social engineering

Apple Pay Phish Uses Fake Support Calls to Steal Payment Details

Apple Pay phishing campaign hijacks user information through fake support calls. Victims receive emails mimicking Apple alerts about unauthorized transactions, prompting them to call provided numbers. Scammers impersonate Apple agents, extracting sensitive data like Apple ID verification codes and payment details under false pretenses. Users are advised to avoid sharing 2FA codes, scrutinize sender addresses, and verify communications independently.

https://www.malwarebytes.com/blog/news/2026/02/apple-pay-phish-uses-fake-support-calls-to-steal-payment-details

Are Criminal Hacking Organizations Recruiting Teenagers to Do the Dirty Work?

Criminal hacking organizations are recruiting teenagers in Western countries by offering fake jobs and cryptocurrency payments. These groups use social media and gaming platforms to groom young individuals for illegal activities, including ransomware attacks. Parents should watch for signs of unusual income or expensive items and be aware that law enforcement, including the FBI, is actively prosecuting young offenders.

https://www.pandasecurity.com/en/mediacenter/are-criminal-hacking-organizations-recruiting-teenagers-to-do-the-dirty-work/

The Biggest Catch: How Whaling Attacks Target Top Executives

Whaling attacks target senior executives, exploiting their time constraints, online visibility, and access to sensitive information. Attackers often use phishing tactics, enabling them to execute large financial frauds. AI enhances these threats by facilitating data gathering and creating convincing communication. Mitigation strategies include personalized training, strong approval processes for fund transfers, and robust email security measures. Protecting against whaling not only safeguards financial assets but also corporate reputations.

https://www.welivesecurity.com/en/business-security/big-catch-how-whaling-attacks-target-top-executives/

Impersonation as a Service’ Next Big Thing in Cybercrime

Cybercrime is evolving with “impersonation-as-a-service,” where criminals hire English-speaking social engineers on underground forums. Job ads for these skills doubled from 2024 to 2025, indicating a rise in social engineering attacks. Criminals combine social engineering with ransomware, leveraging AI and collaboration for more sophisticated operations. Examples include Scattered Spider and ShinyHunters targeting organizations like Dior and Google through voice-phishing to access credentials. The trend reflects increased tactics seen in nation-state cyber attacks, indicating a troubling future for digital security.

https://www.theregister.com/2025/08/21/impersonation_as_a_service/

Social Engineering on the Rise — New Unit 42 Report

TLDR: Palo Alto Networks' 2025 Unit 42 report highlights a significant rise in social engineering attacks, with over a third of incidents starting from these tactics, primarily phishing (65%). Attackers exploit trust and human behavior rather than technical vulnerabilities, leading to business disruptions and data exposure. AI enhances these attacks, allowing for personalized lures and scalable strategies. Organizations are urged to address overpermissions, alert gaps, and strengthen identity security to mitigate risks.

https://www.paloaltonetworks.com/blog/2025/07/social-engineering-rise-new-unit-42-report/

Scroll to Top