What happened
A voice-phishing campaign discovered in mid-December 2025 and running through January 2026 broke into single sign-on accounts in real time. SoundCloud was among the named victims, with roughly 36 million users affected, about 20% of its user base. Betterment was also named, with an attack dated 9 January 2026. Okta researchers identified at least two phishing kits with dedicated panels impersonating Google, Microsoft, Okta and cryptocurrency sign-in flows, and Sophos tracked around 150 malicious domains.
How the deception worked
The operator registers a lookalike SSO domain, then calls the target and controls what the victim's browser shows page by page while the call is in progress. That synchronisation is the innovation: the caller can say exactly what will appear next, and can time the spoken instruction to the moment a genuine MFA prompt lands, so the victim approves on cue rather than reading a code aloud to a stranger. Because the operator drives a live session against the real identity provider, the stolen authentication is immediately usable.
AI involvement · Unknown
Researchers described live human callers driving phishing kits in real time; no synthetic voice was reported, though attribution of voice authenticity was not addressed.
The control that would have caught it· our reading, not a claim from the sources
Origin-bound passkeys or FIDO2 keys defeat real-time relay regardless of how persuasive the caller is; number matching alone does not, because the caller narrates the number.
Sources (1)
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.