Same Sea, New Phish
Russian Government-Linked Social Engineering Targets App-Specific Passwords

Keir Giles, a prominent expert on Russia, was targeted with a new form of social-engineering attack that leverages App-Specific Passwords. Google links the operation to UNC6293, a Russian state-backed group.

Featured Publications

Unspoken Implications: A Preliminary Analysis of Bill C-2 and Canada’s Potential Data-Sharing Obligations Towards the United States and Other Countries

Our preliminary analysis of Bill C-2 situates the legislation within the context of existing research by the Citizen Lab about two potential data-sharing treaties that are most relevant to the new proposed powers being introduced in Bill C-2: the Second Additional Protocol to the Budapest Convention (2AP) and the CLOUD Act. Both of which carry significant constitutional and human rights risks.

Lifting the lid off the Internet.

The Citizen Lab is an interdisciplinary laboratory based at the Munk School of Global Affairs & Public Policy, University of Toronto, focusing on research and development at the intersection of information and communication technologies, human rights, and global security. Learn more.

Get the latest Citizen Lab news right in your inbox.

Subscribe below.

Privacy Policy

Features & News

Exposing Pegasus: How the State Spies on You

In an interview with What Bitcoin Did, Citizen Lab senior researcher John Scott-Railton discusses the proliferation of spyware and the repercussions of its use on victims. He explains how mass surveillance “ultimately leads to self-censorship,” with significant implications for our freedom. Watch here.

John Scott-Railton on U.K.’s Age-Verification Laws

A new U.K. age-verification law aimed to protect children can push people to seedier parts of the web. Citizen Lab senior researcher John Scott-Railton spoke with the Washington Post about the “law of unintended consequences” faced by regulators.  The law “suppresses traffic to compliant platforms while driving users to sites without age verification,” says Scott-Railton…. Read more »

Featured Video

Gender-based Digital Transnational Repression Explained