Connect with us

Technology

Harvard hit by new breach after phone phishing attack

Published

on

Harvard hit by new breach after phone phishing attack

NEWYou can now listen to Fox News articles!

Elite universities like Harvard, Princeton and Columbia spend fortunes on research, talent and digital infrastructure. Even then, they’ve become easy targets for attackers who see massive databases filled with personal information and donation records as a goldmine. Over the past few months, breaches across Ivy League campuses have exposed the same problem. These institutions handle huge amounts of sensitive data, but their internal defenses often don’t match the scale of what they store. That pattern brings us to Harvard’s newest incident, which exposed a database of alumni, donors, some students and faculty to hackers.

Sign up for my FREE CyberGuy Report

Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.

CHECK IF YOUR PASSWORDS WERE STOLEN IN HUGE LEAK

Advertisement

Elite universities hold massive troves of personal and financial data that make them irresistible targets for attackers. (Photo by Aaron M. Sprecher/Getty Images)

A phone phishing attack unlocks Harvard’s data

Harvard confirmed that a database tied to alumni, donors, faculty and some students was accessed by an unauthorized party. This happened after a phone phishing attack tricked someone into giving the attacker a way into the system.

“On Tuesday, November 18, 2025, Harvard University discovered that information systems used by Alumni Affairs and Development were accessed by an unauthorized party as a result of a phone-based phishing attack,” the university said in a notification posted on its website. “The University acted immediately to remove the attacker’s access to our systems and prevent further unauthorized access.”

The exposed data includes personal contact details, donation histories and other records tied to the university’s fundraising and alumni operations. For Harvard, a school that routinely raises more than a billion dollars a year, this database is one of its most valuable assets, which makes the breach even more serious.

This is also the second time Harvard has had to investigate a breach in recent months. In October, it looked into reports that its data was caught up in a broader hacking campaign targeting Oracle customers. That earlier warning already showed that the school sits in a high-risk category. This latest breach only confirms it.

Advertisement

SCAMMERS NOW IMPERSONATE COWORKERS, STEAL EMAIL THREADS IN CONVINCING PHISHING ATTACKS

Harvard’s latest breach began with a phone phishing scam that let an intruder access a key alumni and donor database. (Jens Büttner/picture alliance via Getty Images)

Ivy League schools are in a growing crisis

Harvard isn’t alone here. Ivy League campuses have seen a wave of incidents that line up almost back-to-back. Princeton reported on Nov. 15 that one of its databases tied to alumni, donors, students and community members was compromised.

The University of Pennsylvania said on Oct. 31 that information systems connected to its development and alumni activities were accessed without permission. Columbia has been dealing with an even larger fallout. A breach in June exposed the personal data of roughly 870,000 people, including students and applicants.

These attacks show how universities have become predictable targets. They store identities, addresses, financial records and donor information. They also run sprawling IT systems where a single mistake, a weak password or a convincing phone call can create an entry point.

Advertisement

Hackers know this, and they strike repeatedly. The recent cluster of Ivy League breaches suggests that attackers are mapping these environments, looking for shared weaknesses that appear again and again.

NEW EMAIL SCAM USES HIDDEN CHARACTERS TO SLIP PAST FILTERS

A wave of incidents across Ivy League campuses shows hackers are exploiting the same weaknesses again and again. (Kurt “CyberGuy” Knutsson)

7 steps you can take to protect yourself from such data breaches

You can’t stop a university or company from being breached, but you can make sure that your own information is harder to exploit. These steps help you reduce the fallout when your data ends up in the wrong hands.

1) Turn on two-factor authentication (2FA)

Using 2FA gives your accounts an extra layer of security. Even if someone steals your password in a breach, they still need the one-time code from your phone or authentication app. It blocks most casual attempts and forces attackers to work much harder.

Advertisement

2) Use a password manager

A password manager creates and stores strong, unique passwords for every site you use. This keeps one compromised password from unlocking everything else. It also removes the stress of remembering dozens of logins, so you don’t cut corners.

Next, see if your email has been exposed in past breaches. Our No. 1 password manager pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials.

Check out the best expert-reviewed password managers of 2025 at Cyberguy.com

3) Reduce the personal info floating around

You can request takedowns from data broker sites, delete old accounts and trim what you share publicly. When your information isn’t scattered across the internet, attackers have a much harder time piecing together your identity.

While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.

Advertisement

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com

4) Be cautious with emails, texts and calls

Phishing doesn’t always come as obvious scam mail. Attackers spoof institutions, copy their tone and pressure you into sharing details quickly. Slow down, verify the message through an official website or helpline, then decide.

The best way to safeguard yourself from malicious links is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.

Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com

Advertisement

5) Keep your devices fully updated

Many attackers rely on old flaws in operating systems, browsers and apps. Regular updates patch these holes and shut down the most common attack paths. If you’re someone who delays updates, turning on automatic updates helps.

6) Separate your online identities

Use alias email addresses for banking, education, shopping and newsletters. If one of them gets exposed, it won’t automatically give attackers a map of your entire digital life. It makes targeted scams much harder to pull off, and also stops attackers from stealing your identity. By creating email aliases, you can protect your information and reduce spam. These aliases forward messages to your primary address, making it easier to manage incoming communications and avoid data breaches.

For recommendations on private and secure email providers that offer alias addresses, visit Cyberguy.com

7) Use an identity theft protection service

You might also want to consider an identity theft protection service to be on the safe side. Identity Theft companies can monitor personal information like your Social Security number (SSN), phone number and email address, and alert you if it is being sold on the dark web or being used to open an account. They can also assist you in freezing your bank and credit card accounts to prevent further unauthorized use by criminals.

See my tips and best picks on how to protect yourself from identity theft at Cyberguy.com

Advertisement

Kurt’s key takeaway

Harvard’s latest breach adds to a growing list of cyberattacks that show how vulnerable top universities have become. Even the most well-funded institutions aren’t keeping pace with modern threats. When a simple phone phishing call can open the door to sensitive data tied to donors, alumni and students, it’s clear that these campuses need stronger defenses and more proactive monitoring. Until that happens, you can expect more headlines like this and more investigations after the damage is already done.

Do you trust universities to protect the personal data you’ve shared with them? Let us know by writing to us at Cyberguy.com

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter. 

Copyright 2025 CyberGuy.com. All rights reserved.

Advertisement

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Technology

Cold Court’s debut EP is an infectious, glitchy genre mashup

Published

on

Cold Court’s debut EP is an infectious, glitchy genre mashup

Cold Court is a brother-sister duo from Philly that seems to love nothing more than shoving all of their influences together in a messy soup that at least superficially resembles the hyperpop you’ve come to expect from acts like 100 Gecs. But, where songs like “Dumbest Girl Alive” goofily wink at pop punk and emo, Cold Court are a bit more self-serious, and that’s not necessarily a bad thing.

The opening track on the band’s debut EP (^_^) / (aka Hands Up), “Nina”, starts off sounding not unlike the dance punk bands that stormed the scene in the mid aughts like Franz Ferdinand or Test Icicles. But that all starts to change about a minute in, when the skuzzy riff gets chopped up and fed through a beat repeater. Another minute later, there’s a mellow proggy bridge that calls to mind Mars Volta. Then the whole thing ends on a barrage of glitches and digital chaos.

The record largely continues in this fashion. The songs on Hands Up clearly started life on drums and guitar. But then Mini and Jojo fed their creations to a computer, added layers, rearranged the pieces, and piled on the effects. Single “Burn” is perhaps the best example of all the parts coming together. It features big rock riffs, Daft Punk-esque synths, dubstep chops, autotuned vocals, and even a rapped bridge. Yet the whole thing feels like a cohesive, seething whole as they shout, “I just want to see it burn, give a fuck about your word.”

They’re not the deepest lyrics, but it works.

While Cold Court is clearly an exercise in maximalism, not every song goes quite as big as “Burn.” “Cola” moves more slowly, strips back some of the layers, but doesn’t turn the volume down. “Glass” almost becomes math rock as its guitars get chopped up and spit back out, and the EP’s closer “Light” is blown-out, sparkly prog.

Advertisement

Over the course of a full album, the relentless barrage might grow exhausting. But at just 21 minutes, Hands Up doesn’t overstay its welcome, and it will be interesting to see how the band evolves as the young duo grow.

Continue Reading

Technology

Bose thinks it can be a media company for some reason

Published

on

Bose thinks it can be a media company for some reason

The history books are littered with the corpses of corporate record labels started by companies that had no business being in the music industry. Bose thinks it can be the exception to the rule. It thinks it can be Red Bull. And, while Bose has more of a right to dip its toes into the media world than Build-a-Bear, there’s little reason to believe it can succeed where so many others have failed.

In an interview with Business Insider, Bose CMO Jim Mollica said the company had created Bose Studios as part of a move away from traditional “campaign-driven marketing.” A big element of that is going to be Bose Records, a new label the company has formed to “help break underappreciated or new artists.” The competition isn’t the big three — Sony, UMG, Warner — it’s independent labels already being squeezed in an era of bedroom producers and self-distribution.

Mollica was transparent about the real goal, though: build a library of music that Bose could feature in its commercials without having to pay the licensing rights for. He said that the company wouldn’t own the artists’ masters or take a share of their streaming or sales revenue, and that they’d be free to sign with other labels. That sounds extremely artist-friendly on its face, which is great. But there’s still a lot we don’t know about the new business venture.

Bose is primarily known for making consumer-grade audio gear that tries to put on airs. Most audiophiles will be quick to tell you that Bose products are overpriced and, at best, merely okay. What the company is undeniably great at is marketing. But selling mediocre Bluetooth speakers at inflated prices is very different from discovering talent and promoting artists. Mollica didn’t mention poaching A&R talent from other labels or any splashy celebrity partnerships to launch. Though he did mention that some “legendary Hollywood names” were attached to films and TV series being commissioned by Bose Studios.

Which brings us to another issue: a lack of focus. Simply launching a record label is hard enough. Why does Bose — again, whose primary experience is in manufacturing audio hardware — think that it can also launch a movie studio, a podcast network, and a live event production company? These are all things that Mollica said are in the works, according to Business Insider.

Advertisement

Sure, you could argue that Bose, as an audio company, has more of a right to dive into the music industry than those failed ventures. But they featured celebrity endorsements, partnerships with bigger labels, or, at the very least, some specific cultural hook. Bose Studios just seems desperate and unfocused.

Continue Reading

Technology

Fake AAA email scam targets drivers

Published

on

Fake AAA email scam targets drivers

NEWYou can now listen to Fox News articles!

A strange email lands in your inbox, and at first, it sounds helpful. It uses a familiar company, leans into family safety and warns that you may need to act before a deadline.

That is what makes this suspicious AAA-themed email we received worth warning you about. It reads like a friendly safety reminder from someone who claims to work in AAA’s member outreach. It isn’t the kind of message most of us would delete right away.

Still, something feels off. Before you click any link or trust the warning, it helps to slow down and look for the signs that this could actually be one big scam.

Sign up for my FREE CyberGuy Report

Advertisement
  • Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
  • For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com trusted by millions who watch CyberGuy on TV daily.
  • Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.

FAKE TRAFFIC VIOLATION TEXT SCAM USES QR CODES TO STEAL PAYMENT INFO

A suspicious AAA-themed email can look harmless at first, especially when it uses a familiar company and a safety warning. (Kurt “CyberGuy” Knutsson)

What this fake AAA email scam is

The email appears to use car safety as bait, then pushes you toward a link that should raise concern.

 

A message built around family safety

The email claims to come from someone named Sloane Garibaldi at AAA. It says the recipient’s household appeared on a member outreach list. Then it asks whether the family is “actually safe” in the car. That wording makes the message feel personal. It also turns a random email into something that sounds urgent.

 

A supposed rule with a deadline

The email says a new federal rule starts on July 1, 2026. It claims every passenger vehicle must carry a certified emergency rescue tool that can cut a seatbelt and break glass. Then it adds a warning about a $200 fine per occurrence. That kind of deadline can make any driver worry. However, the message does not point to a government site or an official AAA page. Instead, it pushes a shared Google link.

 

A fake status check

The email includes a small “compliance check” box. It lists the recipient as a member and says the check has not been completed. That detail makes the message feel like an account notice. It also creates a small task the reader may want to fix. Scammers use that tactic often. They make the action look quick, then hope you click before you question the message.

Advertisement

YOUR EMAIL DIDN’T EXPIRE; IT’S JUST ANOTHER SNEAKY SCAM

The email claims a new car safety rule is coming, but the message pushes the recipient toward a shared link instead of an official AAA website. (Kurt “CyberGuy” Knutsson)

 

Red flags in the fake AAA email

Several clues inside the message suggest this email deserves to be treated as suspicious.

 

1) The real sender address looks suspicious

The display name says Sloane Garibaldi, but the expanded sender address shows pfiz@middlerunred.guru. That domain has no clear connection to AAA. Display names can be faked. The real sender address often tells a very different story.

The sender name looks familiar, but the real email address shown here has no clear connection to AAA. (Kurt “CyberGuy” Knutsson)

Advertisement

 

2) The email does not use official AAA branding

The message uses the AAA name, but it does not include the official AAA logo or the kind of polished branding you would expect from a real member safety notice. That alone does not prove an email is fake. However, it adds to the concern when combined with a strange sender address, a shared link and urgent language. A real company email usually looks consistent with the brand’s website, app and past messages.

 

3) The link goes through a shared URL

The message uses a share. Google link instead of an official AAA website. That should make you pause. Shared links can hide the final destination. They can also lead to fake forms that collect personal details, account information, vehicle data or payment details. A real AAA notice should point to an official AAA domain or tell you to log in through the AAA app.

 

4) The email pushes fear before facts

The message asks whether your family is safe. It mentions a deadline. It warns about fines. Then it says the check only takes 60 seconds. That is a pressure move. The scammer wants clicking to feel easier than checking.

 

5) The rule citation does not match the claim

The email cites NHTSA FMVSS 571.220. That sounds convincing until you check what the rule covers. That federal standard deals with school bus rollover protection. It does not appear to require everyday passenger vehicles to carry an emergency rescue tool. Scammers often use official-sounding language because many people will not look it up.

 

6) The tone feels too casual for a legal warning

The message uses friendly lines like “I promise I’m not being dramatic” and “I’d rather chase you about this twice.” That tone may be meant to lower your guard. It sounds like someone trying to help. Still, a real safety or compliance notice should not arrive from a strange domain with a shared link and casual pressure.

Advertisement

 

7) The fine print repeats the suspicious link

The bottom of the email includes a P.S. that says the link may “wrap oddly” in your mail app. Then it repeats the same shared link so you can click it again. It even adds, “I’ve had people miss it because their inbox cut it in half,” which sounds casual but also gives the sender another excuse to push the link. That may seem helpful, but it keeps steering you toward the same questionable destination. Legitimate companies do not need to explain why a safety link looks strange in your inbox.

The fine print also says the recipient’s email address is tied to a “member household” in an outreach queue for the July 1, 2026, FMVSS §571.220 rollout. That wording sounds official, but it gives no member number, no verified AAA account link and no official AAA contact path. Even the opt-out line deserves caution. Scam emails often include unsubscribe or opt-out links to make the message look legitimate. In this case, “opt out here” could confirm your email address is active or send you to another suspicious page.   

10 WAYS TO PROTECT SENIORS FROM EMAIL SCAMS

The fine print repeats the same questionable link and adds an opt-out line that could be another trap. (Kurt “CyberGuy” Knutsson)

 

AAA says it did not send the email

We reached out to AAA, and the organization confirmed the message did not come from them.

Advertisement

“AAA did not send those emails, and they could potentially be malicious,” an AAA spokesperson told CyberGuy. “We remind members to avoid clicking on suspicious links and contact us directly if they have questions or concerns.”

That confirmation makes the warning even clearer: do not click the link in the email. Go directly to AAA if you have any questions about your membership or a safety notice.

 

Why this fake AAA email could fool drivers

The scam feels believable because it mixes a practical safety concern with a personal tone and an official-sounding reference.

 

Car safety gets attention

Most people want to protect their family on the road. A seatbelt cutter or window breaker can also sound useful in a real emergency. That makes the topic believable. The issue is the email, not necessarily the idea of keeping an emergency tool in your vehicle.

 

Personal details can lower your guard

The email uses the recipient’s actual first and last name. Scammers often use personal details to make messages feel legitimate. A name, city, phone number or family reference can make someone hesitate before deleting an email.

Advertisement

 

Official names add fake credibility

The email mentions NHTSA and a federal motor vehicle safety standard. Those details make the message look researched. However, one official name does not make the claim true. Scammers count on people trusting the reference without checking it.

SSA IMPERSONATION SCAMS ARE GETTING MORE PERSONAL

The fake AAA-themed email uses a familiar name and safety language to make a suspicious message look trustworthy. (Jaap Arriens/NurPhoto)

 

How to stay safe from fake AAA emails

A few quick checks can help you avoid bad links, fake forms and phishing attempts that pretend to come from trusted brands.

 

1) Check the sender address

Do not rely on the display name. Click or tap the sender to see the full address. If the domain does not match the company, treat the message as suspicious.

Advertisement

 

2) Look for missing or sloppy branding

Pay attention to the overall look of the email. Missing logos, odd spacing, plain formatting or generic design can be warning signs. Also, compare the message with past emails from the same company. If the style looks off, do not click.

 

3) Skip links in urgent emails

Avoid clicking links in surprise emails that mention deadlines, penalties or account problems. Instead, open your browser and go directly to the company’s official website. You can also use the company’s app.

 

4) Use strong antivirus software

Strong antivirus software can help block malicious links, phishing pages and dangerous downloads. It can also warn you before you land on a risky site. That extra alert can stop a quick mistake from becoming a bigger problem. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com

 

5) Do not fill out surprise forms

A fake “readiness check” can collect more than you realize. Do not enter your name, address, phone number, vehicle details, payment information or account login through an unexpected email link.

 

6) Verify legal claims on your own

If an email cites a rule, law or government agency, search for it separately. Use official government websites or trusted legal sources. Do not use the link inside the message to verify the message.

Advertisement

 

7) Use a data removal service

Scam emails become more convincing when criminals know personal details about you. Data brokers and people-search sites can expose names, addresses, phone numbers and relatives. A data removal service can help reduce that exposure. It will not remove everything, but it can make you a harder target. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com

 

8) Report and block the sender

Mark the message as phishing or junk. Then block the sender and delete the email. If the message claims to come from AAA, contact AAA through its official website or app to report it.

 

9) Warn someone who may click quickly

This kind of scam can fool anyone. It may be especially risky for older relatives, new drivers or anyone who takes safety notices seriously. A quick warning could help them avoid a bad link and major headaches down the road.

 

Kurt’s key takeaways

This fake AAA email works because it feels personal and practical. It talks about family safety. It uses a deadline. It cites a federal rule. Then it pushes a link that does not belong in a legitimate AAA notice. That is the real lesson here. When an email makes you feel rushed, slow down. Check the sender address. Look at the link. Notice the branding. Verify the claim somewhere else. You may still decide to keep an emergency tool in your car. Just do not buy one, register one or share personal information because a suspicious email told you to act fast.

Should companies and email providers be doing more to stop scam messages like this before they ever hit your inbox? Let us know by writing to us at Cyberguy.com

Advertisement

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report

  • Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
  • For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com trusted by millions who watch CyberGuy on TV daily.
  • Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.

Copyright 2026 CyberGuy.com. All rights reserved. 

Advertisement
Continue Reading
Advertisement

Trending