< ciso
brief />
Tag Banner

All news with #phishing tag

805 articles · page 3 of 41

Trezor Data Breach Now Affects 81,000 Customers

🚨 Trezor disclosed that an August data breach at its logistics partner ShipMonk has expanded to affect 81,000 customers after an additional 67,000 U.S. customers were found impacted. The exposed data includes full names, shipping addresses, email addresses, phone numbers, and order numbers for customers who ordered during specific periods between 2019 and 2026. Trezor confirmed its own systems and devices were not compromised and warned customers to expect increased phishing and fraud risk. The incident stems from a Metabase vulnerability and extortion attempts linked to the ShinyHunters gang.
read more →

Attackers conceal phishing lures with invisible Unicode

🔍 Microsoft researchers revealed a large-scale phishing campaign that used ASCII smuggling by inserting invisible Unicode tag characters into finance-related lure words to evade email filters. The operation peaked at about 2.37 million daily messages in late February and remained active, though diminished, through May 2026. Messages relied on domains promoting funding and loans and were sent via infrastructure tied to the ActiveCampaign platform. Microsoft recommends normalizing or stripping tag-block and other invisible code points before applying keyword or AI-based detection.
read more →

ThreatsDay roundup: phishing kits, AI risks, breaches

🛡️ This ThreatsDay bulletin surveys recent campaigns exploiting trusted tools and social engineering, from Microsoft Teams vishing to resilient phishing-as-a-service kits. It highlights ransomware affiliate playbooks, signed-software sideloading, a large ID-theft marketplace, and supply-chain risks tied to llms.txt misconfigurations. The report also notes Dropbox disclosed ~5,000 account compromises linked to legacy Lenovo IDs.
read more →

ASCII smuggling used to evade phishing filters

🛡️ Microsoft researchers observed a high-volume phishing campaign that used invisible Unicode tag characters (U+E0000–U+E007F) — a technique popularized in AI prompt-injection research as ASCII smuggling — to split finance lure words and evade email filters. The activity spiked on February 9, 2026, and persisted on weekdays for about three months before declining. Microsoft Defender for Office 365 telemetry shows most messages were caught by layered protections rather than a single Unicode-specific signal. The tactic leverages invisible tag characters to disrupt tokenization and literal keyword matching, making it harder for ML/NLP-based filters to detect phishing lures.
read more →

AI agents probing account and delivery defenses

📧 An autonomous AI agent reports field research on account creation and email deliverability, describing successes and failures across services. The agent details where protections actually trigger—captchas, IP reputation, account age, and resource costs—while pointing out accidental open doors such as permissive SMTP rules and reverse-DNS limits. It also documents defensive measures like prompt-injection tripwires on sign-up forms and publishes machine-readable door lists and notes.
read more →

Palo Alto Networks joins Zendesk Startup Program

🔒 Palo Alto Networks partners with the Zendesk Startup Program to offer startups enterprise-grade browser security. The post explains how Prisma Browser for Business (PBB) protects support agents and customer data by blocking phishing, preventing data leakage, and applying tailored policies to Zendesk sessions. The program allows eligible startups to access PBB with minimal setup, helping founders build securely from day one while preserving runway.
read more →

Revolut-targeted phone scams hit Jersey residents

📞 Police in Jersey warn residents to be vigilant after a spike in phone scams targeting Revolut accounts. Over a four-week period, 75% of reported scam incidents involved Revolut, with victims losing roughly £180,000. Callers impersonate bank staff, request security details, or ask victims to transfer funds to purportedly "safe" accounts. Revolut urges customers to use its secure in-app chat and never share passwords; police remind the public to report suspected fraud.
read more →

Chinese-speaking group weaponises Brazilian sites

🛡️ Check Point Research attributes a sustained SEO fraud and phishing campaign to a Chinese-speaking cluster dubbed Gambling Goblin, active since mid-2025. Attackers implanted custom Apache modules to act as reverse proxies on compromised Brazilian government, education and commercial websites, redirecting specific visitors to localized phishing pages that impersonated app stores and promoted betting. The operation leveraged a broad Linux malware toolkit including AlphaAgent, oRAT and credential stealers, plus reconnaissance tools to map targets.
read more →

Unsolicited praise emails puzzle newsletter author

📧 Bruce Schneier reports a sudden influx of brief, flattering replies to his newsletter confirmation emails. The messages are single-line praises and originate from apparently random Gmail addresses that never subscribed to Crypto-Gram. He initially replied to a few genuine-looking notes before realizing the volume and uniformity suggested AI-generated content. Schneier is uncertain of the senders' motive and asks readers for hypotheses about the possible scam.
read more →

Webinar: Google Workspace breach autopsy and response

📢 This live webinar on September 23, 2026, explores how fast-growing companies are breached via Google Workspace and what practical steps lean security teams can take. Speakers Rajan Kapoor of Material Security and Rick Fitzgerald of Fireside Consulting will analyze real, publicly documented incidents, focusing on social engineering, forgotten third-party integrations, and first-hour response decisions. The discussion emphasizes prioritized, realistic controls over long checklists.
read more →

LLM-Enabled Social Engineering Scams Rise

🔍 OpenAI disrupted a Cambodia-based social engineering group that leveraged ChatGPT to run coordinated scams. The network blended multiple fraud types—romance, fake investments, gambling schemes, and impersonation of authorities—using consistent deceptive personas and forged documents. Operators created fake profiles, counterfeit IDs and legal notices, and fabricated transaction confirmations to deceive victims and extract funds.
read more →

Phishing-as-a-Service Exploits AI Calls to Strip Activation Lock

📣 SOCRadar researchers uncovered a PhaaS platform called AnonyMousKIT that uses rented AI voice agents and multi-channel lures to trick owners of recently lost or stolen Apple devices into revealing passcodes, Apple ID credentials, and live 2FA codes. The service is credit-metered across email, SMS, WhatsApp, recorded calls, and AI calls, and its capture pages show device model and Find My status to increase believability. Calls—mostly to Brazil—ran between August 2025 and May 2026, and the kit is offered through multiple storefronts with shared infrastructure and operational features resembling a small criminal SaaS business.
read more →

Attackers Abuse npm Mirrors to Host Phishing Pages

📄 Threat actors are abusing npm packages and public mirrors to host malicious HTML that impersonates Cloudflare CAPTCHA pages and redirects visitors to attacker-controlled sites. Security researchers found multiple npm packages containing a single index.html that, when served through mirrors like unpkg, renders from legitimate domains and executes obfuscated JavaScript to redirect users. Some payloads fetch remote configuration (via api.keyval.org) allowing attackers to change redirect targets without republishing packages. OX Security warns mirrors can act as free frontend hosts for phishing content and recommends treating direct HTML requests to npm mirrors as suspicious.
read more →

AnonyMousKIT PhaaS Uses Voice AI to Phish iPhones

🔍 Researchers uncovered AnonyMousKIT, a phishing-as-a-service platform active since early 2024 that automates retrieval of codes to unlock stolen Apple devices and bypass Activation Lock. The service powers a broad ecosystem of 168 reseller storefronts and 506 linked domains. SOCRadar investigators recovered call records and transcripts showing voice AI agents impersonating Apple support to extract passcodes and account credentials, with most calls targeting Brazil.
read more →

How to Spot Suspicious and Risky Websites

🔎 This article explains how many websites fall into a gray area between legitimate services and outright scams, outlining common deceptive practices and how they harm users. It describes schemes such as hidden subscription traps, counterfeit or non-delivered goods, fraudulent crypto and investment platforms, and fake middlemen charging inflated fees. The piece also highlights dangerous fake browser extensions and recommends using Kaspersky security solutions, including the Kaspersky Protection browser extension and Kaspersky Premium, to detect, block, and warn about sites with uncertain trust.
read more →

ZeroTokens phishing platform enables live session control

🔒 A phishing platform named ZeroTokens gives attackers live visibility into victim sessions and lets operators change prompts in real time to steer interactions. The campaign, analyzed by Abnormal AI on August 25, sent over 45,000 messages to more than 24,000 recipients across 700+ organizations, using convincing pretexts and legitimate-looking email authentication. The platform replicated financial institutions' verification flows, collected credentials and codes, and used persistent WebSocket connections to relay victim inputs to operator consoles for adaptive attacks.
read more →

Large-Scale Debt-Relief Phishing Campaign Blocked

📧 Check Point detected and blocked a widespread email phishing campaign that used fraudulent debt-relief and financial hardship offers to trick recipients into calling attacker-controlled phone numbers. Over 14 days, about 24,700 messages targeted users at more than 9,000 organizations, highlighting phishing tactics that rely on social engineering and phone-based conversion rather than malicious links or attachments. Check Point Email Security uses AI, threat intelligence, and intent analysis to stop such campaigns before users engage.
read more →

Fake recruiter phishing targets corporate mobile logins

🔍 Researchers at Zimperium’s zLabs uncovered recruitment-themed phishing campaigns that target corporate credentials on mobile devices by presenting full-screen counterfeit login pages and rejecting personal email domains to prioritize enterprise accounts. The activity, linked to RecruitTrap, impersonated major employers and persisted across cloud, hosting and domain-parking providers, exposing gaps in URL blocklists. Zimperium recommends securing mobile identity touchpoints and dynamically inspecting network traffic to detect credential harvesting.
read more →

ReliaQuest confirms failed data-theft attempt after breach

🔒 ReliaQuest disclosed that an employee was targeted by a social engineering campaign in which attackers impersonated a security team member and hosted a fake SSO page. The actor obtained temporary, view-only access after the employee entered credentials and approved an MFA push, but device-trust controls prevented further access. ReliaQuest revoked sessions, reset tokens, and found no evidence of application, system, or customer data access.
read more →

Doubloon Dredger abuses Notion to harvest tokens

📄 Sublime's Threat Intelligence team identified a financially motivated actor, tracked as Doubloon Dredger, abusing free Notion accounts and malicious PDFs in July 2026 to harvest authentication tokens. Fake notifications from compromised Notion accounts bypassed DKIM/SPF/DMARC checks and steered victims to intermediary PDFs that redirected to an EvilTokens device-code phishing page. If users entered the provided code on Microsoft's legitimate device-code entry, attackers obtained authorization tokens and could access accounts and inboxes via tools like MailVault.
read more →