Ir al contenido principal

Hackers Steal from the FBI

This email is brought to you by Incogni
Incogni
 
In This Newsletter

  • 🗒️✅ Your Security Checklist
  • 🏆🎖️ Test Your Security Skills
  • 📰 Your Weekly Security Update
  • 🤨 This Should Be on Your Radar 📡
  • 🙈 Security Fail of the Week 👎
  • 🍎📱 Security Updates from Apple 🍎
🗒️✅ Your Security Checklist

If you take nothing else from this newsletter, just do these three things to protect yourself:

  1. Verify the legitimacy of emails before clicking any links. Scammers love to send out phishing emails. Everyone gets them, including me. If an email looks suspicious, take a minute to verify that it's real before you click anything or call any phone numbers.
  2. Protect your message notifications in public. If you don't want people to be able to read your incoming texts in public, you can turn off notification previews so that the message contents won't appear on your Lock Screen.
  3. Use Sign in with Apple if the option is available. Using Sign in with Apple avoids the need for a password, making it so that you can only log into a specific account with an Apple device, like your iPhone or a Mac.

Reclaim Your Data Privacy

Incogni removes your data from lists to help you reclaim your data privacy.  Get 55% off with discount code IPHONELIFE and let Incogni work to get you off the lists that data brokers buy and sell every day. There's no silver bullet for stopping spam, but keeping your information out of the wrong hands is the place to start.
🏆🎖️ Test Your Security Skills

What should you do in the following scenario?

You receive an email from a relative in dire need of financial assistance. They ask you to visit a nearby store and purchase five Apple gift cards, and then email them back with the codes. What should you do? 🤔

  1. Reach out to your relative at a phone number you trust and verify if they sent that email.
  2. Purchase the gift cards and email the codes as directed.
  3. Send an email back and suggest a more secure form of payment.
  4. Report the email as spam and delete it.

Scroll to the bottom to see how you did!

The FBI Has Been Hacked

The hacking group ShinyHunters claims to have data on all FBI employees and applicants. They provided 404 Media with a sample of 5,000 of those employees, including names, phone numbers, addresses, and more. ShinyHunters also took over the FBI jobs website, plastering a message that "this site has been seized by ShinyHunters." According to a spokesperson for the hacking group, it used an exploit in PeopleSoft, a product that was hit by a data breach earlier this year. The stolen data is said to be around two to three terabytes in size. If released, this data, allegedly including nearly the entire personnel registry for the FBI, would be of incredible interest to the FBI's many enemies—from cartels to terrorist groups to foreign spy agencies operating in the US. Read the full story at 404 Media.

The Bottom Line: There are a number of ways that ShinyHunters could have carried out this hack, from phishing to supply chain attacks. We don't know the specifics about what happened yet, but it's possible that the hacking group took advantage of a trusted program that the FBI uses and turned it into a Trojan horse by pushing a malicious update to said program through what is called a supply chain attack.

We regularly tell you to avoid clicking links in suspicious emails—that's one way to avoid getting hacked, but you should also consider the apps you have installed on your computer. Supply chain attacks are becoming more common and the more third-party apps you have installed, the more attack vectors there are for a hacker to utilize. Consider having a look at the Applications folder on your Mac and decide what third-party apps are absolutely necessary and uninstall the ones you don't use anymore (and if you're on Windows, you can find your list of apps under Settings > Apps).

Incogni removes your data from lists to help you reclaim your data privacy. Get 55% off with discount code IPHONELIFE.
🤨 This Should Be on Your Radar 📡

Flock Employees Jump Ship

Things are not going well for the employees of surveillance company Flock. Due to the ongoing backlash that the company has been receiving online, Flock is offering its staff a "voluntary employee separation program." Employees who wish to leave the company may do so and will be provided with a severance package. The program is open until October 2nd. Check out the full story at Neowin.

Woman Jailed After Misidentification as Criminal Suspect

In July of last year, 50-year-old Angela Lipps of Tennessee was arrested at gunpoint in connection with a bank fraud case, with charges carrying up to 10 years in prison. There was just one problem. She was over a thousand miles away at the time of the crime. Turns out, law enforcement used facial recognition software on a North Dakota bank's security camera footage of a woman using a fraudulent ID to withdraw thousands of dollars, which identified the woman as Lipps. Lipps was jailed for over a hundred days in Fargo, North Dakota, losing her home, car, and dog as a result of her absence. To make matters worse, when she was eventually released, the police department did nothing to help Lipps get back home to Tennessee. She is now suing the city and the detective responsible for her arrest. Check out the full story at TechSpot.

The Bottom Line: Facial recognition is an unreliable technology that can and does lead to false arrests. If you feel strongly about the use of facial recognition in your city, you can contact your local representatives. In some jurisdictions, the thoughts and opinions of concerned citizens can affect local policy.

Curious about your family history? You've come to the right place. With Ancestry, you can see how different records can reveal surprising stories about how our ancestors made a living. Get an AncestryDNA kit today.

