Credential phishing Charles Schwab account holders with 2FA bypass · Blog · Sublime Security
ID: 0ba575a9-0b3d-500b-a3dd-aa7204ec6d6e
STIX ID: report--0ba575a9-0b3d-500b-a3dd-aa7204ec6d6e
Feed Name: Sublime Security Blog
Threat Score
Sublime's Attack Spotlight describes a credential-phishing campaign impersonating Charles Schwab where recipients are lured through a fake Cloudflare challenge to a convincing phishing login that captures credentials and prompts for a phone number to intercept 2FA codes; Sublime detected the attack via signals such as a suspicious ".jp" sender TLD, credential-theft language, and mismatched sender/link domains and prevented the campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
