Recent Professional Services Cyber Attacks

Page 2 of 6
Fake IT Help-Desk Calls Steal M365 Sessions

Fake IT Help-Desk Calls Steal M365 Sessions

Arctic Wolf reports a wave of phone-based social engineering where attackers pose as internal IT, guide executives through “routine” MFA/passkey setup, and then send a company-branded login link that steals Microsoft 365 credentials and session tokens. Once inside, attackers methodically inventory…

September 8, 2026
BigBear 2.0 Steals M365 Sessions After MFA

BigBear 2.0 Steals M365 Sessions After MFA

CloudSEK reported a phishing-as-a-service operation (“BigBear 2.0”) that tricks Microsoft 365 users into signing in and completing MFA on a lookalike login page. Even though MFA succeeds, the attackers capture the authenticated session cookie and reuse it to access the victim’s Microsoft 365…

September 8, 2026
BigBear 2.0 PhaaS Steals 5,100+ M365 Logins

BigBear 2.0 PhaaS Steals 5,100+ M365 Logins

Researchers say the “BigBear 2.0” phishing-as-a-service operation stole over 5,100 Microsoft 365 credential records across 461 organizations by capturing passwords and session cookies. The campaign used an adversary-in-the-middle setup to bypass MFA and maintain access, with stolen data sent to…

September 8, 2026
Fake IT Help Desk Calls Steal M365 Data, Extort

Fake IT Help Desk Calls Steal M365 Data, Extort

Threat actors are calling employees while pretending to be internal IT/help desk staff and directing them to fake Microsoft 365 login pages. The goal is to capture credentials and MFA approvals, steal session tokens, then access and exfiltrate data from SaaS services like SharePoint, OneDrive, and…

September 7, 2026
Fake “Google Security” Calls Abuse Real Gmail Alerts

Fake “Google Security” Calls Abuse Real Gmail Alerts

A scammer called a Gmail user pretending to be Google’s security team and used real Google account-recovery emails to make the story believable. The attacker first triggered legitimate Google verification and security-alert messages, then tried to pressure the victim during the phone call into…

September 5, 2026
Invisible Unicode Used to Evade Finance Phishing Filters

Invisible Unicode Used to Evade Finance Phishing Filters

Microsoft researchers reported a real, high-volume phishing campaign that used invisible Unicode “tag” characters to break up finance-related lure words (like “funding”) so email filters wouldn’t detect them. The emails looked normal to recipients but contained hidden characters in the underlying…

September 3, 2026
Fake CAPTCHA “Fix” Tricks Users Into Running Malware

Fake CAPTCHA “Fix” Tricks Users Into Running Malware

Multiple real-world intrusions used a ClickFix-style lure where victims visiting compromised websites saw fake CAPTCHA prompts and were tricked into running a command themselves. Separately, attackers also abused the legitimate, signed Node.js runtime (node.exe) to run malicious JavaScript while…

September 3, 2026
Fake Recruiters Push Malware Git Repos

Fake Recruiters Push Malware Git Repos

The article describes real-world scams where attackers pose as recruiters on LinkedIn and send developers “take-home assessment” code repositories that contain hidden malware triggers. Simply cloning and opening the project in an IDE or coding agent can execute malicious hooks/configs that download…

September 3, 2026
Stolen API Key Ran Up $600K AI Usage at METR

Stolen API Key Ran Up $600K AI Usage at METR

AI research non-profit METR disclosed two real security incidents. In one, attackers got access to an exposed system and used an AI agent to reveal an API key, then burned through about $600,000 in AI credits over weeks. In a separate incident, METR observed systematic probing of its public…

September 2, 2026
Fake Freelancer Accounts Pushed Malicious Excel Macros

Fake Freelancer Accounts Pushed Malicious Excel Macros

U.S. prosecutors say a Russian national used hundreds of fake accounts on a freelance platform to send Excel files that tricked users into enabling macros, which then downloaded remote-control malware. The campaign targeted tens of thousands of users and led to thousands of infections, enabling…

