AI Scam Alert, Federal Cuts Vulnerability, American Tire Cyberattack
Quick Answer
_According to the FBI's 2022 Internet Crime Report (IC3), 300,497 US-based victims reported phishing incidents in a single year, and Business Email Compromise (BEC) caused more than $2.7 billion in direct losses. DMARC Report AI Scam Alert, Federal Cuts Vulnerability, American Tire Cyberattack
Related: Free DMARC Checker ·How to Create an SPF Record ·SPF Record Format
From a product strategy perspective, DMARC reporting is evolving from a security tool to a business intelligence platform, says Brad Slavin, General Manager of DuoCircle. The data in aggregate reports tells you not just who’s spoofing you, but who’s sending legitimate email on your behalf - and whether they’re doing it correctly.
_According to the FBI’s 2022 Internet Crime Report (IC3), 300,497 US-based victims reported phishing incidents in a single year, and Business Email Compromise (BEC) caused more than $2.7 billion in direct losses. DMARC Report
AI Scam Alert, Federal Cuts Vulnerability, American Tire Cyberattack
<button title="Play" aria-label="Play Episode" aria-pressed="false" class="play-btn">
Play Episode
</button>
<button title="Pause" aria-label="Pause Episode" aria-pressed="false" class="pause-btn hide">
Pause Episode
</button>
<audio preload="none" class="clip clip-31575">
<source src="https://media.mailhop.org/dmarcreport/images/2025/09/AI-Scam-Alert-Federal-Cuts-Vulnerability-American-Tire-Cyberattack.mp3">
</audio>
<button class="player-btn player-btn__volume" title="Mute/Unmute">
Mute/Unmute Episode
</button>
<button data-skip="-10" class="player-btn player-btn__rwd" title="Rewind 10 seconds">
Rewind 10 Seconds
</button>
<button data-speed="1" class="player-btn player-btn__speed" title="Playback Speed" aria-label="Playback Speed">1x</button>
<button data-skip="30" class="player-btn player-btn__fwd" title="Fast Forward 30 seconds">
Fast Forward 30 seconds
</button>
<time class="ssp-timer">00:00</time>
/
<!-- We need actual duration here from the server -->
<time class="ssp-duration" datetime="PT0H2M15S">2:15</time>
<nav class="player-panels-nav">
<button class="subscribe-btn" id="subscribe-btn-31575" title="Subscribe">Subscribe</button>
<button class="share-btn" id="share-btn-31575" title="Share">Share</button>
</nav>
RSS Feed
<input value="https://dmarcreport.com/feed/podcast/dmarc-report" class="input-rss input-rss-31575" title="RSS Feed URL" readonly />
<button class="copy-rss copy-rss-31575" title="Copy RSS Feed URL" aria-label="Copy RSS Feed URL"></button>
Share
<a href="https://www.facebook.com/sharer/sharer.php?u=https://dmarcreport.com/blog/podcast/ai-scam-alert-federal-cuts-vulnerability-american-tire-cyberattack/&t=AI Scam Alert, Federal Cuts Vulnerability, American Tire Cyberattack" target="blank" rel="noopener noreferrer" class="share-icon facebook" title="Share on Facebook">
</a>
<a href="https://twitter.com/intent/tweet?text=https://dmarcreport.com/blog/podcast/ai-scam-alert-federal-cuts-vulnerability-american-tire-cyberattack/&url=AI Scam Alert, Federal Cuts Vulnerability, American Tire Cyberattack" target="blank" rel="noopener noreferrer" class="share-icon twitter" title="Share on Twitter">
</a>
