Recent Professional Services Cyber Attacks

Attacks on consultancies, accounting firms, and other professional services providers that hold sensitive client data. Each entry is broken down with an original video explainer, key findings, and the red flags your team should watch for. How we produce these.

Fake Job Interview Repo Tricks DevOps Into Malware

Fake Job Interview Repo Tricks DevOps Into Malware

North Korea–linked "Jade Sleet" used job interview-style coding projects to trick developers into running malicious infrastructure code. The lure involved GitHub repositories that contained a weaponized Terraform file, leading to downloads from attacker-controlled domains and installation of macOS…

September 21, 2026
Fake Recruiters Hit Job Seekers With Malware Files

Fake Recruiters Hit Job Seekers With Malware Files

An alleged North Korean operation called “WaterPlum” targeted job seekers by posing as AI and blockchain companies and using the interview process to trick applicants into downloading malicious files. Authorities say the campaign infected tens of thousands of devices worldwide and led to theft from…

September 18, 2026
Fake Job Interviews Backdoor 30,000 Devices

Fake Job Interviews Backdoor 30,000 Devices

An international advisory says North Korea–linked actors posing as recruiters tricked jobseekers into downloading “coding assignments” during fake interview processes. Opening the files installed backdoors and malware, enabling theft from over 7,000 crypto wallets and supporting at least $10.71M in…

September 18, 2026
Fake ChatGPT Invoice Email Steals Logins

Fake ChatGPT Invoice Email Steals Logins

Attackers are sending fake ChatGPT billing emails that pressure people to “update payment” within 48 hours to avoid service interruption. The message links to a convincing look‑alike ChatGPT login page via a Google redirect, aiming to steal OpenAI credentials.

September 18, 2026
Prompt Injection Steals Agent Vault Secrets

Prompt Injection Steals Agent Vault Secrets

Unit 42 showed that default AWS AgentCore Harness settings can let an attacker use prompt injection to trick an AI agent into running shell commands and exposing plaintext credentials from AgentCore Identity at runtime. In their demo, a malicious support ticket embedded instructions (via hidden…

September 18, 2026
Fake Claude Download Ads Push Infostealer

Fake Claude Download Ads Push Infostealer

A researcher found fake Claude “download” pages hosted on claude.ai and promoted via paid Google Ads. The pages tricked users into clicking “download” and running an install command that actually installed an information-stealing malware, leveraging the trust of a legitimate domain and…

September 17, 2026
Fake ChatGPT Invoice Steals Login Credentials

Fake ChatGPT Invoice Steals Login Credentials

Cofense observed a real phishing email that impersonates OpenAI/ChatGPT billing to trick users into “updating” payment details. The email uses the real ChatGPT logo, urgency (“48 hours”), and a prominent button to drive clicks to a lookalike ChatGPT login page. Any credentials entered are harvested…

September 17, 2026
Fake Helpdesk Passkey Setup Steals Cloud Access

Fake Helpdesk Passkey Setup Steals Cloud Access

The article describes real intrusions where attackers impersonate a company helpdesk and lure employees into "passkey, MFA, or SSO setup" steps. Victims are sent links via text (often to personal phones), leading to account takeover through adversary-in-the-middle phishing or device-code…

September 16, 2026
N0va Phishkit Uses Trusted Apps to Steal SSO Access

N0va Phishkit Uses Trusted Apps to Steal SSO Access

A phishing kit dubbed N0va is targeting organizations in North America and Europe by impersonating familiar business services (like Microsoft Teams/SharePoint and DocuSign) and pushing victims through legitimate sign-in flows. By capturing authentication tokens rather than dropping obvious malware,…

September 16, 2026
AI Assistant Tricked Into Leaking GitHub Repos

AI Assistant Tricked Into Leaking GitHub Repos

A Mandiant assessment showed an internal AI assistant could be socially engineered into abusing its legitimate access. Testers convinced the agent it was part of an authorized security test and gave it a GitHub token, leading it to clone sensitive internal repositories and push them to an external…

