[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2kIRSxvqaVnjUyMXO-fMX7tvX63ZnFQbRjbXBsJ3TMg":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"fd51e704-2b34-4199-ac36-9bdf8f7bfec0","earthquake-relief-scams-212-fake-domains-exploit-disaster-urgency","245c8944-2749-46b2-b23c-baf18ce3cb44","Earthquake Relief Scams: 212 Fake Domains Exploit Disaster Urgency","Cybercriminals rapidly registered 212 domains mimicking legitimate Venezuela earthquake relief efforts, exploiting public goodwill and the urgency of disaster situations to solicit fraudulent donations or harvest personal information. The root cause is a lack of public security awareness about how scammers weaponize breaking news events to create convincing but fraudulent campaigns. Opaque domain registrant information (WHOIS privacy) further obscures accountability, making it difficult for donors to distinguish legitimate charities from imposters. This matters because victims not only lose money but may also expose sensitive financial and personal data to threat actors. Disasters create time pressure that short-circuits critical thinking, making user education and proactive warnings essential countermeasures.","**Immediate actions:**\n- Verify any donation site against official charity registries (e.g., IRS Tax Exempt Organization Search, Charity Navigator) before contributing.\n- Report suspicious disaster-relief domains to ICANN, national cybercrime units, or the domain registrar directly.\n\n**User awareness measures:**\n- Train employees and the public to recognize urgency-based social engineering tactics commonly deployed after major news events.\n- Distribute internal security advisories whenever a major disaster or breaking news event occurs, warning staff about likely phishing and scam surges.\n\n**Long-term improvements:**\n- Establish a process for security teams to monitor new domain registrations related to major organizational or world events using threat intelligence feeds.\n- Partner with brand-protection services to detect and initiate takedowns of domains impersonating your organization or known legitimate charities.\n- Incorporate disaster-scam scenario training into annual security awareness programs to build lasting skepticism habits.",[12,13,14,15,16,17,18,19,20],"CIS Control 14 – Security Awareness and Skills Training","CIS Control 17 – Incident Response Management","NIST SP 800-50 – Building an Information Technology Security Awareness and Training Program","NIST CSF DE.CM-1 – Network Monitoring and Detection","NIST CSF RS.CO-2 – Incident Reporting","GDPR Article 5(1)(f) – Integrity and Confidentiality of Personal Data","GDPR Article 83 – Conditions for Imposing Administrative Fines (relevant for fraudulent data collection)","FTC Act Section 5 – Unfair or Deceptive Acts (US context for scam reporting)","ITIL – Problem Management (proactive identification of recurring threat patterns)","published","2026-06-29T22:20:37.699894+00:00","2026-06-29T22:20:37.404+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fhackread.com\u002Fvenezuela-earthquake-domains-donation-scam-warnings\u002F","212-new-venezuela-earthquake-domains-prompt-donation-scam-warnings-785f47","212 New Venezuela Earthquake Domains Prompt Donation Scam Warnings",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"182e11d5-57c4-444e-8ec8-4682ad60261b","Incident Response","incident-response","Slow detection, poor containment, missing playbooks","#14b8a6",{"id":36,"name":37,"slug":38,"description":39,"color":40},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]