logo

Credential phishing Charles Schwab account holders with 2FA bypass · Blog · Sublime Security

ID: 0ba575a9-0b3d-500b-a3dd-aa7204ec6d6e

STIX ID: report--0ba575a9-0b3d-500b-a3dd-aa7204ec6d6e

Feed Name: Sublime Security Blog

Threat Score
65/100

Date Published: 2026-01-08

Date Updated: 2026-05-01

...
...

Sublime's Attack Spotlight describes a credential-phishing campaign impersonating Charles Schwab where recipients are lured through a fake Cloudflare challenge to a convincing phishing login that captures credentials and prompts for a phone number to intercept 2FA codes; Sublime detected the attack via signals such as a suspicious ".jp" sender TLD, credential-theft language, and mismatched sender/link domains and prevented the campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.