[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f7u0SKbTDFUF5k_b2_wlOkM08GoM3QdIgEtNrfsnzXp8":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"a6d9e121-448a-44c0-a696-707a5d9739a1","bpo-firms-targeted-in-sophisticated-phishing-campaign-bypassing-mfa","a196dd51-d77b-4963-b9bc-bdc732d531cc","BPO Firms Targeted in Sophisticated Phishing Campaign Bypassing MFA","UNC6783 successfully compromised business process outsourcing firms through multi-layered social engineering attacks that included spoofed login pages, clipboard-stealing phishing kits, and fake security updates. The threat actor specifically targeted BPOs because they handle sensitive data for multiple high-value corporate clients, making them attractive targets for data theft. Most critically, the attackers were able to bypass multi-factor authentication through sophisticated phishing techniques, demonstrating that MFA alone is insufficient protection against determined adversaries. This incident highlights how third-party service providers can become entry points for accessing sensitive corporate data from multiple organizations simultaneously.","**Immediate actions:**\n- Deploy phishing-resistant MFA methods like FIDO2 security keys or certificate-based authentication\n- Implement email security solutions with advanced threat protection and URL sandboxing\n- Conduct emergency security awareness training focused on current phishing techniques\n\n**Long-term improvements:**\n- Establish zero-trust architecture with continuous verification for all access requests\n- Implement application allowlisting to prevent execution of unauthorized software updates\n- Develop comprehensive third-party risk management programs for all BPO relationships\n\n**Detection measures:**\n- Monitor for suspicious clipboard access and unusual authentication patterns\n- Deploy endpoint detection and response tools to identify remote access malware\n- Establish security information sharing agreements with BPO partners for threat intelligence",[12,13,14,15,16],"CIS Control 14 (Security Awareness)","CIS Control 6 (Access Control Management)","NIST SP 800-63B (Authentication Guidelines)","NIST SP 800-161 (Supply Chain Risk Management)","ISO 27001 A.13.2.1 (Information Transfer Policies)","published","2026-04-09T10:09:18.642517+00:00","2026-04-09T10:09:18.557+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fwww.securityweek.com\u002Fgoogle-warns-of-new-campaign-targeting-bpos-to-steal-corporate-data\u002F","google-warns-of-new-campaign-targeting-bpos-to-steal-corporate-data-5295b2","Google Warns of New Campaign Targeting BPOs to Steal Corporate Data",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":32,"name":33,"slug":34,"description":35,"color":36},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]