GLOBSEC A.I CyberSecurity Scoring
GLOBSEC
Company Information
Website:http://www.globsec.org
Employees number:151
Number of followers:21,750
NAICS:92812
Industry Type:International Affairs
Homepage:globsec.org
GLOBSEC Risk Score (AI oriented)
Between 700 and 749
GLOBSECInternational Affairs
Updated:
27/08/2026
27/08/2026
738/1000
Moderate
Ba
GLOBSEC Global Score (TPRM)
xxxx
GLOBSECInternational Affairs
Score locked

GLOBSECModerate
Current Score
738Ba (MODERATE)
01000
1 incidents
-17 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
738
AUGUST 2026
738
JULY 2026
737
JUNE 2026
737
MAY 2026
736
APRIL 2026
736
MARCH 2026
735
FEBRUARY 2026
735
JANUARY 2026
751
Cyber Attack
13 Jan 2026 • GLOBSEC
GLOBSEC and Google: Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts
Russian-Linked Cyber Espionage Campaign Expands OAuth and Phishing Tactics
734
CRITICAL-17
GOOGLO1787819408
Russian-Linked Cyber Espionage Campaign Expands OAuth and Phishing Tactics
A sophisticated cyber espionage campaign linked to Russian threat actors including UNC6293, a subcluster of ICE RELIC (APT29/Cozy Bear/Midnight Blizzard) is escalating account-compromise operations by abusing legitimate authentication workflows. The campaign combines OAuth phishing, device-code attacks, credential-harvesting infrastructure, and suspected Evilginx reverse-proxy setups to bypass multi-factor authentication (MFA) protections.
### Key Tactics and Infrastructure
The attackers exploit trust in authentication processes rather than software vulnerabilities, tricking victims into authorizing attacker-controlled access. This method undermines MFA by convincing targets to complete legitimate logins before handing over tokens or OAuth permissions.
Lure Domains and Social Engineering
- foreignrelations[.]us and dosportal[.]app were identified as OAuth phishing lures, with historical WHOIS data linking them to the registrant email given956[@]2200freefonts[.]com, which also registered internationalaffairsportal[.]us and stateaffairs[.]us.
- Archived content on foreignrelations[.]us referenced a Council on Foreign Relations article, while other domains reused web templates and meta tags to mimic trusted diplomatic and policy content.
- Evilginx-style behavior was observed on stateaffairs[.]us subdomains between January 13 and February 2, 2026, redirecting users to legitimate U.S. Department of State sites to capture session credentials.
Additional Threat Clusters
- UNC7005, tracked separately due to weaker operational security, used Microsoft device-code phishing and targeted WhatsApp accounts via fake event invitations (e.g., a spoofed GLOBSEC Forum 2026 lure hosted on my-invite[.]org).
- UNC5976 focused on Google-themed OAuth phishing, including drive[.]google[.]verify-drive[.]com, which mimicked Google Drive with a decoy login page. A shared favicon hash (c66f20f2e39eb2f6a0a4cdbe0d955e5f) linked multiple domains, aiding detection.
### Targets and Impact
The campaign primarily targets academia, government, aerospace, defense, and think tanks across Europe and the U.S.. By blending polished decoy sites, legitimate redirects, and OAuth prompts, the attackers reduce the likelihood of detection before account access is compromised.
### Indicators of Compromise (IOCs)
- IPs: 151.236.15[.]213, 185.158.250[.]155
- Domains: fllefolder[.]com, sharefolders[.]org, formshare[.]cloud, sharedfolders[.]org
- Subdomains: drive[.]google[.]sharefolders[.]org, drive[.]google[.]formshare[.]cloud
The campaign highlights the growing threat of adversary-in-the-middle (AitM) phishing frameworks, which exploit trust in identity services rather than technical flaws. Organizations are advised to monitor for unexpected OAuth consent requests, device-code prompts, and anomalous token usage to mitigate exposure.
INCIDENT DETAILS -
TYPE
MOTIVATION
DATA BREACH
REFERENCES
DECEMBER 2025
751
NOVEMBER 2025
751
OCTOBER 2025
751
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for GLOBSEC ??
What was GLOBSEC's A.I Rankiteo Cyber Score in August 2026 ??
What was GLOBSEC's A.I Rankiteo Cyber Score in July 2026 ??
What was GLOBSEC's A.I Rankiteo Cyber Score in June 2026 ??
What was GLOBSEC's A.I Rankiteo Cyber Score in May 2026 ??
What was GLOBSEC's A.I Rankiteo Cyber Score in April 2026 ??
What was GLOBSEC's A.I Rankiteo Cyber Score in March 2026 ??
What was GLOBSEC's A.I Rankiteo Cyber Score in February 2026 ??
What was GLOBSEC's A.I Rankiteo Cyber Score in January 2026 ??
What was GLOBSEC's A.I Rankiteo Cyber Score in December 2025 ??
What was GLOBSEC's A.I Rankiteo Cyber Score in November 2025 ??
What was GLOBSEC's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on GLOBSEC's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with GLOBSEC ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view GLOBSEC's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?