Category: News

  • Microsoft Teams Up with CBI to Bust Indian Call Center Scam Targeting Japan

    Microsoft Teams Up with CBI to Bust Indian Call Center Scam Targeting Japan

    In a major international cybersecurity crackdown, Microsoft has partnered with the Central Bureau of Investigation (CBI) to dismantle several illegal call centers in India that were behind a widespread tech support scam targeting Japanese citizens.

    The coordinated operation led to the raiding of multiple call centers across India, revealing a sophisticated scam network that impersonated Microsoft support representatives. The fraudsters would deceive unsuspecting Japanese users into believing their devices were compromised, then coerce them into paying for fake technical support services.

    According to Microsoft’s Cybercrime Investigation Team, this scam had been active for years and had defrauded thousands of Japanese victims. Victims were typically lured through fake pop-up alerts or misleading search engine ads, which directed them to call what they believed were official Microsoft helplines. Once on the line, operators would manipulate the victims using technical jargon and social engineering tactics to gain remote access to their computers and demand payments for unnecessary or non-existent repairs.

    Microsoft’s Digital Crimes Unit collaborated closely with CBI by providing intelligence, digital evidence, and technical support, which proved instrumental in tracing the scam to its origin. The company has been working globally to disrupt tech support fraud networks, having already assisted in dismantling similar operations in the United States, Europe, and other parts of Asia.

    “This successful operation underscores the importance of public-private partnerships in the fight against cybercrime,” said a Microsoft spokesperson. “We are committed to protecting users worldwide and holding cybercriminals accountable.”

    The CBI has confirmed the arrest of several suspects, seizure of digital equipment, and the freezing of bank accounts linked to the operation. Authorities are now working with Japanese law enforcement to assist affected victims and recover stolen funds.

    The case is a stark reminder of the growing global nature of cyber fraud, often spanning borders and exploiting trust in reputable brands like Microsoft. It also highlights the importance of cyber awareness and vigilance, especially among vulnerable users.

    Microsoft has urged users to remember:

    • Microsoft will never proactively reach out to offer unsolicited tech support.
    • Genuine Microsoft pop-ups will not request personal or financial information.
    • Users should report suspicious activity via the company’s support and fraud reporting portals.

    As investigations continue, both Microsoft and the CBI reaffirm their commitment to dismantling cybercrime syndicates and protecting digital citizens worldwide.

    Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. Summitsystemsissp assumes no liability for the accuracy or consequences of using this information

  • Victoria’s Secret Takes Website Offline Amid Serious Security Breach

    Victoria’s Secret Takes Website Offline Amid Serious Security Breach

    In a dramatic move that has caught the attention of the cybersecurity world and fashion retail industry alike, Victoria’s Secret has temporarily taken down its U.S. website following the discovery of a significant security incident. While the company has not revealed full details of the breach, it confirmed the precautionary shutdown is part of an active response to the issue. A statement posted on the brand’s homepage reads, “We are working around the clock to fully restore operations.”

    What We Know So Far

    On May 28, 2025, Victoria’s Secret initiated an emergency shutdown of its U.S. website and some in-store services. Customers looking to shop online have been greeted with a static message instead of the usual product pages and promotional banners.

    The company is currently working with third-party cybersecurity experts to investigate the nature and extent of the breach. As of now, no timeline has been provided for the full restoration of digital services.

    Customer Impact and Frustration

    The outage could not have come at a worse time—it overlapped with Memorial Day weekend, typically a major sales period for retailers. Users have taken to social media to express frustration over:

    Inability to place or track online orders

    Problems redeeming gift cards and promotional offers

    Concerns over delayed payroll access for employees

    In response, Victoria’s Secret has extended coupon expiry dates and return windows for affected customers. Physical store locations remain open, but some services like in-store returns for online purchases are temporarily suspended.

    Financial Fallout

    Digital sales make up over one-third of Victoria’s Secret’s $6.2 billion annual revenue. Following news of the incident, the company’s stock (NYSE: VSCO) dropped nearly 7%, signaling investor anxiety over the operational and reputational damage.

    Cybersecurity analysts speculate that this could be part of a broader pattern of attacks on major retailers, referencing recent breaches at Adidas, Marks & Spencer, and Co-op. Some experts warn that sophisticated cybercriminal groups like Scattered Spider could be involved, though no direct link has yet been confirmed.

    What Should Customers Do?

    Although the company hasn’t disclosed whether customer data has been compromised, experts recommend the following precautions:

    Monitor bank and card activity for unusual transactions.

    Change your Victoria’s Secret account password, especially if reused elsewhere.

    Be cautious of phishing emails or fake promotions pretending to be from the company.

    These steps can help protect your personal information while investigations continue.

    Key Takeaways for Businesses

    This incident serves as a major reminder: No company is too big to be targeted. Retailers handling large volumes of sensitive customer data must prioritize:

    Regular security audits

    Incident response planning

    Employee cybersecurity training

    Up-to-date data protection policies

    As threats evolve, so must defenses.

    Victoria’s Secret is in damage-control mode, and while customers are understandably upset, the company’s transparency and swift response will be critical in regaining trust.

    We’ll continue to monitor the situation and provide updates as more information becomes available. In the meantime, stay cyber-aware—and always use unique, strong passwords across your accounts.

    Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. Summitsystemsissp assumes no liability for the accuracy or consequences of using this information

  • FBI Issues Warning Over Malicious Deepfake Campaign Targeting Former Senior Government Officials

    FBI Issues Warning Over Malicious Deepfake Campaign Targeting Former Senior Government Officials

    The Federal Bureau of Investigation (FBI) has issued a public warning following an investigation into a sophisticated malicious campaign that leverages deepfake technology to target former high-ranking U.S. federal and state government officials. The advisory, released Thursday, highlights the growing threat posed by artificial intelligence-generated content used for disinformation, impersonation, and other cyber-enabled attacks.

    According to the FBI, the campaign involves the creation and dissemination of highly realistic deepfake videos and audio clips intended to impersonate former officials. These manipulated media assets are being used to spread false information, manipulate public opinion, and potentially conduct fraudulent activities.

    “The FBI has identified a coordinated effort that utilizes deepfake technology to exploit the reputations of former senior government officials,” the Bureau stated. “These materials are being shared across social media platforms, email campaigns, and spoofed news outlets in attempts to deceive the public and possibly compromise national security.”

    The warning did not name specific targets but emphasized that the individuals being impersonated held positions of significant influence in national and state-level governance. Some of the deepfakes were reportedly used to make it appear as though the individuals were endorsing controversial policies, participating in criminal activities, or communicating classified information.

    Cybersecurity experts say this marks a dangerous escalation in information warfare.

    “Deepfakes have moved from being a novelty to a serious tool in cyber operations,” said Lisa Reynolds, a cybersecurity analyst with Summit Systems ISSP. “When former officials are targeted, it’s not just their reputations at risk, but also public trust and institutional credibility.”

    The FBI advises the public to remain vigilant and to verify the authenticity of videos, especially when they involve sensitive political content or controversial statements. They encourage individuals to report suspicious media to their Internet Crime Complaint Center (IC3).

    The Bureau is also coordinating with tech companies to flag and remove malicious deepfake content and is working with other federal agencies to protect current and former public servants from targeted influence operations.

    This incident underscores growing concerns among intelligence and cybersecurity communities about the misuse of AI technologies to manipulate reality and spread misinformation at scale.

    As the 2026 midterm elections approach, the FBI warns that such tactics could increasingly be used to influence voter behavior, incite division, and disrupt democratic processes.

    What You Can Do:

    • Scrutinize viral videos or audio clips that seem shocking or out of character.
    • Use trusted news sources for verification.
    • Report suspected deepfakes to authorities or platform moderators

    Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. Summitsystemsissp assumes no liability for the accuracy or consequences of using this information

  • Over 62,000 Facebook Users Tricked by Fake AI Tools, Infected with Noodlophile Malware

    Over 62,000 Facebook Users Tricked by Fake AI Tools, Infected with Noodlophile Malware

    The rise of AI tools has been nothing short of exciting—everyone wants to try the latest chatbot, image generator, or virtual assistant. But cybercriminals are using this curiosity against us.

    Security experts recently uncovered a sneaky campaign where fake AI tools were used to spread a dangerous piece of malware called Noodlophile. Over 62,000 people—many of them active on Facebook—have already been targeted.

    Hooked by Curiosity: How It Starts

    Let’s face it: when we see ads promising free access to premium AI tools or exclusive early features, it’s tempting to click.

    That’s exactly what these attackers are banking on.

    They’re creating Facebook ads and posts that look legit—offering flashy downloads like:

    • “Try ChatGPT Premium for Free!”
    • “Unlock Midjourney’s Hidden Features”
    • “Boost Your Workflow with This AI Tool”

    But instead of downloading a real tool, users are tricked into installing Noodlophile malware on their devices.

    Meet Noodlophile: Silent but Dangerous

    Noodlophile doesn’t cause a pop-up or crash your screen—it works quietly in the background, stealing valuable personal data like:

    • Saved browser passwords
    • Session cookies (think: logged-in accounts)
    • Crypto wallet info
    • Clipboard contents
    • Your device’s system info

    It then sends all that data to the attacker’s server, all without you noticing a thing.

    How the Scam Works – Step by Step

    1. Enticing Facebook Ads: Fake AI tool promotions are posted or sponsored.
    2. Click & Redirect: You’re taken to a very convincing website that mimics real AI platforms.
    3. Download & Install: You download what looks like an AI app—but it’s actually malware.
    4. Game Over: Noodlophile gets to work stealing your data and securing its place on your system.

    Most victims had no idea anything was wrong—because the entire setup looked polished and professional.

    Why Facebook?

    Facebook is still a top target for cybercriminals because:

    • People trust what they see from friends or popular pages
    • Posts and links spread quickly through likes and shares
    • Ads can be narrowly targeted at specific users
    • Many users don’t double-check sources or think about cybersecurity

    This combination makes it a goldmine for attackers using social engineering tactics.

    How to Stay Safe Online

    Double-check the source – Only download tools from official websites or known platforms.
    Use antivirus or endpoint protection – Keep your security software updated.
    Enable two-factor authentication (2FA) – Adds an extra layer of protection to your accounts.
    Think before you click – If it sounds too good to be true, it probably is.
    Spread the word – Let friends and coworkers know about these scams so they can avoid them too.

    The AI wave isn’t slowing down anytime soon, and cybercriminals know it. They’re smart, opportunistic, and constantly evolving—using whatever is trending to get into our systems.

    So whether it’s a hot new AI tool or some freebie that seems amazing, pause and verify before you download.

    Stay safe, stay informed—and always click with caution.

    Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. Summitsystemsissp assumes no liability for the accuracy or consequences of using this information

  • EU Fines TikTok €530 Million Over Illegal Data Sharing with China

    EU Fines TikTok €530 Million Over Illegal Data Sharing with China

    On May 2, 2025, Ireland’s Data Protection Commission (DPC) dropped a bombshell on TikTok, fining the social media giant €530 million ($600 million) for violating the EU’s General Data Protection Regulation (GDPR). The hefty penalty stems from TikTok’s unauthorized transfer of European user data to China, raising serious concerns about privacy and potential access by Chinese authorities. This marks one of the largest GDPR fines ever and underscores the EU’s aggressive stance on data protection.

    What Happened?

    According to the investigation conducted by the Irish Data Protection Commission (DPC)—the lead supervisory authority for TikTok in the EU—TikTok unlawfully processed the personal data of EU citizens, including minors, and transferred that data to China without transparent disclosures or valid legal mechanisms.

    The key issues include:

    • Lack of clarity and transparency on where user data was being sent.
    • Insufficient safeguards to protect personal data during cross-border transfers.
    • Processing of children’s data without adequate protection or consent.

    Why Is This Important?

    This fine serves as a major warning to any company operating in the EU, particularly those dealing with cross-border data transfers. The European Union has strict rules about sending data outside the bloc, especially to countries without similar data protection standards.

    Transferring EU citizens’ data to China—where the government has broad access to corporate data—raises both privacy and national security concerns.

    What TikTok Says

    TikTok has expressed disappointment in the decision and claims that it uses robust systems to ensure user privacy. The company insists that its data access is tightly controlled, and that it is investing heavily in data residency projects within the EU.

    “We strongly disagree with the decision and plan to appeal. We have made significant changes to address these issues,” said a TikTok spokesperson.

    Implications for Other Tech Companies

    This ruling is expected to intensify scrutiny of other major platforms—especially those with ties to non-EU countries. Companies like Meta, Google, and Amazon are also under watch for their data handling practices. It reinforces the importance of:

    • Local data storage and residency programs.
    • Clear user communication regarding data usage.
    • Proper legal mechanisms (such as Standard Contractual Clauses) for data transfers.

    What’s Next for TikTok?

    As TikTok faces legal appeals and possibly further investigations, it must also work on rebuilding trust with European regulators and users. A failure to comply could result in:

    • More sanctions or even temporary service restrictions.
    • Increased public backlash and political pressure.
    • A stronger push for data localization within the EU.

    This €530 million fine isn’t just about TikTok—it’s about the future of digital privacy in Europe. With growing global concerns about data sovereignty and surveillance, this case sets a powerful precedent. For users, it’s a reminder to be vigilant. For businesses, it’s a clear signal: Respect data protection laws, or face the consequences.

    Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. Summitsystemsissp assumes no liability for the accuracy or consequences of using this information

  • Cyber Crisis in Abilene: Cyberattack Shuts Down Texas City Systems.

    Cyber Crisis in Abilene: Cyberattack Shuts Down Texas City Systems.

    On April 18, 2025, the city of Abilene, Texas, faced a significant disruption when a cyberattack targeted its internal network, forcing multiple servers offline. With a population of roughly 130,000, Abilene, known for its vibrant cultural scene and home to three Christian universities, is now grappling with the aftermath of this cybersecurity incident. The attack has prompted swift action from city officials, who are working tirelessly to restore services and secure their systems.

    The Incident Unfolds

    The cyberattack was first detected on Friday, April 18, when city officials noticed unresponsive servers. In response, Abilene’s IT department, consisting of 26 full-time staff, immediately enacted an incident response plan, disconnecting affected and critical assets to contain the breach. While the city has not disclosed specific details about the nature of the attack, some reports suggest it may involve ransomware, though no group has claimed responsibility at the time of writing.

    The attack disrupted several municipal services, including the Abilene Public Library and CityLink transit services. During a city council meeting on April 24, the absence of a sign language interpreter, live stream, and computerized voting underscored the extent of the disruption. Additionally, credit card systems at government offices were affected, limiting payment options to cash, checks, or online card payments.

    Despite these challenges, critical services such as emergency response and water utilities have remained operational. The city has also assured residents that water services will not be disconnected due to past-due balances during this period, and payments can still be made online or in person.

    Response and Recovery Efforts

    Abilene’s IT team has been working around the clock to restore services and minimize downtime. The city is collaborating with third-party cybersecurity experts to investigate the scope and scale of the attack. A public notice issued on April 24 announced a temporary suspension of the state’s public information law requirements from April 22 to April 28, reflecting the severity of the disruption.

    City officials have emphasized their commitment to monitoring systems for unusual activity and securing the network. While some systems are gradually coming back online, response times to service requests may be delayed. The city’s participation in the Texas Municipal League Intergovernmental Risk Pool (TMLIRP) provides cyber liability coverage and incident response support, which is likely aiding recovery efforts.

    A Broader Context of Cyber Threats

    Abilene’s cyberattack is not an isolated incident. In recent months, other Texas cities, including Mission and Fort Bend County, have faced similar attacks, exposing vulnerabilities in municipal networks. Ransomware attacks alone have cost Texas cities billions of dollars over the past five years, affecting 53 municipalities.

    In response to this growing threat, Texas lawmakers have taken action. On April 24, 2025, the Texas House passed a bill to establish a cyber command center in San Antonio, aimed at bolstering the state’s defenses against cyberattacks. Governor Greg Abbott has made the creation of this command an emergency legislative priority, citing the need to protect critical infrastructure from hostile actors, including foreign state-sponsored groups like China’s Salt Typhoon, which recently compromised U.S. telecommunications systems.

    Implications and Moving Forward

    The cyberattack on Abilene highlights the increasing sophistication and frequency of cyber threats targeting local governments. Municipalities, often operating with limited cybersecurity resources, are prime targets for attackers seeking to exploit sensitive data or disrupt public services. The temporary suspension of public records access and the disruption of routine city functions underscore the far-reaching impact of such incidents on residents and governance.

    As Abilene continues its recovery, the incident serves as a stark reminder of the importance of robust cybersecurity measures. The establishment of the Texas Cyber Command could provide much-needed support for cities like Abilene, enhancing threat detection and response capabilities across the state.

    For now, Abilene’s residents are encouraged to stay patient as services are restored. The city’s website remains a resource for updates and payment options, and officials are committed to transparency as the investigation progresses. In an era where cyber threats are a persistent reality, Abilene’s experience may catalyze broader efforts to safeguard Texas communities against future attacks.

    Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. Summitsystemsissp assumes no liability for the accuracy or consequences of using this information