Rapid alerts

Current safety alerts

Short, plain-language warnings about current scam patterns and impersonation attempts. Check the date and status on each alert before sharing it.

New: WatchOut These alerts as a shareable feed with free email alerts, at watchout.report
investigating
A web page copying Booking.com's checkout. A card graphic reads cardholder verification in progress, and a chat window styled as Booking customer support sits over the page.

A fake Booking hotel page asks you to confirm a reservation and verify your card

A page copying Booking's checkout asks you to verify your card to confirm a hotel reservation. A chat posing as Booking support says your bank may send a confirmation code. That code can approve a payment. Do not enter card details, and never pass a code on.

Read alert →
investigating
A Samsung-branded cashback page asks for a CPF number before showing a gift-card offer

Fake Samsung Brazil pages ask for a PIX fee to release an order or a gift card

A site using Samsung's name asks for your CPF, then shows an order or a cashback balance waiting for you. To release it you must pay a small fee by PIX: R$ 97,00 for a delivery, R$ 7,36 for a gift card. Nothing arrives. Check any order in the shop's own app instead.

Read alert →
confirmed
A fake Find My screen with six empty code boxes above the words: Enter your Security Code to view current location on Map.

A fake "we found your iPhone" page asks for the code that unlocks your phone

CSRF reviewed a page on a look-alike domain that imitates Apple's Find My. It shows an animated map and a device named "iPhone 14 Pro" marked Online, then asks for a six-digit "Security Code to view current location on Map" before it asks for any account details. The device and location are fixed in the page and identical for every visitor. The first code entered is always reported as incorrect after it has already been sent, which prompts a second entry. The page then asks for an Apple Account email address and password and redirects to the genuine icloud[.]com. The domain was registered one day before the page was submitted to CSRF.

Read alert →
confirmed
Screenshot of a Trump-branded cryptocurrency giveaway page promising to return twice the amount sent

Trump-branded crypto giveaway website promises to double deposits

A website using Trump imagery and the name trumpamerica[.]io claims that people can send cryptocurrency and receive twice as much back. Its instructions tell visitors to send coins to a special address and say the doubled amount will be returned immediately. That is a classic cryptocurrency giveaway warning sign: sending funds does not create a right to receive anything back.

Read alert →
investigating
A dark crypto flasher sales page advertises fake blockchain transactions, fake explorer pages, and temporary wallet balances

A crypto flasher site advertises fake transaction proof

A website at cryptoflasher[.]net advertises a paid tool that claims to create temporary crypto credits, pending transfers, fake wallet balances, and fake blockchain-explorer pages showing a transaction as confirmed. A person could use that false proof to persuade someone to release goods, money, or services before a real payment exists. Verify every crypto payment independently on the correct blockchain before accepting it.

Read alert →
investigating
A fake Discord page showing a Cloudflare-style verification box and instructions to press Win plus R and paste a command

Fake Discord verification pages tell you to paste a PowerShell command

A page at discord-eu[.]cfd uses Discord branding and a Cloudflare-style human check. Its pop-up tells visitors to press Win + R, paste text with Ctrl + V, and press Enter. That is not a normal verification step: it can run a hidden PowerShell command on a Windows computer. Close the page and do not paste or run anything.

Read alert →
investigating
TuntunSahur download page showing a completed 15.8 MB software download

TuntunSahur malware uses nested password-protected ZIPs to deliver an installer

A page at tuntunsahur[.]sbs offers a TuntunSahur malware download. The first ZIP contains an encrypted ZIP, and another file provides its password. The inner archive contains an installer reported to be malicious. Do not download, extract, or run the files. The theme may make this especially appealing to children and young gamers.

Read alert →
investigating

A cloud-storage address does not make a payment or sign-in page safe

A link may show the name of a familiar cloud-storage company such as Amazon, Cloudflare, or Backblaze while displaying a fake delivery, refund, prize, or account page. The storage company may only be hosting the file; it does not mean the offer belongs to the company shown on the page. Do not enter passwords, card details, identity numbers, or verification codes. Open the real organization's app or website yourself instead.

Read alert →
investigating
Screenshot of a Buffalo Couriers-branded delivery page asking for an R18.99 payment and full identity and card details.

Fake Buffalo Couriers pages ask for your ID and card details to pay a delivery fee

A Buffalo Couriers-branded page shows a fake shipment summary and says an R18.99 shipping fee must be confirmed within 48 hours. A confirmation button leads to a second page that requests an ID or passport number, cellphone number, card number, expiry date, and CVV. The pages are hosted on an unrelated address, and the second page's code sends submitted information to an unknown Telegram recipient. Do not enter details or pay through the pages; check deliveries through the courier's official website or app opened independently.

Read alert →
investigating
Extracted e-challan app logo from the reported Android APK.

Fake e-challan texts may use legal threats to install an Android app

A text claims that an e-challan has been issued and threatens legal action unless a penalty is paid immediately. The message uses a shortened link instead of an official traffic or government address. The submitted report says the link downloads an Android APK described as a Trojan; the file was not available for independent analysis. Do not open the link or install the app. Check fines through the official government or traffic service opened independently.

Read alert →
investigating

Unexpected high-salary job emails may impersonate a real recruiter

An email claims to represent an executive search partner and offers a remote operations and executive-support role with a $200,000 compensation package. This example uses a free Gmail address while pointing to a profile associated with a large staffing firm, then asks for an updated résumé. Similar messages may use a lookalike or other unofficial domain that resembles the real firm's address. A familiar company name or real person's profile does not prove that the sender is genuine. Verify the opportunity through the firm's official website and contact details before sharing your résumé or personal information.

