35,000 Hacked by Multi-Stage Phishing Campaign Trick
Estimated reading time: 6 minutes
A recent multi-stage phishing campaign shows how cyberattacks are changing fast. In April 2026, attackers targeted over 35,000 users with fake HR emails. At first, the message looked normal. However, it led users into a carefully planned attack.
As a result, many people clicked the link and entered their details. Consequently, attackers gained access to their accounts.
In just two days, the attack affected over 13,000 organizations in 26 countries. Therefore, this case shows how fast and powerful modern phishing can be.
Why Multi-Step Phishing Attacks Are More Dangerous
Phishing is no longer simple. In the past, attackers used one fake login page. Now, however, they use many steps. A multi-stage phishing campaign guides users through a process. At each stage, the page looks safe. Because of this, users do not suspect danger.
In addition, these attacks look more real than before. For example, emails use proper design and clear language. As a result, users trust them more easily.
Also Read: Financial Literacy Topics for Students
How the Multi-Stage Phishing Campaign Worked
This attack followed a clear plan. First, attackers gained attention. Then, they built trust step by step.

Step 1: Multi-Stage Phishing Campaign using Fake HR Email
First, users received an email that looked like it came from HR. It mentioned a conduct issue. Because of this, users felt pressure to act quickly.
Step 2: PDF With a Link
Next, the email included a PDF file. It looked official. Inside, users found a link to review details. Therefore, many people clicked it without doubt.
Step 3: CAPTCHA Page
After that, the link opened a CAPTCHA page. On one hand, it blocked bots. On the other hand, it made the process feel secure.
Step 4: Multi-Stage Phishing Campaign using Fake Portal
Then, users saw a secure-looking page. It asked them to log in. At this point, the process seemed normal.
Step 5: Extra Verification
After logging in, users entered their email again. In addition, they solved another CAPTCHA. As a result, trust increased further.
Step 6: Fake Login Page
Finally, users reached a fake Microsoft login page. It looked real. Therefore, many users entered their credentials.
Why This Attack Worked So Well
There are several reasons for its success. First, the emails looked real. They used formal language and proper format. Therefore, users did not notice warning signs.
Second, the message created urgency. Because of this, users acted quickly without checking. Third, attackers used common tools like PDFs and CAPTCHAs. As a result, the process felt trustworthy.
Finally, each step built confidence. In other words, users felt safer as they moved forward.
What Is AiTM and Why It Matters
This multi-stage phishing campaign used a method called Adversary-in-the-Middle (AiTM). In this method, attackers sit between the user and the real website. When a user logs in, the request goes to the real site. Meanwhile, the attacker captures the session.
As a result, attackers can access the account without needing the password again. Therefore, this method is more dangerous than basic phishing.
How It Bypasses 2FA
Many users rely on two-factor authentication (2FA). Normally, it adds strong protection. However, this attack can still bypass it. This is because attackers steal the session after login.
So even if a user enters a code, the attacker can still gain access. Therefore, a Advanced phishing campaign remains a serious threat.
Scale of the Attack caused by Multi-Stage Phishing Campaign
This campaign reached a large number of users.
- 35,000+ users targeted
- 13,000+ organizations affected
- 26 countries involved
For example, healthcare and finance were major targets. This is because they store sensitive data. Meanwhile, tech companies were also affected.
The Role of Human Behavior
This attack worked because of human behavior. People trust messages from HR. In addition, they react quickly to urgent issues. Because of this, they often skip verification. Moreover, the steps felt normal. As a result, users believed the process was safe.
How Attackers Misused CAPTCHA
CAPTCHAs are meant to stop bots. However, attackers used them differently. On one hand, CAPTCHAs blocked security tools. On the other hand, they increased user trust.
How to Stay Safe from Multi-Stage Phishing Campaign

You can protect yourself by following these simple steps:
- Check emails carefully
Do not trust unexpected HR messages. Instead, verify them through official channels. - Check links before clicking
Make sure the website URL is correct and not a fake version. - Avoid opening unknown files
Even official-looking attachments can be harmful. - Use strong login methods
Choose safer options like passkeys or hardware security keys. - Pause before you act
Take a moment to think. In many cases, a short delay can stop an attack.
Career Opportunities in Cybersecurity
Attacks like this increase demand for cybersecurity experts. As a result, many job opportunities are available. For example:
- Security Analyst
- Ethical Hacker
- Malware Analyst
- Security Engineer
- Digital Forensics Expert
These roles help prevent a Advanced phishing campaign.
Skills You Need to Get Started
Students can start early. First, learn computer science basics. Then, focus on networking and coding. In addition, build problem-solving skills through math.
Also, understand human behavior. This helps you detect threats. Together, these skills help you stop a Advanced phishing campaign.
What the Future Looks Like
Cyberattacks will continue to evolve. Therefore, they will become more advanced.For example, attackers may use AI to improve their methods. Meanwhile, security systems will also improve.
However, awareness will remain important. By understanding a multi-stage phishing campaign, users can stay prepared.
Final Thoughts on Multi-Stage Phishing Campaign
This multi-stage phishing campaign shows how attackers combine technology and human behavior. They use trust, urgency, and familiar tools. As a result, many users fall for the attack.However, users can stay safe. By staying alert and careful, you can avoid such threats.
Frequently Asked Questions about Multi-Stage Phishing Campaign
A multi-stage phishing campaign is a type of cyberattack that uses several steps to trick users. Instead of one fake page, attackers guide users through multiple stages. As a result, each step builds trust and makes the attack harder to detect.
A multi-stage phishing campaign can bypass two-factor authentication by using techniques like Adversary-in-the-Middle (AiTM). In this method, attackers capture session data after login. Therefore, even if a user enters a verification code, the attacker can still access the account.
These attacks are more effective because they look realistic and follow a logical flow. For example, they use trusted elements like emails, PDFs, and CAPTCHAs. In addition, each step feels safe. As a result, users are less likely to question the process.
You can stay safe by following simple steps. First, verify unexpected emails before clicking links. Next, check website URLs carefully. Also, avoid opening unknown attachments. Most importantly, pause and think before taking action.
Reference:
- Team, M. D. S. R., & Intelligence, M. T. (2026, May 4). Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise. Microsoft Security Blog. https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/


1tg8ty