Technology
6 sneaky scams that could ruin your holiday season
The holiday season is a time filled with joy, festivities and cherished moments with family and friends. However, amidst the hustle and bustle of shopping, cooking and celebrating, it’s easy to overlook a lurking danger: scams. Scammers thrive during this busy time, preying on our excitement and stress to trick us into revealing personal information or losing money. We’re going to discuss six sneaky scams that could ruin your holiday spirit and provide you with essential tips on how to protect yourself from these deceptive tactics.
GET SECURITY ALERTS, EXPERT TIPS – SIGN UP FOR KURT’S NEWSLETTER – THE CYBERGUY REPORT HERE
Scam alert illustration (Kurt “CyberGuy” Knutsson)
1) Package delivery scam
With the holiday season in full swing, the end-of-year sales have begun, and you probably have already started your holiday shopping and are expecting packages coming via different types of delivery services like FedEx, UPS or USPS. So, if you receive a text that mentions a package delivery, you may be likely to easily fall for a scam. I was expecting a package recently and received this text out of the blue (see image).
Fake package delivery scam text (Kurt “CyberGuy” Knutsson)
BEST ANTIVIRUS FOR MAC, PC, IPHONES AND ANDROIDS – CYBERGUY PICKS
Even though the text says the sender is not in my contact list and that it may be junk, I almost clicked the link because I was so focused on the fact that there may have been a typo in my delivery address. But once I looked a little closer, there were a few red flags in this text message that tipped me off to it being a scam.
- First, the link does not lead you to usps.com. It’s a fake link that scammers hope you won’t notice. Notice it is uspsts.top and not usps.com. This is a common scam going around called typosquatting wherein a scammer uses a domain that looks close to a real website. Next, the text says “pls,” which is lingo for “please” that you likely wouldn’t see in correspondence from the USPS. Scammers often make typos or use poor grammar when communicating, so always double-check.
- Scammers are sending emails, texts and even occasionally there could be a phone call that is regarding an issue with package delivery. It may be something like this text I received that has a link where they’ll end up asking for information, or you may be asked to pay a “shipping fee” to get your package.
- Be sure to always have strong antivirus software running on your devices to prevent any disasters from happening if you were to click on a malicious link. See my expert review of the best antivirus protection for your Windows, Mac, Android and iOS devices.
How to avoid package delivery scams
If you are expecting a package, and you’re wondering if you’ve received real information or not about it, the best way to check is to go to the original confirmation you received about shipping. You most likely received an email regarding your package, and if you go to that email to get your order number, you should be able to look up the status of your order directly on any website.
A woman shopping on her laptop (Kurt “CyberGuy” Knutsson)
8 PHISHING EMAIL SCAMS TO WATCH OUT FOR THIS HOLIDAY SEASON
2) Charity scams
Sadly, charity scams aren’t new, but they are way more prevalent during the holiday season since scammers are hoping you’re feeling more generous during this time of year. Sometimes, scammers may create fake names of organizations to get you to donate money, or they may reach out to you via phone/email/text posing as someone working for a legitimate charity. Social media has also become a popular place for charities to market themselves and reach more eyes in hopes of donations, so scammers may try to pose as fake charities. These schemes will try to appeal to your emotions during this season, so be sure to check where you donate your money so you don’t fall for a scam.
How to avoid charity scams
Never give your money to anyone immediately who approaches you or reaches out on behalf of any organization without doing your own independent research. Either do a little googling or check with a family member to see if it’s real, and if it is, you should be able to donate to an official website or an official address. You can always mention this to anyone who asks you to donate somewhere. Don’t fall into the pressure of donating right then and there. Also, always double-check the name of an organization. Sometimes (especially online), scammers will alter the name of a known organization slightly to trick you into donating.
9 WAYS SCAMMERS CAN USE YOUR PHONE NUMBER TO TRY TO TRICK YOU
3) Social media gift exchange scam
The Better Business Bureau is warning about a gift exchange scam with a new twist, which has been occurring during recent holiday seasons. It’s an online version of the popular “Secret Santa” gift exchange. However, the BBB says these social media-driven gift exchanges are actually pyramid schemes, and you will most likely be disappointed if you participate.
