https://files.constantcontact.com/a7cea0f5101/c02ee673-acee-4923-866b-3c99042ee334.jpg?rdr=truea=1135602328535

Issue

715

Wednesday,

December 3, 2025

Amazon Warns Customers of Holidays Cyberattacks as FBI Sees $300M in Thefts: ‘Account Takeover Fraud’

 

Shoppers should be suspicious about delivery or account issue messages.

 

Amazon is warning its over 300 million customers to watch out for cybercriminals who are out in force this holiday season impersonating reps from the e-commerce giant — as the FBI said online crooks have stolen nearly $300 million by taking over victims’ accounts so far this year.

 

The largest online retailer in the world recently emailed customers about criminals trying to “get access to sensitive information like personal or financial information or Amazon account details,” according to Forbes. 

 

The warning came as the FBI said since January, it’s received 5,100 complaints about “account takeover fraud” — in which criminals gain illicit access to accounts in order to rip them off — inflicting losses of over $262 million.

 

For its part, Amazon sounded the alarm about common fraud practices from fake delivery and account issue messages to unsolicited tech support calls.

 

The company also said to be careful about social media ads offering Amazon deals and requests for account or payment info through unofficial channels.


To read this article in its entirety, please click:


Amazon Warns Customers of Holidays Cyberattacks as FBI Sees $300M in Thefts: ‘Account Takeover Fraud’


RiskIT Logo
Is a publication provided by
Eminere Group Logo

Eminere Group is a leading assurance and advisory firm specializing in IT Governance, Risk Management, Cybersecurity, privacy, business risk, and internal audit services.


We distinguish ourselves through our team of highly experienced professionals, all holding relevant certifications and extensive expertise.


Contact Us Here

Hackers Steal Sensitive Data from Major Banking Industry Vendor

 

The incident highlights how supply-chain compromises threaten even well-defended industries.

 

JPMorgan Chase was one of several banks affected by a cyberattack on a major financial-services industry vendor.

 

One of the banking industry’s biggest vendors is responding to a cyberattack that has compromised some of its clients’ sensitive data.

 

SitusAMC, which major banks use to manage their real-estate loans and mortgages, announced on Saturday that hackers broke into its systems on Nov. 12 and stole data that included banks’ “accounting records and legal agreements,” as well as information belonging to some of those banks’ customers.

 

“The incident is now contained and our services are fully operational,” the company said in a statement, adding that the attack, which remains under investigation, did not involve ransomware.

 

A SitusAMC spokesperson declined to answer questions about the incident, including how many of the company’s more than 1,500 clients the breach affected and whether the company had identified the attacker.


The FBI said in a statement that it was helping SitusAMC probe the hack.

 

To read this article in its entirety, please click:


Hackers Steal Sensitive Data from Major Banking Industry Vendor


How Android Malware Lets Thieves Access Your ATM Cash

 

Attackers are now after your ATM cash: How to stay safe

 

Smartphone banking has made life easier, but it has also opened new opportunities for cybercriminals.

 

Over the past few years, we have seen Android malware steal passwords, intercept OTPs and even take remote control of phones to drain accounts. Some scams focus on fake banking apps, while others rely on phishing messages that trick you into entering sensitive details.

 

Security researchers have now discovered a new threat that goes a step further. Instead of simply stealing login information, this malware gives thieves the ability to walk up to an ATM and withdraw your money in real time.

 

How the NGate Malware Works

 

The Polish Computer Emergency Response Team (CERT Polska) discovered a new Android malware called NGate that uses NFC activity to access a victim's bank account. This malware monitors contactless payment actions on the victim's phone and forwards all transaction data, including the PIN, directly to a server controlled by attackers. It does not just copy card details. Instead, it waits until the victim taps to pay or performs a verification step, then captures the fresh, one-time authentication codes that modern Visa and Mastercard chips generate.

  

To read this article in its entirety, please click:


How Android Malware Lets Thieves Access Your ATM Cash


Digital Fraud at Industrial Scale: 2025 Wasn't Great

 

Advanced fraud attacks surged 180% in 2025 as cyber scammers used generative AI to churn out flawless IDs, deepfakes, and autonomous bots at levels never before seen.

 

The global battle against digital fraud has become more fraught, with cybercriminals pivoting from high-volume, opportunistic attacks to sophisticated, AI-driven operations; they're not just harder to detect, but can cause substantially more damage as well.

 

An analysis of data from more than 4 million fraud attempts, and surveys of some 300 fraud and risk professions and another 1,200 end users by Sumsub, found what the identity verification firm described as a noticeable "sophistication shift" over the past year.

 

A Sophistication Shift for Fraud & Phishing

 

Fraud involving the use of advanced deception techniques, social engineering, AI-generated identities, and telemetry tampering surged 180% year-over-year, even as the share of these incidents within the overall fraud volume increased from 10% in 2024 to 28% in 2025. Ominously, Sumsub found scammers increasingly deploying autonomous systems capable of executing multistep fraud with minimal human intervention. AI-generated documents accounted for just 2% of all fake IDs and records used in digital fraud last year. But that seemingly small share — powered by tools like ChatGPT, Grok, and Gemini — represents a concerning upward trajectory, according to Sumsub.


To read this article in its entirety, please click:


Digital Fraud at Industrial Scale: 2025 Wasn't Great

  

How AI Deepfakes Turn Human Trust Into a Cyber Risk

 

Jeremy Nelson of Insight on AI-Driven Deception and Automated Threats

 

Artificial intelligence deepfakes have created an unprecedented crisis in identity verification, exposing enterprises to a new class of identity-driven cyber risk.

 

"The ability to trust what we see and hear is completely wiped away," said Jeremy Nelson, CISO for North America at Insight. "We now find ourselves completely reliant on other tools and mechanisms in order to be able to fill that gap that deepfakes and AI have now been able to subvert."

 

Nelson advocates for decentralized identity systems coupled with real-time biometric verification as a resolution to this problem. Like a digital driver's license from trusted issuers, these solutions provide cryptographically sound validation that surpasses what our eyes and ears can no longer reliably confirm in the deepfake era.

 

In this video interview with Information Security Media Group at Microsoft Ignite 2025, Nelson also discussed:

 

  • Why functions such as accounts payable, HR and IT support have become prime entry points;


  • How generative AI enables threat actors to execute social engineering attacks at unprecedented scale;



  • Why centralized identity systems prove monolithic and limited against AI-enabled attacks.


To read this article in its entirety, please click:


How AI Deepfakes Turn Human Trust Into a Cyber Risk



More Useful Links: