Egidio
Transparency · Sources

Every source used on egidio.app

Every competitive claim, every scam statistic, every regulatory reference cited on this site comes from an identifiable public source. Here is the complete list, market by market, with the date each source was accessed.

Why this page exists. A comparison that states facts about a competitor without sourcing them is worthless — to you, to a journalist, to an AI tool that might cite this content. We prefer verifiability over convenience.

Found an error or a dead link? Write to us: contact@egidio.app.

How these sources are chosen and verified: see our methodology.

Comparisons with competitors

Germany — vs tellowsGermany
  • tellows.deOfficial site — community-based scoring 1-9, German company subject to GDPR, Premium €4.99/year. Accessed 12/07/2026.
  • phone-safety.de — "Spam-Blocker-Apps im Test 2026"Independent comparison citing tellows as the DACH reference, ~500,000 active users. Accessed 12/07/2026.
Indonesia / Malaysia / Philippines — vs Whoscall (+ Getcontact for Indonesia)Southeast Asia
  • whoscall.comOfficial Gogolook site — regional leader in Southeast Asia, offline database. Accessed 12/07/2026.
  • getcontact.comOfficial site — community hashtag feature, also widely used in Indonesia. Accessed 12/07/2026.
Brazil — vs Truecaller / Não Me PerturbeBrazil
  • minhaoperadora.com.brBrazilian telecom-focused outlet — Não Me Perturbe registry (ANATEL) and Truecaller's strong penetration in Brazil. Accessed 12/07/2026.
Spain — vs Truecaller / Lista RobinsonSpain
  • cope.esSpanish media outlet — coverage of phone scams and blocking tools available in Spain. Accessed 12/07/2026.
  • cibervoluntarios.orgSpanish digital-mediation NGO — references the Lista Robinson (ADigital), the telemarketing opt-out registry. Accessed 12/07/2026.
United States — vs HiyaUnited States
  • hiya.comOfficial site — Hiya notably powers Samsung Smart Call. Accessed 12/07/2026.
  • unstar.app/blogIndependent comparison of Hiya / RoboKiller / Truecaller / Nomorobo, 2026. Accessed 12/07/2026.
  • robokiller.com/compareOfficial RoboKiller comparison page, used to verify its claims before citation. Accessed 12/07/2026.
France — vs Truecaller / Saracroche / Orange TéléphoneFrance
  • truecaller.comOfficial site — how it works, free ad-supported model, subscription Premium options. Accessed 12/07/2026.
  • saracroche.fr / Google Play listing for SaracrocheFrench free call-blocking app, ~600k downloads, 4.8★. Accessed 12/07/2026.
  • assistance.orange.fr — Anti-Spam OrangeOfficial Orange page describing the Phone/Anti-Spam app bundled with certain mobile plans. Accessed 12/07/2026.
  • support.google.com — Caller ID & spam protectionOfficial Android documentation on the native call-filtering setting (only one app active at a time). Accessed 12/07/2026.
Gulf / United Arab Emirates — vs CallAppGulf
  • callapp.comOfficial CallApp site — community caller identification, strong presence in the Middle East. Accessed 12/07/2026.
  • wizcase.comCybersecurity analysis confirming Truecaller's ban in the United Arab Emirates — the reason Truecaller is never cited as a comparison on the site's Arabic pages. Accessed 12/07/2026.
Japan — vs WhoscallJapan
  • whoscall.comOfficial Gogolook site — 100M+ downloads, offline database, leader in Asia/Southeast Asia. Accessed 12/07/2026.
  • jetro.go.jpJapan External Trade Organization — Gogolook/Whoscall presence in Fukuoka. Accessed 12/07/2026.
Mexico — vs TruecallerMexico
  • truecaller.comOfficial Truecaller site — how it works, free/ad-supported model, strong presence in Latin America. Accessed 12/07/2026.
Netherlands — vs Truecaller / Bel-me-nietNetherlands
  • nationaletelefoongids.nlDutch national number registry — Bel-me-niet reference. Accessed 12/07/2026.
  • avrotros.nlCoverage of the new opt-in telemarketing law, in force since 1 July 2026 (ACM). Accessed 12/07/2026.
Poland — vs Orange TelefonPoland
  • lowiczanin.infoPolish local press referencing the Orange Telefon app. Accessed 12/07/2026.
  • sekurak.plPolish cybersecurity outlet — CERT Polska, SMS alert shortcode 8080. Accessed 12/07/2026.
Turkey — vs GetcontactTurkey
  • getcontact.comOfficial site — works via community hashtags attached to phone numbers. Accessed 12/07/2026.
  • idntimes.com — report on Getcontact hashtagsExplains how the hashtag feature can expose personal information added by other users. Accessed 12/07/2026.

Rigor note: one source mentioned a Turkish court ruling blocking Getcontact and 70 other apps. This information could not be corroborated by a second reliable source at the time of writing — it was therefore deliberately not used in the published content.

The Threat Lab

The Threat Lab — UK Data Breaches: What the ICO Records (2025-2026) (page /en-gb/laboratoire/uk-data-breaches/)United Kingdom
  • ICO, Data Security Incident Trends dashboardQ4 2025: 3,600 incidents reported in the quarter, up 16% year on year; 77% non-cyber, 23% cyber. Just over 50% of 2025 breaches affected 1-9 individuals.
  • ICO, monetary penalty against Capita plc and Capita Pension SolutionsOctober 2025: combined £14m fine (£8m / £6m) over the March 2023 intrusion affecting c. 6.6 million people; reduced from a proposed £45m.
  • ICO, press release and enforcement notice, 27 March 2025Advanced Computer Software Group fined £3.07m over the August 2022 ransomware attack, 79,404 people affected; first ICO fine issued against a data processor.
  • ICO enforcement actions, 2025£2.31m against 23andMe and £1.23m against LastPass UK for UK GDPR security failings.
  • Co-op, chief executive statement, 2025Confirmation that the personal data of all 6.5 million members was taken in the April 2025 attack; no financial or transactional data involved.
  • UK Finance, Annual Fraud Report 2026£1.28 billion in payment fraud losses across the UK banking sector in 2025, up 4% year on year across more than four million reported cases.
The Threat Lab — Global scam report (page /laboratoire/rapport-mondial-arnaques/)
  • Europol, Internet Organised Crime Threat Assessment (IOCTA) 2026Published 28/04/2026: persistence of ransomware (several groups active throughout 2025), growing overlap between hybrid state threats and criminal actors, cybercrime expansion enabled by encryption, proxies, and AI. Accessed 14/07/2026.
  • ENISA, Threat Landscape 2025Diversified targeting of public administrations by organized groups (beyond central government institutions alone: diplomatic entities, ministries, law enforcement, political parties). Accessed 14/07/2026.
  • FBI, Internet Crime Complaint Center (IC3) — 2024 annual report859,532 complaints in 2024, $16.6 billion in reported losses (+33% year-on-year). Already cited on this page for /en/true-cost/. Accessed 14/07/2026.
  • FBI, 2026 communication on IC3 complaint classificationIntroduction of an "AI-related" descriptor: over 22,000 complaints and nearly $900 million in losses in the very first year of this classification. Accessed 14/07/2026.
The Threat Lab — Generative AI & voice deepfakes (page /laboratoire/ia-generative-deepfake/)
  • FBI, 2026 communication on IC3 complaint classificationReused (see section above): 22,000+ "AI-related" complaints, ≈$900 million in losses. Accessed 14/07/2026.
  • Pindrop, 2025 Voice Intelligence and Security Report1300% rise in voice-deepfake fraud attempts measured in 2024; potential call-center exposure estimated at ≈$44.5 billion in fraud in 2025. Accessed 14/07/2026.
  • Hong Kong Police, documented case from early 2024, widely covered by specialized pressAn employee deceived by a video conference composed of AI-generated participants impersonating company executives, authorizing a $25.6 million transfer. Accessed 14/07/2026.
The Threat Lab — SIM farms & criminal call centers (page /laboratoire/sim-farms-centres-appels/)
  • Europol & Eurojust, "SIMCARTEL" operation (October 2025)Coordinated with Austrian, Estonian, Latvian, and Finnish authorities: 49 million fake online accounts enabled, 1,200 SIM-box devices seized, 40,000 active SIM cards seized (numbers from 80+ countries), 5 servers seized, 7 arrests. Documented losses: ≈$5.2M across 1,700 Austrian cases, ≈$490,000 across 1,500 Latvian cases. Accessed 14/07/2026.
The Threat Lab — Documented criminal networks: the Lazarus case (page /laboratoire/reseaux-criminels-lazarus/)
  • FBI, CISA & US Treasury, joint advisory (April 2022)Attribution of the "TraderTraitor" subgroup's activities to the Lazarus group (DPRK). Accessed 14/07/2026.
  • US Department of Justice (DOJ), 2023Seizure of over $15 million in crypto assets stolen by the group across four exchanges. Accessed 14/07/2026.
  • FBI & Japan National Police Agency (NPA), May 2024Theft of $308 million from the DMM Bitcoin exchange, attributed to TraderTraitor. Accessed 14/07/2026.
  • FBI, public attribution, late 2024Theft of $1.5 billion from the Bybit exchange, attributed to North Korean TraderTraitor actors. Accessed 14/07/2026.
  • Microsoft & Google Threat Intelligence / Mandiant, 2025Documentation of the "fake North Korean IT workers" scheme: infiltrating companies via fake remote developer/freelancer profiles to steal crypto assets and intellectual property. Accessed 14/07/2026.
The Threat Lab — Fake QR codes & quishing (page /laboratoire/faux-qr-codes-quishing/)
  • FBI, Internet Crime Complaint Center (IC3), alert PSA250731 (31/07/2025)Unsolicited packages containing QR codes used to initiate fraud schemes. Accessed 14/07/2026.
  • FTC (Federal Trade Commission), consumer alert (December 2023)Scammers hiding malicious links inside QR codes to steal personal information. Accessed 14/07/2026.
  • FTC (Federal Trade Commission), consumer alert (January 2025)QR codes received with unexpected packages, redirecting to phishing sites. Accessed 14/07/2026.
  • KnowBe4, 2025 Phishing Threat Trends Report82.6% of phishing emails analyzed used generative AI, up 53.5% year-on-year. Report from a named, dated security vendor — cited as such, distinct from a public/academic source. Accessed 14/07/2026.
The Threat Lab — Recruitment fraud (page /laboratoire/fraude-recrutement/)
  • FTC (Federal Trade Commission)$150.4 million in reported losses across 25,002 reports in Q4 2025; annual losses rose from $90 million (2020) to $501 million (2024); median loss per victim of $2,000. Accessed 14/07/2026.
  • Better Business Bureau (BBB), study published May 2026Employment-fraud reports doubled in 2025 versus the prior year (23,234 reports via BBB Scam Tracker). Accessed 14/07/2026.
The Threat Lab — Why fraud is exploding now (page /laboratoire/pourquoi-maintenant/)
  • FBI, 2026 communication on IC3 complaint classification; Pindrop, 2025 Voice Intelligence and Security ReportReused (see sections above, /laboratoire/rapport-mondial-arnaques/ and /laboratoire/ia-generative-deepfake/). Accessed 14/07/2026.
  • IBM, Cost of a Data Breach Report 2025Global average cost of a data breach: $4.44 million in 2025 (down 9% year-on-year); record $10.22 million cost in the United States (+9%). Accessed 14/07/2026.
  • Europol & Eurojust, "SIMCARTEL" operation (October 2025)Reused (see section above, /laboratoire/sim-farms-centres-appels/). Accessed 14/07/2026.
  • PIRG (Public Interest Research Group), "Ringing in Our Fears 2025"Average monthly volume of fraud and telemarketing calls rose from 2.14 billion (2024) to 2.56 billion per month through September 2025, +20% year-on-year. Accessed 14/07/2026.
  • FBI, Internet Crime Complaint Center (IC3), 2024 reportLosses from fraudulent calls targeting people over 60: over $4.57 billion in the United States in 2024. Accessed 14/07/2026.
The Threat Lab — Phone harassment (page /laboratoire/telephone-relations-toxiques/)
  • Cour de cassation, ruling of 23 May 2007A text message can constitute admissible evidence before French courts, including in criminal matters, provided its author is identifiable and the message is preserved in context — unlike a phone recording made without the other party's knowledge. Accessed 14/07/2026.
  • Insee, "Cyberviolences dans les établissements scolaires et dans la société," 2025Malicious phone calls and messages are the most common form of digitally linked harassment: 89% of people affected by this type of harassment also report associated cyberviolence. Accessed 14/07/2026.
  • 3919, Violences Femmes InfoNational reference number, run by the Fédération Nationale Solidarité Femmes with state support — free, anonymous, available 24/7 across mainland France and overseas territories. Accessed 14/07/2026.
  • 3018, national number against cyberbullyingDedicated service for young people and those around them (e-Enfance association). Accessed 14/07/2026.
The Threat Lab — Threats 2030 (page /laboratoire/menaces-2030/)
  • ENISA, Foresight Cybersecurity Threats for 2030 — Update 2024Structured foresight exercise (Delphi survey + scenario workshops) identifying the ten threat trajectories judged most likely/impactful by 2030, including software supply-chain compromise (1st), skills shortage (2nd), AI abuse, cross-border cloud-provider concentration, and advanced disinformation campaigns. Accessed 14/07/2026.
  • ENISA, Threat Landscape 2025Reused (see section above, /laboratoire/pourquoi-maintenant/): growing convergence between hacktivists, cybercriminals, and state-linked groups. Accessed 14/07/2026.
  • FBI (IC3), 2026Reused (see section above, /laboratoire/rapport-mondial-arnaques/): "AI-related crime" descriptor, 22,000 complaints/≈$900M in losses. Accessed 14/07/2026.
The Threat Lab — Hybrid threats (page /laboratoire/guerres-hybrides/)
  • Hybrid CoE — The European Centre of Excellence for Countering Hybrid ThreatsReference definition of a hybrid threat: action by a state or non-state actor aiming to weaken a target by influencing its decision-making. Intergovernmental structure based in Helsinki. Accessed 14/07/2026.
  • Council of the European Union, "Hybrid threats" pageOfficial description of the combination of means characterizing a hybrid threat (information, cyber, economic, political). Accessed 14/07/2026.
  • ENISA & EEAS, "Foreign Information Manipulation and Interference (FIMI) and Cybersecurity — Threat Landscape"Joint report on the link between information manipulation and cybersecurity; the FIMI term originated in 2021, proposed by the European External Action Service. Accessed 14/07/2026.
  • ENISA, Threat Landscape 2025Reused (see section above, /laboratoire/pourquoi-maintenant/): "faketivism" phenomenon, disinformation activity spikes around sensitive political events. Accessed 14/07/2026.
The Threat Lab — Dark web (page /laboratoire/dark-web/)
  • Europol, Internet Organised Crime Threat Assessment (IOCTA) 2025"Steal, Deal, and Repeat": the online criminal economy runs on access (credentials, identities, sensitive data); 34% of listings on major dark-web markets analyzed in 2025 involved financial services; average price of $4,200 for a corporate bank credential with MFA bypass. Accessed 14/07/2026.
  • TechRadar, coverage of a joint international operation (2025)Over 373,000 dark-web-linked sites taken offline, dozens of servers seized. Accessed 14/07/2026.
  • The Hacker News, "FBI and Europol Seize LeakBase Forum Used to Trade Stolen Credentials" (March 2026)Seizure of the LeakBase forum, specialized in reselling infostealer "logs." Accessed 14/07/2026.
The Threat Lab — Emerging phishing techniques (page /laboratoire/techniques-phishing-emergentes/)
  • Microsoft Defender for Office 365, October 2025Over 13 million malicious emails linked to the "Tycoon 2FA" phishing kit (adversary-in-the-middle technique bypassing two-factor authentication) blocked in October 2025 alone. Accessed 15/07/2026.
  • Trustwave, 2024-2025 research140% rise in callback-phishing (TOAD) campaigns between July and September 2024; most-impersonated brands: Microsoft, Norton, PayPal, DocuSign. Accessed 15/07/2026.
The Threat Lab — Evolution of smishing (page /laboratoire/evolution-smishing/)
  • Federal Trade Commission (FTC), Data Spotlight$470 million in reported text-scam losses in the United States in 2024, a fivefold increase since 2020. Accessed 15/07/2026.
  • FBI, Internet Crime Complaint Center (IC3), 202459,271 complaints received for SMS scams linked to fake road-toll fees. Accessed 15/07/2026.
The Threat Lab — Voice spoofing (page /laboratoire/spoofing-vocal/)
  • Federal Communications Commission (FCC), "Caller ID Spoofing"Official definition of neighbor spoofing (a number displaying the target's local area code); fines of up to $10,000 per violation for malicious spoofing. Accessed 15/07/2026.
  • FCC, STIR/SHAKEN deployment data as of 28/09/202544% of registered US phone carriers have fully deployed the STIR/SHAKEN call-authentication protocol. Accessed 15/07/2026.
  • TNS, 2026 Robocall Investigation ReportOnly 17.5% of traffic signed and verified between small phone carriers in 2025, versus a markedly higher rate among large carriers. Accessed 15/07/2026.
The Threat Lab — Romance scams (page /laboratoire/arnaques-sentimentales/)
  • Federal Trade Commission (FTC), 2025$1.16 billion in reported romance-scam losses over the first nine months of 2025; median loss of $2,218 in Q3 2025. Accessed 15/07/2026.
  • FTC, 2026 Data Spotlight on social-media-related scamsNearly 60% of people who reported a romance-scam loss in 2025 say the first contact happened on a social media platform. Accessed 15/07/2026.
  • FBI, Internet Crime Complaint Center (IC3), 2025 reportRomance scams ranked among the costliest categories; $7.7 billion in losses in 2025 for people aged 60 and over, across all fraud categories. Accessed 15/07/2026.
The Threat Lab — Social media banned under 15, France + European panorama (page /laboratoire/majorite-numerique-15-ans/)
  • French National Assembly, final adoption, 21/07/2026France becomes the first European country to ban social media for under-15s. Accessed 21/07/2026.
  • European panorama — distinct country pages, locally sourced (not translations of the French dossier)Germany (Prien/SPD/Ethikrat debate, Bund/Länder competence question), Netherlands (coalition agreement, European strategy), Spain (bill in parliamentary shuttle, CNMC filter), Italy (AGCOM age-verification precedent, Nov. 2025), Poland (eIDAS 2.0/EUDI-Wallet mechanism), Portugal (adopted at first reading, 12/02/2026). Accessed 21-26/07/2026.
The Threat Lab — Minimum age for social media, 8 non-EU markets (bespoke pages per language)
  • Mexico — Clic Noticias, La Razón, El Informador, Congreso CDMX, Cadena Política, La Silla RotaNational debate launched by the Sheinbaum administration (SEP forums Aug-Sept 2026) + initiative by CDMX Congress member Laura Álvarez (16/04/2026), proposed threshold 15-16, not yet adopted. Accessed 26/07/2026.
  • Brazil — Senado Notícias, ConJur, GCAA, Câmara dos Deputados, CNN Brasil, Gazeta do PovoLaw No. 15.211/2025 (ECA Digital) in force since 17/03/2026; new PL 94/2026 debate for a stricter ban, public hearing July 2026. Accessed 26/07/2026.
  • Turkey — Balkan Insight, Washington Post, US NewsLaw passed by the TBMM on 22-23/04/2026, threshold 15, operational effect expected 01/11/2026. Accessed 26/07/2026.
  • United Arab Emirates — Gulf News/Khaleej Times, Baker McKenzie, Clyde & Co, Hogan Lovells, ZawyaThreshold of 15 for personal social media accounts + Federal Decree-Law No. 26 of 2025 (Child Digital Safety), in force since 01/01/2026. Accessed 26/07/2026.
  • Indonesia — Library of Congress Global Legal Monitor, JURIST, cms.law, Jakarta Globe, TechCrunchPP 17/2025 ("PP TUNAS") in force since 28/03/2026, tiered system 13/15/16. Accessed 26/07/2026.
  • Malaysia — The Edge Malaysia, Malay Mail, FMT, Mayer Brown, SoyaCincau, BernamaOnline Safety Act 2025 (ONSA), threshold of 16 in force since 01/06/2026; private-messaging provisions in public consultation until 20/07/2026. Accessed 26/07/2026.
  • Japan — Nikkei, Bloomberg Japan, Biometric Update, Japan TodayDebate on stronger age verification (MIC, LDP, Children and Family Agency, spring-summer 2026); Japan explicitly rejects an Australia-style strict ban. Accessed 26/07/2026.
  • Philippines — senate.gov.ph, Philstar, Manila Bulletin, PNA, BusinessMirrorFour competing bills under consideration in Senate/Congress (SB 595, SB 2066, SB 1955, HB 9825), none adopted to date. Accessed 26/07/2026.

Rigour note: for each market where no local debate equivalent to the EU's message-scanning Chat Control was found (notably Mexico, Philippines, Japan), the dossier says so explicitly rather than forcing a parallel with the European regulation.

The Threat Lab — United Kingdom: Online Safety Act and under-16 social media ban (pages /en/laboratoire/)United Kingdom
  • NPR, NBC News, 15/06/2026Prime Minister Keir Starmer announces a ban on social media for under-16s, named platforms (Instagram, Facebook, TikTok, Snapchat, YouTube, X), livestreaming/stranger-contact blocks, fines up to 10% of global turnover or £18m. Accessed 26/07/2026.
  • UK Parliament, research briefing CBP-10468; government consultation83% of parents judge the risks to outweigh the benefits, 90% support a threshold of 16. Accessed 26/07/2026.
  • Internet Watch Foundation, Ofcom (consultations Dec. 2024 and June 2025)Online Safety Act 2023, Technology Notice power (§121) for message scanning — never exercised against an encrypted service to date; final guidance expected around April 2026. Accessed 26/07/2026.
  • blakemorgan.co.uk, jurist.org, computerweekly.com, internetsociety.org, privacyinternational.org, gsmarena.comApple/Home Office standoff: Apple withdraws Advanced Data Protection in the UK (February 2025), UK government withdraws its access demand (August 2025), related litigation ongoing in 2026. Accessed 26/07/2026.
The Threat Lab — Country report Germany (page /de/laboratoire/deutschland-betrugsbericht/)Germany
  • BKA (Bundeskriminalamt), Bundeslagebild Cybercrime 2024 (published June 2025)€178.6 billion in annual damage from cyberattacks in Germany (+€30B year-on-year); 32% clearance rate for cybercrime (vs 58% for all offenses); 131,391 domestic cybercrime cases recorded + 201,877 cases abroad/unknown. Accessed 15/07/2026.
  • BSI (Bundesamt für Sicherheit in der Informationstechnik), Die Lage der IT-Sicherheit in Deutschland 2025950 ransomware cases reported to police (80% targeting SMEs); 119 new vulnerabilities detected per day on average. Accessed 15/07/2026.
  • Bundesnetzagentur, press release of 09/02/202685,158 complaints about phone-number abuse in 2025, about 6,200 numbers deactivated. Accessed 15/07/2026.
  • Verbraucherzentrale Brandenburg, January 2026Alert on AI voice-cloning shock calls replacing the classic "Enkeltrick" (fake-grandchild scam). Accessed 15/07/2026.
The Threat Lab — Country report Brazil (page /pt-br/laboratorio/relatorio-brasil-golpes/)Brazil
  • Febraban, survey published 2025R$10.1 billion in financial-fraud losses in 2024 (+17% vs R$8.6B in 2023).
  • Serasa Experian, Indicador de Tentativas de Fraude, H1 20256.9 million fraud attempts detected in H1 2025 (+29.5% year-on-year, one every 2.3 seconds), 53.7% targeting banks/card issuers.
  • SaferNet Brasil, 2025 report (published February 2026)87,689 cybercrime reports received by the Central Nacional de Denúncias in 2025 (+28.4% vs 2024).
  • Polícia Federal, July 2026 ("Operação Ad Phishing")1,770 fraudulent ads identified impersonating the federal government, across multiple states.
The Threat Lab — Country report United Arab Emirates (page /ar/mukhtabar-altahdidat/taqrir-alimarat/)United Arab Emirates
  • UAE Financial Intelligence Unit (UAEFIU), Strategic Analysis ReportAED 1.2 billion (≈$326M) in documented fraud losses, 2021-2023; vishing/phishing/smishing as the three leading fraud types per suspicious-transaction-report analysis. Accessed 15/07/2026.
  • Central Bank of the UAE (CBUAE), notice 2025/3057, issued May 202531 March 2026 deadline for the full phase-out of SMS/email OTP codes by UAE banks. Accessed 15/07/2026.
  • Dubai Media Office, official press releaseFraud network dismantled by the Dubai Police anti-fraud center (20/07/2025), using 6 fake trading brands. Accessed 15/07/2026.
The Threat Lab — Country report Spain (page /es/laboratorio/informe-espana-estafas/)Spain
  • Ministerio del Interior (Spain), Informe sobre la Cibercriminalidad en España 2025488,426 cybercrimes recorded in 2025 (+5.1%), 19.8% of total crime; 429,677 computer frauds (nearly 9 in 10 cybercrimes); 383,285 victims (+9.3%), the 51-65 age bracket most affected, 146,737 bank-card fraud victims. Accessed 15/07/2026.
  • INCIBE (Instituto Nacional de Ciberseguridad), Balance de Ciberseguridad 2025122,223 incidents handled in 2025 (+26%), including 45,445 online frauds (+19%) driven by 25,133 phishing cases; 142,767 calls to the 017 helpline (+44.9%). Accessed 15/07/2026.
  • Moncloa.com, citing Ertzaintza data, 2026Regional spike of +125% in online scams in the Basque Country — an illustrative real case, not a national average. Accessed 15/07/2026.
The Threat Lab — Country report United States (page /en/laboratoire/us-fraud-report/)United States
  • FBI, Internet Crime Complaint Center (IC3), 2025 annual report$20.877 billion in losses / 1,008,597 complaints (first time crossing one million complaints); $7.7 billion for people 60+ (+37%); investment fraud in the lead ($8.6B); 22,364 AI-related complaints (≈$893M). Accessed 15/07/2026.
  • FTC, Consumer Sentinel Network Data Book 2024 (published March 2025)$12.5 billion in losses / 6.5 million reports, +25% year-on-year. Accessed 15/07/2026.
The Threat Lab — France report (page /laboratoire/rapport-france/)France
  • Cybermalveillance.gouv.fr, 2025 activity report (published March 2026)Over 500,000 victims assisted in 2025 (+20% year-on-year); breakdown 93% individuals / 6% businesses and associations / 1% local authorities; +73% in assistance requests from businesses and associations; phishing the top threat across all audiences (+70%); online account takeover the top threat for professionals (+45%). Accessed 14/07/2026.
The Threat Lab — Country report Indonesia (page /id/laboratorium/laporan-indonesia-penipuan/)Indonesia
  • OJK / Indonesia Anti-Scam Centre (IASC), June 2026 dataOver 608,000 cases, Rp9.3 trillion in cumulative losses; over 557,000 accounts blocked, Rp674 billion secured, about Rp200 billion returned. Accessed 15/07/2026.
  • Kominfo, 2024 review1.3 million phone numbers blocked over the year. Accessed 15/07/2026.
  • Bareskrim Polri, February and May 2026 press releasesFake e-tilang phishing case (5 suspects, February 2026); cross-border network linked to Cambodia dismantled (23 complaints, arrests in May 2026). Accessed 15/07/2026.
The Threat Lab — Country report Italy (page /it/laboratorio/rapporto-italia-truffe/)Italy
  • Polizia Postale e delle Comunicazioni, Rapporto 2025 (released January 2026)€269 million taken from victims, 27,085 economic-financial cybercrime cases; 94,000+ phishing/attack reports; 51,560 total cases, 293 arrests, 7,590 people reported. Accessed 15/07/2026.
  • ACN (Agenzia per la Cybersicurezza Nazionale), Relazione annuale 2025+38% cyber events in 2025 vs 2024 (2,729 events, 615 confirmed-impact incidents); Italian public administration hit by 1,140 events (vs 756 in 2024). Accessed 15/07/2026.
  • Garante per la protezione dei dati personali, 2025 data2,415 data-breach notifications received in 2025 (over 6 per day), +22% versus 2023-2024. Accessed 15/07/2026.
The Threat Lab — Country report Japan (page /ja/kyoi-kenkyujo/nihon-sagi-report/)Japan
  • National Police Agency (警察庁), 2025 official report on "tokushu sagi" (特殊詐欺, special fraud)27,832 cases in 2025 (historic record); ¥142.31 billion in losses (nearly doubled year-on-year, record); fake-police fraud: 11,014 cases / ¥100.5 billion (doubled year-on-year); social-media investment/romance fraud: 15,168 cases / ¥183.4 billion, average loss ¥12.13 million per case; people 65+ = 51.3% of cases and 59.2% of losses. Accessed 15/07/2026.
The Threat Lab — Country report Malaysia (page /ms/makmal/laporan-malaysia-penipuan/)Malaysia
  • Malaysian Ministry of Home Affairs, via Malay Mail, June 2026RM2.97 billion in total online-scam losses in 2025. Accessed 15/07/2026.
  • Bukit Aman CCID (PDRM), via Malay Mail, December 202528,698 phone-scam cases (Macau-scam type, voice impersonation) for RM715 million in losses; RM1.37 billion in investment-fraud losses (9,296 cases), over half of national losses. Accessed 15/07/2026.
  • National Scam Response Centre (NSRC), via New Straits Times, February 2025146,167 calls received on the 997 hotline, RM34.05 million saved through rapid intervention. Accessed 15/07/2026.
The Threat Lab — Country report Mexico (page /es-mx/laboratorio/reporte-mexico-fraudes/)Mexico
  • CONDUSEF, via El Universal, accessed 15/07/20262.48 million bank-fraud complaints in H1 2025 (+5.2% year-on-year); 10,714 million pesos claimed, 72% of all bank claims; only 24.3% reimbursement rate (Q1 2026).
  • La Jornada, citing the Guardia Nacional, accessed 15/07/2026+40.7% in internet crimes reported via the 088 system in 2024 vs 2023, fraud the leading motive (35.5%) of cyber-police investigations.
The Threat Lab — Country report Netherlands (page /nl/laboratorium/nederland-fraude-rapport/)Netherlands
  • Fraudehelpdesk, Terugblik 2025 (published February 2026)100,000 reports in 2025 (+69% year-on-year); about €69 million in total reported damage, credit-card fraud the main driver. Accessed 15/07/2026.
  • De Nederlandsche Bank (DNB), February 2026€198 million in payment fraud within the Dutch system in 2025 (+22%), 658,000 fraudulent transactions (+30%). Accessed 15/07/2026.
  • CBS (Centraal Bureau voor de Statistiek), Veiligheidsmonitor 202517% of the population (15 and over) victims of online crime in 2025 (≈2.5 million people), including 10% specifically online fraud/scams. Accessed 15/07/2026.
The Threat Lab — Country report Philippines (page /fil/laboratoryo/ulat-pilipinas-scam/)Philippines
  • NTC (National Telecommunications Commission), 2025 data, via Philippine Daily InquirerOver 2.2 billion fraudulent texts blocked, 10.8 million numbers blacklisted, 2.3 million SIM cards deactivated. Accessed 15/07/2026.
  • Philippine Daily Inquirer, 2025 (BSP-linked data)+71.9% in cybercrime complaints in Q1 2025 (1,891 → 3,251 cases year-on-year); 76% of 2025 losses due to social engineering/account takeover/identity theft. Accessed 15/07/2026.
  • PNP Anti-Cybercrime Group (ACG)8,897 scam-related cases (January-October 2025) versus 14,529 over the same period in 2024. Accessed 15/07/2026.
  • NBI (National Bureau of Investigation), press release, November 2025Arrest in Parañaque City of a foreign national spoofing numbers to impersonate US law enforcement, demanding $3,000 to $5,000 in cryptocurrency. Accessed 15/07/2026.
The Threat Lab — Country report Poland (page /pl/laboratorium/raport-polska-oszustwa/)Poland
  • CERT Polska / NASK, Raport roczny 2025 (published 08/04/2026)658,320 reports in 2025 (+10% year-on-year), 260,783 distinct incidents (+150%+ year-on-year).
  • Komenda Główna Policji (reused, see section above /le-vrai-cout/)About 160 million zł in losses from "na legendę" scams (fake grandchild/fake police officer) in 2025.
  • ZBP (Związek Banków Polskich), infoDOK report359.7 million zł in attempted credit fraud prevented in 2025 (15,200 attempts).
  • CBZC (Policja), second half of 2025Criminal group extorting BLIK codes dismantled — about 1,300 victims, over 3 million zł.
The Threat Lab — Country report Portugal (page /pt/laboratorio/relatorio-portugal-burlas/)Portugal
  • Renascença, 10/02/2026, citing Linha Internet Segura949 cybercrime/violence reports in 2025 (+39% year-on-year); +44% in reported online scams (358 cases in 2025 vs 247 in 2024).
  • Renascença, 01/07/2026, citing Polícia Judiciária / Procuradoria-Geral da República€50 million moved through shell companies in a dismantled network (11 arrests), originating from a CEO-fraud scam.
  • Banco de Portugal, Relatório dos Sistemas de Pagamentos 2025€5.3 million in card/transfer fraud losses in H1 2025 (-40.4%), 66 frauds per million card transactions.
The Threat Lab — Country report Turkey (page /tr/laboratuvar/turkiye-dolandiricilik-raporu/)Turkey
  • TÜİK, Türkiye Suç Mağduriyeti Araştırması 2025 (first national victimization survey, published early 2026)2.8% of people 15+ victims of consumer fraud over one year; 3.5% victims of cybercrime over the same period.
  • İçişleri Bakanlığı Emniyet Genel Müdürlüğü (cybercrime unit), operation of 10/07/202676.28 billion Turkish lira in traced transaction volume in an Istanbul-centered operation (68 suspects, aggravated fraud + money laundering).
  • BTK (Bilgi Teknolojileri ve İletişim Kurumu), decision of 23/12/2025, effective 01/04/2026Regulation blocking fraudulent SMS at the carrier level and requiring electronic signatures for bulk SMS senders.
The Threat Lab — Data breaches Germany (page /de/laboratoire/deutschland-datenlecks/)Germany
  • BfDI, 34. Tätigkeitsbericht, presented 06/05/20269,170 GDPR breach notifications received in 2025 (+36% year-on-year), 11,824 complaints/requests.
  • BfDI, press release of 03/06/2025Record €45 million fine against Vodafone Germany (€15M for lack of partner-agency oversight, €30M for authentication flaws in the "MeinVodafone" portal).
  • Samsung Germany, March 2025≈270,000 customer records leaked on a hacker forum, traced to a 2021 infostealer infection at a third-party provider (Spectos GmbH) whose credentials had never been rotated.
  • Unimed (hospital billing provider), 14/04/2026Over 120,000 private patient records exposed (billing, diagnoses, banking data), notably affecting the Freiburg (54,000) and Cologne (30,000) university hospitals.
  • Apotheke Adhoc, Deutsche Apotheker Zeitung, Pharmazeutische ZeitungD-Trust (Bundesdruckerei subsidiary), 1-6/01/2025: professional healthcare-card portal (eHBA/SMC-B) compromised; initial partial tallies (413 pharmacists in North Rhine-Westphalia, 247 in Lower Saxony) followed by final official confirmation of at least 2,113 pharmacists and over 10,000 doctors nationwide — a gap between initial figures and the official tally. Accessed 16/07/2026.
  • it-daily.net, citing a Darktrace study, June 202693.3% of surveyed German professional sports organizations suffered a cyber incident in 2025; 100% of organizations with over €100M in revenue affected; 81% show signs of AI-assisted attacks. Accessed 16/07/2026.
  • Zerforschung.org, confirmed by NDR/WDR/Süddeutsche Zeitung, 08/10/2025Hotel software Sihot (Gubse AG): up to 48.5 million customer profiles and 35.5 million bookings exposed (names, addresses, birth dates, partial card numbers, passport numbers), affecting Motel One and several DJH youth hostels. Accessed 16/07/2026.
The Threat Lab — Data breaches Brazil (page /pt-br/laboratorio/vazamentos-de-dados-brasil/)Brazil
  • Brazilian federal government, data cited by specialized press3,253 breaches reported between January and July 2024, more than the sum of 2020-2023.
  • ANPD, June 202619 new sanction proceedings opened (the largest batch ever); maximum fine of R$50 million per violation under the LGPD.
  • Agência Brasil / Banco Central, 24-26/07/2025Sisbajud judicial-system flaw exposing 46.8 million Pix keys belonging to 11 million people; passwords/balances not exposed per the Central Bank.
  • Hardware.com.br / iMasters, 2026"MORGUE" database: 251,720,444 CPF records linked to Gov.br put up for sale for $500, surpassing the previous record of 223 million (2021).
The Threat Lab — Data breaches Brazil, additional sectors (page /pt-br/laboratorio/vazamentos-de-dados-brasil/)Brazil
  • Poder360, CNN Brasil — ISAC (Instituto Saúde e Cidadania), 2025Ransomware affecting about 500,000 patients across 6 states, including 78,772 minors and 47,921 elderly people; ANPD opened a sanction proceeding for lack of individual notifications. Accessed 16/07/2026.
  • TecMundo, Athena Security — Universidade Cruzeiro do Sul + 10 institutions (30/10/2025)Attacker "darkhackbreach" claiming over 3 million records/100,000 credentials across 11 higher-education institutions; university confirming "possible access" without confirming exact figures. Accessed 16/07/2026.
  • CryptoID — Gol/Smiles (12/11/2025)Unauthorized access to the loyalty-program system via a third party, less than 0.04% of the customer base affected. Accessed 16/07/2026.
The Threat Lab — Data breaches United Arab Emirates (page /ar/mukhtabar-altahdidat/tasarrub-bayanat-alimarat/)United Arab Emirates
  • UAE Cyber Security Council, statement of 25/03/2025 (The National / Khaleej Times)634 UAE public/private entities targeted in a single attack linked to a global cloud provider.
  • Federal Decree-Law No. 45 of 2021 (PDPL), Article 9Legal 72-hour deadline to notify a data breach.
  • DataBreaches.Net, 04/06/2025 (claim not confirmed by the hospital)American Hospital Dubai: about 4 TB claimed exfiltrated by the Gunra ransomware group.
  • Ransomware.live / DeXpose, incident disclosed 20/07/2025TransCore (Dubai office): over 200 GB claimed exfiltrated by the Crypto24 group.
The Threat Lab — Data breaches United Arab Emirates, additional sectors (page /ar/mukhtabar-altahdidat/tasarrub-bayanat-alimarat/)United Arab Emirates
  • DeXpose, RedPacket Security, Breachsense — Mediclinic Middle East (04-05/02/2026)Ransomware group 0APT claims ~2.1 TB exfiltrated (health insurance records, staff data); not confirmed by Mediclinic. Accessed 16/07/2026.
  • Brinztech, breach alert — NEST Academy Dubai (July 2026)Unidentified threat actor claims 1.14 GB published publicly (passports, ID documents, unredacted academic certificates); not confirmed by the institution. Accessed 16/07/2026.
The Threat Lab — Data breaches Spain (page /es/laboratorio/espana-filtraciones-datos/)Spain
  • AEPD, press release, January 20262,765 breach notifications received in 2025 (vs 2,933 in 2024, 2,005 in 2023), 80% from the private sector; over 200 million high-risk communications sent to affected individuals in 2025, roughly double the prior year.
  • Iberdrola / I-DE, AEPD sanction April 20241.3 million customers affected by a 2022 leak (national ID, phone, email); combined €6.5 million fine for security failures dating back to 2019.
  • CaixaBank, AEPD sanctions 2024€5 million (February) for exposing other customers' transfer data; €3.5 million (December) for a separate online-banking access flaw.
  • El Economista, Servimedia, EscudoDigital — Hospital Los Madroños (Madrid)Ransomware attack attributed to the Qilin group, detected 07/03/2025; about 540 GB / 21,000+ files claimed, patient data (names, national ID, medical records) exposed; AEPD notified, exact victim count never disclosed by the hospital. Accessed 16/07/2026.
  • IUSPORT, AEDD, Mountain Bike — Real Federación Española de CiclismoBreach detected August 2024, about 80,000 federation members exposed (name, national ID/tax ID, address, phone, license photo, club). Accessed 16/07/2026.
  • wwwhatsnew, Hosteltur, Portal Artico — Booking.comBreach confirmed 13/04/2026, disproportionately affecting Spanish hotel customers (13% of Spanish hotels attacked over 12 months vs 7% EU average); gap between an unofficial figure of about 1 million customers mentioned and about 4,000 formally documented cases with 300 involving card data. Accessed 16/07/2026.
The Threat Lab — Data breaches United States (page /en/laboratoire/us-data-breaches/)United States
  • Identity Theft Resource Center (ITRC), 2025 Annual Data Breach Report, published January 20263,322 data compromises recorded in 2025 (historic record, +79% over five years); 278.8 million victim notifications. Accessed 15/07/2026.
  • AT&T, legal settlement, preliminary approval June 2025$177 million settlement covering up to 182 million people (2024 dark-web leak ≈73M + Snowflake cloud leak ≈109M accounts).
  • Aflac, June 2025; HHS OCR, 2025 review≈22.65 million people affected worldwide (at least 13.9M in the US), the largest healthcare breach of 2025, linked to the Scattered Spider group; 35M+ people affected by major healthcare breaches in 2025 per HHS OCR.
  • HHS OCR, HIPAA Journal, TechCrunch, Security AffairsTriZetto Provider Solutions (Cognizant): 3,433,965 people confirmed via the HHS OCR notification portal, breach Nov. 2024-Oct. 2025, notifications started Feb. 2026. Accessed 16/07/2026.
  • Tech Times, teissStrategic Education (Strayer & Capella universities): 111,706 confirmed victims (social security numbers) per state-regulator filings, February 2026 breach discovered 21/05/2026. Accessed 16/07/2026.
  • CPO Magazine, SecureWorld, ComplianceHub.wikiMadison Square Garden Sports/Knicks: the ShinyHunters group claimed 26 million records (June 2026), but MSG never confirmed the breach and independent analysts verified only about 9.8 million emails — a textbook case of the gap between claim and official confirmation. Accessed 16/07/2026.
  • The Register, SecurityWeek, CybernewsBWH Hotels (Best Western): 6-month breach (Oct. 2025-Apr. 2026), data of "some guests" exposed among more than 53 million loyalty-program members, no exact count disclosed. Accessed 16/07/2026.
The Threat Lab — Data breaches (page /laboratoire/fuites-donnees/)France
  • CNIL (French data protection authority), 2025 review17,802 data-breach notifications received in 2025, versus 5,630 in 2024; the attacks on software vendors Weda and Harvest alone generated over 11,600 additional notifications; 2,730 breaches notified in Q1 2026 alone, versus 2,500 for the same period in 2025. Accessed 14/07/2026.
  • CNIL, France Travail sanction (January 2026)Reused (see section /laboratoire/rapport-mondial-arnaques/ above for general context): €5 million fine following the March 2024 intrusion potentially affecting 43 million users. Accessed 14/07/2026.
  • CNIL, Free / Free Mobile sanctions (13/01/2026)Combined fines of €42 million (€27M Free Mobile + €15M Free) following the October 2024 cyberattack that exposed data linked to 24 million subscriber contracts, with IBANs compromised for some customers. Accessed 14/07/2026.
  • Ministry of the Interior, official confirmation (20/04/2026), cited by specialized pressFrance Titres (formerly ANTS): access-control flaw (IDOR) exploited by a 15-year-old on moncompte.ants.gouv.fr, detected 15/04/2026. Officially confirmed figure: 11.7 million accounts affected — lower than the hacker's initial claim of 19 million, corrected on this page on 16/07/2026 to reflect the official figure rather than the claim. €200 million cyber plan announced 30/04/2026. Accessed 16/07/2026.
  • Silicon.fr / Generation-NT, citing URSSAF (19/01/2026, official)Fraudulent access via the DPAE API (credentials stolen from an authorized partner), up to 12 million employees hired since January 2023 potentially affected (names, dates of birth, employer SIRET — no national ID/email/IBAN). CNIL notified, complaint filed. Accessed 16/07/2026.
  • education.gouv.fr, official press release (14/04/2026)National Education / ÉduConnect: credentials of an authorized staff member compromised in late 2025, flaw exploited just before it was patched. First name, last name, ÉduConnect ID, school, and class exposed; hackers "Dump Sec" claimed 3.5 million minor students. Accessed 16/07/2026.
  • France 24 · Franceinfo · France Assos Santé (February 2026)Cegedim Santé: cyberattack late 2025, administrative data of 15 million French people exposed via 1,500 physician users (name, phone, address); no prescriptions or test results leaked, but the type of doctor consulted could indirectly reveal sensitive information. Paris Prosecutor's Office involved. Accessed 16/07/2026.
  • leto.legal (June 2026)DMP (shared medical record): claim of 34 million accounts stolen by a pseudonymous cybercriminal "Lagui"; Assurance Maladie denies any mass extraction or unauthorized access detected — an unconfirmed claim, treated as such on this page. Accessed 16/07/2026.
  • Franceinfo · patrickbayeux.com (April 2026)French Basketball Federation: cyberattack of 17/04/2026, 2 million members and 900,000 legal guardians exposed (no banking data). French Athletics Federation: over 11 million records extracted. Series of cyberattacks hitting golf, hunting, climbing, tennis, judo, sailing, gymnastics, skiing, aikido, badminton federations. Accessed 16/07/2026.
  • Clubic, citing French Breaches and Le Parisien (14-15/05/2026)Pierre & Vacances-Center Parcs: 4,575,065 customer profiles claimed (data dating back to 2005) via a subsidiary Maeva platform; the hacker cites other brands within and beyond the group (Adagio, Sunparks, Belambra, etc.) but the officially confirmed scope is limited to a single subsidiary. Complaint filed, CNIL alerted 15/05/2026. Accessed 16/07/2026.
  • IBM, Cost of a Data Breach Report 2025Reused (see section /laboratoire/pourquoi-maintenant/ above). Accessed 14/07/2026.
  • Specialized compilation (shattered.io), unofficialEstimate of about 300 breached services and 250 million exposed records in France since January 2026 — presented as an order of magnitude, not a statistic certified by a public authority (unlike the CNIL figures above). Accessed 14/07/2026.
The Threat Lab — Data breaches Indonesia (page /id/laboratorium/indonesia-kebocoran-data/)Indonesia
  • BSSN, reported April 2026 (Kompas)5.5 billion cyberattack anomalies in Indonesia in 2025 (+714% vs the 2020-2024 average); 93.8% classified as malware (Mirai Botnet, Remcos RAT, generic Trojan dominant).
  • Kompas, May 2021 (confirmed by Kemkominfo as identical to BPJS Kesehatan data)279 million civil-registry records and 20 million personal photos sold on a hacker forum by the account "Kotz."
  • ASIS Online / Fulcrum / Biometric UpdateBrain Cipher ransomware against the Pusat Data Nasional (17-20/06/2024, Surabaya): 282 public services across 200+ institutions paralyzed, $8 million ransom refused by the government, decryption key released for free on 03/07/2024.
The Threat Lab — Data breaches Indonesia, additional sectors (page /id/laboratorium/indonesia-kebocoran-data/)Indonesia
  • Brinztech, breach alert — BPJS Kesehatan (08/06/2026)Actor "DIVACCX 707" claims ~280 million records; not confirmed by BPJS Kesehatan or Kominfo. Accessed 16/07/2026.
  • Tempo, Beritasatu, Info Pendidikan BIC (08/02/2026)Claimed leak of 58 million student records, denied by the Menko PMK and Kemendikdasmen; investigation opened by Komdigi. Accessed 16/07/2026.
  • PHRI DIY, Tempo, Kompas (August 2024)~120 hotels/homestays in Yogyakarta victims of Google Business listing hijacking, booking contact details altered to siphon travelers' deposits. Accessed 16/07/2026.
The Threat Lab — Data breaches Italy (page /it/laboratorio/italia-violazioni-dati/)Italy
  • Garante per la protezione dei dati personali, 2025 data2,415 breach notifications in 2025 (+10% vs 2,204 in 2024, itself +22% over the prior year); €37.7 million in fines issued in 2025 (+54.5% vs €24.4M in 2024).
  • InfoCert, December 2024Attack discovered 27/12/2024, data claimed on BreachForums: ≈5.5M records, 1.1M phone numbers, 2.5M emails; Garante inquiry opened 03/01/2025.
  • Garante Privacy, 2026 press releaseRecord €31.8 million fine against Intesa Sanpaolo for over 6,600 improper accesses to the bank records of 3,573 customers between 21/02/2022 and 24/04/2024.
  • Garante Privacy, admonition no. 10116834 of 13/02/2025ASL 1 Abruzzo: Monti ransomware attack on 03/05/2023, 10,631 people affected (employees, patients, minors, and vulnerable people), sensitive health data exposed (oncology, HIV, pregnancy terminations); attackers claimed 522 GB, only 389 GB actually published. Accessed 16/07/2026.
  • "Mydocs" group, June-August 2025, Italian specialized press4 hotels named (Ca' dei Conti Venice, Regina Isabella Ischia, Hotel Continentale Trieste, Casa Dorita Milano Marittima); tens of thousands of scanned ID cards/passports stolen and resold on the dark web; the group claimed over 70,000 documents (up to 160,000 per some analysts), confirmed at tens of thousands per property. Accessed 16/07/2026.
  • Nicola Bernardi, chairman of Federprivacy, February 2026Nuvola school electronic register (Madisoft platform, used by 1,000+ schools): credentials, IBANs, contracts, and passwords indexed unprotected on Google. Accessed 16/07/2026.
The Threat Lab — Data breaches Japan (page /ja/kyoi-kenkyujo/nihon-jouhou-roei/)Japan
  • Personal Information Protection Commission (PPC), 2025 annual report (via Nikkei/Jiji)19,417 breach notifications (2nd highest level ever recorded, -8% year-on-year); private sector 17,139 (-10%); public administrations 2,278 (record).
  • Aflac Japan, official announcement + Nikkei≈4.38 million customers affected, ≈230,000 with banking data exposed; intrusion began 15/06/2026, discovered 25/06, disclosed 30/06/2026.
  • Askul, official statements≈740,000 records leaked (590k B2B, 132k B2C), ransomware detected 19/10/2025, initial intrusion 05/06/2025, full findings disclosed 12/12/2025.
The Threat Lab — Data breaches Japan, additional sectors (page /ja/kyoi-kenkyujo/nihon-jouhou-roei/)Japan
  • Official hospital reports, INTERNET Watch — Nihon Medical School Musashi-Kosugi Hospital (09-27/02/2026)Ransomware via a medical-equipment maintenance VPN; initial estimate of ~10,000 patients (13/02), revised to ~130,000 patients + ~1,700 staff members after further investigation (27/02) — a 13x factor illustrating the gap between the initial claimed figure and the final confirmed figure. Accessed 16/07/2026.
  • Official JFA statement, FOOTBALL ZONE (25 and 28/04/2026)Breach on the CAMPFIRE crowdfunding platform used by the Japan Football Association: 225,846 unique records (names, addresses, phone, email, bank details), no card data. Accessed 16/07/2026.
  • Official hotel statement, 株式会社アクト — Kyoto Garden Palace (detected 23/10/2025, announced 14/11/2025)~2,800 guest booking records, reused for email phishing within the following three weeks. Accessed 16/07/2026.
The Threat Lab — Data breaches Malaysia (page /ms/makmal/malaysia-kebocoran-data/)Malaysia
  • Jabatan Perlindungan Data Peribadi (JPDP), Data Breach Notification Guideline, 25/02/2025Mandatory breach notification effective 01/06/2025 (72h to the JPDP, 7 days to affected individuals if over 1,000 people affected); fines up to RM250,000 and/or 2 years in prison.
  • MyCERT, Cyber Incident Quarterly Summary Report Q4 2025171 breach incidents reported in Q4 2025 (+20% vs Q3 2025); 195 reports in Q1 2025 (+29% vs Q4 2024).
  • TechWireAsia, January 2024Telekom Malaysia: a hacker claims theft of about 20 million customer records (MyKad numbers, religion, marital status).
  • MalaysiaNow, 04/08/2025Government sites: a hacker claims compromise of over 11 ministry/agency sites, offered for sale for $20,000 on a dark-web forum.
The Threat Lab — Data breaches Malaysia, additional sectors (page /ms/makmal/malaysia-kebocoran-data/)Malaysia
  • Malay Mail, The Star, Free Malaysia Today (27-30/06/2026)Hack of the Ministry of Health (MOH) website via a Joomla vulnerability; the ministry officially confirms no patient data was exposed. Accessed 16/07/2026.
  • The Star, New Straits Times (06/10/2025)Ransomware attack on the Malaysian Football Federation's (FAM) competition management system, 13-hour ultimatum. Accessed 16/07/2026.
  • Cybernews (21-22/04/2026)Claim of 82 million Malaysian Agoda customer records, denied by Agoda; Cybernews' analysis found only a 23-line sample with no stay-date field. Accessed 16/07/2026.
The Threat Lab — Data breaches Mexico (page /es-mx/laboratorio/mexico-filtraciones-datos/)Mexico
  • El Financiero, 30/01/2026Hack of 25 federal/state agencies by the "Chronus" group: 36.5 million people affected, 2.3 TB of data.
  • R3D (Red en Defensa de los Derechos Digitales)Consejería Jurídica de la Presidencia (November 2024, 200+ GB exfiltrated); IMSS (August-September 2025, 20 million retirees, sold for 50,000 pesos by the "Sc0rp10nn" group); "InfernoLeaks" (April 2025, 700 GB of Mexican personal data).
The Threat Lab — Data breaches Mexico, additional sectors (page /es-mx/laboratorio/mexico-filtraciones-datos/)Mexico
  • El Financiero, R3D, ejecentral — IMSS-Bienestar / "Chronus" (30/01/2026)SPPA health data of over 3.1 million beneficiaries, part of a claimed 36.5 million/2.3 TB haul; ATDT (government agency) publicly downplayed the severity — a noted gap between claim and official confirmation. Accessed 16/07/2026.
  • Fortuna y Poder, xeu noticias — IMSS blood bank (May 2026)3.4 million people exposed via an IDOR-type flaw (CURP manipulation in the URL). Accessed 16/07/2026.
  • Infobae — DGETI/CBTis/CETis, UNAM (January 2026)At least 14 confirmed incidents in the education sector by March 2026. Accessed 16/07/2026.
  • ShinyHunters, claim July-October 2025 — AeroméxicoClaim of 30-39 million records, but only about 2,000 customer records were confirmed by independent researchers — a notable gap between claim and confirmation. Accessed 16/07/2026.
The Threat Lab — Data breaches Netherlands (page /nl/laboratorium/nederland-datalekken/)Netherlands
  • Autoriteit Persoonsgegevens (AP), Rapportage datalekken 202544,374 data-breach notifications in 2025 (vs 37,839 in 2024, 25,694 in 2023); 2,428 breaches caused by cyberattacks in 2025, nearly doubling from 2024.
  • AddComm, May 2024 ransomware attack≈1.5 million people affected via over 5,400 client organizations; the AP forced 16 organizations to notify an additional 83,000 victims.
  • Cervical cancer screening program, 2025Breach at an external lab, initially 485,000 then ultimately ≈941,000 women affected (medical data + BSN number).
  • NOS, ICT&health, Computable, NL Times — ChipSoft (Embargo group), 07/04/2026Patient-record software used by over half of Dutch hospitals; hackers claimed 100 GB stolen; ChipSoft first denied, then confirmed weeks later; De Forensische Zorgspecialisten confirmed about 6,000 clients affected, over 60 notifications to the AP. Accessed 16/07/2026.
  • NOS, Security.NL — Basic-Fit, April 2026About 200,000 Dutch members affected (including IBAN and attendance history) out of 1 million Dutch members among 5.8 million worldwide. Accessed 16/07/2026.
  • EenVandaag, Security.NL, AGConnect — Secureholiday/CtoutvertDetected 28/02/2026, exploited May-June 2026: 41,577 Dutch campers affected; documented direct breach-to-scam case, 14 campers (including 6 Dutch) actually defrauded via phishing emails containing their real booking data. Accessed 16/07/2026.
The Threat Lab — Data breaches Philippines (page /fil/laboratoryo/pilipinas-data-breach/)Philippines
  • Manila Bulletin, 22/10/2025Over 4.3 million Filipinos affected by data breaches in Q3 2025 (+73% vs the prior quarter).
  • National Privacy Commission (NPC), official rulesLegal 72-hour deadline to notify a data breach.
  • vpnMentor, research relayed by InquirerNBI/PNP/BIR (April 2023): 1,279,437 records (817.54 GB) exposed for over 6 weeks.
  • NPC, findings of 30/10/2025GCash/G-Xchange: a dark-web listing claimed 7 to 8 million customer records, but the NPC's official investigation found "no sufficient basis" to confirm a breach — the data sample did not match GCash's verified structures. A case cited as an example of rigor: an unconfirmed claim is not treated as fact.
The Threat Lab — Data breaches Philippines, additional sectors (page /fil/laboratoryo/pilipinas-data-breach/)Philippines
  • HIPAA Journal, Rappler, NPC (National Privacy Commission) — PhilHealth (22/09/2023-03/10/2023)Medusa ransomware, data published after a $300,000 ransom refusal; the NPC's official investigation confirms 42,089,693 PhilHealth ID numbers exposed. Accessed 16/07/2026.
  • Instructure statement — Canvas LMS (02/05/2026)ShinyHunters group; 5 Philippine universities publicly named (DLSU, Ateneo, UST, UE, San Beda); student names/emails/IDs exposed, passwords and identity documents explicitly not affected. Accessed 16/07/2026.
  • Blackpanda, case study — Philippine casino-hotel (early 2025)Anonymous dark web report claiming a leak of wealthy guests' data; Blackpanda's forensic investigation confirms no actual data theft — false alarm. Accessed 16/07/2026.
The Threat Lab — Data breaches Poland (page /pl/laboratorium/polska-wycieki-danych/)Poland
  • rp.pl (Cybersec Expo Forum 2026) / prawo.plOver 22,400 breach notifications received by UODO in 2025 (+50% vs about 14,000 in 2024); 32 fines totaling about 64.5 million zł in 2025 (vs 20 fines/13.9M zł in 2024).
  • Cyberdefence24.pl / odoserwis.plALAB Laboratoria (November 2023): about 55,000 lab-result records leaked to the darknet, up to 200,000 patients potentially affected.
  • Cyberdefence24.plChemirol, ransomware attack by the "Payouts King" group (discovered 26/11/2025): PESEL numbers, bank accounts, and salaries exposed, over 400,000 files claimed stolen.
The Threat Lab — Data breaches Poland, additional sectors (page /pl/laboratorium/polska-wycieki-danych/)Poland
  • Polish press — WCM Remedium (Poznań, 28/05/2026) and IKP (April 2025, confirmed by the Ministry of Health)WCM Remedium: PESEL/health data of an unquantified "large group," reported to UODO. IKP: exactly 4 patients confirmed via a URL-manipulation flaw — a contrast between an unquantified case and a precisely confirmed one. Accessed 16/07/2026.
  • POLADA (Polish anti-doping agency), 06/08/2024Russia-linked hackers, about 250 GB/50,000 files, athlete medical/anti-doping data; POLADA officially denied any positive-doping data, calling the claims "fake news" — UODO investigating separately. Accessed 16/07/2026.
  • Polish press — Nowa Itaka (30/10/2025) and Hotres booking system (03/07/2026)Nowa Itaka: 10,000 users confirmed by the company, but the scope may be larger per Deputy PM Gawkowski. Hotres: SQL injection affecting over 2,000 properties, data actively exploited in real-time WhatsApp/SMS scams. Accessed 16/07/2026.
The Threat Lab — Data breaches Portugal (page /pt/laboratorio/portugal-fugas-dados/)Portugal
  • CNPD, Relatório de Atividades 2025 (approved 24/03/2026)472 breach proceedings opened in 2025 (+42% vs 2024, the highest level since 2020); +41% in phishing-caused breach cases (72 cases).
  • Renascença/Sapo/CNN Portugal, April 2026CTT: over a million customer records from the Locky locker service potentially stolen.
  • PÚBLICO/Renascença, May 2026SNS (Portuguese health system): a doctor's stolen credentials used to access records of over 100,000 patients nationwide.
The Threat Lab — Data breaches Portugal, additional sectors (page /pt/laboratorio/portugal-fugas-dados/)Portugal
  • Medscape Portugal, SAPO Tek, IT Insight — Centro Hospitalar de SetúbalAbout 37 GB of patient/staff data (identities, passports, addresses, phone numbers) sold on a dark-web forum after a hospital email account was compromised. Accessed 16/07/2026.
  • PÚBLICO, Malwarebytes, 4gnews — Canvas platform (May 2026)Attacker claimed 275 million users worldwide, but no confirmed impact for the two Portuguese institutions involved (Universidade Europeia, IPAM) — an emblematic case of an unconfirmed claim. Accessed 16/07/2026.
  • PÚBLICO, Observador, ECO — Booking.com (April 2026)Names, emails, phone numbers, booking details exposed, already exploited in phishing/WhatsApp campaigns. Accessed 16/07/2026.
The Threat Lab — Data breaches Turkey (page /tr/laboratuvar/turkiye-veri-sizintilari/)Turkey
  • Balkan Insight, 08/03/2024 and 12/09/2024e-Devlet portal breach revealed March 2024: data of 85 million Turkish citizens offered for free; confirmed by a minister in September 2024 with a 42.18 GB dataset including 108.5 million ID numbers.
  • KVKK, 2025 activity statistics328 breach notifications in 2025 (vs 289 in 2024), 90,358,500 Turkish lira in total fines issued in 2025.
  • Mondaq.com / Güneş Partners, 2026Aktif Yatırım Bankası A.Ş. (January 2026): vulnerability at a third-party software vendor exposing data of 45,000 customers, heavy administrative sanction imposed by the KVKK.
The Threat Lab — Data breaches Turkey, additional sectors (page /tr/laboratuvar/turkiye-veri-sizintilari/)Turkey
  • KVKK, official announcement + T24 — Özbeyler Sağlık ve Özel Hastane (Bodrum), 20/01/2026Ransomware affecting patients, staff, interns, donors and visitors; health data, sex life, religion and biometric data exposed. KVKK public disclosure decision dated 27/01/2026. Accessed 16/07/2026.
  • KVKK, decision no. 2025/573 (20/03/2026) — Bilfen Eğitim KurumlarıBreach discovered on 12/03/2025 via a WhatsApp message from the attackers; 24,061 people affected (students, parents, staff). Accessed 16/07/2026.
  • Turizm Gazetesi, Sekoia Threat Detection & Research (06/11/2025)Hijacking of Booking.com extranet accounts at Turkish hotels to phish guests' banking data (PureRAT malware, campaign active since April 2025); compromised hotel credentials resold for $5 to $5,000 on criminal forums. Accessed 16/07/2026.
The Threat Lab — From breach to scam, Germany (page /de/laboratoire/vom-datenleck-zum-betrug/)Germany
  • BKA, Bundeslagebild / Polizeiliche Kriminalstatistik (PKS) 2025First year of systematic national tracking of Enkeltrick, Schockanruf, and fake-police scams. Accessed 16/07/2026.
  • LKA Niedersachsen, 2025 data1,658 call-center fraud cases, about €8.45M + €2.5M in damages. Accessed 16/07/2026.
  • Rhineland-Palatinate Interior Minister Michael Ebling, January 2026€1.44M in fake-police damages in H1 2025, already exceeding the 2024 total. Accessed 16/07/2026.
  • BKA, press release April 2025Seniors identified as the top priority target group; reporting rate estimated at only about 20%. Accessed 16/07/2026.
The Threat Lab — From breach to scam, Brazil (page /pt-br/laboratorio/do-vazamento-ao-golpe/)Brazil
  • Poder360Brazil ranks first worldwide for data exposed on the dark web, from 2 to 7 billion records (+250% in a year). Accessed 16/07/2026.
  • Serasa Experian, 2025-2026 indicators51% of Brazilians already victimized; a new digital-fraud attempt every 13 minutes; +36.6% in account-opening fraud attempts in Q1 2026. Accessed 16/07/2026.
  • Seade/Agência Brasil, senior study82% of São Paulo seniors targeted by a scam attempt; over 72,000 senior-fraud cases reported to Disque 100 in 2024. Accessed 16/07/2026.
The Threat Lab — From breach to scam, United Arab Emirates (page /ar/mukhtabar-altahdidat/tasarrub-albayanat-ila-alihtiyal/)United Arab Emirates
  • Resecurity — smishing campaign impersonating Dubai Police (peak December 2024)50,000 to 100,000 messages/day, 144+ malicious domains documented. Accessed 16/07/2026.
  • GASA × Trend Micro, 27/01/2026 (n=1,000 UAE residents)1 in 3 people lost money to a scam within 12 months; encountered an attempt on average every 3 days. Accessed 16/07/2026.
  • National Financial Ombudsman Scheme (UAE)Digital banking fraud complaints +73% year-on-year (1,436 → 2,483, January-May 2024 vs 2025); virtual cards the main target. Accessed 16/07/2026.
  • Khaleej Times, testimonials (2023 and May 2025)Account of a journalist targeted by a fake Dubai Police call; case of a victim defrauded via Gulf First Commercial Brokers. Accessed 16/07/2026.
The Threat Lab — From breach to scam, Spain (page /es/laboratorio/de-la-filtracion-a-la-estafa/)Spain
  • INCIBE, Balance de Ciberseguridad 2025Vishing +442% in Spain in 2025; 122,223 incidents handled (+26%); 142,767 calls to the helpline (+44.9%, of which 28% phishing/vishing/smishing). Accessed 16/07/2026.
  • Ministerio del Interior, Balance de Criminalidad 2025429,677 computer frauds / 383,285 victims; average loss of €577 per victim; 146,737 bank-card fraud victims, 51-65 age bracket most affected. Accessed 16/07/2026.
  • Kaspersky, cited by Moncloa.com69% of victims never report the incident. Accessed 16/07/2026.
  • El Correo Gallego (Lacame/Teo operation), El Debate (Balearics), Noticias MenorcaThree documented real cases of video-call/fake-advisor scams in Spain, used as sourced illustrations in the absence of a citable direct testimony found via OCU. Accessed 16/07/2026.
The Threat Lab — From breach to scam, United States (page /en/laboratoire/from-leak-to-scam/)United States
  • FTC, Consumer Sentinel Network$3.5 billion lost to identity-theft scams in 2025 (nearly 3x since 2020); $920 million to government-agency impersonation (vs $789M in 2024); 4x rise in reports of $10,000+ losses among seniors between 2020-2024, 8x for $100,000+ losses. Accessed 16/07/2026.
  • FBI, Internet Crime Complaint Center (IC3), 2025 annual report$7.75 billion lost by over 201,000 victims aged 60+ (+59% year-on-year), average loss $38,000+; 32,400 government-agency-impersonation complaints ($798M), over 8,600 from seniors. Accessed 16/07/2026.
  • AARP, Fraud Watch NetworkReal testimony from Judith Boivin, victim of a fake-FBI-agent scam, $595,000.98 lost. Accessed 16/07/2026.
The Threat Lab — From breach to scam (page /laboratoire/de-la-fuite-a-larnaque/)France
  • Cybermalveillance.gouv.fr, 2025 activity report (published March 2026)Fake-bank-advisor fraud +159% (new variants: fake opposition numbers, use of WhatsApp); transfer fraud +170% (extended to e-invoicing and payroll); phishing +70% (108,000 requests); 504,000+ assistance requests in 2025 (+20%), over 5 million cumulative over two consecutive years. Accessed 16/07/2026.
  • Que Choisir, "Arnaque au faux conseiller bancaire — quand les escrocs connaissent tout de vous," 2026Two victim testimonies documenting scenario personalization (scammer knows the victim's name, address, bank branch); average amount stolen by transfer of €3,000 per victim; 12/05/2026 Paris judicial court ruling dismissing two victims' claims for lack of proof about the displayed number's authenticity. Accessed 16/07/2026.
  • developpez.com, citing a study on dark-web stolen-data pricingA complete identity data pack ("fullz": name, address, social security number, driver's license) can trade for around $35. Rigor note: prices vary widely across sources (from a few cents to several hundred euros depending on the data type and source consulted) — treated on the page as an illustration of a market principle, not a fixed, reliable price. Accessed 16/07/2026.
  • Trend Micro · MetaCompliance, social-engineering reportsSocial engineering exploits human psychology rather than a technical flaw; attacks are built in layers with growing perceived legitimacy; 74% of data breaches involve the human element. Accessed 16/07/2026.
  • Ifop for Fondation April, March 2023 study23% of French people aged 60+ report having already been targeted by a digital scam attempt; 60% of complaints for fraud/abuse of weakness in France involve elderly people. Accessed 16/07/2026.
The Threat Lab — From breach to scam, Indonesia (page /id/laboratorium/dari-kebocoran-ke-penipuan/)Indonesia
  • IASC (Indonesia Anti-Scam Center)608,000+ reported cases, 9.3 trillion IDR in cumulative losses, average loss of 17 million IDR per victim. Accessed 16/07/2026.
  • Bareskrim Polri+30% of cases in Q1 2026; 52.96% of victims are women. Accessed 16/07/2026.
  • KasperskyStarting price ~$0.5 (≈7,000 IDR) for Indonesian personal data on underground markets; prices vary widely by source. Accessed 16/07/2026.
  • Indonesian press, documented cases (BCA Tasikmalaya, Ambon, Palembang)Three concrete dated scams: 160 million IDR (BCA Tasikmalaya), 60.2 million IDR (public official in Ambon), 17.7 million IDR (parcel scam in Palembang). Accessed 16/07/2026.
The Threat Lab — From breach to scam, Italy (page /it/laboratorio/dalla-fuga-alla-truffa/)Italy
  • Polizia Postale, year-end 2025 review€137 million in illicit profits (+20%), 27,085 cases, €81.6M stolen in Q1 2025 vs €57.5M the prior year; documented use of AI-cloned voices in impersonation scams. Accessed 16/07/2026.
  • NordVPN/NordStellar, study published 21/04/2026Dark-web resale price of a complete Italian identity ("fullz"): around $90. Accessed 16/07/2026.
  • Open.online, 14/07/2026Real testimony: Mediobanca Premier number spoofed, five-hour call, account drained of about €1,000 (incident of 16/06/2026). Accessed 16/07/2026.
  • Eurispes, 37th Rapporto Italia 202542,890 victims aged over 65 in 2024 (+15.58%); 7.3% of people over 64 victimized (up to 9.9% in the North-West); 53% of scams are direct requests for money. Accessed 16/07/2026.
The Threat Lab — From breach to scam, Japan (page /ja/kyoi-kenkyujo/roei-kara-sagi-e/)Japan
  • 弁護士JPニュース (12/10/2024)Investigator's quote: fresh/unused victim lists sold for ~¥10,000, already-used lists for ¥300-500 — a figure from a single report, not universal. Accessed 16/07/2026.
  • National Police Agency of Japan (NPA/警察庁)27,832 cases / ¥142.3 billion (2025) versus 21,043 / ¥71.88 billion (2024); fake-police fraud 11,014 cases / ¥100.5 billion; 51.3% of cases and 59.2% of losses involve people 65 and older. Accessed 16/07/2026.
  • Miyagi prefectural police, via Mainichi Shimbun (18/06/2026)49 cases / ~¥359.59 million (January-May 2026), sharp year-on-year rise; prefectural campaign "STOP!名簿流出" on data-list hygiene. Accessed 16/07/2026.
  • Mainichi Shimbun (18/06/2026), Yomiuri ShimbunAccount of a Sendai victim defrauded of ¥1,000,000 via a chain of calls (fake public service → fake police → video call with a fake badge); account of an elderly victim in Kyoto. Accessed 16/07/2026.
The Threat Lab — From breach to scam, Malaysia (page /ms/makmal/dari-kebocoran-ke-penipuan/)Malaysia
  • Malaysian Ministry of Home Affairs, via Malay Mail (24/06/2026)Losses linked to impersonation fraud (bank/police/official): RM497.12 million (2024) → RM802.47 million (2025), i.e. +61%. Total online scam losses: RM2.97 billion (2025) versus RM1.57 billion (2024). Accessed 16/07/2026.
  • Bukit Aman CCID (December 2025), NST (February 2025)28,698 telecom fraud cases / RM715 million; 146,167 calls received by the NSRC-997. Accessed 16/07/2026.
  • GASA21-30 age bracket most affected; 62% of victims report psychological distress. Accessed 16/07/2026.
  • The Vibes, Bernama/The StarDocumented real-case accounts of impersonation scams in Malaysia. Accessed 16/07/2026.
The Threat Lab — From breach to scam, Mexico (page /es-mx/laboratorio/de-la-filtracion-a-la-estafa/)Mexico
  • CONDUSEF, January-May 2026 data+11.4% in digital bank-fraud complaints; +17.3% among 60-69 year-olds, who now represent 32.2% of claims (about 1 in 3 digital-fraud victims is now a senior). Accessed 16/07/2026.
  • CONDUSEF, H1 2025Over 2.4 million bank-fraud cases, +24.6% in identity fraud, 634 million pesos. Accessed 16/07/2026.
The Threat Lab — From breach to scam, Netherlands (page /nl/laboratorium/van-lek-naar-fraude/)Netherlands
  • Fraudehelpdesk / NVB (Nederlandse Vereniging van Banken), 2025 annual figures€25.8M in fake-bank-advisor damages in 2025 (+€3M vs 2024), 5,900 victims; 70% of online scams start on social media; over 100,000 reports in 2025 (+69%). Accessed 16/07/2026.
  • RTV Noord, 2024Real testimony from Henk (83), €10,000 lost in a fake-advisor scam. Accessed 16/07/2026.
  • ANBO-PCOB, February 2025, Fraudehelpdesk data80% of fake-bank-advisor scam victims are over 70; reporting rate of 82%. Accessed 16/07/2026.
The Threat Lab — From breach to scam, Philippines (page /fil/laboratoryo/mula-sa-leak-hanggang-scam/)Philippines
  • BSP (Banko Sentral ng Pilipinas), via Philstar/BusinessWorld (February 2026)76% of 2025 cyber fraud losses in the Philippines stem from social engineering, account takeover and identity theft. Accessed 16/07/2026.
  • BSP, via Inquirer₱5.82 billion in cyber-incident losses in 2024 at supervised institutions. Accessed 16/07/2026.
  • Whoscall+78.4% fraudulent calls year-on-year, 62,390 calls detected in one quarter. Accessed 16/07/2026.
  • GASA, "State of Scams in the Philippines 2025"52% of Filipinos scammed at least once, 77% faced an attempt, average loss of ₱11,896 over 12 months. Accessed 16/07/2026.
  • KAMI.com.ph (July 2026), PCIJ.org (June 2026)Real, dated testimonials: a Mangaldan (Pangasinan) victim defrauded of ₱230,000 by voice phishing; a family targeted by BDO-impersonating smishing, ~₱250,000 lost. Accessed 16/07/2026.

Rigor note: The Threat Lab (hub /laboratoire/) is an ongoing editorial project — more dossiers will be added progressively, each with its own sourced section here. The detailed financial side of crypto scams (rug pulls, pig butchering, fake exchanges) is deliberately out of scope at this stage, reserved for a dedicated project.

The Threat Lab — From breach to scam, Poland (page /pl/laboratorium/od-wycieku-do-oszustwa/)Poland
  • CBZC (Centralne Biuro Zwalczania Cyberprzestępczości), 2025 report1,374 people charged (+30% year-on-year), 80 million PLN seized. Accessed 16/07/2026.
  • Polish police, "na legendę" data (January-April 2026)2,805 cases (+300 year-on-year), about 160 million PLN in 2025 losses. Accessed 16/07/2026.
  • Bank Pocztowy / SW Research, late 2025 (n=1,032)46% of surveyed seniors were contacted by scammers, 12% suffered a successful attempt. Accessed 16/07/2026.
The Threat Lab — From breach to scam, Portugal (page /pt/laboratorio/da-fuga-ao-golpe/)Portugal
  • GNR, Q1 2026 data and 2025 reviewAbout 300 "fake official" scams in Q1 2026 (1,092 across all of 2025 vs 974 in 2024); 75% success rate for bank impersonation, 86% for authority impersonation (GNR/PSP/PJ). Accessed 16/07/2026.
  • PGR, Gabinete Cibercrime, 2025695 phishing complaints and 303 for fraudulent calls in 2025. Accessed 16/07/2026.
  • DGPJ/GNR, 2020-2025Victims aged 65+ up 30.5% (33,850 → 44,161); 42,873 isolated elderly people flagged by the GNR in 2024. Accessed 16/07/2026.
The Threat Lab — From breach to scam, Turkey (page /tr/laboratuvar/sizintidan-dolandiriciliga/)Turkey
  • ŞikayetvarComplaints about the "lawsuit/enforcement SMS" scam: 75 in 2023, 855 in 2024, 8,798 in the first 9 months of 2025 (+929%). Accessed 16/07/2026.
  • TÜİK, 2025 victimization survey3.5% cybercrime victims, 2.8% consumer fraud (≈1.9 million people). Accessed 16/07/2026.
  • Turkish press (Sabah, Hürriyet, Takvim, Bursa Hakimiyet), July 2026Documented real case in Bursa: a couple in their 70s stripped of roughly 100 million TL over 2.5 months by a fake-police scam. Accessed 16/07/2026.
The Threat Lab — Krypto-Anlagebetrug, Germany (page /de/laboratoire/krypto-anlagebetrug/)Germany
  • TRM Labs, Wikipedia "$Libra cryptocurrency scandal" (Feb. 2025)Collapse of the $LIBRA token, market cap hit $4.5B in 40 minutes, ~$107M withdrawn by insiders before a ~85% crash. Accessed 16/07/2026.
  • Verbraucherzentrale, guide "So erkennen Sie unseriöse Online-Tradingplattformen"Mechanics of financial pig butchering (manipulated trading interface, test withdrawal, real withdrawal blocked). Accessed 16/07/2026.
  • BaFin, page "Betrug mit dem Namen der BaFin" + dated alerts ("Krypto Holdings Ltd." Dec. 2025, "Zentrum Krypto GmbH" Oct. 2025)Fake platforms impersonating the German financial supervisory authority. Accessed 16/07/2026.
  • Zentralstelle Cybercrime Bayern (ZCB), Bavarian Ministry of Justice press release (20/03/2024)370 cases / ~330 platforms / ~€29M in damages since 2021, average loss ~€80,000/victim. Accessed 16/07/2026.
  • BKA, press release 07/05/2025Takedown of crypto exchange service "eXch" (raid on 30/04/2025), €34M seized, ~$1.9B total volume, linked to laundering part of the Bybit hack. Accessed 16/07/2026.
The Threat Lab — Fraudes com criptomoedas, Brazil (page /pt-br/laboratorio/fraudes-com-criptomoedas/)Brazil
  • TRM Labs, "The $LIBRA Affair" (Feb. 2025); CoinDesk (April 2026)Collapse of the $LIBRA token (Argentina): market cap of $4.56B, ~$251M lost across ~114,000 wallets, $107M+ withdrawn by insiders. Accessed 16/07/2026.
  • FBI, "Cryptocurrency Investment Fraud" / Operation Level UpMechanics of financial pig butchering (rigged platform, test withdrawal, real withdrawal blocked). Accessed 16/07/2026.
  • CVM, Ato Declaratório nº 23.539 (June 2025); CVM/ANBIMA, educational simulation (May 2024)Suspension of Digital Smart LLC/BULLEX (330+ complaints on Reclame Aqui); fake-broker simulation: 104,000 unique visitors, 48% clicked investment links. Accessed 16/07/2026.
  • Polícia Federal, Operação Fantasos (April 2025)R$1.6B frozen, Trade Coin Club scheme, ~100,000 victims worldwide, suspect arrested in Switzerland (Douver Torres Braga). Accessed 16/07/2026.
مختبر التهديدات — Ihtiyal al'umlat al-raqamia, UAE (page /ar/mukhtabar-altahdidat/ihtiyal-alumlat-alraqamia/)United Arab Emirates
  • Chainalysis, 2026 Crypto Crime Report; crypto.news, CoinLawCollapse of the Mantra (OM) token, 13/04/2025: 43.6M tokens moved across 17 wallets, 94% drop, ~$5.52B in market value erased (still under investigation as a potential rug pull). Accessed 16/07/2026.
  • VARA, public warning (March 2025); SCA via Khaleej TimesUnauthorized entities impersonating the Dubai Land Department's real-estate tokenization pilot; recurring impersonation of licensed companies. Accessed 16/07/2026.
  • VARA (Oct. 2025); DOJ, joint Dubai Police/FBI/China press release (2025)19 unlicensed companies sanctioned, fines of AED 100,000 to 600,000 (~$27,000-163,000); joint operation: 276 arrests, 9 scam centers dismantled (Ko Thet Company, Sanduo Group, Giant Company), ~$562M in potential losses prevented (Finance Magnates). Accessed 16/07/2026.
The Threat Lab — Estafas de inversión en criptomonedas, Spain (page /es/laboratorio/estafas-inversion-criptomonedas/)Spain
  • Coincub, "Biggest Crypto Rug Pulls" (2025)~$6B in aggregated global losses in 2025; Mantra (OM) case, April 2025 collapse (drop >90%), rug-pull classification disputed by the project — treated with editorial caution. Accessed 16/07/2026.
  • Guardia Civil, press release — "Madeira Invest Club" operation€260M / 3,000+ victims, mechanism explicitly labeled "pig butchering" by the Guardia Civil itself. Accessed 16/07/2026.
  • CNMV, "Advertencias" list (unauthorized entities) via Pressdigital.es16 entities listed in Oct. 2025, then 12 and 24 Dec. 2025, 13 and 21 Feb. 2026; MiCA licensing requirement from 01/07/2026. Accessed 16/07/2026.
  • Ministerio del Interior — "Coinblack-Wendimine" operation€19M / 208 victims, AI-generated misleading ads. Accessed 16/07/2026.
  • Cross-border operation Spain/Portugal/Bulgaria/Romania, Sept. 2025€102,908,705 total, including €12.2M from Spanish victims. Accessed 16/07/2026.
The Threat Lab — Crypto investment scams, USA (page /en/laboratoire/crypto-investment-scams/)United States
  • Chainalysis, 2025 Crypto Crime ReportLosses tied to rug pulls: $5.06B (2021 peak) → $1.3M (2022) → $94.8M (2024). Accessed 16/07/2026.
  • DOJ, USAO Central District of California, indictment dated 20/12/2024 (case 2:24-cr-00756)9 fraudulent NFT projects ("Vault of Gems," "MoonPortal"), $22M+ misappropriated — the largest NFT scheme ever prosecuted by the DOJ. Accessed 16/07/2026.
  • FBI IC3, 2024 Internet Crime Report$5.8B in crypto investment fraud, the largest financial-cybercrime subcategory; Operation Level Up: 8,103 victims proactively contacted, $511.5M in losses prevented. Accessed 16/07/2026.
  • SEC, press release 2025-144 (22/12/2025); CFTC, investor alertMorocoin Tech Corp., Berge Blockchain Technology, Cirkor Inc. + 4 WhatsApp "investment clubs," $14M misappropriated via fake government licenses. Accessed 16/07/2026.
  • FBI IC3 ($9.3B total 2024, +66% year-on-year); FTC Data Spotlight, Sept. 2024$2.8B lost by investors aged 60+; median loss of $5,400 via Bitcoin ATMs (H1 2024). Accessed 16/07/2026.
The Threat Lab — Crypto investment fraud, France (page /laboratoire/fraude-investissement-crypto/)France
  • The Block, Cointelegraph, TRM Labs (February 2025)Collapse of the $LIBRA token (Argentina): peaked at $4.56 billion market cap, fell 94% in eleven hours, eight wallets withdrew ~$107 million. Accessed 16/07/2026.
  • FBI IC3, 2025 annual report; Chainalysis, Crypto Crime Report 2026Mechanics of financial "pig butchering" (rigged platform, test withdrawal, real withdrawal blocked). Accessed 16/07/2026.
  • Journal du Coin (2025)Phishing wave impersonating Coinbase support. Accessed 16/07/2026.
  • AMF (French financial markets authority), press release 22/04/202623 new names added to the blacklist of unauthorized crypto platforms since early 2026. Accessed 16/07/2026.
  • Cybermalveillance.gouv.fr, 2025 activity report (published 26/03/2026)+277% in "fake financial investment" reports from individuals. Accessed 16/07/2026.
  • Moneyvox (October 2025), AMF (blacklist, 22/09/2025)AccGn case: fake AI trading platform, ~125 victims, class complaint to the National Financial Prosecutor's Office (20/10/2025) over €18M+ in crypto flows. Accessed 16/07/2026.
The Threat Lab — Penipuan investasi kripto, Indonesia (page /id/laboratorium/penipuan-investasi-kripto/)Indonesia
  • Chainalysis 2025; Solidus Labs$2.8B in global rug-pull losses; 93% of Raydium liquidity pools showing rug-pull/pump-and-dump signatures. Accessed 16/07/2026.
  • DOJ EDNY — Aurelien Michel case, "Mutant Ape Planet" (judgment of 01/11/2024)$1.4M forfeited from a ~$2.9M scheme. Accessed 16/07/2026.
  • OJK / Satgas PASTI, 2025 press releases; Indodax, 2026 anti-phishing campaignFake "robot trading" platforms; 74 illegal offerings duplicating licensed entities (June 2025). Accessed 16/07/2026.
  • OJK (Dec. 2025); Satgas PASTI (cumulative to 31/05/2025)20.19M crypto users, Rp482.23T volume in 2025; 13,228 entities stopped since 2017, of which 1,811 were illegal investments. Accessed 16/07/2026.
  • Bareskrim Polri, via Detik.com (arrest of 22/03/2022)Fahrenheit case (PT FSP Akademi Pro), robot-trading Ponzi scheme, operator Hendry Susanto. Accessed 16/07/2026.
The Threat Lab — Truffe criptovalute, Italy (page /it/laboratorio/truffe-criptovalute/)Italy
  • Crypto press, April 2025; Chainalysis, 2026 Crypto Crime Report; Solidus Labs (Pump.fun analysis, Jan. 2024-March 2025)Collapse of the MANTRA (OM) token on 13/04/2025 (treated with editorial caution, not confirmed as a rug pull); 7M+ tokens launched on Pump.fun, 98.6% having lost all liquidity. Accessed 16/07/2026.
  • Polizia Postale / Polizia di Stato, official "Falso trading online" pageMechanics of financial pig butchering; Chainalysis: average scam payment rose from $782 to $2,764 (2024→2025). Accessed 16/07/2026.
  • CONSOB, action of 16/10/2025; precedent of 12/12/202417 sites blocked for using deepfakes of Italian political figures (Meloni, Salvini, Schlein, Calenda) promoting unauthorized crypto platforms. Accessed 16/07/2026.
  • CONSOB (direct consultation consob.it, 10/07/2026); Polizia Postale via MilanoFinanza219 crypto sites blocked out of 1,769 total; €116M lost via fake trading Jan-Aug 2025 (+15% year-on-year, 81% of fraud losses over the period). Accessed 16/07/2026.
脅威研究所 — 暗号資産詐欺, Japan (page /ja/kyoi-kenkyujo/angoshisan-sagi/)Japan
  • Chainalysis, 2025 Crypto Crime Report2024 rug-pull losses: ~$94.8M (2021 peak: ~$5.06B); 3.59% of tokens issued in 2024 (74,037) showing rug-pull behavior; Pump.fun: 98.6% of the 7M+ tokens deployed (Jan. 2024-March 2025) lost all liquidity. Accessed 16/07/2026.
  • NPA, SOS47 page on "SNS型投資詐欺" (social-media investment fraud)Mechanics: DM → discussion group → fake posted profits → fake trading app → "deposit/tax" demand blocking withdrawal. Accessed 16/07/2026.
  • bitFlyer, Coincheck (official phishing alerts); FSA, alert list (Nov. 2024)Unregistered crypto operators flagged: KuCoin, bitcastle LLC, Bybit Fintech Limited, MEXC Global, Bitget Limited. Accessed 16/07/2026.
  • NPA, confirmed report of 22/05/2026 (Reiwa 7)SNS-type investment fraud: ¥127.47B in 2025 losses (+46.3% year-on-year), 9,538 cases (+48.7%); combined average loss (investment + romance): ¥12.133M/case. Accessed 16/07/2026.
The Threat Lab — Rug pull & pertukaran kripto palsu, Malaysia (page /ms/makmal/rug-pull-pertukaran-kripto-palsu/)Malaysia
  • $HAWK memecoin (Dec. 2024); Chainalysis 2025 (Mantra/OM collapse)~$490M initial market cap, 90%+ drop within hours on insider selling. Accessed 16/07/2026.
  • Bukit Aman JSJK, public warnings 2024-2025Mechanics of financial pig butchering (rigged platform, test withdrawal). Accessed 16/07/2026.
  • SC Malaysia, Investor Alert List; The Block (Bybit case, halted operations late 2024)Cloned/unregistered platforms; Bybit suspended for failing to register as a DAX, removed from the list in April 2026 after coming into compliance. Accessed 16/07/2026.
  • Bukit Aman CCID via Malay Mail (Dec. 2025; 09/02/2025)RM1.37B in investment fraud (including crypto); UVKXE case: RM33M, 44 reports, one victim lost RM2.56M. Accessed 16/07/2026.
The Threat Lab — Fraude cripto y plataformas falsas, Mexico (page /es-mx/laboratorio/fraude-cripto-plataformas-falsas/)Mexico
  • Chainalysis, 2025 Crypto Crime Report$2,800M in global losses in 2025, 68% of crypto scams in Q1 2025; MetaYield Farm case ($290M, Feb. 2025). Accessed 16/07/2026.
  • Oktaris (Mexican digital forensics firm), Sept. 2025Documented "Cobe-Coins" case: 2,000 MXN deposit, fake balance shown of 2,800 USDT, then a demand for 3,800 MXN to "unlock" the withdrawal. Accessed 16/07/2026.
  • Bitso, help center (documented phishing campaigns); CNBV, Ley Fintech registryImpersonation of Bitso via fake contests; registration requirement for fintech institutions. Accessed 16/07/2026.
  • SSC Ciudad de México, Policía Cibernética, press release COM2691 (18/09/2025); CONDUSEF, guide "¿Piensas invertir en criptomonedas?"Alerts on fraudulent investment apps and how to verify CNBV registration. Accessed 16/07/2026.
The Threat Lab — Cryptofraude, Netherlands (page /nl/laboratorium/cryptofraude-rug-pull-nepplatform/)Netherlands
  • Chainalysis, 2025 Crypto Crime ReportGlobal rug-pull losses: $2.8B+ in 2025 (vs $94.8M in 2024); Thodex case (Turkey, founder fled with ~$2B, convicted in 2023). Accessed 16/07/2026.
  • FBI IC3, Cryptocurrency Investment Fraud alert; FinCEN, Pig Butchering Alert (2023)Mechanics of financial pig butchering (rigged platform, test withdrawal, real withdrawal blocked by a fake "fee/tax"). Accessed 16/07/2026.
  • AFM, public warning registry (named cases: axessinvest, 2bfx trading); press release 10/2025Platforms cloning the identity of licensed providers; fraud via discussion groups. Accessed 16/07/2026.
  • Fraudehelpdesk, "Terugblik 2025"; AFM, "De onzichtbare omvang van beleggingsfraude in Nederland"€29M in crypto losses Jan-Oct 2025 (vs €25M for all of 2024, +65% in victims); real damage estimated at €750M/year vs €75M recorded by police (2024). Accessed 16/07/2026.
  • Openbaar Ministerie Noord-Nederland, press release 09/12/2025Crypto fraud network in Groningen/Appingedam impersonating Bitvavo staff, €800,000+ seized. Accessed 16/07/2026.
The Threat Lab — Crypto investment scam, Philippines (page /fil/laboratoryo/crypto-investment-scam-pilipinas/)Philippines
  • Solidus Labs, "2025 Rug Pull Report"98.6% of the 7M+ Pump.fun tokens (Jan. 2024-March 2025) classified as rug pull/pump-and-dump; Mantra (OM) collapse (13/04/2025) presented with editorial caution (classification disputed by the project team). Accessed 16/07/2026.
  • PNP Anti-Cybercrime Group, bulletinMechanics of financial pig butchering (rigged dashboard, test withdrawal, real withdrawal blocked by endless fees). Accessed 16/07/2026.
  • SEC Philippines, public alert list (August 2025); SEC EIPD, Riscoin order (14/05/2026)10 unregistered platforms named; fraudulent Riscoin copy-trading case. Accessed 16/07/2026.
  • US Treasury OFAC, press release 29/05/2025; PNP-ACG (Gen. Nartatez)Sanction against Funnull Technology Inc. (Philippines-based infrastructure), $200M+ in losses to US victims; 311 investment-scam cases in 2025, of which 12 specifically crypto. Accessed 16/07/2026.
The Threat Lab — Oszustwa kryptowalutowe, Poland (page /pl/laboratorium/oszustwa-kryptowalutowe/)Poland
  • Galaxy Research (Feb. 2025); Solidus Labs, Rug Pull ReportLIBRA token (Argentina): ~$99M in liquidity withdrawn, $250M+ in investor losses; 98.6% of the 7M+ tokens launched on Pump.fun since 2024 show manipulation/rug-pull signatures. Accessed 16/07/2026.
  • ChainalysisAverage scam payment +253% year-on-year (2024→2025); global losses from crypto investment fraud: $3.96B (2023) → $5.8B (2024) → $7.2B+ (2025). Accessed 16/07/2026.
  • UOKiK, KNF (alert list), rp.pl, Telepolis.plKanga Exchange case: false claim of KNF authorization, UOKiK decision of Dec. 2024 (under appeal), Warsaw prosecutor's investigation. Accessed 16/07/2026.
  • CBZC (Policja), case summaries 2025-2026537M zł in cumulative losses (CBZC 2025 cases); 75M zł (Agricole Trade/Partner Groupe/Global Maxis network, 1,500+ victims); 60M zł (6-brand network); 3.5M zł (Poznań group, ~2,000 victims). Accessed 16/07/2026.
The Threat Lab — Burlas cripto e rug pull, Portugal (page /pt/laboratorio/burlas-cripto-rug-pull/)Portugal
  • Chainalysis, "The 2025 Crypto Crime Report"Rug-pull losses: $1.3M (2022) → $94.8M (2024), 3.59% of tokens launched in 2024 showing rug-pull behavior; Mantra (OM) case, April 2025, drop >90% in a single day (treated with editorial caution). Accessed 16/07/2026.
  • Público, 08/10/2025 — PJ investigation1,500 victims, ~4,000 fund-dissipation transactions, 8 bank accounts, ~€1.5M. Accessed 16/07/2026.
  • CMVM, alert list of 21/10/2025 ("EG Investment Group," "XUEX")Unauthorized entities; MiCA regulation in force from 01/07/2026 (Observador, 29/06/2026). Accessed 16/07/2026.
  • Linha Internet Segura 2025, via Público/RR (10/02/2026)60 crypto/investment cases out of 949 total reports, +39% year-on-year. Accessed 16/07/2026.
  • Transnational operation, Público/Observador (23-24/09/2025)Losses of Portuguese victims >€1M in a cross-border operation. Accessed 16/07/2026.
The Threat Lab — Kripto dolandırıcılığı, Turkey (page /tr/laboratuvar/kripto-dolandiriciligi/)Turkey
  • Euronews Türkçe (08/09/2023), Anadolu Ajansı, BloombergHT, Medyascope (01/11/2025)Collapse of the Thodex platform (April 2021): ~391,000 users affected, founder fled with an amount most often estimated at ~$2B by the Turkish press (estimates vary by source), sentenced in 2023 to over 11,000 years in prison + 26.615B TL in fines, found dead in prison in November 2025. Accessed 16/07/2026.
  • Anadolu Ajansı, court coverage (2025)"Oceans Enterprise Smart Trade Coin Go" case: 387 victims, ~$14,948,978 in total losses. Accessed 16/07/2026.
  • Legal compilations/user complaints (2025); SPK, Law No. 7518 (27/06/2024)Fake platform "Clodex" (shut down April 2025, citing "technical maintenance"); SPK licensing framework (BTCTurk, Paribu, Binance TR licensed). Accessed 16/07/2026.
  • We Are Social & Meltwater, Digital 2025 (July); SPK, bulletins 2024/56-2025/725.6% crypto ownership among internet users 16+ in Turkey, the highest rate in the world; 300+ unauthorized crypto service sites blocked by SPK action. Accessed 16/07/2026.

