19.1 C
Delhi
Tuesday, March 3, 2026

LinkedIn Phishing Scam Targets Executives with Fake Board Offers

Key Takeaways

  • Finance executives are being targeted by sophisticated LinkedIn phishing scams
  • Attackers use fake board membership offers to steal Microsoft credentials
  • The scam bypasses traditional email filters using social media platforms
  • Security firm Push Security has detected and blocked these high-risk attacks

A sophisticated new phishing campaign is targeting LinkedIn users, specifically aiming to steal Microsoft login credentials from finance leaders and executives. Unlike traditional email-based attacks, this method uses direct messaging on the professional network to appear more legitimate.

How the LinkedIn Phishing Scam Works

The attack begins with a direct message from what appears to be a legitimate LinkedIn profile. The message contains an exclusive invitation for executives to join the executive board of a newly created “Commonwealth” investment fund in South America.

“I’m excited to extend an exclusive invitation for you to join the Executive Board of the Commonwealth investment fund in South America in partnership with AMCO – Our Asset Management branch, a bold new venture capital fund launching an Investment Fund in South America,” the fake message reads

The prestigious-sounding offer tempts targets with what appears to be a career milestone. However, the real scam begins when victims click on a document link included in the message to review the board position details.

Multi-Stage Credential Theft Process

Clicking the link initiates a complex redirect process through Google Search, then to an attacker-controlled site, and finally to a custom landing page hosted on firebasestorage.googleapis[.]com. When victims attempt to view the document using Microsoft, they’re redirected to a custom-designed adversary-in-the-middle (AiTM) phishing page that perfectly mimics the official Microsoft login screen.

Entering credentials on this fake page results in immediate theft of corporate login information, putting both personal and organizational data at significant risk.

Security Firm Sounds Alarm

Push Security uncovered this campaign and has successfully blocked several high-risk LinkedIn phishing attacks. The security company noted that attackers are employing advanced protection measures to avoid detection.

“Attackers are using common bot protection technologies like CAPTCHA and Cloudflare Turnstile to prevent security bots from accessing their web pages to be able to analyse them (and therefore block pages from being automatically flagged),” Push Security said in a blogpost.

The firm emphasized that phishing campaigns are increasingly shifting from email to social media platforms, requiring organizations to adapt their security awareness and protection strategies accordingly.

“Just because the attack happens over LinkedIn doesn’t lessen the impact — these are corporate credentials and accounts being targeted, even if it is nominally a “personal” application. Taking over a core identity like a Microsoft or Google account can have wide-ranging consequences, putting data at risk in both core apps and any downstream apps that can be accessed via SSO from the compromised account.” Push Security warned.

Organizations should and implement additional verification processes for sensitive credential requests originating from social media platforms.

Latest

Sam Altman reveals real reason why OpenAI rushed to partner with US Military after Trump banned Anthropic

OpenAI executives have given more information regarding the AI startup’s contract with the US Department of Defense after facing backlash online. The Sam Altm

After Donald Trump banned Anthropic, US Military used Claude in Iran strikes: Here is what changed

The US Military reportedly used Anthropic’s Claude AI model during its strikes on Iran. The attack on Iran came just a day after US President Donald Trump ins

SIM binding rules go live starting March 1: These WhatsApp, Telegram, Signal and other messaging app users to be impacted

Tech News News: Starting March 1, messaging apps like WhatsApp, Telegram, Signal and others must comply with the Department of Telecommunications' SIM-binding r

More than one year after DeepSeek’s R1 wiped nearly $600 billion off Nvidia market value in single day, Chinese startup planning another launch

Tech News News: DeepSeek, the Chinese AI startup that wiped nearly $600 billion off Nvidia’s market value in a single day with launch of its R1 model, is repo

Nothing Phone 4a and 4a Pro launching on 5 March: Design, expected specs and more

Nothing is set to launch its Phone 4 (a) series on 5 March. The launch event is also likely to see the unveling of new Headphone (a) with bold colors and long b

Topics

Who is Alexis Stone and did he really impersonate Jim Carrey in Paris? All about the makeup artist

Alexis Stone's alleged transformation into Jim Carrey for the 51st Caesar Film Awards has sparked mixed reactions.

Horoscope Today, March 3, 2026: Financial planning requires logic over instinct today

Daily Horoscope: Read the astrological predictions for each zodiac sign based on an expert's guidance on March 3, 2026.

Dubai and Abu Dhabi flights: Which UAE air routes are reopening? Updates on Emirates, flydubai and Etihad

Dubai’s government told passengers to head to airports only if they were contacted directly during what it said would be a “limited resumption of operations

IRS update: When will $8,046 tax refunds be credited? Reasons for possible delay

The IRS has reminded taxpayers claiming the EITC or ACTC that refunds may be delayed under the PATH Act.

Nancy Guthrie update: Savannah, Annie and Tommaso Cioni share emotional hug outside Catalina home

Savannah Guthrie, sister Annie and brother-in-law Tommaso Cioni shared an emotional hug outside Nancy Guthrie’s Catalina home Monday afternoon.

Europe reacts to Macron’s atomic offer

Europe reacts to Macron's atomic offer

BJP slams Mamata over March 6 sit-in plan against roll revision

Patna: The NDA on Monday slammed West Bengal CM Mamata Banerjee over his proposed March 6 sit-in against the ongoing special intensive revision (SIR) .

Quack’s heinous act: 57-Year-Old Quack Arrested for Raping Minor After Rituals; Victim’s Mother Takes Action Following Daughter’s Ordeal

Chaibasa: A 57-year-old quack was arrested on Monday on charges of raping a minor girl at her house after performing the rituals to cure the survivor’.
spot_img

Related Articles

Popular Categories

spot_imgspot_img