December 2025 News & Tips | FaceBook Scam Ads, Modern Car Issues, and Social Media Bans

December 2025 News & Tips | FaceBook Scam Ads, Modern Car Issues, and Social Media Bans
View this email in your browser
The mission of this publication is to cut through the clutter of cybersecurity news stories and provide you with the most important, relevant and actionable cybersecurity information.

If this newsletter adds value, fantastic! That is the goal. Please forward it on to friends/colleagues. If not, no hard feelings. Please look to the bottom for an easy to click "unsubscribe" button.
Subscribe
In this issue:
Month's News in Review
Upcoming Speaking Events
TCE Strategy in the News
Must Read Articles This Month
Cybersecurity Tip of the Month
Enjoy this month's newsletter? You can use this link to post on social media or send to friends! Thanks for sharing!
This Month's News in Review

Welcome back to the monthly TCE Strategy newsletter! From $16B in revenue for running scam ads to 4 million cars needing to be retrofitted because they can be stolen with a USB cable, December has not disappointed around important news in the world of cybersecurity. Let’s see how this month’s cybersecurity news can help us make better decisions about what is Secure Enough for us, the companies we work for, and our families.


Meta (Facebook) document leaks show that they purposely ran 15 billion scam ads per day in 2024

Reuters came into possession of internal Meta documents from late 2023. These documents stated the following: Meta estimated that 10.1% of all ads run on Facebook, Instagram and WhatsApp would be either scams for products that don’t exist, or would be truly cybercriminal in nature (trying to install viruses, tricking users to call an 800 number for help with a computer problem that the ad caused, etc.). These ads amounted to 15 billion separate ads served up per day. Meta estimated that they would make $16 billion from running those ads. Meta developed an AI algorithm that would stop ads from running if the algorithm was 95% confident that the ad was a scam, but 94% confidence wasn’t good enough. However, if the algorithm was less than 95% sure but still reasonably sure that an ad was a scam, Meta would charge the scammer more money to run the ad. The documents also state that users who click a scam ad are more likely to see more scam ads in the future.

I. Just. Can’t. Even… These ads do real damage to real people. These ads can be the beginnings of attempts to drain bank accounts, steal cryptocurrency, perform ransomware attacks and who knows what else. Meta knew it, but it was more profitable for them to run the ads than to protect their users.

Takeaways: Social media’s customers are not you. Their customers are advertisers looking to sell to you. You are the product. If Facebook was a restaurant, you would not be the person eating there. You would be the chicken nuggets and burgers. Do not click on social media ads. If you see something that interests you on a social media ad, look it up independently online to see if it’s legitimate. Even then, be wary, as Google scam ads are also a thing.


Hyundai / Kia to retrofit 4 million cars with immobilizers

Modern cars are fundamentally computers attached to an engine and wheels. That is a problem, because if a thief can trick a computer into believing they have a valid car key, then they can drive away with that car. Car theft isn’t a new issue, but being able to use cybercriminal means to steal a car is a more modern phenomenon. Car makers don’t want their cars stolen, because that can hurt sales. However, the amount of money they are willing to invest in a car to make it hard to steal depends widely on the manufacturer of the car. Most car makers use a device called an “immobilizer” that is designed to thwart criminals that try to trick the computer into believing that they have a valid car key. The parent company of Hyundai / Kia, Hyundai Motor Group, is not one of those companies. For many lower-end 2015-2021 Hyundais or 2011-2021 Kias, the manufacturer chose to not include an immobilizer, meaning that anyone with a USB cable and a bit of know how could easily steal the car. The Attorneys General of 35 USA states banded together and sued Hyundai and Kia for knowingly selling cars that were trivial to steal. As a result, 4 million cars will need to be retrofitted at Hyundai Motor Group’s expense, which will likely cost them up to $500 million.

Takeaways: This is an example of the government doing something right. It is reasonable to expect that vehicles are reasonably secure, cyber or otherwise. Do research on the theft rates of a vehicle before purchasing it. This Hyundai / Kia issue was so bad that some insurance companies refused to sell policies to the owners of these cars.


Australia bans social media for children under 16 years old.

As a parent of two children under 16, I see both sides of this. Social media has been widely shown to have harmful impacts on children (and frankly, I question the harm/benefit ratio for adults as well). Society should protect children from bad things. That’s nothing new – I remember massive anti-smoking campaigns when I was a kid. I remember the police speaking to my 6th grade class about the dangers of illegal drugs. We have laws prohibiting people under a certain age from driving motor vehicles, owning firearms, and so on. The Australian government has chosen to ban anyone under 16 from having their own social media account. The trouble with this is the practical means of enforcing it. Do social media companies have to verify government-issued ID cards to prove someone’s age? If so, the cybersecurity concerns around protecting that data are enormous. We have the same problem in the USA with certain states banning adult content websites unless they verify the age of users, which caused websites such as PornHub to remove themselves entirely from anyone accessing them in those states (which a VPN can easily bypass in a matter of seconds). 

Is this something that governments should step in on? I honestly don’t know. I’ll say that I’d be a lot happier if requirements to not have scam ads on social media were much, much stricter, but that doesn’t solve the problem of people online saying truly horrific things to children. Sometimes it’s children doing the harm to other children. There are some sites that are honestly trying to address this issue, but their reach is very limited compared to large social media companies. Kids are smart and technically savvy, and their ability to get around bans such as this is strong.

Takeaways: As parents, we need to parent our kids. It’s up to us to set good examples and provide coaching on reasonable use of online services. Personally, I think banning kids under a certain age from having accounts will have little practical effect. I’d rather see social media companies have more government regulation to identify and remove genuinely malicious content, starting with ads, as there are fewer free-speech concerns there. This isn’t an easy problem to solve.


Until next month, stay safe!

Upcoming Speaking Events


Here is a list of the cities that I will be in over the next several months. Please reach out if you have an event in mind!


December 22-26, Ft. Myers, FL

February 19-23, 2026, New Orleans, LA

March 8-17, 2026, Cairns, Australia

June 19-26, 2026, Hayward, WI

July 23-28, 2026, Austin, TX

Nov 30-Dec 4th, 2026, Key West, FL

Dec 10-13, 2026, San Diego, CA

TCE Strategy in the News

Thank you to JJ Javier and the CISO Whisperer team for naming me as one of the "CISOs Every Security Vendor Wants Feedback From"! I am honored to be on the list.

Interesting Articles

"The Cyber Security and Resilience Bill arrives as cyber-attacks cost the British economy an estimated £14.7 billion annually - approximately 0.5% of GDP."
What should the legal penalty for deepfake images / videos be? It's a new kind of crime, so what an "appropriate" penalty should be is a new question.
Installing web browser "extension" programs is a bad idea unless you absolutely need them. This story is a stunning example of why.
 
I completely agree with this. A TV should be for watching television, not for spying on me and my family. I hope this lawsuit brings about positive change. Nice job Texas.
Cybersecurity Tip of the Month
 
How to Stay Cyber-Safe as We Head Into 2026

Cybersecurity can feel like common sense, but a well-timed reminder goes a long way—especially during the busy holiday season. As you wrap up the year, here are a few simple ways to protect yourself and those you love:

1. Think twice about gift cards. They’re a favorite target for scammers. When possible, choose cash or more secure payment options—they're straightforward, flexible, and hard to exploit.

2. Turn on Multi-Factor Authentication (MFA). Any account that matters (especially financial, email, or social media) should have MFA enabled. This extra layer of protection can prevent fraud and save you major stress during an already hectic time of year.

3. Consider security as a gift. A subscription to a trusted password manager (such as Dashlane, LastPass, or 1Password) is both practical and thoughtful. For about $60 a year for a family plan, it offers everyday peace of mind.

4. Head into the new year prepared. Take time now to review passwords, update security settings, and apply system patches. Whether for personal use or your business, stepping into 2026 with strong cyber habits sets the tone for a safer year ahead.

LinkedIn
Twitter
Facebook
Website
Forward Forward
We want your feedback!

< On a scale of 10, how helpful was this newsletter?>

lowest 1   2   3   4   5   6   7   8   9   10   highest

Copyright © 2025 TCE Strategy, All rights reserved.
You are receiving this email because you are on Bryce Austin's contact list

Our mailing address is:
TCE Strategy
18268 Java Trl
Lakeville, MN 55044

Add us to your address book


Want to change how you receive these emails?
You can update your preferences or unsubscribe from this list

You can reach Bryce at bryce@bryceaustin.com

Email Marketing Powered by Mailchimp
Subscribe to Newsletter

Browse newsletter archives: