Technology
Harvard hit by new breach after phone phishing attack
NEWYou can now listen to Fox News articles!
Elite universities like Harvard, Princeton and Columbia spend fortunes on research, talent and digital infrastructure. Even then, they’ve become easy targets for attackers who see massive databases filled with personal information and donation records as a goldmine. Over the past few months, breaches across Ivy League campuses have exposed the same problem. These institutions handle huge amounts of sensitive data, but their internal defenses often don’t match the scale of what they store. That pattern brings us to Harvard’s newest incident, which exposed a database of alumni, donors, some students and faculty to hackers.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
CHECK IF YOUR PASSWORDS WERE STOLEN IN HUGE LEAK
Elite universities hold massive troves of personal and financial data that make them irresistible targets for attackers. (Photo by Aaron M. Sprecher/Getty Images)
A phone phishing attack unlocks Harvard’s data
Harvard confirmed that a database tied to alumni, donors, faculty and some students was accessed by an unauthorized party. This happened after a phone phishing attack tricked someone into giving the attacker a way into the system.
“On Tuesday, November 18, 2025, Harvard University discovered that information systems used by Alumni Affairs and Development were accessed by an unauthorized party as a result of a phone-based phishing attack,” the university said in a notification posted on its website. “The University acted immediately to remove the attacker’s access to our systems and prevent further unauthorized access.”
The exposed data includes personal contact details, donation histories and other records tied to the university’s fundraising and alumni operations. For Harvard, a school that routinely raises more than a billion dollars a year, this database is one of its most valuable assets, which makes the breach even more serious.
This is also the second time Harvard has had to investigate a breach in recent months. In October, it looked into reports that its data was caught up in a broader hacking campaign targeting Oracle customers. That earlier warning already showed that the school sits in a high-risk category. This latest breach only confirms it.
SCAMMERS NOW IMPERSONATE COWORKERS, STEAL EMAIL THREADS IN CONVINCING PHISHING ATTACKS
Harvard’s latest breach began with a phone phishing scam that let an intruder access a key alumni and donor database. (Jens Büttner/picture alliance via Getty Images)
Ivy League schools are in a growing crisis
Harvard isn’t alone here. Ivy League campuses have seen a wave of incidents that line up almost back-to-back. Princeton reported on Nov. 15 that one of its databases tied to alumni, donors, students and community members was compromised.
The University of Pennsylvania said on Oct. 31 that information systems connected to its development and alumni activities were accessed without permission. Columbia has been dealing with an even larger fallout. A breach in June exposed the personal data of roughly 870,000 people, including students and applicants.
These attacks show how universities have become predictable targets. They store identities, addresses, financial records and donor information. They also run sprawling IT systems where a single mistake, a weak password or a convincing phone call can create an entry point.
Hackers know this, and they strike repeatedly. The recent cluster of Ivy League breaches suggests that attackers are mapping these environments, looking for shared weaknesses that appear again and again.
NEW EMAIL SCAM USES HIDDEN CHARACTERS TO SLIP PAST FILTERS
A wave of incidents across Ivy League campuses shows hackers are exploiting the same weaknesses again and again. (Kurt “CyberGuy” Knutsson)
7 steps you can take to protect yourself from such data breaches
You can’t stop a university or company from being breached, but you can make sure that your own information is harder to exploit. These steps help you reduce the fallout when your data ends up in the wrong hands.
1) Turn on two-factor authentication (2FA)
Using 2FA gives your accounts an extra layer of security. Even if someone steals your password in a breach, they still need the one-time code from your phone or authentication app. It blocks most casual attempts and forces attackers to work much harder.
2) Use a password manager
A password manager creates and stores strong, unique passwords for every site you use. This keeps one compromised password from unlocking everything else. It also removes the stress of remembering dozens of logins, so you don’t cut corners.
Next, see if your email has been exposed in past breaches. Our No. 1 password manager pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials.
Check out the best expert-reviewed password managers of 2025 at Cyberguy.com
3) Reduce the personal info floating around
You can request takedowns from data broker sites, delete old accounts and trim what you share publicly. When your information isn’t scattered across the internet, attackers have a much harder time piecing together your identity.
While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.
Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com
Get a free scan to find out if your personal information is already out on the web: Cyberguy.com
4) Be cautious with emails, texts and calls
Phishing doesn’t always come as obvious scam mail. Attackers spoof institutions, copy their tone and pressure you into sharing details quickly. Slow down, verify the message through an official website or helpline, then decide.
The best way to safeguard yourself from malicious links is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.
Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com
5) Keep your devices fully updated
Many attackers rely on old flaws in operating systems, browsers and apps. Regular updates patch these holes and shut down the most common attack paths. If you’re someone who delays updates, turning on automatic updates helps.
6) Separate your online identities
Use alias email addresses for banking, education, shopping and newsletters. If one of them gets exposed, it won’t automatically give attackers a map of your entire digital life. It makes targeted scams much harder to pull off, and also stops attackers from stealing your identity. By creating email aliases, you can protect your information and reduce spam. These aliases forward messages to your primary address, making it easier to manage incoming communications and avoid data breaches.
For recommendations on private and secure email providers that offer alias addresses, visit Cyberguy.com
7) Use an identity theft protection service
You might also want to consider an identity theft protection service to be on the safe side. Identity Theft companies can monitor personal information like your Social Security number (SSN), phone number and email address, and alert you if it is being sold on the dark web or being used to open an account. They can also assist you in freezing your bank and credit card accounts to prevent further unauthorized use by criminals.
See my tips and best picks on how to protect yourself from identity theft at Cyberguy.com
Kurt’s key takeaway
Harvard’s latest breach adds to a growing list of cyberattacks that show how vulnerable top universities have become. Even the most well-funded institutions aren’t keeping pace with modern threats. When a simple phone phishing call can open the door to sensitive data tied to donors, alumni and students, it’s clear that these campuses need stronger defenses and more proactive monitoring. Until that happens, you can expect more headlines like this and more investigations after the damage is already done.
Do you trust universities to protect the personal data you’ve shared with them? Let us know by writing to us at Cyberguy.com
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
Copyright 2025 CyberGuy.com. All rights reserved.
Technology
Cold Court’s debut EP is an infectious, glitchy genre mashup
Cold Court is a brother-sister duo from Philly that seems to love nothing more than shoving all of their influences together in a messy soup that at least superficially resembles the hyperpop you’ve come to expect from acts like 100 Gecs. But, where songs like “Dumbest Girl Alive” goofily wink at pop punk and emo, Cold Court are a bit more self-serious, and that’s not necessarily a bad thing.
The opening track on the band’s debut EP (^_^) / (aka Hands Up), “Nina”, starts off sounding not unlike the dance punk bands that stormed the scene in the mid aughts like Franz Ferdinand or Test Icicles. But that all starts to change about a minute in, when the skuzzy riff gets chopped up and fed through a beat repeater. Another minute later, there’s a mellow proggy bridge that calls to mind Mars Volta. Then the whole thing ends on a barrage of glitches and digital chaos.
The record largely continues in this fashion. The songs on Hands Up clearly started life on drums and guitar. But then Mini and Jojo fed their creations to a computer, added layers, rearranged the pieces, and piled on the effects. Single “Burn” is perhaps the best example of all the parts coming together. It features big rock riffs, Daft Punk-esque synths, dubstep chops, autotuned vocals, and even a rapped bridge. Yet the whole thing feels like a cohesive, seething whole as they shout, “I just want to see it burn, give a fuck about your word.”
They’re not the deepest lyrics, but it works.
While Cold Court is clearly an exercise in maximalism, not every song goes quite as big as “Burn.” “Cola” moves more slowly, strips back some of the layers, but doesn’t turn the volume down. “Glass” almost becomes math rock as its guitars get chopped up and spit back out, and the EP’s closer “Light” is blown-out, sparkly prog.
