Microsoft Uncovers Phishing Attack on 35,000 WordPress Users

Date:

Massive Credential Theft Campaign Targets Over 35,000 Users Worldwide

In a recent cybersecurity alert, Microsoft revealed a large-scale phishing attack aimed at stealing user credentials. Spanning from April 14 to April 16, 2026, the attack impacted over 35,000 users across 13,000 organizations in 26 countries, predominantly in the U.S.

The attackers employed sophisticated email tactics, disguising their messages as legitimate internal communications related to code of conduct reviews. These emails created a sense of urgency, urging users to click on malicious links that led to credential harvesting sites capable of bypassing multi-factor authentication.

Sectors most affected included healthcare, financial services, and technology. To protect against such attacks, users are advised to verify email sources, avoid clicking on suspicious links, and enable multi-factor authentication whenever possible.

Risk Level: High – Given the scale and sophistication of this attack, vigilance is essential for all organizations and individuals.

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

WPScan 4.0.0: Critical XSS Vulnerability Exposed!

WordPress Vulnerability Report: WPScan 4.0.0 Released Introduction The latest version of...

119 Edge Extensions: Malware Disguised as Useful Tools

Cybersecurity Alert: Malware Infiltrates Popular Browser Extensions A recent malware...

200K WordPress Sites Face XSS Risk from Burst Statistics Plugin

Critical Vulnerability Discovered in Burst Statistics Plugin for WordPress On...

Foxconn Cyberattack: Nitrogen Ransomware Strikes WordPress Sites

Cyberattack Hits Foxconn: Major Data Breach Reported Foxconn, the largest...