A crypto user lost $20,000 from their MetaMask wallet after being socially engineered by scammers posing as NPR's "The Indicator" podcast. The attackers gained credentials through a fake interview, compromised multiple accounts, and drained the wallet containing funds from a newly launched $JERRY token on Robinhood Chain.
North Korean hackers impersonated job applicants to infiltrate AI, crypto, and NFT companies, stealing credentials and data to extract over $11 million. The scheme exploited normal recruitment processes, making it difficult to detect compared to traditional phishing or wallet attacks.
Microsoft Defender Experts identified a sophisticated multi-stage AiTM phishing and BEC campaign targeting financial services organizations, originating from a compromised vendor and using an indirect proxy technique to steal session cookies and MFA credentials. The attackers exploited misconfigured MFA policies to update authentication methods without challenges, then launched a second-stage phishing campaign to 16,000+ contacts. The attack was conducted by Storm-1167 and demonstrates the evolving complexity of identity compromise threats requiring comprehensive remediation beyond standard password resets.