Plain-English intelligence on phishing, malware, ransomware, and the cons aimed at families — written by people who watch real inboxes for a living. No jargon, no fearmongering, no fluff.
After breaking into an email account, the scammer's first move is often a quiet rule that deletes or buries the bank's fraud alert, the provider's security warning and a worried friend's reply, so nothing looks wrong. The signs that leak through anyway, and how to check Gmail filters and Outlook rules in five minutes.
Read it →A caller says your account needs an urgent passkey or security update. Microsoft documented this exact script in September against company help desks; the trick underneath is an old one. Passkeys themselves are safe. What to say, what never to approve, and the family rule that stops it.
Read it →A real vendor, a real invoice thread, and a reply asking you to pay a new account. Every technical check passes because the account really was taken over. How conversation hijacking works, what AI is changing, and the callback rule that stops it for churches and small offices.
Read it →A card from someone you actually know, sent from their real email account to their whole contact list, that asks for your email password before you can view it. How a hijacked account spreads a fake Paperless Post invitation like a chain letter, the tells that expose it, and the full checklist to undo it — whether you received one, clicked one, or your own account sent it.
Read it →A Texas woman received an email with her pastor's name on it, asking her to buy gift cards for church volunteers — keep it a surprise. She lost $23,000 before she realized the email never came from him. Here is exactly how this scam works, why faith communities are a particular target, and the one phone call that stops it every time.
Read it →A fake CAPTCHA or error tells you to press a few keys — and you run the malware yourself, right past the antivirus. These attacks jumped 517% in a year. Every disguise it wears, what it steals, and the one rule that stops it.
Read the full breakdown →Attackers this month are sending fake vendor quotes and invoice requests to churches and nonprofits through real, compromised mail servers — so every technical security check passes. The sender is legitimate, the attachment is a picture, and your filters wave it through. The only defense is a 60-second conversation with the person who would have made the request. Here is the protocol.
Read it →Cryptocurrency investment scammers spend weeks building a fake online friendship, steer you into a bogus trading platform, then — when banks block the wire transfer — send a courier to your home to collect cash in person. The FBI issued a formal warning about this tactic in June 2026. Here is how the scheme works, the one rule that defeats it, and what to do if someone in your family has already been contacted.
Read it →Americans lost $470 million to text scams in 2024, and the most-reported type is the fake package delivery alert impersonating USPS, FedEx, or UPS. A criminal network has built more than 28,000 lookalike USPS websites to harvest card numbers. Here's what the text is really after, the one sign that always gives it away, and what to do if someone in your family already tapped the link.
Read it →Email security was built to find the bad thing in a message. The newest attacks win by making sure there isn't one: the QR code is just an image, the attachment is a picture that's secretly a program, the HTML file is empty until your browser fills it in — and the writing is flawless, because a machine wrote it. A technical breakdown of the techniques defeating signature-based filters, and the intent-based defenses that answer them.
Read the full analysis →"Turn on MFA" was good advice for a decade. It is no longer sufficient. A class of phishing kit now steals the live session token — the thing MFA can't protect — and replays it from the attacker's browser, no code, no prompt. How the reverse-proxy attack works, the phishing-as-a-service economy selling it by subscription, and the phishing-resistant defenses that actually stop it.
Read the full analysis →Scammers can now copy a loved one's voice from a few seconds of audio — a video, a voicemail — and fake a panicked emergency call asking for money. It's the oldest trick with a frightening new twist. Here's exactly how it works, and the simple family plan that stops it cold: a safe word, a hang-up, and a call back.
Read it →Corporate email gets guarded by security teams and million-dollar tooling. Your personal inbox — where your bank statements, medical bills, and family photos live — gets a spam filter built to stop bulk junk mail. Here's what's actually coming at it this year: the phishing that impersonates your bank pixel-perfectly, the malware riding in "invoice" attachments, and the scams engineered for the people you love.
Read the full report →Americans over 60 lost $7.75 billion to fraud last year — up 59% in a single year, and the average successful scam costs a senior over $33,000. Credit and identity tools sound the alarm after the wire clears. Family Sentinel is the only watch that sits in the inbox, where the con is built and believed, and steps in before the money moves.
We see the scam email or text first — where there's still time to stop it, not after.
The hardest part of a scam is admitting it almost worked — so no one has to confess to be protected.
Nothing installed on the device, no passwords shared, revoke in one click. Oversight that never feels like a leash.
Every serious threat is verified by a working Security Architect before you're alarmed — and when you call, a person answers.
A short, plain-English briefing on the newest phishing, malware, and impersonation attacks — and how to spot them. Free, and unsubscribe in one click.
We never sell or share your address — ever.