Job Offer & Doc-Link Phishing Drive Real Breaches

Check Point Research · High sophistication
Last updated August 18, 2026

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and trojanized software to infect defense organizations, an approach that can be recreated for employee training.

How the Attacks Worked

Two distinct but related patterns emerge from this reporting. In the first, an employee at IEH Corporation, a defense and aerospace component manufacturer, received a fraudulent document-sharing link. Clicking it led to a fake Microsoft 365 login page, and entering credentials there gave attackers access to the mailbox. This type of attack does not rely on malware at all, just a convincing pretext and a login prompt.

In the second pattern, tied to the Lazarus-linked Operation Dream Job, attackers used fake job opportunities to reach engineers and defense program staff. Instead of a credential-harvesting link, the payload was trojanized 'PDF software' that, once opened, deployed malware onto the target's system.

A third data point, from Levi Strauss & Co., shows that social engineering does not need to involve a phishing link or malware installer at all. Attackers used social engineering to compromise three employee devices directly and steal corporate information.

Why These Attacks Succeeded

Each scenario exploits a routine workplace behavior that employees rarely question:

  • Reviewing a shared document from what looks like a business contact
  • Considering a job opportunity that appears relevant to their skills
  • Trusting normal-seeming requests without independent verification

Because these pretexts mimic everyday tasks, such as viewing files or reviewing career opportunities, they bypass the skepticism people typically reserve for obviously suspicious emails.

What to Watch For

Defenders and employees should be alert to:

  • Unexpected document shares tied to purchase orders, engineering files, or contracts you weren't expecting
  • Links that lead to a login prompt asking for corporate credentials rather than displaying a file directly
  • Unsolicited job offers, especially for sensitive or defense-related roles, that ask you to install or run unfamiliar software
  • Any message creating urgency to review documents or respond to a job offer quickly

Building Resistance

Organizations, particularly in defense, aerospace, and manufacturing, can reduce risk by training employees to verify unexpected document-share requests before entering credentials, and to treat unsolicited recruiting outreach with the same scrutiny as any unknown attachment. Reporting suspicious interactions immediately, even when no data appears to have been exposed, helps security teams respond before an initial compromise escalates. Since these incidents show that both credential phishing and direct social engineering can lead to real corporate data loss, awareness training should cover both technical red flags, like unexpected login prompts, and human-behavior red flags, like recruiter contact regarding roles the employee did not apply for.

Key findings

  • Levi Strauss reported attackers used social engineering to compromise three employee devices and steal corporate information.
  • IEH Corporation confirmed a phishing compromise of an employee’s Microsoft 365 mailbox using a fraudulent document-sharing link to steal credentials.
  • Operation Dream Job (Lazarus-linked) used fraudulent job opportunities and trojanized PDF software to deploy malware against defense organizations.

Who’s being targeted

  • Commonly targeted roles: All employees, Engineering, Defense/Aerospace program teams, HR/Recruiting, Executives, IT/Helpdesk.
  • Affected industries: Government, Healthcare, Retail/Apparel, Defense/Aerospace Manufacturing, Energy.
  • Attack channels: email.
  • Impersonated: Document-sharing service / business contact, Recruiter / hiring team for a job opportunity.

Red flags to watch for

  • Unexpected document share or purchase/engineering context you weren’t expecting
  • Link leads to a login prompt asking for corporate credentials
  • Sender pressure or urgency to review documents quickly
  • Unsolicited job offer tied to sensitive/defense roles
  • Request to install or run “PDF software” rather than using standard PDF viewing
  • Unexpected attachments or installers presented as recruiting materials
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers compromise IEH Corporation?

Attackers sent a fraudulent document-sharing link that led an employee to a fake login page, stealing their Microsoft 365 credentials and potentially exposing engineering and export-controlled data.

What is Operation Dream Job?

Operation Dream Job is a Lazarus-linked campaign that uses fraudulent job opportunities and trojanized PDF software to deploy malware against defense organizations in Europe, India, and Brazil.

Did Levi Strauss suffer a data breach?

Levi Strauss reported that attackers used social engineering to compromise three employee devices and steal corporate information.

What red flags indicate a document-sharing phishing attempt?

Watch for unexpected document shares, links that prompt a corporate login, and messages that pressure you to act quickly on unfamiliar purchase or engineering content.

Read the video transcript

Levi Strauss and a defense supplier were breached the same way: someone trusted a link and a file they shouldn't have. At IEH, a defense manufacturer, one click on a fake document‑sharing link led to a Microsoft 365 login page. The employee entered their password, and their mailbox, and sensitive engineering documents, were exposed. In Operation Dream Job, targets get an email from a 'recruiter' for a sensitive defense role. The catch: to see the job details, you have to install their special 'PDF software', which is actually malware. Aha moment: if a link or job email makes you log in or install software unexpectedly, stop. Do not click or install, forward it to the security team and ask them to check it.

Similar attacks

Lazarus Lures Staff With Fake Jobs to Drop Malware

Lazarus Lures Staff With Fake Jobs to Drop Malware

Researchers tied North Korea’s Lazarus Group to a real-world campaign that approaches professionals with convincing fake recruiter outreach and job offers. Victims are tricked into opening a malicious PDF or installing a fake PDF viewer from lookalike websites, which then installs backdoors and can…

August 12, 2026
Hotel WiFi Scam Pushes Fake Updates and Malware

Hotel WiFi Scam Pushes Fake Updates and Malware

A Russia-linked threat group compromised hotel WiFi captive portals to redirect guests to fake “verification” pages. Victims were pushed toward either copying commands into a terminal to install malware or entering Microsoft credentials on spoofed login pages that added an attacker-controlled…

August 7, 2026
Zero-Click Prompts Hijack AI Browsers via Email/X

Zero-Click Prompts Hijack AI Browsers via Email/X

Zenity demonstrated real-world attack chains where hidden instructions in emails or content on X can hijack AI “agentic browsers” (ChatGPT Atlas and the Claude Chrome extension). In the demos, the AI agent can be steered to perform actions in the user’s already logged-in sessions, sending phishing…

August 6, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Vishing “Help Desk” Scams and Lookalike Phish Surge

Vishing “Help Desk” Scams and Lookalike Phish Surge

This weekly roundup highlights multiple real-world social engineering threats, including fake IT help-desk phone calls that push employees to phishing sites to steal passwords and one-time authentication codes. It also describes credential-phishing sites impersonating WhatsApp and Instagram that…

August 14, 2026