Phishing
Curated coverage and analysis in this editorial area.

Italian Revenue Agency Phishing: Cloned SPID Portal Uses Pre-filled Emails to Target Public Sector
CERT-AGID has identified a targeted phishing campaign against the Italian Revenue Agency (Agenzia delle Entrate) featuring cloned SPID…

7-Eleven Confirms Data Breach After ShinyHunters Leaks 9.4GB of Files
7-Eleven has officially confirmed a cyberattack originating in April 2026. Following a failed ransom negotiation with the ShinyHunters…

15 Instagram Posts and One Cent: The New Price of Convincing Spear-Phishing
Research from UT Arlington and LSU demonstrates how 10-15 public Instagram posts and less than a penny can generate personalized phish…

CERT-AGID: Italian Cyberattacks Surge 13% as PagoPA and INPS Face Targeted Campaigns
CERT-AGID identified 131 malicious campaigns in Italy between May 9 and 15, 2026. The activity involved 1,382 indicators of compromise…

ShinyHunters: A Serial Extortion Campaign Targets Enterprise SaaS (May 2026)
Between May 7 and May 18, 2026, ShinyHunters targeted Canvas, 7-Eleven, and Grafana in a high-profile data extortion spree. While Inst…

Škoda Germany Data Breach: Online Store Offline After Password Hashes Exposed
Škoda has confirmed a cyberattack on its German online store. While customer data and password hashes were exposed, forensic investiga…

Active OAuth Redirection Attacks Targeting Government Entities via Entra ID
Microsoft has identified a phishing campaign exploiting OAuth 2.0 flows to deliver multi-stage malware to public sector organizations,…

Weaponized OAuth: Government and Public Sector Targeted in Malicious Redirection Campaign
Microsoft researchers have identified active campaigns abusing OAuth redirection to steer government and public sector entities toward…

Vishing and AiTM Bypass MFA: Invisible Extortion in SaaS
Criminal groups like Cordial Spider use vishing and AiTM to bypass MFA and target SaaS environments. Protect your corporate data from…

Russian Aviation Phishing: Drone Simulators Steal Sensitive Data
HeartlessSoul phishing campaign targets Russian aviation: drone simulators and Starlink tools steal geospatial data. Here is what you…

Cyberattacks and Cargo Theft: RMM Risk in Logistics
The impact of cyberattacks on cargo theft: how phishing and RMM software hijack goods in logistics. Here's what to know about the new…

Bluekit Risk: The AI Phishing Kit That Bypasses MFA
Discover how Bluekit, the new AI phishing kit, leverages Evilginx to bypass MFA on over 40 platforms. Learn what you need to know to p…