defensescoop.com AAFES Investigates Suspicious Messages Targeting Military Customers
Article Content
- •AAFES is investigating suspicious messages sent to military customers via email and app.
- •Customers reported receiving emails with links to a fraudulent 'wish list' from AAFES.
- •Experts suggest a potential security breach due to the targeted nature of the messages.
The Army and Air Force Exchange Service (AAFES) is investigating suspicious messages sent to customers via email and its app, impersonating AAFES. Customers reported receiving emails with links to a 'wish list' from a fraudulent account. AAFES has alerted account holders and issued warnings on social media, advising them not to click on links or provide personal information. The organization is currently determining the origin and impact of these messages, noting a slight increase in customer inquiries. Experts suggest that the targeted nature of the messages could indicate a security breach either within AAFES or a third-party partner. AAFES operates over 5,500 facilities globally, serving around 30 million eligible customers, making the potential impact significant. The military community is frequently targeted by online scams, which often exploit sensitive information. AAFES has not confirmed the source of the messages but is treating the situation with urgency.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Army And Air Force Exchange Service in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…