Connect with us

%

Receiving Urgent Documents From Trusted Contacts? Experts Warn Of Malicious WhatsApp File Scam

Published

on

receiving-urgent-documents-from-trusted-contacts?-experts-warn-of-malicious-whatsapp-file-scam

Kaspersky warns WhatsApp users about malicious files sent by contacts. Photo Credit: Dimitri Karastelev / Unsplash

A multinational cybersecurity company has warned of a fast-spreading scam on WhatsApp that has already targeted users in various countries, including Spain and the UK. Kaspersky, a Russian cybersecurity and anti-virus provider company, has alerted users of the popular mobile app that hackers are using compromised accounts to send malicious files, disguised as important documents including invoices, payment notices, and statements.

How it works: A malicious file from your mum, best friend, or spouse

According to Kaspersky researcher Fareed Radzi, “Attackers are exploiting trust within messaging platforms by using compromised WhatsApp accounts to deliver malicious attachments that appear to originate from known contacts.”

The hackers break into the accounts and then send the malware to its contacts, meaning that, from the victim’s point of view, the malicious documents could appear to be coming from a friend, close family member, client, or colleague. For this reason, users would be far more likely to open the malware without suspecting anything.

To be specific, the malware is an attachment known as VBScript, and is carefully named to appear as if it is a financial report, account notice, or another important document that users would need to open.  According to India’s Cyber Crime Coordination Centre, which issued a similar warning to users, hackers often name these files things like “View Details” or “Invoice” to appear genuine.

A single click, compromising a whole WhatsApp account

Once the victim opens the file, it triggers a so-called “infection” that runs harmful components on the device from external servers. In many cases, the attackers can eventually gain control of the affected device, without the user realising it, through the installation of a remote access tool.

In short, a single click on a document is capable of compromising an entire WhatsApp account, as well as its contact list. So far, the scam is reported to have affected users in multiple countries, including Spain, the United Kingdom, India, Brazil, Mexico, Taiwan, Australia, Russia, Vietnam, and Malaysia. 

Who are the main targets of this scam and how can users stay safe?

According to the cybersecurity firm Quick Heal Technologies, WhatsApp-based malware scams are quickly evolving, with finance teams, senior executives, and accountants among the key targets. However, any user could fall victim to this scam, regardless of their job, age, or status.

Kaspersky, along with its warning, has also advised users to be very cautious of opening unexpected attachments, even if it comes from a close friend or family member. Specifically, the company warned against opening script or executable files, including VBS, EXE, BAT, and JS.

In general, it is also good practice to be wary of messages that urge immediate action, like messages that ask users to send money quickly or, in this case, review a document at once.

For users who are concerned they may have received a malicious document, the best way to verify its legitimacy is by calling the person who sent it and confirming it is genuine.

Otherwise, it is best to avoid opening the document completely, and report the incident to a local cyber crime or law enforcement official.

%

Fast Food Chain Soaring Beef Costs

Published

on

fast-food-chain-soaring-beef-costs

There is a reason Spain is now Five Guys’ most successful European market. People cannot get enough of those juicy burgers, generous fries and sugary sweet shakes, but for the chain, keeping portions unchanged during a period of soaring beef prices came at a steep cost. Here is how the burger giant hit record revenue while navigating an 83% drop in profits.

Record year for sales

Five Guys Spain has just smashed through the €100 million mark for the first time ever. Sales hit €105.9 million in 2025, up 10.4 per cent on the year before. That’s a huge deal for a brand that only landed in Spain back in 2016, and it means Spain is now the best-performing market Five Guys has anywhere in Europe, even though it’s one of the smallest countries the chain operates in.

Big knock in profits

Interestingly though more sales didn’t mean more money in the bank. Net profit dropped to just €698,327, a massive 83.2 per cent fall from the €4.16 million made the year before. Operating profit also slid, down 26.9 per cent to €4.9 million. The reason, beef got a lot more expensive, and rather than pass that cost onto customers, Five Guys chose to eat into its own margins instead. Recipes and portions stayed exactly the same, and toppings and sauces are still free.

