
Fake Install Guides and Helpdesk Calls Drive Attacks
This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…
A Russian-linked group allegedly stole sensitive contact data from the Netherlands National Police after getting access to an employee’s email account. The podcast describes a realistic spearphishing lure: an email invitation to a “European Defence Summit” that includes a link or a QR code in a PDF leading to a fake Microsoft Teams login page designed to capture credentials.
The lure described in this incident began with a personal invitation delivered by email, framed as an invite to a European Defence Summit. The message included either a link or a QR code embedded in a PDF attachment. Following that link or scanning the code led targets to a login page designed to look like Microsoft Teams. Once a victim entered their username and password, the attacker captured those credentials. This access was reportedly used to compromise a staff member's email account at the Netherlands National Police Force, which enabled theft of contact data on over 64,000 officers and informants.
The pretext relied on plausibility rather than technical complexity. An invitation to a defense-related summit is a believable reason for government, law enforcement, and defense personnel to expect correspondence, register online, and log in to a conference or collaboration platform. Embedding the malicious link inside a PDF and using a QR code added a layer of obfuscation, since QR codes are harder to inspect before scanning and often bypass email link scanning tools. The destination page's resemblance to a familiar Microsoft Teams login also reduced suspicion at the critical moment of credential entry.
Organizations, particularly those in government, law enforcement, and defense, should train staff to treat unsolicited event invitations as high-risk, especially when the call to action involves scanning a QR code or clicking a link inside a PDF. When a login page appears that looks like Microsoft Teams but was reached via an unexpected invite, staff should be encouraged to stop and verify through a trusted channel, such as the official event website or an internal security contact, rather than entering credentials directly. It's also worth reinforcing that attackers in cases like this were focused on intelligence collection rather than immediate financial gain, meaning any credential compromise, even one that seems minor, can lead to significant downstream data exposure. Anyone who regularly handles contact databases, informant information, or other sensitive directories should receive particular attention in this kind of awareness training, given the scale of data that a single compromised account can expose.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Targets received an email invitation to a European Defence Summit containing a link or a QR code inside a PDF. Clicking or scanning led to a fake Microsoft Teams login page designed to capture usernames and passwords.
Attackers gained access to a staff member's email account and used that access to steal contact data on over 64,000 officers and informants.
Microsoft and Dutch intelligence publicly attributed the operation to a group referred to as Void Blizzard, also known as Laundry Bear, according to the podcast.
No. The podcast frames it as intelligence collection, stating the goal was gathering intel to exploit later rather than deploying ransomware or extorting money.
You get an email: personal invite to a “European Defence Summit” with a glossy PDF attached. Looks legit, right? This exact trick was used against the Netherlands National Police. One compromised inbox, and data on over sixty-four thousand officers and informants was stolen by a group called Void Blizzard. Here’s the move: the PDF says, 'Scan this QR to join on Microsoft Teams.' You scan, a page that looks like Teams pops up, asks you to sign in, and, bang, they’ve got your username and password. If an unsolicited invite pushes you to scan a QR or click a PDF link to log in, don’t do it, open Teams or your calendar yourself and check the meeting there.

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Russia’s FSB claims Ukrainian intelligence used a Telegram dating chatbot to deceive and psychologically pressure young Russians into sharing locations,…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through…

Researchers reported a real spearphishing campaign that impersonates DocuSign emails to trick tech executives into clicking “Review Document” links and…

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites…