a> <div><div class="tw-mt-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-sm"><a href="/en-us/blog/hotforsecurity/author/vlad" title="Vlad CONSTANTINESCU" class="tw-overflow-hidden tw-rounded-full tw-h-11 tw-w-11"><img width="50" height="50" alt="Vlad CONSTANTINESCU" title="Vlad CONSTANTINESCU" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w100/2021/12/Vlad.jpg" class="tw-h-full tw-w-full tw-object-cover"></a> <div class="tw-pl-2"><div class="tw-flex tw-flex-wrap tw-gap-x-2"><a href="/en-us/blog/hotforsecurity/author/vlad" title="Vlad CONSTANTINESCU" class="tw-py-1 tw-mr-1.5 last:tw-mr-0">Vlad CONSTANTINESCU
         </a></div> <p style="color:#6B6B6B;">
         August 20, 2026
      </p></div> <div class="tw-relative tw-ml-5 tw-flex tw-items-center before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959] sm:first:before:tw-hidden"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 23 23" overflow="visible" class="tw-text-[#595959]"><path d="M11.5 2c5.2 0 9.5 4.3 9.5 9.5S16.7 21 11.5 21 2 16.7 2 11.5 6.3 2 11.5 2m0-2C5.1 0 0 5.1 0 11.5S5.1 23 11.5 23 23 17.9 23 11.5 17.9 0 11.5 0z" style="fill: currentColor"></path> <path d="M11.5 6.6v4.5M12 12.1l3.5 3.2" class="st0"></path></svg> <span class="tw-pl-2">
             2 min read
         </span></div> <!----> <div class="tw-py-1 tw-relative tw-ml-5 before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959]"><button aria-label="Add to bookmark" class="tw-block tw-text-base"><svg xmlns="http://www.w3.org/2000/svg" width="20" viewBox="0 0 50.9 52.1" overflow="visible" class="tw-w-[1em] tw-h-[1em]"><path d="M3.4 2.5h34.3c.4 0 .7.4.7.8v45.2c0 .6-.6.9-.9.5L21.1 37.3c-.4-.3-.8-.3-1.2 0L3.4 49.5c-.4.4-.9.1-.9-.5l.2-45.7c0-.4.3-.8.7-.8z" fill="#fff" stroke="#adb5b9" stroke-width="5" stroke-miterlimit="10"></path></svg> <!----></button></div></div></div></div></div></div><div class="tw-mb-4 tw-w-full md:tw-mb-12 md:tw-w-1/3"><div class="tw-mb-4 tw-flex tw-gap-4 md:tw-mb-0 md:tw-block"><a href="/en-us/blog/hotforsecurity/update-iphone-mac-image-flaw-spyware-potential" title="Update your iPhone and Mac! Apple patches image flaw with spyware potential" class="tw-block tw-w-1/4 md:tw-mb-3 md:tw-w-full"><img width="400" height="300" alt="Update your iPhone and Mac! Apple patches image flaw with spyware potential" title="Update your iPhone and Mac! Apple patches image flaw with spyware potential" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w600/2026/08/apple-products.jpg" class="tw-h-36 tw-w-full tw-object-contain tw-object-top md:tw-object-cover lg:tw-h-52"></a> <div class="tw-w-3/4 md:tw-w-full"><div class="tw-mb-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-xs tw-font-bold tw-uppercase" style="color:#0065EB;"><a href="/en-us/blog/hotforsecurity/tag/industry-news" title="Industry News" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Industry News
      </a><!----> <!----></div> <a href="/en-us/blog/hotforsecurity/update-iphone-mac-image-flaw-spyware-potential" title="Update your iPhone and Mac! Apple patches image flaw with spyware potential" class="tw-text-lg tw-font-bold tw-leading-tight tw-line-clamp-2 lg:tw-text-xl xl:tw-text-2xl"><h3>Update your iPhone and Mac! Apple patches image flaw with spyware potential</h3></a> <div><div class="tw-mt-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-sm"><a href="/en-us/blog/hotforsecurity/author/ftruta" title="Filip TRUȚĂ" class="tw-overflow-hidden tw-rounded-full tw-h-11 tw-w-11"><img width="50" height="50" alt="Filip TRUȚĂ" title="Filip TRUȚĂ" data-src="https://0.gravatar.com/avatar/377aeee1f02a7ae7ac62f20f2f4ce504?s=64&amp;d=mm&amp;r=g" class="tw-h-full tw-w-full tw-object-cover"></a> <div class="tw-pl-2"><div class="tw-flex tw-flex-wrap tw-gap-x-2"><a href="/en-us/blog/hotforsecurity/author/ftruta" title="Filip TRUȚĂ" class="tw-py-1 tw-mr-1.5 last:tw-mr-0">Filip TRUȚĂ
         </a></div> <p style="color:#6B6B6B;">
         August 19, 2026
      </p></div> <div class="tw-relative tw-ml-5 tw-flex tw-items-center before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959] sm:first:before:tw-hidden"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 23 23" overflow="visible" class="tw-text-[#595959]"><path d="M11.5 2c5.2 0 9.5 4.3 9.5 9.5S16.7 21 11.5 21 2 16.7 2 11.5 6.3 2 11.5 2m0-2C5.1 0 0 5.1 0 11.5S5.1 23 11.5 23 23 17.9 23 11.5 17.9 0 11.5 0z" style="fill: currentColor"></path> <path d="M11.5 6.6v4.5M12 12.1l3.5 3.2" class="st0"></path></svg> <span class="tw-pl-2">
             4 min read
         </span></div> <!----> <div class="tw-py-1 tw-relative tw-ml-5 before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959]"><button aria-label="Add to bookmark" class="tw-block tw-text-base"><svg xmlns="http://www.w3.org/2000/svg" width="20" viewBox="0 0 50.9 52.1" overflow="visible" class="tw-w-[1em] tw-h-[1em]"><path d="M3.4 2.5h34.3c.4 0 .7.4.7.8v45.2c0 .6-.6.9-.9.5L21.1 37.3c-.4-.3-.8-.3-1.2 0L3.4 49.5c-.4.4-.9.1-.9-.5l.2-45.7c0-.4.3-.8.7-.8z" fill="#fff" stroke="#adb5b9" stroke-width="5" stroke-miterlimit="10"></path></svg> <!----></button></div></div></div></div></div></div></div></section> <section class="tw-overflow-hidden tw-bg-[#111] tw-py-12"><div class="tw-container"><div class="tw-mb-6 tw-flex tw-w-1/2 tw-items-center"><h2><span class="tw-block tw-text-sm tw-font-medium tw-uppercase lg:tw-text-sm" style="color:#969696;">
      latest
   </span> <span class="tw-block tw-text-xl tw-font-bold tw-uppercase lg:tw-text-2xl tw-text-white">
      Digital Privacy
   </span></h2></div> <div class="tw-flex-wrap tw-gap-7 md:tw-inline-flex"><div class="tw-mb-8 tw-w-full"><div class="tw-relative tw-h-[360px] tw-p-6 md:tw-h-[460px] lg:tw-h-[600px] lg:tw-p-12"><div class="tw-relative tw-z-20 tw-flex tw-h-full tw-flex-col tw-flex-wrap tw-justify-between"><div class="tw-mt-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-sm tw-text-white"><a href="/en-us/blog/hotforsecurity/author/abizga" title="Alina BÎZGĂ" class="tw-overflow-hidden tw-rounded-full tw-h-11 tw-w-11"><img width="50" height="50" alt="Alina BÎZGĂ" title="Alina BÎZGĂ" data-src="https://2.gravatar.com/avatar/8438d6e3076d0baf471aec1235424fcf?s=64&amp;d=mm&amp;r=g" class="tw-h-full tw-w-full tw-object-cover"></a> <div class="tw-pl-2"><div class="tw-flex tw-flex-wrap tw-gap-x-2"><a href="/en-us/blog/hotforsecurity/author/abizga" title="Alina BÎZGĂ" class="tw-py-1 tw-mr-1.5 last:tw-mr-0">Alina BÎZGĂ
         </a></div> <p style="color:#757575;">
         August 18, 2026
      </p></div> <div class="tw-relative tw-ml-5 tw-flex tw-items-center before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959] sm:first:before:tw-hidden"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 23 23" overflow="visible" class="tw-text-[#595959]"><path d="M11.5 2c5.2 0 9.5 4.3 9.5 9.5S16.7 21 11.5 21 2 16.7 2 11.5 6.3 2 11.5 2m0-2C5.1 0 0 5.1 0 11.5S5.1 23 11.5 23 23 17.9 23 11.5 17.9 0 11.5 0z" style="fill: currentColor"></path> <path d="M11.5 6.6v4.5M12 12.1l3.5 3.2" class="st0"></path></svg> <span class="tw-pl-2">
             3 min read
         </span></div> <!----> <div class="tw-py-1 tw-relative tw-ml-5 before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959]"><button aria-label="Add to bookmark" class="tw-block tw-text-base"><svg xmlns="http://www.w3.org/2000/svg" width="20" viewBox="0 0 50.9 52.1" overflow="visible" class="tw-w-[1em] tw-h-[1em]"><path d="M3.4 2.5h34.3c.4 0 .7.4.7.8v45.2c0 .6-.6.9-.9.5L21.1 37.3c-.4-.3-.8-.3-1.2 0L3.4 49.5c-.4.4-.9.1-.9-.5l.2-45.7c0-.4.3-.8.7-.8z" fill="#fff" stroke="#adb5b9" stroke-width="5" stroke-miterlimit="10"></path></svg> <!----></button></div></div> <div><div class="tw-mb-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-xs tw-font-bold tw-uppercase" style="color:#006DFF;"><a href="/en-us/blog/hotforsecurity/tag/data-breach" title="Data Breach" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Data Breach
      </a><a href="/en-us/blog/hotforsecurity/tag/digital-privacy" title="Digital Privacy" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Digital Privacy
      </a><!----> <!----></div> <a href="/en-us/blog/hotforsecurity/france-dgfip-data-breach-678000-affected" title="French tax authority breach exposes data of 678,000 people and businesses" class="tw-bold tw-max-w-md tw-overflow-hidden tw-text-2xl tw-font-bold tw-text-white tw-line-clamp-3 md:tw-text-3xl md:tw-leading-tight">French tax authority breach exposes data of 678,000 people and businesses</a></div></div> <div class="tw-absolute tw-left-0 tw-top-0 tw-h-full tw-w-full after:tw-absolute after:tw-left-0 after:tw-bottom-0 after:tw-z-10 after:tw-block after:tw-h-1/2 after:tw-w-full after:tw-bg-gradient-to-t after:tw-from-[#111]/[1] after:tw-via-[#111]/[0.8] after:tw-to-[#111]/[0]"><img width="500" height="500" alt="French tax authority breach exposes data of 678,000 people and businesses" title="French tax authority breach exposes data of 678,000 people and businesses" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w600/2026/08/French-tax-authority-breach-exposes-data-of-678-000-people-and-businesses.png" class="tw-h-full tw-w-full tw-object-cover"></div></div></div> <!----><!----> <div class="tw-mb-4 tw-w-full tw-flex-1 last:tw-mb-0 md:tw-mb-12 md:tw-w-1/3"><div class="tw-mb-4 tw-flex tw-gap-4 md:tw-mb-0 md:tw-block tw-text-white"><a href="/en-us/blog/hotforsecurity/bloctel-data-breach-phone-numbers-leaked" title="Phone number leaked in the Bloctel breach? Here’s what to do." class="tw-block tw-w-1/4 md:tw-mb-3 md:tw-w-full"><img width="400" height="300" alt="Phone number leaked in the Bloctel breach? Here’s what to do." title="Phone number leaked in the Bloctel breach? Here’s what to do." data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w600/2026/08/Phone-number-leaked-in-the-Bloctel-breach-Here-s-what-to-do..png" class="tw-h-36 tw-w-full tw-object-contain tw-object-top md:tw-object-cover lg:tw-h-52"></a> <div class="tw-w-3/4 md:tw-w-full"><div class="tw-mb-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-xs tw-font-bold tw-uppercase" style="color:#1479FF;"><a href="/en-us/blog/hotforsecurity/tag/data-breach" title="Data Breach" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Data Breach
      </a><a href="/en-us/blog/hotforsecurity/tag/digital-privacy" title="Digital Privacy" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Digital Privacy
      </a><!----> <!----></div> <a href="/en-us/blog/hotforsecurity/bloctel-data-breach-phone-numbers-leaked" title="Phone number leaked in the Bloctel breach? Here’s what to do." class="tw-text-lg tw-font-bold tw-leading-tight tw-line-clamp-2 lg:tw-text-xl xl:tw-text-2xl"><h3>Phone number leaked in the Bloctel breach? Here’s what to do.</h3></a> <div><div class="tw-mt-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-sm"><a href="/en-us/blog/hotforsecurity/author/abizga" title="Alina BÎZGĂ" class="tw-overflow-hidden tw-rounded-full tw-h-11 tw-w-11"><img width="50" height="50" alt="Alina BÎZGĂ" title="Alina BÎZGĂ" data-src="https://2.gravatar.com/avatar/8438d6e3076d0baf471aec1235424fcf?s=64&amp;d=mm&amp;r=g" class="tw-h-full tw-w-full tw-object-cover"></a> <div class="tw-pl-2"><div class="tw-flex tw-flex-wrap tw-gap-x-2"><a href="/en-us/blog/hotforsecurity/author/abizga" title="Alina BÎZGĂ" class="tw-py-1 tw-mr-1.5 last:tw-mr-0">Alina BÎZGĂ
         </a></div> <p style="color:#808080;">
         August 18, 2026
      </p></div> <div class="tw-relative tw-ml-5 tw-flex tw-items-center before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959] sm:first:before:tw-hidden"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 23 23" overflow="visible" class="tw-text-[#595959]"><path d="M11.5 2c5.2 0 9.5 4.3 9.5 9.5S16.7 21 11.5 21 2 16.7 2 11.5 6.3 2 11.5 2m0-2C5.1 0 0 5.1 0 11.5S5.1 23 11.5 23 23 17.9 23 11.5 17.9 0 11.5 0z" style="fill: currentColor"></path> <path d="M11.5 6.6v4.5M12 12.1l3.5 3.2" class="st0"></path></svg> <span class="tw-pl-2">
             3 min read
         </span></div> <!----> <div class="tw-py-1 tw-relative tw-ml-5 before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959]"><button aria-label="Add to bookmark" class="tw-block tw-text-base"><svg xmlns="http://www.w3.org/2000/svg" width="20" viewBox="0 0 50.9 52.1" overflow="visible" class="tw-w-[1em] tw-h-[1em]"><path d="M3.4 2.5h34.3c.4 0 .7.4.7.8v45.2c0 .6-.6.9-.9.5L21.1 37.3c-.4-.3-.8-.3-1.2 0L3.4 49.5c-.4.4-.9.1-.9-.5l.2-45.7c0-.4.3-.8.7-.8z" fill="#fff" stroke="#adb5b9" stroke-width="5" stroke-miterlimit="10"></path></svg> <!----></button></div></div></div></div></div></div><!----> <div class="tw-mb-4 tw-w-full tw-flex-1 last:tw-mb-0 md:tw-mb-12 md:tw-w-1/3"><div class="tw-mb-4 tw-flex tw-gap-4 md:tw-mb-0 md:tw-block tw-text-white"><a href="/en-us/blog/hotforsecurity/identity-theft-prevention" title="Identity Theft Prevention: How to Protect Your SSN &amp; Credit" class="tw-block tw-w-1/4 md:tw-mb-3 md:tw-w-full"><img width="400" height="300" alt="Identity Theft Prevention: How to Protect Your SSN &amp; Credit" title="Identity Theft Prevention: How to Protect Your SSN &amp; Credit" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w600/2026/08/Identity-Theft-Prevention-How-to-Protect-Your-SSN---Credit.png" class="tw-h-36 tw-w-full tw-object-contain tw-object-top md:tw-object-cover lg:tw-h-52"></a> <div class="tw-w-3/4 md:tw-w-full"><div class="tw-mb-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-xs tw-font-bold tw-uppercase" style="color:#1479FF;"><a href="/en-us/blog/hotforsecurity/tag/digital-privacy" title="Digital Privacy" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Digital Privacy
      </a><a href="/en-us/blog/hotforsecurity/tag/how-to" title="How to" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">How to
      </a><!----> <!----></div> <a href="/en-us/blog/hotforsecurity/identity-theft-prevention" title="Identity Theft Prevention: How to Protect Your SSN &amp; Credit" class="tw-text-lg tw-font-bold tw-leading-tight tw-line-clamp-2 lg:tw-text-xl xl:tw-text-2xl"><h3>Identity Theft Prevention: How to Protect Your SSN &amp; Credit</h3></a> <div><div class="tw-mt-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-sm"><a href="/en-us/blog/hotforsecurity/author/bitdefender" title="Bitdefender" class="tw-overflow-hidden tw-rounded-full tw-h-11 tw-w-11"><img width="50" height="50" alt="Bitdefender" title="Bitdefender" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w100/2022/02/logo_bd_social.png" class="tw-h-full tw-w-full tw-object-cover"></a> <div class="tw-pl-2"><div class="tw-flex tw-flex-wrap tw-gap-x-2"><a href="/en-us/blog/hotforsecurity/author/bitdefender" title="Bitdefender" class="tw-py-1 tw-mr-1.5 last:tw-mr-0">Bitdefender
         </a></div> <p style="color:#808080;">
         August 11, 2026
      </p></div> <div class="tw-relative tw-ml-5 tw-flex tw-items-center before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959] sm:first:before:tw-hidden"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 23 23" overflow="visible" class="tw-text-[#595959]"><path d="M11.5 2c5.2 0 9.5 4.3 9.5 9.5S16.7 21 11.5 21 2 16.7 2 11.5 6.3 2 11.5 2m0-2C5.1 0 0 5.1 0 11.5S5.1 23 11.5 23 23 17.9 23 11.5 17.9 0 11.5 0z" style="fill: currentColor"></path> <path d="M11.5 6.6v4.5M12 12.1l3.5 3.2" class="st0"></path></svg> <span class="tw-pl-2">
             11 min read
         </span></div> <!----> <div class="tw-py-1 tw-relative tw-ml-5 before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959]"><button aria-label="Add to bookmark" class="tw-block tw-text-base"><svg xmlns="http://www.w3.org/2000/svg" width="20" viewBox="0 0 50.9 52.1" overflow="visible" class="tw-w-[1em] tw-h-[1em]"><path d="M3.4 2.5h34.3c.4 0 .7.4.7.8v45.2c0 .6-.6.9-.9.5L21.1 37.3c-.4-.3-.8-.3-1.2 0L3.4 49.5c-.4.4-.9.1-.9-.5l.2-45.7c0-.4.3-.8.7-.8z" fill="#fff" stroke="#adb5b9" stroke-width="5" stroke-miterlimit="10"></path></svg> <!----></button></div></div></div></div></div></div><!----> <div class="tw-mb-4 tw-w-full tw-flex-1 last:tw-mb-0 md:tw-mb-12 md:tw-w-1/3"><div class="tw-mb-4 tw-flex tw-gap-4 md:tw-mb-0 md:tw-block tw-text-white"><a href="/en-us/blog/hotforsecurity/met-police-exposed-woman-address-stalker" title="Met Police exposed a woman’s address to her alleged stalker" class="tw-block tw-w-1/4 md:tw-mb-3 md:tw-w-full"><img width="400" height="300" alt="Met Police exposed a woman’s address to her alleged stalker" title="Met Police exposed a woman’s address to her alleged stalker" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w600/2026/08/met-police-stalker.jpg" class="tw-h-36 tw-w-full tw-object-contain tw-object-top md:tw-object-cover lg:tw-h-52"></a> <div class="tw-w-3/4 md:tw-w-full"><div class="tw-mb-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-xs tw-font-bold tw-uppercase" style="color:#1479FF;"><a href="/en-us/blog/hotforsecurity/tag/industry-news" title="Industry News" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Industry News
      </a><a href="/en-us/blog/hotforsecurity/tag/digital-privacy" title="Digital Privacy" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Digital Privacy
      </a><!----> <!----></div> <a href="/en-us/blog/hotforsecurity/met-police-exposed-woman-address-stalker" title="Met Police exposed a woman’s address to her alleged stalker" class="tw-text-lg tw-font-bold tw-leading-tight tw-line-clamp-2 lg:tw-text-xl xl:tw-text-2xl"><h3>Met Police exposed a woman’s address to her alleged stalker</h3></a> <div><div class="tw-mt-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-sm"><a href="/en-us/blog/hotforsecurity/author/ftruta" title="Filip TRUȚĂ" class="tw-overflow-hidden tw-rounded-full tw-h-11 tw-w-11"><img width="50" height="50" alt="Filip TRUȚĂ" title="Filip TRUȚĂ" data-src="https://0.gravatar.com/avatar/377aeee1f02a7ae7ac62f20f2f4ce504?s=64&amp;d=mm&amp;r=g" class="tw-h-full tw-w-full tw-object-cover"></a> <div class="tw-pl-2"><div class="tw-flex tw-flex-wrap tw-gap-x-2"><a href="/en-us/blog/hotforsecurity/author/ftruta" title="Filip TRUȚĂ" class="tw-py-1 tw-mr-1.5 last:tw-mr-0">Filip TRUȚĂ
         </a></div> <p style="color:#808080;">
         August 11, 2026
      </p></div> <div class="tw-relative tw-ml-5 tw-flex tw-items-center before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959] sm:first:before:tw-hidden"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 23 23" overflow="visible" class="tw-text-[#595959]"><path d="M11.5 2c5.2 0 9.5 4.3 9.5 9.5S16.7 21 11.5 21 2 16.7 2 11.5 6.3 2 11.5 2m0-2C5.1 0 0 5.1 0 11.5S5.1 23 11.5 23 23 17.9 23 11.5 17.9 0 11.5 0z" style="fill: currentColor"></path> <path d="M11.5 6.6v4.5M12 12.1l3.5 3.2" class="st0"></path></svg> <span class="tw-pl-2">
             5 min read
         </span></div> <!----> <div class="tw-py-1 tw-relative tw-ml-5 before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959]"><button aria-label="Add to bookmark" class="tw-block tw-text-base"><svg xmlns="http://www.w3.org/2000/svg" width="20" viewBox="0 0 50.9 52.1" overflow="visible" class="tw-w-[1em] tw-h-[1em]"><path d="M3.4 2.5h34.3c.4 0 .7.4.7.8v45.2c0 .6-.6.9-.9.5L21.1 37.3c-.4-.3-.8-.3-1.2 0L3.4 49.5c-.4.4-.9.1-.9-.5l.2-45.7c0-.4.3-.8.7-.8z" fill="#fff" stroke="#adb5b9" stroke-width="5" stroke-miterlimit="10"></path></svg> <!----></button></div></div></div></div></div></div></div></div></section> <section data-fetch-key="FilterSection:0" class="tw-container tw-flex tw-flex-wrap tw-py-8 lg:tw-flex-nowrap lg:tw-space-x-7"><div class="tw-order-last tw-mb-12 tw-w-full md:tw-mb-0 lg:tw-order-first lg:tw-w-2/3"><div class="tw-mb-7 tw-flex tw-h-20 tw-items-center tw-border-b tw-border-[#e1e3e5] tw-text-xs tw-font-bold sm:tw-text-sm md:tw-text-base"><h2 data-button-active="true" class="tw-mr-5 tw-cursor-pointer tw-uppercase tw-text-[#595959] last:tw-mr-0 data-[button-active=true]:tw-text-black">
               All
            </h2><h2 class="tw-mr-5 tw-cursor-pointer tw-uppercase tw-text-[#595959] last:tw-mr-0 data-[button-active=true]:tw-text-black">
               Threats
            </h2><h2 class="tw-mr-5 tw-cursor-pointer tw-uppercase tw-text-[#595959] last:tw-mr-0 data-[button-active=true]:tw-text-black">
               Product Updates
            </h2><h2 class="tw-mr-5 tw-cursor-pointer tw-uppercase tw-text-[#595959] last:tw-mr-0 data-[button-active=true]:tw-text-black">
               Smart Home
            </h2><h2 class="tw-mr-5 tw-cursor-pointer tw-uppercase tw-text-[#595959] last:tw-mr-0 data-[button-active=true]:tw-text-black">
               Tips and Tricks
            </h2><h2 class="tw-mr-5 tw-cursor-pointer tw-uppercase tw-text-[#595959] last:tw-mr-0 data-[button-active=true]:tw-text-black">
               VPN
            </h2></div> <div class="tw-grid-cols-2 tw-gap-7 md:tw-grid"><div><div class="tw-mb-4 tw-flex tw-gap-4 md:tw-mb-0 md:tw-block tw-mb-4 md:tw-mb-0"><a href="/en-us/blog/hotforsecurity/empty-bank-account-valuable-cybercriminals" title="Why an Empty Bank Account Is Valuable to Cybercriminals" class="tw-block tw-w-1/4 md:tw-mb-3 md:tw-w-full"><img width="400" height="300" alt="Why an Empty Bank Account Is Valuable to Cybercriminals" title="Why an Empty Bank Account Is Valuable to Cybercriminals" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w600/2026/08/mohamed_hassan-money-transfer-7185873_1920.png" class="tw-h-36 tw-w-full tw-object-contain tw-object-top md:tw-object-cover lg:tw-h-52"></a> <div class="tw-w-3/4 md:tw-w-full"><div class="tw-mb-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-xs tw-font-bold tw-uppercase" style="color:#006DFF;"><a href="/en-us/blog/hotforsecurity/tag/finance" title="Finance" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Finance
      </a><!----><!----> <!----></div> <a href="/en-us/blog/hotforsecurity/empty-bank-account-valuable-cybercriminals" title="Why an Empty Bank Account Is Valuable to Cybercriminals" class="tw-text-lg tw-font-bold tw-leading-tight tw-line-clamp-2 lg:tw-text-xl xl:tw-text-2xl"><h3>Why an Empty Bank Account Is Valuable to Cybercriminals</h3></a> <div><div class="tw-mt-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-sm"><a href="/en-us/blog/hotforsecurity/author/sstahie" title="Silviu STAHIE" class="tw-overflow-hidden tw-rounded-full tw-h-11 tw-w-11"><img width="50" height="50" alt="Silviu STAHIE" title="Silviu STAHIE" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w100/2026/03/BD_Silviu_Stahie_Pic3-1.jpeg" class="tw-h-full tw-w-full tw-object-cover"></a> <div class="tw-pl-2"><div class="tw-flex tw-flex-wrap tw-gap-x-2"><a href="/en-us/blog/hotforsecurity/author/sstahie" title="Silviu STAHIE" class="tw-py-1 tw-mr-1.5 last:tw-mr-0">Silviu STAHIE
         </a></div> <p style="color:#757575;">
         August 21, 2026
      </p></div> <div class="tw-relative tw-ml-5 tw-flex tw-items-center before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959] sm:first:before:tw-hidden"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 23 23" overflow="visible" class="tw-text-[#595959]"><path d="M11.5 2c5.2 0 9.5 4.3 9.5 9.5S16.7 21 11.5 21 2 16.7 2 11.5 6.3 2 11.5 2m0-2C5.1 0 0 5.1 0 11.5S5.1 23 11.5 23 23 17.9 23 11.5 17.9 0 11.5 0z" style="fill: currentColor"></path> <path d="M11.5 6.6v4.5M12 12.1l3.5 3.2" class="st0"></path></svg> <span class="tw-pl-2">
             4 min read
         </span></div> <!----> <div class="tw-py-1 tw-relative tw-ml-5 before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959]"><button aria-label="Add to bookmark" class="tw-block tw-text-base"><svg xmlns="http://www.w3.org/2000/svg" width="20" viewBox="0 0 50.9 52.1" overflow="visible" class="tw-w-[1em] tw-h-[1em]"><path d="M3.4 2.5h34.3c.4 0 .7.4.7.8v45.2c0 .6-.6.9-.9.5L21.1 37.3c-.4-.3-.8-.3-1.2 0L3.4 49.5c-.4.4-.9.1-.9-.5l.2-45.7c0-.4.3-.8.7-.8z" fill="#fff" stroke="#adb5b9" stroke-width="5" stroke-miterlimit="10"></path></svg> <!----></button></div></div></div></div></div></div><div><div class="tw-mb-4 tw-flex tw-gap-4 md:tw-mb-0 md:tw-block tw-mb-4 md:tw-mb-0"><a href="/en-us/blog/hotforsecurity/vpn-bypass-age-verification" title="Can a VPN bypass age verification?" class="tw-block tw-w-1/4 md:tw-mb-3 md:tw-w-full"><img width="400" height="300" alt="Can a VPN bypass age verification?" title="Can a VPN bypass age verification?" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w600/2026/08/Can-a-VPN-bypass-age-verification.png" class="tw-h-36 tw-w-full tw-object-contain tw-object-top md:tw-object-cover lg:tw-h-52"></a> <div class="tw-w-3/4 md:tw-w-full"><div class="tw-mb-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-xs tw-font-bold tw-uppercase" style="color:#006DFF;"><a href="/en-us/blog/hotforsecurity/tag/vpn" title="VPN" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">VPN
      </a><a href="/en-us/blog/hotforsecurity/tag/family" title="Family Safety" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Family Safety
      </a><!----> <!----></div> <a href="/en-us/blog/hotforsecurity/vpn-bypass-age-verification" title="Can a VPN bypass age verification?" class="tw-text-lg tw-font-bold tw-leading-tight tw-line-clamp-2 lg:tw-text-xl xl:tw-text-2xl"><h3>Can a VPN bypass age verification?</h3></a> <div><div class="tw-mt-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-sm"><a href="/en-us/blog/hotforsecurity/author/cpopov" title="Cristina POPOV" class="tw-overflow-hidden tw-rounded-full tw-h-11 tw-w-11"><img width="50" height="50" alt="Cristina POPOV" title="Cristina POPOV" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w100/2025/12/20251024_153349.jpg" class="tw-h-full tw-w-full tw-object-cover"></a> <div class="tw-pl-2"><div class="tw-flex tw-flex-wrap tw-gap-x-2"><a href="/en-us/blog/hotforsecurity/author/cpopov" title="Cristina POPOV" class="tw-py-1 tw-mr-1.5 last:tw-mr-0">Cristina POPOV
         </a></div> <p style="color:#757575;">
         August 21, 2026
      </p></div> <div class="tw-relative tw-ml-5 tw-flex tw-items-center before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959] sm:first:before:tw-hidden"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 23 23" overflow="visible" class="tw-text-[#595959]"><path d="M11.5 2c5.2 0 9.5 4.3 9.5 9.5S16.7 21 11.5 21 2 16.7 2 11.5 6.3 2 11.5 2m0-2C5.1 0 0 5.1 0 11.5S5.1 23 11.5 23 23 17.9 23 11.5 17.9 0 11.5 0z" style="fill: currentColor"></path> <path d="M11.5 6.6v4.5M12 12.1l3.5 3.2" class="st0"></path></svg> <span class="tw-pl-2">
             5 min read
         </span></div> <!----> <div class="tw-py-1 tw-relative tw-ml-5 before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959]"><button aria-label="Add to bookmark" class="tw-block tw-text-base"><svg xmlns="http://www.w3.org/2000/svg" width="20" viewBox="0 0 50.9 52.1" overflow="visible" class="tw-w-[1em] tw-h-[1em]"><path d="M3.4 2.5h34.3c.4 0 .7.4.7.8v45.2c0 .6-.6.9-.9.5L21.1 37.3c-.4-.3-.8-.3-1.2 0L3.4 49.5c-.4.4-.9.1-.9-.5l.2-45.7c0-.4.3-.8.7-.8z" fill="#fff" stroke="#adb5b9" stroke-width="5" stroke-miterlimit="10"></path></svg> <!----></button></div></div></div></div></div></div><div><div class="tw-mb-4 tw-flex tw-gap-4 md:tw-mb-0 md:tw-block tw-mb-4 md:tw-mb-0"><a href="/en-us/blog/hotforsecurity/secret-social-media-account-teen" title="How to tell if your teen has a secret social media account" class="tw-block tw-w-1/4 md:tw-mb-3 md:tw-w-full"><img width="400" height="300" alt="How to tell if your teen has a secret social media account" title="How to tell if your teen has a secret social media account" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w600/2026/08/How-to-tell-if-your-teen-has-a-secret-social-media-account.png" class="tw-h-36 tw-w-full tw-object-contain tw-object-top md:tw-object-cover lg:tw-h-52"></a> <div class="tw-w-3/4 md:tw-w-full"><div class="tw-mb-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-xs tw-font-bold tw-uppercase" style="color:#006DFF;"><a href="/en-us/blog/hotforsecurity/tag/family" title="Family Safety" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Family Safety
      </a><a href="/en-us/blog/hotforsecurity/tag/how-to" title="How to" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">How to
      </a><!----> <!----></div> <a href="/en-us/blog/hotforsecurity/secret-social-media-account-teen" title="How to tell if your teen has a secret social media account" class="tw-text-lg tw-font-bold tw-leading-tight tw-line-clamp-2 lg:tw-text-xl xl:tw-text-2xl"><h3>How to tell if your teen has a secret social media account</h3></a> <div><div class="tw-mt-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-sm"><a href="/en-us/blog/hotforsecurity/author/cpopov" title="Cristina POPOV" class="tw-overflow-hidden tw-rounded-full tw-h-11 tw-w-11"><img width="50" height="50" alt="Cristina POPOV" title="Cristina POPOV" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w100/2025/12/20251024_153349.jpg" class="tw-h-full tw-w-full tw-object-cover"></a> <div class="tw-pl-2"><div class="tw-flex tw-flex-wrap tw-gap-x-2"><a href="/en-us/blog/hotforsecurity/author/cpopov" title="Cristina POPOV" class="tw-py-1 tw-mr-1.5 last:tw-mr-0">Cristina POPOV
         </a></div> <p style="color:#757575;">
         August 21, 2026
      </p></div> <div class="tw-relative tw-ml-5 tw-flex tw-items-center before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959] sm:first:before:tw-hidden"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 23 23" overflow="visible" class="tw-text-[#595959]"><path d="M11.5 2c5.2 0 9.5 4.3 9.5 9.5S16.7 21 11.5 21 2 16.7 2 11.5 6.3 2 11.5 2m0-2C5.1 0 0 5.1 0 11.5S5.1 23 11.5 23 23 17.9 23 11.5 17.9 0 11.5 0z" style="fill: currentColor"></path> <path d="M11.5 6.6v4.5M12 12.1l3.5 3.2" class="st0"></path></svg> <span class="tw-pl-2">
             9 min read
         </span></div> <!----> <div class="tw-py-1 tw-relative tw-ml-5 before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959]"><button aria-label="Add to bookmark" class="tw-block tw-text-base"><svg xmlns="http://www.w3.org/2000/svg" width="20" viewBox="0 0 50.9 52.1" overflow="visible" class="tw-w-[1em] tw-h-[1em]"><path d="M3.4 2.5h34.3c.4 0 .7.4.7.8v45.2c0 .6-.6.9-.9.5L21.1 37.3c-.4-.3-.8-.3-1.2 0L3.4 49.5c-.4.4-.9.1-.9-.5l.2-45.7c0-.4.3-.8.7-.8z" fill="#fff" stroke="#adb5b9" stroke-width="5" stroke-miterlimit="10"></path></svg> <!----></button></div></div></div></div></div></div><div><div class="tw-mb-4 tw-flex tw-gap-4 md:tw-mb-0 md:tw-block tw-mb-4 md:tw-mb-0"><a href="/en-us/blog/hotforsecurity/russian-hackers-google-whatsapp-phishing" title="Russian-linked hackers turn Google and WhatsApp logins into phishing traps" class="tw-block tw-w-1/4 md:tw-mb-3 md:tw-w-full"><img width="400" height="300" alt="Russian-linked hackers turn Google and WhatsApp logins into phishing traps" title="Russian-linked hackers turn Google and WhatsApp logins into phishing traps" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w600/2026/08/dimitri-karastelev-ynJaWgrwSlM-unsplash--1-.jpg" class="tw-h-36 tw-w-full tw-object-contain tw-object-top md:tw-object-cover lg:tw-h-52"></a> <div class="tw-w-3/4 md:tw-w-full"><div class="tw-mb-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-xs tw-font-bold tw-uppercase" style="color:#006DFF;"><a href="/en-us/blog/hotforsecurity/tag/industry-news" title="Industry News" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Industry News
      </a><!----> <!----></div> <a href="/en-us/blog/hotforsecurity/russian-hackers-google-whatsapp-phishing" title="Russian-linked hackers turn Google and WhatsApp logins into phishing traps" class="tw-text-lg tw-font-bold tw-leading-tight tw-line-clamp-2 lg:tw-text-xl xl:tw-text-2xl"><h3>Russian-linked hackers turn Google and WhatsApp logins into phishing traps</h3></a> <div><div class="tw-mt-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-sm"><a href="/en-us/blog/hotforsecurity/author/vlad" title="Vlad CONSTANTINESCU" class="tw-overflow-hidden tw-rounded-full tw-h-11 tw-w-11"><img width="50" height="50" alt="Vlad CONSTANTINESCU" title="Vlad CONSTANTINESCU" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w100/2021/12/Vlad.jpg" class="tw-h-full tw-w-full tw-object-cover"></a> <div class="tw-pl-2"><div class="tw-flex tw-flex-wrap tw-gap-x-2"><a href="/en-us/blog/hotforsecurity/author/vlad" title="Vlad CONSTANTINESCU" class="tw-py-1 tw-mr-1.5 last:tw-mr-0">Vlad CONSTANTINESCU
         </a></div> <p style="color:#757575;">
         August 21, 2026
      </p></div> <div class="tw-relative tw-ml-5 tw-flex tw-items-center before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959] sm:first:before:tw-hidden"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 23 23" overflow="visible" class="tw-text-[#595959]"><path d="M11.5 2c5.2 0 9.5 4.3 9.5 9.5S16.7 21 11.5 21 2 16.7 2 11.5 6.3 2 11.5 2m0-2C5.1 0 0 5.1 0 11.5S5.1 23 11.5 23 23 17.9 23 11.5 17.9 0 11.5 0z" style="fill: currentColor"></path> <path d="M11.5 6.6v4.5M12 12.1l3.5 3.2" class="st0"></path></svg> <span class="tw-pl-2">
             2 min read
         </span></div> <!----> <div class="tw-py-1 tw-relative tw-ml-5 before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959]"><button aria-label="Add to bookmark" class="tw-block tw-text-base"><svg xmlns="http://www.w3.org/2000/svg" width="20" viewBox="0 0 50.9 52.1" overflow="visible" class="tw-w-[1em] tw-h-[1em]"><path d="M3.4 2.5h34.3c.4 0 .7.4.7.8v45.2c0 .6-.6.9-.9.5L21.1 37.3c-.4-.3-.8-.3-1.2 0L3.4 49.5c-.4.4-.9.1-.9-.5l.2-45.7c0-.4.3-.8.7-.8z" fill="#fff" stroke="#adb5b9" stroke-width="5" stroke-miterlimit="10"></path></svg> <!----></button></div></div></div></div></div></div><div><div class="tw-mb-4 tw-flex tw-gap-4 md:tw-mb-0 md:tw-block tw-mb-4 md:tw-mb-0"><a href="/en-us/blog/hotforsecurity/australia-roblox-3-months-safety" title="Australia gives Roblox 3 months to strengthen child safety amid grooming concerns" class="tw-block tw-w-1/4 md:tw-mb-3 md:tw-w-full"><img width="400" height="300" alt="Australia gives Roblox 3 months to strengthen child safety amid grooming concerns" title="Australia gives Roblox 3 months to strengthen child safety amid grooming concerns" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w600/2026/08/11333328-fortnite-4129124.jpg" class="tw-h-36 tw-w-full tw-object-contain tw-object-top md:tw-object-cover lg:tw-h-52"></a> <div class="tw-w-3/4 md:tw-w-full"><div class="tw-mb-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-xs tw-font-bold tw-uppercase" style="color:#006DFF;"><!----><a href="/en-us/blog/hotforsecurity/tag/family" title="Family Safety" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Family Safety
      </a> <!----></div> <a href="/en-us/blog/hotforsecurity/australia-roblox-3-months-safety" title="Australia gives Roblox 3 months to strengthen child safety amid grooming concerns" class="tw-text-lg tw-font-bold tw-leading-tight tw-line-clamp-2 lg:tw-text-xl xl:tw-text-2xl"><h3>Australia gives Roblox 3 months to strengthen child safety amid grooming concerns</h3></a> <div><div class="tw-mt-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-sm"><a href="/en-us/blog/hotforsecurity/author/sstahie" title="Silviu STAHIE" class="tw-overflow-hidden tw-rounded-full tw-h-11 tw-w-11"><img width="50" height="50" alt="Silviu STAHIE" title="Silviu STAHIE" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w100/2026/03/BD_Silviu_Stahie_Pic3-1.jpeg" class="tw-h-full tw-w-full tw-object-cover"></a> <div class="tw-pl-2"><div class="tw-flex tw-flex-wrap tw-gap-x-2"><a href="/en-us/blog/hotforsecurity/author/sstahie" title="Silviu STAHIE" class="tw-py-1 tw-mr-1.5 last:tw-mr-0">Silviu STAHIE
         </a></div> <p style="color:#757575;">
         August 20, 2026
      </p></div> <div class="tw-relative tw-ml-5 tw-flex tw-items-center before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959] sm:first:before:tw-hidden"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 23 23" overflow="visible" class="tw-text-[#595959]"><path d="M11.5 2c5.2 0 9.5 4.3 9.5 9.5S16.7 21 11.5 21 2 16.7 2 11.5 6.3 2 11.5 2m0-2C5.1 0 0 5.1 0 11.5S5.1 23 11.5 23 23 17.9 23 11.5 17.9 0 11.5 0z" style="fill: currentColor"></path> <path d="M11.5 6.6v4.5M12 12.1l3.5 3.2" class="st0"></path></svg> <span class="tw-pl-2">
             3 min read
         </span></div> <!----> <div class="tw-py-1 tw-relative tw-ml-5 before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959]"><button aria-label="Add to bookmark" class="tw-block tw-text-base"><svg xmlns="http://www.w3.org/2000/svg" width="20" viewBox="0 0 50.9 52.1" overflow="visible" class="tw-w-[1em] tw-h-[1em]"><path d="M3.4 2.5h34.3c.4 0 .7.4.7.8v45.2c0 .6-.6.9-.9.5L21.1 37.3c-.4-.3-.8-.3-1.2 0L3.4 49.5c-.4.4-.9.1-.9-.5l.2-45.7c0-.4.3-.8.7-.8z" fill="#fff" stroke="#adb5b9" stroke-width="5" stroke-miterlimit="10"></path></svg> <!----></button></div></div></div></div></div></div><div><div class="tw-mb-4 tw-flex tw-gap-4 md:tw-mb-0 md:tw-block tw-mb-4 md:tw-mb-0"><a href="/en-us/blog/hotforsecurity/sakura-internet-breach-1-36-million-accounts" title="Sakura Internet hack may affect 1.36 million accounts" class="tw-block tw-w-1/4 md:tw-mb-3 md:tw-w-full"><img width="400" height="300" alt="Sakura Internet hack may affect 1.36 million accounts" title="Sakura Internet hack may affect 1.36 million accounts" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w600/2026/08/david-brooke-martin-lFTtQqVfx6g-unsplash.jpg" class="tw-h-36 tw-w-full tw-object-contain tw-object-top md:tw-object-cover lg:tw-h-52"></a> <div class="tw-w-3/4 md:tw-w-full"><div class="tw-mb-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-xs tw-font-bold tw-uppercase" style="color:#006DFF;"><a href="/en-us/blog/hotforsecurity/tag/industry-news" title="Industry News" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Industry News
      </a><a href="/en-us/blog/hotforsecurity/tag/data-breach" title="Data Breach" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Data Breach
      </a><!----> <!----></div> <a href="/en-us/blog/hotforsecurity/sakura-internet-breach-1-36-million-accounts" title="Sakura Internet hack may affect 1.36 million accounts" class="tw-text-lg tw-font-bold tw-leading-tight tw-line-clamp-2 lg:tw-text-xl xl:tw-text-2xl"><h3>Sakura Internet hack may affect 1.36 million accounts</h3></a> <div><div class="tw-mt-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-sm"><a href="/en-us/blog/hotforsecurity/author/vlad" title="Vlad CONSTANTINESCU" class="tw-overflow-hidden tw-rounded-full tw-h-11 tw-w-11"><img width="50" height="50" alt="Vlad CONSTANTINESCU" title="Vlad CONSTANTINESCU" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w100/2021/12/Vlad.jpg" class="tw-h-full tw-w-full tw-object-cover"></a> <div class="tw-pl-2"><div class="tw-flex tw-flex-wrap tw-gap-x-2"><a href="/en-us/blog/hotforsecurity/author/vlad" title="Vlad CONSTANTINESCU" class="tw-py-1 tw-mr-1.5 last:tw-mr-0">Vlad CONSTANTINESCU
         </a></div> <p style="color:#757575;">
         August 20, 2026
      </p></div> <div class="tw-relative tw-ml-5 tw-flex tw-items-center before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959] sm:first:before:tw-hidden"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 23 23" overflow="visible" class="tw-text-[#595959]"><path d="M11.5 2c5.2 0 9.5 4.3 9.5 9.5S16.7 21 11.5 21 2 16.7 2 11.5 6.3 2 11.5 2m0-2C5.1 0 0 5.1 0 11.5S5.1 23 11.5 23 23 17.9 23 11.5 17.9 0 11.5 0z" style="fill: currentColor"></path> <path d="M11.5 6.6v4.5M12 12.1l3.5 3.2" class="st0"></path></svg> <span class="tw-pl-2">
             2 min read
         </span></div> <!----> <div class="tw-py-1 tw-relative tw-ml-5 before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959]"><button aria-label="Add to bookmark" class="tw-block tw-text-base"><svg xmlns="http://www.w3.org/2000/svg" width="20" viewBox="0 0 50.9 52.1" overflow="visible" class="tw-w-[1em] tw-h-[1em]"><path d="M3.4 2.5h34.3c.4 0 .7.4.7.8v45.2c0 .6-.6.9-.9.5L21.1 37.3c-.4-.3-.8-.3-1.2 0L3.4 49.5c-.4.4-.9.1-.9-.5l.2-45.7c0-.4.3-.8.7-.8z" fill="#fff" stroke="#adb5b9" stroke-width="5" stroke-miterlimit="10"></path></svg> <!----></button></div></div></div></div></div></div></div> <div class="tw-mb-12 tw-mt-16"><button class="tw-rounded-lg tw-mx-auto tw-block tw-w-full tw-max-w-[260px] tw-cursor-pointer tw-bg-[#006dff] tw-px-10 tw-py-4 tw-text-sm tw-font-bold tw-text-white hover:tw-bg-[#0059d6] disabled:tw-pointer-events-none disabled:tw-opacity-50 focus:tw-bg-[#0045ad] focus-visible:tw-outline-2 focus-visible:tw-outline-offset-2 focus-visible:tw-outline-solid">
            Load more
         </button></div></div> <div class="tw-w-full lg:tw-w-1/3"><!----> <h2 class="tw-mb-7 tw-h-20 tw-border-b tw-border-[#e1e3e5]"><span class="tw-block tw-text-sm tw-font-medium tw-uppercase lg:tw-text-sm" style="color:#696969;">
      Right now
   </span> <span class="tw-block tw-text-xl tw-font-bold tw-uppercase lg:tw-text-2xl tw-text-black">
      Top posts
   </span></h2> <div class="tw-mb-6 tw-flex tw-gap-4 tw-border-b tw-border-[#e1e3e5] tw-pb-6 last:tw-border-b-0"> <div class="tw-w-1/4"><a href="/en-us/blog/hotforsecurity/empty-bank-account-valuable-cybercriminals" title="Why an Empty Bank Account Is Valuable to Cybercriminals" class="tw-block tw-h-full"><img width="200" height="200" alt="Why an Empty Bank Account Is Valuable to Cybercriminals" title="Why an Empty Bank Account Is Valuable to Cybercriminals" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w300/2026/08/mohamed_hassan-money-transfer-7185873_1920.png" class="tw-h-full tw-w-full tw-object-top tw-object-contain"></a></div> <div class="tw-w-3/4"><div class="tw-mb-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-xs tw-font-bold tw-uppercase" style="color:#006DFF;"><a href="/en-us/blog/hotforsecurity/tag/finance" title="Finance" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Finance
      </a><!----><!----> <!----></div> <a href="/en-us/blog/hotforsecurity/empty-bank-account-valuable-cybercriminals" title="Why an Empty Bank Account Is Valuable to Cybercriminals" class="tw-block"><h3 class="tw-font-bold tw-leading-tight tw-line-clamp-3 tw-text-lg">
               Why an Empty Bank Account Is Valuable to Cybercriminals
            </h3></a> <div class="tw-mt-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-sm"><!----> <div><!----> <p style="color:#757575;">
         August 21, 2026
      </p></div> <!----> <!----> <div class="tw-py-1 tw-relative tw-ml-5 before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959]"><button aria-label="Add to bookmark" class="tw-block tw-text-base"><svg xmlns="http://www.w3.org/2000/svg" width="20" viewBox="0 0 50.9 52.1" overflow="visible" class="tw-w-[1em] tw-h-[1em]"><path d="M3.4 2.5h34.3c.4 0 .7.4.7.8v45.2c0 .6-.6.9-.9.5L21.1 37.3c-.4-.3-.8-.3-1.2 0L3.4 49.5c-.4.4-.9.1-.9-.5l.2-45.7c0-.4.3-.8.7-.8z" fill="#fff" stroke="#adb5b9" stroke-width="5" stroke-miterlimit="10"></path></svg> <!----></button></div></div></div></div><div class="tw-mb-6 tw-flex tw-gap-4 tw-border-b tw-border-[#e1e3e5] tw-pb-6 last:tw-border-b-0"> <div class="tw-w-1/4"><a href="/en-us/blog/hotforsecurity/bank-scam-fraudsters-come-to-your-home" title="Police Warning: Your bank is not coming to your house for your card" class="tw-block tw-h-full"><img width="200" height="200" alt="Police Warning: Your bank is not coming to your house for your card" title="Police Warning: Your bank is not coming to your house for your card" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w300/2026/08/Police-Warning-Your-bank-is-not-coming-to-your-house-for-your-card-.png" class="tw-h-full tw-w-full tw-object-top tw-object-contain"></a></div> <div class="tw-w-3/4"><div class="tw-mb-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-xs tw-font-bold tw-uppercase" style="color:#006DFF;"><a href="/en-us/blog/hotforsecurity/tag/scam" title="Scam" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Scam
      </a><!----><!----> <!----></div> <a href="/en-us/blog/hotforsecurity/bank-scam-fraudsters-come-to-your-home" title="Police Warning: Your bank is not coming to your house for your card" class="tw-block"><h3 class="tw-font-bold tw-leading-tight tw-line-clamp-3 tw-text-lg">
               Police Warning: Your bank is not coming to your house for your card
            </h3></a> <div class="tw-mt-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-sm"><!----> <div><!----> <p style="color:#757575;">
         August 13, 2026
      </p></div> <!----> <!----> <div class="tw-py-1 tw-relative tw-ml-5 before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959]"><button aria-label="Add to bookmark" class="tw-block tw-text-base"><svg xmlns="http://www.w3.org/2000/svg" width="20" viewBox="0 0 50.9 52.1" overflow="visible" class="tw-w-[1em] tw-h-[1em]"><path d="M3.4 2.5h34.3c.4 0 .7.4.7.8v45.2c0 .6-.6.9-.9.5L21.1 37.3c-.4-.3-.8-.3-1.2 0L3.4 49.5c-.4.4-.9.1-.9-.5l.2-45.7c0-.4.3-.8.7-.8z" fill="#fff" stroke="#adb5b9" stroke-width="5" stroke-miterlimit="10"></path></svg> <!----></button></div></div></div></div><div class="tw-mb-6 tw-flex tw-gap-4 tw-border-b tw-border-[#e1e3e5] tw-pb-6 last:tw-border-b-0"> <div class="tw-w-1/4"><a href="/en-us/blog/hotforsecurity/steam-gift-scams-why-you-should-never-accept-one-from-an-unknown-user" title="Steam gift scams: Why you should never accept one from an unknown user" class="tw-block tw-h-full"><img width="200" height="200" alt="Steam gift scams: Why you should never accept one from an unknown user" title="Steam gift scams: Why you should never accept one from an unknown user" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w300/2026/08/ChatGPT-Image-Aug-11--2026--06_31_10-PM.png" class="tw-h-full tw-w-full tw-object-top tw-object-contain"></a></div> <div class="tw-w-3/4"><div class="tw-mb-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-xs tw-font-bold tw-uppercase" style="color:#006DFF;"><a href="/en-us/blog/hotforsecurity/tag/scam" title="Scam" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Scam
      </a><!----><!----> <!----></div> <a href="/en-us/blog/hotforsecurity/steam-gift-scams-why-you-should-never-accept-one-from-an-unknown-user" title="Steam gift scams: Why you should never accept one from an unknown user" class="tw-block"><h3 class="tw-font-bold tw-leading-tight tw-line-clamp-3 tw-text-lg">
               Steam gift scams: Why you should never accept one from an unknown user
            </h3></a> <div class="tw-mt-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-sm"><!----> <div><!----> <p style="color:#757575;">
         August 11, 2026
      </p></div> <!----> <!----> <div class="tw-py-1 tw-relative tw-ml-5 before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959]"><button aria-label="Add to bookmark" class="tw-block tw-text-base"><svg xmlns="http://www.w3.org/2000/svg" width="20" viewBox="0 0 50.9 52.1" overflow="visible" class="tw-w-[1em] tw-h-[1em]"><path d="M3.4 2.5h34.3c.4 0 .7.4.7.8v45.2c0 .6-.6.9-.9.5L21.1 37.3c-.4-.3-.8-.3-1.2 0L3.4 49.5c-.4.4-.9.1-.9-.5l.2-45.7c0-.4.3-.8.7-.8z" fill="#fff" stroke="#adb5b9" stroke-width="5" stroke-miterlimit="10"></path></svg> <!----></button></div></div></div></div><div class="tw-mb-6 tw-flex tw-gap-4 tw-border-b tw-border-[#e1e3e5] tw-pb-6 last:tw-border-b-0"> <div class="tw-w-1/4"><a href="/en-us/blog/hotforsecurity/deepfake-onlyfans-account-scam" title="Deepfake OnlyFans accounts are scamming fans and putting creators at risk" class="tw-block tw-h-full"><img width="200" height="200" alt="Deepfake OnlyFans accounts are scamming fans and putting creators at risk" title="Deepfake OnlyFans accounts are scamming fans and putting creators at risk" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w300/2026/08/deepfake-onlyfans.jpg" class="tw-h-full tw-w-full tw-object-top tw-object-contain"></a></div> <div class="tw-w-3/4"><div class="tw-mb-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-xs tw-font-bold tw-uppercase" style="color:#006DFF;"><a href="/en-us/blog/hotforsecurity/tag/industry-news" title="Industry News" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Industry News
      </a><a href="/en-us/blog/hotforsecurity/tag/scam" title="Scam" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Scam
      </a><!----><!----><!----> <!----></div> <a href="/en-us/blog/hotforsecurity/deepfake-onlyfans-account-scam" title="Deepfake OnlyFans accounts are scamming fans and putting creators at risk" class="tw-block"><h3 class="tw-font-bold tw-leading-tight tw-line-clamp-3 tw-text-lg">
               Deepfake OnlyFans accounts are scamming fans and putting creators at risk
            </h3></a> <div class="tw-mt-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-sm"><!----> <div><!----> <p style="color:#757575;">
         August 11, 2026
      </p></div> <!----> <!----> <div class="tw-py-1 tw-relative tw-ml-5 before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959]"><button aria-label="Add to bookmark" class="tw-block tw-text-base"><svg xmlns="http://www.w3.org/2000/svg" width="20" viewBox="0 0 50.9 52.1" overflow="visible" class="tw-w-[1em] tw-h-[1em]"><path d="M3.4 2.5h34.3c.4 0 .7.4.7.8v45.2c0 .6-.6.9-.9.5L21.1 37.3c-.4-.3-.8-.3-1.2 0L3.4 49.5c-.4.4-.9.1-.9-.5l.2-45.7c0-.4.3-.8.7-.8z" fill="#fff" stroke="#adb5b9" stroke-width="5" stroke-miterlimit="10"></path></svg> <!----></button></div></div></div></div><div class="tw-mb-6 tw-flex tw-gap-4 tw-border-b tw-border-[#e1e3e5] tw-pb-6 last:tw-border-b-0"> <div class="tw-w-1/4"><a href="/en-us/blog/hotforsecurity/mac-not-safe-clickfix-attacks" title="Just because you use a Mac doesn't mean you're safe from ClickFix attacks" class="tw-block tw-h-full"><img width="200" height="200" alt="Just because you use a Mac doesn't mean you're safe from ClickFix attacks" title="Just because you use a Mac doesn't mean you're safe from ClickFix attacks" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w300/2026/08/ChatGPT-Image-Aug-7--2026--05_16_19-PM.png" class="tw-h-full tw-w-full tw-object-top tw-object-contain"></a></div> <div class="tw-w-3/4"><div class="tw-mb-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-xs tw-font-bold tw-uppercase" style="color:#006DFF;"><a href="/en-us/blog/hotforsecurity/tag/threats" title="Threats" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Threats
      </a><!----><!----> <!----></div> <a href="/en-us/blog/hotforsecurity/mac-not-safe-clickfix-attacks" title="Just because you use a Mac doesn't mean you're safe from ClickFix attacks" class="tw-block"><h3 class="tw-font-bold tw-leading-tight tw-line-clamp-3 tw-text-lg">
               Just because you use a Mac doesn't mean you're safe from ClickFix attacks
            </h3></a> <div class="tw-mt-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-sm"><!----> <div><!----> <p style="color:#757575;">
         August 07, 2026
      </p></div> <!----> <!----> <div class="tw-py-1 tw-relative tw-ml-5 before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959]"><button aria-label="Add to bookmark" class="tw-block tw-text-base"><svg xmlns="http://www.w3.org/2000/svg" width="20" viewBox="0 0 50.9 52.1" overflow="visible" class="tw-w-[1em] tw-h-[1em]"><path d="M3.4 2.5h34.3c.4 0 .7.4.7.8v45.2c0 .6-.6.9-.9.5L21.1 37.3c-.4-.3-.8-.3-1.2 0L3.4 49.5c-.4.4-.9.1-.9-.5l.2-45.7c0-.4.3-.8.7-.8z" fill="#fff" stroke="#adb5b9" stroke-width="5" stroke-miterlimit="10"></path></svg> <!----></button></div></div></div></div><div class="tw-mb-6 tw-flex tw-gap-4 tw-border-b tw-border-[#e1e3e5] tw-pb-6 last:tw-border-b-0"> <div class="tw-w-1/4"><a href="/en-us/blog/hotforsecurity/bbb-warns-about-free-gas-and-grocery-card-postcard-scams" title="BBB warns about ‘free’ gas and grocery card postcard scams" class="tw-block tw-h-full"><img width="200" height="200" alt="BBB warns about ‘free’ gas and grocery card postcard scams" title="BBB warns about ‘free’ gas and grocery card postcard scams" data-src="https://blogapp.bitdefender.com/hotforsecurity/content/images/size/w300/2026/07/free-gas-and-groceries.png" class="tw-h-full tw-w-full tw-object-top tw-object-contain"></a></div> <div class="tw-w-3/4"><div class="tw-mb-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-xs tw-font-bold tw-uppercase" style="color:#006DFF;"><a href="/en-us/blog/hotforsecurity/tag/scam" title="Scam" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Scam
      </a><a href="/en-us/blog/hotforsecurity/tag/industry-news" title="Industry News" class="tw-py-1 tw-relative tw-mr-4 after:tw-absolute after:tw-top-0 after:tw-bottom-0 after:tw--right-2.5 after:tw-m-auto after:tw-mr-0 after:tw-block after:tw-h-1 after:tw-w-1 after:tw-rounded-full after:tw-bg-current last:tw-mr-0 last:after:tw-hidden ">Industry News
      </a><!----><!----> <!----></div> <a href="/en-us/blog/hotforsecurity/bbb-warns-about-free-gas-and-grocery-card-postcard-scams" title="BBB warns about ‘free’ gas and grocery card postcard scams" class="tw-block"><h3 class="tw-font-bold tw-leading-tight tw-line-clamp-3 tw-text-lg">
               BBB warns about ‘free’ gas and grocery card postcard scams
            </h3></a> <div class="tw-mt-2.5 tw-flex tw-flex-wrap tw-items-center tw-text-sm"><!----> <div><!----> <p style="color:#757575;">
         July 31, 2026
      </p></div> <!----> <!----> <div class="tw-py-1 tw-relative tw-ml-5 before:tw-absolute before:tw-top-0 before:tw-bottom-0 before:tw--left-3 before:tw-m-auto before:tw-block before:tw-h-1 before:tw-w-1 before:tw-rounded-full before:tw-bg-[#595959]"><button aria-label="Add to bookmark" class="tw-block tw-text-base"><svg xmlns="http://www.w3.org/2000/svg" width="20" viewBox="0 0 50.9 52.1" overflow="visible" class="tw-w-[1em] tw-h-[1em]"><path d="M3.4 2.5h34.3c.4 0 .7.4.7.8v45.2c0 .6-.6.9-.9.5L21.1 37.3c-.4-.3-.8-.3-1.2 0L3.4 49.5c-.4.4-.9.1-.9-.5l.2-45.7c0-.4.3-.8.7-.8z" fill="#fff" stroke="#adb5b9" stroke-width="5" stroke-miterlimit="10"></path></svg> <!----></button></div></div></div></div></div></section> <!----> <div class="tw-fixed tw-top-0 tw-right-0 tw-z-[9999] tw-h-full tw-w-full tw-max-w-[450px] tw-translate-x-[450px] tw-bg-white tw-p-6 tw-transition-transform data-[bookmark-active=true]:tw-translate-x-0"><div class="tw-relative tw-mb-4"><h4 class="tw-text-sm tw-font-bold tw-uppercase tw-text-[#595959]">Bookmarks</h4> <button aria-label="Close bookmarks list" class="tw-absolute tw-right-0 tw-top-0 tw-bottom-0 tw-m-auto tw-flex tw-h-7 tw-w-7 tw-items-center tw-justify-center tw-text-2xl tw-text-[#595959] tw-opacity-50 hover:tw-opacity-100"><svg aria-hidden="true" focusable="false" role="img" width="24" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 320 512" class="tw-w-[1em] tw-h-[1em]"><path fill="currentColor" d="M207.6 256l107.72-107.72c6.23-6.23 6.23-16.34 0-22.58l-25.03-25.03c-6.23-6.23-16.34-6.23-22.58 0L160 208.4 52.28 100.68c-6.23-6.23-16.34-6.23-22.58 0L4.68 125.7c-6.23 6.23-6.23 16.34 0 22.58L112.4 256 4.68 363.72c-6.23 6.23-6.23 16.34 0 22.58l25.03 25.03c6.23 6.23 16.34 6.23 22.58 0L160 303.6l107.72 107.72c6.23 6.23 16.34 6.23 22.58 0l25.03-25.03c6.23-6.23 6.23-16.34 0-22.58L207.6 256z"></path></svg></button></div> <div class="tw-h-full tw-overflow-y-auto"><hr class="tw-mb-4"> <!----> </div></div> <div class="tw-fixed tw-top-1/3 tw-right-0 tw-left-0 tw-z-[9999] tw-m-auto tw-hidden tw-h-12 tw-w-11/12 tw-max-w-3xl tw-overflow-hidden tw-rounded-lg tw-border tw-border-[#595959] tw-bg-[#343a40] tw-text-white data-[search-show=true]:tw-block data-[search-active=true]:tw-h-96"><div class="tw-relative"><svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 58.1 59.4" width="22" overflow="visible" class="tw-w-[1em] tw-h-[1em] icon-search tw-absolute tw-left-3 tw-top-3 tw-text-2xl tw-opacity-50"><circle cx="23" cy="23" r="20.5" class="icon-search-inner"></circle> <path d="M39.5 35.2l16.1 11.7" class="icon-search-inner"></path></svg> <input placeholder="What are you looking for?" class="tw-block tw-h-12 tw-w-full tw-border-0 tw-bg-transparent tw-py-2.5 tw-pl-12 tw-pr-2.5 tw-text-2xl tw-text-white"> <div class="tw-my-2 tw-h-80 tw-overflow-y-auto"><img data-src="https://download.bitdefender.com/resources/themes/draco/images/lite_v2/blog-images/loader-white.svg" alt="loader" title="loader" class="tw-mx-auto tw-block tw-h-14 tw-w-32 tw-object-cover"> <!----> </div></div></div> <footer class="tw-bg-[#111] tw-py-12"><div class="tw-container tw-items-center tw-text-center tw-flex-col lg:tw-text-left"><div class="tw-flex tw-flex-col lg:tw-flex-row lg:tw-justify-between tw-items-center lg:tw-items-end tw-pb-3 tw-mb-4 tw-border-b tw-border-solid tw-border-white"><a title="Bitdefender" aria-label="Bitdefender" href="/" class="tw-block tw-w-[150px] tw-pb-3 lg:tw-pb-0"><svg xmlns="http://www.w3.org/2000/svg" width="189.789" height="27.868" viewBox="0 0 189.789 27.868" class="tw-block tw-w-full"><path fill="#fff" d="M176.528 83.716a8.723 8.723 0 0 0-9.081 9.161c0 5.491 4.036 9.161 9.848 9.161a12.146 12.146 0 0 0 4.652-.865l2.477-4.146-.328-.192a14.073 14.073 0 0 1-6.407 1.694c-3 0-5.6-1.517-5.888-4.141h13.274v-1.2c0-6.067-3.678-9.485-8.536-9.485m-4.739 7.415a4.318 4.318 0 0 1 4.5-4.146c2.724 0 4.394 1.6 4.425 4.146zm95.177-7.4a8.718 8.718 0 0 0-9.081 9.161c0 5.491 4.036 9.161 9.848 9.161a12.086 12.086 0 0 0 4.642-.865l2.487-4.146-.328-.177a14.1 14.1 0 0 1-6.412 1.694c-3 0-5.59-1.517-5.883-4.141h13.264c.575-6.836-3.093-10.688-8.536-10.688m-4.737 7.417a4.314 4.314 0 0 1 4.49-4.146c2.724 0 4.394 1.6 4.43 4.146zm-56.1-7.417a8.723 8.723 0 0 0-9.081 9.161c0 5.491 4.036 9.161 9.848 9.161a12.126 12.126 0 0 0 4.652-.865l2.477-4.146-.333-.177a14.038 14.038 0 0 1-6.4 1.694c-3 0-5.6-1.517-5.888-4.141h13.279c.575-6.836-3.1-10.688-8.546-10.688m-4.732 7.417a4.318 4.318 0 0 1 4.5-4.146c2.719 0 4.394 1.6 4.425 4.146zM116.2 88.039v-.071a5.717 5.717 0 0 0 4.46-5.632c0-4.692-3.991-6.471-7.865-6.471H99.68v.384l1.32 1.122c1.584 1.294 1.786 1.542 1.786 2.71v21.528h9.258c4.853 0 9.722-1.744 9.722-7.346a6.128 6.128 0 0 0-5.55-6.219m-8.864-8.256h3.769c2.553 0 3.34.354 4.112 1.092a2.931 2.931 0 0 1 .858 2.22 2.885 2.885 0 0 1-.883 2.149c-.757.728-1.8 1.082-3.688 1.082h-4.167zm4.208 17.888h-4.208v-7.413h4.389c3.7 0 5.439.945 5.439 3.635 0 3.382-3.269 3.782-5.62 3.782m18.83-19.45a2.8 2.8 0 1 1-2.8-2.629 2.681 2.681 0 0 1 2.825 2.619m-7.336 5.936h6.695V101.6h-4.359V87.872c0-1.441-.081-1.673-1.645-2.882l-.691-.551zm34.65-9.06l1.367.88c1.241.794 1.428 1.173 1.428 2.28v8.089h-.106a7.158 7.158 0 0 0-5.913-2.654c-4.969 0-8.42 4-8.42 9.161s3.234 9.161 8.6 9.161a6.746 6.746 0 0 0 5.989-3.034h.071l.454 2.619h3.678V74.782h-7.147zm-2.174 23a5.234 5.234 0 1 1 5.121-5.233 5.059 5.059 0 0 1-5.121 5.233m92.473-23l.605.4c2.1 1.33 2.361 1.714 2.361 3.984v6.89h-.111a7.166 7.166 0 0 0-5.913-2.654c-4.969 0-8.415 4-8.415 9.161s3.229 9.161 8.577 9.161a6.734 6.734 0 0 0 5.989-3.034h.076l.459 2.619h3.678V74.782h-7.315zm-2.018 23a5.234 5.234 0 1 1 5.116-5.233 5.059 5.059 0 0 1-5.116 5.237m43.449-14.156v4.216a8.7 8.7 0 0 0-2.1-.329 4.391 4.391 0 0 0-4.682 4.4v9.343h-4.349V88.706c0-2.194-.116-2.528-1.887-3.645l-1.095-.723v-.192h7.341v2.771h.076a5.549 5.549 0 0 1 5.151-3.2 5.715 5.715 0 0 1 1.559.253m-96.673.11h4.036v3.72H192.8v13.8h-4.369V89.3c0-1.461-.293-1.785-2.018-3.155l-2.22-1.81v-.255h4.243V80.9c0-4.737 3.083-7.746 9.752-6.411l1.009 3.7-.212.172c-3.486-1.375-6.185-.506-6.185 2.528zm41.239 6.5v11.02h-4.354v-9.709c0-1.921-.5-4.247-3.532-4.247-2.866 0-3.991 2.108-3.991 4.434v9.522h-4.349V88.7c0-2.194-.116-2.528-1.887-3.645l-1.059-.723v-.192h7.114v2.66h.071a6.742 6.742 0 0 1 5.55-3.094c4.112 0 6.483 2.821 6.483 6.866m-89.345 7.523l.141.091s-2.164 3.468-2.159 3.468c-3.532.966-7.537-.061-7.537-5.764v-7.078c0-1.127-.182-1.067-2.623-3.084l-1.579-1.37v-.207h4.228L136.8 79.1h2.76v5.056h4.657v3.7h-4.657v7.912c0 3.15 2.154 3.226 5.186 2.326" transform="translate(-99.68 -74.171)"></path></svg></a> <svg xmlns="http://www.w3.org/2000/svg" width="201.188" height="24.44" viewBox="0 0 201.188 24.44"><path id="Path_2" data-name="Path 2" d="M14.482-14.638v-3.51H.7v3.51H5.616V0H9.568V-14.638ZM19.656,0V-7.982c0-1.586,1.092-2.08,3.328-2.08h.962V-13.65H23.27a3.422,3.422,0,0,0-3.484,2.964h-.13V-13.65H15.808V0ZM34.372,0H38.22V-13.65H34.372v8.866a2.173,2.173,0,0,1-2.418,1.976c-1.4,0-1.95-.936-1.95-2.6V-13.65H26.156v8.58c0,3.432,1.482,5.382,4.264,5.382a3.706,3.706,0,0,0,3.822-2.6h.13ZM46.436.312c3.51,0,5.85-1.924,5.85-4.55,0-2.366-1.534-3.718-4.5-4.108l-1.534-.208c-1.118-.156-1.43-.546-1.43-1.274,0-.676.52-1.144,1.82-1.144a4.563,4.563,0,0,1,3.146,1.4L52-11.83a6.861,6.861,0,0,0-5.564-2.132c-3.25,0-5.3,1.82-5.3,4.446,0,2.47,1.508,3.822,4.6,4.212l1.482.182c.962.13,1.378.468,1.378,1.144,0,.806-.52,1.3-2.028,1.3A4.746,4.746,0,0,1,42.952-4.42L40.69-2.132A7.126,7.126,0,0,0,46.436.312ZM61.776,0V-2.99h-2.5v-7.67h2.7v-2.99h-2.7v-3.692H55.822v2.236c0,.936-.312,1.456-1.352,1.456h-.962v2.99h1.924v6.682c0,2.6,1.4,3.978,4.056,3.978Zm8.476.312a7.4,7.4,0,0,0,5.72-2.262L74.048-4.342A4.326,4.326,0,0,1,70.694-2.7a2.682,2.682,0,0,1-3.016-2.938V-5.85H76.44V-6.994c0-3.692-1.82-6.968-6.344-6.968-4.108,0-6.4,2.808-6.4,7.124C63.7-2.47,66.066.312,70.252.312Zm-.078-11.44c1.534,0,2.288,1.118,2.288,2.782v.234H67.678V-8.32A2.5,2.5,0,0,1,70.174-11.128ZM87.542,0H91.39V-19.24H87.542v7.878h-.13a3.7,3.7,0,0,0-3.666-2.6c-3.458,0-5.252,2.5-5.252,7.124S80.288.312,83.746.312a3.727,3.727,0,0,0,3.666-2.6h.13ZM85.02-2.808A2.565,2.565,0,0,1,82.5-5.642V-8.008a2.565,2.565,0,0,1,2.522-2.834c1.456,0,2.522.754,2.522,2v4.03C87.542-3.562,86.476-2.808,85.02-2.808ZM97.214.286A2,2,0,0,0,99.5-1.794v-.52a2,2,0,0,0-2.288-2.08,2,2,0,0,0-2.288,2.08v.52A2,2,0,0,0,97.214.286ZM124.67,0l-5.9-18.148H113.88L107.9,0h4l1.3-4.316h6.058L120.562,0ZM118.3-7.67h-4.16l2-6.89h.13ZM132.548,0V-2.99h-1.716V-19.24h-3.848v15.5c0,2.418,1.2,3.744,3.822,3.744Zm4.732,0h3.952L142.9-5.772l.936-3.536h.078l.962,3.536L146.536,0h4.03l3.77-13.65h-3.562l-1.326,5.512-.936,4.16h-.1l-1.118-4.16L145.7-13.65h-3.51l-1.56,5.512-1.092,4.16h-.1l-.936-4.16-1.326-5.512h-3.718Zm31.2,0V-2.99h-1.274V-8.97c0-3.224-1.976-4.992-5.824-4.992-2.86,0-4.42.988-5.512,2.6l2.288,2.028a3.37,3.37,0,0,1,2.938-1.612c1.612,0,2.262.832,2.262,2.158v.858H161.2c-3.614,0-5.85,1.378-5.85,4.264,0,2.366,1.508,3.978,4.238,3.978,2.08,0,3.588-.936,4-2.7h.156A2.6,2.6,0,0,0,166.348,0Zm-7.462-2.366c-1.144,0-1.794-.468-1.794-1.456v-.39c0-.988.78-1.534,2.262-1.534h1.872v1.612C163.358-2.886,162.292-2.366,161.018-2.366ZM177.164-7.28,176.15-3.328h-.156l-.988-3.952-2-6.37h-3.822L173.966.7,173.5,2.21h-2.574V5.2h2.392c2.34,0,3.484-.988,4.186-3.094l5.252-15.756h-3.588ZM189.1.312c3.51,0,5.85-1.924,5.85-4.55,0-2.366-1.534-3.718-4.5-4.108l-1.534-.208c-1.118-.156-1.43-.546-1.43-1.274,0-.676.52-1.144,1.82-1.144a4.563,4.563,0,0,1,3.146,1.4l2.21-2.262a6.861,6.861,0,0,0-5.564-2.132c-3.25,0-5.3,1.82-5.3,4.446,0,2.47,1.508,3.822,4.6,4.212l1.482.182c.962.13,1.378.468,1.378,1.144,0,.806-.52,1.3-2.028,1.3a4.746,4.746,0,0,1-3.614-1.742l-2.262,2.288A7.126,7.126,0,0,0,189.1.312ZM199.6.286a2,2,0,0,0,2.288-2.08v-.52a2,2,0,0,0-2.288-2.08,2,2,0,0,0-2.288,2.08v.52A2,2,0,0,0,199.6.286Z" transform="translate(-0.702 19.24)" fill="#fff"></path></svg></div> <div class="tw-pb-3 [&amp;_*]:tw-text-[13px] lg:[&amp;_*]:tw-text-[14px] [&amp;_*]:tw-text-white [&amp;_a]:tw-no-underline hover:[&amp;_a]:tw-underline [&amp;_span]:tw-px-3 lg:[&amp;_span]:tw-px-4"><a href="https://www.bitdefender.com/site/view/legal-terms.html" title="Legal Information">Legal Information</a> <span>|</span> <a href="https://www.bitdefender.com/site/view/legal-privacy-policy-for-bitdefender-websites.html" title="Privacy Policy">Privacy Policy</a> <span>|</span> <a href="https://www.bitdefender.com/site/Main/contact/1" title="Contact Us">Contact Us</a></div> <div class="tw-flex tw-flex-col lg:tw-flex-row lg:tw-justify-between tw-items-center"><span class="tw-pb-3 lg:tw-pb-0 tw-text-[13px] lg:tw-text-[14px] tw-text-[#969696]">
            Copyright © 1997 - 2026 Bitdefender.
         </span> <div><div class="tw-flex tw-items-center tw-justify-center lg:tw-justify-end"><a aria-label="Facebook Bitdefender" title="Facebook Bitdefender" rel="nofollow" target="_blank" href="https://facebook.com/Bitdefender/" class="tw-flex tw-items-center tw-bg-none tw-mr-2 tw-p-2"><svg xmlns="http://www.w3.org/2000/svg" height="16" width="16" viewBox="0 0 512 512" class="tw-h-5 tw-w-5"><path opacity="1" fill="#595959" d="M512 256C512 114.6 397.4 0 256 0S0 114.6 0 256C0 376 82.7 476.8 194.2 504.5V334.2H141.4V256h52.8V222.3c0-87.1 39.4-127.5 125-127.5c16.2 0 44.2 3.2 55.7 6.4V172c-6-.6-16.5-1-29.6-1c-42 0-58.2 15.9-58.2 57.2V256h83.6l-14.4 78.2H287V510.1C413.8 494.8 512 386.9 512 256h0z"></path></svg></a> <a aria-label="Twitter Bitdefender" title="Twitter Bitdefender" rel="nofollow" target="_blank" href="https://twitter.com/bitdefender/" class="tw-flex tw-items-center tw-bg-none tw-mr-2 tw-p-2"><svg xmlns="http://www.w3.org/2000/svg" height="16" width="16" viewBox="0 0 512 512" class="tw-h-5 tw-w-5"><path opacity="1" fill="#595959" d="M389.2 48h70.6L305.6 224.2 487 464H345L233.7 318.6 106.5 464H35.8L200.7 275.5 26.8 48H172.4L272.9 180.9 389.2 48zM364.4 421.8h39.1L151.1 88h-42L364.4 421.8z"></path></svg></a> <a aria-label="Instagram Bitdefender" title="Instagram Bitdefender" rel="nofollow" target="_blank" href="https://instagram.com/bitdefender/" class="tw-flex tw-items-center tw-bg-none tw-mr-2 tw-p-2"><svg xmlns="http://www.w3.org/2000/svg" height="16" width="14" viewBox="0 0 448 512" class="tw-h-5 tw-w-5" data-v-0f536bc0=""><path opacity="1" fill="#595959" d="M224.1 141c-63.6 0-114.9 51.3-114.9 114.9s51.3 114.9 114.9 114.9S339 319.5 339 255.9 287.7 141 224.1 141zm0 189.6c-41.1 0-74.7-33.5-74.7-74.7s33.5-74.7 74.7-74.7 74.7 33.5 74.7 74.7-33.6 74.7-74.7 74.7zm146.4-194.3c0 14.9-12 26.8-26.8 26.8-14.9 0-26.8-12-26.8-26.8s12-26.8 26.8-26.8 26.8 12 26.8 26.8zm76.1 27.2c-1.7-35.9-9.9-67.7-36.2-93.9-26.2-26.2-58-34.4-93.9-36.2-37-2.1-147.9-2.1-184.9 0-35.8 1.7-67.6 9.9-93.9 36.1s-34.4 58-36.2 93.9c-2.1 37-2.1 147.9 0 184.9 1.7 35.9 9.9 67.7 36.2 93.9s58 34.4 93.9 36.2c37 2.1 147.9 2.1 184.9 0 35.9-1.7 67.7-9.9 93.9-36.2 26.2-26.2 34.4-58 36.2-93.9 2.1-37 2.1-147.8 0-184.8zM398.8 388c-7.8 19.6-22.9 34.7-42.6 42.6-29.5 11.7-99.5 9-132.1 9s-102.7 2.6-132.1-9c-19.6-7.8-34.7-22.9-42.6-42.6-11.7-29.5-9-99.5-9-132.1s-2.6-102.7 9-132.1c7.8-19.6 22.9-34.7 42.6-42.6 29.5-11.7 99.5-9 132.1-9s102.7-2.6 132.1 9c19.6 7.8 34.7 22.9 42.6 42.6 11.7 29.5 9 99.5 9 132.1s2.7 102.7-9 132.1z" data-v-0f536bc0=""></path></svg></a> <!----> <a aria-label="Youtube Bitdefender" title="Youtube Bitdefender" rel="nofollow" target="_blank" href="https://www.youtube.com/Bitdefender/" class="tw-flex tw-items-center tw-bg-none tw-mr-2 tw-p-2"><svg xmlns="http://www.w3.org/2000/svg" width="25.6" height="18" viewBox="0 0 25.6 18" class="tw-h-5 tw-w-5"><path id="Path_5" data-name="Path 5" d="M25.765-15.184A3.217,3.217,0,0,0,23.5-17.462c-2-.538-10-.538-10-.538s-8.005,0-10,.538a3.217,3.217,0,0,0-2.263,2.278A33.744,33.744,0,0,0,.7-8.982a33.744,33.744,0,0,0,.535,6.2A3.169,3.169,0,0,0,3.5-.538C5.495,0,13.5,0,13.5,0s8.005,0,10-.538A3.169,3.169,0,0,0,25.765-2.78a33.744,33.744,0,0,0,.535-6.2A33.744,33.744,0,0,0,25.765-15.184ZM10.882-5.175v-7.613l6.691,3.806L10.882-5.175Z" transform="translate(-0.7 18)" fill="#595959"></path></svg></a></div></div></div></div></footer></div></div></div></div><script nonce="DhcnhD3khTMePgXW">window.__NUXT__=(function(a,b,c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z,A,B,C,D,E,F,G,H,I,J,K,L,M,N,O,P,Q,R,S,T,U,V,W,X,Y,Z,_,$,aa,ab,ac,ad,ae,af,ag,ah,ai,aj,ak,al,am,an,ao,ap,aq,ar,as,at,au,av,aw,ax,ay,az,aA,aB,aC,aD,aE,aF,aG,aH,aI,aJ,aK,aL,aM,aN,aO,aP,aQ,aR,aS,aT,aU,aV,aW,aX,aY,aZ,a_,a$,ba,bb,bc,bd,be,bf,bg,bh,bi,bj,bk,bl,bm,bn,bo,bp,bq,br,bs,bt,bu,bv,bw,bx,by,bz,bA,bB,bC,bD,bE,bF,bG,bH,bI,bJ,bK){bx.HFS=am;bx.LAB="labs";bx.BI="businessinsights";bx.CYB="cyberpedia";return {layout:"default",data:[{featuredPost:[{id:"6a8423538beeea9658028e6c",title:"Authorized vs unauthorized fraud and what it means for your refund rights",slug:"authorized-vs-unauthorized-fraud",feature_image:"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002Fauthorized-unauthorized-fraud.jpg",featured:N,published_at:"2026-08-18T12:21:17.000+03:00",custom_excerpt:at,html:"\u003Cp\u003E\u003Cem\u003ETwo victims can lose money to similar scams but face very different refund rules depending on who actually approved the payment. Understanding authorized vs unauthorized fraud helps you describe what happened accurately, dispute the transaction, and act quickly before recovery options narrow.\u003C\u002Fem\u003E\u003C\u002Fp\u003E\u003Ch2 id=\"key-takeaways\"\u003EKey takeaways\u003C\u002Fh2\u003E\u003Cul\u003E\u003Cli\u003EUnauthorized fraud generally means someone else initiated a payment without your consent; an authorized scam payment means you were tricked into sending or approving it\u003C\u002Fli\u003E\u003Cli\u003ERefund rights depend on that distinction, but also on the country, payment method and circumstances\u003C\u002Fli\u003E\u003Cli\u003EA password, PIN or one-time code can authenticate a payment without necessarily proving that you authorized it\u003C\u002Fli\u003E\u003Cli\u003EContact the bank or payment provider immediately, explain who initiated the payment, preserve evidence and secure exposed accounts\u003C\u002Fli\u003E\u003C\u002Ful\u003E\u003Ch2 id=\"authorized-vs-unauthorized-fraud-in-plain-language\"\u003EAuthorized vs unauthorized fraud in plain language\u003C\u002Fh2\u003E\u003Cp\u003EIn payments law, “authorized” usually describes consent to the payment instruction, not whether the underlying story was accurate. If a fake bank employee convinces you to move money to a “safe account” and you approve the transfer, the payment may be treated as authorized even though the deception was criminal.\u003C\u002Fp\u003E\u003Cp\u003EIf the scammer instead obtains your login details and initiates the transfer without your consent, the transaction may be unauthorized. That distinction can determine which refund rules apply and how the claim is investigated. Importantly, use of a correct PIN, password or security code may show authentication without necessarily proving authorization.\u003C\u002Fp\u003E\u003Cp\u003EThis is one of the most important distinctions affecting recovery from \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Ffinancial-scams\"\u003Efinancial scams\u003C\u002Fa\u003E: two scams with almost identical social-engineering tactics can produce very different payment disputes depending on who ultimately initiated the transaction.\u003C\u002Fp\u003E\u003Cfigure class=\"kg-card kg-image-card\"\u003E\u003Cimg src=\"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002Fauthorized-unauthorized-payment.jpg\" class=\"kg-image\" alt=\"\" loading=\"lazy\" width=\"1500\" height=\"1080\" srcset=\"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002Fsize\u002Fw600\u002F2026\u002F08\u002Fauthorized-unauthorized-payment.jpg 600w, https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002Fsize\u002Fw1000\u002F2026\u002F08\u002Fauthorized-unauthorized-payment.jpg 1000w, https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002Fauthorized-unauthorized-payment.jpg 1500w\" sizes=\"(min-width: 720px) 720px\"\u003E\u003C\u002Ffigure\u003E\u003Ch2 id=\"why-the-difference-changes-bank-refund-rights\"\u003EWhy the difference changes bank refund rights\u003C\u002Fh2\u003E\u003Cp\u003EThere is no single global refund rule. Consumers should report the payment immediately and check the rules for their jurisdiction and payment method.\u003C\u002Fp\u003E\u003Ch3 id=\"united-states\"\u003EUnited States\u003C\u002Fh3\u003E\u003Cp\u003E\u003Ca href=\"https:\u002F\u002Fwww.consumerfinance.gov\u002Frules-policy\u002Fregulations\u002F1005\u002F3\u002F\"\u003ERegulation E\u003C\u002Fa\u003E protects consumers against certain unauthorized electronic fund transfers. CFPB guidance says that when a fraudster tricks a consumer into sharing account access information and then uses it to initiate a transfer, the transfer can still qualify as unauthorized.\u003C\u002Fp\u003E\u003Cp\u003EA transfer the consumer personally initiates after being deceived generally does not fit Regulation E’s definition of an unauthorized electronic funds transfer. Coverage also varies by payment rail. Some wire-transfer systems primarily used between financial institutions or businesses, including Fedwire, are excluded from Regulation E.\u003C\u002Fp\u003E\u003Ch3 id=\"united-kingdom\"\u003EUnited Kingdom\u003C\u002Fh3\u003E\u003Cp\u003EFor an unauthorized payment, the FCA \u003Ca href=\"https:\u002F\u002Fwww.fca.org.uk\u002Fconsumers\u002Ffraudulent-payments\"\u003Esays\u003C\u002Fa\u003E the bank should generally refund the consumer by the end of the next business day once notified, subject to exceptions, and consumers normally have up to 13 months to report it.\u003C\u002Fp\u003E\u003Cp\u003EThe UK also has \u003Ca href=\"https:\u002F\u002Fwww.psr.org.uk\u002Fmedia\u002Frhelv4op\u002Fps25-5-app-scams-reimbursement-consolidated-policy-statement-may-2025.pdf\"\u003Emandatory reimbursement\u003C\u002Fa\u003E for eligible authorized push payment (APP) scams through Faster Payments or CHAPS from October 7, 2024. Eligible claims can be reimbursed up to £85,000, usually within five business days, although an excess of up to £100 and other exceptions may apply.\u003C\u002Fp\u003E\u003Ch3 id=\"european-union\"\u003EEuropean Union\u003C\u002Fh3\u003E\u003Cp\u003EUnder \u003Ca href=\"https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Fdir\u002F2015\u002F2366\u002F2025-01-17\u002Feng\u002F\"\u003EPSD2\u003C\u002Fa\u003E, a payment is authorized only when the payer has given consent. Without consent, it is unauthorized. Unauthorized transactions generally must be refunded immediately and no later than the end of the next business day after notification, with a 13-month reporting deadline in most cases.\u003C\u002Fp\u003E\u003Cp\u003EScam transfers authorized by victims do not currently receive the same broad EU-wide reimbursement treatment. Proposed \u003Ca href=\"https:\u002F\u002Fwww.europarl.europa.eu\u002Flegislative-train\u002Ftheme-a-new-plan-for-europe-s-sustainable-prosperity-and-competitiveness\u002Ffile-revision-of-eu-rules-on-payment-services\"\u003EPSR\u002FPSD3\u003C\u002Fa\u003E rules would strengthen protection for some impersonation scams, but the latest official status verified for this article said formal adoption was still required before the legislation could enter into force.\u003C\u002Fp\u003E\u003Cfigure class=\"kg-card kg-image-card\"\u003E\u003Cimg src=\"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002Fimpersonation-scam-authorized-unauthorized.jpg\" class=\"kg-image\" alt=\"\" loading=\"lazy\" width=\"1080\" height=\"2300\" srcset=\"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002Fsize\u002Fw600\u002F2026\u002F08\u002Fimpersonation-scam-authorized-unauthorized.jpg 600w, https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002Fsize\u002Fw1000\u002F2026\u002F08\u002Fimpersonation-scam-authorized-unauthorized.jpg 1000w, https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002Fimpersonation-scam-authorized-unauthorized.jpg 1080w\" sizes=\"(min-width: 720px) 720px\"\u003E\u003C\u002Ffigure\u003E\u003Ch2 id=\"warning-signs-before-you-approve-a-payment\"\u003EWarning signs before you approve a payment\u003C\u002Fh2\u003E\u003Cp\u003EBe wary of unsolicited instructions to move money urgently, particularly claims purportedly from a bank, police force, government body or support team. A “safe account,” demands for secrecy, remote-access software, requests for verification codes or pressure to ignore an in-app warning are all reasons to stop and independently verify the request through an official channel.\u003C\u002Fp\u003E\u003Cp\u003EThe criminal’s objective may be the payment itself, or the banking credentials, verification codes and account access needed to initiate transactions without you. Ending the conversation and contacting the organization independently can prevent the scammer from controlling both the story and your next action.\u003C\u002Fp\u003E\u003Ch2 id=\"what-to-do-if-money-has-already-moved\"\u003EWhat to do if money has already moved\u003C\u002Fh2\u003E\u003Cul\u003E\u003Cli\u003E\u003Cstrong\u003EContact the bank, card issuer or payment service immediately.\u003C\u002Fstrong\u003E State whether you initiated the payment or someone else did, ask whether it can be stopped or recalled, and open the appropriate fraud or scam claim.\u003C\u002Fli\u003E\u003Cli\u003E\u003Cstrong\u003ESecure exposed accounts.\u003C\u002Fstrong\u003E Change compromised banking and email passwords, end unfamiliar sessions and replace or freeze affected cards when advised.\u003C\u002Fli\u003E\u003Cli\u003E\u003Cstrong\u003EPreserve the evidence.\u003C\u002Fstrong\u003E Save messages, receipts, transaction IDs, beneficiary details, URLs and screenshots. Our \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fscam-evidence-checklist\"\u003Escam evidence checklist\u003C\u002Fa\u003E explains what to preserve before accounts or websites disappear.\u003C\u002Fli\u003E\u003Cli\u003E\u003Cstrong\u003EFollow the \u003C\u002Fstrong\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fscam-recovery-timeline\"\u003E\u003Cstrong\u003Escam recovery timeline\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E and report the incident through the appropriate national channel. If you initiated the transfer yourself, see what to do after you have \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fsent-money-scammer-bank-transfer\"\u003Esent money to a scammer by bank transfer\u003C\u002Fa\u003E.\u003C\u002Fli\u003E\u003C\u002Ful\u003E\u003Cfigure class=\"kg-card kg-image-card\"\u003E\u003Cimg src=\"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002Fwhat-to-do-scam-payment.jpg\" class=\"kg-image\" alt=\"\" loading=\"lazy\" width=\"1080\" height=\"1280\" srcset=\"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002Fsize\u002Fw600\u002F2026\u002F08\u002Fwhat-to-do-scam-payment.jpg 600w, https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002Fsize\u002Fw1000\u002F2026\u002F08\u002Fwhat-to-do-scam-payment.jpg 1000w, https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002Fwhat-to-do-scam-payment.jpg 1080w\" sizes=\"(min-width: 720px) 720px\"\u003E\u003C\u002Ffigure\u003E\u003Ch2 id=\"how-bitdefender-can-help\"\u003EHow Bitdefender can help\u003C\u002Fh2\u003E\u003Cp\u003EBefore paying, \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fscamio\"\u003E\u003Cstrong\u003EBitdefender Scamio\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E can analyze suspicious texts, emails, links, QR codes and screenshots you submit and flag potential scam risk. It can provide a useful second check when an unexpected payment request arrives, but it is not a bank-refund decision service.\u003C\u002Fp\u003E\u003Cp\u003EIf a scam exposed personal information or account credentials, \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fdigital-identity-protection\"\u003E\u003Cstrong\u003EBitdefender Digital Identity Protection\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E monitors a user's digital footprint for exposed data and compromised accounts and can alert them to identified risks. It cannot reverse a payment or guarantee recovery.\u003C\u002Fp\u003E\u003Ch2 id=\"conclusion\"\u003EConclusion\u003C\u002Fh2\u003E\u003Cp\u003EThe distinction between authorized and unauthorized fraud can change which refund framework applies and how a claim is assessed. Act quickly, tell the provider exactly who initiated the payment, preserve evidence and challenge an incorrect classification if the facts do not match it.\u003C\u002Fp\u003E\u003Ch2 id=\"frequently-asked-questions\"\u003EFrequently asked questions\u003C\u002Fh2\u003E\u003Ch3 id=\"what-does-authorized-transaction-mean\"\u003EWhat does \"authorized transaction\" mean?\u003C\u002Fh3\u003E\u003Cp\u003EAn authorized transaction is a payment to which the payer consented. In a scam, that can include a transfer the victim personally approved because a criminal deceived them. “Authorized” describes the payment instruction; it does not mean the scam was legitimate or that reimbursement is impossible.\u003C\u002Fp\u003E\u003Ch3 id=\"will-the-bank-refund-an-authorized-transaction\"\u003EWill the bank refund an authorized transaction?\u003C\u002Fh3\u003E\u003Cp\u003ESometimes, but not automatically and not under the same rules everywhere. Refund rights depend on the jurisdiction, payment method, bank policy and scam type. The UK, for example, has mandatory reimbursement rules for many eligible APP scam payments, while other countries may offer narrower statutory rights.\u003C\u002Fp\u003E\u003Ch3 id=\"what-qualifies-as-an-unauthorized-transaction\"\u003EWhat qualifies as an unauthorized transaction?\u003C\u002Fh3\u003E\u003Cp\u003EAn unauthorized transaction is generally one initiated without the account holder's consent or actual authority. Examples include a fraudster using stolen payment details or taking over an account and sending money. Valid credentials do not necessarily settle the question, so the facts behind who initiated the payment matter.\u003C\u002Fp\u003E",tags:[{id:O,name:P,slug:Q,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:m,name:n,slug:o,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:e,name:f,slug:d,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a}],authors:[{id:z,name:A,slug:B,profile_image:C,cover_image:a,bio:D,website:a,location:a,facebook:a,twitter:a,meta_title:a,meta_description:a}],excerpt:at,reading_time:E,url:"\u002Fblog\u002Fhotforsecurity\u002Fauthorized-vs-unauthorized-fraud\u002F"}],topPost:[{id:_,title:$,slug:aa,feature_image:ab,featured:c,published_at:ac,custom_excerpt:x,plaintext:"Even if it’s not immediately obvious, bank accounts hold something that can be just as useful as cash: a detailed record of your financial life. Transactions can reveal where you work, what services you use, who sends you money, when you pay bills and which other accounts may be connected to your name.\n\nThat information can help enable identity theft, more convincing scams and fraud that unfolds over time.\n\nA criminal breaking into a bank account with no money in it doesn’t make the breach harmless.\n\n\nKey takeaways\n\n * A low balance does not make a compromised bank account safe\n * Transaction histories can expose personal details criminals can use in follow-up scams\n * Attackers may wait for incoming payments, exploit connected services or try reused passwords elsewhere\n * A compromised account can also be used to receive and move stolen money\n * Report suspicious access or transactions to your bank immediately\n\n\n\nAn empty account is not an empty target\n\nThe obvious risk of a bank account takeover is theft. A criminal can transfer money, make purchases or attempt withdrawals. But the account balance is not the only valuable aspect.\n\nSomeone with access to an account can see regular salary payments, tax refunds, benefits, insurance payments, reimbursements or transfers from relatives. They may wait for money to arrive.\n\nThey will also look for services connected to the account, including payment apps, debit cards, overdraft facilities, savings accounts or automatic bill payments. What is available depends on the bank and the account, but even limited access can give criminals useful information or options.\n\nThe Consumer Financial Protection Bureau advises people to monitor accounts for unfamiliar activity, including small charges or debits. These may be attempts to test whether stolen details work before a larger fraud attempt.\n\n\nYour transaction history can become a fraud playbook\n\nA bank statement is often a surprisingly detailed profile of a person’s life. It reveals employers, utility providers, insurers, subscriptions, mortgage or rent payments, medical providers, travel plans and shopping habits.\n\nThat information can help criminals build a more believable lie. Instead of sending a generic phishing message, they may impersonate a bank, delivery company, employer or family member using details that make the message seem credible.\n\nFor example, an attacker who sees a regular payment from an insurer might send a fake “policy update” email. Someone who notices regular transfers between family members may attempt an impersonation scam that appears to come from a relative in need.\n\n\nCompromised banking details can lead to identity theft\n\nFinancial information is valuable because it can be combined with data stolen from other data breaches. A name, address, account number, payment history and contact details may help criminals impersonate a victim, attempt to open accounts or answer security questions.\n\nIdentity theft does not always become visible immediately. Warning signs can include bills for things you did not buy, debt collection calls, unfamiliar accounts on a credit report or loan applications being denied unexpectedly. USAGov’s identity theft guidance recommends reporting suspected identity theft to the affected financial institutions and taking action to protect your credit where appropriate.\n\n\nCriminals may try the same password elsewhere\n\nA bank account takeover can also confirm that a username and password combination works.\n\nIf the victim reused that password, as many people do, criminals may try it on email, shopping, social media, payment and cryptocurrency accounts. Access to email is especially valuable because it can allow attackers to reset passwords for other services.\n\nThis is why changing only the bank password may not be enough. If you used that password anywhere else, change it there too. The FTC specifically recommends creating a new, strong password and changing it on any other accounts where it was reused.\n\n\nYour account could be used to move stolen money\n\nCriminals sometimes use other people’s accounts to receive and transfer stolen funds. This is known as money mule activity.\n\nA victim may not realize their account has been used this way until they see unexplained transfers, hear from their bank or face questions about suspicious activity.\n\nThe FBI’s Internet Crime Complaint Center warns that money mule schemes can expose people to identity theft, financial losses and serious legal consequences, even when they were not fully aware of the wider scheme.\n\nA compromised account is therefore not just a victim’s problem. It can become part of the criminal infrastructure used to target other people.\n\n\nWhat to do if you think someone accessed your bank account\n\n * Act quickly, even if no money appears to be missing\n * Contact your bank using the number on its official website, app or the back of your card\n * Report unfamiliar transactions, new payees, changed contact details or login alerts\n * Change your online-banking password and enable multi-factor authentication if your bank has this option\n * Change any reused password on email, payment and shopping accounts\n * Review connected cards, payment apps, direct debits and account alerts\n * Check your account statements over the following weeks for delayed or small fraudulent transactions\n * If personal information was exposed, follow your country’s identity-theft reporting and credit-monitoring guidance\n\n\nNever rely on a phone number or link sent in an unexpected text or email claiming to be from your bank. Find the bank’s official contact details independently.\n\n\nBetter protection starts before a breach\n\nUse a unique password for every financial account and store it in a reputable password manager. Turn on multi-factor authentication, keep your phone and computer updated, and avoid using links in unexpected messages.\n\nA security solution can also help block malicious websites and phishing attempts before they reach a fake banking page. Bitdefender Ultimate Security includes protection designed to help keep phishing, scams and identity-related threats from turning into a larger problem.\n\n\nFAQ\n\n\nCan someone steal money from an empty bank account?\n\nPossibly, depending on the account’s features and linked payment methods. But even if there is no money to take immediately, criminals may wait for incoming payments or use the account data for other fraud.\n\n\nWhy would a hacker want my bank statements?\n\nStatements can reveal personal information, regular payments, employers, services you use and people you send money to. Criminals can use these details to make scams more convincing.\n\n\nCan a hacked bank account lead to identity theft?\n\nYes. Banking details may be combined with other stolen personal information to impersonate you, attempt account fraud or target you with more believable scams.\n\n\nWhat is a money mule account?\n\nA money mule account is used to receive or transfer money connected to crime. Criminals may use compromised accounts, or trick people into moving money for them.\n\n\nWhat should I do if my bank account was compromised but no money was taken?\n\nContact your bank immediately, secure your login credentials, review recent activity and change any reused passwords. Do not wait for a financial loss to appear.",tags:[{id:O,name:P,slug:Q,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:e,name:f,slug:d,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:h,name:g,slug:g,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a}],authors:[{id:p,name:q,slug:r,profile_image:s,cover_image:t,bio:u,website:a,location:a,facebook:a,twitter:a,meta_title:a,meta_description:a}],excerpt:x,url:ad},{id:au,title:av,slug:aw,feature_image:ax,featured:c,published_at:ay,custom_excerpt:a,plaintext:"Scammers can be frighteningly creative. And while we tend to imagine scams happening behind a phone or laptop screen, they don't always stay there.\n\nPolice in Kent, Ohio, are warning the public about a banking scam that can start with a simple text message and end with a stranger showing up at your front door to collect your bank card.\n\n\nKey takeaways\n\n * Your bank will not send someone to your home to collect a compromised debit or credit card.\n * Caller ID isn't proof you're speaking with your bank. Scammers can spoof legitimate phone numbers.\n * A scam that starts online can quickly move offline. Never assume you're physically distant from the people behind a text, email or phone scam.\n * Don't move or withdraw money because someone claims your account is part of an investigation.\n * If someone unexpectedly comes to your home claiming to represent your bank, don't give them your card, PIN, cash or personal information.\n * Discuss new scams with your family. Parents, grandparents and other relatives should know about emerging tactics before they're confronted with them.\n\n\nHow does the bank card collection scam work?\n\nSource\n\nAccording to Kent Police, the scheme can begin with a text message that looks like it comes from your bank.\n\nThe message asks if you recognize a supposedly suspicious transaction. This creates a sense of urgency and gives scammers a reason to contact you again.\n\nNext comes a phone call.\n\nThe criminal poses as a bank representative and claims your card has been compromised. Caller ID may even display what appears to be the bank's legitimate phone number.\n\nThat doesn't make the call genuine. Caller ID information can be spoofed, allowing scammers to disguise the number they're actually calling from.\n\nThen comes the twist that makes this scam stand out.\n\nThe supposed bank employee offers to send someone to your home to collect the compromised card and provide a temporary replacement.\n\nA person posing as a bank employee may subsequently arrive at the address, potentially wearing clothing intended to make the visit look legitimate.\n\nIt's a reminder that scammers aren't restricted to phishing emails, text messages or fraudulent websites. If a scheme requires someone to knock on your door to make the deception more believable, some criminals are willing to take that step.\n\nAnd if this sounds a bit familiar, that’s because it’s not the first time similar tactics have been used to steal people’s money.\n\nIf you’re a regular on our Hot for Security blog, you’ve probably read about a similar scheme. For example, in July 2025, we talked about gold-bar scams in which criminals impersonated government or law-enforcement officials and convinced victims to withdraw their savings, buy gold, and hand it to a supposed \"courier.\"\n\nNow, the scale of these schemes is becoming clearer. In August 2026, the NYPD warned that hundreds of victims may have lost more than $100 million to gold-bar scams. In many cases, a courier reportedly showed up at the victim's home to collect the gold while another scammer remained on the phone.\n\n\nWhen an online scam follows you into the real world\n\nThere's another reason this particular type of scam deserves your attention.\n\nWe often think of online scams as having a degree of physical separation. The criminal is somewhere behind a screen, while you're behind yours.\n\nBut think about it like this:\n\n If criminals have your name, phone number, and home address, and you engage with their initial messages, they may learn even more about you before someone arrives at your door.\n\nAn in-person visit could potentially reveal additional information about your household:\n\n·         Who answers the door?\n\n·         Does an older person live alone?\n\n·         Are there other family members around?\n\n·         What security measures are visible?\n\n·         Is there a doorbell camera?\n\n·         Does the person appear particularly trusting or vulnerable?\n\nThere is no indication from the Kent Police warning that this scheme has led to burglaries or home invasions. Still, allowing someone involved in a scam to visit your home creates a physical-security concern that doesn't exist with an ordinary phishing email.\n\nAnd there's a broader issue worth considering. If criminals know that someone has already responded to one scam, what's stopping them from trying again?\n\nScam victims can be targeted repeatedly, sometimes through completely different approaches. That's one more reason to treat an incident like this as more than a compromised bank card.\n\nAnd let’s break down the part that makes this type of scam so convincing.\n\nFirst of all, these fraudsters don’t rely on a single trick to con people. They build credibility in multiple stages, using text messages to alert you, a phone call to confirm the “issue,” and personal information to establish trust.\n\nThen comes the solution to fix your problem: another person physically arriving at your door.\n\nEach step appears to confirm the one before it.\n\nThat's also why an unexpected call shouldn't be trusted simply because the caller knows something about you. Names, addresses, phone numbers, email addresses and other personal information can be obtained through data breaches, public records, social media, previous scams and other sources.\n\nAnd remember, knowing your name, bank or address doesn't prove someone is legitimate. Sometimes it simply means a scammer has done their homework.\n\n\nWill a bank come to your house to collect a compromised card?\n\nDefinitely Not! A request to hand a payment card to someone arriving at your home should immediately raise alarm bells.\n\nIf your card really has been compromised, stop communicating with the person who contacted you and independently contact your bank.\n\nUse the official banking app, visit a branch, or call the verified telephone number printed on your card or published on the bank's official website.\n\nDon't use a phone number or link supplied in the suspicious text message.\n\nPolice also warn that legitimate banks and law enforcement agencies won't tell you to withdraw or move money because it's supposedly needed for an investigation.\n\nRequests to transfer your savings to a \"safe account,\" withdraw cash for safekeeping, hand over a bank card, or give someone your PIN are also major warning signs.\n\n\nWhat if someone claiming to be from your bank comes to your door?\n\nDon't hand over your card, cash, PIN, account credentials or identification documents.\n\nRemember, you don't have to continue the conversation simply because someone is standing at your door.\n\nDon't let the visitor inside. Close the door and contact your bank independently. If the person refuses to leave, behaves aggressively or makes you feel unsafe, contact local law enforcement.\n\nUniforms, badges, branded clothing and caller ID can all be used to create an appearance of legitimacy. Verification should happen through a communication channel you choose, not one provided by the person asking for your money or card.\n\n\nWhat should you do if you receive a suspicious bank text?\n\nIf you receive an unexpected fraud alert, don't panic. A few simple steps can help you determine whether there's actually a problem:\n\n * Don't click links in the message. Open your banking app yourself or type the bank's official website into your browser.\n * Don't continue an unexpected call. Hang up and contact the bank using a verified number.\n * Never reveal your PIN, password or verification codes.\n * Don't move money to protect it. Anyone urgently instructing you to transfer or withdraw your savings because your account is supposedly under attack should be treated with suspicion.\n * Never hand your card to an unexpected visitor.\n * Check your account. Look for transactions, transfers or changes you don't recognize.\n\nYou can also check suspicious messages with Bitdefender Scamio and inspect questionable URLs with Bitdefender Link Checker before interacting with them.\n\n\nMake scam awareness a family conversation\n\nThere's one security resource every family already has: each other.\n\nDon't wait until a parent or grandparent receives a suspicious phone call to explain how these scams work. Talk about new tactics when you hear about them.\n\nConsider making scam awareness a small monthly family habit. It doesn't need to be a cybersecurity lecture. Spend ten minutes talking about one or two scams you've recently encountered or read about. Show parents and grandparents examples of suspicious texts. Remind everyone that caller ID can be spoofed and that legitimate organizations won't pressure them into immediately handing over money, cards or passwords.\n\nMost importantly, agree on a simple family rule: If something feels strange, urgent or frightening, call someone you trust before doing anything.\n\nThat conversation becomes even more important as scammers combine digital and real-world tactics. Protecting a family today isn't just about securing individual devices. It's about protecting the accounts, identities, money and personal information connected to everyone in the household.\n\nBitdefender's family plans are designed around that broader idea of protecting your entire digital life across the people and devices that matter to you. Combined with regular conversations about scams, technology can provide another layer of protection when fraudulent messages, malicious links and other threats reach family members.\n\n\nAlready handed over your card? Act quickly\n\nIf you've given your card, PIN or banking information to someone you now suspect is a scammer, contact your bank immediately.\n\nAsk the bank to block the card and review the account for unauthorized transactions. Change compromised online-banking credentials and check whether unfamiliar beneficiaries, transfers or contact details have been added.\n\nIf you've shared passwords that you also use elsewhere, change those accounts too and use unique passwords going forward.\n\nReport the incident to local law enforcement and preserve text messages, phone numbers, screenshots, transaction records and any available doorbell or security-camera footage.\n\nBecause the scammers may now have your home address and know that someone at the address responded to their scheme, make sure everyone in the home knows what happened. Be particularly cautious about unexpected visitors, calls or follow-up messages.\n\n\nFAQs\n\n\nWould a scammer come to your house?\n\nYes. While many scams happen entirely through calls, texts, emails or websites, some schemes involve in-person couriers or scammers coming directly to a victim's home.\n\nThe FBI has warned about scams in which criminals impersonating government agencies, banks or tech-support companies convince victims to withdraw cash or buy gold before sending a courier to collect it.\n\n\nCan someone steal your money if they have your bank details?\n\nIt depends on what information they have. Knowing your bank's name or even some account information doesn't necessarily give a scammer direct access to your money, but those details can help them build a much more convincing attack.\n\nHowever, if a scammer has your bank account number and routing number, they may attempt unauthorized withdrawals or payments from your account.\n\nAdditionally, scammers may use information they already have to impersonate your bank and trick you into revealing passwords, card information, PINs or one-time verification codes. They may also persuade you to authorize a transfer yourself.\n\nIf you believe your banking information has been compromised, contact your bank immediately using its official app, website or the number printed on your card.\n\n\nShould I be worried if a scammer has my address?\n\nDon't panic, but take it seriously. Your home address alone usually isn't enough for someone to access your bank account, but scammers can combine it with other personal information to make future scams much more convincing.\n\nYour address can also be used for scams that reach your physical doorstep. In so-called brushing scams, for example, criminals or unscrupulous sellers send packages you never ordered to your home. More recently, the FBI and FTC have warned about a variation involving unsolicited packages containing QR codes. The recipient may be encouraged to scan the code to discover who sent the \"gift\" or how to return it, only to be directed to a phishing site designed to steal personal or financial information or potentially download malicious software.\n\nReceiving a strange package doesn't necessarily mean you're in immediate physical danger. But it does show why you shouldn't dismiss the fact that a scammer has your address. Be alert for follow-up calls and messages, unexpected packages and people showing up at your door, and make sure everyone in your household knows what's happening.\n\nAnd never scan a QR code in an unsolicited package simply because you're curious about who sent it.",tags:[{id:m,name:n,slug:o,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:e,name:f,slug:d,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:h,name:g,slug:g,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a}],authors:[{id:F,name:G,slug:H,profile_image:I,cover_image:a,bio:J,website:a,location:a,facebook:a,twitter:a,meta_title:a,meta_description:a}],excerpt:az,url:aA},{id:aB,title:aC,slug:aD,feature_image:aE,featured:c,published_at:aF,custom_excerpt:R,plaintext:"Valve warns Steam users not to accept gifts from people they don't know, but the practice remains common enough that the company specifically flags it as a potential source of fraud.\n\nUnsolicited games can be linked to payment-card fraud, phishing, or item-trading scams. These problems don’t always involve an obvious fake. A stranger offers you a free game, then claim they sent a gift by mistake, or direct the recipient to a page that supposedly lets them accept it.\n\nEach approach aims to turn this apparently benign interaction into something more valuable for the scammer: a Steam login, rare in-game items, a payment, or a way to convert a fraudulent purchase into legitimate value.\n\n\nKey takeaways\n\n * Decline Steam gifts from people you don't know, even when the offer appears genuine\n * Never use a link in a chat, email, or Discord message to “accept” a gift or verify your account\n * A gift may be bait for a trade, a fake refund request, or an attempt to launder money from payment-card fraud\n\n\n\nWhy would a scammer send a Steam gift?\n\nSteam lets users send games as gifts—a handy feature when you want to send something to a friend or a family member. But scammers have weaponized the feature.\n\nAn unsolicited gift from someone you don’t know can open a conversation, create a sense of obligation or make an unfamiliar account seem credible before the sender asks for something of greater value.\n\nThe clearest financial motive involves payment fraud. A scamer can buy a game with a stolen card, send it to another account, then ask the recipient for cash, Steam items, skins, cryptocurrency, or another gift.\n\nThat exchange turns a fraudulent purchase into value the criminal can keep or resell. If the payment is reversed, the recipient may lose the game and face questions about a fraudulent gift.\n\nValve's own account-restriction guidance is very clear: “Never accept a gift from an unknown user.” It specifically lists redeeming fraudulent gifts among conduct that can lead to account restrictions.\n\n\nHow Steam gift scams work\n\n\n1. The stolen-payment-card gift\n\nThe sender offers a game bought with a compromised card, then asks for something they can transfer or resell: an item trade, a wallet-code purchase or payment outside Steam.\n\nThe request may sound reasonable: “I bought the wrong game; send me the equivalent in skins,” or “Accept it and give me half the price.” It isn't a resale arrangement. The sender keeps the clean value while the recipient becomes connected to the disputed purchase.\n\n\n2. The ‘I sent it by mistake’ trade scam\n\nOther scammers use a small, real gift to establish credibility. Later, they claim they sent something expensive by mistake or need help reversing a transaction. They may demand rare CS2, Dota 2, or Team Fortress 2 items as “compensation.”\n\nThey rely on pressure: accusations of theft, threats to report the account or an invented deadline.\n\n\n3. The fake Steam gift link\n\nSometimes there is no gift at all. A message may claim one is waiting, say Steam needs an age check, or require a login to view the sender's profile. The link can lead to a copy of Steam built to collect a username, password, Steam Guard code, or QR-code approval.\n\nWith access to an account, attackers can empty inventory, lock out the owner and message friends from a familiar profile.\n\n\n4. The trust-building setup\n\nA small gift can also make the sender appear friendly. After a few messages, they may pitch a “sponsor” offer, a tournament, a high-value trade or a supposed Steam Support investigation. They may also push the conversation to Discord or other platforms, away from the context in which the offer began.\n\nValve says its employees never discuss account issues through Steam Chat or Discord. Anyone who claims to be Valve or Steam Support and asks you to verify items should be reported for trade scams.\n\n\nHow to tell a real Steam gift from a scam\n\nIf you don't know the sender, decline the gift. This is the most effective way to ensure you stay safe and that your account won’t be affected by possible bans.\n\nFor gifts from actual friends or family, verify the situation independently. Ask the person via a separate method whether they sent it, especially if their account suddenly writes in an unusual tone or asks you to click a link.\n\nWarning signs include:\n\n * The sender is an unfamiliar account or recently added you as a friend\n * The message creates urgency: “Accept in five minutes” or “your account will be banned”\n * The sender wants payment, skins, Steam Wallet codes, crypto, or another gift in return\n * The sender asks you to move to Discord, Telegram, or another platform\n * A link asks for your Steam password, Steam Guard code, QR scan, or other login approval\n * Someone claims to be a Valve employee and demands that you trade or “verify” your items\n\n\nA real gift doesn't require payment to a stranger, login credentials or a detour outside Steam's ecosystem. Open Steam yourself to check account notifications and support information.\n\n\nWhat to do if an unknown account sends you a gift\n\n1. Don't accept or redeem it. Decline the offer.\n\n2. Don't negotiate. Don't send money or items to “return” a mistaken gift.\n\n3. Block and report the account. Preserve screenshots if the sender used threats, links, or impersonation.\n\n4. Open Steam Support yourself. Type the address or use the support option within Steam; don't follow the sender's link.\n\n5. Tell friends who may receive the same message. Compromised accounts often contact people from an existing friend list.\n\n\n\nWhat to do if you clicked a link or accepted the gift\n\nIf you only received an unsolicited gift and took no action, decline it and cut contact. If you typed credentials into a suspicious page, approved a Steam Guard prompt, scanned a QR code, or traded items, act quickly.\n\n * Change your Steam password from the official Steam website or client\n * Review Steam Guard and remove any unfamiliar devices or authorizations\n * Check recent trades, market listings, and account activity for anything you didn't approve\n * Use the official Steam Support site to report account compromise or an item scam\n * Change the password on the email account linked to Steam if you reused credentials or believe it may be exposed\n\n\nEnable Steam Guard and use a unique password for Steam. Multi-factor authentication makes it harder for an attacker to enter an account even after obtaining a password, according to the FTC.\n\n\nFAQ\n\n\nIs it safe to accept a Steam gift from a stranger?\n\nAnswer: No. Valve specifically advises users never to accept gifts from unknown users.\n\n\nCan someone steal my Steam account by sending a gift?\n\nAnswer: A gift notification alone doesn't give someone access to your account.\n\n\nWhat happens if a Steam gift was bought with a stolen card?\n\nAnswer: The payment can be disputed and reversed. Valve says redeeming fraudulent gifts can lead to account restrictions, so don't accept gifts from unknown accounts.\n\n\nDoes Steam Support contact users on Discord?\n\nAnswer: No. Valve says Steam employees won't communicate about account issues through chat systems, including Steam Chat and Discord.\n\n\nShould I repay someone who says they sent me a Steam gift by mistake?\n\nAnswer: Don't send money, items, gift cards, or cryptocurrency. Decline the gift, block the sender, and report suspicious conduct through Steam.",tags:[{id:m,name:n,slug:o,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:e,name:f,slug:d,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:h,name:g,slug:g,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a}],authors:[{id:p,name:q,slug:r,profile_image:s,cover_image:t,bio:u,website:a,location:a,facebook:a,twitter:a,meta_title:a,meta_description:a}],excerpt:R,url:aG}],postsWhite:[{id:aH,title:aI,slug:aJ,feature_image:aK,featured:c,published_at:aL,custom_excerpt:a,html:aM,tags:[{id:i,name:j,slug:k,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:e,name:f,slug:d,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a}],authors:[{id:z,name:A,slug:B,profile_image:C,cover_image:a,bio:D,website:a,location:a,facebook:a,twitter:a,meta_title:a,meta_description:a}],excerpt:aN,reading_time:S,url:aO},{id:aP,title:aQ,slug:aR,feature_image:aS,featured:c,published_at:aT,custom_excerpt:a,html:aU,tags:[{id:i,name:j,slug:k,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:T,name:U,slug:V,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:e,name:f,slug:d,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a}],authors:[{id:z,name:A,slug:B,profile_image:C,cover_image:a,bio:D,website:a,location:a,facebook:a,twitter:a,meta_title:a,meta_description:a}],excerpt:aV,reading_time:S,url:aW},{id:"6a8582308beeea96580290a6",title:"Update your iPhone and Mac! Apple patches image flaw with spyware potential",slug:"update-iphone-mac-image-flaw-spyware-potential",feature_image:"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002Fapple-products.jpg",featured:c,published_at:"2026-08-19T13:22:48.000+03:00",custom_excerpt:a,html:"\u003Cp\u003EApple has rolled out security updates for iPhones, iPads and Macs addressing a potentially dangerous vulnerability in its image-processing framework – the kind of flaw that has historically been useful to makers of sophisticated mobile spyware.\u003C\u002Fp\u003E\u003Ch2 id=\"key-takeaways\"\u003EKey takeaways\u003C\u002Fh2\u003E\n\u003Cul\u003E\n\u003Cli\u003EApple patched an integer-overflow vulnerability in its ImageIO image-processing framework\u003C\u002Fli\u003E\n\u003Cli\u003EProcessing a malicious image could allow arbitrary code execution on an affected device\u003C\u002Fli\u003E\n\u003Cli\u003EImage-processing vulnerabilities have played a role in sophisticated zero-click spyware campaigns\u003C\u002Fli\u003E\n\u003Cli\u003EThe flaw was reported by Nik Tsytsarkin of Meta's Red Team X\u003C\u002Fli\u003E\n\u003Cli\u003EThere is currently no public confirmation that CVE-2026-65346 has been exploited in real-world spyware attacks\u003C\u002Fli\u003E\n\u003Cli\u003EApple users are advised to install the latest OS updates as soon as possible\u003C\u002Fli\u003E\n\u003C\u002Ful\u003E\n\u003Ch2 id=\"an-image-processing-vulnerability\"\u003EAn image-processing vulnerability\u003C\u002Fh2\u003E\u003Cp\u003E\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003ECVE-2026-65346\u003C\u002Fstrong\u003E is an \u003Cstrong\u003Einteger-overflow vulnerability \u003C\u002Fstrong\u003Ein \u003Cstrong\u003EImageIO\u003C\u002Fstrong\u003E, an Apple framework responsible for reading and processing image data.\u003C\u002Fp\u003E\u003Cp\u003EThe vulnerability affects Apple's ImageIO framework across its entire product lineup and could allow arbitrary code execution when a vulnerable device processes a maliciously crafted image.\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003EApple patched the issue in updates released Aug. 17\u003C\u002Fstrong\u003E, including iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, and iOS 18.7.10 and iPadOS 18.7.10.\u003C\u002Fp\u003E\u003Cp\u003EWhile Apple has not said the vulnerability has been exploited in the wild, its location and potential impact make it noteworthy. Image-processing vulnerabilities have been used as components of earlier \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fwhatsapp-zero-click-spyware-attack-android\"\u003E\u003Cstrong\u003Ezero-click spyware attacks\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E, where victims can be compromised without opening a malicious attachment or knowingly interacting with an attacker.\u003C\u002Fp\u003E\u003Cp\u003E\u003Ca href=\"https:\u002F\u002Fsupport.apple.com\u002Fen-us\u002F100100\"\u003EAccording to\u003C\u002Fa\u003E Apple's security advisory, processing an image on a vulnerable device may lead to arbitrary code execution. Apple says it addressed the vulnerability through improved input validation. The company credits \u003Cstrong\u003ENik Tsytsarkin of Meta Red Team X\u003C\u002Fstrong\u003E with reporting it.\u003C\u002Fp\u003E\u003Cp\u003EThe vulnerability affects iPhone 11 and later, along with iPad Pro, iPad Air, iPad and iPad mini models. It also affects macOS Tahoe.\u003C\u002Fp\u003E\u003Ch2 id=\"can-be-leveraged-in-spyware-attacks\"\u003ECan be leveraged in spyware attacks\u003C\u002Fh2\u003E\u003Cp\u003E\u003C\u002Fp\u003E\u003Cp\u003EThere is no evidence disclosed so far that CVE-2026-65346 has been used to deploy spyware.\u003C\u002Fp\u003E\u003Cp\u003EHowever, researchers are \u003Ca href=\"https:\u002F\u002Fwww.theregister.com\u002Fsecurity\u002F2026\u002F08\u002F18\u002Fapple-plugs-image-processing-hole-ripe-for-spyware-abuse\u002F5289031\"\u003Epaying attention\u003C\u002Fa\u003E because vulnerabilities in image-processing components have been exploited in highly sophisticated attacks in the past.\u003C\u002Fp\u003E\u003Cp\u003EOne of the best-known examples is \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fforcedentry-exploit-is-the-ultimate-cyberweapon-researchers-say\"\u003E\u003Cstrong\u003EFORCEDENTRY\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E, an exploit used to deliver NSO Group's Pegasus spyware. The attack exploited Apple's image-processing technology and allowed malicious content delivered through iMessage to compromise devices without victims clicking a link.\u003C\u002Fp\u003E\u003Cp\u003EAnother sophisticated campaign, \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fapple-issues-emergency-updates-to-combat-triangulation-spyware\"\u003E\u003Cstrong\u003EOperation Triangulation\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E, also relied on zero-click techniques delivered through Apple's messaging ecosystem.\u003C\u002Fp\u003E\u003Cp\u003EThese attacks demonstrate why \u003Cstrong\u003Evulnerabilities in components that automatically process incoming content are invaluable to spyware operators\u003C\u002Fstrong\u003E.\u003C\u002Fp\u003E\u003Cp\u003EIt’s not necessary that a victim fall for a phishing message. In a zero-click attack, receiving specially crafted content may be enough to start an exploitation chain.\u003C\u002Fp\u003E\u003Ch2 id=\"apple-hasnt-reported-active-exploitation\"\u003EApple hasn't reported active exploitation\u003C\u002Fh2\u003E\u003Cp\u003E\u003C\u002Fp\u003E\u003Cp\u003EWhile the vulnerability has characteristics that could make it useful in sophisticated attacks, it isn’t a zero-day known to be under active attack – i.e. Apple doesn’t say it has actually been exploited.\u003C\u002Fp\u003E\u003Cp\u003EBut that doesn’t mean attackers aren’t doing so now. So it’s advisable to apply this patch soon.\u003C\u002Fp\u003E\u003Ch2 id=\"apples-update-fixes-more-than-imageio\"\u003EApple's update fixes more than ImageIO\u003C\u002Fh2\u003E\u003Cp\u003E\u003C\u002Fp\u003E\u003Cp\u003ECVE-2026-65346 isn't the only security problem addressed in Apple's latest updates.\u003C\u002Fp\u003E\u003Cp\u003EThe patched vulnerabilities affect components including Audio, ImageIO, IOGPUFamily, Kernel, Telephony and WebKit. The consequences of the issues could range from information disclosure and crashes to memory corruption and code execution.\u003C\u002Fp\u003E\u003Cp\u003EAnother notable issue is \u003Cstrong\u003ECVE-2026-65329\u003C\u002Fstrong\u003E, an authentication vulnerability in Apple's Telephony component.\u003C\u002Fp\u003E\u003Cp\u003EAccording to Apple, an attacker in a privileged network position could bypass IPsec authentication and intercept network traffic. Apple addressed the vulnerability with improved state management.\u003C\u002Fp\u003E\u003Cp\u003EThe update also includes multiple fixes for WebKit, the browser engine powering Safari and web content across Apple's platforms.\u003C\u002Fp\u003E\u003Cp\u003EApple additionally released \u003Cstrong\u003EiOS 18.7.10 and iPadOS 18.7.10\u003C\u002Fstrong\u003E for older hardware unable to run iOS 26, including devices such as the iPhone XS, XS Max and XR.\u003C\u002Fp\u003E\u003Ch2 id=\"how-apple-users-can-stay-safe\"\u003EHow Apple users can stay safe\u003C\u002Fh2\u003E\u003Cp\u003E\u003C\u002Fp\u003E\u003Cp\u003EFor most people, the key response is straightforward: \u003Cstrong\u003Einstall Apple's latest security updates promptly\u003C\u002Fstrong\u003E.\u003C\u002Fp\u003E\u003Cp\u003EOn an iPhone or iPad, go to \u003Cstrong\u003ESettings &gt; General &gt; Software Update\u003C\u002Fstrong\u003E and install the latest version available for your device.\u003C\u002Fp\u003E\u003Cp\u003EMac users can check \u003Cstrong\u003ESystem Settings &gt; General &gt; Software Update\u003C\u002Fstrong\u003E.\u003C\u002Fp\u003E\u003Cp\u003EUsers should also consider these precautions:\u003C\u002Fp\u003E\u003Cul\u003E\u003Cli\u003E\u003Cstrong\u003EEnable automatic updates.\u003C\u002Fstrong\u003E Keeping automatic updates enabled reduces the time your device remains exposed after security patches become available.\u003C\u002Fli\u003E\u003Cli\u003E\u003Cstrong\u003EDon't postpone security updates.\u003C\u002Fstrong\u003E Vulnerabilities become much more useful to attackers once patches reveal that a weakness exists.\u003C\u002Fli\u003E\u003Cli\u003E\u003Cstrong\u003EKeep messaging and browser apps updated.\u003C\u002Fstrong\u003E These applications often process content from potentially untrusted sources.\u003C\u002Fli\u003E\u003Cli\u003E\u003Cstrong\u003EBe alert to unusual device behavior.\u003C\u002Fstrong\u003E Unexpected crashes, unexplained battery drain or other anomalies aren't proof of spyware, but persistent suspicious behavior warrants investigation.\u003C\u002Fli\u003E\u003Cli\u003E\u003Cstrong\u003EHigh-risk users should consider Lockdown Mode.\u003C\u002Fstrong\u003E Apple provides Lockdown Mode for people who believe they may be targeted by highly sophisticated digital threats.\u003C\u002Fli\u003E\u003Cli\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Ftotal-security\"\u003E\u003Cstrong\u003ERun an independent security solution\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E on your iPhone, iPad or Mac to add another layer of security.\u003C\u002Fli\u003E\u003C\u002Ful\u003E\u003Cp\u003ECVE-2026-65346 is a reminder that something as ordinary as an image can become an attack surface.\u003C\u002Fp\u003E\u003Cp\u003EThere is currently no public evidence that attackers have exploited the vulnerability to deploy spyware, and users shouldn't assume that every malicious image could compromise an iPhone. But previous campaigns involving mercenary spyware have demonstrated why vulnerabilities in automatically processed content deserve attention.\u003C\u002Fp\u003E\u003Cp\u003EApple has released the fix. Installing it is the simplest way to remove the risk posed by this particular vulnerability.\u003C\u002Fp\u003E\u003Cp\u003E\u003Cem\u003EYou may also like:\u003C\u002Fem\u003E\u003C\u002Fp\u003E\u003Cp\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fmacos-screen-sharing-flaw-exploited-crypto-miner-hack\"\u003E\u003Cstrong\u003E\u003Cem\u003EmacOS ‘Screen Sharing’ flaw exploited for crypto-mining\u003C\u002Fem\u003E\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E\u003C\u002Fp\u003E\u003Cp\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fwhatsapp-new-spyware-israel-nso-group\"\u003E\u003Cstrong\u003E\u003Cem\u003EWhatsApp detects new spyware activity from Israel’s NSO Group despite court order\u003C\u002Fem\u003E\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E\u003C\u002Fp\u003E\u003Cp\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fzero-day-phone-hacks-spyware-phone\"\u003E\u003Cstrong\u003E\u003Cem\u003EZero-day phone hacks: how spyware slips into your device before anyone knows\u003C\u002Fem\u003E\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E\u003C\u002Fp\u003E",tags:[{id:i,name:j,slug:k,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:e,name:f,slug:d,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a}],authors:[{id:ae,name:af,slug:ag,profile_image:ah,cover_image:a,bio:ai,website:a,location:a,facebook:a,twitter:a,meta_title:a,meta_description:a}],excerpt:"Apple has rolled out security updates for iPhones, iPads and Macs addressing a potentially dangerous vulnerability in its image-processing framework – the kind of flaw that has historically been useful to makers of sophisticated mobile spyware.\n\n\nKey takeaways\n\n\n * Apple patched an integer-overflow vulnerability in its ImageIO image-processing framework\n * Processing a malicious image could allow arbitrary code execution on an affected device\n * Image-processing vulnerabilities have played a rol",reading_time:W,url:"\u002Fblog\u002Fhotforsecurity\u002Fupdate-iphone-mac-image-flaw-spyware-potential\u002F"}],postsBlack:[{id:"6a84658d8beeea9658028f40",title:"French tax authority breach exposes data of 678,000 people and businesses",slug:"france-dgfip-data-breach-678000-affected",feature_image:"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002FFrench-tax-authority-breach-exposes-data-of-678-000-people-and-businesses.png",featured:c,published_at:"2026-08-18T17:55:10.000+03:00",custom_excerpt:a,html:"\u003Cp\u003EFrance's tax authority has confirmed a major data breach affecting 678,000 individuals and professionals after cybercriminals gained access to systems of the Direction générale des Finances publiques (DGFiP).\u003C\u002Fp\u003E\u003Cp\u003EThe disclosure came after a threat actor publicly claimed responsibility for the attack and advertised allegedly stolen DGFiP information on a cybercrime forum.\u003C\u002Fp\u003E\u003Ch2 id=\"key-takeaways\"\u003EKey takeaways\u003C\u002Fh2\u003E\u003Cul\u003E\u003Cli\u003E678,000 individuals and professionals are confirmed to have been affected\u003C\u002Fli\u003E\u003Cli\u003EAttackers accessed tax and property-related information, including reference taxable income, family quotient, withholding tax rates, property addresses and property sizes\u003C\u002Fli\u003E\u003Cli\u003EFor businesses, exposed information included company names and SIREN identification numbers\u003C\u002Fli\u003E\u003Cli\u003EDGFiP says users' online tax accounts were not compromised, and usernames and passwords belonging to individuals and businesses were not exposed\u003C\u002Fli\u003E\u003Cli\u003EAffected users can expect to be contacted directly by DGFiP by email or postal mail, with information about what data may have been accessed or stolen\u003C\u002Fli\u003E\u003C\u002Ful\u003E\u003Ch2 id=\"what-happened-in-the-dgfip-data-breach\"\u003EWhat happened in the DGFiP data breach?\u003C\u002Fh2\u003E\u003Cp\u003EAccording to the French government, the attacker gained access to DGFiP information systems in June and July using compromised credentials.\u003C\u002Fp\u003E\u003Cp\u003EDGFiP says it terminated access for the accounts involved after detecting the intrusions. However, initial access checks did not reveal that data had also been stolen, which authorities attributed to the attack's sophistication.\u003C\u002Fp\u003E\u003Cp\u003EFollowing claims made by the attacker on August 12 and 13, investigators conducted a deeper analysis and determined that the unauthorized access had been used to view and extract information belonging to \u003Cstrong\u003E678,000 people and professionals\u003C\u002Fstrong\u003E.\u003C\u002Fp\u003E\u003Cp\u003EThe \u003Ca href=\"https:\u002F\u002Fpresse.economie.gouv.fr\u002Facces-illegitime-au-systeme-dinformation-de-la-direction-generale-des-finances-publiques\u002F\"\u003Eincident\u003C\u002Fa\u003E is now being investigated by France's national cybersecurity agency, ANSSI. DGFiP has also notified the French data protection authority, CNIL, and said it will file a criminal complaint.\u003C\u002Fp\u003E\u003Ch2 id=\"what-information-was-exposed\"\u003EWhat information was exposed?\u003C\u002Fh2\u003E\u003Cp\u003EThe confirmed compromised information includes some sensitive financial and tax-related details.\u003C\u002Fp\u003E\u003Cp\u003EFor individuals, the exposed data includes \u003Cstrong\u003Ereference taxable income, family quotient and withholding tax rates\u003C\u002Fstrong\u003E. Cadastral information was also accessed, including \u003Cstrong\u003Eproperty addresses and property sizes\u003C\u002Fstrong\u003E.\u003C\u002Fp\u003E\u003Cp\u003EFor businesses, the stolen information may include \u003Cstrong\u003Ecompany names and SIREN numbers\u003C\u002Fstrong\u003E.\u003C\u002Fp\u003E\u003Cp\u003EImportantly, DGFiP says personal and professional accounts available through its online services were \u003Cstrong\u003Enot compromised\u003C\u002Fstrong\u003E and users' usernames and passwords were not stolen.\u003C\u002Fp\u003E\u003Ch2 id=\"what-should-affected-users-expect\"\u003EWhat should affected users expect?\u003C\u002Fh2\u003E\u003Cp\u003EDGFiP says it will contact each affected individual and professional directly by email or postal mail. Those notifications should explain which information may have been stolen and provide recommendations on precautions users should take.\u003C\u002Fp\u003E\u003Cp\u003EEven without exposed passwords, however, the stolen information could create opportunities for highly convincing fraud.\u003C\u002Fp\u003E\u003Cp\u003ETax information, property details and other data can give scammers valuable context when impersonating tax authorities, banks or other organizations. Affected users should therefore be particularly cautious about unexpected messages claiming to come from DGFiP or another government service, especially those asking them to verify an account, provide additional information, follow a link or make a payment.\u003C\u002Fp\u003E\u003Ch2 id=\"how-can-you-stay-safe-after-the-dgfip-breach\"\u003EHow can you stay safe after the DGFiP breach?\u003C\u002Fh2\u003E\u003Cp\u003EIf you receive a notification from DGFiP, don’t panic. Read it carefully and check what information was affected. Keep in mind that scammers may also try to take advantage of news about the breach by sending fake notifications of their own.\u003C\u002Fp\u003E\u003Cp\u003EHere are a few precautions you can take:\u003C\u002Fp\u003E\u003Cul\u003E\u003Cli\u003E\u003Cstrong\u003EChange your password as a precaution.\u003C\u002Fstrong\u003E DGFiP says taxpayer usernames and passwords were not compromised. Still, consider updating the password you use for your tax account, particularly if you have used it on another website. Use a strong, unique password for every important account and enable two-factor authentication (2FA) wherever it's available.\u003C\u002Fli\u003E\u003Cli\u003E\u003Cstrong\u003EBe wary of breach-related scams.\u003C\u002Fstrong\u003E Watch for unexpected emails, texts or calls claiming to come from DGFiP, tax officials, banks or other government services. Criminals could potentially use stolen tax and property information to make their stories sound more convincing.\u003C\u002Fli\u003E\u003Cli\u003E\u003Cstrong\u003EDon't trust someone simply because they know information about you.\u003C\u002Fstrong\u003E Just because caller knows details about your finances, taxes or property doesn’t mean he’s legitimate. Never provide passwords, banking information or verification codes in response to an unsolicited request.\u003C\u002Fli\u003E\u003Cli\u003E\u003Cstrong\u003EDon't click first and investigate later.\u003C\u002Fstrong\u003E Be especially cautious with messages about tax refunds, unpaid taxes, compromised accounts or urgent verification requests. Instead of following the provided link, navigate directly to the organization's official website.\u003C\u002Fli\u003E\u003Cli\u003E\u003Cstrong\u003ECheck suspicious messages and links for free.\u003C\u002Fstrong\u003E If you're unsure whether something you've received is legitimate, ask \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fscamio\"\u003E\u003Cstrong\u003EBitdefender Scamio\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E, our free AI-powered scam detector, to analyze suspicious messages, emails, QR codes and links. You can also check suspicious URLs with the free \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Flink-checker\"\u003E\u003Cstrong\u003EBitdefender Link Checker\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E before opening them.\u003C\u002Fli\u003E\u003Cli\u003E\u003Cstrong\u003EKeep an eye on your exposed personal information.\u003C\u002Fstrong\u003E \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fdigital-identity-protection\"\u003E\u003Cstrong\u003EBitdefender Digital Identity Protection\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E helps you monitor your digital footprint and alerts you when your personal information is found in data breaches and leaks.\u003C\u002Fli\u003E\u003C\u002Ful\u003E\u003Cp\u003EAlso, remember that information stolen in a data breach can remain useful to criminals long after the initial incident. Tax, financial and property information could also be combined with data obtained from other breaches to build a more complete profile of a potential victim, making future phishing, impersonation and social engineering attempts harder to spot.\u003C\u002Fp\u003E",tags:[{id:T,name:U,slug:V,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:K,name:v,slug:L,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:e,name:f,slug:d,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a}],authors:[{id:F,name:G,slug:H,profile_image:I,cover_image:a,bio:J,website:a,location:a,facebook:a,twitter:a,meta_title:a,meta_description:a}],excerpt:"France's tax authority has confirmed a major data breach affecting 678,000 individuals and professionals after cybercriminals gained access to systems of the Direction générale des Finances publiques (DGFiP).\n\nThe disclosure came after a threat actor publicly claimed responsibility for the attack and advertised allegedly stolen DGFiP information on a cybercrime forum.\n\n\nKey takeaways\n\n * 678,000 individuals and professionals are confirmed to have been affected\n * Attackers accessed tax and prope",reading_time:X,url:"\u002Fblog\u002Fhotforsecurity\u002Ffrance-dgfip-data-breach-678000-affected\u002F"},{id:"6a8462c18beeea9658028f25",title:"Phone number leaked in the Bloctel breach? Here’s what to do.",slug:"bloctel-data-breach-phone-numbers-leaked",feature_image:"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002FPhone-number-leaked-in-the-Bloctel-breach-Here-s-what-to-do..png",featured:c,published_at:"2026-08-18T16:56:31.000+03:00",custom_excerpt:a,html:"\u003Cp\u003EIf you’re a French citizen who registered your phone number with Bloctel to avoid unwanted marketing calls, you may want to be extra careful about unexpected calls and messages.\u003C\u002Fp\u003E\u003Cp\u003EFrance's Directorate General for Competition Policy, Consumer Affairs and Fraud Control (DGCCRF) has warned that a cybercriminal obtained files containing 3 million phone numbers, including 600,000 registered with Bloctel.\u003C\u002Fp\u003E\u003Ch2 id=\"key-takeaways\"\u003EKey takeaways\u003C\u002Fh2\u003E\u003Cul\u003E\u003Cli\u003E3 million phone numbers were exposed, including around 600,000 registered with Bloctel\u003C\u002Fli\u003E\u003Cli\u003ENames, addresses and other personal information were not exposed in this incident, according to French authorities\u003C\u002Fli\u003E\u003Cli\u003ECriminals could combine leaked phone numbers with information from previous data breaches or other sources to identify and target individuals\u003C\u002Fli\u003E\u003Cli\u003EAffected users should be wary of suspicious calls, texts, password-reset requests and unexpected SIM changes\u003C\u002Fli\u003E\u003Cli\u003EBloctel officially closed on Aug. 11 as France moved to an opt-in system for commercial telephone calls\u003C\u002Fli\u003E\u003C\u002Ful\u003E\u003Ch2 id=\"how-can-a-leaked-phone-number-still-be-useful-to-scammers\"\u003EHow can a leaked phone number still be useful to scammers?\u003C\u002Fh2\u003E\u003Cp\u003EA phone number on its own provides relatively little information. The problem is that criminals don't use information from just one breach.\u003C\u002Fp\u003E\u003Cp\u003ENames, email addresses, passwords, dates of birth, addresses and other personal information have been exposed in countless previous data breaches.\u003C\u002Fp\u003E\u003Cp\u003EIf your phone number appears in one leaked dataset and your name or email address appears in another, criminals may connect the dots. They can also search social media, public records and other online sources for additional information.\u003C\u002Fp\u003E\u003Cp\u003EAnd if they still don't know enough about you, they may simply try to get you to reveal it.\u003C\u002Fp\u003E\u003Cp\u003EA scammer might call pretending to represent your bank, mobile provider or another trusted organization. Knowing your phone number or a few other details collected from elsewhere can make the story considerably more convincing.\u003C\u002Fp\u003E\u003Ch2 id=\"what-should-affected-bloctel-users-watch-out-for\"\u003EWhat should affected Bloctel users watch out for?\u003C\u002Fh2\u003E\u003Cp\u003EThe \u003Ca href=\"https:\u002F\u002Fpresse.economie.gouv.fr\u002Fla-dgccrf-met-en-garde-les-consommateurs-a-la-suite-dune-fuite-de-donnees-sur-bloctel\u002F\"\u003EDGCCRF\u003C\u002Fa\u003E recommends being cautious about unknown calls and text messages, avoiding suspicious links and never disclosing personal information over the phone.\u003C\u002Fp\u003E\u003Cp\u003EConsumers should also watch for unusual activity they didn't initiate, particularly \u003Cstrong\u003ESIM card changes and password updates\u003C\u002Fstrong\u003E. If your phone number is used as the login identifier for an online service, the DGCCRF recommends changing your password.\u003C\u002Fp\u003E\u003Cp\u003EUnexpected authentication codes, password-reset messages and account recovery notifications should also get your attention.\u003C\u002Fp\u003E\u003Cp\u003EIf someone calls claiming to represent your bank, mobile operator or another company and asks for sensitive information, end the conversation and contact the organization yourself using an official phone number, website or app.\u003C\u002Fp\u003E\u003Ch2 id=\"put-some-extra-defenses-around-your-phone-number\"\u003EPut some extra defenses around your phone number\u003C\u002Fh2\u003E\u003Cp\u003EIf your phone number has been exposed, a few additional tools can help you spot suspicious activity and scams.\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003ECheck your digital footprint.\u003C\u002Fstrong\u003E \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fdigital-identity-protection\"\u003EBitdefender Digital Identity Protection\u003C\u002Fa\u003E can help you monitor your personal information and discover whether your data has been exposed. This can be particularly useful when a phone number may be linked to information leaked elsewhere.\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003ECheck suspicious messages before acting.\u003C\u002Fstrong\u003E If you receive an unexpected SMS, email, QR code or other suspicious communication, you can ask \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fscamio\"\u003EBitdefender Scamio\u003C\u002Fa\u003E to analyze it and help determine whether you're dealing with a scam.\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003ECheck unfamiliar phone numbers.\u003C\u002Fstrong\u003E If you receive a call from a number you don't recognize, \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Freverse-phone-lookup\"\u003EBitdefender Reverse Phone Lookup\u003C\u002Fa\u003E lets you check the number for signs of spam or scam activity before you decide whether to call back or engage with the caller.\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003EReduce unwanted and suspicious calls.\u003C\u002Fstrong\u003E \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fmobile-security-android\" rel=\"noreferrer\"\u003EBitdefender Mobile Security\u003C\u002Fa\u003E for Android includes \u003Cstrong\u003ECall Blocking\u003C\u002Fstrong\u003E, which can automatically block known scam and spam callers. Its AI-powered detection can also identify suspicious calling patterns, including unusual or potentially spoofed numbers, while users can create their own block lists for unwanted callers.\u003C\u002Fp\u003E\u003Cp\u003ENo tool can prevent every fraudulent call, particularly when criminals continually change or spoof phone numbers. Treat these protections as another layer of defense alongside healthy skepticism about unexpected callers.\u003C\u002Fp\u003E\u003Ch2 id=\"bloctel-has-officially-closed\"\u003EBloctel has officially closed\u003C\u002Fh2\u003E\u003Cp\u003EThe incident arrived just before the end of Bloctel itself.\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003EBloctel officially closed on Aug. 11, 2026.\u003C\u002Fstrong\u003E France now operates under an opt-in system for commercial telephone calls. Instead of consumers having to register their refusal to receive marketing calls, businesses must generally obtain explicit, prior and traceable consent before calling and be able to prove that consent was given.\u003C\u002Fp\u003E\u003Cp\u003EConsumers who receive commercial calls without providing consent can report them through SignalConso, request that the company delete their information, and preserve evidence such as the caller's number and the date and time of the call.\u003C\u002Fp\u003E",tags:[{id:T,name:U,slug:V,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:K,name:v,slug:L,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:e,name:f,slug:d,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a}],authors:[{id:F,name:G,slug:H,profile_image:I,cover_image:a,bio:J,website:a,location:a,facebook:a,twitter:a,meta_title:a,meta_description:a}],excerpt:"If you’re a French citizen who registered your phone number with Bloctel to avoid unwanted marketing calls, you may want to be extra careful about unexpected calls and messages.\n\nFrance's Directorate General for Competition Policy, Consumer Affairs and Fraud Control (DGCCRF) has warned that a cybercriminal obtained files containing 3 million phone numbers, including 600,000 registered with Bloctel.\n\n\nKey takeaways\n\n * 3 million phone numbers were exposed, including around 600,000 registered with",reading_time:X,url:"\u002Fblog\u002Fhotforsecurity\u002Fbloctel-data-breach-phone-numbers-leaked\u002F"},{id:"6a7ae0d58beeea9658028a4a",title:"Identity Theft Prevention: How to Protect Your SSN & Credit",slug:"identity-theft-prevention",feature_image:"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002FIdentity-Theft-Prevention-How-to-Protect-Your-SSN---Credit.png",featured:c,published_at:"2026-08-11T11:53:54.000+03:00",custom_excerpt:a,html:"\u003Cp\u003EUS consumers lost $27.3 billion to identity theft and related fraud in 2025, according to Javelin Strategy &amp; Research's\u003Ca href=\"https:\u002F\u002Fjavelinstrategy.com\u002Fwhitepapers\u002F2026-identity-fraud-study-illusion-progress\"\u003E \u003C\u002Fa\u003E\u003Ca href=\"https:\u002F\u002Fjavelinstrategy.com\u002Fwhitepapers\u002F2026-identity-fraud-study-illusion-progress\"\u003E2026 Identity Fraud Study\u003C\u002Fa\u003E. Losses held roughly steady from the year before, when they had climbed 19%, yet the number of victims rose across every fraud category, with new-account fraud growing the fastest.\u003C\u002Fp\u003E\u003Cp\u003EMuch of the cost comes from a delay, since stolen data can circulate for years before it surfaces as a fraudulent account. Moreover, the\u003Ca href=\"https:\u002F\u002Fwww.idtheftcenter.org\u002F\"\u003E \u003C\u002Fa\u003EIdentity Theft Resource Center found that 80% of consumers received at least one data breach notice in the past year, often with no clear sense of what happened to the exposed information afterward. Sounds familiar?\u003C\u002Fp\u003E\u003Cp\u003EIdentity thieves are getting more efficient and more common. The Federal Trade Commission states that reports filed in the first nine months of 2025 already passed the full-year total for 2024.\u003C\u002Fp\u003E\u003Cp\u003EBut there are ways to protect your personal information, as most identity theft prevention is within your control. That is why this guide aims to cover the habits, monitoring, and services that reduce your exposure, and what to do the moment you suspect fraud.\u003C\u002Fp\u003E\u003Ch2 id=\"key-takeaways\"\u003EKey Takeaways\u003C\u002Fh2\u003E\u003Cp\u003E●&nbsp;&nbsp;&nbsp;&nbsp; \u003Cstrong\u003EIdentity theft and identity fraud are different problems.\u003C\u002Fstrong\u003E Theft is when someone steals your personal information, while fraud is what they do with it. Knowing which stage you are in tells you how to respond.\u003C\u002Fp\u003E\u003Cp\u003E●&nbsp;&nbsp;&nbsp;&nbsp; \u003Cstrong\u003EPrevention works in layers.\u003C\u002Fstrong\u003E Offline habits, strong account security, and monitoring each close a different gap. A protection service shortens the time a thief can operate before you catch it.\u003C\u002Fp\u003E\u003Cp\u003E●&nbsp;&nbsp;&nbsp;&nbsp; \u003Cstrong\u003EMonitoring catches fraud early, while a credit freeze stops it at the source.\u003C\u002Fstrong\u003E Especially in the US, freezing your credit is free and blocks most new credit accounts in your name. Monitoring alerts you when something gets through via your chosen financial institutions.\u003C\u002Fp\u003E\u003Cp\u003E●&nbsp;&nbsp;&nbsp;&nbsp; \u003Cstrong\u003EProtection works globally.\u003C\u002Fstrong\u003E Credit freezes are a US tool, but dark web monitoring, breach alerts, and data-privacy rights under laws like GDPR give people outside the US real options.\u003C\u002Fp\u003E\u003Ch2 id=\"what-identity-theft-is-and-why-it-differs-from-fraud\"\u003EWhat identity theft is, and why it differs from fraud\u003C\u002Fh2\u003E\u003Cfigure class=\"kg-card kg-image-card\"\u003E\u003Cimg src=\"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002Fimage-5.png\" class=\"kg-image\" alt=\"\" loading=\"lazy\" width=\"975\" height=\"650\" srcset=\"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002Fsize\u002Fw600\u002F2026\u002F08\u002Fimage-5.png 600w, https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002Fimage-5.png 975w\" sizes=\"(min-width: 720px) 720px\"\u003E\u003C\u002Ffigure\u003E\u003Cp\u003E\u003Ca href=\"https:\u002F\u002Funsplash.com\u002Fphotos\u002Fwhite-printer-paper-on-red-textile-xKmXZ4Fv63w\"\u003ESource\u003C\u002Fa\u003E\u003C\u002Fp\u003E\u003Cp\u003EIdentity theft and identity fraud describe two stages of the same crime, and they call for different responses.\u003C\u002Fp\u003E\u003Cp\u003E●&nbsp;&nbsp;&nbsp;&nbsp; Identity theft is the unauthorized capture of your personal information, such as your social security number, birth date, online account credentials, or credit card number.\u003C\u002Fp\u003E\u003Cp\u003E●&nbsp;&nbsp;&nbsp;&nbsp; Identity fraud is what criminals do with it, from opening new credit accounts to filing a false tax return or taking out loans in your name.\u003C\u002Fp\u003E\u003Cp\u003EKnowing which stage you are in tells you what to do next. For example, a leaked email address means you tighten passwords and turn on alerts. A fraudulent account already opened in your name means you start the recovery steps covered later in this guide.\u003C\u002Fp\u003E\u003Cp\u003EThieves also commit crimes with less than you would expect. A birth date from social media, an old address from a data breach, or a phone number from a leaked list can be enough to verify your identity somewhere and open the door.\u003C\u002Fp\u003E\u003Cp\u003ESome go further and combine real and fake details, sometimes using a child's unused Social Security number, to build a synthetic identity that goes undetected for years.\u003C\u002Fp\u003E\u003Ch2 id=\"how-thieves-get-your-identity-with-or-without-your-ssn-us-first\"\u003EHow thieves get your identity, with or without your SSN (US-first)\u003C\u002Fh2\u003E\u003Cp\u003EYou don't really need to lose your Social Security number to become a victim. Criminals build identities from whatever they can reach, and many of the most common routes never touch your SSN. For example, a name paired with an email, a birth date, an account number, and other personal information (seemingly harmless) can be enough to bypass initial identity verification layers.\u003C\u002Fp\u003E\u003Ch3 id=\"data-breaches-and-the-dark-web\"\u003EData breaches and the dark web\u003C\u002Fh3\u003E\u003Cp\u003EData breaches are a routine part of online life, and the exposure outlasts the notice. Stolen records can sit on the dark web for years, so a breach you have forgotten can resurface as fraud much later. Identity theft monitoring solutions scan the dark web for your exposed personal information and alert you when it shows up.\u003C\u002Fp\u003E\u003Cp\u003EPS: This is where a tool like\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fdigital-identity-protection\"\u003E \u003C\u002Fa\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fdigital-identity-protection\"\u003EBitdefender Digital Identity Protection\u003C\u002Fa\u003E can save you, as it scans the public web and dark web for leaks tied to your accounts, so you learn about exposure while you can still act on it.\u003C\u002Fp\u003E\u003Ch3 id=\"phishing-and-ai-powered-scams\"\u003EPhishing and AI-powered scams\u003C\u002Fh3\u003E\u003Cp\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fconsumer\u002Fsupport\u002Fanswer\u002F2204\u002F\"\u003EPhishing\u003C\u002Fa\u003E scams work by targeting your trust, not your device. Attackers impersonate banks or government agencies and use urgency to rush your judgment. So, make sure to keep one rule in mind: \u003Cstrong\u003Elegitimate companies never ask for personal information by email.\u003C\u002Fstrong\u003E Treat any unsolicited message that demands immediate action as suspect, and avoid clicking links in emails from unknown sources.\u003C\u002Fp\u003E\u003Cp\u003EBefore you enter sensitive data anywhere, check for https and the padlock symbol, and type bank URLs yourself instead of following a link. Scam messages have grown more convincing as attackers use AI to personalize them, so you need to use all the tools at your disposal to stay ahead.\u003C\u002Fp\u003E\u003Ch3 id=\"stolen-wallets-mail-and-physical-theft\"\u003EStolen wallets, mail, and physical theft\u003C\u002Fh3\u003E\u003Cp\u003EPlenty of theft happens offline, too. Think about what would happen if your wallet were stolen, your mailbox raided, or if someone found a discarded bank statement. Sometimes, these are enough to help a scammer impersonate you.\u003C\u002Fp\u003E\u003Cp\u003EMake sure to carry only essential items in your wallet and leave your Social Security card at home. Shred anything showing an account number or date of birth before you throw it out, and secure your mail if theft or other crimes are a risk where you live.\u003C\u002Fp\u003E\u003Ch3 id=\"public-wi-fi-and-unsecured-networks\"\u003EPublic Wi-Fi and unsecured networks\u003C\u002Fh3\u003E\u003Cp\u003EOn public Wi-Fi at an airport or cafe, someone on the same network can intercept your data in transit. Use a trusted virtual private network (like\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fvpn\"\u003E \u003C\u002Fa\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fvpn\"\u003EBitdefender's VPN\u003C\u002Fa\u003E) to encrypt your traffic before you log into any financial account or start shopping online, and keep your home Wi-Fi network locked down so it stays off the list of easy entry points.\u003C\u002Fp\u003E\u003Ch2 id=\"five-essential-ways-to-prevent-identity-theft\"\u003EFive essential ways to prevent identity theft\u003C\u002Fh2\u003E\u003Cp\u003ENo single step stops identity theft, so the strongest approach stacks a few habits that each close a different gap. Here are the five that give you the most protection for the least effort.\u003C\u002Fp\u003E\u003Ch3 id=\"1-lock-down-your-personal-information-offline\"\u003E1. Lock down your personal information offline\u003C\u002Fh3\u003E\u003Cp\u003EStart with what a thief can grab physically. Limit what you carry in your wallet to the cards you use, and keep your Social Security card at home. Shred bank statements, credit card statements, tax records, and pre-approved credit offers before you throw them out, since each one shows an account number or other details a thief can use. When a business or provider asks for your Social Security number, ask if they can accept another identifier instead. Share it only when it is legally required.\u003C\u002Fp\u003E\u003Ch3 id=\"2-use-strong-passwords-and-multi-factor-authentication\"\u003E2. Use strong passwords and multi-factor authentication\u003C\u002Fh3\u003E\u003Cp\u003EYour online accounts are only as safe as the passwords guarding them. Use different passwords for every account, each with at least eight characters and a mix of letters, numbers, and symbols.