Visualização normal

Antes de ontemCybersecurity News
  • ✇Security Affairs
  • AI Deepfakes Used to Impersonate OnlyFans Creators in New Scam Pierluigi Paganini
    Scammers use AI deepfakes to impersonate OnlyFans creators, trick fans into sending money, then disappear after payment. Criminals are building fake identities using AI-generated deepfakes of real OnlyFans creators, luring their followers with promises of live chats, and then disappearing after collecting payment. The scheme runs on social platforms that most people consider harmless, TikTok for discovery, Snapchat for the conversation, Cash App for the payment, and by the time the fan reali
     

AI Deepfakes Used to Impersonate OnlyFans Creators in New Scam

7 de Agosto de 2026, 03:55

Scammers use AI deepfakes to impersonate OnlyFans creators, trick fans into sending money, then disappear after payment.

Criminals are building fake identities using AI-generated deepfakes of real OnlyFans creators, luring their followers with promises of live chats, and then disappearing after collecting payment. The scheme runs on social platforms that most people consider harmless, TikTok for discovery, Snapchat for the conversation, Cash App for the payment, and by the time the fan realizes something is wrong, the money is already gone and the account is blocked.

“This is a form of catfishing, in which an attacker impersonates someone online and engages in romantic or sexual interactions for ulterior motives. In this case, the scammers create fake accounts on platforms like TikTok, using material lifted from a real creator’s photos and given a synthetic voice.” reads the report published by MalwareBytes. “They’ll use that to nudge viewers into a direct message conversation on services like Snapchat.”

The choice of Cash App as the payment method isn’t accidental. It’s a peer-to-peer platform built for informal transfers between friends, not commerce — and transfers clear instantly. Once sent, the money is effectively gone.

“This kind of fraud has two victims: the fans who lose money to scams, and the creators. The latter lose income that they might have collected from fans, and also run the risk of retribution from disgruntled followers who think they’ve been taken advantage of.” continues the report.

One creator, Jessieanna Campbell, told USA Today she constantly receives messages from angry fans accusing her of taking their money and blocking them, for transactions she never made. Another creator interviewed by USA Today had fans show up at her home after the confusion, and now sometimes doesn’t feel safe leaving the house.

“The problem is that domestic laws only apply to domestic platforms. The stolen material largely sits on overseas hosts, making it difficult to control.” concludes the report. “Even if laws could be universally enforced, it might not matter. In three experiments conducted this year, researchers at the University of Bristol found that most participants relied on deepfake content even after being told it was fake.”

Federally, the Take It Down Act criminalizes non-consensual explicit content including AI-generated material and requires rapid platform takedowns. The EU’s AI Act requires disclosure when AI is used for image generation. Neither law has stopped the content from circulating because enforcement stops at national borders and the hosting doesn’t.

Spotting a deepfake is still possible if you know what to look for. USA Today described a TikTok video impersonating creator Elaina St. James, made by animating a still photo with a cloned voice, that showed distorted teeth and frozen eyebrows. Those artifacts are common in AI-generated video, especially when the source material is limited. Malwarebytes has published a practical guide to spotting deepfakes of any kind.

A similar pattern has been documented in romance scam contexts. Malwarebytes previously reported on Amazon and Apple impersonation scams using the same redirect-and-collect mechanics, where the victim is moved off a trusted platform into a direct channel before the ask. The underlying manipulation — establish familiarity, trigger urgency, request payment through an irreversible channel, is consistent across scam types regardless of which face or brand is being faked.

If a “creator” reaches out to you through a third-party platform and steers the conversation toward a direct payment for exclusive content, treat it as a red flag. Verify through the creator’s official, verified accounts before doing anything else. And if someone who looks like a creator you follow is asking for Cash App payment before delivering anything, assume you’re about to be blocked.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, AI Deepfakes)

Kali365 Exploits Microsoft Device Login to Access US Corporate Data

Learn how Kali365 has been abusing Microsoft device login to gain OAuth tokens, targeting US firms, and how SOC teams can detect, hunt, and stop these phishing attacks.

Fake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor Infections

Fake helpdesk callers use Microsoft Teams and Quick Assist to access employee computers, where attackers install new GoGRPC backdoor in suspected ransomware operations

Hackers Compromise Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts

Compromised hotel Wi-Fi gateways redirect business travelers to fake Microsoft 365 login pages allowing attackers to steal credentials and authorization tokens.

Fake FBI Agents Use IC3 Complaint Scams to Target Fraud Victims

Fake FBI agents are using deepfake videos, spoofed IC3 websites and false recovery claims to steal money and personal information from people who were scammed before, the FBI warns.
  • ✇Graham Cluley
  • Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers Graham Cluley
    An app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks - no login, no passwords, no permissions needed. Meanwhile, Geoff - swimming in money and Lamborghinis, as all published authors are - has been on the receiving end of a slew of AI-generated scam pitches from fake book marketing experts. Rather than ignore them, he's been playing them at their own game... All this and more in this episode of the "Smashing Security" podcast with cyb
     

Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers

16 de Julho de 2026, 06:02
An app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks - no login, no passwords, no permissions needed. Meanwhile, Geoff - swimming in money and Lamborghinis, as all published authors are - has been on the receiving end of a slew of AI-generated scam pitches from fake book marketing experts. Rather than ignore them, he's been playing them at their own game... All this and more in this episode of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Geoff White.
  • ✇Firewall Daily – The Cyber Express
  • Dutch Police Arrest Key Suspect in €100M Global Crypto Investment Scam Samiksha Jain
    A major global crypto investment scam investigation has led to the arrest of an alleged key figure behind an international criminal organization accused of defrauding victims of more than €100 million every month. Dutch police announced multiple arrests across Europe following a long-running investigation into a fraud network that allegedly employed over 700 people operating from around 20 call centers worldwide. The main suspect, a 46-year-old dual Israeli and Polish national,
     

Dutch Police Arrest Key Suspect in €100M Global Crypto Investment Scam

global crypto investment scam

A major global crypto investment scam investigation has led to the arrest of an alleged key figure behind an international criminal organization accused of defrauding victims of more than €100 million every month. Dutch police announced multiple arrests across Europe following a long-running investigation into a fraud network that allegedly employed over 700 people operating from around 20 call centers worldwide.

The main suspect, a 46-year-old dual Israeli and Polish national, was arrested at an airport in Poland on May 26 at the request of Dutch authorities. Investigators believe he played an indispensable role in the organization, which allegedly carried out large-scale investment fraud targeting victims across multiple countries.

Global Crypto Investment Scam Network Operated Through Worldwide Call Centers

According to Dutch police, the organization functioned like a professional company with approximately 700 employees spread across nearly 20 offices globally. Individuals working as financial advisors scam operators allegedly contacted victims daily through online platforms and telephone calls while posing as legitimate investment professionals.

Authorities said the organization was structured with a central headquarters overseeing multiple teams, each assigned to target victims in specific countries. Employees reportedly worked under pseudonyms and used technical measures to hide their identities and locations.

[caption id="attachment_113134" align="aligncenter" width="600"]global crypto investment scam Excerpts from emails that victims sent to scammers[/caption]

As part of the investigation, Belgian police arrested five individuals believed to have worked as fraudulent financial advisors.

Multiple Arrests Made Across Europe

The investigation resulted in several coordinated arrests during May and July.

On July 7, authorities arrested two Dutch nationals aged 45 and 34, along with a 34-year-old Belgian, all residing in Cyprus. A 25-year-old suspect was also arrested in Belgium the same day. On July 10, police arrested a 44-year-old Dutch national in Athens.

The main suspect has since been extradited to the Netherlands, where an examining magistrate ordered 14 days of pre-trial detention. Dutch authorities indicated that additional arrests remain possible as the investigation continues.

How the Global Crypto Investment Scam Worked

Investigators said the online investment scam relied on building long-term trust with victims. Individuals posing as account managers or financial advisors maintained frequent contact through phone calls and online communication, sometimes over several months.

Victims were encouraged to begin with relatively small investments that appeared to generate immediate returns. Police said the investment platforms displayed convincing but fabricated profits, even though no actual investments were being made.

As confidence grew, victims were persuaded to transfer increasingly larger amounts, often in the form of cryptocurrency fraud payments. Instead of being invested, investigators said the funds were diverted directly to the criminal organization.

Authorities also warned that victims who stop investing may later be contacted by so-called recovery companies requesting upfront deposits to recover lost funds. Police believe these recovery operations may also be connected to the same fraud networks.

Hundreds of Complaints Linked to Investment Fraud

Dutch authorities have received approximately 550 reports connected to the organization, while Belgian police have recorded around 200 complaints. Investigators estimate the total number of victims worldwide could reach tens of thousands.

The financial losses reported by victims in the Netherlands alone amount to nearly €25 million, with many individuals losing well over €10,000.

Dutch police said officers proactively contacted some victims after discovering that many remained unaware they had fallen victim to cyber fraud.

Financial investigators are now examining whether assets linked to the suspects can be frozen or seized.

Digital Infrastructure Taken Offline

Investigators said the criminal organization remained active since at least 2021 and relied heavily on concealed digital infrastructure to evade law enforcement.

By tracing financial transactions, IP addresses, and other digital evidence, the Dutch police identified offices, suspects, and critical infrastructure supporting the operation. Authorities worked with commercial service providers to take key elements of the network offline.

The investigation also involved Europol, with intelligence shared across multiple countries to support ongoing criminal prosecutions.

Officials said the case demonstrates the scale and sophistication of modern investment fraud operations and highlighted continued international cooperation to dismantle cyber-enabled financial crime networks.

Fake Céline Dion Paris Tickets Sold on Facebook and Ticketmaster Clones

Group-IB says scammers are targeting Céline Dion fans through Facebook, duplicate digital tickets and fake websites impersonating Ticketmaster, AXS and the venue site.

Siggen Backdoor Hits Windows Developers Via Infected Visual Studio Projects

Dr.Web details Siggen Windows backdoor that uses Steam for C2, steals credentials and crypto data and infects Visual Studio projects to spread among developers.

Armored Likho Hits Government, Energy Sectors With BusySnake Stealer

Kaspersky details how the newly named Armored Likho APT uses BusySnake Stealer, AI-generated loaders, and phishing to target government and energy organizations.

UNK_MassTraction Exploits Roundcube Flaws Against US, Canadian Universities

China-linked UNK_MassTraction targets US and Canadian universities through Roundcube flaws, stealing sessions and opening access to research mail servers.

AI Can Forge Documents in Minutes – “Looks Right” Is No Longer Enough

Generative AI is making document fraud faster and harder to spot, pushing security teams to verify provenance, signatures and file integrity at intake securely.

Fake “Google Notes” Browser Extension Caught Swapping Crypto Wallet Addresses

McAfee says a Google Notes browser extension is replacing copied crypto payment details, putting wallet transfers at risk for Chrome, Brave, and Microsoft Edge users.

Fake Interpol Investigation Emails Push Ransomware at Small Businesses Globally

Fake Interpol investigation emails are targeting small businesses with Proton Drive links that deliver ransomware, encrypt files, and route victims to Tox chat.

Scammers race to cash in on Venezuelan earthquake disaster

30 de Junho de 2026, 18:04
Scammers wasted no time exploiting Venezuela's devastating earthquake, with researchers uncovering 212 newly-registered relief-themed domains in just five days. Read more in my article on the Hot for Security blog.

Hackers Use Fake FIFA World Cup 2026 T-Shirt Offers to Spread Voidrift Malware

A fake FIFA World Cup 2026 T-shirt giveaway scam is spreading Voidrift malware through personalized emails using company logos and trusted websites to bypass security filters.

212 New Venezuela Earthquake Domains Prompt Donation Scam Warnings

Researchers spotted 212 new domains registered after Venezuela's earthquake, warning donors of donation scam risks and urging them to verify relief sites first.

Bluekit Phishing Kit Uses Browser-in-the-Middle Attacks to Evade Detection

A new phishing-as-a-service (PHaaS) platform called Bluekit is letting cybercriminals steal user accounts using a tricky method. While…
❌
❌