<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:atom="http://www.w3.org/2005/Atom"
    xmlns:media="http://search.yahoo.com/mrss/">
    <channel><title>Consumer Insights</title><description>News, views and insights from the Bitdefender experts</description><link>https://www.bitdefender.com/en-gb/blog/hotforsecurity/</link><image><url>https://download.bitdefender.com/resources/images/favicon/favicon-32x32.png</url><title>Consumer Insights</title><link>https://www.bitdefender.com/en-gb/blog/hotforsecurity/</link></image><generator>Bitdefender Blog</generator><lastBuildDate>Tue, 28 Apr 2026 22:56:09 GMT</lastBuildDate><atom:link href="https://www.bitdefender.com/nuxt/api/en-gb/rss/hotforsecurity/industry-news/" rel="self" type="application/rss+xml"/><ttl>1800</ttl><item><title>Social Media Scams Cost Americans $2.1 Billion in 2025, FTC Warns</title><description><![CDATA[Social media has become a cash cow for scammers. New data from the U.S. Federal Trade Commission (FTC) reveals a surge in fraud linked to social platforms, with consumers reporting $2.1 billion in losses in 2025 alone.


Key takeaways:


 * Social media scams inflicted $2.1 billion in reported losses in 2025
 * Nearly 1 in 3 scam victims said the fraud started on a social platform
 * Losses have grown eight-fold since 2020
 * Investment scams caused the biggest financial damage
 * Shopping scams]]></description><link>https://www.bitdefender.com/en-gb/blog/hotforsecurity/social-media-scams-2-1-billion-2025-ftc</link><guid isPermaLink="false">69f073d32fa53a9f2eef68a3</guid><category><![CDATA[Industry News]]></category><category><![CDATA[Scam]]></category><dc:creator>Filip TRUȚĂ</dc:creator><pubDate>Tue, 28 Apr 2026 08:49:50 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/04/header-social-media-scams-2-1-billion-2025-FTC.png" medium="image"/><content:encoded><![CDATA[Social media has become a cash cow for scammers. New data from the U.S. Federal Trade Commission (FTC) reveals a surge in fraud linked to social platforms, with consumers reporting $2.1 billion in losses in 2025 alone.


Key takeaways:


 * Social media scams inflicted $2.1 billion in reported losses in 2025
 * Nearly 1 in 3 scam victims said the fraud started on a social platform
 * Losses have grown eight-fold since 2020
 * Investment scams caused the biggest financial damage
 * Shopping scams]]></content:encoded></item><item><title>French police arrest 21-year-old "HexDex" hacker over 100 alleged data breaches</title><description><![CDATA[A 21-year-old man suspected of conducting approximately 100 data breaches since late 2025 - including a hack of the French Ministry of National Education that exposed records on almost a quarter of a million employees — has been arrested at his home in western France.

According to French prosecutors, the man was reportedly preparing to dump yet another collection of stolen data online at the time of his arrest on 20 April, and has admitted to using the pseudonym "HexDex" online.

The police inv]]></description><link>https://www.bitdefender.com/en-gb/blog/hotforsecurity/french-police-arrest-hexdex-hacker</link><guid isPermaLink="false">69f05d6c2fa53a9f2eef6882</guid><category><![CDATA[Industry News]]></category><dc:creator>Graham CLULEY</dc:creator><pubDate>Tue, 28 Apr 2026 07:11:46 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/04/hexdex.jpeg" medium="image"/><content:encoded><![CDATA[A 21-year-old man suspected of conducting approximately 100 data breaches since late 2025 - including a hack of the French Ministry of National Education that exposed records on almost a quarter of a million employees — has been arrested at his home in western France.

According to French prosecutors, the man was reportedly preparing to dump yet another collection of stolen data online at the time of his arrest on 20 April, and has admitted to using the pseudonym "HexDex" online.

The police inv]]></content:encoded></item><item><title>iOS Flaw Exposes ‘Deleted’ Message Data Through Notifications – Patch Now! (iOS 26.4.2 and iOS 18.7.8)</title><description><![CDATA[Apple has rolled out emergency security updates to fix a privacy flaw that allowed “deleted” notification data—including message previews from encrypted apps like Signal—to persist on iPhones and be recovered later.

The issue, now patched in iOS 26.4.2 and older supported versions, drew attention after reports that U.S. investigators were able to extract supposedly deleted Signal messages from a suspect’s device—not by breaking encryption, but by accessing the iPhone’s notification database.


]]></description><link>https://www.bitdefender.com/en-gb/blog/hotforsecurity/ios-flaw-exposes-deleted-messages-signal-iphone-fbi</link><guid isPermaLink="false">69ea16ac2fa53a9f2eef6671</guid><category><![CDATA[Industry News]]></category><category><![CDATA[Mobile Security]]></category><dc:creator>Filip TRUȚĂ</dc:creator><pubDate>Thu, 23 Apr 2026 13:01:06 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/04/iphone-deleted-messages.jpg" medium="image"/><content:encoded><![CDATA[Apple has rolled out emergency security updates to fix a privacy flaw that allowed “deleted” notification data—including message previews from encrypted apps like Signal—to persist on iPhones and be recovered later.

The issue, now patched in iOS 26.4.2 and older supported versions, drew attention after reports that U.S. investigators were able to extract supposedly deleted Signal messages from a suspect’s device—not by breaking encryption, but by accessing the iPhone’s notification database.


]]></content:encoded></item><item><title>Sony Starts Enforcing PlayStation Age Verification; UK and Ireland Are First</title><description><![CDATA[Sony will soon require users in the UK and Ireland to complete age verification to access certain features. The new security measures are optional at first, but will be enforced later in 2026.]]></description><link>https://www.bitdefender.com/en-gb/blog/hotforsecurity/sony-playstation-age-verification-uk-ireland</link><guid isPermaLink="false">69e8dc5c2fa53a9f2eef658b</guid><category><![CDATA[Industry News]]></category><dc:creator>Silviu STAHIE</dc:creator><pubDate>Wed, 22 Apr 2026 14:37:29 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/04/50eba233-4103-47d9-aae1-59ad9dc7b317.png" medium="image"/><content:encoded><![CDATA[Sony will soon require users in the UK and Ireland to complete age verification to access certain features. The new security measures are optional at first, but will be enforced later in 2026.]]></content:encoded></item><item><title>Ransomware ‘Negotiator’ Faces 20 Years in Prison for Allegedly Betraying His Employers</title><description><![CDATA[A Florida man who allegedly worked as a ransomware negotiator has pleaded guilty to conspiring with cybercriminals to carry out ransomware attacks against U.S. organizations—while simultaneously advising victims on how to respond.


Key takeaways:


 * A ransomware negotiator has pleaded guilty to secretly working with the BlackCat (ALPHV) ransomware crew
 * He is accused of sharing sensitive client data to help hackers maximize ransom payments
 * The insider also allegedly helped deploy ransomw]]></description><link>https://www.bitdefender.com/en-gb/blog/hotforsecurity/ransomware-negotiator-20-years-prison</link><guid isPermaLink="false">69e8b2882fa53a9f2eef655e</guid><category><![CDATA[Industry News]]></category><dc:creator>Filip TRUȚĂ</dc:creator><pubDate>Wed, 22 Apr 2026 11:43:17 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/04/ransomware-negotator-header.png" medium="image"/><content:encoded><![CDATA[A Florida man who allegedly worked as a ransomware negotiator has pleaded guilty to conspiring with cybercriminals to carry out ransomware attacks against U.S. organizations—while simultaneously advising victims on how to respond.


Key takeaways:


 * A ransomware negotiator has pleaded guilty to secretly working with the BlackCat (ALPHV) ransomware crew
 * He is accused of sharing sensitive client data to help hackers maximize ransom payments
 * The insider also allegedly helped deploy ransomw]]></content:encoded></item><item><title>You’ve Got Mail and It’s Tracking Your Warship</title><description><![CDATA[Dutch journalists have figured out an ingenious way of discovering the location of a warship by using a simple Bluetooth tracker, thus exposing a vulnerability in the military operation and forcing the armed forces to reconsider their protocols.]]></description><link>https://www.bitdefender.com/en-gb/blog/hotforsecurity/mail-tracking-dutch-warship</link><guid isPermaLink="false">69e74fda2fa53a9f2eef6429</guid><category><![CDATA[Industry News]]></category><dc:creator>Silviu STAHIE</dc:creator><pubDate>Tue, 21 Apr 2026 10:39:57 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/04/b8ef65dc-485b-4abf-b3c0-3aaceefc7f13.png" medium="image"/><content:encoded><![CDATA[Dutch journalists have figured out an ingenious way of discovering the location of a warship by using a simple Bluetooth tracker, thus exposing a vulnerability in the military operation and forcing the armed forces to reconsider their protocols.]]></content:encoded></item><item><title>Crypto Investment Scam Costs Woman in Hong Kong Nearly $1 Million</title><description><![CDATA[A woman from Hong Kong lost nearly $1 million in a crypto scam that promised “AI-powered trading.”

Her story, as shocking as it may be, is a clear sign of how scams are evolving and why it’s more important than ever to stay informed.


 Key takeaways

 * A Hong Kong woman lost HK$7.7 million ($982,000) after being lured into an “AI crypto trading” scam
 * Scammers used Telegram and fake platforms to build trust and simulate profits
 * 17 transactions were made before the victim realized somethi]]></description><link>https://www.bitdefender.com/en-gb/blog/hotforsecurity/crypto-investment-scam-hong-kong</link><guid isPermaLink="false">69e66f242fa53a9f2eef63a9</guid><category><![CDATA[Scam]]></category><category><![CDATA[Industry News]]></category><dc:creator>Alina BÎZGĂ</dc:creator><pubDate>Mon, 20 Apr 2026 18:36:50 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/04/Crypto-Investment-Scam-Costs-Woman-in-Hong-Kong-Nearly--1-Million.jpg" medium="image"/><content:encoded><![CDATA[A woman from Hong Kong lost nearly $1 million in a crypto scam that promised “AI-powered trading.”

Her story, as shocking as it may be, is a clear sign of how scams are evolving and why it’s more important than ever to stay informed.


 Key takeaways

 * A Hong Kong woman lost HK$7.7 million ($982,000) after being lured into an “AI crypto trading” scam
 * Scammers used Telegram and fake platforms to build trust and simulate profits
 * 17 transactions were made before the victim realized somethi]]></content:encoded></item><item><title>Operation PowerOFF warns 75,000 DDoS users as 53 domains go dark</title><description><![CDATA[Europol-backed Operation PowerOFF warned 75,000 users, seized 53 domains, and widened the crackdown on DDoS-for-hire services.]]></description><link>https://www.bitdefender.com/en-gb/blog/hotforsecurity/operation-poweroff-75-000-ddos-users</link><guid isPermaLink="false">69e1f9da2fa53a9f2eef61bd</guid><category><![CDATA[Industry News]]></category><dc:creator>Vlad CONSTANTINESCU</dc:creator><pubDate>Fri, 17 Apr 2026 09:16:25 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/04/compagnons-EJe6LqEjHpA-unsplash-1.jpg" medium="image"/><content:encoded><![CDATA[Europol-backed Operation PowerOFF warned 75,000 users, seized 53 domains, and widened the crackdown on DDoS-for-hire services.]]></content:encoded></item><item><title>Singer loses life savings to fake wallet downloaded from the Apple App Store</title><description><![CDATA[If you hold cryptocurrency, there's a very simple golden rule that you should always follow. Never hand over your seed phrase.

Garrett Dutton, better known as G. Love - the front man of blues-hip-hop outfit G. Love & Special Sauce - has learnt that lesson the hard way.

In what must have been a painful admission earlier this month, G. Love described how while setting up a new computer, he downloaded what he believed was the legitimate Ledger Live app from Apple's official App Store.

The bogus ]]></description><link>https://www.bitdefender.com/en-gb/blog/hotforsecurity/singer-loses-life-savings-fake-wallet</link><guid isPermaLink="false">69e1dd0b2fa53a9f2eef609c</guid><category><![CDATA[Industry News]]></category><category><![CDATA[Scam]]></category><dc:creator>Graham CLULEY</dc:creator><pubDate>Fri, 17 Apr 2026 07:12:02 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/04/fake-app.jpeg" medium="image"/><content:encoded><![CDATA[If you hold cryptocurrency, there's a very simple golden rule that you should always follow. Never hand over your seed phrase.

Garrett Dutton, better known as G. Love - the front man of blues-hip-hop outfit G. Love & Special Sauce - has learnt that lesson the hard way.

In what must have been a painful admission earlier this month, G. Love described how while setting up a new computer, he downloaded what he believed was the legitimate Ledger Live app from Apple's official App Store.

The bogus ]]></content:encoded></item><item><title>AgingFly malware hits local authorities and hospitals in Ukraine</title><description><![CDATA[CERT-UA links a new credential-stealing campaign to phishing, browser theft and modular remote access.


Phishing lure initial vector

Ukraine’s national cyber response team (CERT-UA) has uncovered a new malware family, dubbed AgingFly, in attacks on local government bodies and hospitals. Forensic evidence suggests some Defense Forces representatives may also have been targeted. CERT-UA tracks the activity under the UAC-0247 cluster.

According to the incident report, the campaign begins with em]]></description><link>https://www.bitdefender.com/en-gb/blog/hotforsecurity/agingfly-malware-ukraine</link><guid isPermaLink="false">69e0e52b2fa53a9f2eef6085</guid><category><![CDATA[Industry News]]></category><category><![CDATA[Ukraine]]></category><dc:creator>Vlad CONSTANTINESCU</dc:creator><pubDate>Thu, 16 Apr 2026 13:36:48 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/04/ed-hardie-1C5F88Af9ZU-unsplash.jpg" medium="image"/><content:encoded><![CDATA[CERT-UA links a new credential-stealing campaign to phishing, browser theft and modular remote access.


Phishing lure initial vector

Ukraine’s national cyber response team (CERT-UA) has uncovered a new malware family, dubbed AgingFly, in attacks on local government bodies and hospitals. Forensic evidence suggests some Defense Forces representatives may also have been targeted. CERT-UA tracks the activity under the UAC-0247 cluster.

According to the incident report, the campaign begins with em]]></content:encoded></item><item><title>108 malicious Chrome extensions caught stealing Google and Telegram data from 20,000 users</title><description><![CDATA[What looked like harmless Chrome add-ons for Telegram, YouTube, TikTok, translation, or casual games were in fact part of a coordinated data-theft campaign affecting roughly 20,000 users. The case is another reminder that malicious browser extensions can quietly siphon credentials, hijack sessions, and tamper with web traffic even when they are downloaded from an official store.


Key Takeaways

 * Researchers identified 108 malicious Chrome extensions tied to a single command-and-control infras]]></description><link>https://www.bitdefender.com/en-gb/blog/hotforsecurity/malicious-chrome-extensions-steal-google-telegram-data</link><guid isPermaLink="false">69df6d5c2fa53a9f2eef604f</guid><category><![CDATA[Industry News]]></category><dc:creator>Graham CLULEY</dc:creator><pubDate>Wed, 15 Apr 2026 10:54:29 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/04/extensions.jpeg" medium="image"/><content:encoded><![CDATA[What looked like harmless Chrome add-ons for Telegram, YouTube, TikTok, translation, or casual games were in fact part of a coordinated data-theft campaign affecting roughly 20,000 users. The case is another reminder that malicious browser extensions can quietly siphon credentials, hijack sessions, and tamper with web traffic even when they are downloaded from an official store.


Key Takeaways

 * Researchers identified 108 malicious Chrome extensions tied to a single command-and-control infras]]></content:encoded></item><item><title>Rockstar Games confirms breach after ShinyHunters leaks stolen analytics data</title><description><![CDATA[Rockstar Games says a third-party breach exposed internal analytics data after ShinyHunters linked the incident to Anodot and Snowflake.]]></description><link>https://www.bitdefender.com/en-gb/blog/hotforsecurity/rockstar-games-data-breach</link><guid isPermaLink="false">69de05b62fa53a9f2eef5f71</guid><category><![CDATA[Industry News]]></category><category><![CDATA[Data Breach]]></category><dc:creator>Vlad CONSTANTINESCU</dc:creator><pubDate>Tue, 14 Apr 2026 09:23:44 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/04/Rockstar-Games-confirms-data-breach.jpg" medium="image"/><content:encoded><![CDATA[Rockstar Games says a third-party breach exposed internal analytics data after ShinyHunters linked the incident to Anodot and Snowflake.]]></content:encoded></item><item><title>FBI: Cybercrime Losses Hit a Record $21 Billion Last Year, Fueled by AI</title><description><![CDATA[Americans reported losing $20.9 billion to cybercrime in 2025—much of it to AI-enabled scams.

The FBI’s latest Internet Crime Complaint Center (IC3) report reveals that cybercrime losses in the U.S. surged to nearly $21 billion in 2025, setting a new record and marking a dramatic jump from the already staggering $16.6 billion reported for 2024.

Scams are becoming more sophisticated, more scalable, and far more profitable than ever.


Key takeaways


 * Cybercrime losses reached ~$21 billion in]]></description><link>https://www.bitdefender.com/en-gb/blog/hotforsecurity/fbi-cybercrime-losses-21-billion-2025-ai</link><guid isPermaLink="false">69d66ba32fa53a9f2eef5e88</guid><category><![CDATA[Industry News]]></category><dc:creator>Filip TRUȚĂ</dc:creator><pubDate>Wed, 08 Apr 2026 14:59:32 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/04/header-cybercrime-losses-2025-FBI-1.png" medium="image"/><content:encoded><![CDATA[Americans reported losing $20.9 billion to cybercrime in 2025—much of it to AI-enabled scams.

The FBI’s latest Internet Crime Complaint Center (IC3) report reveals that cybercrime losses in the U.S. surged to nearly $21 billion in 2025, setting a new record and marking a dramatic jump from the already staggering $16.6 billion reported for 2024.

Scams are becoming more sophisticated, more scalable, and far more profitable than ever.


Key takeaways


 * Cybercrime losses reached ~$21 billion in]]></content:encoded></item><item><title>Life imprisonment for Cambodian scam compound operators - but will it make a difference?</title><description><![CDATA[Cambodia has taken a dramatic step in its fight against scam compounds that have imprisoned innocent people, and forced them to work as virtual slaves defrauding victims via the internet around the world with romance scams and dodgy investment schemes.

But with Amnesty International simultaneously revealing that state-licensed casinos are directly linked to torture and trafficking, serious questions linger about whether enforcement will match the rhetoric.

Cambodia's Law on Combating Online Sc]]></description><link>https://www.bitdefender.com/en-gb/blog/hotforsecurity/life-imprisonment-cambodian-scam-operators</link><guid isPermaLink="false">69d4aa682fa53a9f2eef5d2c</guid><category><![CDATA[Industry News]]></category><category><![CDATA[Scam]]></category><dc:creator>Graham CLULEY</dc:creator><pubDate>Tue, 07 Apr 2026 06:56:43 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/04/compound.jpeg" medium="image"/><content:encoded><![CDATA[Cambodia has taken a dramatic step in its fight against scam compounds that have imprisoned innocent people, and forced them to work as virtual slaves defrauding victims via the internet around the world with romance scams and dodgy investment schemes.

But with Amnesty International simultaneously revealing that state-licensed casinos are directly linked to torture and trafficking, serious questions linger about whether enforcement will match the rhetoric.

Cambodia's Law on Combating Online Sc]]></content:encoded></item><item><title>Fake Claude code leak on GitHub pushes Vidar malware</title><description><![CDATA[Fake Claude Code leak repos on GitHub are pushing Vidar malware at people hunting for Anthropic’s exposed source code.]]></description><link>https://www.bitdefender.com/en-gb/blog/hotforsecurity/claude-code-leak-github-vidar-malware</link><guid isPermaLink="false">69cfb0462fa53a9f2eef5c79</guid><category><![CDATA[Industry News]]></category><dc:creator>Vlad CONSTANTINESCU</dc:creator><pubDate>Fri, 03 Apr 2026 12:21:40 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/04/xavier-cee-genkxag3nY4-unsplash.jpg" medium="image"/><content:encoded><![CDATA[Fake Claude Code leak repos on GitHub are pushing Vidar malware at people hunting for Anthropic’s exposed source code.]]></content:encoded></item></channel>
        </rss>