Social Engineering & Phishing
Articles covering phishing campaigns, social engineering tactics, callback phishing, brand impersonation, and human-centric cybersecurity threats.
Levi Strauss Cyberattack: Why the coupang data breach lesson on social engineering still matters
In August 2026, Levi Strauss & Co. disclosed a cybersecurity incident where attackers used social engineering against three employees to access corporate systems. The breach, linked to UNC6671 voice phishing campaigns, highlights why the coupang data breach lesson on social engineering remains critical for 2026 security strategies.
Inside the Coupang Data Breach: How Device Code Phishing and Vishing Bypass Security Controls
An analysis of how device code phishing and vishing attacks bypass traditional security controls while leaving minimal forensic evidence, using the coupang data breach as a case study of modern social engineering tactics.
Brands Exploited to Lure Job Seekers in Wide-Scale Phishing Operation
A persistent phishing campaign is impersonating more than 30 major global brands, exploiting legitimate CRM and marketing cloud services to execute nested redirect chains and steal Google account credentials via a convincing browser-based authentication mimicry technique.
When Malware Wears a Halo: The New Era of Reputation Hijacking in Crypto Attacks
How attackers weaponize GitHub, YouTube, and VirusTotal to build false trust for crypto clipboard hijackers — and what defenders can do about it.
Bluekit’s Browser-in-the-Middle Phishing Is Now a Living, Breathing Threat
Bluekit’s phishing-as-a-service platform has evolved from simple credential harvesting to a dynamic, adaptive browser-in-the-middle attack that bypasses detection by mimicking real user behavior — and it’s getting smarter every week.
Kali365 Operators Didn’t Just Survive the FBI—They Grew Stronger
Despite FBI warnings and takedown attempts, the operators of Kali365 have expanded their phishing-as-a-service platform, refining their MFA bypass techniques and scaling operations globally.
Shopify Shop App Exploited to Push Callback Phishing Attacks
Threat actors are abusing the popular Shop order-tracking app by inserting fake purchase receipts, tricking users into calling fraudulent support lines to steal sensitive data and credentials.