Published on 16 August 2026
A single email. Three parallel attacks. And your device decides which one you get. What sounds like an advertising slogan is the sober summary of an active phishing campaign that the KnowBe4 Threat Lab analysed in late July 2026 and that the specialist service All About Security picked up on 13 August 2026. The scheme: a fake iCloud sign-in alert. What happens next depends on which operating system you use to open the link – and in the worst case you lose not just your password, but also control of your device or your Microsoft 365 mailbox.
For small and medium-sized enterprises, this is a wake-up call. Because this technique doesn't exploit some mysterious security flaw in Apple or Microsoft software for which a patch would exist. It exploits trust, time pressure and clever camouflage – and that's precisely why any employee can become the point of entry.
On 30 July 2026, the KnowBe4 Threat Lab published the analysis "Inside the OS-Aware Phishing Kit Profiling Your Device". It examined a phishing campaign that was active at that point, featuring a so-called AiTM component – short for "Adversary in the Middle", meaning an attacker who inserts themselves in real time between the victim and the genuine service.
The bait is an email imitating an iCloud sign-in alert – complete with a supposed reference number (03483526-WQAD). Anyone who clicks doesn't realise they're passing through a multi-stage redirection chain, at the end of which sits the attacker's server. There, a script evaluates which operating system the victim is using and sends them down one of three paths:
ScreenConnect.ClientSetup.exe – a legitimate, commercially signed remote administration tool (RMM = Remote Monitoring and Management), which is abused here to gain remote access to the machine.Analysts Prabhakaran Ravichandhiran and Jeewan Singh Jalal sum it up:
„One email. Three parallel operations. Your device chooses which one you got.“
The activity is documented by the attackers' own redirection log: for the 48-hour window from 5 to 6 May 2026, it recorded more than 250 verified human clicks. Of these, around 65% came from Apple devices, 28% from Windows and 7% from Android and other systems. Of 157 geolocated clicks, 150 were in the US. Important for context: these are click figures, not a count of successful account takeovers. The source names no confirmed German victims.
The visible link in the email posed as an Apple address. In reality it led through three redirection hops:
Before anything is even displayed, an anti-bot script checks whether it's dealing with a real victim or an analysis system. Among other things, it checks the browser user agent string against Microsoft Defender and security scanners, verifies whether the call came via Outlook SafeLinks, evaluates IP reputation and requires genuine JavaScript interaction. As a result, automated scanners see only a 404 error – the campaign remains largely invisible to conventional inspection mechanisms.
Only then does a PHP script decide the onward path based on the operating system. The third route is particularly insidious: there, email address, password, IP, timestamp and browser identifier are immediately sent to a Telegram bot. A human operator then steers the next page in real time – for instance a fake Microsoft login, a repeated password prompt or a request to enter the MFA code.
And this is precisely where the real danger lies: the attacker intercepts the one-time code entered by the victim and immediately reuses it within its validity period against the genuine service. Two-factor authentication (MFA) is therefore not technically cracked – it is bypassed, because the victim hands the code straight to the attacker in real time. Microsoft describes the same risk class in general terms as token theft:
„Traditional MFA methods such as SMS codes, email-based OTPs, and push notifications are becoming less effective ... Attackers now exploit social engineering, man-in-the-middle tactics, and user fatigue ... to bypass these mechanisms.“ (Microsoft Learn)
For clarity: there is no CVE number, no affected software version and no vendor patch for this campaign. Not because it's harmless – but because no product flaw is being exploited. The weapon is deception.
In principle, anyone who uses an iCloud or Microsoft 365 login and falls for the link. According to the log, the campaign itself mainly targeted users in the US, but the technique can be reused independently of brand and region. For German SMEs, the risk is therefore high.
The crucial point: based on this source material, it is not your website that is technically vulnerable, but your identities and endpoints. A compromised Microsoft 365 account opens access to emails, OneDrive and SharePoint. A Windows machine remotely controlled via ScreenConnect can serve as a springboard into the entire corporate network. And via compromised admin accounts, there is a threat of access to website backends, DNS and hosting accounts, source code, and payment and support processes.
The following indicators (IOCs) come from a single analysis and age quickly. Use them for a retrospective search in your logs – not as a complete detection guarantee.
globalema[.]com, cherylbirch[.]com, andersonsin[.]com and login1[.]indomesinq[.]click. Important: do not blanket-block the entire domain of a legitimate financial institution simply because its open redirect path was abused.03483526-WQAD.ScreenConnect.ClientSetup.exe and the checksum SHA-256 f9a67b861d56beffa0c880ecc90ec8c1fe6b540aec6438783bb60ea094c0aef9. A hit confirms the download indicator – additionally assess installation, process, service and network events.reportphishing@apple.com.„Apple wird dich niemals auffordern, dich bei einer Website anzumelden oder ... dein Passwort, deinen Gerätecode oder deinen Code für die Zwei-Faktor-Authentifizierung auf einer Website einzugeben.“ (Apple Support)
A successful phishing or AiTM attack can constitute a personal data breach as soon as attackers can gain unauthorised access to personal data in mailboxes, cloud files or customer enquiries. Not every clicked phishing email automatically triggers a notification obligation – what matters is the existence of a data breach and the risk assessment. The European Data Protection Board explicitly counts phishing attacks among the relevant incidents:
„Datenschutzverletzungen ... umfassen ... absichtliche Handlungen (wie Phishing-Angriffe, um Zugang zu Kundendaten zu erhalten).“ (EDSA)
Every breach must be documented. If a risk to the rights and freedoms of natural persons is not unlikely, the competent data protection authority must be notified where possible within 72 hours of becoming aware; where a high risk is likely, the affected individuals must be informed without delay. Processors must inform the controller without delay.
Art. 32 GDPR requires appropriate technical and organisational measures. Breaches of the obligations under Art. 25 to 39 GDPR can, under Art. 83(4) GDPR, be sanctioned with fines of up to EUR 10 million or up to 2% of annual worldwide turnover, whichever is higher. This is not an automatic sanction and not a prognosis for the individual case.
How relevant transparent conduct is is shown by a German comparison case: in 2018, the LfDI Baden-Württemberg imposed a fine of EUR 20,000 for an Art. 32 breach following a hacker attack on around 330,000 users (including passwords and email addresses) – and explicitly took the prompt notification, transparent cooperation and security improvements into account as mitigating factors. The then State Commissioner Dr. Stefan Brink put it this way:
„Wer aus Schaden lernt und transparent an der Verbesserung des Datenschutzes mitwirkt, kann auch als Unternehmen aus einem Hackerangriff gestärkt hervorgehen.“
This assessment is general information, not legal advice. Where the evaluation is unclear, you should consult data protection officers and, where appropriate, legal counsel.
This campaign is a textbook example of modern phishing: credible brand impersonation, trustworthy redirection infrastructure, anti-analysis, operating-system-dependent attack paths, a signed remote administration download and a live-operated AiTM flow that even defeats conventional MFA. What is documented is more than 250 clicks in 48 hours and live-controlled MFA prompts – but the source names no confirmed compromises or German victims.
For German website operators: the immediate threat is identity- and endpoint-related. Priority therefore goes to employee and admin accounts, Windows endpoints, Microsoft 365 and Apple accounts, a clean log analysis and a fast, documented incident response process. The most effective lever against exactly this class of attack is the switch to phishing-resistant MFA with passkeys or FIDO2 – combined with employees who know the pattern and understand that genuine iCloud or Microsoft alerts never ask for a password or code via an email link.
As Martina Link, Vice President of the Federal Criminal Police Office (BKA), notes: "Cybercriminals continuously adapt their methods and thereby increase the pressure on the state, the economy and society." Those who are prepared give this pressure considerably less to work with.