<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Response Red — Victim Advisories</title>
    <link>https://responsered.com/advisories/</link>
    <atom:link href="https://responsered.com/advisories/feed.xml" rel="self" type="application/rss+xml" />
    <description>First-hours guidance for victims of ransomware, fraud, scams, breaches, and insider theft — what to do, what to preserve, and how to stay calm before professional responders engage.</description>
    <language>en</language>
    <lastBuildDate>Thu, 23 Jul 2026 08:00:00 GMT</lastBuildDate>
    <ttl>1440</ttl>
    <image>
      <url>https://responsered.com/icon-512.png</url>
      <title>Response Red — Victim Advisories</title>
      <link>https://responsered.com/advisories/</link>
    </image>
    <item>
      <title>Clear head, cold blood: managing panic during a cyber incident</title>
      <link>https://responsered.com/advisories/cyber-incident-psychology/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/cyber-incident-psychology/</guid>
      <pubDate>Thu, 23 Jul 2026 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Crisis Psychology</category>
      <description>Cyber incidents are psychological events before they are technical ones. Attackers weaponize urgency — deliberate calm is a countermeasure, and it can be practiced.</description>
      <content:encoded>&lt;p&gt;Cyber incidents are psychological events before they are technical ones. Attackers weaponize urgency — deliberate calm is a countermeasure, and it can be practiced.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Urgency is a weapon: countdowns, deadlines, and threats exist to force unforced errors.&lt;/li&gt;&lt;li&gt;The acute stress response passes within minutes if you let it — make no irreversible decision inside it.&lt;/li&gt;&lt;li&gt;Write, don't remember: a shared incident log offloads working memory and measurably reduces anxiety.&lt;/li&gt;&lt;li&gt;One incident lead and a fixed decision rhythm prevent more early damage than any technical control.&lt;/li&gt;&lt;li&gt;No blame during the incident: fear of punishment hides the facts responders need most.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/cyber-incident-psychology/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/cyber-incident-psychology.png" type="image/png" length="121352" />
    </item>
    <item>
      <title>Do we have to tell anyone? Breach notification in plain language</title>
      <link>https://responsered.com/advisories/breach-notification-duties/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/breach-notification-duties/</guid>
      <pubDate>Thu, 16 Jul 2026 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Compliance</category>
      <description>Regulators, customers, partners — after a breach, who must hear about it, and by when? The clocks start earlier than most teams think, and the decision needs a written trail either way.</description>
      <content:encoded>&lt;p&gt;Regulators, customers, partners — after a breach, who must hear about it, and by when? The clocks start earlier than most teams think, and the decision needs a written trail either way.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Clocks generally start at awareness of a likely breach — not at full understanding. GDPR's 72-hour supervisory notice is the famous one; it is not alone.&lt;/li&gt;&lt;li&gt;Duties stack in layers: data-protection regulators, affected individuals, contracts with customers and partners, and sector rules (finance, health, critical infrastructure) — each with its own trigger and deadline.&lt;/li&gt;&lt;li&gt;Not every incident is notifiable — most regimes are risk-based. But the assessment must be done, and documented, even when the conclusion is &amp;quot;no&amp;quot;.&lt;/li&gt;&lt;li&gt;Facts from forensics feed the decision; counsel makes it. Neither works alone.&lt;/li&gt;&lt;li&gt;Over-notification has real costs too — panic, churn, legal exposure — which is why precision of scope matters in both directions.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/breach-notification-duties/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/breach-notification-duties.png" type="image/png" length="112862" />
    </item>
    <item>
      <title>Your first cyber insurance claim: keep the coverage you paid for</title>
      <link>https://responsered.com/advisories/cyber-insurance-first-claim/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/cyber-insurance-first-claim/</guid>
      <pubDate>Thu, 25 Jun 2026 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Insurance</category>
      <description>The incident is real and the policy exists for exactly this. Between here and a paid claim sit notice deadlines, panel rules, and a documentation trail — start all three now.</description>
      <content:encoded>&lt;p&gt;The incident is real and the policy exists for exactly this. Between here and a paid claim sit notice deadlines, panel rules, and a documentation trail — start all three now.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Notify the insurer immediately — late notice is among the most common reasons cyber claims are reduced or denied.&lt;/li&gt;&lt;li&gt;Many policies require approved (&amp;quot;panel&amp;quot;) vendors for response and forensics; hiring your own first can leave those costs uncovered.&lt;/li&gt;&lt;li&gt;Document from hour zero: costs, hours, decisions, and business impact. Claims are paid on evidence, not narrative.&lt;/li&gt;&lt;li&gt;Do not admit liability, settle with third parties, or authorize extortion payments without insurer involvement — each can void parts of coverage.&lt;/li&gt;&lt;li&gt;Read the policy tonight with counsel: sublimits, exclusions, and waiting periods shape response strategy more than most teams expect.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/cyber-insurance-first-claim/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/cyber-insurance-first-claim.png" type="image/png" length="120415" />
    </item>
    <item>
      <title>Preserving digital evidence: what to save before responders arrive</title>
