HeadFlash

Topic · 50 stories

Phishing: attacks, scams and latest news

Updated · Edited by Marcin Rybak

In short

Phishing is a social-engineering attack in which a criminal impersonates a trusted person or organization to steal passwords, card details or to get you to install malware. In 2026 one employee's click exposed data on about 1.3 million people at an Arizona court, and the BigBear platform bypassed multi-factor authentication at 258 organizations. MFA alone is not enough, which is why Microsoft is forcing passkeys.

What is phishing

Phishing is a social-engineering attack in which a criminal impersonates a trusted person, company or agency to steal a password or card details, or to get the victim to install malware. The name plays on “fishing”: the message is the bait, whether an email, a text, a Teams chat or a web page posing as a routine browser check. A phishing scam does not break technical defenses. It exploits trust and urgency, which is why it starts so many serious intrusions.

October 2026 shows the result. An Arizona court employee clicked a malicious link, and the attack copied data on about 1.3 million people from the FARE fines program, plus over 150,000 Foster Care Review Board records going back to 2010. In July, one click by a Vanderbilt Health employee opened their mailbox and may have exposed names, record numbers and diagnosis details of some patients. Both are typical government data breaches and healthcare data breaches.

What is spear phishing, smishing and vishing

Spear phishing is phishing aimed at one person or organization: the message is tailored to the victim and their work instead of being sent to thousands of addresses. Smishing is phishing by text message, a short SMS with a link to a fake page. Vishing is phishing by phone, where the caller poses as a bank or an IT department.

Type Channel What it looks like in 2026
Mass phishing email, text, ads fake Roblox login pages promising free Robux; Star Blizzard’s mass campaigns
Spear phishing email, messaging apps conversations lasting days or weeks before a malicious file arrives (APT42, TA419)
Smishing text message links to a fake Microsoft login texted to employees’ personal phones
Vishing phone a call from the “help desk” urging you to update your passkey

How to spot phishing emails and what might be a phishing message

A message might be phishing if it shows any of four signs: urgent or threatening language, a request for personal or financial information, a shortened or wrong link, or a sender address that does not match. CISA’s guide to recognizing and reporting phishing (as of 10 October 2026) lists these signs and adds that AI writes error-free messages, so spelling no longer helps.

Three more signals matter in 2026, because filters do not always catch them:

  • No real CAPTCHA asks you to open the Run dialog or paste a command. That is how ClickFix works, described below.
  • The sender address can be forged so that it passes verification. SEC Consult showed that two flaws in iCloud mail let anyone spoof any address on icloud.com and still pass SPF, DKIM and DMARC. Apple paid a $15,000 bounty and confirmed fixes on 12 November 2025.
  • A look-alike address can fool the eye. Proton Mail still allows spoofing via the domain gmaiI.com with a capital I, because the default font renders I and l the same and domains without a DMARC record get no warning. The February 2025 report earned a $100 bounty but was not fixed.

Similarly, an empty return address defeats the Reject Direct Send setting in Microsoft 365, which was meant to block external mail posing as internal. In ReliaQuest’s tests most such messages reached the recipient’s inbox. Browser pop-ups can lie too: fake Chrome update prompts pushed by compromised extensions download a .vbs or .exe file.

What phishing looks like in 2026: ClickFix and IT impersonation

The two most common patterns of 2026 are ClickFix, a fake verification that makes the victim run a command themselves, and impersonation of the IT department.

ClickFix. A hacked site shows what looks like a CAPTCHA, but instead of ticking a box the visitor is told to open the Run dialog and paste a command. Netskope found over 5,400 hacked websites across more than 2,200 organizations; many belong to small businesses, and where inspected, most ran WordPress. The instructions sit in a smart contract on the BNB Smart Chain testnet, so attackers can change them without touching the sites. Microsoft described a variant, TerminalFix, in which a fake Cloudflare CAPTCHA sends the victim to Windows Terminal and installs an implant with access to the internal network. This feeds malware and infostealers: a hijacked HBO Max Reddit account ran 108 malicious ads pushing a fake app, and Cisco assesses with moderate confidence that a Ukrainian government organization was hit by a Russian actor; a similar infection began with a fake Google CAPTCHA, but researchers could not confirm both started the same way.

IT impersonation. Microsoft warned of a campaign where attackers message on Teams as IT support, ask for screen sharing or remote access, and end with data theft and ransomware. It advises verification passwords for the internal help desk. Groups linked to ShinyHunters use a similar pretext, covered in the next section.

Hotel Wi-Fi. Microsoft attributed the CaptiveCrunch campaign to Russia’s Storm-2945, in which DNS manipulation on hotel networks sends travelers to fake Microsoft 365 logins. ReliaQuest suspected the Russian group APT28 of a similar campaign. Treat hotel Wi-Fi as untrusted and do not install updates offered by the portal.

Does MFA stop phishing

Not always: MFA based on codes, SMS or approvals can be bypassed, and Microsoft recommends phishing-resistant methods. The phishing-as-a-service platform BigBear 2.0 bypassed MFA at 258 organizations using the Evilginx2 framework, which sits between the victim and the real site and steals the password together with the session cookie. The panel held 5,137 records, including 474 complete authentications with MFA bypassed and 4,148 session cookies, from victims in over 40 countries.

The campaign Microsoft calls passkey-themed phishing works the same way. Groups linked to ShinyHunters and Helix call or message as the help desk and tell victims to “update their passkey”, but they do not register one: they steer the victim to an adversary-in-the-middle (AiTM) page or a device-code login. A password is not even needed with OAuth consent abuse: depending on the scope, the attacker gets a token that can read mailboxes or change repositories, because MFA protects the login, not what the user approves afterwards.

That is why Microsoft will turn off SMS and voice MFA in Entra on 1 February 2027. From 1 September 2026 users are prompted to register a passkey, and anyone left with only SMS or voice after the deadline cannot sign in until they register one. For wider context see password security.

Who is targeted by phishing

Everyone is a target, from Roblox players to EU officials, but the loudest 2026 campaigns hit employees of companies and institutions.

How to report phishing and what to do after a click

Report phishing with the report option in your email or messaging app, then delete the message. CISA’s phishing guide (as of 10 October 2026) says the option is usually next to the sender’s name, or in the report-spam button, and it advises not to reply or click any link, including “unsubscribe”. At work, tell your IT or security team first.

After clicking a suspicious link or entering credentials, the first minutes count:

  • Change the password, but do not stop there. In the APT42 campaign, changing the password does not invalidate stolen session cookies, so all sessions and OAuth tokens must be revoked.
  • Remove authentication methods and mailbox rules you did not add. Attackers often add their own phone numbers or authenticator apps.
  • If money was taken, contact your bank immediately, keep the transaction records and report it to the police, as experts advise after the tap-to-pay charity scam.

What it means for you

  • Do not trust how a sender looks or the display name. Check any request for a password, a transfer or a “passkey update” through another channel before you act.
  • Never paste commands from a “CAPTCHA verification” into the Run dialog, a terminal or PowerShell.
  • Where you can, move to passkeys or hardware keys, and turn off device-code login where it is not needed.
  • At work, limit user consent to OAuth apps and agree a verification phrase for help desk contacts.

Still open: whether Proton will ship a fix against spoofing, and when Microsoft will switch Direct Send off by default. Netskope has not established how the ClickFix sites were compromised, and the BigBear campaign was still running when it was reported.

Key facts

  • An Arizona court employee clicked a phishing link. The 24 September attack copied data on about 1.3 million people from the FARE program and over 150,000 Foster Care Review Board records. (source)
  • China-aligned TA419 impersonated Anthropic staff to reach AI policy experts at think tanks, universities and law firms. The goal was to take over their cloud accounts. (source)
  • Russian group Star Blizzard moved to mass phishing campaigns. Microsoft counted at least 13 since January, hitting over 100 organizations, mostly in the US and UK. (source)
  • Roblox is the second most impersonated brand in phishing, at 12.32 percent of cases in NordVPN's 2026 consumer report. Only Microsoft ranks higher. (source)
  • Netskope found over 5,400 hacked websites across more than 2,200 organizations showing a fake CAPTCHA that tells visitors to paste a command (ClickFix). (source)
  • Microsoft described passkey-themed phishing: attackers call or message as IT help desk and steer victims to AiTM pages or device-code login to take over Microsoft 365 accounts. (source)
  • Phishing-as-a-service BigBear 2.0 bypassed MFA at 258 organizations and exfiltrated over 5,000 Microsoft 365 credential records, including 4,148 session cookies. (source)
  • Microsoft will switch off its own SMS and voice MFA in Entra ID on 1 February 2027. From 1 September 2026 users are prompted to register a passkey. (source)

