Home
/
Collections
/
Phish of the Week

Phish of the Week

# Phishing
Popular topics
# Phishing
# Phish of the Week
# Security Awareness Training
# Cybersecurity Awareness Month
# Storytelling
# Programme
# Threat Studies
# Gamification
# Metrics
# Workshop
# Data
# Narrative
# Content
# Jobs
# Opportunities
# New Starters
# Onboarding
# Careers
Content

Phish of the Week 8th of June

This week's Phish of the Week breaks down a Claude AI impersonation attack that uses a look-alike landing page and a Browser-in-the-Browser pop-up to harvest Google credentials.
# Phish of the Week
# Phishing
Mette Luntama
Mette Luntama · Jun 8th, 2026
Comment
Content

Phish of the Week 11th of June

A legitimate Temu password reset notification becomes the delivery vehicle in this callback phishing attack, where an attacker-injected phone number poses as customer support.
# Phish of the Week
# Phishing
Mette Luntama
Mette Luntama · Jun 11th, 2026
Comment
Content

Phish of the Week 15th of June

Attackers impersonate FIFA World Cup 2026 recruitment staff in this credential harvesting campaign, using a fake scheduling page and a Browser-in-the-Browser pop-up to steal Google credentials.
# Phish of the Week
# Phishing
Mette Luntama
Mette Luntama · Jun 15th, 2026
Comment
Content

Phish of the Week 22nd of June

This legitimate Facebook Business Manager partner request highlights how attackers can weaponize a real platform notification to smuggle a malicious link past security filters.
# Phish of the Week
# Phishing
Mette Luntama
Mette Luntama · Jun 22nd, 2026
Comment
Content

Phish of the Week 29th of June

This spoofed incoming message failure alert uses sender address impersonation and a Google domain open redirect to deliver a prefilled Microsoft credential harvester.
# Phish of the Week
# Phishing
Mette Luntama
Mette Luntama · Jun 29th, 2026
Comment
Content

Phish of the Week 06th of July

This multi-stage HR impersonation attack uses a realistic training quiz to build credibility before funneling the target into a dynamically branded Microsoft credential harvester.
# Phish of the Week
# Phishing
Mette Luntama
Mette Luntama · Jul 6th, 2026
Comment
Content

Phish of the Week 13th of July

A fake prescription notice uses a QR code to launch a device code phishing flow, giving attackers Microsoft account access without ever needing to steal the recipient's password.
# Phish of the Week
# Phishing
Mette Luntama
Mette Luntama · Jul 13th, 2026
Comment
Content

Phish of the Week 20th of July

Attackers repurpose a legitimate email marketing platform to deliver a Fastway Couriers impersonation, funneling recipients toward a fake customs duty payment and financial theft.
# Phish of the Week
# Phishing
Mette Luntama
Mette Luntama · Jul 20th, 2026
Comment
Content

Phish of the Week 27th of July

This Phish of the Week features a personalized Adobe Summit invitation with mismatched event dates and a countdown timer that pressures recipients into signing in through a fake Google pop-up.
# Phish of the Week
# Phishing
Mette Luntama
Mette Luntama · Jul 27th, 2026
Comment
Content

Phish of the Week 03rd of August

Attackers are sending out a team lunch RSVP email featuring a genuine Microsoft sign-in link that quietly hands recipients off to a fake Google credential harvester.
# Phish of the Week
# Phishing
Mette Luntama
Mette Luntama · Aug 3rd, 2026
Comment
Content

Phish of the Week 10th of August

A fake charge alert is delivered through VISA's own account-creation system, luring recipients into calling scammers to "cancel" a payment.
# Phish of the Week
# Phishing
Mette Luntama
Mette Luntama · Aug 10th, 2026
Comment
Content

Phish of the Week 17th of August

A fake project collaboration invite, where a calm, urgency-free pretext and a simulated live Teams meeting lull recipients into entering their Microsoft password not once, but twice.
# Phish of the Week
# Phishing
Mette Luntama
Mette Luntama · Aug 17th, 2026
Comment
Content

Phish of the Week 24th of August

A Google Ads on Air impersonation, where genuine branding, a real third-party mailing platform, and zero urgency combine to make a credential-harvesting page feel routine.
# Phish of the Week
# Phishing
Mette Luntama
Mette Luntama · Aug 24th, 2026
Comment