Skip to content

Menu

Robinson & Cole LLP logo
About UsOur PracticeContactTopics
Search
Close
Subscribe

Data Privacy + Cybersecurity Insider

Leveraging Knowledge to Manage Your Data Risks

Social Engineering Schemes Target C-Suite Executives

By Linn Foster Freedman on April 16, 2026
Posted in Cybersecurity

March was a busy month for former Black Basta affiliates who are using old social engineering techniques to target executives in the manufacturing, professional, scientific, and technical services industries. According to Reliaquest, the activity of the threat actors indicates that these sectors “were likely direct targets.”

According to its report, “Attackers are using automation to compress a multi-step social engineering attack into minutes, reducing the time defenders have to intervene before a live remote management session is established on a senior leader’s machine.” This means that they target C-Suite executives to ratchet up the pressure. Initially, the threat actors send a high volume of emails, known as a “bomb,” which floods the user’s email account within minutes. This technique is designed to overwhelm the user. While the victim struggles to manage a flood of incoming emails, the threat actor reaches out via a direct Microsoft Teams message or phone call (vishing), posing as technical support. Within minutes of the email flooding, the attacker initiates contact, gains the user’s trust, and steals their credentials—ultimately obtaining full access to the account.

The rest is history. The takeaway? Educate your C-Suite executives on their increased risk of being targeted by cyber threat actors and how to identify an email bomb, a vishing scheme, suspicious Teams chat from an external account, the launching of a remote session that is not one used by the organization, and to never give away their credentials. Any one of these clues could prevent an incident.

Tags: Black Basta, C-Suite Executives, cyber actors, email bomb, login credentials, Microsoft Teams, social engineering, vishing
Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Linn Foster Freedman Linn Foster Freedman

Linn Freedman practices in data privacy and security law, cybersecurity, and complex litigation. She is a member of the Business Litigation Group and the Financial Services Cyber-Compliance Team, and chairs the firm’s Data Privacy and Security and Artificial Intelligence Teams. Linn focuses her…

Linn Freedman practices in data privacy and security law, cybersecurity, and complex litigation. She is a member of the Business Litigation Group and the Financial Services Cyber-Compliance Team, and chairs the firm’s Data Privacy and Security and Artificial Intelligence Teams. Linn focuses her practice on compliance with all state and federal privacy and security laws and regulations. She counsels a range of public and private clients from industries such as construction, education, health care, insurance, manufacturing, real estate, utilities and critical infrastructure, marine and charitable organizations, on state and federal data privacy and security investigations, as well as emergency data breach response and mitigation. Linn is an Adjunct Professor of the Practice of Cybersecurity at Brown University and an Adjunct Professor of Law at Roger Williams University School of Law.  Prior to joining the firm, Linn served as assistant attorney general and deputy chief of the Civil Division of the Attorney General’s Office for the State of Rhode Island. She earned her J.D. from Loyola University School of Law and her B.A., with honors, in American Studies from Newcomb College of Tulane University. She is admitted to practice law in Massachusetts and Rhode Island. Read her full rc.com bio here.

Read more about Linn Foster Freedman
Show more Show less
Related Posts
ShinyHunters Hit Instructure + Downs Canvas Learning Management System
May 14, 2026
ShinyHunters Target Medical Device Company Medtronic
May 7, 2026
CISA Warning: Firestarter Malware Persists in Cisco Devices
May 7, 2026
Follow us on X Follow us on X
Follow Us on Facebook Follow Us on Facebook
View Our Linkedin Profile View Our Linkedin Profile

Data Privacy + Cybersecurity Insider

Our Authors
Robinson & Cole LLP logo
Connecticut•Massachusetts•New York•Washington DC•Rhode Island•Florida•California•Delaware•Pennsylvania•Texas
Follow us on X Follow Us on Facebook View Our Linkedin Profile RSS
Privacy PolicyTerms of UseDisclaimerCalifornia Privacy Rights Notice
  • Home
  • Subscribe
  • Our Practice
  • Contact

Robinson+Cole is a law firm serving regional, national and global clients from nine offices throughout the Northeast. Our Data Privacy + Security Team brings together lawyers from the firm’s Intellectual Property and Technology, Commercial Litigation, and E-Commerce Groups.

Read More...

Topics

Archives

Copyright © 2026, Robinson & Cole LLP. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo

Please note that as of January 1, 2023 our Privacy Policy has changed. Click here for details on our new terms.

OK