Phishers Abuse LiveChat Support Tools to Steal Sensitive Data in New SaaS-Based Attack Tactic
ID: 57ebe0ef-752d-58f3-8569-7403bac6f673
STIX ID: report--57ebe0ef-752d-58f3-8569-7403bac6f673
Feed Name: cybersecurityNews.com
A phishing campaign is abusing LiveChat (lc.chat) to host convincing brand-impersonation chat sessions (PayPal, Amazon) that solicit email addresses, dates of birth, home addresses, full credit card data (number, expiration, CVC), and MFA codes through multi-stage social engineering lures (refunds/order confirmations). The technique leverages legitimate SaaS pages and live-chat interactions to increase trust and evade detection; defenders are advised to monitor and block lc.chat traffic and treat unsolicited refund/order communications with caution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
