Visualização normal

Antes de ontemCyber Threat Intel
  • ✇Malwarebytes
  • StreamRat Android malware spreads through Meta and TikTok ads
    A malicious advertising campaign promoting a fake free TV-streaming service reached roughly 570,000 Meta users. The researchers who discovered the campaign found that its streaming-themed ads were aimed at Spanish-speaking users, with most observed victims located in Spain. One Meta campaign ran from June 11 through July 3, 2026, and the same banners were also used to distribute the malware through TikTok. The available data shows the ads’ reach, not the number of downloads or infections,
     

StreamRat Android malware spreads through Meta and TikTok ads

3 de Setembro de 2026, 13:04

A malicious advertising campaign promoting a fake free TV-streaming service reached roughly 570,000 Meta users.

The researchers who discovered the campaign found that its streaming-themed ads were aimed at Spanish-speaking users, with most observed victims located in Spain. One Meta campaign ran from June 11 through July 3, 2026, and the same banners were also used to distribute the malware through TikTok.

The available data shows the ads’ reach, not the number of downloads or infections, but it demonstrates how quickly paid advertising can put a scam in front of a very large audience.

The ads promoted an Android banking Trojan and infostealer called StreamRat. It can monitor what’s on screen, capture information typed into apps, show convincing fake screens to steal usernames and passwords, and allow attackers to control the device remotely.

We often warn people not to click suspicious links in unexpected texts or emails. But malicious advertising is harder to recognize because it appears in the same feeds where people expect to find promotions, videos, and recommendations.

This campaign is a perfect demonstration of why “after-the-fact” ad checks are inadequate when it comes to protecting social media users. Attackers used familiar social media advertising and carefully tailored instructions to turn casual interest in free entertainment into a risky app installation.

How the attack worked

The ad led victims to a website posing as a streaming platform. The site checked whether a visitor was using Android. Non-Android visitors were simply prevented from downloading anything, while Android users were shown an app download option. This is a common way for scammers to concentrate their efforts on devices their malware can infect.

The site also identified whether someone had arrived through Instagram, TikTok, Facebook, or a regular browser. It then displayed instructions suited to that situation, including steps to allow the browser to install apps from “unknown sources.” In other words, this was not a generic malicious download page: It was designed to coach people through the security warnings that would normally make them stop and think.

StreamRat is an Android banking Trojan and infostealer. It can monitor what’s on screen, capture information typed into apps, show convincing fake screens to collect usernames and passwords, and enable attackers to operate the device remotely. The researchers also found options to cover the screen with a black page or fake Android update screen. These can distract victims while criminals interact with the phone behind the scenes.

How to stay safe

While this campaign targeted Spanish-speaking people, primarily in Spain, the following guidelines can help anyone avoid similar attacks.

  • Avoid installing Android apps from ads, direct-download websites, social media messages, sponsored search results, or links sent by strangers.
  • Download apps through Google Play whenever possible, and check the developer’s name, reviews, and app history rather than relying on an ad.
  • Before enabling installation from “unknown sources,” read our guide, Sideloading on Android: What it is, why it’s risky, and how to do it more safely.
  • Be very cautious when an app asks for Accessibility access, screen-sharing permission, Device Admin privileges, or permission to become the default launcher. Permissions that don’t line up with the intended use of the app are very suspicious.
  • Use an up-to-date, real-time anti-malware solution on all your devices.

What to do if you installed a suspicious app

If you installed a suspicious APK and granted it Accessibility access, disconnect the phone from Wi-Fi and mobile data. If possible, revoke the app’s Accessibility access and remove it. Use another device to change relevant passwords and contact your bank if you used banking apps on the infected phone. A factory reset may be necessary if you cannot confidently remove the infection.

Malwarebytes for Android detects the components of StreamRat as Android/Trojan.Agent.ACRAEEF8A36H36, Android/Trojan.Agent.ACR02DB0614H7, and Android/Trojan.Dropper.ACR9B7ECE83D1.


Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

  • ✇Malwarebytes
  • Why Facebook’s war on ad blockers could help scammers
    Reports that uBlock Origin is stepping back from the never-ending effort to filter Facebook ads are a reminder that ad blocking is no longer only an argument about inconvenience, publishers, and lost advertising revenue. It is also an issue of security. For years, ad blockers have occupied an uncomfortable place in the web economy. Publishers and platforms rely on advertising to fund their services, while users install blockers to escape intrusive banners, autoplay videos, tracking scripts
     

Why Facebook’s war on ad blockers could help scammers

17 de Agosto de 2026, 05:59

Reports that uBlock Origin is stepping back from the never-ending effort to filter Facebook ads are a reminder that ad blocking is no longer only an argument about inconvenience, publishers, and lost advertising revenue.

It is also an issue of security.

For years, ad blockers have occupied an uncomfortable place in the web economy. Publishers and platforms rely on advertising to fund their services, while users install blockers to escape intrusive banners, autoplay videos, tracking scripts, and feeds that increasingly feel designed around monetization rather than the people using them.

That debate is usually framed as a contest between a platform’s right to make money and a user’s desire for a cleaner browsing experience. But it leaves out an important detail: Ads are not always merely ads.

Malwarebytes General Manager Mark Beare stated:

“While it’s easy to look at ad blockers solely as a way of hurting monetization for these businesses, the other thing that ad blockers are doing is blocking malicious and scam ads.”

Sometimes ads are scams. At other times, they lead to malicious sites. And often, they impersonate trusted brands, promise fictional government payments, promote fake investment opportunities, or send victims into private messaging channels where the fraud continues.

In those cases, an ad blocker is not simply removing something annoying. It’s removing a route into a scam.

The advantage lies with the platforms

The reported decision by uBlock Origin’s team to stop continually chasing changes to Facebook ads highlights a structural advantage held by large platforms.

An ad blocker generally works by identifying requests, scripts, page elements, and patterns associated with advertising or tracking. A platform that controls the entire delivery stack can alter those patterns: It can change element names, move content into new components, serve ads through first-party infrastructure, or make sponsored content look more like ordinary posts.

This creates a familiar cat and mouse game. Filter-list maintainers identify a new method, the platform changes its implementation, users receive an update, and then the cycle starts all over. Again and again.

It’s the difference in resources that matters. A major platform can deploy changes on an enormous scale and has dedicated teams working on its products, advertising systems, and infrastructure. Open-source filter maintainers and independent blocking tools do not have the same staffing, telemetry, or ability to anticipate upcoming changes in how ads are delivered or how the platform will modify its systems.

That does not mean platforms should be expected to design their products around every third-party extension. Nor does it mean every attempt to detect or resist blocking is malicious. Advertising funds a great deal of the online content and services people use every day.

Not every blocked ad is harmless

A platform’s ability to make ads harder to distinguish from ordinary content should come with a corresponding responsibility: Make sure the ads being delivered deserve the trust implied by that integration.

Internal Meta documents reviewed by Reuters showed that the company projected about 10% of its 2024 revenue, or $16 billion, would come from ads for scams and banned goods. Meta said the estimate was “rough and overly-inclusive,” and that the true figure was lower.

That is a clear mismatch with Meta’s advertising rules, which explicitly prohibit deceptive and misleading ads, including schemes intended to scam people. Meta said its ad-review system examines ads before they go live and can re-review them later, but Meta also acknowledges that an ad may begin delivering before it has been reviewed against every policy.

That time gap is important. Scam campaigns are built to exploit speed and scale. Fraudsters can test new creatives, swap landing pages, impersonate a brand or public figure, and adapt when enforcement catches up. Meta disputed Reuters’ characterization of its anti-fraud efforts.

This is not an argument that every ad on Facebook, Instagram, or another large platform is dangerous. Most are not. The problem is that users cannot reliably tell, at a glance, which ad is a legitimate offer and which one is an attempt to steal money, credentials, or personal data.

Better moderation of ads is better for everyone

Rather than treating every blocker as a threat to revenue, a more productive response to ad blocking is to make the advertising experience safer, less invasive, and more accountable.

That starts with focusing less on defeating filters and more on preventing harmful ads from being approved or reaching users in the first place.

Some practical priorities include:

  • Verify advertisers more consistently, especially in high-risk categories such as financial services, cryptocurrency, health products, job offers, and government-benefit claims.
  • Review not only the visible creative, but also the destination page, redirects, tracking behavior, and later changes to the advertiser’s site.
  • Detect and act on coordinated impersonation campaigns quickly, rather than treating each fraudulent ad account as an isolated incident.
  • Make it easy for users to report ads and give them useful feedback when action has been taken.
  • Tackle ads before they can direct people into private messages, where scammers can continue the conversation outside public scrutiny.
  • Treat repeat offenders, cloned campaigns, and accounts linked to known fraud infrastructure as a network problem, which is much more effective than moderating them one ad at a time.
  • Give users meaningful controls over ad personalization, tracking, and the volume of ads they see.

Meta has policies against scams in place, continues to remove ads that violate those policies, and has announced additional anti-scam measures. Those are necessary steps. The question is whether they are sufficient for an environment where criminals are motivated, well-funded, and able to adapt rapidly.

No ad-review system will catch everything. Criminals will continue to use deception, compromised advertising accounts, and fast-changing infrastructure to get around automated checks.

That is why layered protection matters here as well.

Users should be able to choose tools that reduce tracking, block intrusive advertising, and stop access to known malicious sites. They should also be able to use browser protections, security software, and healthy skepticism when an ad promises easy money, a surprise refund, a miracle product, or a deal that seems too good to be true.

If ad blockers and the platforms that rely on advertising can find ways to work together, allowing security tools to intercept the malicious content their moderation systems miss, we can make the internet safer for everyone.


Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

  • ✇Malwarebytes
  • Meta ordered to pay $942 million over harm to children
    A New Mexico court has ordered Meta to pay a total of $942 million after finding that Facebook and Instagram harmed young users and that the company misled consumers about the safety of its platforms. Reportedly, the decision combines a $375 million civil-penalty verdict from March with a newly ordered $567 million abatement fund intended to address the damage. The court accepted the state’s argument that Meta had concealed what it knew about risks to children’s mental health and child sexual
     

Meta ordered to pay $942 million over harm to children

7 de Agosto de 2026, 18:04

A New Mexico court has ordered Meta to pay a total of $942 million after finding that Facebook and Instagram harmed young users and that the company misled consumers about the safety of its platforms.

Reportedly, the decision combines a $375 million civil-penalty verdict from March with a newly ordered $567 million abatement fund intended to address the damage. The court accepted the state’s argument that Meta had concealed what it knew about risks to children’s mental health and child sexual exploitation, while making misleading claims about the safety of its products.

Meta said it disagreed with the ruling and planned to appeal.

“We remain confident in our record of protecting teens online and will continue to defend ourselves against claims that misrepresent the facts.”

But the ruling is more than just a fine. It also imposes product-level obligations in New Mexico. Meta must continue improving its age-assurance tools, including:

  • Develop an under-13 prediction model within two years.
  • Seek proof of age from users it estimates are under 13.
  • Treat uncertain accounts as belonging to minors until their age is verified.
  • Delete personal data collected from under-13 users.

The company must also create a channel through which schools or a child-safety organization can report suspected underage accounts and submit compliance updates twice a year.

This is a significant step. A company can remove individual accounts or posts after the fact, but the New Mexico case focuses on whether the surrounding product design, age checks, disclosure practices, and reporting systems adequately protect children in the first place.

From Meta’s side, this is hardly a one-off incident. The Wall Street Journal reports that Meta is fighting thousands of lawsuits by individuals, school districts, and more than 40 state attorneys general which are pending in state and federal courts. 


Safer. Cleaner. Ad-free browsing.


How to keep your children safe

In February, we published research on how safe kids are when using social media. As the company behind Facebook, Instagram, and WhatsApp, Meta plays a major role in this field. But unfortunately, it seems Meta isn’t even capable of blocking ads that contain AI generated Child Sexual Abuse Material (CSAM).

Some tips for parents:

  • Keep communication open. Keep conversations about online activity open and ongoing, not one-off warnings. Talk to your child about who they interact with online and what kinds of conversations are appropriate. Warn them about strangers in comments, group and gaming chats, and direct messages. Encourage them to leave spaces that make them uncomfortable, even if they didn’t do anything wrong.
  • Set up accounts together. Use child or teen accounts where available and avoid defaulting to adult accounts. Keep friends and followers lists set to private. Avoid using real names, birthdays, or other identifying details unless they are strictly required. Avoid facial recognition features for children’s accounts. For teens, be aware of “spam” or secondary accounts they’ve set up that may have looser settings.
  • Treat age limits seriously. While we don’t like many of the ways they are implemented, the age restrictions are there for good reasons. Do not help children bypass a platform’s minimum age requirement. Age restrictions can reduce exposure to adult spaces, unwanted contact, and features not designed for children.
  • Discuss images and AI explicitly. Teach children never to send intimate images, even to someone they know, and to be wary of “nudify,” face-swap, or AI image-editing apps. Explain that AI-generated sexual images can be used to harass, blackmail, or humiliate someone, even when no original explicit photo exists.
  • Have a simple escalation plan. If someone becomes sexual, coercive, threatening, or asks to move a conversation to another app: stop replying, preserve relevant evidence, block the account, and report it to the platform and appropriate child-protection or law-enforcement services.
  • Teach a “pause before you click” habit. Children should know that ads, giveaways, direct messages, and links can be scams or gateways to harmful material. Encourage them to ask an adult before installing unfamiliar apps, entering personal information, or sharing photos.

The most effective and probably hardest of them all is to find a balance between relying on device and platform controls and helicopter parenting. Device and platform controls can limit screen time, sensitive content, and unknown contacts. And they work best alongside trust, shared rules, and periodic check-ins rather than covert surveillance.


Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

  • ✇Malwarebytes
  • A week in security (August 3 – August 9)
    Last week on Malwarebytes Labs: AI chat bots are sliding into League of Legends friend requests Meta ordered to pay $942 million over harm to children Apple WebKit vulnerabilities reveal your IP address, despite Private Relay Scammers target OnlyFans users with deepfakes Amazon and Apple impersonated in “$149.99 unauthorized charge” scam Anthropic’s Mythos AI used social engineering to target real people Google’s synchronized passkeys can be stolen in “Pass‑ta‑key” attacks
     
  • ✇Malwarebytes
  • Meta ordered to pay $942 million over harm to children
    A New Mexico court has ordered Meta to pay a total of $942 million after finding that Facebook and Instagram harmed young users and that the company misled consumers about the safety of its platforms. Reportedly, the decision combines a $375 million civil-penalty verdict from March with a newly ordered $567 million abatement fund intended to address the damage. The court accepted the state’s argument that Meta had concealed what it knew about risks to children’s mental health and child sexual
     

Meta ordered to pay $942 million over harm to children

7 de Agosto de 2026, 18:04

A New Mexico court has ordered Meta to pay a total of $942 million after finding that Facebook and Instagram harmed young users and that the company misled consumers about the safety of its platforms.

Reportedly, the decision combines a $375 million civil-penalty verdict from March with a newly ordered $567 million abatement fund intended to address the damage. The court accepted the state’s argument that Meta had concealed what it knew about risks to children’s mental health and child sexual exploitation, while making misleading claims about the safety of its products.

Meta said it disagreed with the ruling and planned to appeal.

“We remain confident in our record of protecting teens online and will continue to defend ourselves against claims that misrepresent the facts.”

But the ruling is more than just a fine. It also imposes product-level obligations in New Mexico. Meta must continue improving its age-assurance tools, including:

  • Develop an under-13 prediction model within two years.
  • Seek proof of age from users it estimates are under 13.
  • Treat uncertain accounts as belonging to minors until their age is verified.
  • Delete personal data collected from under-13 users.

The company must also create a channel through which schools or a child-safety organization can report suspected underage accounts and submit compliance updates twice a year.

This is a significant step. A company can remove individual accounts or posts after the fact, but the New Mexico case focuses on whether the surrounding product design, age checks, disclosure practices, and reporting systems adequately protect children in the first place.

From Meta’s side, this is hardly a one-off incident. The Wall Street Journal reports that Meta is fighting thousands of lawsuits by individuals, school districts, and more than 40 state attorneys general which are pending in state and federal courts. 


Safer. Cleaner. Ad-free browsing.


How to keep your children safe

In February, we published research on how safe kids are when using social media. As the company behind Facebook, Instagram, and WhatsApp, Meta plays a major role in this field. But unfortunately, it seems Meta isn’t even capable of blocking ads that contain AI generated Child Sexual Abuse Material (CSAM).

