
How Attackers Bypass MFA in the Real World
The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay…
A Welsh Doxbin administrator, Callum Dare, was jailed after investigators linked him to encouraging and assisting others to place dangerous “swatting” hoax calls in the UK, US, and Canada. The hoaxes included false reports of bombs, hostages, shootings, and explosives, designed to trigger armed police responses and public evacuations.
A Welsh Doxbin administrator, Callum Dare, was jailed for encouraging and assisting others to carry out swatting hoax calls in the UK, US, and Canada. Dare did not make the calls himself. Instead, he used Doxbin's "#deadnet" channel to motivate others and shared montage videos of police responses to encourage further attacks. The hoax calls themselves used extreme pretexts, including bomb threats, nail bombs, hostage situations, and claims of being armed with explosives, all designed to force an immediate, large-scale emergency response.
Each hoax call relied on urgency and violence to bypass normal verification. A caller with a fake Russian accent told the Los Angeles Police Department that bombs were placed under chairs in a University of California lecture theater, causing an evacuation. Another caller told a Western Mail journalist he was armed with nail bombs and holding hostages at a named Cardiff hotel, which led police to close off and evacuate the street. In a third case, a caller claimed to be at a private address, having shot a victim and taken hostages while armed with explosives. In all three cases, the recipient had no practical way to verify the caller's identity or confirm the threat before responding.
Organizations that could plausibly receive one of these calls, including university administration, campus security, newsrooms, corporate communications, and hospitality front desks, benefit from a written playbook for handling bomb, hostage, or shooting claims. This should define who takes the call, what details to record (exact wording, caller number, claimed location), and how to escalate to police without amplifying unverified information further than necessary.
Because swatting depends on knowing where to aim a false threat, reducing the amount of personally identifiable information, especially home addresses, posted publicly about staff and executives lowers the chance that a swatting call can be targeted at a real person's location. Doxbin itself is described as a platform used to expose personal information specifically to enable harassment and swatting, underscoring why limiting exposed PII matters as a defensive measure alongside call-handling training.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Swatting is a hoax emergency call, such as a false bomb or hostage threat, designed to trigger an armed police response to a target's location. It relies on the same pressure and urgency tactics used in vishing attacks to bypass normal verification.
Callum Dare was a Doxbin administrator convicted for encouraging and assisting others to carry out swatting hoax calls across the UK, US, and Canada, though he did not personally make the calls.
Callers used pretexts like bomb threats, hostage situations, and claims of being armed with explosives, sometimes disguising their accent, to pressure police and organizations into immediate evacuation or armed response.
Build a written verification and escalation playbook for bomb, hostage, or shooting claims, train front-line staff to capture caller details without prolonged engagement, and reduce public exposure of employee addresses that could be used to aim an attack.
Imagine you pick up the phone and hear: “There are bombs under the chairs at a University of California lecture.” What do you do next? A Doxbin admin, Callum Dare, was jailed for encouraging swatting, fake bomb, hostage, and shooting calls, like a hoax nail‑bomb hostage threat at Cardiff’s Sandringham Hotel that shut down St Mary Street. Swatting calls use accents, extreme threats, and specific locations to force instant action: “I’m armed with nail bombs and holding hostages at Cardiff’s Sandringham Hotel on St Mary Street.” That’s social engineering by phone. Your move: if you ever get a bomb, hostage, or shooting call, follow our emergency call playbook on the intranet, capture exact words and location, then hand it straight to security or 999, nothing else.

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay…

Scammers on TikTok are impersonating resin artists by reposting stolen videos and telling viewers to “DM to order.” After moving the conversation into direct…

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into…

Apple warns that scammers are using FaceTime calls, often with spoofed caller ID, to impersonate Apple or banks and pressure people into sharing passwords,…

The article highlights how attackers can quickly build convincing executive “profiles” from public information and use them to manipulate employees. It cites…

Qantas avoided a formal Australian privacy regulator investigation after a June 2025 breach that impacted about 5.12 million people. The breach started with a…