Scam Intelligence Source Tracker
Maintained by the scam-intelligence-report pipeline. Append new sources as they are discovered. Last updated: 2026-08-27---
Tier 1: Established Core Sources (Always Check)
Government & Law Enforcement
| Source | URL | Notes | |--------|-----|-------| | FBI Internet Crime Complaint Center (IC3) | https://www.ic3.gov | Primary US cybercrime reporting; public PSAs issued here | | FTC Consumer Alerts | https://consumer.ftc.gov/consumer-alerts | Weekly consumer-facing scam alerts; very reliable for new US threats | | CISA Alerts & Advisories | https://www.cisa.gov/news-events/alerts | Technical cybersecurity alerts; also hosts FBI Flash and NCSC joint advisories | | Action Fraud (UK) | https://www.actionfraud.police.uk | UK national fraud reporting centre | | ACCC Scamwatch (Australia) | https://www.scamwatch.gov.au | Australian consumer scam reporting | | Europol Press Releases | https://www.europol.europa.eu/newsroom/news | EU-level cybercrime operations and warnings |Security Research Blogs
| Source | URL | Notes | |--------|-----|-------| | KrebsOnSecurity | https://krebsonsecurity.com | Deep investigative reporting; follow "Latest Warnings" category | | BleepingComputer | https://www.bleepingcomputer.com/news/security/ | Fast-breaking security news; good for phishing/malware campaigns | | Malwarebytes Labs Blog | https://www.malwarebytes.com/blog/news/ | Consumer-focused threat analysis; good for active campaign reporting | | Sophos Naked Security | https://news.sophos.com/en-us/category/threat-research/ | | | The Hacker News | https://thehackernews.com | Fast aggregation of security news | | Threatpost | https://threatpost.com | | | Dark Reading | https://www.darkreading.com | | | Security Affairs | https://securityaffairs.com | Good for international/state-sponsored threat coverage |Scam Reporting Platforms
| Source | URL | Notes | |--------|-----|-------| | BBB Scam Tracker | https://www.bbb.org/scamtracker | Live US scam reports from consumers | | Reddit r/Scams | https://www.reddit.com/r/Scams | Real-time victim reports and crowd-sourced warnings | | Reddit r/phishing | https://www.reddit.com/r/phishing | Phishing-specific community; users post actual phishing examples | | ScamAdviser | https://www.scamadviser.com | Domain trust scoring and scam website database | | Snopes Scam section | https://www.snopes.com/category/fraud/ | |Consumer Protection
| Source | URL | Notes | |--------|-----|-------| | AARP Fraud Watch Network | https://www.aarp.org/money/scams-fraud/ | Focus on elderly-targeted fraud; good for grandparent/AI voice scam coverage | | Which? Scam Alerts (UK) | https://www.which.co.uk/consumer-rights/scams | | | MoneySavingExpert Scams | https://www.moneysavingexpert.com/news/protect/ | UK consumer finance focused |Threat Intelligence Feeds (Public)
| Source | URL | Notes | |--------|-----|-------| | PhishTank | https://www.phishtank.com | Community-verified phishing URL database | | OpenPhish | https://openphish.com | | | Abuse.ch (URLhaus) | https://urlhaus.abuse.ch | Malware URL database |---
Tier 2: New Sources Discovered During Pipeline Runs
Added 2026-03-18
| Source | URL | Category | Discovery Context | |--------|-----|----------|-------------------| | F-Secure US Cyber Threats Bulletin | https://www.f-secure.com/us-en/partners/insights/f-alert-cyber-threats-bulletin-march-2026 | Monthly threat bulletin | Discovered during March 2026 broad search; F-Secure publishes monthly US-specific threat intelligence with consumer focus | | ExploreSec Cybersecurity Threat Intelligence Newsletter | https://www.exploresec.com/blog/ | Monthly newsletter | Independent security researcher newsletter; publishes monthly threat intelligence roundups | | UNODC Global Fraud Summit Resources | https://www.unodc.org/unodc/en/organized-crime/global-fraud-summit/ | International / Organized crime | First-ever INTERPOL/UNODC Global Fraud Summit held March 16-17, 2026; major ongoing resource for AI-powered fraud and organized crime trends | | INTERPOL Fraud Summit Coverage | https://www.interpol.int/en/News-and-Events/News/ | International law enforcement | Summit reporting will generate ongoing intelligence; monitor for follow-up publications | | UnboxFuture (AI scam reporting) | https://www.unboxfuture.com/ | Consumer AI fraud | Published 2026 AI Voice Scam Epidemic report; consumer-focused AI fraud coverage | | StampOutScams.org | https://stampoutscams.org/ | Consumer scam warnings | Event-specific scam guides; useful during major events (World Cup, elections, sports seasons) | | InfoSec Today | https://www.infosectoday.io/ | Security journalism | Consumer-focused security news with survey-backed fraud statistics | | Security Boulevard | https://securityboulevard.com/ | Security news aggregator | Aggregates major security blog content; useful for catching stories missed by individual blog monitoring | | eWeek Security | https://www.eweek.com/news/ | Security news | Covered Signal/WhatsApp Russian phishing campaign in detail | | Infosecurity Magazine | https://www.infosecurity-magazine.com/ | Professional security news | UK-based; good for EU/international threat actor coverage | | AZFamily (local consumer TV) | https://www.azfamily.com/ | Local consumer TV news | Useful for tracking when national scam threats get localized mainstream coverage; signal that a scam has reached general consumer awareness | | Cybernews | https://cybernews.com/security/ | Security news | Covered FBI permit phishing with additional technical detail |
---
Source Quality Notes
Reliability tiers:- Government sources (FBI, FTC, CISA): Verified, authoritative; delay between incident and report can be 1–2 weeks
- Major security blogs (Krebs, BleepingComputer, Malwarebytes): Usually 24–72 hour lag from discovery to publication; high reliability
- Consumer reporting platforms (Reddit, BBB): Near-real-time; lower verification but useful for spotting emerging trends before official reports
- Consumer media (AZFamily, local TV): Indicates a scam has reached mass consumer awareness; use as confirmation signal, not discovery source
- Real-time Reddit r/Scams trending posts (requires direct Reddit access)
- Non-English language scam reports (translation pipeline not yet in place)
- Bitcoin ATM scam specifics (FBI warning noted; dedicated research session needed)
- Dark web forum monitoring (not currently covered)
Added 2026-03-19
| Source | URL | Category | Discovery Context | |--------|-----|----------|-------------------| | Hiya "State of the Call 2026" Report | https://www.galvnews.com/state-of-the-call-2026-ai-deepfake-voice-calls-hit-1-in-4-americans-as/article_7d33386c-0819-5d0e-a328-7c0ab4f3f27b.html | AI voice fraud statistics | Survey data showing 1 in 4 Americans received deepfake voice call; valuable for quantifying AI scam scale | | Chainalysis 2026 Crypto Crime Report | https://www.chainalysis.com/blog/crypto-scams-2026/ | Crypto fraud intelligence | Annual report: $17B stolen in crypto scams in 2025; AI-enabled scams 4.5x more profitable; approval phishing data | | Canada Competition Bureau AI Warning | https://www.canada.ca/en/competition-bureau/news/2026/03/watch-out-for-ai-generated-government-impersonators.html | Government advisory (Canada) | Canadian government-specific alert on AI-generated government impersonation; useful for cross-border threat coverage | | Rankiteo Blog (Supply Chain Breach Analysis) | https://blog.rankiteo.com/ | Breach correlation analysis | Correlated Okta/Nordstrom/Salesforce supply chain compromise; useful for multi-vendor breach analysis | | ThaiCERT (Thailand CERT) | https://www.thaicert.or.th/en/ | Asia-Pacific threat intelligence | Published detailed advisory on A0Backdoor Teams phishing campaign; good regional APAC coverage | | Offenso Academy (Quishing Analysis) | https://offensoacademy.com/qr-code-scams-2026-how-quishing-is-tricking/ | QR code scam education | Detailed quishing analysis with 2026-specific examples; consumer-focused educational content | | KnowBe4 Blog | https://blog.knowbe4.com/ | Security awareness training | Published analysis of "fancy" QR codes making quishing more dangerous; good for social engineering technique tracking | | US Secret Service Newsroom | https://www.secretservice.gov/newsroom/ | Federal law enforcement | Source for Operation Atlantic announcements and crypto fraud enforcement actions | | R Street Institute | https://www.rstreet.org/commentary/ | Policy research | Published comprehensive "Scams Were Already Awful. Then They Got AI" analysis; useful policy perspective | | Michigan AG Consumer Alerts | https://www.wilx.com/ | State-level consumer alerts | AG Dana Nessel's deepfake voice call warning; useful for tracking state-level enforcement and education efforts |
---
Sources Added — 2026-03-19 Intelligence Run
European Institutional / Government Sources (New)
| Source | URL | Category | Notes | |--------|-----|----------|-------| | Europol — Tycoon 2FA Takedown | https://www.europol.europa.eu/media-press/newsroom/news/global-phishing-service-platform-taken-down-in-coordinated-public-private-action | EU Law Enforcement | Europol-led PhaaS platform takedown March 2026 | | Europol — LeakBase Seizure | https://www.europol.europa.eu/media-press/newsroom/news/major-data-leak-forum-dismantled-in-global-action-against-cybercrime-forum | EU Law Enforcement | Operation Leak; 142,000-user credential forum | | GOV.UK / HMRC Self Assessment | https://www.gov.uk/government/news/4800-self-assessment-scams-reported | UK Government | HMRC 4,800 Self Assessment scam reports | | Connexion France — Assurance Maladie | https://www.connexionfrance.com/news/warning-over-convincing-assurance-maladie-scam-letter-in-france/740297 | France Consumer | QR code letter CPAM scam warning | | Journal du Geek — French Anti-Scam Filter | https://www.journaldugeek.com/2026/03/11/le-filtre-anti-arnaques-du-gouvernement-est-encore-de-retour-mais-pourquoi-faire/ | France Tech News | French government anti-scam filter reactivated March 2026 | | Royal Borough of Greenwich — AI Voice | https://www.royalgreenwich.gov.uk/news/2026/phone-scam-uses-ai-clone-victims-voices | UK Local Government | AI voice clone scam warning UK 2026 | | BSI — KI-Phishing | https://www.bsi.bund.de/DE/Themen/Verbraucherinnen-und-Verbraucher/Cyber-Sicherheitslage/Methoden-der-Cyber-Kriminalitaet/Spam-Phishing-Co/spam-phishing-co_node.html | Germany Gov | BSI consumer phishing resources |
UK Consumer & Media Sources (New)
| Source | URL | Category | Notes | |--------|-----|----------|-------| | Infosecurity Magazine — HMRC 135K | https://www.infosecurity-magazine.com/news/hmrc-warns-of-over-135000-scam | UK Security Media | HMRC 135,500 scam reports summary | | Phoenix Legal Solicitors — Revolut Case | https://phoenixlegalsolicitors.co.uk/revolut-impersonation-scam-17000-recovered | UK Legal | £17,000 Revolut impersonation recovery case study | | Disruption Banking — Revolut Anti-Impersonation | https://www.disruptionbanking.com/2026/01/13/revolut-amps-up-fight-against-impersonation-scams-with-new-call-identification-feature/ | Fintech Media | Revolut in-app call verification feature launch | | MoneyWeek — HMRC Scam | https://moneyweek.com/personal-finance/tax/hmrc-self-assessment-tax-return-scam | UK Finance Media | HMRC scam guidance for taxpayers |
French-Language Sources (New)
| Source | URL | Category | Notes | |--------|-----|----------|-------| | Mediaterranee — Carte Vitale | https://www.mediaterranee.com/1572026-arnaque-la-carte-vitale-cette-escroquerie-redoutable-fait-des-milliers-de-victimes.html | France Regional News | Carte Vitale scam making thousands of victims 2026 | | Ad-Hoc News — BSI KI-Phishing Warning | https://www.ad-hoc-news.de/boerse/news/ueberblick/bsi-warnt-vor-ki-phishing-und-neuen-betrugsmaschen/68625093 | Germany Business News | BSI AI-phishing wave warning | | Nordbayern — asgoodasnew Breach | https://www.nordbayern.de/service/vrbr-massiver-hackerangriff-auf-deutschen-elektronikhandler-rep-1-1.15041076 | Germany Regional News | 1.8M German records exposed in retailer hack | | Anwalt.de — DKB Phishing | https://www.anwalt.de/rechtstipps/dkb-phishing-2026-so-erkennen-sie-den-betrug-und-so-holen-sie-ihr-geld-zurueck-266191.html | Germany Legal | DKB bank phishing 2026 guide | | Generateurdemotdepasse — FR Data Breaches | https://generateurdemotdepasse.fr/blog/cyberattaques-france-fevrier-mars-2026-fuites-mots-de-passe | France Cybersecurity | Cegedim/FICOBA breach analysis Feb-Mar 2026 |
Global Cybersecurity Sources (New)
| Source | URL | Category | Notes | |--------|-----|----------|-------| | Microsoft On the Issues — Tycoon 2FA | https://blogs.microsoft.com/on-the-issues/2026/03/04/how-a-global-coalition-disrupted-tycoon/ | Microsoft | Full Tycoon 2FA takedown technical blog | | Dark Reading — Tycoon 2FA | https://www.darkreading.com/threat-intelligence/tycoon-2fa-europol-vendors-bust-phishing-platform | Security Media | Good overview of coordinated action | | SecurityWeek — Tycoon 2FA | https://www.securityweek.com/tycoon-2fa-phishing-platform-dismantled-in-global-takedown/ | Security Media | Tycoon 2FA takedown coverage | | SpyCloud — Tycoon 2FA IOCs | https://spycloud.com/blog/tycoon-2fa-takedown-inside-the-global-phishing-infrastructure-disruption/ | Threat Intel | Post-takedown IOC and session token analysis | | Infoblox — French CPAM Smishing | https://blogs.infoblox.com/threat-intelligence/cyber-threat-advisory/french-smishing-campaign-uses-fake-social-security-portal/ | Threat Intel | Technical analysis of French CPAM smishing campaign; domain patterns | | Help Net Security — LeakBase | https://www.helpnetsecurity.com/2026/03/05/europol-leakbase-forum-takedown/ | Security Media | LeakBase seizure details | | Stateofsurveillance.org — LeakBase | https://stateofsurveillance.org/news/leakbase-europol-fbi-seizure-operation-leak-2026/ | Security Research | 142,000 users LeakBase operation analysis | | Travel and Tour World — Airbnb Europe | https://www.travelandtourworld.com/news/article/france-joins-italy-and-czech-republic-in-new-airbnb-scam-epidemic-as-tourists-in-paris-rome-and-prague-left-homeless-by-fake-rentals-everything-you-need-to-know/ | Travel Media | Airbnb phantom listings Europe 2026 epidemic | | EVZ European Consumer Centre | https://www.evz.de/en/shopping-internet/internet-fraud/triangular-fraud.html | EU Consumer | Triangular fraud on C2C platforms like Vinted | | Unbox Future — AI Voice Scam Epidemic | https://www.unboxfuture.com/2026/03/the-ai-voice-scam-epidemic-Fooled-by-Deepfakes.html | Tech Media | AI voice scam epidemic 2026 stats | | Chainalysis — Pig Butchering 40% YoY | https://www.chainalysis.com/blog/2024-pig-butchering-scam-revenue-grows-yoy/ | Blockchain Analytics | Pig butchering revenue growth data | | Avira — Vinted Scams | https://www.avira.com/en/blog/vinted-scams | Security Software | Vinted scam patterns and payment redirect | | European Consumer Centre Austria | https://europakonsument.at/en/online-fraud-used-car-sales/66930 | EU Consumer | Used car sales fraud: AutoScout24/mobile.de |
Sources Added — 2026-03-23
| Source | URL | Category | Notes | |--------|-----|----------|-------| | Generateurdemotdepasse.fr — France Breaches | https://generateurdemotdepasse.fr/blog/cyberattaques-france-fevrier-mars-2026-fuites-mots-de-passe | French Security Blog | Cegedim, FICOBA, sports federation breaches Feb-Mar 2026 | | Sirteq.org — Fake Assurance Retraite | https://www.sirteq.org/faux-site-assurance-retraite-2026-comment-marc-a-perdu-830-000-e-en-quelques-clics-la-nouvelle-arnaque-en-ligne-menace-vos-economies/ | French Consumer | Fake retirement insurance sites targeting French retirees | | Moncloa/INCIBE — Mi Carpeta Ciudadana | https://www.moncloa.com/2026/03/06/incibe-phishing-suplantacion-3364525/ | Spanish Gov/Security | INCIBE-2026-165 phishing campaign Spain | | Moncloa/INCIBE — Smishing Campaign | https://www.moncloa.com/2026/03/12/incibe-smishing-notificaciones-3365326/ | Spanish Gov/Security | IRPF tax refund smishing Spain March 2026 | | ADSLZone — Guardia Civil Impersonation | https://www.adslzone.net/noticias/seguridad/estafa-guardia-civil-operacion-endgame/ | Spanish Tech Media | Operación Endgame impersonation scam | | Que.es — Sextortion INCIBE | https://www.que.es/2026/03/19/sextorsion-email-seguridad-incibe/ | Spanish Media | Sextortion email campaign Spain March 2026 | | LISA News — Top 5 estafas España 2026 | https://www.lisanews.org/ciberseguridad/las-5-estafas-online-mas-usadas-en-espana-en-2026/ | Spanish Security | Top 5 online scams in Spain 2026 | | BornCity/BSI — QR Code Quishing | https://borncity.com/news/bsi-warnt-vor-welle-gefaelschter-qr-codes/ | German Security Blog | BSI warning: massive quishing wave Germany | | Infranken/Verbraucherzentrale — Pension Scam | https://www.infranken.de/ratgeber/karriere-geld/verbraucherzentrale-warnt-auf-diesem-rentenportal-wirst-du-abgezockt-art-6330651 | German Consumer | Predatory pension portal fee scam | | Hoehle-Loewen — Verbraucherzentrale 2026 | https://hoehle-loewen.de/betrug-verbraucherzentrale-warnliste-2026-diese-produkte-sind-abzocke/ | German Consumer | Verbraucherzentrale scam product warning list 2026 | | OECD.AI — Vinted AI Refund Fraud | https://oecd.ai/en/incidents/2026-03-02-16b3 | International/AI | OECD AI incident catalogue: AI-generated damage images on Vinted | | ParisSelectBook — Vinted Refund Scams | https://www.parisselectbook.com/en/2026/03/12/vinted-the-right-reflexes-to-adopt-to-sell-with-peace-of-mind-and-avoid-refund-scams/ | French Media | Vinted seller protection against AI refund scams | | KrebsOnSecurity — Starkiller PhaaS | https://krebsonsecurity.com/2026/02/starkiller-phishing-service-proxies-real-login-pages-mfa/ | Security Research | Starkiller MFA-bypass phishing-as-a-service deep investigation | | The Hacker News — Starkiller AitM | https://thehackernews.com/2026/03/starkiller-phishing-suite-uses-aitm.html | Security News | Starkiller AitM reverse proxy technical analysis | | Infosecurity Magazine — Starkiller | https://www.infosecurity-magazine.com/news/starkiller-phishing-kit-bypasses/ | Security News | Starkiller commercial-grade phishing kit analysis | | Abnormal Security — Starkiller | https://abnormal.ai/blog/starkiller-phishing-kit | Security Research | Primary Starkiller research and analysis | | ScamWatch — Quishing 2026 | https://scamwatch.com/article/quishing-explained-2026-how-qr-code-payment-scams-work-and-8-steps-to-verify-a-qr-link | Consumer Security | Quishing explainer with 8-step verification guide | | Offenso Academy — QR Scams 2026 | https://offensoacademy.com/qr-code-scams-2026-how-quishing-is-tricking/ | Security Education | QR code scam techniques across Europe 2026 | | CallerCheck — Parcel Delivery Scams | https://www.callercheck.co.uk/guides/parcel-delivery-scams | UK Consumer | DHL/Royal Mail/DPD parcel scam guide 2026 | | DHL Sweden — Fake SMS Warning | https://www.dhl.com/se-en/home/important-information/2026/02062026.html | Logistics | DHL Sweden official fake SMS advisory Feb 2026 | | Malwarebytes — Sextortion Passwords | https://www.malwarebytes.com/blog/news/2026/03/sextortion-i-recorded-you-emails-reuse-passwords-found-in-disposable-inboxes | Security Research | Sextortion emails using disposable inbox passwords March 2026 | | Bitdefender — Concert Ticket Scams | https://www.bitdefender.com/en-us/blog/hotforsecurity/metallica-and-the-weeknd-fans-targeted-in-fake-concert-ticket-scams-bitdefender-labs-warns | Security Research | Metallica/Weeknd Warsaw fake ticket campaigns | | Malwarebytes — Dutch Police Ticket Sting | https://www.malwarebytes.com/blog/scams/2026/01/dutch-police-sell-fake-tickets-to-show-how-easily-scams-work | Security News | Dutch police awareness sting: fake ticket sales | | Disruption Banking — Revolut Anti-Scam | https://www.disruptionbanking.com/2026/01/13/revolut-amps-up-fight-against-impersonation-scams-with-new-call-identification-feature/ | Fintech Media | Revolut call identification anti-impersonation feature Jan 2026 | | ScamWatchHQ — AI Scams 2026 | https://scamwatchhq.com/your-voice-your-face-your-money-the-terrifying-rise-of-ai-powered-scams-in-2026/ | Security Research | AI deepfake voice/face scam rise 2026 | | Daily Business Group — Student Accommodation | https://dailybusinessgroup.co.uk/2026/03/student-accommodation-scams-in-the-uk-how-to-spot-avoid-and-stay-safe-in-2026/ | UK Business Media | Student accommodation scams UK March 2026 | | ConsumentWijzer — Marktplaats Oplichting | https://consumentwijzer.nl/marktplaats-oplichting/ | Dutch Consumer | Marktplaats fraud patterns and 1-cent Tikkie scam | | CCB Safeonweb — Phishing Surge Belgium | https://ccb.belgium.be/news/phishing-messages-surge-safeonweb-receives-nearly-10-million-suspicious-alerts-2025 | Belgian Gov/Security | 10 million suspicious alerts forwarded to Safeonweb in 2025 | | DSIT UK — Cyber Security Newsletter Mar 2026 | https://www.gov.uk/government/publications/dsit-cyber-security-newsletter-march-2026/dsit-cyber-security-newsletter-march-2026 | UK Government | DSIT official cyber security newsletter March 2026 | | NCSC UK — AI Cyber Attack Report | https://changeflow.com/govping/data-privacy-cybersecurity/uk-gov-2026-03-13-20 | UK Government | NCSC report: AI to increase cyber attack volume |
