Find notable cyber news and cases, enriched with sources, timelines, and signals.

Whisper 2FA phishing campaign targeting accounts across multiple industries

Campaign
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

Whisper 2FA has become a high-volume phishing campaign that has driven nearly one million attacks against accounts across multiple industries since July 2025. The scale and persistence make it a significant credential-theft threat. The platform's design helps attackers repeatedly capture passwords and MFA codes until they obtain a valid token.

Related Happenings

Kali365 Microsoft 365 device-code phishing campaign

Campaign
H score46 First: 25.05.2026 15:45 Last: 25.05.2026 15:45 Sources 1

About this happening: A Kali365 phishing campaign is targeting Microsoft 365 environments worldwide with device-code login lures, putting accounts at risk of token theft and MFA bypas...

CypherLoc phishing-led browser scareware campaign

Campaign
H score49 First: 20.05.2026 13:00 Last: 20.05.2026 13:00 Sources 1

About this happening: The CypherLoc operation has driven around 2.8 million attacks since the start of 2026, using phishing emails to send users to malicious pages that lock browsers an...

EvilTokens Microsoft 365 consent phishing campaign

Campaign
H score39 First: 19.05.2026 14:30 Last: 19.05.2026 14:30 Sources 1

About this happening: The EvilTokens campaign rapidly compromised more than 340 Microsoft 365 organizations across five countries, showing how OAuth grant abuse can bypass MFA and c...

BlackFile vishing extortion campaign targeting retail and hospitality organizations

Campaign
H score37 First: 24.04.2026 21:26 Last: 24.04.2026 21:26 Sources 1

About this happening: The BlackFile campaign is driving vishing-based data theft and extortion against retail and hospitality organizations, putting employee credentials and enterprise data...

W3LL Microsoft 365 adversary-in-the-middle phishing campaign

Campaign
H score39 First: 13.04.2026 21:55 Last: 13.04.2026 21:55 Sources 1

About this happening: The W3LL phishing operation turned into a high-volume Microsoft 365 credential-theft campaign, exposing more than 17,000 victims worldwide to BEC risk. The kit use...

Timeline

  1. 15.10.2025 18:00 2 articles · 9mo ago

    Whisper 2FA phishing campaign disclosure

    Initial Disclosure

    Security researchers describe Whisper 2FA as a high-volume phishing platform that has driven nearly one million attacks since July 2025 against accounts across multiple industries. The kit uses AJAX and attacker command-and-control systems to repeatedly capture credentials and multi-factor authentication codes, while delivering lures that impersonate DocuSign, Adobe and Microsoft 365.

    Show sources