PhishFort Blog

Our Research and Announcements

Stay informed with our latest blog posts.

Research 3 min read

Fake Paws, Real Scams: How to Spot and Avoid Online Puppy Scams

Online puppy scams use stolen photos, fake breeders, and endless "fees" to steal your money and break your heart. Here's exactly how the trap is set and the one rule that protects you.

Read more: Fake Paws, Real Scams: How to Spot and Avoid Online Puppy Scams
Research 4 min read

UAC-0099 Weaponizes Notepad++ and WinRAR Plugins to Deliver Malware

UAC-0099 is hijacking trusted apps like Notepad++ and WinRAR through malicious plugins and DLL sideloading. Here's the full infection chain, based on CERT-UA's technical advisory.

Read more: UAC-0099 Weaponizes Notepad++ and WinRAR Plugins to Deliver Malware
Crypto 4 min read

How Impersonation Fuels Gift Card and Crypto Scams

Gift card and crypto scams work because attackers borrow someone else's identity: a celebrity, an investment manager, even a loved one's voice. Here's how the impersonation angle actually plays out.

Read more: How Impersonation Fuels Gift Card and Crypto Scams
Research 2 min read

How a Real ChatGPT Link Delivers Phishing via a Fake Codex Install

A malicious Google Ad leads to a real chatgpt.com link, where a fake "Codex" install command hides a base64 payload that drops the MacSync infostealer. Here's the full chain.

Read more: How a Real ChatGPT Link Delivers Phishing via a Fake Codex Install
Research 3 min read

Fake Data Breach Claims: Why Scam-Style Extortion Is Surging in 2026

Scam-style extortion is rising: attackers post fake data breach claims on leak sites with no real intrusion. Here's how the bluff works and how to verify before you panic.

Read more: Fake Data Breach Claims: Why Scam-Style Extortion Is Surging in 2026
Blog

Latest posts

Research 3 min read

Click to Pray Exposes 700k Users: Inside a Textbook IDOR Failure

The Vatican's Click to Pray app leaked the personal data of 700,000 users for over six months through a basic IDOR flaw. Here's how sequential user IDs and zero auth checks did the damage.

Read more: Click to Pray Exposes 700k Users: Inside a Textbook IDOR Failure
Research 6 min read

A Hard Lesson in Randomness: Understanding the Coldcard Entropy Incident

A firmware bug silently weakened seed generation on Coldcard hardware wallets, letting an attacker recreate and drain vulnerable wallets at scale. Here's how the entropy failure worked.

Read more: A Hard Lesson in Randomness: Understanding the Coldcard Entropy Incident
Gambling 3 min read

Multi-Accounting Detection: Stopping Gnoming and Chip-Dumping

How multi-accounting detection works in iGaming and Gambling, why it matters beyond the financial hit, and how gnoming and chip-dumping schemes actually get caught.

Read more: Multi-Accounting Detection: Stopping Gnoming and Chip-Dumping
Gaming 3 min read

Gaming Fraud Prevention: How It Differs From iGaming Across Platforms

Gaming fraud prevention goes beyond iGaming: in-game currency abuse, account trading, and esports match-fixing all need a different detection approach. Here's how they compare.

Read more: Gaming Fraud Prevention: How It Differs From iGaming Across Platforms
Gaming 5 min read

The Complete Guide to iGaming Fraud Prevention Solutions for 2026

Everything you need to know about iGaming fraud prevention solutions: what iGaming fraud looks like, what makes a solution effective, and how operators implement one without disrupting play.

Read more: The Complete Guide to iGaming Fraud Prevention Solutions for 2026