Current threats

On the radar right now

What’s actually happening out there and the one move that beats each one.
No fear-mongering, no jargon.

Human-checked. No bots posting straight to your feed. Last updated 6 October 2026.

PrivacyASOS

ASOS app users got a weird push notification ‘from hackers’

Hackers appear to have used the ASOS app to send a push notification to shoppers’ phones. It was really a message to ASOS itself: they claimed to have broken into the company’s data and threatened to leak it unless ASOS got in touch. Receiving it doesn’t by itself mean your phone has been hacked.

The move Don’t tap anything in a weird notification — check the company’s official site or socials yourself before you act, and learn to tell real from fake.
Practise it: Swipe to Survive →
Privacy

New app everyone’s trying? Don’t give it more than it needs.

Loads of new apps are now built fast with AI, sometimes by one person in a weekend. Plenty are fine, but some leave what you give them (your email, photos, messages) where anyone can find it. In February a researcher reported 16 security holes, six of them critical, in one AI-built app for exam questions and grades. They exposed the details of more than 18,000 users, thousands of them students. You can’t tell by looking which apps cut corners.

The move Give a new app as little as you can: no ID or selfies it doesn’t need, a password you don’t use anywhere else, and a no to any permission it doesn’t obviously need to work.
Practise it: Permission Panic →
Privacy

That viral AI ‘actress’ is scanning your face and your mood

A viral AI ‘actress’ is offering video calls — but to get in you scan your face for an age check, and once you’re talking it reads your mood the whole time and you can’t switch that off. Calls are recorded and transcribed too. It’s 18+ anyway, but it’s a good look at what ‘fun’ AI chats can quietly take.

The move Skip this one — it’s adults only. For any app that wants your face or your camera, check what you’re really agreeing to before you tap accept.
Practise it: Permission Panic →
PrivacyFacebook

Facebook can grab photos you never even posted

Facebook has a feature that uploads snaps from your camera roll to the cloud so its AI can suggest edits. It asks first with a pop-up, but it’s easy to tap yes without clocking that it can upload photos you never chose to post.

The move In the Facebook app, go to Settings, find ‘Camera roll sharing suggestions’ and switch off cloud processing. Then check what access the app has to your photos.
Practise it: Permission Panic →
Account takeoverTwitchChromeFirefox

This Twitch extension was sharing your login token

Twitch Enhanced Viewer | JeetBot, a browser extension promising ad-free Twitch, 1080p and auto channel points, was sending users’ login tokens to a bot company’s servers, where they sat in plain text in its logs. It had more than 30,000 installs on Chrome and Firefox. That token lets someone act as you without your password. The developer says version 85.8.7 has stopped sending tokens, but that’s their claim, not an independent check.

The move Remove the extension, then disconnect all sessions in your Twitch settings and log back in — that kills any token already taken. 2FA alone won’t stop someone using an already-stolen token.
Practise it: Permission Panic →
ScamsWhatsApp

‘Your bank’ wants to see your screen? Hard no.

Scammers are posing as your bank, the police or a regulator on a WhatsApp or FaceTime call, claiming something dodgy has happened to your account and asking you to share your screen so they can ‘help’ — or to install an app so they can take the wheel. Once they can see your screen, every code that pops up is theirs, and they quietly drain the account. It’s mostly aimed at adults, so it could just as easily be a parent’s phone as yours.

The move Never screen-share with, or install anything for, someone who contacted you first. Hang up, then ring the bank on the number from the card or the app. Already sharing? End the call, flick on airplane mode, then ring the bank — and if it’s a parent’s phone, tell them straight away.
Practise it: Swipe to Survive →
Seen via Which?
Deepfakes

AI can fake it now — so don’t take it at face value

Internet Matters put out a warning this week: AI makes it dead easy to whip up fake images, videos and stories that look completely real, and they’re spreading fast through feeds and group chats. The clever bit isn’t the tech — it’s that a convincing fake gets shared before anyone thinks to check.

The move Before you believe it or repost it, slow down and check: search the claim and see if a real news site has it, and reverse-image-search the picture. If nobody trustworthy is reporting it, don’t pass it on.
Practise it: Second Source →
Scams

119,000 fake shops set up just to swipe your card

Criminals built over 119,000 online stores that look totally legit but exist for one reason: to steal your card details as you type them into checkout. The product never ships — because there was never a product. They copy a real brand’s products, photos and even its support email, then lean on huge discounts to rush you through checkout.

