Enterprise Cyber Alert

AI-enhanced vishing and OAuth-based identity compromise

AI-enhanced vishing and OAuth-based identity compromise

UNC6671's campaign has targeted major hedge funds and expanded to Levi Strauss, while Apollo confirmed a July breach exposing SSNs and involving ransom demands up to $3 million. LHC Group reporting adds a healthcare voice-phishing case involving clinical, insurance, government-ID and limited financial data. Russian actors continue bypassing MFA through OAuth and WhatsApp device pairing, making phishing-resistant authentication, strong identity governance and rapid token revocation urgent.

Sources (2)
Updated Sep 5, 2026