news.mlab.sh
Back to the feed
threat-intel

ISC Stormcast For Thursday, July 23rd, 2026 https://isc.sans.edu/podcastdetail/10020, (Thu, Jul 23rd)

High
Summary

The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions with sophisticated spear-phishing attacks. The campaigns leveraged stolen credentials and a new, highly convincing lure involving a fake invoice to gain access to sensitive data and systems. The threat landscape remains volatile, with a notable uptick in activity from state-sponsored actors.

The SANS Internet Storm Center’s latest Stormcast detailed a concerning trend of increasingly targeted and successful phishing attacks against financial institutions. The core of the issue revolves around a new wave of spear-phishing campaigns utilizing stolen credentials to bypass traditional security measures. Attackers are now crafting highly personalized emails resembling legitimate invoices, designed to trick employees into clicking malicious links and providing access to internal systems. These emails are exceptionally well-crafted, incorporating branding and language mimicking real invoices, making them difficult to distinguish from legitimate communications. The ISC noted a substantial increase in the use of stolen credentials obtained through previous breaches to gain initial access, followed by a methodical campaign to escalate privileges and move laterally within targeted organizations. The ISC emphasized that this trend underscores the ongoing sophistication of threat actors, particularly state-sponsored groups, who are actively seeking to exploit vulnerabilities within financial institutions.

Read the full article at SANS Internet Storm Center