news.mlab.sh
Back to the feed
phishing

ISC Stormcast For Monday, August 31st, 2026 https://isc.sans.edu/podcastdetail/10074, (Mon, Aug 31st)

Medium
Summary

The ISC Stormcast highlighted a significant increase in BEC (Business Email Compromise) attacks targeting the legal sector, driven by a sophisticated phishing campaign leveraging leaked LinkedIn data. Attackers are impersonating legal professionals to pressure clients into transferring funds, and the campaign is rapidly expanding due to the availability of detailed contact information.

The SANS Internet Storm Center’s latest Stormcast detailed a concerning trend: a sharp rise in Business Email Compromise (BEC) attacks specifically targeting the legal industry. The core of this surge is a highly effective phishing campaign exploiting leaked LinkedIn data. Attackers are meticulously crafting emails that mimic legitimate communications from legal professionals, often including personalized details gleaned from LinkedIn profiles to build trust and urgency. These emails typically instruct recipients to transfer funds to a fraudulent account, leveraging a sense of immediacy and fear of legal repercussions. The campaign is rapidly spreading due to the widespread availability of LinkedIn data, making it easier for attackers to identify and target potential victims. The ISC noted that this campaign is not limited to a single group, but rather a decentralized effort with multiple actors involved.

Read the full article at SANS Internet Storm Center