Flirty OnlyFans promoters on X may be using AI to appear human
Developer Álvaro Martínez Majado found OnlyFans-promoting accounts on X following rigid scripts yet handling encoded instructions, suggesting generative AI use.
Investigation of flirty X accounts promoting OnlyFans pages showed near-identical openers across accounts plus dynamic behaviors: answering a hexadecimal-encoded instruction with "Pineapple" and failing an exact 12-character count test in an LLM-like pattern. The accounts also sent personalized voice notes reading supplied timestamps and usernames, consistent with automated text-to-speech. Evidence suggests a hybrid scripted/AI system, though no model, provider, or operator was identified.
Scammers have figured out the best time to text you
Malwarebytes threat data shows scammers tailor platforms per scam, with the web as top channel, Friday midday peaks, and MrBeast the most impersonated person.
Malwarebytes analyzed its threat data from April 15 to July 14, 2026 across more than 20 scam categories, finding scammers match platforms to scam types: job scams via email, romance scams via social media, and tech support scams via phone. The web is the top delivery channel ahead of email and SMS, and Malwarebytes says it blocks about 500,000 phishing sites a day. Scam texts peak at 12:00 pm ET, roughly 874% above the quietest hour, with volume peaking on Fridays about 50% higher than the start of the week. MrBeast (Jimmy Donaldson) appears in about 30% of impersonation scams, and the most impersonated brands are Google, Microsoft, Apple, Roblox and Amazon.
Scammers are getting smarter about where they target you
Malwarebytes data shows scammers tailor fraud by platform: 90% of toll scams arrive via email/SMS and MrBeast is now the most impersonated person.
Malwarebytes threat research analyzed global scam data from April 15 to July 14, 2026, across more than 20 scam types, finding each type favors a specific channel such as email, SMS, phone, or social media. Roughly nine in ten toll scams arrive by email or text, about half of IRS scams come by phone, and MrBeast is impersonated in about 30% of impersonation scams. The most impersonated brands are Google, Microsoft, Apple, Roblox, and Amazon, and Malwarebytes blocks around 500,000 phishing websites daily. Gaming scams on Roblox, Steam, Discord, and Minecraft increasingly carry losses of $1,000 or more, with 15-19% activity spikes in mid-2026.
58 Arrested In International Cybercrime Crackdown
Interpol's Operation Jackal IV arrested 58 people across 22 countries, disrupting Black Axe-linked money laundering and fraud networks and uncovering $166 million.
Law enforcement in 22 countries coordinated on Operation Jackal IV from November 2025 to June 2026, arresting 58 people and identifying hundreds of suspects, Interpol announced. Actions in Argentina uncovered a 196-person crime-as-a-service network providing domains and money laundering support to Black Axe, with 17 arrests there; South African raids in Johannesburg linked to romance and investment scams targeting the elderly led to 39 arrests and about $2.7 million seized. Romanian investigators found $166 million in stolen and laundered funds in electronic wallets controlled by a cryptocurrency investment scam call center, making 11 arrests and seizing about $379,000 plus properties and luxury watches. Interpol also flagged rising sextortion of minors as young as 14 via social media and gaming platforms.
Kids’ online safety bill faces dim prospects of passage this session despite progress
Kids Online Safety Act clears Senate committee but passage looks unlikely this session amid House-Senate deadlock over the duty-of-care provision.
KOSA advanced out of the Senate Commerce Committee, but the chambers remain split on a duty-of-care provision requiring platforms to act with reasonable caution to prevent foreseeable harm, which House leadership opposes over First Amendment and negligence-lawsuit concerns. The Senate passed KOSA 91-3 last Congress before it died in the House, and the House passed its own version without the duty of care in June as part of a larger package, after stripping a state-law preemption provision. Observers say even Senate passage this year is a struggle given the short calendar, with a lame-duck window between November and January the more plausible path, and Majority Leader John Thune controlling whether a roll-call vote happens.
Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups
Trump White House memo directs NCC to build a program within 60 days authorizing vetted U.S. companies to conduct cyber surveillance and effects operations against foreign criminal groups.
A new White House memorandum instructs the National Coordination Center to establish, within 60 days, a program letting vetted private-sector companies, under federal oversight, conduct cyber surveillance operations (accessing sensitive data without authorization) and cyber effects operations (disruption, degradation, or destruction) against foreign Transnational Criminal Organizations. Targets are groups conducting cyber-enabled crime against U.S. government, persons, or interests that are not institutionally part of a foreign government. Companies must stop operations exceeding approved parameters, run minimization procedures, and alert the NCC, which notifies the Department of Justice. The fact sheet cites an estimated $20.8 billion in reported U.S. consumer losses to cyber-enabled crimes, and experts note legal and security risks since existing laws prohibit private companies from offensive cyber without court authorization.
White House authorizes private US companies to hack foreign criminal networks
Trump memorandum authorizes vetted private US companies to conduct government-supervised offensive cyber operations against foreign criminal networks.
The National Security Presidential Memorandum signed August 12 lets vetted private companies run offensive cyber operations against transnational criminal organizations behind ransomware, phishing and sextortion, under US government oversight. The Homeland Security Task Force's National Coordination Center, led by DOJ and DHS executive directors, must give written approval for both Cyber Surveillance Operations and Cyber Effects Operations. Participating companies must post a $1 million bond or escrow, undergo annual review, and notify authorities if they unintentionally target US persons or systems.
FBI: Hackers using social engineering to breach accounts and steal explicit content
FBI warns hackers use social engineering and password-stuffing to hijack social media accounts and sell victims' explicit content on criminal marketplaces.
The FBI issued an alert on threat actors who breach social media accounts of adults and children using password-stuffing with credentials from data leak sites, impersonation of social media support staff, and cloned login pages, in order to steal and sell explicit content. Stolen content is often posted with victims' personal information, leading to sextortion, harassment, and stalking. Related DOJ cases include a man who pleaded guilty to hacking about 600 Snapchat accounts and a former University of Michigan coach who accessed records of about 150,000 people across 100+ colleges.