Cybersecurity Report Roundup: Phishing Job Recruitment, Traffic Fine Scams and Internal Business Fraud
- Roy Urrico

- 2 days ago
- 5 min read
By Roy Urrico

Finopotamus aims to highlight white papers, surveys, blogs and reports that provide a glimpse as to what is taking place and/or impacting credit unions and other organizations in the financial services industry.
In this cybersecurity roundup, we focus on global phishing attacks, identity crime and internal business fraud.
NordVPN Reveals Global Phishing Campaign Impersonating Major Brand Recruiters

NordVPN’s Threat Intelligence research team identified a phishing campaign that impersonates recruiters from more than 75 global brands to collect corporate Google Workspace and Meta for Business (formerly Facebook for Business) credentials. The operation deliberately targets marketing and communications professionals rather than finance or IT staff.
A compromised marketing professional's account typically controls Google and Facebook ads manager profiles, often with a payment method attached. It also gives access to corporate content management systems (CMS), customer lists, and social media profiles with large follower counts, according to NordVPN.
“For attackers, this means immediate monetization. They can burn advertising budgets on malvertising campaigns served from a verified business account, or simply resell the access to other criminals,” said NordVPN.
A fake recruiter contacts victims, often using the real name and photo of an actual HR employee, and invites them to schedule an interview, where they are prompted to “Sign in with Google” during the “booking” process.

“The scam is particularly dangerous because it targets a person's professional credibility to gain a foothold in their company,” says Adrianus Warmenhoven, cybersecurity advisor at NordVPN. “The attacker orchestrates a login through a fake window that looks so real the victim never suspects they might be handing over the keys to their company’s internal systems.”
The campaign’s success relies on a technique known as browser-in-the-browser (BitB). When a victim clicks a login button, the phishing kit generates an HTML drawing that imitates a separate browser window. Because the victim believes they are interacting with a genuine prompt, they enter their credentials and approve two-factor authentication (MFA) codes. The attackers relay these codes to the real platforms in real time, allowing them to bypass security measures and obtain a fully authenticated session.
The campaign impersonated an extensive range of organizations, including:
Tech and software: Nvidia, Adobe, Salesforce, and SoundCloud.
Retail and apparel: Nike, Adidas, Louis Vuitton, Levi’s, and Sephora.
Entertainment and gaming: Disney, Epic Games, and Ubisoft.
Food and beverage: Coca-Cola, Starbucks, Heineken, and Red Bull.
Travel and hospitality: Booking.com, Marriott, and Expedia.
Airlines: American Airlines, Delta Air Lines, Emirates, and United Airlines.
Sports and luxury: FIFA, Formula 1, UEFA Champions League, and Lamborghini.
Caution Ahead: The ITRC Warns Drivers of Traffic Fine Scam

Identity criminals are capitalizing on the stress of a court appearance to trick people into handing over their money and personal information, warns the El Cajon, Calif.-based Identity Theft Resource Center (ITRC), a national nonprofit organization established to support identity crime victims.
The latest traffic fine scam involves a text message referencing a specific – but fake – case number, and claiming people owe money for a traffic-related offense. The text typically provides two options: pay the fine immediately through a QR code or link, or show up at a local courthouse by a specific time.
“Since these messages often use the names of local officials or specific county courthouses, they can look surprisingly real,” said the ITRC. “Similar ‘toll and ticket’ scams have been reported across the country, with fraudsters impersonating various state transportation and law enforcement agencies.”
Scammers use these traffic fine scam texts and fake legal threats, noted the ITRC, to steal a variety of assets, such as:
Money: They want victims to pay “fines” immediately via untraceable methods or credit cards.
Financial Access: Clicking links or scanning QR codes can lead to “spoofed” websites designed to capture banking or credit card login credentials.
Personal Data: They may ask for a driver’s license number or other identifiers to “verify” the case and then used for identity theft.
The ITRC recommends:
Remember that the district court, sheriff’s office and district attorney’s office do not send court notices or fine demands by text.
Never scan a QR code or click a link in an unsolicited text. “These can install malware on your device or take you to a fraudulent payment site.”
“If you are worried you might actually have an outstanding ticket, look up the official phone number for your local clerk of court or Department of Motor Vehicles and call them directly.”
If victims have already sent money or shared banking details, contact the financial institution immediately to report the fraud.
Chargebacks911: The Biggest Fraud Risk May Already Be Inside the Business

The payments industry has spent years building walls through fraud filters, AI detection, behavioral biometrics, 3D Secure and machine learning that have all been designed to stop threats arriving from outside. However, new research from Tampa, Fla.-based Chargebacks911 in their 2026 Chargeback Field Report suggested one of the biggest business blind spots may already exist inside the business.
The report, based on proprietary survey data from more than 250 merchants, finds that nearly one in four merchants has experienced employee-initiated fraud or in-house collusion, yet fewer than four in ten of those affected actively monitor for it. More than half, 53.5%, either do not know whether internal fraud is being tracked within their organization or confirmed it is not.
The findings come as retailers enter a major seasonal hiring period, bringing large numbers of temporary employees into contact with payment systems, customer data and refund processes. Chargebacks911 warns that internal fraud can be particularly difficult to detect because it can look like legitimate activity rather than an external attack.

As Monica Eaton, Founder and CEO of Chargebacks911, puts it: “Merchants have invested heavily in stopping fraud at the door. Very few have stopped to ask what happens when the threat already has a key."
“The chargeback system was originally designed to protect consumers against fraud and merchant error,” noted the report. It pointed out today however, it is often used for “friendly fraud”: illegitimate disputes initiated (either accidentally or intentionally) by consumers or their financial institution. “This represents a growing threat for merchants, yet most have limited visibility beyond their own chargeback activity.”
Internal fraud rarely looks dramatic as it does not resemble someone breaking into a system or stealing payment credentials. It looks like ordinary business continuing exactly as expected and that is precisely what makes it so difficult to detect.
In its most deliberate form, an employee with access to customer accounts directs a buyer to file a chargeback rather than request a refund through the merchant, with the resulting funds shared between them. The merchant loses the transaction, absorbs the chargeback fee and has no obvious way to trace the loss back to its source.
Sometimes there is no malicious intent. A refund is agreed but never processed correctly. The customer disputes the payment, the merchant absorbs the loss and the resulting chargeback appears no different from external fraud.
Both scenarios produce losses that are functionally indistinguishable from external fraud. Without visibility across the full dispute lifecycle, most merchants will never know the difference.
"Most merchants discover internal fraud by accident," said Eaton. "A pattern eventually becomes too obvious to ignore, or someone says something they shouldn't. That is not a detection strategy. Merchants who are serious about managing this risk need to understand their own dispute activity well enough to recognize when something doesn't add up, before the business starts explaining away losses it should have prevented."



