The FBI warns cybercriminals will “exploit mass casualty events and disasters” as lures “to commit fraud,” primarily through soliciting donations for fake charities or other good causes, preying on people’s natural instincts to help. Beyond financial theft, these lures include links to steal credentials and to install malware on people’s devices.
This hacking of disasters and mass casualty events is just the tip of an ugly iceberg. A new investigation by the research team at DomainTools found that when “viral media events capture global attention… a different group also takes notice: malicious actors looking to capitalize on the public’s interest and urgency.”
I reported on this threat earlier this year, when Veriti warned “as California grapples with devastating wildfires,” with entire communities affected, “those disasters are serving as fertile ground for cybercriminals seeking to exploit chaos and uncertainty. Then as now, it’s “alarming trends in phishing scams linked to the ongoing disasters [that]
highlight the need for heightened cybersecurity awareness.”
With the Californian fires still raging, Veriti reported “in just 72 hours, we identified multiple newly registered domains linked to the California fires.” This isn’t rocket science — far from it. Those domains were as simple as can be, the likes of malibu-fire[.]
com, fire-evacuation-service[.]com, Pacificpalisadesrecovery[.]com, boca-on-fire[.]com, palisades-fire[.]com and palisadesfirecoverage[.]com.
Back then, Veriti said the fires “underscore the dual tragedy of natural disasters and cyber exploitation. As hackers continue to refine their techniques, awareness and vigilance are critical in preventing against their attacks.”
Now, DomainTools says “for almost all events, we identified websites explicitly seeking to profit by being part of a legitimate donation foundation supporting the cause (e.g., for the LA Fire, the Ukraine War, and other tragedies like the Myanmar earthquakes).”
As cybercriminals hack disasters in this way, the FBI warns citizens to “do your own research before you donate to anything [and] confirm the validity of any charitable opportunity.” This includes “reviewing email headers and domain information to evaluate legitimacy. Emails from official organizations almost never will come from free email services. IP addresses can reveal if the information is originating from overseas.”
Unsurprisingly, this is DomainTools’s domain — no pun intended. “The sheer volume of newly observed domains in 2024 was over 106 million,” it says. “Approximately 289,000 daily creates a significant challenge for security teams.”
The bureau warns users to “be suspicious of online communications claiming to be from individuals affected by the events and seeking immediate financial assistance. Recognize that pressure to “act fast” might be a sign of a scam. [And] do not send payments to unknown individuals or organizations asking for financial assistance.”
As LA fires dominated the news cycle, California’s Attorney General Rob Bonta warned “we have people with big hearts who want to help, they want to donate, they want to support the victims… We also see scammers who are taking advantage of that goodness and that generosity and scamming and defrauding those individuals.”
This latest report from DomainTools — switching LA for Myanmar and elsewhere — just shows nothing has changed. If you have such emails on your PC, whatever your email platform, delete them as soon as they come in. It’s exactly the same advice as with the plague of so-called smishing texts also sweeping from state to state.







