Insights on digital risk and
personal security
Digital risk is evolving quickly. For individuals and families with greater public presence, professional responsibility, or complex personal lives, digital exposure is often higher. The impact of a security incident can extend beyond inconvenience to affect privacy, reputation, and financial well-being.
%20(1).avif)
%20(1).png)
Featured articles
A small selection of articles that help readers stay informed about personal and executive digital risk.

On September 1, 2026, cybersecurity journalist Brian Krebs found a listing on the dark web called Nexus selling scans of more than 153 million driver's licences from Canada and the U.S.A. The images appeared to come from an identity verification company most people have never heard of: IDScan.net.
Have you ever handed your driver's licence to a retail store cashier, nightclub manager, hotel front desk clerk or car rental agent? If yes, this breach may impact you.
If matters even more if you run a company, sit on an advisory board or manage family wealth.
Here is what we know, why it hits harder at the high-net-worth level, and what a smart response looks like.
What we know so far
The information that follows comes from Krebs on Security, Global News, Yahoo Finance Canada and IDScan.net itself.
These identity files claimed 153 million driver's licences, 10 million ID cards, 3 million travel documents and 579,000 medical cards. About 1.1 million records were Canadian, and Ontario had the most, at 473,673.
Krebs said a record could include front and back images, plus infrared and ultraviolet scans. He checked nine people's records. Each had travelled on or near the date stamp, including at a car rental counter and a cannabis dispensary.
IDScan.net sells ID scanning software to businesses such as bars, casinos, car rental firms and cannabis shops. The company's September 4th notice said an unauthorized party may have accessed or copied customer data, including names and ID numbers. IDScan.net said full access required payment, and it offered free credit monitoring.
Officials then stepped in:
- The FBI said on September 2 that it was looking into the incident. The RCMP also said it was monitoring the situation.
- On September 21, Privacy Commissioner Philippe Dufresne opened a formal investigation. The investigation will examine IDScan.net's security safeguards and whether it properly told affected people, under PIPEDA, Canada's federal private-sector privacy law. CBC and The Spec also covered the announcement.
One caution: the big numbers come from the seller and from Krebs. Global News reported that neither the RCMP nor the Canadian Centre for Cyber Security has confirmed them.
IDScan.net has not said how many Canadians are affected. Krebs reported that Nexus went offline soon after his story ran. A site going dark does not mean copied data disappears.
Why your Canadian driver's licence is more than just an identity card
A driver's licence holds your full name, home address, birth date and ID number, plus your photo. Yahoo Finance reports that modern scanners capture both sides of the card and often send the image to cloud servers.
Criminals can use those details to open credit in your name. They can also write scams that sound real, because they know things about you.
Experts told Global News that phishing emails and texts are the likely next step. They also said that once data is out, there is little you can do to pull it back. And you can't reset your face like a password.
Researchers have warned that AI photo-matching tools make stolen photo scans a real concern.
Why this breach in particular matters for high-net-worth individuals, executives and their family members
You have increased visibility
Security researcher Zach Edwards said, "There's never been a breach of driver's licences at this scale." He added that the ongoing nature of the breach created national security risks for high-profile people.
Krebs found licences of senior U.S. officials for sale. Cybernews reported that analysts see celebrities, politicians, lawyers and wealthy people as especially exposed.
For a prominent family, a name, address and face are a strong starting kit for a targeted scam, or something worse. A driver's licence scan is also easy to pair with public facts about you, like your company, your donations and your advisory board seats.
You have heightened responsibility
If you lead a business, a family office or an estate, your identity is a key that opens other people's money. A criminal posing as you can call a bank, email an advisor or pressure an assistant. The damage can be financial, and it can hurt your reputation too.
You deal with added complexity
Wealth means more properties, vehicles, trips, accounts and people acting on your behalf. Your adult children get scanned at clubs. An assistant rents a car. A house manager registers a guest. Each one is another vendor holding another copy.
There is a bright side: Wealth buys excellent lawyers, accountants and security advisors. The problem is that each sees only their own slice. No one often sees the whole picture.
You can't audit every vendor
The privacy commissioner's investigation matters. Under PIPEDA, businesses must protect the data they collect. Unfortunately investigations come after the breach, and your driver's licence was sitting with a company you never chose, after a scan you didn't think twice about.
A modern approach: Assume you are exposed, but limit the damage
Good security today does not depend on keeping every secret. It assumes some of your data is already out there, then makes it hard to use. Five habits help:
1. Ask for a visual check
Yahoo Finance notes you can usually ask staff to look at your card instead of scanning it. You can also ask where scans are stored.
2. Watch your credit
Pull your reports from TransUnion or Equifax, and consider a fraud alert. The RCMP also urges people to monitor financial and government accounts and to report fraud to police and the Canadian Anti-Fraud Centre.
TransUnion is included with your Richter Guardian subscription.
3. Lock down your accounts, including email addresses and social media
Use strong, unique passwords and multi-factor-authentication (MFA) everywhere, as the Canadian Centre for Cyber Security advises. Start with your email addresses and social media accounts, for everyone in your family.
4. Set a family "verify first" rule
Any urgent request for money, access or documents has to be confirmed through a second channel, like a call to a known number. This should cover assistants, advisors and adult children.
5. Get a single, comprehensive and ongoing view of your digital risk level
Someone should watch the whole household, not each account on its own.
You can start making these first four changes today.
The fifth is difficult and time-consuming to do alone, and where Richter Guardian delivers as a modern personal cybersecurity program for high-net-worth individuals, executives and their families.
Where Richter Guardian fits
Richter Guardian can't pull a licence out of a dark web vendor's database. No one can. What we can do is watch the doors criminals try next.
After a government ID leaks, attackers still need to act like you. That often means taking over an email account or social account, or building a fake profile.
Richter Guardian's reputation and identity protection is built for that moment. It works in four steps:
Understand
We begin by understanding your personal digital environment, including the devices and accounts you rely on, your social media presence, and where exposure is most likely to exist.
Monitor
24 hours a day, 7 days a week, our monitoring and prevention runs quietly in the background. Richter Guardian helps identify meaningful risk signals tied to your personal digital life.
Surface
When something matters, our team of cybersecurity experts will review it. We share with you the context and priority, so you know why it's important. This can be done via the Richter Guardian mobile app, telephone, email, online video or in-person.
Guide
If action is needed, Richter Guardian's human-led team, known as the Cyber Defence Desk help you decide next steps, discreetly.
Instead of a flood of alerts, you get what matters: Summary and guidance explained in plain language, and a human to talk to and lead you through the situation.
Our team can also coordinate with your existing advisors or IT service provider, so your family office, lawyer and bank aren't left guessing. Richter Guardian fits into a busy life instead of interrupting it.
Take the next step: Request a private consultation or complete a brief assessment
A breach like this is a good opportunity to look at you and your family's digital risk level, before someone else does.
Request a private consultation. Discuss the identities and accounts you want protected, and ask us any questions. It's confidential and no-obligation.
Not yet ready to talk? Try our What's my risk? assessment. It takes a few minutes, needs no sensitive details, and your summary arrives by email.

Why Family Offices Need to Improve Security Beyond Their Corporate Perimeter
In August 2026, the Liechtenstein government disclosed that hackers had broken into a register holding beneficial ownership data for 31,000 legal entities. The incident is part of a pattern that keeps privacy compromises high on the private banking and wealth management agenda, and it wasn't an isolated event.
Around the same time, government systems in the UK, the Netherlands, Sweden, and Spain were also targeted, and researchers tracked 187 ransomware attacks on government agencies worldwide in just the first half of the year, a 13 percent rise from the second half of 2025.
Why does a European government breach matter to a family office in Canada or the USA?
The data stolen in attacks like this often includes the same information that family offices work hard to protect: ownership structures, trust details, and personal information tied to wealthy families.
When a government registry gets hit, the fallout can reach private clients who never even knew their data lived there.
This is the backdrop for a bigger shift happening across the family office world right now: more offices are hiring outside specialists to handle essential services, and that shift brings real benefits along with new risks that need careful management.
Family offices are easy targets, and criminals know it
Family offices sit on enormous wealth but often run lean, and that combination makes them attractive to criminals.
- A cybersecurity consultant who previously worked at Google and served as deputy chief information security officer for New York City has said family offices have not kept pace with cybersecurity strategy, so it isn't surprising that so many have already been attacked.
- A 2020 report from law firm Dentons found that about one in four family offices had suffered a cyberattack, with nearly two-thirds of those attacks happening in just the prior 12 months. A separate EY survey found the number closer to three in four.
- More recent US research tells a similar story: one 2025 study found 37 percent of family offices had experienced an attack in the previous two years, with average losses per incident reaching $1.2 million, and 62 percent of family offices still had no formal cybersecurity plan in place. The problem has caught regulators' attention too, with cybersecurity now a named priority area for SEC examinations.
Closer to home, Canadian advisors are sounding the same alarm.
Looking ahead to 2026, family office advisors flagged shoring up cybersecurity as one of the most pressing issues on their radar, alongside geopolitical volatility and cross-border risk.
Business email compromise, deepfake voice cloning, and social engineering scams are getting harder to catch because generative AI makes fraud attempts look and sound convincingly real, as Richter's own commentary on the “human firewall” has noted.
The rise of the outside specialist
Faced with all of this, many family offices have concluded they can't do everything in-house.
A recent Ocorian survey of family offices managing a combined $119.37 billion found that 77 percent expect to increase their use of outsourced specialists over the next three years, and only 21 percent expect no change at all.
Cybersecurity is one of the top three services families are already sending outside, cited by 49 percent of respondents, just behind illiquid investment advice. The main reasons families gave for outsourcing were the need for more sophisticated services, a lack of in-house expertise as the office grows, and the simple cost-effectiveness of hiring a specialist rather than building a full internal team.
This trend isn't limited to cybersecurity.
Family offices across Hong Kong, Singapore, and other hubs are bringing in outside experts for governance, succession planning, and legacy work as the sector matures and families realize that no single in-house team can master every discipline at once.
The logic is sound. Cyber threats evolve daily. Keeping a specialist current on the latest phishing tactics, deepfake tools, and vendor exploits is a full-time job, and most family offices don't have room on staff for a full-time cybersecurity expert.
What gets more complicated when you bring in outside help
Hiring a specialist solves one problem and creates a new one: you now must manage a relationship with someone outside your walls who has access to some of your most sensitive information. That adds real complexity.
Vendor risks
First, there's the vendor risk itself. Every external specialist, contractor, or platform you connect to your systems becomes a potential entry point for an attacker. Criminals increasingly go after the weakest link in a chain of vendors rather than attacking a well-defended target directly.
If your outside technology provider, IT consultant, or even a bookkeeper has an overly relaxed password policy, that weakness becomes yours too.
Coordination challenges
Second, there's the coordination problem. When a family office builds a “lean” model with just one to three internal staff and outsources nearly everything else, someone still needs to own the big picture.
Without a person or team tracking how all the outside pieces fit together, families can end up with the exact fragmentation they were trying to avoid: one firm handles the network, another handles computers and phones, a third handles monitoring, and nobody owns the whole picture when something goes wrong.
Personal and household gaps
Third, there's the personal and household gap.
Corporate-style information and IT security, even when outsourced well, tends to stop at the office door.
This type of security protects the family office's servers and accounts, but personal devices, family members' social media, household staff, and private communications often fall outside that coverage entirely.
Criminals know this and increasingly go after the people rather than the institution, calling family members directly and posing as a security expert who needs remote access, or targeting an assistant's inbox instead of the principal's.
Human factors
Finally, there's the human factor, which no amount of outsourcing removes.
Most cybersecurity breaches trace back to human error, not a firewall failure. Training family members, executive staff, and household contacts to recognize scams matters just as much as any technology contract you sign.
What family offices need to know before signing a contract
Given all this, hiring external specialists is smart, but it needs to be done carefully. A few considerations matter most.
Check credentials and scope, not just reputation
Ask exactly what the specialist covers. Does it include personal devices and family members, or only office infrastructure? Many families assume broader coverage than they're actually getting.
Require a real incident response plan, in writing
A written plan should spell out who gets called first, how a breach gets contained, and who communicates with the family. Too many family offices only think about this after something has already gone wrong.
Keep one person accountable for the whole picture
Even with several outside vendors involved, someone inside the family office needs to own coordination between them, so no risk quietly falls through the cracks.
Ask about multi-jurisdiction experience
Wealthy families increasingly cross physical borders, and the ability to operate across multiple jurisdictions was the single most important factor families cited when choosing a specialist in the Ocorian survey.
Build in ongoing verification, not a one-time check
Vendor risk changes over time. A specialist that was solid two years ago may have grown, been acquired, or changed staff since then. Periodic reviews catch changes before they become a problem.
Don't skip the human side
No contract replaces training family members and staff to spot phishing attempts. Be sure to verify wire transfer requests by phone, and question unusual requests, even urgent-sounding ones.
Where Richter Guardian fits in: Closing the personal gap
The clearest lesson from recent breaches, whether it's a government registry in Europe or a Canadian family office's own systems, is that modern cybersecurity can't stop at the corporate perimeter.
Cybersecurity has to extend to the people: principals, family members, executives, and trusted household staff, wherever they are and whatever device they're using.
This is exactly the gap Richter Guardian was built to close.
Family office managers are already responsible for keeping operations running while protecting privacy and sensitive communication, but personal devices, private accounts, and household exposure often sit in a space where ownership is unclear and support is inconsistent.
Richter Guardian extends structured, human-led protection into that space, working alongside your existing corporate security team and outside specialists rather than replacing them.
- That means continuous threat and vulnerability monitoring that give a clear view of personal digital exposure across devices, accounts, and identities.
- It means ongoing, proactive monitoring designed to surface meaningful risk signals without burying families in constant alerts.
- It means reputation and identity protection that helps catch impersonation and credential exposure early.
- When something does go wrong, it means concierge, human-led incident response with a clear next step, so a compromised account or suspicious message doesn't spiral into operational chaos.
Bringing in outside cybersecurity expertise is one of the smartest moves a family office can make right now. Just make sure the coverage reaches all the people who need it, not just at the office.
If you support principals or families with elevated exposure and want a clearer approach to personal digital protection, Richter Guardian starts with a confidential conversation to understand your priorities.
Ready to stay protected from digital threats, with experienced professionals overseeing your family office security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.

A $4.5-Million Account Raid: What Every Investor Should Learn About Protecting Their Wealth While on Vacation
What happened
A Calgary investor is suing TD Waterhouse Canada Inc. after fraudsters allegedly broke into his TD Direct Investing accounts while he vacationed in Hawaii.
According to The Globe and Mail, the intruders sold his holdings and poured more than $5 million into a thinly traded Hong Kong stock.
When it collapsed, he lost roughly $4.5 million in retirement savings.
TD says he either made the trades himself or failed to secure his account. Nothing has been proven in court, but the case shows how fast wealth can vanish once login credentials fall into the wrong hands.
Why this keeps happening
This isn't an isolated incident.
TD Bank has faced other serious regulatory scrutiny in recent years, and securities fraud attorneys continue to field claims from investors who say controls failed them.
Banks guard their own core systems closely, but the real weak points are often somewhere else: the client's personal devices, account passwords, and email accounts, all sitting outside the bank's oversight and controls.
Why travel makes you a target
It's worth pausing on the timing here: the alleged fraud happened while the investor was away in Hawaii. That's not a coincidence worth overlooking.
Vacations pull people out of their normal routines on purpose, and that's exactly what makes them good for rest, and terrible for security.
At home, most people have habits without even thinking about them: checking accounts over morning coffee, noticing a strange email between meetings, recognizing when something on a statement looks off.
Travel disrupts every one of those habits at once:
- You're on hotel or airport Wi-Fi, which is rarely as secure as your home network.
- You're checking email and banking apps quickly, often on borrowed time between activities, so a suspicious login alert can get skimmed past instead of read carefully.
- Time zone changes mean notifications may arrive at 3 am and get dismissed unread.
Many people intentionally "unplug" from their finances while traveling, treating vacation as a break from monitoring entirely.
Fraudsters understand this pattern well. Account takeovers cluster around known absences: holidays, long trips and/or business travel.
A window of even a few days without anyone watching an account closely is often all it takes to sell off holdings and move funds into a single volatile position, which is exactly what allegedly happened in this case.
None of this means people shouldn't travel or unplug — they should. It means the monitoring can't rely on the account owner remembering to check in from a beach in Hawaii.
Steps you can take right now
Basic habits, especially before and during travel, meaningfully reduce your own risk:
- Turn on multi-factor authentication for every brokerage, banking, and email account.
- Use a unique, strong password for each financial account — never reuse them.
- Avoid logging into financial accounts on public or hotel Wi-Fi while traveling.
- Set up account alerts for trades, withdrawals, and login attempts before you leave.
- Designate someone you trust to glance at statements while you're away.
- Review account activity closely in the days right after returning.
- Ask your brokerage about limiting or freezing margin trading if you rarely use it.
Where personal habits aren't enough
Even careful people get targeted, especially the moment they step away from their routine.
This is a gap Richter Guardian is built to close.
Corporate and bank-side security stops at the workplace door — it doesn't watch the personal phone, laptop, or email account a fraudster actually needs.
Richter Guardian's monitoring and prevention service watches continuously, including while clients travel, for compromised credentials and suspicious activity. If something looks wrong, clients aren't left to figure it out alone.
Our incident response team, the Cyber Defence Desk, is reachable via phone, email, video or a mobile app to explain what's happening and guide next steps.
The bottom line
Vacations should mean rest, not vigilance. For high-net-worth individuals and families with complex accounts and multiple devices, someone still needs to be watching while you're not. Protection shouldn't stop where your routine does.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.

Cheaper Cyber Insurance, Costlier Risk: The Family Office Coverage Gap
The cyber insurance market is softening just as the threats driving demand for it accelerate.
Premiums are falling, yet more than 40% of cyber claims are now denied — most often because controls attested to on the application were never actually in place.
For family offices, with their informal governance and concentrated wealth, a cheaper policy is increasingly a policy that will not pay.
The defensible position for family offices is verifiable security controls, not a lower premium.
The market contradiction
Reporting from the Family Office Cybersecurity Forum in New York describes a market where competition is outpacing risk. New entrants including major carriers have pushed prices down, and average premiums were projected to fall a further 11% in 2026.
Buyers are being advised to shop around — but price is now the least important variable.
The frequency and severity of losses continue to climb even as rates drop, and the early signs suggest the rate of decline is starting to slow.
By the numbers
- ~50% of US family offices were hit by a cyberattack in 2025.
- 40%+ of cyber insurance claims are currently being denied — driven by missing controls, late notification and absent policy provisions, not exclusions.
- ~75% of carriers now run external attack surface scans during underwriting, replacing self-attestation.
- $713K average global ransomware claim in 2025 — nearly double the $374K recorded in 2024.
- 60% of family offices are confident their staff can detect and prevent AI-powered attacks.
- 2,137% rise in deepfake-driven fraud attacks since 2022; now 6.5% of all fraud.
Why family offices are uniquely exposed
Forum specialists characterized family offices as structurally vulnerable in ways that standard commercial cyber exposure does not capture.
The same traits that make a family office efficient make it exploitable:
- Cultures of informal approval and trust-based authorization.
- Heavy reliance on personal assistants and a small circle of staff.
- A bias toward speed over documented process.
- Multi-generational structures that widen the attack surface and blur accountability.
Layered on top is an AI-driven threat surface: deepfake voice impersonation of principals, AI-generated phishing, and business email compromise.
The FBI logged a 37% rise in AI-assisted BEC incidents using cloned executive voices, and attackers can now sit undetected inside a compromised environment for 100 days or more.
The regulatory squeeze
Family offices and their advisers face a tightening regulatory environment that mirrors what insurers already demand.
Amendments to the SEC's Regulation S-P took effect for smaller registered investment advisers on June 3, 2026, introducing a written incident response program, a 30-day customer breach notification obligation, and expanded vendor oversight.
The SEC's examiners have named S-P compliance a 2026 priority.
The controls the regulator now mandates are in most cases, the same controls cyber insurers require for a claim to be honored. One program satisfies both.
How Richter Guardian can help family offices
- Controls verification and attestation readiness — ensuring what you tell underwriters is true and evidenced.
- External attack surface assessment aligned to carrier underwriting scans.
- Regulation S-P alignment: written incident response program, breach notification readiness, vendor risk oversight.
- Human-layer defence against deepfake and AI-enabled social engineering, including principal and staff awareness.
- Ongoing managed monitoring so that controls stay in place between renewals.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.

Understanding Business Email Compromise: Why Trusted Emails Still Need Verification
Business Email Compromise, or BEC, is a targeted scam in which a criminal impersonates someone you trust. They may pose as an executive, lawyer, vendor, advisor, employee, or family member and ask you to send money, change banking details, or share sensitive information.
The message may come from a lookalike email address or a real account that has been compromised. This can make the request appear normal and include details that only a trusted person would seem to know.
Executives, high-net-worth individuals and their families, and anyone able to move money or release sensitive information are valuable criminal targets. AI-written emails and voice cloning can make these scams even more convincing.
How it works
An attacker sends a message that appears to come from someone you know. It is designed to seem routine or urgent so that you act before confirming the request another way.
If a real email account has been compromised, the attacker may review conversations, invoices, contacts, and travel details. They can use this information to create a convincing request at the right time.
The risk works both ways. You may receive a fraudulent message, or your own account may be taken over and used to contact others in your name.
Why BEC is a major threat
According to the FBI Internet Crime Complaint Center’s 2025 Annual Report, BEC led to 24,768 reported complaints and more than $3 billion in reported losses in 2025. Only investment fraud caused greater reported losses that year.
BEC is also becoming harder to identify. AI can create professional messages without the spelling mistakes or awkward wording often linked to scams. Voice cloning may also make a call or voice message sound like someone you know.
Warning signs of business email compromise
Watch for:
- Urgency combined with secrecy
- New or changed payment or banking details
- A reply-to address that differs from the sender’s address
- A request that skips the normal approval process
- Pressure to move the conversation to text or WhatsApp
- An unusual request for sensitive information
A message from a compromised account may not show any of these signs. Verifying the request is more reliable than deciding whether the email looks suspicious.
How to protect yourself
Confirm every new payment instruction, banking change, or urgent transfer by calling the person directly. Use a number saved in your contacts, shown on a previous statement, or obtained from another trusted source.
Never use a number provided in the same email as the request.
During the call, confirm the payment amount, recipient, bank, account details, and reason for the transaction. Be especially careful if any information has changed.
Require approval from a second trusted person for payments above a set amount. Everyone involved should be expected to pause and verify a request, even if this causes a short delay.
Protect every email account including personal accounts, with a strong, unique password and multi-factor authentication. Keep recovery information current and check for unfamiliar forwarding rules, filters, connected applications, or signed-in devices. Do not reuse your email password on other services.
If you have been targeted
If you sent money or shared banking information, contact your financial institution immediately. Ask whether the payment can be stopped, recalled, or frozen. Keep the original emails, messages, and payment records.
If you believe your email account was compromised:
- Change the password from a trusted device.
- Sign out of other active sessions.
- Review the account’s security and recovery settings.
- Remove unfamiliar rules or connected applications.
- Notify anyone who may have received a fraudulent message from your account.
How Richter Guardian can help you
Richter Guardian can help reduce BEC risk by monitoring for exposed credentials and identifying impersonation attempts, including lookalike domains, websites, or accounts created in your name.
We can also help secure your accounts, review suspicious requests, and provide guidance if you believe an account has been compromised.
If you receive a suspicious email, payment request, banking change, or request for sensitive information, contact us before taking action.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.

Fraud Alert — CRA Data Breach Settlement Scams
On August 4, 2026, the claims process opened for a $8.7 million settlement of a class action against the Government of Canada.
This covered people whose personal or financial information in a Government of Canada online account, including the Canada Revenue Agency portal, was accessed without authorization in 2020.
KPMG is the court appointed administrator, and eligible class members can submit claims online or by mail until February 3, 2027.
The settlement is legitimate, but the publicity around it is exactly the conditions fraudsters look for:
- A national news story
- A real government linked payout
- A real deadline
- A real administrator asking people to enter a last name and the last three digits of a Social Insurance Number on a website
That combination gives criminals a credible pretext to build convincing fake eligibility checkers and claim portals, and to harvest identity data and account credentials at scale.
Our expectation
A wave of phishing email, SMS, social media advertising, sponsored search results, and voice calls impersonating KPMG, the CRA, the Federal Court, and class counsel, beginning within days of the news coverage and continuing through the February 2027 claim deadline.
The only legitimate channels and what to watch for
Official settlement website
https://www.breachsettlementcanada.kpmg.ca (English and French). This is the court appointed administrator's website.
Official email address
breachsettlementcanada@kpmg.ca
What the real eligibility check asks for
- Last name
- Last three digits of the SIN
- An email address
- Nothing more at the eligibility stage
What the real process NEVER asks for
- Full SIN
- Date of birth
- Banking credentials
- CRA My Account user ID or password
- A multi factor authentication code
- A credit card number
- A copy of a government ID uploaded to a chat window
- Any payment or fee. There is no fee to file a claim
Anything arriving by unsolicited text, direct message, or phone call that pushes you toward a different address, a shortened link, or an app download should be treated as fraudulent until proven otherwise.
What the fakes will look like
The following mock ups were produced by Richter Guardian for training purposes.
These are not real messages and the addresses and links shown are illustrative only.
Share them with your household, your office staff, and anyone who manages correspondence on your behalf.
Example 1: Phishing email impersonating the claims administrator