In the past few years, variations of the gift exchange have popped up, with someone asking you to select a random person and send them a gift to pay it forward. Another asks you to exchange bottles of wine with someone else, and while it seems fun and light-hearted, you don’t know who is on the receiving end.
How to avoid social media gift exchange scams
It may sound nice to send a holiday gift to a stranger in turn for receiving multiple gifts yourself, but you’re never going to receive many (if any) gifts at all. Don’t participate in gift exchanges with anyone you don’t know, or you won’t be able to guarantee you’ll actually be gifting someone who isn’t a scammer.
HOW TO REMOVE YOUR PRIVATE DATA FROM THE INTERNET
4) Gift card scams
Gift card scams are another popular method that has been rising in popularity recently, but it’s especially important to watch out for the possibilities, since you may be purchasing gift cards for friends or family for the holidays. Scammers often steal gift cards and use the information before they make it look like they didn’t. They have a number of methods for tricking you using gift cards, so if you can send an online one (so that you can ensure you’ve purchased it on a legitimate, official website), that would be a much safer alternative.
How to avoid gift card scams
If you’re getting anyone a gift card and buying it in person, be sure to check that the package hasn’t been tampered with. Double-check that nothing on the packaging looks suspicious since scammers will try to make it seem like the package was sealed, but they will already have used the gift card, so you’re essentially buying a useless piece of plastic.
Illustration of a gift card (Kurt “CyberGuy” Knutsson)
THE BEST WAY TO BUY GIFT CARDS EVER
5) Home Depot email confirmation scam
Scammers are capitalizing on the festive spirit with a deceptive email campaign targeting people at this time of year. This scam involves a deceptive email that appears to be from Home Depot with such wording as “Confirmation needed: please confirm receipt.” The email body typically contains enticing text like “Congratulations! The Home Depot – You are our winner!” along with a customer number and a blue circle that says, “Check if you won.” Who couldn’t use a little extra cheer or perhaps a holiday prize from Home Depot this season?
The problem is this is a scam, and the goal of this scam is to lure you into clicking on an embedded link, which can lead to various malicious outcomes. These include phishing for personal and financial information, installing malware on your device, redirecting to a fake website that resembles Home Depot’s or prompting you to pay a “delivery fee” for a non-existent prize.
How to avoid Home Depot email scams
To protect yourself from this and similar scams, scrutinize the sender’s email address for any discrepancies. Hover over links without clicking to reveal their true destination. Be wary of unexpected “winnings” or requests for confirmation. If you receive an email that raises suspicion, contact Home Depot directly through their official website or customer service number to verify its legitimacy. Finally, remember that legitimate companies will not ask you to confirm sensitive information via email or require you to click on links to claim prizes.
Fake Home Depot winning email (Kurt “CyberGuy” Knutsson)
6) Fake online shopping sites scam
One of the most common scams during the holiday season is the fake online shopping site scam. Scammers create websites that look like legitimate online stores but are actually designed to steal your personal and financial information. They may offer products at very low prices or claim to have limited-time deals or exclusive items. They may also send you phishing emails or text messages with links to these fake sites.
A woman shopping on her laptop (Kurt “CyberGuy” Knutsson)
Some signs of a fake online shopping site are:
- The website address does not match the name of the store or brand.
- The website has poor design and/or spelling and grammar errors.
- The website does not have a secure connection (https) or a padlock icon in the address bar.
- The website asks for too much personal information, such as your Social Security number or bank account details.
- The website does not have a clear return policy, contact information or customer reviews.
How to avoid falling victim to this scam
By following a few simple precautions, you can significantly reduce your risk of falling prey to online scams and ensure a safer shopping experience.
1) Shop only from trusted and reputable online stores that you know and have used before.
2) Check the website address carefully and look for any red flags.
3) Do some research on the online store before making a purchase. Read customer reviews, look for ratings or search for complaints online.
4) Use a credit card or a secure payment service like PayPal when shopping online. Do not use debit cards, wire transfers or gift cards.
5) Keep track of your online purchases and monitor your bank statements for any unauthorized charges.
6) Use strong antivirus protection software. An effective antivirus software is a must-have. The best way to protect yourself from clicking on any malicious links on fake websites or in phishing emails and text messages is to have antivirus protection installed and actively running on all your devices. It’s the best to help stop and alert you of any malware in your system and ultimately protect you from being hacked. See my expert review of the best antivirus protection for your Windows, Mac, Android and iOS devices.
