Skip to content
Attackers Abuse LiveChat to Phish Credit Card, Personal Data

Attackers Abuse LiveChat to Phish Credit Card, Personal Data

Darkreading •Elizabeth Montalbano • March 16, 2026

A social engineering campaign impersonating PayPal and Amazon uses customer support interactions to acquire sensitive info.

Attackers have found yet another innovative way to conduct phishing attacks by abusing the customer support platform LiveChat, using real-time social engineering to steal a range of sensitive user data.

Researchers from Cofense's Phishing Defense Center (PDC) discovered a campaign that impersonates Amazon and PayPal to engage with victims via online chat, coercing them through what seems like a trusted, personal interaction to data such as account credentials, credit card details, multifactor authentication (MFA) codes, and other personally identifiable information (PII), according to a blog post published today.

The campaign demonstrates how attackers are constantly refining tactics to create phishing threats that "are no longer easy to spot," Cobi Aloia and Mark Deomampo of the Cofense PDC wrote in the blog post . Indeed, phishing is one of the oldest security threats to user endpoints but remains highly successful, due to the often simple yet psychologically effective tactics attackers have adopted.

In this case, the attacks leverage a number of diverse yet commonly used phishing tactics — including brand impersonation, social engineering, credential theft, and identity theft, among others — "that demonstrate the rapid evolution and integration of threats," the researchers wrote.

Cofense specifically identified two different attack vectors for the campaign, both of which use the psychologicial tactic of urgency, impersonation of trusted brands, and the abuse of LiveChat interactions to get customers to give up data. Both chat interactions use poor grammar and punctuation, which suggests that a human operator following a script was on the other end, rather than an automated bot or AI assistant, the researchers noted.

The first email uses a refund lure with a spoofed message from PayPal — a top brand impersonated by phishers — claiming the recipient will receive a $200 refund, prompting them to click a "View Transaction Details" button. Doing so redirects the user to a LiveChat-hosted page configured to resemble a legitimate PayPal customer support interaction, where a series of prompts in the conversation with the operator directs them to an external phishing site to "complete the refund process" by entering PayPal credentials.

Once this is done, the victim is then prompted to supply an MFA code sent to their phone, after which the attackers use the phishing site to get them to fill out additional forms collecting billing details, date of birth, and credit card information.

The second phishing email is not branded, offering a generic message stating that an order is pending and needs confirmation, which the user can do by clicking on the hyperlinked "View Update" text.

This link leads to a page that prompts them to enter an email address to start a chat, only after which a human operator impersonates an Amazon support agent and begins requesting additional persona details from the user. The "agent" then claims that a refund is available but is missing card details, asking the victim to provide a credit card number and its expiration date and CVC for "verification."

Though phishers have used various tricks throughout the years to get customers to give up data, the campaign is the first time on record that attackers have abused LiveChat in this way, the researchers said. The vector is not unlike an online version of vishing attacks , in which attackers use social engineering and psychological tactics in live conversations with people to get them to give up sensitive data and even let attackers remotely control their devices using tools such as AnyDesk .

That personal interaction, which disarms a victim and convinces them that they are in conversation with someone whom they can trust, is the secret to why these types of attacks work, the researchers noted. This "makes the phishing attempt feel like real-time customer service, reducing the victim's caution and increasing the chance of successful credential and data theft," they wrote in the report.

Mitigating these attacks requires not only software- or machine-based security but also human-driven analysis that combines "expert-level threat hunters, real-time intelligence, and user reports to identify and stop evolving attacks before they cause harm," according to the researchers. To help defenders identify the LiveChat-driven attacks, the blog post provides specific indicators of compromise (IoCs) for both malicious emails used in the campaign.

Elizabeth Montalbano is a freelance writer, journalist, and therapeutic writing mentor with more than 25 years of professional experience. Her areas of expertise include technology, business, and culture. Elizabeth previously lived and worked as a full-time journalist in Phoenix, San Francisco, and New York City; she currently resides in a village on the southwest coast of Portugal. In her free time, she enjoys surfing, hiking with her dogs, traveling, playing music, yoga, and cooking.

Frost Radar™: Non-human Identity Solutions

2026 CISO AI Risk Report

Cybersecurity Forecast 2026

The ROI of AI in Security

ThreatLabz 2025 Ransomware Report

Building a Robust SOC in a Post-AI World

Retail Security: Protecting Customer Data and Payment Systems

Rethinking SSE: When Unified SASE Delivers the Flexibility Enterprises Need

Securing Remote and Hybrid Work Forecast: Beyond the VPN

AI-Powered Threat Detection: Beyond Traditional Security Models

Extracted Entities

Attack Types (1)

Platforms (1)

Tools (1)