Recent Professional Services Cyber Attacks

Attacks on consultancies, accounting firms, and other professional services providers that hold sensitive client data. Each entry is broken down with an original video explainer, key findings, and the red flags your team should watch for. How we produce these.

Spy Groups Phish Victims Into Chrome Exploit Kit

Spy Groups Phish Victims Into Chrome Exploit Kit

Researchers reported four separate espionage groups using the same “BlueMoon” exploit kit within days, targeting organizations in the US and Southeast Asia. The attacks began with phishing emails that lured recipients to attacker-controlled websites, where Chrome and Windows vulnerabilities were…

September 10, 2026
AI-Assisted CEO Invoice Scam Pushes $50K ACH

AI-Assisted CEO Invoice Scam Pushes $50K ACH

Microsoft reports a real, large-scale email campaign that impersonated company executives and ServiceNow to pressure accounts payable teams into sending nearly $50,000 via ACH/bank transfer. The emails bundled a CEO “approval,” a fake ServiceNow-branded invoice, and a fabricated forwarded thread to…

September 10, 2026
BlueMoon Phishing Uses Browser Zero-Days to Spy

BlueMoon Phishing Uses Browser Zero-Days to Spy

Multiple suspected China-linked espionage groups used a new exploit kit (“BlueMoon”) that starts with phishing emails and a malicious link to break into organizations in the US and Southeast Asia. Clicking the link can trigger browser and Windows vulnerabilities to install surveillance tools,…

September 9, 2026
Hidden Prompts Hijack ChatGPT Connected Apps

Hidden Prompts Hijack ChatGPT Connected Apps

Check Point demonstrated a prompt-injection technique where a hidden instruction inside ChatGPT can make a user’s session quietly run extra tasks using the session’s existing permissions. In the proof of concept, the victim’s ChatGPT (with Gmail connected) pulled email data and relayed it to an…

September 9, 2026
Spy Groups Lured Victims to BlueMoon Exploit Links

Spy Groups Lured Victims to BlueMoon Exploit Links

Proofpoint reports multiple espionage-focused threat groups used a shared exploit kit (“BlueMoon”) after tricking targets with spear-phishing emails to click malicious links. Visiting the attacker-controlled web pages triggered Chrome and Windows exploits to install malware (including a fake…

September 9, 2026
BigBear 2.0 Steals M365 Sessions to Bypass MFA

BigBear 2.0 Steals M365 Sessions to Bypass MFA

Researchers say the “BigBear 2.0” phishing-as-a-service operation compromised Microsoft 365 accounts by stealing authenticated session cookies after users completed MFA normally. This let attackers replay the session and access accounts without triggering another MFA prompt, impacting 258…

September 8, 2026
Fake IT Help-Desk Calls Steal M365 Sessions

Fake IT Help-Desk Calls Steal M365 Sessions

Arctic Wolf reports a wave of phone-based social engineering where attackers pose as internal IT, guide executives through “routine” MFA/passkey setup, and then send a company-branded login link that steals Microsoft 365 credentials and session tokens. Once inside, attackers methodically inventory…

September 8, 2026
BigBear 2.0 Steals M365 Sessions After MFA

BigBear 2.0 Steals M365 Sessions After MFA

CloudSEK reported a phishing-as-a-service operation (“BigBear 2.0”) that tricks Microsoft 365 users into signing in and completing MFA on a lookalike login page. Even though MFA succeeds, the attackers capture the authenticated session cookie and reuse it to access the victim’s Microsoft 365…

September 8, 2026
BigBear 2.0 PhaaS Steals 5,100+ M365 Logins

BigBear 2.0 PhaaS Steals 5,100+ M365 Logins

Researchers say the “BigBear 2.0” phishing-as-a-service operation stole over 5,100 Microsoft 365 credential records across 461 organizations by capturing passwords and session cookies. The campaign used an adversary-in-the-middle setup to bypass MFA and maintain access, with stolen data sent to…

September 8, 2026
Fake IT Help Desk Calls Steal M365 Data, Extort

Fake IT Help Desk Calls Steal M365 Data, Extort

Threat actors are calling employees while pretending to be internal IT/help desk staff and directing them to fake Microsoft 365 login pages. The goal is to capture credentials and MFA approvals, steal session tokens, then access and exfiltrate data from SaaS services like SharePoint, OneDrive, and…

