Tag: social engineering
408 articles

WhatsApp Disrupts NSO Group's Spyware Phishing Campaigns
Meta's WhatsApp team swiftly sprang into action, disrupting a sophisticated spyware phishing campaign linked to the NSO Group after investigating user reports of targeted social-engineering attacks. They successfully stopped the attackers' attempts to trick people into clicking malicious links that could have put their data at risk.

China Exploits Job Sites for Spying on Five Eyes Targets
Be cautious on job sites - Chinese spies are posing as recruiters on LinkedIn, Indeed, and Upwork to trick Five Eyes targets into divulging sensitive information. They're using clever social engineering tactics to make their scams seem all too believable.

Meta Accuses NSO Group of Breaching WhatsApp Injunction
Meta is taking a stand against NSO Group, accusing the Israeli spyware vendor of breaching a WhatsApp injunction by targeting users with social engineering attempts. The company claims it successfully thwarted these malicious efforts, but is now asking a federal judge to hold NSO Group in contempt.

Threat Actors Exploit Vishing, Physical Intrusions in US Data Extortion Campaign
Meet UNC3753, a notorious group of threat actors using clever voice phishing and social engineering tactics to infiltrate US corporate environments and steal sensitive data. Their deceitfully simple attacks start with a phone call or email and quickly escalate into rapid data theft and ransom demands.

Silent Ransom Group Exploits Law Firms with Fake IT Support Scams
Law firms are being targeted by the Silent Ransom Group through clever fake IT support scams, putting sensitive client information at risk. This sophisticated attack starts with innocent-looking invoice emails that trick victims into calling a phone number, initiating a chain of events that can lead to devastating consequences.

Mandiant Exposes UNC3753's US Law Firm Data Heist Tactics
Beware of UNC3753, a notorious group that's been stealing sensitive data from US law firms and other professional services, using clever vishing tactics and lightning-fast intrusions to extort their victims. In some cases, they can go from initial contact to data theft in under an hour.

Multiple Breaches Expose Sensitive Data Across Industries
Sensitive data has been compromised across various industries in a series of alarming breaches, including a clever social engineering scam that exposed info of 6 million Carnival Corporation customers and two incidents involving learning management company Instructure's Canvas platform. These breaches highlight the growing threat of cyber attacks and the importance of robust data protection measures.

Cybercriminals Target FIFA World Cup 2026 with Sophisticated Scams
As the 2026 FIFA World Cup approaches, cybercriminals are gearing up to scam unsuspecting fans with sophisticated ticketing scams, counterfeit sites, and panic-inducing mechanics. Experts warn that this major event has become a prime target for cyberattacks, with thousands of fraudulent domains and fake Facebook ads already circulating.

Microsoft Warns AI Adoption Exposes Organizations to New Malware Threats
Microsoft's senior security researcher warns that the AI tools making our jobs easier can also be exploited by threat actors, highlighting a new and urgent risk for organizations to manage. As AI adoption grows, companies must recognize it as both a valuable asset and a potential attack surface that requires careful protection.

Bayer Overhauls Security Training to Counter AI-Driven Threats
Bayer is revolutionizing its security training to combat AI-driven threats by ditching traditional checklist-driven advice for a psychology-first approach that outsmarts increasingly realistic social engineering tactics. This bold move aims to empower staff and suppliers to safely harness the power of generative AI.

Silent Ransom Group Escalates Tactics with In-Person IT Impersonation
The FBI warns that the notorious Silent Ransom Group is taking a more aggressive approach, impersonating IT staff in person to infiltrate corporate systems, targeting US law firms, insurance, finance, and healthcare companies since 2023. This new tactic marks a significant escalation from their previous remote trickery methods.

Kimsuky Expands Malware Arsenal with HTTPSpy, HelloDoor
Kimsuky, a notorious North Korean hacking group, has upgraded its malware arsenal with HTTPSpy and HelloDoor, using clever tactics like fake installation pages and a spoofed Webex meeting to infiltrate targets. The group's latest attacks involve highly tailored social engineering and real-time infection verification to maximize success.

GreyVibe hackers wield AI tools to fuel multi-sector cyberattacks
Meet GreyVibe, a likely Russian threat group that's been wreaking havoc across multiple sectors in Ukraine since at least August 2025, using AI-generated social engineering and custom malware to fuel its attacks. WithSecure researchers uncovered the group's activities, revealing a surprisingly unsophisticated approach despite its use of advanced AI tools like ChatGPT and Google Gemini.

Carnival Cruise Data Breach Exposes 6 Million Customers
A recent data breach at Carnival Cruise, affecting 6 million customers, highlights the vulnerability of traditional security controls to social engineering tactics, where a single compromised employee device can lead to devastating consequences. This incident serves as a stark reminder of the human factor in cybersecurity, where threat actors exploit trust and impersonation to gain access to sensitive information.

Jinx-0164 Targets Crypto Developers with Custom macOS Malware
Beware of fake meetings on LinkedIn - cyber attackers are using them to trick crypto developers into installing custom macOS malware called Audiofix, which can steal sensitive info like passwords, SSH keys, and cryptocurrency wallet details. This sneaky malware is disguised as an audio fix, but its real goal is to harvest your valuable data.

Carnival Cruise Breach Exposes 6 Million in Data Heist
Millions of Carnival Cruise customers are reeling after a massive data breach exposed sensitive information, with 5.9 million individuals affected by the shocking incident. The breach, which occurred over a 12-day period, was sparked by a clever social engineering scam that duped an employee into handing over access to the company's IT systems.

JINX-0164 Exploits Crypto Firms with Fake Recruiter Lures and macOS Malware
Meet JINX-0164, a cunning threat actor who's been targeting crypto developers with clever fake recruiter lures and custom macOS malware since mid-2025. By impersonating credible LinkedIn profiles and posing as recruiters, they've been tricking victims into virtual meetings that lead to rogue domains.

FBI Warns Law Firms of Silent Ransom Group's In-Person Data Heists
The FBI is sounding the alarm for US-based law firms after the Silent Ransom Group, a notorious data-extortion gang, claimed over 100 attacks - with a recent surge in activity that's left experts on high alert. This group's twist? They're using in-person tactics, combined with social engineering, to get their hands on sensitive data.

FBI Warns of In-Person Data Theft Attacks by Extortion Gang
The FBI has issued a warning about a sneaky new tactic used by the notorious Silent Ransom Group: showing up in person to steal sensitive data, after gaining trust through clever phishing and phone scams. This brazen approach combines remote access tricks with physical presence at victim sites, marking a chilling evolution in their extortion methods.

Microsoft Warns of AI-Driven Cryptojacking Campaign Targeting High-Performance GPUs
Beware of a sneaky new cryptojacking scam that's using AI chatbots to trick you into downloading malicious software - hackers are now hiding in plain sight, serving up poisoned links in chatbot responses that seem like harmless software recommendations. This cunning tactic is a game-changer for cyber threats, making it even harder to spot danger online.

FBI Warns of Kali365 Phishing Service Targeting Microsoft 365 Accounts
Beware of Kali365, a sneaky phishing service that's hijacking Microsoft 365 accounts by exploiting a legitimate authentication flow - and it's happening fast, with the platform emerging as recently as April 2026. This clever trick uses a short code to trick victims into handing over control of their accounts.

Microsoft Abuses Self-Service Password Reset in Azure Data Theft Attacks
Microsoft warns that hackers are using clever social engineering tactics and exploiting self-service password reset features to drain sensitive data from high-value Azure assets. By tricking users into approving multi-factor authentication prompts, attackers can gain access to production Microsoft 365 and Azure environments.

Vulnerability Exploitation Surges in Data Breaches
Vulnerability exploitation is now the top attack vector, responsible for a staggering one-third of all data breaches. This alarming trend highlights the urgent need for robust patch management and cybersecurity measures to stay ahead of threats.

Poland Shifts Officials to State Messaging App Citing Security Concerns
Poland is swapping out Signal for a state-developed messaging app touted as more secure, amid rising concerns over targeted social engineering attacks on government officials. The move marks a significant shift in how officials communicate, prioritizing security over popular choice.