Finance Phishing Lures Feed Telegram Data Leaks

AhnLab ASEC · Medium sophistication
Last updated July 30, 2026

A June 2026 financial-sector threat report describes real phishing emails that used business-looking themes (e.g., money transfers, receipts, voicemail) to push victims to malicious links or HTML attachments that mimic login pages. The report also highlights cases where stolen account information was exfiltrated to attackers via the Telegram API, alongside dark-web sales of financial datasets and access credentials.

How the attack worked

This campaign relied on business-sounding email themes such as money transfer notices, receipts, and voicemail alerts to pressure recipients into clicking a link or opening an attachment. Those links and attachments led to login pages designed to harvest credentials. A second variant used attachment filenames crafted to resemble tax and payment receipts or HR and contract documents, aiming to build trust before the recipient opened the file. Phishing was the most common initial access method observed in the financial sector, frequently followed by downloaders or infostealers in multi-stage attack chains.

Why it succeeded

The lures worked because they mimicked routine business communication that finance, accounting, treasury, and HR staff handle daily. A message about a transfer receipt or a voicemail does not stand out as unusual in these workflows, which lowers scrutiny. Attachment filenames were deliberately structured to resemble real business documents, tax and payment receipts, and HR or contract paperwork, making them look legitimate at a glance. HTML attachments made up the largest share of malicious files, and script-based extensions such as js, vbe, vbs, bat, and hta were also common, both of which can bypass casual visual inspection since they don't look like traditional executable threats.

What to watch for

  • Unexpected emails referencing a money transfer, receipt, or voicemail that push you toward a link or attachment
  • HTML files presented as documents, especially when unsolicited
  • Attachment filenames that closely resemble tax, payment, HR, or contract paperwork but arrive outside normal document exchange processes
  • Login pages reached through an email link or attachment that don't match your organization's normal sign-in flow
  • Script-based file extensions like js, vbe, vbs, bat, or hta attached to business-themed emails

How to build resistance

Organizations in finance, insurance, fintech, banking, and asset management should treat money transfer, receipt, and voicemail-themed emails as high-risk until verified through a separate, trusted channel. Staff should be trained to view HTML attachments with the same caution as executables, since HTML accounted for the largest share of malicious attachments in this reporting period. Because stolen account information was reportedly exfiltrated to attackers through the Telegram API, rapid reporting of suspected phishing matters: the faster a suspicious email is flagged, the less time attackers have to move stolen credentials off-site. Techniques referenced in this campaign map to spearphishing via link (T1566.002), spearphishing attachment (T1566.001), and user execution of malicious files (T1204.001), which security awareness programs can use as a basis for targeted training scenarios.

Key findings

  • Phishing was the most prevalent initial access method for the financial sector in June, often followed by downloaders/droppers and then infostealers in multi-stage chains.
  • HTML attachments were the most common malicious attachment type, suggesting heavy use of HTML-based phishing pages and related techniques.
  • Korean-language attachment names were designed to look like real business documents (e.g., tax/payment receipts and HR/contract paperwork) to build trust.
  • Stolen account information gathered via malware infections and phishing emails was leaked to attackers via the Telegram API; phishing emails used themes like “money transfer,” “receipt,” and “voicemail.”
  • The report also highlights dark-web activity: alleged sales of leaked databases, ransomware/extortion victim claims, and sales of access credentials.

Who’s being targeted

  • Commonly targeted roles: Finance, Accounting, Treasury, HR, Procurement, Operations, Executive assistants.
  • Affected industries: Financial services, Insurance, Fintech, Banking, Asset management.
  • Attack channels: email, website.
  • Impersonated: A bank/payment service or internal finance system (masquerading as a legitimate login page), External business partner or internal HR/finance team (via a realistic-looking document filename).

Red flags to watch for

  • Unexpected message pressuring you to view a transfer/receipt/voicemail via a link or attachment
  • HTML attachment used as the ‘document’
  • Link/attachment leads to a login page that doesn’t match normal company sign-in flow
  • Attachment filename looks like a sensitive business document but arrives unexpectedly
  • Script-based attachment types (e.g., .js, .vbe) or web-document types (e.g., .html)
  • Sender context doesn’t match normal document exchange processes
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What phishing themes are being used against finance teams?

Attackers used routine business themes like money transfer notices, receipts, and voicemail alerts to get recipients to click links or open HTML attachments leading to fake login pages.

Why are HTML attachments a concern in this campaign?

HTML accounted for the largest share of malicious attachments, often paired with script-based extensions like js, vbe, vbs, bat, and hta, which are used to build convincing fake login pages.

What happens to stolen credentials in this campaign?

Stolen account information collected through malware infections and phishing emails was leaked to attackers through the Telegram API, allowing rapid off-site exfiltration.

Who is most targeted by these phishing lures?

Finance, accounting, treasury, HR, procurement, operations, and executive assistant roles are the primary targets, particularly within financial services, insurance, fintech, banking, and asset management.

Read the video transcript

You get an email: “Subject: Money transfer receipt, please review.” Looks routine, right? The email pushes you to click a link or open an HTML “receipt.” That opens a login page that looks like your bank or finance portal, but it’s fake. Here’s the nasty part: the moment you type your ID and password, that data can be shot straight out through the Telegram API and sold on dark‑web markets within minutes. If an email about money transfers, receipts, or voicemail asks you to log in from a link or HTML file, stop, report it as phishing and verify the request through our normal finance or HR channels.

Similar attacks