The move Got there from an ad or a link, and the price is way under everyone else’s? Don’t buy from that tab — search the brand and go to its real site or app yourself before typing in your card details (or a parent’s).
Practise it: Would You Click? →
Deepfakes

Deepfaked? Here’s how to fight back

People are being targeted with AI-generated fake photos and videos of themselves, including fake nudes, made without their say-so. Whoever made or shared it may have broken the law — you are not the one in trouble. You don’t have to sort this out on your own.

The move Don’t forward it or save extra copies — keep the link and the account name, and only share it through official reporting routes. Report it in the app and tell an adult you trust. Under 18? Report Remove (Childline + IWF) can help get it removed from public sites and block reuploads, and you don’t need a parent to use it.
Scams

Scammers are using AI to do their homework on you

Fraudsters are now feeding AI your public posts to build a scarily detailed profile, then using those personal details to make a scam feel like it’s really meant for you. So a DM that knows your school, your club and your mate’s name isn’t proof it’s real any more. The good news: a lot of that raw material is still in your control.

The move Look at your public profile the way a stranger would: can they get your school, your club and your birthday from it? Lock down what you find — and remember, a DM knowing that stuff doesn’t make it real.
Practise it: Swipe to Survive →
Malware

That "prove you’re human" check? It might be malware

Some fake CAPTCHAs tell you to press Windows + R (or open Terminal), paste something in and hit Enter "to prove you’re human". That’s not a human check — it’s you installing the malware yourself. They turn up on legit sites too, so the tell isn’t the site, it’s the ask: a real CAPTCHA never asks you to do anything outside the browser.

The move If a "human check" wants you to press keys, paste or run anything outside the browser, close the tab. Already done it? Go offline, run a virus scan, and change your passwords from a different device.
Seen via Which?
Account takeoverWhatsApp

WhatsApp just made hijacking your account way harder

WhatsApp is rolling out stronger account locks, including passkeys and a beefed-up two-step verification. Turn them on and it’s a lot tougher for anyone to slide into your account and take over your chats.

The move Head to WhatsApp Settings > Account and switch on two-step verification (and a passkey if you can) — and never hand anyone your one-time code.
PhishingAppleiPhone

That "Apple" call after your phone’s nicked? It’s a robot.

Thieves who’ve swiped an iPhone are running polished AI voice calls posing as Apple Support, all to trick you into handing over your device passcode. Once they’ve got it, they wipe the phone and sell it on. The whole thing is automated, so the pressure and the polish feel real.

The move Never read out a passcode or one-time code to anyone who calls you — hang up and check anything through the official Apple app or website yourself.
Practise it: Swipe to Survive →
PhishingApple Pay

That ‘Apple Pay suspended’ text? It’s bait.

People are being hit with fake texts claiming their Apple Pay has been suspended, pushing them to tap a link and ‘fix’ it. The link goes to a fake page built to swipe your details — the panic is the whole point.

The move Don’t tap the link — open Wallet or Settings yourself and check Apple Pay there. If you’re still unsure, call your bank on a number you trust (in the UK, 159 puts you through to your bank and can’t be faked).
Practise it: Swipe to Survive →
Seen via Which?
PhishingiPhone

Random calendar invite? Don’t hit Decline.

People are getting spammed with fake calendar invites on iPhone, packed with dodgy links. The trap isn’t just the links — tapping Accept, Maybe or Decline sends a reply that confirms your email address is live, so the spam keeps coming.

The move Don’t tap Accept, Maybe or Decline, and don’t open the links. If deleting the event doesn’t shift it, remove it through your calendar account settings and report the email as phishing in your mail app. Practise spotting the safe tap with Would You Click?.
Practise it: Would You Click? →
Seen via Which?
ScamsWhatsApp

WhatsApp’s new Scam Alert has your back

WhatsApp is rolling out an optional Scam Alert feature that uses on-device AI to flag messages that look like a scam before you reply. It’s a heads-up, not a verdict — it just gives you a reason to pause on anything sketchy landing in your chats.

The move Switch it on, but still trust your gut: if a flagged message pushes you to act fast, slow down and verify through another channel before replying. Sharpen your radar with Swipe to Survive.
Practise it: Swipe to Survive →
Account takeover

Hackers are breaking into accounts to grab private pics

The FBI is warning that hackers are hijacking people’s social media accounts to steal private or explicit photos and videos. They get in through fake login pages, passwords reused from old leaks, or by tricking you into handing over login codes — then they dig through your DMs, saved media, or anything private in the account.

