Loading article…
Learn how attackers use sophisticated social engineering and legitimate service flows to conduct phishing campaigns, including recent large-scale incidents.
Phishing attacks have evolved beyond simple spam, with modern campaigns increasingly leveraging legitimate service processes to deceive users. In one notable instance, an open-source project was utilized by malicious actors to facilitate a phishing campaign that targeted 14,000 individuals [1].
Key takeaways
Modern phishing often relies on "theater" to convince victims of its legitimacy. In a documented case, attackers triggered legitimate password reset flows from a service provider to overwhelm a target with authentic, properly signed emails [1]. By contacting support services while impersonating the victim, scammers can generate real case IDs, which they then present on pixel-perfect replica websites to gain the user's confidence [1].
These sites often include fake chat transcripts or evidence of the "attack" to pressure the victim into clicking a sign-in button [1]. Because these interactions utilize the actual infrastructure of the service being spoofed, traditional email filters may fail to flag the messages as malicious [1]. Experts note that these campaigns are designed to be highly persuasive, often involving calm and knowledgeable individuals posing as support staff to guide the victim through the fraudulent process [1].
The shift toward using legitimate service flows makes it increasingly difficult for individuals to distinguish between genuine security alerts and sophisticated scams [1]. Because some phishing attempts will inevitably bypass standard filters, security organizations emphasize that relying solely on user education is insufficient [2]. Instead, a robust defense requires a multi-layered approach that includes technical mitigations, such as implementing DMARC to prevent domain spoofing [2]. By focusing on systemic technical defenses, organizations can better protect their users and prevent their own reputations from being associated with fraudulent activity [2].
Coverage is mostly measured — 133 of 135 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 2 outlets · Jun 1, 2026 · How we report
The perpetrators called victims, claimed their cryptocurrency was at risk, and instructed them to transfer funds to accounts that appeared to be police‑run, but were controlled by the scammers.
Approximately £1 million of the stolen crypto was recovered by police, a fraction of the total £4 million taken.
Reported incidents rose to 77 in the first half of 2026, compared with 45 for the entire previous year, indicating a significant increase.
They launched a prevention platform and rapid‑alert system for crypto holders and professionals, leading to around 200 arrests.
CertiK advises using multisignature or multiparty computation setups, withdrawal delays, spending limits, and geographically separated signers.