Technology
VA issues overpayment scam alert for veterans
NEWYou can now listen to Fox News articles!
As the nation honors veterans for their service, the Department of Veterans Affairs is reminding the community to stay alert to a growing threat, the VA overpayment scam.
Reports show that fraudsters are contacting veterans through text, email and phone calls, pretending to be VA employees. They claim you were overpaid on your benefits and must send money or banking details to correct the issue.
These criminals often make their messages look official with VA logos, formal wording and even fake caller IDs. Once they gain your trust, they push for quick payment, hoping you act before verifying. Staying informed and cautious is the best way to protect your benefits and your identity.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CyberGuy.com newsletter.
Scammers are claiming veterans were overpaid on their benefits by impersonating VA employees. (Kurt “CyberGuy” Knutsson)
How to spot a VA overpayment scam
Be on alert for these red flags:
- Messages demanding urgent payment, especially by gift card, wire transfer or cryptocurrency.
- Requests for your VA login or password.
- Emails or texts with links that don’t lead to VA.gov.
- Caller ID spoofing showing “VA” or “Debt Center” to look official.
- Messages or letters that lack detailed explanations or account numbers.
If you spot any of these, don’t engage; instead, verify the communication directly through VA.gov or by calling the VA’s official number.
HOW TO STOP IMPOSTOR BANK SCAMS BEFORE THEY DRAIN YOUR WALLET
Legitimate VA communications always direct veterans to VA.gov or the official Debt Management Center. (Kurt “CyberGuy” Knutsson)
How real VA overpayments work
When the VA determines an actual overpayment, it sends a formal letter explaining the amount and your options to appeal or set up a payment plan. You’ll never be told to pay through text or third-party apps, and you’ll never be asked to share login credentials or banking info outside VA.gov.
Real VA notices always direct you to official channels like VA.gov or the Debt Management Center (1-800-827-0648). If something feels off, it probably is, so always verify before taking action.
To protect your hard-earned VA benefits stay alert and verify messages through official channels. (Kurt “CyberGuy” Knutsson)
Top ways to protect yourself from VA overpayment scams
Stay ahead of scammers by following these simple but powerful steps to protect your VA benefits.
1) Verify through your official VA.gov account
Whenever you receive a notice about an overpayment, log in to your VA.gov account directly instead of clicking any link or responding to a message. The site shows your current balance, payment status and any real debts.
2) Use official VA payment channels
If you discover a legitimate debt, handle it only through VA’s official payment options. Call the Debt Management Center at 1-800-827-0648 or make payments through your secure VA.gov dashboard. Avoid sending funds through apps, wire transfers, or prepaid cards as the VA will never ask for those.
3) Never share your login information
Your VA login and password are like your house keys. The VA will never ask for them, not by phone, email, or text. Anyone who requests them is a scammer. If you think your credentials were compromised, change your password immediately and enable multi-factor authentication (MFA) if available.
Consider using a password manager, which securely stores and generates complex passwords, reducing the risk of password reuse.
Next, see if your email has been exposed in past breaches. Our No. 1 password manager pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials.
Check out the best expert-reviewed password managers of 2025 at CyberGuy.com.
NATIONAL PROGRAM HELPS SENIORS SPOT SCAMS AS LOSSES SURGE
4) Avoid suspicious links and attachments
Fraudsters often embed fake links in messages that look real at first glance. Hover over a link before clicking to preview the URL; if it doesn’t start with “https://www.va.gov,” it’s fake. Be equally cautious with attachments, as they can install malware designed to steal your personal data.
The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.
Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices at CyberGuy.com.
5) Use a data removal service
Data brokers often publish your name, phone number and even veteran status online, information scammers use to target you. Personal data removal services can automatically request data removals from hundreds of broker sites, reducing your exposure and lowering the odds of being targeted.
While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.
Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting CyberGuy.com.
Get a free scan to find out if your personal information is already out on the web: CyberGuy.com.
6) Watch out for unusual payment methods
Scammers love untraceable transactions. Any request for payment through gift cards, Bitcoin, prepaid debit cards, or wire transfers is an instant red flag. The VA does not and will not use these methods to collect payments.
7) Limit your social media exposure
Scammers sometimes gather information from social networks to make messages seem more personal. Review your friends and followers, tighten privacy settings and think twice before posting details about your military service or VA benefits.
8) Report suspected fraud immediately
If you think someone tried to scam you, contact the VA directly at 1-800-827-1000. You can also report incidents at VSAFE.gov or call (833) 38V-SAFE (833-388-7233). Reporting quickly helps protect others in the veteran community.
Kurt’s key takeaways
This Veterans Day is a time to reflect on service, sacrifice and strength, and that includes protecting what you have earned. Scammers may be persistent, but staying alert and using official VA resources gives you the upper hand. Your benefits represent more than money; they are recognition of your service. Keep them safe, stay skeptical of sudden messages and verify everything before you act.
How can technology companies and the government do a better job of protecting veterans online? Let us know your thoughts in the comments below. Let us know by writing to us at CyberGuy.com.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CyberGuy.com newsletter.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Copyright 2025 CyberGuy.com. All rights reserved.
Technology
Fake Windows update installs hidden malware
NEWYou can now listen to Fox News articles!
If you’ve ever clicked “Check for updates” and trusted what you saw, you’re not alone. That’s exactly what this latest scam is counting on.
The page mimics official branding, includes a believable knowledge base number and presents a big blue download button that feels familiar.
The catch? The download installs malware designed to steal passwords, payment details and account access.
According to researchers at Malwarebytes Labs, a cybersecurity research and threat intelligence team inside Malwarebytes, the site uses a typosquatted domain that looks close enough to a real Microsoft URL to fool a quick glance. That small trick is often all it takes.
APPLE APP PASSWORD SCAM EMAIL WARNING
Cybersecurity researchers warn a fake Microsoft update site uses a look-alike URL and a familiar download button to deliver data-stealing malware. (Michael Nagle/Bloomberg via Getty Images)
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
Why this fake Windows update malware slips past detection
At first glance, nothing seems off. The file looks like a standard Windows installer. It even lists “Microsoft” in its properties. That’s where this attack gets clever. Instead of using obvious malicious code, the attackers built the installer with legitimate tools and layered the attack in stages. Each piece looks harmless on its own.
Here’s what’s happening behind the scenes:
- The installer launches what appears to be a normal app
- That app quietly runs hidden scripts
- A disguised process loads a full Python environment
- Data theft tools activate in the background
Because each step looks routine, many security tools fail to flag it right away. Researchers also noted that antivirus engines initially showed zero detections for key parts of the attack. That does not mean the file is safe. It means the malicious behavior is well hidden.
What this fake Windows update malware is stealing
Once installed, the malware gets to work fast. It collects details about the infected device, including location and IP address. Then it reaches out to remote servers to receive instructions and upload stolen data.
The targets include:
- Saved browser passwords
- Login sessions and cookies
- Payment details
- Discord account tokens
It even tries to shut down other processes on your system to avoid interference while it works. In some cases, it modifies apps like Discord to intercept account activity in real time.
How the fake Windows update malware stays on your system
This malware is designed to stick around. It creates entries that look like normal system processes, so they blend in. One registry entry mimics Windows Security Health, which most users would ignore. It also drops a shortcut in your startup folder with a familiar name like Spotify. That makes it easy to overlook. Two different persistence tricks mean it can survive a reboot and keep running.
FAKE WINDOWS UPDATE PUSHES MALWARE IN NEW CLICKFIX ATTACK
A fake Windows update page is tricking users into downloading malware that steals passwords, payment details and account access. (Beata Zawrzel/NurPhoto)
Why this fake Windows update scam feels so real
There’s a bigger trend behind this. Researchers say campaigns like this often target regions where large data breaches have already exposed personal information. When attackers already know your name, provider or habits, they can build scams that feel tailored to you. That makes a fake Windows update page far more believable than a generic phishing email.
It also highlights something important. Today’s malware often hides inside legitimate tools and trusted frameworks. That makes it harder to detect and easier to trust. This campaign shows how far scammers have come. They are no longer relying on sloppy emails or obvious fake links. Instead, they are building layered attacks that look and behave like trusted software.
Even experienced users can get caught off guard when everything appears normal. The biggest takeaway is simple. A clean scan result or a familiar interface does not guarantee safety.
Microsoft says it’s aware of the threat
Microsoft confirmed it is tracking this type of activity and urges users to be cautious when downloading updates from unfamiliar sources.
“We are aware of reports of fraudulent websites impersonating Microsoft, and we actively work to detect and disrupt malicious activity across the internet,” A Microsoft spokesperson told CyberGuy. “We encourage customers to be cautious of unexpected prompts or downloads and to verify that they are interacting with legitimate Microsoft domains. As a best practice, we recommend users verify the legitimacy of a link by going directly to our website from your own saved favorite, from a web search, or by typing the domain name yourself.”
For more guidance on how to protect against online phishing scams, you can refer to Microsoft’s official support page at support.microsoft.com.
MICROSOFT CROSSES PRIVACY LINE FEW EXPECTED
A convincing Windows update scam is spreading malware that can grab saved passwords, cookies, payment data and Discord tokens. (Todor Tsvetkov/Getty Images)
Ways to stay safe from fake Windows update malware
You don’t need to be a security expert to avoid this. A few habits make a big difference.
1) Only update Windows from your settings
Go to Settings > Windows Update and check for updates there. Avoid downloading updates from websites.
2) Double-check the URL
Real Microsoft pages use microsoft.com. Anything else, even if it looks close, should raise a red flag.
3) Be cautious with urgent update prompts
If a site or message pressures you to install an update, stop and verify it manually.
4) Use strong antivirus software with behavior detection
Traditional antivirus software, which often comes built into your device or as basic security software, mainly looks for known threats using signature matching, which means it can miss new or well-hidden attacks like this one. Strong antivirus software uses behavior detection to monitor what programs are doing in real time, helping flag suspicious activity even if the malware hasn’t been seen before. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com.
5) Use a data removal service to limit your exposure
If your personal information is already circulating online from past breaches, it can make scams like this more convincing. A data removal service helps reduce how much of your information is publicly available, making it harder for attackers to target you with tailored phishing attempts. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com
6) Turn on two-factor authentication
Two-factor authentication (2FA) adds a second layer of protection if your passwords are stolen.
7) Avoid downloading installer files from unknown sites
Legitimate updates rarely require manual downloads.
Kurt’s key takeaways
Fake updates are one of the most effective tricks because they tap into something we all trust. Keeping your system secure should not put you at risk, yet that’s exactly what attackers are exploiting here. The safest move is to slow down, verify where updates come from and stick to built-in tools whenever possible.
Are tech companies doing enough to keep fake updates from putting your data at risk? Let us know your thoughts in the comments below. Let us know by writing to us at Cyberguy.com.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
The Vergecast Vergecast, 2026 edition
We get a lot of questions about how The Verge works. And how The Vergecast works. And how we make money. And whether some of that money helps Nilay buy more jackets, several yachts, or something else entirely. So, every once in a while, we spend an episode of the podcast answering as many questions as we can.
On this episode of The Vergecast, Nilay and David are joined by The Verge’s publisher, Helen Havlak, to talk about ads, subscriptions, our website, our audience, and more. Then, Nilay and David answer some more questions about how we think about journalism, our relationship with Verge alumni, video podcasts, and (of course) Brendan Carr.
Thanks to everyone who sent us questions for this episode, and please keep them coming! You can always call the Vergecast Hotline (866-VERGE11) or send us an email (vergecast@theverge.com) with your questions, thoughts, feelings, and misgivings about everything we’re up to. We truly love hearing from you. And if you want to be part of everything we’re up to, and help make The Verge even bigger and better, the best thing you can do is subscribe! You even get all our podcasts ad-free.
Oh, and also, in case you missed it yesterday, be sure and check out our emergency pod on the news that Tim Cook is stepping down as Apple CEO. We’ll be talking more about the future of Apple on Friday’s show, too, so send questions if you have ’em!
Technology
Alexa+ lets you order food like a real conversation
Food delivery drones launch in NJ
FOX Business correspondent Madison Alworth reports on drone food delivery services launching in New Jersey on ‘America Reports.’
NEWYou can now listen to Fox News articles!
You’re hungry, and your stomach’s already growling. Normally, you’d grab your phone, open your favorite delivery app and start scrolling through endless restaurant lists. Tap a few menus, pick a few items and before you know it, you’ve built your order piece by piece.
But with Amazon Alexa+, you can skip all that tapping and scrolling. Just tell Alexa what you’re in the mood for, change your mind halfway or add something extra as you go, like you’re chatting with someone taking your order.
That’s the new idea behind Alexa+. Amazon has rolled out a voice-powered food ordering feature that lets you get delivery from Uber Eats and Grubhub without ever opening an app. Just say what you want, and Alexa handles the rest.
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
ALEXA.COM BRINGS ALEXA+ TO YOUR BROWSER
Amazon Alexa+ now lets users order food from Uber Eats and Grubhub by voice, turning delivery into a back-and-forth conversation instead of a series of taps. (Michael Nagle/Bloomberg via Getty Images)
What you need to use Alexa+
Now, before you start ordering with your voice, there are a few quick setup steps.
- You need an Alexa+ compatible device, like an Echo Show
- You must link your Uber Eats or Grubhub account in the Alexa app
- Your past orders can sync automatically for quick reordering
Once that’s done, it becomes a hands-free experience.
How to set up Alexa+ for food ordering (step by step)
We set this up using the Amazon Alexa app on a phone, and these are the exact steps we followed. The menus may look slightly different depending on your device.
- Open the Alexa app on your phone
- Tap “More” (it usually has three horizontal lines)
- Tap “Alexa+ Store”
- Use the search bar and type in Uber or Grubhub.
- Tap the service you want
- When it appears, tap to open it.
- Tap “Connect” or “Enable” (You may see a page from “pitangui.amazon.com” during setup. That’s part of Amazon’s system and is safe if you open it from the Alexa app. )
- Next, sign in to your account on your phone
- Tap “Grant access”
- Tap “Continue”
- Tap “Close” to return to the app
After we linked our Grubhub account, we got a confirmation email saying everything was successfully connected. Once that’s all done, it becomes a hands-free experience.
To actually place an order, go to your Echo device and say, “Alexa, I want to order food,” then follow the prompts on the screen. Note: the feature is still rolling out and works best on newer Echo Show devices.
You can also manage or remove the connection anytime in the Alexa app by going to: Alexa App > Menu > Settings > Manage Alexa+ Services Unlink & Revoke Permissions
How Alexa+ actually builds your order
After you’re set up, this is where things start to change. For years, voice assistants followed a simple pattern. You ask something. It answers. That’s it.
With Amazon Alexa+, that model shifts. Instead of giving one command at a time, you can carry on a back-and-forth conversation.
You might start with:
- “Show me Mexican food”
- “Actually, let’s do pizza”
- “Add a large pepperoni with extra cheese”
- “Wait, make that two”
The system updates your order in real time. If you change your mind, it adjusts instantly on screen. Even better, it only jumps in when you need help. That means fewer interruptions and a smoother flow.
GRUBHUB CONFIRMS DATA BREACH AMID EXTORTION CLAIMS
With Alexa+, Amazon is pushing voice ordering beyond basic commands, letting users browse restaurants, customize meals and check delivery status through natural conversation. (Michael Nagle/Bloomberg via Getty Images)
How Alexa+ lets you customize your order
This is where things start to feel different from anything we’ve seen before.
You can explore like you’re talking to a person
You don’t need exact menu names. Say something like “meat lovers pizza,” and Alexa+ finds the closest match. Want dessert? Just ask. Curious what’s popular? Ask that too.
You can change your mind mid-order
Most apps make you backtrack. Alexa+ lets you pivot on the fly. Add items. Remove them. Adjust quantities. Switch restaurants entirely. Everything updates live on your screen.
You see the full breakdown before you pay
Before checkout, you’ll get a clear summary:
- Item names
- Quantities
- Individual prices
- Total cost
That transparency matters, especially when small add-ons can quickly add up.
You can track your delivery with your voice
Once your order is placed, you can simply ask:
“Alexa, where’s my food?”
No need to dig through notifications or open another app.
Why Amazon is pushing Alexa+ now
This isn’t just about food delivery. Amazon is testing a bigger idea. It wants Alexa+ to adapt based on what you’re trying to do. Ordering food needs flexibility. Checking the weather doesn’t. So instead of one rigid interaction style, Alexa+ shifts its behavior depending on the task. Food ordering is just the beginning. Amazon is already hinting at future uses like grocery shopping and travel planning.
GRUBHUB LAUNCHES FIRST-EVER COMMERCIAL DRONE FOOD DELIVERY SERVICE IN NEW JERSEY
Amazon’s new Alexa+ food-ordering feature connects with Uber Eats and Grubhub, allowing users to build, change and track delivery orders without opening an app.
What this means to you
This feature sounds convenient, and in many ways it is. Still, there are a few things worth thinking about before you start ordering dinner out loud. First, it makes ordering easier. That’s great for speed, but it can also make spending feel effortless. When ordering becomes a conversation, it’s easy to keep adding items without paying attention to the total. Second, your data matters. Linking accounts means Amazon can connect your voice activity with your food habits. That includes what you order, when you order and how often. Third, it changes how you interact with technology. Instead of tapping and scrolling, you’re relying on AI to interpret what you mean. That saves time, but it also means trusting the system to get things right. Finally, it may reshape your habits. If this becomes second nature, opening apps could start to feel old-fashioned before long.
Take my quiz: How safe is your online security?
Think your devices and data are truly protected? Take this quick quiz to see where your digital habits stand. From passwords to Wi-Fi settings, you’ll get a personalized breakdown of what you’re doing right and what needs improvement. Take my Quiz here: Cyberguy.com.
Kurt’s key takeaways
Ordering food has always been simple. Now it’s becoming conversational. That shift might sound small, but it signals something bigger. Technology is moving away from commands and toward natural interaction. The goal is to make devices feel less like tools and more like assistants. The real question is how far that goes. If your device can handle dinner tonight, what else will it manage tomorrow?
And here’s something to think about: At what point does convenience start making decisions for you instead of helping you make them? Let us know by writing to us at Cyberguy.com.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
Copyright 2026 CyberGuy.com. All rights reserved.
-
Technology30 seconds agoFake Windows update installs hidden malware
-
Business7 minutes agoNetflix plans to buy historic Radford Studio Center
-
Entertainment12 minutes agoAfter Epstein scandal, Hollywood bidders race for Wasserman’s $3-billion agency
-
Lifestyle18 minutes agoThe story behind this rare architectural speaker from cult Japanese fashion brand TheSoloist
-
Politics24 minutes agoBecerra sees momentum, money and movement in the polls in governor’s race
-
Science31 minutes agoFBI probes cases of missing or dead scientists, including four from the L.A. area
-
Sports36 minutes agoRams coach Sean McVay says Puka Nacua is ‘doing really well’ after rehab stint
-
World49 minutes agoTehran vows to ‘resist bullying’ as Trump extends Iran truce, blocks ports