7) Use a personal data removal service. Scammers can obtain your information from various online sources, including data brokers, people search sites and public records. Using a data removal service can help reduce your digital footprint, making it harder for scammers to access your personal information. This proactive step can be crucial in preventing identity theft and minimizing the chances of falling victim to scams during the busy holiday season.
While no service promises to remove all your data from the internet, having a removal service is great if you want to constantly monitor and automate the process of removing your information from hundreds of sites continuously over a longer period of time. Check out my top picks for data removal services here.
Below are some next steps if you find you or your loved one is a victim of identity theft. 1) If you can regain control of your accounts, change your passwords and inform the account provider
2) Look through bank statements and checking account transactions to see where outlier activity started
3) Use an identity theft protection service: Identity theft companies can monitor personal information like your Social Security number, phone number and email address and alert you if it is being sold on the dark web or being used to open an account. They can also assist you in freezing your bank and credit card accounts to prevent further unauthorized use by criminals.
One of the best parts of using some services is that they might include identity theft insurance of up to $1 million to cover losses and legal fees and a white-glove fraud resolution team where a U.S.-based case manager helps you recover any losses. See my tips and best picks on how to protect yourself from identity theft.
4) Report any breaches to official government agencies like the Federal Communications Commission. 5) Get the professional advice of a lawyer
6) Alert all three major credit bureaus and possibly place a fraud alert on your credit report.
7) Run your own background check or request a copy of one if that is how you discovered your information has been used by a criminal.
If you are a victim of identity theft, the most important thing to do is to take immediate action to mitigate the damage and prevent further harm.
SUBSCRIBE TO KURT’S YOUTUBE CHANNEL FOR QUICK VIDEO TIPS ON HOW TO WORK ALL OF YOUR TECH DEVICES
As we dive into the holiday season, let’s keep our guard up against those sneaky scams that could spoil our celebrations. Remember to stay vigilant while shopping online or responding to unexpected messages. A little caution can go a long way in ensuring that your holidays remain joyful and stress-free. So, enjoy the festivities, cherish the moments with loved ones, and keep these tips in mind to outsmart the scammers. What are some of your personal experiences with holiday scams, and how did you protect yourself from them? Let us know by writing us at Cyberguy.com/Contact.
For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter.
Ask Kurt a question or let us know what stories you’d like us to cover.
Follow Kurt on his social channels:
Answers to the most asked CyberGuy questions: New from Kurt:
Copyright 2024 CyberGuy.com. All rights reserved.
I’ve been scammed! What to do next?
Kurt’s key takeaways
Technology
Musk says he’s going to open-source the new X algorithm next week
In 2023, what was then still called Twitter, open-sourced at least portions of the code that decided what it served up in your feed. But that GitHub repository is hopelessly out of date, with the vast majority of the files appearing to be from the initial upload three years ago. Elon Musk says that in seven days, he will open-source X’s new algorithm and finally give people a peek behind the curtain and possibly a technical explanation as to why your feed is 90 percent rage bait.
Elon has always made promises to open-source parts of X, and has followed through to at least some degree, including Grok-1 in 2024. But xAI is now on Grok-3, and the Grok GitHub repository hasn’t been updated in two years. The timing of the announcement open-sourcing the X algorithm is also likely to be met with some suspicion, as Musk is fending off criticism from across the globe and the political spectrum regarding Grok’s willingness to make deepfake nudes.
Musk says this release of the X algorithm will include “all code used to determine what organic and advertising posts are recommended to users.” He also says this will be just the first, with updates coming every four weeks, and that those will include developer notes highlighting any changes. Of course, considering how things played out in 2023, you’ll have to forgive us for taking that promise with a grain of salt.
Technology
Covenant Health data breach affects nearly 500,000 patients
NEWYou can now listen to Fox News articles!
When a healthcare data breach is first disclosed, the number of people affected is often far lower than the final tally. That figure frequently climbs as investigations continue.
That’s exactly what happened with Andover, Massachusetts-based Covenant Health. The Catholic healthcare provider has confirmed a cyberattack discovered last May may have affected nearly 500,000 patients, a sharp increase from the fewer than 8,000 people it initially reported earlier this year.
A ransomware group later claimed responsibility for the incident, though Covenant Health has not publicly confirmed the use of ransomware. The attackers accessed names, addresses, Social Security numbers and health information, among other sensitive data that could put patients at serious risk.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.
UNIVERSITY OF PHOENIX DATA BREACH HITS 3.5M PEOPLE
Covenant Health detected suspicious activity in late May 2025, but investigators later confirmed attackers had already accessed systems days earlier. (Kurt “CyberGuy” Knutsson)
What happened in the Covenant Health breach
Covenant Health says it detected unusual activity in its IT environment May 26, 2025. A later investigation revealed that an attacker had actually gained access eight days earlier, on May 18, and was able to access patient data during that window.
In July, Covenant Health told regulators that the breach affected 7,864 individuals. After completing what it describes as extensive data analysis, the organization now says that up to 478,188 individuals may have been affected.
Covenant Health operates hospitals, nursing and rehabilitation centers, assisted living residences and elder care organizations across New England and parts of Pennsylvania. That wide footprint means the breach potentially touched patients across multiple states and care settings.
In late June, the Qilin ransomware group claimed responsibility for the attack, Bleeping Computer reported. The group alleged it stole 852 GB of data, totaling nearly 1.35 million files. Covenant Health has not confirmed those figures, but it did acknowledge that patient information was accessed.
According to the organization, the exposed data may have included names, addresses, dates of birth, medical record numbers, Social Security numbers, health insurance details and treatment information such as diagnoses, dates of treatment and types of care received.
700CREDIT DATA BREACH EXPOSES SSNS OF 5.8M CONSUMERS
Qilin ransomware lists Covenant Health on its data leak site. (Bleeping Computer)
What Covenant Health is telling patients
In a notice sent to regulators and patients, Covenant Health says it engaged third-party forensic specialists to investigate the incident and determine what data was involved. The organization says its data analysis is ongoing as it continues identifying individuals whose information may have been involved.
Then there are the familiar statements every company makes after a breach, claiming they’ve strengthened the security of their IT systems to help prevent similar incidents in the future. Covenant Health says it has also set up a dedicated toll-free call center to handle questions related to the breach.
Beginning Dec. 31, 2025, the organization started mailing notification letters to patients whose information may have been compromised. For individuals whose Social Security numbers may have been involved, Covenant Health is offering complimentary credit monitoring and identity theft protection services.
We reached out to Covenant Health, and the company confirmed the expanded scope of the incident and outlined steps being taken to notify patients and enhance security safeguards.
DATA BREACH EXPOSES 400K BANK CUSTOMERS’ INFO
The breach exposed highly sensitive information, including names, Social Security numbers, medical records and treatment details tied to nearly half a million patients. (Kurt “CyberGuy” Knutsson)
7 steps you can take to protect yourself after the Covenant Health breach
If you received a notice from Covenant Health, or if your data has been exposed in any healthcare breach, these steps can help reduce the risk of misuse.
1) Enroll in the free identity protection offered
If the organization offers you credit monitoring or identity protection, take it. These services can alert you to suspicious activity tied to your Social Security number, credit file or identity details before real damage is done. If you’re not offered one and want to be on the safer side, you might consider getting one yourself.
Identity theft companies can monitor personal information like your Social Security number, phone number and email address and alert you if it is being sold on the dark web or being used to open an account. They can also assist you in freezing your bank and credit card accounts to prevent further unauthorized use by criminals.
See my tips and best picks on how to protect yourself from identity theft at Cyberguy.com
2) Monitor medical and insurance statements closely
Medical identity theft often shows up quietly. Review an explanation of benefits (EOBs), insurance claims and billing statements for services you don’t recognize. If something looks off, report it to your insurer immediately.
3) Place a fraud alert or credit freeze
A fraud alert tells lenders to take extra steps to verify your identity before approving credit. A credit freeze goes further by blocking new accounts entirely unless you lift it. If Social Security numbers were exposed, a freeze is usually the safer option.
To learn more about how to do this, go to Cyberguy.com and search “How to freeze your credit.”
4) Use a password manager
Healthcare breaches often lead to credential-stuffing attacks elsewhere. A password manager ensures every account uses a unique password, so one exposed dataset can’t unlock everything else. It also makes it easier to update passwords quickly after a breach.
