CrowdStrike reports multiple real-world campaigns where attackers used human manipulation to break into organizations, including LinkedIn outreach that led to a malicious link click and phone-based scams that pushed victims to fake sign-in pages. The report also describes attackers abusing stolen or compromised identities to rapidly gain access to cloud and AI services, then moving quickly to data theft or large-scale API abuse.
Key findings
- Attackers approached a Mastra employee on LinkedIn, moved them to a video call, and convinced them to click a malicious link, leading to malicious npm dependency injection across AI framework packages.
- Vishing increased significantly, and some groups used phone calls to push targets to spoofed single sign-on pages on personal mobile devices, followed by rapid account takeover and data theft.
- The report describes attackers hijacking access to corporate large language models (“LLMjacking”) by escalating a compromised identity to admin and rapidly flooding an AI model API with requests.
Who’s being targeted
- Commonly targeted roles: All employees, Engineering, DevOps, IT helpdesk / IT support, Executives, Finance.
- Affected industries: Technology, Financial services, Academic institutions, Software development / DevOps (software supply chain).
- Attack channels: linkedin, vishing, website.
- Impersonated: A legitimate-looking professional contact (e.g., recruiter/partner) met on LinkedIn, IT/SSO support (spoofed single sign-on experience).
Awareness takeaways
- Treat LinkedIn outreach that quickly pushes you into a call and a link-click as a high-risk interaction; verify the person and avoid clicking links shared live.
- Do not follow login instructions from an unsolicited phone call, use only your company’s known sign-in URLs and official support channels.
- Assume attackers can move from stolen credentials to data theft very quickly; report suspected account compromise immediately.
Red flags to watch for
- Unsolicited LinkedIn outreach that quickly escalates to an off-platform call
- Pressure to click a link during a live conversation
- Link not associated with an official company domain or verified channel
- Unexpected security call that instructs login via a link/page provided by the caller
- Request to use a personal device for corporate sign-in
- Single sign-on page URL does not match the organization’s known login address
Read the video transcript
LinkedIn message: “Can you jump on a quick video call to discuss something?” That invite might be the entire breach. CrowdStrike saw this play out at Mastra: a “recruiter” meets an employee on LinkedIn, jumps to video, then drops a link in chat. One click, and a malicious npm dependency was injected into 131 Mastra AI framework packages. Same playbook with vishing: a call says, “Please open this sign-in page on your personal mobile device to fix the issue.” Targets are steered to a spoofed single sign-on page, and Snarky Spider went from account takeover to data theft in under five minutes. Your move: if someone on LinkedIn or a caller tells you to click a link or log in to “fix” something, hang up, close the call, and go to our official login or help portal yourself, then report it.