
Fake Zoom/Teams Calls Used to Steal Crypto Wallets
North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…
Cofense reports real finance-themed phishing campaigns are shifting from obvious “urgent” language to routine, process-sounding subject lines that blend into daily finance workflows. These emails commonly mimic invoices, remittance advice, procurement requests, and contract/e-sign steps to trick recipients into opening attachments or clicking credential-theft links. The shift makes both employees and email security tools less likely to spot the messages because they look like normal business operations.
Finance-themed phishing campaigns are moving away from obvious urgency cues like "urgent" or "final notice" and toward subject lines that sound like normal parts of a finance workflow. These messages mimic invoices, remittance advice, procurement requests, and contract or e-sign steps. Instead of pressuring a recipient with fear, they rely on the appearance of routine business process to get an attachment opened or a link clicked.
Three narratives dominate these campaigns:
Each narrative fits naturally into daily finance, accounts payable, procurement, or legal work, which is exactly why it succeeds.
Most security awareness training was built to catch emotional pressure tactics, words like "urgent" or "immediate." These campaigns intentionally avoid that language. Data cited in the findings shows operationally styled phishing language accounted for 79% of campaigns in Q1 2026, compared to 21% that used urgency-based wording, and this pattern has held at 59% to 79% across multiple quarters.
The contract-in-progress narrative is particularly effective because it implies continuity rather than asking the recipient to start something new. A recipient may assume the message belongs to a colleague, another department, or an earlier conversation they do not fully recall, which lowers suspicion before any content is even reviewed.
These lures can lead to credential theft through embedded URLs or credential/malware delivery through attachments, including PDFs and QR codes.
Because these campaigns are designed to look like normal business activity, resistance depends less on spotting alarm and more on building a habit of verification for financial process emails.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Because it mimics normal business operations like invoices, remittance advice, and procurement requests, it closely resembles legitimate correspondence and does not trigger the same suspicion that overtly urgent language does.
Watch for remittance and payment statement notices, e-signature or contract approval requests, and unsolicited RFP/RFQ invitations, especially when they come from unfamiliar or external senders.
According to the findings, operationally styled phishing language accounted for 79% of campaigns in Q1 2026, compared to 21% that used urgency-based language.
Add verification steps before opening attachments or links in finance workflows, and update awareness training and simulations to include routine, process-sounding subject lines rather than only urgent ones.
That boring email in your inbox titled “Wire Payment – Remittance Advice Attached”? That’s today’s phishing trap. Cofense says 79% of finance phish now use routine language, remittance, statements, approvals, instead of “URGENT” or “final notice,” so they blend right into real invoices and vendor emails. You open a PDF called “eSiqnature Request on Behalf Of… Contract Approval and EFT Remit Advice 34870.pdf”. It asks you to sign in to view the contract, that sign-in page is where your credentials get stolen. If a finance email about remittance, statements, or contracts is unexpected, stop: don’t open the attachment or link, forward it to the security team and confirm it first.

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Cofense reports that attackers target finance teams with phishing emails designed to look like normal invoices, contracts, and payment notices, not urgent “act…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

Cofense observed a real phishing campaign impersonating Google Ads Sync Accounts (MMC) with a fake “maintenance/system upgrade” notice. The email pressures…

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in…