The Growing Threat of Phishing Kits and Account Takeovers

According to a recent report from The Hacker News, cybercriminals are now using cheap, ready-made phishing kits and OAuth traps to break into business accounts at scale. The report highlights attacks that impersonate IT support over Microsoft Teams, target CEOs with fake document-sharing lures, and abuse old Dropbox links to steal credentials.

What makes these attacks so dangerous is how normal they look. A message from "IT" asking you to approve a remote session. A shared file that appears to come from a colleague. A simple request to click "Allow" on a trusted app. Attackers don't need to break down the door when someone inside opens it for them.

Why These Attacks Work on Even Savvy Teams

The shift to "phishing-as-a-service" means anyone can buy a sophisticated attack kit for a few hundred dollars. Services like BlueKit, mentioned in the report, offer browser-in-the-middle tools that bypass multi-factor authentication. This lowers the barrier for criminals and makes professional-grade phishing available to anyone with a credit card.

Another pattern in the report is how attackers abuse legitimate tools. They use Microsoft Teams, ScreenConnect, and Dropbox to blend in. Employees trust these platforms, so they let their guard down. The attackers also target OAuth permissions — when you click "Allow" on a third-party app, you may be handing over access to your email, files, or calendar without realising the risk.

For Australian businesses, the message is clear: the old advice of "don't click suspicious links" is no longer enough. Attackers now use trusted channels and impersonate real people. A call from "IT support" could be a criminal trying to install remote access software on your computer.

What This Means for Australian SMBs

Small and mid-sized Australian businesses are prime targets because they often lack dedicated cybersecurity teams. They rely on cloud tools like Microsoft 365, Dropbox, and Google Workspace — exactly the platforms being exploited. A single compromised account can lead to data theft, ransomware, or a costly business interruption.

Many Australian SMBs also use external IT support providers. The report shows attackers impersonating help desk staff, which makes it even harder for employees to tell what's real. Without proper verification procedures, a quick "Teams call from IT" could be the start of a serious breach.

What You Can Do Now

  • Verify every IT support request — If someone calls or messages claiming to be from IT, hang up and call your support team back using a known number. Never approve remote access from an unsolicited request.
  • Review OAuth app permissions regularly — Check which third-party apps have access to your Microsoft 365 or Google Workspace accounts. Remove any you don't recognise or no longer use.
  • Enable strong multi-factor authentication — Use app-based authenticators or hardware keys rather than SMS. MFA is not foolproof, but it stops many basic attacks.
  • Train staff to spot phishing attempts — Run short, regular sessions on how to identify fake login pages, unusual file-sharing requests, and social engineering tricks. Practice with simulated phishing tests.
  • Limit admin and high-privilege accounts — Only give employees the permissions they need for their job. This limits the damage if an account is compromised.

At MS&VG, we help Australian SMBs build practical cybersecurity defences that match their risk and budget — from staff training to cloud security reviews. Contact us to discuss how we can protect your business from these evolving threats.