Recent Telecommunications Cyber Attacks

Attacks on carriers and telecom providers, including SIM swap operations and the smishing campaigns that abuse their networks. Each entry is broken down with an original video explainer, key findings, and the red flags your team should watch for. How we produce these.

Fake T-Mobile Points Expiry Texts Hit Phones

Fake T-Mobile Points Expiry Texts Hit Phones

A large phishing (smishing) campaign is sending messages that claim a T-Mobile customer’s rewards points are about to expire. The texts use urgency, made-up point balances, and lookalike “t-mobile.*.top” links to push people into clicking and entering sensitive information. Malwarebytes observed…

September 17, 2026
AT&T Insider Aided SIM-Swap Bank Heists

AT&T Insider Aided SIM-Swap Bank Heists

A former AT&T retail employee helped a SIM-swap crew hijack customers’ phone numbers, letting the criminals intercept SMS two-factor codes and reset online banking passwords. The gang then attempted (and in one case succeeded) to wire large sums from victims’ bank accounts, often to accounts in…

September 15, 2026
FBI Warns of OAuth Consent Phishing Tricks

FBI Warns of OAuth Consent Phishing Tricks

A SecurityWeek roundup highlights multiple real-world scams and campaigns where attackers trick people rather than “hack” systems directly. Notable items include OAuth “consent phishing” (getting users to approve a malicious app’s access), and phishing-evasion using invisible Unicode characters…

September 11, 2026
Fraudsters Can Remotely “Brick” Phones for $3

Fraudsters Can Remotely “Brick” Phones for $3

Researchers showed that attackers can abuse mobile carriers’ “lost/stolen phone” reporting process to get devices blocked from the cellular network, even when the devices were never lost. With only a prepaid account and a target device’s IMEI number, blocking can cost just a few dollars and take…

September 11, 2026
Smishing Kit Rebounds After Major Takedown

Smishing Kit Rebounds After Major Takedown

Researchers say a “phishing-as-a-service” kit called Outsider kept generating new scam pages even after a major law-enforcement and industry takedown. The kit supports SMS-based lures that impersonate trusted brands and can capture payment details and MFA codes in real time using…

September 3, 2026
Smart TV Apps Turn Homes Into DDoS Proxies

Smart TV Apps Turn Homes Into DDoS Proxies

Researchers describe how some smart TV apps bundle “residential proxy” relay kits that users unknowingly approve via a consent screen. The same always-on home devices can then be repurposed (“flipped”) from commercial web scraping into DDoS traffic, contributing to a sharp rise in devices seen in…

August 30, 2026
Dark Caracal Phishes Tax Lures With SVG Files

Dark Caracal Phishes Tax Lures With SVG Files

Researchers linked a June 2026 intrusion at a communications organization in Venezuela to the Dark Caracal espionage group. The attackers used phishing emails with financial/tax-themed lures and weaponized SVG attachments that redirected victims through URL shorteners to an attacker site hosting…

August 27, 2026
Notion Alerts Used to Steal Microsoft Tokens

Notion Alerts Used to Steal Microsoft Tokens

A financially motivated actor (“Doubloon Dredger”) abused legitimate Notion sharing notifications to trick employees into opening a PDF and completing a Microsoft device-code login flow. This allowed the attacker to harvest authentication tokens and access victim accounts without needing the…

August 24, 2026
Fake Bank Calls and ClickFix Drive Data Theft

Fake Bank Calls and ClickFix Drive Data Theft

The roundup describes multiple real-world attacks where criminals manipulate people, not just systems, such as fake bank support calls that trick victims into installing phone malware, and “ClickFix” lures that convince Mac users to run malicious commands. It also highlights an AI-assisted…

August 21, 2026
Spoofed Portal Drops APT36 Backdoor on Telecoms

Spoofed Portal Drops APT36 Backdoor on Telecoms

The bulletin describes an APT36 (Transparent Tribe) espionage campaign that uses social-engineering lures and spoofed download portals to trick targets into installing a malicious Windows installer. The installer (“TMS_AfghanTelecom.exe”) deploys the PATCHCORD backdoor, which then calls out to…

August 18, 2026
Azure Employee Directories Dumped via Stolen Access

Azure Employee Directories Dumped via Stolen Access

A threat actor called “TheHatman” claims they stole and posted large internal employee directories from multiple Fortune 500 companies’ Microsoft Azure tenants. Hudson Rock says the leaked samples look like real Azure directory exports, but the exact way the attacker got in is still unclear. One…

August 18, 2026
Vishing Console + Fake CCleaner Trap Users

Vishing Console + Fake CCleaner Trap Users

This bulletin highlights multiple real-world threats, including voice-phishing (vishing) operations that industrialize account takeovers and a fake CCleaner download site that installs spyware. The items provide concrete, repeatable lures (a vishing-driven takeover workflow and a lookalike software…

August 17, 2026
Fake VPN Installers Hit Afghan Telecom Targets

Fake VPN Installers Hit Afghan Telecom Targets

Acronis reported a real espionage campaign delivering a backdoor (PATCHCORD) to Afghan telecom providers and South Asian critical infrastructure by tricking victims into installing look‑alike VPN and telecom tools. The operation also used cloud services like Google Sheets (and GitHub Gists) to…

August 16, 2026
RingCentral Breach Fuels Spoofed M365 Phish Risk

RingCentral Breach Fuels Spoofed M365 Phish Risk

Have I Been Pwned says the RingCentral incident exposed 1.6 million email addresses plus names, phone numbers, and physical addresses, which can make targeted phishing more convincing. Separately, researchers described spoofed RingCentral emails that bypassed defenses due to allowlisting and led…

August 14, 2026
Phone Scammers Used Fear to Sell €4,000 of Fake Filters

Phone Scammers Used Fear to Sell €4,000 of Fake Filters

A real phone scam convinced an elderly woman that her drinking water was unsafe and pressured her into buying four overpriced “water filters,” costing about €4,000. The article also describes common Portugal-targeted scams, including “Hi Mum/Hi Dad, I lost my phone” money-transfer fraud and SMS…

August 14, 2026
Deepfake Face-Swap Busted in Live Video ID Check

Deepfake Face-Swap Busted in Live Video ID Check

Spanish police arrested a suspect accused of using real-time face-swap deepfakes during live video identity checks to obtain fraudulent digital certificates for later misuse. The article describes how the attacker relied on lighting tricks and camera injection to spoof document and biometric…

August 13, 2026
Hackers Recruit Insiders With Cash and Referrals

Hackers Recruit Insiders With Cash and Referrals

A TrendAI (Trend Micro) report describes a structured underground market where criminals recruit employees to provide access, approve transactions, and bypass controls, often via Telegram and hacking forums. The article gives concrete examples (e.g., paying a FedEx employee $1,000/day to update…

August 7, 2026
Fake Job Interviews Used to Breach 1,600 Firms

Fake Job Interviews Used to Breach 1,600 Firms

A researcher says North Korean operators used fake high-salary job offers to trick software developers into downloading an “interview test” program that installed malware. He reports evidence that 1,640 organizations across 57 countries were impacted, with hundreds suffering serious intrusions,…

August 6, 2026
Consent Phishing and Hijacked Hotel Wi‑Fi Portals

Consent Phishing and Hijacked Hotel Wi‑Fi Portals

This weekly threat bulletin summarizes multiple real-world incidents, including phishing that abuses Microsoft’s legitimate app login/consent screens and a campaign that hijacks hotel Wi‑Fi captive portals. In both cases, the goal is to trick people into granting access or capturing Microsoft…

August 3, 2026
Cybercrime as a Service Fuels New Scam Waves

Cybercrime as a Service Fuels New Scam Waves

A threat landscape report describes how criminals now buy or rent phishing, fraud, malware, and hidden infrastructure “as a service,” making scams faster to launch and harder to stop. The article highlights practical, repeatable social-engineering workflows such as fake CAPTCHA pages that trick…

July 31, 2026
Try Mirage

Mirage simulates attacks like these against your own team, live and safely, so you can measure how your people actually respond.

Get a demo