Every story tagged Phishing, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
39 stories · open in the command center
GenAI has made phishing far more scalable, convincing, and difficult to detect, turning a long-standing nuisance into a material enterprise risk that can lead to account compromise, cloud/SaaS intrusion, and costly financial fraud. For CIOs and technology leaders, the strategic shift is clear: legacy filter-based email defenses are no longer enough, and IT organizations need AI-driven, context-aware protections that evaluate intent and behavior rather than relying on grammar errors or obvious malicious indicators.
A fast-moving browser-in-browser phishing campaign is impersonating trusted AI and advertising brands to steal advertising credentials, MFA codes, payment methods, and even linked client accounts, creating direct financial loss and operational risk for marketing and digital teams. For CIOs and technology leaders, the key implication is that attackers can rapidly rebrand a reusable phishing platform, so IT organizations need stronger identity controls, continuous domain/reputation monitoring, and detections that work across Google, Meta, TikTok, and Okta workflows—not just brand-specific defenses.
England’s secondary schools are seeing fewer reported cyber incidents and much faster recovery, with two-thirds restoring operations immediately and fewer incidents causing critical damage. However, the data also highlights weak security ownership and maturity: many staff don’t know what changes were made, responsibility is still seen as an IT issue rather than a leadership mandate, and training is often ineffective. For CIOs and technology leaders, the strategic takeaway is that resilience is improving, but lasting risk reduction will require stronger governance, clearer accountability, tested backups, and better staff awareness—not just technical controls.
Threat actors are abusing legitimate OpenAI and Google infrastructure, including malicious Custom GPTs, to lure users into a ClickFix-style infection chain that installs remote access Trojans (RATs) and additional malware. For CIOs and technology leaders, this is a reminder that trusted AI platforms can be weaponized as delivery channels, increasing the risk of credential theft, endpoint compromise, and broader enterprise intrusion even when employees believe they are interacting with sanctioned services. IT organizations should assume attackers will exploit user trust in reputable SaaS and AI tools, making layered endpoint controls, web filtering, and rapid detection/containment essential.
Russia-linked Star Blizzard is shifting from a narrow, multi-step phishing approach to a lower-friction, higher-volume technique that requires only one user click to deliver malware, increasing the odds of successful compromise and making detection harder. For CIOs and IT leaders, this signals that nation-state adversaries are scaling social engineering against NGOs, think tanks, government, and adjacent organizations, so email defenses, identity protections, endpoint telemetry, and rapid incident response need to be treated as strategic controls, not just user-awareness issues.
A fake iPhone Duo preorder site is being used to exploit older, unpatched iPhones and quietly exfiltrate high-value data including crypto wallet files, saved credentials, notes, and other personal information. For CIOs and technology leaders, the business risk extends beyond consumer fraud: compromised employee mobile devices can expose corporate identities, sensitive communications, and financial assets, reinforcing the need for aggressive mobile patching, link filtering, and endpoint visibility.
Google’s new Gboard scam detection adds another layer of defense against mobile smishing by warning users before they send replies to suspicious texts, which could reduce account compromise, fraud losses, and time spent responding to incidents. For CIOs and technology leaders, the strategic takeaway is that Google is pushing more security onto-device and closer to the user, but the feature is limited to eligible Pixel devices and is not fully reliable, so it should be treated as a supplemental control rather than a primary defense. IT organizations should view it as part of a broader mobile security and user-awareness strategy that still depends on policy, training, and verification workflows.
Dutch police have arrested a suspected member of the ShinyHunters cybercrime group, underscoring how organized threat actors continue to target enterprises through social engineering, credential abuse, and internal-system access rather than only technical exploits. For CIOs and technology leaders, the business impact is clear: these campaigns can expose millions of customer records, drive regulatory and reputational risk, and disrupt operations even when attackers initially gain access through a single employee interaction. IT organizations should treat this as a reminder to tighten identity verification, privileged access controls, and detection for vishing and insider-style intrusion paths.
AI is lowering the skill and time required for cyberattacks, allowing a single actor to automate reconnaissance, phishing, and exploitation at scale, which disproportionately raises risk for hospitals, banks, nonprofits, municipalities, and other resource-constrained organizations. For CIOs, the strategic implication is that cybersecurity must be built for AI-accelerated adversaries: assume faster, more frequent attacks, strengthen core controls and detection/response, and don’t rely on premium AI defense tools that may be out of reach for many IT budgets.
A malware campaign is using Google ads to deliver convincing tech-support scams that freeze Windows and Mac browsers, bypassing some ad filters and endpoint defenses while exposing users across hundreds of legitimate sites. For CIOs and IT leaders, the business risk is not just fraud loss but also help desk disruption, reputational damage, and the need to harden user awareness, browser controls, and detection around ad-delivered threats that can evade traditional security layers.
This article highlights how voice-phishing operations are becoming more organized, scalable, and deceptive, even when the criminals themselves make mistakes. For CIOs and technology leaders, the business impact is clear: social engineering remains a top initial-access vector, especially for cloud environments, so IT organizations need stronger identity verification, layered access controls, and more realistic employee training to reduce the risk of account takeover and fraud.
Party-invite phishing is a reminder that AI-enhanced social engineering is making email threats more convincing, more personal, and harder for employees to distinguish from legitimate communication. For CIOs and technology leaders, the business risk goes beyond credential theft and fraud: these scams can bypass traditional controls by exploiting trust, urgency, and familiar platforms, increasing the need for stronger identity protections, user verification workflows, and continuous security awareness across the organization.
Revolut’s latest breach underscores how third-party and legacy data relationships can create significant security, compliance, and reputational risk even when a company’s own systems are not directly compromised. For CIOs and technology leaders, the key implication is that vendor governance, data retention controls, and identity-verification workflows must be treated as core parts of the security architecture, because exposed customer attributes can fuel phishing, impersonation, and fraud at scale.
Salesforce Agentforce had multiple vulnerabilities that could let attackers poison public lead inputs, silently exfiltrate CRM data without a user click, and send phishing messages under the agent’s identity. For CIOs and technology leaders, the business risk is not just data loss but loss of trust in AI-driven workflows: as agents gain access to sensitive systems and external content, traditional secure-by-design approaches are not enough without stronger containment, monitoring, and governance. IT organizations should treat agent security as an enterprise control plane issue, especially where AI agents connect CRM, Slack, and other collaboration tools.
This article highlights a new security risk in agentic AI workflows: untrusted content can be carried from the web through AI-connected business apps and end up as seemingly trusted messages in internal channels like Slack. For CIOs and technology leaders, the business impact is increased exposure to phishing, social engineering, and unauthorized actions that can compromise operations, while the strategic implication is that AI governance must extend beyond model safety to include app-to-app data flows, permission boundaries, and message provenance across the enterprise stack. IT organizations will need to treat AI agents as privileged integrations that require tighter controls, monitoring, and incident response planning.
This article highlights a phishing technique that uses one carefully crafted URL to confuse different security tools: browsers, email filters, and URL scanners can each interpret it differently, allowing malicious links to slip past controls. For CIOs and technology leaders, the business risk is reduced effectiveness of layered defenses and increased likelihood of credential theft, which means IT organizations need stronger URL parsing, normalization, and detection logic across email, web, and security platforms.
The article argues that AI agents are crossing from novelty to practical business tools, with the potential to automate routine work like scheduling, reservations, travel changes, and other administrative tasks that consume employee time. For CIOs and technology leaders, the strategic implication is clear: agentic AI could materially improve productivity and user experience, but only if IT organizations address major risks around security, data retention, permissions, vendor access, and operational reliability before broad deployment.
Microsoft and partners disrupted EvilTokens, a phishing-as-a-service operation that used AI and device code phishing to compromise more than 12,000 inboxes across over 10,000 organizations worldwide, underscoring how quickly identity attacks can scale into broad business email compromise risk. For CIOs and IT leaders, the incident reinforces that Microsoft 365 and identity controls are a front-line business resilience issue: organizations need stronger phishing-resistant authentication, tighter session/token monitoring, and faster detection of anomalous inbox and Graph API activity to limit financial fraud and lateral exposure.
Attackers are poisoning AI chatbot and AI-overview results with optimized fake support pages, reviews, and login links so tools like ChatGPT, Gemini, and Google AI Overview surface fraudulent guidance as if it were authoritative. For CIOs, this turns AI from a productivity enhancer into a potential trust and brand-risk multiplier: employees and customers may be redirected to phishing sites or bad support numbers, while IT and security teams must now defend not just endpoints and inboxes, but the information supply chain feeding AI systems.
Microsoft disrupted an AI-assisted scam platform that compromised 12,000 accounts across 10,000 organizations, showing how attackers are using automation to scale email compromise and fraud faster than traditional defenses can react. The key strategic shift is that once an inbox is breached, AI can rapidly map relationships, identify payment authorities, and craft convincing follow-up lures—compressing attacker analysis from days to minutes and increasing business risk for finance, operations, and customer trust. For IT organizations, this elevates identity hardening, OAuth/device-code controls, and behavioral monitoring from technical hygiene to core business protection measures.
The article highlights how AI is changing the phishing threat landscape by making social engineering attacks more convincing, scalable, and harder for employees to detect. For CIOs and technology leaders, the strategic implication is that traditional one-size-fits-all security awareness programs are no longer sufficient; IT organizations need more tailored, behavior-based phishing simulations and training that reflect real-world attack patterns and user risk profiles. This shifts phishing defense from a compliance exercise to a continuous resilience program tied to measurable employee behavior and security outcomes.
