Phishing Attack Using Fake Purchase Order Attachment Targets Login Credentials

Phishing Attack Using Fake Purchase Order Attachment Targets Login Credentials

First seen 2 Mar 2026, 11:09 UTC MalwarebytesCybernews 26.3

Article Content

Browse articles
ThreatCluster

A phishing attack has been identified involving a fake purchase order attachment that is not a PDF but a phishing page aimed at capturing user login details. Users are advised to utilize up-to-date anti-malware solutions to protect against such scams. The attack specifically targets individuals who may be expecting purchase order communications.

Timeline

2026-03-02
Malwarebytes reports phishing email with fake purchase order
2026-03-02
Securityboulevard confirms phishing page designed to harvest credentials