WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts (TLP:CLEAR) FBI Releases Multiple Alerts on Credential Theft and Evolving Ransomware Intrusion Techniques
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

(TLP:CLEAR) FBI Releases Multiple Alerts on Credential Theft and Evolving Ransomware Intrusion Techniques

TLP:CLEAR

Author: Chase Snow

Created: Thursday, May 28, 2026 - 15:56

Categories: Cybersecurity, Federal & State Resources, Security Preparedness

Summary: The FBI recently released two cyber FLASH reports and a Public Service Announcement (PSA) highlighting evolving tactics used by cyber threat actors to gain access to victim environments, bypass authentication protections, conduct social engineering campaigns, and support ransomware-related intrusions. The reports address the use of phishing-as-a-service (PhaaS) platforms targeting Microsoft 365 accounts, as well as social engineering schemes involving threat actors impersonating IT personnel. Ransomware actors are also using anonymization infrastructure to conduct reconnaissance and compromise victim systems.

Analyst Note: Collectively, the reports reinforce ongoing concerns regarding credential theft, remote access abuse, identity-focused attacks, and the increasing use of legitimate services and tools to evade detection. The FBI FLASH reports in particular contain relevant information mapping threat actor tactics to the MITRE ATT&CK® framework and include indicators of compromise (IOCs) useful for members’ defense efforts. WaterISAC encourages members to review the reports which can help utilities understand and defend against current tactics used by threat actors.

Original Sources:

  • FBI FLASH: Silent Ransom Group Impersonating IT Personnel through Social Engineering
  • FBI FLASH: “First VPN Service” Used by Ransomware Actors to Compromise Systems
  • FBI PSA: Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokens

Additional Reading:

  • Ransomware Resilience – Understanding Ransomware Behaviors and the Typical Ransomware Attack Chain

Related WaterISAC PIRs: 6, 7, 7.1, 10, 10.1, 10.2, 12

Related Resources

(TLP:CLEAR) WaterISAC’s Quarterly Water Sector Incident Summary, January to March 2026 – Executive Summary

Jun 23, 2026 in Cybersecurity, Intelligence, Physical Security
Members Only

(TLP:AMBER) WaterISAC’s Quarterly Water Sector Incident Summary, January to March 2026

Jun 23, 2026 in Cybersecurity, Intelligence, Physical Security
Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated June 18, 2026)

Jun 18, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar