What's actually happening out there and the one move that beats each
one. No fear-mongering, no jargon.
Human-checked. No bots posting straight to your feed. Last updated 28 August 2026.
Scams
Scammers are using AI to do their homework on you
Fraudsters are now feeding AI your public posts to build a scarily detailed profile, then using those personal details to make a scam feel like it's really meant for you. So a DM that knows your school, your club and your mate's name isn't proof it's real any more. The good news: a lot of that raw material is still in your control.
The moveLook at your public profile the way a stranger would: can they get your school, your club and your birthday from it? Lock down what you find — How Exposed Are You? shows you where to look.
That "prove you're human" check? It might be malware
Some fake CAPTCHAs tell you to press Windows + R (or open Terminal), paste something in and hit Enter "to prove you're human". That's not a human check — it's you installing the malware yourself. They turn up on legit sites too, so the tell isn't the site, it's the ask: a real CAPTCHA never asks you to do anything outside the browser.
The moveIf a "human check" wants you to press keys, paste or run anything outside the browser, close the tab. Already done it? Go offline, run a virus scan, and change your passwords from a different device.
WhatsApp just made hijacking your account way harder
WhatsApp is rolling out stronger account locks, including passkeys and a beefed-up two-step verification. Turn them on and it's a lot tougher for anyone to slide into your account and take over your chats.
The moveHead to WhatsApp Settings > Account and switch on two-step verification (and a passkey if you can) — and never hand anyone your one-time code.
That "Apple" call after your phone's nicked? It's a robot.
Thieves who've swiped an iPhone are running polished AI voice calls posing as Apple Support, all to trick you into handing over your device passcode. Once they've got it, they wipe the phone and sell it on. The whole thing is automated, so the pressure and the polish feel real.
The moveNever read out a passcode or one-time code to anyone who calls you — hang up and check anything through the official Apple app or website yourself.
People are being hit with fake texts claiming their Apple Pay has been suspended, pushing them to tap a link and 'fix' it. The link goes to a fake page built to swipe your details — the panic is the whole point.
The moveDon't tap the link — open Wallet or Settings yourself and check Apple Pay there. If you're still unsure, call your bank on a number you trust (in the UK, 159 puts you through to your bank and can't be faked).
People are getting spammed with fake calendar invites on iPhone, packed with dodgy links. The trap isn't just the links — tapping Accept, Maybe or Decline sends a reply that confirms your email address is live, so the spam keeps coming.
The moveDon't tap Accept, Maybe or Decline, and don't open the links. If deleting the event doesn't shift it, remove it through your calendar account settings and report the email as phishing in your mail app. Practise spotting the safe tap with Would You Click?.
WhatsApp is rolling out an optional Scam Alert feature that uses on-device AI to flag messages that look like a scam before you reply. It's a heads-up, not a verdict — it just gives you a reason to pause on anything sketchy landing in your chats.
The moveSwitch it on, but still trust your gut: if a flagged message pushes you to act fast, slow down and verify through another channel before replying. Sharpen your radar with Swipe to Survive.
Hackers are breaking into accounts to grab private pics
The FBI is warning that hackers are hijacking people’s social media accounts to steal private or explicit photos and videos. They get in through fake login pages, passwords reused from old leaks, or by tricking you into handing over login codes — then they dig through your DMs, saved media, or anything private in the account.
The moveTurn on two-factor authentication now, and never read out or forward a one-time code to anyone — no real login ever needs that. And if a login link lands in your DMs, don’t tap it: open the app or type the site yourself.
Brazil suspends Discord's Go Live after a 13-year-old's death
Brazilian regulators ordered Discord to suspend its Go Live streaming feature after linking it to the death of a 13-year-old. The risk isn’t the button itself — it’s the people in the room who push you, dare you, or pile on while you’re live and can’t step back.
The moveIf a live stream turns into pressure or dares, end the stream, block and report whoever’s behind it in Discord, and tell an adult you trust.
AI tutoring apps can be genuinely useful for schoolwork, but they vary a lot in how much of your data they hoover up and how reliable their answers actually are. Some are solid; others quietly collect way more than they need, or confidently hand you stuff that's just wrong.
The moveBefore you lean on any AI tutor, check what permissions and data it's asking for and only allow what it actually needs.
