Topic
Phishing & Fraud
Phishing, social engineering and financial fraud — including how campaigns now get past MFA.
17 articles in this topic
EvilTokens PhaaS: Device Code Phishing Bypasses MFA to Hijack Microsoft 365 Accounts
EvilTokens PhaaS platform has compromised 340+ Microsoft 365 orgs by abusing OAuth device code flow to bypass MFA. Learn how Saudi financial institutions can defend against this active threat.
Cloud & IdentityTycoon2FA Rebounds: Device-Code Phishing Bypasses MFA to Hijack Microsoft 365 Accounts
The Tycoon2FA phishing-as-a-service kit has rebounded after a March takedown, now weaponizing OAuth device-code flows to steal Microsoft 365 tokens — rendering traditional MFA useless. Here's what Saudi CISOs need to know.
RansomwareVishing and SSO Abuse: How Cybercrime Groups Are Executing Rapid SaaS Extortion in Minutes
Cybercrime groups like ShinyHunters are combining AI-powered vishing calls with SSO exploitation to breach SaaS environments in under 45 minutes. Learn how Saudi financial institutions can defend against this rapidly evolving threat.
Breaches & Data LeaksCushman & Wakefield Vishing Breach: How One Phone Call Exposed 500K Salesforce Records
A single vishing call gave ShinyHunters access to 500,000 Salesforce records at Cushman & Wakefield. Two ransomware groups now claim the data. Here's what went wrong and why Saudi institutions must act now.
Phishing & FraudVENOMOUS#HELPER RMM Phishing Campaign: Risk to SAMA Banks
A new initial-access campaign is hijacking legitimate RMM tools — SimpleHelp and ScreenConnect — to slip past EDR and establish dual-channel persistence. Here is why CISOs at SAMA-regulated banks must act this week.
Phishing & FraudAiTM Phishing Campaign 2026: 35,000-Victim MFA Bypass Threatens SAMA Banks
Microsoft Defender Research uncovered a multi-stage AiTM phishing campaign that hit 35,000 users across 26 countries — financial services was 18% of victims. What SAMA-regulated banks must do today.
Phishing & FraudAccountDumpling: Google AppSheet Phishing Bypasses DMARC — A SAMA Email Risk
Attackers are weaponizing Google AppSheet's noreply@appsheet.com address to send phishing emails that pass SPF, DKIM and DMARC. The AccountDumpling campaign is a wake-up call for every SAMA-regulated bank that treats email authentication as a finished control.
Phishing & FraudThe Deepfake Threat Saudi Financial CISOs Can No Longer Ignore: AI Voice Cloning, CEO Fraud, and KYC Bypass in 2026
A darknet actor is selling real-time deepfake tools that defeat bank KYC in seconds. Across the GCC, fraudsters are impersonating CEOs with AI-cloned voices to authorize wire transfers. Saudi financial institutions need a response framework — now.
Cloud & IdentityEvilToken: The AI-Powered Phishing Kit That Defeats MFA and Targets Saudi Financial M365 Environments
A new phishing-as-a-service toolkit called EvilToken is bypassing MFA at scale using AI-generated lures and OAuth device code abuse, targeting M365 users across the UAE and beyond — a direct risk to Saudi financial institutions.
Supply Chain & Third PartyBooking.com's ClickFix Supply Chain Breach: The Third-Party Vendor Risk Every Saudi Financial CISO Must Address Now
Booking.com confirmed a breach exposing millions of customers' reservation data — attackers never touched Booking.com directly. They compromised hotel partners using ClickFix malware. Saudi financial institutions face identical third-party exposure under SAMA CSCC.
Phishing & FraudAI-Generated Phishing Is Now the #1 Email Threat of 2026 — A Tactical Response Guide for Saudi Financial CISOs
AI-generated phishing attacks have surged 1,265% since 2023 and now account for 82% of all phishing emails. For Saudi financial institutions under SAMA and NCA oversight, the stakes — and the compliance obligations — have never been higher.
Phishing & FraudW3LL Phishing Marketplace Dismantled: How a $500 Kit Bypassed MFA at Scale — Lessons for Saudi Financial CISOs
FBI Atlanta and Indonesian National Police seized the W3LL phishing marketplace on April 10, 2026 — a platform that sold MFA-bypassing phishing kits for $500 and enabled over $20M in fraud across 17,000 victims. Here's what SAMA-regulated institutions must do now.