In January, folk artist Murphy Campbell discovered several songs on her Spotify profile that did not belong there. They were songs that she had recorded, but she’d never uploaded them to Spotify, and something was off about the vocals.
Technology
How 3.5B WhatsApp numbers were scraped and exposed
NEWYou can now listen to Fox News articles!
Most major platforms have dealt with large-scale data leaks tied to weak or unprotected APIs. You’ve seen this play out with Facebook, X and even Dell.
The pattern is always the same. A feature meant to make life easier becomes a gateway for bulk data collection.
WhatsApp is now part of that list after researchers managed to scrape 3.5 billion phone numbers by exploiting a simple gap in the app’s contact-discovery system.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
How the researchers scraped 3.5B WhatsApp numbers
WHATSAPP BANS 6.8M SCAM ACCOUNTS, LAUNCHES SAFETY TOOL
Researchers discovered that weak API limits made it possible to scrape billions of WhatsApp numbers. (Getty Images)
As reported by Bleeping Computer, the entire incident started with WhatsApp’s GetDeviceList API. This is the endpoint the app uses when you add a number to your contacts. It tells WhatsApp to check if that number has an account and what devices are linked to it. The problem was that the API had no meaningful rate limiting. In simple terms, the system didn’t slow down or block repeated requests, which opened the door for mass enumeration.
Researchers from the University of Vienna and SBA Research decided to test how far they could push this. Using only five authenticated sessions and a single university server, they started hammering WhatsApp’s servers with queries. They expected to get blocked fast, but WhatsApp didn’t react at all.
That’s how they were able to check more than 100 million phone numbers per hour. After generating a global pool of 63 billion possible mobile numbers, they ran the list through the API and confirmed 3.5 billion active WhatsApp accounts.
Researchers managed to scrape more than just phone numbers
The researchers didn’t stop at confirming account existence. They used other WhatsApp endpoints like GetUserInfo, GetPrekeys and FetchPicture to pull more details. This included profile photos, “about” text, device information and public keys. A test run in the United States alone downloaded 77 million profile photos without hitting any limits, many with clear images of people’s faces. Public “about” sections often revealed personal info or links to other profiles. When compared to Facebook’s 2021 scrape, they found that 58% of leaked Facebook numbers were still active on WhatsApp years later. That’s what makes phone-number leaks so damaging. They stay useful to attackers long after the initial breach.
RUSSIAN LAWMAKERS CLAIM WHATSAPP IS A NATIONAL SECURITY THREAT, SHOULD PREPARE TO LEAVE THE COUNTRY
It’s important to note that this study was done by researchers who haven’t released the data. They also reported the issue to WhatsApp. The company has since added rate-limiting protections to prevent similar abuse from happening again. Still, the findings show how easily threat actors could have done the same thing if they had found the loophole first.
Why this keeps happening across major platforms
Weak or nonexistent API rate limits have caused several major data leaks in recent years, and WhatsApp isn’t the only example. In 2021, attackers abused Facebook’s “Add Friend” feature by uploading contact lists and checking which numbers matched active accounts. The API lacked proper safeguards, so they scraped 533 million profiles. Meta later confirmed the incident as automated scraping, and the Irish DPC fined the company €265 million.
Twitter had a similar problem when attackers used an API bug to match phone numbers and email addresses to 54 million accounts. Dell also reported that 49 million customer records were scraped after attackers took advantage of an unprotected API endpoint.
All of these cases share the same root cause. APIs that allow account lookups or data queries end up being easy to attack when they don’t limit how often someone can access them. One unchecked feature can turn into a pipeline for mass data collection.
7 steps you can take to keep your WhatsApp data safe
If your phone number ends up in one of these massive scrapes, you can’t pull it back, but you can make sure it’s far less useful to anyone trying to target you. Here are a few steps that help you stay safer.
1) Use two-factor authentication
Turn on 2FA for WhatsApp and every other important account. Even if someone has your number, they can’t break in without that second verification step. It also protects you from SIM-swap attempts since thieves can’t access your accounts with just a password.
A simple automated script pulled phone data at a massive scale without triggering alerts. (eyecrave productions/Getty Images)
2) Use a password manager
A password manager keeps every login unique. If attackers try to pair your scraped number with credential-stuffing attacks, reused passwords won’t give them an easy win. Strong, random passwords shut down a whole category of automated attacks.
Next, see if your email has been exposed in past breaches. Our No. 1 password manager pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials.
Check out the best expert-reviewed password managers of 2025 at Cyberguy.com.
3) Remove your data from public databases
Opt out of data brokers and people-search sites when you can. The less public information attackers can tie to your number, the harder it is for them to craft convincing phishing messages or identity-based scams.
While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.
IS YOUR FRIEND’S PHONE NUMBER COMPROMISED? HERE’S WHAT TO LOOK FOR
Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.
Get a free scan to find out if your personal information is already out on the web: Cyberguy.com.
4) Limit what you share in profile bios
Keep your WhatsApp “about” text minimal. Avoid details like job titles, hometowns, or links to other accounts. Scraped phone numbers often get paired with publicly visible bios to build fuller profiles for scams.
5) Tighten your privacy settings
Adjust who can see your profile photo, last-seen and status. Setting these to “Contacts only” or “Nobody” prevents strangers from pulling more personal info once they have your number. To tighten your privacy settings on WhatsApp on iPhone or Android, follow these steps:
- Open WhatsApp on your phone on your phone.
- Go to Settings: On iPhone, tap the “Settings” gear icon at the bottom right. On Android, tap the three vertical dots in the top-right corner, then select “Settings.”
- Tap “Account.”
- Tap “Privacy.”
- Adjust the privacy options below to control who can see your personal info:
- Last Seen & Online: Tap “Last Seen & Online” and choose “My Contacts” or “Nobody” to restrict who sees your last active status.
- Profile Photo: Tap “Profile Photo” and select “My Contacts” or “Nobody” to prevent strangers from viewing your profile picture.
- About: Tap “About” and pick “My Contacts” or “Nobody” to limit who can see your About info.
- Status: Tap “Status,” then select “My Contacts,” “My Contacts Except…,” or “Only Share With…” to control who can view your status updates.
These changes prevent people not in your contacts or strangers from pulling personal details from your WhatsApp profile, enhancing your privacy effectively on either iPhone or Android devices.
Because the system lacked proper rate-limiting, the scraping continued undetected for months. (Kurt Knutsson)
6) Install strong antivirus software
A lot of phishing and malware campaigns start with scraped numbers. Strong antivirus software can block malicious links, detect harmful downloads and warn you when something looks suspicious.
The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.
Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.
7) Be cautious with unknown calls and messages
Treat unexpected messages with more suspicion. Don’t click links, don’t share OTPs, and don’t respond to anyone asking for verification codes. Once numbers are scraped, scammers ramp up spam and impersonation attempts.
Kurt’s key takeaway
WhatsApp might have fixed the issue, but the bigger problem is still out there. Any platform that exposes an API without proper rate limits is leaving a window open for someone with the right tools and enough time. This scrape shows you how quickly that window can turn into a firehose of personal data. Until API security becomes a priority across the board, you’ll keep seeing leaks like this repeat on bigger and bigger scales.
Do you think apps should be legally required to enforce strict API limits? Let us know by writing to us at Cyberguy.com.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
Copyright 2025 CyberGuy.com. All rights reserved.
Technology
A folk musician became a target for AI fakes and a copyright troll
She quickly surmised that someone had pulled performances of the songs she posted to YouTube, created AI covers, and uploaded them to streaming platforms under her name. I ran one of the songs, “Four Marys”, through two different AI detectors, and it seemed to support her suspicions with both saying it was probably AI-generated.
Campbell was shocked, “I was kind of under the impression that we had a little bit more checks in place before someone could just do that. But, you know, a lesson learned there,” she told The Verge. It took some time before Campbell managed to get the fake songs removed, “I became a pest,” she said. And even then, it wasn’t a complete victory. While the offending tracks don’t appear to be available on YouTube Music or Apple Music anymore, at least one can still be found on Spotify, just under a different artist profile, but with the same name. There are now multiple Murphy Campbells — “Obviously, I was thrilled by that,” the real Murphy Campbell said.
Spotify is testing a new system that would allow artists to manually approve songs before they appear on their profile, but Campbell is skeptical after being burned. “I feel like, every time, an entity that’s that large makes a promise like that to musicians. It seems to just not be what they made it out to be, but I’ll be curious to try it out in the future,” she said.
This was just the beginning of Campbell’s nightmare, however.
On the day that a Rolling Stone article was published, discussing Campbell’s brush with AI imitators, a series of videos were uploaded to YouTube through distributor Vydia. Those videos have not been posted publicly, and it’s unclear if anyone other than the uploader, who goes by Murphy Rider, has seen them. YouTube declined to comment for this story.
Those were used to claim ownership of the material in several of Murphy Campbell’s videos. Campbell received a notice from YouTube reading: “You are now sharing revenues with the copyright owners of the music detected in your video, Darling Corey.” The most confusing part, the songs at the center of these claims are all in the public domain, including the classic “In the Pines,” which dates back to at least the 1870s and has been covered by everyone from Lead Belly to Nirvana (as “Where Did You Sleep Last Night”).
Vydia has since released those claims, and spokesperson Roy LaManna says the person who uploaded the videos has been banned from their platform. Of the over 6,000,000 claims filed by Vydia through YouTube’s Content ID system, 0.02 percent were found to be invalid, which LaManna says is, “by industry standards is like amazing.” Continuing, “we pride ourselves on doing this the right way.”
LaManna also says that Vydia has no connection to Timeless IR or the AI covers that were uploaded to streaming platforms under Campbell’s name. While the timing is certainly suspicious, LaManna says the two incidents are separate.
Vydia has received a lot of blowback including, LaManna says, “literal death threats” which have led to the offices being evacuated. Campbell isn’t about to let Vydia off the hook, but notes that it’s not solely to blame. The worlds of generative AI, music distribution, and copyright are complex with multiple points of failure and opportunities for abuse. “I think it goes way deeper than we think it does,” Campbell says.
Technology
Industrial exoskeletons help workers do more with less strain
NEWYou can now listen to Fox News articles!
If you have ever spent a full day lifting, drilling overhead, or bending over a conveyor belt, you know how quickly fatigue sets in. That is exactly where industrial exoskeletons come in.
These wearable systems strap onto the body and help carry the load. Instead of your muscles doing all the work, the device shares it. As a result, workers feel less strain and can stay productive longer. This tech is already showing up on real job sites across the country.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily. Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
WEARABLE ROBOTICS ARE CHANGING HOW WE WALK AND RUN
A worker uses the Laevo FLEX exoskeleton to support the lower back during repetitive lifting and bending tasks. (Laevo)
What are industrial exoskeletons?
Industrial exoskeletons are wearable mechanical systems designed to support your body during physical tasks. They do not replace workers. They help workers perform demanding jobs with less physical stress. There are three main types, and each works differently depending on the job.
Passive exoskeletons: simple support that works
Passive systems do not use motors or batteries. Instead, they rely on springs or mechanical structures to redistribute weight.
A strong real-world example is the Hilti EXO-O1. This shoulder harness shifts the weight of your arms to your hips using spring-loaded supports. Testing shows it can reduce shoulder muscle load by up to 47% during overhead work. Many workers say tools feel almost weightless by the end of the day.
Another example is the Laevo FLEX. This passive system uses spring-based assistance to support the lower back during bending and lifting. It is designed for dynamic movement, allowing workers to walk freely and lift without needing to switch the system on or off.
Laevo FLEX also offers adjustable support and is built for long wear across different environments, including outdoor use. Like other passive systems, it helps reduce strain on the lower back during repetitive tasks without adding motors or batteries.
These systems are relatively lightweight, typically between about 4.4 and 8.8 pounds. However, support remains constant during use, so it cannot adapt automatically to different tasks in real time.
Passive Hilti EXO-O1 exoskeleton to help relieve strain on shoulders and arms during overhead installation work. (HILTI)
Powered exoskeletons: high-tech strength on demand
Powered exoskeletons use motors, sensors, and onboard processors to actively assist movement. An example is the German Bionic Exia. This battery-powered back exoskeleton is designed for warehouse and logistics work, where employees lift and move items throughout the day. It actively supports the lower back during lifts, helping reduce strain and fatigue over time.
These systems track your motion using sensors and respond almost instantly. Many can detect lifting movements in real time and provide support as you move, so the assistance feels natural instead of delayed.
Powered exoskeletons can significantly reduce the effort required for repetitive lifting tasks, especially in high-volume environments.
However, there are trade-offs. Some powered systems are heavier and can weigh over 40 pounds, depending on the design. They are also far more expensive, often costing tens of thousands of dollars, so most companies introduce them through pilot programs.
NEW EXOSKELETON ADAPTS TO TERRAIN WITH SMART AI POWER
German Bionic’s powered exoskeleton Exia provides real-time support to ease physical strain on the job. (German Bionic)
Soft exosuits: flexible and lightweight
Soft exosuits use fabric, straps and tension systems instead of rigid frames. One example is the HeroWear Apex 2. This lightweight system weighs about three pounds and wraps around the shoulders and waist to assist with lifting movements.
In warehouse testing, soft back-support exosuits have been shown to improve productivity while reducing reported lower back discomfort for workers performing repetitive tasks.
These systems allow more natural movement than rigid exoskeletons. However, they provide less force, so they are best suited for repetitive tasks rather than heavy lifting.
Workers use the HeroWear Apex 2 exosuit to reduce back strain during repetitive lifting and bending tasks. (HeroWear)
Where exoskeletons make the biggest impact
The biggest benefits show up in everyday tasks that put the most strain on your body.
Overhead work becomes manageable
Holding tools above your head all day strains your shoulders and neck. Systems like the Hilti EXO-O1 can reduce muscle load by up to about 47%, making tools feel much lighter.
Heavy lifting gets safer
Back-support systems like the Laevo FLEX shift part of the load away from the spine. Studies show muscle effort can drop by up to 30% during lifting.
Repetitive bending adds up less
Soft systems like the HeroWear Apex 2 help reduce fatigue during constant bending. Workers complete more tasks while feeling less strain by the end of a shift.
The trade-offs you should know
Exoskeletons offer real benefits, but they are not perfect. Fit is critical. If a device does not align properly with your body, it can cause discomfort or limit movement. Proper fitting and training are essential. Weight also matters. Even lightweight systems add extra load. Powered systems can weigh more than 40 pounds.
Cost remains a barrier for many companies. Passive systems may cost a few thousand dollars, while powered systems can cost tens of thousands. There is also a long-term consideration. Relying too heavily on assistance could reduce muscle engagement over time. Experts recommend using exoskeletons alongside proper ergonomics and regular movement.
What this means for you
If your job involves physical labor, this technology could change your daily experience. You may feel less sore at the end of a shift. You may reduce your risk of injury over time. You may even be able to work longer without the same level of fatigue.
For employers, the benefits are clear. Fewer injuries, fewer missed workdays, and more consistent productivity. Adoption is still growing, so many workplaces are testing these systems before rolling them out more broadly.
Where can you buy industrial exoskeletons?
You might be wondering if you can order one of these like any other piece of gear. In most cases, you cannot. Most industrial exoskeletons are sold directly to companies, not individuals. Manufacturers typically work with employers through pilot programs or bulk orders. That means you will not usually find these on standard retail sites.
Some lighter systems, especially passive or soft exosuits, are easier to access. Even then, many brands still prefer to sell through business channels or approved partners.
If you are interested, start with the manufacturer’s website. Look for options like “request a demo” or “contact sales.” This is often the first step before any purchase. For now, access depends on where you work. As adoption grows, that could change. More companies are testing these systems, which may eventually make them easier to get.
Take my quiz: How safe is your online security?
Think your devices and data are truly protected? Take this quick quiz to see where your digital habits stand. From passwords to Wi-Fi settings, you’ll get a personalized breakdown of what you’re doing right and what needs improvement. Take my Quiz here: Cyberguy.com
Kurt’s key takeaways
Industrial exoskeletons are moving quickly from early trials to real-world use. They are not replacing human workers. They are helping people work smarter and safer. As the technology improves, expect lighter designs, better comfort, and more intelligent assistance. This shift could redefine what physically demanding work looks like in the years ahead.
If your employer offered you an exoskeleton tomorrow, would you wear it on the job or would you hesitate? Let us know by writing to us at Cyberguy.com.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com — trusted by millions who watch CyberGuy on TV daily. Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
Anthropic essentially bans OpenClaw from Claude by making subscribers pay extra
Starting tomorrow at 12pm PT, Claude subscriptions will no longer cover usage on third-party tools like OpenClaw.
You can still use these tools with your Claude login via extra usage bundles (now available at a discount), or with a Claude API key.
We’ve been working hard to meet the increase in demand for Claude, and our subscriptions weren’t built for the usage patterns of these third-party tools. Capacity is a resource we manage thoughtfully and we are prioritizing our customers using our products and API.
Subscribers get a one-time credit equal to your monthly plan cost. If you need more, you can now buy discounted usage bundles. To request a full refund, look for a link in your email tomorrow.
We want to be intentional in managing our growth to continue to serve our customers sustainably long-term. This change is a step toward that.
-
South-Carolina7 days agoSouth Carolina vs TCU predictions for Elite Eight game in March Madness
-
Miami, FL1 week agoJannik Sinner’s Girlfriend Laila Hasanovic Stuns in Ab-Revealing Post Amid Miami Open
-
Education1 week agoVideo: Transgender Athletes Barred From Women’s Olympic Events
-
Minneapolis, MN1 week agoBoy who shielded classmate during school shooting receives Medal of Honor
-
Vermont7 days ago
Skier dies after fall at Sugarbush Resort
-
Politics7 days agoTrump’s Ballroom Design Has Barely Been Scrutinized
-
Atlanta, GA6 days agoFetishist ‘No Kings’ protester in mask drags ‘Trump’ and ‘JD Vance’ behind her wheelchair
-
Entertainment3 days agoInside Ye’s first comeback show at SoFi Stadium