Trezor says a phishing campaign targeted about 347,000 customer email addresses after hackers breached its third-party marketing provider, Brevo. Around 2,500 recipients clicked the malicious link before the company disabled it. The attackers sent fake security warnings from a legitimate Trezor email address. They claimed that a hardware flaw threatened the recovery seeds used to…
A phishing-as-a-service platform called BigBear 2.0 has compromised Microsoft 365 accounts at 258 organizations. The operation collected more than 5,000 credential records by intercepting passwords and authenticated session cookies. CloudSEK researchers gained administrator access to the service’s control panel. Their investigation uncovered 42 virtual private server nodes configured to target Microsoft 365 users. The BigBear…
Threat actors are using invisible Unicode characters to hide phishing lures from email security filters. The technique, known as ASCII smuggling, inserts hidden characters inside suspicious words. As a result, a message can appear normal to a recipient while bypassing keyword-based detection systems. Microsoft researchers identified a major campaign that used Unicode phishing lures in…
Researchers have identified an npm mirror phishing technique that uses package registries and public mirrors to host malicious redirect pages. Instead of infecting developers who download a package, attackers store harmful HTML files inside npm packages. Mirror services then copy those files and make them available from trusted developer-related domains. This approach can make phishing…
Researchers have uncovered AnonyMousKIT, a phishing-as-a-service platform that uses AI voice agents to target owners of stolen iPhones. The service reportedly helps criminals obtain passcodes, Apple Account credentials and two-factor authentication codes. Attackers can then unlock stolen devices, remove Activation Lock and access sensitive data. Researchers at SOCRadar say the platform has operated since early…
A newly discovered phishing framework called the JWR phishing kit gives criminals real-time visibility into the information victims type into fake websites. The tool can mimic payment, login and checkout pages for brands including PayPal, Apple, Shopify, WooCommerce, Klarna and banks. Unlike many phishing pages, JWR does not wait for a victim to submit a…
Hackers have launched an AI voice phishing campaign against several major Wall Street investment firms, including Citadel, Two Sigma, Point72 Asset Management, and Millennium Management. The attacks use AI-generated voices to impersonate trusted people over phone calls or voice messages. Rather than relying on malware, the threat actors appear to be targeting employees directly and…
A sophisticated Credit Agricole phishing operation used stolen email-service credentials, exposed cloud files, and carefully planned phone scams to steal from bank customers. Researchers uncovered the campaign on June 19 after finding a publicly accessible server used to run the fraud operation. The phishing infrastructure contained records for 912 people who submitted their banking credentials…
Microsoft Teams vishing attacks are being used to trick employees into granting remote access to their work devices, allowing attackers to deploy Chaos ransomware. Sophos tracked the campaign as STAC4749 after it targeted dozens of organisations in North America between February and June 2026. At least three intrusions ended in ransomware, while one attack moved…
A new Microsoft sign-in screen phishing campaign is using genuine Microsoft login pages to bypass traditional phishing checks. Instead of directing users to a fake website, attackers trick them into approving a malicious app after they sign in. Check Point researchers found that the campaign used convincing HR-themed Microsoft Teams lures. Once a victim grants…