Researchers at a major cybersecurity firm say they have identified a large-scale phishing campaign targeting employees at financial institutions across multiple countries.
The attackers reportedly used convincing replicas of internal login pages, harvesting credentials before redirecting victims to legitimate sites to avoid raising suspicion.
Several of the affected institutions have already reset employee credentials and rolled out additional multi-factor authentication requirements in response.
Security experts recommend that organizations review email filtering rules and run refresher phishing-awareness training in light of the campaign.