<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>GlobalGuard Blog</title>
    <link>https://www.globalguard.com/blog</link>
    <description>Get the latest news and email threat intelligence from the GlobalGuard team</description>
    <language>en</language>
    <pubDate>Tue, 18 Aug 2026 05:43:22 GMT</pubDate>
    <dc:date>2026-08-18T05:43:22Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>ChatGPT 'Update Your Payment Details' Scam</title>
      <link>https://www.globalguard.com/blog/chatgpt-update-your-payment-details-scam</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.globalguard.com/blog/chatgpt-update-your-payment-details-scam" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.globalguard.com/hubfs/OpenAI%20-%20H.png" alt="ChatGPT 'Update Your Payment Details' Scam" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;span style="background-color: transparent;"&gt;A new phishing email campaign is impersonating ChatGPT and OpenAI billing. The scam claims that the recipient’s last ChatGPT Plus payment has failed and urges them to “update your payment details”, but instead directs them to a fake Stripe checkout page designed to steal email addresses, credit card details and billing information.&lt;/span&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;/h2&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.globalguard.com/blog/chatgpt-update-your-payment-details-scam" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.globalguard.com/hubfs/OpenAI%20-%20H.png" alt="ChatGPT 'Update Your Payment Details' Scam" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;span style="background-color: transparent;"&gt;A new phishing email campaign is impersonating ChatGPT and OpenAI billing. The scam claims that the recipient’s last ChatGPT Plus payment has failed and urges them to “update your payment details”, but instead directs them to a fake Stripe checkout page designed to steal email addresses, credit card details and billing information.&lt;/span&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;/h2&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=441818&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.globalguard.com%2Fblog%2Fchatgpt-update-your-payment-details-scam&amp;amp;bu=https%253A%252F%252Fwww.globalguard.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>American Express scam</category>
      <pubDate>Tue, 18 Aug 2026 05:43:22 GMT</pubDate>
      <guid>https://www.globalguard.com/blog/chatgpt-update-your-payment-details-scam</guid>
      <dc:date>2026-08-18T05:43:22Z</dc:date>
      <dc:creator>GlobalGuard</dc:creator>
    </item>
    <item>
      <title>American Express 'Sign-In Alert Phishing Scam</title>
      <link>https://www.globalguard.com/blog/american-express-sign-in-alert-phishing-scam</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.globalguard.com/blog/american-express-sign-in-alert-phishing-scam" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.globalguard.com/hubfs/AdobeStock_2048363529.jpeg" alt="American Express 'Sign-In Alert Phishing Scam" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;span style="background-color: transparent;"&gt;GlobalGuard has intercepted a new phishing email campaign impersonating American Express, designed to trick recipients into handing over their credit card account details, card verification data, personal identity information and multi‑factor authentication codes.&lt;/span&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;/h2&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.globalguard.com/blog/american-express-sign-in-alert-phishing-scam" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.globalguard.com/hubfs/AdobeStock_2048363529.jpeg" alt="American Express 'Sign-In Alert Phishing Scam" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;span style="background-color: transparent;"&gt;GlobalGuard has intercepted a new phishing email campaign impersonating American Express, designed to trick recipients into handing over their credit card account details, card verification data, personal identity information and multi‑factor authentication codes.&lt;/span&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;/h2&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=441818&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.globalguard.com%2Fblog%2Famerican-express-sign-in-alert-phishing-scam&amp;amp;bu=https%253A%252F%252Fwww.globalguard.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>American Express scam</category>
      <pubDate>Tue, 18 Aug 2026 04:46:50 GMT</pubDate>
      <guid>https://www.globalguard.com/blog/american-express-sign-in-alert-phishing-scam</guid>
      <dc:date>2026-08-18T04:46:50Z</dc:date>
      <dc:creator>GlobalGuard</dc:creator>
    </item>
    <item>
      <title>Quickbooks Payment Confirmation Phishing Alert</title>
      <link>https://www.globalguard.com/blog/quickbooks-payment-confirmation-phishing-alert</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.globalguard.com/blog/quickbooks-payment-confirmation-phishing-alert" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.globalguard.com/hubfs/QuickBooks%20-%20H.png" alt="Quickbooks Payment Confirmation Phishing Alert" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;span style="background-color: transparent;"&gt;GlobalGuard has intercepted a new phishing campaign impersonating Intuit QuickBooks that attempts to steal victims' account credentials by directing them to a fake login page designed to harvest usernames and passwords. Unlike many phishing campaigns that rely solely on deceptive emails, this attack uses a polished HTML email and a staged credential‑capture flow that mimics genuine QuickBooks interfaces. The scam leverages convincing branding, realistic payment details, and urgency cues to trick recipients into entering their login information.&lt;/span&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;/h2&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.globalguard.com/blog/quickbooks-payment-confirmation-phishing-alert" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.globalguard.com/hubfs/QuickBooks%20-%20H.png" alt="Quickbooks Payment Confirmation Phishing Alert" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;span style="background-color: transparent;"&gt;GlobalGuard has intercepted a new phishing campaign impersonating Intuit QuickBooks that attempts to steal victims' account credentials by directing them to a fake login page designed to harvest usernames and passwords. Unlike many phishing campaigns that rely solely on deceptive emails, this attack uses a polished HTML email and a staged credential‑capture flow that mimics genuine QuickBooks interfaces. The scam leverages convincing branding, realistic payment details, and urgency cues to trick recipients into entering their login information.&lt;/span&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;/h2&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=441818&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.globalguard.com%2Fblog%2Fquickbooks-payment-confirmation-phishing-alert&amp;amp;bu=https%253A%252F%252Fwww.globalguard.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>QuickBooks</category>
      <category>Intuit</category>
      <category>Intuit Quickbooks</category>
      <pubDate>Tue, 18 Aug 2026 03:40:43 GMT</pubDate>
      <guid>https://www.globalguard.com/blog/quickbooks-payment-confirmation-phishing-alert</guid>
      <dc:date>2026-08-18T03:40:43Z</dc:date>
      <dc:creator>GlobalGuard</dc:creator>
    </item>
    <item>
      <title>Disney+, Account on Hold Phishing Scam</title>
      <link>https://www.globalguard.com/blog/disneyplus-account-on-hold-phishing-scam</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.globalguard.com/blog/disneyplus-account-on-hold-phishing-scam" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.globalguard.com/hubfs/disneyplus-featured-clear.png" alt="Disney+, Account on Hold Phishing Scam" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;span style="background-color: transparent;"&gt;GlobalGuard has intercepted a phishing email campaign impersonating Disney+ to trick recipients into handing over their email credentials and payment card details. The email claims that your Disney+ membership has been placed “on hold” due to incomplete information and urges victims&amp;nbsp;to “update” their account. In reality, clicking the link takes users to a series of fake Disney+ web pages designed to harvest sensitive data.&lt;/span&gt;&lt;span style="background-color: transparent;"&gt;.&lt;/span&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;/h2&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.globalguard.com/blog/disneyplus-account-on-hold-phishing-scam" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.globalguard.com/hubfs/disneyplus-featured-clear.png" alt="Disney+, Account on Hold Phishing Scam" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;span style="background-color: transparent;"&gt;GlobalGuard has intercepted a phishing email campaign impersonating Disney+ to trick recipients into handing over their email credentials and payment card details. The email claims that your Disney+ membership has been placed “on hold” due to incomplete information and urges victims&amp;nbsp;to “update” their account. In reality, clicking the link takes users to a series of fake Disney+ web pages designed to harvest sensitive data.&lt;/span&gt;&lt;span style="background-color: transparent;"&gt;.&lt;/span&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;/h2&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=441818&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.globalguard.com%2Fblog%2Fdisneyplus-account-on-hold-phishing-scam&amp;amp;bu=https%253A%252F%252Fwww.globalguard.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>disney+</category>
      <category>disneyplus</category>
      <pubDate>Tue, 18 Aug 2026 02:23:17 GMT</pubDate>
      <guid>https://www.globalguard.com/blog/disneyplus-account-on-hold-phishing-scam</guid>
      <dc:date>2026-08-18T02:23:17Z</dc:date>
      <dc:creator>GlobalGuard</dc:creator>
    </item>
    <item>
      <title>AT&amp;T Phishing Campaign Exploits Website Redirect Vulnerability</title>
      <link>https://www.globalguard.com/blog/att-phishing-campaign-exploits-website-redirect-vulnerability</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.globalguard.com/blog/att-phishing-campaign-exploits-website-redirect-vulnerability" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.globalguard.com/hubfs/AT%26T%20-%20featured.png" alt="AT&amp;amp;T Phishing Campaign Exploits Website Redirect Vulnerability" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;span style="background-color: transparent;"&gt;GlobalGuard is intercepting a new phishing campaign impersonating telecommunications provider AT&amp;amp;T that attempts to steal victims' personal information and payment card details.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="background-color: transparent;"&gt;Unlike many phishing campaigns that rely solely on deceptive emails, this attack abuses an open redirect vulnerability on a legitimate website to disguise the malicious destination. This technique can help malicious links evade traditional reputation-based security controls and make them appear more trustworthy to recipients.&lt;/span&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;/h2&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.globalguard.com/blog/att-phishing-campaign-exploits-website-redirect-vulnerability" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.globalguard.com/hubfs/AT%26T%20-%20featured.png" alt="AT&amp;amp;T Phishing Campaign Exploits Website Redirect Vulnerability" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;span style="background-color: transparent;"&gt;GlobalGuard is intercepting a new phishing campaign impersonating telecommunications provider AT&amp;amp;T that attempts to steal victims' personal information and payment card details.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="background-color: transparent;"&gt;Unlike many phishing campaigns that rely solely on deceptive emails, this attack abuses an open redirect vulnerability on a legitimate website to disguise the malicious destination. This technique can help malicious links evade traditional reputation-based security controls and make them appear more trustworthy to recipients.&lt;/span&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;/h2&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=441818&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.globalguard.com%2Fblog%2Fatt-phishing-campaign-exploits-website-redirect-vulnerability&amp;amp;bu=https%253A%252F%252Fwww.globalguard.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>AT&amp;T</category>
      <pubDate>Fri, 14 Aug 2026 07:18:30 GMT</pubDate>
      <guid>https://www.globalguard.com/blog/att-phishing-campaign-exploits-website-redirect-vulnerability</guid>
      <dc:date>2026-08-14T07:18:30Z</dc:date>
      <dc:creator>GlobalGuard</dc:creator>
    </item>
    <item>
      <title>Bank of Baroda: Core Systems Secure. Business Still Breached.</title>
      <link>https://www.globalguard.com/blog/bank-of-baroda-core-systems-secure.-business-still-breached</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.globalguard.com/blog/bank-of-baroda-core-systems-secure.-business-still-breached" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.globalguard.com/hubfs/BoB.png" alt="Bank of Baroda: Core Systems Secure. Business Still Breached." class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Bank of Baroda recently confirmed a data leak that originated from a single compromised employee email account. A forensic investigation is underway following reports that a significant volume of customer and internal data was exposed, but the bank has been clear on one point: its core banking systems were not breached.&lt;/p&gt; 
&lt;p&gt;That distinction is the whole story, and it's worth unpacking for clients who still think of "the breach" as something that happens to servers and databases, not inboxes.&lt;/p&gt; 
&lt;h2&gt;&lt;/h2&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.globalguard.com/blog/bank-of-baroda-core-systems-secure.-business-still-breached" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.globalguard.com/hubfs/BoB.png" alt="Bank of Baroda: Core Systems Secure. Business Still Breached." class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Bank of Baroda recently confirmed a data leak that originated from a single compromised employee email account. A forensic investigation is underway following reports that a significant volume of customer and internal data was exposed, but the bank has been clear on one point: its core banking systems were not breached.&lt;/p&gt; 
&lt;p&gt;That distinction is the whole story, and it's worth unpacking for clients who still think of "the breach" as something that happens to servers and databases, not inboxes.&lt;/p&gt; 
&lt;h2&gt;&lt;/h2&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=441818&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.globalguard.com%2Fblog%2Fbank-of-baroda-core-systems-secure.-business-still-breached&amp;amp;bu=https%253A%252F%252Fwww.globalguard.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>bank of baroda</category>
      <pubDate>Fri, 14 Aug 2026 07:04:49 GMT</pubDate>
      <guid>https://www.globalguard.com/blog/bank-of-baroda-core-systems-secure.-business-still-breached</guid>
      <dc:date>2026-08-14T07:04:49Z</dc:date>
      <dc:creator>GlobalGuard</dc:creator>
    </item>
    <item>
      <title>"Microsoft 365 Account Suspension" Scam Steals Business Payment Details</title>
      <link>https://www.globalguard.com/blog/microsoft-365-account-suspension-scam-steals-business-payment-details</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.globalguard.com/blog/microsoft-365-account-suspension-scam-steals-business-payment-details" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.globalguard.com/hubfs/M365%20-%20featured-1.png" alt="&amp;quot;Microsoft 365 Account Suspension&amp;quot; Scam Steals Business Payment Details" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;GlobalGuard's threat detection network has intercepted a new phishing campaign impersonating Microsoft 365, using a fabricated subscription suspension notice to pressure recipients into handing over their card details on a fake payment page.&lt;/p&gt; 
&lt;h2&gt;&lt;/h2&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.globalguard.com/blog/microsoft-365-account-suspension-scam-steals-business-payment-details" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.globalguard.com/hubfs/M365%20-%20featured-1.png" alt="&amp;quot;Microsoft 365 Account Suspension&amp;quot; Scam Steals Business Payment Details" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;GlobalGuard's threat detection network has intercepted a new phishing campaign impersonating Microsoft 365, using a fabricated subscription suspension notice to pressure recipients into handing over their card details on a fake payment page.&lt;/p&gt; 
&lt;h2&gt;&lt;/h2&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=441818&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.globalguard.com%2Fblog%2Fmicrosoft-365-account-suspension-scam-steals-business-payment-details&amp;amp;bu=https%253A%252F%252Fwww.globalguard.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Fri, 14 Aug 2026 06:23:15 GMT</pubDate>
      <guid>https://www.globalguard.com/blog/microsoft-365-account-suspension-scam-steals-business-payment-details</guid>
      <dc:date>2026-08-14T06:23:15Z</dc:date>
      <dc:creator>GlobalGuard</dc:creator>
    </item>
  </channel>
</rss>
