Today’s Menu (30-second skim)

  • Fake law-firm letters are promising millions in life insurance money: Scammers are mailing official-looking letters that promise fake life insurance money so they can steal your cash or personal information.
  • Zoom patched a Windows flaw that could let attackers take over accounts: If your Zoom app on Windows is out of date, someone could hijack the account and use it to spy, impersonate you, or spread bad links.
  • 23andMe agreed to an $18 million settlement over its genetic data breach: A new settlement puts fresh attention on how exposed DNA account data can follow people long after a breach is over.

1) Fake law-firm letters are promising millions in life insurance money

Letter with QR code and hook icon

What happened (plain English): The FTC says scammers are mailing paper letters that pretend to come from real law firms. The letter claims a person with your last name died and left behind a life insurance policy worth millions of dollars. It says you can share the money with the so-called law firm and sometimes even a charity, which makes the story sound generous and official. But the money is not real. The goal is to get you to reply, trust them, and hand over personal details, bank information, or upfront fees.

Why it matters to you: A paper letter can feel more believable than a text message because it looks formal and arrives in your mailbox. That makes it easier for someone to lower their guard and call the number or send documents. One common abuse scenario is paying a fake processing fee for money that does not exist. Another is giving away enough personal information for identity theft, new scams, or account fraud later.

How to protect yourself (do this):

  • Treat any surprise inheritance or insurance claim as fake until you verify it another way.
  • Do not call the number in the letter or send money, documents, or account details.
  • If you are unsure, ask a family member or contact a trusted lawyer or insurer using a phone number you looked up yourself.

Published: 2026-07-15

Source: FTC Consumer Advice


2) Zoom patched a Windows flaw that could let attackers take over accounts

Security warning on a computer screen representing a data breach

What happened (plain English): Zoom published a security bulletin about a serious bug in its Windows software. The company said the issue affected Zoom Workplace for Windows and some Zoom VDI Windows versions. According to Zoom, the flaw could let an attacker take over an account over the network without first signing in. That means the danger was tied to the software itself, not just weak passwords. Zoom says users should install the latest updates right away.

Why it matters to you: If you use an older Zoom app on Windows, someone could hijack the account and act like they are you. That could mean joining private meetings, reading meeting details, or sending harmful links to coworkers, friends, or family. A stolen work account could be used to spy on business calls or trick teammates into trusting a fake message. A stolen personal account could be used to embarrass you, snoop on conversations, or spread more scams through your contacts.

How to protect yourself (do this):

  • Update Zoom on Windows now instead of waiting until later.
  • Only get Zoom updates from Zoom itself or your device’s official software updater.
  • If you get an email warning about Zoom, do not click first – open the app or official Zoom website yourself and update there.

Published: 2026-07-14

Source: Zoom


3) 23andMe agreed to an $18 million settlement over its genetic data breach

Data breach exposed personal information

What happened (plain English): A group of state attorneys general announced that 23andMe agreed to an $18 million settlement over its 2023 data breach. Officials said 6.9 million consumers were affected worldwide. The exposed information included sensitive customer details and, for some people, genetic ancestry information. Investigators said the company had weak protections against password-stuffing, which is when criminals try passwords stolen from other sites. They also said monitoring for suspicious logins was not strong enough.

Why it matters to you: DNA and family history are deeply personal, and you cannot change them the way you can change a password. If criminals connect breached account details with other leaked information, they can build a much more believable scam around your identity or relatives. One abuse scenario is a fake health, family, or legal message that uses personal details to sound real. Another is using your old reused password to break into other accounts that still hold financial, medical, or identity information.

How to protect yourself (do this):

  • If you ever used 23andMe or a similar DNA service, change that password anywhere else you reused it.
  • Turn on two-factor authentication wherever you can, especially for accounts tied to health, money, or identity.
  • Review older accounts that store very personal information and delete what you no longer want companies to keep.

Published: 2026-07-14

Source: Pennsylvania Office of Attorney General


Grandma’s Firewall

Grandma's Firewall

This week’s simple rule:

Surprising good news and scary security warnings use the same trick: they try to make you react before you think. Put every surprise on a short pause.

Two scripts you can steal:

  • “I’m not doing anything with this until I check it another way.”
  • “I’ll contact the company myself using the app, website, or number I already trust.”

Top rated products