Almost 8000 organizations hit by fake voicemail transcript emails in credential phishing attack
- Check Point spotted phishing emails spoofing voicemail transcript notifications, hitting 7,800+ orgs
- Malicious SVG attachments auto‑fill victim emails, redirecting to fake login pages for credential theft
- SVG format bypasses filters; businesses urged to verify notifications and treat SVGs as active content
Hackers have a new phishing lure - the automated voicemail transcript notification, and have already used it against thousands of organizations already, sending tens of thousands of malicious emails.
In a new report, security experts from Check Point Research (CPR) said they spotted an ongoing campaign that has already targeted thousands of organizations.
The goal of the campaign seems to be credential theft - grabbing access to people’s email accounts, business services, and similar.
Abusing the trends
The proliferation of AI gave rise to a new trend in the office - automated voicemail transcripts. When a person receives a voicemail, they can choose to read it instead of listening...
Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE