Multiple reports describe social-engineering scams that impersonate trusted brands and payment providers to drive victims into credential theft or direct monetary loss. A “crypto compensation” lure abuses a legitimate-looking Yandex poll as an entry point, then redirects victims to a fake Bitcoin payout page claiming an approved 0.943 BTC transaction and imposes a small “commission”/fee to withdraw funds—classic advance-fee fraud wrapped in a polished, multi-step funnel (including a fake chat “support agent”). Separately, Japanese-language phishing emails impersonating ANA, DHL, and myTOKYOGAS show consistent infrastructure patterns (notably .cn domains in sender and landing-page URLs), suggesting a single operator or shared kit targeting Japanese-speaking recipients.
Several consumer scam advisories highlight SMS-based fraud alerts that push targets to call attacker-controlled phone numbers, where scammers pose as “support” to steal Apple ID/2FA codes or payment details, or to coerce victims into moving money. One PayPal-themed case escalated to cash withdrawals handed to a courier after a victim called a number from an unsolicited text, illustrating how “fraud department” pretexts can transition from phishing to cash-out theft. Additional warnings cover lookalike payment sites (e.g., payyourbill.aps medical.com) and generic guidance on what to do after clicking a phishing link; these are broadly consistent with the same theme (phishing/payment fraud) but are not tied to a single, specific campaign or actor across all items.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
48 events from the most recent confirmed update back to the earliest known activity.
A Coinbase-themed smishing campaign was reported in which attackers sent fake text messages about unauthorized withdrawals, locked accounts, new logins, or unsolicited OTP/reference codes. The messages used urgency to push recipients to call fraudulent support numbers or click malicious links, with the apparent goal of stealing Coinbase login credentials and two-factor authentication codes.
A smishing campaign was reported in which attackers impersonated Giffgaff through text messages claiming issues such as an inactive SIM, updated terms, or security problems. The messages used malicious or lookalike links to steal bank details, account credentials, and two-step verification codes, with some variants also misusing O2 branding.
A Venmo-themed advance-fee scam targeted marketplace sellers by having fake buyers ask for the seller's email address and then send spoofed Venmo payment notices. The emails falsely claimed funds were on hold until the seller paid an account upgrade or business fee, aiming to steal money and possibly credentials.
A scam campaign was reported in which unsolicited text or WhatsApp messages posing as Warner Bros. Discovery HR offered a remote 'Content Promotion Assistant' job with unrealistic pay, flexible hours, and a large joining bonus. Victims were told to complete simple content-promotion tasks and later pressured to send their own money to 'upgrade' accounts and unlock more tasks or earnings, after which the scammers disappeared.
A scam text campaign was reported in which messages falsely claimed an Apple Pay transaction required confirmation and used urgency to push recipients to click malicious links or call 1-888-593-6001. The apparent goal was to steal personal or financial information by impersonating Apple-related support.
A report published on 2026-06-13 identified mcrev.store as a scam website falsely tied to Aldi that advertised a $750 Aldi gift card and large MacBook discounts. The site allegedly used fake or automated social media promotion to harvest personal and payment information and expose victims to spam, identity theft, unauthorized charges, subscription traps, and fraudulent card use.
A warning published on 2026-06-08 described unsolicited messages from supposed law firms such as 'Kimmel and Rowe' offering to recover inherited, lost, or scammed funds as likely advance-fee fraud. The scam reportedly impersonates attorneys, recovery agencies, or government entities and demands upfront payments labeled as retainers, taxes, or processing fees before any recovery occurs.
A scam campaign was reported in which fraudsters exploited the rollout of children's Trump Accounts by sending phishing emails and text messages. The messages allegedly asked targets to pay fake processing fees to unlock funds or provide sensitive personal information such as Social Security numbers under the guise of speeding up enrollment, while guidance said legitimate activation emails would come only from no-reply@TrumpAccounts.Treasury.gov.
A widespread USPS-themed phishing campaign was reported in which text messages claimed a package could not be delivered due to an incorrect or incomplete address and urged recipients to open a PDF attachment. The PDF linked to a fake USPS website that attempted to steal personal information and payment card details, often by requesting a small redelivery fee.
