One approved MFA push gave ShinyHunters-linked callers a brief view-only session inside ReliaQuest.
ShinyHunters dumped account data after RingCentral refused an extortion demand.
Google ties a vishing wave against finance and legal firms to UNC6671, which calls staff on personal phones.
Okta warns of a rise in voice phishing attacks where callers impersonate IT support to steal Microsoft 365 credentials and…
The Muddled Libra threat actor uses voice phishing and fake Microsoft Entra passkey enrollment portals to gain persistent access to…
The Helix group uses vishing and device code phishing to break into SharePoint, then exfiltrates data for extortion or sale.