Huntress found legitimate remote management software abused in 45% of the endpoint incidents it logged in the first quarter of 2026. A rogue copy can behave like IT's approved one, so defenders have to know which tools are sanctioned and how each install arrived.
Reality
- Evidence45
- Adoption55
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Former airmen Chijioke Timothy Odimegwu and Harafat Mogaji got a combined 189 months in federal prison for BEC scams that diverted a $1.68 million wire. Their scheme worked wherever a payer accepted new bank details on the strength of an email.
Perspective Coverage
4 publishers
- Builder
- Builder 11%
- Operator
- Operator 68%
- Investor
- Investor 21%
Reality
- Evidence74
- Adoption
- Insufficient
- Hype gap0
- Incentives30
- Confidence78
French notaries lost the money to intruders who lived on their networks and edited payment details before the instructions went out, which is why bank-side verification kept waving the transfers through.
Publishers:csn.notaires.fr · news.risky.biz · risky.biz Perspective Coverage
3 publishers
- Builder
- Builder 13%
- Operator
- Operator 77%
- Investor
- Investor 10%
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+5
- Incentives20
- Confidence55
Microsoft has tracked passkey- and SSO-themed help desk impersonation since May 2026, with the calls steering employees into adversary-in-the-middle proxies and device-code grants that hand over live Microsoft 365 sessions.
Perspective Coverage
6 publishers
- Builder
- Builder 28%
- Operator
- Operator 62%
- Investor
- Investor 10%
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+10
- Incentives45
- Confidence60
The Cape Town Zone of Black Axe ran romance and advance fee scams from 2011 until South African police made arrests in 2021, and the accounts prosecutors traced also carried business email compromise proceeds.
Perspective Coverage
4 publishers
- Builder
- Builder 10%
- Operator
- Operator 76%
- Investor
- Investor 14%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+20
- Incentives40
- Confidence68
Microsoft's Digital Crimes Unit and its partners pulled down the EvilTokens phishing service about seven months after it launched, and British police arrested its two suspected operators. The authentication technique it sold survives on other platforms.
Perspective Coverage
8 publishers
- Builder
- Builder 25%
- Operator
- Operator 60%
- Investor
- Investor 15%
Reality
- Evidence66
- Adoption58
- Hype gap+18
- Incentives62
- Confidence64
Rapid7's research with Zimbra turned up more than 50 vulnerabilities, several of which let an attacker send mail as another user with no password involved. The operational item today is CVE-2026-73570, the SNMP command injection CISA gave federal agencies three days to fix.
Reality
- Evidence55
- Adoption60
- Hype gap+25
- Incentives78
- Confidence55
Microsoft says the phishing-as-a-service platform reached more than 12,000 inboxes at over 10,000 organizations in seven months by abusing a legitimate OAuth flow, and its Digital Crimes Unit has now disrupted the infrastructure behind the service.
Reality
- Evidence58
- Adoption62
- Hype gap+20
- Incentives76
- Confidence57
Microsoft Security Research reported over a million emails pairing fake ServiceNow invoices with forged forward threads. No malware ran, so the investigation lives in mail headers and accounting records.
Reality
- Evidence45
- Adoption30
- Hype gap−10
- Incentives65
- Confidence55
Rapid7's read of the fraud economy names Xleet, Blackpass, Infodig and Styx as the venues doing the trade, and points teams at MITRE's Fraud Fighting Framework, introduced in early 2026, to order what they watch.
Reality
- Evidence34
- Adoption
- Insufficient
- Hype gap+28
- Incentives68
- Confidence55
Hunt.io says a Chinese-speaking operator drove Claude Code, Alibaba Qwen and DeepSeek through an orchestration framework called SecFlow, splitting reconnaissance, exploitation and collection among specialist agents that fired only publicly documented exploits.
Reality
- Evidence46
- Adoption30
- Hype gap+18
- Incentives62
- Confidence45
France's ANSSI spent two years quietly evicting a crew that had been altering payment instructions inside notary networks. The procedural fix that landed takes bank details off email rather than checking whether they changed.
Reality
- Evidence45
- Adoption58
- Hype gap−20
- Incentives42
- Confidence50
Experian's respondents are funding fraud controls ahead of their own loss experience, so the question facing a finance team this quarter is less whether AI-enabled attacks land than which budget carries the answer.
Reality
- Evidence32
- Adoption55
- Hype gap+34
- Incentives82
- Confidence54
KnowBe4 says a new build of the commodity infostealer uses Unicode emoji to break string signatures and keeps its final payload off disk. The lure is a spoofed bank thread aimed at finance teams.
Reality
- Evidence45
- Adoption20
- Hype gap+30
- Incentives70
- Confidence52
Cisco Talos revives a 1990s criminology method to describe intrusions as narratives, then uses a business email compromise to show which steps AI makes cheap and where defenders can push back.
Reality
- Evidence28
- Adoption
- Insufficient
- Hype gap+18
- Incentives55
- Confidence46