- What: Phishing scams target corporate credentials on mobile devices
- Impact: Enterprise accounts and sensitive data at risk
Phishing Fake recruiter scams target corporate credentials on mobile devices August 26, 2026 Share By SC Staff (Adobe Stock) Infosecurity Magazine reports that fake recruiter scams are increasingly targeting corporate credentials on mobile devices, employing sophisticated tactics like full-screen login pages and pre-qualification checks to specifically harvest enterprise accounts. Researchers at Zimperium's zLabs have identified these campaigns, tracked as RecruitTrap, impersonating major companies such as Amazon, Apple, and Deloitte. The attacks utilize full-screen counterfeit login pages on mobile devices, removing browser elements to hinder user detection. A key tactic involves screening submitted information, rejecting personal email addresses and demanding corporate credentials, indicating a focus on accounts with access to sensitive enterprise resources. Attackers aim to obtain OAuth tokens, potentially leading to unauthorized access to internal communications and cloud applications, facilitating further network intrusion. The infrastructure behind these scams has shown persistence across various cloud, hosting, and domain-parking providers, including Amazon and SEDO. This persistence allows new lookalike domains to remain operational before being added to threat intelligence feeds, posing a challenge for traditional URL blocklists. Zimperium recommends securing corporate identities at the mobile touchpoint and dynamically inspecting network traffic to counter these credential-harvesting attempts. Source: Infosecurity Magazine SC Staff Related Phishing AnonyMousKIT phishing service targets Apple credentials and Activation Lock SC Staff August 26, 2026 AnonyMousKIT is specifically designed to circumvent Apple's Activation Lock, a security measure that links an Apple device to its owner's Apple ID, making stolen devices difficult to resell. Phishing ShinyHunters claims social engineering attack against ReliaQuest SC Staff August 24, 2026 The attack involved threat actors calling employees and attempting to trick them into accessing a fake ReliaQuest single sign-on (SSO) page hosted on a lookalike domain, reliaquest[.]claims. Phishing FBI warns of rising sextortion attacks targeting social media users SC Staff August 12, 2026 Perpetrators are largely using social engineering tactics, brute-forcing accounts with leaked passwords, impersonating social media customer service, and employing phishing emails with fake login pages. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds