Massive Credential Theft Campaign Targets Over 35,000 Users Worldwide
In a recent cybersecurity alert, Microsoft revealed a large-scale phishing attack aimed at stealing user credentials. Spanning from April 14 to April 16, 2026, the attack impacted over 35,000 users across 13,000 organizations in 26 countries, predominantly in the U.S.
The attackers employed sophisticated email tactics, disguising their messages as legitimate internal communications related to code of conduct reviews. These emails created a sense of urgency, urging users to click on malicious links that led to credential harvesting sites capable of bypassing multi-factor authentication.
Sectors most affected included healthcare, financial services, and technology. To protect against such attacks, users are advised to verify email sources, avoid clicking on suspicious links, and enable multi-factor authentication whenever possible.
Risk Level: High – Given the scale and sophistication of this attack, vigilance is essential for all organizations and individuals.
Source: View Original Report
