Cybersecurity · Monday, 10 August 2026
01 · Briefing · what happened
Attackers stopped fighting the locks and started calling the people who hold the keys
A wave of fresh reporting shows the same shift - the fastest-growing break-ins skip the software and target the person, talking victims into pasting a command, approving a fake login, or trusting a familiar voice.
1,500%
rise in fake-login phishing
device-code attacks in 2026
89%
of scam sites live under 2 days
too fast for block-lists
$1.1bn
lost to cross-border fraud
over 1,500 Interpol-tracked cases
$289
a month for a phishing kit
Greatness, sold on Telegram
At a glance
- Device-code phishing (approving the attacker's login on a real Microsoft page) is up 1,500% in 2026; phone scams have doubled.
- For the first time, tricked and stolen logins beat software flaws as the top way ransomware crews first break in.
- ClickFix attacks show a fake error and get the victim to paste a command that installs the malware themselves.
- Rent-a-kit services (Greatness at $289/month, Kali365, DOUBLECUP) now sell these tricks to anyone.
- A Buffalo mother got a 20-minute call from a deepfake of her sobbing teenage son; the fix is a family code word.
- Cheap AI is the accelerant: it writes the lures, clones the voices, and spins up throwaway scam sites in minutes.
Forces in play
tricked logins now the top ransomware entry point, ahead of software flaws
Greatness, Kali365, DOUBLECUP sell the tricks to anyone by subscription
writes convincing lures, clones voices, outruns block-lists
simple defenses spread: code words, callbacks, never-paste-a-command
How it unfolded
- Sept 2025 deepfake-voice call fakes a mother's teenage son
- Early June DOUBLECUP rent-a-tool ClickFix service goes live
- This week reports show fake-login phishing up 1,500%, logins now the top break-in
- Next watch whether passkeys and phishing-resistant logins spread faster than the kits
Where this points
Watch whether passkeys and phishing-resistant logins spread to everyday accounts faster than the rent-a-kit services can sell around them.
Full briefing
The numbers this week all point one way. Device-code phishing is up 1,500% in 2026, and phone scams (vishing) have doubled
The victim runs the malware
The clearest example is “ClickFix.” A web page shows a fake error or a “prove you’re human” check. Then it tells you to copy a line of text and paste it into your computer’s command window to fix it. You do it, and you just installed the malware yourself.
A new Russian rent-a-tool service called DOUBLECUP has run since early June
Approving a login you didn’t start
The second move gets you to hand over the login itself. Phishing kits sold as a service now do this on a subscription. Greatness costs about $289 a month over a Telegram channel with more than 3,250 subscribers
Others sit invisibly in the middle. In a campaign researchers call “Payroll Pirates,” voicemail-themed emails lead to a decoy page
The familiar voice
The oldest lever is the phone. Elizabeth Benz, a mother in Buffalo, got a call in September 2025
The AI accelerant
Cheap AI is what turned these from craft into industry. It writes convincing scam emails and spins up throwaway phishing sites faster than any block-list can keep up. Some 89% of phishing web addresses now live under two days
What it means for you
The through-line is calm, not scary: the attack needs your cooperation, so slowing down defeats most of it. Never paste a command a website tells you to. Treat any urgent message as a reason to stop and check, not act. A login prompt you didn’t start, a frantic call from family, an invoice due right now: verify each through a channel you already trust, not the one it arrived on. A code word, a callback to a known number, a passkey instead of a typed password: each puts a second, human check between the attacker and the door.
02 · Lesson · why it matters
The exploit isn't in the code. It's in you.
A lock is only as strong as the person you can talk into opening it, and this week the attackers are talking.
How it works
- The lock (the software) is too hard to pick
- So the attacker targets the person holding the key
- Urgency and a trusted face lower the person's guard
- The victim pastes, approves, or tells, and opens the door
- A second, out-of-band check is what breaks the spell
The twist
The strongest technical lock doesn't matter if you can talk the person with the key into opening the door; trust, urgency, and authority are the real levers.
