• Almost 8000 organizations hit by fake voicemail transcript emails

    From TechnologyDaily@1337:1/100 to All on Tuesday, September 15, 2026 16:00:21
    Almost 8000 organizations hit by fake voicemail transcript emails in credential phishing attack

    Date:
    Tue, 15 Sep 2026 14:45:00 +0000

    Description:
    That voicemail notification in your inbox could be a phishing lure being sent by a cybercriminal.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Check Point spotted phishing emails spoofing voicemail transcript notifications, hitting 7,800+ orgs Malicious SVG attachments autofill victim emails, redirecting to fake login pages for credential theft SVG format bypasses filters; businesses urged to verify notifications and treat SVGs as active content Hackers have a new phishing lure - the automated voicemail transcript notification, and have already used it against thousands of organizations already, sending tens of thousands of malicious emails.

    In a new report, security experts from Check Point Research (CPR) said they spotted an ongoing campaign that has already targeted thousands of organizations. The goal of the campaign seems to be credential theft - grabbing access to peoples email accounts, business services, and similar. Latest Videos From TechRadar Watch full video here: Abusing the trends The proliferation of AI gave rise to a new trend in the office - automated voicemail transcripts. When a person receives a voicemail, they can choose to read it instead of listening to it. Useful for a noisy workplace environment, or for emails that are too sensitive to be blasted through a speaker system. An automated system mails the transcript to the recipients inbox in a
    familiar format, and since theyre used to receiving this type of email,
    theyre not suspicious or skeptical enough. Their guard is lowered, which is a perfect opportunity for the attackers.

    Between August 17 and August 31, Check Point identified more than 58,000 emails tied to the campaign. The operation targeted over 7,800 organizations, leveraging more than 38,400 spoofed sender addresses across over 9,300
    spoofed domains, the researchers explained. You may like Hackers are using 'invisible' Unicode characters to sneak phishing lures into emails Microsoft 365 users hit by two major threat campaigns - fake IT calls and phishing emails target users across the world Microsoft login pages are being abused
    as hackers try and lure in unlucky victims

    The emails follow a simple formula the recipients are already used to seeing. Each messages subject line begins with Automated transcript, followed by a partially redacted phone number and a random tracking string. The effect is deliberately understated: a notification that appears to have been generated by a trusted workplace system, CPR explains.

    The email domains are also spoofed in a way that makes it seem as if theyre coming from within the same organization. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me
    with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over. SVG attachments Every email comes with an attachment. It is designed to look like a regular call recording file, using names such as 001min 09sec_.svg. But notice the file type - SVG. This is not an audio file, it is short for Scalable Vector Graphics (SVG) - an image file. There are a few reasons why scammers are opting for this particular format, but the number one is that it is an XML-based document that can contain JavaScript. When a browser opens
    the SVG, that JavaScript can execute, redirecting victims to a spoofed login page where theyre asked to log in.

    This is exactly the setup here, too. To make matters worse, since the recipients email address is hardcoded in the URL, the fake login form auto-fills it. When the victim opens up the SVG, theyre redirected to a login page where the username part is already populated, making it more
    personalized and credible.

    Another key reason why SVG is a popular format in these attacks is that it
    can bypass email security systems. If scammers put a hyperlink in the emails body, it can be scanned by the system, and sanitized if proven malicious (which it would). But without a link the only other thing a security system can check are the attachments, and there the usual suspects are .exe, .docx, or .pdf files. Very few are focusing on SVG files, as well. Adapting to
    change This campaign is a great example of how quickly attackers adapt to enterprise workflows as automation becomes more common, Check Points researchers have warned. In response, businesses should start treating automated notifications as signals that need to be verified - especially
    those when the sender appears to match the recipients domain.

    Furthermore, businesses should define which file types and domains AI agents are allowed to access without human confirmation, and finally, they should definitely inspect SVG attachments as active content, not simply as images. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/almost-8000-organizations-hit-by-fake-v oicemail-transcript-emails-in-credential-phishing-attack


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)