The roundup describes real social-engineering incidents: a phishing email that led an employee to enter credentials on a fake Microsoft 365 login page, and a wave of voice-phishing attempts against major hedge funds using voice-mimicking technology. Both incidents show practical lures that can be recreated for security awareness simulations.
Key findings
- IEH Corporation reports an employee mailbox compromise that started with a phishing message impersonating a prospective business contact and a fake login page.
- Attackers could view mailbox content including purchase orders and engineering files during the access window, though the firm found no evidence of outbound emails or confirmed exfiltration.
- A wave of vishing targeted large hedge funds/private equity firms using voice-mimicking technology to trick staff into granting access or disclosing information.
- Two Sigma reported it blocked the attempt with no impact; Point72 reported reviewing an incident with no initial evidence of client data theft.
Who’s being targeted
- Commonly targeted roles: All employees, Finance (hedge funds/private equity), IT helpdesk / IAM teams, Sales/Business development, Procurement, Engineering, Executive assistants.
- Affected industries: Finance (hedge funds/private equity), Manufacturing (defense/aerospace components), Transportation/Ports and logistics.
- Attack channels: email, website, vishing.
- Impersonated: Prospective business contact (external partner/vendor), Trusted internal leader or known colleague (voice-mimicked).
Awareness takeaways
- Treat unexpected “new business contact” emails as high-risk and verify the sender via a trusted channel before clicking or logging in.
- Never enter work credentials after following a link from an unsolicited message; navigate to Microsoft 365/SSO by typing the known URL or using a bookmark.
- For phone-based requests, require a callback to a known number or an out-of-band verification step, especially for access approvals or sensitive information.
- Train staff that “voice sounds right” is no longer proof of identity; deepfake/voice-mimic fraud is being used in real attacks.
Red flags to watch for
- Unexpected request to log in from an unsolicited contact
- Login page is not the real Microsoft 365 domain/SSO portal
- Message creates urgency or pressure to respond to a new 'business contact' quickly
- Caller insists on bypassing normal verification steps
- Requests for access approvals or sensitive data over the phone
- Unusual urgency or secrecy, especially tied to senior leadership
Read the video transcript
Imagine this: one click on a “new business contact” email, and your entire mailbox is wide open. That’s what hit IEH Corporation: a phishing email posing as a prospective business contact, leading to a fake Microsoft 365 login where the user typed their password, letting someone quietly read emails, purchase orders, even engineering files. Now add this twist: funds like Two Sigma and Point72 are getting phone calls where the voice sounds exactly like a senior leader, because it’s being mimicked, to pressure staff into granting access or sharing data. The voice sounds right, but the caller isn’t. Your move: if a new contact email or a phone request sends you to a login or asks for access, stop and use your own route, type our Microsoft 365 or SSO URL yourself or call back on a known number before you do anything.