{"success":true,"data":{"id":"synthetic-kyc-reverification-credential-phish","label":"Synthetic KYC / AML re-verification credential phishing — impersonates a fintech or crypto platform with a post-incident KYC/AML re-verification narrative harvesting government ID scans + selfies + financial credentials. FinCEN/CFPB 2025; Abnormal Security Mar 2026; Cofense Feb 2026.","description":"Fraudulent KYC (Know Your Customer) / AML (Anti-Money Laundering) re-verification emails claiming a security incident or regulatory update requires the recipient to re-upload government-issued ID, selfies, and financial credentials to a fake compliance portal. Three-part detection: (1) KYC/AML re-verification brand language, (2) post-incident / regulatory-update justification, (3) document-upload / selfie-with-ID CTA with off-domain link. FinCEN and CFPB 2025 advisories documented a wave of synthetic-identity-recovery attacks targeting fintech / crypto / bank users; Abnormal Security March 2026 confirmed active campaigns. Harvests not just credentials but the raw materials for synthetic identity fraud.","tier":"danger","category":"phishing","isThin":false}}