Posted on

Security-alert fatigue exploited by repeated fraudulent notifications

Security warnings are supposed to interrupt routine behavior.

The problem begins when interruption becomes routine behavior.

Microsoft describes “push-bombing” or MFA-fatigue attacks in which an attacker repeatedly triggers authentication requests to a victim’s device. The victim is expected to deny the requests. The attacker is betting that enough buzzing, tapping, and confusion will eventually produce one accidental or exhausted approval.

See Microsoft’s security guidance on push-bombing and credential attacks.

Microsoft later reported observing roughly 6,000 MFA-fatigue attempts per day by the end of June 2023 and described repeated notifications as a social-engineering technique that can overwhelm or distract users.

See Microsoft’s guidance on protecting credentials from social engineering.

The attacker turns a safeguard into noise

An unexpected authentication prompt is useful because it tells the user that someone is attempting to sign in.

Twenty unexpected prompts create a different psychological problem.

The user may start treating them as background noise, assume the system is malfunctioning, or approve one simply to make the interruption disappear. That is alert fatigue: the warning remains technically visible while its ability to command careful attention declines.

This is not limited to authenticator apps. Fraudulent security emails, password-reset notices, browser warnings, and fake account alerts can all benefit from the same exhaustion if users are conditioned to click through warning after warning.

Do not resolve an unexpected alert through the alert itself

If you receive an authentication request you did not initiate, deny it.

Then open the account or security dashboard through a known route and inspect recent sign-in activity. Change a compromised password if appropriate, review active sessions, and use stronger authentication options the provider supports.

Microsoft has pushed number matching and phishing-resistant authentication partly because a simple Approve button is easier to abuse through repeated prompting.

See Microsoft’s phishing-resistant MFA guidance.

The important habit is to separate notification from action.

A warning can tell you something may be wrong.

It should not automatically decide what you click next.

The scammer wants the hundredth alert to receive less thought than the first.

Security only works if the hundredth one still gets checked.

Posted on

False copyright complaints that pressure creators into dangerous actions

A copyright complaint has one feature scammers love: creators are supposed to take it seriously.

For someone whose income, audience, archive, or reputation depends on a platform account, the words copyright strike can create exactly the urgency a phishing campaign needs.

In April 2026, Malwarebytes documented a campaign sending YouTube creators fake copyright-strike notices. The fraudulent pages pulled real channel information into the lure and then directed creators toward a fake Google sign-in flow intended to steal account access.

See Malwarebytes’ report on fake YouTube copyright notices.

The threat works because the underlying consequence is real.

YouTube says a valid copyright removal request can remove content and apply a copyright strike. Three active copyright strikes within 90 days can put a channel at risk of termination.

See YouTube’s copyright strike documentation.

The scam inserts itself between the warning and the response

A creator who believes a channel is in immediate danger may click a case-review link, download supposed evidence, reply to a fake claimant, or enter credentials into a page that looks like Google.

The safest question is not whether the email sounds legally serious.

It is whether the claimed enforcement action exists inside the platform’s actual system.

YouTube says copyright strikes are visible in YouTube Studio, where creators can review the affected content and the strike’s status. Official strike notifications also come through YouTube’s documented process.

A message that claims catastrophic enforcement but leaves no corresponding record in Studio deserves suspicion.

Use the platform’s process, not the sender’s emergency route

If a strike is real, YouTube documents the legitimate options: wait for expiration after Copyright School where applicable, request a retraction, or submit a valid counter notification when the removal was mistaken or otherwise eligible.

Those processes exist independently of whatever link appeared in an alarming email.

See YouTube’s guidance on counter notifications.

That separation is useful beyond YouTube.

A genuine legal or platform notice should be verifiable through the platform’s own dashboard, help center, case system, or established legal process.

The scammer wants the creator to react to the threat before checking whether the threat exists.

The creator’s fear is real.

The strike may not be.

Posted on

Impersonated government notices that demand immediate payment

A fake government notice does not need to survive a legal review.

It needs to frighten someone for five minutes.

Scammers imitate agencies because official authority changes how a message feels. A seal, case number, court date, tax balance, arrest threat, or suspended-license warning can make an ordinary payment request feel like an instruction rather than a decision.

The Internal Revenue Service lists several warning signs of impersonation. An unexpected contact that rushes or threatens the recipient, demands immediate payment, or asks for personal or financial information should be treated with suspicion.

See the IRS’s tax scam guidance and explanation of how the IRS normally contacts taxpayers.

Procedure is harder to fake than a logo

The IRS says it normally makes first contact by U.S. mail. It does not use social-media direct messages to initiate tax business, and an unexpected phone call, email, or text demanding payment now is not how a legitimate tax obligation should be verified.

The broader pattern appears outside taxes as well.

In April 2026, the FTC warned about texts containing official-looking traffic-hearing notices with seals, fake case numbers, deadlines, and QR codes. The messages threatened consequences unless recipients scanned the code and paid a supposed balance.

See the FTC’s warning about fake traffic-violation notices.

The design is meant to collapse the time available for checking.

Verify the agency without using the notice

If a government demand might be real, the message itself should not be the only route to confirming it.

Find the agency’s website independently. Look up the case, notice, or account through the official system. Call a verified number from the agency’s website rather than one printed in the suspicious message.

Do not assume that a seal, employee name, badge number, official vocabulary, or correct personal detail proves authenticity. Much of that information can be copied.

A real government agency has procedures that exist outside one alarming email or text.

That is the scammer’s weakness.

The fake notice wants the victim to believe there is only one path forward and it expires in ten minutes.

Real bureaucracy is many things.

It is rarely that efficient.

Posted on

Fake document shares used to create urgency around a login

“A document has been shared with you” is one of the least suspicious sentences in modern office work.

That is why it makes such a useful phishing lure.

Microsoft documented campaigns in 2024 that abused legitimate file-hosting services including OneDrive, SharePoint, and Dropbox. In some cases, the notification itself was genuine because the attacker had actually shared a file through the service. The malicious step came later, after the recipient opened the file and followed another link toward a phishing page.

See Microsoft’s analysis of file-hosting services misused for identity phishing.

A real notification can still lead into a fraudulent workflow

That distinction matters.

Users are often taught to inspect whether an email really came from Microsoft or Dropbox. That is useful, but a legitimate notification is not proof that the person who shared the file is legitimate or that every link inside the shared content is safe.

Microsoft observed restricted-access files that required the intended recipient to authenticate before viewing them. The file could then display a message or preview containing a second link. That later link sent the user toward an adversary-controlled sign-in flow designed to capture credentials and authentication data.

The attack therefore borrows trust in several layers:

The familiar cloud service. The ordinary “shared with you” workflow. The expectation that a private document may require sign-in. And often an urgent business pretext telling the recipient to review something quickly.

Check the task from inside the service

If a document-share notice is unexpected, do not let the email define the entire path.

Open the cloud service through a known bookmark, company portal, or official application and check whether the file appears there. Verify who shared it. If the document itself immediately sends you somewhere else to authenticate again, slow down and inspect the destination.

A legitimate shared file may require authentication to the hosting service.

It should not make an unrelated domain become trustworthy simply because the journey started in OneDrive or Dropbox.

The useful mental model is that a shared document is content, not authority.

Someone can place a dangerous instruction inside a perfectly real file-sharing system.

The email can be genuine.

The file can be genuine.

The trap can still be the next click.

Posted on

Account-recovery impersonation that targets users already locked out

A person who cannot get into an account is unusually easy to sell a shortcut to.

The problem is immediate. The account may contain years of photos, messages, customers, contacts, saved work, or access to other services. Normal help pages suddenly feel slow, repetitive, and useless.

That is exactly when an unsolicited “recovery expert” sounds most believable.

The Federal Trade Commission’s guidance for hacked email and social-media accounts says that if you cannot log in, use the provider’s own account-recovery instructions. Its recovery guidance links directly to the official processes for major services rather than to third-party helpers.

See the FTC’s guidance for hacked email and social-media accounts.

Meta similarly directs hacked Facebook users to its own recovery flow at facebook.com/hacked, preferably from a device previously used with the account.

See Facebook’s official hacked-account recovery page.

The impostor sells certainty during uncertainty

A fake recovery helper may claim to have an internal contact, special tool, administrator access, or guaranteed method the public does not know about.

The requests that follow are the important part.

A scammer may ask for an upfront fee, a password, a login code, a backup code, personal identity information, or access to the victim’s email. Those are not proof that recovery is underway. They may simply create a second compromise on top of the first one.

