The company reports a 400% year-over-year increase in successfully phished identities, with business email addresses found in nearly 40% of recaptured records, making the workforce three times more likely to be phished than infected by malware.
The campaign, which ran from April to November 2025, utilized the open-source phishing kit Evilginx, employing an adversary-in-the-middle (AiTM) strategy.
The FBI has warned about the mounting prevalence of "virtual kidnapping" and extortion schemes, which evolves upon grandparent scams with the use of fraudulent proof-of-life photos or videos that could have been scraped from online postings of real missing person information, according to The Register.
More than 75 widely known brands, including MasterCard, Uber, Unilever, and Disney, have been spoofed in fraudulent Calendly invites as part of an ongoing phishing attack campaign aimed at pilfering Google Workspace and Facebook Business account credentials, BleepingComputer reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.