Stay up-to-date on the latest phishing threats and learn how to prepare for them
Recently active
Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking. September 11, 2026 By Eduard Kovacs Cold cryptocurrency storage provider Trezor says roughly 347,000 of its customers received phishing emails after a third-party marketing platform used by the company was hacked.The incident involved the marketing platform Brevo, which Trezor uses for newsletters. Brevo said an attacker exploited how it handles SAML Single Sign-On (SSO) to access 138 accounts.“The attacker created a Brevo account and enabled single sign-on (SSO) on it, then invited legitimate Brevo users into that SSO configuration. Using their own identity provider, they were able to sign in as those invited users, which by itself is expected behavior for SSO,” Brevo explained.“This access was not properly scoped: instead of being limited to the single organization where SSO was enabled, it wrongly granted the attacker access to all organizations
Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block. September 9, 2026 By Kevin Townsend Future phishing campaigns may no longer involve a detectable physical web page.Barracuda has analyzed a new type of phishing campaign that adds both stealth and flexibility to traditional phishing. Rather than standard social engineering to persuade a target to visit a static compromised web page, this campaign generates a blob URL to render and deliver the phishing page inside the target’s own browser. This reduces the possibility of security scanners detecting either the social engineering email or the static residence of the phishing page.The attack flow is similar to standard phishing since the victim must be steered to an external resource. In this campaign, however, the steering is obfuscated through trusted processes. It starts with a Docusign-themed email with an attached calendar inv
Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access. September 8, 2026 By Alexander Culafi Source: LeoPatrizi via Getty ImagesUPDATEAttackers are chaining together multiple Google services in order to get phishing links past security gateways.Cybersecurity vendor KnowBe4 published research on Sept. 4 concerning an ongoing phishing campaign observed in the wild. To some extent, the mechanics of the campaign are typical: The threat actor sends a malicious email under false pretenses, the victim clicks the link, and the link leads to a malicious landing page where the victim is compromised.What sets this campaign apart is the link in the initial phishing email. In order to bypass gateways, email filters, and other security tools, the link relies on a chain of redirects across Google domains, intending for link inspectors to see multiple Google domains and let the URL through.Attackers regularly
Ravie Lakshmanan Sep 08, 2026 Web Security / Phishing Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams.The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has operated out of the Indian state of Rajasthan since at least 2015, driven by two IT service providers named WeConnect Solutions LLC (previously iConnect Soft Solutions LLC) and Garage2Global.Although Garage2Global claims to be a website design, SEO, and digital marketing services provider, the cyber threat intelligence platform said it unearthed evidence indicating the company develops malicious web infrastructure used in SEO poisoning campaigns as part of the BengalSEO scam cluster."This group utilizes its extensive SEO and web development capabilities to create and promote lure pages with multiple Black Hat SEO techniques," the DFIR Report said in a technical
September 1, 2026 By Bill Toulas Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software.In activity observed between July 21 and August 20, Faronics-themed lures reached more than 457 endpoints via emails disguised as invoices, tax documents, or other business files.Faronics Deploy is a cloud-based endpoint management platform that allows IT administrators to remotely enroll and manage computers, deploy software, and execute scripts.Researchers at managed detection and response company (MDR) Huntress say that the embedded malicious links lead to a website that profiles potential targets and guides them through a malicious download flow.If the website is reached from an analysis environment, a decoy routine is activated, such as displaying an error message.Huntress explains that a potential victim is prompted to download and launch a legitima
September 7, 2026 By Bill Toulas A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials.Researchers at cybersecurity company CloudSEK gained administrator access to the control panel and found that the service managed 42 VPS nodes, all configured to target Microsoft 365 as part of the observed operation.According to the researchers, the campaign uses an Evilginx2-based adversary-in-the-middle framework to intercept passwords and authenticated session cookies, allowing attackers to hijack accounts after victims complete the multi-factor authentication (MFA) process.BigBear uses a configuration called “offy” that sets up a man-in-the-middle (AiTM) proxy between the victim and Microsoft’s legitimate authentication infrastructure.This allows the attacker to capture credentials, including MFA, and session cookies and replay them through an API to hijack the victim’s aut
September 6, 2026 By Bill Toulas Threat actors have adopted the ASCII smuggling technique in phishing campaigns, using invisible Unicode characters to evade email security filters.ASCII smuggling has been used in AI prompt injection attacks to conceal malicious instructions from users by encoding them with Unicode characters from the Tags block (U+E0000–U+E007F).Microsoft threat researchers discovered a large-scale phishing campaign using this technique, which peaked at up to 2.37 million daily messages in late February. Although the volume has dropped gradually in May, the operation is still active.“The high-volume phase persisted for roughly three months after February 9 and dropped sharply after May 15, 2026,” explains Microsoft.“These dates bound the observed use of the specific technique in our telemetry, not the broader campaign, which started earlier without it and continued without it.” >>Full Article<<
The adversary-in-the-middle (AitM) phishing service lowers the barrier to entry for actors to create attacks and steal more than just user credentials. August 26, 2026 By Elizabeth Montalbano Source: DPA Picture Alliance via Alamy Stock Photo A novel phishing service is giving attackers a turnkey solution to steal authenticated Microsoft 365 sessions for only $320 a month, bypassing multifactor authentication (MFA) protections and highlighting the need for more robust security for enterprise email.Researchers from enterprise browser maker Island discovered the adversary-in-the-middle (AitM) phishing service, dubbed "NovaCookies," which provides lures, domains, hosting, redirects, and support to relay Microsoft 365 logins in real time to steal authenticated sessions, according to a report published today by Shachar Gritzman, a senior security researcher at Island.NovaCookies — which also includes an option to pay $200 for 14 days — runs like a commercial operation and is targeting hundr
August 25, 2026 By Bill Toulas A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature.The illegal service has been active since early 2024 and is powering a structured ecosystem that sells stolen iPhones, harvests Apple IDs, accesses iCloud backups, and Keychain credentials.Researchers at threat intelligence platform SOCRadar took advantage of the platform operator's use of bare relative paths to gather information on how the service works, its operators, and infrastructure.SOCRadar found that AnonyMousKIT is connected to 506 domains and is fueling a sprawling business with 168 storefront brands acting as resellers.Overview of the operationSource: SOCRadarThe researchers recovered records of 200 calls made to victims between August 2025 and May 2026, using 55 distinct interaction transcripts handled by a voice AI agent operating under five personas.SOCRadar
August 24, 2026 By Pierluigi Paganini iAuthFlow v2 phishing toolkit uses a phished Google session to enroll an attacker-controlled passkey that survives password resets.Abnormal Security researchers have published an analysis of iAuthFlow v2, a phishing toolkit sold on a Russian-language cybercrime forum for $10,000 base price. The author also offers for sale additional capability modules separately. The headline feature is not the phishing itself. It’s what happens after the phishing succeeds.“Once the target completes a phishable Google login, the toolkit uses the authenticated session to enroll a passkey controlled by the operator.” reads the report published by Abnormal Security. “In the seller’s recorded demonstration, the account owner later changes their password, invalidating the active session—but the operator authenticates with the newly enrolled passkey and returns to the mailbox.”That’s the architecture. The phishing flow gives the attacker a temporary window. iAuthFlow v2
August 21, 2026 By Bill Toulas A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen.The attacker impersonates the target company's IT help desk, a tactic Microsoft highlighted earlier this year as increasingly common in multi-stage attacks.Expel’s security researcher Marcus Hutchins explains that the attacks direct the victim to install a fake “PowerShell Cleaner” executable (.MSI) hosted in Microsoft Azure, making the download appear trustworthy.Analysis of the malware showed "compile dates and file timestamps indicating it was first compiled and distributed around July 28, 2026."The installer extracts a PowerShell script named cleaner.ps1 and a ZIP archive containing the Python framework, a malicious Python script, precompiled Python libraries, and several fake Microsoft runtime DLLs. >>Full Article<<
The Hacker News Aug 19, 2026 Phishing / Artificial Intelligence Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It stopped working when the danger moved into the message's intent, and it is failing now that the sender is no longer a person.From Bad Content to Bad Intent to AI on Both SidesPhishing 1.0 was bad content. Malicious links, infected attachments, spam. Secure email gateways were built for this. Scan the message, match the signature, drop the bad stuff. That era is largely handled.Phishing 2.0 is bad intent. Business email compromise, executive impersonation, fake invoices, wire fraud. There is no malicious payload to scan, only social engineering that reads as a normal request from a person you trust. Gateways are blind to it because there is nothing in the content to flag. Behavioral analysis is the only thing that catches it, whi
Ravie Lakshmanan Aug 07, 2026 Phishing / Email Security Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email."The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic," Arctic Wolf Labs said. "Automated activity maintains compromised sessions at approximately eight-hour intervals."The activity is assessed to impact organizations across healthcare, education, manufacturing, government, and professional services sectors located in the U.S., Canada, and Europe. It shares tactical overlaps with Payroll Pirate attacks tracked by Microsoft under the moniker Storm-2755.Payroll Pirates is the designation assigned to a broader financially motivated threat cluster that involves hijacking the accounts of employees to
August 5, 2026 By Lawrence Abrams A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software.Proofpoint, which discovered the campaign, says it uses emails impersonating COLDCARD that claim a security audit is underway across its hardware cold storage wallet devices.The phishing campaign comes after attackers recently stole approximately 1,367 Bitcoin, worth an estimated $88.6 million, from 4,585 addresses using what is believed to be a random number generation flaw affecting multiple COLDCARD models and firmware versions.The emails are sent from compliance@coldcardteamnews.com with the subject "Hardware audit now available" and tell recipients that recent findings require COLDCARD to verify the integrity of devices across all hardware revisions."We are writing to inform you of a coordinated security audit now underway across the CO
Ravie Lakshmanan Aug 04, 2026 Phishing / CybercrimeThe commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts."Greatness supports AiTM [adversary-in-the-middle] credential and token theft, device code phishing, and OAuth consent abuse, all from the same operator panel and shared backend infrastructure," ZeroBEC said in a report shared with The Hacker News detailing the PhaaS kit's latest capabilities."The platform now supports AiTM token theft, device code phishing, OAuth consent abuse, and multiple target platforms, including iCloud, Yahoo, and Google Workspace. This evolution reflects the broader trend of PhaaS platforms expanding from simple credential harvesting to integrated attack ecosystems."The phishing platform w
July 29, 2026 By Alessandro Mascellino A phishing-as-a-service (PaaS) platform has been observed building a unique login page for each victim in real time, pulling a live screenshot of the target organization's own website to use as the page background.According to new research from Barracuda published on July 29, recent LogoKit campaigns extracted the victim's email address from the phishing URL, used the domain to identify their employer, then called commercial web services to assemble a matching page on the fly.RiskIQ, which named the phishing kit in 2021, found it was already pulling brand logos from Clearbit and already carrying the victim's email address in the URL.What has changed is the live website screenshot, which Barracuda described as a shift from brand impersonation to environment impersonation, recreating parts of the victim's genuine web environment rather than serving a generic replica. >>Full Article<<
July 24, 2026 By Ravie Lakshmanan The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware."BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, wallet reconnaissance and malware delivery into a repeatable victim acquisition pipeline," JUMPSEC said in a detailed report shared with The Hacker News. "The platform profiles victims' cryptocurrency wallets before malware delivery, enabling selective targeting of high-value victims."Describing the campaign as an operator-driven victim acquisition platform, the cybersecurity company noted that the activity involves using compromised trusted contacts as the initial access vector to create a self-propagating attack chain via Telegram.Details of the activity have been doc
Electronic signature platforms have become a routine part of business operations, making them an attractive lure for threat actors. While DocuSign remains the most commonly spoofed brand, attackers are increasingly abusing alternative document-signing services and trusted email infrastructure to make their campaigns appear legitimate.A recent campaign observed by our team illustrates this evolution. The attack impersonated PandaDoc and claimed that overdue invoices required review and signature, leveraging a workflow that many finance, procurement, and accounts payable employees encounter regularlyThe email was delivered through a compromised SendGrid account and legitimate SendGrid infrastructure. Rather than building trust from scratch, the attackers inherited credibility from an established business communications platform, increasing the likelihood that the message would reach inboxes and be viewed as authentic.Clicking "OPEN THE DOCUMENT" did not immediately direct users to a log
The attackers call victims to direct them to phishing websites mirroring Microsoft Entra ID login pages. July 10, 2026 By Ionut Arghire Organizations across multiple sectors have been targeted in a vishing campaign aimed at harvesting Microsoft 365 credentials, Okta warns.The campaign started in April and has involved voice calls directing the victims to fake Microsoft Entra ID login pages under the pretense that they need to register a new passkey.Tracked as O-UNC-066 and also known as CL-CRI-1147 and Pink, the hacking group has been targeting automotive, aviation, construction, food and beverage, healthcare, and technology organizations, mainly for data extortion.As part of the observed attacks, the threat actor has been registering domains incorporating the word ‘passkey’, and has been directing victims to pages that closely mirror the Microsoft passkey enrollment process.“It appears engineered to convince a targeted user they are in the process of enrolling a passkey with Microsoft