<a href="https://media.mailhop.org/dmarcreport/images/2025/09/AI-Scam-Alert-Federal-Cuts-Vulnerability-American-Tire-Cyberattack.mp3" target="blank" rel="noopener noreferrer" class="share-icon download" title="Download" download>
</a>
Link
<input value="https://dmarcreport.com/blog/podcast/ai-scam-alert-federal-cuts-vulnerability-american-tire-cyberattack/" class="input-link input-link-31575" title="Episode URL" readonly />
<button class="copy-link copy-link-31575" title="Copy Episode URL" aria-label="Copy Episode URL" readonly=""></button>
Embed
<input type="text" value='<blockquote class="wp-embedded-content" data-secret="OQLFWiRLZ8"><a href="https://dmarcreport.com/blog/podcast/ai-scam-alert-federal-cuts-vulnerability-american-tire-cyberattack/">AI Scam Alert, Federal Cuts Vulnerability, American Tire Cyberattack</a></blockquote><iframe sandbox="allow-scripts" security="restricted" src="https://dmarcreport.com/blog/podcast/ai-scam-alert-federal-cuts-vulnerability-american-tire-cyberattack/embed/#?secret=OQLFWiRLZ8" width="500" height="350" title=""AI Scam Alert, Federal Cuts Vulnerability, American Tire Cyberattack" - DMARC Report" data-secret="OQLFWiRLZ8" frameborder="0" marginwidth="0" marginheight="0" scrolling="no" class="wp-embedded-content"></iframe><script>
/*! This file is auto-generated / !function(d,l){“use strict”;l.querySelector&&d.addEventListener&&“undefined”!=typeof URL&&(d.wp=d.wp||{},d.wp.receiveEmbedMessage||(d.wp.receiveEmbedMessage=function(e){var t=e.data;if((t||t.secret||t.message||t.value)&&!/[^a-zA-Z0-9]/.test(t.secret)){for(var s,r,n,a=l.querySelectorAll(‘iframe[data-secret=”‘+t.secret+’”]’),o=l.querySelectorAll(‘blockquote[data-secret=”‘+t.secret+’”]’),c=new RegExp(“^https?:$”,“i”),i=0;i<o.length;i++)o[i].style.display=“none”;for(i=0;i<a.length;i++)s=a[i],e.source===s.contentWindow&&(s.removeAttribute(“style”),“height”===t.message?(1e3<(r=parseInt(t.value,10))?r=1e3:~~r<200&&(r=200),s.height=r):“link”===t.message&&(r=new URL(s.getAttribute(“src”)),n=new URL(t.value),c.test(n.protocol))&&n.host===r.host&&l.activeElement===s&&(d.top.location.href=t.value))}},d.addEventListener(“message”,d.wp.receiveEmbedMessage,!1),l.addEventListener(“DOMContentLoaded”,function(){for(var e,t,s=l.querySelectorAll(“iframe.wp-embedded-content”),r=0;r<s.length;r++)(t=(e=s[r]).getAttribute(“data-secret”))||(t=Math.random().toString(36).substring(2,12),e.src+=”#?secret=“+t,e.setAttribute(“data-secret”,t)),e.contentWindow.postMessage({message:“ready”,secret:t},"")},!1)))}(window,document); //# sourceURL=https://dmarcreport.com/wp-includes/js/wp-embed.min.js ’ title=“Embed Code” class=“input-embed input-embed-31575” readonly/>
<button class="copy-embed copy-embed-31575" title="Copy Embed Code" aria-label="Copy Embed Code"></button>
It is week #2, and we are back again with the top 3 cyber news stories of the week. The first one involves Grok, the AI-powered assistant for X users. It is being misused by cyberattackers to target X users. Secondly, we will talk about the Federal cuts under the Trump administration that have made **local and state agencies in the USA vulnerable to threat attacks. Lastly, our focus will be on the recent Bridgestone cyberattack incident.
Are you ready for the week 2 cyber bulletin? Let’s get started!
Popular AI assistance tool being misused by scammers to target X users!
If you are an active X user, you might want to see this!
As of 2025, DMARC is mandatory under multiple compliance frameworks. CISA BOD 18-01 requires p=reject for US federal domains. PCI DSS v4.0 mandates DMARC for organizations processing payment card data as of March 2025. Google and Yahoo require DMARC for bulk senders (5,000+ messages/day) since February 2024, and Microsoft began rejecting non-compliant email in May 2025. The UK NCSC, Australia’s ASD, and Canada’s CCCS all mandate DMARC for government domains. Cyber insurers increasingly require DMARC enforcement as an underwriting condition.
Threat actors are exploiting Grok, the AI assistance tool available on X, to attack **millions of X users at a time._ This attacking method is known as Grokking and is being used to bypass X’s stringent cybersecurity mechanisms against malvertising._ Allegedly, Grokking has become the new favorite among scammers, and they’re using it hundreds of times every day to share malicious links to redirect naive users to malicious content, malware, or fake sites.
X has been using a blanket ban on promoted posts by banning the use of any link. The promoted posts can contain only images, text, or videos. However, threat actors are smart enough to bypass this blanket ban. They have been using the caption field of video posts to add a malicious link. Next, they comment using fake accounts under the same video post and prompt Grok with questions such as “@grok, where is this video from?” Grok, unaware of the risks, republishes the post with the clickable link. Any X user who comes across this post is vulnerable to a threat attack.
What further adds to the degree of risk is that these malicious links even get a certain degree of credibility because they are being **republished by Grok. 
Experts believe that to prevent any cyber mishap, X must start working on building a robust link scanning system for all posts.
Local and state agencies are left vulnerable after Federal cuts by the Trump administration!
The Trump administration has made some notable changes in the USA’s cybersecurity landscape. The deduction in the **Federal budget and staffing cuts are one of the major shifts under the Trump administration. Clearly, cybersecurity experts are not happy with the current equation. Last month, on August 24, cybercriminals targeted the state of Nevada. It was a ransomware attack, and the cybercrooks managed to wipe away crucial data, leading to service outages. Some of the g overnment services went online only this week. _Meanwhile, Nevada has not been able to restore all the computer and data systems completely. _The FBI and the CISA (Cybersecurity and Infrastructure Security Agency) have been working in close coordination with the concerned authorities of Nevada to find the perpetrators.
A similar threat attack took place back in July. It targeted the City of St. Paul and led to a state-wide emergency declaration. The governor of St. Paul requested the National Guard’s cybersecurity experts to look into the matter. Although the city has come back to normalcy, the officials are still working with **third-party cybersecurity experts to cope with the damage.
Due to a lack of cybersecurity budget and skilled staff, cybercriminals are intentionally targeting small government entities with lower budgets, fewer experts, and almost zero expertise in combating threat attacks.
A major American tire manufacturing company is under a cyberattack.
The global tire manufacturing company, Bridgestone Americas (BSA), has confirmed a cyber incident. It states that the cyber mishap has impacted its manufacturing units. However, BSA claims that the everyday **business operations are being carried out as usual. According to a Canadian news outlet, BSA has suspended one of its manufacturing joints situated in Joliette. The mayor of Joliette has confirmed that the cyber mishap has affected all of BSA’s plants across North America.
There is no information around any customer or employee data being divulged because of the threat of an attack._ A forensic investigation is being carried out to nab the real culprits. Bridgestone claims that it managed to respond right in time, and that’s how the extent of the damage has been less adverse._ **BSA states that they already have a set of established protocols that helped them to contain the damage.
There is still not much clarity around the scope and nature of the threat attack. Also, no cybercrime group has claimed responsibility for the cyber incident so far.
Experts highlight that alongside defenses against AI scams and ransomware, SPF, DKIM, and DMARC are vital to stop phishing and email spoofing, reinforcing the overall **cybersecurity posture of organizations.
Sources
Operations Lead
Operations Lead at DuoCircle. Runs project management, developer coordination, and technical support execution for DMARC Report.
LinkedIn Profile →Take control of your DMARC reports
Turn raw XML into actionable dashboards. Start free - no credit card required.