Pink Hacking Group Targets Enterprises to Steal Cloud Passwords
ID: e54c00e9-fbe1-5ed8-ad14-1e55e67ea212
STIX ID: report--e54c00e9-fbe1-5ed8-ad14-1e55e67ea212
Feed Name: GBHackers
Pink is a newly observed extortion brand conducting targeted enterprise attacks that begin with vishing and helpdesk-style calls to prime victims, followed by tailored credential-phishing pages to capture passwords and bypass MFA (real-time prompts, push fatigue, OTP interception). After gaining access, operators search cloud storage and productivity suites for sensitive documents, exfiltrate proof files to a public leak site (live as of May 31, 2026) and demand payment; mitigations include phishing-resistant MFA, conditional access, session controls, permission audits, logging, and vishing awareness.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
