BT
Privacy ToolboxJournalProjectsResumeBookmarks
Feed
Privacy Toolbox
Journal
Projects
Resume
Bookmarks
Intel
Threat Actors
Privacy Threats
Dashboard
CVEs
Tags
Intel
Threat ActorsPrivacy ThreatsDashboardCVEsTags

Intel

  • Feed
  • Threat Actors
  • Privacy Threats
  • Dashboard
  • Privacy Toolbox
  • CVEs

Personal

  • Journal
  • Projects

Resources

  • Subscribe
  • Bookmarks
  • Developers
  • Tags
Cybersecurity News & Analysis
github
defconxt
•
© 2026
•
blacktemple.net
  1. Feed
  2. /Privacy Settlement, Phishing Evolution, and Weekly Threat Intel Roundup

Privacy Settlement, Phishing Evolution, and Weekly Threat Intel Roundup

March 2, 2026Malware & Threats2 min readmedium

Originally reported by BleepingComputer, Malwarebytes Labs

#privacy#phishing#smart-tv#data-collection#threat-intelligence#social-engineering
Share

TL;DR

Samsung agrees to stop collecting Texas residents' viewing data without consent following state settlement. Meanwhile, threat actors deploy sophisticated phishing campaigns disguised as purchase order PDFs to harvest credentials.

Why medium?

The phishing campaign represents an active threat to organizations through social engineering tactics, while the Samsung privacy settlement addresses ongoing data collection concerns affecting millions of users.

Privacy Enforcement and Evolving Threat Landscape

This week brought significant developments in privacy enforcement and threat actor tactics, highlighting the dual challenges of corporate data collection practices and sophisticated social engineering campaigns.

Samsung Settles Texas Data Collection Case

Samsung reached a settlement agreement with the State of Texas over allegations of unlawful collection of content-viewing information through its smart TV platform. The agreement requires Samsung to stop collecting Texans' viewing data without express consent, marking a significant privacy enforcement action at the state level.

The case underscores growing regulatory scrutiny of connected device data collection practices, particularly in jurisdictions with strengthened privacy laws. Smart TV manufacturers have faced increasing pressure over automatic content recognition (ACR) technology that tracks viewing habits for advertising purposes.

For security teams managing IoT device policies, this settlement reinforces the importance of understanding data flows from connected devices within corporate networks and ensuring compliance with applicable privacy regulations.

Purchase Order Phishing Campaign Targets Credentials

Malwarebytes researchers identified a sophisticated phishing campaign using fake purchase order attachments to harvest login credentials. The attack vector leverages business document expectations to bypass user suspicion, presenting what appears to be a standard PDF attachment that instead redirects to credential harvesting pages.

This technique exploits the routine nature of purchase order processing in business environments, where employees regularly receive and open similar documents. The campaign demonstrates threat actors' continued evolution in social engineering tactics, moving beyond generic phishing attempts to context-specific business process exploitation.

Security teams should reinforce email security training around business document verification and implement additional controls for attachment handling, particularly for finance and procurement-related communications.

Weekly Security Intelligence Digest

Malwarebytes Labs released their weekly security roundup covering threat intelligence developments from February 23 through March 1, 2026. The digest format provides security practitioners with consolidated awareness of emerging threats and ongoing campaigns.

Regular threat intelligence consumption remains critical for maintaining situational awareness of the evolving threat landscape. Weekly digests from established research organizations offer efficient methods for security teams to stay informed about trends that may impact their environments.

Sources

  • https://www.bleepingcomputer.com/news/security/samsung-tvs-to-stop-collecting-texans-data-without-express-consent/
  • https://www.malwarebytes.com/blog/threat-intel/2026/03/purchase-order-attachment-isnt-a-pdf-its-phishing-for-your-password
  • https://www.malwarebytes.com/blog/news/2026/03/a-week-in-security-february-23-march-1

Originally reported by BleepingComputer, Malwarebytes Labs

Tags

#privacy#phishing#smart-tv#data-collection#threat-intelligence#social-engineering

Tracked Companies

🇰🇷Samsung

Related Intelligence

  • Weekly Threat Roundup: EU Court Shifts Phishing Liability, New .arpa Evasion Techniques Emerge

    mediumMar 9, 2026
  • Microsoft: Threat Actors Weaponizing AI Across Full Attack Chain

    mediumMar 8, 2026
  • Social Security Phishing Campaign Deploys Datto RMM for Remote PC Takeover

    mediumMar 8, 2026

Explore

  • Dashboard
  • Privacy Threats
  • Threat Actors
← Back to the feed

Previous Article

← Ransomware Payments Drop 8% Despite 50% Attack Surge, Median Ransom Size Climbs

Next Article

LLM Agents Achieve Scalable De-anonymization Across Social Platforms →