Two new briefings target attacks that start with a phone call, not an email. The first is a call from “IT” asking you to share your screen. The second is a caller who already knows your name, role, and account. Silent Ransom Group uses the first to steal client files from law firms. ShinyHunters used the second to breach McKesson through employee Okta accounts.
What’s new
- Fake IT calls targeting legal teams (Silent Ransom Group): A briefing for legal teams on the campaign the FBI and Google have warned about. It covers the full sequence, from a vague “invoice” email to a call asking you to install AnyDesk or Zoho Assist. It also covers the in-person version, where someone shows up to “image” your laptop.
- McKesson vishing breach: A briefing on how ShinyHunters talked their way into Okta accounts and reached Salesforce and Snowflake. It covers why vishing works when there’s no suspicious link to spot.
Why it matters
Law firms are targeted for their client data, and investigators have seen the whole attack happen in a single business day. The habit that stops it: hang up, verify through a known channel, and never install anything a caller asks for.
One compromised account can open the door to an entire network. This briefing reduces every unexpected call to one rule: a familiar voice doesn’t make a request legitimate. Verify, then report.
How to access it: These briefings are available in the Fable content catalog. Navigate to the Catalog in the Fable platform to find and deploy them.