\u003C\u002Fp\u003E\u003Cp\u003EThen, use a password manager, which stores all your passwords so you only remember one master password. Then add multi-factor authentication on your sensitive accounts, especially email, banking, and social media. It is one of the highest-value habits you can build, since MFA blocks more than 99% of identity-based attacks, even when an attacker already has your password. Where you have the choice, use an authenticator app rather than SMS codes, as those can be intercepted.\u003C\u002Fp\u003E\u003Cp\u003EPS: We're offering a\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fpassword-generator\"\u003E \u003C\u002Fa\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fpassword-generator\"\u003Efree strong password generator\u003C\u002Fa\u003E to create airtight credentials.\u003C\u002Fp\u003E\u003Ch3 id=\"3-secure-your-devices-and-keep-them-updated\"\u003E3. Secure your devices and keep them updated\u003C\u002Fh3\u003E\u003Cfigure class=\"kg-card kg-image-card\"\u003E\u003Cimg src=\"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002Fimage-4.png\" class=\"kg-image\" alt=\"\" loading=\"lazy\" width=\"975\" height=\"640\" srcset=\"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002Fsize\u002Fw600\u002F2026\u002F08\u002Fimage-4.png 600w, https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002Fimage-4.png 975w\" sizes=\"(min-width: 720px) 720px\"\u003E\u003C\u002Ffigure\u003E\u003Cp\u003EUpdates patch the security holes that malware and spyware rely on, so turn on automatic updates for your phone, computer, and apps. Recent operating systems help here. Apple now turns on Stolen Device Protection for all iPhone users in iOS 26.4, which requires Face ID or Touch ID for sensitive actions when your phone is away from familiar places, and Android automatically resets permissions for apps you have stopped using. Back those settings with reputable antivirus software, and review app permissions so a flashlight app is not reaching your contacts or location.\u003C\u002Fp\u003E\u003Ch3 id=\"4-share-less-and-more-strategically-on-social-media\"\u003E4. Share less (and more strategically) on social media\u003C\u002Fh3\u003E\u003Cp\u003EAttackers mine social media for the details that verify your identity to commit fraud. A full birth date, a pet's name, a hometown, or a first school can double as an answer to a security question. Make sure to tighten your privacy settings so only people you trust can see your posts, and keep personal details like your birth date and address off public profiles.\u003C\u002Fp\u003E\u003Ch3 id=\"5-freeze-your-credit-and-set-fraud-alerts\"\u003E5. Freeze your credit and set fraud alerts\u003C\u002Fh3\u003E\u003Cp\u003EA credit freeze is the single strongest move against new-account fraud, and it is free by federal law in the US. A security freeze restricts access to your credit reports, so a lender who tries to open a new account cannot pull your file to approve it. Place one at each of the three major credit bureaus separately, since a freeze at one does not carry to the others. Requests placed online or by phone take effect within one business day, and you can lift a freeze in as little as an hour when you need to apply for credit yourself.\u003C\u002Fp\u003E\u003Cp\u003EIf you would rather keep your credit accessible, a fraud alert is the lighter option. It asks lenders to verify your identity before granting credit and lasts one year, or seven years if you are a confirmed victim. Parents can also freeze a child's credit file, which matters because a child's unused Social Security number is a prime target, and the misuse can go unnoticed for years and affect their credit history.\u003C\u002Fp\u003E\u003Ch2 id=\"how-to-protect-your-personal-identity-outside-the-us\"\u003EHow to protect your personal identity (outside the US)\u003C\u002Fh2\u003E\u003Cp\u003ECredit freezes, the FTC, and\u003Ca href=\"http:\u002F\u002Fidentitytheft.gov\"\u003E \u003C\u002Fa\u003E\u003Ca href=\"http:\u002F\u002Fidentitytheft.gov\"\u003EIdentityTheft.gov\u003C\u002Fa\u003E are US-specific, but the risk is global and so are the defenses. As of 2025, most countries have data-privacy laws on the books, from the GDPR across Europe and the UK to Brazil's LGPD and India's DPDP framework.\u003C\u002Fp\u003E\u003Cp\u003EUnder the GDPR, for example, you can ask any company what personal data it holds on you and request that it be deleted, which shrinks the pool of information a thief could exploit.\u003C\u002Fp\u003E\u003Cp\u003EThe monitoring layer works the same wherever you live. Dark web scanning, breach alerts, and password managers do not depend on a single credit system, which is why a globally available service matters outside the US.\u003C\u002Fp\u003E\u003Cp\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fdigital-identity-protection\"\u003EBitdefender Digital Identity Protection\u003C\u002Fa\u003E is available worldwide and maps your digital footprint, tracks which services hold your data, and alerts you in real time when your information leaks. For account-level fraud where local credit reporting exists, check whether your national credit bureau offers its own freeze or alert equivalent, since many now do.\u003C\u002Fp\u003E\u003Ch2 id=\"how-to-check-if-someone-is-using-your-identity-and-get-identity-theft-protection\"\u003EHow to check if someone is using your identity (and get identity theft protection)\u003C\u002Fh2\u003E\u003Cfigure class=\"kg-card kg-image-card\"\u003E\u003Cimg src=\"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002Fimage-3.png\" class=\"kg-image\" alt=\"\" loading=\"lazy\" width=\"975\" height=\"550\" srcset=\"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002Fsize\u002Fw600\u002F2026\u002F08\u002Fimage-3.png 600w, https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002Fimage-3.png 975w\" sizes=\"(min-width: 720px) 720px\"\u003E\u003C\u002Ffigure\u003E\u003Cp\u003E\u003Ca href=\"https:\u002F\u002Funsplash.com\u002Fphotos\u002Fa-man-sitting-in-front-of-a-computer-monitor-eaVaEMs9FQA\"\u003ESource\u003C\u002Fa\u003E\u003C\u002Fp\u003E\u003Cp\u003ERegular monitoring is how you catch fraud while it is still small, and the habit of learning to monitor your own accounts costs nothing. The fastest signals are free and already available to you:\u003C\u002Fp\u003E\u003Cp\u003E●&nbsp;&nbsp;&nbsp;&nbsp; Review your bank statements and credit card statements each month for charges you do not recognize, including small test financial transactions that thieves use to confirm a credit card works before a larger purchase.\u003C\u002Fp\u003E\u003Cp\u003E●&nbsp;&nbsp;&nbsp;&nbsp; Monitor for suspicious activity by setting up account alerts for transactions over a set amount, new payees, and changes to your contact details, so your bank tells you the moment something shifts.\u003C\u002Fp\u003E\u003Cp\u003E●&nbsp;&nbsp;&nbsp;&nbsp; Your credit file is the other place fraud shows up first. In the US, you are entitled to one free annual credit report from each of the three major credit bureaus (Equifax, Experian, and TransUnion) at\u003Ca href=\"http:\u002F\u002Fannualcreditreport.com\"\u003E \u003C\u002Fa\u003E\u003Ca href=\"http:\u002F\u002Fannualcreditreport.com\"\u003EAnnualCreditReport.com\u003C\u002Fa\u003E. Request one bureau every four months, and you get free coverage across the whole year. Read each report for accounts you did not open and inquiries you did not authorize, and dispute any error you find directly with the bureau that reported it.\u003C\u002Fp\u003E\u003Cp\u003ENow, monitoring services automate this watch and widen it, so you no longer have to monitor every statement by hand. Credit monitoring services notify you when your credit file changes, such as a new account or a hard inquiry, and identity monitoring services monitor and extend the same idea to the dark web and data breaches.\u003C\u002Fp\u003E\u003Cp\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fidentity-theft-protection\"\u003EBitdefender Identity Theft Protection\u003C\u002Fa\u003E combines both by tracking your credit alongside your identity and privacy, so a single alert covers a new credit line and a leaked record on the dark web.\u003C\u002Fp\u003E\u003Cp\u003EBut if you want to go a step ahead and really tighten your security,\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fultimate-security\"\u003E \u003C\u002Fa\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fultimate-security\"\u003EBitdefender Ultimate Security\u003C\u002Fa\u003E folds that identity protection into a wider layer of prevention, pairing the monitoring and recovery above with scam and email protection, a VPN, and device security that work to stop the phishing, malware, and data leaks that hand your details to thieves in the first place.\u003C\u002Fp\u003E\u003Ch2 id=\"what-to-do-if-you-suspect-identity-theft\"\u003EWhat to do if you suspect identity theft\u003C\u002Fh2\u003E\u003Cp\u003EIf someone has your Social Security number or you spot fraud in progress, move in order and keep records of phone calls and letters. Fast, organized action limits the damage.\u003C\u002Fp\u003E\u003Col\u003E\u003Cli\u003EFirst, contact the fraud department of any affected bank or card issuer. Freeze or close the compromised accounts, dispute the fraudulent charges and any unauthorized charges, and reset the passwords and multi-factor authentication on the linked online accounts.\u003C\u002Fli\u003E\u003Cli\u003ESecond, place a fraud alert with one of the major credit bureaus, which is free and legally required to be shared with the other two.\u003C\u002Fli\u003E\u003Cli\u003EThird, if you are in the US, file a report at\u003Ca href=\"http:\u002F\u002Fidentitytheft.gov\"\u003E \u003C\u002Fa\u003E\u003Ca href=\"http:\u002F\u002Fidentitytheft.gov\"\u003EIdentityTheft.gov\u003C\u002Fa\u003E, which builds you a personalized recovery plan and generates the letters you will need for creditors and bureaus. Outside the US, report the incident to your national data-protection authority.\u003C\u002Fli\u003E\u003Cli\u003EFourth, file a police report with local law enforcement to create an official record of the theft, which supports your disputes with creditors and identity theft insurance company. If the fraud is tax-related, respond to any IRS notice promptly and request an Identity Protection PIN if you qualify.\u003C\u002Fli\u003E\u003C\u002Fol\u003E\u003Cp\u003EOur subscribers in the US work with certified specialists who handle creditor contacts, agency filings, and credit bureau disputes until the case closes, which spares you the hardest part of recovery.\u003C\u002Fp\u003E\u003Ch2 id=\"start-protecting-your-identity-long-term\"\u003EStart protecting your identity long-term\u003C\u002Fh2\u003E\u003Cfigure class=\"kg-card kg-image-card\"\u003E\u003Cimg src=\"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002Fimage-2.png\" class=\"kg-image\" alt=\"\" loading=\"lazy\" width=\"975\" height=\"548\" srcset=\"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002Fsize\u002Fw600\u002F2026\u002F08\u002Fimage-2.png 600w, https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002Fimage-2.png 975w\" sizes=\"(min-width: 720px) 720px\"\u003E\u003C\u002Ffigure\u003E\u003Cp\u003EIdentity theft involves unauthorized use of personal and financial information. It can lead to distress and costly financial and personal outcomes. Fortunately, identity theft prevention comes down to an easy-to-sustain routine:\u003C\u002Fp\u003E\u003Cp\u003E●&nbsp;&nbsp;&nbsp;&nbsp; Strong unique passwords with multi-factor authentication\u003C\u002Fp\u003E\u003Cp\u003E●&nbsp;&nbsp;&nbsp;&nbsp; Caution with the personal or sensitive information you share online and offline\u003C\u002Fp\u003E\u003Cp\u003E●&nbsp;&nbsp;&nbsp;&nbsp; Layer monitoring so exposure reaches you as an alert rather than a surprise\u003C\u002Fp\u003E\u003Cp\u003E●&nbsp;&nbsp;&nbsp;&nbsp; A frozen credit file if you suspect identity theft or a breach in your personal and sensitive information\u003C\u002Fp\u003E\u003Cp\u003E●&nbsp;&nbsp;&nbsp;&nbsp; Monthly checks of your statements and credit reports (make sure to use your one free credit report each year)\u003C\u002Fp\u003E\u003Cp\u003EFor protection that combines proactive monitoring with recovery in one place,\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fultimate-security\"\u003E \u003C\u002Fa\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fultimate-security\"\u003EBitdefender Ultimate Security\u003C\u002Fa\u003E brings device security, privacy tools, and identity theft protection together. Get peace of mind and steer away from identity theft-related costs.\u003C\u002Fp\u003E\u003Ch3 id=\"frequently-asked-questions\"\u003EFrequently asked questions\u003C\u002Fh3\u003E\u003Ch4 id=\"how-do-i-protect-myself-if-someone-has-my-ssn\"\u003EHow do I protect myself if someone has my SSN?\u003C\u002Fh4\u003E\u003Cp\u003EPlace a fraud alert or credit freeze with the major credit bureaus right away so no one can open new credit accounts in your name. File a report at\u003Ca href=\"http:\u002F\u002Fidentitytheft.gov\"\u003E \u003C\u002Fa\u003E\u003Ca href=\"http:\u002F\u002Fidentitytheft.gov\"\u003EIdentityTheft.gov\u003C\u002Fa\u003E for a recovery plan, review your credit reports for accounts you did not open, and consider requesting an IRS Identity Protection PIN to block tax fraud. Keep a record of every step you take.\u003C\u002Fp\u003E\u003Ch4 id=\"how-do-i-check-if-someone-is-using-my-identity\"\u003EHow do I check if someone is using my identity?\u003C\u002Fh4\u003E\u003Cp\u003EWatch three places. Review your bank and credit card statements monthly for charges you do not recognize, check your free credit reports from each bureau for unfamiliar accounts or inquiries, and use credit monitoring or identity monitoring to catch dark web exposure and credit file changes as they happen.\u003C\u002Fp\u003E\u003Ch4 id=\"can-someone-steal-your-identity-without-your-ssn\"\u003ECan someone steal your identity without your SSN?\u003C\u002Fh4\u003E\u003Cp\u003EYes. A thief can do real harm with your name, birth date, email, or account number alone, using them to access existing accounts or piece together enough to impersonate you. This is why protecting all of your personal information matters, not only your Social Security number.\u003C\u002Fp\u003E\u003Ch4 id=\"is-a-credit-freeze-better-than-credit-monitoring\"\u003EIs a credit freeze better than credit monitoring?\u003C\u002Fh4\u003E\u003Cp\u003EThey do different jobs, so use both. A security freeze restricts access to your credit file and prevents most new accounts from being opened, working as prevention. Credit monitoring alerts you after a change occurs, working as detection. A freeze stops new-account fraud at the source, while monitoring catches the activity a freeze cannot, such as misuse of existing accounts.\u003C\u002Fp\u003E",tags:[{id:K,name:v,slug:L,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:aX,name:aY,slug:aZ,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:e,name:f,slug:d,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a}],authors:[{id:"66d5cbea28045a04f10b89ca",name:"Bitdefender",slug:aj,profile_image:"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2022\u002F02\u002Flogo_bd_social.png",cover_image:a,bio:"The meaning of Bitdefender’s mascot, the Dacian Draco, a symbol that depicts a mythical animal with a wolf’s head and a dragon’s body, is “to watch” and to “guard with a sharp eye.”",website:a,location:a,facebook:a,twitter:a,meta_title:a,meta_description:a}],excerpt:"US consumers lost $27.3 billion to identity theft and related fraud in 2025, according to Javelin Strategy & Research's 2026 Identity Fraud Study. Losses held roughly steady from the year before, when they had climbed 19%, yet the number of victims rose across every fraud category, with new-account fraud growing the fastest.\n\nMuch of the cost comes from a delay, since stolen data can circulate for years before it surfaces as a fraudulent account. Moreover, the Identity Theft Resource Center foun",reading_time:11,url:"\u002Fblog\u002Fhotforsecurity\u002Fidentity-theft-prevention\u002F"},{id:"6a7ade1c8beeea96580289e6",title:"Met Police exposed a woman’s address to her alleged stalker",slug:"met-police-exposed-woman-address-stalker",feature_image:"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002Fmet-police-stalker.jpg",featured:c,published_at:"2026-08-11T11:36:01.000+03:00",custom_excerpt:a,html:"\u003Cp\u003EA woman who changes her address and phone number to escape an alleged stalker should be able to trust that the police will keep those details confidential. However, in one case examined by the UK’s data protection regulator, an unredacted police document put that information directly into the hands of the person she feared.\u003C\u002Fp\u003E\u003Cp\u003EThe Information Commissioner’s Office (ICO) has reprimanded the Metropolitan Police Service (MPS) over that breach and a separate email error connected to the high-profile “Honeytrap” investigation.\u003C\u002Fp\u003E\u003Cp\u003EThe regulator said the incidents exposed weaknesses in training, monitoring, governance and safeguards for sensitive information—not merely two isolated mistakes.\u003C\u002Fp\u003E\u003Cp\u003EThe reprimand and enforcement action, announced on Aug. 5, requires the MPS to improve its data protection practices on deadlines of three and 12 months.\u003C\u002Fp\u003E\u003Ch2 id=\"key-takeaways\"\u003EKey takeaways\u003C\u002Fh2\u003E\n\u003Cp\u003E• The MPS disclosed a woman’s new address and phone number to her alleged stalker in unredacted documents\u003Cbr\u003E\n• A separate bulk email exposed the names and email addresses of 18 people linked to the UK Parliament and the “Honeytrap” investigation\u003Cbr\u003E\n• The ICO found that the MPS lacked appropriate technical and organisational safeguards, breaching Section 40 of the Data Protection Act 2018\u003Cbr\u003E\n• Investigators identified wider failures in training compliance, oversight, document checks and secure communication practices\u003Cbr\u003E\n• The MPS must make improvements to training, monitoring and governance within three and 12 months\u003C\u002Fp\u003E\n\u003Ch2 id=\"unredacted-documents-exposed-a-stalking-victim%E2%80%99s-new-details\"\u003EUnredacted documents exposed a stalking victim’s new details\u003C\u002Fh2\u003E\u003Cp\u003E\u003C\u002Fp\u003E\u003Cp\u003EThe first incident involved documents supporting an application for a Stalking Protection Order, a legal measure intended to protect people from stalking-related risks.\u003C\u002Fp\u003E\u003Cp\u003EAccording to the \u003Ca href=\"https:\u002F\u002Fico.org.uk\u002Fabout-the-ico\u002Fmedia-centre\u002Fnews-and-blogs\u002F2026\u002F08\u002Fmetropolitan-police-service-issued-with-enforcement-notice-and-reprimand-following-data-protection-failures\u002F\"\u003EICO\u003C\u002Fa\u003E, an MPS officer served the defendant with documents that had not been properly redacted. They contained the victim’s new home address and phone number, along with the names and contact details of three witnesses.\u003C\u002Fp\u003E\u003Cp\u003EThe victim had changed her address and phone number to reduce the risk. The defendant subsequently contacted her on the new number and told her that the MPS had supplied documents containing her updated details.\u003C\u002Fp\u003E\u003Cp\u003EThe regulator found that the MPS had failed to ensure confidential third-party information was removed before the documents were served. Relevant officers had also not received the required specialist training on Stalking Protection Orders, while the process for preparing and checking documents was inadequate.\u003C\u002Fp\u003E\u003Cp\u003EThis is what makes the disclosure especially serious. Contact details are often treated as routine personal data, but their sensitivity depends on context. For someone trying to hide from a stalker, a phone number or address can become safety-critical information.\u003C\u002Fp\u003E\u003Ch2 id=\"a-bulk-email-identified-18-people-linked-to-the-%E2%80%9Choneytrap%E2%80%9D-case\"\u003EA bulk email identified 18 people linked to the “Honeytrap” case\u003C\u002Fh2\u003E\u003Cp\u003E\u003C\u002Fp\u003E\u003Cp\u003EThe second breach arose from the so-called “Honeytrap matter,” in which people connected to the UK Parliament were targeted through WhatsApp messages in 2024 and 2025 in an apparent attempt to obtain compromising information.\u003C\u002Fp\u003E\u003Cp\u003EAn officer sent a bulk email notifying affected people that the suspect’s bail date had changed. Instead of concealing the distribution list, the officer placed every recipient in the “To” field. All recipients could therefore see one another’s names and email addresses.\u003C\u002Fp\u003E\u003Cp\u003EThe MPS confirmed that 18 people linked to Parliament were affected. Although the body of the message did not explicitly include sensitive details about them, the context could allow recipients to infer their connection to the investigation.\u003C\u002Fp\u003E\u003Cp\u003EThe ICO concluded that the MPS should have used a more appropriate communication method rather than a single bulk email in such sensitive circumstances.\u003C\u002Fp\u003E\u003Ch2 id=\"systemic-failures\"\u003ESystemic failures\u003C\u002Fh2\u003E\u003Cp\u003E\u003C\u002Fp\u003E\u003Cp\u003ENeither incident involved a hacker exploiting a software vulnerability or breaking into a police network. Both resulted from preventable failures in how people, processes and technology handled sensitive data.\u003C\u002Fp\u003E\u003Cp\u003EThe ICO found that the MPS had not put appropriate technical and organisational measures in place to protect personal information, infringing Section 40 of the Data Protection Act 2018.\u003C\u002Fp\u003E\u003Cp\u003EIts investigation also uncovered poor compliance with mandatory data protection training and inadequate management oversight.\u003C\u002Fp\u003E\u003Cp\u003EThe officer responsible for the Honeytrap email had not undergone data protection training for more than four years before the incident. The officer’s line manager had also gone almost four years without the training.\u003C\u002Fp\u003E\u003Cp\u003EMore broadly, completion rates for the MPS’s mandatory Managing Information course were found to be low, with the force itself acknowledging that further improvement was needed.\u003C\u002Fp\u003E\u003Cp\u003EJo Stones, ICO group manager for Civil and Cyber Investigations, described the incidents as “foreseeable and preventable,” adding:\u003C\u002Fp\u003E\u003Cblockquote\u003EPolicies and reminders are not enough if they are not followed, checked and enforced.\u003C\u002Fblockquote\u003E\u003Cp\u003EThat distinction matters well beyond policing. Written policies cannot protect sensitive data unless staff understand them, managers verify compliance, high-risk processes include meaningful checks, and technical safeguards help prevent predictable human errors.\u003C\u002Fp\u003E\u003Ch2 id=\"what-happens-next\"\u003EWhat happens next\u003C\u002Fh2\u003E\u003Cp\u003E\u003C\u002Fp\u003E\u003Cp\u003EThe MPS notified the people affected and offered additional support in the stalking case. It also delivered more specialist training and introduced a stronger, multi-stage quality-assurance process for Stalking Protection Order applications.\u003C\u002Fp\u003E\u003Cp\u003EFollowing the bulk-email incident, the force contacted the affected people, issued a force-wide reminder about mandatory information-security training and introduced a behavioral alert designed to warn staff when they are about to email multiple external recipients.\u003C\u002Fp\u003E\u003Cp\u003EThe ICO took those measures into account but concluded they were not enough. Training completion remained low, while some wider technical controls and monitoring arrangements had not been fully implemented or shown to work effectively.\u003C\u002Fp\u003E\u003Cp\u003EThe enforcement notice therefore gives the MPS three- and 12-month deadlines to improve training compliance, monitoring and governance. The reprimand formally records the infringements associated with both incidents.\u003C\u002Fp\u003E\u003Cp\u003EThe decision adds to the force’s recent information-governance scrutiny. In March 2026, the ICO \u003Ca href=\"https:\u002F\u002Fico.org.uk\u002Faction-weve-taken\u002Ffoi-regulatory-action\u002F2026\u002F03\u002Fmetropolitan-police-service\u002F\"\u003Eserved the MPS with a separate enforcement notice\u003C\u002Fa\u003E over its performance under the Freedom of Information Act.\u003C\u002Fp\u003E\u003Ch2 id=\"what-to-do-if-an-organization-exposes-your-personal-information\"\u003EWhat to do if an organization exposes your personal information\u003C\u002Fh2\u003E\u003Cp\u003E\u003C\u002Fp\u003E\u003Cp\u003EA proper response depends on what was disclosed and who received it. A leaked password creates different risks than an exposed home address, case history or list of contacts.\u003C\u002Fp\u003E\u003Cp\u003EIf an organisation tells you that your information has been exposed:\u003C\u002Fp\u003E\u003Cp\u003E• Ask exactly what information was disclosed, when it happened, who received it and what the organisation has done to contain the incident\u003C\u002Fp\u003E\u003Cp\u003E• Treat physical safety information as urgent—contact the police or the organisation’s safeguarding team if an address, phone number or location data could put you at risk\u003C\u002Fp\u003E\u003Cp\u003E• Be alert for targeted calls, messages and emails that use the exposed information to appear credible\u003C\u002Fp\u003E\u003Cp\u003E• Change passwords and enable multi-factor authentication if login credentials or account details were involved; there is no need to reset unrelated accounts\u003C\u002Fp\u003E\u003Cp\u003E• Keep the breach notice and records of your communications in case you need to make a complaint or document resulting harm\u003C\u002Fp\u003E\u003Cp\u003E• Raise unresolved data protection concerns with the organisation first and, where appropriate, \u003Ca href=\"https:\u002F\u002Fico.org.uk\u002Fmake-a-complaint\u002Fdata-complaints-complaints\u002Fcheck-if-you-can-complain\u002F\"\u003Ereport the matter to the ICO\u003C\u002Fa\u003E\u003C\u002Fp\u003E\u003Cp\u003EData-exposure monitoring can also help people discover whether personal information appears in known breaches. Services such as \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fdigital-identity-protection\"\u003E\u003Cstrong\u003EBitdefender Digital Identity Protection\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E provide alerts and guidance, but monitoring cannot reverse a disclosure—especially when the exposed information affects someone’s physical safety. Rapid containment and direct support are essential.\u003C\u002Fp\u003E\u003Ch2 id=\"privacy-must-not-depend-on-a-simple-reminder\"\u003EPrivacy must not depend on a simple reminder\u003C\u002Fh2\u003E\u003Cp\u003E\u003C\u002Fp\u003E\u003Cp\u003EThe MPS incidents show that a data breach does not need malware, stolen credentials or an advanced attacker to cause real harm. An unredacted document or a poorly addressed email can be enough—particularly when an organisation holds information about victims, witnesses and sensitive investigations.\u003C\u002Fp\u003E\u003Cp\u003ETraining matters, but the ICO’s message goes further: when personal information can affect someone’s safety, privacy can’t depend on a simple reminder. Organisations must verify that training is completed, build checks into high-risk workflows, use technical guardrails and hold managers accountable.\u003C\u002Fp\u003E\u003Cp\u003E\u003Cem\u003ERelated:\u003C\u002Fem\u003E\u003C\u002Fp\u003E\u003Cp\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fwhat-to-do-your-data-caught-in-a-breach\"\u003E\u003Cstrong\u003E\u003Cem\u003EWhat to do if your data gets caught in a breach\u003C\u002Fem\u003E\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E\u003C\u002Fp\u003E\u003Cp\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fhave-you-fallen-victim-to-a-data-breach-follow-these-six-steps-to-protect-against-possible-side-effects\"\u003E\u003Cstrong\u003E\u003Cem\u003EHave you fallen victim to a data breach? Follow these six steps\u003C\u002Fem\u003E\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E\u003C\u002Fp\u003E",tags:[{id:i,name:j,slug:k,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:K,name:v,slug:L,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:e,name:f,slug:d,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a}],authors:[{id:ae,name:af,slug:ag,profile_image:ah,cover_image:a,bio:ai,website:a,location:a,facebook:a,twitter:a,meta_title:a,meta_description:a}],excerpt:"A woman who changes her address and phone number to escape an alleged stalker should be able to trust that the police will keep those details confidential. However, in one case examined by the UK’s data protection regulator, an unredacted police document put that information directly into the hands of the person she feared.\n\nThe Information Commissioner’s Office (ICO) has reprimanded the Metropolitan Police Service (MPS) over that breach and a separate email error connected to the high-profile “",reading_time:E,url:"\u002Fblog\u002Fhotforsecurity\u002Fmet-police-exposed-woman-address-stalker\u002F"}],tagWhiteDetail:{slug:k,id:i,name:j,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a,url:"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Ftag\u002Findustry-news\u002F"},tagBlackDetail:{slug:L,id:K,name:v,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a,url:"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Ftag\u002Fdigital-privacy\u002F"},settings:{title:ak,description:a_,logo:a$,icon:a,accent_color:ba,cover_image:bb,facebook:aj,twitter:bc,lang:d,locale:d,timezone:bd,codeinjection_head:a,codeinjection_foot:a,navigation:[{label:be,url:al},{label:bf,url:bg},{label:v,url:bh},{label:M,url:bi},{label:bj,url:bk},{label:y,url:bl}],secondary_navigation:[],meta_title:a,meta_description:a,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,members_support_address:bm,members_enabled:c,allow_self_signup:c,members_invite_only:c,paid_members_enabled:c,firstpromoter_account:a,portal_button_style:bn,portal_button_signup_text:bo,portal_button_icon:a,portal_signup_terms_html:a,portal_signup_checkbox_required:c,portal_plans:[bp,bq,Y],portal_default_plan:Y,portal_name:N,portal_button:c,comments_enabled:br,recommendations_enabled:c,outbound_link_tagging:c,default_email_address:bs,support_email_address:bt,editor_default_email_recipients:bu,labs:{},url:bv,version:bw},allBiTags:[]}],fetch:{"BlogMenu:0":{settings:{title:ak,description:a_,logo:a$,icon:a,accent_color:ba,cover_image:bb,facebook:aj,twitter:bc,lang:d,locale:d,timezone:bd,codeinjection_head:a,codeinjection_foot:a,navigation:[{label:be,url:al},{label:bf,url:bg},{label:v,url:bh},{label:M,url:bi},{label:bj,url:bk},{label:y,url:bl}],secondary_navigation:[],meta_title:a,meta_description:a,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,members_support_address:bm,members_enabled:c,allow_self_signup:c,members_invite_only:c,paid_members_enabled:c,firstpromoter_account:a,portal_button_style:bn,portal_button_signup_text:bo,portal_button_icon:a,portal_signup_terms_html:a,portal_signup_checkbox_required:c,portal_plans:[bp,bq,Y],portal_default_plan:Y,portal_name:N,portal_button:c,comments_enabled:br,recommendations_enabled:c,outbound_link_tagging:c,default_email_address:bs,support_email_address:bt,editor_default_email_recipients:bu,labs:{},url:bv,version:bw},blogNames:bx,blogTitles:{hotforsecurity:ak,labs:"Labs",businessinsights:"Business Insights",cyberpedia:"Cyberpedia"},blogRegions:{hotforsecurity:[d,"ro","de",by,"es"],labs:[d],businessinsights:[d,by],cyberpedia:[d]},activeBlog:am,blogFound:am},"FilterSection:0":{posts:[{id:_,title:$,slug:aa,feature_image:ab,featured:c,published_at:ac,custom_excerpt:x,html:bz,tags:[{id:O,name:P,slug:Q,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:e,name:f,slug:d,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:h,name:g,slug:g,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a}],authors:[{id:p,name:q,slug:r,profile_image:s,cover_image:t,bio:u,website:a,location:a,facebook:a,twitter:a,meta_title:a,meta_description:a}],excerpt:x,reading_time:W,url:ad},{id:"6a883abb8beeea965802921c",title:"Can a VPN bypass age verification?",slug:"vpn-bypass-age-verification",feature_image:"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002FCan-a-VPN-bypass-age-verification.png",featured:c,published_at:"2026-08-21T14:52:20.000+03:00",custom_excerpt:a,html:"\u003Cp\u003EAs more websites begin requiring age verification, many people wonder whether a VPN can help them get around these checks.\u003C\u002Fp\u003E\u003Cp\u003EOur advice: \u003Cstrong\u003Edon't use a VPN to try to bypass age verification.\u003C\u002Fstrong\u003E\u003C\u002Fp\u003E\u003Cp\u003EThese checks exist for a reason: they help keep age-restricted content away from minors and help platforms comply with child-safety and other legal requirements. A VPN can change your apparent location and hide your IP address, but it can't prove your age, verify your identity, or make those safeguards disappear. Trying to get around them can also violate a platform's terms of service or local laws.\u003C\u002Fp\u003E\u003Cp\u003EHere's how VPNs interact with age verification systems and what they can and can't do.\u003C\u002Fp\u003E\u003Ch2 id=\"key-takeaways\"\u003EKey takeaways\u003C\u002Fh2\u003E\u003Cul\u003E\u003Cli\u003EA VPN changes your virtual location and encrypts your internet traffic.\u003C\u002Fli\u003E\u003Cli\u003EA VPN cannot verify your age or create a fake identity.\u003C\u002Fli\u003E\u003Cli\u003EWe don't recommend using a VPN to bypass age verification, as doing so may violate a platform's terms of service or local laws.\u003C\u002Fli\u003E\u003Cli\u003EMany age verification systems rely on identity documents, payment methods, or third-party verification that a VPN cannot bypass.\u003C\u002Fli\u003E\u003Cli\u003EA VPN can still help protect your privacy when sharing personal information online.\u003C\u002Fli\u003E\u003C\u002Ful\u003E\u003Ch2 id=\"what-is-age-verification\"\u003EWhat is age verification?\u003C\u002Fh2\u003E\u003Cp\u003EAge verification is the process websites and online services use to confirm that a visitor is old enough to access certain content or features.\u003C\u002Fp\u003E\u003Cp\u003EDepending on where you live, you may be asked to verify your age before accessing:\u003C\u002Fp\u003E\u003Cul\u003E\u003Cli\u003EAdult websites\u003C\u002Fli\u003E\u003Cli\u003EOnline gambling platforms\u003C\u002Fli\u003E\u003Cli\u003EAlcohol or vaping websites\u003C\u002Fli\u003E\u003Cli\u003ESome social media platforms\u003C\u002Fli\u003E\u003Cli\u003EOther age-restricted online services\u003C\u002Fli\u003E\u003C\u002Ful\u003E\u003Cp\u003ENot every website verifies age in the same way. Some simply ask you to enter your date of birth, while others require you to upload an ID, verify a payment card, or use a third-party identity verification service.\u003C\u002Fp\u003E\u003Cp\u003EAs more countries introduce online safety and child protection laws, these checks are becoming increasingly common.\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003EMore about how it works:\u003C\u002Fstrong\u003E \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fage-verification-for-teens-privacy-risks\"\u003EAge verification for teens: Privacy risks parents should know\u003C\u002Fa\u003E\u003C\u002Fp\u003E\u003Ch2 id=\"can-a-vpn-bypass-age-verification\"\u003ECan a VPN bypass age verification?\u003C\u002Fh2\u003E\u003Cp\u003E\u003Cstrong\u003EIn some cases, a VPN may affect location-based age verification, but we don't recommend using one to try to bypass these checks.\u003C\u002Fstrong\u003E\u003C\u002Fp\u003E\u003Cp\u003EA VPN changes your IP address and encrypts your internet traffic. This means websites see the VPN server's location instead of your actual one.\u003C\u002Fp\u003E\u003Cp\u003EThat's also where its role ends. While a VPN can change your apparent location, it can't verify your identity or prove your age. If a website verifies users by checking official documents or other personal information, using a VPN won't remove that requirement.\u003C\u002Fp\u003E\u003Ch2 id=\"when-can-a-vpn-affect-age-verification\"\u003EWhen can a VPN affect age verification?\u003C\u002Fh2\u003E\u003Cp\u003EWe don't recommend using a VPN to try to get around age verification. However, there are situations where a VPN may change what you see, depending on how a website is designed.\u003C\u002Fp\u003E\u003Ch3 id=\"location-based-age-verification\"\u003ELocation-based age verification\u003C\u002Fh3\u003E\u003Cp\u003ESome websites apply different rules depending on where visitors appear to be connecting from. For example, a service may only display age verification prompts in countries where local laws require them.\u003C\u002Fp\u003E\u003Cp\u003EBecause a VPN changes your apparent location, the website may show a different version of the site or different requirements.\u003C\u002Fp\u003E\u003Cp\u003EHowever, this isn't guaranteed. Many services use additional methods to determine whether age verification is required.\u003C\u002Fp\u003E\u003Ch3 id=\"different-regional-versions-of-a-website\"\u003EDifferent regional versions of a website\u003C\u002Fh3\u003E\u003Cp\u003ESome online services offer different features or content depending on the country you're visiting from. Connecting through another country with a VPN may give you access to a different regional version of the website.\u003C\u002Fp\u003E\u003Cp\u003EWhether that changes the age verification process depends entirely on the service's own policies and technical implementation.\u003C\u002Fp\u003E\u003Ch2 id=\"when-wont-a-vpn-bypass-age-verification\"\u003EWhen won't a VPN bypass age verification?\u003C\u002Fh2\u003E\u003Cp\u003EIn many cases, a VPN won't make any difference because the website verifies your identity, not your location.\u003C\u002Fp\u003E\u003Cp\u003EA VPN cannot bypass age verification systems that rely on:\u003C\u002Fp\u003E\u003Cul\u003E\u003Cli\u003EGovernment-issued IDs\u003C\u002Fli\u003E\u003Cli\u003EPassports or driver's licenses\u003C\u002Fli\u003E\u003Cli\u003ECredit or debit card verification\u003C\u002Fli\u003E\u003Cli\u003EFacial age estimation\u003C\u002Fli\u003E\u003Cli\u003EMobile carrier verification\u003C\u002Fli\u003E\u003Cli\u003EDigital identity services\u003C\u002Fli\u003E\u003Cli\u003EThird-party identity verification providers\u003C\u002Fli\u003E\u003C\u002Ful\u003E\u003Cp\u003EThese methods are designed to confirm who you are, regardless of where you're connecting from. \u003Cstrong\u003EChanging your IP address or apparent location with a VPN doesn't change the information these systems use to verify your age.\u003C\u002Fstrong\u003E\u003C\u002Fp\u003E\u003Ch2 id=\"does-a-vpn-make-age-verification-more-private\"\u003EDoes a VPN make age verification more private?\u003C\u002Fh2\u003E\u003Cp\u003EWhile a VPN doesn't replace age verification, it can still help protect your privacy.\u003C\u002Fp\u003E\u003Cp\u003EWhen you use a VPN, your internet traffic is encrypted between your device and the VPN server. This helps prevent people on the same network, such as on public Wi-Fi, from intercepting your connection.\u003C\u002Fp\u003E\u003Cp\u003EA VPN also hides your IP address from the website.\u003C\u002Fp\u003E\u003Cp\u003EIf you voluntarily upload an ID, enter your date of birth, or submit other personal information during age verification, that information is still shared directly with the website or its verification provider. A VPN doesn't prevent that.\u003C\u002Fp\u003E\u003Cp\u003EIt's also worth noting that \u003Cstrong\u003Enot all VPNs offer the same level of privacy\u003C\u002Fstrong\u003E. Some free VPNs may log your activity, display ads, or even collect and monetize your data. If you're using a VPN to protect sensitive information, choose a reputable provider with a clear no-logs policy and strong security features.\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003ERelated:\u003C\u002Fstrong\u003E\u003C\u002Fp\u003E\u003Cul\u003E\u003Cli\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Ffree-vpn-vs-paid-vpn\"\u003EFree VPN vs Paid VPN: Are Free VPNs Safe?\u003C\u002Fa\u003E\u003C\u002Fli\u003E\u003Cli\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fkids-bypass-age-verification\"\u003EHow kids bypass age verification online and what families can do about it\u003C\u002Fa\u003E\u003C\u002Fli\u003E\u003C\u002Ful\u003E\u003Ch2 id=\"how-to-protect-your-privacy-during-online-age-verification\"\u003EHow to protect your privacy during online age verification\u003C\u002Fh2\u003E\u003Cp\u003EIf you need to verify your age online, a few simple precautions can help protect your personal information.\u003C\u002Fp\u003E\u003Cul\u003E\u003Cli\u003EMake sure you're using the official website, not a link from an email or text message.\u003C\u002Fli\u003E\u003Cli\u003ECheck that the website uses HTTPS before submitting personal information.\u003C\u002Fli\u003E\u003Cli\u003ERead the privacy policy to understand how your information will be stored and used.\u003C\u002Fli\u003E\u003Cli\u003EOnly provide the information that's actually required.\u003C\u002Fli\u003E\u003Cli\u003EBe cautious of fake age verification pages designed to steal personal information.\u003C\u002Fli\u003E\u003Cli\u003EUse a trusted VPN, especially when you're connected to public Wi-Fi, to encrypt your connection while your information is transmitted.\u003C\u002Fli\u003E\u003C\u002Ful\u003E\u003Cp\u003EIf you're simply looking for a VPN, \u003Cstrong\u003EBitdefender Premium VPN\u003C\u002Fstrong\u003E encrypts your internet traffic and helps protect your privacy on public Wi-Fi and other networks. It's available as a standalone app, making it a good choice if your main goal is to secure your connection.\u003C\u002Fp\u003E\u003Cp\u003EGet \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fvpn\"\u003E\u003Cstrong\u003EBitdefender Premium VPN\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E and take control of your online privacy.\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003EBitdefender Premium VPN\u003C\u002Fstrong\u003E is also included in all \u003Cstrong\u003EBitdefender Family Plans\u003C\u002Fstrong\u003E, which offer broader protection against the online threats that often accompany age verification and other everyday online activities. These include phishing websites, scam links and messages, malicious downloads, and other attempts to steal personal information.\u003C\u002Fp\u003E\u003Cp\u003EFind out more about \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Ffamily\"\u003E\u003Cstrong\u003EBitdefender Family Plans\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E.\u003C\u002Fp\u003E\u003Ch2 id=\"you-may-also-want-to-read\"\u003EYou may also want to read\u003C\u002Fh2\u003E\u003Cul\u003E\u003Cli\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fwhen-should-you-use-a-vpn\"\u003EWhen should you use a VPN?\u003C\u002Fa\u003E\u003C\u002Fli\u003E\u003Cli\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fdoes-a-vpn-protect-you-from-hackers\"\u003EDoes a VPN protect you from hackers?\u003C\u002Fa\u003E\u003C\u002Fli\u003E\u003Cli\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Ftest-if-vpn-is-working\"\u003EIs my VPN working? 7 easy tests to see if it works\u003C\u002Fa\u003E\u003C\u002Fli\u003E\u003Cli\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fteen-social-media-ban-therapist-advice\"\u003EHow to handle teen social media bans, according to therapist\u003C\u002Fa\u003E\u003C\u002Fli\u003E\u003C\u002Ful\u003E\u003Ch2 id=\"faqs\"\u003EFAQs\u003C\u002Fh2\u003E\u003Ch3 id=\"can-a-vpn-bypass-age-verification-1\"\u003ECan a VPN bypass age verification?\u003C\u002Fh3\u003E\u003Cp\u003E\u003Cstrong\u003EWe don't recommend trying.\u003C\u002Fstrong\u003E A VPN may affect location-based age verification in some cases, but it cannot bypass identity-based verification systems that require proof of age. Age verification measures are there to help keep age-restricted content away from minors and meet legal requirements.\u003C\u002Fp\u003E\u003Ch3 id=\"can-a-vpn-change-my-age\"\u003ECan a VPN change my age?\u003C\u002Fh3\u003E\u003Cp\u003ENo. A VPN only changes your IP address and apparent location. It does not change your identity or date of birth.\u003C\u002Fp\u003E\u003Ch3 id=\"why-am-i-still-being-asked-to-verify-my-age-when-using-a-vpn\"\u003EWhy am I still being asked to verify my age when using a VPN?\u003C\u002Fh3\u003E\u003Cp\u003EMany websites use identity verification methods such as IDs, payment cards, or third-party verification services. A VPN doesn't affect those checks.\u003C\u002Fp\u003E\u003Ch3 id=\"does-a-vpn-protect-my-personal-information-during-age-verification\"\u003EDoes a VPN protect my personal information during age verification?\u003C\u002Fh3\u003E\u003Cp\u003EA VPN encrypts your internet connection, helping protect your data while it's being transmitted. However, any information you choose to submit, such as an ID or your date of birth, is still shared with the website or verification provider.\u003C\u002Fp\u003E\u003Ch3 id=\"is-it-legal-to-use-a-vpn-to-bypass-age-verification\"\u003EIs it legal to use a VPN to bypass age verification?\u003C\u002Fh3\u003E\u003Cp\u003EOur advice is not to use a VPN to bypass age verification. The legality of using a VPN itself varies by country, but using one to get around age checks can still violate a platform's terms of service and, in some places, the law.\u003C\u002Fp\u003E\u003Cp\u003EMore importantly, these checks exist for a reason: they help keep age-restricted content away from minors and help platforms meet child-safety and other legal requirements. If you're unsure, check the regulations that apply where you live and the terms of the service you're using.\u003C\u002Fp\u003E",tags:[{id:"66f50fb228045a04f10ce9a9",name:an,slug:ao,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:ap,name:aq,slug:ar,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:e,name:f,slug:d,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a}],authors:[{id:bA,name:bB,slug:bC,profile_image:bD,cover_image:a,bio:bE,website:a,location:a,facebook:a,twitter:a,meta_title:a,meta_description:a}],excerpt:"As more websites begin requiring age verification, many people wonder whether a VPN can help them get around these checks.\n\nOur advice: don't use a VPN to try to bypass age verification.\n\nThese checks exist for a reason: they help keep age-restricted content away from minors and help platforms comply with child-safety and other legal requirements. A VPN can change your apparent location and hide your IP address, but it can't prove your age, verify your identity, or make those safeguards disappea",reading_time:E,url:"\u002Fblog\u002Fhotforsecurity\u002Fvpn-bypass-age-verification\u002F"},{id:"6a8838418beeea96580291f5",title:"How to tell if your teen has a secret social media account",slug:"secret-social-media-account-teen",feature_image:"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002FHow-to-tell-if-your-teen-has-a-secret-social-media-account.png",featured:c,published_at:"2026-08-21T14:46:14.000+03:00",custom_excerpt:a,html:"\u003Cp\u003EAs countries introduce stricter age verification and social media restrictions for younger users, some teens may look for ways around the rules, including creating accounts their parents don't know about.\u003C\u002Fp\u003E\u003Cp\u003EIf you're wondering whether your teen has a secret social media account, here are the signs to watch for and how to address the situation without damaging trust, with insights from clinical psychologist and CBT psychotherapist Anca Ivu.\u003C\u002Fp\u003E\u003Ch2 id=\"key-takeaways\"\u003EKey takeaways:\u003C\u002Fh2\u003E\u003Cul\u003E\u003Cli\u003ETeens may create secret social media accounts to gain privacy, fit in with friends, or get around parental rules and age restrictions.\u003C\u002Fli\u003E\u003Cli\u003EA hidden account should be addressed, especially if your teen is using it to access a platform or content that isn't appropriate for their age.\u003C\u002Fli\u003E\u003Cli\u003EChanges in phone habits, hidden notifications, unknown accounts, or unexplained online activity can be signs, but no single behavior proves a secret account exists.\u003C\u002Fli\u003E\u003Cli\u003EIf you discover a hidden account, find out why it was created, what it's being used for, and whether your teen is exposed to any safety risks.\u003C\u002Fli\u003E\u003Cli\u003ERespecting a teenager's growing need for privacy doesn't mean ignoring rules or safety concerns. Parents can set clear boundaries while keeping communication open.\u003C\u002Fli\u003E\u003C\u002Ful\u003E\u003Ch2 id=\"why-teens-create-secret-social-media-accounts\"\u003EWhy Teens Create Secret Social Media Accounts\u003C\u002Fh2\u003E\u003Cp\u003ESecret social media accounts aren't a new phenomenon. In a large US sample of 10,092 children ages 11 to 15,&nbsp;\u003Cstrong\u003E6.3% of social media users \u003C\u002Fstrong\u003E\u003Ca href=\"https:\u002F\u002Fwww.sciencedirect.com\u002Fscience\u002Farticle\u002Fpii\u002FS1876285925000099\"\u003Ereported\u003C\u002Fa\u003E\u003Cstrong\u003E having an account their parents didn't know about\u003C\u002Fstrong\u003E. And that was before the latest wave of social media restrictions for children and teens. As access becomes more restricted, some teens may look for new ways to get around the rules without their parents knowing.\u003C\u002Fp\u003E\u003Cp\u003EA secret account shouldn't be ignored, particularly when it's being used to bypass an age restriction or a family rule. But discovering the account alone doesn't tell you why your teen created it, what they're doing there, or how much risk is involved.\u003C\u002Fp\u003E\u003Ch3 id=\"privacy-secrecy-and-lying-arent-the-same-thing\"\u003EPrivacy, secrecy, and lying aren't the same thing\u003C\u002Fh3\u003E\u003Cp\u003EAs children move into adolescence, they naturally start deciding which parts of their lives they want to share with their parents and which they consider personal. Their growing need for privacy is part of becoming more independent.\u003C\u002Fp\u003E\u003Cp\u003EResearch has documented this distinction for years. A 2006 study \u003Ca href=\"https:\u002F\u002Fpubmed.ncbi.nlm.nih.gov\u002F16460534\u002F\"\u003Epublished\u003C\u002Fa\u003E in&nbsp;\u003Cem\u003EChild Development\u003C\u002Fem\u003E&nbsp;found that adolescents felt more obligated to tell their parents about issues involving their safety and wellbeing than about matters they considered personal.\u003C\u002Fp\u003E\u003Cp\u003EMore recent research \u003Ca href=\"https:\u002F\u002Fpubmed.ncbi.nlm.nih.gov\u002F35348992\u002F\"\u003Eadds\u003C\u002Fa\u003E an important nuance:&nbsp;\u003Cstrong\u003Eprivacy, secrecy, and lying aren't the same thing\u003C\u002Fstrong\u003E. A 2022 study of 332 Swiss adolescents found that teens could communicate quite openly with their parents while still keeping certain things to themselves. The more concerning pattern was when greater secrecy appeared alongside less communication and more lying.\u003C\u002Fp\u003E\u003Cp\u003EThis doesn't mean parents should accept a secret social media account as simply part of adolescence. Instead,&nbsp;\u003Cstrong\u003Elook at the account in the context of your teen's wider behavior. \u003C\u002Fstrong\u003EAre they repeatedly lying to protect it? Are they using it to bypass age restrictions or important family rules? Are they communicating with strangers, hiding potentially dangerous experiences, or showing significant changes in their behavior or relationship with you?\u003C\u002Fp\u003E\u003Cp\u003EIt may also help to ask yourself: \u003Cstrong\u003E\u003Cem\u003E\"Why did my teen feel this account needed to be secret from me?\"\u003C\u002Fem\u003E\u003C\u002Fstrong\u003E\u003C\u002Fp\u003E\u003Cp\u003EUnderstanding the reason gives you a better starting point for deciding what to do next.\u003C\u002Fp\u003E\u003Ch2 id=\"signs-your-teen-may-have-a-secret-social-media-account\"\u003ESigns your teen may have a secret social media account\u003C\u002Fh2\u003E\u003Cp\u003ENo single behavior proves your teen has a secret social media account. Many of these signs have perfectly normal explanations. What matters more is a&nbsp;\u003Cstrong\u003Esudden change in behavior or several signs appearing together\u003C\u002Fstrong\u003E.\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003EThey become very protective of their phone.\u003C\u002Fstrong\u003E Your teen may suddenly turn their screen away when you enter the room, quickly close apps, take their phone everywhere, or become uncomfortable when someone else picks it up.\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003ENotifications suddenly stop appearing. \u003C\u002Fstrong\u003ETurning off notifications or hiding lock-screen previews can keep activity on another account out of sight. Pay attention if notifications that used to appear regularly suddenly disappear.\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003EThey have apps you don't recognize or that look disguised. \u003C\u002Fstrong\u003ESome apps \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fkids-using-secret-decoy-apps-what-parents-need-to-know-about-the-dangers\"\u003Ecan hide\u003C\u002Fa\u003E photos, messages, or other online activities behind an ordinary-looking icon, such as a calculator or utility. If you notice unfamiliar apps on your teen's phone, especially ones they seem reluctant to explain, it's worth asking what they are and how they're using them.\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003EThey have email addresses you didn't know about\u003C\u002Fstrong\u003E. A second email address can be used to register another social media account. Of course, teens may also have separate emails for school, gaming, shopping, or other legitimate reasons.\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003EThey frequently clear their browsing history\u003C\u002Fstrong\u003E. Regularly deleting browsing history, searches, messages, or recently used apps can make online activity harder to trace. A sudden change in this behavior is more significant than occasionally clearing a history.\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003EFriends mention accounts you've never seen\u003C\u002Fstrong\u003E. A friend may mention a username, post, video, or account you don't recognize. Some teens maintain different profiles for different audiences, including accounts intended only for close friends.\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003EThey suddenly start using a VPN\u003C\u002Fstrong\u003E. VPNs are legitimate privacy and security tools, so using one isn't evidence of a secret account. But some teens may try using a VPN to get around location-based social media restrictions. If one suddenly appears on your teen's device after a platform becomes restricted, ask what they're using it for.\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003EThey become defensive when you ask about social media\u003C\u002Fstrong\u003E. Anger, avoidance, or quickly changing the subject when you ask simple questions about social media may be worth noticing, particularly if it's a new behavior.\u003C\u002Fp\u003E\u003Cp\u003EAgain,&nbsp;\u003Cstrong\u003Eone of these signs doesn't tell you much on its own. Several significant changes happening together may mean it's time for a conversation.\u003C\u002Fstrong\u003E\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003E&nbsp;\u003C\u002Fstrong\u003E\u003C\u002Fp\u003E\u003Ch2 id=\"what-to-do-if-you-discover-a-secret-account\"\u003EWhat to do if you discover a secret account\u003C\u002Fh2\u003E\u003Cp\u003EFinding out that your teen has been hiding a social media account can trigger a lot of emotions. You may feel angry, worried, betrayed, or frightened about what they might be doing there, which then influences what you do next.\u003C\u002Fp\u003E\u003Cp\u003EAnd that next step matters.\u003C\u002Fp\u003E\u003Cblockquote\u003E\"Your first impulse may be to immediately close the account or get a confession,\" explains&nbsp;\u003Cstrong\u003EAnca Ivu, clinical psychologist and CBT psychotherapist\u003C\u002Fstrong\u003E. \"But the parent's focus should be on understanding why the adolescent felt the need to hide it and checking that they are safe.\"\u003C\u002Fblockquote\u003E\u003Ch3 id=\"get-your-own-reaction-under-control-first\"\u003E&nbsp;Get your own reaction under control first\u003C\u002Fh3\u003E\u003Cp\u003EThis may be difficult, especially if you've discovered something that genuinely worries you. But try not to start the conversation while you're angry or frightened. Anca recommends that parents&nbsp;\u003Cstrong\u003Eregulate their own reaction before acting on it\u003C\u002Fstrong\u003E. Confrontations such as&nbsp;\u003Cem\u003E\"I caught you!\"\u003C\u002Fem\u003E, threats, or other intense reactions can change the direction of the conversation.\u003C\u002Fp\u003E\u003Cp\u003EAs she puts it, the question in the teen's mind can shift from&nbsp;\u003Cem\u003E\"What's happening to me and how can I talk to my parent about it?\"\u003C\u002Fem\u003E&nbsp;to&nbsp;\u003Cstrong\u003E\"How do I make sure I don't get caught next time?\"\u003C\u002Fstrong\u003E\u003C\u002Fp\u003E\u003Ch3 id=\"tell-them-what-you-know-without-accusing-them\"\u003E&nbsp;Tell them what you know without accusing them\u003C\u002Fh3\u003E\u003Cp\u003EYou don't need to pretend you haven't discovered the account. Be straightforward, but leave room for your teen to explain.\u003C\u002Fp\u003E\u003Cp\u003EAnca suggests saying something like: \u003Cem\u003E\"I found out that you have an account I didn't know about. I don't want to jump to conclusions before I ask you about it and understand why you felt the need to keep it hidden.\"\u003C\u002Fem\u003E\u003C\u002Fp\u003E\u003Ch3 id=\"be-curious-before-you-become-punitive\"\u003EBe curious before you become punitive\u003C\u002Fh3\u003E\u003Cp\u003EAsk what the account means to them. Why did they create it? Why didn't they want you to know? Is it where their friends communicate? Did they feel left out because everyone else had an account? Did they know you would say no?\u003C\u002Fp\u003E\u003Cp\u003E\"Be curious before acting like a punitive parent,\" Anca says.&nbsp;\u003Cstrong\u003E\"Ask what the account represents for them and why they didn't want their parents to know about it.\"\u003C\u002Fstrong\u003E\u003C\u002Fp\u003E\u003Ch3 id=\"check-whether-theyre-safe\"\u003ECheck whether they're safe\u003C\u002Fh3\u003E\u003Cp\u003EThere is a point where privacy stops being the priority:&nbsp;\u003Cstrong\u003Ewhen your child's safety may be at risk\u003C\u002Fstrong\u003E.\u003C\u002Fp\u003E\u003Cp\u003EFind out whether your teen is communicating with unknown adults, being bullied or threatened, sharing intimate images or personal information, encountering harmful content, or doing something else that could put them in danger.\u003C\u002Fp\u003E\u003Cp\u003E\"When it comes to safety, the parent has a responsibility to know whether their child is in danger,\" Anca explains. This distinction should also be made clear to the teenager:&nbsp;\u003Cstrong\u003Eyou can respect their need for privacy while still intervening when their safety is at stake.\u003C\u002Fstrong\u003E\u003C\u002Fp\u003E\u003Ch3 id=\"go-back-to-your-familys-digital-rules\"\u003E&nbsp;Go back to your family's digital rules\u003C\u002Fh3\u003E\u003Cp\u003EIf your teen broke a rule you had already agreed on, talk about what happened and why that rule exists. As Anca points out,&nbsp;\u003Cstrong\u003Efamily rules need to be renegotiated and adapted as children grow\u003C\u002Fstrong\u003E. A rule that made sense for a 10-year-old may no longer be appropriate for a 15-year-old.\u003C\u002Fp\u003E\u003Cp\u003EIf there needs to be a consequence, connect it to the behavior and to your teen's safety rather than using punishment to embarrass or shame them.\u003C\u002Fp\u003E\u003Cp\u003EUltimately, Anca says, teenagers should come away from the conversation with&nbsp;\u003Cstrong\u003Etwo messages at the same time\u003C\u002Fstrong\u003E:\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003E\"I understand that you need privacy.\"\u003C\u002Fstrong\u003E\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003E\"I'm still your parent, and I have a responsibility to make sure you're safe.\"\u003C\u002Fstrong\u003E\u003C\u002Fp\u003E\u003Cp\u003ETeen independence and parental boundaries don't have to cancel each other out. The challenge is finding a way for both to coexist.\u003C\u002Fp\u003E\u003Ch2 id=\"what-not-to-do-if-you-discover-a-secret-account\"\u003EWhat not to do if you discover a secret account\u003C\u002Fh2\u003E\u003Cp\u003ETry not to respond to one secret account by making privacy impossible. Understand what happened, address any broken rules or risks, and keep communication open enough that your teen is still willing to come to you when something goes wrong.\u003C\u002Fp\u003E\u003Ch3 id=\"don%E2%80%99t-confiscate-their-phone-indefinitely\"\u003EDon’t confiscate their phone indefinitely\u003C\u002Fh3\u003E\u003Cp\u003ETaking the phone away temporarily may sometimes be an appropriate consequence, but avoid dramatic punishments you can't realistically maintain, such as&nbsp;\u003Cem\u003E\"You're never getting your phone back.\"\u003C\u002Fem\u003E\u003C\u002Fp\u003E\u003Cp\u003EAs Anca points out, parents sometimes make absolute threats in the heat of the moment and then eventually give the phone back anyway.&nbsp;\u003Cstrong\u003EWhen parents don't follow through on what they say, it can undermine their credibility and authority.\u003C\u002Fstrong\u003E\u003C\u002Fp\u003E\u003Cp\u003EIf there is a consequence, make it realistic, time-limited, and connected to what actually happened.\u003C\u002Fp\u003E\u003Ch3 id=\"don%E2%80%99t-shame-or-label-them\"\u003EDon’t shame or label them\u003C\u002Fh3\u003E\u003Cp\u003EThere is an important difference between&nbsp;\u003Cem\u003E\"You lied to me about this account\"\u003C\u002Fem\u003E&nbsp;and&nbsp;\u003Cem\u003E\"You're a liar.\"\u003C\u002Fem\u003E&nbsp;One addresses a behavior that can be discussed and changed; the other turns that behavior into an identity.\u003C\u002Fp\u003E\u003Cp\u003EAnca also recommends avoiding consequences whose purpose is simply to&nbsp;\u003Cstrong\u003Epunish, shame, or \"teach them a lesson.\" \u003C\u002Fstrong\u003EThe goal should still be to help your teen understand the rule, take responsibility for what happened, and stay safe.\u003C\u002Fp\u003E\u003Ch3 id=\"don%E2%80%99t-threaten-to-monitor-everything-they-do\"\u003EDon’t threaten to monitor everything they do\u003C\u002Fh3\u003E\u003Cp\u003EAfter discovering a secret account, you may be tempted to say,&nbsp;\u003Cem\u003E\"From now on, I'm checking everything.\"\u003C\u002Fem\u003E&nbsp;But permanent surveillance can have the opposite effect of what you want.\u003C\u002Fp\u003E\u003Cp\u003EAs Anca explains,&nbsp;\u003Cstrong\u003Ewhen teenagers perceive parental behavior as an invasion of their privacy, they may become more secretive. Paradoxically, parents can end up knowing less about their child's life, not more.\u003C\u002Fstrong\u003E\u003C\u002Fp\u003E\u003Cp\u003EThere is an important exception. If you have genuine reasons to believe your teen is in danger,&nbsp;\u003Cstrong\u003Esafety takes priority over privacy\u003C\u002Fstrong\u003E, and closer monitoring or more direct intervention may be necessary.\u003C\u002Fp\u003E\u003Ch2 id=\"protect-them-without-invading-their-privacy\"\u003EProtect them without invading their privacy\u003C\u002Fh2\u003E\u003Cp\u003EKeeping your teen safe online doesn't have to mean reading every message, checking every conversation, or constantly looking over their shoulder.\u003C\u002Fp\u003E\u003Cp\u003EBitdefender Family Plans are designed to help families stay protected without turning digital safety into surveillance. Parents get tools to manage internet time, set age-appropriate boundaries, and help protect their children's devices, while the whole family benefits from protection against scams, phishing, malware, dangerous websites, and other online threats.\u003C\u002Fp\u003E\u003Cp\u003EAs teenagers become more independent, that balance matters.&nbsp;\u003C\u002Fp\u003E\u003Cp\u003EFind out more about your family safety plan,&nbsp;\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Ffamily\"\u003Ehere.\u003C\u002Fa\u003E\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003EYou may also want to read:\u003C\u002Fstrong\u003E\u003C\u002Fp\u003E\u003Cul\u003E\u003Cli\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fparents-need-know-instagram-finstagram-rinstagram\"\u003EWhat Parents Need to Know. Does Your Child Have a Secret Instagram Account?\u003C\u002Fa\u003E\u003C\u002Fli\u003E\u003Cli\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-au\u002Fblog\u002Fhotforsecurity\u002Fprivacy-vs-secrecy-in-adolescence-how-to-help-your-tween-tell-the-difference\"\u003EPrivacy vs. Secrecy in Adolescence: How to Help Your Tween Tell the Difference\u003C\u002Fa\u003E\u003C\u002Fli\u003E\u003Cli\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fkids-using-secret-decoy-apps-what-parents-need-to-know-about-the-dangers\"\u003EKids Using Secret Decoy Apps: What Parents Need to Know About the Dangers\u003C\u002Fa\u003E\u003C\u002Fli\u003E\u003Cli\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fage-verification-for-teens-privacy-risks\"\u003EAge verification for teens: Privacy risks parents should know\u003C\u002Fa\u003E\u003C\u002Fli\u003E\u003Cli\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fteen-social-media-ban-therapist-advice\"\u003EHow to handle teen social media bans, according to therapist\u003C\u002Fa\u003E\u003C\u002Fli\u003E\u003C\u002Ful\u003E\u003Cp\u003E&nbsp;\u003C\u002Fp\u003E\u003Ch2 id=\"faqs\"\u003EFAQs\u003C\u002Fh2\u003E\u003Ch3 id=\"\"\u003E&nbsp;\u003C\u002Fh3\u003E\u003Ch3 id=\"how-can-i-tell-if-my-teen-has-a-secret-social-media-account\"\u003EHow can I tell if my teen has a secret social media account?\u003C\u002Fh3\u003E\u003Cp\u003EThere is no single sign that proves your teen has a hidden account. Changes such as becoming unusually protective of their phone, hiding notifications, using unfamiliar email addresses, frequently clearing browsing history, or friends mentioning usernames you don't recognize may be worth paying attention to. Look for several changes together rather than relying on one sign.\u003C\u002Fp\u003E\u003Ch3 id=\"what-should-i-do-if-i-find-my-teen-has-a-secret-social-media-account\"\u003EWhat should I do if I find my teen has a secret social media account?\u003C\u002Fh3\u003E\u003Cp\u003EStart by finding out why the account was created and what your teen is doing there. Check for safety concerns, including contact with strangers, bullying, threats, inappropriate content, or sharing personal or intimate information. If a family rule or age restriction has been broken, address it clearly without turning the conversation into shame or indefinite punishment.\u003C\u002Fp\u003E\u003Ch3 id=\"should-parents-check-their-teenagers-social-media-accounts\"\u003EShould parents check their teenager's social media accounts?\u003C\u002Fh3\u003E\u003Cp\u003EParents should balance their responsibility for their child's safety with a teenager's growing need for privacy. Regular conversations, clear family rules, and age-appropriate parental controls are generally more sustainable than constantly reading messages or secretly monitoring everything a teen does. If there is a genuine safety concern, however, closer supervision may be necessary.\u003C\u002Fp\u003E\u003Ch3 id=\"can-teens-hide-social-media-accounts-from-parental-controls\"\u003ECan teens hide social media accounts from parental controls?\u003C\u002Fh3\u003E\u003Cp\u003ENo parental control tool can guarantee that a teenager won't find ways to hide an account or access social media another way. Parental controls can help parents set age-appropriate boundaries and manage device use, but they work best alongside clear rules and ongoing conversations about online safety.\u003C\u002Fp\u003E\u003Ch3 id=\"can-teens-use-a-vpn-to-bypass-social-media-restrictions\"\u003ECan teens use a VPN to bypass social media restrictions?\u003C\u002Fh3\u003E\u003Cp\u003EA VPN can change the apparent location of a device, so some teens may try to use one to get around location-based restrictions. However, a VPN cannot change a person's actual age or bypass every type of age-verification system. Parents should talk to teens about why age restrictions exist rather than treating a VPN as a solution for getting around them.\u003C\u002Fp\u003E",tags:[{id:ap,name:aq,slug:ar,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:aX,name:aY,slug:aZ,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:e,name:f,slug:d,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a}],authors:[{id:bA,name:bB,slug:bC,profile_image:bD,cover_image:a,bio:bE,website:a,location:a,facebook:a,twitter:a,meta_title:a,meta_description:a}],excerpt:"As countries introduce stricter age verification and social media restrictions for younger users, some teens may look for ways around the rules, including creating accounts their parents don't know about.\n\nIf you're wondering whether your teen has a secret social media account, here are the signs to watch for and how to address the situation without damaging trust, with insights from clinical psychologist and CBT psychotherapist Anca Ivu.\n\n\nKey takeaways:\n\n * Teens may create secret social media",reading_time:9,url:"\u002Fblog\u002Fhotforsecurity\u002Fsecret-social-media-account-teen\u002F"},{id:aH,title:aI,slug:aJ,feature_image:aK,featured:c,published_at:aL,custom_excerpt:a,html:aM,tags:[{id:i,name:j,slug:k,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:e,name:f,slug:d,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a}],authors:[{id:z,name:A,slug:B,profile_image:C,cover_image:a,bio:D,website:a,location:a,facebook:a,twitter:a,meta_title:a,meta_description:a}],excerpt:aN,reading_time:S,url:aO},{id:"6a8707948beeea96580291c4",title:"Australia gives Roblox 3 months to strengthen child safety amid grooming concerns",slug:"australia-roblox-3-months-safety",feature_image:"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002F11333328-fortnite-4129124.jpg",featured:c,published_at:"2026-08-20T17:14:14.000+03:00",custom_excerpt:bF,html:"\u003Cp\u003E\u003Cem\u003EAustralia has moved to strengthen Roblox child safety procedures after the country’s online safety regulator discovered gaps that could permit strangers to contact kids and view parts of their profiles without parental consent.\u003C\u002Fem\u003E\u003C\u002Fp\u003E\u003Cp\u003ENow Roblox has three months to strengthen its safeguards for Australian users. The company must restrict adult-to-child contact, make children’s accounts private by default, improve reporting outcomes, and submit its safety controls to an external audit, including age-estimation technologies.\u003C\u002Fp\u003E\u003Cp\u003EIf Roblox breaches the agreement, eSafety can ask the Federal Court to order compliance. Roblox says it believes it complies with Australia’s Online Safety Act, but it has agreed to the additional measures.\u003C\u002Fp\u003E\u003Ch2 id=\"key-takeaways\"\u003EKey takeaways\u003C\u002Fh2\u003E\u003Cul\u003E\n\u003Cli\u003EAustralia’s eSafety Commissioner accepted a court-enforceable undertaking from Roblox on August 20, 2026.\u003C\u002Fli\u003E\n\u003Cli\u003EeSafety testing found that adults could send connection requests to young children and that children’s profile details and connections could remain broadly visible.\u003C\u002Fli\u003E\n\u003Cli\u003ERoblox has three months to implement new controls and undergo an independent assessment of their effectiveness.\u003C\u002Fli\u003E\n\u003Cli\u003EThe undertaking does not mean every risk disappears. Parents should still review privacy, communication and spending settings with their child.\u003C\u002Fli\u003E\n\u003C\u002Ful\u003E\n\u003Ch2 id=\"what-did-australia-find-on-roblox\"\u003EWhat did Australia find on Roblox?\u003C\u002Fh2\u003E\u003Cp\u003EeSafety said testing earlier this year found safety issues that could have exposed kids to risks. The regulator said adult users could send connection requests to children without parental or carer consent.\u003C\u002Fp\u003E\u003Cp\u003EThey also discovered that children and adults could view and respond to each other’s posts in forums outside game environments without parental or carer consent. Children’s connections, account names, avatars, biographies and other information could also be visible across the platform, with no option to limit the visibility of that information.\u003C\u002Fp\u003E\u003Cp\u003ERoblox is especially important to Australian regulators because of its reach. eSafety cited research estimating that about 1.7 million Australian children use the platform, which it described as the country’s second-most-popular game among children. The regulator’s announcement attributes the estimate to Roy Morgan research.\u003C\u002Fp\u003E\u003Ch2 id=\"what-must-roblox-change-in-australia\"\u003EWhat must Roblox change in Australia?\u003C\u002Fh2\u003E\u003Cp\u003EUnder the undertaking, Roblox has committed to several measures intended to reduce unwanted adult-to-child contact and improve accountability:\u003C\u002Fp\u003E\u003Cul\u003E\n\u003Cli\u003EPrevent adults from contacting unknown children without parental consent\u003C\u002Fli\u003E\n\u003Cli\u003EMake children's accounts private by default\u003C\u002Fli\u003E\n\u003Cli\u003EAccessible reporting mechanisms that notify users of complaint outcomes is needed\u003C\u002Fli\u003E\n\u003Cli\u003EThe company must use an independent third-party auditor to assess the effectiveness of its safety measures, including the deployment of its age-estimation measures\u003C\u002Fli\u003E\n\u003C\u002Ful\u003E\n\u003Cp\u003EThe three-month deadline is significant. Roblox must not only announce changes; it must implement them. A breach could lead eSafety to seek a Federal Court order compelling compliance and any other order the court considers appropriate. \u003Ca href=\"https:\u002F\u002Fwww.esafety.gov.au\u002Fnewsroom\u002Fmedia-releases\u002Fesafety-secures-court-enforceable-undertaking-from-roblox-to-do-more-to-protect-australian-kids-from-grooming-and-sexual-exploitation\"\u003EeSafety\u003C\u002Fa\u003E did not state that the undertaking itself imposes an automatic fine.\u003C\u002Fp\u003E\u003Cp\u003ERoblox has already made age-based communication a major part of its safety strategy. In our earlier \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Froblox-selfie-age-check-teen\"\u003Ecoverage\u003C\u002Fa\u003E, we explained the company’s plans for age estimation, Trusted Connections and parent insights. Australia’s undertaking shifts the focus from product promises to independently verifiable results.\u003C\u002Fp\u003E\u003Ch2 id=\"what-can-parents-do-now\"\u003EWhat can parents do now?\u003C\u002Fh2\u003E\u003Cp\u003EThe undertaking applies in Australia and the promised changes need time to take effect. Parents don’t need to wait to reduce exposure to unwanted contact.\u003C\u002Fp\u003E\u003Col\u003E\n\u003Cli\u003EReview your child’s Roblox account privacy and communication controls together. Choose the most restrictive settings that still fit their age and how they use the platform.\u003C\u002Fli\u003E\n\u003Cli\u003EExplain that a friendly avatar or shared interest does not make an online contact trustworthy. Children should not move conversations to other apps, share personal details or accept requests from people they do not know offline.\u003C\u002Fli\u003E\n\u003Cli\u003EMake reporting a routine, not a last resort. Show your child how to block and report a user, and ask them to tell you if a stranger or an older-sounding person contacts them.\u003C\u002Fli\u003E\n\u003Cli\u003ECheck their friend list and profile. Remove unfamiliar connections and avoid including identifying information in a username, bio or avatar.\u003C\u002Fli\u003E\n\u003Cli\u003EKeep account credentials and payment details protected. Roblox-related scams and unofficial “executor” tools can expose accounts and devices to malware and fraud.\u003C\u002Fli\u003E\n\u003C\u002Fol\u003E\n\u003Ch2 id=\"faqs\"\u003EFAQs\u003C\u002Fh2\u003E\u003Ch3 id=\"is-roblox-banned-in-australia\"\u003EIs Roblox banned in Australia?\u003C\u002Fh3\u003E\u003Cp\u003ENo. Roblox has agreed to a court-enforceable undertaking with Australia’s eSafety regulator. The platform remains available, but it must introduce additional child-safety measures within three months.\u003C\u002Fp\u003E\u003Ch3 id=\"what-did-australia-find-wrong-with-roblox\"\u003EWhat did Australia find wrong with Roblox?\u003C\u002Fh3\u003E\u003Cp\u003EeSafety said its testing found that adult strangers could send connection requests to young children without parental consent. It also identified broadly visible children’s profile and connection information and adult-child interaction in some forum areas.\u003C\u002Fp\u003E\u003Ch3 id=\"when-will-roblox%E2%80%99s-new-australian-safety-measures-take-effect\"\u003EWhen will Roblox’s new Australian safety measures take effect?\u003C\u002Fh3\u003E\u003Cp\u003ERoblox has three months from the August 20, 2026 undertaking to implement the agreed changes.\u003C\u002Fp\u003E\u003Ch3 id=\"what-happens-if-roblox-does-not-comply\"\u003EWhat happens if Roblox does not comply?\u003C\u002Fh3\u003E\u003Cp\u003EeSafety can apply to Australia’s Federal Court for an order requiring Roblox to comply and for other orders the court considers appropriate. The regulator did not say the undertaking creates an automatic fine.\u003C\u002Fp\u003E\u003Ch3 id=\"should-parents-still-use-roblox-parental-controls\"\u003EShould parents still use Roblox parental controls?\u003C\u002Fh3\u003E\u003Cp\u003EYes. Platform-level safeguards help, but parents should still review privacy, communication, friend and spending settings with their child and discuss how to handle contact from strangers.\u003C\u002Fp\u003E\u003Ch2 id=\"more-related-to-this-subject\"\u003EMore related to this subject\u003C\u002Fh2\u003E\u003Cp\u003E·&nbsp;&nbsp;&nbsp; \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Froblox-selfie-age-check-teen?utm_source=chatgpt.com\"\u003ERoblox Introduces Selfie-Based Age Check for Teen Users\u003C\u002Fa\u003E\u003C\u002Fp\u003E\u003Cp\u003E·&nbsp;&nbsp;&nbsp; \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fkids-in-roblox-will-need-parents-consent-to-message-others?utm_source=chatgpt.com\"\u003EKids in Roblox Will Need Parent’s Consent to Message Others\u003C\u002Fa\u003E\u003C\u002Fp\u003E\u003Cp\u003E·&nbsp;&nbsp;&nbsp; \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Froblox-investigation-dutch-authorities-minors?utm_source=chatgpt.com\"\u003ERoblox Under Investigation as Dutch Authorities Cite Risks to Minors\u003C\u002Fa\u003E\u003C\u002Fp\u003E\u003Cp\u003E·&nbsp;&nbsp;&nbsp; \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Froblox-and-child-safety-what-parents-need-to-know?utm_source=chatgpt.com\"\u003ERoblox and Child Safety: What Parents Need to Know\u003C\u002Fa\u003E\u003C\u002Fp\u003E",tags:[{id:e,name:f,slug:d,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:ap,name:aq,slug:ar,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a}],authors:[{id:p,name:q,slug:r,profile_image:s,cover_image:t,bio:u,website:a,location:a,facebook:a,twitter:a,meta_title:a,meta_description:a}],excerpt:bF,reading_time:X,url:"\u002Fblog\u002Fhotforsecurity\u002Faustralia-roblox-3-months-safety\u002F"},{id:aP,title:aQ,slug:aR,feature_image:aS,featured:c,published_at:aT,custom_excerpt:a,html:aU,tags:[{id:i,name:j,slug:k,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:T,name:U,slug:V,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:e,name:f,slug:d,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a}],authors:[{id:z,name:A,slug:B,profile_image:C,cover_image:a,bio:D,website:a,location:a,facebook:a,twitter:a,meta_title:a,meta_description:a}],excerpt:aV,reading_time:S,url:aW}],sidePosts:[{id:_,title:$,slug:aa,feature_image:ab,featured:c,published_at:ac,custom_excerpt:x,html:bz,tags:[{id:O,name:P,slug:Q,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:e,name:f,slug:d,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:h,name:g,slug:g,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a}],authors:[{id:p,name:q,slug:r,profile_image:s,cover_image:t,bio:u,website:a,location:a,facebook:a,twitter:a,meta_title:a,meta_description:a}],excerpt:x,reading_time:W,url:ad},{id:au,title:av,slug:aw,feature_image:ax,featured:c,published_at:ay,custom_excerpt:a,html:"\u003Cp\u003EScammers can be frighteningly creative. And while we tend to imagine scams happening behind a phone or laptop screen, they don't always stay there.\u003C\u002Fp\u003E\u003Cp\u003EPolice in Kent, Ohio, are warning the public about a banking scam that can start with a simple text message and end with a stranger \u003Cstrong\u003Eshowing up at your front door to collect your bank card\u003C\u002Fstrong\u003E.\u003C\u002Fp\u003E\u003Ch2 id=\"key-takeaways\"\u003EKey takeaways\u003C\u002Fh2\u003E\u003Cul\u003E\u003Cli\u003E\u003Cstrong\u003EYour bank will not send someone to your home to collect a compromised debit or credit card.\u003C\u002Fstrong\u003E\u003C\u002Fli\u003E\u003Cli\u003E\u003Cstrong\u003ECaller ID isn't proof you're speaking with your bank.\u003C\u002Fstrong\u003E Scammers can spoof legitimate phone numbers.\u003C\u002Fli\u003E\u003Cli\u003E\u003Cstrong\u003EA scam that starts online can quickly move offline.\u003C\u002Fstrong\u003E Never assume you're physically distant from the people behind a text, email or phone scam.\u003C\u002Fli\u003E\u003Cli\u003E\u003Cstrong\u003EDon't move or withdraw money because someone claims your account is part of an investigation.\u003C\u002Fstrong\u003E\u003C\u002Fli\u003E\u003Cli\u003E\u003Cstrong\u003EIf someone unexpectedly comes to your home claiming to represent your bank, don't give them your card, PIN, cash or personal information.\u003C\u002Fstrong\u003E\u003C\u002Fli\u003E\u003Cli\u003E\u003Cstrong\u003EDiscuss new scams with your family.\u003C\u002Fstrong\u003E Parents, grandparents and other relatives should know about emerging tactics before they're confronted with them.\u003C\u002Fli\u003E\u003C\u002Ful\u003E\u003Ch2 id=\"how-does-the-bank-card-collection-scam-work\"\u003EHow does the bank card collection scam work?\u003C\u002Fh2\u003E\u003Cfigure class=\"kg-card kg-image-card\"\u003E\u003Cimg src=\"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002Fimage-6.png\" class=\"kg-image\" alt=\"\" loading=\"lazy\" width=\"767\" height=\"501\" srcset=\"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002Fsize\u002Fw600\u002F2026\u002F08\u002Fimage-6.png 600w, https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002Fimage-6.png 767w\" sizes=\"(min-width: 720px) 720px\"\u003E\u003C\u002Ffigure\u003E\u003Cp\u003E\u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002FKPDOhio\u002Fposts\u002Fpfbid02m8w6fb2egjuFYGPu8Rjh4W6tQp8eXPgAEQvSJrJUFrs6gKE7wpsTTNpSBAXRHbp8l?rdid=yuqcYeIuQvttWIRU\" rel=\"noreferrer\"\u003ESource\u003C\u002Fa\u003E\u003C\u002Fp\u003E\u003Cp\u003EAccording to Kent Police, the scheme can begin with a text message that looks like it comes from your bank.\u003C\u002Fp\u003E\u003Cp\u003EThe message asks if you recognize a supposedly suspicious transaction. This creates a sense of urgency and gives scammers a reason to contact you again.\u003C\u002Fp\u003E\u003Cp\u003ENext comes a phone call.\u003C\u002Fp\u003E\u003Cp\u003EThe criminal poses as a bank representative and claims your card has been compromised. Caller ID may even display what appears to be the bank's legitimate phone number.\u003C\u002Fp\u003E\u003Cp\u003EThat doesn't make the call genuine. Caller ID information can be spoofed, allowing scammers to disguise the number they're actually calling from.\u003C\u002Fp\u003E\u003Cp\u003EThen comes the twist that makes this scam stand out.\u003C\u002Fp\u003E\u003Cp\u003EThe supposed bank employee offers to send someone to your home to collect the compromised card and provide a temporary replacement.\u003C\u002Fp\u003E\u003Cp\u003EA person posing as a bank employee may subsequently arrive at the address, potentially wearing clothing intended to make the visit look legitimate.\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003E\u003Cem\u003EIt's a reminder that scammers aren't restricted to phishing emails, text messages or fraudulent websites. If a scheme requires someone to knock on your door to make the deception more believable, some criminals are willing to take that step.\u003C\u002Fem\u003E\u003C\u002Fstrong\u003E\u003C\u002Fp\u003E\u003Cp\u003EAnd if this sounds a bit familiar, that’s because it’s not the first time similar tactics have been used to steal people’s money.\u003C\u002Fp\u003E\u003Cp\u003EIf you’re a regular on our \u003Cem\u003EHot for Security\u003C\u002Fem\u003E blog, you’ve probably read about a similar scheme. For example, in July 2025, \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-au\u002Fblog\u002Fhotforsecurity\u002Fno-real-government-agents-dont-want-you-to-buy-gold-bars-how-to-spot-and-stop-this-scam\"\u003Ewe talked about gold-bar scams\u003C\u002Fa\u003E in which criminals impersonated government or law-enforcement officials and convinced victims to withdraw their savings, buy gold, and hand it to a supposed \"courier.\"\u003C\u002Fp\u003E\u003Cp\u003ENow, the scale of these schemes is becoming clearer. In August 2026, the NYPD \u003Ca href=\"https:\u002F\u002Fabcnews.com\u002FUS\u002Fscammers-target-seniors-steal-100m-gold-bar-scheme\u002Fstory?id=135430602\"\u003Ewarned\u003C\u002Fa\u003E that hundreds of victims may have lost more than $100 million to gold-bar scams. In many cases, a courier reportedly showed up at the victim's home to collect the gold while another scammer remained on the phone.\u003C\u002Fp\u003E\u003Ch2 id=\"when-an-online-scam-follows-you-into-the-real-world\"\u003EWhen an online scam follows you into the real world\u003C\u002Fh2\u003E\u003Cp\u003EThere's another reason this particular type of scam deserves your attention.\u003C\u002Fp\u003E\u003Cp\u003EWe often think of online scams as having a degree of physical separation. The criminal is somewhere behind a screen, while you're behind yours.\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003E\u003Cem\u003EBut think about it like this:\u003C\u002Fem\u003E\u003C\u002Fstrong\u003E\u003C\u002Fp\u003E\u003Cp\u003E&nbsp;If criminals have your name, phone number, and home address, and you engage with their initial messages, they may learn even more about you before someone arrives at your door.\u003C\u002Fp\u003E\u003Cp\u003EAn in-person visit could potentially reveal additional information about your household:\u003C\u002Fp\u003E\u003Cp\u003E·&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Who answers the door?\u003C\u002Fp\u003E\u003Cp\u003E·&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Does an older person live alone?\u003C\u002Fp\u003E\u003Cp\u003E·&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Are there other family members around?\u003C\u002Fp\u003E\u003Cp\u003E·&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; What security measures are visible?\u003C\u002Fp\u003E\u003Cp\u003E·&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Is there a doorbell camera?\u003C\u002Fp\u003E\u003Cp\u003E·&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Does the person appear particularly trusting or vulnerable?\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003EThere is no indication from the Kent Police warning that this scheme has led to burglaries or home invasions.\u003C\u002Fstrong\u003E Still, allowing someone involved in a scam to visit your home creates a physical-security concern that doesn't exist with an ordinary phishing email.\u003C\u002Fp\u003E\u003Cp\u003EAnd there's a broader issue worth considering. \u003Cstrong\u003E\u003Cem\u003EIf criminals know that someone has already responded to one scam, what's stopping them from trying again?\u003C\u002Fem\u003E\u003C\u002Fstrong\u003E\u003C\u002Fp\u003E\u003Cp\u003EScam victims can be targeted repeatedly, sometimes through completely different approaches. That's one more reason to treat an incident like this as more than a compromised bank card.\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003EAnd let’s break down the part that makes this type of scam so convincing.\u003C\u002Fstrong\u003E\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003EFirst of all, these fraudsters don’t rely on a single trick to con people. \u003C\u002Fstrong\u003EThey build credibility in multiple stages, using text messages to alert you, a phone call to confirm the “issue,” and personal information to establish trust.\u003C\u002Fp\u003E\u003Cp\u003E\u003Cem\u003EThen comes the solution to fix your problem: another person physically arriving at your door.\u003C\u002Fem\u003E\u003C\u002Fp\u003E\u003Cp\u003EEach step appears to confirm the one before it.\u003C\u002Fp\u003E\u003Cp\u003EThat's also why an unexpected call shouldn't be trusted simply because the caller knows something about you. Names, addresses, phone numbers, email addresses and other personal information can be obtained through data breaches, public records, social media, previous scams and other sources.\u003C\u002Fp\u003E\u003Cp\u003EAnd remember, \u003Cstrong\u003Eknowing your name, bank or address doesn't prove someone is legitimate. Sometimes it simply means a scammer has done their homework.\u003C\u002Fstrong\u003E\u003C\u002Fp\u003E\u003Ch2 id=\"will-a-bank-come-to-your-house-to-collect-a-compromised-card\"\u003EWill a bank come to your house to collect a compromised card?\u003C\u002Fh2\u003E\u003Cp\u003E\u003Cstrong\u003EDefinitely Not! A request to hand a payment card to someone arriving at your home should immediately raise alarm bells.\u003C\u002Fstrong\u003E\u003C\u002Fp\u003E\u003Cp\u003EIf your card really has been compromised, stop communicating with the person who contacted you and independently contact your bank.\u003C\u002Fp\u003E\u003Cp\u003EUse the official banking app, visit a branch, or call the verified telephone number printed on your card or published on the bank's official website.\u003C\u002Fp\u003E\u003Cp\u003EDon't use a phone number or link supplied in the suspicious text message.\u003C\u002Fp\u003E\u003Cp\u003EPolice also warn that legitimate banks and law enforcement agencies won't tell you to withdraw or move money because it's supposedly needed for an investigation.\u003C\u002Fp\u003E\u003Cp\u003ERequests to transfer your savings to a \"safe account,\" withdraw cash for safekeeping, hand over a bank card, or give someone your PIN are also \u003Cstrong\u003Emajor warning signs\u003C\u002Fstrong\u003E.\u003C\u002Fp\u003E\u003Ch2 id=\"what-if-someone-claiming-to-be-from-your-bank-comes-to-your-door\"\u003EWhat if someone claiming to be from your bank comes to your door?\u003C\u002Fh2\u003E\u003Cp\u003EDon't hand over your card, cash, PIN, account credentials or identification documents.\u003C\u002Fp\u003E\u003Cp\u003ERemember, \u003Cstrong\u003Eyou don't have to continue the conversation simply because someone is standing at your door.\u003C\u002Fstrong\u003E\u003C\u002Fp\u003E\u003Cp\u003EDon't let the visitor inside. Close the door and contact your bank independently. If the person refuses to leave, behaves aggressively or makes you feel unsafe, contact local law enforcement.\u003C\u002Fp\u003E\u003Cp\u003EUniforms, badges, branded clothing and caller ID can all be used to create an appearance of legitimacy. Verification should happen through a communication channel \u003Cstrong\u003Eyou choose\u003C\u002Fstrong\u003E, not one provided by the person asking for your money or card.\u003C\u002Fp\u003E\u003Ch2 id=\"what-should-you-do-if-you-receive-a-suspicious-bank-text\"\u003EWhat should you do if you receive a suspicious bank text?\u003C\u002Fh2\u003E\u003Cp\u003EIf you receive an unexpected fraud alert, don't panic. A few simple steps can help you determine whether there's actually a problem:\u003C\u002Fp\u003E\u003Cul\u003E\u003Cli\u003E\u003Cstrong\u003EDon't click links in the message.\u003C\u002Fstrong\u003E Open your banking app yourself or type the bank's official website into your browser.\u003C\u002Fli\u003E\u003Cli\u003E\u003Cstrong\u003EDon't continue an unexpected call.\u003C\u002Fstrong\u003E Hang up and contact the bank using a verified number.\u003C\u002Fli\u003E\u003Cli\u003E\u003Cstrong\u003ENever reveal your PIN, password or verification codes.\u003C\u002Fstrong\u003E\u003C\u002Fli\u003E\u003Cli\u003E\u003Cstrong\u003EDon't move money to protect it.\u003C\u002Fstrong\u003E Anyone urgently instructing you to transfer or withdraw your savings because your account is supposedly under attack should be treated with suspicion.\u003C\u002Fli\u003E\u003Cli\u003E\u003Cstrong\u003ENever hand your card to an unexpected visitor.\u003C\u002Fstrong\u003E\u003C\u002Fli\u003E\u003Cli\u003E\u003Cstrong\u003ECheck your account.\u003C\u002Fstrong\u003E Look for transactions, transfers or changes you don't recognize.\u003C\u002Fli\u003E\u003C\u002Ful\u003E\u003Cp\u003EYou can also check suspicious messages with \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fscamio\"\u003EBitdefender Scamio\u003C\u002Fa\u003E and inspect questionable URLs with \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Flink-checker\"\u003EBitdefender Link Checker\u003C\u002Fa\u003E before interacting with them.\u003C\u002Fp\u003E\u003Ch2 id=\"make-scam-awareness-a-family-conversation\"\u003EMake scam awareness a family conversation\u003C\u002Fh2\u003E\u003Cp\u003EThere's one security resource every family already has: \u003Cstrong\u003Eeach other\u003C\u002Fstrong\u003E.\u003C\u002Fp\u003E\u003Cp\u003EDon't wait until a parent or grandparent receives a suspicious phone call to explain how these scams work. Talk about new tactics when you hear about them.\u003C\u002Fp\u003E\u003Cp\u003EConsider making scam awareness a small monthly family habit. It doesn't need to be a cybersecurity lecture. Spend ten minutes talking about one or two scams you've recently encountered or read about. Show parents and grandparents examples of suspicious texts. Remind everyone that caller ID can be spoofed and that legitimate organizations won't pressure them into immediately handing over money, cards or passwords.\u003C\u002Fp\u003E\u003Cp\u003EMost importantly, agree on a simple family rule: \u003Cstrong\u003EIf something feels strange, urgent or frightening, call someone you trust before doing anything.\u003C\u002Fstrong\u003E\u003C\u002Fp\u003E\u003Cp\u003EThat conversation becomes even more important as scammers combine digital and real-world tactics. Protecting a family today isn't just about securing individual devices. It's about protecting the accounts, identities, money and personal information connected to everyone in the household.\u003C\u002Fp\u003E\u003Cp\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Ffamily\" rel=\"noreferrer\"\u003E\u003Cstrong\u003EBitdefender's family plans\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E are designed around that broader idea of protecting your entire digital life across the people and devices that matter to you. Combined with regular conversations about scams, technology can provide another layer of protection when fraudulent messages, malicious links and other threats reach family members.\u003C\u002Fp\u003E\u003Ch2 id=\"already-handed-over-your-card-act-quickly\"\u003EAlready handed over your card? Act quickly\u003C\u002Fh2\u003E\u003Cp\u003EIf you've given your card, PIN or banking information to someone you now suspect is a scammer, contact your bank immediately.\u003C\u002Fp\u003E\u003Cp\u003EAsk the bank to block the card and review the account for unauthorized transactions. Change compromised online-banking credentials and check whether unfamiliar beneficiaries, transfers or contact details have been added.\u003C\u002Fp\u003E\u003Cp\u003EIf you've shared passwords that you also use elsewhere, change those accounts too and use unique passwords going forward.\u003C\u002Fp\u003E\u003Cp\u003EReport the incident to local law enforcement and preserve text messages, phone numbers, screenshots, transaction records and any available doorbell or security-camera footage.\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003EBecause the scammers may now have your home address and know that someone at the address responded to their scheme, make sure everyone in the home knows what happened. Be particularly cautious about unexpected visitors, calls or follow-up messages.\u003C\u002Fstrong\u003E\u003C\u002Fp\u003E\u003Ch2 id=\"faqs\"\u003EFAQs\u003C\u002Fh2\u003E\u003Ch3 id=\"would-a-scammer-come-to-your-house\"\u003EWould a scammer come to your house?\u003C\u002Fh3\u003E\u003Cp\u003EYes. While many scams happen entirely through calls, texts, emails or websites, some schemes involve \u003Cstrong\u003Ein-person couriers or scammers coming directly to a victim's home\u003C\u002Fstrong\u003E.\u003C\u002Fp\u003E\u003Cp\u003EThe FBI has warned about scams in which criminals impersonating government agencies, banks or tech-support companies convince victims to withdraw cash or buy gold before sending a courier to collect it. \u003C\u002Fp\u003E\u003Ch3 id=\"can-someone-steal-your-money-if-they-have-your-bank-details\"\u003ECan someone steal your money if they have your bank details?\u003C\u002Fh3\u003E\u003Cp\u003EIt depends on what information they have. Knowing your bank's name or even some account information doesn't necessarily give a scammer direct access to your money, but those details can help them build a much more convincing attack.\u003C\u002Fp\u003E\u003Cp\u003EHowever, if a scammer has your \u003Cstrong\u003Ebank account number and routing number\u003C\u002Fstrong\u003E, they may attempt unauthorized withdrawals or payments from your account.\u003C\u002Fp\u003E\u003Cp\u003EAdditionally, scammers may use information they already have to impersonate your bank and trick you into revealing passwords, card information, PINs or one-time verification codes. They may also persuade you to authorize a transfer yourself.\u003C\u002Fp\u003E\u003Cp\u003EIf you believe your banking information has been compromised, contact your bank immediately using its official app, website or the number printed on your card.\u003C\u002Fp\u003E\u003Ch3 id=\"should-i-be-worried-if-a-scammer-has-my-address\"\u003EShould I be worried if a scammer has my address?\u003C\u002Fh3\u003E\u003Cp\u003EDon't panic, but take it seriously. Your home address alone usually isn't enough for someone to access your bank account, but scammers can combine it with other personal information to make future scams much more convincing.\u003C\u002Fp\u003E\u003Cp\u003EYour address can also be used for scams that reach your physical doorstep. In so-called \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-au\u002Fblog\u002Fhotforsecurity\u002Fbrushing-scams-with-a-twist-what-to-do-when-an-unexpected-package-asks-you-to-scan-a-qr-code\" rel=\"noreferrer\"\u003E\u003Cstrong\u003Ebrushing scams\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E, for example, criminals or unscrupulous sellers send packages you never ordered to your home. More recently, the FBI and FTC have warned about a variation involving unsolicited packages containing QR codes. The recipient may be encouraged to scan the code to discover who sent the \"gift\" or how to return it, only to be directed to a phishing site designed to steal personal or financial information or potentially download malicious software.\u003C\u002Fp\u003E\u003Cp\u003EReceiving a strange package doesn't necessarily mean you're in immediate physical danger. But it does show why you shouldn't dismiss the fact that a scammer has your address. Be alert for follow-up calls and messages, unexpected packages and people showing up at your door, and make sure everyone in your household knows what's happening.\u003C\u002Fp\u003E\u003Cp\u003EAnd never scan a QR code in an unsolicited package simply because you're curious about who sent it.\u003C\u002Fp\u003E",tags:[{id:m,name:n,slug:o,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:e,name:f,slug:d,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:h,name:g,slug:g,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a}],authors:[{id:F,name:G,slug:H,profile_image:I,cover_image:a,bio:J,website:a,location:a,facebook:a,twitter:a,meta_title:a,meta_description:a}],excerpt:az,reading_time:8,url:aA},{id:aB,title:aC,slug:aD,feature_image:aE,featured:c,published_at:aF,custom_excerpt:R,html:"\u003Cp\u003E\u003Cem\u003EValve warns Steam users not to accept gifts from people they don't know, but the practice remains common enough that the company specifically flags it as a potential source of fraud.\u003C\u002Fem\u003E\u003C\u002Fp\u003E\u003Cp\u003EUnsolicited games can be linked to payment-card fraud, phishing, or item-trading scams. These problems don’t always involve an obvious fake. A stranger offers you a free game, then claim they sent a gift by mistake, or direct the recipient to a page that supposedly lets them accept it.\u003C\u002Fp\u003E\u003Cp\u003EEach approach aims to turn this apparently benign interaction into something more valuable for the scammer: a Steam login, rare in-game items, a payment, or a way to convert a fraudulent purchase into legitimate value.\u003C\u002Fp\u003E\u003Ch2 id=\"key-takeaways\"\u003EKey takeaways\u003C\u002Fh2\u003E\u003Cul\u003E\n\u003Cli\u003EDecline Steam gifts from people you don't know, even when the offer appears genuine\u003C\u002Fli\u003E\n\u003Cli\u003ENever use a link in a chat, email, or Discord message to “accept” a gift or verify your account\u003C\u002Fli\u003E\n\u003Cli\u003EA gift may be bait for a trade, a fake refund request, or an attempt to launder money from payment-card fraud\u003C\u002Fli\u003E\n\u003C\u002Ful\u003E\n\u003Ch2 id=\"why-would-a-scammer-send-a-steam-gift\"\u003EWhy would a scammer send a Steam gift?\u003C\u002Fh2\u003E\u003Cp\u003ESteam lets users send games as gifts—a handy feature when you want to send something to a friend or a family member. But scammers have weaponized the feature.\u003C\u002Fp\u003E\u003Cp\u003EAn unsolicited gift from someone you don’t know can open a conversation, create a sense of obligation or make an unfamiliar account seem credible before the sender asks for something of greater value.\u003C\u002Fp\u003E\u003Cp\u003EThe clearest financial motive involves payment fraud. A scamer can buy a game with a stolen card, send it to another account, then ask the recipient for cash, Steam items, skins, cryptocurrency, or another gift.\u003C\u002Fp\u003E\u003Cp\u003EThat exchange turns a fraudulent purchase into value the criminal can keep or resell. If the payment is reversed, the recipient may lose the game and face questions about a fraudulent gift.\u003C\u002Fp\u003E\u003Cp\u003EValve's own account-restriction guidance is very clear: “Never accept a gift from an unknown user.” It specifically lists redeeming fraudulent gifts among conduct that can lead to account restrictions.\u003C\u002Fp\u003E\u003Ch2 id=\"how-steam-gift-scams-work\"\u003EHow Steam gift scams work\u003C\u002Fh2\u003E\u003Ch3 id=\"1-the-stolen-payment-card-gift\"\u003E1. The stolen-payment-card gift\u003C\u002Fh3\u003E\u003Cp\u003EThe sender offers a game bought with a compromised card, then asks for something they can transfer or resell: an item trade, a wallet-code purchase or payment outside Steam.\u003C\u002Fp\u003E\u003Cp\u003EThe request may sound reasonable: “I bought the wrong game; send me the equivalent in skins,” or “Accept it and give me half the price.” It isn't a resale arrangement. The sender keeps the clean value while the recipient becomes connected to the disputed purchase.\u003C\u002Fp\u003E\u003Ch3 id=\"2-the-%E2%80%98i-sent-it-by-mistake%E2%80%99-trade-scam\"\u003E2. The ‘I sent it by mistake’ trade scam\u003C\u002Fh3\u003E\u003Cp\u003EOther scammers use a small, real gift to establish credibility. Later, they claim they sent something expensive by mistake or need help reversing a transaction. They may demand rare CS2, Dota 2, or Team Fortress 2 items as “compensation.”\u003C\u002Fp\u003E\u003Cp\u003EThey rely on pressure: accusations of theft, threats to report the account or an invented deadline.\u003C\u002Fp\u003E\u003Ch3 id=\"3-the-fake-steam-gift-link\"\u003E3. The fake Steam gift link\u003C\u002Fh3\u003E\u003Cp\u003ESometimes there is no gift at all. A message may claim one is waiting, say Steam needs an age check, or require a login to view the sender's profile. The link can lead to a copy of Steam built to collect a username, password, Steam Guard code, or QR-code approval.\u003C\u002Fp\u003E\u003Cp\u003EWith access to an account, attackers can empty inventory, lock out the owner and message friends from a familiar profile.\u003C\u002Fp\u003E\u003Ch3 id=\"4-the-trust-building-setup\"\u003E4. The trust-building setup\u003C\u002Fh3\u003E\u003Cp\u003EA small gift can also make the sender appear friendly. After a few messages, they may pitch a “sponsor” offer, a tournament, a high-value trade or a supposed Steam Support investigation. They may also push the conversation to Discord or other platforms, away from the context in which the offer began.\u003C\u002Fp\u003E\u003Cp\u003EValve \u003Ca href=\"https:\u002F\u002Fhelp.steampowered.com\u002Fen\u002Ffaqs\u002Fview\u002F4F62-35F9-F395-5C23\"\u003Esays\u003C\u002Fa\u003E its employees never discuss account issues through Steam Chat or Discord. Anyone who claims to be Valve or Steam Support and asks you to verify items should be reported for trade scams.\u003C\u002Fp\u003E\u003Ch2 id=\"how-to-tell-a-real-steam-gift-from-a-scam\"\u003EHow to tell a real Steam gift from a scam\u003C\u002Fh2\u003E\u003Cp\u003EIf you don't know the sender, decline the gift. This is the most effective way to ensure you stay safe and that your account won’t be affected by possible bans.\u003C\u002Fp\u003E\u003Cp\u003EFor gifts from actual friends or family, verify the situation independently. Ask the person via a separate method whether they sent it, especially if their account suddenly writes in an unusual tone or asks you to click a link.\u003C\u002Fp\u003E\u003Cp\u003EWarning signs include:\u003C\u002Fp\u003E\u003Cul\u003E\n\u003Cli\u003EThe sender is an unfamiliar account or recently added you as a friend\u003C\u002Fli\u003E\n\u003Cli\u003EThe message creates urgency: “Accept in five minutes” or “your account will be banned”\u003C\u002Fli\u003E\n\u003Cli\u003EThe sender wants payment, skins, Steam Wallet codes, crypto, or another gift in return\u003C\u002Fli\u003E\n\u003Cli\u003EThe sender asks you to move to Discord, Telegram, or another platform\u003C\u002Fli\u003E\n\u003Cli\u003EA link asks for your Steam password, Steam Guard code, QR scan, or other login approval\u003C\u002Fli\u003E\n\u003Cli\u003ESomeone claims to be a Valve employee and demands that you trade or “verify” your items\u003C\u002Fli\u003E\n\u003C\u002Ful\u003E\n\u003Cp\u003EA real gift doesn't require payment to a stranger, login credentials or a detour outside Steam's ecosystem. Open Steam yourself to check account notifications and support information.\u003C\u002Fp\u003E\u003Ch2 id=\"what-to-do-if-an-unknown-account-sends-you-a-gift\"\u003EWhat to do if an unknown account sends you a gift\u003C\u002Fh2\u003E\u003Cp\u003E\u003Cstrong\u003E1.\u003C\u002Fstrong\u003E Don't accept or redeem it. Decline the offer.\u003Cbr\u003E\n\u003Cstrong\u003E2.\u003C\u002Fstrong\u003E Don't negotiate. Don't send money or items to “return” a mistaken gift.\u003Cbr\u003E\n\u003Cstrong\u003E3.\u003C\u002Fstrong\u003E Block and report the account. Preserve screenshots if the sender used threats, links, or impersonation.\u003Cbr\u003E\n\u003Cstrong\u003E4.\u003C\u002Fstrong\u003E Open Steam Support yourself. Type the address or use the support option within Steam; don't follow the sender's link.\u003Cbr\u003E\n\u003Cstrong\u003E5.\u003C\u002Fstrong\u003E Tell friends who may receive the same message. Compromised accounts often contact people from an existing friend list.\u003C\u002Fp\u003E\n\u003Ch2 id=\"what-to-do-if-you-clicked-a-link-or-accepted-the-gift\"\u003EWhat to do if you clicked a link or accepted the gift\u003C\u002Fh2\u003E\u003Cp\u003EIf you only received an unsolicited gift and took no action, decline it and cut contact. If you typed credentials into a suspicious page, approved a Steam Guard prompt, scanned a QR code, or traded items, act quickly.\u003C\u002Fp\u003E\u003Cul\u003E\n\u003Cli\u003EChange your Steam password from the official Steam website or client\u003C\u002Fli\u003E\n\u003Cli\u003EReview Steam Guard and remove any unfamiliar devices or authorizations\u003C\u002Fli\u003E\n\u003Cli\u003ECheck recent trades, market listings, and account activity for anything you didn't approve\u003C\u002Fli\u003E\n\u003Cli\u003EUse the official Steam Support site to report account compromise or an item scam\u003C\u002Fli\u003E\n\u003Cli\u003EChange the password on the email account linked to Steam if you reused credentials or believe it may be exposed\u003C\u002Fli\u003E\n\u003C\u002Ful\u003E\n\u003Cp\u003EEnable Steam Guard and use a unique password for Steam. Multi-factor authentication makes it harder for an attacker to enter an account even after obtaining a password, according to the FTC.\u003C\u002Fp\u003E\u003Ch2 id=\"faq\"\u003EFAQ\u003C\u002Fh2\u003E\u003Ch3 id=\"is-it-safe-to-accept-a-steam-gift-from-a-stranger\"\u003EIs it safe to accept a Steam gift from a stranger?\u003C\u002Fh3\u003E\u003Cp\u003E\u003Cstrong\u003EAnswer:\u003C\u002Fstrong\u003E No. Valve specifically advises users never to accept gifts from unknown users.\u003C\u002Fp\u003E\u003Ch3 id=\"can-someone-steal-my-steam-account-by-sending-a-gift\"\u003ECan someone steal my Steam account by sending a gift?\u003C\u002Fh3\u003E\u003Cp\u003E\u003Cstrong\u003EAnswer:\u003C\u002Fstrong\u003E A gift notification alone doesn't give someone access to your account.\u003C\u002Fp\u003E\u003Ch3 id=\"what-happens-if-a-steam-gift-was-bought-with-a-stolen-card\"\u003EWhat happens if a Steam gift was bought with a stolen card?\u003C\u002Fh3\u003E\u003Cp\u003E\u003Cstrong\u003EAnswer:\u003C\u002Fstrong\u003E The payment can be disputed and reversed. Valve says redeeming fraudulent gifts can lead to account restrictions, so don't accept gifts from unknown accounts.\u003C\u002Fp\u003E\u003Ch3 id=\"does-steam-support-contact-users-on-discord\"\u003EDoes Steam Support contact users on Discord?\u003C\u002Fh3\u003E\u003Cp\u003E\u003Cstrong\u003EAnswer:\u003C\u002Fstrong\u003E No. Valve says Steam employees won't communicate about account issues through chat systems, including Steam Chat and Discord.\u003C\u002Fp\u003E\u003Ch3 id=\"should-i-repay-someone-who-says-they-sent-me-a-steam-gift-by-mistake\"\u003EShould I repay someone who says they sent me a Steam gift by mistake?\u003C\u002Fh3\u003E\u003Cp\u003E\u003Cstrong\u003EAnswer:\u003C\u002Fstrong\u003E Don't send money, items, gift cards, or cryptocurrency. Decline the gift, block the sender, and report suspicious conduct through Steam.\u003C\u002Fp\u003E",tags:[{id:m,name:n,slug:o,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:e,name:f,slug:d,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:h,name:g,slug:g,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a}],authors:[{id:p,name:q,slug:r,profile_image:s,cover_image:t,bio:u,website:a,location:a,facebook:a,twitter:a,meta_title:a,meta_description:a}],excerpt:R,reading_time:E,url:aG},{id:"6a7adfcb8beeea9658028a0d",title:"Deepfake OnlyFans accounts are scamming fans and putting creators at risk",slug:"deepfake-onlyfans-account-scam",feature_image:"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002Fdeepfake-onlyfans.jpg",featured:c,published_at:"2026-08-11T11:47:29.000+03:00",custom_excerpt:a,html:"\u003Cp\u003EA familiar OnlyFans creator appears in your TikTok feed. She looks into the camera, speaks in a recognizable voice and invites you to continue the conversation somewhere more private. Soon, she offers exclusive content in return for a quick payment.\u003C\u002Fp\u003E\u003Cp\u003EExcept the creator never recorded the video, never sent the messages and never received the money.\u003C\u002Fp\u003E\u003Cp\u003EAccording to reports, scammers are now stealing creators’ photos and videos, animating still images, cloning voices and building fake social media accounts to deceive their fans.\u003C\u002Fp\u003E\u003Cp\u003EThe fraud may begin with a synthetic video, but it ultimately relies on a combination of impersonation, emotional manipulation and hard-to-reverse payments.\u003C\u002Fp\u003E\u003Ch2 id=\"key-takeaways\"\u003EKey takeaways\u003C\u002Fh2\u003E\n\u003Cul\u003E\n\u003Cli\u003EScammers are using stolen creator content, animated images and cloned voices to build convincing OnlyFans impersonations\u003C\u002Fli\u003E\n\u003Cli\u003EFake accounts may approach fans on TikTok before moving conversations to private messaging apps such as Snapchat\u003C\u002Fli\u003E\n\u003Cli\u003EVictims are asked to pay through peer-to-peer services for exclusive content or live interactions that never arrive\u003C\u002Fli\u003E\n\u003Cli\u003EBoth sides face harm: fans lose money, while creators suffer lost income, reputational damage and even threats to their physical safety\u003C\u002Fli\u003E\n\u003Cli\u003EVerify every unexpected approach through the creator’s official account and never treat a familiar face or voice as proof of identity\u003C\u002Fli\u003E\n\u003Cli\u003ELook for visual, audio and behavioral warning signs, then use a dedicated deepfake detector when a video remains suspicious\u003C\u002Fli\u003E\n\u003C\u002Ful\u003E\n\u003Ch2 id=\"how-the-scam-moves-from-a-fake-video-to-real-payment\"\u003EHow the scam moves from a fake video to real payment\u003C\u002Fh2\u003E\u003Cp\u003E\u003C\u002Fp\u003E\u003Cp\u003EThe scheme is a technologically enhanced form of catfishing. Instead of relying only on stolen profile pictures, criminals now use AI tools to make a still image appear to speak, then pair it with a synthetic version of the creator’s voice.\u003C\u002Fp\u003E\u003Cp\u003EScammers have used this material to create fake accounts on social platforms like TikTok. They then encourage fans to move to a direct-messaging service such as Snapchat, where the conversation is less visible and the imposter can apply pressure one-on-one.\u003C\u002Fp\u003E\u003Cp\u003EThe fake creator eventually offers exclusive content or a live interaction in exchange for payment, sometimes through Cash App, which lets users easily send, receive, and save money. Once the payment arrives, the scammer blocks the fan and disappears.\u003C\u002Fp\u003E\u003Cp\u003EPeer-to-peer payment apps are especially useful to fraudsters because transfers can clear quickly and may be difficult to reverse.\u003C\u002Fp\u003E\u003Ch2 id=\"a-classic-deepfake-scam\"\u003EA classic deepfake scam\u003C\u002Fh2\u003E\u003Cp\u003E\u003C\u002Fp\u003E\u003Cp\u003EA deepfake is media created with AI to make someone appear to say or do something they never said or did. It can involve a face swap, altered lip movements, a cloned voice, a fully generated scene or a mixture of authentic and fabricated elements.\u003C\u002Fp\u003E\u003Cp\u003EIn this campaign, scammers do not necessarily need a flawless, cinema-quality fake. They need just enough movement, speech and familiarity to make a stolen image feel like fresh proof that the account is genuine.\u003C\u002Fp\u003E\u003Cp\u003EOne fake TikTok video reportedly impersonating creator Elaina St. James animated a still photo and cloned her voice. The illusion was not perfect: the teeth appeared distorted and the eyebrows remained unnaturally still.\u003C\u002Fp\u003E\u003Cp\u003ESocial media viewers tend to watch short clips quickly and on small screens, making imperfections easier to miss.\u003C\u002Fp\u003E\u003Ch2 id=\"two-sets-of-victims\"\u003ETwo sets of victims\u003C\u002Fh2\u003E\u003Cp\u003E\u003C\u002Fp\u003E\u003Cp\u003EFans who send money are the most obvious victims, but the fraud also shifts blame and risk onto the person being impersonated.\u003C\u002Fp\u003E\u003Cp\u003ECreator Jessieanna Campbell \u003Ca href=\"https:\u002F\u002Feu.usatoday.com\u002Fstory\u002Flife\u002Fhealth-wellness\u002F2026\u002F08\u002F03\u002Fonlyfans-creators-ai-imposters-deepfake-scammers\u002F91095998007\u002F\"\u003Etold\u003C\u002Fa\u003E USA Today that she regularly hears from confused fans who believe she accepted payments and then blocked them. One reported complaint involved $150.\u003C\u002Fp\u003E\u003Cp\u003EThe victim believed the face and voice belonged to the real creator, so the anger may be directed at her rather than at the unknown scammer.\u003C\u002Fp\u003E\u003Cp\u003EThe consequences can move offline. USA Today also spoke with a creator who said angry fans had come to her home, leaving her afraid to go outside at times. Impersonation can therefore cost creators income and trust while exposing them to harassment or physical danger.\u003C\u002Fp\u003E\u003Ch2 id=\"a-convincing-face\"\u003EA convincing face\u003C\u002Fh2\u003E\u003Cp\u003E\u003C\u002Fp\u003E\u003Cp\u003EPeople naturally use faces, voices and apparent live interaction as evidence of identity. Deepfakes exploit that reflex by borrowing a real person’s credibility and placing it inside a false story.\u003C\u002Fp\u003E\u003Cp\u003EBitdefender’s \u003Ca href=\"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Ffiles\u002F2025\u002F11\u002F11052025-2025-Consumer-Cybersecurity-Survey.pdf?_gl=1*6jca3p*_ga*MTI2Mzk0NTA1My4xNzgxNzY2MDQz*_ga_6M0GWNLLWF*czE3ODY0MzE4Mzgkbzk4JGcxJHQxNzg2NDMyOTAyJGo2MCRsMCRoMTE5NDQ0MTMyMA..*_fplc*bU5SU3c5WHpUUWEzT014TWxWSWVxUE9NeHA2V2RCMHM1bzBzUGYyOVFhTVlSUFJsT0ZuOFpsdlVmbUc3ZUZCMjBWOHVxM25hUUoyb2U1QjBHWXJJNjBQdWlUcEtHMGZuJTJCWjFUemhYSCUyRlVabkpFNUpoMlluY1EwNDRtQVFXUSUzRCUzRA..*FPAU*MTkwNjEwOTEyMy4xNzgxNzY4NjM3\"\u003E\u003Cstrong\u003E2025 Consumer Cybersecurity Survey\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E of more than 7,000 internet users in seven countries found that \u003Cstrong\u003E37% consider deepfake videos a top concern regarding AI’s use in scams\u003C\u002Fstrong\u003E.\u003C\u002Fp\u003E\u003Cfigure class=\"kg-card kg-image-card\"\u003E\u003Cimg src=\"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002Fchart-1-2.jpg\" class=\"kg-image\" alt=\"\" loading=\"lazy\" width=\"600\" height=\"492\" srcset=\"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002Fchart-1-2.jpg 600w\"\u003E\u003C\u002Ffigure\u003E\u003Cp\u003E\u003Cstrong\u003ESocial media was the leading scam-delivery channel\u003C\u002Fstrong\u003E, cited by \u003Cstrong\u003E34%\u003C\u002Fstrong\u003E of respondents, while \u003Cstrong\u003E66%\u003C\u002Fstrong\u003E said they \u003Cstrong\u003Epost personal content\u003C\u002Fstrong\u003E such as photos, videos and milestones online.\u003C\u002Fp\u003E\u003Cp\u003EThat public material gives impersonators a person’s voice, expressions, routines, relationships and communication style — ingredients for a tailored scam.\u003C\u002Fp\u003E\u003Ch2 id=\"how-to-spot-an-onlyfans-deepfake-scam\"\u003EHow to spot an OnlyFans deepfake scam\u003C\u002Fh2\u003E\u003Cp\u003E\u003C\u002Fp\u003E\u003Cp\u003EAs we explain in \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fhow-to-detect-fake-video-deepfake\"\u003E\u003Cstrong\u003Eour guide to spotting deepfake videos\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E, no single glitch proves that a video is fake. Compression, filters and poor lighting can also create strange effects.\u003C\u002Fp\u003E\u003Cp\u003ELook at the source, the media and the request together.\u003C\u002Fp\u003E\u003Ch3 id=\"start-with-the-account\"\u003E\u003Cstrong\u003EStart with the account\u003C\u002Fstrong\u003E\u003C\u002Fh3\u003E\u003Cp\u003ECheck whether the message came from the creator’s verified account or from a new profile using a similar name.\u003C\u002Fp\u003E\u003Cp\u003EVisit the creator’s known website or official social media accounts directly rather than following a link supplied by the sender. Search for warnings about impersonators and confirm whether the creator actually uses the platform where you were contacted.\u003C\u002Fp\u003E\u003Ch3 id=\"replay-the-face-and-mouth\"\u003E\u003Cstrong\u003EReplay the face and mouth\u003C\u002Fstrong\u003E\u003C\u002Fh3\u003E\u003Cp\u003ESlow down a short section and look to see whether the lips match the words.\u003C\u002Fp\u003E\u003Cp\u003ELook for teeth that merge or change shape, frozen eyebrows, blurred facial edges, skin texture that shifts between frames, or hair and accessories that briefly disappear. These are reasons to investigate further, not proof by themselves.\u003C\u002Fp\u003E\u003Ch3 id=\"listen-beyond-the-familiar-voice\"\u003E\u003Cstrong\u003EListen beyond the familiar voice\u003C\u002Fstrong\u003E\u003C\u002Fh3\u003E\u003Cp\u003EA cloned voice may sound recognizable despite unnatural pauses, flat emotion, missing breaths or odd pronunciation. Background noise may cut in and out while the voice remains unnaturally clean.\u003C\u002Fp\u003E\u003Cp\u003EDo not use voice recognition alone to confirm identity.\u003C\u002Fp\u003E\u003Ch3 id=\"examine-what-the-person-wants\"\u003E\u003Cstrong\u003EExamine what the person wants\u003C\u002Fstrong\u003E\u003C\u002Fh3\u003E\u003Cp\u003EThe behavior may expose the scam even when the video does not.\u003C\u002Fp\u003E\u003Cp\u003EBe wary when someone quickly tries to switch you to a private chat, promises a live interaction, demands secrecy or requests advance payment through a peer-to-peer app, cryptocurrency, gift card or another difficult-to-reverse method.\u003C\u002Fp\u003E\u003Ch3 id=\"verify-through-a-separate-channel\"\u003E\u003Cstrong\u003EVerify through a separate channel\u003C\u002Fstrong\u003E\u003C\u002Fh3\u003E\u003Cp\u003EContact the creator only through an official account you locate independently. Do not simply ask the suspicious profile for proof of identity—the scammer controls that channel and can send more fabricated material.\u003C\u002Fp\u003E\u003Cp\u003EFor an additional check, \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fdeepfake-detector-bitdefender-realcheck\"\u003E\u003Cstrong\u003EBitdefender RealCheck\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E can analyze a suspicious video for signs of manipulation and deceptive intent. A detection tool should support independent verification, not replace it.\u003C\u002Fp\u003E\u003Ch2 id=\"what-to-do-if-you-encounter-or-pay-a-fake-account\"\u003EWhat to do if you encounter (or pay) a fake account\u003C\u002Fh2\u003E\u003Cp\u003E\u003C\u002Fp\u003E\u003Cul\u003E\u003Cli\u003EStop communicating and do not send more money or personal information\u003C\u002Fli\u003E\u003Cli\u003ESave the profile name, messages, payment details, video links and screenshots before the account disappears\u003C\u002Fli\u003E\u003Cli\u003EReport the impersonation to every platform involved\u003C\u002Fli\u003E\u003Cli\u003EContact the payment provider immediately and ask whether the transfer can be stopped or disputed\u003C\u002Fli\u003E\u003Cli\u003ENotify the real creator through a verified channel without blame or threats\u003C\u002Fli\u003E\u003Cli\u003EChange any password you disclosed and enable two-factor authentication on affected accounts\u003C\u002Fli\u003E\u003Cli\u003EReport the fraud to the national consumer-protection or cybercrime authority\u003C\u002Fli\u003E\u003C\u002Ful\u003E\u003Cp\u003ECreators targeted by impersonation should also document each account, alert followers through verified channels and avoid exposing home addresses, real-time locations or other details that could help an angry or confused fan find them offline.\u003C\u002Fp\u003E\u003Ch2 id=\"deepfake-scams-dont-have-to-be-perfect-to-work\"\u003EDeepfake scams don't have to be perfect to work\u003C\u002Fh2\u003E\u003Cp\u003E\u003C\u002Fp\u003E\u003Cp\u003EA short synthetic video can provide a spark of credibility, while private messages, emotional attention and an urgent payment request do the rest.\u003C\u002Fp\u003E\u003Cp\u003EIf a supposed creator contacts you away from their official platform, don’t let a familiar face or voice settle the question.\u003C\u002Fp\u003E\u003Cp\u003EPause, inspect the account and the video, verify the approach independently and \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fdeepfake-detector-bitdefender-realcheck\"\u003Euse a detection tool\u003C\u002Fa\u003E when needed.\u003C\u002Fp\u003E\u003Cp\u003E\u003Cstrong\u003E\u003Cem\u003ERelated:\u003C\u002Fem\u003E\u003C\u002Fstrong\u003E\u003C\u002Fp\u003E\u003Cp\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fdeepfake-romance-scams\"\u003E\u003Cstrong\u003E\u003Cem\u003EDeepfakes are making romance scams harder to doubt\u003C\u002Fem\u003E\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E\u003C\u002Fp\u003E\u003Cp\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fhow-to-detect-fake-video-deepfake\"\u003E\u003Cstrong\u003E\u003Cem\u003EIs that video real? How to spot a deepfake before it fools you\u003C\u002Fem\u003E\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E\u003C\u002Fp\u003E\u003Cp\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fdeepfake-detector-bitdefender-realcheck\"\u003E\u003Cstrong\u003E\u003Cem\u003EThe deepfake detector in your pocket: introducing Bitdefender RealCheck\u003C\u002Fem\u003E\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E\u003C\u002Fp\u003E",tags:[{id:i,name:j,slug:k,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:m,name:n,slug:o,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:"696f63bc2fa53a9f2eef2657",name:"AI",slug:"ai",description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:h,name:g,slug:g,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:e,name:f,slug:d,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a}],authors:[{id:ae,name:af,slug:ag,profile_image:ah,cover_image:a,bio:ai,website:a,location:a,facebook:a,twitter:a,meta_title:a,meta_description:a}],excerpt:"A familiar OnlyFans creator appears in your TikTok feed. She looks into the camera, speaks in a recognizable voice and invites you to continue the conversation somewhere more private. Soon, she offers exclusive content in return for a quick payment.\n\nExcept the creator never recorded the video, never sent the messages and never received the money.\n\nAccording to reports, scammers are now stealing creators’ photos and videos, animating still images, cloning voices and building fake social media ac",reading_time:E,url:"\u002Fblog\u002Fhotforsecurity\u002Fdeepfake-onlyfans-account-scam\u002F"},{id:"6a75e8fd8beeea96580288b1",title:"Just because you use a Mac doesn't mean you're safe from ClickFix attacks",slug:"mac-not-safe-clickfix-attacks",feature_image:"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002FChatGPT-Image-Aug-7--2026--05_16_19-PM.png",featured:c,published_at:"2026-08-07T17:22:42.000+03:00",custom_excerpt:bG,html:"\u003Cp\u003EMac users are encountering fake CAPTCHA checks, download prompts and troubleshooting pages that tell them to open Terminal and paste a command, just like on a Windows PC. That “verification,” however, can install an information stealer instead.\u003C\u002Fp\u003E\u003Cp\u003EJust a few days ago, Microsoft \u003Ca href=\"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F08\u002F05\u002Fmacos-clickfix-campaign-learned-hide\u002F\" rel=\"noreferrer\"\u003Etracked\u003C\u002Fa\u003E campaigns that use this ClickFix tactic to deliver MacSync and Atomic Stealer (AMOS), but it has been happening for a while. The message is simple: while macOS security features help, they won’t protect users if they run the attacker’s command themselves.\u003C\u002Fp\u003E\u003Ch2 id=\"key-takeaways\"\u003EKey takeaways\u003C\u002Fh2\u003E\u003Cul\u003E\n\u003Cli\u003EClickFix is a social-engineering attack, not a conventional app download. It tries to trick you into copying and running a command.\u003C\u002Fli\u003E\n\u003Cli\u003EMac-focused lures impersonate CAPTCHAs, software downloads and fixes for common problems such as low disk space.\u003C\u002Fli\u003E\n\u003Cli\u003EThe resulting malware can target browser data, Keychain entries, iCloud-related data and cryptocurrency wallets.\u003C\u002Fli\u003E\n\u003Cli\u003EA real CAPTCHA never needs you to open Terminal, paste a command or run a script.\u003C\u002Fli\u003E\n\u003Cli\u003EIf you have followed one of these prompts, disconnect the Mac from the internet, change passwords from a clean device and get the system checked promptly.\u003C\u002Fli\u003E\n\u003C\u002Ful\u003E\n\u003Ch2 id=\"what-is-a-mac-clickfix-attack\"\u003EWhat is a Mac ClickFix attack?\u003C\u002Fh2\u003E\u003Cp\u003EClickFix is a type of scam that turns a victim into the person who launches the malware. Instead of tricking the user into downloading a suspicious app, a website will display a fake error, a CAPTCHA prompt, or an installation step. It then instructs the victim to copy a command, open Terminal, paste it and press Enter.\u003C\u002Fp\u003E\u003Ch2 id=\"are-macs-safe-from-clickfix-attacks\"\u003EAre Macs safe from ClickFix attacks?\u003C\u002Fh2\u003E\u003Cp\u003ENo. ClickFix attacks target Mac users with fake CAPTCHAs, download pages and troubleshooting guides that tell them to paste a command into Terminal. This simple action can download the infostealer malware, which may steal browser data, Keychain entries, iCloud-related data and cryptocurrency wallet information.\u003C\u002Fp\u003E\u003Cp\u003EA legitimate CAPTCHA never asks you to open Terminal or paste a command.\u003C\u002Fp\u003E\u003Ch2 id=\"why-macos-protections-dont-stop-all-clickfix-scams\"\u003EWhy macOS protections don't stop all ClickFix scams\u003C\u002Fh2\u003E\u003Cp\u003EApple’s security layers, including Gatekeeper, code-signing checks and notarization, offer users protection against many malicious applications.\u003C\u002Fp\u003E\u003Cp\u003EWhen a user launches a downloaded app through Finder, macOS can apply its normal application-trust checks. When that same user runs a command in Terminal, the command can retrieve scripts or payloads remotely.\u003C\u002Fp\u003E\u003Cp\u003EThat does not mean macOS is insecure. It means the attacker has shifted from defeating a technical barrier to defeating the user. Dedicated security software and platform defenses can still detect parts of the chain, but no product can make “paste this unknown command into Terminal” a safe decision.\u003C\u002Fp\u003E\u003Ch2 id=\"what-attackers-can-steal\"\u003EWhat attackers can steal\u003C\u002Fh2\u003E\u003Cp\u003EThe malware behind Mac ClickFix attacks usually aims to steal information, not display ads or slow down a computer. Attackers may use stolen browser sessions, saved passwords and authentication data to take over accounts after the initial infection. That makes a successful ClickFix attack potentially wider than a single compromised Mac.\u003C\u002Fp\u003E\u003Cp\u003EFor example, \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Flabs\u002Ffake-claude-code-google-ads-malware\"\u003EBitdefender researchers documented\u003C\u002Fa\u003E the same deception in a March 2026 campaign that abused Google Ads to impersonate Claude Code. A sponsored result led people to a fake documentation page hosted on a Squarespace subdomain; Mac visitors received an obfuscated command that decoded content and fetched a Mach-O backdoor.\u003C\u002Fp\u003E\u003Ch2 id=\"how-to-spot-and-stop-a-fake-captcha\"\u003EHow to spot and stop a fake CAPTCHA\u003C\u002Fh2\u003E\u003Cp\u003EFollow this rule: \u003Cstrong\u003Ea website must never require Terminal to prove that you are human.