news.mlab.sh
Back to the feed
threat-intel

ISC Stormcast For Thursday, July 16th, 2026 https://isc.sans.edu/podcastdetail/10010, (Thu, Jul 16th)

Medium
Summary

The ISC Stormcast highlighted a significant increase in BEC (Business Email Compromise) attacks targeting the legal sector, driven by a sophisticated phishing campaign leveraging leaked LinkedIn data. Attackers are impersonating legal professionals to pressure clients into transferring funds, and the campaign is rapidly expanding due to the availability of detailed contact information.

The SANS Internet Storm Center’s latest Stormcast identified a concerning trend: a surge in Business Email Compromise (BEC) attacks specifically targeting the legal industry. The core of this escalation stems from a leak of LinkedIn data, providing attackers with highly detailed contact information – names, email addresses, phone numbers, and even internal email addresses – of legal professionals and their clients. Attackers are now using this information to craft extremely convincing phishing emails that mimic legitimate communications from law firms and legal departments. These emails typically pressure recipients to transfer funds to fraudulent accounts, often under false pretenses of urgent legal matters or settlements. The campaign is spreading quickly due to the sheer volume of readily available data, making it difficult for victims to discern genuine communications from malicious actors. The ISC urges vigilance and proactive security measures within the legal sector to mitigate the risk.

Read the full article at SANS Internet Storm Center