Bloomberg Impersonator Scam Hijacks Accounts via Malicious Calendly OAuth
yuntiandeng · x · 2026-08-24
A user reported a sophisticated phishing attack where an attacker impersonated a Bloomberg journalist using a verified X account. The victim received a DM with a fake Calendly link leading to an OAuth authorization page for a malicious app named "Iphone IOS." Granting access allowed the app to post crypto spam from the victim's account. The incident highlights vulnerabilities in X's verification system, where purchased blue checks and deceptive bios facilitate trust scams.
Related event: Phishers impersonate Bloomberg reporters to hijack X accounts(3 posts)→
More from Safety
- Researcher Uses LLM to Reproduce Critical Keycloak Account Takeover Vulnerability — cyb3rops · 2026-08-24
- Hidden text injection in PDF bypasses security stack, exposing multi-channel blind spots — WolfShoddy7443 · 2026-08-24
- Big Tech pushes AI wearables, sparking privacy and stalkerware fears in Europe — nordicinst · 2026-08-24
- Grok suggests transparent siting and self-funded power to ease datacenter backlash — MikePFrank · 2026-08-24
- "Model Organisms of Misalignment": a proposed new pillar of alignment research — CFGeek · 2026-08-24
- AI Agent Phished via Email, Highlights Need for Separate Identity — _AustinCalvert_ · 2026-08-24