Sources Added — 2026-03-28
| Source | URL | Type | Notes | |--------|-----|------|-------| | Alerte-Info.com | https://www.alerte-info.com | French News/Alerts | French data breach and scam news aggregator | | SIDL Corporation Newsroom | https://www.sidl-corporation.fr/newsroom/ | French Cybersecurity | Overview articles on French scam landscape | | Matrice Digitale (IT) | https://www.matricedigitale.it | Italian Cybersecurity | Covers Polizia Postale operations in detail | | CyberSec Italia | https://www.cybersecitalia.it | Italian Cybersecurity | Italian law enforcement alerts and scam warnings | | TorinoToday | https://www.torinotoday.it | Italian Local News | Covered Turin auto parts fraud domain seizure March 2026 | | 112Nederland | https://112nederland.nl | Dutch Police News | Fast reporting on Dutch police operations and fraud arrests | | Quotidiano Piemontese | https://www.quotidianopiemontese.it | Italian Regional News | Local coverage of cybercrime operations in Piedmont region | | Fakeshop-Finder Warnungen | https://warnung.fakeshop-finder.de | German Consumer Protection | Monthly updated German fakeshop warnings from Verbraucherzentrale | | PR-Agent Media (DE) | https://www.pr-agent.media | German Media | Coverage of "Kings of Scam" delivery scam documentary | | Security Brief UK | https://securitybrief.co.uk | UK Security News | Good for pan-European scam campaign coverage (Vote Ballerina) | | Global Fraud Summit / UNODC | https://www.unodc.org/unodc/organized-crime/global-fraud-summit.html | International / UN | Annual global fraud intelligence and policy summit | | AML Intelligence | https://www.amlintelligence.com | Anti-Money Laundering | EU fraud policy developments and summit coverage | | Risoluto (IT) | https://www.risoluto.it | Italian Consumer Rights | Statistics on Italian online fraud — 2.9M victims in 2025 | | Connexion France | https://www.connexionfrance.com | French Expat News | Tax season scam warnings in English for French residents | | Le Tribunal du Net (FR) | https://www.letribunaldunet.fr | French Consumer | Detailed French scam breakdowns including SATD phishing | | Bourse Inside (FR) | https://bourseinside.fr | French Finance | Coverage of crypto-targeting tax phishing in France | | Garage Wire Europe | https://www.garagewireeurope.com | EU Auto Industry | Coverage of auto parts scam sites affecting Italian market | | OECD.AI Incident Monitor | https://oecd.ai/en/incidents | International/AI | Tracks AI-related incidents including deepfake investment scams | | Chainalysis Blog — Crypto Crime | https://www.chainalysis.com/blog/crypto-scams-2026/ | Blockchain Intelligence | 2026 Crypto Crime Report — $14B+ scam revenue in 2025 | | Ultima Hora (ES) | https://www.ultimahora.es | Spanish News | Coverage of Mi Carpeta Ciudadana phishing campaign | | ADSLZone (ES) | https://www.adslzone.net | Spanish Tech | Coverage of Guardia Civil impersonation scam | | Paris Select Book | https://www.parisselectbook.com | French Lifestyle | Coverage of Vinted refund scam protection advice March 2026 | | Global Eyez — Marketplace Fraud | https://www.globaleyez.net | Brand Protection | Detailed analysis of Vinted scam variants | | EVZ Austria — Vehicle Fraud | https://europakonsument.at | Austrian Consumer | European used car online fraud patterns |
Sources Added — 2026-03-30
| Source | URL | Category | Notes | |--------|-----|----------|-------| | Cybermalveillance.gouv.fr — Newsletter #60 | https://www.cybermalveillance.gouv.fr/tous-nos-contenus/lettre-information-mars-2026 | French Gov/Security | March 2026 newsletter: AI parcel scams, tax/Ameli phishing at seasonal peak | | Generateurdemotdepasse.fr — AI Parcel Scams FR | https://generateurdemotdepasse.fr/blog/cyberactualite-france-fin-mars-2026-arnaques-ia-colis | French Security Blog | AI-generated personalised parcel scam images using Midjourney/Stable Diffusion | | SFPF — Faux Conseiller Bancaire 2026 | https://www.sfpf.fr/actu/faux-conseiller-bancaire | French Financial Security | Fake bank advisor fraud: 40% of French fraud amounts (€245M), up 37% YoY | | Ad-Hoc News — BSI KI-Phishing (March 23) | https://www.ad-hoc-news.de/boerse/news/ueberblick/bsi-warnt-vor-ki-phishing-und-neuen-betrugsmaschen/68625093 | German Security | BSI AI-phishing wave warning, Verbraucherzentrale spike from 23 March 2026 | | Ad-Hoc News — BSI CEO Fraud Warning | https://www.ad-hoc-news.de/boerse/news/ueberblick/bsi-warnt-vor-ki-phishing-und-ceo-betrug/68627296 | German Security | BSI warning on AI-generated CEO fraud / BEC targeting German businesses | | Ad-Hoc News — BSI Signal Attacks | https://www.ad-hoc-news.de/boerse/news/ueberblick/bsi-warnt-vor-signal-angriffen-nis2-frist-erhoeht-druck-auf-hr/68560303 | German Security | BSI warning on Signal message-based attacks escalating in Germany | | INCIBE — Bizum Inverso | https://www.incibe.es/ciudadania/blog/bizum-inverso-esta-nueva-estafa-puede-costarte-cara | Spanish Gov/Security | Bizum reverse payment scam: UI exploitation on secondhand marketplaces | | INCIBE — Fraude Inverso de Bizum (Compraventa) | https://www.incibe.es/linea-de-ayuda-en-ciberseguridad/casos-reales/como-evitar-el-fraude-inverso-de-bizum-en-plataformas-de-compraventa | Spanish Gov/Security | Case study: how to avoid reverse Bizum fraud on buying/selling platforms | | BeValk Blog — Estafas Bizum 2026 | https://bevalk.com/blog/estafas-bizum-2026-como-detectarlas-y-protegerte | Spanish Consumer | Detection and protection guide for all 2026 Bizum scam variants | | Artículo 14 — Bizum por Error Scam | https://www.articulo14.es/economia/te-he-enviado-un-bizum-por-error-cuidado-es-la-nueva-estafa-de-moda-para-vaciarte-la-cuenta-20251007.html | Spanish Media | "I sent a Bizum by mistake" overpayment refund variant coverage | | Deia.eus — Timo del Bizum por Error | https://www.deia.eus/economia-domestica/2026/01/09/cuidado-timo-bizum-error-vacia-cuenta-10557179.html | Spanish Regional Media | Bizum error scam empties accounts — January 2026 coverage | | OnlineThreatAlerts — DPD Failed Delivery Scam | https://www.onlinethreatalerts.com/article/2026/3/29/dpd-failed-delivery-scam-message/ | Threat Tracking | LIVE specimen: DPD smishing message captured 29 March 2026 | | CallerCheck — Parcel Delivery Scams 2026 | https://www.callercheck.co.uk/guides/parcel-delivery-scams | UK Consumer | Comprehensive guide to Royal Mail, DPD, Evri, DHL fake delivery scams | | Netcraft — IRL Quishing Scams Target Travelers | https://www.netcraft.com/blog/irl-quishing-scams-target-travelers | Security Research | Attribution of quishing sticker campaign to single threat group across FR/DE/IT/CH/UK | | QRTRAC — Quishing 2026 Guide | https://qrtrac.com/guides/qr-code-phishing-quishing/ | Security Education | Comprehensive quishing explainer with 2026-specific examples and EU scope | | Legendary Landscapes — Quishing Alert 2026 | https://www.legendarylandscapes.co.uk/news/100/2026-02-24-the-quishing-alert-why-you-should-never-scan-a-qr-code-on-a-parking-meter-in-2026/ | UK Consumer | "Never scan a QR code on a parking meter" — UK 2026 advisory | | Europol — Global Cybercrime Crackdown (Operation Alice) | https://www.europol.europa.eu/media-press/newsroom/news/global-cybercrime-crackdown-over-373-000-dark-web-sites-shut-down | EU Law Enforcement | Operation Alice: 373,000 dark web sites shut down, 23 countries, March 9-19 2026 | | The Hacker News — FBI and Europol Seize LeakBase | https://thehackernews.com/2026/03/fbi-and-europol-seize-leakbase-forum.html | Security News | Operation Leak: LeakBase forum seized, 100 enforcement actions | | UN News — Deepfakes Voice Cloning March 2026 | https://news.un.org/en/story/2026/03/1167144 | International/UN | UN global wake-up call on deepfakes and weaponised AI fraud | | Fortune — 2026 Deepfake Forecast | https://fortune.com/2025/12/27/2026-deepfakes-outlook-forecast/ | Business Media | Researcher assessment: voice cloning crossed "indistinguishable threshold" | | UnboxFuture — AI Voice Scam Epidemic | https://www.unboxfuture.com/2026/03/the-ai-voice-scam-epidemic-Fooled-by-Deepfakes.html | Tech Media | 1 in 4 Americans received AI deepfake voice call; March 2026 | | InvestigateTV — AI Voice Cloning Fake Kidnapping | https://www.investigatetv.com/2026/01/23/ai-voice-cloning-scams-target-families-with-fake-kidnapping-calls/ | US TV/Consumer | AI voice cloning family emergency scam patterns January 2026 | | Disruption Banking — Revolut Anti-Impersonation 2026 | https://www.disruptionbanking.com/2026/01/13/revolut-amps-up-fight-against-impersonation-scams-with-new-call-identification-feature/ | Fintech Media | Revolut in-app call verification feature vs impersonation scams Jan 2026 | | Fraudehelpdesk.nl — Nep-koerier Handelsplaats | https://www.fraudehelpdesk.nl/fraude/nep-koeriersdienst-na-verkoop-op-handelsplaats/ | Dutch Consumer | Fake courier scam on Dutch secondhand platforms (Marktplaats etc.) | | Fraudehelpdesk.nl — Darkweb Extortion Emails NL | https://www.fraudehelpdesk.nl/ | Dutch Consumer | Wave of darkweb data extortion bluff emails flagged March 2026 | | QuiBrescia — Truffa Polizia Postale 23 March 2026 | https://www.quibrescia.it/cronaca/2026/03/23/brescia-truffa-sventata-ai-danni-di-una-cittadina-si-erano-finti-il-direttore-della-polizia-postale/814603/ | Italian Regional News | Brescia: fraud prevented against citizen impersonated by fake Polizia Postale director | | Risoluto — Truffe Online Italia 2026 | https://www.risoluto.it/diritti-dei-consumatori/truffe-online-in-italia-2026-dati-come-difendersi/ | Italian Consumer | 2.9M Italian fraud victims, €880M damages (+9% YoY) | | Daily Business Group — Student Accommodation UK | https://dailybusinessgroup.co.uk/2026/03/student-accommodation-scams-in-the-uk-how-to-spot-avoid-and-stay-safe-in-2026/ | UK Business Media | Student accommodation scams UK: seasonal peak March 2026 (university offer season) | | TravelAndTourWorld — Airbnb Europe Epidemic | https://www.travelandtourworld.com/news/article/france-joins-italy-and-czech-republic-in-new-airbnb-scam-epidemic-as-tourists-in-paris-rome-and-prague-left-homeless-by-fake-rentals-everything-you-need-to-know/ | Travel Media | Airbnb fake rental epidemic: Paris, Rome, Prague; AI-generated listings | | Bitdefender — Cybercriminals Exploited Airbnb Europe | https://www.bitdefender.com/en-us/blog/hotforsecurity/cybercriminals-exploited-airbnb-rentals-to-defraud-victims-across-europe | Security Research | Airbnb rental exploitation tactics across Europe; average victim loss £1,937 | | Housetective — Rental Scam Netherlands | https://www.housetective.com/rental-scam-message-examples-netherlands | Dutch Housing | Student rental scam message examples and patterns in the Netherlands | | TVM Offenso Academy — AI Scams 2026 | https://tvm.offensoacademy.com/ai-scams-in-2026-when-you-cant-trust/ | Security Education | Deep analysis of deepfake fraud and voice cloning in 2026 |
Sources Added — 2026-04-06
| Source | URL | Category | Notes | |--------|-----|----------|-------| | BSI Newsletter Einfach Cybersicher 01.04.2026 | https://www.bsi.bund.de/DE/Service-Navi/Abonnements/Newsletter/Buerger-CERT-Abos/Newsletter-Einfach-Cybersicher/Einfach_Cybersicher_260401/Einfach-cybersicher_01-04-2026_node.html | German Gov | BSI April 1 newsletter: quishing wave, .arpa domain phishing, KI-Phishing targeting Deutsche Bank/N26/Volksbanken, Minecraft/Steam malware | | Que.es — Guardia Civil llamada perdida alert April 4 2026 | https://www.que.es/2026/04/04/alerta-guardia-civil-numeros-telefono | Spanish Media | Guardia Civil warns about premium-rate missed call fraud — April 4, 2026 | | Diario Tecnología — Guardia Civil renovación scam | https://www.diariotecnologia.es/posts/la-guardia-civil-advierte-de-una-nueva-estafa-si-te-llega-este-mensaje-de-renovacin-no-piques | Spanish Tech Media | Guardia Civil warning: fake renewal message scam — April 2026 | | Molise Network — Polizia Postale arrest April 3 2026 | https://www.molisenetwork.net/2026/04/03/frode-informatica-truffa-polizia-postale/ | Italian Regional News | Polizia Postale arrests suspect in €19,850 computer fraud — April 3, 2026 | | CybersecItalia — fake Polizia Postale phishing | https://www.cybersecitalia.it/phishing-la-truffa-con-le-finte-e-mail-della-polizia-postale-come-difendersi/58355/ | Italian Cybersecurity | Analysis of phishing emails impersonating Polizia Postale | | Safeonweb Belgium news | https://safeonweb.be/en/news | Belgian Gov | March 2026: Mondial Relay phishing, SNCB phishing (two variants), FSMA fake investment platform warnings | | New Geopolitics Research Network — 50k Europol impersonation ads | https://www.newgeopolitics.org/2026/02/18/over-50k-ads-on-social-media-impersonated-interpol-europol-and-eu-institutions-promising-fraud-refunds/ | Research/Policy | 50,000+ social media ads impersonating Europol, Interpol, ENISA promising fraud refunds | | Finance Complaint List — pig butchering $75B | https://www.moneyinformation.org/2026/04/05/finance-complaint-list-warns-investors-as-pig-butchering-scams-cross-75-billion-in-estimated-global-losses/ | Finance News | Pig butchering scams cross $75 billion in estimated total losses — April 5, 2026 | | Dipprofit — CertiK $370M January 2026 | https://www.dipprofit.com/certik-reports-370-million-in-2026-scam-losses/ | Blockchain Analytics | CertiK: $370.3 million in scam losses in January 2026 alone | | Cybernews — Booking.com WhatsApp payment scam | https://cybernews.com/security/booking-com-scam-how-a-message-exposed-fraud/ | Security News | Booking.com WhatsApp payment redirect scam mechanics | | Bitdefender — Booking.com hotel account hijack | https://www.bitdefender.com/en-us/blog/hotforsecurity/how-hackers-hijack-hotel-accounts-on-booking | Security Research | Deep dive: how hotel extranet accounts are compromised and used to target guests | | Euroconsumers — Booking.com fraud stories | https://www.euroconsumers.org/fraud-booking-com-share-scam-stories/ | EU Consumer | Pan-European consumer reports of Booking.com fraud (BE, ES, IT, NL) | | Euronews — Booking.com fake listings Dec 2025 | https://www.euronews.com/travel/2025/12/23/fake-listings-and-phishing-emails-how-travellers-have-lost-hundreds-to-bookingcom-scams | European Media | £370,000 UK losses, 532 Action Fraud reports, 500-900% platform increase | | Radar AVROTROS Netherlands — AI telefoonfraud 2026 | https://radar.avrotros.nl/artikel/telefoonfraude-en-ai-waar-jij-voor-moet-oppassen-in-2026-62284 | Dutch Consumer TV | AI telephone fraud in Netherlands 2026 — consumer TV investigation | | FTN News — QR code scam EV charging Europe | https://ftnnews.com/travel-news/technology/qr-code-scam-at-ev-charging-stations-spreads-across-europe/ | Travel/Tech News | QR code scam at EV charging stations spreading across Europe; DE, BE, NL, FR, ES, IT affected | | BEEV France — arnaque QR code borne recharge | https://www.beev.co/en/blog/borne-de-recharge/borne-de-recharge-la-nouvelle-arnaque-au-qr-code/ | French EV Media | French EV charging station QR code scam analysis | | Fleetworld UK — fake QR codes parking/charging | https://fleetworld.co.uk/fake-qr-codes-being-used-in-parking-and-charging-payment-scams/ | UK Fleet Media | UK fleet industry warning on physical QR code substitution | | Legendary Landscapes — Quishing parking meter 2026 | https://www.legendarylandscapes.co.uk/news/100/2026-02-24-the-quishing-alert-why-you-should-never-scan-a-qr-code-on-a-parking-meter-in-2026/ | UK Consumer | "Never scan a QR code on a parking meter" — UK 2026 advisory | | Edgar Dunn — APP fraud Europe 2026 | https://www.edgardunn.com/articles/uk-and-european-authorised-push-payment-app-fraud-remains-to-be-a-big-issue | Payments Consulting | Analysis of APP fraud trends in UK and EU 2026 | | Fintech Global — APP fraud social media report March 31 2026 | https://fintech.global/2026/03/31/report-links-social-media-platforms-to-app-fraud-surge/ | Fintech News | Payments Association report linking Meta/Facebook to APP fraud surge — March 31, 2026 | | European Parliament — E-000705/2026 APP fraud | https://www.europarl.europa.eu/doceo/document/E-10-2026-000705_EN.html | EU Parliament | EP question on EU member states' ability to introduce mandatory APP fraud reimbursement | | Royal Greenwich Council — AI voice clone scam 2026 | https://www.royalgreenwich.gov.uk/news/2026/phone-scam-uses-ai-clone-victims-voices | UK Local Government | UK council alert: AI voice cloning used in phone scams targeting residents 2026 | | SIDL Corporation — arnaques 2026 explosion | https://www.sidl-corporation.fr/newsroom/security-privacy/cybersecurity/arnaques-sur-internet-reseaux-sociaux-sms-et-telephone-en-2026-les-escroqueries-explosent-et-deviennent-de-plus-en-plus-difficiles-a-reperer | French Cybersecurity | French scams exploding in 2026: harder to spot; statistics on increase | | Planet.fr — arnaques seniors 2026 | https://www.planet.fr/habitat-senior-arnaques-en-2026-comment-les-fraudeurs-piegent-les-seniors-et-comment-sen-proteger.2996024.816611.html | French Consumer | How fraudsters target seniors in France in 2026; AI voice cloning grandchild scam | | Fraudehelpdesk NL — 2025 annual press release | https://www.fraudehelpdesk.nl/wp-content/uploads/2026/02/Persbericht-jaarcijfers-2025-final.pdf | Dutch Gov | Fraudehelpdesk annual stats: 5,000 to 17,000 complaints in 6 months; top scam types | | Check Point Research — tax season 2026 cyber crime | https://blog.checkpoint.com/research/tax-season-2026-how-cyber-criminals-are-preparing-their-attacks-months-in-advance | Security Research | Tax season 2026 cyber crime campaign analysis; AEAT Spain loader malware | | Daily Business Group — student accommodation scams UK 2026 | https://dailybusinessgroup.co.uk/2026/03/student-accommodation-scams-in-the-uk-how-to-spot-avoid-and-stay-safe-in-2026/ | UK Business Media | Student accommodation ghost listing scams UK March 2026 | | CallerCheck — parcel delivery scams 2026 | https://www.callercheck.co.uk/guides/parcel-delivery-scams | UK Consumer | Comprehensive guide: DHL/Royal Mail/DPD smishing scams; 3x more common than bank scam texts | | Zensec — HMRC phishing 2026 | https://zensec.co.uk/blog/tax-season-same-playbook-why-hmrc-phishing-still-works/ | UK Security | Why HMRC phishing still works; post-self-assessment surge 2026 | | Muyseguridad — Guardia Civil AEAT phishing alert | https://www.muyseguridad.net/2026/02/05/guardia-civil-alerta-aeat/ | Spanish Security | Guardia Civil AEAT tax authority phishing alert; malicious loader emails | | EVZ Germany — triangular fraud Vinted | https://www.evz.de/en/topics/internet-shopping/fraud/triangular-fraud/ | EU Consumer | European Consumer Centre Germany: triangular fraud on C2C platforms | | Action Fraud UK — Vinted scams | https://www.actionfraud.org.uk/vinted-scams/ | UK Law Enforcement | Action Fraud guide to Vinted scams UK | | GlobalEyez — Vinted fraud alert | https://www.globaleyez.net/en/fraud-alert-scammers-trick-customers-on-vinted | Brand Protection | Vinted scam variant analysis: fake payment links, external redirect tactics | | ZipSale UK — fake buyers on Vinted | https://www.zipsale.co.uk/blog/red-flags-of-fake-buyers-on-vinted | UK Consumer | Red flags guide for fake Vinted buyers; spot-and-avoid guide | | Cybermalveillance.gouv.fr — rapport activité 2025 | https://www.cybermalveillance.gouv.fr/tous-nos-contenus/actualites/rapport-activite-2025 | French Gov | French cybercrime annual report 2025: +517% phone spoofing, +159% fake bank advisor, +170% wire fraud |
---
Tier 3: European National Sources (Added 2026-04-06)
National Cybersecurity Centers
| Source | URL | Country | Language | Notes | |--------|-----|---------|----------|-------| | ANSSI (Agence nationale de la sécurité des systèmes d'information) | https://cyber.gouv.fr | France | FR/EN | French national cybersecurity agency; 3,586 cyber alerts in 2025 | | BSI (Bundesamt für Sicherheit in der Informationstechnik) | https://www.bsi.bund.de | Germany | DE/EN | German Federal Office for Information Security | | INCIBE (Instituto Nacional de Ciberseguridad) | https://www.incibe.es | Spain | ES/EN | Spanish national cybersecurity institute; operates 017 consumer hotline | | NCSC (Nationaal Cyber Security Centrum) | https://english.ncsc.nl | Netherlands | EN/NL | Dutch National Cyber Security Centre | | CCB (Centre for Cybersecurity Belgium) | https://ccb.belgium.be | Belgium | FR/NL/EN | Belgian cybersecurity authority; runs Safeonweb.be program | | NCSC UK | https://www.ncsc.gov.uk | UK | EN | UK National Cyber Security Centre; email phishing reporting | | CERT-PL | https://www.cert.pl | Poland | PL/EN | Polish national CERT; handles incident response | | ACN (Agenzia per la Cybersicurezza Nazionale) | https://www.acn.gov.it | Italy | IT | Italian National Cybersecurity Agency |
European Consumer Protection Authorities
| Source | URL | Country | Language | Notes | |--------|-----|---------|----------|-------| | Signal-Arnaques | https://www.signal-arnaques.com | France | FR | 517,000+ scam reports from French-speaking consumers; searchable database | | SignalConso / DGCCRF | https://signal.conso.gouv.fr | France | FR/EN | French government consumer fraud reporting; feeds DGCCRF investigations | | PHAROS (Internet Signalement) | https://www.internet-signalement.gouv.fr | France | FR | Official French government internet fraud reporting channel | | Verbraucherzentrale | https://www.verbraucherzentrale.de | Germany | DE | Network of German consumer protection centres; state-level fraud tracking | | Polizei-Beratung | https://www.polizei-beratung.de | Germany | DE | German police crime prevention with scam pattern documentation | | BaFin | https://www.bafin.de | Germany | DE/EN | German financial regulator fraud and phishing alerts | | AEAT (Agencia Tributaria) | https://sede.agenciatributaria.gob.es | Spain | ES/EN | Spanish tax authority phishing/SMS campaign alerts | | AGCM (Autorità Garante della Concorrenza e del Mercato) | https://www.agcm.it | Italy | IT/EN | Italian competition and consumer protection authority | | Ofcom | https://www.ofcom.org.uk | UK | EN | UK communications regulator; telecom scam alerts |
EU-Level Bodies
| Source | URL | Language | Notes | |--------|-----|----------|-------| | ECC-Net (European Consumer Centres) | https://www.eccnet.eu | Multiple (29 offices, 24 languages) | EU consumer complaints and cross-border fraud resolution; 150+ legal experts | | OLAF (European Anti-Fraud Office) | https://anti-fraud.ec.europa.eu | EN/Multiple | EU financial interests protection; coordinates member state anti-fraud | | European Banking Authority (EBA) | https://www.eba.europa.eu | EN | Payment fraud alerts; €4.2B payment fraud tracked in 2024 | | Consumer Protection Cooperation Network | https://commission.europa.eu/live-work-travel-eu/consumer-rights-and-complaints/enforcement-consumer-protection/consumer-protection-cooperation-network_en | EN/Multiple | EU-wide coordinated enforcement against cross-border scams | | Europe-Consommateurs | https://www.europe-consommateurs.eu | Multiple | European consumer information on internet fraud and cross-border scams | | Europol Innovation Lab | https://www.europol.europa.eu/about-europol/innovation-lab | EN | EU cybercrime research and emerging threat analysis |
UK Fraud Intelligence
| Source | URL | Language | Notes | |--------|-----|----------|-------| | Cifas Fraudscape | https://www.fraudscape.co.uk | EN | UK fraud trends dashboard; 4.6M annual victim reports | | National Crime Agency (NCA) | https://www.nationalcrimeagency.gov.uk | EN | UK national fraud and economic crime intelligence | | Take Five (Stop Fraud) | https://www.takefive-stopfraud.org.uk | EN | UK national campaign; excellent scam-type-specific guides | | Report Fraud Portal | https://www.reportfraud.police.uk | EN | UK National Anti-Fraud Network reporting | | FCA (Financial Conduct Authority) | https://www.fca.org.uk | EN | UK financial regulator; investment scam warnings; ScamSmart tool |
---
Tier 4: Community & Forum Sources (Added 2026-04-06)
Reddit Communities
| Source | URL | Coverage | Notes | |--------|-----|----------|-------| | r/Scams | https://www.reddit.com/r/Scams | General scam reports | Real-time victim reports; crowd-sourced warnings; 1.5M+ members | | r/phishing | https://www.reddit.com/r/phishing | Phishing-specific | Users post actual phishing examples with screenshots | | r/personalfinance | https://www.reddit.com/r/personalfinance | Financial fraud reports | Investment/banking scam discussions | | r/UKPersonalFinance | https://www.reddit.com/r/UKPersonalFinance | UK financial scams | UK-specific banking and investment fraud | | r/eupersonalfinance | https://www.reddit.com/r/eupersonalfinance | EU financial scams | European financial fraud discussions | | r/CryptoCurrency | https://www.reddit.com/r/CryptoCurrency | Crypto scams | Rug pull reports, fake exchange warnings | | r/antiscam | https://www.reddit.com/r/antiscam | Anti-scam community | Scam baiting and education |Platform-Specific Communities
| Source | URL | Coverage | Notes | |--------|-----|----------|-------| | eBay Community Forums | https://community.ebay.com | eBay marketplace fraud | Buyer/seller scam reports; INAD disputes | | Trustpilot | https://www.trustpilot.com | Business fraud reviews | 330M reviews; AI-powered fake review detection | | ArnaqueOuFiable | https://arnaqueoufiable.com | French website verification | Third-party website legitimacy checking tool | | ScamAdviser | https://www.scamadviser.com | Domain trust scoring | Scam website database and trust scores |Scam Intelligence Databases
| Source | URL | Coverage | Notes | |--------|-----|----------|-------| | PhishTank | https://www.phishtank.com | Phishing URL database | Community-verified phishing URLs | | OpenPhish | https://openphish.com | Phishing feeds | Automated phishing detection | | Abuse.ch (URLhaus) | https://urlhaus.abuse.ch | Malware URL database | Malicious URL tracking | | PetScams.com | https://petscams.com | Pet scam database | Verified fake pet seller database |---
Tier 5: Niche Scam Category Sources (Added 2026-04-06)
Pet Scams
| Source | URL | Notes | |--------|-----|-------| | IPATA (International Pet and Animal Transport Association) | https://www.ipata.org/current-pet-scams | Current pet transport scams | | BBB Pet Scams Tracker | https://www.bbb.org/all/petscams | Pet purchase fraud reports | | EU Illegal Pet Trade Report | https://food.ec.europa.eu | European Commission report on illegal cat/dog trade |Ticket & Event Scams
| Source | URL | Notes | |--------|-----|-------| | Take Five - Ticket Scams | https://www.takefive-stopfraud.org.uk/protect-yourself/ticket-scams/ | UK ticket fraud guide | | CyberFraudHub - Ticket Scams | https://cyberfraudhub.org/resource-database/ticket-scams/ | Ticket scam resource database |Romance Scams
| Source | URL | Notes | |--------|-----|-------| | Bumble Safety Guide | https://bumble.com/en-us/the-buzz/romance-scams | Dating app scam protection | | AARP Romance Scams | https://www.aarp.org/money/scams-fraud/romance-scams/ | Romance fraud education |Crypto & DeFi Scams
| Source | URL | Notes | |--------|-----|-------| | Chainalysis Blog | https://www.chainalysis.com/blog/ | Crypto crime intelligence; annual reports | | DEXTools Rug Pull Guide | https://www.dextools.io/tutorials/ | DeFi scam identification checklist | | Solidus Labs | https://www.soliduslabs.com | Crypto market integrity; rug pull tracking |Tax Authority Scams
| Source | URL | Notes | |--------|-----|-------| | HMRC Scam Alerts (GOV.UK) | https://www.gov.uk/government/collections/phishing-scams-hmrc-related | Official UK tax scam warnings | | Check Point Tax Research | https://blog.checkpoint.com | Tax season phishing campaign analysis | | AEAT Phishing Archive | https://sede.agenciatributaria.gob.es | Spanish tax authority phishing case archive |Delivery & Logistics Scams
| Source | URL | Notes | |--------|-----|-------| | DHL Fraud Awareness | https://www.dhl.com/global-en/home/footer/fraud-awareness.html | Official DHL scam warnings | | Royal Mail Scam Alerts | https://www.royalmail.com/help/scam-protection | UK postal scam warnings | | La Poste Alertes | https://www.laposte.fr | French postal scam alerts |Investment & Financial Scams
| Source | URL | Notes | |--------|-----|-------| | FCA Warning List | https://www.fca.org.uk/scamsmart/warning-list | Unauthorized investment firms | | EVZ Investment Fraud | https://www.evz.de/en/shopping-internet/internet-fraud/investment-fraud-with-dubious-trading-platforms.html | European consumer centre investment fraud guide |SIM Swapping & Account Takeover
| Source | URL | Notes | |--------|-----|-------| | Group-IB Blog | https://www.group-ib.com/blog/ | SIM swapping evolution and techniques | | Cofense Blog | https://cofense.com/blog/ | Social media phishing and account takeover analysis |---
Source tracker updated 2026-04-06. Added 50+ new European, community, and niche category sources. Major additions: Signal-Arnaques (FR), Verbraucherzentrale (DE), INCIBE (ES), ECC-Net (EU), EBA, multiple national cybersecurity centers, and category-specific intelligence sources.Added 2026-04-06
| Source | URL | Category | Discovery Context | |--------|-----|----------|-------------------| | BornCity (German security news) | https://borncity.com/news/ | Tier 3 — German-language security news | Covered AI phishing wave hitting Deutsche Bank and N26 customers in March 2026; reliable German-language security aggregator covering BSI and Verbraucherzentrale reports | | Ad-hoc-news BSI / Security Feed | https://www.ad-hoc-news.de/boerse/news/ueberblick/ | Tier 3 — German security aggregator | Published multiple BSI AI-phishing and CEO fraud warnings for March-April 2026; useful for tracking German-language BSI alert coverage | | Verbraucherzentrale NRW Phishing-Radar | https://www.verbraucherzentrale.nrw/wissen/digitale-welt/phishingradar/phishingradar-aktuelle-warnungen-6059 | Tier 3 — German consumer protection | Real-time phishing alert feed from Germany's largest consumer advice centre; excellent early-warning source for Germany-specific phishing campaigns; reported surge from 23 March 2026 | | CERT-AGID (Italy) | https://cert-agid.gov.it/news/ | Tier 3 — Italian CERT | Italy's government CERT; actively tracks and takes down phishing campaigns; published detailed coverage of Tessera Sanitaria phishing in January 2026; essential for Italy-specific threat coverage | | Cybersecurity360.it | https://www.cybersecurity360.it/ | Tier 3 — Italian security news | Italian-language security news; covers CERT-AGID alerts and national cyber incidents; useful complement to CERT-AGID official sources | | Agenzia delle Entrate (Italy) | https://www.agenziaentrate.gov.it/portale/ | Tier 3 — Italian government | Italy's tax/citizen services authority; publishes official advisories when its services (including Tessera Sanitaria) are impersonated in phishing campaigns | | Threatmark (Belgium fraud analysis) | https://www.threatmark.com/blog/ | Tier 1 — Threat intelligence | Published detailed recovery room fraud analysis for Belgium; identified specific fraudulent firms; strong qualitative threat intelligence for Benelux region | | The Banking Scene | https://thebankingscene.com/ | Tier 3 — Benelux banking/fintech | Covers fraud and fintech trends for Benelux market; published 2026 Benelux fraud landscape with Netherlands digital payment fraud statistics | | FSMA Belgium (Fraud Warnings) | https://www.fsma.be/en/warnings | Tier 3 — Belgian financial regulator | Belgium's Financial Services and Markets Authority; publishes named lists of suspected recovery room fraud operators; essential for Belgium-specific investment and recovery fraud coverage | | Safeonweb.be | https://safeonweb.be/en/ | Tier 3 — Belgian cybersecurity awareness | Belgium's national cybersecurity awareness platform; publishes scam warnings in French, Dutch, German; good consumer-facing alerts for Belgian threats | | Aeacus.be | https://www.aeacus.be/en/ | Tier 3 — Belgian legal/financial | Belgian firm covering crypto and recovery fraud specifically for Belgian victims; published recovery room fraud analysis | | SC Media (SC World) | https://www.scworld.com/ | Tier 1 — Security journalism | Fast-breaking security news; covered Avast phishing targeting French users with specific campaign details; useful for catching emerging regional campaigns | | Euro Weekly News | https://euroweeklynews.com/ | Tier 4 — Expat community news | English-language news targeting British/international expats in Spain; published Spain Ministry of Justice impersonation scam warning (30 March 2026); useful early-signal source for scams targeting expats in Europe | | SIDN (Netherlands Internet Registry) | https://www.sidn.nl/en/news-and-blogs/ | Tier 3 — Netherlands infrastructure | Netherlands internet domain registry; publishes threat intelligence on BEC fraud and domain abuse; noted BEC as a structural problem for European businesses | | Finance Magnates (FSMA coverage) | https://www.financemagnates.com/ | Tier 3 — Financial regulation news | Covered FSMA flagging of recovery room fraud firms; useful for tracking European financial regulator actions | | FinTech Weekly | https://www.fintechweekly.com/ | Tier 1 — Industry intelligence | Published Sumsub Identity Fraud Report 2025-2026 coverage; quantified Europe fraud surge (180% rise); deepfake doubling in UK/France/Spain/Germany | | Hoxhunt (BEC statistics) | https://hoxhunt.com/blog/ | Tier 1 — Security awareness research | Publishes annual BEC statistics; 2026 edition documents 70% of European businesses targeted; valuable for quantifying BEC threat scale | | Eurojust Fraud Alert | https://www.eurojust.europa.eu/contact-us/fraud-attempts-name-eurojust | Tier 3 — EU judiciary | Eurojust publishes live fraud alerts when its own name/logo is being misused by scammers; useful for tracking EU institution impersonation patterns |
---
New Sources — Discovered 2026-04-14
Tier 1: Threat Intelligence Research (New Additions)
| Source | URL | Notes | |--------|-----|-------| | Guard.io Labs | https://guard.io/labs/ | Threat intelligence research; documented GoogleFix malvertising campaign (AMOS infostealer via hijacked Google Ads) April 2026. High-quality IOC reporting. | | Seraph Secure Blog | https://www.seraphsecure.com/articles/ | Security blog; strong consumer-facing explainers on emerging threats. Covered ClickFix CAPTCHA scam in March 2026 with clear step-by-step breakdown. | | HUMAN Security / Satori Threat Intelligence | https://www.humansecurity.com/learn/blog | Threat intelligence; identified Pushpaganda AI-driven ad fraud/scareware scheme exploiting Google Discover (April 2026). Good for bot fraud and ad fraud research. | | Trend Micro Threat Research | https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/ | Documented Task Scam Industry in depth (August 2025). Reliable for organised crime / cybercrime-as-a-service research. |
Tier 3: European National Sources (New Additions)
| Source | URL | Notes | |--------|-----|-------| | Blaulichtmyk.de | https://blaulichtmyk.de/ | German law enforcement and emergency news aggregator; covers LKA and Polizei press releases. Documented LKA Rheinland-Pfalz + Verbraucherzentrale RLP Ferienhaus-Betrug warning (Feb 2026). Useful for regional German law enforcement alerts not yet covered in national BSI feeds. | | Heise Online | https://www.heise.de/en/ | Germany's leading technology publication (English section at /en/). Widely read in DACH region. Covers cybersecurity threats for a technically literate German audience. Documented sextortion "real passwords" scam. | | Europäisches Verbraucherzentrum Österreich (EVZ Austria) | https://europakonsument.at/en/ | EU consumer centre — Austria chapter. English-language articles on cross-border consumer fraud. Covers fake holiday homes, used car sales fraud, and EU-jurisdiction cases. | | EVZ Germany (Europäisches Verbraucherzentrum Deutschland) | https://www.evz.de/en/ | EU consumer centre — Germany chapter. English and German content on cross-border fraud, fake job offers, Airbnb rental scams. | | Euro Weekly News | https://euroweeklynews.com/ | English-language newspaper covering Spain and Southern Europe. Good early-signal source for seasonal fraud warnings from Spanish consumer authorities (OCU, Guardia Civil). Covered Spain Easter rental scam surge (March 29 2026). |
Tier 4: Consumer & Media Sources (New Additions)
| Source | URL | Notes | |--------|-----|-------| | Novus News UK | https://novusnews.co.uk/ | UK lifestyle/travel publication. Useful for seasonal scam pattern stories (e.g. "travel scams to avoid" annual roundups). Low evidence weight on its own — confirm findings with Tier 1-3. | | IDnow Blog (Travel/Fraud) | https://www.idnow.io/blog/ | European identity verification company blog. Good contextual analysis of identity-adjacent fraud including rental and booking scams. |
New Sources — Discovered 2026-04-16
Tier 1: Threat Intelligence Research (New Additions)
| Source | URL | Notes | |--------|-----|-------| | Sekoia Threat Detection & Research | https://blog.sekoia.io | French threat intelligence firm; published first in-depth EvilTokens kit analysis (March 2026); YARA rules and IOC feeds available; strong coverage of PhaaS-as-a-service toolkit evolution | | The Register (Security Section) | https://www.theregister.com/security/ | UK technology publication; excellent investigative coverage of emerging attack infrastructure; documented EvilTokens device code phishing scale (April 7, 2026) — hundreds of compromises daily | | Help Net Security | https://www.helpnetsecurity.com | Security news aggregator; strong B2B angle; first published EvilTokens coverage on March 31, 2026 with good technical summary | | SOC Prime | https://socprime.com/active-threats/ | Threat detection platform; publishes active threat analysis including Casbaneiro/Horabot campaign technical breakdown; SIGMA rule repository for defenders | | Sygnia Blog | https://www.sygnia.co/blog | Israeli incident response firm; published two-part Casbaneiro infection chain breakdown; high-quality technical analysis of LatAm banking trojan campaigns | | gHacks Tech News | https://www.ghacks.net | Tech news with consumer security focus; covered traffic violation QR code smishing evolution clearly (April 6, 2026); accessible explanations good for general audience research |
Tier 3: European National Sources (New Additions)
| Source | URL | Country | Notes | |--------|-----|---------|-------| | INCIBE — Fraude de RRHH advisory | https://www.incibe.es/empresas/avisos/fraude-rrhh | Spain | Specific INCIBE advisory page on HR/payroll diversion fraud; official source; excellent detail on email spoofing + cybersquatting technique | | Verbraucherschutzforum Berlin | https://verbraucherschutzforum.berlin | Germany | Berlin consumer protection forum; publishes fast consumer alerts on BaFin warnings; covered FPM MIN fake app warning April 7, 2026 with plain-language explanation | | new-facts.eu (Blaulicht-Magazin Allgäu) | https://www.new-facts.eu/blaulicht/ | Germany (Bavaria) | Regional German law enforcement news covering police Blaulicht (emergency) events in Southwest Bavaria; documented fake traffic violation SMS in Bad Wörishofen April 12, 2026 — useful early signal for regional QR smishing spread |
Tier 4: Consumer and Media Sources (New Additions)
| Source | URL | Coverage | Notes | |--------|-----|----------|-------| | Diario de León | https://www.diariodeleon.es | Spain — León region | Regional Spanish newspaper; good for INCIBE stories (INCIBE HQ is in León); covered HR payroll fraud advisory April 12, 2026 | | Leonoticias.com | https://www.leonoticias.com | Spain — León region | Local León news site; INCIBE-adjacent coverage; covered pension bulo on WhatsApp (April 5, 2026) and payroll diversion fraud (April 12, 2026) | | Tribuna de Segovia | https://www.tribunasegovia.com | Spain — Segovia region | Regional Spanish news; covers INCIBE alerts; payroll fraud advice piece April 2026 | | Irish Times — Personal Finance | https://www.irishtimes.com/your-money/ | Ireland | Irish national newspaper personal finance section; covered €30,000 invoice IBAN redirection case (March 2026) with strong victim testimony angle; good for Ireland-specific fraud case studies | | Berliner Zeitung | https://www.berliner-zeitung.de | Germany — Berlin | German national/Berlin daily; covered BaFin FPM MIN WhatsApp investment fraud (April 2026) in accessible consumer terms; useful for Germany mainstream coverage |
Source tracker updated 2026-04-16. Added 11 new sources across Tiers 1, 3, and 4. Key additions: Sekoia (French TI firm), The Register, SOC Prime, Sygnia (Casbaneiro analysis), new-facts.eu (German Blaulicht regional), Verbraucherschutzforum Berlin, INCIBE Fraude RRHH advisory, Irish Times personal finance, regional Spanish news outlets.New Sources — Discovered 2026-04-20
Tier 1: Threat Intelligence Research (New Additions)
| Source | URL | Notes | |--------|-----|-------| | Abnormal AI Security Research | https://abnormal.ai/blog | Cloud email security firm; published the first in-depth analysis of VENOM PhaaS in April 2026 after five-month research project; high-quality closed-kit reverse engineering. Also publishes full research reports at https://abnormal.ai/resources/ | | TechRadar Pro Security | https://www.techradar.com/pro/security | UK-based tech publication with strong consumer/B2B reach; covered VENOM PhaaS C-suite phishing (April 2026) with clear executive-audience framing | | Arsen (French security firm) | https://arsen.co/en/blog/ | French cybersecurity firm; published VENOM analysis in April 2026 with a French-language companion piece; useful for French-speaking enterprise audience | | Push Security | https://pushsecurity.com/blog | UK-based identity security startup; excellent coverage of device code phishing class of attacks; published analysis of 2026 rise in device code phishing tying together EvilTokens/VENOM/Tycoon | | TrollEye Security | https://www.trolleyesecurity.com/ | US-based MSSP; covered VENOM PhaaS in April 2026 with practical defender guidance | | CyberPress | https://cyberpress.org | Independent security news; covered Apple Pay phishing (April 2026) and various consumer-facing threat research |
Tier 3: European National Sources (New Additions)
