Technology
Top 7 tips for sending sensitive documents online
Gone are the days of mailing physical files or delivering them by hand to ensure the safe and secure delivery of sensitive files. While there is no guarantee or foolproof method of sharing files online, below are some of the best tips for how to share sensitive files as safely as possible.
GET SECURITY ALERTS, EXPERT TIPS – SIGN UP FOR KURT’S NEWSLETTER – THE CYBERGUY REPORT HERE
A man handing a folder to a co-worker (Kurt “CyberGuy” Knutsson)
Top 7 tips for safely sending sensitive files online
1) Restrict access to files
Red skull and bones next to protected file on a computer screen (Kurt “CyberGuy” Knutsson)
When transmitting sensitive files online, think of them as confidential documents that require stringent security protocols. Most file-sharing services offer robust access control settings, which are crucial for protecting your data. By default, shared links may allow anyone to access the file, posing a significant risk if the link is inadvertently shared with unauthorized individuals. To mitigate this, proactively adjust the settings to:
Limit access to specific individuals: Assign access rights exclusively to designated email addresses or registered users on the platform. This ensures that only verified individuals can view, edit or provide feedback on your files.
Use advanced permissions: Customize user permissions with granular control, determining who can download, edit or merely view the files. This prevents unauthorized alterations and distribution.
Enable link expiration: Set shared links to expire after a certain period or after the intended use, reducing the window of opportunity for unauthorized access.
Track file activity: Use the platform’s tracking features to monitor who accesses the files and when, providing an audit trail for security purposes.
By implementing these measures, you create a digital equivalent of a secure, locked filing cabinet, ensuring that your sensitive files remain confidential and only in the hands of those who are meant to see them.
HOW TO REMOVE YOUR PRIVATE DATA FROM THE INTERNET
2) Regularly update your software
If your system isn’t safe and protected, your files cannot stay safe and protected. By regularly updating your operating system’s software and the applications you use, you are less likely to be exposed to certain vulnerabilities. This practice is not just a recommendation; it’s a critical component of a robust cybersecurity strategy.
Software updates do more than introduce new features; they are often released to patch security holes and fix vulnerabilities that have been discovered since the last version. Cybercriminals constantly scan for systems with outdated software to exploit these weaknesses. By staying current with updates, you close these openings and make it significantly harder for attackers to gain unauthorized access to your system. Running outdated software is akin to leaving the door to your digital house unlocked. It invites a host of potential risks, including:
Malware infections: Outdated applications can become the perfect hosts for malicious software, which can spread across your network, corrupting files and stealing sensitive information.
Data breaches: Unpatched vulnerabilities can serve as entry points for data breaches, leading to the exposure of confidential data such as personal details, financial information and intellectual property.
3) Password-protect files
Username and password screen (Kurt “CyberGuy” Knutsson)
SUBSCRIBE TO KURT’S YOUTUBE CHANNEL FOR QUICK VIDEO TIPS ON HOW TO WORK ALL OF YOUR TECH DEVICES
When you can, password-protect any of the files you share online. It is an extra layer of protection that must be bypassed to access your file. Password protection requires anyone who has access to the recipient’s device to know the password to access your file, too. Consider using a password manager to generate and store complex passwords.
HOW YOUR PASSWORDS CAN BE STOLEN BY AI LISTENING TO YOUR KEYSTROKES
4) Opt for trusted file-sharing services
When it comes to transmitting sensitive data online, the integrity of your file-sharing service is paramount. Opting for established and trustworthy platforms can significantly mitigate the risk of unauthorized access or data breaches. Here are some of the most renowned and secure file-sharing services that have earned their reputation for reliability:
Microsoft OneDrive: Integrated seamlessly with Windows and Office 365, OneDrive provides a secure and efficient way to store and share files, with advanced features like Personal Vault for an extra layer of protection.
Dropbox: A pioneer in cloud storage, Dropbox has evolved to offer high-level security features, including two-factor authentication and file encryption, making it a solid choice for sensitive information.
Amazon Cloud Drive: With the backing of a tech giant, Amazon Cloud Drive delivers a secure and reliable platform for file storage and sharing, complete with comprehensive controls to manage access and permissions.
Google Drive: Renowned for its user-friendly interface, Google Drive offers robust sharing options and powerful collaboration tools, all while ensuring your data is protected with industry-leading security measures.
Each of these platforms offers unique features and security protocols. It’s essential to evaluate their offerings in relation to your specific needs. For instance, if collaboration is a key aspect of your workflow, Google Drive or Microsoft OneDrive might be more suitable due to their integration with productivity suites. On the other hand, if you’re looking for straightforward file storage with easy retrieval, Dropbox and Amazon Cloud Drive are excellent choices.
For a deeper dive into the capabilities and security features of these platforms, consider checking out “Best ways to save and restore documents,” which provides valuable insights into optimizing your file management practices while maintaining the highest security standards.
5) Install and use strong antivirus software
Before uploading or downloading any files you are sending or receiving, use your antivirus program to scan them for malware. There’s no point in securely sending or receiving corrupt files. If you don’t have one, you should, as it is also the best way to protect yourself from clicking malicious links that install malware that may access your private information. We recommend having strong antivirus protection installed on all your devices. This can also alert you of any phishing emails or ransomware scams. Get my picks for the best 2024 antivirus protection winners for your Windows, Mac, Android and iOS devices.
6) Encrypt your files
A person typing on a laptop with the words “Your personal files are encrypted” (Kurt “CyberGuy” Knutsson)
Even though emails seem almost instantaneous, the files you email can still be intercepted while traveling between you and your intended recipients. If cybercriminals intercept a file, but it is encrypted, then regardless of that breach, the file will be unreadable and useless to them. By encrypting your files, you create a formidable barrier that preserves the confidentiality and integrity of your data, ensuring that only the intended eyes can decipher the message within.
BEWARE OF ENCRYPTED PDFs AS LATEST TRICK TO DELIVER MALWARE TO YOU
7) Enable 2-factor authentication
In today’s digital world, protecting sensitive files during online transmission is crucial, and one of the most effective security measures available is two-factor authentication (2FA). This advanced security protocol requires two proofs of identity, significantly enhancing the protection of your digital assets. When you enable 2FA, you’ll first enter your username and password followed by a second form of identification, such as a code sent to your mobile device, a fingerprint or facial recognition.
The importance of 2FA cannot be overstated; it not only reduces the risk of password theft but also offers a variety of verification methods to suit your preferences, along with immediate security alerts for any unauthorized access attempts. To implement 2FA, always check the security settings of your platforms and enable it wherever possible.
For a more secure experience, consider using authenticator apps, which generate time-sensitive codes. It’s also wise to have backup codes or a secondary authentication device in case your primary 2FA method is unavailable. Incorporating 2FA into your security routine ensures that your sensitive files remain confidential and well-protected during online transactions.
Kurt’s key takeaways
While cloud and file-sharing services can make life a lot easier, it is important to protect what you are sharing, especially sensitive files. Because not all files can be password protected on every file-sharing platform or safe during online transit, the seven steps outlined above can keep your sensitive files safer when being shared online.
What additional measures do you think could enhance the security of file-sharing platforms currently available? Let us know by writing us at Cyberguy.com/Contact.
For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter.
Ask Kurt a question or let us know what stories you’d like us to cover.
Follow Kurt on his social channels:
Answers to the most asked CyberGuy questions:
Copyright 2024 CyberGuy.com. All rights reserved.
Technology
Meta is closing down three VR studios as part of its metaverse cuts
Meta is laying off about 10 percent of its Reality Labs metaverse division, and the cuts include closing down some of its VR gaming studios.
Twisted Pixel Games, the developer of Marvel’s Deadpool VR, Sanzaru Games, the developer of the Asgard’s Wrath franchise, and Armature Studio, which worked on the Resident Evil 4 VR port, are all being closed down, according to an internal memo viewed by Bloomberg. The team behind the VR fitness app Supernatural will no longer develop new content or features for it, though the “existing product” will still be supported, Bloomberg says. Meta spokesperson Tracy Clayton confirmed to The Verge that Bloomberg’s reporting is accurate.
Laid off staffers have posted about the closures online.
Meta acquired Supernatural developer Within in 2023 (after a fight with the FTC), Twisted Pixel and Armature in 2022, and Sanzaru in 2020. The company closed Echo VR developer Ready at Dawn, which it also acquired in 2020, in 2024.
In a statement about the broader Reality Labs layoffs, Clayton said that “We said last month that we were shifting some of our investment from Metaverse toward Wearables. This is part of that effort, and we plan to reinvest the savings to support the growth of wearables this year.”
Update, January 13th: Added details from Bloomberg about the studio closures.
Technology
Teen hackers recruited through fake job ads
NEWYou can now listen to Fox News articles!
At first glance, the job posts look completely harmless. They promise fast money, flexible hours and paid training. No experience required. Payment comes in crypto. But these are not tutoring gigs or customer service roles. They are recruiting ads for ransomware operations.
And many of the people responding are middle and high school students. Some posts openly say they prefer inexperienced workers. Others quietly prioritize young women. All of them promise big payouts for “successful calls.”
What they leave out is the risk. Federal charges. Prison time. Permanent records. This underground ecosystem goes by a familiar name. Insiders often refer to it as “The Com,” short for “The Community.”
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.
HACKERS ABUSE GOOGLE CLOUD TO SEND TRUSTED PHISHING EMAILS
Fake job ads promising fast cash and flexible hours are quietly recruiting teens into ransomware and extortion schemes, often paying in cryptocurrency to hide criminal activity. (Donato Fasano/Getty Images)
How The Com operates behind the scenes
The Com is not a single organized gang. It functions as a loose network of groups that regularly change names and members. Well-known offshoots tied to this ecosystem include Scattered Spider, Lapsus$, ShinyHunters and related splinter crews. Some groups focus on data theft. Others specialize in phishing or extortion. Collaboration happens when it benefits the operation.
Since 2022, these networks have targeted more than 100 major companies in the U.S. and UK. Victims include well-known brands across retail, telecom, finance, fashion and media, including companies such as T-Mobile, Nike and Instacart. The combined market value of affected companies exceeds one trillion dollars.
Teenagers often take on the riskiest roles within these schemes. Phone calls, access testing and social engineering scripts typically fall to younger participants. More experienced criminals remain in the background, limiting their exposure.
That structure mirrors what identity and fraud experts are seeing across the industry. Ricardo Amper, founder and CEO of Incode Technologies, a digital identity verification company, says fake job ads are effective because they borrow trust from a familiar social contract.
“A job post feels structured, normal and safe, even when the actual behavior being requested is anything but,” Amper said. “A job posting implies a real process – a role, a manager, training and a paycheck. That’s exactly why it works. It lowers skepticism and makes risky requests feel like normal onboarding.”
Amper notes that what’s changed is not just the scale of recruitment, but how criminals package it. “Serious crime is now being sold as ‘work.’”
Why teens excel at social engineering attacks
Teenagers bring a unique mix of skills that make them highly convincing. Fluent English and comfort with modern workplace technology help them sound legitimate. Familiarity with tools like Slack, ticketing systems and cloud platforms makes impersonation easier.
According to Amper, teens don’t need technical expertise to get pulled in. “The on-ramp is usually social, a Discord server, a DM, a ‘quick gig,’” he said. “It can feel like trolling culture, but the targets are real companies and the consequences are real people.”
Risk awareness is often lower. Conversations frequently take place in public chats, where tactics and mistakes are shared quickly. That visibility accelerates learning and increases the likelihood of detection and arrest.
Gaming culture feeds the pipeline
For many teens, it starts small. Pranks in online games turn into account takeovers. Username theft becomes crypto theft. Skills escalate. So do the stakes.
Recruitment often begins in gaming spaces where fast learning and confidence are rewarded. Grooming is common. Sextortion sometimes appears. By the time real money enters the picture, legal consequences feel distant.
Amper compares the progression to gaming itself. “These crews package crime as a ladder,” he said. “Join the group, do small tasks, level up, get paid, get status.”
Why young women are being targeted
Cybercrime remains male-dominated, but recruiters adapt. Young women are increasingly recruited for phone-based attacks. Some use AI tools to alter accents or tone. Others rely on stereotypes. Distress lowers suspicion faster than authority. Researchers say women often succeed because they are underestimated. That same dynamic puts them at risk inside these groups. Leadership remains overwhelmingly male. Girls often perform low-level work. Training stays minimal. Exploitation is frequent.
Red flags that signal fake job scams and ransomware recruitment
These warning signs show up repeatedly in cases involving teen hackers, social engineering crews and ransomware groups.
Crypto-only pay is a major warning sign
Legitimate employers do not pay workers exclusively in cryptocurrency. Crypto-only pay makes transactions hard to trace and protects criminals, not workers.
Per-call or per-task payouts should raise concern
Promises of hundreds of dollars for a single call or quick task often point to illegal activity. Real jobs pay hourly or a salary with documentation.
Recruitment through Telegram or Discord is a red flag
Criminal groups rely on private messaging apps to avoid oversight. Established companies do not recruit employees through gaming chats or encrypted DMs.
Anonymous mentors and vague training are dangerous
Being “trained from scratch” by unnamed individuals is common in ransomware pipelines. These mentors disappear when arrests happen.
Secrecy requests signal manipulation
Any job that asks teens to hide work from parents or employees to hide tasks from employers is crossing a line. Secrecy protects the recruiter, not the recruit.
Amper offers a simple rule of thumb: “If a ‘job’ asks you to pretend to be someone else, obtain access, move money, or share sensitive identifiers before you’ve verified the employer, you’re not in a hiring process. You’re in a crime pipeline.”
He adds that legitimate employers collect sensitive information only after a real offer, through verified HR systems. “The scam version flips the order,” he said. “It asks for the most sensitive details first, before anything is independently verifiable.”
Urgency and emotional pressure are deliberate tactics
Rushing decisions or creating fear lowers judgment. Social engineering depends on speed and emotional reactions.
If you see more than one of these signs, pause immediately. Walking away early can prevent serious legal consequences later.
MICROSOFT TYPOSQUATTING SCAM SWAPS LETTERS TO STEAL LOGINS
Cybercrime recruiters are targeting middle and high school students for risky roles like social engineering calls, exposing them to federal charges and prison time. (Philip Dulian/picture alliance via Getty Images)
Law enforcement is cracking down on teen cybercrime
Since 2024, government indictments and international arrests have shown cybercriminal groups tied to The Com and Scattered Spider are under increasing scrutiny from law enforcement. In Sept. 2025, U.S. prosecutors unsealed a Department of Justice complaint against 19-year-old Thalha Jubair, accusing him of orchestrating at least 120 ransomware and extortion attacks that brought in over $115 million in ransom payments from 47 U.S. companies and organizations, including federal court networks. Prosecutors charged Jubair with computer fraud, wire fraud and money laundering conspiracy.
Across the Atlantic, British authorities charged Jubair and 18-year-old Owen Flowers for their alleged roles in a Transport for London cyberattack in 2024 that compromised travel card data and disrupted live commuter information. Both appeared in court under the U.K.’s Computer Misuse Act. Earlier law enforcement action in the U.S. included criminal charges against five Scattered Spider suspects for mass phishing campaigns that stole login credentials and millions in cryptocurrency, laying out how members of this collective staged coordinated extortion and data theft.
Federal agencies are also issuing advisories about the group’s social engineering techniques, noting how attackers impersonate help desks, abuse multi-factor authentication and harvest credentials to access corporate networks.
Parents often learn the truth late. In many cases, the first warning comes when federal agents arrive at the door. Teens can move from online pranks to serious federal crimes without realizing where the legal line lies.
How parents and teens can avoid ransomware recruitment traps
This type of cybercrime thrives on silence and speed. Slowing things down protects families and futures.
Tips for parents and guardians to spot fake job scams early
Parents play a critical role in spotting early warning signs, especially when online “work” starts happening behind closed doors or moves too fast to explain.
1) Pay attention to how online “jobs” are communicated
Ask which platforms your child uses for work conversations and who they talk to. Legitimate employers do not recruit through Telegram or Discord DMs.
2) Question sudden income with no clear employer
Money appearing quickly, especially in crypto, deserves scrutiny. Real jobs provide paperwork, supervisors and pay records.
3) Treat secrecy as a serious warning sign
If a teen is told to keep work private from parents or teachers, that is not independence. It is manipulation.
4) Talk early about legal consequences online
Many teens do not realize that cybercrime can lead to federal charges. Honest conversations now prevent life-changing outcomes later. Also, monitoring may feel uncomfortable. However, silence creates more risk.
Tips for teens to avoid fake job offers and cybercrime traps
Teenagers with tech skills have real opportunities ahead, but knowing how to spot fake offers can mean the difference between building a career and facing serious legal trouble.
1) Be skeptical of private messages offering fast money
Real companies do not cold-recruit through private chats or gaming servers.
2) Avoid crypto-only payment offers
Being paid only in cryptocurrency is a common tactic used to hide criminal activity.
3) Choose legal paths to build skills and reputation
Bug bounty programs, cybersecurity clubs and internships offer real experience without risking your future. Talent opens doors. Prison closes them.
Take my quiz: How safe is your online security?
Think your devices and data are truly protected? Take this quick quiz to see where your digital habits stand. From passwords to Wi-Fi settings, you’ll get a personalized breakdown of what you’re doing right and what needs improvement. Take my Quiz here: Cyberguy.com
FBI WARNS OF FAKE KIDNAPPING PHOTOS USED IN NEW SCAM
A loose cybercrime network known as “The Com” has been linked to major U.S. and U.K. data breaches affecting companies worth trillions combined. (Photo by Uli Deck/picture alliance via Getty Images)
Kurt’s key takeaways
What makes this trend so unsettling is how ordinary it all looks. The job ads sound harmless. The chats feel friendly. The crypto payouts seem exciting. But underneath that surface is a pipeline pulling teenagers into serious crimes with real consequences. Many kids do not realize how far they have gone until it is too late. What starts as a quick call or a side hustle can turn into federal charges and years of fallout. Cybercrime moves fast. Accountability usually shows up much later. By the time it does, the damage is already done.
If fake job ads can quietly recruit teenagers into ransomware gangs, how confident are you that your family or workplace would spot the warning signs before it is too late? Let us know by writing to us at Cyberguy.com.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
Fired Rockstar employees’ plea for interim pay denied
A UK employment tribunal rejected a request from fired Rockstar Games employees to receive interim pay while waiting for a full hearing about their dismissal, according to Bloomberg and IGN. After Rockstar fired 34 employees last year — 31 from the UK and three from Canada — the Independent Workers’ Union of Great Britain (IWGB) accused the company of “union busting.” Rockstar claims that the fired employees were leaking company information in a Discord channel.
The hearing took place over two days last week. “Despite being refused interim relief today, we’ve come out of last week’s hearing more confident than ever that a full and substantive tribunal will find Rockstar’s calculated attempt to crush a union to be not only unjust but unlawful,” IWGB president Alex Marshall says in a statement. “The fact that we were granted this hearing speaks to the strength of our case and, over the course of the two-day hearing, Rockstar consistently failed to back up claims made in the press or to refute that they acted unfairly, maliciously, and in breach of their own procedures.”
“We regret that we were put in a position where dismissals were necessary, but we stand by our course of action as supported by the outcome of this hearing,” a Rockstar Games spokesperson says in statements to Bloomberg and IGN. Rockstar and owner Take-Two didn’t immediately reply to a request for comment.
Rockstar is working on Grand Theft Auto VI, which was recently delayed from a planned May launch to November 19th.
-
Technology1 week agoPower bank feature creep is out of control
-
Montana3 days agoService door of Crans-Montana bar where 40 died in fire was locked from inside, owner says
-
Delaware5 days agoMERR responds to dead humpback whale washed up near Bethany Beach
-
Dallas, TX5 days agoAnti-ICE protest outside Dallas City Hall follows deadly shooting in Minneapolis
-
Dallas, TX1 week agoDefensive coordinator candidates who could improve Cowboys’ brutal secondary in 2026
-
Iowa1 week agoPat McAfee praises Audi Crooks, plays hype song for Iowa State star
-
Virginia3 days agoVirginia Tech gains commitment from ACC transfer QB
-
Montana4 days ago‘It was apocalyptic’, woman tells Crans-Montana memorial service, as bar owner detained