Return to Threats

N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security

thehackernews.com 2026-09-16 malicious AI use High

What Happened

N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity. From there, a single compromised identity can open the door to sensitive data, business systems, and additional cloud

Why It Matters

Reported facts: The N0va phishing kit is used in campaigns across North America and Europe that impersonate trusted services and abuse legitimate authentication flows, enabling attackers to obtain valid account access without obvious malware activity. A single compromised identity can then expose sensitive data, business systems, and additional cloud resources. RealGround analysis: While the article describes identity-focused phishing rather than a specific AI system compromise, similar attacks can be used to hijack AI-driven business tools and cloud-hosted AI services by stealing user credentials. Organizations should integrate AI CISO advisory and continuous red teaming to ensure identity protections, MFA enforcement, and phishing-resistant authentication are applied to all AI-related accounts and admin consoles.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to malicious AI use. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/09/n0va-phishkit-targets-us-and-eu.html

Talk to AI CISO