started · updated
Cert.lv warns of Microsoft account exploits and CSDD phishing in Latvia
Cybersecurity institution Cert.lv has issued warnings regarding new fraudulent activities targeting users in Latvia. Attackers are exploiting the legitimate Microsoft 365 and Azure ‘device code’ authentication feature. This method, described as a form of phishing rather than a software vulnerability, involves an attacker generating a code that a user is tricked into authorizing on their own device, granting the attacker access to the account.
Additionally, Cert.lv reported a surge in fraudulent activities throughout August. This includes ongoing phishing campaigns impersonating the Road Traffic Safety Directorate (CSDD). Following a cyber incident at CSDD that compromised a significant amount of personal data for both individuals and legal entities, scammers have been using this information to send deceptive emails and SMS messages regarding alleged unpaid traffic fines or vehicle parking violations.