12.1 C
Delhi
Friday, January 16, 2026

LinkedIn Phishing Scam Targets Executives with Fake Board Offers

Key Takeaways

  • Finance executives are being targeted by sophisticated LinkedIn phishing scams
  • Attackers use fake board membership offers to steal Microsoft credentials
  • The scam bypasses traditional email filters using social media platforms
  • Security firm Push Security has detected and blocked these high-risk attacks

A sophisticated new phishing campaign is targeting LinkedIn users, specifically aiming to steal Microsoft login credentials from finance leaders and executives. Unlike traditional email-based attacks, this method uses direct messaging on the professional network to appear more legitimate.

How the LinkedIn Phishing Scam Works

The attack begins with a direct message from what appears to be a legitimate LinkedIn profile. The message contains an exclusive invitation for executives to join the executive board of a newly created “Commonwealth” investment fund in South America.

“I’m excited to extend an exclusive invitation for you to join the Executive Board of the Commonwealth investment fund in South America in partnership with AMCO – Our Asset Management branch, a bold new venture capital fund launching an Investment Fund in South America,” the fake message reads

The prestigious-sounding offer tempts targets with what appears to be a career milestone. However, the real scam begins when victims click on a document link included in the message to review the board position details.

Multi-Stage Credential Theft Process

Clicking the link initiates a complex redirect process through Google Search, then to an attacker-controlled site, and finally to a custom landing page hosted on firebasestorage.googleapis[.]com. When victims attempt to view the document using Microsoft, they’re redirected to a custom-designed adversary-in-the-middle (AiTM) phishing page that perfectly mimics the official Microsoft login screen.

Entering credentials on this fake page results in immediate theft of corporate login information, putting both personal and organizational data at significant risk.

Security Firm Sounds Alarm

Push Security uncovered this campaign and has successfully blocked several high-risk LinkedIn phishing attacks. The security company noted that attackers are employing advanced protection measures to avoid detection.

“Attackers are using common bot protection technologies like CAPTCHA and Cloudflare Turnstile to prevent security bots from accessing their web pages to be able to analyse them (and therefore block pages from being automatically flagged),” Push Security said in a blogpost.

The firm emphasized that phishing campaigns are increasingly shifting from email to social media platforms, requiring organizations to adapt their security awareness and protection strategies accordingly.

“Just because the attack happens over LinkedIn doesn’t lessen the impact — these are corporate credentials and accounts being targeted, even if it is nominally a “personal” application. Taking over a core identity like a Microsoft or Google account can have wide-ranging consequences, putting data at risk in both core apps and any downstream apps that can be accessed via SSO from the compromised account.” Push Security warned.

Organizations should and implement additional verification processes for sensitive credential requests originating from social media platforms.

Latest

iQOO Z11 Turbo Launched With 7,600mAh Battery & Snapdragon 8s Gen 3

iQOO Z11 Turbo debuts with a massive battery, 100W charging, and flagship Snapdragon 8s Gen 3 chip. Check price, specs, and launch details.

India’s Scramjet Success: Why Fighter Jets Still Use Conventional Engines

India joins the hypersonic club with scramjet tech. We explain why this breakthrough won't power fighter jets yet and what it means for missiles and space travel.

Meta Bans ChatGPT on WhatsApp from 2026: How to Save Chats

WhatsApp will block ChatGPT and third-party AI tools in 2026. Learn why Meta is banning AI, how to back up your chat history, and what it means for users.

Amazon Republic Day Sale 2026: Up to 80% Off on Gadgets & Appliances

Amazon's Great Republic Day Sale 2026 is live with massive discounts on electronics, fashion & home appliances. Get top deals, no-cost EMI & a chance to win a trip.

Amazon Republic Day Sale: iPhone 15, OnePlus Nord 5, iQOO 15 Big Discounts

Get record-low prices on iPhone 15, OnePlus Nord 5, and iQOO 15 during Amazon's Great Republic Day Sale 2025 from Jan 14-18. Details on discounts, bank offers, and early access.

Topics

Mumbai Voter Turnout Hits 32-Year High in Lok Sabha Elections

Mumbai recorded 55.38% voter turnout in 2024 Lok Sabha polls, its second-highest in 32 years. Analysis reveals what drove the surge and what it means for the city's civic engagement.

Spirit Release Date: Prabhas & Sandeep Reddy Vanga Film Set for Jan 2026

Sandeep Reddy Vanga announces January 10, 2026, as the release date for his pan-India film Spirit, starring Prabhas and Tripti Dimri.

BJP Breaks Sena Fortress, Wins Historic 2026 BMC Election

The BJP-led Mahayuti alliance ends the Thackeray dynasty's 30-year rule over Mumbai's civic body. Analysis on why Shiv Sena (UBT) crumbled and Congress stalled.

Wipro Declares Rs 6 Dividend as Q3 Profit Dips to Rs 3,119 Crore

Wipro announces Rs 6 per share interim dividend for FY25. Q3 net profit falls to Rs 3,119 crore, but order bookings surge 31% year-on-year.

Bhumi Pednekar’s Daldal Teaser Out, Series Premieres April 5 on Prime

Watch the gritty teaser for crime thriller 'Daldal' starring Bhumi Pednekar as a cop. The series premieres on Amazon Prime Video on April 5.

Doctor’s Viral Senate Testimony: “Biologically, Men Cannot Get Pregnant”

Dr Nisha Verma's exchange with a US senator on pregnancy and gender terminology goes viral, highlighting post-Roe reproductive rights debates.

Trump Nominated for Nobel Peace Prize Over Abraham Accords Role

US lawmaker nominates Donald Trump for the Nobel Peace Prize, citing his historic role in brokering the Abraham Accords. This marks his fourth nomination.

US Lawmaker Calls Pakistan a Failed State, Contrasts with India

Congressman Rich McCormick's speech contrasts India's investment role with Pakistan, which he accuses of harbouring terrorism and being a Chinese client state.
spot_img

Related Articles

Popular Categories

spot_imgspot_img