Malwarebytes reported a phishing campaign that impersonates a promotion from Anthropic, falsely claiming to offer 10,000 users a free month of Claude Max to mark 100 million users. Victims who click through are directed to a fake Google login page designed to steal their credentials, using a convincing 'browser-in-a-browser' overlay that mimics a real Google sign-in window.
cnet.com
· 2026-09-23
Microsoft has shut down EvilTokens, a subscription-based cybercrime service sold via Telegram that used AI tools to break into Microsoft accounts and mine stolen inboxes for payment details and business contacts. The company said the service compromised roughly 12,000 accounts across 10,000 organizations by abusing Microsoft's device-code sign-in process, and it seized 50 websites and 150 domains via legal action. UK police separately arrested two men suspected of running the operation.
techspot.com
· 2026-09-23
Microsoft and partners including Cloudflare, Coinbase, OpenAI, SpyCloud, TRM Labs and Health-ISAC disrupted EvilTokens, a phishing-as-a-service platform that used AI to scan compromised inboxes and craft tailored lures. The operation had compromised over 12,000 inboxes across more than 10,000 organizations worldwide, spanning sectors like healthcare, finance and higher education. The takedown seized 50 sites and disabled 150 domains, and UK police arrested two men, aged 32 and 38, after Microsoft shared intelligence with the Metropolitan Police's cybercrime unit.
yro.slashdot.org
· 2026-09-23
Microsoft and partner organizations dismantled EvilTokens, a phishing-as-a-service operation that used AI tools and device code phishing to compromise over 12,000 inboxes across more than 10,000 organizations. Following a US court-enabled legal action, Microsoft seized 50 websites and disabled over 150 additional domains linked to the operators, tracked as Storm-2992. The UK's Metropolitan Police also arrested two men connected to the scheme this month; both were released on bail pending further investigation.
darkreading.com
· 2026-09-22
Microsoft announced it coordinated an industry-wide disruption of EvilTokens, a subscription phishing service sold via Telegram since February that used an AI chatbot to help criminals analyze compromised inboxes and craft convincing fraud emails. The platform compromised 12,000 accounts across 10,000 organizations worldwide, mostly in the US, and Microsoft seized 50 websites and 150 domains as UK police arrested two suspects.
arstechnica.com
· 2026-09-22
A QR code hides its destination until you have already opened it. susQR is a free web tool that checks the link first, and it is worth keeping one tap away.
susqr.com
· 2026-09-22
Quishing works because a QR code gives you nothing to judge before you commit. Here is what the scams look like in practice and the habits that defuse them.
gokawiil.com
· 2026-09-22
In the latest Apple @ Work episode, host discusses tailored phishing simulations with Samantha Schwartz and Jack Hirsch of Sublime Security. The conversation focuses on how simulated phishing tests are evolving to reflect increasingly sophisticated, AI-generated attack techniques. The episode is sponsored by Mosyle, which markets itself as a unified Apple device management platform used by over 45,000 organizations.
9to5mac.com
· 2026-09-22
Security firm Sublime found that malicious calendar invites sent via email, known as ICS phishing, have surged dramatically, rising 282% in June, 338% in July, and 1,216% in August, with a projected 2,852% jump in September. These fake invites exploit a default feature in Outlook, Gmail, and Apple Mail that auto-adds ICS files to a user's calendar before they accept or decline them.
zdnet.com
· 2026-09-18
A tech commentator argues that while Big Tech companies like Google and Microsoft are aggressively pushing users toward passkeys, the technology trades one security risk for another. Passkeys eliminate phishing by binding logins to a specific site, but because they can't be backed up or transferred between hardware keys, users face a higher chance of losing access entirely if devices are lost or accounts are banned.
hawksley.dev
· 2026-09-18
Google's Threat Intelligence Group disclosed a credential-harvesting operation where attackers compromised cloud infrastructure and deployed a multi-agent AI framework that scanned for vulnerabilities, fixed its own errors, and rotated IP addresses largely without human input. The entire campaign, which compromised thousands of third-party credentials, took less than six hours to execute. Separately, Microsoft found AI-assisted phishing messages reaching click-through rates of 54%, compared to roughly 12% for conventional campaigns.
bleepingcomputer.com
· 2026-09-17
Microsoft researchers uncovered a phishing operation in which an unidentified attacker sent over one million fraudulent emails within three days, each tailored to target accounts payable staff at specific companies. The emails impersonated ServiceNow, demanding nearly $50,000 in fake subscription payments, and included fabricated email threads featuring real executives' names to make the scam appear legitimate.
darkreading.com
· 2026-09-11