Topic

Phishing & Fraud

Phishing, social engineering and financial fraud — including how campaigns now get past MFA.

17 articles in this topic

Cloud & Identity

EvilTokens PhaaS: Device Code Phishing Bypasses MFA to Hijack Microsoft 365 Accounts

EvilTokens PhaaS platform has compromised 340+ Microsoft 365 orgs by abusing OAuth device code flow to bypass MFA. Learn how Saudi financial institutions can defend against this active threat.

21 May 2026 5 min
Cloud & Identity

Tycoon2FA Rebounds: Device-Code Phishing Bypasses MFA to Hijack Microsoft 365 Accounts

The Tycoon2FA phishing-as-a-service kit has rebounded after a March takedown, now weaponizing OAuth device-code flows to steal Microsoft 365 tokens — rendering traditional MFA useless. Here's what Saudi CISOs need to know.

19 May 2026 6 min
Ransomware

Vishing and SSO Abuse: How Cybercrime Groups Are Executing Rapid SaaS Extortion in Minutes

Cybercrime groups like ShinyHunters are combining AI-powered vishing calls with SSO exploitation to breach SaaS environments in under 45 minutes. Learn how Saudi financial institutions can defend against this rapidly evolving threat.

17 May 2026 5 min
Breaches & Data Leaks

Cushman & Wakefield Vishing Breach: How One Phone Call Exposed 500K Salesforce Records

A single vishing call gave ShinyHunters access to 500,000 Salesforce records at Cushman & Wakefield. Two ransomware groups now claim the data. Here's what went wrong and why Saudi institutions must act now.

13 May 2026 6 min
Phishing & Fraud

VENOMOUS#HELPER RMM Phishing Campaign: Risk to SAMA Banks

A new initial-access campaign is hijacking legitimate RMM tools — SimpleHelp and ScreenConnect — to slip past EDR and establish dual-channel persistence. Here is why CISOs at SAMA-regulated banks must act this week.

8 May 2026 4 min
Phishing & Fraud

AiTM Phishing Campaign 2026: 35,000-Victim MFA Bypass Threatens SAMA Banks

Microsoft Defender Research uncovered a multi-stage AiTM phishing campaign that hit 35,000 users across 26 countries — financial services was 18% of victims. What SAMA-regulated banks must do today.

7 May 2026 4 min
Phishing & Fraud

AccountDumpling: Google AppSheet Phishing Bypasses DMARC — A SAMA Email Risk

Attackers are weaponizing Google AppSheet's noreply@appsheet.com address to send phishing emails that pass SPF, DKIM and DMARC. The AccountDumpling campaign is a wake-up call for every SAMA-regulated bank that treats email authentication as a finished control.

6 May 2026 4 min
Phishing & Fraud

The Deepfake Threat Saudi Financial CISOs Can No Longer Ignore: AI Voice Cloning, CEO Fraud, and KYC Bypass in 2026

A darknet actor is selling real-time deepfake tools that defeat bank KYC in seconds. Across the GCC, fraudsters are impersonating CEOs with AI-cloned voices to authorize wire transfers. Saudi financial institutions need a response framework — now.

18 Apr 2026 6 min
Cloud & Identity

EvilToken: The AI-Powered Phishing Kit That Defeats MFA and Targets Saudi Financial M365 Environments

A new phishing-as-a-service toolkit called EvilToken is bypassing MFA at scale using AI-generated lures and OAuth device code abuse, targeting M365 users across the UAE and beyond — a direct risk to Saudi financial institutions.

18 Apr 2026 5 min
Supply Chain & Third Party

Booking.com's ClickFix Supply Chain Breach: The Third-Party Vendor Risk Every Saudi Financial CISO Must Address Now

Booking.com confirmed a breach exposing millions of customers' reservation data — attackers never touched Booking.com directly. They compromised hotel partners using ClickFix malware. Saudi financial institutions face identical third-party exposure under SAMA CSCC.

18 Apr 2026 6 min
Phishing & Fraud

AI-Generated Phishing Is Now the #1 Email Threat of 2026 — A Tactical Response Guide for Saudi Financial CISOs

AI-generated phishing attacks have surged 1,265% since 2023 and now account for 82% of all phishing emails. For Saudi financial institutions under SAMA and NCA oversight, the stakes — and the compliance obligations — have never been higher.

16 Apr 2026 6 min
Phishing & Fraud

W3LL Phishing Marketplace Dismantled: How a $500 Kit Bypassed MFA at Scale — Lessons for Saudi Financial CISOs

FBI Atlanta and Indonesian National Police seized the W3LL phishing marketplace on April 10, 2026 — a platform that sold MFA-bypassing phishing kits for $500 and enabled over $20M in fraud across 17,000 victims. Here's what SAMA-regulated institutions must do now.

15 Apr 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality