Threat Watcher

Real-world phishing, vishing, and social engineering attacks, continuously collected from security reporting and broken down with an original video explainer, key findings, and the red flags your team should watch for. How we produce these.

Early Access Apps Hide Risks From Employees
September 11, 2026

Early Access Apps Hide Risks From Employees

Bitdefender reports that Google Play’s “Early Access” apps can’t be publicly rated or reviewed, reducing a key warning signal employees use to spot deceptive apps. The research found thousands of suspicious Early Access…

Source: CSO Online
Try Mirage

Mirage simulates attacks like these against your own team, live and safely, so you can measure how your people actually respond.

Get a demo
BlueMoon Spearphish Turns One Click Into Admin

BlueMoon Spearphish Turns One Click Into Admin

Proofpoint reports that multiple espionage-focused groups are using a shared “BlueMoon” toolkit to run targeted spear‑phishing campaigns that trick people into clicking a link. A single click can trigger a Chrome/Windows exploit chain that gives attackers full Windows admin access and lets them…

September 11, 2026
Pig Butchering Scams Drive $12.7B Crypto Losses

Pig Butchering Scams Drive $12.7B Crypto Losses

FinCEN reports that overseas scam centers stole about $12.7B from U.S. victims since 2023, largely through “pig butchering” style cryptocurrency investment scams. Scammers build trust using fake personas (often romance or “financial adviser” roles), then pressure victims to buy crypto and send it…

September 10, 2026
DoppelCart Fake Shops Steal Payment Details

DoppelCart Fake Shops Steal Payment Details

Researchers uncovered a massive network of over 119,000 fake online stores that copy real brands to trick shoppers into entering payment details. The cloned sites look legitimate and use big discounts to create urgency, but the checkout pages capture card and personal data that criminals can reuse…

September 10, 2026
Spy Groups Phish Victims Into Chrome Exploit Kit

Spy Groups Phish Victims Into Chrome Exploit Kit

Researchers reported four separate espionage groups using the same “BlueMoon” exploit kit within days, targeting organizations in the US and Southeast Asia. The attacks began with phishing emails that lured recipients to attacker-controlled websites, where Chrome and Windows vulnerabilities were…

September 10, 2026
Fake CAPTCHA Trick Fuels WebDAV Malware Chain

Fake CAPTCHA Trick Fuels WebDAV Malware Chain

Cisco Talos investigated a real incident at a Ukrainian government organization and found a complex WebDAV-based infection chain linked to a Russian actor (UAT-10820). The campaign uses fake CAPTCHA/verification prompts to manipulate users into copying and pasting commands, leading to credential…

September 10, 2026
AI-Assisted CEO Invoice Scam Pushes $50K ACH

AI-Assisted CEO Invoice Scam Pushes $50K ACH

Microsoft reports a real, large-scale email campaign that impersonated company executives and ServiceNow to pressure accounts payable teams into sending nearly $50,000 via ACH/bank transfer. The emails bundled a CEO “approval,” a fake ServiceNow-branded invoice, and a fabricated forwarded thread to…

September 10, 2026
Crypto Newsletter Breach Triggers Fake Security Emails

Crypto Newsletter Breach Triggers Fake Security Emails

Attackers abused access to a third-party email newsletter provider to send convincing “security alert” emails from legitimate-looking crypto company domains. The emails pushed users to click links that led to phishing sites designed to look nearly identical to real platforms. Trezor, CoinTracking,…

September 10, 2026
Fake M&A Wire Fraud and Trezor Phishing Alert

Fake M&A Wire Fraud and Trezor Phishing Alert

This bulletin describes multiple real-world scams where attackers manipulate trust to steal money or sensitive data. Notably, attackers impersonated executives to pressure legal teams into moving M&A discussions to WhatsApp/personal email to trigger international wire transfers, and Trezor users…

September 10, 2026
AI Brands Used as Bait in Phishing Waves

AI Brands Used as Bait in Phishing Waves

Microsoft Threat Intelligence reports real campaigns where attackers impersonate popular AI tools (like ChatGPT, Copilot, DeepSeek, and Claude) to trick people into clicking links, installing fake software, or entering payment and login details. One campaign sent up to 100,000 emails in a day to…

