23.1 C
Delhi
Wednesday, November 5, 2025

LinkedIn Phishing Scam Targets Executives with Fake Board Offers

Key Takeaways

  • Finance executives are being targeted by sophisticated LinkedIn phishing scams
  • Attackers use fake board membership offers to steal Microsoft credentials
  • The scam bypasses traditional email filters using social media platforms
  • Security firm Push Security has detected and blocked these high-risk attacks

A sophisticated new phishing campaign is targeting LinkedIn users, specifically aiming to steal Microsoft login credentials from finance leaders and executives. Unlike traditional email-based attacks, this method uses direct messaging on the professional network to appear more legitimate.

How the LinkedIn Phishing Scam Works

The attack begins with a direct message from what appears to be a legitimate LinkedIn profile. The message contains an exclusive invitation for executives to join the executive board of a newly created “Commonwealth” investment fund in South America.

“I’m excited to extend an exclusive invitation for you to join the Executive Board of the Commonwealth investment fund in South America in partnership with AMCO – Our Asset Management branch, a bold new venture capital fund launching an Investment Fund in South America,” the fake message reads

The prestigious-sounding offer tempts targets with what appears to be a career milestone. However, the real scam begins when victims click on a document link included in the message to review the board position details.

Multi-Stage Credential Theft Process

Clicking the link initiates a complex redirect process through Google Search, then to an attacker-controlled site, and finally to a custom landing page hosted on firebasestorage.googleapis[.]com. When victims attempt to view the document using Microsoft, they’re redirected to a custom-designed adversary-in-the-middle (AiTM) phishing page that perfectly mimics the official Microsoft login screen.

Entering credentials on this fake page results in immediate theft of corporate login information, putting both personal and organizational data at significant risk.

Security Firm Sounds Alarm

Push Security uncovered this campaign and has successfully blocked several high-risk LinkedIn phishing attacks. The security company noted that attackers are employing advanced protection measures to avoid detection.

“Attackers are using common bot protection technologies like CAPTCHA and Cloudflare Turnstile to prevent security bots from accessing their web pages to be able to analyse them (and therefore block pages from being automatically flagged),” Push Security said in a blogpost.

The firm emphasized that phishing campaigns are increasingly shifting from email to social media platforms, requiring organizations to adapt their security awareness and protection strategies accordingly.

“Just because the attack happens over LinkedIn doesn’t lessen the impact — these are corporate credentials and accounts being targeted, even if it is nominally a “personal” application. Taking over a core identity like a Microsoft or Google account can have wide-ranging consequences, putting data at risk in both core apps and any downstream apps that can be accessed via SSO from the compromised account.” Push Security warned.

Organizations should and implement additional verification processes for sensitive credential requests originating from social media platforms.

Latest

Zoho’s Arattai Messaging App to Get End-to-End Encryption

Zoho founder Sridhar Vembu seeks user input on implementing end-to-end encryption in WhatsApp rival Arattai, considering default vs optional security.

Amazon Threatens Perplexity AI Over Browser Shopping Feature

Perplexity AI reveals legal threat from Amazon over Comet browser's shopping agent, calling it corporate bullying that threatens AI innovation.

CERT-In High-Severity Warning: Update Google Chrome Now

Critical Chrome vulnerabilities allow system takeover. Learn which versions are affected and how to protect your device immediately.

Apple Lets Users Turn Off Controversial iOS 26 Liquid Glass Design

iOS 26.1 update introduces settings to reduce Liquid Glass effects and disable lock screen camera gesture, addressing key user complaints.

Smart TV Price Drop: LG, Samsung, Xiaomi TVs Under ₹14,000

Massive discounts up to 48% on 32-inch LED Smart TVs from top brands. Compare features and prices to find the best deal for your home.

Topics

Zoho’s Arattai Messaging App to Get End-to-End Encryption

Zoho founder Sridhar Vembu seeks user input on implementing end-to-end encryption in WhatsApp rival Arattai, considering default vs optional security.

Commercial Vehicle Sales Rebound in October on Infrastructure Push

India's CV sector shows strong recovery with major manufacturers reporting double-digit growth driven by infrastructure projects and festive logistics demand.

India-NZ FTA Talks Advance as Piyush Goyal Meets Trade Minister

Commerce Minister Piyush Goyal begins New Zealand visit for FTA negotiations, aiming to boost bilateral trade and investment opportunities between both nations.

Amazon Threatens Perplexity AI Over Browser Shopping Feature

Perplexity AI reveals legal threat from Amazon over Comet browser's shopping agent, calling it corporate bullying that threatens AI innovation.

CERT-In High-Severity Warning: Update Google Chrome Now

Critical Chrome vulnerabilities allow system takeover. Learn which versions are affected and how to protect your device immediately.

Paytm Posts Second Straight Quarterly Profit; Revenue Up 24%

Paytm reports strong Q2 results with Rs 211 crore profit before impairment, 24% revenue growth to Rs 2,061 crore, and 63% surge in financial services business.

Maldives Enacts Historic Generational Tobacco Ban for Youth

The Maldives implements a permanent smoking ban for anyone born after 2007, aiming to create a tobacco-free generation and protect teen health.

IBM to Cut 2,700 Jobs in 2025 Amid AI Restructuring

IBM joins Amazon, Microsoft, Google in tech layoffs as companies shift focus to artificial intelligence. Over 30,000 jobs cut across major tech firms in 2025.
spot_img

Related Articles

Popular Categories

spot_imgspot_img