The FTC warns broadly about recovery scams in which people claiming they can fix an earlier loss demand advance fees or personal and financial information.

See the FTC’s guidance on refund and recovery scams.

Start recovery from a place you already trust

The safest recovery path begins with the service itself: its app, a bookmarked help center, or a domain you independently type or verify.

Do not use a phone number, link, username, or “specialist” supplied by a stranger who found your public complaint. Do not hand over one-time codes. A recovery code is often equivalent to a key.

Account-recovery scams are unusually cruel because they arrive after the victim already has a real problem.

The scammer does not need to invent the emergency.

The lockout is real.

The scam is the stranger claiming to be the only person who can make it disappear.

Posted on

Business email impersonation and fraudulent payment changes

The dangerous invoice is often not the obviously fake one.

It is the invoice that arrives in the middle of a real business relationship and changes one small thing.

New bank details.

Business email compromise, or BEC, works because the attacker borrows an existing relationship between a company and a supplier, executive, employee, customer, or contractor. The message may refer to real work, real names, and a payment the recipient genuinely expects to make.

The fraud appears in the instruction telling the recipient where the money should go.

The FBI specifically warns businesses to verify changes in account numbers or payment procedures and to confirm transfer requests through another channel.

See the FBI’s Business Email Compromise guidance.

Familiar context does not authenticate a new bank account

A fraudulent message does not have to invent the entire transaction.

An attacker who has compromised an email account, studied public information, or learned the normal rhythm of a business can wait for the moment when a payment is expected. The request then feels routine because most of it is routine.

That is why a sudden change in payment instructions deserves its own verification step even when everything else in the message looks correct.

The FBI recommends verifying payment and purchase requests in person when possible, or by calling the person through a known number. Its older BEC guidance makes the same point: confirm vendor payment-location changes and use previously established contact information rather than whatever number appears in the suspicious message.

See the FBI’s earlier BEC prevention guidance.

Verify the change outside the message that requested it

If a supplier says its bank account changed, do not verify the change by replying to the same email thread.

Use a phone number already on file, an established vendor portal, a known contact, or another trusted channel. For larger transfers, a second employee approval can make one compromised inbox much less useful to an attacker.

Urgency is another warning sign. An attacker benefits when the normal verification procedure suddenly feels too slow for this one special payment.

The key distinction is simple.

A real invoice proves that money is owed.

It does not prove that a newly supplied destination account belongs to the company that earned it.

The relationship may be genuine.

The last line of the payment instructions may not be.

Posted on

QR-code phishing that moves a victim from print to a deceptive site

A QR code is a door with the address painted on the other side.

That is convenient when the code belongs to a restaurant menu, transit system, ticket, parking meter, or event organizer. It is also the reason QR-code phishing works: the user often cannot judge the destination until the phone has already decoded it.

In September 2026, the Federal Trade Commission warned about reports of scammers covering legitimate QR codes on parking meters with fraudulent ones. A driver sees the meter, sees a code in roughly the place a code should be, scans it, and lands on a site designed to collect money or personal information.

See the FTC’s warning about altered parking QR codes.

The physical object lends the link credibility

A scam email has a sender address. A suspicious website has a visible domain. A QR sticker attached to a city parking meter inherits some of the meter’s authority before the phone ever opens a browser.

That transfer of trust is the trick.

The FTC has also documented QR-code scams delivered through texts and emails, including messages claiming a package could not be delivered, an account had a problem, or suspicious activity required a password change.

See the FTC’s earlier consumer alert on harmful links hidden in QR codes.

The code itself does not prove who created it. A perfectly functional QR code can lead to a perfectly fraudulent site.

Preview the destination before trusting the context

Many phone cameras and QR readers display the destination before opening it. That preview deserves more attention than the logo, sign, envelope, flyer, or parking meter carrying the code.

Look for misspellings, substituted letters, strange subdomains, or a domain that simply does not belong to the organization named on the physical object.

For a payment, account change, fine, or government notice, the safer route is often to ignore the code entirely and reach the organization through a known website or official app.

The same rule applies when a QR code appears in a message that creates urgency.

A square of black-and-white pixels is not proof of identity.

It is merely a compressed instruction telling your phone where to go next.

The security decision begins after the phone decodes it, not before.