
Discover the latest online threats and cyber security trends impacting businesses and consumers worldwide, brought to you by F-Secure's threat intelligence specialists.
September's F‑Alert examines the evolving role of AI in cyber crime, from scam compounds and compromised streaming devices to new developments in autonomous AI agent cyber attacks. We also look at "gold bar" scams targeting older adults and a healthcare data breach affecting more than 1.2 million people, with expert insight and practical guidance on what these threats mean for consumers.
Last year, we reported on international crackdowns on Southeast Asia's scam compounds. But the criminal networks behind them remain active — and they're evolving. Joel Latto examines how these groups are adopting AI to increase the scale, sophistication, and efficiency of their operations.
Hugging Face has revealed new details about how an autonomous AI agent attacked its platform in July 2026. Megan Squire explores the new findings and what they could mean for consumers.
The New York City Police Department (NYPD) has warned older adults about a "gold bar" scam targeting their life savings. We explain how the scam works and what consumers can do to protect themselves.
Medical billing firm Medical Computer Business Services (MCBS) recently disclosed that a 2025 data breach exposed the data of more than 1.2 million people. We explain what data was exposed and what those who may have been affected should do.
New research shows how cheap H96 Android TV streaming devices are being secretly exploited for proxy services and ad fraud, generating tens of thousands of dollars a day. Joel Latto examines the role of AI in the operation and what it reveals about the evolving threat posed by compromised consumer devices.
Raids Haven't Stopped Scam Compounds — They’re Evolving
International crackdowns on Southeast Asia's scam compounds have not stopped the criminal networks behind them. Instead, new evidence shows how they are adopting AI across the scam process to increase the scale, sophistication, and efficiency of their operations.
Key facts:
AI is being used to create fake online personas, generate and translate messages, produce promotional content, bypass banking identity checks, and assist with day-to-day operations. Emerging tactics include real-time face swapping, while some groups are developing and selling their own AI tools rather than relying solely on commercially available technology.
These criminal networks are also expanding their human trafficking operations. People from at least 80 countries and territories have been identified in scam compounds, with recruitment networks spanning Asia, the Middle East, and Africa, and deceptive job offers increasingly reaching Europe and North America.
Agentic AI could be the next evolution, allowing criminal groups to automate multiple stages of a scam — from identifying and contacting victims to social engineering and stealing and laundering funds — with minimal human involvement.
International police raids targeting scam compounds haven't stopped the criminal networks behind them. If anything, these operations appear to be growing. Generative AI allows them to scale and localize scams for targets around the world. Agentic AI could be the next technological frontier — for criminals as much as for defenders.
Joel Latto, Threat Advisor at F‑Secure

AI Agents Are Changing the Rules of Cyber Defense
AI company Hugging Face has released more technical details about the July 2026 incident in which an autonomous AI agent driven by an OpenAI pre-release model attacked its platform. The new analysis shows how the agent exploited vulnerabilities while carrying out thousands of actions at machine speed, and how Hugging Face used AI to forensically reconstruct and understand the attack.
Key facts:
Unlike known attacks, novel attacks like this may have no known "signature" for defenders to detect and understand what is happening.
Instead, evidence of the attack was scattered across thousands of individual actions and low-signal events. To find the needle in the haystack, Hugging Face used AI to correlate activity across several systems and reconstruct around 17,600 attacker actions.
This shifts defense from identifying known threats to detecting patterns of abnormal behavior. With autonomous agents capable of executing thousands of actions at machine speed, defenders increasingly need AI to detect and respond at the same pace.
As we've said before, even though this incident affected a company, as the cost of AI‑enabled attacks goes down, we expect consumers and small businesses to eventually become targets. This kind of sophisticated monitoring and behavioral spotting isn't something consumers can or should have to do themselves. In the AI agent era, products and platforms need to take on more of the responsibility for keeping consumers safe.
Dr. Megan Squire, Principal Threat Intelligence Researcher at F‑Secure

"Gold Bar" Scam Targets Older Adults
What's happening:
The New York City Police Department (NYPD) has warned older adults about a "gold bar" scam targeting their life savings.
The scam begins with a pop-up claiming the victim's computer or bank account has been compromised. Scammers convince victims to provide remote access to their device, access their bank accounts, and create fake evidence of hacking. Victims are then connected to someone posing as law enforcement, who tells them to "protect their life savings" by converting their money into gold and handing it to a courier for safekeeping. Victims are also told not to inform their bank or family.
Over the past two years, the NYPD has investigated more than 100 cases, with losses exceeding $100 million.
What to do:
Individuals should never give remote computer access to someone they don't know or move money at the request of an unsolicited caller. If someone claims there is a problem with their account, they should hang up and call their bank using the number on their bank statement.
People who receive suspicious messages should report them to the Attorney General's office and their local NYPD precinct.
Medical Billing Firm Breach Exposes Data of 1.2M People
What's happening:
Medical billing firm Medical Computer Business Services (MCBS) recently disclosed that a 2025 data breach exposed the data of more than 1.2 million people.
MCBS processes and manages patient records on behalf of healthcare providers, providing billing, financial, and other administrative services. An investigation found that data including names, addresses, Social Security numbers, health insurance details, and medical histories may have been exposed.
The notice names seven healthcare providers whose patient data MCBS handled, including South Georgia Radiology Consultants, SkinPath Solutions, and Stephen W. Brown and Radiology Associates of Augusta.
What to do:
People who have received medical care in Georgia should contact their healthcare provider to check whether it uses MCBS and whether their personal information may have been affected.
Those who believe they were affected should place a fraud alert on their credit report and consider a security freeze.
H96 Streaming Sticks Fuel $50K-a-Day Scam Operation
New research shows how cheap H96 Android TV streaming devices are being secretly exploited for proxy services and ad fraud, generating tens of thousands of dollars a day. The operation uses AI‑generated websites and automated ad clicks to profit from fake ad traffic, highlighting the evolving threat posed by compromised consumer devices.
Key facts:
The devices perform two hidden functions. When the TV is on, they typically act as residential proxies, allowing anonymous paying customers — potentially including bad actors — to route internet traffic through the user's home connection. When the TV is off, they switch to ad fraud.
For the ad fraud, devices disguise themselves as mobile phones and visit AI‑generated websites, where bots navigate pages and click ads to generate fraudulent revenue. Multiple vision and reasoning systems help the bots identify and interact with ads like human users.
Researchers identified around 38,000 H96 devices worldwide communicating with just one domain, estimating that the ad fraud alone generates nearly $50,000 a day. The real scale could be significantly larger, as this estimate does not include revenue from the residential proxy operation.
A cheap streaming stick might seem harmless, but consumers could unknowingly be providing the infrastructure for criminal activity through their own internet connection. AI is making these schemes increasingly automated and scalable, showing how even everyday connected devices can become part of a much bigger criminal operation. Consumers should stick to reputable, certified devices that receive regular security updates.
Joel Latto, Threat Advisor at F‑Secure
