Skip to main content

Tag: social engineering

408 articles

Cloud storage workstation with blank laptop screen and keyboard, symbolizing a data breach.

ShinyHunters Fuel Surge in Data Leaks

Meet the ShinyHunters, a notorious group behind a surge in public data leaks, who team up with The Com to scam victims out of cloud system access and then hold their data for ransom. This duo's alarming tactic has resulted in a steady stream of sensitive information being dumped into the public domain.

Analyst 207
Worker looks concerned at laptop screen in office setting.

AI-Powered Phishing Scams Evade Detection in Workplace

Phishing scams are getting sneakier, with 72% of people saying AI-powered attempts are more convincing than ever - and 57% believe AI makes them harder to spot because they seem more professional. As a result, employees are struggling to tell the difference between genuine workplace messages and fraudulent ones.

Analyst 207
Person in a corporate office speaking on phone with neutral expression.

Social Engineering Exposes Vulnerability in Corporate Networks

A clever phone call can be all it takes to breach a corporate network - just ask Brandon Dixon, a former penetration tester who convinced an IT security team to hand over root access by pretending to be their boss. With a simple social engineering trick, Dixon was able to reset his "password" and gain unrestricted access to the network.

Analyst 207
Person sitting at desk with laptop showing Microsoft Teams, surrounded by office equipment and cityscape through window.

KongTuke Hackers Exploit Microsoft Teams for Rapid Corporate Breaches

KongTuke hackers have found a lightning-fast way to breach corporations, exploiting Microsoft Teams to go from initial contact to persistent foothold in under five minutes. This alarming new tactic is part of KongTuke's evolving social engineering toolkit, complementing its previous web-based attacks.

Analyst 207
IT manager sits at desk with concerned expression, surrounded by office decor.

Social Engineering Tactics Expose Company's Vulnerability

A simple request from "the boss" was all it took for a threat actor to gain root access to a company's system, exposing a shocking vulnerability in their security - one that was exploited through a clever social engineering tactic. Human IT managers, trying to be helpful, inadvertently handed over the keys to the kingdom.

Analyst 207
Smartphone screen showing messaging interface with blurred contacts and verified name label.

Signal Bolsters Defenses Against Social Engineering, Phishing Attacks

Stay one step ahead of scammers with Signal's latest update, designed to help you spot fake profiles and phishing attempts with added confirmations and warning messages. You'll now see a "Name not verified" label and get richer safety tips to make sure you're chatting with the real deal.

Analyst 207
Modern office network closet with equipment racks, patch panels, and computer workstations.

Cybercriminals Leverage ClickFix with PySoxy for Persistent Attacks

Cybercriminals are using a potent combination of ClickFix and PySoxy to launch persistent attacks, with experts warning that their deliberate preparation shows a sinister intent for continued access. This sophisticated tactic allows attackers to survive removal attempts and endpoint blocks, making it a major threat.

Analyst 207
Windows office workstations with computers and monitors in daylight-lit setting, highlighting potential vulnerabilities in…

Attackers Exploit AD CS for Stealthy Privilege Escalation

Malicious actors are exploiting weaknesses in Active Directory Certificate Services (AD CS) to secretly escalate privileges, often disguising their attacks as routine administrative actions. This stealthy tactic allows them to blend in with normal operations, making it a high-impact threat that's often under-monitored.

Analyst 207
Person sitting at laptop in office setting with blurred screen.

Australia Warns of ClickFix Malware Attacks Spreading Vidar Stealer

Beware of ClickFix malware attacks that trick you into executing commands, allowing hackers to bypass security and steal your info. The Australian Cyber Security Center has warned of a new campaign using WordPress-hosted sites to spread the Vidar Stealer malware.

Analyst 207
Dimly lit, ransacked suburban home interior with laptop and digital wallet setup.

Crypto Heist Ringleader Gets 6.5 Years for $230 Million Loot

Marlon Ferro, the mastermind behind a brazen crypto heist, has been sentenced to 6.5 years for stealing $230 million in cryptocurrency using a cunning mix of online scams and targeted home invasions. He served as the group's instrument of last resort, carrying out daring residential burglaries to get his hands on valuable digital assets.

Analyst 207
Laptop screen displays Microsoft Teams meeting in modern office setting with blurred cityscape background.

MuddyWater Exploits Microsoft Teams in False Flag Ransomware Attacks

MuddyWater hackers are impersonating Chaos ransomware affiliates, using clever social engineering tactics via Microsoft Teams to steal credentials and gain access to sensitive systems. Their sophisticated campaign involves interactive screen-sharing and manipulation of multi-factor authentication.

Analyst 207
Older adult sits alone in quiet room, conveying vulnerability.

Romance Scammers Pocket £102M via Cyber Deception Tactics

Romance scammers made off with a staggering £102 million in the UK last year, using their silver tongues to swindle victims out of their hard-earned cash. Their tactics, cloaked in sweet talk and false affection, ultimately led to a £102 million payday.

Analyst 207
Blurred office workers in background, phone on desk in focus, with cityscape visible through window.

Real Estate Giant Hit by Vishing Incident from ShinyHunters, Qilin Gang

Cushman & Wakefield, a real estate giant, has confirmed a vishing incident at the hands of notorious threat actors ShinyHunters and Qilin Gang, highlighting the growing threat of social engineering attacks. This recent breach serves as a stark reminder of the importance of robust security measures.

Analyst 207
Office desk with phone in foreground and blurred person in background.

Cushman & Wakefield Discloses Vishing Incident Amid Dual Ransomware Threats

Cushman & Wakefield recently fell victim to a vishing incident, but swift action was taken to contain the breach and protect its systems. The company has confirmed that its operations remain normal and it's working closely with experts to investigate and respond to the incident.

Analyst 207
Person sits alone in dimly lit room, surrounded by blurred dating profiles on laptop screen, conveying sadness and isolation.

Romance Scammers Rake in £102M Through Emotional Manipulation

Romance scammers exploited the trust of unsuspecting victims to pocket a staggering £102 million in 2025, with the average person losing around £9,500 in these emotionally manipulative scams. This heart-wrenching trend saw a 29% surge in reported cases, with £280,000 lost daily.

Analyst 207
Loan officer's workspace with laptop and papers, busy banking hall blurred in background.

Fraudsters Target Credit Unions with Structured Loan Scams

Fraudsters are now targeting credit unions with sophisticated loan scams, using stolen identities and social engineering to exploit lending workflows. In fact, auto lending fraud exposure is expected to hit $9.2 billion by 2025, making it a lucrative target for these scammers.

Analyst 207
European cityscape with technology hint, person walking in distance.

Russia Targets Signal Users in Germany with Social Engineering Hacks

Stay vigilant, especially when it comes to trusted messaging apps like Signal - a recent wave of social-engineering attacks in Germany targeted government officials, exploiting user trust rather than any technical flaw. Signal has assured users that its encryption and infrastructure remain secure, but warns that these types of attacks can still compromise user safety.

Analyst 207
Crypto executive looks concerned at laptop with subtle scheduling software on screen.

North Korean Hackers Exploit Fake Zoom Meetings to Target Crypto Executives

North Korean hackers are using a sneaky tactic to target crypto executives: they pose as legitimate meeting attendees, harvesting video and audio to make future scams more convincing. They start by sending Calendly invites for fake catch-up meetings, then swap the link with a fake Zoom or Teams URL to gain their victim's trust.

Analyst 207
Laptop screen displays Microsoft Teams conversation in bright office setting.

Microsoft Teams Used to Deploy Sophisticated Snow Malware

Cyber attackers have cleverly used Microsoft Teams to deploy a sophisticated malware suite, dubbed Snow, by tricking victims into installing a fake anti-spam patch that ultimately led to prolonged access, credential theft, and domain compromise. They started by creating a sense of urgency through email bombing, then followed up with a direct message on Microsoft Teams.

Analyst 207
Retail customer service desk with blurred computer screen nearby in daytime setting.

BlackFile Targets Retail with Vishing Extortion Tactics

Meet BlackFile, a financially motivated group that's been wreaking havoc on retail and hospitality organizations with a clever vishing extortion tactic, posing as IT support staff to steal data since February 2026. They're using spoofed VoIP numbers and fake Caller ID names to pull off their scams.

Analyst 207
Person sitting at laptop with neutral expression, hint of Zoom call on screen.

Scammers Exploit Trust in Remote Job Interviews

Boris Vujičić thought he had landed a legit remote job interview, but the scammers behind it expertly gained his trust, convincing him to let his guard down long enough to hack into his laptop. A fake LinkedIn recruiter, a professional website, and a convincing Zoom call with a person named Zam Villalon were all part of their clever scheme.

Analyst 207
Laptop screen displays Microsoft Teams chat invitation on office desk with papers and chair in background.

Threat Actors Exploit Microsoft Teams for SNOW Malware Deployment

Cyber attackers are exploiting Microsoft Teams by impersonating IT helpdesk staff, tricking victims into accepting chats from unfamiliar accounts and deploying SNOW malware. They start by flooding inboxes with urgent emails, then pose as IT support over Teams, offering to fix the problem.

Analyst 207
Cluttered office desk with computer, papers, and open smartphone showing an email inbox.

UNC6692 Exposes Custom Malware Suite via Social Engineering

In a clever social engineering ploy, UNC6692 launched a massive email campaign in late December 2025, flooding targets with messages to create a sense of urgency and distraction, before following up with a convincing Microsoft Teams message that pushed a malicious link. The attackers then cleverly disguised their malware as a legitimate "Mailbox Repair and Sync Utility" patch, hosted on an Amazon S3 page.

Analyst 207
Person sitting at desk with phone, surrounded by computer monitors and notes, in a dimly lit room with a cityscape visible…

Cybercrime Shifts to Caller-as-a-Service Model

US elderly citizens alone lost a staggering $3.4B in 2023 to phone-based scams, highlighting the alarming rise of a highly organized and profitable fraud economy. This Caller-as-a-Service model has made it easier for scammers to specialize and scale their operations, putting even more people at risk.

Analyst 207