Topic
Phishing & Fraud
Phishing, social engineering and financial fraud — including how campaigns now get past MFA.
17 articles in this topic
EvilTokens PhaaS: Device Code Phishing Bypasses MFA to Hijack Microsoft 365 Accounts
EvilTokens PhaaS platform has compromised 340+ Microsoft 365 orgs by abusing OAuth device code flow to bypass MFA. Learn how Saudi financial institutions can defend against this active threat.
Cloud & IdentityTycoon2FA Rebounds: Device-Code Phishing Bypasses MFA to Hijack Microsoft 365 Accounts
The Tycoon2FA phishing-as-a-service kit has rebounded after a March takedown, now weaponizing OAuth device-code flows to steal Microsoft 365 tokens — rendering traditional MFA useless. Here's what Saudi CISOs need to know.
RansomwareVishing and SSO Abuse: How Cybercrime Groups Are Executing Rapid SaaS Extortion in Minutes
Cybercrime groups like ShinyHunters are combining AI-powered vishing calls with SSO exploitation to breach SaaS environments in under 45 minutes. Learn how Saudi financial institutions can defend against this rapidly evolving threat.
Breaches & Data LeaksCushman & Wakefield Vishing Breach: How One Phone Call Exposed 500K Salesforce Records
A single vishing call gave ShinyHunters access to 500,000 Salesforce records at Cushman & Wakefield. Two ransomware groups now claim the data. Here's what went wrong and why Saudi institutions must act now.
Phishing & FraudVENOMOUS#HELPER RMM Phishing Campaign: Risk to SAMA Banks
A new initial-access campaign is hijacking legitimate RMM tools — SimpleHelp and ScreenConnect — to slip past EDR and establish dual-channel persistence. Here is why CISOs at SAMA-regulated banks must act this week.
Phishing & FraudAiTM Phishing Campaign 2026: 35,000-Victim MFA Bypass Threatens SAMA Banks
Microsoft Defender Research uncovered a multi-stage AiTM phishing campaign that hit 35,000 users across 26 countries — financial services was 18% of victims. What SAMA-regulated banks must do today.
Phishing & FraudAccountDumpling: Google AppSheet Phishing Bypasses DMARC — A SAMA Email Risk
Attackers are weaponizing Google AppSheet's noreply@appsheet.com address to send phishing emails that pass SPF, DKIM and DMARC. The AccountDumpling campaign is a wake-up call for every SAMA-regulated bank that treats email authentication as a finished control.
Phishing & FraudThe Deepfake Threat Saudi Financial CISOs Can No Longer Ignore: AI Voice Cloning, CEO Fraud, and KYC Bypass in 2026
A darknet actor is selling real-time deepfake tools that defeat bank KYC in seconds. Across the GCC, fraudsters are impersonating CEOs with AI-cloned voices to authorize wire transfers. Saudi financial institutions need a response framework — now.
Cloud & IdentityEvilToken: The AI-Powered Phishing Kit That Defeats MFA and Targets Saudi Financial M365 Environments
A new phishing-as-a-service toolkit called EvilToken is bypassing MFA at scale using AI-generated lures and OAuth device code abuse, targeting M365 users across the UAE and beyond — a direct risk to Saudi financial institutions.
Supply Chain & Third PartyBooking.com's ClickFix Supply Chain Breach: The Third-Party Vendor Risk Every Saudi Financial CISO Must Address Now
Booking.com confirmed a breach exposing millions of customers' reservation data — attackers never touched Booking.com directly. They compromised hotel partners using ClickFix malware. Saudi financial institutions face identical third-party exposure under SAMA CSCC.
Phishing & FraudAI-Generated Phishing Is Now the #1 Email Threat of 2026 — A Tactical Response Guide for Saudi Financial CISOs
AI-generated phishing attacks have surged 1,265% since 2023 and now account for 82% of all phishing emails. For Saudi financial institutions under SAMA and NCA oversight, the stakes — and the compliance obligations — have never been higher.
Phishing & FraudW3LL Phishing Marketplace Dismantled: How a $500 Kit Bypassed MFA at Scale — Lessons for Saudi Financial CISOs
FBI Atlanta and Indonesian National Police seized the W3LL phishing marketplace on April 10, 2026 — a platform that sold MFA-bypassing phishing kits for $500 and enabled over $20M in fraud across 17,000 victims. Here's what SAMA-regulated institutions must do now.
From reading to doing
Your people are the first line of defence
Phishing simulation measures how your team responds to realistic attack emails and turns the results into targeted training.
Phishing Simulation
Controlled, realistic phishing campaigns that measure human risk for real — turning results into targeted training and a metric yo...
Security Awareness Training
Security awareness and training programs that transform your employees from the weakest link to an effective first line of defense
Executive and technical training
Tailored training for executives and technical teams that raises your security readiness at every level.