← Back to feed
PhishingEmerging1 sourceAug 11, 2026 · 05:52via Cyber Security News

New Phishing Attack Uses SSL/TLS Certificates to Target Customers of High-Value Brands via WhatsApp

Brief

A new phishing attack is using web certificates and chosen web addresses to target customers of high-value brands through WhatsApp. The activity is designed to make fraudulent pages look normal at a glance, turning a familiar security signal into part of the deception.

The campaign relies on fake sites with lookalike names. A message can steer a recipient from WhatsApp to a sign-in page resembling a service they know, where passwords, verification details, or other account information may be collected.

Clandestine researchers identified activated phishing and interface-cloning infrastructure aimed primarily at WhatsApp and Instagram.

The certificates were issued on August 10, 2026, suggesting the supporting sites were recently prepared for a new social-engineering wave.

Read more on Cyber Security News