logo

An AI-powered phishing campaign has compromised hundreds of organizations

ID: 89a160fc-42c7-58b6-8293-0ab08c4d1df1

STIX ID: report--89a160fc-42c7-58b6-8293-0ab08c4d1df1

Feed Name: CyberScoop

Threat Score
75/100

Date Published: 2026-03-23

Date Updated: 2026-04-21

Author: djohnson

...
...

Huntress researchers attribute a large-scale phishing campaign to abuse of Railway's cloud hosting and AI-generated bespoke lures to harvest credentials and obtain long-lived Microsoft OAuth tokens for devices, compromising hundreds of organizations across multiple sectors (344 victims detailed) and potentially thousands more; Railway blocked identified accounts and Huntress applied conditional access mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.