<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/phishing" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Phishing ]]></title>
                <link>https://www.itpro.com/security/phishing</link>
        <description><![CDATA[ All the latest phishing content from the ITPro team ]]></description>
                                    <lastBuildDate>Fri, 24 Jul 2026 08:23:13 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ NCSC issues alert over 'zero-click' phishing campaign hitting enterprises ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/ncsc-issues-alert-over-zero-click-phishing-campaign-hitting-enterprises</link>
                                                                            <description>
                            <![CDATA[ Ukrainian organizations were used to test new zero-click techniques employed by Russian hackers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TBMSiPEYprpUySAU2QTRDj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Jul 2026 08:23:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:description>                                                            <media:text><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK’s <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> has issued an alert over a new ‘zero-click’ threat campaign being waged by Russian state-backed hackers.</p><p>The advisory, published in collaboration with international partners, warned ‘beehive’ attacks by the ‘Laundry Bear’ threat group aim to steal email correspondence at organizations operating across a range of critical sectors. </p><p>This includes organizations in the defense, education, energy, and technology industries, as well as law enforcement and government agencies. </p><p>Attacks against these organizations all have a common theme, according to the NCSC, mainly the use of Zimbra Collaboration Suite (ZCS) software. Targeting focuses specifically on those using vulnerable versions of the software, the advisory noted. </p><p>Rather than requiring users to click a link or open a file, zero-click attacks mean users only have to view a malicious email to be compromised. </p><p>The NCSC urged organisations that use ZCS to follow mitigation advice, patch immediately, and “improve network monitoring capabilities”. </p><p>Crucially, analysis of the campaign found these techniques could be adapted to exploit vulnerabilities in other email software applications used by Western organizations. </p><p>“This <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaign demonstrates how hostile actors will ruthlessly adapt techniques and exploit vulnerable technology in pursuit of their aims to steal sensitive information from Western organizations,” said NCSC chief operating officer (COO) Beth Hopkins.</p><h2 id="ukrainian-organizations-used-in-testing">Ukrainian organizations used in testing </h2><p>According to the NCSC, the techniques used by Laundry Bear were “extensively trialled” on Ukrainian victims before use against other Western nations. The security agency noted this is part of a growing trend among Russian threat groups.</p><p>Notably, technical analysis of the campaign also highlighted the use of AI in development of a “simple codebase” used during operations. </p><p>Zero-click attacks have surged in frequency over the last 12 months, research shows, with threat actors accelerating efforts to capitalize on vulnerabilities. </p><p><a href="https://www.rapid7.com/blog/post/tr-q1-2026-threat-landscape-report-geopolitics-ransomware/" target="_blank"><u>Analysis from Rapid7</u></a> found that vulnerability exploitation has now surpassed social engineering as the “largest initial access vector”, accounting for more than one-third (38%) of all attacks. </p><p>More than 50% of all exploited vulnerabilities involved zero-click attacks, rather than network-facing vulnerabilities, the study noted, highlighting evolving techniques by threat actors. </p><p>“These types of vulnerabilities require no authentication and no user interaction, giving attackers rapid pathways into exposed systems and edge infrastructure,” Rapid7 noted. </p><p>Dray Agha, senior manager of security operations at Huntress, said these types of exploits are a “worst-case scenario for defenders” as potential victims are only required to view malicious emails. </p><p>“Simply viewing the email in a vulnerable client triggers the compromise,” he explained. “This completely bypasses traditional employee security training and gives state-backed hackers a silent, invisible backdoor into sensitive communications without the victim ever making a mistake.”</p><p>Agha said the rise of these techniques mean organizations need to place a greater focus on regular patching to avoid falling prey. </p><p>“This is why defense-in-depth is advised, as where the human security layer is porous, the technical defensive layer can step in,” he said. </p><p>“Organizations shouldn’t just rely on their staff acting as a ‘human firewall’. Rapid software patching, coupled with layered technical defenses, is the only reliable safety net against modern state-sponsored threats.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Multi-channel phishing attacks: How to manage the risk ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/multi-channel-phishing-attacks-how-to-manage-the-risk</link>
                                                                            <description>
                            <![CDATA[ Attackers are evolving beyond email towards phishing across multiple channels. Why is this, and what can be done to manage the risk? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SesFueAF7AB4ZgF8y8JrvA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Vwb8TLBgSxGdDgEKAcxuKZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 08 Jul 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Vwb8TLBgSxGdDgEKAcxuKZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A cartoon graphic depicting phishing as a service, shown as bugs, keys, fingerprints, bitcoins, shields, eyes, etc surrounding a fish hook. All are placed on a light grey background.]]></media:description>                                                            <media:text><![CDATA[A cartoon graphic depicting phishing as a service, shown as bugs, keys, fingerprints, bitcoins, shields, eyes, etc surrounding a fish hook. All are placed on a light grey background.]]></media:text>
                                <media:title type="plain"><![CDATA[A cartoon graphic depicting phishing as a service, shown as bugs, keys, fingerprints, bitcoins, shields, eyes, etc surrounding a fish hook. All are placed on a light grey background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Vwb8TLBgSxGdDgEKAcxuKZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Email <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a> has always been a simple yet effective form of attack. While the method isn’t going away, research is showing attackers evolving beyond email to multiple channels such as Slack and cloud-based platforms. </p><p>That’s according to security firm KnowBe4’s Phishing Threat Trends report, which <a href="https://www.itpro.com/security/phishing/the-inbox-is-no-longer-the-only-frontline-phishing-attacks-are-evolving-as-cyber-criminals-ramp-up-multi-channel-campaigns-over-email-and-microsoft-teams"><u>found</u></a> hackers are leveraging new “touchpoints” when targeting victims, with calendar invites and messaging tools a frequent tactic. The company recorded a 41% increase in Microsoft Teams-based attacks between October 2025 and March 2026 as adversaries strived to create more avenues for success.</p><p>With <a href="https://www.itpro.com/uk/technology/artificial-intelligence"><u>AI</u></a> offering cybercriminals the ability to supercharge phishing attacks further, what should businesses be doing to manage the risk?</p><h2 id="phishing-evolution">Phishing evolution</h2><p>In the past, phishing attacks relied on adversaries targeting a wide range of users in the hope that some of them would engage with malicious content, or give away valuable information.<strong> </strong>But since then, businesses have improved their security, with tools such as <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication"><u>multi-factor authentication</u></a> (MFA) used as standard. This has forced attackers to utilize more sophisticated techniques. </p><p>“When attackers cannot compromise technical controls, such as MFA, they are instead seeking to bypass the technology and move the attack onto end users through social engineering,” says Luiz Simpson, head of offensive security at Bridewell.</p><p>He cites the example of <a href="https://learn.microsoft.com/en-us/defender-office-365/detect-and-remediate-illicit-consent-grants"><u>illicit consent grant</u></a> attacks in Microsoft 365, which trick users into granting access to data. These attacks often “go completely under the radar”, says Simpson. “Users will accept an untrustworthy app while logged into their cloud workspace and under the legitimate Microsoft or Google workspace platforms. These attacks don’t require any bypass of MFA and almost always aren’t flagged by detection and response.”</p><p>Another reason attackers are targeting multiple channels is the fact that the workplace itself has changed.  “Employees now spend far more time in collaboration platforms, cloud applications, messaging tools, and video conferencing environments,” says Ray Canzanese, director of Netskope Threat Labs. “Attackers are following that behavior.”</p><p>Canzanese describes how phishing lures are increasingly delivered through platforms such as Microsoft Teams, Zoom and fake meeting invitations. “These are designed to exploit the trust users place in familiar collaboration workflows.”</p><p>From a criminal perspective, multi-channel phishing is becoming “progressively structured”, according to Benson Varghese, a criminal lawyer and founder and managing partner at law firm Varghese Summerset. Rather than flooding potential victims with random messages, phishers will prepare their sequence, test the response rate, and react to engagement in real-time, he says. “This makes attacks more focused and effective.”</p><h2 id="security-shift">Security shift </h2><p>Experts believe the evolution of phishing requires businesses to change the way they think about securing communication channels.</p><p>The shift means no longer treating phishing as purely an email security problem. “Security teams need visibility across a much broader digital environment that includes collaboration tools, cloud platforms, browsers, unmanaged devices and AI applications,” according to Canzanese. </p><p>Almost all social media platforms include user messaging, which supports the distribution of links and images. Yet historically, the focus on preventing <a href="https://www.itpro.com/security/a-new-silent-social-engineering-attack-is-being-used-by-hackers-and-your-security-systems-might-not-notice-until-its-too-late"><u>social engineering attacks</u></a> has been around traditional email-based messages, encouraging users to avoid clicking links. “None of these defences will help prevent attackers from contacting end users and sending malicious content across other channels,” says Simpson.  </p><p>“As these interactions do not arrive via traditional email, there is no URL rewriting, sandboxing or inspections of content,” he points out. “This leaves you with just endpoint and identity-based controls to protect users.”</p><p>However, endpoint detection and response (EDR) solutions traditionally fall short in having visibility of what goes on within a browser, Simpon explains. “If a user is to bring<a href="https://www.itpro.com/security/the-new-byod-how-to-leaders-can-securely-evolve-policy"><u> your own device (BYOD)</u></a> with access to enterprise resources, you are very much on the back foot to prevent identity-based attacks.”</p><h2 id="managing-multi-channel-phishing">Managing multi-channel phishing </h2><p>The move to multiple channels is just one way phishing is changing. In tandem, AI is accelerating the quality and scale of attacks, while lowering the barrier to entry for new cybercriminals, according to Danny Jenkins, CEO of ThreatLocker.</p><p>“Attackers no longer need to spend hours researching targets or carefully crafting convincing messages,” he tells <em>ITPro</em>. </p><p>“AI can generate highly personalised, context-aware phishing content in seconds – whether that’s a Teams message, a fake document-sharing notification, or a voice <a href="https://www.itpro.com/security/deepfake-business-risks-are-growing-what-leaders-need-to-know"><u>deepfake</u></a> impersonating a colleague or executive.”</p><p>There is also a rise in adaptive social engineering, where AI-driven phishing attempts evolve in real time based on how a user responds, he warns. “Instead of relying on static messages, these interactions can mimic natural conversations, making them significantly more convincing,” explains Jenkins.</p><p>The threat from multi-channel phishing is certainly growing, but firms can help boost defenses by making several key changes. Some of these are cultural. </p><p>From a security perspective, organizations need to accept that they will not stop every phishing attempt across every channel, says Jenkins. </p><p>“Humans are imperfect, and mistakes will happen, and no amount of training can prevent every phishing attempt.” </p><p>Instead, the priority should be reducing the impact of an attack and tightly controlling access, rather than trying to eliminate exposure, he advises.</p><p><a href="https://www.itpro.com/security/password-manager-passkey-guidance-ncsc"><u>Passkey</u></a> use can help, says Simpson, pointing out that the <a href="https://www.ncsc.gov.uk/"><u>UK National Cyber Security Centre (NCSC)</u></a> has started to actively recommend the adoption of passkeys over passwords and MFA.</p><p>“Passkeys help address many of the shortfalls of traditional passwords and MFA. Notably, they’re resistant to phishing because they’re tied to the legitimate website only; they are fast and convenient, and cannot be stolen if a website is breached.”</p><p>As with traditional phishing, organizations should adopt a strategy of user awareness and technical controls to defend against multi-channel attacks, according to Simpson.</p><p>This means ensuring users are aware that a spectrum of social engineering attacks are possible, beyond solely email-based phishing. Users, especially those in high-risk roles, such as executives and finance teams, should be targeted with training to empower them to identify and report attacks, Simpson advises. </p><p>“This should be an ongoing message and constantly refreshed based on active attacks seen in the wild, rather than just an annual policy that’s read and signed off.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are posing as Interpol to target small businesses – here's what you need to know ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/hackers-are-posing-as-interpol-to-target-small-business-heres-what-you-need-to-know</link>
                                                                            <description>
                            <![CDATA[ Small businesses are warned to think twice before clicking on links ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dfEYQHdzwBELh5bxQfdbGS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 06 Jul 2026 10:58:23 +0000</pubDate>                                                                                                                                <updated>Mon, 06 Jul 2026 21:36:13 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:description>                                                            <media:text><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Criminals are posing as Interpol cyber crime investigators to target small businesses across Europe, Asia, the Middle East, and North America.</p><p>According to <a href="https://www.bitdefender.com/en-us/blog/hotforsecurity/fake-interpol-emails-serve-ransomware" target="_blank"><u>new research from Bitdefender</u></a>, the phishing messages claim to contain evidence that the recipients are carrying out suspicious activity, pressuring them into opening a password-protected archive.</p><p>"Based on information that has come to our attention, there may be activities involving accounts, systems or services associated with your organization that warrant further examination. We have obtained information and video material that may assist in your assessment of the matter," the emails read. </p><p>"We recommend conducting an internal review to determine whether any unauthorized, suspicious or potentially fraudulent activities have occurred. Prompt attention to such matters may help mitigate potential financial operational, reputational or regulatory risks."</p><p>Upon opening the link, recipients are directed to a <a href="https://www.itpro.com/security/proton-is-launching-its-own-private-alternative-to-google-workspace-and-microsoft-365">Proton </a>Drive-hosted file that delivers a ransomware payload hidden within multiple archive layers. Once executed, researchers said the <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>seeks to encrypt files across available drives and presents victims with a ransom message.</p><p>The campaign is targeting organizations across multiple industries, including food and agriculture, legal services, pharmaceuticals, media, technology, and finance.</p><p>The ransomware is relatively simple, according to Bitdefender researchers. The code contains hardcoded values, including the password used during encryption and decryption, and lacks many of the features typically associated with large <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>operations.</p><p>Interestingly, victims are instructed to contact the attackers through a Tox chat channel to negotiate a ransom, rather than through the more usual dedicated negotiation portal or victim site.</p><p>This, researchers noted, is another indication that this is likely a custom-built operation, perhaps assembled using publicly available code and tools rather than the work of an established ransomware group.</p><h2 id="what-small-businesses-need-to-know">What small businesses need to know</h2><p>Javvad Malik, Lead CISO advisor at <a href="https://www.itpro.com/security/cyber-firm-knowbe4-unknowingly-hired-a-north-korean-hacker-and-it-went-exactly-as-you-might-think">KnowBe4</a>, said that impersonating Interpol – or law enforcement in general – is specifically designed to trigger a “rapid emotional response” and dupe victims into ignoring red flags. </p><p>"What is interesting about this campaign is that it targets small business,” he said. “These are often understaffed and have no security or even IT expertise on hand, so it's not difficult to see why people would easily fall victim to these kinds of attacks."</p><p>Bitdefender has warned small businesses to be on the alert, urging them to verify all unsolicited correspondence by reaching out through official channels to confirm whether the communication is legitimate.</p><p>"One of the biggest red flags in this campaign is the delivery method itself," researchers said. "While the attackers impersonate Interpol, legitimate law enforcement agencies don't send unsolicited emails containing Proton Drive links to password-protected files and ask organizations to review alleged evidence of wrongdoing."</p><p>They should treat password-protected archives with caution, especially when the password is included in the email. Showing file extensions on Windows devices will make it easier to spot executables masquerading as videos or documents, and <a href="https://www.itpro.com/security/cyber-attacks/how-hackers-bypass-mfa-and-what-to-do-about-it">multi-factor authentication (MFA)</a> should be used wherever possible.</p><p>Elsewhere, the company urged small businesses to ensure staff are trained to help spot tell-tale signs that communications are fraudulent. </p><p>"Small businesses are often viewed as easier targets than large enterprises," the researchers warned.</p><p>"Many operate without dedicated IT teams or cybersecurity staff. Security responsibilities are often shared among employees who already wear multiple hats, and limited budgets can make it difficult to invest in advanced security measures or ongoing training."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Hacking groups have the transport network firmly in their sights’: Network Rail is battling a torrent of cyber threats ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/hacking-groups-have-the-transport-network-firmly-in-their-sights-network-rail-is-battling-a-torrent-of-cyber-threats</link>
                                                                            <description>
                            <![CDATA[ FoI requests have revealed that the rail operator is under increasing attack, as cyber criminals set their sights on the transport sector ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">RoW86jKhaGNwz8fh2EZQkX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rUvp25YMvPTLYowbCM5HSC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 29 Jun 2026 11:26:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rUvp25YMvPTLYowbCM5HSC-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Network Rail logo and branding pictured on a glass partition at a waiting room in London Euston railway station.]]></media:description>                                                            <media:text><![CDATA[Network Rail logo and branding pictured on a glass partition at a waiting room in London Euston railway station.]]></media:text>
                                <media:title type="plain"><![CDATA[Network Rail logo and branding pictured on a glass partition at a waiting room in London Euston railway station.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rUvp25YMvPTLYowbCM5HSC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Network Rail is fighting off millions of cyber attacks every month, according to new research, as experts warn of a rising tide of threats facing public services. </p><p>Freedom of information (FoI) requests show the organization blocked over 7.1 million malicious emails between December 2025 and March this year.  </p><p>Of the 7,129,314 email attacks blocked by Network Rail, 331,352 were phishing emails, 1,412 were <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>-laden emails, 2,066,392 were spam emails, and 4,730,158 were edge blocked emails. </p><p>This all adds up to an average of more than 800,000 attacks per day, including around 37,000 <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>attempts.</p><p>“With so many people in the UK depending on public transport for their daily lives, a successful cyber attack could cause significant disruption, such as potentially stopping people from getting to work," warned Simon Edwards, CEO of SE Labs. </p><p>"Therefore, it’s vital that our public sector organizations have a dedicated cyber strategy put in place and ensure rigorous testing to identify any security holes and keep hackers at bay.”</p><p>Just last week, two members of the hacking group known as Scattered Spider pleaded guilty over their <a href="https://www.itpro.com/security/cyber-attacks/duo-accused-of-role-in-tfl-cyber-attack-plead-guilty-after-lengthy-highly-complex-and-painstaking-investigation">involvement in an attack on Transport for London (TfL) systems</a>. </p><p>The attack forced all 28,000 employees to attend a TfL office for a password reset and led to a reported £29 million in losses and recovery costs.</p><p>"As we've seen from the recent Scattered Spider convictions, hacking groups have the transport network firmly in their sights. A single successful cyber attack on the rail network could drive Britain to a halt, operationally and economically," said Graeme Stewart, head of public sector at Check Point. </p><p>"The transport network is also a treasure trove of personal and financial data, something unscrupulous criminals are eager to get their hands on. That’s why it's vital that our roads, rail and aviation systems are fully protected with the latest cyber defenses to keep hackers locked out."</p><h2 id="what-happened-with-the-network-rail-cyber-attack">What happened with the Network Rail cyber attack?</h2><p>In 2024, Network Rail suffered a <a href="https://www.itpro.com/security/network-rail-confirms-cyber-attack-on-wi-fi-systems-at-uk-train-stations"><u>cyber attack</u></a> on its WiFi systems that saw commuters who logged in at affected stations receive information pertaining to terrorist attacks in Europe, as well as a message stating “we love you Europe”. </p><p>The attack is believed to have taken place through a third-party service provider, Telent, which managed Network Rail's WiFi services.</p><p>More recently, train operator LNER said a <a href="https://www.itpro.com/security/cyber-attacks/lner-warns-customers-to-remain-vigilant-after-personal-data-exposed-in-cyber-attack"><u>cyber attack</u></a> had led to unauthorized access to files managed by an unnamed third-party supplier.</p><p>Travel networks, particularly rail services, are among the top targets for cyber criminals and state-sponsored groups due to the critical role they play in the British economy, according to research conducted last year. </p><p>The UK's Department for Science, Innovation and Technology (DSIT) released a <a href="https://assets.publishing.service.gov.uk/media/69144f259d50fc2fe816163a/Economic_impact_of_a_systemic_cyber_incident_rail_sector_scenario.pdf" target="_blank"><u>report</u></a> from KPMG that concluded a major attack on the rail network could cost £1.8 billion for a one-week period of disruption.</p><p>The direct financial cost to Network Rail would, it concluded, cost around £123 million, with the cost to passengers due to delays adding up to about £281.3 million. </p><p>Notably, the impact on Gross Value Added (GVA) could be as much as £1.397 billion, representing approximately 2.8% of the UK’s weekly GDP and 0.05% of annual GDP.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘They risk damaging confidence’: A Canadian health board outraged staff with phishing tests offering paid leave – experts say it shows why you need to be careful with cyber awareness campaigns ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/they-risk-damaging-confidence-a-canadian-health-board-outraged-staff-with-phishing-tests-offering-paid-leave-experts-say-shows-why-you-need-to-be-careful-with-cyber-awareness-campaigns</link>
                                                                            <description>
                            <![CDATA[ Phishing tests require a delicate touch, emulating realism while not “exploiting goodwill” ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LfUaaa5ELrjpAENwf6HrXn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iDKidsDKjf2VvPGKQeUDaC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Jun 2026 15:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iDKidsDKjf2VvPGKQeUDaC-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing concept image showing a red-colored email symbol with a hook placed through it dangling over a laptop computer.]]></media:description>                                                            <media:text><![CDATA[Phishing concept image showing a red-colored email symbol with a hook placed through it dangling over a laptop computer.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing concept image showing a red-colored email symbol with a hook placed through it dangling over a laptop computer.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iDKidsDKjf2VvPGKQeUDaC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security experts have urged organizations to take a more considerate approach to cyber awareness training after a Canadian health board sent emails to staff offering paid leave as part of a phishing test. </p><p>Ron Johnson, interim chief executive at Newfoundland and Labrador Health Services, apologized for the phishing test last week, admitting the emails were sent in poor taste. </p><p>“We acknowledge the approach taken in this particular exercise was not appropriate, and we sincerely apologize to employees, physicians, and union representatives,” he <a href="https://nlhealthservices.ca/news/nl-health-services-apologizes-for-the-recent-cybersecurity-awareness-exercise/" target="_blank"><u>wrote</u></a>. </p><p>The <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>simulation prompted backlash after being circulated to hundreds of employees, and has since prompted a review of future activities, Johnson added. </p><p>“We value the feedback and are reviewing how future awareness exercises are developed and communication,” he said. </p><p>“It is important they reflect employee and physician perspectives, as well as our organizational values to foster a respectful and supportive workplace culture.”</p><p>This isn’t the first time an organization has been forced into a U-turn after a controversial phishing test campaign. </p><p>As <em>ITPro </em>reported in late 2024, the University of California Santa Cruz (UCSC) was heavily criticized for a “tone deaf” campaign <a href="https://www.itpro.com/security/how-not-to-conduct-cyber-awareness-training-ucsc-slammed-for-tone-deaf-ebola-phishing-tests"><u>which used a fake Ebola virus track and trace alert</u></a>. </p><p>The campaign caused a panic on campus and was highly convincing, even employing links to a fake webpage set up to support those affected by the “outbreak”. </p><h2 id="phishing-tests-are-a-vital-part-of-cyber-hygiene">Phishing tests are a vital part of cyber hygiene</h2><p>While this particular incident sparked ire among employees, phishing tests are a common practice by cybersecurity professionals to ensure staff remain vigilant to potential security threats. </p><p>Phishing attacks, in particular, are a leading cause of breaches at organizations across a range of industries – and the healthcare sector specifically is a prime target for cyber criminals. </p><p><a href="https://www.itpro.com/security/phishing/ai-generated-phishing-became-the-baseline-for-hackers-last-year-kaseya-warns-its-going-to-get-worse-in-202">Add AI into the equation</a>, and the threat landscape faced by enterprises today is becoming increasingly perilous, with threat actors using the technology to refine techniques and curate highly convincing emails. </p><p>Rob Anderson, head of reactive consulting services at Reliance Cyber, told <em>ITPro </em>that the “best phishing exercises are realistic” – after all, they are intended to emulate the tactics used by cyber criminals. </p><p>"They should use the same sneaky tactics that threat actors may use, hopefully triggering the trained, instinctive suspicion we want staff to develop when handling unexpected emails,” he said. </p><p>“However, there is a fine line. Nobody likes to be made a fool of, especially at sensitive times.”</p><p>Anderson pointed to a phishing exercise by one UK police force’s Information Protection Unit, which circulated emails targeting staff in a typical fashion. Those who fell foul were met with a message stating: “whoops, you’ve failed this training”. </p><p>In this instance, Anderson said the Information Protection Unit had “failed to read the room”. </p><p>“A week earlier, the force had announced a restructure, with likely compulsory redundancies and transfers,” he said. “Police officers can be a vocal and cynical bunch, and they made their feelings known.”</p><h2 id="a-delicate-balancing-act">A delicate balancing act</h2><p>It’s here that phishing tests often become a delicate balancing act, according to Simon McNalley, identity and access management (IAM) technical director at Thales. </p><p>Ultimately, <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>professionals need to ensure that simulations are “realistic enough to reflect the tactics attackers use” without “exploiting goodwill”. </p><p>“Scenarios involving pay, bonuses, annual leave, personal hardship, or other highly sensitive employment matters should be approached with caution, as they risk damaging confidence in legitimate internal communications,” he told <em>ITPro</em>. </p><p>Anderson echoed McNally’s comments, adding that human resources (HR), communications, and senior leadership should be consulted before campaigns go live.</p><p>Ultimately, McNally said the NL Health Services incident should serve as an example to other organizations hoping to keep staff on their guard in light of rising threats. </p><p>“There is a place for phishing simulations as part of building cyber awareness, especially as attackers routinely use such techniques. However, it’s vital that these exercises do not come at the expense of trust between employer and employee. Trust is a critical component of security culture,” he said. </p><p>“If awareness programs leave employees feeling misled, embarrassed or manipulated, organizations risk undermining the very behaviors they are trying to encourage.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are capitalizing on AI hype to ramp up social engineering attacks – and they're using big brands like Anthropic, OpenAI, and DeepSeek as ‘bait’ to lure victims ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/hackers-are-capitalizing-on-ai-hype-to-ramp-up-social-engineering-attacks-and-theyre-using-big-brands-like-anthropic-openai-and-deepseek-as-bait-to-lure-victims</link>
                                                                            <description>
                            <![CDATA[ Microsoft says cyber criminals are impersonating popular AI platforms to deliver malware ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Bt3jnSdxJvJ3eU7nUZAaq5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 11 Jun 2026 11:11:12 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:description>                                                            <media:text><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber criminals are exploiting <a href="https://www.itpro.com/technology/artificial-intelligence/businesses-finding-it-hard-to-distinguish-real-ai-from-the-hype-report-suggests">AI hype</a> to impersonate the branding of AI platforms such as ChatGPT, Microsoft Copilot, DeepSeek, and Anthropic’s Claude, according to new research. </p><p>Microsoft Threat Intelligence said it's observed an uptick in <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a>, malvertising, and search engine optimization (SEO)-driven attacks that ultimately lead to credential theft, financial fraud, or malware infection.</p><p>Campaigns focus on highly anticipated launches or emerging trends, using tried-and-tested tactics such as urgency-driven messaging, abuse of trusted services, and multi-stage redirection chains that require user interaction to evade detection.</p><p>"While traditional lures like invoices, payment notifications, or delivery alerts remain effective and continue to be widely used, AI-themed lures reflect a shift in <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> that is likely to persist as a long-term tactic used by threat actors, from cyber criminal groups to nation states," the company warned. </p><h2 id="chatgpt-users-in-the-crosshairs">ChatGPT users in the crosshairs</h2><p>In one example, Microsoft said it had observed a ChatGPT-themed phishing attack delivering malicious URLs which led to phishing pages that collected credit card and personal information such as names and addresses. </p><p>The emails used the sender display name ChatGPT and the subject line: “To ensure your ChatGPT Plus continues to work – please update your payment method”. </p><p>This phishing activity, which consisted of 4,500 emails sent to targets in South Africa, was part of a broader campaign using similar themes and infrastructure that delivered as many as 100,000 emails on a single day to targets in Switzerland, Austria, and South Africa. </p><p>Microsoft noted the campaign affected a broad range of industries, including higher education and professional services.</p><h2 id="thousands-targeted-in-a-claude-themed-phishing-attack">Thousands targeted in a Claude-themed phishing attack</h2><p>In another example, security experts spotted a phishing campaign impersonating Anthropic-branded services to target users with account-related lures tied to the Claude AI platform. </p><p>The campaign sent phishing emails to targets across more than 2,000 organizations, mainly in the US, UK, and India.</p><p>"The campaign used enforcement-themed messaging claiming that the recipient’s account was in violation of acceptable use policies and required immediate action," the company noted. </p><p>"The emails impersonated Anthropic’s popular AI service Claude using the display names Anthropic Teams and Anthropic PBC, masquerading as legitimate account-related communications. Subject lines followed a consistent structure of 'Claude Appeal Request' combined with date elements."</p><h2 id="deepseek-malvertising-is-a-growing-threat">DeepSeek malvertising is a growing threat</h2><p>Other examples included malvertising campaigns that use AI-themed terms such as 'Awesome AI Windows Plugin' and 'Flux Pro AI' in social engineering lures, and fake DeepSeek V4 installers on GitHub that delivered Vidar Stealer.</p><p>"Within hours of <a href="https://www.itpro.com/security/using-deepseek-at-work-security-risks">DeepSeek </a>previewing their latest version, V4, attackers created a fake GitHub organization and repository.  They copied real branding and benchmark data, added AI and SEO-search-friendly content, and pushed malicious archives that looked like installers," explained John Bruggeman, vCISO at CBTS. </p><p>"What the attacker did was not particularly exotic, but it was well timed and convincingly packaged. A user searching for the newest model could very easily end up in the wrong place, especially because the malicious repository showed up in GitHub, Google, Bing, or AI-assisted search results. The search results added legitimacy to the <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>."</p><h2 id="remain-vigilant">Remain vigilant</h2><p>To counter these rising threats, Microsoft advised customers to configure automatic attack disruption in Microsoft Defender XDR, enforce <a href="https://www.itpro.com/security/how-resellers-can-win-with-smarter-multi-factor-authentication-mfa">multi-factor authentication (MFA)</a> on all accounts, use the Microsoft Authenticator app for passkeys and MFA, and scope conditional access policies to strengthen privileged accounts with <a href="https://www.itpro.com/security/cyber-attacks/how-hackers-bypass-mfa-and-what-to-do-about-it">phishing-resistant MFA</a>.  </p><p>Other tips included:</p><ul><li>Enabling Zero-hour auto purge (ZAP) in Office 365</li><li>Configuring Microsoft Defender for Office 365 Safe Links</li><li>Invest in ‘advanced’ anti-phishing solutions</li></ul><p>"The companies that have a handle on AI governance (policies and procedures) well will be the ones that make safe AI use easy, risky AI use visible, and malicious activity hard to ignore. That means publishing a clear list of approved tools, blocking obvious lookalike domains and very recently registered domains can help stop this kind of threat," said Bruggeman. </p><p>"Monitoring suspicious downloads and sign-ins, and training employees on the AI-themed lures should also be done right now - don't think that generic phishing examples from five years ago are going to cut it today."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Beware of emails threatening a code of conduct review ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/beware-of-emails-threatening-a-code-of-conduct-review</link>
                                                                            <description>
