< Back to all clusters
[TECHNOLOGY] · Czechia, Slovakia, Slovenia, Australia · 3 sources

started · updated

Cybersecurity experts warn of rising phishing and NFC-based mobile payment fraud

Cybersecurity researchers have identified evolving threats involving sophisticated phishing techniques and specialized malware. According to Cisco Talos, phishing has become a primary entry point for corporate network breaches, increasing from one-third of incidents in the first quarter of 2026 to over half in the second quarter.

New tactics include the use of malicious QR codes embedded in tailored PDF documents and the rise of ‘Phishing-as-a-Service’ platforms like ARToken. These platforms provide attackers with APIs to steal authentication tokens, access emails, and exfiltrate data from SharePoint. Notably, attackers are increasingly successful at bypassing multi-factor authentication (MFA), with failure rates rising from 35% to 65%.

Separately, Group-IB has identified a targeted malware campaign named ‘WindRelay’ affecting Eastern Europe, including the Czech Republic, Slovakia, and Slovenia. In these highly personalized attacks, criminals pose as bank employees to convince victims to install malware based on the SpyNote RAT. Once installed, the malware transforms the victim's Android smartphone into a fraudulent payment terminal capable of capturing contactless card data via NFC relay.

Entities

Cisco Talos · SpyNote