LinkedIn Lures and Vishing Drive Fast AI Attacks

SiliconANGLE Security · High sophistication
Last updated August 5, 2026

CrowdStrike reports multiple real-world campaigns where attackers used human manipulation to break into organizations, including LinkedIn outreach that led to a malicious link click and phone-based scams that pushed victims to fake sign-in pages. The report also describes attackers abusing stolen or compromised identities to rapidly gain access to cloud and AI services, then moving quickly to data theft or large-scale API abuse.

Key findings

  • Attackers approached a Mastra employee on LinkedIn, moved them to a video call, and convinced them to click a malicious link, leading to malicious npm dependency injection across AI framework packages.
  • Vishing increased significantly, and some groups used phone calls to push targets to spoofed single sign-on pages on personal mobile devices, followed by rapid account takeover and data theft.
  • The report describes attackers hijacking access to corporate large language models (“LLMjacking”) by escalating a compromised identity to admin and rapidly flooding an AI model API with requests.

Who’s being targeted

  • Commonly targeted roles: All employees, Engineering, DevOps, IT helpdesk / IT support, Executives, Finance.
  • Affected industries: Technology, Financial services, Academic institutions, Software development / DevOps (software supply chain).
  • Attack channels: linkedin, vishing, website.
  • Impersonated: A legitimate-looking professional contact (e.g., recruiter/partner) met on LinkedIn, IT/SSO support (spoofed single sign-on experience).

Awareness takeaways

  • Treat LinkedIn outreach that quickly pushes you into a call and a link-click as a high-risk interaction; verify the person and avoid clicking links shared live.
  • Do not follow login instructions from an unsolicited phone call, use only your company’s known sign-in URLs and official support channels.
  • Assume attackers can move from stolen credentials to data theft very quickly; report suspected account compromise immediately.

Red flags to watch for

  • Unsolicited LinkedIn outreach that quickly escalates to an off-platform call
  • Pressure to click a link during a live conversation
  • Link not associated with an official company domain or verified channel
  • Unexpected security call that instructs login via a link/page provided by the caller
  • Request to use a personal device for corporate sign-in
  • Single sign-on page URL does not match the organization’s known login address
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

LinkedIn message: “Can you jump on a quick video call to discuss something?” That invite might be the entire breach. CrowdStrike saw this play out at Mastra: a “recruiter” meets an employee on LinkedIn, jumps to video, then drops a link in chat. One click, and a malicious npm dependency was injected into 131 Mastra AI framework packages. Same playbook with vishing: a call says, “Please open this sign-in page on your personal mobile device to fix the issue.” Targets are steered to a spoofed single sign-on page, and Snarky Spider went from account takeover to data theft in under five minutes. Your move: if someone on LinkedIn or a caller tells you to click a link or log in to “fix” something, hang up, close the call, and go to our official login or help portal yourself, then report it.

Similar attacks

Deepfake FBI Videos Push Victims to Fake IC3 Sites

Deepfake FBI Videos Push Victims to Fake IC3 Sites

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into sharing more personal and financial information. In one example, victims are contacted on Facebook Messenger by someone posing as an FBI…

July 21, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Fake Teams “Update” Led to $630K Crypto Theft

Fake Teams “Update” Led to $630K Crypto Theft

AI firm ORO says a suspected North Korean attacker hijacked a real conference contact’s Telegram account and lured an employee into joining a fake Microsoft Teams call link. After the call “had no working audio,” the victim approved what looked like a Teams update, which installed a malicious…

July 21, 2026
Fake Screenshot ZIP Led to DigiCert Cert Theft

Fake Screenshot ZIP Led to DigiCert Cert Theft

Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a customer support chat. The attackers then abused DigiCert’s support portal features to intercept EV code-signing certificate “initialization…

July 17, 2026
AiTM Phishing Now #1 Break-In Method for Law Firms

AiTM Phishing Now #1 Break-In Method for Law Firms

A legal-sector threat intel report says adversary-in-the-middle (AiTM) phishing is now the most common way attackers gain initial access to law firms, because it can bypass MFA by stealing valid session cookies. The report highlights deadline-driven lures (fake document/court portal errors) and…

July 31, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026