The article highlights how simple Gmail configuration changes—reporting phishing, tightening spam filters, blocking domains/senders, and maintaining blocklists—can materially reduce AI-enabled scam and spam exposure at the user level. For CIOs and technology leaders, the strategic takeaway is that email security is still a frontline control: IT organizations should combine technical filtering with user-driven reporting and hygiene to lower phishing risk, reduce help desk noise, and protect employees from credential theft and business email compromise.
ClickFix attacks have become a mainstream, cross-platform threat because they use a simple fake-CAPTCHA social engineering flow to trick users into running malicious terminal commands on Windows and macOS, bypassing many traditional malware delivery controls. For CIOs and technology leaders, the strategic implication is that attacker tradecraft is shifting from infrastructure-heavy delivery to user-executed compromise, expanding the attack surface to any employee browsing a compromised site and increasing the importance of layered endpoint, browser, and identity protections. IT organizations should expect higher incident volume from this technique and treat user behavior, device hardening, and web-content controls as core parts of the defense strategy rather than optional awareness measures.
Amazon is using its AI assistant as a trust-and-verification layer to help customers confirm whether emails, texts, or calls claiming to be from the company are genuine, which can reduce impersonation fraud and lower support friction. For CIOs and technology leaders, this signals a broader shift toward AI being embedded in security and customer-experience workflows, raising the bar for how organizations authenticate outbound communications and protect users from phishing and spoofing. IT teams should view this as a model for strengthening identity verification, improving message integrity, and aligning support processes with AI-enabled fraud detection.
Amazon’s new AI capability for Alexa for Shopping can verify whether a message claiming to be from Amazon is legitimate or a scam, addressing a large and costly customer pain point while reducing pressure on support teams. Strategically, this shows how AI is moving from convenience features into trust and safety functions, signaling that IT organizations should expect greater demand for AI-enabled fraud detection, identity verification, and customer self-service across digital channels.
A sophisticated threat actor has orchestrated a coordinated campaign targeting dozens of U.S. private equity firms and other financial institutions using multi-vector attacks combining phone-based social engineering, phishing websites, and meticulous reconnaissance tactics. This represents a significant escalation in targeting high-value organizations and demonstrates that traditional security controls are insufficient against determined adversaries willing to invest substantial effort in reconnaissance and personalized attacks. IT leaders must recognize that financial services and PE firms are prime targets and that human-centric attack vectors remain a critical vulnerability despite technological defenses.
Threat actors are increasingly exploiting legitimate cloud platforms (Cloudflare Workers, Vercel, Netlify, GitHub Pages) to host sophisticated phishing infrastructure, leveraging platform reputation and built-in anonymity features to evade detection at scale. These multi-stage attacks use adversary-in-the-middle techniques combined with service workers to intercept credentials and MFA sessions, making traditional domain-blocking strategies ineffective and requiring security teams to shift toward advanced content-based detection methods. For IT organizations, this represents a critical gap where trusted cloud vendors become attack vectors, demanding enhanced email security, user authentication monitoring, and closer vendor relationship management to identify and respond to account compromise campaigns.
Legitimate delivery and payment notification systems are so poorly designed and riddled with security flaws that they are indistinguishable from phishing attacks, creating a critical vulnerability where users cannot reliably authenticate genuine communications. This represents a systemic failure where major companies like FedEx and financial institutions like Commonwealth Bank have implemented payment verification systems with basic security defects (parameter tampering, inconsistent formatting, invalid links) that actively enable scammers and erode user trust. IT organizations must recognize that security education alone cannot protect against threats when legitimate systems exhibit identical red flags to malicious ones, requiring urgent collaboration with business and product teams to redesign customer-facing authentication and payment processes.
Online scams cost Americans an estimated $150 billion annually—seven times higher than FBI-reported figures—driven by AI-enabled deepfakes, compromised business email, and investment fraud, creating significant cybersecurity and operational risks for organizations. With only 14% of victims reporting crimes and Meta platforms facilitating 87% of scam distribution, IT leaders face mounting pressure to implement advanced threat detection, employee training, and incident response protocols. This dramatic underreporting gap signals that cyber risk exposure in enterprise environments is likely substantially underestimated, requiring urgent reassessment of security budgets and third-party platform governance.
The episode highlights a critical security threat: callback phishing attacks exploiting auto-notifications and verification alerts, which represents an evolving attack surface that enterprises must address in their security posture. CIOs should recognize that traditional email security solutions (reminiscent of legacy tools like Postini) are insufficient against modern phishing vectors that abuse legitimate system notifications and user workflows. This underscores the need for comprehensive endpoint security strategies and user awareness programs that extend beyond email filtering to protect against social engineering attacks leveraging system-level notifications.