{
  "id": 2318083,
  "title": "Russian snoops add OAuth abuse to targeted phishing campaigns",
  "url": "https://urgent.news/2026/08/21/russian-snoops-add-oauth-abuse-to-targeted-phishing-campaigns-2318083",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-21T00:19:25.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/security/2026/08/21/russian-snoops-add-oauth-abuse-to-targeted-phishing-campaigns/5290706"
  },
  "original_language": "en",
  "account": "Google is monitoring three suspected Russian cyber-spy groups targeting academics, aerospace professionals, defense personnel, government agencies, and think tanks in Europe and the US. These groups, known as UNC, have been conducting targeted campaigns since last year and continue to do so. Each campaign has fewer than 100 targets and under 10 victims. Despite the small numbers, the Russian cyber-spy groups have adapted their tactics by abusing OAuth authentication flows, making the social engineering attempts appear more legitimate and allowing them to compromise personal accounts across multiple platforms. Two of the groups, UNC6293 and UNC7005, have been specifically identified as posing as US State Department employees and targeting academia, aerospace, defense, government agencies, and think tanks. UNC6293 has been linked to the 2020 SolarWinds hack and is believed to be connected to Russia's Foreign Intelligence Service (SVR). UNC7005, on the other hand, is less sophisticated but shares similarities with UNC6293. Google urges targets to be cautious of phishing attempts, especially those that appear to come from government entities, and advises not to trust any unsolicited communications blindly.",
  "summary": "Don't click on that State Department meeting invite",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register Science",
        "title": "Russian snoops add OAuth abuse to targeted phishing campaigns",
        "url": "https://urgent.news/2026/08/21/russian-snoops-add-oauth-abuse-to-targeted-phishing-campaigns",
        "published": "2026-08-21T00:19:25.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}