Signal users targeted in backup-stealing phishing attacks
2026-05-29T20:51:52Z•599667392f19daa284c03bfc3bc9d932483198c266ae26d48e9dc8b3eac8d660
backup-key-theftchromeclickfixclickjackingcredential-theftdata-breachdeno-ratfake-download-sitefox-tempestghost-cmshealthcare-breachmalwaremalware-signingmfa-bypassmicrosoft-defenderphishingphishing-kitsecure-bootshinyhunterssignalsoftware-vulnerabilitiessupply-chain
What happened
Malwarebytes Labs roundup (May 2026) covering multiple active threats and large breaches: phishing campaigns targeting Signal users to steal backup recovery keys; Carnival hit by a ShinyHunters data breach affecting ~6 million people; a major healthcare vendor breach exposing biometrics, diagnoses, and bank details (~1.8M affected). Multiple active phishing and malware campaigns—fake ChatGPT download sites delivering Windows and macOS malware, Kali365 phishing kit that bypasses MFA to steal Microsoft/Outlook/Teams/OneDrive access, LinkedIn credential theft using abused Adobe Target, and fake/G
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- 599667392f19daa284c03bfc3bc9d932483198c266ae26d48e9dc8b3eac8d660
- Enrichment time
- 2026-05-29T20:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.