      <link>https://responsered.com/advisories/digital-evidence-preservation/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/digital-evidence-preservation/</guid>
      <pubDate>Thu, 18 Jun 2026 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Forensics</category>
      <description>In the gap between discovering an incident and professional response, evidence either survives or it doesn't. You don't need forensic tools — you need to stop destruction.</description>
      <content:encoded>&lt;p&gt;In the gap between discovering an incident and professional response, evidence either survives or it doesn't. You don't need forensic tools — you need to stop destruction.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The best preservation is not touching things: isolate affected systems, then leave them alone.&lt;/li&gt;&lt;li&gt;Memory disappears at power-off, and logs silently overwrite themselves within days or even hours — these two losses are permanent.&lt;/li&gt;&lt;li&gt;Phone photos of screens, with timestamps, are legitimate and genuinely useful evidence.&lt;/li&gt;&lt;li&gt;Never work on the evidence: no antivirus scans, cleanups, updates, or casual logins on affected machines.&lt;/li&gt;&lt;li&gt;A handwritten timeline made today beats a reconstructed one made next week.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/digital-evidence-preservation/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/digital-evidence-preservation.png" type="image/png" length="122922" />
    </item>
    <item>
      <title>Sextortion: they have intimate images and are demanding money</title>
      <link>https://responsered.com/advisories/sextortion-blackmail-response/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/sextortion-blackmail-response/</guid>
      <pubDate>Thu, 04 Jun 2026 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Extortion</category>
      <description>Someone you trusted online is threatening to send private images to your family and followers unless you pay. Do not pay — payment escalates. There is a path through this, and you are not walking it alone.</description>
      <content:encoded>&lt;p&gt;Someone you trusted online is threatening to send private images to your family and followers unless you pay. Do not pay — payment escalates. There is a path through this, and you are not walking it alone.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Do not pay. Payment marks you as someone who pays — demands escalate and continue; refusal, statistically, is what makes them move on.&lt;/li&gt;&lt;li&gt;Stop responding, but do not delete the conversation — it is the evidence for every takedown and report that follows.&lt;/li&gt;&lt;li&gt;Hash-blocking services (StopNCII for adults; NCMEC's Take It Down for anyone under 18) can prevent images from being posted on major platforms without you ever sharing the images themselves.&lt;/li&gt;&lt;li&gt;This is industrialized crime run from scripts against thousands of targets at once — nothing about it is personal, and the operator's only lever is your silence.&lt;/li&gt;&lt;li&gt;If the target is a minor: a trusted adult and an immediate report (NCMEC / local police). The law protects the victim, and there is no trouble waiting for them — only help.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/sextortion-blackmail-response/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/sextortion-blackmail-response.png" type="image/png" length="116668" />
    </item>
    <item>
      <title>Suspected insider data theft: investigate quietly, act correctly</title>
      <link>https://responsered.com/advisories/insider-threat-response/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/insider-threat-response/</guid>
      <pubDate>Thu, 28 May 2026 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Insider Threat</category>
      <description>When the threat has a badge and a login, the first days decide the case. Mishandled, they destroy the evidence, the legal position, and sometimes an innocent career.</description>
      <content:encoded>&lt;p&gt;When the threat has a badge and a login, the first days decide the case. Mishandled, they destroy the evidence, the legal position, and sometimes an innocent career.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Keep the circle tiny: legal, HR, one executive, and security — strictly need-to-know.&lt;/li&gt;&lt;li&gt;Do not confront or suspend on suspicion alone; tipping off the person triggers evidence destruction, and employment law shapes every available move.&lt;/li&gt;&lt;li&gt;Preserve, don't inspect: opening files and mailboxes yourself alters timestamps a legal case may depend on.&lt;/li&gt;&lt;li&gt;Coordinate every access change with counsel — a wrong move creates wrongful-dismissal exposure on top of the data loss.&lt;/li&gt;&lt;li&gt;Typical signals: mass downloads, activity at odd hours, personal cloud or USB transfers, and spikes shortly before a resignation.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/insider-threat-response/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/insider-threat-response.png" type="image/png" length="119424" />
    </item>
    <item>
      <title>Wrong recipient, public bucket: when the leak was an accident</title>
      <link>https://responsered.com/advisories/accidental-data-exposure/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/accidental-data-exposure/</guid>
      <pubDate>Thu, 14 May 2026 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Data Handling</category>
      <description>A spreadsheet to the wrong client, a storage bucket open to the internet. No attacker, real exposure — and the clock does not care that it was a mistake.</description>
      <content:encoded>&lt;p&gt;A spreadsheet to the wrong client, a storage bucket open to the internet. No attacker, real exposure — and the clock does not care that it was a mistake.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Assume delivered and seen: email recall functions rarely work outside your own organization.&lt;/li&gt;&lt;li&gt;Contain first — close the bucket, expire the link, restrict the file — then scope precisely: whose data, which fields, how long exposed.&lt;/li&gt;&lt;li&gt;For misdirected email, a prompt, polite deletion request with written confirmation is standard practice and genuinely effective.&lt;/li&gt;&lt;li&gt;Accidental exposure can be a notifiable breach; the analysis is the same as for an attack, and &amp;quot;it was a mistake&amp;quot; is not an exemption.&lt;/li&gt;&lt;li&gt;Access logs decide severity for open buckets: exposed-but-never-accessed is a different incident from crawled-and-downloaded.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/accidental-data-exposure/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/accidental-data-exposure.png" type="image/png" length="114360" />
    </item>
    <item>
      <title>Scammed online: your first moves after financial fraud</title>
      <link>https://responsered.com/advisories/online-scam-financial-fraud-response/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/online-scam-financial-fraud-response/</guid>
      <pubDate>Thu, 07 May 2026 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Scams</category>
      <description>Investment platforms that vanish, &quot;support&quot; that drains accounts, a relationship that turned into transfers. Recovery depends on speed and evidence — not confrontation.</description>
      <content:encoded>&lt;p&gt;Investment platforms that vanish, &amp;quot;support&amp;quot; that drains accounts, a relationship that turned into transfers. Recovery depends on speed and evidence — not confrontation.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Stop all further payments immediately — including &amp;quot;release fees&amp;quot;, &amp;quot;taxes&amp;quot;, or &amp;quot;verification deposits&amp;quot; to withdraw your money. Those are the same scam continuing.&lt;/li&gt;&lt;li&gt;Call your bank or card issuer about recalls and chargebacks the same day; for crypto, record transaction hashes and report — tracing is possible, reversal is rare.&lt;/li&gt;&lt;li&gt;Do not confront the scammer or reveal that you know. Silence preserves accounts and evidence.&lt;/li&gt;&lt;li&gt;Anyone who contacts you offering to recover your lost money is almost always a second scam.&lt;/li&gt;&lt;li&gt;Capture everything now — profiles, chats, and platforms are deleted overnight.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/online-scam-financial-fraud-response/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/online-scam-financial-fraud-response.png" type="image/png" length="118144" />
    </item>
    <item>
      <title>The CEO on the call wasn't the CEO: deepfake voice and video fraud</title>
      <link>https://responsered.com/advisories/deepfake-executive-fraud/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/deepfake-executive-fraud/</guid>
      <pubDate>Thu, 23 Apr 2026 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Deepfake Fraud</category>
      <description>A live call, the right face, the right voice, an urgent confidential transfer. Cloned audio and video now survive real-time conversation — process is the only reliable defense.</description>
      <content:encoded>&lt;p&gt;A live call, the right face, the right voice, an urgent confidential transfer. Cloned audio and video now survive real-time conversation — process is the only reliable defense.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Minutes of public audio or video are enough to clone an executive convincingly — including live, interactive calls.&lt;/li&gt;&lt;li&gt;The tell is never the face or the voice; it is the pattern: urgency, secrecy, and authority pushing a payment or credential action outside normal process.&lt;/li&gt;&lt;li&gt;Verification means an independent channel you initiate — a callback to a number you already hold, or a pre-agreed code word. &amp;quot;It sounded exactly like her&amp;quot; is not verification.&lt;/li&gt;&lt;li&gt;Report attempts even when they fail; finance and security teams need to know the campaign is running.&lt;/li&gt;&lt;li&gt;Defenses that scale are procedural: callback rules and dual approval for payments above a threshold, with no executive exception.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/deepfake-executive-fraud/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/deepfake-executive-fraud.png" type="image/png" length="117611" />
    </item>
    <item>
      <title>Company network breach: contain it without destroying the evidence</title>
      <link>https://responsered.com/advisories/network-breach-containment/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/network-breach-containment/</guid>
      <pubDate>Thu, 16 Apr 2026 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Network Breach</category>
      <description>An attacker is — or was — inside your network. Your next moves either preserve the ability to answer &quot;what did they take?&quot; or erase it permanently.</description>
      <content:encoded>&lt;p&gt;An attacker is — or was — inside your network. Your next moves either preserve the ability to answer &amp;quot;what did they take?&amp;quot; or erase it permanently.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Containment and evidence preservation are one decision, not two: isolate systems, don't wipe them.&lt;/li&gt;&lt;li&gt;Rebuilding a compromised server before it is imaged destroys the record your insurer, regulator, and lawyers will ask for.&lt;/li&gt;&lt;li&gt;Move incident communications out of band immediately — assume the attacker reads your email and chat.&lt;/li&gt;&lt;li&gt;Scope before eviction: blocking indicators one at a time teaches the attacker to dig deeper footholds.&lt;/li&gt;&lt;li&gt;Start an incident log now — times, observations, actions, and who decided what.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/network-breach-containment/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/network-breach-containment.png" type="image/png" length="120549" />
    </item>
    <item>
      <title>Payroll diversion: the &quot;employee&quot; who changed their bank details wasn't</title>
      <link>https://responsered.com/advisories/payroll-diversion-fraud/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/payroll-diversion-fraud/</guid>
      <pubDate>Thu, 09 Apr 2026 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Financial Fraud</category>
      <description>HR processed a routine direct-deposit change, and salary went to a criminal's account. It is business email compromise aimed at payroll — and it responds to the same clock.</description>
      <content:encoded>&lt;p&gt;HR processed a routine direct-deposit change, and salary went to a criminal's account. It is business email compromise aimed at payroll — and it responds to the same clock.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The request came from a spoofed lookalike address or the employee's genuinely compromised mailbox — determine which, because the second means a live intrusion.&lt;/li&gt;&lt;li&gt;Bank recall is a race measured in hours, exactly like wire fraud: call the moment the diversion is discovered.&lt;/li&gt;&lt;li&gt;Search for other pending or recent detail changes now — these campaigns hit many employees at once.&lt;/li&gt;&lt;li&gt;Verify every change with the employee by phone or in person, never by replying to the requesting email.&lt;/li&gt;&lt;li&gt;The lasting fix is procedural: out-of-band verification for every banking change, no exceptions for urgency.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/payroll-diversion-fraud/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/payroll-diversion-fraud.png" type="image/png" length="117176" />
    </item>
    <item>
      <title>Your vendor was breached: assume nothing, rotate everything they held</title>
      <link>https://responsered.com/advisories/supply-chain-vendor-breach/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/supply-chain-vendor-breach/</guid>
      <pubDate>Thu, 02 Apr 2026 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Supply Chain</category>
      <description>The email says your provider &quot;detected unauthorized access&quot;. Their incident just became your exposure — measured by what they could reach and what they stored.</description>
      <content:encoded>&lt;p&gt;The email says your provider &amp;quot;detected unauthorized access&amp;quot;. Their incident just became your exposure — measured by what they could reach and what they stored.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Your exposure equals the vendor's access plus the vendor's storage: credentials, API keys, network paths, and your data on their systems.&lt;/li&gt;&lt;li&gt;Rotate every credential and key the vendor held or could see — now, without waiting for their final forensics report.&lt;/li&gt;&lt;li&gt;An MSP or IT provider with admin access is the maximum-severity case: treat it as potential direct compromise of your own environment.&lt;/li&gt;&lt;li&gt;Ask the vendor pointed written questions; their first notice is usually vague by design.&lt;/li&gt;&lt;li&gt;Expect phishing that impersonates the breached vendor within days — attackers ride the news.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/supply-chain-vendor-breach/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/supply-chain-vendor-breach.png" type="image/png" length="119329" />
    </item>
    <item>
      <title>Identity theft: contain the damage, step by step</title>
      <link>https://responsered.com/advisories/identity-theft-response/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/identity-theft-response/</guid>
      <pubDate>Thu, 26 Mar 2026 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Identity Fraud</category>
      <description>Accounts you didn't open, charges you didn't make, a login that no longer accepts your password. Work account by account, in the right order, and write everything down.</description>
      <content:encoded>&lt;p&gt;Accounts you didn't open, charges you didn't make, a login that no longer accepts your password. Work account by account, in the right order, and write everything down.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Secure your email account first — it is the master key that resets everything else.&lt;/li&gt;&lt;li&gt;Freeze your credit with the bureaus (in the US: Equifax, Experian, TransUnion — free). A freeze blocks new accounts; a fraud alert only asks lenders to be careful.&lt;/li&gt;&lt;li&gt;Move your most important accounts to unique passwords and app-based two-factor or passkeys: email, banking, and your phone carrier first.&lt;/li&gt;&lt;li&gt;Ask your mobile carrier for a SIM-swap / port-out lock — hijacking your number defeats SMS codes.&lt;/li&gt;&lt;li&gt;Keep a dated log of every discovery, call, and case number. It becomes your dispute file.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/identity-theft-response/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/identity-theft-response.png" type="image/png" length="116994" />
    </item>
    <item>
      <title>Your company appeared on a leak site: verify before you react</title>
      <link>https://responsered.com/advisories/data-leak-site-exposure/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/data-leak-site-exposure/</guid>
      <pubDate>Thu, 19 Mar 2026 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Data Breach</category>
      <description>A ransomware crew's blog lists your name, a countdown, and &quot;proof&quot; samples. What happens next should be driven by verification and law — not by the countdown.</description>
      <content:encoded>&lt;p&gt;A ransomware crew's blog lists your name, a countdown, and &amp;quot;proof&amp;quot; samples. What happens next should be driven by verification and law — not by the countdown.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Verify first: leak-site &amp;quot;proof&amp;quot; is sometimes recycled from old breaches, inflated, or another company's data entirely.&lt;/li&gt;&lt;li&gt;Capture the listing and samples immediately — postings change and vanish, and you will need the record.&lt;/li&gt;&lt;li&gt;The posting itself starts clocks: regulators, contracts, and insurers may all have notice requirements regardless of what you pay or say.&lt;/li&gt;&lt;li&gt;Paying for &amp;quot;deletion&amp;quot; buys a promise from criminals; there is no verification, and copies routinely survive.&lt;/li&gt;&lt;li&gt;If the data is real, the intrusion that took it may still be live — scoping the source breach comes with the response.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/data-leak-site-exposure/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/data-leak-site-exposure.png" type="image/png" length="121389" />
    </item>
    <item>
      <title>Microsoft 365 or Google Workspace compromised: evict them from the tenant</title>
      <link>https://responsered.com/advisories/cloud-tenant-compromise/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/cloud-tenant-compromise/</guid>
      <pubDate>Thu, 12 Mar 2026 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Cloud Breach</category>
      <description>An attacker is inside your productivity cloud — mail, files, identities. Password resets alone do not evict them; tokens, app grants, and rules do the persisting.</description>
      <content:encoded>&lt;p&gt;An attacker is inside your productivity cloud — mail, files, identities. Password resets alone do not evict them; tokens, app grants, and rules do the persisting.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Identity is the perimeter: revoke sessions and refresh tokens for affected accounts tenant-wide — a password change without revocation leaves the attacker logged in.&lt;/li&gt;&lt;li&gt;Persistence hides in four places: OAuth app grants, inbox rules and forwarding, new or elevated admin accounts, and changed federation or authentication settings. Check all four.&lt;/li&gt;&lt;li&gt;Export the audit logs now; default retention is short and the investigation depends on them.&lt;/li&gt;&lt;li&gt;Common entry: MFA-fatigue prompts, phished session tokens, and legacy protocols that bypass MFA entirely.&lt;/li&gt;&lt;li&gt;Scope what was read — mailboxes, files, sharing links — before declaring the incident closed; legal duties ride on that answer.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/cloud-tenant-compromise/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/cloud-tenant-compromise.png" type="image/png" length="121208" />
    </item>
    <item>
      <title>Business email compromise: the first 24 hours after wire fraud</title>
      <link>https://responsered.com/advisories/business-email-compromise-response/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/business-email-compromise-response/</guid>
      <pubDate>Thu, 05 Mar 2026 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Financial Fraud</category>
      <description>A payment went to a criminal account after an email that looked exactly right. Funds can sometimes be frozen — but the window is measured in hours, not days.</description>
      <content:encoded>&lt;p&gt;A payment went to a criminal account after an email that looked exactly right. Funds can sometimes be frozen — but the window is measured in hours, not days.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Call your bank's fraud line immediately and request a recall; ask them to alert the receiving bank. Every hour matters.&lt;/li&gt;&lt;li&gt;Report to law enforcement the same day — rapid-response programs (such as IC3's Recovery Asset Team in the US) can freeze funds, with the best odds inside 24–72 hours.&lt;/li&gt;&lt;li&gt;Do not delete the fraudulent emails. Their full headers prove how the fraud was routed.&lt;/li&gt;&lt;li&gt;Assume the mailbox is still compromised: check rules, forwarding, and connected apps before trusting it again.&lt;/li&gt;&lt;li&gt;Verify any &amp;quot;corrected&amp;quot; bank details by phone, using a number you already had on file — never one from the email.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/business-email-compromise-response/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/business-email-compromise-response.png" type="image/png" length="118606" />
    </item>
    <item>
      <title>Crypto wallet drained: trace it, report it, stop the bleeding</title>
      <link>https://responsered.com/advisories/crypto-wallet-drained/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/crypto-wallet-drained/</guid>
      <pubDate>Thu, 26 Feb 2026 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Crypto Theft</category>
      <description>The balance is gone in transactions you never signed — or one you did sign, without understanding what it approved. Reversal is rare; tracing and freezing are not hopeless.</description>
      <content:encoded>&lt;p&gt;The balance is gone in transactions you never signed — or one you did sign, without understanding what it approved. Reversal is rare; tracing and freezing are not hopeless.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Move whatever remains to a brand-new wallet — new seed phrase, created on a clean device — before anything else.&lt;/li&gt;&lt;li&gt;Record every transaction hash and destination address now; on-chain tracing is real, and exchanges can freeze funds that land with them.&lt;/li&gt;&lt;li&gt;Work out the how: a leaked seed phrase, a malicious token approval you signed, or malware on the device — each has a different cleanup.&lt;/li&gt;&lt;li&gt;Report to the exchanges on the fund path and to law enforcement with the hashes; speed improves the freeze odds.&lt;/li&gt;&lt;li&gt;Every &amp;quot;fund recovery expert&amp;quot; who contacts you or advertises to victims is a second scam.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/crypto-wallet-drained/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/crypto-wallet-drained.png" type="image/png" length="122226" />
    </item>
    <item>
      <title>Website defaced: restore it without erasing the way they got in</title>
      <link>https://responsered.com/advisories/website-defacement-response/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/website-defacement-response/</guid>
      <pubDate>Thu, 19 Feb 2026 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Web Attack</category>
      <description>Your homepage is showing someone else's message. The defacement is the visible symptom — the access that made it possible is the actual incident.</description>
      <content:encoded>&lt;p&gt;Your homepage is showing someone else's message. The defacement is the visible symptom — the access that made it possible is the actual incident.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Defacement is proof of write access to your site; the real question is what else that access reached — databases, customer data, other sites on the host.&lt;/li&gt;&lt;li&gt;Capture the defaced state and preserve server logs before any restore; the logs identify the entry point.&lt;/li&gt;&lt;li&gt;Entry is usually an unpatched CMS or plugin, stolen admin credentials, or a weak hosting account.&lt;/li&gt;&lt;li&gt;Restoring from backup without closing the hole invites re-defacement within days — often automated.&lt;/li&gt;&lt;li&gt;Check for webshells and new admin users; attackers leave doors behind the graffiti.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/website-defacement-response/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/website-defacement-response.png" type="image/png" length="116604" />
    </item>
    <item>
      <title>Ransomware attack: what to do in the first hour</title>
      <link>https://responsered.com/advisories/ransomware-first-hour/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/ransomware-first-hour/</guid>
      <pubDate>Thu, 12 Feb 2026 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Ransomware</category>
      <description>Screens are locked and a ransom note is on your systems. What you do in the first hour decides how much you recover — and how much evidence survives.</description>
      <content:encoded>&lt;p&gt;Screens are locked and a ransom note is on your systems. What you do in the first hour decides how much you recover — and how much evidence survives.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Disconnect affected machines from the network — but do not power them off. Memory can hold attacker artifacts and, in some cases, encryption keys.&lt;/li&gt;&lt;li&gt;Protect your backups before anything else. Attackers hunt backups during the attack, not after it.&lt;/li&gt;&lt;li&gt;Do not pay, reply to, or negotiate with the attackers before a professional assessment.&lt;/li&gt;&lt;li&gt;Do not wipe, rebuild, or restore onto affected systems — you may overwrite the only evidence of what was taken.&lt;/li&gt;&lt;li&gt;Photograph every ransom note and record the exact time you found it.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/ransomware-first-hour/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/ransomware-first-hour.png" type="image/png" length="119956" />
    </item>
    <item>
      <title>DDoS attack: your site is down and the traffic keeps coming</title>
      <link>https://responsered.com/advisories/ddos-attack-response/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/ddos-attack-response/</guid>
      <pubDate>Thu, 05 Feb 2026 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Availability</category>
      <description>The site is unreachable, monitoring is red, and traffic graphs are vertical. Mitigation lives upstream — and sometimes the flood is cover for something quieter.</description>
      <content:encoded>&lt;p&gt;The site is unreachable, monitoring is red, and traffic graphs are vertical. Mitigation lives upstream — and sometimes the flood is cover for something quieter.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Volumetric attacks are absorbed upstream — your hosting provider, CDN, or a DDoS-protection service — not by rebooting your servers.&lt;/li&gt;&lt;li&gt;If an extortion email arrived with the flood (&amp;quot;pay or it continues&amp;quot;), do not pay; payment reliably invites the next demand.&lt;/li&gt;&lt;li&gt;Watch authentication and admin logs during the noise — DDoS is sometimes a smokescreen for intrusion attempts.&lt;/li&gt;&lt;li&gt;Honest status updates to customers beat silence; outages are forgiven, stonewalling is not.&lt;/li&gt;&lt;li&gt;Capture traffic graphs and provider tickets as you go; they are the incident record and the insurance evidence.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/ddos-attack-response/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/ddos-attack-response.png" type="image/png" length="120039" />
    </item>
    <item>
      <title>Stolen laptop: from lost hardware to data exposure, and back</title>
      <link>https://responsered.com/advisories/stolen-laptop-data-exposure/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/stolen-laptop-data-exposure/</guid>
      <pubDate>Thu, 29 Jan 2026 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Device Loss</category>
      <description>A laptop is gone — car, café, airport. Whether this is a hardware receipt or a data breach depends mostly on one fact: was the disk encrypted?</description>
      <content:encoded>&lt;p&gt;A laptop is gone — car, café, airport. Whether this is a hardware receipt or a data breach depends mostly on one fact: was the disk encrypted?&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Full-disk encryption with a decent password turns a stolen laptop into a brick with resale value — establish encryption status first, everything else follows from it.&lt;/li&gt;&lt;li&gt;Trigger remote lock or wipe through your device management as soon as possible; it takes effect whenever the machine next comes online.&lt;/li&gt;&lt;li&gt;Rotate credentials and revoke sessions for accounts that were signed in — cached sessions can outlive the password that created them.&lt;/li&gt;&lt;li&gt;File the police report with the serial number; insurers and some recoveries depend on it.&lt;/li&gt;&lt;li&gt;An unencrypted disk with personal data on it is a notifiable-breach analysis, not just a loss.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/stolen-laptop-data-exposure/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/stolen-laptop-data-exposure.png" type="image/png" length="118460" />
    </item>
    <item>
      <title>Malware on a work device: the alert fired — now what</title>
      <link>https://responsered.com/advisories/malware-on-work-device/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/malware-on-work-device/</guid>
      <pubDate>Thu, 22 Jan 2026 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Malware</category>
      <description>The antivirus flagged something, or the machine started behaving strangely. What you do next either hands responders a clean picture or smears it.</description>
      <content:encoded>&lt;p&gt;The antivirus flagged something, or the machine started behaving strangely. What you do next either hands responders a clean picture or smears it.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Disconnect from the network but leave the machine powered on — the standing rule for preserving evidence.&lt;/li&gt;&lt;li&gt;Report to IT before attempting any cleanup; &amp;quot;I removed it myself&amp;quot; usually means the evidence is gone and the persistence is not.&lt;/li&gt;&lt;li&gt;An antivirus &amp;quot;threat removed&amp;quot; message is not an all-clear — loaders drop payloads that the first detection may have missed.&lt;/li&gt;&lt;li&gt;Every credential typed on that device recently should be treated as potentially captured.&lt;/li&gt;&lt;li&gt;Write down what you saw and when: the popup, the slowdown, the file you opened.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/malware-on-work-device/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/malware-on-work-device.png" type="image/png" length="118021" />
    </item>
    <item>
      <title>SIM-swap attack: your phone number was just stolen</title>
      <link>https://responsered.com/advisories/sim-swap-attack/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/sim-swap-attack/</guid>
      <pubDate>Thu, 15 Jan 2026 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Identity Fraud</category>
      <description>Your phone drops to &quot;No service&quot; and password-reset emails start arriving. Someone convinced your carrier to move your number — and every SMS code now goes to them.</description>
      <content:encoded>&lt;p&gt;Your phone drops to &amp;quot;No service&amp;quot; and password-reset emails start arriving. Someone convinced your carrier to move your number — and every SMS code now goes to them.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Sudden, unexplained loss of service plus reset emails is the signature — act in minutes, from another device.&lt;/li&gt;&lt;li&gt;Call the carrier's fraud line first and demand the number back and a freeze on further changes.&lt;/li&gt;&lt;li&gt;Until the number returns, every SMS code protects the attacker, not you — switch critical accounts to app-based MFA from a safe device.&lt;/li&gt;&lt;li&gt;Banking and crypto are the usual objective; alert your bank before the attacker gets there.&lt;/li&gt;&lt;li&gt;A port-out PIN or number-lock at the carrier prevents a repeat; SMS-based 2FA on critical accounts is the vulnerability that made this profitable.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/sim-swap-attack/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/sim-swap-attack.png" type="image/png" length="117490" />
    </item>
    <item>
      <title>Your social account is hijacked and messaging your followers</title>
      <link>https://responsered.com/advisories/social-media-account-takeover/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/social-media-account-takeover/</guid>
      <pubDate>Thu, 08 Jan 2026 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Account Takeover</category>
      <description>You are locked out, the profile is posting crypto scams, and your followers are getting DMs &quot;from you&quot;. Recovery and damage control have to run in parallel.</description>
      <content:encoded>&lt;p&gt;You are locked out, the profile is posting crypto scams, and your followers are getting DMs &amp;quot;from you&amp;quot;. Recovery and damage control have to run in parallel.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Start the platform's official recovery flow immediately — hijackers change recovery details fast, and the trail cools within hours.&lt;/li&gt;&lt;li&gt;Check the email account behind the profile first; it is the usual way in, and if it's compromised, recovery loops back to the attacker.&lt;/li&gt;&lt;li&gt;Warn your followers from any other channel you have — the hijacker's real target is usually them, not you.&lt;/li&gt;&lt;li&gt;For business profiles, check the ad account and stored payment methods; fraudulent ad spend is a common cash-out.&lt;/li&gt;&lt;li&gt;&amp;quot;Account recovery experts&amp;quot; advertising in replies and DMs are a second scam.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/social-media-account-takeover/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/social-media-account-takeover.png" type="image/png" length="121354" />
    </item>
    <item>
      <title>Your password showed up in a breach dump: what it really means</title>
      <link>https://responsered.com/advisories/credentials-on-dark-web/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/credentials-on-dark-web/</guid>
      <pubDate>Tue, 30 Dec 2025 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Credential Exposure</category>
      <description>A monitoring alert says your email and password are circulating. The danger is not the site that leaked — it is every other account where you reused that password.</description>
      <content:encoded>&lt;p&gt;A monitoring alert says your email and password are circulating. The danger is not the site that leaked — it is every other account where you reused that password.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The breached site is the smallest problem; credential-stuffing bots try that password against hundreds of other services within hours of a dump circulating.&lt;/li&gt;&lt;li&gt;Change the password everywhere it was reused — not just where it leaked. Reuse is the entire attack surface.&lt;/li&gt;&lt;li&gt;This is the moment to adopt a password manager: unique passwords end this class of problem permanently.&lt;/li&gt;&lt;li&gt;MFA on email, banking, and work accounts blunts stuffing attacks even where reuse existed.&lt;/li&gt;&lt;li&gt;Expect targeted phishing that quotes the leaked data to look credible.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/credentials-on-dark-web/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/credentials-on-dark-web.png" type="image/png" length="115484" />
    </item>
    <item>
      <title>After the fake support call: they had remote control of your computer</title>
      <link>https://responsered.com/advisories/tech-support-remote-access-scam/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/tech-support-remote-access-scam/</guid>
      <pubDate>Thu, 18 Dec 2025 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Scams</category>
      <description>A &quot;Microsoft technician&quot; or &quot;bank fraud team&quot; walked you into installing remote-access software. Everything on that machine — and every account it touched — now needs a reset.</description>
      <content:encoded>&lt;p&gt;A &amp;quot;Microsoft technician&amp;quot; or &amp;quot;bank fraud team&amp;quot; walked you into installing remote-access software. Everything on that machine — and every account it touched — now needs a reset.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Assume everything on the device was visible: saved passwords, banking sessions, files, email.&lt;/li&gt;&lt;li&gt;Disconnect the machine now and do your banking from a different device until this one is professionally cleaned.&lt;/li&gt;&lt;li&gt;Call your bank on the number on your card — especially if any payment, &amp;quot;refund&amp;quot;, or screen-share of your account happened.&lt;/li&gt;&lt;li&gt;The &amp;quot;accidental over-refund&amp;quot; they beg you to return is the core of the scam — it is your own money moved between your accounts.&lt;/li&gt;&lt;li&gt;Your number is now on a victim list; expect polished follow-up calls, including from the &amp;quot;refund department&amp;quot;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/tech-support-remote-access-scam/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/tech-support-remote-access-scam.png" type="image/png" length="117779" />
    </item>
    <item>
      <title>&quot;We recorded you&quot;: extortion emails, and how to tell bluff from breach</title>
      <link>https://responsered.com/advisories/extortion-email-hoax-or-real/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/extortion-email-hoax-or-real/</guid>
      <pubDate>Thu, 11 Dec 2025 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Extortion</category>
      <description>An email claims they hacked your webcam, shows you a real password, and demands cryptocurrency. Almost always it is a mass-mailed bluff — here is how to check, and what to do either way.</description>
      <content:encoded>&lt;p&gt;An email claims they hacked your webcam, shows you a real password, and demands cryptocurrency. Almost always it is a mass-mailed bluff — here is how to check, and what to do either way.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;These emails are sent in the millions. The password they show is nearly always from an old, public data breach — not from your device.&lt;/li&gt;&lt;li&gt;The convincing detail — your real password on screen — is the entire trick. It proves a website leaked years ago, nothing more.&lt;/li&gt;&lt;li&gt;Never pay and never reply; either marks your address as live and paying.&lt;/li&gt;&lt;li&gt;If the quoted password is still in use anywhere, change it there today and enable MFA.&lt;/li&gt;&lt;li&gt;Treat it as potentially real only if it shows something genuinely current: a recent password, actual file names, or real screenshots.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/extortion-email-hoax-or-real/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/extortion-email-hoax-or-real.png" type="image/png" length="118577" />
    </item>
    <item>
      <title>I clicked a phishing link: what actually happens now</title>
      <link>https://responsered.com/advisories/phishing-link-clicked/</link>
      <guid isPermaLink="true">https://responsered.com/advisories/phishing-link-clicked/</guid>
      <pubDate>Thu, 04 Dec 2025 08:00:00 GMT</pubDate>
      <dc:creator>Bob Vasic</dc:creator>
      <category>Phishing</category>
      <description>You clicked, maybe you typed a password — and now your stomach is in your shoes. What matters is the next ten minutes, not the last ten seconds.</description>
      <content:encoded>&lt;p&gt;You clicked, maybe you typed a password — and now your stomach is in your shoes. What matters is the next ten minutes, not the last ten seconds.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The essentials:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Clicking alone is rarely a compromise; entering credentials or running a download usually is. Be precise about which happened.&lt;/li&gt;&lt;li&gt;Change the exposed password now, from a different device, and revoke active sessions — attackers use stolen credentials within minutes, not days.&lt;/li&gt;&lt;li&gt;Report it to IT or security immediately. Speed is the single biggest factor in how small this stays.&lt;/li&gt;&lt;li&gt;Multi-factor authentication helps but does not make you safe: real-time phishing kits relay codes as you type them.&lt;/li&gt;&lt;li&gt;Write down exactly what you saw, clicked, and entered — that detail directs the whole response.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href=&quot;https://responsered.com/advisories/phishing-link-clicked/&quot;&gt;Read the full advisory on responsered.com&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <enclosure url="https://responsered.com/og/phishing-link-clicked.png" type="image/png" length="120868" />
    </item>
  </channel>
</rss>
