San Diego, CA
This is the phishing scam that gets a San Diego identity theft expert ‘really, very angry’
Digital thieves are nothing if not persistent and innovative.
They keep finding new ways to try to part you from your money.
Phishing — where thieves pose as trusted entities or send legitimate looking emails or messages to trick you into giving them access to your accounts — is a widespread method. And it is constantly evolving.
“We’ve seen phishing go through the roof,” said Eva Velasquez, the CEO of the Identity Theft Resource Center, a San Diego-based national nonprofit.
But knowledge is power. So here are three emerging phishing threats to look out for, according to internet safety experts. All three threats target key parts of people’s digital lives: email attachments that lead to fake login pages, multi-factor authentication trickery and deceptive calendar invites.
Spending a few minutes reading these pointers could help you avoid getting your ID or money stolen and save you countless hours of dealing with the fallout.
HTML attachments that open fake login pages
Imagine a busy professional who is in email action mode. In the past 30 minutes on a Saturday morning, he has filled out emailed liability waivers for his seven children’s summer camps, filed an expense report for work, answered a secure portal message from the veterinarian about his sick puppy’s prescription, skimmed 182 email subject lines and paid five bills from his email inbox, including a car insurance premium and his beloved cheese-of-the-month club.
Amid this flurry of inbound emails, ads, invoices and secure messages, he is working on autopilot: opening messages, skimming, clicking and signing in.
What a perfect opportunity.
Scammers are taking advantage of user distraction — and their trust — by sending emails with HTM or HTML attachments. When clicked, those open a browser file that looks like secure, familiar login page. These pages might look like secure invoice viewers, file-sharing services like DocuSign or Dropbox, or sign-in pages to platforms including Microsoft 365.
“Once the user enters their credentials, they are sent surreptitiously to the attacker’s server,” said Vlad Cristescu, the head of cybersecurity with ZeroBounce, a Florida company that helps businesses lower their rate of bounced marketing emails.
Why this method is especially insidious: “There isn’t a clickable link in the email, so standard email security filters (which scan for malicious URLs or attachments like PDFs and ZIPs) may not catch it,” Cristescu added.
To prevent this, he added, companies should “restrict HTML attachments unless essential, and users should treat unfamiliar HTML files the same way they’d treat a suspicious link — don’t open it unless you’re absolutely sure of the sender.”
If you do receive incoming communication with an HTML link or attachment, don’t engage, said Velasquez, with the ITRC.
“Don’t click on links, people. That’s the big, overarching message,” she said. Instead, go to the source: call the phone number on the back of your credit card, visit the bank in person.
Multifactor authentication tricks
If you are one of the many people who uses multifactor authentication, take note.
Multifactor authentication is still very helpful and should be used.
But Cristescu flagged one way that scammers are taking this tool — which is designed to make people’s online accounts more secure — and using it to slither in.
As a refresher, multifactor authentication is an added layer of protection that prevents data thieves from logging into your accounts if they have your username and password. It helps ensure that you’re the one who typed in your password when you log in, and not some scammer in the Philippines or Poughkeepsie.
To use multifactor authentication, you typically download an app, such as Google Authenticator or Microsoft Authenticator. You register your sensitive online accounts, such as Facebook, bank or email, with that app. Then, every time you log into a registered website, the authenticator app generates a new, random code that you enter after your password as a second layer of verification.
With the rise of this protection, a new threat has emerged: Scammers who have your username and password can send log-in requests to your authenticator app. Next, the scammer can pose as an IT expert from your workplace and ask you to approve the log-in request.
If you fall for it, then boom — the scammer is in.
This technique “exploits a user’s frustration and trust in IT. If you’re receiving multiple (authenticator) prompts you didn’t initiate, that’s not a glitch – it’s an attack,” Cristescu said. He recommends pausing, never approving these unexpected requests and flagging the interaction with IT.
Velasquez added that if you get an authenticator notification and you didn’t just log in yourself, “That is a huge red flag. Stop and address it. Don’t ignore it.”
Anytime you interact with IT, be sure you’re the one initiating that contact, she added. If someone from IT calls or emails you, disconnect and reach back out using a trusted method, such as the same phone number you always dial.
Fake calendar invites
A third technique data thieves are using is calendar invites.
“I just get really very angry about this one,” Velasquez said. “It is super hard to detect.”
Here’s what to look out for. If you use an online calendar like Google calendar or the native iPhone calendar app, you might receive an invitation to an event you didn’t see coming. Sometimes these meetings are legitimate. Sometimes, they are not.
