Tax Season Amplifies Spear Phishing Risks in Accounting Firms
Accounting firms face heightened spear-phishing exposure during filing season as attackers exploit routine client inquiries and tax-themed lures to...

Created by Oscar Lankford Jr
Technical research on spear‑phishing attacks and defenses for high‑value financial institutions
Explore the latest content tracked by Financial Spear Phishing Digest
Accounting firms face heightened spear-phishing exposure during filing season as attackers exploit routine client inquiries and tax-themed lures to...
A fraudster spoofed a Pune director's Microsoft Teams profile with matching name and photo, joined the internal group, and directed an employee to...
Russian groups UNC6293, UNC7005, and UNC5976 are abusing OAuth flows to steal tokens from high-value targets in government, academia, and...
A finance-targeted spear-phishing email with personalized PTO details delivered an AiTM page that bypassed MFA and captured a live Microsoft 365...
Microsoft 365 Copilot's undocumented ?autorun=1 parameter enabled silent prompt execution, bypassing consent requirements.
Microsoft 365 E5 provides a strong baseline but leaves repeatable gaps against payload-less BEC and internal account takeover that target high-value...
Lazarus operators used spear-phishing recruitment lures impersonating Enveil to deliver an encrypted archive containing a signed PDF viewer and...
This vendor payment diversion via AiTM phishing illustrates how 2026 email account takeover trends enable rapid MFA bypass and insider mailbox...
Lazarus Group's Operation Dream Job deploys fake job lures via LinkedIn and messaging to defense targets, delivering trojanized PDF viewers or...
A single compromised inbox allowed attackers to direct its Microsoft Copilot to hide alerts, map the org chart, and draft CEO-style phishing emails,...
Kimsuky now runs local LLMs via Ollama and GPT4All to generate finance-themed lures offline, avoiding cloud detection.
Three novel attacks defeat passkeys without breaking their cryptography:
Kimsuky has deployed Ollama, GPT4All, and Msty on C2 servers to run local LLMs with RAG and AI agent frameworks, enabling offline malware development...
UNC6671 actors impersonate coworkers or IT staff to phish passwords and MFA codes from large US financial firms via spoofed websites, followed by data-leak threats and ransom demands of $750K–$3M.
Scammers compromised a city assistant's email to internally "verify" fake contractor banking details, enabling a $913,839.81 ACH payment.
-...
Pittsburg's ACH payment to a spoofed vendor account exposed critical gaps in email security and payment verification.
Generative AI has collapsed spear phishing preparation from roughly 16 hours of manual OSINT work to under five minutes while lifting click-through...