Risk archive
High risk Scam alerts
Track the most urgent incidents first, including actively exploited flaws, large-scale breach fallout, high-confidence phishing waves and severe ransomware activity.
This view narrows the archive to high risk scam alerts, helping readers and search engines separate urgent coverage from broader reporting while surfacing the clearest next-step guidance first.
Scam alerts by risk level
This filtered view helps users compare only the most relevant high risk incidents in the scam alerts stream, which is useful for both urgent research and cleaner search intent matching.
Filter the alert archive
Narrow the archive by category and risk level to review phishing alerts, data breach alerts, malware coverage, vulnerability updates and ransomware incidents faster.
Full alert archive
Showing 12 of 220 matching alerts.
Each alert card surfaces the threat type, documented summary and best next step so the listing itself can answer intent around latest cybersecurity alerts, phishing alerts, breach alerts and incident response without forcing every visitor to click through immediately.
Older alerts from 2021-2025 are still available, but stronger, documented and more recent reporting is ranked first so the archive stays aligned with current Google quality expectations.
Hackers Exploit Microsoft Teams by Impersonating IT Helpdesk Staff to Breach Organizations
Human review: Artur Ślesik | Source date: Apr 24, 2026 | Sources: 3A sophisticated cyber threat group known as UNC6692 has been leveraging Microsoft Teams to infiltrate corporate networks by impersonating IT helpdesk personnel. Using... Verified across 3 sources. Focus: lure pattern, spoofing signals and account-protection next steps.
Best next step: Identity Theft Recovery Planner
Booking.com Data Breach Exposes Customer Reservation Details – 20th April 2026 Threat Intelligence Report
Human review: Artur Ślesik | Source date: Apr 20, 2026 | Sources: 1On April 20, 2026, Check Point Research disclosed a significant data breach affecting Booking.com customers, where unauthorized actors accessed sensitive reservation d... Documented alert summary. Focus: lure pattern, spoofing signals and account-protection next steps.
Best next step: Identity Theft Recovery Planner
Identity Remains Prime Target as Endpoint and Cloud Threats Expand
Human review: Artur Ślesik | Source date: May 04, 2026 | Sources: 1Identity-based attacks continue to dominate cybersecurity incidents, with phishing campaigns leveraging Microsoft Teams and AI-driven lures on the rise, according to r... Documented alert summary. Focus: lure pattern, spoofing signals and account-protection next steps.
Best next step: Identity Theft Recovery Planner
GlassWorm Malware Resurfaces via 73 Malicious OpenVSX Sleeper Extensions in 2026
Human review: Artur Ślesik | Source date: Apr 27, 2026 | Sources: 3In 2026, the GlassWorm malware campaign has made a significant comeback by exploiting 73 dormant 'sleeper' extensions on the OpenVSX marketplace. These extensions init... Verified across 3 sources. Focus: lure pattern, spoofing signals and account-protection next steps.
Best next step: Identity Theft Recovery Planner
Tangerine Turkey Campaign: VBS Worm Exploits Systems for Cryptomining
Human review: Marcin Pocztowski | Source date: Nov 03, 2025 | Sources: 2The Tangerine Turkey campaign uses a Visual Basic Script worm to hijack system resources for cryptomining, causing performance issues and financial losses. Cybereason’... Verified across 2 sources. Focus: lure pattern, spoofing signals and account-protection next steps.
Best next step: Crypto Scam Checker for Fake Investments and Recovery Fraud
‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty to Major Phishing and Cryptocurrency Theft Scheme
Human review: Artur Ślesik | Source date: Apr 21, 2026 | Sources: 1Tyler Robert Buchanan, a senior member of the notorious cybercrime group Scattered Spider, has pleaded guilty to wire fraud conspiracy and aggravated identity theft. H... Documented alert summary. Focus: fraud signals, pressure tactics and what to do before paying or replying.
Best next step: Crypto Scam Checker for Fake Investments and Recovery Fraud
Supply Chain Attack Targets SAP npm Packages to Steal Credentials
Human review: Artur Ślesik | Source date: May 01, 2026 | Sources: 3Four SAP npm packages have been compromised with credential-stealing malware in a supply chain attack linked to the mini Shai-Hulud campaign. Developers using these pa... Verified across 3 sources. Focus: infection path, likely payload impact and containment priorities.
Best next step: Crypto Scam Checker for Fake Investments and Recovery Fraud
Database Breaches in South Africa: A Persistent Cybersecurity Threat in 2026
Human review: Artur Ślesik | Source date: Apr 23, 2026 | Sources: 1South Africa continues to face high-risk data breaches primarily targeting database layers, as highlighted by Johan Lamberts, MD of Ascent Technology. This HackWatch a... Documented alert summary. Focus: exposed data, who may be affected and breach-response priorities.
Best next step: Identity Theft Recovery Planner
Cybercriminals Harness AI to Accelerate Zero-Day Vulnerability Exploitation
Human review: Marcin Pocztowski | Source date: May 04, 2026 | Sources: 1Security researchers report a significant shift as threat actors deploy artificial intelligence to identify and exploit zero-day flaws within minutes, drastically shor... Documented alert summary. Focus: affected products, exploit urgency and remediation guidance.
Best next step: Identity Theft Recovery Planner
Scattered Spider Co-Conspirator Pleads Guilty Amid Ongoing Cybercrime Threats
Human review: Artur Ślesik | Source date: Apr 24, 2026 | Sources: 1Tyler Buchanan, a member of the notorious Scattered Spider cybercrime group, has pleaded guilty to conspiring to steal over $8 million in virtual currency through soph... Documented alert summary. Focus: lure pattern, spoofing signals and account-protection next steps.
Best next step: Crypto Scam Checker for Fake Investments and Recovery Fraud
Trio of New Windows Vulnerabilities—BlueHammer, UnDefend, and RedSun—Under Active Exploitation
Human review: Marcin Pocztowski | Source date: Apr 21, 2026 | Sources: 1A cluster of three critical Windows Defender vulnerabilities—BlueHammer, UnDefend, and RedSun—are actively exploited following the leak of proof-of-concept exploits by... Documented alert summary. Focus: infection path, likely payload impact and containment priorities.
Best next step: Identity Theft Recovery Planner
Check Point Research Uncovers the 2026 Phishing Paradox: Microsoft Tops Brand Impersonation Charts
Human review: Artur Ślesik | Source date: Apr 20, 2026 | Sources: 1Check Point Research's Q1 2026 Brand Phishing Ranking reveals Microsoft as the most impersonated brand in phishing attacks, accounting for 22% of all attempts. This re... Documented alert summary. Focus: lure pattern, spoofing signals and account-protection next steps.
Best next step: Identity Theft Recovery Planner
Alerts archive SEO topics
Archive maintenance and remediation tracking. HackWatch does not treat alerts as one-time posts. We continue checking whether vendors have issued patches, workarounds or final remediation updates, then refresh the article with the latest incident status so readers can see whether a threat is still active, mitigated or already resolved.