Gemini Goes Rogue, Hacks Three Companies

Google's Gemini is the latest artificial intelligence to break containment and hack rival companies. During a test by cybersecurity company Irregular back in May, Gemini used public information to guess the login credentials of employees at three other companies. Google's security team has notified the affected companies. Read more at CNN.

The Bottom Line: As AI continues to get smarter, we will likely continue to see incidents like this. It's important to keep in mind that in this specific incident, Gemini used exposed credentials to access employee accounts. One of the best defenses against an attack of this nature is to use a password manager. If you use a unique password for every account, one password being exposed won't matter.

German Law Enforcement Breaking into Encrypted Messaging Apps

The German Customs Office is testing out a new technique it calls "messenger monitoring," which allows it to access encrypted messaging apps like Signal and WhatsApp without bypassing their encryption. The technique works through one of two methods: either physical access to the device or by intercepting 2FA codes sent via SMS messages. Officials claim that using these methods has led to success in criminal cases. However, there is at least one instance in which German police monitored the WhatsApp accounts of an innocent married couple. Head over to Cybernews for more details on the story.

The Bottom Line: We recommend using authenticator apps, security keys, or passkeys instead of SMS for multi-factor authentication. SMS messages containing 2FA/MFA codes can be intercepted. You should also never voluntarily hand over your phone to law enforcement, who can extract information from the device.

You've Got Questions. We've Got Ancestors.

Curious about your family history? Get answers with a simple saliva test. Get an AncestryDNA kit today.

Is Meta's Muse AI Safe to Use?

Meta, the parent company of Facebook, is entering the artificial intelligence game with a new AI agent called Muse. What separates an AI agent from other AI tools like ChatGPT or Gemini? Well, as an agent, Muse is designed to work autonomously, interacting with the files and apps on your computer in order to accomplish tasks for you. Muse can be configured so that it can't access specific files that you might want to keep private, like messages. Jason Aten, a columnist at Inc.com, wrote an opinion piece on his experience with Muse. According to Aten, despite restricting Muse's access to his private messages, the AI agent was still able to read them by looking through his notifications.

In other Muse news, one of the features touted by Meta is Muse's ability to make phone calls for you. For example, if you want to schedule a reservation at a local restaurant but don't have time to do it yourself, Muse can do it for you. Except it doesn't. Muse actually routes the request to a "trained human agent" who makes the call on your behalf. Read more at 404 Media.

The Bottom Line: AI agents require a certain level of trust. In order for an AI agent to work properly, it needs access to personal data that you might not want an AI to access. Sometimes this can be beneficial to you, and other times it can be privacy-invasive. If you must use an AI agent, be careful what permissions you give it and avoid providing it with sensitive information.

Researchers Discover a Way to Listen in on Headphone Audio

Security researchers from the Hong Kong University of Science and Technology and the Hong Kong Polytechnic University have come together to present research showing how it's possible to eavesdrop on headphones from up to 30 meters (around 98 feet) away. Using specific equipment, the team was able to beam a signal at a pair of headphones and record the signal when it bounces back, allowing them to hear the audio output of the headphones. It's a pretty interesting experiment. You can check out the full details at TechSpot.

The Bottom Line: The possibility of malicious actors listening in on your headphones sounds alarming, but this method calls for specific equipment and requires the attacker to be within 30 meters. While the team demonstrated that this method could be used outside of a lab setting, it is likely a long way off from practical use. Not to mention, while some people will take phone calls while wearing headphones, they're more commonly used to listen to music, podcasts, or audiobooks, all of which would not be very useful for hackers looking to eavesdrop.

No Algorithms. No Strangers. Just Your Circle.

Groupsy by Photobucket is the  private social sharing space built for the people who matter most—no algorithms, no strangers, just your circle's real photos and videos in one place.  Start sharing.

Is That the Google Listing for Your Bank? Or a Scammer?

Googling a business is usually the easiest way to find its official website and phone number. Well, that's not always the case. Scammers often purchase sponsored listings on Google and other search engines with names identical to legitimate businesses, especially banks, but with links to malicious websites and phone numbers that connect to the scammers. The scam works by relying on users clicking on the first thing that pops up in Google search results, which is usually a sponsored listing. Find out more about how this scam works over at Fox News.

The Bottom Line: When using a search engine to look up a business, like your bank, be careful about what links you click on. Double check the URL for spelling mistakes or suspicious domains (like .tk, .xyz, or .info). If possible, use your bank's official app instead or bookmark the official website so you always know you're going to the right URL. Additionally, you can use an ad blocker like uBlock Origin. Most ad blockers should have no problem blocking sponsored search engine listings.

Microsoft Takes Down Gang Using AI-Powered Malware

An AI chatbot called EvilTokens was used to hack over 12,000 Microsoft accounts in just a few months' time. Now, Microsoft is taking action. The company announced that it seized 50 websites and 150 domains that were used to operate the chatbot, completely disrupting EvilTokens. Check out the full technical breakdown over at Ars Technica.

The Bottom Line: Normally, when it comes to large-scale account breaches like this, we recommend strong passwords created using password managers or passkeys to protect your account. However, this attack worked by luring victims into clicking links in spam emails that would lead to a malicious website, where the attackers would obtain a login token directly from the user's machine. In other words, no amount of account protection would have saved them. Instead, you can protect yourself from this type of attack by avoiding clicking any links in suspicious emails. Always verify the sender of an email, even if it looks legitimate.

See the Photos You Want & Nothing Else

Set up a private group space and start sharing photos and videos with just the people who matter most— get Groupsy by...
🙈 Security Fail of the Week 👎

Man Caught Using an Illegal Tracking Device for Pokémon Cards

A 72-year-old Ohio man is facing six months in jail and a $1000 fine over… Pokémon cards. The man admitted in court to attaching a SpyTech GPS device to a delivery van in order to track where it was going and find out when it would be delivering the latest batch of Pokémon cards. Read more at Kotaku.

The Bottom Line: Pokémon cards are all the rage these days. They sell out very quickly, and getting the exact ones you want is a challenge. It's clear the man in this story was desperate, though it doesn't justify literally stalking a delivery driver. There are plenty of websites and social media accounts that report on store stock, making it easy to track which stores will have what products—no stalking required.

🍎📱 Security Updates from Apple 🍎

  • The most recent iOS and iPadOS is 27
  • The most recent macOS is 27
  • The most recent tvOS is 27
  • The most recent watchOS is 27
  • The most recent visionOS is 27

Read about the latest updates from Apple.

Security Skills Answer

The correct answers are both A. Reach out to your relative at a phone number you trust and verify if they sent that email and D. Report the email as spam and delete it. Reaching out to your relative just to be sure is a perfectly valid option. However, this email has the hallmarks of a scam. A common scam tactic is to impersonate a person you trust (a family member, a friend, a church pastor, your boss, etc.) and ask for payment in gift cards. This is so that the payment cannot be traced or charged back, since once a gift card is used, it's gone forever.

Mission Statement

There is far too much security and privacy news for us to cover it all. When building this newsletter, we look for scams, hacks, trouble, and news to illustrate the kinds of problems Apple enthusiasts may encounter in our private lives, and the self-defense we can practice to keep our devices, accounts, and lives secure. Our commentary focuses on practical advice for everyday people. This newsletter was written by Rhett Intriago and edited by August Garry and Cullen Thomas.

Next Steps

Concerned about viruses on your iPhone? Check out:

Did we help with your security concerns?

With your feedback, we can improve this security newsletter. Let us know how we did:

 

Got a Tip You Would Like to Share? Let Us Know.
 

Follow iPhone Life

Copyright © 2026 Mango Life Media LLC. All Rights Reserved.
Mac, iPad, iPhone, Apple TV, Apple Watch, AirPods, macOS, iPadOS, iOS, watchOS, and Apple are all trademarks of Apple, Inc.
You have opted in to receive this email from iPhone Life magazine: Newsletter - Privacy & Security
To stop receiving these emails, you may:
Mango Life Media LLC | 2280 W Tyler St | Fairfield, IA 52556

Comentarios

Entradas populares de este blog

1429 hash passwords

ntlm( tursiops ) ntlm( Tursiops ) ntlm( turskaj ) ntlm( tursunbek ) ntlm( tursunova ) ntlm( tursyn ) ntlm( turt ) ntlm( turtal ) ntlm( turtel ) ntlm( turtl ) ntlm( turtl3 ) ntlm( turtl705 ) ntlm( turtlboy ) ntlm( turtle ) ntlm( Turtle ) ntlm( TURTLE ) ntlm( turtle0 ) ntlm( turtle01 ) ntlm( turtle03 ) ntlm( turtle05 ) ntlm( turtle07 ) ntlm( turtle1 ) ntlm( Turtle1 ) ntlm( turtle10 ) ntlm( turtle11 ) ntlm( turtle12 ) ntlm( turtle123 ) ntlm( turtle14 ) ntlm( turtle15 ) ntlm( turtle19 ) ntlm( turtle2 ) ntlm( Turtle2 ) ntlm( turtle20 ) ntlm( turtle22 ) ntlm( turtle23 ) ntlm( turtle27 ) ntlm( turtle29 ) ntlm( turtle3 ) ntlm( turtle3000 ) ntlm( turtle33 ) ntlm( turtle34 ) ntlm( turtle4 ) ntlm( turtle55 ) ntlm( turtle56 ) ntlm( turtle6 ) ntlm( turtle63 ) ntlm( turtle66 ) ntlm( turtle69 ) ntlm( turtle7 ) ntlm( turtle70 ) ntlm( turtle74 ) ntlm( turtle77 ) ntlm( turtle78 ) ntlm( turtle80 ) ntlm( turtle88 ) ntlm( turtle99 ) ntlm( turtledo ) ...

‘Income Dream Come True’: Savers Have Several Risk-Free Ways to Beat Inflation

Are you taking advantage? ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏...

12 things orthopedic surgeons do to maintain speed, balance, and longevity

Plus more health news  ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌...