Tag

#Social Engineering

83 stories taggedSocial Engineering · page 5 of 6.

Extreme close-up of a glowing laptop screen in a dim office, displaying a realistic login page, with a faint ghostly reflection of the same page morphing into a
Threat Intelligence

Phishing Emails Now Study Your Phone Before They Attack You

A new wave of scam emails quietly profiles your device — your operating system, location, and screen size — then delivers malware tailored specifically to your setup.

3 min read
A plain official-looking envelope resting on a wooden desk, partially open, with a single folded letter visible inside
Ransomware

Fake Interpol Arrest Notices Are Delivering Ransomware to Small Businesses

Criminals are impersonating the international police agency to frighten small business owners into downloading malware. The tactic is simple. It's working.

3 min read
Aerial 16:9 editorial photograph of a busy international airport terminal, shot from above at dusk, warm amber lighting illuminating rows of empty check-in desk
Threat Intelligence

TA558 Is Back, Targeting Hotels and Airlines With Fake Booking Emails

A criminal group that has quietly stolen travel-industry data since 2018 has dramatically ramped up its fake-reservation campaigns, now using compressed file tricks to sneak spying software onto victims' computers.

3 min read
Photoreal editorial image of an empty international airport departure gate at dawn, blue departure screens softly glowing, a lone rolling suitcase left near a s
Threat Intelligence

Alleged Scattered Spider member, 19, extradited to the US after airport arrest

Peter Stokes, a dual US-Estonian citizen picked up in Helsinki in April, is accused of helping the notorious hacking crew squeeze millions from big-name companies.

3 min read
Full-frame photoreal editorial image of a laptop screen showing a generic web browser with a red warning icon in the address bar and a blurred popup dialog, dim
Threat Intelligence

Opera's new Paste Protect tries to stop the copy-paste scam that's been draining wallets

The browser will now block dodgy commands before they reach your clipboard, targeting the ClickFix trick that has become criminals' favourite way to trick people into infecting their own computers.

3 min read
Close-up overhead view of several plain black USB thumb drives scattered across weathered asphalt in a parking lot, shallow depth of field, natural overcast day
Threat Intelligence

The USB Drop That Changed Pen Testing: Steve Stasiukonis's Credit Union Experiment, Revisited

Twenty years ago, a handful of booby-trapped thumb drives in a parking lot became one of the most-cited social-engineering case studies in security history. Here's what actually happened.

3 min read
Threat Intelligence

Scattered Spider Suspect, 19, Extradited From Finland to Chicago

Peter Stokes, a dual U.S.-Estonian citizen, faces conspiracy, intrusion and fraud charges tied to the loose-knit crew behind a string of high-profile enterprise breaches.

2 min read
Threat Intelligence

ClickFix Grows a Back Office: API-Served Payloads and a New AMSI Bypass

Researchers pulled roughly 3,000 live payloads from ClickFix infrastructure and found a polymorphic delivery pipeline built to defeat Windows script scanning.

2 min read
Threat Intelligence

SSU, FBI Detail Russian Phishing Op Targeting Signal and Telegram Accounts

Ukrainian counterintelligence says GRU and FSB-linked operators ran fake tech-support flows against officials' messengers across Ukraine, Europe, and the U.S.

2 min read
Identity & Access

The Service Desk Is the New Phishing Inbox

Help desks keep getting talked out of MFA resets. The fix is less about training and more about treating identity verification like an auth protocol.

3 min read
Threat Intelligence

ClickFix Campaign Turns Google Ads, GitLab, and Claude Into a Six-Wave Trust Machine

Attackers chained legitimate infrastructure across seven weeks to push malicious PowerShell commands to developers. Session tokens, SSH keys, and cloud credentials were the prize.

3 min read
Threat Intelligence

Three New Loaders Ride the ClickFix Wave: BabaDeda, Lorem Ipsum, and Potemkin

Separate research teams have pinned three distinct loader families on the same social-engineering pattern, with education and finance taking the brunt of the April 2026 activity.

3 min read
Threat Intelligence

Facebook Impersonation Scams Sweep MENA, Pushing Fake Subsidies and 'Free Data' Lures

Group-IB ties the campaign to a broader fraud network using cloned political figures, fake government programs and browser-push alerts to harvest credentials and payment data.

2 min read
Breaches

Tchap Account Takeover Exposes 73,000 French Government Users

France's sovereign messaging platform wasn't broken — a user was. Social engineering got an attacker inside, and unencrypted public rooms did the rest.

2 min read
AI Security

Attackers Are Wrapping Old Phishing Tricks in AI Branding. It's Working.

Microsoft and Google both dropped advisories this week documenting how threat actors are dressing up familiar credential theft and malware campaigns as ChatGPT, Copilot, and DeepSeek experiences. The technique is not new. The success rate is.

2 min read
© 2026 Threat Vectr