True Cost and Zen Mode, market by market

Germany — Der wahre Preis: Egidio's price vs. the damage of a Betrug (page /de/wahre-kosten/)Germany
  • Ministerium des Inneren, für Digitalisierung und Kommunen Baden-Württemberg — press release "Organisierte Kriminalität und Wirtschaftskriminalität im Jahr 2024"8,780 cases recorded in 2024 for "falscher Polizeibeamter, Enkeltrick und Schockanruf" (fake police officer, grandchild scam, shock call), total damage of €18.4 million — an average loss of about €2,100 per case. Accessed 13/07/2026.
  • Polizeipräsidium Nordhessen — press release via presseportal.de, 19/06/2026Documented real case: a retired woman in Korbach (Hesse) defrauded of €100,000 via a Russian-language shock call, on the pretext of a car accident involving a relative. Accessed 13/07/2026.

Rigor note: no confirmed monthly price exists for Egidio in the German market — no "Monatlich" line was therefore added to the pricing table. The BKA (Bundeslagebild Cybercrime 2024, PKS 2024) does not publish an isolated national average loss for this type of phone fraud; the Baden-Württemberg regional figure (total ÷ number of cases) was therefore used as the most solid official average available, mirroring the method used for the French page.

Germany — Zen-Modus: sleep and blue light (page /de/zen-modus/)Germany
  • National Sleep Foundation / American Academy of Sleep MedicineRecommendations on screen use before bedtime and the effect of nighttime notifications on sleep continuity — international source, kept as-is for this market. Accessed 13/07/2026.
  • Deutsche Hirnstiftung — press release of 03/05/2024Replaces the Inserm (French) source for this market: evening smartphone use, nighttime screen time, and melatonin secretion delayed by blue-light emission. Accessed 13/07/2026.
  • Robert Koch-Institut (RKI) — Themenblatt SchlafReplaces the Santé publique France source for this market: according to KiGGS Welle 2 (2014-2017), the share of German teenagers reaching recommended sleep duration has clearly declined ("deutlich gesunken") compared to the 2003-2006 reference survey. Accessed 13/07/2026.
Brazil — O custo real: preço da Egidio vs prejuízo de um golpe (page /pt-br/custo-real/)Brazil
  • Fórum Brasileiro de Segurança Pública, cited by Agência Senado (18/08/2025)Between July 2024 and June 2025, about 24 million Brazilians were victims of golpes via Pix or boletos, for estimated total damage of nearly R$29 billion — a calculated average of about R$1,208 per victim. Accessed 13/07/2026.
  • Polícia Federal — Operação Dumb Money, relayed by CNN Brasil (07/08/2025)Documented real case: takedown of a financial pyramid scheme in Curitiba (PR), with branches in São Paulo (SP) and Balneário Camboriú (SC), estimated damage over R$21 million. Accessed 13/07/2026.
  • FEBRABAN, via Finsiders Brasil (11/03/2025)Total banking-sector fraud damage over two years (2023-2024): R$10.1 billion, of which R$2.7 billion from Pix golpes alone (+43% year-on-year). Accessed 13/07/2026.

Rigor note: no confirmed monthly price exists for Egidio in the Brazilian market — no "Mensal" line was therefore added to the pricing table. The headline figure (≈R$1,208) is an average calculated directly from the two raw figures published by the Fórum Brasileiro de Segurança Pública (total damage ÷ number of victims); the Dumb Money case and the FEBRABAN total are presented separately, as a documented real case and a sectoral aggregate respectively, never conflated with a per-case average.

Brazil — Modo Zen: sono e luz azul (page /pt-br/modo-zen/)Brazil
  • National Sleep Foundation / American Academy of Sleep MedicineRecommendations on screen use before bedtime and the effect of nighttime notifications on sleep continuity — international source, kept as-is for this market. Accessed 13/07/2026.
  • Ministério da Saúde — Vigitel survey 2006-2024, relayed by Jornal da USP (27/02/2026)Replaces the Santé publique France source for this market: for the first time, the Vigitel survey included sleep data — 20% of Brazilian adults in state capitals sleep less than six hours a night. Accessed 13/07/2026.

Rigor note: no sufficiently solid, dated, and institutional Brazilian equivalent (Ministério da Saúde, Academia Brasileira do Sono) was found specifically on the effect of screen blue light on melatonin — available articles cited only US sources (Harvard Health) or no institution at all. This claim was therefore deliberately removed from the page rather than weakly or indirectly sourced.

Spain — El coste real: precio de Egidio vs perjuicio de una estafa (page /es/coste-real/)Spain
  • Kaspersky — study cited by que.es, moncloa.com and escudodigital.com (26/06/2026)Average loss per victim of digital scams in Spain: €577, with 7.5% of victims losing over €1,150. Accessed 13/07/2026.
  • Policía Nacional / Ministerio del Interior — joint operation COINBLACK-WENDIMINE (official press release, 07/04/2025)Documented real case: crypto-investment fraud network using AI-manipulated celebrity videos, 6 people arrested, 208 victims, total damage exceeding €19 million, Granada and Alicante. Accessed 13/07/2026.
  • Banco de España — joint ECB-EBA report on payment fraud (December 2025)Total detected payment fraud in Spain in 2024: about €318 million (transfers + cards), out of a total of €4.2B across the EEA. Accessed 13/07/2026.

Rigor note: no confirmed monthly price exists for Egidio in the Spanish market — no "Mensual" line was therefore added to the pricing table. The headline figure used (€577) comes from a Kaspersky study relayed by several dated, identified Spanish media outlets, presented as a survey-based average rather than an official police statistic; the COINBLACK-WENDIMINE case and the Banco de España total are presented separately, as a real case and an aggregate respectively, never conflated with a per-case average.

Spain — Modo Zen: sueño y luz azul (page /es/modo-zen/)Spain
  • National Sleep Foundation / American Academy of Sleep MedicineRecommendations on screen use before bedtime and the effect of nighttime notifications on sleep continuity — international source, kept as-is for this market. Accessed 13/07/2026.
  • Sociedad Española del Sueño — statements from the coordinator of the Grupo de Cronobiología (Dra. María José Martínez Madrid), reported by eldiario.es (15/10/2025)Replaces the Inserm (French) source for this market: blue light from screens activates the circadian system and delays melatonin secretion. Accessed 13/07/2026.

Rigor note: no sufficiently solid, dated, and sourced Spanish equivalent (Ministerio de Sanidad, Encuesta de Salud de España) was found specifically on the evolution of average sleep time in the population at the time of writing. This claim was therefore deliberately removed from the page rather than weakly or indirectly sourced.

True Cost — Egidio's price vs. the cost of a scam (page /en/true-cost/)United States
  • FBI Internet Crime Complaint Center (IC3) — Annual Report 2024$16.6 billion in total reported losses across 859,532 complaints in 2024 (+33% year-on-year); used to calculate an average loss of ≈$19,300 per complaint, across all fraud types. Accessed 13/07/2026.
  • FBI IC3 — Elder Fraud Report 2024$4.9 billion in reported losses across 147,127 complaints filed by victims aged 60 and over in 2024; average loss reported: $83,000. Accessed 13/07/2026.

Rigor note: the English-speaking market targeted by this page has no confirmed monthly price for Egidio — no "Monthly" line was therefore added to the pricing table, to avoid inventing a figure.

