home.social

#smishing — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #smishing, aggregated by home.social.

  1. Supuestos “mensajes urgentes” disparan casos de fraudes digitales, alerta UNED

    La casa de enseñanza señala que las estafas a través de smishing se han convertido en “una de las principales amenazas digitales” en 2026.
    La entrada Supuestos “mensajes urgentes” disparan casos de fraudes digitales, alerta UNED aparece primero en Semanario Universidad.

    #Ciberfraudes #Estafas #Fraudes #País #RolandoRojas #Smishing #Tecnología #Uned #UniversidadEstatalADistancia #ÚltimaHora

    semanariouniversidad.com/pais/

  2. 📱Smishing Slows, Quishing Quickens 🎣

    Sick of smishing and those pesky parking/toll texts? Don’t get caught by crafty, counterfeit court QR codes — it’s a scan-and-scam! 💳 🚨

    North American cell phone users are being hit with yet another wave of smishing campaigns that now include quishing elements. Likely orchestrated by Chinese-speaking threat actors, this latest campaign builds on previous vehicular violations, evolving tactics while impersonating US courts. 🧑‍⚖️

    We’ve recently seen a flurry of SMS messages pushing parking violations — but with a twist: face justice in court… or scan and pay instead!

    Delivered as an official-looking image, the actor has begun integrating QR codes into these lures to help mask suspicious phishing URLs, baiting victims into entering personal information, credentials, and ultimately making payments.

    For some, this lure may sound better than facing justice for their perceived poor parking. Victims who don't comply are warned that failure to appear or pay could have serious repercussions - a scare tactic designed to push you toward a hasty decision and scanning the QR code! 🫣

    We uncovered thousands of these nefarious domains, through their use of Registered Domain Generation Algorithms (RDGAs) and local government impersonation, hosted across a diverse range of hosting providers to evade takedown.

    Recent examples:
    ⛔ ahfgx[.]icu
    ⛔ euoyq[.]icu
    ⛔ htpze[.]icu
    ⛔ mwlaj[.]icu

    Friendly reminder - courts don't usually communicate with you via text. That said, we suspect this actor will continue to evolve, expanding their global reach and diversifying lures while improving tradecraft used in smishing and quishing delivery. As for us, we'll take our chances on evading that bench warrant and running from the law. 🏃‍♂️‍➡️

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #smishing #quishing

  3. OpenAI has reported that a breach at Mixpanel exposed limited API-user metadata, including names, emails, coarse location, OS/browser details and IDs.

    This was not an OpenAI breach, and no chat content, credentials, API keys or payment data were exposed.

    The incident resulted from a smishing compromise of Mixpanel’s environment.

    OpenAI has fully removed Mixpanel and is conducting wider vendor audits.
    How concerned should teams be about metadata exposure at third-party analytics providers?

    Full Article: technadu.com/mixpanel-breach-e

    Follow us for more security coverage.
    #infosec #OpenAI #Mixpanel #databreach #smishing #securityincident #MFA #vendorsecurity #securitynews

  4. Next week, I'm speaking at #Saintcon about #phishing, #smishing, #quishing (all the -ishings) and propose a broad-based possible solution that could end this problem forever. Nothing big.

    If you're going to be there, you can find me in Track 2 at 2:30pm, or most of the rest of the time at the @SAINTCON @malwarevillage Community, where we will be hosting two of our contests (MARC I and BOMBE) and encouraging people to consider the field of malware analysis and threat research as a career.

    We also will have minibadges, both at #MalwareVillage and at the #Netcraft booth. If you're a #minibadge fan/collector, you aren't going to want to miss out on the Netcraft minibadge, which is awesome. Just drop by the booth to get a kit to build one. Tell them Spike sent ya.

    Until then, stay safe, and please tell everyone you know, don't click links to tax refunds or toll road fees you get on your phone.

    /END

    netcraft.com/blog/taxpayers-dr