ZeroHour

Search: “credentials”

3 stories in the last 24h

A fake ChatGPT billing email is after your OpenAI password

Cofense reports a fake ChatGPT billing email harvesting OpenAI credentials via a Google redirect to a spoofed login page.

Cofense's Phishing Defense Center traced a fake ChatGPT billing email, sent from support@9527db6e1a[.]nxcli[.]io, claiming a $23.80 overdue balance and a 48-hour deadline before account suspension. The 'Update Payment Information' button routes through a notifications[.]googleapis[.]com redirect to a spoofed OpenAI login page that captures credentials and sends victims to an error page. Cofense published indicators including the Google redirect link plus login.php and key.php paths on the nxcli[.]io host.

Help Net Security · 1h agoPhishing & fraud in the wild

T-Mobile rewards points expiry texts are a phishing scam

Malwarebytes tracks an SMS phishing campaign, active since May 2026, impersonating T-Mobile rewards expiry with 1,000+ templates and 81 rotating domains to lure victims.

Malwarebytes Labs has monitored a large smishing campaign since early May 2026 that falsely claims recipients' T-Mobile Rewards points are expiring, using invented balances like 18,400 points and imminent deadlines to create urgency. Researchers identified more than 1,000 semantically similar message templates (199 scoring at least 0.95 similarity) that vary only in salutation, headline, expiry date, and point balance. The links resolve to rotating domains such as t-mobile.biktpw[.]top, with at least 81 short-lived domains observed over four months, pushing victims to fake redemption pages where they may enter credentials or payment details. Activity peaked in two large spikes and has since declined, though messages are still circulating.

Malwarebytes Labs · 3h agoPhishing & fraud in the wild

GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds

eSentire identified GhostCode, a phishing kit abusing Microsoft 365 OAuth device-code sign-in to steal tokens and take over accounts in seconds.

eSentire analysts identified GhostCode in late August, a phishing kit that uses business contact-form messages and an NDA pretext to deliver a password-protected HTML attachment leading victims to a Microsoft device-code sign-in. Victims authenticate on legitimate Microsoft pages, letting the kit obtain a Primary Refresh Token in 32 seconds and register three devices in 78 seconds, with residential proxies matching the victim's location. The kit hides its redirect with encrypted addresses, junk data, and scanner-filtering challenges, and uses GHOSTnet-linked infrastructure during device enrolment. eSentire recommends blocking device-code authentication via Conditional Access, invalidating tokens, and reviewing newly enrolled devices.

Cyber Security News · 23h agoPhishing & fraud in the wild 2 sources5