Today’s Menu (30-second skim)
- O2 warns of a new inactive SIM scam targeting mobile customers: Fraudsters are posing as O2, pushing people to a fake login page, and trying to steal account credentials.
- LastPass says customer names, contact details, and support case records were stolen in a partner breach: The breach did not hit password vaults, but support records can still give scammers believable details to work with.
- Polymarket says hackers stole users’ funds after a third-party breach: The company says it contained the issue and is refunding victims, but the incident shows how quickly a web app compromise can turn into real money loss.
1) O2 warns of a new inactive SIM scam targeting mobile customers

What happened (plain English): Virgin Media O2 warned customers about a phishing scam where fraudsters pretend to be the telecom company and say SIM cards will be deactivated unless people accept new terms and conditions. The message sends victims to a fake O2 site that asks them to log in and hand over their MyO2 credentials. O2 says it has already blocked more than 1 billion scam messages, but the fake texts and sites keep evolving. The company is telling people to report suspicious messages to 7726.
Why it matters to you: A mobile account takeover can lock you out of your phone number, your two-factor codes, and any account tied to that number. The scam also uses urgency and fear, which is exactly what gets people to click before they think. If you rely on your phone for banking, email, or work, this kind of phishing can snowball fast. A fake SIM warning is the sort of message many people will trust if it looks official enough.
How to protect yourself (do this):
- Do not click links in unexpected texts about your SIM, billing, or account status.
- Open the MyO2 app or go to the official site yourself if you need to check anything.
- Report suspicious messages to 7726, and change your password immediately if you already clicked.
Published: 2026-06-30
Source: Virgin Media O2
2) LastPass says customer names, contact details, and support case records were stolen in a partner breach

What happened (plain English): LastPass said hackers got customer information during a breach at Klue, one of its technology partners. The stolen data includes names, phone numbers, email addresses, physical addresses, and customer support case records. LastPass said its own systems were not breached in this incident, and customers’ password vaults were not taken. The problem is that support records can reveal the kinds of issues people had with their accounts. That gives crooks a script they can use to sound informed and trustworthy.
Why it matters to you: If a scammer knows your name, contact info, and details from a past support problem, a fake support message becomes much more believable. You might get a call or email that mentions a real account issue and then asks for a one-time code or password reset approval. Someone could also claim your account is in danger and pressure you to act fast before you have time to think. These tricks work because they mix real facts with fake instructions.
How to protect yourself (do this):
- Treat any unexpected LastPass call, email, or text as suspicious, even if it mentions real details about you.
- Never share a one-time code, master password, or recovery phrase with anyone claiming to be support.
- Open your password manager app or type the company website yourself if you need to check alerts or change settings.
Published: 2026-06-23
Source: TechCrunch
3) Polymarket says hackers stole users’ funds after a third-party breach

What happened (plain English): Polymarket confirmed that hackers stole funds from an unspecified number of users after a third-party breach let malicious code reach its site for some users. The company says it contained the incident and is refunding affected victims in full. TechCrunch reported that the theft appears to have involved users’ crypto funds, and that phishing reports surfaced around the same time. In other words, this was not just a scare. Real money moved out the door.
Why it matters to you: If you use crypto apps or prediction markets, a web compromise can become a wallet drain in minutes. Even a brief site injection or fake prompt can push people to approve the wrong transaction or hand over access they should never share. The big lesson is the same one we keep seeing: if a site or message suddenly pushes you to act, pause before you approve anything. Crypto scams move fast because the money moves fast.
How to protect yourself (do this):
- Use the official app or bookmarked site instead of clicking links from messages or posts.
- Never share a seed phrase, recovery phrase, or wallet login with anyone claiming to help.
- Review wallet activity often and move funds off a platform when you are done using it.
Published: 2026-06-25
Source: TechCrunch
Grandma’s Firewall
This week’s simple rule: If a message or login screen wants your money, password, or code, stop and open the real app or website yourself.
Two scripts you can steal:
- “I’m not using the link in the message. I’ll open the app myself.”
- “I don’t hand over codes or passwords on the spot. I’ll check first and call back if it’s real.”
Share this: Forward it to someone who clicks the first urgent text they see.
– Philip | Human In[Security]

