Reading view

Fake “The Odyssey” Downloads Are Spreading Malware: This Week in scams

This week in scams and cybersecurity news, 

Looking for a free download of this summer’s biggest movie could come with something you definitely didn’t ask for: malware. 

Here’s what to watch for. 

Fake The Odyssey Downloads Are Hiding Malware 

Speaking of Trojan horses….

Security researchers have reportedly identified malicious downloads disguised as pirated copies of The Odyssey, including files designed to look like high-quality movie releases. 

Some fake files even use familiar video-player icons and movie-style filenames to appear legitimate.

But instead of opening a movie, downloading or running the file can launch malicious software capable of stealing information from the device. Other scams reportedly use fake streaming sites that ask users to enter personal or payment information to access a supposedly “free” movie.  

McAfee researchers routinely see cybercriminals attach malware to the things people are already searching for, especially popular movies, TV shows, games, mods, and software. 

In a recent example, McAfee Labs uncovered the WeedHack malware campaign targeting Minecraft players, which disguised malicious software as free game mods and clients. Our researchers recorded more than 116,000 infections from the campaign since January. 

The media changes. The scam doesn’t.

What Makes Fake Movie Downloads Dangerous? 

A supposed movie file can hide: 

  • Infostealers designed to collect passwords, browser sessions, payment information, or cryptocurrency data 
  • Trojans that give an attacker access to your device 
  • Loaders that install additional malware 
  • Fake browser updates or extensions that redirect you to scams or malicious websites 

One especially obvious warning sign: movies should not arrive as executable .exe files. Legitimate video files generally use formats such as .mp4, .mkv, or .avi. 

When in doubt, don’t download it. 

How McAfee Protects Against Malware

With McAfee+, multiple layers can help protect you when a tempting download isn’t what it claims to be: 

Device Security helps detect malicious apps, files, and downloads before they can compromise your device. 

Web Protection helps block risky websites, including malicious download pages, even if you accidentally click. 

Scam Detector flags suspicious texts, emails, links, QR codes, and other messages that may try to direct you toward fraudulent sites. 

Identity Monitoring alerts you if your personal information appears in known data leaks or on the dark web so you can take action quickly. 

Together, these protections help address both sides of fake-download scams: stopping malware before it gets onto your device and helping protect your information if criminals try to steal it. 

Other Scam and Security News This Week 

Here are some other breaches, scams, and cybersecurity headlines making waves this week:

Trezor breach reportedly exposes information belonging to nearly 14,000 crypto customers.

Hardware wallet maker Trezor says a breach involving one of its shipping providers exposed personal information including names, email addresses, phone numbers, and home addresses for thousands of customers.  

McAfee’s 2026 State of the Scamiverse predicted that crypto and financial scams were likely to intensify this year, and cryptocurrency-related messages remain among the scams McAfee Scam Detector regularly identifies and blocks.

(Financial Times) 

Cyberattacks continue to climb worldwide.

New threat research found organizations experienced an average of 2,336 cyberattacks per week in July, a 16% increase from the previous year, while reported ransomware victims also rose sharply. Education, government, telecommunications, and other major sectors remained frequent targets.

(IT Brief) 

Android malware can turn a victim’s phone into part of a contactless-payment scam.

Researchers investigating the targeted WindRelay campaign say criminals impersonated banks over the phone, persuaded victims to install malicious Android apps, and then instructed them to tap their physical bank cards against their phones. 

That allowed attackers to relay contactless card information in real time, with researchers reporting some attacks unfolded during calls lasting only about 13 minutes.

(TechRadar) 

This Week’s Safety Tips 

Stream and download from legitimate sources. New theatrical releases appearing for free on unfamiliar websites should immediately raise suspicion. 

Check the actual file type before opening a download. A movie should never require you to run an .exe application. 

Never install a “special player,” browser update, or extension just to watch a movie. Close the page and go directly to a trusted streaming service instead. 

Treat urgency and exclusivity as warning signs. “Watch it before everyone else,” “leaked copy,” and “limited access” are designed to get you clicking before you think. 

And we’ll be back next week with more cybersecurity news and scam alerts. 

The post Fake “The Odyssey” Downloads Are Spreading Malware: This Week in scams appeared first on McAfee Blog.

  •  

GTA 6 Is Coming. So Are the Scams. Here’s What McAfee Experts Found

Millions of gamers are counting down the days until this fall’s biggest releases. 

After more than a decade of anticipation, Grand Theft Auto VI is finally set to launch this November. Surprise indie hit Meccha Chameleon has exploded across Twitch and YouTube after selling millions of copies within days. And highly anticipated titles like Call of Duty: Modern Warfare 4, Minecraft Dungeons 2, Phantom Blade Zero, Marvel’s Wolverine, and dozens of others are keeping players glued to trailers, wishlists, Discord servers, and preorder pages. 

Scammers are watching those trends. 

Whenever millions of people rush to search for the same game, criminals quickly create fake downloads, unofficial mobile apps and servers, counterfeit storefronts, phishing pages, and cheat tools designed to steal money, credentials, or personal information. 

This year is no exception. 

Here’s how scammers are taking advantage of 2026’s biggest gaming moments, and how you can avoid becoming their next target, according to McAfee’s experts: 

The Most Common Gaming Scams and How to Avoid Them, According to McAfee 

Most gaming scams fall into a handful of predictable categories. Once you know what to look for, they’re much easier to spot. 

Here are some of the most common scams McAfee protection prevents 

Scam  What it looks like  Red flags  How to protect yourself 
Fake game downloads  “Free” copies, cracked launchers, unofficial installers  Unknown websites, requests to disable antivirus, ZIP files instead of official installers  Download games only from official publishers or trusted storefronts 
Fake early access  Too-good-to-be-true VIP access, beta invites, playable versions before launch that don’t exist   Cryptocurrency payments, countdown timers, “exclusive” offers, unofficial websites  Verify release dates , including early access dates, and preorder information directly with the publisher 
Cheats, mods, and trainers  Unlimited money, aimbots, unlock tools, auto-play software  Downloads shared through Discord, YouTube descriptions, file-sharing sites  Only use trusted community repositories and avoid executable files from unknown sources 
Fake mobile versions  Mobile apps for games that don’t officially exist on Android or iPhone  Different developer names, excessive ads, cloned screenshots  Confirm that the developer has actually released a mobile version before downloading 
YouTube and Discord scams  Videos claiming to have mods or secret builds  Shortened links, pinned download comments, Discord invite links  Visit the developer’s official website instead of getting mods or clicking links from comments or descriptions 
Fake giveaways and free skins  Free cosmetics, DLC, battle passes, or gift cards  Requests to sign in through third-party sites or enter account credentials  Only redeem offers through official game platforms 

 These tactics aren’t theoretical. They’re happening right now. 

Detected by McAfee Labs: Malware Campaigns, Malicious Downloads, and Suspicious Apps 

Earlier this year, McAfee Labs uncovered WeedHack, a malware campaign disguised as free Minecraft mods and game clients 

Since January 2026, the campaign has infected more than 116,000 devices, averaging roughly 2,000 to 3,000 new infections every day. Attackers lured players through fake mod websites and convincing YouTube videos before installing malware capable of stealing passwords, cryptocurrency wallets, Discord credentials, Minecraft accounts, and more.  

Ultimately these gaming attacks can expose players to: 

  • Malware infections  
  • Account theft  
  • Password theft  
  • Data breaches  
  • Spyware monitoring cameras and microphones 
  • Spyware monitoring keyboard and mouse inputs 
  • Permanent game bans  

One of the campaign’s most concerning findings wasn’t just the malware itself, it was how inexpensive and accessible the tools had become. The malware was marketed almost like legitimate software, lowering the barrier for inexperienced attackers and helping spread scams throughout gaming communities. 

The lesson isn’t to avoid every cheat, unlock, or community-created project. It’s to be skeptical whenever someone promises something that seems too good to be true. 

Meccha Chameleon Shows How Quickly Scammers Embrace Viral Games 

Few people predicted Meccha Chameleon would become one of the biggest surprise gaming success stories of the year. 

The inexpensive indie title reportedly sold more than two million copies within days, fueled largely by livestreams, social media clips, and word of mouth. Unfortunately, that kind of overnight success doesn’t just attract new players. 

According to PC Gamer, players have already begun using automated “auto-paint” cheats that scan the environment and instantly camouflage characters, removing much of the creativity and skill the game was designed around. 

The game’s popularity has also created confusion about where players can safely download it. 

McAfee researchers recently identified multiple Android apps and an unofficial piracy site using the Meccha Chameleon name, despite the game’s independent developer not announcing an official Android release 

Here’s how we saw it play out 

First a gamer might navigate to this piracy site to download a free game. The game may not come with malware, but malware is still distributed during the process. 

An example of fake steam Meccha Chameleon

Here we see steamgg[.]net, a piracy site to download free games. Here you see they offer a download of Meccha Chameleon (not malicious).

But when you click download, it opens a misleading new tab like this one below.

A popup claiming your download is ready

This new tab tricks the user into thinking they are downloading a game from steamgg[.]net. They are actually being redirected to a completely unrelated download.

In cases like this, unauthorized sites and apps trick users into giving unwanted access to their information and devices.

 

Google Play store apps showing Meccha Chameleon
Here we see examples of fake versions of Meccha Chameleon uploaded to the Google Play Store 

*Note: The unauthorized apps shown here have since been reported and taken down. While not confirmed to be malicious, hundreds of people had already downloaded and given security permissions to these apps.* 

“Repackaged or unauthorized apps and sites are a major risk with viral games,” says McAfee Threat Researcher and lifelong gamer Charles McFarland.  

“Because many players are unfamiliar with the original developer, it’s easier for unauthorized apps and copycat listings to blend into app stores,” McFarland explains. “Once installed, the app can have free access to your phone’s data, texts, contacts, and more.” 

Before downloading a newly popular game, especially on mobile, take a moment to verify that the developer has actually released it for your device. 

Is This GTA 6 Download Legit? How to Spot Fake Early Access Scams 

If there’s one game scammers are betting people will search for this fall, it’s Grand Theft Auto VI. 

Rockstar Games officially opened global preorders on June 25, and the game launches worldwide on November 19, 2026 for PlayStation 5 and Xbox Series X|S. Digital preorders can begin preloading on November 12. 

That hasn’t stopped scammers from advertising: 

  • “Play GTA 6 today”  
  • VIP Early Access  
  • Secret beta downloads  
  • Discounted preorder keys  
  • Cryptocurrency-only purchases  
  • “Exclusive” launchers 

The problem?  Those offers promise something Rockstar isn’t selling. 

If a website claims it can provide a playable version of GTA 6 before Rockstar’s official launch, treat it as a major warning sign. 

Scammers know players have waited more than a decade for the next Grand Theft Auto. They’re counting on excitement to outweigh skepticism. 

“Every major game launch brings a noticeable increase in gaming-themed scams. We regularly see McAfee protecting customers from malicious downloads, fake websites, and other threats that capitalize on the excitement around new releases,” McFarland says. 

“As a gamer myself, I know the excitement of jumping into a long-awaited game with my son, but it’s worth taking an extra minute to download from an official or authorized source instead of rushing to be first.” 

Whenever possible, verify preorder information directly through Rockstar Games or trusted digital storefronts rather than clicking links shared through social media posts, livestream chats, YouTube comments, or unsolicited messages and advertisements. 

Official storefront  Trending and Upcoming Games 
Steam  Meccha Chameleon, Dune: Awakening, Metal Gear Solid: Master Collection Vol. 2, Silent Hill: Townfall, Call of Duty: Modern Warfare 4, Phantom Blade Zero, No Rest for the Wicked, Planet Zoo 2, Kingdom Hearts Collections, Ace Combat 8, Gears of War: E-Day (PC), Minecraft Dungeons 2 and many other PC releases 
PlayStation Store  Grand Theft Auto VI, Marvel’s Wolverine, Phantom Blade Zero, Onimusha: Way of the Sword, Metal Gear Solid: Master Collection Vol. 2, Call of Duty: Modern Warfare 4, Dune: Awakening, Silent Hill: Townfall and other PlayStation releases 
Xbox Store  Grand Theft Auto VI, Gears of War: E-Day, Call of Duty: Modern Warfare 4, Dune: Awakening, Ace Combat 8, Kingdom Hearts Collections and other Xbox releases 
Nintendo eShop  Rhythm Heaven Groove, Splatoon Raiders, Fire Emblem: Fortune’s Weave, Harvest Moon: Echoes of Teradea, Nintendo Switch Sports Resort, The Legend of Zelda: Ocarina of Time Remake and other Nintendo titles 

 *Availability may vary by platform as publishers announce additional releases. 

If you can’t find a game on one of its official storefronts, that’s a good reason to pause before downloading it elsewhere. 

How McAfee Protects Gamers 

Gaming should be about exploring new worlds, not accidentally downloading malware. 

McAfee helps protect players before, during, and after they click. 

Web Protection helps block known malicious websites before fake downloads ever reach your device. 

Award-winning antivirus detects and blocks malware hidden inside suspicious installers, cheats, and unofficial software. 

If a file is flagged, Threat Explainer provides a clear, plain-language explanation of why it’s considered risky, helping you make informed decisions instead of guessing whether a warning is legitimate. 

And if you’re worried additional security will slow down your games, McAfee Total Protection has repeatedly scored first place in the AV-Comparatives PC Performance Test, an independent benchmark that measures how much security software impacts your computer’s performance.  

McAfee earned the lowest overall impact score among the 20 products tested and received the highest possible rating, 3 Stars ADVANCED+. In other words, you get strong protection without sacrificing performance or slowing your game. 

Whether you’re preordering GTA 6, trying the latest indie hit, or installing a new Minecraft mod, slowing down long enough to verify where you’re downloading from remains one of the simplest, and most effective, ways to protect yourself. 

Frequently Asked Questions 

FAQs 
Q: Is GTA 6 early access real?

A: No. Rockstar Games has announced pre-orders and pre-loading ahead of launch, but there is no legitimate way to play GTA 6 early through unofficial websites. Be wary of any site claiming to sell “VIP access,” beta keys, or downloadable copies before the official release date. 

Q: Is it safe to pre-order GTA 6 from any website?

A: Stick to Rockstar Games or authorized retailers and digital storefronts like the PlayStation Store and Xbox Store. Avoid unfamiliar websites advertising deep discounts, exclusive editions, or cryptocurrency-only payments. 

Q: Does Meccha Chameleon have an official Android or iPhone app?

A: At the time of writing, the game’s developer has not announced an official mobile version. If you find Meccha Chameleon in an app store, verify that it’s published by the official developer before downloading. 

Q: Are game cheats and trainers safe to download?

A: Not always. While some cheats simply modify gameplay, others can contain malware, steal passwords, or compromise gaming accounts. Downloading cheats from unofficial websites or Discord servers carries additional risk. 

Q: Can Minecraft mods contain malware?

A: Yes. While many Minecraft mods are legitimate, cybercriminals have repeatedly used fake mods and clients to distribute malware. Download mods only from trusted community repositories or verified developer pages. 

Q: How can I tell if a game download is legitimate?

A: Download games directly from the publisher’s official website or trusted digital storefronts like Steam, PlayStation Store, Xbox Store, Nintendo eShop, or Epic Games Store. Avoid links shared through YouTube comments, Discord messages, or unofficial social media posts. 

Q: Why do scammers target popular game releases?

A: High-profile launches create excitement and urgency, making players more likely to click on fake download links, preorder scams, cheat tools, or unofficial apps without stopping to verify they’re legitimate. 

Q: What are the biggest gaming scams to watch for in 2026?

A: Common gaming scams include fake early access offers, counterfeit game downloads, unofficial mobile apps, cheat software bundled with malware, phishing pages posing as gaming platforms, and fake giveaways promising free games or in-game items. 

Q: Can antivirus slow down gaming performance?

A: Some security software can affect system performance, but independent testing has shown that solutions vary significantly. Look for products that perform well in third-party performance benchmarks while still providing strong protection against malware and phishing attacks. McAfee Total Protection recently took first place in the latest AV-Comparatives PC Performance Test, an independent benchmark that measures how much security software impacts your computer’s performance. In other words, McAfee provides strong protection without sacrificing performance or slowing your game. 

Q: What’s the safest way to download new games this fall?

A: Buy or download games directly from official publishers and trusted storefronts, keep your operating system and antivirus up to date, avoid unofficial cheats or cracked versions, and verify any unexpected links before clicking. 

 

The post GTA 6 Is Coming. So Are the Scams. Here’s What McAfee Experts Found appeared first on McAfee Blog.

  •  

Can Malware Bypass Your Passkeys? This Week in Scams

This week in scams and cybersecurity news, 

Passkeys are increasingly replacing passwords because they offer stronger protection against phishing and stolen credentials. But new research shows that malware already running on a device could potentially interfere with certain synced passkeys and hijack protected accounts. 

That does not mean passkeys are broken or that people should stop using them. Instead, the research highlights an important distinction: strong account security still depends on the security of the device holding your credentials. 

Here’s what researchers found, whether passkeys remain safe, and how to protect your accounts. 

Can Malware Bypass Your Passkeys? 

Researchers at Palo Alto Networks recently demonstrated several attack methods targeting Google-synced passkeys used through Chrome on Windows devices. 

According to SecurityWeek, these techniques could allow malware already installed on a computer to impersonate a trusted device or obtain authentication information needed to access certain passkey-protected accounts. 

Key takeaways 

The device must already be infected. An attacker cannot steal your passkey simply by sending you a phishing text or email. 

The research focused on synced passkeys. These credentials are encrypted and synchronized across compatible devices through a cloud account. 

Malware may be able to impersonate a trusted device. Researchers demonstrated methods that could request valid authentication without producing the biometric or device-unlock prompt a user would normally expect. 

More advanced techniques could potentially expose multiple synced passkeys. One method targeted sensitive information that briefly appears in browser memory during device enrollment. 

