In this article
- Latest
- How we cover this
- What to do with any of it
- Corrections
Latest
Round-ups, analysis and explainers on how online fraud is actually working right now. These are longer pieces rather than headlines: the aim is to explain what a development means for an ordinary person, and what — if anything — you should do differently because of it.
The 10 biggest cyber hacks of 2026
The year's most significant confirmed breaches from ten countries, and what each one means for ordinary people.
Read it → ANALYSISScam trends in 2026: what has actually changed
Cheap fluent writing, copied voices and industrial operations have changed how fraud arrives — but not what it needs from you.
Read it → EXPLAINERHow data breaches actually happen
The five routes attackers really use, what happens to stolen records, and how to read a breach notice properly.
Read it → EXPLAINERInside a modern phishing operation
Phishing is a supply chain. Why the old warning signs stopped working, and which defences still hold.
Read it →How we cover this
We do not republish press releases or rewrite other outlets' reporting. Each piece here is written for this site, and we are deliberate about the difference between three things: confirmed incidents, which we attribute and date; analysis of patterns across many incidents, which we label as analysis; and explainers describing how a technique works in general.
We also leave things out on purpose. Explaining how an attack works helps people recognise it; supplying the operational detail needed to run one does not, so we stop short of that line. And we avoid the reflex of treating every new technique as unprecedented — most are variations, and saying so is more useful than alarm.
What to do with any of it
News about fraud is only worth reading if it changes something. In practice the response to nearly every development on this page is the same short list, which is itself a useful signal about where the real risk sits.
- Two-factor authentication on your email account first, because it resets everything else.
- A password manager, so one breach stays one problem.
- A family check word, so an urgent call can be verified without relying on a voice.
- Automatic updates, everywhere.
- Verify through a channel you chose — hang up and dial the number on your card.
If something has already happened, skip the reading and go to the first 24 hours checklist. The order you do things in affects what can be recovered.
Corrections
If anything here is wrong or out of date, tell us and we will fix the page and update its review date. Our editorial policy sets out how this material is produced and reviewed.
Frequently asked questions
Do you report on individual data breaches?
We cover significant incidents in round-ups and attribute them. Most of what we publish is analysis of patterns across many incidents, or explainers on how a technique works, and we label which is which.
How often is this section updated?
Each piece shows the date it was last reviewed. We add to it when something changes that would alter the advice we give, rather than publishing for its own sake.
Do you explain how attacks are carried out?
Only as far as helps people recognise them. We deliberately stop short of operational detail that would help someone run an attack rather than avoid one.
I found an error in an article. Will you correct it?
Yes. Email us the page and the problem. Substantive corrections are made to the page itself and the review date is updated.