Category: Phishing Attacks


  • Seized Bitcoin Phishing Scam Leaves South Korean Police Empty-Handed

    A seized Bitcoin phishing scam has left South Korean law enforcement without access to cryptocurrency confiscated during a criminal investigation. The loss occurred after attackers exploited a phishing scheme that targeted officials responsible for managing seized digital assets. The incident has triggered internal reviews and raised broader concerns about how authorities store and protect cryptocurrency…

  • Live Personalized Phishing Pages Turn Legit Sites Into Real-Time Traps

    Cybercriminals are deploying live personalized phishing pages that change content in real time to deceive users more effectively. Instead of relying on static fake websites, attackers now modify pages dynamically after a visitor arrives. This approach allows scams to appear legitimate at first glance and transform into phishing traps only when a target interacts with…

  • Okta SSO vishing attacks steal enterprise credentials

    Okta SSO vishing attacks are targeting enterprise employees through voice-based social engineering campaigns. Attackers impersonate IT support staff and convince victims to share login details during live phone calls. These attacks aim to steal single sign-on credentials that unlock access to multiple cloud services. The campaign shows how threat actors now combine human manipulation with…

  • LastPass Phishing Scam Targets Users With Fake Backup Emails

    A new LastPass phishing scam targets users with deceptive emails that claim urgent action is required to protect password vaults. The messages pressure recipients into creating backups under false pretenses, a tactic attackers use to steal credentials and gain full account access. The campaign adds to growing concerns around social engineering attacks aimed at password…

  • LinkedIn Phishing Campaign Targets Executives With Weaponized Files

    A LinkedIn phishing campaign is targeting executives by delivering weaponized files through direct messages. Attackers abuse the platform’s professional trust to convince senior employees to download files disguised as legitimate business documents. Once opened, the files install malware designed to evade detection and maintain long-term access. The campaign highlights how social networking platforms have become…

  • CIRO Phishing Attack Exposes Investor Data

    A CIRO phishing attack has exposed sensitive investor data after attackers gained unauthorized access to internal systems. The incident affects hundreds of thousands of individuals and highlights ongoing cybersecurity risks facing financial regulators. Even organizations tasked with protecting markets remain vulnerable to well-executed social engineering campaigns. The breach did not rely on advanced malware or…

  • Mustang Panda Phishing Targets US After Maduro Operation

    Mustang Panda phishing activity escalated following a recent US operation tied to Venezuelan President Nicolás Maduro. The campaign shows how quickly state-linked threat actors react to geopolitical events. By exploiting breaking news, attackers attempt to increase trust and urgency among targeted recipients. Researchers say the operation focused on US government-related individuals and policy organizations. The…

  • Couple Arrested Over Multi-State Credit Card Phishing Scheme

    Authorities in the United States have arrested a couple accused of running a multi-state credit card phishing scheme that targeted victims across several states. Investigators say the suspects used phone-based social engineering to steal credit card details and carry out fraudulent purchases. Law enforcement stopped the pair during a traffic stop after tracking suspicious financial…

  • Nigeria arrests developer tied to Raccoon0365 phishing platform

    Nigerian authorities have arrested the suspected developer of the Raccoon0365 phishing platform following an international cybercrime investigation. The arrest targets a service that enabled large-scale Microsoft 365 credential theft across multiple regions. Investigators linked the platform directly to phishing campaigns that compromised enterprise email accounts. By selling ready-made phishing infrastructure, the operator helped cybercriminals launch…

  • Mimecast Link Abuse Drives Surge in Sophisticated Phishing Emails

    Mimecast link abuse drives a new wave of convincing phishing emails that bypass detection. Attackers exploited trusted link-rewriting features to send thousands of fake notifications and lure victims into credential theft attempts. Attackers exploit trusted link rewriting The campaign relied on a simple but powerful tactic. Mimecast rewrites outbound links to inspect them for threats.…