Read alert →
investigating
Cropped screenshot of a SteamUnlocked-branded site advertising free pre-installed PC games and a separate launcher.

Free game-download sites can expose children to unsafe launchers and files

A site branded SteamUnlocked presents free pre-installed PC games and promotes a separate launcher outside Steam's official store. A polished catalogue, game covers, and an 'official' claim can make the downloads feel safe, but the site and its files are not verified by Steam or the game publishers. Do not download or run unknown launchers or game files. Children should ask a parent or trusted adult before downloading games from an unfamiliar site.

Read alert →
investigating
Cropped screenshot of a Tim Hortons-branded prize page asking visitors to share with Messenger or WhatsApp groups before continuing.

Fake Tim Hortons prize page asks you to share before you can continue

A page using Tim Hortons branding says the visitor has won a $200 gift card and asks them to share it with multiple groups or friends through Messenger or WhatsApp before continuing. Links shown for people who receive the shared page use unrelated domains, including assaitssapp[.]com and assaibonus[.]com. Do not share the page or enter information on it; verify promotions through the official Tim Hortons app or website opened independently.

Read alert →
investigating
A dark game-download page using itch.io-like branding and offering a password-protected update archive

Kids, students, and gamers: fake itch[.]io game updates can install malware

A GitHub Pages site at jessellis95[.]github[.]io/update/ copies itch[.]io and offers a password-protected ZIP as a game update for Windows and macOS. The archive contains malware, not a game. Its macOS instructions tell you to paste a remote command into Terminal and enter your computer password; the Windows download contains an obfuscated executable package. Do not download, extract, run, or follow instructions from this page.

Read alert →
investigating
A long screenshot of a vacation-rental page and booking form using Vrbo-like branding on an unfamiliar domain

Fake Vrbo booking site looks identical to the real thing

reservation[.]holiday-vrbo[.]com copies Vrbo branding and presents a fake-looking vacation-rental booking flow. It offers a property listing, a “Book now” button, contact fields, a message-to-host form, and a large deposit. The domain is not Vrbo. Do not enter information or pay through this site.

Read alert →
investigating
A fake Zoom page says the latest Zoom Workplace app is required and tells visitors to download it before joining a meeting

Fake Zoom meeting page downloads malware

A page at quickmeetinglink[.]es copies Zoom branding and claims that the latest Zoom Workplace app is required to join a meeting. It directs visitors to download a file before continuing. The downloaded file was flagged as malware. Close the page, delete the file, and open Zoom through its official app or website instead.

Read alert →
investigating
Three printer-support page examples using Canon, Brother, and HP branding show similar driver-download prompts; the Canon example also shows a menu listing remote-access tools.

Printer support pages can push remote-access tools

A printer-support site using Canon branding shows a printer error, asks visitors to download a driver, and offers several remote-access tools under a support menu. Related subdomains reported under myprinter[.]live use Brother and Canon branding; the same pattern may also impersonate HP. The pages may be trying to persuade visitors to give an unfamiliar person access to their computer.

Read alert →
investigating
WatchOut graphic highlighting the unusual vwww- prefix and [.]co ending in the defanged address vwww-roblox[.]co.

Lookalike game sites can steal player information

A website using the address vwww-roblox[.]co uses Roblox's name with an unusual vwww- prefix and a different domain ending. Lookalike game sites can be used to trick players into entering passwords, verification codes, or payment details. Do not sign in through a link sent in a chat, video, ad, or game message.

Read alert →
confirmed
A fake Microsoft Store page displays Zoom Workplace with an Install button and Microsoft branding.

A Zoom-branded meeting page can deliver a ScreenConnect installer through a fake Microsoft Store

The observed page uses Zoom Workplace branding inside an S3-hosted imitation of a Microsoft Store listing. Its install flow presents a plug-in or update pretext and initiates a download of ScreenConnect[.]ClientSetup[.]msi from pivotalequipmentllc2[.]screenconnect[.]com. The infrastructure and delivery sequence are inconsistent with a normal Zoom meeting workflow.

Read alert →
investigating
Signal chat showing a message claiming an account is at risk and asking for a recovery key, with Block, Report, and Accept buttons visible.

Fake Signal support messages can ask for recovery keys

A message pretending to be Signal support claims that an account is at risk and asks the recipient to click Accept and provide a recovery key. This is a scam warning: never share a recovery key, registration code, verification code, password, or other account secret in response to an unexpected message.

Read alert →
investigating

A phishing campaign impersonating the Canadian government shows signs of preparing German government lures

A CSRF investigation mapped a phishing email impersonating the Government of Canada and Service Canada. The Canadian redirect chain is now offline, but the same GitHub account uploaded a logo belonging to Germany's Federal Motor Transport Authority (KBA) on 2026-08-07. This suggests preparation for a possible German pivot; no live German phishing page has been confirmed. CSRF reported the GitHub account to GitHub.

Read alert →
investigating

A suspected Nike recruitment impersonation site uses a Facebook-style login

A reported recruitment-themed website at nikerecruits[.]com appears to use Nike branding and presents a Facebook-style sign-in page. The combination may be intended to trick visitors into entering account credentials. This is an initial warning based on the reported page appearance and requires review before publication.

Read alert →
investigating

A suspected Zillow impersonation site may lead to a task scam

A reported website uses Zillow branding while presenting an agent or in-house tester program. Its FAQ describes daily order sets, negative balances on premium tasks, and topping up an account before work can continue. A separate domain is reported as the support destination. These are strong warning signs associated with task scams and impersonation, but this alert does not establish who operates the sites or whether Zillow was involved.

Read alert →