July 3, 2026 By Lawrence Abrams A new phishing-as-a-service (PhaaS) platform dubbed "ARToken" appears to operate as an affiliate of the EvilTokens phishing platform, giving researchers a glimpse into an extensive toolkit designed to compromise Microsoft 365.Cisco Talos researchers discovered the platform while investigating phishing infrastructure used in an incident response engagement and identified a React-based management panel called "ARToken Panel" that exposed more than 80 API endpoints.Reverse engineering the client-side JavaScript code revealed previously undocumented capabilities that extend well beyond what you would normally find in a phishing platform.The platform allows attackers to steal Microsoft 365 authentication tokens, establish persistent access using Primary Refresh Tokens (PRTs), and access Outlook mailboxes, SharePoint sites, and OneDrive files. It also includes tools to deploy phishing infrastructure through Cloudflare Workers and automate many aspects of busin
July 3, 20263:20 AM EDT Updated 5 hours ago NEW DELHI, July 3 (Reuters) - The world's biggest internet domain seller, GoDaddy, has warned that India's crackdown on fake websites impersonating famous brands will make the internet less safe for legitimate businesses and carry global ramifications.Soaring smartphone and internet use has coincided with a worsening problem of online fraud in India, the world's most populous nation. It's a key challenge for Prime Minister Narendra Modi's government, which last year received 2.4 million complaints of alleged cyber fraud amounting to $2.4 billion. Article
Separate but similar campaigns described by Microsoft and Trend Micro use malicious zip files to spread malware via social engineering and obsfucation, including blockchain abuse. June 30, 2026, By Elizabeth Montalbano Source: Henk Vrieselaar via Alamy Stock Photo Attackers have been targeting hotels and other hospitality organizations with a phishing campaign that uses malicious zip files purporting to include guest photos, with the aim of installing malware to achieve long-term access to compromised systems.Both researchers at Microsoft and Trend Micro have observed the malicious activity, though they did not confirm if it was connected, according to separate reports published recently. Neither company immediately responded to a request for comment by Dark Reading about a potential link between the activities they described. Attackers in both campaigns use similar social engineering tactics to target the hospitality sector by impersonating guests who have complaints or requests, and
The Hacker News Jun 30, 2026 Phishing / ImpersonationThe FIFA World Cup 2026 opened on June 11. By that date, according to Check Point Research, the fraud infrastructure targeting it had already been built, staged, and partially deployed. Threat actor activity was pre-planned, months out, across three sectors and at least ten languages.Check Point Exposure Management published the FIFA World Cup 2026 Cyber Threat Report this month, covering financial services, transportation, hospitality, and gambling. Here are three findings worth reading carefully.1 in 3 FIFA Partners Can't Block Email ImpersonationPre-tournament research by Proofpoint found that more than one-third of official FIFA World Cup 2026 partners lack sufficient DMARC enforcement to prevent domain spoofing. That means attackers can send an email that appears to come from a sponsor, a vendor, or a logistics partner, with no technical barrier stopping it.The World Cup supply chain is enormous. Airlines, hotels, broadcast par
June 25, 2026, By Bill Toulas Threat actors are increasingly abusing Shop, the order-tracking app from Shopify, by adding fake purchase receipts in users' order histories to trick them into providing sensitive data or installing remote access software.The Shop digital shopping assistant serves as a centralized platform where users can track orders from multiple online retailers, access receipts and shipping updates, and discover and purchase products from merchants that use Shopify.The app is very popular in North America, where support and purchasing options are more substantial. It has 50 million downloads on Google Play and 7 million ratings in Apple's App Store.According to cybersecurity company Gen Digital, scammers are inserting fake orders that appear alongside legitimate purchases, impersonating brands such as Norton, McAfee, Apple, and PayPal.Fake Norton purchase receipt in the Shop appSource: Gen DigitalThe threat actor also listed a phone number in the digital receipts that
While phishing is often associated with credential theft, many modern campaigns are designed with a more direct objective: financial gain. Rather than simply compromising accounts, attackers are increasingly targeting payment card information and online banking access that can be monetized quickly. The following examples demonstrate two common approaches toward achieving that goal.Domain renewal scams remain effective because they exploit a routine administrative responsibility that many organizations regularly manage. In this campaign, attackers impersonated Bluehost and warned recipients of an impending domain renewal issue requiring immediate action. The email originated from infrastructure associated with an Austrian ccTLD and was transmitted through a French IP address, highlighting the use of distributed infrastructure to obscure attribution.Unlike traditional phishing campaigns that focus on account credentials, this attack immediately directed victims to a payment collection pa
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.