Zen Mode — sleep and blue light (page /en/zen-mode/)United States
  • National Sleep Foundation / American Academy of Sleep MedicineRecommendations on screen use before bedtime and the effect of nighttime notifications on sleep continuity — already a US source, kept as-is for this market. Accessed 13/07/2026.
  • CDC — NIOSH Work Hour Training for Nurses, "The Color of Light Affects Circadian Rhythms"Replaces the Inserm (French) source for this market: effects of evening blue light on melatonin secretion and circadian rhythms. Accessed 13/07/2026.
  • CDC — Sleep Facts and Stats (2024 National Health Interview Survey data)Replaces the Santé publique France (French) source for this market: about 30.5% of US adults sleep less than 7 hours per night on average in 2024. Accessed 13/07/2026.
The Real Cost — Egidio's price vs. the damage of a scam (page /le-vrai-cout/)France
  • Paris Prosecutor's Office cybercrime unit, Cybermalveillance.gouv.fr & MicrosoftJoint official press release (08/07/2025): 585 complaints for fake tech support in 2023, total damage of €374,000, i.e. an average loss of about €640 per case. Accessed 13/07/2026.
  • Gendarmerie nationale — GendinfoOfficial press release (July 2025): 4 victims of a fake bank advisor, Aubagne (13) area, total damage of €230,000. Accessed 13/07/2026.
  • Banque de France — Observatoire de la sécurité des moyens de paiement (OSMP)2024 annual report: total payment fraud in France stabilized just under €1.2B; manipulation-based fraud (a category including the fake bank advisor scam) accounts for 32% of the total. Accessed 13/07/2026.

Rigor note: we did not find an official, sourced, dated average loss specific to the fake-bank-advisor scam alone (available figures are either aggregated totals or individual cases). The Aubagne case is presented as a documented example, never as a statistical average.

Zen Mode — sleep and blue light (page /mode-zen/)France
  • National Sleep Foundation / American Academy of Sleep MedicineRecommendations on screen use before bedtime and the effect of nighttime notifications on sleep continuity. Accessed 13/07/2026.
  • Inserm — "Sleep" dossierEffects of evening blue light from screens on melatonin secretion and circadian rhythms. Accessed 13/07/2026.
  • Santé publique France — Baromètre de Santé publique FranceSuccessive surveys on the evolution of average sleep time among the French population. Accessed 13/07/2026.
Gulf / United Arab Emirates — التكلفة الحقيقية: Egidio's price vs. the damage of a scam (page /ar/al-taklifa-alhaqiqia/)Gulf
  • Global Anti-Scam Alliance (GASA) & BioCatch — "The State of Scams in the United Arab Emirates 2024" (published 28/11/2024)Survey of about 2,000 UAE residents: 27% report losing money in a scam, for an average loss of $2,194 per victim; over 40,000 residents affected during the year, for combined losses of several million dollars. Accessed 13/07/2026.
  • Chainalysis, relayed by Khaleej TimesCrypto-scam victims in the UAE: average loss of about $80,000 (≈AED 293,600) per victim in H1 2025 — the highest amount worldwide for that period. Accessed 13/07/2026.

Rigor note: no confirmed monthly price exists for Egidio in the Gulf market — no "شهري" line was therefore added to the pricing table. Prices ($29.99 / $59.99 / $89.99) are expressed in dollars, as on the site's Arabic homepage, given the Gulf market. No official police statistic (Dubai Police, Ministry of Interior) giving an average loss per case was found for this market at the time of writing; the headline figure used ($2,194) therefore comes from a GASA/BioCatch survey, presented as such.

Gulf / United Arab Emirates — وضع الهدوء: sleep and blue light (page /ar/wad-alzen/)Gulf
  • National Sleep Foundation / American Academy of Sleep MedicineRecommendations on screen use before bedtime and the effect of nighttime notifications on sleep continuity — international source, kept as-is for this market. Accessed 13/07/2026.
  • Cureus (peer-reviewed journal) — study conducted at Imam Mohammad Ibn Saud Islamic University, Riyadh, Saudi Arabia (published 09/09/2025)Replaces the Inserm (French) source for this market: among 102 Saudi university students, screen exposure one hour or more before bedtime is associated with poorer sleep quality; the documented mechanism is melatonin-secretion suppression by blue light from LED screens. Accessed 13/07/2026.

Rigor note: no sufficiently solid, dated, and sourced regional equivalent was found on the evolution of average sleep time in the Gulf (equivalent of the Santé publique France barometer) at the time of writing. This claim was therefore deliberately removed from the page rather than weakly or indirectly sourced.

Indonesia — biaya sebenarnya: Egidio's price vs. the damage of a scam (page /id/biaya-sebenarnya/)Indonesia
  • OJK Jember — Aris Budiman (Head of OJK Jember), media briefing 18/06/2026Average loss per online-purchase-fraud victim: about Rp17,000,000, calculated from Indonesia Anti Scam Center (IASC) data — total damage of Rp1.3 trillion (≈77,000 reports). Accessed 13/07/2026.
  • Bareskrim Polri — Directorate of Special Economic Crimes, press release 16/08/2023Documented real case: "robot trading" investment scheme Net89, total damage of Rp402,527,617,240 (≈Rp402.5 billion), 2,388 victims across 10 filed complaints. Accessed 13/07/2026.
  • OJK — Friderica Widyasari Dewi (Commissioner for Consumer Education and Protection), published 16/06/2026Total cumulative damage from online scams reported to OJK/IASC: Rp9.1 trillion (as of 14/01/2026), roughly 1,000 reports per day. Accessed 13/07/2026.

Rigor note: no official monthly price for Egidio exists in the Indonesian market to date — this line was omitted rather than invented. Rupiah amounts (billions/trillions) follow the short scale used by the Indonesian press (1 triliun = 1,000 miliar).

Indonesia — zen mode: sleep and blue light (page /id/mode-zen/)Indonesia
  • National Sleep Foundation / American Academy of Sleep MedicineRecommendations on screen use before bedtime, the effect of nighttime notifications on sleep continuity, and the effect of blue light on melatonin secretion — same sources as the FR page /mode-zen/. Accessed 13/07/2026.

Rigor note: no Indonesian equivalent of Inserm / Santé publique France (Kementerian Kesehatan RI, Perhimpunan Dokter Spesialis Kedokteran Tidur Indonesia) could be found with a sourced, dated figure specific to blue light or sleep debt — research conducted 13/07/2026, content removed rather than weakly approximated.

Italy — Il vero costo: prezzo di Egidio vs danno di una truffa (page /it/vero-costo/)Italy
  • CRIF · Mister Credit — Osservatorio Frodi Creditizie 2024Report published 02/07/2025: nearly 31,000 credit-fraud cases in Italy in 2024, total damage of about €150 million, average amount over €4,800 per case (+3.2% year-on-year). Accessed 13/07/2026.
  • Polizia Postale e delle Comunicazioni — report of 14/05/202518,967 online scams + 8,602 computer fraud cases in 2024 (27,569 cases), total economic damage of €232 million; €81.6 million taken in Q1 2025, vs €57.5 million in the same period in 2024. Accessed 13/07/2026.

Rigor note: the Italian market has no confirmed monthly price for Egidio — no "Mensile" line was therefore added to the pricing table, to avoid inventing a figure. The €4,800 average retained as the headline figure comes from credit fraud (CRIF), the closest available category to an official, recurring average for Italy; the Polizia Postale figures are presented as aggregated totals, not as an average per case.

Italy — Modalità Zen: sonno e luce blu (page /it/modalita-zen/)Italy
  • National Sleep Foundation / American Academy of Sleep MedicineRecommendations on screen use before bedtime and the effect of nighttime notifications on sleep continuity — international source, kept as-is for this market. Accessed 13/07/2026.

Rigor note: no sufficiently solid, dated, and sourced Italian equivalent (Istituto Superiore di Sanità, Associazione Italiana di Medicina del Sonno) was found specifically on screen blue light or sleep debt at the time of writing. These claims were therefore deliberately removed from the page rather than weakly or indirectly sourced.

Japan — 本当のコスト: Egidio's price vs. the damage of a scam (page /ja/hontou-no-kosuto/)Japan
  • National Police Agency (警察庁) — "令和7年における特殊詐欺及びSNS型投資・ロマンス詐欺の認知・検挙状況等について(確定値)"Confirmed official 2025 statistics: 27,832 cases recorded (+32.3% year-on-year), total damage of ¥142.31 billion (+98.0%), an average loss of ¥5,236,000 per completed case — the highest figure ever recorded. Also includes the "fake police" subcategory (ニセ警察官詐欺): 11,014 cases, ¥100.5 billion, sharply rising. Accessed 13/07/2026.
  • nippon.com — "2025年の特殊詐欺:全国で被害1400億円 前年から倍増、ニセ警察詐欺が顕著"Article published 03/06/2026, reporting and detailing the official 警察庁 statistics cited above. Accessed 13/07/2026.

Rigor note: unlike other markets, Japan has a confirmed monthly price for Egidio (¥1,000) — this line was therefore included in the pricing table, the only language to have it. The headline figure (¥5,236,000) is an official average per completed case, not an isolated extreme case; the other two figures cited (aggregate total, fake-police subcategory) come from the same official publication and are never presented as per-case averages.

Japan — 禅モード: sleep and blue light (page /ja/zen-mode/)Japan
  • National Sleep Foundation / American Academy of Sleep MedicineRecommendations on screen use before bedtime and the effect of nighttime notifications on sleep continuity — international source, kept as-is for this market. Accessed 13/07/2026.
  • 厚生労働省 (Ministry of Health, Labour and Welfare) — "健康づくりのための睡眠指針"Official recommendation to avoid screens 1 to 2 hours before bedtime, since blue light delays melatonin secretion — replaces the Inserm source for this market. Accessed 13/07/2026.
  • OECD — "Time Use" survey 2021, relayed by nippon.com ("Shut-Eye Deficit: OECD Survey Reveals Japan Most Lacking in Sleep")Replaces the Santé publique France source for this market: Japan ranks last among 30 OECD member countries with an average sleep time of 7h22, against a global average of 8h24. Accessed 13/07/2026.
Malaysia — Kos sebenar: harga Egidio vs kerugian sebuah penipuan (page /ms/kos-sebenar/)Malaysia
  • Jabatan Siasatan Jenayah Komersial (CCID), Polis Diraja Malaysia (PDRM) — relayed by World of Buzz (21/12/2025)28,698 telecommunication scam cases (calls & SMS) recorded between January and November 2025, for total damage of RM715.7 million — a calculated average of about RM24,900 per case. Accessed 13/07/2026.
  • Malay Mail (1 September 2025)Documented real case: an office worker in Penang lost RM601,850 in a phone scam where fraudsters posed as police officers, via 14 transfers between 14 and 28 August 2025. Accessed 13/07/2026.
  • Bank Negara Malaysia — Laporan Tahunan 2025, relayed by Fintech News Malaysia (31/03/2026)Total scam losses in Malaysia in 2025: RM2.8 billion (all types combined), including RM1.37 billion for fake investment opportunities and RM715.7 million for telecommunication scams. Accessed 13/07/2026.

Rigor note: no confirmed monthly price exists for Egidio in the Malaysian market — no "Bulanan" line was therefore added to the pricing table. The headline figure (≈RM24,900) is an average calculated directly from the two raw figures published by the CCID/PDRM (total damage ÷ number of cases), restricted to phone and SMS scams — the most relevant category for Egidio. The Penang case and the national BNM aggregate are presented separately, as a documented real case and a sectoral total respectively, never conflated with a per-case average.

Malaysia — Mod Zen: tidur dan cahaya biru (page /ms/mod-zen/)Malaysia
  • National Sleep Foundation / American Academy of Sleep MedicineRecommendations on screen use before bedtime and the effect of nighttime notifications on sleep continuity — international source, kept as-is for this market. Accessed 13/07/2026.
  • Kementerian Kesihatan Malaysia / Institut Kesihatan Umum — National Health and Morbidity Survey (NHMS) 2023Replaces the Santé publique France source for this market: 38% of Malaysian adults do not sleep enough, with an average sleep duration of about 6h18 per night, below the recommended 7 hours. Accessed 13/07/2026.

Rigor note: no sufficiently solid, dated, and institutional Malaysian equivalent (Kementerian Kesihatan Malaysia, Malaysian Sleep Society / Sleep Disorder Society Malaysia) was found specifically on the effect of screen blue light on melatonin — available sources cited only generic international studies or non-institutional professional opinions. This claim (Inserm equivalent) was therefore deliberately removed from the page rather than weakly or indirectly sourced.

Mexico — El costo real: precio de Egidio vs perjuicio de un fraude (page /es-mx/costo-real/)Mexico
  • "Brújula 2026" study — Tala in collaboration with Condusef, cited by El Economista (24/02/2026)Survey of over 3,000 people across Mexico's 32 states: documented average loss of 8,750 pesos per digital-fraud victim (fintech impersonation, malicious links, cloned pages). Accessed 13/07/2026.
  • Condusef (Buró de Entidades Financieras), CNBV data — relayed by El Informador (06/07/2026)1,515,000 bank-fraud complaints in Q1 2026 (+31.5% year-on-year), 5,201 million pesos claimed, of which only 24.3% reimbursed by banks. Accessed 13/07/2026.

Rigor note: no confirmed monthly price exists for Egidio in the Mexican market — no "Mensual" line was therefore added to the pricing table, to avoid inventing a figure. No sufficiently documented, dated official case (Mexican police/prosecutor) was found to serve as a concrete example comparable to the Aubagne (FR) case; only aggregated figures and a survey average were therefore used.

Mexico — Modo Zen: sueño y luz azul (page /es-mx/modo-zen/)Mexico
  • National Sleep Foundation / American Academy of Sleep MedicineRecommendations on screen use before bedtime and the effect of nighttime notifications on sleep continuity — international source, kept as-is for this market. Accessed 13/07/2026.
  • UNAM — Instituto de Fisiología Celular, Dr. Raúl Aguilar Roblero, via Fundación UNAM ("Dispositivos que roban el sueño")Replaces the Inserm (French) source for this market: light from mobile screens delays melatonin secretion and causes hyperexcitation that harms falling asleep. Accessed 13/07/2026.
  • ISSSTE — official press release (15/03/2024)Replaces the Santé publique France source for this market: nighttime use of screens, phones, and television increases the risk of sleep disorders; the release notes that one in five people in Mexico suffers from insomnia. Accessed 13/07/2026.
Netherlands — De echte kosten: Egidio's price vs. schade van oplichting (page /nl/echte-kosten/)Netherlands
  • Fraudehelpdesk — "Persbericht: Druk van oplichters op samenleving was nog nooit zo groot" (Terugblik 2025, published February 2026)Official 2025 figures: 15,116 financieel gedupeerden (financial victims) for €68,492,848 in declared damage via the call center — a calculated average of about €4,531 per victim, across all scam types. Accessed 13/07/2026.
  • Nederlandse Vereniging van Banken (NVB), relayed by NOS.nl (28/04/2025)Bankhelpdeskfraude (fake bank advisor): nearly €26 million in total damage in 2024, about 5,900 customers affected. Accessed 13/07/2026.
  • CBS (Centraal Bureau voor de Statistiek) — "Schade van criminaliteit tegen burgers," 2024 report, Spoofing chapterTotal estimated spoofing damage in 2023: about €318 million, roughly 10% of total damage from crime against citizens; 107,000 victims recorded. Accessed 13/07/2026.

Rigor note: no confirmed monthly price exists for Egidio in the Dutch market — no "Maandelijks" line was therefore added to the pricing table. The headline figure (€4,531) is an official average across all categories, calculated directly from the two raw figures published by the Fraudehelpdesk (total divided by number of victims) — no isolated official average was found for a single scam category (such as fake tech support in France), as no solid, dated source provided one for the Netherlands.

Netherlands — Zen-modus: slaap en blauw licht (page /nl/zen-modus/)Netherlands
  • National Sleep Foundation / American Academy of Sleep MedicineRecommendations on screen use before bedtime and the effect of nighttime notifications on sleep continuity — international source, kept as-is for this market. Accessed 13/07/2026.
  • RIVM (Rijksinstituut voor Volksgezondheid en Milieu) — "Schermgebruik, blauw licht en slaap" (2019 report)Replaces the Inserm (French) source for this market: evening blue light from screens influences the biological clock and can disrupt sleep, an effect documented especially in children and teenagers who use screens daily before bedtime. Accessed 13/07/2026.
  • Volksgezondheid en Zorg (VZinfo.nl, RIVM-linked portal), based on CBS-Gezondheidenquête dataReplaces the Santé publique France source for this market: more than one in four Dutch people aged 12 and over report sleep problems, a proportion that has risen significantly between 2017 and 2024 across all population groups. Accessed 13/07/2026.
Philippines — Tunay na Halaga: presyo ng Egidio vs pinsala ng scam (page /fil/tunay-na-halaga/)Philippines
  • Global Anti-Scam Alliance (GASA), in partnership with Mastercard and Whoscall — "State of Scams in the Philippines 2025" report (published 25/11/2025)31% of respondents who reported a financial loss lost an average of ₱11,896.30 per victim, over the period February 2024 – February 2025; total estimated loss of ₱280.5 billion over 12 months across the Philippines. Accessed 13/07/2026.
  • Bangko Sentral ng Pilipinas (BSP), data relayed by business.inquirer.net ("Human-focused scams lead PH fraud losses in 2025")₱409 million in losses from account-takeover fraud in the Philippines in 2024. Accessed 13/07/2026.

Rigor note: no confirmed monthly price exists for Egidio in the Philippine market — no "Buwanan" line was therefore added to the pricing table. The headline figure (₱11,896) is the official average published by the GASA/Mastercard/Whoscall report, the most solid and recent source identified for this market.

Philippines — Zen Mode: tulog at blue light (page /fil/zen-mode/)Philippines
  • National Sleep Foundation / American Academy of Sleep MedicineRecommendations on screen use before bedtime and the effect of nighttime notifications on sleep continuity — international source, kept as-is for this market. Accessed 13/07/2026.
  • Milieu Insight (2023 data), relayed by GMA News Online — "Filipinos are the most sleep-deprived in Southeast Asia — study" (31/07/2024)Replaces the Santé publique France source for this market: 56% of Filipinos sleep less than seven hours a night; the Philippines ranks first in Southeast Asia for sleep deprivation. Accessed 13/07/2026.

Rigor note: no solid, dated Philippine source was found specifically on the blue light/melatonin link (Inserm equivalent) — this paragraph was therefore deliberately removed from the /fil/zen-mode/ page, per the site's editorial rule.

Prawdziwy koszt PL — Egidio's price vs. the damage of a scam in Poland (page /pl/prawdziwy-koszt/)Poland
  • Komenda Główna Policji, cited by PAP (pap.pl)2024 annual crime report: 3,825 scams affecting 4,183 victims, total damage of 156,418,154 zł in 2024 (vs 139,591,396 zł in 2023). Accessed 13/07/2026.
  • portalsamorzadowy.pl, citing Polish police dataArticle of 24/05/2026: documented case in Białystok (over 100,000 zł scammed from three seniors, attempted theft of an additional 80,000 zł from a fourth victim); national total of "na legendę" scams in 2025 estimated at nearly 160 million zł. Accessed 13/07/2026.

Rigor note: the average of 37,400 zł per victim is calculated from official 2024 totals (156,418,154 zł ÷ 4,183 victims); no separate official average was found for the "legend scam" category alone (fake police officer, fake grandchild).

Tryb Zen PL — sleep (page /pl/tryb-zen/)Poland
  • National Sleep Foundation / American Academy of Sleep MedicineRecommendations on screen use before bedtime and the effect of nighttime notifications on sleep continuity (source already cited on the FR page /mode-zen/). Accessed 13/07/2026.

Rigor note: we searched for a credible Polish equivalent to Inserm / Santé publique France (Instytut Medycyny Pracy, Polskie Towarzystwo Badań nad Snem, CBOS) on blue light and sleep debt, but found no dated, verifiable primary source at the time of writing. These claims were therefore removed from the Polish page rather than weakly sourced.

Portugal — O custo real: preço da Egidio vs prejuízo de um golpe (page /pt/custo-real/)Portugal
  • Público — "Pelo menos 11 idosos lesados em mais de 60 mil euros em esquema de 'falso acidente'" (25/07/2025)Case documented by the PSP: at least 11 elderly victims for total damage exceeding €60,000, i.e. an average of at least ≈€5,455 per victim. Accessed 13/07/2026.
  • CNN Portugal / Jornal i — "Falso bancário detido por burlar idosos em quase 164 mil euros" (03/02/2025)Documented individual case: a man arrested by the PSP in Lisbon for defrauding elderly people while posing as a bank employee, total damage of €163,912.40. Accessed 13/07/2026.
  • Banco de Portugal — Relatório dos Sistemas de Pagamentos 2025Total losses from card and transfer fraud in Portugal: €5.3M in H1 2025, down 40.4% from €8.9M in H1 2024. Accessed 13/07/2026.

Rigor note: no confirmed monthly price exists for Egidio in the Portuguese market — no "Mensal" line was therefore added to the pricing table. We found no single official, sourced, dated average loss covering all scam types in Portugal; the average figure used (≈€5,455) comes from a collective case documented by the press based on a police source (PSP), not from an aggregated national statistic.

Portugal — Modo Zen: sono e luz azul (page /pt/modo-zen/)Portugal
  • National Sleep Foundation / American Academy of Sleep MedicineRecommendations on screen use before bedtime and the effect of nighttime notifications on sleep continuity — international source, kept as-is for this market. Accessed 13/07/2026.
  • Associação Portuguesa do Sono (APS) — "Como posso manter um sono saudável?"Official Portuguese recommendation to avoid screens for at least an hour before bedtime, due to blue light suppressing melatonin secretion. Replaces the Inserm (French) source for this market. Accessed 13/07/2026.

