Tag: email
-
Revolut handed customer data to fraudsters using government email account
British fintech Revolut confirmed disclosing sensitive customer data to fraudsters who submitted emergency data requests from a legitimate government email account. First seen on therecord.media Jump to article: therecord.media/revolut-scam-crypto-impersonation
-
Protecting Microsoft 365 and Google Workspace: Why Email Security and Backup Belong Together
Originally published at Protecting Microsoft 365 and Google Workspace: Why Email Security and Backup Belong Together by Mike Anderson. Microsoft 365 and Google Workspace have become essential to how businesses communicate, collaborate, and operate. But as these platforms have become… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/protecting-microsoft-365-and-google-workspace-why-email-security-and-backup-belong-together/
-
What we know about the Revolut data breach so far
Someone impersonating a government agency, using an email address on that agency’s domain, obtained sensitive customer records from Revolut. The bank confirmed the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/14/revolut-data-breach-privacy/
-
Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users
A Casbaneiro banking Trojan campaign targeting users across Latin America, using phishing lures, geofenced delivery infrastructure, and distributed command-and-control (C2) servers to obscure malicious activity. The operation, observed in August 2026, primarily targets victims in Argentina, Peru, Colombia, and Mexico through fake invoice and legal-notice emails carrying links to malicious PDF files. The campaign demonstrates…
-
Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users
A Casbaneiro banking Trojan campaign targeting users across Latin America, using phishing lures, geofenced delivery infrastructure, and distributed command-and-control (C2) servers to obscure malicious activity. The operation, observed in August 2026, primarily targets victims in Argentina, Peru, Colombia, and Mexico through fake invoice and legal-notice emails carrying links to malicious PDF files. The campaign demonstrates…
-
Security Affairs newsletter Round 594 by Pierluigi Paganini INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open…
-
Saturday Security: AI Industrializes Phishing
This week’s Saturday Security Story shows how AI is industrializing an old scam, and doing it at a scale that should get everyone’s attention. Microsoft spotted a campaign that blasted more than 1 million fraudulent emails across a three-day… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/saturday-security-ai-industrializes-phishing/
-
Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
Cybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/1m-personalized-fraud-emails-3-days
-
The Cost of Silence: Why Fear Kills Phishing Reporting
An employee clicks a link in an urgent email that seems to come from payroll. A login page flashes, then vanishes. In that split second, a cold wave of dread hits them. Their stomach drops, their heart rate spikes, and their… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/the-cost-of-silence-why-fear-kills-phishing-reporting/
-
Microsoft sees some new wrinkles in invoice-scam emails
Researchers analyzed a flood of fraudulent business emails and found that the threat actors had doubled-up on tactics to make them appear legitimate, including help from AI. First seen on therecord.media Jump to article: therecord.media/invoice-scam-emails-new-features-microsoft-researchers
-
McKesson Data Leak Includes 6.4M Email Addresses After $55.2M Extortion Demand
McKesson breach data includes 6.4 million unique email addresses after ShinyHunters allegedly demanded $55.2 million to keep the records private. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/news-mckesson-breach-6-4-million-shinyhunters/
-
Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider
This is the second data breach affecting a company that hardware crypto wallet maker Trezor relies on. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/11/scammers-target-hundreds-of-thousands-of-crypto-owners-after-trezor-confirms-data-breach-of-email-provider/
-
Hackers Favor US Eastern Business Hours in M365 Phishing Campaign
KnowBe4 researchers observed a new phishing campaign leveraging Microsoft 365’s Direct Send to send malicious emails First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/hackers-us-business-hours-m365/
-
Trezor: 347,000 users targeted in phishing attacks after Brevo breach
Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/trezor-347-000-users-targeted-in-phishing-attacks-after-brevo-breach/
-
Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
Threat actors are using AI-assisted phishing templates, executive impersonation, fake ServiceNow invoices, and fabricated email threads to pressure finance teams into authorizing fraudulent ACH payments worth nearly $50,000. Microsoft detected more than one million messages in the campaign, demonstrating how business email compromise (BEC) operations are becoming more polished, scalable, and difficult to spot. The…
-
Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
Threat actors are using AI-assisted phishing templates, executive impersonation, fake ServiceNow invoices, and fabricated email threads to pressure finance teams into authorizing fraudulent ACH payments worth nearly $50,000. Microsoft detected more than one million messages in the campaign, demonstrating how business email compromise (BEC) operations are becoming more polished, scalable, and difficult to spot. The…
-
Companies may be measuring phishing resilience the wrong way
Companies that judge phishing simulation programs by how often employees click simulated attack emails may be overlooking more important indicators of cyber resilience, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/11/pistachio-employee-phishing-risk-report/
-
Multiple crypto companies warn customers of phishing emails after alleged provider breach
Subscribers to newsletters from Trezor, CoinTracking and BitBox received corrupted messages through an email provider that all three companies use. First seen on therecord.media Jump to article: therecord.media/trezor-bitbox-cointracking-phishing-crypto-holders
-
Cryptohack Roundup: Trezor’s Phishing Warning
Also: ‘White-Hat’ Hackers Withdraw $320M From Liquid. Every week, ISMG rounds up cybersecurity incidents in digital assets. This week, Trezor warns customers after email provider breach, Liquid pauses network after $320 million Bitcoin withdrawal, man pleads guilty in $245 million theft and India targets 15 crypto platforms over compliance failures. First seen on govinfosecurity.com Jump…
-
Mapping Cequence AI Gateway Controls to OWASP’s Top 10 for Agentic Applications
Hidden instructions embedded in a shared document were enough to turn a Microsoft 365 Copilot session into a channel for exfiltrating sensitive data, an incident now known as “EchoLeak”, no phishing email, no malicious click, just a document the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mapping-cequence-ai-gateway-controls-to-owasps-top-10-for-agentic-applications/
-
Mapping Cequence AI Gateway Controls to OWASP’s Top 10 for Agentic Applications
Hidden instructions embedded in a shared document were enough to turn a Microsoft 365 Copilot session into a channel for exfiltrating sensitive data, an incident now known as “EchoLeak”, no phishing email, no malicious click, just a document the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mapping-cequence-ai-gateway-controls-to-owasps-top-10-for-agentic-applications/
-
Mapping Cequence AI Gateway Controls to OWASP’s Top 10 for Agentic Applications
Hidden instructions embedded in a shared document were enough to turn a Microsoft 365 Copilot session into a channel for exfiltrating sensitive data, an incident now known as “EchoLeak”, no phishing email, no malicious click, just a document the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mapping-cequence-ai-gateway-controls-to-owasps-top-10-for-agentic-applications/
-
Mapping Cequence AI Gateway Controls to OWASP’s Top 10 for Agentic Applications
Hidden instructions embedded in a shared document were enough to turn a Microsoft 365 Copilot session into a channel for exfiltrating sensitive data, an incident now known as “EchoLeak”, no phishing email, no malicious click, just a document the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mapping-cequence-ai-gateway-controls-to-owasps-top-10-for-agentic-applications/
-
Mapping Cequence AI Gateway Controls to OWASP’s Top 10 for Agentic Applications
Hidden instructions embedded in a shared document were enough to turn a Microsoft 365 Copilot session into a channel for exfiltrating sensitive data, an incident now known as “EchoLeak”, no phishing email, no malicious click, just a document the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mapping-cequence-ai-gateway-controls-to-owasps-top-10-for-agentic-applications/
-
MSP New Client Onboarding Checklist for DMARC Implementation
Originally published at MSP New Client Onboarding Checklist for DMARC Implementation by Anush Yolyan. A new client usually does not come with a perfect list of every system that sends emails for them. They may use Microsoft 365 or Google… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/msp-new-client-onboarding-checklist-for-dmarc-implementation/
-
B2B SaaS Product Launch Email: Tips Examples
Introduction As a B2B SaaS provider, one of the best ways to keep your existing customers engaged, informed, and excited about your brand is through product announcement emails. These emails serve as a powerful tool to not only announce new… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/b2b-saas-product-launch-email-tips-examples/
-
Trezor warns users of email provider breach, phishing attacks
Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/trezor-warns-users-of-email-provider-breach-phishing-attacks/

