AntiMalwareAugust 12, 2026🇷🇺Translated from Russian

WhatsApp Begins Limited Beta Testing of On-Device Scam Alert to Detect Fraud While Preserving End-to-End Encryption

WhatsApp, owned by Meta, has launched limited beta testing of its Scam Alert feature designed to warn users about potentially fraudulent messages from strangers.

The protection relies on a machine learning model that runs directly on the smartphone. Conversation content is never transmitted to WhatsApp or Meta, preserving end-to-end encryption. After activation, the device downloads the model and examines dialogue structure along with linguistic signs of fraud.

When a message appears suspicious, the recipient sees a warning while the sender remains unaware. Users can then block the contact, file a report, dismiss the alert, or designate the chat as trusted. In the trusted case, the last five messages can optionally be shared to help improve the model.

To prevent Meta from deploying a customized analyzer to specific users, every model release is recorded in an immutable log. A manifest containing SHA-256 hashes is signed with Ed25519 keys controlled by Cloudflare. The smartphone verifies the signature, log entry, and file integrity before executing the model.

WhatsApp collects only anonymized counters of detections and subsequent user actions. The app also includes a Scam Alert Activity log showing check results and model versions.

The current release remains an early technical preview. Meanwhile, Signal has introduced automatic key verification that uses a cryptographically verifiable log and allows users to confirm no unauthorized intermediary is present. Independent audits are performed by Cloudflare and Trail of Bits without access to user data.

Related articles

AntiMalwareFraud & Social Engineering

Scammers Embed Phishing Inside Telegram Mini Apps After August Update

Cybercriminals are increasingly abusing Telegram's Mini Apps and WebView features to deliver phishing attacks that mimic legitimate banking, payment, and cryptocurrency services. Following the platform update on August 25, attackers can now present fake interfaces for transfers, airdrops, and voting systems directly inside the messenger. Victims are tricked into entering confirmation codes, connecting wallets, or pasting commands into PowerShell under the guise of fixing errors or claiming bonuses. The attacks rely heavily on social engineering rather than automated malware, requiring users to actively authorize actions such as signing transactions or providing phone verification details. Fake voting schemes are used to harvest account credentials, while crypto-related lures prompt users to link wallets to malicious services. Experts emphasize that simply opening a Mini App does not lead to immediate theft, but authorizing or connecting assets does expose users to significant risk.

AntiMalwareFraud & Social Engineering

Google Introduces Multi-Step Verification for Android APK Sideloading to Combat Fraud

Google has begun rolling out an enhanced installation flow for Android apps installed outside of Google Play. Users must first confirm that no one is coercing them to enable unknown sources, then reboot their device and wait 24 hours before the option becomes available. The new process includes explicit warnings about scammers who pressure victims into enabling sideloading, noting that legitimate organizations never require this setting. After the waiting period, users can grant the permission for seven days or indefinitely. The change does not affect ADB installations, preserving a workaround for advanced users. Google states the delay is intended to give people time to reconsider before enabling potentially risky settings. An Android Authority poll showed 88 percent of respondents expect further restrictions in the future.

HabrFraud & Social Engineering

Why 'Be Vigilant' Is Not Enough: Dissecting Human Psychology During Social Engineering Attacks

A cybersecurity expert with years of SOC and pentest experience explains why traditional awareness training fails against social engineering. The article details how attackers exploit psychological levers such as authority, urgency, reciprocity, social proof, and emotion to bypass conscious decision-making. It emphasizes that people who fall for attacks are often the most helpful and diligent employees, not the careless ones. Instead of relying on willpower in stressful moments, organizations must implement procedures that enforce independent verification and protect the right to pause. The piece also highlights how a blame-free culture dramatically reduces incident impact by encouraging early reporting. Technical measures that reduce reliance on a single human decision are presented as effective supplements to policy.

AntiMalwareFraud & Social Engineering

Scammers Impersonate Gas Workers to Pressure Russians into Overpriced Repairs Before September 1 Deadline

Fraudsters have started visiting apartments and private homes in Russia, posing as employees of gas services or management companies. They claim to have discovered critical issues such as gas leaks, faulty valves, problematic meters, or dangerous chimneys during supposed August inspections. Residents are warned that gas will be disconnected by September 1 unless immediate and expensive repairs are paid for on the spot. In some cases, scammers demand prepayments for urgent work and then disappear with the money. Victims are often charged 5 to 10 times the market price for equipment replacement. The Moshelovka platform of the Narodny Front has reported these incidents and issued safety recommendations. Residents are advised to verify maintenance schedules in advance and never pay cash or transfer money to individuals without confirmation.