Techradar Credential Phishing Campaign Targets 7,800+ Organizations via Fake Voicemail Emails
Article Content
- •Over 7,800 organizations targeted in a phishing campaign using fake voicemail emails.
- •Malicious SVG attachments redirect users to credential-harvesting pages with auto-filled email addresses.
- •Attackers exploit familiarity with automated voicemail notifications to lower user skepticism.
A large-scale phishing campaign has targeted over 7,800 organizations by sending emails that impersonate automated voicemail transcript notifications. Between August 17 and August 31, Check Point identified more than 58,000 phishing emails leveraging over 38,400 spoofed sender addresses across 9,300 spoofed domains. The emails contain malicious SVG attachments that redirect users to credential-harvesting pages. The subject lines of these emails mimic familiar notifications, making them appear legitimate. The SVG files execute JavaScript to auto-fill the victim's email address on the phishing page, enhancing the attack's credibility. Organizations are urged to treat SVGs as active content and verify notifications before acting. This campaign highlights the limitations of traditional email security measures that rely on sender reputation and known malicious links.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…