Category: Phishing Attacks


  • Trezor Says 347,000 Users Targeted After Brevo Breach

    Trezor says a phishing campaign targeted about 347,000 customer email addresses after hackers breached its third-party marketing provider, Brevo. Around 2,500 recipients clicked the malicious link before the company disabled it. The attackers sent fake security warnings from a legitimate Trezor email address. They claimed that a hardware flaw threatened the recovery seeds used to…

  • BigBear phishing service bypassed MFA at 258 organizations

    A phishing-as-a-service platform called BigBear 2.0 has compromised Microsoft 365 accounts at 258 organizations. The operation collected more than 5,000 credential records by intercepting passwords and authenticated session cookies. CloudSEK researchers gained administrator access to the service’s control panel. Their investigation uncovered 42 virtual private server nodes configured to target Microsoft 365 users. The BigBear…

  • Attackers Hide Phishing Lures With Invisible Unicode Characters

    Threat actors are using invisible Unicode characters to hide phishing lures from email security filters. The technique, known as ASCII smuggling, inserts hidden characters inside suspicious words. As a result, a message can appear normal to a recipient while bypassing keyword-based detection systems. Microsoft researchers identified a major campaign that used Unicode phishing lures in…

  • Hackers Use npm Mirrors to Host Phishing Redirect Pages

    Researchers have identified an npm mirror phishing technique that uses package registries and public mirrors to host malicious redirect pages. Instead of infecting developers who download a package, attackers store harmful HTML files inside npm packages. Mirror services then copy those files and make them available from trusted developer-related domains. This approach can make phishing…

  • AnonyMousKIT Phishing Uses AI Calls to Steal iPhone Passcodes

    Researchers have uncovered AnonyMousKIT, a phishing-as-a-service platform that uses AI voice agents to target owners of stolen iPhones. The service reportedly helps criminals obtain passcodes, Apple Account credentials and two-factor authentication codes. Attackers can then unlock stolen devices, remove Activation Lock and access sensitive data. Researchers at SOCRadar say the platform has operated since early…

  • JWR phishing kit mimics PayPal, Apple and online stores

    A newly discovered phishing framework called the JWR phishing kit gives criminals real-time visibility into the information victims type into fake websites. The tool can mimic payment, login and checkout pages for brands including PayPal, Apple, Shopify, WooCommerce, Klarna and banks. Unlike many phishing pages, JWR does not wait for a victim to submit a…

  • AI Voice Phishing Attacks Target Citadel, Two Sigma and Point72

    Hackers have launched an AI voice phishing campaign against several major Wall Street investment firms, including Citadel, Two Sigma, Point72 Asset Management, and Millennium Management. The attacks use AI-generated voices to impersonate trusted people over phone calls or voice messages. Rather than relying on malware, the threat actors appear to be targeting employees directly and…

  • Credit Agricole Phishing Scam Used Stolen Email Keys and Fake Calls

    A sophisticated Credit Agricole phishing operation used stolen email-service credentials, exposed cloud files, and carefully planned phone scams to steal from bank customers. Researchers uncovered the campaign on June 19 after finding a publicly accessible server used to run the fraud operation. The phishing infrastructure contained records for 912 people who submitted their banking credentials…

  • Microsoft Teams Vishing Attacks Lead to Chaos Ransomware

    Microsoft Teams vishing attacks are being used to trick employees into granting remote access to their work devices, allowing attackers to deploy Chaos ransomware. Sophos tracked the campaign as STAC4749 after it targeted dozens of organisations in North America between February and June 2026. At least three intrusions ended in ransomware, while one attack moved…

  • Attackers Use Real Microsoft Sign-In Screens in Phishing Campaign

    A new Microsoft sign-in screen phishing campaign is using genuine Microsoft login pages to bypass traditional phishing checks. Instead of directing users to a fake website, attackers trick them into approving a malicious app after they sign in. Check Point researchers found that the campaign used convincing HR-themed Microsoft Teams lures. Once a victim grants…