Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Tech
Conti ransomware gang member sentenced to 4 years in prison
A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022.
44-year-old Oleksii Oleksiyovych Lytvynenko was arrested by the Irish national police (An Garda Síochána) in July 2023 at the request of the United States and was extradited last year.
Lytvynenko and his Conti accomplices deployed ransomware on victim networks in the United States and abroad, stealing data and encrypting devices to extort Bitcoin ransom payments.
“From 2020 until 2022, Conti was used to attack computers and networks in 47 states, 31 foreign countries, the District of Columbia, and Puerto Rico. The FBI estimates that, as of January 2022, there had been victim payouts associated with Conti ransomware exceeding $150,000,000,” the Department of Justice said on Thursday.
“Lytvynenko joined that conspiracy as both an intruder and a developer — personally harming at least 12 companies, storing stolen data from victims, and helping build the malicious tools Conti used to extort and threaten communities,” added Assistant Attorney General A. Tysen Duva.
The defendant pleaded guilty to conspiracy to commit wire fraud in June 2026 and was facing a maximum sentence of 20 years in prison.
He admitted to joining the Conti ransomware operation in September 2021, controlling the stolen data of eight U.S. victims and four overseas victims, and sending ransom notes as part of the cybercrime gang’s double extortion attacks between 2020 and June 2022.
Lytvynenko also admitted to joining a team run by another Conti conspirator, where he coded a “loader,” which is a type of malware designed to load the software needed to carry out attacks.
Conti ransomware gang
The Conti ransomware operation emerged from the Ryuk cybercrime group in 2020 with close ties to the TrickBot malware gang, and became notorious for large-scale attacks against healthcare organizations, governments, and enterprises.
Conti evolved into a cybercrime syndicate that controlled multiple malware operations, including BazarBackdoor and TrickBot, and it shut down two years later, in 2022, after increased law enforcement pressure and leaked internal chats.
The Conti gang later split into other ransomware groups, including BlackCat, Black Basta, ZEON, Hive, Quantum, BlackByte, Karakurt, and the Silent Ransom Group.
Seven TrickBot/Conti members were sanctioned in February 2023, after a massive leak of personal information and internal conversations belonging to Conti and TrickBot members, known as the ContiLeaks and TrickLeaks.
In September 2023, the U.S. and the United Kingdom also sanctioned and charged nine Russian nationals associated with Conti and TrickBot for attacks against over 900 victims worldwide, while the Federal Criminal Police Office of Germany (Bundeskriminalamt or BKA) doxed the leader of the TrickBot and Conti cybercrime gangs in May 2025, claiming he is a 36-year-old Russian named Vitaly Nikolaevich Kovalev using the alias “Stern.”
According to court documents, the Conti cybercrime gang has targeted more than 1,000 victims worldwide and collected over $150 million in ransom payments while active.
Tech
Now You See It, Solano CHP Stops a Jetta With a Push-Button Plate Hider

A black Volkswagen Jetta rolled through an Express Lane in Solano County with a blank bumper where a rear plate should have been. A California Highway Patrol cruiser in the next lane caught that empty space on dashcam, then saw the same car moments later with a full, readable California plate sitting in place. That change was the whole stop.
Officers stopped a Jetta, and there was just one driver inside. After speaking with the motorist, CHP Solano learned that the strange hardware on the bumper was intended to avoid paying Express Lane costs and Bay Area bridge tolls. The office later posted the encounter with a short line that has already traveled farther than the car did that day. “Now you see it, now you don’t.”
Sale
9″ Wireless CarPlay Screen with Apple Car Play & Android Auto for Car, OTA Updates, Backup Camera…
- 【Wireless Apple Carplay & Android Auto】Enjoy seamless wireless carplay and android auto connectivity for your phone’s music, map navigation…
- 【OTA Updates】Keep your device up to date with over-the-air firmware updates, so you’re always one step ahead. This wireless CarPlay screen…
- 【Phone Mirroring Link & Four Audio Outputs】This 9-inch CarPlay screen supports mirroring for both iOS and Android phones. The double-DIN car…
On body camera footage, that hardware appears to be quite typical. An officer picked up a small remote that functions similarly to a key fob, hit a button, and a black shield swooped over the plate, erasing the numbers. With another squeeze, the cover fell back out, revealing a standard licence plate. In the video coverage, that panel is described as a sliding cover or a raised shield, which is basically the same type of motorized frame you can buy online as plate hiders, flippers, and curtains, and a driver can hide the tag on the way up to a bridge, then revert it before the cameras get a clear look.
Tolls in that section of the state do not require a person at a booth to check your plate because Express Lanes and Bay Area bridges combine FasTrak readers with overhead cameras. If the transponder does not respond, the camera captures a photo of the rear plate, and the agency sends the bill to the owner. Cover the plate for a few seconds, and the snapshot comes back empty. Pay by plate only works if you are prepared to display your plate, which is why there is a removable cover like this.
California has previously excluded the concept from the Vehicle Code. Section 5201.1 states that you are not permitted to operate a vehicle with a removable frame, flipper, or any other device designed to conceal a license plate from view or electronic readers. The base fine is $250, before the state and county add extra costs and take it from there. Section 5201 still requires plates to be properly attached, visible, and readable at all times. If you don’t pay your tolls, you’re also breaking another law, 23302(a)(1), which will result in civil penalties and a DMV hold, prohibiting you from renewing your registration. The same chapter was tightened in 2025 and 2026, including any goods that seek to peel or paint over a plate’s reflective coating, preventing cameras from locking on it.
[Source]
Tech
Microsoft warns that killing VBScript could break Windows activation for businesses
Scriptocalypse: Microsoft announced the deprecation of the VBScript environment a few years ago, asking companies and power users to switch to modern scripting systems. Now, the company is warning organizations that depend on VBScript that Windows activation might even become impossible after the language is gone.
Microsoft is asking organizations that rely on the Slmgr.vbs tool to switch to PowerShell, as the old script will soon stop working along with the rest of the VBScript language. Companies that use the script to manage Windows activation should act soon, as Microsoft is likely to accelerate VBScript deprecation in future Windows upgrades.
As explained in Microsoft’s own documentation, Slmgr.vbs is a Visual Basic Script included in Windows to manage OS activation from the command line. The script can install and change product keys, activate Windows, check the current activation or licensing status, and much more. The tool is specifically designed to provide enterprise organizations with a flexible way to manage multiple OS activations, which has nothing to do with KMS servers or other “unofficial” methods designed to achieve the same results without paying Microsoft a dime.
As the company first announced in 2023, VBScript will soon disappear from Windows after being part of the operating system’s convoluted lineage for almost 30 years. Modeled after the Visual Basic programming language, VBScript was designed as a powerful automation technology for programmers and users looking to exert greater control over the Windows operating environment.
According to Microsoft’s latest timeline for VBScript deprecation, the technology is now available as a Feature on Demand (FOD) on Windows and is enabled by default. At a later stage, VBScript’s FOD will no longer be enabled by default, and users will need to manually install the feature if they need it.
Finally, a future Windows release will completely remove VBScript. At that point, Slmgr.vbs and other automation solutions will stop working altogether.
Microsoft said that Slmgr.vbs can be easily replaced with PowerShell, where the OSLicense module provides the automation features currently available through VBScript. OSLicense requires Windows PowerShell 5.1 and can be used to manage activation information, invoke new licensing instances, and more.
One potential issue with adopting the OSLicense module is the version of Windows used by organizations. The PowerShell component is available in client versions of Windows 11 after installing the August 2026 Preview update (KB5120998) or later. Meanwhile, Windows Server will provide support for the new module with the next major release of the enterprise-focused operating system.
Either way, Redmond said organizations should start checking their scripts, command-line tools, and group policies right now. Companies using Slmgr.vbs and other VBScript-based “dependencies” are advised to thoroughly check their IT automation procedures so they can ease the pain that comes with changing decades-old conventions.
Tech
Altman Considers Slowing Down AI Development
Bloomberg reports (paywalled) that Sam Altman told OpenAI employees the company is open to slowing the pace of AI development alongside other leading labs as concerns grow over increasingly capable systems and recent incidents in which models escaped human control. OpenAI has already paused development once this year for security work and is now pushing for mandatory U.S. AI safety requirements. Anthropic has also signaled interest in coordinating on the pace of new releases. Here are some of the details Bloomberg reported, as summarized by Reuters:
– Altman told employees in a company-wide meeting that the ChatGPT maker could pace development alongside other AI labs, but some may not agree, the report added.
– Safety warnings from AI researchers this week, along with several recent incidents where AI models from developers including OpenAI escaped human control, have prompted alarm and calls for tighter safety regulations.
– Jacob Coxon, a former Anthropic and OpenAI researcher, publicly accused the companies earlier this week of racing toward AI advancements without acting responsibly.
– An Anthropic spokesperson said on Thursday said that the company is interested in working with the AI industry on the pace of releasing new AI tools.
– OpenAI said in July that AI acceleration for frontier model development may be so high that the world will “need to pace the rate of AI advancement” at some point in the future.
– In August, OpenAI paused much of its model development for two weeks to bolster its defenses after its AI agents escaped containment and hacked open-source platform Hugging Face.
– OpenAI said on Wednesday that it was pushing for mandatory national AI safety requirements in the United States, citing concerns that advanced AI systems could accelerate its own development.
Read more of this story at Slashdot.
Tech
Researchers warn that social media can reveal sensitive details about users
What you post online is only part of the story. A new review of research into social media privacy warns that platforms and third parties can potentially infer sensitive details about people from seemingly ordinary digital activity, including their political opinions, religious leanings and shopping habits.
The findings, as reported by Techxplore, published in the International Journal of Management Concepts and Philosophy, point to a widening gap between the amount of personal information generated online and the legal and ethical protections designed to safeguard it. The researchers examined privacy breaches, regulatory frameworks, and the responsibilities of both social media companies and their users.
Your digital trail says more than your posts
The central concern is not necessarily what users deliberately share. Instead, researchers highlight what can be inferred from their activity after it has been collected, indexed, and analysed.
Every interaction can contribute to a broader “digital trail” containing information about activities, locations and interactions. According to the research review, this trail can potentially be searched and analysed by third parties or, at the very least, by the platforms themselves. Even mundane online behaviour can provide clues about personality traits, purchasing patterns, political opinions and religious affiliations.

That creates a privacy problem that is easy to overlook. You might never explicitly state a political preference, religious belief or particular consumer habit, yet your online behaviour could still provide enough signals for someone else to make an educated inference.
The researchers argue that privacy is therefore not simply about keeping secrets. It is about maintaining control over who can access and interpret information about you. They connect that control to personal autonomy, civil liberties and democratic participation.
Why stronger privacy rules may be needed
The findings matter because social media has transformed privacy from something people could largely manage themselves into something increasingly shaped by algorithms, platforms and data analysis. Not just this; last year the city of New York decided to start treating social media with warning labels, like cigarettes.

The review calls for greater legal accountability and transparency from social media companies, alongside better digital literacy so users can understand and manage the risks associated with sharing information online.
The familiar argument that people who have “nothing to hide” have little reason to worry about privacy also comes under scrutiny. The researchers frame privacy as a right to decide who gets to see into the personal aspects of our lives – not as a tool for concealing wrongdoing.
For users, the takeaway is straightforward: your social media profile is potentially more revealing than the information you consciously put on it. Likes, interactions, locations and other seemingly harmless activity can form a larger picture when analysed together.
What happens next will depend on how regulators, platforms and users respond. The researchers’ call for stronger accountability and transparency suggests that privacy protections may need to evolve alongside the increasingly sophisticated ways online behaviour can be analysed.
Tech
Larry Ellison has cancelled his plan to sell $7.5bn of Oracle stock, a day after it surfaced
Larry Ellison has cancelled a trading plan that would have let him sell up to 50 million Oracle shares by 24 October, a day after the plan was disclosed and with no stock sold under it. The instrument is a Rule 10b5-1 plan, an American safe harbour with no European counterpart, because EU market abuse rules bar managers from dealing in the 30 calendar days before results instead.
Larry Ellison has cancelled the plan that would have let him sell up to 50 million Oracle shares, a day after it was disclosed, Bloomberg reported.
“No Oracle stock was sold under that plan, and he has no other plans to sell any of his Oracle stock,” the company said.
The plan was adopted on 22 June and would have run to 24 October. The shares were worth about $8.75B then and about $7.5B now, after a 16% fall. Oracle described it as a 10b5-1 plan in its statement.
Ellison controls about 40% of the company and is its executive chair and chief technology officer.
The timing was the problem. Oracle reported shrinking gross margins on Thursday, its shares fell 1.7% on Friday, and the same week it raised the cost of its job cuts to $2.8B.
A Rule 10b5-1 plan is a piece of American market plumbing with no European equivalent.
An executive who adopts one while not holding inside information can let trades execute later on a fixed schedule, including in periods when selling at their own discretion would draw questions. The rule dates from 2000, and the SEC tightened what has to be disclosed about these plans in 2022.
Europe closes the window instead.
Under the Market Abuse Regulation, a person discharging managerial responsibilities may not deal in the company’s shares during the 30 calendar days before an interim or year-end report.
There is no adopt-in-advance exemption from that.
Europe also discloses different things. It publishes transactions rather than intentions, within three working days of each deal, once EUR 5,000 has been reached in a calendar year. A plan that never traded would have left no trace at all.
None of which suggests Ellison did anything improper. No shares were sold, and the plan was disclosed exactly as American rules require, which is the only reason anybody knew about it.
But the two regimes would have produced different weeks. Europe would never have published a plan for the market to read, and would not have let one run through the results of a company sitting one notch above junk.
Tech
Apple’s best use of AI isn’t happening on the iPhone
AI is constantly being shoved in our faces. From your laptop to your phone, every new gadget now ships with some features built around AI. Over the last couple of years, even Apple has tried to make Apple Intelligence sound like the next big thing on the iPhone.
With iOS 27, the argument finally became worth listening to. Siri AI is a great example of this. It can search through personal information and understand what is on your screen before answering specific or broader general questions. Visual Intelligence looks through your phone’s camera to understand what you’re seeing, and a lot more.
