New Mexico Attorney General Raúl Torrez won a historic sum of $375 million in a landmark child safety case against Meta earlier this year. But the next stage of the fight could be even more consequential for Meta and the social media industry at large.
Technology
How Android malware lets thieves access your ATM cash
NEWYou can now listen to Fox News articles!
Smartphone banking has made life easier, but it has also opened new opportunities for cybercriminals.
Over the past few years, we have seen Android malware steal passwords, intercept OTPs and even take remote control of phones to drain accounts. Some scams focus on fake banking apps, while others rely on phishing messages that trick you into entering sensitive details.
Security researchers have now discovered a new threat that goes a step further. Instead of simply stealing login information, this malware gives thieves the ability to walk up to an ATM and withdraw your money in real time.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
Android malware like NGate tricks users into downloading fake banking apps that steal sensitive data. (Kurt “CyberGuy” Knutsson)
How the NGate malware works
The Polish Computer Emergency Response Team (CERT Polska) discovered a new Android malware called NGate that uses NFC activity to access a victim’s bank account. This malware monitors contactless payment actions on the victim’s phone and forwards all transaction data, including the PIN, directly to a server controlled by attackers. It does not just copy card details. Instead, it waits until the victim taps to pay or performs a verification step, then captures the fresh, one-time authentication codes that modern Visa and Mastercard chips generate.
To pull this off, attackers need to infect the phone first. They typically send phishing messages claiming there is a security problem with the victim’s bank account. These messages often push people to download a fake banking app from a non-official source. Once the victim installs it, the app walks them through fake verification prompts and requests permissions that allow it to read NFC activity. As soon as the victim taps their phone or enters their PIN, the malware captures everything the ATM needs to validate a withdrawal.
MANAGE ANDROID APPS WITH THE NEW ‘UNINSTALL’ BUTTON
Once installed, the malware captures NFC tap-to-pay codes and PINs the moment the victim uses their phone. (Kurt “CyberGuy” Knutsson)
What attackers do with the stolen data at the ATM
The attackers rely on speed. The one-time codes generated during an NFC transaction are valid for only a short period. As soon as the infected phone captures the data, the information is uploaded to the attacker’s server. An accomplice waits near an ATM, holding a device capable of emulating a contactless card. This could be another phone, a smartwatch or custom NFC hardware.
When the data arrives, the accomplice presents the card-emulating device at the ATM. Since the information contains fresh, valid authentication codes and the correct PIN, the machine treats it like a real card. The ATM authorizes the withdrawal because everything appears to match a legitimate transaction. All of this happens without the criminal ever touching the victim’s physical card. Everything depends on timing, planning and getting the victim to unknowingly complete the transaction on their own phone.
Criminals use the stolen, time-limited codes at an ATM to make real withdrawals without the victim’s card. (Kurt “CyberGuy” Knutsson)
7 steps you can take to stay safe from Android NGate malware
As attacks like NGate become more sophisticated, staying safe comes down to a mix of good digital habits and a few simple tools that protect your phone and your financial data.
1) Download apps only from the Play Store
Most malicious banking apps spread through direct links sent in texts or emails. These links lead to APK files hosted on random servers. When you install apps only from the Play Store, you get Google’s built-in security checks. Play Protect regularly scans apps for malware and removes harmful ones from your device. However, it is important to note that Google Play Protect may not be enough. Historically, it isn’t 100% foolproof at removing all known malware from Android devices. Even if attackers send convincing messages, avoid installing anything from outside the official store. If your bank wants you to update an app, you will always find it on the Play Store.
2) Use strong antivirus software
One careless tap on a fake bank alert can hand criminals everything they need. Strong antivirus software can stop most threats before they cause damage. It scans new downloads, blocks unsafe links and alerts you when an app behaves in ways that could expose your financial data. Many threats like NGate rely on fake banking apps, so having real-time scanning turned on gives you an early warning if something suspicious tries to install itself.
Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.
ATM ‘JACKPOTTING’ CRIME WAVE GROWS AFTER THIEVES WALK AWAY WITH HUNDREDS OF THOUSANDS IN CASH
3) Keep your device and apps updated
Security patches fix vulnerabilities that attackers use to hijack permission settings or read sensitive data. Updates also improve how Android monitors NFC and payment activity. Turn on automatic updates for both the operating system and apps, especially banking and payment apps. A fully updated device closes many of the holes that malware tries to exploit.
4) Use a password manager to avoid phishing traps
Phishing attacks often direct you to fake websites or fake app login pages that look identical to the real thing. A password manager saves your credentials and fills them in only when the website or app is authentic. If it refuses to autofill, it is a clear sign that you are on a fake page. Consider using a password manager to generate and store complex passwords.
Next, see if your email has been exposed in past breaches. Our No. 1 password manager pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials.
Check out the best expert-reviewed password managers of 2025 at Cyberguy.com.
5) Turn on two-factor authentication for all financial services
Two-factor authentication gives you a second layer of protection, even if your password is compromised. App-based authenticators are more secure than SMS codes because they cannot be intercepted as easily. For banking apps, enabling 2FA adds friction for attackers trying to perform unauthorized actions. Combined with strong passwords from a password manager, it significantly reduces the chance of account takeover.
6) Ignore suspicious texts, emails and calls
Attackers rely on urgency to trick you. They often claim that your card is blocked, your account is frozen or a payment needs verification. These messages push you to act fast and install a fake app. Always pause and check your bank’s official channels. Contact the bank through verified customer care numbers or the official app. Never click links or open attachments in unsolicited messages, even if they look legitimate.
7) Review app permissions
Most people install apps and forget about them. Over time, unused apps pile up with unnecessary permissions that increase risk. Open your phone’s permission settings and check what each app can access. If a simple tool asks for access to NFC, messages or accessibility features, uninstall it. Attackers exploit these excessive permissions to monitor your activity or capture data without your knowledge.
Kurt’s key takeaway
Cybercriminals are now combining social engineering with the secure hardware features inside modern payment systems. The malware does not break NFC security. Instead, it tricks you into performing a real transaction and steals the one-time codes at that moment. This makes the attack difficult to spot and even harder to reverse once the withdrawal goes through. The best defense is simple awareness. If a bank ever urges you to download an app from outside the Play Store, treat it as an immediate warning sign. Keeping your phone clean is now as important as keeping your physical card safe.
Have you ever downloaded an app from outside the Play Store? Let us know by writing to us at Cyberguy.com.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
Copyright 2025 CyberGuy.com. All rights reserved.
Technology
Reggie Fils-Aimé says Amazon once asked Nintendo to break the law
“Literally, we stopped selling to Amazon, and it’s because I wasn’t going to do something illegal. I wasn’t going to do something that would put at risk the relationship we have with other retailers. But it also set the stage to say, look, you’re not going to push me around. This is the way we do business. And so that’s how, over time, you build respect.”
Technology
Data broker opt-out steps widows should take in 90 days
NEWYou can now listen to Fox News articles!
Three weeks after her husband’s funeral, Carol’s phone rings. The caller knows her husband’s name, their address and their daughter’s name, even mentioning that she lives across town.
He says he’s calling from a life insurance company and that there’s a policy ready to be paid out. He just needs Carol’s Social Security number and bank routing details to process it.
This scenario draws from real scams reported by fraud investigators and elder abuse advocates across the country. The details change, but the playbook stays the same.
The reason these attacks work so well comes down to something most grieving families never think to check.
HOW SCAMMERS TARGET YOU EVEN WITHOUT SOCIAL MEDIA
Scammers build detailed profiles using obituaries, public records and data broker sites often within days of a loss. (Kurt “CyberGuy” Knutsson)
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
Why scammers target widows and how they find you so fast
Losing a spouse creates a perfect storm for scammers. Grief can leave you overwhelmed, and at the same time, you are handling financial decisions, paperwork and major life changes. That combination makes it easier for someone to catch you off guard.
THE ONE THING SCAMMERS CHECK BEFORE TARGETING YOU ONLINE
Meanwhile, your personal information becomes easier to find. Obituaries often include names, relationships and locations. Death records get filed with the Social Security Administration and added to the Death Master File. Probate filings can reveal property transfers, beneficiaries and account details.
Data brokers collect all of this and turn it into detailed profiles that almost anyone can access. According to research from a data privacy company analyzing five years of FBI Internet Crime Complaint Center data, about 52.5% of crimes reported by Americans over 60 in 2023 were either enabled or worsened by personal data available online. Widows, especially those managing estates alone, sit high on that target list.
Here’s what you should do in the first 90 days
Despite being in a high-risk group, taking these protective steps should keep scammers at bay. I know how overwhelming this time can be, so I recommend asking a trusted family member or friend for assistance setting things up. Though you should always refrain from sharing sensitive details like account numbers and your Social Security number.
THE DATA BROKER OPT-OUT STEPS EVERY RETIREE SHOULD TAKE TODAY
Days 1-30: Limit what enters the system
The first month is when the most damaging data gets published. So your first job is damage control.
1) Be strategic about the obituary
Obituaries are the single most accessible data source scammers use after a death. A traditional obituary lists full names, survivor relationships, hometowns and sometimes even ages. That’s a complete family map, and in the wrong hands, it can be a powerful weapon.
You don’t have to skip the obituary. But consider removing or abbreviating the exact home city (use the region instead), names of minor grandchildren and the surviving spouse’s first and last name combined with their address. “Carol of Cleveland” is safer than “Carol Patterson of 114 Birchwood Lane, Cleveland.”
HOW TO REMOVE YOUR PERSONAL INFO FROM PEOPLE-SEARCH SITES
2) Search your name on people-finder sites
Before you can remove anything, you need to see what’s already there.
Go to Spokeo, Whitepages, BeenVerified and Intelius. Search your name and your spouse’s name. What you find will likely include your address, phone number, email addresses, relatives’ names and property records.
This snapshot is your starting point. Take screenshots. You’ll need them.
10 SIGNS YOUR PERSONAL DATA IS BEING SOLD ONLINE
3) Set up a Google Alert for your name and address
It takes two minutes, and it’s free. Go to google.com/alerts and create alerts for:
- Your full name
- Your spouse’s full name
- Your street address.
If your information gets published anywhere new, you’ll get an email notification. This is your early warning system.
REMOVE YOUR PERSONAL INFO FROM THE WEB — STOP IT FROM COMING BACK
Days 31-60: Start removing and automating what you can’t do manually
People-search sites can expose your address, relatives and contact details, making it easier for scammers to target you. (Kurt “CyberGuy” Knutsson)
By now, your information has had weeks to spread. Manual opt-outs are worth doing, but here’s the reality: there are hundreds of data broker sites. Each one has its own removal process. Many require you to submit ID, wait days for confirmation and then re-submit when your data reappears, because it will.
1) Opt out of people-search sites
Prioritize manual opt-outs from the sites that appear in your Google search results. These carry the most weight because scammers often start with whatever Google surfaces first.
You can find these exposures quickly and easily with Incogni’s free scanner. This tool will scan the web for your personal information and email you a report with a list of results you can start with.
HOW TO HAND OFF DATA PRIVACY RESPONSIBILITIES FOR OLDER ADULTS TO A TRUSTED LOVED ONE
If you’d rather go about it on your own, some of the most common sites include:
- Spokeo: spokeo.com/opt_out/new
- Whitepages: whitepages.com/suppression_requests
- BeenVerified: beenverified.com/opt-out
- Intelius: intelius.com/opt-out.
Each one will ask you to verify your email. Follow through on every confirmation; unconfirmed requests don’t get processed.
Keep in mind that removing your information takes time and persistence. There are hundreds of data broker sites, and many of them re-list your information after it has been removed, especially when new public records become available.
Because of that, some people choose to use automated data removal services that send ongoing opt-out requests on their behalf. These services can help reduce the workload by continuously monitoring and removing listings as they reappear.
No matter which approach you take, consistency matters. Checking your information regularly and following up on removals helps limit what scammers can find.
Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com
2) Update security questions on all financial accounts
This step is urgent, and most people skip it entirely.
Data broker profiles almost always contain the exact answers to your bank’s security questions. Mother’s maiden name. Previous address. City where you were born. Scammers use these to impersonate you and access your accounts.
WHAT HACKERS CAN LEARN ABOUT YOU FROM A DATA BROKER FILE
Call your bank, brokerage and insurance companies. Ask to update your knowledge-based authentication questions. Use answers that are completely made up, something only you know and store them in a password manager. Don’t use any answer that appears anywhere in a data broker profile.
Days 61-90: Lock down the perimeter
By now, the most urgent exposure has been addressed. These final steps close the remaining gaps and protect you in the long term.
1) Place a credit freeze on your account and your spouse’s
A credit freeze prevents new credit accounts from being opened in your name. It’s free at all three major bureaus: Equifax, Experian and TransUnion.
HOW TO SAFEGUARD YOUR CREDIT SCORE IN RETIREMENT AS FRAUD AND IDENTITY THEFT RISE AMONG SENIORS
Critically: freeze your spouse’s credit too. After a death, identity thieves frequently open new accounts in the deceased person’s name before the credit bureaus are updated. This is called ghosting, and it can haunt an estate for years.
To freeze a deceased spouse’s credit, contact each bureau individually and provide the death certificate. It’s a few phone calls. It’s worth every minute.
2) Request removal from the Social Security Death Master File
Families can submit a request to limit access to a deceased person’s Social Security data in certain contexts. Visit ssa.gov for current guidance. This won’t scrub the record entirely, but limiting access to the Death Master File reduces the pool of parties who can use it to enrich your data broker profile.
3) Review all joint account access and update beneficiary information
This isn’t directly a data privacy step, but it protects you from a related threat. Scammers who know about an estate sometimes pose as financial advisors, attorneys or government representatives to intercept beneficiary changes. Confirm all account changes directly through institutions you contact yourself, never through a number someone else gives you.
4) Set up simple safeguards to stop scams early
By this stage, your data is more controlled. Now the focus shifts to stopping scams before they escalate. Start by setting clear expectations with your family. Let them know you will never ask for money through an unexpected call, text or email. Creating a simple code word or check-in rule can stop panic-driven decisions, which is exactly what scammers rely on.
Next, slow down any urgent financial request. Scammers create pressure to force quick action. If someone claims there is a payout, problem or deadline, pause and verify it using a phone number or website you trust, not one they provide. It also helps to keep a short list of your financial institutions and their official contact details in one place. That way, you always know how to reach them directly without relying on incoming calls or messages.
Taking simple steps early, like removing your data and freezing your credit, can reduce your risk during the most vulnerable time. (Kurt “CyberGuy” Knutsson)
INSIDE A SCAMMER’S DAY AND HOW THEY TARGET YOU
Finally, be cautious in real-time conversations. Scammers often build trust by collecting small details over multiple interactions. Keeping answers brief and avoiding unnecessary personal details makes it that much harder.
Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting CyberGuy.com
Get a free scan to find out if your personal information is already out on the web: CyberGuy.com
Kurt’s key takeaways
The first few months after losing a spouse bring enough decisions without adding fraud risks on top. Yet that is when your personal information spreads the fastest. Public records and data broker sites can quietly build a profile that scammers use against you. Early action makes a real difference. Limiting what gets published, removing existing data and securing your accounts all reduce your exposure. Even small steps, like updating security questions or freezing credit, can stop a scam before it starts. You do not need to handle everything at once. Start with a simple search of your name and review what appears. From there, take control at your own pace and protect what matters most.
If someone can piece together your personal life within days of a loss, how much of your information are you comfortable leaving online? Let us know by writing to us at CyberGuy.comCyberguy.com
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
Meta’s historic loss in court could cost a lot more than $375 million
Beginning Monday, attorneys for Meta and New Mexico will return to a Santa Fe courthouse for a three-week public nuisance trial, where they’ll argue over the changes the AG wants the judge to order Meta make to Facebook, Instagram, and WhatsApp. Those changes include adding age verification for New Mexico users, prohibiting end-to-end encryption for users under 18 and capping their use to 90 hours per month, limiting engagement-boosting features like infinite scroll and autoplay, and requiring Meta to detect 99 percent of new child sexual abuse material (CSAM).
“From the outset, our goal was to try and change the way the company’s doing business,” Torrez told The Verge on a recent visit to Washington, DC, to advocate for new kids safety legislation. “I recognize that even at $375 million for a company this big and this profitable, it’s not enough in and of itself to change the way they’re doing business. In fact, there’s probably some folks in that company who think of it as the cost of doing business.”
“Even at $375 million for a company this big and this profitable, it’s not enough in and of itself to change the way they’re doing business”
While any changes ordered by the judge would only apply to Meta and its operations in New Mexico, the company could apply the changes in other states for the sake of simplicity. Or, as it’s threatened to do, it could simply go dark in the state. A court order could send a message to other tech companies that courts may be willing to alter their businesses if they’re found liable.
During the trial, New Mexico will argue Meta has become a public nuisance by creating a public health hazard in the state. The AG’s office expects to call on about 15 witnesses, including experts who will testify to the feasibility of their proposed remedies, and fact witnesses who will testify about Meta’s alleged harms. After Meta makes its defense, Judge Bryan Biedscheid will evaluate which proposals are relevant and feasible — a process that could take some time, compared to the speedy turnaround of the jury verdict in March.
A sweeping win for New Mexico could energize Torrez and thousands of other plaintiffs currently pursuing cases against tech companies. Conversely, a limited order could be a significant blow. The outcome won’t directly impact other cases, but it will almost certainly color negotiations over potential settlements.
Several of Torrez’s requests are hot-button tech policy issues. Age verification would almost certainly require Meta or a third-party provider to collect more personal information on adults and minors alike, which privacy advocates have consistently warned can make users less safe. Don McGowan, who previously served on the board of the National Center for Missing and Exploited Children (NCMEC), said that barring encrypted communications on platforms like Facebook “is a great way to make sure that nobody uses Facebook Messenger anymore and just moves their activity to other platforms that aren’t touched by this lawsuit.”
The mandate may do little to change the reality of certain parts of the business — Meta recently announced it was getting rid of end-to-end encrypted messaging on Instagram that it said “very few people” actually used.
Peter Chapman, associate director of the Knight-Georgetown Institute, which works to connect policymakers and others with independent tech policy research, said there could be “significant tradeoffs” to a prohibition on encryption, and other changes may be more effective. For example, evidence presented by the state showed that Meta’s own profile recommendations were connecting adults and minors, a feature that poses a clearer danger of harm without much benefit, and which Torrez is also asking the court to stop. “There’s an opportunity to intervene at that level and try to prevent more of these harmful interactions from taking place without having to tackle encryption,” said Chapman.
No single feature change is likely to solve the entire child and teen safety problem, said Chapman, which is why it’s notable that Torrez plans to ask for several layers of changes. Still, the overall effectiveness of any given remedy will also depend on how it’s implemented and monitored. For instance, what would be the methodology Meta uses to report a 99 percent detection rate of new CSAM? How does it count or surmise what it hasn’t caught? The same goes for the accuracy and reliability of any mandated age verification.
Meta points to this potential issue in its argument against Torrez’s proposed remedies. “Regardless of where the accuracy threshold is set, Meta would never be able to prove that the system met that standard, because doing the calculation would require that Meta detect 100% of CSAM to use as the denominator,” the company wrote in a legal filing. Torrez’s chief deputy, James Grayson, said on a press call that the court and an appointed independent monitor would have some discretion over tracking; the office hasn’t yet identified who this monitor would be.
“The demands that are being made in New Mexico are ill-informed and provide massive additional exposure for other kinds of exploitation”
Meta and other groups that oppose the AG’s approach say the outcomes he’s seeking are counterproductive. “The demands that are being made in New Mexico are ill-informed and provide massive additional exposure for other kinds of exploitation,” said Maureen Flatley, president of Stop Child Predators, a group that advocates for more funding for enforcement of criminal laws against child predators, and has received funding from Meta-backed trade group NetChoice. “This notion that the platforms have to be responsible for pushing all these people out would be like saying to the US Bankers Association, ‘By the way, you are responsible for all the bank robberies from now on,’ which is ludicrous.”
“The New Mexico Attorney General’s focus on a single platform is a misguided strategy that ignores the hundreds of other apps teens use daily,” Meta spokesperson Chris Sgro said in a statement. “The state’s proposed mandates infringe on parental rights and stifle free expression for all New Mexicans. Regardless, we remain committed to providing safe, age-appropriate experiences and have already launched many of the protections the state seeks, including 13 safety measures this past year.”
But Torrez has taken aim at the broader tech industry, too. He recently visited Washington, DC, to advocate for new protections for kids online and an overhaul of Section 230, the law that protects tech platforms from being held liable for their users’ posts. “While we were able to prevail in our district court in Santa Fe, I still think the law as it currently exists creates a lot of ambiguity,” he told The Verge on that visit. “If Section 230 were not something that these companies could hide behind, then it increases the chances that they’re going to have to actually make their case to a jury.”
But Chapman said regulation through lawsuits isn’t an “uncommon sort of story” in the US. “Whether that’s tobacco, opioids, e-cigarettes, there is precedent for legal action moving a broader policy conversation.”
-
Louisiana5 minutes agoLouisiana baseball claims doubleheader sweep over GSU
-
Maine11 minutes agoUSM awards degrees to MaineHealth Maine Track medical school graduates
-
Maryland17 minutes agoMaryland Gov. Wes Moore’s Army records show training delays, gaps
-
Michigan23 minutes agoDiesel fuel posts record high in Michigan on Sunday
-
Massachusetts29 minutes agoWhy backyard beekeeping in Massachusetts is so important
-
Minnesota35 minutes agoSpeculation Swirls Around Vikings Sale, but Evidence Falls Short
-
Mississippi41 minutes agoWhy Texas Longhorns Are Facing Must-Win Game vs. Mississippi State
-
Montana53 minutes agoMontana’s Underrated Beach State Park Has Sandy Shorelines, Swimming, And Birding – Islands