Boss too tough? Salary too low? If you're after a new gig, look no further 💼

We’re tracking a recruitment‑themed phishing campaign that opens with hope of a career upgrade and ends in stolen credentials.

Victims are targeted through emails spammed out by “recruiters” impersonating real people — LinkedIn profiles copied in full, including photos and current recruiter identities. The lure leans on exciting big‑name brands including FIFA, UEFA, Nike and Spotify to anchor legitimacy before prompting victims to schedule an interview using a bogus Calendly page 👔 💫

About time they noticed your stellar performance, right? But this interview comes with a catch 🎣 To seal the deal, you'll need to log in with your company email.

The mechanics:
• Initial outreach primes the role and rapport with some feel-good shmoozing
• Link to schedule your interview lands on a cloned Calendly recruitment portal
• Follow‑on contact nudges the victim through staged redirects
• Your credentials submit their 30-day notice ⚠️

Behind the scenes:
• Convincing lookalike domains generated at scale (RDGAs), rotated aggressively
• Layered redirect chains to blur origin and intent
• Compromised or fraudulently obtained Salesforce Marketing Cloud used for delivery, helping mails sail past controls
• Lure pages clone the Pinpoint ATS — attribution supported by Pinpoint’s own Cloudinary account ID (pinpointhq) embedded in assets
• Domain validation logic limits logins to business email providers, excluding free webmail services

Sad to say, the only thing getting “shortlisted” here is your inbox for another round of credential theft.

IOCs
• brand-jobs[.]com
• brand-careers[.]com
• hr-brand[.]com
• brand-talenthub[.]com

These campaigns remain active, with the actor spinning up new lures impersonating other major brands. We regret to inform you, it seems they'll be moving forward with other candidates 😩

Better luck next time.

#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing

MyPillow appears on Play ransomware leak site

Guess they could deny the alleged intrusion … like the 2020 election results

theregister
FBI easily nabs man selling sexy deepfakes who used his own photo in profile

A creepy saved post on Instagram linked man to AI porn account, FBI says.

Ars Technica

Parents demand ’emotional’ Starmer bans social media for kids before ‘more lives lost’

https://fed.brid.gy/r/https://metro.co.uk/2026/05/26/parents-demand-emotional-starmer-bans-social-media-kids-more-lives-lost-28524555/

Darknet Diaries Deutsch: Kids ohne Skrupel - Teil 2

Drew fängt an, Namen zu nennen und irrsinnige Methoden zu enthüllen, mit denen in Untergrund-Communities richtig viel Geld gemacht wird.

https://www.heise.de/news/Darknet-Diaries-Deutsch-Kids-ohne-Skrupel-Teil-2-11269283.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon

#Kriminalität #Cybercrime #Darknet #DarknetDiaries #IdentityManagement #Journal #news

Darknet Diaries Deutsch: Kids ohne Skrupel - Teil 2

Drew fängt an, Namen zu nennen und irrsinnige Methoden zu enthüllen, mit denen in Untergrund-Communities richtig viel Geld gemacht wird.

heise online
Netherlands seizes 800 servers of hosting firm enabling cyberattacks

Financial crime investigators in the Netherlands (FIOD) arrested two men and seized 800 servers linked to a web hosting company that enabled cyberattacks, interference operations, and disinformation campaigns.

BleepingComputer
Via #LLRX Pete Recommends Weekly highlights on cyber security issues, 5/23/26 - Five highlights from this week: #OpenAI Shared Your #Chats with #Meta & #Google, #Lawsuit Claims; #FBI Wants to Buy Nationwide Access to #LicensePlate Readers; #YouTube Opens AI Deepfake Detection Tool to All #Adult Users; Lawmakers warn #data #protection rules don’t protect key sites; and Google’s Spam Policies Now Apply to Attempts to Manipulate #AI. #cybercrime #privacy #cybersecurity https://www.llrx.com/2026/05/pete-recommends-weekly-highlights-on-cyber-security-issues-may-23-2026/
Former US execs plead guilty to aiding tech support scammers

Two former executives of a call-tracking and analytics company pleaded guilty to concealing a years-long tech support fraud scheme that victimized individuals worldwide.

BleepingComputer
7-Eleven data breach affects over 185,000 people's personal data | TechCrunch

The data breach included names, dates-of-birth, postal addresses, and Social Security numbers, according to a state government listing.

TechCrunch

Phishing Trends: February 2026 – April 2026

We observed decreases in overall phishing attacks reported, unique domain names reported for phishing, and phishing attacks hosted at free or cheap web site services. But not all good news. Other stories:

Weed Prevention Fails in .GARDEN

Small TLDs Under Siege

Spaceship Takes Off… But Not in a Good Way

Cloudflare Is King of a Reshuffled Top 20 Mountain

Ball of Confusion?

https://lnkd.in/e8bigV_P

#phishing #fraud #cybercrime #fakesites #cybersecurity

LinkedIn

This link will take you to a page that’s not on LinkedIn