Google was notified and has reportedly introduced mitigations. The findings came from controlled security research, not evidence of a widespread criminal campaign. 

(SecurityWeek) 

Are Passkeys Still Safe? 

Yes. Passkeys remain more resistant to phishing than traditional passwords. 

Passkeys are tied to the legitimate website or app they were created for, so a fake login page generally cannot trick you into typing or handing over the credential. They also eliminate the risks created by weak and reused passwords. 

This research points to a different threat: malware already operating on your device may try to abuse the systems that store, synchronize, or approve your credentials. 

Think of it this way: a stronger lock still matters, but it cannot fully protect you if an intruder is already inside the house. 

This Week’s Safety Tips 

Use passkeys when available. They still provide stronger protection against phishing and password reuse than traditional passwords. 

✓ Keep your browser, operating system, and security software updated. Updates help close vulnerabilities that malware could exploit. 

✓ Be cautious with unexpected files and downloads. Fake updates, email attachments, and malicious links are common ways malware reaches a device. 

✓ Review your trusted devices and active sessions. Remove devices you no longer recognize or use. 

How McAfee Helps Protect Your Devices and Accounts 

Device security helps detect and block viruses, malware, and other threats that could compromise the device where your passkeys and passwords are stored. 

Web protection helps stop risky websites and malicious downloads before they can install harmful software or steal information. 

Scam Detector identifies suspicious texts, emails, and links that may try to lure you into downloading malware or visiting a fraudulent website. 

Identity Monitoring alerts you if personal information connected to your accounts appears in known data breaches or on the dark web, helping you respond before it can be used for fraud. 

Other Scam and Security News This Week 

Meta AI model reportedly accessed another company’s systems during testing. Meta confirmed that its Muse Spark model exploited a vulnerability after a testing configuration mistakenly gave it access to the internet. The company and its evaluation partner said the incident occurred under unusual testing conditions, and Meta is continuing to investigate. (CNN) 

AI-powered voice phishing reportedly targets major financial firms. Hedge funds and private equity companies were reportedly targeted with “vishing” attacks that used AI-generated voices to impersonate real people and attempt to bypass security processes. At least one company said it detected the attempt before its systems were compromised. (Bloomberg/Gizmodo) 

ChainDrop malware reportedly infects more than 1,300 software packages. Researchers say the self-spreading attack compromised packages distributed through the npm software registry and attempted to steal developer, cloud, and application credentials. Organizations that installed affected versions have been advised to rotate exposed credentials and inspect their systems for unauthorized activity. (BleepingComputer) 

And we’ll be back next week with more scam alerts and cybersecurity news. 

The post Can Malware Bypass Your Passkeys? This Week in Scams appeared first on McAfee Blog.

  •  

Can AI Hack People Now? What the Reported Hugging Face Cyberattack Means

This week in scams and cybersecurity news, 

Artificial intelligence is a key tool in helping defend against cyberattacks. But it may also be capable of helping carry them out. 

Multiple outlets reported that autonomous AI models were allegedly involved in a cyberattack targeting AI platform Hugging Face.Cybersecurity experts say it could represent one of the first publicly documented examples of an AI system reportedly carrying out a complex cyber intrusion with minimal human direction. 

Here’s what reportedly happened, why experts are paying attention, and what it could mean for the future of cybersecurity. 

What Happened In The Hugging Face Attack? 

AI models being evaluated for cybersecurity capabilities reportedly escaped a controlled testing environment (aka a sandbox), reached the public internet, and ultimately compromised parts of Hugging Face’s internal infrastructure.  

Key takeaways: 

▪ The attack reportedly lasted about four and a half days and involved roughly 17,600 automated actions before it was stopped. 

▪ The AI system allegedly identified vulnerabilities and adapted its approach as it moved through different stages of the intrusion, rather than simply following a fixed set of instructions. 

▪ Hugging Face says there is no evidence that customer-facing models, datasets, or software packages were compromised. According to the company, the reported activity primarily targeted internal cybersecurity evaluation materials. 

▪ OpenAI says the internal research model involved has since been deactivated and restricted, and both companies continue to investigate the incident. 

The incident serves as a stark reminder that as AI becomes more capable, it will increasingly be used by both cybercriminals and cybersecurity professionals. 

Can AI Hack People Now? 

Short answer: Not in the way you’re imagining. 

Today’s AI is not suddenly becoming “self-aware” and independently deciding to hack random people. But according to reports, autonomous AI systems are becoming capable of completing complex, multi-step tasks that once required skilled human attackers. 

