Attackers are going after prominent individuals through OAuth phishing, FBI warns
Attackers are targeting prominent individuals and their personal contacts through OAuth consent phishing attacks to gain persistent access to accounts including private emails and files, according to an FBI warning. This sophisticated technique, which has been active since late 2025, deceives users into granting access without requiring passwords. The FBI's Internet Crime Complaint Center is tracking the ongoing campaign aimed at compromising high-profile targets.
Keepnet has released a free iOS app called SMS/Call Reporter that enables users to quickly report suspicious text messages and phone calls with a single tap. The application is available for both personal use and organizational deployment, with an Android version planned for future release. For Keepnet customers, reported incidents integrate directly into their Extended Human Risk Management platform.
The ongoing social engineering threat, which dates back to late 2025, tricks victims into granting threat actors long-term access to their accounts. The post FBI raises alarm over deceptive phishing campaign targeting prominent people appeared first on CyberScoop.
A coordinated vishing campaign called Spring Ring exploited Microsoft Teams by creating fake IT support accounts designed to impersonate internal teams, targeting employees across more than 10 companies between January and April 2026. Attackers contacted over 150 employees through these fraudulent accounts, attempting to trick them into installing malware or granting remote access to their systems. The campaign demonstrates how legitimate collaboration platforms can be weaponized for initial network compromise when attackers craft convincing social engineering pretexts.
The most common way into a company last year was to ask. A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through opening a terminal and pasting it in. The technique is called ClickFix, and it was the most common initial access method Microsoft’s team observed last year, accounting