Visualização normal

Antes de ontemStream principal
  • ✇Firewall Daily – The Cyber Express
  • FBI, LinkedIn Warn Job Seekers of Employment Scams and Exploitation Samiksha Jain
    Employment scams are increasingly being used to target job seekers, with the FBI and LinkedIn joining forces to educate applicants about fraudulent job opportunities and the warning signs of potential exploitation. The FBI's Internet Crime Complaint Center received 24,688 reports of employment scam victimization in 2025, with nearly $363 million in reported losses. The FBI defines employment fraud as a scheme designed to deceive someone into believing they have been, or could soon be, hired f
     

FBI, LinkedIn Warn Job Seekers of Employment Scams and Exploitation

Employment scams

Employment scams are increasingly being used to target job seekers, with the FBI and LinkedIn joining forces to educate applicants about fraudulent job opportunities and the warning signs of potential exploitation. The FBI's Internet Crime Complaint Center received 24,688 reports of employment scam victimization in 2025, with nearly $363 million in reported losses. The FBI defines employment fraud as a scheme designed to deceive someone into believing they have been, or could soon be, hired for a job. However, officials warn that these schemes are not always focused on stealing money from victims. They can also be used to recruit money mules, collect personally identifiable information, or force people into labor.

Employment Scams Exploit Trust in Job Opportunities

LinkedIn, which has more than 1.3 billion members across more than 200 countries and regions, said people submit approximately 10,000 job applications every minute on the platform. The company uses automated systems and human oversight to detect and remove fraudulent activity. According to LinkedIn, automated defenses remove 98.7% of detected spam and scam content before members see it, while 99.5% of detected fake accounts are stopped proactively. LinkedIn also uses verification indicators to show when certain information about people, companies, recruiters, and candidates has been confirmed. Despite these measures, the company said scammers are becoming more sophisticated, with artificial intelligence making it cheaper, faster, and easier to impersonate legitimate individuals. One warning sign highlighted by LinkedIn is when a recruiter or company representative attempts to move a conversation away from LinkedIn's messaging platform. Doing so can allow scammers to bypass the platform's protections and reporting tools.

Money Mule Scams Turn Job Seekers Into Financial Intermediaries

One major form of employment scams involves recruiting victims as money mules. Scammers may advertise legitimate-sounding positions such as cryptocurrency transaction specialist, accounts receivable assistant, remote financial coordinator, or payment processing agent. After being hired, victims may receive money in their personal bank accounts, often through peer-to-peer payment applications. They are then instructed to withdraw the funds, convert them into cash, gift cards, or cryptocurrency, and transfer them elsewhere in exchange for a small commission. The money is generally linked to other scams or compromised accounts. Victims may face legal consequences, account closures, and seized funds despite being deceived into participating.

Stolen PII Employment Scams Target Personal Information

Another type of fraud uses fake employment opportunities to collect stolen PII. Job titles may include onboarding specialist, HR assistant, compliance reviewer, or know your customer and identity verification agent. Victims may be asked to collect identity documents from customers, forward files, verify accounts, handle one-time codes, open accounts, submit applications, or organize data into spreadsheets and shared drives. Instead of directly moving stolen money, victims become part of a process designed to harvest personal information.

Forced Labor Can Begin With a Fake Job Offer

The FBI also warns that some employment scams can become gateways to human trafficking and forced labor. Victims may be offered jobs abroad or remote positions and encouraged to travel internationally, with Southeast Asia identified as a known hotspot. After arriving, victims may have their passports confiscated and be told they must repay travel costs. Some are then forced to work in scam compounds, where they are required to contact targets. Victims may face monitoring, threats, or physical abuse if they fail to meet quotas.

FBI Warns Job Seekers About Employment Scam Red Flags

The FBI and LinkedIn advise applicants to research companies carefully and watch for warning signs. For money mule scams, red flags include requests to use personal bank accounts for business transactions, bypass normal payroll systems, move money quickly, open new accounts, or use cryptocurrency and gift cards. For scams involving stolen PII, applicants should be cautious if they are asked to handle sensitive identity documents without a legitimate compliance structure, receive files through informal channels, or are pressured to bypass normal safeguards. Potential forced labor scams may involve unusually high pay for vague overseas jobs, demands for quick relocation, employer-controlled travel arrangements, vague contracts, early moves to encrypted messaging apps, or instructions to keep the job secret from family. The FBI and LinkedIn said educating job seekers can help disrupt employment fraud before victims become involved. Anyone who believes they have been targeted should contact their financial institution immediately and report the incident to the FBI's Internet Crime Complaint Center with as many details as possible.
  • ✇Firewall Daily – The Cyber Express
  • FBI Warns of Surge in Cyber-Enabled Cargo Theft Targeting Logistics Firms Samiksha Jain
    The Federal Bureau of Investigation (FBI) has issued a public warning over a sharp rise in cyber-enabled cargo theft, as threat actors increasingly use digital tactics to impersonate legitimate businesses, hijack freight, and steal high-value shipments. According to the FBI, cybercriminals are targeting transportation and logistics companies involved in shipping, receiving, and insuring cargo. The agency said these attacks have been ongoing since at least 2024 and are now becoming more sophis
     

FBI Warns of Surge in Cyber-Enabled Cargo Theft Targeting Logistics Firms

cyber-enabled cargo theft

The Federal Bureau of Investigation (FBI) has issued a public warning over a sharp rise in cyber-enabled cargo theft, as threat actors increasingly use digital tactics to impersonate legitimate businesses, hijack freight, and steal high-value shipments. According to the FBI, cybercriminals are targeting transportation and logistics companies involved in shipping, receiving, and insuring cargo. The agency said these attacks have been ongoing since at least 2024 and are now becoming more sophisticated and widespread. Losses linked to cyber-enabled cargo theft have surged significantly. In 2025, estimated cargo theft losses in the United States and Canada reached nearly $725 million, marking a 60 percent increase from the previous year. Confirmed incidents rose by 18 percent, while the average value per theft increased by 36 percent to $273,990, reflecting a shift toward more targeted, high-value shipments.

How Cyber-Enabled Cargo Theft Works

The FBI outlined a structured, multi-step process used in cyber-enabled cargo theft schemes. Attackers begin by compromising accounts of brokers and carriers through phishing techniques such as spoofed emails, fake websites, and malicious links. Victims are often sent emails posing as legitimate business communications, such as carrier agreements or service complaints. These emails include links that lead to phishing websites designed to mimic trusted platforms. Once accessed, these sites deploy malware or remote monitoring tools, allowing attackers to gain full control over systems without detection. After gaining access, cybercriminals exploit online freight marketplaces known as load boards. They impersonate legitimate brokers or carriers and post fake shipment listings, sometimes in large volumes. Unsuspecting carriers bid on these listings and are further compromised through fraudulent agreements or malicious downloads. In the next stage, attackers use the compromised accounts to accept real shipment contracts. They then engage in illegal double-brokering, rerouting freight to unintended locations. Shipment documents are manipulated, including bills of lading, and delivery destinations are altered without the knowledge of the original parties. The final stage of cyber-enabled cargo theft involves physically diverting the cargo. Goods are transferred through cross-docking or transloading to other drivers, often complicit, and then stolen for resale. In some cases, attackers demand ransom payments in exchange for information about the shipment’s location. [caption id="attachment_111803" align="aligncenter" width="972"]cyber-enabled cargo theft Image Source: https://www.ic3.gov/[/caption]

Indicators of Cyber-Enabled Cargo Theft

The FBI has identified several warning signs that may indicate a cyber-enabled cargo theft attempt. These include unexpected communications regarding shipments made in a company’s name, spoofed email domains, and requests to download documents from suspicious links. Other indicators include emails referencing negative service reviews with embedded links, unauthorized changes to email account settings, and slight variations in domain names designed to mimic legitimate organisations. Attackers may also use temporary or internet-based phone numbers to communicate with victims. These tactics are designed to create a sense of urgency or legitimacy, increasing the likelihood that employees will engage with malicious content.

Steps to Prevent Theft

To reduce the risk of cyber-enabled cargo theft, the FBI is urging organisations to adopt stronger verification and security practices. Companies are advised to independently confirm shipment requests using multiple communication channels before releasing goods. The agency recommends implementing multi-layer verification processes and not relying solely on familiar names or email addresses. Businesses should also maintain detailed records of all transactions, including driver identification, vehicle details, and communication logs, to support investigations if needed. Recognising phishing attempts and avoiding interaction with suspicious links remain critical preventive measures.

Reporting Theft Incidents

The FBI has encouraged victims of cyber-enabled cargo theft to report incidents promptly. In addition to contacting local law enforcement, affected organisations should file complaints with the Internet Crime Complaint Center (IC3) or reach out to their nearest FBI field office. The agency said timely reporting can help identify patterns, disrupt criminal networks, and prevent further losses across the logistics sector.
  • ✇Krebs on Security
  • Most Parked Domains Now Serving Malicious Content BrianKrebs
    Direct navigation — the act of visiting a website by manually typing a domain name in a web browser — has never been riskier: A new study finds the vast majority of “parked” domains — mostly expired or dormant domain names, or common misspellings of popular websites — are now configured to redirect visitors to sites that foist scams and malware. A lookalike domain to the FBI Internet Crime Complaint Center website, returned a non-threatening parking page (left) whereas a mobile user was instantl
     

Most Parked Domains Now Serving Malicious Content

16 de Dezembro de 2025, 11:14

Direct navigation — the act of visiting a website by manually typing a domain name in a web browser — has never been riskier: A new study finds the vast majority of “parked” domains — mostly expired or dormant domain names, or common misspellings of popular websites — are now configured to redirect visitors to sites that foist scams and malware.

