PrivacySignal
Breach

‘We detected unusual activity’: the scam that uses AI to exploit your holiday photos

The Guardian — Tech · · International · Data Breaches

Scammers are harvesting location details from holiday photos posted on Instagram and Facebook, then using that information to craft convincing phishing messages that reference specific places and trips to trick people into handing over bank details.

Why this matters: Posting a holiday photo feels harmless. This shows it can be raw material for a targeted scam. The detail that makes the message convincing — the city, the timing, the trip — came from you. AI makes it cheaper and faster to turn that public data into personalized fraud at scale. You do not have to do anything wrong to become a target. The simplest fix is limiting who can see your posts, but most people never touch those settings.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

The Attacker Did Not Need to Sleep

Spain received its first reported personal-data breach carried out by an AI agent. The techniques were familiar. The speed and autonomy were not.

· 4 min read Read →

Related stories

Breach
HIPAA Journal · · US Federal

DC Medicaid Agency Notifies 400,000 Beneficiaries About Data Exposure

Washington DC's Medicaid agency has notified nearly 400,000 beneficiaries that their personal and protected health information was exposed online. The agency has not yet disclosed how the exposure occurred or how long the data was accessible.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach Critical
BleepingComputer · · International

Bitget hacked via zero-day in third-party security products

Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
CyberScoop · · US Federal

WaterISAC reckons with range of threats after summer of cyberattacks

Internet-exposed tech, PLCs, outside integrators and inside protections are all factors the water sector’s information sharing and analysis center is watching. The post WaterISAC reckons with range of threats after summer of cyberattacks appeared first on CyberScoop.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

Data breach incident targets prisoner medical records at 2 Mass. jails

A cybersecurity incident has compromised the electronic health record system used at two Suffolk County jails in Massachusetts. The system provider, Computer Systems Integrated Inc., confirmed it is investigating the breach, which exposed prisoner medical and health data stored on its EHRs-C platform.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
BleepingComputer · · International

Former US Air Force members sent to prison over BEC attacks

Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →