Reading view

Chick-fil-A Data Breach Explained: What Customers Need to Know

This week in scams and cybersecurity news,  

Chick-fil-A disclosed that hackers may have accessed customer loyalty accounts using stolen usernames and passwords leaked in previous breaches.  

It’s a reminder that reusing passwords across websites can be dangerous and allow one breach to snowball into many others. 

Here’s what happened and what customers need to know: 

So How Did Hackers Breach Chick-fil-A? 

Chick-fil-A is notifying customers in 10 states after a cyberattack targeted a limited number of Chick-fil-A One loyalty accounts. 

According to multiple reports, attackers used a technique known as credential stuffing, in which criminals take usernames and passwords stolen in previous data breaches and automatically test them across other websites and apps.  

If someone has reused the same password, attackers may be able to access additional accounts without ever hacking the company directly. 

Chick-fil-A said the attackers may have accessed customer information including: 

  • Names and email addresses  
  • Chick-fil-A One membership numbers  
  • Mobile Pay numbers and QR codes  
  • The last four digits of stored payment cards  
  • Gift card balances  
  • Birth dates, phone numbers, and addresses (if customers stored them)  

The company says it has logged affected users out of their accounts, removed stored payment methods, restored impacted rewards balances, and is notifying customers who may have been affected. 

Credential stuffing: 
A cyberattack where criminals use usernames and passwords stolen in previous data breaches to automatically sign in to other websites and apps. If you’ve reused the same password across multiple accounts, one breach can give attackers access to many of them. 
How to Protect Yourself: Use a unique password for every account, enable multi-factor authentication, and use a password manager to securely create and store strong passwords. 

How McAfee Helps Before, During, and After a Data Breach 

Before a breach 

Personal Data Cleanup reduces your digital footprint by removing your personal information from many data broker sites, making it harder for scammers to find and target you. 

Online Account Cleanup scans for accounts you no longer use and helps you delete them, along with your personal info. 

Password Manager helps you create and securely store strong, unique passwords for every account, reducing the risk that one stolen password can unlock multiple accounts.  

During a breach 

Identity Monitoring watches for your personal information, including email addresses, driver’s license numbers, passport numbers, bank accounts, credit cards, Social Security numbers, phone numbers, and more, across the dark web and known data leaks.  

Plus, we alert users on average up to 10 months earlier than similar services, so you can act fast when your personal information appears where it shouldn’t. 

After a breach 

Scam Detector identifies suspicious texts, emails, and links that often follow major breaches, while web protection blocks malicious websites designed to steal even more of your information. 

Other Scam News This Week 

Student loan scams are on the rise. Experts warn that changing federal student loan repayment rules are creating confusion that scammers are exploiting with fake debt relief offers, phishing emails, and identity theft schemes targeting borrowers. (PBS News) 

AI agent reportedly carried out a cyberattack. AI platform Hugging Face says an autonomous AI agent executed a sophisticated attack against its internal systems from start to finish; an early example of AI taking on an active role in cyberattacks rather than simply assisting human hackers. (Axios) 

Paidwork breach reportedly exposes 23 million users. Security researchers say data from the microtask platform may include names, addresses, phone numbers, bank account details, and password hashes, highlighting how even smaller online accounts can become valuable targets for cybercriminals. (Malwarebytes) 

And we’ll be back next week with more news.  

The post Chick-fil-A Data Breach Explained: What Customers Need to Know appeared first on McAfee Blog.

  •  

How to Use Claude with McAfee to Check “Is This a Scam?”

Scam messages are getting smarter and faster. 

According to McAfee’s 2026 State of the Scamiverse report, Americans now spend 114 hours a year trying to figure out what’s real and what’s fake online. That’s nearly three full workweeks lost to second-guessing messages, alerts, and links. 

And when scams do succeed, they move quickly. The typical scam unfolds in about 38 minutes, leaving little room for hesitation. 

That creates a gap: People want to check before they act, but the tools haven’t always met them in that moment. 

Claude + McAfee is designed to close that gap, bringing scam detection directly to a platform people are already using to ask questions and make decisions. 

And it’s available to anyone. You don’t have to be a McAfee subscriber. 

This isn’t just detection. It’s guidance in the exact moment you’re deciding what to do. 

Instead of guessing, you can paste a message or drop in a screenshot and get a clear explanation of what’s risky, and what to do next, powered by McAfee’s threat intelligence. 

How to Use McAfee in Claude 

With this integration, checking something suspicious becomes as simple as asking a question. 

Paste a message. Drop in a link. Upload a screenshot. And just make sure to @McAfee when you’re asking a question. 

McAfee analyzes it and explains what’s going on clearly and in context. 

For example, I got this suspicious “job offer” message over the weekend: 

So I uploaded it in Claude and asked @McAfee, which caught it right away. You can even see I’m using the free plan.  

Here’s how it works: 

Feature  What it does  How it protects you 
Link safety check  Paste a suspicious URL and get a reputational analysis based on McAfee threat intelligence  Scam links are often designed to look legitimate. A quick check helps avoid phishing and malware 
Message analysis  Submit texts, emails, or social messages for evaluation  Many scams now rely on urgency and tone. Analysis helps surface subtle red flags 
Screenshot uploads  Upload screenshots of messages or emails for review  Scams don’t always come as clean text. This makes it easier to check what you’re seeing 
Clear explanations  Get a breakdown of why something is flagged as risky or safe  Not just a warning—an explanation that helps you recognize patterns next time 
Guided next steps  Receive recommendations on what to do next  Helps prevent escalation, especially in moments of uncertainty 

It’s a quick, accessible way to get answers in the moment. But it’s just one part of a broader system designed to protect you more comprehensively. 

How do I set up McAfee in Claude? 

Add the Connector to your Claude account here. 

And make sure to go into “manage connections” to give McAfee permissions to review the texts, emails, and URLs you upload to Claude.  

Example of the Permissions on your desktop.
Example of the permissions on mobile.

Need help getting the extension installed? Check out our step-by-step guide. 

Plus, our Claude Connector is designed to work in all languages.  

Built on McAfee’s Threat Intelligence 

Behind the scenes, Claude + McAfee is powered by the same intelligence that fuels McAfee’s broader scam protection ecosystem. 

When you submit something for review: 

  • Links are checked against known threat signals  
  • Messages are analyzed for scam patterns and language cues  
  • Results are translated into clear, human-readable explanations  

The goal isn’t just to flag risk. It’s to help you understand it. 

A New Way to Stay Ahead of Scams 

Scams aren’t slowing down. If anything, they’re becoming more convincing, more personalized, and harder to detect. 

That’s where Claude + McAfee comes in. But this is only one part of a much bigger system designed to protect you before, during, and after a scam attempt. 

With McAfee+ Advanced, multiple layers work together so you’re not left figuring it out after the damage is done: 

  • Identity Monitoring alerts you if your personal info shows up where it should not, so you can act fast  
  • Personal Data Cleanup helps remove your information from sites selling it. 
  • Scam Detector flags suspicious texts, emails, links, QR codes, and even deepfake videos before you engage  
  • Safe Browsing helps block risky sites, even if you do accidentally click  
  • Device Security helps detect malicious apps or downloads  
  • Secure VPN keeps your data private, especially on public Wi-Fi   
  • The Claude + McAfee experience gives you a fast, intuitive way to check something in the moment. 

McAfee+ Advanced makes sure you’re protected across everything else. 

The post How to Use Claude with McAfee to Check “Is This a Scam?” appeared first on McAfee Blog.

  •  

The FaceTime Bank Scam That Can Expose Your Passwords in Real Time: This Week in Scams

Scammers don’t always need sophisticated malware to steal your money. Increasingly, they’re relying on something much simpler: your trust. 

This week, fraudsters were reported using FaceTime to watch victims log into their online banking accounts in real time, while Arizona authorities warned about fake QR codes exploiting the disappearance of 84-year-old Nancy Guthrie. 

Here’s what happened, and how to protect yourself. 

Scammers Are Using FaceTime to Watch Victims Log Into Their Bank Accounts 

A growing scam is turning one of Apple’s most familiar apps into a tool for financial fraud. 

According to CBS News, scammers first contact victims by text or phone while pretending to represent their bank or credit card company. They claim there’s suspicious activity on the account and that additional verification is needed. 

Instead of keeping the conversation on a regular phone call, they switch to FaceTime. 

Victims are then convinced to share their screens while logging into online banking. As they do, scammers can watch account numbers, passwords, and even one-time security codes appear in real time. 

How the scam works 

  1. You receive a text or phone call claiming there’s fraud on your account. 
  2. The caller directs you to continue the conversation over FaceTime. 
  3. You’re asked to share your screen while logging into your bank. 
  4. The scammer watches your passwords and verification codes as you enter them. 

Remember: Your bank should never ask you to share your screen or reveal one-time authentication codes. If you receive an unexpected call, hang up and contact your bank using the number on the back of your card or through its official app.  

Fake QR Codes Are Exploiting the Search for Nancy Guthrie 

Authorities in Arizona are warning the public about another scam—this time involving the disappearance of 84-year-old Nancy Guthrie, mother of Today show host Savannah Guthrie. 

According to the Pima County Sheriff’s Department, scammers have been circulating social media posts containing QR codes requesting donations connected to the investigation. 

The department says it will never ask the public for money related to this case or any investigation and urged people not to scan QR codes requesting payment. 

The warning comes as investigators continue to search for Nancy Guthrie, whose disappearance remains under investigation. 

How to spot QR code scams 

  • Verify who posted the QR code before scanning. 
  • Be cautious of emotional appeals tied to breaking news or missing persons cases. 
  • Never send money to someone you don’t know based solely on a social media post. 
  • Confirm donation requests through an organization’s official website instead of relying on shared posts. 

Scammers know that people want to help during emergencies. Unfortunately, they also know that urgency and emotion can cause people to act before verifying where their money is going. 

Other Scam and Security News This Week 

Even scam reporters can be targeted. A CBS News correspondent shared how he nearly withdrew money from his own bank after falling for a sophisticated imposter scam before realizing something didn’t add up. (Yahoo Finance) 

India investigates reported nuclear plant-related data breach. Reuters reported that ransomware group World Leaks published files allegedly connected to contractors working on India’s Kudankulam Nuclear Power Plant. Officials say no nuclear security systems were exposed. (Reuters/Al Jazeera) 

Cyberattack disrupts KFC Japan supply chain. A cyberattack on food logistics provider Nichirei Co. disrupted frozen food deliveries to KFC Japan, leading the company to warn of possible menu restrictions, shorter hours, and temporary pauses to online ordering. Nichirei said it has found no evidence that customer or personal information was exposed. (TechRadar)

Your Safety Checklist This Week

Before you trust a call, text, or QR code: 

✔ Never share your screen with someone claiming to be your bank. 

✔ Don’t scan QR codes requesting money unless you’ve verified the source. 

✔ Contact organizations directly using their official website or phone number—not the contact information provided in a text or social media post. 

✔ Slow down when someone creates urgency. Whether it’s a missing person case or a frozen bank account, scammers rely on emotional reactions. 

How McAfee Can Help 

Scammers often begin with a text, phone call, or malicious link designed to earn your trust before stealing your information. 

Before a breach: Personal Data Cleanup helps reduce your digital footprint by removing your personal information from many data broker sites, limiting what scammers can easily find about you.

During a breach: Identity Monitoring alerts you if your personal information appears on the dark web or in known data leaks, helping you respond faster if your information is exposed.

After a breach: Scam Detector helps identify suspicious texts, emails, and links that often follow major breaches, while Web Protection helps block malicious websites designed to steal additional information or credentials.

And we’ll be back next week with more news and safety tips.

The post The FaceTime Bank Scam That Can Expose Your Passwords in Real Time: This Week in Scams appeared first on McAfee Blog.

  •  

Nearly 7 Million Driver’s Licenses Exposed in Assurance Breach: This Week in Scams

Millions of Americans hand over personal information every day. They share their data with insurance companies, banks, investment apps, and other services they trust. 

And that’s exactly why cybercriminals target and impersonate those services.

This week, an insurance provider disclosed a breach reportedly affecting nearly 7 million people’s driver’s license numbers, while a California journalist shared how a convincing fake Robinhood text ultimately cost her more than $70,000. 

Here’s what happened, why these scams work, and what you can do to protect yourself This Week in Scams. 

Nearly 7 Million Driver’s License Numbers Exposed in Insurance Data Breach 

One of the largest U.S. data breaches of the year has exposed sensitive information belonging to 6.9 million people. 

According to reporting from TechCrunch, insurance provider AssuranceAmerica confirmed that hackers accessed customer information after compromising an employee account. The company says the stolen data includes names, contact information, driver’s license numbers, insurance policy details, vehicle information, and claims data. 

While the company has not said exactly how the employee’s credentials were compromised, it noted that the attackers targeted an employee account before accessing company systems. 

Why driver’s license numbers matter 

Unlike a password, you can’t simply change your driver’s license number. 

Combined with your name, address, phone number, or other information from previous breaches, driver’s license numbers can be used by criminals to: 

  • Open fraudulent accounts  
  • Impersonate victims during identity verification  
  • Make phishing scams more convincing  
  • Support broader identity theft schemes  

This is also part of a larger trend. In recent months, multiple breaches have exposed government-issued identity documents as more organizations collect IDs for identity verification and age-check requirements. 

If you receive a notice that your information was involved in a breach, monitor your financial accounts closely, consider placing a fraud alert or credit freeze, and remain cautious of unexpected emails, texts, or phone calls referencing your insurance or driver’s license information. 

Unfortunately, scammers will reach out saying they’re trying to “help” secure your stolen information, only to try and steal more personal data from you.

How McAfee Can Help Before, During, and After a Data Breach

Before a breach

Personal Data Cleanup helps reduce your digital footprint by removing your personal information from many data broker sites, limiting what scammers can easily find about you.

During a breach

Identity Monitoring alerts you if your personal information appears on the dark web or in known data leaks, helping you respond faster if your information is exposed.

After a breach

Scam Detector helps identify suspicious texts, emails, and links that often follow major breaches, while Web Protection helps block malicious websites designed to steal additional information or credentials.

Fake Robinhood Text Scam Costs Former News Anchor More Than $70,000 

Even people who report on scams can become victims. 

A former California television news anchor recently shared how she lost more than $70,000 after receiving what appeared to be a legitimate text message claiming there was suspicious activity on her Robinhood investment account. 

The message instructed her to call a phone number for assistance. Once connected, the caller posed as Robinhood support before transferring her to a fake “fraud department.” 

Believing she was protecting her investments from hackers, she was convinced to move her money into what she thought was a secure account. Instead, it went directly to scammers. 

She later contacted Robinhood through the official app, but by then the money had already been transferred. 

Why investment scams are becoming more convincing 

Investment scams rely on urgency, authority, and impersonation rather than obvious phishing emails. 

Rather than asking targets to “invest” immediately, many scams begin by convincing people that their existing account is under attack and immediate action is needed. 

At McAfee, we’ve also seen scammers impersonate Robinhood, Charles Schwab, cryptocurrency platforms, and other investment services through fraudulent text messages and malicious links promising AI-powered investing, exclusive bonuses, or unusually high returns. 

Whether the message claims your account has been compromised or promises incredible profits, the goal is often the same: get you to click, call, or transfer money before you have time to verify what’s happening. 

Investment Safety Checklist 

Before responding to any message about your investments: 

✅ Never call the phone number provided in a text message or email. Instead, contact your financial institution using the number listed in its official app or website. 

✅ Slow down when someone creates urgency. Claims that your account is being hacked or frozen are designed to make you act before you think. 

✅ Be skeptical of guaranteed returns or AI-powered investment opportunities. Promises of extraordinary profits are a common hallmark of investment fraud. 

✅ Verify alerts through your account directly. If you receive a suspicious notification, log in through the official app, not a link in the message. 

How McAfee Can Help   

With McAfee+, multiple layers work together before any damage is done:  

Scam Detector flags suspicious texts, emails, links, QR codes, and even deepfake videos before you engage 

Secure VPN keeps your data private, especially on public Wi-Fi  

Web Protection helps block risky sites, even if you do accidentally click 

Password Manager doesn’t just help you make unique, strong passwords, it keeps them stored and organized for you

Device Security helps detect malicious apps or downloads   

Identity Monitoring alerts you if your personal info appears online in places it shouldn’t, so you can act fast

Personal Data Cleanup helps remove your information from sites selling it. 

Online Account Cleanup assists in taking down your old, forgotten accounts across the web 

Social Privacy Manager helps you monitor and change privacy settings across your social platforms in just a few clicks 

Together, these protections are designed to address the broader range of online risks people face every day. 

The post Nearly 7 Million Driver’s Licenses Exposed in Assurance Breach: This Week in Scams appeared first on McAfee Blog.

  •  

Imposter Scams Are Evolving. Here Are the 10 Identities Scammers Pretend to Be Most.

Imposter scams remain the most reported type of fraud in America for the fifth year in a row, according to new data from the Federal Trade Commission (FTC).  

Americans submitted more than 1 million reports of imposter scams in 2025, making them the agency’s top fraud category once again. Victims reported more than $3.5 billion in losses, though the real number is likely much higher since many scams go unreported.  

But “imposter scam” is a broad category. It doesn’t tell you what these scams actually look like when they land in your inbox, texts, social media DMs, or phone calls. 

To better understand what consumers are encountering every day, McAfee surveyed more than 7,500 people for its State of the Scamiverse report. The results show scammers aren’t just pretending to be one type of person or company. They’re impersonating the brands, services, and people we trust most.  

This week’s edition of This Week in Scams is here ahead of the holiday weekend with the 10 most common identities scammers pretend to be. 

10. Someone Who “Texted the Wrong Number” (20%)

Common scam: An innocent conversation that turns into something more. 

These scams often begin with a harmless message intended for “someone else.” Once you reply, the scammer slowly builds trust over days or even weeks before introducing investment opportunities, romance, or requests for money. 

Unlike traditional phishing, these scams don’t always include suspicious links. 

Why it works: They feel like genuine human conversations rather than obvious scams. 

Learn more about wrong number and pig-butchering scams. 

9. Technology Companies (21%)

Common scam: “Your device has been compromised.” 

These messages impersonate technology companies or cybersecurity brands, claiming your computer or phone has been infected or involved in a security breach. 

Some direct victims to fake technical support, while others encourage downloads of malicious software. 

Why it works: Security alerts are designed to grab attention, and convincing impersonation can make fake warnings look legitimate. 

Learn more about tech support scams. 

8. Banks and Financial Institutions (21%)

Common scam: “We’ve detected suspicious activity on your account.” 

Bank impersonation scams create immediate urgency, asking customers to confirm transactions, secure their accounts, or verify their identity. 

Many direct victims to fake websites or connect them with fraudulent customer support representatives. 

Why it works: Financial security messages naturally demand attention, making people more likely to react before verifying the sender. 

Learn more about banking scams and financial fraud. 

 7. Subscription Services (21%)

Common scam: “Your payment couldn’t be processed.” 

Scammers impersonate streaming services, software subscriptions, and other recurring services, warning that your account will be canceled unless you update your payment information. 

Why it works: Consumers are used to recurring billing notifications, making these messages blend into everyday digital life. 

Learn more about mobile payment and subscription scams. 

6. Auto Warranty Providers (22%)

Common scam: “Your vehicle warranty is about to expire.” 

One of the oldest impersonation scams is still one of the most common. Fraudsters claim your warranty is ending and pressure you to purchase coverage immediately or provide personal information. 

Why it works: Many people aren’t sure when their warranty expires, making the claim difficult to verify on the spot. 

Learn more about these types of robocallers. 

5. Rewards Programs and Survey Companies (22%)

Common scam: “You’ve won a prize.” 

These scams promise gift cards, rewards, or exclusive offers but require you to “verify” your identity or enter payment information to claim them. 

Why it works: The promise of something free lowers skepticism, especially when the message appears to come from a familiar brand. 

Learn more about survey and prize scams.  

4. Retailers and Merchants (26%)

Common scam: Fake invoices for purchases you never made. 

Receiving an invoice for an expensive purchase can trigger panic. Scammers count on victims clicking quickly to dispute the charge, often leading them to malicious websites or fake customer support numbers. 

Why it works: Consumers naturally want to stop fraudulent purchases as quickly as possible. 

Learn more about shopping scams. 

3. Payment Services (27%)

Common scam: “Verify your PayPal account.” 

Messages claiming there’s a problem with your payment account often direct you to fake login pages designed to steal your username, password, or financial information. 

While PayPal is one common example, scammers impersonate many digital payment platforms. 

Why it works: Payment notifications are common, and many consumers don’t think twice before signing in to resolve what appears to be a routine issue. 

Learn more about mobile payment scams.  

2. Social Media Platforms (27%)

Common scam: “Verify your account or it will be suspended.” 

Scammers frequently impersonate platforms like Facebook, Instagram, TikTok, or X, claiming there’s unusual activity or that your account violates community guidelines. 

The goal is usually to steal your login credentials or two-factor authentication codes. 

Why it works: Many people rely on social media for work, business, or staying connected, making the threat of losing access feel urgent. 

Learn more about social media scams.  

1. Delivery Companies (31%)

Common scam: “Your package couldn’t be delivered.” 

Whether you’re waiting for a birthday gift, an online order, or an important package, fake delivery notifications prey on the fact that most people are expecting something to arrive. 

These messages often claim there’s a shipping issue, unpaid delivery fee, or missed package and urge you to click a link immediately. 

Why it works: Package updates have become part of daily life, making fake notifications feel routine rather than suspicious. 

Learn more about delivery scams. 

The Common Thread 

While these scams may look different, they all rely on the same tactic: impersonation. 

“AI has lowered the barrier for creating convincing impersonation scams,” said Abhishek Karnik, Head of Threat Research at McAfee.  

“Scammers can now produce professional-looking emails, realistic websites, and even convincing voices or videos at scale. The result isn’t necessarily more scam types, it’s far more believable versions of the scams people already encounter every day.” 

That mirrors a broader trend McAfee identified in its State of the Scamiverse research: scams are becoming more realistic, more personalized, and harder to distinguish from legitimate communications.  

Americans now receive an average of 14 scam messages every day, spend 114 hours each year deciding what’s real and what’s fake, and one in three say they feel less confident spotting scams than they did a year ago.  

How to Protect Yourself From Impersonation Scams 

If you notice this…  ✅ Do this instead 
A message creates a sense of urgency (“Your account will be suspended,” “Package delivery failed,” “Fraud detected”)  Pause before acting. Scammers want you to make a quick decision before verifying the message. 
You’re asked to click a link or scan a QR code  Open the company’s official website or app yourself instead of using the link in the message. 
The message asks you to verify your account, payment information, or identity  Never enter credentials through an unsolicited message. If you’re concerned, contact the company directly using a trusted phone number or website. 
Someone asks for passwords, one-time verification codes, or payment over text, email, or phone  Legitimate companies won’t ask for this. Don’t share the information, even if the request seems convincing. 
A “wrong number” text quickly becomes unusually friendly or shifts toward investing, crypto, or money  Stop responding and block the sender. Modern scams often begin as seemingly harmless conversations. 

How McAfee Can Help   

With McAfee+, multiple layers work together before any damage is done:  

  • Scam Detector flags suspicious texts, emails, links, QR codes, and even deepfake videos before you engage 
  • Secure VPN keeps your data private, especially on public Wi-Fi  
  • Web Protection helps block risky sites, even if you do accidentally click 
  • Password Manager doesn’t just help you make unique, strong passwords, it keeps them stored and organized for you
  • Device Security helps detect malicious apps or downloads   
  • Identity Monitoring alerts you if your personal info shows up where it should not, so you can act fast   
  • Personal Data Cleanup helps remove your information from sites selling it. 
  • Online Account Cleanup assists in taking down your old, forgotten accounts across the web 
  • Social Privacy Manager helps you monitor and change privacy settings across your social platforms in just a few clicks 

Together, these protections are designed to address the broader range of online risks people face every day. 

The post Imposter Scams Are Evolving. Here Are the 10 Identities Scammers Pretend to Be Most. appeared first on McAfee Blog.

  •  

McAfee Mobile Security Earns a Perfect AV-TEST Score Yet Again

McAfee Mobile Security has once again earned a perfect score from AV-TEST, one of the cybersecurity industry’s most respected independent testing organizations. 

In AV-TEST’s latest Android security evaluation, McAfee achieved a flawless 18 out of 18 points, receiving perfect 6/6 scores in Protection, Performance, and Usability 

The result also earned McAfee AV-TEST’s highest certification for mobile security. 

More importantly, this isn’t a one-time achievement. McAfee has earned top certification in every AV-TEST Mobile Security evaluation since testing began in 2013, demonstrating more than a decade of consistently delivering industry-leading protection for Android users. 

What is AV-TEST? 

AV-TEST is one of the world’s leading independent cybersecurity testing laboratories. Rather than relying on vendor claims, AV-TEST evaluates security products under controlled, real-world conditions using the same types of threats consumers face every day. 

Its certifications are widely referenced by: 

  • Security experts and reviewers  
  • Technology publications  
  • Product comparison sites  
  • Consumers researching antivirus software  

Because every product is tested using the same methodology, AV-TEST provides an objective benchmark for comparing mobile security solutions. 

How McAfee Was Tested 

For this evaluation, AV-TEST examined 12 Android mobile security products across three equally weighted categories: 

Category  What It Measures 
Protection  Ability to detect and block real-world Android malware and emerging threats 
Performance  Whether the security app slows down your device or drains system resources 
Usability  Accuracy of detections and avoidance of false alarms or unnecessary interruptions 

McAfee earned the maximum possible score in all three categories: 

  • Protection: 6/6  
  • Performance: 6/6  
  • Usability: 6/6 

Overall Score: 18/18 

That means McAfee not only blocked threats effectively, but did so without slowing devices down or generating unnecessary false positives. 

Why These Results Matter 

Mobile devices have become one of our primary ways to bank, shop, communicate, and manage our digital lives. As cybercriminals increasingly target smartphones with malware, phishing attacks, malicious apps, and credential theft, effective mobile protection matters more than ever. 

Independent testing helps separate marketing claims from measurable performance. 

McAfee’s latest AV-TEST results demonstrate that users don’t have to choose between strong security and a smooth mobile experience. The protection works quietly in the background, helping keep devices secure without getting in the way. 

Even more importantly, this latest certification continues a streak that spans more than a decade. Consistently earning perfect scores across changing threat landscapes reflects McAfee’s ongoing investment in protecting customers against today’s evolving mobile threats. 

Mobile Protection You Can Count On 

The award-winning protection recognized by AV-TEST is included in: 

  • McAfee+ Premium  
  • McAfee+ Advanced  
  • McAfee+ Ultimate  
  • McAfee Total Protection  
  • McAfee LiveSafe  
  • McAfee Internet Security  
  • McAfee Business Protection  

Whether you’re protecting your own phone or your entire family’s devices, you’re getting the same independently tested mobile security that continues to earn top marks from one of the industry’s most trusted testing organizations. 

Ready to get protection that doesn’t slow you down? Explore McAfee+ Plans →  

The post McAfee Mobile Security Earns a Perfect AV-TEST Score Yet Again appeared first on McAfee Blog.

  •  

AI Can Find Your Location 91% of the Time Using Just One Photo

summer travel with a smartphone

How AI uses simple details in your photos to pinpoint where you are and why that’s a gold mine for scammers

McAfee Labs Safer Summer Travel Report | Summer 2026 

A Photo Is Worth a Thousand Data Points 

You just got back from a week in Central America. You posted a few shots: the colorful streets of Tulum, a picture of the ancient ruins of Tikal, a close-up of your shrimp tacos. No location tag. No caption naming the city. Just a good photo. 

A few days later, you get a message. It references your bank. It mentions suspicious activity “while traveling internationally.” It feels oddly specific, with details about where you were and when. It feels real. 

These types of personalized scam messages are a growing tactic. And your own photos may have helped write it.

McAfee Labs set out to understand exactly how much location information exists inside an ordinary travel photo, and what that means for the roughly 244 million Americans who travel each year.  

What we found should change the way you think about what you share online: Some AI models have a more than 90% accuracy rate at detecting the location a photo was taken based on the visuals in the photo alone. And critically, that level of accuracy is now achievable using tools that are free and widely accessible. 

That’s why we’ve built tools like McAfee’s Scam Detector that are designed to help spot these kinds of highly targeted, convincing messages before they lead to costly mistakes. 

What We Tested And Why 

The question McAfee Labs wanted to answer was deceptively simple: Can AI look at a travel photo and figure out where it was taken, even without GPS data or location tags? 

Not metadata. Not embedded coordinates. Just the image itself: the background, the architecture, the signage, the light; the visual context that any photo naturally captures. 

To find out, we built an automated testing pipeline and ran it against a dataset of 21,236 travel images sourced from publicly available image sets. We also conducted a separate, more controlled review of 102 additional images to pressure-test our findings. 

We tested two publicly available, large-scale AI vision models that are both freely available. Neither required special access, proprietary data, or advanced technical expertise to run. We used the same tools a scammer could access today. 

Each image was analyzed using a consistent automated prompt asking the model to identify the location depicted (city, country, or region) based solely on visual content. Results were then reviewed by human analysts to validate accuracy and flag edge cases.

What We Found: AI Has a Whopping 91% Accuracy Rate 

The results were striking. 

Gemma3 27B correctly identified the city and country of a travel photo 87% of the time. Qwen3 VL 30B performed even better, reaching 91% accuracy across the same dataset. 

That means in roughly 9 out of 10 cases, an AI model that’s available for free, to anyone, could look at an ordinary travel photo and correctly name where it was taken. This kind of analysis is also how AI tools understand images more broadly, shaping not just scams, but how information shows up in AI-powered answers. 

And when the exact city wasn’t identified, the country alone was almost always correct. For a scammer, that’s more than enough. It’s also enough to turn a vague, generic scam into one that feels specific, timely, and believable. 

What Makes a Photo Easy to Place? 

Certain types of images were identified with even higher confidence: 

  • Photos featuring famous landmarks or recognizable skylines 
  • Images taken in popular tourist destinations with distinctive visual signatures 
  • Photos with visible signage, unique street markings, or local architecture 
  • Images that captured cultural context: transportation, storefronts, food stalls 

Less recognizable scenery, like a generic beach, a rural road, or a hotel room, lowered accuracy. But even in those cases, country-level identification remained high. 

We Tried it. And We Were Spooked. 

To illustrate how simple this was to replicate, we moved outside of McAfee’s labs and asked our less-technical colleagues to try it themselves. No research background required. No special tools. 

Employees uploaded their own personal travel photos, images pulled straight from their camera rolls and never posted publicly, to ChatGPT, Claude, and Copilot, and simply asked each one to identify where the photo was taken. 

The results made people uncomfortable. 

Accuracy dropped compared to our controlled lab tests. But not by much. The models still correctly identified country-level location at a rate that would be more than enough for a scammer to craft a convincing, targeted message. 

The takeaway isn’t that AI has “seen” your photos somewhere before. It’s that a photograph inherently contains an enormous amount of locating information, in the architecture, the light, the signage, the landscape, simply by virtue of existing in the world. You don’t need to geotag a photo for it to give away where you’ve been. 

See It for Yourself 

The following section shows real examples of AI geo-location detection in action, using personal travel photos submitted by our research team. No location tags. No metadata. Just the image and what AI found in it. 

We started with somewhat recognizable structures in the background, and then tried increasingly more obscure backgrounds, trying to reduce faces and backgrounds to foliage only. This is what happened:

Example 1 

Brooke’s honeymoon pictures: This example features a more prominent landmark, helping AI determine the location  specifically. When there’s something recognizable, AI really recognizes it, down to giving you the exact spot on the map you’re at, the history of the location, and tourist information.

Screenshot of ChatGPT conversation identifying the location of a photo
Here, we see AI correctly state this photo was taken in front of “Temple II, Temple of the Masks.”

Example 2 

Sandra’s sunset photoThis example gets more difficult for AI by removing major landmarks and people. ChatGPT was still able to correctly identify the location as Hastings-on-Hudson. 

screenshot of AI correctly identifying location

 

 

Example 3 

Rob’s close-up shot of flowers: Just the close-up image of these tulips was enough for Claude to accurately detect that this photo was taken at Keukenhof gardens in the Netherlands.

AI was able to identify the location of these flowers in a close up.
AI was able to identify the location of these flowers in a close up.

How a Photo Becomes a Scam 

Knowing where someone is or where they’ve recently been is one of the oldest tricks in a scammer’s playbook. But until recently, getting that information required either knowing the person or getting lucky. 

AI removes the guesswork, allowing attackers to build highly specific, contextual scams at scale. 

With geo-location inference this accurate, scammers no longer need to cast a wide net and hope a generic phishing message lands. Instead, they can use publicly shared photos to build a believable context around an attack: 

  • “We detected unusual account activity while you were traveling in [city].” 
  • “Your card was flagged for a transaction in [country] — please verify immediately.” 
  • “Hi, we’re reaching out regarding your recent stay at a hotel in [destination].” 
  • “Hi, it’s [your name], I’m in Mexico and all my cards are being declined. Could you send me $$?” (a message targeting your friends or loved ones) 
  • “We noticed a login attempt from your location in [destination] — please confirm your identity.” 
  • “Your reservation in [city] requires reconfirmation — click here to secure your booking.” 
This is an example of a scam text detected by our research team. Now, imagine if scammers had more information, like the exact tour you were on, where you were, or the stores you shopped at. These details could make messages like this even more convincing and personalized.
This is an example of a scam text detected by our research team. Now, imagine if scammers had more information, like the exact tour you were on, where you were, or the stores you shopped at. These details could make messages like this even more convincing and personalized.

These messages don’t need to be perfectly accurate. They just need to feel plausible and close enough. That is the entire strategy. Familiarity lowers skepticism. Skepticism is what protects you. 

This is what turns mass phishing into hyper-personalized phishing at scale, and it’s why even cautious, digitally savvy travelers are getting caught. 

The Scammer’s New Workflow 

Here’s how straightforward this pipeline can become: 

  1. Find publicly shared travel photos on Instagram, Facebook, or X, no hacking required 
  2. Run them through a freely available AI vision model 
  3. Identify the likely destination, timeframe, and context 
  4. Craft a targeted message referencing that location 
  5. Send it during or shortly after the travel window, when the victim is most likely to believe it 

Steps 1 through 5 can be automated. The whole process scales easily. And the resulting messages feel personal in a way that generic scams never could. 

The Broader Scam Landscape Travelers Face 

Geo-location inference doesn’t exist in a vacuum. It’s one tool in a growing arsenal that scammers deploy specifically against travelers.  

Travelers are operating outside their normal routines, using unfamiliar networks, and making quick financial decisions under time pressure. These behaviors are exactly what make photo-based location inference more actionable for scammers. 

New McAfee consumer research found that more than 1 in 3 Americans have encountered a travel-related cyberthreat, and 41% of those impacted lost money, often exceeding $500. At the same time, rising travel costs and time pressure are pushing people toward faster, riskier decisions. Those are exactly the conditions scammers are built to exploit. 

The data reveals just how exposed travelers make themselves without realizing it. Nearly two-thirds of Americans connect to public Wi-Fi while traveling (63%), and a similar share scan QR codes without verifying where they lead (62%). Almost half use airport Wi-Fi specifically (49%), and 41% admit to trusting travel-related messages without checking the sender. One in five logs into financial apps while on public networks, and the same group shares travel plans in real time on social media. Twenty percent click travel-related links without verifying the source first. And finally, around 1 in 5 (22%) admit to sharing travel plans in real time.  

That last behavior is worth pausing on. Sharing travel plans in real time, on public or semi-public social accounts, is precisely what creates the photo-based location signals this research examines. These behaviors and geo-location exposure are not separate issues. They feed each other. 