What to watch for
- Look-alike sender domain rather than https://www.breachsettlementcanada.kpmg.ca
- A pre-approved dollar figure the real administrator would never quote up front
- A 48 hour forfeiture threat against a deadline that is actually February 3, 2027
- A request for the full SIN
- CRA sign-in details
- Banking information
Example 2: Smishing text message

What to watch for
- The administrator does not solicit claims by text message
- The domain is not kpmg.ca
- The amount is presented as guaranteed
- Urgency is manufactured
Legitimate class action notice arrives by mail or from the administrator's own address.
Example 3: Fake eligibility and claim portal

What to watch for
- An unencrypted look-alike domain
- A full SIN and CRA credentials requested where the real site asks only for a last name
- Three SIN digits
- An email address
- An ID upload
- A processing fee where the real claim is free
- False scarcity counters
Criminals also buy sponsored search advertisements so these pages appear above the real one.
Example 4: Voice call and voicemail pre-text

What to watch for
- An inbound unsolicited call
- Identity verification demanded by the caller rather than by you
- Above all, a request to read back a code sent to your phone. That code is a multi factor authentication (MFA) prompt for an account the caller is trying to take over at that moment. No legitimate organization will ever ask for it
Example 5: Social media and search advertising

What to watch for
- An invented average payout
- A fabricated deadline
- A paid placement above the genuine result
Reach the administrator by typing the address directly - https://www.breachsettlementcanada.kpmg.ca - rather than by clicking any advertisement or search result.
Red flags to brief your household and staff on
Unsolicited contact
The administrator contacts class members by mail or from its own domain. It will not cold call, text, or direct message you.
A guaranteed amount up front
Real compensation is up to $80 or up to $200 for time spent, plus up to $5,000 in documented out of pocket costs, and amounts may be reduced depending on how many claims are approved. Nobody can promise you $5,000.
Artificial urgency
The real deadline is February 3, 2027. Any message giving you 24 hours, 48 hours, or "this week" is manufacturing pressure.
Over collection of identity data
The genuine eligibility check asks for a last name, the last three digits of your SIN, and an email address. A request for the full SIN, date of birth, ID scans, or CRA credentials is a data harvest.
Any request for a fee
Filing a claim is free. A processing, verification, or expedite fee means fraud.
Any request for a code
A one time passcode read aloud, forwarded, or typed into a third party site hands over your account.
Look-alike domains
Check the address carefully. The genuine site is https://www.breachsettlementcanada.kpmg.ca.
Anything ending in .info, .net, .co, .ca-claims, or a hyphenated variant of the KPMG name is not it.
Payment by unusual method
Requests to move funds, buy gift cards, or receive a payout through e-transfer to a new recipient are not part of any settlement.
What we recommend you do
For principals and family members
Type the address, never click
Reach the eligibility check only by typing https://www.breachsettlementcanada.kpmg.ca into the web browser. Do not use links from email, text, social media, or search advertisements.
Verify by calling back
If someone claims to be the administrator, hang up and contact breachsettlementcanada@kpmg.ca from the details on the official site.
Treat the SIN as a credential
Never provide a full Social Insurance Number to an inbound contact.
Check your CRA account directly
Sign in to CRA My Account by typing the address, confirm your direct deposit details and mailing address have not been changed, and enable multi factor authentication if it is not already on.
Consider a credit file alert
If you believe your information was exposed, place a fraud alert with Equifax Canada and TransUnion Canada.
For family offices and business staff
Brief your team this week
Forward or print this email to anyone who handles correspondence, banking, or tax filings on a principal's behalf.
Add a verification step
Any instruction arising from a settlement, refund, or government notice must be verified by an out of band call to a known number before any data or funds move.
Watch for lookalike domains
Ask your IT provider to monitor for newly registered domains that combine your family or firm name with settlement, claim, refund, or CRA terms.
Tune your email filtering
Quarantine newly registered sender domains and flag external mail referencing CRA settlements or class action payouts.
Report and preserve
Report suspected scams to the Canadian Anti-Fraud Centre at 1-888-495-8501 and preserve the original message headers rather than deleting them.
If you think you've already been caught
Move quickly
Change the password on any account whose credentials were entered, starting with CRA My Account and your email, and revoke active sessions.
Call the CRA
If CRA credentials were disclosed, contact the CRA immediately and ask that the account be locked and reviewed for changes to direct deposit or address.
Notify your bank
Report the exposure and ask for enhanced verification on outbound payments.
File a credit alert
Contact Equifax Canada and TransUnion Canada.
Contact Richter Guardian
Speak to your Richter Guardian team. We can help contain the incident, assess what was exposed, and coordinate monitoring.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.
Browse by topic
Explore articles based on areas of risk and responsibility.
Latest articles
New articles and updates from the Richter Guardian team.

MOVEit Data Breach
Introduction
In May 2023, the Cl0p ransomware group started exploiting a newly discovered vulnerability in Progress Software’s MOVEit Transfer, a tool for enterprise file transfer. Although Progress swiftly released a fix, the impact was already significant. This extensive cyberattack by Cl0p targeted a wide range of sectors globally, affecting entities such as the public school system in New York City, a UK-based company providing HR and payroll services to clients like British Airways and the BBC, among others.
Over 2,000 organizations have reported being attacked, with data thefts affecting more than 62 million people
Fallout of the incident
With such a large exposure, many people have begun to receive notices that their personal information was compromised as part of this breach. Many of the organizations that people entrust their data to, like accounting firms and wealth management companies, were affected by this breach. Companies affected by this breach have a legal obligation in Canada to report to their customers if they believe their customers have had their personal information breached.
Companies that notify their customers of the breach often offer one to two years of credit monitoring and identity protection services at no cost.
Richter recommends that victims receiving these notices enroll in the free credit monitoring and identity protection services provided.
Implications
The diagram on the right illustrates how hackers use personal information to carry out attacks using your personal information. Credit monitoring and identity protection services can assist with identity theft and financial fraud implications; however, this protection is insufficient.
Hackers can still use your personal information to conduct blackmail and ransom operations. They can impersonate you online and wreak havoc on your social reputation. They can use it to mount very sophisticated phishing attacks.
Recommendations
Richter Guardian is a state-of-the-art service that gives you exclusive access to commercial-grade protection unavailable in the consumer market.
By protecting your online presence, Richter Guardian will defend you from impersonations, inadvertent leakage of critical data and worse, any compromise to your digital safety. By protecting your devices, Richter Guardian will thwart sophisticated phishing and other technical attacks. You can rest assured that our seasoned cybersecurity professionals are there for you to address any of your cybersecurity concerns.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.

