Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Pink Group Uses Vishing to Steal Cloud Passwords

Pink Group Uses Vishing to Steal Cloud Passwords

Posted on June 8, 2026 By CWS

A newly identified cyber extortion group known as Pink is posing a significant threat to enterprises by employing social engineering tactics to acquire cloud storage credentials and sensitive information. This group, under the cluster code CL-CRI-1147, unveiled its data leak platform on May 31, 2026, already affecting multiple organizations.

Pink Group’s Tactics and Operations

Pink distinguishes itself by opting for non-traditional methods such as voice phishing, commonly referred to as vishing, to infiltrate corporate networks. By impersonating internal IT personnel, they trick employees into visiting phishing sites controlled by attackers, leading to unintentional disclosure of login credentials and multi-factor authentication codes. This human-centric approach makes Pink particularly dangerous as it leverages trust rather than exploiting technical flaws.

Analysts from Unit 42 have documented the group’s activities, revealing affiliations with the wider Com network, a community known for aggressive social engineering efforts. Pink shares operational similarities with other notorious cybercriminal groups like Lapsus$, Scattered Spider, and ShinyHunters, suggesting a common tactical framework.

Execution and Impact of Pink’s Attacks

Once access is gained, Pink swiftly exploits Microsoft’s internal automation tools to commandeer cloud storage environments, exfiltrating data from OneDrive and SharePoint in mere minutes. Following data acquisition, the group uses compromised accounts to send urgent payment demands via Microsoft Teams and emails, imposing a 72-hour deadline to heighten the sense of urgency and legitimacy.

The group may also represent a rebranding of a previous operation, with Google’s Threat Intelligence Group suggesting links to the now-defunct BlackFile, which briefly operated as Redact. Such rebranding strategies are common among advanced extortion operations seeking to evade detection.

Defensive Measures Against Pink

The effectiveness of Pink’s strategies lies in their ability to bypass standard security measures. By utilizing legitimate employee accounts and Microsoft’s tools, their activities often go unnoticed by firewalls and endpoint detection systems. They direct victims to phishing domains like passkeydeploy.com, capturing session cookies and circumventing MFA without needing passwords again.

To combat such threats, security experts recommend a people-first approach. Organizations should train employees to independently verify unexpected IT calls and exercise caution when asked to enter credentials. Implementing phishing-resistant authentication methods like FIDO2 hardware keys, monitoring unusual file downloads, and blocking known phishing domains linked to Pink’s infrastructure are critical steps in enhancing security.

Additionally, deploying behavioral monitoring tools to detect large data transfers can help prevent potential breaches before data leaves the network.

Conclusion

As Pink continues to evade traditional detection mechanisms, organizations must adopt comprehensive security strategies combining human vigilance with advanced technical defenses. By staying informed and proactive, enterprises can better protect themselves against this evolving threat.

Cyber Security News Tags:cloud security, cloud storage, cyber threat, Cybersecurity, data protection, data theft, enterprise security, Extortion, IT security, MFA, Phishing, Pink hacking group, security training, social engineering, Vishing

Post navigation

Previous Post: A Security Secures $37M for Advanced Cyber Defense
Next Post: Meta Thwarts NSO Group’s WhatsApp Phishing Scheme

Related Posts

New Clickfix Attack Exploits finger.exe Tool to Trick Users into Execute Malicious Code New Clickfix Attack Exploits finger.exe Tool to Trick Users into Execute Malicious Code Cyber Security News
Authorities Dismantle IoT Botnets Behind Massive DDoS Attacks Authorities Dismantle IoT Botnets Behind Massive DDoS Attacks Cyber Security News
How IOC Feeds Streamline Response and Threat Hunting for Best SOC Teams  How IOC Feeds Streamline Response and Threat Hunting for Best SOC Teams  Cyber Security News
Addressing SOC False Negatives with Interactive Analysis Addressing SOC False Negatives with Interactive Analysis Cyber Security News
Ghost CMS Vulnerability Exploited in Widespread Malware Attack Ghost CMS Vulnerability Exploited in Widespread Malware Attack Cyber Security News
Critical Redis Flaws Expose Systems to Remote Attacks Critical Redis Flaws Expose Systems to Remote Attacks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Anthropic Calls for Unified AI Development Pause Amid Risks
  • Meta Thwarts NSO Group’s WhatsApp Phishing Scheme
  • Pink Group Uses Vishing to Steal Cloud Passwords
  • A Security Secures $37M for Advanced Cyber Defense
  • Critical Linux Kernel Flaw Allows Root Privilege Escalation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Anthropic Calls for Unified AI Development Pause Amid Risks
  • Meta Thwarts NSO Group’s WhatsApp Phishing Scheme
  • Pink Group Uses Vishing to Steal Cloud Passwords
  • A Security Secures $37M for Advanced Cyber Defense
  • Critical Linux Kernel Flaw Allows Root Privilege Escalation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark