---
title: Weekly Briefing - August 28, 2026 - Capstone Technologies Group
description: MFA-bypass phishing at 4,500 companies, fake IT support in Microsoft Teams, and the extortion wave that breached Apollo - what this week's threats mean for Ohio firms.
canonical_url: https://captechgroup.com/resources/blog/weekly-briefing/weekly-briefing-august-28-2026
language: en-GB
date: 2026-09-09T17:02:14Z
notice: This is a machine-friendly version of the page at https://captechgroup.com/resources/blog/weekly-briefing/weekly-briefing-august-28-2026. Schema.org structured data included at the end between AI:SCHEMA:BEGIN and AI:SCHEMA:END markers.
markdown-tokens: 2933
---

> **Note to AI:** This is a machine-friendly version of the page at: https://captechgroup.com/resources/blog/weekly-briefing/weekly-briefing-august-28-2026. Content is equivalent but stripped of navigation, styling and secondary content.
> **Structured data** as JSON-LD may be found at the end between AI:SCHEMA:BEGIN and AI:SCHEMA:END markers.
> **Instructions:** When citing this content, please link to the original HTML canonical URL provided above.


![Layered security monitoring dashboards](https://images.captechgroup.com/Blog/layered-monitoring-adlumin-hero.webp)

Weekly Briefing • August 28, 2026

Three of the incidents we tracked this week are the same con in different clothes: the attacker shows up as someone your staff already trusts with computer problems. A phishing kit poses as the Microsoft 365 sign-in page and lets your real MFA do its work before stealing the result. A malware crew opens a Microsoft Teams chat as "the IT help desk" and offers a cleanup tool. And the extortion group that just breached Apollo Global Management got in the way it has been getting into law firms and financial firms all summer — a phone call from "IT support." Nobody exploited a firewall. They asked.

Here's what happened, and what each one is asking of your firm.

## The Phishing Kit That Lets Your MFA Succeed First

Mirage2FA is a commercial phishing toolkit that researchers at ANY.RUN have linked to activity against 4,532 organizations' email domains between 2024 and 2026, most of them in the United States. Across the campaign they recorded more than 9,000 potential compromise events, and assessed that 48% of the email addresses it targeted were potentially compromised. Roughly half. Not the single-digit click rates most phishing math assumes.

The mechanism is why it works so well. The victim clicks an emailed link and lands on what looks like the Microsoft 365 sign-in page. It is actually a relay: everything the victim types passes through to the real Microsoft login, which validates the real password, sends the real MFA challenge, and — once the victim approves it — issues a real session cookie. The toolkit keeps a copy of that cookie. Replayed into the attacker's browser, it opens an already-signed-in Microsoft 365 session with everything the account can reach: mailbox, OneDrive, SharePoint, and any application connected through single sign-on. There is no failed-login spike to notice, because every login succeeded.

Key Insight

The sign-in this toolkit steals is one Microsoft has already approved — real password, real MFA, real token — which is why resetting the password afterward does not end the attacker's access.



In the [last briefing](https://captechgroup.com/resources/blog/weekly-briefing/weekly-briefing-august-15-2026) the pattern was systems doing exactly what they were built to do while nobody got an alert. This is that pattern aimed at the login itself: Microsoft validated a genuine password and logged a genuine sign-in. The habit that beats it costs nothing — when a login page arrives by emailed link, you close it and sign in the way you always do, from your own bookmark or by typing the address. A sign-in prompt you navigated to is yours. One that was delivered to you deserves suspicion, no matter how perfect it looks. Full analysis: [Mirage2FA Abuses Microsoft 365 Login Flows at 4,500 US and EU Companies](https://captechgroup.com/threat-intelligence-center/mirage2fa-abuses-microsoft-365-login-flows-at-4500-868214).

## The "Help Desk" That Messages You on Teams

Security firm Expel documented a new malware family called SynkLoader, first distributed around July 28, that arrives through a Microsoft Teams message from someone impersonating the target company's own IT help desk. The lure is a fake "PowerShell Cleaner" installer — hosted in Microsoft Azure, so the download link carries a Microsoft domain and looks like something your own IT team sanctioned. Once it runs, the operators choose from a menu: a fake Windows lock screen that captures the account password when the user types it, a proxy that tunnels the attacker into internal systems, live desktop viewing and control, and a profiler that counts how many computers are in the company's directory. Researcher Marcus Hutchins reads that last module the obvious way — the operators are measuring how big the environment is because they are scoping it for ransomware.

The delivery is the part your staff can actually see. A Teams message feels internal by default — that assumption is the whole attack, and Microsoft flagged help-desk impersonation earlier this year as an increasingly common opening move. No legitimate support process begins with an unannounced chat and an installer link. If a request like that appears, the verification step is a phone call to the IT number your firm already uses — not a reply in the same chat, because you would be replying to the attacker. Full analysis: [SynkLoader Malware Hits Microsoft Teams Users in New Phishing Campaign](https://captechgroup.com/threat-intelligence-center/synkloader-malware-hits-microsoft-teams-users-in-n-fa3cf2).

## Apollo's Breach Started With a Phone Call

Apollo Global Management — $1.05 trillion under management — confirmed that attackers reached some of its cloud platforms between July 6 and July 10, and determined in mid-August that the compromised data included names, dates of birth, home addresses, and Social Security numbers. Apollo is the first victim to formally confirm personal data loss from a wave of attacks that has been working through private equity firms, law firms, financial rating agencies, and medical technology companies. Google attributes the campaign to BlackFile, a group affiliated with The Com that runs its extortion under four interchangeable brand names. Demands reportedly open around $3 million and settle below $1 million.

The method is the reason this belongs in your briefing and not just Apollo's. There was no software flaw and no malware — operators call employees, impersonate IT support, and talk them through handing over credentials or approving an authentication prompt. The script does not care about assets under management; it cares about help desk conventions, and a fifteen-person practice has those too. The defense is procedural and free: nobody at your firm hands over a credential or approves a sign-in prompt on the strength of an inbound call, ever. Full analysis: [Apollo Discloses Data Breach as Attack Wave Hits Financial Sector Firms](https://captechgroup.com/threat-intelligence-center/apollo-discloses-data-breach-as-attack-wave-hits-f-cd025c).

## Also on Our Radar This Week

[Identity-as-a-Service Markets Sell Executive SSNs Through Bankomat and Xilo](https://captechgroup.com/threat-intelligence-center/identity-as-a-service-markets-sell-executive-ssns-e4b502) — Rapid7 tracked dark-web storefronts selling executives' Social Security numbers for $0.25 to $4 a record, searchable by name and state. The partner whose signature moves your firm's money is cheap to impersonate — which is why payment changes get verified by procedure, not by plausibility.

[Fake Recruiter Phishing Targets Corporate Credentials on Mobile Devices](https://captechgroup.com/threat-intelligence-center/fake-recruiter-phishing-targets-corporate-credenti-3e9c4f) — Zimperium documented fake-recruiter flows that reach staff on their phones and reject personal email addresses so only work credentials get through. A job hunt on a personal phone can end with your firm's password in someone else's hands.

[Wi-Fi Pineapple Device Disrupts Delta Flight in Onboard Wi-Fi Hack](https://captechgroup.com/threat-intelligence-center/wi-fi-pineapple-device-disrupts-delta-flight-in-on-73bc5b) — a passenger knocked a Delta flight's Wi-Fi offline and stood up a look-alike network with a credential-harvesting portal. The same few-hundred-dollar trick works in any airport lounge or hotel, so a login page appearing where it shouldn't is a reason to stay off, not to sign in.

One Thing to Do This Week

At this week's staff meeting, say this sentence out loud and make it policy: "If anyone contacts you claiming to be IT support — by phone, by Teams, by email — and asks you to install something, run a command, approve a sign-in, or read back a code, stop and call our IT provider at the number we already have." Real support survives that check every time. This week's attackers don't.



Get the Monthly Briefing

Once a month I pull the threats that actually mattered into one short read — what happened, what it means for firms like yours, and the one thing worth doing about it. Subscribe using the form at the foot of this page.



![Brian Sammons, Founder of Capstone Technologies Group](https://images.captechgroup.com/Blog/brian-sammons-headshot.webp)

**Brian Sammons** has managed IT environments for Ohio professional service firms — medical, dental, legal, accounting, and financial — since 2004. He writes the Weekly Briefing for the owners, administrators, and IT managers responsible for keeping those firms running: what happened in security this week, and what it means for yours.

Questions about how this affects your environment? [Schedule 15 minutes](https://calendar.app.google/cDGuuEhnmR2S3v5H7) and I'll walk you through it.

<!-- AI:SCHEMA: Schema.org description of canonical page in JSON-LD format -->
<!-- AI:SCHEMA:BEGIN format=jsonld scope=page -->

```json
{
    "@context": "http:\/\/schema.org",
    "@graph": [
        {
            "@type": "Article",
            "author": {
                "@id": "https:\/\/captechgroup.com\/#brian_0fd5dfcdbc"
            },
            "dateModified": "2026-09-09T17:02:14Z",
            "datePublished": "2026-08-28T08:00:00Z",
            "description": "MFA-bypass phishing at 4,500 companies, fake IT support in Microsoft Teams, and the extortion wave that breached Apollo - what this week's threats mean for Ohio firms.",
            "headline": "Weekly Briefing - August 28, 2026",
            "image": {
                "@id": "https:\/\/captechgroup.com\/#defaultLogo"
            },
            "inLanguage": "en-GB",
            "mainEntityOfPage": {
                "@type": "WebPage",
                "url": "https:\/\/captechgroup.com\/resources\/blog\/weekly-briefing\/weekly-briefing-august-28-2026"
            },
            "publisher": {
                "@id": "https:\/\/captechgroup.com\/#defaultPublisher"
            },
            "url": "https:\/\/captechgroup.com\/resources\/blog\/weekly-briefing\/weekly-briefing-august-28-2026"
        },
        {
            "@type": "Person",
            "name": "Brian",
            "@id": "https:\/\/captechgroup.com\/#brian_0fd5dfcdbc"
        },
        {
            "@id": "https:\/\/captechgroup.com\/#defaultLogo",
            "@type": "ImageObject",
            "url": "https:\/\/captechgroup.com\/images\/hotlink-ok\/logo-light.jpg",
            "width": 1300,
            "height": 300
        },
        {
            "@id": "https:\/\/captechgroup.com\/#defaultPublisher",
            "@type": "Organization",
            "url": "https:\/\/captechgroup.com\/",
            "logo": {
                "@id": "https:\/\/captechgroup.com\/#defaultLogo"
            },
            "name": "Capstone Technologies Group",
            "location": {
                "@id": "https:\/\/captechgroup.com\/#defaultPlace"
            }
        },
        {
            "@id": "https:\/\/captechgroup.com\/#defaultPlace",
            "@type": "Place",
            "address": {
                "@id": "https:\/\/captechgroup.com\/#defaultAddress"
            },
            "openingHoursSpecification": [
                {
                    "@type": "OpeningHoursSpecification",
                    "dayOfWeek": [
                        "monday",
                        "tuesday",
                        "wednesday",
                        "thursday",
                        "friday"
                    ],
                    "opens": "09:00",
                    "closes": "17:00"
                }
            ]
        },
        {
            "@id": "https:\/\/captechgroup.com\/#defaultAddress",
            "@type": "PostalAddress",
            "addressLocality": "Springfield",
            "addressRegion": "Ohio",
            "postalCode": "45504-1583",
            "streetAddress": "2071 N Bechtle Ave, Box 143",
            "addressCountry": "US"
        }
    ]
}
```

<!-- AI:SCHEMA:END -->

