LinkedIn Lures and Vishing Drive Fast AI Attacks

SiliconANGLE Security · High sophistication
Last updated August 5, 2026

CrowdStrike reports multiple real-world campaigns where attackers used human manipulation to break into organizations, including LinkedIn outreach that led to a malicious link click and phone-based scams that pushed victims to fake sign-in pages. The report also describes attackers abusing stolen or compromised identities to rapidly gain access to cloud and AI services, then moving quickly to data theft or large-scale API abuse.

Key findings

  • Attackers approached a Mastra employee on LinkedIn, moved them to a video call, and convinced them to click a malicious link, leading to malicious npm dependency injection across AI framework packages.
  • Vishing increased significantly, and some groups used phone calls to push targets to spoofed single sign-on pages on personal mobile devices, followed by rapid account takeover and data theft.
  • The report describes attackers hijacking access to corporate large language models (“LLMjacking”) by escalating a compromised identity to admin and rapidly flooding an AI model API with requests.

Who’s being targeted

  • Commonly targeted roles: All employees, Engineering, DevOps, IT helpdesk / IT support, Executives, Finance.
  • Affected industries: Technology, Financial services, Academic institutions, Software development / DevOps (software supply chain).
  • Attack channels: linkedin, vishing, website.
  • Impersonated: A legitimate-looking professional contact (e.g., recruiter/partner) met on LinkedIn, IT/SSO support (spoofed single sign-on experience).

Awareness takeaways

  • Treat LinkedIn outreach that quickly pushes you into a call and a link-click as a high-risk interaction; verify the person and avoid clicking links shared live.
  • Do not follow login instructions from an unsolicited phone call, use only your company’s known sign-in URLs and official support channels.
  • Assume attackers can move from stolen credentials to data theft very quickly; report suspected account compromise immediately.

Red flags to watch for

  • Unsolicited LinkedIn outreach that quickly escalates to an off-platform call
  • Pressure to click a link during a live conversation
  • Link not associated with an official company domain or verified channel
  • Unexpected security call that instructs login via a link/page provided by the caller
  • Request to use a personal device for corporate sign-in
  • Single sign-on page URL does not match the organization’s known login address
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

LinkedIn message: “Can you jump on a quick video call to discuss something?” That invite might be the entire breach. CrowdStrike saw this play out at Mastra: a “recruiter” meets an employee on LinkedIn, jumps to video, then drops a link in chat. One click, and a malicious npm dependency was injected into 131 Mastra AI framework packages. Same playbook with vishing: a call says, “Please open this sign-in page on your personal mobile device to fix the issue.” Targets are steered to a spoofed single sign-on page, and Snarky Spider went from account takeover to data theft in under five minutes. Your move: if someone on LinkedIn or a caller tells you to click a link or log in to “fix” something, hang up, close the call, and go to our official login or help portal yourself, then report it.

Similar attacks

AI “Apple Support” Calls Steal iPhone Passcodes

AI “Apple Support” Calls Steal iPhone Passcodes

Researchers say a phishing-as-a-service platform called AnonyMousKIT targets people who recently lost or had an iPhone stolen by pretending to be “Apple Support.” The operation uses email/SMS/WhatsApp and AI-assisted voice calls to convince victims to share their iPhone passcode and follow a…

August 26, 2026
Fake Passkey Updates Used to Hijack M365 Accounts

Fake Passkey Updates Used to Hijack M365 Accounts

Microsoft says attackers have been compromising Microsoft 365 cloud accounts by posing as internal IT staff and pressuring employees to “update” passkeys or sign-in settings. Victims are directed to lookalike sign-in pages or tricked into authorizing attacker access via device-code sign-in, after…

September 18, 2026
Fraudulent Gov Email and Passkey Lures Hit Orgs

Fraudulent Gov Email and Passkey Lures Hit Orgs

The bulletin describes real-world social engineering where staff were tricked into disclosing sensitive data or access. In one case, Revolut employees responded to fraudulent information requests sent from a real government-domain email account, exposing extensive customer records. Separately,…

September 14, 2026
Passkey Helpdesk Scam Hijacks Microsoft Accounts

Passkey Helpdesk Scam Hijacks Microsoft Accounts

Microsoft described two real-world campaigns: an invoice fraud blast impersonating executives to trick finance teams into ACH payments, and a passkey-themed helpdesk scam that steals or bypasses authentication to take over Microsoft cloud accounts. In the second campaign, victims are called or…

September 13, 2026
Passkey Helpdesk Scam Hijacks Microsoft 365

Passkey Helpdesk Scam Hijacks Microsoft 365

Microsoft reports active intrusions where attackers trick employees with “passkey/SSO update” helpdesk pretexts delivered by phone, SMS, or even Microsoft Teams. Victims are sent to lookalike Microsoft sign-in pages or guided through device-code sign-in, letting attackers capture session access and…

September 9, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026