PrivacySignal
Breach

‘We detected unusual activity’: the scam that uses AI to exploit your holiday photos

The Guardian — Tech · · International · Data Breaches

Scammers are harvesting location details from holiday photos posted on Instagram and Facebook, then using that information to craft convincing phishing messages that reference specific places and trips to trick people into handing over bank details.

Why this matters: Posting a holiday photo feels harmless. This shows it can be raw material for a targeted scam. The detail that makes the message convincing — the city, the timing, the trip — came from you. AI makes it cheaper and faster to turn that public data into personalized fraud at scale. You do not have to do anything wrong to become a target. The simplest fix is limiting who can see your posts, but most people never touch those settings.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
The Guardian — Tech · · International

AI cheating, leaked papers and marking errors: how exam protests went global

Student protests over exam integrity have spread across multiple countries this year, with incidents including mass exam resits in Mexico following suspected cheating affecting nearly 60,000 applicants, and a failed digital marking rollout in Portugal that triggered a serious education crisis.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
DataBreaches.net · · International

NC: Possible cyberattack hits Wake election software vendor, leaving poll workers’ data exposed

Wake County, North Carolina has suspended its use of an elections software vendor following a possible cyberattack. Election officials say voting machines, ballots, voter registration data, and vote-counting systems were not affected, but information about poll workers may have been exposed.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

Time ran out for victims; CRPx0 puts data up for sale

CRPx0 made the news last month for its somewhat novel approach of offering free OnlyFans accounts to get victims to click links that would deploy its malware. Since August 7, when it launched a leak site on both the clear net and dark web, CRPx0 has listed 47 victims that did not pay its extortion... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
DataBreaches.net · · International

UK: ICO reprimands ACRO Criminal Records Office after data breach

The UK Information Commissioner's Office has formally reprimanded ACRO Criminal Records Office for violating UK GDPR security requirements following a data breach. ACRO is a national police unit that handles sensitive records including criminal history, Police Certificates, and International Child Protection Certificates.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · AI governance

#breach#gdpr Read original →
Breach
DataBreaches.net · · International

KR: Sogang University data breach exposes 180,000 student, staff accounts

Sogang University in South Korea disclosed a cyberattack that exposed personal data linked to roughly 180,000 students, alumni, and staff accounts. The university confirmed the breach involved its integrated login system, with an unidentified outside party responsible.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →
Breach
DataBreaches.net · · International

CISA Unveils New Cybersecurity Resources for K-12 Schools and Districts

A recent report claims ransomware attacks on K-12 are down for the first half of 2026, while another news story’s headline today claims schools are becoming a new cybersecurity battleground. New? We don’t think it’s new. But the education sector has long been characterized as providing low-hanging fruit for criminals, and recent attacks on edtech... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →