Daylila

Cybersecurity · Monday, 10 August 2026

01 · Briefing · what happened

Attackers stopped fighting the locks and started calling the people who hold the keys

Cybersecurity 4 min 14 sources

A wave of fresh reporting shows the same shift - the fastest-growing break-ins skip the software and target the person, talking victims into pasting a command, approving a fake login, or trusting a familiar voice.

1,500%

rise in fake-login phishing

device-code attacks in 2026

89%

of scam sites live under 2 days

too fast for block-lists

$1.1bn

lost to cross-border fraud

over 1,500 Interpol-tracked cases

$289

a month for a phishing kit

Greatness, sold on Telegram

At a glance

  • Device-code phishing (approving the attacker's login on a real Microsoft page) is up 1,500% in 2026; phone scams have doubled.
  • For the first time, tricked and stolen logins beat software flaws as the top way ransomware crews first break in.
  • ClickFix attacks show a fake error and get the victim to paste a command that installs the malware themselves.
  • Rent-a-kit services (Greatness at $289/month, Kali365, DOUBLECUP) now sell these tricks to anyone.
  • A Buffalo mother got a 20-minute call from a deepfake of her sobbing teenage son; the fix is a family code word.
  • Cheap AI is the accelerant: it writes the lures, clones the voices, and spins up throwaway scam sites in minutes.

Forces in play

Attacks on people High

tricked logins now the top ransomware entry point, ahead of software flaws

Rent-a-scam kits Building

Greatness, Kali365, DOUBLECUP sell the tricks to anyone by subscription

AI as accelerant High

writes convincing lures, clones voices, outruns block-lists

Human awareness Easing

simple defenses spread: code words, callbacks, never-paste-a-command

In play Phishing-kit sellers — rent ready-made attacks by the month Microsoft researchers — warn: never paste a command a website hands you Interpol — AI-fueled fraud 4.5x more profitable than the old way Elizabeth Benz — Buffalo mother targeted by a deepfake-voice call

How it unfolded

  1. Sept 2025 deepfake-voice call fakes a mother's teenage son
  2. Early June DOUBLECUP rent-a-tool ClickFix service goes live
  3. This week reports show fake-login phishing up 1,500%, logins now the top break-in
  4. Next watch whether passkeys and phishing-resistant logins spread faster than the kits

Where this points

Watch whether passkeys and phishing-resistant logins spread to everyday accounts faster than the rent-a-kit services can sell around them.

Full briefing

The numbers this week all point one way. Device-code phishing is up 1,500% in 2026, and phone scams (vishing) have doubled [1]. The trick gets you to approve the attacker’s own login on a real Microsoft page. For the first time, stolen and tricked logins have overtaken software flaws as the leading way ransomware crews first get in [2]. The lock still works. The attacker just talks the person holding the key into opening the door.

The victim runs the malware

The clearest example is “ClickFix.” A web page shows a fake error or a “prove you’re human” check. Then it tells you to copy a line of text and paste it into your computer’s command window to fix it. You do it, and you just installed the malware yourself.

A new Russian rent-a-tool service called DOUBLECUP has run since early June [3]. It hides its code inside ordinary-looking images cached by the browser, then delivers a loader and a remote-control program to Windows and Mac [3]. Researchers have counted more than 250 ClickFix websites that fingerprint your browser to dodge scanners; a Mac version ends in a stealer that drains crypto wallets [4]. The step that makes it work never changes: the site asks the human to paste a command, and the human does. Microsoft’s advice is blunt: never follow any website, pop-up, or chat that tells you to paste text into your Terminal [4]. Fake Adobe and Zoom “updates,” pushed by phishing emails, run the same play to install remote-access software [12].

Approving a login you didn’t start

The second move gets you to hand over the login itself. Phishing kits sold as a service now do this on a subscription. Greatness costs about $289 a month over a Telegram channel with more than 3,250 subscribers [5]. It steals passwords and the second-step codes together, and reaches Microsoft 365, iCloud, Yahoo, and Google [5]. A kit called Kali365 shows a fake SharePoint or DocuSign page [7]. It then bounces you to Microsoft’s real login and asks you to type in a code the attacker supplied. Approve it, and they hold your account.

Others sit invisibly in the middle. In a campaign researchers call “Payroll Pirates,” voicemail-themed emails lead to a decoy page [8]. The page quietly relays everything to the genuine Microsoft login, capturing the password and the multi-factor code as you type. Then it reroutes people’s salary payments [8]. One phishing service impersonated the calling platform RingCentral so convincingly that a fake “sender verified” banner was added to lower the reader’s guard [6].

The familiar voice

The oldest lever is the phone. Elizabeth Benz, a mother in Buffalo, got a call in September 2025 [9]. It sounded exactly like her sobbing 16-year-old son. A stranger then took over the line for 20 minutes [9]. The voice was a deepfake, cloned from a few seconds of audio. Security researchers now push a low-tech defense: a family code word only your real people know [9]. A machine can copy your voice, but not what’s inside your head.

The AI accelerant

Cheap AI is what turned these from craft into industry. It writes convincing scam emails and spins up throwaway phishing sites faster than any block-list can keep up. Some 89% of phishing web addresses now live under two days [11]. Interpol says AI-fueled fraud is 4.5 times more profitable than the old way [14]. More than 1,500 cross-border fraud cases have cost victims $1.1 billion [14]. Scam kits can now defeat “take a selfie to verify” checks with deepfaked video [14]. In Africa, Interpol reckons AI already drives over half of cybercrime, most of it aimed at victims in Europe and North America [10]. Even a Russian state group is now stealing Microsoft logins through booby-trapped hotel Wi-Fi rather than breaking the software [13].

