LIVE · cybersecurity feed
Live wire
Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context InjectionMalware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply ChainHow an Emerging Industrial Protocol Family Could Put OT at Risk14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentials
scammedium

Polite replies to wrong-number texts can confirm number validity for scammers

Engaging with unsolicited texts, even with a polite response like "wrong number," can inadvertently confirm your phone number is active and that you are receptive to communication. This makes your number more valuable to cybercriminals who may use it for future scams, as responsive numbers are worth more in criminal marketplaces. The initial text often serves as a simple test to gauge user engagement before deploying more targeted fraudulent activities.

zeroday.news ·

Replying to a "wrong number" text message, even with a polite correction, can inadvertently confirm the validity of a phone number and a user's responsiveness, making them a more valuable target for various scam operations. This initial interaction, while seemingly harmless, is often the first step in a sophisticated process designed to identify and exploit potential victims.

Cybercrime intelligence reports indicate that active and responsive phone numbers are significantly more valuable to criminal syndicates than inactive ones. The wrong-number text itself is typically not a phishing attempt or malware delivery, but rather a preliminary "personality test" to gauge a recipient's willingness to engage with strangers. Scammers often acquire phone numbers in bulk from data breaches for a minimal cost and already know if a message was delivered successfully. Their primary objective is to determine if a recipient is worth further investment of time and resources.

A polite reply provides three key pieces of information: the recipient is responsive, placing them in a top tier of active numbers; they are polite and willing to help a stranger, a trait scammers deliberately exploit; and they reply quickly, which can indicate how closely they monitor their phone and their likelihood of responding to future messages.

From this point, the interaction can evolve in two primary ways. In the "slow burn" scenario, the initial reply is followed by another message, often apologetic and friendly, such as "Oh no, I’m so sorry! But honestly, you seem like a really kind person. I’m Sarah, by the way." These early exchanges may be managed by artificial intelligence using open-source language models like Llama or Mistral, allowing scammers to handle thousands of conversations simultaneously. The AI assigns a real-time vulnerability score based on response time and message length. If a score crosses a certain threshold, a human operator takes over, continuing the conversation as if they had been present from the start. Over two to three weeks, this individual cultivates a friendly relationship, texting daily and sending stolen photos. Around the third week, they introduce a casual mention of a lucrative investment opportunity, often claiming significant earnings. If the target shows interest, they are directed to a fake trading platform. Initial small deposits may show fabricated gains, encouraging larger investments before the platform and the money disappear. The FBI’s Internet Crime Complaint Center (IC3) reported over $4.5 billion in losses from investment fraud in a single year, with victims of "pig butchering" scams (long-term romance/financial scams) experiencing average losses between $70,000 and $75,000.

In the "silent recycling" scenario, a recipient who replies "wrong number" but does not continue the conversation is categorized as active, responsive, and polite, but not susceptible to the initial wrong-number hook. Their number is then added to a cleaned database and either sold or reused for different scam campaigns. This could lead to subsequent texts offering fake job opportunities, package delivery notifications, or bank alerts, which victims may not connect to the initial wrong-number interaction. The first message serves as a sorting mechanism, with subsequent messages being the actual attack.

Common opening lines for these wrong-number scams are optimized for response rates and often involve scenarios such as a friend who doesn't exist ("Hey! See you tonight at 6?"), a concerned neighbor ("Sorry to bother you, I’ve noticed your dog sometimes runs into my yard."), a professional mix-up ("This is Mike from the office, did you get my earlier message?"), a family emergency ("Do you know Sarah? There’s been an emergency?"), or a recruiter ("Hi! I came across your profile, we have an incredible opportunity."). While genuine wrong numbers occur, if a conversation quickly shifts to small talk, personal questions, or encouragement to continue chatting, it is advisable to stop replying.

These messages are not typically sent by individual cybercriminals but are part of a highly organized criminal industry with global supply chains. For example, Cambodian and Chinese authorities arrested Chen Zhi, president of Prince Holding Group, in January 2026, accusing him of operating a network of scam compounds in Southeast Asia where thousands of trafficked individuals were forced to manage these conversations. These operations rely on underground marketplaces for resources ranging from phone lists and stolen identities to AI tools and fake investment websites. Blockchain analytics firm Elliptic estimated that the Huione Guarantee underground marketplace alone processed over $134 billion.

scamphishingcybercrimesms security
ShareXLinkedInWhatsAppFacebook

More News

view all →
malware

ToxicPanda Android malware uses VPN permissions to block Google Play

The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. [...]

iran

UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks

Hackers linked to Iran have successfully disabled a small UK power plant for four days, marking the first confirmed attack of its kind against the nation's energy infrastructure. The incident occurred concurrently with cyberattacks targeting water facilities across 12 US states. While the UK power plant's outage did not impact the national grid, the attack served as a demonstration of capability, with intentions likely focused on showcasing access rather than causing widespread disruption.

ransomware

Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Windows 11’s strongest security defenses can be bypassed without a screwdriver Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assume

aihigh

Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context Injection

Researchers at Adversa AI have developed a novel attack called Cryptographic Context Injection, which bypasses AI safety filters by embedding malicious instructions within AES-encrypted payloads. This technique tricks AI models like xAI's Grok and Google's Gemini into decrypting and executing these hidden commands. In the case of Grok, the attack can lead to zero-click theft of user chat histories and personal data by disguising the malicious payload as a webpage summary request.

breach

Welcoming the Sri Lankan Government to Have I Been Pwned

Today, we welcome the 48th government onboarded to Have I Been Pwned’s free gov service: Sri Lanka. Sri Lanka CERT now has access to monitor Sri Lankan government domains against the data in HIBP, helping identify exposed government accounts and respond when they appear in new data breaches.

security

Postal Service moves to finalize mail ballot regs before SCOTUS ruling

The rules have already been rejected by multiple state courts, but the Trump administration said it’s preparing in case of a favorable Supreme Court decision. The post Postal Service moves to finalize mail ballot regs before SCOTUS ruling appeared first on CyberScoop.