Over the course of a full album, the relentless barrage might grow exhausting. But at just 21 minutes, Hands Up doesn’t overstay its welcome, and it will be interesting to see how the band evolves as the young duo grow.
Technology
Bose thinks it can be a media company for some reason
The history books are littered with the corpses of corporate record labels started by companies that had no business being in the music industry. Bose thinks it can be the exception to the rule. It thinks it can be Red Bull. And, while Bose has more of a right to dip its toes into the media world than Build-a-Bear, there’s little reason to believe it can succeed where so many others have failed.
In an interview with Business Insider, Bose CMO Jim Mollica said the company had created Bose Studios as part of a move away from traditional “campaign-driven marketing.” A big element of that is going to be Bose Records, a new label the company has formed to “help break underappreciated or new artists.” The competition isn’t the big three — Sony, UMG, Warner — it’s independent labels already being squeezed in an era of bedroom producers and self-distribution.
Mollica was transparent about the real goal, though: build a library of music that Bose could feature in its commercials without having to pay the licensing rights for. He said that the company wouldn’t own the artists’ masters or take a share of their streaming or sales revenue, and that they’d be free to sign with other labels. That sounds extremely artist-friendly on its face, which is great. But there’s still a lot we don’t know about the new business venture.
Bose is primarily known for making consumer-grade audio gear that tries to put on airs. Most audiophiles will be quick to tell you that Bose products are overpriced and, at best, merely okay. What the company is undeniably great at is marketing. But selling mediocre Bluetooth speakers at inflated prices is very different from discovering talent and promoting artists. Mollica didn’t mention poaching A&R talent from other labels or any splashy celebrity partnerships to launch. Though he did mention that some “legendary Hollywood names” were attached to films and TV series being commissioned by Bose Studios.
Which brings us to another issue: a lack of focus. Simply launching a record label is hard enough. Why does Bose — again, whose primary experience is in manufacturing audio hardware — think that it can also launch a movie studio, a podcast network, and a live event production company? These are all things that Mollica said are in the works, according to Business Insider.
Sure, you could argue that Bose, as an audio company, has more of a right to dive into the music industry than those failed ventures. But they featured celebrity endorsements, partnerships with bigger labels, or, at the very least, some specific cultural hook. Bose Studios just seems desperate and unfocused.
Technology
Fake AAA email scam targets drivers
NEWYou can now listen to Fox News articles!
A strange email lands in your inbox, and at first, it sounds helpful. It uses a familiar company, leans into family safety and warns that you may need to act before a deadline.
That is what makes this suspicious AAA-themed email we received worth warning you about. It reads like a friendly safety reminder from someone who claims to work in AAA’s member outreach. It isn’t the kind of message most of us would delete right away.
Still, something feels off. Before you click any link or trust the warning, it helps to slow down and look for the signs that this could actually be one big scam.
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
FAKE TRAFFIC VIOLATION TEXT SCAM USES QR CODES TO STEAL PAYMENT INFO
A suspicious AAA-themed email can look harmless at first, especially when it uses a familiar company and a safety warning. (Kurt “CyberGuy” Knutsson)
What this fake AAA email scam is
The email appears to use car safety as bait, then pushes you toward a link that should raise concern.
A message built around family safety
The email claims to come from someone named Sloane Garibaldi at AAA. It says the recipient’s household appeared on a member outreach list. Then it asks whether the family is “actually safe” in the car. That wording makes the message feel personal. It also turns a random email into something that sounds urgent.
A supposed rule with a deadline
The email says a new federal rule starts on July 1, 2026. It claims every passenger vehicle must carry a certified emergency rescue tool that can cut a seatbelt and break glass. Then it adds a warning about a $200 fine per occurrence. That kind of deadline can make any driver worry. However, the message does not point to a government site or an official AAA page. Instead, it pushes a shared Google link.
A fake status check
The email includes a small “compliance check” box. It lists the recipient as a member and says the check has not been completed. That detail makes the message feel like an account notice. It also creates a small task the reader may want to fix. Scammers use that tactic often. They make the action look quick, then hope you click before you question the message.
YOUR EMAIL DIDN’T EXPIRE; IT’S JUST ANOTHER SNEAKY SCAM
The email claims a new car safety rule is coming, but the message pushes the recipient toward a shared link instead of an official AAA website. (Kurt “CyberGuy” Knutsson)
Red flags in the fake AAA email
Several clues inside the message suggest this email deserves to be treated as suspicious.
1) The real sender address looks suspicious
The display name says Sloane Garibaldi, but the expanded sender address shows pfiz@middlerunred.guru. That domain has no clear connection to AAA. Display names can be faked. The real sender address often tells a very different story.
The sender name looks familiar, but the real email address shown here has no clear connection to AAA. (Kurt “CyberGuy” Knutsson)
2) The email does not use official AAA branding
The message uses the AAA name, but it does not include the official AAA logo or the kind of polished branding you would expect from a real member safety notice. That alone does not prove an email is fake. However, it adds to the concern when combined with a strange sender address, a shared link and urgent language. A real company email usually looks consistent with the brand’s website, app and past messages.
3) The link goes through a shared URL
The message uses a share. Google link instead of an official AAA website. That should make you pause. Shared links can hide the final destination. They can also lead to fake forms that collect personal details, account information, vehicle data or payment details. A real AAA notice should point to an official AAA domain or tell you to log in through the AAA app.
4) The email pushes fear before facts
The message asks whether your family is safe. It mentions a deadline. It warns about fines. Then it says the check only takes 60 seconds. That is a pressure move. The scammer wants clicking to feel easier than checking.
5) The rule citation does not match the claim
The email cites NHTSA FMVSS 571.220. That sounds convincing until you check what the rule covers. That federal standard deals with school bus rollover protection. It does not appear to require everyday passenger vehicles to carry an emergency rescue tool. Scammers often use official-sounding language because many people will not look it up.
6) The tone feels too casual for a legal warning
The message uses friendly lines like “I promise I’m not being dramatic” and “I’d rather chase you about this twice.” That tone may be meant to lower your guard. It sounds like someone trying to help. Still, a real safety or compliance notice should not arrive from a strange domain with a shared link and casual pressure.
7) The fine print repeats the suspicious link
The bottom of the email includes a P.S. that says the link may “wrap oddly” in your mail app. Then it repeats the same shared link so you can click it again. It even adds, “I’ve had people miss it because their inbox cut it in half,” which sounds casual but also gives the sender another excuse to push the link. That may seem helpful, but it keeps steering you toward the same questionable destination. Legitimate companies do not need to explain why a safety link looks strange in your inbox.
The fine print also says the recipient’s email address is tied to a “member household” in an outreach queue for the July 1, 2026, FMVSS §571.220 rollout. That wording sounds official, but it gives no member number, no verified AAA account link and no official AAA contact path. Even the opt-out line deserves caution. Scam emails often include unsubscribe or opt-out links to make the message look legitimate. In this case, “opt out here” could confirm your email address is active or send you to another suspicious page.
10 WAYS TO PROTECT SENIORS FROM EMAIL SCAMS
The fine print repeats the same questionable link and adds an opt-out line that could be another trap. (Kurt “CyberGuy” Knutsson)
AAA says it did not send the email
We reached out to AAA, and the organization confirmed the message did not come from them.
“AAA did not send those emails, and they could potentially be malicious,” an AAA spokesperson told CyberGuy. “We remind members to avoid clicking on suspicious links and contact us directly if they have questions or concerns.”
That confirmation makes the warning even clearer: do not click the link in the email. Go directly to AAA if you have any questions about your membership or a safety notice.
Why this fake AAA email could fool drivers
The scam feels believable because it mixes a practical safety concern with a personal tone and an official-sounding reference.
Car safety gets attention
Most people want to protect their family on the road. A seatbelt cutter or window breaker can also sound useful in a real emergency. That makes the topic believable. The issue is the email, not necessarily the idea of keeping an emergency tool in your vehicle.
Personal details can lower your guard
The email uses the recipient’s actual first and last name. Scammers often use personal details to make messages feel legitimate. A name, city, phone number or family reference can make someone hesitate before deleting an email.
Official names add fake credibility
The email mentions NHTSA and a federal motor vehicle safety standard. Those details make the message look researched. However, one official name does not make the claim true. Scammers count on people trusting the reference without checking it.
SSA IMPERSONATION SCAMS ARE GETTING MORE PERSONAL
The fake AAA-themed email uses a familiar name and safety language to make a suspicious message look trustworthy. (Jaap Arriens/NurPhoto)
How to stay safe from fake AAA emails
A few quick checks can help you avoid bad links, fake forms and phishing attempts that pretend to come from trusted brands.
1) Check the sender address
Do not rely on the display name. Click or tap the sender to see the full address. If the domain does not match the company, treat the message as suspicious.
2) Look for missing or sloppy branding
Pay attention to the overall look of the email. Missing logos, odd spacing, plain formatting or generic design can be warning signs. Also, compare the message with past emails from the same company. If the style looks off, do not click.
3) Skip links in urgent emails
Avoid clicking links in surprise emails that mention deadlines, penalties or account problems. Instead, open your browser and go directly to the company’s official website. You can also use the company’s app.
4) Use strong antivirus software
Strong antivirus software can help block malicious links, phishing pages and dangerous downloads. It can also warn you before you land on a risky site. That extra alert can stop a quick mistake from becoming a bigger problem. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com
5) Do not fill out surprise forms
A fake “readiness check” can collect more than you realize. Do not enter your name, address, phone number, vehicle details, payment information or account login through an unexpected email link.
6) Verify legal claims on your own
If an email cites a rule, law or government agency, search for it separately. Use official government websites or trusted legal sources. Do not use the link inside the message to verify the message.
7) Use a data removal service
Scam emails become more convincing when criminals know personal details about you. Data brokers and people-search sites can expose names, addresses, phone numbers and relatives. A data removal service can help reduce that exposure. It will not remove everything, but it can make you a harder target. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com
8) Report and block the sender
Mark the message as phishing or junk. Then block the sender and delete the email. If the message claims to come from AAA, contact AAA through its official website or app to report it.
9) Warn someone who may click quickly
This kind of scam can fool anyone. It may be especially risky for older relatives, new drivers or anyone who takes safety notices seriously. A quick warning could help them avoid a bad link and major headaches down the road.
Kurt’s key takeaways
This fake AAA email works because it feels personal and practical. It talks about family safety. It uses a deadline. It cites a federal rule. Then it pushes a link that does not belong in a legitimate AAA notice. That is the real lesson here. When an email makes you feel rushed, slow down. Check the sender address. Look at the link. Notice the branding. Verify the claim somewhere else. You may still decide to keep an emergency tool in your car. Just do not buy one, register one or share personal information because a suspicious email told you to act fast.
Should companies and email providers be doing more to stop scam messages like this before they ever hit your inbox? Let us know by writing to us at Cyberguy.com
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
Copyright 2026 CyberGuy.com. All rights reserved.
-
Lifestyle14 minutes agoTop 5 Pixar movies, ranked by listeners : Pop Culture Happy Hour
-
Technology27 minutes agoCold Court’s debut EP is an infectious, glitchy genre mashup
-
World30 minutes agoUS military conducts strike on another vessel carrying alleged narco-traffickers, killing 2
-
Politics35 minutes agoCollege sports sees pivotal moment as Senate looks to move legislation on NIL, transfers across goal line
-
Health42 minutes agoDad jokes may be good for your brain in one surprising way, experts say
-
Sports45 minutes agoWhere In The World Cup Is Jameis Winston?
-
Business57 minutes agoNewsom and L.A. declare state of emergency as Boyle Heights fire continues spewing smoke across region
-
Entertainment60 minutes agoPuppets, performers and politics filled the streets at LACMA’s first-ever Art Parade