Phishing Campaign Exploits Fake Security Incident Report Targeting Crypto Users

Phishing Campaign Exploits Fake Security Incident Report Targeting Crypto Users

First seen 17 Feb 2026, 14:11 UTC Securityaffairs.CoRadar.OffseqGbhackersCybersecuritynewsCyberpress 24.3

Article Content

Browse articles
ThreatCluster

A phishing campaign has been identified that uses a fake PDF security incident report hosted on AWS to trick victims into enabling two-factor authentication (2FA). The campaign specifically targets Metamask users, a popular crypto wallet, and has been described as poorly crafted. Freelance security consultant Xavier Mertens reported the incident, highlighting the tactics used by the attackers.

Timeline

2026-02-17
Phishing campaign reported using fake PDF incident report
2026-02-17
Phishing email targets Metamask users