Threat actors are increasingly achieving initial access through identity compromise rather than software exploitation, with infostealer malware and phishing infrastructure supplying large volumes of valid credentials for automated login attempts against enterprise authentication front doors. Defused Cyber reported a large-scale credential-stuffing campaign targeting F5 BIG-IP and other SSO-adjacent services (including ADFS, STS, and OWA), where honeypots observed high-confidence corporate email/password pairs being submitted at scale from 219.75.254.166 (OPTAGE Inc., Japan). Correlation against Hudson Rock’s infostealer telemetry indicated the majority of observed credentials were harvested from infostealer-infected employee endpoints, suggesting a pipeline from endpoint infection to external SSO gateway intrusion attempts impacting major enterprises and public-sector entities.
In parallel, Datadog Security Labs documented the evolution of the 1Phish kit into an operationally mature, MFA-aware phishing framework targeting 1Password users, shifting from simple credential capture to multi-stage workflows that explicitly collect 2FA codes—consistent with real-time authentication attempts even without confirmed reverse-proxy session hijacking. Broader incident-response telemetry in Sophos’ Active Adversary Report reinforces the same trend: identity-related techniques (compromised credentials, brute force, phishing) accounted for a majority of observed root causes, and attackers often pivot quickly to Active Directory after initial access. A separate finance-sector “2026” threat landscape post is largely high-level and does not add specific, verifiable details to the infostealer/SSO or 1Phish activity described elsewhere.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-24, Whiteintel’s Intelligence Division published research finding that infostealer infections can lead to stolen corporate credentials being exposed or sold on dark web markets in less than 48 hours. The report highlighted unmanaged-device infections as a major enterprise blind spot, linked infostealer activity to credential-based intrusions used by ransomware operators, and noted continued activity from strains including Lumma, StealC, and RedLine.
On 2026-02-27, Sophos' Active Adversary Report 2026 was published, summarizing trends from 661 cases across 70 countries. It highlighted identity compromise as the leading initial access vector and found generative AI was mainly increasing the speed and scale of phishing and social engineering rather than creating fundamentally new attack methods.
As of Datadog's 2026-02-27 report, 1Password said it was aware of the phishing campaign, had been monitoring it, and was pursuing takedowns of lookalike sites. The company also advised users to avoid unsolicited email links and only enter credentials on verified 1Password domains.
On 2026-02-27, Datadog Security Labs published a technical deep dive identifying four distinct 1Phish kit versions, culminating in a REST API-driven build with session management, internationalization, enterprise targeting, and recovery-code harvesting. The report concluded the activity reflects an actively maintained phishing kit with shared artifacts and reused infrastructure across multiple domains.
Subsequent analysis published on 2026-02-27 tied 54 of 70 observed email-password pairs from the SSO brute-forcing campaign to Hudson Rock infostealer infection records. The same credentials were also used against ADFS, STS, and OWA, and the attack infrastructure was linked to a compromised Fortinet FortiGate-60E device.
On 2026-02-23, Defused Cyber publicly reported large-scale login attempts against corporate SSO edge infrastructure, especially F5 BIG-IP interfaces, from IP address 219.75.254.166. Their honeypots showed the campaign was using apparently valid corporate usernames and passwords rather than exploiting software flaws.
By February 2026, analysis showed 1Phish had evolved through multiple versions into a more advanced phishing kit with browser and device fingerprinting, bot filtering, staged workflows, and explicit collection of one-time passcodes. The changes indicated an actively maintained framework designed to support real-time authentication abuse rather than simple credential theft alone.
From 2024-11-01 to 2025-10-31, Sophos analyzed 661 incident response and MDR cases and found identity-related techniques such as compromised credentials, brute force, and phishing accounted for 67% of identified initial access root causes. The report also found attackers reached Active Directory in a median of 3.4 hours and that ransomware encryption and exfiltration often occurred outside business hours.
In October 2025, Malwarebytes publicly reported phishing activity impersonating 1Password, describing breach-themed email lures and typosquatted domains used to steal credentials. This reflects early public documentation of the 1Phish campaign.
In September 2025, the 1Phish phishing kit was operating as a relatively simple credential-harvesting campaign using fake 1Password login pages. The activity targeted 1Password users via lookalike infrastructure and early-stage phishing workflows.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcesecuritylabs.datadoghq.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.