#phishing
172 stories taggedphishing · page 11 of 12.

Chinese Spy Group Lures Energy Workers With Fake Australian News Site — Then Steals Everything They Type
A state-linked hacking group spent two months tricking employees at offshore energy companies into visiting a bogus news website that silently recorded their keystrokes.

US warns Russian spies are still hunting your WhatsApp and Signal accounts
CISA and the FBI say Russian intelligence officers are running fresh phishing campaigns to hijack accounts on messaging apps used by journalists, officials and activists.

TA558 Is Back, Targeting Hotels and Airlines With Fake Booking Emails
A criminal group that has quietly stolen travel-industry data since 2018 has dramatically ramped up its fake-reservation campaigns, now using compressed file tricks to sneak spying software onto victims' computers.

0ktapus Phishing Campaign Hits 130 Companies, Compromising Nearly 10,000 Accounts
A phishing campaign exploiting Okta's authentication system has breached 9,931 accounts across 130 organizations, with Twilio, Cloudflare and DoorDash among the victims.

Drag, Drop, Hijacked: How 'ConsentFix' Steals Microsoft 365 Sessions in Seconds
A new twist on the ClickFix trick turns Microsoft's own sign-in prompts into a session-theft machine, and a step-by-step guide is now circulating on a Russian crime forum.

Nelnet Data Breach Exposes 2.5 Million Student Loan Records
A vulnerability in Nelnet's loan servicing system exposed personal data for millions of borrowers. What happened, and what should you do now.

Ousaban Resurfaces in Iberia, Hiding Bank-Stealer Payloads Inside Images
A Brazilian trojan pivots to Spanish and Portuguese banking customers, using geofenced PDF lures and steganography to bury its real payload.

Phantom Squatting: When Attackers Camp on the Domains LLMs Hallucinate
Unit 42 documents a pre-positioning tactic where actors register non-existent domains that AI assistants keep suggesting, then wait for the traffic to arrive.

FIFA 2026 Fraud Infrastructure Was Pre-Staged Months Before Kickoff, Researchers Say
A Check Point exposure report documents pre-positioned phishing kits, lookalike domains and multilingual scam pages built well ahead of the June 11 opening match.

236,000 Sites Run Pig-Butchering Templates Built on DCloud Uni-App
Infoblox researchers tie a sprawling fake-exchange and wallet-drainer ecosystem to a legitimate Chinese cross-platform dev framework.

BEC Keeps Winning Because It Looks Exactly Like Normal Work
The phishing payload is gone. The pretext is the payload now, and your SEG was never built for that.

Russia's Signal Phishing Now Targets the Backup Recovery Key — and the Key Doesn't Expire
An FBI/CISA update says GRU-linked operators are coaxing victims into surrendering their Signal Backup Recovery Key, which yields full message history and durable account access.

Hotel Front Desks Hit by Photo-ZIP Phishing Dropping Node.js Implant
Microsoft flags an unattributed campaign active since April 2026 against hospitality targets in Europe and Asia.

The Week in Cheap Crime: Stale Creds, Trusted Apps, and Phishing Through the Front Door
Not elite. Not cinematic. Just effective, and that's the problem.

Email security teams are buried in alerts. Behavioral AI vendors say they have an answer.
Phishing, BEC and account takeover noise keeps SOC teams busy. A new webinar pitches behavioral detection as the way to cut through it.