Unveiling the dark side of voice-cloning artifical intelligence
Introduction
Voice-cloning AI, which is the technology that enables the replication of a person’s voice, can assist researchers with collecting and analyzing data from different languages, dialects, and accents. Voice-cloning AI is versatile and finds applications in various creative domains.
voice-cloning artifical intelligence and small businesses with voice-cloning AI. Deep learning models can now replicate the nuances, inflections, and specific characteristics of a person’s voice with just a few minutes of sample media.
Implications for families and small businesses
While there are positive and creative uses for voice-cloning AI, it is important to be aware of the potential risks and misuse. Here are some ways in which voice-cloning AI could lead to cybercriminal activity:
- Impersonation and Social Engineering: Cybercriminals could use voice-cloning AI to mimic the voices of individuals in positions of authority, such as company executives. In doing so, cybercriminals could instruct employees into making unauthorized transactions.
- Phishing Attacks: Voice-cloning could be used to voice-phish; individuals can be deceived into sharing sensitive information over a call.
- Extortion and Blackmail: Cybercriminals may leverage voice-cloning to create audio deepfakes of the targeted individual for the purpose of extortion or blackmail.
Recommendations
Given the sophistication of these threats, Richter recommends individuals and businesses to safeguard themselves by employing the following:
- Multi-factor authentication (MFA) – If you currently use voice verification as a type of authentication, ensure to include another form of verification to help safeguard against voice-cloning AI.
- Establish protocol within your small-business – Set clear protocols for financial transactions and sensitive data sharing. Keep these protocols confidential.
- Remain skeptical – Individuals should exercise caution when receiving unexpected calls, especially if the caller requests sensitive information.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.

What is authorized push payment fraud?
Introduction
Authorized push payments involve an account holder granting permission to their bank or payment service to transfer funds directly from their account to another account. The payer usually triggers this transaction using services like online banking, phone banking, or peer-to-peer payment platforms.
Authorized push payment (APP) fraud, also known as bank transfer scams or authorised bank transfer fraud, occurs when a victim is tricked into authorizing a payment to an account controlled by a scammer.
Unlike unauthorized transactions where a fraudster gains access to someone’s account without permission, in APP fraud, the victim is deceived into willingly making the payment, often believing they are paying a legitimate entity or individual.
How does app fraud happen?
Authorized push payment fraud can happen in various ways.
- Advance Fee Scams: The victims are asked to pay a fee to access a service or a prize, which are never delivered. For example, a scammer may impersonate a lottery organization, and will withhold the prize until an administrative fee is paid. When the payment is made, the victim never receives the reward.
- Impersonation: The scammer poses as a trusted entity, such as a bank, government agency, utility company, or even a friend or family member, and requests payment for a fake invoice, overdue bill, or urgent situation.
- Fake Services or Goods: The victim pays for goods or services that are never delivered or are significantly different from what was advertised. The scammer may set up a fake online store, auction, or classified ad to lure victims.
- Social Engineering: The scammer manipulates the victim through psychological tactics, exploiting emotions like fear, urgency, or greed to coerce them into making the payment.
- Business Email Compromise (BEC): Scammers compromise email accounts of businesses or individuals, or create lookalike accounts, and use them to request payments from employees, clients, or partners, often by impersonating company executives or vendors.
- Invoice Fraud: The scammer pretends to be a vendor and sends fake invoices to the business. The invoice may request payment for goods or services that were never delivered.
Prevention
We recommend the following measures to mitigate the risks of authorized push payment fraud.
- Verify the authenticity of requests for payments – ensure that the request for payment is legitimate by confirming the identity of the individual, organization or service you are initiating a payment for. If the payment is sent to an organization, check the organization’s website and contact their phone number to confirm the request.
- Establish payment protocols – establish clear protocols within your organization that outline how to properly authorize payments. Ensure relevant employees are aware of these protocols and procedures.
- Monitor transactions – check your accounts to identify any unusual activity that could indicate fraud.
To combat APP fraud, it’s essential for individuals and businesses to remain vigilant and verify the authenticity of requests for payments. We understand that It can be difficult to approach this alone.
Transunion identity protection is included on our platform. Transunion identity protection will alert you of any unusual activity on your credit monitoring report that could indicate fraud.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.

Travelling and Social Media – How To Keep Safe
Introduction
It’s natural to want to capture the moments from your special vacations and share them on platforms like Facebook and Instagram with family and friends. However, posting these photos while you are still on your trip can expose you to various cybersecurity risks. Cybercriminals often exploit social media to gather information about your travel plans, and by sharing your vacation in real time, you may unknowingly make yourself a target.
How to enhance your security on vacation
By following these precautions, you can enjoy your vacation while minimizing the risks associated with social media sharing:
- Set Your Account to Private: Restrict access to your personal information by sharing only with people you know. Public settings allow anyone to view your posts, potentially putting you at risk.
- Decline Requests from Unfamiliar Individuals: Be cautious when receiving friend requests from strangers. Unfamiliar profiles might be cybercriminals in disguise, aiming to extract money or steal your identity.
- Avoid Posting Travel Details or Itineraries: Keep your travel arrangements private. Sharing confirmation numbers for hotel reservations, airline tickets, or excursions online can provide cybercriminals with valuable information they can exploit.
- Share Photos After Returning Home: Although it may be tempting to post in real-time, consider waiting until you’re back home. You can still share your vacation highlights, and it’s a safer approach.
- Educate Your Children on Social Media Safety: While you might be aware of how to stay safe online, your children might not. Ensure they understand the importance of secure sharing practices during and after the trip.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.

CrowdStrike Update Cripples Windows Systems
Introduction
On July 19, CrowdStrike released a flawed update to its Falcon sensor for Windows devices, triggering widespread system crashes. Due to a bug in the content validator and insufficient testing, the update bypassed CrowdStrike’s internal quality checks.
The update reached over 8.5 million Windows devices, resulting in an out-of-bounds memory read that caused the Falcon sensor to crash the operating system, leading to the infamous Blue Screen of Death (BSOD). The impact was severe, with enterprises across various sectors, including airports, hospitals, government agencies, media outlets, and financial institutions, experiencing critical and costly IT disruptions.
Both Windows workstations and servers were affected, leading to massive outages that incapacitated entire organizations and rendered hundreds of thousands of computers inoperable.
Root cause
The issue stemmed from a recent update to the CrowdStrike Falcon sensor, which caused Windows systems to either get stuck in a boot loop or crash with the Blue Screen of Death. CrowdStrike acknowledged the problem and issued a technical alert, stating that its engineers had “identified a content deployment related to this issue and reverted those changes.
Despite the swift response, it took days for some organizations to restore normal operations, resulting in prolonged outages and delays. While most organizations have since recovered, the repercussions of the incident continue to unfold, with increased cybercriminal activity, loss of trust, and potential litigation.
According to a report by Guy Carpenter, the estimated insured losses from the faulty Falcon update range between $300 million and $1 billion, while CyberCube has suggested the figure could be as high as $1.5 billion.
The impact on personal computers
CrowdStrike warned users that cybercriminals were exploiting the Falcon outage. Phishing attempts, posing as CrowdStrike representatives, surged as attackers sought to distribute malware. A significant example involved a fake recovery manual that installed a new information-stealing malware called Daolpu. Once active, this malware harvested account credentials, browser history, and authentication cookies stored in browsers like Chrome, Edge, and Firefox.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.

Navigating the terrain of synthetic and traditional theft scams
Introduction
In an increasingly interconnected digital world, safeguarding personal and financial information has never been more crucial. Cybercriminals can exploit stolen identity information to commit financial fraud, gain unauthorized access to accounts, and engage in other criminal activities. In the context of identity theft – there is both synthetic identity theft and traditional identity theft.
Synthetic identity theft combines personally identifiable information (PII) to manufacture a person or entity for the use of illegal, nefarious activity.
Traditional identity theft involves stealing an individual’s existing personal data to impersonate them.
Alternatively, synthetic identity theft involves criminals obtaining small fragments of a real person’s identity to fabricate a completely new identity. The real elements of the fabricated individual adds a sense of legitimacy to the identity.
Preventing identity theft of all kinds
Protecting yourself from identity theft, fraud, and unauthorized access to your sensitive data is our responsibility. Below, we have compiled a comprehensive list of security measures and best practices to help you fortify your defenses against potential threats.
By following these guidelines, you can take proactive steps to enhance your security and financial well-being. From monitoring your credit report to secure document disposal, each suggestion in this list is designed to empower you with the knowledge and tools to protect your valuable information and minimize the risks associated with identity theft and fraud.
- Monitor Your Credit Report: Regularly monitor your credit report to detect any unauthorized activity. If you come across information unrelated to you, contact the creditor and inquire about the account or inquiry.
- Limit What You Carry: Avoid carrying additional credit cards, birth certificates, SIN cards, or passports in your wallet or purse unless absolutely necessary. This precaution reduces the amount of information a potential thief could access if your wallet or purse gets lost.
- Secure Your Mailbox: Consider installing a mailbox with a lock at your residence to minimize the risk of mail theft.
- Securely Dispose: Never dispose of credit card receipts or personal information documents in a public trash container; use a shredder instead.
- Secure Your Purse or Wallet: Never leave your purse or wallet unattended, whether at work or in places like churches, restaurants, fitness clubs, parties, or shopping carts. Also, avoid leaving your purse or wallet visible in your car, even if the vehicle is locked.
- Limit Your Credit: Limit the number of credit cards you possess and cancel inactive accounts to simplify your financial security.
- Be Careful of What you Disclose: Do not disclose your credit card, bank, or Social Insurance information over the phone, even if you initiated the call, unless you can confidently verify the call’s legitimacy
- Secure Receipts: Securely store and shred credit, debit, and ATM card receipts before disposing of them.
- Scrutinize Your Bills: Scrutinize your utility and subscription bills regularly to confirm the accuracy of the charges.
- Do Not Write Down Your Passwords (except in a Password Vault): Memorize your passwords and personal identification numbers (PINs) to eliminate the need to write them down or use a password vault. Remain vigilant when entering your PIN to ensure no one is observing you.
- Secure Your Information: Maintain a comprehensive list of all your credit and bank accounts in a secure location, such as a password vault. This will facilitate quick communication with issuers if your cards go missing, including providing account numbers, expiration dates, and customer service and fraud department contact numbers.
- Shred Pre-approved Credit Offers: Before discarding pre-approved credit offers, credit card receipts, or phone bills, tear them into small pieces or cross-cut shred them to prevent potential identity theft. Thieves can use such offers to apply for credit cards in your name and redirect them to their address.
- Keep Your Credit Information Accurate: According to consumer reporting legislation, if you believe any entry on your credit report is incorrect or incomplete, you can notify a major credit reporting bureau, which will verify the information at no charge. Remember that they typically do not accept disputes from third parties unless accompanied by a notarized power of attorney authorizing a licensed attorney or a family member to represent you or if the power of attorney is unlimited and irrevocable.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.

Apps and Location Tracking: What Are the Consequences?
Introduction
Of the many digital traces we leave in daily life, location metadata may be the most revealing. Location tracking is common in many applications because it’s so useful – it can allow you to get directions from here to there, discover the closest restaurants near you, or tell you your local weather conditions. These perks, however, can come with large privacy risks.
Companies that you would never suspect needing so much of your data, are quietly collecting enormous amounts of data. For example, in 2020, an investigation was done on Tim Hortons, as the Tim Hortons app reportedly tracked an individual’s location more than 2,700 times in five months. Commissioners say Tim Hortons collected “vast amounts” of granular location data with the aim of delivering targeted advertising, to better promote its coffee and associated products, but that it never actually used the data for this purpose.
Some of the apps on our phone sell or share location data about their users with companies that analyze the data and sell their insights. There are many ways location data can be used, and the market for this data is huge – the location data industry is an estimated $12 billion market. Collectors, aggregators, marketplaces, and location intelligence firms are potential buyers interested in your location data.
What is being collected?
Some apps genuinely need your location to work properly, but others have different motives. Many collect location data for reasons unrelated to their main function, like targeted ads or selling it to data brokers.
Once an app collects your location data, you lose control over where it goes. It can be sold repeatedly—from data providers to aggregators that combine information from multiple sources. It could end up in the hands of a “location intelligence” firm that uses the raw data to analyze foot traffic for retail shopping areas and the demographics associated with its visitors.
You might think, “I have nothing to hide.” But location data can reveal much more than you realize, such as:
- Where you get medical treatment and what kind
- If you visit a domestic abuse shelter
- Where you worship
- Where your kids play (if they have phones)
- When you’re on vacation and where you go
- Where you shop, eat, and bank
- Who you spend time with
Even though this data isn’t directly linked to your name, experts have shown that it’s easy to match location history with other data to identify people and their habits. In 2020, a religious publication used smartphone app data to infer the sexual orientation of a high-ranking Roman Catholic official. The publication claimed it obtained “commercially available” location data from an unnamed vendor and linked it to the priest’s phone, revealing visits to gay bars and private residences while using Grindr, a dating app popular with the LGBTQ+ community.
Privacy advocates have long cautioned that advertisers gather location and personal data, which is then compiled and sold by data brokers. This information can be used to identify individuals and is not subject to regulations requiring clear consent from those being tracked.
What can I do to limit location tracking?
The quickest and easiest way to reduce tracking is to delete unnecessary apps. Both Android and Apple allow you to check which apps have access to your location and whether they track it only while in use or all the time. If you don’t use an app often, consider removing it.
Your location can be tracked through your phone, logged-in accounts, internet connection, and location services. To limit oversharing, take these steps:
- Only allow location access for apps that truly need it.
- Set location permissions to “While Using the App” instead of “Always.”
- Only share “Find My Phone” with trusted friends and family.
- Review third-party apps in location settings—you might be sharing more than you realize.
Despite these precautions, location tracking can’t be completely eliminated. It’s important to support companies that provide clear and transparent privacy policies.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.

PetSmart Warns Customers of Credential Stuffing Attack
Introduction
PetSmart, a pet retail giant in the United States, is alerting certain customers about password resets resulting from an ongoing credential stuffing attack attempting to breach existing accounts. The company released a statement on March 6 to let customers know about the credential stuffing attack.
As a precaution, PetSmart reset the passwords for any accounts logged in during the credential stuffing attack. Additionally, they reassured customers that there was no evidence of compromise to petsmart.com or any of their systems during the incident.
What is credential stuffing?
A credential stuffing attack is a type of cyber-attack in which threat actors use previously acquired usernames and passwords, typically obtained from data breaches, to gain unauthorized access to user accounts on various online platforms.
Threat actors usually automate the process of trying these login credentials across multiple websites and services. Threat actors are cognizant of the fact that people commonly reuse passwords across various accounts, making them even more inclined to exploit this widespread behavior.
How to protect yourself against credential stuffing attacks
Although cyber breaches may be unavoidable, you can still prevent breached details from being used on other websites or services by taking the following precautions:
- Use Unique Passwords For Each Account – Minimize the impact if one account is compromised.
- Enable Multi-Factor Authentication (MFA) – Implement MFA wherever possible to add an additional layer of security.
- Update Outdated Passwords – Change your passwords periodically, especially for critical accounts like email, banking, and social media.
- Limit Access – Only use trusted devices and networks to access sensitive accounts. Avoid logging in from public computers or unsecured Wi-Fi networks to access sensitive accounts. Ensure that you are not saving your credentials on a public computer.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.

Why Regular Software Updates Are Essential for Strengthening Cybersecurity
Introduction
As technology rapidly advances, so do the threats to business security, underscoring the critical importance of regular software updates. Cyber-attacks are becoming increasingly sophisticated and widespread, posing significant risks to organizations of all sizes. To defend against these malicious threats, businesses must prioritize keeping their software up to date.
Software updates not only introduce new features but also provide essential security patches to address potential vulnerabilities. Failing to update can leave individuals and businesses exposed to cyber breaches, data theft, and financial loss. Given the growing reliance on technology for daily operations, maintaining strong security measures is more important than ever.
Regular software updates are a crucial line of defense against cyber threats, making it imperative for businesses to stay current to protect their data, customers, and reputation.
How can I check if my software is up-to-date?
You can check if your device’s software is up to date by going into the device’s settings and looking for the “software update” option. Here’s how to do it on different types of devices:
- On Apple devices (iPhone, iPad): Go to Settings > General > Software Update to see if any updates are available.
- On Android devices (like Samsung Galaxy): Go to Settings and tap on Software Update or System Update. The exact location may vary depending on the model, but it’s usually found in the main settings menu.
- On Windows devices: Go to Settings and find the Windows Update section. From there, click Check for updates to see if your system needs an update.
- On macOS (iMac, MacBook): From the Apple menu n the corner of your screen, choose System Settings. Click General in the sidebar of the window that opens, then click Software Update on the right.
Whenever possible, activate automatic updates to receive the latest patches immediately upon release.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.

Potential Concern with Apple's New NameDrop Feature
Introduction
In Early November, Apple released ‘NameDrop’ as part of the iOS 17.1 operating system update. NameDrop allows users to share saved contacts between other newer iPhones or Apple Watches within an inch of each other. While the prompt must be accepted to share contact information, several law enforcement agencies recommend parents to change this feature for children.
Summary of the incident
The ‘NameDrop’ feature is similar to Apple’s AirDrop functionality. When NameDrop is enabled, two iPhone users can activate the feature by holding the top ends of their iPhones together. After that, the users can tap ‘Share’ or ‘Receive Only’. The NameDrop feature is automatically enabled once a user updates to iOS 17.1.
While the feature itself is not a threat, law enforcement agencies are concerned that the feature puts children at a bigger risk with connecting to strangers. Children may not be completely aware when accepting a new ‘Share’ or ‘Receive Only’ prompt. Police recommend turning the feature off for children once they upgrade to iOS 17.1.
Recommendations
- Turn the ‘NameDrop’ Feature Off for Children – It is good practice to upgrade your iPhone devices to the latest operating system update. The latest operating system update will include ‘NameDrop’ and automatically enable the feature. To turn off the NameDrop feature, complete the following:
Navigate to iPhone Settings > General > Airdrop > Bringing Devices Together > Off.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.
%20(1).png)
Have questions after reading?
If something you’ve read raises a concern, our team can help you understand how it applies to you. Richter Guardian provides ongoing monitoring and expert support for individuals, families, and leadership teams.
- Clear visibility into personal digital risk
- Guidance from experienced cybersecurity professionals
- Support designed for both private clients and enterprise leadership
%20(1).avif)
.png)