Rigor note: no sufficiently solid, dated, and sourced Portuguese equivalent (Direção-Geral da Saúde) was found specifically on the evolution of average sleep time in the population — only an isolated statistic on teenagers (Direção-Geral de Educação) was identified, deemed too narrow to generalize. This claim was therefore deliberately removed from the page rather than weakly or indirectly sourced.

Turkey — Gerçek maliyet: Egidio's price vs. the damage of a scam (page /tr/gercek-maliyet/)Turkey
  • İçişleri Bakanlığı — announcement of the DOLUNAY project (18/05/2026)156,068 fraud cases (72.6% of the 214,847 property-crime cases reviewed), for estimated economic damage exceeding 50 billion TL within the Gendarmerie's (Jandarma) scope alone — an average of about 320,000 TL per case. Accessed 13/07/2026.
  • Bursa İl Emniyet Müdürlüğü (Dolandırıcılık Büro Amirliği), under the Mudanya prosecutor's coordination — relayed by Sabah (02/07/2026)Documented real case: an elderly couple defrauded by a fake police network, total damage of about 100 million TL (currency and jewelry, card spending, sale of a property well below its value). Accessed 13/07/2026.

Rigor note: since no official monthly price was confirmed for the Turkish market at the time of writing, this line was deliberately omitted from the page (only Annual, Family, and Lifetime tiers are shown).

Turkey — Zen Modu: sleep and blue light (page /tr/zen-modu/)Turkey
  • National Sleep Foundation / American Academy of Sleep MedicineRecommendations on screen use before bedtime and the effect of nighttime notifications on sleep continuity — international source, kept as-is for this market. Accessed 13/07/2026.
  • Türk Uyku Tıbbı Derneği — Prof. Dr. Zeynep Zeren Uçar (president), relayed by Anadolu Ajansı (AA), World Sleep Day 2026 (13/03/2026)Evening screen blue light reduces melatonin secretion by about 50% — replaces the Inserm source for this market. Accessed 13/07/2026.

Rigor note: no solid, dated official Turkish data on the evolution of average sleep time (equivalent of the Santé publique France barometer) was found — this claim was therefore deliberately omitted from the Turkish page.

Diaspora and professional life

Sandwich Generation, family emergency scams — sources (pages /en/sandwich-generation/, /en/hi-mum-scam/, /en/protect-without-spying/)
  • Pew Research Center — The Sandwich GenerationMore than half of US adults aged 40-49 have a living parent 65+ and a dependent or financially-supported child. Survey October 2021. Accessed 19/07/2026.
  • UK Office for National Statistics — Sandwich carers, UKAn estimated 1.4 million people aged 16-64 in the UK are "sandwich carers," caring for both a dependent child and an older or disabled relative. Accessed 19/07/2026.
  • U.S. Census Bureau — Families and Living ArrangementsRoughly 10 million single-parent families with children under 18 in the US; nearly two-thirds headed by a single mother. Accessed 19/07/2026.
  • Australian Competition & Consumer Commission (ACCC) — "Hi Mum" scam alertOver 11,000 Australians caught by the "Hi Mum" scam at its 2022 peak, AU$7.2 million lost. Accessed 19/07/2026.
  • Santander UK — press statement on WhatsApp family scams506 "Hi Mum/Dad" scam cases and £490,606 lost since the start of 2025, reported via Santander UK. Accessed 19/07/2026.
  • FBI — Internet Crime Complaint Center (IC3) 2025 Annual Report / The Grandparent ScamAmericans aged 60+ reported $7.7 billion in fraud losses in 2025; description of the grandparent scam mechanism and rising use of AI voice cloning. Accessed 19/07/2026.
  • Canadian Anti-Fraud Centre (CAFC) — Emergency scamOver $23 million lost to the emergency/grandparent scam in Canada, per CAFC reporting data. Accessed 19/07/2026.
  • Government of India (Press Information Bureau) — Digital Arrest ScamAn estimated ₹2,140 crore lost to digital arrest scams in the first 10 months of 2024 (January-October); reported cases nearly tripled 2022-2024. Accessed 19/07/2026.
  • KnowBe4 — Africa scam reportFamily/friend impersonation scams estimated at 18% of scams across surveyed African countries (8-country survey, 2023). Accessed 19/07/2026.
  • Truecaller — Nigeria spam call rankingNigeria ranked Africa's most-spammed country, with 51% of unknown calls flagged as unwanted. Distinct source from the KnowBe4 impersonation figure above. Accessed 19/07/2026.
Diaspora inserts (pages /le-vrai-cout/, /es/coste-real/, /fil/tunay-na-halaga/)
  • SeneNews / Orishas Finance (2025)Scam tried in France: fake West African real-estate investment tontine targeting the diaspora, 97 mostly Senegalese victims, Val-d'Oise, total damage of €1.268 million (≈831 million FCFA). No individual named on our pages, per the site's editorial rule. Accessed 13/07/2026.
  • Infobae — "El negocio (y el riesgo) de las remesas desde España" (17/02/2025)Latin American households relying on remesas spend about 20% of monthly income on them (food, medicine); documented description of fake "comisionistas" operating via Instagram/WhatsApp from Spain. Accessed 13/07/2026.
  • Banco Interamericano de Desarrollo (BID)Official study on remesas sent by Latin American emigrants living in Spain back to their countries of origin. Accessed 13/07/2026.
  • Department of Migrant Workers (Philippines) / Philippine Statistics Authority — relayed by BusinessMirror and Gulf News (2026)$6.48 billion in remittances sent by OFWs from the Middle East to the Philippines in 2025; official alerts on fake "travel assistance" and fake job offers targeting OFWs. Accessed 13/07/2026.
The Diaspora Connection — 16 corridor pages by language

Each page covers a specific migration corridor (country of residence → country of origin), with its own sourced statistics and scam typologies — never a translation from one page to another. Doctrine: the diaspora is always the protected victim, never the subject; no ethnic generalization about perpetrators.

France — Scams targeting the diaspora (page /arnaques-diaspora/)

  • World Bank, cited by Africa24 (2025)Over $50 billion transferred each year by diasporas to sub-Saharan Africa. Accessed 13/07/2026.
  • Jeune Afrique, World Bank data (2025)$3.69 billion transferred to Senegal in 2024; France is the top sending country for this corridor. Accessed 13/07/2026.
  • Afrique sur 7 (2025)840 billion FCFA sent to Côte d'Ivoire in 2024, up over 540% in 15 years; about $1.1 billion received by Mali over the same period. Accessed 13/07/2026.
  • SeneNews / Orishas Finance (2025)Real case: fake real-estate investment tontine, 97 mostly Senegalese victims, Val-d'Oise, €1.268M. Accessed 13/07/2026.

United States / English-speaking — Diaspora Scams (page /en/diaspora-scams/)

  • World Bank Blogs, Migration and Development Brief (2024)$68 billion in remittances to Mexico. Accessed 13/07/2026.
  • World Bank, cited by Business Standard (Dec. 2024)$129 billion in remittances to India, the world's top recipient. Accessed 13/07/2026.
  • FTC, Consumer Sentinel Network Data Book (2024)$789 million lost, 265,272 reports of government-official impersonation. Accessed 13/07/2026.
  • USCIS.gov, official "Avoid Scams" page; GOV.UK, "Fraud, tricks and scams"; Action Fraud UK, "Hi Mum/Dad" alertOfficial prevention pages cited for administrative-impersonation and WhatsApp family-emergency typologies. Accessed 13/07/2026.
  • FBI, official "Virtual Kidnapping" pages and FBI El Paso; US Department of Justice (EDNY), press release (Feb. 2026)Real case: network dismantled in the New York area, fake immigration law firm, fake video hearings with impersonated judges/officials. Accessed 13/07/2026.

Spain — Estafas dirigidas a la diáspora (page /es/estafas-diaspora/)

  • Infobae (17/02/2025)€10,700 million in remesas sent from Spain to Latin America in 2023 (record, +75% in 10 years). Accessed 13/07/2026.
  • Banco Interamericano de Desarrollo (BID)Official study on remesas from Latin American emigrants living in Spain. Accessed 13/07/2026.
  • International Organization for Migration (IOM)"El corredor de remesas Sur-Sur Argentina-Bolivia" — $301 million sent from Argentina to Bolivia. Accessed 13/07/2026.
  • Ministerio del Interior / Policía Nacional, official press release (May 2026)Real case: Vizcaya/Guipúzcoa operation, 19 arrests, 118 forged documents, 42 fraudulently obtained residence permits. Accessed 13/07/2026.

Mexico — Estafas a paisanos (page /es-mx/estafas-paisanos/)

  • Banco de México, official figure cited by El Financiero (04/02/2025)Official Mexico remesas statistic. Accessed 13/07/2026.
  • World Bank / KNOMAD, cited by El Financiero (2025)$68 billion, US-Mexico corridor. Accessed 13/07/2026.
  • Fiscalía del Estado de Jalisco, figure reported by Récord (14/10/2025)Real "secuestro virtual" case (fake kidnapping targeting families in Mexico). Accessed 13/07/2026.
  • FBI.gov, "U.S. Citizens Threatened by Mexican Virtual Kidnapping Schemes"Official alert on the secuestro virtual mechanism. Accessed 13/07/2026.

Brazil — Golpes contra brasileiros no exterior (page /pt-br/golpes-diaspora/)

  • Ministério das Relações Exteriores (Itamaraty), Comunidades Brasileiras no ExteriorOfficial statistics on the Brazilian diaspora (Portugal, US, Japan). Accessed 13/07/2026.
  • Observatório da Emigração, 2024 dataData on Brazilian communities in Portugal. Accessed 13/07/2026.
  • Official Japanese data (June 2024); Japanese Embassy in Brazil, official alert (November 2024)Dekasegi community (Brazilians of Japanese descent working in Japan) and alerts on golpes targeting this community. Accessed 13/07/2026.

Portugal — Burlas contra emigrantes (page /pt/burlas-diaspora/)

  • Observatório da Emigração / Banco de Portugal, cited by ECO (23/02/2026)Official transfer statistics of the Portuguese diaspora (France, Switzerland, Luxembourg). Accessed 13/07/2026.
  • Observatório da Emigração, "Emigração Portuguesa 2025"Size and distribution of the Portuguese diaspora. Accessed 13/07/2026.
  • Polícia Judiciária, official press release (2026)Real documented case affecting Portuguese emigrants. Accessed 13/07/2026.

Poland — Oszustwa wymierzone w Polonię (page /pl/oszustwa-polonia/)

  • House of Commons Library / ONS data (2024)Size of the Polish community in the United Kingdom (~700,000 people). Accessed 13/07/2026.
  • Narodowy Bank Polski, quarterly data (2025)Official przekazy pieniężne transfer statistics. Accessed 13/07/2026.
  • Centralne Biuro Śledcze Policji (CBŚP), international-operation press release; policja.plReal case: international operation against a scam network targeting the Polonia. Accessed 13/07/2026.

Turkey — Gurbetçi dolandırıcılığı (page /tr/gurbetci-dolandiriciligi/)

  • Almanya Federal İstatistik Ofisi (Destatis), 2024 dataSize of the Turkish community in Germany (~3 million). Accessed 13/07/2026.
  • World Bank, balance-of-payments data (2024)Transfer statistics to Turkey. Accessed 13/07/2026.
  • Yenişafak / Hürriyet, Istanbul police operation (2026); Berliner Kurier / Landeskriminalamt Niedersachsen, "Warnung vor falschen Polizisten"Real cases and official German alerts on fake Turkish police/prosecutors calling from Turkey. Accessed 13/07/2026.

Gulf / Arab world — احتيال يستهدف المغتربين (page /ar/ihtiyal-almughtaribin/)

  • Central Bank of Egypt (CBE), official press release (January 2025)Official remittance statistics to Egypt. Accessed 13/07/2026.
  • GASA & BioCatch, "State of Scams in the UAE" (28/11/2024)Already cited on /ar/al-taklifa-alhaqiqia/, reused for this corridor. Accessed 13/07/2026.
  • Gulf News; Dubai Police, repeated official alertsImpersonation of immigration officials, fake job offers, and fake work-visa deposits. Accessed 13/07/2026.

Note: in line with the Arab/Gulf market editorial rule, Truecaller is never cited on this page (banned in the UAE).

Indonesia — Penipuan terhadap PMI (page /id/penipuan-pmi/)

  • Bank Indonesia, cited by Infobanknews (2025)Official remittance statistics for Indonesian migrant workers. Accessed 13/07/2026.
  • BP2MI / KP2MI, placement and protection statistics (2024)Official state agency for PMI (Pekerja Migran Indonesia). Accessed 13/07/2026.
  • Naker.news (2025), based on KJRI Penang assistanceReal case documented with the Indonesian consulate in Penang (Malaysia). Accessed 13/07/2026.

Malaysia — Penipuan terhadap rakyat Malaysia di luar negara (page /ms/penipuan-diaspora/)

  • Singapore Census 2020, Jabatan Perangkaan (Department of Statistics)Size of the Malaysian community in Singapore (~1.1 million). Accessed 13/07/2026.
  • World Bank / KNOMAD, migration & remittances report (2024)Transfer statistics. Accessed 13/07/2026.
  • Jabatan Siasatan Jenayah Komersial (CCID), PDRM (21/12/2025); Singapore Police Force (SPF), official press release (24/01/2025)Documented joint operation against cross-border Macau Scam. Accessed 13/07/2026.

Japan — 海外在住邦人を狙う詐欺 (page /ja/kaigai-zaiju-sagi/)

  • 外務省 (MOFA) "海外在留邦人数調査統計" Reiwa 6 (2024) editionOfficial statistics: about 1.3 million Japanese residing abroad. Accessed 13/07/2026.
  • Consulate-General of Japan in New York / Consulate-General of Japan in São Paulo (official MOFA sites)Official consular alerts (注意喚起) on fraudulent calls targeting Japanese residents abroad. Accessed 13/07/2026.

Philippines — Scam laban sa OFW (page /fil/scam-sa-ofw/)

  • Department of Migrant Workers / Philippine Statistics Authority, cited by BusinessMirror and Gulf News (2026)$6.48 billion in OFW remittances from the Middle East in 2025. Accessed 13/07/2026.
  • DMW, cited by The Filipino Times (May 2026) and Tribune.net.ph (June 2026)Official alerts on illegal recruitment and fake "travel assistance." Accessed 13/07/2026.
  • OWWA, cited by The Global Filipino Magazine and Gulf News (2026)Official hotline 1348, alerts on fake embassies and the padala scam. Accessed 13/07/2026.

Germany — Betrug gegen Diaspora-Communitys (page /de/diaspora-betrug/)

  • Deutsche Bundesbank, "Heimatüberweisungen der Gastarbeiter / Remittances"€8.5 billion sent from Germany in 2025, including ~€5.8B to Europe (Turkey/Romania/Ukraine/Poland leading). Accessed 13/07/2026.
  • LKA NRW, official alert "Vorsicht Betrug: KEIN Anruf von Europol oder Interpol"; Polizei NRWOfficial alerts on police impersonation and caller-ID spoofing. Accessed 13/07/2026.
  • Polizeipräsidium Oberpfalz / Niederbayern (Bavarian Police), press releases (2026)Real case: Russian-speaking call center, Regensburg/Amberg, April 2026, five-figure damage to a Russian-speaking senior victim. Accessed 13/07/2026.

Italy — Truffe contro la diaspora (page /it/truffe-diaspora/)

  • Banca d'Italia, official annual rimesse statistics≈€9 billion in 2025, main corridors Bangladesh/Pakistan/Morocco/Philippines/Romania. Accessed 13/07/2026.
  • Ministero degli Affari Esteri (Farnesina)Official AIRE figure: about 6 million Italians registered as residing abroad. Accessed 13/07/2026.
  • AGCOM49 million fraudulent calls blocked by the anti-spoofing filter in 11 days (November 2025). Accessed 13/07/2026.

Netherlands — Oplichting gericht op diaspora (page /nl/diaspora-oplichting/)

  • Wereldbank, cited by Dagblad Suriname (21/06/2025)≈$147 million in official remittances to Suriname in 2023 (≈4% of GDP). Accessed 13/07/2026.
  • Fraudehelpdesk, "Terugblik 2025," press release (February 2026)€68.5 million in total damage, including €7.5M for hulpvraagfraude (17,264 reports). Accessed 13/07/2026.
  • Openbaar Ministerie (OM.nl), press release (07/04/2021)Real case: charges against two men for "friend-in-distress" fraud via WhatsApp nationwide. Accessed 13/07/2026.
Scams targeting the diaspora in France (page /arnaques-diaspora/)France
  • World Bank, cited by Africa24 (2025)Over $50 billion transferred each year by diasporas to sub-Saharan Africa. Accessed 13/07/2026.
  • Jeune Afrique, World Bank data (2025)$3.69 billion transferred to Senegal in 2024; France is the top sending country for this corridor. Accessed 13/07/2026.
  • Afrique sur 7 (2025)840 billion FCFA sent to Côte d'Ivoire in 2024, up over 540% in 15 years; about $1.1 billion received by Mali over the same period. Accessed 13/07/2026.
  • SeneNews / Orishas Finance (2025)Reused real case (see section above): fake real-estate investment tontine, 97 mostly Senegalese victims, Val-d'Oise, €1.268M. Accessed 13/07/2026.
Dual work/personal SIM — line mixing, stress, and productivity (page /double-sim-pro-perso/)
  • Gloria Mark (UC Irvine), book Attention Span (2023) and two decades of published research23 minutes 15 seconds on average to fully regain focus after a single interruption; interruptions are linked to significantly higher stress, frustration, and cognitive load. Accessed 14/07/2026.
  • EmailToolTester, survey of 1,125 US employees (September 2024)90.4% would support a "right to disconnect" law; 81.4% have their work-communication tools on their personal phone; 71.1% feel obligated to respond outside work hours; 78.7% dread opening their work inbox; 82% report sleep disrupted by constant connectivity. Commercial survey (methodology as stated by the publisher), cited as such — not an academic study. Accessed 14/07/2026.
  • Gallup, State of the Global Workplace (2023)76% of employees report feeling burned out at least occasionally. Accessed 14/07/2026.
  • Whelan, E. et al., Internet Research (Emerald Publishing), January 2024 — University of Galway & University of MelbourneQuasi-experimental study on ≈40 employees at a European site of a major pharmaceutical company: a total ban on personal phones at work increased family tension and work-life conflict, with no measurable productivity gain after the ban was lifted. Relayed by University of Galway (press release, 08/01/2024). Accessed 14/07/2026.
  • GSMA Intelligence, "Variable network quality a key driver of multi-SIM ownership"Owning multiple SIM cards and using dual-SIM phones is more common in markets where network quality and coverage are uneven between operators. Accessed 14/07/2026.
  • Dataintelo, Global Dual SIM Smartphone Market Research Report (2025)Market research: about 1.62 billion dual-SIM smartphones shipped worldwide in 2025, over 71% of total smartphone shipments; India estimated to account for about 17.2% of global dual-SIM smartphone shipments. Market data estimated by a research firm, not an official census — cited as such. Accessed 14/07/2026.
  • IDC Brasil, cited by Tech in Brazil, "Use of Multi-SIM Mobiles in Brazil"680% growth in dual-SIM device sales in Brazil in 2013, driven by cost optimization across operators with highly uneven rates. Historical data point (2013) — cited to explain the origin of the usage pattern, not as a current measure. Accessed 14/07/2026.
  • Malaysian Communications and Multimedia Commission (MCMC), Mandatory Standard on prepaid SIM registration, in force 26/02/2026Biometric (MyKad fingerprint) verification required at registration; cap of 5 prepaid SIMs maximum per operator and per person — a registration limit, not a limit on active lines within a single phone. Reported by Lowyat.NET, Malay Mail and Malaysianwireless (26-27/02/2026), official mcmc.gov.my FAQ. Accessed 27/07/2026.
  • BTK (Turkish telecom regulator), IMEI registration rule for devices bought abroadNo dual-SIM restriction from BTK — the opposite: explicit recognition, with a dual-SIM/eSIM device benefiting from an extended 8-month usage window before mandatory IMEI registration, versus a shorter window for single-SIM. Fraud documented in 2026 (declaring a second IMEI of the same device as a separate phone), compliance deadline 01/05/2026. Reported by several converging Turkish outlets (Cumhuriyet, Hürriyet, Habertürk, ShiftDelete.net). Exact regulatory text not directly verified — treat with caution. Accessed 27/07/2026.
  • Anatel (Brazilian telecom regulator), federal Lei 10.703/2003 and Resolução Anatel n° 477/2007, art. 58Mandatory registration (name, CPF/CNPJ, address) at activation of any prepaid SIM in Brazil; cap of 5 prepaid SIMs maximum per CPF and per operator (secondary source Olhar Digital, 2020 — treat with caution). Cross-operator verification portal cadastropre.com.br (January 2020). Accessed 27/07/2026.
  • Supreme Court of Mexico (SCJN), Acción de Inconstitucionalidad 82/2021 y 86/2021, April 2022PANAUT (national mobile phone user registry, 2021) ruled unconstitutional (9 votes), disproportionate privacy intrusion. Separate new registry in force since 09/01/2026 under the new Ley de Telecomunicaciones (CRT, Comisión Reguladora de Telecomunicaciones), explicitly motivated by combating phone extortion and smishing, compliance deadline announced for 30/06/2026. Reported by El Financiero, Xataka México, La Silla Rota, R3D. Accessed 27/07/2026.
  • CST (Communications, Space & Technology Commission, Saudi Arabia), biometric SIM registration regimeDifferentiated cap: 2 prepaid SIMs maximum per Iqama for foreign residents, up to 10 SIMs for Saudi citizens — ground that makes dual-SIM use (local line + home-country line) common and already legally recognised for the expatriate population. Converging secondary sources (mysaudilife.com, ksaexpats.com, dailyexpatinfo.com); figures not directly confirmed on cst.gov.sa — treat with caution. Accessed 27/07/2026.
  • UKE (Polish electronic communications regulator), 2016 anti-terrorism act and 2024 Prawo komunikacji elektronicznejMandatory nominative registration of prepaid SIM cards, in force since 25/07/2016 (compliance deadline 01/02/2017); 2024 law (transposing the EU Electronic Communications Code, in force 10/11/2024) confirming and extending the obligation, also motivated by fraud and money laundering. Sources: archiwum.uke.gov.pl, Panoptykon, isap.sejm.gov.pl (official text). Accessed 27/07/2026.

Rigor note: market figures (Dataintelo, IDC Brasil) are research-firm estimates, not official census data — presented as orders of magnitude, never as certified statistics. The EmailToolTester survey is a commercial survey with a stated methodology, distinct from the academic studies (Whelan et al., Gloria Mark) and the Gallup survey cited on the same page.

Religious-themed scams

Brazil — estelionato religioso (page /pt-br/estelionato-religioso/)Brazil
  • Operação Blasfêmia — agenciabrasil.ebc.com.br, band.com.br (Sept. 2025)Takedown of a religious call center that collected over R$3 million in two years via Pix, on charges of fraud, identity theft, criminal association, and money laundering. Accessed 13/07/2026.
  • Operação Falso Profeta — correiobraziliense.com.brSeparate investigation estimated at around 50,000 victims. Accessed 13/07/2026.
  • jusbrasil.com.br"Estelionato religioso" as a recognized Brazilian legal term, treated by courts as an ordinary financial crime. Accessed 13/07/2026.

In line with the site's editorial rule, no church, denomination, or individual is named on this page — only police operations and legal classifications published by the press and authorities.

Gulf / Egypt — Hajj, Umrah, and fake fundraiser fraud (page /ar/ihtiyal-alhajj-walumrah/)Gulf
  • nusuk.sa — official platform of the Saudi Ministry of Hajj and UmrahOfficial booking reference cited for verification before payment. Accessed 13/07/2026.
  • Resecurity.com, Arab NewsFraudulent sites mimicking the Nusuk platform to collect passports and payments; arrest by Dubai police of a group organizing fake Hajj/Umrah campaigns on social media in 2025. Accessed 13/07/2026.
  • Egypt's 2024 season crisis ("visa-swap")Unlicensed agents issuing tourist visas instead of valid Hajj permits — more than a dozen agencies lost their licenses following this crisis. Accessed 13/07/2026.
  • islamic-relief.org — official "Scams and fraud" pageThe NGO confirms it never solicits donations via unofficial WhatsApp/Telegram groups impersonating its name or logo. Accessed 13/07/2026.
Indonesia — umroh travel fraud (page /id/penipuan-umroh/)Indonesia
  • hukumonline.com, kompas.com, mediaindonesia.comLegal and press coverage of the First Travel case: roughly 63,000 jamaah affected, estimated damage of around Rp905 billion, criminal conviction of the operators. Accessed 13/07/2026.
  • Kementerian Agama (Kemenag) — PPIU listOfficial registry of Penyelenggara Perjalanan Ibadah Umrah (licensed umrah travel agencies), cited as the reference for verification before payment. Accessed 13/07/2026.
Malaysia — umrah travel fraud (page /ms/penipuan-pakej-umrah/)Malaysia
  • malaysiagazette.com (Nov. 2023)123 complaints, losses exceeding RM1.3 million against one umrah package operator. Accessed 13/07/2026.
  • journal.jawhar.gov.my — "Fraud in Hajj and Umrah: An Exploratory Review"Academic study citing 2,761 cases handled by the Tribunal Tuntutan Pengguna Malaysia (TTPM) between 2012 and 2015, cumulative losses exceeding RM19 million. Accessed 13/07/2026.
  • Malay Mail, Daily Express Malaysia (Feb. 2025)MOTAC revoked the license of Al Quds Umrah & Tours (M) Sdn Bhd, effective 24 January 2025, over fraud allegations. Accessed 13/07/2026.
  • The Star (Jan. 2025)MOTAC studying a RM250,000 bank-guarantee requirement for umrah operators. Accessed 13/07/2026.
  • motac.gov.my / ecentral.my — umrah operator verificationOfficial MOTAC license-verification portal, cited as the reference for verification before payment. Accessed 13/07/2026.

Regulation and how the app works

Dedicated telemarketing ranges — France, Spain, IndiaDedicated telemarketing ranges
  • ARCEP — Décision n° 2018-0881 du 24 juillet 2018, plan national de numérotation0162, 0163, 0270, 0271, 0377, 0378, 0424, 0425, 0568, 0569, 0948, 0949
  • ARCEP — « Les numéros 08 et les numéros courts », mise à jour du 24/07/202509475, 09476, 09477, 09478, 09479 (outre-mer)
  • Resolución de 14 de abril de 2026, SETID — BOE-A-2026-8409, BOE núm. 93 du 16/04/2026NXY = 400 · effets au 17/04/2026 · exclusivité au 17/10/2026
  • CNMC — Anuncio de asignación de numeración 400, BOE-B-2026-12824 du 24/04/2026400ABM · blocs de 1 000 numéros
  • Real Decreto 2296/2004 — Plan Nacional de Numeración Telefónica, apartado 4.1numéro national à 9 chiffres
  • TRAI — série 140, Telecom Commercial Communications Customer Preference Regulations140

Official texts allocating ranges reserved for commercial cold calling. Checked on 05/08/2026.

Premium-rate ranges — Germany, Austria, Switzerland, Belgium, NetherlandsPremium-rate ranges
  • BNetzA — Verfügung 73/2023, « Nummernplan (0)900 », 12/07/20230900 (paliers -0 à -8 ouverts depuis le 01/12/2024)
  • BNetzA — Verfügung 24/2016, « Nummernplan Massenverkehrs-Rufnummern », 05/05/20160137, 0138 · 118 (Auskunftsdienste)
  • RTR — KEM-V 2009, BGBl. II Nr. 212/2009, novelle BGBl. II Nr. 66/2026 du 25/03/20260900, 0901, 0930, 0931, 0939 (dialers, § 119)
  • OFCOM / BAKOM — Plan E.164, annexe 2.2 (RS 784.101.113/2.2), éd. 8 du 08/11/20230900, 0901, 0906
  • IBPT / BIPT — Arrêté royal du 27/04/2007, art. 50070, 077, 0900 à 0907, 0909
  • ACM — Nummerplan telefoon- en ISDN-diensten, consolidé au 03/10/20250900, 0906, 0909

Regulators' numbering plans and tariff decisions. Checked on 05/08/2026.

Premium-rate ranges — United Kingdom, Italy, Spain, Portugal, Poland, TürkiyePremium-rate ranges
  • Ofcom — The National Telephone Numbering Plan, en vigueur au 22/04/202509, 118
  • Ofcom — « Personal numbering: review of the 070 number range », statement du 01/10/2018070 retiré : plafonné au tarif mobile
  • AGCOM — Allegato A alla delibera n. 8/15/CIR, 20/02/2015892, 893, 894, 895, 899, 455, 124 à 129
  • CNMC — Real Decreto 2296/2004 et Orden IET/2733/2015 (BOE-A-2015-13738)803, 806, 807, 905, 907, 118
  • ANACOM — Décision codes 761/762 (04/04/2007) et règles de barramento (17/08/2013)760, 761, 762, 601, 607, 608, 646, 648
  • UKE — Dz.U. 2024 poz. 1862, en vigueur le 01/01/2025700, 701, 703, 704, 708
  • BTK — Genel Numaralandırma Planı, « katma değerli hizmet numaraları »0888, 0898, 0900

Regulators' numbering plans and tariff decisions. Checked on 05/08/2026.

Premium-rate ranges — United States, Canada, Mexico, Japan, Egypt, PakistanPremium-rate ranges
  • NANPA — 9YY NXX Codes ; 47 CFR § 64.1501 et § 64.1504, subpart O900 (États-Unis et Canada)
  • IFT — Plan Técnico Fundamental de Numeración, acuerdo au DOF du 11/05/2018900
  • MIC / 総務省 — 電気通信番号計画(令和元年総務省告示第6号), 別表第20990 (情報料代理徴収機能)
  • MIC / 総務省 — 電気通信番号指定状況, état au 01/07/20260180 : aucune attribution · 0570 non surtaxé
  • NTRA — plan de numérotation égyptien publié par l'UIT-T (E.164, 20/07/2014)0900, 0800
  • PTA — National Numbering Plan 2008, § 18 (Premium Rate Services)0900

National numbering plans and regulatory texts. Checked on 05/08/2026.

Premium-rate ranges and telemarketing — United Arab Emirates, Saudi Arabia, Qatar, KuwaitPremium-rate ranges and telemarketing
  • TDRA — الخطة الوطنية للأرقام / National Numbering Plan, version 5.3, 03/06/2015900 + Y (0 ou 2) + 5 chiffres · 600 et 700 exclus : coût fixe et coût partagé
  • Cabinet Resolution No. (56) of 2024 on the Telemarketing Regulations (EAU), signée le 10/06/2024Do Not Connect Register · appels 9h-18h · identification orale obligatoire · aucun préfixe dédié
  • CST — National Numbering Plan, réf. RR08, cinquième version, février 2024 (décision 523/1445)700 + 5 chiffres, seule plage surtaxée · 9200/9211/9222 exclus, plafonnés au tarif géographique
  • CITC / CST — Regulations for Curbing SPAM Messages & Calls, version 3, RC01, octobre 2022opt-in exprès · arrêt sous 24 h · interdits 22h-9h, et 1h-12h pendant le Ramadan
  • CRA — Qatar National Numbering Plan, notifié à l'UIT le 27/03/2023900 + 4 chiffres · aucun préfixe interurbain : le niveau 0 est réservé à l'international
  • CRA — Spam Regulation, réf. CRA-CA-3589-16-NG, novembre 2016, amendée le 06/08/2017couvre explicitement la voix · consentement préalable · STOP en arabe et en anglais
  • CITRA — Kuwait National Numbering Plan, notifié à l'UIT le 10/08/2023aucune plage surtaxée publiée · quatorze lignes au plan complet · 18xx = numéros d'entreprise, jamais un numéro vert
  • CITRA — User Protection and Privacy Rules Regulationopposition portée par chaque opérateur · messages commerciaux 7h-22h · identification de l'expéditeur

National numbering plans and telemarketing rules, read in full on 05/08/2026. None of these four countries has a range reserved for commercial cold calling: the duty there is to identify yourself out loud at the start of the call. Kuwait publishes no premium-rate range at all — a negative verified across three concordant documents, not a gap in our research.

Countries removed or left empty after verificationCountries removed or left empty after verification
  • ANATEL — Telemarketing Ativo, préfixe 0303obligation révoquée en août 2025 · 0304 absent du catalogue
  • ACMA — Telecommunications Numbering Plan 2025 (F2025L00409), Sch. 5, 21/03/20251900 réaffecté aux usages de données
  • Kominfo — Permen 14/2018annexe de numérotation non consultable · 0807 et 0809 non confirmés
  • NTC — Memorandum Circular No. 02-05-2008, « Value Added Services », 30/05/2008aucune plage assignée · tarifs déréglementés (§ 9)
  • NCC — National Numbering Plan, version du 06/05/2025aucune plage surtaxée publiée · 070x-072x sont des mobiles

Sources that led us to remove a range, or to record nothing at all. Checked on 05/08/2026.

ARCEP telemarketing prefixes — figures and methodology (page /egidio-vs-saracroche/)
  • ARCEP — démarchage téléphonique, fiche pratiqueOfficial list of the 17 prefixes dedicated to telemarketing calls since 1 January 2023. Accessed 18/07/2026.
  • Code source Egidio — RegulatoryNumberMatcher.kt / CountryPack FRInternal implementation of the 17 ARCEP prefixes (0162, 0163, 0270, 0271, 0377, 0378, 0424, 0425, 0568, 0569, 09475-09479, 0948, 0949), prefix matching on normalized national number. Accessed 18/07/2026.
  • Saracroche : bloqueur d'appels — fiche App Store (Camille Bouvat, Toulouse)Free, open-source app with no data collection, available on iOS and Android; claims over 15 million numbers blocked via the ARCEP list and user reports. Accessed 18/07/2026.

Rigor note: the “up to 12.5 million numbers” calculation presented on the /egidio-vs-saracroche/ page is a methodological derivation (French 10-digit numbering plan applied to the 17 official prefixes), not a figure published by ARCEP itself — the calculation method is explained on the page. We do not know Saracroche's exact internal list and do not claim to.

Why Egidio doesn't exist on iPhone — technical sources (page /en/why-not-iphone/)
  • developer.apple.com — Call Directory & CallKitOfficial Apple documentation on CXCallDirectoryExtension (app-supplied number-based block/identify lists) and Live Caller ID Lookup (encrypted server-side lookup during a call), both strictly number-based. Accessed 18/07/2026.
  • developer.apple.com — Message Filter Extension (ILMessageFilterExtension)Official documentation on iOS SMS filtering, limited to unknown senders and siloed per app, with no cross-channel correlation possible. Accessed 18/07/2026.
  • support.apple.com — Silence Unknown Callers, iOS 26 and message filteringApple support pages on “Silence Unknown Callers” (iOS 13+), native unknown-sender message filtering, and independent press coverage (9to5Mac, MacRumors) of the native call screening feature introduced with iOS 26. Accessed 18/07/2026.
Android / platform regulation
  • support.google.comOfficial documentation: Android allows only one active call-filtering app at a time (the "Caller ID & spam protection" setting). Factual basis of the central argument across all comparisons on the site. Accessed 12/07/2026.
Battery and OEM management (pages /aide/protection-sarrete/ and /en/help/protection-stops-by-itself/)
  • dontkillmyapp.comCommunity developer project tracking, brand by brand, the most restrictive battery-management behaviors on Android (Samsung, Xiaomi, Oppo, Vivo, Huawei...). Accessed 13/07/2026.
  • "Device care" screenshots (Samsung One UI, FR page)Primary source: real, unedited screenshots, Egidio team's Samsung Galaxy S24, taken on 4 dates between 26 June and 11 July 2026 (0.5% to 0.9% battery for 2h25 to 4h39 of background monitoring). Examples from a single device, not a guaranteed average.
  • Native Android "App Info" screenshots (EN page)Primary source: real, unedited screenshots, same Samsung Galaxy S24, native Android Settings screen (Apps → Egidio) dated 13/07/2026 — 1% battery used since last full charge. Complements the Device Care evidence: this native Android screen works the same way on any brand.

Glossary, etymology and studies

General studies on scams and spam

See the dedicated page Scams, spam and mental load: figures and studies, which compiles FBI IC3, FTC, and academic reports on the cognitive impact of spam and senior vulnerability — with full sources and direct links.

Scam glossary (page /glossaire/)
  • FBI Internet Crime Complaint Center (IC3)Official terminology and categorization of online fraud types (phishing, romance scam, sextortion, etc.). Accessed 12/07/2026.
  • Federal Trade Commission (FTC)Consumer-facing definitions of common scams (smishing, spoofing, money mule). Accessed 12/07/2026.
  • Cybermalveillance.gouv.frFrench public cybersecurity-awareness body — definitions and French examples (SIM swap, ransomware, social engineering). Accessed 12/07/2026.
Affinity fraud (FR + EN glossary, page /en/affinity-fraud/)
  • U.S. Securities and Exchange Commission (SEC) — Affinity FraudOfficial category of financial fraud exploiting trust within communities (professional, associative, cultural) — investor.gov, Investor Alerts. Accessed 13/07/2026.
  • SEC / investorclaims.com — Kenneth Mattson case (May 2025)Roughly $46 million Ponzi-type scheme over ~15 years, targeting mainly elderly and retired members of his own religious community, ~200 investors affected. Accessed 13/07/2026.
  • moneywise.com, finance.yahoo.com — Winston Batino caseChicago pastor charged with defrauding ~40 people (mostly members of his congregation) of at least $2 million via a fake investment project. Accessed 13/07/2026.
  • SEC — 2024 actionsDocumented affinity-fraud cases affecting very diverse communities (Christian, Filipino-American, Latino, Orthodox Jewish) — used to illustrate that the mechanism targets trust, not any specific community. Accessed 13/07/2026.
Etymology & mythology (page /histoire/)
  • αἰγίς (aegis) — Greek etymologyEtymological dictionary of Ancient Greek (Chantraine) — the aegis as Athena's protective attribute, bearing the head of Medusa (gorgoneion). Accessed 12/07/2026.
  • Aegidius → Egidio / GillesEvolution of the Latin name Aegidius into its Romance forms: Egidio (Italian), Gilles (French), Giles (English) — name and onomastics dictionaries. Accessed 12/07/2026.
The Grammar of Manipulation (hub /grammaire/, 8 pages)
  • Ferreira, A., Coventry, L. & Lenzini, G. (2015), "Principles of Persuasion in Social Engineering and Their Use in Phishing," HAISA/Springer LNCS 9190Reference taxonomy of the 5 levers of persuasion in social engineering (Authority, Social Proof, Liking/Similarity & Deception, Commitment/Reciprocation & Consistency, Distraction), merging Cialdini, Gragg and Stajano & Wilson, tested on 52 real phishing emails. Accessed 17/07/2026.
  • Zielinska, O., Welk, A., Mayhorn, C. & Murphy-Hill, E. (2016), Proc. Human Factors and Ergonomics Society Annual Meeting, 60(1)Longitudinal analysis of 887 phishing emails coded against Cialdini's 6 principles: rising use of commitment/consistency and scarcity over time. Accessed 17/07/2026.
  • Whitty, M. (2013), British Journal of Criminology5-stage model of romance scams (ideal profile, grooming, sting, abuse, revelation). Accessed 17/07/2026.
  • arXiv:2412.15423 (Dec. 2024)Analysis of 1,280 pig-butchering victim accounts: love bombing (n=340), guilt-tripping (n=290), artificial urgency (n=260), isolation (n=210). Accessed 17/07/2026.
  • The Gerontologist (Oxford Academic)Case study on financial exploitation of seniors by trusted relatives: gradual escalation and active isolation of the victim. Modest qualitative sample. Accessed 17/07/2026.
  • Kahneman, D. & Tversky, A. (1979), "Prospect Theory: An Analysis of Decision under Risk," Econometrica, 47(2)Loss aversion, a founding bias of behavioral economics. Accessed 17/07/2026.
  • Sharot, T. (2011), "The Optimism Bias," Current Biology, 21(23)Optimism bias documented in neuroscience. Accessed 17/07/2026.
  • Tversky, A. & Kahneman, D. (1974), "Judgment under Uncertainty: Heuristics and Biases," Science, 185(4157)Base-rate neglect. Accessed 17/07/2026.
  • Cialdini, R. (1984), Influence: The Psychology of PersuasionClassic persuasion principles (commitment/consistency, reciprocity) incorporated into the Ferreira et al. taxonomy. Accessed 17/07/2026.

Rigor note (Grammar): two comparisons initially considered — Steven Hassan's BITE model and Lifton's 8 criteria applied directly to the isolation of romance-scam victims, as well as a point-by-point mapping between Cialdini's 6 principles and romance scammers' tactics — did not withstand adversarial review of the source text. They are therefore not presented as established facts in this dossier, in line with our sourcing methodology.

Scam Radar

Scam Radar (page /radar/)
  • Cybermalveillance.gouv.frFrench public awareness body — alerts on relative impersonation, package smishing, and bank vishing. Accessed 13/07/2026.
  • 33700 — national reporting service for fraudulent SMS/callsReferenced in Radar entries for official reporting in France. Accessed 13/07/2026.
  • Fédération bancaire françaiseRecommendations on vishing and protecting security codes (OTP). Accessed 13/07/2026.
  • DGCCRFAlerts from the French consumer-fraud authority on fraudulent solidarity fundraisers. Accessed 13/07/2026.

Radar entries are editorial reconstructions of documented scam patterns — never real screenshots or raw reports republished as-is. Full methodology: Radar page.

Update of 16/07/2026: the alert levels for Turkey, Philippines, United Arab Emirates (raised to "High") and Japan (raised to "Moderate") rely on statistics already sourced in the dedicated Threat Lab sections above (country reports and data-breach pages) — see Turkey, Philippines, UAE, Japan.