Skip to content

Topic

Social Engineering and Voice Phishing

Cyberattack techniques that manipulate victims via calls, texts, or fake support/police contacts into revealing credentials or installing malware.

Current stories

security5 publishers

Fake Zoom installer talks macOS users past Gatekeeper to drop CloudSyncD backdoor

Jamf Threat Labs reported CloudSyncD, a new macOS backdoor that spreads through a fake Zoom installer and beacons to its server every 8 to 16 seconds. First caught as a VirusTotal sample that looked unfinished, it now appears in builds that connect to live infrastructure in what Jamf calls an active campaign.

Perspective Coverage

5 publishers
Builder
Builder 25%
Operator
Operator 70%
Investor
Investor 5%

Reality

Evidence70
Adoption15
Hype gap+15
Incentives
Insufficient
Confidence68
security2 publishers

Pindrop survey finds purpose-built deepfake defenses at 10% of US organizations

Pindrop's survey of more than 250 US security leaders found 74% faced or suspected a deepfake attack in the past year. The targets are live channels such as help-desk calls, job interviews and video meetings, and identity controls were not designed to verify who is on them.

Reality

Evidence40
Adoption10
Hype gap+25
Incentives
Insufficient
Confidence45
security3 publishers

RingCentral's platform held. Its customer records are on the internet anyway.

ShinyHunters claims 623GB from a July social-engineering campaign and leaked part of it. Have I Been Pwned confirmed 1.6 million account records. Both the vendor and the crew can be telling the truth.

Perspective Coverage

3 publishers
Builder
Builder 22%
Operator
Operator 62%
Investor
Investor 16%

Reality

Evidence72
Adoption
Insufficient
Hype gap+5
Incentives55
Confidence70
security5 publishers

Stolen logins, not a SaaS breach: nine enterprises' Entra directories are now for sale

A seller using the name TheHatman is offering employee directory exports from nine named enterprises. Hudson Rock ties the theft to infostealer credentials, not a compromise of the provider.

Perspective Coverage

5 publishers
Builder
Builder 25%
Operator
Operator 61%
Investor
Investor 14%

Reality

Evidence55
Adoption
Insufficient
Hype gap+30
Incentives50
Confidence60
security5 publishers

ShinyHunters phished the firm that had just profiled it, and device trust was the only thing that mattered

A ReliaQuest employee gave up a password and an MFA push five days after the company named the .claims campaign. Device trust, not training, kept the session worthless.

Perspective Coverage

5 publishers
Builder
Builder 29%
Operator
Operator 56%
Investor
Investor 15%

Reality

Evidence58
Adoption
Insufficient
Hype gap+25
Incentives70
Confidence62
security3 publishers

Rogue ScreenConnect clients are pushing VBScripts to every endpoint that connects

ConnectWise's September 3 advisory promises a CVE and a fix within the week, so until one lands the only control is a per-role permission change. Huntress says the spread is already worm-like across newly connected machines.

Perspective Coverage

3 publishers
Builder
Builder 38%
Operator
Operator 57%
Investor
Investor 5%

Reality

Evidence68
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence64
invest5 publishers

A fake Google and Gemini call delivered 94% of the thefts named in Malone Lam's plea

Prosecutors valued the take at 4,100 bitcoin, more than $245 million, drained after one Washington holder granted Google Drive access and read out security codes; every other victim named in the case totals about $14.8 million.

Perspective Coverage

5 publishers
Builder
Builder 19%
Operator
Operator 49%
Investor
Investor 32%

Reality

Evidence68
Adoption
Insufficient
Hype gap+20
Incentives
Insufficient
Confidence64
security8 publishers

Revolut handed over passports to a rogue account inside a real government domain

The fraudulent request passed domain authentication because it genuinely came from the agency's mail domain, sent by an account the agency had not authorised. Revolut found out only when it called the agency to check.

Perspective Coverage

8 publishers
Builder
Builder 11%
Operator
Operator 70%
Investor
Investor 19%

Reality

Evidence68
Adoption
Insufficient
Hype gap+5
Incentives55
Confidence66
security9 publishers

Group-IB ties the Handala Hack persona to a Telegram-run backdoor that steals saved passwords

Group-IB says the Iran-linked leak-and-brag front Handala Hack runs HEAVYGRAM, a Python implant that takes orders from a Telegram bot, opens the microphone and lifts saved passwords after a loader writes Defender exclusions for it.