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Timeline

  1. Arizona court phishing attack exposes data on 1.3 million people Security
  2. China-aligned TA419 impersonates Anthropic staff to target AI policy experts Security
  3. SEC Consult finds iCloud email spoofing flaws, Apple pays $15,000 Security
  4. Star Blizzard deploys CosmicPulse backdoor via new RedFlick technique Security
  5. Star Blizzard expands phishing beyond Ukraine with RedFlick malware Security
  6. Proton Mail sender spoofing remains unfixed after bounty dispute Security
  7. WhatsApp malware campaign targets business users with BYOVD Security
  8. Roblox phishing scams target young players and their Robux Security
  9. Fake LastPass Authenticator repos push Rapuncel infostealer Security
  10. OAuth consent abuse grants persistent SaaS access Security
Show older (40 stories)
  1. HBO Max Reddit Account Hijacked for 108 ClickFix Ads Security
  2. Revolut Disclosed Customer Data After Fake Government Requests Privacy
  3. Passkey-themed phishing campaign hits Microsoft 365 and steals corporate data Security
  4. Netskope finds 5,400 hacked websites pushing ClickFix malware through fake CAPTCHAs Security
  5. ClickFix attacks spread to Macs and Windows as attackers shift tactics Security
  6. Empty return address defeats Microsoft’s Reject Direct Send anti-spoofing setting Security
  7. Cisco links Ukrainian government breach to Russian actor using fake CAPTCHA Security
  8. BigBear phishing service bypasses MFA at 258 organizations, steals 5,000 Microsoft 365 credentials Security
  9. Cyber criminals use ASCII smuggling to evade filters in mass phishing campaigns Security
  10. Spam Campaign Uses Invisible Unicode Characters to Split Word ‘Funding’ and Evade Filters Security
  11. Microsoft Warns of Teams Helpdesk Impersonation Campaign Ending in Ransomware Security
  12. Microsoft Warns of TerminalFix Campaign Abusing Windows Terminal for Backdoor Deployment Security
  13. TerminalFix Malware Chain: From PowerShell to Reverse Tunnel Security
  14. TerminalFix: Microsoft Urges Investigation for Lateral Movement and Credential Exposure Security
  15. State actors tried to hack EU officials’ Signal and WhatsApp accounts Security
  16. Tap-to-pay charity scam can charge thousands instead of small donations Security
  17. Hackers Abuse npm Mirrors to Host Phishing Pages on Legitimate Domains Security
  18. New WordlistLoader Malware Uses Plain English Words to Hide Amatera Infostealer Security
  19. India Orders Google to Remove Firebase Accounts Linked to Bank Fraud Security
  20. WhatsApp tests AI-powered Scam Alert feature to flag suspicious messages Privacy
  21. Fake Chrome update pop-ups traced to compromised browser extensions Security
  22. Hackers Use BNB Chain Smart Contracts to Spread Malware via Fake CAPTCHAs Security
  23. Fake Claude Install Guide Delivers MacSync Malware to Empty Crypto Wallets Security
  24. Midnight Blizzard sub-cluster targets travelers via captive portals in CaptiveCrunch campaign Security
  25. Russian State Hackers Hijack Hotel Wi-Fi to Steal Traveler Credentials Security
  26. Microsoft ties CaptiveCrunch hotel Wi-Fi attacks to Russian APT29 sub-cluster Security
  27. DOUBLECUP ClickFix service hides malware in browser cache images Security
  28. Vanderbilt Health Employee Click Sparks Patient Data Exposure in Nashville Privacy
  29. Hackers Hijack Hotel Wi-Fi DNS to Steal Microsoft 365 Accounts Security
  30. Microsoft Mandates Passkeys in Entra by February 2027, Retires SMS and Voice MFA Security
  31. Iranian APT42 Campaign SpearSpecter Uses AI Lures, Telegram C2, and Password-Reset-Proof Backdoor Security
  32. Fake IT Support Calls on Microsoft Teams Deliver EtherRAT Malware Security
  33. The Intercept’s Signal Tip Line Breached by Unauthorized Third Party Privacy
  34. Opera Browser Launches Paste Protect to Block Clipboard Hijacking Attacks Security
  35. Scammers Exploit GTA VI Hype to Steal Bank Details and Deploy Malware Security
  36. New macOS ClickFix Attack Silently Mounts DMGs to Push Infostealer Security
  37. Kali365 Phishing Platform Uses AI to Bypass Multi-Factor Authentication and Steal Microsoft Accounts Security
  38. FBI and Google Takedown AI Phishing Service Outsider Enterprise Security
  39. Google Sues Chinese Cybercrime Network for Using Its AI in Scams Security
  40. North Korean Hackers Use Elaborate Fake Job Interviews to Steal Crypto and Credentials Security

FAQ

What is phishing?

Phishing is an attack in which a criminal impersonates a trusted person, bank, company or agency to steal passwords or card details, or to get you to install malware. It usually arrives by email, text or messaging app and leads to a fake login page or a malicious file.

How to spot phishing emails?

Look for four signs: urgent or threatening language, a request for personal or financial information, shortened or wrong links, and a sender address that does not match. CISA (as of 10 October 2026) notes that perfect grammar no longer rules out phishing, because AI writes without errors.

What is spear phishing?

Spear phishing is phishing aimed at one person or organization, with a message tailored to the victim instead of mass-mailed. Iran-linked APT42 holds conversations for days or weeks before sending a malicious file, and TA419 impersonated Anthropic staff to reach AI policy experts.

What is a phishing link?

A phishing link is a URL in a message that leads to a fake login page or a malicious download. Warning signs are shortened URLs and look-alike domains, such as gmaiI.com with a capital I, which Proton Mail still displayed without a warning in September 2026.

Does MFA stop phishing?

Not always. The BigBear 2.0 platform bypassed MFA at 258 organizations by capturing passwords and session cookies on proxy pages (AiTM). Microsoft recommends phishing-resistant MFA and will turn off its SMS and voice MFA in Entra on 1 February 2027.

How do I report phishing?

Use the report option in your email or messaging app, usually next to the sender's name, or the report-spam button, then delete the message. This is CISA's guidance (as of 10 October 2026). If money was lost, contact your bank at once and keep the transaction records.