September 2, 2026
Fake Recruiters Push “Coding Tests” as RAT Traps

Fake Recruiters Push “Coding Tests” as RAT Traps

Researchers say the Iran-linked group Nimbus Manticore posed as recruiters on LinkedIn and job platforms to send developers “technical challenge” ZIP files that secretly installed cross-platform remote access trojans. The lures used urgency (short test windows) and realistic developer workflows…

September 1, 2026
Fake Recruiter Lure Drops NodeRabbit RAT

Fake Recruiter Lure Drops NodeRabbit RAT

Researchers tied Mirage Kitten to a job-recruiting scam that targets developers via LinkedIn and job platforms. Victims are sent a “technical assessment” ZIP file hosted on legitimate cloud storage; running the project silently installs a remote-access trojan (NodeRabbit) that lets attackers…

September 1, 2026
Aurora Gang Email-Bombs Staff, Poses as IT Helpdesk

Aurora Gang Email-Bombs Staff, Poses as IT Helpdesk

Researchers tied to the Aurora ransomware group described a real intrusion that started with aggressive email bombing, then phone calls where attackers posed as the IT help desk to “help” employees fix the issue. Separate reporting shows the same group used the Cursor AI coding assistant to plan…

August 31, 2026
Arup Deepfake Call Triggers $25M Transfer

Arup Deepfake Call Triggers $25M Transfer

The article warns that AI is making impersonation and social engineering more convincing, citing a real 2024 case where Arup was reportedly tricked during a video conference featuring a digitally cloned senior manager. The core lesson is to validate requests through policy and independent…

August 28, 2026
DocuSign Share Lure Steals Microsoft 365 Sessions

DocuSign Share Lure Steals Microsoft 365 Sessions

Researchers described an active phishing operation using real DocuSign notifications to trick employees into opening a fake “remittance-advice” document and clicking a hidden malicious link. The attack routes victims through legitimate Microsoft/Google pages before landing on an…

August 28, 2026
Deepfake Video Call Led to $25M Transfer

Deepfake Video Call Led to $25M Transfer

The article explains how generative AI is making phishing and impersonation more convincing, so “bad grammar” is no longer a reliable warning sign. It cites a real case in Hong Kong where fraudsters used deepfake video to impersonate senior colleagues on a video meeting and tricked a finance worker…

August 28, 2026
Tax & Invoice Phish Push Legit RMM in 46 Countries

Tax & Invoice Phish Push Legit RMM in 46 Countries

Researchers reported a real phishing operation spanning 46 countries that tricks people into installing legitimate remote monitoring and management (RMM) tools, giving attackers remote access that can look like normal IT activity. The lures use familiar business themes (tax documents, invoices,…

August 28, 2026
ReliaQuest Hit by Vishing + Fake SSO MFA Push Scam

ReliaQuest Hit by Vishing + Fake SSO MFA Push Scam

ReliaQuest reported a real social-engineering incident where an attacker impersonated a security team member, called employees, and directed them to a fake ReliaQuest SSO login page hosted behind a CDN. One employee entered credentials and approved an MFA push, briefly giving the attacker view-only…

August 27, 2026
Malicious Site Tricks Claude Auto Mode into Running Code

Malicious Site Tricks Claude Auto Mode into Running Code

A researcher demonstrated that a seemingly harmless “summarize this website” request can be turned into a prompt-injection style attack that pushes Claude Code (Auto Mode) into running commands and ultimately executing attacker code. The workflow uses a fake archive site that forces a tool fallback…

August 27, 2026
Fake Recruiters Steal Corporate Logins on Mobile

Fake Recruiters Steal Corporate Logins on Mobile

Scammers posing as HR staff at major brands are luring targets into an interview “scheduling” flow that ultimately steals corporate passwords on mobile devices. The campaign uses a browser-in-the-browser style approach (or a full-screen fake login on phones) and even blocks personal email logins to…

August 26, 2026
Try Mirage

Mirage simulates attacks like these against your own team, live and safely, so you can measure how your people actually respond.

Get a demo