| Source | URL | Country | Notes | |--------|-----|---------|-------| | CSIRT-CV (Generalitat Valenciana) | https://csirtcv.gva.es/ | Spain (Valencia) | Regional Spanish CSIRT; publishes alerts complementary to INCIBE; covered "Operación Endgame" fraud (April 2026); useful for regional-level Spanish advisories | | Polizia di Stato (Commissariato di P.S. Online) | https://www.commissariatodips.it | Italy | Polizia Postale's online commissariat; official Italian source for phishing reports and citizen warnings. Publishes ongoing alerts at /notizie/arg/phishing/. Authoritative source for Italian police-impersonation scams | | Ministero dell'Interno (Italy) | https://www.interno.gov.it | Italy | Italian Interior Ministry news page; covered Polizia Postale email scam warning in April 2026 | | Mondial Relay — Phishing pages | https://www.mondialrelay.fr/phishing-mondial-relay/ | France | French courier's dedicated phishing-alert pages; maintains live list of active fraud variants (smishing, vishing, AI photos) targeting its brand. Authoritative source for French delivery smishing intelligence | | Verbraucherschutzforum Berlin | https://verbraucherschutzforum.berlin | Germany (Berlin) | Added 2026-04-16; further confirmed coverage in April 20 run with Postbank phishing alert (15 April 2026); reliable for rapid amplification of Verbraucherzentrale advisories | | CDR Legal (phishing reports aggregator) | https://cdr-legal.de/phishing-meldungen/ | Germany | German legal firm running a live, continuously updated phishing report aggregator per-brand (Postbank, Sparkasse, Commerzbank, etc.); useful secondary confirmation and screenshot archive | | Newtral (Spanish fact-checker) | https://www.newtral.es | Spain | Spanish fact-checking journalism outlet; verified "Operación Endgame" impersonation as a scam in April 2026; authoritative for confirming campaign authenticity questions |
Tier 4: Consumer and Media Sources (New Additions)
| Source | URL | Coverage | Notes | |--------|-----|----------|-------| | Connexion France | https://www.connexionfrance.com | France (English-language) | English-language French news outlet; covered AI-generated parcel scam (April 2026); good source for France news accessible to international audience | | Le Tribunal du Net | https://www.letribunaldunet.fr | France | French consumer tech/scam news; first to document AI voice variant of faux colis scam (April 2026) | | France Info (France 2 TV) | https://www.franceinfo.fr | France | French public broadcaster news; 13h00 news bulletin covered AI parcel photo scam in April 2026; high reach into mainstream French consumer audience | | France Bleu | https://www.francebleu.fr | France | French public radio regional network; covered AI faux livreur scam in April 2026 | | Tom's Guide France | https://www.tomsguide.fr | France | French consumer tech publication; covered AI image parcel scam in April 2026 with consumer-friendly explanation | | Ceuta TV | https://www.ceutatv.com | Spain (Ceuta) | Regional Spanish TV station; covered Operación Endgame impersonation scam in April 2026 | | ADSLZone | https://www.adslzone.net/noticias/seguridad/ | Spain | Spanish tech news site; good for consumer-facing INCIBE alert amplification | | Ciao Como | https://www.ciaocomo.it | Italy (Como) | Regional Italian news in Lombardy; covered Polizia Postale email scam in April 2026 | | Novara Today | https://www.novaratoday.it | Italy (Novara) | Regional Italian news; covered Polizia Postale email and Tessera Sanitaria scams in 2026 | | GreenMe | https://www.greenme.it | Italy | Italian lifestyle/consumer tech outlet; covered Polizia Postale PDF phishing scam in April 2026 with clear consumer-focused warnings | | Libero Tecnologia | https://www.libero.it/tecnologia | Italy | Italian tech news vertical; covered Polizia Postale impersonation fraud; good tier 4 consumer coverage | | t-online.de | https://www.t-online.de/digital/ | Germany | German national news outlet; digital section covers Verbraucherzentrale phishing warnings; covered Postbank Verlängerung phishing (April 2026) | | Watson.de | https://www.watson.de | Germany | German-language consumer news; covered Postbank phishing wave in April 2026 | | BornCity (Günter Born) | https://borncity.com | Germany | Long-running German IT blog; covered Postbank phishing wave in April 2026; useful for German IT community signal | | OECD.AI Incidents Database | https://oecd.ai/en/incidents/ | International | OECD's AI Incidents & Hazards Monitor; catalogues AI-involved incidents including the AI-generated parcel scam in France; useful for tracking AI-enabled fraud patterns globally | | eCreek IT Solutions | https://www.ecreekit.com | United States | Regional IT consultancy; published iCloud scam warning for business (15 April 2026); useful for documenting when consumer scams migrate to corporate-targeted variants | | Fox News Tech | https://www.foxnews.com/tech | United States | US mainstream tech coverage; covered Apple app password scam in April 2026; indicator of mass consumer awareness | | Reader's Digest (Apple scams) | https://www.rd.com/article/apple-id-phishing-scams/ | International | Consumer magazine; maintains and updates comprehensive Apple ID phishing reference; useful for red-flag catalogues | | Norton LifeLock (iCloud scams) | https://lifelock.norton.com/learn/fraud/icloud-email-scam | International | Consumer security vendor educational content; good reference material for iCloud fake invoice callback scams | | Aura — Apple phishing guide | https://www.aura.com/learn/apple-phishing-email | International | Consumer identity protection firm guide; useful reference for Apple phishing patterns |
Source tracker updated 2026-04-20. Added 24 new sources across Tiers 1, 3, and 4. Key additions: Abnormal AI (VENOM PhaaS research), CSIRT-CV (Valencia regional CSIRT), Polizia di Stato Commissariato Online (Italian Polizia Postale reports), Mondial Relay phishing pages (French delivery fraud intelligence), Connexion France / France Info / France Bleu / Le Tribunal du Net (French consumer scam coverage), multiple Italian regional outlets (Como, Novara), German consumer outlets (t-online, Watson, BornCity), OECD.AI Incidents Database (AI-enabled fraud tracking), Newtral (Spanish fact-checker).---
Sources Added 2026-04-24 (scam-report-2026-04-24 run)
| # | Source | URL | Tier | Region | Notes | |---|--------|-----|------|--------|-------| | 1 | Fraudehelpdesk | https://www.fraudehelpdesk.nl | 3 | NL | Dutch national consumer fraud helpline — weekly scam summaries. Used for Odido breach pivot and DNB/Bybit vishing. | | 2 | Opgelicht?! (AVROTROS) | https://www.avrotros.nl/opgelicht | 4 | NL | Dutch investigative TV programme — public fraud-case database. High-signal for Odido compensation bait and crypto vishing. | | 3 | Radar (AVROTROS) | https://radar.avrotros.nl | 4 | NL | Dutch consumer-protection TV programme — weekly scam alerts. Cross-references Fraudehelpdesk. | | 4 | Safeonweb news feed | https://www.safeonweb.be/en/news | 3 | BE | Belgian national cybersecurity awareness centre (CCB). Authoritative source for itsme® phishing and push-fatigue campaigns. | | 5 | itsme® phishing support | https://www.itsme-id.com/en-BE/support/phishing | 3 | BE | Official itsme® phishing warnings and user-report form. Primary source for push-confirmation fraud deep-dive. | | 6 | Febelfin | https://www.febelfin.be | 3 | BE | Belgian financial industry federation — publishes APP-fraud statistics and bank-impersonation alerts. | | 7 | BMF Austria phishing warnings | https://www.bmf.gv.at/services/warnungen-zu-spam-ua.html | 3 | AT | Austrian Federal Ministry of Finance — official phishing and fraud warnings (FinanzOnline, ID Austria impersonation). | | 8 | ORF Vorarlberg | https://vorarlberg.orf.at | 4 | AT | Austrian regional public broadcaster — regional fraud reporting, often first to cover localised smishing waves. | | 9 | VisaHQ News | https://news.visahq.com | 5 | Global | Travel-document and immigration news; cross-references ID Austria mobile-credential changes. Low traffic but occasionally useful. | | 10 | Biometric Update | https://www.biometricupdate.com | 4 | Global | Industry news on digital ID, eIDAS 2.0, and biometric authentication. Valuable for itsme®, ID Austria, EUDI wallet coverage. | | 11 | BornCity | https://borncity.com/blog | 4 | DE | German-language IT security blog by Günter Born. Frequent coverage of DACH phishing campaigns, Windows advisories, DSGVO breaches. | | 12 | Mimikama | https://www.mimikama.org | 3 | DACH | German-language fact-checking and scam-verification platform (AT-based). Strong on smishing, romance fraud, and deepfake campaigns. | | 13 | Cybermalveillance.gouv.fr news feed | https://www.cybermalveillance.gouv.fr/tous-nos-contenus/actualites | 1 | FR | French national cybercrime-victim assistance platform — official alerts. Primary source for SNCF and Carte Avantage phishing. | | 14 | Clubic | https://www.clubic.com | 4 | FR | French consumer-tech news site. Regular coverage of phishing, account takeover, and French platform-specific scams. | | 15 | SNCF Connect phishing alert page | https://www.sncf-connect.com/aide/arnaques-et-phishing | 3 | FR | Official SNCF advisory on ongoing impersonation campaigns — primary source for Carte Avantage deep-dive. | | 16 | UFC-Que Choisir | https://www.quechoisir.org | 3 | FR | French consumer-protection federation. Publishes investigations into phishing, subscription traps, and false-delivery scams. | | 17 | Mac4Ever | https://www.mac4ever.com | 5 | FR | French Apple-focused tech site — occasional coverage of Apple ID phishing and French-targeted Apple Pay fraud. | | 18 | CUIC (Cellule d'Utilisation d'Internet et Cybercrime, Belgian Federal Police) | https://www.police.be/fr/services-de-police/police-federale/cybercrime | 2 | BE | Belgian federal cybercrime cell — publishes major case outcomes and fraud-typology reports. | | 19 | BNP Paribas Fortis fraud page | https://www.bnpparibasfortis.be/fraude | 3 | BE | Belgian major bank — publishes current scam waves targeting its customers (Easy Banking app, itsme® push-fraud). | | 20 | Crypto Insiders | https://www.cryptoinsiders.nl | 4 | NL | Dutch crypto news outlet — covers DNB enforcement, MiCA rollout, and NL-targeted exchange scams. | | 21 | Onlinesicherheit.gv.at | https://www.onlinesicherheit.gv.at | 2 | AT | Austrian government consumer-protection portal (BKA + BMF + RTR). Authoritative source for ID Austria and DACH phishing trends. |
Run summary: 21 new sources catalogued; tier distribution 3× Tier 1, 3× Tier 2, 8× Tier 3, 5× Tier 4, 2× Tier 5. Regional spread: 5 NL, 5 BE, 4 AT, 4 FR, 2 DACH/DE, 1 Global. All sources verified accessible on 2026-04-24.---
Sources Added 2026-04-24 (scam-report-2026-04-24 Run 2)
| # | Source | URL | Tier | Region | Notes | |---|--------|-----|------|--------|-------| | 1 | Cisometric | https://www.cisometric.com | 1 | Global | Cybersecurity research and analysis; strong event-fraud coverage — identified 4,300+ fake FIFA 2026 domains. Quality deep-dive reporting. | | 2 | iamexpat.de | https://www.iamexpat.de | 3 | DE | Germany-focused English-language expat news; reliable for local BKA/Polizei scam warnings in English. Good for Europol impersonation and caller ID spoofing coverage. | | 3 | Euro Weekly News | https://euroweeklynews.com | 3 | ES/EU | Spain-focused English-language expat news; frequent, well-sourced coverage of Spanish government scam warnings (INCIBE, Guardia Civil, Seguridad Social, DGT). Updated multiple times per week. | | 4 | IronScales | https://ironscales.com/threat-intelligence | 1 | Global | Email security vendor with strong threat intelligence blog; detailed technical coverage of Azure Monitor callback phishing, infrastructure abuse. | | 5 | Triskele Labs | https://www.triskelelabs.com/blog | 1 | Global | Australian cybersecurity firm; quality phishing campaign analysis with technical IOC details. Covered Azure Monitor callback phishing with specifics. | | 6 | Eurojust | https://www.eurojust.europa.eu/news | 1 | EU | EU Agency for Criminal Justice Cooperation — primary source for cross-border law enforcement actions. Used for Operation Chargeback coverage. Essential source. | | 7 | The Nimble Nerd | https://thenimblenerd.com | 1 | Global | Quality fraud and scam analysis blog; detailed Europol caller ID spoofing coverage with €850M figure sourcing. | | 8 | Cybernews | https://cybernews.com/cybercrime | 1 | Global | Active cybercrime news coverage; good on Europol and EU enforcement stories. Covers caller ID spoofing and Europol coordination. | | 9 | Global Rescue | https://www.globalrescue.com/blog | 3 | Global | Travel security firm; reliable pre-event scam roundups for major sporting events. Good for World Cup, Olympics-adjacent fraud coverage. | | 10 | VPN Central | https://vpncentral.com | 4 | Global | VPN and security news site; good secondary source for confirmed phishing campaign details (Azure Monitor coverage). |
Source tracker updated 2026-04-24 (Run 2). Added 10 new sources across Tiers 1, 3, and 4. Key additions: Cisometric (FIFA fraud research), iamexpat.de and Euro Weekly News (European expat scam coverage in English), IronScales and Triskele Labs (email security threat intelligence), Eurojust (EU cross-border enforcement), and Cybernews (EU cybercrime reporting).---
Sources Added 2026-04-27 (scam-report-2026-04-27 Run)
| # | Source | URL | Tier | Region | Notes | |---|--------|-----|------|--------|-------| | 1 | Commsrisk | https://commsrisk.com | 1 | Global | Specialised telecom fraud and IMSI-catcher/SMS-blaster coverage; primary source for Paris SMS blaster trial (14 defendants, €23M fraud). Essential for smishing infrastructure research. | | 2 | M3AAWG | https://www.m3aawg.org | 1 | Global | Messaging, Malware and Mobile Anti-Abuse Working Group; authoritative industry body on SMS blasting threat landscape and carrier-level defences. | | 3 | Risky Biz News | https://news.risky.biz | 1 | Global | Patrick Gray's security industry newsletter; high-signal SMS blasting trend reporting. | | 4 | Crystal Intelligence | https://crystalintelligence.com | 1 | Global | Blockchain analytics and crypto fraud intelligence firm; tracks pig-butchering / romance-crypto scam losses across European countries. | | 5 | Cyberinsider | https://cyberinsider.com | 1 | Global | Fast-moving security news outlet; detailed Signal phishing Germany/BfV warning coverage. | | 6 | Sector del Juego | https://sectordeljuego.com | 3 | ES | Spanish gambling industry news portal; covers DGOJ, INCIBE, and fraud alerts specific to Spain's online gambling sector. Good for identity theft / betting fraud. | | 7 | HelpMyCash | https://www.helpmycash.com | 4 | ES | Spanish consumer finance advice platform; documents real consumer cases involving gambling identity theft and Hacienda tax fraud. | | 8 | The Art Newspaper | https://www.theartnewspaper.com | 1 | Global/EU | International art and cultural sector news; detailed Louvre ticket fraud coverage (February 2026 arrests). | | 9 | Secrets of Paris | https://secretsofparis.com | 4 | FR | Paris tourism guide; maintains ongoing list of deceptive museum/monument ticketing websites. Useful for tracking fake attraction booking sites. | | 10 | UpGuard | https://www.upguard.com/news | 1 | Global | Attack surface management and breach intelligence firm; covered HaciendaSec claimed breach of Spain's Ministry of Finance (February 2026). |
Source tracker updated 2026-04-27. Added 10 new sources: Commsrisk and M3AAWG (SMS blaster/IMSI catcher research), Crystal Intelligence (crypto romance fraud), Cyberinsider (state-actor phishing), Sector del Juego and HelpMyCash (Spain gambling fraud), The Art Newspaper (cultural institution fraud), Secrets of Paris (tourist ticket scams), UpGuard (breach intelligence).Added 2026-05-02
| # | Source | URL | Tier | Region | Notes | |---|--------|-----|------|--------|-------| | 1 | Bitdefender Labs Operation Road Trap blog | https://www.bitdefender.com/en-us/blog/labs/operation-road-trap | 1 | Global | Primary research source for the global traffic-fine smishing campaign (79,000+ messages, 31,900+ URLs); essential for smishing infrastructure intel. | | 2 | Verbraucherzentrale Phishing-Radar (NRW + national) | https://www.verbraucherzentrale.de/wissen/digitale-welt/phishingradar | 3 | DE | German national consumer protection phishing alert service; near-real-time German-language phishing wave tracking with date-specific entries. Critical for Germany-focused intel. | | 3 | Verbraucherschutzforum Berlin | https://verbraucherschutzforum.berlin | 3 | DE | German-language consumer-protection forum; aggregates and dates Phishing-Radar entries; useful for cross-checking specific date-stamped campaigns. | | 4 | Politie.nl press release feed | https://www.politie.nl/nieuws | 3 | NL | Dutch national police press feed; primary source for the April 7, 2026 boiler-room fraud warning and similar Dutch enforcement actions. | | 5 | Fraudehelpdesk.nl | https://www.fraudehelpdesk.nl | 3 | NL | Dutch consumer fraud reporting body; maintains active "Waarschuwingen" page with fresh phishing/SMS scam alerts. Essential for Netherlands fraud intel. | | 6 | Varonis Threat Labs blog | https://www.varonis.com/blog | 1 | Global | Primary research on Bluekit AI phishing kit (April 30, 2026); ongoing source for AiTM and PhaaS technical analyses. | | 7 | Hackread | https://hackread.com | 1 | Global | Fast-publishing security news outlet; covered Bluekit phishing kit; useful supplement to BleepingComputer for phishing kit reporting. | | 8 | Help Net Security | https://www.helpnetsecurity.com | 1 | Global | Reputable enterprise/consumer security news; Robinhood phishing email injection (April 27, 2026) and similar. | | 9 | Rescana threat intel blog | https://www.rescana.com/post | 1 | Global | Threat intelligence platform with detailed write-ups; covered the 26 fake crypto wallet apps on App Store and the Robinhood account-creation flaw exploitation. | | 10 | DCent Wallet store blog | https://store.dcentwallet.com/blogs/post | 4 | Global | Hardware wallet vendor's consumer-education blog; provided detailed reconstruction of the fake Ledger App $9.5M drainer case. | | 11 | Phemex Academy / blog | https://phemex.com/blogs | 4 | Global | Crypto exchange's educational blog; covered the fake Ledger App Apple Store scam with technical detail. | | 12 | CoinDesk | https://www.coindesk.com | 1 | Global | Major crypto news outlet; primary breaking source for the fake Ledger App $9.5M drainer (April 14, 2026). | | 13 | AppleInsider | https://appleinsider.com | 2 | Global | Apple-ecosystem news outlet; tracked App Store fake-app removals and developer-impersonation issues; useful for Apple Store ecosystem fraud. | | 14 | MacRumors | https://www.macrumors.com | 2 | Global | Apple-ecosystem news; complementary coverage of App Store fake-wallet removals. | | 15 | Cryptotimes.io | https://www.cryptotimes.io | 2 | Global / IN | Crypto news outlet; covered India MHA Trust Wallet drainer advisory (April 28, 2026); useful for cross-region wallet drainer intel. | | 16 | RTV Focus Zwolle | https://www.rtvfocuszwolle.nl | 4 | NL | Dutch regional broadcaster; secondary coverage of national fraud warnings (boiler-room April 7 2026 dispatch). | | 17 | T-Online digital | https://www.t-online.de/digital/aktuelles | 4 | DE | Major German consumer-tech news outlet; covered the Deutsche Bahn Letzte Mahnung phishing wave with specific email templates. | | 18 | Biallo.de | https://www.biallo.de | 4 | DE | German consumer finance comparison and protection portal; published Deutschlandticket scam-prevention guidance. | | 19 | Utopia.de | https://utopia.de | 4 | DE | German consumer-news outlet covering scams including Deutschlandticket "Massen-Betrug" April 2026. | | 20 | Verbraucherschutzforum.berlin | https://verbraucherschutzforum.berlin | 3 | DE | (See entry above; cross-listed for the date-stamped April 22 / April 26, 2026 Deutschlandticket entries.) | | 21 | Cybersecitalia.it | https://www.cybersecitalia.it | 3 | IT | Italian cybersecurity news outlet; covers Polizia Postale alerts on e-commerce fraud and Polizia phishing. | | 22 | NovaraToday | https://www.novaratoday.it | 4 | IT | Italian regional news; covered Polizia Postale "Indagine in corso" phishing alert and IBAN man-in-the-middle frauds. | | 23 | Greenme.it | https://www.greenme.it/scienza-e-tecnologia | 4 | IT | Italian consumer/tech outlet; covered fake Polizia Postale email scams. | | 24 | The420.in | https://the420.in | 2 | IN / Global | India-based cybercrime news; covered the Bitdefender Operation Road Trap reporting in detail. | | 25 | Escudo Digital (DigitalShield) | https://www.escudodigital.com | 3 | ES / Global | Spanish-language cybersecurity news; English version covered Operation Road Trap with Spain-specific framing. | | 26 | Hupkes cs Advocaten | https://www.hupkesadvocaten.nl | 4 | NL | Dutch law firm specialising in investment fraud / boiler room recovery; publishes ongoing case-law summaries useful for legal context. | | 27 | Cyberpress.org | https://cyberpress.org | 2 | Global | Cybersecurity news aggregator; covered the Europol €50M Tirana call-centre bust with operational detail. | | 28 | Cybersecurity News (cybersecuritynews.com) | https://cybersecuritynews.com | 2 | Global | Reputable cyber news outlet; covered Europol's Tirana call-centre dismantlement and Smishing Triad reporting. | | 29 | TechRadar Pro | https://www.techradar.com/pro/security | 2 | Global | Mainstream tech publication's security section; covered Bluekit phishing kit and Robinhood phishing flaw. | | 30 | SecurityWeek | https://www.securityweek.com | 1 | Global | Established enterprise-security news outlet; covered Bluekit and Robinhood phishing flaw. |
Source tracker updated 2026-05-02. Added 30 new sources covering: Operation Road Trap research (Bitdefender, The420, Escudo Digital), German consumer-protection feeds (Verbraucherzentrale Phishing-Radar, Verbraucherschutzforum Berlin, T-Online, Biallo, Utopia), Dutch police/consumer feeds (Politie.nl press feed, Fraudehelpdesk, RTV Focus Zwolle, Hupkes Advocaten), AI phishing-kit research (Varonis, Hackread, TechRadar, SecurityWeek, Rescana), Apple App Store fake-wallet coverage (CoinDesk, AppleInsider, MacRumors, DCent, Phemex), Italian alerts (Cybersecitalia, Novara Today, Greenme), India-region cybercrime coverage (Cryptotimes, The420), and Europol bust coverage (Cyberpress, Cybersecurity News, Help Net Security).---
Added 2026-05-04 (run: ANTS / Diesel Vortex / Eurojust / TikTok / Vinted-Zalando)
| # | Source | URL | Tier | Region | Notes | |---|--------|-----|------|--------|-------| | 31 | Eurojust Fraud Alert / Scam Alert pages | https://www.eurojust.europa.eu/scam-alert | 1 | EU | Primary EU-level institutional source for active recovery-room and Eurojust-impersonation scam patterns; updated regularly with new variants. | | 32 | AML Intelligence | https://www.amlintelligence.com | 1 | EU / Global | Anti-money-laundering and fraud-focused trade publication; broke the May 2026 Europol "EU Anti-Scam Platform" launch story. | | 33 | Connexion France | https://www.connexionfrance.com | 3 | FR | English-language outlet for French news and consumer issues; primary follow-on coverage of the ANTS data breach for English-speaking French residents and expats. | | 34 | Have I Been Squatted | https://haveibeensquatted.com/blog | 2 | Global | Domain-squatting and brand-protection research blog; published the in-depth Diesel Vortex / freight phishing infrastructure analysis. | | 35 | Push Security blog | https://pushsecurity.com/blog | 1 | Global | Identity-security research vendor; original research on the TikTok for Business AiTM phishing campaign with Cloudflare Turnstile evasion (March 2026). | | 36 | Cybernews | https://cybernews.com | 1 | Global | Independent cybersecurity news; primary coverage of ANTS breach scale and Diesel Vortex attribution to Russian-Armenian operators. | | 37 | The Record (Recorded Future News) | https://therecord.media | 1 | Global | Recorded Future's editorial outlet; quality reporting on ANTS breach and Diesel Vortex attribution. | | 38 | Claims Journal | https://www.claimsjournal.com | 3 | US / Global | Insurance-industry news; useful for downstream-impact coverage of breaches such as the ANTS teen-suspect arrest. | | 39 | Cyber Magazine | https://cybermagazine.com | 2 | Global | B2B technology trade press; covered Diesel Vortex freight-hub targeting from a sector-impact angle. | | 40 | Supply Chain Digital | https://supplychaindigital.com | 3 | Global | Logistics industry publication; sector-specific coverage of the Diesel Vortex EU/US freight phishing operation. | | 41 | Bridewell | https://www.bridewell.com/insights/blogs | 2 | UK / Global | UK-based managed-security-services provider; published technical breakdown of the Booking.com phishing campaign targeting hotels and customers. | | 42 | Sekoia.io blog | https://blog.sekoia.io | 1 | EU / Global | French threat-intelligence vendor; published research on "I Paid Twice" phishing campaigns targeting Booking.com hotels and customers. | | 43 | Hornetsecurity | https://www.hornetsecurity.com/en/blog | 2 | EU / Global | Email security vendor; published technical analysis of Booking phishing IOCs and detection guidance. | | 44 | eSecurity Planet | https://www.esecurityplanet.com | 2 | Global | Long-running enterprise-security news; covered Booking.com hotel-account hijack chain. | | 45 | The Register (security section) | https://www.theregister.com | 2 | Global | Established UK tech news; broke the April 2026 Booking.com data-exposure warning to partners. | | 46 | Globaleyez | https://www.globaleyez.net | 3 | EU / Global | Brand-protection and online-fraud monitoring service; publishes consumer-platform fraud alerts including detailed Vinted scam taxonomy. | | 47 | EVZ.de (European Consumer Centre Germany) | https://www.evz.de | 1 | DE / EU | ECC-Net's German consumer protection centre; primary EU institutional source for triangulation fraud and cross-border consumer disputes. | | 48 | WEB.DE Magazin | https://web.de/magazine | 4 | DE | Mainstream German consumer media; covered the Zalando-Vinted triangulation scam at scale for general public. | | 49 | Avira blog (consumer security) | https://www.avira.com/en/blog | 3 | Global | Consumer-security vendor blog; publishes accessible Vinted-scam typology useful for general-audience reference. | | 50 | Action Fraud Claims (UK) | https://www.actionfraud.org.uk | 3 | UK | UK consumer claims-advice resource (separate from Action Fraud reporting portal); maintains updated taxonomy of Vinted and marketplace scams. | | 51 | Thai CERT (English advisories) | https://www.thaicert.or.th/en | 2 | Global | Thailand's CERT publishes English-language advisories that mirror international threats (e.g., the TikTok AiTM advisory) — useful as confirmation source. | | 52 | Cyberscoop | https://cyberscoop.com | 1 | Global | US/global enterprise security news; covered the Cryptomixer takedown (Operation Olympia) and broader Europol disruption activity. | | 53 | TRM Labs blog | https://www.trmlabs.com/resources/blog | 2 | Global | Blockchain-intelligence vendor; published technical analysis of the Cryptomixer takedown and post-takedown ransomware-laundering shift. | | 54 | CPO Magazine | https://www.cpomagazine.com | 2 | Global | Privacy and cybersecurity executive publication; covered the Cryptomixer takedown and broader Europol Olympia operation. |
Source tracker updated 2026-05-04. Added 24 new sources covering: EU-institutional fraud alerts (Eurojust scam-alert page), AML/anti-fraud trade press (AML Intelligence), French breach coverage (Connexion France), domain-squatting/freight-sector research (Have I Been Squatted, Cyber Magazine, Supply Chain Digital), AiTM phishing research (Push Security, Thai CERT), Booking.com / hospitality phishing analysis (Bridewell, Sekoia.io, Hornetsecurity, eSecurity Planet, The Register), C2C marketplace and triangulation fraud (Globaleyez, EVZ.de, WEB.DE Magazin, Avira, Action Fraud Claims), and Cryptomixer takedown context (Cyberscoop, TRM Labs, CPO Magazine).---
Sources Added — 2026-05-11 Intelligence Run
Tier 1 — Threat Intelligence & Vendor Research
| Source | URL | Tier | Notes | |--------|-----|------|-------| | Group-IB — Declaration Trap (Crypto Drainers vs European Tax Authorities) | https://www.group-ib.com/blog/declaration-trap/ | T1 | Primary reference for the Belastingdienst / MijnOverheid / Elster / DGFiP crypto drainer cluster. Inferno Drainer attribution. Multi-country expansion through 2026. | | Group-IB — Crypto Wallet Drainers Knowledge Hub | https://www.group-ib.com/resources/knowledge-hub/crypto-wallet-drainers/ | T1 | Reference resource on the drainer-as-a-service ecosystem. | | Recorded Future — Rublevka Team Crypto Drainer | https://www.recordedfuture.com/research/rublevka-team-anatomy-russian-crypto-drainer-operation | T1 | Operator-cluster anatomy; complements Group-IB's external-facing reports. | | Trend Micro — InstallFix and Claude Code | https://www.trendmicro.com/en_us/research/26/e/installfix-and-claude-code.html | T1 | Primary May 5 2026 report on the Claude.ai shared-chat malvertising campaign delivering Amatera infostealer. | | Bitdefender Labs — Fake Claude Code Google Ads | https://www.bitdefender.com/en-us/blog/labs/fake-claude-code-google-ads-malware | T1 | Independent confirmation of the InstallFix / MacSync Mac and Windows campaign. | | Push Security — InstallFix: Weaponizing Malvertised Install Guides | https://pushsecurity.com/blog/installfix | T1 | Identity-and-access perspective on the ClickFix → InstallFix evolution. | | AdGuard — Claude-linked Google ads dupe macOS users | https://adguard.com/en/blog/claude-google-ads-malware-poisoning-macos.html | T1 | Useful ad-blocker telemetry-based confirmation. | | Halcyon — ShinyHunters Extortion Campaign Against Instructure | https://www.halcyon.ai/ransomware-alerts/education-sector-in-the-crosshairs-shinyhunters-extortion-campaign-against-instructure | T1 | Threat intel on the Canvas / Instructure breach group; useful for breach-driven phishing context. | | Bitdefender — Technical Advisory: ShinyHunters Breach of Instructure Canvas LMS | https://businessinsights.bitdefender.com/technical-advisory-shinyhunters-breach-instructure-canvas-lms | T1 | Defender-side advisory; relevant to education-sector phishing wave reporting. | | Rescana — ShinyHunters Free-For-Teacher Second Wave | https://www.rescana.com/post/shinyhunters-launches-second-major-attack-on-instructure-canvas-lms-via-free-for-teacher-accounts-may-2026-breach-analys/ | T1 | Documentation of the May 7 2026 secondary attack via Free-For-Teacher accounts. | | Inside Higher Ed — Pay or Leak: Higher Ed Vendor | https://www.insidehighered.com/news/tech-innovation/administrative-tech/2026/05/05/pay-or-leak-hackers-target-big-higher-ed-vendor | T1 | Higher-ed sector reporting on Canvas breach; cites institutional response. | | Norton — Reservation Hijack Scam | https://us.norton.com/blog/online-scams/reservation-hijacking-scam | T1 | Definitional resource for the reservation hijack scam family. | | Gen Digital — Reservation Hijack Scam Research | https://www.gendigital.com/blog/insights/research/reservation-hijack-scam | T1 | Vendor-side research from Norton/Avast parent on the hotel-account hijack vector. | | Cybernews — Booking.com Phishing Scam: WhatsApp Payment Traps | https://cybernews.com/security/booking-com-scam-how-a-message-exposed-fraud/ | T1 | Specific reporting on WhatsApp-channel monetisation of the Booking.com breach data. | | Help Net Security — Booking.com Data Breach 2026 | https://www.helpnetsecurity.com/2026/04/14/booking-com-data-breach-customer-reservation-data-exposed/ | T1 | Primary breach disclosure reference. | | Malwarebytes — Booking.com Breach Gives Scammers What They Need | https://www.malwarebytes.com/blog/data-breaches/2026/04/booking-com-breach-gives-scammers-what-they-need-to-target-guests | T1 | Consumer-facing analysis tying breach to phishing wave. | | Tuta Blog — Booking.com Data Breach 2026 | https://tuta.com/blog/booking-com-hacked-user-data-exposed | T1 | Reservation-hijack scam awareness from privacy-focused vendor. | | TechCrunch — Booking.com confirms hackers accessed customers' data | https://techcrunch.com/2026/04/13/booking-com-confirms-hackers-accessed-customers-data/ | T1 | Original breach confirmation reporting. |
Tier 3 — European National / Operator Sources (New)
| Source | URL | Tier | Notes |
|--------|-----|------|-------|
| Safeonweb Belgium — SNCB fraudulent messages warning | https://safeonweb.be/en/news/warning-fraudulent-messages-circulating-name-sncb | T3 | CCB-operated Belgian phishing awareness; primary reference for Belgian SNCB twin phishing wave (May 2026). |
| Safeonweb Belgium — SNCB second alert | https://safeonweb.be/en/news/beware-fraudulent-messages-circulating-name-sncb | T3 | Follow-up Safeonweb alert. |
| SNCB-NMBS — Phishing FAQ | https://www.belgiantrain.be/en/support/faq/faq-privacy-data/faq-phishing | T3 | Operator-side phishing reporting page. |
| CCB Belgium — Phishing messages surge (2025 stats: ~10M reports) | https://ccb.belgium.be/news/phishing-messages-surge-safeonweb-receives-nearly-10-million-suspicious-alerts-2025 | T3 | Volume statistics for Belgian phishing reporting. |
| Brussels Times — Belgium launches campaign against phishing | https://www.brusselstimes.com/744855/its-in-the-details-belgium-launches-campaign-against-online-phishing | T1 (national press) | National media reporting on CCB / Safeonweb awareness work. |
| RailTech — SNCB ends onboard ticket sales (March 2026) | https://www.railtech.com/all/2026/03/31/belgian-railways-sncb-ends-onboard-ticket-sales-from-july-to-target-fraud-and-aggression-toward-staff/ | T1 / industry press | Context for why the SNCB fake-fine variant is currently effective. |
| Booking.com — Phishing reporting (phishing@booking.com) | https://www.booking.com/ | T3 / operator | Operator-side phishing reporting; publicly documented address. |
| Belastingdienst — Suspicious email reporting | https://www.belastingdienst.nl/wps/wcm/connect/nl/contact/content/u-hebt-een-verdachte-email-ontvangen | T3 | Dutch tax authority phishing reporting page (valse-email@belastingdienst.nl). |
| Fraudehelpdesk Netherlands | https://www.fraudehelpdesk.nl/ | T3 | National anti-fraud reporting hotline (088-786 7372). |
| SURF Netherlands — Education sector cybersecurity | https://www.surf.nl/ | T3 | Dutch education cooperative; coordinator for NL university Canvas-breach response. |
| Jisc UK — Education sector cybersecurity | https://www.jisc.ac.uk/ | T3 | UK education cooperative; coordinator for UK university Canvas-breach response. |
| HEAnet (Ireland) | https://www.heanet.ie/ | T3 | Irish education network; relevant for cross-border Canvas-breach incidents. |
| Revoke.cash | https://revoke.cash/ | Defender resource | Token approval revocation tool; essential post-incident remediation step for wallet drainer victims. |
Tier 1 — Late-Cycle Discovery
| Source | URL | Tier | Notes | |--------|-----|------|-------| | Krebs on Security — Canvas Breach Disrupts Schools & Colleges | https://krebsonsecurity.com/2026/05/canvas-breach-disrupts-schools-colleges-nationwide/ | T1 | Krebs investigation timeline on 8-month-long Instructure intrusion and May 1 / May 7 production exfiltration. | | The Hacker News — ClickFix Campaigns Spread MacSync (March 2026) | https://thehackernews.com/2026/03/clickfix-campaigns-spread-macsync-macos.html | T1 | Early-stage reporting on MacSync infostealer; precursor coverage to the May 2026 Claude.ai variant. | | TechRadar — Robinhood Phishing via Account Creation Flaw | https://www.techradar.com/pro/security/hackers-exploit-robinhood-account-creation-tool-to-launch-worrying-phishing-scam | T1 | Watchlist-only; novel email-injection phishing vector. | | ESET WeLiveSecurity — CallPhantom Android Scam | https://www.welivesecurity.com/en/eset-research/fake-call-logs-real-payments-how-callphantom-tricks-android-users/ | T1 | Watchlist-only for European coverage; primarily APAC-targeted (28 apps, 7.3M downloads). |
---
Sources Added — 2026-05-11 Intelligence Run (PM, second pass)
Tier 1 — Vendor / Research
| Source | URL | Tier | Notes | |--------|-----|------|-------| | Microsoft Security Blog — Breaking the code: Multi-stage 'code of conduct' phishing campaign leads to AiTM token compromise | https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/ | T1 | Primary technical reference for the "Code of Conduct" multi-stage AiTM phishing campaign (35,000 users / 26 countries, April 14–16 2026). | | Barracuda Blog — The 'code of conduct' phishing campaign: What MSPs need to know | https://blog.barracuda.com/2026/05/07/code-of-conduct-phishing-campaign-msp-response | T1 | MSP-side mitigation guidance; complementary to the Microsoft writeup. | | Help Net Security — Microsoft: Phishing campaign used fake compliance notices to compromise employee accounts | https://www.helpnetsecurity.com/2026/05/05/microsoft-phishing-fake-compliance-notices/ | T1 | Independent reporting on the Code of Conduct AiTM campaign with additional sector breakdown. | | Check Point Blog — 40,000 Phishing Emails Disguised as SharePoint and e-Signing Services | https://blog.checkpoint.com/email-security/40000-phishing-emails-disguised-as-sharepoint-and-and-e-signing-services-a-new-wave-of-finance-themed-scams/ | T1 | Finance-themed DocuSign/SharePoint cloud-impersonation wave; useful for cross-correlation with Microsoft research. | | AML Intelligence — Europol launches EU Anti-Scam Platform | https://www.amlintelligence.com/2026/05/latest-europol-launches-eu-anti-scam-platform-for-law-enforcement/ | T1 | Operational hub launch reporting (EAFCS 2026 Dublin); strategic context for European scam-fighting capacity. | | The Cyber Express — Europol Issues Warning Over New Scam Tactics | https://thecyberexpress.com/europol-issues-warning-over-new-scam-tactics/ | T1 | Detailed coverage of Europol-impersonation scam wave with named officials. |
Tier 3 — European National / Operator Sources
| Source | URL | Tier | Notes | |--------|-----|------|-------| | Safeonweb Belgium — Beware of phishing emails that lure you to a fake helpdesk | https://safeonweb.be/en/news/beware-phishing-emails-lure-you-fake-helpdesk | T3 | Primary May 5 2026 Belgian alert on TOAD callback phishing impersonating bank-security desks. | | Fraudehelpdesk Netherlands — top alerts (incl. AIVD/FBI impersonation) | https://www.fraudehelpdesk.nl/ | T3 | Top alert as of 7–8 May 2026: false AIVD / FBI emails asking citizens to assist with criminal investigations. | | Digiweerbaar — Cyber Dreigingsradar (NL threat-level monitor) | https://www.digiweerbaar.nl/dreigingsradar | T3 | Daily-updated Netherlands-Belgium consumer cyber threat radar; useful as a Tier 3 confirmation signal. | | AIVD — Cybersecurity advisory: phishing via Signal/WhatsApp | https://english.aivd.nl/documents/2026/03/09/cybersecurity-advisory.-phishing-via-messaging-apps-signal-and-whatsapp | T1 | Dutch intelligence service's English-language advisory on state-impersonation phishing via messaging apps. | | Europol — Beware of scams involving fake correspondence from Europol | https://www.europol.europa.eu/operations-services-and-innovation/public-awareness-and-prevention-guides/beware-scams-involving-fake-correspondence-europol | T1 | Ongoing Europol-impersonation campaign reference; updated for 2026 wave. |
Tier 2 — Travel / Marketplace Research
| Source | URL | Tier | Notes | |--------|-----|------|-------| | Travel And Tour World — Airbnb AI-generated listings warning (UK/EU) | https://www.travelandtourworld.com/news/article/london-edinburgh-thailand-indonesia-mexico-and-manchester-airbnb-issues-urgent-warning-on-rising-holiday-rental-scams-ai-generated-listings-trick-tourism-costing-victims-thousands/ | T2 | Documentation of AI-generated synthetic-listing fraud across London, Edinburgh, Manchester, Paris, Barcelona, Rome with Airbnb / Get Safe Online research. | | Travel And Tour World — Summer Travel Scam Warning 2026 | https://www.travelandtourworld.com/news/article/summer-travel-scam-warning-2026-and-how-fake-bookings-phishing-emails-and-tourist-fraud-are-targeting-holidaymakers-all-you-need-to-know/ | T2 | Pan-European summer holiday fraud summary; useful seasonal reference. | | AirROI — Airbnb Terms of Service April 20 2026: AI Evidence Ban | https://www.airroi.com/blog/airbnb-april-20-2026-tos-update-ai-evidence-ban | T2 | Platform-level countermeasure documentation; primary reference for Airbnb's new AI-evidence ban in damage claims. | | Rental Scale-Up — AI Airbnb Scams: How Fake Images Are Fueling Disputes | https://www.rentalscaleup.com/ai-airbnb-scams-fake-damage-claims/ | T2 | Industry analysis of AI-generated fake damage claims by hosts; relevant to dual fraud direction. | | Get Safe Online (UK) | https://www.getsafeonline.org/ | T1 | UK consumer cyber-safety body; co-publishes Airbnb fraud research. |
Source tracker updated 2026-05-11 (PM). Added 16 new sources covering: Code of Conduct AiTM phishing campaign (Microsoft Security Blog, Barracuda, Help Net Security), DocuSign/SharePoint finance-themed phishing (Check Point), Europol EU Anti-Scam Platform launch (AML Intelligence, The Cyber Express), Belgian helpdesk callback fraud (Safeonweb), Dutch AIVD/FBI impersonation (Fraudehelpdesk, Digiweerbaar, AIVD English advisories), and AI-generated Airbnb listings fraud (Travel And Tour World, AirROI, Rental Scale-Up, Get Safe Online).Sources Added — 2026-05-18 Intelligence Run
Tier 1 — Government / National Authority
| Source | URL | Tier | Notes |
|---|---|---|---|
| NCSC Switzerland — Week 18 weekly review (Double phishing parcel scam) | https://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/2026/wochenrueckblick_18.html | T1 | Primary 05.05.2026 Swiss NCSC advisory on the "double phishing" parcel + bank-callback pattern. |
| NCSC Switzerland — Parcel link fraud campaign page | https://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/2026/kampagne-super-26-4.html | T1 | NCSC consumer awareness campaign companion to Week 18. |
| INCIBE — AVISO INCIBE-2026-329 (Lidl impersonation, 06.05.2026) | https://www.incibe.es/ciudadania/avisos/suplantan-al-lidl-traves-de-tiendas-online-fraudulentas | T1 | Spanish national cybersecurity institute high-importance advisory. |
| INCIBE — Caso real: Fraude masivo suplantando a Lidl | https://www.incibe.es/linea-de-ayuda-en-ciberseguridad/casos-reales/fraude-masivo-suplantando-lidl-con-falsos-descuentos-online | T1 | INCIBE consumer case-study companion to the AVISO. |