Next, see if your email has been exposed in past breaches. Our No. 1 password manager pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials.
Check out the best expert-reviewed password managers of 2025 at Cyberguy.com.
5) Be cautious of phishing scams and use strong antivirus software
Breaches are frequently followed by phishing emails, texts or calls that reference the incident to sound legitimate. Attackers may pose as the healthcare provider, an insurer or a credit bureau. Don’t click links or share information unless you verify the source independently.
The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.
Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.
6) Consider a personal data removal service
Once your data leaks, it often spreads across data broker sites. Personal data removal services help reduce your digital footprint by requesting takedowns from these databases. While they can’t erase everything, they lower your exposure and make targeted fraud harder.
While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.
Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.
Get a free scan to find out if your personal information is already out on the web: Cyberguy.com.
7) Review your credit reports regularly
You’re entitled to free credit reports from all major bureaus. Check them for unfamiliar accounts, hard inquiries or address changes. Catching fraud early makes it far easier to contain.
Kurt’s key takeaway
Healthcare organizations remain prime targets for cybercriminal groups because of the volume and sensitivity of the data they store. Medical records contain a mix of personal, financial and health information that is difficult to change once exposed. Unlike a password, you cannot reset a diagnosis or treatment history. This breach also shows how early disclosures often underestimate impact. Large healthcare networks rely on complex systems and third-party vendors, which can slow forensic analysis in the early stages. As investigations continue, the number of affected individuals often climbs.
Do you think healthcare organizations do enough to protect user data? Let us know by writing to us at Cyberguy.com.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
Copyright 2025 CyberGuy.com. All rights reserved.
Technology
Amazfit’s Active 2 tracker and Blu-rays are this week’s best deals
The start of the year is typically a great time to snag deals on health and fitness gear, including trackers and wireless earbuds, and this week was no exception. We found plenty on sale and highlighted the best picks below. Not all of the deals are related to New Year’s resolutions, though; there are also a number of other worthwhile deals worth checking out. Despite the Consumer Electronics Show wrapping up earlier this week, we’re already seeing deals roll in, for example. And if your main goal is to unwind this weekend, we’ve spotted solid deals on Blu-rays to help you relax. Below, you’ll find all of our favorite deals from this week.
Of fitness trackers on sale right now, the deal on the Amazfit Active 2 is ideal, especially if you’re on a budget. It’s currently on sale for just $84.99 ($15 off) at Amazon, Best Buy, and Target, which is just $5 shy of its lowest price to date.
We think the Active 2 is one of the best fitness tracker you can currently buy, namely because it offers a feature set you don’t typically don’t find at this price point. It covers most of the health and fitness features people need and then some, with continuous heart rate and blood oxygen tracking, in addition to menstrual cycle tracking. You also get offline maps with turn-by-turn navigation and up to nine days of battery life — far longer than most smartwatches. It looks stylish, too, thanks to its stainless steel case and 2,000-nit OLED display that makes it seem more expensive than it is.
What makes the latest Nano Charger stand out from previous models its built-in display, which shows real-time charging details like power flow, charge level, and temperature at a glance. If you have an iPhone 15 or newer — or an iPad Pro released in 2020 or later — it can also adjust charging based on the device’s power needs. What’s more, it delivers up to 45W of power in a compact design with folding prongs that rotate 180 degrees, allowing you to squeeze it into smaller spaces.
Three more of this week’s best deals
-
Detroit, MI1 week ago2 hospitalized after shooting on Lodge Freeway in Detroit
-
Technology5 days agoPower bank feature creep is out of control
-
Dallas, TX3 days agoAnti-ICE protest outside Dallas City Hall follows deadly shooting in Minneapolis
-
Dallas, TX6 days agoDefensive coordinator candidates who could improve Cowboys’ brutal secondary in 2026
-
Delaware2 days agoMERR responds to dead humpback whale washed up near Bethany Beach
-
Iowa5 days agoPat McAfee praises Audi Crooks, plays hype song for Iowa State star
-
Health7 days agoViral New Year reset routine is helping people adopt healthier habits
-
Nebraska4 days agoOregon State LB transfer Dexter Foster commits to Nebraska