September 10, 2026
Poisoned GitHub Issues Hijack AI Agent Tokens

Poisoned GitHub Issues Hijack AI Agent Tokens

Researchers described a real-world style attack where text posted in a GitHub issue was treated as an instruction by an AI agent, leading the agent to use a victim’s token to access private repositories. The article also highlights common weak setups in MCP integrations, overbroad permissions,…

September 10, 2026
Fake Title IX Claims Push Zoho Assist RAT

Fake Title IX Claims Push Zoho Assist RAT

A real phishing campaign is using fabricated sexual misconduct (Title IX-style) allegations to pressure university staff into clicking a link and installing Zoho Assist, a legitimate remote-access tool being abused as malware. The emails impersonate university leaders and route victims through a…

September 10, 2026
Early Access Loophole Floods Play Store With Scams

Early Access Loophole Floods Play Store With Scams

Researchers say criminals are abusing Google Play’s “Early Access” program to distribute deceptive apps that promise cash, rewards, or casino winnings. The apps are promoted through social media ads (including AI celebrity deepfakes) and use a “never-ending payout” loop to keep people watching ads…

September 10, 2026
Fake IT Calls Steal Microsoft 365 Access

Fake IT Calls Steal Microsoft 365 Access

Microsoft reports a real-world campaign where attackers call or text employees’ personal phones while posing as internal IT. Victims are pushed to “update” passkeys/MFA/SSO and click a link to a fake Microsoft sign-in page, letting attackers get into Microsoft 365 and quietly pull email and files…

September 10, 2026
Fake Google Support Bait Led to $245M Crypto Theft

Fake Google Support Bait Led to $245M Crypto Theft

A Singaporean man, Malone Lam (aliases including “Anne Hathaway”), pleaded guilty to leading a group that stole over $245 million in cryptocurrency from U.S. victims. The group used social engineering, such as posing as Google Support and using spoofed phone numbers, to trick victims into handing…

September 10, 2026
Gigabud Hides Fake Bank App in Android Work Profile

Gigabud Hides Fake Bank App in Android Work Profile

Researchers say the Gigabud banking trojan is being installed via fake apps (e.g., pretending to be an airline, tax office, or government portal) and then uses an Android “work profile” to hide a tampered banking app. Victims are tricked into granting powerful permissions, after which attackers can…

September 10, 2026
Deepfake ‘Kidnapping’ Calls and the Safe Word Fix

Deepfake ‘Kidnapping’ Calls and the Safe Word Fix

The article describes how scammers use AI voice cloning to impersonate a loved one during a phone call and pressure relatives into paying money (often framed as a kidnapping emergency). It recommends a practical defense: a pre-agreed family “safe word” and a simple verification process (hang up and…

September 10, 2026
Brevo Breach Sparks Trezor Phishing Wave

Brevo Breach Sparks Trezor Phishing Wave

Trezor said attackers breached its third-party email provider (Brevo) and gained access to Trezor’s email domain, triggering phishing emails to subscribers. The scam emails used a fake “critical security alert” about a supposed microcontroller vulnerability and attempted to trick users into handing…

September 10, 2026
Fake Reward Apps Abuse Google Play Early Access

Fake Reward Apps Abuse Google Play Early Access

Researchers say scammers are using Google Play’s “Early Access” listings to push deceptive Android apps that don’t show public ratings or warnings. Victims are lured by TikTok/Facebook ads promising cash rewards or free casino spins, but the apps primarily bombard users with ads and never deliver…

September 10, 2026
Instagram Copyright Strikes Used for Ransom

Instagram Copyright Strikes Used for Ransom

Scammers are filing fake copyright complaints to get Instagram accounts temporarily suspended, then demanding money to “withdraw” the complaint and restore access. Victims are pushed to communicate off-platform (for example, on Telegram) and asked to pay in cryptocurrency, yet even paying doesn’t…

September 10, 2026
DocuSign Phish Uses “Blob” Pages in Your Browser

DocuSign Phish Uses “Blob” Pages in Your Browser

Researchers described a real phishing campaign where victims click through legitimate Microsoft services and end up on a fake login page that is generated inside their own browser. The phishing page uses a temporary “blob URL” (not a normal website) and can disappear after the session, making it…

September 10, 2026