Log in to see all content. Some content is hidden to the public.
Can't find what you're looking for? Help us improve the search functionality by reporting the expected results.
193 Results
Feb 2023: Phishing Attacks Distribute IRS Notice-Themed Lures
Cybercriminals have launched a series of phishing attacks using timely tax-themed lures. While the email from field says “Irs notice” and then the name of the organization, the sending address is a Madwire account.The phishing emails contain an HTML attachment allegedly containing delivery details about a tax related USPS letter. Opening the attachment leads to a lookalike Microsoft login page designed to steal credentials.
Dec 2022: HIPAA-Related Lures
Cybercriminals have launched a series of phishing attacks impersonating the legitimate law firm, including Latham & Watkins.
Fortifying Digital Defenses: The Power of Security Tools at UCSF
Learn about IT Security Tools and pass the quiz at the end of the article.
May 2023: Phishing Kit Uses Finance-Themed Lures
Cybercriminals are increasingly using phishing-as-a-service kits to build and distribute lookalike Microsoft Office 365 landing pages via phishing lures. The phishing lures can be customized to have a variety of different appearances or themes.
Mar 2023: Invoice-Themed Phishing Lures Spreading Malware
Cybercriminals have launched phishing attacks using malicious invoice-themed attachments to spread malicious software (malware).The phishing attacks hijack legitimate email threads to deliver the phishing lures to further increase the believability of the attacks. This means the lures may appear to be response to previous, legitimate email conversations.The malicious attachments used in this campaign are extremely large, zipped Microsoft Word files.
Feb 2023: Phishing Attacks Use Earthquake-Themed Lures
Cybercriminals have launched multiple phishing attacks attempting to take advantage of the humanitarian crisis in Turkey and Syria following the earthquake. These attacks are intended to steal recipient’s funds or to lead to the installation of malicious software (malware). As multiple attacks are exploiting this crisis, lures will appear different.
Jan 2023: Phishing Attacks Abuse Microsoft OneNote
Recent email-based attacks have abused Microsoft’s legitimate OneNote application to share malicious files. The emails use subject lines like “New Document Shared with you” and encourage the recipient to follow a link to view a shared OneNote file. The OneNote link leads recipients to a shared document which contains the text “DOUBLE CLICK TO DOWNLOAD THE FILE NOW.”Some attacks may also distribute similar malicious OneNote files as email attachments.
Nov 2022: Twitter-Themed Lures Used in Credential Phishing Attacks
Cybercriminals have launched phishing attacks impersonating Twitter Services. The emails include links to lookalike landing pages that are designed to steal Twitter credentials and phone numbers.While the email display names make it appear the messages come from “Twitter Services,” the actual sending address is a Gmail account.The emails use the proposed change at Twitter of charging verified users a monthly fee to maintain their verification status.
Mar 2023: Global Phishing Campaigns Using Tax Season Lures
Cybercriminals have launched numerous, different phishing attacks using timely tax-themed lures. As multiple attacks are leveraging this topic, the lures will appear different. Lures may attempt to impersonate tax or revenue agencies, as well as companies or individuals asking for or offering to provide tax-related services.
Feb 2023: Valentine’s Day-Themed Lures
Cybercriminals have launched phishing attacks claiming to be senior executives offering employees a Valentine’s Day-themed reward in appreciation of their work. The message purporting to be from executives might compel users to engage with the supposed employer-related communications.