Visualização normal

Antes de ontemMalwarebytes
  • ✇Malwarebytes
  • Watch out for fake TikTok Shops trying to steal your money
    TikTok Shop is a real, functioning e-commerce feature built into the TikTok app, allowing users to buy goods without ever leaving TikTok. As it’s grown in popularity, scammers have begun cloning its appearance.Storefronts that reproduce its look, its trust badges, and its category layout closely enough to pass a quick glance are showing up as entirely separate, unverified websites. The short version If a shopping site looks like TikTok Shop but you didn’t reach it from inside the actual Ti
     

Watch out for fake TikTok Shops trying to steal your money

11 de Agosto de 2026, 06:05

TikTok Shop is a real, functioning e-commerce feature built into the TikTok app, allowing users to buy goods without ever leaving TikTok. As it’s grown in popularity, scammers have begun cloning its appearance.Storefronts that reproduce its look, its trust badges, and its category layout closely enough to pass a quick glance are showing up as entirely separate, unverified websites.

The short version

If a shopping site looks like TikTok Shop but you didn’t reach it from inside the actual TikTok app, treat it as an unknown third-party store, not an extension of TikTok. It might look like TikTok, but it’s the same risks as any sketchy online shop: paying for something that never arrives, or handing over card details to a site with no accountability behind it.

Fake TikTok Shops

Clone sites in this category tend to reproduce TikTok Shop’s homepage design closely enough that, at a glance, they could pass for the real thing.

They have matching color schemes, matching layout, and language borrowed directly from the platform, such as “curated products,” “trusted sellers,” and “secure service.”

Underneath, they typically show the same kind of reassurance badges the real platform uses: claims of platform-verified sellers, local delivery guarantees, and after-sales support windows.

A fake TikTok shop

None of that trust signaling is backed by anything. It’s copied language and copied visual design sitting on top of a site with no verified relationship to TikTok at all. Scammers borrow the legitimacy that TikTok Shop has built up, then use it to move products—or simply take payment—through a storefront TikTok has no oversight of.

Wholesale stores and fake loan offers

A related version of this scam leans into bulk or wholesale pricing, offering goods across categories like fashion, home, and beauty, again wrapped in TikTok’s name and logo. Some of these sites go a step further and add a consumer credit or “loan service” option directly into the site navigation, sitting alongside ordinary shopping categories.

A TikTop Shop "wholesale site" scam

A legitimate wholesale marketplace doesn’t typically need to offer consumer credit as a checkout feature. When it does, it’s worth treating as a separate red flag from the shopping itself. Loan applications typically ask for far more sensitive information than a purchase does, including identity documents, banking details, and other personal data. Handing that information to a site that’s already impersonating a major platform significantly increases the risk of fraud or identity theft.

The checkout is the real risk

Both scams point to the same underlying concern: it’s not really about whether the products are real. It’s about what happens when you enter payment information into a storefront with a fake identity and no accountability. The order may never arrive, leaving you out of pocket, and your payment details themselves could be stolen, reused, or resold.

How to stay safe

  • Only use TikTok Shop from inside the official TikTok app, not a link from an ad, DM, or search result.
  • Always check a website’s address before entering any payment information. A convincing homepage doesn’t mean a legitimate business sits behind it.
  • Be skeptical of any shopping site that also pushes a loan, credit line, or financing offer at checkout.
  • Pay with a credit card rather than a bank transfer where possible. It gives you a dispute path if the order never shows up.

Brand impersonation is one of the oldest tricks in e-commerce fraud. TikTok Shop’s badge system and trust language are simply the latest assets being borrowed.


Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

  • ✇Malwarebytes
  • Deepfake porn sites are going offline (re-air) (Lock and Code S07E12)
    This week on the Lock and Code podcast… If you weren’t taking deepfakes seriously before, it’s too late now to ignore them. According to new research from Malwarebytes, one in three people who use AI every day said it’s okay to generate pornography of people without their consent. Nearly 10 years ago, “deepfake” technology provided hobbyists and film editors with artificial intelligence (AI) tools to swap the face of one person onto the body of another. In its infancy, this technology
     

Deepfake porn sites are going offline (re-air) (Lock and Code S07E12)

15 de Junho de 2026, 11:32

This week on the Lock and Code podcast…

If you weren’t taking deepfakes seriously before, it’s too late now to ignore them.

According to new research from Malwarebytes, one in three people who use AI every day said it’s okay to generate pornography of people without their consent.

Nearly 10 years ago, “deepfake” technology provided hobbyists and film editors with artificial intelligence (AI) tools to swap the face of one person onto the body of another. In its infancy, this technology brought silly film experiments like swapping Tom Cruise in Mission Impossible with Keanu Reeves. Today, this same technology produces something far more harmful—fake nude images of teenagers.

On the Lock and Code podcast today with host David Ruiz, we are re-visiting an interview from 2024, in which we spoke with a lawyer named David Chiu about his lawsuit against 16 deepfake nude generation websites.

The websites named in that lawsuit often needed just one image of a person to generate fake pornography. And while nearly everyone has at least one image of themselves online, even if they had hundreds, the path towards deletion is somewhat understood—start by deactivating and deleting popular social media accounts. But for teenagers today, raised mostly online, and who share images directly with friends and boyfriends and girlfriends and exes, it’s likely impossible to remove every visual trace of themselves. Also, they shouldn’t have to face this problem alone.

The Lock and Code podcast frequently discusses structural problems that require individual management. You have to skirt corporate data collection. You have to find the automated license plate readers in your hometown. You have to review every single message you get with a certain antagonism, to guard yourself against scams.

So, it’s rare to encounter a solution that benefits more than one person.

Chiu serves as the City Attorney for San Francisco, which means his department can file a lawsuit on behalf of not just the people of San Francisco, but also California, and that’s what his team did in going after the deepfake websites.

Since then, Chiu’s department has shut down 10 deepfake nude websites, and it received a settlement agreement from a company called Briver LLC to no longer operate any website that creates nonconsensual deepfake pornography.

And, as California goes, so goes the nation.

In May of last year, the Take It Down Act became effective as law in the United States, which criminalizes “revenge porn” and AI-generated nonconsensual intimate imagery. The law is not perfect but so far it is being used as intended. Last month, two men in the US were among the first to be charged with violating the Take It Down act for allegedly creating deepfake nudes that, according to the AP, “included both celebrities as well as private women, including recent high school graduates.”

Today, we revisit our conversation with San Francisco City Attorney David Chiu about the important fight against deepfake porn and the clear threat that his department found against the public.

“At least one of these websites specifically promotes the non-consensual nature of this. So, and I’ll just quote, ‘Imagine wasting time taking her out on dates when you can just use website X to get her nudes.'”

Tune in today to listen to the full conversation.

Show notes and credits:

Intro Music: “Spellbound” by Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 4.0 License
http://creativecommons.org/licenses/by/4.0/
Outro Music: “Good God” by Wowa (unminus.com)


Listen up—Malwarebytes doesn’t just talk cybersecurity, we provide it.

Protect yourself from online attacks that threaten your identity, your files, your system, and your financial well-being with our exclusive offer for Malwarebytes Premium Security for Lock and Code listeners.

  • ✇Malwarebytes
  • 88% of people struggle to tell what’s real online
    What would you trade for a technology that can do almost anything? For many people, the answer is clear: Everything they thought they could trust.In a few, short years, Artificial Intelligence (AI) tools have granted people unfettered access to easier writing, faster image generation, quicker coding, and near-instantaneous answers, advice, and information—advantages they value and want. But the same tools that can spruce up a dating profile or reimagine an old photograph can also manipulate the
     

88% of people struggle to tell what’s real online

10 de Junho de 2026, 08:45

What would you trade for a technology that can do almost anything? For many people, the answer is clear: Everything they thought they could trust.

In a few, short years, Artificial Intelligence (AI) tools have granted people unfettered access to easier writing, faster image generation, quicker coding, and near-instantaneous answers, advice, and information—advantages they value and want. But the same tools that can spruce up a dating profile or reimagine an old photograph can also manipulate the broader world online, and people are noticing.

According to new research from Malwarebytes, 88% of people said it’s becoming harder to tell what content online is genuinely human or real, with 84% saying that “convincing video evidence” no longer feels like proof. Further, 85% said it can be hard to tell scams apart from the real thing—a major uptick from the 66% who said the same thing last year.

Statistics from the Face Value report

These are the first signs of AI’s counterfeit world. Replete with fake websites, fake products, fake videos, fake pictures, fake voices, and even fake people, it is threatening to swallow the web.

The latest report from Malwarebytes, Face value: How AI is reshaping trust, identity, and scams exposes the hidden cost of AI on the public: an excess of fraud that is dismantling trust in reality and in one another.

The damage arrives in large moments and small, from the US parent who said they “received a voicemail that sounded exactly like my son’s voice, saying he was in trouble and needed money for legal fees,” to the two entirely unrelated respondents fooled by the same AI-generated video of rabbits bouncing on a trampoline, to the individual worried about “my grandfather showing me AI slop and he thought it was real.”

For this research, Malwarebytes surveyed 1,500 adults aged 18 and older across the US, UK, Austria, Germany, and Switzerland about their uses, feelings, and concerns regarding AI. The sample was equally split for gender with a spread of ages, geographical regions, and race groups, and weighted to provide a balanced view.

The complete findings can be found in the full report:

Here are some of the key takeaways and findings:

  • 88% said it’s becoming harder to tell what content online is genuinely human or real
  • 84% said convincing video evidence no longer feels like proof 
  • 85% of people said it’s hard to tell a scam from the real thing (up from 66% last year)
  • 50% have experienced some form of AI fraud or scam, such as being misled by AI-generated photos of products or receiving a highly personalized scam message
  • 19% have specifically experienced some form of AI-driven identity harm, including the 10% who have had someone use AI to generate sexually explicit content of them without permission
  • 81% fear someone stealing their family’s likeness, yet only 13% have created a family codeword to guard against it
  • 67% worry about voice cloning, yet only 19% have turned off voicemail recordings to prevent it
  • 45% say it’s okay to use AI for personal emotional tasks (like writing wedding vows or a eulogy)
  • 34% say it’s okay to use AI to help create or improve a dating profile
  • One in three self-avowed daily users of AI said it’s okay to generate explicit images of someone without their consent 

Defeat would be the wrong lesson to take from all this. It is true now that the internet requires assistance, but there are plenty of safe places to seek help.

While Malwarebytes works to provide new tools, we’d like to remind both the AI anxious and the eager about the first rule of the internet: Remember the human. People’s voices, bodies, choices, and agency belong to them and them alone. 

As for every fake video, product, website, and image, understand that there’s help. No one needs to navigate an artificial internet alone. Whether through scam detection, identity protection, and simple awareness, people have more options than they may realize.

  • ✇Malwarebytes
  • A week in security (May 25 – May 31)
    Last week on Malwarebytes Labs: Payment apps are watching what you say (Lock and Code S07E11) Scammers pretending to be Microsoft had help from US executives 700+ education and tech websites hijacked in huge ClickFix malware campaign Fake software on GitHub and SourceForge distribute Deno RAT Fake LinkedIn emails abuse Adobe to track victims Company bragged phone mics could listen to conversations. They couldn’t. Kali365 phishing kit bypasses MFA and steals Microsoft logins
     
❌
❌