Articles

08
Jan
'26

ClickFix attacks are increasingly devious, dangerous, and can hack you in an instant

These attacks spoof Windows errors, CAPTCHAs, and real login pages to trick victims into hacking themselves with malware that skirts common cyber defenses.
11 min read
a screenshot of a blue-screen-style windows error, which is actually a ClickFix attack. the text has been slightly blurred for effect.
20
Dec
'25

Faced threats as a security researcher or journalist? Take our survey

Are you a security researcher or journalist? Working in partnership, this week in security and DataBreaches.net want to hear from you about your experiences facing or receiving legal demands and criminal threats as part of your research or reporting. We hope to learn more about how threats affect cybersecurity research and the journalism process.

Responses can be anonymous. Please take our survey (and please share!)

1 min read
19
Dec
'25

Apple nuking a customer's account over a bad gift card is a warning for everyone

One long-time Apple customer was left with no recourse after a bad gift card triggered a full account and device lock-out.
2 min read
a photo of an Apple MacBook's computer screen closer-up, displaying the dock on its desktop, in a slightly blue tinted light
12
Dec
'25

Last-minute cybersecurity and privacy gifts your friends and family won't hate

Running out of gift ideas for the security or privacy buff in your life? Here are some thoughtful suggestions, including what tech you might want to avoid.
10 min read
Photo of a programmer's laptop with a red-backlit keyboard, with many energy drinks and holiday twinkly lights, in a darkened room.
06
Dec
'25

I've investigated 'stalkerware' for five years. Here's what I've learned

Stalkerware is a pervasive surveillance used by millions around the world, but these operations keep getting hacked and leaking victims' private phone data.
11 min read
a screenshot showing a Riverside film studio setup, with Zack Whittaker on the left and documentary journalist Daisy Maskell on the right.
26
Nov
'25

Banning TP-Link won't save America from its own terrible cybersecurity

TP-Link routers face a ban in the U.S. over the company's alleged links to China, but shoddy cybersecurity is the real insider threat to the United States.
6 min read
a photo of the back of a TP-Link wireless router
14
Nov
'25

It's far too easy to find leaked passports and driver's licenses online

Passports and driver's licenses are easy to find online, thanks to a dizzying array of websites and apps that require a copy but aren't keeping the data safe.
5 min read
It's far too easy to find leaked passports and driver's licenses online
06
Nov
'25

Thousands of North Koreans have secretly infiltrated US and European companies as remote IT workers

North Korea's secret remote workers are a major threat facing U.S. and European businesses today, taking jobs in Fortune 100 and smaller companies alike. Here's how to recognize and combat the threat.
15 min read
a photo of North Korean propaganda, featuring a man holding a book, gesturing to the North Korean flag, which reads in Korean: "Let's march forward towards a new victory!"
25
Oct
'25

AI browsers are a hot mess of security risks

AI-enabled web browsers are putting their users' data, security, and privacy at risk from rudimentary prompt injection attacks.
4 min read
a photo of OpenAI's ChatGPT Atlas browser, with a glitchy effect added to the image.
20
Oct
'25

Amazon's cloud outage takes much of the internet down with it

The internet is broken, and not just because Amazon's cloud service went down.
2 min read
a photo showing Amazon Web Services' logo on the outside of a glass building.
14
Oct
'25

Why ad blockers are a top security and privacy defense for everyone

Ad blockers can help defend against some of the top hacks, scams, and surveillance today. Here are some of the best ad blockers that you can use.
9 min read
a billboard at a train station with eyes, symbolizing an ad watching you.
04
Oct
'25

Discord says users' government IDs used for age checks stolen by hackers

Thanks to age verification laws, expect more data breaches of users' government-issued passports and driver's licenses.
3 min read
Discord says users' government IDs used for age checks stolen by hackers