What it means for you

The through-line is calm, not scary: the attack needs your cooperation, so slowing down defeats most of it. Never paste a command a website tells you to. Treat any urgent message as a reason to stop and check, not act. A login prompt you didn’t start, a frantic call from family, an invoice due right now: verify each through a channel you already trust, not the one it arrived on. A code word, a callback to a known number, a passkey instead of a typed password: each puts a second, human check between the attacker and the door.

02 · Lesson · why it matters

The exploit isn't in the code. It's in you.

A lock is only as strong as the person you can talk into opening it, and this week the attackers are talking.

How it works

  1. The lock (the software) is too hard to pick
  2. So the attacker targets the person holding the key
  3. Urgency and a trusted face lower the person's guard
  4. The victim pastes, approves, or tells, and opens the door
  5. A second, out-of-band check is what breaks the spell

The twist

The strongest technical lock doesn't matter if you can talk the person with the key into opening the door; trust, urgency, and authority are the real levers.

Where you've seen this

Con artists

pose as a bank or the tax office to rush you into paying

Tailgating a door

carry a box, look busy, and someone holds the badge-locked door open

Fake IT support

a caller claiming to be help desk talks you into a password reset

The catch

No single check is foolproof; the defense is a habit of pausing under urgency and verifying through a channel the attacker doesn't control.

Full lesson

The cheapest way past a wall is a person standing at the gate

For thirty years, security was mostly a contest between engineers. Attackers found flaws in software; defenders patched them. Both sides got good at it. So good, in fact, that breaking modern software has become expensive and slow.

So the attackers stopped trying. This week the reporting says it plainly: for the first time, tricked and stolen logins have passed software flaws as the top way ransomware crews get in. The wall got taller, so they walked up to the gate and asked the guard to open it.

That is social engineering, and it is not a technical trick at all. It is a trick on a human being. The password page is genuine. The multi-factor prompt is real. The login portal belongs to Microsoft. Every piece of the machine is working exactly as designed. The one part that fails is the person, because a person was persuaded.

Three levers, and you carry all three

The people who do this well are not typing furiously in a dark room. They are pulling on three levers that every human comes with.

The first is trust. We are built to believe familiar things. A page that looks like SharePoint, an email that seems to come from a service you use, a voice that sounds like your child. When a mother in Buffalo heard her son sobbing on the phone last year, she wasn’t foolish for believing it. The voice was cloned from a few seconds of audio, and her whole body told her it was real.

The second is urgency. A frantic call. An invoice due today. A login that will “expire in ten minutes.” Urgency does something specific to us: it switches off the slow, careful part of the mind and hands the wheel to the fast, reacting part. You cannot check a story you have been given no time to check. That is the point.

The third is authority. A caller who says they are from IT. An email carrying a company logo. A prompt that wears the face of a system you are told to obey. We are trained our whole lives to do what the badge says, and attackers wear the badge.

The machine never has to break

Look at how neatly this sidesteps everything we built. “ClickFix” shows you a fake error and asks you to paste a line of text to fix it. You paste it, and you have installed the malware with your own hands. No flaw was exploited, because you did the work. A phishing kit sits invisibly between you and the real login. You type your password and your one-time code straight through it, both surrendered in the moment you thought you were being careful.

The antivirus saw nothing wrong, because nothing was technically wrong. You were not hacked. You were convinced. This is why the strongest lock in the world protects nothing if the person holding the key can be reached. And everyone can be reached, because trust, urgency, and authority are not bugs to be patched. They are how humans function.

You are inside this, not above it

It is tempting to read all this and think: I would never fall for it. That thought is itself the vulnerability. The mother in Buffalo was not careless. The employee who approves the fake login is often the diligent one, trying to clear a task quickly. The attack is designed to catch you precisely when you are moving fast and trying to be helpful - which is most of the time, for most of us.

And it reaches far past the person who clicks. When one worker’s login opens the door, the salaries of their colleagues get rerouted, the customer records leak, the hospital’s systems lock. The chain runs from a single tired human at 4pm straight into thousands of lives that person will never meet. You are a node in that web whether you asked to be or not.

The one move that breaks the spell

There is a defense, and it is almost embarrassingly simple: a second channel the attacker does not control. Not the number in the email - the number you already had. Not the link in the message - the app you open yourself. A family code word, so a cloned voice hits a question the machine can’t answer. A callback to a colleague before the payment goes out.

None of it is clever. It works because the whole attack depends on you deciding in the moment, on the attacker’s terms, at the attacker’s speed. The moment you step out of the conversation and check somewhere else, the spell needs a fact it never had. Slowing down is not caution for its own sake. Under pressure, it is the entire defense - and a workplace where “let me check first” is safe, not annoying, is worth more than any wall.

03 · Lab · your turn

Trust or Verify

Rehearse spotting a social-engineering attempt and feel how stepping out to a second channel defeats it, while acting on the sender's terms gets you breached.

04 · Hope · carry this

The same trick that clones a voice can't touch the code word your family shares. The oldest defenses, checking with each other and slowing down, still outrun the newest machines.

Across the beats