18.1 C
Delhi
Tuesday, March 3, 2026

LinkedIn Phishing Scam Targets Executives with Fake Board Offers

Key Takeaways

  • Finance executives are being targeted by sophisticated LinkedIn phishing scams
  • Attackers use fake board membership offers to steal Microsoft credentials
  • The scam bypasses traditional email filters using social media platforms
  • Security firm Push Security has detected and blocked these high-risk attacks

A sophisticated new phishing campaign is targeting LinkedIn users, specifically aiming to steal Microsoft login credentials from finance leaders and executives. Unlike traditional email-based attacks, this method uses direct messaging on the professional network to appear more legitimate.

How the LinkedIn Phishing Scam Works

The attack begins with a direct message from what appears to be a legitimate LinkedIn profile. The message contains an exclusive invitation for executives to join the executive board of a newly created “Commonwealth” investment fund in South America.

“I’m excited to extend an exclusive invitation for you to join the Executive Board of the Commonwealth investment fund in South America in partnership with AMCO – Our Asset Management branch, a bold new venture capital fund launching an Investment Fund in South America,” the fake message reads

The prestigious-sounding offer tempts targets with what appears to be a career milestone. However, the real scam begins when victims click on a document link included in the message to review the board position details.

Multi-Stage Credential Theft Process

Clicking the link initiates a complex redirect process through Google Search, then to an attacker-controlled site, and finally to a custom landing page hosted on firebasestorage.googleapis[.]com. When victims attempt to view the document using Microsoft, they’re redirected to a custom-designed adversary-in-the-middle (AiTM) phishing page that perfectly mimics the official Microsoft login screen.

Entering credentials on this fake page results in immediate theft of corporate login information, putting both personal and organizational data at significant risk.

Security Firm Sounds Alarm

Push Security uncovered this campaign and has successfully blocked several high-risk LinkedIn phishing attacks. The security company noted that attackers are employing advanced protection measures to avoid detection.

“Attackers are using common bot protection technologies like CAPTCHA and Cloudflare Turnstile to prevent security bots from accessing their web pages to be able to analyse them (and therefore block pages from being automatically flagged),” Push Security said in a blogpost.

The firm emphasized that phishing campaigns are increasingly shifting from email to social media platforms, requiring organizations to adapt their security awareness and protection strategies accordingly.

“Just because the attack happens over LinkedIn doesn’t lessen the impact — these are corporate credentials and accounts being targeted, even if it is nominally a “personal” application. Taking over a core identity like a Microsoft or Google account can have wide-ranging consequences, putting data at risk in both core apps and any downstream apps that can be accessed via SSO from the compromised account.” Push Security warned.

Organizations should and implement additional verification processes for sensitive credential requests originating from social media platforms.

Latest

Sam Altman reveals real reason why OpenAI rushed to partner with US Military after Trump banned Anthropic

OpenAI executives have given more information regarding the AI startup’s contract with the US Department of Defense after facing backlash online. The Sam Altm

After Donald Trump banned Anthropic, US Military used Claude in Iran strikes: Here is what changed

The US Military reportedly used Anthropic’s Claude AI model during its strikes on Iran. The attack on Iran came just a day after US President Donald Trump ins

SIM binding rules go live starting March 1: These WhatsApp, Telegram, Signal and other messaging app users to be impacted

Tech News News: Starting March 1, messaging apps like WhatsApp, Telegram, Signal and others must comply with the Department of Telecommunications' SIM-binding r

More than one year after DeepSeek’s R1 wiped nearly $600 billion off Nvidia market value in single day, Chinese startup planning another launch

Tech News News: DeepSeek, the Chinese AI startup that wiped nearly $600 billion off Nvidia’s market value in a single day with launch of its R1 model, is repo

Nothing Phone 4a and 4a Pro launching on 5 March: Design, expected specs and more

Nothing is set to launch its Phone 4 (a) series on 5 March. The launch event is also likely to see the unveling of new Headphone (a) with bold colors and long b

Topics

“Who cares?”: New York Yankees captain Aaron Judge opens up about Bryce Harper’s message before playoff pressure hit

MLB News: New York Yankees captain Aaron Judge does not often look nervous. He is one of the biggest stars in baseball but before a huge 2025 postseason game at

Israeli military says it killed Hezbollah’s intelligence chief in Beirut strike

The IDF described Hussein Makled as a central figure in Hezbollah’s intelligence apparatus, responsible for gathering and analysing information on Israeli tro

Spain draws red line, rejects US use of bases in Iran campaign

Europe News: Spain has refused to allow the United States to use jointly operated military bases on its territory for strikes against Iran, as Madrid hardened i

Keir Starmer shrugs off Trump rebuke, says UK won’t back regime change from skies

Keir Starmer defended the UK’s decision to stay out of initial US-Israeli strikes on Iran. On Sunday, the UK agreed to allow limited US use of British bases f

“My whole life is written”: Joe Burrow’s rumored girlfriend Olivia Ponton makes a cryptic comment about her life as he stays out of the...

NFL News: Joe Burrow, the Cincinnati Bengals’ star player, was rumored to be engaged to his ex girlfriend before the two ended things in 2022.Since then, the

Lunar Eclipse 2026: Food rules to follow, dos and don’ts during Chandra Grahan

Eclipses are natural set of events that define the beauty of nature and at the same time, help us understand its powder. A Lunar or moon eclipse occur.

Bigg Boss 16 fame Manya Singh stranded in Dubai amid Middle East tensions; says, “Could hear blasts”

Bigg Boss 16 fame Manya Singh, who is currently stuck in Dubai, shared a video on her social media account a few hours ago. She posted the video after.

NHL Trade Update: Seattle Kraken sign defenseman Gustav Olofsson to a one-year deal ahead of deadline

NHL News: Ahead of the trade deadline, the NHL's Seattle Kraken have signed defenseman Gustav Olofsson to a one-year, two-way contract worth $775,000, adding ex
spot_img

Related Articles

Popular Categories

spot_imgspot_img