CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Operation DoppelBrand Phishing Campaign Targets Fortune 500 Firms

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A phishing campaign named Operation DoppelBrand has been targeting Fortune 500 companies, including Wells Fargo and USAA, between December 2025 and January 2026. The campaign, attributed to a financially motivated threat actor known as GS7, uses lookalike domains and cloned login portals to harvest credentials. The operation also deploys remote management tools for persistent access and monetizes compromised accounts. The infrastructure is highly automated, with over 150 domains identified, and targets major US financial institutions, investment firms, and technology brands.

Timeline

  1. 16.02.2026 17:45 1 articles · 7h ago

    Operation DoppelBrand Phishing Campaign Targets Fortune 500 Firms

    A phishing campaign named Operation DoppelBrand has been targeting Fortune 500 companies, including Wells Fargo and USAA, between December 2025 and January 2026. The campaign, attributed to a financially motivated threat actor known as GS7, uses lookalike domains and cloned login portals to harvest credentials. The operation also deploys remote management tools for persistent access and monetizes compromised accounts. The infrastructure is highly automated, with over 150 domains identified, and targets major US financial institutions, investment firms, and technology brands.

    Show sources

Information Snippets