Skip to main content

Choose your country

Report

F-Alert US Cyber Threats Bulletin September 2026

Discover the latest online threats and cyber security trends impacting businesses and consumers in the United States, brought to you by F-Secure's threat intelligence specialists. 

September's F‑Alert examines the evolving role of AI in cyber crime, from scam compounds and compromised streaming devices to new developments in autonomous AI agent cyber attacks. We also look at "gold bar" scams targeting older adults and a healthcare data breach affecting more than 1.2 million people, with expert insight and practical guidance on what these threats mean for consumers.

Raids Haven't Stopped Scam Compounds — They’re Evolving

International crackdowns on Southeast Asia's scam compounds have not stopped the criminal networks behind them. Instead, new evidence shows how they are adopting AI across the scam process to increase the scale, sophistication, and efficiency of their operations.

Key facts:

  • AI is being used to create fake online personas, generate and translate messages, produce promotional content, bypass banking identity checks, and assist with day-to-day operations. Emerging tactics include real-time face swapping, while some groups are developing and selling their own AI tools rather than relying solely on commercially available technology.

  • These criminal networks are also expanding their human trafficking operations. People from at least 80 countries and territories have been identified in scam compounds, with recruitment networks spanning Asia, the Middle East, and Africa, and deceptive job offers increasingly reaching Europe and North America.

  • Agentic AI could be the next evolution, allowing criminal groups to automate multiple stages of a scam — from identifying and contacting victims to social engineering and stealing and laundering funds — with minimal human involvement.

International police raids targeting scam compounds haven't stopped the criminal networks behind them. If anything, these operations appear to be growing. Generative AI allows them to scale and localize scams for targets around the world. Agentic AI could be the next technological frontier — for criminals as much as for defenders.

Joel Latto, Threat Advisor at F‑Secure

AI Agents Are Changing the Rules of Cyber Defense

AI company Hugging Face has released more technical details about the July 2026 incident in which an autonomous AI agent driven by an OpenAI pre-release model attacked its platform. The new analysis shows how the agent exploited vulnerabilities while carrying out thousands of actions at machine speed, and how Hugging Face used AI to forensically reconstruct and understand the attack. 

Key facts:

  • Unlike known attacks, novel attacks like this may have no known "signature" for defenders to detect and understand what is happening.

  • Instead, evidence of the attack was scattered across thousands of individual actions and low-signal events. To find the needle in the haystack, Hugging Face used AI to correlate activity across several systems and reconstruct around 17,600 attacker actions.

  • This shifts defense from identifying known threats to detecting patterns of abnormal behavior. With autonomous agents capable of executing thousands of actions at machine speed, defenders increasingly need AI to detect and respond at the same pace.

As we've said before, even though this incident affected a company, as the cost of AI‑enabled attacks goes down, we expect consumers and small businesses to eventually become targets. This kind of sophisticated monitoring and behavioral spotting isn't something consumers can or should have to do themselves. In the AI agent era, products and platforms need to take on more of the responsibility for keeping consumers safe.

Dr. Megan Squire, Principal Threat Intelligence Researcher at F‑Secure

"Gold Bar" Scam Targets Older Adults

What's happening:

  • The New York City Police Department (NYPD) has warned older adults about a "gold bar" scam targeting their life savings.

  • The scam begins with a pop-up claiming the victim's computer or bank account has been compromised. Scammers convince victims to provide remote access to their device, access their bank accounts, and create fake evidence of hacking. Victims are then connected to someone posing as law enforcement, who tells them to "protect their life savings" by converting their money into gold and handing it to a courier for safekeeping. Victims are also told not to inform their bank or family.

  • Over the past two years, the NYPD has investigated more than 100 cases, with losses exceeding $100 million.

What to do:

  • Individuals should never give remote computer access to someone they don't know or move money at the request of an unsolicited caller. If someone claims there is a problem with their account, they should hang up and call their bank using the number on their bank statement.

  • People who receive suspicious messages should report them to the Attorney General's office and their local NYPD precinct.

Medical Billing Firm Breach Exposes Data of 1.2M People

What's happening:

  • Medical billing firm Medical Computer Business Services (MCBS) recently disclosed that a 2025 data breach exposed the data of more than 1.2 million people.

  • MCBS processes and manages patient records on behalf of healthcare providers, providing billing, financial, and other administrative services. An investigation found that data including names, addresses, Social Security numbers, health insurance details, and medical histories may have been exposed.

  • The notice names seven healthcare providers whose patient data MCBS handled, including South Georgia Radiology Consultants, SkinPath Solutions, and Stephen W. Brown and Radiology Associates of Augusta.

What to do:

  • People who have received medical care in Georgia should contact their healthcare provider to check whether it uses MCBS and whether their personal information may have been affected.

  • Those who believe they were affected should place a fraud alert on their credit report and consider a security freeze.

H96 Streaming Sticks Fuel $50K-a-Day Scam Operation

New research shows how cheap H96 Android TV streaming devices are being secretly exploited for proxy services and ad fraud, generating tens of thousands of dollars a day. The operation uses AI‑generated websites and automated ad clicks to profit from fake ad traffic, highlighting the evolving threat posed by compromised consumer devices.

Key facts:

  • The devices perform two hidden functions. When the TV is on, they typically act as residential proxies, allowing anonymous paying customers — potentially including bad actors — to route internet traffic through the user's home connection. When the TV is off, they switch to ad fraud.

  • For the ad fraud, devices disguise themselves as mobile phones and visit AI‑generated websites, where bots navigate pages and click ads to generate fraudulent revenue. Multiple vision and reasoning systems help the bots identify and interact with ads like human users.

  • Researchers identified around 38,000 H96 devices worldwide communicating with just one domain, estimating that the ad fraud alone generates nearly $50,000 a day. The real scale could be significantly larger, as this estimate does not include revenue from the residential proxy operation.

A cheap streaming stick might seem harmless, but consumers could unknowingly be providing the infrastructure for criminal activity through their own internet connection. AI is making these schemes increasingly automated and scalable, showing how even everyday connected devices can become part of a much bigger criminal operation. Consumers should stick to reputable, certified devices that receive regular security updates.

Joel Latto, Threat Advisor at F‑Secure

Experts behind the insights

  • Joel Latto

    Threat Advisor, F‑Secure

    Joel Latto is a threat researcher focused on scams and social media. A regular contributor to threat reports, including F-Secure's F‑Alert, he has also collaborated with Laurea University of Applied Sciences to educate the public about cyber crime.

  • Dr. Megan Squire

    Principal Threat Intelligence Researcher, F‑Secure

    Megan Squire holds a PhD in computer science and is the author of two books and 40+ peer-reviewed articles. A recipient of Best Paper Awards and a recognized cyber threat expert, she has been featured in major media including The New York Times, WIRED, and PBS Frontline.

Contact us

If you’re interested in finding out how we can personalize our solutions to your business strategy and consumer needs, contacting our team of experts is easy. Get in touch to find out:

  • How we integrate our security solutions

  • How we can add value to your business

  • How your customers benefit from our security

By submitting this form, you agree to receive emails and equivalent communications from F‑Secure, including news­letters, event invitations, offers, and product-related information. However, if you wish to change your consent settings in the future, we always provide that possibility through the Preference Center link at the bottom of our emails. We process the personal data you share with us in accordance with our privacy statement.

Thank you for your interest

We'll be in touch soon.