Security Reference
Scam Watch
Last updated: July 2026
A regularly updated reference of active scams targeting businesses and individuals. Use the tabs below to browse by how the scam reaches you. Bookmark this page and check back as we update it when new threats emerge.
⚠ High Risk
MFA Bypass via Microsoft 365 OAuth Tokens
The FBI issued a formal warning in May 2026 about Kali365, a phishing kit sold on Telegram that bypasses multi-factor authentication without stealing your password. A phishing email with a legitimate-looking Microsoft device authorization code links to Microsoft’s real login page. When you complete MFA normally, the attacker receives your OAuth access token and gains persistent access to your Outlook, Teams, and OneDrive. Even users with MFA enabled are vulnerable.
What to do: Be suspicious of any email asking you to visit a Microsoft device authorization page or enter a device code. Your IT administrator can restrict device code authentication through Conditional Access policies. If you believe your account was compromised, revoke active session tokens immediately.
Also arrives via: Text
Added June 2026
⚠ High Risk
Fake CAPTCHA Malware Installs
The FTC issued an alert in June 2026 about a scam that looks exactly like a standard CAPTCHA. A pop-up asks you to prove you are human but instead of clicking images or typing characters, it instructs you to press Windows + R, then Ctrl + V, then Enter. Following those steps pastes and runs hidden malware placed in your clipboard without your knowledge.
What to do: A real CAPTCHA will never ask you to press keyboard shortcuts or run commands. If any website asks you to press Windows + R or open a Run dialog, close the browser tab immediately and run a malware scan.
Added June 2026
⚠ High Risk
Fake Party & Event Invitation Phishing
The FTC warned in May 2026 that scammers are sending fake digital invitations impersonating platforms like Evite and Paperless Post. The invitation may list someone you know as the host. To RSVP, it asks you to sign in with Google or Microsoft. Those login screens are fake and capture your credentials, giving attackers access to every account linked to that login. Over 80 fraudulent domains running this campaign have been identified.
What to do: Real invitation platforms do not ask for your Google or Microsoft login to open an invitation. If you receive an unexpected invite requiring a login, contact the supposed host directly before clicking anything.
Also arrives via: Text
Added June 2026
⚠ High Risk
Summer Travel Phishing
Travel-related cyberattacks increased 122% over the past three years, with 47,318 new fraudulent travel domains registered in May 2026 alone — one in every 112 already classified as malicious. Scammers impersonate Booking.com, Airbnb, Skyscanner, and major airlines with convincing fake websites and WhatsApp messages claiming problems with your reservation. Some messages include genuine booking details obtained from prior data breaches to appear credible. Norton data shows imposter scams surge 144% in summer months.
What to do: Book travel only through official websites by typing addresses directly into your browser. Never click links in unsolicited emails or texts about reservations. If a message claims there is a problem with your booking, call the hotel or airline at a number from their official site.
Also arrives via: Text, Social Media
Added July 2026
⚠ High Risk
AI-Generated Phishing Emails
Over 80% of phishing emails are now AI-generated, with a 60% higher click rate than traditionally written scams. These emails are grammatically perfect, match your organization’s tone, and can appear to come from someone you know. Hoxhunt research recorded a 14x surge in AI-generated phishing in late 2025 that has continued into 2026. You can no longer use poor writing or odd phrasing as a warning sign.
What to do: Verify any unusual request through a separate channel. Call the sender directly using a known number. Do not reply to the email or use any contact information provided within it.
Added March 2026
⚠ High Risk
CEO / Executive Impersonation (BEC)
Emails appearing to come from your CEO or a senior executive urgently requesting a wire transfer, gift card purchase, or payment instruction change. AI now mimics the exact writing style of specific executives pulled from public sources including LinkedIn and company websites. Business email compromise caused $3.05 billion in verified losses in 2025.
What to do: Never act on financial requests received only by email. Call the executive directly using a known number. Establish a two-person approval policy for all wire transfers regardless of who is asking.
Added March 2026
⚠ High Risk
Callback Phishing
A phishing email with a fake invoice, subscription renewal, or security alert tells you to call a phone number to resolve the issue. Phone numbers bypass email security filters entirely. Once you call, attackers use social engineering to walk you through installing remote access software or revealing credentials. This method increased 500% in late 2025 and continues to grow in 2026.
What to do: Never call a phone number provided in an unexpected email. Look up the company’s contact information independently. Legitimate companies do not send alarming notices requiring you to call immediately to avoid consequences.
