Job Offer & Doc-Link Phishing Drive Real Breaches

Check Point Research · High sophistication
Last updated August 18, 2026

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and trojanized software to infect defense organizations, an approach that can be recreated for employee training.

How the Attacks Worked

Two distinct but related patterns emerge from this reporting. In the first, an employee at IEH Corporation, a defense and aerospace component manufacturer, received a fraudulent document-sharing link. Clicking it led to a fake Microsoft 365 login page, and entering credentials there gave attackers access to the mailbox. This type of attack does not rely on malware at all, just a convincing pretext and a login prompt.

In the second pattern, tied to the Lazarus-linked Operation Dream Job, attackers used fake job opportunities to reach engineers and defense program staff. Instead of a credential-harvesting link, the payload was trojanized 'PDF software' that, once opened, deployed malware onto the target's system.

A third data point, from Levi Strauss & Co., shows that social engineering does not need to involve a phishing link or malware installer at all. Attackers used social engineering to compromise three employee devices directly and steal corporate information.

Why These Attacks Succeeded

Each scenario exploits a routine workplace behavior that employees rarely question:

  • Reviewing a shared document from what looks like a business contact
  • Considering a job opportunity that appears relevant to their skills
  • Trusting normal-seeming requests without independent verification

Because these pretexts mimic everyday tasks, such as viewing files or reviewing career opportunities, they bypass the skepticism people typically reserve for obviously suspicious emails.

What to Watch For

Defenders and employees should be alert to:

  • Unexpected document shares tied to purchase orders, engineering files, or contracts you weren't expecting
  • Links that lead to a login prompt asking for corporate credentials rather than displaying a file directly
  • Unsolicited job offers, especially for sensitive or defense-related roles, that ask you to install or run unfamiliar software
  • Any message creating urgency to review documents or respond to a job offer quickly

Building Resistance

Organizations, particularly in defense, aerospace, and manufacturing, can reduce risk by training employees to verify unexpected document-share requests before entering credentials, and to treat unsolicited recruiting outreach with the same scrutiny as any unknown attachment. Reporting suspicious interactions immediately, even when no data appears to have been exposed, helps security teams respond before an initial compromise escalates. Since these incidents show that both credential phishing and direct social engineering can lead to real corporate data loss, awareness training should cover both technical red flags, like unexpected login prompts, and human-behavior red flags, like recruiter contact regarding roles the employee did not apply for.

Key findings

  • Levi Strauss reported attackers used social engineering to compromise three employee devices and steal corporate information.
  • IEH Corporation confirmed a phishing compromise of an employee’s Microsoft 365 mailbox using a fraudulent document-sharing link to steal credentials.
  • Operation Dream Job (Lazarus-linked) used fraudulent job opportunities and trojanized PDF software to deploy malware against defense organizations.

Who’s being targeted

  • Commonly targeted roles: All employees, Engineering, Defense/Aerospace program teams, HR/Recruiting, Executives, IT/Helpdesk.
  • Affected industries: Government, Healthcare, Retail/Apparel, Defense/Aerospace Manufacturing, Energy.
  • Attack channels: email.
  • Impersonated: Document-sharing service / business contact, Recruiter / hiring team for a job opportunity.

Red flags to watch for

  • Unexpected document share or purchase/engineering context you weren’t expecting
  • Link leads to a login prompt asking for corporate credentials
  • Sender pressure or urgency to review documents quickly
  • Unsolicited job offer tied to sensitive/defense roles
  • Request to install or run “PDF software” rather than using standard PDF viewing
  • Unexpected attachments or installers presented as recruiting materials
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers compromise IEH Corporation?

Attackers sent a fraudulent document-sharing link that led an employee to a fake login page, stealing their Microsoft 365 credentials and potentially exposing engineering and export-controlled data.

What is Operation Dream Job?

Operation Dream Job is a Lazarus-linked campaign that uses fraudulent job opportunities and trojanized PDF software to deploy malware against defense organizations in Europe, India, and Brazil.

Did Levi Strauss suffer a data breach?

Levi Strauss reported that attackers used social engineering to compromise three employee devices and steal corporate information.

What red flags indicate a document-sharing phishing attempt?

Watch for unexpected document shares, links that prompt a corporate login, and messages that pressure you to act quickly on unfamiliar purchase or engineering content.

Read the video transcript

Levi Strauss and a defense supplier were breached the same way: someone trusted a link and a file they shouldn't have. At IEH, a defense manufacturer, one click on a fake document‑sharing link led to a Microsoft 365 login page. The employee entered their password, and their mailbox, and sensitive engineering documents, were exposed. In Operation Dream Job, targets get an email from a 'recruiter' for a sensitive defense role. The catch: to see the job details, you have to install their special 'PDF software', which is actually malware. Aha moment: if a link or job email makes you log in or install software unexpectedly, stop. Do not click or install, forward it to the security team and ask them to check it.

Similar attacks

Device-Code Phishing and “ClickFix” Lures Spread

Device-Code Phishing and “ClickFix” Lures Spread

This weekly recap highlights multiple real-world campaigns where attackers trick users into taking actions that grant access, without needing to steal passwords directly. Notable examples include “device code” phishing (victims are instructed to enter a short code to approve an attacker session)…

September 28, 2026
M365 “Direct Send” Abused for Internal-Looking Phish

M365 “Direct Send” Abused for Internal-Looking Phish

Researchers observed a real phishing campaign that abused Microsoft 365’s Direct Send feature to make emails look like they came from the victim organization’s own domain, without compromising an employee account. The campaign was timed to mimic human sending patterns during U.S. Eastern business…

September 14, 2026
CSuite Phish Steals M365 Sessions, Installs RMM

CSuite Phish Steals M365 Sessions, Installs RMM

Researchers observed a real phishing campaign (“CSuite”) heavily targeting U.S. organizations using familiar business-themed lures (DocuSign, Adobe, Zoom/Meet, Dropbox, Microsoft 365). After a victim engages, the attackers either steal Microsoft 365 sessions (enabling mailbox takeover and fraud) or…

September 30, 2026
Fake ChatGPT Invoice Email Steals Logins

Fake ChatGPT Invoice Email Steals Logins

Attackers are sending fake ChatGPT billing emails that pressure people to “update payment” within 48 hours to avoid service interruption. The message links to a convincing look‑alike ChatGPT login page via a Google redirect, aiming to steal OpenAI credentials.

September 18, 2026
Recruiter, RMM, and Vishing Scams Hit Hard

Recruiter, RMM, and Vishing Scams Hit Hard

This weekly roundup includes multiple real-world social-engineering and phishing-style operations, including fake recruiter outreach pushing malicious Android apps, phishing emails that trick users into installing remote management tools, and vishing that reportedly led to compromised Okta…

September 4, 2026
Malicious Calendar Invites Surge With Malware Links

Malicious Calendar Invites Surge With Malware Links

Attackers are sending fake calendar meeting invites that can be automatically added to a victim’s calendar, even if the email is blocked. A documented example used a Google Calendar invite with a financial “invoice credit” lure to drive victims to a hosted webpage and download a malicious…

September 18, 2026