ChatGPT has entered the top 10 most impersonated brands in phishing campaigns for the first time, according to new research. OpenAI accounted for 1.1% of tracked brand phishing attempts during the second quarter of 2026. The figure places the company alongside widely impersonated brands such as PayPal, WhatsApp and Facebook. Microsoft remains the main phishing…
Police have dismantled the Kratos phishing platform and arrested its alleged developer in Indonesia. Authorities in Germany and the United States seized more than 200 servers during the coordinated operation. The takedown disrupted the service’s central infrastructure. Investigators believe the action has made the phishing operation inoperable. Kratos allegedly operated as a phishing-as-a-service platform. It…
A new password manager phishing campaign is targeting LastPass and Bitwarden customers with fake security and compliance emails. The messages claim that users must review updated policies through an electronic document service. However, the included buttons lead to fraudulent websites that impersonate legitimate business platforms. These pages then pressure visitors to download untrusted files. LastPass…
A newly identified cybercrime group called Helix is targeting Microsoft SharePoint environments. The attackers rely on voice phishing, device-code phishing, and multi-factor authentication (MFA) abuse to steal sensitive company data. Researchers say the group focuses on compromising Microsoft 365 accounts first. It then steals SharePoint files and uses the data to extort victims. In some…
Security researchers have uncovered Forg365, a phishing-as-a-service (PhaaS) platform that uses artificial intelligence to create phishing campaigns targeting Microsoft 365 users. The platform combines adversary-in-the-middle (AiTM) attacks with device-code phishing to steal Microsoft 365 accounts. It also includes tools that help attackers maintain long-term access to compromised accounts without requiring victims to log in again.…
Belgian authorities have arrested a 19-year-old man suspected of playing a leading role in a Belgian phishing gang that targeted victims across Europe. Investigators believe the network stole hundreds of thousands of euros by impersonating bank employees, convincing victims to install remote access software, and laundering the proceeds through cryptocurrency and overseas accounts. Police say…
A newly discovered phishing-as-a-service platform called ARToken PhaaS appears to operate as an affiliate of the EvilTokens phishing ecosystem, giving cybercriminals an advanced toolkit for compromising Microsoft 365 accounts. Researchers say the platform automates account takeovers, steals authentication tokens, and includes powerful tools for business email compromise (BEC) attacks. Cisco Talos Uncovers ARToken PhaaS Platform…
A new FIFA World Cup 2026 phishing campaign is targeting football fans and employees with convincing emails that promise exclusive tournament merchandise. Researchers warn that the scam installs Voidrift malware, giving attackers access to corporate networks while successfully evading several leading email security platforms. Fake FIFA Merchandise Emails Deliver Voidrift Malware Cybersecurity researchers at Cofense…
Microsoft has uncovered a sophisticated hotel phishing campaign targeting hospitality businesses across Europe and Asia. The attackers disguise malware as photo attachments and trick hotel employees into opening them. Once activated, the files install malware that gives cybercriminals long-term access to infected systems. Microsoft has not linked the activity to a known threat group, and…
Cybercriminals have found a new way to exploit the Shop app by placing fake purchase receipts directly into users’ order histories. The fraudulent orders appear alongside legitimate purchases and encourage victims to call fake customer support numbers, where scammers attempt to steal personal and financial information. Researchers warn that the tactic is more convincing than…