Phishing
Theft of personal data, passwords, and account access through fake websites and malicious messages.
Group-IB researchers uncovered a large-scale smishing operation known as Error544. The campaign targeted users in 72 countries, abused the names of more than 260 brands, and relied on thousands of phishing domains to steal personal and financial information. In this video, we explain how the scheme worked, what tactics the attackers used, and how users can verify suspicious links before visiting a website.
Scammers actively exploit interest in football and major sporting events by creating fake FIFA websites. In this video, we explain how to identify fraudulent websites, what information scammers try to obtain, and what steps can help protect your personal and financial data.
ИИ уже умеет собирать информацию о человеке из открытых соцсетей и использовать её для персонализированного фишинга.
Достаточно нескольких постов, чтобы мошенническое сообщение выглядело убедительно и “именно под вас”.
Будьте внимательны: не переходите по подозрительным ссылкам, ограничивайте публичность профиля и включайте двухфакторную защиту.
Fraudsters use the names and logos of well-known companies to offer “bonuses” on Telegram and then gain access to users’ accounts.
In this post, we explain how this scheme works, how scammers take control of Telegram accounts, and provide practical recommendations to strengthen your account security and protect your personal data.
Scammers were sending phishing SMS messages on a massive scale using so-called SMS blasters — devices that imitate cellular base stations.
These devices forced nearby phones to connect to a less secure network, allowing attackers to bypass telecom operators' protections and send up to 100,000 messages per hour.
A group of suspects has been detained in connection with the case.
17,5 миллионнан астам Instagram пайдаланушысының деректері таралғаны туралы ақпарат тарауда.
Аты-жөндер, электрондық пошта мекенжайлары мен телефон нөмірлері фишингтік шабуылдар мен аккаунттарды бұзу әрекеттерінде пайдаланылуы мүмкін.
Құпиясөзіңізді өзгертіңіз, екі факторлы аутентификацияны қосыңыз және күмәнді сілтемелерге өтпеңіз.
On November 9, 2025, a data security incident occurred at Mixpanel, an analytics service previously used by OpenAI for web analytics.
According to OpenAI, this was not a breach of OpenAI's own systems. Passwords, API keys, payment information, chats, prompts and responses were not exposed.
However, attackers may have obtained account names, email addresses, approximate locations, browser and operating system details, referral sources, as well as user or organization IDs.
The main risk associated with this type of exposure is phishing and more convincing fraudulent messages impersonating trusted services. OpenAI stated that it has stopped using Mixpanel and is notifying affected users.
The Astana Cyber Police and CTS have warned about fake advertisements promoting supposedly discounted travel cards valid for six months for 1,250 tenge.
According to CTS, this information is false: such travel cards do not exist, and the advertisements redirect users to suspicious websites.
The purpose of these campaigns is to steal users' personal and banking information.
A data breach occurred at Discord following an attack on a contractor responsible for processing customer support requests.
The attackers may have gained access to support tickets, attached files and certain personal information belonging to users who contacted support.
Users who submitted documents, photographs, account information or other personal data may be at particular risk.
This material explains what information may have been exposed, why two-factor authentication is important and how to review your active sessions for suspicious activity.
Starting October 4, new rules for connecting to public internet networks will take effect in Kazakhstan.
Users will be able to authenticate in one of two ways: by entering a one-time SMS password sent to their phone number or by using a digital signature.
The changes are intended to improve security when using public Wi-Fi networks, which may pose risks to privacy, finances and personal data.
At the same time, questions remain about who will identify and shut down malicious Wi-Fi hotspots designed to steal digital signatures and other user data.