Microsoft Uncovers Phishing Attack on 35,000 WordPress Users

Date:

Massive Credential Theft Campaign Targets Over 35,000 Users Worldwide

In a recent cybersecurity alert, Microsoft revealed a large-scale phishing attack aimed at stealing user credentials. Spanning from April 14 to April 16, 2026, the attack impacted over 35,000 users across 13,000 organizations in 26 countries, predominantly in the U.S.

The attackers employed sophisticated email tactics, disguising their messages as legitimate internal communications related to code of conduct reviews. These emails created a sense of urgency, urging users to click on malicious links that led to credential harvesting sites capable of bypassing multi-factor authentication.

Sectors most affected included healthcare, financial services, and technology. To protect against such attacks, users are advised to verify email sources, avoid clicking on suspicious links, and enable multi-factor authentication whenever possible.

Risk Level: High – Given the scale and sophistication of this attack, vigilance is essential for all organizations and individuals.

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

Critical PHP Object Injection Vulnerability Found in GiveWP Plugin

A recently discovered vulnerability in the GiveWP plugin poses...

AI Advances Strengthen Cybersecurity: Wordfence Unveils Critical Vulnerability Discovery

Wordfence has revealed significant advancements in its incorporation of...

Critical Unauthenticated Account Takeover Vulnerability Found in TranslatePress Plugin

On August 11, 2026, a significant security vulnerability was...

Hackers Target WordPress Sites in miniOrange Authentication Bypass Attacks

In recent weeks, hackers have escalated their attacks on...