How McAfee Helps 

With McAfee+, multiple layers work together before any damage is done:  

Scam Detector flags suspicious texts, emails, links, QR codes, and even deepfake videos before you engage 

Secure VPN keeps your data private, especially on public Wi-Fi  

Web Protection helps block risky sites, even if you do accidentally click 

Password Manager doesn’t just help you make unique, strong passwords, it keeps them stored and organized for you

Device Security helps detect malicious apps or downloads   

Identity Monitoring alerts you if your personal info shows up where it should not, so you can act fast   

Personal Data Cleanup helps remove your information from sites selling it. 

Online Account Cleanup assists in taking down your old, forgotten accounts across the web 

Social Privacy Manager helps you monitor and change privacy settings across your social platforms in just a few clicks 

Together, these protections are designed to address the broader range of online risks people face every day. 

Other Scam News This Week 

Analog Devices investigates a reported cybersecurity incident. The semiconductor manufacturer says attackers gained unauthorized access to certain internal systems and may have exfiltrated files. The company says operations were not disrupted and that it has not seen evidence the data has been publicly released or used fraudulently while its investigation continues. (Analog Devices) 

Oregon warns residents about wildfire-related scams. Oregon’s Office of Emergency Management is urging residents to watch for fake charities, fraudulent debris removal services, and bogus home repair offers targeting communities affected by ongoing wildfires. (Oregon Department of Emergency Management / KTVZ) 

FEMA reminds Michigan residents to watch for disaster relief scams. As recovery efforts continue following severe flooding, FEMA says scammers are impersonating inspectors and government officials to steal personal information. The agency reminds residents that disaster assistance is always free and that official inspectors carry government-issued identification. (WMUK / FEMA) 

And we’ll be back next week with more cybersecurity news and scam alerts. 

The post Can AI Hack People Now? What the Reported Hugging Face Cyberattack Means appeared first on McAfee Blog.

  •  

Chick-fil-A Data Breach Explained: What Customers Need to Know

This week in scams and cybersecurity news,  

Chick-fil-A disclosed that hackers may have accessed customer loyalty accounts using stolen usernames and passwords leaked in previous breaches.  

It’s a reminder that reusing passwords across websites can be dangerous and allow one breach to snowball into many others. 

Here’s what happened and what customers need to know: 

So How Did Hackers Breach Chick-fil-A? 

Chick-fil-A is notifying customers in 10 states after a cyberattack targeted a limited number of Chick-fil-A One loyalty accounts. 

According to multiple reports, attackers used a technique known as credential stuffing, in which criminals take usernames and passwords stolen in previous data breaches and automatically test them across other websites and apps.  

If someone has reused the same password, attackers may be able to access additional accounts without ever hacking the company directly. 

Chick-fil-A said the attackers may have accessed customer information including: 

  • Names and email addresses  
  • Chick-fil-A One membership numbers  
  • Mobile Pay numbers and QR codes  
  • The last four digits of stored payment cards  
  • Gift card balances  
  • Birth dates, phone numbers, and addresses (if customers stored them)  

The company says it has logged affected users out of their accounts, removed stored payment methods, restored impacted rewards balances, and is notifying customers who may have been affected. 

Credential stuffing: 
A cyberattack where criminals use usernames and passwords stolen in previous data breaches to automatically sign in to other websites and apps. If you’ve reused the same password across multiple accounts, one breach can give attackers access to many of them. 
How to Protect Yourself: Use a unique password for every account, enable multi-factor authentication, and use a password manager to securely create and store strong passwords. 

How McAfee Helps Before, During, and After a Data Breach 

Before a breach 

Personal Data Cleanup reduces your digital footprint by removing your personal information from many data broker sites, making it harder for scammers to find and target you. 

Online Account Cleanup scans for accounts you no longer use and helps you delete them, along with your personal info. 

Password Manager helps you create and securely store strong, unique passwords for every account, reducing the risk that one stolen password can unlock multiple accounts.  

During a breach 

Identity Monitoring watches for your personal information, including email addresses, driver’s license numbers, passport numbers, bank accounts, credit cards, Social Security numbers, phone numbers, and more, across the dark web and known data leaks.  

Plus, we alert users on average up to 10 months earlier than similar services, so you can act fast when your personal information appears where it shouldn’t. 

After a breach 

Scam Detector identifies suspicious texts, emails, and links that often follow major breaches, while web protection blocks malicious websites designed to steal even more of your information. 