Scammers “are now sending meeting requests with malicious links embedded in the invite or ‘join’ button. These invitations sync directly into calendars and often go unquestioned,” according to ZeroBounce.
Scammers use calendar invites because they have “built-in credibility – they’re not usually scrutinized like emails,” Cristescu said. Look for meeting requests from unknown senders and vague event names like “Sync” or “Project Review,” he added.
In some jobs or roles, meetings routinely get added to calendars by other people — clients, prospects, coworkers, bosses, peers.
“I have gotten these repeatedly,” said Velasquez, with the ITRC. “Depending on your lifestyle and your job and how you work, these are going to be particularly challenging. They are real calendar invites. The problem is they have malicious software embedded in them — so when you click on portions of them, ‘Click to join,’ it’s like opening an attachment (or) clicking on a suspicious link. It’s the same principle.”
Cristescu, with ZeroBounce, shared this tip: “Treat those just like a phishing email. Disable auto-accept where possible and review every invite manually before clicking anything.”
Never stop questioning what lands in your inbox or calendar, Cristescu added. “Always verify the sender’s email address, ensure that any link you click matches the legitimate domain, and look out for subtle red flags like spelling errors or unusual formatting.”
A big picture pointer
“All three of these (scams) are so common that it has probably happened to every single person reading the article — at least one of them. That’s how ubiquitous these are,” Velasquez said.
She shared this broader thought: It’s less important to know how to respond to each scenario and more important to pause, be skeptical, double check.
It’s important to be ever more skeptical, because AI makes it easier and easier for thieves to create convincing ruses, Cristescu and Velasquez both said.
AI “really helps with making these phishing offers look and sound so much more legitimate,” Velasquez said. “And with the amount of data that is out there from public sources and from data breaches, it’s very easy to see what relationships people have.” Where you bank, where you do business — that is all fodder for someone to create a copycat page designed to trick you into logging in.
Adopt an “investigator mindset,” Velasquez said. Use this helpful reminder: the acronym STAR, which stands for Stop. Think. Ask questions or ask for help. Reassess.
The ITRC nonprofit can answer questions, for free, through phone and live chat. Toll-free phone: 888-400-5530. Live chat staffed by people, not bots: https://www.idtheftcenter.org/victim-help-center/
San Diego, CA
Man fatally struck by hit-and-run vehicle in San Diego
A man in the Mission Bay Park community of San Diego was fatally struck Sunday morning by a hit-and run vehicle, authorities said.
The victim was also struck by a second vehicle and that motorist stayed at the scene to cooperate with officers, the San Diego Police Department reported.
The initial crash occurred at about 2:20 a.m. Sunday in the area of West Mission Bay and Sea World drives.
The pedestrian was in the southbound lanes of the 2000 block of West Mission Bay Drive when he was struck by a silver vehicle also in the southbound lanes. That vehicle fled the scene, continuing southbound, police said.
A 28-year-old man driving his vehicle southbound ran over the downed pedestrian.
“That driver remained at the scene and is not DUI,” according to a police statement. “The pedestrian was pronounced deceased at the scene.”
Anyone with information regarding the initial crash was urged to call Crime Stoppers at 888-580-8477.
San Diego, CA
Here are the 9 San Diego County communities that set or tied heat records
San Diego County is known for having wet, cold weather in February. But it had numerous hot spells this year. And when the month ended on Saturday a high pressure system produced heat that broke or tied temperature records in nine communities from the desert to the sea, the National Weather Service said.
The most notable temperature occurred in Borrego Springs, which reached 99, five degrees higher than the previous record for Feb. 28, set in 1986. The 99 reading is also the highest temperature ever recorded in Borrego in February.
Escondido reached 95, tying a record set in 1901.
El Cajon reached 92, three degrees higher than the record set in 2009.
Ramona topped out at 88, five degrees higher than the record set in 2009.
Alpine hit 88, four degrees higher the record set in 1986.
Campo reached 87, four degrees higher than the record set in 1999.
Vista hit 86, four degrees higher than the record set in 2020.
Chula Vista reached 84, one degree higher than the record set in 2020.
Lake Cuyamaca rose to 76, four degrees higher than the record set in 1986.
Forecasters say the weather is not likely to broadly produce new highs on Sunday. Cooler air is moving to the coast, and on Monday, San Diego’s high will only reach 67, a degree above normal.
San Diego, CA
Francis Parker captures Open Division girls basketball title
OCEANSIDE — The Frontwave Arena scoreboard showed 23 seconds remaining in the fourth quarter. Up 16, Francis Parker’s win over Westview High School for the CIF San Diego Section Open Division girls basketball championship was secure.
“No, no, no!” Parker head coach Courtney Clements screamed to freshman guard Jordan Brown, telling her there was no need to score.
So Brown walked the ball up the floor, from the backcourt, across midcourt, a 1,000-watt smile etched across her face.
With no Wolverines defending her, Brown dribbled from side to side across the logo. Then, a fraction of a moment before the final buzzer sounded, Brown flung the basketball high toward the rafters, then was engulfed by teammates.
The job was complete. Parker’s first Open Division title in program history was secure, the final reading 66-50 on Saturday night.
Of those final seconds, said Brown, who scored 23 points. “It was a surreal moment, knowing we worked for this all year long. It’s amazing.”
One reason it was amazing was because the top-seeded Lancers (21-7) were a decided favorite, but were stressed by the sixth-seeded Wolverines (20-9). Led by UC Santa Barbara-bound senior guard Sarah Heyn (18 points in the first half), Westview led 35-28 early in the third quarter.
“I just knew I had to do whatever it took to win,” said Brown. “Whether that was defense or offense. I just wanted to win, period.”
Sparked by its defense, Parker closed the quarter on a 14-0 run. Westview’s final 11 possessions of the quarter ended with five missed shots and six turnovers.
Still, the game wasn’t over. Heyn cut the deficit to 48-44 with just over six minutes to play on a bucket. But with 5:47 to play, Heyn was whistled for her fifth foul on a reach-in.
“Knowing their best player fouled out, we sealed the win,” said Brown.
As for Heyn, who finished with 23 points, she sat on the bench and pulled her jersey over her eyes, hiding tears.
Clements’ thoughts when Heyn fouled out? “I hope we can put this game away now.”
That the Lancers did, outscoring Westview 18-6 down the stretch.
The Lancers’ players and coach were effusive in their praise for Heyn, a four-year starter.
“She’s a great player,” said Brown.
“She played phenomenally,” said Clements. “She played the way you would think a senior would play in a championship game. She played desperately. She played every possession like it was the last 20 seconds of the game. She was extremely impressive. (Heyn buried five 3s, missing only once from deep.) She should be proud of herself.”
Clements was proud of her team for another reason. After blowing out two-time reigning Open Division champion Mission Hills by 26 in the semis, some thought Parker might cruise in the title game.
“I figured it was going to be a fight, and it was,” said Clements. “It was good that our girls had to come together, had to stick together. That’s what this is all about, developing character via the sport of basketball. When the kids face adversity, they have to make a decision. Who do they want to be? They showed the best version of themselves. That’s what I want to remember from a game like this.”
Francis Parker’s primary color is brown, which is fitting for the girls basketball team. They are led not only by the freshman Jordan Brown, but also junior Brieana Brown, a strong, aggressive and athletic 5-foot-11 wing.
Brieana Brown scored 25 points and yanked down a team-best eight rebounds.
About the team in brown being led by the Browns (who are not related), Jordan Brown said: “It’s super cool. I love Bri and our story. So many people think we’re related, that we’re siblings. In reality, we’re not, but we play like it.”
Francis Parker and Westview both will advance to the Southern California Regionals.
Earlier in the season, Clements — who was dressed in all black for the championship game — confessed she wasn’t crazy about Parker’s primary color. Her mood shifted Saturday night.
“Brown’s doing well for me now,” she said.
Asked if Lancers’ Brown squared tandem represents the best one-two girls basketball punch in the San Diego Section, Clements gave the questioner a “What do you think?” smirk.
“That,” said the coach of the Open Division champions, “is a no-brainer.”
-
World5 days agoExclusive: DeepSeek withholds latest AI model from US chipmakers including Nvidia, sources say
-
Massachusetts5 days agoMother and daughter injured in Taunton house explosion
-
Denver, CO5 days ago10 acres charred, 5 injured in Thornton grass fire, evacuation orders lifted
-
Louisiana1 week agoWildfire near Gum Swamp Road in Livingston Parish now under control; more than 200 acres burned
-
Technology1 week agoYouTube TV billing scam emails are hitting inboxes
-
Politics1 week agoOpenAI didn’t contact police despite employees flagging mass shooter’s concerning chatbot interactions: REPORT
-
Technology1 week agoStellantis is in a crisis of its own making
-
News1 week agoWorld reacts as US top court limits Trump’s tariff powers