Also involves: Phone
Added March 2026
⚠ High Risk
Vendor / Invoice Fraud
A scammer compromises a vendor’s email account or spoofs their domain and sends a fraudulent invoice or updated banking details notice. Payments are redirected to the attacker’s account. The FTC flagged fake invoice scams targeting small businesses specifically in May 2026, noting that scammers send invoices for products or services never ordered, counting on busy staff to pay without checking.
What to do: Any change to payment instructions from a vendor must be verified by calling at a number you already have on file. Verify any unexpected invoice against your purchase records before paying. Never use contact information provided in the invoice itself.
Added March 2026
⚠ High Risk
Fake Microsoft / Google Login Pages
Microsoft remains the most impersonated brand in phishing attacks in 2026, followed by Google. Emails warn of unusual account activity and link to convincing fake login pages. Google’s June 2026 advisory confirmed that attackers are increasingly using cloud-hosted documents with hidden pages to host phishing content, bypassing standard security scanners by exploiting the reputation of trusted platforms.
What to do: Never click login links in emails. Type addresses directly into your browser. Enable multi-factor authentication on all accounts and use an authenticator app rather than SMS codes where possible.
Added March 2026
⚠ High Risk
Tax & IRS Phishing (2026 Dirty Dozen)
The IRS published its 2026 Dirty Dozen list in March 2026. Top threats include emails impersonating the IRS, QuickBooks, TurboTax, and DocuSign with fake filing alerts, AI robocalls using cloned IRS agent voices, and spear-phishing targeting tax professionals. The IRS flagged fabricated long-term capital gains claims on Form 2439 as a new scheme. Over 600 social media IRS impersonators were reported in fiscal year 2025.
What to do: The IRS contacts taxpayers by mail first, never by unsolicited email, text, or social media. Go directly to irs.gov to check your account status. Report suspicious IRS-related emails to phishing@irs.gov.
Also arrives via: Phone, Text
Added March 2026
⚠ High Risk
Real Estate Wire Transfer Fraud
Scammers monitor real estate transaction email threads and at a critical moment send fraudulent wire instructions appearing to come from your agent, attorney, or title company. Funds sent to the wrong account are rarely recovered. This remains a consistently active threat reported regularly to the NJCCIC from New Jersey residents.
What to do: Always verify wire instructions by calling your agent, attorney, or title company at an independently sourced number before sending any funds. Be especially cautious of any last-minute changes to payment details.
Added March 2026
⚠ High Risk
Fake Job Offers & Employment Scams
With over 1.17 million U.S. layoffs in 2025, employment scams continue to grow in 2026. Scammers post fake positions on legitimate job boards or contact job seekers directly to collect Social Security numbers, banking details, or upfront fees. Hoxhunt data shows a surge in recruitment scams targeting HR professionals with fake job seekers and Sales and Marketing staff with fraudulent job offers.
What to do: Never pay any fee to obtain a job or interview. Research the company independently before providing any personal information. A legitimate employer will never ask for upfront payment of any kind.
Also arrives via: Text, Social Media
Added May 2026
⚠ High Risk
Childcare Provider Scams
The FTC issued a warning in June 2026 specifically targeting childcare providers and other service businesses. A scammer contacts a provider urgently needing service and sends a check for more than the agreed amount, then asks you to wire back the difference. The check is fraudulent and you are left liable for the full amount once it bounces. Similar versions target pet sitters, tutors, cleaners, and other service providers.
What to do: Never accept a check for more than the agreed amount and wire back the difference under any circumstances. Treat any overpayment as a fraud attempt. Wait for checks to fully clear at your bank before providing services or returning any funds.
Added June 2026
● Medium Risk
Amazon Prime & Subscription Renewal Scams
The NJCCIC issued an alert in April 2026 about an active phishing campaign impersonating Amazon Prime renewal notices. Similar campaigns target Netflix, Adobe, and other subscription services. The sender address is not associated with the real company despite official-looking branding. Clicking the link leads to a credential and payment harvesting site. Package delivery scams spike 89% in summer months according to Norton’s 2026 threat research.
What to do: Do not click links in subscription renewal emails. Navigate directly to the company’s website by typing the address yourself to check your account status. Check the actual sender email address carefully for misspellings or unrelated domains.
Added April 2026
● Medium Risk
Investment Scams
Scammers use deepfake videos of celebrities and public figures to promote fake investment platforms. Investment scams caused the highest financial losses of any fraud category in 2024 at $5.7 billion. Romance-based crypto investment scams cost U.S. victims over $1.16 billion in 2025. Norton blocked 20 million dating scam attacks in Q1 2026 alone. Financial scams surge 55% in summer months.
What to do: No legitimate investment guarantees profit. Be skeptical of any unsolicited investment opportunity, especially those promoted by someone you met online. Never invest money you cannot afford to lose entirely.
Also arrives via: Social Media, Phone
Added March 2026
● Medium Risk
Social Engineering & Pretexting
Attackers research targets using LinkedIn and company websites, then craft personalized scenarios to manipulate them into revealing information or granting access. Google’s June 2026 advisory flagged multi-channel attacks — where the same fake message arrives through email, text, and a calendar invite simultaneously — as a growing tactic that makes these attempts significantly more convincing.
What to do: Verify the identity of anyone requesting sensitive information or system access through a separate, independently sourced channel. A second opinion from a colleague before acting on an unusual request can prevent costly mistakes.
Also arrives via: Phone, Text
Added March 2026
● Medium Risk
CIPA Website Privacy Demand Letters
This is not a phishing scam but a legal threat targeting any business with a website. Serial litigants and plaintiffs’ firms send demand letters claiming your website violates California’s Invasion of Privacy Act by using standard tools like Google Analytics, Meta Pixel, or chat widgets without explicit consent. Statutory damages are $5,000 per violation with no proof of actual harm required. Settling one claim can mark you as a target for follow-on letters from other firms.
What to do: Do not ignore these letters and do not pay without legal advice. Consult a privacy attorney before responding. Audit your website for third-party tracking tools and consider implementing a cookie consent manager that blocks non-essential scripts until a visitor actively consents. Paying one settlement can invite additional claims.
Added June 2026
⚠ High Risk
Calendar Invite Phishing
Google’s June 2026 scams advisory flagged fake calendar invites as an emerging attack vector. Scammers send invitations that automatically appear on your Google Calendar even from unknown senders. The invites look like security alerts, billing notices, subscription renewals, or event notifications. Because calendar invites arrive outside the email inbox, they bypass many phishing filters. Google confirmed attackers are also using “invisible pages” in cloud documents to host phishing instructions that evade standard web filters.
What to do: In Google Calendar settings, change your invitation settings to only show invitations from people in your contacts. Do not click links in unexpected calendar invites. Turn off automatic event creation from emails if you do not use that feature.
Added June 2026
⚠ High Risk
NJ MVC & E-ZPass Text Scams
The NJCCIC continues to receive active reports in 2026 of SMS phishing targeting New Jersey residents. Texts impersonate the NJ Motor Vehicle Commission claiming unpaid traffic tickets with threatening language about license suspension and credit damage. Separate campaigns impersonate E-ZPass and NJ Courts. The NJCCIC identified over 20,000 second-level domains linked to these campaigns. The FTC reported $470 million in losses from text message scams in 2024, a fivefold increase since 2020.
What to do: The NJ MVC only texts residents about scheduled appointments. E-ZPass does not send unsolicited payment requests by text. NJ Courts do not collect fines by text. Go directly to the official agency website to verify any claimed balance. Forward suspicious texts to 7726 (SPAM).
Added May 2026
⚠ High Risk
Fake Party & Event Invitation Phishing
The FTC warned in May 2026 that scammers are sending fake digital invitations by text as well as email, impersonating platforms like Evite and Paperless Post. To RSVP, it asks you to sign in with Google or Microsoft. Those login screens are fake and capture your credentials, giving attackers access to every account linked to that login.
What to do: Real invitation platforms do not ask for your Google or Microsoft login to open an invitation. If you receive an unexpected invite requiring a login, contact the supposed host directly before clicking anything.
Also arrives via: Email
Added June 2026
● Medium Risk
QR Code Phishing (“Quishing”)
Emails and physical materials contain QR codes directing you to fake login pages or malware downloads. Attackers place fake QR code stickers over legitimate codes at parking meters, retail locations, and office signage. Bitdefender’s summer 2026 travel research found scammers placing fake QR codes at restaurants, museums, and tourist attractions, redirecting to fake payment pages. Google’s June 2026 advisory confirmed quishing remains a growing attack method.
What to do: Use a QR scanner that previews the destination URL before opening it. Before scanning any QR code in a public place, check for signs of tampering. Never scan a QR code from an unexpected email using your phone.
Also arrives via: Email, In-Person
Added March 2026
● Medium Risk
Toll Road & Delivery Text Scams
Toll road scams increased 900% in 2025 and remain active in 2026. Text messages claim you have an unpaid toll balance or an undeliverable package with a link to pay a small fee. The FTC received 59,271 IC3 complaints related to toll scams in 2024. Package delivery scams surge 89% in summer months according to Norton’s threat research. Scammers impersonate E-ZPass, SunPass, UPS, FedEx, and USPS.
What to do: Do not click links in unexpected texts. Go directly to the carrier’s or toll authority’s official website by typing the address yourself. Legitimate services do not demand immediate payment by text.
Added May 2026
● Medium Risk
Rewards Points Expiration Scams
The FTC reported in June 2026 that people are receiving texts and emails warning that their loyalty or rewards points are about to expire. The message looks like it is from a real rewards program and includes a link to redeem points before they expire. The link leads to a fake login page designed to steal your username, password, and sometimes payment information.
What to do: Do not click links in rewards expiration messages. Log in to the rewards program directly by typing the address yourself to check your points balance. Real programs rarely require immediate action to prevent expiration.
Added June 2026
⚠ High Risk
Deepfake Video & Voice Call Scams
In a widely reported case, a finance employee wired $25 million after joining a video call where every participant, including the CFO, was a deepfake. The FBI’s 2025 Internet Crime Report noted deepfake and voice cloning scams cost Americans nearly $900 million in 2025. Romance scams using AI-generated video profiles are surging in summer 2026, with Norton blocking 20 million dating scam attacks in Q1 2026 alone. The old “send me a selfie holding today’s newspaper” verification is no longer reliable.
What to do: Establish a verbal code word with your family and colleagues for genuine emergencies. For any financial request made by phone or video, hang up and call back on a number you have on file independently. Treat any unexpected video call involving money or credentials as suspicious regardless of who appears on screen.
Added May 2026
⚠ High Risk
Tech Support Impersonation
A pop-up, email, or phone call claims your computer has a critical security problem and instructs you to call a number or grant remote access. Tech support scams surge 30% in summer months according to Norton’s 2026 research. Apple issued a specific warning in early 2026 about Apple Pay impersonation scams. The AARP notes a terror-based variation where scammers claim you are the subject of a criminal investigation and hold you “digitally captive” on video calls for hours or days, pressing for payment.
What to do: Microsoft and Apple do not contact you unsolicited about computer or account problems. Close the pop-up, hang up the call, and never grant remote access to someone who contacts you first. No legitimate organization will hold you on a call for hours demanding payment.
Also arrives via: Email, Pop-Up
Added March 2026
⚠ High Risk
Government Impersonation & Jury Duty Scams
The FTC reported $3.5 billion in losses to imposter scams in 2025, with government impersonation the leading category for the ninth consecutive year. A resurgent version involves calls claiming you missed jury duty and threatening arrest unless you pay immediately by gift card or cryptocurrency. The FTC filed a complaint in April 2026 against operators impersonating the government and large insurance carriers to sell fake health insurance plans.
What to do: Real courts and law enforcement do not call to threaten arrest for missed jury duty. Government agencies do not demand payment by gift card, cryptocurrency, or wire transfer. Hang up and call the agency directly using a number from their official .gov website.
Also arrives via: Email, Text
Added March 2026
⚠ High Risk
Callback Phishing
A phishing email with a fake invoice or security alert instructs you to call a phone number to resolve the issue. Phone numbers bypass email security filters. Once you call, attackers use social engineering to walk you through installing remote access software or revealing credentials. This method increased 500% in late 2025 and continues to grow in 2026.
What to do: Never call a phone number provided in an unexpected email. Look up the company’s contact information independently. Legitimate companies do not send alarming notices requiring you to call immediately to avoid consequences.
Starts via: Email
Added March 2026
● Medium Risk
Pension & Retirement Plan Scams
Scammers contact employees by phone, email, or social media offering a free review of retirement savings with promises of better returns, collecting personal information and attempting to redirect deposits. Fraudulent domains mimic official state pension websites, including those for New Jersey state employees. Adults 60 and older who reported losses of $10,000 or more from imposter scams alone more than quadrupled between 2020 and 2024 according to FTC data.
What to do: Contact your HR department or plan administrator directly using contact information from official company communications, not from any unsolicited message. Never provide financial information to someone who reaches out to you first.
Also arrives via: Email, Social Media
Added March 2026
⚠ High Risk
Pet Adoption & Sale Scams
The FTC issued a warning in late June 2026 specifically about pet scams targeting animal lovers. Scammers steal and manipulate real pet photos and videos, or use AI-generated deepfakes, to create convincing fake listings for puppies, kittens, and other animals. After you pay a deposit or purchase price, the animal never arrives and the seller disappears. Some demand additional fees for “shipping insurance” or “customs clearance” to extract further payments. These scams are particularly common on social media and classified ad sites.
What to do: Never purchase a pet you have not seen in person or via a live video call showing the actual animal. Be suspicious of any seller who cannot meet locally or who asks for wire transfers, gift cards, or cryptocurrency. Research the seller independently before sending any money.
Also arrives via: Email, Social Media
Added July 2026
⚠ High Risk
Hurricane & Disaster Relief Scams
The FTC issued a hurricane season warning on June 1, 2026 — the first day of hurricane season. Scammers follow weather emergencies wherever they strike, impersonating FEMA, the Red Cross, and local relief organizations to collect donations that never reach victims, or to target displaced residents with fake recovery assistance offers. Fraudulent contractors also appear after storms offering debris removal or home repairs, collecting deposits and disappearing. These scams are active even in regions where the storm did not hit directly.
What to do: Donate only to established, verifiable charities through their official websites. Before hiring a contractor after a disaster, verify their license with your state licensing board and never pay the full amount upfront. FEMA does not charge fees for disaster assistance applications.
Also arrives via: Email, Text, Phone
Added July 2026
⚠ High Risk
FIFA World Cup 2026 Scams (Active Through July 19)
The FIFA World Cup runs through July 19, 2026, with MetLife Stadium in East Rutherford, NJ hosting the final. Norton’s threat research found gambling scams surge 88% during summer and 338% in the U.S. specifically. Fraudulent ticketing websites, fake merchandise stores, counterfeit sportsbook apps with deepfake celebrity endorsements, and phishing campaigns using World Cup branding are all active. Hundreds of scam domains impersonating FIFA and venue websites were registered ahead of the tournament.
What to do: Purchase tickets only through FIFA’s official website or authorized sellers. Be cautious of any third-party ticketing or betting site, especially those with recently registered domains or celebrity endorsements. Verify the URL carefully before entering any payment information.
Also arrives via: Email, Text
Added May 2026
● Medium Risk
QR Code Stickers on Physical Signs
Attackers place fake QR code stickers over legitimate codes at parking meters, retail locations, restaurants, and office signage. Bitdefender’s summer 2026 travel research found this especially prevalent at tourist attractions and EV charging stations. The codes look identical to the originals. Scanning them leads to fake payment or login pages. Summer travel increases the number of unfamiliar QR codes people encounter and scan without thinking.
What to do: Before scanning any QR code in a public place, look for signs of tampering, particularly a sticker placed over the original. Use a QR scanner that previews the destination URL before opening it. If the URL looks unusual for the location, do not proceed.
Also arrives via: Email, Text
Added March 2026
● Medium Risk
Health Insurance Search Scams
The FTC filed a complaint in April 2026 against operators buying search engine ads for terms like “health insurance” and “Medicare” to intercept people searching for coverage. Clicking the first result leads to fake broker sites or impersonators of HealthCare.gov that collect personal and payment information while enrolling victims in plans they did not choose, or no plan at all. Summer job changes often prompt people to search for new coverage, making this a seasonal risk.
What to do: When searching for health insurance or government healthcare programs, scroll past the ads and go directly to HealthCare.gov or Medicare.gov by typing the address yourself. Official government sites end in .gov.
Also arrives via: Email, Phone
Added June 2026
Sources: NJ Cybersecurity & Communications Integration Cell (NJCCIC) | IRS 2026 Dirty Dozen | FBI Internet Crime Complaint Center (IC3) | FTC Consumer Advice | Google Scams Advisory June 2026 | AARP Fraud Watch | Hoxhunt Phishing Trends Report | Paubox 2026 Email Threat Report | Bitdefender Summer Travel Scams 2026 | Norton 2026 Scam-Free Summer Report | Check Point Research Travel Phishing 2026
Report suspicious activity to the FBI IC3, the FTC, or the NJCCIC. Forward suspicious texts to 7726 (SPAM). Forward phishing emails to reportphishing@apwg.org.