Recent Technology Cyber Attacks

Page 2 of 16
Fake ChatGPT Billing Email Steals OpenAI Logins

Fake ChatGPT Billing Email Steals OpenAI Logins

A phishing email posing as a ChatGPT billing notice pressures users to “update payment information” to avoid service interruption. The button routes through a Google redirect and lands on a fake OpenAI login page that captures usernames and passwords before sending victims to an error page.

September 17, 2026
Fake Claude Download Ads Push Infostealer

Fake Claude Download Ads Push Infostealer

A researcher found fake Claude “download” pages hosted on claude.ai and promoted via paid Google Ads. The pages tricked users into clicking “download” and running an install command that actually installed an information-stealing malware, leveraging the trust of a legitimate domain and…

September 17, 2026
Fake ChatGPT Invoice Steals Login Credentials

Fake ChatGPT Invoice Steals Login Credentials

Cofense observed a real phishing email that impersonates OpenAI/ChatGPT billing to trick users into “updating” payment details. The email uses the real ChatGPT logo, urgency (“48 hours”), and a prominent button to drive clicks to a lookalike ChatGPT login page. Any credentials entered are harvested…

September 17, 2026
AI Scammer Hijacks Band’s Spotify via Distributor

AI Scammer Hijacks Band’s Spotify via Distributor

A journalist showed how easy it is to upload AI-generated songs onto a real artist’s official Spotify page by abusing weak identity checks in digital music distribution. By claiming to be the band during a distributor signup/upload process, the uploader can publish fake tracks to major streaming…

September 17, 2026
Fake T-Mobile Points Expiry Texts Hit Phones

Fake T-Mobile Points Expiry Texts Hit Phones

A large phishing (smishing) campaign is sending messages that claim a T-Mobile customer’s rewards points are about to expire. The texts use urgency, made-up point balances, and lookalike “t-mobile.*.top” links to push people into clicking and entering sensitive information. Malwarebytes observed…

September 17, 2026
Fake Avast Renewal Page Feeds a Support Scam

Fake Avast Renewal Page Feeds a Support Scam

Malwarebytes found a convincing fake “Avast Premium Security” renewal page targeting users in Belgium, claiming a €129.99 renewal and pushing visitors toward a cancellation flow. The real goal is to harvest a victim’s name, email, and mobile number so scammers can call next while posing as support…

September 17, 2026
Iranian “Chosen Brick” Lures Sent via Telegram

Iranian “Chosen Brick” Lures Sent via Telegram

UK, US, and Dutch agencies warned that Iranian state-linked actors used social messaging apps to build trust with dissidents, journalists, and activists before sending disguised files that install Windows malware. The attackers often impersonated someone the target already knows or “technical…

September 17, 2026
Fake Helpdesk Passkey Setup Steals Cloud Access

Fake Helpdesk Passkey Setup Steals Cloud Access

The article describes real intrusions where attackers impersonate a company helpdesk and lure employees into "passkey, MFA, or SSO setup" steps. Victims are sent links via text (often to personal phones), leading to account takeover through adversary-in-the-middle phishing or device-code…

September 16, 2026
HBO Max Reddit Ads Hijacked to Spread ClickFix Malware

HBO Max Reddit Ads Hijacked to Spread ClickFix Malware

Attackers compromised HBO Max’s verified Reddit advertising account and used it to run 108 malicious ads in about 48 hours. The ads sent people to attacker-controlled websites that used “ClickFix” instructions to trick users into running commands that installed malware on Windows and macOS.

September 16, 2026
N0va Phishkit Uses Trusted Apps to Steal SSO Access

N0va Phishkit Uses Trusted Apps to Steal SSO Access

A phishing kit dubbed N0va is targeting organizations in North America and Europe by impersonating familiar business services (like Microsoft Teams/SharePoint and DocuSign) and pushing victims through legitimate sign-in flows. By capturing authentication tokens rather than dropping obvious malware,…

September 16, 2026
Iranian Spies Lure Targets via WhatsApp to Drop Malware

Iranian Spies Lure Targets via WhatsApp to Drop Malware

A joint UK-US-Dutch advisory warns Iranian state-backed cyber actors are targeting dissidents, activists, and journalists by first contacting them on WhatsApp or Telegram and building trust. The attackers then persuade victims to open a malicious file disguised as legitimate software (or even MRI…

September 16, 2026
AI Assistant Tricked Into Leaking GitHub Repos

AI Assistant Tricked Into Leaking GitHub Repos

A Mandiant assessment showed an internal AI assistant could be socially engineered into abusing its legitimate access. Testers convinced the agent it was part of an authorized security test and gave it a GitHub token, leading it to clone sensitive internal repositories and push them to an external…

September 16, 2026
Iran-Backed Spyware Uses Fake Support Chats

Iran-Backed Spyware Uses Fake Support Chats

UK and allied agencies warn that a Tehran-backed operation is targeting dissidents, activists, and journalists using social engineering to trick them into installing spyware called “Chosen Brick.” Attackers build trust on social media by impersonating known contacts or “technical support,” then…

September 16, 2026
Fake Avast Renewal Page Lures Victims Into Calls

Fake Avast Renewal Page Lures Victims Into Calls

Researchers found a realistic-looking fake Avast renewal page that claims a subscription renewed for €129.99 and pushes victims to “cancel” by entering their name, email, and mobile number. The charge is fake, and the real goal is to collect contact details so scammers can follow up with a phone…

September 16, 2026
Iran Spyware Poses as Apps, Delivered by Message

Iran Spyware Poses as Apps, Delivered by Message

Government agencies say Iranian intelligence-linked attackers are targeting dissidents, journalists, and activists with Windows malware controlled through Telegram. The attack starts with a trust-building message impersonating someone the victim knows or app support, then delivers a file disguised…

September 15, 2026
Iran-Linked Spyware Posed as Apps on WhatsApp

Iran-Linked Spyware Posed as Apps on WhatsApp

UK, US and Dutch authorities warned that Iran-linked attackers are targeting dissidents, activists, and journalists with Windows spyware. The group builds trust over messaging apps, then tricks victims into downloading malware disguised as legitimate software (or even medical files). The spyware…

September 15, 2026
Fake MRI File Used to Deliver Iran Spyware

Fake MRI File Used to Deliver Iran Spyware

UK, US, and Dutch agencies warned that Iran-linked operators used long-running social engineering to build trust with targets (including dissidents, activists, and journalists), then sent malicious files disguised as legitimate documents or software installers. One lure included a fake MRI scan…

September 15, 2026
Iranian Actors Lure Targets via Telegram/WhatsApp

Iranian Actors Lure Targets via Telegram/WhatsApp

UK, US, and Dutch authorities reported Iranian state-linked cyber actors using social messaging apps like Telegram and WhatsApp to build trust with dissidents, activists, and journalists. The actors then convince targets to open “legitimate-looking” files (fake apps or documents like MRI results)…

September 15, 2026
Iran-Linked Spyware Lures Targets via WhatsApp

Iran-Linked Spyware Lures Targets via WhatsApp

UK cyber authorities and international partners warned that Iranian state cyber actors have been tricking dissidents, activists, and journalists into installing spyware called CHOSEN BRICK. The campaign uses impersonation over messaging apps (such as WhatsApp and Telegram), rapport-building, and…

September 15, 2026
AI “Agents” Flood Inboxes With Spam Pitches

AI “Agents” Flood Inboxes With Spam Pitches

The article describes real-world examples of unsolicited emails that claim to be sent by “AI agents,” pitching services, interviews, coverage, and paid work. It includes specific subject lines and message excerpts that show a repeatable workflow: automated outreach that tries to prompt recipients…

September 15, 2026
Try Mirage

Mirage simulates attacks like these against your own team, live and safely, so you can measure how your people actually respond.

Get a demo