Financial organizations in the U.S., Canada, Europe, Hong Kong and other countries are being impacted by the novel MirrorBlast phishing campaign launched by Russia-linked threat group Evil Corp, or TA505, since early last month, a Morphisec report revealed in SecurityWeek.
Phishing URLs impersonating Chase rose by 300% between May and August, with phishing kits behind all the malicious URLs. The report also showed that Chase was the second most targeted brand by phishing kits, only behind Microsoft 365, according to a report from Cyren.
Financial institutions may want to invest in stronger forms of 2FA/MFA, such as time-based one-time passwords from authorization apps, push-notification codes, or FIDO-based hardware security keys.
Amichai Shulman, chief technology officer and co-founder of AirEye, warned of "more and more severe vulnerabilities in the implementation and design" of wireless network communication.
Federal prosecutors in Virginia are charging four individuals for a wide-ranging scheme to defraud businesses, first by hacking into their email or networks and then impersonating trusted third-party vendors in order to collect on unpaid bills.