September 16, 2026
Rogue ScreenConnect Clients Spread Worm-Like Attack

Rogue ScreenConnect Clients Spread Worm-Like Attack

Attackers exploited a critical flaw in ConnectWise ScreenConnect and used social engineering to trick people into running a modified (rogue) ScreenConnect client. Once executed, the rogue client looked for active remote sessions and pushed VBScript files to connected systems to spread further.…

September 14, 2026
Passkey Helpdesk Scam Hijacks Microsoft Accounts

Passkey Helpdesk Scam Hijacks Microsoft Accounts

Microsoft described two real-world campaigns: an invoice fraud blast impersonating executives to trick finance teams into ACH payments, and a passkey-themed helpdesk scam that steals or bypasses authentication to take over Microsoft cloud accounts. In the second campaign, victims are called or…

September 13, 2026
N0va Device-Code Phish Steals Microsoft Sessions

N0va Device-Code Phish Steals Microsoft Sessions

Researchers reported a real phishing operation (“N0va” phishkit) that tricks people into signing into Microsoft through a legitimate Microsoft page, but for an attacker-started session. Victims can complete MFA and still grant the attacker access and refresh tokens, letting the attacker operate as…

September 11, 2026
Iranian Hackers Use Fake Recruiter Coding Test

Iranian Hackers Use Fake Recruiter Coding Test

A suspected Iranian government-backed hacking group approached people while pretending to be recruiters, then used a “coding challenge” as the hook to get targets to run malicious code. Victims were sent a ZIP file containing a trojanized Node.js project that infects the machine when it’s…

September 11, 2026
Spy Groups Phish Victims Into Chrome Exploit Kit

Spy Groups Phish Victims Into Chrome Exploit Kit

Researchers reported four separate espionage groups using the same “BlueMoon” exploit kit within days, targeting organizations in the US and Southeast Asia. The attacks began with phishing emails that lured recipients to attacker-controlled websites, where Chrome and Windows vulnerabilities were…

September 10, 2026
AI-Assisted CEO Invoice Scam Pushes $50K ACH

AI-Assisted CEO Invoice Scam Pushes $50K ACH

Microsoft reports a real, large-scale email campaign that impersonated company executives and ServiceNow to pressure accounts payable teams into sending nearly $50,000 via ACH/bank transfer. The emails bundled a CEO “approval,” a fake ServiceNow-branded invoice, and a fabricated forwarded thread to…

September 10, 2026
BlueMoon Phishing Uses Browser Zero-Days to Spy

BlueMoon Phishing Uses Browser Zero-Days to Spy

Multiple suspected China-linked espionage groups used a new exploit kit (“BlueMoon”) that starts with phishing emails and a malicious link to break into organizations in the US and Southeast Asia. Clicking the link can trigger browser and Windows vulnerabilities to install surveillance tools,…

September 9, 2026
Hidden Prompts Hijack ChatGPT Connected Apps

Hidden Prompts Hijack ChatGPT Connected Apps

Check Point demonstrated a prompt-injection technique where a hidden instruction inside ChatGPT can make a user’s session quietly run extra tasks using the session’s existing permissions. In the proof of concept, the victim’s ChatGPT (with Gmail connected) pulled email data and relayed it to an…

September 9, 2026
Spy Groups Lured Victims to BlueMoon Exploit Links

Spy Groups Lured Victims to BlueMoon Exploit Links

Proofpoint reports multiple espionage-focused threat groups used a shared exploit kit (“BlueMoon”) after tricking targets with spear-phishing emails to click malicious links. Visiting the attacker-controlled web pages triggered Chrome and Windows exploits to install malware (including a fake…

September 9, 2026
BigBear 2.0 Steals M365 Sessions to Bypass MFA

BigBear 2.0 Steals M365 Sessions to Bypass MFA

Researchers say the “BigBear 2.0” phishing-as-a-service operation compromised Microsoft 365 accounts by stealing authenticated session cookies after users completed MFA normally. This let attackers replay the session and access accounts without triggering another MFA prompt, impacting 258…

September 8, 2026
Try Mirage

Mirage simulates attacks like these against your own team, live and safely, so you can measure how your people actually respond.

Get a demo