Phone Scammers Are Getting Smarter: How to Protect Your Work and Personal Accounts
Criminals are using sophisticated phone calls and fake login pages to steal passwords and extort victims. Here is how to recognize and stop these attacks.
Source
DataBreaches.net
Original headline: Welcome to BlackFile: Inside a Vishing Extortion Operation
Plain-English summary by GetCyberRight. Read the full report at the source above.
Google's Threat Intelligence Group has uncovered an extensive scam operation called BlackFile, run by a group tracked as UNC
- These criminals are using voice phishing, also known as vishing, to target organizations. They call victims pretending to be from IT support or other trusted sources, then trick them into entering their login credentials on fake websites. Once they steal these passwords, they use them to break into accounts and extort victims. The scammers use adversary-in-the-middle techniques that can even bypass some security protections. This threat affects anyone who uses single sign-on accounts for work. Single sign-on is when you use one login (often your work email and password) to access multiple work applications. If you work for a company, nonprofit, school, or any organization that uses cloud-based tools, you could be a target. The scammers often call pretending to be from your IT department or a service like Microsoft or Google. They create a sense of urgency to pressure you into acting quickly without thinking. Here is what you should do right now:
- Never give your password to anyone who calls you, even if they claim to be from IT support. Legitimate IT staff will never ask for your password over the phone.
- If someone calls claiming to be from your company's IT department or a tech service, hang up and call back using a number you find independently (from your company directory or the official website), not a number the caller provides.
- Look carefully at any login page before entering your password. Check the web address in the browser bar. Fake sites often have slight misspellings or unusual domain names.
- Enable two-factor authentication (also called multi-factor authentication or 2FA) on all your work and personal accounts. Even if scammers steal your password, they cannot get in without the second verification step.
- Report suspicious calls immediately to your workplace IT or security team. To stay safe long-term, treat unexpected phone calls with skepticism, especially ones creating urgency about account security or asking you to verify information. Train yourself and your family members to pause and verify before taking action. Scammers rely on pressure and fear. Taking a moment to think and verify independently can stop most of these attacks before they succeed.
Curated from trusted cybersecurity sources by GetCyberRight
Source: DataBreaches.netStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles

Russian Hackers Build New Spying Network: How This Affects Your Digital Safety
A sophisticated Russian hacking group has upgraded their tools for long-term spying. Most families won't be directly targeted, but understanding advanced threats helps protect your data.
2 min read
Russian Hacking Group Updates Spying Software: What Families Should Know
A Russian hacking group has updated their surveillance software to be harder to detect. This affects government and business targets, not home users.
1 min readPhone Scammers Are Using Fake Login Pages to Steal Work Accounts
Scammers are calling workers pretending to be tech support, then tricking them into giving away passwords through fake login screens.
2 min readMichigan Nurse Stole Patient Records to Commit $1.6 Million Medicare Fraud
A home health care agency owner used stolen patient information to bill Medicare for services never provided. This case shows why protecting medical records matters.
2 min read