New phishing scam on LinkedIn is using fake board offers to steal credentials

New phishing scam on LinkedIn is using fake board offers to steal credentials

A new phishing scheme is making waves on LinkedIn, specifically aiming to compromise the Microsoft credentials of finance professionals. Deviating from traditional phishing tactics, this sophisticated attack focuses on high-profile individuals, as revealed by cybersecurity firm Push Security. The campaign was recently uncovered when Push Security detected and thwarted a significant phishing attempt on LinkedIn. Victims are approached through direct messages from profiles that appear legitimate. The attackers extend invitations to join the executive board of a fictitious investment fund called "Commonwealth," claiming it is a partnership with AMCO, their asset management division. The fraudulent message entices recipients with an exclusive opportunity, proclaiming, "I'm excited to extend an exclusive invitation for you to join the Executive Board of the Commonwealth investment fund in South America, a bold new venture capital fund launching an Investment Fund in South America." This enticing offer lures targets into believing they are on the verge of a major career advancement. However, the real deception lies in the message's embedded link to a document that the victim is urged to review. Clicking this link initiates a series of redirects, first through Google Search, then to a site controlled by the attackers, and finally landing on a custom page hosted on firebasestorage.googleapis[.]com. Here, the victim is prompted to access the document using Microsoft. This step leads them to a meticulously crafted adversary-in-the-middle (AiTM) phishing page that resembles the official Microsoft login screen. If victims enter their credentials on this page, the attackers capture this sensitive information. Push Security notes that these attackers employ standard bot protection measures like CAPTCHA and Cloudflare Turnstile to evade detection by security bots, making it more challenging for users to identify the fraudulent pages. This evolution in phishing strategies signals a shift from email-based attacks to social media platforms, prompting organizations to remain vigilant against this new threat. The firm cautions that the implications of such attacks are significant, stating, "Just because the attack occurs on LinkedIn doesn't diminish its impact—these are corporate accounts being targeted, even if the application is ostensibly personal. Compromising essential identities like Microsoft or Google accounts can lead to widespread risks, affecting data integrity across both primary and ancillary applications accessed through single sign-on from the breached account."

Sources : Mint

Published On : Nov 03, 2025, 17:00

Startups
Quince Secures $500 Million Funding, Achieves $10 Billion Valuation Amid E-Commerce Growth

In a noteworthy development in the e-commerce landscape, Quince has successfully raised $500 million in a Series E fundi...

TechCrunch | Mar 11, 2026, 21:20
Quince Secures $500 Million Funding, Achieves $10 Billion Valuation Amid E-Commerce Growth
Gaming
Exciting Update: Xbox Mode Set to Transform Windows 11 PCs This April

Last summer, when Asus and Microsoft unveiled the ROG Xbox Ally X, it featured a unique, controller-friendly interface t...

Ars Technica | Mar 11, 2026, 21:00
Exciting Update: Xbox Mode Set to Transform Windows 11 PCs This April
Startups
Venture Capital Giants Set to Raise Billions Amid AI Boom

In a striking turn of events in the venture capital landscape, General Catalyst is reportedly in discussions to raise a ...

TechCrunch | Mar 11, 2026, 18:25
Venture Capital Giants Set to Raise Billions Amid AI Boom
Computing
Satellite Showdown: FCC Chair Takes Sides in SpaceX vs. Amazon Feud

In the competitive landscape of satellite communications, disputes over orbital territories and electromagnetic spectrum...

Ars Technica | Mar 11, 2026, 22:05
Satellite Showdown: FCC Chair Takes Sides in SpaceX vs. Amazon Feud
AI
Atlassian Makes Tough Choice: 1,600 Jobs Cut to Fuel AI Growth

Atlassian announced on Wednesday a significant restructuring plan that involves cutting 10% of its workforce, equating t...

CNBC | Mar 11, 2026, 21:55
Atlassian Makes Tough Choice: 1,600 Jobs Cut to Fuel AI Growth
View All News