Find notable cyber news and cases, enriched with sources, timelines, and signals.

Whisper 2FA phishing campaign targeting accounts across multiple industries

Campaign
First reported
Last updated
Happening score
H score 37
1 unique sources, 1 articles

Summary

Hide ▲

Whisper 2FA has become a high-volume phishing campaign that has driven nearly one million attacks against accounts across multiple industries since July 2025. The scale and persistence make it a significant credential-theft threat. The platform's design helps attackers repeatedly capture passwords and MFA codes until they obtain a valid token.

Related Happenings

Kali365 Microsoft 365 device-code phishing campaign

Campaign
First: 25.05.2026 15:45 Last: 25.05.2026 15:45 Sources 1

About this happening: A **Kali365** phishing campaign is targeting **Microsoft 365** environments worldwide with **device-code login lures**, putting accounts at risk of **token theft** and **MFA bypas...

CypherLoc phishing-led browser scareware campaign

Campaign
First: 20.05.2026 13:00 Last: 20.05.2026 13:00 Sources 1

About this happening: The **CypherLoc** operation has driven **around 2.8 million attacks** since the start of **2026**, using **phishing emails** to send users to malicious pages that lock browsers an...

EvilTokens Microsoft 365 consent phishing campaign

Campaign
First: 19.05.2026 14:30 Last: 19.05.2026 14:30 Sources 1

About this happening: The **EvilTokens** campaign rapidly compromised **more than 340 Microsoft 365 organizations** across **five countries**, showing how **OAuth grant abuse** can bypass **MFA** and c...

BlackFile vishing extortion campaign targeting retail and hospitality organizations

Campaign
First: 24.04.2026 21:26 Last: 24.04.2026 21:26 Sources 1

About this happening: The **BlackFile** campaign is driving **vishing-based data theft and extortion** against **retail and hospitality organizations**, putting employee credentials and enterprise data...

W3LL Microsoft 365 adversary-in-the-middle phishing campaign

Campaign
First: 13.04.2026 21:55 Last: 13.04.2026 21:55 Sources 1

About this happening: The **W3LL** phishing operation turned into a high-volume **Microsoft 365** credential-theft campaign, exposing **more than 17,000 victims worldwide** to **BEC** risk. The kit use...

Timeline

  1. 15.10.2025 18:00 2 articles · 7mo ago

    Whisper 2FA phishing campaign disclosure

    Initial Disclosure

    Security researchers describe Whisper 2FA as a high-volume phishing platform that has driven nearly one million attacks since July 2025 against accounts across multiple industries. The kit uses AJAX and attacker command-and-control systems to repeatedly capture credentials and multi-factor authentication codes, while delivering lures that impersonate DocuSign, Adobe and Microsoft 365.

    Show sources