logo

LiveChat Abuse: How Phishers Are Exploiting SaaS Support Tools to Steal Sensitive Data

ID: 628829b3-34b1-5347-99d0-76da80110c7c

STIX ID: report--628829b3-34b1-5347-99d0-76da80110c7c

Feed Name: Cofense Blog

Threat Score
68/100

Date Published: 2026-03-16

Date Updated: 2026-04-27

Author: Cofense

...
...

Cofense PDC observed a live phishing campaign that abuses LiveChat (lc.chat / direct.lc.chat) to impersonate PayPal and Amazon customer service; attackers use real-time chat interactions to harvest credentials, card data, MFA codes, and PII, then redirect victims to external payload URLs. The report includes observed infection and payload URLs, associated IP addresses, examples of the social-engineering lures, and demonstrates how attackers can bypass MFA and drain financial accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.