logo

HubSpot phishing targets 20,000 Microsoft Azure accounts

ID: 30468ecc-b078-5fc0-9bdc-90f3a3cc1285

STIX ID: report--30468ecc-b078-5fc0-9bdc-90f3a3cc1285

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-12-18

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

A widespread phishing campaign (June–Sept 2024) leveraged HubSpot Form Builder links and DocuSign-mimicking PDFs to redirect victims to credential-harvesting pages impersonating Microsoft Outlook/Azure; Unit 42 attributes about 20,000 compromised accounts across automotive, chemical, and industrial manufacturing firms in Europe, notes use of VPNs and password-reset attempts during takeovers, and identifies infrastructure artifacts ('.buzz' domains, a novel ASN, and unusual user-agent strings) useful for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.