EU court adviser says banks must immediately refund phishing victims

2026-03-08T19:23:37Z21a802fa310f9caf31d84965c79a0f505b14adce6fba123d159e0922efe78823
ai-abuse','infostealer','openclaw','bing-aiapt-uAT-9244arpacastleratcisaclickfixcognizantcoruna-exploit-kitdata-breachdonutloaderfbi-breachgithub-malwarehealthcare-datainstallfixios-vulnerabilitiesipv6phishingphishing-evasiontelco-targetingtermite-ransomwaretrizettovelvet-tempestweb-vulnerabilitywikipedia-wormwordpress-plugin

What happened

Multiple security and legal developments: an EU CJEU adviser recommended banks must immediately refund customers for unauthorized transactions (including phishing) even when user error is involved; threat actors are abusing the special-use .arpa domain and IPv6 reverse DNS to evade phishing/domain-reputation checks; Termite/Velvet Tempest campaigns use ClickFix social engineering and legitimate Windows utilities to deploy DonutLoader and the CastleRAT backdoor; Microsoft reports widespread attacker use of AI across attack stages; Cognizant TriZetto suffered a breach exposing ~3.4 million患者/ins

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
21a802fa310f9caf31d84965c79a0f505b14adce6fba123d159e0922efe78823
Enrichment time
2026-03-08T19:23:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.