What's happening in email security: May 25 – May 31, 2026
Three things stood out this week. Scammers are already industrializing the 2026 World Cup with hundreds of fake FIFA sites, phishing found a new home inside AI assistants, and France drew a hard line on the tracking pixel that quietly sits in most marketing email. A busy end to the month, so let's get into it.
ChatGPhish turns a trusted AI answer into a phishing page
Permiso Security disclosed "ChatGPhish," a flaw in the way ChatGPT renders content from pages it summarizes. Because the response renderer trusts Markdown links and image URLs pulled from third-party pages, an attacker can inject fake security alerts and deceptive QR codes straight into ChatGPT's trusted interface. Malicious images even leak the victim's IP, user-agent, and referrer when fetched. The attack bypasses URL filters because the phishing arrives inside a tool the user already trusts. As teams wire AI assistants into daily work, that trusted interface becomes a phishing surface your email gateway never sees.
State actors are shipping AI-assisted malware faster
IRGC-linked Nimbus Manticore ran campaigns across the US, Europe, and the Middle East using career-opportunity and meeting-invite lures, delivering a MiniFast backdoor that researchers say shows signs of AI-assisted development. The lure hasn't changed. The build speed has.
France says tracking pixels need consent now
France's CNIL ruled that tracking pixels in marketing email require explicit user consent before deployment, with a binding compliance deadline of July 14, 2026. Italy's regulator followed with softer, non-binding best-practice guidance and a six-month window. Open tracking has run largely unchecked for years, and this closes the grey area for anyone emailing French and Italian recipients. If your email program relies on open rates from embedded pixels, this affects your measurement and your consent flows, not just your legal team's reading list.
GHOST STADIUM is building a fake World Cup, 300 domains at a time
An operation dubbed GHOST STADIUM has stood up more than 300 domains hosting pixel-perfect clones of the official FIFA site, aimed at fans across the UK, US, Canada, Mexico, Brazil, Germany, and beyond. Researchers also tracked 55-plus football-themed malvertising campaigns feeding into fake stores, fraudulent apps, and credential-harvesting pages. The goal is ticket fraud and account theft.
This is brand impersonation at industrial scale, and the timing is the point. Attackers pre-register hundreds of domains months ahead of a known event, then let search traffic and fan hype do the targeting for them. By the time the tournament kicks off, the fake ecosystem is already indexed and ranking. If you protect a brand that shows up in World Cup coverage, whether you're a sponsor, a payment provider, or a broadcaster, this is the season to watch new domain registrations closely and line up takedowns before the traffic peaks. Pair your DMARC work with active lookalike-domain monitoring, because that's the half of the impersonation problem your SPF and DKIM records were never designed to see.
The FBI's IC3 numbers are still landing
Fresh analysis of the 2025 report puts total cybercrime losses at $20.9 billion, with BEC alone at $3.04 billion across 24,768 complaints and phishing losses up 208% year over year. Red Sift's read of the data notes only 35% of Northeast US organizations have reached full DMARC enforcement. The attacks are getting more expensive per incident, not just more frequent.
- JINX-0164 lures crypto developers with fake recruiter profiles
A previously undocumented actor used credible fake LinkedIn recruiter profiles to lure crypto-firm developers to bogus teleconference apps that dropped a macOS infostealer, harvesting password managers, Keychain, SSH keys, and wallets.
- Kimsuky delivers a Rust backdoor via fake Cisco Webex invites
North Korea's Kimsuky delivered a Rust backdoor "likely developed using LLMs" through spoofed security-software pages and fake Cisco Webex invites.
- Signal users targeted for backup recovery keys
Fake "Signal Support" messages trick journalists and activists into handing over their 64-character recovery key, which unlocks full message history. Same support-impersonation pattern as email phishing, different channel.
- Dutch police dismantle the Asocks proxy botnet
Over 200 servers seized behind a residential-proxy service tied to 17 million infected devices. These proxies are what let phishing campaigns originate from clean residential IPs and slip past reputation filters.
- BlobPhish keeps its phishing page in memory
A campaign against Microsoft 365 and US financial institutions generates phishing pages inside the browser using blob objects, avoiding network signatures that gateways rely on.
Want email security news in your inbox every week?
Subscribe here and stay up to date with what's happening in email security.