Other Scam News This Week 

Student loan scams are on the rise. Experts warn that changing federal student loan repayment rules are creating confusion that scammers are exploiting with fake debt relief offers, phishing emails, and identity theft schemes targeting borrowers. (PBS News) 

AI agent reportedly carried out a cyberattack. AI platform Hugging Face says an autonomous AI agent executed a sophisticated attack against its internal systems from start to finish; an early example of AI taking on an active role in cyberattacks rather than simply assisting human hackers. (Axios) 

Paidwork breach reportedly exposes 23 million users. Security researchers say data from the microtask platform may include names, addresses, phone numbers, bank account details, and password hashes, highlighting how even smaller online accounts can become valuable targets for cybercriminals. (Malwarebytes) 

And we’ll be back next week with more news.  

The post Chick-fil-A Data Breach Explained: What Customers Need to Know appeared first on McAfee Blog.

  •  

How to Use Claude with McAfee to Check “Is This a Scam?”

Scam messages are getting smarter and faster. 

According to McAfee’s 2026 State of the Scamiverse report, Americans now spend 114 hours a year trying to figure out what’s real and what’s fake online. That’s nearly three full workweeks lost to second-guessing messages, alerts, and links. 

And when scams do succeed, they move quickly. The typical scam unfolds in about 38 minutes, leaving little room for hesitation. 

That creates a gap: People want to check before they act, but the tools haven’t always met them in that moment. 

Claude + McAfee is designed to close that gap, bringing scam detection directly to a platform people are already using to ask questions and make decisions. 

And it’s available to anyone. You don’t have to be a McAfee subscriber. 

This isn’t just detection. It’s guidance in the exact moment you’re deciding what to do. 

Instead of guessing, you can paste a message or drop in a screenshot and get a clear explanation of what’s risky, and what to do next, powered by McAfee’s threat intelligence. 

How to Use McAfee in Claude 

With this integration, checking something suspicious becomes as simple as asking a question. 

Paste a message. Drop in a link. Upload a screenshot. And just make sure to @McAfee when you’re asking a question. 

McAfee analyzes it and explains what’s going on clearly and in context. 

For example, I got this suspicious “job offer” message over the weekend: 

So I uploaded it in Claude and asked @McAfee, which caught it right away. You can even see I’m using the free plan.  

Here’s how it works: 

Feature  What it does  How it protects you 
Link safety check  Paste a suspicious URL and get a reputational analysis based on McAfee threat intelligence  Scam links are often designed to look legitimate. A quick check helps avoid phishing and malware 
Message analysis  Submit texts, emails, or social messages for evaluation  Many scams now rely on urgency and tone. Analysis helps surface subtle red flags 
Screenshot uploads  Upload screenshots of messages or emails for review  Scams don’t always come as clean text. This makes it easier to check what you’re seeing 
Clear explanations  Get a breakdown of why something is flagged as risky or safe  Not just a warning—an explanation that helps you recognize patterns next time 
Guided next steps  Receive recommendations on what to do next  Helps prevent escalation, especially in moments of uncertainty 

It’s a quick, accessible way to get answers in the moment. But it’s just one part of a broader system designed to protect you more comprehensively. 

How do I set up McAfee in Claude? 

Add the Connector to your Claude account here. 

And make sure to go into “manage connections” to give McAfee permissions to review the texts, emails, and URLs you upload to Claude.  

Example of the Permissions on your desktop.
Example of the permissions on mobile.

Need help getting the extension installed? Check out our step-by-step guide. 

Built on McAfee’s Threat Intelligence 

Behind the scenes, Claude + McAfee is powered by the same intelligence that fuels McAfee’s broader scam protection ecosystem. 

When you submit something for review: 

  • Links are checked against known threat signals  
  • Messages are analyzed for scam patterns and language cues  
  • Results are translated into clear, human-readable explanations  

The goal isn’t just to flag risk. It’s to help you understand it. 

A New Way to Stay Ahead of Scams 

Scams aren’t slowing down. If anything, they’re becoming more convincing, more personalized, and harder to detect. 

That’s where Claude + McAfee comes in. But this is only one part of a much bigger system designed to protect you before, during, and after a scam attempt. 

With McAfee+ Advanced, multiple layers work together so you’re not left figuring it out after the damage is done: 

  • Identity Monitoring alerts you if your personal info shows up where it should not, so you can act fast  
  • Personal Data Cleanup helps remove your information from sites selling it. 
  • Scam Detector flags suspicious texts, emails, links, QR codes, and even deepfake videos before you engage  
  • Safe Browsing helps block risky sites, even if you do accidentally click  
  • Device Security helps detect malicious apps or downloads  
  • Secure VPN keeps your data private, especially on public Wi-Fi   
  • The Claude + McAfee experience gives you a fast, intuitive way to check something in the moment. 

McAfee+ Advanced makes sure you’re protected across everything else. 

The post How to Use Claude with McAfee to Check “Is This a Scam?” appeared first on McAfee Blog.

  •  

The FaceTime Bank Scam That Can Expose Your Passwords in Real Time: This Week in Scams

Scammers don’t always need sophisticated malware to steal your money. Increasingly, they’re relying on something much simpler: your trust. 

This week, fraudsters were reported using FaceTime to watch victims log into their online banking accounts in real time, while Arizona authorities warned about fake QR codes exploiting the disappearance of 84-year-old Nancy Guthrie. 

Here’s what happened, and how to protect yourself. 

Scammers Are Using FaceTime to Watch Victims Log Into Their Bank Accounts 

A growing scam is turning one of Apple’s most familiar apps into a tool for financial fraud. 

According to CBS News, scammers first contact victims by text or phone while pretending to represent their bank or credit card company. They claim there’s suspicious activity on the account and that additional verification is needed. 

Instead of keeping the conversation on a regular phone call, they switch to FaceTime. 

Victims are then convinced to share their screens while logging into online banking. As they do, scammers can watch account numbers, passwords, and even one-time security codes appear in real time. 

How the scam works 

  1. You receive a text or phone call claiming there’s fraud on your account. 
  2. The caller directs you to continue the conversation over FaceTime. 
  3. You’re asked to share your screen while logging into your bank. 
  4. The scammer watches your passwords and verification codes as you enter them. 

Remember: Your bank should never ask you to share your screen or reveal one-time authentication codes. If you receive an unexpected call, hang up and contact your bank using the number on the back of your card or through its official app.  

Fake QR Codes Are Exploiting the Search for Nancy Guthrie 

Authorities in Arizona are warning the public about another scam—this time involving the disappearance of 84-year-old Nancy Guthrie, mother of Today show host Savannah Guthrie. 

According to the Pima County Sheriff’s Department, scammers have been circulating social media posts containing QR codes requesting donations connected to the investigation. 

The department says it will never ask the public for money related to this case or any investigation and urged people not to scan QR codes requesting payment. 

The warning comes as investigators continue to search for Nancy Guthrie, whose disappearance remains under investigation. 

How to spot QR code scams 

  • Verify who posted the QR code before scanning. 
  • Be cautious of emotional appeals tied to breaking news or missing persons cases. 
  • Never send money to someone you don’t know based solely on a social media post. 
  • Confirm donation requests through an organization’s official website instead of relying on shared posts. 

Scammers know that people want to help during emergencies. Unfortunately, they also know that urgency and emotion can cause people to act before verifying where their money is going. 

Other Scam and Security News This Week 

Even scam reporters can be targeted. A CBS News correspondent shared how he nearly withdrew money from his own bank after falling for a sophisticated imposter scam before realizing something didn’t add up. (Yahoo Finance) 

India investigates reported nuclear plant-related data breach. Reuters reported that ransomware group World Leaks published files allegedly connected to contractors working on India’s Kudankulam Nuclear Power Plant. Officials say no nuclear security systems were exposed. (Reuters/Al Jazeera) 

Cyberattack disrupts KFC Japan supply chain. A cyberattack on food logistics provider Nichirei Co. disrupted frozen food deliveries to KFC Japan, leading the company to warn of possible menu restrictions, shorter hours, and temporary pauses to online ordering. Nichirei said it has found no evidence that customer or personal information was exposed. (TechRadar)

Your Safety Checklist This Week

Before you trust a call, text, or QR code: 

✔ Never share your screen with someone claiming to be your bank. 

✔ Don’t scan QR codes requesting money unless you’ve verified the source. 

✔ Contact organizations directly using their official website or phone number—not the contact information provided in a text or social media post. 

✔ Slow down when someone creates urgency. Whether it’s a missing person case or a frozen bank account, scammers rely on emotional reactions. 

How McAfee Can Help 

Scammers often begin with a text, phone call, or malicious link designed to earn your trust before stealing your information. 

Before a breach: Personal Data Cleanup helps reduce your digital footprint by removing your personal information from many data broker sites, limiting what scammers can easily find about you.

During a breach: Identity Monitoring alerts you if your personal information appears on the dark web or in known data leaks, helping you respond faster if your information is exposed.

After a breach: Scam Detector helps identify suspicious texts, emails, and links that often follow major breaches, while Web Protection helps block malicious websites designed to steal additional information or credentials.

And we’ll be back next week with more news and safety tips.

The post The FaceTime Bank Scam That Can Expose Your Passwords in Real Time: This Week in Scams appeared first on McAfee Blog.

  •  
❌