Skip to the main content.

ABT Blog

Read about mortgage technology solutions topics

phishing

Laptop showing three attack routes from the 2026 Microsoft Digital Defense Report: a Verify you are human prompt telling the user to press Win + R and paste, a Microsoft Teams call from an external caller, and an Outlook email asking Do you have a moment, beside the Microsoft 365 logo and the headline Keep staff working, Catch the stolen session, Report it to the board.

13 min read

Microsoft Digital Defense Report 2026: What Banks, Credit Unions, and Lenders Should Do First

In This Article Inside the Microsoft Digital Defense Report 2026 Attackers start with people and sign-ins Phishing now steals the session ClickFix...

Read More
Microsoft Defender for Office 365 settings panel beside a Payment Advice Note email with a password-protected ZIP file and a password shown as an image, illustrating Star Blizzard phishing checks for financial institutions

12 min read

Star Blizzard Phishing: What Banks, Credit Unions, and Lenders Should Check

In This Article What Star Blizzard changed in 2026 How a RedFlick phishing email works Four signs your staff can spot Seven Microsoft 365 and...

Read More
Hotel conference room laptop showing a captive portal sign-in, with a stolen Microsoft 365 session token flowing to an attacker past Microsoft Entra ID controls

14 min read

Hotel Wi-Fi Is Stealing Microsoft 365 Sessions

In This Article What Microsoft Found on Hotel and Conference Wi-Fi Two Attack Paths, and Why the Difference Decides Your Controls The Part That...

Read More
A credit union professional reviewing email on a laptop with a Microsoft 365 security shield deflecting a phishing attack

15 min read

Security Awareness Training for Financial Institutions

In This Article The control with no dashboard: your people Why your staff is the most-attacked control at a financial institution The training your...

Read More
ConsentFix v3 OAuth consent phishing toolkit bypasses Microsoft 365 MFA — financial institution defense guide

13 min read

ConsentFix v3: The OAuth Consent Phishing Toolkit That Bypasses MFA for Financial Institutions

In This Article The Attack That Skips MFA How ConsentFix v3 Actually Works Why Financial Institutions Are the Target What Stops This (and What Does...

Read More
Microsoft-branded hero image for ABT blog article: The Exploit: Anatomy of a Modern Cyber Heist Part 2 - The Perfect Phish. Banks, credit unions, and mortgage companies.

14 min read

The Exploit: Anatomy of a Modern Cyber Heist Part 2 - The Perfect Phish

In This Article Tycoon2FA: 13 Million Phishing Emails in a Single Month How Adversary-in-the-Middle Attacks Defeat Standard MFA NYDFS Part 500 Is Now...

Read More
Microsoft Defender for Office 365 anti-phishing configuration for credit unions, banks, and mortgage companies

19 min read

Microsoft Defender for Office 365 for Financial Institutions: The Anti-Phishing Configuration Examiners Expect

In This Article The Phishing Reality for Banks, Credit Unions, and Mortgage Companies in 2026 What You Actually Own: Defender for Office 365 Plan 1...

Read More
Phishing-resistant MFA for financial institutions: hardware-backed FIDO2 security keys, passkeys, and Microsoft Entra ID Conditional Access protecting against AiTM, credential theft, and phishing attacks

16 min read

Phishing-Resistant MFA for Financial Institutions: Why FFIEC, NCUA, and OCC Examiners Now Expect FIDO2, Passkeys, and Hardware Keys

In This Article What "Phishing-Resistant" Authentication Actually Means Why SMS, Push, and One-Time Codes No Longer Pass the Bar What FFIEC Examiners...

Read More
Microsoft-branded hero image for ABT blog article: Code of Conduct AiTM Phishing: How 35,000 Users in 13,000 US Organizations Were Compromised in 72 Hours - What Banks, Credit Unions, and Mortgage Companies Must Verify Now. Banks, credit unions, and mortga

18 min read

Code of Conduct AiTM Phishing: How 35,000 Users in 13,000 US Organizations Were Compromised in 72 Hours - What Banks, Credit Unions, and Mortgage Companies Must Verify Now

In This Article What Happened: 72 Hours, 35,000 Users, 13,000 Organizations Why a Code of Conduct Lure Works on Financial Institution Users The...

Read More
VENOM PhaaS QR code AiTM phishing attack targeting financial institution executives

15 min read

VENOM PhaaS: MFA Bypass Targeting Financial Executives

In This Article What Is VENOM? The QR Code That Email Security Cannot See The Attack Chain: From Inbox to Persistent Access Why Standard MFA Does Not...

Read More