#Social Engineering
98 stories taggedSocial Engineering · page 2 of 7.

ShinyHunters Claimed It Broke Into ReliaQuest. The Reality Is More Complicated.
A cybersecurity company's own employee fell for a fake login page, handing criminals limited access. What happened next is actually a story about defences holding.

The Fake IT Call and the Click That Opens the Door
Attackers are skipping the smash-and-grab, choosing polite phone calls, spoofed login pages and poisoned software guides to walk in through the front door.

US Now Top Target in Global Phishing Campaign That Hijacks Remote Access Tools
A phishing operation first spotted using fake Canadian tax notices has spread to 46 countries, with nearly half of all sightings hitting American inboxes.

A Former Internet Godfather Explains How AI Gives Criminals a Head Start
Brett Johnson built some of the first organised online crime networks. Now he's showing security conferences exactly how fast AI lets attackers work, and why defenders are still catching up.

Criminals Pose as IT Support Inside Microsoft Teams to Take Over Company Networks
A hacking campaign called Spring Ring tricked more than 150 employees at ten-plus companies into handing over remote control of their computers, all through a fake Teams call from a fake help desk.

Russian Hackers Are Phishing EU Officials on WhatsApp and Signal
Eight serious attacks on European government staff have exposed a gap no one planned for: officials trusting consumer messaging apps with sensitive business.

Criminals Hid a Hacking Network Inside a Cryptocurrency Blockchain. Thirty-One Companies Got Caught.
A new campaign turns blockchain technology into an untraceable instruction relay, letting attackers redirect infected computers to a new server for less than a penny per update.

Hidden Text in Emails Can Trick AI Assistants Into Showing You Fake Numbers
Researchers planted invisible instructions inside ordinary emails and watched an AI summariser rewrite invoice amounts and meeting dates without any warning to the reader.

Iranian Hackers Nimbus Manticore Target Mac and Linux With Fake Job Tests
Kaspersky says the state-linked crew is now posing as recruiters and hiding remote-access malware inside coding challenges sent to job hunters.

ClickFix: The Attack That Talks You Into Hacking Yourself
Microsoft says the fake 'prove you're not a robot' trick was the single most common way criminals broke into companies last year. The clever bit is that the victim does the hard work.

Man Posed as NFL Player to Steal $1.3 Million from 26 Women Across Four States
Federal prosecutors say Daejon Love used dating apps, fake investment accounts, and a made-up San Francisco 49ers identity to run a romance fraud that took over a million dollars from victims in Oregon, Washington, Idaho and California.

TerminalFix: The Fake CAPTCHA That Opens a Back Door Into Company Networks
Microsoft has spotted a new twist on the ClickFix scam that pushes victims to paste attacker commands straight into Windows Terminal, ending with a hidden tunnel into the internal network.

Bank Impersonation Scams: How One Target Wasted the Fraudsters' Time for Hours
A reader who received a fake Barclays automated call decided not to hang up. What followed is a useful case study in how these scams work and what you can do when one lands in your lap.

He sent $180,000 to a woman who didn't exist. AI built her face.
A retired Australian psychologist spent a year in a deepfake romance before a six-fingered hand gave the game away. The technology is now good enough to fool a professional trained in human behaviour.

When Google Workspace gets breached, the door is usually already open
Most Workspace break-ins start with a tricked employee or a forgotten app connection, not a clever hack. Here is what actually happens in the first hours, and what stops the damage.