Take a Product Tour Request a Demo Cybersecurity Assessment Contact Us

Blogs

The latest cybersecurity trends, best practices, security vulnerabilities, and more

The Collapse of Digital Trust: Abuse of Relationships

Amid the ongoing conflicts in Iran and the disruptive 2026 United States military campaign "Operation Epic Fury," a far more insidious, global threat is emerging for businesses: The collapse of digital trust. While the world watches the Strait of Hormuz, adversaries are quietly shifting their strategy. They are no longer interested in "breaking in" through the front door of your network; they are simply "logging in" by weaponizing the very relationships, service providers, and SaaS tools your organization relies on to function.

This blog is the first in a series analyzing the rapid evolution of the 2026 threat landscape that involves machine-speed, adaptive adversaries who have successfully industrialized deception.

In the aftermath of the early 2026 United States military campaign "Operation Epic Fury" in Iran and ongoing regional instability, a far more insidious, global threat has emerged for businesses: The collapse of digital trust. While the world watched the Strait of Hormuz, adversaries quietly shifted their strategy. They are no longer interested in "breaking in" through the front door of your network; they are simply "logging in" by weaponizing the very relationships, service providers, and SaaS tools your organization relies on to function.

This blog is the first in a series analyzing the rapid evolution of the 2026 threat landscape, which involves machine-speed, adaptive adversaries who have successfully industrialized deception.

Why this matters to you

The primary implication of this shift is the failure of reputation-based security models. When adversaries weaponize legitimate infrastructure, traditional indicators of compromise (IoCs) become obsolete. For stakeholders, the "so what" is clear— security must move from a static compliance-based posture to a model of continuous readiness that prioritizes identity integrity and behavioral verification over perimeter defense.

Vendor concentration risk: The GrayCharlie case

Background: Intensifying between November 2025 and February 2026, the GrayCharlie campaign compromised at least fifteen U.S. law firms by infiltrating a shared third-party IT service provider, SMB Team, to steal confidential legal documents.1 Visitors to these trusted law firm websites were redirected to malware through fake "browser update" pop-ups.

Linked to the SmartApeSG group and active since mid-2023, the GrayCharlie campaign has demonstrated a sophisticated ability to chain exploits. This allows them to pivot from compromising a single vendor to achieving impact across an entire industry. They use MivoCloud and HZ Hosting Ltd infrastructure to distribute NetSupport RAT and the Stealc infostealer.

Strategic ‘so what': The campaign's success hinges on exploiting trust to steal highly sensitive legal data. This underscores the critical concentration risk, in which the weakest shared services provider compromises the security of an entire industry. Adversaries no longer need to breach a large company; they only need to compromise one of their technology providers to scale the impact silently and massively.

Actionable insight: Conduct a vendor concentration audit to identify providers with high-level access and mandate that they use phishing-resistant multi-factor authentication (MFA) for every login. This should be part of a larger continuous vendor risk management strategy. Because you cannot control a provider’s internal security, your strategy must focus on limiting their access and planning for their failure.

Identity ecosystem pollution: The Dutch telecommunications data breach

Background: In February 2026, a Dutch telecommunications company confirmed a breach exposing personal data for over six million accounts, including passports and bank account numbers.

The extortion group ShinyHunters has taken credit for the data breach. This incident is linked to a major criminal syndicate specializing in identity harvesting. ShinyHunters exposed passport and bank account numbers for over 6 million accounts on dark web forums. The information is described as "fuel" for future synthetic identity fraud, where real data is leveraged with AI to create fraudulent personas for sophisticated banking and insurance scams.

Strategic 'so what': This is not just a data leak; it is a "fueling event" for future fraud. Stolen passports are prime raw material for synthetic identity fraud. This pollution of the identity ecosystem will be leveraged by threat actors for years to come.

Actionable insight: Given that static personal data is now likely compromised, we must adopt additional methods to verify identity, such as behavioral biometrics. This involves tracking a user's unique patterns, such as keystrokes, mouse movements, and transaction rhythms.

SaaS deception: Bypassing filters via trusted domains

Background: Earlier this year, in January 2026, threat actors abused the legitimate Atlassian Jira Cloud domain to send automated spear-phishing emails. Because the emails came from a trusted, reputable domain, they successfully bypassed corporate filters.

This activity is attributed to a highly professionalized spam and phishing operator that relies on the "reputation" of legitimate SaaS providers rather than domain registration. The campaign targeted specific sectors, including government and corporate entities, using automated systems to scale the deception. The threat actor targeted government and corporate entities worldwide across six language groups, driving users to fraudulent investment schemes and casinos.2

Strategic 'so what': This exemplifies the "all green" problem. Security systems report that everything is safe because the traffic is coming from a known, "good" cloud provider. It exploits the inherent trust employees place in notifications from collaboration tools. The strategic risk is the misuse of trusted connectivity to bypass perimeters at scale.

Actionable insight: Tighten controls around third-party cloud-generated email. Redesign high-value workflows so they cannot be authorized solely through a link in a SaaS notification.

Social engineering and MFA bypass: Global Consumer Social Platform Provider and Commercial Market Intelligence Provider

Background: In January 2026, the ShinyHunters group breached a global consumer social platform and a commercial market intelligence provider. The attackers used voice phishing (vishing) to target administrative credentials and bypass technical filters.

The ShinyHunters extortion group is infamous for high-volume data theft, advanced social engineering tactics, and aggressive public leaking. During the global consumer social platform (Match.com and Hinge) compromise, they stole 10 million records. Separately, they breached the commercial market intelligence provider, stealing 2 million records through a voice phishing attack. This particular attack circumvented MFA by targeting administrative single sign-on (SSO) credentials.3

Strategic 'so what': This demonstrates the vulnerability of even well-defended organizations to low-tech social engineering, particularly when the attack focuses on a single, privileged identity. The primary target is the "keys to the kingdom", such as SSO credentials.

Actionable insight: Move away from "persistent admin grants" toward a "just-in-time" access model where privileges are valid only for a specific task and duration.

With early 2026's geopolitical conflicts serving as a catalyst for a new era of cyber warfare, the luxury of "good enough" security has expired. The 2026 threat landscape is no longer defined by the lone hacker, but by machine-speed, adaptive adversaries who have successfully industrialized deception. Through the collapse of digital trust, they have turned our most essential business relationships—our IT providers, our SaaS tools, and our very identities—into high-velocity delivery systems for compromise.

The strategic "so what" is undeniable —compliance is not security. A green checkmark on an audit will not stop a "fueling event" like the Dutch telecommunications breach or an identity-bypass attack like those seen from the global consumer social platform and the commercial market intelligence provider breaches.

To survive this shift, executive leadership must move from a posture of static defense to one of continuous readiness. We must stop protecting the "gate" and start verifying the "behavior." By anchoring our strategy in identity-first architectures and behavioral intelligence, we don't just react to the next crisis—we build an organization resilient enough to withstand a world where trust is the ultimate battlefield.

The perimeter hasn't just moved; it has vanished. It’s time to log in to a new reality.

Citations

1 https://www.ampcuscyber.com/shadowopsintel/graycharlies-targeting-of-law-firms/
2 https://www.trendmicro.com/en_us/research/26/b/spam-campaign-abuses-atlassian-jira.html
3 https://www.helpnetsecurity.com/2026/02/02/shinyhunters-mfa-social-engineering/

Discover the latest cybersecurity research from the Trellix Advanced Research Center.

Get the latest

Stay up to date with the latest cybersecurity trends, best practices, security vulnerabilities, and so much more.
Please enter a valid email address.

Zero spam. Unsubscribe at any time.