A small price rise, but nothing else changed

Back in May 2025, the chain did slightly bump up its menu prices, roughly in line with inflation, just to help protect those margins. It’s keen to stress that nothing else changed. No smaller portions, no reformulated recipes, no charging extra for sauce. That’s a contrast to several other restaurant brands in Spain that have trimmed portions or added new charges over the past year.

Could you soon have one near you?

Only three new restaurants opened in 2025, a much slower pace than the eleven the year before, taking the total to 43 across Spain. New spots opened in Malaga and Benidorm, with Andalucia flagged as a particular focus for growth. Last month, Five Guys opened its first airport location, at Barcelona’s El Prat, hinting at more travel-hub openings to come. Next year, expect fresh openings across several regions, including the Balearic Islands. Since first arriving in Spain, the chain has opened an average of seven restaurants a year (aside from the pandemic years of 2020 and 2021), and bosses say that pace is set to pick up again from 2026 onwards, both on the mainland and the islands. Soon you could be tucking into that huge pile of seasoned fries and sipping on one of there shakes at a location near you.

Continue Reading

%

World Record Rowing Challenge

Published

on

world-record-rowing-challenge

Raising money for mental health support for military personnel Credit: Instagram/James_Priestley_

A British resident in Mallorca is preparing for a gruelling 12-hour rowing challenge that could see him break a Guinness World Records title while raising money for mental health support for military personnel, veterans and their families.

James Priestley, who moved to Mallorca just over two years ago, will attempt to row at least 153 kilometres on an indoor rowing machine on Saturday, October 3.

The challenge will take place at his new gym in Port d’Andratx, where he hopes to attract support from the local community as he attempts to complete a record-breaking endurance feat.

From SAS to rowing machine

Priestley is no stranger to extreme challenges. Originally from Leeds and Bradford, he previously worked in the property sector before entering Channel 4’s SAS: Who Dares Wins, which he won in 2020.

His latest challenge is particularly significant because it is an attempt to complete something he previously had to abandon.

In 2021, Priestley attempted the same 12-hour rowing challenge in Leeds. However, after nine hours and 45 minutes, an injury forced him to stop. The injury eventually required surgery.

Five years later, he has decided to try again, this time from Mallorca.

The current men’s record for the longest distance rowed on a Concept2 indoor rowing machine in 12 hours stands at 152.869 kilometres, meaning Priestley needs to exceed that distance to claim the title.

A challenge with a purpose

The attempt is not simply about setting a new sporting record.

Priestley co-founded VÕS HELP, a mental health support service aimed at serving military personnel, veterans, their families and anyone who needs someone to talk to.

The service connects users with trained counsellors and aims to reduce the time people have to wait before accessing support.

Priestley says the October challenge aims to raise enough money to fund 1,000 free mental health support calls.

He says each call costs around £20 through the service, compared with a significantly higher typical cost for professional support.

The organisation currently has around 1,000 counsellors and volunteers involved, according to Priestley.

Port d’Andratx community gym

The rowing attempt will also showcase Priestley’s new Port d’Andratx gym, which has been created with local residents in mind.

Rather than focusing solely on seasonal visitors, the facility is intended to operate throughout the year and provide a community-focused space offering personal training and fitness facilities.

The gym will be open to the public during the record attempt, with a second rowing machine positioned alongside Priestley.

That means members of the public will be able to join the challenge by rowing alongside him for part of the 12-hour effort.

The mayor of Andratx is also expected to attend during the final hour.

Two records in one day

Priestley is not stopping at the 12-hour target.

He also plans to attempt the eight-hour distance record during the same challenge, before continuing towards the 12-hour mark.

The former SAS winner admits the physical demands will be considerable, particularly because he does not have the physique or specialist rowing background of elite indoor rowers.

However, he believes the mental resilience developed during his time on SAS: Who Dares Wins could help him push through the toughest stages.

The challenge will begin at 7am on October 3 and continue until 7pm.

People wanting to support the fundraising effort can donate through VÕS HELP or visit the Port d’Andratx gym, where QR codes will be available during the event.

Continue Reading

%

50,000 Brits Caught Up In Huge Passport Scare. Did You Hand Over Your ID In Spain?

Published

on

50,000-brits-caught-up-in-huge-passport-scare.-did-you-hand-over-your-id-in-spain?

More than 50,000 British nationals were reportedly listed in records caught up in the cannabis club identity-document security scare. Credit: Max_555 / Shutterstock

If you have ever handed over your passport to join a cannabis club in Spain, you may want to pay attention to this.

More than 50,000 British nationals and around 12,000 Irish passport holders appear in records caught up in a huge security scare after almost one million passport and identity document scans were reportedly left accessible online.

A security researcher investigating the system identified 50,113 British nationals in the database, while fresh reporting by The Journal revealed that around 12,000 Irish passports were also among the records potentially exposed.

For anyone who remembers handing over their passport at one of these clubs, the obvious question is: was yours among them?

Why Spain is at the heart of the passport scare

Cannabis social clubs are particularly common in Spain, with estimates cited by The Journal putting their number at between 1,000 and 2,000 nationwide.

Unlike Amsterdam-style coffee shops, they generally operate as private associations. Prospective members may therefore be asked to register and prove their identity and age, sometimes by handing over a passport or another form of identification.

Some clubs used membership technology supplied by Cannabis Club Systems (CCS), an Irish-registered company formerly known as Nefos Solutions. Reception staff could upload customers’ identity documents to the system for verification, creating an enormous central collection of personal information.

Security researcher Sammy Azdoufal says the affected system contained 985,841 identity-document scans, including passports, identity cards and driving licences. His published account of the investigation lists 50,113 member records with British nationality.

However, not every British or Irish document necessarily came from a club in Spain. The researcher says the software was used by 377 clubs across Spain, the UK, Ireland, South Africa and elsewhere, although many were based in Spain.

How were the passports exposed?

According to the researcher, identity-document images were stored at predictable web addresses that did not require a login, password or security token. Anyone who understood the address pattern could potentially view the documents using an ordinary web browser.

That does not establish that criminals downloaded or misused the files. CCS disputes descriptions of the incident as a confirmed public data leak, saying it has found no verified evidence that personal information was extracted, published or distributed. Its investigation into the historical extent of any unauthorised access remains ongoing. The company says the reported vulnerabilities have been fixed and that the previously identified access points are no longer publicly accessible.

The Journal reported that Ireland’s Data Protection Commission is engaging with the Irish-registered company. The regulator has not made any finding of wrongdoing.

Spain has already warned about copying IDs

The case echoes something Spanish authorities have already been warning consumers about. As Euro Weekly News previously reported, businesses retaining complete copies of passports or identity cards can create risks that people may not consider when handing them over.

Spain’s Data Protection Agency says that, as a general rule, a complete copy of an identity document is not necessary simply to verify someone’s identity when entering a contract. However, it notes that sector-specific laws, including anti-money-laundering rules, can require copies in some circumstances.

One worrying aspect of the exposure is that passport details falling in to the wrong hands can make identity fraud and targeted scams considerably more convincing. Whilst another obviously sensitive element in this case is that the documents were connected to cannabis club memberships, potentially linking identifiable individuals with membership of a cannabis association.

Cybersecurity specialist Brian Honan told The Journal that such information could be exploited for scams or blackmail if it fell into the wrong hands.

Should British or Irish passport holders do anything?

There has been no reported blanket instruction telling affected British or Irish citizens to replace otherwise valid passports. Anyone who believes they may be affected should contact the club or CCS through official contact details rather than following links in unexpected messages. The UK’s National Cyber Security Centre advises people concerned about a data breach to remain alert for suspicious communications and check their accounts for unauthorised activity.

Be particularly cautious about unexpected emails, calls or messages containing genuine personal information. Never provide banking details, passwords or security codes simply because the person contacting you appears to know who you are.

If a physical passport has actually been lost or stolen, British citizens should use the government’s official lost or stolen passport service, while Irish citizens in Spain can follow the Embassy of Ireland’s guidance.

But for people whose passport is still safely sitting at home, the concern is different. 50,113 British nationals. Around 12,000 Irish passports. Almost one million identity document scans.

If you remember handing your passport across the reception desk at a cannabis club, you may now be wondering the same thing: Was yours one of them?

Continue Reading
Advertisement
Advertisement

Spanish Real Estate Agents

Tags

Trending

Copyright © 2017 Spanish Property & News