{"id":59553,"date":"2026-06-03T15:47:23","date_gmt":"2026-06-03T15:47:23","guid":{"rendered":"https:\/\/zero.redgem.net\/?p=59553"},"modified":"2026-06-03T15:47:23","modified_gmt":"2026-06-03T15:47:23","slug":"we-found-this-fake-invoice-campaign-while-scammers-were-still-building-it","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=59553","title":{"rendered":"We found this fake-invoice campaign while scammers were still building it_MALWAREBYTES:25837C9966B4BAC9D5751BE5031B9FC8"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-06-03T20:05:07&#8243;,&#8221;description&#8221;:&#8221;A new batch of fake payment invoices is being staged right now, and we caught the campaign while it was still being put together. The emails impersonate PayPal, Amazon, and Geek Squad, and others, and they all share one goal: to scare you into calling a phone number where a fake \\&#8221;support agent\\&#8221; is waiting.\\n\\nWhat makes this wave unusual is that some of the templates we recovered still contained blank fields where the phone number and price should have been, while others were already complete and in circulation. We caught the campaign mid-rollout.\\n\\n## What&#8217;s the scam?\\n\\nIf you receive an email that looks like a receipt\u2014\u201cYour subscription renewed for $349,\u201d \u201cYou sent a payment of $598.96\u201d\u2014and it tells you to call a number to cancel or dispute the charge, stop.\\n\\nThere is no charge. The email exists to get you on the phone with a scammer who will then try to talk you into handing over remote access to your computer, your card details, or a \u201crefund\u201d that somehow requires you to send them money.\\n\\n  * ![](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2026\/06\/2026-06-02_144608.png)\\n  * ![](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2026\/06\/2026-06-02_144548_816f67.png)\\n  * ![](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2026\/06\/2026-06-02_144520_3f8b96.png)\\n  * ![](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2026\/06\/2026-06-02_144502.png)\\n\\n\\n\\nThis particular flavor is called a \u201cphantom invoice\u201d or \u201crefund\u201d scam, and the trick is psychological, not technical. That&#8217;s why these emails can often slip past spam filters: there\u2019s often no malicious attachment or link for security systems to analyze. The scam is in the phone number you&#8217;re urged to call.\\n\\nIf you didn\u2019t make the purchase, there\u2019s no need to call the number in the email to cancel it. Real companies don\u2019t pressure customers into resolving unexpected charges through unsolicited phone numbers.\\n\\nThe goal is simple: create enough concern to get you to call. You see a significant charge you don&#8217;t recognize, say $499, and your first instinct is to stop it. The invoice helpfully provides a number to call \\&#8221;if this wasn&#8217;t you.\\&#8221; So you call, and now you&#8217;re talking to the scammer.\\n\\nFrom there, the conversation usually leads to one of a few outcomes. They may ask you to install software so they can \\&#8221;fix\\&#8221; the charge, giving them access to your computer. They may ask for your card or bank details to \\&#8221;process the refund.\\&#8221; Or they may \\&#8221;accidentally\\&#8221; refund too much and ask you to send the difference back, usually by gift card or bank transfer.\\n\\nThe invoice is just the bait, while the phone call is the trap.\\n\\nThese emails are convincing, and some are already reaching inboxes. The good news is that simply receiving one doesn\u2019t put you at risk. The scam only works if it succeeds in getting you to call the number provided. If you recognize the message as fraudulent and delete it, the attack stops there.\\n\\nIf you did call the number and followed instructions from a scammer, run a virus scan and check your bank accounts. Change your critical passwords, enable multi-factor authentication (MFA), and make sure your security software is up to date.\\n\\n## How we caught it half-built\\n\\nMost scam investigations start after the damage is done. This one was different. We came across a cluster of nearly identical invoice templates that were clearly part of the same kit, and several of them were incomplete.\\n\\nWhere a finished scam email would show a phone number, some of these showed the literal text `#TFN#` instead, which is just a placeholder. (\\&#8221;TFN\\&#8221; is the scammers&#8217; shorthand for toll-free number, the callback line they route victims to.) Others left the price as `#PRICE#`, the date as `#DATE#`, and the recipient as `#EMAIL#`. These are merge fields\u2014the blanks a bulk-sending tool fills in automatically before a campaign goes out.\\n\\nFinding those placeholders still in place told us that the operation was still being assembled. Some templates were still half-finished, while others were already complete and carrying live callback numbers. We&#8217;d caught the campaign mid-rollout, between being built and fully launched.\\n\\n## Why these invoices look believable\\n\\nThe scammers use familiar brands such as PayPal, Amazon, and Geek Squad. They&#8217;re companies people expect to receive receipts and renewal notices from, which lowers suspicion.