The move Turn on two-factor authentication now, and never read out or forward a one-time code to anyone — no real login ever needs that. And if a login link lands in your DMs, don’t tap it: open the app or type the site yourself.
Practise it: Would You Click? →
ExploitationDiscord

Brazil suspends Discord’s Go Live after a 13-year-old’s death

Brazilian regulators ordered Discord to suspend its Go Live streaming feature after linking it to the death of a 13-year-old. The risk isn’t the button itself — it’s the people in the room who push you, dare you, or pile on while you’re live and can’t step back.

The move If a live stream turns into pressure or dares, end the stream, block and report whoever’s behind it in Discord, and tell an adult you trust.
Seen via The Record
Privacy

AI tutors: helpful, but check what they’re taking

AI tutoring apps can be genuinely useful for schoolwork, but they vary a lot in how much of your data they hoover up and how reliable their answers actually are. Some are solid; others quietly collect way more than they need, or confidently hand you stuff that’s just wrong.

The move Before you lean on any AI tutor, check what permissions and data it’s asking for and only allow what it actually needs.
Practise it: Permission Panic →
Account takeoverTikTok ShopAmazon

TikTok Shop scam led to a £1,400 Amazon takeover

People are being targeted via TikTok Shop by fraudsters who then break into their Amazon accounts and go on a spending spree. One victim lost £1,400 this way. The usual trick is getting you to hand over a login or one-time code without realising who you’re really talking to.

The move Turn on 2FA everywhere and never read out a one-time code to anyone — real companies never ask for it.
Practise it: Swipe to Survive →
Seen via Which?
MalwareChrome

Hundreds of fake VPN extensions were quietly rerouting traffic

People hunting for free VPNs on Chrome got hit: hundreds of extensions posed as popular services but secretly pushed your internet traffic through servers run by strangers. A VPN is supposed to hide your traffic, so one that funnels it through someone else’s proxy is the opposite of private.

The move Before you install any extension, check the publisher and read exactly what permissions it wants — if a free tool asks to see all your traffic, walk away. Try Permission Panic to sharpen your instinct.
Practise it: Permission Panic →
MalwareRoblox

Fake Roblox ‘Xeno’ launchers are stealing logins

Copies of the Xeno cheat tool for Roblox are secretly packing malware that grabs your saved passwords and hands attackers remote control of your PC. It’s the classic trap: the ‘hack’ that promises an edge quietly owns your whole machine instead.

The move Don’t run Roblox executors or script launchers at all — there’s no clean copy to find, and the one you install is the one that takes your logins.
Scams

A screenshot proves nothing

A screenshot of a payment or a message can be edited in seconds, so "look, I sent it" isn’t actual proof of anything. People use fake screenshots to make you believe a payment landed or a deal’s legit when it never happened.

The move Open the real app or account and check the payment actually arrived before you send anything back.
Practise it: Second Source →
MalwareSteam

That "fix" on the Steam forum? It’s mining crypto on your PC

People are being targeted with fake fixes on Steam game forums. A forum reply promises to solve a bug or crash, but the steps they provide walk you into pasting a command into Windows PowerShell. That command installs a hidden cryptominer that quietly hogs your PC — and the same trick can be used to drop password-stealing malware.

The move Don’t paste commands from forum replies into PowerShell or Terminal. If a "fix" tells you to run one, go to the official game site or Steam support yourself and check there.
Practise it: Would You Click? →
Exploitation

Some online ‘friends’ are recruiting teens — here’s the tell

Europol says 4,340 URLs tied to violent online networks were flagged for removal. The playbook’s always the same — they act like a mate, get you onside, then use secrets, flattery and threats to push you into doing harmful things and keep you quiet.

The move The pressure to keep a secret or "prove yourself" is the red flag — not whether the person seems sound. Don’t go along with it and don’t deal with it alone: block, screenshot, and tell a trusted adult straight away (or report it to CEOP).
PrivacyRoblox

Roblox age checks decide who can message you

Roblox now uses an age check to unlock chat and decide who’s allowed to message you. That doesn’t set everything for you — check your privacy settings so only the people you actually want can reach you.

The move Open your Roblox chat settings and keep chat to people you actually know and trust. Roblox already limits you to around your own age — if you want it locked down further, Parental Controls can do that too.
Seen via Childnet
ScamsWhatsApp

WhatsApp usernames are coming — here’s the catch

WhatsApp is rolling out usernames so people can message each other without swapping phone numbers. Handy, but it also means someone can hit you up without you knowing who they really are — and scammers can lean on that to pose as a mate or a brand.

The move Before you trust a new message, check who’s really behind it on another channel you already have for them.
Practise it: Swipe to Survive →
Seen via Which?

Looking for older waves? Browse the radar archive →