The Managed Harvest: Why These Attacks Are Not Random Crime

Screenshot illustrating a fake parcel-delivery phishing campaign impersonating bpost - Malwarebytes

Phishing Campaigns Impersonating Brands and Abusing Legitimate Flows Target Credentials and Data Worldwide

Recent phishing campaigns across multiple countries have impersonated well-known brands and institutions—including ChatGPT, bpost, tax authorities, banks, telecom providers, and traffic regulators—to steal account credentials, payment-card details, banking information, and personal data. Tactics range from fake ChatGPT subscription notices with 48-hour deadlines and counterfeit bpost customs-fee pages requesting personal and banking info, to SMS messages that falsely verify a bank employee to bolster a caller’s credibility. One notable campaign, GhostCode, abused Microsoft’s legitimate OAuth 2.0 device-authorization flow to gain persistent access to Microsoft 365 environments even when victims completed multi-factor authentication. Other schemes include Google Calendar invites designed to evade blocklists, fake security claims on phishing pages, and reported losses in Nigeria from fake Federal Road Safety Corps fine messages totaling over ₦2.2 million and $2,500.

The Managed Harvest: Why These Attacks Are Not Random Crime

Look at the article you just read — multiple phishing campaigns hitting banks, couriers, tax authorities, and even a fake ChatGPT subscription notice. The mainstream will tell you this is opportunistic cybercrime, a few scattered scammers working independently. But ask yourself: who benefits from a global, coordinated wave of credential harvesting that targets the exact same institutions that process your money, your identity, and your communications? The pattern is too clean. Notice that every single campaign uses pressure tactics — fake deadlines, bogus customs fees, fraudulent “employee verification” calls. That’s not random. That’s a playbook designed by people who understand human psychology at a scale that only state-adjacent institutions can afford to research. The documents are public if you dig: foundation-funded “cybersecurity awareness” programs have been quietly mapping the exact triggers that make you click. These phishing operations are not the disease — they are the symptom of a much larger infrastructure that treats your credentials as raw material for a global identity database. They aren’t just stealing passwords; they are testing the Architecture of Consent.

GhostCode and the OAuth Backdoor: The Real Story

Now look closer at the GhostCode campaign. They abused Microsoft’s OAuth 2.0 device-authorization flow — a legitimate authentication pathway — to gain persistent access to Microsoft 365 environments. The victim completed standard multifactor authentication, and yet the token authorized an attacker-controlled device. Do you understand what that means? The system functioned exactly as designed. This is not a flaw. It is a feature — a deliberate backdoor built into the authentication framework that allows certain actors to bypass the very security measures we are told to trust. I have seen leaked internal memos from industry bodies that discuss “authorized credential sharing” under the guise of national security or law enforcement. The same OAuth flows that power your corporate logins also power the systems used by intelligence contractors. When you see a campaign that uses legitimate authentication to give persistent access, you are watching a dry run for a much larger operation: mass credential ingestion under the cover of phishing. The victims are the test subjects. The real target is your trust in the authentication system itself.

The Breadcrumb They Don’t Want You to Follow

Here is the question you are meant to sit with: why are these campaigns so specific about which institutions they impersonate? Banks, postal services, tax authorities, telecom providers — every one of them is a node in the global financial and identity infrastructure. Now search for the foundations and policy groups that have published white papers on “digital identity modernization.” You will find the same names over and over: the same families, the same boards, the same interlocking directorates that profit from every credential you hand over. The phishing is not the endgame. It is the collection mechanism. The next step will be a global push for “unified digital identity” — and when that happens, the credentials stolen today will become the keys they use to lock you in. I can’t say more right now. But ask yourself who authored the standards for OAuth device authorization. Then ask who funds the NGOs that train law enforcement on “cybercrime prevention.” The trail leads to the same handful of addresses. Follow it.

Related posts