                            <![CDATA[ A widespread phishing campaign has targeted tens of thousands of employees ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">77y4eje5T825eD49NpbPGa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 06 May 2026 09:34:02 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:description>                                                            <media:text><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has <a href="https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/" target="_blank">issued an alert</a> over a large-scale credential theft campaign that uses lures centered around corporate codes of conduct.</p><p>The emails were related to internal compliance or regulatory issues, with display names such as 'Internal Regulatory COC', 'Workforce Communications', and 'Team Conduct Report'.</p><p>Subject lines included 'Internal case log issued under conduct policy' and 'Reminder: employer opened a non-compliance case log'.</p><p>The emails were sent using a legitimate email delivery service, likely originating from a cloud-hosted <a href="https://www.itpro.com/security/ransomware/ransomware-gangs-are-sharing-virtual-machines-to-wage-cyber-attacks-on-the-cheap-but-it-could-be-their-undoing">Windows virtual machine (VM)</a>. </p><p>The accusations and repeated time-bound action prompts created a sense of urgency, Microsoft researchers said. Similarly, the emails were based on polished, enterprise-style HTML templates with structured layouts and authenticity statements, making them appear more credible than most phishing emails.</p><p>The bodies of the messages claimed that a code of conduct review had been initiated, referenced organization-specific names embedded within the text, and instructed recipients to open a PDF attachment to see the materials of the case. </p><p>When clicked, users were first directed to one of two attacker-controlled domains - acceptable-use-policy-calendly[.]de or compliance-protectionoutlook[.]de. </p><p>The landing pages displayed a <a href="https://www.itpro.com/security/cyber-crime/fake-captcha-attacks-surged-in-late-2024-heres-what-to-look-out-for">Cloudflare CAPTCHA</a>, presented as checking that the user was coming 'from a valid session', and that likely served as a gating mechanism to impede automated analysis and sandbox detonation. </p><p>According to Microsoft, the attack chain ultimately led to a legitimate sign-in experience that formed part of an <a href="https://www.itpro.com/security/cyber-crime/adversary-in-the-middle-attacks-are-becoming-hackers-go-to-method-to-bypass-mfa">adversary in the middle (AiTM)</a> phishing flow. </p><p>Unlike traditional credential harvesting, AiTM attacks intercept authentication traffic in real time, <a href="https://www.itpro.com/security/cyber-attacks/how-hackers-bypass-mfa-and-what-to-do-about-it">bypassing multifactor authentication (MFA)</a>. </p><p>As a result, the attackers were able to proxy the authentication session and capture authentication tokens that could provide immediate account access. </p><p>"<a href="https://www.itpro.com/security/29093/what-is-phishing">Phishing </a>campaigns continue to improve sophistication and refinement in blending social engineering, delivery and hosting infrastructure, and authentication abuse to remain effective against evolving security controls," the researchers warned. </p><h2 id="what-industries-are-affected">What industries are affected?</h2><p>Between 14 and 16 April this year, the Microsoft Defender Research team said it spotted a series of campaigns targeting more than 35,000 users across over 13,000 organizations in 26 countries. Most targets - 92% - were located in the US. </p><p>The campaign didn't focus on a single vertical but instead impacted a broad range of industries, most notably healthcare and life sciences (19%), financial services (18%), professional services (11%), and technology and software (11%).</p><p>Microsoft said organizations should review the recommended settings for Exchange Online Protection and Microsoft Defender for Office 365 to check for essential defenses and the ability to monitor and respond to threat activity. They should also invest in user awareness training and phishing simulations. </p><p>Enabling Zero-hour auto purge (ZAP) in Defender for Office 365 is advised to quarantine sent mail in response to newly acquired threat intelligence. Users are also urged to retroactively neutralize malicious phishing, spam, or <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>messages that have already been delivered to mailboxes.</p><p>It's also worth manually checking for, and purging, unwanted emails containing URLs and/or Subject fields that are similar, but not identical, to those of known bad messages.</p><p>Organizations should enable password-less authentication methods or use authenticator apps, researchers said, and strengthen privileged accounts with phishing resistant MFA.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘The inbox is no longer the only frontline’: Phishing attacks are evolving as cyber criminals ramp up ‘multi-channel’ campaigns over email and Microsoft Teams ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/the-inbox-is-no-longer-the-only-frontline-phishing-attacks-are-evolving-as-cyber-criminals-ramp-up-multi-channel-campaigns-over-email-and-microsoft-teams</link>
                                                                            <description>
                            <![CDATA[ New research shows threat actors are ramping up “multi-channel” phishing attacks by combining lures via email and Microsoft Teams ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KeqM2mhYx8M92mZgtJqven</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 04 May 2026 05:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:description>                                                            <media:text><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security researchers have issued a warning over a “seismic shift” in how threat actors are conducting phishing campaigns, with traditional email-based attacks no longer the primary vector. </p><p>KnowBe4’s <a href="https://www.knowbe4.com/hubfs/Phishing_Threat_Trends_Report_Vol7_en-US.pdf" target="_blank"><u><em>Phishing Threat Trends Report</em></u></a> found hackers are leveraging new “touchpoints” when targeting victims, with calendar invites and messaging tools now frequently used. </p><p>Indeed, across the last year, the company recorded a 49% increase in calendar invite-based phishing attacks, while </p><p>Jack Chapman, SVP of Threat Intelligence at KnowBe4, said the report shows “the inbox is no longer the only frontline for coordinated social engineering attacks”. </p><p>“Cyber criminals are actively broadening the email threat landscape,” he said. </p><p>“As businesses rely on tools for real-time collaboration, cyber criminals have added this to their attacks, along with targeting people’s calendars. This attack method targets people and technology together. This escalation in scale of threat brings a whole new issue to the forefront.”</p><h2 id="microsoft-teams-attacks-are-surging">Microsoft Teams attacks are surging</h2><p>KnowBe4 warned that threat actors are increasingly leveraging impersonation tactics when conducting phishing campaigns, with legitimate platform and brand names often used to dupe users.</p><p>The company recorded a 41% increase in Microsoft Teams-based attacks between October 2025 and March 2026, for example. </p><p>These attacks prey on the fact that Teams is “built for speed and informality”, researchers noted, with victims often forgoing security considerations when responding to communications. </p><p>“Attackers are banking on this perceived safety, turning our primary collaboration tool into their path of least resistance,” the report states. </p><p>Notably, the report warned Teams now forms a core component of “multi-channel” attacks. Nearly one-in-five (17.38%) of all Teams-based attacks are now multi-channel, the study found. </p><p>Email still remains the primary attack vector, yet the workplace collaboration platform allows threat actors to “extend the kill chain and create more avenues for success”. </p><p>In these cases, threat actors have been observed initiating contact with a victim via email communications, then following up with a message via Microsoft Teams. </p><p>This, the report noted, allows them to essentially validate their identity across different environments. </p><p>“These threats are particularly dangerous as Teams allows an attacker to communicate consistently with a victim over multiple messages,” the report explains. </p><p>“This enables them to build a rapport and a sense of legitimacy that is much harder to achieve through traditional channels.”</p><p>KnowBe4 attributed the surge in Teams-based attacks with the launch of the “Chat with Anyone” feature, which allows users to initiate chats using an email address. </p><p>Teams is also a go-to platform for threat actors impersonating company personnel, the report found, with a host of roles and professions often impersonated. These include:</p><ul><li>IT professionals</li><li>Human resources professionals (and platforms such as Workday)</li><li>CEOs and company executives</li><li>Finance personnel</li></ul><p>“Social engineering is becoming more targeted, making it more difficult to discern what is legitimate versus what is malicious,” said Chapman.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Tycoon 2FA is down, but not out – researchers warn the phishing as a service operation is still a huge threat to businesses ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/tycoon-2fa-phishing-risk-takedown-barracuda</link>
                                                                            <description>
                            <![CDATA[ Millions of Tycoon 2FA attacks are still hitting businesses, according to research from Barracuda ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vXDsxDKKWbMUkuvkVXXwHC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Apr 2026 11:05:53 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                        <dc:contributor><![CDATA[ Ross Kelly ]]></dc:contributor>
                                                                    <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:description>                                                            <media:text><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security experts have issued a warning about the continued risk of Tycoon 2FA attacks, even after a law enforcement operation took down the <a href="https://www.itpro.com/security/cyber-security/368284/what-is-phishing-as-a-service-phaas">phishing as a service (PhaaS)</a> platform last month. </p><p>According to Barracuda, while attacks have since dropped by 77%, they still persist, with more than two million taking place each month. </p><p>Before the takedown, Tycoon 2FA was behind tens of millions of phishing messages, reaching over 500,000 organizations each month worldwide.</p><p>First spotted in August 2023, it used adversary in the middle (AitM) proxying to <a href="https://www.itpro.com/security/cyber-attacks/how-hackers-bypass-mfa-and-what-to-do-about-it">bypass traditional multi-factor authentication (MFA)</a> and capture session cookies in real time, leading to large-scale account compromise.</p><p>It was linked to more than 96,000 distinct phishing victims globally, including more than 55,000 Microsoft customers and around 5,350 in the UK, hitting sectors including education, healthcare, finance, and the public sector. </p><p>The takedown last month saw <a href="https://www.itpro.com/security/law-enforcement-and-security-firms-take-down-huge-phaas-platform"><u>Microsoft seize 330 domains forming the core infrastructure of the criminal service</u></a>, including phishing pages and control panels.</p><p>Yet Barracuda said its analysis shows the impact of the takedown has been largely restricted to Tycoon’s own brand name and visibility, along with a drop in the use of Tycoon-linked hosting and domain patterns.</p><p>"The ‘body’ of Tycoon: its tools and techniques, live on. They have migrated, been redistributed and diversified across competing platforms, or simply left where they are,” the company said in a <a href="https://blog.barracuda.com/2026/04/16/threat-spotlight-tycoon-2fa-scattered-everywhere" target="_blank">blog post</a>. </p><h2 id="pouncing-on-the-tycoon-2fa-takedown">Pouncing on the Tycoon 2FA takedown</h2><p>Notably, Barracuda found that other phishing kits have moved quickly to take Tycoon 2FA's place, with increased campaign activity involving the established platforms of Mamba 2FA and EvilProxy, as well as aggressive newcomers such as Sneaky 2FA and Whisper 2FA. </p><p>These kits have boosted their feature sets and infrastructure maturity, according to Barracuda, often leveraging tools formerly used by Tycoon 2FA.</p><p>"Tycoon 2FA was widely used by independent affiliates. This means that variants of Tycoon 2FA’s attack code that have been cloned or modified by individual adversaries continue circulating. It also means that independently hosted deployments remain active and that fragmented, low-volume campaigns persist," the firm said.</p><p>"For example, Barracuda recently detected a ‘device code’ phishing campaign that leveraged Tycoon’s stand-out features. Code similarities included Tycoon’s signature ‘noise’ of motivational style comments. In this incident, the comments all begin with the word ‘success’."</p><p>This campaign also featured Tycoon 2FA’s unique anti-analysis, anti-debugging and redirection capabilities. </p><h2 id="tycoon-2fa-is-still-alive-and-kicking">Tycoon 2FA is still alive and kicking</h2><p>Barracuda said the reasons for Tycoon 2FA’s persistence include the fact that attackers have reused and repurposed phishing code. </p><p>Meanwhile, attack domains remain active until expiry, backup hosting often evades immediate seizure, and some low-visibility phishing campaigns fall beneath alert thresholds.</p><p><a href="https://www.itpro.com/security/29093/what-is-phishing">Phishing</a> frameworks have built-in redundancy, researchers noted, while the disruption of infrastructure doesn't necessarily revoke victim access. </p><p>Stolen session cookies may remain valid, OAuth abuse can enable extended cloud access, and organizations may remain compromised after the end of the phishing campaign.</p><p>"This does not mean the takedown operation failed. Rather, it shows what happens when disruption hits a maturing underground economy, and why security defenses need to look more broadly than individual players," said Barracuda.</p><p>"The Tycoon 2FA takedown accelerated ecosystem diversification. Defensive strategies therefore need to focus on models for identity-based attacks, session abuse and adversary economics. Tycoon 2FA as a branded service has declined, but the techniques it popularized are now more widely distributed than before."</p><h2 id="cyber-crime-whack-a-mole">Cyber crime whack-a-mole</h2><p>Barracuda’s findings highlight a painful recurring theme for law enforcement agencies tackling cyber crime – these operations are very hard to kill outright. </p><p>While takedowns cripple infrastructure and hamper operations for a time, many groups simply dust themselves off and get back to it, and often in a far more aggressive way. </p><p>There have been repeated instances of cyber crime operations coming back from the dead in recent years despite hard crackdowns by industry stakeholders and law enforcement agencies. </p><p><a href="https://www.itpro.com/security/hacking/361340/what-is-emotet">Emotet</a> ranks among the best examples of this. The botnet was used to facilitate an eye-watering volume of attacks over its lifespan before being taken down by a Europol-led operation in January 2021. </p><p>Less than a year later, however, the botnet was back up and running, with <a href="https://www.itpro.com/security/cyber-attacks/369526/hundreds-of-thousands-of-emotet-attacks-spotted-daily-after-hiatus"><u>Analysis from November 2022</u></a> showing the cyber criminals behind the operation ramped up attacks to record levels. </p><p>Of course, that’s not to say law enforcement should just down tools and stop trying. The impact of these takedowns may have a limited shelf life, but they do provide a temporary reprieve for victims and deliver long-term benefits. </p><p>As <em>ITPro </em>reported in the wake of the <a href="https://www.itpro.com/security/cyber-crime/the-fbi-has-seized-the-ramp-hacking-forum-but-will-the-takedown-stick-history-tells-us-otherwise"><u>RAMP hacking forum takedown</u></a> last year, they enable law enforcement to gain vital intelligence on how these groups work and support other operations further down the line. </p><p>This cat and mouse game between hackers and law enforcement is as old as cyber crime itself, and shows no signs of slowing down. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Zephyr Energy hackers swiped £700,000 after redirecting a contractor payment ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/zephyr-energy-hackers-swiped-gbp700-000-after-redirecting-a-contractor-payment</link>
                                                                            <description>
                            <![CDATA[ Payment to a Zephyr Energy contractor was siphoned off, but the incident has been contained and new security measures implemented ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m6aEtDpzcUUX6suSr8UbWg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MY2WgJEVTBewbYoYNy8qFJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Apr 2026 10:17:04 +0000</pubDate>                                                                                                                                <updated>Fri, 10 Apr 2026 10:45:34 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MY2WgJEVTBewbYoYNy8qFJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Email security attack concept image showing mail symbol with a red warning symbol imposed over a digital interface.]]></media:description>                                                            <media:text><![CDATA[Email security attack concept image showing mail symbol with a red warning symbol imposed over a digital interface.]]></media:text>
                                <media:title type="plain"><![CDATA[Email security attack concept image showing mail symbol with a red warning symbol imposed over a digital interface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MY2WgJEVTBewbYoYNy8qFJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Oil and gas firm Zephyr Energy has reported that one of its US subsidiaries has suffered a cyber intrusion that allowed the attackers to siphon off hundreds of thousands of pounds.</p><p>The London-headquartered company said the incident saw a contractor payment diverted to an account controlled by threat actors. The company confirmed around £700,000 was lost in the incident. </p><p>"Upon discovery of the incident, the company immediately notified the relevant law enforcement authorities and is working with the corresponding banks and consultants to attempt to recover the diverted funds," the company said in a <a href="https://polaris.brighterir.com/public/zephyr_energy/news/rns_widget/story/xo91ymx" target="_blank"><u>regulatory filing</u></a> with the London Stock Exchange.</p><p>Zephyr noted that the incident has been contained and IT systems have been thoroughly assessed by a leading cybersecurity consultancy. </p><p>Operations and corporate activities are continuing as normal, but its own internal IT teams are keeping a close eye on company systems. </p><p>"While Zephyr uses industry standard practices in relation to its technology and payment systems, additional layers of security have been implemented as a result of this attack," it added.</p><p>"The company's board of directors can confirm that the company has more than sufficient working capital to ensure that this isolated matter will not impact the company's ability to perform its ongoing operations."</p><h2 id="zephyr-energy-attack-what-happened">Zephyr Energy attack: What happened?</h2><p>There's no information on how the attack actually took place, but it has all the hallmarks of a <a href="https://www.itpro.com/security/cyber-attacks/what-is-business-email-compromise-bec">business email compromise (BEC)</a> incident. </p><p>Via <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaigns, hackers typically gain access to email inboxes or accounting systems that enables them to change bank details during payment or invoice processing, in what's known as an <a href="https://www.itpro.com/security/cyber-crime/adversary-in-the-middle-attacks-are-becoming-hackers-go-to-method-to-bypass-mfa">adversary in the middle (AiTM)</a> attack.</p><p>Earlier this year, Microsoft <a href="https://www.itpro.com/security/cyber-attacks/microsoft-warns-of-rising-aitm-phishing-attacks-on-energy-sector" target="_blank"><u>warned</u></a> that AiTM campaigns targeting cloud collaboration platforms such as Microsoft SharePoint and OneDrive were on the rise. </p><p>The tech giant specifically highlighted energy companies among those at highest risk of targeting. </p><p>At the time, Microsoft’s Defender Research Team said attackers were abusing SharePoint file sharing services to deliver phishing payloads, and had succeeded in compromising a number of accounts. </p><p>In terms of mitigation, because the sign-in session is compromised, simply resetting passwords doesn't work. The company outlined a series of steps that organizations should take to mitigate risks, including:</p><ul><li>Using conditional access policies, especially risk-based access policies</li><li>Implementing continuous access evaluation</li><li>Investing in advanced anti-phishing solutions</li><li>Continuous monitoring for suspicious or anomalous activities</li></ul><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'AI-generated phishing became the baseline' for hackers last year – Kaseya warns it's going to get worse in 2026 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/ai-generated-phishing-became-the-baseline-for-hackers-last-year-kaseya-warns-its-going-to-get-worse-in-2026</link>
                                                                            <description>
                            <![CDATA[ Forget looking for typos and bad grammar, phishing campaigns are using AI to boost their attack success ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bMNzEiSHCoLywhdK6jLQfa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iLr5eH4Tgk7GAiwMDELMzG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 19 Mar 2026 11:36:23 +0000</pubDate>                                                                                                                                <updated>Thu, 19 Mar 2026 11:55:32 +0000</updated>
                                                                                                                                            <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iLr5eH4Tgk7GAiwMDELMzG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing email attack concept image showing email with warning symbol on a laptop screen with a fishing hook attached.]]></media:description>                                                            <media:text><![CDATA[Phishing email attack concept image showing email with warning symbol on a laptop screen with a fishing hook attached.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing email attack concept image showing email with warning symbol on a laptop screen with a fishing hook attached.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iLr5eH4Tgk7GAiwMDELMzG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>AI-generated phishing “became the baseline” for cyber crime operations last year, according to new research from Kaseya. </p><p>Findings from the company’s annual report on email security highlight how quickly hackers have managed to take advantage of generative AI models across operations. </p><p>The study showed 2025 was an "inflection point" for phishing and AI, with malicious emails now generated by AI by default. That fits with a previous report from <a href="https://www.itpro.com/technology/artificial-intelligence/google-says-hacker-groups-are-using-gemini-to-augment-attacks-and-companies-are-even-stealing-its-models"><u>Google that hackers</u></a> are trying to use its Gemini model to augment their attacks. </p><p>Kaseya pointed to industry research that showed 83% of phishing emails use AI content in some way, with 40% of business email compromise (BEC) attacks using <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai">generative AI</a> in some capacity. </p><p>The results aren’t surprising, according to Kaseya, especially given AI-generated phishing emails have a 54% click rate, versus 12% for standard malicious messages. </p><p>That's in part down to attacks that react to current events, better formatting and grammar, and personalized messaging, the report noted. </p><p>“In the past year, AI-generated phishing became the baseline,” said Dave Baggett, SVP of Security Suite at Kaseya. “Attackers can now produce highly convincing messages at scale, which means the traditional signals security tools relied on for years — bad grammar, suspicious domains, obvious links — are disappearing."</p><h2 id="harder-to-defend">Harder to defend</h2><p>Baggett warned that AI-generated phishing campaigns are presenting security practitioners with new challenges, particularly with regard to detection. </p><p>“Defenders now have to evaluate intent and context, not just indicators,” he said. </p><p>Indeed, the report notes that AI tools mean attackers can ditch templates that lead to detectable repetition, meaning spam-spotting systems have to work harder to filter out phishing messages. </p><p>The plus side for enterprises is that AI-powered tools are helping take the fight to cyber criminals. New detection models, contextual understanding, and other AI-powered techniques are helping security teams respond rapidly.</p><p>"The next phase of <a href="https://www.itpro.com/security/phishing/359702/what-is-dmarc-and-how-can-it-improve-your-email-security">email security</a> will not be defined by filtering alone, but by AI systems capable of analyzing messages holistically and adapting continuously as tactics evolve," the report predicted. </p><p>Staying ahead of the curve remains a challenge, however. <a href="https://www.itpro.com/security/data-breaches/ai-breaches-arent-just-a-scare-story-any-more-theyre-happening-in-real-life"><u>IBM warned</u></a> last year that AI adoption is outpacing AI security, and <a href="https://www.itpro.com/security/hackers-are-using-ai-to-dissect-threat-intelligence-reports-and-vibe-code-malware"><u>TrendMicro spotted that hackers</u></a> were using AI to read through intelligence reports to help better target their attacks. </p><h2 id="phishing-losses-are-skyrocketing">Phishing losses are skyrocketing</h2><p>The report noted that 26% of cyber crime complaints filed to the FBI were down to phishing, adding that while losses from <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> had fallen 79%, the costs from phishing climbed by 275% from $18.7 billion to $70 billion annually. </p><p>Kaseya said this wasn't because ransomware was disappearing, but because companies were getting better at responding and had improved their backup strategies. </p><p>"Instead, it reflects a strategic shift: attackers are increasingly applying phishing and <a href="https://www.itpro.com/security/cyber-attacks/what-is-business-email-compromise-bec">business email compromise (BEC)</a> schemes as lower-risk, high-return alternatives to disruptive encryption-based attacks," the report said. </p><p>Eight-in-ten of these attacks target small and medium-sized businesses (SMBs) rather than larger counterparts, the company noted, with an average loss per incident of $50,000 for SMBs. </p><h2 id="brand-impersonate-is-still-a-go-to-for-hackers">Brand impersonate is still a go-to for hackers</h2><p>Attackers continue to use brand impersonation to fool victims – styling their malicious emails to look like they came from major companies or the government, for example. INKY detected 6.7 billion brand impersonation emails in the second half of 2025, with the vast majority – more than 5.3bn – from just 25 well-known brands. </p><p>Kaseya found that no-payload phishing was increasingly common, with these brand impersonation emails no longer including dodgy links or malicious attachments. In their place, they offer phone numbers, try to trick victims into hitting reply, or use QR codes. </p><p>"These techniques reduce detectable indicators while increasing reliance on user decision-making," the report noted. </p><p>While phishing dominates the fraud universe, Kaseya also pointed to the rise of new techniques including call centers and emergency scams. </p><p>"These figures reflect a broader shift toward social engineering-driven fraud – scams that exploit urgency, fear and trust rather than technical vulnerabilities," the report notes. </p><p>"Many of these schemes begin or are supported by phishing-based email campaigns."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Interpol teams up with tech firms to seize 45,000 malicious IPs, servers in global cyber crime crackdown ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/interpol-teams-up-with-tech-firms-to-seize-45-000-malicious-ips-servers-in-global-cyber-crime-crackdown</link>
                                                                            <description>
                            <![CDATA[ Operation Synergia III saw 94 arrests - and counting - with malicious IP addresses used in phishing and fraud schemes seized ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XFNDAXHXAFtquRa5PNdCj4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iYKtddn8SPxwMyTSxMyxEK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 13 Mar 2026 11:48:22 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iYKtddn8SPxwMyTSxMyxEK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Interpol logo and insignia pictured on a building facade at a regional unit in Singapore. ]]></media:description>                                                            <media:text><![CDATA[Interpol logo and insignia pictured on a building facade at a regional unit in Singapore. ]]></media:text>
                                <media:title type="plain"><![CDATA[Interpol logo and insignia pictured on a building facade at a regional unit in Singapore. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iYKtddn8SPxwMyTSxMyxEK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Interpol has taken down more than 40,000 malicious IP addresses and servers as part of an international cyber crime operation targeting phishing, <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>and <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>activities. </p><p>Law enforcement bodies from 72 countries and territories took part in Operation Synergia III between July 2025 and the end of January this year, with 94 people arrested and another 110 still under investigation.</p><p>In all, 45,000 malicious IP addresses were taken down and 212 electronic devices and servers were seized.</p><p>“Cyber crime in 2026 is more sophisticated and destructive than ever before, but Operation Synergia III stands as a powerful testament to what global cooperation can achieve," said Neal Jetton, director of Interpol's Cybercrime Directorate. </p><p>"Interpol remains at the forefront of this fight, uniting law enforcement agencies and private sector experts to dismantle criminal networks, disrupt emerging threats and protect victims around the world.”</p><p>As investigations are still ongoing, some details are under wraps. However, the results include the identification of more than 33,000 <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>and fraudulent websites in Macau, China, related to fake casinos and critical infrastructure, such as official bank, government and payment service sites. </p><p>Victims are defrauded by topping up their accounts via the fraudulent sites, or by having their personal information and credit card details stolen.</p><p>Police in Togo, meanwhile, arrested 10 suspects operating a fraud ring from a residential area. Some specialized in technical crimes such as hacking social media accounts while others carried out <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> schemes including romance scams and sextortion. </p><p>In Bangladesh, police arrested 40 suspects and seized 134 electronic devices related to a wide range of cyber crime schemes, including loan and job scams, identity theft, and credit card fraud.</p><h2 id="hot-on-the-heels-of-tycoon-2fa-takedown">Hot on the heels of Tycoon 2FA takedown</h2><p>The operation follows the disruption last week of the the massive phishing<a href="https://www.itpro.com/security/cyber-security/368284/what-is-phishing-as-a-service-phaas"> as a service (PhaaS)</a> platform, Tycoon 2FA.</p><p>This saw threat actors use <a href="https://www.itpro.com/security/cyber-crime/adversary-in-the-middle-attacks-are-becoming-hackers-go-to-method-to-bypass-mfa">adversary in the middle (AitM)</a> proxying to <a href="https://www.itpro.com/security/cyber-attacks/how-hackers-bypass-mfa-and-what-to-do-about-it">bypass traditional multi-factor authentication (MFA)</a> and capture session cookies in real time, leading to large-scale account compromise.</p><p>In an <a href="https://www.itpro.com/security/law-enforcement-and-security-firms-take-down-huge-phaas-platform"><u>international operation</u></a>, 330 domains were seized, including parts of the core infrastructure, such as phishing pages and control panels. </p><p>Much like that action, Operation Synergia III was carried out in collaboration with a number of private sector organizations, including Trend Micro.</p><p>“This kind of international operation highlights the value of close collaboration between law enforcement and the cybersecurity community. Behind every malicious server or phishing kit sits a wider criminal ecosystem that needs to be mapped and understood before arrests become possible," said Robert McArdle, director of cybercrime research at Trend Micro business unit TrendAI. </p><p>"Our support for investigations such as Tycoon 2FA, and contributions to operations like this one led by Interpol, demonstrates how actionable threat intelligence can help authorities identify infrastructure, connect actors and disrupt cyber criminal networks at scale.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Is your new hire an AI clone? Microsoft says North Korean hackers are using AI to impersonate job seekers and steal company secrets ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/is-your-new-hire-an-ai-clone-microsoft-says-north-korean-hackers-are-using-ai-to-impersonate-job-seekers-and-steal-company-secrets</link>
                                                                            <description>
                            <![CDATA[ The groups are increasingly using face-changing or voice-changing software to make their fake identities more plausible ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9jyHo9d4gA83CkaZBtmvcQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/U7xFHys4ZqNqAUYxH7V7Sa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 09 Mar 2026 12:23:15 +0000</pubDate>                                                                                                                                <updated>Tue, 10 Mar 2026 12:00:49 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/U7xFHys4ZqNqAUYxH7V7Sa-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Side profile view of a human head with brain synapses and flowing data lines. ]]></media:description>                                                            <media:text><![CDATA[Side profile view of a human head with brain synapses and flowing data lines. ]]></media:text>
                                <media:title type="plain"><![CDATA[Side profile view of a human head with brain synapses and flowing data lines. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/U7xFHys4ZqNqAUYxH7V7Sa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/should-your-business-worry-about-north-korean-cyber-attacks">North Korean threat groups</a> are using AI to ramp up efforts to infiltrate western companies with fake employees, according to new research.</p><p>Analysis from Microsoft’s Threat Intelligence Team shows three groups – Jasper Sleet, Sapphire Sleet, and Coral Sleet (formerly Storm-1877) – are using voice-changing software during remote interviews to disguise their accents and make their cover stories more convincing.</p><p>They're also using the AI app Face Swap to place their faces in stolen identity documents and generate convincing headshots for CVs.</p><p>"Threat actors are using <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>to shortcut the reconnaissance process that informs the development of convincing digital personas tailored to specific job markets and roles," Microsoft warned in a <a href="https://www.microsoft.com/en-us/security/blog/2026/03/06/ai-as-tradecraft-how-threat-actors-operationalize-ai/" target="_blank"><u>blog post</u></a>. </p><p>"Jasper Sleet leverages generative AI platforms to streamline the development of fraudulent digital personas. For example, Jasper Sleet actors have prompted AI platforms to generate culturally appropriate name lists and email address formats to match specific identity profiles."</p><p>The groups are also using AI to search job postings on jobs platforms such as Upwork, then using AI to make their applications meet the jobs' skill requirements. </p><p>This includes generating realistic names, email formats, and social media handles using AI prompts, writing AI-assisted resumes and cover letters, creating fake developer portfolios using AI-generated content, and using AI-enhanced images to create professional-looking profile photos and forged identity documents. </p><p>Microsoft noted that these personas are used across multiple job applications and platforms.</p><h2 id="voice-cloning-and-agentic-ai-are-in-vogue">Voice cloning and agentic AI are in vogue</h2><p>Elsewhere, Microsoft warned threat groups are using <a href="https://www.itpro.com/security/deepfake-business-risks-are-growing-what-leaders-need-to-know">AI-generated voice cloning</a> to impersonate executives or trusted individuals in vishing and <a href="https://www.itpro.com/security/cyber-attacks/what-is-business-email-compromise-bec">business email compromise (BEC)</a> scams</p><p>Once the fake workers are inside an organization, they use AI-enabled communications to support daily tasks and fit in with role expectations. </p><p>"For example, Jasper Sleet uses AI to help sustain long-term employment by reducing language barriers, improving responsiveness, and enabling workers to meet day-to-day performance expectations in legitimate corporate environments," Microsoft noted.</p><p>"Threat actors are leveraging generative AI in a way that many employees are using it in their daily work, with prompts such as 'help me respond to this email', but the intent behind their use of these platforms is to deceive the recipient into believing that a fake identity is real."</p><p>With the advent of agentic AI, Microsoft warned threat actors are also flocking to powerful new tools. </p><p>The tech giant’s threat intelligence team observed groups using agents to create semi‑autonomous workflows that help refine <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaigns, test and adapt infrastructure, maintain persistence, or monitor open source intelligence for new opportunities.</p><h2 id="north-korean-hackers-are-prolific">North Korean hackers are prolific</h2><p>The problem of North Korean fake workers just won't seem to go away. While this trend primarily affected US companies, Google warned last summer that threat groups are now <a href="https://cloud.google.com/transform/ultimate-insider-threat-north-korean-it-workers"><u>expanding campaigns to target European organizations</u></a>. </p><p>Last month, Security Alliance (SEAL) warned that <a href="https://www.itpro.com/security/fake-north-korean-it-workers-are-rampant-on-linkedin-security-experts-warn-operatives-are-stealing-profiles-to-apply-for-jobs-and-infiltrate-firms">North Korean hackers are hijacking genuine LinkedIn profiles</a> to apply for remote jobs and infiltrate enterprises. </p><p>Hackers typically use real identities, leveraging verified workplace emails and identity badges, and constructing credible employment histories to pass background checks.</p><p>Organizations are advised to tighten up their identity verification processes, including document checks and, wherever possible, in-person interviews.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ LastPass issues alert as customers face second major phishing campaign of 2026 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/lastpass-issues-alert-as-customers-face-second-major-phishing-campaign-of-2026</link>
