Threats Tagged 'phishing'
View all threats tagged with 'phishing'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'phishing'
Click on any threat for detailed analysis and mitigation recommendations
Microsoft has issued a reminder for administrators to migrate Entra ID users to phishing-resistant authentication methods, such as passkeys, ahead of the planned retirement of SMS-based first-factor sign-in in February 2027. This change aims to improve security by reducing reliance on less secure SMS authentication. Join the discussion | Bleeping Computer | 09/21/2026, 13:16:20 UTC Added: 09/21/2026, 13:16:38 UTC |
Cybercriminals have created numerous fake websites mimicking Bitrefill, a legitimate cryptocurrency-based gift card and eSIM retailer. These fraudulent sites appear in search engine results and use lookalike domains incorporating the Bitrefill brand name with added words or character substitutions, including internationalized domain names using Punycode. Victims are guided through convincing checkout processes that replicate Bitrefill's legitimate payment flow, complete with cryptocurrency options, QR codes, and countdown timers. However, payments are sent directly to attacker-controlled cryptocurrency addresses rather than Bitrefill, with virtually no chance of recovery. The operation demonstrates sophisticated measurement using commercial analytics software to optimize conversion rates, indicating organized criminal activity rather than opportunistic fraud. Join the discussion | AlienVault OTX General | 09/15/2026, 12:44:15 UTC Added: 09/15/2026, 13:47:19 UTC |
Threat actors linked to extortion groups such as ShinyHunters and Helix are conducting passkey-themed phishing attacks targeting corporate Microsoft 365 accounts. These attacks use social engineering to impersonate IT help desks and trick employees into signing into adversary-in-the-middle phishing sites or authorizing device-code authentication flows. Once compromised, attackers perform reconnaissance and systematically exfiltrate data from Microsoft 365 services including SharePoint Online, OneDrive for Business, and Exchange Online. The attackers maintain persistence by registering MFA methods they control and avoid rapid data theft to evade detection. Join the discussion | Bleeping Computer | 09/11/2026, 17:26:50 UTC Added: 09/11/2026, 17:32:18 UTC |
A large-scale phishing simulation study involving 2.47 million simulated attacks across 1,200 organizations reveals that measuring only click rates in phishing awareness tests is insufficient. The research shows that credential leaks and reporting behaviors are critical metrics for assessing true phishing resilience. Different industries and teams exhibit varying susceptibility, with tech and IT employees surprisingly vulnerable. Sustained training programs improve reporting rates and reduce leaks over time, but initial click and leak rates may increase before declining. The study emphasizes the need for nuanced phishing risk profiles and continuous, behavior-focused training beyond simple click metrics. Join the discussion | SecurityWeek | 09/11/2026, 17:23:36 UTC Added: 09/11/2026, 17:31:57 UTC |
This report summarizes multiple cybersecurity news items including a new InjectEave electromagnetic side-channel attack, a SIM swapping conviction, and findings on the Glasswing vulnerability ledger. The InjectEave attack allows attackers to recover audio or appliance states remotely by inducing hardware nonlinearities with RF signals. A former AT&T employee was sentenced for SIM swapping that enabled bank account takeovers. The Glasswing review found a low remediation rate of reported vulnerabilities and discrepancies in severity assessments. Other highlights include phishing evasion using invisible Unicode, a US bounty on an Iranian cyber official, and ties between a Chinese hacking group and military contractors. Join the discussion | SecurityWeek | 09/11/2026, 14:19:18 UTC Added: 09/11/2026, 14:31:57 UTC |
Hackers compromised the Brevo marketing platform by exploiting its SAML Single Sign-On (SSO) implementation, gaining unauthorized access to multiple customer accounts. Using this access, attackers sent phishing emails to approximately 347,000 Trezor users, among others, with malicious links designed to steal wallet backups. About 2,500 users clicked the phishing link before the malicious site was taken offline. The incident also involved exfiltration of contact data from 43 Brevo accounts. Other affected customers include BitBox and CoinTracking. This breach follows a recent data leak involving Trezor's third-party shipping provider, increasing the risk of targeted phishing attacks. Join the discussion | SecurityWeek | 09/11/2026, 12:48:04 UTC Added: 09/11/2026, 13:01:57 UTC |
Trezor customers were targeted in a phishing campaign after a breach of Brevo, Trezor's third-party email marketing provider. Approximately 347,000 email addresses were exposed, and 2,500 users clicked on malicious links in phishing emails that impersonated Trezor and claimed a hardware vulnerability. The phishing emails attempted to trick users into downloading an app to steal wallet backup seeds. Trezor quickly took down the malicious domain within 20 minutes, limiting the impact. The breach only affected the newsletter database, and no other Trezor systems were compromised. This incident follows previous breaches involving Trezor's support and logistics providers. Join the discussion | Bleeping Computer | 09/11/2026, 07:55:15 UTC Added: 09/11/2026, 08:01:58 UTC |
In August 2026, a Casbaneiro campaign targeted Latin American users through phishing emails and PDFs themed as fake invoices and legal notices. The multi-stage infection chain includes HTA downloaders and AutoIt loaders, employing geofencing to filter victims by IP address location. The malware exhibits sophisticated evasion techniques, including distributed data-receiving servers, deliberate HTTP 403 responses, and activation only when victims access targeted banking websites. Casbaneiro steals email data, performs clipboard injection, and creates fake windows for fraudulent activities. The campaign specifically targets Argentina, Peru, Colombia, and Mexico while avoiding German, French, and English language systems. The malware splits stolen data across multiple servers and uses malformed HTTP packets to complicate detection and analysis efforts. Join the discussion | AlienVault OTX General | 09/10/2026, 17:27:46 UTC Added: 09/11/2026, 09:02:09 UTC |
Trezor warned customers that threat actors who breached its third-party email provider are conducting phishing attacks targeting its users. The phishing emails impersonate Trezor and claim a critical hardware vulnerability, attempting to trick recipients into clicking malicious links. Trezor has taken down the fraudulent domain and is investigating the breach. This incident follows a prior data breach involving Trezor's shipping provider ShipMonk, which exposed customer order data affecting tens of thousands of users across multiple countries. The phishing attack leverages compromised email infrastructure rather than a direct vulnerability in Trezor products. Join the discussion | Bleeping Computer | 09/10/2026, 06:56:33 UTC Added: 09/10/2026, 07:07:20 UTC |
Two sophisticated phishing campaigns employed browser-in-the-browser (BiTB) techniques to deceive victims into installing rogue ScreenConnect remote management tools. Attackers sent phishing messages with malicious links redirecting targets to fake Adobe Reader update pages. The BiTB technique created convincing fake browser windows within webpages, displaying legitimate-looking Adobe URLs to bypass user awareness training. Victims were tricked into downloading ScreenConnect installers disguised as Adobe software updates. Each incident resulted in deployment of multiple rogue ScreenConnect instances for redundant persistence, followed by execution of defense-evasion binaries (HideCursor.exe and HideUL.exe) designed to hide attacker activities. The attacks established service-based persistence through Windows services, enabling continued remote access. Both campaigns were intercepted before further damage occurred, demonstrating how threat actors combine social engineering throughout the entire attack chain... Join the discussion | AlienVault OTX General | 09/09/2026, 15:55:36 UTC Added: 09/10/2026, 05:52:16 UTC |
Showing 1 to 10 of 321 results