A sophisticated phishing campaign has emerged in Switzerland, specifically targeting Twint users through fake emails that urge recipients to verify their account details or risk being blocked. These emails direct victims to fraudulent websites designed to steal credit card information and personal data. The attackers exploit moments when users are likely to be distracted, such as early mornings or busy periods, and leverage the automatic nature of Twint payments to increase the scam's credibility. The campaign highlights a trend toward more personalized and behaviorally targeted phishing attacks, with additional concerns raised about the security of emerging technologies like household robots.
Simultaneously, security researchers report a fourfold increase in mobile phishing attacks during the holiday season, with attackers impersonating well-known brands, payment processors, and logistics providers. These campaigns not only target consumers but also pose risks to enterprises, as employees may inadvertently expose corporate credentials or install malware on BYOD or COPE devices. The multi-stage nature of these attacks, which follow users throughout the purchase and delivery process, makes detection challenging and increases the likelihood of financial fraud or data exfiltration. Organizations are advised to remain vigilant and implement robust security awareness and monitoring measures to mitigate these evolving threats.

Get the infrastructure and lures behind it.
1 event from the most recent confirmed update back to the earliest known activity.
A Zimperium report warned that mobile phishing attacks are expected to rise sharply during the holiday shopping season, with activity increasing fourfold and campaigns impersonating major retailers, payment services, digital wallets, and shipping providers. The report also highlighted enterprise risks from BYOD and COPE devices, including credential theft, mobile malware infections, financial fraud, and data exfiltration.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.