Cybersecurity professionals are emphasizing the increased risk of holiday-themed scams, including fraudulent delivery texts, family emergency calls, and gift card traps. Attackers are leveraging social engineering tactics such as urgent messages, spoofed caller IDs, and requests for off-platform payments to trick individuals into revealing sensitive information or sending money. Security experts recommend verifying all requests through official channels, using family codewords, and reporting suspicious activity to authorities. Common red flags include unexpected delivery notifications, lookalike email domains, and requests for payment via gift cards or cryptocurrency.
Guidance for consumers includes never clicking on links in unsolicited messages, keeping communications and payments within trusted platforms, and using credit cards for charitable donations. Security professionals also highlight the importance of educating friends and family about these threats, especially during the holiday season when such scams are most prevalent. Reporting mechanisms such as forwarding spam texts to 7726 or using ReportFraud.ftc.gov are encouraged to help combat these scams.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
AlphaHunt and Huntress published holiday-focused security guidance covering delivery smishing, AI voice impersonation, bank and government imposters, gift card fraud, marketplace scams, sextortion, romance scams, and pig-butchering. The guidance emphasized verification through official channels, keeping payments on trusted platforms, enabling MFA, using passkeys and password managers, and maintaining skepticism toward unsolicited communications.
During a Tradecraft Tuesday session, Huntress leaders said the critical React remote code execution flaw CVE-2025-55182 was being exploited rapidly at a scale comparable to Log4Shell, with attackers deploying cryptominers, Linux backdoors, and botnets. They urged organizations to respond within 24 hours due to the speed of attacks.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.