Blog.Malwarebytes
Phishing Emails Masquerading as Spam Alerts Target Email Credentials
First seen 2 Dec 2025, 18:33 UTC
•

•7.8
Export
Article Content
Browse articles
Phishing emails disguised as spam filter alerts are being used to steal user login credentials. These emails often contain a 'Secure Message' alert that prompts users to click, leading to potential credential theft. Organizations and their employees are primarily affected by this tactic.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Critical Appsmith Vulnerability Enables Account Takeovers
Google Chrome Zero-Day Vulnerability CVE-2025-13223 Exploited in the Wild
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
APT28 Exploits Zimbra Vulnerability in Ongoing Attacks Against Ukraine
GRU Compromises Home Routers in 23 States to Steal Outlook Credentials