news.mlab.sh
Back to the feed
threat-intel

ISC Stormcast For Wednesday, September 2nd, 2026 https://isc.sans.edu/podcastdetail/10078, (Wed, Sep 2nd)

Medium
Summary

The ISC Stormcast highlighted a significant increase in BEC (Business Email Compromise) attacks targeting the legal and accounting sectors, driven by a new technique leveraging compromised LinkedIn profiles to spearfish targets. Attackers are now using this information to craft highly personalized and convincing emails, resulting in substantial financial losses for victims. The podcast emphasized the need for enhanced vigilance and proactive security measures to combat this evolving threat landscape.

The SANS Internet Storm Center’s latest Stormcast addressed a concerning trend: a sharp rise in Business Email Compromise (BEC) attacks, specifically targeting the legal and accounting industries. The core of this increase stems from a novel tactic involving the exploitation of compromised LinkedIn profiles. Attackers are leveraging this stolen data – including email addresses, job titles, and company information – to craft extremely convincing and personalized BEC emails. These emails are designed to mimic internal communications and build trust with recipients, leading to successful financial transfers. The podcast noted that this method significantly reduces the time spent on reconnaissance, allowing attackers to quickly move to exploitation. The ISC stressed that this trend underscores the importance of robust employee training and multi-factor authentication to mitigate the risk of credential compromise and phishing attacks.

Read the full article at SANS Internet Storm Center