JCyberSec_ Profile Banner
Jake | JCyberSec_ Profile
Jake | JCyberSec_

@JCyberSec_

Followers
10K
Following
24K
Media
3K
Statuses
9K

Expert in Credential Phishing and Phishing Kit Research. Working in Cyber Security - Threat Intelligence #Phishing

UK
Joined August 2017
Don't wanna be here? Send us removal request.
@JCyberSec_
Jake | JCyberSec_
6 days
HMRC show the scale of these campaigns - Over 4,600 websites 📈. 🔨And yet they still get stood up, hundreds per day!.
Tweet media one
Tweet media two
@HMRCgovuk
HM Revenue & Customs
6 days
We took down more than 4,600 Winter Fuel Payment scam websites in June, protecting taxpayers across the UK. ⛔. If you’re unsure if the contact you’ve received from us is genuine, use our online guidance to learn how to recognise and report scams. ⬇️.
Tweet media one
0
0
1
@JCyberSec_
Jake | JCyberSec_
22 days
A new cluster sitting on IP: 47.251.127.54
Tweet media one
Tweet media two
0
0
1
@JCyberSec_
Jake | JCyberSec_
22 days
Always remember hunt, pivot, and analyse. Using the right tools allows you to expand your visibility into threats to assess the risk posed and understand the actors behind them.
0
0
0
@JCyberSec_
Jake | JCyberSec_
22 days
Notably 2 domains stand out:.fetcetcgovstw[.]top.phlmpost-gov[.]com. These appear to be targeting government bodies within the Philippines. Ones to watch.
1
0
0
@JCyberSec_
Jake | JCyberSec_
22 days
The second domain: golbe-phlu3[.]com is again using Cloudflare🌐. This time rather than pattern matching we can look at nameserver overlaps. Looking at the Cloudflare NSs we find more domains all linked. nameserver:(AND
Tweet media one
1
0
0
@JCyberSec_
Jake | JCyberSec_
22 days
The first domain: globeio-ph[.]com sits behind CloudFlare🌐. 👓We can look at the hostname pattern to allow us to find more linked domains. @urlscanio hunting: 'hostname_dashes:>0 AND hostname: globe*AND tags:apexdomain'
Tweet media one
1
0
0
@JCyberSec_
Jake | JCyberSec_
22 days
This is a SMS phishing campaign targeting GLOBE a telecoms provider in Philippines 🇵🇭📲📶. ⚠️The Smishing message is injected into the legitimate GLOBE short code flow💉. There are 2 domains seen but there are hundreds more. 📈. 🔎Let's go hunting in @urlscanio ⤵️
Tweet media one
1
1
3
@JCyberSec_
Jake | JCyberSec_
22 days
I wonder what triggered this public service announcement from the DWP 😁.
@DWPgovuk
Department for Work and Pensions
22 days
Be aware of scam text messages claiming to be from @dwpgovuk. Always be careful about links and never share personal or financial details . Only engage with trusted official sources. You can report suspicious messages to @actionfrauduk or search
Tweet media one
1
0
2
@JCyberSec_
Jake | JCyberSec_
28 days
@DWPgovuk This group is also targeting UK parking fines and penalty charges. ip:47.251.117.125 AS45102 🇨🇳
Tweet media one
2
1
2
@JCyberSec_
Jake | JCyberSec_
28 days
@DWPgovuk Another linked IP: 47.251.127.67 . 📈28 more hostnames
Tweet media one
2
1
5
@JCyberSec_
Jake | JCyberSec_
28 days
@DWPgovuk Some pivoting on the pattern and found another IP linked to this⤵️. 📈40 more hostnames. IP:49.51.135.75 AS132203🇨🇳
Tweet media one
1
1
3
@JCyberSec_
Jake | JCyberSec_
28 days
Been sent an interesting UK @DWPgovuk smishing message 📲. 🔭URL pattern has been seen 37 other times. All sitting on ip:47.251.59.158 AS45102🇨🇳. 🖥️Interestingly there is a /api directory which is called when the page is loaded. #phishing
Tweet media one
Tweet media two
Tweet media three
1
2
10
@JCyberSec_
Jake | JCyberSec_
3 months
Hey @0x6rss can you DM me please! 👍.
0
0
0
@JCyberSec_
Jake | JCyberSec_
4 months
We are seeing an increase in QR code overlays in the UK📈🧑🏼‍💻. 💻Interesting domain linked to this campaign . 🌐/payzoneparking.info which redirected to 🌐/payzoneparking.contact. 🔥👀Second image is another campaign and the poster included the person apparently responsible
Tweet media one
Tweet media two
Tweet media three
@LeilaniDowding
leilani dowding 🌸🚜 ☮️
4 months
Please be careful with fake QR codes at car parks, or anywhere you need to pay. People are getting scammed out of thousands by entering their card details in
0
3
13
@JCyberSec_
Jake | JCyberSec_
4 months
🔎This is the first case of an RCS spam message that I have seen👀. ⚠️RCS acts like other rich media messaging allowing for media, text & buttons to be embedded into a message. 🇮🇳This is an Indian example but brace for more English language campaigns using RCS📈. #RCS #Phishing
Tweet media one
0
0
4
@JCyberSec_
Jake | JCyberSec_
5 months
🔒Recommendations:. 1⃣ Secure the entire identity ecosystem.2⃣ Eliminate cross-domain visibility gaps.3⃣ Defend the cloud as core infrastructure.4⃣ Prioritize vulnerabilities with an adversary-centric approach.5⃣ Know your adversary and be prepared
Tweet media one
0
0
0
@JCyberSec_
Jake | JCyberSec_
5 months
Key highlights:🔦. ☎️Voice phishing up 422%.☁️35% of cloud incidents were through valid accounts.💻The technology sector was the most targeted
Tweet media one
@blackorbird
blackorbird
5 months
CrowdStrike Global Threat Report 2025.
Tweet media one
1
0
6
@JCyberSec_
Jake | JCyberSec_
5 months
🛡️ Defending Against eM Client Abuse:. ✅ Disable IMAP/SMTP where possible.✅ Enforce MFA with app-specific passwords 🔑.✅ Monitor for unauthorized client connections.✅ Educate users on phishing risks 🎓. #CyberSecurity.
0
0
0
@JCyberSec_
Jake | JCyberSec_
5 months
Implement Conditional Access: Enforce policies that restrict access based on device compliance or location. User Training: Educate staff about the risks of unauthorized applications. Layered security measures are key to protection.
1
0
0
@JCyberSec_
Jake | JCyberSec_
5 months
🔧 Mitigation Strategies.To defend against eM Client exploitation:. Restrict Application Registrations: Limit who can register applications in your environment. Disable Legacy Protocols: Turn off IMAP/SMTP if not required.
1
0
0