Skip to main content

Phishing Threats

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Type: Phishing

Filtered Threats

Click on any threat for detailed analysis and mitigation recommendations

Threat actors linked to extortion groups such as ShinyHunters and Helix are conducting passkey-themed phishing attacks targeting corporate Microsoft 365 accounts. These attacks use social engineering to impersonate IT help desks and trick employees into signing into adversary-in-the-middle phishing sites or authorizing device-code authentication flows. Once compromised, attackers perform reconnaissance and systematically exfiltrate data from Microsoft 365 services including SharePoint Online, OneDrive for Business, and Exchange Online. The attackers maintain persistence by registering MFA methods they control and avoid rapid data theft to evade detection.

Join the discussion

Hackers compromised the Brevo marketing platform by exploiting its SAML Single Sign-On (SSO) implementation, gaining unauthorized access to multiple customer accounts. Using this access, attackers sent phishing emails to approximately 347,000 Trezor users, among others, with malicious links designed to steal wallet backups. About 2,500 users clicked the phishing link before the malicious site was taken offline. The incident also involved exfiltration of contact data from 43 Brevo accounts. Other affected customers include BitBox and CoinTracking. This breach follows a recent data leak involving Trezor's third-party shipping provider, increasing the risk of targeted phishing attacks.

Join the discussion

Trezor customers were targeted in a phishing campaign after a breach of Brevo, Trezor's third-party email marketing provider. Approximately 347,000 email addresses were exposed, and 2,500 users clicked on malicious links in phishing emails that impersonated Trezor and claimed a hardware vulnerability. The phishing emails attempted to trick users into downloading an app to steal wallet backup seeds. Trezor quickly took down the malicious domain within 20 minutes, limiting the impact. The breach only affected the newsletter database, and no other Trezor systems were compromised. This incident follows previous breaches involving Trezor's support and logistics providers.

Join the discussion

Trezor warned customers that threat actors who breached its third-party email provider are conducting phishing attacks targeting its users. The phishing emails impersonate Trezor and claim a critical hardware vulnerability, attempting to trick recipients into clicking malicious links. Trezor has taken down the fraudulent domain and is investigating the breach. This incident follows a prior data breach involving Trezor's shipping provider ShipMonk, which exposed customer order data affecting tens of thousands of users across multiple countries. The phishing attack leverages compromised email infrastructure rather than a direct vulnerability in Trezor products.

Join the discussion

A new phishing attack technique uses trusted Microsoft services and blob URLs to create phishing pages that exist only inside the victim's browser, leaving no static web page for defenders to detect or block. The attack starts with a Docusign-themed email containing a calendar invite to appear legitimate. The victim is redirected through Microsoft Teams to an external resource, which the browser converts into a blob URL rendering the phishing page locally. This method leverages trusted assets to evade traditional detection methods and enables centralized control of the phishing workflow. Detection requires new approaches focusing on browser activity and identity protection rather than static URL or domain blocking.

Join the discussion

Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack. [...]

MediumPhishing
Join the discussion

A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. [...]

Join the discussion

Threat actors are using invisible Unicode characters in phishing emails to evade detection by email security filters. This technique, known as ASCII smuggling, involves inserting invisible Unicode characters inside finance-related lure words to split them and bypass keyword-based filters. Microsoft observed a large-scale campaign using this method, peaking at 2.37 million daily messages in early 2026. The phishing messages promote business funding, loans, and credit services and are sent through infrastructure linked to the legitimate ActiveCampaign email-marketing platform. Microsoft Defender still detected over 99% of these messages using other signals. Microsoft recommends normalizing or stripping invisible Unicode characters before applying detection rules to improve filtering effectiveness.

Join the discussion

Huntress researchers discovered Knight Office, a phishing kit utilizing Adversary-in-the-Middle techniques to steal Microsoft 365 session tokens. The attack chain begins with DocuSign-themed phishing emails containing redirects through Monday.com and compromised Joomla websites. Victims are directed to credential capture pages where session tokens are harvested and fed into the Knight Office console. These stolen tokens enable attackers to bypass multi-factor authentication entirely by using already-authenticated sessions. In one incident, attackers registered rogue devices in Microsoft Entra ID and bound Windows Hello for Business credentials for persistence. Analysis revealed nine phishing attacks linked to this kit over two weeks, with hundreds of related emails reported since April. The console, hosted at IP 104.37.188.94, manages at least 25 phishing domains using .vu top-level domains.

Join the discussion

Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. This abuse involves leveraging the admin tool to deploy unauthorized remote access software, potentially enabling attackers to control affected systems remotely.

Join the discussion

Showing 1 to 10 of 346 results

Filters:Type: Phishing
Page 1 of 35
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses