
Phishing Link Could Plant a Rogue ChatGPT Agent
Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…
Researchers described a long-running fraud campaign where criminals clone real Russian company websites and replace contact and bank details to intercept international business deals. Victims are lured through cold calls, phishing emails, and fake supplier websites, then sent realistic contracts and invoices that route “advance payments” to attacker-controlled accounts.
This campaign relies on cloned websites that copy the look, content, and branding of real companies engaged in international trade. The only changes are to contact details and bank account information, which are altered to route communications and payments to the attackers instead of the legitimate supplier. Victims are drawn in through cold calls, phishing emails, and these fraudulent corporate websites, then guided through what looks like a normal sales process: a commercial offer, a contract, and finally an invoice requesting an advance payment for goods that do not exist.
In some cases, hired sales representatives make the initial cold call and then hand the deal off to a supposed senior manager once negotiations near the payment stage. From that point on, all communication is with the fraudsters, who supply convincing documentation, including offers and contracts on what appears to be official letterhead, with only the payment details swapped out.
The scheme works because the documentation looks complete and authentic. Attackers prepare a full set of business paperwork designed to build confidence and mirror a genuine transaction. Because the cloned website and communications closely resemble the real supplier, victims have little reason to suspect anything is wrong until the payment has already gone to a fraudulent account. The reliance on an advance payment model for international goods purchases also creates a natural point where money moves before the buyer ever receives a product to inspect.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Attackers copy content from a legitimate company's website onto a lookalike domain, altering only the contact details and bank account information so victims unknowingly send advance payments to the fraudsters.
Procurement, finance and accounts payable, supply chain, and sales staff who handle vendor communications and payment approvals are the primary targets.
Independently confirm contact details and bank account information through a trusted, out-of-band channel rather than relying on the details listed in the email or website that initiated contact.
Some campaigns use sales representatives to cold-call potential customers and then hand the negotiation off to a supposed senior manager right before payment, adding a layer of social pressure and legitimacy.
You get a great offer from a Russian supplier, contract attached, invoice ready. Looks legit, right? Behind that email is a cloned website of a real Russian company, same logo, same text, but a lookalike domain and swapped contact and bank details sending money to someone else. They cold-call, send phishing emails, then hit you with polished offers, contracts, and invoices on letterhead. One company in Azerbaijan wired $150,000 in an 'advance payment' straight to bogus subsidiary bank details. Aha moment: if the website or caller gives you bank details, don’t trust them. Before any advance payment, independently confirm the account using a phone number or contact you already know.

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…

Microsoft reports billions of phishing attempts in Q2 2026, with attackers increasingly using attachments (PDF/DOC/HTML) and new formats like calendar invites…

The FBI warns scammers are impersonating FBI/IC3 staff and re-targeting people who already lost money to fraud. The scammers use emails, phone calls, social…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through…

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay…