Skip to content
Large-Scale Code of Conduct Phishing Campaign Targets 35,000 Users

Large-Scale Code of Conduct Phishing Campaign Targets 35,000 Users

First seen 5 May 2026, 11:32 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 6, 2026 at 09:27 UTC
  • Over 35,000 users from 13,000 organizations were targeted in a phishing campaign.
  • The attack used code of conduct-themed lures and multi-step methods for credential theft.
  • Microsoft Defender identified the campaign as leading to AiTM token compromises.

A sophisticated phishing campaign themed around code of conduct documents has compromised over 35,000 users from 13,000 organizations. The multi-stage attack occurred between April 14 and April 16, 2026, primarily affecting users in the United States. Attackers utilized social engineering tactics and legitimate email services to distribute fully authenticated messages from domains they controlled. Microsoft Defender Research reported that the campaign led to the compromise of authentication tokens through an Account Takeover (AiTM) method. The attack highlights the evolving nature of phishing threats and the need for enhanced security measures. Current status indicates ongoing investigations and heightened awareness among targeted organizations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 137d ago How this analysis works

Timeline

2026-04-14
Phishing campaign launched targeting users with code of conduct themes
2026-04-16
Campaign concluded with over 35,000 users affected
2026-05-04
Microsoft Defender Research published findings on the attack
2026-05-05
Gbhackers reported on the phishing campaign's impact

More articles in this cluster (3)