AI: Threat, tool, or both?

2026-06-07T20:51:52Z1f4aeaed3e155a9980ae38a407ccd86d53cf40807d6571ed8f4a44bb10c70fbe
account-takeoverai-abusecredential-theftdata-breachfake-invoicefake-softwareinfostealerkali365mac-malwaremfa-bypassmobile-malwarephishingscamssignal-phishingsocial-engineering

What happened

Malwarebytes Labs highlights an uptick in credential- and data-theft campaigns: infostealers are becoming the preferred phishing payload, phishing kits (notably Kali365) are bypassing MFA to seize long-term access to Microsoft accounts, and scammers deploy fake downloads (ChatGPT, BlueWallet), fake invoices, and spoofed takedown notices to harvest credentials and crypto. AI misuse and social-engineering enable account takeovers (e.g., Meta support bot handing over Instagram accounts), while backup- and recovery-key phishing targets Signal users. Several large data breaches and scam-focused new

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
1f4aeaed3e155a9980ae38a407ccd86d53cf40807d6571ed8f4a44bb10c70fbe
Enrichment time
2026-06-07T20:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.