The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Construction
Breach intelligence, attack campaigns, and threat reports targeting the Construction sector.
Explore Other Sectors
Construction Threat Reports
EvilTokens Exposed: How Storm-2992's AI-Powered PhaaS Bypassed MFA at Scale
EvilTokens emerged in February 2026 as a sophisticated phishing-as-a-service (PhaaS) platform operated by threat actor Storm-2992, compromising over 12,000 inboxes across 10,000+ organizations worldwide. The platform exploited OAuth device code authentication flows through AI-powered phishing campaigns, enabling cybercriminals to bypass multifactor authentication and steal authentication tokens at scale. EvilTokens featured 44 customizable phishing templates, automated AI assistants for crafting targeted lures, and multi-stage delivery pipelines designed to evade traditional email security controls. This incident highlights the industrialization of token-based attacks as organizations increasingly adopt MFA, forcing threat actors to evolve beyond credential theft toward authentication bypass techniques that exploit legitimate OAuth flows and cloud service integrations.
2 days ago
Kill Chain
EvilTokens PhaaS Platform Disrupted After Compromising 12,000 Microsoft Accounts
In September 2026, Microsoft's Digital Crimes Unit successfully disrupted the EvilTokens phishing-as-a-service platform that had compromised over 12,000 Microsoft accounts across 10,000+ organizations since February 2026. The platform specialized in device-code phishing attacks that bypassed multi-factor authentication by abusing OAuth 2.0 device authorization flows, targeting wholesale distribution, construction, financial services, healthcare, and education sectors. Two suspected administrators were arrested in the UK, though the threat remains active with affiliates creating clone platforms. This incident highlights the escalating sophistication of phishing-as-a-service operations and the growing threat of device-code authentication abuse, which has seen a 37x surge in attacks as cybercriminals adopt AI-powered tools for enhanced targeting and evasion.
2 days ago
Kill Chain
EvilTokens Takedown: How AI Transformed Phishing-as-a-Service in 2026
In September 2026, Microsoft coordinated a global takedown of EvilTokens, a sophisticated phishing-as-a-service platform that leveraged artificial intelligence throughout its attack chain. The Storm-2992 threat group operated this commercial cybercrime service, which exploited OAuth 2.0 device authorization flows to compromise over 12,000 email inboxes across 10,000 organizations worldwide. EvilTokens featured an AI-powered chatbot that analyzed victim inboxes to identify trusted relationships and recommend fraud strategies, significantly lowering the technical barriers for business email compromise attacks. The platform generated approximately $1.1 million in revenue and targeted organizations across wholesale distribution, construction, financial services, healthcare, and education sectors. This incident highlights the dangerous convergence of AI technology with cybercrime infrastructure, demonstrating how threat actors are weaponizing artificial intelligence to automate and scale sophisticated social engineering attacks at an unprecedented level.
2 days ago
Kill Chain
PREY-0058: How Vishing Attacks Are Bypassing Microsoft 365 Security
Arctic Wolf identified PREY-0058, a widespread data theft and extortion campaign targeting Microsoft 365 and SaaS platforms through sophisticated vishing attacks. The threat actors impersonate IT help desk personnel, directing executives to fraudulent authentication pages that harvest credentials and MFA tokens via adversary-in-the-middle techniques. Using residential proxy infrastructure like NodeMaven, attackers perform session replay attacks to access SharePoint, OneDrive, Exchange, and Box for mass data exfiltration before issuing extortion demands. The campaign primarily targets directors and executives across construction, healthcare, finance, and professional services sectors. This incident highlights the growing sophistication of identity-based attacks that bypass traditional security controls. As organizations increasingly rely on cloud services and remote access, vishing campaigns exploiting human factors and legitimate authentication flows represent a critical threat vector requiring enhanced user education and phishing-resistant authentication measures.
2 weeks ago
Kill Chain
Industrial Automation Under Siege: Q2 2026 Threat Landscape Analysis
In Q2 2026, Kaspersky's industrial threat landscape report revealed a significant shift in cybersecurity threats targeting industrial control systems (ICS), with malicious objects blocked on 19.15% of ICS computers—the lowest level since 2022. The report identified 10,904 different malware families affecting industrial automation systems, with malicious scripts and phishing pages leading threat categories at 5.42% globally. Notable regional variations emerged, with Africa showing the highest attack rates at 27.9% while Northern Europe recorded the lowest at 8.1%. The biometrics sector faced the most severe threats at 26.44%, experiencing increases across multiple threat vectors including ransomware, spyware, and malicious documents. This trend reflects the evolving sophistication of threat actors targeting critical infrastructure, coinciding with increased adoption of cloud-native industrial systems and the expansion of attack surfaces through IoT integration. The data highlights growing concerns around industrial cybersecurity as nation-state actors and cybercriminal groups increasingly focus on operational technology environments.
4 weeks ago
Kill Chain
Bearlyfy's Custom GenieLocker Ransomware: A New Threat to Russian Enterprises
In March 2026, the pro-Ukrainian hacking group Bearlyfy, also known as Labubu, launched over 70 cyberattacks against Russian companies, primarily targeting the manufacturing sector. The group deployed a custom-built Windows ransomware strain named GenieLocker, marking a significant evolution from their previous use of third-party encryptors like LockBit 3 and Babuk. These attacks involved exploiting external services and vulnerable applications to gain access, followed by the deployment of tools such as MeshAgent for remote access and encryption. Ransom demands escalated to hundreds of thousands of dollars, with approximately 20% of victims reportedly paying. ([thehackernews.com](https://thehackernews.com/2026/03/bearlyfy-hits-70-russian-firms-with.html?utm_source=openai)) This incident underscores the increasing sophistication and boldness of hacktivist groups in leveraging custom malware to achieve both financial gain and strategic sabotage. The development and deployment of proprietary ransomware like GenieLocker highlight a trend where threat actors are investing in bespoke tools to enhance their operational effectiveness and evade detection. ([thehackernews.com](https://thehackernews.com/2026/03/bearlyfy-hits-70-russian-firms-with.html?utm_source=openai))
1 month ago
Kill Chain
Critical Vulnerabilities Discovered in Johnson Controls' C-CURE 9000 and Victor Application Servers
In July 2026, multiple critical vulnerabilities were identified in Johnson Controls' C-CURE 9000 and Victor application servers, widely used in physical security management. These vulnerabilities, including CVE-2026-21655, CVE-2026-21653, and CVE-2026-34496, could allow unauthenticated attackers to execute arbitrary code, perform server-side request forgery, and escalate privileges, potentially compromising physical security systems and sensitive data. ([johnsoncontrols.com](https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories?utm_source=openai)) The discovery of these vulnerabilities underscores the increasing targeting of critical infrastructure by cyber threats. Organizations must prioritize patching and implementing robust security measures to protect against such exploits, as the exploitation of these flaws could lead to significant operational disruptions and security breaches.
2 months ago
Kill Chain
Ransomware Surge in 2026: Understanding the 25% Increase and Its Implications
Between April 2025 and March 2026, ransomware incidents surged by 25%, with 7,551 known victims worldwide. This escalation was driven by the emergence of over 60 new ransomware groups and a significant increase in attacks targeting small and medium-sized businesses (SMBs). Notably, the Qilin ransomware group experienced a 443% year-over-year increase in activity, operating across more than 50 countries. The manufacturing sector remained the top target, accounting for 1,660 victims. ([gbhackers.com](https://gbhackers.com/2026-ransomware-report/?utm_source=openai)) This trend underscores the evolving threat landscape, where ransomware groups are becoming more operationalized, and the barriers to entry are lowering. Organizations must enhance their cybersecurity measures, focusing on patching known vulnerabilities, strengthening vendor oversight, and preparing for AI-driven threats. ([mbtmag.com](https://www.mbtmag.com/cybersecurity/news/22970998/report-addresses-evolving-state-of-ransomware?utm_source=openai))
2 months ago
Kill Chain
FBI Issues Warning on Fake Permit Fee Phishing Scam
In March 2026, the FBI issued a public alert regarding a sophisticated phishing campaign where cybercriminals impersonated city and county planning officials to defraud property owners. By leveraging publicly accessible permit records, these actors sent emails to individuals with active applications, demanding payments for fictitious permit fees via wire transfers, peer-to-peer transfers, or cryptocurrency. The emails were meticulously crafted, incorporating real permit details to enhance credibility, leading victims to authorize payments that bypassed traditional fraud detection mechanisms. This scheme resulted in significant financial losses and highlighted vulnerabilities in existing payment verification processes. The urgency of this issue is underscored by the rapid escalation of government impersonation scams, which nearly doubled in reported losses to approximately $798 million in 2025. The increasing sophistication of these attacks, particularly their ability to exploit publicly available data and evade standard fraud detection systems, necessitates immediate attention and the development of more robust security measures to protect individuals and businesses from such fraudulent activities.
2 months ago
Kill Chain
Iranian Hackers Target U.S. Industrial Control Systems in 2026
In early 2026, Iranian state-sponsored hackers launched a series of cyberattacks targeting U.S. critical infrastructure, focusing on industrial control systems (ICS) such as Rockwell Automation's Allen-Bradley programmable logic controllers (PLCs). These attacks exploited vulnerabilities in internet-exposed devices, leading to operational disruptions and potential safety hazards across sectors like water treatment and energy. ([nextgov.com](https://www.nextgov.com/cybersecurity/2026/04/pro-iran-hackers-are-targeting-us-industrial-control-systems-advisory-says/412679/?oref=ng-homepage-river&utm_source=openai)) This incident underscores the escalating threat landscape for ICS environments, highlighting the urgent need for organizations to secure operational technology assets against sophisticated nation-state actors. ([cybersecuritydive.com](https://www.cybersecuritydive.com/news/critical-infrastucture-plcs-iran-hacking-censys/817209/?utm_source=openai))
2 months ago
Kill Chain
Kubota Data Breach 2026: A Wake-Up Call for Industrial Cybersecurity
In early 2026, Kubota North America Corporation experienced a significant data breach where unauthorized actors accessed its network systems from March 16 to April 20. The intrusion led to the exposure of sensitive personal information belonging to employees and their dependents, including full names, Social Security numbers, dates of birth, taxpayer IDs, driver's license numbers, direct deposit bank account details, corporate payment card information, and benefits enrollment data. Kubota has since notified affected individuals and offered identity protection services to mitigate potential risks. This incident underscores the escalating threat landscape targeting industrial manufacturers, emphasizing the critical need for robust cybersecurity measures. The breach highlights the importance of proactive security protocols and continuous monitoring to safeguard sensitive employee data against unauthorized access and potential misuse.
2 months ago
Kill Chain
ARToken: The Next Evolution in BEC-as-a-Service Platforms
In April 2026, Cisco Talos identified ARToken, a sophisticated phishing platform linked to the EvilTokens phishing-as-a-service operation. ARToken is designed to bypass multi-factor authentication and compromise Microsoft 365 accounts, featuring advanced capabilities such as inbox rule manipulation and shared access links. The platform employs a seven-layer anti-analysis system to evade detection, and its phishing lures are highly targeted, often impersonating legitimate vendor communications to deceive accounts-payable staff into processing fraudulent invoices. The emergence of ARToken underscores a significant evolution in business email compromise (BEC) tactics, highlighting the increasing sophistication and accessibility of phishing-as-a-service platforms. This development poses a heightened risk to organizations, emphasizing the need for enhanced email security measures and employee vigilance against such targeted attacks.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports