Business Email Compromise stories
Barracuda spots 7 million device code phishing attacks
Last week
#
firewalls
#
mfa
#
cloud security
Barracuda links surge in device code phishing attacks to EvilTokens kit as criminals exploit Microsoft 365 logins and bypass multifactor checks.
VIPRE report says attackers shift to trusted services
Last week
#
endpoint protection
#
cloud security
#
phishing
VIPRE says cyber criminals are increasingly abusing trusted services like Cloudflare, Microsoft and TestFlight to dodge email security filters.
One-third of FIFA World Cup partners lack email protection
Last week
#
gaming
#
data protection
#
mfa
Proofpoint warns that 36% of FIFA World Cup 2026 commercial partners still lack the strongest DMARC settings, leaving fans exposed to spoofed emails.
Ecommpay report says eCommerce fraud needs overhaul
This month
#
fintech
#
phishing
#
martech
Ecommpay urges eCommerce overhaul as fraud report says current controls miss social engineering, distort competition and leave merchants exposed.
Former Black Basta affiliates target executives in Teams
This month
#
uc
#
mfa
#
phishing
ReliaQuest says suspected former Black Basta operators are bombarding staff with emails and posing as IT support in Microsoft Teams to reach senior executives.
Bitdefender launches GravityZone email security for MSPs
This month
#
ransomware
#
endpoint protection
#
hybrid cloud
Bitdefender adds integrated email defence to GravityZone, giving MSPs and businesses post-delivery protection against phishing, ransomware and BEC.
Proofpoint flags mailbox rule abuse in Microsoft 365
This month
#
edutech
#
mfa
#
cloud security
Proofpoint says mailbox rule abuse is becoming a routine Microsoft 365 takeover tactic, helping attackers hide alerts, hijack threads and drive fraud.
Trustifi adds AI video training for MSP phishing drills
This month
#
data protection
#
ransomware
#
mfa
Trustifi rolls out AI-powered training videos for managed service providers, turning real phishing emails into branded simulations inside one dashboard.
Cyber teams unready for major attack, Sygnia finds
This month
#
ransomware
#
digital transformation
#
public cloud
Most companies lack confidence in cyber defences as a Sygnia survey finds major gaps in visibility, coordination and board-level readiness.
Doppel wins ISO trifecta for AI, security & privacy
This month
#
firewalls
#
data protection
#
network security
Doppel secures three ISO certifications for AI governance, security and privacy, as enterprise buyers demand stronger assurance against AI-driven cyber threats.
iProov report warns of soaring iOS injection attacks
This month
#
uc
#
data protection
#
devops
iProov warns iOS injection attacks surged 1,151% in late 2025 as generative AI fuels deepfake impersonation and identity fraud.
Microsoft 365 EvilToken campaign hits hundreds daily
This month
#
mfa
#
cloud security
#
phishing
Microsoft warns that 10 to 15 EvilToken phishing runs are launched daily, compromising hundreds of organisations through OAuth token abuse.
Orange Business adds deepfake detection to services
This month
#
uc
#
cx
#
phishing
Orange Business to weave Reality Defender's deepfake checks into enterprise communications for 7,000 customers amid rising fraud fears.
Barracuda overhauls BarracudaONE & partner programme
Last month
#
firewalls
#
data protection
#
network security
Barracuda adds Google Workspace email protection, SecureEdge Access and AI security to BarracudaONE while unifying its global partner programme.
Proofpoint unifies email & AI data security platform
Last month
#
data protection
#
hybrid cloud
#
digital transformation
Proofpoint unveils unified platform to secure email and govern AI data access, extending visibility across cloud and on-premises environments.
HPE Threat Labs spot industrialised cybercrime surge
Last month
#
malware
#
firewalls
#
vpns
HPE Threat Labs warns cybercrime now runs like big business, as AI-fuelled, industrial-scale attacks hammer government and finance.
Kroll warns of widening gap in global cyber resilience
Last month
#
dr
#
devops
#
digital transformation
Kroll warns boards are overestimating cyber resilience as attacks cost firms an average USD $2.2 million a year and response plans lag reality.
Netcraft tool targets malicious domains before attacks
Last month
#
phishing
#
advanced persistent threat protection
#
email security
Netcraft unveils Preemptive Domain Disruption to knock out attacker domains in their dormant phase before phishing and BEC scams launch.
Abnormal AI rolls out Attune 1.0 to fight AI cyberattacks
Last month
#
uc
#
phishing
#
advanced persistent threat protection
Abnormal AI launches Attune 1.0, a behavioural model that spots AI-crafted cyberattacks by learning normal workplace communication patterns.
VIPRE email security integrates with Microsoft Defender
Last month
#
cloud security
#
phishing
#
advanced persistent threat protection
VIPRE links its Integrated Email Security with Microsoft Defender, unifying phishing and BEC detections in a single Defender console view.