Almost 8000 organizations hit by fake voicemail transcript emails in credential phishing attack
Check Point spotted phishing emails spoofing voicemail transcript notifications, hitting 7,800+ orgs Malicious SVG attachments auto‑fill victim emails, redirecting to fake login pages for credential theft SVG format bypasses filters; businesses urged to verify notifications and treat SVGs as active content Hackers have a new phishing lure - the automated voicemail transcript notification, and have already used it against thousands of organizations already, sending tens of thousands of malicious emails.
In a new report, security experts from Check Point Research (CPR) said they spotted an ongoing campaign that has already targeted thousands of organizations.
The goal of the campaign seems to be credential theft - grabbing access to people’s email accounts, business services, and similar.
Abusing the trends The proliferation of AI gave rise to a new trend in the office - automated voicemail transcripts.
When a person receives a voicemail, they can choose to read it instead of listening to it.
Useful for a noisy workplace environment, or for emails that are too sensitive to be blasted through a speaker system.
An automated system mails the transcript to the recipient’s inbox in a familiar format, and since they’re used to receiving this type of email, they’re not suspicious or skeptical enough.
Their guard is lowered, which is a perfect opportunity for the attackers.
“Between August 17 and August 31, Check Point identified more than 58,000 emails tied to the campaign.
The operation targeted over 7,800 organizations, leveraging more than 38,400 spoofed sender addresses across over 9,300 spoofed domains,” the researchers explained.
The emails follow a simple formula the recipients are already used to seeing.
Each message’s subject line begins with “Automated transcript”, followed by a partially redacted phone number and a random tracking string.
“The effect is deliberately understated: a notification that appears to have been generated by a trusted workplace system,” CPR explains.
The email domains are also spoofed in a way that makes it seem as if they’re coming from within the same organization.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.