fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

10K
active users

#identitytheft

5 posts4 participants0 posts today

Gizmodo: People Making AI Studio Ghibli Images Are Now Producing Fake Legal Letters to Go With Their Fake Art. “The trend of using Open AI’s ChatGPT to create AI images in the distinctive style of Studio Ghibli probably should have ceased the moment the official White House X account hopped aboard. But there’s a new wrinkle in the story today, as one of the trend’s proponents posted a […]

https://rbfirehose.com/2025/03/29/gizmodo-people-making-ai-studio-ghibli-images-are-now-producing-fake-legal-letters-to-go-with-their-fake-art/

CBC: Fake election news ads are luring people into investment schemes. We got some taken down. “Fake CBC News articles that link to sketchy investment schemes are flooding social media with sensational headlines about the Canadian election and other recent political developments. CBC’s visual investigations unit reported on a similar scam in late January, where fake articles lured victims to […]

https://rbfirehose.com/2025/03/29/cbc-fake-election-news-ads-are-luring-people-into-investment-schemes-we-got-some-taken-down/

ResearchBuzz: Firehose | Individual posts from ResearchBuzz · CBC: Fake election news ads are luring people into investment schemes. We got some taken down | ResearchBuzz: Firehose
More from ResearchBuzz: Firehose

#Trump on Friday commuted the sentence & probation of #CarlosWatson, a co-founder of the now-defunct #digital #media company Ozy Media, on the day he was set to surrender to prison.

Watson was sentenced in Dec to almost 10yrs in #prison for #fraud, #IdentityTheft, #SecuritiesFraud, & #WireFraud.

Watson & Ozy were also ordered to pay $96M in restitution & forfeiture. As part of Trump’s commutation, they will no longer have to pay.

#law #felon47 #CFPB #SEC #corruption
cnbc.com/2025/03/28/trump-comm

CNBCTrump commutes sentence of Ozy Media founder Carlos Watson just before prison surrenderOzy had falsely claimed to have deals with Google and Oprah Winfrey before the company and CEO Watson were criminally charged.

AFP: Spain seeks to criminalize AI-generated sexual images. “The government wants ‘deepfakes of a sexual or seriously insulting nature’ to be ‘considered crimes against moral integrity,’ Justice Minister Felix Bolanos told a news conference after a weekly cabinet meeting. In a statement, the government said the measure would be part of a bill aimed at ‘protecting young girls and boys as well […]

https://rbfirehose.com/2025/03/26/afp-spain-seeks-to-criminalize-ai-generated-sexual-images/

ResearchBuzz: Firehose | Individual posts from ResearchBuzz · AFP: Spain seeks to criminalize AI-generated sexual images | ResearchBuzz: Firehose
More from ResearchBuzz: Firehose

Ars Technica: Mom horrified by Character.AI chatbots posing as son who died by suicide. “A mother suing Character.AI after her son died by suicide—allegedly manipulated by chatbots posing as adult lovers and therapists—was horrified when she recently discovered that the platform is allowing random chatbots to pose as her son.”

https://rbfirehose.com/2025/03/21/ars-technica-mom-horrified-by-character-ai-chatbots-posing-as-son-who-died-by-suicide/

Casino Data Jackpot – For Hackers: Merkur’s API Disaster

A couple of days ago, I saw a Mastodon post from Lilith Wittmann in my timeline. She linked to an article on her Medium page detailing a catastrophic security failure at Merkur AG. You can find the original Mastodon post here.

The casino company Merkur AG and its service providers have made almost all the data available in their casino systems publicly accessible. This includes payment data, gaming sessions, and copies of the ID cards of over one million players.

Lilith Wittmann’s Medium Post (German)

Oh wow. Losing data of a million customers is bad enough. To make things worse, they also integrated third-party services like Sumsub for Know Your Customer (KYC) checks. So, the leak also includes over 70,000 ID photos, selfies and proof of address from the KYC process.

A perfect setup for identity theft. What a mess!

All this was possible due to a unprotected GraphQL API endpoint.

Let’s learn from this!

For Merkur it is a massive damage. For us it is a lesson we can learn from: This breach is a good example of why securing APIs should be a top priority. Some simple steps that could have prevented this:

  • Never expose internal APIs to the public internet unless absolutely necessary. If an API must be public, it should have strict access controls, rate limits and maybe even IP-restrictions.
  • Put sensitive systems in a private subnet. Even if an API is misconfigured, at least it won’t be wide open to the world.
  • Use proper authentication, authorization, and role-based access control. A single user or role should never have unrestricted access to all sensitive data. Access should be limited to only the necessary fields for a given role.
  • Regular security audits. If you’re handling sensitive data, you better have security experts regularly pentesting your systems.

Obviously, a lot went wrong here. Let’s try to do better and avoid this kind of disaster in our own projects.

locked.de/casino-data-jackpot-
#hacking #IdentityTheft #Merkur #MerkurBreach #Privacy

mastodon.socialMastodon

This is the first I’ve heard of a “#BrushingScam,” where scammers “brush up” the reviews and trustworthiness of their online storefronts by using your personal data to order and review something on your behalf. They even send you the thing in hopes of #phishing more to commit #IdentityTheft.

proton.me/blog/brushing-scam

So now you have to treat the receipt of unordered merchandise the same as any other unsolicited commercial communication: a data #breach signal.

Proton · Received an unexplained package? It could be a brushing scam | ProtonA brushing scam means your personal data has leaked online. Learn how to protect yourself with hide-my-email aliases and dark web monitoring.