Find notable cyber news and cases, enriched with sources, timelines, and signals.

CSuite phishing exposure concentrates in the United States and key sectors

Trend
First reported
Last updated
Happening score
H score 28
1 unique sources, 1 articles

Summary

Hide ▲

A US-concentrated CSuite phishing pattern is spreading across 351 sandbox analyses, raising the risk of Microsoft 365 compromise and broader business access across exposed organizations. 51% of related submissions came from the United States, while technology, manufacturing, government, and consulting organizations were the most exposed sectors. Activity also appeared in India and several other countries, showing a wider but uneven exposure footprint.

Related Happenings

CSuite phishing campaign stealing Microsoft 365 sessions and deploying remote-access tools

Campaign
H score30 First: 30.09.2026 13:45 Last: 30.09.2026 13:45 Sources 1

How related: ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States.

About this happening: The CSuite phishing campaign is stealing Microsoft 365 sessions and deploying ScreenConnect or Action1, creating paths to account takeover, endpoint control, and b...

RMM phishing campaign spanning 46 countries

Campaign
H score30 First: 03.09.2026 14:58 Last: 03.09.2026 14:58 Sources 1

About this happening: A rotating RMM phishing campaign now spans 46 countries, increasing the risk of unauthorized remote-access installation and making detection harder. The United States...

Mirage2FA Microsoft 365 phishing-as-a-service campaign

Campaign
H score53 First: 25.08.2026 14:56 Last: 25.08.2026 14:56 Sources 1

About this happening: The Mirage2FA phishing-as-a-service campaign is actively targeting Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication, pu...

Timeline

  1. 30.09.2026 13:45 2 articles · 2h ago

    CSuite phishing reaches U.S. organizations and high-value sectors

    Campaign Scope Update

    ANY.RUN researchers traced CSuite phishing across 351 sandbox analyses and found that 51% of related submissions came from the United States. The same activity also appeared in India, the Philippines, Australia, the United Kingdom, Canada, and other countries, with technology, manufacturing, government and administration, and consulting organizations among the most exposed. The campaign’s business-themed lures can escalate into Microsoft 365 session theft and remote-access tool deployment such as ScreenConnect or Action1, widening exposure from account compromise to endpoint access.

    Show sources