Connect with us

Technology

Spot fake online stores, avoid Facebook subscription scams

Published

on

Spot fake online stores, avoid Facebook subscription scams

NEWYou can now listen to Fox News articles!

Given the number of phishing scams we have all faced over the past decade, most of us have developed a basic skill to spot and avoid obvious phishing emails or SMS messages. Cybercriminals are aware of this, and they have evolved their tactics by shifting to more complex and convincing schemes designed to bypass skepticism and lure victims.

Their goal remains the same: to trick you into handing over sensitive information, especially credit card data. One of the latest examples is the rise in subscription scam campaigns. Scammers are creating incredibly convincing websites selling everything from shoes and clothes to electronics, tricking people into signing up for monthly subscriptions and willingly providing their credit card information. Facebook is being used as the primary platform to promote these new and sophisticated scams.

Join the FREE “CyberGuy Report”: Get my expert tech tips, critical security alerts and exclusive deals, plus instant access to my free “Ultimate Scam Survival Guide” when you sign up!

A woman shopping online (Kurt “CyberGuy” Knutsson)

Advertisement

What you need to know

Bitdefender researchers have uncovered a massive and highly coordinated subscription scam campaign involving more than 200 active websites designed to look like real online stores. These sites, often promoted through Facebook ads, sell everything from clothes and electronics to beauty products, but the real goal is to trick users into signing up for recurring payments, often without realizing it.

One of the most common lures is the “mystery box” scam, where you are promised a surprise package at a bargain price. These offers are made to look fun and harmless, but behind the scenes you are giving away personal and credit card information while unknowingly agreeing to hidden subscription terms, often written in tiny fine print.

The scam doesn’t stop there. Once you’re convinced and reach the checkout page, scammers often layer in a second scam, like loyalty cards or VIP memberships that further lock you into payments. It’s all designed to confuse you, overwhelm you with supposed perks and make the scam feel like a good deal.

Researchers found that many of these websites share a single Cyprus address, possibly tied to offshore entities linked to the Paradise Papers. Despite being spread across different categories and brand names, the sites often use the same layouts, AI agents and payment structures, all pointing to a centralized fraud network.

Scammers frequently rotate the brands they impersonate and have started moving beyond mystery boxes, now peddling low-quality products, counterfeit goods, fake investment schemes, dubious supplements and more. To avoid automatic detection, they employ several tactics. These include running multiple versions of an ad, with only one of which is actually malicious while the others display harmless product images, uploading ad images from platforms like Google Drive so they can be swapped out later and cropping visuals to alter recognizable patterns.

Advertisement

Listing fake products (Bitdefender) (Kurt “CyberGuy” Knutsson)

DOUBLECLICKJACKING HACK TURNS DOUBLE-CLICKS INTO ACCOUNT TAKEOVERS

The scam is expanding

What started with simple “mystery box” scams has grown into a sprawling, coordinated campaign. These scams now feature fake surveys, tiered “VIP” memberships and deceptive credit systems that make the purchase process intentionally confusing. Users are promised deep discounts or access to exclusive deals, but in reality they’re just being locked into recurring payments.

Many of the scam websites trace back to the same physical address in Cyprus, pointing to what appears to be a centralized operation. Researchers also found links to entities mentioned in the Paradise Papers, suggesting these fraudsters are hiding behind offshore infrastructure.

And it’s not just mystery boxes anymore. The same scam format is being used to sell low-quality goods, fake supplements and even bogus investment opportunities. With high-quality site design, aggressive advertising and increasingly sophisticated tactics, subscription scams are becoming the new face of online fraud.

Advertisement

A person shopping online (Kurt “CyberGuy” Knutsson)

RELENTLESS HACKERS ABANDON WINDOWS TO TARGET YOUR APPLE ID

10 proactive measures to take to protect your data

Even as scammers become more sophisticated, there are practical steps you can take right now to protect your personal and financial information from subscription fraud and other online threats. Here are ten proactive measures to help keep your data safe:

1) Always read the fine print: One of the simplest yet most effective ways to protect yourself from subscription scams is to slow down and read the fine print, especially on checkout pages. Scammers often hide recurring payment terms in small or lightly colored text that’s easy to miss. What seems like a one-time purchase could actually sign you up for a biweekly or monthly charge. Taking just a moment to scan for hidden terms before hitting “Pay” can help you avoid weeks of silent billing.

2) Avoid mystery box or VIP-style deals: These offers often prey on curiosity and the promise of surprise or luxury for a low fee. In reality, the “mystery” is the trap: you might receive nothing or a low-quality item while being unknowingly enrolled in a recurring subscription. Scammers use the illusion of exclusivity or urgency to pressure quick decisions.

Advertisement

3) Don’t trust ads blindly on social media: Facebook, Instagram and other platforms are a hotbed for these scams, with criminals running paid ads that mimic well-known brands or influencers. These ads often link to professional-looking but fake storefronts. If you’re interested in a deal you see online, don’t click through immediately. Instead, look up the brand or offer in a separate tab and check if it exists outside social media.

4) Investigate before you buy: Before purchasing from any unfamiliar site, take a few quick steps to verify its legitimacy. Search the brand’s name alongside words like “scam” or “reviews” to see what others have experienced. Look up the company’s physical address and check if it actually exists using tools like Google Maps. Make sure the website uses HTTPS, review the site’s contact information and cross-check reviews on trusted third-party sites like the Better Business Bureau or Consumer Reports.

5) Use strong antivirus software: Adding a strong antivirus program to your devices can provide an extra layer of defense against fraudulent websites and phishing attempts. Strong antivirus software warns you about suspicious links, blocks malicious ads and scans downloads for malware. Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices.

6) Invest in personal data removal services: Scammers often rely on leaked or publicly available personal information to target victims with convincing subscription scams. Investing in a personal data removal service can help minimize your digital footprint by removing your information from data broker databases and reducing the chances of being targeted in future campaigns. Regularly monitoring and cleaning up your online presence makes it harder for fraudsters to exploit your data for financial gain. Check out my top picks for data removal services here.

Get a free scan to find out if your personal information is already out on the web.

Advertisement

7) Be cautious with payment methods: Use secure payment options like credit cards, which often offer better fraud protection than wire transfers, gift cards or cryptocurrency.

8) Limit personal information shared on social media: Scammers often gather details from public profiles to craft convincing scams. Review your privacy settings and only share necessary information.

9) Use strong, unique passwords and enable multifactor authentication: Create strong, unique passwords for each of your online accounts, especially those tied to your finances or shopping. Enable multifactor authentication wherever possible, as this adds an extra layer of security and makes it harder for scammers to access your accounts, even if your password is compromised. Also, consider using a password manager to generate and store complex passwords. Get more details about my best expert-reviewed password managers of 2025 here.

10) Keep your devices and software updated: Regularly update your operating system, browsers and apps. Security updates often patch vulnerabilities that scammers exploit to gain access to your information or install malicious software.

MALWARE EXPOSES 3.9 BILLION PASSWORDS IN HUGE CYBERSECURITY THREAT

Advertisement

Kurt’s key takeaway

While the rise of subscription scams and deceptive ads is concerning, it’s especially troubling that platforms like Facebook continue to allow these fraudulent ads to run unchecked. Facebook has repeatedly failed to adequately vet or prevent these malicious campaigns from reaching vulnerable individuals. The platform’s ad approval system should be more proactive in spotting and blocking ads promoting scams, particularly those that impersonate well-known brands or content creators. 

How do you feel about Facebook’s role in allowing scam ads to circulate? Let us know by writing us at Cyberguy.com/Contact.

For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter.

Ask Kurt a question or let us know what stories you’d like us to cover.

Follow Kurt on his social channels:

Advertisement

Answers to the most-asked CyberGuy questions:

New from Kurt:

Copyright 2025 CyberGuy.com. All rights reserved.

Technology

A second US Sphere could come to Maryland

Published

on

A second US Sphere could come to Maryland

The second US sphere would be built in an area known as National Harbor in Prince George’s County, Maryland. Located along the Potomac River, National Harbor currently features a convention center, multiple hotels, restaurants, and shops. While Abu Dhabi plans to build a sphere as large as the one in Las Vegas, the National Harbor venue would be one of the first mini-Sphere venues announced last March.

Its capacity would be limited to 6,000 seats instead of over 17,000. But the smaller Sphere would still be hard to miss with an exterior LED exosphere for showcasing the “artistic and branded content” that helped make the original sphere a unique part of the Las Vegas skyline.

The inside of the mini-Sphere will feature a high-resolution 16,000 by 16,000 pixel wrap-around screen, the company’s immersive sound technology, haptic seating, and “4D environmental effects.” For the AI-enhanced version of The Wizard of Oz currently playing in Las Vegas, audiences experience effects like wind, fog, smells, and apples falling from the ceiling.

The mini-Sphere will potentially also be cheaper to build than the $2.3 billion original, but its construction is contingent on the “receipt of certain governmental incentives and approvals from Prince George’s County and the State of Maryland.” Sphere Entertainment says the project “would utilize a combination of public and private funding, including approximately $200 million in state, local, and private incentives,” but would potentially generate millions of dollars in revenue for the country and state while supporting over 4,700 jobs once it opens.

Continue Reading

Technology

Apple warns millions of iPhones are exposed to attack

Published

on

Apple warns millions of iPhones are exposed to attack

NEWYou can now listen to Fox News articles!

The Apple iPhone is the most popular smartphone in the United States and one of the most widely used devices in the world. An estimated 1.6 billion people rely on iPhones every day. That massive user base also makes the platform a prime target. 

Over the past few weeks, Apple has been sending out warnings about a serious security flaw. New data suggests the risk could affect roughly half of all iPhone users.

That puts hundreds of millions of devices in potential danger right now.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

Advertisement

WHATSAPP WEB MALWARE SPREADS BANKING TROJAN AUTOMATICALLY

Apple is warning iPhone users about a serious Safari security flaw that could leave hundreds of millions of devices vulnerable if updates are delayed. (Thomas Trutschel/Photothek via Getty Images)

What Apple discovered in Safari and WebKit

Late last month, Apple confirmed two critical vulnerabilities in WebKit. WebKit powers Safari and every browser that runs on iOS. According to Apple, the flaws were used in an extremely sophisticated attack that targeted specific individuals. The problem allowed malicious websites to trick iPhones and iPads into running harmful code. Once that happens, attackers could gain control of the device, steal passwords or access payment information. In simple terms, visiting the wrong website could have been enough.

Why millions of iPhones are still exposed

Apple moved quickly to release a fix. The patch is included in the latest software update. The problem is that many people have not installed it yet. Estimates suggest that about 50 percent of eligible users have not upgraded from iOS 18 to iOS 26. That would leave around 800 million devices vulnerable worldwide. Data from StatCounter paints an even worse picture. It estimates that only 20 percent of users have updated so far. Once security details become public, the risk grows fast. Attackers know exactly what to exploit.

iPhone and iPad models at the highest risk

Apple says the following devices are affected if they are not updated:

Advertisement
  • iPhone 11 and later
  • iPad Pro 12.9-inch 3rd generation and later
  • iPad Pro 11-inch 1st generation and later
  • iPad Air 3rd generation and later
  • iPad 8th generation and later
  • iPad mini 5th generation and later

If your device appears on this list and you have not updated it, it is vulnerable.

INSTAGRAM PASSWORD RESET SURGE: PROTECT YOUR ACCOUNT

New data suggests nearly half of all iPhone users worldwide may still be exposed to a critical WebKit exploit Apple says was actively used in attacks. (Jakub Porzycki/NurPhoto via Getty Images)

Why upgrading is the only real protection

There is no setting to flip and no safe browsing habit that fixes this issue. The vulnerability lives deep inside the browser engine. Security experts say there is no workaround or user behavior that meaningfully reduces the risk. Installing the latest software is the only effective defense. Apple is no longer offering a security-only update for users who want to stay on iOS 18. Unless your device cannot run iOS 26, the fix is only available through iOS 26.2 and iPadOS 26.2.

Steps to update your iPhone or iPad now

Updating is quick and usually painless. If automatic updates are enabled, the fix may already be installed.

If not, follow these steps:

Advertisement
  • Open the Settings app on iPhone
  • Tap General
  • Select Software Update
  • Download and install iOS 26.2 or iPadOS 26.2 or later 

Make sure your device is connected to Wi-Fi and has enough battery life or is plugged in.

Pro tip: Use strong antivirus software

Keeping your iPhone updated is critical, but it should not be your only line of defense. Strong antivirus software adds another layer of protection by scanning malicious links, blocking risky websites and alerting you to suspicious activity before damage is done.

This matters even more when attacks rely on compromised websites or hidden browser exploits. Security software can help catch threats that slip through and give you extra visibility into what is happening on your device.

Think of it as backup protection. Software updates close known holes, while strong antivirus tools help guard against the next one.

Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.

 FAKE ERROR POPUPS ARE SPREADING MALWARE FAST

Advertisement

Apple says malicious websites could exploit a Safari flaw to steal passwords or payment information from unpatched iPhones and iPads. (David Paul Morris/Bloomberg via Getty Images)

Kurt’s key takeaways

Apple rarely uses language like “extremely sophisticated” unless the threat is serious. This flaw shows how even trusted browsers can become attack paths when updates are delayed. Waiting weeks or months to update now carries real consequences. If you use your iPhone for banking, shopping or work, this update should be treated as urgent.

How long do you usually wait before installing major iPhone updates, and is that delay worth the risk anymore? Let us know by writing to us at Cyberguy.com.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

Advertisement

Copyright 2026 CyberGuy.com.  All rights reserved.

Continue Reading

Technology

You need to listen to the cosmic horror-comedy podcast Welcome to Night Vale

Published

on

You need to listen to the cosmic horror-comedy podcast Welcome to Night Vale

It’s relatively rare for a podcast to last 14 years, especially a fiction one. In fact, as far as I can tell, Welcome to Night Vale is the longest continually running fiction podcast out there. (Some will argue it’s actually We’re Alive, but that has taken a few significant breaks between seasons.) The story of Night Vale, the titular desert town, now spans 12 seasons, over 280 episodes, three books, and at least 10 live standalone shows. While dedicating several hundred hours of your life to listening to every episode might seem like a big ask, I believe you’ll be hooked once you dive in.

The show is written by Joseph Fink and Jeffrey Cranor, who draw heavily on the work of H.P. Lovecraft. Every season has its own arc, but broadly, the show tells the story of a town that exists in an alternate version of Earth. In this town Angels are real, but acknowledging their existence is illegal; librarians are dangerous creatures with “thousands of spiny legs” and “pincers”; and there is a Faceless Old Woman who secretly lives in your home.

These are clearly unsettling concepts when taken at face value. But rather than trying to scare the listener, Cranor and Fink lean into the natural absurdity of cosmic horror and refuse to take themselves too seriously. They also routinely subvert the bigotry of their inspiration, using Lovecraftian creations to tell stories rich with LGBTQ+ characters.

Of course, having well-written scripts and telling a compelling story is only part of the equation. What elevates Welcome to Night Vale to true greatness is the cast, especially narrator Cecil Baldwin, who plays the host of the central radio show, Cecil Palmer. Cecil’s voice has the gravitas to tell ominous stories of secretive government agencies and ancient gods. But he has the range to deliver light-hearted banter with a sentient patch of haze (her name is Deb, in case you were wondering).

Cecil Baldwin has the charisma to make even the reading of a repair manual for a toaster compelling. He can be creepy, funny, or soothing, often all within the same episode. (For this reason, I don’t suggest listening to Night Vale at night. I have fallen asleep to the dulcet sounds of Baldwin’s voice several times, only for the more unsettling parts of the show to make their way into my dreams.)

Advertisement

Every episode also features a musical interlude in the guise of “The Weather.” The show mostly features lesser-known artists, but alumni include Jason Isbell, The Mountain Goats, Waxahatchee, Angel Olsen, Open Mike Eagle, and Sylvan Esso.

Welcome to Night Vale is also a great way to introduce younger listeners to horror. I would never suggest my eight-year-old read H.P. Lovecraft. Partly because the man’s unrepentant racism is baked into the very fabric of his stories, but also because the violence is often too much for children. Night Vale, on the other hand, takes those horrors and exposes them for what they are: entertainment. I can put the podcast on, bond with my kid over their burgeoning love of all things creepy and weird, and trust that they’ll walk away with a good message.

Welcome to Night Vale is available on most podcast platforms, including Apple Podcasts, Pocketcasts, YouTube, and Spotify.

Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.

Continue Reading
Advertisement

Trending