Contact Us
Oct 1

October PhishQueue Phishing News


“Whisper 2FA proves it: Verification alone won’t save you, but PhishQueue will.”

New Whisper 2FA Phishing Kit Targets Microsoft 365 Accounts

The Growing Threat

What’s Going On?

A new phishing toolkit called Whisper 2FA is being used to break into Microsoft 365 accounts. It does not just steal your password; it also captures your multi-factor authentication (MFA) codes in real time, which means even if you use MFA, attackers may still get in.

This phishing kit is widely available, easy for attackers to use, and effective at bypassing protections many users rely on.

How It Works:

  1. You receive an email impersonating from Microsoft, Docusign, a voicemail system, or another familiar service.
  2. You click the link and see a login screen that looks just like Microsoft 365.
  3. You enter your password and your MFA code.
  4. The phishing toolkit captures everything in real time, giving attackers immediate access to your account, even if MFA is enabled.

Why It Is Dangerous:

  • It is effective even if you use MFA.
  • The fake login screens are highly convincing and closely mimic real Microsoft 365 pages.
  • Attackers may try multiple times until they capture a valid MFA code.
  • You may not realize your account has been compromised until the damage has already occurred.

Sources: Nearly a Million Microsoft 365 Accounts Targeted by New Whisper 2FA Phishing Kit

🛡️ Your Best Defense: Do Not Click it. Submit It.

If something seems off; a strange sender, an unexpected login screen, or even a legit-looking email with a login link, report it to PhishQueue before you do anything else.

 

📌 Remember: The smartest move? Use PhishQueue first, not your best guess.

_____________________________________

🤖 Massive Microsoft 365 Phishing Attacks Using Whisper 2FA Kit

🔍 Example: A global malware campaign is using fake CAPTCHA pages to trick users into installing the Lumma information stealer, targeting industries like telecom, banking, and healthcare.

By convincing victims to run malicious commands outside the browser, attackers bypass security measures and evade detection. The campaign is part of a growing trend of sophisticated phishing tactics using fake domains, compromised emails, and platforms like Gravatar to mimic trusted services and steal credentials.

🤖Fake Voicemail Alerts Lead to Full Account Takeovers: 

🔍 Example: Users received “voicemail” notifications that led to fake login pages designed to steal credentials and bypass MFA.

🚨 The Bottom Line

Think before you click.

👉 Always verify through PhishQueue.

______________________________________________________

Quick Tips to Stay Safe:

  • Be wary of login prompts you did not initiate.
  • Hover over links before clicking to check the real URL.
  • Never enter an MFA code unless you are sure you requested it.
  • When in doubt, submit it to PhishQueue and wait for confirmation.

______________________________________________________

🎭 Phishing Joke of the Month

💡Why did the intern send the phishing email to the whole company?

👉Because teamwork makes the breach work! 😆

Cybersecurity is serious, but staying informed does not have to be dull!

Stay vigilant,

The PhishQueue Team


Paul Henry's 14 Absolute Truths In Network Security

We must recognize the 14 Absolute Truths In Network Security.

Reality check time – It is not too late.

Here are fourteen things you need to know:

  1. There is no such thing as security, only varying degrees of insecurity…
  2. The network does not exist to be secured…
14 Absolute Truths In Network Security

Download Full Document in PDF Form:

BlogMore from BSI

100% Privacy Guaranteed
Mar 26

March 2026 Lunch N Learn

This event will be both educational and informative. Attendees are eligible to earn ISC2 and ISACA CPE credits by providing their membership numbers. Certificates for ISC2 and ISACA CPEs will be issued following the event. Speaker:  Justin Formosa brings more than 18 years of experience in IT and cybersecurity, with deep expertise in protecting and […]

chasitynoel Mar 11 2026
Feb 1

February PhishQueue Phishing News

“DocuSign or DocuScam? PhishQueue to the rescue” New Phishing Campaign Uses Fake DocuSign Notifications to Deliver Malware and Steal Information The Growing Threat What’s Going On? Cybercriminals are using fake DocuSign notifications to trick people into clicking links that lead to harmful outcomes. These emails appear to be legitimate requests to review or sign a document. When […]

chasitynoel Feb 28 2026
Mar 11

BSI’s March 2026 Get Lit and Learn Networking Event – Corona Cigar Company

This event will be educational and informative. We offer ISC2 and ISACA CPE credits, if you provide us with your membership number, you are eligible to earn credits. We will provide ISC2 and ISACA certificates following the event. Event Sponsor: Title of Event: BSI Cyber Smoke Event Summary: Join us at Corona Cigar Company for […]

chasitynoel Feb 26 2026
Feb 26

February 2026 Lunch N Learn

This event will be both educational and informative. Attendees are eligible to earn ISC2 and ISACA CPE credits by providing their membership numbers. Certificates for ISC2 and ISACA CPEs will be issued following the event. Speaker:  G. Mark Hardy is the President of National Security Corporation and has been a trusted provider of information security […]

chasitynoel Feb 4 2026
Jan 1

January PhishQueue Phishing News

“Phishing hides in plain sight…PhishQueue brings it to light.” Microsoft Flags Multi-Stage Phishing and Business Email Compromise Attacks Targeting Organizations The Growing Threat What’s Going On? Security researchers at Microsoft have uncovered a sophisticated phishing campaign that starts with a deceptive email appearing to come from a trusted contact or familiar service. This attack leads […]

chasitynoel Jan 28 2026
Feb 4

BSI’s February 2026 Get Lit and Learn Networking Event – Corona Cigar Company

This event will be educational and informative. We offer ISC2 and ISACA CPE credits, if you provide us with your membership number, you are eligible to earn credits. We will provide ISC2 and ISACA certificates following the event. Event Sponsor: & Title of Event: BSI Cyber Smoke Event Summary: Join us at Corona Cigar Company […]

chasitynoel Jan 22 2026
Bayside Solutions