Moneycontrol PRO
Black Friday Sale
Black Friday Sale
HomeTechnologyNew LinkedIn phishing scam uses fake board invitations to steal your work passwords

New LinkedIn phishing scam uses fake board invitations to steal your work passwords

Unlike traditional phishing emails, this attack unfolds entirely within LinkedIn’s messaging system, making it more convincing and harder to detect.

November 05, 2025 / 07:31 IST
LinkedIn

A new phishing campaign is targeting LinkedIn users, specifically senior finance professionals, through fake executive board offers designed to steal Microsoft login credentials. Unlike traditional phishing emails, this attack unfolds entirely within LinkedIn’s messaging system, making it more convincing and harder to detect.

The campaign was uncovered by cybersecurity firm Push Security, which recently intercepted and blocked one of these high-risk attempts.

How the LinkedIn phishing scam works

Victims are first contacted via LinkedIn direct message by what appears to be a legitimate executive or recruiter. The message extends a formal invitation to join the “Executive Board of the Commonwealth Investment Fund,” a supposedly prestigious venture capital initiative linked to a fictional asset management firm named “AMCO.”

The message reads: “I'm excited to extend an exclusive invitation for you to join the Executive Board of the Commonwealth Investment Fund in South America, in partnership with AMCO — our asset management branch, a bold new venture capital fund launching in the region.”

The offer appears lucrative and credible, encouraging recipients to review an attached “proposal” document to proceed. However, clicking the link triggers a series of redirects — starting with a Google Search result, then to an attacker-controlled website, and finally to a landing page hosted on firebasestorage.googleapis[.]com.

Once there, victims are prompted to open a document via Microsoft, which leads them to a realistic fake Microsoft login page built using an adversary-in-the-middle (AiTM) setup. Any credentials entered on this page are instantly captured by the attacker.

Push Security noted that the attackers use CAPTCHA and Cloudflare Turnstile verification tools to block automated scans by cybersecurity bots — allowing their phishing pages to evade detection.

The company warned that this reflects a broader trend: phishing campaigns are increasingly moving away from email to professional social platforms like LinkedIn, where targets are more trusting and less suspicious.

“Just because the attack happens over LinkedIn doesn’t lessen the impact,” Push Security said. “These are corporate credentials being targeted. Taking over a Microsoft or Google account can have severe consequences, exposing sensitive data and any linked applications accessed via single sign-on.”

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Ayush Mukherjee
first published: Nov 5, 2025 07:30 am

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347