Signal users targeted in backup-stealing phishing attacks

2026-05-29T20:51:52Z599667392f19daa284c03bfc3bc9d932483198c266ae26d48e9dc8b3eac8d660
backup-key-theftchromeclickfixclickjackingcredential-theftdata-breachdeno-ratfake-download-sitefox-tempestghost-cmshealthcare-breachmalwaremalware-signingmfa-bypassmicrosoft-defenderphishingphishing-kitsecure-bootshinyhunterssignalsoftware-vulnerabilitiessupply-chain

What happened

Malwarebytes Labs roundup (May 2026) covering multiple active threats and large breaches: phishing campaigns targeting Signal users to steal backup recovery keys; Carnival hit by a ShinyHunters data breach affecting ~6 million people; a major healthcare vendor breach exposing biometrics, diagnoses, and bank details (~1.8M affected). Multiple active phishing and malware campaigns—fake ChatGPT download sites delivering Windows and macOS malware, Kali365 phishing kit that bypasses MFA to steal Microsoft/Outlook/Teams/OneDrive access, LinkedIn credential theft using abused Adobe Target, and fake/G

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
599667392f19daa284c03bfc3bc9d932483198c266ae26d48e9dc8b3eac8d660
Enrichment time
2026-05-29T20:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Signal users targeted in backup-stealing phishing attacks · Baitaphish