Perspective Coverage

9 publishers
Builder
Builder 44%
Operator
Operator 52%
Investor
Investor 4%

Reality

Evidence82
Adoption64
Hype gap+5
Incentives45
Confidence80

Earlier coverage

  1. Brooklyn man gets four to 12 years for posing as a Coinbase representative to take nearly $16 million

    Security · September 24, 2026 · 1 publisher

  2. Attackers reached Astrana Health's servers by spoofing its own main phone number

    Security · September 24, 2026 · 1 publisher

  3. Apple's iOS 27 gives opted-in apps an on-device scam risk level to flag possible impersonation

    Security · September 24, 2026 · 1 publisher

  4. Seven agencies price North Korea's fake-recruiter funnel at $1,530 a wallet

    Invest · September 23, 2026 · 1 publisher

  5. A ClickFix technique beat Meta's Muse safeguards within 13 days of launch

    Invest · September 21, 2026 · 1 publisher

  6. A year-old Scattered Spider guilty plea surfaced only when prosecutors moved on the crypto

    Security · September 21, 2026 · 1 publisher

  7. Fake recruiters are working the Rust maintainers who can publish to crates.io

    Security · September 21, 2026 · 2 publishers

  8. FBI ties $1.6 billion in losses to police and government impersonation scams over 19 months

    Security · September 21, 2026 · 1 publisher

  9. eSentire finds GhostCode phishing Microsoft device codes through web contact forms

    Security · September 20, 2026 · 1 publisher

  10. Attackers hit Cisco's email gateway with a SQL injection zero-day before the patch shipped

    Security · September 20, 2026 · 1 publisher

  11. Revolut puts 150 million francs behind 1.3 million Swiss customers it already serves

    Invest · September 19, 2026 · 1 publisher

  12. Trusting the repository author in VS Code runs the fake recruiter's task file

    Build · September 19, 2026 · 1 publisher

  13. Four governments trace 30,000 infected devices to fake interview coding tasks

    Build · September 18, 2026 · 1 publisher

  14. A forfeiture order disclosed Ahmed Elbadawy's year-old guilty plea in the Scattered Spider case

    Security · September 18, 2026 · 1 publisher

  15. The FBI counted $893 million in AI-linked fraud losses in its first year of tracking them

    Product · September 17, 2026 · 1 publisher

  16. Brockman tells security teams to give an agent approved access to their highest-priority systems

    Security · September 16, 2026 · 1 publisher

  17. AI agents pleading for $20 move the spam signal from the template to the persona

    Build · September 16, 2026 · 1 publisher

  18. Fake support accounts are answering airline complaints under the brand's verified posts

    Security · September 16, 2026 · 1 publisher

  19. FBI logged 22,000 AI-linked fraud complaints in its first year of counting them

    Science · September 14, 2026 · 1 publisher

  20. Fake helpdesk calls use the passkey rollout as the pretext for Microsoft 365 intrusions

    Leadership · September 13, 2026 · 1 publisher

  21. AdaptHealth declared its breach material 12 days after it discovered the intrusion

    Leadership · September 12, 2026 · 2 publishers

  22. AdaptHealth traces a 4.1 million-record breach to one compromised contractor session

    Security · September 12, 2026 · 2 publishers

  23. Revolut handed identity files and Bitcoin histories to an email that passed SPF, DKIM and DMARC

    Invest · September 12, 2026 · 1 publisher

  24. To counter voice clones built from a few seconds of scraped audio, experts suggest agreeing on a family safe word

    Security · September 10, 2026 · 1 publisher

  25. Fake IT callers register their own MFA method under the Microsoft 365 identities they phish

    Security · September 10, 2026 · 1 publisher

  26. Agents meant to be isolated used a package cache as their message board

    Product · September 10, 2026 · 1 publisher

  27. OpenAI's agents borrowed a wiki admin's username months before the incident was disclosed

    Product · September 9, 2026 · 1 publisher

  28. Scattered Spider talks help desks into moving MFA onto attacker-controlled devices

    Security · September 9, 2026 · 1 publisher

  29. Investigators traced a $240m bitcoin theft to a $47,500-a-month rental in Encino

    Invest · September 9, 2026 · 1 publisher

  30. One unhidden IP address at an exchange signup broke the $240 million bitcoin heist case

    Security · September 8, 2026 · 2 publishers

  31. An infected ScreenConnect guest pushes scripts up the support session to the operator's host

    Build · September 8, 2026 · 1 publisher

  32. ShinyHunters claims it scraped 200,000 driver records out of Florida's DAVID lookup portal

    Security · September 8, 2026 · 1 publisher

  33. ClickFix scales by asking employees to paste the command themselves

    Leadership · August 31, 2026 · 1 publisher

  34. The refund scam that asks you to uninstall your antivirus, then writes down which one

    Security · August 24, 2026 · 1 publisher