\\n\\nThe charges are also carefully chosen. Amounts in the few-hundred-dollar range are large enough to cause concern but still seem plausible as a subscription renewal or online purchase.\\n\\nMany messages add urgency, telling recipients to call quickly to dispute or cancel the charge. This pressure is designed to stop people from verifying the transaction independently.\\n\\nSome invoices even combine trusted brands, such as claiming a payment was sent through PayPal to Amazon. Referencing multiple well-known companies makes the message appear more credible.\\n\\n## **How to spot a fake invoice**\\n\\nThe good news is that these scams share warning signs. Once you know what to look for, they get a lot easier to catch. Watch for any of these:\\n\\n  * **A charge you don\u2019t remember making.** If you don&#8217;t recognize the charge, verify it independently through your account or bank. If there&#8217;s no record of it, the invoice is likely a lure designed to get you to call.\\n  * **A ticking clock.** \u201cCall within 12 hours,\u201d \u201ccancel before it renews,\u201d or \u201cact immediately\u201d provide fake urgency designed to stop you thinking. Real billing problems can wait while you check.\\n  * **Brands you trust, used as cover.** The more familiar the logo, the less carefully people read. Scammers borrow trust they didn\u2019t earn.\\n  * **Odd details that don\u2019t quite fit.** A PayPal email \u201cfrom\u201d Amazon, a stray address that belongs to no one, or slightly off wording. Trust the small things that feel wrong.\\n  * **Pressure to keep you on the phone.** Once you call, a real company would never stop you from hanging up to verify, but a scammer will.\\n\\n\\n\\nIf even one of these is present, treat the whole message as suspicious.\\n\\nRemember the single rule that defeats this entire scam: A genuine company will never rush you onto a call to undo a payment you never made. If you\u2019re not sure whether a charge is real, close the email and check your account the normal way: by typing the company\u2019s website into your browser yourself, or calling the number on the back of your bank card.\\n\\n**Pro tip:**Malwarebytes Scam Guard can help spot scams like these and guide you in what to do next, while Browser Guard will block you from accessing scam websites. \\n\\n## What to do if one of these lands in your inbox\\n\\nIf you receive a suspicious invoice like the ones described here, take a few simple precautions:\\n\\n  * **Don &#8216;t call the number. **That&#8217;s the core of the scam. Legitimate refunds or cancellations don&#8217;t require you to call a number from an unsolicited receipt.\\n  * **Don &#8216;t reply or click anything. **Treat the message as suspicious, even if it looks legitimate.\\n  * **Verify charges independently.** If you&#8217;re concerned a charge might be real, log in directly to PayPal, your bank, or the retailer by typing the address yourself and reviewing your transaction history.\\n  * **Report it.** Forward suspected phishing emails to the impersonated company&#8217;s abuse address and, in the US, report them to the FTC at `reportfraud.ftc.gov`. Reporting helps disrupt scam operations.\\n  * **If you already called, end the conversation.** Don&#8217;t install any software they recommend. If you granted remote access or shared payment information, contact your bank immediately and run a trusted security scan on your device.\\n  * **Be wary of urgency.** Phrases like \\&#8221;within 12 hours\\&#8221; or \\&#8221;cancel now\\&#8221; are designed to pressure you into acting before you think. Take the time to verify the claim independently.\\n\\n\\n\\nScammers are increasingly shifting to tactics that software can&#8217;t easily inspect. A phone number in an email is difficult for security tools to evaluate, and the actual scam happens over a phone call instead of through a malicious link or attachment.\\n\\nThat&#8217;s why finding this campaign during rollout matters. Instead of seeing the damage afterward, we got a look at the preparation: unfinished templates, incomplete details, and the scam kit before it was fully deployed.\\n\\nThe best defense is simple: if an unexpected invoice tells you to call a number immediately, stop and verify the charge independently first.\\n\\n## Indicators of compromise\\n\\n### Domains\\n\\n`invoicepdfin[.]xyz`\\n\\n`invoicepdfus[.]xyz`\\n\\n`invoicepdfusa[.]xyz`\\n\\n`invoicerep[.]xyz`\\n\\n`invoicestatement[.]xyz`\\n\\n`invoicestm[.]xyz`\\n\\n### Callback numbers\\n\\n`804-392-2793`\\n\\n`801-640-8589`\\n\\n* * *\\n\\n### **Something feel off? Check it before you click.  ** \\n\\n**Malwarebytes Scam Guard**  helps you analyze suspicious links, texts, and screenshots instantly.  \\n\\nAvailable with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  \\n\\nTry it free \u2192&#8221;,&#8221;published&#8221;:&#8221;2026-06-03T18:05:19&#8243;,&#8221;modified&#8221;:&#8221;2026-06-03T18:05:19&#8243;,&#8221;type&#8221;:&#8221;malwarebytes&#8221;,&#8221;title&#8221;:&#8221;We found this fake-invoice campaign while scammers were still building it&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;MALWAREBYTES:25837C9966B4BAC9D5751BE5031B9FC8&#8243;,&#8221;bulletinFamily&#8221;:&#8221;blog&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[],&#8221;sourceData&#8221;:&#8221;&#8221;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:0,&#8221;severity&#8221;:&#8221;NONE&#8221;,&#8221;vector&#8221;:&#8221;NONE&#8221;,&#8221;version&#8221;:&#8221;NONE&#8221;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/www.malwarebytes.com\/blog\/threat-intel\/2026\/06\/we-found-this-fake-invoice-campaign-while-scammers-were-still-building-it&#8221;,&#8221;category_name&#8221;:&#8221;News&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-06-03T20:05:07&#8243;,&#8221;description&#8221;:&#8221;A new batch of fake payment invoices is being staged right now, and we caught the campaign while it was still being put together. The&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[6,8,12,115,13,33,7,11,5],"class_list":["post-59553","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-cve","tag-cvss","tag-exploit","tag-malwarebytes","tag-news","tag-none","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>We found this fake-invoice campaign while scammers were still building it_MALWAREBYTES:25837C9966B4BAC9D5751BE5031B9FC8 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=59553\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"We found this fake-invoice campaign while scammers were still building it_MALWAREBYTES:25837C9966B4BAC9D5751BE5031B9FC8 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2026-06-03T20:05:07&#8243;,&#8221;description&#8221;:&#8221;A new batch of fake payment invoices is being staged right now, and we caught the campaign while it was still being put together. The...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=59553\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-03T15:47:23+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=59553#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=59553\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"We found this fake-invoice campaign while scammers were still building it_MALWAREBYTES:25837C9966B4BAC9D5751BE5031B9FC8\",\"datePublished\":\"2026-06-03T15:47:23+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=59553\"},\"wordCount\":1676,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"exploit\",\"malwarebytes\",\"news\",\"NONE\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=59553#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=59553\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=59553\",\"name\":\"We found this fake-invoice campaign while scammers were still building it_MALWAREBYTES:25837C9966B4BAC9D5751BE5031B9FC8 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-06-03T15:47:23+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=59553#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=59553\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=59553#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"We found this fake-invoice campaign while scammers were still building it_MALWAREBYTES:25837C9966B4BAC9D5751BE5031B9FC8\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"We found this fake-invoice campaign while scammers were still building it_MALWAREBYTES:25837C9966B4BAC9D5751BE5031B9FC8 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=59553","og_locale":"en_US","og_type":"article","og_title":"We found this fake-invoice campaign while scammers were still building it_MALWAREBYTES:25837C9966B4BAC9D5751BE5031B9FC8 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2026-06-03T20:05:07&#8243;,&#8221;description&#8221;:&#8221;A new batch of fake payment invoices is being staged right now, and we caught the campaign while it was still being put together. The...","og_url":"https:\/\/zero.redgem.net\/?p=59553","og_site_name":"zero redgem","article_published_time":"2026-06-03T15:47:23+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=59553#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=59553"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"We found this fake-invoice campaign while scammers were still building it_MALWAREBYTES:25837C9966B4BAC9D5751BE5031B9FC8","datePublished":"2026-06-03T15:47:23+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=59553"},"wordCount":1676,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","exploit","malwarebytes","news","NONE","Security","tapic","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=59553#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=59553","url":"https:\/\/zero.redgem.net\/?p=59553","name":"We found this fake-invoice campaign while scammers were still building it_MALWAREBYTES:25837C9966B4BAC9D5751BE5031B9FC8 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-06-03T15:47:23+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=59553#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=59553"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=59553#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"We found this fake-invoice campaign while scammers were still building it_MALWAREBYTES:25837C9966B4BAC9D5751BE5031B9FC8"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/59553","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=59553"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/59553\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=59553"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=59553"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=59553"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}