August 5, 2026
Teddy Bears, Banks, and Botnet Chaos
Citigroup, Idaho, and Build-a-Bear Launched a Coordinated Attack on Me
Even the comments were torn between “great catch” and “wait, is this too wild to be real?”
TLDR: A researcher says infected machines inside big organizations like Citigroup, Idaho, and Build-A-Bear were used in the same phone scam wave, and he even posted a free tool to check for it. Commenters were split between praising the wild headline, doubting elite institutions should miss this, and derailing into an AI-writing argument.
This story arrived with the kind of headline that makes people do a double take: Citigroup, Idaho, and Build-A-Bear attacked me. Naturally, the community pounced. The actual claim is less cartoon-villain team-up and more digital bad luck: the writer says machines inside major companies and public agencies were secretly hijacked and used to try to make expensive international phone calls through his system. In plain English, scammers were allegedly trying to turn other people’s computers into a giant phone bill machine.
But the real drama was in the reaction. One camp was impressed by the sheer nerve of the opener, with one commenter calling it a “Hell of an opening” and praising the write-up and the honeypot trap that caught the activity. Another group was stunned for a different reason: how on earth were these big-name institutions sloppy enough to get caught up in this? That disbelief came through loud and clear, with readers basically saying they expected banks, governments, and defense giants to have tighter defenses.
Then came the classic internet side quest: was this written with AI? One commenter abruptly swerved from the security scare to accuse the author of using a language model instead of writing “with your own words,” instantly giving the thread a mini culture-war subplot. And of course, someone compared the headline to an Onion-style conspiracy blast, which is honestly the perfect summary of the mood: half alarm, half laughter, all eyes on the chaos.
Key Points
- •The article reports that over 27 hours in four waves, networks linked to multiple major organizations attempted to use the author’s SIP honeypot server to place calls.
- •The activity is described as International Revenue Share Fraud, in which attackers try to route calls to premium-rate numbers they control.
- •The author says the same target number, spoofed caller IDs, and timing appeared across honeypot servers in Los Angeles, New York, and Tokyo, suggesting a shared command source.
- •The article attributes the traffic to compromised machines inside corporate or government networks rather than intentional actions by the named organizations.
- •A public API is provided to let organizations check whether their ASN, IP ranges, or IP addresses appear in the honeypot’s historic attack data, with Build-A-Bear’s ASN shown as an example.