PhishFort Blog

Our Research and Announcements

Stay informed with our latest blog posts.

Financial Services 5 min read

DriveWealth Breach: What Revolut Users Need to Know

A breach at DriveWealth, Revolut's US stock trading partner, exposed historical customer data. What happened, who is affected and how breach notices become phishing lures.

Read more: DriveWealth Breach: What Revolut Users Need to Know
Financial Services 6 min read

Revolut Data Leak: Fake Government Request Passed DMARC

A request sent from a real government email domain passed SPF, DKIM and DMARC and led Revolut to release passports and Bitcoin records. Here is what failed.

Read more: Revolut Data Leak: Fake Government Request Passed DMARC
News 7 min read

MECCHA CHAMELEON Malware: Workshop Map to Discord Takeover

A Steam Workshop map for MECCHA CHAMELEON dropped a RAT on players' PCs and led to a hijacked official Discord: what happened and what to check now.

Read more: MECCHA CHAMELEON Malware: Workshop Map to Discord Takeover
Gambling 6 min read

Account Takeover in Online Casinos

How online casinos detect account takeover: credential stuffing, deposit fraud signals, and the response steps that stop withdrawals before they clear.

Read more: Account Takeover in Online Casinos
Gaming 8 min read

Bonus Abuse in iGaming: Detecting Coordinated Rings

Coordinated bonus abuse rings exploit iGaming promotions through shared infrastructure and scripted behavior. Learn how fraud teams detect and stop them.

Read more: Bonus Abuse in iGaming: Detecting Coordinated Rings
Gaming 10 min read

Affiliate Fraud in iGaming: Detection and Prevention Guide

Affiliate fraud in iGaming takes three forms: domain typosquatting, brand bidding, and fake traffic. Detection signals and enforcement options for each.

Read more: Affiliate Fraud in iGaming: Detection and Prevention Guide
Blog

Latest posts

News 6 min read

153M Driver's Licenses for Sale: The IDScan.net Nexus Leak

A dark web service called Nexus offered 153 million US and Canadian driver's license scans tied to IDScan.net. What was exposed and how to limit the fraud that follows.

Read more: 153M Driver's Licenses for Sale: The IDScan.net Nexus Leak
Research 4 min read

AliExpress Is Using Silent WebAudio to Fingerprint Your Browser

A Bluetooth glitch led to an unexpected discovery: AliExpress runs silent WebAudio processing as part of a browser fingerprinting anti-fraud system. Here's what was found and what it means for security and privacy.

Read more: AliExpress Is Using Silent WebAudio to Fingerprint Your Browser
Research 3 min read

Fake Paws, Real Scams: How to Spot and Avoid Online Puppy Scams

Online puppy scams use stolen photos, fake breeders, and endless "fees" to steal your money and break your heart. Here's exactly how the trap is set and the one rule that protects you.

Read more: Fake Paws, Real Scams: How to Spot and Avoid Online Puppy Scams
Research 4 min read

UAC-0099 Weaponizes Notepad++ and WinRAR Plugins to Deliver Malware

UAC-0099 is hijacking trusted apps like Notepad++ and WinRAR through malicious plugins and DLL sideloading. Here's the full infection chain, based on CERT-UA's technical advisory.

Read more: UAC-0099 Weaponizes Notepad++ and WinRAR Plugins to Deliver Malware
Research 5 min read

From Exploit to Phishing: How Attackers Weaponized the Coldcard Entropy Incident

Days after the Coldcard entropy vulnerability went public, a phishing campaign impersonating Coinkite began tricking users into installing remote access malware disguised as a hardware audit tool.

Read more: From Exploit to Phishing: How Attackers Weaponized the Coldcard Entropy Incident