news.mlab.sh
Back to the feed
phishing

ISC Stormcast For Wednesday, September 16th, 2026 https://isc.sans.edu/podcastdetail/10096, (Wed, Sep 16th)

Medium
Summary

The ISC Stormcast highlighted a significant increase in BEC (Business Email Compromise) attacks targeting the legal sector, driven by a sophisticated phishing campaign leveraging leaked LinkedIn data. Attackers are impersonating legal professionals to trick clients into transferring funds to fraudulent accounts. The campaign is particularly effective due to the detailed personalization of emails and the use of legitimate-looking branding.

The SANS Internet Storm Center’s latest Stormcast identified a concerning trend: a surge in Business Email Compromise (BEC) attacks specifically targeting the legal industry. The core of this increase stems from a campaign utilizing leaked LinkedIn data to craft highly convincing phishing emails. Attackers are impersonating legal professionals, sending emails that appear to be from legitimate firms, and requesting urgent wire transfers to shell accounts. The sophistication of these emails includes mimicking branding, using specific legal jargon, and referencing past communications to build trust with victims. The campaign is actively exploiting vulnerabilities in email security systems and the human tendency to trust familiar names and brands. The ISC noted that this campaign is not just a single event but a sustained effort with a growing number of reported incidents.

Read the full article at SANS Internet Storm Center