{"success":true,"data":{"id":"fake-matter-smart-home-firmware-credential-harvest","label":"Fake Matter smart-home firmware credential harvest — impersonates Nest, Philips Hue, Aqara, SmartThings, or Amazon Echo with a \"mandatory Matter/Thread firmware update requires account re-authentication\" hook harvesting cloud credentials. Bitdefender Mar 2026; Malwarebytes Jan 2026; CISA 2026.","description":"Emails impersonating smart home device manufacturers (Nest/Google Home, Philips Hue, Aqara, Eve Home, Nanoleaf, IKEA Dirigera, SmartThings, Amazon Echo) claiming a mandatory firmware update is required for Matter or Thread connectivity, and directing users to \"re-authenticate\" to complete the firmware push — harvesting cloud account credentials. This is distinct from fake-smart-home-device-breach-lure (breach notification language). Matter 1.3–1.4 standard updates in 2025–2026 triggered legitimate firmware notifications; attackers cloned these emails to exploit user confusion. Bitdefender (March 2026) documented active campaigns; Malwarebytes noted a 300% increase in smart-home-brand phishing containing \"firmware,\" \"Matter,\" or \"Thread\" language.","tier":"danger","category":"phishing","isThin":false}}