PhishFort Blog

Our Research and Announcements

Stay informed with our latest blog posts.

Gambling 6 min read

Account Takeover in Online Casinos

How online casinos detect account takeover: credential stuffing, deposit fraud signals, and the response steps that stop withdrawals before they clear.

Read more: Account Takeover in Online Casinos
Gaming 8 min read

Bonus Abuse in iGaming: Detecting Coordinated Rings

Coordinated bonus abuse rings exploit iGaming promotions through shared infrastructure and scripted behavior. Learn how fraud teams detect and stop them.

Read more: Bonus Abuse in iGaming: Detecting Coordinated Rings
Gaming 10 min read

Affiliate Fraud in iGaming: Detection and Prevention Guide

Affiliate fraud in iGaming takes three forms: domain typosquatting, brand bidding, and fake traffic. Detection signals and enforcement options for each.

Read more: Affiliate Fraud in iGaming: Detection and Prevention Guide
Research 4 min read

AliExpress Is Using Silent WebAudio to Fingerprint Your Browser

A Bluetooth glitch led to an unexpected discovery: AliExpress runs silent WebAudio processing as part of a browser fingerprinting anti-fraud system. Here's what was found and what it means for security and privacy.

Read more: AliExpress Is Using Silent WebAudio to Fingerprint Your Browser
Research 3 min read

Fake Paws, Real Scams: How to Spot and Avoid Online Puppy Scams

Online puppy scams use stolen photos, fake breeders, and endless "fees" to steal your money and break your heart. Here's exactly how the trap is set and the one rule that protects you.

Read more: Fake Paws, Real Scams: How to Spot and Avoid Online Puppy Scams
Blog

Latest posts

Research 4 min read

UAC-0099 Weaponizes Notepad++ and WinRAR Plugins to Deliver Malware

UAC-0099 is hijacking trusted apps like Notepad++ and WinRAR through malicious plugins and DLL sideloading. Here's the full infection chain, based on CERT-UA's technical advisory.

Read more: UAC-0099 Weaponizes Notepad++ and WinRAR Plugins to Deliver Malware
Research 5 min read

From Exploit to Phishing: How Attackers Weaponized the Coldcard Entropy Incident

Days after the Coldcard entropy vulnerability went public, a phishing campaign impersonating Coinkite began tricking users into installing remote access malware disguised as a hardware audit tool.

Read more: From Exploit to Phishing: How Attackers Weaponized the Coldcard Entropy Incident
Crypto 4 min read

How Impersonation Fuels Gift Card and Crypto Scams

Gift card and crypto scams work because attackers borrow someone else's identity: a celebrity, an investment manager, even a loved one's voice. Here's how the impersonation angle actually plays out.

Read more: How Impersonation Fuels Gift Card and Crypto Scams
Research 2 min read

How a Real ChatGPT Link Delivers Phishing via a Fake Codex Install

A malicious Google Ad leads to a real chatgpt.com link, where a fake "Codex" install command hides a base64 payload that drops the MacSync infostealer. Here's the full chain.

Read more: How a Real ChatGPT Link Delivers Phishing via a Fake Codex Install
Research 3 min read

Fake Data Breach Claims: Why Scam-Style Extortion Is Surging in 2026

Scam-style extortion is rising: attackers post fake data breach claims on leak sites with no real intrusion. Here's how the bluff works and how to verify before you panic.

Read more: Fake Data Breach Claims: Why Scam-Style Extortion Is Surging in 2026
Research 3 min read

Click to Pray Exposes 700k Users: Inside a Textbook IDOR Failure

The Vatican's Click to Pray app leaked the personal data of 700,000 users for over six months through a basic IDOR flaw. Here's how sequential user IDs and zero auth checks did the damage.

Read more: Click to Pray Exposes 700k Users: Inside a Textbook IDOR Failure