Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Why academic selfie fraud benchmarks fail in the real world

Academic deepfake datasets rarely static: generate an image, label it real or fake, done. Real-world fraud doesn't hold still. Zhaofeng Si, a PhD student at University at Buffalo and research scientist intern at Persona, breaks down the gap. Public academic datasets are mostly typical face swaps and diffusion-model-generated images with a fixed label. In the real world, there's an attack-and-defense loop. Fraudsters actively probe for ways to bypass detection, so defenses have to keep adapting instead of training against a static benchmark.

PoSA v1.11: Turning Fragmented Attack Signals Into Actionable Risk

With PoSA v1.11, we focused on a practical problem: detecting more attack activity does not necessarily help fraud and security teams make better decisions. PoSA already identifies activity across digital impersonation, credential theft, attacker devices and account access. The challenge is making the connections between that activity easier to understand, identifying which users and devices require attention, and making that intelligence available to the systems and teams responsible for responding.

The Rising Threat of Deepfakes: Why Organizations Must Rethink Trust

For decades, we believed that if could hear someone’s voice on a phone call or see them on a video call, they were who they said they were. What if that’s no longer true? This article is part of an ongoing series from Sophos frontline security operations specialists, sharing the expertise they use to strengthen our industry-leading Managed Detection and Response (MDR) service and defend customers against evolving AI Era threats.

iGaming Fraud Prevention: How to Protect Player Accounts Preemptively Without Adding Friction

iGaming fraud prevention does not have to mean applying more security checks broadly across the player journey. For player account takeover, the better objective is to obtain enough reliable risk context early enough to reserve additional checks for the accounts and access attempts that actually warrant them. The commercial stakes are growing alongside the market. U.S. iGaming revenue reached $10.73 billion in 2025, up 27.6% year over year, according to the American Gaming Association.

Cash App Scams: How to Spot Them Before You Lose Your Money

Cash App makes sending money instant — and that's exactly what scammers are counting on. Once a payment goes through, getting it back is nearly impossible. In this video, we break down the most common Cash App scams circulating right now: fake support agents, phishing texts and emails, payment reversal tricks, crypto investment fraud, and fake giveaways.

Brand Impersonation is moving into the App Store

Apple's 2025 App Store Transparency Report states that the company blocked over $2.2 billion in fraudulent transactions and removed roughly 59,000 apps for bait-and-switch tactics: publishing one thing to gain approval, then swapping in something else once the app goes live. The year before, fraud accounted for 38,315 of Apple's 82,509 total app removals, roughly 46%, making it the second-largest removal category that year. Google's numbers point in the same direction.

Online Gambling Fraud: How Fake Sites, Apps and Social Ads Divert Player Deposits

Online gambling fraud includes more than bonus abuse, payment fraud, account takeover and suspicious withdrawals on a genuine betting platform. Fake gambling sites, cloned apps and deceptive social ads can capture players before they reach that platform, diverting registrations, credentials and deposits into an attacker-controlled or unlicensed environment.

Social Engineering Campaign Uses Phony NDAs to Avoid Detection

Researchers at Gen Digital are tracking a sophisticated social engineering campaign that’s using phony NDA documents to trick employees into moving the conversation to WhatsApp and personal email accounts. The attackers targeted an employee at Gen itself, but the employee recognized that it was a scam and played along to see what the attackers would do. The threat actors first impersonated a real Gen executive based in Dublin, who introduced a second impersonated person who claimed to work at PwC.

Survey: Companies Cite Phishing as their Top AI-Enabled Fraud Concern

A recent survey from Experian found that 60% of companies report fraud losses that are “somewhat or significantly higher” than in previous years, with a majority of respondents citing AI-generated phishing attacks as their top AI-related fraud concern. “Businesses identify AI-generated phishing as the most common AI-enabled fraud risk at 53%,” the report says.