Major Cyber Attacks in September 2026: US Organizations Face Session Theft, Remote Access, and Payment Fraud
September campaigns CSuite, N0va, and IronToll phished US organizations for Microsoft 365 sessions, tokens, and payment data.
ANY.RUN's September 2026 roundup describes phishing operations against US and European organizations. CSuite combined Microsoft 365 session theft with remote-management tools including ScreenConnect, Action1, Atera, Syncro, and PDQ Connect; 51% of 351 linked sandbox submissions came from the United States. N0va used device-code phishing to steal Microsoft 365 access and refresh tokens through legitimate authentication flows. IronToll, tied to 114 domains across more than 12 countries, used cloned payment pages and a live operator panel to steal card data and one-time passwords.