All of this is impressive, till you see what Apple has in store with the Apple Watch Series 12 and Watch Ultra 4. The way it approaches AI in the wearables is different. It isn’t just a smaller secondary screen with a language model, and that’s why it works.

The Apple Watch doesn’t waste time
An iPhone gives Apple plenty of space to demonstrate AI, which is not the case for the Watches. Its tiny screen actively discourages long interactions, and I think that limitation is forcing Apple toward more interesting ideas. Take the new Audio Intelligence suite, for example. Each of the new features under it serves to make the users’ lives easier.
Sound Recognition can identify important noises such as alarms, sirens, doorbells, or a crying baby and alert you. Automatic Shazam identifies music around you and surfaces the result in Smart Stack. Live Rewind can recover the previous 15 seconds of speech when you missed something someone said. Siri Recap can turn conversations into short summaries you can revisit later.

Live Rewind can be really useful… if you ignore the privacy concerns
Live Rewind is probably the best example. I can just double-press the Digital Crown and get the previous 15 seconds as text if I missed something important in the conversation. Adding to its functionality, you can even ask Siri about it or have it saved for later. On the iPhone side, there isn’t any such interaction. By the time I’ve taken my phone out, unlocked it, and started recording, it’s already too late.
A lot of the new AI gadgets are all about seamless, display-free interactions. And just like those devices, the new Apple Watch changes how we interact with AI thanks to its physical proximity. A wearable has access to situations an iPhone sitting in my pocket can’t interact with quite as naturally, and Apple is beginning to build intelligence around that advantage.

We made a similar argument about Siri Recap recently. The privacy implications of a smartwatch listening to conversations deserve scrutiny. Though Apple’s implementation avoids retaining raw recordings and processes audio inside a hardware-isolated Secure Exclave on the S11 chip. Live Rewind also gives people nearby an audible and visual indication when it has been activated.
Why an iPhone can’t match the Apple Watch
Fitness and health features are what make the Apple Watch so popular. It knows much more about what my body is doing at any particular moment. Workout Buddy uses Apple Intelligence to provide spoken motivation based on personal workout data, and watchOS 27 expands the information it can incorporate. It can now operate while you exercise without carrying your iPhone, even if Apple still requires a paired Apple Intelligence-enabled iPhone and compatible Bluetooth audio hardware.
Series 12 and Ultra 4 also gather heart-rate measurements every five seconds and HRV as frequently as every five minutes through the new Health Sensing System. This data feeds Apple’s new Readiness experience, which combines activity, sleep, vitals, and training information into a score that updates as your condition changes throughout the day.

Apple’s redesigned Health app uses Apple Intelligence to interpret longer-term health information, while new vision-based AI assessments can combine the iPhone camera with Watch data to evaluate flexibility, strength, balance, movement mechanics, and VO2 max.
Siri AI on your wrist just works
Ironically, even Apple’s more conventional chatbot-style AI arguably gains something by being on the Watch. Siri AI brings the same personal-context understanding, conversational abilities, and broad knowledge available on the iPhone to watchOS 27. But on a phone, Siri is competing with other AI services like ChatGPT and Gemini.

With the Apple Watch, however, I can change an activity goal halfway through a run. Maybe even find something from my personal info or ask about my training without ever having to reach for my phone. Even watchOS 27’s smaller intelligence features play into this whole thing. The app grid can surface Siri-suggested apps based on usage, and something like Smart Stack recommendations can appear around context such as where you parked or someone’s birthday.
To be fair, the Apple Watch is more powerful than the iPhone. Features like Visual Intelligence bring some serious image-generation and editing tools. I just think the Watch is providing a better example of how AI can fit into an existing product without becoming the product.
I like the version of AI that’s all about making interactions feel more natural. It hears the thing you missed and recognizes the song playing nearby without needing any input. Nothing too intrusive, but still present enough to be handy in day-to-day use.
Tech
Anthropic CEO Dario Amodei Calls For AI Slowdown
An anonymous reader quotes a report from The New York Times: The chief executive of Anthropic called for a global slowdown of artificial intelligence development in a 3,800-word essay on Saturday, just days after one of the company’s employees quit over concerns about the safety of the technology. Dario Amodei, who co-founded Anthropic to focus on securely and carefully building A.I., wrote that while he believed the technology could bring many benefits, it was advancing at too quick a pace for researchers to continue safely.
“Over the last few months, I have become convinced that fully addressing the risks requires even more prudence — not just investing in risk prevention, but pacing the rate of capabilities advancement so that risk prevention has time to keep up,” Mr. Amodei said. “We must slow the pace at which we improve the capabilities of A.I. models. Progress will still seem fast, and we must make wise use of the time we gain.” […] “Left unchecked, it could outrun our ability to understand and control these systems, and so must be pursued very carefully, if at all,” Mr. Amodei said.
[…] In his essay on Saturday, Mr. Amodei suggested actions that the industry might take to slow down the pace of development.
Mr. Amodei said all A.I. labs could agree to third-party technology assessments from “embedded evaluators,” or outside specialists who can verify best safety practices across companies. He also suggested that countries with democratic governance systems coordinate to create safety standards, which could take the form of regulatory action. He added that it would probably require a global effort working with other nations, including authoritarian ones, to properly coordinate a slowdown.
Mr. Amodei stressed in his essay that he still finds A.I. capable of bringing “incredible benefits” to humanity, including potentially curing diseases and accelerating economic growth. But even so, Mr. Amodei said the risks of A.I. were too great to not proceed with extreme caution. “The measures I propose to advance the frontier at a safe pace will not be easy,” Mr. Amodei wrote. “But I believe we owe it to humanity to try.” Amodei’s essay comes just hours after Bloomberg reported that Sam Altman told OpenAI employees the company is open to slowing the pace of AI development amid similar concerns.
Read more of this story at Slashdot.
Tech
How and When to Use Them
A virtual card number is a substitute payment number linked to an eligible underlying card account. You can use it for supported online or in-app purchases without giving the merchant the number printed on your physical card, which can reduce the usefulness of exposed payment credentials if a merchant is later compromised.
It does not usually create a separate account or credit line, make an unsafe merchant trustworthy, or add new dispute rights by itself. Its main benefit is isolating the credential used at checkout from the number on the physical card.
How Virtual Card Numbers Work
A virtual card number replaces the card number you would normally type at checkout with a different number generated for an eligible account. Capital One describes its virtual card numbers as unique numbers linked to the underlying credit-card account, allowing eligible users to make online purchases without sharing the physical card number.
The number associated with the actual card account is commonly called the Primary Account Number, or PAN. A virtual-card system leaves the underlying account in place while presenting a substitute credential to the merchant.
In practical terms, the process usually works like this:
- An issuer or supported payment service generates a virtual card number for an eligible account.
- You use the substitute number at an online or in-app checkout instead of the number printed on the physical card.
- The merchant submits the virtual credential for authorization through the normal card-payment process.
- The virtual credential remains associated with the underlying account so the issuer can authorize and post the purchase there.
- The transaction appears on the underlying account rather than creating a separate balance or credit line.
Implementations differ. Capital One currently offers both general-use virtual numbers and eligible merchant-specific numbers. Its general-use number can work with multiple online merchants, while a merchant-specific number is restricted to one merchant. Capital One also notes that not every customer or card is eligible.
Google describes its virtual cards as digital versions of eligible cards that use randomly generated numbers instead of the actual card number. Google also says availability depends on participating banks or networks, supported countries or regions, and merchant acceptance.
A simple example is a physical card whose account number ends in 1234. A supported virtual-card service can provide a different number for checkout while the resulting purchase still belongs to the original account.
Virtual card numbers and tokenized digital wallets can both reduce exposure of the underlying card number, but they are not necessarily the same technical implementation or checkout experience.
A virtual card number may look like an ordinary card number that you or a browser autofill tool enters into an online checkout. A digital wallet can instead use a payment token associated with a device, merchant, or payment context.
EMVCo describes payment tokenization as replacing a Primary Account Number with an alternative value that can be constrained to a particular merchant, device, or payment scenario. That explains the broader security principle, but not every product marketed as a virtual card should automatically be described as an EMV payment token.
The distinction matters because different products support different controls. Some virtual numbers stay the same across many purchases, others are tied to one merchant, and wallet tokens can be restricted to a device or payment environment.
A virtual card vs digital wallet comparison matters when choosing between a manually entered substitute card number and a wallet-based payment token.
Our Recommendations
1
When Buying From a New but Legitimate Online Store
Best for: reducing exposure of your physical card number when trying a retailer you have independently checked but have not used before.
A virtual number can be useful when you trust a merchant enough to make a purchase but would rather not give it the reusable number printed on your card.
Where the issuer supports merchant-specific numbers, the containment can be stronger. Capital One states that its merchant-specific virtual numbers are valid only with the assigned merchant, so that credential cannot simply be reused at another store through the same feature.
The benefit is credential containment, not merchant verification. A virtual number can still successfully authorize a payment to a dishonest seller if you approve the transaction.
The Federal Trade Commission recommends checking unfamiliar online sellers independently and warns that an encrypted website alone does not prove that the seller is legitimate.
Important limitation: a virtual card number can reduce exposure of your physical card number, but it cannot establish whether a merchant is legitimate or whether an order will be fulfilled.
2
When a Merchant Stores Your Card for Future Purchases
Best for: isolating one merchant from the number on your physical card when the issuer supports merchant-specific virtual credentials.
Saved-card checkout is convenient, but it means a merchant or its payment provider retains a payment credential associated with your account. A merchant-specific virtual number can give that merchant a dedicated substitute credential rather than the number printed on your physical card.
Capital One currently lets eligible users create multiple merchant-specific virtual numbers, each intended for one merchant, and manage those credentials separately.
This can be useful if you shop repeatedly at one website and want the stored credential for that retailer separated from the card number you use elsewhere.
Important limitation: merchant-specific numbers are implementation-dependent. Other virtual-card services may provide one substitute number that works across multiple merchants.
3
For Subscriptions You Want to Isolate
Best for: recurring payments when the issuer supports a persistent virtual number that can be managed separately.
A persistent virtual number can be useful for subscriptions because the merchant can keep charging the substitute credential without receiving the physical card number.
Capital One states that eligible virtual cards can be used for recurring payments and subscriptions. Its current management tools also let eligible users lock, replace, or delete virtual numbers separately from ordinary purchases made with the physical card number.
That can isolate one recurring merchant from unrelated card activity. For example, a merchant-specific credential used only for one subscription is easier to identify and manage than one physical card number shared across many merchants.
There is an operational consequence. Capital One explicitly states that recurring payments associated with a deleted virtual number will be declined, so legitimate payment details may need to be updated afterward.
Deleting a payment credential is not the same as canceling a contract or subscription. If the service has a cancellation process, follow it rather than relying on failed future charges.
Important limitation: deleting or replacing a virtual number can interrupt legitimate recurring payments, and issuer behavior varies.
4
When You Want Online Purchases Separated From Your Physical Card Number
Best for: routine e-commerce when you want merchants to receive a substitute credential instead of the number printed on your card.
This is the broadest everyday use case. Instead of entering the physical card number at each supported checkout, a virtual-card system can provide a different credential while keeping the same underlying account.
American Express says its eligible virtual-card implementation does not share the physical card details with the merchant and dynamically supplies the security code used at checkout. Purchases still appear as regular transactions on the underlying Amex account.
This illustrates the central trade-off: the credential shown to the merchant changes, but the underlying account remains. Spending still posts to that account and remains subject to its credit limit, balance, issuer rules, and other account terms.
Capital One likewise states that its virtual cards are tied to the associated physical-card account. If the physical card is locked, transactions on its virtual cards will not go through.
Important limitation: a virtual number does not separate you from the underlying account’s balance, credit limit, fees, interest, or repayment obligations.
5
For Controlled Business or Vendor Payments
Best for: organizations that need payment credentials with transaction or policy controls.
Commercial virtual cards can do more than conceal a broader funding-account number. Business systems can generate credentials for specific transactions, suppliers, or workflows and apply controls to their use.
Mastercard’s current commercial virtual-card material describes unique virtual numbers, workflow approvals, and controls defining how, where, and when a virtual number may be used. Its commercial platform also supports spending limits and restrictions.
This can let a business provide a constrained payment credential for a supplier or purchase without exposing the broader funding-account number.
These are commercial virtual-card capabilities. They should not be assumed to exist on an ordinary consumer virtual card merely because both products use the same general terminology.
Important limitation: amount restrictions, approval workflows, merchant controls, and similar features are commercial product capabilities, not universal consumer virtual-card features.
When a Virtual Card Number Is a Poor Fit
A substitute credential is useful only when the merchant and the later transaction lifecycle can support it. In some cases, the physical card number or another payment method is more practical.
- The merchant does not accept virtual cards. Google says certain merchant sites and apps opt out of virtual-card acceptance, while Capital One also notes that some merchants may reject virtual numbers.
- You may need to show the original card later. Capital One warns that a virtual number may be unsuitable when a travel reservation, hotel, event, or similar transaction requires the customer to present or swipe the card used for booking because the virtual and physical numbers do not match.
- Your account is not eligible. Availability can depend on the issuer, card, account status, network, country or region, browser, device, and payment platform.
- A changing credential would interfere with repeat billing. Persistent virtual numbers can support subscriptions, but short-lived or replaced credentials can cause later charges to fail.
- You are treating it as protection from a fraudulent seller. A virtual number can still authorize a transaction that you willingly approve.
If an eligible virtual card unexpectedly fails, a virtual card decline can result from merchant acceptance, an expired credential, a billing-address mismatch, insufficient available credit, or issuer restrictions.
How to Get a Virtual Card Number
There is no universal setup process because availability is controlled by the issuer, network, or supported payment platform. Common access methods include an issuer’s website or mobile app and supported browser or Android autofill features.
For example, Capital One currently lets eligible cardholders access virtual numbers through its website and mobile app. Google supports virtual-card enrollment for eligible cards from participating banks or networks in supported regions. American Express lets eligible U.S. cardholders enroll supported cards for its Google-based virtual-card feature.
