
Microsoft has disrupted EvilTokens, a phishing-as-a-service platform that was linked to more than 12,000 compromised email inboxes across more than 10,000 organizations worldwide. The service used device-code phishing to gain access to Microsoft accounts and then used AI-powered tools to analyze compromised mailboxes and help attackers identify opportunities for further fraud. The operation highlights how […]
I received an email from someone calling himself “Daniel Kelvin Esq Solicitor.” He claimed to be handling the affairs of a deceased client and said there were business transaction funds waiting to be released. According to the email, I could become the client’s next of kin and receive 50% of the money, while he would […]
Conventional Phishing attacks involved tricking potential victims to enter their respective usernames and passwords on fake websites which resembled the genuine websites. Once the login credentials were captured, they were used to steal business as well as personal data. A new trend that has emerged is to trick users into downloading malware that once downloaded […]