Find notable cyber news and cases, enriched with sources, timelines, and signals.

Jingle Thief cloud phishing and smishing gift card fraud campaign

Campaign
First reported
Last updated
Happening score
H score 42
1 unique sources, 1 articles

Summary

Hide ▲

The Jingle Thief campaign is actively using phishing and smishing to steal cloud credentials and drive unauthorized gift card fraud against retail and consumer services organizations. Researchers observed a wave of coordinated attacks in April and May 2025, and the cluster has been active since at least late 2021. The operation matters because intruders can keep prolonged cloud access, broaden their foothold, and issue gift cards at scale with minimal traceability.

Related Happenings

Storm-2949 Microsoft 365 and Azure data-theft campaign

Campaign
First: 19.05.2026 22:35 Last: 19.05.2026 22:35 Sources 1

About this happening: The **Storm-2949** campaign is targeting **Microsoft 365 and Azure production environments** to steal sensitive data, increasing the risk of privileged-account takeover and cloud...

PCPJack credential theft framework worms across exposed cloud infrastructure

Malware Activity
First: 08.05.2026 12:00 Last: 08.05.2026 12:00 Sources 1

About this happening: The **PCPJack** malware activity is extending a **credential-theft** operation across **exposed cloud infrastructure**, stripping **TeamPCP** artifacts and stealing access from se...

QR code phishing surged across email threats in Q1 2026

Target Trend
First: 05.05.2026 09:35 Last: 05.05.2026 09:35 Sources 1

About this happening: **Q1 2026** email-threat telemetry shows **QR code phishing** and **CAPTCHA-gated phishing** rising quickly, increasing the risk of **credential theft** across **organizations**....

W3LL Microsoft 365 adversary-in-the-middle phishing campaign

Campaign
First: 13.04.2026 21:55 Last: 13.04.2026 21:55 Sources 1

About this happening: The **W3LL** phishing operation turned into a high-volume **Microsoft 365** credential-theft campaign, exposing **more than 17,000 victims worldwide** to **BEC** risk. The kit use...

OAuth device-code phishing campaign targeting SaaS accounts

Campaign
First: 04.04.2026 17:17 Last: 04.04.2026 17:17 Sources 1

About this happening: A **device code phishing** campaign now includes **EvilTokens**, a **phishing-as-a-service** kit sold on **Telegram** that uses the **OAuth 2.0 device authorization flow** to hija...

Timeline

  1. 23.10.2025 10:52 2 articles · 7mo ago

    Jingle Thief cloud phishing and smishing gift card fraud campaign

    Initial Disclosure

    In **April and May 2025**, **Jingle Thief** entered a coordinated credential-theft phase by sending **phishing and smishing** lures to capture **Microsoft 365** logins. That initial access was then used to search for gift-card issuance workflows and prepare follow-on fraud.

    Show sources