People are being targeted via TikTok Shop by fraudsters who then break into their Amazon accounts and go on a spending spree. One victim lost £1,400 this way. The usual trick is getting you to hand over a login or one-time code without realising who you're really talking to.
The moveTurn on 2FA everywhere and never read out a one-time code to anyone — real companies never ask for it.
Hundreds of fake VPN extensions were quietly rerouting traffic
People hunting for free VPNs on Chrome got hit: hundreds of extensions posed as popular services but secretly pushed your internet traffic through servers run by strangers. A VPN is supposed to hide your traffic, so one that funnels it through someone else's proxy is the opposite of private.
The moveBefore you install any extension, check the publisher and read exactly what permissions it wants — if a free tool asks to see all your traffic, walk away. Try Permission Panic to sharpen your instinct.
Copies of the Xeno cheat tool for Roblox are secretly packing malware that grabs your saved passwords and hands attackers remote control of your PC. It's the classic trap: the 'hack' that promises an edge quietly owns your whole machine instead.
The moveDon't run Roblox executors or script launchers at all — there's no clean copy to find, and the one you install is the one that takes your logins.
A screenshot of a payment or a message can be edited in seconds, so "look, I sent it" isn't actual proof of anything. People use fake screenshots to make you believe a payment landed or a deal's legit when it never happened.
The moveOpen the real app or account and check the payment actually arrived before you send anything back.
That "fix" on the Steam forum? It's mining crypto on your PC
People are being targeted with fake fixes on Steam game forums. A forum reply promises to solve a bug or crash, but the steps they provide walk you into pasting a command into Windows PowerShell. That command installs a hidden cryptominer that quietly hogs your PC — and the same trick can be used to drop password-stealing malware.
The moveDon't paste commands from forum replies into PowerShell or Terminal. If a "fix" tells you to run one, go to the official game site or Steam support yourself and check there.
Some online 'friends' are recruiting teens — here's the tell
Europol says 4,340 URLs tied to violent online networks were flagged for removal. The playbook's always the same — they act like a mate, get you onside, then use secrets, flattery and threats to push you into doing harmful things and keep you quiet.
The moveThe pressure to keep a secret or "prove yourself" is the red flag — not whether the person seems sound. Don't go along with it and don't deal with it alone: block, screenshot, and tell a trusted adult straight away (or report it to CEOP).
Roblox now uses an age check to unlock chat and decide who's allowed to message you. That doesn't set everything for you — check your privacy settings so only the people you actually want can reach you.
The moveOpen your Roblox chat settings and keep chat to people you actually know and trust. Roblox already limits you to around your own age — if you want it locked down further, Parental Controls can do that too.
WhatsApp is rolling out usernames so people can message each other without swapping phone numbers. Handy, but it also means someone can hit you up without you knowing who they really are — and scammers can lean on that to pose as a mate or a brand.
The moveBefore you trust a new message, check who's really behind it on another channel you already have for them.
Spending hours pouring everything into an AI chatbot can quietly mess with your mood, because it feels like it gets you when it actually can't. It's not a real friend, and it's no replacement for actual people when things get heavy.
The moveSet yourself limits, take proper breaks, and take the big stuff to a person you trust — not a bot.
Some phones, usually ones that just use the front camera, can be fooled by a photo of your face. Face scanners that map your face in 3D are much harder to trick.
The moveUse a strong PIN, passcode or fingerprint for your phone lock, and turn on 2FA for your most important accounts.
That random WhatsApp 'document'? It can hijack your PC
People are being targeted on WhatsApp with messages carrying what looks like a business document — but it's really a script file in disguise. Open it on a Windows PC and it can quietly install software that hands a stranger control of your computer.
The moveDon't open attachments you weren't expecting — check with the sender on another channel first.
That 'handmade' shop with the sad story? Might be all fake
Some accounts on social media are pulling people in with emotional sob stories, deepfake videos and 'artisan' shops selling stuff that doesn't actually exist. The sad story rushes you so you pay before you think to check anything.
The moveSlow down, check the shop's URL properly, and look the seller up somewhere else before you send a penny.
Hackers tricked Instagram's AI bot into stealing accounts
People are being targeted via Instagram after hackers worked out how to social-engineer Meta's AI support bot into resetting passwords. Once they're in, they lock the real owner out and take over the account. It's proof that even an official help tool can be played.
The moveTurn on two-factor authentication now, so a password reset alone can't get anyone into your account.