Today’s Menu (30-second skim)

  • Scammers are using QR codes and barcodes as the new gift cards: Criminals are telling people to load money onto QR codes and barcodes instead of old-school gift cards.
  • Frontline Education breach exposed school district employee information: A school software breach exposed personal details for some district employees, including Social Security numbers in at least one case.
  • Microsoft’s official X account was hijacked to promote a crypto scam: A real Microsoft social account was taken over and used to push a fake crypto promotion.

1) Scammers are using QR codes and barcodes as the new gift cards

Scammers are using QR codes and barcodes as the new gift cards story image

What happened (plain English): The Social Security Administration’s watchdog warned about a payment scam that uses QR codes and barcodes. Scammers may call or text while pretending to be police, a sheriff’s office, a federal agent, or someone helping a family member in trouble. Instead of asking for gift cards, they send a code and tell the victim to take it to a store and load money onto it. To the victim, it can feel like paying a bill or helping with an emergency. But once the money is loaded and the code is shared, the scammer can grab it quickly.

Why it matters to you: This trick is dangerous because the QR code or barcode is the trap, even if you never give away your Social Security number or password. A scammer might say your grandchild is in jail and needs payment right now, then send a barcode to “fix it.” Another scammer might pretend to be a government office and say you owe a fine that must be paid at a store. Fear and urgency are the tools, and the code is how they collect the money.

How to protect yourself (do this):

  • If someone tells you to put money on a QR code or barcode, stop. Real law enforcement and government agencies do not collect money that way.
  • Hang up and call the agency or family member using a number you find yourself, not a number the caller gives you.
  • Talk to one trusted person before paying during any surprise emergency.

Published: 2026-09-28

Source: SSA Office of the Inspector General


2) Frontline Education breach exposed school district employee information

Frontline Education breach exposed school district employee information story image

What happened (plain English): Frontline Education, a company used by school districts for administration and workforce tools, started notifying districts about a data breach. Attackers reportedly used a weakness in third-party software to get into part of Frontline’s systems. For at least one district, the exposed information included employee Social Security numbers, email addresses, and home addresses. Affected adults are being offered two years of credit monitoring and identity theft protection through TransUnion. This is the kind of breach where people may be affected even if they never personally chose to use the software.

Why it matters to you: School employees could be targeted for identity theft, fake tax filings, loan fraud, or very believable phishing emails. For example, a criminal could email a teacher pretending to be payroll and include the correct district name and personal details to sound real. Someone could also use stolen information to try opening credit in an employee’s name. When employers and schools use outside systems, your information can be caught up in someone else’s security problem.

How to protect yourself (do this):

  • If you receive a breach notice, read it carefully and sign up for the free protection if offered.
  • Consider freezing your credit with Equifax, Experian, and TransUnion so criminals cannot easily open new credit in your name.
  • Be extra suspicious of calls or emails that mention your school district, benefits, payroll, or identity monitoring and ask you to click fast.

Published: 2026-10-02

Source: BleepingComputer


3) Microsoft’s official X account was hijacked to promote a crypto scam

Microsoft’s official X account was hijacked to promote a crypto scam story image

What happened (plain English): Attackers got unauthorized access to Microsoft’s official X account, which has more than 13 million followers. The account reposted content promoting a crypto token using Microsoft’s Clippy branding. Microsoft removed the unauthorized posts, secured the account, and said it is investigating. The big lesson is simple: even a famous, real, blue-check account can be temporarily taken over. A post can look official and still be part of a scam.

Why it matters to you: People are more likely to trust a scam when it appears to come from a brand they recognize. A fake crypto post from a famous account might push you to buy a coin before you think, connect your wallet, or approve a transaction. One bad wallet approval can drain real money fast. A “limited time” investment offer on social media is especially risky because it is designed to make you act before you check.

How to protect yourself (do this):

  • Do not buy crypto, enter a password, or connect a wallet just because a famous account posted a link.
  • Check the company’s official website or press page before trusting a surprise promotion.
  • Treat any “limited time” investment offer on social media as guilty until proven innocent.

Published: 2026-10-02

Source: BleepingComputer


Grandma’s Firewall

Grandma's Firewall

This week’s simple rule:

A logo, blue check, government name, or QR code is not proof. If it asks for money, a login, or a wallet connection, leave the message and use a trusted path you choose yourself.

Two scripts you can steal:

  • I’m not paying from a code or link. I’m going to hang up and call the real office myself.
  • I don’t make money decisions from social media posts, even if the account looks official.

Top rated products