Skip to content

Sam's News — email-security — 2026-09-18

Security

7.5 Calendar-based phishing attacks surge 33,000% since May, bypassing spam filters

Calendar invitation phishing attacks have increased dramatically by 33,000% since May and remain effective even when emails reach spam folders.

Sources: TechRadar Web Search

6.5 Voice Phishing Campaigns Targeting Microsoft Teams Users

Security researchers document voice phishing tactics exploiting Microsoft Teams to compromise user credentials.

Sources: Unit 42 Web Search

6.5 Fake ChatGPT billing email targets work and home users

Phishing emails impersonating ChatGPT billing notifications are being used to target users at both work and personal email addresses.

Sources: IT Pro Web Search

6.5 Revolut customers targeted in phishing campaign following data breach

Fintech company Revolut customers are being targeted by phishing attacks after a data breach exposed their information.

Sources: Hackread RSS

6 T-Mobile Customers Targeted with Fake Rewards Expiry Phishing Texts

Cybercriminals are using fraudulent T-Mobile rewards expiration messages to direct users to phishing sites.

Sources: gbhackers.com RSS, CyberSecurityNews RSS Update to: T-Mobile Rewards Points Expiry Texts Used in Active Phishing Scam

Email Security

7 New credential theft phishing kit targets hundreds of organizations

Security researchers identified a newly discovered phishing toolkit actively targeting hundreds of organizations as of September 18, 2026. The toolkit is designed to steal credentials through phishing attacks across multiple sectors.

  • Target scope: hundreds of organizations, multiple sectors

Sources: KnowBe4 Blog Web Search

7 Business email compromise attacks: prevention and mitigation strategies

Business email compromise (BEC) is a targeted cybercrime using deceptive emails to trick employees into transferring funds or data. BEC bypasses standard IT filters through text-based, highly targeted impersonation—commonly of executives or vendors.

  • Attack type: text-based, highly targeted impersonation
  • Primary tactics: CEO/executive impersonation; vendor email compromise
  • Bypasses: standard IT security filters and malicious link/attachment defenses
  • Targets: businesses of all sizes; larger firms have complex accounts payable
  • Consequences: financial loss, data exposure, disruption, reputation damage

Sources: Chase for Business AI Web Searched, Chase Bank Web Search

7 Browser-based phishing attacks hide malicious content within victim browsers

Security researchers identify a phishing technique that hides malicious pages inside compromised browsers to evade detection.

Sources: Barracuda Networks Blog Web Search

7 Fake ChatGPT billing notification phishing campaign targets OpenAI users

Threat actors are conducting a phishing campaign impersonating ChatGPT and OpenAI billing notifications, directing users to fake Stripe pages to steal credit card details, CVCs, and billing information. The campaign targets both work and personal ChatGPT accounts.

  • Impersonation: ChatGPT Plus subscription payment-failed notifications
  • Fake domain: imi2001.co.jp (not OpenAI/ChatGPT)
  • Stolen data: email, card numbers, expiry, CVC, cardholder name, billing address
  • Fake hosting: argentina.alwaysdata.net and similar non-OpenAI domains
  • User misdirection: fake Stripe page simulates legitimate payment flow with error retry loop

Sources: MailGuard AI Web Searched, Hackread Web Search

Security analysis identifies key threat trends and attack patterns targeting email systems in the second quarter of 2026.

Sources: Microsoft Web Search