LinkedIn Lures and Vishing Drive Fast AI Attacks

SiliconANGLE Security · High sophistication
Last updated August 5, 2026

CrowdStrike reports multiple real-world campaigns where attackers used human manipulation to break into organizations, including LinkedIn outreach that led to a malicious link click and phone-based scams that pushed victims to fake sign-in pages. The report also describes attackers abusing stolen or compromised identities to rapidly gain access to cloud and AI services, then moving quickly to data theft or large-scale API abuse.

Key findings

  • Attackers approached a Mastra employee on LinkedIn, moved them to a video call, and convinced them to click a malicious link, leading to malicious npm dependency injection across AI framework packages.
  • Vishing increased significantly, and some groups used phone calls to push targets to spoofed single sign-on pages on personal mobile devices, followed by rapid account takeover and data theft.
  • The report describes attackers hijacking access to corporate large language models (“LLMjacking”) by escalating a compromised identity to admin and rapidly flooding an AI model API with requests.

Who’s being targeted

  • Commonly targeted roles: All employees, Engineering, DevOps, IT helpdesk / IT support, Executives, Finance.
  • Affected industries: Technology, Financial services, Academic institutions, Software development / DevOps (software supply chain).
  • Attack channels: linkedin, vishing, website.
  • Impersonated: A legitimate-looking professional contact (e.g., recruiter/partner) met on LinkedIn, IT/SSO support (spoofed single sign-on experience).

Awareness takeaways

  • Treat LinkedIn outreach that quickly pushes you into a call and a link-click as a high-risk interaction; verify the person and avoid clicking links shared live.
  • Do not follow login instructions from an unsolicited phone call, use only your company’s known sign-in URLs and official support channels.
  • Assume attackers can move from stolen credentials to data theft very quickly; report suspected account compromise immediately.

Red flags to watch for

  • Unsolicited LinkedIn outreach that quickly escalates to an off-platform call
  • Pressure to click a link during a live conversation
  • Link not associated with an official company domain or verified channel
  • Unexpected security call that instructs login via a link/page provided by the caller
  • Request to use a personal device for corporate sign-in
  • Single sign-on page URL does not match the organization’s known login address
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

LinkedIn message: “Can you jump on a quick video call to discuss something?” That invite might be the entire breach. CrowdStrike saw this play out at Mastra: a “recruiter” meets an employee on LinkedIn, jumps to video, then drops a link in chat. One click, and a malicious npm dependency was injected into 131 Mastra AI framework packages. Same playbook with vishing: a call says, “Please open this sign-in page on your personal mobile device to fix the issue.” Targets are steered to a spoofed single sign-on page, and Snarky Spider went from account takeover to data theft in under five minutes. Your move: if someone on LinkedIn or a caller tells you to click a link or log in to “fix” something, hang up, close the call, and go to our official login or help portal yourself, then report it.

Similar attacks

AI “Apple Support” Calls Steal iPhone Passcodes

AI “Apple Support” Calls Steal iPhone Passcodes

Researchers say a phishing-as-a-service platform called AnonyMousKIT targets people who recently lost or had an iPhone stolen by pretending to be “Apple Support.” The operation uses email/SMS/WhatsApp and AI-assisted voice calls to convince victims to share their iPhone passcode and follow a…

August 26, 2026
Passkey Helpdesk Scam Hijacks Microsoft 365

Passkey Helpdesk Scam Hijacks Microsoft 365

Microsoft reports active intrusions where attackers trick employees with “passkey/SSO update” helpdesk pretexts delivered by phone, SMS, or even Microsoft Teams. Victims are sent to lookalike Microsoft sign-in pages or guided through device-code sign-in, letting attackers capture session access and…

September 9, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026
Deepfake FBI Videos Push Victims to Fake IC3 Sites

Deepfake FBI Videos Push Victims to Fake IC3 Sites

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into sharing more personal and financial information. In one example, victims are contacted on Facebook Messenger by someone posing as an FBI…

July 21, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026