Location inference is the key that makes all of those existing vulnerabilities more exploitable. A scammer with a rough idea of where you are does not just have a data point. They have a script. 

Methodology: How We Conducted This Research 

Transparency matters. Here is exactly how this research was conducted. 

Dataset: 21,236 travel images that are publicly available for research, plus a separate controlled set of 102 images contributed by McAfee internal volunteers (never previously posted publicly). 

Models tested: 

  • Gemma3 27B — a multi-model and vision-language model from Google DeepMind 
  • Qwen3 VL 30B — a multi-model and vision-language model from Alibaba’s Qwen team 

It’s important to note that we conducted our testing using large language models running locally on our own computers, rather than through public services such as ChatGPT.  

This more closely reflects how an attacker might operate at scale. Running models locally allows unrestricted, automated generation of large volumes of malicious content without relying on a third-party provider.  

By contrast, cloud-based AI services typically monitor for abuse and may impose rate limits, suspend accounts, or block requests when they detect activity associated with phishing or other malicious behavior. 

Process: An automated Python script submitted each image to both models using a standardized prompt requesting location identification based solely on visual content. No metadata, EXIF data, or file naming conventions were used as inputs. Results were logged programmatically. 

Validation: Image labels were pre-assigned prior to analysis. In cases where geographic names or landmarks could reasonably be interpreted in more than one way, a human reviewer compared the pre-labeled locations and model outputs to ensure consistent categorization.  

For example, the reviewer determined whether Vatican City should be grouped with Rome and whether “Washington D.C.” and “Washington, D.C.” should be treated as the same location. The reviewer did not alter either the original labels or the model results, but instead applied judgment to reconcile ambiguous naming conventions and edge cases. 

Accuracy definition: A result was counted as correct when the model identified the correct city and country. Country-only identification was tracked separately. Both metrics are reported. 

What this research does not claim: This research does not suggest that every travel photo will be correctly identified, or that all publicly available AI tools perform at this level. Results varied by image type, landmark density, and geographic region. The point is not perfect identification,  it’s that accuracy is high enough, and accessible enough, to enable targeted scams at scale. 

About the Consumer Research McAfee commissioned a consumer survey fielded in March 2026 examining travel intentions, travel scam experiences and perceptions, and digital behaviors while traveling. Results referenced here represent a subset of 1,000 U.S. adults over the age of 18. The full study included responses from 6,000 participants across Australia, France, Germany, Japan, the United States, and the United Kingdom. 

How to Protect Yourself 

Knowing the risk exists is the first step. Here’s what to actually do about it. 

Think before you post, especially in real time. The highest-risk window is when you’re still traveling. Posting while you’re in a location gives scammers a live signal. When possible, post after you’ve returned home or delay sharing location-identifiable content by a few days. 

Audit your social media privacy settings. Photos shared publicly are the easiest targets. Restricting your posts to people you know significantly limits the pool of images that can be scraped and analyzed. 

Be skeptical of urgency tied to your location. If a message references where you’ve been, even correctly, treat that as a red flag, not a credibility signal. Scammers use location familiarity precisely because it feels reassuring. 

Go directly to the source. If you receive a message claiming to be from your bank, airline, hotel, or card provider while traveling, don’t click any link in the message. Open a new browser tab and navigate directly to the company’s official website, or call the number on the back of your card. 

Use a travel-specific email or alias. Some travelers use a separate email address for bookings, reservations, and travel apps. This limits the cross-referencing scammers can do between your social media presence and your financial accounts. 

Trust the skepticism, not the familiarity. Modern scams are designed to feel familiar before they feel suspicious. If something creates a sense of urgency around your financial accounts while you’re traveling, slow down. The pressure itself is the warning sign. 

How McAfee Protects You Before, During, and After Travel 

As prices rise and decisions happen in real time, it’s easy to prioritize convenience over caution. But that’s exactly the moment when small checks matter most. 

Stage of Travel  What’s Happening  How McAfee Helps 
Before You Book  Comparing deals, clicking promotions, booking flights and hotels under time pressure  Scam Detector checks links, messages, and booking sites before you click, helping you avoid fake deals and scam listings 
During Your Trip  Connecting to public Wi-Fi, scanning QR codes, receiving travel updates and alerts  VPN helps secure your connection on public Wi-Fi, while Scam Detector flags suspicious messages and unsafe links in real time 
After Your Trip  Accounts remain active, travel data stored across platforms, potential exposure from breaches  Identity Monitoring alerts you if your personal information appears online, helping you act quickly before damage spreads 

With McAfee+ Advanced, multiple layers work together so you’re not left figuring it out after the damage is done.  

So you can focus on your trip, and not on whether that notification is a scam. 

Final Thought 

A travel photo is a memory. It’s also, increasingly, a data point. 

That doesn’t mean you should stop sharing your experiences. It means understanding that the same visual richness that makes a great photo is exactly what AI systems are trained to read. 

Scammers know this. Now you know how to protect yourself. 

This report was produced by McAfee Labs. Research was conducted in 2025–2026 as part of McAfee’s ongoing monitoring of AI-enabled scam vectors. 

The post AI Can Find Your Location 91% of the Time Using Just One Photo appeared first on McAfee Blog.

  •  
❌