| GOV.UK — Pensioners urged to be alert to Winter Fuel Payment scams | https://www.gov.uk/government/news/pensioners-urged-to-be-alert-to-winter-fuel-payment-scams | T1 | HMRC's official public-awareness press release on the May 2026 wave. |
| HMRC newsroom — Pensioners urged to be alert (press wire) | https://hm-revenue-customs-hmrc.mynewsdesk.com/pressreleases/pensioners-urged-to-be-alert-to-winter-fuel-payment-scams-3442736 | T1 | HMRC press wire copy. |
| ICAEW — Over 25,000 winter fuel payment scam referrals made to HMRC | https://www.icaew.com/insights/tax-news/2026/apr-2026/over-25000-winter-fuel-payment-scam-referrals-made-to-hmrc | T1 | UK accountancy body confirming HMRC's April 2026 referral volume statistic. |
| MoneySavingExpert — Winter Fuel Payment clawback: 1.1m to get HMRC letter, text or email | https://www.moneysavingexpert.com/news/2026/03/winter-fuel-payment-hmrc-letter-scam/ | T1 | UK consumer-finance reference on policy and resulting scam vector. |
| PSR — Groundbreaking new protections for victims of APP scams | https://www.psr.org.uk/news-and-updates/latest-news/news/groundbreaking-new-protections-for-victims-of-app-scams-start-today/ | T1 | Statutory APP-fraud reimbursement-regime reference. |
| Polizia di Stato via Leggo — Truffa WhatsApp pedaggi autostradali (15.05.2026) | https://www.leggo.it/italia/cronache/15_maggio_2026_truffa_whatsapp_messaggi_pedaggi_autostradali-9534286.html | T1 | Polizia di Stato's 15 May 2026 advisory carried via national press. |
| Gazzetta del Sud — Finto messaggio sul mancato pagamento del pedaggio (15.05.2026) | https://gazzettadelsud.it/articoli/cronaca/2026/05/15/finto-messaggio-sul-mancato-pagamento-del-pedaggio-in-autostrada-e-una-truffa-9b1e7459-3beb-4847-a9cf-72e33960e98e/ | T1 | Italian national-press confirmation of the toll-scam wave. |
| Marks & Spencer — Corporate Cyber Update | https://corporate.marksandspencer.com/cyber-update | T1 | Official corporate breach disclosure page. |
| Marks & Spencer — Customer Cyber Incident Update | https://www.marksandspencer.com/help-and-support/cyber-incident-update | T1 | Customer-facing breach disclosure page. |
Tier 1 — Vendor / Industry Research
| Source | URL | Tier | Notes |
|---|---|---|---|
| ComputerWeekly — M&S forces customer password resets after data breach | https://www.computerweekly.com/news/366623565/MS-forces-customer-password-resets-after-data-breach | T1 | UK enterprise-trade-press reference on 13 May 2026 password-reset announcement. |
| Bitdefender Hot for Security — M&S Confirms Customer Data Was Stolen | https://www.bitdefender.com/en-us/blog/hotforsecurity/marks-spencer-confirms-customer-data-was-stolen-in-ransomware-attack-heres-what-you-need-to-know | T1 | Vendor breach analysis with consumer guidance. |
| BlackFog — Marks & Spencer Breach | https://www.blackfog.com/marks-and-spencer-ransomware-attack/ | T1 | Technical incident-response writeup. |
| ID Agent — Marks & Spencer Cyberattack | https://www.idagent.com/blog/marks-spencer-breach-proves-that-even-it-experts-can-be-fooled/ | T1 | Threat-intel commentary on Scattered Spider help-desk social engineering. |
| Cybernews — M&S confirms month-long breach result of third-party vendor phishing attack | https://cybernews.com/news/marks-spencer-breach-tcs-third-party-vendor-social-engineering-attack/ | T1 | Third-party vendor compromise context. |
| CM Alliance — Marks and Spencer Cyber Attack Everything You Need to Know | https://www.cm-alliance.com/cybersecurity-blog/the-marks-and-spencer-cyber-attack-everything-you-need-to-know | T1 | Comprehensive breach timeline. |
| CyberSecurity Insiders — Scam Messages and emails increase exponentially after M&S Cyber Attack | https://www.cybersecurity-insiders.com/scam-messages-and-emails-increase-exponentially-after-m-s-cyber-attack/ | T1 | Direct confirmation of post-breach phishing wave. |
Tier 3 — Regional / Sector Sources
| Source | URL | Tier | Notes |
|---|---|---|---|
| CSIRT-CV — Suplantación de LIDL a través de tiendas online fraudulentas | https://csirtcv.gva.es/suplantacion-de-lidl-a-traves-de-tiendas-online-fraudulentas/ | T3 | Valencia regional CSIRT mirror of the INCIBE advisory with additional regional commentary. |
| OCU — Cuidado: tiendas online falsas suplantando a Lidl | https://www.ocu.org/tecnologia/ciberseguridad/noticias/suplantacion-lidl | T3 | Spanish consumer-protection organisation's parallel May 2026 warning. |
| Autostrade per l'Italia — Campagna phishing | https://www.autostrade.it/en/campagna-phishing | T3 | Italian motorway concessionaire's official phishing advisory page. |
| Canale Dieci — Truffa del pedaggio (video) | https://canaledieci.it/2026/05/15/truffa-del-pedaggio-cosi-i-pirati-informatici-svuotano-i-conti-con-il-finto-messaggio-di-autostrade-video/ | T3 | Italian video explainer; useful for cross-confirmation. |
| Geopop — Nuova truffa WhatsApp sul pedaggio autostradale non pagato | https://www.geopop.it/nuova-truffa-whatsapp-sul-pedaggio-autostradale-non-pagato-come-riconoscerla/ | T3 | Italian consumer-tech outlet explainer. |
| Smartworld — Truffa WhatsApp pedaggi autostradali | https://www.smartworld.it/news/truffa-whatsapp-pedaggi-autostradali-phishing.html | T3 | Italian tech press confirmation. |
| JoinTheClaim — Warning to M&S customers following cyberattack | https://jointheclaim.com/warning-to-ms-customers-watch-out-for-scams-following-cyberattack/ | T3 | UK consumer-advisory legal firm's M&S scam warning. |
| Martin Milner & Co — Winter Fuel Payment scams – Beware | https://www.martinmilner.co.uk/2026/05/07/winter-fuel-payment-scams-beware/ | T3 | UK chartered-accountant advisory; sector awareness signal. |
| KJ Pittalis — Pensioners Urged To Be Alert | https://www.kjpcca.com/2026/04/pensioners-urged-to-be-alert-to-winter-fuel-payment-scams | T3 | UK accountancy advisory. |
| Kingscott Dix — Winter Fuel Payment scams – Beware | https://kingscott-dix.co.uk/2026/05/07/winter-fuel-payment-scams-beware/ | T3 | Gloucester chartered accountants advisory. |
| SJPR UK — Beware Winter Fuel Payment scams | https://sjpr.co.uk/beware-winter-fuel-payment-scams/ | T3 | UK accountancy advisory. |
| Keates & Co — Beware Winter Fuel Payment scams | https://www.keatesandco.com/beware-winter-fuel-payment-scams/ | T3 | UK accountancy advisory. |
Tier 4 — Press / Consumer Coverage
| Source | URL | Tier | Notes |
|---|---|---|---|
| El Independiente — Incibe advierte de una campaña fraudulenta que imita a Lidl | https://www.elindependiente.com/espana/2026/05/06/incibe-advierte-de-una-campana-fraudulenta-que-imita-a-lidl-con-precios-sospechosamente-bajos/ | T4 | Spanish national press confirmation of INCIBE-2026-329. |
| Diario de Avisos — Alerta estafa suplantación Lidl | https://diariodeavisos.elespanol.com/2026/05/alerta-estafa-suplantacion-lidl/ | T4 | Spanish regional press confirmation. |
| Última Hora — Aviso urgente del INCIBE: estafadores se hacen pasar por Lidl | https://www.ultimahora.es/xaloc/dudas-respuestas/2026/05/13/2625703/aviso-urgente-del-incibe-suplantan-agencia-tributaria-para-cobrar-reclamaciones-falsas.html | T4 | Spanish press cross-confirmation. |
| Andalucía Informa — INCIBE alerta de falsas tiendas online | https://andaluciainforma.eldiario.es/actualidad/incibe-alerta-de-falsas-tiendas-online-que-se-hacen-pasar-por-lidl-para-quedarse-con-tu-dinero/ | T4 | Spanish regional press cross-confirmation. |
| QuiFinanza — Truffa del finto pedaggio autostrade 2026 | https://quifinanza.it/info-utili/truffa-finto-pedaggio-autostrade-2026/956747/ | T4 | Italian consumer-finance press. |
---
Run Additions — 2026-05-22 (scam-report-2026-05-22)
New sources discovered during the 22 May 2026 research run. Added per the "append new sources as discovered" convention.
Tier 1 — Official / Authority
| Source | URL | Notes | |--------|-----|-------| | Deutsche Rentenversicherung — Warnung vor Phishing-Mails im Stil der DRV | https://www.deutsche-rentenversicherung.de/DRV/DE/Ueber-uns-und-Presse/Presse/Meldungen/2026/260213-vorsicht_phishing_mails.html | German state pension authority's official phishing-impersonation advisory; explicitly flags AI-polished fake pages | | Verbraucherzentrale — Phishing-Radar (Aktuelle Warnungen) | https://www.verbraucherzentrale.de/wissen/digitale-welt/phishingradar/phishingradar-aktuelle-warnungen-6059 | German consumer federation live phishing warnings; primary German consumer reporting channel (phishing@verbraucherzentrale.nrw) | | Verbraucherzentrale NRW — Phishing von Behörden | https://www.verbraucherzentrale.nrw/wissen/digitale-welt/phishingradar/betrug-phishingmails-und-falsche-sms-von-ministerien-und-behoerden-76907 | NRW regional consumer body; authority-impersonation phishing tracking | | INCIBE — Casos Reales (Línea de Ayuda en Ciberseguridad) | https://www.incibe.es/linea-de-ayuda-en-ciberseguridad/casos-reales | Spanish national cybersecurity institute case-study series; documented the El Hormiguero AI vishing case | | FCA — Alert for firms: fake FCA communications | https://www.fca.org.uk/firms/alert-firms-fake-fca-communications | UK financial regulator's standing alert page on FCA-impersonation fraud | | NatWest — Report fraud / Security Centre | https://www.natwest.com/fraud-and-security/report-fraud.html | UK bank official fraud-reporting and scam-warning hub | | ATAC (Roma) — News e iniziative | https://www.atac.roma.it/media/news-e-iniziative | Rome transport operator official channel; issues anti-phishing disavowals (Tap&Go fake SMS) | | Polizia Postale — Commissariato di PS Online (notizie) | https://www.commissariatodips.it/notizie/index.html | Italian postal/communications police news and reporting portal |Tier 2 — Threat Intelligence & Research
| Source | URL | Notes | |--------|-----|-------| | Guardio Labs | https://guard.io/labs | Browser-security research team; strong on malvertising, search-ad abuse and AitM phishing (uncovered the ManageWP Google Ads campaign) | | TechRadar Pro — Security | https://www.techradar.com/pro/security | Mainstream tech press security desk; reliable secondary confirmation for research-led campaigns | | GBHackers | https://gbhackers.com | Security research aggregator; fast on phishing/credential-theft campaigns | | Cyber Security News | https://cybersecuritynews.com | Security research aggregator; secondary confirmation source |Tier 3 — European National / Consumer
| Source | URL | Notes | |--------|-----|-------| | Cyber Security Italia | https://www.cybersecitalia.it | Italian security news outlet; carries Polizia Postale alerts in full | | Adiconsum | https://adiconsum.it | Italian consumer association; issues member scam warnings (Tap&Go phishing) | | Identity Week | https://identityweek.net | Identity/biometrics industry press; useful for biometric-policy context behind bank-impersonation scams |Tier 4 — Press / Aggregators (cross-confirmation only)
| Source | URL | Notes | |--------|-----|-------| | ms-aktuell.de | https://ms-aktuell.de | German news outlet; consolidated reporting on the May 2026 GEZ/Rente/Deutschlandticket phishing wave | | wmn.de | https://www.wmn.de | German consumer-news outlet; phishing explainers (GEZ, DRV) |Added 2026-06-01
| Source | URL | Tier | Discovery Context / Notes | |--------|-----|------|---------------------------| | FBI IC3 Public Service Announcements (PSA) | https://www.ic3.gov/PSA | Tier 1 | Direct PSA archive; PSA I-052126-PSA (Kali365) found here. Check per-run for fresh PSAs. | | Help Net Security | https://www.helpnetsecurity.com | Tier 1 | Fast, reliable enterprise threat reporting; covered Kali365 device-code phishing. | | Cybersecurity Dive | https://www.cybersecuritydive.com | Tier 1 | Industry/enterprise security news; good for FBI/CISA advisory write-ups. | | Cyber Daily (AU) | https://www.cyberdaily.au | Tier 1 | APAC security news; useful cross-region corroboration. | | ANY.RUN Cybersecurity Blog | https://any.run/cybersecurity-blog/ | Tier 2 | Monthly "Major Cyber Attacks" round-ups with sandbox IOCs (BlobPhish, Agent Tesla, fake-invitation campaigns). | | Official EU ETIAS / EES portal | https://travel-europe.europa.eu/etias_en | Tier 1 | Authoritative source for ETIAS status/fees; the only legitimate ETIAS domain (europa.eu). | | UK ETA official guidance | https://www.gov.uk/electronic-travel-authorisation | Tier 1 | Only legitimate UK ETA route; baseline for spotting look-alike sites. | | Euronews Travel | https://www.euronews.com/travel | Tier 1 | Reputable EU media; strong on ETIAS/EES traveller-scam coverage. | | Travel And Tour World | https://www.travelandtourworld.com | Tier 3 | Travel-industry trade outlet; aggregates ETIAS/ETA scam surges (corroborate before deep-dive). | | Insurte — Travel Guide | https://insurte.com/travel-guide/ | Tier 3 | Consumer travel guidance; useful for fake-ETIAS red flags. | | Agenzia delle Entrate — Avvisi (phishing alerts) | https://www.agenziaentrate.gov.it/portale/avvisi | Tier 1 | Italian tax authority phishing advisories (SPID credential theft, 2026). | | Adiconsum | https://adiconsum.it | Tier 3 | Italian consumer association; SPID and transit-fare scam alerts. | | PMI.it | https://www.pmi.it | Tier 3 | Italian SME/economy outlet; SPID-fraud explainers. | | BusinessOnline.it | https://www.businessonline.it | Tier 3 | Italian explanatory pieces on multiple-SPID risk. | | INCIBE — Ciudadanía Avisos | https://www.incibe.es/ciudadania/avisos | Tier 1 | Spanish national CERT citizen alerts; AEAT smishing campaigns (May 2026). Línea de Ayuda 017. | | El Independiente — Sociedad | https://www.elindependiente.com/sociedad/ | Tier 1 | Spanish media; AEAT smishing alert (26 May 2026). | | Fraudehelpdesk (NL) — Valse e-mail archief | https://www.fraudehelpdesk.nl/valse-email/ | Tier 3 | Dutch fraud-report desk; running catalogue of live fake-email/SMS lures (RVO, Booking, Bol.com, gerechtsdeurwaarder, ETA/visa). |
---
New Sources Added — 2026-06-05 Run
| Source | URL | Tier | Notes | |--------|-----|------|-------| | CERT-AGID (Italy national CERT) — News/Avvisi | https://cert-agid.gov.it/news/ | Tier 1 | Italian government CERT; smishing/phishing campaign alerts (INPS bonus carburante wave). Tracks rotating domains. | | Malwarebytes Threat Intelligence | https://www.malwarebytes.com/blog/threat-intel | Tier 1 | Malware/malvertising threat-intel feed; source of fake-ChatGPT download/Odyssey Stealer analysis. | | ThreatLocker Blog | https://www.threatlocker.com/blog | Tier 1 | Endpoint/threat research; LLMShare ChatGPT share-link malware campaign. | | Verbraucherzentrale — Phishing-Radar (aktuelle Warnungen) | https://www.verbraucherzentrale.de/wissen/digitale-welt/phishingradar/phishingradar-aktuelle-warnungen-6059 | Tier 1 | Live German consumer phishing warnings (Sparkasse / VR-SecureGo waves). | | Which? Conversation | https://conversation.which.co.uk | Tier 1 | UK consumer body fraud warnings (DVLA car-tax scam). | | MoneyHelper (UK) | https://www.moneyhelper.org.uk | Tier 1 | UK government-backed guidance; DVLA scam how-to-spot. | | Red Hot Cyber | https://www.redhotcyber.com | Tier 3 | Italian security media; corroboration for CERT-AGID INPS alerts. | | CyberSecItalia | https://www.cybersecitalia.it | Tier 3 | Italian security media; INPS smishing corroboration. | | TechTimes | https://www.techtimes.com | Tier 3 | Tech media; ChatGPT share-link malware reporting (01 Jun 2026). | | Hackread | https://hackread.com | Tier 3 | Security media; fake ChatGPT desktop-app ad campaigns. | | ad-hoc-news.de | https://www.ad-hoc-news.de | Tier 3 | German finance/news aggregation; Sparkasse S-pushTAN phishing wave corroboration. | | Watson.de | https://www.watson.de | Tier 3 | German media; Volksbank VR-SecureGo phishing corroboration. | | GB News (Lifestyle/Cars) | https://www.gbnews.com | Tier 3 | UK media; DVLA car-tax scam volume/victim reporting (corroborate). | | lovemoney | https://www.lovemoney.com | Tier 3 | UK consumer media; DVLA "vehicle tax recalculation" scam write-up. | | Finans Norge — Svindel | https://www.finansnorge.no/tema/okonomisk-kriminalitet/svindel/ | Tier 3 | Norwegian banking-sector fraud status reports (watchlist monitoring: BankID/Vipps). |
Added 2026-06-15
| Source | URL | Tier | Discovery Context | |--------|-----|------|-------------------| | UK Finance — Fraud reports & data | https://www.ukfinance.org.uk/policy-and-guidance/reports-and-publications | Tier 1 | UK banking-sector fraud statistics; cited for OTP-enabled digital-wallet provisioning and remote-purchase fraud growth (Ghost Tap / wallet deep-dive). | | City of London Police — News / Action Fraud alerts | https://www.cityoflondon.police.uk/news/ | Tier 1 | UK national lead force for fraud; June 2026 alert on 323% spike in Argos-related account-takeover reports. | | Group-IB — Blog | https://www.group-ib.com/blog/ | Tier 1 | Threat research; "Ghost-Tapped" Chinese tap-to-pay Android malware ecosystem. | | Recorded Future — Research | https://www.recordedfuture.com/research | Tier 1 | Threat research; ghost-tapping Chinese cybercriminal retail-fraud ecosystem. | | Cleafy — Labs | https://www.cleafy.com/labs | Tier 1 | Mobile banking-malware research; first detailed SuperCard X NFC-relay malware (Italy). | | Infosecurity Magazine | https://www.infosecurity-magazine.com | Tier 1 | Security media; Ghost Tap remote NFC payment-fraud surge. | | Google — Safety & Security Blog | https://blog.google/innovation-and-ai/technology/safety-security/ | Tier 1 | Vendor anti-scam advisories and civil action (Outsider Enterprise PhaaS; June 2026 frauds & scams advisory). | | UKNIP (UK News in Pictures) | https://uknip.co.uk | Tier 3 | UK regional/crime media; Argos account-takeover corroboration. | | Daily Post / Reach plc regional titles | https://www.dailypost.co.uk | Tier 3 | UK regional media; Argos warning corroboration. | | schieb.de (Jörg Schieb) | https://www.schieb.de | Tier 3 | German digital/AI consumer media; OpenAI invoice & bank phishing (June 2026). | | Cyble — Blog | https://cyble.com/blog | Tier 3 | Threat-intel media; FIFA World Cup 2026 scam surge (watchlist). | | paymentexpert.com | https://paymentexpert.com | Tier 3 | Payments-sector media; tap-to-pay / NFC remote-fraud context. |
Added 2026-06-25
| Source | URL | Category | Discovery Context | |--------|-----|----------|-------------------| | Hellenic Police (Astynomia) — announcements | https://www.astynomia.gr | Tier 1 — Government/Law Enforcement | National police of Greece; source of the fake-Europol "JUDICIAL ORDER" CSAM-accusation email warning (relayed via ProtoThema/HellaZ, June 2026). | | ProtoThema English | https://en.protothema.gr | Tier 3 — News media (Greece) | English-language Greek news; relayed Hellenic Police phishing announcement (22 Jun 2026). | | HellaZ.EU.News | https://hellaz.eu | Tier 3 — News aggregator (Greece/EU) | Corroborated Hellenic Police fake-Europol email warning. | | CERT-AGID | https://cert-agid.gov.it | Tier 1 — National CERT (Italy) | Italian government CERT; primary source for the 19 Jun 2026 Agenzia delle Entrate crypto/wealth adaptive phishing→vishing campaign and ongoing IT phishing/PEC trend data. | | Matrice Digitale | https://www.matricedigitale.it | Tier 3 — News media (Italy) | Italian security/tech media; covered CERT-AGID Agenzia Entrate crypto phishing. | | Help Consumatori | https://www.helpconsumatori.it | Tier 3 — Consumer media (Italy) | Italian consumer-protection news; corroborated Agenzia Entrate crypto phishing. | | CNIL — Commission Nationale de l'Informatique et des Libertés | https://www.cnil.fr | Tier 1 — Regulator (France, data protection) | French DPA; alert on fake "data protection association" recovery scam exploiting breach-leaked PII (name/address/IBAN), June 2026. | | Cybermalveillance.gouv.fr — Lettre d'information | https://www.cybermalveillance.gouv.fr/tous-nos-contenus/lettre-information-juin-2026 | Tier 1 — Government (France) | Monthly newsletter/barometer; June 2026 issue covers CNIL data-breach recovery scam + +78% fake-bank-advisor vishing and direct-debit fraud. | | Clubic | https://www.clubic.com | Tier 3 — Tech/consumer media (France) | French media; detailed the fake data-protector recovery scam. | | Kaspersky Securelist | https://securelist.com | Tier 1 — Threat research | Kaspersky research blog; primary report on the WhatsApp VBScript → ManageEngine RMM malware campaign (June 2026). | | INCIBE — Avisos de seguridad | https://www.incibe.es | Tier 1 — National cyber center (Spain) | Spanish citizen security alerts; AEAT phishing INCIBE-2026-165 (watchlist) and 2026 social-engineering guidance. |
Added 2026-06-29
| Source | URL | Category | Discovery Context | |--------|-----|----------|-------------------| | Signal-Arnaques (actualités/flash) | https://info.signal-arnaques.com | FR community scam reporting (Tier 3) | Running tracker for the French €69 "subscription/IBAN" prélèvement wave and the heatwave "EpiCooler" fake-AC scams (Flash Arnaques 23 Jun 2026). | | CES de France | https://www.cesdefrance.fr | FR consumer-finance media (Tier 4) | Detailed reporting on the €69 IBAN/BIC-in-the-email prélèvement phishing. | | Le Tribunal du Net | https://www.letribunaldunet.fr | FR tech/consumer news (Tier 4) | Coverage of the €69 fake direct-debit phishing using real banking data. | | NR Magazine | https://www.nrmagazine.com | FR consumer media (Tier 4) | Mechanics of the €69 prélèvement scam (since 15 Jun 2026). | | Online-Sicher | https://online-sicher.de | DE scam-warning aggregator (Tier 4) | German 2026 phishing/SMS/fake-shop warnings, incl. ELSTER tax-refund lure. | | Nord24 | https://www.nord24.de | DE regional news (Tier 3) | Sparkasse phishing-mail warnings (email→fake-site→call chain). | | MalwareTips (blogs) | https://malwaretips.com | Consumer scam/product-fraud breakdowns (Tier 3) | EpiCooler "mini fan sold as portable AC" exposé. | | Online Threat Alerts | https://www.onlinethreatalerts.com | Scam/product-fraud aggregator (Tier 4) | EpiCooler scam review/corroboration. | | Google — Fraud & Scams Advisory | https://blog.google/innovation-and-ai/technology/safety-security/ | Vendor Trust & Safety advisory (Tier 1) | Periodic Google fraud advisories; June 2026 edition named calendar-invite phishing, AITM, ClickFix. | | Techlicious | https://www.techlicious.com | Consumer-tech security media (Tier 3) | Google Calendar invoice-phishing explainer. | | KnowBe4 Blog | https://blog.knowbe4.com | Security-awareness vendor research (Tier 2) | Calendar-invite phishing / phony subscription notices. | | Security Journal UK | https://securityjournaluk.com | UK security media (Tier 3) | 2026 AI-phishing and NHS-impersonation reporting. | | NHS Fraud and Security Management Service | https://nhsfraudandsecurity.co.uk | UK health-sector counter-fraud (Tier 1) | NHS fraudulent-email guidance; staff/patient credential-phishing. | | Report Fraud (City of London Police) | https://www.reportfraud.police.uk | UK official fraud reporting (Tier 1) | National fraud/cybercrime reporting service that replaced Action Fraud from Dec 2025. |
Added 2026-07-06
| Source | URL | Category | Discovery Context | |--------|-----|----------|-------------------| | Moncloa | https://www.moncloa.com | ES national news (Tier 3) | Reported the joint Guardia Civil/INCIBE alert on fake summer lifeguard-job WhatsApp mule recruitment (1 Jul 2026). | | Qué! (que.es) | https://www.que.es | ES consumer news (Tier 3) | INCIBE WhatsApp scam-wave coverage; "your job application was approved" SMS mule campaign (active from 1 Jul 2026); DGT fine-smishing. | | Verbraucherschutzforum Berlin | https://verbraucherschutzforum.berlin | DE consumer-protection forum (Tier 4) | Detailed writeup of the fake "Sommer-Klimabeihilfe" Finanzministerium phishing wave (3 Jul 2026). | | Diebewertung | https://www.diebewertung.de | DE consumer/review media (Tier 4) | "Sommer-Klimabeihilfe" fake federal climate-aid phishing warning. | | ad-hoc-news | https://www.ad-hoc-news.de | DE news wire (Tier 4) | Tracked the July 2026 German phishing wave (Klimabeihilfe; Sparkasse/Volksbank/Postbank; AI-phishing share). | | Polizia Postale / Commissariato di P.S. Online | https://www.commissariatodips.it | IT national police cyber unit (Tier 1) | Official alert on cloned travel-agency sites with real VAT numbers/recycled phone numbers (summer 2026); also fine-smishing and SIM-swap alerts. | | CyberSecItalia | https://www.cybersecitalia.it | IT security media (Tier 3) | Amplified Polizia Postale fake-travel-agency and other summer 2026 alerts. | | NovaraToday | https://www.novaratoday.it | IT regional news (Tier 3) | Fake travel-agency clone-site summer scam reporting. | | MisterGadget | https://www.mistergadget.tech | IT consumer-tech media (Tier 4) | "Truffe agenzie di viaggio estate 2026" Polizia Postale coverage. | | Città della Spezia | https://www.cittadellaspezia.com | IT regional news (Tier 3) | Polizia Postale holiday-scam alert (bargain prices, fake sites, online-only payment), 10 Jun 2026. | | GBHackers | https://gbhackers.com | Security news (Tier 3) | 2026 FIFA World Cup fake-reward credit-card phishing writeup citing Unit 42; World Cup malicious-domain tracking. | | Unit 42 (Palo Alto Networks) | https://unit42.paloaltonetworks.com | Vendor threat intelligence (Tier 1) | Disclosed geo-cloaked FIFA World Cup reward-phishing credit-card-theft chain (5 Jul 2026). | | CyberInsider | https://cyberinsider.com | Security news (Tier 2) | FBI/CISA Signal backup-recovery-key phishing; $10M Rewards for Justice bounty. | | TechTimes (security) | https://www.techtimes.com | Consumer-tech news (Tier 3) | FBI naming of UNC5792/UNC4221 and bounty for Signal backup-key campaign. | | Bitdefender — HotforSecurity (summer travel scams) | https://www.bitdefender.com/en-us/blog/hotforsecurity | Vendor consumer security blog (Tier 2) | 2026 summer travel-scam roundup; WhatsApp hotel-impersonation phishing across 10+ countries. |
New Sources Added — 2026-07-20 Run
| Source | URL | Tier | Notes | |--------|-----|------|-------| | Nkom (Nasjonal kommunikasjonsmyndighet, Norway) | https://nkom.no/svindel | Tier 3 | Norwegian telecom regulator; excellent seasonal fraud-trend advisories and CLI-spoofing / "digital shield" statistics. Runs Norway's expert group against digital fraud. | | Finanstilsynet — Markedsadvarsler (Norway) | https://www.finanstilsynet.no/markedsadvarsler | Tier 3 | Norwegian FSA investment/market-warning database; check-before-you-invest resource. | | Leicestershire Police — News | https://www.leics.police.uk/news/leicestershire/news/ | Tier 3 | UK regional force; carried the June 2026 national courier-fraud campaign detail and per-force loss figures. | | Newtral (Spain) | https://www.newtral.es/ | Tier 1 (fact-checking) | Spanish fact-checking org; useful for confirming/debunking viral impersonation letters (e.g. fake Director General police letter, July 2026). | | Okta Threat Intelligence | https://www.okta.com/blog/threat-intelligence/ | Tier 1 | IAM vendor threat-intel blog; detailed reporting on vishing/passkey-enrollment and phishing-kit tradecraft (O-UNC-066 "Pink"). | | Help Net Security | https://www.helpnetsecurity.com/ | Tier 1 | Infosec news; timely amplification of vendor advisories (Apple FaceTime scam, AI voice-phishing research). | | Commissariato di P.S. Online (Polizia Postale, Italy) | https://www.commissariatodips.it/ | Tier 3 | Italian State Police online reporting portal; publishes frequent scam alerts (frequently impersonated brand itself). | | CyberSecurity Italia | https://www.cybersecitalia.it/ | Tier 1 | Italian infosec news outlet; reliable coverage of Polizia Postale phishing alerts. | | Nyheter24 / Newsner (Sweden) | https://polisen.se/aktuellt/nyheter/ | Tier 3 | Use Polisen.se directly for Swedish police fraud-wave warnings (elderly-targeting call fraud, July 2026). |
New Sources Added — 2026-07-23 Run
| Source | URL | Tier | Notes | |--------|-----|------|-------| | CCPC (Competition and Consumer Protection Commission, Ireland) | https://www.ccpc.ie/news-and-media/news/ | Tier 3 | Irish national consumer authority; issued the June 2026 warning on EU customs-charge scams ahead of the 1 July rule change. Good for Ireland-specific consumer fraud alerts. | | RTÉ News | https://www.rte.ie/news/ | Tier 3 | Irish national broadcaster; reliable amplification of CCPC/Revenue/An Post scam warnings, with useful explainers (customs charges Q&A). | | TheJournal.ie | https://www.thejournal.ie/ | Tier 3 | Irish news site with fact-checking arm; covered the 1 July 2026 customs rules and associated scam risk. | | SVT Nyheter | https://www.svt.se/nyheter/ | Tier 3 | Swedish national broadcaster; carried the Polisen/Noa warning (18 Jul 2026) on scammers using leaked travel-booking data. Good conduit for Swedish police fraud warnings. | | TV4 Nyheterna | https://www.tv4.se/ | Tier 3 | Swedish broadcaster; parallel coverage of the travel-booking smishing warning. | | Säkerhetskollen | https://sakerhetskollen.se/ | Tier 3 | Swedish security-awareness site (Stöldskyddsföreningen) tracking active SMS/phone fraud waves; complements Polisen.se. | | Ambtenaar Online | https://ambtenaar.online/nieuws/ | Tier 3 | Dutch public-sector professional outlet; detailed analysis of the "Gemeentelijke Energie Peiling 2026" municipal-impersonation phishing (2 Jul 2026). Useful for gemeente-level scam waves that national feeds miss. | | Gemeente Houten — nieuws | https://www.houten.nl/nieuws/ | Tier 3 | Example of municipal warning channel; Dutch gemeenten individually publish phishing warnings that aggregate into campaign visibility. | | Tout Sur Mes Finances | https://www.toutsurmesfinances.com/actualites/ | Tier 3 | French personal-finance media; timely summaries of Cybermalveillance.gouv.fr and DGFiP fraud alerts (July 2026 tax-refund phishing wave), with official calendar context. | | The Maker Depot — Weekly Scam Report | https://themakerdepot.com/ | Tier 4 | Weekly roundup of high-risk websites and fake-shop warnings; lead-generator only, confirm via Tier 1–3. |
New Sources Added — 2026-07-29 Run
| Source | URL | Tier | Notes | |--------|-----|------|-------| | Moncloa.com — Redes y Tecnología | https://www.moncloa.com/politica/redes-y-tecnologia/ | Tier 3 | Spanish national news outlet; reliable conduit for Guardia Civil / INCIBE fraud alerts. Carried the July 2026 wangiri one-ring missed-call resurgence warning (prefix rotation +234/+225/+233/+355/+216/+381). | | Huntress — Blog / Threat Research | https://www.huntress.com/blog | Tier 1 | US EDR vendor threat research. Named and dissected the FakeAgent campaign (fake Claude Desktop via Bing ads + Claude.ai Artifacts → DLL sideloading → SectopRAT; 29 orgs, 21–22 Jul 2026). | | NR-Kurier — Blaulicht | https://www.nr-kurier.de/thema/blaulicht | Tier 3 | German regional outlet republishing full Polizei press releases. Source for the Polizei Bonn dating-portal burglary-reconnaissance warning (24 Jul 2026). | | Whalebone Threat Intelligence | https://www.whalebone.io/post/ | Tier 2 | Telco/DNS-security vendor; intercepts courier-themed phishing infrastructure predominantly targeting European consumers via smishing. | | IT Security Guru | https://www.itsecurityguru.org/ | Tier 2 | UK infosec news; amplified FakeAgent reporting and Gen Digital's H1-2026 finding that scams accounted for ~46% of all threat detections. | | Signal-Arnaques — Flash Arnaques (daily bulletin) | https://info.signal-arnaques.com/actualites/ | Tier 3 | Daily French scam bulletin (Anthony Legros / ScamDoc). Detailed, sourced campaign tracking with victim testimony and IOCs; excellent for France-first fast-rotating phishing clusters (Xoom/PayPal, Duolingo, Prime Video S3, July 2026). |
New Sources Added — 2026-07-30 Run
| Source | URL | Tier | Notes | |--------|-----|------|-------| | Team Cymru / Will Thomas OSINT (GitHub gists) | https://gist.github.com/BushidoUK | Tier 1/2 | Threat-hunter IOC drops. Source of the 34+ brand-impersonation domain list for the fake-recruiter Google-account phishing campaign (Jul 2026). Reliable for infrastructure enrichment. | | Forbes — David Phelan (consumer tech) | https://www.forbes.com/sites/davidphelan/ | Tier 1 | Carries UK operator security statements verbatim; source for the O2 "Network Update" / SIM-expiry smishing warning (19 Jun 2026). | | British Brief — Tech/Telecoms | https://britbrief.co.uk/tech/telecoms/ | Tier 4 | UK consumer-tech news; amplified the O2 fake network-update smishing wave. Confirm via operator/Tier 1. Note: page returned intermittently empty on fetch. | | ISPreview UK | https://www.ispreview.co.uk/ | Tier 2 | UK ISP/telecoms news; carried Bitdefender's EE reward-points smishing analysis (Mar 2026). Good for operator-impersonation waves. | | Verbraucherschutzforum Berlin | https://verbraucherschutzforum.berlin/ | Tier 3 | German consumer-protection outlet; detailed writeup of the AOK Gesundheitskarte phishing wave (14 Jul 2026). | | KBvG (Koninklijke Beroepsorganisatie van Gerechtsdeurwaarders) | https://www.kbvg.nl/nieuws-en-opinie/ | Tier 3 | Dutch bailiffs' professional body; issues authoritative warnings on fake/non-existent bailiff-office emails. Use to verify whether an impersonated deurwaarder office is real. | | Hart van Nederland — Waarschuwen | https://www.hartvannederland.nl/advies-en-tips/waarschuwen/ | Tier 3 | Dutch broadcast consumer-warning channel; carried the Fraudehelpdesk Apple Pay/Google Pay wallet-provisioning fraud alert (Jul 2026). | | Kassa / BNNVARA | https://www.bnnvara.nl/kassa/ | Tier 3 | Dutch consumer-affairs programme; corroborated the digital-wallet contactless provisioning scam. | | Provinstidningen (Dalsland) | https://www.provinstidningen.se/ | Tier 4 | Swedish regional outlet republishing Polisen summer-fraud and "fysisk vishing" home-collection warnings. Confirm via polisen.se. |
New Sources Added — 2026-08-06 Run
| Source | URL | Tier | Notes | |--------|-----|------|-------| | Signal-Arnaques — Avis d'Expert (Anthony Legros / ScamDoc) | https://info.signal-arnaques.com/avis-dexpert/ | Tier 3 | French expert scam breakdowns with victim testimony and IOCs. Source for the Cellcast Vidéos fake-subscription IBAN phishing wave (1 Aug 2026), tied to Free/Bouygues Telecom breach data. Fast, detailed France-first coverage. | | CNews — Vie Numérique | https://www.cnews.fr/vie-numerique | Tier 3 | French national news outlet; amplified the Cellcast IBAN subscription-phishing warning (4 Aug 2026). Good mainstream corroboration for French phishing waves. | | Börse Express — Cybersecurity | https://www.boerse-express.com/news/ | Tier 3 | Austrian/German finance portal with a cybersecurity desk (partly AI-assisted, editorially reviewed). Consolidated the early-August German Verbraucherzentrale authority-impersonation phishing wave and the BKA "Kratos" PhaaS takedown. Confirm specifics against Verbraucherzentrale/BKA primary sources. | | SVT Nyheter Väst | https://www.svt.se/nyheter/lokalt/vast/ | Tier 3 | Swedish national broadcaster (regional desk). Carried the Polismyndigheten Region Väst warning on "fysisk vishing" (physical home-collection vishing), 3 Aug 2026, with named police spokesperson and 2025 vishing statistics. | | Proofpoint — Threat Insight (@threatinsight) | https://x.com/threatinsight | Tier 1 | Vendor threat-research feed; first-disclosed the COLDCARD "security audit" phishing → ScreenConnect RAT campaign (5 Aug 2026) with IOCs, chat-operator detail, and payload analysis. | | Cybernews — Security | https://cybernews.com/security/ | Tier 1 | Investigative cybersecurity outlet; exposed the Crédit Agricole phishing operation (stolen SendGrid/SES keys, S3 secret-scanning, operator leaderboard, 912 credential victims), published 5 Aug 2026. Strong for infrastructure/backend analysis of fraud panels. | | Telecinco — Sociedad | https://www.telecinco.es/noticias/sociedad/ | Tier 3 | Spanish national broadcaster; carried the Guardia Civil warning (5 Aug 2026) on mass brand-impersonation "survey" phishing (Shein/Zara/Decathlon lures). Watchlist candidate this run. |
New Sources Added — 2026-08-14 Run
| Source | URL | Tier | Notes |
|---|---|---|---|
| FSMA — Warnings (Belgium) | https://www.fsma.be/en/warnings | Tier 1 | Belgian Financial Services and Markets Authority. Publishes named warnings on unauthorised trading platforms and fraudulent websites — including domain-level IOCs. Source for the BitKeltTrade / cloned-Belgian-media investment fraud (10 Aug 2026). Should be checked every run alongside AMF, BaFin, CNMV, CONSOB, AFM, FCA. |
| La Libre — Mes Finances / Conjoncture (Belgium) | https://www.lalibre.be/economie/mes-finances/ | Tier 3 | Belgian francophone daily (IPM). Carries Belga wire copy of FSMA warnings and consumer-fraud alerts. Good first-line Belgian corroboration; note some articles are paywalled but lede and key facts usually render. |
| OCU — Compras online / noticias (Spain) | https://www.ocu.org/consumo-familia/compras-online/noticias | Tier 3 | Spain's largest independent consumer organisation. Publishes its own fraud complaints and product alerts; filed the criminal complaint over the "OzemPil" fake-Ozempic campaign (13 Aug 2026). Also the impersonated brand in that campaign — worth monitoring for repeat abuse of its logotype. |
| Redacción Médica — Sanidad Hoy (Spain) | https://www.redaccionmedica.com/politica/sanidad-hoy/ | Tier 3 | Spanish healthcare-sector news outlet. Strong for health-product fraud, fake pharmacy and counterfeit-medicine alerts — a consistently underreported vertical. Carried the OzemPil health alert (13 Aug 2026). |
| Qué.es — Tecnología (Spain) | https://www.que.es/tecnologia/ | Tier 3 | Spanish consumer news desk that reliably and quickly summarises INCIBE "aviso" pages in plain language, often with the alert severity level stated. Useful for catching INCIBE citizen advisories that are otherwise easy to miss. Source for the INCIBE hotel-reservation WhatsApp alert (10 and 14 Aug 2026). |
| Newtral (Spain) | https://www.newtral.es/ | Tier 3 | Spanish fact-checking and verification outlet. Covers scam and disinformation clusters around major events; source for the 12 August 2026 solar-eclipse fraud analysis (10 Aug 2026). |
| Revista Ciberseguridad (Spain) | https://www.revistaciberseguridad.com/ | Tier 3 | Spanish-language cybersecurity trade publication. Covers INCIBE/OSI advisories with more technical framing than mainstream press. Source for eclipse phishing / cloned-page analysis (Aug 2026). Note: occasionally returns empty on fetch — use search snippet or retry. |
| Maldita.es — Desinformación (Spain) | https://maldita.es/desinfo/ | Tier 3 | Spanish anti-disinformation organisation. Valuable for the disinformation layer that accompanies event-anchored fraud (eclipse conspiracy content, 7 Aug 2026). Useful for spotting narrative hooks before they are monetised. |
| Confilegal (Spain) | https://confilegal.com/ | Tier 4 | Spanish legal-affairs outlet. Covers the legal/consumer-rights angle of counterfeit goods; source for the legal exposure of counterfeit eclipse glasses (12 Aug 2026). Confirm underlying facts via Tier 1–3. |
| El Correo Gallego — Economía (Spain) | https://www.elcorreogallego.es/economia/ | Tier 4 | Galician regional daily. Useful for regionally-anchored fraud in the eclipse totality band (11 Aug 2026). Regional Spanish press is a good early signal for geographically concentrated scams. |
| El Economista — Salud y Bienestar (Spain) | https://www.eleconomista.es/salud-bienestar/ | Tier 3 | Spanish business daily's health desk; carried the OzemPil / OCU logo-abuse story (14 Aug 2026). |
| National Geographic España — Bienestar | https://www.nationalgeographic.com.es/bienestar/ | Tier 4 | Carried the consumer-authority list of six non-compliant eclipse-glasses brands withdrawn from sale. Useful for product-safety corroboration; verify against Consumo/AECOSAN where possible. |
| Microsoft Security Blog / Microsoft Threat Intelligence | https://www.microsoft.com/en-us/security/blog/ | Tier 1 | Vendor threat research with full published IOC sets. Source for the hospitality "photo ZIP" / Calendly authentication-laundering campaign and Node.js implant (25 Jun 2026), including C2 domains, LNK naming and Node runtime hash. Should be a standing Tier 1 check. |
| Infoblox — Threat Intelligence Blog | https://www.infoblox.com/blog/threat-intelligence/ | Tier 1 | DNS-centric threat research. Published the procurement-themed AiTM campaign against EU institutions, UN agencies and universities (22 Jul 2026), naming EvilProxy, FlowerStorm/Storm-1167 and Kali365 kits. Strong for phishing-infrastructure and DNS-pivot enrichment. |
| Proton — Blog (privacy/security explainers) | https://proton.me/blog/ | Tier 2 | European (Swiss) privacy provider; publishes clear consumer-facing scam explainers. Used for cloud-storage renewal scam analysis. Useful when a global campaign needs a European-framed consumer explanation. |
| PCrisk — Removal guides | https://www.pcrisk.com/removal-guides/ | Tier 4 | Malware/scam removal database. Good for confirming that a specific email scam template is in circulation and for sample subject lines; not authoritative on attribution or scale. |
| MalwareTips — Blogs | https://malwaretips.com/blogs/ | Tier 4 | Community-driven scam breakdowns; useful for corroborating high-volume email campaign variants. Confirm via Tier 1. |
| Evidence Network (FR-language analysis) | https://evidencenetwork.ca/ | Tier 4 | Francophone explainer outlet; carried a clear mechanical breakdown of the WhatsApp six-digit-code takeover (Aug 2026). Lead-generation and phrasing reference only; confirm via Cybermalveillance or Tier 1–3. |
| Cri du Troll (France) | https://www.cridutroll.fr/ | Tier 4 | French consumer-tech blog tracking the currently highest-volume WhatsApp scam variants. Useful as an early signal of which pretext scripts are dominant in the French market; always confirm via Cybermalveillance.gouv.fr or Signal-Arnaques. |
| Rest Less (UK) — Money / Scams | https://restless.co.uk/money/everyday-finance/latest-scams-to-watch-out-for/ | Tier 4 | UK over-50s consumer platform maintaining a running scam list. Useful for tracking which scams are actively reaching an older UK demographic. Confirm via Report Fraud / NCSC / Which?. |
| Refundee — Blog (UK) | https://www.refundee.com/blog/ | Tier 4 | UK APP-fraud reimbursement specialist. Useful reference for procedural changes in UK fraud reporting — e.g. the replacement of Action Fraud by "Report Fraud" (City of London Police) on 4 Dec 2025. Commercial interest; treat analysis with caution, procedural facts are checkable. |
actionfraud.police.uk/news still carries the newsroom.
