< ciso
brief />
Tag Banner

All news with #business email compromise tag

140 articles

CSuite phishing campaign escalates to account and endpoint access

πŸ” ANY.RUN researchers traced a US-focused CSuite phishing campaign across hundreds of sandbox analyses, finding 51% of submissions from the United States and heavy exposure in technology, manufacturing, government, and consulting. The operation uses business-themed lures (Adobe, DocuSign, Zoom, Microsoft 365) to either harvest credentials or deliver droppers that install legitimate remote-access tools like ScreenConnect and Action1. This dual path enables mailbox takeover, financial fraud, persistent RMM access, and lateral misuse of trusted identities, expanding impact beyond typical phishing.
read more β†’

Ex-Air Force Members Sentenced for BEC Fraud

πŸ”’ Two former U.S. Air Force airmen were sentenced to a combined 189 months in federal prison for conducting multi-year business email compromise (BEC) and phishing campaigns while stationed at Dover Air Force Base. They stole employee email credentials, used spoofed addresses to redirect corporate payments, and laundered funds through accomplices in the U.S. and abroad. The pair diverted millions in wire transfers and were also ordered to pay substantial restitution and serve supervised release after prison.
read more β†’

Microsoft disruption exposes AI-driven phishing-as-a-service

πŸ”Ž Microsoft says it disrupted EvilTokens, an AI-powered phishing-as-a-service platform that compromised over 12,000 Microsoft 365 inboxes across more than 10,000 organizations. Launched in February 2026, EvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation behind a subscription dashboard and chatbot. The operation abused Microsoft’s OAuth 2.0 device-code flow to steal session tokens and used an AI analyst to scan mailboxes and craft business email compromise scams. Microsoft seized infrastructure via a US court order and partners arrested two suspects in the UK amid coordinated takedown efforts.
read more β†’

Five Black Axe Members Extradited to US Courts

πŸ“° Five alleged leaders of the Black Axe cybercrime syndicate were extradited from South Africa to the United States to face wire fraud, money laundering, and aggravated identity theft charges. Prosecutors allege the defendants ran romance and advance-fee scams targeting U.S. victims from Cape Town between 2011 and 2021, using aliases, social media, dating sites, and VoIP services to defraud and coerce victims. Arrested in 2021 at U.S. request, they face significant prison terms if convicted.
read more β†’

Revolut data breach exposes sensitive customer records

πŸ”’ Fintech firm Revolut disclosed a data breach after an attacker impersonating a government agency obtained customer data by sending requests from an email address using the agency's legitimate domain. The company said the request carried valid domain authentication, so it was fulfilled in good faith, and that systems and customer funds remain unaffected. Affected records include identity documents, contact details, account statements, transaction histories, and facial verification images, and Revolut says only a very limited number of customers were impacted.
read more β†’

Threat Actors Use Passkey Phishing to Breach Cloud

πŸ›‘οΈ Microsoft disclosed two related campaigns: one sent over a million CEO-impersonation invoice scams in August 2026 to induce ACH transfers, and the other used passkey-themed social engineering since May 2026 to compromise cloud accounts. The fraud campaign leveraged generative AI, forged threads, and bogus domains to target enterprise finance teams. Cloud intrusions employed voice/SMS pretexts, counterfeit sign-in pages, AitM and device-code flows, and persistent MFA enrollment to enable extensive Microsoft Graph, SharePoint, OneDrive, and mailbox access.
read more β†’

AI-assisted Executive Impersonation Invoice Fraud

πŸ” This Microsoft Threat Intelligence blog describes a large campaign in early August that used third-party email services to send over a million invoice-fraud emails impersonating executives and vendors. The actor layered CEO impersonation, fabricated invoices, and forged vendor threads to convince finance teams to initiate ACH payments near $50,000. Microsoft details indicators of AI-assisted template generation, observed domains and addresses, and recommended Defender and mail-authentication mitigations.
read more β†’

Revolut-targeted phone scams hit Jersey residents

πŸ“ž Police in Jersey warn residents to be vigilant after a spike in phone scams targeting Revolut accounts. Over a four-week period, 75% of reported scam incidents involved Revolut, with victims losing roughly Β£180,000. Callers impersonate bank staff, request security details, or ask victims to transfer funds to purportedly "safe" accounts. Revolut urges customers to use its secure in-app chat and never share passwords; police remind the public to report suspected fraud.
read more β†’

INTERPOL Operation Jackal IV Targets West African Crime

πŸ›‘οΈ An eight-month INTERPOL operation has led to 58 arrests and the identification of 263 suspects linked to West African organized crime groups, including Black Axe. The effort, involving 22 countries across six continents, targeted cyber-enabled fraud, romance and investment scams, and money laundering. Investigations uncovered a major crime-as-a-service network and disrupted call-center and syndicate operations responsible for large-scale thefts and laundering.
read more β†’

Global cybercrime crackdown leads to dozens of arrests

πŸ“° International law enforcement actions led to the identification of 263 suspects and 58 arrests connected to West African-organized cybercrime networks during Operation Jackal IV, conducted from November 2025 to June 2026. The operation targeted the Black Axe syndicate and related groups involved in romance, cryptocurrency, investment scams and business email compromise, with arrests and seizures across Argentina, South Africa, Romania and Italy. Authorities disrupted money-laundering services, blocked accounts and confiscated millions while highlighting the use of Crime-as-a-Service and coercion tactics against victims.
read more β†’

Agent Tesla v4 uses emoji obfuscation to evade detection

πŸ›‘οΈ KnowBe4 has identified a new Agent Tesla v4 campaign using emoji-based obfuscation and a JScript dropper to bypass detection and steal credentials. The lure leveraged a convincing BEC email spoofing a Philippine bank and instructing finance staff to open an attachment. The dropper embeds Unicode emoji characters to disrupt signature matching, then uses DonutLoader for reflective PE injection so the final binary never touches disk. Researchers advise updating email security and creating YARA rules that combine emoji patterns with JScript function calls to detect the threat.
read more β†’

Ransomware Forces Shift Toward Enterprise Resilience

πŸ”’ Ransomware has evolved from simple encryption schemes into multifaceted campaigns that combine data theft, extortion, and operational disruption. Attackers increasingly leverage AI and target third parties, expanding the attack surface and complicating detection. CISOs must now prioritize business continuity, vendor risk, and AI governance alongside traditional security controls to maintain trust and operational resilience.
read more β†’

Communication Channels and Identity Risks in SaaS Era

πŸ›‘οΈ Enterprise collaboration platforms are now central to business workflows and have become part of the identity attack surface. Threat actors increasingly misuse trusted collaboration tools for identity phishing, impersonation, credential theft and malware delivery, often leveraging compromised accounts, external federation or guest access. Unit 42 observations show a significant rise in malicious activity tied to collaboration tools, and defenders may lack visibility into actions that occur after authentication. The report reviews techniques attackers use and offers detection and mitigation guidance, noting enhanced protection through Palo Alto Networks products.
read more β†’

Using Crime Script Analysis to Explain Cyber Attacks

πŸ” Crime script analysis (CSA) breaks cyber attacks into sequences of actions, decisions, and situational requirements, making complex campaigns accessible to non-technical audiences. CSA complements models like MITRE ATT&CK and the Lockheed Martin Cyber Kill Chain by offering a narrative view that highlights practical "choke points" for disruption. The post illustrates CSA with a business email compromise (BEC) example and explains how AI can both enable attackers and provide new detection opportunities. Practical mitigations include honeypot canary organizations, provider-side detection of malicious LLM use, email rate-limiting, and stricter payment verification processes.
read more β†’

OpenAI Disrupts Cambodia-Based Scam Network

πŸ›‘οΈ OpenAI says it dismantled a Poipet-based scam operation that used ChatGPT to run investment, romance, gambling, and law-enforcement impersonation schemes. The company banned a coordinated cluster of accounts tied to Poipet that created fake personas, generated promotional content, translated messages, and handled administrative tasks. OpenAI investigated in partnership with WhatsApp and highlighted the hybrid, opportunistic nature of modern scam networks.
read more β†’

Phishing service spoofs RingCentral to steal Microsoft 365

πŸ“§ The Greatness phishing-as-a-service platform has expanded to adversary-in-the-middle and device-code phishing targeting Microsoft 365 users across several countries. Operators abused RingCentral to bypass filters by leveraging whitelisting and fraudulent verification banners to lower suspicion. Victims were routed to AiTM or device-code flows that captured MFA-approved tokens, enabling long-lived access to mailboxes, Teams, SharePoint, OneDrive, and more.
read more β†’

Interpol: AI now drives majority of African cybercrime

πŸ” Interpol reports that AI-driven cybercrime accounted for 55% of all reported digital crime in Africa in its African Cyberthreat Assessment Report 2026. The report, compiled from data provided by 36 member countries, links AI-powered scams, social engineering and credential harvesting to a rise in losses from $192m in 2024 to $484m in 2025. It highlights threats such as AI-enabled deepfake sextortion, sophisticated BEC campaigns, AI-driven ransomware, and the growth of Cybercrime-as-a-Service platforms.
read more β†’

LogoKit uses live site screenshots for phishing

πŸ›‘οΈ Barracuda researchers observed LogoKit phishing campaigns that build a unique login page for each victim in real time by pulling a live screenshot of the target organization’s website as the page background. The kit extracts the victim email from the URL, identifies the employer domain, and uses commercial services like Thum.io and Clearbit to assemble a convincing, per-victim page. Credential harvesting is routed via a Telegram bot, and victims are redirected to the genuine site, complicating detection and takedown.
read more β†’

Spanish police dismantle €140M cyber fraud ring

πŸ” Spanish police dismantled an industrial-scale cybercrime and money-laundering operation that stole €140 million via investment fraud and business email compromise. Four suspects were arrested across Spain, Portugal, and Panama after raids on multiple premises and an international operation with Interpol and Europol. Authorities seized digital devices, froze €3 million in proceeds, and identified hundreds of mule accounts used to launder funds.
read more β†’

Forg365 PhaaS Targets Microsoft 365 Accounts

πŸ›‘οΈ A new phishing-as-a-service operation named Forg365 targets Microsoft 365 by combining device-code phishing, AitM tactics, antibot evasion, AI-assisted lure creation, and post-compromise mailbox operations. Distributed via Telegram and offered as a subscription, the kit uses legitimate delivery infrastructure like Amazon SES and SendGrid to blend into normal email flows before redirecting victims to attacker-controlled domains. The platform includes a clearnet operator panel, OAuth and token handling, and a Chromium extension called ForgCookie that automates cookie refresh and sustained access to compromised accounts.
read more β†’