15.1 C
Delhi
Thursday, November 6, 2025

LinkedIn Phishing Scam Targets Executives with Fake Board Offers

Key Takeaways

  • Finance executives are being targeted by sophisticated LinkedIn phishing scams
  • Attackers use fake board membership offers to steal Microsoft credentials
  • The scam bypasses traditional email filters using social media platforms
  • Security firm Push Security has detected and blocked these high-risk attacks

A sophisticated new phishing campaign is targeting LinkedIn users, specifically aiming to steal Microsoft login credentials from finance leaders and executives. Unlike traditional email-based attacks, this method uses direct messaging on the professional network to appear more legitimate.

How the LinkedIn Phishing Scam Works

The attack begins with a direct message from what appears to be a legitimate LinkedIn profile. The message contains an exclusive invitation for executives to join the executive board of a newly created “Commonwealth” investment fund in South America.

“I’m excited to extend an exclusive invitation for you to join the Executive Board of the Commonwealth investment fund in South America in partnership with AMCO – Our Asset Management branch, a bold new venture capital fund launching an Investment Fund in South America,” the fake message reads

The prestigious-sounding offer tempts targets with what appears to be a career milestone. However, the real scam begins when victims click on a document link included in the message to review the board position details.

Multi-Stage Credential Theft Process

Clicking the link initiates a complex redirect process through Google Search, then to an attacker-controlled site, and finally to a custom landing page hosted on firebasestorage.googleapis[.]com. When victims attempt to view the document using Microsoft, they’re redirected to a custom-designed adversary-in-the-middle (AiTM) phishing page that perfectly mimics the official Microsoft login screen.

Entering credentials on this fake page results in immediate theft of corporate login information, putting both personal and organizational data at significant risk.

Security Firm Sounds Alarm

Push Security uncovered this campaign and has successfully blocked several high-risk LinkedIn phishing attacks. The security company noted that attackers are employing advanced protection measures to avoid detection.

“Attackers are using common bot protection technologies like CAPTCHA and Cloudflare Turnstile to prevent security bots from accessing their web pages to be able to analyse them (and therefore block pages from being automatically flagged),” Push Security said in a blogpost.

The firm emphasized that phishing campaigns are increasingly shifting from email to social media platforms, requiring organizations to adapt their security awareness and protection strategies accordingly.

“Just because the attack happens over LinkedIn doesn’t lessen the impact — these are corporate credentials and accounts being targeted, even if it is nominally a “personal” application. Taking over a core identity like a Microsoft or Google account can have wide-ranging consequences, putting data at risk in both core apps and any downstream apps that can be accessed via SSO from the compromised account.” Push Security warned.

Organizations should and implement additional verification processes for sensitive credential requests originating from social media platforms.

Latest

Maharashtra Becomes First Indian State to Partner With Starlink

Maharashtra partners with Elon Musk's Starlink to bring satellite internet to remote areas, bridging digital divide and boosting connectivity.

Microsoft to Process AI Queries in Indian Data Centres by 2025

Microsoft will enable Indian customers to process AI queries locally by end-2025, addressing data residency needs for government and regulated sectors with in-country data processing.

Google Maps Adds Gemini AI for Hands-Free Navigation & Landmarks

Drive smarter with Google Maps' new Gemini AI features: hands-free navigation, real-world landmark directions, and proactive traffic alerts for easier commuting.

Louvre Museum Used ‘LOUVRE’ as Security Password in Major Breach

Shocking security report reveals Louvre's surveillance used password 'LOUVRE' while housing priceless artworks. Cybersecurity experts call it basic security failure.

India Launches AI Governance Guidelines for Responsible Technology

MeitY unveils phased AI governance framework focusing on innovation, ethics and existing laws rather than immediate regulation to guide responsible AI deployment.

Topics

Supreme Court Questions Trump Tariffs, Billions in Refunds at Stake

The Supreme Court examines presidential power over import tariffs in a case that could force billions in refunds and reshape US trade policy for years to come.

India Blocks China-Linked Satellites in Security Move

India directs broadcasters to shift from Chinese satellites to domestic and approved foreign alternatives by March, strengthening national security infrastructure.

India’s Corporate Regulatory System Gets Major Overhaul from 2026

MCA approves 6 new RoC offices and 3 new RDs to streamline corporate compliance and boost ease of doing business in India's expanding corporate landscape.

Scientists Demand Ban on Chelsea Tractors After Fatal Crash Data

Imperial College researchers reveal SUVs are 82% more deadly to children and demand urgent action to remove these dangerous vehicles from British cities.

India Cuts Russian Oil Imports After US Sanctions on Rosneft, Lukoil

Major Indian refiners halt direct Russian crude purchases from December as US sanctions take effect, shifting to alternative suppliers amid market changes.

India-US Trade Agreement Talks Progress Despite Sensitive Issues

Commerce Minister Piyush Goyal confirms continuous India-US trade talks with 2025 deadline. Five rounds completed for bilateral trade agreement.

Novo Nordisk Cuts Forecasts Again Amid Weight-Loss Drug Competition

Ozempic maker Novo Nordisk slashes financial guidance for the fourth time as competition from Eli Lilly and copycat drugs intensifies in the weight-loss market.

Particle Accelerator Reveals Perfect Pasta Cooking Method

Scientists used particle accelerators to discover the ideal salt level and cooking time for perfect pasta, explaining why gluten-free versions turn mushy.
spot_img

Related Articles

Popular Categories

spot_imgspot_img