Security researchers have identified a new wave of dating app scams leveraging AI to create fraudulent profiles and fake video calls designed to deceive users into sending money.
Security researcher Matthew Gore-Kormanik discovered the scheme while analyzing a fraudulent app called Dora. After receiving a message from a profile named Jennifer—a 41-year-old woman with detailed biographical information—Gore-Kormanik accepted a video call.
Instead of seeing the person described in the profile, Gore-Kormanik encountered a video feed showing only a moving tapestry and heard distorted audio in the background. The incident revealed how scammers are deploying AI-generated profiles and manipulated video feeds to impersonate attractive matches.
These scams typically follow a pattern: users match with AI-generated profiles, receive calls with fake or obscured video feeds, and are eventually asked to transfer money under various pretexts. The use of AI-generated personas and deepfake-adjacent technology makes these schemes increasingly difficult for users to identify.
Experts recommend verifying matches through multiple communication channels and remaining skeptical of profiles requesting money transfers.
A banking malware operation has been deploying a toolkit called KREMLIN since mid-2025 to bypass browser security checks and force-install malicious extensions on Chrome and Edge browsers. The extensions target user credentials and session tokens.
The ShinyHunters hacking group has published thousands of drivers' personal records after breaching Florida's motor vehicle database. The leak follows the gang's failed ransom demand to the state agency.
Data broker Radaris.com has lost its domains after a New Jersey court ruling in a privacy violation case. The company faced legal action for publishing personal information on state law enforcement officials in violation of state privacy law.
Spain's data protection agency has received its first report of a cyberattack carried out using an AI agent powered by a large language model. The breach marks a new category of security threat for regulators.