AI Just Pumped Out 1M Scams—Here’s This Week’s Nightmare Fuel

If you needed another reason to be paranoid about your digital footprint, this week’s cybersecurity news delivers in spades. From AI-generated phishing campaigns targeting corporate payroll to hijacked brand accounts spreading infostealer malware, the threat landscape is not just evolving—it’s accelerating. We’re breaking down the most brutal security stories of the week, including the good news that law enforcement finally nailed a long-running DDoS-for-hire service.

Let’s get straight into the weeds of the vulnerabilities, data breaches, and malware campaigns that are keeping security researchers up at night.

Threat Actor Uses AI to Generate 1M Personalized Fraud Emails in 3 Days

When we talk about how AI is a hacker’s favorite tool and how it supercharges malware campaigns, this is what we mean. Dark Reading reports that researchers at Microsoft tracked a phishing campaign in which an unknown threat actor sent over 1 million highly personalized phishing emails in less than three days. The target? Payroll and accounts payable departments at companies worldwide, hit with fake ServiceNow invoices demanding payment for overdue bills.

Even worse, because the threat actor used AI to draft the emails, they were often personalized with the actual names and roles of the target employees at the impacted companies, along with information about each company’s management. The emails even looked like they were part of a threaded conversation with other company representatives, making the message appear as if it was originally addressed to a company leader, who then directed the scammer to contact accounting to have the bill paid.

Attacks like this play on the human element of security, creating a false sense of urgency and authority to encourage overworked, stressed-out employees to just do what the email asks rather than stop to verify its claims. It’s certainly creative, if not scary, and AI is making it easy for scammers to scale up such spear-phishing campaigns. This is the new reality of the hacking ecosystem—automated, intelligent, and incredibly difficult to distinguish from legitimate business traffic.

Trusted Names Compromised: From HBO Max to Torrent Sites

Attackers are increasingly compromising legitimate, trusted names to spread malware, and this week was a prime example of that trend. Perhaps the biggest incident was the hijacking of an HBO Max Reddit account, which was used to direct users to an app that was actually infostealer malware in disguise. This type of social engineering is particularly dangerous because it leverages the trust users place in verified accounts and official-sounding subreddits.

Hot on the heels of that attack were the Iranian-affiliated hackers who used known security brands like Norton and KeePass to trick users into installing spyware. In that case, you may not need to worry about it as much, since the campaign is designed to target political dissidents, journalists, and activists opposed to the Iranian government. Even so, targeted malware attacks usually don’t stay targeted for long—the tools and tactics often leak into the broader criminal ecosystem.

Speaking of the broader ecosystem, cybersecurity company Kaspersky published a warning this week that iTorrents.org, a public torrent repository, had been hijacked and was instead spreading malware, including a malware-laden version of Christopher Nolan’s *The Odyssey*. As of right now, the site remains compromised, meaning anyone downloading from it is potentially exposing themselves to a significant cybersecurity risk. Always scan downloaded files and verify checksums when dealing with unofficial repositories.

Copyright Scammers Get Instagram Accounts Suspended and Demand Payment

This isn’t so much a strict security story as it is a warning for anyone with an Instagram account they’d actually like to hold on to, and another example of social media platforms’ lax policy enforcement and overreliance on automated tools for reporting and moderation. Both the BBC and the Malwarebytes blog shared an alarming story about copyright scammers on Instagram weaponizing the platform’s automated reporting tools and “suspend first, verify later” approach to moderation.

Attackers are filing repeated false copyright strikes against accounts, getting them suspended, and then demanding payment via cryptocurrency to have the complaints withdrawn so the owner can get their accounts back. As with any ransom-style attack, there’s no guarantee that paying the ransom will actually get the attacker to withdraw the complaint, and even if they do, there’s no guarantee that Meta, the parent company of Instagram (and Facebook and WhatsApp), will restore the account.

Malwarebytes reported that similar attacks have been occurring since 2023, and the platform hasn’t found a way to handle them. Meta says it restored the accounts the BBC reported, but let’s be honest: It shouldn’t take a media campaign to get a platform to listen to its users and to fight people who use its own tools to scam others. This is a social engineering attack that doesn’t rely on a traditional data breach or vulnerability—it exploits the platform’s own processes against its users.

Victory Laps: DDoS Takedown and Smart Glasses Detection

It’s not all bad news, though. We love sharing security-related wins when we find them, and this week we reported on law enforcement taking down one of the web’s most long-running DDoS sites. The site, NightmareStresser, posed as a legitimate tool that allowed users to stress test websites for reliability. But of course, for a modest fee, you could stress test hard enough to disrupt a site that didn’t belong to you, and that was the primary business model. The takedown is a significant blow to the DDoS-for-hire industry, which has plagued online services for years.

Similarly, this week Bastille Networks, a security startup specializing in wireless intrusion detection, announced it had developed tools to detect nearby smart glasses, specifically for businesses and government agencies that want to keep them out of sensitive areas. Considering the reputation that spy glasses have, we can only hope the tech becomes available to consumers soon, too. This is a proactive step in mitigating the privacy risks posed by wearable technology.

EFF: Privacy Considerations With AI Tools

We’ve discussed before that AI and privacy don’t really go hand in hand, and we've even tested the most popular chatbots ourselves to see which ones store the most personal data. Since they’re so widely used, we also have tips to limit what ChatGPT and what Google Gemini know about you. But the folks over at the Electronic Frontier Foundation published a broad guide to AI privacy last month that dives much deeper, going into the differences between cloud-based AI and on-device AI.

They remind people that “do not train using my data” is not the same thing as “do not access my data and use it for other things,” which is easy to overlook. Opting out of one method of data handling doesn’t mean you’re successfully keeping your data private, unfortunately. The EFF guide also has specific links to disable AI training for individual tools, including ChatGPT, Gemini, Claude, and others.

Additionally, it reminds people to consider how these services would handle law enforcement requests and if that should matter in your use case. Whether you’re an AI skeptic or a regular user, it’s worth bookmarking, if only as a reminder of how these platforms handle your data, from your prompts and queries to everything else they’re capable of collecting about you just based on your usage habits.

Passkeys and Physical Theft: What You Need to Know

Finally, we have to address a question we received from a reader: if your phone is snatched out of your hand while unlocked, are your passkeys at risk? The short answer is yes. If someone snatches your phone out of your hand and it’s unlocked, whoever has your phone probably has your passkeys as well and can use them, assuming you don’t have your password manager or whatever tool you use to store the passkeys set to ask you to authenticate every time you use one.

Most modern password managers require authentication before unlocking the vault, which can mitigate this risk. A thief who runs off with your phone may have access to some open sessions before the phone locks itself (or before you lock and wipe it remotely, which you should do as soon as possible if your phone gets stolen). But when someone has physical access to your unlocked device, all bets are off, really. That’s not the fault of passkeys any more than it’s the fault of saved passwords or any other security measure that relies on your device to work.

So don’t think of it as a limitation of passkeys—just remember that there’s a reason security experts admit there’s only so much you can do if someone has physical control of your device.

Stay safe out there, and keep your patching schedule tight.