Where you've seen this
Con artists
pose as a bank or the tax office to rush you into paying
Tailgating a door
carry a box, look busy, and someone holds the badge-locked door open
Fake IT support
a caller claiming to be help desk talks you into a password reset
The catch
No single check is foolproof; the defense is a habit of pausing under urgency and verifying through a channel the attacker doesn't control.
Full lesson
The cheapest way past a wall is a person standing at the gate
For thirty years, security was mostly a contest between engineers. Attackers found flaws in software; defenders patched them. Both sides got good at it. So good, in fact, that breaking modern software has become expensive and slow.
So the attackers stopped trying. This week the reporting says it plainly: for the first time, tricked and stolen logins have passed software flaws as the top way ransomware crews get in. The wall got taller, so they walked up to the gate and asked the guard to open it.
That is social engineering, and it is not a technical trick at all. It is a trick on a human being. The password page is genuine. The multi-factor prompt is real. The login portal belongs to Microsoft. Every piece of the machine is working exactly as designed. The one part that fails is the person, because a person was persuaded.
Three levers, and you carry all three
The people who do this well are not typing furiously in a dark room. They are pulling on three levers that every human comes with.
The first is trust. We are built to believe familiar things. A page that looks like SharePoint, an email that seems to come from a service you use, a voice that sounds like your child. When a mother in Buffalo heard her son sobbing on the phone last year, she wasn’t foolish for believing it. The voice was cloned from a few seconds of audio, and her whole body told her it was real.
The second is urgency. A frantic call. An invoice due today. A login that will “expire in ten minutes.” Urgency does something specific to us: it switches off the slow, careful part of the mind and hands the wheel to the fast, reacting part. You cannot check a story you have been given no time to check. That is the point.
The third is authority. A caller who says they are from IT. An email carrying a company logo. A prompt that wears the face of a system you are told to obey. We are trained our whole lives to do what the badge says, and attackers wear the badge.
The machine never has to break
Look at how neatly this sidesteps everything we built. “ClickFix” shows you a fake error and asks you to paste a line of text to fix it. You paste it, and you have installed the malware with your own hands. No flaw was exploited, because you did the work. A phishing kit sits invisibly between you and the real login. You type your password and your one-time code straight through it, both surrendered in the moment you thought you were being careful.
The antivirus saw nothing wrong, because nothing was technically wrong. You were not hacked. You were convinced. This is why the strongest lock in the world protects nothing if the person holding the key can be reached. And everyone can be reached, because trust, urgency, and authority are not bugs to be patched. They are how humans function.
You are inside this, not above it
It is tempting to read all this and think: I would never fall for it. That thought is itself the vulnerability. The mother in Buffalo was not careless. The employee who approves the fake login is often the diligent one, trying to clear a task quickly. The attack is designed to catch you precisely when you are moving fast and trying to be helpful - which is most of the time, for most of us.
And it reaches far past the person who clicks. When one worker’s login opens the door, the salaries of their colleagues get rerouted, the customer records leak, the hospital’s systems lock. The chain runs from a single tired human at 4pm straight into thousands of lives that person will never meet. You are a node in that web whether you asked to be or not.
The one move that breaks the spell
There is a defense, and it is almost embarrassingly simple: a second channel the attacker does not control. Not the number in the email - the number you already had. Not the link in the message - the app you open yourself. A family code word, so a cloned voice hits a question the machine can’t answer. A callback to a colleague before the payment goes out.
None of it is clever. It works because the whole attack depends on you deciding in the moment, on the attacker’s terms, at the attacker’s speed. The moment you step out of the conversation and check somewhere else, the spell needs a fact it never had. Slowing down is not caution for its own sake. Under pressure, it is the entire defense - and a workplace where “let me check first” is safe, not annoying, is worth more than any wall.
03 · Lab · your turn
Trust or Verify
Rehearse spotting a social-engineering attempt and feel how stepping out to a second channel defeats it, while acting on the sender's terms gets you breached.
04 · Hope · carry this
The same trick that clones a voice can't touch the code word your family shares. The oldest defenses, checking with each other and slowing down, still outrun the newest machines.
More from Cybersecurity