Large-Scale Code of Conduct Phishing Campaign Targets 35,000 Users

Large-Scale Code of Conduct Phishing Campaign Targets 35,000 Users

First seen 5 May 2026, 11:32 UTC Blogs.MicrosoftGbhackersCybersecuritynews 77% similarity 71.0

Article Content

Browse articles
ThreatCluster

A sophisticated phishing campaign themed around code of conduct documents has compromised over 35,000 users from 13,000 organizations. The multi-stage attack occurred between April 14 and April 16, 2026, primarily affecting users in the United States. Attackers utilized social engineering tactics and legitimate email services to distribute fully authenticated messages from domains they controlled. Microsoft Defender Research reported that the campaign led to the compromise of authentication tokens through an Account Takeover (AiTM) method. The attack highlights the evolving nature of phishing threats and the need for enhanced security measures. Current status indicates ongoing investigations and heightened awareness among targeted organizations.

Key Points: • Over 35,000 users from 13,000 organizations were targeted in a phishing campaign. • The attack used code of conduct-themed lures and multi-step methods for credential theft. • Microsoft Defender identified the campaign as leading to AiTM token compromises.

ThreatCluster AI

Timeline

2026-04-14
Phishing campaign launched targeting users with code of conduct themes
2026-04-16
Campaign concluded with over 35,000 users affected
2026-05-04
Microsoft Defender Research published findings on the attack
2026-05-05
Gbhackers reported on the phishing campaign's impact

Community

Browse all →

Tracked Entities in This Story