One smart solution for total online safety.

Joined September 2019
694 Photos and videos
Pinned Tweet
Lovable builds the future. Guardio scans it when it goes live. You won’t see it. You won’t feel it. But without it? You’d be clicking into scams built by AI all day long. Introducing the new integration between Guardio and Lovable - making the web a cleaner, safer place for everyone. @lovable
10
27
176
257,744
Scammers aren't waiting for kickoff. Our team spotted a rise in newly registered domains containing the words "FIFA" and "World Cup." A significant portion of them are malicious and are being blocked by Guardio. These include crypto scams using World Cup branding to appear legitimate, fake merchandise sites, suspicious betting platforms, and fake ticket resellers. Be on the lookout whenever you're engaging with similar websites, and only use trusted sources and websites you know and trust
2
22,026
Think you can spot a fake website in 2026? 👀 Scammers are now using AI to perfectly clone official platforms, making them nearly impossible to tell apart. Watch our updated YouTube guide to learn the exact red flags to look for before you click youtube.com/watch?v=ssYpNs_w…
2
2
179
Scammers keep finding creative ways exploit AI tools and hack people's accounts. Make sure you enable 2FA and keep an eye out for any suspicious account activity
Today Instagram had this massive exploit where hackers were just stealing rare handles left and right. Hundreds of accounts gone. People losing handles they’ve owned since 2010, some worth hundreds of thousands. I own a few rare ones so I was actually stressed watching this happen in real time, which I haven’t been in years. Obama White House account got hit. These aren’t some random new accounts, these are verified, locked down accounts and they still got compromised. The thing is the exploit is so simple it’s almost funny. Attacker goes to Forgot Password, says their account is hacked, turns on a VPN to match the target’s location (which now you can find on the about section of the page). Instagram’s AI support flow asks them to verify with a selfie. They grab a photo from the target’s profile, run it through an AI video generator to make an animation of the person’s face moving around, upload that to Meta’s AI as proof. And Meta’s AI just accepts it because it can’t tell the difference between a real selfie and an AI-generated video of someone’s face . Once verified they change the email to theirs. Password reset link goes to their email. They own it now. 2FA gets bypassed somehow in the process but honestly I don’t know exactly how, just that it did. Point is even locked down accounts went down. Then you try to recover your account and you’re talking to a chatbot that has zero ability to help. You can’t escalate to a human. You’re just stuck. Your asset is gone and there’s no one to call. The whole thing just highlighted how stupid it is to automate account security without any human in the loop. One AI fooling another AI while there’s literally no person anywhere to catch it. Meta took hours to even acknowledge it while accounts were getting stolen every minute. Now thankfully it’s patched but I don’t think it will be the last one. Stay safe!
2
233
Falling for scams
Fastest way to go broke?
1
141
The Canvas breach is the kind of cyber story that spreads fast for a reason - millions of users, a well-known hacking group, and a platform used by schools and universities worldwide. Here’s the full breakdown 👇
2
234
Nobody will remember: - your salary - how “busy you were” - how many hours you worked People will remember: - that time you clicked on a phishing email and infected the entire company with malware
3
153
Every scammer's dream
🤯 This is scary good for something rendering in real time. Selfie-based liveness checks ask for a fixed set of motions: head turn, blink, close approach to the camera. This demo nails all of them, including the part that usually breaks for synthetic faces (skin micro-texture and forehead wrinkles holding up at close range). Without the side-by-side at the bottom, you wouldn't know it's not Will Smith. Source: Incognia
1
231
Fake websites are getting harder to spot - and scammers are counting on that. Save this guide before you need it 👇 youtu.be/My1xVSiYdqM?si=T8O9…

198
“Your Oral-B dental kit is waiting” If you recently got a message like this from "UnitedHealthcare" ,it’s a phishing scam designed to steal your crefit card information 🧵
1
184
These messages usually claim you’ve won a free product and just need to “pay for shipping” In reality, the link leads to a fake UnitedHealthcare website that asks for your credit card info - and you’ll likely never receive anything while your details are put at risk
2
1
145
These scammers are also impersonating @UHC, adding another layer of “legitimacy” to trick people into trusting it. Did you get this scam text?
102
Thanks for covering our fake Amazon texts scam warning @JohnMatarese!
How to know if an Amazon message about a safety recall is real… or a scam: wcpo.com/money/consumer/dont… @WCPO @GuardioSecurity #SCAM #consumer #Amazon
1
5
268
Read more about these new findings by @GuardioLabs on @BleepinComputer 👇
Hackers abuse Google ads for GoDaddy ManageWP login phishing bleepingcomputer.com/news/se… bleepingcomputer.com/news/se…
1
171
Guardio retweeted
Still Google for your account login? Beware not to "WrongPress"! We found yet another Google Ads phish, this time abusing search results for ManageWP, GoDaddy's WordPress admin platform. The fake result sits right on top of the real one, and one click later you're in an AiTM (Adversary in the Middle) trap that hijacks your account 👉 more...
1
2
5
3,977
Our latest @GuardioLabs research on @TheHackersNews
🛑 30,000 Facebook accounts compromised in a phishing campaign using Google AppSheet emails. A Vietnamese-linked operation called AccountDumpling targeted Facebook Business users, stole credentials, sent data to Telegram, and resold accounts. Read: thehackernews.com/2026/05/30…
1
1
217
Learn all about our new @GuardioLabs research on @CyberInsidercom 👇
Google AppSheet abused to compromise 30,000 Facebook accounts #Google #AppSheet #Facebook cyberinsider.com/google-apps…
161
Guardio retweeted
On the menu in Vietnam: pho, banh mi, dumplings... and 30,000 hijacked Facebook business accounts 🥟 Meet "AccountDumpling": phishing sent straight through Google's own infrastructure. Yum. Looks like it's a serious business over there. Steal the account. Resell it. Fabricate fake identities. Sell "recovery" right back to the victim for a fee and even more shenanigans. Brilliant deep-dive research by our own @shaked__chen! Learn how they abused Google to send phishing emails, so many methods and tricks they used along the way, and the mistakes they made that helped us catch them red-handed and reach victims in time to save what could still be saved. (link to full research in reply...)
2
5
21
305,914
Introducing ״AccountDumpling״ - Google-sent phishing that's hijacked over 30K Facebook accounts. The emails weren't spoofed. They were authenticated, signed, and delivered by Google - because the attackers abused Google AppSheet as a relay. Every spam filter waved them through. Our team at Guardio Labs pulled on every thread: fake login pages, a stolen-account storefront, Telegram bot infrastructure, and a real name the attacker left behind in a PDF they forgot to scrub. We mapped the victims and reached out to thousands of them directly, before more damage was done. The operation is still active - here’s the full breakdown: guard.io/labs/accountdumplin…
1
5
16
339,033
Guardio retweeted
NoMetaWhat. Ever got a phishing email from Meta that actually came from Facebook ?! Oh No.. Attackers abuse Facebook Business Manager to send real emails from noreply@business.facebook.com, then stuff the invite with their own sender name, urgency bait, and a clickable phishing link! DKIM, SPF, DMARC all pass. Of course they do. 👉 more...
1
4
6
356