                                                                            <description>
                            <![CDATA[ The campaign is the third to hit LastPass users in six months ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MoCaRUcUDxBBuWzHCWEBw8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ocP3dX4tjhaXs2GSGBykGh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 04 Mar 2026 11:42:09 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ocP3dX4tjhaXs2GSGBykGh-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[LastPass logo and branding reflected on the internal discs of a hard drive.]]></media:description>                                                            <media:text><![CDATA[LastPass logo and branding reflected on the internal discs of a hard drive.]]></media:text>
                                <media:title type="plain"><![CDATA[LastPass logo and branding reflected on the internal discs of a hard drive.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ocP3dX4tjhaXs2GSGBykGh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/software/368008/lastpass-vs-1password">LastPass </a>customers are again being targeted by <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>emails that appear to be forwarded internal messages.</p><p>In a <a href="https://blog.lastpass.com/posts/march-2026-phishing-campaign-targeting-lastpass-customers" target="_blank"><u>customer advisory</u></a>, the password manager firm warned emails  are being sent from several email addresses, with various subject lines, claiming there has been unauthorized access to individuals’ accounts. </p><p>"This is an attempt on the part of a malicious actor to draw attention and generate urgency in the mind of the recipient, a common tactic for social engineering and phishing emails," the company warned.</p><p>The fake email chains are intended to make it appear as though another individual is trying to take unauthorized action on their LastPass account - for example, exporting vaults, attempting full account recovery, or registering a new trusted device. </p><p>Attackers use display name spoofing as part of the attack so that the name portion of the sender field appears to be LastPass, while the actual sending email address is unrelated. </p><p>This can fool recipients, LastPass warned, as many email clients, especially mobile, show only the display name while the complete sender address is shown if it's expanded. </p><h2 id="what-lastpass-users-need-to-know">What LastPass users need to know</h2><p>The emails ask the recipient to take action such as reporting suspicious activity, disconnecting and locking the vault, or revoking a device, via included links - links that direct the targets to fake <a href="https://www.itpro.com/security/single-sign-on-sso/361728/what-is-single-sign-on-sso">Single Sign-On (SSO)</a> pages that then collect their credentials.</p><p>"At the center of the phishing chain is the domain https[:]//verify-lastpass[.]com," said LastPass. </p><p>"Most malicious links redirect to this domain, but the attackers generate many slightly modified versions by adding different trailing numbers. This lets them produce a large set of URLs that all resolve to the same phishing page."</p><p>The emails originate from several addresses, including:</p><ul><li>office@hancochem.at</li><li>admin@salud5i.cl</li><li>no_reply@remstal-praxis.de</li><li>demo@fluxstore.io</li><li>no_reply@kreducationsa.com</li><li>support@yodhafinance.com</li><li>hr@bebran.com</li><li>info@itpbusa.com</li></ul><p>Subject lines include "Re: the details", "Re: pending approval", "Re: Access request pending", "Re: FYI", "RE: sign-in — TRZ-2302300", "Fwd: Re: your request" and "Re: credential download".</p><p>LastPass emphasized that it will never ask for their master password and said it is working with its third-party partners to have the offending sites taken down as soon as possible.</p><h2 id="lastpass-users-face-an-array-of-threats">LastPass users face an array of threats</h2><p>This is the second phishing campaign against LastPass users in the space of two months, highlighting the range of threats faced by customers. </p><p>In January, for example, fraudulent emails were distributed to users <a href="https://www.itpro.com/security/phishing/lastpass-issues-alert-as-customers-targeted-in-new-phishing-campaign"><u>claiming that the site was due to undergo maintenance</u></a>. </p><p>That particular campaign urged customers to back-up vaults within 24 hours, and some received phone calls from the scammers aimed at increasing pressure. </p><p>In October last year, another campaign used similar tactics, claiming that the company had been hacked.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A single compromised account gave hackers access to 1.2 million French banking records ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/a-single-compromised-account-gave-hackers-access-to-1-2-million-french-banking-records</link>
                                                                            <description>
                            <![CDATA[ Ficoba has warned that “numerous” scams are already in circulation following the data breach ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MctzL27C9DgHoFVWrZYiq4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 20 Feb 2026 10:55:22 +0000</pubDate>                                                                                                                                <updated>Fri, 20 Feb 2026 13:17:05 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:description>                                                            <media:text><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Credentials stolen from a single government official enabled threat actors to access a French national database containing data on more than 1.2 million bank accounts.</p><p>The attackers were able to access the Fichier des comptes bancaires (Ficoba) database, which contains files on all bank accounts opened in France. </p><p>Stolen credentials were used by the threat actors to impersonate a civil servant and view data that included personal information such as bank account numbers, account holders' names and addresses, IBANs, and, in some cases, the account owner's tax number. </p><p>"Starting at the end of January 2026, a malicious actor, who had impersonated a civil servant with access rights as part of an inter-ministerial information exchange, was able to consult a portion of this file," Ficoba said in a <a href="https://presse.economie.gouv.fr/acces-illegitimes-au-fichier-national-des-comptes-bancaires-ficoba/" target="_blank"><u>statement</u></a>.</p><p>"As soon as this incident was detected, immediate access restrictions were implemented to stop the attack, limit the scope of the data accessed and extracted from this database – which reportedly includes 1.2 million accounts – and prevent any further unauthorized access." </p><p>Ficoba said IT teams at the French Public Finances Directorate, along with other bodies, were working to address this incident and strengthen security. The incident has also been reported to the French Data Protection Authority (CNIL), it said.</p><p>The chief of France's Public Finances told Agence France-Presse that affected individuals will be contacted over the next few days. Officials insisted the breach did not give attackers access to account balances or transactions.</p><h2 id="ficoba-breach-prompts-phishing-frenzy">FICOBA breach prompts phishing frenzy</h2><p>Security researchers at Cybernews said that this may not be the full story. While account balances can’t be accessed from this data alone, this incident “still poses risks” to users across the country. </p><p>“Exposed PII, such as names and addresses, can be combined with other leaked data to profile people and construct convincing <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaigns that can pose as the national bank.”</p><p>When combined with tax identification numbers, researchers said this increases the risk of fraud and identity theft, as these numbers can be used as identifiers on government platforms.</p><p>Ficoba has warned that "numerous" scams are circulating via email or SMS, aiming to obtain information or payments from users. </p><p>Individuals contacted have been urged not to reply directly, and should instead contact their local tax office directly through the secure messaging system in their online account or by phone to check out the authenticity of the message.</p><p>Meanwhile, Michael Jepson, penetration testing manager at CybaVerse, said it's worrying that a single individual within the organization was able to access large volumes of sensitive data unilaterally.</p><p>"Traditionally, access scope often increased with seniority, an approach that is now widely recognized as problematic in modern threat environments," he said. </p><p>"Modern security practice recognizes that access should be determined strictly by operational need rather than hierarchy. Senior figures are frequently primary targets for threat actors, which makes <a href="https://www.itpro.com/cloud/cloud-security/are-your-cloud-resources-at-risk">excessive privilege</a> particularly dangerous."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Starkiller: Cyber experts issue warning over new phishing kit that proxies real login pages ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/starkiller-cyber-experts-issue-warning-over-new-phishing-kit-that-proxies-real-login-pages</link>
                                                                            <description>
                            <![CDATA[ The Starkiller package offers monthly framework updates and documentation, meaning no technical ability is needed ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mHwEJejwdhDhzJt7KvMCBA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tjxtfTzqYUV5qV2FNQQYVM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 19 Feb 2026 12:06:46 +0000</pubDate>                                                                                                                                <updated>Thu, 19 Feb 2026 12:22:07 +0000</updated>
                                                                                                                                            <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tjxtfTzqYUV5qV2FNQQYVM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Close-up image of a web browser URL bar with https code.]]></media:description>                                                            <media:text><![CDATA[Close-up image of a web browser URL bar with https code.]]></media:text>
                                <media:title type="plain"><![CDATA[Close-up image of a web browser URL bar with https code.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tjxtfTzqYUV5qV2FNQQYVM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Researchers at Abnormal Security have uncovered a new <a href="https://www.itpro.com/security/phishing/phishing-as-a-service-kits-growth-2025-barracuda">phishing kit</a> that proxies live login pages, <a href="https://www.itpro.com/security/cyber-attacks/how-hackers-bypass-mfa-and-what-to-do-about-it">bypasses MFA</a>, and includes a full credential-harvesting platform for a monthly fee.</p><p>While most phishing kits rely on static HTML clones of login pages, these are inherently fragile, as even minor interface updates from the impersonated brand can reveal the deception immediately.</p><p>However, a new framework called Starkiller – not to be confused with the legitimate BC-Security red team tool of the same name – does things differently. </p><p>"Sold openly as a commercial-grade cybercrime platform by a threat group calling itself Jinkusu, Starkiller is distributed like a <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas">SaaS </a>product," said Abnormal.</p><p>"It launches a headless Chrome instance — a browser that operates without a visible window — inside a Docker container, loads the brand’s real website, and acts as a reverse proxy between the target and the legitimate site."</p><h2 id="how-starkiller-works">How Starkiller works</h2><p>Cyber criminals select a brand to impersonate; for example, Google, Microsoft, Facebook, Apple, Amazon, Netflix, PayPal, and various banks.</p><p>Because the recipients are served genuine page content directly through the attacker's infrastructure, the phishing page never goes out of date. Similarly, as Starkiller proxies the real site live, there are no template files for security vendors to fingerprint or blocklist.</p><p>Researchers found that Starkiller's control panel gives cyber criminals a polished dashboard for deploying phishing campaigns, and the core workflow requires almost no technical skill. </p><p>Docker engine status, image builds, and active containers are managed from the same panel, meaning threat actors don't need to understand reverse proxies or certificate management to launch an attack.</p><p>An attacker enters a brand’s real URL, and the platform spins up a Docker container running a headless Chrome instance that loads the real login page. </p><p>The container then acts as a man-in-the-middle reverse proxy, forwarding the end user’s inputs to the legitimate site and returning the site's responses. </p><p>"Every keystroke, form submission, and session token passes through attacker-controlled infrastructure and is logged along the way," the researchers said.</p><h2 id="keeping-tabs-on-victims">Keeping tabs on victims</h2><p>Notably, the package offers real-time session monitoring, allowing attackers to watch the target interact with the <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>page live. </p><p>Along with keylogger capture for every keystroke, it includes cookie and session token theft for direct account takeover, geo-tracking of targets, and automated Telegram alerts when new credentials come in. </p><p>Because the end user is actually authenticating with the real site through the proxy, any one-time codes or authentication tokens they submit are forwarded to the legitimate service in real time. </p><p>Capturing the resulting session cookies and tokens gives the attacker authenticated access to the account. This means that MFA protections can effectively be neutralized, despite functioning exactly as designed.</p><p>Jinkusu maintains a community forum where cyber criminals discuss techniques, request features, and troubleshoot deployments. </p><p>"The forum shows an active user base sharing operational tips and asking about mobile support, indicating a growing pool of operators using the framework in the wild," the researchers said.</p><p>"Operators also receive dedicated support via Telegram, monthly framework updates, and documentation. The level of ongoing development means Starkiller is likely to become increasingly difficult to detect and defend against."</p><h2 id="how-to-avoid-falling-prey">How to avoid falling prey</h2><p>Traditional detection approaches such as static page analysis, domain blocklisting, and reputation-based URL filtering don't work, as Starkiller dynamically generates phishing pages for each session. </p><p>Instead, Abnormal said detection needs to shift toward behavioral signals such as anomalous login patterns and session token reuse from unexpected locations. </p><p>Elsewhere, identity-aware analysis needs to be improved to catch a compromised session - even when the phishing page itself looks perfect.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google says hacker groups are using Gemini to augment attacks – and companies are even ‘stealing’ its models ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/google-says-hacker-groups-are-using-gemini-to-augment-attacks-and-companies-are-even-stealing-its-models</link>
                                                                            <description>
                            <![CDATA[ Google Threat Intelligence Group has shut down repeated attempts to misuse the Gemini model family ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qzWopoZe4zTA5NEjJaY4zK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/u2PgWCzhcwJ3sd5MyNLvqf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 12 Feb 2026 11:40:16 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                <author><![CDATA[ rory.bathgate@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LFPWMoCGDVHowHbMpHJZkU.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rory Bathgate is the Features and Multimedia Editor at ITPro, overseeing all in-depth content and case studies. He is a subject expert on artificial intelligence and business networks but in his time at ITPro has also covered a wide range of areas including cyber security and hardware. Throughout his time at ITPro, Rory has charted the rise in popularity of generative AI and specifically companies such as Microsoft, OpenAI, and Google. &lt;/p&gt;&lt;p&gt;Alongside this, he has delved into increasing calls for ethical and responsible AI as global legislators circle the technology, as well as the latest in mobile networking technology, from 5G mmWave to the 3G sunset and how it will affect businesses.&lt;/p&gt;&lt;p&gt;He has provided coverage from high-profile tech conferences such as Dell Technologies World, SuiteWorld, and VMware Explore Europe. His on-the-ground coverage has included live blogs, extensive daily coverage of the most significant announcements, analysis pieces, and podcasts.&lt;/p&gt;&lt;p&gt;Indeed, Rory is also a full-time co-host of the ITPro Podcast alongside Jane McCallion, where he swaps a keyboard for a microphone to discuss the latest learnings in tech. Each week, a guest comes onto the show to discuss topics such as cyber security, productivity, or digital transformation in detail.&lt;/p&gt;&lt;p&gt;Rory has an MA in Eighteenth-Century Studies from King’s College London, as well as a BA in English and American Literature from the University of Kent. He joined ITPro in 2022 as a graduate, after four years in student journalism.&lt;/p&gt;&lt;p&gt;In his free time, Rory enjoys photography and video editing, and can often be found at the cinema or reading a good science fiction paperback.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/u2PgWCzhcwJ3sd5MyNLvqf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google Gemini AI logo and branding picture on a smartphone screen.]]></media:description>                                                            <media:text><![CDATA[Google Gemini AI logo and branding picture on a smartphone screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Google Gemini AI logo and branding picture on a smartphone screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/u2PgWCzhcwJ3sd5MyNLvqf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>State-backed threat actors from <a href="https://www.itpro.com/security/cyber-attacks/crink-attacks-nation-state-hackers--threat-2026"><u>CRINK nations</u></a> have come to rely on large language models (LLMs) as “essential tools” for researching and targeting victims, according to a new report.</p><p>The latest <a href="https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use" target="_blank"><u><em>AI Threat Tracker</em></u></a> report from Google Threat Intelligence Group (GTIG), produced in collaboration with Google DeepMind, details the numerous ways threat groups are already using AI to plan and carry out attacks.</p><p><a href="https://www.itpro.com/security/cyber-attacks/what-is-an-apt"><u>Advanced persistent threat (APT)</u></a> groups were tracked using Google’s own Gemini family of models to conduct targeted research on potential victims, probe vulnerabilities, and create tailored code and scripts.</p><p>For example, the China-based APT Temp.HEX was found using Gemini to file information on individual targets in Pakistan.</p><p>The as-yet-unattributed APT UNC6148 also used Gemini to seek out sensitive information tied to victims, such as email addresses and account details, as the first step in a targeted <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing campaign</a> on Ukraine and the wider defense sector. </p><p>In response, Google disabled the assets associated with both groups. Other incidents saw attackers use public AI models to more directly fuel attack campaigns.</p><p>Iranian-backed groups such as APT42 were observed using Gemini and other AI models to research potential victims, then craft convincing phishing emails based on target biographies. </p><p>That same group was observed using Gemini to translate local languages as well as regional references and phrases.</p><p>North Korea-backed groups seized headlines throughout 2024 and 2025, as <a href="https://www.itpro.com/security/cyber-attacks/north-korean-it-workers-the-growing-threat"><u>hackers infiltrated IT departments</u></a> of major organizations <a href="https://www.itpro.com/security/cyber-firm-knowbe4-unknowingly-hired-a-north-korean-hacker-and-it-went-exactly-as-you-might-think"><u>including KnowBe4</u></a> with fake addresses and identities. </p><p>In the report, the North Korean-backed group UNC2970 was found using Gemini to plan attacks on <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>defense companies and map job specifications.</p><h2 id="ai-enhanced-malware-is-gathering-steam">AI-enhanced malware is gathering steam</h2><p>The report also noted the growing risk presented by malware that uses AI to achieve novel capabilities such as preventing network detection.</p><p>HONESTCUE <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>, for example, has been found to use API calls to Gemini to generate ‘stage two’ code. This is used to download and execute additional malware directly in the memory of target systems using CSharpCodeProvider, a legitimate .NET class for executing C# code.</p><p>Because the Gemini-produced code executes the secondary malware directly in memory, HONESTCUE infects target systems without leaving telltale artifacts on the victim’s disk. </p><p>Though the malware hasn’t been linked to specific attack campaigns to date, GTIG researchers said they believe its developer is a single threat actor or small group testing the waters for future attacks. This is backed up by evidence HONESTCUE has been tested on Discord.</p><p>Another example can be found in COINBAIT, a <a href="https://www.itpro.com/security/phishing/phishing-as-a-service-kits-growth-2025-barracuda">phishing kit</a> created by the APT UNC5356 that shows signs of having been created using the <a href="https://www.itpro.com/technology/artificial-intelligence/vibe-coding-security-risks-how-to-mitigate"><u>vibe coding platform</u></a> Lovable.</p><p>GTIG has previously warned that <a href="https://www.itpro.com/business/google-says-leading-ai-malware-strains-are-nowhere-near-good-enough-yet-but-that-wont-last-long-as-hackers-refine-techniques"><u>while AI malware is still nascent, it’s developing quickly</u></a>. In the latest report, authors noted that while no “paradigm shift” has yet been unlocked by APTs, their exploration of malicious AI is ongoing and the technology will play a growing role in every stage of the attack lifecycle.</p><p>On the other hand, researchers discovered that threat actors are passing off jailbroken public AI models as handmade offensive tools.</p><p>For example ‘Xantharox’, a dark web toolkit advertised as tailor-made offensive AI toolset, is actually powered by open source AI tools such as Crush and Hexstrike AI via model context protocol (MCP), as well as public AI models like Gemini.</p><p>Threat actors are stealing API keys to enable this hidden activity, with GTIG warning organizations with cloud and AI resources are at risk. Users on platforms such as One API and New API, often those in countries with regional AI censorship, are also targeted for API key harvesting.</p><h2 id="model-extraction-puts-ai-developers-at-risk">Model extraction puts AI developers at risk</h2><p>Researchers also observed instances of APTs performing ‘model extraction’, in which attackers use legitimate access to frontier models such as Gemini to help train new AI and machine learning (ML) models.</p><p>Generally, attackers use an approach known as knowledge distillation (KD) in which a ‘student’ AI model is trained on the answers to specific questions based on the exemplar answers of the pre-existing AI model.</p><p>This can result in models with advanced capabilities such as frontier reasoning but none of the guardrails present in public AI models like Gemini. In the future, threat actors could then use </p><p>GTIG tracked over 100,000 prompts intended to expose and replicate Gemini’s reasoning capabilities in non-English languages, which were automatically counteracted by Google’s systems.</p><p>“Google’s latest AI Threat Tracker marks a specific turning point: we are no longer just worried about bad prompts, but the industrial-scale extraction of the models themselves,” <a href="https://www.linkedin.com/feed/update/urn:li:activity:7427616775657426944/?originTrackingId=mUmbBH5%2FM1mlBWHYZ4FCAg%3D%3D" target="_blank"><u>wrote</u></a> Jamie Collier, lead advisor in Europe at Google Threat Intelligence Group, in a LinkedIn post marking the launch of the report.</p><p>Google DeepMind and GTIG blocked attempts at model extraction throughout 2025, noting that the attacks were launched by private companies and researchers around the world rather than APTs.</p><p>Distilling secondary models from Gemini is a violation of Google’s terms of service and is considered theft of intellectual property (IP). The hyperscaler recommended organizations that provide AI models as a service should closely observe API access for signs of model extraction. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security experts warn Substack users to brace for phishing attacks after breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/security-experts-warn-substack-users-to-brace-for-phishing-attacks-after-breach</link>
                                                                            <description>
                            <![CDATA[ Substack CEO Christ Best confirmed the incident occurred in October 2025 ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">o7MCXZ7M3JJJe6sM7bNT9B</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/k4Nndu7uQs2VrqAomgdw8R-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 Feb 2026 09:38:32 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/k4Nndu7uQs2VrqAomgdw8R-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Substack logo and branding pictured on a laptop screen with hand placed on keyboard and blurred user head in foreground.]]></media:description>                                                            <media:text><![CDATA[Substack logo and branding pictured on a laptop screen with hand placed on keyboard and blurred user head in foreground.]]></media:text>
                                <media:title type="plain"><![CDATA[Substack logo and branding pictured on a laptop screen with hand placed on keyboard and blurred user head in foreground.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/k4Nndu7uQs2VrqAomgdw8R-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/28133/what-is-cyber-security">Cybersecurity </a>experts have warned Substack users to be on the lookout for potential phishing scams after the blogging platform suffered a data breach. </p><p>In an <a href="https://bsky.app/profile/newsguy.bsky.social/post/3me3dhsexmt2s" target="_blank"><u>email </u></a>distributed to users, CEO Chris Best revealed a “security incident” saw account email addresses, contact numbers, and “other internal metadata” exposed. </p><p>Exact details on how the breach unfolded are yet to be disclosed. However, on 3 February, the organization discovered an issue that allowed an unauthorized third-party to “access limited user data.”</p><p>A preliminary investigation found the data was first accessed in October 2025, Best added. </p><p>“Importantly, credit card numbers, passwords, and financial information were not accessed,” the email reads. </p><p>“We have fixed the problem with our system that allowed this to happen. We are conducting a full investigation and are taking steps to improve our systems and processes to prevent this type of issue from happening in the future.”</p><p>Substack hasn’t revealed information on the scale of the breach. However, reports from <a href="https://www.bleepingcomputer.com/news/security/newsletter-platform-substack-notifies-users-of-data-breach/" target="_blank"><u><em>BleepingComputer </em></u></a>suggest the incident could have impacted over half a million users. </p><p>On Monday 2 February, a threat actor uploaded a database to BreachForums allegedly containing 697,313 stolen records.</p><h2 id="substack-users-should-remain-vigilant">Substack users should remain vigilant</h2><p>Best noted that there is currently no evidence that information exposed in the breach is being misused, but nonetheless warned users to remain vigilant. </p><p>“We encourage you to take extra caution with any emails or text messages you receive that may be suspicious,” he said. </p><p>That same advice has since been reiterated by cybersecurity experts. <a href="https://www.itpro.com/security/29093/what-is-phishing">Phishing </a>attacks are a common occurrence in the wake of a data breach as cyber criminals look to capitalize on contact information to dupe unsuspecting users.</p><p>This information often represents a goldmine for threat actors, according to Jamie Akhtar, CEO of CyberSmart.</p><p>“While Substack has stated that sensitive data such as passwords and payment information was not accessed, exposure of contact details like email addresses and phone numbers can still be highly valuable to cyber criminals,” he said. </p><p>“This type of data is often used as the foundation for targeted phishing, impersonation attempts, and wider <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> campaigns.”</p><p>Javvad Malik, lead security awareness advocate at KnowBe4, echoed Akhtar’s comments, but noted that the information provided by Substack is limited, which could still leave some users at risk. </p><p>“It is a bit light on the details which can help people accurately judge the risk and take concrete action,” he said. The timeline is significant. If the data was accessed in October 2025, but only just disclosed, it's a significant dwell time.”</p><p>“That isn't to say there's negligence on part of Substack because detection can be difficult,” Malik added. “But impacted users deserve a clearer explanation of how the breach was identified.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google issues warning over ShinyHunters-branded vishing campaigns ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/google-issues-warning-over-shinyhunters-branded-vishing-campaigns</link>
                                                                            <description>
                            <![CDATA[ Related groups are stealing data through voice phishing  and fake credential harvesting websites ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zHr8MESTqLrM7FdPM6unGB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6UMt7L8cwrivqQPjJWN3eX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 04 Feb 2026 08:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6UMt7L8cwrivqQPjJWN3eX-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Device code phishing concept image showing cartoon cell phone with a hook attached to a sign-in page. ]]></media:description>                                                            <media:text><![CDATA[Device code phishing concept image showing cartoon cell phone with a hook attached to a sign-in page. ]]></media:text>
                                <media:title type="plain"><![CDATA[Device code phishing concept image showing cartoon cell phone with a hook attached to a sign-in page. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6UMt7L8cwrivqQPjJWN3eX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google Threat Intelligence Group (GTIG) has identified a group with all the hallmarks of ShinyHunters using <a href="https://www.itpro.com/security/cyber-attacks/phishing-tactics-the-top-attacks-trends-in-year">voice phishing</a> (vishing) and fake credential harvesting websites to steal sensitive data. </p><p>In an advisory, the tech giant warned the group primarily gains access to corporate environments by obtaining single sign-on (SSO) credentials and <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">multi-factor authentication (MFA)</a> codes. </p><p>Once inside, the attackers target cloud-based SaaS applications to exfiltrate sensitive data and internal communications that they can use in subsequent extortion demands.</p><p>Google is currently <a href="https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhunters-saas-data-theft" target="_blank"><u>tracking</u></a> the activity under several threat clusters, including UNC6661, UNC6671, and UNC6240.</p><p>Last month, for example, UNC6661 pretended to be IT staff and called employees at targeted organisations, claiming that the company was updating MFA settings. </p><p>The threat actor then directed employees to victim-branded credential harvesting sites to capture credentials and MFA codes, with victims thereafter registering their own device for MFA. </p><p>According to Google, threat actors moved laterally through victim customer environments to exfiltrate data from various <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas">SaaS </a>platforms.</p><p>While the attacks are targeted, analysis suggests that subsequent access is probably opportunistic, determined by the specific permissions and applications accessible via the individual compromised SSO session. Google stressed that the activity isn't the result of a security vulnerability in vendors' products or infrastructure. </p><p>"In some cases, they have appeared to target specific types of information. For example, the threat actors have conducted searches in cloud applications for documents containing specific text including 'poc', 'confidential', 'internal', 'proposal', 'salesforce', and 'vpn' or targeted personally identifiable information (PII) stored in Salesforce," researchers said. </p><p>"Additionally, UNC6661 may have targeted Slack data at some victims' environments, based on a claim made in a ShinyHunters-branded data leak site (DLS) entry."</p><h2 id="valuable-intelligence">Valuable intelligence</h2><p>Cory Michal, CSO at AppOmni, praised the level of operational detail in the report, and particularly the volume and specificity of indicators of compromise that weren’t previously public.</p><p>This intelligence could prove vital for organizations that find themselves in the crosshairs moving forward, Michael noted.</p><p>“Publishing concrete domains, tooling names/artifacts, and workflow-level signals gives defenders something they can deploy immediately at scale (email/web filtering, OAuth/app controls, identity telemetry detections, and retro-hunting),” he said.</p><p>“It helps the ecosystem disrupt infrastructure and tradecraft faster by enabling consistent blocking and takedown actions across many organizations rather than each team rediscovering the same indicators in isolation.”</p><h2 id="what-can-enterprises-do-to-protect-themselves">What can enterprises do to protect themselves?</h2><p>Google has published <a href="https://cloud.google.com/blog/topics/threat-intelligence/defense-against-shinyhunters-cybercrime-saas" target="_blank"><u>guidance</u></a> on hardening, logging, and detection against the threats. </p><p>Organizations responding to an active incident should focus on rapid containment steps, such as severing access to infrastructure environments, SaaS platforms, and the specific identity stores typically used for lateral movement and persistence. </p><p>Long-term defense, meanwhile, requires a transition toward phishing-resistant MFA, such as FIDO2 security keys or passkeys, which are more resistant to <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> than push-based or SMS authentication.</p><p>“Companies should treat this as both a hunt and prevent problem: First, take the IoCs in the report and run them through your detection-and-response workflows (SIEM/SOAR, email security, web proxy/DNS, EDR, and SaaS audit logs) to identify any historical or active exposure," Michal added. </p><p>Michael added they should add continuous monitoring for look-alike domain registrations that incorporate their company name or common brands that they use for login, support, and HR. </p><p>"In many of these campaigns, those newly registered domains are a leading indicator, they show up before the first vishing call, so catching and blocking them early (and tightening your help desk/MFA enrollment controls in parallel) can meaningfully reduce the chance the intrusion ever gets to the “mass download and extortion” stage,” he said.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are using LLMs to generate malicious JavaScript in real time – and they’re going after web browsers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hackers-are-using-llms-to-generate-malicious-javascript-in-real-time-and-theyre-going-after-web-browsers</link>
                                                                            <description>
                            <![CDATA[ Defenders advised to use runtime behavioral analysis to detect and block malicious activity at the point of execution, directly within the browser ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jCEPJqp6YG8HwK82cTm96g</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MNSH2GsMD6TfUQC4bpLHm-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 28 Jan 2026 12:57:52 +0000</pubDate>                                                                                                                                <updated>Wed, 28 Jan 2026 13:11:31 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MNSH2GsMD6TfUQC4bpLHm-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Generative AI attack concept image showing a robotic, AI-controlled hand holding an alert symbol.]]></media:description>                                                            <media:text><![CDATA[Generative AI attack concept image showing a robotic, AI-controlled hand holding an alert symbol.]]></media:text>
                                <media:title type="plain"><![CDATA[Generative AI attack concept image showing a robotic, AI-controlled hand holding an alert symbol.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MNSH2GsMD6TfUQC4bpLHm-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Organizations are being warned to look out for a new <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>technique, in which LLMs are used to assemble the attack at the moment of execution in the victim's browser.</p><p>The method, <a href="https://unit42.paloaltonetworks.com/real-time-malicious-javascript-through-llms/" target="_blank"><u>said</u></a> Palo Alto Networks, involves a seemingly benign webpage using client-side API calls to trusted LLM services to generate malicious JavaScript dynamically in real time. </p><p>By using carefully engineered prompts to bypass AI safety guardrails, attackers could trick the LLM into returning malicious code snippets via the LLM service API. These are then assembled and executed in the victim's browser at runtime, resulting in a fully functional phishing page.</p><p>The technique is designed to be evasive. The malicious content is delivered from a trusted LLM domain, bypassing network analysis, and assembled and executed at runtime. </p><p>Similarly, the code for the phishing page is polymorphic, so there’s a unique, syntactically different variant for each visit.</p><p>"The dynamic nature of this attack in combination with runtime assembly in the browser makes it a formidable defense challenge," said the Palo Alto researchers. </p><p>"This attack model creates a unique variant for every victim. Each malicious payload is dynamically generated and unique, transmitted over a trusted domain."</p><h2 id="how-the-technique-works">How the technique works</h2><p>The proof of concept involved selecting a webpage from an active phishing campaign to use as a model for the <a href="https://www.itpro.com/security/hackers-are-taking-advantage-of-ai-hallucinations-to-sneak-malicious-software-packages-onto-enterprise-repositories">malicious code</a>. From there, attackers can create JavaScript code snippets that will be generated in real time to dynamically render the final page displayed to the user.</p><p>The next step involved crafting prompts describing the <a href="https://www.itpro.com/development/30202/what-is-javascript-and-why-should-i-learn-it">JavaScript </a>code's functionality to the LLM in plain text. These could be iteratively refined, generating malicious code that bypasses existing LLM guardrails. </p><p>These generated snippets could differ in both structure and syntax, allowing attackers to create polymorphic code with the same functionality.</p><p>Attackers could embed these engineered prompts inside a webpage, which would load on the victim's browser. The webpage then uses the prompt to request a popular, legitimate LLM API endpoint to generate malicious code snippets. </p><p>Ultimately, these snippets could be transmitted over popular, trusted domains to bypass network analysis. Subsequently, these generated scripts could be assembled and executed to render malicious code or phishing content.</p><h2 id="llm-guardrails-at-breaking-point">LLM guardrails at breaking point</h2><p>This scenario, said the researchers, signals a critical shift in the security landscape: while detecting these attacks is possible through enhanced browser-based crawlers, it ​​requires runtime behavioral analysis within the browser.</p><p>"Defenders should also restrict the use of unsanctioned <a href="https://www.itpro.com/cloud/cloud-security/enterprises-beware-your-llm-servers-could-be-unintentionally-exposing-sensitive-data">LLM </a>services at workplaces. While this is not a complete solution, it can serve as an important preventative measure," the researchers said.</p><p>"Finally, our work highlights the need for more robust safety guardrails in LLM platforms, as we demonstrated how careful <a href="https://www.itpro.com/technology/artificial-intelligence/this-engineering-discipline-was-hailed-as-the-next-big-thing-but-ai-has-killed-it-before-it-even-started">prompt engineering</a> can circumvent existing protections and enable malicious use."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Thousands of Microsoft Teams users are being targeted in a new phishing campaign ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/microsoft-teams-phishing-scam-fake-billing-check-point</link>
                                                                            <description>
                            <![CDATA[ Microsoft Teams users should be on the alert, according to researchers at Check Point ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xYBLYYi6CQjeTaVUDQ9sSk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WwZJrcyz5jLppWLVcEFL8m-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 26 Jan 2026 10:45:59 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WwZJrcyz5jLppWLVcEFL8m-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft Teams login page on desktop app pictured on a laptop screen.]]></media:description>                                                            <media:text><![CDATA[Microsoft Teams login page on desktop app pictured on a laptop screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft Teams login page on desktop app pictured on a laptop screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WwZJrcyz5jLppWLVcEFL8m-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaign is abusing trusted collaboration platforms like <a href="https://www.itpro.com/software/33703/microsoft-teams-review-a-no-brainer-for-microsoft-shops">Microsoft Teams</a> to bypass traditional email security.</p><p><a href="https://www.itpro.com/security/28133/what-is-cyber-security">Cybersecurity</a> researchers at Check Point have <a href="https://blog.checkpoint.com/email-security/attackers-continue-to-target-trusted-collaboration-platforms-12000-emails-target-teams-users/" target="_blank"><u>discovered</u></a> more than 12,000 malicious emails sent to over 6,000 users, most of which use legitimate Microsoft Teams guest invitations to impersonate billing alerts and trick victims into calling fake support lines. </p><p>Rather than relying on <a href="https://www.itpro.com/security/phishing/how-hackers-are-using-legitimate-tools-to-distribute-phishing-links">malicious links</a> or attachments, attackers are exploiting built-in guest invitation options and finance-themed team names to dupe users with fake billing and subscription notifications.</p><p>The attacker starts off by creating a new team in Microsoft Teams and assigning it a finance-themed name designed to resemble an urgent billing or subscription notice. </p><p>One example given by Check Point researchers read: “<em>Subscription Auto-Pay Notice (Ivoice ID: 2025_614632PPOT_SAG Amount 629. 98 USD). If you did not authorize or complete this m0nthly Payment,plese c0ntact our support team urgently.</em>”</p><p>The aim here for attackers is to bypass automated detection by embedding obfuscation techniques in the team name. This includes character substitutions, mixed Unicode characters, visually similar glyphs, and the like.</p><p>After creating the team, the attacker uses the <em>Invite a Guest</em> feature in Microsoft Teams, sending the victim an email invitation from a legitimate Microsoft address, with the fake team name displayed prominently in large font. </p><p>"At first glance, the message appears to be a genuine Microsoft-generated notification, increasing the likelihood that users trust the content and follow the instructions," the researchers warned.</p><p>Recipients are then asked to call a fraudulent support number to resolve the "billing issue".</p><p>The fraudulent emails are being used to target a wide range of organizations, researchers noted, with 27% targeting manufacturing, engineering and construction and 1% technology/SaaS. </p><p>One-in-eight, meanwhile, went to educational organizations, followed by professional services at 11%, government at 8%, and finance at 7%.</p><p>"The distribution likely reflects broad Microsoft Teams adoption across these industries, rather than deliberate targeting," the researchers said. "This suggests the attacker’s primary objective was to exploit a trusted collaboration platform at scale, rather than focus on specific verticals."</p><p>Two-thirds of victims were in the US, with 16% in Europe and 6% in Asia. </p><h2 id="microsoft-teams-scams-are-surging">Microsoft Teams scams are surging</h2><p>Microsoft Teams, and indeed collaboration platforms and trusted brands, have become a common attack vector for cyber criminals. </p><p>This time last year, researchers at Sophos spotted <a href="https://www.itpro.com/security/cyber-attacks/hackers-are-using-microsoft-teams-to-conduct-email-bombing-attacks"><u>threat actors posing at tech support workers</u></a> to launch attacks through the platform.</p><p>More recently, the Scattered Spider hacking group <a href="https://www.itpro.com/security/ransomware/the-scattered-spider-ransomware-group-is-infiltrating-slack-and-microsoft-teams-to-target-vulnerable-employees"><u>expanded this technique</u></a> by impersonating workers to ask IT teams to reset passwords or transfer MFA tokens using both Microsoft teams and Slack.</p><p>The hackers even set up fake identities and took part in company teleconferences and remediation and response calls to gather security information.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft warns of rising AitM phishing attacks on energy sector ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/microsoft-warns-of-rising-aitm-phishing-attacks-on-energy-sector</link>
                                                                            <description>
                            <![CDATA[ The campaign abused SharePoint file sharing services to deliver phishing payloads and altered inbox rules to maintain persistence ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Bt6xNvsN2W3SWsSesfhL95</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7F8eeczqdKrpFNsWATj8VL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 23 Jan 2026 11:10:09 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7F8eeczqdKrpFNsWATj8VL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft logo illuminated on the side of a building a night time in Tromso, Norway.]]></media:description>                                                            <media:text><![CDATA[Microsoft logo illuminated on the side of a building a night time in Tromso, Norway.]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft logo illuminated on the side of a building a night time in Tromso, Norway.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7F8eeczqdKrpFNsWATj8VL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The energy sector should be on the alert for a new multi‑stage <a href="https://www.itpro.com/security/cyber-crime/adversary-in-the-middle-attacks-are-becoming-hackers-go-to-method-to-bypass-mfa">adversary‑in‑the‑middle (AitM)</a> campaign, Microsoft has warned.</p><p>Cloud collaboration platforms, particularly Microsoft SharePoint and OneDrive, are popular with threat actors thanks to their widespread presence in enterprise environments. </p><p>They offer built-in legitimacy, flexible file‑hosting capabilities, and authentication flows that attackers can take over and use to hide their presence. </p><p>This latest <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>and <a href="https://www.itpro.com/security/cyber-attacks/what-is-business-email-compromise-bec">business email compromise (BEC)</a> campaign, <a href="https://www.microsoft.com/en-us/security/blog/2026/01/21/multistage-aitm-phishing-bec-campaign-abusing-sharepoint/" target="_blank">Microsoft said</a>, abused SharePoint file sharing services to deliver phishing payloads. Emails with the subject line “NEW PROPOSAL – NDA” appeared legitimate, coming from a previously-compromised email address belonging to a trusted organization. </p><p>A number of user accounts have already been compromised, according to the Microsoft Defender Research team. </p><p>Victims clicking on a link included in the email were redirected to a fake login page, which collected their credentials. The attackers also altered inbox rules to mark all emails as "read", making their activity harder to detect. </p><p>They were then able to make use of trusted internal identities from the target to conduct large‑scale phishing attacks, both within the organization and externally, significantly expanding the scope of the campaign. </p><p>In one example, this phishing campaign involved more than 600 emails with a different phishing URL, which were sent to the compromised user’s contacts within and outside the organization, as well as distribution lists. </p><p>The attackers then made further efforts to avoid suspicion.</p><p>"The attacker read the emails from the recipients who raised questions regarding the authenticity of the phishing email and responded, possibly to falsely confirm that the email is legitimate," said the Microsoft team. </p><p>"The emails and responses were then deleted from the mailbox. These techniques are common in any BEC attacks and are intended to keep the victim unaware of the attacker’s operations, thus helping in persistence."</p><h2 id="tackling-adversary-in-the-middle-attacks">Tackling adversary-in-the-middle attacks </h2><p>Microsoft highlighted the operational complexity of AiTM campaigns, saying that password resets alone are not enough to fix the problem. </p><p>Impacted organizations must, said the firm, make sure that they've revoked active session cookies, reversed the changes to MFA settings made by the attacker on the compromised user’s accounts and removed the altered inbox rules. </p><p>"While AiTM phishing attempts to circumvent <a href="https://www.itpro.com/security/cyber-attacks/how-hackers-bypass-mfa-and-what-to-do-about-it">MFA</a>, implementation of MFA still remains an essential pillar in identity security and highly effective at stopping a wide variety of threats. </p><p>MFA is the reason that threat actors developed the AiTM session cookie theft technique in the first place," the team said.</p><p>The researchers also advised organizations to work with their identity provider to ensure security controls like MFA are in place. </p><p>They added: "Organizations should also consider complementing MFA with conditional access policies, where sign-in requests are evaluated using additional identity-driven signals like user or group membership, IP location information, and device status, among others." </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ LastPass issues alert as customers targeted in new phishing campaign ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/lastpass-issues-alert-as-customers-targeted-in-new-phishing-campaign</link>
                                                                            <description>
                            <![CDATA[ LastPass has urged customers to be on the alert for phishing emails amidst an ongoing scam campaign that encourages users to backup vaults. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ijqU7Q6m8qg9BLHKYP63hX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ocP3dX4tjhaXs2GSGBykGh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 21 Jan 2026 10:43:16 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ocP3dX4tjhaXs2GSGBykGh-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[LastPass logo and branding reflected on the internal discs of a hard drive.]]></media:description>                                                            <media:text><![CDATA[LastPass logo and branding reflected on the internal discs of a hard drive.]]></media:text>
                                <media:title type="plain"><![CDATA[LastPass logo and branding reflected on the internal discs of a hard drive.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ocP3dX4tjhaXs2GSGBykGh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/software/368008/lastpass-vs-1password">LastPass</a> has urged customers to be on the alert for phishing emails amidst an ongoing scam campaign. </p><p>The <a href="https://www.itpro.com/software/368049/best-password-managers-for-business">password management</a> firm said emails claiming the site is due to undergo maintenance have been circulating since 19 January. The messages include prompts for customers to backup vaults within the next 24 hours, LastPass revealed. </p><p>"Please be advised that LastPass is NOT asking customers to backup their vaults in the next 24 hours; rather, this is an attempt on the part of a malicious actor to generate urgency in the mind of the recipient, a common tactic for <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> and phishing emails," said the firm in a <a href="https://blog.lastpass.com/posts/new-phishing-campaign-targeting-lastpass-customers" target="_blank"><u>statement</u></a>.</p><div class="product"><a data-dimension112="8f17cc04-2cb5-45e2-a984-eff001d84b39" data-action="Deal Block" data-label="Make Password Security Your New Year's Resolution" data-dimension48="Make Password Security Your New Year's Resolution" href="https://click.linksynergy.com/deeplink?id=kXQk6%2AivFEQ&mid=42966&u1=itpro-gb-1046892004221913649&murl=https%3A%2F%2Fwww.keepersecurity.com%2Fen_GB%2Fnew-year-resolution.html" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://click.linksynergy.com/deeplink?id=kXQk6%2AivFEQ&mid=42966&u1=itpro-gb-1046892004221913649&murl=https%3A%2F%2Fwww.keepersecurity.com%2Fen_GB%2Fnew-year-resolution.html" target="_blank" rel="sponsored" data-dimension112="8f17cc04-2cb5-45e2-a984-eff001d84b39" data-action="Deal Block" data-label="Make Password Security Your New Year's Resolution" data-dimension48="Make Password Security Your New Year's Resolution" data-dimension25="">Make Password Security Your New Year's Resolution</a></p><p>Get 50% off Keeper Personal and Family plans, and 30% off Keeper Business Starter today!<a class="view-deal button" href="https://click.linksynergy.com/deeplink?id=kXQk6%2AivFEQ&mid=42966&u1=itpro-gb-1046892004221913649&murl=https%3A%2F%2Fwww.keepersecurity.com%2Fen_GB%2Fnew-year-resolution.html" target="_blank" rel="nofollow" data-dimension112="8f17cc04-2cb5-45e2-a984-eff001d84b39" data-action="Deal Block" data-label="Make Password Security Your New Year's Resolution" data-dimension48="Make Password Security Your New Year's Resolution" data-dimension25="">View Deal</a></p></div><p>The emails come with several different subject lines, including: </p><ul><li>"LastPass Infrastructure Update: Secure Your Vault Now”</li><li>“Your Data, Your Protection: Create a Backup Before Maintenance”</li><li>“Don’t Miss Out: Backup Your Vault Before Maintenance”</li><li>“Important: LastPass Maintenance & Your Vault Security”</li><li>“Protect Your Passwords: Backup Your Vault (24-Hour Window)”.</li></ul><p>The sender addresses are <em>support@sr22vegas[.]com</em> and support@lastpass[.]server8/server7/server3.</p><p>IPs associated with the campaign include 192.168.16[.]19 and 172.23.182.202, LastPass confirmed.</p><h2 id="how-to-spot-the-fake-lastpass-emails">How to spot the fake LastPass emails</h2><p>The emails claim that a “legacy access” request has been opened – often using alarming language, such as even informing recipients they may be deceased – and include fake case details to appear legitimate. </p><p>Victims are directed to a fraudulent LastPass website that looks like the real thing, hosted at “group-content-gen2.s3.eu-west-3.amazonaws[.]com/5yaVgx51ZzGf”, which then redirects to “mail-lastpass[.]com.” </p><p>Here they are prompted to enter their credentials. In some cases, the attackers also follow up with phone calls to increase pressure. </p><p>“This campaign is designed to create a false sense of urgency, which is one of the most common and effective tactics we see in phishing attacks,” said a spokesperson for the threat intelligence, mitigation, and esalaction (TIME) team at LastPass. </p><p>“We want customers and the broader security community to be aware that LastPass will never ask for their master password or demand immediate action under a tight deadline. We thank our customers for staying vigilant and continuing to report suspicious activity.” </p><h2 id="lastpass-campaign-looks-to-catch-users-off-guard">LastPass campaign looks to catch users off-guard</h2><p>Notably, the campaign was timed for a holiday weekend in the US, probably in the hopes that this would mean reduced staffing levels that could delay detection and draw out response time.</p><p>"Please remember that no one at LastPass will ever ask for your master password. Rest assured, we are working with our third-party partners to have this domain taken down as soon as possible," said the firm. </p><p>"In the meantime, please take the appropriate precautions and, as always, if you are ever unsure whether a LastPass branded email is legitimate, submit it to abuse@lastpass.com."</p><p>The latest advisory marks the <a href="https://blog.lastpass.com/posts/october-13-2025-phishing-campaign"><u>second time</u></a> in six months that LastPass has been forced to put out an alert like this. A <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaign in October 2025 used similar tactics, claiming that the company had been hacked.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hacked London council warns 100,000 households at risk of follow-up scams ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/kensington-and-chelsea-council-cyber-attack-data-breach</link>
                                                                            <description>
                            <![CDATA[ The council is warning residents they may be at increased risk of phishing scams in the wake of the cyber attack. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wZ7G9ZrPZjmFuj5WHFTupd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FAsuGpEyETVLrjxktBXe5B-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 08 Jan 2026 12:04:34 +0000</pubDate>                                                                                                                                <updated>Thu, 08 Jan 2026 13:55:21 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FAsuGpEyETVLrjxktBXe5B-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Fallen leaves pictured on the pavement outside residential townhouses in London&#039;s Kensington Gardens area, part of the Kensington and Chelsea Council district.]]></media:description>                                                            <media:text><![CDATA[Fallen leaves pictured on the pavement outside residential townhouses in London&#039;s Kensington Gardens area, part of the Kensington and Chelsea Council district.]]></media:text>
                                <media:title type="plain"><![CDATA[Fallen leaves pictured on the pavement outside residential townhouses in London&#039;s Kensington Gardens area, part of the Kensington and Chelsea Council district.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FAsuGpEyETVLrjxktBXe5B-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A London council has written to hundreds of thousands of residents to warn them that criminals may use details leaked via a cyber attack last year to target them for scams. </p><p>At the end of November, Kensington and Chelsea was one of a <a href="https://www.itpro.com/security/cyber-attacks/hammersmith-and-fulham-council-cyber-attacks"><u>trio of west London councils that suffered an outage</u></a> that was quickly <a href="https://www.itpro.com/security/cyber-attacks/ncsc-called-in-as-london-councils-grapple-with-cyber-attacks"><u>attributed to a cyber attack</u></a>. </p><p>A week later, the council confirmed that personal <a href="https://www.itpro.com/security/hacking/data-was-likely-leaked-in-council-hack"><u>data was likely leaked</u></a>, though it stressed it was only "historical data". </p><p>Now, a spokesperson for the council has said the attackers had "criminal intent", with the council's <a href="https://www.rbkc.gov.uk/newsroom/we-are-responding-cyber-security-issue" target="_blank"><u>website</u></a> adding that sensitive data and personal information that could impact residents had been accessed by the attackers. </p><p>Council leader Elizabeth Campbell said the "serious" breach required action from the council, with an update in the middle of December saying 100,000 households had already been contacted with warnings following the attack. </p><p>A spokesperson told <em>ITPro </em>the letters were sent out at the beginning of December, and the message references the attack of "two weeks ago". </p><p>"We decided to go out immediately and say to people this is what's happened, this data has been copied and it has been taken and you should be aware therefore you are at risk," she told the <a href="https://www.bbc.co.uk/news/articles/ce3knggd1lwo" target="_blank"><u><em>BBC</em></u></a>. </p><h2 id="written-warning">Written warning</h2><p>In a copy of the letter shared with <em>ITPro </em>by the council, recipients are advised to be wary of scam messages, check online accounts for unusual activity, and report any suspicious activity to the <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a>.</p><p>"Like any local authority, it was always possible that our systems could come under attack and therefore we had invested significantly in our digital, data and technology services over many years," Campbell said in the letter. </p><p>"This meant that we had a cyber defence system that was able to spot this attack quickly and protect much of our infrastructure, and the infrastructure of others, as best as possible."</p><p>Campbell added: "Despite this, we do believe that some data has been copied and taken. It is important to say we still have access to this information, but it is possible a copy could end up in the public domain. As a priority we are checking if this contains any personal or financial details of residents, customers, and service users. This may take months and we will update residents at every step."</p><p>The council is now "going through all the documentation" to spot any specific risks and will contact individuals directly if affected, though it noted that work may take months. </p><p>Similarly, the local authority said it was checking which details in files may have been accessed, admitting that work may yield nothing, but said "we want to make sure we turn over every stone."</p><h2 id="what-happened">What happened</h2><p>The attack began on the morning of 24 November, and was immediately spotted by staff at Kensington and Chelsea, who took steps to isolate systems. </p><p>A week later, that council admitted some data had been accessed, including sensitive information; however, it stressed the data wasn't encrypted by the attackers, such as in a <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>attack, and therefore remained accessible to the council. </p><p>Hammersmith and Fulham Council and Westminster City Council were the other two local authorities hit by the outage, as the three organizations share some systems. </p><p>Hammersmith has said it so far appears its systems were not compromised, while Westminster earlier this month <a href="https://www.bbc.co.uk/news/articles/czrke560ze3o.amp" target="_blank"><u>confirmed</u></a> that "limited data" had been breached. </p><p>Keven Knight, CEO of Talion, told <em>ITPro </em>last year that councils are a prime target for cyber criminals, largely due to the scope of personal and financial information they hold on residents.</p><p>"This is the type of information that can’t be changed easily. This means it's now in the hands of a threat actor, and victims will be exposed to an increased risk of <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a>," he said.</p><p>The <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner's Office (ICO)</a> has been informed of the incident, and the Metropolitan Police and NCSC are investigating. So far, there's no indication who is behind the attack. </p><p>"The Met is leading an investigation and we are working alongside them with the national cyber security centre and the NCC Group," a spokesperson for Kensington and Chelsea council said. </p><p>"We are taking steps to work through the data in accordance with ICO and legal rules."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Phishing kits soared in popularity last year as rookie hackers ramped up DIY cyber attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/phishing-as-a-service-kits-growth-2025-barracuda</link>
                                                                            <description>
                            <![CDATA[ As PhaaS kits increase in sophistication, organizations should be on the alert ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TxzYZV9miajXYFXsXXBgFZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iLr5eH4Tgk7GAiwMDELMzG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 08 Jan 2026 11:03:07 +0000</pubDate>                                                                                                                                <updated>Thu, 08 Jan 2026 11:03:59 +0000</updated>
                                                                                                                                            <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iLr5eH4Tgk7GAiwMDELMzG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing email attack concept image showing email with warning symbol on a laptop screen with a fishing hook attached.]]></media:description>                                                            <media:text><![CDATA[Phishing email attack concept image showing email with warning symbol on a laptop screen with a fishing hook attached.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing email attack concept image showing email with warning symbol on a laptop screen with a fishing hook attached.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iLr5eH4Tgk7GAiwMDELMzG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The number of known <a href="https://www.itpro.com/security/cyber-security/368284/what-is-phishing-as-a-service-phaas">Phishing as a Service (PhaaS)</a> kits doubled last year, according to new research, with enterprises warned about a looming onslaught of social engineering attacks in 2026 and beyond. </p><p>Across the year, 90% of high-volume phishing campaigns leveraged PhaaS kits, <a href="https://blog.barracuda.com/2026/01/07/threat-spotlight-phishing-kits-evolved-2025" target="_blank"><u>researchers at Barracuda found</u></a>. These make it easier for lower-level cyber criminals to access advanced tools to wage large-scale attacks. </p><p>The new kits are sophisticated, evasive, and stealthy, Barracuda noted, with <a href="https://www.itpro.com/security/phishing/whisper2fa-phishing-attacks-microsoft-365-barracuda">Whisper 2FA</a> and GhostFrame introducing inventive and evasive tools and tactics, including a suite of techniques to prevent analysis of their malicious code.</p><p>Established groups in this space, such as Mamba and Tycoon, continued to evolve and thrive. Each kit was behind millions of attacks, with 10 million Mamba 2FA attacks in late 2025 alone.</p><p>The main tools were multi-factor authentication (MFA) bypass and URL obfuscation techniques, both seen in 48% of attacks. Attackers also added open redirects and human verification steps, making <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>URLs appear authentic and harder to block.</p><p>Polymorphic techniques and the use of <a href="https://www.itpro.com/security/hackers-are-stepping-up-qishing-attacks-by-hiding-malicious-qr-codes-in-pdf-email-attachments">malicious QR codes</a> were each seen in around 20% of attacks, and malicious attachments in 18%. </p><p>Crucially, researchers warned attackers have now begun splitting QR codes into multiple images or nesting malicious codes within or around legitimate ones to evade detection by email security tools. </p><p>“Phishing kits shifted up another level in 2025 as they increased in number and sophistication, bringing advanced, full-service attack platforms to even less-skilled cybercriminals and enabling them to launch powerful attacks at scale,” said Ashok, Sakthivel, director of software engineering at Barracuda.</p><h2 id="phishing-lures-remain-largely-unchanged">Phishing lures remain largely unchanged</h2><p>While techniques may have evolved, the main phishing lures have remained broadly the same – fake payments, financial, legal, digital signature, and HR-related messages. </p><p>One-in-five emails related to payment and invoices scams, the Barracuda study found. Digital signature and document review emails accounted for 18% of attacks, with HR-related documents featuring in 13%. </p><p>Many exploited trusted brand names, <a href="https://www.itpro.com/security/phishing/how-hackers-are-using-legitimate-tools-to-distribute-phishing-links">mimicking websites and logos</a>, including Microsoft, DocuSign, and SharePoint with increasing accuracy. </p><p>New kits include Sneaky 2FA, an advanced phishing kit leveraging adversary-in-the-middle (AitM) techniques to bypass two-factor authentication, and CoGUI, a sophisticated kit designed with advanced evasion and anti-detection capabilities. </p><p>The latter of these is commonly used by Chinese-speaking threat actors, Barracuda noted. </p><p> “The kits feature techniques designed to make it harder for users and security teams to detect and prevent fraud," said Sakthivel. </p><p>"To stay protected, organizations need to move past static defenses and adopt layered strategies: user training, phishing-resistant MFA, continuous monitoring, and to ensure email security sits at the heart of an integrated, end-to-end security strategy.” </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Warning issued as surge in OAuth device code phishing leads to M365 account takeovers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/warning-issued-as-surge-in-oauth-device-code-phishing-leads-to-m365-account-takeovers</link>
                                                                            <description>
                            <![CDATA[ Successful attacks enable full M365 account access, opening the door to data theft, lateral movement, and persistent compromise ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KvYoW3sdJ4wDkctJHg82bk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cH6m7NRbNRSksBtYe4xHVH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 22 Dec 2025 10:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cH6m7NRbNRSksBtYe4xHVH-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft 365 logo pictured on a smartphone with Microsoft logo pictured in background.]]></media:description>                                                            <media:text><![CDATA[Microsoft 365 logo pictured on a smartphone with Microsoft logo pictured in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft 365 logo pictured on a smartphone with Microsoft logo pictured in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cH6m7NRbNRSksBtYe4xHVH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/28133/what-is-cyber-security">Cybersecurity </a>researchers at Proofpoint have issued a warning over a surge in Microsoft 365 account takeovers through <a href="https://www.itpro.com/security/369985/hackers-target-business-cloud-abusing-microsofts-verified-publisher-status">abuse of OAuth</a> device code authorization.</p><p>This legitimate Microsoft login process is now being weaponized by both cyber criminal and state-aligned actors, who are tricking users into entering a device code on Microsoft’s real login page - instantly granting unauthorized access.</p><p>Proofpoint said the trend signals a major evolution in phishing, shifting attacks away from passwords and towards abusing trusted authentication flows.</p><p>Attacks start with an initial message containing a URL embedded behind a button, as hyperlinked text, or within a <a href="https://www.itpro.com/security/hackers-are-stepping-up-qishing-attacks-by-hiding-malicious-qr-codes-in-pdf-email-attachments">QR code</a>. Once visited, it initiates an attack sequence leveraging the legitimate Microsoft device authorization process. </p><p>The user is presented with a device code with the claim that it's a one-time password (OTP). The user is directed to input the code at Microsoft’s verification URL - and once this is done, the original token is validated, giving the threat actor access to the targeted <a href="https://www.itpro.com/desktop-software/19337/office-365-review">Microsoft 365</a> account.  </p><p>"While this is not necessarily a novel technique, it is notable to see it used increasingly by multiple threat clusters including a tracked cybercriminal threat actor, TA2723," the researchers said. </p><p>"Proofpoint threat researchers have identified a malicious application for sale on hacking forums, which could be used for this type of campaign."</p><p>Meanwhile, some red team tools, such as Squarephish and SquarephishV2, can be used for this type of attack, helping to mitigate the short-lived nature of device codes and enabling larger campaigns than were previously possible. </p><p>In one example, researchers identified a campaign that used a shared document reminder alert to trick users into clicking a Google Share URL hyperlinked as text, to access a fictitious document called “Salary Bonus + Employer Benefit Reports 25”. </p><p>The URL leads to an attacker-controlled website with a domain localized according to browsing IP, and showing the targeted company branding. </p><p>Thereafter, the website prompts the user to input their email address and go through an authentication process that includes a code that, when input into the Microsoft-provided OAuth page, gives the threat actor access to the user’s Microsoft 365 account.</p><p>Proofpoint ascribes this activity to TA2723, a financially-motivated, high-volume credential <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>threat actor notable for its campaigns spoofing Microsoft OneDrive, LinkedIn, and DocuSign. It's seen the group conducting OAuth device code phishing since October. </p><p>But the technique is in use by other state-aligned actors, too, including UNK_AcademicFlare. </p><p>Since September, the Russia-linked group has been using compromised email addresses belonging to multiple government and military organizations to target bodies within government, think tanks, and the higher education and transportation sectors in the US and Europe. </p><p>Earlier this year, Volexity <a href="https://www.volexity.com/blog/2025/02/13/multiple-russian-threat-actors-targeting-microsoft-device-code-authentication/" target="_blank"><u>said</u></a> it had identified several campaigns using the same techniques and carried out by Russian actors. </p><p>The company said it believed that at least one was CozyLarch - overlapping with DarkHalo, APT29, <a href="https://www.itpro.com/security/cyber-attacks/sneak-and-peek-midnight-blizzard-attack-highlights-worrying-flaws-in-microsoft-security-processes">Midnight Blizzard,</a> and CozyDuke. It said it was tracking the remaining activity under UTA0304 and UTA0307.</p><p>Proofpoint expects the abuse of OAuth authentication flows to continue to grow, with the adoption of FIDO compliant MFA controls. Organizations should strengthen their OAuth controls and educate users about these evolving threats. </p><p>"From the use of malicious OAuth applications for persistent access to the abuse of legitimate Microsoft authentication flows with device codes, "threat actors’ tactics to achieve account takeover are evolving with quick adoption across the threat landscape," the researchers said.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Complacent Gen Z and Millennial workers are more likely to be duped by social engineering attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/complacent-gen-z-and-millennial-workers-are-more-likely-to-be-duped-by-social-engineering-attacks</link>
                                                                            <description>
                            <![CDATA[ Overconfidence and a lack of security training are putting organizations at risk ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">487j6euuWzVzHbTfjp59jF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QGJdnzL5ujgBmZvWfYVyk7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 16 Dec 2025 11:00:35 +0000</pubDate>                                                                                                                                <updated>Tue, 16 Dec 2025 11:01:19 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QGJdnzL5ujgBmZvWfYVyk7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ethical hacker concept image showing hands of a female pentester typing on a laptop keyboard.]]></media:description>                                                            <media:text><![CDATA[Ethical hacker concept image showing hands of a female pentester typing on a laptop keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Ethical hacker concept image showing hands of a female pentester typing on a laptop keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QGJdnzL5ujgBmZvWfYVyk7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>While most workers believe they can spot a <a href="https://www.itpro.com/security/cyber-attacks/phishing-tactics-the-top-attacks-trends-in-year">phishing attempt</a>, nearly one-in-four under-35s would fall for a suspicious message if they thought it came from a colleague or boss.</p><p>Four-in-five British workers told Accenture researchers they were confident they'd spot a suspicious message, even though more than a third have never received <a href="https://www.itpro.com/security/cyber-security/354950/10-ways-to-get-employees-invested-in-cyber-security-awareness">cybersecurity training</a>. </p><p>Men show the biggest faith in themselves, being nearly twice as likely as women to report high confidence in spotting cyber threats, at 22% compared with 12%.</p><p>But younger workers in particular may be wrong about this. The survey of over 1,000 British employees found that 15% would share company data or make payments via messaging apps, without verifying the sender, if the message seemed to come from a leader or colleague. </p><p>Among under-35s, so those in the millennial and Gen Z demographics, this rose to nearly a quarter (24%).</p><p>“With cyber criminals weaponizing information from social media to deceive people with realistic messages or calls, employees must make faster judgement calls on what’s real and what’s not," said Kamran Ikram, Accenture’s security lead in the UK and Ireland. </p><p>"The workforce feels cyber confident – though its uneven among men and women – there remains a serious skills and training gap across the board. Being overconfident yet undertrained is a dangerous position to be in."</p><h2 id="more-cybersecurity-training-is-needed">More cybersecurity training is needed</h2><p>Notably, more than one-third (37%) of British workers have never received any <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>training, including 44% of over-55s. Meanwhile, only one-in-five have been trained to recognize <a href="https://www.itpro.com/security/preventing-deepfake-attacks-how-businesses-can-stay-protected">deepfakes </a>or AI-generated phishing emails. </p><p>This lack of training is more significant in smaller companies, where 79% of microbusinesses with less than 10 employees and 55% of small firms with between 10 and 49 employees offer no cybersecurity training at all.</p><p>"Organizations must look to be resilient in every area of their operations and supply chain, which means ongoing education on cyber threats," said Ikram. "Businesses can’t rely on patchy preparedness when attackers are advancing by the day.”</p><p>Even when employees are receiving training, it's not adequately covering all the risks, Accenture found. Half of those that have been trained said they've received no guidance on <a href="https://www.itpro.com/technology/artificial-intelligence/office-workers-lack-the-skills-to-use-generative-ai-tools-safely-and-accurately">using AI safely</a>, such as what data should not be shared with public tools or how to identify AI-enabled attacks.</p><p>As a result, 17% have no awareness of <a href="https://www.itpro.com/security/microsoft-the-uk-is-woefully-unprepared-for-future-ai-cyber-threats">AI-driven cyber threats</a> while only 61% are aware of deepfake videos or AI-generated phishing emails, and fewer than half are aware of voice cloning or identity theft.</p><p>“AI is bringing immense opportunity to business, but it also is changing the risk landscape as criminals increasingly incorporate AI into their arsenal," said Ikram. </p><p>"Today, awareness of AI-enabled attacks is still uneven, and that gap is where the next wave of breaches will likely happen. But more than that - building a cyber-savvy workforce isn’t just about protecting your systems, it’s also what allows innovation and trust to scale together.”</p><p>Workers do at least have a sense of collective responsibility. While a quarter of British employees believe that the IT or security department is most responsible for protecting a company against cyber threats, more than twice as many accept that it's a joint responsibility across the organization.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/is-sector-cyber-awareness-crisis-workforce">Are we in a cyber awareness crisis?</a></li><li><a href="https://www.itpro.com/security/phishing/employee-phishing-training-is-working-but-dont-get-complacent">Employee phishing training is working – but don’t get complacent</a></li><li><a href="https://www.itpro.com/business-strategy/careers-training/358117/the-top-online-cyber-security-courses">Best online cyber security courses</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The Scattered Lapsus$ Hunters group is targeting Zendesk customers – here’s what you need to know ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/the-scattered-lapsus-usd-hunters-group-is-targeting-zendesk-customers-heres-what-you-need-to-know</link>
                                                                            <description>
                            <![CDATA[ The group appears to be infecting support and help-desk personnel with remote access trojans and other forms of malware ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">yA82eDy5m43beT5ptyrzhG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KfsCD25eUDMdmZevdnb6rU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 27 Nov 2025 11:45:15 +0000</pubDate>                                                                                                                                <updated>Thu, 27 Nov 2025 11:46:02 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KfsCD25eUDMdmZevdnb6rU-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Zendesk logo and branding pictured on a smartphone screen. ]]></media:description>                                                            <media:text><![CDATA[Zendesk logo and branding pictured on a smartphone screen. ]]></media:text>
                                <media:title type="plain"><![CDATA[Zendesk logo and branding pictured on a smartphone screen. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KfsCD25eUDMdmZevdnb6rU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Scattered Lapsus$ Hunters threat group appears to be targeting <a href="https://www.itpro.com/business/marketing-and-comms/how-lush-aligned-its-disjointed-customer-support-operations">Zendesk </a>users in a new <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaign, according to analysis from ReliaQuest.</p><p>The security firm <a href="https://reliaquest.com/blog/zendesk-scattered-lapsus-hunters-latest-target/" target="_blank"><u>said</u></a> it has spotted Zendesk-related infrastructure, including more than 40 typosquatted domains and URLs impersonating the company, created over the last six months. </p><p>These domains aim to mimic organizations’ Zendesk environments and host phishing pages, researchers warned. </p><p>"These domains, such as znedesk[.]com or vpn-zendesk[.]com, are clearly designed to mimic legitimate Zendesk environments. Some host phishing pages, like fake <a href="https://www.itpro.com/security/single-sign-on-sso/361728/what-is-single-sign-on-sso">single sign-on (SSO)</a> portals that appear before Zendesk authentication," said ReliaQuest. </p><p>"It’s a classic tactic probably aimed at stealing credentials from unsuspecting users. We also identified Zendesk-related impersonating domains that contained multiple different organizations’ names or brands within the URL, making it even more likely that unsuspecting users would trust and click on these links."</p><p>The domains shared several registry details: registration through NiceNic, US and UK registrant contact information, and Cloudflare-masked nameservers. </p><p>"These elements are reminiscent of the recent Scattered Lapsus$ Hunters campaign that targeted customer relationship management platform Salesforce in August 2025," ReliaQuest said. </p><p>"The domains we uncovered while investigating the August campaign shared similarities with the Zendesk domains: formatting, registry characteristics, and the use of deceptive SSO portals." </p><h2 id="be-wary-of-fraudulent-zendesk-tickets">Be wary of fraudulent Zendesk tickets</h2><p>Meanwhile, ReliaQuest said it has observed fraudulent tickets being submitted to legitimate Zendesk portals operated by organizations using the software for customer service. </p><p>Pretexts include urgent system administration requests or fake password reset inquiries, and the aim is to infect support and help-desk personnel with <a href="https://www.itpro.com/security/30081/what-is-a-trojan-virus">remote access trojans (RATs)</a> and other forms of <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>.</p><p>In September, Scattered Lapsus$ Hunters targeted the communication platform Discord, accessing its Zendesk-based support system and exfiltrating a large number of names, email addresses, billing information, IP addresses, and government-issued IDs.</p><p>A message posted on a Telegram channel associated with the group in November claimed: "Wait for 2026, we are running 3-4 campaigns atm." </p><p>Another read: "all the IR (incident response) people should be at work watching their logs during the upcoming holidays till January 2026 bcuz #ShinyHuntazz is coming to collect your customer databases."</p><p>ReliaQuest said organizations should handle customer support platforms with the same level of security as their own core infrastructure.  </p><p>"ReliaQuest anticipates that SLSH, or copycat threat actors, will likely continue abusing Zendesk and similar customer support platforms — typically monitored less rigorously than inbound email traffic — to access downstream customers' sensitive data and credentials," said the firm. </p><p>"These platforms now warrant equivalent security controls to core infrastructure, particularly since SLSH operates multiple, concurrent attack paths, i.e. external phishing domains coupled with internal ticket injection."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/crowdstrike-insider-attack-wake-up-call">If you're not taking insider threats seriously, then the CrowdStrike incident should be a big wake up call</a></li><li><a href="https://www.itpro.com/security/cyber-crime/scattered-spider-group-marks-and-spencer">Scattered Spider: Who are the alleged hackers behind the M&S cyber attack?</a></li><li><a href="https://www.itpro.com/security/hackers-behind-jaguar-land-rover-announce-their-retirement-should-we-believe-them">Hackers behind Jaguar Land Rover announce their 'retirement' – should we believe them?</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google wants to take hackers to court ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/google-wants-to-take-hackers-to-court</link>
                                                                            <description>
                            <![CDATA[ You don't have a package waiting for you, it's a scam – and Google is fighting back ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">DDsJH49C7fhTRu7oseXiE6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/yfUArnWfBRPqRCc8yFhuxe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Nov 2025 11:58:15 +0000</pubDate>                                                                                                                                <updated>Thu, 13 Nov 2025 11:58:58 +0000</updated>
                                                                                                                                            <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/yfUArnWfBRPqRCc8yFhuxe-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google logo pictured on a sign on side of the company&#039;s headquarters in Krakow, Poland. ]]></media:description>                                                            <media:text><![CDATA[Google logo pictured on a sign on side of the company&#039;s headquarters in Krakow, Poland. ]]></media:text>
                                <media:title type="plain"><![CDATA[Google logo pictured on a sign on side of the company&#039;s headquarters in Krakow, Poland. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/yfUArnWfBRPqRCc8yFhuxe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Tired of scam messages purporting to have a package for you? So is Google – and it's lawyering up to fight back. </p><p>Google said it is adopting a multifaceted approach to takedown a <a href="https://www.itpro.com/security/cyber-security/368284/what-is-phishing-as-a-service-phaas">phishing as a service</a> (PhaaS) operation known as 'Lighthouse', not only suing those responsible, but backing bipartisan US legislation to take on such scams and rolling out new AI-based tech to protect users. </p><p>"That text message you got about a 'stuck package' from USPS or an 'unpaid road toll'? It’s not just spam. It’s the calling card of a sophisticated, global scam that has swindled victims out of millions of dollars," said Google's general counsel Halimah DeLaine Prado in a <a href="https://blog.google/outreach-initiatives/public-policy/legal-action-and-legislation-fight-scammers/" target="_blank"><u>blog post</u></a>.</p><p>"Bad actors built 'Lighthouse' as a phishing as a service kit to generate and deploy massive '<a href="https://www.itpro.com/security/phishing/361625/what-is-smishing">smishing</a>' (SMS phishing) attacks."</p><p>Those attacks arrive via a text message claiming to have a delivery or warning of an unpaid road toll, with a malicious link where victims are urged to enter their email, banking data, and more. </p><p>According to Google, the Lighthouse operation has impacted over one million victims spanning 120 countries, stealing information on anywhere between 12.7 million and 115 million credit cards in the US alone</p><p>“This represents a five-fold increase in these types of attacks since 2020,” DeLaine Prado noted. </p><p>Google said attacks often make use of legitimate brands and their trademarks on malicious websites, with the tech giant spotting at least 107 website templates using its own branding on fake sign-in screens. </p><h2 id="google-getting-tough-on-scams">Google getting tough on scams</h2><p>Google said it is taking legal action in the hopes of dismantling the "core infrastructure" of the Lighthouse operation. </p><p>"We are bringing claims under the Racketeer Influenced and Corrupt Organizations Act, the Lanham Act, and the Computer Fraud and Abuse Act to shut it down, protecting users and other brands," DeLaine Prado noted. </p><p>The lawsuit is being brought against 25 unnamed people believed to live in China, seeking a restraining order and damages. Of course, given the individuals accused of running Lighthouse are not known, the intent isn't to necessarily target them. </p><p>Instead, Google is also asking <a href="https://www.itpro.com/network-internet/web-hosting/368170/best-web-hosting-services-in-2022">web hosting providers</a> to block Lighthouse associated IP addresses and domains. </p><p>Alongside the lawsuit, Google has thrown its weight behind a trio of bills currently working their way through US Congress: Guarding Unprotected Aging Retirees from Deception (GUARD) Act, Foreign Robocall Elimination Act and Scam Compound Accountability and Mobilization (SCAM) Act. </p><p>Those bills would see the establishment of taskforces to target such scams — and funding to investigate them. </p><p>Legal actions aside, Google said it is also developing tools using <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>to better spot and flag such scams in a bid to better protect users. </p><h2 id="tough-fight-ahead">Tough fight ahead</h2><p>While the actions by Google have been welcomed, one industry expert said such efforts may be like playing whack-a-mole. They might knock one down, but another will just pop up again. </p><p>"Groups like Lighthouse appear regularly, and while legal action can disrupt them, these operations often re-emerge using alternative infrastructures," said Carl Wearn, head of threat intelligence and analysis & future ops at Mimecast. </p><p>"Copycat phishing as a service models will continue to grow, exploiting people’s instinctive trust in familiar digital channels like email and SMS."</p><p>While the increase of these scams – which not only now impersonate delivery firms and toll threats but governments and banks to trick victims – may spark more lawsuits from brands following Google's lead, Wearn said that "lasting impact will depend on public awareness, taking a moment to pause, verify and think before clicking."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/phishing-kits-cyber-crime-dark-web">Cheap cyber crime kits can be bought on the dark web for less than $25</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/phishing-tactics-the-top-attacks-trends-in-year">Phishing tactics: The top attack trends</a></li><li><a href="https://www.itpro.com/security/phishing/employee-phishing-training-is-working-but-dont-get-complacent">Employee phishing training is working – but don’t get complacent</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 77% of security leaders say they'd fire staff who fall for phishing scams, even though they've done the same thing ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/77-percent-of-security-leaders-say-theyd-fire-staff-who-fall-for-phishing-scams-even-though-theyve-done-the-same-thing</link>
                                                                            <description>
                            <![CDATA[ A new report uncovers worrying complacency amongst IT and security leaders ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">se8utRnanCv3BCSK2H2n5N</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6VWtT5jw3HYNZeXsUu7hrV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Oct 2025 13:04:07 +0000</pubDate>                                                                                                                                <updated>Thu, 16 Oct 2025 13:04:45 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6VWtT5jw3HYNZeXsUu7hrV-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Office worker using a desktop computer and clicking on a mouse button.]]></media:description>                                                            <media:text><![CDATA[Office worker using a desktop computer and clicking on a mouse button.]]></media:text>
                                <media:title type="plain"><![CDATA[Office worker using a desktop computer and clicking on a mouse button.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6VWtT5jw3HYNZeXsUu7hrV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>While enterprises place a huge emphasis on educating workers to look out for <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing scams</a>, the worst offenders when it comes to clicking malicious links are actually <a href="https://www.itpro.com/security/security-leaders-report-pressure-from-boards-to-downplay-cyber-risks">security leaders</a> themselves. </p><p>That’s according to new <a href="https://arcticwolf.com/resource/aw/2025-human-risk-behavior-snapshot" target="_blank"><u>research from Arctic Wolf</u></a>, which found that despite three-quarters of IT and security leaders believing their organization wouldn’t fall for a phishing attack, nearly two-thirds click phishing links. </p><p>Notably, one-in-five failed to report falling for a malicious link or phishing email. </p><p>Adam Marrè, senior vice president and <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">chief information security officer (CISO)</a> at Arctic Wolf, said the study highlights a major blind spot and degree of hubris among some security leaders. </p><p>"When leaders are overconfident in their defenses while overlooking how employees actually use technology, it creates the perfect conditions for mistakes to become breaches,” he said. </p><p>Yet despite their own poor record, 77% of IT leaders say they would fire staff who fall for scams, marking not only a double standard but a sharp increase from 66% in 2024. </p><p>More than six-in-ten of IT leaders have changed employees’ access or limited their access as a result of falling victim to phishing scams. </p><h2 id="better-training-and-culture-require-to-stop-phishing-scams">Better training and culture require to stop phishing scams</h2><p>Arctic Wolf said a better strategy to combat the rise of phishing attacks lies in <a href="https://www.itpro.com/security/phishing/employee-phishing-training-is-working-but-dont-get-complacent">more robust training for staff at all levels</a>. Indeed, companies that emphasize corrective training reported an 88% reduction in long-term risk. </p><p>“Terminating employees for falling victim to a phishing attack may feel like a quick fix, but it doesn’t solve the underlying problem," said Marrè. </p><p>"Our research shows that better-trained and better-equipped end users are far less likely to be duped — and when organizations take an education-first approach, nearly nine in ten see positive outcomes."</p><h2 id="attacks-keep-on-coming">Attacks keep on coming</h2><p>The call to action comes at a critical time for enterprises. The number of incidents is surging worldwide, according to Arctic Wolf, with 68% of IT leaders saying their organization suffered a breach in the past year. </p><p>This marks an 8% increase from 2024. More than one-in-ten had more than five breaches, while only 30% reported none.</p><p>Senior leadership teams are a prime target, the study noted, with 39% hit by phishing attempts and 35% facing <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>infections that put high-value accounts at risk.</p><p>The UK, Australia, New Zealand and Ireland saw the steepest year-over-year increases, with the number of incidents in the UK and Ireland rising by 35% year over year, partly because of recent high-profile attacks on retailers. </p><p>"Contributing factors include the sector’s historical reliance on legacy systems, seasonal spikes in consumer activity, and the complexity of managing customer data across distributed environments," the researchers said.</p><p>"While these attacks are serious, they also reflect a broader shift in threat actor behavior toward more opportunistic and scalable methods, making retail a prime target."</p><p>The researchers found that many organizations are neglecting the basics, with only 54% of organizations enforcing <a href="https://www.itpro.com/security/cyber-attacks/how-hackers-bypass-mfa-and-what-to-do-about-it">MFA </a>for all users.</p><p>“Progress comes when leaders accept that human risk is not just a frontline issue but a shared accountability across the organization," said Marrè. </p><p>"Reducing that risk means pairing stronger policies and safeguards with a culture that empowers employees to speak up, learn from errors, and continuously improve.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/phishing-tactics-the-top-attacks-trends-in-year">Phishing tactics: The top attack trends</a></li><li><a href="https://www.itpro.com/security/357406/four-tips-for-building-effective-security-awareness-training">Four tips for implementing effective cybersecurity awareness training</a></li><li><a href="https://www.itpro.com/security/malware/malware-as-a-service-explained-what-it-is-and-why-businesses-should-take-note">Malware as a Service explained</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Been offered a job at Google? Think again. This new phishing scam is duping tech workers looking for a career change ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/been-offered-a-job-at-google-think-again-this-new-phishing-scam-is-duping-tech-workers-looking-for-a-career-change</link>
                                                                            <description>
                            <![CDATA[ A new Google Careers phishing scam is targeting tech workers looking for a change of scenery – here's how to stay safe ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SVYarkCEJVnpoCzah5NkFc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sRnYxWRCtCVXgvACRyiqq8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Oct 2025 07:50:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sRnYxWRCtCVXgvACRyiqq8-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Job application concept image showing woman in a coffee shop updating her CV on a laptop computer.]]></media:description>                                                            <media:text><![CDATA[Job application concept image showing woman in a coffee shop updating her CV on a laptop computer.]]></media:text>
                                <media:title type="plain"><![CDATA[Job application concept image showing woman in a coffee shop updating her CV on a laptop computer.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sRnYxWRCtCVXgvACRyiqq8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Researchers have issued a warning about a new Google Careers <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>scam used by hackers to dupe tech workers looking for a career change. </p><p>Victims receive an '<em>are you open to talk?</em>' message impersonating an outreach email from Google Careers. If they click the link, they’re taken to a landing page designed to look like a Google Careers meeting scheduler and, from there, to the phishing page. </p><p>Detailing the scam in a <a href="https://sublime.security/blog/google-careers-impersonation-credential-phishing-scam-with-endless-variation/" target="_blank">blog post</a>, Sublime Security threat detection engineer Brandon Murphy said the phishing campaign has evolved rapidly in recent weeks, employing more sophisticated techniques to dupe unsuspecting victims. </p><p>"What makes this attack particularly interesting is that it is in active development,” he said. “We have observed threat actors refining and adjusting their tactics and techniques over time, evolving to evade detection."</p><p>The initial message may be sent in a number of languages, including English, Spanish, and Swedish, and purports to come from a talent recruiter or recruiting department.</p><p>It includes a <em>Book a Call</em> button that leads to a URL that also has a hiring-themed subdomain and Google Careers-themed root domain, although they didn't always match the sender’s domain. There are a number of different links in use, Murphy noted. </p><h2 id="how-the-google-careers-scam-works">How the Google Careers scam works</h2><p>In almost all cases, after clicking on the <em>Book a Call</em> button, the target is taken to either a real or impersonated Cloudflare Turnstile page. </p><p>After completing a <a href="https://www.itpro.com/security/cyber-crime/fake-captcha-attacks-surged-in-late-2024-heres-what-to-look-out-for">Captcha</a>, they are directed to a spoofed Google Careers meeting scheduling page, where their name, email address, and phone number are all recorded by threat actors.</p><p>After clicking save & continue, victims are taken to the password phishing phase of the attack, which features a fake login page, as seen in most Google credential phishing attacks.</p><p>While most modern credential phishing attacks typically use <a href="https://www.itpro.com/security/cyber-crime/adversary-in-the-middle-attacks-are-becoming-hackers-go-to-method-to-bypass-mfa">Adversary in the Middle (AITM)</a> infrastructure to automate the validation and theft of credentials, this attack appears to be using a C2 server, Murphy noted. </p><h2 id="what-to-look-out-for">What to look out for</h2><p>With all the variations, there are certain common features of attacks. The phishing messages impersonated Google Careers, but are delivered on non-Google Careers infrastructure, and links to domains that mimic Google branding but are not a legitimate domain.</p><p>These domains are typically newly registered, with the sender and/or links within the message using domains that were registered within the past 30 days. </p><p>Similarly, there's a misalignment between claimed sender identity – Google Careers – and the actual sender domain, which varies.</p><p>As so often with phishing messages, there's a sense of urgency, with job offers coming with vague details, but requiring a call to be scheduled immediately. Messages also use flattering language but are short on the specifics.</p><p>"Adversaries will impersonate trusted sites and services to improve their chances of success," said Murphy.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/business/careers-and-training/how-leaders-can-uncover-hidden-tech-talent">How leaders can uncover hidden tech talent</a></li><li><a href="https://www.itpro.com/business-strategy/careers-training/359789/best-paying-tech-jobs">The highest-paying tech jobs</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/phishing-tactics-the-top-attacks-trends-in-year">Phishing tactics: The top attack trends</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are using a new phishing kit to steal Microsoft 365 credentials and MFA tokens – Whisper 2FA is evolving rapidly and has been used in nearly one million attacks since July ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/whisper2fa-phishing-attacks-microsoft-365-barracuda</link>
                                                                            <description>
                            <![CDATA[ Whisper 2FA is now the third most common Phishing as a Service tool worldwide ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">o2296ByLgWyubbBQFtiSkh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Oct 2025 09:55:00 +0000</pubDate>                                                                                                                                <updated>Wed, 15 Oct 2025 12:57:42 +0000</updated>
                                                                                                                                            <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:description>                                                            <media:text><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security firm Barracuda has issued a warning to <a href="https://www.itpro.com/desktop-software/19337/office-365-review">Microsoft 365</a> users after researchers uncovered a new <a href="https://www.itpro.com/security/cyber-security/368284/what-is-phishing-as-a-service-phaas">Phishing as a Service (PhaaS)</a> tool that’s being used to target millions of accounts. </p><p>Whisper 2FA steals both credentials and MFA tokens while evading detection through complex obfuscation techniques. The tool bears similarities to Salty 2FA, researchers noted, a new PhaaS with a focus on stealing Microsoft 365 credentials reported recently by AnyRun. </p><p>It's a well-obfuscated credential harvester with anti-debugging, anti-analysis, and brand mimicking features. Tracked since July 2025, it has already powered close to a million attacks, making it the third most-common PhaaS after <a href="https://www.itpro.com/security/tycoon-2fa-the-popular-phishing-kit-built-to-bypass-microsoft-and-gmail-2fa-security-protections-just-got-a-major-upgrade-and-its-now-even-harder-to-detect">Tycoon </a>and <a href="https://www.itpro.com/security/cyber-attacks/phishing-kits-cyber-crime-dark-web">EvilProxy</a>.</p><p>Whisper 2FA can steal credentials multiple times through a real-time credential exfiltration loop that's enabled by a web technology known as Asynchronous <a href="https://www.itpro.com/development/30202/what-is-javascript-and-why-should-i-learn-it">JavaScript </a>and XM (AJAX).</p><p>This feature, which speeds up live chat, instant search suggestions and dynamic dashboards, allows websites to update information in real-time without needing to reload the entire page. </p><p>"By combining realistic login flows, seamless user interaction and real-time MFA interception, Whisper 2FA makes it extremely difficult for users and security teams to detect fraud," <a href="https://blog.barracuda.com/2025/10/15/threat-spotlight-stealthy-phishing-kit-microsoft-365" target="_blank">researchers warned</a>.</p><p>"Unlike traditional <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>kits that stop after collecting usernames and passwords, Whisper 2FA goes further. It validates sessions in real time, intercepts MFA codes and uses advanced anti-analysis techniques to avoid detection."</p><h2 id="under-the-hood-of-whisper-2fa">Under the hood of Whisper 2FA</h2><p>Analysts at Barracuda found a wide range of phishing emails leading to Whisper 2FA, many of which were based on well-known, trusted brands and urgent pretexts, including DocuSign, Voicemail, Adobe, and ‘Invoice’.</p><p>Notably, researchers warned the kit is evolving rapidly in both its technical complexity and anti-detection strategies. Barracuda said that random text snippets used in the early versions have been removed, stripping away human-readable hints and making static analysis more difficult.</p><p>Obfuscation has also become denser and multilayered, with repeated Base64 decoding functions – which suggests the original data was encoded into strings of letters, numbers, and symbols several times over.</p><p>Meanwhile, new protections have been added to make it harder for attackers defenders to analyze or tamper with the system. These include tricks to detect and block debugging tools, disabling shortcuts used by developers, and crashing inspection tools by manipulating browser behavior.</p><h2 id="whisper-2fa-is-becoming-harder-to-crack">Whisper 2FA is becoming harder to crack</h2><p>Elsewhere, Barracuda analysts warned there are stronger session-based checks and multi-factor authentication (MFA) exfiltration logic, where tokens and one-time passwords are validated in real time through the attacker’s command-and-control (C2) systems.</p><p>Users of the <a href="https://www.itpro.com/security/cyber-attacks/phishing-tactics-the-top-attacks-trends-in-year">phishing </a>kit can now rely on enhanced checks to instantly validate intercepted login codes and tokens through the attackers’ C2 systems.</p><p>"The Whisper 2FA phishing campaign demonstrates how phishing kits have evolved from simple credential stealers into sophisticated, full-service attack platforms," researchers said.</p><p>"As phishing kits like this continue to evolve, organizations need to move past static defenses and adopt layered strategies: user training, phishing-resistant MFA, continuous monitoring, and threat intelligence sharing. Only then can defenders keep pace with the relentless innovation we’re now seeing in phishing campaigns like Whisper 2FA."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/phishing/employee-phishing-training-is-working-but-dont-get-complacent">Employee phishing training is working – but don’t get complacent</a></li><li><a href="https://www.itpro.com/security/hackers-are-using-microsoft-365-features-to-bombard-enterprises-with-phishing-emails-and-theyve-already-hit-more-than-70-organizations">Hackers are using Microsoft 365 features to bombard enterprises with phishing emails</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/malicious-urls-overtake-email-attachments-as-the-biggest-malware-threat">Malicious URLs overtake email attachments as the biggest malware threat</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft and Cloudflare just took down a major phishing operation ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/microsoft-and-cloudflare-just-took-down-a-major-phishing-operation</link>
                                                                            <description>
                            <![CDATA[ RaccoonO365’s phishing as a service platform has risen to prominence via Telegram ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9mAaawBnYk74K7Jxi4d7dG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GXhsxEguUZLXXPu6ptYrtW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Sep 2025 11:40:27 +0000</pubDate>                                                                                                                                <updated>Thu, 18 Sep 2025 11:40:56 +0000</updated>
                                                                                                                                            <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ rory.bathgate@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LFPWMoCGDVHowHbMpHJZkU.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rory Bathgate is the Features and Multimedia Editor at ITPro, overseeing all in-depth content and case studies. He is a subject expert on artificial intelligence and business networks but in his time at ITPro has also covered a wide range of areas including cyber security and hardware. Throughout his time at ITPro, Rory has charted the rise in popularity of generative AI and specifically companies such as Microsoft, OpenAI, and Google. &lt;/p&gt;&lt;p&gt;Alongside this, he has delved into increasing calls for ethical and responsible AI as global legislators circle the technology, as well as the latest in mobile networking technology, from 5G mmWave to the 3G sunset and how it will affect businesses.&lt;/p&gt;&lt;p&gt;He has provided coverage from high-profile tech conferences such as Dell Technologies World, SuiteWorld, and VMware Explore Europe. His on-the-ground coverage has included live blogs, extensive daily coverage of the most significant announcements, analysis pieces, and podcasts.&lt;/p&gt;&lt;p&gt;Indeed, Rory is also a full-time co-host of the ITPro Podcast alongside Jane McCallion, where he swaps a keyboard for a microphone to discuss the latest learnings in tech. Each week, a guest comes onto the show to discuss topics such as cyber security, productivity, or digital transformation in detail.&lt;/p&gt;&lt;p&gt;Rory has an MA in Eighteenth-Century Studies from King’s College London, as well as a BA in English and American Literature from the University of Kent. He joined ITPro in 2022 as a graduate, after four years in student journalism.&lt;/p&gt;&lt;p&gt;In his free time, Rory enjoys photography and video editing, and can often be found at the cinema or reading a good science fiction paperback.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GXhsxEguUZLXXPu6ptYrtW-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing email attack concept image showing letter symbols being held by dark colored hands.]]></media:description>                                                            <media:text><![CDATA[Phishing email attack concept image showing letter symbols being held by dark colored hands.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing email attack concept image showing letter symbols being held by dark colored hands.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GXhsxEguUZLXXPu6ptYrtW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has announced a significant takedown of RaccoonO365, a popular tool used by hackers to seize Microsoft 365 credentials via phishing.</p><p>The tech giant’s Digital Crimes Unit (DCU) seized 338 domains linked to RaccoonO365, which form the backbone of its <a href="https://www.itpro.com/security/cyber-security/368284/what-is-phishing-as-a-service-phaas"><u>phishing as a service (PhaaS)</u></a> offering used in thousands of attacks worldwide. </p><p>Cloudflare partnered with Microsoft for the takedown, tracking user signups to map out the threat group’s infrastructure and disabling all of its domains.</p><div class="product"><a data-dimension112="43e649ec-cee6-4bd8-90de-00771d270c94" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="43e649ec-cee6-4bd8-90de-00771d270c94" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="43e649ec-cee6-4bd8-90de-00771d270c94" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>The full takedown began on 2 September, with Cloudflare acting in coordination with Microsoft’s seizure of 338 websites associated with the group as authorized in a court order by the Southern District of New York.</p><p>“Cloudflare’s response represents a strategic shift from reactive, single-domain takedowns to a proactive, large-scale disruption aimed at dismantling the actor's operational infrastructure on our platform,” the firm <a href="https://www.cloudflare.com/en-gb/threat-intelligence/research/report/cloudflare-participates-in-global-operation-to-disrupt-raccoono365/" target="_blank"><u>wrote</u></a>.</p><p>“By taking coordinated action in early September 2025, we aim to significantly increase RaccoonO365’s operational costs and send a clear message to other malicious actors: the free tier is too expensive for criminal enterprises.”</p><h2 id="raccono365-s-rise-and-fall">RacconO365’s rise and fall</h2><p>Microsoft designates RaccoonO365 as ‘Storm-2246’, indicating a group under development. It noted that the group has rapidly risen to prominence since June 2024, with its tools directly linked to the theft of at least 5,000 Microsoft credentials, across 94 countries.</p><p>In April, Microsoft Threat Intelligence warned of phishing attacks disguised as enterprise and tax documents, launched against 2,300 US organizations via RaccoonO365.</p><p>As part of the operation, Microsoft’s DCU also identified the group’s leader as Joshua Ogundipe, based out of Nigeria, following the trail of a cryptocurrency wallet the tool’s operators accidentally exposed.</p><p>Steven Masada, assistant general counsel at Microsoft’s DCU, <a href="https://blogs.microsoft.com/on-the-issues/2025/09/16/microsoft-seizes-338-websites-to-disrupt-rapidly-growing-raccoono365-phishing-service/"><u>noted</u></a> that Ogundipe and his fellow group members have made at least $100,000 selling their services on Telegram, with‘RaccoonO365 Suite’ $355 subscriptions for 30 days’ access, or $999 for 90 days.</p><p>RacoonO365 is believed to have 100-200 active subscribers paying in cryptocurrency. Microsoft noted this is enough for hundreds of millions of phishing emails sent per year – and is most likely an underestimate of the full customer figures.</p><p>In a screenshot of the Telegram group <a href="https://www.cloudflare.com/en-gb/threat-intelligence/research/report/cloudflare-participates-in-global-operation-to-disrupt-raccoono365/#coordinating-our-racoono365-disruption" target="_blank"><u>shared</u></a> by Cloudflare, the group advertised how it manages “all tech updates & backend” and offers a “100% clean codebase – no backdoors, no tracking”.</p><p>The tool was centrally managed, with the operators able to roll out new evasion methods or attack campaign strategies without needing to roll out new kits by simply altering a small amount of code.</p><p>Ogundipe is believed by Microsoft to have written the majority of RaccoonO365’s code, which Cloudflare researchers noted includes protections against connections from 17 major security vendors including Microsoft Defender and Proofpoint, reverse proxying to disguise its phishing servers as having legitimate Cloudflare IP addresses.</p><p>Since December 2024, RaccoonO365 had been deploying Cloudflare Worker clusters to obscure its attack infrastructure, expanding its features and growing in sophistication with each deployment.</p><p>By August 2025, the tool was capable of real-time data exfiltration and the group had begun to advertise an AI-powered tool ‘RaccoonO365 AI-MailCheck’.</p><p>Cloudflare had been mitigating individual RaccoonO365 domains based on complaints for some time but partnered with Microsoft after it launched its legal efforts to achieve a broader victory against the group.</p><p>It has now banned all Workers scripts linked to the group, suspended associated user accounts, and placed phishing warnings on banned domains.</p><p>“It’s positive that Microsoft DCU has worked to proactively take down this site, which was clearly putting internet users across the world at serious risk,” said Simon Phillips, CTO of engineering at CybaVerse.</p><p>“Users of RaccoonO365 were offered a ready-made package to send out thousands of phishing emails every day, in a bid to steal Microsoft credentials, with minimal effort.”</p><p>“With everything being ready-made, this lowered the barrier to entry for phishing scammers, offering them a tried and tested package, that would yield results quickly. This would have made the phishing emails far more convincing, with artwork, language and spelling all accurate.”</p><p>Phillips added that stolen credentials are especially effective against victims who reuse passwords across accounts. He cautioned that attackers cut off from PhaaS tools could still turn to the <a href="https://www.itpro.com/security/32117/what-is-the-dark-web"><u>dark web</u></a> to purchase email addresses for <a href="https://www.itpro.com/security/cyber-attacks/credential-theft-has-surged-160-percent-in-2025"><u>AI-powered phishing campaigns</u></a> of their own.</p><p>Microsoft stated that RaccoonO365’s operators will likely attempt to rebuild infrastructure but that it will continue to take legal action to prevent attackers from resuming their operations.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/phishing/employee-phishing-training-is-working-but-dont-get-complacent">Employee phishing training is working – but don’t get complacent</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/phishing-tactics-the-top-attacks-trends-in-year">Phishing tactics: The top attack trends</a></li><li><a href="https://www.itpro.com/security/hackers-are-using-microsoft-365-features-to-bombard-enterprises-with-phishing-emails-and-theyve-already-hit-more-than-70-organizations">Hackers are using Microsoft 365 features to bombard enterprises with phishing emails</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Varonis snaps up AI email security specialist SlashNext ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/acquisition/varonis-snaps-up-ai-email-security-specialist-slashnext</link>
                                                                            <description>
                            <![CDATA[ The vendor will integrate SlashNext’s phishing and social engineering detection capabilities into its Data Security Platform ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">NTm3yWUndWneEkdgKF5KAT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/98R6uA9EGq7B7qGSeGEfcS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 04 Sep 2025 11:30:12 +0000</pubDate>                                                                                                                                <updated>Thu, 04 Sep 2025 11:30:44 +0000</updated>
                                                                                                                                            <category><![CDATA[Acquisition]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/98R6uA9EGq7B7qGSeGEfcS-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Varonis logo and branding pictured on a smartphone screen.]]></media:description>                                                            <media:text><![CDATA[Varonis logo and branding pictured on a smartphone screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Varonis logo and branding pictured on a smartphone screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/98R6uA9EGq7B7qGSeGEfcS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Varonis has announced plans to acquire SlashNext, an <a href="https://www.itpro.com/technology/artificial-intelligence/what-is-ai-native-cloud-and-what-does-it-mean-for-business">AI-native</a> email security vendor that specializes in <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>and <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> detection.</p><p>Founded in 2017 by Atif Mushtaq, one of the main architects behind FireEye’s malware detection technology, SlashNext uses AI to defend organizations from multi-channel phishing attacks.</p><p>The solution will be integrated into Varonis’ Data Security Platform to enable advanced protection against AI-generated threats sent via email, SMS, and messaging services such as WhatsApp, Slack, Zoom, and Microsoft Teams.</p><p>By combining the two offerings, Varonis said it is aiming to deliver a comprehensive platform capable of thwarting threats long before their data is impacted.</p><p>Terms of the transaction were not disclosed in the company’s announcement but <a href="https://www.bloomberg.com/news/articles/2025-09-02/varonis-to-buy-email-security-firm-slashnext-for-150-million" target="_blank"><u>reports</u></a> suggest the deal could total up to $150 million.</p><p>Commenting on the agreement, Varonis co-founder and CEO Yaki Faitelson described the acquisition as a “natural evolution” of the company’s platform, with the move set to “significantly expand” its total addressable market.</p><p>“By connecting the dots between email, identity, and data we will dramatically increase the value of our MDDR service and help customers stop threats in their inbox, where many data breaches begin,” he said.</p><h2 id="varonis-eyes-email-security-gains">Varonis eyes email security gains</h2><p>SlashNext leverages predictive AI models that use techniques such as computer vision, natural language processing, and virtual browsers to protect users against attacks across communication and collaboration platforms.</p><p>The technology identifies characteristics in tone and style to reveal the intent and motive of the attacker before training itself on the core threat as well as possible variations that it self-generates.</p><p>In an independent test of cloud security vendors conducted by The Tolly Group back in 2024, SlashNext was found to demonstrate the highest overall detection accuracy (99%) when compared with its market competitors, and scored a perfect 100% detection rate for business email compromise (BEC) and QR code attacks.</p><p>“At SlashNext, we built a fast, automated solution to stop advanced threats across communication channels,” commented Atif Mushtaq, SlashNext’s founder and CPO. </p><p>“I’m excited to join the Varonis team on their mission to protect the world’s data, giving customers end-to-end protection from the first point of attack to the last."</p><h3 class="article-body__section" id="section-more-from-channelpro"><span>MORE FROM CHANNELPRO</span></h3><ul><li><a href="https://www.itpro.com/security/blackpoint-cyber-and-ninjaone-partner-to-bolster-msp-cybersecurity">Blackpoint Cyber and NinjaOne partner to bolster MSP cybersecurity</a></li><li><a href="https://www.itpro.com/business/acquisition/workday-snaps-up-ai-powered-conversation-recruitment-platform-paradox">Workday snaps up AI-powered conversation recruitment platform</a></li><li><a href="https://www.itpro.com/business/acquisition/okta-acquires-axiom-security-to-enhance-privileged-access-management">Okta acquires Axiom Security to enhance privileged access management</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are abusing ConnectWise ScreenConnect, again ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/watch-out-for-fake-zoom-invites-hackers-are-abusing-connectwise-screenconnect-to-take-over-devices</link>
                                                                            <description>
                            <![CDATA[ A new spear phishing campaign has targeted more than 900 organizations with fake invitations from platforms like Zoom and Microsoft Teams. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aufhxNMDzjp8GwNMjv2ojN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iLr5eH4Tgk7GAiwMDELMzG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 28 Aug 2025 10:10:00 +0000</pubDate>                                                                                                                                <updated>Thu, 28 Aug 2025 11:34:51 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iLr5eH4Tgk7GAiwMDELMzG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing email attack concept image showing email with warning symbol on a laptop screen with a fishing hook attached.]]></media:description>                                                            <media:text><![CDATA[Phishing email attack concept image showing email with warning symbol on a laptop screen with a fishing hook attached.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing email attack concept image showing email with warning symbol on a laptop screen with a fishing hook attached.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iLr5eH4Tgk7GAiwMDELMzG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new spear phishing campaign has targeted more than 900 organizations with fake invitations from platforms like Zoom and Microsoft Teams.</p><p>Analysis from Abnormal.ai shows the campaign involves tricking victims into downloading legitimate remote monitoring and management (RMM) software such as ConnectWise ScreenConnect. </p><p>Thereafter, attackers are able to assume control of end-user devices and extract sensitive information. </p><p>"To manipulate targets into engaging and downloading ScreenConnect, the attackers employ advanced deception techniques built around impressive impersonations and familiar business contexts, effectively creating workflows that align with end-user expectations," researchers said.</p><p>"Specific tactics observed include the utilization of compromised legitimate email accounts, AI-generated phishing components, and strategic URL obfuscation methods, as well as the exploitation of trusted business tools such as file-sharing platforms for hosting malicious links."</p><p>Initial access comes via phishing emails from compromised accounts, disguised as meeting invitations via trusted entities like Zoom and Microsoft Teams. </p><p>Researchers noted the threat actors also incorporate various themes to make these invitations look legitimate, for example, "Meeting Invite - 2024 Tax Organizer".</p><p>Targets are then tricked into installing ScreenConnect through AI-generated landing pages, legitimate file-sharing platforms, direct session links, or executable email attachments.</p><p>Once installed, ScreenConnect gives the attackers remote access capabilities that enable comprehensive system control equivalent to direct access while avoiding detection due to minimal signal activity.</p><p>Attackers then leverage compromised systems for account takeover, including lateral phishing campaigns and credential harvesting. They often use the targetʼs email accounts to target colleagues and business partners with the same techniques.</p><p>"This campaign represents a significant evolution in cybercrime tactics," the researchers said.</p><p>"The weaponization of a legitimate IT administration tool — one designed to grant IT professionals deep system access for troubleshooting and maintenance — combined with <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> and convincing business impersonation creates a multi-layered deception that provides attackers with the dual advantage of trust exploitation and security evasion."</p><h2 id="how-to-stay-safe">How to stay safe</h2><p>Researchers pointed out that the sophisticated and resilient infrastructure supporting these attacks implies a mature criminal ecosystem, with dark web vendors operating like legitimate software providers. </p><p>"The commoditization of advanced attack capabilities —driven by bad actors who profit from widespread tool adoption — has democratized complex cybercrime operations and poses an escalating threat to organizations across all sectors, particularly those with legacy security infrastructure or limited security awareness programs," they said.</p><p>The attackers don't appear to be targeting any particular sector, with a fairly even spread across industries. Most victims were based in the US, with Canadian, Australian and UK organizations also affected.</p><p><a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISOs </a>should deploy AI-powered email security solutions capable of detecting complex <a href="https://www.itpro.com/security/a-new-silent-social-engineering-attack-is-being-used-by-hackers-and-your-security-systems-might-not-notice-until-its-too-late">social engineering</a> attacks that bypass traditional security controls, and establish comprehensive monitoring for legitimate remote access tools, focusing on unauthorized installations and suspicious usage patterns.</p><p>Similarly, researchers urged enterprises to update training programs to address evolving tactics and implement network segmentation and access controls to limit the potential impact of compromised systems with remote access capabilities.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/ransomware/hackers-are-targeting-windows-quick-assist-remote-desktop-features-to-deploy-ransomware">Hackers are targeting Windows Quick Assist remote desktop features to deploy ransomware</a></li><li><a href="https://www.itpro.com/security/ransomware/the-scattered-spider-ransomware-group-is-infiltrating-slack-and-microsoft-teams-to-target-vulnerable-employees">The Scattered Spider ransomware group is infiltrating Slack and Microsoft Teams to target vulnerable employees</a></li><li><a href="https://www.itpro.com/security/clickfix-social-engineering-state-sponsored-hackers">State-sponsored cyber groups are flocking to the 'ClickFix' social engineering technique</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Malicious URLs overtake email attachments as the biggest malware threat ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/malicious-urls-overtake-email-attachments-as-the-biggest-malware-threat</link>
                                                                            <description>
                            <![CDATA[ With malware threats surging, research from Proofpoint highlights the increasing use of off-the-shelf 'phish kits' like CoGUI and Darcula ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MnqNyLFMRRCSCpH4xotVDV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UjWjTqk5HiFp2xWB4yo93k-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 18 Aug 2025 10:11:40 +0000</pubDate>                                                                                                                                <updated>Mon, 18 Aug 2025 10:12:06 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UjWjTqk5HiFp2xWB4yo93k-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Insider threat hacker concept image showing man typing on keyboard in a dimly lit room. ]]></media:description>                                                            <media:text><![CDATA[Insider threat hacker concept image showing man typing on keyboard in a dimly lit room. ]]></media:text>
                                <media:title type="plain"><![CDATA[Insider threat hacker concept image showing man typing on keyboard in a dimly lit room. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UjWjTqk5HiFp2xWB4yo93k-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>There's been a sharp rise in the number of <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>and URL-based attacks over the last year, with <a href="https://www.itpro.com/security/phishing/how-hackers-are-using-legitimate-tools-to-distribute-phishing-links">malicious URLs</a> now being used four-times as often as attachments in email threats.</p><p>Malicious links are embedded in messages, buttons, and even within attachments like PDFs or Word documents to entice clicks that initiate credential phishing or malware downloads.</p><p>According to a <a href="https://www.proofpoint.com/us/resources/threat-reports/human-factor-url-phishing" target="_blank"><u>new report from Proofpoint</u></a>, researchers observed around 3.7 billion URL-based threats over a six month period, highlighting the growing scale of the problem. </p><p>Only 8.3 million of these threats were intended to deliver malware, however, with the most frequently-observed payloads in URL-based campaigns being <a href="https://www.itpro.com/technology/choosing-the-best-rmm-solution-for-your-msp-business">remote monitoring and management (RMM) tools</a> and remote access software (RAS). </p><p>These attacks are getting increasingly difficult for users to identify, Proofpoint noted, with cyber criminals now using advanced <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> techniques and <a href="https://www.itpro.com/technology/artificial-intelligence-ai/370293/ai-detection-tools-vs-generative-ai-arms-race">AI-generated content</a> to create their malicious URLs. </p><p>Not only are they <a href="https://www.itpro.com/security/cyber-attacks/hackers-are-using-pdfs-to-impersonate-big-brands-like-microsoft-and-docusign-in-a-new-threat-campaign">impersonating trusted brands</a>, but also abusing legitimate services, tricking users with fake error prompts and bypassing traditional security by <a href="https://www.itpro.com/security/hackers-are-stepping-up-qishing-attacks-by-hiding-malicious-qr-codes-in-pdf-email-attachments">embedding threats in QR codes</a> and SMS messages.</p><p>"URL-based phishing threats are no longer confined to the inbox, they can be carried out anywhere and are often extremely difficult for people to identify,” said Selena Larson, senior threat intelligence analyst at Proofpoint.</p><h2 id="new-techniques-are-paying-off-for-hackers">New techniques are paying off for hackers</h2><p>Some of the URL-based credential phishing campaigns with the highest volumes in the past 12 months have been facilitated by off-the-shelf 'phish kits' like CoGUI and Darcula. </p><p>CoGUI is primarily used by Chinese-speaking threat actors, according to Proofpoint. These high-volume campaigns typically include message counts ranging from the hundreds of thousands to tens of millions at a time, and are mainly used to steal personal details such as credit card numbers.</p><p>Meanwhile, <a href="https://www.itpro.com/security/clickfix-social-engineering-state-sponsored-hackers">ClickFix malware campaigns</a> - a phishing technique that lures users into running malicious code by displaying fake error messages or CAPTCHA screens - are up by nearly 400% year-over-year. </p><p>Malware operators are exploiting the urge to resolve a perceived technical issue, helping them spread remote access trojans (RATs), infostealers and loaders.</p><h2 id="qr-code-and-smishing-threats-are-rising">QR code and smishing threats are rising</h2><p>Proofpoint also identified more than 4.2 million QR code phishing threats in the first half of 2025 alone. In these cases, the main aim of attackers is credential phishing, with 3.7 billion URL-based attacks aimed at stealing logins. </p><p>With phishing lures that impersonate trusted brands and use off-the-shelf tools such as CoGUI and Darcula phish kits, Proofpoint said even low-skilled actors can deploy highly convincing campaigns that bypass multi<a href="https://www.itpro.com/security/forget-mfa-fatigue-attackers-are-exploiting-click-tolerance-to-trick-users-into-infecting-themselves-with-malware">-factor authentication (MFA)</a> and lead to full account takeover.</p><p>The number of smishing campaigns rocketed by 2,534%, as attackers shift their focus to mobile devices - at least 55% of suspected SMS-based phishing messages analyzed by the firm contained malicious URLs, often mimicking government communications or delivery services.</p><p>“From QR codes in emails and fake CAPTCHA pages to mobile-first smishing scams, attackers are weaponizing trusted platforms and familiar experiences to exploit human psychology," said Larson. </p><p>"Defending against these threats requires multi-layered, AI-powered detection and a human-centric security strategy.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/malware/why-malware-as-a-service-is-becoming-a-serious-problem">Why ‘malware as a service’ is becoming a serious problem</a></li><li><a href="https://www.itpro.com/security/malware/developers-face-a-torrent-of-malware-threats-as-malicious-open-source-packages-surge-188-percent">Developers face a torrent of malware threats as malicious open source packages surge 188%</a></li><li><a href="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools">The best malware removal kits for small businesses</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New hires are your weakest link when it comes to phishing attacks – here's how you can build a strong security culture that doesn't judge victims ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/new-hires-are-your-weakest-link-when-it-comes-to-phishing-attacks-heres-how-you-can-build-a-strong-security-culture-that-doesnt-judge-victims</link>
                                                                            <description>
                            <![CDATA[ Research from Keepnet shows new hires are far more likely to fall for phishing attacks – here's how you can improve security awareness during onboarding processes. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cJBoQGagYkR3DvwwpoYpB8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iLr5eH4Tgk7GAiwMDELMzG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Jul 2025 10:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iLr5eH4Tgk7GAiwMDELMzG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing email attack concept image showing email with warning symbol on a laptop screen with a fishing hook attached.]]></media:description>                                                            <media:text><![CDATA[Phishing email attack concept image showing email with warning symbol on a laptop screen with a fishing hook attached.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing email attack concept image showing email with warning symbol on a laptop screen with a fishing hook attached.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iLr5eH4Tgk7GAiwMDELMzG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>New hires are far more likely to fall victim to <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>attacks, according to a recent study, highlighting the need for more robust <a href="https://www.itpro.com/business-strategy/careers-training/358117/the-top-online-cyber-security-courses">security training</a> during onboarding. </p><p>Figures from Keepnet’s 2025 <a href="https://keepnetlabs.com/reports/new-hires-phishing-susceptibility-report" target="_blank"><u><em>New Hires Phishing Susceptibility Report </em></u></a>show new team members are 44% more likely to <a href="https://www.itpro.com/security/phishing/361625/what-is-smishing">click on malicious links</a> compared to more seasoned colleagues. </p><p>Indeed, the study noted that nearly three-quarters (71%) of new hires are duped by phishing scams or <a href="https://www.itpro.com/security/a-new-silent-social-engineering-attack-is-being-used-by-hackers-and-your-security-systems-might-not-notice-until-its-too-late">social engineering techniques</a> within the first three months on the job. </p><div class="product"><a data-dimension112="12c8b16b-1560-4980-a3ee-5c7abf976533" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="12c8b16b-1560-4980-a3ee-5c7abf976533" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="12c8b16b-1560-4980-a3ee-5c7abf976533" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>“New hires pose a high <a href="https://www.itpro.com/security/cyber-security/356585/why-remote-working-isnt-a-cyber-security-risk">cybersecurity risk</a> during onboarding due to their lack of familiarity with <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>processes and limited cybersecurity training, increasing their phishing susceptibility to <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> attacks,” the study warned. </p><p>Among the most common attack types encountered by new hires were CEO impersonation, according to Keepnet, with threat actors specifically targeting inexperienced staff through this method. </p><p>The firm noted that in these instances, new hires typically receive an “urgent email” from a sender impersonating the chief executive requesting they transfer money or divulge sensitive information. </p><p>“They may comply without question because they are unfamiliar with international communications norms,” the study noted. </p><p>These particular types of attacks had a far higher success rate among new hires compared to experienced colleagues. </p><p>Elsewhere, vendor invoicing scams are another common tactic employed against inexperienced members of staff. These once again include requests for payment, except from what appears to be a recognized vendor. </p><p>“New hires in finance or procurement roles who are unfamiliar with standard vendor interactions might approve such payments,” the study warned. </p><h2 id="security-awareness-training-is-critical">Security awareness training is critical</h2><p>The risks faced by new employees, and by default their employers, highlights the need for more robust training during the onboarding process, experts told <em>ITPro</em>. </p><p>Greg Crowley, CISO at eSentire, noted that training “needs to start from day one”. </p><p>“Security awareness should be a core part of onboarding, not an afterthought or something we expect employees to ‘catch up on’ later,” he explained. </p><p>Crowley added that the onboarding process at eSentire focuses heavily on running new hires through the threats they face, as well as company-specific tools and policies. </p><p>In doing so, they become far more comfortable reporting issues and navigating their early days at the company.  </p><p>“Employers need to let them know that it is very common for new hires, just like them, to be targeted by threat actors,” he explained. </p><p>“Tell them specific things to watch out for, such as unexpected text messages claiming to be the CEO or someone senior in the company asking for a favor.” </p><p>Crucially, security awareness training should be “ongoing and engaging” and not a one-time affair, Crowley said.</p><p>“People forget, threats evolve, and attackers get smarter,” he said. “So we ensure that there is recurring security training, we push simulated phishing campaigns, and communicate timely,  real-world threats to the company with reminders on what to look out for and how to report.”</p><p>Masha Sedova, VP, Human Risk Strategy at Mimecast, echoed Crowley’s comments on continuous training strategies - which is a practice she noted often falls flat at enterprises. </p><p>“These findings point to a broader issue with how many organizations approach cybersecurity training,” Sedova said. “For years, awareness efforts have relied on annual modules and phishing simulations that create a false sense of progress.”</p><iframe allow="" height="200px" width="100%" id="" style="" data-lazy-priority="high" data-lazy-src="https://player.captivate.fm/episode/a696c78c-0d94-4bc0-b1cf-106e70c68480/"></iframe><p>“They often treat all employees the same, regardless of role, exposure or previous behavior and that one-size-fits-all approach rarely delivers lasting impact,” Sedova added. </p><p>“Training completion rates may tick the compliance box, but they don’t reflect whether employees are actually making better decisions in the moments that matter.”</p><p>Keepnet advised organizations to implement dedicated security behavior and culture programs for onboarding processes in order to protect new hires. These, the company noted, can reduce risks by up to 30%, at least according to its own offering on this front.</p><p>However, Crowley said that senior employees play an equally important role in helping new hires. This, he told <em>ITPro</em>, is “one of the most underused resources in any organization.”.</p><p>“The influence they have is huge. When senior team members model good security habits — like using password managers, reporting phishing attempts, or being cautious about links — others notice and follow,” he said. </p><p>“Especially for new hires, it's not just the training they remember; it's how their manager or team lead handles this stuff in practice.”</p><p>In fostering a culture of collaboration between new hires and senior staff, Crowley said this helps alleviate the pressure placed on the latter and reduces the “fear of messing up”. </p><p>“We want people to report issues immediately, and seasoned employees who are comfortable saying, ‘hey, I once clicked something bad too — just report it quickly’ help create that psychological safety,” Crowley explained. </p><p>“That culture matters more than any tech control you can put in place.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/hackers-are-using-pdfs-to-impersonate-big-brands-like-microsoft-and-docusign-in-a-new-threat-campaign">Hackers are using PDFs to impersonate big brands in a new threat campaign</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/phishing-tactics-the-top-attacks-trends-in-year">Phishing tactics: The top attack trends</a></li><li><a href="https://www.itpro.com/security/phishing/employee-phishing-training-is-working-but-dont-get-complacent">Employee phishing training is working – but don’t get complacent</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are using Microsoft 365 features to bombard enterprises with phishing emails – and they’ve already hit more than 70 organizations ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hackers-are-using-microsoft-365-features-to-bombard-enterprises-with-phishing-emails-and-theyve-already-hit-more-than-70-organizations</link>
                                                                            <description>
                            <![CDATA[ A new phishing campaign uncovered by researchers at Varonis shows threat actors are abusing Microsoft 365's Direct Send feature to launch phishing attacks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GkZeWAQdAPYkDzGXhHvzZL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GXhsxEguUZLXXPu6ptYrtW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 27 Jun 2025 09:47:23 +0000</pubDate>                                                                                                                                <updated>Fri, 27 Jun 2025 09:47:40 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GXhsxEguUZLXXPu6ptYrtW-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing email attack concept image showing letter symbols being held by dark colored hands.]]></media:description>                                                            <media:text><![CDATA[Phishing email attack concept image showing letter symbols being held by dark colored hands.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing email attack concept image showing letter symbols being held by dark colored hands.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GXhsxEguUZLXXPu6ptYrtW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security experts have warned of a new phishing campaign which exploits <a href="https://www.itpro.com/desktop-software/19337/office-365-review">Microsoft’s 365’s</a> Direct Send feature to steal credentials – and they’ve already hit more than 70 organizations.</p><p>Direct Send is a feature in Exchange Online that allows devices and applications to send emails within a Microsoft 365 tenant. It uses a smart host with a format like "<em>tenantname.mail.protection.outlook.com</em>". </p><p>Intended for internal use only, the feature doesn't require authentication, meaning that attackers don’t need credentials, tokens, or access to the tenant, just a few publicly available details. </p><p>According to <a href="https://www.varonis.com/blog/direct-send-exploit">researchers at Varonis</a>, attackers have been taking advantage of this since May to spoof internal users and deliver <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> emails without ever needing to compromise an account. </p><p>The victims span multiple verticals and locations, but are mainly US-based organizations.</p><p>The attacker used PowerShell to send emails appearing to come from a legitimate internal address via the smart host. Notably, because the email is routed through Microsoft’s infrastructure and appears to originate from within the tenant, it can bypass traditional email security controls. </p><p>Microsoft’s own filtering mechanisms, for example, may treat the message as internal-to-internal traffic, while third-party email security solutions often rely on sender reputation, authentication results, or external routing patterns to flag suspicious messages. </p><p>The Varonis MDDR Forensics team said it has observed multiple instances across different environments where organizations have received alerts for “abnormal behavior: Activity from stale geolocation to the organization.”</p><p>"In one case, the alert was triggered by a Ukrainian IP address, an unexpected and unusual location for the affected tenant," said Tom Barnea, a forensics specialist at Varonis. </p><p>"Typically, alerts tied to abnormal geolocation are accompanied by authentication attempts. This time, however, there were no login events, only email activity. Even more unusual, users were sending emails to themselves with <a href="https://www.itpro.com/operating-systems/microsoft-windows/356552/what-is-windows-powershell">PowerShell</a> as the user agent."</p><h2 id="how-the-phishing-emails-work">How the phishing emails work</h2><p>In one instance recorded by Varonis, emails were designed to resemble voicemail notifications - complete with a PDF attachment that contained a QR code redirecting users to a phishing site designed to harvest Microsoft 365 credentials. </p><p>To stay safe, Varonis recommends that organizations should enable “Reject Direct Send” in the Exchange Admin Center and implement a strict DMARC policy, for example p=reject. </p><p>They should flag unauthenticated internal emails for review or quarantine, enforce “SPF hardfail” within Exchange Online Protection (EOP) and use anti-spoofing policies. </p><p>User education is also important, as is the use of MFA and conditional access policies, in case a user’s credentials are stolen. </p><p>Similarly, organizations should enforce a static IP address in the SPF record to prevent unwanted send abuse, as recommended, but not required, by Microsoft.</p><p>"Direct Send is a powerful feature, but in the wrong hands, it becomes a dangerous attack vector," said Barnea. </p><p>"If you’re not actively monitoring spoofed internal emails or haven’t enabled the new protections, now is the time. Don’t assume internal means safe." </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/phishing/how-hackers-are-using-legitimate-tools-to-distribute-phishing-links">How hackers are using legitimate tools to distribute phishing links</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/phishing-tactics-the-top-attacks-trends-in-year">Phishing tactics: The top attack trends</a></li><li><a href="https://www.itpro.com/security/phishing/employee-phishing-training-is-working-but-dont-get-complacent">Employee phishing training is working – but don’t get complacent</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FIN6 attackers target recruiters with fraudulent resumes ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/fin6-attackers-target-recruiters-with-fraudulent-resumes</link>
                                                                            <description>
                            <![CDATA[ The group's phishing methods protect it from many detection tools, researchers warn ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SaTwmxFXECL6xpADrrDaNb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QiKYok3J9ymuxFszVLW8CM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 11 Jun 2025 09:53:24 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QiKYok3J9ymuxFszVLW8CM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A cyber criminal using a laptop, with a close-up of their hands on the keyboard]]></media:description>                                                            <media:text><![CDATA[A cyber criminal using a laptop, with a close-up of their hands on the keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[A cyber criminal using a laptop, with a close-up of their hands on the keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QiKYok3J9ymuxFszVLW8CM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The FIN6 hacking group, also known as Skeleton Spider, has been spotted impersonating job seekers to target recruiters with malware.</p><p>Contacting recruiters and HR departments on sites such as LinkedIn or Indeed, the group is submitting <a href="https://www.itpro.com/security/cyber-crime/firms-warned-to-beware-of-fake-it-workers">convincing-looking job resumes</a> containing <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> links. These links lead to the applicant's 'personal website', said to contain their resume. The links are given in a 'johnsmith[.]com format.</p><p>"The faulty links are crafted in a way that evades detection and blocking, requiring recipients to type them on their browsers manually," said Andrew Costis, engineering manager of the adversary research team at AttackIQ. </p><p>"The domains are registered anonymously, and come equipped with environmental fingerprinting and behavioral checks to ensure that only the target can open the landing pages."</p><p>In a new <a href="https://dti.domaintools.com/skeleton-spider-trusted-cloud-malware-delivery/">report</a> by DomainTools, researchers identified a number of these domains hosted on AWS infrastructure, including bobbyweisman[.]com, emersonkelly[.]com, and davidlesnick[.]com.  </p><p>"It is likely the actors behind these domains use disposable or fraudulent email addresses, anonymous or foreign IP addresses, and prepaid or stolen payment methods to create and maintain these accounts," the researchers said. </p><p>"Combined with the use of resume-themed domain names and impersonation techniques, this registration strategy allows FIN6 to keep their infrastructure alive just long enough to carry out active phishing campaigns while avoiding rapid takedown by security researchers or registrars."</p><p>The researchers said that, when accessed, the sites often display a professional-looking fake resume, lulling recruiters into a false sense of security. </p><p>Meanwhile, to help them stay under the radar, the attackers use traffic filtering techniques to control who can access the malicious content, with only users appearing to be on residential IP addresses and using common Windows-based browsers allowed to download the malicious document.</p><p>If the visitor is coming via a known <a href="https://www.itpro.com/security/27098/best-vpn-services">VPN</a> service, cloud infrastructure like AWS or corporate security scanners, the site instead delivers a harmless plain-text version of the resume.  </p><p>DomainTools said that one of the group's favorite payloads is more_eggs, a stealthy JavaScript-based backdoor developed by the Venom Spider group, also known as Golden Chickens, and offered as malware-as-a-service.</p><p>The more_eggs malware facilitates credential theft, system access and follow-on attacks, including the use of ransomware. And FIN6 has been using this malware since at least 2018, with Visa <a href="https://usa.visa.com/dam/VCOM/global/support-legal/documents/fin6-cybercrime-group-expands-threat-To-ecommerce-merchants.pdf">warning</a> in 2019 that the group was targeting e-commerce firms, placing skimming malware on their checkout pages.</p><p>"What makes FIN6 a particularly dangerous group is the length of time they've survived and the breadth of different attack tactics they've been observed implementing," said Costis. </p><p>"The group has compromised point-of-sale systems to conduct financial fraud, expanded into ransomware attacks, and most recently used social engineering campaigns to deliver malware-as-a-service JavaScript backdoors for credential theft. This vast pool of experience makes them especially threatening to unprotected data."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 100,000 accounts have been hit in a HMRC scam campaign, but the tax office says it wasn't hacked – here's why ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hmrc-scam-account-campaign</link>
                                                                            <description>
                            <![CDATA[ Organized criminals used phished data to set up dodgy HMRC accounts and demand tax rebates ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8jdVp5LJwTZZ84xo9Vo3xT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xP6A8Prw5RKCLWiZNrCaNT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 05 Jun 2025 11:26:03 +0000</pubDate>                                                                                                                                <updated>Thu, 05 Jun 2025 11:26:13 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xP6A8Prw5RKCLWiZNrCaNT-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[HM Revenue &amp; Customs (HMRC) letter pictured on a table top. ]]></media:description>                                                            <media:text><![CDATA[HM Revenue &amp; Customs (HMRC) letter pictured on a table top. ]]></media:text>
                                <media:title type="plain"><![CDATA[HM Revenue &amp; Customs (HMRC) letter pictured on a table top. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xP6A8Prw5RKCLWiZNrCaNT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK's tax revenue service has lost £47 million in a breach that started last year and impacted 100,000 people. </p><p>The HMRC told the treasury select committee yesterday that the account scam was the result of "organized crime" that set up PAYE, or ‘Pay As You Earn’, accounts for individual taxpayers and used them to claim refunds. </p><p>"This was organized crime phishing for identity data out of HMRC systems, so stuff that banks and others will also unfortunately experience, and then trying to use that data to create PAYE accounts to pay themselves a repayment and/or access an existing account," HMRC CEO John-Paul Marks said, according to media <a href="https://www.theguardian.com/politics/2025/jun/04/100000-uk-taxpayer-accounts-hit-in-47m-phishing-attack-on-hmrc" target="_blank"><u>reports</u></a>. </p><p>The total amount stolen was £47 million, though Marks said that no individual would face any financial loss from the incident. HMRC said that individuals' own money wasn't targeted.. </p><p>"This was an attempt to claim money from HMRC, not an attempt to take any money from you," it said on the <a href="https://www.gov.uk/guidance/unauthorised-access-of-hmrc-online-accounts" target="_blank"><u>HMRC website</u></a>. </p><h2 id="what-happened-2">What happened?</h2><p>The incident appeared to have happened last year, with a subsequent investigation resulting in arrests. It was unclear why the incident is only now being revealed — a point raised by the treasury select committee itself, with Chair Dame Meg Hillier <a href="https://www.bbc.co.uk/news/articles/cvgnz3r2m7eo" target="_blank"><u>offering</u></a> "a word to the wise" to advise parliament of such matters rather than let the committee hear about it from the news. </p><p>HMRC officials stressed that its systems weren't directly attacked nor breached, but instead involved criminals setting up new accounts in the name of people who didn't need a tax account and didn't have one already set up. The criminals did so using information from phishing attacks or elsewhere, according to HMRC. </p><p>However, as the incident was being investigated and addressed, the "nature of the attack altered", said Angela MacDonald, HMRC’s deputy CEO, with the methods used by the attackers evolving throughout time. </p><p>"What has been a challenge in terms of... cleaning the accounts up is being clear that we were then talking to the genuine customer and not in fact talking to the criminal who was on the other end of the account," she added, according to the <a href="https://www.bbc.co.uk/news/articles/cvgnz3r2m7eo"><u><em>BBC</em></u></a>. </p><h2 id="was-hmrc-hacked">Was HMRC hacked?</h2><p>MacDonald said that the incident was "not a cyber attack, we have not been hacked, we have not had data extracted from us." </p><p>She later clarified: "The ability for somebody to breach your systems and to extract data, to hold you to ransomware and all of those things, that is a cyber-attack. That is not what has happened here."</p><p>The clarification seems designed to make clear this incident isn't akin to the recent round of cyber attacks against retailers, which has left <a href="https://www.itpro.com/security/cyber-attacks/m-and-s-customer-personal-data-stolen"><u>M&S struggling to recover</u></a> — though it may also be a reaction to accusations from five years ago that the HMRC was <a href="https://www.itpro.com/security/358028/hmrc-branded-incompetent-following-11-serious-data-breaches"><u>"incompetent" following 11 serious data breaches.</u></a></p><p>However, treasury select committee Chair Dame Meg Hillier didn't <a href="https://www.bbc.co.uk/news/articles/cvgnz3r2m7eo"><u>seem to accept the distinction</u></a>: "Money was got. By criminals. By penetrating the digital system. A lot of people would consider that a cyber crime, however you define it."</p><p>Will Richmond-Coggan, a partner specializing in data and cyber disputes at Freeths LLP, suggested the incident showed the impact of previous attacks. </p><p>“While HMRC were at pains to stress that their own systems had not been compromised in a cyber attack, this incident nonetheless underscores how widespread the consequences of cyber incidents can be," he noted. </p><p>"It is clear from HMRC's explanation that the crime against HMRC was only possible because of earlier <a href="https://www.itpro.com/security/data-breaches">data breaches</a> and cyber attacks. Those earlier attacks put personal data in the hands of the criminals which enabled them to impersonate tax payers and apply successfully to claim back tax."</p><h2 id="what-next">What next?</h2><p>In a statement given to the press, HMRC said it has “acted to protect customers identifying attempts to access a very small minority of tax accounts”. </p><p>The tax office added that it’s currently working with law enforcement agencies in “both the UK and overseas” to find those responsible. </p><p>HMRC said on its website that it had locked down all affected accounts, deleted impacted login credentials, removed any incorrect information from tax records, and checked that no other details were changed. It has also written to affected users to let them know. Letters should arrive over the next three weeks. </p><p>Any individuals seeking to check their account themselves could sign in, head to Settings in their Profile, and view the sign-in history to look for suspicious activity. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/phishing/employee-phishing-training-is-working-but-dont-get-complacent">Employee phishing training is working – but don’t get complacent</a></li><li><a href="https://www.itpro.com/security/this-hacker-group-is-posing-as-it-helpdesk-workers-to-target-enterprises-and-researchers-warn-its-social-engineering-techniques-are-exceptionally-hard-to-spot">This hacker group is posing as IT helpdesk workers to target enterprises</a></li><li><a href="https://www.itpro.com/security/cyber-scams-cost-businesses-1-7-million-per-year-report">Cyber scams cost businesses $1.7 million per year, claims report</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Employee phishing training is working – but don’t get complacent ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/employee-phishing-training-is-working-but-dont-get-complacent</link>
                                                                            <description>
                            <![CDATA[ Educating staff on how to avoid phishing attacks can cut the rate by 80% ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">37z7vZ2GgU3rttv3wGMRRe</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GXhsxEguUZLXXPu6ptYrtW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 15 May 2025 11:22:11 +0000</pubDate>                                                                                                                                <updated>Thu, 15 May 2025 11:22:17 +0000</updated>
                                                                                                                                            <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GXhsxEguUZLXXPu6ptYrtW-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing email attack concept image showing letter symbols being held by dark colored hands.]]></media:description>                                                            <media:text><![CDATA[Phishing email attack concept image showing letter symbols being held by dark colored hands.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing email attack concept image showing letter symbols being held by dark colored hands.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GXhsxEguUZLXXPu6ptYrtW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Increased <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>training is paying dividends for enterprises, according to new research, particularly in larger enterprises. </p><p>Analysis from KnowBe4 shows awareness and resilience are improving based on what it describes as ‘Phish-prone Percentage’ (PPP) metrics. This tracks the percentage of employees likely to fall for social engineering or phishing attacks, the company said. </p><p>According to the firm’s 2025 <a href="https://www.knowbe4.com/hubfs/2025-PIB-UKI-Report_EN-US.pdf"><u><em>Phishing by Industry Benchmarking Report</em></u></a>, organizations have a baseline PPP of around a third worldwide on average - but can improve that dramatically with the right training.</p><p>Globally, PPP drops on average to 19% after three months' training, and to just 4.8% after 12 months. After a year's training, all regions achieved average improvement rates of more than 80%, with North America showing the biggest improvement at 90%, and South America a close second at 89%.</p><p>The highest baseline PPPs were found in South America at 39%, North America at 37%, and Australia and New Zealand at 37%. The most phish-prone of all were organizations with 1,000-plus employees in Australia and New Zealand, with 44.6% happily clicking on simulated phishing hyperlinks. </p><p>The most cautious, meanwhile, were organizations with fewer than 249 employees in both Asia and the United Kingdom and Ireland, where fewer than a quarter of employees clicked the links.</p><p>"The <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>landscape in the UK and Ireland is rapidly evolving, driven by AI advancements, supply chain vulnerabilities, and a shift in how we view the human element in defense," said Javvad Malik, lead security awareness advocate at KnowBe4. </p><p>"AI offers both powerful tools and new risks, while supply chain security has become a critical focus due to its interconnected nature."</p><p>In the UK and Ireland, healthcare and pharmaceuticals, consumer services, and hospitality tend to have a higher initial baseline resilience to phishing attacks, especially in the case of larger organizations.</p><p>Similarly, bigger firms often start with a higher baseline, but show more substantial improvements over time. Researchers suggested this is perhaps because they can afford more comprehensive training resources.</p><p>Notably, KnowBe4 researchers said they have observed a shift in perception, with employers increasingly seeing their staff as a crucial line of defense against cyber threats.</p><p>There's also been a move away from punitive approaches to security training, with organizations now empowering employees to make security decisions and report potential threats without the fear of being penalized.</p><p>"The biggest shift is the growing recognition of employees as an essential line of defense, with organisations now fostering a culture of <a href="https://www.itpro.com/security/cyber-security/354950/10-ways-to-get-employees-invested-in-cyber-security-awareness">cybersecurity awareness</a>," said Malik. </p><p>"While progress is being made, it is clear from the data in the Benchmarking Report that sustained security training is essential to drive long-lasting change."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/malware/fake-file-converter-tools-are-on-the-rise-heres-what-you-need-to-know">Fake file converter tools are on the rise – here’s what you need to know</a></li><li><a href="https://www.itpro.com/security/phishing/device-code-phishing-storm-2372-microsoft">Hackers are using this new phishing technique to bypass MFA</a></li><li><a href="https://www.itpro.com/security/cyber-scams-cost-businesses-1-7-million-per-year-report">Cyber scams cost businesses $1.7 million per year, claims report</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Russian hackers tried to lure diplomats with wine tasting – sound familiar? It’s an update to a previous campaign by the notorious Midnight Blizzard group ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/midnight-blizzard-grapeloader-campaign</link>
                                                                            <description>
                            <![CDATA[ The Midnight Blizzard threat group has been targeting European diplomats with malicious emails offering an invite to wine tasting events, according to Check Point. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gfj5NaQ622X4dJM3a496XK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/N7Ps3tz7EftxHFVrboGb6g-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 06 May 2025 23:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/N7Ps3tz7EftxHFVrboGb6g-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wine tasting concept image showing a man holding up a glass of red wine in a cellar surrounded by barrels. ]]></media:description>                                                            <media:text><![CDATA[Wine tasting concept image showing a man holding up a glass of red wine in a cellar surrounded by barrels. ]]></media:text>
                                <media:title type="plain"><![CDATA[Wine tasting concept image showing a man holding up a glass of red wine in a cellar surrounded by barrels. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/N7Ps3tz7EftxHFVrboGb6g-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Notorious Russian threat group Midnight Blizzard has been mixing up its attack methods in recent months, according to analysis from Check Point, including targeting European diplomats with the lure of luxury events. </p><p>In a <a href="https://research.checkpoint.com/2025/apt29-phishing-campaign/" target="_blank"><u>blog post</u></a> detailing the campaign, researchers said the threat group has been targeting European governments and diplomats since January this year. </p><p>The campaign saw hackers impersonate a “major European Ministry of Foreign Affairs” and target victims with phishing emails inviting them to a wine tasting event. </p><p>Malicious emails curated by the group contained a link to deploy a backdoor dubbed ‘GRAPELOADER’, researchers added. </p><p>“The emails contained a malicious link that led, in some cases, to the download of an archive, eventually leading to the deployment of GRAPELOADER,” the blog post reads. </p><p>“In other cases, the link in the phishing emails redirects to the official website of the impersonated Ministry of Foreign Affairs.”</p><p>The malicious emails in question were sent from two distinct domains, according to Check Point - <em>bakenhof[.]com</em> and <em>silry[.]com</em> - and sought to mimic legitimate communications from a particular individual in the fake Ministry of Foreign Affairs. </p><p>When the target clicks the malicious link, this initiates the download of an archive dubbed <em>‘wine.zip’</em> which sets the next stage of attack in motion. This archive contained three files, including:</p><ul><li>A legitimate PowerPoint executable, ‘wine.exe’, which the group exploited for DLL side loading.</li><li>A hidden DLL, ,AppvIsvSubsystems64.dll’, which researchers said serves as a “required dependency for the PowerPoint executable to run</li><li>Another “hidden and heavily obfuscated” DLL, ppcore.dll, which functions as a loader and used to deliver the payload in later phases of the attack</li></ul><p>Once wine.exe is executed and the GRAPELOADER DLL is side-loaded, researchers explained the malware copies contents of the wine.zip archive to a new location on the device disk. </p><p>“It then gains persistence by modifying the Windows registry’s Run key, ensuring that wine.exe is executed automatically every time the system reboots,” the blog post noted. </p><p>“Next, GRAPELOADER collects basic information about the infected host, such as the host name and username. This collected data is then sent to the Command and Control (C2) server, where it waits for the next-stage shellcode to be delivered.”</p><h2 id="sound-familiar-you-re-not-far-off">Sound familiar? You’re not far off</h2><p>If you’re wondering why this sounds familiar, it’s because a similar campaign has already been carried out by the Midnight Blizzard. </p><p>Last year, the threat group targeted German politicians with fake invitations to a dinner reception using malware dubbed ‘WINELOADER’. This latest campaign, Check Point revealed, is a continuation of that previous flurry of attacks. </p><p>In this instance, GRAPELOADER is designed specifically for the initial stages of an attack. </p><p>“It is primarily used for fingerprinting the infected environment, establishing persistence, and retrieving the next-stage payload,” researchers said. </p><p>Detailed analysis of both show that they share a range of similarities, particularly with regard to code structure, obfuscation techniques, and string decryption processing, the company added. </p><p>Notably, Check Point revealed this particular campaign also included a new variant of WINELOADER being used in conjunction with GRAPELOADER, which suggests “codebase overlaps or shared development tactics”. </p><p>This new variant displayed improved stealth and evasion techniques, which researchers warned will muddle detection efforts. </p><h2 id="midnight-blizzard-doesn-t-quit">Midnight Blizzard doesn’t quit</h2><p>Midnight Blizzard, also known as Cozy Bear, is among the most active and aggressive threat groups operating globally. With links to the Russian government, the group has been identified as the culprit behind a raft of breaches in recent years, including an <a href="https://www.itpro.com/security/cyber-attacks/microsoft-confirms-customer-emails-were-stolen-during-midnight-blizzard-breach"><u>attack on Microsoft</u></a> which saw email communications compromised. </p><p>This particular attack saw the group reportedly use password spraying techniques to compromise a legacy account. In the wake of the incident, Microsoft revealed the group was able to access a “very small percentage” of corporate email accounts.</p><p>Some of these accounts belonged to members of the tech giant’s senior leadership team, as well as staff from its security and legal teams. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/data-breaches/hpe-midnight-blizzard-data-breach-notification">HPE alerts affected staff after Midnight Blizzard breach</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/sneak-and-peek-midnight-blizzard-attack-highlights-worrying-flaws-in-microsoft-security-processes">Sneak-and-peek Midnight Blizzard attack highlights “worrying flaws” in Microsoft security processes</a></li><li><a href="https://www.itpro.com/security/midnight-blizzard-is-on-the-rampage-again-and-enterprises-should-be-wary-of-its-new-tactics">Midnight Blizzard is on the rampage again, and enterprises should be wary of its new tactics</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This hacker group is posing as IT helpdesk workers to target enterprises – and researchers warn its social engineering techniques are exceptionally hard to spot ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/this-hacker-group-is-posing-as-it-helpdesk-workers-to-target-enterprises-and-researchers-warn-its-social-engineering-techniques-are-exceptionally-hard-to-spot</link>
                                                                            <description>
                            <![CDATA[ The Luna Moth hacker group is ramping up attacks on firms across a range of industries with its 'callback phishing' campaign, according to security researchers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">askdj8bRPN3gJq5xf8wMCL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WyQFFy6TAF7mzUvPhASUCd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 06 May 2025 11:29:54 +0000</pubDate>                                                                                                                                <updated>Tue, 06 May 2025 11:29:59 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WyQFFy6TAF7mzUvPhASUCd-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Luna Moth concept image showing cartoon mothman figure with red eyes and wings hovering against the night sky. ]]></media:description>                                                            <media:text><![CDATA[Luna Moth concept image showing cartoon mothman figure with red eyes and wings hovering against the night sky. ]]></media:text>
                                <media:title type="plain"><![CDATA[Luna Moth concept image showing cartoon mothman figure with red eyes and wings hovering against the night sky. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WyQFFy6TAF7mzUvPhASUCd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers are ramping up <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaigns involving fake helpdesk domains to target the legal, financial services, and accounting sectors in the US.</p><p>According to researchers at EclecticIQ, with the help of threat researchers Silent Push, the Luna Moth group - also known as Silent Ransom Group, UNC3753, and Storm-0252 - has carried out a flurry of 'callback phishing' attacks since March this year.</p><p>The group is believed to be linked to the 2021 BazarCall campaign, known for deploying Conti and Ryuk <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a>. However, it's recently turned its focus to data theft and extortion, threatening to expose stolen data on a dedicated leak site and demanding seven-figure ransoms.</p><p>In a <a href="https://blog.eclecticiq.com/from-callback-phishing-to-extortion-luna-moth-abuse-reamaze-helpdesk-and-rmm-tools-against-u.s.-legal-and-financial-sectors?hs_preview=uuwiUNbk-189553948704" target="_blank">blog post</a> detailing the group’s TTP’s, researchers said the campaign begins with a phishing email that lures its victim into calling a fake helpdesk number. Here, live operators posing as IT staff deceive victims into installing remote monitoring and management (RMM) tools. </p><p>These applications, which include Syncro, SuperOps, Zoho Assist, Atera, <a href="https://www.itpro.com/mobile/remote-access/368059/anydesk-review">AnyDesk</a>, and Splashtop won't be flagged by security software as they're legitimate tools, researchers noted. </p><p>However, once installed, they give the attackers access to sensitive data.</p><p>Luna Moth then threatens to leak the data publicly on its own clearweb domain unless the victims pay a ransom of between $1 million and $8 million.</p><p>In order to collect victim data, the attackers have also registered typosquatted domains via GoDaddy, impersonating US firms to collect contact details and enable targeted social engineering. </p><p>Typical examples include <em>[company_name]-helpdesk.com and [company_name]helpdesk.com.</em></p><p>"As of March 2025, EclecticIQ assesses with high confidence that Luna Moth has likely registered at least 37 domains through <a href="https://www.itpro.com/network-internet/web-hosting/368196/godaddy-web-hosting-review">GoDaddy </a>to support its callback-phishing campaigns," researchers said.</p><p>"Most of these domains impersonate <a href="https://www.itpro.com/business/is-there-any-future-for-the-it-helpdesk-ai-and-automation-could-render-it-redundant-within-three-years">IT helpdesk</a> or support portals for major US law firms and financial services firms, using typosquatted patterns."</p><p>One example impersonated a US-based law firm, with a <em>Contact Us</em> form collecting names, emails, and a message from the victim, enabling attackers to identify high-value targets. Another uses a 'CISO Helpdesk’ lure.</p><p>"By impersonating a helpdesk for <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">Chief Information Security Officers (CISOs)</a>, the phishing page leverages the authority and urgency typically associated with executive security communications," said the researchers. </p><p>"This approach is designed to increase victim compliance and maximize the chances of compromising privileged accounts within the target organization."</p><h2 id="luna-moth-tactics-are-hard-to-spot">Luna Moth tactics are hard to spot</h2><p>EclecticIQ warned that Luna Moth’s activities can be hard to spot as no malicious links or attachments appear in the phishing emails. Similarly, victims are installing signed, legitimate software themselves. </p><p>Meanwhile, few security tools can handle voice interactions and activity remains local to the infected machine and network.</p><p>"This slow-paced, trust-based approach slips past both signature-based and behavioral threat detection, revealing a critical blind spot in modern security architectures," they said.</p><p>The best strategy is to lock or restrict installations of Zoho Assist, AnyDesk, and other <a href="https://www.itpro.com/technology/choosing-an-rmm-solution-five-factors-for-msps-to-consider">RMM tools</a> unless they've been explicitly approved, researchers advised. </p><p>Organizations should track the use of RMM tools and file transfer utilities like WinSCP or Rclone for suspicious parameters and execution patterns.</p><p>They should also use email rules to flag messages from impersonated helpdesk domains, and give staff regular training on <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> to help spot spoofed invoices and verify suspicious support requests.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/hackers-are-duping-developers-with-malware-laden-coding-challenges">Hackers are duping developers with malware-laden coding challenges</a></li><li><a href="https://www.itpro.com/security/malware/fake-file-converter-tools-are-on-the-rise-heres-what-you-need-to-know">Fake file converter tools are on the rise – here’s what you need to know</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/why-government-email-servers-are-top-targets-for-state-backed-hackers">Why government email servers are top targets for state-backed hackers</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Healthcare organizations are turning a blind eye to phishing attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/healthcare-organizations-are-turning-a-blind-eye-to-phishing-attacks</link>
                                                                            <description>
                            <![CDATA[ A survey reveals that most attacks go unreported, putting patient data at risk ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zCKUnaWuQZ4KtMKbaUX7jY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GXhsxEguUZLXXPu6ptYrtW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 25 Apr 2025 08:25:33 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GXhsxEguUZLXXPu6ptYrtW-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing email attack concept image showing letter symbols being held by dark colored hands.]]></media:description>                                                            <media:text><![CDATA[Phishing email attack concept image showing letter symbols being held by dark colored hands.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing email attack concept image showing letter symbols being held by dark colored hands.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GXhsxEguUZLXXPu6ptYrtW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The vast majority of phishing attacks against the healthcare sector go unreported to security teams, leaving organizations unable to fully learn from their mistakes.</p><p>In a survey of 150 US-based healthcare IT leaders for secure email firm Paubox, six-in-ten said they had experienced at least one email security breach last year, and three-quarters that they expected even more security challenges this year.</p><p>The top risks were phishing, man-in-the-middle attacks, and password guessing, often through personal information revealed on social media.</p><p>However, IT leaders said 95% of phishing attacks went unreported to security teams, along with 96% of known email violations of the 1996 Health Insurance Portability and Accountability Act (HIPAA), aimed at protecting sensitive health information from disclosure without patient's consent.</p><p>As a result, these incidents weren't investigated, meaning that systems weren’t patched, staff weren’t alerted, and patients weren’t warned that their data may be at risk.</p><p>"We encountered a significant case where an outdated email system directly impacted patient care due to a cybersecurity breach," said Matt Murren, CEO of healthcare IT support firm True North ITG.</p><p>"The <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>attack compromised user credentials and eventually deployed ransomware across the network. It shut systems down for two weeks. Appointments were delayed. Test results were inaccessible. Urgent care cases were diverted elsewhere. Patients lost trust. This isn’t just an IT failure — it’s a patient safety crisis."</p><p>The problem doesn't seem to be a lack of awareness amongst staff. Nine-in-ten said they carried out staff training.</p><p>Ryan Winchester, CareM director of information technology, said "no amount of training can completely eliminate human error, so businesses must have safeguards in place."</p><p>The report found that healthcare organizations currently allocate only 11–20% of their IT budgets to email security, despite email being their top risk area. One persistent problem is poor infrastructure, with 83% of healthcare IT leaders saying that legacy systems disrupt day-to-day operations. </p><p>"I’ve seen first-hand how legacy email platforms can quietly — but critically — undermine operational stability and efficiency across healthcare organizations" said Murren.</p><p>In larger healthcare networks, the most common challenges include high maintenance costs that drain IT resources, persistent security vulnerabilities, outdated and complex user interfaces, system performance bottlenecks, and limited support for mobile and remote working. </p><p>The result is reactive firefighting, with about 37% of healthcare IT leaders spending between 11 and 20 hours per week just resolving secure email tickets. </p><p>"Healthcare doesn’t need more patchwork fixes — it needs a mindset shift. Patients expect secure, convenient communication, and it’s on us to meet that standard," said CEO of Paubox Hoala Greevy.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/phishing/369028/the-it-pro-podcast-are-phishing-tests-a-waste-of-time">Are phishing tests a waste of time?</a></li><li><a href="https://www.itpro.com/security/scams/355013/10-quick-tips-for-identifying-phishing-emails">10 quick tips for identifying phishing emails</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/phishing-tactics-the-top-attacks-trends-in-year">Phishing tactics: The top attack trends</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Phishing kits are a force multiplier': Cheap cyber crime kits can be bought on the dark web for less than $25 – and experts warn it’s lowering the barrier of entry for amateur hackers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/phishing-kits-cyber-crime-dark-web</link>
                                                                            <description>
                            <![CDATA[ Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qsveyM9EvfU5jiXfZRPQk8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6UMt7L8cwrivqQPjJWN3eX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Apr 2025 11:58:06 +0000</pubDate>                                                                                                                                <updated>Fri, 11 Apr 2025 12:03:14 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6UMt7L8cwrivqQPjJWN3eX-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Device code phishing concept image showing cartoon cell phone with a hook attached to a sign-in page. ]]></media:description>                                                            <media:text><![CDATA[Device code phishing concept image showing cartoon cell phone with a hook attached to a sign-in page. ]]></media:text>
                                <media:title type="plain"><![CDATA[Device code phishing concept image showing cartoon cell phone with a hook attached to a sign-in page. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6UMt7L8cwrivqQPjJWN3eX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>While inflation is rising around the world, some things are getting cheaper - and one is the cost of launching a phishing attack.</p><p><a href="https://www.itpro.com/security/29093/what-is-phishing">Phishing</a> kits are now widely available on the <a href="https://www.itpro.com/security/the-dark-web-is-absolutely-awash-with-stolen-data-on-british-mps">dark web</a> and via messaging apps like Telegram, and are often selling for less than $25. </p><p>This means that even criminals with minimal tech skills can easily steal personal information, carry out identity theft and access bank accounts. Meanwhile, <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>infections can lead to the complete loss of device control, enabling cyber criminals to steal files, encrypt sensitive data, or launch <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>attacks.</p><p>"Phishing kits are a force multiplier for cyber crime. They put powerful attack tools into the hands of people who may not have the skills to build them on their own," said Adrianus Warmenhoven, a cybersecurity expert at <a href="https://www.itpro.com/vpns/27145/nordvpn-review">NordVPN</a>. </p><p>"With features like drag-and-drop website builders, email templates, and even contact lists, these kits enable even the least technical attackers to carry out professional-looking scams."</p><h2 id="phishing-as-a-service-is-booming">Phishing as a Service is booming</h2><p>Meanwhile, subscription-based Phishing as a Service (PhaaS) is also on the rise, with these services handling everything from hosting to victim targeting.</p><p>“Phishing kits and PhaaS platforms lower the barrier to entry, so we’re seeing a surge in the number and variety of attacks. That means consumers need to be more alert than ever," said Warmenhoven.</p><p>The research team <a href="https://nordvpn.com/research-lab/online-threats-statistic/"><u>found</u></a> that last year's most commonly impersonated brands in phishing attacks were Google, Facebook, and Microsoft - and that fake URLs imitating these popular platforms are a primary method for cyber criminals to harvest credentials. </p><p>Nearly 85,000 fake Google URLs were discovered last year.</p><p>Similarly, .exe, .zip, .php, .dll and .pdf were the riskiest extensions when downloading files. Video hosting, entertainment and sports, meanwhile, were the domain categories with the most malware.</p><p>According to <a href="https://blog.barracuda.com/2025/03/19/threat-spotlight-phishing-as-a-service-fast-evolving-threat" target="_blank"><u>research</u></a> from Barracuda Networks, the first quarter of this year showed a massive spike in phishing, with more than a million attacks detected by the firm's systems in January and February.</p><p>Tycoon 2FA was the most prominent - and sophisticated - platform, accounting for 89% of incidents in January 2025. Next came EvilProxy, with a share of 8%, followed by a new contender, Sneaky 2FA, with a 3% share of attacks.</p><p>To stay safe, Warmenhoven recommended constantly checking suspicious links for misspellings or inconsistencies before clicking, avoiding free video hosting sites, and enabling multi-factor authentication.</p><p>"Be cautious of unsolicited emails, especially those offering deals or urgent requests. Always verify the legitimacy of files before downloading and use anti-malware tools to scan them," he said.</p><p>"Protect your privacy using tracker blockers to block personal data collection, and ensure your devices are regularly updated to close security vulnerabilities."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-crime/afds-phishing-campaign-microsoft">A new phishing campaign is exploiting Microsoft’s legacy ADFS identity solution to steal credentials and bypass MFA</a></li><li><a href="https://www.itpro.com/security/malware/why-malware-as-a-service-is-becoming-a-serious-problem">Why ‘malware as a service’ is becoming a serious problem</a></li><li><a href="https://www.itpro.com/security/phishing/device-code-phishing-storm-2372-microsoft">Hackers are using this new phishing technique to bypass MFA</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Have I Been Pwned owner Troy Hunt’s mailing list compromised in phishing attack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/have-i-been-pwned-owner-troy-hunts-mailing-list-compromised-in-phishing-attack</link>
                                                                            <description>
                            <![CDATA[ Troy Hunt, the security blogger behind data-breach site Have I Been Pwned, has fallen victim to a phishing attack targeting his email subscriber list. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">DeZk4b24SkqhNduybCNMUS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cNZLBdbFMucebEe8kjq7di-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Mar 2025 08:30:00 +0000</pubDate>                                                                                                                                <updated>Wed, 26 Mar 2025 11:20:43 +0000</updated>
                                                                                                                                            <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ jane.mccallion@futurenet.com (Jane McCallion) ]]></author>                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Wq9nnLr7TNkY8gyBRb7YsA.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Jane is managing editor at ITPro, and its sibling titles Cloud Pro and ChannelPro. She started out with the brands as a staff writer specializing in cloud computing before going on to become senior writer and reports editor, managing the content and creation of ITPro’s quarterly whitepapers. During this time, she broadened her expertise to include cybersecurity, data centers and enterprise IT infrastructure. In 2016, she became features editor, managing a pool of freelance and internal writers, while continuing to specialize in enterprise IT infrastructure, data centers, and business strategy.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;In October 2021, she became the sites’ deputy editor, before moving to the role of managing editor in June 2024. Although she now has a more strategic role, &amp;nbsp;she is still a specialist in enterprise IT infrastructure and business strategy.&lt;/p&gt;
&lt;p&gt;Jane holds an MA in journalism from Goldsmiths, University of London, and a BA in Applied Languages from the University of Portsmouth. She is fluent in French and Spanish, and has written features in both languages.&lt;/p&gt;
&lt;p&gt;Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cNZLBdbFMucebEe8kjq7di-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing concept image showing an email symbol with fishing hook.]]></media:description>                                                            <media:text><![CDATA[Phishing concept image showing an email symbol with fishing hook.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing concept image showing an email symbol with fishing hook.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cNZLBdbFMucebEe8kjq7di-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Troy Hunt, the security blogger behind data breach site <em>Have I Been Pwned</em>, has fallen victim to a <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> attack targeting his email subscriber list.</p><p>In <a href="https://www.troyhunt.com/a-sneaky-phish-just-grabbed-my-mailchimp-mailing-list/" target="_blank"><u>a blog post</u></a> disclosing the incident, Hunt described how the attack took place, with screen shots of the phishing email, which purported to come from his email marketing provider, Mailchimp.</p><p>The trap used a classic <a href="https://www.itpro.com/security/cyber-attacks/phishing-tactics-the-top-attacks-trends-in-year">phishing tactic</a> of including a button that linked to a page with a similar url to the legitimate one – mailchimp-sso.com (now deactivated) versus mailchimp.com. </p><p>Hunt, who said he was “really jet lagged and really tired” at the time entered his credentials and the <a href="https://www.itpro.com/security/cyber-crime/a-cyber-criminal-group-behind-an-mfa-bypass-operation-promised-hackers-profit-within-minutes-theyre-now-facing-lengthy-jail-sentences">one time password (OTP)</a> and the page then hung, rather than loading.</p><p>“Moments later, the penny dropped,” Hunt wrote. “I logged onto the official website, which Mailchimp confirmed via a notification email which showed my London IP address.”</p><p>“I immediately changed my password, but not before I got an alert about my mailing list being exported from an IP address in New York,” he added.</p><p>Hunt himself and others in the industry reacting to the news have said this is an example of how hackers <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">exploit human weaknesses to carry out successful attacks</a>. </p><p>In the case of Hunt, tiredness led to lack of attention, which in turn led to him falling for a phishing scam of the kind he said he would typically have recognized early.</p><p>Erich Kron, security advocate at KnowBe4, said the incident is a prime example of how even a seasoned cybersecurity veteran can fall prey to cyber criminals. </p><p>"<a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">Social engineering</a> is largely getting the right message to the right person at the right time, and that combination can lead to unfortunate situations such as this.”</p><p>Aditi Gupta, principal security consultant at Black Duck, echoed Kron's comments, noting that bad actors deliberately "feed on fear and weaknesses such as tiredness and a sense of urgency" to bait unsuspecting users. </p><p>"This recent phishing attack further highlights that, in the end, we are all humans, and sophisticated phishing attacks could get the best of us." </p><p>Kron commended Hunt, adding that he “deserves kudos” for revealing what had happened to him and using the incident as an opportunity to educate others.</p><p>For his part, Hunt said he has gone through the usual gamut of emotions felt by someone who falls for a scam, including feeling “so stupid” and acknowledged “[his] own foolishness”. </p><p>However, he also hit out at some of Mailchimp's own practices that he claimed are poor in relation to data security. These include not offering phishing-resistant <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication">two factor authentication (2FA)</a> and not automatically deleting unsubscribed email addresses.</p><p>Hunt concluded his blog post by offering his “sincere apologies to anyone impacted by this”, but added that “on balance I think this will do more good than harm and I encourage everyone to share this experience broadly”.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/phishing/device-code-phishing-storm-2372-microsoft">Hackers are using this new phishing technique to bypass MFA</a></li><li><a href="https://www.itpro.com/security/scams/355013/10-quick-tips-for-identifying-phishing-emails">10 quick tips for identifying phishing emails</a></li><li><a href="https://www.itpro.com/security/phishing/how-hackers-are-using-legitimate-tools-to-distribute-phishing-links">How hackers are using legitimate tools to distribute phishing links</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security experts warn of ‘contradictory confidence’ over critical infrastructure threats ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/critical-infrastructure-cyber-threats</link>
                                                                            <description>
                            <![CDATA[ Almost all critical national infrastructure (CNI) organizations in the UK (95%) experienced a data breach in the last year, according to new research. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">heNCYhzyqu24MbBtP54Xgb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WpWQgus5fSc7duCTbNXWAm-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 Mar 2025 10:44:54 +0000</pubDate>                                                                                                                                <updated>Mon, 24 Mar 2025 14:30:09 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WpWQgus5fSc7duCTbNXWAm-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity concept image showing digitized padlock with data points flowing out from behind.]]></media:description>                                                            <media:text><![CDATA[Cybersecurity concept image showing digitized padlock with data points flowing out from behind.]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity concept image showing digitized padlock with data points flowing out from behind.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WpWQgus5fSc7duCTbNXWAm-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Almost all critical national infrastructure (CNI) organizations in the UK (95%) experienced a data breach in the last year, according to new research. </p><p><a href="https://insights.bridewell.com/hubfs/Cyber%20Security%20in%20Critical%20National%20Infrastructure%202025%20Research%20Report.pdf" target="_blank"><u>Analysis </u></a>from Bridewell found that more than half had incurred financial losses of over £100,000 per breach, mostly thanks to <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>upgrades, systems recovery, and increased operational costs.</p><p>Cloud services have become the most targeted attack vector across IT and OT environments in UK CNI sectors, the study found, with web browsing and internet access the second biggest. </p><p>Similarly, data protection remains a big concern, with nine-in-ten organizations worried about meeting compliance requirements.</p><p>The speed of response is the fastest-growing priority, with only 22% of organizations saying they could respond to a ransomware attack within an hour, and 69% within six hours.</p><p>Notably, the study found that while nine-in-ten respondents believe they have a mature <a href="https://www.itpro.com/enterprise-security/34017/who-should-take-ownership-of-your-cyber-security-strategy">cybersecurity strategy</a>, only a quarter are following best practices for cyber risk assessments. </p><p>Confidence in OT security maturity is even lower, with just a third describing their <a href="https://www.itpro.com/security/cyber-attacks/manufacturing-firms-are-struggling-to-handle-rising-ot-security-threats">OT security</a> as 'very mature', compared with 44% for IT security.</p><h2 id="cni-organizations-concerned-about-supply-chain-resilience">CNI organizations concerned about supply chain resilience</h2><p>Despite growing reliance on third-party providers, only 42% of UK CNI organizations said they were 'very confident' in their ability to handle supply chain cyber threats. </p><p>More than half (57%) of respondents experienced a supply chain attack in the past year, with the top three types being firmware attacks, data interception and tampering, and third-party breaches.</p><p>Bridewell CEO Anthony Young said the study highlights the need for critical infrastructure organizations to ramp up their cybersecurity capabilities and boost resilience. </p><p>“As cyber threats continue to evolve, UK CNI organizations must prioritize rapid incident detection and response, as well as bolster their cybersecurity maturity and strengthen resilience against supply chain risk," he said. </p><p>The report highlighted a sharp increase in AI-driven cyber threats, with <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>emerging as the top AI-powered attack vector. Around 83% of respondents specifically highlighted this threat as their top concern in the year ahead. </p><p>"With <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>taking a bigger role in both attacks and defences, organizations must remain proactive to safeguard critical infrastructure and national security, especially in a tumultuous geo-political climate," Young added.</p><h2 id="contradictory-confidence-placing-firms-at-risk">'Contradictory confidence' placing firms at risk</h2><p>Dray Agha, senior manager of security operations at Huntress, said the report makes for worrying reading and urged CNI firms to bolster their defences. </p><p>"A staggering 25% of breached organizations only realized they were compromised when the attacker told them. This highlights critical failures in detection capabilities: organizations need to improve proactive threat hunting, EDR monitoring, and anomaly detection," he said. </p><p>Agha noted that the study also highlighted a “contradictory confidence” among CNI organizations. Around 90% of respondents said they believe their cyber risk assessment practices accurately reflect their security posture, yet 95% suffered breaches. </p><p>This overconfidence suggests many organizations may be relying on outdated or incomplete risk models, failing to assess real-world attack pathways."</p><p>Conversely, Tim Ward, CEO and co-founder of ThinkCyber Security, said the study does showcase signs of improvement. </p><p>Nearly half (40%) of respondents identified employee reporting as a leading method for detecting breaches, he noted, which is encouraging and highlights a growing awareness among staff. </p><p>“Organizations also rate investment in training employees most highly as a practice to counter <a href="https://www.itpro.com/security/cyber-attacks/uk-public-sector-at-risk-from-supply-chain-attacks-new-report-warns">supply chain attacks</a>," Ward added.</p><p>"It is imperative for organizational leaders to seek ways to integrate achieving secure behaviors into the day to day for busy staff, whilst they continue to focus on their day jobs. Approaches such as nudging as risks are encountered, and direct metrics of secure behaviors will be key to increasing resilience in these highly targeted sectors."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/why-attacks-against-critical-national-infrastructure-cni-are-such-a-threat">Why attacks against critical national infrastructure (CNI) are such a threat</a></li><li><a href="https://www.itpro.com/infrastructure/data-centres/data-centers-finally-get-critical-national-infrastructure-designation-in-the-uk">Data centers will now be classed as critical infrastructure in the UK</a></li><li><a href="https://www.itpro.com/security/us-sanctions-chinese-tech-firm-that-targets-critical-infrastructure">US sanctions Chinese tech firm that targets critical infrastructure</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Healthcare organizations need to shake up email security practices ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/healthcare-organizations-need-to-shake-up-email-security-practices</link>
                                                                            <description>
                            <![CDATA[ Microsoft 365 is the source of almost half of all healthcare email breaches, thanks mainly to misconfigurations in security settings. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">93TwYBNZR67ud924vKQoj8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GXhsxEguUZLXXPu6ptYrtW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Mar 2025 10:28:18 +0000</pubDate>                                                                                                                                <updated>Tue, 18 Mar 2025 16:50:07 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GXhsxEguUZLXXPu6ptYrtW-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing email attack concept image showing letter symbols being held by dark colored hands.]]></media:description>                                                            <media:text><![CDATA[Phishing email attack concept image showing letter symbols being held by dark colored hands.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing email attack concept image showing letter symbols being held by dark colored hands.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GXhsxEguUZLXXPu6ptYrtW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/desktop-software/19337/office-365-review">Microsoft 365</a> is the source of almost half of all healthcare <a href="https://www.itpro.com/security/four-in-ten-employees-sacked-over-email-security-breaches-as-firms-tackle-truly-staggering-increase-in-attacks">email breaches</a>, thanks mainly to misconfigurations in security settings. </p><p>According to Paubox’s <a href="https://www.paubox.com/hubfs/Report%20Assets/2025-03-07_REPORT_StateofSecurity.pdf?utm_campaign=Demand%20Gen%20Nurture&utm_source=press_new" target="_blank"><u>2025 </u><u><em>Healthcare Email Security Report</em></u></a>, email is the main attack vector in the sector, with Microsoft 365 accounting for 43% of all breaches.</p><p>Proofpoint was next, at 13%, followed by Barracuda Networks and Mimecast at 7%, and Google Workspace at 3.%. </p><p>The report found that many healthcare organizations are failing to implement fundamental email security protocols, with virtually all breached organizations lacking Mail Transfer Agent Strict Transport Security (MTA-STS) protections and exposing email communications to interception. </p><p>More than a third of Microsoft 365 users had <a href="https://www.itpro.com/security/phishing/359702/what-is-dmarc-and-how-can-it-improve-your-email-security">Domain-based Message Authentication, Reporting, and Conformance (DMARC)</a> in monitor-only mode, meaning a concerning volume of <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> attempts went undetected. </p><p>Notably, researchers found three-in-ten lacked any DMARC records at all. Meanwhile, 12% lacked Sender Policy Framework (SPF) records and four-in-ten had weak configurations, making it easier for attackers to spoof emails.</p><p>“HIPAA-regulated entities need to be proactive in ensuring their compliance with the HIPAA rules, and not wait for OCR to reveal long-standing HIPAA deficiencies," warned HHS Office for Civil Rights (OCR) director Melanie Fontes Rainer.</p><p>According to the report, there's been a 264% increase in <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>attacks on healthcare organizations since 2018, with email acting as the main attack method. </p><p>Shockingly, though, only 1% of the analyzed healthcare organizations had a low-risk email security posture. Three-in-ten were categorized as high risk, meaning they had multiple security gaps that exposed them to major <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>threats. </p><p>According to IBM, the average cost of a healthcare email breach is $9.8 million - and that's before you take  into account HIPAA fines, which amounted to more than $9 million last year.</p><p>These include a $9.76 million settlement by Solara Medical Supplies, after a phishing attack gave hackers access to eight employee email accounts. More than 114,000 patient records were compromised. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="RiC3RruL6cTkMa8n7C2xWh" name="Azure Cost Optimization" caption="" alt="Azure Cost Optimization" src="https://cdn.mos.cms.futurecdn.net/RiC3RruL6cTkMa8n7C2xWh.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: US Cloud)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-computing/azure-cost-optimization"><em>Achieve annual cost savings on Azure Cloud Service</em></a></p></div></div><p>LA Cares was also hit with a $1.3 million fine over systemic security lapses that led to a breach.</p><p>"The increasing frequency and sophistication of cyber attacks in the health care sector pose a direct and significant threat to patient safety," said HHS deputy secretary Andrea Palm.</p><p>"These attacks endanger patients by exposing vulnerabilities in our health care system, degrading patient trust, disrupting patient care, diverting patients, and delaying medical procedures." </p><h2 id="email-attacks-show-no-sign-of-slowing-down">Email attacks show no sign of slowing down</h2><p>Looking ahead, Paubox said it expects to see more attacks on cloud-based email systems, with attackers developing more sophisticated techniques to exploit misconfigurations and bypass existing security measures. </p><p>The use of AI in phishing attacks will also rise, it said.</p><p>As a result, organizations will have to work harder, with more healthcare firms required to move from optional security measures to mandatory enforcement of DMARC and SPF.</p><p>"The data shows that even the most established email security tools are just a starting point in protecting patient data," said Paubox chief compliance officer Rick Kuwahara.</p><p>"To stay compliant, organizations must continuously evaluate their implementations. That can mean adding in additional layers of defense." </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/business-email-compromise-attacks-are-evolving-but-what-can-be-done-about-it">Business email compromise attacks are evolving, but what can be done about it?</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/hackers-are-using-microsoft-teams-to-conduct-email-bombing-attacks">Hackers are using Microsoft Teams to conduct “email bombing” attacks</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/why-government-email-servers-are-top-targets-for-state-backed-hackers">Why government email servers are top targets for state-backed hackers</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google is dropping SMS authentication for QR codes ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/google-is-dropping-sms-authentication-for-qr-codes</link>
                                                                            <description>
                            <![CDATA[ Google appears finally ready to deprecate using SMS codes for multi-factor authentication (MFA) for Gmail according to insiders at the search giant. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UCEDXHknwhEr83pN7eWGzb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KWnuenMsdyFzLapjnaFXAU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Feb 2025 16:30:00 +0000</pubDate>                                                                                                                                <updated>Wed, 26 Feb 2025 15:23:01 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a Staff Writer at ITPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KWnuenMsdyFzLapjnaFXAU-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google logo pictured at the company&#039;s Bay View campus in Mountain View, California.]]></media:description>                                                            <media:text><![CDATA[Google logo pictured at the company&#039;s Bay View campus in Mountain View, California.]]></media:text>
                                <media:title type="plain"><![CDATA[Google logo pictured at the company&#039;s Bay View campus in Mountain View, California.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KWnuenMsdyFzLapjnaFXAU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google appears finally ready to deprecate using SMS codes for multi-factor authentication (MFA) in <a href="https://www.itpro.com/email-providers/24794/gmail-vs-outlookcom-which-one-is-better">Gmail</a>, according to insiders at the search giant.</p><p>On 23 February, <em>Forbes </em><a href="https://www.forbes.com/sites/daveywinder/2025/02/23/google-confirms-gmail-to-ditch-sms-code-authentication/" target="_blank">reported</a> internal sources at Google had revealed the firm made the decision to do away with SMS codes for authentication, with QR codes set to replace them.</p><p>A Google spokesperson said that much like its effort to replace passwords with passkeys, it's looking to move away from SMS authentication in light of a global torrent of cyber attacks abusing SMS-based MFA processes.</p><p>The primary weakness of SMS code authentication is that attackers trigger the MFA process to intercept the one time passcode (OTP) and use this to compromise accounts.</p><p>This can be achieved by tricking victims into revealing their OTPs via social engineering scams, or by taking control of the victim’s phone number via a SIM swapping attack.</p><p>The spokesperson said SMS verification also plays a role in ensuring cyber criminals cannot abuse its services for malicious purposes, but has been exploited in some scams like SIM swapping and traffic pumping.</p><p>Rishi Bhargava, co-founder of Descope, said Google’s decision to finally do away with SMS code authentication as a pivotal moment in the security industry, but considering the process's weaknesses he labelled the move long overdue.</p><p>“Google's decision to abandon SMS authentication is a watershed moment in security, but it's unsurprising, given that SMS has been the weakest link in MFA for years,” he noted.</p><p>Bhargava highlighted that Google also cited traffic pumping, which involves criminals tricking service providers into sending OTPs to premium lines they control thus generating profit each time an SMS verification was generated.</p><p>“While SMS codes are better than no authentication, they are vulnerable to phishing, SIM swapping, and real-time interception attacks that bypass traditional MFA. What's particularly telling is Google citing 'traffic pumping' scams as a key driver - where fraudsters exploit SMS infrastructure for financial gain.”</p><h2 id="google-s-qr-code-switch-set-for-the-near-future-but-fears-remain">Google’s QR code switch set for the ‘near future’, but fears remain</h2><p>Moving forward, when verifying phone numbers Google will be transitioning to using a QR code that the user can scan using their mobile device.</p><p>Firstly, this will significantly reduce an attacker’s ability to trick users into sharing their verification codes as it's far more difficult to share a QR code than a simple six digit number.</p><p>The new verification system will also remove the network providers who can be manipulated in SIM swapping and traffic pumping.</p><p>QR codes are not without their own weaknesses when it comes to cybersecurity. QR code phishing, or ‘qishing’, is an increasingly prevalent attack vector employed by threat actors.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="8gbqQ5wS2WUXaSX2RbTEXZ" name="Build a proactive security strategy" caption="" alt="Build a proactive security strategy" src="https://cdn.mos.cms.futurecdn.net/8gbqQ5wS2WUXaSX2RbTEXZ.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: AWS)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/build-a-proactive-security-strategy" target="_blank"><em>Protect your applications and focus on core business</em></a></p></div></div><p>After Google transitions to QR code verification, cyber attackers may take advantage of the increased usage of the tool and tailor their phishing attack chains to mirror this process.</p><p>In one campaign observed by Trend Micro, threat actors were found distributing a malicious QR code disguised as a two-factor authentication method for ‘documents’ being sent to victims.</p><p>A senior researcher at Trend Micro told <em>ITPro </em>that QR code-based attacks pose a considerable threat as phones often lack many of the security protections that PCs are equipped with and are an easier target to compromise for attackers.</p><p>Google has not given a specific timeframe in which the transition will be made for Google account holders, but added that users should look out for updates from the firm in the ‘near future’.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li>INSERT CONTENT</li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why ‘malware as a service’ is becoming a serious problem ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/why-malware-as-a-service-is-becoming-a-serious-problem</link>
                                                                            <description>
                            <![CDATA[ Researchers have issued a warning over the rise of 'malware as a service' platforms amid a surge in attacks over the last year. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">88BZdeNJiYUjw3wdr39wYe</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/C5CVHQe64yFiVrMZmpFsbQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Feb 2025 13:00:13 +0000</pubDate>                                                                                                                                <updated>Fri, 21 Feb 2025 12:52:13 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a Staff Writer at ITPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/C5CVHQe64yFiVrMZmpFsbQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Close up of yellow networking cables going to a circuitboard]]></media:description>                                                            <media:text><![CDATA[Close up of yellow networking cables going to a circuitboard]]></media:text>
                                <media:title type="plain"><![CDATA[Close up of yellow networking cables going to a circuitboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/C5CVHQe64yFiVrMZmpFsbQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>There was a distinct surge in separate <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a> campaigns delivering the same payload last year, research shows, suggesting hackers are increasingly procuring tools from ‘malware as a service’ platforms.</p><p>The malware as a service model is becoming the dominant mode of cyber attacks as the cyber crime space continues to mature into a <a href="https://www.itpro.com/security/ransomware/359919/ransomware-criminals-look-to-other-hackers-to-provide-them-with-network">lucrative ecosystem</a> for hackers for hire.</p><p>New <a href="https://darktrace.com/resources/annual-threat-report-2024" target="_blank">research</a> from <a href="https://www.itpro.com/business/business-strategy/darktrace-cleared-of-channel-stuffing-claims-by-ey-audit-announces-31-revenue-growth">Darktrace</a> found the malware as a service (MaaS) model was responsible for 57% of all cyber threats detected in the second half of 2024, up 17% from the first half of the year.</p><p>A <a href="https://www.watchguard.com/wgrd-news/press-releases/internet-security-report-q3-2024" target="_blank">report</a> from <a href="https://www.itpro.com/business/acquisition/watchguard-snaps-up-actzero-to-power-mdr-services">WatchGuard</a> also warned it observed an “astronomical surge” in total malware threats in the third quarter of 2024, surpassing 420,000.</p><p>Total <a href="https://www.itpro.com/internet-of-things-iot/33371/iot-malware-threats-ballooned-in-2018https://www.itpro.com/security/stealthy-malware-the-threats-hiding-in-plain-sight">malware threats</a> refers to the number of unique attempts detected on WatchGuard-protected endpoints with any duplicates - those with the same hash are not counted.</p><p>WatchGuard noted this represented a 300% increase on the previous quarter’s figures, which is the largest quarterly rise it has ever observed.</p><p>The report stated that one might conclude this surge was driven by an overall increase in new threats, but WatchGuard found that there was actually an “uncharacteristic decline in new threats”.</p><p>It noted that the results of its telemetry indicate there has been a “flood of homogenous <a href="https://www.itpro.com/security/34784/the-future-of-spam-is-scary">spam</a>-like malware arriving on endpoints, likely separate malware campaigns with the same payload”.</p><p>The report further stated that there are often numerous duplicate malware families from quarter to quarter, but this time there was only one: Glupteba.</p><p>WatchGuard described Glupteba as a multi-faceted malware with various capabilities, such as acting as a <a href="https://www.itpro.com/botnets/1644/what-is-a-botnet">botnet</a>, stealing information, <a href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining">mining cryptocurrency</a>, and loading other malware onto the system.</p><h2 id="malware-as-a-service-rise-propped-up-by-phishing-attacks">Malware as a service rise propped up by phishing attacks</h2><p>Phishing remains the dominant initial access vector used in these attacks, with Darktrace recording over 30.4 million <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> emails targeting its customers between December 2023 and 2024.</p><p>Just under two-fifths (38%) of these emails were targeted <a href="https://www.itpro.com/software/google-docs/361922/researchers-spot-spear-phishing-exploit-in-google-docs">spear phishing</a> attacks tailored for ‘high value individuals’.</p><p>Darktrace noted 32% of the detected <a href="https://www.itpro.com/technology/artificial-intelligence/six-generative-ai-cyber-security-threats-and-how-to-mitigate-them">phishing emails contained AI generated text</a> that displayed some form of ‘linguistic complexity’ such as increased text volume, punctuation, and sentence length.</p><p>The sophistication of these techniques has blossomed, the report added, stating that 70% of the emails containing  <a href="https://www.itpro.com/technology/artificial-intelligence/ai-threats-the-importance-of-a-concrete-strategy-in-fighting-novel-attacks">AI-enhanced phishing</a> content passed the popular DMARC authentication system, which is used to verify the legitimacy of incoming emails.</p><p>Moreover, 55% of all the emails had successfully found their way through all of the target organization’s existing layers before being detected.</p><p>Attacks leveraging <a href="https://www.itpro.com/marketing-comms/qr-codes/360864/are-qr-codes-safe">QR codes</a>, or <a href="https://www.itpro.com/security/hackers-are-stepping-up-qishing-attacks-by-hiding-malicious-qr-codes-in-pdf-email-attachments">qishing</a>, have become a growing trend in today’s threat landscape, exploiting the often-weaker security of mobile devices, and Darktrace detected just under a million (940,000) malicious QR codes in the emails it analyzed.</p><h2 id="legitimate-service-attacks-are-another-key-focus">Legitimate service attacks are another key focus</h2><p>The report also noted threat actors were often seen abusing legitimate services to lend authenticity to their scams. The researchers observed hackers exploiting  a number of trusted services such as <a href="https://www.itpro.com/software/microsoft-office/355740/microsoft-announces-lists-a-new-app-for-teams-sharepoint-and">Microsoft Sharepoint</a>, <a href="https://www.itpro.com/software/zoom-wants-to-take-on-google-and-microsoft-with-its-own-docs">Zoom Docs</a>, <a href="https://www.itpro.com/software/367972/how-easy-is-it-to-sync-quickbooks-to-another-computer">QuickBooks</a>, HelloSign, and Adobe to disguise their sender address.</p><p>In addition, trusted service providers were also appropriated as parts of the threat actor’s attack infrastructure, Darktrace noted.</p><p>“Threat actors were frequently observed using redirects via legitimate services like <a href="https://www.itpro.com/software/google">Google</a> to deliver malicious payloads, effectively evading detection,” the report said.</p><p>“Additionally,Darktrace noted instances where attackers hijacked email accounts, including <a href="https://www.itpro.com/security/biometrics/356023/amazon-halts-police-use-of-its-facial-recognition-tech">Amazon</a> Simple Email Service (SES) accounts, belonging to legitimate third parties, such as business partners and trusted vendors.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="sN9hzieUPYt9YngAjVNAJK" name="Whitepaper_ DevSecOps is dead...or is it__" caption="" alt="Whitepaper: DevSecOps is dead...or is it?:" src="https://cdn.mos.cms.futurecdn.net/sN9hzieUPYt9YngAjVNAJK.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Snyk)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/devsecops-is-dead-or-is-it"><em>Integrate security into the development processes</em></a></p></div></div><p><em>ITPro </em>learned that <a href="https://www.itpro.com/security/cyber-crime/threat-actors-are-leaning-on-trusted-services-more-than-ever">living off trusted services</a> (LoTS) attacks are becoming an increasingly important part of the threat actors arsenal as general security awareness among their targets grows.</p><p>A recent report from security firm Mimecast explained that while these tactics often make their attacks more complex, it helps attackers get around increased authentication checks on corporate accounts.</p><p>It added that major cloud providers whose services are often abused in these attacks, namely Google and <a href="https://www.itpro.com/software/microsoft">Microsoft</a>, have begun taking steps to root out the malicious use of their platforms in such attacks.</p><p>As a result, threat actors have been observed migrating to slightly smaller trusted services providers that they can use to lend authenticity to their attacks.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-crime/what-is-hackbot-as-a-service-and-are-malicious-llms-a-risk">What is hackbot as a service and are malicious LLMs a risk?</a></li><li><a href="https://www.itpro.com/security/cyber-crime/blacklock-ransomware-group-reliaquest">The ‘BlackLock’ group has become one of the most prolific operators in the cyber crime industry</a></li><li><a href="https://www.itpro.com/security/open-source-malware-surged-by-156-percent-in-2024">Open source malware surged by 156% in 2024</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>