logo

Phishing Campaigns Abuse AI Workflow Automation Platforms

ID: 56d60bad-3797-5119-a6c0-7da62d954f69

STIX ID: report--56d60bad-3797-5119-a6c0-7da62d954f69

Feed Name: KnowBe4 Blog

Threat Score
65/100

Date Published: 2026-04-22

Date Updated: 2026-04-28

Author: KnowBe4 Team

...
...

Researchers at Cisco Talos report that attackers are abusing the n8n AI workflow automation platform's URL-exposed webhooks to send phishing emails, deliver malware, and perform device fingerprinting; webhooks can mask payload origins and dynamically tailor content (for example by user-agent), making phishing links appear legitimate. Talos observed a substantial rise in emails containing n8n webhook URLs (approximately 686% increase from January 2025 to March 2026), indicating active and growing misuse of the platform for malicious campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.