A PayPal-themed scam was reported in which fake invoice emails falsely claimed a $1,489.99 Bitcoin purchase would be charged through PayPal Auto Pay unless the recipient called 1-656-556-2147. The scammers allegedly impersonated PayPal billing support to trick callers into disclosing account credentials and personal information.
A PayPal-themed phishing scam was reported in which emails falsely claimed a PayPal Business account upgrade request was under review and referenced a $649.00 processing fee, SSN verification, and a June 2, 2026 verification date. Recipients were urged to call 1-888-717-6077, where scammers allegedly impersonated PayPal representatives to steal account credentials and personal information.
An ongoing phishing and smishing campaign was reported that impersonates National Commercial Bank (NCB) with text messages claiming an account has been placed on hold due to unusual activity. The messages direct recipients to the fraudulent site ncbonlinefiles.info, which mimics the bank's portal to steal credentials, personal information, OTPs, PINs, passwords, and RSA token codes.
A warning published on 2026-06-01 identified costcosaved.com as a fraudulent site impersonating Costco. The site was described as part of scams using fake Costco branding to harvest personal information or login credentials, or to sell nonexistent goods and capture payment card data.
A scam campaign was reported in which fraudulent emails claiming to be from BlockFi or Kroll used service.govdelivery.com or public.govdelivery.com-related delivery paths to promote fake estate withdrawal or claim payout messages. The emails were described as leveraging GovDelivery-associated trust to appear legitimate and evade spam filtering while directing recipients toward cryptocurrency fraud.
A scam campaign was reported in which fraudsters impersonated Amazon through calls, texts, or emails claiming an expensive purchase such as a MacBook Pro or iPhone had been made. The messages pressured recipients to contact fake customer service, where scammers attempted to steal credit card or bank details under the guise of canceling the charge or issuing a refund.
An Apple support impersonation scam was reported in which attackers sent alarming messages about suspicious Apple ID activity or Apple Pay charges and then triggered legitimate Apple password reset or support notifications to make the fraud appear credible. Victims were pressured to call fake support numbers or visit cloned sites where scammers attempted to steal Apple ID credentials and two-factor authentication codes.
A scam campaign was reported in which text messages falsely claimed recipients were owed refunds for mis-sold PCP car finance. The messages impersonated car finance lenders, claims firms, or regulatory bodies and used links or replies to steal personal or banking information.
A scam campaign was reported in which fraudsters posing as 'Mayline USA' sent unsolicited text messages and voicemails claiming recipients had been approved for large personal loans. The scam sought sensitive personal information or advance payments through fabricated charges such as processing fees, insurance, or first-month payments.
A phishing campaign was reported in which attackers spoofed the legitimate info@buah.de address of German company buah GmbH to send fraudulent emails themed around Celsius Network payouts, unclaimed Bitcoin balances, remaining crypto funds, and fake order confirmations. The messages reportedly used the trusted buah.de identity to improve credibility and potentially bypass spam filters while attempting to trick recipients into clicking links, opening attachments, or disclosing personal information.
A phishing scam was reported in which fraudulent emails or text messages impersonated Geek Squad and falsely claimed a subscription renewal or imminent large charge. The messages pressured recipients to call a fake support number, where scammers allegedly sought financial information, remote access, malware installation, or refund fraud payments via gift cards or bank transfers.
A widespread scam was reported in which fraudsters impersonated Venmo support by phone or text, claimed unauthorized activity or password changes, and directed victims to press a button or call a hotline. Once engaged, the scammers triggered a real Venmo one-time passcode and tricked victims into reading it aloud, enabling account takeover, credential changes, and theft of funds.
A scam email campaign was reported in which messages falsely claimed recipients had won an 'Elon Musk Mega Millions Jackpot' prize, including money and a Tesla Model X. The emails used fake winner language and codes to induce engagement, with the apparent goal of extracting advance fees, sending fake checks, or stealing personal and banking information.
A fraudulent website, grocerysaved.com, was reported impersonating an Aldi rewards program and falsely promising visitors a $750 gift card. The site allegedly redirected users to other scam offers and collected email addresses and potentially other personal information for spam, follow-on scams, or fraud.
A scam email campaign was reported in which messages impersonating Melio Payments falsely claimed the recipient owed money for a Bitcoin purchase and warned that funds would be withdrawn from their PayPal account within 12 to 24 hours. The alert characterized the emails as fraudulent and advised users to verify account activity only through the official Melio app or meliopayments.com.
A scam campaign was reported in which attackers impersonated CoinSpot through SMS and email messages claiming suspicious logins, unauthorized withdrawals, or unexpected verification codes. The messages urged recipients to call a fake support number, while guidance noted that CoinSpot does not provide phone support and advised users to use only official support channels and account-freezing features.
A scam campaign was reported in which fraudulent online stores impersonated toy company Schylling, especially its NeeDoh product line, to harvest customers' payment card information. Victims reportedly saw payment errors such as declined or unsupported cards, followed by unauthorized attempts to add the stolen card details to Apple Pay or Google Pay; any goods shipped were warned to be potentially counterfeit.
A phishing campaign was reported in which emails impersonating Infomedics claimed recipients had outstanding healthcare bills, typically demanding urgent payment amounts between €115 and €158. The messages reportedly used malicious links or fake payment pages, while guidance noted legitimate Infomedics emails do not include direct iDEAL payment links or attachments and should be verified through official channels.
A Ledger-themed phishing campaign was reported in which spoofed emails, including typo-squatted sender names such as "legder," used fake firmware updates, security alerts, or breach notices to lure users to counterfeit Ledger sites. The scam aimed to steal victims’ 24-word Secret Recovery Phrases, with warnings that follow-up phone calls could be used to reinforce the fraud and enable cryptocurrency theft.
A phishing scam was reported in which fraudulent emails impersonated Norton or LifeLock and falsely claimed an antivirus subscription renewal or charge, typically for roughly $200 to more than $300. The messages urged recipients to call a fake support number or click malicious links in an attempt to steal payment card details, personal information, or potentially deliver malware.
A scam campaign was reported in which attackers impersonated Crypto.com through SMS or email messages claiming unauthorized logins or withdrawals, then directed victims to fraudulent sites or possible follow-up calls posing as support. The scam sought credentials, 2FA verification codes, and anti-phishing codes to enable account compromise and theft.
A warning published on April 26, 2026 described nfeeds.com as a suspicious website copying Lidl branding and allegedly showing denied transactions during checkout. The reported behavior suggested the site was designed to collect payment card information rather than fulfill purchases, with unrealistic pricing cited as an additional fraud indicator.
A scam call campaign was reported in which fraudsters impersonated Kaiser Permanente and spoofed legitimate-looking medical center or billing numbers to pressure targets into disclosing personal or financial information. The callers used pretexts including unpaid bills, insurance problems, identity theft, Medicare issues, or urgent membership cancellation, and some reportedly targeted people with Asian surnames and insisted on speaking Mandarin.
A phishing scam was reported in which fraudulent emails impersonated McAfee and falsely claimed an automatic subscription renewal or purchase charge of about USD559.44 to USD583.66. The messages urged recipients to call 1-810-353-2779 or 1(808)221-2318, where scammers allegedly sought financial information, remote access, or malware delivery through attached fake invoices.
A PayPal-themed scam was reported in which attackers used a real 0.01 MXN or one-cent transaction to make a fraudulent notification appear legitimate, falsely claiming that USD 987.90 was pending deposit to Coinbase via PayPal. The message instructed recipients to call 888-632-2011, where scammers allegedly impersonated PayPal support to steal credentials or banking information.
A phone scam was reported in which fraudsters impersonated Revolut staff, used urgent claims of suspicious account activity, and sometimes spoofed official-looking caller ID information. The scam sought to steal money or sensitive information, while guidance emphasized that Revolut does not make unsolicited calls or ask for PINs, 2FA codes, or transfers to so-called safe accounts.