\u003C\u002Fstrong\u003E Close the page if it asks you to:\u003C\u002Fp\u003E\u003Cul\u003E\n\u003Cli\u003EPress Command + Space to open Spotlight, then open Terminal\u003C\u002Fli\u003E\n\u003Cli\u003EPaste a “verification code,” “token” or command\u003C\u002Fli\u003E\n\u003Cli\u003ERun text that starts with curl, bash, zsh, osascript, python, base64 or a long unreadable string\u003C\u002Fli\u003E\n\u003Cli\u003EBypass macOS warnings, disable security settings or enter an administrator password to continue a download\u003C\u002Fli\u003E\n\u003C\u002Ful\u003E\n\u003Cp\u003EFor families and small businesses, explain the rule in plain language: \u003Cstrong\u003Edon’t paste website text into Terminal unless you understand exactly what it does and you trust the source.\u003C\u002Fstrong\u003E That one habit breaks the ClickFix chain before it starts.\u003C\u002Fp\u003E\u003Ch2 id=\"what-to-do-if-you-ran-the-command\"\u003EWhat to do if you ran the command\u003C\u002Fh2\u003E\u003Cp\u003EDisconnect from Wi-Fi or Ethernet first. Then, from a known-clean device, change the passwords for your email, Apple Account, password manager, financial accounts and any account that was signed in on the Mac. Revoke any active sessions for online services.\u003C\u002Fp\u003E\u003Ch2 id=\"faq\"\u003EFAQ\u003C\u002Fh2\u003E\u003Ch3 id=\"can-a-fake-captcha-infect-a-mac\"\u003ECan a fake CAPTCHA infect a Mac?\u003C\u002Fh3\u003E\u003Cp\u003E\u003Cstrong\u003EAnswer:\u003C\u002Fstrong\u003E A CAPTCHA page alone does not infect the Mac. The danger starts when the page tricks you into copying and running a malicious Terminal command, which can download malware.\u003C\u002Fp\u003E\u003Ch3 id=\"does-macos-protect-me-from-clickfix-attacks\"\u003EDoes macOS protect me from ClickFix attacks?\u003C\u002Fh3\u003E\u003Cp\u003E\u003Cstrong\u003EAnswer:\u003C\u002Fstrong\u003E macOS provides important protection, but ClickFix tries to bypass normal app-download checks by persuading you to execute a command yourself. Don’t run commands that a website gives you unless you fully understand and trust them.\u003C\u002Fp\u003E\u003Ch3 id=\"what-is-the-biggest-red-flag-in-a-clickfix-scam\"\u003EWhat is the biggest red flag in a ClickFix scam?\u003C\u002Fh3\u003E\u003Cp\u003E\u003Cstrong\u003EAnswer:\u003C\u002Fstrong\u003E Any “verification,” update or download page that tells you to open Terminal and paste text is a major red flag. Legitimate CAPTCHAs do not require that step.\u003C\u002Fp\u003E\u003Ch3 id=\"what-should-i-do-if-i-pasted-a-command-into-terminal\"\u003EWhat should I do if I pasted a command into Terminal?\u003C\u002Fh3\u003E\u003Cp\u003E\u003Cstrong\u003EAnswer:\u003C\u002Fstrong\u003E Disconnect from the internet, change important passwords from another clean device, revoke active sessions and have the Mac scanned or reviewed. If cryptocurrency wallets were present, treat wallet credentials as exposed.\u003C\u002Fp\u003E",tags:[{id:"66f50fb228045a04f10ce990",name:bH,slug:bI,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:e,name:f,slug:d,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:h,name:g,slug:g,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a}],authors:[{id:p,name:q,slug:r,profile_image:s,cover_image:t,bio:u,website:a,location:a,facebook:a,twitter:a,meta_title:a,meta_description:a}],excerpt:bG,reading_time:X,url:"\u002Fblog\u002Fhotforsecurity\u002Fmac-not-safe-clickfix-attacks\u002F"},{id:"6a6c9e1e8beeea96580285a9",title:"BBB warns about ‘free’ gas and grocery card postcard scams",slug:"bbb-warns-about-free-gas-and-grocery-card-postcard-scams",feature_image:"https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F07\u002Ffree-gas-and-groceries.png",featured:c,published_at:"2026-07-31T16:14:04.000+03:00",custom_excerpt:a,html:"\u003Cp\u003EThe Better Business Bureau (BBB) is warning consumers about a growing scam involving official-looking postcards that claim recipients qualify for valuable gas or grocery vouchers. Instead of free gift cards, victims often end up paying fees, facing unauthorized charges, or handing over personal information that can later be used in fraud.\u003C\u002Fp\u003E\u003Ch2 id=\"key-takeaways\"\u003EKey takeaways\u003C\u002Fh2\u003E\u003Cul\u003E\u003Cli\u003EThe Better Business Bureau (BBB) is warning consumers about scam postcards promising free gas or grocery gift cards.\u003C\u002Fli\u003E\u003Cli\u003EVictims are typically asked to pay a small \"processing\" or \"activation\" fee to claim the reward.\u003C\u002Fli\u003E\u003Cli\u003EIn many reported cases, the promised gift cards never arrive, victims face additional unauthorized charges, or are enrolled in recurring subscriptions without realizing it.\u003C\u002Fli\u003E\u003Cli\u003EThese scams often target people looking to save money amid rising grocery and fuel costs.\u003C\u002Fli\u003E\u003Cli\u003EPhysical mail may feel more legitimate than email or text messages, but it can be just as deceptive.\u003C\u002Fli\u003E\u003C\u002Ful\u003E\u003Ch2 id=\"how-the-scam-works\"\u003EHow the scam works\u003C\u002Fh2\u003E\u003Cp\u003EAccording to the BBB, consumers have reported receiving postcards stating the recipient is eligible for gas and grocery cards.\u003C\u002Fp\u003E\u003Cp\u003E“In addition to groceries or gas, these types of mailings may claim to offer&nbsp;rebates or shopping rewards,” the BBB \u003Ca href=\"https:\u002F\u002Fwww.bbb.org\u002Farticle\u002Fnews-releases\u002F34935-bbb-scam-alert-dont-be-fooled-by-free-gas-and-grocery-card-postcards?backurl=\u002Fus\u002Fnews\"\u003Esaid\u003C\u002Fa\u003E.\u003C\u002Fp\u003E\u003Cp\u003EThe mailers use urgent phrases such as \"Final Notice,\" \"Limited Time Offer,\" or \"Expires Soon,\" and often include barcodes, tracking numbers, expiration dates, and customer service phone numbers.\u003C\u002Fp\u003E\u003Cp\u003ERecipients are instructed to call a number or visit a website to claim the reward.\u003C\u002Fp\u003E\u003Cp\u003EInstead of receiving free gift cards, callers are asked to pay a small processing, activation, shipping, or handling fee—often around \u003Cstrong\u003E$5\u003C\u002Fstrong\u003E. While the amount may seem insignificant, victims may later discover additional unauthorized charges or recurring subscription fees, or simply fail to receive the promised reward.\u003C\u002Fp\u003E\u003Cp\u003E\u003Cem\u003E“Sister received a postcard from AAPP, Presorted 1st class mail from Tampa&nbsp;phone #. Postcard&nbsp;stated&nbsp;she was eligible for gas &amp; grocery cards.&nbsp;She agreed to the $5 processing fee, then immediately after they took another $46.&nbsp;Total dollars lost: $51,” one consumer reported via the BBB’s Scam Tracker.\u003C\u002Fem\u003E&nbsp;\u003C\u002Fp\u003E\u003Cp\u003EMore than phishing emails or suspicious text messages, physical mail carries an air of legitimacy. Many people assume that if something arrives through the postal service, it has already been vetted.\u003C\u002Fp\u003E\u003Cp\u003EScammers also know that many families are looking for ways to reduce everyday expenses. With grocery and fuel prices remaining high, offers for free gift cards can seem especially convincing.\u003C\u002Fp\u003E\u003Cp\u003EAnother reason these scams succeed is the low upfront cost. A $5 fee doesn't sound like much, making victims less likely to question the offer before providing payment details.\u003C\u002Fp\u003E\u003Cp\u003EYou may also want to read:\u003C\u002Fp\u003E\u003Cul\u003E\u003Cli\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fbrushing-scams-what-to-do-if-you-receive-free-goods-in-the-mail-without-ordering-them \" rel=\"noreferrer\"\u003EBrushing scams: What to do if you receive ‘free’ goods in the mail without ordering them\u003C\u002Fa\u003E\u003C\u002Fli\u003E\u003Cli\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-au\u002Fblog\u002Fhotforsecurity\u002Fbrushing-scams-with-a-twist-what-to-do-when-an-unexpected-package-asks-you-to-scan-a-qr-code\" rel=\"noreferrer\"\u003EBrushing Scams With a Twist: What to Do When an Unexpected Package Asks You to Scan a QR Code\u003C\u002Fa\u003E\u003C\u002Fli\u003E\u003C\u002Ful\u003E\u003Ch2 id=\"the-bigger-risk-its-not-just-about-losing-5\"\u003EThe bigger risk: It's not just about losing $5\u003C\u002Fh2\u003E\u003Cp\u003EThe small processing fee is often only the beginning.\u003C\u002Fp\u003E\u003Cp\u003EBy responding to the offer, consumers may also provide:\u003C\u002Fp\u003E\u003Cul\u003E\u003Cli\u003Etheir name and address\u003C\u002Fli\u003E\u003Cli\u003Ephone number\u003C\u002Fli\u003E\u003Cli\u003Eemail address\u003C\u002Fli\u003E\u003Cli\u003Epayment card information\u003C\u002Fli\u003E\u003Cli\u003Eother personal details\u003C\u002Fli\u003E\u003C\u002Ful\u003E\u003Cp\u003EThis information can later be used in phishing attacks or identity fraud, or sold to other scammers who know the victim has responded to fraudulent offers before.\u003C\u002Fp\u003E\u003Ch2 id=\"how-to-spot-fake-reward-offers\"\u003EHow to spot fake reward offers\u003C\u002Fh2\u003E\u003Cp\u003EBe suspicious if an offer:\u003C\u002Fp\u003E\u003Cul\u003E\u003Cli\u003ERequires you to pay before receiving a prize or reward\u003C\u002Fli\u003E\u003Cli\u003ECreates urgency with phrases like \"Final Notice\" or \"Limited Time\"\u003C\u002Fli\u003E\u003Cli\u003EPromises unusually valuable gift cards for little or no effort\u003C\u002Fli\u003E\u003Cli\u003EProvides only a phone number instead of directing you to a well-known retailer\u003C\u002Fli\u003E\u003Cli\u003EAsks for payment or personal information before verifying your eligibility\u003C\u002Fli\u003E\u003C\u002Ful\u003E\u003Cp\u003ERemember: legitimate prizes and gift cards don't require you to pay processing or activation fees upfront.\u003C\u002Fp\u003E\u003Ch2 id=\"what-to-do-if-you-receive-one\"\u003EWhat to do if you receive one\u003C\u002Fh2\u003E\u003Cp\u003EIf you receive one of these postcards:\u003C\u002Fp\u003E\u003Cul\u003E\u003Cli\u003EDon't call the number immediately.\u003C\u002Fli\u003E\u003Cli\u003EResearch the company independently instead of relying on the information printed on the mailer.\u003C\u002Fli\u003E\u003Cli\u003ENever provide payment information just to claim a reward.\u003C\u002Fli\u003E\u003Cli\u003EIf you've already paid, monitor your bank or credit card statements for unauthorized charges and contact your financial institution if you notice suspicious activity.\u003C\u002Fli\u003E\u003Cli\u003EReport the scam to the BBB Scam Tracker and your local consumer protection authorities.\u003C\u002Fli\u003E\u003C\u002Ful\u003E\u003Ch2 id=\"stay-protected-from-scams\"\u003EStay protected from scams\u003C\u002Fh2\u003E\u003Cp\u003EWhile this particular scam arrives in the mailbox, fake reward offers are just as common via email, text messages, social media ads, messaging apps, and fake websites. Regardless of the delivery method, the goal is the same: persuade you to share personal information or payment details before you realize the offer isn't real.\u003C\u002Fp\u003E\u003Cp\u003EThat's why it's important to combine healthy skepticism with layered security. Before responding to an unexpected offer, verify it through the company's official website or customer service channels, and never pay a fee to claim a prize or gift card.\u003C\u002Fp\u003E\u003Cp\u003EBitdefender offers several tools that can help you stay one step ahead of scammers:\u003C\u002Fp\u003E\u003Cul\u003E\u003Cli\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fscamio\"\u003E\u003Cstrong\u003EScamio\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E lets you check suspicious emails, text messages, social media posts, QR codes, links, and screenshots to help determine whether they are likely fraudulent.\u003C\u002Fli\u003E\u003Cli\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Flink-checker\"\u003E\u003Cstrong\u003ELink Checker\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E lets you scan suspicious URLs before opening them, helping you avoid phishing pages and malicious websites.\u003C\u002Fli\u003E\u003Cli\u003E\u003Cstrong\u003EScam Protection\u003C\u002Fstrong\u003E, included in Bitdefender \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fpremium-security\"\u003Eall-in-one security plans\u003C\u002Fa\u003E, helps detect and block scam attempts across websites, emails, SMS messages, phone calls, messaging apps, and remote access scams before they can do damage.\u003C\u002Fli\u003E\u003Cli\u003E\u003Cstrong\u003EScam Radar\u003C\u002Fstrong\u003E uses AI to analyze the context behind what you're seeing online, identifying emerging scam patterns and providing real-time risk assessments. Rather than simply checking whether a link is malicious, it helps you understand \u003Cem\u003Ewhy\u003C\u002Fem\u003E an offer or message appears suspicious, making it easier to recognize new and evolving scams.\u003C\u002Fli\u003E\u003C\u002Ful\u003E\u003Cp\u003EWhether a scam arrives in your mailbox or your inbox, taking a moment to verify an offer and using tools designed to spot fraud can help you avoid becoming the next victim.\u003C\u002Fp\u003E\u003Ch2 id=\"faqs\"\u003EFAQs\u003C\u002Fh2\u003E\u003Ch3 id=\"are-free-gas-and-grocery-gift-card-postcards-legitimate\"\u003EAre free gas and grocery gift card postcards legitimate?\u003C\u002Fh3\u003E\u003Cp\u003EUsually not. If you're asked to pay a fee before receiving a reward, it's a strong indication of a scam. Legitimate prizes don't require upfront payments.\u003C\u002Fp\u003E\u003Ch3 id=\"why-do-scammers-ask-for-only-a-small-fee\"\u003EWhy do scammers ask for only a small fee?\u003C\u002Fh3\u003E\u003Cp\u003EA small fee makes the offer seem less risky and increases the chances that victims will provide payment details. Some scammers then make additional unauthorized charges or enroll victims in recurring subscriptions.\u003C\u002Fp\u003E\u003Ch3 id=\"can-physical-mail-be-used-for-scams\"\u003ECan physical mail be used for scams?\u003C\u002Fh3\u003E\u003Cp\u003EYes. While many scams arrive by email or text, criminals still use physical mail because official-looking letters and postcards often appear more trustworthy.\u003C\u002Fp\u003E\u003Ch3 id=\"can-scammers-steal-my-identity-from-these-offers\"\u003ECan scammers steal my identity from these offers?\u003C\u002Fh3\u003E\u003Cp\u003EPotentially. If you provide personal or financial information, scammers may use it for identity fraud, phishing campaigns, or sell it to other criminals.\u003C\u002Fp\u003E",tags:[{id:m,name:n,slug:o,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:i,name:j,slug:k,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:e,name:f,slug:d,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a},{id:h,name:g,slug:g,description:a,feature_image:a,visibility:b,og_image:a,og_title:a,og_description:a,twitter_image:a,twitter_title:a,twitter_description:a,meta_title:a,meta_description:a,codeinjection_head:a,codeinjection_foot:a,canonical_url:a,accent_color:a}],authors:[{id:F,name:G,slug:H,profile_image:I,cover_image:a,bio:J,website:a,location:a,facebook:a,twitter:a,meta_title:a,meta_description:a}],excerpt:"The Better Business Bureau (BBB) is warning consumers about a growing scam involving official-looking postcards that claim recipients qualify for valuable gas or grocery vouchers. Instead of free gift cards, victims often end up paying fees, facing unauthorized charges, or handing over personal information that can later be used in fraud.\n\n\nKey takeaways\n\n * The Better Business Bureau (BBB) is warning consumers about scam postcards promising free gas or grocery gift cards.\n * Victims are typical",reading_time:W,url:"\u002Fblog\u002Fhotforsecurity\u002Fbbb-warns-about-free-gas-and-grocery-card-postcard-scams\u002F"}],page:1,limit:999,isLoading:c,filterString:l,blogname:bx,menuItems:{hotforsecurity:{en:[{tag:l,name:w},{tag:bI,name:bH},{tag:Z,name:y},{tag:as,name:M},{tag:"tips-and-tricks",name:"Tips and Tricks"},{tag:ao,name:an}],es:[{tag:l,name:w},{tag:"consejos-de-seguridad",name:"Consejos de Seguridad"},{tag:"noticias-de-la-industria",name:"Noticias de la industria"},{tag:"microempresas",name:"Microempresas"},{tag:"actualizaciones-de-productos",name:"Actualizaciones de productos"},{tag:"hogar-inteligente",name:"Hogar Inteligente"},{tag:ao,name:an}],ro:[{tag:l,name:w},{tag:Z,name:y},{tag:as,name:M}],fr:[{tag:l,name:w},{tag:Z,name:y},{tag:"conseils-astuces",name:"Conseils"},{tag:"maison-connectee",name:"Maison Connectée"},{tag:bJ,name:"ABC CYBERSÉCURITÉ"}],de:[{tag:l,name:w},{tag:"branchennachrichten",name:"Nachrichten"},{tag:Z,name:y},{tag:"tipps-und-tricks",name:"TIPPS"},{tag:as,name:M},{tag:bJ,name:"ABC DER CYBERSICHERHEIT"}]},labs:{en:[{tag:l,name:w},{tag:"antimalware-research",name:"Anti-Malware Research"},{tag:"free-tools",name:"Free Tools"},{tag:"whitepapers",name:"Whitepapers"}]},businessinsights:{en:[{tag:l,name:w},{tag:"enterprise-security",name:"Enterprise Security"},{tag:"cloud-security",name:"Cloud Security"},{tag:"privacy-and-data-protection",name:"Privacy and Data Protection"}]}}}},error:a,state:{lang:d,primaryTag:bK,server:"http:\u002F\u002Flocalhost:3000\u002Fnuxt\u002Fapi",mainTag:bK,locale:"en-us"},serverRendered:N,routePath:"\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002F",config:{pageEnv:"prod",_app:{basePath:al,assetsPath:"\u002Fnuxt\u002F_nuxt\u002F",cdnURL:a}}}}(null,"public",false,"en","66f50fb228045a04f10ce986","EN","top","66f50fb228045a04f10ce992","66f50fb228045a04f10ce98a","Industry News","industry-news","all","66f50fb228045a04f10ce9b2","Scam","scam","66d5cbea28045a04f10b89df","Silviu STAHIE","sstahie","https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F03\u002FBD_Silviu_Stahie_Pic3-1.jpeg","https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F03\u002FBD_Silviu_Stahie_Pic3.jpeg","Silviu is a seasoned writer who followed the technology world for almost two decades, covering topics ranging from software to hardware and everything in between.","Digital Privacy","All","Even if it’s not immediately obvious, bank accounts hold something that can be just as useful as cash: a detailed record of your financial life. ","Product Updates","66d5cbea28045a04f10b89eb","Vlad CONSTANTINESCU","vlad","https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2021\u002F12\u002FVlad.jpg","Vlad's love for technology and writing created rich soil for his interest in cybersecurity to sprout into a full-on passion.\nBefore becoming a Security Analyst, he covered tech and security topics.",5,"66d5cbea28045a04f10b89c1","Alina BÎZGĂ","abizga","http:\u002F\u002F2.gravatar.com\u002Favatar\u002F8438d6e3076d0baf471aec1235424fcf?s=512&d=mm&r=g","Alina is a history buff passionate about cybersecurity and anything sci-fi, advocating Bitdefender technologies and solutions. She spends most of her time between her two feline friends and traveling.","66f50fb228045a04f10ce985","digital-privacy","Smart Home",true,"6a608f628beeea9658028065","Finance","finance","Valve warns Steam users not to accept gifts from people they don't know, but the practice remains common enough that the company specifically flags it as a potential source of fraud.",2,"66f50fb228045a04f10ce9b3","Data Breach","data-breach",4,3,"yearly","product-updates","6a88606c8beeea9658029244","Why an Empty Bank Account Is Valuable to Cybercriminals","empty-bank-account-valuable-cybercriminals","https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002Fmohamed_hassan-money-transfer-7185873_1920.png","2026-08-21T18:20:34.000+03:00","\u002Fblog\u002Fhotforsecurity\u002Fempty-bank-account-valuable-cybercriminals\u002F","66d5cbea28045a04f10b89d0","Filip TRUȚĂ","ftruta","http:\u002F\u002F0.gravatar.com\u002Favatar\u002F377aeee1f02a7ae7ac62f20f2f4ce504?s=512&d=mm&r=g","Filip has 17 years of experience in technology journalism. In recent years, he has focused on cybersecurity in his role as a Security Analyst at Bitdefender.","bitdefender","Consumer Insights","\u002F","hotforsecurity","VPN","vpn","66f50fb228045a04f10ce987","Family Safety","family","smart-home","Two victims can lose money to similar scams but face very different refund rules depending on who actually approved the payment. Understanding authorized vs unauthorized fraud helps you describe what happened accurately, dispute the transaction, and act quickly before recovery options narrow.","6a7da9f88beeea9658028bde","Police Warning: Your bank is not coming to your house for your card","bank-scam-fraudsters-come-to-your-home","https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002FPolice-Warning-Your-bank-is-not-coming-to-your-house-for-your-card-.png","2026-08-13T14:52:45.000+03:00","Scammers can be frighteningly creative. And while we tend to imagine scams happening behind a phone or laptop screen, they don't always stay there.\n\nPolice in Kent, Ohio, are warning the public about a banking scam that can start with a simple text message and end with a stranger showing up at your front door to collect your bank card.\n\n\nKey takeaways\n\n * Your bank will not send someone to your home to collect a compromised debit or credit card.\n * Caller ID isn't proof you're speaking with your","\u002Fblog\u002Fhotforsecurity\u002Fbank-scam-fraudsters-come-to-your-home\u002F","6a7b40a88beeea9658028aa3","Steam gift scams: Why you should never accept one from an unknown user","steam-gift-scams-why-you-should-never-accept-one-from-an-unknown-user","https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002FChatGPT-Image-Aug-11--2026--06_31_10-PM.png","2026-08-11T18:36:40.000+03:00","\u002Fblog\u002Fhotforsecurity\u002Fsteam-gift-scams-why-you-should-never-accept-one-from-an-unknown-user\u002F","6a88204f8beeea96580291e1","Russian-linked hackers turn Google and WhatsApp logins into phishing traps","russian-hackers-google-whatsapp-phishing","https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002Fdimitri-karastelev-ynJaWgrwSlM-unsplash--1-.jpg","2026-08-21T12:55:54.000+03:00","\u003Cp\u003E\u003Cem\u003EThree suspected Russian cyber-espionage clusters are abusing legitimate authentication features to compromise personal accounts of people in sensitive sectors across Europe and the US, Google says.\u003C\u002Fem\u003E\u003C\u002Fp\u003E\u003Ch2 id=\"key-takeaways\"\u003EKey takeaways\u003C\u002Fh2\u003E\u003Cul\u003E\u003Cli\u003EGoogle is tracking UNC6293, UNC7005 and UNC5976, which it assesses with high confidence to have a Russian nexus\u003C\u002Fli\u003E\u003Cli\u003EThe campaigns abuse legitimate Google OAuth, app-password and device-linking workflows rather than software vulnerabilities\u003C\u002Fli\u003E\u003Cli\u003EUNC7005 has also used WhatsApp device linking to attach attacker-controlled devices to victims’ accounts\u003C\u002Fli\u003E\u003Cli\u003ETargets include academics, diplomats, defense personnel, government-linked users and think-tank researchers\u003C\u002Fli\u003E\u003C\u002Ful\u003E\u003Ch2 id=\"legitimate-sign-in-pages-become-phishing-traps\"\u003ELegitimate sign-in pages become phishing traps\u003C\u002Fh2\u003E\u003Cp\u003EThe Google Threat Intelligence Group (GTIG) \u003Ca href=\"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Fdistinct-clusters-target-individuals-of-interest-to-russia\"\u003Esays\u003C\u002Fa\u003E victims may encounter genuine authentication pages during these attacks. UNC6293 has asked targets to complete legitimate logins and surrender verification codes or URLs, while UNC5976 built fake file-sharing pages that redirected users through authentic Google OAuth screens.\u003C\u002Fp\u003E\u003Cp\u003EAfter authentication, victims could be sent to attacker-controlled cloud projects designed to capture access tokens. Google says it disrupted at least 12 domains and related infrastructure created by UNC5976, which has since started shifting parts of its phishing infrastructure away from Google services.\u003C\u002Fp\u003E\u003Ch2 id=\"whatsapp-linking-gives-attackers-another-route-in\"\u003EWhatsApp linking gives attackers another route in\u003C\u002Fh2\u003E\u003Cp\u003EUNC7005, also tracked by Microsoft as Storm-2945, used fake invitations and secure-communication lures to target academics, diplomats and nonprofit personnel. In May and June, phishing pages impersonating WhatsApp asked victims to enter a phone number and approve a legitimate device-link request for an attacker-controlled device.\u003C\u002Fp\u003E\u003Cp\u003EOnce linked, the attacker could gain ongoing account access. Google also observed prompts for fake encrypted chats, file downloads and voice calls. One call flow used malicious JavaScript to record a target’s audio and video. In August, the same cluster used Google OAuth phishing against people connected to Europe’s defense industry.\u003C\u002Fp\u003E\u003Ch2 id=\"why-this-matters-beyond-high-profile-targets\"\u003EWhy this matters beyond high-profile targets\u003C\u002Fh2\u003E\u003Cp\u003EThese operations are highly selective, but the techniques matter to everyone because they rely on familiar, legitimate-looking security workflows. A real Google sign-in page, QR code or WhatsApp linking prompt is not proof that the request leading to it is trustworthy.\u003C\u002Fp\u003E\u003Cp\u003EUsers should verify unexpected invitations through a separate channel, never share app passwords or verification codes, review linked WhatsApp devices, and treat unverified OAuth consent screens as a warning sign. Google also recommends that high-risk users consider its Advanced Protection Program.\u003C\u002Fp\u003E\u003Ch2 id=\"stay-safer-from-phishing-and-account-takeover-lures\"\u003EStay safer from phishing and account-takeover lures\u003C\u002Fh2\u003E\u003Cp\u003EAttackers increasingly build scams around legitimate services, so the initial message or link deserves as much scrutiny as the login page itself. \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fscamio\"\u003E\u003Cstrong\u003EBitdefender Scamio\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E can analyze suspicious messages, links and QR codes before you interact with them, while \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fultimate-security\"\u003E\u003Cstrong\u003EBitdefender Ultimate Security\u003C\u002Fstrong\u003E\u003C\u002Fa\u003E adds anti-phishing, web, email and scam protection across supported devices.\u003C\u002Fp\u003E","Three suspected Russian cyber-espionage clusters are abusing legitimate authentication features to compromise personal accounts of people in sensitive sectors across Europe and the US, Google says.\n\n\nKey takeaways\n\n * Google is tracking UNC6293, UNC7005 and UNC5976, which it assesses with high confidence to have a Russian nexus\n * The campaigns abuse legitimate Google OAuth, app-password and device-linking workflows rather than software vulnerabilities\n * UNC7005 has also used WhatsApp device li","\u002Fblog\u002Fhotforsecurity\u002Frussian-hackers-google-whatsapp-phishing\u002F","6a86ed2b8beeea96580291ab","Sakura Internet hack may affect 1.36 million accounts","sakura-internet-breach-1-36-million-accounts","https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2026\u002F08\u002Fdavid-brooke-martin-lFTtQqVfx6g-unsplash.jpg","2026-08-20T15:05:06.000+03:00","\u003Cp\u003E\u003Cem\u003EJapanese cloud and data center provider Sakura Internet is investigating unauthorized access to a sales management system that may have exposed personal and contract information linked to as many as 1.36 million customer accounts. The company says the final impact is under investigation and large-scale data exfiltration hasn’t been confirmed.\u003C\u002Fem\u003E\u003C\u002Fp\u003E\u003Ch2 id=\"key-takeaways\"\u003EKey takeaways\u003C\u002Fh2\u003E\u003Cul\u003E\u003Cli\u003EUp to 1,360,563 Sakura Internet accounts potentially fall within the scope of the incident\u003C\u002Fli\u003E\u003Cli\u003EExposed information may include contact, profile, contract and billing details\u003C\u002Fli\u003E\u003Cli\u003EHashed password data associated with 30 accounts may also have been affected\u003C\u002Fli\u003E\u003Cli\u003ESakura says customer credit card information was not stored in the compromised system\u003C\u002Fli\u003E\u003C\u002Ful\u003E\u003Ch2 id=\"intrusion-reaches-sakura-internets-sales-system\"\u003EIntrusion reaches Sakura Internet's sales system\u003C\u002Fh2\u003E\u003Cp\u003ESakura Internet \u003Ca href=\"http:\u002F\u002Fwww.sakura.ad.jp\u002Fcorporate\u002Finformation\u002Fnewsreleases\u002F2026\u002F08\u002F19\u002F1968225633\u002F\"\u003Euncovered\u003C\u002Fa\u003E the broader compromise while investigating unauthorized access to its Sakura Rental Server service. That earlier incident affected 583 accounts, allowed attackers to reach customer environments and involved malware on company systems.\u003C\u002Fp\u003E\u003Cp\u003EInvestigators subsequently found evidence of possible unauthorized access to a separate sales management system holding membership and service-contract information. The activity occurred before Aug. 9, when the rental-server intrusion was detected, although Sakura has yet to determine whether the two events are directly connected.\u003C\u002Fp\u003E\u003Ch2 id=\"personal-and-contract-data-may-have-been-exposed\"\u003EPersonal and contract data may have been exposed\u003C\u002Fh2\u003E\u003Cp\u003EPotentially affected records include member IDs, names, company and department information, addresses, phone numbers, email addresses, birth dates, gender, subscribed services, contract periods and billing amounts. Importantly, 1.36 million represents the maximum number of accounts possible within the scope, not a confirmed tally of stolen customer records.\u003C\u002Fp\u003E\u003Cp\u003ESakura also identified possible exposure of hashed passwords belonging to 30 accounts. The company says it has found no evidence that data was removed from the affected system, while credit card information was not stored there.\u003C\u002Fp\u003E\u003Ch2 id=\"customers-should-change-passwords-and-watch-for-phishing\"\u003ECustomers should change passwords and watch for phishing\u003C\u002Fh2\u003E\u003Cp\u003ESakura has revoked the credentials abused during the intrusion, removed malware, strengthened monitoring and brought in external specialists for forensic analysis. The company says it will contact customers who need to take specific action as investigators establish the final scope.\u003C\u002Fp\u003E\u003Cp\u003ECustomers can take precautions now by changing Sakura-related passwords, particularly FTP and email credentials, and replacing reused passwords on other services. Because leaked identity and contract information can make fraudulent messages more convincing, unexpected emails, attachments and links claiming to concern the breach should receive extra scrutiny.\u003C\u002Fp\u003E\u003Ch2 id=\"stay-ahead-of-breach-related-risks\"\u003EStay ahead of breach-related risks\u003C\u002Fh2\u003E\u003Cp\u003E\u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fdigital-identity-protection\"\u003EBitdefender Digital Identity Protection\u003C\u002Fa\u003E can monitor personal information for breach exposure and alert users when compromised data surfaces online or on the dark web. \u003C\u002Fp\u003E\u003Cp\u003ESuspicious follow-up emails, texts, links or QR codes can also be checked with the free \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fscamio\"\u003EBitdefender Scamio\u003C\u002Fa\u003E scam-detection service before users interact with them.\u003C\u002Fp\u003E","Japanese cloud and data center provider Sakura Internet is investigating unauthorized access to a sales management system that may have exposed personal and contract information linked to as many as 1.36 million customer accounts. The company says the final impact is under investigation and large-scale data exfiltration hasn’t been confirmed.\n\n\nKey takeaways\n\n * Up to 1,360,563 Sakura Internet accounts potentially fall within the scope of the incident\n * Exposed information may include contact, ","\u002Fblog\u002Fhotforsecurity\u002Fsakura-internet-breach-1-36-million-accounts\u002F","66f50fb228045a04f10ce989","How to","how-to","News, views and insights from the Bitdefender experts","https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2021\u002F05\u002Fh4s_2x.png","#15171A","https:\u002F\u002Fstatic.ghost.org\u002Fv3.0.0\u002Fimages\u002Fpublication-cover.png","@bitdefender","Europe\u002FAthens","Home","Cybersecurity News","\u002Ftag\u002Fpeople-of-bitdefender\u002Findustry-news\u002F","\u002Ftag\u002Fdigital-privacy\u002F","\u002Ftag\u002Fsmart-home\u002F","How To","\u002Ftag\u002Fhow-to\u002F","\u002Ftag\u002Fproduct-updates\u002F","noreply","icon-and-text","Subscribe","free","monthly","off","hotforsecurity@bitdefender.com","noreply@blogapp.bitdefender.com","disabled","https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002F","5.101",{},"fr","\u003Cp\u003EEven if it’s not immediately obvious, bank accounts hold something that can be just as useful as cash: a detailed record of your financial life. Transactions can reveal where you work, what services you use, who sends you money, when you pay bills and which other accounts may be connected to your name.\u003C\u002Fp\u003E\u003Cp\u003EThat information can help enable identity theft, more convincing scams and fraud that unfolds over time.\u003C\u002Fp\u003E\u003Cp\u003EA criminal breaking into a bank account with no money in it doesn’t make the breach harmless.\u003C\u002Fp\u003E\u003Ch2 id=\"key-takeaways\"\u003EKey takeaways\u003C\u002Fh2\u003E\u003Cul\u003E\n\u003Cli\u003EA low balance does not make a compromised bank account safe\u003C\u002Fli\u003E\n\u003Cli\u003ETransaction histories can expose personal details criminals can use in follow-up scams\u003C\u002Fli\u003E\n\u003Cli\u003EAttackers may wait for incoming payments, exploit connected services or try reused passwords elsewhere\u003C\u002Fli\u003E\n\u003Cli\u003EA compromised account can also be used to receive and move stolen money\u003C\u002Fli\u003E\n\u003Cli\u003EReport suspicious access or transactions to your bank immediately\u003C\u002Fli\u003E\n\u003C\u002Ful\u003E\n\u003Ch2 id=\"an-empty-account-is-not-an-empty-target\"\u003EAn empty account is not an empty target\u003C\u002Fh2\u003E\u003Cp\u003EThe obvious risk of a bank account takeover is theft. A criminal can transfer money, make purchases or attempt withdrawals. But the account balance is not the only valuable aspect.\u003C\u002Fp\u003E\u003Cp\u003ESomeone with access to an account can see regular salary payments, tax refunds, benefits, insurance payments, reimbursements or transfers from relatives. They may wait for money to arrive.\u003C\u002Fp\u003E\u003Cp\u003EThey will also look for services connected to the account, including payment apps, debit cards, overdraft facilities, savings accounts or automatic bill payments. What is available depends on the bank and the account, but even limited access can give criminals useful information or options.\u003C\u002Fp\u003E\u003Cp\u003EThe Consumer Financial Protection Bureau advises people to monitor accounts for unfamiliar activity, including small charges or debits. These may be \u003Ca href=\"https:\u002F\u002Fwww.consumerfinance.gov\u002Fconsumer-tools\u002Fbank-accounts\u002Fwatch-accounts-closely-when-card-data-is-hacked\u002F\"\u003Eattempts to test\u003C\u002Fa\u003E whether stolen details work before a larger fraud attempt.\u003C\u002Fp\u003E\u003Ch2 id=\"your-transaction-history-can-become-a-fraud-playbook\"\u003EYour transaction history can become a fraud playbook\u003C\u002Fh2\u003E\u003Cp\u003EA bank statement is often a surprisingly detailed profile of a person’s life. It reveals employers, utility providers, insurers, subscriptions, mortgage or rent payments, medical providers, travel plans and shopping habits.\u003C\u002Fp\u003E\u003Cp\u003EThat information can help criminals build a more believable lie. Instead of sending a generic phishing message, they may impersonate a bank, delivery company, employer or family member using details that make the message seem credible.\u003C\u002Fp\u003E\u003Cp\u003EFor example, an attacker who sees a regular payment from an insurer might send a fake “policy update” email. Someone who notices regular transfers between family members may attempt an impersonation scam that appears to come from a relative in need.\u003C\u002Fp\u003E\u003Ch2 id=\"compromised-banking-details-can-lead-to-identity-theft\"\u003ECompromised banking details can lead to identity theft\u003C\u002Fh2\u003E\u003Cp\u003EFinancial information is valuable because it can be combined with data stolen from other data breaches. A name, address, account number, payment history and contact details may help criminals impersonate a victim, attempt to open accounts or answer security questions.\u003C\u002Fp\u003E\u003Cp\u003EIdentity theft does not always become visible immediately. Warning signs can include bills for things you did not buy, debt collection calls, unfamiliar accounts on a credit report or loan applications being denied unexpectedly. \u003Ca href=\"https:\u002F\u002Fwww.usa.gov\u002Fidentity-theft\"\u003EUSAGov’s identity theft guidance\u003C\u002Fa\u003E recommends reporting suspected identity theft to the affected financial institutions and taking action to protect your credit where appropriate.\u003C\u002Fp\u003E\u003Ch2 id=\"criminals-may-try-the-same-password-elsewhere\"\u003ECriminals may try the same password elsewhere\u003C\u002Fh2\u003E\u003Cp\u003EA bank account takeover can also confirm that a username and password combination works.\u003C\u002Fp\u003E\u003Cp\u003EIf the victim reused that password, as many people do, criminals may try it on email, shopping, social media, payment and cryptocurrency accounts. Access to email is especially valuable because it can allow attackers to reset passwords for other services.\u003C\u002Fp\u003E\u003Cp\u003EThis is why changing only the bank password may not be enough. If you used that password anywhere else, change it there too. The FTC specifically \u003Ca href=\"https:\u002F\u002Fconsumer.ftc.gov\u002Farticles\u002Fwhat-do-if-you-were-scammed\"\u003Erecommends\u003C\u002Fa\u003E creating a new, strong password and changing it on any other accounts where it was reused.\u003C\u002Fp\u003E\u003Ch2 id=\"your-account-could-be-used-to-move-stolen-money\"\u003EYour account could be used to move stolen money\u003C\u002Fh2\u003E\u003Cp\u003ECriminals sometimes use other people’s accounts to receive and transfer stolen funds. This is known as money mule activity.\u003C\u002Fp\u003E\u003Cp\u003EA victim may not realize their account has been used this way until they see unexplained transfers, hear from their bank or face questions about suspicious activity.\u003C\u002Fp\u003E\u003Cp\u003EThe FBI’s Internet Crime Complaint Center \u003Ca href=\"https:\u002F\u002Fwww.ic3.gov\u002FPSA\u002F2021\u002FPSA211203\"\u003Ewarns\u003C\u002Fa\u003E that money mule schemes can expose people to identity theft, financial losses and serious legal consequences, even when they were not fully aware of the wider scheme.\u003C\u002Fp\u003E\u003Cp\u003EA compromised account is therefore not just a victim’s problem. It can become part of the criminal infrastructure used to target other people.\u003C\u002Fp\u003E\u003Ch2 id=\"what-to-do-if-you-think-someone-accessed-your-bank-account\"\u003EWhat to do if you think someone accessed your bank account\u003C\u002Fh2\u003E\u003Cul\u003E\n\u003Cli\u003EAct quickly, even if no money appears to be missing\u003C\u002Fli\u003E\n\u003Cli\u003EContact your bank using the number on its official website, app or the back of your card\u003C\u002Fli\u003E\n\u003Cli\u003EReport unfamiliar transactions, new payees, changed contact details or login alerts\u003C\u002Fli\u003E\n\u003Cli\u003EChange your online-banking password and enable multi-factor authentication if your bank has this option\u003C\u002Fli\u003E\n\u003Cli\u003EChange any reused password on email, payment and shopping accounts\u003C\u002Fli\u003E\n\u003Cli\u003EReview connected cards, payment apps, direct debits and account alerts\u003C\u002Fli\u003E\n\u003Cli\u003ECheck your account statements over the following weeks for delayed or small fraudulent transactions\u003C\u002Fli\u003E\n\u003Cli\u003EIf personal information was exposed, follow your country’s identity-theft reporting and credit-monitoring guidance\u003C\u002Fli\u003E\n\u003C\u002Ful\u003E\n\u003Cp\u003ENever rely on a phone number or link sent in an unexpected text or email claiming to be from your bank. Find the bank’s official contact details independently.\u003C\u002Fp\u003E\u003Ch2 id=\"better-protection-starts-before-a-breach\"\u003EBetter protection starts before a breach\u003C\u002Fh2\u003E\u003Cp\u003EUse a unique password for every financial account and store it in a reputable password manager. Turn on multi-factor authentication, keep your phone and computer updated, and avoid using links in unexpected messages.\u003C\u002Fp\u003E\u003Cp\u003EA security solution can also help block malicious websites and phishing attempts before they reach a fake banking page. \u003Ca href=\"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fconsumer\u002Fultimate-security\"\u003EBitdefender Ultimate Security\u003C\u002Fa\u003E includes protection designed to help keep phishing, scams and identity-related threats from turning into a larger problem.\u003C\u002Fp\u003E\u003Ch2 id=\"faq\"\u003EFAQ\u003C\u002Fh2\u003E\u003Ch3 id=\"can-someone-steal-money-from-an-empty-bank-account\"\u003ECan someone steal money from an empty bank account?\u003C\u002Fh3\u003E\u003Cp\u003EPossibly, depending on the account’s features and linked payment methods. But even if there is no money to take immediately, criminals may wait for incoming payments or use the account data for other fraud.\u003C\u002Fp\u003E\u003Ch3 id=\"why-would-a-hacker-want-my-bank-statements\"\u003EWhy would a hacker want my bank statements?\u003C\u002Fh3\u003E\u003Cp\u003EStatements can reveal personal information, regular payments, employers, services you use and people you send money to. Criminals can use these details to make scams more convincing.\u003C\u002Fp\u003E\u003Ch3 id=\"can-a-hacked-bank-account-lead-to-identity-theft\"\u003ECan a hacked bank account lead to identity theft?\u003C\u002Fh3\u003E\u003Cp\u003EYes. Banking details may be combined with other stolen personal information to impersonate you, attempt account fraud or target you with more believable scams.\u003C\u002Fp\u003E\u003Ch3 id=\"what-is-a-money-mule-account\"\u003EWhat is a money mule account?\u003C\u002Fh3\u003E\u003Cp\u003EA money mule account is used to receive or transfer money connected to crime. Criminals may use compromised accounts, or trick people into moving money for them.\u003C\u002Fp\u003E\u003Ch3 id=\"what-should-i-do-if-my-bank-account-was-compromised-but-no-money-was-taken\"\u003EWhat should I do if my bank account was compromised but no money was taken?\u003C\u002Fh3\u003E\u003Cp\u003EContact your bank immediately, secure your login credentials, review recent activity and change any reused passwords. Do not wait for a financial loss to appear.\u003C\u002Fp\u003E","66d5cbea28045a04f10b89cc","Cristina POPOV","cpopov","https:\u002F\u002Fblogapp.bitdefender.com\u002Fhotforsecurity\u002Fcontent\u002Fimages\u002F2025\u002F12\u002F20251024_153349.jpg","Cristina Popov is a Denmark-based content creator and small business owner who has been writing for Bitdefender since 2017, making cybersecurity feel more human and less overwhelming. ","Australia has moved to strengthen Roblox child safety procedures after the country’s online safety regulator discovered gaps that could permit strangers to contact kids and view parts of their profiles without parental consent.","Mac users are encountering fake CAPTCHA checks, download prompts and troubleshooting pages that tell them to open Terminal and paste a command, just like on a Windows PC. That “verification,” however, can install an information stealer instead.","Threats","threats","abc",""));</script></body></html>