NewsTradingSentimentCalendarCommunityBriefing
Tech

N0va Phishing Campaign Targets US and EU Business Identities

By Tech Desk · 2026-09-16 · 2 min read
A sleek metallic padlock with a keyhole set against a dark background.
Illustration: Tradingbird

A new phishing kit is exploiting legitimate login processes to steal access to corporate accounts across North America and Europe, bypassing traditional malware detection methods.

Businesses in the United States and the European Union are facing a sophisticated phishing campaign known as N0va. Unlike traditional attacks that rely on obvious malware, this operation abuses legitimate authentication flows to gain access to valid user accounts. The campaign targets organizations in high-risk sectors, including government, healthcare, and technology, by impersonating trusted services like Microsoft Teams and Google Drive.

The danger lies in the subtlety of the intrusion. Because the attackers use official login mechanisms, their activity does not trigger standard security alerts for malicious software. Once a single identity is compromised, threat actors can access sensitive data, manipulate financial records, and disrupt operations. As reported by The Hacker News, the longer this access goes unnoticed, the greater the potential for widespread financial loss and reputational damage.

Exploiting Trusted Login Flows

N0va operates by sending convincing lures that mimic popular business platforms. Victims are guided through what appears to be a standard verification process. Instead of a simple fake login page, the kit captures access and refresh tokens during these legitimate interactions. These tokens are then used to establish single sign-on access, allowing attackers to bypass multi-factor authentication and reach email, files, and cloud applications.

This approach creates a significant trade-off for security teams. While the attack looks like normal user behavior, it is actually a breach. The method relies on the victim’s trust in familiar brands and the validity of the authentication flow itself, making it harder to detect than a direct malware injection.

Widespread Impact Across Sectors

The campaign has been observed affecting a broad range of industries. Targets include consulting firms, healthcare providers, and government agencies. The versatility of the attack means that any organization using cloud-based collaboration tools is potentially vulnerable. The impact extends beyond data theft to include operational disruption, as companies must revoke sessions and reset access for affected users.

Financial consequences can be severe, with risks ranging from invoice fraud to the exposure of intellectual property. Additionally, breaches involving regulated data may trigger legal reporting requirements and compliance penalties. The reputational cost of a breach involving trusted company accounts can also strain relationships with clients and partners.

Detecting Hidden Campaign Activity

Security teams face a challenge in distinguishing this activity from isolated phishing events. Effective defense requires understanding the broader context of the campaign. Analysts can identify related activity by looking for specific URL patterns associated with the kit. This allows organizations to move beyond single indicators and see how the campaign appears across different infrastructure submissions.

Treating these incidents as part of a wider campaign helps in prioritizing threats and responding with greater confidence. By integrating this intelligence into existing security tools, teams can better detect the token capture and device registration mechanisms that N0va relies on to maintain access.

Based on reporting by The Hacker News, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories
  • A sleek modern electric SUV parked on a quiet suburban driveway with its charging port open and a cable connected to a wall box.
    Illustration: Tradingbird

    Li Auto I9 Brings Swiveling Seats and Premium Comfort to the EV Market

    Li Auto has officially launched the Li i9, a six-seat flagship electric SUV priced at RMB 369,800, with deliveries beginning immediately. The vehicle targets the family segment with a focus on premium comfort and cabin flexibility, offering a spacious alternative to traditional luxury options.

    2026-09-16
  • A flat-vector illustration of a modern living room with a smart thermostat on the wall and a wireless router on a shelf.
    Illustration: Tradingbird

    Smart Home Sales Rely on Networking, Not Just Gadgets

    Independent retailers are finding that successful smart home sales depend on solving specific customer problems and ensuring robust network infrastructure, rather than just selling individual devices.

    2026-09-16
  • A small, boxy electric delivery vehicle parked on a city street
    Illustration: Tradingbird

    Stellantis Unveils BOW Autonomous Delivery Concept

    A new boxy electric vehicle aims to replace human drivers in city logistics, but key performance details remain hidden.

    2026-09-16