logo

Beware of the Latest Phishing Tactic Targeting Employees

ID: afb306fa-0d6c-509f-991c-0d149fc84489

STIX ID: report--afb306fa-0d6c-509f-991c-0d149fc84489

Feed Name: Cofense Blog

Threat Score
65/100

Date Published: 2024-07-15

Date Updated: 2026-04-27

Author: Cofense

...
...

This Cofense blog dissects a credential-harvesting phishing campaign that impersonates a company's HR department to trick employees into submitting Microsoft credentials on a fake login page; after capturing credentials the attack redirects victims to the legitimate SSO (e.g., Okta) to conceal the compromise. The report includes multiple IoCs (malicious URLs and IPs), details the social-engineering tactics and attack flow, and recommends security awareness training and layered email defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.