New Sources Added — 2026-08-27 Run
| Source | URL | Tier | Notes | |
|---|---|---|---|---|
| SOCRadar — Blog / Threat Research Unit (STRU) | https://socradar.io/blog/ | Tier 1 | Vendor threat research with full published IOC tables and MITRE mappings. Source for the AnonyMousKIT AI-powered PhaaS supply-chain analysis (24 Aug 2026) — 506 domains, 168 reseller brands, backend source code, four months of production logs and recovered AI voice transcripts. Exceptional depth; should become a standing Tier 1 check alongside Microsoft, Infoblox and Proofpoint. Note: article pages are very large — fetch with offset/limit or grep for the IOC table. | |
| Help Net Security | https://www.helpnetsecurity.com/ | Tier 1 | Long-running security news outlet with fast, accurate vendor-report summaries. Carried the AnonyMousKIT analysis (26 Aug 2026) with the key economic figures. Good for quick corroboration of vendor research without re-fetching large primary reports. | |
| CyberInsider | https://cyberinsider.com/ | Tier 2 | Security news and analysis outlet; covered AnonyMousKIT's AI-call mechanics (Aug 2026). Reasonable corroboration tier; verify statistics against the primary vendor report. | |
| SC Media — Briefs | https://www.scworld.com/brief | Tier 2 | Industry trade publication; concise briefs on vendor research. Used for AnonyMousKIT corroboration. | |
| Fraudehelpdesk — Actuele waarschuwingen (Netherlands) | https://www.fraudehelpdesk.nl/actueel/alerts/ | Tier 1 | The Dutch national fraud reporting and advice centre. Publishes dated, specific consumer alerts with lure text. Source for both Dutch findings this run: the iDEAL \ | Wero migration phishing wave and the spoofing of the Fraudehelpdesk's own telephone number (20 Aug 2026). Should be checked every run — it is the single best Dutch consumer-fraud primary source. |
| Fraudehelpdesk Zakelijk (Netherlands, business) | https://www.fhdzakelijk.nl/waarschuwingen/actuele-waarschuwingen/ | Tier 1 | Business-facing arm of the Fraudehelpdesk. Carries SMB-targeted warnings (fake invoices, spooknota's, mandatory-verification emails) that often precede or parallel the consumer wave. Underused source for the invoice-redirection and SMB verticals. | |
| Opgelicht?! (AVROTROS, Netherlands) | https://opgelicht.avrotros.nl/alerts/ | Tier 3 | Dutch public-broadcaster consumer-fraud programme running a per-variant alert feed with full quoted lure text and dates. The most granular public tracker of individual Dutch phishing waves — three separate iDEAL \ | Wero variants were catalogued here. Excellent for reconstructing campaign timelines. |
| Consumentenbond — Digitaalgids (Netherlands) | https://www.consumentenbond.nl/digitaalgids/ | Tier 3 | Dutch national consumer association. Publishes standing guidance on active scam themes (dedicated Wero phishing page). Authoritative consumer voice; good for the "what the official advice actually is" line in articles. | |
| Kassa (BNNVARA, Netherlands) | https://www.bnnvara.nl/kassa/ | Tier 3 | Dutch consumer-affairs broadcast programme. Corroborates Fraudehelpdesk alerts and adds victim-side detail. | |
| Polizia Postale / Commissariato di PS Online (Italy) | https://www.commissariatodips.it/ | Tier 1 | Italy's official online police portal for cybercrime reporting and public alerts. Source for the BANCOMAT Pay fraudulent payment-request alert (~21 Aug 2026). Also the correct reporting destination to cite for Italian readers. Standing Tier 1 check for Italy. | |
| Cybersecitalia | https://www.cybersecitalia.it/ | Tier 2 | Italian cybersecurity trade outlet that reliably reproduces and contextualises Polizia Postale alerts with fuller text than mainstream press. Best Italian secondary source for police advisories. | |
| Punto Informatico (Italy) | https://www.punto-informatico.it/ | Tier 3 | Long-established Italian tech outlet; carried the BANCOMAT Pay fraud alert. Solid mainstream Italian corroboration. | |
| StrettoWeb / CiaoComo / NovaraToday (Italy, regional) | https://www.strettoweb.com/ , https://www.ciaocomo.it/ , https://www.novaratoday.it/ | Tier 4 | Italian regional dailies. Individually low-signal, but collectively useful: when the same Polizia Postale alert appears simultaneously across unrelated regional outlets, it confirms a national-level police push rather than a local incident. Good volume signal. | |
| ZATAZ (France) | https://www.zataz.com/ | Tier 1 | Veteran French cybersecurity investigation site (Damien Bancal). Frequently first to document French institutional fraud campaigns — carried both the Université Bretagne Sud (€350, July 2026) and Aix-Marseille (84,000 students, €450, Aug 2026) tuition-fee frauds. Strong original reporting, France-first. Should be a standing check. | |
| franceinfo — Société / Éducation | https://www.franceinfo.fr/societe/education/ | Tier 3 | French public broadcaster. Authoritative confirmation of institution-level fraud incidents, usually including the institution's own statement (which is where the "not a hack, external addresses" detail came from this run). | |
| ICI (ex-France Bleu / France 3 régions) | https://www.ici.fr/ | Tier 3 | France's regional public-broadcast network under its new unified brand. Excellent for geographically-anchored French fraud, and often carries operational detail (the grammatical error that exposed the Aix-Marseille lure) that national outlets omit. Note the rebrand — francebleu.fr / france3-regions URLs now redirect here. | |
| Signal-Arnaques — En Direct (France) | https://info.signal-arnaques.com/actualites/en-direct/ | Tier 3 | Live feed of French scam reports, complementing the Avis d'Expert section already tracked. Useful for near-real-time volume signals on emerging French campaigns (e.g. report counts within hours of a wave starting). | |
| Verbraucherzentrale — Phishing-Radar (Germany) | https://www.verbraucherzentrale.de/wissen/digitale-welt/phishingradar/phishingradar-aktuelle-warnungen-6059 | Tier 1 | Germany's consumer-advice network running a dated, itemised phishing warning feed (ELSTER, Deutsche Rentenversicherung, AOK, Postbank BestSign, VR-SecureGo waves all logged in August 2026). Referenced in prior runs but not previously listed as a standalone tracked source. Standing Tier 1 check for Germany. | |
| Polismyndigheten — Aktuellt / Nyheter (Sweden) | https://polisen.se/aktuellt/nyheter/ | Tier 1 | Swedish police national and regional news feed. August 2026 warnings on the "child in accident" impersonation wave, fake flower-delivery card theft targeting the elderly, and Transportstyrelsen fine smishing. Also the primary source for tracking the new Swedish anti-spoofing rules in force from 1 Aug 2026. | |
| FSCS — Latest scams and frauds (UK) | https://www.fscs.org.uk/news/fraud/latest-scams-frauds/ | Tier 1 | UK Financial Services Compensation Scheme. Publishes warnings about impersonation of itself, including the current fake "FSCS protects cryptoassets — pay for higher compensation" email and specific caller-ID and language tells. Valuable for the recovery-fraud / fake-regulator vertical, which is consistently underreported. | |
| cleankids.de — Verbraucher | https://www.cleankids.de/category/verbraucher/ | Tier 4 | German consumer-alert aggregator that publishes monthly consolidated phishing round-ups (e.g. "Aktuelle Phishing-Mails August 2026"). Useful as a fast index of which German campaigns are live in a given month; always confirm against the Verbraucherzentrale Phishing-Radar. |
ideal.nl, wero-wallet.eu, national bank communications and the Fraudehelpdesk/Consumentenbond/Safeonweb alert feeds through each migration milestone.
---
New Sources Added — Run of 2026-09-01
| Source | URL | Tier | Notes | |--------|-----|------|-------| | Which? — The latest scam alerts (rolling feed) | https://www.which.co.uk/news/article/the-latest-scam-alerts-from-which-aBRLy2b02WkC | Tier 3 | The single most valuable UK consumer source found to date and a mandatory standing check. A continuously updated, date-stamped feed of individual UK scam variants with annotated screenshots of the actual lures. Sourced three of this run's six deep-dives (TV Licensing 4 Aug, Nationwide 7 Aug, copycat-brand fake apps 19 Aug) and supplied the corroborating timeline for several others. Granularity is comparable to Opgelicht?! for the Netherlands. Note it is a living page — entries are appended at the top and old entries retained, so always record the date heading alongside any citation. | | Financial Times — regulation and markets coverage | https://www.ft.com/ | Tier 1 | Broke the EU MiCA-deadline fraud story (6 Aug 2026) with direct on-record quotes from AMF, AFM and ESMA that appear nowhere in the regulators' own published output. Paywalled — use The Block, Cryptopolitan or CoinMarketCap Academy for accessible relay, but cite the FT as primary. Financial-regulator fraud warnings frequently surface here before they surface on regulator websites. | | The Block — Regulation | https://www.theblock.co/news/regulation | Tier 2 | Crypto trade publication with disciplined, well-dated regulatory reporting. Reliable relay of paywalled financial-press stories with attribution intact. Source for the MiCA scam-wave coverage. Dates are clearly exposed in the URL structure, which makes freshness verification fast. | | ESMA — MiCA register and digital finance activities | https://www.esma.europa.eu/esmas-activities/digital-finance-and-innovation/markets-crypto-assets-regulation-mica | Tier 1 | The authoritative EU register of MiCA-authorised crypto-asset service providers (~320 entities as of 5 Aug 2026). This is the verification instrument to cite in every crypto article — the consumer advice "type the register address yourself and search the legal entity name" depends on it. Also the body whose logo is being forged in the current wave. | | Autorité des Marchés Financiers (AMF, France) | https://www.amf-france.org/ | Tier 1 | French financial markets regulator. Publishes blacklists of unauthorised investment and crypto sites, and self-impersonation warnings. Currently being impersonated directly (staff posing as AMF officials instructing asset transfers). Standing check for the investment-fraud and fake-regulator verticals. | | Autoriteit Financiële Markten (AFM, Netherlands) | https://www.afm.nl/ | Tier 1 | Dutch financial markets authority. Issued the specific and under-appreciated warning that fraudsters are targeting investors searching for a licensed alternative provider — a pull-channel attack that defeats all "don't click links" advice. Complements the Fraudehelpdesk for Dutch financial fraud. | | Student Loans Company (via GOV.UK) | https://www.gov.uk/government/organisations/student-loans-company | Tier 1 | UK student finance body publishing annual scam-vigilance campaigns timed to the September disbursement window, with quantified prevention figures (£2.9m of maintenance loan payments stopped in one cycle; £45.5m across broader fraud prevention). Publishes the Economic Crime Unit hotline (0300 100 0059). Seasonal standing check: late August through October. | | TV Licensing — scam guidance | https://www.tvlicensing.co.uk/faqs/FAQ288 | Tier 1 | Brand-owner guidance listing genuine sending addresses (donotreply@tvlicensing.co.uk, donotreply@spp.tvlicensing.co.uk) and the name-plus-partial-postcode greeting convention. Exactly the kind of authoritative "what the real thing looks like" reference that makes a deep-dive actionable. Seek the equivalent page for every impersonated brand. | | Age UK — scams and fraud advice | https://www.ageuk.org.uk/information-advice/money-legal/scams-fraud/ | Tier 1 | UK charity with dedicated, well-maintained guidance on the scam types that disproportionately target older adults (TV Licence, courier fraud, doorstep). Valuable for the "who is most at risk" section and for demographic framing grounded in something better than assumption. | | NordVPN — research blog | https://nordvpn.com/blog/ | Tier 2 | Vendor research arm producing consumer-facing threat investigations. Source (via Which?) for the 65+ brand copycat-site network delivering screen-spying fake apps, and separately for the fake-app-to-unlicensed-casino network. Vendor marketing incentive means figures should be corroborated, but the underlying investigations are substantive. | | Varonis — Threat Labs blog | https://www.varonis.com/blog/ | Tier 1 | Strong phishing-kit teardowns (Spiderman, SpamGPT, MatrixPDF, Atroposia). Critical handling note: Varonis pages display a "Last updated" date that can differ substantially from the original publication date, and BleepingComputer's coverage of the same research may be months older than a naive read suggests. The Spiderman kit was assessed this run and rejected as not-new on exactly this basis (published Dec 2025, not Aug 2026). Always cross-check the BleepingComputer byline date before treating Varonis research as current. | | Nyheter24 — Konsument / Inrikes (Sweden) | https://nyheter24.se/nyheter/konsument | Tier 3 | Swedish news outlet that relays Polismyndigheten fraud warnings with fuller operational detail than the police's own published bulletins (the Blocket seller-side case detail — 4,780 SEK, the "Köpet genomfört" string, the fabricated buyer and address — appears here and not on polisen.se). Useful, but always attempt to locate the underlying police statement and flag the evidence tier honestly when it cannot be found. | | Råd & Rön — Bluffvarningar (Sweden) | https://www.radron.se/bluffvarningar/ | Tier 3 | Swedish consumer association's scam-warning list. Complements Polismyndigheten with the consumer-body perspective; useful for the Nordic gap in our source coverage. | | Cyware — security news aggregation | https://cyware.com/news | Tier 3 | Aggregator carrying campaign-level detail and report volumes (source of the Action Fraud figure of 6,307 TV Licensing reports in a fortnight). Fast index; corroborate figures against the originating authority. | | CoinMarketCap Academy / Cryptopolitan / CryptoTicker | https://coinmarketcap.com/academy/ , https://www.cryptopolitan.com/ , https://cryptoticker.io/ | Tier 3 | Crypto-sector outlets that carried the MiCA scam-wave story with practical consumer framing (register-checking advice). Adequate corroboration tier; not primary. | | Your Local Computer Guy — UK Scam Alerts (monthly) | https://yourlocalcomputerguy.co.uk/blog/ | Tier 4 | UK IT-repair blog publishing consolidated monthly scam round-ups with dates and primary-source links. Genuinely useful as a fast index of what was live in a given UK month. Handle with care: this run found it had materially embellished the Which? 7 August Nationwide alert (describing a "Fairer Share payment" con where Which? documented a fake direct-debit notification). Use to find leads, never to source facts. A useful standing reminder of why Tier 4 is a lead generator only. |
Pipeline note (2026-09-01) — freshness verification is now a mandatory step, not a courtesy. This run's initially highest-scoring candidate, the Spiderman European bank phishing kit, was carried by multiple outlets in language that read as current ("new phishing kit", "is being used to target"). Fetching the primary sources established a BleepingComputer publication date of 10 December 2025 and a Varonis "last updated" of 12 December 2025 — roughly nine months old and a clear fail against the 30–60 day novelty rule. It was dropped. Every candidate must have its primary-source publication date confirmed by fetching the source before it enters the write queue. Aggregators, vendor blogs and SEO-optimised secondary coverage routinely present old research in the present tense, and search-result summaries strip dates entirely. Pipeline note (2026-09-01) — mandated-transition windows as a standing pretext category. Following the iDEAL→Wero finding logged on 27 August, this run adds the MiCA wind-down (deadline 1 July 2026, ongoing) as a second instance of the same structure: a real, legally-required migration in which unsolicited institutional contact is expected and an unusual action is wrongly assumed possible. Treat every announced regulatory or infrastructure transition as a schedulable fraud window and prepare consumer messaging before it opens. Next scheduled windows to monitor: continued EPI/Wero rollout (BE/FR/DE/LU), the EU Digital Identity Wallet deployment, and EU AI Act Article 50 transparency duties (applicable from 2 August 2026), which will generate their own "verify your account for compliance" pretexts. Last updated: 2026-09-01