Phishing Threats
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Filtered Threats
Click on any threat for detailed analysis and mitigation recommendations
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms 0 The 0ktapus threat group conducted a large-scale phishing campaign targeting over 130 companies, primarily aiming to steal Okta identity credentials and multi-factor authentication (MFA) codes. The attackers sent text messages with links to phishing sites mimicking the Okta authentication pages of targeted organizations. This campaign compromised nearly 10,000 accounts across more than 130 organizations, including 114 US-based firms and victims in 68 other countries. Initial attacks targeted telecommunications companies to gather phone numbers used in MFA attacks. The ultimate goal was to access internal systems and facilitate supply-chain attacks. The campaign demonstrated how attackers can bypass MFA protections through phishing. Researchers recommend using FIDO2-compliant security keys and educating users about MFA attack methods to mitigate such threats. Join the discussion | Threatpost | 08/29/2022, 14:56:19 UTC Added: 08/04/2026, 12:41:23 UTC |
Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st) 0 Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.
 MediumPhishing Join the discussion | SANS ISC Handlers Diary | 08/01/2026, 07:22:32 UTC Added: 08/01/2026, 07:33:00 UTC |
Built a "defensive deception" layer that feeds believable fake data to unauthorized readers — looking for fresh eyes to try to break it (beta) ? 0 Built a "defensive deception" layer that feeds believable fake data to unauthorized readers — looking for fresh eyes to try to break it (beta) ? Source: https://break-izanami.com Join the discussion | Reddit BlueTeam | 07/27/2026, 02:13:47 UTC Added: 07/27/2026, 02:37:03 UTC |
ShinyHunters data leaks fuel $2,000 sextortion email scam 0 Threat actors are leveraging email addresses exposed in data breaches attributed to the ShinyHunters extortion group to conduct sextortion email scams. These emails demand $2,000 in Bitcoin from recipients, attempting to extort money by threatening to release compromising information. This is a phishing campaign exploiting leaked personal data rather than a software vulnerability. MediumPhishing Join the discussion | Bleeping Computer | 07/25/2026, 14:16:26 UTC Added: 07/25/2026, 14:52:13 UTC |
Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass 0 Device code phishing exploits the OAuth 2.0 device authorization grant, a legitimate authentication feature designed for input-limited devices like smart TVs. Attackers initiate a device-code request with Microsoft, receive a valid code, then trick victims into approving it through social engineering. The victim authenticates on genuine Microsoft pages and completes MFA, but the session tokens are issued to the attacker instead. When targeting the Microsoft Authentication Broker, attackers can register rogue devices and obtain long-lived refresh tokens for persistent access. A recent campaign used sophisticated multi-stage delivery chains involving Google Sites, compromised website redirectors, and fake document-sharing portals. After successful authentication, attackers registered multiple devices, created hidden mailbox rules, and used compromised accounts to send additional phishing emails, all without touching victim endpoints. Join the discussion | AlienVault OTX General | 07/23/2026, 07:30:50 UTC Added: 07/23/2026, 15:22:23 UTC |
Inside a Global Procurement-Themed AiTM Phishing Campaign 0 A sophisticated adversary-in-the-middle phishing campaign is targeting universities, enterprises, and multinational institutions including EU and UN agencies. Active since May 2026, the operation leverages compromised organizational email accounts to distribute procurement-themed lures that mimic requests for information, bid invitations, and project documentation. Victims are redirected through fake document portals, CAPTCHA verification stages, and cloned authentication pages impersonating Microsoft, OpenGov, and financial institutions. The attacker rotates between multiple AiTM phishing kits including EvilProxy, FlowerStorm, and Kali365 to intercept MFA-protected sessions in real time, capturing session tokens and cookies to establish authenticated access. Rather than using newly registered domains, the actor compromises aged domains that have been dormant for years, injecting PHP files to host phishing infrastructure and evade detection through domain reputation systems. Join the discussion | AlienVault OTX General | 07/22/2026, 00:59:04 UTC Added: 07/22/2026, 08:07:06 UTC |
Police dismantle Kratos phishing platform, arrest developer 0 Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia. [...] MediumPhishing Join the discussion | Bleeping Computer | 07/21/2026, 23:07:33 UTC Added: 07/21/2026, 23:22:13 UTC |
When Inclusive Language ends in phishing 0 This threat involves a passive phishing campaign that exploits the use of inclusive language in emails by abusing ".es" domain suffixes. Legitimate users include words ending with ".es" as part of inclusive language, but attackers register these domains to redirect victims to fake Microsoft 365 login pages or malicious browser extension installation pages. The campaign is subtle and effective because it targets internal communications and leverages trusted third-party partners, making the malicious links appear legitimate. No specific affected software versions are identified. No known exploits in the wild have been reported. Join the discussion | Reddit Cybersecurity | 07/16/2026, 09:11:30 UTC Added: 07/16/2026, 09:17:27 UTC |
Operation Fake KickOff: Attackers Abuse Recruiters and SaaS to Harvest Work Credentials 0 A sophisticated multi-stage phishing operation has been active since April 2025, systematically exploiting legitimate SaaS platforms and cloud services to steal corporate credentials. The campaign utilizes 232 phishing domains and 80 command-and-control servers, primarily impersonating human resources consulting firms, with Robert Half Inc. and Aquent LLC representing 50% of targeted brands. Attackers leverage legitimate platforms like Salesforce, SendGrid, and Zoho for email delivery, directing victims to fake Calendly interview pages that mimic real recruiter identities. The operation deploys an adversary-in-the-middle toolkit using browser-in-the-box techniques to create replica Google sign-in pages, capable of harvesting credentials and bypassing MFA through email, SMS, Google Authenticator, and prompt notifications. The campaign specifically targets corporate email accounts, filtering out personal providers, with stolen data exfiltrated to Render-hosted servers and Telegram bots. Join the discussion | AlienVault OTX General | 07/15/2026, 20:49:51 UTC Added: 07/15/2026, 22:03:24 UTC |
Dutch police bust investment fraud ring stealing over €100 million 0 The Dutch Police announced the arrest of multiple individuals suspected of being part of an international investment fraud scheme estimated to have tens of thousands of victims. [...] MediumPhishing Join the discussion | Bleeping Computer | 07/15/2026, 21:55:50 UTC Added: 07/15/2026, 22:03:09 UTC |
Showing 1 to 10 of 26 results