Manufacturing Sector Under Fire From Microsoft Credential Thieves
ID: 4e5b356c-78e2-59f1-8ba8-e562b1bfd4e3
STIX ID: report--4e5b356c-78e2-59f1-8ba8-e562b1bfd4e3
Feed Name: Dark Reading
BlueVoyant researchers identified a credential-harvesting spear-phishing campaign targeting the manufacturing sector (at least 15 victims, March–August) that uses emails impersonating legitimate suppliers and a file named "Product List RFQ, NDA & Purchase Terms 2024.shtml" to redirect victims to a spoofed Microsoft login page pre-filled with their username to capture passwords; victims are primarily in the US and Canada. Recommendations include monitoring for fake/typosquatted domains, employee phishing awareness, and enforcing conditional access and strong authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