A scam campaign was reported in which attackers impersonated Robinhood through text messages and emails claiming unusual activity, anomalies, or account freezes. The messages used malicious links or fake support numbers to steal usernames, passwords, and other sensitive account information or facilitate financial theft.
A PayPal scam variant was reported that used Philippine Peso transactions, including tiny 1 PHP deposits and fake alerts about large unauthorized charges such as 20,000 PHP, to lure victims into calling fraudulent support numbers or visiting phishing pages. The campaign reportedly aimed to steal credentials and drain funds, with some stolen money transferred to GCash.
A phishing scam was reported in which fraudsters impersonated parcel company Evri via text messages claiming failed delivery, incomplete address details, or a small redelivery fee. The messages used urgency and phishing links to steal personal or payment information, while Evri stated it does not request such details or fees by SMS.
A PayPal-themed email scam was reported in which recipients received fake invoices or order confirmations as PDF attachments claiming a transaction needed to be reversed. The messages used unauthorized-payment scare tactics to pressure targets into calling a fraudulent support number so scammers could steal personal or payment information.
A Bank of America impersonation phone scam was reported in which fraudsters spoofed official-looking bank numbers and falsely claimed fraudulent account activity to pressure victims. The callers attempted to obtain PINs, Social Security numbers, account numbers, one-time authentication codes, or convince targets to send money through Zelle, cryptocurrency, or gift cards.
A scam campaign was reported in which fraudsters impersonated DPD through SMS, email, and marketplace messages, commonly claiming a missed parcel delivery and directing victims to pay a small redelivery fee on lookalike sites to steal personal and banking data. The reporting also described related variants involving fake DPD collection arrangements on Facebook Marketplace and bogus courier insurance or service fees.
A phone-based scam was reported in which fraudulent emails impersonating PayPal's billing department falsely claimed a $349.99 auto-debit charge and told recipients to call 1-808-371-1635 if the payment was unauthorized. Callers were reportedly routed to a scam call center where operators impersonated Norton and other technology companies to steal sensitive information or gain device access.
A PayPal-themed social engineering scam was reported in which attackers sent a real 2-cent PayPal transaction and a message claiming a payout had been processed, then directed victims to call 1-800-613-9844. The goal was to impersonate PayPal support and steal account or banking information over the phone.
An active scam campaign was documented that redirected users from seemingly legitimate survey links to fake Bitcoin compensation pages promising large payouts, then demanded small commission payments before withdrawal. A second variant impersonated Octa with a fake transfer notification and OTP-style flow before requesting a similar fee.
A PayPal fraud impersonation scam was reported in which a victim received an unsolicited text, called the provided number, and was manipulated into withdrawing thousands of dollars in cash for collection by a courier. The scammers later attempted to extract additional funds, using spoofed identities and urgency to pressure the victim.
A smishing campaign was reported in which recipients received text messages posing as Apple Security Alert or Apple Support notices about unauthorized Apple Pay transactions and were urged to call a phone number. The messages were described as fraudulent attempts to harvest sensitive information through social engineering.
Three phishing emails observed in February 2026 shared similar header artifacts, including the same Foxmail X-mailer string, suggesting a common operator or toolkit behind the Japanese-brand impersonation campaign. The samples reinforced the pattern of .cn-linked infrastructure across multiple lures.
Bradley Duncan reported that he had been receiving Japanese-language phishing emails targeting his @malware-traffic-analysis.net addresses for at least the past year. The messages impersonated brands including ANA, DHL, and myTOKYOGAS and used recurring .cn sender domains and .cn-hosted phishing URLs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
50 references tracked. Mallory keeps watching after this page renders.
onlinethreatalerts.com
Open sourceonlinethreatalerts.com
Open sourceonlinethreatalerts.com
Open sourceonlinethreatalerts.com
Open sourceonlinethreatalerts.com
Open sourceonlinethreatalerts.com
Open sourceonlinethreatalerts.com
Open sourceonlinethreatalerts.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.