惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
罗磊的独立博客
宝玉的分享
宝玉的分享
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
V
V2EX
酷 壳 – CoolShell
酷 壳 – CoolShell
T
Tailwind CSS Blog
博客园_首页
量子位
月光博客
月光博客
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 司徒正美
人人都是产品经理
人人都是产品经理
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
爱范儿
爱范儿
S
SegmentFault 最新的问题
雷峰网
雷峰网
小众软件
小众软件
博客园 - 聂微东
美团技术团队
Apple Machine Learning Research
Apple Machine Learning Research
WordPress大学
WordPress大学
Jina AI
Jina AI
Hugging Face - Blog
Hugging Face - Blog

Consumer Insights

The ransomware negotiator who was working for the other side After years on the run, alleged Ryuk ransomware operator pleads guilty INTERPOL crackdown shows scammers shifting to social media Meta lets strangers remix your public Instagram photos with AI—here’s how to opt out Invited to a "job interview" with Netflix or OpenAI? Beware! Your Google password could be at risk Two arrested over credit card phishing - as the Netherlands is named Europe's worst for payment fraud India pauses WhatsApp username feature over security concerns Alleged teen ransomware hustler faces US charges after arrest in Finland WhatsApp usernames explained: how to reserve yours and stay safe USB drives carrying China-linked malware infected Japanese military networks for nearly a year WhatsApp tests new safety prompt before you chat with strangers Social media is worth celebrating. It's also worth protecting. Polish police dismantle SIM-swap gang accused of crypto theft Operation Endgame deals fresh blow to StealC and Amadey malware networks Hacker hijacks Brazil's national alert system, sending "misanthropy" to millions of phones Cybercrime now rivals traditional crime across parts of Asia Apple's Hide My Email tweak leaves privacy fans fuming Americans lost $3.5 billion to imposter scams last year — and the scams are getting harder to spot Scammers have killed the physical Steam Gift cards Crypto investment scam sends couriers to collect victims' cash, FBI warns Maine forced to take down data breach portal after fake notices filed with authorities Privacy own-goal: World Cup blunder leaks Lionel Messi's passport details Why schools remain one of cybercriminals' favourite targets WhatsApp detects new spyware activity from Israel’s NSO Group despite court order Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5 Europol cracks down on illegal streaming globally Hackers didn't hack Instagram; they just asked Meta AI FBI Warns Fans About FIFA Scams Ahead of 2026 World Cup Virtual knife, real lawsuit: Counter-Strike skin dispute ends in court As Deepfakes Spread, YouTube Makes AI Labels Harder to Miss
Scammers race to cash in on Venezuelan earthquake disaster
Graham CLULEY · 2026-07-01 · via Consumer Insights

When a devastating earthquake struck north central Venezuela last week, rescue teams were not the only ones who mobilised fast. So did domain registrars.

Researchers at threat intelligence firm WhoisXML API say that they uncovered 212 newly-registered domains referencing the earthquake, all of which had been filed within five days of the disaster.

To put that in context, in the three days before the quake, the company found a grand total of zero matching domains. The disaster struck and on the very same day, registrations began, peaking the following day (25 June) with 105 domains filed in those 24 hours alone, before tapering off over the following three days.

Many of the names of the registered domains look reassuringly helpful: 110 reference aid or donations, 52 use "SOS" or rescue-related wording, 56 mention earthquakes or seismic activity, and 12 refer to missing or affected people.

Meanwhile others promise medical help, listings for shelter, maps, or tracking services.

Now, some of those 212 new earthquake-related domains will no doubt belong to genuine charities and volunteers offering to help with the country's recovery. But, according to researchers, 93% of the domains exposed no individual registrant contact, with those details hidden behind privacy services or simply left blank.

Suspiciously, some of the newly-live websites are already soliciting Bitcoin donations with no verifiable proof that donations will reach victims, according to researcher Alexandre François.

Regular readers of Hot for Security are well aware that disaster-chasing scammers are nothing new, with the pattern recurring for years.

For instance, Hurricane Harvey in 2017 brought such a concerning wave of phishing campaigns and fake charity activity that the FTC issued a direct warning, urging donors to properly vet charities before offering money, and to be wary of any "charity" born overnight.

Scammers played the same trick during the COVID-19 pandemic impersonating UN compensation schemes and recruiting unsuspecting "remote workers" to launder stolen donation money through Bitcoin ATMs.

Even years after a natural disaster scammers can still exploit human misery. That happened a few years after the Japanese tsunami of 2011 when fraudsters attempted "Nigerian Prince"-style scams claiming that dead businessmen had left unclaimed millions.

It's not a new trick, and it doesn't have to be. And that's because exploitation of a major news event - whether it be a natural disaster of otherwise - can be a successful lure for criminals to deploy when defrauding the unwary out of their savings. And when a natural disaster creates an urgent need for response, it is all the easier for cybercriminals to exploit it.

If you want to donate safely for a good cause, type in the URL of a charity that you already know and trust, rather than clicking on links from social media or unsolicited emails.

In addition, you should be suspicious of brand new websites, especially those registered in the days immediately following a disaster, and avoid sites that request cryptocurrency-only donations. Legitimate charities will offer traceable, conventional payment methods and be transparent about where the funds will go.

Generosity after a disaster deserves to benefit the people who need it most, not disappear into the cryptocurrency wallet of a fraudster.