BforeAI has released a new report revealing a surge in opportunistic domain registrations and digital infrastructure aimed at exploiting public fear, disaster relief mechanisms, and donation campaigns in the wake of the severe 2025 Texas flooding disaster.
BforeAI’s research reveals the main threat themes and motifs to include disaster claims fraud, donation and relief fraud, volunteer/registration bait, e-commerce abuse, search redirection and cloaking, and reputation piggybacking.
Key findings include 45 domain registrations observed to be suspicious, with less than 10% blocklisted on VirusTotal or major thread feeds until BforeAI started disruption, and most hosted with free page builders.
The research team identified over 70 suspicious or malicious domains within 10 days of the flooding onset, out of which 13 were registered within a week, exactly when the news of the Texas flooding started making headlines. Other than this, 46 domains have been updated since January 2025.
Many of the domains analyzed as part of this advisory feature typically have themes that leverage flood-related services, donation drives, and legal fraud baits like fake flood insurance claims and lawsuits.
The researchers also observed volunteer registration forms with PII-harvesting risks and Google SEO or sponsored ad manipulation and infrastructure patterns linked to prior natural disaster scams and several domains hosted on cheap/free registrars, with rotating hosting infrastructure.
You can read the research here: https://bfore.ai/report/advisory-2025-texas-flooding-crisis-scams/
Claud Mythos Threat Report By BforeAI’s PreCrime Labs
Posted in Commentary with tags BforeAI on May 27, 2026 by itnerdIn the six weeks following Anthropic’s Mythos announcement, BforeAI’s PreCrime Labs identified 3,188 domains built to exploit the Claude and Mythos brands. These weren’t simple typosquat pages – they were enterprise-style platforms impersonating AI security scanners, developer tools, vulnerability assessment services, and account marketplaces. Their targets: developers, security teams, and organizations curious enough about Mythos to hand over API tokens, infrastructure data, or payment credentials without realizing the platform wasn’t legitimate.
This series of threats are coming after Anthropic’s recent announcement of Mythos, and its shareability to a limited set of vendors to find vulnerabilities.
You can read more here: https://bfore.ai/report/anthropic-mythos-phishing-domains-threats-exploiting-claude/
Leave a comment »