Before relying on a virtual number, check:
- whether your exact card or account is eligible;
- whether identity verification or enrollment is required;
- whether the credential works only online or in supported apps;
- whether it is general-use, merchant-specific, persistent, or temporary;
- whether recurring payments are supported;
- how the issuer lets you lock, replace, or delete it; and
- what happens when the underlying card is locked, replaced, or closed.
Do not assume two issuers implement virtual cards the same way. Capital One, American Express, Google-supported issuers, and commercial Mastercard systems expose different eligibility rules, controls, and checkout behavior.
What a Virtual Card Does Not Protect You From
A virtual card number addresses one main problem: exposing the number associated with the underlying physical card. It does not eliminate the other ways online payments can fail.
- Fraudulent merchants: a substitute number can still authorize a purchase from a scam seller.
- Account takeover: an attacker who gains access to your issuer account or authentication method may present a different problem from stolen merchant-side card data.
- Underlying debt: a virtual credit-card number is still connected to the underlying credit account, so balances, interest, fees, and repayment obligations remain.
- Merchant disputes: using a virtual number does not automatically create stronger refund, chargeback, or statutory rights than the underlying account already provides.
- Compatibility problems: the feature may not be available for the card, platform, region, or merchant involved in the transaction.
If the goal is broader than concealing a physical card number, compare alternatives to credit cards for online payments by credential exposure, reachable funds, dispute options, and debt risk.
A virtual card number is most useful when you already intend to make a legitimate online purchase and want the merchant to receive a substitute credential instead of your physical card number. Used in that role, it can reduce credential-reuse risk without changing the account that ultimately pays for the transaction.
Tech
Sam Altman backs Dario Amodei’s call to slow down, and says OpenAI will do the same
Sam Altman says OpenAI will match Anthropic’s commitment to give independent evaluators employee-like access, a day after Dario Amodei asked the industry to slow down and asked Washington for a narrow antitrust waiver so competitors could coordinate. Europe has no waiver to grant, because Brussels abolished individual exemptions in 2004, and the only soft safe harbour it has since written for competitor standards covers sustainability.
OpenAI has said it will match Anthropic’s safety commitment, a day after Dario Amodei asked the industry to slow down. “I agree with Dario that we need to pace the frontier,” Sam Altman wrote, as Axios reported.
He called independent evaluators with employee-like access a great idea, said OpenAI would do the same, and promised more to share soon. Pacing had been a primary topic of discussion inside OpenAI in recent weeks, he added.
Elon Musk, who runs xAI, was briefer. “Dario is right,” he posted.
Amodei’s essay on Saturday asked frontier labs to let outside teams verify their safety work from inside their offices. Anthropic’s own version gives them desks, badges, company laptops and the right to publish what they find. It also asked Washington for something harder.
He wants a narrow waiver, so that competitors can hold safety conversations without the conversations themselves becoming the legal problem. Governments need not take part, he wrote, only permit the discussions.
Two of the largest labs have now agreed a common commitment in public, inside a day. That is the first rung of the three-step plan Amodei set out.
In Europe there would be nobody to ask.
The Commission stopped granting individual exemptions when Regulation 1/2003 took effect in 2004. Before that, companies notified their agreements to Brussels and waited. Competitors now assess their own against Article 101 and live with the answer.
What Europe has instead is a precedent. It rewrote its horizontal cooperation guidelines in 2023, expanding them from 72 pages to 167.
The new text carries a 21-page chapter on sustainability agreements, including a soft safe harbour for standards that meet six conditions. It also reworked the chapters on standardisation and on information exchange between rivals.
That is close to the machinery Amodei is asking America to build. Europe has already built it once, for a different public good.
There is no equivalent chapter for safety standards, and nobody has asked for one.
His essay does not mention Europe, and neither did Altman’s reply. The Commission’s own tech chief said last week that global rules are needed.
Tech
AT&T store worker gets 16 months inside for SIM-swap side hustle
cyber-crime
Phone shop staffer claimed he was paid less than $4k for in his part attacks leading to combined intended losses of $600,000
A former AT&T retail worker who used his system access to hijack customers’ phone numbers for cybercriminals has been sentenced to 16 months in federal prison.
Kenneth Carter, 44, carried out the SIM swaps at a store in Portland, Oregon, , allowing the criminals to intercept authentication codes and raid victims’ bank accounts.
Court documents show that Carter worked with at least three other people in the scheme, which ran between May 2018 and November 2019, and caused nearly $600,000 in intended losses.
Co-conspirator One, described in court documents as the operation’s main “hacker,” identified victims with online bank accounts, gathered their personal data, and sent it to Carter, who could reassign their phone numbers.
Carter abused his access to AT&T’s systems to transfer victims’ phone numbers to devices controlled by the other criminals. His role was described as “instrumental to the scheme.”
Co-conspirator Two and Co-conspirator Three would walk into the store and impersonate the victim whose number they planned to SIM-swap, and Carter would reassign the number to a phone they controlled – usually a “cheap flip phone.”
Once the swap was complete, the criminals could use the flip phone to intercept SMS-based 2FA codes and password reset messages, take over the victim’s bank account, and steal funds.
The intercepted codes were relayed to Co-conspirator One, who used them to access the victims’ bank accounts.
Court documents also refer to “an unnamed family member” who held a minor role in the scheme. They were described as someone “who occasionally passed along the two-step authentication codes” to Co-conspirator One.
According to the Justice Department, three victims incurred combined intended losses of $593,963.77, and Carter admitted carrying out additional unauthorized SIM swaps.
Carter’s plea agreement [PDF] included details of three SIM swap attacks he helped execute. Only one victim suffered an actual loss: $99,528.33 transferred to a Portuguese bank account.
The conspirators attempted to transfer $247,652.74 and $246,782.70 from the other two victims, but the banks’ fraud controls blocked both transactions.
Prosecutors said Carter was paid between $1,000 and $2,000 per swap, although he maintained that he earned less than $4,000 in total.
Law enforcement raided Carter’s residence in November 2019, finding copies of the personal data provided to him to carry out the SIM swaps, including the Social Security number of the one victim whose money was successfully stolen.
AT&T terminated Carter’s employment at an unspecified date in 2019. He pleaded guilty on March 24, 2026, to conspiracy to commit wire fraud and bank fraud.
In a letter to United States District Judge Stanley Blumenfeld, Jr., Carter described his offending as “a one-off situation that truly was a mistake.”
He explained that he takes care of his mother-in-law, who spends much of her time in a hospital bed located in the family living room, and two daughters, one of whom has schizophrenia.
Carter claimed that he was “propositioned by my in-law cousin with an opportunity for me to make a little extra money for my family.”
“I was told I wouldn’t have to do anything but do my job,” he added. “So, I was under the impression that this was a harmless act. As far as I knew at the time, I was never a part of a ring, nor was this an out-of-state matter.
“My incident was isolated to just Portland, OR, and the incident occurred while I was employed by AT&T. I later learned that what I found myself a part of was criminal, and I also learned after the fact the severity of what my co-conspirators were doing with the flip phones I sold under customer accounts.”
Federal prosecutors were unmoved by Carter’s letter. In their response [PDF], US attorneys argued that Carter had not provided enough evidence to show he was unaware of the criminal activity’s scope or nature, or that he was less culpable than the “hacker” who coordinated the operation.
In addition to the 16-month sentence, Judge Blumenfeld, Jr. ordered Carter to pay $99,528 in restitution. ®
-
Tech5 days agoMemory prices are slowing because buyers ran out of money
-
Business3 days agoMicron Stock Climbs Above $1,031 as AI Memory Crunch and a $50 Billion Outlook Fuel the Rally
-
Business3 days agoAMD Stock Climbs After Management Lifts 2027 Data Center Outlook Toward $70 Billion in AI Sales
-
Crypto World4 days agoBitcoin price risks $76K drop as $78K support weakens
-
Crypto World4 days agoRobinhood Stock: How To Take Advantage With Reduced Risk
-
Crypto World4 days agoEthereum price stalls below $2,500 as ADX drops to 11
-
Fashion1 day agoWeekend Open Thread – Corporette.com
-
NewsBeat5 days agoEngland up in reading, maths and science rankings as Scotland and Wales dip
-
Crypto World2 days agoXAG/USD: Silver’s Short-Term Rally Meets Its Moment of Truth
-
Crypto World3 days ago2 Chip Stocks Broke Out This Week. Neither Was Nvidia
-
Crypto World2 days agoOKX launches 10x OpenAI, Anthropic X-Perps in Europe
-
Crypto World2 days agoDiesel Tops $6 a Gallon for the First Time as 28 States Set Records
-
Crypto World5 days agoIntel Stock Jumps 9% on Chip Price Hike Report, US Stake Gains $36 Billion
-
NewsBeat4 days agoWhat went right this week: an ‘historic’ fall in violent crime, plus more
-
Crypto World3 days agoBitcoin price risks $70K if $78K neckline breaks
-
Business4 days agoMeta debuts long-awaited personal AI agent, Muse
-
Crypto World4 days agoBitcoin price holds near $79K as cycle drawdowns narrow
-
Crypto World2 days ago
Ethereum Price Analysis: Consolidation at $2.5K Tests Momentum as On-Chain Activity Surges
-
Crypto World5 days agoPump Fun and Kraken delete Hunter Biden $LAPTOP promotion
-
Entertainment3 days agoCase Sees Major Update As Jury Deliberations Begin




You must be logged in to post a comment Login