Cyber scams to watch out for right now
Cybercriminals are becoming increasingly convincing. They are no longer relying on obviously suspicious emails or poorly written messages – they are using trusted brands, AI-generated content and fake software updates to catch people off guard.
Here are three scams businesses and employees should be watching out for.
Claude/ChatGPT/YouTube scam
This is how it goes:
You search something normal like “how to free up disk space on Mac.”
Google comes up with a ChatGPT conversation with step-by-step instructions. It’s on the actual ChatGPT website and looks completely legit.
The instructions tell you to open Terminal, paste a command, and enter your password.
You do it. Because why wouldn’t you?
And just like that, you’ve handed over access to your machine.
The attacker created a shared conversation designed to rank in Google and target the exact workflow you’d trust.
Another example:
Advert: Claude Pro costs $20/month.
But here’s how you can get it for free…
Head over to the mentioned YouTube tutorial.
Open Command Prompt.
Paste the line he provides.
Ignore the weird AI-generated mannerisms.
And just like that, you gave a scammer access to your computer.
Hackers are building AI-generated YouTubers to run scams like this.
This video has 34k+ views, 2k likes, and comments saying it worked. It’s all bots.
One rule that will save you: Never paste something into Command Prompt or Terminal if you don’t actually understand it yourself.
The fake DocuSign link
One phishing email almost cost an accounting firm everything.
Jodi, the firm’s founder, received what she didn’t realize was a fake DocuSign.
The night before, her favourite team won the championship and she was running on fumes when the email hit her inbox.
So she clicked.
By the end of the workday her email froze. Then her computer locked her out entirely. A threat actor was logged in from Canada, with access to everything from financial records to sensitive data.
Huntress software flagged the sus VPN login automatically.
Dave, head of the firm’s trusted MSP, got the alert mid-carpool. By the time he walked through his front door, Huntress had already kicked the attacker out and locked down the tenant.
Jodi’s words when the forensic audit came back clean: “You guys saved my company.”
When you’re not at your best, the basics can help keep you safe:
1. Conditional access policies, especially on sensitive accounts
2. MFA enabled and enforced across the board
3. Unique passwords, keeping corporate and personal accounts separate
Phishing only has to work once.
The fake Microsoft Teams update
Another clever trick is pretending that your usual Microsoft Teams or video-conferencing software needs an urgent update.
Huntress software has identified attacks where criminals create convincing fake video-conference pages and use them to push malicious “mandatory” app or driver updates.
You might see a message saying your Teams version is outdated and that you need to install an update before you can continue. The download, however, may contain malware or give an attacker a foothold on your computer.
Remember: Don’t download updates from unexpected pop-ups, messages or unfamiliar websites. Use your normal software update process or go directly to the official vendor.
The common thread
These scams all rely on the same thing: trust.
A familiar logo. A convincing video. A Teams update that looks completely normal.
The technology behind the attack may be sophisticated, but the best defence is still simple: stop, check and verify before you click or install.
If something feels unusual – even if it looks completely legitimate – ask your IT or security team before taking action.
Source: Huntress