Index live· 1,284 files · 148 editions
ForensicPost

Search the index

24 results
Try
Results for “Phishing”Newest first
26-0527
File

Carnival Reports Phishing Breach Affecting Close to Six Million Guests

A phishing-led compromise affecting close to six million guests, including passport numbers a passenger could never have declined to provide.

UnattributedPhishing → accountRetailIdentity
Sev 4TargetCarnival CorporationActorUnattributed
26-0429
File

ShinyHunters Campaign Compromised More Than a Thousand Organisations via Device Code Phishing

More than a thousand organisations through device code phishing. There is nothing to patch, which is why the campaign has no natural ceiling.

ShinyHuntersDevice code phishingCloudTokens
Sev 4TargetSaaS tenants, multipleActorShinyHunters
26-0322
File

Thirteen Million Support Tickets, Allegedly, Through a Contractor

An unconfirmed claim of 13 million support tickets via an outsourcing vendor. The access transfers; the control environment does not.

Mr. RaccoonBPO vendor phishingCloudThird party
Sev 3TargetAdobe (alleged)ActorMr. Raccoon
25-1208
File

Princeton and Harvard Breached by Phone-Based Phishing Against Alumni Offices

Princeton was compromised. The difference was what happened in the next twenty-four hours.

UnattributedVoice phishingEducationEducation
Sev 4TargetPrinceton; HarvardActorUnattributed
25-1029
File

ShinyHunters Used Stolen CRM Data to Phish the Affected Firms' Own Clients

There is no version of “monitor your accounts” that helps somebody who has already taken the call.

ShinyHuntersTargeted phishingCloudExtortion
Sev 4TargetTenant clients and personnelActorShinyHunters
25-1026
File

Princeton Detected and Ejected Attackers Within a Day

Twenty-four hours is not an improvement on 102 days. It is a different regime.

UnattributedVoice phishingEducationMethod
Sev 3TargetPrinceton UniversityActorUnattributed
25-1024
File

The Fundraising Office Is the Softest Part of a University

The reached system is almost never the one the security programme was built around.

MultipleVoice phishingEducationAnalysis
Sev 3TargetUniversity advancement officesActorMultiple
25-1022
File

Retail, Insurance, Aviation and Universities All Fell to the Same Phone Call

There is no packet to inspect and no domain to block. The output of the call is a legitimate action by an authorised person.

MultipleVoice phishingMultipleMethod
Sev 5TargetMultiple sectorsActorMultiple
25-1020
File

Will the Donors Be Told?

A wealth capacity assessment is an estimate of what somebody could afford, recorded about them, which they have never seen.

UnattributedVoice phishingEducationAccountability
Sev 3TargetUniversity donorsActorUnattributed
25-0923
File

One Technique, One Platform, Several Hundred Companies

What concentrated was not the data but the method. Every tenant presents the same consent screen and the same vocabulary for a caller to use.

ShinyHuntersConsent phishingCloudExtortion
Sev 4TargetSaaS platform tenantsActorShinyHunters
25-0806b
File

Attackers Posing as HR and IT Staff Phoned Workday Employees

An HR pretext works everywhere. Employees are conditioned not to question it, because the topics are personal and the consequences are employment-related.

ShinyHuntersVoice and SMS phishingCloudIdentity
Sev 3TargetWorkdayActorShinyHunters
25-0813
File

Attackers Registered Their Own MFA Device After Phishing an SSO Code

A stolen code is worth one authentication. An enrolled device is worth all of them, and a password reset does not remove it.

ShinyHuntersMFA enrolmentCloudIdentity
Sev 4TargetEnterprise SSO accountsActorShinyHunters
25-0806
File

Operators Posing as IT Staff Had Employees Authorise a Connected App

Every anti-phishing control is looking for a fake site. There was no fake site — the employee consented on the real one.

ShinyHuntersConsent phishingCloudIdentity
Sev 4TargetEnterprise SaaS tenantsActorShinyHunters
25-0615b
File

Half of Businesses, a Third of Charities

For most organisations, most of the time, the answer is a phishing email. The rest is what happens to those worth the effort.

MultiplePhishingMultipleVerification
Sev 3TargetUK businesses and charitiesActorMultipleUnited Kingdom
25-0311
File

The Consent Screen Asks a Question Nobody Can Answer

A control that is correct 999 times out of 1,000 teaches people to stop reading it. That is not user failure.

MultipleConsent phishingCloudMethod
Sev 3TargetSaaS consent modelsActorMultiple
23-1220
File

MongoDB Says Phishing Reached Support Systems but Not Customer Clusters

No lookalike domain and no spoofed sender. The message came from a real colleague’s real account.

UnattributedPhishingTechnologyIdentity
Sev 2TargetMongoDBActorUnattributed
23-0913
File

A Synced Authenticator Turned Retool’s Second Factor Into No Factor

Once the seeds live in an account protected by the same identity, there is one factor wearing two names.

UnattributedSMS phishingTechnologyIdentity
Sev 4TargetRetoolActorUnattributed
23-0712
File

JumpCloud Says a Nation-State Phish Reached Fewer Than Five Customers

The blast radius was tiny because the targeting was precise, not because the access was limited.

UNC4899Spear-phishingTechnologySupply chain
Sev 4TargetJumpCloudActorUNC4899
23-0619
File

Reddit Says Phishing Took Source Code and Internal Documents, Not User Passwords

The only demand in this database attaching a condition unrelated to payment. Nobody repeated it.

ALPHV/BlackCatPhishingTechnologyActors
Sev 3TargetRedditActorALPHV/BlackCat
22-1220
File

Guardian Ransomware Exposed UK Staff Data and Closed Its London Office for Six Weeks

It held the information, had the means to publish, and every commercial reason not to.

UnattributedPhishing — as reportedMediaAftermath
Sev 3TargetThe GuardianActorUnattributedUnited Kingdom
22-1104
File

Vanuatu Government Systems Stayed Offline for Weeks as Officials Used Personal Email

The fallback kept the state running, and put a month of government correspondence in consumer mailboxes.

UnattributedPhishing — as reportedGovernmentPublic sector
Sev 5TargetGovernment of VanuatuActorUnattributedVanuatu
22-1101
File

Dropbox Says Phishing Reached 130 Repositories After a Hardware Key Code Was Relayed

Cloudflare was not saved by the metal. It was saved by origin binding — and this key was not doing that.

UnattributedPhishing → OTP relayTechnologySupply chain
Sev 3TargetDropboxActorUnattributedUSA
22-0808
File

Same Phish, Same Week, Two Companies, Two Outcomes

Three Cloudflare employees typed their password into the attacker’s page. Nothing happened.

0ktapusSMS phishing → credential relayTechnologyIdentity
Sev 4TargetTwilioActor0ktapusUSA
ACT-004
Actor

ShinyHunters

Voice phishing into identity providers, then leak-site extortion. Active since 2020.

VishingSSOLeak siteData theft
Profile
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging