Almost 8000 organizations hit by fake voicemail transcript emails in credential phishing attack
That voicemail notification in your inbox could be a phishing lure being sent by a cybercriminal.
A recent phishing campaign, identified by Check Point Research, has targeted over 7,800 organizations with fraudulent voicemail transcript emails. The malicious SVG attachments, which bypass email filters, redirect victims to fake login pages, enabling credential theft. The attackers exploit the trust associated with automated voicemail transcripts, taking advantage of the fact that recipients are more likely to open such messages without suspicion.
Between August 17 and August 31, the campaign sent more than 58,000 emails, using more than 38,400 spoofed sender addresses across over 9,300 domains. To combat this threat, businesses should verify automated notifications, restrict file types and domains for AI agents, and treat SVG attachments as active content that requires inspection.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.