logo

Figma abuse from compromised vendor used in credential theft attack · Blog · Sublime Security

ID: 57efc028-e578-544d-8c06-6814b3d59a51

STIX ID: report--57efc028-e578-544d-8c06-6814b3d59a51

Feed Name: Sublime Security Blog

Threat Score
55/100

Date Published: 2025-10-22

Date Updated: 2026-05-01

...
...

Sublime Security's Attack Spotlight describes a credential-phishing campaign that used a compromised vendor email and a Figma-hosted link to deliver a fake OneDrive/ RFQ flow, ultimately redirecting victims to a credential-harvesting Microsoft login page (csoaitv.org). The report details the multistage LOTS technique, detection signals observed by Sublime's AI, and guidance on adaptive email security to mitigate these attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.