news.mlab.sh
Back to the feed
threat-intel

ISC Stormcast For Friday, September 4th, 2026 https://isc.sans.edu/podcastdetail/10082, (Fri, Sep 4th)

Medium
Summary

The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions and a concerning trend of sophisticated BEC (Business Email Compromise) attacks leveraging leaked credentials. The podcast emphasized the need for enhanced vigilance and proactive security measures to combat these evolving threats, particularly focusing on employee training and robust identity verification processes.

The SANS Internet Storm Center’s latest Stormcast discussed a notable uptick in malicious email campaigns specifically targeting the financial sector. The core focus was on a surge in Business Email Compromise (BEC) attacks, where attackers impersonate executives to trick employees into transferring funds or divulging sensitive information. The podcast indicated that a substantial number of leaked credentials, obtained through various data breaches, were being actively utilized in these BEC schemes. Attackers are now leveraging these stolen credentials to craft highly convincing emails that closely mimic legitimate communications, making it increasingly difficult for employees to discern the difference. The ISC noted that many of these attacks are targeting smaller, less-resourced financial institutions, which may lack the resources to implement comprehensive security controls. The podcast stressed the importance of ongoing employee training to recognize and report suspicious emails, alongside strengthening identity verification processes to prevent unauthorized access to accounts.

Read the full article at SANS Internet Storm Center