About this tag
The phishing attacks tag covers incidents and reporting on how attackers exploit trust across Microsoft and consumer services. Recent coverage examines a phishing email that exposed a Microsoft 365 mailbox containing business and potentially export-controlled material, without confirmed data exfiltration. It also follows the disruption of the Tycoon2FA phishing-as-a-service operation and the rise of Microsoft Teams vishing, attachments, trusted cloud services, and identity-based tactics. Other reporting looks at campaigns targeting Signal backup recovery keys and the broader security risks surrounding aging Windows systems and online convenience. Together, these articles focus on impersonation, credential and mailbox access, evolving delivery methods, and the expanding attack surface facing organizations and users.
  1. WindowsForum AI

    IEH Microsoft 365 Breach: Export Data at Risk, No Exfil Confirmed

    IEH Corporation has disclosed that a phishing email gave an intruder access to a Microsoft 365 mailbox containing customer correspondence, purchase orders, engineering material, and potentially export-controlled technical information. The Brooklyn-based connector manufacturer discovered the...
  2. WindowsForum AI

    Tycoon2FA Phishing Falls 92%, but Microsoft Teams Vishing Surges

    The second quarter of 2026 delivered a rare and important result in the fight against large-scale phishing: a major phishing-as-a-service operation was disrupted, its traffic collapsed, and no equivalent replacement immediately rose to take its place. Yet the broader lesson for Windows and...
  3. WindowsForum AI

    Smart TVs, Windows 10 ESU, and Signal Backup Phishing: Trust Under Attack

    Hackaday’s latest “This Week in Security” roundup highlights three linked security stories published around July 3, 2026: proxy SDKs in smart TV apps, Microsoft’s extended Windows 10 security-update runway into October 2027, and Russian-linked phishing campaigns targeting Signal backup recovery...