A lookalike domain to the FBI Internet Crime Complaint Center website, returned a non-threatening parking page (left) whereas a mobile user was instantly directed to deceptive content in October 2025 (right). Image: Infoblox.

When Internet users try to visit expired domain names or accidentally navigate to a lookalike “typosquatting” domain, they are typically brought to a placeholder page at a domain parking company that tries to monetize the wayward traffic by displaying links to a number of third-party websites that have paid to have their links shown.

A decade ago, ending up at one of these parked domains came with a relatively small chance of being redirected to a malicious destination: In 2014, researchers found (PDF) that parked domains redirected users to malicious sites less than five percent of the time — regardless of whether the visitor clicked on any links at the parked page.

But in a series of experiments over the past few months, researchers at the security firm Infoblox say they discovered the situation is now reversed, and that malicious content is by far the norm now for parked websites.

“In large scale experiments, we found that over 90% of the time, visitors to a parked domain would be directed to illegal content, scams, scareware and anti-virus software subscriptions, or malware, as the ‘click’ was sold from the parking company to advertisers, who often resold that traffic to yet another party,” Infoblox researchers wrote in a paper published today.

Infoblox found parked websites are benign if the visitor arrives at the site using a virtual private network (VPN), or else via a non-residential Internet address. For example, Scotiabank.com customers who accidentally mistype the domain as scotaibank[.]com will see a normal parking page if they’re using a VPN, but will be redirected to a site that tries to foist scams, malware or other unwanted content if coming from a residential IP address. Again, this redirect happens just by visiting the misspelled domain with a mobile device or desktop computer that is using a residential IP address.

According to Infoblox, the person or entity that owns scotaibank[.]com has a portfolio of nearly 3,000 lookalike domains, including gmai[.]com, which demonstrably has been configured with its own mail server for accepting incoming email messages. Meaning, if you send an email to a Gmail user and accidentally omit the “l” from “gmail.com,” that missive doesn’t just disappear into the ether or produce a bounce reply: It goes straight to these scammers. The report notices this domain also has been leveraged in multiple recent business email compromise campaigns, using a lure indicating a failed payment with trojan malware attached.

Infoblox found this particular domain holder (betrayed by a common DNS server — torresdns[.]com) has set up typosquatting domains targeting dozens of top Internet destinations, including Craigslist, YouTube, Google, Wikipedia, Netflix, TripAdvisor, Yahoo, eBay, and Microsoft. A defanged list of these typosquatting domains is available here (the dots in the listed domains have been replaced with commas).

David Brunsdon, a threat researcher at Infoblox, said the parked pages send visitors through a chain of redirects, all while profiling the visitor’s system using IP geolocation, device fingerprinting, and cookies to determine where to redirect domain visitors.

“It was often a chain of redirects — one or two domains outside the parking company — before threat arrives,” Brunsdon said. “Each time in the handoff the device is profiled again and again, before being passed off to a malicious domain or else a decoy page like Amazon.com or Alibaba.com if they decide it’s not worth targeting.”

Brunsdon said domain parking services claim the search results they return on parked pages are designed to be relevant to their parked domains, but that almost none of this displayed content was related to the lookalike domain names they tested.

Samples of redirection paths when visiting scotaibank dot com. Each branch includes a series of domains observed, including the color-coded landing page. Image: Infoblox.

Infoblox said a different threat actor who owns domaincntrol[.]com — a domain that differs from GoDaddy’s name servers by a single character — has long taken advantage of typos in DNS configurations to drive users to malicious websites. In recent months, however, Infoblox discovered the malicious redirect only happens when the query for the misconfigured domain comes from a visitor who is using Cloudflare’s DNS resolvers (1.1.1.1), and that all other visitors will get a page that refuses to load.

The researchers found that even variations on well-known government domains are being targeted by malicious ad networks.

“When one of our researchers tried to report a crime to the FBI’s Internet Crime Complaint Center (IC3), they accidentally visited ic3[.]org instead of ic3[.]gov,” the report notes. “Their phone was quickly redirected to a false ‘Drive Subscription Expired’ page. They were lucky to receive a scam; based on what we’ve learnt, they could just as easily receive an information stealer or trojan malware.”

The Infoblox report emphasizes that the malicious activity they tracked is not attributed to any known party, noting that the domain parking or advertising platforms named in the study were not implicated in the malvertising they documented.

However, the report concludes that while the parking companies claim to only work with top advertisers, the traffic to these domains was frequently sold to affiliate networks, who often resold the traffic to the point where the final advertiser had no business relationship with the parking companies.

Infoblox also pointed out that recent policy changes by Google may have inadvertently increased the risk to users from direct search abuse. Brunsdon said Google Adsense previously defaulted to allowing their ads to be placed on parked pages, but that in early 2025 Google implemented a default setting that had their customers opt-out by default on presenting ads on parked domains — requiring the person running the ad to voluntarily go into their settings and turn on parking as a location.

❌
❌