September 7, 2026
Fake “Google Security” Calls Abuse Real Gmail Alerts

Fake “Google Security” Calls Abuse Real Gmail Alerts

A scammer called a Gmail user pretending to be Google’s security team and used real Google account-recovery emails to make the story believable. The attacker first triggered legitimate Google verification and security-alert messages, then tried to pressure the victim during the phone call into…

September 5, 2026
Invisible Unicode Used to Evade Finance Phishing Filters

Invisible Unicode Used to Evade Finance Phishing Filters

Microsoft researchers reported a real, high-volume phishing campaign that used invisible Unicode “tag” characters to break up finance-related lure words (like “funding”) so email filters wouldn’t detect them. The emails looked normal to recipients but contained hidden characters in the underlying…

September 3, 2026
Fake CAPTCHA “Fix” Tricks Users Into Running Malware

Fake CAPTCHA “Fix” Tricks Users Into Running Malware

Multiple real-world intrusions used a ClickFix-style lure where victims visiting compromised websites saw fake CAPTCHA prompts and were tricked into running a command themselves. Separately, attackers also abused the legitimate, signed Node.js runtime (node.exe) to run malicious JavaScript while…

September 3, 2026
Fake Recruiters Push Malware Git Repos

Fake Recruiters Push Malware Git Repos

The article describes real-world scams where attackers pose as recruiters on LinkedIn and send developers “take-home assessment” code repositories that contain hidden malware triggers. Simply cloning and opening the project in an IDE or coding agent can execute malicious hooks/configs that download…

September 3, 2026
Stolen API Key Ran Up $600K AI Usage at METR

Stolen API Key Ran Up $600K AI Usage at METR

AI research non-profit METR disclosed two real security incidents. In one, attackers got access to an exposed system and used an AI agent to reveal an API key, then burned through about $600,000 in AI credits over weeks. In a separate incident, METR observed systematic probing of its public…

September 2, 2026
Fake Freelancer Accounts Pushed Malicious Excel Macros

Fake Freelancer Accounts Pushed Malicious Excel Macros

U.S. prosecutors say a Russian national used hundreds of fake accounts on a freelance platform to send Excel files that tricked users into enabling macros, which then downloaded remote-control malware. The campaign targeted tens of thousands of users and led to thousands of infections, enabling…

September 2, 2026
Fake Recruiters Push “Coding Tests” as RAT Traps

Fake Recruiters Push “Coding Tests” as RAT Traps

Researchers say the Iran-linked group Nimbus Manticore posed as recruiters on LinkedIn and job platforms to send developers “technical challenge” ZIP files that secretly installed cross-platform remote access trojans. The lures used urgency (short test windows) and realistic developer workflows…

September 1, 2026
Fake Recruiter Lure Drops NodeRabbit RAT

Fake Recruiter Lure Drops NodeRabbit RAT

Researchers tied Mirage Kitten to a job-recruiting scam that targets developers via LinkedIn and job platforms. Victims are sent a “technical assessment” ZIP file hosted on legitimate cloud storage; running the project silently installs a remote-access trojan (NodeRabbit) that lets attackers…

September 1, 2026
Aurora Gang Email-Bombs Staff, Poses as IT Helpdesk

Aurora Gang Email-Bombs Staff, Poses as IT Helpdesk

Researchers tied to the Aurora ransomware group described a real intrusion that started with aggressive email bombing, then phone calls where attackers posed as the IT help desk to “help” employees fix the issue. Separate reporting shows the same group used the Cursor AI coding assistant to plan…

August 31, 2026
Arup Deepfake Call Triggers $25M Transfer

Arup Deepfake Call Triggers $25M Transfer

The article warns that AI is making impersonation and social engineering more convincing, citing a real 2024 case where Arup was reportedly tricked during a video conference featuring a digitally cloned senior manager. The core lesson is to validate requests through policy and independent…

August 28, 2026
Try Mirage

Mirage simulates attacks like these against your own team, live and safely, so you can measure how your people actually respond.

Get a demo