Some tips for parents:

  • Keep communication open. Keep conversations about online activity open and ongoing, not one-off warnings. Talk to your child about who they interact with online and what kinds of conversations are appropriate. Warn them about strangers in comments, group and gaming chats, and direct messages. Encourage them to leave spaces that make them uncomfortable, even if they didn’t do anything wrong.
  • Set up accounts together. Use child or teen accounts where available and avoid defaulting to adult accounts. Keep friends and followers lists set to private. Avoid using real names, birthdays, or other identifying details unless they are strictly required. Avoid facial recognition features for children’s accounts. For teens, be aware of “spam” or secondary accounts they’ve set up that may have looser settings.
  • Treat age limits seriously. While we don’t like many of the ways they are implemented, the age restrictions are there for good reasons. Do not help children bypass a platform’s minimum age requirement. Age restrictions can reduce exposure to adult spaces, unwanted contact, and features not designed for children.
  • Discuss images and AI explicitly. Teach children never to send intimate images, even to someone they know, and to be wary of “nudify,” face-swap, or AI image-editing apps. Explain that AI-generated sexual images can be used to harass, blackmail, or humiliate someone, even when no original explicit photo exists.
  • Have a simple escalation plan. If someone becomes sexual, coercive, threatening, or asks to move a conversation to another app: stop replying, preserve relevant evidence, block the account, and report it to the platform and appropriate child-protection or law-enforcement services.
  • Teach a “pause before you click” habit. Children should know that ads, giveaways, direct messages, and links can be scams or gateways to harmful material. Encourage them to ask an adult before installing unfamiliar apps, entering personal information, or sharing photos.

The most effective and probably hardest of them all is to find a balance between relying on device and platform controls and helicopter parenting. Device and platform controls can limit screen time, sensitive content, and unknown contacts. And they work best alongside trust, shared rules, and periodic check-ins rather than covert surveillance.


Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

  • ✇Malwarebytes
  • Meta pauses controversial employee-tracking program after security review
    Meta has paused a controversial employee‑tracking program after an internal security review found that highly granular keystroke and screen‑capture data from staff laptops was far more widely accessible inside the company than intended. The program was part of Meta’s Model Capability Initiative (MCI), which collected mouse movements, click locations, keystrokes, and screen content from employees’ work laptops to help train internal AI systems. The program also introduced an obvious risk. C
     

Meta pauses controversial employee-tracking program after security review

23 de Junho de 2026, 10:01

Meta has paused a controversial employee‑tracking program after an internal security review found that highly granular keystroke and screen‑capture data from staff laptops was far more widely accessible inside the company than intended.

The program was part of Meta’s Model Capability Initiative (MCI), which collected mouse movements, click locations, keystrokes, and screen content from employees’ work laptops to help train internal AI systems.

The program also introduced an obvious risk. Collecting highly sensitive employee activity data is one thing. Keeping it properly secured is another.

According to reporting based on internal documents and employee accounts, the data wasn’t just collected. It was left accessible across thousands of internal data tables, including AI prompts, transcriptions, private conversations, and performance‑related information.

After coverage of the exposure, Meta scaled back and then paused the initiative, amid sustained internal backlash and questions about whether privacy protections were ever more than a reassurance in a memo.

From Meta’s perspective, the Model Capability Initiative was an efficiency play. The goal was to provide AI models with “real examples of how people actually use computers” by passively logging how employees navigate everyday tools like Gmail, GChat, Metamate, and VS Code. Agents would be able to learn from live workflows instead of synthetic benchmarks.

Employees were promised that the data gathering would be limited to work apps and not employees’ phones. But you can imagine how it was perceived:

  • Keystroke and mouse‑tracking software was pushed to US workers’ laptops, with no option to opt out on company devices, as confirmed internally by Meta’s CTO.
  • The software captured inputs plus associated screen content, creating a behavioral dataset: what you type, where you click, what is on your screen while you do it.

The program prompted significant internal criticism. An engineer’s internal post protesting “laptop surveillance” and screen monitoring went viral inside Meta, sparking a petition to kill the program entirely.

From a compliance angle, employee-monitoring programs of this scope can raise difficult legal and regulatory questions, particularly in jurisdictions that require transparency around workplace surveillance and data collection.

The reputational impact is arguably even worse. When a company is always under scrutiny for tracking users, breaking trust with employees sends a strong signal about its default attitude toward data.

All this while knowing that keystroke and screenshot data is high‑risk by design. That type of data is content‑rich, behavioral, and often contains secrets. Collecting it at scale creates a security burden. Every new data point adds obligations around access control, minimization, retention, and audit, that the organization must actively manage for as long as the data exists.

  • Access controls must be precise and regularly audited, because a simple misconfiguration can have big consequences.
  • Data minimization and retention limits are essential since long‑term storage multiplies the impact of a potential breach.
  • Any future data leak—internal or external—could expose not just emails, but the exact sequences employees type, including authentication flows and draft content. In the wrong hands, this kind of information could expose the company to compromise.

This episode is a reminder that every new dataset creates new responsibilities. The more detailed and sensitive the information, the greater the consequences when access controls fail.


Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

  • ✇Malwarebytes
  • A week in security (June 8 – June 14)
    Last week on Malwarebytes Labs: Stolen iPhones could soon be worth a lot less to thieves Fake verification pages are stealing Steam accounts from players Google can be liable for false AI Overviews, court rules VRChat says reported data breach never happened Children’s phones must block nude images by September, UK says Free Spotify Premium hacks on social media are spreading infostealers Microsoft’s biggest-ever Patch Tuesday fixes 206 bugs, including 3 zero-days 88% of
     
  • ✇Malwarebytes
  • VRChat says reported data breach never happened
    A data breach notice has been filed with the Maine Attorney General, saying more than 2.4 million users of VRChat have had their data breached. The question is, was it VRChat who filed the breach notice, or did someone pretending to represent the company post it instead? On Reddit, a VRChat representative posted: VRChat did not submit this Notice of Data Incident, and we have no reason to believe that our systems have been compromised. We are in the process of contacting the Maine Attor
     

VRChat says reported data breach never happened

11 de Junho de 2026, 08:31

A data breach notice has been filed with the Maine Attorney General, saying more than 2.4 million users of VRChat have had their data breached.

The question is, was it VRChat who filed the breach notice, or did someone pretending to represent the company post it instead? On Reddit, a VRChat representative posted:

VRChat did not submit this Notice of Data Incident, and we have no reason to believe that our systems have been compromised. We are in the process of contacting the Maine Attorney General’s office to have this removed.

The breach notice states that VRChat experienced unauthorized access to some account data between May 10 and May 12, 2026. The access supposedly happened in VRChat’s cloud environment and involved user profile and login-related data.

According to the notice, the information exposed varied by account, but may have included:

  • VRChat username
  • Email address associated with the VRChat account
  • VRChat+ subscription status
  • Login history, including device information, hardware identifiers, and IP addresses

VRChat is a social platform designed primarily for virtual reality headsets, allowing users to interact with others through user-created 3D avatars and worlds. Users can access VRChat through Steam for PC, the Meta Quest Store, or as an Android app for compatible devices.

The notice states that no passwords or payment card data was exposed. However, even without passwords or card details, there are still potential risks when it comes to other breached data.

Phishing

Cybercriminals may use usernames and email addresses in targeted phishing attempts. For example, users may receive phishing emails or in‑platform messages claiming to be from “Support,” with fake security alerts or prompts to “confirm your age” via a malicious link.

Knowledge of subscription status could make scams more convincing. A scammer could send tailored lures like “billing issue with your subscription” or refund scams, which tend to have higher click-through rates among paying users.

Account takeover

Cybercriminals may combine usernames and email addresses from one breach with passwords stolen in other data breaches and try them against accounts. This technique, known as credential stuffing, takes advantage of people who reuse passwords across multiple sites.

Valuable accounts may then be sold to other players or used for scams.

Identity correlation

Steam and Meta user IDs linked to breached accounts can help cybercriminals connect identities across gaming and social platforms, especially if the same email or profile name is reused.

IP addresses, login history, device information, and other identifiers can also help build a more detailed advertising or tracking profile of a user.

How to stay safe

Whether or not the breach turns out to be an actual breach, here are some steps you can take to protect yourself:

First and foremost, be cautious of emails, texts, or calls claiming to come from VRChat or the gaming platforms you used it on, as cybercriminals often exploit breaches with phishing scams.

If you’ve used your VRChat password anywhere else, change those accounts immediately, and set up two-factor authentication (2FA) on your VRChat account if you haven’t already.

More general advice can be found in our article on what to do when you find out you’re involved in a data breach.

Update June 11, 2026: Article was updated to reflect VRChat’s post on Reddit.

Before publishing our original article, we tried to contact VRChat on two separate email addresses but received no meaningful response.


Let’s face it, an incognito window can only do so much. 
 
Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance. 

❌
❌